This fourth part follows How can I check crypto marketing against UK rules? and focuses on EU and UK financial-services teams. The question is how to identify relevant changes, establish their legal effect and verify implementation. The applicable duties depend on the entity and its activities. The operating procedure described here is a recommended way to support those duties, rather than a prescribed universal checklist. (Regulation (EU) 2023/1114, Art. 68(4)–(6); FCA Handbook, SYSC 1 Annex 1, Parts 2–3, SYSC 6.1.1R.)
Summary
- EU: A crypto-asset service provider subject to the EU Markets in Crypto-assets Regulation (MiCA) must maintain effective compliance policies and procedures. Its management body must periodically review the specified arrangements and address deficiencies. Monitoring changes helps keep those arrangements current. (Regulation (EU) 2023/1114, Art. 68(4)–(6).)
- UK: Apply the compliance requirements for the firm's category. Common platform firms have express risk-based monitoring duties; those rules cannot be assigned to every crypto business without checking scope. (FCA Handbook, SYSC 1 Annex 1, Parts 2–3, SYSC 6.1.3-AR–6.1.3-BR.)
- EU/UK: Record an update's legal status and operative dates separately. A consultation, an enacted future requirement and an applicable rule require different decisions. Guidance also needs classification under its issuing body's powers. (TFEU, Arts. 288, 297; Regulation (EU) No 1095/2010, Art. 16(3); FCA Handbook Reader's Guide, “What is the Handbook?” and “Guidance (G)”.)
- UK: The Regulatory Initiatives Grid assists forward planning. It excludes enforcement and firm-specific supervisory activity, and published editions are not continuously updated. Other sources remain necessary. (Financial Services Regulatory Initiatives Forum, Regulatory Initiatives Grid, 10th edition, 19 May 2026, “Scope of the Grid”.)
- EU/UK: Evaluate regulatory intelligence software against source coverage, version history, applicability decisions and implementation evidence. These are recommended purchasing criteria; the cited compliance duties do not prescribe a branded product or a universal review interval. (Regulation (EU) 2023/1114, Art. 68(4)–(6); FCA Handbook, SYSC 6.1.1R, SYSC 6.1.3-BR.)
- UK: A discovered control failure requires a separate notification assessment. Where SUP 15 applies, the significant-rule-breach trigger can require immediate notification before an internal investigation is complete. (FCA Handbook, SUP 15.3.11R(1)(a), (2), SUP 15.3.12G.)
The compliance duty and its scope
MiCA Article 68(4) requires effective compliance policies and procedures from covered crypto-asset service providers. Paragraph 5 addresses staff competence. Paragraph 6 requires management-body review of arrangements for Chapters 2 and 3 of Title V and correction of deficiencies. A process for identifying relevant amendments is a practical means of maintaining those arrangements. The provision does not prescribe an alert subscription, software product or weekly review meeting. (Regulation (EU) 2023/1114, Art. 68(4)–(6).)
For firms within its application, SYSC 6.1.1R requires adequate policies and procedures sufficient for compliance. Common platform firms must also maintain an independent compliance function and a risk-based monitoring programme. That programme covers their designated investment business and relevant ancillary services and activities. Its priorities follow the compliance risk assessment. Applicability depends on SYSC 1 Annex 1 and the relevant rules; a business's use of cryptoassets does not determine its category. (FCA Handbook, SYSC 1 Annex 1, Parts 2–3, SYSC 6.1.1R, SYSC 6.1.3-AR–6.1.3-BR.)
A practical starting record identifies each legal entity, its permissions, services, customer categories and countries of operation. The reviewer should connect each source to the entity and activity it can govern. A new service or jurisdiction should reopen that assessment even when no legislation has changed. This proposed control addresses changes in the business as well as changes in the rules.
Official sources and coverage
The source register should identify the publication channel, subject coverage, assigned reviewer and backup reviewer. For EU matters, the register should distinguish EU acts from national implementing measures. Article 288 of the Treaty on the Functioning of the European Union makes a regulation directly applicable and binds Member States to the result required by a directive. A team examining a directive therefore needs the relevant national provisions as well as the EU text. National provisions should also be checked wherever a regulation assigns Member States a further implementation task. (TFEU, Art. 288.)
An EU source set can combine the Official Journal, EUR-Lex document records and the relevant authorities' official publications. A UK source set can combine legislation.gov.uk, FCA legal instruments and applicable supervisory publications. The recommended register should also cover material correspondence addressed to the firm. Public feeds cannot retrieve a private instruction that has never been published.
Each source should have a defined collection method and a fallback. A reviewer can compare received alerts with the authority's publication index and record gaps. When a feed fails, the procedure should require a manual check and retrieval of documents published during the interruption. A quiet inbox alone cannot establish that the authority issued nothing relevant.
