Kristina Stark

Junior Growth Manager

Share

Contact Us

ONINO provides infrastructure for digital & tokenized financing across the EU and Switzerland.

On this page

Key Takeaways

ECSPR Article 4 requires every crowdfunding service provider to run effective and prudent management: documented governance, a working risk management framework, and controls for conflicts of interest, outsourcing, and complaint handling. The licence is day zero; Article 4 defines the operating system the platform runs every day after, and most of that operating system lives in software. The stakes are concrete: 181 providers raised EUR 4.25 billion across 21 Member States in 2024, and 88 percent of those investors were retail, at an average ticket of roughly EUR 660. This article covers the five controls in turn — what the management body must produce, what a risk framework looks like per offer, how conflicts must be policed, what outsourcing means when the software comes from a vendor, and how complaint handling must work — then maps the nine ongoing obligations to where each one lives in platform software.

ECSPR Article 4, the provision titled "effective and prudent management", is what turns a crowdfunding licence into a daily operating duty. The EU Crowdfunding Regulation (ECSPR), the law that gives investment and lending crowdfunding platforms one shared rulebook across all EU countries, has applied for years, and the transition period for platforms that were operating under older national rules is over.

In plain terms, Article 4 says that the people running a crowdfunding platform must actually manage it, with written rules, clear responsibilities, and a system for spotting and handling risk, and that they must keep doing so for as long as the platform exists. This means the duty sits with named directors from the start, and what those directors have to produce is a documented governance map plus the decision records showing it was followed.

Most coverage of ECSPR ends at authorisation, and this article starts after it. The licence is day zero, and Article 4, together with the neighbouring rules on complaint handling, conflicts of interest, and outsourcing, defines the operating system a regulated crowdfunding platform must run every single day afterwards. Five controls make up that operating system: governance, risk management, conflicts of interest, outsourcing control, and complaint handling, and each one is both a legal obligation and a piece of software behaviour. This article takes them in turn: what Article 4 requires of the management body, what a risk management framework looks like per offer, how conflicts of interest have to be policed, what the outsourcing rules mean when the platform software comes from a vendor, how complaint handling must work, and which obligations fire on every single investment after authorisation.

Supervisors care about this operating system because of who sits on the other side of it. According to ESMA, the EU's financial markets regulator, 181 crowdfunding service providers raised EUR 4.25 billion across 21 Member States in 2024, out of 229 providers holding authorised status on the ESMA register at year-end, and 88 percent of the investors on those platforms were retail investors, each investing an average of roughly EUR 660. An average ticket of roughly EUR 660 spread across a retail base that size means the damage from one weak control arrives thinly and invisibly, which is precisely the pattern supervision exists to catch early. Therefore the burden lands on the platform's compliance owner, who has to show that the control worked on every one of those tickets.

What does ECSPR Article 4 actually require of a crowdfunding service provider?

Article 4 requires the management body of a crowdfunding service provider, which means the people legally responsible for running the company, typically the directors, to establish and to oversee the implementation of adequate policies and procedures that ensure effective and prudent management. That includes segregation of duties (no single person controls a whole critical process), business continuity (the platform keeps working, and data survives, if something breaks), and the prevention of conflicts of interest, all in a manner that promotes the integrity of the market and the interests of the platform's clients. More specifically, the board has to produce three artefacts before a supervisor asks for them: a written governance map showing who decides what, a tested business continuity and recovery plan, and minutes proving that the board reviewed both.

The load-bearing word in Article 4 is oversee. Writing a policy can be delegated to counsel or to a compliance hire, but overseeing its implementation cannot, because responsibility sits with named people and cannot be delegated into an org chart and forgotten. Therefore the most common weakness a supervisor finds is a governance file that names a committee without recording that the committee ever met, and the directors are the people who have to answer for that gap.

In platform terms, governance shows up as configuration. The governance map has to be mirrored in role-based access control, so that the person approving an offer is not the person who onboarded the project owner, in approval workflows with named approvers, and in an audit trail a supervisor can read without assistance. Where a policy says "four eyes", the software has to make one pair of eyes insufficient, which means the compliance owner answers a supervisory question with a permission matrix.

What does an ECSPR risk management framework look like in practice?

An ECSPR risk management framework is the documented, repeatable process by which a platform assesses the risks of the projects it hosts and the way it operates, proportionate to the nature, scale, and complexity of its business. Lending platforms carry more. The regulation expects systems and controls that assess the risk of the loans arranged on the platform, and where the platform sets the price itself, it must make a reasonable assessment of credit risk before the offer goes out and set a price that is fair and appropriate, following a pricing method the EU has spelled out in detail. Therefore a lending platform needs a named credit function inside the operator, because someone has to own the pricing methodology and defend it line by line when a supervisor asks how a particular rate was set.


Diagram of an ECSPR risk management framework: two pillars, Article 4 risk assessment and pricing and Article 5 due diligence on project owners, feeding down into a software layer of onboarding, assessment and reporting workflows.

Alongside the risk framework sits the due diligence rule, where due diligence means checking who you are dealing with before you let them raise money. At minimum, a platform must verify that a project owner has no criminal record for breaches of commercial, insolvency, financial services, anti-money-laundering, fraud, or professional liability law, and is not established in a jurisdiction the EU treats as non-cooperative or high-risk. In practice this means the onboarding team has to hold dated, attributable evidence for each of those checks on every project owner, because a supervisor tests the file itself.

Software carries this framework as structured workflows. A project-owner onboarding flow records the documented checks and refuses to advance without them, risk assessments are stored per offer with the assessor's name and date, and reporting surfaces risk indicators. When the regulator asks "show me how you assessed this project", the answer should be a query the compliance owner can run in minutes, which turns a supervisory request into an afternoon of work.

How must a crowdfunding service provider manage conflicts of interest?

A conflict of interest is any situation where the platform's own interests could pull against the interests of its investors, and the regulation handles the sharpest cases with outright bans. A crowdfunding service provider may not have any participation in the offers on its own platform, and its major shareholders (holding 20 percent or more), managers, and employees may not act as project owners on the platform at all. They may invest in hosted projects only if the platform discloses this, including the specific projects, and treats them on the same conditions as every other investor, with no preferential treatment or privileged access to information.

Beyond the bans, the regulation requires internal rules to prevent conflicts, appropriate steps to identify, manage, and disclose them, and disclosure of the general nature and sources of any conflicts together with the steps taken to mitigate them. Therefore the compliance owner has to keep a live register of restricted persons, covering shareholders at or above the 20 percent threshold, managers and staff, and update it as people join and leave. A register that was accurate on the day of authorisation and never touched again is the version a supervisor will find.

Platform software either enforces this obligation or silently undermines it. Investor and project-owner onboarding should screen against the restricted-persons register, related-party flags should fire before an offer goes live, and every disclosure should be logged with a timestamp. A policy that lives only in a handbook fails the day an employee quietly invests through the regular checkout flow, which means the operator ends up explaining a breach it could have blocked with a database check.

What do ECSPR outsourcing requirements mean when your platform software comes from a vendor?

Outsourcing, in ECSPR's language, is relying on a third party for an operational function, and buying your platform from a software provider is exactly that. The regulation permits it on conditions: the platform must take all reasonable steps to avoid additional operational risk, and the arrangement must not impair the quality of its internal control or the national regulator's ability to monitor compliance. Above all, the platform operator stays fully responsible for compliance with the regulation in respect of the outsourced activities.

Read that plainly: hiring a software provider outsources the work, never the responsibility. The operator cannot point at its vendor when a control fails. Therefore the ICT function inside the operator has to maintain its own outsourcing register, its own risk assessment of the vendor and a documented exit plan, because those are the three papers a supervisor asks for when it wants to test whether the outsourcing rules were taken seriously.

That allocation of responsibility should shape how an operator buys software. The platform must give its operator, and by extension the supervisor, full visibility: documentation of what the system does, exportable records that remain the operator's property, defined support and change-management arrangements, and contractual audit access. A vendor whose system is a black box leaves the operator's obligations intact and makes them impossible to demonstrate. ONINO's white-label infrastructure starts from the same premise: the operator holds the permission and the accountability, so the white-label crowdfunding platform software has to make the operator's controls documented and provable. In practice this means the compliance owner and the ICT function belong in the vendor selection alongside the engineers, since they are the people who will have to evidence the arrangement later.

How should complaint handling work on a crowdfunding platform?

The regulation requires every crowdfunding platform to have effective and transparent procedures for handling investor complaints promptly, fairly, and consistently, free of charge. The procedure must be published, complaints must be accepted in a standard format, and every complaint and the measures taken must be recorded. The EU prescribes the standard complaint template and the process details. Therefore one person inside the operator has to own the complaints queue by name, with a deadline attached to each case, because "free of charge" and "promptly" are both testable and both fail quietly once the queue belongs to everybody.

For a lay reader: an investor must be able to complain easily and for free, the platform must answer within a reasonable, communicated timeframe, and a record of the whole exchange must exist. Supervisors read complaint logs the way engineers read error logs, as the earliest honest signal of where a process is failing. This means a suspiciously thin complaints log reads as a missing pipe, and the complaints owner is the person who has to show otherwise.

In software, complaint handling has to be a workflow with deadlines and a named owner. The pipe runs from intake in the prescribed format through acknowledgement, assignment and resolution, with the complete record retained and retrievable per case. The platforms that struggle here are rarely malicious; they simply never built that pipe, which means the compliance owner is left reconstructing two years of complaint history from email threads in front of a supervisor.

