2024-12-17
Added · Updated
The European Securities and Markets Authority (ESMA) issued final guidelines to specify investor protection requirements under the Markets in Crypto Assets Regulation (MiCA) regarding suitability assessments and periodic statements for portfolio management services. These guidelines align MiCA suitability principles with MiFID II standards, requiring crypto-asset service providers to evaluate client knowledge, financial situation, and risk tolerance, while also clarifying that asset-referenced and electronic money tokens are generally considered safer than other crypto-assets. Additionally, ESMA established rules for the format and frequency of periodic portfolio statements and provided guidance on procedures for crypto-asset transfer services to ensure consistent application across the EU.
ESMA published 1 document in the last 30 days — get each new one by email the day it lands.
17 December 2024
ESMA35-1872330276-1936
Final Report
Guidelines specifying certain requirements of the Markets in Crypto Assets Regulation (MiCA) on investor protection – third package
ESMA - 201-203 rue de Bercy - CS 80910 - 75589 Paris Cedex 12 - France - Tel. +33 (0) 1 58 36 43 21 - www.esma.europa.eu 2
Table of Contents
1 Executive Summary.....................................................................................................5
2 Aspects of the suitability requirements applicable to the provision of advice and portfolio management in crypto-assets and the format of the periodic statement referred to in Article
81(14) of MiCA....................................................................................................................6
2.1 Background and legal basis..................................................................................6
2.2 Feedback to the consultation ................................................................................9
2.2.1 Suitability assessment ............................................................................................9
2.2.1 Periodic statement for portfolio management services..........................................13
3 Guidelines on the procedures and policies, including the rights of clients, in the context
of transfer services for crypto-assets ................................................................................16
3.1 Background and legal basis................................................................................16
3.2 Feedback to the consultation ..............................................................................19
4 Annexes ....................................................................................................................25
4.1 Annex I: Cost-benefit analysis.............................................................................25
4.2 Annex II: SMSG advice to ESMA on its third consultation paper on the Markets in
Crypto Assets Regulation (MiCA)..................................................................................38
4.3 Annex III: Guidelines on certain aspects of the suitability requirements and format
of the periodic statement for portfolio management activities under MiCA ....................45
4.4 Annex IV: Guidelines on the procedures and policies, including the rights of clients,
in the context of transfer services for crypto-assets.......................................................75
Acronyms and definitions used
CP Consultation Paper
ESMA European Securities and Markets Authority ESMA Regulation Regulation (EU) 1095/2010 of the European Parliament and of the Council of 24 November 2010 establishing a European Supervisory Authority (European Securities and Markets Authority), amending Decision 716/2009/EC and repealing Commission Decision 2009/77/EC EU European Union MiCA Regulation (EU) 2023/1114 of the European Parliament and the Council of 31 May 2023 on markets in crypto-assets1 MiFID II Directive 2014/65/EU of the European Parliament and of the Council of 15 May 2014 on markets in financial instruments and amending Directive 2002/92/EC and Directive 2011/61/EU NCAs National competent authorities SMSG Securities and Markets Stakeholder Group established under Regulation (EU) No 1095/2010 1 Regulation (EU) 2023/1114 of the European Parliament and the Council of 31 May 2023 on markets in crypto-assets (OJ L 150,9.6.2023, p. 40–205).
1 Executive Summary
Reasons for publication
MiCA requires ESMA to submit regulatory technical standards (RTS) and guidelines on a variety of topics. On 25 March 2024, ESMA published a CP to seek stakeholders’ views on ESMA’s proposals for 1 RTS and 3 sets of guidelines. The consultation period closed on 25 June 2024. ESMA received 32 responses, 7 of which were confidential. The answers received are available on ESMA’s website2 unless respondents requested otherwise. ESMA sought the advice of the SMSG established under Article 37 of the ESMA Regulation. Contents Sections 2 to 3 set out the feedback statements relating to i) the guidelines on certain aspects of the suitability requirements and the periodic statement for portfolio management and ii) the guidelines on the policies and procedures, including the rights of clients, providing transfer services for crypto-assets, which were both included in the aforementioned ESMA public consultation. Section 4 contains the Annexes. Annex I contains the cost-benefit analysis. Annex II sets out the advice of the SMSG. Annex III contains the full text of the guidelines on certain aspects of the suitability requirements and format of the periodic statement for portfolio management activities. Annex IV contains the guidelines on the procedures and policies, including the rights of clients, in the context of transfer services for crypto-assets. Next Steps The two sets of guidelines in Annex III and IV will be translated into the official EU languages and published on ESMA’s website. The publication of the translations in all official languages of the EU will trigger a two-month period during which NCAs must notify ESMA whether they comply or intend to comply with the guidelines. 2 See: https://www.esma.europa.eu/press-news/consultations/consultation-technical-standards-specifying-certain-requirementsmica-3rd#responses
Article 81(15) of MiCA:
ESMA shall, by 30 December 2024, issue guidelines in accordance with Article 16 of Regulation (EU) No 1095/2010 specifying:
[…]
(b) the information referred to in paragraph 8; and (c) the format of the periodic statement referred to in paragraph 14 2 Aspects of the suitability requirements applicable to the provision of advice and portfolio management in cryptoassets and the format of the periodic statement referred to in Article 81(14) of MiCA
2.1 Background and legal basis
Legal background
Suitability assessment
Periodic statement for portfolio management services
3. Under Article 81(14) of MiCA, crypto-asset service providers providing the service of
portfolio management of crypto-assets shall provide to their clients periodic statements of the portfolio management activities carried out on their behalf.
4. Article 81(15)(c) of MiCA gives mandate to ESMA to issue guidelines on the format of
the periodic statement referred to in Article 81(14) of MiCA.
Background
Suitability assessment
5. ESMA, in accordance with the mandate it has received under Article 81(15)(b) addresses
the information that crypto-asset service providers shall collect from clients in the guidelines presented in Annex III. ESMA is however of the view that further aspects of the suitability requirements under MiCA are worthy of guidance to ensure a consistent and harmonised application of the requirements related to the suitability assessment, so as to strengthen investor protection, a key objective for ESMA. ESMA therefore is complementing the guidelines issued on the basis of the mandate in Article 81(15) of MiCA by own-initiative guidelines in the same area, based on Article 16(1) of the ESMA Regulation.
6. Hence, the draft guidelines also deal with topics such as the criteria for the assessment
of client’s knowledge and experience, the importance of the information provided to clients about the suitability assessment and the necessary arrangements to ensure the suitability of an assessment.
7. In addition, ESMA has taken the ESMA Guidelines on certain aspects of the MiFID II
suitability requirements3 (the “MiFID II guidelines”) as a basis for the draft guidelines in the CP. This is because the MiCA suitability requirements obey to the same principles as, and are similar to, the suitability requirements provided by MiFID II, in relation to which ESMA has built extensive guidance.
8. ESMA is of the view that some principles provided in the MiFID II guidelines should apply
to market participants providing advice or portfolio management services, be it in relation to financial instruments (under MiFID II) or crypto-assets (under MiCA). Clients should also benefit from the same level of protection when they invest in financial instruments and/or in crypto-assets, especially as such services may be provided by the same entity engaging in activities related to both categories of investment products. 3 Available here.
ESMA is of the view that such approach is in line with MiCA as the suitability
requirements provided in MiCA are almost identical to the MiFID II requirements, although less detailed.
For the purpose of the draft guidelines presented in the CP, ESMA however considered
and adapted the MiFID II guidelines through the prism of crypto-assets markets. Periodic statement for portfolio management services
The periodic statement for portfolio management services shall include a fair and
balanced review of the activities undertaken and of the performance of the portfolio during the reporting period, an updated statement of how the activities undertaken meet the preferences, objectives and other characteristics of the client, as well as an updated information on the suitability assessment referred to in paragraph 1 or its review under paragraph 12.
This periodic statement is to be provided at least every 3 months, unless the client has
access to an online system where up-to-date valuations of the client’s portfolio and updated information on the suitability assessment referred to in paragraph 1 can be accessed. The crypto-asset service provider must however have evidence that the client has accessed a valuation at least once during the relevant quarter.
The legal mandate under Article 81(15)(c) of MiCA requires ESMA to issue guidelines
further specifying the format of the periodic statement for portfolio management services (referred to in Article 81(14) of MiCA). Article 81(14) of MiCA already provides that the periodic statement shall be provided in an electronic format. ESMA considered that further aspects related to the format of the periodic statement should be further clarified (Guideline 1 of the draft guidelines in the CP).
In addition, ESMA considered that other aspects pertaining to the periodic statement for
portfolio management services, which are not addressed by the mandate in Article 81(15)(c) of MiCA, may also benefit from guidance, especially since the obligation for crypto-asset service providers offering portfolio management services to provide such statement is entirely new.
A similar requirement also applies under the MiFID II framework to investment firms
providing portfolio management services and the MiFID II framework regulates additional aspects in comparison to Article 81(14) of MiCA. Besides, the same entities may be providing portfolio management services under MiCA and MiFID II. For consistency purposes between the two regimes, it may thus be appropriate to provide further guidance under MiCA to ensure consistency between the two regimes, when this is possible.
On this basis, ESMA decided to draw on the existing MiFID II requirements to also
provide further guidance in relation to the periodic statement for portfolio management services to be provided under MiCA.
2.2 Feedback to the consultation
2.2.1 Suitability assessment
The point that seemed to raise the most comments and objections was that the draft
guidelines in the CP took the view that there is no safe crypto-assets. Many respondents disagreed with this statement. Some objected that this could not be said for assetreferenced tokens and electronic money tokens.
Asset-referenced tokens are crypto-assets designed to be more stable as they are
backed by a specific pool of underlying assets (called reserve of assets under MiCA), including fiat currencies, and are meant to be maintaining a stable value thanks to that reserve of assets. Electronic money tokens also purport to maintain a stable value by referencing the value of one official currency. In addition, both asset-referenced tokens and electronic money tokens are subject to more stringent requirements attached to their issuance and their issuers are subject to authorisation requirements.
ESMA agrees that asset-referenced tokens and electronic money tokens should,
generally, be considered safer than crypto-assets other than asset-referenced tokens and electronic money tokens. This is because they are backed by a reserve of assets, including fiat currencies, and should therefore have reduced volatility. They are also more scrutinised by national competent authorities which should reduce the risk of mismanagement.
Consequently, ESMA amended the guidelines attached hereto in Annex III so as to
remove this statement.
Q8: Do you agree with ESMA’s approach regarding consistency between the MiCA and MiFID II suitability regimes? If you think that the two regimes should diverge, where and for which reasons?
The vast majority of respondents, including the SMSG, agreed with the approach taken
by ESMA to have consistency between the MiCA and MiFID II regimes with respect to the suitability assessment. Only 3 respondents strongly disagreed with this approach – 2 of which are significant crypto-asset services firms – and argued instead for a lighter regime under MiCA for a variety of reasons such as: crypto-asset service providers are newly regulated actors and should thus benefit from a more gradual and proportional approach, or crypto-assets are not as varied as financial instruments under MiFID II and,
consequently, the suitability assessment need not be as thorough as required under MiFID II.
22. The MiCA and MiFID II suitability regimes are based on the same core principles. Article
81(8) of MiCA makes it clear that the same factors must be considered when conducting a suitability assessment under MiCA as under MiFID II. These include the client’s knowledge and experience in investments (including crypto-assets), their investment objectives (including risk tolerance), their financial situation and ability to bear losses, and their basic understanding of the risks associated with purchasing crypto-assets.
23. Therefore, all the information required by Article 81(8) of MiCA must be collected, and
the suitability of a crypto-asset should be evaluated based on all these factors before a crypto-asset service provider can present it as suitable for the client or invest in it on their behalf, as part of portfolio management services.
