MiCAEuropean UnionCrypto

MiCA KYC Requirements for Crypto Exchanges in the EU

Definitive guide to MiCA KYC requirements for crypto exchanges operating in the European Union. Covers CASP authorization, Travel Rule compliance, asset-referenced token obligations, and identity verification standards for digital asset platforms.

Understanding MiCA: The EU's Comprehensive Crypto Regulatory Framework

The Markets in Crypto-Assets Regulation (MiCA) stands as the European Union's flagship statute for crypto-assets and the firms that service them. Exchanges that run inside the EU, or that serve EU customers, now sit under KYC duties that bind the same way in all 27 member states.

A hole in the rulebook lasted for years: no single, EU-wide licence for crypto-asset platforms. National regimes filled the space, each with its own bar for identifying customers, watching transactions, and running anti-money laundering controls. Crypto exchanges had to thread that patchwork. The fragmented period has closed.

Want EU market access? Obtain Crypto-Asset Service Provider (CASP) authorization and put KYC procedures in place that satisfy MiCA's strict standards. The rest of this guide walks through those duties.

CASP Authorization: The Gateway to EU Market Access

Who Needs a CASP License?

Crypto-asset services are defined broadly under MiCA. The definition catches the core work exchanges actually perform:

  • Operation of a trading platform for crypto-assets
  • Exchange of crypto-assets for funds or other crypto-assets
  • Execution of orders for crypto-assets on behalf of clients
  • Custody and administration of crypto-assets on behalf of clients
  • Transfer services for crypto-assets
  • Reception and transmission of orders for crypto-assets
  • Providing advice on crypto-assets and portfolio management

Perform one or more of those services and you need CASP authorization from a national competent authority (NCA) in an EU member state. Once authorized, the CASP may passport the services across the whole EU. Extra national licences are not required.

Authorization Requirements Relevant to KYC

The CASP application is where crypto exchanges prove they can run full KYC and AML programmes. Applicants must show:

  • A detailed description of internal KYC policies, procedures, and controls
  • Evidence of technological systems for customer identification and verification
  • Appointment of a qualified compliance officer responsible for AML/KYC oversight
  • A documented risk assessment methodology for customer and transaction risk
  • Procedures for detecting and reporting suspicious transactions to the relevant Financial Intelligence Unit (FIU)

Core KYC Obligations for Crypto Exchanges

Customer Identification and Verification

A MiCA-compliant exchange verifies every customer's identity before any service is delivered. For an ongoing business relationship, that duty does not turn on transaction size. The process itself has to cover:

  • Document collection: Obtaining a government-issued identity document (passport, national ID card, or residence permit) for natural persons.
  • Identity authentication: Verifying the authenticity of the document and confirming it has not been tampered with, expired, or reported as lost or stolen.
  • Biometric verification: Using facial recognition technology with liveness detection to match the customer's face against their identity document photograph.
  • Legal entity verification: For corporate clients, obtaining articles of incorporation, shareholder registers, and identifying all beneficial owners with holdings exceeding 25%.

Need the basics of identity verification first? Our what is KYC guide sets out KYC principles and how they apply in digital financial services.

Risk-Based Approach

MiCA also requires a risk-based approach (RBA) to KYC. Exchanges scale due diligence intensity to the risk scored for each customer and each transaction. The RBA has to take in:

  • Customer risk factors: Geographic location, political exposure, source of wealth, and the nature of the business relationship.
  • Product and service risk: Whether the customer is trading stablecoins, utility tokens, or higher-risk asset types.
  • Delivery channel risk: Fully remote onboarding carries different risk considerations than relationships initiated through regulated intermediaries.
  • Geographic risk: Exposure to jurisdictions with weak AML controls or under EU/FATF sanctions.

The Travel Rule and Crypto Transfers

Applicability to Crypto Exchanges

The EU's Transfer of Funds Regulation (TFR) sits alongside MiCA and extends the FATF Travel Rule to crypto-asset transfers. So exchanges collect, verify, and pass on originator and beneficiary data for every crypto-asset transfer. No amount threshold applies.

CASP-to-CASP transfers require the originating exchange to send:

  • The originator's full name
  • The originator's account number (wallet address)
  • The originator's address, national identity number, or date and place of birth
  • The beneficiary's full name
  • The beneficiary's account number (wallet address)

Self-Hosted Wallet Transfers

Self-hosted (unhosted) wallet transfers sit under closer TFR scrutiny. Handle a transfer that involves a self-hosted wallet above 1,000 EUR and the CASP must:

  • Collect information identifying the owner of the self-hosted wallet
  • Verify that information through appropriate measures
  • Assess the risk associated with the transfer

Those extra steps raise the KYC load on exchanges. They also call for technology that can test wallet-ownership claims.

