CryptaCount
EN
EnglishENDeutschDEEspañolESFrançaisFRItalianoIT日本語JA한국어KONederlandsNLPolskiPLPortuguêsPT
Log in Start Free

MFSA FinTech2030: MiCA, Stablecoins and DeFi Accounting Takeaways

CryptaCount Editorial · · 11 min read
NEWS MFSA FinTech2030: MiCA, Stablecoins andDeFi Accounting Takeaways

The Malta Financial Services Authority brought together regulators, policymakers and industry specialists on 22 September 2026 for its FinTech2030 conference, and the agenda reads like a checklist of everything keeping crypto compliance teams busy right now. MiCA's next phase, stablecoin treatment, tokenisation of securities and fund units, AI-driven risk, quantum resilience and crypto AML were all on the table. For accounting firms, CFOs and auditors serving digital-asset clients across the EU, the signals from Valletta deserve a close read.

MFSA FinTech2030: MiCA, Stablecoins and DeFi Accounting Takeaways

MiCA: Two Years In and Already Evolving

The opening keynote set the tone. MFSA Chief Executive Kenneth Farrugia framed the conference around a single tension that every compliance function recognises: technology is moving faster than regulatory frameworks, and the gap creates both opportunity and risk. The regulator's job, he argued, is to stay responsive without sacrificing resilience or market integrity.

That framing landed against a concrete backdrop. Peter Kerstens, adviser on technological innovation and cybersecurity at the European Commission's DG FISMA, outlined the Commission's thinking on MiCA's next phase. The regulation is no longer a horizon event — it is live, and the focus is shifting from implementation to evolution. Carlo Comporti of CONSOB brought a supervisory perspective on convergence, reflecting Italy's experience of aligning national practice with the EU-level framework. Giles Swan rounded out the panel by drawing on two years of practical MiCA lessons to sketch what comes next.

Cross-border supervisory alignment

A dedicated panel brought together supervisors from Malta, Luxembourg, Italy and Estonia — Christopher Buttigieg, Karen O'Sullivan, Carlo Comporti and Tõnis Reinik — to compare notes on how different member states are applying MiCA in practice. The divergence in supervisory emphasis across those four jurisdictions matters for any firm passporting crypto-asset services into multiple EU markets. What satisfies the MFSA may not satisfy the CSSF in Luxembourg, and the panel discussion surfaced exactly those friction points.

For accounting teams, the practical consequence is straightforward: a single stablecoin accounting policy is unlikely to survive unmodified across all EU booking entities. Firms with subsidiaries in two or more of these jurisdictions should map the supervisory expectations of each NCA against their current group accounting policies before the next MiCA review cycle lands.

Stablecoins and Crypto-Derivatives: What the Supervisors Said

Stablecoins received dedicated session time, and the supervisory tone was consistent with the direction of travel seen elsewhere in the EU this year. The conference examined both the regulatory treatment of stablecoins and the supervisory approaches being applied to crypto-derivatives across jurisdictions. The international dimension was broadened by contributions from Christos Efthymiopoulos of the Bermuda Monetary Authority and Andrew Cuomo, currently on OKX's board, who joined a fireside discussion on the development of crypto-asset regulatory frameworks.

Stablecoin accounting implications for EU firms

The accounting treatment of e-money tokens and asset-referenced tokens under MiCA is not yet settled in practice. Reserve asset requirements, redemption obligations and the prohibition on interest-bearing features all have balance-sheet consequences that firms are still working through. Under IFRS, whether a stablecoin held by a corporate treasury qualifies as cash and cash equivalents under IAS 7, a financial asset under IFRS 9, or an intangible asset under IAS 38 depends heavily on the specific contractual rights attached to that token — and those rights vary by issuer.

For firms holding USDC or similar regulated stablecoins, the key accounting question is whether the on-demand redemption feature at par is sufficiently robust to support a cash-equivalent classification. If supervisory guidance in the firm's home jurisdiction introduces any uncertainty about the enforceability of that redemption right, the classification argument weakens and IFRS 9 fair-value-through-profit-or-loss treatment may be the safer default. The multi-jurisdictional supervisor panel at FinTech2030 is a reminder that those supervisory signals are not yet uniform across the EU. Firms should document their classification rationale at the entity level, not just at group level, and revisit it each time a relevant NCA issues updated guidance.

For context on how the ESCB is approaching stablecoin reserve and liquidity requirements at the MiCA level, see our earlier coverage of how the ESCB is pushing to rewrite MiCA stablecoin liquidity rules.

