A significant CASP (a crypto-asset service provider classified as significant under the MiCA (Markets in Crypto-Assets Regulation) regime) carries materially heavier supervisory obligations than a standard authorised CASP – obligations that reshape compliance budgets, governance structures and cross-border operating models. With VASP supervision tightening across EU member states and ESMA asserting its coordinating role over national competent authorities, understanding where a business sits on this classification spectrum is not a theoretical concern. It is a business-critical one.
The classification turns on criteria set by ESMA and applied by the relevant national competent authority. Once a CASP crosses the threshold – measured by reference to the scale of its activities – enhanced supervisory engagement follows automatically. Businesses that fail to anticipate the reclassification risk being caught flat-footed: governance structures that were adequate at authorisation may not satisfy the elevated expectations that attach to significant status, and the consequences of non-compliance at this tier are correspondingly severe.
This analysis sets out what triggers significant CASP status, what changes operationally when it applies, how it interacts with AML compliance, the Travel Rule and KYC obligations, and what the cross-border operator should do before, not after, reclassification arrives.
What Is a Significant CASP and How Does the Classification Work?
A significant CASP is a crypto-asset service provider whose scale of activity – measured against criteria developed under the MiCA regime – crosses a supervisory threshold that triggers heightened regulatory engagement. The classification is not a licence upgrade; it is a status imposed by the national competent authority, in coordination with ESMA, once a CASP's operational footprint meets the relevant criteria.
Under MiCA, the criteria are activity-based. The regime focuses on factors such as the number of clients served across the EU, the volume of transactions processed and the geographic breadth of services offered. ESMA holds a coordinating mandate: it can recommend reclassification and is empowered to intervene where a national competent authority's supervision is considered insufficient for the scale of the entity being overseen.
The practical consequence of classification is direct. A significant CASP becomes subject to more intensive supervisory scrutiny – more frequent reporting cycles, enhanced governance expectations and, in some cases, expanded ESMA involvement alongside the home-state regulator. For a business that designed its compliance infrastructure around standard CASP obligations, the additional layer can expose structural gaps it did not know it had.
In our regulatory practice, we regularly advise CASPs that have grown through EU passporting into situations where their client numbers and transaction volumes place them squarely in the significant tier – sometimes before their internal compliance teams have recognised the trajectory. The time to assess exposure is during growth planning, not after an ESMA opinion lands in the inbox.
How Does Significant CASP Status Change Governance Requirements?
Significant CASP status elevates the minimum governance standard a business must meet, moving it from the baseline CASP authorisation conditions into a regime that more closely resembles the expectations applied to significant institutions in the banking sector. The practical gap between the two tiers is wider than many operators anticipate.
At the standard tier, a CASP is expected to maintain adequate management body oversight, clear segregation of client assets, and functional internal controls. At the significant tier, regulators expect more: documented escalation protocols, independent risk functions, board-level engagement with supervisory findings and, frequently, a more granular reporting cadence. The national competent authority retains primary supervisory responsibility, but it does so with ESMA's analytical lens now formally applied.
For a crypto exchange operating across multiple EU jurisdictions under the MiCA passporting regime, significant status in one member state effectively puts the whole network under a more intense spotlight. A home-state NCA conducting a thematic review at the request of ESMA will examine practices that touch every jurisdiction in which the passport applies – not just the home market.
The governance gap also manifests in practical ways: the board composition expectations, the independence of the compliance and risk functions, and the adequacy of management information produced for oversight purposes all become points of NCA scrutiny. Operators that have scaled quickly through organic growth or acquisition often find that governance infrastructure has lagged behind commercial expansion. That lag is precisely what enhanced supervision is designed to surface.
For a scoped governance-gap assessment before significant status is formally applied, contact OBOLUS at info@oboluslaw.com. The process above describes the standard compliance path. Your facts – the entity structure, the client footprint, the transaction volumes – change the analysis materially.
What AML Obligations Apply to Significant CASPs Under MiCA?
Significant CASPs operate at the intersection of MiCA's CASP regime and the broader EU AML/CFT architecture, and the combined effect of both frameworks imposes obligations that go beyond what a newly authorised standard CASP must satisfy from day one. The FATF Recommendations – including Recommendation 15, which applies the full FATF standards to virtual asset service providers – set the global baseline on which EU member-state AML law builds.
