Skip to content
Thu, 6 Aug 2026 BTC $64,415.76 -0.45%ETH $1,906.77 -0.10%SOL $72.93 -1.62%XRP $1.04 -2.84%Updated 1 min ago · Source: CoinLore
EN

What a crypto licence actually obliges a platform to do

“Regulated” is a marketing word covering registrations that require almost nothing and licences that require a great deal. How to tell which one you are looking at.

· ·4 min read
A doorway frame crossed by three horizontal bars of increasing thickness set at different heights

“Regulated” appears on nearly every crypto platform’s homepage. It is not a lie and it is not informative, because it covers arrangements ranging from being recorded on a public list to operating under capital, custody and reporting obligations. The word is identical; the substance is not.

The registration end of the range

The lightest common arrangement is registration for anti-money-laundering purposes. A firm demonstrates it has identification procedures, appoints someone responsible for compliance, and is entered on a register.

This is a genuine obligation and it addresses a genuine problem. What it does not do is say anything about how customer assets are held, whether the firm holds capital against losses, whether customer funds are segregated, or what happens in insolvency. A firm can hold this registration, market itself as regulated, and be under no obligation whatsoever regarding your balance.

The licensing end of the range

At the other end, an authorisation to conduct regulated financial activity typically brings a substantially longer list: minimum capital, rules on holding client assets, requirements to segregate them from the firm’s own, periodic reporting, controls on outsourcing, fitness requirements for management, and complaint-handling procedures.

Firms under this kind of regime are also usually subject to supervisory attention rather than merely a one-off registration — inspections, data returns, and the possibility of intervention.

The distinction that matters most to a customer is in there: client asset rules. Whether assets must be segregated, and whether they sit outside the firm’s estate if it fails, is decided by the regime the firm operates under and not by anything the firm chooses.

The questions that separate them

Four questions distinguish a meaningful authorisation from a listing, and all four have published answers:

  • Does the regime require customer assets to be segregated from the firm’s own?
  • Does it impose capital requirements scaled to the business?
  • Does it include a compensation or protection scheme, and does that scheme cover crypto holdings or only cash?
  • Is the firm supervised on an ongoing basis, or was it assessed once at entry?

Answering these takes a few minutes on the regulator’s own register, and it is the difference between reading a claim and checking one.

Which entity holds the permission

A subtlety that does real damage. Large platforms are corporate groups. A licence held by one entity does not extend to another, and the entity serving you may not be the licensed one.

The check is to find the entity named in the terms you accepted, then look up that name on the regulator’s register — not the brand. Where they differ, the permission belongs to whichever entity is listed, and your relationship is with whichever entity is in the contract.

What compensation schemes usually cover

Where a protection scheme exists, its scope is narrower than the marketing implies. Schemes typically cover money held by a failed regulated firm in the course of a protected activity. Whether crypto assets qualify depends on whether holding them is itself a protected activity in that jurisdiction, and frequently it is not.

A platform can therefore be a member of a compensation scheme, disclose that accurately, and have crypto balances entirely outside its scope. The scheme’s own documentation states what it covers, and reading it is more reliable than reading a badge.

What none of it guarantees

Worth stating plainly: authorisation reduces certain risks and eliminates none. Regulated firms fail. Rules can be broken and are sometimes only discovered afterwards. Supervision is periodic rather than continuous.

What authorisation genuinely provides is a set of obligations that exist independently of the firm’s goodwill, and a body with the power to act. That is meaningfully better than nothing and is not the same as a guarantee — a distinction the word “regulated”, used alone, is designed to blur. Our note on what happens when an exchange fails covers the insolvency side.

Checking a register properly

Regulators publish searchable registers, and using one takes a couple of minutes. Three things are worth extracting.

The permissions granted, which are usually itemised. A firm may be authorised for one activity and not another, and offering a product outside its permissions is a compliance problem regardless of how it is marketed. The status and dates, since registrations lapse, get varied, or carry conditions imposed after entry. And any restrictions, which are recorded on the register and are rarely mentioned elsewhere.

The register is also where you confirm the entity name matches the one in the terms of service, which is the check that catches the group-structure problem.

Passporting and its limits

In some regions an authorisation obtained in one member state permits operation across the bloc. Where that applies it genuinely reduces friction, and it is frequently invoked loosely by firms outside such arrangements.

The limit worth knowing is that passporting operates within a defined legal framework and does not extend beyond it. A licence from a jurisdiction outside the bloc confers no rights inside it, however reputable the issuing regulator. Claims that a firm is “licensed in Europe” on the strength of an authorisation from a non-member state are a specific and recurring form of overstatement.

What to do with all this

The practical routine is short. Find the entity name in the terms. Look it up on the register of the regulator named. Read the permissions and any conditions. Check whether client asset rules apply to that permission, and check what any compensation scheme actually covers.

That is perhaps ten minutes and it replaces a badge with a fact. It will not tell you whether a platform is well run — nothing available to a customer will — but it establishes what obligations exist independently of the firm’s intentions, which is the part that still holds when intentions change.

This article is for informational purposes only and is not financial advice. Crypto assets are volatile and high-risk, and platform terms change without notice. Verify anything here against the provider’s own current terms before acting on it.