24. Co-legislators introduced some proportionality and a more flexible regime in MiCA, which
does not impose appropriateness requirements, unlike MiFID II. Nevertheless, when the suitability requirements apply, a full suitability assessment must be conducted before a crypto-asset can be deemed suitable for the client.
25. On this basis as well as the largely positive feedback received, ESMA confirmed the
approach adopted in the CP in the guidelines attached hereto as Annex III.
26. ESMA also noted, based on the responses received, that there seems to be some
confusion or misunderstanding, at least for certain actors, as to the scope and how the suitability assessment works. One respondent also expressed concerns relating to the unclarity of the definition of advice under MiCA.
27. ESMA would like to clarify that the requirement to conduct a suitability assessment is
only required where a crypto-asset service provider provides advice on crypto-assets or portfolio management on crypto-assets. There is no such requirement for other cryptoasset services. Therefore, where crypto-asset service providers do not want to have to carry out a suitability assessment, they should ensure that they cannot be regarded as providing advice or portfolio management services on crypto-assets.4 However, if they are providing advice, the suitability assessment should be conducted in every instances, even for occasional advice.
28. Lastly, one respondent also argued that the suitability assessment under MiCA should
be lighter than the suitability assessment under MiFID II because there are many 4 Although issued in relation to investment advice on financial instruments under the MiFID II framework, the following supervisory briefing may provide some helpful guidance on the circumstances where advice is provided: ESMA Supervisory Briefing on understanding the definition of advice under MiFID II.
categories of financial instruments under MiFID II whilst crypto-assets are more homogeneous.
29. ESMA fundamentally disagrees with such interpretation. While MiCA indeed refers to
only 3 categories of crypto-assets (asset-referenced tokens (ARTs), electronic money tokens (EMTs) and other crypto-assets that are not ARTs and EMTs), the suitability assessment applies in any case to the individual crypto-asset/transaction and the risks it carries. Q9: Do you think that the draft guidelines should be amended to better fit crypto-assets and the relevant crypto-asset services? In which regard? Please justify your answer.
30. Many respondents, even those agreeing with ESMA’s overall approach, were of the view
that the guidelines should be amended to better fit crypto-assets. Many, however, did not specify how. Understanding of the underlying technology and risks associated (Guideline 3)
31. Some respondents suggested to include in the guidelines the requirement that, as part
of the assessment of a client’s knowledge and experience, crypto-asset service providers should also collect information and assess whether the client understands the underlying technology and risks associated with it (for instance, risk of transferring crypto-assets to the wrong address, hacking risks).
32. ESMA would like to point out that draft Guideline 3, paragraph 52, second bullet point, in
the CP already included wording to the effect that crypto-asset service providers should ensure that the information regarding a client’s or potential client’s knowledge and experience in investing, including in the crypto-asset field, includes whether the client understands distributed ledger technology, on which crypto-assets are based, and the risks inherent to it. ESMA, however, amended paragraph 34 of Guideline 3 in Annex III to include examples of risks inherent to the underlying technology. Good practice in relation to environmental, social and governance (ESG) factors (Guideline 2)
33. Many respondents disagreed with the inclusion in the draft guidelines in the CP of the
good practice relating to ESG factors (paragraph 27 of Guideline 2 (Arrangements necessary to understand clients) in the CP). As previously explained in the CP, the MiFID II guidelines were reviewed recently to integrate new obligations relating to sustainability preferences into the suitability requirements under MiFID II.5 In contrast with MiFID II and the MiFID II Delegated Regulation, MiCA does not include an express obligation to 5 Delegated Regulation (EU) 2021/1253 as regards the integration of sustainability factors, risks and preferences into certain organisational requirements and operating conditions for investment firms, which was part of the Commission ‘s Action Plan ‘Financing Sustainable Growth’, published in March 2018.
collect information on clients’ or potential clients’ sustainability preferences. ESMA thus did not include in the draft guidelines in the CP the new additions relating to sustainability preferences that were introduced in the latest version of the MiFID II guidelines.
34. ESMA believes that, while not mandatory, this good practice could be beneficial, as some
clients may be interested in selecting crypto-assets that align more closely with their ESG objectives. Since different crypto-assets may have varying ESG impacts, such criteria could be relevant when conducting suitability assessments, though they are not required. Inconsistencies in the data collected (Guideline 4)
35. Some respondents requested clarifications on circumstances where the data collected,
either under MiCA solely or under MiCA and MiFID II, included inconsistencies.
36. ESMA wishes to highlight that such occurrence is already addressed in the draft
guidelines in the CP in paragraph 55 of draft Guideline 4. Where this happens cryptoasset service providers should “contact the client in order to resolve any material potential inconsistencies or inaccuracies”. Portfolio approach (Guideline 8)
37. A number of respondents also objected to the draft guidelines allowing crypto-asset
service providers providing portfolio management services to assess the suitability of crypto-assets taking into consideration the portfolio of the client as a whole (paragraph 84 of the draft guidelines in the CP).
38. ESMA wishes to clarify that the portfolio approach (that is also permitted under MiFID II)
would actually provide some flexibility to crypto-asset service providers. It consists in evaluating the suitability of a transaction by considering the client’s entire investment portfolio, rather than assessing each investment in isolation. It is a possibility but not an obligation. Paragraph 84 of draft Guideline 8 in the CP makes this clear: “When conducting a suitability assessment, a crypto-asset service provider providing the service of portfolio management of crypto-assets […] On the other hand, with regard to the client’s financial situation and investment objectives, the suitability assessment about the impact of the crypto-asset(s) and transaction(s) can be done at the level of the client’s portfolio as a whole” [emphasis added] and “When a crypto-asset service provider conducts a suitability assessment based on the consideration of the client’s portfolio as a whole within the service of advice on crypto-assets, this means that, on the one hand, the level of knowledge and experience of the client should be assessed regarding each crypto-asset and risks involved in the related transaction. On the other hand, with regard to the client’s financial situation and investment objectives, the suitability assessment about the impact of the product and transaction can be done at the level of the client’s portfolio” [emphasis added].
portfolio or have access to them and have the power to enter into transactions on behalf of the client.
47. Therefore, it is not clear to ESMA why such respondents raised the aforementioned
concerns, unless there was some misunderstanding as to the scope of portfolio management services on crypto-assets or the requirements to provide a periodic statement (which ESMA clarified above). Therefore, crypto-asset service providers that do provide portfolio management services should certainly be able to provide the valuation of the crypto-assets included in the portfolio, unless such crypto-assets are so illiquid that the valuation is impossible, in which case this should be specified in the periodic statement. Periodicity of reporting
48. Few respondents called for a more frequent reporting (such as monthly), whilst a couple
others said that the reporting every 3 months was not workable and that, in any case, clients are generally able to access an online valuation of their portfolio at any time.
49. ESMA notes that the periodicity of the reporting (every 3 months) does not originate from
the guidelines. It is a requirement of the level 1 text and therefore the guidelines may not change this requirement. However, crypto-asset service providers providing portfolio management services may decide to provide more frequent reporting, such as on a monthly basis. Format of the periodic statement (Guideline 1)
50. As MiCA already provides that the periodic statement shall be provided in an electronic
format, ESMA amended Guideline 1 to clarify that the format mentioned in Guideline 1 should be understood as an electronic format which is also a durable medium. This is to avoid that Guideline 1 may be understood as being inconsistent with the level 1 text by allowing paper forms. Content of the periodic statement
51. Some respondents were of the view that the periodic statement should also include
information on additional topics such as technological and other risk metrics, performance benchmarks, digital delivery and accessibility and other educational content such as market abuse measures.
52. ESMA agrees that crypto-asset service providers may decide to include additional
information in the periodic statement, notably to educate investors on the risks associated with crypto-assets (technological or other). However, the guidelines focus on
further specifying the level 1 requirements and thus may not require that such content always be included since it cannot be read as deriving from the level 1 requirements.
53. One respondent also stated that they did not consider that crypto-asset service providers
shall provide information on the periodic assessment. ESMA would like to clarify that this is a level 1 requirement. Indeed, Article 81(14) requires crypto-asset service providers to include in the periodic statement “an updated information on the suitability assessment referred to in paragraph 1 or its review under paragraph 12”. Article 81(12) of MiCA requires crypto-asset service providers providing advice on crypto-assets or portfolio management of crypto-assets to regularly review for each client the suitability assessment referred to in article 81(1), at least every two years after the initial assessment made in accordance with that paragraph. There should thus be no doubt that such information should be included in the periodic statement.
Article 82(2) of MiCA:
ESMA, in close cooperation with EBA, shall issue guidelines in accordance with Article 16 of Regulation (EU) No 1095/2010 for crypto-asset service providers providing transfer services for crypto-assets on behalf of clients as regards procedures and policies, including the rights of clients, in the context of transfer services for crypto-assets. 3 Guidelines on the procedures and policies, including the rights of clients, in the context of transfer services for crypto-assets
3.1 Background and legal basis
Legal background
54. MiCA sets out a new legal framework which encompasses requirements for the provision
of ten different crypto-asset services. These services include the provision of transfer services for crypto-assets on behalf of clients, defined in Article 3(1)(26) of MiCA as “providing services of transfer, on behalf of a natural or legal person, of crypto-assets from one distributed ledger address or account to another”.
55. With regards to crypto-asset service providers’ policies and procedures in relation to
crypto-asset transfer services, MiCA does not set out any specific requirements. Article 82(2) of MiCA, however, gives a mandate to ESMA to issue, in close cooperation with EBA, guidelines in accordance with Article 16 of the ESMA Regulation (Regulation (EU) No 1095/2010) for crypto-asset service providers providing transfer services for cryptoassets as regards procedures and policies, including the rights of clients. Background
56. The guidelines set out in Annex IV hereto should be read having in mind several
aspects relating to the scope of transfer services for crypto-assets on behalf of clients. Firstly, the European Commission has published Q&A (2071) on the scope of cryptoasset transfer services and, more specifically, on crypto-asset transfers as component of another crypto-asset service or as a separate crypto-asset transfer service.6 6 ESMA Q&A 2071, available here.
irreversible or sufficiently irreversible in case of probabilistic settlement and (ii) information on all charges for the crypto-asset transfer payable by the client.
62. Draft Guideline 2 also clarified that crypto-asset service providers should have
appropriate policies and procedures to ensure that, after the execution of individual crypto-asset transfers, the client is provided with certain minimum information, including:
a reference enabling the client to identify each crypto-asset transfer, the amount and type of crypto-assets transferred or received and all costs relating to the transfer for crypto-assets.
63. Lastly, ESMA proposed to also address in Guideline 2 the information that crypto-asset
service providers should provide to their clients in case a crypto-asset transfer is rejected, returned or suspended (for instance, the reason for the rejection, return or suspension and how to remedy such rejection, return or suspension as well as any costs incurred). Policies and procedures in relation to the execution of transfers of crypto-assets (Guidelines 3 and 4)
64. In the CP, ESMA proposed that crypto-asset service providers offering transfer services
on behalf of clients should implement policies and procedures addressing a minimum set of elements. These should include the conditions for executing crypto-asset transfers (Guideline 3) and the criteria for deciding whether to execute, reject, return, or suspend such transfers (Guideline 4).
65. In draft Guideline 3, ESMA proposed clarifying the minimum set of elements related to
the process of transferring crypto-assets. Draft Guideline 3 specifies that crypto-asset service providers should include in their policies and procedures some key elements of the transfer process. This includes setting maximum execution times based on the crypto-asset transferred, as well as determining the number of block confirmations needed for the transfer of crypto-assets to be irreversible on the DLT network (or sufficiently irreversible in case of probabilistic settlement), for each DLT network.