Legal status and supervisory material
A change record should classify the document before assigning implementation work. The proposed categories are consultation, adopted measure awaiting application, currently applicable requirement, guidance and firm-specific communication. Record the issuer, legal basis and addressee where relevant. A consultation deadline belongs to the decision about responding; it must not be copied into the field for complying with a final rule. The operative text and commencement provisions determine that separate date. (TFEU, Art. 297; FCA Handbook Reader's Guide, “What is the Handbook?”.)
Official guidance needs its own assessment. FCA Handbook provisions marked R are rules; provisions marked G are guidance. The FCA explains that guidance is not binding and other means of complying with a rule remain available. Under the ESMA Regulation, competent authorities and financial market participants must make every effort to comply with guidelines and recommendations issued under Article 16. A blanket label treating every non-legislative document as optional would obscure that statutory distinction. (FCA Handbook Reader's Guide, “Guidance (G)”; Regulation (EU) No 1095/2010, Art. 16(3).)
The reviewer should record whether supervisory material changes the team's interpretation, identifies deficient practice or requests a response. An enforcement decision concerning another firm warrants examination of its facts and applicable rule. Its outcome should not automatically become a new obligation assigned to every entity. The recommendation is to retain the relevant reasoning and identify the actual source of any proposed control change.
Versions and commencement dates
The record should distinguish adoption, publication, entry into force and application. It should also capture a relevant transition, expiry or separate commencement instrument. A single publication can contain provisions with different starting dates. The decision about which version governs must follow the activity or event being assessed, rather than the date on which a newsletter arrived. (TFEU, Art. 297; FCA Handbook Reader's Guide, “What is the Handbook?”.)
For an amendment, preserve the earlier provision and the new text with their official identifiers. The reviewer should record what changed in the actor, trigger, required conduct, exception or deadline. A textual comparison can identify altered words; legal review must determine whether those words change a duty, relocate it or correct an error. Related definitions and cross-references should be checked before recording the effect.
Publication tools have limits. EUR-Lex describes its consolidated texts as documentation without legal effect and directs users to authentic Official Journal versions. The FCA states that its legal instrument controls if the Handbook website differs from it. These limits support checking the enacted or made text and any relevant correction or commencement measure before approving a deadline. (EUR-Lex, consolidated Regulation (EU) 2023/1114, introductory notice; FCA Handbook Reader's Guide, “What is the Handbook?”.)
Planning tools and operational alerts
The Regulatory Initiatives Grid is an official planning aid for expected UK measures. The May 2026 edition covers a 24-month horizon. It excludes enforcement actions, firm-specific supervision and market-sensitive information. Editions remain snapshots after publication, even when timings change. The team should use the Grid to anticipate work and confirm each material milestone through the responsible authority's subsequent publications. (Financial Services Regulatory Initiatives Forum, Regulatory Initiatives Grid, 10th edition, 19 May 2026, “Scope of the Grid”.)
Other official tools can support collection. EUR-Lex offers predefined RSS feeds and registered-user alerts for documents or procedures. The FCA Handbook provides favourites and update alerts. These functions can supply inputs to a team-owned register. Their availability does not establish that a chosen subscription covers every relevant authority, language or document type. The proposed source register should state those coverage limits. (EUR-Lex Help, “Predefined RSS alerts”; FCA Handbook, home page, introductory notice.)
A team can begin with official alerts, a controlled shared register and its existing task system. The decision to buy additional coverage should follow a demonstrated gap: missed sources, delayed collection, unreliable version comparison or unmanageable review volume. This is a procurement recommendation, not a claim that a particular software category is legally required.
Applicability and the change register
Each collected item should receive a reasoned disposition. A useful record distinguishes applicable changes, items requiring further legal assessment, matters to watch and exclusions. For an exclusion, the reviewer should identify the provision and business fact supporting it. A decision concerning one entity should not silently exclude the same update for the rest of its group.
The proposed register connects an official source to the affected duty and the action needed. Its fields should identify the instrument and pinpoint, source version, legal status, relevant dates and affected entities. The assessment should describe the present control, required change, accountable owner and evidence needed to demonstrate completion. Keep the legal deadline separate from the earlier internal delivery and testing dates.
One publication may create several tasks with different owners. Conversely, several announcements may concern the same obligation. Link those records so the team can avoid duplicate projects without losing the source history. A later final measure should reopen the earlier consultation assessment and preserve the comparison. Closing the consultation task should not automatically close implementation of the enacted text.
Where interpretation remains unresolved, the record should name the reviewer and the question requiring a decision. It should identify any immediate restriction or interim action that the responsible manager has approved. A pending legal assessment should remain visible until its effect on the relevant activity and deadline has been decided.
