ID-DRITT XXXVI – Fiduciary obligations, conflicts of interest and an EU regulation called “MiCAR”

Introduction

Conflicts of interest are a central issue to all legal systems, an awareness which is exemplified by the Markets in Crypto-Assets Regulation1, a foundational regulation aimed at protecting consumers of crypto-assets. MiCAR has addressed the issue frontally. Article 72 addresses the identification, prevention, management, and disclosure of conflicts of interest in the context of the provision of services to clients when they relate to crypto-assets, a new form of assets. These are new forms of digital assets broadly similar to investment instruments, and possibly even money, on which there is a large amount of regulation already in place.

For ease of reference, Article 72 on the identification, prevention, management, and disclosure of conflicts of interest is being reproduced here:

1. Crypto-asset service providers shall implement and maintain effective policies and procedures, taking into account the scale, the nature and range of crypto-asset services provided, to identify, prevent, manage and disclose conflicts of interest between:

(a) themselves and:

i. their shareholders or members;
ii. any person directly or indirectly linked to the crypto asset service provider or their shareholders or members by control;
iii. members of their management body;
iv. their employees; or
v. their clients; or

(b) two or more clients whose mutual interests conflict.

2.Crypto-asset service providers shall, in a prominent place on their website, disclose to their clients and prospective clients the general nature and sources of conflicts of interest referred to in paragraph 1 and the steps taken to mitigate them.

3.The disclosure referred to in paragraph 2 shall be made in an electronic format and shall include sufficient detail, taking into account the nature of each client, in order to enable each client to take an informed decision about the crypto-asset service in the context of which the conflicts of interest arise.

4.Crypto-asset service providers shall assess and, at least annually, review their policy on conflicts of interest and take all appropriate measures to address any deficiencies in that respect.

5.ESMA, in close cooperation with EBA, shall develop draft regulatory technical standards to further specify: (a) the requirements for the policies and procedures referred to in paragraph 1, taking into account the scale, the nature and the range of crypto-asset services provided; (b) the details and methodology for the content of the disclosure referred to in paragraph 2. ESMA shall submit the draft regulatory technical standards referred to in the first subparagraph to the Commission by 30 June 2024. Power is delegated to the Commission to supplement this Regulation by adopting the regulatory technical standards referred to in the first subparagraph of this paragraph in accordance with Articles 10 to 14 of Regulation (EU) No 1095/2010.

MiCAR draws heavily from the Markets in Financial Instruments Directive (MiFID II)2, the European Union’s (EU) principal framework for investment services. MiCAR identifies and applies similar principles to those crypto-assets which have a broad resemblance to investments, regulating both their issuance and the services related to them. Consequently, MiCAR replicates many of MiFID II’s core regulatory standards, including those on conflicts of interest. Of course, there is sensitivity to the context, and it should be noted that there are many other pieces of legislation relating to innovative technology both in Malta and the EU which need to be kept in mind.

MiCAR requires all crypto-asset service providers (CASPs) to have a robust policy on conflicts of interest. The identification, prevention, management, and disclosure of conflicts of interest are basic in the provision of any fiduciary services to clients by intermediaries. Intermediaries are fiduciaries. This is the case whether their services refer to traditional assets or new ones. CASPs play a pivotal role by offering a diverse range of services to clients.

As a Regulation, MiCAR is directly applicable in Malta and its courts. However, any EU law will be best applied if it finds consistent rules within the domestic legal system. This is the case in Malta, not only because Malta has fully adopted and implemented the EU rules on investment services, but because the Civil Code3 robustly addresses fiduciary obligations. MiCAR has been transposed into Maltese law through the Markets in Crypto-Assets Act, Chapter 647 of the Laws of Malta.

Article 1124A(4) of the Civil Code deals specifically with conflicts of interest in sub-paragraphs (b), (c), and (d). These reflect the commonly applied principles after a statement in sub-article (4) that a fiduciary must carry out his obligations ‘with utmost good faith and to act honestly in all cases’. Sub paragraph (a) continues with a statement that the diligence of a bonus pater familias is expected in relation to the performance of all fiduciary obligations, and after sub-paragraph (d), we then find a series of administrative duties intended to protect clients through segregation of assets, record keeping, accounting, and returning the property to the beneficiary. All these are then strengthened by the very important rules in Article 1124C and other provisions setting out the legal regime on fiduciary obligations in more detail. A very important foundational rule is found in Article 1124C, which creates a segregated patrimony for all fiduciary assets:

1124C. (1) Where a person is vested with ownership, has registered in his name, holds, exercises control or powers of disposition over property subject to fiduciary obligations, such property shall constitute a distinct and separate patrimony, consisting of all relative rights and obligations with respect thereto, and such property shall not be subject to the claims or rights of action of the fiduciary’s personal creditors, nor of his spouse or heirs at law, except as stated in the provisions of this Code or of special laws.

This is the background against which MiCAR will apply in Malta, and that is a very positive factor to keep in mind. The more detailed contextual rules in MiCAR complement the basic principles in the Civil Code admirably.

MiCAR recognises that CASPs operate in a complex environment where competing interests often arise.4 CASPs, as service providers, are mostly always fiduciaries as they act in the interest of other persons. Conflicts may emerge between CASPs and their clients, between clients themselves, or internally within the CASP’s structure. MiCAR’s approach is to ensure that these conflicts are not only identified but also disclosed and mitigated. This reflects a broader regulatory trend seen since MiFID II’s implementation in 2014, which introduced stricter behavioural rules for investment firms across the EU.5

Service providers are principally guided by the general requirement to act honestly, fairly, and professionally in accordance with the best interests of their clients. Addressing conflicts of interest is part of these general duties of all service providers in this context. As we see in other articles preceding Article 72, CASPs are obliged to provide their clients with information that is complete, fair, clear, and not misleading, as well as inform them of the risks associated with crypto-assets.6 In complying with these regulatory requirements, CASPs ensure consumer protection, market integrity, and financial stability in this relatively new sector of economic activity.