66. In draft Guideline 4, ESMA proposed clarifying that crypto-asset service providers should
establish, implement and maintain adequate risk-based policies and procedures for determining whether and how to execute, reject, return or suspend a transfer of cryptoassets. Such policies and procedures should particularly take into account the provisions of the TFOR applicable to crypto-asset service providers, as also specified in the EBA Guidelines preventing the abuse of funds and certain crypto-assets transfers for money laundering and terrorist financing purposes8 . 8 Available here.
Liability of the crypto-asset service provider (Guideline 5)
67. Finally, in draft Guideline 5, ESMA proposes clarifying that crypto-asset service providers
should establish, implement, and maintain adequate policies and procedures outlining the conditions under which they would be liable to clients in cases of unauthorized or incorrectly initiated or executed crypto-asset transfers. Given the specific risks associated with crypto-asset transfers, such as hacking or the risk of sending assets to the wrong address, ESMA believes that service providers should have clear policies and procedures regarding their liability to clients.
3.2 Feedback to the consultation
68. The following paragraphs summarize the feedback received to ESMA’s consultation on
the draft guidelines on the policies and procedures for crypto-asset service providers providing transfer services for crypto-assets on behalf of clients. The feedback reflects broad support for ESMA’s approach, though respondents also provided specific suggestions on areas such as pre-contractual disclosures, ex-ante fee transparency, and information on transfer irreversibility. These inputs, alongside ESMA's responses, are detailed below. Q11: Do you agree with the approach taken by ESMA in the draft guidelines for cryptoasset service providers providing transfer services for crypto-assets on behalf of clients as regards procedures and policies, including the rights of clients? Please also state the reasons for your answer.
69. Most respondents, including the SMSG, agreed with the approach taken by ESMA in its
proposed draft guidelines for CASPs providing crypto-asset transfer services on behalf of clients. However, respondents made suggestions on specific elements included in the draft guidelines which are addressed below. On the format of pre-contractual information to clients (Guideline 1) and ex-ante disclosures (Guideline 2)
70. A few respondents suggested that the information required under draft guidelines 1 and
2 should not need to be provided on a durable medium, as currently proposed in the CP. In the view of those respondents, crypto-asset service providers should instead provide this information in an “electronic format” (for example, based on the definition of Article 4(4)(62a) MiFID II). These respondents noted that providing the information in an electronic format would ensure making available the relevant information to clients whilst simultaneously facilitating the disclosure and internal processing of this information for crypto-asset service providers.
of the total charges is attributable to fees charged by the crypto-asset service provider and what part is attributable to the DLT network. This will allow clients to manage their transactions more effectively as they can better understand whether network conditions and their own needs warrant to execute a transfer immediately. On the policies and procedures for pre-contractual information and warning related to the irreversibility of crypto-asset transfers
77. With regards to the disclosure of information related to the irreversibility of crypto-asset
transfers, respondents’ comments addressed mainly two topics: (i) the pre-contractual information on the number of block confirmations needed for the transfer of crypto-assets to be irreversible on the relevant DLT network (or sufficiently irreversible in case of probabilistic settlement) (in paragraph 12 of draft Guideline 1 in the CP) and (ii) the brief and standardised warning as to whether and when the crypto-asset transfer will be irreversible or sufficiently irreversible (in case of probabilistic settlement) (in paragraph 16 of draft Guideline 2 in the CP).
78. Firstly, a few respondents explicitly supported the disclosure of pre-contractual
information on the number of block confirmations needed for the transfer of crypto-assets to be (sufficiently) irreversible on the DLT, as proposed in paragraph 12 of draft Guideline 1). Conversely, a few respondents suggested changes to such pre-contractual information, for example:
service providers to manage expectations and would also have the potential to reduce disputes. Consequently, ESMA is of the view that such pre-contractual information is a key information for clients to understand the reliability and speed of a crypto-asset transfer (e.g. in comparison to other, traditional payment services). Therefore, ESMA maintained the wording included in paragraph 12 of Guideline 1 in the CP to the effect that crypto-asset service providers should have policies and procedures to ensure that the client receives the relevant pre-contractual information related to transfer irreversibility.
80. However, varying levels of blockchain usage may lead to differences in the period of time
needed to obtain the number of block confirmations for irreversibility. Thus, ESMA proposes to include in paragraph 23 of Guideline 1 that the information on the time needed for the transfer to be irreversible on the DLT network should be based on reasonable estimations. It is crucial that such estimations are made on a reasonable basis to provide clients with a realistic time period so that they may decide whether the time is right to execute a transaction. Additionally, ESMA notes that further supervisory convergence work by ESMA and the NCAs could be done in the future, if needed, to set out in more detail what is meant by a “reasonable estimation of the time or block confirmations needed for the transfer to be irreversible on the DLT network”.
81. Secondly, some respondents supported the proposed warning for clients (in paragraph
16 of draft Guideline 2 in the CP) as informing client about the irreversibility conditions helps them understand that a transaction might not be final and secure right after it is submitted. However, a few respondents expressed the view that a warning would not be necessary and that crypto-asset service providers should instead be given more flexibility in providing the relevant information about the restrictions related to crypto-asset transfers to clients.
82. ESMA is of the view that such brief and standardised warning has the potential to further
improve transparency as it may raise clients’ awareness of this topic if not sufficiently flagged through pre-contractual disclosures. In addition, since Guideline 2 only refers to a brief and standardised warning and leaves crypto-asset service providers great flexibility in how they provide it, ESMA found that such warning was proportionate and, consequently, did not amend paragraph 16 of Guideline 2. On the policies and procedures for pre-contractual information related to the means of communication (Guideline 1)
83. A few respondents invited ESMA to provide clarification of the wording “the means of
communication, including the technical requirements for the client’s equipment and software, agreed between the parties for the transmission of information or notifications related to the crypto-asset transfer service”, included in paragraph 12 of draft Guideline 1 in the CP.
included the provision of pre-contractual information to clients, the brief and standardised warning on the irreversibility of transactions and the disclosure of charges and fees related to crypto-asset transfers.
89. With regards to whether the draft guidelines address sufficiently the on- and off-DLT
crypto-asset transfers related risks for clients, a few respondents noted that the features of off-chain transactions (e.g. transfer between clients of the same provider) would differ significantly from on-chain transfers. These respondents were also of the view that the draft guidelines should focus on on-chain transactions and invited ESMA to clarify that these guidelines only refer to on-chain crypto-asset transfers. Additionally, a few respondents noted that the draft guidelines could also address off-chain transfers (in addition to one-chain ones), which would however require some changes to the currently proposed provisions (for example, in Guideline 2).
90. In light of the definition of “providing transfer services for crypto-assets on behalf of
clients” set out in Article 3(1)(26) of MiCA and to focus on the most relevant category of crypto-asset transfers, ESMA notes that these guidelines aim at addressing the risks for clients related to on-DLT crypto-asset transfers. Q13: Are there any additional comments that you would like to raise and/or information that you would like to provide, for example, on whether other relevant points or clients’ rights should be considered?
91. Few respondents replied to this question and their responses were addressed as part of
the feedback statement on questions 11 and 12.
4 Annexes
4.1 Annex I: Cost-benefit analysis
4.1.1.MiCA guidelines on certain aspects of the suitability requirements and the periodic statement for portfolio management Impact of the Guidelines
As per Article 16(2) of Regulation (EU) No 1095/2010, any guidelines developed by
ESMA are to be accompanied by an analysis of ‘the related potential costs and benefits of issuing such guidelines’. Such analysis shall be ‘proportionate in relation to the scope, nature and impact of the guidelines’.
MiCA requires crypto-asset service providers to undertake a suitability assessment when
providing advice on crypto-assets and portfolio management on crypto-assets, the objective being that the crypto-assets advised to the client or invested in on behalf of the client be suitable, taking into consideration the client’s knowledge and experience, investment objectives and financial situation. Similar requirements have existed for a long time for investment firms providing investment advice or portfolio management under MiFID II but the MICA requirements are entirely new for crypto-assets markets. To ensure the adequate implementation of the MiCA requirements by providing clarity to the crypto-assets market, thereby also enhancing investor protection, ESMA is issuing the guidelines attached in Annex III hereto.
In addition, under Article 81(14) of MiCA, crypto-asset service providers providing the
service of portfolio management of crypto-assets shall provide to their clients periodic statements of the portfolio management activities carried out on their behalf.
This periodic statement should include a fair and balanced review of the activities
undertaken and of the performance of the portfolio during the reporting period, an updated statement of how the activities undertaken meet the preferences, objectives and other characteristics of the client, as well as an updated information on the suitability assessment referred to in paragraph 1 or its review under paragraph 12.
This periodic statement is to be provided at least every 3 months, unless the client has
access to an online system where up-to-date valuations of the client’s portfolio and updated information on the suitability assessment referred to in paragraph 1 can be accessed. The crypto-asset service provider must however have evidence that the client has accessed a valuation at least once during the relevant quarter.
Article 81(15)(c) of MiCA gives mandate to ESMA to issue guidelines on the format of
the periodic statement referred to in Article 81(14) of MiCA.
The next paragraphs present the cost-benefit analysis of the main policy options included
in this Final Report on the guidelines on certain aspects of the suitability requirements and periodic statement for portfolio management under Article 81 of MiCA. Problem identification
The MiCA requirements relating to the suitability assessment and periodic statement for
portfolio management are entirely new for crypto-asset service providers. Whilst these requirements are established under MiCA, it is crucial to offer guidance on their application to provide clarity to the market, ensure a harmonised implementation and enhance investor protection.
Moreover, feedback received to the consultation indicates that there is still significant
misunderstanding within the crypto-asset industry regarding the scope and application of the suitability requirements.
Therefore, ESMA considers it essential to clarify how these requirements should be
applied and what is expected of crypto-asset service providers in relation to the suitability standards set by MiCA.
Similar issues arise with the periodic statement requirements for portfolio management,
though to a lesser degree. As a result, ESMA has also chosen to issue guidelines under
Article 81(15)(c) of MiCA, albeit at a higher level.
Policy objectives
The strategic objective of the guidelines is to strengthen investor protection by ensuring
an adequate and harmonised implementation of the suitability requirements under Article 81 of MiCA, as well as to provide clarity on the requirements for the periodic statement for portfolio management services. Baseline scenario
In the absence of guidelines, crypto-asset service providers would need to comply with
the suitability requirements and the requirements applicable to the periodic statement for portfolio management under Article 81 of MiCA without additional guidance. This could result in varied practices across entities and Member States, leading to fragmented investor protection and inefficiencies in regulatory oversight.
As such requirements are entirely new to the crypto-asset industry (or at least, the most
part of it), such guidance is particularly essential.
Options considered and preferred options
15. This section presents the main policy options discussed and the decisions made when
developing the guidelines. The policy options’ respective advantages and disadvantages and the preferred options resulting from this analysis are assessed below. Policy issue 1: Exhaustiveness and extensiveness of the guidelines on the suitability requirements under Article 81 of MiCA
16. The legal mandate under Article 81(15)(b) of MiCA requires ESMA to issue guidelines
further specifying the information that crypto-asset service providers shall obtain from their clients or prospective clients in accordance with Article 81(8) of MiCA: “the necessary information regarding their knowledge of, and experience in, investing, including in crypto-assets, their investment objectives, including risk tolerance, their financial situation including their ability to bear losses, and their basic understanding of the risks involved in purchasing crypto-assets, so as to enable crypto-asset service providers to recommend to clients or prospective clients whether or not the crypto-assets are suitable for them and, in particular, are in accordance with their risk tolerance and ability to bear losses”.
