This final report presents the regulatory technical standards and implementing technical standards related to the authorization to offer to the public or seek admission to trading of asset-referenced tokens (ARTs) under the MiCAR regulation. It outlines the information requirements to be provided by legal entities seeking to obtain this authorization, as well as standardized procedures to ensure uniformity across…
This document is the final report of the European Banking Authority (EBA) published in 2024, entitled “Final Report on draft RTS and ITS on information for authorisation as issuers of ARTs under MiCAR.” It concerns the draft regulatory technical standards (RTS) and implementing technical standards (ITS) regarding the information to be provided in authorization applications to offer to the public or seek admission to trading of asset-referenced tokens (ARTs) under the European MiCAR regulation (EU) 2023/1114. The scope covers information requirements, application submission procedures, as well as evaluation modalities by competent authorities within the European Union. The document comprises approximately 68 pages, of which the first 37 were provided for this synthesis.
The EBA final report responds to the mandate of Article 18, paragraphs (6) and (7) of the MiCAR regulation, which requires that only legal entities established in the EU and authorized may offer to the public or seek admission to trading of ARTs. The EBA developed two technical standards: an RTS specifying the information to be provided in the authorization application, and an ITS establishing standardized forms, models, and procedures to ensure uniformity at the European level (p. 3-5). The RTS details the required information, notably the issuer’s identification, operations program (business model, strategy, risks, three-year financial forecasts including stress scenarios), internal governance (including critical third-party providers), liquidity and asset reserve management, as well as compliance with AML/CFT requirements (anti-money laundering and counter-terrorist financing) (p. 3-4, 7-9). The RTS also requires information on the reputation, skills, and time commitment of management body members, as well as the good reputation of shareholders holding qualifying holdings (p. 8, 27-31). The ITS complements the RTS by specifying application submission modalities, favoring electronic submission, and defining processing steps for incomplete or complete files, with standardized templates for the submission letter and application form (p. 4, 32-34). These standards aim to harmonize supervisory practices and ensure that authorities have complete and consistent information to assess issuers’ compliance with prudential and risk management requirements, while ensuring investor protection and financial stability. The report emphasizes that information must be accurate, complete, and updated until authorization, and that authorities may request additional information if necessary (p. 3, 12). Next steps include submitting the standards to the European Commission for approval, followed by adoption by the European Parliament and the Council.
The document was drafted to respond to the regulatory framework established by MiCAR, which governs the public offering and admission to trading of ARTs in the European Union. Article 16 of MiCAR limits these activities to authorized legal entities or credit institutions, with exemptions for small issuances (below 5 million euros) or exclusively for professional investors, subject to transparency (p. 6). The objective is to ensure harmonization of supervisory practices across the EU by precisely defining the information to be provided in authorization applications and the modalities of their submission. The mandate given to the EBA aims to specify this information (RTS) and standardize procedures (ITS) to facilitate prudent assessment of issuers, notably considering risks related to governance, reserve management, anti-money laundering, counter-terrorist financing, and operational resilience (p. 6-10). The document specifies that the methodology for application evaluation is addressed in other standards and guidelines, and that the granularity of requested information is adapted to the complexity and risk profile of issuers, with enhanced requirements for significant issuers (p. 7-9). The report also incorporates lessons from recent stablecoin failures and international recommendations, notably from the Financial Stability Board (FSB) (p. 8). Finally, consultations were conducted, including with the European Data Protection Supervisor, to ensure compliance with personal data protection rules (p. 9).
Issuer Identification: The application must contain detailed information on the issuer’s legal identity, contact details, legal status, registered office, as well as official documents such as statutes and registration certificates. For non-legal entities, a legal opinion attesting to equivalent third-party protection is required (p. 16).
Operations Program: The file must include the white paper and an operations program covering three years, describing the business model, strategy, risks, and financial forecasts in baseline and stress scenarios. The issuance, redemption, and distribution mechanisms of ARTs must be explained, notably the involvement of crypto asset service providers (CASP). The program must also present the competitive environment, market position, and a SWOT analysis (strengths, weaknesses, opportunities, threats) (p. 17-19).
Financial Information: The business plan must demonstrate the viability and sustainability of the business model, with detailed accounting forecasts (balance sheet, income statement, cash flow), capital requirements, and the constitution and management of asset reserves. Financial statements for the last three years are required, as well as information on indebtedness and guarantees (p. 20-21).
