FMA Liechtenstein Notice 2026-3: What the CRR Regulatory Authority Choice Means for Accounting Firms and CFOs
On 10 July 2026, the Financial Market Authority of Liechtenstein (FMA) published Notice 2026-3, which addresses the formal process by which institutions operating under the Capital Requirements Regulation (CRR) select their competent regulatory authority. For accounting firms, auditors, and CFOs who advise or service entities with cross-border EEA operations, the notice carries immediate practical weight: it touches licensing structure, supervisory relationships, capital adequacy reporting lines, and the audit trail requirements that sit behind any robust crypto accounting software workflow.
Background: The CRR and the Liechtenstein EEA Position
Liechtenstein is not an EU member state, but it participates in the European Economic Area (EEA) and has adopted EU financial services legislation through the EEA Agreement. That includes the Capital Requirements Regulation, the cornerstone prudential rulebook that applies to credit institutions and investment firms across the single market. Because the CRR operates on an EEA-wide basis, an institution incorporated in Liechtenstein can passport services into EU member states and vice versa, but it must be unambiguously clear which national competent authority (NCA) holds supervisory responsibility at any given time.
The FMA is Liechtenstein's NCA for prudential supervision. Where a firm's structure spans multiple EEA jurisdictions, questions about which authority leads on capital, liquidity, and reporting obligations can become genuinely complex. Notice 2026-3 is designed to remove that ambiguity.
What Notice 2026-3 Actually Says
The FMA has published this notice to clarify the procedural and substantive criteria institutions must follow when exercising any discretion available under the CRR to choose, or confirm, which regulatory authority will act as the competent supervisor for their operations. The notice is directed at institutions that are either already authorised in Liechtenstein or seeking authorisation, where the applicable CRR provisions give a degree of optionality regarding supervisory allocation.
The Core Procedural Requirements
Firms affected by the notice need to engage directly with the FMA to make the relevant election or confirmation. The notice sets the expectation that this choice is not a passive administrative step: institutions are required to document their rationale, ensure the election aligns with their actual operational footprint, and keep that documentation available for supervisory review. In practical terms, this means the choice of regulatory authority must be reflected consistently across the firm's internal governance records, its capital adequacy reporting, and its supervisory disclosure filings.
For firms that use digital asset accounting software or crypto bookkeeping software to manage their regulatory reporting, this is a signal to audit the configuration of those systems. The supervisory entity coded into reporting templates, the jurisdiction mapped against each reporting obligation, and the entity hierarchy used for consolidation all need to match the elected authority identified under the CRR framework.
Timing and Effective Date
The notice was published on 10 July 2026. Institutions with pending decisions about regulatory authority allocation should treat this date as the reference point for compliance. There is no indication in the published notice of a grace period for firms that have not yet formalised their position; the presumption is that affected entities should act promptly to confirm or document their election.
Who Is Directly Affected
The immediate audience for Notice 2026-3 is any credit institution or investment firm that is authorised, or seeking authorisation, in Liechtenstein and whose CRR obligations involve a choice of competent authority. That category is narrower than the full universe of financial services firms, but it has particular relevance in the current regulatory environment for several reasons.
Crypto-Asset Service Providers Operating Under Dual Frameworks
A growing number of digital asset firms in Liechtenstein hold, or are pursuing, authorisation under both the Liechtenstein Blockchain Act (TVTG) and, following the EEA adoption of MiCA, the Markets in Crypto-Assets Regulation. Where such a firm also holds a banking or investment firm licence, it sits within the CRR's scope. The interplay between MiCA supervisory requirements and CRR prudential supervision means the question of which authority leads is not theoretical: it directly affects which set of reporting templates applies, which authority receives the firm's own funds disclosures, and which supervisory college the firm participates in.
Accounting teams advising these entities need to map the CRR authority election onto the MiCA supervisory relationship and ensure the two are coherent. Any inconsistency can create gaps in regulatory reporting that become visible during an audit or supervisory review.
EEA Passporting Firms
Firms that passport services from Liechtenstein into EU member states, or that are EU-authorised and operating into Liechtenstein, need to verify that the home/host authority split is correctly reflected in their prudential filings. The FMA notice reinforces that the allocation of supervisory responsibility under the CRR is not assumed: it is elected and documented. Passporting firms should review their regulatory mapping as a matter of routine following this notice.
Accounting and Reporting Implications
The accounting consequences of Notice 2026-3 flow from a single practical reality: the identity of the competent regulatory authority determines which reporting templates, which granularity of disclosure, and which supervisory timeline apply to a firm's capital adequacy obligations.
Consolidation and Entity Structure
Under the CRR, prudential consolidation follows supervisory responsibility. If a group operates across multiple EEA jurisdictions and the choice of regulatory authority at the Liechtenstein level has not been formally made or documented, the consolidation scope used in capital adequacy reporting may not align with the supervisor's expectations. This creates a reconciliation risk that auditors and CFOs need to address proactively. The entity hierarchy within the firm's crypto accounting software or ERP should reflect the confirmed supervisory structure, not an assumed one.
Own Funds and Capital Ratio Reporting
Capital ratio calculations, own funds disclosures, and leverage ratio filings are all authority-specific in the sense that they are submitted to, and reviewed by, the elected NCA. A mismatch between the elected authority and the entity actually named in filings is a reportable error in most EEA jurisdictions. Finance teams should run a targeted reconciliation of all open CRR submissions to confirm they reference the correct supervisory counterpart following this notice.
