Skip to content
← The MiCA course

Section 6 of 9

Running the licence

Section 5 ended with a grant; this section is the day after. Nine modules, in the order the work actually happens, each answering one operational question twice — what the desk does, and what it means at the board — with the instrument and its lifecycle stage cited underneath. Read one module a day for two weeks and the stack is yours.

In one screen · section 6 of 9

WHAT THE ASSET ISWHO YOU ARE, AND WHAT YOU OWETHE LAW IN MOTIONTHE UMPIRE’S LADDERINSIDE MiCAEvery assetThe sortfinancial instrument? · 9 guidelinesFinancial instrument→ MiFID II, out of MiCAUnique & non-fungible→ excluded, Art 2(3)ARTTitle IIIEMTTitle IVOther crypto-assetTitle II · incl. utility tokensIssuer / offerorSeeking admissionto tradingCASPthe ten servicesNon-EU firmthe perimeterThe licenceauthorisation · the fileThe operating stackthe day-to-day dutiesIssuer rulebook — Titles III & IVwhite paper · own funds · reserve · redemptionThe moving edgeconsultation → final report → Commission → OJ → appliesPracticeclosed recordsCourt of Justicethe final wordEuropean Commissionmakes Level-2 lawESMA · EBAdraft, converge, answerYour NCAone of 30 supervisorsYour management bodythe first umpire
The whole regime, one map — this section's territory is lit; every section lights its own.

The operating stack: complaints, continuity, record-keeping, conflicts, platform duties, market-abuse watch, conduct rules — each with its instrument, its stage, and its desk work.

How to read a module

Every card below has the same anatomy. The heading is the question the module answers. “At the desk” is imperative — the things Ines actually does. “In the boardroom” is consequence — what Viktor and the board are answerable for. The So what line is an instruction to your hands. And the footer is where citations live: every instrument named, at its registry lifecycle stage, with a link to the official text. Where a footer row is a guideline, its comply-or-explain nature is stated on the stage line itself.

The perimeter modules that precede these — the sort, reverse solicitation, whose-rules-are-these — are taught from scratch in Sections 2 and 3; the full reference surface with all thirteen modules stays at MiCA in operation.

Check yourself

A footer row on one of the cards below reads 'guideline · comply-or-explain'. Who is bound by it, and how does it reach your firm?

When each rule started biting

2024 H220252025 H22026Titles III–IV applyMiCA applies in full2024/28612024-12-032025/2942025/2992025/4162025/4172025/3052025/3062025/4142025-03-05 – 04-202025/11402025/11422025-06-302025/8852025-09-092024/29842025/4212025-12-23
When each act in the operating stack started biting — applies-from dates drawn from the instrument registry at build, against MiCA’s own two Level-1 application dates.

What actually goes in the authorisation file?

The Level-1 list looks like nineteen items. The RTS underneath it is far more demanding — and it is the document the case officer actually reads against.

At the desk

  • Draft the programme of operations as a three-year commitment: group strategy, every activity regulated or not, target countries with client numbers, websites and languages, outsourcing named and located, forecasts with stress scenarios.
  • Build the AML section to the RTS's shape: your own inherent-and-residual risk assessment, a copy of the policies themselves, the named AML officer with evidence of competence, the training plan.
  • Describe segregation to the key-ceremony level: how keys are approved, how omnibus wallets separate one client from another, funds to a credit institution by close of the next business day.
  • Submit on the mandatory form. A mid-assessment change to the file restarts the clock — notify nothing avoidable.

