Skip to content
buybitcoinsmart

Glossary / Regulation & tax

Regulatory authorisation

Also known as Regulatory licence, Regulatory approval.

What is Regulatory authorisation?
Regulatory authorisation is the permission a financial supervisor grants a named firm to carry on specific listed activities, valid only for the services the decision itself names.

Under the European Union's Markets in Crypto-Assets Regulation, nobody may provide a crypto-asset service in the Union without one. A competent authority has 40 working days from a complete application to grant or refuse, and must withdraw an authorisation that has gone unused for 12 months. Read which services a platform's authorisation actually covers before you send it money.

How it works

Regulatory authorisation under MiCA starts life as a prohibition. Article 59(1) says a person shall not provide crypto-asset services within the Union unless authorised as a crypto-asset service provider in accordance with Article 63, or unless it is one of the listed financial entities (credit institutions, investment firms, electronic money institutions and others) allowed to provide those services under Article 60. The permission that lifts the prohibition is narrow by design: Article 59(6) requires competent authorities to make each authorisation specify the crypto-asset services the firm is authorised to provide, and Article 59(8) sends a firm that wants to add a service back to apply for an extension, assessed all over again. Article 59(4) makes the conditions continuous rather than one-off, since an authorised provider "shall at all times meet the conditions for their authorisation".

Article 63 puts the decision on a clock. The authority acknowledges the application in writing within five working days, checks within 25 working days whether it is complete, and once it is complete has 40 working days to adopt a fully reasoned decision granting or refusing, which is notified to the applicant within five working days of the date of that decision. Article 64 then makes the result revocable, and lists seven grounds for mandatory withdrawal: the authorisation was not used within 12 months, the firm expressly renounced it, no crypto-asset services were provided for nine consecutive months, it was obtained by irregular means such as false statements in the application, the firm no longer meets the conditions it was granted under and has not taken the remedial action the authority asked for in time, it fails to have effective systems to detect and prevent money laundering and terrorist financing under Directive (EU) 2015/849, or it has seriously infringed the Regulation.

Where you see it

A regulatory authorisation is granted by one national supervisor, and that supervisor's own pages are where the practical shape of it shows. Finland's Financial Supervisory Authority (FIN-FSA) publishes the processing sequence for crypto-asset service providers, restating Article 63(12) in plain language: during the 40 working day substantive assessment it may request further clarifications, but only the first of those requests suspends the assessment period, and it suspends it for a maximum of 20 working days. The same page sets out what the application file has to contain, including a programme of operations covering a three-year period, governance and internal control descriptions, prudential safeguards and minimum capital, and a description of how client assets are segregated and safeguarded.

That is the reason our country crypto-licence guides are organised around the authority, the scope and the deadline rather than around the bare word "licensed". A firm's authorisation tells you which services it may legally sell you, which supervisor hears your complaint, and which decision could later be withdrawn.

Regulatory authorisation vs MiCA passporting

Regulatory authorisation and MiCA passporting answer two different questions: who granted the permission, and how far it reaches. The authorisation is a single decision by the competent authority of the firm's home Member State, which under Article 59(2) is where the firm must keep its registered office, with its place of effective management in the Union and at least one director resident there. Passporting is what Article 59(7) does with that decision: an authorised provider may serve clients throughout the Union through the right of establishment or the freedom to provide services, and a cross-border provider cannot be required to have a physical presence in a host Member State. So a Finnish authorisation is not a Finland-only permission, but it is still one authority's decision, and it still covers only the services named in it.

Not to be confused with

Frequently asked questions

How long does a MiCA authorisation decision take?

The competent authority acknowledges the application within five working days, decides within 25 working days whether it is complete, and then has 40 working days to grant or refuse, notifying the applicant within five working days of that decision. Under Article 63(12), only the first request for further information suspends that 40 working day period, and the suspension may not exceed 20 working days; Finland's FIN-FSA restates the same rule on its own processing page.

Does an authorisation mean my money is guaranteed?

No. The authorisation articles bind the firm to conditions it must meet at all times and let the authority withdraw the permission when it stops meeting them, but they promise you no repayment. Check what the authorisation actually names: it covers only the crypto-asset services listed in the decision itself.

Read next

Related terms

More in Regulation & tax