There is no doubt that CASPs engage in various activities and offer an expanding range of services, increasing the potential for conflicts of interest to arise.7 Therefore, CASPs have a firm duty to take active measures to mitigate any potential detriment which may arise to the interests of their clients.8 These conflicts should be effectively managed within the framework of a functional financial system.

The term ‘conflict of interest’ is not an easy term to define. Most legal systems do not do so expressly. If the term had to be defined in a law such as MiCAR, there would be a real risk that it would be used to exclude dishonest behaviours on the basis of technical wording. It should be noted, therefore, that the drafters of Article 72 were correct in not attempting a definition of what a conflict of interest is.

A conflict of interest may arise from contexts such as an unconditional or exclusive duty on one party to protect the interests of another, the holding or administration of property of another, or the awareness of confidential information regarding another party and his assets. Most conflicts of interest emerge from a combination of these elements, which may be increased when other objective elements combine with them, such as family, professional, or business relationships, apart from purely personal interests. These all clash with the unconditional or exclusive loyalty a service provider must extend to a client.

The term ‘interests’ is also ambiguous, as conflicts do not only arise when economic interests feature. Conflicts will also undoubtedly arise even outside a strictly economic realm. Moreover, the interests may refer to another person and not necessarily the service provider itself. If a third party is allowed by the CASP to benefit to the detriment of the client, it will equally qualify as a failure of duty, even if the service provider does not gain anything at all.

The lack of a uniform definition of the term ‘conflict of interest’ may create difficulties for CASPs to identify scenarios which constitute a conflict of interest and may lead to situations where conflicts go unidentified and unmanaged. In truth, the challenge of conflicts should not be addressed technically but should more importantly be addressed intuitively. Given overriding conflicts of interest, a person with normal levels of good faith and honesty will immediately recognise if actions amount to dishonest or disloyal behaviour. Of course, ‘normal levels of good faith and honesty’ is not something which can always be assumed, and in the crypto sector we have seen some serious aberrations.

Additionally, MiCAR identifies both CASPs and crypto-assets as the subject of regulation. These concepts, which have now been defined, constitute a quantum leap in this area of law. Had MiCAR not taken these definitional steps, most EU member states would have major problems dealing with this group of service providers and this class of assets. There would also be the risk that as each country started to legislate on the sector, they would all come out with different definitions of what the sector includes and excludes. This would be to the detriment of their citizens and economies. We now see that the very notion of conflicts of interest is firmly anchored to CASPs and crypto-assets as a defined service sector in relation to a defined type of property. That is a major advance in itself.

In order to ensure that CASPs understand how to avoid situations of conflicts of interest, one may refer to what happened with MiFID. Commission Delegated Regulation (EU) 2017/565 (EU 2017/565), supplementing MiFID II, provides a set of minimum criteria to identify conflicts which are potentially harmful to the interests of clients. Under Article 33 thereof, these criteria cover financial gains, interests in service outcomes, incentives, similar businesses, and inducements from external sources.9 Indeed, we now see that MiCAR is again following the same model used for MiFID II and is resorting to EU 2017/565 as guidance in identifying possible scenarios of conflicts of interest.

In fact, earlier this year, following a Consultation Paper10 and the Final Report on the Regulatory Technical Standards by the European Securities and Markets (ESMA),11 the Commission adopted the Commission Delegated Regulation (EU) 2025/1142,12 which supplements MiCAR with regard to regulatory technical standards specifying the requirements for policies and procedures on conflicts of interest for crypto-asset service providers and the details and methodology for the content of disclosures on conflicts of interest (EU 2025/1142).

EU 2025/1142 provides guidance on methodology, proportionality, and transparency, requiring CASPs to allocate resources for effective conflict management. These rules do not only protect investors but also promote legal certainty and simplify compliance for regulated entities, fostering trust and encouraging investments in crypto-assets through regulated CASPs. EU 2025/1142 focuses on CASPs and connected persons, and aims for further standardising practices across EU legislation for consistent conflict identification. Naturally, and while there still exists a lack of definition of what constitutes a conflict of interest, a regulatory first step is to make it clear that conflicts of interest are to be avoided, and guidance is then given on the direction of thought and behaviour expected of CASPs.

Additionally, EU 2025/1142, particularly in Article 2, addresses conflicts which are potentially harmful to the CASP itself, taking a step beyond client-centric concerns. It outlines circumstances impacting connected persons’ duties in CASPs and provides that CASPs must consider economic, personal, professional, and political relationships, along with conflicting tasks or hierarchical supervision in which the connected person is involved. CASPs are therefore urged to conduct a holistic review, particularly for high-risk services.

To identify conflicts of interest, CASPs should have procedures in place to identify situations that give, or may give, rise to conflicts of interests, including the role and capacity in which the CASP is acting. This is particularly relevant in situations where the CASP is presenting itself as an exchange but engages in multiple activities such as operating a trading platform in crypto-assets, market making, or offering margin trading.13 When the CASP trades on its own account in such lines of activity, such as when performing OTC trading services, there is such an obvious conflict of interest, which activity is expressly prohibited by Article 76(5) of MiCAR. This proactive approach aims to minimise conflicts of interest, reducing the risk of material damage to clients’ interests.14

In view of the above, managing conflicts of interest necessitates a multifaceted approach that combines competition, disclosure, regulatory frameworks, and organisational adjustments to foster a financial landscape that prioritises the interests of clients.15 Beyond the technicalities of the drafting, it ought to be recognised that MiCAR creates an expectation of honest, fair, and loyal behaviour from all CASPs, who cannot claim ignorance of the law on the most basic tenets of good behaviour expectations in carrying out a regulated activity.

