Crypto exchange is a commercial label, not a single legal category. One venue may match customer orders, act as principal, custody keys, transmit value, lend assets, offer derivatives, stake tokens, and convert bank money. Regulators usually analyze those functions separately, even when a user experiences one account and one screen.
The useful question is not whether the interface looks like an exchange, but which entity performs each regulated function for each customer. A service map can then drive licensing, custody, surveillance, disclosure, and change-control gates before a venue launches or adds a product.
What you will learn
- Decompose an exchange into legally relevant services and entities
- Explain licensing, custody, market-integrity, and customer-protection controls
- Distinguish registration scope from approval of every product
- Build a jurisdiction-aware launch and change-management process
Map the operating model
Begin with legal entities and contracts. Identify who accepts the customer, owns the interface, matches orders, faces trades, controls keys, receives fiat, extends credit, performs staking, and contracts with market makers. Affiliates may split these roles, and a terms-of-service reference does not prove that money and assets follow the stated path.
Then classify each product. Spot purchases, security tokens, commodity derivatives, payment services, custody, interest-bearing accounts, and managed strategies can activate different statutes and supervisors. The same token may be available only to certain customer types or countries. Product inventory and customer eligibility should therefore be machine-enforced and reconciled to written legal approvals.
Licensing is activity and territory specific
Licensing applications commonly require ownership, management fitness, business plans, financial statements, AML controls, cybersecurity, custody architecture, complaints, disaster recovery, and financial projections. New York's Department of Financial Services directs virtual-currency applicants to a jurisdiction-specific BitLicense checklist and does not treat an incomplete submission as ready for substantive review.
Authorization scope matters after approval. A license may cover named services, entities, and territories but not a new derivative, lending product, or foreign affiliate. Some regimes require prior approval or notification for material changes. Displaying a regulator's logo or registration number should never be read as government endorsement of returns, solvency, or every listed asset.
Custody and customer assets
Custody controls address private-key authority, wallet architecture, transaction approvals, segregation, books and records, reconciliation, incident response, and access after insolvency. Cold storage is only one technical component. Governance over key generation, backups, staff privileges, vendor access, software changes, and emergency transfers determines whether the custody system is controlled.
Customer agreements should explain ownership, liens, rehypothecation, forks, airdrops, fees, withdrawal conditions, and the role of sub-custodians. Operational records must match those promises. A venue that says assets are segregated should be able to reconcile onchain addresses, internal ledgers, bank accounts, liabilities, and exceptions at an appropriate frequency with independent review.
Fair trading and conflicts
Market-integrity programs monitor wash trading, spoofing, manipulation, insider misuse, abusive liquidations, and suspicious coordination. Listing teams assess technology, legal classification, issuer disclosures, supply concentration, conflicts, and surveillance feasibility. Transparent criteria matter because listing fees, venture investments, treasury holdings, and affiliated market makers can influence decisions.
A vertically integrated venue can combine exchange, broker, custodian, lender, and proprietary trader roles that conventional markets often separate. Integration may reduce friction, but it intensifies conflicts and concentration. Controls can include information barriers, restricted lists, best-execution or fair-dealing processes where applicable, independent risk limits, public conflict disclosures, and surveillance that covers affiliates.
Cross-border access and failure planning
A website accessible worldwide is not necessarily authorized worldwide. Customer solicitation, localization, payment rails, staff, and active marketing can create territorial connections. Geoblocking and contractual restrictions can support a territorial policy but are imperfect when users employ false documents, intermediaries, or network tools to disguise location.
Venues also need orderly failure plans. Cyberattack, banking loss, liquidity stress, chain halt, vendor outage, or insolvency can interrupt withdrawals and price formation. Recovery procedures, communication protocols, customer-asset records, wind-down funding, and regulator notification reduce harm but cannot eliminate loss. Users should verify current official registers and terms in their own jurisdiction.
Common misconceptions
“A crypto exchange needs one exchange license that covers every feature worldwide.”
Licenses and registrations attach to specific entities, services, products, and territories. Custody, transmission, securities, derivatives, and lending may require separate analysis.
“Regulator registration means the government approved every listed token and guarantees customer funds.”
Registration establishes a defined supervisory relationship and scope; it does not ordinarily endorse investments, promise solvency, or insure every customer asset.
“An offshore venue is outside all customer-country rules.”
Territorial reach can depend on solicitation, customers, conduct, and effects. Incorporation is relevant but is rarely the only connection examined.
Risks and limitations
- Commingling and custody failures can leave customer records inconsistent with onchain and bank assets during stress or insolvency.
- Conflicts from proprietary trading, affiliated market making, lending, and token investments can distort listings, prices, and liquidations.
- License-scope drift can occur when product teams add assets, leverage, staking, or countries without formal regulatory change review.
- Cross-border controls may fail when marketing, affiliates, payment providers, or users create connections that geofencing misses.
Key takeaways
- Decompose the venue into entities, services, products, assets, customers, and flows.
- Treat authorization as scoped permission, not product endorsement.
- Test custody promises through reconciliations and access controls.
- Monitor trading abuse and conflicts across the venue and affiliates.
- Plan for outages, insolvency, and cross-border control failures before launch.
Primary and further reading
Test your understanding
Score at least 2 out of 3 to complete this lesson. Explanations appear after you submit.