In the boardroom

  • The programme of operations is what you will be supervised against. Changing the permission set later is a fresh application, assessed on the same clock.
  • Budget more senior time and external spend for this file than for any other phase of the journey — and budget it before the filing date is promised, not after.
Exhibit · What one authority's intake actually looks like
  • One PDF per information point, I to XVII — general information through custody policy and trading-platform rules
  • File names following the structure of the form, with exact references back to its numbered points
  • Submission through the authority's platform, access issued by email before filing
  • Non-applicability of any point justified in writing — never left blank
  • Any change to submitted documents notified immediately, in writing, while the procedure runs

The Austrian FMA's Art 62 application form (EN, held) — the EU-wide CIR 2025/306 template, expanded with the CDR 2025/305 catalogue

So whatOpen the RTS next to your draft file and tick article by article. The application journey dossier then walks the whole process with the statutory clocks — read it before the board asks for a date.

the information catalogue, article by article · Commission Delegated Regulation (EU) 2025/305 · applicable — this binds · verified 2026-08-26 · Read the text ↗
the mandatory form and the procedures around it · Commission Implementing Regulation (EU) 2025/306 · applicable — this binds · verified 2026-08-26 · Read the text ↗

Verified: 2026-08-27 — RTS/ITS and the held FMA form re-read

Who may run the firm — and who may own it?

Two gates on people: the board is assessed one by one and as a collective, and anyone buying a qualifying stake is assessed all over again.

At the desk

  • Assemble per-member proof: no convictions or penalties in AML, fraud, financial services, insolvency or professional liability — and evidence the board collectively knows this business.
  • Treat competence as qualifications and experience together: national practice expects hands-on time, ordinarily with a regulated firm, with supervised practice as the bridge where one limb is thin.
  • Trace ownership to ultimate beneficial owners before someone else does. A qualifying holding is 10% or significant influence — and an acquisition triggers its own assessment with its own file.

In the boardroom

  • Your own record is now a regulatory filing. Disclosure is survivable; discovery is not.
  • An unready shareholder can stall the firm's application: qualifying holders supply their own fit-and-proper evidence, on the firm's timetable.

So whatKeep a living suitability file per board member and per qualifying holder — assessed at appointment and on every change. The Malta and Austria panels on this page show two supervisors running exactly this check, differently.

the Union standard for a fit management body · Joint EBA/ESMA Guidelines on the suitability assessment of members of the management body of issuers of ARTs and of CASPs (EBA/GL/2024/09; ESMA75-453128700-10) · issued guidelines — comply-or-explain, binding authorities rather than firms · verified 2026-08-26 · Read the text ↗
what a proposed qualifying holder must file · Commission Delegated Regulation (EU) 2025/414 · applicable — this binds · verified 2026-08-26 · Read the text ↗

Verified: 2026-08-27 — the joint guidelines and the RTS re-read; national layer per the NCA panels

What must happen when a client complains?

Complaint-handling is specified to the template level — filing, acknowledgment, investigation, decision, and how you talk to the complainant throughout.

At the desk

  • Publish the procedure and the standard complaint template; let clients file by the stated means and languages.
  • Acknowledge receipt, verify admissibility, and investigate on the clock your own published timeline sets — then issue a reasoned decision and say what happens next.
  • Keep the complaint file: the register of complaints, the communications, the measures taken in response.

In the boardroom

  • The complaints book is the first thing an examiner samples, because the rules make you keep exactly the records that show how clients are actually treated. A tidy book is the cheapest credibility the firm can buy.

So whatTime-stamp your last five complaints end to end and compare them against your published procedure. The gap between the two documents is your finding before it is anyone else's.

Commission Delegated Regulation (EU) 2025/294 · applicable — this binds · verified 2026-08-26 · Read the text ↗

Verified: 2026-08-27 — the RTS article structure re-read in the held text

What must keep running when something breaks?

Continuity and regularity of the service is its own regulated subject — organisational arrangements, a policy, plans, and tests that actually run.

At the desk

  • Stand up the three layers the RTS names: organisational arrangements, a business-continuity policy, and the plans that implement it.
  • Test the plans periodically — a plan that has never run is a document, not a control.
  • Scale everything to complexity and risk: the RTS builds proportionality in, which means your reasoning for the scale you chose must exist in writing.

In the boardroom

  • Continuity failures are client-visible within minutes and supervisor-visible within days. The test calendar is a board agenda item, not an IT one.

So whatFind the date of your last continuity test and the list of what failed. If either takes more than a day to produce, that is the work.