17. ESMA’s mandate under MiCA thus covers the information to be collected from clients or
prospective clients by crypto-asset service providers to perform the suitability assessment.
18. Against this backdrop, ESMA considered 4 policy options with regards to the
exhaustiveness and level of detail of the guidelines set out in Annex III hereto. Option 1a: Focus on the mandate given to ESMA under Article 81(15)(b) of MiCA and remain high level Option 1b: Focus on the mandate given to ESMA under Article 81(15)(b) of MiCA and provide comprehensive guidance Option 1c: Provide guidance on the topic covered by the mandate given to ESMA under
Article 81(15)(b) of MiCA10 and also issue some guidelines11 on other relevant aspects of
the suitability assessment, but remain high level in the guidance provided 10 On the necessary information to be collected by crypto-asset service providers for the purpose of the suitability assessment. 11 Under Article 16(1) of the ESMA Regulation.
Option 1d: Provide guidance on the topic covered by the mandate given to ESMA under
Article 81(15)(b) of MiCA12 and also issue some guidelines13 on other relevant aspects of
the suitability assessment and provide comprehensive guidance.
19. ESMA considered that Options 1a and 1b were inadequate for several reasons:
i) other aspects of the suitability requirements, which are not addressed by the mandate in Article 81(15)(b) of MiCA, also benefit from guidance, especially since the obligation for crypto-asset service providers offering advice or portfolio management services to conduct a suitability assessment is entirely new; ii) there is already extensive guidance available under the MiFID II framework that pertains to similar suitability assessment requirements, and this guidance encompasses a broader range of topics than those covered by the mandate in
Article 81(15)(b) of MiCA;
iii) the same entities may be providing advice and portfolio management services under MiCA and MiFID II, for consistency purposes between the two regimes, it is appropriate to also ensure consistency between the two suitability regimes; iv) in order to avoid regulatory arbitrage between the MiCA and the MiFID II regimes, it is also important to ensure that the two regimes are consistent.
20. ESMA also regarded Option 1c as inadequate because, although the guidance provided
under such option would have been more exhaustive in terms of aspects of the suitability requirements covered, ESMA deems that, for such a complex topic as the suitability assessment, high level guidance is not appropriate. In addition, Option 1c would also not be adequate to ensure consistency between the MiCA and the MiFID II suitability regimes and to avoid regulatory arbitrage.
21. Option 1d, on the other hand, enables ESMA to provide more extensive guidance on the
most essential aspects of the suitability assessment under MiCA. Given that this obligation is new to the crypto-asset industry and that this is a complex topic, it was also important to ensure that the guidance provided was sufficiently detailed to provide clarity to the market and ensure a harmonised implementation as well as enhanced investor protection. Lastly, it ensures consistency between the MiCA and the MiFID II regimes, which is also an important aspect given that the same firms may be providing advice or portfolio management services under the two regimes and/or clients may be using these services under the two regimes as well. It would be confusing for firms and clients if the same requirement (to undertake a suitability assessment) applied differently depending on the type of product advised on or included in the portfolio. 12 On the necessary information to be collected by crypto-asset service providers for the purpose of the suitability assessment. 13 Under Article 16(1) of the ESMA Regulation.
Therefore, Option 1d has been chosen as the preferred option.
Policy issue 2: Exhaustiveness and extensiveness of the guidelines on the suitability requirements under Article 81 of MiCA
Article 81(14) of MiCA requires that crypto-asset service providers providing the service
of portfolio management of crypto-assets shall provide to their clients periodic statements of the portfolio management activities carried out on their behalf. This periodic statement must be provided in an electronic format, shall include a fair and balanced review of the activities undertaken and of the performance of the portfolio during the reporting period, an updated statement of how the activities undertaken meet the preferences, objectives and other characteristics of the client, as well as an updated information on the suitability assessment referred to in Article 81(1) or its review under Article 81(12).
In addition, this periodic statement is to be provided at least every 3 months, unless the
client has access to an online system where up-to-date valuations of the client’s portfolio and updated information on the suitability assessment referred to in Article 81(1) of MiCA can be accessed. The crypto-asset service provider must however have evidence that the client has accessed a valuation at least once during the relevant quarter.
However, the legal mandate under Article 81(15)(c) of MiCA solely requires ESMA to
issue guidelines further specifying the format of the periodic statement for portfolio management services (referred to in Article 81(14) of MiCA).
Against this backdrop, ESMA considered 4 policy options with regards to the range of
topics covered by and the level of detail of the related guidelines set out in Annex III hereto. Option 2a: Focus on the mandate given to ESMA under Article 81(15)(c) of MiCA and remain high level Option 2b: Focus on the mandate given to ESMA under Article 81(15)(c) of MiCA and provide comprehensive guidance, maybe even a template Option 2c: Provide guidance on the topic covered by the mandate given to ESMA under
Article 81(15)(c) of MiCA14 and also issue guidelines15 on other relevant aspects related
to the periodic statement, but remain high level in the guidance provided Option 2d: Provide guidance on the topic covered by the mandate given to ESMA under
Article 81(15)(c) of MiCA16 and also issue guidelines17 on other relevant aspects of the
suitability assessment and provide comprehensive guidance.
14 On the format of the periodic statement.
15 Under Article 16(1) of the ESMA Regulation.
16 On the format of the periodic statement.
17 Under Article 16(1) of the ESMA Regulation.
ESMA considered that Options 2a and 2b were inadequate for several reasons:
i) other aspects pertaining to the periodic statement for portfolio management services, which are not addressed by the mandate in Article 81(15)(c) of MiCA, also necessitate guidance, especially since the obligation for crypto-asset service providers offering portfolio management services to provide such statement is entirely new; ii) the same requirement also applies under the MiFID II framework to investment firms providing portfolio management services and the MiFID II framework regulates additional aspects in comparison to Article 81(14) of MiCA iii) the same entities may be providing portfolio management services under MiCA and MiFID II, for consistency purposes between the two regimes, it may thus be appropriate to provide further guidance under MiCA to ensure consistency between the two regimes.
ESMA also regarded Option 2d as inadequate because, although for the reasons
explained above it is appropriate to cover several aspects linked to the periodic statement, ESMA does not consider that such topic necessarily requires extensive and detailed guidance (such as a template). High level guidance is, in this case, more adequate so as to leave flexibility to crypto-asset service providers as to how they want to present such periodic report.
Therefore, Option 2c has been chosen as the preferred option.
Cost-benefit analysis
Considering the main objectives of these guidelines (extensively illustrated in the
foregoing), the following paragraphs aim at explaining the benefits and costs of the key policy choices that are presented for consultation.
It should be preliminary observed that since the requirements on the suitability
assessment and periodic statement for portfolio management are provided under MiCA, the impact of the proposed guidelines should be considered having in mind those legal provisions that they support. While crypto-asset service providers will likely incur certain costs for implementing these guidelines, they will also benefit from the increased legal certainty and the harmonised application of the requirements across Member States. Investors would in turn benefit from an improved suitability of the crypto-assets that are being recommended or purchased on their behalf as well as an increased transparency. The guidelines should also facilitate competent authorities’ efforts to improve the overall compliance with MiCA requirements, thereby increasing investors’ confidence in the crypto industry. Costs
The main costs that crypto-asset service providers are likely to incur stem from the initial
one-off and ongoing costs related to procedural and organisational arrangements necessary for the implementation of the guidelines where crypto-asset service providers provide advice on crypto-assets and/or portfolio management on crypto-assets. Such costs may include initial and ongoing IT costs, HR costs to ensure that staff providing advice and portfolio management services is appropriately qualified and is able to comply with the relevant obligations of the crypto-asset service provider under MiCA and costs linked to the collection of information from clients and prospective clients.
For national competent authorities, these guidelines will lead to limited ongoing costs for
the supervision of crypto-asset service providers to ensure compliance (or not) with the guidelines. National competent authorities might also have to slightly extent their resources applied to the supervision of CASPs in light of the relevant MiCA requirements. Benefits
In terms of benefits, the guidelines will promote the convergence of national competent
authorities’ supervisory activities, thereby contributing to one of the main objectives of MiCA, to foster investor protection. The guidelines also promote fair competition between crypto-asset service providers independently of the home Member State.
Clients benefit from the guidelines due to the improved suitability of the crypto-assets
recommended to them or purchased on their behalf, as well as the improved transparency related to the periodic statement for portfolio management services. Clients with mixed portfolios (financial instruments and crypto-assets) also benefit from the consistency of the two regimes.
Finally, crypto-asset service providers also benefit from the guidelines as they provide
clarity as to how to apply the MiCA suitability requirements and those relating to the periodic statement for portfolio management. The resulting surge in the suitability of the crypto-assets recommended to or purchased on behalf of clients as well as the increased transparency should therefore enhance clients’ trust in the crypto-asset industry. In addition, entities providing advice or portfolio management services under both the MiCA and the MiFID II regimes, will benefit from the consistency between the two regimes.
Considering what has been illustrated above, ESMA believes that the overall costs
associated with the implementation of the guidelines set out in Annex III are fully justified by the objectives described above.
Table: costs and benefits
Stakeholder groups affected
Costs Benefits
Cryptoasset service providers
Initial one-off and ongoing costs related to procedural and organisational arrangements necessary for the implementation of the guidelines (IT costs, HR costs, costs related to the collection of information from clients…) Enhanced clients’ trust in the cryptoasset industry. Consistency between the MiFID II and MiCA regimes for entities operating under both frameworks. Competent authorities Limited ongoing cost of supervision to ensure that crypto-asset service providers have properly implemented the guidelines. Slight extension of their resources dedicated to the supervision of the MiCA framework may be needed. Enhanced consistency of supervision of the MiCA requirements related to the suitability assessment and the periodic statement for portfolio management. Safer crypto-asset market and mitigation of investor detriment due to the improved suitability of the cryptoassets recommended or purchased on behalf of clients and the improved transparency. Clients None Improved suitability of the crypto-assets recommended or purchased on their behalf. Improved transparency. Consistency between the MiFID II and MiCA regimes for clients with mixed portfolios.
4.1.2 MiCA guidelines on the policies and procedures, including the
rights of clients, for transfer services for crypto-assets Impact of the guidelines under the first subparagraph of Article 82(2) of MiCA
38. As per Article 16(2) of Regulation (EU) No 1095/2010, any guidelines developed by
ESMA are to be accompanied by an analysis of ‘the related potential costs and benefits of issuing such guidelines’. Such analysis shall be ‘proportionate in relation to the scope, nature and impact of the guidelines’.
39. MiCA sets out a new legal framework which encompasses requirements for the provision
of ten different crypto-asset services. These services include the provision of transfer services for crypto-assets on behalf of clients defined in Article 3(1)(26) of MiCA as “providing services of transfer, on behalf of a natural or legal person, of crypto-assets from one distributed ledger address or account to another”. Article 82(2) of MiCA gives a mandate to ESMA to issue, in close cooperation with EBA, guidelines in accordance with Article 16 of Regulation (EU) No 1095/2010 for crypto-asset service providers providing transfer services for crypto-assets as regards procedures and policies, including the rights of clients.
40. The next paragraphs present the cost-benefit analysis of the main policy options included
in this Final Report on the guidelines for providing transfer services for crypto-assets on behalf of clients under Article 82 of MiCA. Problem identification
41. Crypto-asset transfers play a crucial role in the practical utilisation of these assets,
allowing clients to manage and deploy their crypto-assets in line with their specific needs and investment strategies. For instance, they may transfer crypto-assets to a wallet for secure storage or move then to an exchange for trading and liquidity purposes. At the same time, crypto-asset transfers also present potential challenges: (i) the functionality and risks associated with crypto-assets and the underlying DLT technology are often less familiar to many investors compared to traditional financial instruments like shares or ETFs, (ii) certain characteristics of crypto-asset transfers, such as their irreversibility, pose risks for investors, potentially leading to adverse outcomes (such as the loss of crypto-assets, if transferred to the incorrect address or wallet).