2. Purpose of Implementing and Maintaining Effective Policies and Procedures to Identify, Prevent, Manage, and Disclose Conflicts of Interest – Article 72(1)

General Comments

Managing conflicts of interest is fundamental to any fiduciary relationship. In the context of CASPs, this obligation is heightened due to the inherent information asymmetry between service providers and clients. Clients may find themselves in a position where they lack access to sufficient information to identify and safeguard against potential repercussions resulting from these conflicts. Therefore, proactive measures are essential to ensure transparency and facilitate informed decision-making for clients in navigating the complexities of such relationships.16

Both CASPs and their connected persons bear the responsibility of executing their roles objectively and independently, always prioritising the best interests of their clients. While Article 72(1) lists specific categories of persons such as shareholders, management, employees, and clients, the concept of ‘connected persons’ emerges more clearly in EU 2025/1142. EU 2025/1142 expands the scope of Article 72(1), offering a more nuanced understanding of potential conflict scenarios.

In its Consultation Paper, ESMA provided further analysis and contexts within which a conflict of interest can arise:17

  1. conflicts arising between the CASP and its clients;
  2. conflicts emerging between individual clients or groups of clients of the CASP; and
  3. conflicts that may prevent persons or entities linked to the CASP such as employees, shareholders, or members of the management body, to exercise their duties and responsibilities in an objective manner, further classifying this last category as internal conflicts of interest.

Article 2 of EU 2025/1142 outlines specific circumstances in which conflicts of interest are likely to arise. These circumstances often revolve around instances where there is a potential for financial gain or a vested interest in a particular outcome, or when the CASP is involved in the same business activities as the client.

Additionally, Article 6 of EU 2025/1142 goes on to define a ‘personal transaction’ which is not referred to in Article 72(1). ESMA once again provides more examples and a wider context for conflicts of interest to arise. In its definition of a ‘personal transaction’, ESMA also makes reference to ‘family relationships or close links’, stating that, for the purposes of identifying conflicts of interest, a ‘person with whom a connected person has a family relationship’ includes the spouse of the connected person or any partner recognised by national law as equivalent to a spouse, a dependent child or stepchild of the connected person and any other relative of the connected person who has shared the same household for at least one year on the date of the relevant personal transaction.

In instances where a CASP’s independence and objectivity may be compromised due to a potential conflict of interest, the CASP must take all necessary measures to prevent and mitigate such conflicts. The initial and fundamental step in this process involves identifying and familiarising oneself with the various types of conflicts of interest that may emerge. This proactive approach ensures that conflicts are not only identified but also appropriately addressed to safeguard the interests of all parties involved. After having identified the conflicts, the obligation shifts into a higher gear in the identification, prevention, management, and disclosure.

Scope of the Prohibition against Conflicts and of Relevant Obligations

Effective management of conflicts of interest relies significantly on the formulation and implementation of specific policies and procedures. Establishing clear rules and policies is vital in shaping the behaviour of service providers. These guidelines may directly address conflicts of interest, outlining the conduct that is permissible or not.18

The preparation in written form of policies and procedures on the subject of conflicts of interest plays a pivotal role in reducing conflicts, whether their details are openly disclosed or not. One approach involves direct prohibition, whereby rules dictate the avoidance of conflicts or the activities that might give rise to conflicts of interest.

However, policies alone are insufficient. They must be understood and internalised across the organisation. Training and induction are critical, especially in a sector marked by diverse backgrounds and varying levels of regulatory awareness. The difficulty of ensuring proper awareness, understanding, and internalisation is real. The financial crisis of 2008 happened in the most sophisticated of financial centres so nothing can be taken for granted in this innovative sector which sometimes lacks discipline, good governance, and transparency, with its emerging army of traditionally unregulated players. Policies and procedures are essential but are only a first step.

As a second step, indirect strategies may focus on creating conditions that inherently minimise the likelihood of conflicts.19 Given the nuanced nature of determining whether a particular action constitutes a conflict of interest, the exercise often demands judgment and careful evaluation on a case-by-case basis. Consequently, finely drafted policies and procedures tailored to the distinct characteristics of each CASP are likely to be more effective than overarching and industry-wide regulations. This approach recognises the diversity within the CASP sector and underscores the importance of internal vigilance within each institution as the initial line of defence against conflicts of interest.20

While MiCAR’s requirements offer comprehensive guidelines for CASPs to maintain transparency and accountability, the effectiveness hinges on dedicated resources, personnel skills, knowledge, and expertise. CASPs must allocate sufficient resources to implement, maintain, and regularly review these policies and procedures, ensuring investor protection and sound operational management. For the responsibilities assigned to the management body, the conflicts of interest policies and procedures must specify the content of the annual report submitted by the staff overseeing their implementation, maintenance, and review.21

Article 4(6) of EU 2025/1142 expands on measures which the policies, procedures, and arrangements should address. These include:

  1. Segregation of duties and supervision;
  2. Controls on information exchange;
  3. Restrictions on remuneration structures that incentivise conflicted behaviour; and
  4. Safeguards for sequential or simultaneous service provision.