AML compliance for a significant CASP means, at minimum: a documented risk appetite, a risk-based customer due diligence framework with enhanced measures for higher-risk relationships, transaction monitoring calibrated to the asset types and geographies served, and a senior individual accountable for AML compliance – the MLRO (money-laundering reporting officer). At the significant tier, regulators expect each of these elements to be proportionate to the scale and complexity of the business, not merely present on paper.
Transaction monitoring deserves particular attention. A significant CASP processing large volumes across multiple chains and asset classes cannot rely on static rule sets designed for a smaller operation. ESMA and national competent authorities have indicated, through supervisory guidance and thematic reviews, that transaction monitoring calibration – the ongoing tuning of alert thresholds and typologies – is an active supervisory concern, not a set-and-forget exercise.
A KYC framework that was adequate for a few hundred institutional clients may be structurally insufficient for a significant CASP serving retail users across the EU. The risk-based approach requires genuine calibration: the due diligence applied to a retail spot-trading user in Germany is different from what applies to a corporate custody client domiciled in a non-EEA jurisdiction with a complex beneficial-ownership structure. Both must be right, and both will be tested.
How Does the Travel Rule Interact With Significant CASP Status?
The Travel Rule – the obligation to pass originator and beneficiary identifying data alongside a virtual asset transfer – applies to all CASPs under the EU's funds-transfer regulation as extended to crypto assets, regardless of whether the CASP is classified as significant. But significant status changes the supervisory stakes around Travel Rule compliance in ways that matter operationally.
For a standard CASP, Travel Rule deficiencies may be identified in an annual review or a routine supervisory submission. For a significant CASP, ESMA's coordinating role means Travel Rule compliance is a potential subject of cross-border thematic review, with findings shared across NCAs. A systematic failure to collect and transmit originator data – or to apply the required checks on incoming transfers from non-compliant counterparties – will be visible at a level that routine national supervision might not have caught quickly.
The cross-border dimension compounds the difficulty. A significant CASP operating with EU clients may receive transfers from CASPs domiciled outside the EU – in Singapore, the UAE, the UK or Switzerland – where the Travel Rule applies but the data standards and messaging formats differ. Reconciling those incoming data fields with the EU's requirements, at scale, requires technology infrastructure that smaller operators rarely have on day one of authorisation.
In our cross-border practice, we have seen operators assume that their Travel Rule obligations end at the technical act of transmitting data. In practice, regulators expect CASPs to have a documented policy for handling incomplete or absent originator data on inbound transfers – including the criteria for rejecting or delaying a transfer – and to be able to demonstrate that the policy is consistently applied. Significant CASPs are expected to demonstrate this at a higher evidentiary standard than the standard tier.
What Does the Cross-Border Operator Face When Significant Status Applies?
For a business that sits between jurisdictions – an exchange licensed under MiCA in one member state but banking in a non-EU hub, or a custodian serving EU institutional clients from a VARA-regulated Dubai entity – significant CASP classification in the EU creates a supervisory interface that must be actively managed on both sides of the border.
The MiCA passporting mechanism allows a significant CASP authorised in its home member state to provide services across the EU without separate authorisation in each host jurisdiction. But significant status in the home state means the home NCA is operating under ESMA's closer scrutiny, and that scrutiny extends to the cross-border services the passport enables. Host-state NCAs are entitled to raise concerns with the home NCA; ESMA acts as a coordination point. The result is that a significant CASP with widespread EU reach is, effectively, under distributed supervisory observation.
The banking interaction is particularly acute. A significant CASP that cannot demonstrate robust AML compliance – including a functional KYC framework and a mature transaction monitoring programme – will find it difficult to maintain banking relationships with EU-regulated institutions. Banks conducting correspondent or payment services due diligence on a CASP client now have ESMA's assessment of that CASP's significance as a data point. Supervisory friction at the regulatory level translates, almost directly, into banking friction at the commercial level.
For operators with a VARA-regulated entity in Dubai serving EU clients through a MiCA-licensed affiliate, the two regulatory regimes must be mapped against each other. VARA and MiCA do not have a mutual recognition arrangement; AML standards, KYC depth and Travel Rule implementation must satisfy both regimes independently. Where the stricter standard applies, that becomes the floor for the group.
