CryptaCount
EN
EnglishENDeutschDEEspañolESFrançaisFRItalianoIT日本語JA한국어KONederlandsNLPolskiPLPortuguêsPT
Log in Start Free

ESMA's 2027 Digital Innovation Priority: What It Means for Firms

CryptaCount Editorial · · 10 min read
AML / KYC / LICENSING ESMA's 2027 Digital InnovationPriority: What It Means for Firms

The European Securities and Markets Authority has confirmed it will launch a new Union Strategic Supervisory Priority on digital innovation, starting from 2027. The initial focus is on how supervised entities use artificial intelligence and tokenisation, and it will run in parallel with the existing cyber and operational resilience priority that has been active since 2025. For accounting firms, auditors, and CFOs advising EU-regulated clients, this is a direct signal that supervisors are building the expertise to scrutinise every layer of a firm's technology stack, including its crypto accounting software and digital asset accounting software infrastructure.

ESMA's 2027 Digital Innovation Priority: What It Means for Firms

What a Union Strategic Supervisory Priority Actually Is

USSPs are ESMA's formal convergence instruments. They direct supervisory resources across the EU toward the risks that the authority considers most material for investor protection, financial stability, and the orderly functioning of European financial markets. By elevating a topic to USSP status, ESMA signals to all National Competent Authorities that they should align their inspection programmes, data requests, and enforcement focus accordingly.

From voluntary guidance to co-ordinated pressure

A USSP is not a new rulebook. It does not create fresh legal obligations by itself. What it does is concentrate supervisory attention in a way that reshapes the practical risk calculus for regulated firms. When ESMA ran its USSP on ESG disclosures from 2023, NCAs across the bloc began issuing targeted requests and mystery-shopping exercises that went well beyond what the underlying regulation strictly required. Firms that had treated ESG as a disclosure exercise rather than a governance one were caught off-guard.

The same dynamic is now in play for digital innovation. ESMA has explicitly stated it will collaborate with NCAs on how supervised entities use AI and tokenisation, and that it will remain flexible to address further technological developments as they emerge, including those arising from advanced frontier AI models. The practical implication is that NCAs will be equipped, and expected, to ask hard questions about technology governance from 2027 onward.

The Two Core Technologies in Scope

Artificial intelligence in regulated workflows

ESMA's reference to AI is broad by design. Supervised entities that use algorithmic tools for trading decisions, client onboarding, surveillance, risk modelling, or indeed crypto bookkeeping software automation are all potentially in scope. The authority has separately co-signed a joint ESA call, alongside EBA and EIOPA, for enhanced governance and consistent supervision to mitigate ICT risks from frontier AI models in the EU financial sector. That document reinforces the message: it is not enough to deploy AI, firms must demonstrate they govern it.

For accounting and audit teams, this has an immediate practical dimension. Automated reconciliation tools, anomaly-detection engines, and AI-assisted journal-entry workflows that touch digital asset portfolios will need to sit inside a governance framework that a supervisor can inspect. Firms that adopted these tools rapidly during the crypto boom years, without contemporaneous policy documentation, should treat the 2027 horizon as a remediation deadline rather than a distant concern.

Tokenisation and its supervisory implications

ESMA's inclusion of tokenisation alongside AI is significant. Tokenisation of financial instruments, real-world assets, and settlement assets is accelerating across the EU, driven in part by the DLT Pilot Regime and the broader MiCA framework. Supervisors recognise that tokenised structures create new custody arrangements, novel settlement finality questions, and valuation challenges that traditional oversight frameworks were not designed to handle.

For firms using digital asset accounting software to record tokenised positions, the supervisory lens will extend beyond whether the positions are correctly valued. NCAs will want to understand the end-to-end technology chain: which platform generates the transaction data, how that data flows into the accounting ledger, what controls exist to prevent manipulation, and who has oversight of the process. This mirrors the governance questions ESMA raised in its ESG USSP but applied to a technically more complex asset class.