Commission Delegated Regulation (EU) 2025/299 · applicable — this binds · verified 2026-08-26 · Read the text ↗

Verified: 2026-08-27 — the RTS article structure re-read in the held text

Which records must exist, and in what shape?

The record-keeping RTS names the records by category — policies, client agreements, safekeeping, orders, transactions — and the shape they must hold.

At the desk

  • Map your stores to the RTS's categories: policies and procedures; the documents setting out the firm's and the client's rights; safekeeping of client crypto-assets and funds; orders; transactions.
  • Key entities by identifier — the firm's own LEI exists precisely so supervisors can join your records to everyone else's.
  • Where platform records overlap other regimes' standards, keep them to those standards — the RTS says so itself.

In the boardroom

  • Records are the firm's memory under examination: every other module on this page is evidenced — or not — by what this one keeps.
Exhibit · The record categories, as the RTS names them
  • Retention of records — the general duty and its clock
  • The firm's policies and procedures, as records in themselves
  • Documents setting out the firm's and the client's rights and obligations
  • Safekeeping records for clients' crypto-assets and funds
  • Records of orders — and of transactions

CDR (EU) 2025/1140, Articles 2–7 (held)

So whatPut the RTS's record categories next to your systems inventory and mark every record you could not produce this week. The regulation names the records; the gap list is yours to own before anyone asks.

Commission Delegated Regulation (EU) 2025/1140 · applicable — this binds · verified 2026-08-26 · Read the text ↗

Verified: 2026-08-27 — the RTS article structure re-read in the held text

How must conflicts be policed — and disclosed?

The conflicts RTS splits the subject the way the risk splits: conflicts that can hurt the firm, conflicts that can hurt clients, and the policies, pay structures and personal trades behind both.

At the desk

  • Run both inventories the RTS runs: conflicts potentially detrimental to the firm, and those potentially detrimental to clients — they are different lists with different owners.
  • Cover remuneration and personal transactions explicitly: the RTS gives each its own policy article, including the connected persons around your people.
  • Disclose with content, not boilerplate: the disclosure states the role and capacity in which the firm acts when providing the service.

In the boardroom

  • Crypto firms concentrate roles — venue, dealer, custodian — that traditional finance separates by licence. The conflicts file is where that concentration is either managed or exposed.

So whatTake one service you provide in two capacities and write down who could be hurt and how the client is told. If the disclosure reads like boilerplate, it is.

Commission Delegated Regulation (EU) 2025/1142 · applicable — this binds · verified 2026-08-26 · Read the text ↗

Verified: 2026-08-27 — the RTS article structure re-read in the held text

Running a venue: what must it record and show?

A trading platform carries two data duties of its own: an order book kept to a prescribed content and format, and transparency data presented the prescribed way.

At the desk

  • Keep the order book to the RTS's field set and format — it is a supervisory record, designed to be read by machines other than yours.
  • Present pre- and post-trade transparency data as the second RTS prescribes, not as the product team prefers.
  • Remember the venue's operating rules already owe MiCA an admission process with due diligence on what is admitted — the venue is a gatekeeper, not just a matching engine.

In the boardroom

  • Venue permissions are rare — eighteen platform authorisations in the whole register at the 24 August 2026 snapshot — because the duties attached to them are the heaviest in this stack. If the plan includes a venue, the plan includes that cost.

So whatAsk your venue team to export one day of order-book records in the regulatory format today. The exercise finds the schema gaps while they are still cheap.

order-book records — content and format · Commission Delegated Regulation (EU) 2025/416 · applicable — this binds · verified 2026-08-26 · Read the text ↗
how transparency data is presented · Commission Delegated Regulation (EU) 2025/417 · applicable — this binds · verified 2026-08-26 · Read the text ↗

Verified: 2026-08-27 — both RTS re-read in the held texts; count from the register snapshot

What must you detect — and what must you report?

The market-abuse machinery has two moving parts: arrangements that detect, and the STOR that reports — plus a disclosure duty when the firm itself holds inside information.

