Updated 13/09/2025
In force

Initial Legal Act
Amendments
Search within this legal act

Article 3 - Delegated Regulation 2025/885

Article 3

Prevention, monitoring and detection

1.   The arrangements, systems and procedures referred to in Article 92(1) of Regulation (EU) 2023/1114 shall:

(a)

cover the full range of trading activities undertaken by the persons professionally arranging or executing transactions in crypto-assets;

(b)

produce alerts indicating activities requiring further analysis to detect potential market abuse;

(c)

enable crypto-asset service providers operating a trading platform to:

(i)

analyse, individually and comparatively, each transaction executed, and each order placed, modified, cancelled, or rejected in the systems of the trading platform;

(ii)

prevent the occurrence of repeated behaviours observed on the same trading platform;

(d)

enable persons professionally arranging or executing transactions in crypto-assets to analyse, individually and comparatively each transaction executed and each order placed, modified, cancelled or rejected inside and outside a trading platform, irrespective of whether or not the orders and transactions are placed and executed by means of the distributed ledger, and aspects of the functioning of DLT that could constitute market abuse.

2.   Persons professionally arranging or executing transactions in crypto-assets shall put in place and maintain arrangements and procedures that ensure an appropriate level of human analysis in the prevention, monitoring, detection and identification of transactions, orders and aspects of the functioning of the distributed ledger technology that indicate the likelihood or existence of market abuse behaviours. Persons professionally arranging or executing transaction in crypto-assets shall collect additional personal data, only for the sole purpose of ensuring appropriate level of human analysis.

3.   For the purposes of Article 92(1) of Regulation (EU) 2023/1114, persons professionally arranging or executing transactions in crypto-assets shall, to a degree which is appropriate for, and proportionate in relation to, the scale, size, and nature of their business activity, employ ICT systems.

The ICT systems referred to in the first subparagraph shall include ICT systems capable of deferred automated reading, replaying and analysis of order book data. Such systems shall have sufficient capacity to operate in an algorithmic trading environment.

For the purposes of the second subparagraph, algorithmic trading means trading in crypto-assets where a computer algorithm automatically determines individual parameters of orders, including as to whether to initiate the order, the timing, price or quantity of the order, or how to manage the order after its submission, with limited or no human intervention, and does not include any system that is only used for the purpose of routing orders to one or more trading platform or for the processing of orders involving no determination of any trading parameters or for the confirmation of orders or the post-trade processing of executed transactions.

4.   Persons professionally arranging or executing transactions in crypto-assets may by written agreement outsource to a third party or delegate to a legal person forming part of the same group, as defined in Article 2, point (11), of Directive 2013/34/EU of the European Parliament and of the Council (6) (‘providers’), the functions relating to the prevention, monitoring, detection and identification of orders, transactions or other aspects of the functioning DLT that could constitute market abuse, including analysis of data, including order and transaction data, and the generation of alerts. Persons delegating or outsourcing those functions shall remain fully responsible for complying with all of their obligations under this Regulation and Article 92 of Regulation (EU) 2023/1114. Where those functions are outsourced to a third party, persons outsourcing those functions shall comply with the following requirements at all times:

(a)

retain the expertise and resources necessary to:

(i)

evaluate the quality of the services provided and the organisational adequacy of the providers;

(ii)

supervise the outsourced services;

(iii)

manage of the risks associated with the outsourcing of those functions on an ongoing basis;

(b)

they shall have direct access to all the relevant information about the data analysis and the generation of alerts.

The written agreement referred to in the first subparagraph shall describe the rights and obligations of the person delegating or outsourcing the functions and those of the provider. It shall also set out the grounds on the basis of which the person delegating or outsourcing the functions can terminate that agreement.

5.   As part of the arrangements, systems and procedures referred to in the first and second subparagraphs, persons professionally arranging or executing transactions in crypto-assets shall maintain the information documenting the analysis carried out with regard to orders, transactions and aspects of the functioning of DLT that could constitute market abuse for a period of 5 years. That information shall include the analysis made and the reasons for submitting or not submitting a STOR. Persons professionally arranging or executing transactions in crypto-assets shall provide that information to the competent authority upon request.


(6)  Directive 2013/34/EU of the European Parliament and of the Council of 26 June 2013 on the annual financial statements, consolidated financial statements and related reports of certain types of undertakings, amending Directive 2006/43/EC of the European Parliament and of the Council and repealing Council Directives 78/660/EEC and 83/349/EEC (OJ L 182, 29.6.2013, p. 19, ELI: http://data.europa.eu/eli/dir/2013/34/oj).