These measures aim to ensure that connected persons act independently and objectively, regardless of their role or relationship with the CASP. Policies must be implemented by the CASP’s management body and supported by adequate resources. This includes assigning responsibility for monitoring and reviewing conflict management procedures. Annual reporting and ad hoc escalation of deficiencies are essential to maintaining accountability.

In order for these policies and procedures to be considered ‘effective’, it is necessary that they are designed to ensure that connected persons who are engaged in different business activities which may give rise to potential or actual conflicts of interest carry out such activities in an independent and objective manner, which is appropriate to the scale, nature, and range of crypto-asset services provided by the CASPs.22 Therefore, despite the fact that a broad range of situations, relationships, and affiliations may create potential conflicts of interest, it is essential that the circumstances to be covered in the conflict of interest policies address those situations which hinder the ability of the CASP or its connected persons to exercise their duties independently and objectively.

Lastly, apart from the proper identification of situations which may lead to conflicts of interest, the CASP should, where conflicts have been identified, take appropriate and active steps to ensure, with reasonable confidence, that the risk of damage to clients’ interests or to the interests of the CASP is prevented. Wherever this is not possible, further steps should be taken in order to appropriately mitigate the damage caused.23

Connected Persons

A key element is understanding who ‘connected persons’ are. One normally would assume that these are members of one’s family and persons in intimate relationships, partners in the same business, and the like. In laws addressing this kind of issue, there is rarely a clear definition of when a conflict arises based on identified persons or lists of positions or functions. One always has to look at the facts on both ends of the relationships, from the angle of the client whose interest is clearly paramount. On the one side we look to the service provider, intermediary, or other fiduciary, and on the other side we consider the third party outside the service provider, intermediary, or fiduciary function.

In Article 72(1), we have a list of the classes of persons who are considered to be connected persons giving rise to a conflict and hence provoking a duty to take some effective measure under the Regulation. One can consider each in some detail:

i.CASPs and their shareholders or members

A business is rarely seen as having a conflict with its own shareholders or members as these are the owners of the very business itself and make a living and profit from the carrying of the very business in a successful manner. The CASP may have different legal forms, from limited liability companies to partnerships, and even informal business associations – we are also seeing the emergence of a new form referred to as decentralised autonomous organisations – but all these have a division between management and ownership or providers of capital.

In ordinary circumstances, the management would focus on client relationships and carry out their functions through teams of staff and other resources in a diligent manner and would respect client confidentiality and the privacy of their business with the CASP. It is unlikely that the shareholders and members of the CASP would be involved in the provision of services or share in the information about clients and their transactions. Rules on privacy and confidentiality would normally prohibit this. If anyone was providing services on the basis of full information on client affairs, one would then categorise them as directors, managing partners, management or similar titles. Just like the CASP itself, they would be individually bound by the same rules on conflicts of interest we are discussing in this commentary. The conflict rules apply to CASPs and these persons in the same way. If they are not involved in management, then there is no conflict.

It would clearly be very wrong for the CASP or its officers to share information with the shareholders of the CASP so that the shareholders can benefit from inside information on transactions and so on. This is a clear conflict of interest context, and a serious breach would take place through sharing information with shareholders, but the same would apply to anyone benefitting from such a breach.

It is therefore not very clear what the item in (i) is referring to. It seems to be contemplating a situation where directors, shareholders, and members are all carrying out the same functions, which could be the case in technology start-ups, but would quickly disappear as the start-up develops into an organised legal structure, with some shareholders merely holding equity and others in management.

What sub-paragraph (a) (i) may be contemplating is a scenario which could bring about a conflict of interest among different boards of directors and shareholders (being the parent company lead by the directors) particularly in the context of international conglomerates. In such cases, the board of directors of the parent company are often able to exert influence, qua shareholders in subsidiaries, affecting local management at lower levels, even without direct control being explicitly established by the parent board executives over the activities of the subsidiary. Many parent board directors think of themselves as management, when in reality they are mere representatives of the shareholders in subsidiaries. In such cases, it is appropriate to catch ‘shareholders in the provision.

Of course, if we had to assume abuse, shareholders may also be tempted to exert pressure on the management of CASPs to pursue activities which would bring them short-term personal benefits to the detriment of the clients of the CASP. This kind of conflict is evidently to be avoided and would amount to a breach of duty on the part of the CASP if it allowed such abuse to occur. The policies normally would not address such obvious matters as shareholders not keeping to their non- management positions.

However, observation of some sharp business practices in the technology field may militate towards requiring CASPs to have clear policies guiding directors on the limits of their relations with shareholders, and shareholders on how not to behave in relation to the management functions of the CASP. Conflicts of this type arise because of failures of both sides of the coin.

ii) Any person directly or indirectly linked to the CASPs or their shareholders or members by control

This item raises a relevant issue of ‘any person who is directly or indirectly linked to the CASP’. This is the correct angle of approach as here we are now catching relevant connected persons who may benefit from a breach of standards in managing conflicts by the CASP. Although the words ‘directly or indirectly linked’ are another way of referring to connected persons, this does not answer the question of who they are. They could be the lawyers, the engineers, or the accountants of the CASP.

Are the words ‘by control’ referring to these linked persons? It is to be noted that in EU 2025/1142, there is no amplification of what is meant by the words ‘by control’. These could be functions carried out by an individual as well as offices held by individuals. They could be consents or approvals or directions vested in defined individuals, or similar situations, often considered to be ‘material actions’ within a legal organisation, which may make the holder of such powers a relevant person for conflicts due to the control that can be exercised as a result.

The second part then brings the shareholders and members back into the picture, and the reference to them suffers from the same weakness referred to above, since shareholders and members are not usually in management, they are not service providers, and are thus, not fiduciaries. They would not normally have any conflict of interest issues unless additional factors are added to their position.

