“Registered,” “licensed,” “authorised” and “regulated” are often used as if they mean the same thing.
They do not.
They also do not form a universal hierarchy in which “registered” always means weak oversight and “licensed” always means strong oversight.
The meaning depends on:
- The jurisdiction
- The law creating the regime
- The regulator
- The legal entity
- The activity covered
- The customer type
- The current status of the permission
A crypto exchange may be incorporated as a company, registered for anti-money-laundering supervision, licensed for a specific virtual-asset activity, authorised under a broader financial-services regime, or subject to several of these at the same time.
The correct question is therefore not:
Is this exchange registered or regulated?
It is:
Which legal entity appears in which official record, under which legal regime, for which activities, in which jurisdiction, and with what current status?
That is the approach Cexvia uses when evaluating exchange regulatory standing.
The short answer
The four terms below should be separated.
| Term | What it can mean | What you still need to verify |
|---|---|---|
| Company registered / incorporated | A legal company exists in a corporate registry | Whether it has financial-services permission |
| AML / VASP / MSB registered | The entity is registered under an AML or virtual-asset regime | Whether the regime authorises the specific financial service |
| Licensed / authorised | A regulator has granted permission for defined activities | Entity, territory, customer type, product scope and licence conditions |
| Regulated | The entity or activity is subject to a regulatory framework | Which framework, which entity and what level of supervision applies |
None of these words should be evaluated without the underlying official record.
“Regulated” is not one universal legal status
“Regulated exchange” is a useful descriptive phrase, but it is not a globally standardised licence category.
A business can be regulated because it is subject to:
- AML and counter-terrorist-financing rules
- Payment-services regulation
- Crypto-asset service-provider rules
- Securities regulation
- Derivatives regulation
- Custody requirements
- Consumer-protection obligations
- Prudential requirements
- Market-abuse rules
Two exchanges can both accurately describe part of their operations as regulated while operating under very different obligations.
This is why Cexvia does not convert the word regulated into a binary yes/no safety label.
The underlying record matters more than the marketing terminology.
Four records that are commonly confused
1. Company incorporation
A corporate registry can establish that a company legally exists.
Typical fields include:
- Legal name
- Company number
- Formation date
- Registered address
- Directors
- Corporate status
This can be valuable when identifying the company behind an exchange.
It does not, by itself, establish permission to:
- Hold customer fiat
- Custody crypto
- Operate a trading venue
- Offer derivatives
- Provide staking
- Offer investment products
- Serve customers in a particular jurisdiction
A genuine certificate of incorporation can therefore be used in a misleading way.
Fraudulent platforms sometimes present a normal company-registration certificate as if it were a financial licence.
The document may be real while the claim made about it is false.
2. AML, MSB or VASP registration
Some jurisdictions require crypto businesses to register under anti-money-laundering or virtual-asset rules.
The strength of these regimes varies.
They may require:
- Customer due diligence
- AML policies
- Suspicious transaction reporting
- Governance controls
- Fit-and-proper assessments
- Recordkeeping
- Compliance personnel
But the existence of a registration does not automatically establish prudential safety, solvency or permission for every product.
3. Financial-services licence or authorisation
A licence or authorisation usually grants permission to conduct defined regulated activities.
Depending on the jurisdiction, those activities may include:
- Operating a crypto trading platform
- Exchange services
- Brokerage
- Transfer services
- Custody
- Lending
- Staking
- Derivatives
- Payment services
A licence can also carry conditions relating to:
- Capital
- Governance
- Cybersecurity
- Client-asset safeguarding
- Reporting
- Complaints
- Audits
- Market conduct
But even a genuine licence remains limited by its legal scope.
4. Regulatory supervision
“Regulated” can describe an entity that is subject to ongoing rules and supervision.
The depth of supervision can vary significantly.
Some regimes focus primarily on AML obligations.
Others impose broader operational, prudential, governance and customer-protection requirements.
This makes the underlying legal regime more important than the label itself.
Example 1: US FinCEN MSB registration
In the United States, many virtual-currency businesses fall within the Money Services Business framework administered by the Financial Crimes Enforcement Network.
