Four-layer banking architecture diagram for MiCA-licensed CASPs on a navy background
Back to blog

How to Open a Bank Account as a MiCA-Licensed CASP in the EU (2026)

Getting a MiCA authorisation under Article 59 of Regulation (EU) 2023/1114 is only half the battle. Without an operational bank account, a CASP cannot segregate client funds, settle fiat legs of trades, or pay staff — yet most EU credit institutions still treat crypto firms as high-risk counterparties. This guide explains what banks actually evaluate, why the Basel/CRR III prudential framework makes your file costly to hold, how to navigate de-risking, and how to build the four-layer banking architecture that keeps a licensed CASP operational under any scenario.

Contents

Key facts

Why EU Banks Still Struggle to Onboard Licensed CASPs

Holding a MiCA authorisation under Article 59 of Regulation (EU) 2023/1114 makes a CASP a regulated entity — supervised by an NCA, subject to prudential capital requirements under Article 67, obliged to segregate client assets under Article 70, and bound by the Travel Rule under Regulation (EU) 2023/1113. What it does not do, automatically, is change how a bank's internal risk committee views your firm. Most European banks built their crypto-sector risk policies between 2018 and 2022 — before MiCA existed — and those frameworks have not been updated at the same pace as the law. The result is a structural mismatch: a fully licensed CASP faces the same blanket risk flags as an unlicensed exchange operating from a jurisdiction with no oversight.

The friction has three concrete roots. First, AML compliance cost versus expected revenue: onboarding a crypto firm requires enhanced due diligence, ongoing transaction monitoring calibrated for blockchain flows, and periodic re-reviews — at a cost that most mid-tier banks estimate materially exceeds the fee income from a startup's operating account. Second, CRR III capital costs: under Article 501d of Regulation (EU) 2024/1623, a bank holding deposits from a CASP whose business involves unbacked crypto-assets faces indirect exposure that risk desks price conservatively. Third, correspondent-banking cascade risk: if a local bank's own correspondent imposes restrictions on crypto-linked flows, the local bank cannot easily quarantine your account from that upstream pressure. The EBA's Opinion on de-risking (EBA/Op/2022/02) found that blanket refusal of entire sectors — without individual risk assessment — constitutes ineffective ML/TF management and does not satisfy obligations under Directive (EU) 2015/849. The Opinion draws a clear line: legitimate individual risk assessment is lawful; unwarranted blanket exclusion of a whole regulated sector is not. In practice, however, enforcement of that distinction remains uneven across Member States.

The practical consequence is that even well-prepared CASPs should plan for 8 to 16 weeks of onboarding due diligence as the current standard at established EU credit institutions. Banks will request your NCA authorisation decision, your AML/CFT policies, your DORA-aligned ICT risk framework, audited financials, shareholder structure, and often a detailed breakdown of the crypto-asset types your platform handles. Some will request quarterly data thereafter. Building this documentation pack before approaching any bank — rather than in response to requests — is one of the few variables entirely within your control.

How Basel SCO60 and CRR III Article 501d Affect Your Banking Relationships

The Basel Committee's prudential standard for cryptoasset exposures — SCO60 — was finalised in December 2022 with targeted revisions in July 2024, and entered into force in the Basel Framework on 1 January 2026. The EU addressed cryptoasset exposures on a transitional basis through Article 501d of CRR III (Regulation (EU) 2024/1623), applicable since 9 July 2024. This transitional regime applies until a comprehensive dedicated legislative act — for which the Commission was required to submit a proposal by 30 June 2025 — enters into application, expected in the course of 2026. The EBA's final draft RTS under Article 501d(5)EBA/RTS/2025/04 — was published on 5 August 2025, specifying the technical criteria for classification and capital treatment. A separate note for global context: the United States rejected implementation of SCO60 via Executive Order 14178, creating a significant transatlantic divergence in bank capital rules for crypto exposures.

The transitional framework establishes three buckets, and where your business sits within them determines how capital-expensive you are to bank. Bucket (a) covers tokenised traditional assets — e.g. on-chain representations of bonds or equities — which are treated as equivalent to their underlying asset for capital purposes: the most bank-friendly outcome. Bucket (b) covers asset-referenced tokens that reference traditional assets but carry some basis risk; these attract a 250% risk weight. Bucket (c) — the most consequential — covers other cryptoassets, meaning unbacked tokens and any asset that does not satisfy the hedging recognition criteria of SCO60. These attract capital charges equivalent to a 1,250% risk weight, effectively requiring a bank to hold capital equal to the full exposure value. The Group 2a / Group 2b nuance matters here: assets such as Bitcoin or Ether may qualify as Group 2a — receiving market-risk-only treatment — if the bank can demonstrate they meet the hedging recognition criteria under SCO60. Assets that do not meet those criteria fall into Group 2b and attract the 1,250% charge. These are not automatically equivalent categories, and the internal classification decision sits with the bank, not the CASP.

