CryptaCount
EN
EnglishENDeutschDEEspañolESFrançaisFRItalianoIT日本語JA한국어KONederlandsNLPolskiPLPortuguêsPT
Log in Start Free

MiCA Is Building Retail Trust, But Enforcement Gaps Remain

CryptaCount Editorial · · 10 min read
AML / KYC / LICENSING MiCA Is Building Retail Trust, ButEnforcement Gaps Remain

The EU's Markets in Crypto-Assets regulation has achieved something regulators rarely manage at speed: a measurable change in retail behaviour. Christian Trummer, co-CEO of Austria-based exchange Bitpanda, told Cointelegraph's Chain Reaction podcast that European users are increasingly placing their trust in MiCA-licensed platforms rather than in self-custody alternatives. That is good news for the regulated sector. The complication is that some firms continue to serve EU customers without the required authorisation, and Trummer argues that the lack of strict enforcement is creating an uneven playing field that undermines the entire framework's credibility. For accounting firms, auditors, and CFOs with crypto-active clients, the implications run from AML due diligence straight through to how you classify counterparty risk on the balance sheet.

MiCA Is Building Retail Trust, But Enforcement Gaps Remain

What MiCA Has Actually Changed for Retail Users

Trummer's observation is worth unpacking carefully. He contrasts two distinct user populations: the self-custody community, which he characterises as a vocal but relatively small "Crypto Twitter" bubble, and the broader retail market, which he says has responded positively to the regulatory clarity MiCA provides. Most users, in his view, would rather interact with a licensed provider than manage private keys themselves.

The trust signal regulated status sends

This is not simply a question of user preference. When a crypto asset service provider (CASP) holds a MiCA licence, it is subject to capital requirements, organisational standards, conflict-of-interest rules, and ongoing supervisory oversight by its national competent authority. For a retail user, that licence functions as a credibility signal broadly analogous to what a banking licence communicates in traditional finance. Trummer's point is that the market is starting to read that signal correctly, which is precisely what the regulation was designed to achieve.

For accounting firms advising retail clients or high-net-worth individuals, the practical read-through is clear: where a client holds assets on a centralised exchange, the regulatory status of that exchange now matters for risk assessment in a way it did not before the MiCA grandfathering deadline passed.

Self-custody is not going away

Trummer is not dismissing self-custody as illegitimate; he is observing that it occupies a smaller share of actual user behaviour than its online prominence suggests. That distinction matters for auditors and compliance leads. Self-custody wallets are entirely outside the MiCA licensing framework, which means transactions routed through them carry a different AML profile than those processed through a licenced CASP with Travel Rule obligations. Firms advising clients on crypto asset allocation need to treat these as structurally different risk categories, not just different interface preferences.

The Enforcement Gap and Why It Matters for Licensed Firms

The sharper part of Trummer's remarks concerns enforcement. He states explicitly that some firms are still offering crypto services to European customers without MiCA authorisation, and that regulators have not moved decisively enough against them. His language is direct: non-compliant players are gaining a competitive advantage precisely because they are not bearing the cost of compliance.

The regulatory timeline so far

MiCA's grandfathering arrangements for existing crypto service providers closed no later than 1 July. The European Securities and Markets Authority (ESMA) directed national competent authorities to take supervisory action against any firm that continued operating past its applicable transition period without authorisation. ESMA has since made public calls for stronger supervisory powers, specifically to address the problem of unauthorised firms and third-country operators soliciting EU investors without a MiCA licence. The framework is in place; the question is the speed and consistency of its application across member states.

Competitive distortion for compliant operators

The distortion Trummer describes is real and quantifiable in business terms. A licensed CASP bears costs that an unlicensed competitor avoids entirely: compliance staffing, technology investment, legal fees, capital buffers, and the ongoing burden of supervisory reporting. If national regulators allow non-compliant firms to operate openly, licensed operators subsidise their competitors' market share. That dynamic, left unaddressed, gives the regulated sector a structural disincentive to invest further in compliance quality.

This is directly relevant to accounting firms and auditors that work with CASP clients. A client operating under MiCA faces a defined compliance cost base that needs to be reflected accurately in financial reporting, budgeting, and client advisory work. If the competitive landscape shifts because enforcement tightens or relaxes, those cost models need updating.

AML and Due Diligence Implications for Firms and CFOs

The enforcement gap has a direct read-through to AML obligations for any regulated entity that transacts with or through crypto service providers.

Counterparty screening under the Travel Rule and AMLD

Under the EU's Transfer of Funds Regulation (TFR), which extended Travel Rule obligations to crypto asset transfers, a licensed CASP must collect and transmit originator and beneficiary information for transfers above the relevant threshold. An unlicensed provider operating in the same market will typically not participate in Travel Rule data sharing, which means any transaction touching that provider creates a data gap in your AML chain. For compliance teams, that gap should trigger enhanced due diligence, not routine processing.

For accounting firms running AML programmes for CASP clients or conducting AML audits, the practical step is to verify that the client's transaction monitoring system flags transfers involving counterparty VASPs that cannot be confirmed as MiCA-authorised or equivalently regulated in their home jurisdiction. ESMA maintains a public register of authorised CASPs, and cross-referencing counterparties against that register should be a standard procedure by now.

Third-country firm risk

ESMA's specific concern about third-country firms soliciting EU investors is worth noting separately. MiCA does not provide a passport for third-country firms; they can only serve EU clients under very limited reverse solicitation carve-outs, a topic covered in detail in our earlier analysis of Binance, MiCA, and the reverse solicitation question. If a client is using a non-EU exchange that does not hold MiCA authorisation, that relationship carries both regulatory and reputational exposure that should be surfaced in any compliance review or audit.

