Top 5 Compliance Steps for CASPs After Registration
Five daily compliance controls CASPs must run after registration: governance, AML/Travel Rule, client asset segregation, reporting, ICT risk.

Getting registered is just the start. If I run a CASP, I still need five controls working every day: governance, AML and sanctions, client asset segregation, reporting, and ICT risk and customer treatment.
Here’s the short version:
- Governance: I need clear owners, board reporting, and written controls.
- AML and Travel Rule: I need KYC, screening, transaction checks, and fast suspicious activity reporting.
- Client assets: I need separate wallets, separate fiat accounts, and daily reconciliations.
- Reporting: I need clean records, audit trails, and incident notices filed on time.
- ICT and customer treatment: I need system security, recovery plans, plain-language risk disclosures, and complaint handling.
A few facts make the point clear:
- The EU Travel Rule applies to all CASP-to-CASP transfers, with no minimum amount.
- For self-hosted wallet transfers above €1,000 (about $1,090 on July 22, 2026, exchange rates vary), wallet control checks are part of the process.
- EU authorities logged 3,383 major ICT incidents in the first DORA reporting period, and about one-third had cross-border impact.
- Coinbase Europe was fined €21.5 million for AML control failures, including delayed suspicious transaction reporting.
If I had to reduce the whole article to one idea, it would be this: registration gives a CASP market access, but daily control work keeps that access in place.
| Step | What I need to keep in place |
|---|---|
| 1. Governance | Clear roles, board oversight, policy reviews, records |
| 2. AML, Sanctions, Travel Rule | CDD/EDD, sanctions screening, transfer data, STR filing |
| 3. Client Asset Protection | Segregated wallets and accounts, custody records, reconciliations |
| 4. Reporting and Audits | Recordkeeping, notices, incident reporting, audit follow-up |
| 5. ICT Risk and Customer Treatment | Security controls, recovery plans, disclosures, complaints logs |
Bottom line: if I want a CASP to stay in good standing after registration, I can’t treat compliance as a one-time approval project. I need it built into daily work.
5 Post-Registration Compliance Controls for CASPs
Why Post-Registration Compliance Matters
Authorization is the starting line, not the finish line.
Once a CASP is registered, regulators expect day-to-day oversight to stay in place. That means current policies, active monitoring, and clear lines of responsibility. ESMA has said that all CASPs should be treated as high-risk when compared with old-line financial firms because they operate across borders and rely on tech-driven, often pseudonymous transactions. That shows up in almost every part of the business: governance, AML, custody, reporting, and security.
If compliance slips, the fallout can be serious. Firms can face fines, limits on services, and damage to their name in the market.
There’s also a practical side to this. Banks and payment providers usually want to see strong AML, governance, and reporting controls before they’ll keep accounts open or provide access to payment rails.
In the EU, day-to-day compliance for CASPs is shaped by MiCA, AML/CTF rules, the Travel Rule, and DORA. MiCA covers services, disclosures, and the safeguarding of client assets. AML/CTF rules require identity checks, transaction monitoring, sanctions screening, and suspicious activity reporting. The Travel Rule requires originator and beneficiary information to travel with crypto transfers, with no minimum threshold. DORA requires CASPs to manage ICT risk, test resilience, and report major incidents.
Taken together, those rules turn post-registration compliance into a set of five controls that CASPs need to keep in place after registration.
1. Establish Governance and Compliance Oversight
After registration, governance becomes the day-to-day control hub for compliance. This is where post-registration work starts. The goal isn't to have controls that look good in a policy binder. They need to work in daily operations. Under MiCA Article 68, CASPs must keep documented lines of responsibility, effective risk identification and reporting processes, and adequate internal controls.
Your full firm should be covered by three functions: risk management, compliance, and internal audit. One executive board member should own the internal control and risk framework. Duties also need to be split where conflicts could happen, so one person isn't controlling both sides of the same issue.
Appoint a Chief Compliance Officer and MLRO with clear mandates, enough resources, and direct access to the board. Smaller CASPs may combine these roles, but the functions still need to be formally documented and clearly separated. Keep records on a durable medium for five years, or seven years if the competent authority requests it.
