Digital Assets

The CBI's 2026 CASP supervisory programme: what authorised firms need to do now

The Central Bank's 2026 Outlook contains a dedicated CASP chapter for the first time. Ten CASPs were authorised in 2025; the 2026 programme is about finding out how well they work. AML/CFT rated amber/red, custody conditions to be followed up, targeted DORA work, and a warning that supervisors read your website too.

Finvisor analysis of the Central Bank of Ireland 2026 CASP supervisory programme under MiCAR

Finvisor Fintech Partners, April 2026. This article accompanies our five-page briefing, MiCAR and CBI RSO 2026: Crypto-Asset Service Providers.

The Central Bank of Ireland's Regulatory and Supervisory Outlook 2026, published on 26 February, contains a dedicated CASP chapter for the first time. The message is direct: the Central Bank has moved from granting licences to conducting real supervision. Ten CASPs were authorised in 2025. The 2026 programme is about finding out how well they actually work.

Six supervisory focus areas define where attention will fall this year: operational and cyber resilience, treatment of customers, custody of crypto-assets, financial integrity (AML/CFT), market abuse and surveillance, and conflicts of interest and governance. All six run across H1 and H2. None are aspirational, and several have concrete deadlines attached.

Three areas carry the highest immediate risk

AML/CFT. The Central Bank has rated the sector's financial crime risk amber/red. An enhanced REQ submission is due covering quantitative and qualitative ML/TF risk data, and on-site AML inspections of selected CASPs are planned for H2. Firms that have not updated their business-wide risk assessment to reflect the rating, or whose transaction monitoring is not calibrated to their actual exposure, will not be ready.

Custody. Where authorisation conditions were applied for custody deficiencies, the Central Bank will follow up in H2 2026. Firms subject to such conditions should already have remediation documented and available for inspection. The Central Bank will expect evidence of action, not intent.

DORA. Targeted DORA compliance work is planned for CASPs in line with individual authorisation conditions. Private key security, ICT incident classification and Registers of Information are all in scope, and ESMA is running a Common Supervisory Action on cyber risk across the sector at the same time.

Active surveillance: the Central Bank will find things you have not told them

Supervisors review publicly accessible information as a matter of course. Your website, app store listing, marketing materials and social media are all within scope, and in some cases supervisors engage with a firm's onboarding journey directly. MiCAR imposes detailed disclosure requirements covering whitepaper content, fees, risks, complaint procedures and the terms under which crypto-assets are held, and the Consumer Protection Code 2025 sits alongside them. If your website does not reflect your authorisation conditions, your whitepaper disclosures are incomplete, or your marketing would not withstand scrutiny under CPC 2025, that risk is visible to your supervisor today.

PCF changes: tell your supervisor before they find out elsewhere

The crypto industry has seen significant hiring activity over the last twelve months, and with it churn at senior and regulated levels. That is normal. What is not acceptable is allowing your supervisor to learn about a PCF departure from LinkedIn. The Central Bank expects prompt notification of departures, role changes and new appointments. In an environment where it is actively building its supervisory picture of each CASP, undisclosed PCF changes create exactly the kind of governance concern that leads to escalation.

The CASP REQ and CARF: the data burden is arriving together

The new quarterly CASP regulatory return is live and the enhanced REQ requires ML/TF risk data at a granularity many CASPs' infrastructure was not built to produce: transaction volumes, exposure by asset class, customer risk distribution and geographic flows. At the same time the OECD's Crypto-Asset Reporting Framework is moving from policy to obligation, with significant overlap in the data sets. Firms that have not mapped their reporting obligations across the REQ and CARF should do so now; the data architecture decisions made today determine whether these obligations are met efficiently or expensively.

The Central Bank has also signalled that firms must engage it before launching new services, including copy trading and automated portfolio management. Material changes require pre-approval engagement, and firms planning service expansion in 2026 should build that into their timelines.

For authorised CASPs, the 2026 compliance monitoring plan should be mapped explicitly to the six focus areas. Gaps in custody documentation, AML infrastructure, PCF governance and DORA implementation are the areas most likely to produce supervisory friction in the next twelve months.

Request the full briefing from the Regulatory Briefings page, or see how Finvisor supports crypto-asset service providers.

Share this post