CryptaCount
EN
EnglishENDeutschDEEspañolESFrançaisFRItalianoIT日本語JA한국어KONederlandsNLPolskiPLPortuguêsPT
Log in Start Free

ESMA Q&A on CASP Custody: What Accounting Firms and CFOs Must Act On Now

CryptaCount Editorial · · 10 min read
AML / KYC / LICENSING ESMA Q&A on CASP Custody: WhatAccounting Firms and CFOs Must Act OnNow

ESMA has published a targeted new question and answer clarifying the authorisation obligations of crypto-asset service providers (CASPs) that offer custody, administration, or transfer services for crypto-assets that are issued after an initial public offer under MiCA. For accounting firms advising digital asset clients, and for CFOs running treasury or custody operations, this guidance directly affects how authorisation scope is mapped, how services are classified in the books, and what your crypto accounting software needs to capture from day one of a new issuance.

ESMA Q&A on CASP Custody: What Accounting Firms and CFOs Must Act On Now

What ESMA Has Actually Said

The new Q&A, reference number 2417, addresses a specific operational question: does a CASP that is already authorised to provide custody and administration, or transfer services, for crypto-assets need any additional or separate authorisation when those services relate to crypto-assets that were not yet in existence at the time of the firm's original authorisation but are subsequently issued to the public under MiCA?

The Authorisation Scope Question

This matters because MiCA authorisation is tied to the categories of service a CASP provides, not to specific tokens or issuers. The practical concern in the market has been whether a newly listed token, one that goes through a public offer under MiCA Title II after a CASP has already been licensed, falls automatically within the firm's existing custody permission or whether a fresh regulatory step is required before the CASP can lawfully hold or transfer that asset on behalf of clients.

ESMA's guidance resolves that ambiguity. The authority's position, as published in Q&A 2417, is that an authorised CASP providing custody, administration, or transfer services does not need a separate or additional authorisation solely because the crypto-assets in question were issued after the firm's own public offer. The service type, not the token's vintage relative to the CASP's licensing date, determines the authorisation requirement. Provided the CASP holds the correct service-category authorisation, it may extend that service to newly issued crypto-assets without seeking a new licence each time a fresh token comes to market.

Why the Distinction Matters in Practice

The nuance is important. ESMA is not saying that any CASP can hold any token. The firm still needs to hold authorisation for the specific service type, custody and administration, or transfer, as the case may be. What the guidance confirms is that the timing of a token's public issuance relative to the CASP's own authorisation date does not create an additional licensing hurdle. This prevents a reading of MiCA that would require CASPs to keep returning to national competent authorities every time a new project launches a token through a compliant offer.

For growing markets where new tokens are issued regularly under MiCA's Title II framework, the operational relief is significant. Without this clarification, a strict reading could have generated repeated authorisation filings, delays in onboarding new assets, and legal uncertainty about the lawfulness of custody arrangements from the first day of a new token's existence.

Compliance Implications for Accounting Firms and Auditors

Accounting practices advising CASPs or digital asset funds need to read Q&A 2417 alongside their existing client authorisation maps. Several practical points follow directly from the guidance.

Authorisation Mapping and Scope Documentation

If your client is a licensed CASP, their compliance file should now record explicitly that post-offer issued crypto-assets fall within the existing service authorisation, with a cross-reference to Q&A 2417 as the interpretive basis. Auditors reviewing CASP licences in the context of year-end or interim audits should confirm that the client's legal team has updated its authorisation scope analysis to reflect this position. A CASP that has been self-limiting its custody services to tokens pre-dating its own authorisation, out of excess caution, may have been leaving revenue on the table and should review whether any retrospective service gap exists.

Recordkeeping and the Role of Crypto Accounting Software

ESMA's Q&A does not alter MiCA's substantive recordkeeping obligations: CASPs must maintain detailed records of every crypto-asset held in custody, the terms under which it is held, and the identity of the beneficial owner. What changes is the classification trigger. Because a newly issued token does not require a separate authorisation event, there is no natural compliance checkpoint at which the accounting team might pause to update custody ledgers or client onboarding records.