42. To address these challenges and ensure a higher level of investor protection and
harmonisation, MiCA gives ESMA a mandate, in close cooperation with the EBA, to issue guidelines for crypto-asset service providers providing transfer services for crypto-assets on behalf of clients. These guidelines should address procedures and policies, including the rights of clients, in the context of transfer services for crypto-assets. By establishing clear standards, ESMA seeks to ensure that crypto-asset service providers adopt robust
policies and procedures to minimize errors, protect clients from avoidable losses, and build trust in the broader crypto-asset ecosystem. Policy objectives
43. The strategic objective of the guidelines is to strengthen investor protection and enhance
the safety of crypto-assets markets by:
a) ensuring that crypto-asset service providers implement the necessary minimum policies and procedures for conducting transfer services for crypto-assets on behalf of clients; and b) promoting client awareness of the terms and conditions governing the execution of crypto-asset transfer services. Baseline scenario
44. In the absence of any guidance from ESMA on the policies and procedures for cryptoasset service providers providing transfer services of crypto-assets, the risks associated
with crypto-asset transfers would likely become more prominent. Without clear regulatory expectations, crypto-asset service providers may lack or adopt inconsistent or inadequate policies and procedures. This lack of standardization could result in a fragmented market where service quality and risk management vary widely across providers, leading to a higher likelihood of errors, fraud, or loss of crypto-assets during transfers.
45. Investors, especially those less familiar with the complexities of blockchain technology
and crypto-asset transfers, would face heightened risks. In the absence of any guidance, many crypto-asset service providers may not provide sufficient information or education to clients regarding the specific risks involved, such as the consequences of sending assets to incorrect addresses or the difficulty of recovering lost funds. This could erode investor confidence in crypto-asset markets, leading to lower participation and potentially hampering the growth of the sector.
46. Moreover, the lack of regulatory guidance may also undermine market integrity. Without
a clear framework for best practices, crypto-asset service providers might not prioritize transparency, security, or proper risk management, resulting in vulnerabilities that could be exploited by bad actors. Options considered and preferred options
47. This section presents the main policy options discussed and the decisions made when
developing the guidelines. The policy options’ respective advantages and disadvantages and the preferred options resulting from this analysis are assessed below.
Policy issue 1: Exhaustiveness and level of detail of the policies and procedures related to transfer services for crypto-assets
48. The legal mandate under Article 82 requires ESMA to issue guidelines on the policies
and procedures, including the rights of clients, of crypto-asset service providers providing crypto-asset transfer services on behalf of clients. Against this backdrop, ESMA considered 2 policy options with regards to the exhaustiveness and level of detail of the guidelines set out in Annex IV hereto. Option 1a: Focus on the topics relating to the most prominent challenges presented by transfers for crypto-assets on behalf of clients and provide guidance on such topics to be included in the procedures and policies, without being overly comprehensive Option 1b: Provide exhaustive and detailed guidance on all topics that crypto-asset service providers should cover in their policies and procedures on crypto-asset transfer services.
49. At this stage, ESMA considered that Option 1b was not representing a balanced
approach, based on the (current) perceived level of issues raised by crypto-asset transfers and the efforts that would have been required by crypto-asset service providers to align their policies and procedures with very detailed and prescriptive guidelines.
50. Option 1a, on the other hand, enables ESMA to focus on the topics that seem the most
essential to tackle at this stage (such as information to clients, irreversibility of cryptoasset transfers) whilst giving crypto-asset service providers enough guidance and sufficient flexibility when covering such topics in their policies and procedures. Option 1a thus represents, at this stage, a balanced approach.
51. Therefore, Option 1a has been chosen as the preferred option. It is, however, without
prejudice to market developments and the possible revision of the guidelines attached hereto in Annex IV so as to adopt a more prescriptive and exhaustive approach if needed. Cost-benefit analysis
52. The guidelines are expected to result in limited costs for crypto-asset service providers
and national competent authorities, while also providing benefits for clients, crypto-asset service providers and national competent authorities. Costs
53. The main costs that crypto-asset service providers are likely to incur stem from (i) the
initial one-off costs related to the implementation of the guidelines in their procedures and policies related to the provision of crypto-asset transfer services and (ii) limited
ongoing costs of keeping the relevant information related to the guidelines updated in their procedures and policies.
54. For national competent authorities, these guidelines will lead to limited ongoing costs for
the supervision of crypto-asset service providers to ensure compliance (or not) with the guidelines. National competent authorities might also have to slightly extent their resources applied to the supervision of CASPs in light of the relevant MiCA requirements. Benefits
55. In terms of benefits, the guidelines will promote the convergence of national competent
authorities’ supervisory activities, thereby contributing to one of the main objectives of MiCA, to foster investor protection. The guidelines also promote fair competition between crypto-asset service providers independently of home Member State, as the provisions set out more specific information to better inform clients about the functioning, risks and costs of crypto-asset transfer services.
56. Clients benefit from the guidelines through receiving relevant information about
functioning, risks and costs, facilitating their choice of the most suitable crypto-asset transfer services.
57. Finally, crypto-asset service providers also benefit from the guidelines as they aim to
help them to better inform clients, manage expectations and should therefore enhance clients’ trust in the recently emerged crypto-asset transfer services.
Table: costs and benefits
Stakeholder groups affected
Costs Benefits
Cryptoasset service providers
Limited, due to (i) initial one-off costs related to the implementation of the guidelines in their policies and procedures on the provision of crypto-asset transfer services and (ii) ongoing costs for keeping the relevant guidance updated. The costs incurred should be particularly limited as it is expected that crypto-asset service provider already have policies and procedures on crypto-asset transfer services. The implementation costs would thus be limited to bring the current policies and procedures in line with the guidelines. Better information of clients. Managing clients’ expectations. Enhanced clients’ trust in crypto-asset transfer services. Competent authorities Limited ongoing cost of supervision to ensure that crypto-asset service providers have properly implemented the guidelines on crypto-asset transfer services. Slight extension of their resources dedicated to the supervision of the MiCA framework may be needed. Enhanced consistency of supervision of the MiCA requirements related to crypto-asset transfer services. Safer crypto-asset market, mitigation of investor detriment due to problems with crypto-asset transfer services. Clients None Receive better information about functioning and risks of crypto-asset transfer services, allowing them to choose the most suitable crypto-asset transfer service.
only when the person professionally arranging or executing transactions (PPAET) shows – e.g., based on empirical evidence or establishing appropriate policies and procedures – that its activity does not imply risks of market abuse at a material level. The SMSG also considers that it would be helpful to clarify whether the monitoring and detection of market abuse for cryptos requires special mechanisms and tools with respect to the mechanisms and tools usually applied to securities markets. Outsourcing and systemic risk. Article 3.4 of the draft RTS on market abuse sets out the requirements for the outsourcing of the prevention, monitoring and detection activities. To ensure that PPAETs remain in control of those functions, the draft RTS sets out some necessary requirements, such as the existence of a written agreement between the parties and the retention of access to the relevant information and the necessary expertise so the PPAET may assess the work conducted by the delegated party. The SMSG believes that the outsourcing of such sensitive tasks should also consider systemic risks (e.g., when several PPAETs delegate the same provider). The relevant authorities may need to monitor the competition and concentration levels of the market related to the outsourced activities. Coordination procedures between competent authorities. Article 11 of the draft RTS on market abuse requires the competent authority suspecting a case of cross-border market abuse to “report the status of its preliminary assessment to the other competent authorities concerned”. However, there is no expected timing for this reporting activity to occur. To avoid ambiguity and to foster convergence, the SMSG believes that it would be useful to specify a precise timing for the exchange of information. By contrast, the receiving competent authorities shall share information about the existence of any supervisory activity or criminal investigation on the same case “without undue delay”. It appears that an asymmetry in the expected timing exists between the NCA originating the coordination activity and the NCA receiving the preliminary assessment. The draft RTS also foresees the possibility that competent authorities inform ESMA of the start of an investigation or an enforcement activity. The SMSG believes that, instead of being a possibility, ESMA should always be informed in order to have a comprehensive view of the ongoing market abuse investigations in the EU. Suitability requirements and the understanding of the risks. Article 81(15) of MiCA gives ESMA a mandate to issue guidelines on suitability requirements under MiCA, including the information that crypto-asset service providers (CASPs) shall obtain from their clients or prospective clients. In this respect, Article 81(8) of MiCA requires CASPs to obtain information – among other things – about their basic understanding of the risks involved in purchasing crypto-assets. The SMSG believes that, for reasons related to both
investor protection and level-playing field, regulation for crypto-assets should be as similar as possible to securities regulation and only differ if this is warranted by differences in product characteristics or risk
2 Background
iii. transfer services for crypto-assets20;
iv. systems and security access protocols21
.
2. In this Advice, the SMSG provides its views on specific questions raised by ESMA in the
consultation paper as well as comments on more general issues that are related to the topics discussed in this consultation.
3. SMSG opinions and comments on market abuse
[…]
4. SMSG opinions and comments on suitability
4.1 General approach and the understanding of the risks
18. The assessment of suitability is an important investor protection requirement under
MiCA. It applies to the provision of advice on crypto-assets and portfolio management of crypto-assets.
19. Article 81(15) of MiCA gives ESMA a mandate to issue guidelines on the following
aspects of the suitability requirements under MiCA: (i) the criteria for the assessment of client’s knowledge and competence; and (ii) the information that crypto-asset service providers shall obtain from their clients or prospective clients regarding their knowledge of, and experience in, investing (including in crypto-assets), their investment objectives (including risk tolerance), their financial situation (including their ability to bear losses), and their basic understanding of the risks involved in purchasing crypto-assets, so as to enable crypto-asset service providers to recommend to clients or prospective clients whether or not the crypto-assets are suitable for them and, in particular, are in accordance with their risk tolerance and ability to bear losses.
20. The SMSG believes that, for reasons related to both investor protection and level-playing
field, regulation for crypto-assets should be as similar as possible to securities regulation and only differ if this is warranted by differences in product characteristics or risk between MiFID financial instruments and MiCA crypto-assets. With this objective in mind, the requirement of a ‘basic’ understanding of the risks involved in purchasing crypto-assets – although included in the MiCA regulation – appears to be a source of concern in terms 20 The consultation paper includes draft guidelines on procedures and policies, including the rights of clients, in the context of transfer services for crypto-assets. 21 The consultation paper includes draft guidelines on maintenance of systems and security access protocols in conformity with appropriate Union standards.
of investor protection. The SMSG also notes that the analogous requirement in the MiFID framework refers to understanding (i.e., without ‘basic’)22 .
4.2 Sustainability preferences
21. ESMA chose to largely base the MiCA suitability guidelines on the MiFID II guidelines.
This is because the MiCA suitability requirements are also largely based on the MiFID II suitability requirements.
22. However, the two sets of guidelines differ in relation to sustainability preferences. The
MiFID II guidelines were reviewed recently to integrate new obligations relating to sustainability preferences into the suitability requirements under MiFID II (Delegated Regulation (EU) 2021/1253). In contrast with MiFID II and the MiFID II Delegated Regulation, MiCA does not include an express obligation to collect information on clients’ or potential clients’ sustainability preferences.
23. ESMA thus did not include in the draft guidelines presented in the third MiCA consultation
paper the new additions relating to sustainability preferences that were introduced in the latest version of the MiFID II guidelines. However, paragraph 27 of Guideline 2 (Arrangements necessary to understand clients) of the draft guidelines suggests that, at this stage, it could be a good practice for crypto-asset service providers to collect information about the preferences on environmental, social and governance factors of the client or potential client.