Interaction with the Cyber and Operational Resilience USSP

The digital innovation USSP does not replace the cyber and operational resilience USSP that has been in place since 2025; it runs alongside it. That matters for how firms structure their responses. The resilience USSP already requires supervised entities to demonstrate robust ICT risk management, incident reporting, and third-party dependency mapping under DORA. The new digital innovation USSP adds a layer: supervisors will now also assess whether firms understand and govern the novel risks that their specific technology choices introduce.

Overlapping obligations for crypto-active firms

A firm that relies on a tokenised settlement system, runs AI-driven AML screening, and uses crypto accounting software to produce regulatory reports is sitting at the intersection of both USSPs simultaneously. The practical workload doubles. Firms should not treat the two priorities as separate workstreams requiring separate teams. The most efficient response is an integrated technology governance framework that satisfies both the resilience and the innovation supervisory lenses from a single policy architecture.

For audit firms providing assurance over digital asset disclosures, this integration point is also relevant. Audit procedures that were designed around static ledger data will need to evolve to cover dynamic AI outputs and on-chain transaction records. The competence requirements for audit teams working in this space are rising.

The ESG USSP Conclusion: A Useful Precedent

ESMA has confirmed it is concluding the ESG disclosures USSP this year, following its launch in 2023. The authority describes the outcome as showing strong progress in improving ESG disclosures and helping investors better understand sustainability information. It also cautions that ESG remains a long-term journey despite the milestone.

This conclusion is instructive for anyone trying to anticipate how the digital innovation USSP will play out. The ESG cycle ran approximately four years from launch to formal conclusion. It generated supervisory convergence reports, NCA inspection campaigns, and sector-specific recommendations along the way. Firms that engaged early with the ESG priority were better positioned when NCA questions arrived. Firms that waited for formal enforcement signals faced a compressed remediation timeline.

The digital innovation USSP starts from 2027. If the ESG cycle is any guide, the most intense supervisory activity, meaning NCA data requests, thematic reviews, and potential enforcement referrals, is likely to cluster between 2028 and 2030. That is not a long runway for firms that have not yet begun mapping their AI and tokenisation governance.

ESMA's 2027 Digital Innovation Priority: What It Means for Firms

Accounting and Audit Implications for Firms

For accounting firms and auditors

The USSP creates two distinct pressures for professional services firms. First, as advisers to regulated entities, they will be asked to help clients build the governance documentation that supervisors will request. That means updating engagement scopes to include technology risk assessments alongside traditional financial statement work. Second, as organisations that themselves use AI-assisted audit tools and digital asset accounting software, accounting firms may themselves fall within the supervisory perimeter depending on their regulated status in relevant EU jurisdictions.

Firms should begin by cataloguing every AI-assisted workflow that touches a regulated client's digital asset data. For each workflow, the questions are: who approved its use, what testing was performed before deployment, what ongoing monitoring exists, and where is that documented? If those questions cannot be answered quickly, the governance gap is real and the 2027 supervisory horizon is closer than it looks.

Audit standards will likely need to adapt as well. Procedures for assessing the completeness and accuracy of on-chain transaction data, validating AI-generated valuations, and testing the integrity of tokenised asset records are not yet standardised. Firms that develop these procedures internally before standard-setters mandate them will have a competitive advantage and a stronger defence if supervisory questions arise.

For CFOs and finance teams at regulated entities

CFOs at MiCA-regulated CASPs, MiFID investment firms with digital asset exposure, and fund managers holding tokenised instruments should treat the USSP announcement as a governance trigger. The immediate priority is a technology inventory: what AI tools are in use, who owns them, and how are they connected to financial reporting outputs? For many firms, this inventory does not yet exist in a form that a supervisor could inspect.

The next step is policy documentation. Existing ICT governance policies should be reviewed to confirm they explicitly address AI decision-making and tokenisation processes. Where gaps exist, remediation should be scoped and scheduled. Finance teams should also consider how their crypto accounting software vendor relationships are governed: under DORA's third-party risk requirements, a software vendor that generates regulatory data is a critical ICT provider and must be treated accordingly.