FinCEN's MSB Registration website explicitly states that inclusion in the database is not a recommendation, certification of legitimacy or endorsement by a government agency.
That distinction is important.
An MSB registration can establish that an entity appears in the federal registration system and is subject to applicable Bank Secrecy Act obligations.
It does not establish that:
- The exchange is solvent
- Customer crypto is insured
- Every state permits the service
- The SEC has approved the platform
- The CFTC has authorised its derivatives
- Every token offered is lawful for every customer
- The business has been endorsed by the US government
US state licensing is a separate layer.
New York has an additional virtual-currency regulatory framework.
Therefore:
FinCEN registration should be recorded as FinCEN registration—not converted into a generic “US crypto licence.”
Official reference:
FinCEN — MSB Registration Website
Example 2: UK crypto registration is changing
The United Kingdom is a particularly useful example of why terminology must be tied to the applicable law and date.
Cryptoasset businesses carrying on certain in-scope activities in the UK currently need to register with the Financial Conduct Authority under the Money Laundering Regulations.
The FCA states that MLR registration is a legal requirement for covered cryptoasset businesses and is not a recommendation or endorsement.
In 2026, the UK is also preparing a broader Financial Services and Markets Act authorisation regime for cryptoasset activities.
The FCA has explicitly stated:
- An MLR registration application is not an FSMA authorisation application.
- Being registered under the MLRs does not guarantee future authorisation under FSMA.
- Firms conducting activities covered by the future regime will need the relevant FSMA permission.
The new regime is scheduled to apply to authorised cryptoasset firms from 25 October 2027.
This is a useful real-world illustration:
UK MLR registration
≠
future FSMA authorisationBoth statuses are regulatory.
They simply represent different legal regimes and different scopes.
Official references:
- FCA — Cryptoassets: AML / CTF regime
- FCA — Registration under the MLRs ahead of the new FSMA regime
- FCA — How the new cryptoasset gateway will operate
Example 3: EU MiCA authorisation
The European Union's Markets in Crypto-Assets Regulation provides a harmonised regulatory framework for crypto-assets and crypto-asset service providers that fall within its scope.
MiCA introduces requirements covering areas including:
- Authorisation
- Governance
- Operations
- Prudential safeguards
- Customer information
- Market integrity
A Crypto-Asset Service Provider authorisation under MiCA is therefore structurally different from a simple company-registration record.
However, even MiCA authorisation must still be read by scope.
A CASP may be authorised for particular services such as:
- Custody and administration
- Operating a trading platform
- Exchange of crypto-assets for funds
- Exchange of crypto-assets for other crypto-assets
- Execution of orders
- Placement
- Transfer services
- Advice
- Portfolio management
The question remains:
Which entity is authorised for which crypto-asset services?
The existence of a MiCA authorisation should not be stretched to an affiliate that is not named in the regulator's record.
Official references:
Example 4: Dubai VARA licensing
Dubai provides another clear example of activity-level licensing.
The Virtual Assets Regulatory Authority maintains a public register of Virtual Asset Service Providers.
VARA's public register can distinguish between firms that are:
- Fully licensed
- Holding an In-Principle Approval
It also identifies the services that a VASP is authorised to provide.
VARA states that firms conducting virtual-asset activities in or from Dubai, excluding the DIFC, need the required VARA licence before commencing regulated activity.
A VASP may be licensed for multiple activities, but the permitted services still need to be checked.
This means:
Company appears in VARA register
↓
Check status
↓
Check licensed activities
↓
Check legal entity
↓
Check whether the user's product is within scopeOfficial references:
Registration is not automatically “weak”
A common mistake is to assume:
Registration = weak
Licence = strongThat is too simplistic.
Some registration regimes involve substantial regulatory review, governance assessment and ongoing compliance requirements.
At the same time, some licences cover only narrow activities.
The useful comparison is not the word used by the regulator.
It is the regulatory substance behind the record.