This means crypto accounting software configurations need to handle the automatic inclusion of new tokens under an existing custody category without creating a false gap in the asset register. Firms using manual or semi-automated crypto bookkeeping software should build a process by which any newly issued token added to the custody book is immediately tagged to the authorised service category and the onboarding date recorded. The absence of a fresh authorisation event should not mean the absence of a fresh documentation step.

AML and KYC Touchpoints

A CASP adding a newly issued crypto-asset to its custody offering must still apply its standard AML and KYC procedures to the underlying clients holding that asset. ESMA's Q&A addresses the authorisation question, not the customer due diligence question. For accounting firms conducting AML advisory or compliance reviews, the practical checklist remains: verify that the CASP's CDD files for clients holding newly issued tokens are complete, that transaction monitoring rules have been updated to cover the new asset's characteristics, and that any higher-risk features of the new token, such as privacy features or unusual transfer mechanics, have been assessed and documented before the asset goes live in the custody ledger.

This connects directly to the broader supervisory environment ESMA is operating in. As covered in our earlier piece on ESMA's Common Supervisory Action on CASP custody resilience, the regulator has been actively examining whether CASPs maintain adequate operational and governance controls around their custody functions. Q&A 2417 is best read as part of that same supervisory push: ESMA is clarifying the perimeter so that CASPs and their advisers have no excuse for ambiguity about which assets sit within the regulated custody perimeter.

What CFOs Running Custody or Treasury Operations Need to Check

CFOs at firms that either operate as CASPs or hold significant digital asset positions through CASP custody arrangements face a more immediate set of action points.

Review Token Onboarding Procedures

If your treasury team relies on a CASP for digital asset custody, ask the CASP directly whether their onboarding process for newly issued tokens reflects ESMA's Q&A 2417. Specifically, confirm that newly issued tokens are brought within the custody arrangement under the existing authorisation without delay, and that the CASP's internal controls team has updated its legal basis documentation to reference the Q&A. A CASP that cannot demonstrate it has absorbed this guidance into its operating procedures is carrying unnecessary regulatory risk, which in turn becomes your counterparty risk.

Balance Sheet Classification of Newly Issued Tokens

From an accounting standards perspective, the timing of a token's issuance relative to its entry into a custody arrangement can affect how the asset is initially recognised and measured. Under IFRS, a digital asset held in custody by a third-party CASP must be assessed for derecognition by the CASP and for recognition by the beneficial owner. The ESMA Q&A does not change those IFRS principles, but it does remove a potential grey area about whether the custody arrangement is legally valid from inception: because the CASP's existing authorisation covers the newly issued token, there is no period during which the custody is legally unauthorised and therefore potentially unenforceable.

CFOs should ensure their digital asset accounting software captures the custody start date as the date the token is first received into custody under the authorised arrangement, not a later date tied to any hypothetical fresh authorisation filing. This matters for measurement, for the segregation of client assets in CASP balance sheets, and for the audit trail.

MiCA Compliance Calendar Updates

The broader MiCA compliance environment continues to evolve rapidly. The EU MiCA review consultation currently under way signals that further refinements to the framework are coming. Q&A 2417 is a relatively narrow but practically important piece of that evolving puzzle. CFOs should maintain a living MiCA compliance log that captures each new Q&A, technical standard, and supervisory statement as it is published, and that maps each item to a specific internal control or process owner. ESMA publishes Q&As on a rolling basis and the pace has increased as the industry moves into full MiCA operation.

The Broader Q&A Publishing Pattern

It is also worth understanding what ESMA's Q&A publications are and are not. They are not legally binding regulation in the same sense as a delegated act or a regulatory technical standard. They represent ESMA's supervisory interpretation of the existing rules and carry significant weight with national competent authorities across the EU. In practice, a CASP or its auditor that follows Q&A guidance has a strong basis for demonstrating regulatory good faith, while a firm that ignores published Q&As does so at its own risk in any supervisory examination.

For accounting firms, this means Q&As should be incorporated into client advice with appropriate framing: authoritative guidance that shapes how national supervisors will assess compliance, even though it sits below the level of binding secondary legislation. Firms using digital asset accounting software to support MiCA reporting should ensure that the software's logic reflects the service-category authorisation model that Q&A 2417 confirms, rather than any token-by-token authorisation model that would require manual overrides for every new issuance.

