MiCA implementation fails when a policy statement, workflow and retained record describe different realities. These six engineering patterns focus on that gap. They are implementation notes, not a substitute for legal interpretation or a complete control catalog.
Pattern: bind every obligation to a risk, system behavior, evidence artifact, owner, test and source version.
Failure mode: a requirement is marked "implemented" because a vendor feature exists, although nobody has shown which configuration, workflow and retained record satisfy the obligation.
Evidence to retain: source identity; applicability decision; control version; configuration snapshot; acceptance test; reviewer; change trigger.
A graph exposes shared dependencies. One complaint, order or wallet identifier may connect several controls; duplicating those identifiers differently in each checklist creates reconciliation risk.
Delegated Regulation (EU) 2025/1140 requires records to expose corrections or amendments and their previous contents while resisting manipulation. A mutable database row can hold the latest truth without preserving the regulatory history.
Pattern: record corrections as new events linked to the prior event, with actor, timestamp, reason and approval where required.
Failure mode: a corrected client, order or transaction record looks clean, but the system cannot show when the error existed, who changed it or which reports used the earlier value.
Evidence to retain: original event; correction event; reason; actor; approval; affected exports and reports; reprocessing result.
Delegated Regulation (EU) 2025/299 requires realistic business-continuity testing and written results, with annual testing that considers prior results, current threats, previous events and changing recovery objectives.
Pattern: define testable scenarios, expected recovery sequence, recovery point and time objectives, evidence capture and remediation closure before the exercise starts.
Failure mode: the exercise is marked complete because a meeting occurred, but actual service restoration, data integrity and client communication were not tested.
Evidence to retain: approved scenario; participants; start and recovery timestamps; data checks; communications; deviations; management review; remediation and retest.
Email, web forms, paper submissions and support tools can all receive complaints. If each channel keeps its own status, management reporting becomes a spreadsheet exercise and case history fragments.
Pattern: create the stable complaint ID at the first controlled intake point, retain the original content and reconcile every channel to one case state machine.
Failure mode: an acknowledgement is sent, but the case never reaches the register; or a management metric cannot be traced back to the cases it counts.
Evidence to retain: original submission; channel and language; acknowledgement; admissibility; ownership; investigation; communication; outcome; remediation; reporting inclusion.
MiCA Article 92 and Delegated Regulation (EU) 2025/885 require systems and procedures to prevent, detect and report suspected market abuse; the delegated standard calls for an appropriate level of human analysis.
Pattern: version detection logic, preserve triggering inputs and require a reasoned analyst decision tied to the alert and any escalation.
Failure mode: model or rule updates make an old alert impossible to replay, or a closure code records the outcome without the analysis that justified it.
Evidence to retain: rule/model version; features; alert; analyst activity; attached evidence; disposition narrative; escalation; quality review.
Specialist providers often supply identity verification, sanctions screening, blockchain analytics and Travel Rule exchange. Build orchestration and evidence around them; do not pretend the CASP controls their internal systems.
Pattern: define timeout, retry, fallback, degraded-service, manual review and evidence behavior for each vendor before go-live.
Failure mode: the primary vendor times out and the platform either approves activity without the intended check or silently blocks it with no reviewable decision trail.
The commonly used phrase "MiCA KYC" joins separate legal workstreams. Pharos Production's MiCA KYC and Travel Rule guide explains why KYC duties arise from the EU AML framework and Transfer of Funds Regulation rather than MiCA itself.
Select one real case and ask a reviewer who did not build the system to reconstruct the source, rule version, decision, exception, communication and final report. If reconstruction depends on private messages or developer memory, the evidence design is unfinished.
Editorial owner: Pharos Production
Last source check: 13 August 2026
Scope: engineering patterns only; counsel determines legal sufficiency.