MiCASpainFintech

KYC Compliance Requirements for Fintech in Spain Under MiCA

Comprehensive guide to KYC compliance requirements for fintech companies operating in Spain under the Markets in Crypto-Assets (MiCA) regulation. Learn about CASP licensing, identity verification obligations, and how to meet regulatory standards.

Introduction to MiCA and Its Impact on Spanish Fintech

Spain is not exempt from the shift the Markets in Crypto-Assets Regulation (MiCA) marks across European financial services. The country hosts one of the EU's fastest-growing fintech ecosystems, and it now faces a substantial regulatory transition as MiCA sets a harmonized framework for crypto-asset service providers (CASPs) across the bloc.

A patchwork of national rules governed Spanish fintech companies in the digital asset space before MiCA. The Bank of Spain's registry for virtual asset service providers (VASPs), created under Royal Decree-Law 5/2023, sat at the centre of that regime. That fragmented model gives way to a unified, pan-European licensing system. Robust Know Your Customer (KYC) processes are required at every stage of the customer lifecycle.

Understanding and implementing MiCA-compliant KYC procedures is a legal imperative for Spanish fintech firms, not an option. Market access across all 27 EU member states turns on it.

Who Must Comply: CASPs and Fintech Operators in Spain

Defining Crypto-Asset Service Providers

Any entity that provides crypto-asset services — exchange platforms, custodial wallet providers, portfolio managers and advisory firms among them — must obtain authorization as a CASP under MiCA. The designated national competent authority (NCA) for CASP authorization and supervision in Spain is the Comision Nacional del Mercado de Valores (CNMV).

Full CASP licensing now replaces the Bank of Spain VASP registry for Spanish fintech companies that previously operated under that register. Firms have had to upgrade operational, governance and KYC frameworks substantially during this transition, which has been a critical compliance milestone.

Entities Subject to KYC Obligations

MiCA-compliant KYC applies to the following fintech entities operating in Spain:

  • Crypto-asset exchanges and trading platforms
  • Custodial wallet service providers
  • Firms offering crypto-asset transfer services
  • Platforms facilitating the placement or reception of crypto-assets
  • Advisory and portfolio management services for crypto-assets
  • Issuers of asset-referenced tokens (ARTs) and e-money tokens (EMTs)

Core KYC Requirements Under MiCA for Spanish Fintech

Customer Identification and Verification

Rigorous customer due diligence (CDD) procedures must be in place before a CASP establishes a business relationship or executes occasional transactions above prescribed thresholds. For Spanish fintech firms, that means:

  • Identity document verification: Collecting and verifying government-issued identification documents (DNI, NIE, or passport for Spanish residents and foreign nationals).
  • Biometric verification: Employing liveness detection and facial recognition to confirm that the person presenting the document is the legitimate holder.
  • Address verification: Confirming the customer's residential address through utility bills, bank statements, or official correspondence.
  • Beneficial ownership identification: For corporate clients, identifying and verifying all natural persons who ultimately own or control more than 25% of the entity.

Readers new to KYC concepts can use our detailed guide on what is KYC, which covers the fundamentals of identity verification and its role in regulatory compliance.

Enhanced Due Diligence (EDD)

Higher-risk scenarios require Spanish fintech companies to apply enhanced due diligence measures, including:

  • Customers from high-risk third countries identified by the EU or FATF
  • Politically exposed persons (PEPs) and their associates
  • Complex or unusually large transactions without an apparent economic purpose
  • Business relationships conducted entirely remotely without face-to-face contact

Ongoing Monitoring and Transaction Screening

A one-time check does not satisfy KYC under MiCA. Continuous monitoring systems must stay in place at Spanish CASPs to detect suspicious transaction patterns, screen against EU and UN sanctions lists, and trigger alerts for activity that deviates from a customer's established risk profile.

