MiCAR: Crypto Asset Service Providers

Continuous compliance, keeping your licence defensible

Onboard, map, show: your scope, worked end to end

Authorisation proved your framework once. Since then, new standards keep publishing, regulations overlap in the same policies, and supervisors test whether controls actually operated. Compliance is a costly endeavour, and the rulebook keeps growing.
Step 1
Onboard
The regulations that apply to your firm, loaded into Helia as structured source and maintained as they arrive, change and lapse.
Step 2
Map
Every atomic requirement traced to the policy or standard that evidences it, and to the control objective it drives.
Step 3
Show
Coverage computed from the mapping, with each gap named and a way to close it. Where you stand, on screen.

The regulations in scope, held as structured source

The AFM's good practices for licence applicants begin with scoping: determine which MiCAR rules apply to your organisation. The question does not stop at MiCAR. Most of the regimes that reach a CASP sit outside it. These form the standard scope for a Dutch crypto-asset service provider, and any other regulation is added on request.

The crypto core, onboarded as standard

MiCAR and Level 2 and 3
Prescriptive obligations, technical standards, templates and forms, including the knowledge and competence guidelines.
AML package
Single-rulebook obligations from July 2027, with standards and templates from AMLA.
Wwft
Risk-based obligations and AFM guidance, until the AML package replaces it.
Travel Rule
Data accompaniment obligations and EBA guidelines. Procedural, zero threshold.
Sanctiewet and EU sanctions
A thin framework carrying absolute obligations, with lists as operational data.
DORA
Obligations, technical standards and reporting templates, including the register of information.

The wider scope, added to the same map

Some of these bind every firm, some depend on a scope determination. Each joins the mapping you already run.
GDPR
Principles and obligations, with EDPB guidance.
DAC8
A reporting schema, due-diligence procedures and filing formats. First filing January 2027.
Consumer protection
Principles-based conduct rules, with Dutch consumer law as the national overlay.
PSD2 and PSR on EMTs
Conditional and authorisation-driven. Scope determination first.
NIS2, AI Act, MiFID II
Conditional on your structure, your technology and your entry route.
Your own additions
Anything else that reaches your firm joins the same scope.

The Impact Assessment, across your policy framework

1
Requirements embedded in policies and standards
Each regulation broken to atomic requirements, each requirement traced to the policy or standard that evidences it, and each gap named.
2
A leaner framework
Where regulations overlap, the shared requirement is worked once, so one obligation is not written into three documents in three forms.
3
Smart recommendations
Where embedment fails, Helia holds the wording that would close it, and the compliance officer approves, edits or rejects.
Recommendation AI
Addition: Add an explicit obligation that human oversight prevents risks to health, safety and fundamental rights from reasonably foreseeable misuse.

Your controls against the control objectives

1
Reuse what you already have
Existing controls linked to the control objectives derived from your requirements, before anything new is proposed.
2
Coverage stated, with the reasoning
Each objective covered, partially covered or not covered, with the argument behind the verdict traceable to source. Ready before a supervisor asks.
3
A control where you have none
Where nothing covers an objective, Helia proposes one benchmarked against the market, so a gap arrives with a way to close it.
Requirement CRR III
Control ICT-04
Policy v3.2
Reported figure Q2 board

The scope keeps moving

Change flagged at source
New technical standards, guidelines, sanctions listings and supervisory publications, picked up as they publish.
Impact scoped to your mapping
The message is not that a regulation has changed. It is which of your requirements, policies and controls the change touches.
New regulations join the same map
When something new reaches your firm, it extends the mapping you already run rather than starting a separate programme.

Built with institutions that answer to the same supervisors

We run this process inside the mature risk and compliance frameworks of large Dutch banks and insurers, under the AFM and DNB. Much of the ground is shared: DORA treats crypto-asset service providers, credit institutions and insurance undertakings alike as financial entities, and the AML regime, the Sanctiewet and the GDPR reach all of them. MiCAR, the Travel Rule and DAC8 are what make a CASP different. The method transfers, and we use it to help you mature your framework.

Next up

The requirements, policies and controls this page maps are held, versioned and evidenced in Regulatory Nexus.

Let us take you further

Schedule a 30 min call. No slide decks. Just a practical assessment of your needs and how we can help.