For firms that are already working through MiCA authorisation or operating under transitional provisions, this USSP adds weight to the argument for investing in robust, auditable digital asset accounting software now rather than retrofitting governance around a system that was chosen for operational convenience. Supervisors assessing innovation risk will look at the quality of a firm's records infrastructure as a proxy for the quality of its overall technology governance. Given the close relationship between MiCA compliance and broader EU supervisory expectations, understanding how the ESCB is pushing to rewrite MiCA stablecoin liquidity rules is directly relevant to how firms should architect their reporting systems today.

Preparing Before 2027: Practical Steps

Build the technology inventory now

Start with a complete map of every AI and tokenisation-related system in use across the firm. Include third-party platforms, API integrations, and any automated process that produces data used in regulatory filings or financial statements. This inventory becomes the foundation for both the DORA third-party risk assessment and the incoming digital innovation supervisory review.

Align governance documentation to supervisory expectations

ESMA and the NCAs will look for evidence that senior management owns the technology risk, not just the IT department. Governance frameworks should include board-level or executive-level sign-off on AI deployment decisions, clear accountability for tokenisation infrastructure, and periodic review cycles for all digital innovation tools. Document these in a form that can be presented to a supervisor without requiring extensive translation.

Invest in staff competency

ESMA has stated explicitly that the USSP aims to ensure supervisors themselves have the expertise and capacity to oversee new technologies. Supervised firms should make the same investment. Compliance officers, internal auditors, and finance staff who understand how AI systems generate outputs and how tokenised asset records are created will be far better placed to respond to NCA requests, and to identify problems before supervisors do. The broader trajectory of digital finance across the EU, explored in our analysis of ESMA's Eurosystem Pontes platform and its digital asset accounting implications, makes this competency investment increasingly urgent.

Source: European Securities and Markets Authority (ESMA)

Frequently Asked Questions

What is a Union Strategic Supervisory Priority and why does it matter?

A USSP is a formal tool ESMA uses to align supervisory focus across all EU National Competent Authorities. It directs inspection resources toward the risks ESMA considers most significant for investor protection and financial stability. Being designated a USSP means NCAs across the bloc will actively assess how regulated firms manage the relevant risk area, making it a material compliance consideration even where no new legal obligation has been created.

When does the digital innovation USSP start and what is its scope?

ESMA has confirmed the priority will start from 2027. The initial focus is on AI and tokenisation use by supervised entities, with ESMA noting it will remain flexible to address other emerging technologies, including frontier AI models, as they develop.

Does this create new legal obligations for firms under MiCA or MiFID?

Not directly. A USSP is a supervisory convergence tool rather than a new rulebook. However, it shapes how NCAs exercise their existing supervisory powers, meaning firms can expect more targeted inspections, data requests, and thematic reviews focused on AI governance and tokenisation risk from 2027 onward.

How should firms think about their crypto accounting software in the context of this priority?

Any crypto accounting or digital asset accounting software that uses AI-assisted processes, interfaces with tokenised asset platforms, or produces data used in regulatory filings is potentially in scope. Firms should confirm that their software vendor relationships are governed under DORA's third-party risk rules, that the software's outputs can be explained and validated, and that there is clear internal accountability for the tool's use.

What can firms learn from the ESG USSP cycle?

The ESG USSP ran from 2023 and is concluding in 2025 or 2026 after generating NCA inspection campaigns, convergence reports, and sector recommendations. Firms that engaged early were better prepared when direct supervisory contact occurred. The digital innovation USSP should be treated the same way: beginning governance work now, well before formal NCA activity intensifies, is significantly less costly than reactive remediation.

EUGeneralProposedAML/KYC & Licensing

Related articles

AML/KYC & Licensing
ESMA Names AI and Tokenization a Union Supervisory Priority From 2027
AML/KYC & Licensing
Deutsche Bank Launches Digital Asset Custody in Europe
AML/KYC & Licensing
MiCA, Sanctions and DeFi AML: The 2023 Regulatory Outlook for Crypto Accounting
AML/KYC & Licensing
Poland Upholds Crypto Veto as Zondacrypto Scandal Widens