top of page
Search

MiCA Audit Example for CASP Readiness in Practice

Writer: NUR Legal
NUR Legal
6 days ago
6 min read

A MiCA audit example for CASP readiness is most useful when it tests whether the business can prove how it operates, not merely whether it has drafted the right policies. For a crypto business approaching EU authorisation, the critical question is simple: if a regulator asks for evidence tomorrow, can management produce a consistent, current and credible answer?

MiCA has changed the operating standard for crypto-asset service providers. A CASP needs more than a legal entity and a compliance manual. It needs clear governance, suitably qualified management, financial resilience, client-asset protections, operational controls and a framework that works across its actual services, jurisdictions and customer base.

The following practical example shows how an internal readiness audit can identify gaps before they become application delays, remediation orders or a reason for a competent authority to lose confidence in the firm.

What a MiCA readiness audit should assess

A readiness audit is not a substitute for the formal authorisation process and it does not guarantee approval. It is a controlled pre-application review that compares the firm’s operating model, documents and evidence against the requirements relevant to its proposed CASP permissions.

The scope depends on the services in question. A platform operating a trading venue faces different issues from a firm providing custody and administration of crypto-assets, exchange services, execution of orders, transfer services or advice. The audit should therefore begin with the business model, not a generic checklist.

Assume the following case: Atlas Digital Ltd is an EU-incorporated crypto business seeking authorisation to provide custody, exchange of crypto-assets for funds and other crypto-assets, and transfer services. It has 18 staff, outsources cloud infrastructure and blockchain analytics, serves retail and professional clients, and intends to passport its services after authorisation.

Its founders believe they are ready because they have AML policies, terms of business and a compliance officer. The audit finds a more complicated position.

MiCA audit example for CASP readiness

The audit team reviews four areas: governance and substance, customer and asset protection, financial crime controls, and ICT and outsourcing. Each finding is tested against three questions: is the control designed appropriately, is it operating in practice, and can the company evidence it?

1. Governance: appropriate people, unclear accountability

Atlas has appointed a chief executive, chief technology officer and MLRO. Their CVs demonstrate relevant sector experience, and board meetings are held monthly. On paper, this is a good start.

However, the minutes do not show who approved the risk appetite, how conflicts of interest are assessed, or which individual has responsibility for client-asset reconciliations. The compliance officer reports to the chief executive but has no documented direct escalation route to the board. There is also no formal suitability assessment covering each member of the management body, including honesty, independence, time commitment and collective knowledge.

Audit finding: high priority. The governance structure exists but cannot yet demonstrate effective oversight. The remediation plan should adopt a responsibility matrix, revise board terms of reference, document fit-and-proper assessments and create regular management information reporting. A regulator should be able to see decisions, challenge and follow-up actions in the record, rather than infer them from job titles.

2. Safeguarding and custody: the policy does not match the wallet model

Atlas states in its custody policy that client crypto-assets are segregated from company assets. Yet the technical review shows that one omnibus wallet architecture is used for several client groups, while the reconciliation process is performed weekly through a spreadsheet maintained by operations.

This may not mean that assets are missing. It does mean the firm has not demonstrated a sufficiently reliable control environment. The audit also identifies that access to private-key management systems is not reviewed after staff role changes, and that the incident procedure does not specify how customers will be informed where access to crypto-assets is affected.

Audit finding: critical. Atlas needs a documented wallet and key-management architecture, daily or risk-based reconciliations appropriate to transaction volumes, independently reviewed exception handling, controlled access rights and tested incident communications. The legal documentation must also accurately explain custody arrangements, risks, fees and customer rights. A polished policy cannot cure a technical process that tells a different story.

3. AML controls: good screening, weak transaction rationale

The firm uses recognised sanctions and PEP screening tools at onboarding. Customer risk ratings are generated automatically, and enhanced due diligence is triggered for higher-risk profiles. These are useful controls, but the audit examines whether the team can explain its decisions.

Sample files show that risk ratings were overridden without a documented rationale. In two higher-risk cases, source-of-wealth information was collected but not meaningfully assessed. Blockchain analytics alerts were closed with short comments such as “no concern”, without an explanation of wallet exposure, transactional behaviour or the basis for the conclusion.