Asset-Referenced Tokens and E-Money Tokens

Enhanced Obligations for ART and EMT Issuers

Issuers of asset-referenced tokens (ARTs) and e-money tokens (EMTs) carry extra KYC duties under MiCA. An exchange that lists these tokens, or that helps trade them, has to confirm that:

  • ART issuers have obtained authorization from their NCA and maintain reserve assets meeting MiCA's composition and custody requirements
  • EMT issuers hold an electronic money institution (EMI) or credit institution license
  • Redemption rights are clearly disclosed to token holders
  • Significant ARTs and EMTs (those exceeding specified thresholds) comply with additional prudential and governance requirements supervised by the European Banking Authority (EBA)

Issuer regulatory status is checked before listing. That due diligence sits on top of customer-facing KYC.

Technology Solutions for MiCA-Compliant KYC

Scaling Verification Across the EU

Serve the EU market and you must handle identity documents issued by all 27 member states, plus papers from third-country nationals who live in the EU. Hundreds of document types sit in that mix, across many languages and security features. Automated verification is what that diversity requires.

Joinble's AI-powered identity verification platform for crypto exchanges is built for that problem. The platform covers automated document recognition and authenticity checks across EU-wide document types, biometric verification with certified liveness detection, real-time sanctions and PEP screening against EU and international watchlists, and seamless API integration into exchange onboarding and transaction workflows. Compliance can be held without dropping the speed or the experience customers expect.

Ongoing Monitoring and Reporting

Onboarding is only the start. MiCA-compliant exchanges still run continuous transaction monitoring that will:

  • Detect patterns consistent with money laundering, terrorist financing, or market manipulation
  • Screen all transactions against current EU and UN sanctions lists
  • Flag activity that deviates from the customer's established risk profile
  • Generate suspicious transaction reports (STRs) for submission to the relevant FIU

Cross-Border Considerations and Passporting

Single License, Pan-European Access

Among MiCA's largest changes is the CASP passport. Authorization from one NCA lets a crypto exchange serve the entire EU once the relevant host-state NCAs are notified. Host-state compliance duties do not disappear with passporting:

  • Host NCAs retain supervisory powers over conduct-of-business rules
  • Local AML regulations may impose additional requirements beyond MiCA's baseline
  • Consumer protection standards may vary, requiring adapted disclosures

KYC systems therefore need enough flexibility for those host-state differences, while the compliance floor stays consistent.

Penalties for Non-Compliance

MiCA's enforcement framework hands NCAs wide sanctioning powers:

  • Administrative fines of up to 5,000,000 EUR for natural persons
  • Fines of up to 12,500,000 EUR or 10% of annual turnover for legal entities (the higher amount applies)
  • Public disclosure of the infringement and the identity of the responsible person
  • Withdrawal of CASP authorization
  • Temporary or permanent prohibition on management body members serving in CASPs

Fines set as a share of turnover hit larger exchanges especially hard when compliance fails.

FAQ

What KYC checks must crypto exchanges perform under MiCA?

Every customer identity is verified with government-issued documents, biometric authentication with liveness detection, and a risk-based assessment. Corporate clients also require beneficial ownership verification. Transaction monitoring and sanctions screening continue for the life of the business relationship.

Does the Travel Rule apply to all crypto transfers in the EU?

Yes. The EU's Transfer of Funds Regulation stretches the Travel Rule across every crypto-asset transfer between CASPs, with no amount floor. Self-hosted wallet transfers above 1,000 EUR add further verification duties for the originating exchange.

Can a crypto exchange use one MiCA license to operate across the entire EU?

Yes. MiCA's passporting regime lets a CASP authorized in one member state serve all 27 EU member states through a notification procedure. Host-state NCAs still keep some supervisory powers, and local AML rules can layer on extra duties.

What are the penalties for crypto exchanges that fail MiCA KYC requirements?

Legal entities face fines of up to 12,500,000 EUR or 10% of annual turnover, plus authorization withdrawal, public censure, and management bans. Penalty severity turns on the nature of the infringement, how long it lasted, and any financial harm caused.

How do asset-referenced tokens affect KYC obligations for exchanges?

List ARTs or EMTs and the exchange must check the issuer's regulatory status and confirm MiCA reserve, redemption, and disclosure rules are met. Significant ARTs and EMTs also sit under extra EBA oversight, and that enhanced bar has to feed into due diligence.

Automate your compliance with AI Agents

Joinble's Agentic Identity platform reduces manual KYC reviews by up to 80%. Book a demo to see it in action.

Book a demo