Source: OJ L, 2025/1140, 10.6.2025

Current language: EN

Article 15 Identification of crypto-assets


Summary What does Article 15 of the RTS on record keeping say?

This article sits alongside Article 14, which addresses how legal entity clients must be identified when reporting to competent authorities.

Article 15 applies the same logic to crypto-assets themselves: when crypto-asset service providers submit order or transaction information to competent authorities under Articles 6 and 7, they must use a standardised identifier for each crypto-asset involved.

The primary standard specified is ISO 24165, though an ESMA-approved equivalent at Union level is also accepted, provided it meets a defined set of quality characteristics.

Important points:

  • When reporting to competent authorities under Articles 6 and 7, use a digital token identifier compliant with ISO 24165 to identify crypto-assets in recorded orders or transactions.
  • An ESMA-approved alternative identifier is permitted, but only if it meets all eight listed characteristics, including being unique, neutral, reliable, open source, and subject to an appropriate governance framework.
  • The obligation applies to crypto-assets that are the subject of the order or transaction, as well as those used as a means of payment.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

When providing information to competent authorities under Articles 6 and 7, a crypto-asset service provider shall identify the crypto-assets that are the subject of the recorded order or transaction, or used as a means of payment, by using a digital token identifier that is compliant with the ISO 24165 standard or an equivalent unique identifier approved by ESMA at Union level, which meets all of the following characteristics:

  1. is unique;

  2. is neutral;

  3. is reliable;

  4. is open source;

  5. is scalable;

  6. is accessible;

  7. is available at a reasonable cost basis; and

  8. is subject to an appropriate governance framework.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod