Centralized exchange in Micronesia
Order-book exchange that takes custody of user assets and matches trades between users.
CEX is conditionally permitted in Micronesia with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- Customer Due Diligence (CDD): Identify and verify natural persons using reliable independent source documents (government-issued ID, passport, driver's license); for legal entities, verify legal name, form, proof of existence, and senior management.
- Beneficial Ownership: Identify and verify beneficial owners of legal entity customers; take reasonable measures to understand ownership and control structure.
- Purpose and Intended Nature: Understand the purpose and intended nature of the business relationship or transaction.
- Ongoing Monitoring: Conduct ongoing due diligence and transaction scrutiny throughout the business relationship to ensure consistency with customer knowledge and risk profile.
- Risk-Based Approach: Apply enhanced due diligence (EDD) for higher-risk customers (PEPs, high-risk jurisdictions, complex/unusually large transactions).
- Suspicious Transaction Reporting (STR): Report any transaction or attempted transaction giving rise to suspicion of money laundering, terrorist financing, or criminal activity to the FSM FIU — obligation exists regardless of amount.
- No Tipping-Off: Prohibition against informing the customer or any third party that an STR has been filed or an investigation conducted.
- Record-Keeping: Maintain customer identification records (CDD documents), transaction records (amounts, asset types, addresses, timestamps), and business correspondence.
- Travel Rule — Cross-Border Transfers: Collect and transmit originator and beneficiary information for cross-border transfers of USD 1,000 or more.
- Travel Rule — Domestic Transfers: Collect and transmit originator and beneficiary information for domestic transfers of USD 3,000 or more.
- Supervisor: Financial Intelligence Unit (FIU) of the Federated States of Micronesia — the central agency for receiving, analyzing, and disseminating STRs and providing AML/CFT guidance.
Key Restrictions
- VASPs must register and be licensed under the AMLA 2011 (as amended 2020) per FATF Recommendation 15 — no known licensing path has yet been operationalized for crypto exchanges.
- If a token is classified as a security under FSM law (applying U.S. common law Howey Test principles), the exchange would need to comply with general securities exchange/broker-dealer rules — but no such framework is adapted for crypto.
- No specific crypto custody or segregation rules exist; general financial services law may apply if the exchange handles fiat currency (Banking Act 1980).
- No publicly available VASPs have been identified by the authorities in FSM — the regulatory infrastructure, supervision, and enforcement capacity are still being developed.
- The APG has recommended that FSM develop a comprehensive legal and regulatory framework for VAs and VASPs, including registration, licensing, and AML/CFT obligations — this is not yet complete.
Key Risks
- Regulatory Ambiguity: No comprehensive crypto framework exists — the exchange operates in a grey area without clear rules for licensing, custody, market conduct, or listing.
- Enforcement Exposure: The FSM has limited capacity and no track record of crypto enforcement, but FATF/APG pressure could lead to sudden regulatory changes or retroactive enforcement under existing AML laws.
- Token Classification Risk: Many crypto tokens may be deemed securities under implicit Howey Test application — listing such tokens without securities compliance creates legal exposure.
- Travel Rule Compliance Burden: FSM has adopted FATF travel rule obligations (2020 amendments) but the operational infrastructure for VASP-to-VASP travel rule transmission in a jurisdiction with no licensed VASPs is unclear.
- Structural Risk: The FSM is a small island nation with limited regulatory infrastructure — a centralized exchange may face challenges in obtaining banking relationships, reliable legal counsel, and supervisory engagement.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
No Explicit Test: The FSM does not have an explicit "Howey Test equivalent" for cryptocurrency tokens.
Likely Implicit Application of Common Law Principles: Due to historical ties and influence, the FSM's legal system often draws from U.S. common law principles. Therefore, if a court or regulator in the FSM were to assess whether a crypto token constitutes a security, it would most likely implicitly apply a functional test very similar to the U.S. Howey Test.
The Howey Test (U.S. Standard): An "investment contract" (and thus a security) exists if there is:
No Specific Crypto Requirements: There are no specific registration or exemption requirements published by the FSM for token issuers.
Application of General Securities Law (if applicable): If a token were classified as a security under existing FSM law, then the issuer would theoretically be subject to any existing general securities registration and disclosure requirements. Given the nascent nature of crypto regulation in the FSM, it is highly improbable that existing securities laws would be practically adaptable to digital asset offerings without explicit guidance or amendments. Issuers would likely find themselves in a regulatory vacuum or an unworkable compliance scenario.
No Specific Crypto Rules: Similar to issuance, there are no specific rules governing the secondary trading of cryptocurrency tokens in the FSM.
Application of General Securities Trading Law (if applicable): If a token were deemed a security, secondary trading would technically be subject to general rules for securities exchanges, broker-dealers, and market conduct. However, these rules are not designed for decentralized or global crypto trading platforms, making practical application extremely difficult without tailored legislation.
Undefined/Indirect: The FSM currently lacks a comprehensive and explicit regulatory framework specifically for cryptocurrencies and virtual assets. The approach can be characterized as largely undefined or operating in a "grey area."
Partial/Indirect Application: While there's no dedicated crypto law, existing anti-money laundering (AML) and combating the financing of terrorism (CFT) legislation and regulatory bodies would likely apply to virtual asset activities, especially for entities operating within the FSM or facilitating transactions involving FSM residents. This aligns with global standards set by the Financial Action Task Force (FATF), which requires countries to regulate Virtual Asset Service Providers (VASPs).