Tokenisation: Securities, Fund Units and the Accounting Frontier

Tokenisation occupied a substantial portion of the programme, with separate attention given to tokenised securities, tokenised fund units and the broader architecture of tokenised financial markets. Sulolit Raj Mukherjee of Bodin Advisory, Pedro Gurrola-Pérez of the World Federation of Exchanges and Ian Meli from the MFSA's investment services supervision team addressed the opportunities and structural challenges involved. A follow-on panel — drawing on asset management, digital asset, legal and professional services perspectives — worked through the practical and regulatory considerations.

Tokenised fund units: the accounting edge case

Tokenised fund units sit in an interesting gap in existing accounting standards. A conventional fund unit held by an investor is typically measured at net asset value under IFRS 9 or at fair value through other comprehensive income where an election is available. When that unit is represented on-chain as a token, the measurement principle does not change, but the operational questions multiply. Who is the authoritative source of NAV? How are fractional tokens reflected in the fund's own shareholder register? What happens when a secondary market price diverges from the NAV used for redemption?

For accounting firms serving fund managers exploring tokenisation, these are not theoretical questions. The FinTech2030 discussions confirm that regulators are actively working through the same questions, which means definitive guidance is coming but is not yet here. In the interim, firms should ensure their engagement letters explicitly address the basis of measurement and the data sources relied upon for any tokenised fund unit positions.

Tokenised securities and DeFi accounting

The tokenisation of conventional securities raises overlapping DeFi accounting questions wherever those tokens are used as collateral, lent out, or traded on decentralised venues. A tokenised bond pledged as collateral on a DeFi protocol, for example, creates a derecognition question under IFRS 9 that is more complex than the equivalent repo transaction in traditional finance, because the smart contract governing the collateral may not satisfy the conditions for a genuine transfer of substantially all risks and rewards. Accounting teams should be stress-testing their derecognition policies against the specific protocols their clients are using, not relying on analogies to traditional collateral arrangements.

The US legislative dimension of DeFi accounting is evolving in parallel — for a summary of where Congress currently stands, see our piece on what the Senate crypto tax debate means for DeFi accounting.

Emerging Technology Risks: AI, Cybersecurity and Quantum

Three dedicated sessions addressed the technology risk layer that sits beneath all of the above. Alan Decelis of the MFSA led on supervisory ICT risk and cybersecurity, covering both the existing DORA obligations and the emerging threat landscape. The AI panel — drawing on perspectives from the MDIA, the European Central Bank and industry — examined how frontier AI is changing the risk profile of financial institutions and what that means for supervisory approaches.

The quantum readiness session was the most forward-looking. Representatives from IBM, Resilia Connect and Safeheron discussed the implications of post-quantum cryptography for the resilience of financial system infrastructure. For firms holding private keys to digital asset wallets or operating custody infrastructure, the migration to post-quantum cryptographic standards is a medium-term operational risk that is beginning to attract supervisory attention. The DORA framework's resilience testing requirements are the current hook, but dedicated post-quantum guidance is likely to follow as the timeline for quantum computing capability becomes clearer.

Crypto AML: Financial Crime Risks and Information Sharing

The final substantive session addressed money laundering risks associated with crypto-assets, drawing on perspectives from financial intelligence, supervision and industry. Jason Sandoval of Asset Reality opened the discussion, and a panel moderated by Jonathan Phyall of Malta's Financial Intelligence Analysis Unit examined the evolving financial crime risks, AML/CFT frameworks, information sharing and cross-sector cooperation.

What the AML session means for accounting firms

The emphasis on information sharing and cooperation is directly relevant to accounting firms and auditors with crypto-asset clients. Under the EU's Anti-Money Laundering Regulation — which extends the obliged entity framework — accounting professionals handling crypto transactions are expected to apply enhanced due diligence where risk indicators are present, and to file suspicious transaction reports through the appropriate national FIU channel. The FinTech2030 discussion reinforced that regulators view the accounting and professional services sector as a key node in the broader AML information-sharing network, not a passive observer.

Practically, that means firms should be reviewing their client risk assessments for any digital asset exposures, ensuring their transaction monitoring covers on-chain activity, and checking that their STR procedures are current. The FIAU's involvement in the FinTech2030 AML panel is a signal that Malta's financial intelligence unit is actively engaged with the crypto risk picture, which is relevant for any firm supervised by or operating in Malta.