Internal Governance: The application must provide a clear description of the organization, operational structure, responsibilities of board members, human and technical resources, as well as internal policies (code of conduct, conflict of interest management, complaint handling, market abuse prevention, whistleblowing policy). Relationships with critical third-party providers must be detailed, including contractual arrangements and business continuity plans (p. 22-23).
Internal Control and Operational Resilience: The internal control framework must be described, including compliance functions, risk management, internal audit, and segregation of duties. Compliance with the DORA regulation on digital operational resilience is required, with detailed technical documentation on ICT risk management, system security, and business continuity capabilities (p. 23-25).
Distributed Ledger Technology (DLT): When ARTs are issued via proprietary or similar DLT, the issuer must explain its legal ownership or control, involved operators, technological risk management plans, independent audits, and transparency mechanisms, notably for permissioned DLTs (p. 24).
Anti-Money Laundering and Counter-Terrorist Financing (AML/CFT): Although ART issuers are not obliged entities under the AMLD directive, they must demonstrate that their business model does not present serious ML/TF risks. Issuance and redemption mechanisms must be designed to limit these risks, with a description of internal controls of involved CASPs, accompanied by a prospective compliance assessment over three years (p. 25).
Liquidity Management, Asset Reserves, and Redemption Rights: The file must include detailed policies on the constitution, composition, management, segregation, custody, and investment of asset reserves, as well as on the ART stabilization mechanism. Contracts with third-party providers must guarantee service continuity in case of redemption plan implementation, with semi-annual independent audits (p. 26-27).
Management Body Members: Each member must provide detailed personal information (identity, experience, judicial background, conflicts of interest, time commitment), allowing a comprehensive assessment of their reputation, skills, and availability. Collective evaluation of the body is also required (p. 27-30).
Shareholders and Members with Qualifying Holdings: The application must present the ownership structure, identity and reputation information of shareholders holding direct or indirect qualifying holdings, as well as links with management body members. The legitimate origin of funds used must be demonstrated (p. 30-31).
Standardized Procedures and Forms: The ITS specifies that applications must preferably be submitted electronically via the competent authority’s portal, with paper documents allowed for certain supporting evidence. It defines processing steps, completeness criteria, as well as standard templates for submission letters and application forms, ensuring harmonization at the European level (p. 32-34).
Findings: The EBA developed draft RTS and ITS compliant with the MiCAR mandate, specifying the information to be provided and procedures to be followed for authorization of ART issuers. Requirements cover identification, operations program, governance, risk management, AML/CFT compliance, operational resilience, as well as reputation and competence of executives and shareholders (p. 3-5, 7-31).
Assumptions: The report starts from the observation that no typical business model for ART issuers yet exists, and relies on lessons learned from recent stablecoin failures and international recommendations to define requirements (p. 8).
Interpretations: The granularity of requested information is justified by the need for prudent risk assessment for financial stability, investor protection, and prevention of money laundering risks. The distinction between public information in the white paper and confidential information in the authorization application is maintained, with some functional overlap (p. 7-9).
Uncertainties: The document does not cover the methodology for application evaluation, nor post-submission steps (ECB opinion, final decision), which fall under other standards or authorities. Moreover, the rapid technological evolution of DLTs requires some flexibility in technology descriptions (p. 7, 24).
In summary, the draft RTS and ITS provide a clear and comprehensive framework for collecting necessary information for harmonized and rigorous supervision of ART issuers in the EU.
The EBA concludes that the draft RTS and ITS meet the requirements of the MiCAR regulation by providing a detailed and harmonized framework for submission and evaluation of authorization applications of ART issuers. These standards ensure that competent authorities will have complete, accurate, and up-to-date information, enabling prudent risk assessment related to governance, operations, reserve management, AML/CFT compliance, and operational resilience (p. 3-5, 12-31).
The report recommends submitting the drafts to the European Commission for approval, followed by publication in the Official Journal of the European Union after review by the European Parliament and the Council (p. 5).
It also highlights the need for authorities to be able to request additional information if necessary, and to ensure personal data protection in accordance with the GDPR and Regulation 2018/1725 (p. 12-13).
Finally, the report stresses the importance of uniform application of these standards across the EU to ensure the stability of the crypto-asset market and investor protection.
Synthesis note written from the full document by DataSAI Academy. This note comes from the scientific library of the DataSAI Academy, open to all.