
Fintech
Guide
Day 2: The back office your MiCA CASP licence assumes you have
Nicolas Devillard
First in the Forest MiCA series by Nicolas Devillard, Forest's CRO. What supervision under MiCA asks of a licensed CASP now that the transitional period has ended.
To get your authorisation as a crypto-asset service provider (CASP) under the EU's Markets in Crypto-Assets regulation (MiCA), you described your procedures to your regulator. How alerts are handled. How client assets stay segregated. How complaints get resolved, who approves what, and how fast. The application was accepted, the licence is on the wall.
Since 1 July 2026, the MiCA transitional period for pre-existing CASPs has ended (Article 143, Regulation (EU) 2023/1114). Supervision is the moment your regulator compares the procedures you described with what your data actually shows. That gap, between the process on paper and the process in production, is what this article is about.
The operational loop every CASP application describes
Strip the legal language away and every CASP application promises the same operational loop: a signal comes in, someone qualified looks at it with full context, a decision gets made within a known delay, and the decision leaves a trace someone else can verify.
The signal can be a Sumsub KYC alert, a Chainalysis flag, a client complaint, a DORA incident. The loop is the same. And in most newly licensed CASPs, it runs across four browser tabs, a SQL query someone writes on demand, and a Slack thread where the actual decision lives.
That setup produces correct decisions most of the time. What it cannot produce is proof, delay metrics, or consistency once volume grows. Those three things are precisely what a supervisor measures (Articles 68 and 73 of MiCA).
What happens when a CASP loop has no floor
The Coinbase Europe case is worth reading for this reason, not for the headline number. In November 2025 the Central Bank of Ireland fined Coinbase Europe €21.5 million under Irish anti-money-laundering rules. Three coding errors had silently disabled 5 of 21 monitoring scenarios, leaving 30 million transactions unmonitored. That part was a detection failure.
The part that concerns a licensed CASP more: once the alerts existed, the suspicious transaction reports reached the regulator years late. Between alert and filing there was no case, no owner, no visible delay. The loop had no floor to stand on, so nobody saw it failing.
Detection vendors cover the signal. The loop after the signal is yours.
Five MiCA questions your NCA is already asking
For each one, the answer should come from a system, not from someone's memory.
Take any AML alert from last month. Can you produce the full decision trail, who reviewed it, what they decided, when, in under an hour?
Can you show which client assets were segregated, where, and who last touched the record?
What is your median delay between an alert firing and a decision being taken?
Are compliance, risk and IT roles separated in your tools, or only in your org chart?
If your regulator asked for evidence tomorrow at 9am, would the export come from a system, or from a developer pulled off the roadmap?
Missing two or three of these is normal at this stage. Nearly every CASP that licensed through the transitional period built its application faster than its operations. Since 1 July 2026, your NCA expects a continuous stream of proof, and on 28 July, ESMA's guidelines on staff knowledge and competence (Article 81 MiCA) add another layer.
What closing the MiCA supervision gap actually buys you
Not compliance for its own sake. Three concrete things.
Hours per case
When the alert, the client's account, the transaction history and the documents sit in one screen, an analyst decides in minutes instead of assembling context across tools. At retail volume, that is the difference between a backlog and a clean queue.
Your roadmap, intact
The alternative is your own engineers building and maintaining an internal compliance back office. Every sprint spent there is a sprint not spent on product, indefinitely, because obligations do not ship and stop.
Short conversations with your regulator
When evidence exports in minutes, reviews end early and trust compounds. Compliance teams that answer fast get asked less.
How the Forest back office closes the MiCA loop
A dedicated compliance suite adds a tool to the stack and moves client data into someone else's cloud. Under DORA (Regulation (EU) 2022/2554, Articles 28-30), that is a new critical ICT provider to assess, contract with, and plan an exit from. Your regulator will ask about that too.
Forest runs the loop on the database you already have, on your infrastructure. Client data never leaves your environment. Alerts become cases with owners and deadlines. Every action is timestamped. Evidence exports without a developer in the room. And because it is a full back office rather than a compliance silo, support, ops and finance work in the same panel, which matters when your whole company is forty people.
MiCA Day 2: where supervision goes from here
Day 2 begins the moment the licence is on the wall. The procedures you described to your regulator are now the standard your data gets measured against, day after day. The teams in the best position a year from now are the ones closing that gap this quarter, while supervision is young and goodwill is cheap.
See the loop on your own data: 30 minutes, your database, a working compliance panel. Book a session.
Forest is the operational infrastructure for regulated fintechs. Compliance, ops, and support teams work on your systems alongside your AI agents, under one permission model and one audit trail. On your own infrastructure. Learn more at forest.app.
