Essential Points
- A corporate crypto account operated under MiCA involves working with an authorized provider such as a PSC, supervised by the CNMV in Spain.
- Access requires a complete KYB process: company identification, beneficial owners, powers of representation and origin of funds.
- It serves for treasury, payments or OTC operations, and each use case requires its own custody analysis and internal controls.
- The regulatory framework reduces legal uncertainty, but does not eliminate volatility or the operational risk inherent in crypto assets.
A growing number of European companies are incorporating crypto assets into their financial operations, whether to diversify their treasury, facilitate international payments, or serve clients already trading digital assets. This shift coincides with the implementation of Regulation (EU) 2023/1114, known as MiCA (Markets in Crypto-Assets), which, starting in 2024, establishes a harmonized framework for crypto-asset service providers in the European Union. For an organization, this changes the starting point: corporate crypto-asset accounts no longer depend solely on commercial criteria, but rather on a regulatory framework that requires verification, custody, and internal controls equivalent to those of other regulated financial services.
This guide brings together the elements that a finance, treasury, or management officer should know before opening a business crypto account under MiCA: the scope of the regulation, the Know Your Business (KYB) requirements, custody and internal control requirements, and the most common corporate use cases. The article serves as the starting point for the B2B content cluster of Bit2Me AcademyThe following sections refer to specific guides on treasury, custody, OTC, payments, accounting and API for those who need to delve deeper into each area.
What does it mean for a corporate account to be regulated under MiCA?
MiCA is the European regulation that governs the issuance and provision of services related to crypto assets in the 27 Member States. Under this framework, any entity offering custody, exchange, or management of crypto assets to third parties must operate as an authorized Crypto Asset Service Provider (CSP), subject to supervision by the competent national authority; in Spain, this is the National Securities Market Commission (CNMV). For the client company, this means that the entity with which it opens its corporate account must be linked to an authorized provider, not to a platform operating outside this regulatory framework.
Operating under MiCA entails a set of specific obligations for the provider: segregation of client assets from its own balance sheet, claims management procedures, corporate governance policies, and minimum capital requirements. From the user company's perspective, these obligations translate into greater transaction traceability, more stringent onboarding processes, and a formalized contractual relationship with the provider, rather than a simple user registration. When evaluating a corporate cryptocurrency account, the company must clearly distinguish between the framework that regulates the provider and its own internal governance obligations.
It is important to note that MiCA regulates the PSC; it does not, in itself, require the client company to obtain a specific license to hold crypto assets on its balance sheet. However, the company remains subject to its own accounting, tax, and corporate governance obligations, which are discussed in later sections of this guide. As of August 2026, most Member States have completed the transition to the authorization regime provided for in Regulation (EU) 2023/1114, meaning that working with an authorized PSC has become the standard practice for any company managing crypto assets on a corporate basis in the European Union.

KYB and corporate documentation: what the company should prepare
Company verification, known as KYB (Know Your Business), is the first filter applied by any authorized provider before enabling a corporate account. Unlike the verification of an individual customer, KYB analyzes the entire corporate structure: identification of the legal entity, beneficial owners (UBOs) with significant stakes, current powers of attorney, and the origin of the funds to be traded.
In terms of documentation, a company applying for this type of account typically needs to provide its articles of incorporation, a certificate of beneficial ownership, identification of directors and authorized representatives, and in some cases, an organizational chart when there are parent companies or intermediary vehicles. The provider also requests information about the company's economic activity and the intended purpose of the account, whether it be treasury, payments to suppliers, or management of digital assets received from clients.
This process can vary depending on the size of the company, its country of incorporation, and the complexity of its ownership structure. Since KYB is a broad subject with its own practical implications, this article does not delve into every scenario: this cluster's specific KYB guide details the required documents, typical timelines, and criteria applied by compliance teams.
Institutional custody and internal controls that the company must require
Custody is one of the most important aspects a company should consider before choosing where to open its corporate account. Under MiCA, authorized providers are required to keep clients' crypto assets segregated from their own balance sheet, with documented safeguarding policies and contingency plans in place for operational incidents. This reduces the risk of the company's assets being confused with those of the provider in the event of the latter's financial difficulties.