Accounting Treatment: What Changes When Your Counterparty Is Unlicensed

The accounting angle is less obvious but equally practical. When a firm holds crypto assets on a centralised exchange, the accounting treatment under IFRS (currently IAS 38 or the entity's chosen policy under IAS 2, depending on the asset's nature) does not formally change based on whether the exchange is MiCA-licensed. However, counterparty risk most definitely does.

Disclosure and impairment considerations

Under IFRS 7, entities are required to disclose information about financial risk concentrations, including credit and counterparty risk. If a material balance is held on an exchange that lacks MiCA authorisation, that could constitute a disclosure-worthy risk concentration. Auditors should be asking whether management has assessed the regulatory status of every custodial counterparty and documented that assessment. If the counterparty is operating outside the MiCA framework, the probability of regulatory disruption (a forced wind-down or assets freeze ordered by a national authority) is materially higher, and that probability should feed into impairment assessments and going-concern evaluations for clients heavily exposed to a single platform.

Digital asset accounting software and compliance workflows

For firms managing large numbers of client transactions across multiple exchanges, the practical burden of counterparty status screening falls partly on the technology layer. A robust crypto accounting software or digital asset accounting software setup should allow compliance teams to tag transactions by the regulatory status of the originating or receiving CASP, flag Travel Rule compliance gaps, and generate audit trails that demonstrate due diligence against the ESMA register. If your current workflow cannot do that, the Bitpanda CEO's remarks are a prompt to re-evaluate it: enforcement is the stated direction of travel, even if the pace has been uneven. For more on how ESMA is planning to expand its supervisory scope, see our coverage of ESMA's MiCA review response on DeFi and stablecoins.

What Firms Should Do Now

Three practical actions follow directly from this development.

Audit your client counterparty lists against the ESMA CASP register

Cross-reference every exchange or crypto service provider your clients use against ESMA's public register of authorised CASPs. Flag any that are not listed and are not operating under a recognisable equivalent regime. Document the review and the conclusions. This is both good AML practice and defensible audit evidence.

Update your compliance cost models for CASP clients

If you advise or audit MiCA-licensed CASPs, factor the ongoing cost of compliance into your advisory work. The regulatory direction of travel is toward stricter enforcement; that means the cost base for licensed operators is unlikely to shrink. Budget accordingly, and advise clients to build compliance infrastructure that scales with transaction volume rather than being held together with manual processes.

Review disclosures for entities holding assets on unlicensed platforms

For any audit client or advisory client with material balances on centralised exchanges, check whether the exchange's MiCA status (or lack thereof) warrants enhanced disclosure under IFRS 7. If it does, ensure the financial statements reflect that risk clearly, before a national competent authority's enforcement action makes it a crisis rather than a disclosure.

MiCA Is Building Retail Trust, But Enforcement Gaps Remain

Frequently Asked Questions

What does MiCA authorisation actually require of a crypto exchange?

A crypto asset service provider seeking MiCA authorisation must meet capital requirements, satisfy governance and organisational standards, implement conflict-of-interest policies, and submit to ongoing supervision by a national competent authority in the EU member state where it is headquartered. The specific requirements vary depending on the services provided, but the framework applies uniformly across all 27 member states once a licence is granted, giving the provider a passporting right to serve EU clients across the bloc.

What is the grandfathering deadline and what happens to firms that missed it?

MiCA allowed existing crypto service providers a transitional period to obtain authorisation. That window closed no later than 1 July. ESMA directed national competent authorities to take supervisory action against any firm continuing to provide crypto asset services to EU clients after the deadline without authorisation. In practice, enforcement has been uneven across member states, which is the gap Bitpanda's co-CEO is highlighting.

How does an unlicensed counterparty affect my AML obligations?

If your client transacts with an unlicensed CASP, Travel Rule data sharing is likely incomplete, creating gaps in the AML chain. Under EU AMLD requirements, that gap should trigger enhanced due diligence. Compliance teams should document why the counterparty was used, what checks were performed on its regulatory status, and what mitigating controls are in place. Failure to do so creates audit exposure if a national authority later investigates the unlicensed firm.

Does the regulatory status of an exchange affect how crypto assets are accounted for under IFRS?

The accounting classification of crypto assets under IFRS does not formally depend on whether the custodial exchange is MiCA-licensed. However, the counterparty risk associated with holding assets on an unlicensed exchange is a distinct matter. IFRS 7 requires disclosure of material financial risk concentrations, and an unlicensed counterparty facing potential enforcement action represents a concentration risk that may warrant explicit disclosure. Auditors should ensure management has considered and documented this assessment.

What powers is ESMA seeking to address non-compliant firms?

ESMA has publicly called for enhanced supervisory powers to deal with firms operating without MiCA authorisation and with third-country operators that solicit EU investors outside the permitted reverse solicitation carve-out. The specific form those powers would take depends on future legislative or regulatory action, but the direction of travel is toward direct EU-level intervention rather than relying solely on national competent authorities to enforce the rules at member-state level.

Source: Cointelegraph

EUGeneralEnforcementAML/KYC & Licensing

Related articles

AML/KYC & Licensing
Japan Sanctions Garantex: What Firms Need to Know
AML/KYC & Licensing
Binance, MiCA, and the Reverse Solicitation Question
AML/KYC & Licensing
Revolut's Double Data Breach: What Firms Need to Know
AML/KYC & Licensing
ECB's Lagarde Blocked Binance's MiCA License in Greece