24. The SMSG highlights that, as the level 1 texts for both MiFID II and MiCA are aligned,
level 3 texts should also be aligned for the following reasons. Both the MiFID II and MiCA level 1 texts refer to the need to assess clients’ “investment objectives, including risk tolerance”, without referring to sustainability preferences. In respect of MiFID II, the level 2 Delegated Regulation (EU) 2017/565 has introduced a definition of sustainability preferences (art. 2(7)) and develops the requirement to ask information on investment objectives by stating that investment firms should obtain information on clients’ “investment objectives including the client’s risk tolerance and any sustainability preferences” (art. 54(2) a)). In respect of MiCA the Level 1 text did not give a mandate to the Commission to issue a level 2 text in respect of the suitability requirements. The SMSG is of the view that this not a sufficient reason to have different level 3 guidelines since (i) the level 1 texts of MiFID II and MiCA in respect of the suitability test use exactly the same wording (“investment objectives, including risk tolerance”); and (ii) level 2 texts can only supplement or amend non-essential elements of the Level 1 Act (art. 290 TFEU). It is clear that MiFID II Delegated Regulation (EU) 2017/565 has not issued a 22 ESMA guidelines on certain aspects of the MiFID II suitability requirements state in paragraph 23 that “firms should also take reasonable steps to assess the client’s understanding of investment risk as well as the relationship between risk and return on investments”.
new legal rule, but merely clarified how broadly the term “investment objectives” should be interpreted (i.e., also including sustainability preferences). The fact that MiCA does not provide for a Level 2 Delegated Act, does therefore not prevent ESMA to fully align the MiCA guidelines with the MiFID II guidelines in respect of sustainability preferences. From a legal coherence perspective, it would also make more sense to fully align the MiFID II and MiCA suitability guidelines on this point. Nor from a legal perspective, nor on the basis of differences in product characteristics or risks between financial instruments and crypto-assets, the SMSG believes there are any reasons to apply different requirements in relation to sustainability preferences.
5. SMSG opinions and comments on transfer services for
crypto-assets
5.1 General approach and the relations with clients
25. The features of the provision of transfer services of crypto-assets share some similarities
with payment services, regulated under the Directive on payment services in the internal market (“PSD 2”). Therefore, ESMA has drawn on PSD 2 provisions – where relevant – in developing the draft guidelines.
26. The SMSG is in favor of this approach and highlights the need that crypto-asset service
providers set up appropriate policies and procedures to assist their customers, especially when the access to the wallets (or similar services) is only based on keys and pass codes, as it commonly happens for payment services.
This advice will be published on the Securities and Markets Stakeholder Group section of ESMA’s website. Adopted on 21 June 2024 [signed] Veerle Colaert Chair Securities and Markets Stakeholder Group [signed] Giovanni Petrella Rapporteur
4.3 Annex III: Guidelines on certain aspects of the suitability
requirements and format of the periodic statement for portfolio management activities under MiCA 1 Scope Who?
2 Legislative references, abbreviations and definitions
2.1 Legislative references
ESMA Regulation Regulation (EU) No 1095/2010 of the European Parliament and of the Council of 24 November 2010 establishing a European Supervisory Authority (European Securities and Markets Authority), amending Decision No 716/2009/EC and repealing Commission Decision 2009/77/EC23 . MiCA Regulation (EU) 2023/1114 of the European Parliament and of the Council of 31 May 2023 on markets in crypto-assets, and amending Regulations (EU) No 1093/2010 and (EU) 1095/2010 and Directives 2013/36/EU and (EU) 2019/193724 .
2.2 Abbreviations
ESFS European System of Financial Supervision
ESMA European Securities and Markets Authority EU European Union
2.3 Definitions
Suitability assessment The whole process of collecting information about a client and the subsequent assessment by the crypto-asset service provider that a given crypto-asset is suitable for him, based also on the crypto-asset service provider’s solid understanding of the crypto-assets that it can recommend or invest into on behalf of the client. Robo-advice The provision of advice on crypto-assets or portfolio management of crypto-assets (in whole or in part) through an automated or semi-automated system used as a client-facing tool. 23OJ L 331, 15.12.2010, p. 84. 24 OJ L 150, 9.6.2023, p. 40.
3 Purpose
4. These guidelines are based on Article 81(15) of MiCA and Article 16(1) of the ESMA
Regulation. The objectives of these guidelines are to establish consistent, efficient and effective supervisory practices within the ESFS and to ensure the common, uniform and consistent application of the provisions in 81(1), (7), (8), (10), (11), (12) and (14) of MiCA, as relevant.
5. In particular, they aim to promote greater convergence in the application of, and
supervisory approaches to, the MiCA suitability requirements and requirements applicable to the format of the periodic statement to be provided by crypto-asset service providers providing portfolio management of crypto-assets.
6. By identifying a number of important issues as set out in the guidelines below and thereby
helping to ensure that crypto-asset service providers comply with regulatory standards, ESMA anticipates a corresponding strengthening of investor protection.
4 Compliance and reporting obligations
4.1 Status of the guidelines
7. In accordance with Article 16(3) of the ESMA Regulation, competent authorities and
financial market participants must make every effort to comply with these guidelines.
8. Competent authorities to which these guidelines apply should comply by incorporating
them into their national legal and/or supervisory frameworks as appropriate, including where particular guidelines are directed primarily at financial market participants. In this case, competent authorities should ensure through their supervision that financial market participants comply with the guidelines.
4.2 Reporting requirements
9. Within two months of the date of publication of the guidelines on ESMA’s website in all
EU official languages, competent authorities to which these guidelines apply must notify ESMA whether they (i) comply, (ii) do not comply, but intend to comply, or (iii) do not comply and do not intend to comply with the guidelines.
10. In case of non-compliance, competent authorities must also notify ESMA within two
months of the date of publication of the guidelines on ESMA’s website in all EU official languages of their reasons for not complying with the guidelines.
11. A template for notifications is available on ESMA’s website. Once the template has been
filled in, it shall be transmitted to ESMA.
12. Financial market participants are not required to report whether they comply with these
guidelines.
5 Guidelines on certain aspects of the suitability requirements under MiCA
5.1 Information to clients about the purpose of the suitability assessment and its
scope (Guideline 1)
Relevant legislation: Articles 66(1) and (2) and 81(1), (8), (10) and (11) of MiCA.
13. Crypto-asset service providers should inform their clients clearly and simply about the
suitability assessment and its purpose which is to enable the crypto-asset service provider to act in the client’s best interest. This should include a clear explanation that it is the crypto-asset service provider’s responsibility to conduct the assessment, so that clients understand (i) the reason why they are asked to provide certain information, (ii) the importance that such information is up-to-date, accurate and complete and (iii) that, without such information, the crypto-asset service provider will not recommend cryptoasset services or crypto-assets, nor begin the provision of portfolio management of crypto-assets. Such information may be provided in a standardised format.
14. Information about the suitability assessment should help clients understand the purpose
of the requirements. It should encourage them to provide up-to-date, accurate and sufficient information about their knowledge, experience, investment objectives (including their risk tolerance) and financial situation (including their ability to bear losses). Crypto-asset service providers should highlight to their clients that it is important to gather complete and accurate information so that the crypto-asset service provider can recommend suitable crypto-assets or crypto-asset services to the client. Without this information, crypto-asset service providers cannot provide advice on crypto-assets or portfolio management of crypto-assets.
15. It is up to the crypto-asset service provider to decide how they will inform their clients
about the suitability assessment. The format used should however enable controls to check if the information was provided.
16. Crypto-asset service providers should not create any ambiguity or confusion about their
responsibilities in the process when assessing the suitability of crypto-asset services or crypto-assets. Notably, crypto-asset service provider should avoid stating, or giving the impression, that it is the client who decides on the suitability of the investment or the service, or that it is the client who establishes which crypto-assets or crypto-asset services fit his own risk profile. For example, crypto-asset service providers should avoid indicating to the client that a certain crypto-asset is the one that the client chose as being suitable, or requiring the client to confirm that a crypto-asset or crypto-asset service is suitable.
17. Any disclaimers (or other similar types of statements) aimed at limiting the crypto-asset
service provider’s responsibility for the suitability assessment would not in any way impact the characterisation of the crypto-asset service provided in practice to clients nor the assessment of the crypto-asset service provider’s compliance to the corresponding
requirements. For example, when collecting clients’ information required to conduct a suitability assessment (such as their investment horizon/holding period or information related to risk tolerance), crypto-asset service providers should not claim that they do not assess the suitability.
18. In order to address potential gaps in clients’ understanding of the crypto-asset services
provided through robo-advice, crypto-asset service providers should inform clients, in addition to other required information, on the following:
and simply that the purpose of answering them is to help assess clients’ attitude to risk (risk profile), and therefore whether crypto-assets services or the crypto-assets are suitable for them (and, if suitable, which types and risks are attached to them).
25. Information necessary to conduct a suitability assessment includes different elements
that may affect, for example, the analysis of the client’s financial situation (including his ability to bear losses) or investment objectives (including his risk tolerance). Examples of such elements are the client’s:
particularly important for the correct assessment of the client’s knowledge and experience. Information collected by crypto-asset service providers about a client’s knowledge and experience should be considered altogether for the overall appraisal of his understanding of the products and services and of the risks involved in the transactions recommended or in the management of his portfolio.
29. It is also important that crypto-asset service providers appraise the client’s understanding
of basic financial notions such as investment risk (including concentration risk) and riskreturn trade off. To this end, crypto-asset service providers should consider using indicative, comprehensible examples of the levels of loss/return that may arise depending on the level of risk taken and should assess the client’s response to such scenarios.
30. As part of the assessment of a client’s knowledge and experience, crypto-asset service
providers should ensure that the client understands crypto-assets specifically and, in particular, the risks inherent to the use of distributed ledger technology (for instance, cybertheft, hacks, loss or destruction of private keys), on which crypto-assets are based.
31. Crypto-asset service providers should design their questionnaires so that they are able
to gather the necessary information about their client. This is particularly relevant for crypto-asset service providers providing robo-advice services given the limited human interaction. In order to ensure their compliance with the requirements concerning that assessment, crypto-asset service providers should take into account factors such as:
5.3 Extent of information to be collected from clients (proportionality) (Guideline 3)
Relevant legislation: Article 81(1), (8) and (10) of MiCA
32. Before providing advice on crypto-assets or portfolio management of crypto-assets,
crypto-asset service providers need to collect all ‘necessary information’26 about the client’s knowledge and experience, financial situation, investment objectives and their basic understanding of the risks involved in purchasing crypto-assets, giving due consideration to the nature and extent of the service provided. The extent of ‘necessary’ information may vary and crypto-asset service providers should determine the extent of the information to be collected from clients in light of all the features of the advice on crypto-assets or portfolio management of crypto-assets to be provided to those clients. Notably, crypto-asset service providers should take into account the features of the advice on crypto-assets or portfolio management of crypto-assets to be provided, the type and characteristics of the crypto-assets to be considered and the characteristics of the clients.
33. In determining what information is ‘necessary’, crypto-asset service providers should
consider, in relation to a client’s knowledge and experience, financial situation, investment objectives and their basic understanding of the risks involved in purchasing crypto-assets:
example, a stablecoin or a utility token), the length of time he has been trading them for, etc.
39. For illiquid crypto-assets28, the ‘necessary information’ to be gathered should include
information on the length of time for which the client is prepared to hold the investment.