Ownership and review frequency
The operating procedure should separate legal assessment, delivery and verification. Compliance can identify the applicable duty and explain the required outcome; the responsible business or technical owner implements the change. The closure reviewer then checks the evidence against the requirement. Where the applicable rules require independence, those assignments must preserve it. Common platform firms' compliance functions also require the necessary authority, resources, expertise and access to information. (FCA Handbook, SYSC 6.1.3-CR(1), (4), SYSC 6.1.5AR.)
A risk-based schedule should combine routine review with urgent escalation. The firm can set collection and assessment intervals according to the source, possible consequences and time available to respond. A newly received item requiring action before the next scheduled meeting needs an earlier decision. Internal service targets should identify a backup owner and escalate missed assessments before they consume implementation time. These are proposed operating controls, not universal statutory review periods.
Management reporting should identify decisions that need authority or resources. Useful entries include unassessed items approaching an operative date, overdue implementation and failed verification. The proposed report should state the affected duty, exposure, responsible person and decision required. It should distinguish an overdue internal milestone from failure to meet an external legal deadline.
Regulatory intelligence software
Regulatory intelligence software should be assessed against the work it is expected to perform. Separate the content service, which collects and classifies publications, from the workflow functions used to assign and verify actions. Procurement should establish which capabilities are included, which require another system and which remain manual. A product demonstration should use the firm's actual source list and record structure.
Coverage claims need a testable definition. Request the included authorities, document types, languages, historical depth and collection arrangements. Establish how the service handles amended pages, replacement attachments, corrections and an unavailable source. The product should preserve an accessible official reference alongside its summary. Where collection or processing fails, the team needs a visible exception and a way to recover missed material.
Workflow testing should examine the full history of an item. A reviewer should be able to identify the original publication, changes to the assessment, ownership transfers and deadline revisions. Check whether permissions protect approved interpretations and whether a reopened item reaches its existing owners. Export should preserve the source references, decisions and supporting evidence needed after the service ends.
These purchasing criteria are recommendations derived from the need to operate and review compliance arrangements. The cited duties regulate their effectiveness; they do not prescribe the purchase of a product described as regulatory intelligence software. A firm should compare the proposed service with its existing process and record the specific deficiency the purchase is intended to address. (Regulation (EU) 2023/1114, Art. 68(4), (6); FCA Handbook, SYSC 6.1.1R.)
Regulatory intelligence tools and automated analysis
A controlled trial should test regulatory intelligence tools against a preselected set of official publications. The set should contain known relevant changes, irrelevant items and documents whose legal status differs. Record the expected classification and applicability before running the trial. Review missed items, incorrect scope decisions and deadline errors separately; a large volume of retrieved documents does not measure those failures.
For each accepted item, test whether another reviewer can recover the source and reproduce the stated change. Include a correction, a future commencement and an item requiring national-law follow-up. Measure the delay between official publication and availability in the service using recorded timestamps. Any reported result should identify the sample and test period, without implying performance outside that test.
Automated summaries and AI-assisted mapping should remain proposed assessments until a designated reviewer checks them. The recommended control is to verify the underlying provision, definitions, exceptions and effective date before changing an obligation or closing work. Preserve the generated text separately from the approved interpretation and record substantive overrides. Material disagreement should be assigned for legal review rather than resolved by selecting the more confident wording.
No provider performance or automation accuracy follows from these criteria alone. Procurement acceptance should depend on the actual test record, identified failures and the agreed method for correcting them. The firm should repeat affected tests after a material change to source coverage or processing.
Completion evidence and discovered breaches
The recommended closure test compares the implemented control with the applicable provision. Evidence should identify the approved policy or system version, the test performed, its result and the person accepting it. A policy amendment may also require changes to forms, access permissions or staff instructions. Where those tasks are necessary for the control to operate, the change should remain open until the evidence covers them.
A failed check should identify the missing requirement and return the item to its owner. The procedure should preserve the failure, remedial action and repeat-test result. Completion statistics should distinguish implemented changes from exclusions, withdrawn proposals and duplicate notices. Combining those categories would conceal how much implementation work remains.
Discovery of a control failure also requires consideration of notification duties. Where SUP 15 applies, a firm must immediately notify the FCA when the significant-rule-breach condition in SUP 15.3.11R is met. The trigger includes awareness or information reasonably suggesting that the matter has occurred, may have occurred or may occur in the foreseeable future. An unfinished investigation does not postpone that trigger once its conditions are satisfied. (FCA Handbook, SUP 15.3.11R(1)(a), (2).)
The FCA's significance guidance addresses potential financial loss, frequency, systems implications and delay in identification or remediation. An overdue tracker entry alone does not establish all elements of the notification duty. The reviewer should assess the underlying rule, circumstances and significance, then record the reporting decision separately from the implementation task. (FCA Handbook, SUP 15.3.12G.)