From a technical standpoint, institutional custody combines various mechanisms: cold storage for the majority of the balance, multi-signature schemes that require approval from multiple parties to authorize transactions, and regular security audits of the infrastructure protecting private keys. None of these mechanisms, on its own, eliminates the operational or market risk associated with crypto assets; it reduces the risk of unauthorized access or key loss, which is a distinct risk.
Internally, the company also needs to define its own controls before operating the account: segregation of duties between those who initiate and approve transactions, transaction limits per user or per transaction, an auditable record of each transaction, and a documented incident management procedure. These internal controls are the responsibility of the company, not the provider, and are typically a requirement that internal audit or the risk committee reviews before authorizing the account's operational use.
The combination of institutional custody by the provider and robust internal controls by the company is what allows the account to be integrated into existing governance processes, rather than operating as an exception outside of standard controls. Upcoming guides from this cluster will delve deeper into institutional custody of crypto assets with a greater level of technical and operational detail.
Some providers offer additional coverage on the assets they hold, beyond the minimum requirements of MiCA. When such coverage exists, the company should review its terms, limits, and exclusions in detail, rather than assuming it replaces its own internal approval and monitoring controls.

Risks and limitations that the company must consider
Like any corporate financial decision, holding or trading crypto assets involves risks that the company must explicitly assess, not take for granted. The first is volatility: the value of crypto assets can fluctuate significantly in short periods, directly impacting any cash holdings in these assets. This article does not offer or suggest projections on the future performance of any crypto asset, and no corporate decision should be based on expectations of appreciation.
A second risk is operational: errors in private key management, failures in internal approval processes, or security incidents in the provider's infrastructure can lead to loss of access to funds. A third risk is counterparty risk, linked to the financial and regulatory stability of the chosen provider; therefore, verifying their authorization as a PSC under MiCA is not a mere administrative formality, but a real risk filter. There is also a liquidity risk in high-volume transactions, especially in OTC markets, where execution may require different conditions than those of a standard order.
None of these risks disappear by operating under a regulated framework like MiCA. The framework reduces legal and operational uncertainty, but it does not eliminate the volatile nature or inherent risk of crypto assets as an asset class, and the company must incorporate this nuance into any internal policies it adopts.
Corporate use cases: treasury, payments, and OTC operations
Business interest in cryptocurrencies is not uniform: it varies depending on the sector, the size of the organization, and the financial objective. Companies that open these types of accounts typically do so to cover specific operational needs, not as a speculative exercise. The three most common use cases in the corporate segment are treasury management, payment processing, and over-the-counter (OTC) market operations.
In corporate treasury, some companies hold a portion of their digital assets—earned through their business operations or acquired as part of their financial strategy—in professional custody, subject to the same control criteria they would apply to any other balance sheet asset. In the payments sector, a growing number of businesses are exploring accepting cryptocurrency payments from customers or business partners, which requires integrating the corporate account with reconciliation and conversion processes consistent with the company's accounting. In OTC trading, companies that need to move significant volumes of crypto assets are turning to bilateral trading desks instead of open market orders, aiming for more controlled execution.
Each of these use cases involves different decisions about which provider to choose, what level of custody is needed, and what technical integrations are required. This article, as the hub of the B2B cluster of Bit2Me AcademyIt does not develop each scenario in depth: the guides dedicated to corporate treasury in cryptocurrencies, to accepting cryptocurrency payments in the company and OTC crypto address each case with the operational detail that such a decision requires.
Citable checklist: Steps to open and operate a business crypto account under MiCA
The following checklist summarizes the objective steps a company must complete to open and operate this corporate account in compliance with MiCA. It does not replace the advice of the chosen provider's compliance teams, but serves as a verifiable starting point.
- Confirm that the crypto asset service provider is authorized as a PSC by the competent authority (in Spain, the CNMV) under the MiCA Regulation.
