Skip to main content
green gradient background, "The Future of Application Security Is Already Here." and a read the report button.
MiCA Third-Party Vendor Assessment TemplateRegulatory Obligations Management
7 min readFor Third-Party Risk Managers

MiCA Third-Party Vendor Assessment Template

ESMA's proposed MiCA revisions demand immediate attention from third-party risk managers. If your organization engages with crypto-asset service providers, you need a structured way to evaluate whether those vendors will comply with the new requirements before ESMA finalizes them.

This template provides a vendor assessment framework based on ESMA's three priority areas: investor protection enhancements, supervisory compliance, and DeFi classification. Use it to identify gaps in your current vendor relationships and flag providers who may struggle with the upcoming changes.

Purpose of the Template

When evaluating a crypto-asset service provider, such as an exchange, custodian, staking service, or DeFi access platform, this template helps you:

  • Assess the vendor's readiness for stricter marketing rules, transparency requirements, and DeFi-related obligations.
  • Document control gaps that could trigger regulatory action or supervisory intervention.
  • Build a remediation roadmap with the vendor before ESMA's recommendations become binding.
  • Support your organization's regulatory alignment efforts if you're a financial entity subject to MiCA.

This isn't a general vendor risk questionnaire. It's specifically designed for the regulatory shifts ESMA has outlined: influencer marketing controls, cost transparency, staking/lending disclosures, and the proposed regulated service for DeFi protocol access.

Prerequisites

Before using this template, confirm:

  • The vendor is in scope. They offer crypto-asset services to EU investors or your organization uses them to access crypto markets.
  • You have access to the vendor's whitepaper and marketing materials. ESMA's proposals emphasize disclosure quality, so review what the vendor currently publishes.
  • You can engage the vendor's compliance or legal team. Some questions require internal policy documentation, not just public-facing materials.
  • You understand your own Impact Tolerance. The template flags issues; you decide which gaps are acceptable and which require remediation.

The Template

Copy the sections below into your vendor risk assessment workflow. Customize the rating scale to match your existing vendor risk methodology.


VENDOR NAME:
ASSESSMENT DATE:
ASSESSOR:
VENDOR CONTACT:

Section 1: Marketing and Third-Party Promotion Controls

ESMA proposes stricter rules for crypto-asset marketing, particularly when promoted by influencers and third parties.

Question Response Rating Evidence
Does the vendor use influencers or affiliates to market crypto-assets to EU investors? Yes / No / Unknown
If yes, does the vendor maintain a registry of influencer partnerships and promotional agreements? Yes / No / N/A
Are influencers required to disclose material risks, conflicts of interest, and compensation arrangements? Yes / No / N/A
Does the vendor review influencer content before publication? Yes / No / N/A
Can the vendor demonstrate compliance with existing national marketing rules in EU member states where it operates? Yes / No / Partial
Has the vendor been subject to enforcement action related to marketing practices in the past 24 months? Yes / No / Unknown

Gap summary:


Section 2: Cost Transparency and Disclosure

ESMA's recommendations emphasize greater transparency in costs before investment decisions are made.

Question Response Rating Evidence
Does the vendor's whitepaper or disclosure documentation clearly itemize all fees (trading, custody, withdrawal, conversion)? Yes / No / Partial
Are fee structures presented in a standardized format that allows comparison with competitors? Yes / No
Does the vendor disclose indirect costs (e.g., spread, slippage, network fees) separately from direct fees? Yes / No / Partial
Are fee schedules updated when material changes occur, with notice to clients? Yes / No / Unknown
Can clients access fee information before committing funds or completing onboarding? Yes / No

Gap summary:


Section 3: Staking, Lending, and Borrowing Safeguards

ESMA proposes requirements for staking, lending, and borrowing, including disclosure obligations covering risks, rewards, collateral arrangements, and potential losses.

Question Response Rating Evidence
Does the vendor offer staking, lending, or borrowing services? Yes / No
If yes, are clients provided with disclosure documents that explain reward calculation methodologies? Yes / No / N/A
Are collateral arrangements, liquidation thresholds, and loss scenarios documented before clients participate? Yes / No / N/A
Does the vendor distinguish between guaranteed and variable returns in promotional materials? Yes / No / N/A
Are counterparty risks (e.g., protocol insolvency, validator slashing) disclosed in plain language? Yes / No / N/A
Does the vendor maintain segregated client assets for staking/lending programs? Yes / No / Unknown / N/A

Gap summary:


Section 4: DeFi Protocol Access and Classification

ESMA suggests creating a new regulated crypto-asset service for firms that provide users with access to DeFi protocols and adopting clearer criteria for determining which activities can be considered genuinely decentralized.

