Warning signs include operating without approval, weak customer onboarding, missing risk assessments, incomplete transaction monitoring, poor record keeping, and failure to collect sender and recipient data above the Travel Rule threshold. Another red flag is outdated governance, such as no MLRO, no documented SOPs, or cloud and API controls that are not clearly secured and tested.
How to recognise a compliance gap before it becomes an enforcement issue
The strongest indicator is not a single missing document, it is a pattern of weak control design. For a crypto exchange or trader, compliance expectations are being missed when approval status is unclear, onboarding is too shallow to establish who the customer is, and the firm cannot show that it applies risk-based checks consistently across accounts, counterparties, and transaction flows.
That matters because compliance for digital-asset activity is operational, not cosmetic. A firm can look active and still fail if it cannot evidence how it screens customers, applies thresholds, flags suspicious activity, and retains records in a way that supports auditability and regulatory review.
One useful way to read the signal is to ask whether the organisation can explain its control decisions, not just claim that controls exist. If the answer depends on informal practice, ad hoc analyst judgement, or undocumented exceptions, the compliance posture is already fragile.
Where weak onboarding, monitoring, and recordkeeping show up
Customer onboarding is often the first place to look because it reveals whether the exchange is collecting enough information to establish risk and ownership. If the firm cannot demonstrate customer identification, beneficial ownership checks where applicable, or a consistent risk-rating workflow, then later monitoring becomes unreliable rather than merely incomplete.
Transaction monitoring is the next pressure point. A compliant programme should be able to detect unusual transfers, trigger review on suspicious patterns, and retain a defensible trail of decisions. Missing monitoring, or monitoring that exists only on paper, usually means the organisation cannot connect activity to risk-based escalation or investigation outcomes.
Recordkeeping is equally important because it shows whether the firm can reconstruct what happened after the fact. In practice, poor retention, scattered spreadsheets, and absent case notes are warning signs that the operation may be unable to support investigation, reporting, or regulator challenge when it matters most.
Why governance, Travel Rule data, and technical controls are part of the test
Governance gaps are often visible in the supporting operating model. If there is no MLRO, no documented SOPs, no clear ownership for reviews, or no evidence that key cloud and API controls are tested, the business may be unable to sustain compliance at scale even if individual staff are trying to do the right thing.
For digital-asset businesses, the Travel Rule adds another practical check because sender and recipient information must be collected and handled consistently once the threshold is reached. Failure here is not just a paperwork issue, it usually indicates that the firm has not operationalised data capture, validation, and handoff across its transaction flow.
Technical control weakness can also be a compliance sign when it undermines monitoring integrity or evidence quality. If cloud access, API authentication, logging, and change control are not clearly governed, the firm may be unable to prove that customer data, transaction events, and reporting logic are trustworthy enough for compliance use.
Risk and Threat Considerations
Compliance gaps in a crypto exchange are risky because they create both regulatory exposure and abuse potential. Weak onboarding, poor monitoring, and thin recordkeeping make it easier for bad actors to move value through the platform, obscure source or destination relationships, or exploit inconsistent control execution.
Failure mechanism: Controls fail when onboarding does not establish a reliable customer profile, when monitoring does not surface suspicious patterns, or when governance and technical logging cannot support a defensible review trail. That combination breaks the chain from activity to detection to escalation.
Impact: The firm can face enforcement action, loss of banking or counterparties, higher fraud and laundering exposure, and a degraded ability to prove compliance during audit or investigation. Once evidence quality is poor, remediation becomes slower and more expensive because the organisation must rebuild trust as well as controls.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP API Security Top 10 addresses the attack and risk surface, while NIST SP 800-53 Rev 5 and CSA Cloud Controls Matrix set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AU-2 — Audit Events | Transaction monitoring and recordkeeping depend on defining and capturing the right events. |
| AU-6 — Audit Record Review, Analysis, and Reporting | Compliance gaps often appear when suspicious activity is not reviewed and escalated from logs. | |
| AC-2 — Account Management | Weak onboarding and poor ownership tracking are account-lifecycle control failures. | |
| Recommendation — Define auditable events for onboarding, monitoring, and escalation so compliance reviews have evidence. Review audit records routinely and escalate suspicious patterns into documented investigations. Enforce account lifecycle controls so access, ownership, and approval status stay current. | ||
| OWASP API Security Top 10 | API2 — Broken Authentication | API and cloud control weakness can undermine trusted access and reporting integrity. |
| Recommendation — Harden API authentication so platform actions and data access are reliably attributable. | ||
| CSA Cloud Controls Matrix | IAM — Identity & Access Management | Cloud and API control gaps are materially part of the governance and access posture. |
| Recommendation — Apply IAM controls to cloud and API paths that support compliance operations and evidence. | ||
Practitioner Guidance
What to verify: Start with whether the firm can produce a clean control story for one real customer or trader account, from onboarding through monitoring to retention. If any step cannot be evidenced with named owners, timestamps, or case records, treat that as a compliance weakness rather than a documentation issue.
Decision rule: If the exchange cannot show consistent approval status, risk assessment, transaction monitoring, and Travel Rule data handling, prioritise control remediation over product expansion or customer growth. A business that cannot evidence its control baseline will struggle to defend volume or complexity.
Practitioner takeaway: The key signal is not whether a control is described in policy, but whether the organisation can execute it consistently and prove it after the fact.
Related resources from NHI Mgmt Group
- What are the main signs that a crypto compliance programme is not meeting Turkey’s requirements?
- How should security teams govern non-human identities for compliance?
- How should security teams govern non-human identities for SOC 2 compliance?
- Why do non-human identities create compliance risk even when policies exist?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 24, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org