1.1. This document constitutes the policy (the “Policy“) for the management of conflicts of interest of RIV-Digital S.r.l. (hereinafter also “RIV Digital” or the “Company“) for the purposes of Regulation 2023/1114 and has the objective of: (i) identifying the circumstances that generate or could generate a conflict of interest capable of harming the interests of one or more clients; (ii) describing the procedures and organizational measures adopted for their management and mitigation; (iii) defining the methods for their communication and monitoring. This Policy is coordinated with other relevant company policies
1.2. The document is approved by the Board of Directors (hereinafter also “BoD“) of RIV Digital and is intended for all its corporate bodies and personnel.
1.3. This Policy is evaluated and reviewed at least once a year or upon the occurrence of relevant circumstances requiring modification and/or integration, so that the identification of circumstances that generate or could generate conflicts of interest is constantly updated, also to account for changes in the Company’s organizational structure and services provided or developments in the relevant regulatory context. The adequacy of the Policy is also verified based on the actual methods of providing regulated services, including operations as a principal desk in the exchange. This activity is handled by the company’s Legal & Compliance function, which relies on the support of the Company’s competent units.
1.4. Proposed amendments are brought to the attention of the BoD which, following its evaluation, may also adopt all appropriate measures to remedy any deficiencies identified in that context.
2.1. The European Parliament and the Council of the European Union adopted Regulation (EU) 2023/1114 of 31 May 2023 on markets in crypto-assets (hereinafter defined as “MiCAR“). The main objective of MiCAR is to provide a clear and uniform legal framework for the creation, distribution and trading of crypto-assets, while ensuring investor protection and market stability.
2.2. The main objective of MiCAR is to provide a clear and uniform legal framework for the creation, distribution and trading of crypto-assets, while ensuring investor protection and market stability. For the purposes of this Policy, the provisions of Title V, Chapter 2, of MiCAR relating to the organizational requirements of crypto-asset service providers are particularly relevant and, specifically, Article 72 on conflicts of interest.
2.3. In particular, Article 72 of MiCAR prescribes the following for crypto-asset service providers, such as RIV Digital, regarding the identification, prevention, management and communication of conflicts of interest:
“1. Crypto-asset service providers shall implement and maintain effective policies and procedures, taking into account the scope, nature and range of crypto-asset services provided, to identify, prevent, manage and disclose conflicts of interest between:
a) themselves and
i) their shareholders or members;
ii) any person directly or indirectly connected to the crypto-asset service providers or their shareholders or members;
iii) the members of their management body;
iv) their employees; or
v) their clients; or
b) two or more clients whose mutual interests are in conflict.
2. Crypto-asset service providers shall disclose, in a prominent position on their website, to their actual and potential clients the general nature and sources of conflicts of interest referred to in paragraph 1 and the measures taken to mitigate them.
3. The disclosure referred to in paragraph 2 shall be made in electronic format and shall be sufficiently detailed, taking into account the nature of each client, in order to enable each client to make an informed decision regarding the crypto-asset service in the context of which the conflict of interest arises.
4. Crypto-asset service providers shall assess and review their conflict of interest policy at least once a year and shall take all appropriate measures to remedy any deficiencies in that regard.
5. […]”
2.4. The aforementioned provision emphasizes the importance that crypto-asset service providers adopt all reasonable measures to identify, prevent, manage and disclose conflicts of interest.
2.5. This Policy also incorporates the requirements set out in Delegated Regulation (EU) 2025/305, in particular Article 4, paragraph 2, regarding proportionate, traceable and documented management of conflicts of interest, as well as Delegated Regulation (EU) 2025/1142 regarding the recording and retention of identified cases.
3.1. This Policy contains the description of circumstances that generate or could generate situations of conflicts of interest capable of seriously harming the interests of one or more clients and that could arise between the Company and/or the Relevant Parties (as defined below) and/or with the client or between clients at the time of providing any crypto-asset service.
3.2. Certain circumstances that may abstractly constitute a conflict of interest, but which also constitute unlawful conduct as prohibited by specific legal and/or regulatory provisions, are not addressed in this Policy. The conduct in question is governed by the specific procedures that the Company has adopted to prevent and identify instances of market abuse.
