Skip to content

Evidence request lists

EU Markets in Crypto-Assets Regulation (MiCA)

Evidence request list. 22 controls, 22 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

MiCA - Asset-Referenced Tokens (Title III)

MiCA-Art.16_17_18_19_20_21
ART authorisation - application + assessment + grant/refusal (Articles 16-21)

Article 16 requires authorisation by the home Member State competent authority before any offer to the public or admission to trading of an ART (or before the issuer is established in the Union). Article 17 sets the carve-out for credit institutions (which use their existing banking authorisation + an Annex II ART white paper notification). Article 18 sets the application content per Annex II. Article 19 sets the content + form of the ART crypto-asset white paper. Article 20 sets the 60-working-day assessment-of-application timeline. Article 21 sets the grant or refusal of authorisation (with reasoned decision, EBA + ECB consultation where applicable).

Artefacts an auditor will ask for
  • Annex II application content for ART authorisation
  • 60-working-day assessment timeline tracking
  • EBA + ECB consultation records where the ART is denominated in a Union currency or referenced to one
Where this commonly fails
  • ART issued without authorisation
  • Credit-institution Article 17 carve-out claimed without notification of WP
MiCA-Art.22_23_24_25_26
ART reporting, restrictions on widely-used ARTs and white paper liability (Articles 22-26)

Article 22 requires monthly reporting on issued ARTs to the competent authority (in particular total value + average daily transactions). Article 23 imposes restrictions on the issuance of ARTs used widely as a means of exchange where they reach >=1 million daily transactions + >=EUR 200 million daily value (the issuer must take measures to limit further use as a means of exchange). Article 24 governs withdrawal of authorisation. Article 25 governs modification of the published ART white paper. Article 26 establishes civil liability of ART issuers for the information given in the white paper.

Artefacts an auditor will ask for
  • Monthly Article 22 reporting infrastructure
  • Article 23 monitoring of daily-transaction + daily-value thresholds for ARTs used as means of exchange + plan to limit further issuance if thresholds met
  • Article 25 modification + supplemental-WP procedure
Where this commonly fails
  • Monthly reporting absent or late
  • Crossing the Article 23 daily-transaction / daily-value threshold without taking the required restrictive measures
MiCA-Art.27_28_29_30_31_32
ART issuer conduct, ongoing information, complaints and conflict of interest (Articles 27-32)

Article 27 imposes the Article 27(1) duty to act honestly, fairly and professionally in the best interest of the holders. Article 27(2) requires fair, clear and non-misleading communication. Article 28 governs publication of the ART white paper. Article 29 governs marketing communications. Article 30 requires ongoing information to ART holders. Article 31 requires complaints-handling procedures for ART holders. Article 32 imposes the duty to identify, prevent, manage and disclose conflicts of interest.

Artefacts an auditor will ask for
  • Conduct policy aligned with Article 27
  • Ongoing information disclosure per Article 30
  • Complaints-handling procedure per Article 31 (free of charge for holders)
  • Conflict-of-interest policy aligned with Article 32
Where this commonly fails
  • Complaints-handling without free-of-charge access for holders
  • Conflict-of-interest management not disclosed publicly
MiCA-Art.33_34_35
Notification of management changes, governance and own funds (Articles 33-35)

Article 33 requires notification of changes to the management body to the competent authority. Article 34 sets the substantive governance arrangements for ART issuers (Article 34 specifies the requirements for the management body, separation of functions, internal control framework, risk management, sound administrative procedures). Article 35 sets the own funds requirements for ART issuers (the higher of EUR 350,000 or 2% of the average amount of the reserve of assets, with significant-ART issuers subject to 3% under Article 45).

Artefacts an auditor will ask for
  • Management body notification procedure per Article 33
  • Article 34 governance arrangements + internal control framework + risk-management framework
  • Article 35 own-funds calculation + 2%-of-reserve floor
  • Significant-ART 3% calibration where applicable
Where this commonly fails
  • Own funds below the Article 35 floor
  • Governance arrangements not aligned with Article 34
MiCA-Art.36_37_38_39_40
ART reserve of assets - composition, custody, investment, redemption, no interest (Articles 36-40)

Article 36 requires ART issuers to constitute, maintain and manage at all times a reserve of assets composed in such a way as to cover the risks associated with the assets referenced by the ART (Article 36(6) liquidity + composition + segregation requirements; Article 36(11) segregation from issuer assets and from other reserves). Article 37 imposes custody of the reserve of assets by EU credit institutions or CASPs authorised for custody under Article 75. Article 38 governs investment of the reserve of assets (highly liquid, low-risk, low-credit-risk, low-market-risk financial instruments + cash + commodities subject to limits). Article 39 grants holders an unconditional right of redemption at par value at any time, with the issuer required to honour redemption requests promptly. Article 40 prohibits granting any interest to holders related to the length of time they hold the ART.

