What organisational and conduct requirements applied to registered CASPs?
The Board, people, systems and controls a registered CASP needed, how it had to inform clients, the penalties for breaches, and where the same ideas now sit in MiCA.
By the ExamPass CY editorial teamLast reviewed 6 min read
Topic 4 of 5 · all topics in this chapter
Short answer
A registered CASP needed a Board of at least four honest and competent members, two directing the business and two independent; fit and proper managers and qualifying shareholders; clear reporting lines; AML/CFT procedures; controls to minimise theft or loss of clients' crypto-assets and unauthorised access; enough own funds; and pay that does not encourage aggressive selling. Information to clients, including marketing, had to be accurate, clear and not misleading. Breaches could bring CySEC sanctions, and failing to register has been a criminal offence since 2023. MiCA now sets comparable requirements.
Organisational requirements at a glance
| Area | Requirement |
|---|---|
| Board | At least four honest and competent members: two direct the business and two are independent |
| People | Managers honest and competent with enough time; qualifying shareholders (beneficiaries) of good reputation and able to keep the firm financially sound; staff honest, professional and knowledgeable |
| Multiple functions | Only if they do not, and are not likely to, stop staff working with diligence, honesty and professionalism |
| Remuneration | No pay, sales targets or evaluation that conflict with clients' best interests or encourage aggressive promotion |
| Systems and controls | AML/CFT procedures; minimising theft or loss of clients' crypto-assets; security against unauthorised access and data leakage; business continuity and data recovery; records; complaints handling |
| Information to clients | Accurate, clear and not misleading; marketing identified as such; timely information on the firm, services, costs and charges |
| Penalties | Administrative fines under Article 59(6): up to €1 million or twice the benefit, plus up to €1,000 a day, and since 2025 up to €5 million or 10% of turnover; failing to register an offence since 2023 (up to 5 years and/or €350,000) |
Source: CySEC Directive R.A.D. 269/2021, as amended, paragraphs 6 and 13 to 15; Law 188(I)/2007, Articles 59(6) and 61E; Regulation (EU) 2023/1114 (MiCA), Articles 66 to 74.
What did CySEC require of a CASP's Board and people?
Everyone in a management position had to be honest and competent: of good reputation, with enough knowledge, skills and experience, and with enough time for the role. A lack of experience on the Board was a reason for CySEC to refuse registration. The Board itself had to have at least four such members, two of whom directed the business and two of whom were independent. The national rules set no residency requirement for directors; MiCA now requires at least one director to be resident in the EU.
Shareholders with a qualifying holding (the beneficiaries) had to be of good reputation and able to keep the CASP financially sound, and the CASP's close links with other persons must not prevent CySEC from supervising it effectively. Governance had to be sound, with clearly defined and transparent reporting lines. Staff had to be honest, professional and knowledgeable for their tasks, and could hold several functions only if that did not, and was not likely to, stop them working with diligence, honesty and professionalism.
Pay and performance assessment must not conflict with the CASP's duty to act in its clients' best interests. In particular, the CASP could not use remuneration, sales targets or similar arrangements that might push staff towards aggressive promotion of products or services.
Terms used in this note
- Independent Board member
- A Board member with no present or recent links to the CASP or its other Board members that could affect their independent judgement.
- Own funds
- The capital a firm holds to absorb losses, measured against minimum amounts set by its regulator.
- Aggressive promotion
- Pushing products or services on clients in a way that puts sales ahead of the clients' interests.
What systems and controls did a CASP need?
A CASP had to have AML/CFT policies and procedures covering its executives, employees and anyone it outsourced functions to, and policies, systems and controls for prudent operation, including keeping to a minimum the risk that clients' crypto-assets are stolen or lost. It needed security mechanisms to protect the transfer of information, limit data corruption and unauthorised access and prevent leaks, and it had to hold enough own funds.