3.3. The conflicts of interest relevant for the purposes of this Policy are those that may arise between:
(A) the Company and
(i) its shareholders and companies belonging to the group;
(ii) any person directly or indirectly connected to it or to its shareholders;
(iii) the members of the Board of Directors;
(iv) its employees and external collaborators, including consultants, critical suppliers and parties acting on behalf of the Company;
(v) clients;
(vi) entities belonging to the same corporate group;
(vii) external suppliers with critical functions.
(the subjects listed from (i) to (iv) are hereinafter defined as “Relevant Parties“. For the purposes of this Policy, conflicts of interest are also assessed with reference to parties connected to the Relevant Parties, meaning natural or legal persons having relationships with the latter such as to determine, directly or indirectly, a risk of circumventing the safeguards on conflicts of interest).
(B) two or more clients whose mutual interests are in conflict.
3.4. The Company ensures compliance with Article 4, paragraph 2, of Delegated Regulation (EU) 2025/305 through a structured and documented process that includes:
(i) preventive and continuous identification of sources of conflict, in relation to services provided, relevant parties and business relationships;
(ii) adoption of organizational, procedural and technical measures suitable to prevent or mitigate such conflicts;
(iii) formalized management of identified cases, with traceability of decisions taken;
(iv) communication to clients, where necessary, of relevant information pursuant to Article 72 MiCAR;
(v) monitoring and periodic review of the effectiveness of the safeguards adopted.
The identified safeguards apply consistently to the entire operating model and regulated services provided by the Company, including the use of a proprietary trading model and the use of a crypto-asset reserve.
4.1. For the purposes of this Policy, a relevant interest is considered to be any advantage, direct or indirect, of any nature, whether material or immaterial, professional, financial or personal.
4.2. For the purposes of identifying conflicts of interest, the Company takes into account the services it provides.
4.3. In identifying conflict situations that may arise from them or from a combination of them, the Company assesses whether itself, a Relevant Party or one of its clients:
(a) may realize a financial gain or avoid a financial loss to the detriment of the Company or a client;
(b) has an interest distinct from that of the Company or one of its clients in carrying out its activities or the service provided or a transaction executed on behalf of the Company;
(c) has a financial or other incentive to favor:
4.4. The potential nature of the conflict must be assessed ex ante, with no relevance to any considerations made ex post regarding the actual existence of the circumstances and the aforementioned conditions.
4.5. Identification of conflict situations is the responsibility of the Legal & Compliance Function, which must in any case be informed of any conflict situations by the Relevant Parties, should they become aware of them.
4.6. In the event that the conflict situation does not fall within those indicated in the conflict of interest mapping but nevertheless represents a situation of potential conflict of interest, the interested party or the party aware of it shall nonetheless communicate it to the Legal & Compliance Function.
4.7. A potential conflict is also considered to be the use of a proprietary platform or wallet developed by an entity belonging to the same corporate group, where this may result in competitive advantages or limit the operational and technical independence of the Company.
5.1. The Legal & Compliance Function provides advice and assistance for the identification of conflict of interest situations and for the definition of appropriate organizational measures for their effective management.
5.2. It verifies that the situation is included in the Company’s conflict of interest mapping prepared by it and, if it does not fall within it, assesses its scope in order to confirm whether the concrete circumstances are such as to give rise to a potential conflict of interest.
5.3. In assessing conflict of interest situations, the Legal & Compliance Function takes into account, at a minimum, the nature of the conflict, the parties involved, the service concerned, the potential impact on clients, the probability of risk occurrence, the adequacy of existing safeguards and the need for escalation to the competent corporate bodies. The Legal & Compliance Function handles the identification and qualification of the situation, proposes management measures to be adopted and coordinates, with the support of the competent functions, the related monitoring.
