Source: OJ L, 2025/303, 20.2.2025

Current language: EN

Article 6 Custody and administration policy


Summary What does Article 6 of the RTS on notification of crypto-asset service provision say?

This article applies specifically to notifying entities intending to provide custody and administration of crypto-assets on behalf of clients.

It sets out the detailed information that must be submitted to the competent authority as part of the notification process under Article 60(7)(e) of MiCA.

The article connects directly to Article 75 of MiCA, which governs the obligations of custodian crypto-asset service providers, and the information required here is essentially designed to demonstrate how a notifying entity will comply with those obligations in practice.

The core thrust of the article is transparency around how client crypto-assets will be safeguarded, managed, and returned, covering everything from the custody policy and risk management arrangements to what happens when custody functions are delegated to a third party.

Important points:

  • Provide the competent authority with your full custody and administration policy, including your standard client agreement, identified operational and ICT risks, and the systems in place to protect, exercise rights over, and return client crypto-assets.
  • Include arrangements to minimise the risk of loss of crypto-assets or means of access to them, as well as how client crypto-assets are identified and kept distinct.
  • Where custody has been delegated to a third party, disclose the identity and regulatory status of that third party, the scope of delegated functions including any sub-delegations, any conflicts of interest arising, and how you intend to supervise those arrangements.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

For the purposes of Article 60(7), point (e), of Regulation (EU) 2023/1114, the notifying entity shall provide to the competent authority the following information:

  1. a description of the arrangements linked to the type of custody offered to clients, a copy of the notifying entity’s standard agreement for the custody and administration of crypto-assets on behalf of clients pursuant to Article 75(1) of Regulation (EU) 2023/1114 and a copy of the summary of the custody policy made available to clients in accordance with Article 75(3) third subparagraph of that Regulation;

  2. the notifying entity’s custody and administration policy, including a description of identified sources of operational and ICT risks for the safekeeping and control of the crypto-assets or the means of access to the crypto-assets of clients, together with the following:

    1. the policies and procedures, and a description of the arrangements to comply with Article 75(8) of Regulation (EU) 2023/1114;

    2. the policies and procedures, and a description of the systems and controls, to manage the operational and ICT risks, including where the custody and administration of crypto-assets on behalf of clients is outsourced to a third party;

    3. the policies and procedures relating to, and a description of, the systems to ensure the exercise of the rights attached to the crypto-assets by the clients;

    4. the policies and procedures relatig to, and a description of, the systems ensuring the return of crypto-assets or the means of access to the clients;

  3. information on how the crypto-assets and the means of access to the crypto-assets of the clients are identified;

  4. information on arrangements to minimise the risk of loss of crypto-assets or means of access to crypto-assets;

  5. where the crypto-asset service provider has delegated the provision of custody and administration of crypto-assets on behalf of clients to a third-party:

    1. information on the identity of any third-party providing the service of custody and administration of crypto-assets and its status in accordance with Article 59 or Article 60 of Regulation (EU) 2023/1114;

    2. a description of any functions relating to the custody and administration of crypto-assets delegated by the crypto-asset service provider, the list of any delegates and sub-delegates, as applicable, and any conflict of interest that could arise from such a delegation;

    3. a description of how the notifying entity intends to supervise the delegations or sub-delegations.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod