Source: OJ L, 2025/303, 20.2.2025

Current language: EN

Article 5 Segregation and safekeeping of clients’ crypto-assets and funds


Summary What does Article 5 of the RTS on notification of crypto-asset service provision say?

This article deals with the client asset and fund segregation requirements that a notifying entity must demonstrate to its competent authority when it intends to hold client crypto-assets, means of access to those crypto-assets, or client funds other than e-money tokens.

It feeds directly into the broader notification framework established under Regulation (EU) 2023/1114, requiring the notifying entity to lay out in detail how it keeps client assets separate from its own — covering everything from wallet separation and cryptographic key management to the depositing of client funds with a central bank or credit institution by the end of the following business day.

Notably, the article also contains a carve-out for crypto-asset service providers that are already electronic money institutions or credit institutions, limiting what they need to submit.

Important points:

  • Provide a detailed description of your client asset and fund segregation procedures to the competent authority, covering wallet separation, cryptographic key safeguarding, and omnibus account arrangements.
  • Client funds other than e-money tokens must be deposited with a central bank or credit institution by the end of the business day following receipt, held in an account separately identifiable from the notifying entity's own funds.
  • Crypto-asset service providers that are electronic money institutions or credit institutions are only required to provide the information set out in paragraph 1 of this article.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

    1. For the purposes of Article 60(7), point (d), of Regulation (EU) 2023/1114, the notifying entity that intends to hold crypto-assets belonging to clients or the means of access to such crypto-assets, or clientsfunds other than e-money tokens, shall provide to the competent authority a detailed description of its procedures for the segregation of clientscrypto-assets and funds, including the following:

      1. how the notifying entity ensures the following:

        1. clientsfunds are not used for its own account;

        2. crypto-assets belonging to the clients are not used for its own account;

        3. the wallets holding clientscrypto-assets are different from the notifying entity’s own wallets;

      2. a detailed description of the approval system for cryptographic keys and safeguarding of cryptographic keys including multi-signature wallets;

      3. how the notifying entity segregates clientscrypto-assets, including from other clientscrypto-assets where wallets containing crypto-assets of more than one client, are kept in omnibus accounts;

      4. a description of the procedure ensuring that clientsfunds other than e-money tokens are deposited with a central bank or a credit institution by the end of the business day following the day on which they were received and are held in an account separately identifiable from any accounts used to hold funds belonging to the notifying entity;

      5. where the notifying entity does not intend to deposit funds with the relevant central bank, which factors the notifying entity takes into account to select the credit institutions with which to deposit clientsfunds, including the notifying entity’s diversification policy, where available, and the frequency of review of the selection of credit institutions with which to deposit clientsfunds;

      6. how the notifying entity ensures that clients are informed in clear, concise and non-technical language about the key aspects of the notifying entity’s systems, policies and procedures to comply with Article 70(1), (2) and (3) of Regulation (EU) 2023/1114.

    1. In accordance with Article 70(5) of Regulation (EU) 2023/1114, crypto-asset service providers that are electronic money institutions or credit institutions shall only provide the information set out in paragraph 1 of this Article.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod