TL;DR: The European Banking Authority has outlined a draft method for calculating MiCA fines, with penalties for significant ART issuers capped at 12.5% of annual turnover and significant EMT issuers at 10%, according to SumSub. That enforcement posture turns regulatory passporting, disclosures, and organisational controls into immediate governance priorities rather than back-office compliance tasks.
Editorial analysis by NHI Mgmt Group, based on content published by SumSub: “EU Watchdog EBA Outlines Fines Under MiCA Enforcement Framework”.
Key questions
Q: What fails when MiCA compliance is treated as paperwork instead of an operational control?
A: What fails is the evidence chain.
Q: Why does the EBA’s MiCA fines framework raise accountability risk for management bodies?
A: Because the draft proposal explicitly covers management body members when an infringement is intentional or negligent.
Q: What should crypto compliance teams review before MiCA passporting deadlines?
A: They should review whether disclosures, organisational controls, and supervisory records are ready to withstand enforcement scrutiny.
Practitioner guidance
- Map MiCA obligations to accountable owners Document which senior leaders own passporting, disclosure, and issuer compliance decisions so regulatory failures cannot be treated as anonymous process drift.
- Build evidence for enforcement factors Retain records that show seriousness, duration, intent, negligence, and remediation timing so the organisation can explain control performance under a penalty review.
- Test organisational readiness before deadlines Run readiness checks for disclosure quality, supervisory reporting, and operating conditions that could trigger halts or sanctions if the regulator reviews them now.
Bottom line: The EBA’s draft MiCA fines framework turns compliance failures into measurable enforcement outcomes for significant ART and EMT issuers.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
MiCA enforcement is becoming a governance measurement problem, not a policy exercise. Once fines are calculated through seriousness, duration, intent, and mitigating factors, firms must prove how controls behaved over time, not merely that controls existed. That shifts compliance evidence into the same operational discipline as identity governance and audit readiness. Practitioners should assume the regulator will judge the story their controls tell, not only the policy they point to.
A question worth separating out:
Q: What is the difference between a MiCA disclosure failure and an organisational failure?
A: A disclosure failure is a specific compliance lapse, while an organisational failure shows the control environment itself is weak. Under the draft EBA approach, both can influence the penalty outcome because the regulator is assessing not only the breach, but how governance failed around it.
👉 Read our full editorial: EBA MiCA fines framework raises the stakes for crypto compliance