← Research library

Regulation / regulatory explainer

Registered, Licensed or Regulated? How to Verify a Crypto Exchange

Learn what registered, licensed and regulated mean for crypto exchanges, how regulatory scope differs by jurisdiction, and how to verify a claim before depositing.

Published 2026-08-16Updated 2026-08-1615 min read

“Registered,” “licensed,” “authorised” and “regulated” are often used as if they mean the same thing.

They do not.

They also do not form a universal hierarchy in which “registered” always means weak oversight and “licensed” always means strong oversight.

The meaning depends on:

  • The jurisdiction
  • The law creating the regime
  • The regulator
  • The legal entity
  • The activity covered
  • The customer type
  • The current status of the permission

A crypto exchange may be incorporated as a company, registered for anti-money-laundering supervision, licensed for a specific virtual-asset activity, authorised under a broader financial-services regime, or subject to several of these at the same time.

The correct question is therefore not:

Is this exchange registered or regulated?

It is:

Which legal entity appears in which official record, under which legal regime, for which activities, in which jurisdiction, and with what current status?

That is the approach Cexvia uses when evaluating exchange regulatory standing.

The short answer

The four terms below should be separated.

TermWhat it can meanWhat you still need to verify
Company registered / incorporatedA legal company exists in a corporate registryWhether it has financial-services permission
AML / VASP / MSB registeredThe entity is registered under an AML or virtual-asset regimeWhether the regime authorises the specific financial service
Licensed / authorisedA regulator has granted permission for defined activitiesEntity, territory, customer type, product scope and licence conditions
RegulatedThe entity or activity is subject to a regulatory frameworkWhich framework, which entity and what level of supervision applies

None of these words should be evaluated without the underlying official record.

“Regulated exchange” is a useful descriptive phrase, but it is not a globally standardised licence category.

A business can be regulated because it is subject to:

  • AML and counter-terrorist-financing rules
  • Payment-services regulation
  • Crypto-asset service-provider rules
  • Securities regulation
  • Derivatives regulation
  • Custody requirements
  • Consumer-protection obligations
  • Prudential requirements
  • Market-abuse rules

Two exchanges can both accurately describe part of their operations as regulated while operating under very different obligations.

This is why Cexvia does not convert the word regulated into a binary yes/no safety label.

The underlying record matters more than the marketing terminology.

Four records that are commonly confused

1. Company incorporation

A corporate registry can establish that a company legally exists.

Typical fields include:

  • Legal name
  • Company number
  • Formation date
  • Registered address
  • Directors
  • Corporate status

This can be valuable when identifying the company behind an exchange.

It does not, by itself, establish permission to:

  • Hold customer fiat
  • Custody crypto
  • Operate a trading venue
  • Offer derivatives
  • Provide staking
  • Offer investment products
  • Serve customers in a particular jurisdiction

A genuine certificate of incorporation can therefore be used in a misleading way.

Fraudulent platforms sometimes present a normal company-registration certificate as if it were a financial licence.

The document may be real while the claim made about it is false.

2. AML, MSB or VASP registration

Some jurisdictions require crypto businesses to register under anti-money-laundering or virtual-asset rules.

The strength of these regimes varies.

They may require:

  • Customer due diligence
  • AML policies
  • Suspicious transaction reporting
  • Governance controls
  • Fit-and-proper assessments
  • Recordkeeping
  • Compliance personnel

But the existence of a registration does not automatically establish prudential safety, solvency or permission for every product.

3. Financial-services licence or authorisation

A licence or authorisation usually grants permission to conduct defined regulated activities.

Depending on the jurisdiction, those activities may include:

  • Operating a crypto trading platform
  • Exchange services
  • Brokerage
  • Transfer services
  • Custody
  • Lending
  • Staking
  • Derivatives
  • Payment services

A licence can also carry conditions relating to:

  • Capital
  • Governance
  • Cybersecurity
  • Client-asset safeguarding
  • Reporting
  • Complaints
  • Audits
  • Market conduct

But even a genuine licence remains limited by its legal scope.