At the desk

  • Scale your surveillance to your own size, scale and nature — the RTS builds proportionality in, and expects you to have reasoned it.
  • File a STOR on the template when orders, transactions or DLT behaviour look abusive — including conduct in how transactions are ordered on-chain.
  • If the firm holds inside information about a crypto-asset, publish it by the prescribed technical means — and document any delay on the conditions the ITS sets.

In the boardroom

  • Cross-border coordination is written into the act itself: one suspicious-transaction report can put several authorities around one table. File every report on the assumption that every relevant supervisor will read it.
  • Who counts as a watcher was a genuinely argued question — the consultation's miners-and-validators debate is on the moving-edge page, resolved into this act.
Exhibit · The STOR template's spine
  • Section 1 — who is reporting: legal form, LEI, the capacity in which you acted
  • Section 2 — what you saw: the crypto-asset by DTI (or described without one), its type — ART, EMT or other
  • The trading platform where the order was placed — or the DLT behaviour observed
  • The narrative and attachments that let an authority reconstruct your suspicion

CDR (EU) 2025/885, Annex (held)

So whatPrint the STOR template and walk one hypothetical through it with your surveillance lead. Every field you cannot populate names a data feed you do not yet have.

the systems and the STOR template · Commission Delegated Regulation (EU) 2025/885 · applicable — this binds · verified 2026-08-26 · Read the text ↗
publishing — and lawfully delaying — inside information · Commission Implementing Regulation (EU) 2024/2861 · applicable — this binds · verified 2026-08-26 · Read the text ↗
how the authorities are told to look · ESMA Guidelines on supervisory practices for competent authorities to prevent and detect market abuse under MiCA (ESMA75-453128700-1039; final report ESMA75-453128700-1408) · issued guidelines — comply-or-explain, binding authorities rather than firms · verified 2026-08-27 · Read the text ↗

Verified: 2026-08-27 — RTS, ITS and the drafting record re-read in the held texts

What do the conduct guidelines add on top?

Three ESMA guideline sets sit above the acts: suitability when you advise or manage, procedures and client rights when you transfer, and competence floors for the people doing the advising. Each is at its own lifecycle stage — read the footer.

At the desk

  • Run suitability to the MiFID-aligned standard the guidelines import — the consultation asked whether crypto deserved a lighter regime, and the answer was no.
  • Give portfolio-management clients their periodic statement in the guideline format.
  • Build transfer procedures around the client's rights in them — the guidelines read the service from the client's side of the transaction.
  • Watch the knowledge-and-competence clock: adopted July 2025, but the comply-or-explain clock starts only when translations publish.

In the boardroom

  • Guidelines bind through pressure on your supervisor, not directly on the firm — but a supervisor that declared compliance examines against them as if they were rules. Know your authority's declarations.

So whatFor each guideline set your services touch, note two dates: when it started applying, and when your authority declared compliance. Where the second is missing, ask — the compliance tables are public.

suitability + the periodic statement · ESMA Guidelines on certain aspects of the suitability requirements under MiCA (ESMA35-1872330276-2031; third-package, Art 81(15)) · translated and applying — comply-or-explain running · verified 2026-08-27 · Read the text ↗
transfer procedures and client rights · ESMA Guidelines on procedures and policies, including the rights of clients, for crypto-asset transfer services (ESMA35-1872330276-2032; third-package, Art 82(2)) · issued guidelines — comply-or-explain, binding authorities rather than firms · verified 2026-08-27 · Read the text ↗
staff knowledge and competence — clock not yet started · ESMA Guidelines for the criteria on the assessment of knowledge and competence under MiCA (final report ESMA35-1872330276-2380) · issued guidelines — comply-or-explain, binding authorities rather than firms · verified 2026-08-27 · Read the text ↗

Verified: 2026-08-27 — all three issued texts re-read; stages from the registry

The stack in motion: one order, five stations

Modules teach the rules one at a time; a real order meets them all in sequence. Scroll the walk: the order stays pinned while the stations pass, and the paper trail it leaves grows a line at each one. This is what “running the licence” means at the resolution of a single trade.