5.4. In order to assess the effectiveness of the safeguards, the Legal & Compliance Function applies key risk and performance indicators, including:
(i) number of situations recorded in the Register per year;
(ii) average resolution time for identified conflicts;
(iii) percentage of conflicts closed within 30 days;
(iv) any recurrences of whistleblowing reports related to conflict issues;
(v) impact on pricing and spreads in exchange services;
(vi) consistency of fee structure with fair treatment among clients;
(vii) any contractual benefits in relationships with placed issuers.
5.5. The management of conflicts of interest involves the Legal & Compliance Function as an independent function, with the support of the Risk and ICT functions for technical and operational aspects, ensuring functional separation from commercial units.
6.1. When the Legal & Compliance Function identifies the existence of a conflict of interest, including potential, in relation to the case under examination, it proceeds to identify the management measures to be adopted and informs the BoD for appropriate decisions.
6.2. The Company calibrates the number and type of measures to be adopted according to the extent of the conflict, having regard to the interests of the Company and/or clients. These must be proportionate to the nature, size and complexity of the Company’s business as well as the type and range of services offered to clients.
6.3. In managing conflict of interest situations, the Company applies, in a manner proportionate to the nature and relevance of the conflict, the following safeguards:
(i) preventive disclosure obligations to the Legal & Compliance Function and, where necessary, to corporate bodies;
(ii) mechanisms for prior authorization or prohibition of the transaction or activity;
(iii) compliance checks by the Legal & Compliance Function;
(iv) abstention obligations for parties involved in decision-making processes;
(v) escalation mechanisms to the Board of Directors in cases of greater relevance;
(vi) segregation of decision-making processes and operational responsibilities;
(vii) complete recording of the situation and decisions taken in the Conflict of Interest Register;
(viii) continuous monitoring and periodic review of identified situations.
7.1. The Company’s Legal & Compliance Function manages and updates an electronic register (hereinafter the “Register“) in which it records, for each service provided, situations in which a conflict of interest has arisen or, in the case of an ongoing service, a conflict of interest relevant for the purposes of this Policy may arise.
7.2. The Conflict of Interest Register is available to the Supervisory Authority and control bodies, whenever requested, and presented to the Board of Directors periodically, at least annually.
7.3. The Register indicates:
7.4. The records contained in the Conflict of Interest Register are retained for a minimum period of 5 (five) years from the date of closure of the situation, pursuant to Article 7 of Delegated Regulation (EU) 2025/1142.
8.1. With regard to conflict situations identified and recorded in the Register, the Legal & Compliance Function carries out periodic monitoring of them in order to assess their evolution over time, the application and effectiveness of safeguards and the possible cessation of the conflict, where appropriate.
8.2. With particular regard to conflict of interest situations relating to outsourcing contracts, ad hoc procedures are applied aimed at verifying the consistency and quality of services provided by suppliers.
8.3. In particular, the outsourcing contract manager, as defined by the Outsourcing Policy, must include a specific section on conflicts of interest in the annual report presented to the BoD regarding the activities carried out by the outsourcer. This section must indicate whether the presence of a conflict of interest situation has prejudiced the level of services offered by the outsourcer or not and the elements underlying its assessment.
8.4. The Legal & Compliance Function carries out sample and targeted checks on the truthfulness of periodic declarations made by relevant parties, including through documentary verification and analysis of transactions carried out.
9.1. The Company has prepared a dedicated section, easily accessible, within its website, dedicated to conflicts of interest.
9.2. This section includes, in Italian and English:
9.3. The Legal & Compliance Function is responsible for ensuring and verifying the continuous updating of this section, in compliance with any significant modifications and updates to internal policies and procedures relating to conflicts of interest.
10.1. This section illustrates the systematic mapping of potential conflict of interest situations identified by the Company in relation to individual crypto-asset services for which authorization is required pursuant to MiCAR. This mapping is conducted in accordance with the provisions of Article 4, paragraph 3, of Delegated Regulation (EU) 2025/1142, with specific reference to the Relevant Parties as defined by this Policy.
10.2. The mapping of conflicts of interest is structured by homogeneous categories, taking into account in particular: (i) services provided; (ii) operating methods adopted, including operations as direct counterparty; (iii) intra-group relationships; (iv) personal transactions of relevant parties and connected parties; (v) remuneration mechanisms; (vi) relationships with partners, suppliers and issuers; (vii) relevant contractual and technological relationships; (viii) remuneration and incentive policies, where susceptible to determining or aggravating conflicts of interest.