4. Regulatory supervision

“Regulated” can describe an entity that is subject to ongoing rules and supervision.

The depth of supervision can vary significantly.

Some regimes focus primarily on AML obligations.

Others impose broader operational, prudential, governance and customer-protection requirements.

This makes the underlying legal regime more important than the label itself.

Example 1: US FinCEN MSB registration

In the United States, many virtual-currency businesses fall within the Money Services Business framework administered by the Financial Crimes Enforcement Network.

FinCEN's MSB Registration website explicitly states that inclusion in the database is not a recommendation, certification of legitimacy or endorsement by a government agency.

That distinction is important.

An MSB registration can establish that an entity appears in the federal registration system and is subject to applicable Bank Secrecy Act obligations.

It does not establish that:

  • The exchange is solvent
  • Customer crypto is insured
  • Every state permits the service
  • The SEC has approved the platform
  • The CFTC has authorised its derivatives
  • Every token offered is lawful for every customer
  • The business has been endorsed by the US government

US state licensing is a separate layer.

New York has an additional virtual-currency regulatory framework.

Therefore:

FinCEN registration should be recorded as FinCEN registration—not converted into a generic “US crypto licence.”

Official reference:

FinCEN — MSB Registration Website

Example 2: UK crypto registration is changing

The United Kingdom is a particularly useful example of why terminology must be tied to the applicable law and date.

Cryptoasset businesses carrying on certain in-scope activities in the UK currently need to register with the Financial Conduct Authority under the Money Laundering Regulations.

The FCA states that MLR registration is a legal requirement for covered cryptoasset businesses and is not a recommendation or endorsement.

In 2026, the UK is also preparing a broader Financial Services and Markets Act authorisation regime for cryptoasset activities.

The FCA has explicitly stated:

  • An MLR registration application is not an FSMA authorisation application.
  • Being registered under the MLRs does not guarantee future authorisation under FSMA.
  • Firms conducting activities covered by the future regime will need the relevant FSMA permission.

The new regime is scheduled to apply to authorised cryptoasset firms from 25 October 2027.

This is a useful real-world illustration:

UK MLR registration
≠
future FSMA authorisation

Both statuses are regulatory.

They simply represent different legal regimes and different scopes.

Official references:

Example 3: EU MiCA authorisation

The European Union's Markets in Crypto-Assets Regulation provides a harmonised regulatory framework for crypto-assets and crypto-asset service providers that fall within its scope.

MiCA introduces requirements covering areas including:

  • Authorisation
  • Governance
  • Operations
  • Prudential safeguards
  • Customer information
  • Market integrity

A Crypto-Asset Service Provider authorisation under MiCA is therefore structurally different from a simple company-registration record.

However, even MiCA authorisation must still be read by scope.

A CASP may be authorised for particular services such as:

  • Custody and administration
  • Operating a trading platform
  • Exchange of crypto-assets for funds
  • Exchange of crypto-assets for other crypto-assets
  • Execution of orders
  • Placement
  • Transfer services
  • Advice
  • Portfolio management

The question remains:

Which entity is authorised for which crypto-asset services?

The existence of a MiCA authorisation should not be stretched to an affiliate that is not named in the regulator's record.

Official references:

Example 4: Dubai VARA licensing

Dubai provides another clear example of activity-level licensing.

The Virtual Assets Regulatory Authority maintains a public register of Virtual Asset Service Providers.

VARA's public register can distinguish between firms that are:

  • Fully licensed
  • Holding an In-Principle Approval

It also identifies the services that a VASP is authorised to provide.

VARA states that firms conducting virtual-asset activities in or from Dubai, excluding the DIFC, need the required VARA licence before commencing regulated activity.

A VASP may be licensed for multiple activities, but the permitted services still need to be checked.

This means:

Company appears in VARA register
        ↓
Check status
        ↓
Check licensed activities
        ↓
Check legal entity
        ↓
Check whether the user's product is within scope

Official references:

Registration is not automatically “weak”

A common mistake is to assume:

Registration = weak
Licence = strong

That is too simplistic.

