An independent reading of your technology against what MiCA authorisation and ongoing CASP supervision actually require, in writing, by someone with no implementation work to sell.
You’re applying for CASP authorisation, or you already hold it. Either way, the technology evidence a regulator actually tests — ICT risk management, governance structure, custody architecture, AML infrastructure operating in practice, not just on paper — is different from what most application files assume is sufficient. What you don’t have is an independent reading of whether your technology would actually survive that scrutiny.
That is what this engagement is.
€15,000. Three to four weeks. Delivered in writing, with a presentation to whoever needs to hear it.
Fixed fee. No implementation work. No commissions. No product recommendations influenced by suppliers.
Why clients commission this review
- A CASP authorisation application is being prepared, and the board wants independent confirmation the technology evidence will hold up before submission.
- Authorisation is already granted, and the board wants a baseline ahead of the next NCA supervisory review or FIAU inspection.
- A gap has emerged between what the compliance file claims and what the technology function can actually demonstrate operationally.
- The firm is expanding to a second MiCA member state and needs confirmation the technology evidence travels with the passport.
- A banking partner or institutional counterparty has asked for independent confirmation of the ICT risk and custody control environment.
Who this is for
CASPs applying for MiCA authorisation, or already authorised, who want independent confirmation the technology evidence matches what supervisors actually test.
Boards and compliance functions preparing for a specific supervisory event — an application decision, an inspection, a banking partner’s own due diligence.
Who this is not for
Firms wanting the application itself drafted or filed — that’s regulatory legal work, and we’ll point you toward specialist counsel where needed.
Buyers evaluating a CASP acquisition target — that’s Technology Due Diligence, with different scope and commercial terms.
Firms wanting custody architecture built or implemented. We identify and recommend; we do not implement.
What you receive
The Review tells you three things in writing: where your technology evidence stands against what MiCA supervision actually tests, where the priorities are, and what to address before your next supervisory touchpoint. Five artefacts, delivered together, in plain language.
A scored reading against MiCA’s operational requirements. ICT risk management under Article 68, governance and fit-and-proper evidence, custody architecture, and AML/KYC infrastructure — assessed with evidence, not assumed from the policy documents alone.
A gap analysis between documented policy and operational reality. Where the compliance file says one thing and the live systems and workflows say another — the specific gap supervisors are trained to find.
A risk register sorted by supervisory impact. Every material gap identified, ranked by what it would mean in an actual inspection or application review.
A prioritised remediation roadmap. What to address first, second, third, sequenced against your actual supervisory timeline — an application deadline, an upcoming inspection, a banking partner’s review.
A board presentation. A one-hour session with your board, compliance committee, or whoever needs to sign off before the next supervisory touchpoint.
How the Review runs
Three to four weeks, in four phases.
Week one — scoping and inventory. Stakeholder mapping, document gathering, and calibration against your specific licence scope and authorisation status.
Week two — interviews and evidence gathering. Interviews across compliance, technology, AML, and custody operations. Evidence collected against each MiCA-relevant requirement.
Week three — synthesis and writing. Findings written up into the artefacts above. Scoring calibrated against what NCA and FIAU inspections actually test.
Week four — presentation and revisions. The board or committee session, scheduled around your existing rhythm.
Everything is written before it is said. Nothing is presented to your board that you have not read first.
What this is not
Regulatory legal advice or application drafting. The Review can inform an application; it does not substitute for regulatory counsel.
A remediation engagement. We identify and recommend; we do not implement.
A guarantee of authorisation or a clean inspection outcome. The Review tells you where the evidence stands — the supervisory decision is the regulator’s.
Proof
References available on request. Anonymised excerpts from prior reviews available on request.
What happens next
Start a ConversationThirty minutes. We confirm fit, scope, and timing against your supervisory calendar. You decide whether to proceed. No proposal is sent unless you ask for one.
Not sure this is the right depth yet? Start with the Technology Control Assessment — €4,950, three to five working days.