There is a reference to ‘by control’, and this would be an additional factor which could be relevant but not necessarily so. When a shareholder is a majority shareholder or even the sole shareholder, their powers of control can be such that their access to information and their influence on management make them equivalent to management and thus subject to the same fiduciary rules to avoid conflicts of interest. However, this is a matter of fact. Rather, what may be suggested here, is that in the carrying out of the obligation to ‘identify, prevent, manage and disclose conflicts’, the above matters could be red flags addressed in complying with these four fundamental obligations but not necessarily rendering such shareholders equivalent to the CASP itself and subject to the same rules. The facts may show exactly the opposite of access to information flows just based on control.

The combination of the persons directly or indirectly linked to the CASP and the shareholders who have control is unfortunate and confusing as the two issues operate on different levels and in different contexts. The ‘linked’ terminology is ambiguous, and one needs to speculate as to who these could be.

Those linked to the CASP itself, if a legal entity, for example, could hardly be family members, spouses, or persons in intimate relationships, but could very well be business partners and commercial relationships of importance such that conflicts may arise and be very relevant. With regard to shareholders or members, these can be corporate or individual, and the linked persons to them can be any type. However, that again will depend on the factual context, and one must look at every case on its own merits.

This item does not say anything new and could easily have been omitted, as by its partial reference to different issues in different contexts, it does not help very much. Indeed, it could risk creating technical limitations which are inappropriate.24

iii) Members of their management body

This is the obvious group of persons in a legal organisation who have conflicts when they handle clients’ money and transactions and then seek personal gain from client information or opportunities. These persons in management are clearly fiduciaries who must forget about their own interests and promote only the interests of their clients.

Anyone connected to these persons who have all the knowledge and awareness of opportunities arising from client handling is the one who should be addressed for having direct or indirect links to the managers, and that clearly includes family, relationships, intimate or commercial, and so on.

It is odd how the linked concept is mentioned in (ii) and not here.

iv) CASP employees

This is again too generic. Of course, some employees may have access to information and client affairs, who are then caught by the conflict rules as they also qualify as fiduciaries.25 Other employees who are not in management, and who do not have access to client information and do not handle client assets or transactions are not usually considered fiduciaries and would not be in a position to have a conflict of interest since the knowledge they have or the assets they control (outside of market manipulation, which is regulated separately) are not susceptible to abuse of this kind.

This item needs further articulation for it to make sense, and of course, this can be expanded upon in the policies and procedures or EU 2025/1142. Otherwise, it will result in a lot of wasted time and resources as the policies will be applied to the wrong persons.

v) CASP clients

Given sub-paragraph (b) of Article 72(1), which addresses conflicts involving clients, this paragraph is difficult to understand as a client of the CASP cannot possibly have any role in the CASP such as to be bound by conflict of interest rules. They are not providing any service, they have no access to clients’ information, and so, have no control of other client assets and transactions. Therefore, how can they be regulated in this manner? The CASP and its management team, but not outsiders, have to be the focus of these rules. Outsiders may be subject to these rules if they are connected or linked directly or indirectly. If a client happens to be so linked, then, of course, one looks at the links and not the client relationship.

The presence of conflicts of interest can significantly impact the relationship between clients and the CASP. However, these conflicts are typically not based on the clients themselves. Rather, they arise from situations where either the CASP, its employees, or any person directly or indirectly linked to the CASP has an interest in the outcome of a service or transaction provided to the client and which is distinct from that of the client. For example, a CASP which offers advisory services, and advises clients to invest in assets in which it holds a significant stake or for which it receives incentives, will clearly have a conflict based on its own position when advising a client to invest in the same assets, but the focus here is on the CASP and not the client.

This also includes situations where the CASP may be carrying out the same business as that of the client. Consequently, this observation raises questions about the clarity of the rule outlined in Article 72(1)(v), for it appears to be addressing a very basic and general rule on conflicts covered in the Article. The paragraph appears unnecessary.

We then have Article 72(1)(b) referring to ‘two or more clients whose mutual interests conflict’. This is a clear example of a potential conflict of interest. When one acts for two clients towards whom there is a duty of care and loyalty, it can become problematic. All the rules on conflict identification, prevention, management, and disclosure must apply, and there is nothing more to state on this front. The same conflicts of interest can obviously arise when there are more than two clients, but the greater the number of clients, the less likely you are to have this problem arising, and the use of the word ‘mutual’ appears to be an attempt to close the circle of clients to which this rule will apply.

When a business deals with numerous clients, the lack of mutuality causes fiduciary duties to take on a different form. The focus shifts to acting impartially, keeping clients’ affairs and assets segregated, and ensuring all information is confidential. These more specific duties do in a way reflect the underlying goal of preventing conflicts such as those which would arise when assets are pooled. However, MiCAR does not seem to address these kinds of situations.

In the normal course of business, having many clients does not pose a problem in itself, and, unless additional factors intervene, all clients will be serviced individually without reference to the business of other clients, even if of the same nature. The rule is silent on what these additional factors are, and that is not surprising as they can be many and very diverse. It is left to the normal intelligence and integrity of the CASP to handle things properly to address these possibilities at all levels.

