CRA-A.2.1

This Module was first issued in February 2019. Changes made subsequently to this Module are annotated with the calendar quarter date in which the change was made as detailed in the table below. Chapter UG 3 provides further details on Rulebook maintenance and version control.

Module Ref.Change DateDescription of Changes
CRA-1.1.6(f)04/2019Amended sub-paragraph.
CRA-1.1.6(g)04/2019Moved to sub-paragraph (f).
CRA-1.6.304/2019Added License fee table based on Category.
CRA-1.6.1004/2019Amended Paragraph.
CRA-1.2.1910/2019Changed from Rule to Guidance.
CRA-1.2.2010/2019Changed from Rule to Guidance.
CRA-1.2.2110/2019Changed from Rule to Guidance.
CRA-1.4.110/2019Changed from Rule to Guidance.
CRA-B.101/2020Added reference to cyber security risk.
CRA-4.1.101/2020Amended reference to CRA-4.1.1 (r).
CRA-5.2.6-CRA-5.2.901/2020Added new Paragraphs on the requirements of IT System Audit.
CRA-5.3.601/2020Removed “at least annually” for security tests.
CRA-5.801/2020Added these terms: Cyber Security Risk, Cyber Security Incident, Cyber Security Threats.
CRA-5.8.19A01/2020Added a new Paragraph on requirements to submit a comprehensive report on cyber security incident.
CRA-5.8.2401/2020Deleted Paragraph.
CRA-5.8.2501/2020Deleted Paragraph.
CRA-5.8.25A01/2020Added a new Paragraph on requirements for periodic assessments of cyber security threats.
CRA-5.8.28-CRA-5.8.2901/2020Added new Paragraphs on the requirement for cyber security insurance.
CRA-7.1.101/2020Amended Paragraph.
CRA-7.1.1A01/2020Added a new Paragraph on references to Module AML.
CRA-7.1.201/2020Deleted Paragraph.
CRA-7.1.301/2020Added clarification that simplified customer due diligence is not allowed.
CRA-7.1.501/2020Added a new Paragraph on reference to Module AML and removed transaction record details.
Appendix-101/2020Added reference to cyber security incident.
Appendix-201/2020Amended Mitigation and aggravating factors.
CRA-4.1.1A10/2020Added a new Paragraph on Provision of Financial Services on a Non-discriminatory Basis.
CRA-10.1.901/2022Amended Paragraph on the submission of the written assessment of the observations/issues raised in the Inspection draft report.
CRA-10.3.101/2022Amended Paragraph on change in licensee corporate and legal name.
CRA-10.3.201/2022Amended Paragraph on change in licensee legal name.
CRA-6.607/2022Replaced Section with new Outsourcing Requirements.
CRA04/2023Amended Module including a new Chapter on Digital Token Offerings and enhancements to cyber security requirements.
CRA-5.910/2023Added a new Section on cyber hygiene practices.
CRA-4.1.1007/2025Added a new Paragraph on stablecoin reporting reference to SIO Module.