Custody Outside the EU: Why Article 70(3) Already Closed the Bermuda Question
Article 70(3) never says the credit institution must sit inside the EU. That silence is being pitched as an opening for Bermuda and other third-country banks. The definition two articles away, plus EBA PSD2 precedent, already closes it.
Friday deep dive (16 September 2026) on MiCA Article 70(3) client-fiat safeguarding and third-country banks (Bermuda pitches). Art. 70(3) requires client funds other than EMTs with a credit institution or central bank by end of next business day; no explicit territorial qualifier in 70(3) itself. Definition at Art. 3(1)(28): CRR Art. 4(1)(1) function AND authorised under CRD (Directive 2013/36/EU). Bermuda licence satisfies function only; needs EU/EEA CRD authorisation or Art. 47 CRD authorised branch. DGS and BRRD protection absent for Hamilton-only supervision. CDR (EU) 2025/305 RTS requires justifying the specific institution. Demand driver: CRR III Art. 501d 1,250% RW and 1% Tier 1 cap; EU banks take 8–16 weeks and often decline. EMT carve-out because Title IV reserve regime. EBA Q&A 2023_6882 (17 Jan 2025) under PSD2 Art. 10(1)(a): no third-country bank; only EU/EEA credit institution or Art. 47 branch. Central bank route: Latvijas Banka plan; ECB Opinion CON/2024/28 (27 May 2024) declines; TARGET Guideline 2022/912; ECB Decision 2025/222 (27 Jan 2025, live 9 Apr 2025) opens TARGET for non-bank PSPs but explicitly bars CASP safeguarding accounts. Four scenarios: (1) client fiat at non-CRD bank = prohibited; (2) Art. 47 branch = permitted if verified; (3) corporate treasury offshore = permitted if walled from client funds; (4) marketing as Art. 70(3) solution = prohibited (Art. 61 + CRD VI 21c). MiFID II CDR 2017/593 Art. 4 lists third-country bank; MiCA deliberately narrower (two options only). UK PSRs 2017 allow approved foreign credit institutions. EEA: same-state banks resolved via Annex IX/Protocol 1; cross-EEA (e.g. Bank Frick for EU CASP) still open in practice. CRD VI Art. 21c: grandfather cutoff 11 Jul 2026 passed; prohibition 11 Jan 2027; Class 1/2 branches. Norway/LI/IS MiCA status diverge. Reverse solicitation Art. 61: corporate OK; safeguarding pitch fails; ESMA guidelines Feb 2025 + Apr 2026 convergence. Art. 69 reporting; failed safeguarding reopens Art. 59 authorisation. Soft-sell: Bermuda pitch exists because EU banking access is hard; Cointegrity/Micahub interest is mapping accounts, verifying Art. 3(1)(28)/Art. 47 status, separating treasury from client fiat, confirming awkward EEA/branch points in writing before NCA review. Wrong shortcut costs more than early verification. Answers: Can Bermuda bank hold MiCA CASP client fiat? Article 70(3) credit institution definition? EBA Q&A 2023_6882 third country? ECB Decision 2025/222 CASP safeguarding? Art. 47 CRD branch for MiCA custody? CRD VI Article 21c dates? Liechtenstein bank Art. 3(1)(28)?
Custody Outside the EU: Why Article 70(3) Already Closed the Bermuda Question MiCA Article 70(3) requires a CASP holding client funds other than e money tokens to place them, by the end of the following business day, with "a credit institution or a central bank." The provision never says the institution has to sit inside the EU. In the files crossing our desks, that silence is doing more work than it should. Third country banks, Bermuda licensed institutions among them, are reading the gap as an opening and pitching segregated client money accounts directly to European CASPs we are already helping through authorisation, and who have been shut out of their domestic banking sector. We know the demand is real because we sit in the middle of it. EU credit institutions built their crypto risk policies between 2018 and 2022, mostly on the assumption that anything touching a wallet was a write off, and CRR III has done nothing to change their minds. {{embed:art70 capital pressure}} Article 501d assigns a 1,250% risk weight to unbacked crypto asset exposures and caps a bank's total exposure to that category at 1% of Tier 1 capital, with a breach triggering an immediate notification to the competent authority. The CASPs we work with can wait eight to sixteen weeks for a banking decision and still get declined. When a Bermuda account that opens in a week then lands in the inbox, it looks like a fix for an operational crisis. We covered the capital side of that squeeze in The Bank Capital Trap. It is not a compliant one. The e money token carve out in Article 70(3) exists because EMT issuers already answer to their own reserve regime under Title IV; everything else, ordinary client fiat, is what this provision governs. Once you follow the definition MiCA actually uses for "credit institution," the answer to where that money can sit is not ambiguous. The European Banking Authority has already ruled on the near identical question under PSD2. The gap in Article 70(3) closes two articles away, and that is the conversation we keep having when a founder forwards the deck and asks whether this time is different. The legal architecture: three articles, one answer Article 70(3) does not define "credit institution" itself. MiCA Article 3(1)(28) does that work, in these words: "'credit institution' means a credit institution as defined in Article 4(1), point (1), of Regulation (EU) No 575/2013 and authorised under Directive 2013/36/EU." That second clause, the CRD authorisation requirement, is the part we keep