Source: OJ L, 2025/1140, 10.6.2025

Current language: FR

Article 3 Enregistrement des politiques et des procédures du prestataire de services sur crypto-actifs


Summary What does Article 3 of the RTS on record keeping say?

This article sets out record-keeping obligations for crypto-asset service providers specifically concerning their internal policies and procedures.

Beyond simply retaining the written policies themselves, it extends the requirement to also capture the ongoing governance activity around those policies, namely the management body's assessments and periodic reviews of their effectiveness, findings of any deficiencies, and the measures taken to address them.

Important points:

  • Keep records of all written policies and procedures required under Regulation (EU) 2023/1114 and its implementing measures.
  • Keep records of the management body's periodic reviews of the effectiveness of those policy arrangements and procedures.
  • Document any deficiencies identified during those reviews, along with the measures taken to address them.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

    1. Les prestataires de services sur crypto-actifs enregistrent toutes les politiques et procédures qu’ils sont tenus de maintenir par écrit en vertu du règlement (UE) 2023/1114 et de ses mesures d’exécution.

    1. Les prestataires de services sur crypto-actifs enregistrent également l’évaluation et le réexamen périodique, effectués par leur organe de direction, de l’efficacité des dispositifs et des procédures stratégiques visés à l’article 68, paragraphe 6, du règlement (UE) 2023/1114, y compris toute défaillance constatée dans ces dispositifs et procédures et toute mesure prise pour y remédier.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod