APRA Expects Crypto Companies to Conduct Due Diligence and Risk Assessment

With the growth in crypto-assets and the use of distributed ledger technology, the potential scale and risks of such activities could become significant over time. The Australian Prudential Regulation Authority (APRA) is setting out initial risk management expectations for all regulated entities that engage in activities associated with crypto-assets, and a policy roadmap for the period ahead.
APRA expects that all regulated entities will adopt a prudent approach if they are undertaking activities associated with crypto-assets, and ensure that any risks are well understood and well managed before launching material new initiatives.
In particular, APRA expects that all regulated entities will:
Conduct appropriate due diligence and a comprehensive risk assessment before engaging in activities associated with crypto-assets, and ensure that they understand, and have actions in place to mitigate, any risks that they may be taking on in doing so;
Consider the principles and requirements of Prudential Standard CPS 231 Outsourcing or Prudential Standard SPS 231 Outsourcing when relying on a third party in conducting activities involving crypto-assets; and
Apply robust risk management controls, with clear accountabilities and relevant reporting to the Board on the key risks associated with new ventures.
Entities also need to ensure they comply with all conduct and disclosure regulation administered by ASIC. This will require robust conduct risk management and consideration of distribution practices and product design, as well as consideration of disclosure.
Entities are expected to consult with APRA and ASIC where they are unclear on prudential, disclosure or conduct requirements and expectations when undertaking activities associated with crypto-assets.
Subscribe Now