finding left out of the offshore banking pitch. {{embed:art70 definition chain}} The CRR half of the definition describes the function: an undertaking that takes deposits or other repayable funds from the public and grants credit for its own account. A Bermuda licensed bank satisfies that without difficulty. But MiCA's cross reference does not stop at the functional description. It requires CRD authorisation, granted by an EU or EEA competent authority or by the ECB under the Single Supervisory Mechanism. A bank licensed exclusively under Bermuda law has never been through that process and cannot acquire the label by resemblance. When we pressure test a proposed safeguarding partner, that is the first filter. There is a route in, but it runs through Article 47 CRD, which allows a third country undertaking to establish an authorised branch inside the EU or EEA. That branch, not the parent bank's Bermuda licence, is what would carry the CRD authorisation Article 3(1)(28) requires. Absent that branch, the entity a CASP is dealing with is a bank under Bermuda law and nothing under EU law. The substantive reason is not bureaucratic box ticking: EU authorised credit institutions sit inside the Deposit Guarantee Scheme Directive, protecting deposits up to €100,000 per depositor, and the Bank Recovery and Resolution Directive, which gives an NCA an actual resolution mechanism if the custodian fails. Neither exists for a depositor at a bank supervised only in Hamilton, and that is the point we have to make when the commercial pressure to "just open the account" is strongest. Commission Delegated Regulation (EU) 2025/305, the RTS specifying what a CASP's authorisation application must contain, makes the point operational rather than theoretical. In the prudential safeguards section of an application we prepare, the documentation has to demonstrate how client funds will be held and with which institutions. An NCA reviewing that file is not checking a box marked "bank." It is asking the CASP to justify the specific institution it chose, and "a bank in Bermuda" is not a justification the RTS was built to accept. We have watched that question come up in completeness reviews; it is not theoretical. The precedent already on the books CASP fiat safeguarding is not the first time the EU has had to decide whether a foreign bank counts as a "credit institution" for client money purposes. PSD2 imposes a structurally identical requirement on payment and e money institutions under Article 10(1)(a), and the EBA answered the third country version of this question directly in Q&A 2023 6882, published 17 January 2025. Asked whether a PSD2 authorised institution could safeguard user funds at a bank based outside the EU, the EBA's answer was no: the eligible institution is either a credit institution authorised in the EU or EEA, or an EU/EEA branch of a third country undertaking authorised under Article 47 CRD. MiCA uses PSD2's credit institution definition without modification. When we advise on Article 70(3), there is no basis for reading it more permissively than Article 10(1)(a), and we do not. The central bank half of Article 70(3) is not a workaround either, and we have had to walk clients through why. In 2023, Latvijas Banka, the Bank of Latvia, floated a plan to let CASPs open safeguarding accounts directly with the central bank starting mid 2024. The Latvian Finance Ministry sought the ECB's view on the underlying draft law, and on 27 May 2024 the ECB issued Opinion CON/2024/28 declining to support it, "at least for the time being." The stated reason: TARGET, the Eurosystem's settlement system, is restricted under Guideline (EU) 2022/912 to credit institutions, investment firms, Eurosystem central banks, and member state treasury departments. CASPs fit none of those categories. {{embed:art70 central bank timeline}} The ECB left a door open in that Opinion for a future harmonised approach, and something did follow, just not what a CASP would want. On 19 July 2024 the Eurosystem announced a policy giving non bank payment service providers, meaning PSD2 payment institutions and EMD2 e money institutions, access to TARGET for settlement purposes, formalised in ECB Decision (EU) 2025/222 of 27 January 2025 and live since 9 April 2025. That same Decision explicitly prohibits Eurosystem central banks from offering or providing safeguarding accounts to non bank PSPs or to crypto asset service providers. The central bank route for CASP safeguarding did not just stay closed. It got closed more explicitly, in the same document that opened a door for everyone else. That sequence matters in client conversations because "what about the central bank?" still comes up as a Plan B after the domestic bank declines. Inside a mandate, the question rarely arrives phrased as abstractly as "is a Bermuda bank a credit institution." It shows up as four different scenarios, and only one of them is actually about client money. {{embed:art70 scenarios}} What is resolved and what is not {{embed:art70 resolved open}} From where we sit, the prohibition on using an unauthorised third country bank for client fiat is resolved. It rests on a definitional cross reference MiCA's drafters wrote deliberately, not an oversight, and it has direct EBA precedent under an analogous regime. We treat it as closed unless and until an NCA or ESMA publishes something that reopens it. There is a genuine textual argument on the other