cryptonist
A modern building facade of repeating glass panels seen at an angle

Exchanges

What a regulated crypto exchange is regulated for

“Regulated” is the single most load-bearing word in crypto marketing, and it is almost never qualified. An exchange says it is regulated; a reader hears that somebody official is watching, that rules exist about how their money is handled, and that there is a body to complain to if it goes wrong.

Usually only the first of those is true, and it is true in a much narrower sense than the sentence implies. The gap matters most at exactly the moment it is tested.

The distinction that does most of the work

There are two very different things a financial authority can do to a firm.

It can register it for anti-money-laundering supervision. That means checking the firm has controls to verify who its customers are, to monitor transactions, and to report suspicious activity. These rules exist to stop the financial system being used to launder money. They are, in the plainest terms, rules that protect the system from the customer.

Or it can authorise the activity itself, which means setting requirements for how the firm holds client assets, what capital it must keep, how it handles complaints, and what happens to customer property if it fails. These are rules that protect the customer from the firm.

Nearly every jurisdiction started with the first and is at some stage of moving toward the second. When an exchange says “regulated” without saying which, assume the first.

The United Kingdom

A cryptoasset firm serving UK customers must register with the FCA under the Money Laundering Regulations. That registration is an anti-money-laundering permission, and the FCA is unusually direct about what it is not: being registered does not mean customers benefit from the Financial Ombudsman Service or the Financial Services Compensation Scheme.

The regulator goes further than stating this. It publishes suggested wording for firms to use, to the effect that the Ombudsman and the FSCS do not apply to the cryptoasset services the business carries on. A rule requiring firms to say what protection is absent is a fair signal of how often the opposite was implied.

So in the UK a “regulated crypto exchange” is, by default, a firm the FCA has checked for money-laundering controls. It is not a firm whose failure triggers compensation, and it is not a firm you can take to the Ombudsman over a disputed trade.

The European Union

MiCA is the first regime in a major market to authorise the activity rather than only supervise the financial-crime side, and the difference is visible in the obligations it creates.

An authorised crypto-asset service provider must hold client crypto-assets separately from its own — under Article 75(7), on the ledger itself, which in practice means different addresses rather than a shared pool with an internal spreadsheet. A custodian must agree its duties with the client in writing and maintain a custody policy. And it is liable to the client for the loss of crypto-assets, or of the means of accessing them, where the incident is attributable to the provider, with that liability capped at the market value of what was lost at the time it was lost.

There is also a structural feature worth understanding, because it is routinely described backwards: a CASP authorisation passports across the EEA. A firm authorised in one member state may serve the others without applying again. What does not travel is unrelated permission — Google’s advertising certification, for instance, is granted per targeted location, which is why a licensed exchange can still be unable to advertise in a market it is perfectly entitled to operate in.

MiCA also regulates the tokens themselves, not only the venues that trade them: stablecoins fall under a separate regime with its own authorisation, redemption and interest rules, set out in what a stablecoin is and what holds the peg.

MiCA is a real upgrade on registration. It is still not deposit insurance.

The United States

There is no single federal licence to run a crypto exchange, which is why American firms describe their status as a list rather than as a permission.

Federally, a firm acting as a money transmitter registers with FinCEN as a money services business — again an anti-money-laundering obligation, under the Bank Secrecy Act, and one that authorises operating in no particular state. State by state, money transmitter licences are required where the firm serves residents. New York runs its own regime on top: serving New Yorkers requires a BitLicense or a limited-purpose trust charter from the state’s Department of Financial Services.

Layered over all of it is an unresolved question about which assets are securities, and therefore whether a given activity falls to the SEC or the CFTC. An exchange’s regulatory position in the US is a map, not a badge.

What none of these are

No regime described here makes an exchange safe to hold assets at indefinitely. None of them guarantees your balance the way deposit insurance guarantees a bank account, and the EU’s liability rule — the strongest of the three — is capped at market value and requires the incident to be attributable to the provider.

That is not an argument against using an exchange. It is an argument for knowing what the word is doing. Regulation changes the probability and the aftermath of a failure; it does not remove the failure mode, which is that you hold a claim rather than the asset. Published reserve attestations do not close that gap either — what they prove is narrower than it sounds.

How to check instead of trusting

Every regime above publishes a register, and all of them are public.

Check the legal entity, not the brand. Large exchanges operate through different companies in different regions, and the permission belongs to one company in one place — the entity that serves your country may not be the one named in the announcement you read. Check what the permission is for: an AML registration and an activity authorisation appear in the same register and read almost identically to anyone not looking for the difference. And check the date, because firms move between regimes as new rules commence, and a claim that was accurate last year may describe a status that has since lapsed or been replaced.

If a firm’s own page says “regulated” and does not name the authority, the permission or the entity holding it, that is not a detail it left out for reasons of space.