The MiCA and Travel-Rule Compliance Stack for a New CASP
The onboarding, screening, travel-rule, record-keeping and continuity stack a MiCA-authorised CASP must run from day one - wired so each obligation produces its own evidence, not a reconstruction at examination time.
- Maturity
- Proven
- Regime
- MiCA + Travel Rule
- Proven stack
- Notabene · Sumsub · 21 Analytics · Elliptic
- Last verified
- August 2026
Reviewed by Andrei Yurkevich, Founding Member at Protofire
EU CASPs authorised after 30 Dec 2024 that have published their full compliance stack - onboarding, messaging, screening, record-keeping and continuity together.
Each named institution below is public about one or two layers. That is a gap in the public record rather than evidence that firms have no stack, and it is why the market has no reference architecture for the combined chain.
01. The opportunity
A crypto-asset service provider authorised under MiCA takes on, from the day its authorisation is granted, obligations that are continuous rather than periodic: transmit originator and beneficiary information on every transfer, screen counterparties and addresses, verify control of self-hosted addresses above a threshold, keep records of every service, activity, order and transaction in a prescribed form, and maintain a business continuity policy its management body has endorsed. Each is separately supervised, and each produces evidence a competent authority can ask for. This blueprint runs that stack so the evidence is a by-product of operating the business rather than a reconstruction carried out under examination.
The recast Transfer of Funds Regulation has applied to crypto-asset transfers since 30 December 2024, and the EBA travel-rule guidelines took effect the same day, so the obligation is live. MiCA's transitional period closed on 1 July 2026, so the firms serving EU clients are now authorised CASPs, each carrying the full obligation set from the date of its own authorisation. The pattern is in production, with three named institutions running it and the earliest screening a MiCA e-money token since August 2024, yet no published reference architecture exists for the combined stack, because vendors publish their own layer and stop at its boundary. For a newly authorised CASP the value is in running every obligation as one evidenced chain from the first day of authorisation, which also clears the way for the product blueprints that usually follow within weeks.
02. The regulatory position
03. Who's already done this
Elliptic blockchain analytics across the EURI e-money token ecosystem - ecosystem monitoring, wallet screening, transaction monitoring and asset due diligence - alongside a stablecoin settlement service launched after CASP approval. The closest available match to this blueprint's reader: a bank that took CASP authorisation and stood up the compliance layer around it.
Travel-rule data exchange via the Sumsub network, documented in Bitpanda's own published customer helpdesk. The mid-market comparator and the more useful row for most readers: it shows the multi-authorisation reality of a firm operating across member states, and it is one of the few cases where the travel-rule arrangement is documented by the institution itself rather than by a vendor.
Notabene as system of record for travel-rule compliance. Instructive by contrast rather than as EU proof: it demonstrates the system-of-record pattern - one authoritative store for transfer messages rather than per-counterparty reconciliation - at a bank serving clients in over 40 countries.
04. Does this fit you?
Yes, if you hold a MiCA Art. 63 CASP authorisation or are in final supervisory dialogue on one, you execute transfers to and from counterparty CASPs and self-hosted addresses, and you already run an onboarding and AML function for another regulated activity.
Probably not, if you will not hold your own authorisation and intend to keep serving EU clients on somebody else's licensed rail - a different pattern applies. Also not, if your transfer volumes are low: this is a fixed-cost operating stack against a variable revenue base, and below a certain volume operating on an authorised provider's rail is the cheaper answer.
05. The stack, layer by layer
Most of these layers can be rented from a named vendor, and usually should be. The part that matters is the one layer you have to own yourself.
The authorisation, the AML function and the client record
The CASP authorisation and the supervisory relationship, an AML function with policies and a nominated officer, customer relationships and the onboarding record, and a core ledger with its reconciliation. Each obligation in this stack is separately supervised and each is continuous rather than periodic.
Directory, screening and identity vendors
Counterparty directory and protocol reachability, screening risk data and typology detection, and identity verification with document checks. Explicitly not provided: the record store in the prescribed form, the routing decision between the two duties, the policy matrix, the continuity plan, or the evidence chain that ties them together.
