“Bad governance is really at the root of all failings or weaknesses that we can detect,” said Karen O’Sullivan, who heads the Innovation, Payments, Market Infrastructures and Governance Department at the CSSF. Photo: Paperjam

“Bad governance is really at the root of all failings or weaknesses that we can detect,” said Karen O’Sullivan, who heads the Innovation, Payments, Market Infrastructures and Governance Department at the CSSF. Photo: Paperjam

With Mica’s transition period nearing its end, CSSF official Karen O’Sullivan said crypto-asset firms face a shift from securing licences to proving they have the governance, controls and risk systems needed for full EU supervision.

Crypto-asset firms will have to show that their internal governance and controls can stand up to full EU supervision, Karen O’SullivanKaren O’Sullivan, a senior CSSF official, said at Nexus Luxembourg on Thursday 11 June.

O’Sullivan heads the Innovation, Payments, Market Infrastructures and Governance Department at the CSSF. She was speaking as the Markets in Crypto-Assets (Mica) regulation’s transition period entered its final weeks.

The figures cited in the interview suggest a steep licensing filter. Chris Hollifield, head of business development at Luxembourg for Finance, pointed to a move from roughly 2,500 virtual asset service provider registrations to 213 crypto-asset service providers under Mica, around 8%.

For O’Sullivan, the first challenge was the compliance burden. “It was a major uplift to go from a national AML type regime into a fully-fledged EU regulation supervisory regime,” she said.

Grey areas

The licensing process also exposed legal uncertainties around operations, business models and whether certain activities could fit under Mica. Those questions were not only for applicants.

O’Sullivan said there was uncertainty on the company side, but also on the CSSF side, about how to treat some business models. Technology added another difficulty, because crypto-asset activity was moving faster than the regulation written to supervise it.

Rules now being applied had been drafted two or three years earlier, while technology and services had continued to develop. The task was to work out how those models could fit into the framework already in place.

The CSSF also had to deepen its understanding of the sector. Before Mica, supervision had been focused more on AML than on the detail of the activities themselves. “We needed also to learn from the industry, learn the activities,” O’Sullivan said.

Blended risks

O’Sullivan also pointed to the difficulty of making Mica sit alongside other European rules, with some firms combining crypto-asset services, payments and more traditional financial activities.

That overlap is already visible in Luxembourg. O’Sullivan said the country had seven CASPs as of the week of the interview, with 60% to 70% of them operating as blended models involving banks, payment institutions and CASP licences.

Stablecoins were one example she gave of where the friction can arise. An activity may fall under Mica while also raising questions under the payments regime, forcing firms and supervisors to make the two sets of rules work together.

“There was really the need for the two licences to come together and work together,” O’Sullivan said.

Firms also have to show that each activity has been assessed on its own terms. A company that already provides investment advice cannot assume the same controls will be enough if it also starts advising on crypto-assets.

The CSSF wants to see the thinking behind the model: the full range of activities, the risks that overlap, the risks that differ, and the parts of the internal control framework that have been adjusted as a result.

First, governance

Once the transition phase gives way to ordinary supervision, O’Sullivan put governance and internal controls at the top of the CSSF’s list.

“Bad governance is really at the root of all failings or weaknesses that we can detect,” she said. Proper governance had to be in place from day one, with internal control arrangements robust enough to reflect the risks inherent in each business model. That, she said, was what would “insulate the business as best we can”.

ICT risk management will also be a focus, as it is across the financial sector. In digital assets, however, the consequences can arrive faster.

“A simple hack in the digital asset space can be very disastrous, and immediately disastrous,” O’Sullivan said.

AML remains part of the supervisory picture too. The rules are familiar, but the risks feel different in crypto because of the speed of activity and the global nature of the assets.

Future proof

O’Sullivan also looked ahead to the next regulatory debate. Mica 2 may still be several years away, but O’Sullivan said a European Commission consultation was open until the end of August.

One question is whether activities now outside Mica’s scope should be brought into the framework. O’Sullivan cited decentralised finance, staking and lending as examples.

Another is whether parts of the current regulation need more legal certainty. Multi-issuance, she said, remained a major discussion point.

Her concern was that the next framework should not become too prescriptive. Technology is moving faster than regulation, and rules written too closely around today’s models could become dated quickly.

“For me, it’s very important that within Mica 2, whilst we still need rules and we still need things to abide by, it needs to be future-proof,” she said.

Otherwise, she added, the EU could adopt Mica 2 only to start talking about Mica 3 six months later.