Equally important for understanding bank behaviour is the aggregate exposure cap under Article 501d(3). Group 2 exposures should generally remain below 1% of Tier 1 capital; exceeding that threshold triggers Group 2b treatment on the excess amount. Breaching the 2% hard limit triggers Group 2b treatment on all Group 2 exposures — a cliff effect that creates a strong incentive for banks to maintain wide headroom beneath both thresholds. For a mid-sized EU bank with €5 billion in Tier 1 capital, the aggregate comfortable exposure to Group 2 crypto-related business is therefore well under €50 million — spread across all clients in the sector, not per CASP. This arithmetic, more than any individual compliance concern, explains why banks ration access to the sector.

BucketAsset typeCapital treatment
Bucket (a)Tokenised traditional assets (bonds, equities, commodities on-chain)Same as underlying asset — standard risk weights apply
Bucket (b) — Group 2a eligibleARTs referencing traditional assets; cryptoassets meeting SCO60 hedging recognition criteria (e.g. BTC/ETH if criteria met)250% RW (ARTs) or market-risk-only treatment (Group 2a)
Bucket (c) — Group 2bUnbacked tokens; any cryptoasset not meeting hedging recognition criteriaEquivalent to 1,250% risk weight — full exposure deducted from capital

What Banks Actually Evaluate: The Seven-Dimension Onboarding File

Banks do not evaluate a CASP the way they evaluate a standard SME client. The review involves multiple internal committees — financial crime, credit, compliance, sometimes a regulatory affairs desk — each with their own checklist. Understanding the seven dimensions they score against is the difference between a first-call approval and a six-month ghosting loop.

Dimension What banks want to see Common rejection triggers
1. Licence quality Authorisation under Article 59 MiCA (Regulation (EU) 2023/1114) from a high-scrutiny NCA — BaFin, CBI, DNB carry material credibility weight. Verification via the ESMA public CASP register. Grandfathered entity still operating under national transitional regime (Article 143); NCA with no supervisory track record; registration-only (not full authorisation)
2. Governance substance EEA-resident executives with verifiable CVs; regulator-approved MLRO; independent compliance officer. MiCA Article 68 real-substance requirement satisfied — not a letter-box entity. Nominee directors; MLRO shared with a dozen other entities; management domiciled outside EEA with no operational presence
3. AML programme Full KYC/CDD stack; Travel Rule capability under Regulation (EU) 2023/1113; live transaction monitoring with documented alert-escalation and SAR workflow referencing AMLD6 obligations. Generic template AML policy; no Travel Rule provider contracted; transaction monitoring described in theory only, no system evidence
4. Volume forecast Monthly throughput of €5–50M sits in the comfort zone for most mid-tier EU banks. Forecasts must be documented and conservative — show how you derived them. Sub-€1M projections (not worth the compliance overhead for the bank); €100M+ with no institutional-grade infrastructure to match; no segmentation of fiat vs. crypto flows
5. Capital and runway 18–24 months operating capital demonstrated; prudential capital segregated and calculated under MiCA Article 67; clean source-of-funds — no capital traceable to sanctioned jurisdictions. Capital runway under 12 months; mixed personal and corporate accounts; capital originating from opaque offshore structures
6. Customer base composition Clear retail/institutional split; explicit list of jurisdictions served; documented self-hosted wallet policy referencing Regulation (EU) 2023/1113 Article 14 enhanced due diligence. Serving high-risk third-country customers without enhanced CDD evidence; no self-hosted wallet policy; anonymous product lines still active
7. Transparency UBO register entry in the Member State of authorisation; clean, single-layer corporate structure; shareholding register provided upfront — not on request. Multi-layer offshore holding structure with no clear UBO; discrepancies between UBO register and submitted shareholding chart; nominee shareholders

The EBA's Opinion on de-risking (EBA/Op/2022/02) explicitly calls out blanket refusal of entire categories of customers — including crypto businesses — as a potential breach of the proportionality principle. Knowing this gives you standing to push back if a bank declines without substantive justification, but it does not force any bank to open an account. Your file must make the risk-reward calculus obvious before it reaches the credit committee. See also our guide on CASP licence requirements for the underlying authorisation standards that dimension one depends on.

