Digital Asset Regulation

Classify the instrument, activity, entity and jurisdiction before applying a rule

Why one “crypto rule” is not enough

Digital assets can represent payment value, a bank deposit claim, a security, a fund interest or an unbacked crypto-asset. A firm can issue, hold, trade, distribute, advise on or transfer an asset. Each combination can fall under a different legal perimeter. The technology does not decide the answer on its own.

A bank's first regulatory task is to write down the instrument, the economic function, every participating legal entity and each relevant jurisdiction. It should then map permissions, customer protections, prudential treatment, financial-crime controls, market conduct, reporting and operational resilience to those facts. A brand name or network label is not a legal classification.

A digital asset regulatory decision path from instrument and activity to applicable obligations.

A four-part perimeter test

Instrument. Identify the holder's legal claim, issuer or obligor, redemption or income rights, transfer restrictions and authoritative register. A tokenised security may remain a security. A tokenised deposit needs a bank-liability analysis. A stablecoin needs its own issuer, backing and redemption analysis. A CBDC is central bank money and sits outside the FSB's crypto-asset recommendations.

Activity. Issuance, custody, exchange, brokerage, advice, payments and operation of a market or platform have different conduct and infrastructure risks. A bank that only distributes a product may still have customer-facing duties; a bank that holds keys has custody and operational exposure. Combined functions create conflicts to assess.

Entity. Name the bank, issuer, custodian, wallet operator, platform, reserve bank and any agent. Record which entity contracts with the customer and which one actually performs each control. A parent brand cannot substitute for entity-level permissions and accountability.

Jurisdiction. Locate the customer, issuer, service providers, reserve and transfer activities. Cross-border access may bring more than one legal framework into view. The bank should obtain current legal analysis instead of assuming that a licence in one market covers every customer or product feature.

International frameworks and local law

The Financial Stability Board (FSB) published high-level recommendations for crypto-asset activities and separate recommendations for global stablecoin arrangements in 2023. They address activity-based oversight, governance, risk management, disclosures and cross-border cooperation. They are recommendations to authorities, not a licence for an individual firm. Its 2025 peer review found gaps and inconsistency in implementation, so a bank must not present the framework as a single globally uniform rulebook.

IOSCO's crypto and digital asset market recommendations address conflicts, market integrity, custody, operational risk and retail distribution. The Financial Action Task Force (FATF) standards address anti-money laundering and counter-terrorist financing for virtual assets and virtual asset service providers; FATF's 2026 update shows implementation still varies among jurisdictions. These bodies describe different risk dimensions. None replaces the current legislation and supervisor guidance that bind the bank's entity.

As one regional example, the European Union's Markets in Crypto-Assets Regulation (MiCA) distinguishes asset-referenced tokens, e-money tokens, other covered crypto-assets and crypto-asset service providers. Its application dates and transition provisions differ by activity and Member State. The bank should use the live EU text, European supervisory material and relevant national authority guidance for the exact activity. A token that is already a regulated financial instrument may instead fall under other financial-services rules.

The bank's evidence file

A release-ready product file should contain:

  1. Instrument terms and a reasoned legal classification, including what the customer can claim.
  2. An entity and activity map with licences or permissions and cross-border scope checked.
  3. Customer disclosures, complaint and redemption routes matched to the actual product.
  4. Custody, segregation, key-control and reconciliation evidence where assets are held.
  5. Financial-crime controls proportionate to the activity, including applicable transfer-data requirements.
  6. Prudential, liquidity and accounting treatment assessed for the bank's actual exposure.
  7. Market conduct, conflicts, data, cyber and outsourcing controls with named owners.
  8. A change process that reopens the analysis when the instrument, network, jurisdiction or law changes.

The file should state a source name, version or access date, legal entity and applicability decision for each material rule. “Compliance reviewed” is not enough to reproduce an answer after a product or law changes.

Worked example: one app, three products

Assume a bank app shows a tokenised fund interest, a fiat-referenced stablecoin and a tokenised bank deposit. All three may look like balances. They have different issuers and claims. The fund interest raises securities and fund-distribution questions. The stablecoin raises issuer, reserve, redemption and service-provider questions. The tokenised deposit raises bank-liability, payment and prudential questions. The bank's own custody or advice role may add obligations to each.

The product team should not reuse one generic “digital asset” disclosure. It should explain who owes the customer, how to exit, how value is protected, when a transfer is final and which party handles a complaint for each product. The legal and compliance teams should check the current rules for every participating entity and customer location. Operations should test a failed transfer, lost access and provider failure under each distinct arrangement.

Change and review triggers

Reassess the perimeter when a token gains new rights, a distribution partner changes, a wallet adds custody, a stablecoin reserve or redemption term changes, an asset crosses into another country, or a platform begins matching buyers and sellers. Regulatory monitoring is not only a calendar task; product changes can alter the applicable activity before a new law is passed.

A useful control measure is the number of live product and entity combinations with a current, evidenced applicability decision. Another is the age of unresolved legal or operational conditions at launch. Neither can be replaced by a count of policies signed.

Takeaway

Regulate the function and claim that actually exist. A bank should map the instrument, activity, entity and jurisdiction, then attach current binding rules and tested controls to that map. International recommendations are useful orientation; the product decision rests on applicable law, permissions and evidence.

Sources and review scope

The sources below were checked on 1 October 2026. This chapter does not provide a legal opinion for any product or jurisdiction.