10.3. The mapping of conflicts of interest is carried out taking into account the actual operations of RIV Digital, as described in the Operating Program, in the Outsourcing Policy and in the technical documentation attached to the authorization application, ensuring consistency among the various company policies.
10.4. For each service, the main abstract or concrete situations susceptible to giving rise to a conflict are identified, together with the organizational and procedural measures adopted for their prevention and management, proportionately to the nature, scope and complexity of the activity carried out. The safeguards listed are accompanied by a set of cross-cutting measures applicable to all services, with the objective of ensuring fair treatment of clients, operational integrity and protection of the Company’s reputation.
10.5. Placement Service for Crypto-Assets
Possible conflicts:
Safeguards adopted:
The procedures for identification, prevention, management and communication of conflicts of interest relating to the placement service are applied in accordance with Article 79, paragraph 2, MiCAR and include ex ante controls on crypto-asset selection criteria, remuneration structure and neutrality of communications to clients. The related assessments are also carried out with reference to placement campaigns having a cross-border dimension, taking into account internal information flows, involvement of competent functions and, where relevant, decision-making flows of the Board of Directors.
10.6. Exchange Service for Crypto-Assets with Other Crypto-Assets
Possible conflicts:
Safeguards adopted:
10.7. Group Membership
Possible conflicts:
Safeguards adopted:
10.8. Conflicts Arising from Outsourcing
Possible conflicts:
Safeguards adopted:
10.9. Operating Method of Execution as Direct Counterparty (Principal Desk)
Potential conflicts:
Safeguards:
The principal desk operating method does not constitute a separate autonomous service, but represents an operating method through which the Company provides exchange services for crypto-assets with funds and exchange services for crypto-assets with other crypto-assets, acting as direct counterparty to the client.
The Company acts as direct counterparty to the client, on own account, within authorized exchange services. Potential conflicts of interest are managed through: (i) price determination according to the published methodology (reference market price plus spread and margin within established maximums), as a documented and verifiable methodology; (ii) functional separation between management functions (portfolio/inventory) and control functions; (iii) periodic monitoring of the adequacy of conditions applied compared to market standards.
10.10. Personal Transactions of Personnel and Corporate Officers
Potential conflicts:
Safeguards:
10.11. Conflicts Related to Critical Suppliers and External Partners
Potential conflicts:
Safeguards:
10.12. Intra-Group Relationship with RIV Technologies FZE
Potential conflicts:
Safeguards:
10.13. Conflicts Related to Relationships with Issuers
Potential conflicts:
Safeguards:
10.14. Cross-Cutting Safeguards
In addition to the specific measures provided for each service, the Company adopts a set of cross-cutting safeguards aimed at ensuring consistent, proportionate and effective management of conflicts of interest at organizational, strategic and operational levels.
(i) Obligation of annual declaration by employees and members of the management body on the absence of personal or professional situations capable of generating relevant conflicts of interest;
(ii) Mandatory and periodic training for all personnel, aimed at promoting awareness of risks related to conflicts of interest and disseminating a culture of corporate integrity;
(iii) Active surveillance by the Legal & Compliance Function on all sensitive transactions, including those carried out by relevant parties with potential conflict profiles;
(iv) Internal reporting system (whistleblowing) also accessible anonymously, to encourage timely communication of critical situations;
(v) Remuneration policy consistent with the objectives of sound management of conflicts of interest, which excludes direct or indirect incentives to behavior that favors the personal interest of the employee or the Company at the expense of clients, including through links to sales targets or individual performance. The policy provides for remuneration mechanisms based on qualitative indicators, collective criteria and compliance with applicable regulations ensuring that the remuneration structure does not in any case result in unjustified preferential treatment among clients with potentially conflicting interests. The Legal & Compliance Function periodically verifies that remuneration systems do not produce distortive incentives and assesses their impact on conflicts of interest. The Company adopts remuneration mechanisms, including the variable component, structured on the basis of KPIs consistent with the objectives of sound and prudent management and client protection. Remuneration systems:
(a) do not incentivize behavior in conflict with client interests;
(b) are consistent with the Company’s risk profile and conflict management safeguards;
(c) include risk alignment mechanisms between individual performance and operational sustainability;
(d) are subject to continuous monitoring by the Legal & Compliance Function;
(e) are subject to periodic review and, where necessary, corrective interventions in the presence of distortions or incentives not consistent with applicable regulations.