Anti-Money Laundering and Terrorist Financing Act 2017 (Title 27 of the FSM Code): This act establishes the general framework for combating money laundering and terrorist financing, including obligations for financial institutions and designated non-financial businesses and professions (DNFBPs). While it may not explicitly mention "virtual assets" or "VASPs" as distinct regulated entities, the FSM, as an APG member, is expected to apply these requirements to VASPs in line with FATF Recommendation 15 (now Recommendation 16 in the context of the FATF's June 2019 Guidance for a Risk-Based Approach to Virtual Assets and Virtual Asset Service Providers).
FSM Banking Act 1980 (Title 29 of the FSM Code): This act provides the general legal framework for banking and financial services. While it does not specifically regulate VASPs, any VASP that offers services resembling traditional financial services (e.g., custody of fiat currency, remittances) might fall under the purview or interpretation of this act or require specific licensing.
For natural persons: Obtaining and verifying identity using reliable, independent source documents, data, or information (e.g., government-issued ID, passport, driver's license).
For legal entities: Obtaining and verifying the legal name, form of organization, proof of existence, powers that regulate and bind the entity, and the names of relevant persons holding senior management positions.
Beneficial Ownership: Identifying and verifying the identity of the beneficial owner(s) of the customer, and taking reasonable measures to understand the ownership and control structure of legal persons and arrangements.
Purpose and Intended Nature of Business Relationship: Understanding the purpose and intended nature of the business relationship or transaction.
Ongoing Monitoring: Conducting ongoing due diligence on the business relationship and scrutiny of transactions undertaken throughout the course of that relationship to ensure that the transactions are consistent with the VASP's knowledge of the customer, their business, and risk profile.
Risk-Based Approach: Applying a risk-based approach to CDD, meaning enhanced CDD (EDD) measures must be applied to higher-risk customers (e.g., Politically Exposed Persons - PEPs, customers from high-risk jurisdictions, complex or unusually large transactions, or where the customer's identity verification poses higher risk) and simplified CDD (SCDD) may be applied to lower-risk customers.
Reporting any transaction (or attempted transaction) that gives rise to a reasonable suspicion that it may be related to money laundering, terrorist financing, or other criminal activity.
The obligation to report exists regardless of the amount or type of assets involved (fiat or virtual).
No Tipping-Off: Prohibitions against informing the customer or any third party that an STR has been filed or that an investigation is being conducted.
Customer Identification Records: All records obtained through CDD measures (e.g., copies of identification documents, verification data).
Transaction Records: Records of all transactions, including amounts, types of virtual assets, sending and receiving addresses/accounts, timestamps, and any other relevant transaction data.
Business Correspondence: All relevant business correspondence, including records of analysis performed.
Financial Intelligence Unit (FIU) of the Federated States of Micronesia (FSM FIU)
Legal Basis: The FSM enacted the Anti-Money Laundering and Counter-Terrorist Financing Act 2011 (as amended 2020). The 2020 amendments were specifically introduced to address FATF Recommendations on VAs and VASPs, including the Travel Rule obligations. This amendment requires VASPs to register, be licensed, and comply with AML/CFT obligations.
For cross-border transfers: The Travel Rule information must be collected and transmitted for transactions equivalent to USD 1,000 or more.
For domestic transfers: The Travel Rule information must be collected and transmitted for transactions equivalent to USD 3,000 or more.
Source: APG Enhanced Follow-Up Report (July 2022), page 23.
Exchange between virtual assets and fiat currencies.
Exchange between one or more forms of virtual assets.
Lack of a Dedicated Regulatory Framework: The FSM currently lacks a comprehensive legal and regulatory framework specifically addressing virtual assets (VAs) and virtual asset service providers (VASPs).
No Registered or Licensed VASPs: As of the latest assessments, there are no known or registered VASPs operating within the FSM that would fall under a regulatory scope (if one existed).
Limited Capacity and Awareness: International assessments indicate that the FSM's financial authorities are still developing their understanding and capacity to monitor and regulate the virtual asset sector.
Federated States of Micronesia (FSM) Financial Intelligence Unit (FIU): This is the primary authority responsible for anti-money laundering and combating the financing of terrorism (AML/CFT) in the FSM. While they address financial crimes, specific crypto enforcement requires a clear regulatory basis for virtual assets.
Asia/Pacific Group on Money Laundering (APG): As an associate member of the Financial Action Task Force (FATF), the APG conducts mutual evaluations of its members' AML/CFT regimes. Their reports provide the most comprehensive public information on the FSM's status regarding virtual assets.
No specific legislation: The FSM had not yet enacted specific legislation or regulations to address virtual assets or virtual asset service providers (VASPs).
No VASPs identified: The authorities had not identified any VASPs operating within the jurisdiction.
Lack of understanding and capacity: The report highlighted a lack of understanding by supervisory authorities regarding the risks associated with virtual assets and a need to develop supervisory capacity in this area.
Recommendations: The APG recommended that FSM develop a comprehensive legal and regulatory framework for VAs and VASPs, including registration, licensing, and AML/CFT obligations, and ensure appropriate supervision and enforcement capabilities.
Legal Basis: The FSM enacted the Anti-Money Laundering and Counter-Terrorist Financing Act 2011 (as amended 2020). The 2020 amendments were specifically introduced to address FATF Recommendations on VAs and VASPs, including the Travel Rule obligations. This amendment requires VASPs to register, be licensed, and comply with AML/CFT obligations.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a centralized exchange operating in the FSM would need to register and be licensed under the 2020 AML/CFT amendments (no operationalized path yet) and comply with full FATF-style AML obligations including Travel Rule thresholds of $1,000 (cross-border) and $3,000 (domestic), while facing near-total regulatory ambiguity on securities classification of tokens, custody rules, and market conduct.
Questions this verdict aims to answer
- What exchange / VASP license applies?
- What custody segregation rules apply to user assets?
- What market-conduct and listing rules apply?
- What travel-rule obligations apply on withdrawals?