Core Documentation Package for CASP Banking Applications

A CASP banking application is not a KYB form — it is a structured regulatory dossier that travels through at least three internal committees and, for larger banks, may be shared with the bank's own NCA for a non-objection review. Submitting documents piecemeal or in response to chase-up emails signals operational immaturity and is itself a rejection signal. Assemble the full package before the first formal submission.

Corporate and ownership

  • Certificate of incorporation and current articles of association
  • UBO declaration cross-referenced to the national beneficial-ownership register entry
  • Full group structure chart (legal entities, ownership percentages, jurisdictions)
  • Shareholding register and any shareholder agreements that affect control

Regulatory

  • NCA authorisation decision letter confirming Article 59 MiCA status and the specific crypto-asset services authorised
  • ESMA public CASP register entry URL (printout or permalink)
  • Programme of operations as submitted to the NCA, including the business plan and projected financial statements referenced in Article 62 and Commission Delegated Regulation (EU) 2025/305
  • Passporting notifications to host-Member-State NCAs, where services are provided cross-border

AML/CFT

  • AML/CFT policy — must cite specific MiCA articles and reference Regulation (EU) 2023/1113 (Travel Rule) obligations explicitly; a copied template with no MiCA references is a fast rejection
  • Risk appetite statement with documented customer-risk scoring methodology
  • MLRO CV, appointment letter, and evidence of NCA approval or notification
  • Transaction monitoring system evidence — not a description, but screenshots or vendor certification showing live deployment
  • Travel Rule provider contract or integration evidence demonstrating originator/beneficiary data transmission capability
  • SAR submission log (redacted) or, for new entities, a documented SAR workflow with escalation paths

Financial

  • Latest audited accounts, or projected financials with supporting assumptions if the entity has operated for less than 12 months
  • Prudential capital calculation under MiCA Article 67 — showing both the fixed-minimum floor (Annex IV class) and the fixed-overheads comparison, with the higher figure identified
  • Safeguarding account evidence or architecture diagram showing how client fiat funds will be segregated under Article 70 MiCA (which covers both fiat client money and crypto-asset segregation obligations) and, where applicable, PSD2 Article 10

Operational

  • DORA ICT risk management framework summary referencing Regulation (EU) 2022/2554 — see our DORA compliance guide for CASPs
  • Business continuity and disaster recovery plan with tested RTO/RPO targets
  • Outsourcing register listing all critical third-party providers and their contractual ICT-risk provisions

Package the dossier as a single indexed PDF with a cover memo mapping each document to the bank's own onboarding questionnaire. Name the MLRO and compliance officer on page one — banks want a named human to call, not a generic compliance inbox. For the AML policy specifically: every section that touches crypto-asset transfers must reference the Travel Rule regulation by name and article number; reviewers are trained to look for this and its absence flags a superficial programme. Our AMLA compliance guide and Travel Rule guide cover the underlying obligations your policies must reflect.

De-Risking: Your Legal Rights When a Bank Says No

De-risking is the practice by which banks and payment institutions refuse to enter into, or terminate, business relationships with entire categories of customers perceived as high-risk — without conducting an individual risk assessment. The EBA addressed this directly in its Opinion on de-risking (EBA/Op/2022/01, 5 January 2022), finding that blanket refusals of this kind are unwarranted and, critically, are themselves a sign of ineffective ML/TF risk management rather than sound compliance. A bank that refuses a MiCA-licensed CASP solely because it is a crypto firm — without examining that specific firm's AML controls, transaction monitoring, and governance — is not acting within the spirit of the EU AML framework.

Your most concrete legal anchor is PSD2 Article 36, which requires credit institutions to make payment account services available to payment institutions on objective, non-discriminatory, and proportionate terms. Any refusal must be communicated to the relevant NCA with duly motivated reasons. In practice, this means a MiCA-authorised CASP can formally request written reasons for rejection, citing its Article 59 authorisation, its ESMA register entry, and any supervisory track record. That written request creates a regulatory paper trail, and some institutions will reconsider when they realise the rejection must be documented and justified to supervisors. Be realistic though: enforcement of Article 36 in the crypto context remains weak, and the letter strategy rarely compels onboarding — its primary value is as evidence if you escalate to the NCA or the EBA's de-risking complaint mechanism.