If your structure spans EU and non-EU hubs and significant CASP status is in view, write to info@oboluslaw.com before the compliance gap widens. A second read of a structure that has already attracted supervisory comment can surface the design issue and the route to resolution.
Decision Matrix: Which Operator Profile Should Prepare for Significant Status?
Not every authorised CASP is on a trajectory toward significant classification, but the profiles that are tend to share identifiable characteristics. Mapping those characteristics against the applicable regime obligations allows an operator to prepare, rather than react.
Profile A: The EU-wide retail exchange. A CASP providing spot trading services to retail users across multiple member states, operating under a passport from a single home-state authorisation, with transaction volumes growing quarter on quarter. This is the profile most directly in the significant tier's sights. The governance and AML infrastructure that supported a mid-sized operation in the home state must now be stress-tested against the expectations applied to a systemically relevant retail intermediary. The indicative priority is governance uplift and transaction-monitoring recalibration, ahead of supervisory review. The key risk is the gap between the legal compliance function (which may have been sized for standard CASP status) and the analytical depth regulators will expect at the significant tier.
Profile B: The institutional custodian with EU clients. A custody-focused CASP serving institutional counterparties – family offices, funds, corporate treasury functions – across the EU, with a relatively small client count but large individual balances. Significant status may apply based on the volume of assets held rather than the raw transaction count. The governance question here centres on the adequacy of enhanced due diligence for large or complex beneficial ownership structures, and on the adequacy of safeguarding documentation. The cross-border risk is acute if the custodian is operating from a non-EU hub: MiCA's reach over third-country CASPs providing services to EU clients is a live and developing issue.
Profile C: The multi-service VASP expanding into the EU. A business currently regulated under VARA in Dubai or under the MAS Payment Services Act in Singapore, now seeking MiCA CASP authorisation to serve EU institutional clients directly. At launch, this entity will not be significant. But if the business plan anticipates rapid EU growth, the structural decisions made at authorisation – governance architecture, AML framework design, Travel Rule vendor selection – will determine how painful the transition to significant status becomes later. Operators we advise in this position regularly ask us to design for the significant tier from the outset, precisely to avoid a costly rebuild.
What Mistakes Do CASPs Make When Approaching Significant Status?
The most common error is treating significant CASP status as a future administrative event rather than a present design constraint. By the time a national competent authority formally communicates that a CASP has crossed the classification threshold, the window to remediate structural deficiencies without supervisory friction has already closed.
A second frequent failure is mis-calibrating the AML programme. A CASP that was authorised with a straightforward KYC framework – adequate for a narrower client base – often finds that its transaction monitoring rules have not been updated as the product range and client geography expanded. When significant status triggers enhanced supervisory scrutiny, the first thing an NCA looks for is evidence that the AML programme has kept pace with the business. Static rule sets and stale risk assessments are immediately visible.
A third mistake is underestimating the cross-border interaction. Operators running parallel entities – a MiCA CASP in one jurisdiction, a separately licensed entity in a non-EU hub – sometimes design their compliance programmes in silos, with each entity meeting its local minimum. That approach fails at the group level when ESMA's coordinating oversight surfaces inconsistencies between what the EU entity reports and what the non-EU affiliate does in practice. Regulators in the leading hubs increasingly expect group-level AML policies that apply the stricter standard across the whole structure.
A common assumption worth addressing directly: a single offshore registration – maintained outside the EU, outside the VARA or MAS regimes, in a lower-supervision environment – does not insulate a CASP from MiCA's reach if the business is actively marketing to EU clients or holding assets for EU counterparties. MiCA's jurisdictional reach is defined by where services are provided and where clients are located, not by where the operating entity sits. The offshore-only model, when applied to EU client acquisition, exposes the business to enforcement risk, banking closure and, ultimately, asset-level disruption.
In a recent regulatory advisory matter, a payments-adjacent CASP had structured its EU operations around a standard authorisation in one member state while growing its client base through the passport into seven further jurisdictions. By the time we were instructed, the transaction volume had already placed the entity in the significant tier on the relevant criteria, but the governance documentation had not been updated since authorisation. We worked with the client to map the gap, restructure the management information framework and engage proactively with the home NCA ahead of the supervisory review cycle. The outcome was a structured remediation timeline agreed with the regulator, rather than an enforcement process.
