Insurance built tothe shape of theEuropean regime
- Risk class
- MiCAR / CASP Insurance
- Focus
- European regulatory perimeter
- Related products
- MICASURANCE · T-SURE
- Operating model
- Verify → Monitor → Prevent → Recover → Insure
Why the traditional market struggles
A regulated CASP is assessed on governance, safeguarding of client assets, operational resilience and continuity, not only on loss history. Most insurance programmes are not written to evidence those obligations, so operators end up buying cover that satisfies neither the supervisor nor the risk. 1B builds the programme and the evidence trail as one object.
What we structurearound.
Client asset safeguarding
Segregation, custody and reconciliation exposures across client holdings.
Governance and conduct
Management liability, conduct exposure and third-party claims arising from regulated activity.
Operational resilience
ICT risk, third-party dependency and continuity obligations under the wider EU resilience framework.
Authorisation continuity
Exposures connected to maintaining the conditions on which authorisation depends.
Cross-border passporting
Multi-jurisdiction exposure where a single authorisation carries activity across member states.
Disclosure and marketing
Liability arising from white papers, disclosures and communications to the market.
Capital, orcover. Theregulationlets you choose.
What the article says
- Art. 67(1)
- Prudential safeguards at all times of at least the higher of: the permanent minimum capital in Annex IV for the services provided, or one quarter of the preceding year's fixed overheads, reviewed annually.
- Art. 67(4)
- Those safeguards shall take the form of own funds, an insurance policy covering the Union territories where the services are provided or a comparable guarantee, or a combination of both.
- Art. 67(5)
- The policy is disclosed publicly on the provider's website, runs for an initial term of at least one year, carries a cancellation notice period of at least 90 days, and comes from a third-party undertaking authorised to provide insurance.
- Art. 67(6)
- It must cover seven named categories of risk, set out below.
Why the choice matters later
The requirement moves. What it costs you depends on which form you chose.
- Own funds
- Capital is committed and stays committed. Each review that raises the threshold has to be met with more of it.
- Insurance policy
- The sum insured is adjusted instead. Capital stays available to the business.
The seven categories, Art. 67(6)
Loss of documents
Art. 67(6)(a).
Misrepresentations
Misrepresentations or misleading statements made. Art. 67(6)(b).
Breach of obligations
Acts, errors or omissions resulting in a breach of legal and regulatory obligations, of the obligation to act honestly, fairly and professionally towards clients, or of obligations of confidentiality. Art. 67(6)(c).
Conflicts of interest
Failure to establish, implement and maintain appropriate procedures to prevent conflicts of interest. Art. 67(6)(d).
Business disruption
Losses arising from business disruption or system failures. Art. 67(6)(e).
Gross negligence in safeguarding
Where applicable to the business model, gross negligence in the safeguarding of clients' crypto-assets and funds. Art. 67(6)(f).
Liability to clients
Liability of the provider towards clients pursuant to Article 75(8). Art. 67(6)(g).
Regulation (EU) 2023/1114 (MiCAR), Article 67. The text of the article governs; this page summarises it and is not legal advice.
Read Article 67 on EUR-LexThe loop, appliedto this class.
- Verify
Mapping of the operating model against the obligations that actually drive insurable exposure.
- Monitor
Ongoing tracking of control state and regulatory change across the European perimeter.
- Prevent
Gap remediation ahead of supervisory review, with documentation designed to be shown, not explained.
- Recover
Coordinated response where an incident carries both a loss and a notification obligation.
- Insure
Programme structured so that the cover and the regulatory narrative are consistent.
What stays under observation once the risk is bound.
- Authorisation status and scope
- Client asset segregation model
- ICT and third-party register
- Continuity and exit planning
- Governance and fit-and-proper posture
- Regulatory change exposure
- Crypto-asset service providers
- E-money and payment institutions
- Token issuers within the EU perimeter
- Groups preparing for authorisation
- Legal and compliance advisors