Running a cryptocurrency exchange legally means more than obtaining a license. It requires a properly structured company, anti-money-laundering controls, rules for custody and listings, honest marketing, tax reporting and sanctions compliance, all of which shape how your platform must be built.
Licensing itself, which regimes exist and how founders choose between them, is covered separately in the exchange licensing guide. This page covers the wider legal framework you will operate inside.
1. Corporate structure
Most exchanges use an operating company in the licensing jurisdiction, sometimes with a holding company elsewhere and separate entities for different services or regions. Regulators look for real substance: local directors, a compliance officer and money-laundering reporting officer, and decision-making that genuinely happens where the license is held. A brass-plate entity with operations elsewhere is increasingly rejected. Keep customer-facing contracts, the license holder and the entity that holds customer assets aligned; mismatches cause problems in audits and insolvency.
2. Anti-money laundering and counter-terrorist financing
Exchanges are treated as virtual asset service providers under the FATF standards that most countries implement. In practice that means:
- Customer due diligence: identity verification, risk-rating and enhanced checks for higher-risk customers and politically exposed persons.
- Ongoing transaction monitoring, both fiat and on-chain, with blockchain analytics to spot funds linked to hacks, darknet markets or sanctioned addresses.
- Suspicious-activity reporting to the national financial intelligence unit.
- The travel rule: sending and receiving originator and beneficiary information with transfers to other providers, and handling transfers to self-hosted wallets under local rules. In the EU this comes from the Transfer of Funds Regulation, which has applied since 30 December 2024 with no minimum threshold for crypto transfers between providers.
- Record keeping for the statutory period, usually five years or more.
3. Sanctions
Sanctions screening is separate from AML and stricter: there is generally no risk-based tolerance. Screen customers, counterparties and wallet addresses against relevant lists, such as those of the US Treasury's Office of Foreign Assets Control (OFAC), the EU and the UK, and block access from sanctioned regions. Enforcement actions against exchanges for sanctions failures have produced some of the largest penalties in the industry.
4. Custody and client assets
After several exchange insolvencies, most notably FTX in 2022, regulators require customer assets to be segregated from the company's own and protected if the exchange fails. MiCA, for instance, requires CASPs that hold client crypto-assets to keep records of each client's holdings, segregate them from their own assets, and have a custody policy; it also makes the CASP liable for losses caused by incidents attributable to it. Your platform's internal ledger, wallet structure and reconciliation process need to support these legal promises. Ask counsel how client assets would be treated in your jurisdiction's insolvency law.
5. Listings and securities law
Every token you list is a legal decision. In the US, a token sold as an investment contract can be a security, and trading it may require registration as a securities exchange or broker-dealer. In the EU, MiCA requires a compliant white paper for most crypto-assets admitted to trading and places obligations on the trading platform. A written listing policy covering legal review, technical review, market-integrity checks and delisting criteria is standard. See the token-side view in the exchange listing guide.
6. Market integrity
Exchanges are expected to prevent and detect market manipulation, wash trading and insider dealing. MiCA introduced an explicit market-abuse regime for crypto-assets, including surveillance and reporting obligations for platforms. Conflicts of interest, such as an exchange's affiliated trading desk trading against customers, must be managed and disclosed or prohibited.
7. Consumer protection and marketing
Clear terms of service, fee disclosures, risk warnings, complaint handling and fair treatment of retail users are standard requirements. Marketing rules can be strict: the UK has applied its financial promotions regime to crypto since October 2023, requiring approved promotions with prescribed risk warnings. Influencer campaigns and referral bonuses are a frequent source of trouble. The exchange marketing guide covers what this means in practice.
8. Tax reporting
Exchanges are increasingly tax data collectors. The EU's DAC8 directive requires crypto-asset service providers to collect and report user transaction data from 2026. In the US, custodial brokers report digital asset sales to the IRS on Form 1099-DA, starting with 2025 transactions. Many other countries are adopting the OECD's Crypto-Asset Reporting Framework. Build tax-residency collection and reporting exports into onboarding and the back office.
9. Data protection and cyber security
Exchanges process identity documents and financial data, so privacy law such as the GDPR applies, along with cyber-resilience rules. In the EU, the Digital Operational Resilience Act (DORA) applies to CASPs, covering ICT risk management, incident reporting and oversight of critical third-party providers, which includes your exchange software vendor.
When things go wrong
Hacks, frozen withdrawals, regulatory investigations and customer claims all have legal dimensions. Having incident-response and communication plans reviewed by counsel in advance is far cheaper than improvising. The crypto litigation overview explains the kinds of disputes exchanges face.
Frequently asked questions
Can I run an exchange from one country and serve the whole world?
Not safely. Many countries regulate services offered to their residents regardless of where the exchange is based. You need either licenses or effective geo-blocking and onboarding restrictions for markets you do not cover.
Does a decentralized exchange have legal obligations?
It can. Regulators examine who controls the front end, the contracts and the fees. Truly decentralized protocols may fall outside regimes like MiCA, but front-end operators and token issuers often do not.
What legal documents does an exchange need at launch?
Typically terms of service, a privacy policy, risk disclosures, a fee schedule, an AML/CTF policy and procedures, a listing policy, a custody policy, a complaints procedure and, where required, a crypto-asset white paper for listed assets.
Who is responsible if a white-label vendor's software fails?
Regulators hold the licensed operator responsible. Your contract with the vendor should address liability, but it does not move your regulatory duty to them.