Artefacts an auditor will ask for
  • Reserve-of-assets composition + segregation evidence
  • Article 37 custody arrangement with EU credit institution or Article-75 CASP
  • Article 38 investment policy aligned with permitted instruments
  • Article 39 par-value redemption mechanism
  • Article 40 no-interest compliance
Where this commonly fails
  • Reserve of assets co-mingled with issuer assets
  • Custody by an unauthorised third party
  • Investment of reserve in non-permitted instruments
  • Redemption refused or delayed beyond a reasonable period
  • Interest paid to holders (Article 40 breach)
MiCA-Art.41_42_43_44_45_46_47
Acquisition assessment + significant-ART regime + recovery and redemption plans (Articles 41-47)

Articles 41-42 establish the assessment of proposed acquisitions of ART issuers (qualifying holding above 10% / 20% / 30% / 50% triggers competent-authority assessment within 60 working days). Article 43 establishes the significant-ART classification (EBA classifies based on Article 43(1) cumulative criteria: large customer base over 10 million / large value over EUR 5 billion / large number of transactions over 2.5 million per day / interconnectedness / cross-border activities / significant means of exchange use). Article 44 enables voluntary classification as significant. Article 45 imposes specific additional obligations for significant-ART issuers (3% own funds, enhanced governance, additional reporting). Articles 46-47 require recovery plan + redemption plan (the redemption plan is invoked where the issuer is unable to fulfil its obligations).

Artefacts an auditor will ask for
  • Notification of qualifying-holding acquisitions per Article 41
  • Significant-ART classification monitoring per Article 43 criteria
  • Article 45 enhanced regime where significant-ART status applies
  • Recovery plan + redemption plan per Articles 46-47
Where this commonly fails
  • Significant-ART issuer without 3%-of-reserve own funds
  • No recovery plan or redemption plan

MiCA - CASP Authorisation and General Obligations (Title V Ch 1-3)

MiCA-Art.59_60_61_62_63_64_65
CASP authorisation - scope, application, assessment, withdrawal, cross-border (Articles 59-65)

Article 59 requires authorisation by the home Member State competent authority before providing any of the 10 enumerated crypto-asset services. Article 60 enables certain financial entities (MiFID II investment firms, credit institutions, UCITS managers, AIFMs etc.) to provide specified crypto-asset services on the basis of their existing authorisation with simplified notification. Article 61 governs the reverse-solicitation exclusion (provision of services at the client's exclusive initiative). Article 62 sets the application content. Article 63 sets the 40-working-day assessment of completeness + 60-working-day substantive assessment. Article 64 governs withdrawal. Article 65 enables cross-border provision of crypto-asset services (passporting).

Artefacts an auditor will ask for
  • Article 59 authorisation evidence per service category
  • Article 60 simplified-notification records for already-authorised financial entities
  • Reverse-solicitation evidence per Article 61 where claimed
  • Cross-border passport notifications per Article 65
Where this commonly fails
  • CASP service provided without Article 59 authorisation
  • Reverse-solicitation claim without robust evidence (Article 61 narrow)
  • Cross-border activity without Article 65 passport notification
MiCA-Art.66_67_68_69_70
CASP general obligations - conduct, prudential, governance, information, safekeeping (Articles 66-70)

Article 66 imposes the duty to act honestly, fairly and professionally in the best interests of clients. Article 67 imposes prudential safeguards: CASPs must hold at all times own funds at least equal to the higher of (a) the Class 1/2/3 minimum capital floor per Annex IV (Class 1 = EUR 50,000; Class 2 = EUR 125,000; Class 3 = EUR 150,000) or (b) a quarter of the previous year's fixed overheads. Article 68 sets governance arrangements. Article 69 requires CASPs to notify competent authorities of certain information. Article 70 imposes safekeeping of client crypto-assets + funds with segregation from CASP own holdings, with bankruptcy-remoteness implications.