That recordkeeping should cover items such as:
- Governance minutes
- Approvals
- Risk assessments
- Policy versions
- Incident logs
- Compliance reports
All of it should be stored in a format that can be retrieved and audited.
This setup also depends on steady reporting. Report to senior management or the board at least once a year, and sooner when a material issue comes up. A board-approved compliance calendar helps keep policy reviews, risk assessments, and reporting deadlines on track.
2. Set Up AML, Sanctions, and Travel Rule Controls
AML and sanctions compliance is the next key layer. CASPs are regulated firms with full AML duties under EU AML rules, and they must apply full AML/CFT controls right away. The main EU rules here are the AMLR (Regulation (EU) 2024/1624) and the updated AMLD6 (Directive (EU) 2024/1640). Travel Rule duties come from the Transfer of Funds Regulation (TFR, Regulation (EU) 2023/1113), which applies to crypto-asset transfers.
The best way to tackle this is simple: start with risk assessment, then move into screening, transfer checks, and reporting.
Your AML program should be risk-based from day one. Start with a firmwide risk assessment that maps risk across product, geography, channel, and wallet type. From there, build tiered customer due diligence. Use standard CDD for most users, and apply Enhanced Due Diligence (EDD) to politically exposed persons, customers from higher-risk jurisdictions, and cases with layered ownership structures. Full CDD also applies to occasional transactions of €1,000 or more, and CDD plus transaction records must be kept for five years.
Sanctions screening needs to sit inside both onboarding and ongoing monitoring. Screen customers and transactions against EU consolidated lists, and keep list management current so new measures are put in place fast. That includes the latest EU sanctions updates that affect crypto services.
The Travel Rule adds another layer to day-to-day operations. Under the TFR, CASPs must collect and send originator and beneficiary data with relevant crypto transfers. The EU applies a no-minimum-threshold rule to CASP-to-CASP transfers, which means Travel Rule data must go with all such transfers, no matter the amount. For transfers involving self-hosted wallets above €1,000, CASPs must verify that the customer controls the wallet, often through a signed message or a small test transfer.
This part can't live in a spreadsheet off to the side. These checks need to work inside onboarding and transfer systems, not as manual add-ons. Build them directly into onboarding and transfer flows.
Suspicious transaction reports must be filed promptly with national Financial Intelligence Units whenever there are reasonable grounds to suspect money laundering, terrorist financing, or a sanctions breach. And regulators have already shown they won't be soft on this. The Central Bank of Ireland fined Coinbase Europe €21.5 million for delayed STR reporting and poor transaction monitoring.
To keep all of this under control, maintain:
- A central compliance register
- A policy suite
- A case management system for STRs and sanctions alerts
With financial crime controls in place, the next priority is safeguarding client assets.
3. Safeguard and Segregate Client Assets
Once AML controls are in place, CASPs need to lock down custody. The next step is protecting client assets in both legal and day-to-day terms. In plain English, custody controls can't live only on paper. They need to show up in wallets, ledgers, and account structures.
MiCA Articles 70 and 75(7) are the main legal sources here. Article 70 says CASPs must protect clients' ownership rights and stop client assets from being used for the CASP's own account. Article 75(7) says client crypto-assets must be kept apart from the CASP's own holdings in separate wallet addresses, with control keys and access credentials clearly identified.
In practice, legal segregation and operational segregation have to work side by side. Legal segregation keeps client assets ring-fenced from the CASP's estate under the applicable legal framework. Operational segregation means separate wallets, systems, and records - not just a line in the books. Hot wallets should be used only for limited liquidity, while most client assets should sit in cold storage.
For client fiat funds, MiCA requires deposits with a credit institution or central bank by the next business day after receipt, in separately identifiable accounts that are never mixed with the CASP's own funds. A common setup is a safeguarded account for client funds, plus a separate internal settlement account for deposits and withdrawals.
CASPs also need a register of positions for each client and a custody policy that covers:
- key management
- incident response
- backups
- multi-signature or MPC controls
Daily reconciliations matter here. Compare on-chain balances, internal ledgers, and bank accounts every day so gaps show up early, not after the damage is done.
Weak segregation usually surfaces later in reconciliations, reporting, and incident reviews. Co-mingling client and corporate assets, using customer funds for proprietary purposes, and keeping poor position records all increase insolvency and misuse risk.
4. Keep Up with Regulatory Reporting, Audits, and Incident Notifications
Once client assets are segregated, the next step is simple in theory and tough in practice: keep clean records and report issues on time.
Under MiCA, along with the EU AML rules and DORA, regulators will expect a clear paper trail. CASPs must keep records of crypto-asset services, activities, orders, and transactions so competent authorities can review your activity without delay. That recordkeeping supports day-to-day supervision and more focused investigations when something looks off.
There’s also a notification layer. You need to file required notices for material business changes and complaints. And if you offer trading-related services, the bar gets higher: submit a suspicious transaction and order report (STOR) immediately when market abuse is suspected.
When systems go down, timing matters even more. Major ICT incidents come with shorter reporting windows under DORA. Submit major ICT incident reports within the applicable deadlines, starting with an initial report and then intermediate updates.
If the incident disrupts services, clients shouldn’t be left guessing. Tell them:
- the expected recovery time
- the impact on services
- the cause of the incident
- any risks to client funds
- the remediation steps underway
Then comes the part many teams put off until it hurts: internal review. Reporting is one thing. Proving that you fixed the problem is another.
ESMA expects written compliance and internal audit reports to reach executive management at least once a year, and earlier when issues come up. Those reports should spell out what failed, what changed, and who owns the fix. In plain English, an audit report shouldn’t just say there was a problem. It should show whether the problem was addressed, by whom, and by when.
A good reporting calendar helps keep all of this from turning into chaos. Tie every item to a clear owner, a due date, and a remediation status so nothing slips through the cracks.
sbb-itb-0796ce6
5. Build In Risk Management, ICT Security, and Consumer Protection
Reporting matters. But for CASPs, the bigger job is stopping problems before they turn into incidents. That means putting solid controls around risk management, system security, and how customers are treated.
Under MiCA and DORA, CASPs must run resilient, secure ICT systems, backed by business continuity and recovery plans.
And this isn't just a box-checking exercise. ICT risk is material. EU authorities recorded 3,383 major ICT incidents across financial entities in the first DORA reporting period, and about one-third had cross-border impact. That tells you a lot. Resilience testing and incident logging aren't optional admin tasks. They're part of day-to-day operations.
Consumer protection sits in the same control framework as risk and ICT security. CASPs must give customers risk disclosures that are clear, fair, and not misleading. Those disclosures need to cover:
- volatility
- the possibility of total loss
- cyber risks
They also need to be written in plain language and shown before a transaction is confirmed.
That same standard carries into complaints handling. CASPs need documented procedures, set response timelines, and a complaints register that tracks issues and patterns over time. For higher-risk products, document suitability.
Just as important: keep evidence. If a control exists, you should be able to prove it exists.
Maintain one risk register with named owners for:
- operational risks
- ICT/cyber risks
- market risks
- liquidity risks
- legal risks
- compliance risks
- conflict risks
- integrity risks
Alongside that, keep ICT incident logs, third-party provider registers, complaint records, and testing evidence. Significant entities must also complete threat-led penetration testing every three years.
CASP Compliance at a Glance
Use this table as a quick ownership map for the five post-registration duties. Each control should have one clear owner and one reporting cadence. The point is simple: turn the five duties into named owners and set deadlines that people can actually follow.
| Compliance Step | Main Obligation | Typical Controls | Reporting Cadence | Primary Owner |
|---|---|---|---|---|
| 1. Governance & Compliance Oversight | Maintain board-level accountability and independent oversight. | Board charter; policy suite; RACI matrix; training plan. | Internal compliance dashboard: monthly or quarterly; board reports: at least annually; regulator interactions: ongoing. | Board of Directors, with the CCO accountable for day-to-day oversight |
| 2. AML, Sanctions & Travel Rule Controls | Run risk-based AML, sanctions, and Travel Rule controls. | KYC/KYB; screening; transaction monitoring; Travel Rule workflow; SAR process. | Transaction monitoring alerts: daily or near real-time; suspicious activity reports: event-driven; AML effectiveness review: annually. | MLRO / Head of Financial Crime |
| 3. Safeguard and Segregate Client Assets | Keep client crypto-assets and funds separate from the CASP's own assets and protect client ownership rights. | Segregated wallets and accounts; daily reconciliations; custody logs; key-loss playbook. | Reconciliations: daily for hot wallets and at least weekly for cold storage; segregation review: quarterly; custody audit: annually. | COO / Head of Custody or Operations |
| 4. Regulatory Reporting, Audits & Incident Notifications | Meet ongoing supervisory reporting, audit, incident-notification, and material-change obligations on time. | Reporting calendar; templates; incident register; audit engagement; material-change notices. | Supervisory returns: quarterly or annually; incident notifications: within the applicable deadline; audited financials: annually. | CCO for regulatory reporting; CFO for financial returns; CISO/CTO for ICT incidents |
| 5. Risk Management, ICT Security & Consumer Protection | Maintain a resilient ICT environment and treat customers fairly through clear disclosures and complaint handling. | Risk register; incident logs; vulnerability management; testing schedule; disclosure templates; complaints workflow. | Risk dashboard and KRIs: monthly or quarterly; ICT security reports: monthly plus event-driven; complaints metrics: monthly. | CRO where present; otherwise CCO for conduct and CISO/CTO for ICT |
This table is a working reference, not legal advice. Local rules may add obligations.
The next section shows the gaps CASPs most often miss.
Post-Registration Compliance Gaps to Avoid
Even strong controls can fall apart if no one keeps them in shape.
One of the most common mistakes is treating authorization like the end of the road. It isn't. Rules, guidance, and supervisory expectations keep shifting after registration. That’s why firms need an annual compliance plan, quarterly horizon scans, and steady board reporting to stay on track.
Another weak spot is under-resourcing. When teams are stretched too thin, routine work starts slipping. Missed filings, slow reporting, and delays in transfer controls often come from the same problem: not enough people, time, or systems to handle the workload.
Travel Rule failures are still common. CASPs need transfer workflows built into day-to-day operations, not patched on later. That includes full sender and recipient data capture, wallet ownership checks, and exception logs.
Weak client-asset reconciliation is another serious gap. Daily checks matter. If there’s a break, fix it right away. In many cases, reporting gaps come from the same weak control setup.
Late incident reporting and vague disclosures can also cause avoidable supervisory and conduct risk. Clear internal triggers help teams know when to escalate. Plain-language disclosure templates help make sure the message is clear when it counts.
Conclusion
Registration is the starting line for supervision. It doesn’t mean compliance is done. The five controls above are the practical framework.
In day-to-day work, that means governance, AML, client asset safeguarding, reporting, and ICT and consumer protections need to show up in routine operations: reconciliations, monitoring, board reporting, staff training, and customer communications. Strong controls help CASPs stay compliant, keep trust with customers and regulators, and keep the business running after registration.
FAQs
Who should own each compliance control?
Ownership needs to be shared across the company. Senior management and legal teams set AML/KYC policy and make sure the business follows EU rules such as MiCA and the Travel Rule.
Compliance teams run risk assessments, handle due diligence, and monitor transactions. Technical teams keep surveillance and verification tools working as they should. And all employees need regular training so they understand their part in spotting, reporting, and helping stop illicit activity.
What records should a CASP keep after registration?
After registration, CASPs need to keep clear, accurate records of:
- customer transactions
- identity verification documents
- reported suspicious activities
- asset pricing at the time of each transaction
In plain terms, this means keeping a paper trail that shows who the customer was, what happened, when it happened, and what the asset was worth at that moment.
These records must generally be kept for at least five years after the business relationship ends. That retention period helps support compliance and accurate reporting.
How often should a CASP review its controls?
CASPs should monitor customer transactions and activities on an ongoing basis to spot suspicious behavior as it happens, not weeks later.
They should also review customer risk levels on a regular schedule, apply enhanced due diligence and closer monitoring to higher-risk customers, and update policies and procedures as regulations, threats, and risks change.