Onboarding a Migrating Client Book
Every unauthorised EU crypto provider had to be winding down by 1 July 2026, and their clients have to move somewhere - absorbing them at ten times normal volume without lowering your onboarding standard is a question of operational capacity and compliance policy.
The full blueprint adds all 11 risks with their controls and owners, the DORA third-party pack and the delivery plan in 4 phases.
Web document · ~15 pages · 21 min read · one link opens all 22 blueprints
- Maturity
- Emerging
- Model
- Consolidation
- Proven stack (4 of 10)
- Sumsub · Onfido · Chainalysis · Elliptic
- Last verified
- August 2026

Reviewed by Ivor Jugo, Offer Owner at Protofire
ESMA-registered CASPs as of 31 Jul 2026, against roughly 1,200 entities that held pre-MiCA national registrations.
This is a material client book in motion: roughly 7.6M of 18.5M European exchange app downloads went to unauthorised platforms, and ~30% of EU crypto transaction volume still sat outside authorised venues as of May 2026.
01. The opportunity
The MiCA transitional period closed on 1 July 2026. Roughly 1,200 entities held pre-MiCA national registrations; as of 31 July the ESMA register showed 321 authorised CASPs. The clients behind that gap have to move to an authorised venue, which puts a large book in motion. This pattern concerns the authorised institution on the receiving end - the one with money, a supervisor watching, and a sudden inbound flow it did not size for. The firms that failed have no revenue, no licence and a wind-down obligation, and are leaving the market.
The work is an operational one. Absorbing that book means running a full onboarding programme against a population that did not choose the institution, at a pace its compliance function has never operated at, while crediting on-chain deposits from infrastructure it has no visibility into. What it requires is the onboarding, screening and custody capacity to take on a migrating book without lowering its own standard or risking its new authorisation - the authorisation the institution spent a year and seven figures obtaining, which is what a badly handled surge puts at risk.
02. The regulatory position
03. Who's already done this
- No named authorised CASP has yet published how it ran a migration like this - stated plainly rather than papered over. The market condition is demonstrably real and large (see the full page), the specific playbook is not yet publicly documented anywhere.
04. Does this fit you?
- Yes if there's an existing CASP authorisation and clients are already arriving faster than onboarding was sized for - by referral, group migration or acquisition.
- Not if authorisation itself is missing - there's no shortcut here; see the counterpart blueprint for the migrating firm's own side, or talk to counsel about applying, passporting, selling or winding down.
05. The stack, layer by layer
Most of these layers can be rented from a named vendor, and usually should be. The part that matters is the one layer you have to own yourself.
Authorisation and infrastructure the institution already has
The CASP authorisation and the passport; an onboarding flow, sized for organic growth; custody infrastructure and a compliance function; a support desk.
Identity, screening and messaging rails
Identity verification and document checks at volume; on-chain screening and address attribution; Travel Rule messaging to counterparty VASPs; custody and key management. The surge-capacity planning, the migration policy and the runbook are what you build.
The migration capacity layer
The migration onboarding funnel and its queue management; a documented deposit policy for assets arriving from a winding-down provider; the screening escalation path and the freeze decision tree; asset coverage mapping and the stranded-token communication; custody capacity planning and deposit crediting at surge; the audit trail the supervisor will ask for.
06. Keep in mind
- The receiving CASP onboards every client from zero. There is no inherited KYC and no shortcut, which makes onboarding capacity and policy the binding constraint rather than the technology.
- A share of any book does not respond to a transfer notice at all. That share is lost in transit, so commercial terms should be tied to the clients who onboard and fund, and an acquisition priced on the raw headcount overpays.
- ESMA's 17 April 2026 statement instructs supervisors to scrutinise exactly this kind of migration. The audit trail of consents, notifications and decisions has to be assembled while the migration runs, so it is complete when the supervisor asks for it.
Risks, controls and owners
From the full blueprint · 3 of 11 shown, one with its control- Standards slip under volume pressureControl: in the full blueprintOwner: The institution's MLRO
- Tainted assets arrive with the bookControl: in the full blueprintOwner: The institution's compliance function
- Supervisory challenge to the migrationControl: A complete audit trail of decisions, notifications and consents, assembled as the migration runs rather than reconstructed afterwardsOwner: The institution's compliance function
The other 8 risks, and every control, are in the full blueprint.
Get all 11 with controls ↓Get the full BP-24
Web document · ~15 pages · 21 min read
This page is the short version. The full BP-24 adds all 11 risks with their controls and owners, the DORA third-party pack and the delivery plan in 4 phases. We email you a personal link, and it opens all 22 blueprints in the library.
We email your personal link and, now and then, a blueprint update. Privacy policy

Reviewed by Ivor Jugo, Offer Owner at Protofire · last verified August 2026



What the full blueprint adds, by reader
- Counsel
- The regulatory position across 4 regimes, article by article
- Risk & compliance
- All 11 risks, each with its control and the party that owns it
- Third-party risk
- The DORA pack: critical-or-important classification, the Art. 28(4) pre-contract assessment, Art. 30(3) contract clauses and Art. 29 concentration. Any commission we may earn on a named vendor is disclosed
- Technical lead
- Which of the 6 building blocks are essential and which are optional, and why
- Delivery
- The delivery plan in 4 phases, with the decision that gates each, then monitoring and incident response once live
- Board
- For the board paper: what each function gets, and where this pattern does not work
FAQ
Can a receiving CASP reuse the migrating firm's KYC when it absorbs a client book?
No. In the Absorbing a Migrating Client Book pattern, the receiving CASP onboards from zero with no inherited KYC, and each client needs individual assignment or novation consent. ESMA's statement of 17 April 2026 instructs supervisors to scrutinise migrations, and penalties reach EUR 5 million or 5 per cent of global turnover. The challenge is absorbing clients at roughly ten times normal volume without lowering the onboarding standard.
What scale of client book is in motion after the MiCA transitional cutoff?
MiCA's transitional period ended on 1 July 2026, and there were 321 authorised CASPs by 31 July 2026 against roughly 1,200 entities that held pre-MiCA national registrations. The gap is a client book in motion: roughly 7.6 million of 18.5 million European exchange app downloads went to unauthorised platforms, and about 30 per cent of EU crypto transaction volume still sat outside authorised venues as of May 2026. Every unauthorised provider had to be winding down by that date.
Who is this absorption pattern for, and what does the CASP build versus rent?
It fits an authorised CASP absorbing clients from a wind-down through referral, group migration or acquisition, a group moving EU clients from a non-EU platform into its own EEA-authorised entity, or a bank or EMI on the Article 60 route whose market is arriving faster than its operations were built for. It is not for a firm that missed authorisation. The CASP keeps its authorisation and infrastructure, rents identity, screening and messaging rails from vendors such as Sumsub, Chainalysis and Notabene, and builds the migration onboarding funnel, the deposit policy, the screening escalation path and the audit trail.
Already evaluating this for your institution?
When you are ready, we scope a business case on your own numbers: the costed build, the controls, the SLA and the ROI your board needs to approve it. Or talk it through first.
Run this pattern in production, or tried to and stopped? .