Although clients are serviced individually, there is the possibility of a CASP, its employees, or any person directly or indirectly linked to it, having a financial or other incentive, which may either be personal or in favour of the firm as a whole, or even a third party who may be connected or to whom there exists a high level of loyalty, to favour the interests of a specific client over the interests of another. This may include the following instances by way of example:

  • where a CASP, its employees, or any person directly or indirectly linked to the CASP engages in manipulative market practice by executing transactions based on insider information to the determinant of certain clients and to the benefit of others
  • where there is a financial or other incentive, which may either be personal to the employees or any person directly or indirectly linked to the CASP, or in favour of the CASP as a whole to favour the interests of a specific client over the interests of another
  • accepting or being induced to accept gifts to offer certain clients more benefits on the platform, such as faster execution times or protections from close-outs; and where the CASP provides preferential treatment and prioritises more important clients or clients who generate higher fees.
  • where the CASP shares more in-depth research to a number of clients and withholds it from others, influencing trading decisions in a manner, which benefits only certain clients.

3. Proportionality

Article 72(1) of MiCAR introduces a principle of proportionality, requiring CASPs to tailor their conflict of interest policies to the scale, nature, and range of services they provide. This is particularly relevant given the diversity of CASPs, which included small start-ups to large multinational entities. While smaller CASPs may not be expected to implement complex compliance frameworks, they are nonetheless required to address the substance of the obligation. ESMA’s Consultation Paper clarifies that proportionality should not be interpreted as a licence for smaller CASPs to ignore conflict management. Regardless of size or service complexity, all CASPs must identify, prevent, manage, and disclose conflicts of interest.26

The proportionality principle ensures that measures adopted are suitable and necessary, striking a balance between the complexity of services offered and the robustness of conflict mitigation strategies. This approach promotes regulatory compliance without stifling innovation, ensuring that all CASPs uphold fiduciary standards and protect client interests.

4. Disclosure

MiCAR places significant emphasis on transparency through disclosure, recognising it as a key mechanism for managing conflicts of interest. Under Article 72(2), CASPs must prominently publish on their website the general nature and sources of conflicts of interest, together with the steps taken to mitigate them. This obligation extends beyond mere formality. It is intended to empower clients by clarifying the CASP’s role, potential risks, and the measures in place to safeguard their needs.

The inclusion of the term ‘mitigate’ in Article 72(2) is notable. It acknowledges that while certain conflicts may not be entirely preventable, they must be managed in a way that reduces potential harm. This concept complements the broader obligations of identification, prevention, and management outlined in Article 72(1). However, it raises important questions: Should disclosure cover both actual and potential conflicts? Is it sufficient to disclose general policies, or must specific situations be outlined? And does website publication equate to client awareness?

These considerations highlight the need for disclosures to be sufficiently detailed and specific, particularly given that CASPs often operate in vertically integrated structures or in close cooperation with affiliated entities. Clients must clearly understand the capacity in which the CASP acts and the situations which may give rise to conflicts.27 The proactive disclosure of a firm’s policies and procedures for handling conflicts of interest can act as a preventive measure. Ensuring that clients are familiar with these practices can help avert potential breaches of fiduciary duty as clients are presumed to be aware of the terms of the document or part of the website that outlines such factors.

Article 72(2) MiCAR requires that such disclosure shall take place in a prominent place on their website. Article 7(3) of EU 2025/1142 reinforces this by requiring disclosures to be easily accessible at all times and across all devices, with a prominent link on the CASP’s website. While this enhances transparency, it may impose a disproportionate burden on smaller and medium-sized CASPs. To be noted is the fact that stating the policies on the website of the CASP is considered to be enough and this is natural given the digital context of this business and the assets involved.

Moreover, it is a methodology which carries its own risks because the materials are more difficult to read, length can be a deterrent as we see in physical paper contexts, the texts can easily be changed with little trace and retention of evidence of earlier texts to be referred to after long periods of time may have elapsed, digital translations may not be accurate, and so on. The website methodology should be subject to its own focus, not only from a conflict-of-interest angle.

Ultimately, disclosure is a multifaceted tool for effectively managing conflicts of interest in financial contexts.28 When clients are aware of potential or actual conflicts, they can respond appropriately, whether by declining, seeking independent advice, demanding further information, or negotiating contractual assurances. For this reason, Article 72(2) requires CASPs to disclose not only the general nature and sources of conflicts but also the crypto-asset services, activities, or situations that may give rise to them, the associated risks, and the measures adopted to mitigate them.29

5. Mode of Disclosure

Building on the substantive obligations in Article 72(2), Article 72(3) specifies the manner in which disclosures must be made. They are required to be in electronic format and include sufficient detail, taking into account the nature of each client, to enable informed decision-making. CASPs must also indicate the capacity and role in which they act when providing a crypto-asset service.

However, it is important to note that the manner in which conflicts of interest are disclosed may vary depending on the specific circumstances, relationships, or affiliations involved. Therefore, it may be necessary to cover other types of specific circumstances, relationships, or affiliations. Overall, while the current requirements for disclosing conflicts of interest by CASP are a step in the right direction, there may be room for improvement to ensure that clients are fully informed and protected.

The concept of a ‘durable medium’ is particularly relevant here.30 While neither MiCAR nor ESMA define this term, Article 4(1)(62) MiFID II defines a durable medium as any instrument that allows clients to store information for future reference over an adequate period and reproduce it unchanged. This ensures that disclosures remain accessible and verifiable, which is crucial for investor protection.

Further, EU 2025/1142 requires disclosures to be available in all languages used for marketing or client communication, and to be continuously updated.

Despite there being no requirement for these disclosures to be personalised, to allow for each individual client to be able to make an informed decision, the disclosures provided must be consistently and constantly accurate. To ensure appropriate investor protection, it is also essential that clients have access to the disclosures referred to in Article 72(2) of MiCAR in a language with which they are familiar.31

6. Identifying and Avoiding Conflicts of Interest

MiCAR’s approach to conflict management is rooted in proactive identification and avoidance. While disclosure is important, it is not a substitute for robust internal arrangements. Drawing from MiFID II, MiCAR emphasises that CASPs must take all appropriate steps to prevent conflicts from adversely affecting client interests. Organisational and administrative arrangements are the first line of defence. These include internal controls, segregation of duties, and clear reporting lines. If these arrangements are deemed insufficient, disclosure becomes necessary, but only as a secondary measure.