AML and KYC Overlay
While Notice 2026-3 is a prudential notice rather than an AML instrument, supervisory authority allocation has an indirect AML relevance. The NCA responsible for CRR supervision is typically the same body that coordinates with AML supervisors on information sharing about the firm's risk profile. In Liechtenstein, the FMA also holds AML supervisory responsibility for a wide range of financial sector entities. A firm that has correctly identified the FMA as its CRR authority will have cleaner supervisory communication channels, which matters when AML queries arise from correspondent banks or cross-border regulators.
Firms that have recently reviewed their AML frameworks in light of broader EEA enforcement trends should ensure their regulatory authority mapping is consistent across both the prudential and AML supervisory records. This is particularly relevant given the heightened scrutiny on digital asset intermediaries across the EEA in the current period.
Practical Steps for Accounting Firms and CFOs
The notice is short and procedural, but the downstream checklist for practitioners is substantive. The following actions are appropriate for firms with any exposure to Liechtenstein-authorised entities or EEA passporting structures involving the FMA.
Step 1: Identify Affected Entities
Start with the group structure and identify any entity that is authorised, or in the process of being authorised, in Liechtenstein under a CRR-covered licence type. This includes credit institutions and investment firms. Crypto-asset service providers that also hold one of these licences are within scope.
Step 2: Review Existing Regulatory Authority Documentation
Pull the current supervisory correspondence file for each affected entity. Confirm that the elected or confirmed regulatory authority is explicitly documented and consistent across: the FMA authorisation letter, the firm's internal governance records, the capital adequacy reporting configuration in any digital asset accounting software or regulatory reporting system, and the most recent own funds disclosure.
Step 3: Engage the FMA Where the Election Is Unclear
Where the documentation is ambiguous or the formal election has not been made, contact the FMA directly. The notice signals that the FMA expects a clear, documented position from all affected institutions. Proactive engagement is preferable to a supervisory query after the fact.
Step 4: Update Reporting System Configuration
Once the regulatory authority position is confirmed, update the entity configuration in all regulatory reporting systems. This includes mapping the correct NCA identifier in any CRR reporting templates and ensuring the supervisory entity is correctly coded for any automated submission workflows. For firms using crypto bookkeeping software that feeds into regulatory capital calculations, the entity mapping within that software should also be audited.
Step 5: Flag for Audit and Board Disclosure
The regulatory authority election is a governance matter as much as a technical one. Document the confirmation in board minutes or an equivalent governance record. Auditors should note the confirmed position in their regulatory compliance workpapers. CFOs should include a brief reference in the next regulatory reporting sign-off, confirming that the CRR authority election has been reviewed in light of FMA Notice 2026-3.
The Broader Regulatory Context
FMA Notice 2026-3 arrives at a moment when supervisory authority clarity across the EEA is under sharper scrutiny than at any point in the past decade. The rollout of MiCA has created a new layer of NCA responsibility for crypto-asset service providers, and the interaction between MiCA supervisory colleges and existing CRR prudential frameworks is still being worked out in practice across the EEA. Liechtenstein, as a small but active EEA financial centre with a well-developed digital assets regulatory regime under the TVTG, sits at an interesting intersection of these pressures.
For accounting firms advising clients in this space, the FMA's willingness to publish a dedicated notice on the authority choice question is a signal of supervisory seriousness. It is consistent with the broader EEA trend of NCAs tightening procedural expectations around regulatory elections and discretions that were previously handled informally. Firms that have relied on an assumed rather than a formally documented supervisory relationship should treat this notice as a prompt to formalise their position.
The notice also has a secondary relevance for firms thinking about regulatory arbitrage. The FMA is making clear that the choice of regulatory authority under the CRR is a substantive legal election, not an administrative preference that can be revisited at convenience. That message is relevant to any firm that has structured its EEA operations with Liechtenstein as a hub partly because of the jurisdiction's regulatory clarity and proportionate supervisory approach.
For more on how supervisory authority allocation intersects with crypto-asset compliance obligations across the EEA, see our coverage of MiCA licensing and ESMA's scrutiny of crypto custodians and the ESMA Q&A on CASP custody obligations.
FAQ
Notice 2026-3, published on 10 July 2026, clarifies the process and criteria by which institutions subject to the Capital Requirements Regulation (CRR) must formally select or confirm their competent regulatory authority. It is directed at credit institutions and investment firms authorised, or seeking authorisation, in Liechtenstein.
It affects any crypto-asset service provider that also holds a CRR-covered licence, such as a banking or investment firm authorisation. Firms operating solely under the Liechtenstein TVTG or MiCA without a CRR-covered licence are not directly in scope, but they should monitor how MiCA supervisory college arrangements interact with any CRR entities in their group.
Under the CRR, own funds disclosures, capital ratio filings, and leverage ratio reports are submitted to the elected national competent authority. If the authority election is undocumented or inconsistent with actual filings, it creates a reportable error. Finance teams should confirm that their regulatory reporting systems, including any crypto accounting software, correctly reference the confirmed supervisory entity.
The notice does not specify a formal grace period. Given that it was published on 10 July 2026, the FMA's expectation is that affected institutions act promptly to confirm or document their regulatory authority election. Firms with unresolved positions should engage the FMA without delay.
The national competent authority for CRR prudential supervision typically also coordinates with AML supervisors on a firm's risk profile. A clearly documented supervisory relationship supports cleaner information flows between regulators, which is particularly relevant when correspondent banks or cross-border authorities raise AML queries about the firm.