The operational response matters as much as the legal one. Apply to 8–15 institutions simultaneously and treat rejections as pipeline management, not failure — conversion rates for MiCA-licensed CASPs are low but non-zero, and volume compensates. Maintain a ranked backup list so that if a live banking relationship terminates, you can activate a secondary institution within 48 hours. Termination triggers a cascade of obligations: notify clients with adequate lead time, ensure client fiat funds remain ring-fenced under MiCA Article 70 (segregated account at a credit institution or central bank — this obligation does not pause because your banking relationship ended), and formally file an EBA de-risking complaint if the termination appears to be category-based rather than firm-specific. Document everything.

EMIs and Crypto-Native Payment Institutions: When to Use Them and When Not To

Electronic Money Institutions with EU licences can issue IBANs, originate and receive SEPA credit transfers, and handle day-to-day fiat flows for crypto businesses with considerably less onboarding friction than a full credit institution. Several EMIs authorised in the Netherlands, Lithuania, and Ireland have built explicit appetite for crypto-firm clients and have invested in the compliance infrastructure to support Travel Rule alignment under Regulation (EU) 2023/1113. For operational payments — payroll, vendor settlements, exchange inflows and outflows — an EMI is often faster to onboard and more responsive than a traditional bank.

However, an EMI is a complement to a bank account, not a replacement for one. The most important limitation is statutory: MiCA Article 70 requires CASPs holding client funds (other than e-money tokens) to place those funds, by the end of the next business day, in a segregated safeguarding account held at a credit institution or a central bank. An EMI account does not satisfy this requirement. Article 70 also covers the safeguarding of client crypto-assets — CASPs must keep detailed records, segregate client crypto-assets from the firm's own, and are prohibited from reusing client assets. The fiat safeguarding account must therefore be at a licensed credit institution regardless of what EMI arrangement you run in parallel. Beyond safeguarding, EMIs cannot provide letters of credit, corporate lending, FX hedging facilities, or the kind of correspondent relationships that larger CASPs eventually need for multi-currency settlement.

The practical architecture that works for most MiCA-licensed CASPs in 2026 combines three layers: an EMI account for operational fiat flows, a full bank account dedicated to Article 70 client-fund safeguarding, and a separate regulated custody provider for client crypto-asset segregation. The table below maps each layer to its function and its eligibility for the Article 70 safeguarding role.

Account typeTypical providerPrimary use caseMiCA Art. 70 safeguarding eligible
EMI payment accountEU-licensed EMI (NL, LT, IE)Operational fiat flows: payroll, vendor payments, exchange settlementNo — EMI is not a credit institution
Credit institution accountLicensed EU bankClient fiat fund safeguarding; corporate treasury; FX, lendingYes — mandatory for Art. 70 fiat segregation
Custody / wallet accountRegulated crypto custodian or internal custody under CASP licenceClient crypto-asset segregation; on-chain settlementYes (crypto leg) — subject to Art. 70 record-keeping and no-reuse rules

If your CASP licence covers custody and administration of crypto-assets, do not assume that solving the bank account problem closes the Article 70 file. The fiat and crypto legs of the safeguarding obligation are both active from day one of authorisation, and regulators have been explicit that the two cannot substitute for each other.

Building Banking Redundancy: The Four-Layer Architecture

A CASP operating through a single banking relationship is not running a business — it is running a countdown. One supervisory inquiry, one internal credit-committee reassessment, or one correspondent bank instruction and that institution can restrict or close the account with little notice. The operational fallout is immediate: client on-ramps freeze, settlement fails, and the regulator begins asking questions about operational resilience under DORA (Regulation (EU) 2022/2554). The only structural answer is a deliberate, pre-activated four-layer banking architecture — not a contingency plan sitting in a drawer, but live accounts with standing orders that can absorb traffic within 48 hours.

Article 70 of MiCA (Regulation (EU) 2023/1114) governs both dimensions of client-asset segregation — not just fiat. It requires CASPs to place client fiat funds in a segregated safeguarding account at a credit institution or central bank by the end of the following business day. It also mandates separate records and strict segregation for client crypto-assets, with an explicit prohibition on commingling or reuse. This dual scope means banking architecture must address two separate institutional relationships: one for fiat safeguarding, one for custody of crypto-assets with documented per-client records. Treating Article 70 as a fiat-only concern leaves the crypto-asset segregation obligation unaddressed — a material compliance gap that NCAs will identify on inspection.