The order

  • A retail client of Alderhaven
  • Buy: a Title II token, EUR 40,000
  • Channel: the firm's app, executed on its own platform

The paper trail so far

  1. The client file: identity, terms of business, and — where advised — the suitability assessment.
  2. ·The conflicts record covering venue-operator dealing and its management.
  3. ·The order record: parties, instrument, quantities, timestamps, outcome — in the prescribed fields.
  4. ·The venue's transparency output and the execution confirmation to the client.
  5. ·The surveillance log entry — and, on suspicion, the STOR on the prescribed template.

Alderhaven and this order are invented for training. The stations are the stack’s real machinery, cited beneath the walkthrough; no real firm, client or token is depicted.

Station 1 · Before the order exists

Whose money, and on what footing?

The order's legal shape is set before it is placed. If Alderhaven advised this client or manages their portfolio, the suitability machinery has already run — profile, assessment, and later the periodic statement. If the client came execution-only, the firm still knows who they are and on what terms they trade. Either way, the client file is the order's foundation: the stack's duties attach to a known client, not an address.

MiCA Art 81; ESMA suitability guidelines

Station 2 · The conflicts screen

Is the firm on both sides of this order?

Alderhaven runs the venue the order will execute on — a concentration of roles traditional finance separates by licence. Before the order touches the book, the conflicts machinery answers for it: the firm's inventory, its fee interest in execution, and any group interest in the token are identified, managed, and where they cannot be managed, disclosed. The conflicts file is standing paper, but the order is what makes it real.

CDR (EU) 2025/1142

Station 3 · The record the order writes

The order becomes data the moment it exists

From receipt, the record-keeping act is running: who ordered, what, when, on which terms, and what happened to it — timestamped through reception, transmission and execution. These records are the firm's memory under examination: every other station on this walk is evidenced, or not, by what this one keeps. Five years is the floor, and the fields are prescribed, not chosen.

CDR (EU) 2025/1140

Station 4 · The venue

Execution, in public

On the platform, the order meets the venue's own duties: operating rules that admit the token, systems that survive load, and the transparency machinery — the order book's data published in the prescribed content and format. The trade that results is not just the client's outcome; it is a data point the whole market, and the supervisor, can read.

CDR (EU) 2025/416; CDR (EU) 2025/417

Station 5 · The watch

Someone is paid to be suspicious of this order

The surveillance layer reads the same order last. As a firm professionally arranging and executing transactions, Alderhaven watches its own flow for the abuse regime's patterns — and where suspicion forms, files the suspicious transaction or order report on the prescribed template, on the clock. One report can put several authorities around one table; the walkthrough's order clears, but the watch is why every order is watched.

CDR (EU) 2025/885; CIR (EU) 2024/2861

Commission Delegated Regulation (EU) 2025/1142 · applicable — this binds · verified 2026-08-26 · Read the text ↗
Commission Delegated Regulation (EU) 2025/1140 · applicable — this binds · verified 2026-08-26 · Read the text ↗
Commission Delegated Regulation (EU) 2025/416 · applicable — this binds · verified 2026-08-26 · Read the text ↗
Commission Delegated Regulation (EU) 2025/417 · applicable — this binds · verified 2026-08-26 · Read the text ↗
Commission Delegated Regulation (EU) 2025/885 · applicable — this binds · verified 2026-08-26 · Read the text ↗
Commission Implementing Regulation (EU) 2024/2861 · applicable — this binds · verified 2026-08-26 · Read the text ↗
ESMA Guidelines on certain aspects of the suitability requirements under MiCA (ESMA35-1872330276-2031; third-package, Art 81(15)) · translated and applying — comply-or-explain running · verified 2026-08-27 · Read the text ↗

So whatSo what — turn the nine questions above into the firm’s own control calendar: one owner, one review date and one evidence location per module, on a single page the board sees quarterly. The regime is run by whoever keeps that page honest.

As at — instrument lifecycle stages verified 2026-08-26 to 2026-08-27, per instrument (each citation above shows its own date); register figures are from the dated snapshots of 24 August 2026. Module citations render each instrument's lifecycle stage from the registry at build; each module carries its own verified date.