Audit finding: high priority. The issue is not a lack of technology. It is the quality of human judgement and the audit trail. Atlas should introduce case narratives, quality assurance reviews, defined escalation thresholds and periodic testing of alert handling. Its AML business-wide risk assessment also needs to reflect the particular risks created by its tokens, customer geography, distribution channels and transfer-service model.

4. ICT, outsourcing and continuity: supplier contracts leave gaps

Atlas relies on a cloud provider, a custody technology vendor and a blockchain analytics supplier. The company has carried out commercial due diligence, but its agreements do not consistently cover audit rights, incident notification, subcontracting controls, data location, exit support or business continuity testing.

This is particularly relevant because operational resilience expectations do not stop at the firm’s legal boundary. The interaction between MiCA requirements, cybersecurity duties and DORA-related obligations requires careful assessment based on the CASP’s authorisation status, activities and applicable national transition arrangements.

Audit finding: high priority. Atlas should maintain a full outsourcing register, classify critical suppliers, complete risk assessments before engagement and test exit and recovery plans. It should not assume that a large technology provider’s standard contract will meet its regulatory needs.

The evidence pack regulators expect to withstand scrutiny

The difference between a credible application and a difficult one is often evidence discipline. For each control, Atlas should be able to produce a current document, an accountable owner and records showing the control has operated.

A practical readiness pack would include:

  • board minutes, committee terms, management responsibility maps and suitability records;

  • policies supported by procedures, staff training records and testing results;

  • customer onboarding files, risk assessments, transaction-monitoring cases and AML quality assurance reports;

  • wallet diagrams, reconciliation logs, access reviews, incident reports and customer communication templates;

  • outsourcing registers, supplier due diligence, contractual assessments and continuity test outcomes; and

  • financial forecasts, own-funds calculations, insurance or comparable protection analysis where relevant, and records of regulatory capital monitoring.

The aim is not to create paperwork for its own sake. Evidence must match the actual business. If Atlas says it operates daily reconciliations, the audit trail must show daily reconciliations. If it says the board oversees outsourcing risk, minutes and risk reporting should demonstrate that oversight.

Turning findings into an authorisation plan

Not every gap warrants the same response. A missing signature on a policy can usually be corrected quickly. A custody architecture that prevents reliable segregation or a management team without sufficient collective competence may require material operational change.

The most effective remediation plans rank findings by regulatory impact, implementation time and dependency. For Atlas, the custody-control redesign must come before finalising disclosures and application narratives, because both depend on the real operating model. Governance documentation and AML quality assurance can progress in parallel, while supplier contract renegotiation may take longer and needs early engagement.

Management should assign one accountable owner per action, a realistic completion date and a defined item of closing evidence. “Update policy” is not an adequate action. “Approve revised wallet reconciliation procedure, complete 30 days of daily reconciliations, independently test exceptions and present results to the board” is measurable and credible.

A final mock regulator review is valuable once remediation is complete. Ask the questions a reviewer will ask: Why is this jurisdiction appropriate? Who controls customer assets? What happens if your custody provider fails? How do you detect suspicious transfers? Which director owns the decision? If answers differ between legal, compliance, operations and technology teams, the firm is not ready.

For businesses building towards MiCA authorisation, early audit work is usually faster and less expensive than correcting contradictions during a live regulatory review. NUR Legal approaches these projects as an execution exercise: align the legal framework, operating model and evidence before they are tested under pressure. The useful closing test is straightforward - build a CASP that can explain, evidence and defend every critical control on its first request from the regulator.

 
 
 

Comments


Contact

NUR Legal OÜ

Registry code: 17142784

VAT nr. EE102815012

+37258339358

  • Facebook
  • Телеграмма
  • Linkedin
  • Instagram
NUR Legal map_edited.jpg

Thanks for submitting!

JURISFIN Verification Badge

News & Articles •  Terms of UsePrivacy Policy
© 2026 NUR Legal All rights reserved.

bottom of page