Beyond regulatory anchoring, each layer serves a distinct operational function. Blend them and you lose both the legal protection (commingling voids safeguarding status) and the resilience benefit (a single institution failure cascades across all functions). Each layer should be subject to a formal re-evaluation cycle of approximately 12 months — reviewing the institution's credit standing, jurisdiction risk, and regulatory appetite for CASP clients. Client contracts should include explicit wording permitting IBAN changes with no less than 14 days' notice, avoiding contractual lock-in to a specific account number and giving the CASP the operational flexibility that four-layer architecture requires.

Layer Institution type Primary function MiCA / regulatory anchor
1 — Primary operating bank Full credit institution, preferably in NCA jurisdiction Corporate treasury, correspondent settlement, payroll, operational payments MiCA Art. 62 (authorisation documentation); DORA Art. 11 (ICT continuity)
2 — Backup operating bank Full credit institution, second EU jurisdiction (e.g., LT or IE if primary is NL) Dormant mirror of Layer 1; pre-activated standing orders; activation SLA ≤ 48 hours DORA Art. 11 (business continuity); EBA de-risking Opinion EBA/Op/2022/02
3 — EMI rails Licensed EMI (PSD2 Art. 10 safeguarding regime) Client IBANs, SEPA on/off-ramp, fast retail flows — operationally separate from safeguarding PSD2 Directive 2015/2366 Art. 10; MiCA Art. 59 (CASP authorisation scope)
4 — Dedicated safeguarding institution Third credit institution (never shared with Layers 1–2) + regulated custodian for crypto Fiat client funds segregated per Art. 70; crypto-asset client records per client, no commingling, no reuse MiCA Art. 70 (dual scope: fiat funds AND crypto-assets); MiCA Art. 75 (custody obligations)

Layers 1 and 2 should be in different EU jurisdictions to ensure that a country-level supervisory action or banking-sector stress event does not simultaneously disable both. Layer 3 EMI rails handle client-facing flows but must never hold safeguarding balances overnight — the end-of-business-day transfer obligation under Article 70 applies regardless of which institution collects the inbound payment. Layer 4 must be documented with a formal safeguarding account agreement and, for crypto-assets, a per-client ledger reconciled at least daily. No single institution should appear in more than one layer — concentration at any point collapses the architecture into the single-bank risk it was built to eliminate.

Jurisdiction Strategy: Where to Bank for Your NCA

Your NCA jurisdiction and your banking jurisdiction are independent decisions — and conflating them is one of the most common structural mistakes a newly licensed CASP makes. The country that granted your authorisation under Article 59 of Regulation (EU) 2023/1114 determines your regulatory home; the country where you hold your primary operating account determines your banking risk profile. Build each deliberately. Your ESMA passporting register entry is the single most effective document for unlocking bank compliance conversations — it signals that a competent authority has already conducted full due diligence on your business, your key personnel, and your AML programme.

The banking landscape varies sharply by jurisdiction. Germany (BaFin) offers the strongest institutional credibility: a small number of established banks — including tier-2 houses with dedicated crypto desks — will engage CASPs with a clean BaFin licence and a solid transaction-monitoring framework. Netherlands (DNB) has a functioning fintech banking ecosystem and a crypto-native EMI layer that can handle fiat-on/off-ramp rails where traditional banks hesitate. Luxembourg (CSSF) is useful for cross-border private banking corridors and infrastructure-adjacent relationships, including settlement proximity to Clearstream. Ireland (CBI) provides strong USD correspondent access — valuable if your clients route dollar flows — but expect elevated scrutiny and longer onboarding timelines. Malta (MFSA) presents the hardest retail banking environment in this group; the country's period of FATF enhanced monitoring left a lasting risk premium with domestic banks, and the EMI route is often the only practical path to an operational account. Lithuania (Bank of Lithuania) has the deepest EMI pool in the EU and consistently the lowest onboarding friction — even if your NCA is elsewhere, a Lithuanian EMI makes a reliable backup payment rail and should be in every CASP's banking architecture.