Other requirements were those of any well-run financial firm: sound administrative and accounting procedures, internal controls and risk assessment; an independent internal control function where the size and complexity of the business called for one; business continuity and data recovery arrangements; care when outsourcing critical functions, so that neither internal control nor CySEC's supervision suffered; records of all activities sufficient for supervision; and a complaints procedure. A CASP operating online needed a website that it owned and used exclusively, unless it had assessed and mitigated the risks and CySEC did not object.
How did a CASP have to treat clients, and what were the penalties?
Anything said to clients or prospective clients, marketing included, had to be accurate, clear and not misleading, with marketing labelled as marketing. The CASP had to tell clients in good time about itself, its services and what they would pay, in a way that let them understand the service, the crypto-assets on offer and their risks well enough to make an informed decision. A standard format could be used.
Breaches of the Directive count as breaches of Article 61E, so CySEC could impose administrative sanctions under Article 59(6) of the AML/CFT Law: fines of up to €1 million, or up to twice the benefit gained if higher, plus up to €1,000 for each day a breach continues. Since Law 96(I)/2025 made CASPs financial organisations, the higher ceiling for financial organisations, up to €5 million or 10% of annual turnover, also applies. Since October 2023, failing to register when required has been a criminal offence punishable by up to five years' imprisonment, a fine of up to €350,000, or both. The registration conditions did not cover market risk or the residency of directors.
Since 1 July 2026 these national rules have given way to MiCA, which sets comparable duties for authorised CASPs: a registered office and effective management in the EU, with at least one EU-resident director but no minimum Board size; acting honestly, fairly and professionally in clients' best interests and giving fair, clear and not misleading information; minimum capital of €50,000, €125,000 or €150,000 depending on the services, or a quarter of fixed overheads if higher; fit and proper management and shareholders; safekeeping of clients' crypto-assets and funds where the CASP holds them; complaints handling; conflicts of interest; outsourcing; and orderly wind-down plans for CASPs providing custody, trading platform, exchange, execution or placing services.
How to think about it
Picture a sound, client-first firm. The Board has at least four fit and proper members, two running the business and two independent; managers, qualifying shareholders and staff are honest and competent; reporting lines are clear. Controls protect clients' crypto-assets from theft, loss and hacking; pay does not reward aggressive selling; information is accurate, clear and not misleading. The national registration conditions did not include residency of directors or managing market risk.
Common mistakes
Putting the Board minimum at two or three members. At least four members were required: two directing the business and two independent.
Adding a residency rule for directors. The national registration conditions set none; MiCA now requires at least one EU-resident director.
Listing market risk among the required safeguards. The controls were about theft or loss of clients' crypto-assets, unauthorised access and AML/CFT compliance.
Letting sales targets drive staff pay. Remuneration must not conflict with clients' best interests or encourage aggressive promotion.
Legal references
- CySEC Directive for the register of crypto-asset service providers (R.A.D. 269/2021), as amended (opens in a new tab)
Paragraph 6: registration conditions and organisational requirements · Paragraph 13: information to clients · Paragraph 14: own funds · Paragraph 15: conflicts of interest
- The Prevention and Suppression of Money Laundering and Terrorist Financing Law of 2007 (Law 188(I)/2007), consolidated Greek text on CyLaw (amendments up to Law 25(I)/2026) (opens in a new tab)
Article 59(6): administrative sanctions · Article 61E(7), (9), (10), (11) and (13): organisational requirements, fitness and probity, Directives and the offence
- Regulation (EU) 2023/1114 on markets in crypto-assets (MiCA) (opens in a new tab)
Article 59: authorisation and EU presence · Articles 66 to 74: obligations of all CASPs · Annex IV: minimum capital
Practise this topic
Test what you just read
The Chapter 8 pack has 35 exam-style questions, 10 of them on this topic. Every question has a hint before you answer and a full explanation after.
Or revise the numbers first with 15 free Chapter 8 flashcards →