Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What are the signs that a crypto exchange…
Governance, Ownership & Risk

What are the signs that a crypto exchange or trader is not meeting Indonesia’s compliance expectations?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 24, 2026 Domain: Governance, Ownership & Risk

Warning signs include operating without approval, weak customer onboarding, missing risk assessments, incomplete transaction monitoring, poor record keeping, and failure to collect sender and recipient data above the Travel Rule threshold. Another red flag is outdated governance, such as no MLRO, no documented SOPs, or cloud and API controls that are not clearly secured and tested.

How to recognise a compliance gap before it becomes an enforcement issue

The strongest indicator is not a single missing document, it is a pattern of weak control design. For a crypto exchange or trader, compliance expectations are being missed when approval status is unclear, onboarding is too shallow to establish who the customer is, and the firm cannot show that it applies risk-based checks consistently across accounts, counterparties, and transaction flows.

That matters because compliance for digital-asset activity is operational, not cosmetic. A firm can look active and still fail if it cannot evidence how it screens customers, applies thresholds, flags suspicious activity, and retains records in a way that supports auditability and regulatory review.

One useful way to read the signal is to ask whether the organisation can explain its control decisions, not just claim that controls exist. If the answer depends on informal practice, ad hoc analyst judgement, or undocumented exceptions, the compliance posture is already fragile.

Where weak onboarding, monitoring, and recordkeeping show up

Customer onboarding is often the first place to look because it reveals whether the exchange is collecting enough information to establish risk and ownership. If the firm cannot demonstrate customer identification, beneficial ownership checks where applicable, or a consistent risk-rating workflow, then later monitoring becomes unreliable rather than merely incomplete.

Transaction monitoring is the next pressure point. A compliant programme should be able to detect unusual transfers, trigger review on suspicious patterns, and retain a defensible trail of decisions. Missing monitoring, or monitoring that exists only on paper, usually means the organisation cannot connect activity to risk-based escalation or investigation outcomes.

Recordkeeping is equally important because it shows whether the firm can reconstruct what happened after the fact. In practice, poor retention, scattered spreadsheets, and absent case notes are warning signs that the operation may be unable to support investigation, reporting, or regulator challenge when it matters most.

Why governance, Travel Rule data, and technical controls are part of the test

Governance gaps are often visible in the supporting operating model. If there is no MLRO, no documented SOPs, no clear ownership for reviews, or no evidence that key cloud and API controls are tested, the business may be unable to sustain compliance at scale even if individual staff are trying to do the right thing.

For digital-asset businesses, the Travel Rule adds another practical check because sender and recipient information must be collected and handled consistently once the threshold is reached. Failure here is not just a paperwork issue, it usually indicates that the firm has not operationalised data capture, validation, and handoff across its transaction flow.

Technical control weakness can also be a compliance sign when it undermines monitoring integrity or evidence quality. If cloud access, API authentication, logging, and change control are not clearly governed, the firm may be unable to prove that customer data, transaction events, and reporting logic are trustworthy enough for compliance use.

Risk and Threat Considerations

Compliance gaps in a crypto exchange are risky because they create both regulatory exposure and abuse potential. Weak onboarding, poor monitoring, and thin recordkeeping make it easier for bad actors to move value through the platform, obscure source or destination relationships, or exploit inconsistent control execution.

Failure mechanism: Controls fail when onboarding does not establish a reliable customer profile, when monitoring does not surface suspicious patterns, or when governance and technical logging cannot support a defensible review trail. That combination breaks the chain from activity to detection to escalation.

Impact: The firm can face enforcement action, loss of banking or counterparties, higher fraud and laundering exposure, and a degraded ability to prove compliance during audit or investigation. Once evidence quality is poor, remediation becomes slower and more expensive because the organisation must rebuild trust as well as controls.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP API Security Top 10 addresses the attack and risk surface, while NIST SP 800-53 Rev 5 and CSA Cloud Controls Matrix set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AU-2 — Audit EventsTransaction monitoring and recordkeeping depend on defining and capturing the right events.
AU-6 — Audit Record Review, Analysis, and ReportingCompliance gaps often appear when suspicious activity is not reviewed and escalated from logs.
AC-2 — Account ManagementWeak onboarding and poor ownership tracking are account-lifecycle control failures.
Recommendation — Define auditable events for onboarding, monitoring, and escalation so compliance reviews have evidence. Review audit records routinely and escalate suspicious patterns into documented investigations. Enforce account lifecycle controls so access, ownership, and approval status stay current.
OWASP API Security Top 10API2 — Broken AuthenticationAPI and cloud control weakness can undermine trusted access and reporting integrity.
Recommendation — Harden API authentication so platform actions and data access are reliably attributable.
CSA Cloud Controls MatrixIAM — Identity & Access ManagementCloud and API control gaps are materially part of the governance and access posture.
Recommendation — Apply IAM controls to cloud and API paths that support compliance operations and evidence.

Practitioner Guidance

What to verify: Start with whether the firm can produce a clean control story for one real customer or trader account, from onboarding through monitoring to retention. If any step cannot be evidenced with named owners, timestamps, or case records, treat that as a compliance weakness rather than a documentation issue.

Decision rule: If the exchange cannot show consistent approval status, risk assessment, transaction monitoring, and Travel Rule data handling, prioritise control remediation over product expansion or customer growth. A business that cannot evidence its control baseline will struggle to defend volume or complexity.

Practitioner takeaway: The key signal is not whether a control is described in policy, but whether the organisation can execute it consistently and prove it after the fact.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 24, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org