CryptaCount
EN
EnglishENDeutschDEEspañolESFrançaisFRItalianoIT日本語JA한국어KONederlandsNLPolskiPLPortuguêsPT
Log in Start Free

ESMA Q&A 2417: What the New CASP Custody and Transfer Clarification Means for EU Firms

CryptaCount Editorial · · 9 min read
AML / KYC / LICENSING ESMA Q&A 2417: What the New CASPCustody and Transfer ClarificationMeans for EU Firms

ESMA has quietly published a question and answer that carries real weight for any EU-licensed crypto-asset service provider offering custody or transfer services. Q&A reference 2417 addresses the authorisation status of a CASP that provides custody, administration, or transfer services specifically for crypto-assets that are issued after an initial offer to the public. For accounting firms, auditors, and CFOs supporting CASP clients, the distinction matters: it affects how a licence is scoped, how client assets are classified on the balance sheet, and what AML and governance controls need to be in place from day one of any new asset type entering the custody perimeter.

ESMA Q&A 2417: What the New CASP Custody and Transfer Clarification Means for EU Firms

Background: Why Post-Issuance Custody Is a Distinct Regulatory Question

MiCA establishes a tiered authorisation model. A CASP must hold authorisation for each specific service it provides, and the boundaries of that authorisation are not always self-evident when the underlying crypto-asset evolves after the original public offer. A token that was offered to the public at launch may later be transferred, staked, or held in custody arrangements that were not contemplated in the original whitepaper or offer document.

The Gap That Q&A 2417 Targets

The practical problem is this: a CASP authorised to provide custody and administration services, or transfer services, for a given crypto-asset class may later encounter client demand to service tokens of the same type that were issued in a subsequent round or tranche, after the original public offer closed. Whether that subsequent issuance falls within the existing authorisation, or whether it triggers a fresh notification or authorisation requirement, is precisely the question ESMA has now addressed.

Without clarity on this point, CASPs face a binary risk. They either over-scope their authorisation and accept compliance obligations they may not be ready for, or they under-scope it and inadvertently provide a regulated service without the corresponding licence permission, which is a direct enforcement exposure under MiCA Article 59.

How Q&A 2417 Fits into the Broader MiCA Q&A Programme

ESMA has been progressively building out its MiCA Q&A library since the regulation began applying to asset-referenced token and e-money token issuers in mid-2024, and then extended its reach to CASPs. Each Q&A is intended to be read alongside the primary regulation and the relevant ESMA technical standards, not as a standalone rule. Q&A 2417 sits in the CASP authorisation cluster and should be read together with the provisions on the scope of CASP licences and the conditions for passporting across the EU single market.

Compliance Implications for Accounting Firms and Auditors

For firms that audit or advise licensed CASPs, Q&A 2417 introduces a concrete review trigger. The question is no longer limited to whether a client holds a valid CASP authorisation, it now extends to whether that authorisation actually covers every asset class the client is currently servicing, including assets that entered the custody or transfer perimeter after a post-offer issuance event.

Authorisation Perimeter Reviews

Accounting and compliance teams should map each CASP client's current service activity against the asset types explicitly covered in their authorisation. Where post-issuance assets are present, the firm should document the basis on which the CASP considers those assets to be within scope, referencing Q&A 2417 directly. This documentation will be important both for internal governance files and for any national competent authority review.

If the mapping exercise reveals that a CASP is servicing post-issuance assets that fall outside the authorised perimeter, the remediation path is a formal communication with the relevant national competent authority, not a quiet expansion of practice. Firms advising on that process should ensure legal counsel is involved early, because the timeline for competent authority responses varies across EU member states and may affect client operations.

Balance Sheet and Classification Considerations

From an accounting standpoint, crypto-assets held in custody for clients are typically off-balance-sheet items for the CASP, provided the custody arrangement is structured correctly under the applicable accounting framework. However, if a CASP is holding post-issuance assets without clear authorisation to do so, there is a risk that the legal character of the holding becomes ambiguous. That ambiguity can affect how auditors treat those positions at year-end, particularly when applying substance-over-form analysis under IFRS.

Firms using crypto accounting software to track client custody positions should ensure their systems can tag assets by issuance event, not just by token type. This level of granularity will be necessary to demonstrate that the authorisation perimeter mapping is accurate and audit-ready. Digital asset accounting software that cannot distinguish between a token issued in an initial offer and one issued in a subsequent tranche will struggle to support the documentation requirements that Q&A 2417 implicitly creates.

AML and KYC Controls

Post-issuance crypto-assets may have a different distribution profile from the original offer. Tokens issued after the public offer may reach the CASP's custody perimeter via secondary market transactions, over-the-counter transfers, or corporate treasury operations. Each of those channels carries its own AML risk profile. The onboarding and transaction monitoring procedures that were calibrated for the original offer may not adequately cover post-issuance assets, particularly if the secondary distribution involved jurisdictions or counterparties that were not part of the initial KYC process.

Accounting firms with AML advisory mandates should use Q&A 2417 as a prompt to review whether their CASP clients' transaction monitoring rules and customer risk assessments have been updated to reflect post-issuance asset flows. This is especially relevant for CASPs that were authorised under the transitional MiCA provisions and are now moving into full compliance mode. The transitional period context is covered in detail in our earlier analysis of MiCA transitional period and CASP compliance obligations.

