Skip to content
European regulatory perimeter

Insurance built tothe shape of theEuropean regime

MiCAR moved crypto-asset service providers inside a supervised perimeter. Authorisation, prudential safeguards and ongoing obligations now sit alongside commercial risk. 1B structures insurance that speaks the language of that regime rather than retrofitting a generic wording to it.
Risk class
MiCAR / CASP Insurance
Focus
European regulatory perimeter
Related products
MICASURANCE · T-SURE
Operating model
Verify → Monitor → Prevent → Recover → Insure
Supervised perimeterIDLE
OBLIGATION MAPPING · EVIDENCE STATE · PASSPORTING
The gap

Why the traditional market struggles

A regulated CASP is assessed on governance, safeguarding of client assets, operational resilience and continuity, not only on loss history. Most insurance programmes are not written to evidence those obligations, so operators end up buying cover that satisfies neither the supervisor nor the risk. 1B builds the programme and the evidence trail as one object.

Exposure surface

What we structurearound.

The risk surfaces that shape the programme. Cover is structured per counterparty, this is the map, not the wording.

Client asset safeguarding

Segregation, custody and reconciliation exposures across client holdings.

Governance and conduct

Management liability, conduct exposure and third-party claims arising from regulated activity.

Operational resilience

ICT risk, third-party dependency and continuity obligations under the wider EU resilience framework.

Authorisation continuity

Exposures connected to maintaining the conditions on which authorisation depends.

Cross-border passporting

Multi-jurisdiction exposure where a single authorisation carries activity across member states.

Disclosure and marketing

Liability arising from white papers, disclosures and communications to the market.

MiCAR Article 67

Capital, orcover. Theregulationlets you choose.

Article 67 sets the prudential safeguard a crypto-asset service provider must hold at all times, and then names three ways of holding it. Most firms only ever consider the first.

What the article says

Art. 67(1)
Prudential safeguards at all times of at least the higher of: the permanent minimum capital in Annex IV for the services provided, or one quarter of the preceding year's fixed overheads, reviewed annually.
Art. 67(4)
Those safeguards shall take the form of own funds, an insurance policy covering the Union territories where the services are provided or a comparable guarantee, or a combination of both.
Art. 67(5)
The policy is disclosed publicly on the provider's website, runs for an initial term of at least one year, carries a cancellation notice period of at least 90 days, and comes from a third-party undertaking authorised to provide insurance.
Art. 67(6)
It must cover seven named categories of risk, set out below.

Why the choice matters later

The requirement moves. What it costs you depends on which form you chose.

One quarter of the preceding year's fixed overheads, reviewed annually: the threshold rises as the business grows. Met with own funds, each rise ties up more capital that stays tied up. Met with cover, the sum insured follows the threshold and the balance sheet does not.
Own funds
Capital is committed and stays committed. Each review that raises the threshold has to be met with more of it.
Insurance policy
The sum insured is adjusted instead. Capital stays available to the business.
Article 67(4) also allows a combination: own funds for a base, cover for the part above it.
Illustrative. Where the thresholds actually go is for the competent authorities to decide, and nothing here is a representation by 1B about future requirements.

The seven categories, Art. 67(6)

    Loss of documents

    Art. 67(6)(a).

    Misrepresentations

    Misrepresentations or misleading statements made. Art. 67(6)(b).

    Breach of obligations

    Acts, errors or omissions resulting in a breach of legal and regulatory obligations, of the obligation to act honestly, fairly and professionally towards clients, or of obligations of confidentiality. Art. 67(6)(c).

    Conflicts of interest

    Failure to establish, implement and maintain appropriate procedures to prevent conflicts of interest. Art. 67(6)(d).

    Business disruption

    Losses arising from business disruption or system failures. Art. 67(6)(e).

    Gross negligence in safeguarding

    Where applicable to the business model, gross negligence in the safeguarding of clients' crypto-assets and funds. Art. 67(6)(f).

    Liability to clients

    Liability of the provider towards clients pursuant to Article 75(8). Art. 67(6)(g).

Source

Regulation (EU) 2023/1114 (MiCAR), Article 67. The text of the article governs; this page summarises it and is not legal advice.

Read Article 67 on EUR-Lex
How 1B operates here

The loop, appliedto this class.

The same five stages, calibrated to the specific evidence this risk class produces.
  1. Verify

    Mapping of the operating model against the obligations that actually drive insurable exposure.

  2. Monitor

    Ongoing tracking of control state and regulatory change across the European perimeter.

  3. Prevent

    Gap remediation ahead of supervisory review, with documentation designed to be shown, not explained.

  4. Recover

    Coordinated response where an incident carries both a loss and a notification obligation.

  5. Insure

    Programme structured so that the cover and the regulatory narrative are consistent.

Continuous signals

What stays under observation once the risk is bound.

  • Authorisation status and scope
  • Client asset segregation model
  • ICT and third-party register
  • Continuity and exit planning
  • Governance and fit-and-proper posture
  • Regulatory change exposure
Built for
  • Crypto-asset service providers
  • E-money and payment institutions
  • Token issuers within the EU perimeter
  • Groups preparing for authorisation
  • Legal and compliance advisors
MiCAR / CASP Insurance

This risk isalready live.The insuranceshould be too.