How to run digital asset operations safely and with full control after MiCA
The MiCA transitional period ended across the EU on 1 July 2026. For companies that hold or use crypto-assets, this changes the questions that need to be asked of every custody arrangement.
Security remains essential, but it is no longer enough to accept a broad claim that assets are safe. A company should understand which legal entity provides each service, whether that service requires MiCA authorisation, who can approve a transaction, who has access to the means of control, what happens during recovery and which records remain available for audit.
This matters for any business that wants to continue operating with digital assets under the new regulatory framework. The right model must give finance, compliance and audit teams clear answers without forcing the company to build and maintain an entire custody stack.
Fortris takes a MiCA-aligned approach built around three principles:
1. Security: Keys, identities and signing actions are protected through certified hardware, isolated computing environments and verified access.
2. Auditability: Every material action remains connected to a named user, an approved policy and an on-chain transaction record.
3. Control of funds: The customer controls authorisation and recovery. Fortris cannot independently initiate, approve or complete a movement of customer funds.
Together, these principles give companies a practical basis for managing digital assets with greater control and peace of mind after MiCA.
Start with a clear custody boundary after MiCA
MiCA defines custody and administration on behalf of clients as the safekeeping or control of crypto-assets, or of the means of access to them, on behalf of those clients. For authorised custodial Crypto-Asset Service Providers, Article 75 sets requirements covering custody agreements, client position records, custody policies, asset segregation, statements and procedures for returning crypto-assets or the means of access.
Those duties apply to providers that fall within the relevant MiCA service category. They do not automatically make every company holding crypto-assets a regulated custodian. Even so, they set a useful standard for corporate due diligence: responsibilities should be clear, controls should be demonstrable and records should be complete.
When reviewing a digital asset custody solution, companies should establish:
● who can initiate, approve and sign a transaction;
● who controls the keys or other means of access;
● whether the provider can act without customer approval;
● how access is restored if a device is lost or a user leaves;
● what happens if the provider becomes unavailable;
● which records support compliance, accounting and audit;
● whether any service in the arrangement requires MiCA authorisation; and ● how funds and recovery materials can be moved away from the platform.
The answers should be supported by the technical design and contractual responsibility model.
Secure the whole custody process, not only the private key
Corporate custody involves more than keeping a private key out of sight. Security must cover key generation, storage, user access, policy approval, transaction signing and recovery.
Fortris uses IBM Hardware Security Modules for sensitive cryptographic operations. Private keys are created and used within tamper-resistant hardware, protected by layered encryption and never stored in plain text. The governance service runs inside Google Confidential Space, an isolated and attested environment where policy checks take place before a signing request can proceed.
The customer controls the material required to authorise use of the signing infrastructure. Fortris manages the infrastructure, but it cannot use, extract or replace the customer's Control Key. This separation means access to the Fortris platform does not, by itself, provide authority to move funds.
Fortris also applies a Zero Trust model. No user, device or session receives assumed authority. Sensitive actions are checked against identity, role, permissions and company policy. FIDO2 authentication ties approvals to verified users and devices, reducing exposure to phishing, impersonation and informal approvals through email or messaging apps.
The result is a custody process in which security follows the transaction from request to signing, rather than sitting around the key as a separate technical layer.
Build auditability into every approval and fund movement
MiCA has raised expectations around records and accountability. A corporate custody process should make it possible to reconstruct the full history of a transaction without collecting evidence from emails, spreadsheets and chat messages.
Fortris creates a digital chain of custody across the life of an account and each movement of funds. Records can show:
● who created the account and its policy;
● who approved the policy;
● which users and devices were authorised;
● who initiated the transaction;
● the source account, destination, asset and amount;
● which approval threshold applied;
● who approved the request and when;
● when the signing event took place; and
● the associated blockchain transaction reference.
Because policy checks and approvals stay within the platform, the evidence reflects what the system enforced, rather than a separate statement of intent. This gives treasury, compliance and audit teams a common record of what happened, who authorised it and why it was allowed.
Accounting and data exports can then connect internal transaction records with auditable on-chain data. This reduces manual reconciliation work and helps finance teams maintain a clear history across accounts, wallets and legal entities.
Keep company authority over funds, workflows and recovery
Control should be tested at three levels: day-to-day decisions, exceptional events and exit from the platform.
In daily operations, the customer decides who can access each account, which roles can initiate or approve a movement and how many approvals are required. Policies can reflect amount thresholds, time conditions and the needs of different business units or legal entities. One account may require a single approval, while a higher-risk account may require several.
Fortris separates human approval from cryptographic signing. A transaction reaches the signing infrastructure only after the customer's policy conditions have been satisfied. Fortris cannot bypass those conditions, create an approval on the customer's behalf or unilaterally move funds.
Control also needs to survive mistakes and disruption. A lost device, the departure of an approver or a platform outage should not leave the company permanently locked out of its assets. Fortris prepares encrypted recovery material that the customer stores and protects. The recovery process uses customer-held recovery material and defined cryptographic safeguards so that the company can regain access without depending solely on Fortris.
