Categories reflect the primary activities of the firm and the degree
of client asset exposure. Firms operating multiple activities may
require combined scoping, and should be prepared to demonstrate how
controls scale across products, regions, and client segments.
Virtual Asset Exchange
Platforms facilitating order matching, routing, or execution of
virtual asset transactions. Expectations emphasize market
integrity, listing governance, surveillance capability, and
client communication discipline.
-
Listing and delisting governance, disclosures, and conflicts
management
-
Market surveillance, abuse monitoring, and escalation pathways
-
Client onboarding standards, suitability measures where
applicable
-
Segregation and safeguarding model when client assets are held
Custody Provider
Entities responsible for safeguarding private keys, wallets, or
client digital assets. Controls emphasize segregation, key
management, operational resilience, incident handling, and
recovery readiness.
- Key management model and access control governance
-
Segregation of client assets and reconciliation discipline
-
Incident response, breach handling, and client notification
readiness
- Business continuity and disaster recovery planning
Broker-Dealer (Digital Assets)
Intermediaries arranging or executing transactions on behalf of
clients, including agency and principal dealing models. Controls
emphasize suitability, conflicts management, and execution
governance.
-
Client categorization, disclosure standards, and conduct
controls
- Execution governance and order handling discipline
- Conflicts, inducements, and remuneration management
- Risk disclosures tailored to product and client type
Token Issuer
Issuers conducting token issuance or distribution. Controls
emphasize disclosure quality, governance discipline, and
distribution safeguards, including marketing standards and
conflicts management.
-
Disclosure framework and governance approvals for issuance
materials
-
Distribution risk controls and communications discipline
- Conflicts management and transparency standards
- Custody/escrow controls where funds or assets are held
Stablecoin Operator
Operators managing stablecoin issuance, reserves, or redemption
arrangements. Controls emphasize reserve governance,
transparency practices, redemption readiness, and risk
disclosures.
-
Reserve management principles and asset segregation model
- Transparency and reporting expectations around reserves
-
Redemption policies, stress readiness, and operational
resilience
- Conflict management and disclosure discipline
Infrastructure Provider
Technology services with material impact on client flows,
custody posture, or security controls. Expectations emphasize
operational resilience, change management, access controls, and
third-party risk governance.
-
Access control governance and privileged access management
- Change management and deployment controls
-
Incident response readiness and security testing practices
- Outsourcing governance and contractual controls