The routing layer, the record store and the evidence chain
The routing layer that decides which duty each transfer engages and evidences it; the record store prescribed by Del. Reg. (EU) 2025/1140, drawing from every vendor layer; the onboarding-to-transfer attribute mapping; and the thresholds-to-actions matrix, the continuity plan and out-of-hours cover. The vendors supply layers; nobody supplies the chain.
06. Why this stack
- The information duty and the self-hosted threshold are separate duties. Article 14 of Regulation (EU) 2023/1113 requires originator and beneficiary information on every crypto-asset transfer with no de-minimis - recital 27 grants no exemption for low-value domestic transfers. The EUR 1,000 figure that does exist governs a different duty: under Art. 14(5), a transfer above it to or from a self-hosted address obliges the provider to assess whether the customer owns or controls that address. A stack that applies a EUR 1,000 data-collection floor by analogy to payments is non-compliant from its first transaction. Separating the two duties at the routing layer keeps that error from occurring.
- Self-declaration does not satisfy the self-hosted duty. The EBA travel-rule guidelines (EBA/GL/2024/11, applying 30 December 2024) address the acceptable methods, and paragraph 83 rules out a customer's own say-so. The verification mechanism has to be built into the architecture.
- No vendor owns the record store. Commission Delegated Regulation (EU) 2025/1140 prescribes records of all crypto-asset services, activities, orders and transactions. Each vendor in the stack holds only its own layer, so the institution cannot outsource this one; it has to be designed in from the start, so the records exist before any examination.
Request the full blueprint
This is the short version. The full blueprint is a single document your counsel and board can read cold, and a third-party-risk function can lift wholesale. Leave your work email and your personal link arrives in your inbox.
- The regulatory position, stated article by article
- Proven options at each layer, with the vendors that hold up
- The risk table with a named owner for each risk
- The division of labour: what is rented, built, and operated
- The third-party-risk pack a DORA governance function can lift
- The delivery path, step by step, with the monitoring and incident model
FAQ
What compliance obligations must a newly authorised CASP run from day one?
The MiCA and Travel-Rule operating stack covers onboarding, screening, travel-rule messaging, record-keeping and continuity, wired so each obligation produces its own evidence. It runs under MiCA Arts. 63 and 68(9), with Del. Reg. (EU) 2025/1140 on records and Del. Reg. (EU) 2025/299 on continuity, the recast Transfer of Funds Regulation (Reg. 2023/1113) Arts. 14, 16 and 17, EBA/GL/2024/11, DORA and GDPR. Each obligation is separately supervised and continuous rather than periodic.
What are the Transfer of Funds thresholds a CASP must apply to crypto transfers?
Under the recast Transfer of Funds Regulation (Reg. 2023/1113), applying from 30 December 2024, there is no de-minimis threshold on the information duty, so travel-rule data must accompany transfers regardless of value. A separate EUR 1,000 threshold under Art. 14(5) applies to assessing control of a self-hosted address. EBA/GL/2024/11 para. 83 states that self-declaration is not an adequate measure. These duties form part of the evidenced compliance chain a MiCA-authorised CASP runs from day one.
What does the CASP build versus rent in this compliance stack?
The CASP owns the authorisation and supervisory relationship, the AML function with its nominated officer, the client onboarding record, and the core ledger. It rents the counterparty directory, screening risk data and identity verification from vendors such as Notabene, Sumsub, 21 Analytics, Chainalysis, Elliptic, TRM or Onfido. What it builds is the routing layer that decides which duty each transfer engages and evidences it, the record store prescribed by Del. Reg. (EU) 2025/1140, the onboarding-to-transfer attribute mapping, and the continuity plan. The vendors supply the layers and the institution builds the chain.
Already evaluating this for your institution?
When you are ready, we scope a business case on your own numbers: the costed build, the controls, the SLA and the ROI your board needs to approve it. Or talk it through first.
Run this pattern in production, or tried to and stopped? .


