MiCA

    How Safeheld Helps Crypto Custodians Meet MiCA Safeguarding Requirements

    How crypto-asset custodians are using Safeheld to automate MiCA Article 70 compliance: wallet reconciliation, asset segregation verification, and continuous reporting.

    11 min read March 2026

    In short

    Meeting MiCA as a custodian means proving continuously that controlled wallet and venue balances match client entitlement in the register, that segregation holds after every movement, and that the historic record cannot have been altered. Safeheld reconciles those references continuously and seals each run for independent verification.

    The custody reconciliation problem in digital assets

    For the wider MiCA framework and authorisation timeline, see What is MiCA? The Complete Guide to EU Crypto-Asset Regulation. A crypto custodian holds assets across cold storage, hot wallets, exchange sub-accounts, staking contracts and, increasingly, tokenised instruments on multiple chains. Client entitlement is recorded in an internal ledger that is entirely separate from any of those environments.

    The gap between entitlement and control is where custody failures live. Assets can be present and correctly totalled while individual entitlement is wrong. Assets can be entitled correctly while a portion is unavailable because it is locked in a delegation with an unbonding period.

    Traditional finance reconciliation assumes a small number of authoritative counterparties producing periodic statements. Digital asset custody has a large number of heterogeneous sources producing continuous, differently formatted data.

    The result is that reconciliation cannot be a nightly batch against a statement. It has to be a continuous process against live sources, with a model of expected settlement behaviour per chain and venue.

    Ingesting chain, venue and ledger data without bespoke builds

    Custodians typically hold data in at least four shapes: on-chain balances and transfers, exchange and venue API responses, internal ledger extracts and treasury or operations spreadsheets that have never been decommissioned.

    Safeheld ingests these in the formats they already exist in, with automated schema mapping handling unfamiliar layouts. Adding a chain, venue or custodial partner does not require a data engineering project before reconciliation resumes.

    Absent data is treated as an exception. A venue feed that normally reports hourly and has stopped raises an alert rather than silently reducing the population being reconciled.

    This matters because the most dangerous reconciliation is one that balances against an incomplete data set and reports a clean result.

    Three-way reconciliation across entitlement, control and movement

    Safeheld reconciles the internal entitlement ledger, the balances actually controlled across wallets and venues, and the transaction population that connects them. Three independent references are required because any two can agree while being jointly wrong.

    The most common example is a fee or spread calculation applied incorrectly at the point of execution. The ledger and the wallet agree because both derive from the same erroneous posting. Only the underlying transaction population reveals the divergence.

    The same structure supports segregation testing. Proprietary inventory and client assets sharing an address is detected by proving the split after every movement rather than by policy assertion.

    Where structures are more complex, with sub-custodians or multiple pooled layers, reconciliation extends to as many independent records as the structure contains rather than collapsing to a two-way check.

    Autonomous investigation of digital asset breaks

    The residual break population in crypto custody is dominated by timing, representation and convention differences rather than by errors. Items in flight across a bridge, pending finality, differing decimal conventions and venue-specific balance definitions all generate apparent variances that are not variances.

    Safeheld investigates each item before a person sees it, assembling the supporting records, forming an explanation and attaching the reasoning to the break. Items that cannot be resolved with sufficient confidence are routed to a named reviewer with the evidence already gathered.

    This preserves attention for the genuine cases. A team that reviews every timing artefact manually will eventually stop reading them carefully, and the one real break will pass through with the rest.

    Because the reasoning is retained, a resolved exception is an evidenced control action rather than a cleared flag, which is what an examiner tests.

    Proof of reserves that stands up to scrutiny

    Proof of reserves published without a corresponding proof of liabilities demonstrates very little. A custodian can control assets in excess of a stated figure while owing considerably more to clients than the figure implies.

    A defensible attestation pairs controlled balances with the entitlement register at the same moment, reconciled and sealed together, so that the assertion is about coverage rather than about holdings.

    Safeheld produces this from the same continuous reconciliation that runs the custody control, which means the attestation is a by-product of the operating process rather than a periodic exercise assembled for publication.

    Independent verification of the seal allows a third party to confirm the attestation relates to a fixed, unaltered record without gaining access to client level detail.

    Standing up to supervisory examination

    Competent authorities examining a CASP will ask what the custody position was on a specific date, what the variance profile looked like over a period, how exceptions were handled and who reviewed them.

    Answering from sealed runs converts the examination into verification. The custodian produces the record, the examiner confirms the seal, and the discussion moves to substance rather than to whether the evidence is reliable.

    Governance reporting follows the same source. Board and risk committee materials describing the custody position are generated from the reconciliation record rather than assembled separately, so the position reported upward is provably the position the control produced.

    That single-source discipline is the most effective protection against the most common finding in custody examinations, which is that different parts of the firm hold different views of the same position.

    Frequently asked questions

    Why is proof of reserves insufficient on its own?

    It demonstrates control of assets without demonstrating what is owed. A custodian can hold the stated balances while client entitlement exceeds them. A defensible attestation pairs controlled balances with the entitlement register at the same moment, reconciled and sealed together, so the claim is about coverage rather than holdings.

    How are timing differences across chains handled without false breaks?

    By modelling expected settlement behaviour per chain and venue so that items in flight are recognised as in flight rather than reported as missing. A process that treats every pending transfer as a variance produces a permanent false break population, which trains teams to ignore exceptions and hides the genuine cases.

    Can a custodian reconcile sub-custodian and pooled structures?

    Yes, provided reconciliation extends to as many independent records as the structure contains rather than collapsing to a two-way check. Each pooled layer introduces a point where entitlement and control can diverge, and each therefore needs its own proved relationship rather than an assumption of correctness.

    What evidence should a CASP be able to produce on demand?

    For any named historic date: the entitlement register position, the balances actually controlled, the movements between them, the variances identified, the investigations performed, the corrections made and the individual who reviewed them, in a form that can be shown not to have been altered since.

    Does automated reconciliation replace the custody policy?

    No, but it should determine its content. A custody policy written to describe controls that operate produces a document that survives examination. A policy written first, describing intentions the operation cannot evidence, is the most common source of findings in early MiCA supervisory work.

    Back to Resources

    The system of record for client funds and reserves