40. As information about a client’s financial situation will always need to be collected, the
extent of information to be collected may depend on the type of crypto-assets and services to be recommended or entered into. For example, as many crypto-assets are highly speculative investments, ‘necessary information’ to be collected may include all of the following elements as necessary to ensure whether the client’s financial situation allows him to invest or be invested in such crypto-assets:
all the crypto-assets that can potentially make up the portfolio may be less detailed than the level that the client should have when an advice on crypto-assets service is to be provided. Nevertheless, even in such situations, the client should at least understand the overall risks of the portfolio (including the risks inherent to distributed ledger technology) and possess a general understanding of the risks linked to each type of crypto-assets that can be included in the portfolio. Cryptoasset service providers should gain a very clear understanding and knowledge of the degree of understanding of crypto-assets and of the investment profile of the client.
42. Similarly, the extent of the service requested by the client may also impact the level of
detail of information collected about the client. For example, crypto-asset service providers should collect more information about clients asking for advice covering their entire financial portfolio than about clients asking for specific advice on how to invest a given amount of money that represents a relatively small part of their overall portfolio.
43. Crypto-asset service providers should also take into account the nature of the client when
determining the information to be collected. For example, more in-depth information would usually need to be collected for potentially vulnerable clients (such as older clients could be) or inexperienced ones asking for advice on crypto-assets or portfolio management of crypto-asset services for the first time.
44. Information to be collected will also depend on the needs and circumstances of the client.
For example, a crypto-asset service provider is likely to need more detailed information about the client’s financial situation where the client’s investment objectives are multiple and/or long-term, than when the client seeks a short-term investment.
45. Information about a client’s financial situation includes information regarding his or her
investments (in crypto-assets and other products). This implies that crypto-asset service providers are expected to possess information about the client’s financial investments he holds with the crypto-asset service provider on a crypto-asset by crypto-asset basis. Depending on the scope of advice provided, crypto-asset service providers should also encourage clients to disclose details on investments they hold with other crypto-asset service providers or financial investments they hold with financial institutions, if possible also on a product-by-product basis.
5.4 Reliability of client information (Guideline 4)
Relevant legislation: Article 81(1) and (10) of MiCA.
46. Clients are expected to provide correct, up-to-date and complete information necessary
for the suitability assessment. However, crypto-asset service providers should take all reasonable steps and have appropriate tools to ensure that the information collected
about their clients is reliable, accurate and consistent, without unduly relying on clients’ self-assessment. This should include, without limitation:
types of crypto-assets the client is familiar with and how recent and frequent his trading experience with them is;
purpose and produce satisfactory results. For example, risk-profiling software could include some controls of coherence of the replies provided by clients in order to highlight contradictions between different pieces of information collected.
53. Crypto-asset service providers should also take reasonable steps to mitigate potential
risks associated with the use of such tools. For example, potential risks may arise if clients were encouraged to provide certain answers in order to get access to cryptoassets or crypto-asset services that may not be suitable for them (without correctly reflecting the clients’ real circumstances and needs). 29
54. In order to ensure the consistency of client information, crypto-asset service providers
should view the information collected as a whole. Crypto-asset service providers should be alert to any relevant contradictions between different pieces of information collected, and contact the client in order to resolve any material potential inconsistencies or inaccuracies. Examples of such contradictions are clients who have little knowledge or experience and an aggressive attitude to risk, or who have a prudent risk profile and ambitious investment objectives.
55. Crypto-asset service providers should adopt mechanisms to address the risk that clients
may tend to overestimate their knowledge and experience, for example by including questions that would help crypto-asset service providers assess the overall clients’ understanding about the characteristics and the risks of crypto-assets in general and the different types of crypto-assets. Such measures may be particularly important in the case of robo-advice, since the risk of overestimation by clients may result higher when they provide information through an automated (or semi-automated) system, especially in situations where very limited or no human interaction at all between clients and the crypto-asset service provider’s employees is foreseen.
5.5 Updating client information (Guideline 5)
Relevant legislation: Article 81(1), (8), (10) and (12) of MiCA.
56. Where a crypto-asset service provider has an ongoing relationship with the client (such
as by providing ongoing advice on crypto-assets or portfolio management of cryptoassets), in order to be able to perform the suitability assessment, crypto-asset service providers should adopt procedures defining: (a) what part of the client information collected should be subject to updating and at which frequency; (b) how the updating should be done and what action should be undertaken by the crypto-asset service provider when additional or updated information is received or when the client fails to provide the information requested. 29 In this regard, see also paragraph 59 of guideline 5, which addresses the risk of clients being influenced by crypto-asset service providers to change answers previously provided by them, without there being any real modification in their situation.
consider in this context is also the type of interaction that occurs with the client (e.g. telephone conversation vs through an automated system).
62. Crypto-asset service providers should inform the client when the additional information
provided results in a change of his profile, whether it becomes more risky (and therefore, potentially, a wider range of riskier and more complex crypto-assets may as a result be suitable for him, with the potential to incur in higher losses) or vice-versa more conservative (and therefore, potentially, a more restricted range of crypto-assets may as a result be suitable for him).
5.6 Client information for legal entities or groups (Guideline 6)
Relevant legislation: Article 81(1), (8) and (10) of MiCA.
63. Where a client is a legal person or a group of two or more natural persons or where one
or more natural persons are represented by another natural person, the crypto -asset service provider should establish and implement a policy, on an ex-ante basis, on the procedure and criteria that should be followed in order to comply with the MiCA suitability requirements in such situations. This includes (i) who should be subject to the suitability assessment, (ii) how the suitability assessment should be done in practice, including from whom information about knowledge and experience, financial situation and investment objectives should be collected and (iii) the possible impact this could have for the relevant clients, in accordance with the existing policy.
64. Where a client is a legal person or a natural person represented by another natural
person, the financial situation and investment objectives should be assessed in light of those of the underlying client (the legal person or the natural person that is being represented) rather than of the representative. The knowledge and experience to be assessed should be that of the representative. This would imply amongst others that they verify that the representative is indeed – according to relevant national law – authorised to carry out transactions on behalf of the client.
65. Crypto-asset service providers should consider whether the applicable national legal
framework provides specific indications that should be taken into account for the purpose of conducting the suitability assessment (this could be the case, for instance, where the appointment of a legal representative is required by law: e.g. for underage or incapacitated persons or for a legal person).
66. The policy should make a clear distinction between situations where a representative is
foreseen under applicable national law, as it can be the case for example for legal persons, and situations where no representative is foreseen, and it should focus on these latter situations. Where the policy foresees agreements between clients, they should be made aware clearly and in written form about the effects that such agreements may have regarding the protection of their respective interests. Steps taken by the crypto-asset
service provider in accordance with its policy should be appropriately documented to enable ex-post controls.
67. Where the client is a group of two or more natural persons and no representative is
foreseen under applicable national law, the crypto-asset service provider’s policy should identify from whom necessary information will be collected and how the suitability assessment will be done. Clients should be properly informed about the crypto-asset service provider’s approach (as decided in its policy) and the impact of this approach on the way the suitability assessment is done in practice.
68. Approaches such as the following could possibly be considered by crypto-asset service
providers: (a) they could choose to invite the group of two or more natural persons to designate a representative; or, (b) they could consider collecting information about each individual client and assessing the suitability for each individual client. Inviting the group of two or more natural persons to designate a representative
69. If the group of two or more natural persons agrees to designate a representative, the
same approach as the one described in paragraph 64 above could be followed: the knowledge and experience shall be that of the representative, while the financial situation and the investment objectives would be those of the underlying client(s). Such designation should be made in written form as well as according to and in compliance with the applicable national law, and recorded by the relevant crypto-asset service provider. The clients - part of the group - should be clearly informed, in written form, about the impact that an agreement amongst clients could have on the protection of their respective interests.
70. The crypto-asset service provider’s policy could however require the underlying client(s)
to agree on their investment objectives.
71. If the parties involved have difficulties in deciding the person/s from whom the information
on knowledge and experience should be collected, the basis on which the financial situation should be determined for the purpose of the suitability assessment or on defining their investment objectives, the crypto-asset service provider should adopt the most prudent approach by taking into account, accordingly, the information on the person with the least knowledge and experience, the weakest financial situation or the most conservative investment objectives. Alternatively, the crypto-asset service provider’s policy may also specify that it will not be able to provide advice on crypto-assets or portfolio management of crypto-assets in such a situation. Crypto-asset service providers should at least be prudent whenever there is a significant difference in the level of knowledge and experience or in the financial situation of the different clients part of the group.
Collecting information about each individual client and assessing the suitability for each individual client
72. When a crypto-asset service provider decides to collect information and assess suitability
for each individual client part of the group, if there are significant differences between the characteristics of those individual clients (for example, if the crypto-asset service provider would classify them under different investment profiles), the question arises about how to ensure the consistency of the advice on crypto-assets or portfolio management of crypto-assets provided with regard to the crypto-assets or portfolio of that group of clients. In such a situation, a crypto-asset may be suitable for one client
part of the group but not for another one. The crypto-asset service provider’s policy
should clearly specify how it will deal with such situations. Here again, the crypto-asset service provider should adopt the most prudent approach by taking into account the information on the client part of the group with the least knowledge and experience, the weakest financial situation or the most conservative investment objectives. Alternatively, the crypto-asset service provider’s policy may also specify that it will not be able to provide advice on crypto-assets or portfolio management of crypto-assets in such a situation. In this context, it should be noted that collecting information on all the clients
part of the group and considering, for the purposes of the assessment, an average profile
of the level of knowledge and competence of all of them, would unlikely be compliant with the MiCA overarching principle of acting in the clients’ best interests.
5.7 Arrangements necessary to understand crypto-assets (Guideline 7)
Relevant legislation: Article 81(10) of MiCA.
73. Crypto-asset service providers should have adequate policies and procedures in place
to ensure that they understand the characteristics, nature, features, including costs and risks of crypto-asset services and crypto-assets selected for their clients and that they assess, while taking into account cost and complexity, whether equivalent crypto-asset services or crypto-assets can meet their client’s profile.
74. Crypto-asset service providers should adopt robust and objective procedures,
methodologies and tools that allow them to appropriately consider the different characteristics and relevant risk factors (such as credit risk, market risk, liquidity risk31 , operational risk including hacking risk, etc.) of each crypto-asset they may recommend or invest in on behalf of clients. Considering the level of ‘complexity’ of products is 31 It is particularly important that the liquidity risk identified is not balanced out with other risk indicators (such as, for example, those adopted for the assessment of credit/counterparty risk and market risk). This is because the liquidity features of cryptoassets should be compared with information on the client’s willingness to hold the crypto-assets for a certain length of time, i.e. the so called ‘holding period’.
particularly important, and this should be matched with a client’s information (in particular regarding their knowledge and experience).
75. Crypto-asset service providers should adopt procedures to ensure that the information
used to understand and correctly classify crypto-assets included in their product offer is reliable, accurate, consistent and up-to-date. When adopting such procedures, cryptoasset service providers should take into account the different characteristics and nature of the crypto-assets considered.
76. In addition, crypto-asset service providers should review the information used so as to
be able to reflect any relevant changes that may impact the product’s classification. This is particularly important, taking into account the continuing evolution and growing speed of crypto-asset markets.
5.8 Arrangements necessary to ensure the suitability of crypto-assets or cryptoasset services (Guideline 8)
Relevant legislation: Article 81(1), (10), (11) and (12) of MiCA.
77. In order to match clients with suitable investments and services, crypto-asset service
providers should establish policies and procedures to ensure that they consistently take into account:
Crypto-asset service providers are reminded that the suitability assessment is not limited
to recommendations to buy a crypto-asset. Every recommendation must be suitable, whether it is, for example, a recommendation to buy, hold or sell a crypto-asset, or not to do so.
