“Regulated” appears on the homepage of almost every crypto exchange. It is one of the least informative words in the industry, because it compresses a question with several distinct answers into a single reassuring adjective.
Three different claims
When a platform says it is regulated, it is usually making one of these claims — and they are not equivalent.
- It is registered for anti-money-laundering supervision. This is the most common and the weakest. It means the firm is subject to AML obligations and supervised for them. It says nothing about how it holds your assets, whether it is solvent, or how it treats customers. FCA registration in the UK, FinCEN registration in the US and AUSTRAC registration in Australia are all of this kind.
- It is licensed to conduct a specific regulated activity. Stronger, and specific: a Payment Services Act licence in Singapore, a CASP authorisation under MiCA, a securities dealer registration in Canada. Conduct, custody and capital requirements typically attach.
- An affiliate somewhere holds a licence. The weakest of all, and unfortunately common. The entity you contract with is frequently not the entity holding the licence.
Registration is not approval
Regulators say this themselves, repeatedly, because the misunderstanding is so persistent. The UK’s FCA has been explicit that registration under the money laundering regulations is not authorisation to conduct regulated financial services and does not extend compensation-scheme protection to cryptoasset holdings. Singapore’s MAS has been equally direct that a licence does not protect consumers from the volatility of the assets themselves.
The check that actually works
Every claim of this kind is verifiable, because regulators publish registers. The procedure is short:
- Find the legal entity name, not the brand. It is in the terms of service and the footer. It is frequently different from the name on the website, and frequently incorporated somewhere other than where you are.
- Search the named regulator’s own register for that entity — reached from the regulator’s own domain, not from a link on the exchange.
- Read what the permission covers. Registers state the category. “Registered for AML” and “authorised to hold client assets” are different lines.
- Confirm it covers you. A licence in one jurisdiction does not extend to customers elsewhere, and this is where most of the ambiguity lives.
Our jurisdiction pages name the relevant regulator for each Tier 1 country and link its register.
What regulation does and does not do
What it can do: require segregation of customer assets from company funds, impose capital and custody standards, require disclosure, and provide a supervised process when a firm fails.
What it cannot do: prevent an exchange being hacked, prevent losses from price movements, or guarantee you are made whole. Our tracker contains incidents at exchanges that were properly registered in well-regarded jurisdictions. Japan’s framework is among the oldest and most demanding, and the DMM Bitcoin outflow still happened — regulation shaped how the failure was handled rather than preventing it.
The most useful question
Rather than “is it regulated”, ask: if this platform failed tomorrow, what specifically happens to my assets, and who decides? That question has a real answer, it depends on segregation rules and the insolvency regime of the licensing jurisdiction, and it is answerable before you deposit rather than afterwards.
Not advice. Conisec reports for information only. Nothing in this article is financial, legal, tax or security advice. Verify against the primary sources linked above before acting on anything.