Some registration regimes involve substantial regulatory review, governance assessment and ongoing compliance requirements.

At the same time, some licences cover only narrow activities.

The useful comparison is not the word used by the regulator.

It is the regulatory substance behind the record.

A better framework is:

QuestionWhy it matters
What law creates the status?Defines the regulatory obligations
Which regulator issued or maintains it?Identifies the supervising authority
Which legal entity holds it?Prevents group-level overstatement
What activities are covered?Determines product scope
Which territory is covered?Determines geographic relevance
Which customer types are covered?Retail and institutional permissions may differ
What is the status?Active, restricted, suspended, revoked or pending matter differently
Is supervision ongoing?A one-time filing may differ from continuous supervisory obligations

This is more reliable than ranking terms by their wording.

“Licensed” also does not mean “everything is licensed”

A group can contain several affiliates.

For example:

Exchange Group
├── Entity A — Spot exchange
├── Entity B — Custody
├── Entity C — Derivatives
├── Entity D — Payments
└── Entity E — Institutional services

If Entity C holds a derivatives licence, that does not automatically license Entity A's spot trading service.

Likewise:

  • A custody licence does not necessarily authorise derivatives.
  • A payment licence does not necessarily authorise crypto trading.
  • A broker-dealer licence does not automatically cover ordinary crypto balances.
  • A licence in Dubai does not automatically authorise service in the United States.
  • A European authorisation does not automatically attach to every website operated by the wider group.

The legal entity is therefore the anchor for licence verification.

Five scope tests every regulatory claim should pass

Cexvia's recommended approach is to test a claim across five boundaries.

1. Entity

Does the name in the regulatory record match the entity named in the user's account agreement?

Check:

  • Full legal name
  • Company number
  • Registered address
  • Regulator reference number

A similar brand name is not enough.

2. Jurisdiction

Does the permission apply where the user is located?

A licence can be genuine but irrelevant to a user in another country or state.

3. Activity

Does the record cover the actual service?

Examples:

  • Spot trading
  • Custody
  • Fiat transfer
  • Staking
  • Lending
  • Futures
  • Options
  • Brokerage

Do not infer one activity from another.

4. Customer type

Some permissions distinguish between:

  • Retail customers
  • Professional clients
  • Institutional customers
  • Accredited or eligible investors

A service available to institutions is not automatically authorised for retail users.

5. Status

Check whether the record is:

  • Active
  • Restricted
  • Suspended
  • Revoked
  • Withdrawn
  • Expired
  • Pending
  • In-principle only

The status can be as important as the licence itself.

Domain matching is also important

A valid regulatory record can still be misused by a cloned or impersonating website.

Imagine a real company called:

Example Digital Assets Ltd

It holds a legitimate regulatory record.

A scammer then creates:

example-digital-profit.com

and copies:

  • The company's name
  • Registration number
  • Certificate image
  • Office address
  • Regulator logo

The record is real.

The website is not.

This is why a complete verification should compare:

domain
+
legal entity
+
regulator record
+
account agreement
+
contact details

If the regulator publishes approved domains, compare those as well.

Incorporation certificates are not financial licences

A certificate of incorporation can be useful evidence of legal identity.

But it does not establish that the company has permission to provide financial or crypto services.

Red flags include websites describing:

  • Companies House incorporation
  • State company registration
  • Tax registration
  • Business licence
  • Chamber of commerce membership

as if they were proof of financial regulation.

A legitimate corporate registration should be classified as:

corporate identity evidence

not:

financial-services authorisation

Proof of Reserves is also not a licence

Proof of Reserves belongs to a separate category of evidence.

It may provide transparency about specified assets or balances at a particular point in time.

It does not create regulatory permission to operate.

It also should not automatically be equated with a complete financial-statement audit.

The SEC has previously cautioned that non-audit crypto assurance arrangements may not provide the same level of assurance as a financial-statement audit.

This means Cexvia should keep these dimensions separate:

Regulatory standing
≠
Asset / solvency transparency
≠
Security history
≠
Corporate transparency

A strong score in one dimension does not automatically resolve risks in another.