Crypto-asset service providers that rely on tools in the suitability assessment process
(such as model portfolios, asset allocation software or a risk-profiling tool for potential investments), should have appropriate systems and controls to ensure that the tools are fit for purpose and produce satisfactory results.
In this regard, the tools should be designed so that they take account of all the relevant
specificities of each client or crypto-asset. For example, tools that classify clients or crypto-assets broadly would not be fit for purpose.
A crypto-asset service provider should establish policies and procedures which enable it
to ensure inter alia that:
client’s portfolio as a whole. In practice, if the portfolio management agreement defines in sufficient details the investment strategy that is suitable for the client with regard to the suitability criteria defined by MiCA and that will be followed by the crypto-asset service provider, the assessment of the suitability of the investment decisions could be done against the investment strategy as defined in the portfolio management agreement and the portfolio of the client as a whole should reflect this agreed investment strategy. When a crypto-asset service provider conducts a suitability assessment based on the consideration of the client’s portfolio as a whole within the service of advice on crypto - assets, this means that, on the one hand, the level of knowledge and experience of the client should be assessed regarding each crypto-asset and risks involved in the related transaction. On the other hand, with regard to the client’s financial situation and investment objectives, the suitability assessment about the impact of the product and transaction can be done at the level of the client’s portfolio.
84. When a crypto-asset service provider conducts a suitability assessment based on the
consideration of the client’s portfolio as a whole, it should ensure an appropriate degree of diversification within the client’s portfolio, taking into account the client’s portfolio exposure to the different financial risks (geographical exposure, currency exposure, etc.). Crypto-asset service providers should be especially prudent regarding credit risk:
exposure of the client’s portfolio to one single issuer or to issuers part of the same group should be particularly considered. This is because, if a client’s portfolio is concentrated in products issued by one single entity (or entities of the same group), in case of default of that entity, the client may lose up to his entire investment.
85. In order to ensure the consistency of the suitability assessment conducted through
automated tools (even if the interaction with clients does not occur through automated systems), crypto-asset service providers should regularly monitor and test the algorithms that underpin the suitability of the transactions recommended or undertaken on behalf of clients. When defining such algorithms, crypto-asset service providers should take into account the nature and characteristics of the crypto-assets and services included in their offer to clients. In particular, crypto-asset service providers should at least:
includes having security arrangements in place to monitor and prevent unauthorised access to the algorithm;
identified in the above guideline 7. For crypto-asset service providers with a restricted range of crypto-assets, or those recommending one type of crypto-asset, where the assessment of ‘equivalent’ crypto-asset could be limited, it is important that clients are made fully aware of such circumstances. In this context, it is particularly important that clients are provided appropriate information on how restricted the range of crypto-assets offered is, pursuant to Article 81(2)(b) of MiCA.32
90. Where a crypto-asset service provider uses common portfolio strategies or model
investment propositions that apply to different clients with the same investment profile (as determined by the crypto-asset service provider), the assessment of cost and complexity for 'equivalent’ crypto-assets could be done on a higher level, centrally, (for example within an investment committee or any other committee defining common portfolio strategies or model investment propositions) although a crypto-asset service provider will still need to ensure that the selected crypto-assets are suitable and meet their clients’ profile on a client-by-client basis.
91. Crypto-asset service providers should be able to justify those situations where a more
costly or complex crypto-asset is chosen or recommended over an equivalent cryptoasset, taking into account that for the selection process of products in the context of advice on crypto-assets or portfolio management further criteria can also be considered (for example: the portfolio’s diversification, liquidity, or risk level). Crypto-asset service providers should document and keep records about these decisions, as these decisions should deserve specific attention from control functions within the crypto-asset service provider. The respective documentation should be subject to internal reviews. When providing advice on crypto-assets crypto-asset service providers could, for specific welldefined reasons, also decide to inform the client about the decision to choose the more costly and complex crypto-asset.
5.10 Costs and benefits of switching investments (Guideline 10)
Relevant legislation: Article 81(1), (10) and (12) of MiCA.
92. As part of the policies and procedures on the suitability assessment, crypto-asset service
providers should undertake an analysis of the costs and benefits of a switch such that crypto-asset service providers are reasonably able to demonstrate that the expected benefits of switching are greater than the costs.
93. For the purpose of this guideline, investment decisions such as rebalancing a portfolio
under management, in the case of a “passive strategy” to replicate an index (as agreed 32 In accordance with MiCA, crypto-asset service providers are therefore not expected to consider the whole universe of possible crypto-asset options existing in the market in order to follow guideline 7.
with the client) would normally not be considered as a switch. For the avoidance of doubt, any transaction without maintaining these thresholds would be considered as a switch.
94. Crypto-asset service providers should take all necessary information into account, so as
to be able to conduct a cost-benefit analysis of the switch, i.e. an assessment of the advantages and disadvantages of the new crypto-asset(s) considered. When considering the cost dimension, crypto-asset service providers should take into account all costs and charges covered by the relevant provisions under Article 81(4) of MiCA. In this context, both monetary and non-monetary factors of costs and benefits could be relevant. These may include, for example:
When providing advice on crypto-assets, a clear explanation of whether or not the
benefits of the recommended switch are greater than its costs should be included in the suitability report33 the crypto-asset service provider has to provide to the client before the transaction is made.
Crypto-asset service providers should also adopt systems and controls to monitor the
risk of circumventing the obligation to assess costs and benefits of recommended switch, for example in situations where an advice to sell a crypto-asset is followed by an advice to buy another crypto-asset at a later stage (e.g. days later), but the two transactions were in fact strictly related from the beginning. 33 The report on suitability referred to in Article 81(13) of MiCA.
Where a crypto-asset service provider uses common portfolio strategies or model
investment propositions that apply to different clients with the same investment profile (as determined by the crypto-asset service provider), the costs/benefits analysis of a switch could be done on a higher level than at the level of each individual client or each individual transaction. More especially, when a switch is decided centrally, for example within an investment committee or any other committee defining common portfolio strategies or model investment propositions, the costs/benefits analysis could be done at the level of that committee. If such a switch is decided centrally, the costs/benefits analysis done at that level would usually be applicable to all comparable client portfolios without making an assessment for each individual client. In such a situation also, the crypto-asset service provider could determine, at the level of the relevant committee, the reason why a switch decided will not be performed for certain clients. Although the costs/benefits analysis could be done at a higher level in such situations, the cryptoasset service provider should nevertheless have appropriate controls in place to check that there are no particular characteristics of certain clients that might require a more discrete level of analysis.
Where a portfolio manager has agreed a more bespoke mandate and investment
strategy with a client due to the client’s specific investment needs, a cost-benefit analysis of the switch at client-level should be performed, in contrast to the above.
Notwithstanding the above, if a portfolio manager considers that the composition or
parameters of a portfolio should be changed in a way that is not permitted by the mandate agreed with the client, the portfolio manager should discuss this with the client and review or conduct a new suitability assessment to agree a new mandate.
5.11 Qualifications of staff (Guideline 11)34
Relevant legislation: Articles 68(5) and 81(7) of MiCA.
Crypto-asset service providers are required to ensure that staff involved in material
aspects of the suitability process have an adequate level of skills, knowledge and expertise with regard to crypto-assets and crypto-asset services.
Staff should understand the role they play in the suitability assessment process and
possess the skills, knowledge and expertise necessary, including sufficient knowledge of the relevant regulatory requirements and procedures, to discharge their responsibilities. 34 As per the mandate under Article 81(15)(a) of MiCA, ESMA will, at a later date, issue more general guidelines on the criteria for the assessment of knowledge and competence in accordance Article 81(7) of MiCA.
Staff should possess the necessary knowledge and competence, including with regard
to the suitability assessment. To that effect, crypto-asset service providers should give staff appropriate training.
Other staff that does not directly face clients but is involved in the suitability assessment
in any other way should still possess the necessary skills, knowledge and expertise required depending on their particular role in the suitability process. This may regard, for example, setting up the questionnaires, defining algorithms governing the assessment of suitability or other aspects necessary to conduct the suitability assessment and controlling compliance with the suitability requirements.
Where relevant, when employing automated tools (including hybrid tools), crypto-asset
service providers should ensure that their staff involved in the activities related to the definition of these tools:
36 OJ L 150, 9.6.2023, p. 40–205.
4.4 Annex IV: Guidelines on the procedures and policies, including
the rights of clients, in the context of transfer services for cryptoassets 1 Scope Who?
37 OJ L 150, 9.6.2023, p. 1–39. transfers of funds and certain crypto-assets and amending Directive (EU) 2015/84937
2.2 Abbreviations
EC European Commission
ESFS European System of Financial Supervision
ESMA European Securities and Markets Authority EU European Union 3 Purpose
4. These guidelines, developed by ESMA in close cooperation with EBA, are based on
Article 82(2) of MiCA. The objectives of these guidelines are to establish consistent,
efficient and effective supervisory practices within the ESFS and to ensure the common, uniform and consistent application of the provisions in Article 82 of MiCA. In particular, they aim at providing more clarity on the requirements for crypto-asset service providers providing transfer services for crypto-assets on behalf of clients as regards procedures and policies, including the rights of clients, in the context of transfer services for crypto - assets. In this regard, ESMA anticipates a corresponding strengthening of investor protection. These guidelines apply without prejudice to the relevant rules under PSD 2, where applicable to relevant transfers of crypto-assets, notably EMTs. 4 Compliance and reporting obligations
4.1 Status of the guidelines
5. In accordance with Article 16(3) of the ESMA Regulation, competent authorities and
crypto-asset service providers shall make every effort to comply with these guidelines.
6. Competent authorities to which these guidelines apply should comply by incorporating
them into their national legal and/or supervisory frameworks as appropriate, including where particular guidelines are directed primarily at financial market participants. In this case, competent authorities should ensure through their supervision that crypto-asset service providers comply with the guidelines.
4.2 Reporting requirements
transfer of crypto-assets to be properly initiated or executed (including, how to authenticate);
the conditions under which the crypto-asset service provider may reject an
instruction to carry out a transfer of crypto-assets;
a reference to the procedure or process established by the crypto-asset service
provider to determine the time of receipt of an instruction or consent to a transfer of crypto-assets and any cut-off time established by the crypto-asset service provider;
an explanation per crypto-asset, of which distributed ledger technology (DLT)
network is supported for the transfer of this crypto-asset;
the maximum execution time for the transfer of crypto-assets service to be
provided;
for each DLT network, reasonably estimated time or number of block confirmations
needed for the transfer to be irreversible on the DLT network or considered sufficiently irreversible in case of probabilistic settlement taking into account the rules and circumstances of the DLT network;
all charges, fees or commissions payable by the client in relation to the cryptoassets transfer service, including those connected to the manner in and frequency
with which information is provided or made available and, where applicable, the breakdown of the amounts of such charges;
the means of communication, including basic information about the technical
requirements for the client’s equipment and software (for example, the minimum software or mobile operating system), agreed between the parties for the transmission of information or notifications related to the crypto-asset transfer service ;
the manner in, and frequency with which, information related to the service of
crypto-asset transfer is to be provided or made available;
the language or languages in which the agreement referred to in Article 82(1) of
MiCA will be concluded and communication during this contractual relationship undertaken;
the secure procedure for notification of the client by the crypto-asset service
provider in the event of suspected or actual fraud or security threats;
the means and time period within which the client is to notify the crypto-asset
service provider of any unauthorised or incorrectly initiated or executed transfers of crypto-assets as well as the crypto-asset service provider’s liability, including maximum amount thereof, for unauthorised or incorrectly initiated or executed transfers;
the right of the client to terminate the agreement on the provision of crypto-asset
transfer services and the modalities to do so;
Read the rest free
Source: European Securities and Markets Authority — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works