> For the complete documentation index, see [llms.txt](https://www.mica.wtf/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://www.mica.wtf/mica/title-v-authorisation-and-operating-conditions-for-crypto-asset-service-providers-art.-59-85/chapter-2/article-68.md).

# Article 68

|                 |                                                                                 |
| --------------- | ------------------------------------------------------------------------------- |
| **Instrument**  | Regulation (EU) 2023/1114 (MiCA)                                                |
| **Source**      | [EUR-Lex](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32023R1114) |
| **Status**      | In force                                                                        |
| **Review rule** | Legal-text changes require human review                                         |

### Governance arrangements

1. Members of the [management body](https://www.mica.wtf/definitions/definitions/mica/management-body) of [crypto-asset service providers](https://www.mica.wtf/definitions/definitions/mica/crypto-asset-service-provider) shall be of sufficiently good repute and possess the appropriate knowledge, skills and experience, both individually and collectively, to perform their duties. In particular, members of the management body of crypto-asset service providers shall not have been convicted of offences relating to [money laundering](https://github.com/jakesenfti/micawtf/blob/main/spaces/definitions/tofr/money-laundering.md) or [terrorist financing](https://github.com/jakesenfti/micawtf/blob/main/spaces/definitions/tofr/terrorist-financing.md) or of any other offences that would affect their good repute. They shall also demonstrate that they are capable of committing sufficient time to effectively perform their duties.
2. Shareholders and members, whether direct or indirect, that have [qualifying holdings](https://www.mica.wtf/definitions/definitions/mica/qualifying-holding) in [crypto-asset service](https://www.mica.wtf/definitions/definitions/mica/crypto-asset-service) providers shall be of sufficiently good repute and, in particular, shall not have been convicted of offences relating to [money laundering](https://github.com/jakesenfti/micawtf/blob/main/spaces/definitions/tofr/money-laundering.md) or [terrorist financing](https://github.com/jakesenfti/micawtf/blob/main/spaces/definitions/tofr/terrorist-financing.md) or of any other offences that would affect their good repute.
3. Where the influence exercised by the shareholders or members, whether direct or indirect, that have [qualifying holdings](https://www.mica.wtf/definitions/definitions/mica/qualifying-holding) in a [crypto-asset service provider](https://www.mica.wtf/definitions/definitions/mica/crypto-asset-service-provider) is likely to be prejudicial to the sound and prudent management of that crypto-asset service provider, [competent authorities](https://www.mica.wtf/definitions/definitions/mica/competent-authority) shall take appropriate measures to address those risks.\
   Such measures may include applications for judicial orders or the imposition of penalties against directors and those responsible for management, or the suspension of the exercise of the voting rights attaching to the shares held by the shareholders or members, whether direct or indirect, that have the qualifying holdings.
4. [Crypto-asset](https://www.mica.wtf/definitions/definitions/mica/crypto-asset) service providers shall adopt policies and procedures that are sufficiently effective to ensure compliance with this Regulation.
5. [Crypto-asset service](https://www.mica.wtf/definitions/definitions/mica/crypto-asset-service) providers shall employ personnel with the knowledge, skills and expertise necessary for the discharge of the responsibilities allocated to them, taking into account the scale, nature and range of crypto-asset services provided.
6. The [management body](https://www.mica.wtf/definitions/definitions/mica/management-body) of [crypto-asset](https://www.mica.wtf/definitions/definitions/mica/crypto-asset) service providers shall assess and periodically review the effectiveness of the policy arrangements and procedures put in place to comply with Chapters 2 and 3 of this Title and take appropriate measures to address any deficiencies in that respect.
7. [Crypto-asset service](https://github.com/jakesenfti/micawtf/blob/main/spaces/definitions/mica/crypto-asset-service.md) providers shall take all reasonable steps to ensure continuity and regularity in the performance of their crypto-asset services. To that end, crypto-asset service providers shall employ appropriate and proportionate resources and procedures, including resilient and secure ICT systems as required by Regulation (EU) 2022/2554.\
   [Crypto-asset](https://github.com/jakesenfti/micawtf/blob/main/spaces/definitions/mica/crypto-asset.md) service providers shall establish a business continuity policy, which shall include ICT business continuity plans as well as ICT response and recovery plans set up pursuant to [Articles 11](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-ii-ict-risk-management/article-11-response-and-recovery) and [12](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-ii-ict-risk-management/article-12-backup-policies-and-procedures) of Regulation (EU) 2022/2554 that aim to ensure, in the case of an interruption to their ICT systems and procedures, the preservation of essential data and functions and the maintenance of crypto-asset services or, where that is not possible, the timely recovery of such data and functions and the timely resumption of crypto-asset services.
8. [Crypto-asset service](https://github.com/jakesenfti/micawtf/blob/main/spaces/definitions/mica/crypto-asset-service.md) providers shall have in place mechanisms, systems and procedures as required by Regulation (EU) 2022/2554, as well as effective procedures and arrangements for risk assessment, to comply with the provisions of national law transposing Directive (EU) 2015/849. They shall monitor and, on a regular basis, evaluate the adequacy and effectiveness of those mechanisms, systems and procedures, taking into account the scale, the nature and range of crypto-asset services provided, and shall take appropriate measures to address any deficiencies in that respect.\
   [Crypto-asset](https://github.com/jakesenfti/micawtf/blob/main/spaces/definitions/mica/crypto-asset.md) service providers shall have systems and procedures to safeguard the availability, authenticity, integrity and confidentiality of data pursuant to Regulation (EU) 2022/2554.
9. Crypto-asset service providers shall arrange for records to be kept of all crypto-asset services, activities, orders, and transactions undertaken by them. Those records shall be sufficient to enable competent authorities to fulfil their supervisory tasks and to take enforcement measures, and in particular to ascertain whether crypto-asset service providers have complied with all obligations including those with respect to [clients](https://www.mica.wtf/definitions/definitions/mica/client) or prospective clients and to the integrity of the market.\
   The records kept pursuant to the first subparagraph shall be provided to [clients](https://www.mica.wtf/definitions/definitions/mica/client) upon request and shall be kept for a period of five years and, where requested by the [competent authority](https://www.mica.wtf/definitions/definitions/mica/competent-authority) before five years have elapsed, for a period of up to seven years.
10. ESMA shall develop draft regulatory technical standards to further specify:

