An over the counter broker arranges private trades between buyers and sellers outside a public exchange order book. In crypto, OTC brokers can help move large blocks with less visible market impact, but weaker identity checks and limited transparency can also make them attractive channels for laundering illicit funds.
Expanded Definition
An over the counter broker sits outside a public exchange order book and matches buyers and sellers directly, usually for size, speed, confidentiality, or price discovery. In crypto and other digital asset markets, that private routing can reduce visible slippage, but it also reduces public transparency.
The term is often used for intermediaries who source counterparties, negotiate settlement terms, and arrange transfer mechanics rather than publishing bids and offers on an exchange. That distinction matters: an OTC broker is not simply a market maker, and it is not the same as a custody provider. The broker may facilitate the trade, but the asset movement, settlement, and compliance controls can sit elsewhere in the workflow.
Usage varies across jurisdictions and firms. Some desks apply the label to fully manual high-touch brokerage, while others include algorithmic RFQ platforms or private liquidity networks. For practitioners, the common misunderstanding is assuming “private” means “low risk.” In reality, private routing can concentrate trust in fewer controls, fewer counterparties, and less public auditability.
Examples and Use Cases
OTC brokerage appears in several common workflows where public exchange execution would be inefficient or undesirable:
- Large crypto block trades that would move the market if posted to a visible order book.
- Institutional treasury conversions, where a buyer wants a quoted price and a scheduled settlement window.
- Cross-border liquidity moves, where the broker helps coordinate counterparties across time zones and venues.
- High-discretion transactions where counterparties prefer limited market signalling and less public exposure.
- Private matching for illiquid tokens or thinly traded assets that do not fill well on open venues.
These use cases share a tradeoff: they can improve execution for size and privacy, but they also make diligence, counterparty verification, and settlement assurance more important. A private channel is only as safe as the onboarding, screening, and transfer controls around it.
Security Implications
The main security issue with OTC brokerage is not the trade format itself, but the reduced visibility and increased trust concentration that often come with it. When a broker operates with weak identity checks, incomplete recordkeeping, or loose source-of-funds review, the channel can be used to obscure beneficial ownership or move illicit proceeds with less friction.
That creates practical failure modes for compliance teams, exchanges, and counterparties. Suspicious activity may be harder to spot because there is no public order book trail to inspect, and post-trade evidence may be fragmented across messaging, off-platform settlement, and third-party custodians. If the broker does not maintain strong audit trails, investigators may struggle to reconstruct who approved the trade, who controlled the funds, and where value ultimately settled.
Failure mechanism: weak onboarding and limited transparency make it easier to pass bad actors through a trusted private channel, especially when screening is inconsistent across counterparties or jurisdictions.
Impact: exposure can include sanctions, AML, fraud, and reputational damage, plus delayed detection when a brokered trade is later tied to illicit activity.
Security, Operational and Governance Implications
From an operational standpoint, OTC brokers are governance-heavy intermediaries. They depend on strong client due diligence, transaction monitoring, reconciliation discipline, and clear responsibility for settlement errors. If any of those controls is ambiguous, the broker becomes a single point where privacy, execution quality, and compliance risk intersect.
For crypto markets in particular, the sensitive issue is that private execution can bypass the visibility that helps market surveillance and controls. That does not make OTC activity inherently improper, but it means governance must compensate for the missing public signal. Documentation, approval workflows, and post-trade review need to be tighter than a casual “off-exchange” label suggests.
A useful practitioner lens is to treat the broker as both a market intermediary and a control boundary. The more discretion the broker has over who can trade, how orders are matched, and how funds are settled, the more important it becomes to test the broker’s controls rather than assuming the private format is self-protecting.
Risk and Threat Considerations
OTC brokerage creates a material risk surface because it combines financial transfer, counterparty trust, and reduced market visibility. That combination is attractive to actors who want to hide source, destination, or intent, especially where the broker’s compliance checks are weak or uneven.
Failure mechanism: attackers or illicit actors can abuse the private execution path to place trades that avoid public scrutiny, while weak recordkeeping and fragmented settlement reduce the chance of timely detection or attribution.
Impact: organisations can face AML and sanctions exposure, disputed settlements, fraud losses, and regulatory scrutiny if a brokered transaction cannot be reconstructed cleanly after the fact.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 and CIS Controls v8 set the technical controls, while PCI DSS v4.0 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.OC — Organisational Context | OTC brokers operate as governed market intermediaries with compliance and trust dependencies. |
| PR.AA — Identity Management, Authentication and Access Control | OTC brokerage depends on strong client verification and controlled transaction authority. | |
| DE.CM — Continuous Monitoring | Private trade paths need monitoring because they lack public order-book visibility. | |
| Recommendation — Define OTC brokerage oversight, ownership, and acceptable-use boundaries. Enforce identity verification and access controls before brokered trade approval. Monitor brokered activity for anomalous trade patterns, settlement behavior, and compliance alerts. | ||
| CIS Controls v8 | 6 — Access Control Management | Brokered transactions need tight authorization for counterparties, settlement rights, and approvals. |
| 8 — Audit Log Management | OTC trades require durable logs to reconstruct private matching and settlement events. | |
| Recommendation — Restrict trade and settlement permissions to approved, verified participants. Retain tamper-resistant logs for matching, approvals, and settlement steps. | ||
| PCI DSS v4.0 | 10 — Log and Monitor All Access to System Components and Cardholder Data | Where OTC operations touch payment or card data, the private workflow needs traceable activity records. |
| Recommendation — Log and review access and transaction activity across the brokered workflow. | ||