CNMV Licensing Process and KYC Documentation

Application Requirements

CASP authorization from the CNMV requires Spanish fintech firms to demonstrate:

  • A detailed description of their KYC and AML/CFT policies and procedures
  • Evidence of adequate technological infrastructure for identity verification
  • Appointment of a designated AML compliance officer
  • A comprehensive risk assessment methodology
  • Internal audit procedures for ongoing compliance monitoring

Timeline and Transitional Provisions

Existing VASPs follow a structured timeline set by the CNMV for the move to full CASP status. A transitional period to submit CASP applications was given to firms already registered with the Bank of Spain. New market entrants, by contrast, must obtain full authorization before commencing operations.

Technology and Automation in MiCA-Compliant KYC

The Role of AI-Powered Identity Verification

Automation is what scale requires if MiCA's stringent KYC requirements are to be met. Manual document checks and in-person verification are neither scalable nor cost-effective for digital-first fintech platforms serving thousands of users.

Spanish fintech companies can automate the entire KYC workflow through Joinble's AI-powered identity verification solutions — from document capture and authenticity validation to biometric matching and liveness detection. Onboarding friction falls, while the high accuracy standards the CNMV expects from licensed CASPs remain in place.

Integration With Existing Compliance Infrastructure

A CASP's existing technology stack — transaction monitoring systems, sanctions screening databases and case management platforms — must accept modern KYC solutions without friction. Spanish fintech firms can embed identity verification directly into their onboarding flows through API-driven solutions, without disrupting the user experience.

Penalties for Non-Compliance in Spain

NCAs must enforce a graduated penalty framework established by MiCA. The CNMV can impose:

  • Administrative fines of up to 700,000 EUR for natural persons and up to 5,000,000 EUR (or 3% of annual turnover) for legal entities
  • Public statements identifying the responsible party and the nature of the infringement
  • Withdrawal or suspension of CASP authorization
  • Temporary bans on management body members from exercising functions in CASPs

An active enforcement posture has historically been the CNMV's approach. MiCA also grants significantly expanded sanctioning powers compared with the previous national framework.

Best Practices for Spanish Fintech Companies

  1. Conduct a gap analysis comparing current KYC procedures against MiCA requirements and CNMV technical standards.
  2. Invest in scalable verification technology that can handle document types from all EU member states, given MiCA's passporting provisions.
  3. Train compliance teams on MiCA-specific obligations, including the nuances of ART and EMT issuer requirements.
  4. Establish clear data retention policies that comply with both MiCA record-keeping mandates and GDPR data minimization principles.
  5. Engage early with the CNMV to clarify any ambiguities in the licensing process and demonstrate a proactive compliance posture.

A foundational view of KYC processes, and of how they apply across regulated industries, is available in our resource on what is KYC.

FAQ

What is MiCA and how does it affect fintech companies in Spain?

An EU-wide regulation, MiCA (Markets in Crypto-Assets Regulation) sets a harmonized licensing and compliance framework for crypto-asset service providers. The previous VASP registry system in Spain is replaced. Fintech firms must obtain CASP authorization from the CNMV and implement comprehensive KYC procedures.

What KYC documents are required for CASP compliance in Spain?

Government-issued identification (DNI, NIE, or passport) must be collected by Spanish CASPs. The customer's identity is verified through biometric checks, residential address is confirmed, and — for corporate clients — all beneficial owners holding more than 25% of the entity must be identified.

How long does the CNMV CASP licensing process take?

Complexity of the application and completeness of submitted documentation both affect the CNMV licensing timeline. Several months should be anticipated for the full review process. Early engagement with the CNMV is advised to expedite the procedure.

Can Spanish fintech companies use automated KYC solutions under MiCA?

Yes. Specific verification technologies are not prescribed by MiCA, so CASPs may employ AI-powered identity verification, biometric matching and automated document checks provided they meet the regulation's accuracy and reliability standards. Solutions like Joinble's platform are designed to satisfy these requirements.

What are the penalties for KYC non-compliance under MiCA in Spain?

Administrative fines of up to 5,000,000 EUR (or 3% of annual turnover) for legal entities sit at one end of the range, with CASP authorization withdrawal and temporary bans on management members at the other. Severity and duration of the infringement guide the CNMV, which has broad discretion in choosing the appropriate sanction.

Automate your compliance with AI Agents

Joinble's Agentic Identity platform reduces manual KYC reviews by up to 80%. Book a demo to see it in action.

Book a demo