Artefacts an auditor will ask for
  • Article 66 conduct standards
  • Article 67 own-funds calculation tracking Annex IV class + fixed-overheads denominator
  • Article 68 governance + risk-management framework
  • Article 70 client-asset segregation - bankruptcy-remote books and accounts
Where this commonly fails
  • CASP own funds below Annex IV / fixed-overheads threshold
  • Client crypto-assets co-mingled with CASP own holdings (Article 70 breach + significant liability risk)
MiCA-Art.71_72_73_74
CASP complaints, conflicts, outsourcing and orderly wind-down (Articles 71-74)

Article 71 requires CASPs to establish a complaints-handling procedure available free of charge to clients. Article 72 imposes the duty to identify, prevent, manage and disclose conflicts of interest. Article 73 governs outsourcing of operational tasks: CASPs remain fully responsible; specific terms required for material outsourcing; the CASP cannot outsource to an extent that it becomes a 'letter-box entity'. Article 74 requires CASPs to have in place arrangements for the orderly wind-down of their business in case of authorisation withdrawal.

Artefacts an auditor will ask for
  • Complaints-handling procedure with free-of-charge client access
  • Conflict-of-interest register + management policy
  • Outsourcing register + material-outsourcing contracts with specific clauses
  • Orderly wind-down plan invoked on authorisation withdrawal
Where this commonly fails
  • Outsourcing that creates a letter-box entity (Article 73 prohibition)
  • No wind-down plan

MiCA - CASP Service-Specific Obligations (Title V Ch 4)

MiCA-Art.75
Custody and administration of crypto-assets on behalf of clients (Article 75)

Article 75 sets the specific obligations for CASPs providing custody and administration of crypto-assets: client agreement; register of holdings; daily statements; full reporting on movements; client-asset segregation; liability for loss of crypto-assets resulting from incident attributable to the CASP (subject to limited exceptions in Article 75(8)).

Artefacts an auditor will ask for
  • Client agreement template per Article 75(2)
  • Register of holdings + daily statements
  • Article 75(8) liability regime + insurance / capital coverage
Where this commonly fails
  • Custody service without daily statements or holdings register
  • Loss of client crypto-assets without Article 75(8) coverage
MiCA-Art.76
Operation of a trading platform for crypto-assets (Article 76)

Article 76 sets the specific obligations for CASPs operating a trading platform: operating rules; admission criteria; trade-transparency (pre-trade + post-trade); orderly trading; market-abuse surveillance + Title VI alignment; fee transparency; circuit-breakers + safeguards.

Artefacts an auditor will ask for
  • Trading-platform operating rules published
  • Admission policy for crypto-assets
  • Pre/post-trade transparency + reporting
  • Market-abuse surveillance arrangement aligned with Title VI
Where this commonly fails
  • Operating a trading platform without market-abuse surveillance
  • No published operating rules
MiCA-Art.77_78_79_80_81_82
Exchange, execution, placing, reception/transmission, advice, portfolio management (Articles 77-82)

Article 77 sets specific obligations for CASPs exchanging crypto-assets for funds or for other crypto-assets (non-discretionary price-setting policy; quote transparency). Article 78 sets execution-of-orders rules (best-execution policy). Article 79 governs placing of crypto-assets (no front-running + due diligence). Article 80 governs reception + transmission of orders. Article 81 governs advice (suitability test) + portfolio management (discretionary management with mandate). Article 82 governs transfer services (the new Title V service category).

Artefacts an auditor will ask for
  • Per-service-specific compliance file (price-setting policy / best-execution / suitability test / portfolio mandate / transfer-service terms)
Where this commonly fails
  • CASP claiming a service category without the service-specific Article 77-82 compliance program

MiCA - E-Money Tokens (Title IV)

MiCA-Art.48_49_50_51_52
EMT issuance requirements + redeemability + no interest + white paper + liability (Articles 48-52)

Article 48 requires that an EMT may only be offered to the public or admitted to trading by an issuer that is either an authorised credit institution or an authorised e-money institution under Directive (EU) 2009/110/EC (EMD2). Article 49 sets the issuance and redeemability rules: EMTs are issued at par value on receipt of funds, the issuer must redeem at any time at par value the monetary value of the EMT in funds upon request, free of charge except for justified costs. Article 50 prohibits granting interest to EMT holders. Article 51 sets the content + form of the EMT crypto-asset white paper. Article 52 establishes civil liability of EMT issuers for the information given in the white paper.

