Accountability usually sits with executive leadership, compliance, risk, and market surveillance owners, not just the trading platform team. If incentives or weak monitoring allow deceptive volume to persist, governance must address design decisions, control failures, and disclosure obligations. Organisations should document who approves reward schemes, who monitors abuse, and who can halt risky programmes.
Why This Matters for Security Teams
Artificial volume is not just a product integrity problem. When a crypto exchange permits inflated activity to shape user decisions, it becomes a governance, disclosure, and control accountability issue across leadership, compliance, surveillance, and risk management. In practice, the failure usually starts with incentives that reward growth or engagement without equally strong controls for market integrity, exception handling, and escalation. The question is therefore less about who operated the platform and more about who owned the decision to allow the practice to continue.
That accountability lens is consistent with broader identity and control failures seen in high-risk environments. NHI Management Group notes in the Ultimate Guide to NHIs that 97% of NHIs carry excessive privileges and that 80% of identity breaches involved compromised non-human identities such as service accounts and API keys. Those figures matter here because deceptive volume often persists when automated systems, privileged workflows, or internal tools are not constrained by clear ownership and oversight. Control design must answer who can approve, who can detect, and who can stop misleading activity. In practice, many security teams encounter the accountability gap only after users, auditors, or regulators have already questioned the volume patterns.
How It Works in Practice
Accountability should be mapped across three layers: decision owners, operational control owners, and independent assurance. Decision owners approve incentive schemes, promotional campaigns, or liquidity programmes that could distort market perception. Operational control owners run surveillance, detect wash-like patterns, monitor anomalies, and preserve logs. Independent assurance reviews whether the controls are actually capable of stopping deception before it reaches users or investors.
A practical control model should tie each artificial-volume risk to a named owner and a response path. For example, if a reward programme increases transaction counts, the business owner should document the objective, the compliance team should approve the disclosure language, and the surveillance function should monitor for abuse. If a market-making arrangement is used, the exchange should be able to show what activity is permitted, what is prohibited, and who can suspend the programme when patterns become misleading.
Useful control questions include:
- Who approved the incentive or liquidity design before launch?
- What thresholds trigger review of suspicious volume concentration?
- Who can halt the programme without waiting for product approval?
- How are disclosures aligned to actual trading conditions?
- Which logs and reports preserve evidence for audits or investigations?
For identity and access discipline, the underlying principle is the same as in NIST SP 800-53 Rev 5 Security and Privacy Controls: control ownership must be explicit, reviews must be repeatable, and suspicious activity must be traceable to a responsible function. Exchanges with weak segregation of duties or unclear escalation paths tend to discover the problem too late because the same team that benefits from volume is also the team expected to police it.
Current guidance suggests that governance should treat misleading volume as a control failure, not merely a reputational issue. That means retention of evidence, documented approvals, and periodic testing of whether surveillance can actually identify manipulative patterns. These controls tend to break down in high-velocity exchanges with heavy promotional pressure because commercial urgency overrides escalation and evidence preservation.
Common Variations and Edge Cases
Tighter surveillance often increases operational friction, requiring organisations to balance growth targets against market integrity and regulatory risk. That tradeoff becomes sharper when the exchange uses outsourced market making, affiliate promotions, token incentives, or multi-jurisdiction operations, because accountability can fragment across legal entities and vendors.
There is no universal standard for this yet, but best practice is evolving toward named accountability for the programme owner, the compliance approver, and the monitoring function. If a third party is involved, the exchange still remains responsible for disclosure quality and for ensuring the arrangement does not mislead users. The fact that a vendor generated the volume does not remove accountability from the exchange leadership that authorised or tolerated the programme.
Some cases are also harder to judge than outright manipulation. For example, legitimate market-making, test environments, or incentive-based liquidity can create elevated volume without deceptive intent. In those scenarios, the burden shifts to whether the exchange disclosed the programme clearly, whether surveillance could distinguish benign from abusive behaviour, and whether leadership acted quickly once risks emerged. The accountability test is simple: if the exchange knew or should have known that the activity could mislead users, governance must show who had authority to stop it and why they did or did not use it. In practice, failures are usually exposed by regulators or complaints after the volume has already shaped buying decisions.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.OV-01 | Oversight governance fits misleading-volume accountability and board-level control ownership. |
| NIST SP 800-63 | Digital identity assurance supports traceability of who approved or operated risky workflows. | |
| NIST AI RMF | AI RMF governance principles help structure accountability for automated or algorithmic volume generation. | |
| OWASP Non-Human Identity Top 10 | NHI-01 | Privileged automation and service identities can enable hidden abuse if ownership is unclear. |
| CSA MAESTRO | Agentic governance patterns apply where automated systems affect trading or market signals. |
Treat autonomous trading or promotion tools as governed workloads with runtime controls and escalation.
Related resources from NHI Mgmt Group
- Who should be accountable when identity verification data is stored in a way that allows unauthorized access or tampering?
- Who is accountable when false partnerships or credentials are used to solicit investors?
- Who is accountable when a peer-to-peer lending platform exceeds its permitted role or misleads users?
- Who is accountable when a crypto exchange account is taken over through recovery abuse?