Official reference:

SEC — The Potential Pitfalls of Purported Crypto “Assurance” Work

Registration does not mean customer assets are insured

Another common marketing leap is:

Registered / regulated
→
customer assets are insured

That conclusion is not valid without additional evidence.

Insurance and compensation depend on:

  • Asset type
  • Account structure
  • Custodian
  • Bank arrangement
  • Applicable law
  • Policy terms
  • Customer category

For example, eligible fiat deposits at a qualifying insured bank can be treated differently from crypto assets held directly by an exchange.

A related broker-dealer may also have protections that do not extend to the brand's ordinary crypto trading account.

Regulatory status and asset protection should therefore be verified independently.

Common misleading regulatory claims

Treat the following phrases as claims that require additional evidence:

  • “Fully regulated”
  • “Globally regulated”
  • “Government approved”
  • “Internationally licensed”
  • “Registered in the United States”
  • “FinCEN licensed”
  • “EU licensed”
  • “FCA approved”
  • “VARA approved”
  • “MiCA compliant”
  • “Licensed in 50 states”

These statements may be:

  • Accurate
  • Partly accurate
  • Outdated
  • Attached to the wrong entity
  • Limited to one activity
  • Limited to one jurisdiction
  • Based on a registration that is being described too broadly

The response should be verification, not assumption.

How Cexvia should classify regulatory evidence

Cexvia should preserve the regulator's actual terminology wherever possible.

Recommended fields:

FieldExample
ExchangeExample Exchange
Legal entityExample Digital Assets Ltd
JurisdictionUnited Kingdom
RegulatorFinancial Conduct Authority
Record typeMLR cryptoasset registration
Licence / reference number123456
ActivityCryptoasset exchange provider
Customer scopeAs stated in official record
StatusRegistered / Active
Effective dateYYYY-MM-DD
Approved domainIf published
SourceRegulator's official register
Cexvia interpretationAML registration; not equivalent to broader FSMA authorisation

The Cexvia interpretation should explain scope without replacing the regulator's wording.

For example:

Official status:
Registered under the UK Money Laundering Regulations

Cexvia interpretation:
AML/CTF registration for covered cryptoasset activities.
This should not be represented as broader FSMA authorisation.

That is more precise than changing every record into:

Licensed: Yes

A practical verification workflow

Start from:

  • Terms of service
  • Legal page
  • Account agreement
  • Privacy policy
  • Deposit instructions

Copy the full legal name.

Do not begin with the brand alone.

Step 2 — Identify the claimed regulatory status

Record exactly what the exchange says.

For example:

"Registered with FinCEN as an MSB"

Do not immediately translate that into:

"US licensed exchange"

Step 3 — Open the regulator's official register

Search using:

  • Legal entity
  • Reference number
  • Brand
  • Domain

Prefer the regulator's own website over screenshots or certificates hosted by the exchange.

Step 4 — Read the entire record

Check:

  • Status
  • Dates
  • Legal entity
  • Address
  • Services
  • Conditions
  • Customer type
  • Territory
  • Approved domains
  • Restrictions

Step 5 — Match the account agreement

Confirm that the entity in the register is the same entity that contracts with the user.

If not, investigate further.

Step 6 — Match the intended product

Ask:

Does this exact permission cover what I plan to do?

Do not assume that spot trading, staking, custody and derivatives fall under the same approval.

Step 7 — Search enforcement and warning databases

A currently registered company may still have:

  • Restrictions
  • Enforcement history
  • Consumer warnings
  • Settlement agreements
  • Suspensions

Regulatory verification should include adverse records, not only positive registrations.

Step 8 — Separate other risk dimensions

After confirming regulatory standing, separately evaluate:

  • Corporate transparency
  • Reserves and liabilities
  • Security incidents
  • Custody
  • Withdrawal reliability
  • Operational history
  • User-protection controls

Regulation is one dimension of exchange risk.