NCA Jurisdiction Retail Bank Access EMI Availability USD Correspondent Strength Strategic Note
Germany (BaFin) Moderate — specialist desks at tier-2 banks Good Strong Highest institutional credibility for institutional counterparties
Netherlands (DNB) Moderate — fintech-friendly banks Strong Good EMI layer well-developed; useful for retail fiat flows
Luxembourg (CSSF) Good — private banking corridors Moderate Good Settlement infrastructure proximity; strong for B2B
Ireland (CBI) Moderate — higher scrutiny, slower KYB Moderate Very strong Best jurisdiction for USD-heavy business models
Malta (MFSA) Low — domestic banks cautious Strong Limited EMI-first strategy; pair with Lithuanian or Dutch rail
Lithuania (Bank of Lithuania) Low for traditional banks Deepest in EU Moderate Lowest friction; recommended as backup rail regardless of NCA

The practical conclusion: anchor your primary banking relationship in a jurisdiction where banks have active crypto compliance desks — Germany and the Netherlands lead here — while maintaining at least one EMI account in Lithuania or the Netherlands as an operational backup. If your NCA is Malta or a smaller member state with limited domestic banking appetite, treat the EMI relationship as your primary rail from day one rather than a fallback. For more on the underlying AML documentation banks will demand at onboarding, see the EU AMLA/AMLR compliance guide for CASPs.

Frequently asked questions

Does a MiCA CASP need a bank account to comply with Article 70?

Yes. MiCA Article 70 requires CASPs to segregate client fiat funds by placing them in a dedicated account at a credit institution or central bank by the end of the next business day after receipt. Electronic money institutions (EMIs) do not satisfy this requirement — only a licensed credit institution or central bank qualifies for the Article 70 fiat safeguarding function. Article 70 also requires segregation of client crypto-assets from the CASP's own assets, with detailed records per client and a prohibition on reuse for the CASP's own account.

Why do banks apply such high capital charges to CASP clients under CRR III?

Under CRR III Article 501d (applicable since 9 July 2024), EU banks must hold capital against their crypto-asset exposures. 'Other crypto-assets' — those not meeting the hedging recognition criteria — attract capital charges equivalent to a 1,250% risk weight. Additionally, a bank's total exposure to such assets must remain below 1% of Tier 1 capital (with a hard 2% cliff). Holding a CASP's operational deposits therefore creates indirect crypto exposure that is expensive in capital terms, which is one structural reason why many banks decline or price the relationship conservatively.

How many banks should a CASP approach simultaneously, and what is a realistic success rate?

Industry practice in 2026 suggests approaching 8–15 institutions in parallel. Full onboarding due diligence — including credit committee, financial-crime committee, and sometimes NCA non-objection — takes 8–16 weeks per institution. Rejection rates remain high even for well-prepared MiCA-licensed firms, primarily due to banks' AML overhead cost models and capital considerations, not necessarily any deficiency in the CASP's compliance programme. Treating banking applications as a pipeline with a target conversion rate, rather than sequential attempts, materially shortens the time to obtaining the first account.

Can a bank legally refuse to open an account for a MiCA-authorised CASP?

Yes, within limits. PSD2 Article 36 requires credit institutions to provide access to payment account services to payment institutions on objective, non-discriminatory and proportionate grounds, and to provide NCAs with duly motivated reasons for any rejection. However, a bank may legitimately refuse based on an individual risk assessment. What the EBA Opinion EBA/Op/2022/01 (5 January 2022) prohibits is blanket de-risking of entire customer categories without individual assessment — the EBA considers this unwarranted and a sign of ineffective ML/TF risk management. A refused CASP can request written reasons and escalate to the relevant NCA, though enforcement remains weak in practice.

What is the minimum banking architecture a MiCA CASP should maintain?

A prudent CASP should maintain at least four distinct relationships: a primary operating bank for corporate treasury; a backup operating bank in a second jurisdiction, pre-activated and capable of going live within 48 hours; an EMI for fast SEPA client deposit flows; and a dedicated Article 70 safeguarding account at a separate credit institution, never commingled with operating funds. Client crypto-assets must also be held in segregated custody with per-client records. A single-bank CASP faces operational shutdown risk from any adverse supervisory action directed at its banking partner.

Does the Basel SCO60 standard apply directly to EU banks today?

SCO60 entered the Basel Framework on 1 January 2026, but EU banks do not apply it directly. The EU has addressed crypto-asset exposures on a transitional basis through CRR III Article 501d (in force since 9 July 2024, via Regulation (EU) 2024/1623). The EBA published final draft RTS/2025/04 on 5 August 2025 to specify the calculation methodology. A permanent EU legislative act — originally expected by 30 June 2025 — has not yet been published; until it applies, EU banks follow the Article 501d transitional regime together with the EBA RTS.

Link copied to clipboard