Which ongoing obligations run every day after authorisation?

Governance, risk, conflicts, outsourcing, and complaints form the management layer, and around them ECSPR wraps a set of investor-protection obligations that fire on every single investment. These crowdfunding service provider compliance obligations are continuous, which makes them product behaviour. A 2025 pan-European review by EUROCROWD, an advisory organisation whose work grew out of the European Crowdfunding Network, scored 236 licensed platforms against 17 ECSPR-derived criteria and found an average of 5.0 out of 10, with nearly 40 percent below baseline expectations and only 25 percent showing strong adherence. That review tested what platforms publicly disclose rather than verified supervisory findings, which makes the gap it measures a visibility gap, and visibility is the first thing a supervisor tests as working functionality. The table below sets out the 9 obligations, the article each one comes from, what the regulation expects, and where each obligation lives in platform software. Read down that last column and the pattern is clear: most of these duties are only real if the software enforces them by default, so auditing that column is the fastest route a compliance owner has to finding where the platform is exposed.

Obligation

ECSPR article

What the regulation expects

Where it lives in platform software

Governance

Art. 4

Effective and prudent management, segregation of duties, business continuity

Role-based access control, approval workflows, audit trail

Risk management framework

Art. 4

Documented, proportionate risk assessment of projects and operations

Risk-scored onboarding, per-offer assessments, risk reporting

Project-owner due diligence

Art. 5

Minimum checks on criminal record and jurisdiction before hosting an offer

Mandatory onboarding checks that cannot be skipped

Complaint handling

Art. 7

Free, prompt, fair complaints procedure with standard format and records

Complaint workflow with deadlines, owners, and a retained case record

Conflicts of interest

Art. 8

No own offers; restricted persons screened; conflicts disclosed

Restricted-persons screening, related-party flags, disclosure logs

Outsourcing control

Art. 9

Vendor reliance without losing control, supervisability, or responsibility

System documentation, exportable records, contractual audit access

Investor appropriateness

Art. 21

Entry knowledge test and loss-bearing simulation for non-sophisticated investors; above the greater of EUR 1,000 or 5 percent of net worth, a risk warning plus explicit consent

Appropriateness tests, simulation tools, automated investment-limit warnings

Reflection period

Art. 22

Four calendar days in which a non-sophisticated investor can withdraw without penalty

Enforced pre-contractual reflection window with clean payment unwinding

Key Investment Information Sheet (KIIS)

Art. 23

A short standardised disclosure document (maximum six sides of A4 when printed) per offer, verified for completeness, correctness, and clarity

KIIS workflows: creation, verification, versioning, display before commitment

A note on scope, so the boundary is explicit: everything above applies inside the crowdfunding service the ECSP licence covers, ECSP being the European Crowdfunding Service Provider licence a crowdfunding platform needs in the EU. That licence does not cover offers above EUR 5 million, counted per project owner over 12 months and adding up that project owner's prospectus-exempt public securities offers. Instruments or volumes outside that perimeter are governed by other regimes, not by ECSPR, and nothing in this article extends to them. Therefore an operator planning a raise above EUR 5 million has to budget a second permission and a second set of controls, and the person who needs to know that earliest is whoever owns the product roadmap.

"But scale brings new expectations. As the market grows, supervision is shifting toward governance, investor protection, and operational resilience. The next phase of ECSPR is less about licensing and more about supervision.”
Luís Pimentel, CEO at Crowdestate

The operating system behind the certificate

Ultimately a crowdfunding licence proves only that a regulator was satisfied on one particular day, and Article 4 governance and risk management is what keeps that true on every day after. Of the five controls, outsourcing control deserves the closest attention, because it is the only one where the operator's exposure grows out of a decision someone else made: the vendor ships the system, and the operator still has to evidence every control inside it. Operators who generate that evidence as a by-product of normal operation answer supervisory questions from a position of strength, while operators who treat governance as an annual documentation exercise accumulate a quiet backlog of risk.

The next actor is the compliance owner. If you operate a crowdfunding platform, or are about to, ask that person to walk each of the nine rows in the table above through your stack as it stands today and mark every row a human is currently holding together by hand. For a deeper look at the regulatory context, see our regulation resource hub.


And if you want to see how a purpose-built platform carries these obligations as native workflows, from appropriateness testing to KIIS versioning, walk the nine rows through a live platform with us and bring your compliance officer: the walkthrough is more useful with the person who owns the audit in the room.

Want to learn more how this can be applied to your business?

Read related Articles

What ECSPR Article 4 governance and risk management means in daily operations: compliance obligations, conflicts of interest, outsourcing, complaint handling.