    1. the measures ensuring continuity and regularity in the performance of the crypto-asset services referred to in paragraph 7;
    2. the records to be kept of all crypto-asset services, activities, orders and transactions undertaken referred to in paragraph 9.

    ESMA shall submit the draft regulatory technical standards referred to in the first subparagraph to the Commission by 30 June 2024.\
    Power is delegated to the Commission to supplement this Regulation by adopting the regulatory technical standards referred to in the first subparagraph of this paragraph in accordance with Articles 10 to 14 of Regulation (EU) No 1095/2010.

***

**Level 2 instruments**

* [2025/299 — CASP Service Continuity](/eu-level/technical-standards/rts/regulatory-technical-standards-continuity-regularity-performance-crypto-asset-services.md) — RTS
* [2025/1140 — CASP Record-Keeping](/eu-level/technical-standards/rts/regulatory-technical-standards-records-crypto-asset-services-activities-orders-transactions.md) — RTS
* [EBA/GL/2024/09 — Management Body Suitability](/eu-level/guidelines/guidelines-on-the-suitability-assessment-of-the-members-of-the-management-body.md) — Guidelines
* [ESMA75-453128700-1229 — Second Technical Standards Package](/eu-level/technical-standards/final-reports/final-report-on-the-technical-standards-specifying-certain-requirements-of-mica-2nd-package.md) — Final Report (final draft submitted)

### Related

* [crypto-asset service provider](https://github.com/jakesenfti/micawtf/blob/main/spaces/definitions/dora/crypto-asset-service-provider.md) — definition used in this article
* [crypto-asset service provider](https://github.com/jakesenfti/micawtf/blob/main/spaces/definitions/mica/crypto-asset-service-provider.md) — definition used in this article
* [crypto-asset service provider](https://github.com/jakesenfti/micawtf/blob/main/spaces/definitions/tofr/crypto-asset-service-provider.md) — definition used in this article
* [crypto-asset service](https://github.com/jakesenfti/micawtf/blob/main/spaces/definitions/mica/crypto-asset-service.md) — definition used in this article
* [competent authority](https://github.com/jakesenfti/micawtf/blob/main/spaces/definitions/mica/competent-authority.md) — definition used in this article
* [terrorist financing](https://github.com/jakesenfti/micawtf/blob/main/spaces/definitions/tofr/terrorist-financing.md) — definition used in this article
* [money laundering](https://github.com/jakesenfti/micawtf/blob/main/spaces/definitions/tofr/money-laundering.md) — definition used in this article
* [management body](https://github.com/jakesenfti/micawtf/blob/main/spaces/definitions/dora/management-body.md) — definition used in this article


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://www.mica.wtf/mica/title-v-authorisation-and-operating-conditions-for-crypto-asset-service-providers-art.-59-85/chapter-2/article-68.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
