Resource center · Digital Assets

MiCA supervisory reporting for crypto-asset service providers.

This record covers the build rather than the rules: what data a supervisory return draws on, how to structure it so it survives a framework change, and what the cycle looks like around each submission.

Guide MiCA · European Union · supervisory reporting build

The four data sources

A supervisory return under Regulation (EU) 2023/1114 is an assembly of four datasets a provider already holds in some form. Templates, frequencies and formats are set by technical standards and by the competent authority, and they are revised; the four datasets are not. Building against the datasets rather than against the current template is what makes the next framework release a mapping change rather than a rebuild.

What a return draws on
DatasetOwned byFailure mode
Client recordsOnboarding and complianceOne person appearing as several clients after account changes.
Authorised activityThe business, mapped to the authorisationProduct names that do not map to any authorised service.
Holdings and client assetsOperations and financeOwn and client positions not separable at the reference date.
Instrument reference dataA reference data function, where one existsThe same asset carried under several identifiers.

Client records

Reporting is by client, so client identity has to resolve to one record per person or entity regardless of how many accounts, sub-accounts or historic registrations exist. Three attributes carry most of the reporting weight: classification as retail or professional, jurisdiction of residence, and status through the period — a client onboarded or offboarded part-way through a period is not the same as one present throughout.

The same identity resolution serves the tax framework. Doing it once, in the client system rather than in each reporting pipeline, is the difference between two consistent filings and two that cannot be reconciled.

Mapping activity to the authorisation

The return describes activity carried on under the authorisation, so every activity has to map to an authorised service — custody and administration, operation of a trading platform, exchange, execution, placing, reception and transmission of orders, advice, portfolio management, or transfer services.

Map from the authorisation outwards, not from the product catalogue inwards. An activity that maps to no authorised service is either a mapping gap or a permissions issue, and the second is considerably more serious than a reporting one.

Holdings and client assets

Holdings are reported at the reference date, which means a point-in-time snapshot rather than a rolling position. Two separations must be clean: own assets from client assets, and assets held in custody from assets merely traded through the provider. Firms that also issue tokens carry a third measurement — the reserve backing tokens in issue — which overlaps with the client-asset position and must be reconciled to it rather than derived independently.

Instrument and entity identifiers

Identifiers are where supervisory reporting fails first. The entity identifier must resolve consistently across returns and periods. Crypto-asset identifiers must be applied consistently where an asset appears under several tickers, on several chains, or in wrapped and bridged forms — and the policy adopted has to be applied to earlier periods too, or period-on-period comparisons break.

Record the identifier policy as a document, not as behaviour embedded in a mapping. It will be asked about.

The operating cycle

  1. Freeze the reference date position for holdings and client assets, and retain the snapshot rather than recomputing it later.
  2. Resolve client identity for the period, including clients who joined or left.
  3. Map activity to authorised services, escalating anything that does not map.
  4. Assemble and validate against the framework version in force for that reference date.
  5. Reconcile the reported holdings to the finance and custody records, and to the reserve position where tokens are issued.
  6. Retain the working — the snapshot, the mapping and the validation output — as the filing record.

Official sources

Primary instruments only. Each is named in full so the reference remains traceable even if a link moves.

  1. Regulation (EU) 2023/1114 on markets in crypto-assets (MiCA), in particular Titles III, IV and VEUR-Lex · Regulation · issuers, service providers and their obligations
  2. European Securities and Markets Authority and European Banking Authority — technical standards and reporting materials made under the RegulationESMA and EBA · templates, frequencies and formats · consult the current release

REGREP is an independent software provider. This record explains a reporting framework in plain language and is not legal, tax or regulatory advice. Confirm scope, thresholds and submission dates with your competent authority before you file.

Keep reading

More on this framework, and the module that produces the filing.

All digital assets resources

Model the data, not the template.

Map your activity and holdings once and let the module carry the mapping across framework versions.