Artefacts an auditor will ask for
  • Article 48 authorisation evidence (credit institution or EMD2 e-money institution)
  • Article 49 par-value-redemption mechanism + free-of-charge floor
  • Article 50 no-interest compliance
  • Article 51 EMT WP aligned with Annex III
Where this commonly fails
  • EMT issued by non-credit / non-EMD2-EMI issuer
  • Redemption not at par value or charging fees beyond justified costs
  • Interest paid to EMT holders
MiCA-Art.53_54_55_56_57_58
EMT marketing, investment of funds, recovery, significant EMT and additional obligations (Articles 53-58)

Article 53 governs marketing communications for EMTs. Article 54 requires funds received in exchange for EMTs to be invested in safeguarding accounts at credit institutions or in highly liquid financial instruments (per EMD2 Article 7 + Article 9 safeguarding rules + MiCA-specific tightening). Article 55 applies the Title III recovery and redemption plans mutatis mutandis. Article 56 establishes significant-EMT classification (parallel to ART). Article 57 enables voluntary significant-EMT classification. Article 58 sets specific additional obligations for significant-EMT issuers + Article 58(4) caps significant-EMT issuance denominated in non-Union currencies where issued by entities other than credit institutions or full-MiCA-authorised EMT issuers.

Artefacts an auditor will ask for
  • Article 54 safeguarding-accounts evidence
  • Article 56 significant-EMT classification monitoring + Article 58 enhanced regime
  • Article 58(4) non-Union-currency issuance cap monitoring
Where this commonly fails
  • EMT funds invested in non-permitted instruments
  • Significant-EMT in non-Union currency exceeding the Article 58 cap

MiCA - Market Abuse, Competent Authorities and Final (Titles VI-IX)

MiCA-Art.117_118_119_120_121
EBA supervisory powers over significant ARTs + EMTs (Articles 117-121)

Articles 117-121 transfer supervisory responsibility for significant ARTs and significant EMTs to the EBA (with retained NCA + EMI supervision for the EMI authorisation). The EBA has direct supervisory + sanctioning powers including periodic penalty payments + administrative fines up to 12.5% of the issuer's annual turnover; the EBA may also adopt binding requirements + supervisory measures + corrective action.

Artefacts an auditor will ask for
  • EBA-supervision tracking where the entity issues a significant ART or significant EMT
  • Cooperation with EBA supervisory measures + on-site inspections
Where this commonly fails
  • Significant-token issuer not coordinating with EBA + retained NCA
MiCA-Art.139
Delegated acts (Article 139)

Article 139 governs the exercise of the delegation of power to the Commission for the Annex amendments and technical standards underpinning MiCA. Multiple Level-2 RTSs and ITSs have been adopted (e.g. fit-and-proper assessments; complaints-handling; recovery + redemption plans; conflict-of-interest disclosures; market-abuse cooperation; cross-border supervisory cooperation).

Artefacts an auditor will ask for
  • Tracking of relevant Commission RTSs + ITSs affecting the entity (e.g. complaints-handling RTS; fit-and-proper RTS; market-abuse cooperation RTS)
Where this commonly fails
  • Reliance on Level-1 text only without checking applicable RTSs / ITSs
MiCA-Art.140_141_142_143_144_145_146_147_148_149
Transitional and final provisions (Articles 140-149)

Article 140 requires Commission reports on application + impact. Article 141 sets requirements for the EBA + ESMA. Article 142 amends EBA Regulation 1093/2010 + ESMA Regulation 1095/2010. Article 143 sets transitional provisions: ARTs / EMTs already issued prior to 30 June 2024 may continue under conditions until they obtain MiCA authorisation; CASPs operating prior to 30 December 2024 may continue under national-law grandfathering until 1 July 2026 (or shorter Member State window). Article 144 amends Directive 2013/36/EU (CRD) to recognise MiCA-CASPs as financial entities for CRD purposes where applicable. Article 145 amends Directive (EU) 2019/1937 (whistleblowing) to add MiCA. Article 146 transposes other Union law adjustments. Article 147 was related to repeals. Article 148 governs the entry into force (29 June 2023). Article 149 sets the application dates: Titles III + IV from 30 Ju

Artefacts an auditor will ask for
  • Compliance calendar reflecting 29 Jun 2023 entry into force + 30 Jun 2024 Titles III + IV + 30 Dec 2024 remaining titles + 1 Jul 2026 CASP grandfathering deadline
Where this commonly fails
  • Operating CASP services after the Article 143 national-law grandfathering window without MiCA authorisation
  • Pre-30-Jun-2024 ART / EMT not transitioning under Article 143 conditions
MiCA-Art.86_87_88_89_90_91_92
Market abuse prohibition - scope, inside information, insider dealing, unlawful disclosure, manipulation (Articles 86-92)

Article 86 sets the scope of Title VI market-abuse rules (applies to acts carried out by any person and concerning crypto-assets admitted to trading or for which a request for admission has been made). Article 87 governs inside information (precise + not public + price-affecting). Article 88 imposes disclosure of inside information by issuers without delay. Article 89 prohibits insider dealing. Article 90 prohibits unlawful disclosure of inside information. Article 91 prohibits market manipulation (transactions / orders / dissemination + benchmark manipulation in respect of crypto-asset reference values). Article 92 requires market-abuse-detection arrangements by CASPs and trading-platform operators.