This provides more than key protection. It gives the business the final say over fund movements, the freedom to define its own workflows and a recovery route for exceptional circumstances. That is where peace of mind comes from: control remains with the company during normal operations and when something goes wrong.
Compare digital asset custody models
The market offers several ways to manage corporate digital assets. The main difference is how authority, infrastructure responsibility and commercial dependency are divided between the company and the provider.
For CFOs and treasury officers: run governed workflows without operational drag
Treasury teams need to move digital assets without weakening internal control. A process that depends on one wallet owner or on approvals collected through email creates a single point of failure and leaves finance with incomplete evidence.
Fortris gives CFOs and treasury officers a governed operating model across users, accounts and entities. Role-based permissions restrict who can see, create or approve activity. Multi-approval policies support separation of duties, while account-level rules keep higher-risk movements subject to the right level of review.
The same process produces transaction histories and accounting-ready exports for reconciliation and financial reporting. Finance teams gain direct control over workflows and funds while spending less time assembling records or maintaining signing infrastructure.
For compliance and legal teams: map responsibility to the party performing each function
Compliance and legal teams need to map liability to the party that actually performs each function. That starts with the custody boundary.
Under the Fortris model, the customer controls authorisation and recovery. Fortris provides protected signing infrastructure and a governance engine, but does not hold customer funds or
independently control the means required to move them. It cannot initiate or approve a customer transaction, move funds outside the customer's defined approval path or recover the assets on its own.
These facts are relevant when assessing whether an arrangement involves the safekeeping or control of crypto-assets, or of the means of access, on behalf of a client under MiCA. The final regulatory classification still depends on the complete service, technical design, contracts and
applicable jurisdiction. It should be confirmed by legal counsel rather than inferred from a product label.
Fortris also supports compliance work within the transaction process. Transaction screening within the platform helps teams assess wallet and transaction risk before funds move. Travel Rule support helps applicable businesses and service providers handle required originator and beneficiary information. System-generated audit trails preserve the approvals, policy checks and transaction data needed for reviews, investigations and regulatory enquiries.
This combination gives compliance teams a clearer answer to two separate questions: who controls the funds, and what evidence proves that required checks took place?
For external auditors and tax advisors: produce evidence that can be independently checked
External reviewers need consistent data across internal records, accounting systems and public blockchains. A wallet balance alone does not explain ownership, approval authority, business purpose or the accounting treatment of each movement.
Fortris links internal governance records to the relevant on-chain transaction data. Auditors can trace a movement from its source account and approval path to its blockchain reference, while finance teams can provide accounting and data exports without rebuilding the history from several tools.
This supports:
● verification of balances and transaction activity against on-chain data; ● review of user access, policy changes and approval history;
● evidence of separation of duties and control operation;
● reconciliation across wallets, entities and accounting periods;
● tax classification and supporting transaction history; and
● faster preparation for financial audits and control testing.
On-chain references can support independent verification of addresses and balances. Where a formal proof-of-reserves opinion or attestation is required, its scope and method should be agreed with the appointed auditor. Fortris supplies the records and associated data needed to support that work; it does not replace the auditor's opinion.
Run your digital asset operations with control
Custody determines how assets are protected and who has the authority to move them. Treasury management determines how those assets are used across the business each day.
Fortris brings custody into a wider operating environment where teams can view balances across wallets and entities, assign permissions, apply approval rules and track income, savings and spending. Payments, transaction screening, accounting records and reporting remain connected to the same governed process.
This allows companies to retain control while carrying out the work their treasury requires: paying partners, funding wallets, managing stablecoins, reconciling activity and producing records for internal or external review. Every permission, policy and transaction is logged and exportable, giving finance and compliance teams one consistent account of their digital asset operations.
See how Fortris helps businesses run their digital asset treasury from one platform.
Choose a custody model built for business after MiCA
Companies should not have to choose between handing control to a third party and becoming full-time custody infrastructure operators.
Fortris gives businesses a different route. The platform supplies protected infrastructure, policy enforcement, multi-user governance, transaction screening, reporting and recovery support. The customer retains control over authorisation, access decisions, fund movements and recovery.
That division of responsibility is designed for the operating standards companies now need: security that covers the full transaction, auditability that connects decisions to on-chain activity and control that remains with the owner of the assets.
Fortris runs the custody infrastructure. Your company holds the authority.
Client-controlled custody is a model in which the business keeps the final say over every fund movement and retains an independent route to recover access, while Fortris provides the protected infrastructure and governed workflows that make corporate use practical.
Editorial and legal note
In this article, "MiCA-aligned" describes how the Fortris product design addresses security, auditability, governance and control considerations that are relevant in the MiCA environment. It does not indicate a regulatory certification, legal opinion or MiCA authorisation. The classification of any service or arrangement depends on its facts, contracts and jurisdiction. Businesses should obtain legal advice on their own obligations.
● Regulation (EU) 2023/1114 on markets in crypto-assets (MiCA)
● ESMA statement on the end of MiCA transitional periods
● EBA Travel Rule Guidelines under Regulation (EU) 2023/1113
Fortris handles digital asset treasury operations for enterprise business.
Want to learn more? Book a demo today.