A MiCA control record connects a legal anchor to an operational risk, testable system behavior and a durable evidence artifact. The five records below are worked engineering examples, not a complete compliance catalog. Applicability and legal interpretation must be confirmed by qualified counsel before implementation.
Every record uses the same fields:
Control ID: stable internal identity that survives wording changes.
Legal anchor: the primary source and relevant article.
Applicability: the services, systems or circumstances that activate the record.
Operational risk: the failure the control addresses.
System behavior: what the product or platform must do.
Evidence artifact: what must remain retrievable after the event.
Owner and test: who evaluates the control and how failure is detected.
Legal anchor: MiCA Article 68(7) and Commission Delegated Regulation (EU) 2025/299, Articles 2 to 5.
Regulatory source summary: the management body establishes and endorses business-continuity plans, procedures and measures, reviews effectiveness at least annually, and documents realistic testing. Plans cover adverse scenarios, recovery deadlines, recovery point objectives, maximum service-resumption time, backup data and stakeholder communication.
Operational risk: a disruption is handled technically but the approved recovery path, decision trail, client communication and annual test evidence cannot be reconstructed.
Software control: maintain a versioned continuity register that binds critical functions to scenarios, activation criteria, accountable roles, recovery objectives, communication templates and test results.
Evidence artifact: approved policy version; management decision; scenario and dependency inventory; test run; recovery timestamps; deviations; client notices; remediation owner and closure proof.
Test: select one critical function and reconstruct the last exercise from approval through restoration and remediation without consulting private messages or individual memory.
Legal anchor: MiCA Article 68 and Commission Delegated Regulation (EU) 2025/1140, Articles 2 to 5.
Regulatory source summary: records must remain accessible for future reference, permit competent authorities to reconstruct key processing stages, expose corrections and prior contents, resist manipulation and support efficient analysis. Certain client-rights documents are retained for five years after termination and, following a timely competent-authority request, for up to seven years.
Operational risk: the platform can display the current state but cannot reproduce the sequence, earlier values, actors and reasons that produced it.
Software control: append events rather than overwrite history; preserve source identifiers, actor identity, timestamps, version links, correction reasons and export provenance; enforce record-class retention policies.
Evidence artifact: immutable event sequence; correction lineage; retention configuration; access log; schema version; export manifest; retrieval-test result.
Test: reconstruct one sampled order, transaction or service event from ingestion to final state, including every correction, then verify the export against the source ledger.
Legal anchor: MiCA Article 71 and Commission Delegated Regulation (EU) 2025/294.
Regulatory source summary: clients must be able to complain free of charge; procedures and a template must be published; submissions must be possible electronically or on paper and in specified languages; receipt and admissibility require handling without undue delay; management oversees the procedure and receives effectiveness reporting.
Operational risk: complaints arrive across channels but are not reconciled into one register, or a status report cannot be tied to underlying cases and communications.
Software control: generate one stable case ID at intake; retain the original submission; track admissibility, ownership, evidence, communication and outcome as explicit states; reconcile management metrics to the case register.
Evidence artifact: original complaint; language and channel; acknowledgement; admissibility decision and reason; investigation log; client communication; outcome; remediation; management report.
Test: trace a sample case from submission through its reported aggregate and verify that no required state can be skipped without an authorized exception.
Legal anchor: MiCA custody requirements and Delegated Regulation 2025/1140, Article 5.
Regulatory source summary: custody records must distinguish, at any time and without delay, one client's crypto-assets and funds from another client's holdings and from the CASP's own assets. The records must support audit use and identify balances, relevant accounts, third parties, responsible persons and ownership agreements.
Operational risk: wallet, omnibus, sub-ledger and client records reconcile operationally but cannot prove ownership and segregation at a chosen point in time.
Software control: bind client entitlements to custody accounts and wallet evidence; preserve reconciliation runs, exceptions and approvals; block silent write-offs or manual balance adjustments.
Evidence artifact: client-level balance snapshot; custody-account mapping; wallet ownership record; reconciliation inputs and outputs; exception case; approval; correction lineage.
Test: choose a historical timestamp and reproduce client, aggregate and proprietary balances, including every unresolved break and the person accountable for it.
Legal anchor: MiCA Article 92 and Commission Delegated Regulation (EU) 2025/885.
Regulatory source summary: persons professionally arranging or executing crypto-asset transactions need effective arrangements, systems and procedures to prevent and detect market abuse and report reasonable suspicions without delay. The delegated standard requires an appropriate level of human analysis alongside monitoring and detection.
Operational risk: surveillance produces alerts, but investigators cannot reproduce why an alert fired, which data was considered, who made the decision or why a case was closed or escalated.
Software control: version detection rules and models; retain inputs and feature values; route alerts into a case workflow; require reasoned human disposition; preserve escalation and reporting decisions.
Evidence artifact: rule or model version; triggering events; alert payload; analyst actions; evidence attachments; disposition code and narrative; escalation; report reference; quality review.
Test: replay a closed and an escalated alert against their original rule version and prove that the decision record has not been silently rewritten.
Create one record per counsel-approved obligation, preserve source wording and exceptions, then assign the engineering interpretation a separate label. A control map should narrow implementation uncertainty; it should never masquerade as a legal opinion.
Editorial owner: Pharos Production
Last source check: 13 August 2026
Status: worked examples for scoping; not a complete control library.