What Self-Assessment Should a CASP Conduct to Evaluate Its Significant-Status Exposure?
A self-assessment for significant-status exposure is not a one-time exercise; it is a standing obligation for any CASP whose client numbers, transaction volumes or asset values are on an upward trajectory. The following points are not exhaustive but represent the minimum an operator should review.
First, measure the business against the classification criteria in the applicable ESMA guidance. That means quantifying – at least quarterly – the number of EU clients served, the volume of transactions processed within the EU, and the geographic distribution of services. These numbers should be maintained in a form that can be presented to the NCA at short notice.
Second, map the governance infrastructure against significant-tier expectations: Is the management body receiving structured, documented information about AML risk? Is the compliance function independent of business-line management? Does the MLRO have direct board access? Are escalation protocols documented and tested?
Third, audit the KYC framework. Are enhanced due diligence procedures being applied consistently to high-risk customers? Is beneficial ownership verified to the depth the regime requires? Is the customer risk model updated as the client portfolio evolves?
Fourth, test the transaction monitoring programme. Not its existence – its performance. Are alert thresholds calibrated to the asset types and transaction patterns actually being processed? Is there a documented process for tuning the rules as typologies evolve? Can the CASP demonstrate that suspicious transaction reports are filed at the right time and with the right quality?
Fifth, map the Travel Rule implementation across all corridors. For transfers to and from non-EU counterparties – including those regulated under VARA, the MAS Payment Services Act or the FCA's AML registration – is the data collected, transmitted and verified in the manner the EU regime requires? Is there a documented policy for incomplete data on inbound transfers?
Sixth, assess the group-level picture. If the business operates through entities in multiple jurisdictions, does the group AML policy apply the stricter standard across all of them? Is there a group compliance function that has visibility into each entity's exposure?
Related at OBOLUS
- AML, Travel Rule and KYC compliance for digital-asset businesses – end-to-end advisory on building a defensible AML programme across jurisdictions
- KYC for crypto – a legal guide for digital-asset businesses – a detailed breakdown of what a compliant KYC framework requires under leading regimes
- Utility token legal opinion in Luxembourg – the role of formal legal opinion in token classification and cross-border structuring
FAQ
What does the Travel Rule require from a VASP?
The Travel Rule requires a virtual asset service provider to collect and transmit identifying information about the originator and beneficiary of a virtual asset transfer alongside the transfer itself. The obligation applies above a defined value threshold that varies by jurisdiction. In the EU, the funds-transfer regulation extended to crypto assets mandates this data exchange between CASPs. Compliance requires both the technical capability to transmit the data and a documented policy for handling transfers where the counterparty CASP cannot provide complete information.
Who must act as MLRO for a crypto firm?
A money-laundering reporting officer (MLRO) is the senior individual accountable for a firm's AML compliance programme, including suspicious activity reporting and engagement with financial intelligence units. Most EU jurisdictions and leading licensing hubs require the MLRO to be a named, approved or notified individual with the seniority and independence to make autonomous compliance decisions. For a significant CASP, regulators expect the MLRO to have direct board access and adequate resources to discharge the function across the full scope of the business – not just the home-jurisdiction operations.
How do regulators audit crypto AML programs?
National competent authorities audit crypto AML programmes through a combination of document review, on-site inspection and thematic supervisory work. Regulators examine customer risk assessments, transaction monitoring alert logs and investigation records, suspicious transaction report volumes and quality, governance documentation and management information provided to the board. For significant CASPs, ESMA may coordinate cross-border thematic reviews that examine the same firm's practices across multiple jurisdictions simultaneously. The standard is proportionality: the programme must be calibrated to the firm's actual risk profile, asset types and client geography.
About OBOLUS
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise crypto exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the AML, KYC and Travel Rule compliance that sits around them. We map the licence, compliance and banking stack across operating, custody and payment layers before our clients commit to a structure. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com or message us at t.me/oboluslaw.
By Victor Olsen, Regulatory & Compliance Analyst – specialist in MiCA compliance architecture, VASP authorisation and cross-border AML programme design for digital-asset businesses.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.