Regulatory verification example

Consider a hypothetical platform:

Example Digital

Its website states:

“Registered and fully regulated internationally.”

Investigation finds:

Entity:
Example Digital Ltd

Corporate record:
UK incorporated company

US record:
FinCEN MSB registration

UK record:
FCA MLR registration

Dubai:
No VARA VASP licence found

Products advertised:
Spot trading
Perpetual futures
Custody
Yield products

What can be concluded?

Supported

  • The company exists in the UK.
  • It appears in the relevant US MSB record if independently verified.
  • It appears in the FCA MLR register if independently verified.

Not yet supported

  • That it is authorised to offer perpetual futures everywhere
  • That VARA has licensed it in Dubai
  • That yield products are covered by either registration
  • That every customer contracts with the registered UK company
  • That “fully regulated internationally” accurately describes the group

The verification result is therefore not:

Safe / unsafe

It is:

The identified registrations support specific regulatory claims, but the advertised product and geographic scope require separate verification.

That is the level of precision Cexvia Research should aim for.

Frequently asked questions

What is the difference between a registered and regulated crypto exchange?

There is no universal global distinction based on those two words alone.

A registration can carry substantive regulatory obligations, while “regulated” can refer broadly to an entity or activity being subject to a particular legal framework.

Verify the underlying law, regulator, entity, activity and status.

Is a registered crypto exchange safe?

Registration is useful evidence but does not establish overall safety.

It does not automatically prove solvency, cybersecurity, reliable withdrawals, good custody practices or suitability for a particular user.

Is an MSB registration a crypto licence?

A FinCEN MSB registration should be described as an MSB registration.

FinCEN explicitly states that inclusion in its MSB registration database is not a recommendation, certification of legitimacy or government endorsement.

Additional state or product-specific permissions may also be relevant.

Is FCA crypto registration the same as FCA authorisation?

No.

Under the current UK framework, firms conducting certain cryptoasset activities register under the Money Laundering Regulations.

The FCA has explicitly stated that MLR registration does not guarantee authorisation under the future FSMA cryptoasset regime.

Is a MiCA authorisation stronger than company registration?

They serve different purposes.

Company incorporation establishes legal existence.

MiCA authorisation permits defined crypto-asset services within the regulatory framework and carries regulatory obligations relevant to those services.

Does one licence cover every exchange product?

No.

Permissions can differ by legal entity, activity, territory and customer type.

Spot trading, custody, derivatives, lending and other products may fall under different permissions.

Does a regulated exchange mean customer crypto is insured?

No.

Regulation and insurance are separate questions.

Any deposit insurance, investor-compensation coverage or private insurance must be verified according to the exact asset, account structure and applicable scheme.

How can I verify a crypto exchange licence?

Start with the legal entity in the account agreement, search the regulator's official register, confirm the reference number and status, then check the permitted activities, territory, customer type and approved domain.

Conclusion

The distinction between registered, licensed, authorised and regulated is not about finding the strongest-sounding word.

It is about determining what the official record actually proves.

A credible crypto exchange regulatory assessment should connect:

brand → legal entity → regulator → record type → legal basis → jurisdiction → activity → customer scope → status → domain

If one link is missing, the claim may be broader than the evidence.

Company incorporation proves legal existence.

AML or MSB registration can establish regulatory obligations within a defined scope.

A licence or authorisation can permit specified financial or crypto-asset activities.

“Regulated” describes the existence of a regulatory framework but should never replace the details of that framework.

For users, the safest approach is to ignore regulatory badges and verify the underlying record directly.

For Cexvia, the correct approach is the same: preserve the regulator's actual terminology, map every permission to the correct legal entity and jurisdiction, and avoid converting narrow registrations into global “licensed” labels.


Primary sources and Cexvia resources


*Cexvia evaluates centralized exchanges using publicly verifiable evidence across regulatory standing, corporate transparency, asset and solvency transparency, security history, and operations and user protection. Regulatory records are mapped to their legal entity, jurisdiction and documented scope. Ratings are evidence-based risk assessments, not guarantees of safety or recommendations to deposit or trade.*