What Accounting Firms and CFOs Should Do Now

The FinTech2030 programme covered a wide range of issues, but the accounting and compliance priorities it surfaces are specific.

Immediate actions for firms

First, map your stablecoin holdings by booking entity and document the classification rationale under the accounting standard applicable to each entity. Do not assume a group-level policy carries automatically to every subsidiary, particularly where different NCAs are applying MiCA differently.

Second, review your derecognition policies for any tokenised assets used as collateral or lent out on DeFi protocols. The standard collateral analogies from traditional finance may not hold, and regulators across the EU are paying attention to this area.

Third, engage your IT and custody teams on post-quantum cryptographic readiness. This is not an immediate accounting issue, but it is a material operational risk for firms holding private keys, and DORA resilience testing is the current supervisory lever.

Fourth, check that your AML/CFT client risk assessments explicitly address crypto-asset exposures, including any tokenised positions. The FinTech2030 AML session makes clear that regulators expect the professional services sector to be an active participant in financial crime detection, not a passive one.

Fifth, watch for post-conference publications from the MFSA, DG FISMA and CONSOB. Conference remarks by senior officials frequently foreshadow formal guidance or consultation papers, and the observations made at FinTech2030 by the European Commission's adviser on technological innovation are worth tracking closely.

MFSA FinTech2030: MiCA, Stablecoins and DeFi Accounting Takeaways

Frequently Asked Questions

How does MiCA affect stablecoin accounting for EU firms?

MiCA classifies stablecoins as either e-money tokens or asset-referenced tokens and imposes reserve, redemption and disclosure obligations on issuers. For holders, the accounting treatment under IFRS depends on the contractual rights attached to the token. Where redemption at par on demand is clear and enforceable, a cash-equivalent or amortised-cost classification may be supportable. Where supervisory uncertainty exists about those rights, fair value through profit or loss is the more defensible default. Firms should document their rationale at entity level, not just group level, given that supervisory emphasis varies across EU member states.

What is the key DeFi accounting question raised by tokenised collateral?

When a tokenised asset is pledged as collateral on a DeFi protocol, the accounting team must assess whether the arrangement meets the derecognition criteria under IFRS 9. Unlike a conventional repo, the smart contract governing the collateral may not clearly transfer substantially all risks and rewards of ownership, which means the asset may need to remain on the pledgor's balance sheet alongside a corresponding financial liability. Firms should test their derecognition policies against the actual protocol mechanics, not generic analogies.

What does the FinTech2030 AML session mean for accountants and auditors?

Accounting professionals handling crypto-asset transactions are obliged entities under EU AML rules and are expected to apply risk-based due diligence, monitor transactions for suspicious activity and file STRs through the relevant national FIU. The FIAU's involvement in the FinTech2030 AML panel signals active supervisory engagement with the crypto risk picture in Malta. Firms should ensure their client risk assessments cover on-chain activity and that their STR procedures are current.

Why does post-quantum cryptography matter for digital asset accounting teams?

Accounting teams themselves may not manage private keys, but the custody infrastructure underpinning a firm's digital asset holdings relies on cryptographic security. If that infrastructure is not migrated to post-quantum standards before sufficiently powerful quantum computers arrive, the integrity of asset ownership records could be compromised. DORA resilience testing is the current supervisory mechanism, but dedicated guidance is expected to follow. Accounting and audit teams should ensure quantum readiness is on the agenda in conversations with custody providers and IT risk teams.

Do conference remarks by regulators have any formal legal weight?

No. Remarks made at a conference, including those by senior officials from the European Commission, CONSOB or the MFSA, are not binding guidance or formal regulatory instruments. However, they frequently signal the direction of forthcoming consultations or guidance papers, and they inform how supervisors are likely to exercise discretion in the near term. Firms should monitor post-conference publications from the relevant authorities and treat conference statements as indicators worth tracking rather than rules to follow.

Source: Malta Financial Services Authority

EUMTLU#stablecoins#defiAdopted

Related articles

Tax Reporting
DAC7 Platform Operator Reporting: EU Implementation Status and Compliance Requirements
AML/KYC & Licensing
ESMA MiCA Register Update: 37 New CASPs Approved Post-Deadline
AML/KYC & Licensing
EU VASPs After MiCA: Who Got Licensed and Who Carries the Risk
Global Crypto Regulation: Compliance and Enforcement Outlook for Accounting Firms and CFOs