Implications for CFOs at Crypto-Native and Traditional Finance Firms

CFOs at firms that either operate as CASPs or hold crypto-assets through third-party custodians have two distinct sets of concerns.

If Your Firm Is the CASP

The CFO's immediate task is to confirm with the legal and compliance team that the firm's authorisation perimeter has been reviewed in light of Q&A 2417. This is not a discretionary governance exercise; it is a regulatory compliance obligation. If the firm cannot confirm that all post-issuance assets in its custody or transfer books are covered by the existing authorisation, that gap needs to be escalated and resolved before the next supervisory review cycle. National competent authorities are actively scrutinising CASP authorisations following the roll-out of ESMA's CASP register, as noted in our coverage of ESMA's fourth MiCA CASP register update.

If Your Firm Uses a Third-Party CASP Custodian

CFOs relying on external custodians to hold crypto-assets on behalf of the firm or its clients should request confirmation from those custodians that their authorisation covers the specific asset types being held, including any tokens that entered the portfolio after an initial issuance. This due diligence step is particularly important for treasury teams that have expanded their crypto holdings through secondary market purchases since the original token launch. If a custodian cannot provide that confirmation in writing, the CFO should treat it as a material counterparty risk item and consider what remediation or alternative arrangements are appropriate.

Practical Next Steps for Firms and CFOs

The publication of Q&A 2417 is a relatively contained regulatory event, but it has specific operational consequences that deserve a structured response rather than a passive watch-and-wait approach. The following steps are grounded in the substance of the Q&A and the wider MiCA authorisation framework.

Immediate Actions

First, retrieve and read the full text of Q&A 2417 from ESMA's official Q&A repository. The guidance should be shared with the firm's legal, compliance, and accounting leads simultaneously, not sequentially, because the implications cut across all three functions. Second, run the authorisation perimeter mapping described above for every CASP client or internal CASP entity within your group. Third, where any gap is identified, initiate a formal internal escalation and document the decision trail.

For firms using crypto bookkeeping software or digital asset accounting software, this is also a good moment to verify that asset-level tagging is granular enough to support the authorisation perimeter documentation. If your current tooling groups all tokens of a given type together regardless of issuance event, you may need to introduce a manual overlay or request a configuration change from your software provider.

Medium-Term Actions

Build Q&A 2417 into your ongoing CASP licence monitoring process. ESMA will continue to publish new Q&As as MiCA implementation raises practical questions, and each one has the potential to redefine the boundaries of existing authorisations. A quarterly review cycle that cross-references new ESMA Q&As against active CASP authorisations is a proportionate governance response for any firm with material exposure to EU crypto-asset services.

Also consider the passporting dimension. A CASP that passports its services into other EU member states on the basis of its home-state authorisation needs to be confident that the home-state authorisation, as now interpreted by Q&A 2417, is broad enough to cover the services being provided in each host state. Passporting a service that turns out to be outside the authorisation perimeter is a compliance failure in every jurisdiction where it operates, not just the home state.

ESMA Q&A 2417: What the New CASP Custody and Transfer Clarification Means for EU Firms

Frequently Asked Questions

What does ESMA Q&A 2417 actually say?

Q&A 2417 addresses whether a CASP's existing authorisation to provide custody and administration services, or transfer services, for crypto-assets also covers crypto-assets of the same type that are issued after the original public offer. ESMA's published Q&A provides the authoritative interpretation of how MiCA applies in this specific scenario. Firms should read the full text directly from ESMA's website.

Which CASPs are most directly affected?

Any CASP authorised under MiCA to provide custody, administration, or transfer services whose client base includes crypto-assets that have had post-offer issuance events. This includes custodians holding tokens for institutional clients who acquired them through secondary markets after the original launch, and transfer agents processing movements of such tokens.

Does this Q&A change the text of MiCA?

No. ESMA Q&As are interpretive guidance, not primary legislation. They clarify how the existing MiCA text should be read in practice. However, national competent authorities and courts will typically give significant weight to ESMA's published interpretations when assessing compliance.

How should an accounting firm document its review of client CASP authorisations in light of Q&A 2417?

The documentation should record: the date of the review, the specific assets reviewed and their issuance history, the authorisation perimeter as stated in the client's MiCA licence, the legal basis for concluding that post-issuance assets are or are not within scope, and any follow-up actions agreed with the client or referred to legal counsel. This file should be retained for at least five years in line with general professional standards for regulatory advisory work.

Is there a deadline for responding to this Q&A?

ESMA has not attached a specific implementation deadline to Q&A 2417. However, MiCA compliance is a continuous obligation, and any gap between a CASP's actual activity and its authorisation perimeter is an immediate compliance risk, not one that can be deferred until the next supervisory cycle. Firms should treat the review as time-sensitive.

Source: European Securities and Markets Authority (ESMA)

EUGeneralAdoptedAML/KYC & Licensing

Related articles

AML/KYC & Licensing
Blockchain.com Secures Cayman VASP Custody Licence: What Accounting Firms and CFOs Must Assess Now
AML/KYC & Licensing
Bybit's Austrian EMI License: Dual-Entity EU Structure and What Accounting Firms Must Assess Now
AML/KYC & Licensing
FATF's PPP Report: Crypto AML Gaps Firms Must Close Now
AML/KYC & Licensing
ESMA Q&A on CASP Custody: What Accounting Firms and CFOs Must Act On Now