Frequently Asked Questions

Does ESMA Q&A 2417 mean a CASP can custody any newly issued token without restrictions?

No. The Q&A confirms that a CASP does not need a separate additional authorisation specifically because a token was issued after the CASP's own authorisation date. The CASP still needs to hold the correct service-category permission, custody and administration, or transfer, as applicable, and must apply all standard MiCA compliance obligations, including AML and KYC checks, to each asset and client.

How should auditors treat Q&A 2417 in a CASP audit?

Auditors should include a reference to Q&A 2417 in the authorisation scope section of the compliance audit workpaper, confirming that the client's custody of post-offer issued tokens is legally grounded in the existing authorisation. They should also verify that the client has updated its internal legal analysis and that its crypto accounting software correctly tags newly issued tokens under the authorised service category from the date of first custody.

Does this Q&A affect AML obligations for newly issued tokens?

No. ESMA's guidance addresses the authorisation question only. CASPs must still conduct full customer due diligence, apply transaction monitoring rules, and carry out any required risk assessments for newly issued tokens before bringing them into the custody offering. The removal of a fresh authorisation step does not remove any AML or KYC step.

What is the status of ESMA Q&As under EU law?

Q&As are supervisory guidance rather than binding secondary legislation. However, they reflect ESMA's official interpretation of the regulation and are used by national competent authorities when assessing compliance. Following published Q&As is strong evidence of regulatory good faith; departing from them without a well-documented legal basis creates material supervisory risk.

Should crypto accounting software be updated to reflect this Q&A?

Yes, to the extent that any existing configuration routes newly issued tokens through a separate authorisation-pending queue before including them in custody ledgers. Q&A 2417 confirms those tokens are within the authorised perimeter from day one of custody, so the software's asset classification and tagging logic should reflect that. Firms should review their digital asset accounting software setup with their compliance officer and ensure the documentation trail supports that position.

Source: ESMA

EUGeneralAdoptedAML/KYC & Licensing

FAQ

Does ESMA Q&A 2417 mean a CASP can custody any newly issued token without restrictions?

No. The Q&A confirms that a CASP does not need a separate additional authorisation specifically because a token was issued after the CASP's own authorisation date. The CASP still needs to hold the correct service-category permission, custody and administration, or transfer, as applicable, and must apply all standard MiCA compliance obligations, including AML and KYC checks, to each asset and client.

How should auditors treat Q&A 2417 in a CASP audit?

Auditors should include a reference to Q&A 2417 in the authorisation scope section of the compliance audit workpaper, confirming that the client's custody of post-offer issued tokens is legally grounded in the existing authorisation. They should also verify that the client has updated its internal legal analysis and that its crypto accounting software correctly tags newly issued tokens under the authorised service category from the date of first custody.

Does this Q&A affect AML obligations for newly issued tokens?

No. ESMA's guidance addresses the authorisation question only. CASPs must still conduct full customer due diligence, apply transaction monitoring rules, and carry out any required risk assessments for newly issued tokens before bringing them into the custody offering. The removal of a fresh authorisation step does not remove any AML or KYC step.

What is the status of ESMA Q&As under EU law?

Q&As are supervisory guidance rather than binding secondary legislation. However, they reflect ESMA's official interpretation of the regulation and are used by national competent authorities when assessing compliance. Following published Q&As is strong evidence of regulatory good faith; departing from them without a well-documented legal basis creates material supervisory risk.

Should crypto accounting software be updated to reflect this Q&A?

Yes, to the extent that any existing configuration routes newly issued tokens through a separate authorisation-pending queue before including them in custody ledgers. Q&A 2417 confirms those tokens are within the authorised perimeter from day one of custody, so the software's asset classification and tagging logic should reflect that. Firms should review their digital asset accounting software setup with their compliance officer and ensure the documentation trail supports that position.

Related articles

AML/KYC & Licensing
FATF's PPP Report: Crypto AML Gaps Firms Must Close Now
AML/KYC & Licensing
ESMA Launches Supervisory Action on CASP Custody Resilience
AML/KYC & Licensing
Digital Sovereignty Is Now a Board-Level Risk: What DORA and the ECB Mean for Crypto Accounting Software
AML/KYC & Licensing
Four Financial Centres Racing to Lead on Crypto Regulation