(vi) Specific safeguards in case of membership in a corporate group, aimed at ensuring the Company’s management and decision-making independence from any affiliated or controlling companies, in particular through:
a. traceability of corporate interactions relevant for the purposes of this Policy;
b. obligation of preventive disclosure to the Board of Directors for any potentially conflicting transaction with group entities;
c. adoption of Chinese walls between the operational areas involved.
(vii) Regulation of personal transactions of relevant parties, subject to prior authorization by the Legal & Compliance Function, with possibility of limitation or prohibition in case of potential conflict and obligation of periodic disclosure of positions held in crypto-assets. Personal transactions are regulated in accordance with Article 6 of Delegated Regulation (EU) 2025/305 and are subject to preventive controls, continuous monitoring and ex post verifications.
(viii) Continuous monitoring is carried out on the presence of any conflicts arising from licenses, updates, operational support or economic conditioning that may derive from the use of technology developed by parties connected to the Company, including the affiliate RIV Technologies FZE;
(ix) Implementation of enhanced and formalized monitoring on intra-group relationships and critical outsourcing, with obligation of at least annual review and with direct escalation mechanisms to the BoD in case of detection of structural conflicts.
11.1. Personal transactions of Relevant Persons are governed in accordance with Art. 6, par. 2, of Delegated Regulation (EU) 2025/305 and are subject to (i) an obligation of prior notification and, where required, authorization by the Legal & Compliance Function; (ii) ex-ante assessment of conflict profiles in relation to the services provided and the crypto-assets handled; (iii) the possibility of restricting or prohibiting the transaction in the event of an actual or potential conflict; (iv) obligations for periodic disclosure of positions held in crypto-assets and the retention of supporting evidence; (v) sample-based and ex-post controls, with traceability of results and, where appropriate, the adoption of corrective and disciplinary measures.
11.2. The management of conflicts arising from intra-group or contractual relationships with suppliers is subject to enhanced supervision, exercised by the Legal & Compliance Function in coordination with the BoD, in order to ensure that every agreement complies with the principles of fairness, independence, and transparency, particularly in the presence of relationships with entities connected to the RIV group.
11.3. Conflict of interest oversight activities are assigned exclusively to resources possessing the skills required by Art. 4, par. 8, of Delegated Regulation (EU) 2025/1142. In particular, responsible personnel are required to:
i. possess proven experience in regulatory compliance, with reference to financial services legislation, the MiCAR Regulation, and delegated acts;
ii. have in-depth knowledge of the operational and decision-making dynamics of the crypto-asset services provided by the Company;
iii. be able to analyze risks, assess reputational and operational impacts, and manage relationships with Corporate Bodies and competent Authorities;
iv. operate with decision-making autonomy, integrity, and independence from operational and commercial units;
v. be familiar with the Company’s organizational and technological safeguards, including tools for documentary monitoring, updating the Conflicts Register, and validating internal controls.
RIV-Digital S.r.l.
Sede legale: Via Luigi Dalla Via 3 B, 36015, Schio
Registro delle Imprese di Vicenza – REA VI-414981
Codice Fiscale/P. IVA: 05421350280
Capitale sociale: € 300.000,00 interamente versato
LEI: 815600DCB0E8882D2314
RIV-Digital S.r.l. — Authorized by CONSOB as a crypto-asset service provider (Resolution no. 24030 of June 10, 2026).
Activity subject to the supervision of CONSOB (Italian Companies and Exchange Commission), Via G. B. Martini 3, 00198 Rome – www.consob.it.
© Copyright 2026 RIV-Digital S.r.l. All Rights Reserved.