Join our Newsletter — 33% off our NHI Course

How should crypto businesses prepare for Indonesia’s regulatory transition from Bappebti to OJK?

Crypto businesses should plan for a two year transition, because supervisory authority is moving from Bappebti to OJK and the regulatory treatment of crypto may change from commodities to securities. The practical response is to review licensing, governance, AML controls, custody arrangements, and disclosure obligations now, so operating models can be adjusted before the new regime takes full effect.

Reading the transition as a regulatory operating-model change

This transition is not just a change of supervisor, it is a change in how crypto activity may be classified, reviewed, and enforced. Businesses should treat the next two years as a window to map current obligations against the likely OJK regime, identify where commodity-style assumptions may no longer hold, and separate what can be preserved from what must be redesigned.

The main operational question is whether your current permissions, product scope, custody model, disclosures, and compliance evidence would still make sense if the activity is judged more like a financial market or securities service. That is the point at which legal structure, governance, and control design stop being back-office issues and become go-live constraints.

A practical transition plan should therefore start with a gap analysis across licensing, entity structure, product classification, customer terms, and control ownership. If a control exists only because the current Bappebti regime requires it, test whether it still works when the supervisory logic changes.

Where licensing, AML, custody, and disclosure are most likely to move

For crypto businesses, the highest-friction areas are usually the ones that touch customer protection and market integrity: licensing, anti-money laundering controls, custody segregation, asset listing standards, and investor disclosure. Those are the places where a commodities framework can be materially different from a securities-style framework.

That means firms should review how onboarding, transaction monitoring, wallet governance, reserve or custody attestations, and conflict management are documented today. If the business cannot show clear responsibility for asset control, screening, recordkeeping, and customer communications, it should assume those weaknesses will be surfaced during the transition.

The safest approach is to align policy language with the operating reality before the regulator forces the issue. Ambiguity between legal entity, platform operator, custodian, and commercial intermediary creates avoidable exposure when the new regime starts asking who is accountable for what.

How to sequence preparation over the transition window

Good preparation is sequential. First, inventory every regulated activity and decide which parts of the current model are dependent on Bappebti assumptions. Next, map those activities to likely OJK expectations, especially where customer assets, marketing claims, or trading permissions could be reinterpreted. Only then should firms change contracts, disclosures, governance committees, and technology controls.

Businesses should also build a decision log for areas where the future treatment is still uncertain. That log helps management show a reasoned transition posture if the rulebook changes faster than the business can re-paper every product and process.

In parallel, internal owners should be assigned now for legal change tracking, compliance implementation, finance and custody reconciliation, and customer communications. Transition risk rises when these activities are split across teams that each assume another function will interpret the final rule.

Risk and Threat Considerations

The main risk is regulatory drift: a business continues operating under old assumptions while the legal treatment of products, custody, or disclosures has already shifted. That can create licensing exposure, remediation cost, customer complaint risk, and, in the worst case, forced suspension or restructuring.

Failure mechanism: Management treats the transition as a future legal event instead of a present operating-model change, so products, controls, and disclosures remain anchored to the wrong supervisory logic.

Impact: The firm can accumulate compliance gaps that are expensive to unwind, especially where customer asset handling, marketing statements, or governance evidence are inconsistent with the new regime.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8 and NIST CSF 2.0 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
ISO/IEC 27001:2022 A.5.31 — Legal, statutory, regulatory and contractual requirements The transition hinges on changing regulatory obligations and evidence of compliance.
A.5.15 — Access control Custody and platform governance depend on clear access and control ownership.
A.5.32 — Intellectual property rights Not directly relevant
Recommendation — Track legal and regulatory changes and update controls, contracts, and disclosures before the regime changes. Review access control ownership across trading, custody, and operational systems.
CIS Controls v8 CIS-17 — Incident Response Management Regulatory transition can trigger response and remediation needs if controls lag.
Recommendation — Prepare a remediation path for control gaps discovered during the transition.
NIST CSF 2.0 GV.RM-01 — Risk Management Strategy The issue is a governance and risk-planning exercise across the transition period.
GV.SC-01 — Supply Chain Risk Management Strategy Custody and third-party dependencies can become material under new supervision.
Recommendation — Define transition risk appetite and assign owners for regulatory change tracking. Map third-party custody and service dependencies before the supervisory change.

Practitioner Guidance

What to prioritise: Start with the parts of the business that are hardest to change later, custody arrangements, customer disclosures, legal entity structure, and AML operating procedures. These usually take longer to rework than policy text, and they are the most likely to determine whether the business can continue operating without interruption.

What to verify: Confirm that each regulated activity has a named owner, a documented legal basis, and evidence that the control design still works if the activity is reclassified. If the answer is unclear for product listing, custody, or customer communications, treat that as a transition blocker rather than a minor documentation issue.

Practitioner takeaway: The businesses that cope best with a supervisor change are the ones that redesign for the likely end state early, instead of waiting for the new regime to define the operating model for them.