A better framework is:
| Question | Why it matters |
|---|---|
| What law creates the status? | Defines the regulatory obligations |
| Which regulator issued or maintains it? | Identifies the supervising authority |
| Which legal entity holds it? | Prevents group-level overstatement |
| What activities are covered? | Determines product scope |
| Which territory is covered? | Determines geographic relevance |
| Which customer types are covered? | Retail and institutional permissions may differ |
| What is the status? | Active, restricted, suspended, revoked or pending matter differently |
| Is supervision ongoing? | A one-time filing may differ from continuous supervisory obligations |
This is more reliable than ranking terms by their wording.
“Licensed” also does not mean “everything is licensed”
A group can contain several affiliates.
For example:
Exchange Group
├── Entity A — Spot exchange
├── Entity B — Custody
├── Entity C — Derivatives
├── Entity D — Payments
└── Entity E — Institutional servicesIf Entity C holds a derivatives licence, that does not automatically license Entity A's spot trading service.
Likewise:
- A custody licence does not necessarily authorise derivatives.
- A payment licence does not necessarily authorise crypto trading.
- A broker-dealer licence does not automatically cover ordinary crypto balances.
- A licence in Dubai does not automatically authorise service in the United States.
- A European authorisation does not automatically attach to every website operated by the wider group.
The legal entity is therefore the anchor for licence verification.
Five scope tests every regulatory claim should pass
Cexvia's recommended approach is to test a claim across five boundaries.
1. Entity
Does the name in the regulatory record match the entity named in the user's account agreement?
Check:
- Full legal name
- Company number
- Registered address
- Regulator reference number
A similar brand name is not enough.
2. Jurisdiction
Does the permission apply where the user is located?
A licence can be genuine but irrelevant to a user in another country or state.
3. Activity
Does the record cover the actual service?
Examples:
- Spot trading
- Custody
- Fiat transfer
- Staking
- Lending
- Futures
- Options
- Brokerage
Do not infer one activity from another.
4. Customer type
Some permissions distinguish between:
- Retail customers
- Professional clients
- Institutional customers
- Accredited or eligible investors
A service available to institutions is not automatically authorised for retail users.
5. Status
Check whether the record is:
- Active
- Restricted
- Suspended
- Revoked
- Withdrawn
- Expired
- Pending
- In-principle only
The status can be as important as the licence itself.
Domain matching is also important
A valid regulatory record can still be misused by a cloned or impersonating website.
Imagine a real company called:
Example Digital Assets Ltd
It holds a legitimate regulatory record.
A scammer then creates:
example-digital-profit.comand copies:
- The company's name
- Registration number
- Certificate image
- Office address
- Regulator logo
The record is real.
The website is not.
This is why a complete verification should compare:
domain
+
legal entity
+
regulator record
+
account agreement
+
contact detailsIf the regulator publishes approved domains, compare those as well.
Incorporation certificates are not financial licences
A certificate of incorporation can be useful evidence of legal identity.
But it does not establish that the company has permission to provide financial or crypto services.
Red flags include websites describing:
- Companies House incorporation
- State company registration
- Tax registration
- Business licence
- Chamber of commerce membership
as if they were proof of financial regulation.
A legitimate corporate registration should be classified as:
corporate identity evidence
not:
financial-services authorisation
Proof of Reserves is also not a licence
Proof of Reserves belongs to a separate category of evidence.
It may provide transparency about specified assets or balances at a particular point in time.
It does not create regulatory permission to operate.
It also should not automatically be equated with a complete financial-statement audit.
The SEC has previously cautioned that non-audit crypto assurance arrangements may not provide the same level of assurance as a financial-statement audit.
This means Cexvia should keep these dimensions separate:
Regulatory standing
≠
Asset / solvency transparency
≠
Security history
≠
Corporate transparencyA strong score in one dimension does not automatically resolve risks in another.
Official reference:
SEC — The Potential Pitfalls of Purported Crypto “Assurance” Work
Registration does not mean customer assets are insured
Another common marketing leap is:
Registered / regulated
→
customer assets are insuredThat conclusion is not valid without additional evidence.