Contrary to MiFID II, MiCAR does not position disclosure as a measure of last resort nor as an alternative to the obligation of having effective policies and procedures for identifying, managing, and preventing conflicts of interest. Instead, disclosure of conflicts of interest is an additional obligation imposed on CASPs under MiCAR. This may be provoked by the context existing around CASPs and crypto-assets, where clients either have less understanding of the operations, less access to useful information, or are subject to multiple distractions due to the complex structures used in these types of businesses, which may involve multiple jurisdictions, absence of transparent legal organisations and systems, and so on.

The Securities and Markets Stakeholder Group (SMSG) supported the clarification from ESMA that conflicts of interest should be either prevented or managed, and the disclosure requirements should not serve as an alternative to the prevention or management of conflicts of interest. The SMSG also believes that conflicts of interest should preferably be prevented, and managed only if prevention is not possible.32

For clients or potential clients to make informed decisions, it is essential that the disclosure of conflicts of interest includes a detailed and clear description of the services and activities conducted by the CASP that may lead to conflicts of interest. Furthermore, it is necessary to disclose the nature and associated risks identified in relation to these conflicts of interest. Article 72(2) MiCAR explicitly outlines that the steps and measures taken to prevent or mitigate the identified conflicts of interest must be provided, ensuring that no residual risks persist.33 This comprehensive disclosure approach enhances transparency and empowers stakeholders to assess potential implications fully.

If we take the traditional financial services industry practices as an example, what we will probably see is the development of fairly standard statements catching all potential conflicts, which will become boilerplate statements appearing on the websites of all CASPSs with little attention to actual context. This is, of course, dangerous, and that is why it is so important to place disclosure in the correct order of priority. Disclosure helps but is not enough. The focus is correctly on mitigation, if not total prevention and avoidance.

7. Assessment and Review of Policies and Procedures

Article 72(4) MiCAR requires CASPs to assess and review their conflict of interest policies at least annually, taking appropriate measures to address any deficiencies. This obligation ensures that conflict management remains dynamic and responsive to evolving risks. Effective implementation demands that CASPs allocate adequate resources to monitor and review these policies. While MiCAR does not define ‘appropriate measures’, the expectation is clear. Personnel must possess the necessary skills, knowledge, and expertise to carry out this function competently. The review process is typically led by compliance and internal audit teams, with findings reported to senior management.

Article 68(6) MiCAR further mandates that the management body periodically review the effectiveness of governance arrangements, including conflict of interest policies. This creates a feedback loop where oversight and accountability are embedded into the CASP’s operational framework. Ultimately, the review process is not a box-ticking exercise. It is a substantive obligation that ensures CASPs remain vigilant and proactive in safeguarding client interests. Regular assessment, supported by skilled personnel and clear reporting structures, is essential to maintaining integrity and trust in the crypto-asset sector.

8. Placing of Crypto-Assets: A Context for Greater Focus

Article 79 MiCAR, which governs the placing of crypto-assets, explicitly cross-refers to Article 72(1), reinforcing the need for CASPs to implement robust conflict of interest procedures when engaging in placement activities. This is particularly relevant when CASPs act on behalf of offerors and may influence pricing or receive incentives, monetary or otherwise, that could compromise objectivity. CASPs must ensure that their conflict of interest policies are tailored to the specific services they provide. MiCAR requires that these policies address risks arising from overestimated or underestimated pricing and from incentives granted by offerors. Here, transparency is key, and CASPs must disclose to offerors or their agents, prior to any agreement, the nature of the placement, whether a minimum purchase is guaranteed, transaction fees, timing, process, pricing, and targeted purchasers.

9. Remuneration Policies

Remuneration policies are a critical component of conflict of interest management under MiCAR. Although MiCAR does not explicitly regulate remuneration practices, Article 5 of EU 2025/1142 mandates that such arrangements must not incentivise behaviour which is detrimental to clients. Remuneration must not compromise objectivity or independence and applies to employees, management, and outsourced personnel. EU 2015/1142 defines remuneration broadly, encompassing both financial and non-financial benefits. These policies must ensure that remuneration does not encourage staff to favour their own interests or those of the CASP over client interests. This principle mirrors MiFID II, which prohibits remuneration structures that incentivise the sale of unsuitable products. For instance, this includes remuneration or sales targets that create incentives to recommend or sell a particular financial instrument when a different product would better serve the client’s needs.34

In accordance with the above, it is necessary that the policies, procedures, and arrangements on conflicts of interest address the removal of any direct link between the remuneration provided to the CASP’s employees, delegatees, outsourcees, sub-contractors, or members of the management body principally engaged in one activity and the remuneration of, or revenues generated by, different employees, delegatees, outsourcees, sub-contractors, or members of the management body of the CASP principally engaged in another activity, where a conflict of interest may arise in relation to those activities.35

In order to avoid a situation which encourages employees, members of the management body, or natural persons directly involved in the provisions of services, to act against the interest of any of the CASP’s clients or impair their ability to fulfil their duties and responsibilities in an objective and independent manner, it is recommended that remuneration and similar incentives not be solely or predominantly based on quantitative commercial criteria, but also take into account appropriate qualitative criteria. The above will ultimately reflect the fair treatment of clients and the quality of services provided to clients.36 Disclosure stands as a vital mechanism for effectively managing conflicts of interest.

