1. Authorization & Legal Entity
- ☐ EU legal entity established and effectively managed in your home member state
- ☐ CASP authorization granted (or application filed) with the home NCA — see the application checklist
- ☐ Services correctly classified under MiCA service definitions
- ☐ Passporting notifications filed for any other member states served
- ☐ White papers published/notified for any tokens offered (see white paper guide)
2. Capital & Prudential Safeguards
- ☐ Correct capital class identified — Class 1 (€50k), Class 2 (€125k), or Class 3 (€150k)
- ☐ Permanent minimum capital held in qualifying own funds
- ☐ One-quarter-of-fixed-overheads test calculated and the higher amount maintained
- ☐ Ongoing monitoring of own funds against the requirement
Detail in our capital requirements guide.
3. Governance, People & Risk
- ☐ Fit-and-proper management body with relevant experience
- ☐ Qualifying shareholders identified and assessed
- ☐ Governance arrangements, internal controls, and risk management documented
- ☐ Conflict-of-interest policy
- ☐ Complaints-handling procedure
- ☐ Outsourcing policy and oversight
- ☐ Business-continuity policy
4. AML / CFT & Travel Rule
- ☐ Business-wide ML/TF risk assessment
- ☐ KYC/CDD and onboarding with verification tooling
- ☐ Transaction monitoring and blockchain analytics
- ☐ Sanctions screening
- ☐ Travel Rule data flows (no threshold for crypto) — see Travel Rule guide
- ☐ Appointed MLRO and SAR/STR process — see MLRO guide
- ☐ Training, independent testing, recordkeeping
5. ICT Resilience & DORA
- ☐ Board-approved ICT risk-management framework
- ☐ Incident classification and 4h/72h/1-month reporting capability
- ☐ Resilience-testing programme (TLPT if significant)
- ☐ Register of information for ICT third parties
- ☐ DORA-compliant supplier contracts and exit strategies
Full detail in our DORA compliance guide.
6. Conduct & Client Protection
- ☐ Segregation of client crypto-assets and funds (custodians — see custody rules)
- ☐ Register of client positions (custody)
- ☐ Fair, clear, not-misleading marketing communications
- ☐ Market-abuse detection and reporting for trading platforms — see market abuse rules
- ☐ Clear client information and risk disclosures
7. Ongoing Obligations
Compliance is continuous. Maintain capital, refresh the AML risk assessment, keep the ICT register current, monitor for market abuse, report incidents and suspicious activity on time, and notify your NCA of material changes. Supervisory reviews can come at any time — keep the evidence current rather than reconstructing it under pressure.
The fastest way to find your gaps is a structured review against this checklist. That is exactly what our MiCA consulting team delivers.