Insurance and compensation depend on:
- Asset type
- Account structure
- Custodian
- Bank arrangement
- Applicable law
- Policy terms
- Customer category
For example, eligible fiat deposits at a qualifying insured bank can be treated differently from crypto assets held directly by an exchange.
A related broker-dealer may also have protections that do not extend to the brand's ordinary crypto trading account.
Regulatory status and asset protection should therefore be verified independently.
Common misleading regulatory claims
Treat the following phrases as claims that require additional evidence:
- “Fully regulated”
- “Globally regulated”
- “Government approved”
- “Internationally licensed”
- “Registered in the United States”
- “FinCEN licensed”
- “EU licensed”
- “FCA approved”
- “VARA approved”
- “MiCA compliant”
- “Licensed in 50 states”
These statements may be:
- Accurate
- Partly accurate
- Outdated
- Attached to the wrong entity
- Limited to one activity
- Limited to one jurisdiction
- Based on a registration that is being described too broadly
The response should be verification, not assumption.
How Cexvia should classify regulatory evidence
Cexvia should preserve the regulator's actual terminology wherever possible.
Recommended fields:
| Field | Example |
|---|---|
| Exchange | Example Exchange |
| Legal entity | Example Digital Assets Ltd |
| Jurisdiction | United Kingdom |
| Regulator | Financial Conduct Authority |
| Record type | MLR cryptoasset registration |
| Licence / reference number | 123456 |
| Activity | Cryptoasset exchange provider |
| Customer scope | As stated in official record |
| Status | Registered / Active |
| Effective date | YYYY-MM-DD |
| Approved domain | If published |
| Source | Regulator's official register |
| Cexvia interpretation | AML registration; not equivalent to broader FSMA authorisation |
The Cexvia interpretation should explain scope without replacing the regulator's wording.
For example:
Official status:
Registered under the UK Money Laundering Regulations
Cexvia interpretation:
AML/CTF registration for covered cryptoasset activities.
This should not be represented as broader FSMA authorisation.That is more precise than changing every record into:
Licensed: YesA practical verification workflow
Step 1 — Identify the legal entity
Start from:
- Terms of service
- Legal page
- Account agreement
- Privacy policy
- Deposit instructions
Copy the full legal name.
Do not begin with the brand alone.
Step 2 — Identify the claimed regulatory status
Record exactly what the exchange says.
For example:
"Registered with FinCEN as an MSB"Do not immediately translate that into:
"US licensed exchange"Step 3 — Open the regulator's official register
Search using:
- Legal entity
- Reference number
- Brand
- Domain
Prefer the regulator's own website over screenshots or certificates hosted by the exchange.
Step 4 — Read the entire record
Check:
- Status
- Dates
- Legal entity
- Address
- Services
- Conditions
- Customer type
- Territory
- Approved domains
- Restrictions
Step 5 — Match the account agreement
Confirm that the entity in the register is the same entity that contracts with the user.
If not, investigate further.
Step 6 — Match the intended product
Ask:
Does this exact permission cover what I plan to do?
Do not assume that spot trading, staking, custody and derivatives fall under the same approval.
Step 7 — Search enforcement and warning databases
A currently registered company may still have:
- Restrictions
- Enforcement history
- Consumer warnings
- Settlement agreements
- Suspensions
Regulatory verification should include adverse records, not only positive registrations.
Step 8 — Separate other risk dimensions
After confirming regulatory standing, separately evaluate:
- Corporate transparency
- Reserves and liabilities
- Security incidents
- Custody
- Withdrawal reliability
- Operational history
- User-protection controls
Regulation is one dimension of exchange risk.
Regulatory verification example
Consider a hypothetical platform:
Example Digital
Its website states:
“Registered and fully regulated internationally.”
Investigation finds:
Entity:
Example Digital Ltd
Corporate record:
UK incorporated company
US record:
FinCEN MSB registration
UK record:
FCA MLR registration
Dubai:
No VARA VASP licence found
Products advertised:
Spot trading
Perpetual futures
Custody
Yield productsWhat can be concluded?
Supported
- The company exists in the UK.
- It appears in the relevant US MSB record if independently verified.
- It appears in the FCA MLR register if independently verified.
