Article 71 of the EU Markets in Crypto-Assets Regulation requires crypto-asset service providers to establish and maintain effective and transparent procedures for the prompt, fair and consistent handling of client complaints. The requirement is operational: a provider needs more than a support inbox or a promise to respond. Regulation (EU) 2023/1114 on markets in crypto-assets
Follow the evidence
Trace how the event could reach markets, then inspect a competing explanation.
Compare explanations
Switch lenses to see what each account explains—and what remains uncertain.
For a CASP, the control should create a consistent case record: client identity, account reference, service involved, transaction timestamps, allegation, supporting files, communications, investigation steps, decision and remediation. Access controls matter because complaint files can contain identity documents, wallet addresses and sensitive account information. Metrics can reveal recurring withdrawal, custody or execution problems. For clients, the practical advantage is traceability. A dated complaint with a concise chronology and attached evidence is easier to investigate than fragmented chat messages. The official rule does not guarantee that the provider will agree with the client, and it does not determine compensation in every dispute. It requires a process capable of reaching and communicating a reasoned outcome.
For a CASP, the control should create a consistent case record: client identity, account reference, service involved, transaction timestamps, allegation, supporting files, communications, investigation steps, decision and remediation. Access controls matter because complaint files can contain identity documents, wallet addresses and sensitive account information. Metrics can reveal recurring withdrawal, custody or execution problems. For clients, the practical advantage is traceability. A dated complaint with a concise chronology and attached evidence is easier to investigate than fragmented chat messages. The official rule does not guarantee that the provider will agree with the client, and it does not determine compensation in every dispute. It requires a process capable of reaching and communicating a reasoned outcome.
Before funding an account, locate the provider’s legal name, authorisation status, complaint policy and contact route. Save the terms that apply on that date. A missing template, paid complaint channel or vague route that never identifies the responsible entity deserves scrutiny. The existence of a polished help centre is not proof of MiCA authorisation. If a dispute occurs, preserve transaction IDs, blockchain hashes, order records, screenshots with visible times and all correspondence. State the requested remedy and ask for a case number. Escalation rights depend on the jurisdiction and service, so verify the competent authority rather than relying on a generic online recovery service. MiCA sets the provider baseline; national procedures complete the path. Compliance teams can test the process with sample cases that vary in language, channel, product and urgency. Reviewers should be able to reconstruct when the complaint arrived, who owned it, what evidence was considered, whether related clients were affected and why the response was fair. Management reporting should distinguish volume from severity: ten password questions are not equivalent to one unresolved custody shortfall. Root-cause analysis matters because a complaint process that repeatedly closes individual files without correcting the underlying control is only administrative. Clients, meanwhile, should avoid including seed phrases, passwords or unnecessary identity data in a complaint. A case record should contain enough evidence to investigate the issue without creating a new security exposure.
Clients must be able to complain without charge
MiCA says providers must publish descriptions of their complaints-handling procedures and make complaint templates available. Clients must be able to file complaints free of charge. Providers must investigate complaints in a timely and fair manner and communicate the outcome within a reasonable period. The regulation also requires records of complaints and the measures taken to resolve them. Regulation (EU) 2023/1114 on markets in crypto-assets
These duties apply to the authorised legal entity providing the service. A group brand, app name or outsourced support contractor does not replace the need to identify that entity. The applicable complaint path should state where the complaint is sent, what information is required, how receipt is acknowledged and how the final response is delivered.
A reliable process connects support, compliance and evidence
For a CASP, the control should create a consistent case record: client identity, account reference, service involved, transaction timestamps, allegation, supporting files, communications, investigation steps, decision and remediation. Access controls matter because complaint files can contain identity documents, wallet addresses and sensitive account information. Metrics can reveal recurring withdrawal, custody or execution problems.
For clients, the practical advantage is traceability. A dated complaint with a concise chronology and attached evidence is easier to investigate than fragmented chat messages. The official rule does not guarantee that the provider will agree with the client, and it does not determine compensation in every dispute. It requires a process capable of reaching and communicating a reasoned outcome.
Test the complaint route before a high-stakes problem
Before funding an account, locate the provider’s legal name, authorisation status, complaint policy and contact route. Save the terms that apply on that date. A missing template, paid complaint channel or vague route that never identifies the responsible entity deserves scrutiny. The existence of a polished help centre is not proof of MiCA authorisation.
If a dispute occurs, preserve transaction IDs, blockchain hashes, order records, screenshots with visible times and all correspondence. State the requested remedy and ask for a case number. Escalation rights depend on the jurisdiction and service, so verify the competent authority rather than relying on a generic online recovery service. MiCA sets the provider baseline; national procedures complete the path.
Compliance teams can test the process with sample cases that vary in language, channel, product and urgency. Reviewers should be able to reconstruct when the complaint arrived, who owned it, what evidence was considered, whether related clients were affected and why the response was fair. Management reporting should distinguish volume from severity: ten password questions are not equivalent to one unresolved custody shortfall. Root-cause analysis matters because a complaint process that repeatedly closes individual files without correcting the underlying control is only administrative. Clients, meanwhile, should avoid including seed phrases, passwords or unnecessary identity data in a complaint. A case record should contain enough evidence to investigate the issue without creating a new security exposure.
