Source: OJ L, 2025/1140, 10.6.2025

Current language: EN

Article 3 Record-keeping of the crypto-asset service provider’s policies and procedures


Summary What does Article 3 of the RTS on record keeping say?

This article sets out record-keeping obligations for crypto-asset service providers specifically concerning their internal policies and procedures.

Beyond simply retaining the written policies themselves, it extends the requirement to also capture the ongoing governance activity around those policies, namely the management body's assessments and periodic reviews of their effectiveness, findings of any deficiencies, and the measures taken to address them.

Important points:

  • Keep records of all written policies and procedures required under Regulation (EU) 2023/1114 and its implementing measures.
  • Keep records of the management body's periodic reviews of the effectiveness of those policy arrangements and procedures.
  • Document any deficiencies identified during those reviews, along with the measures taken to address them.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

    1. Crypto-asset service providers shall keep records of any policies and procedures they are required to maintain in writing under Regulation (EU) 2023/1114 and its implementing measures.

    1. Crypto-asset service providers shall also keep the records of the assessment and periodical review, carried out by their management body, of the effectiveness of the policy arrangements, and procedures referred to in Articles 68(6) of Regulation (EU) 2023/1114, including of any deficiencies identified in relation to such policy arrangements and procedures and of any measures taken to address such deficiencies.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod