Home › Academy › Library › Final Report Draft RTS on the criteria for the…
Synthesis note · Standard

Final Report Draft RTS on the criteria for the appointment of CCP for CASPs and with rules on their functions

European Banking Authority (EBA) · 2025 · Standard · 26 pages · Intermediate

This final report presents regulatory technical standards regarding the appointment of central contact points for payment service providers, electronic money issuers, and crypto-asset service providers in the EU. These contact points are essential to ensure compliance with anti-money laundering and counter-terrorism financing obligations in host member states. The report also outlines the next steps for the…

General Information

This document is the final report of the Regulatory Technical Standards (RTS) prepared by the European Banking Authority (EBA) in 2025. It concerns the amendment of Delegated Regulation (EU) 2018/1108 relating to the criteria for the appointment of central contact points for electronic money institutions (EMIs), payment service providers (PSPs) and crypto-asset service providers (CASPs), as well as the rules governing their functions, pursuant to Article 45(10) of Directive (EU) 2015/849. The scope covers AML/CFT (anti-money laundering and counter-terrorist financing) obligations applicable to establishments of these entities in EU Member States, notably when these establishments are not obliged entities themselves. The document comprises 26 pages and fits within the current and forthcoming European regulatory framework, notably in connection with legislative developments of 2023 and 2024.

Executive Summary

The report addresses the update of the regulatory technical standards governing the appointment of central contact points for PSPs, EMIs and now CASPs operating in an EU Member State other than that of their registered office. This update is necessary following the extension of the scope of Directive (EU) 2015/849 to CASPs by Regulation (EU) 2023/1113, applicable from 30 December 2024 (p. 3-4). The central contact point acts on behalf of the appointing entity to ensure compliance with local AML/CFT obligations, thereby facilitating supervision by the competent authorities of the host State. The EBA chose to amend the existing Delegated Regulation (EU) 2018/1108 rather than fully replace it, in order to limit disruptions for PSPs and EMIs and to maintain a proven approach (p. 13-15). The criteria for appointing a central contact point for CASPs are aligned with those applicable to PSPs and EMIs, with a specific adaptation considering the nature of crypto services, notably a monetary threshold set at 3 million euros of cumulative value of services or activities in the host State per financial year (p. 9, 21-22). The report highlights that appointment may also be required based on the ML/TF risk level, even if the threshold is not met, according to a proportionate and risk-based approach (p. 9, 18). The functions of the central contact point include facilitating AML/CFT compliance, communicating with local authorities, supervising establishments and training staff (p. 10-11). The public consultation conducted between December 2024 and February 2025 received nine responses, generally favorable, but allowed refinement of certain aspects, notably clarification of the notions of threshold, establishment and risk, as well as removal of the acronym CCP to avoid confusion (p. 17-26). The document recommends publication of the amended regulation, which will be submitted to the European Commission, then to the Parliament and the Council, before implementation. This update aims to strengthen the coherence and effectiveness of AML/CFT supervision of CASPs while maintaining a balance between regulatory requirements and costs for the entities concerned.

Context and Objectives

PSPs, EMIs and CASPs authorized in an EU Member State may operate establishments in other Member States, and must comply with local AML/CFT obligations there, even if these establishments are not obliged entities themselves (p. 3-4). To facilitate AML/CFT supervision in these cases, host States may require the appointment of a central contact point on their territory, responsible for ensuring local compliance and representing the entity before authorities (p. 3-4). Article 45(10) of Directive (EU) 2015/849 mandates the EBA to develop regulatory technical standards defining the criteria for appointment and the functions of central contact points (p. 3-4). Initially limited to PSPs and EMIs, this framework must be extended to CASPs following the 2023 legislative amendment (p. 4). The objective is to adapt existing rules to the specificities of CASPs, notably considering their business model and practical particularities related to their notion of establishment (p. 5). The document aims to propose a proportionate update, based on a risk-based approach, minimizing disruptions for already regulated actors while ensuring effective supervision of CASPs (p. 5, 13-15). The scope excludes defining the form the central contact point must take, which remains at the discretion of Member States (p. 4).

Summary of Key Points by Theme

- Criteria for appointing the central contact point: The EBA maintains the structure of the 2018 regulation, extending the criteria to CASPs. Appointment is required if the cumulative activities in the host State exceed 3 million euros per financial year, or if the ML/TF risk justifies such a measure, even without exceeding the threshold (p. 9, 21-22). The notion of establishment now includes activities with limited physical infrastructure, notably internet services (p. 5, 24). The threshold calculation is based on the aggregated value of services provided, adapted to the diversity of crypto services (p. 22).

- Functions of the central contact point: It must ensure AML/CFT compliance of establishments, inform the entity of local requirements, supervise implementation of internal policies, report breaches, ensure staff training, and represent the entity before competent authorities and financial intelligence units (p. 10-11).

- Proportionate and risk-based approach: Appointment of the central contact point relies on a proportionate assessment of ML/TF risk, allowing Member States to adapt requirements according to local context and operational complexity (p. 9, 23).

- Public consultation and feedback: The consultation confirmed the relevance of the proposals, while highlighting needs for clarification on threshold, establishment, and risk notions. The 3 million euro threshold was maintained despite proposals for increase, justified by the risk level associated with CASPs, notably crypto-ATMs (p. 17-19, 21-22). The acronym CCP was removed to avoid confusion with central counterparties (p. 25). The form and location of the central contact point remain at the discretion of Member States, in line with the EBA mandate (p. 17-18, 25).

Main Findings and Lessons Learned

- Established facts: The existing regulatory framework for PSPs and EMIs is extended to CASPs, with a monetary threshold set at 3 million euros for appointing a central contact point. The functions of the central contact point are clearly defined and aim to ensure AML/CFT compliance and facilitate supervision (p. 3-11, 21-22).

- Assumptions: The risk-based and proportionate approach is adapted to the specificities of CASPs, notably the diversity of services and the nature of establishments (p. 5, 23).

- Interpretations: Maintaining the threshold at 3 million euros is justified by the high risk associated with crypto-ATMs and the need for effective supervision, despite concerns expressed during the consultation (p. 18-19, 22).

- Uncertainties: The practical definition of establishment for certain crypto services remains complex, but the reference to the 2024 regulation provides an interpretative framework (p. 5, 24). The variability of costs related to appointing a central contact point will depend on modalities set by each Member State (p. 22).

Conclusions and Recommendations

The EBA concludes that amending Delegated Regulation (EU) 2018/1108 to include CASPs within the framework for appointing central contact points is necessary and proportionate. The monetary threshold of 3 million euros is maintained, aligned with that of PSPs and EMIs, to ensure effective AML/CFT supervision, notably in view of the specific risks of crypto-assets. The functions of the central contact point are specified to ensure compliance and facilitate communication with authorities. The EBA recommends submitting the RTS draft to the European Commission for approval, followed by examination by the European Parliament and the Council, before publication in the Official Journal of the European Union. It emphasizes that the form and location of the central contact point remain at the discretion of Member States, respecting the principle of proportionality. Finally, the EBA recalls that the European Anti-Money Laundering Authority (AMLA) will have a complementary role from 2026, but without replacing the need for central contact points at the national level.

Key takeaways

References

Year
2025
Type
Standard
Level
Intermediate
Licence
Attribution required
Original document
https://www.eba.europa.eu/sites/default/files/2025-04/53283e48-b107-4…
Read the original document ← Back to the library

Synthesis note written from the full document by DataSAI Academy. This note comes from the scientific library of the DataSAI Academy, open to all.