10. Conclusion

Article 72 MiCAR establishes a comprehensive framework for the identification, prevention, management, and disclosure of conflicts of interest within the crypto-asset services sector. By drawing from established principles under MiFID II and adapting them to the unique characteristics of crypto assets, MiCAR ensures that CASPs operate with transparency, integrity, and accountability.

MiCAR recognises the fiduciary nature of CASPs and imposes obligations that go beyond mere procedural compliance. It demands a culture of ethical conduct, supported by robust internal policies, clear disclosure practices, and ongoing oversight. The layered approach, which combines primary legislation with detailed technical standards, reflects the EU’s commitment to safeguarding client interests and promoting market integrity.

As the crypto-asset landscape continues to evolve, the principles enshrined in Article 72 will serve as a foundation for responsible provision of services. CASPs must not only understand their obligations but also internalise them, ensuring that conflicts of interest are addressed proactively and transparently. In doing so, they contribute to the development of a trustworthy and resilient financial ecosystem.

Disclaimer: Ganado Advocates is responsible for contributing to this article but was not in any way involved as legal advisor for the parties discussed herein. This article was first published in ‘ID-Dritt’ in 2026.


1 Regulation (EU) 2023/1114 on markets in crypto-assets [2023] OJ L 150/40.
2 Directive 2014/65/EU of the European Parliament and of the Council of 15 May 2014 on markets in financial instruments and amending Directive 2002/92/EC and Directive 2011/61/EU, OJ L173/349.
3 Civil Code, Chapter 16 of the Laws of Malta, Article 1124A.
4 Joan Boatright, ‘Conflicts of Interest in Financial Services’(2000) 105(2) Business and Society Review 201.
5 Dechert LLP, ‘MiFID II: Conflicts of Interest’ (2017) <https://www.dechert.com/content/dam/dechert%20files/knowledge/hot-topics/mifid- ii/MiFID%20II%20-%20Conflicts%20of%20interest.pdf> accessed 6 November 2025.
6 MiFID II (n 2) Recital 79.
7 ibid Recital 56.
8 ibid.
9 Commission Delegated Regulation (EU) 2017/565 of 25 April 2016 supplementing Directive 2014/65/EU of the European Parliament and of the Council as regards organisational requirements and operating conditions for investment firms and defined terms for the purposes of that Directive [2017] OJ L87/1, Article 33.
10 European Securities and Markets Authority, ‘Consultation Paper: Technical Standards Specifying Certain Requirements of the Markets in Crypto-Assets Regulation (MiCAR)’ (ESMA74449133380-425, 2023).
11 European Securities and Markets Authority, ‘Final Report, Draft Technical Standards Specifying Certain Requirements in Relation to Conflicts of Interest for Crypto-Asset Service Providers under the Markets in Crypto Assets Regulation (MiCA)’ (2024).
12 Commission Delegated Regulation (EU) 2025/1142 of 27 February 2025 supplementing Regulation (EU) 2023/1114 of the European Parliament and of the Council with regard to regulatory technical standards specifying the requirements for policies and procedures on conflicts of interest for crypto-asset service providers and the details and methodology for the content of disclosures on conflicts of interest [2025] OJ L 1142/1.
13 ESMA ‘Consultation Paper’ (n 10).
14 Committee of European Securities Regulators, ‘MiFID Supervisory Briefings: Conflicts of Interest’ <https://www.handbook.fca.org.uk/L3G/MIFID/08_733.pdf> accessed 6 November 2025.
15 Joan Boatright (n 4).
16 CFA Society United Kingdom, ‘Position Paper: Conflicts of Interest’ (2013) < https://www.cfauk.org/-/media/files/pdf/pdf/5-professionalism/3- research-and-position-papers/conflicts-of-interest.pdf> accessed 6 November 2025.
17 ESMA ‘Consultation Paper’ (n 10).
18 Joan Boatright (n 4).
19 ibid.
20 ibid.
21 ESMA ‘Consultation Paper’ (n 10).
22 Commission Delegated Regulation (EU) 2025/1142 (n 12).
23 ibid.
24 It is obviously too late to address this in MiCAR itself, and it may be appropriate to amplify the intent on such terminology and its scope in Commission Delegated Regulation 2025/1142 (n 12).
25 Article 1124A (2) of the Civil Code, Chapter 16 of the Laws of Malta, states that ‘A person who is delegated any function by a fiduciary and is aware, or should, from the circumstances, be aware, of the fiduciary obligations shall also be treated to be subject to fiduciary obligations.’ Employees with certain knowledge would fall within this rule.
26 ESMA ‘Consultation Paper’ (n 10).
27 ibid.
28 Joan Boatright (n 4).
29 ESMA ‘Consultation Paper’ (n 10).
30 Directive 2014/65/EU (n 2) Article 23(3).
31 ESMA ‘Consultation Paper’ (n 10) para 119.
32 European Securities and Markets Authority, Securities and Markets Stakeholder Group, ‘Advice to ESMA: SMSG advice to ESMA on its Consultation Paper on Technical Standards specifying certain requirements of the Markets in crypto-assets Regulation (MiCAR)’ (ESMA24 2292447894580, 2023) <https://www.esma.europa.eu/sites/default/files/2023-10/ESMA24-229244789-4595_SMSG_Advice_on_MiCAR_package1.pdf> accessed 6 November 2025.
33 Commission Delegated Regulation 2025/1142 (n 12).
34 Directive 2014/65/EU (n 2) Recital 77.
35 ESMA ‘Consultation Paper’ (n 10).
36 ibid.

Share

Go Back
01
image

How can we assist?

Contact us