Question Response Rating Evidence
Does the vendor provide access to DeFi protocols (e.g., through a wallet, interface, or aggregation service)? Yes / No
If yes, does the vendor currently operate under any regulated crypto-asset service authorization in the EU? Yes / No / N/A
Has the vendor documented which protocols it considers "genuinely decentralized" versus those requiring regulatory oversight? Yes / No / N/A
Does the vendor perform due diligence on DeFi protocols before offering client access? Yes / No / N/A
Can the vendor demonstrate control over which protocols are accessible through its platform? Yes / No / N/A
Has the vendor assessed whether it would qualify for ESMA's proposed DeFi access service authorization? Yes / No / Unknown / N/A

Gap summary:


Section 5: Supervisory Compliance and Fraud Prevention

ESMA recommends enhancing the EU's capacity to detect, block, and deactivate fraudulent websites, freeze crypto-assets in cases of suspected market abuse or terrorist financing, and reinforce supervisory powers over third-country firms soliciting EU investors without authorization.

Question Response Rating Evidence
Is the vendor authorized under MiCA or a national regime in an EU member state? Yes / No / Pending
If the vendor is based outside the EU, does it have a legal representative or authorized entity within the EU? Yes / No / N/A
Does the vendor maintain systems to freeze or block assets upon supervisory request? Yes / No / Unknown
Has the vendor implemented controls to prevent offering services linked to non-compliant stablecoins? Yes / No / N/A
Does the vendor participate in information-sharing arrangements with EU supervisory authorities? Yes / No / Unknown
Has the vendor been subject to enforcement action or supervisory intervention in any jurisdiction in the past 36 months? Yes / No / Unknown

Gap summary:


Section 6: Token Classification and Hybrid Products

ESMA proposes adopting rules on how crypto-assets should be classified, including new products such as hybrid tokens, and granting ESMA the ability to issue binding opinions on token classification.

Question Response Rating Evidence
Does the vendor issue or list hybrid tokens (assets with characteristics of multiple token types)? Yes / No
If yes, has the vendor documented its classification methodology for these tokens? Yes / No / N/A
Does the vendor have a process to reclassify tokens if ESMA issues binding opinions? Yes / No / Unknown / N/A
Are clients notified when a token's classification changes, particularly if it affects regulatory treatment? Yes / No / N/A

Gap summary:


OVERALL RISK RATING: [Low / Medium / High / Critical]

REMEDIATION REQUIRED: [Yes / No]

NEXT REVIEW DATE:


How to Customize It

Adapt this template to your organization's vendor risk framework:

Adjust the rating scale. If you use a five-point scale (1-5) or qualitative descriptors (Acceptable, Needs Improvement, Unacceptable), replace the Rating column format.

Add weighting. Not all sections carry equal risk. If your organization doesn't use staking services, de-emphasize Section 3. If you rely heavily on DeFi access, weight Section 4 more heavily in your overall risk calculation.

Integrate with your vendor risk platform. If you use ServiceNow GRC, AuditBoard, or a similar IRM platform, map these questions to custom assessment modules. Link evidence requests to your vendor portal so providers can upload documentation directly.

Expand the evidence column. Specify what you want to see: policy documents, audit reports, legal opinions, or screenshots of disclosure pages. The more precise your evidence requirements, the faster vendors can respond.

Tailor for third-country vendors. If you assess providers outside the EU, add questions about their plans for EU market access, legal representation, and willingness to submit to EU supervisory authority.

Validation Steps

After you complete the assessment:

  1. Cross-reference with existing vendor risk profiles. If the vendor already has a Vendor Risk Profile in your system, compare the MiCA-specific findings with broader operational and security risks. A vendor with strong cybersecurity controls but weak disclosure practices still presents regulatory risk.

  2. Engage your legal or compliance team. Share high-risk findings with internal counsel, especially if the vendor operates in a grey area (e.g., offering DeFi access without clear authorization). Legal can advise on contractual remedies or exit strategies.

  3. Request a remediation plan. For any section rated Medium or higher risk, ask the vendor to document how they'll address gaps. Set a timeline: 30 days for policy updates, 90 days for system changes, 180 days for authorization applications.

  4. Schedule a follow-up. ESMA's recommendations aren't final. As the European Commission moves toward formal rulemaking, reassess vendors quarterly. Track whether they're monitoring regulatory developments and adjusting their compliance programs.

  5. Document your decision. If you choose to continue the relationship despite identified gaps, record your rationale in your Policy Exception Registry. Include compensating controls (e.g., limiting transaction volume, requiring additional client disclosures) and the conditions under which you'd terminate the relationship.

This template won't eliminate regulatory uncertainty, but it will give you a defensible process for evaluating crypto-asset vendors as MiCA evolves. That's what supervisors will ask for if your third-party relationships become a point of scrutiny.

Promotional banner highlighting failures found in PCI audits and how to spot the gaps

You Might Also Like