Not yet supported
- That it is authorised to offer perpetual futures everywhere
- That VARA has licensed it in Dubai
- That yield products are covered by either registration
- That every customer contracts with the registered UK company
- That “fully regulated internationally” accurately describes the group
The verification result is therefore not:
Safe / unsafe
It is:
The identified registrations support specific regulatory claims, but the advertised product and geographic scope require separate verification.
That is the level of precision Cexvia Research should aim for.
Frequently asked questions
What is the difference between a registered and regulated crypto exchange?
There is no universal global distinction based on those two words alone.
A registration can carry substantive regulatory obligations, while “regulated” can refer broadly to an entity or activity being subject to a particular legal framework.
Verify the underlying law, regulator, entity, activity and status.
Is a registered crypto exchange safe?
Registration is useful evidence but does not establish overall safety.
It does not automatically prove solvency, cybersecurity, reliable withdrawals, good custody practices or suitability for a particular user.
Is an MSB registration a crypto licence?
A FinCEN MSB registration should be described as an MSB registration.
FinCEN explicitly states that inclusion in its MSB registration database is not a recommendation, certification of legitimacy or government endorsement.
Additional state or product-specific permissions may also be relevant.
Is FCA crypto registration the same as FCA authorisation?
No.
Under the current UK framework, firms conducting certain cryptoasset activities register under the Money Laundering Regulations.
The FCA has explicitly stated that MLR registration does not guarantee authorisation under the future FSMA cryptoasset regime.
Is a MiCA authorisation stronger than company registration?
They serve different purposes.
Company incorporation establishes legal existence.
MiCA authorisation permits defined crypto-asset services within the regulatory framework and carries regulatory obligations relevant to those services.
Does one licence cover every exchange product?
No.
Permissions can differ by legal entity, activity, territory and customer type.
Spot trading, custody, derivatives, lending and other products may fall under different permissions.
Does a regulated exchange mean customer crypto is insured?
No.
Regulation and insurance are separate questions.
Any deposit insurance, investor-compensation coverage or private insurance must be verified according to the exact asset, account structure and applicable scheme.
How can I verify a crypto exchange licence?
Start with the legal entity in the account agreement, search the regulator's official register, confirm the reference number and status, then check the permitted activities, territory, customer type and approved domain.
Conclusion
The distinction between registered, licensed, authorised and regulated is not about finding the strongest-sounding word.
It is about determining what the official record actually proves.
A credible crypto exchange regulatory assessment should connect:
brand → legal entity → regulator → record type → legal basis → jurisdiction → activity → customer scope → status → domain
If one link is missing, the claim may be broader than the evidence.
Company incorporation proves legal existence.
AML or MSB registration can establish regulatory obligations within a defined scope.
A licence or authorisation can permit specified financial or crypto-asset activities.
“Regulated” describes the existence of a regulatory framework but should never replace the details of that framework.
For users, the safest approach is to ignore regulatory badges and verify the underlying record directly.
For Cexvia, the correct approach is the same: preserve the regulator's actual terminology, map every permission to the correct legal entity and jurisdiction, and avoid converting narrow registrations into global “licensed” labels.
Primary sources and Cexvia resources
- FinCEN — MSB Registration Website
- FinCEN — Money Services Business Registration
- FCA — Cryptoassets: AML / CTF Regime
- FCA — Registration under the MLRs ahead of the new FSMA regime
- FCA — Cryptoasset regulatory gateway
- European Commission — Crypto-assets
- ESMA — Markets in Crypto-Assets Regulation
- VARA — Public Register
- VARA — Licensed Activities
- SEC — The Potential Pitfalls of Purported Crypto “Assurance” Work
- Cexvia Exchange Risk Profiles
- Cexvia Risk Radar
- Cexvia Methodology
*Cexvia evaluates centralized exchanges using publicly verifiable evidence across regulatory standing, corporate transparency, asset and solvency transparency, security history, and operations and user protection. Regulatory records are mapped to their legal entity, jurisdiction and documented scope. Ratings are evidence-based risk assessments, not guarantees of safety or recommendations to deposit or trade.*