2025-12-23
The Croatian Financial Services Supervisory Agency (HANFA) issued these guidelines to define good practices and organizational requirements for crypto-asset service providers (CASPs) under the MiCA Regulation. The document mandates robust internal control systems, including distinct risk management, compliance monitoring, and internal audit functions, while strictly regulating the externalization of services to prevent regulatory arbitrage and ensure effective oversight. It further establishes specific standards for ICT risk management, third-party due diligence, and the retention of critical in-house expertise to maintain market stability and investor protection.