Artefacts an auditor will ask for
  • Inside-information identification + disclosure procedure
  • Insider dealing + unlawful disclosure controls (insider list + restricted-list)
  • Market-manipulation surveillance for trading-platform operators
  • STORs (suspicious transaction + order reports) to competent authority
Where this commonly fails
  • Trading-platform operator without market-abuse surveillance + STOR submission path
  • Issuer delaying disclosure of inside information without Article 88 conditions met
MiCA-Art.93_94_95
Competent authorities + supervisory powers + cooperation (Articles 93-95)

Article 93 requires Member States to designate competent authorities for MiCA supervision + cooperation. Article 94 sets the catalogue of supervisory powers (information requests + on-site inspections + suspension of activities + temporary prohibition of marketing + freeze of assets + public statements). Article 95 governs cooperation among competent authorities + with EBA + ESMA.

Artefacts an auditor will ask for
  • Identification of the relevant MiCA competent authority per Member State
  • Engagement records with the competent authority + cooperation with cross-border investigations

MiCA - Other Crypto-Assets and White Paper Regime (Title II)

MiCA-Art.10_11_12_13_14_15
Offeror obligations, modifications, withdrawal and white paper liability (Articles 10-15)

Article 10 sets the result-of-offer + safeguarding-arrangements requirements. Article 11 sets the rights of offerors. Article 12 governs modification of published white papers + marketing communications. Article 13 grants a 14-calendar-day right of withdrawal to retail holders for offers to the public (no right of withdrawal where the crypto-asset is admitted to trading). Article 14 sets the substantive obligations of offerors (act honestly + fairly + professionally; clear marketing; safeguarding clients' funds during offer). Article 15 establishes civil liability for the information given in a crypto-asset white paper.

Artefacts an auditor will ask for
  • 14-day right-of-withdrawal mechanism for retail offers
  • Modification + supplemental-WP procedure per Article 12
  • Article 14 conduct standards documented in policies
  • Article 15 civil-liability awareness in WP drafting
Where this commonly fails
  • Retail offer without functioning 14-day right of withdrawal
  • Modifications to WP not notified per Article 12
MiCA-Art.4_5_6_7_8_9
Offers to the public and admission to trading of crypto-assets other than ART/EMT (Articles 4-9)

Article 4 requires that offerors and persons seeking admission to trading of crypto-assets other than ARTs/EMTs draw up + notify a crypto-asset white paper before offer or admission. Article 5 sets the same regime for admission to trading. Article 6 sets the content + form of the crypto-asset white paper. Article 7 governs marketing communications associated with the offer. Article 8 sets the notification regime for the crypto-asset white paper + marketing communications to the competent authority. Article 9 sets the publication regime.

Artefacts an auditor will ask for
  • Crypto-asset white paper aligned with Article 6 + Annex I
  • Notification + publication procedure per Articles 8-9
  • Marketing-communications review aligned with Article 7
Where this commonly fails
  • Offer to the public without a notified + published white paper
  • Marketing communications inconsistent with the white paper or misleading

MiCA - Subject Matter, Scope and Definitions (Title I)

MiCA-Art.1_2_3
Subject matter, scope and definitions (Articles 1-3)

Article 1 sets the subject matter: uniform requirements for the offer to the public and admission to trading on a trading platform of crypto-assets other than asset-referenced tokens or e-money tokens, for asset-referenced tokens and e-money tokens, and for crypto-asset service providers. Article 2 sets the scope: applies to natural and legal persons who are engaged in the issuance, offer to the public and admission to trading of crypto-assets or who provide services related to crypto-assets in the Union. Article 2(4) sets exclusions including NFTs that are genuinely unique and not interchangeable. Article 3 supplies definitions including 'crypto-asset', 'asset-referenced token (ART)', 'e-money token (EMT)', 'utility token', 'CASP', 'distributed ledger technology (DLT)', 'crypto-asset white paper', 'significant ART/EMT', and 'crypto-asset service'.

Artefacts an auditor will ask for
  • Internal product taxonomy mapping the entity's crypto-asset activities to Article 3 categories (ART / EMT / other crypto-asset)
  • Article 2(4) NFT carve-out analysis where the entity issues / trades NFTs
Where this commonly fails
  • Treating NFTs as out-of-scope without an Article 2(4) genuine-unique-non-fungible analysis
  • Service description that does not commit to Article 3 CASP service categories
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the EU Markets in Crypto-Assets Regulation (MiCA) framework page.