This worksheet turns a counsel-approved MiCA obligation into an engineering control record. Complete one record per obligation. Do not begin vendor selection or backlog estimation until the owner, evidence artifact, system boundary and retrieval test are explicit.
Control ID: stable internal identifier.
Legal anchor: primary source, article, version and retrieval date.
Applicability: entity, service, jurisdiction, conditions and exclusions.
Operational risk: the concrete failure to prevent or detect.
Required system behavior: observable behavior, not a product name.
System boundary: systems of record, upstream sources, downstream consumers and third parties.
Data and identity: subject, client, account, wallet, order, transaction, case and actor identifiers.
Evidence artifact: event, document, approval, communication, report or test output that proves operation.
Accountable owner: control owner, system owner and reviewer.
Control test: sample, procedure, expected result and failure condition.
Review trigger: source change, service change, incident, failed test, vendor change or scheduled review.
Record which crypto-asset services the entity provides, where it is established, which home and host states are involved, and which legal source counsel has approved for the record. Preserve limitations and exclusions. "MiCA applies" is not a usable scope statement.
Decision gate: no implementation status can move beyond Draft until the applicability field names its legal reviewer or approved legal source.
List the system of record and every dependency that can change the control outcome: identity provider, blockchain analytics vendor, Travel Rule network, custody platform, trading engine, case-management tool, data warehouse, notification service and manual spreadsheet.
For each dependency, record:
data received and produced.
identity used to reconcile records.
failure and timeout behavior.
retry or manual fallback.
evidence retained when the dependency is unavailable.
contractual or technical limit that the CASP cannot control.
An evidence artifact needs enough context to answer six questions without reconstructing the system from source code:
What happened?
To which client, asset, order, transaction or case?
When did it happen, and which clock is authoritative?
Which rule, model, policy or workflow version applied?
Who or what made and approved the decision?
What changed later, and why?
Overwriting the current state destroys this chain. Use append-only events or equivalent correction lineage so an amendment preserves the prior content, actor, time and reason.
A retention period is only useful when records can be found and interpreted. Define a realistic sample, maximum retrieval time, required export format, reconciliation procedure and acceptable exceptions. Run the test with someone who did not build the control.
Example: "Given a historical complaint ID, reconstruct the original submission, acknowledgement, admissibility decision, investigator actions, client communications, outcome and management-report inclusion from retained records."
Document the conditions under which an automated decision can be overridden, the person authorized to do it, the required reason, second-line review and the evidence retained. A hidden administrator switch is not an exception process.
A control is ready for release only when:
the legal source and applicability are recorded.
normal and failure paths are specified.
every external dependency has an unavailable-state design.
identifiers reconcile across systems.
corrections preserve prior content.
the evidence artifact has an owner and retention rule.
a reviewer can replay the control from retained records.
source and system changes trigger re-review.
The worksheet does not classify tokens, select a home Member State, determine whether an activity is a crypto-asset service, or replace an NCA or counsel interpretation. It begins after those decisions have been made and makes their engineering consequences traceable.
When the worksheet exposes a build gap, Pharos Production's MiCA compliance software development page describes the adjacent implementation scope.
Editorial owner: Pharos Production
Last source check: 13 August 2026
Worksheet version: 0.1 draft.