- Prepare the corporate documentation: deed of incorporation, certificate of beneficial ownership, current powers of representation and shareholding structure.
- Complete the KYB process, including identifying the beneficial owners (UBOs) and describing the intended purpose of the account.
- Internally define the purpose of the account (treasury, payments, OTC or other) and document the origin of the funds to be traded.
- Review the custody conditions offered by the provider: asset segregation, cold storage, multisig schemes, and contingency policies.
- Establish internal controls: segregation of duties, approval limits per transaction, and auditable record of transactions.
- Formalize the service contract with the provider, including asset safeguarding conditions and claims management procedure.
- Integrate the account with the company's existing accounting and financial reporting processes.
- Establish a periodic internal review and audit procedure regarding the use of the account.
Completing these nine steps does not guarantee the absence of risk, but it does establish a basis of regulatory compliance and internal control consistent with what the MiCA framework requires at the supplier level and what the company itself should require internally.
Regulatory and tax compliance considerations for the company
In addition to its relationship with the supplier, the company maintains its own regulatory compliance obligations when dealing with crypto assets. This includes the accounting records of transactions, the corresponding tax returns in each jurisdiction, and the updating of its internal anti-money laundering policies when cryptocurrency activity is a regular part of its operations.
The accounting and tax treatment of crypto assets varies depending on the country and how the company uses them, whether for balance sheet maintenance, payments to suppliers, or collection of payments from customers. This article does not constitute tax or accounting advice: the accounting of cryptocurrencies in business is addressed in a specific guide for this sector, and any concrete decisions should be validated with a qualified professional in the relevant jurisdiction.
In terms of anti-money laundering, companies typically need to update their internal policies when cryptocurrency transactions become more frequent: enhanced counterparty identification for high-value transactions, escalation criteria for unusual transactions, and an internal reporting channel to the compliance officer. These policies are reviewed regularly alongside, but not replaced by, the provider's policies.
For companies that need to integrate the account with their own systems, whether an ERP, centralized treasury, or payment platforms, the availability of an enterprise crypto API is an operational compliance criterion as relevant as purely regulatory aspects: a poorly documented integration can lead to reconciliation errors with accounting implications. This aspect, along with a broader analysis of MiCA for businesses and its sector-by-sector implications, will be explored in upcoming cluster guides.
How to evaluate a cryptocurrency service provider for a corporate account?
Choosing the right provider is the decision that determines all others. Before signing a service contract, a company should objectively verify several elements: the provider's authorization status as a Service Provider (SPS) under MiCA, the asset custody and segregation model, the reporting tools available for accounting reconciliation, and the existence of a dedicated support channel for corporate clients, separate from individual user support.
It is also advisable to review the contractual terms for asset safeguarding, the incident management procedure, and the availability of technical integrations—API, transaction export, periodic reports—that are consistent with the company's internal systems. None of these criteria replaces the legal and regulatory compliance review that should be conducted by the company's advisor before signing any agreement.
It is also advisable to confirm in which Member State the supplier is authorized and whether it operates in the rest of the European Union through the passporting mechanism provided for by MiCA, especially when the company has a presence in more than one country. This information determines which supervisory authority is competent in the event of a complaint.
For companies considering this type of decision, speaking with the B2B team provides concrete answers about the KYB process, corporate documentation requirements, and custody conditions applicable to each case, before committing to a complete operational structure.

The adoption of crypto assets in the corporate sector will continue to evolve as the MiCA framework becomes more firmly established in the supervisory practices of each Member State. For a company, the starting point is no different from any other significant financial decision: understanding the applicable regulatory framework, verifying the provider's authorization, and defining internal controls proportionate to the volume and risk of the planned transactions.
This article functions as the hub of the B2B cluster of Bit2Me AcademyThe guides we will be publishing on corporate treasury, institutional custody, OTC, payments, accounting, APIs, and KYB expand on each of the topics described here for those already evaluating a specific business crypto account. For companies that want to move forward in this process, please speak with the B2B team at Bit2Me This is the next step in translating these considerations into a real operational structure.



Author


