The European Commission recently adopted a Delegated Regulation amending Commission Delegated Regulation (EU) 2018/1108 to extend the existing framework on central contact points to crypto-asset service providers (“CASPs”). This is expected to come into force following publication in the Official Journal of the EU.
Delegated Regulation (EU) 2018/1108 already established the criteria for the appointment of central contact points in relation to electronic money issuers (“EMIs”) and payment service providers (“PSPs”). The new Delegated Regulation will extend this framework to CASPs. The provisions already applicable to EMIs and PSPs will remain unchanged, while certain new provisions have been introduced specifically for CASPs where this was considered necessary in light of their particular business model and operations. For these purposes, the definition of CASP excludes providers whose only crypto-asset service is providing advice on crypto-assets.
Similar to EMIs and PSPs, host Member States may require CASPs to appoint a central contact point where this is proportionate to the level of money laundering or terrorist financing (“ML/TF”) risk associated with their activities.
Importantly, this requirement is relevant where a CASP has establishments in the host Member State in a form other than a branch and its head office is situated in another Member State.
The wording of the Delegated Regulation indicates that the requirement does not arise merely because a CASP passports its services into another Member State under the freedom to provide services. Rather, the central contact point regime is linked to the CASP having an establishment in the relevant host Member State. Therefore, where a CASP passports its services on a pure freedom to provide services basis and does not maintain an establishment there, the central contact point requirement should generally not be triggered.
However, the absence of a formal branch does not automatically mean that the requirement cannot apply. The relevant question is whether the CASP has an establishment in the host Member State in a form other than a branch. This distinction is therefore particularly important for CASPs passporting their services throughout the EU without making use of the freedom of establishment.
Article 3 sets out the circumstances in which a host Member State may require the appointment of a central contact point. One of the criteria concerns the scale of the CASP’s activities. In particular, the cumulative value of the services and activities carried out by the CASP’s establishments is expected to exceed EUR 3 million per financial year, or has exceeded that amount in the previous financial year. The other criteria are that the number of such establishments is 10 or more, or that information needed to assess either the number-of-establishments criterion or the EUR 3 million criterion is not made available to the host Member State’s competent authority upon request and in a timely manner.
Host Member States may also require categories of CASPs with establishments in their territory to appoint a central contact point where this is commensurate with the ML/TF risk associated with the operation of those establishments.
In exceptional cases, the competent authority of the host Member State may also require an individual CASP to appoint a central contact point if empowered to do so by that Member State and where the host Member State has reasonable grounds to believe that the operation of its establishments presents a high risk of money laundering or terrorist financing.
Where a central contact point is required, its main function will be to ensure that the CASP, in respect of its establishments, complies with the AML/CFT rules applicable in the host Member State.
The central contact point must facilitate the development and implementation of AML/CFT policies and procedures by informing the CASP of the AML/CFT requirements applicable in the host Member State. It must also oversee effective compliance by the relevant establishments with those requirements and with the CASP’s own AML/CFT policies, controls and procedures.
The central contact point must also inform the CASP’s head office of any breaches or compliance issues, ensure corrective action is taken where there is non-compliance or a risk of non-compliance, and ensure that the establishments and their staff participate in the required AML/CFT training. It will also represent the CASP in communications with the competent authorities and the Financial Intelligence Unit of the host Member State.
The central contact point must facilitate supervision by the competent authorities of the host Member State, including by representing the CASP before those authorities and responding to requests relating to the activities of its establishments.
Host Member States may require central contact points to perform additional functions where these are commensurate with the overall ML/TF risk associated with the operation of the CASP’s establishments.
What does this mean for CASPs passporting across the EU?
For CASPs which passport their services across the EU without establishing a branch or any other form of establishment in the host Member State, the immediate impact of the Delegated Regulation should be limited. Nevertheless, CASPs should review their cross-border arrangements to determine whether any presence maintained in another Member State could constitute an establishment for these purposes.
Where an establishment exists, the CASP should assess the relevant Article 3 criteria and any local requirements imposed by the host Member State, particularly where its activities may present an increased ML/TF risk. CASPs should ensure that their passporting structure and AML/CFT framework remain aligned with the requirements applicable in the relevant Member States.
Should you require any assistance in assessing the applicability of these requirements to your CASP’s cross-border operations, please contact us at info@gtg.com.mt.
Author: Dr Kimberley Blundell