Centralized exchange in Labuan (Malaysia)
Order-book exchange that takes custody of user assets and matches trades between users.
CEX is conditionally permitted in Labuan (Malaysia) with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- Must register as a reporting institution under AMLA 2001 and obtain a Labuan Digital Asset Exchange license from LFSA under the DA Guidance Note (LFSA/GL/2020-002)
- Comprehensive CDD/KYC required on a risk-based approach: obtain government-issued ID, proof of address, date of birth, nationality for natural persons; legal form, proof of existence, directors, beneficial ownership for legal entities
- Enhanced Due Diligence (EDD) required for PEPs, customers from high-risk jurisdictions (FATF-listed), and high-risk transactions
- Ongoing transaction monitoring to ensure transactions match customer risk profile
- Suspicious Transaction Reports (STRs) must be filed with the Financial Intelligence Unit (FIU) of Bank Negara Malaysia
- Travel Rule obligations apply — VASPs must obtain and transmit originator and beneficiary information for digital asset transfers, consistent with FATF Recommendation 16 requirements transposed via LFSA AML/CFT Guidelines
- Record-keeping: maintain CDD records and transaction data for the period specified under AMLA 2001 and LFSA Guidelines
Key Restrictions
- Must be incorporated as a Labuan company under the Labuan Companies Act 1990 with substantive physical presence in Labuan IBFC
- Must maintain adequate paid-up capital commensurate with business scale and risk profile — LFSA expects RM 500,000 to RM 1,000,000+ for full-fledged exchanges
- Client digital assets must be held in designated segregated accounts/wallets and must not be commingled with proprietary assets (Section 5.3.1(e) of DA Guidelines)
- Cold storage mandatory for a significant portion of digital assets; multi-signature wallets and robust private key management required
- Directors, controllers, and key management must meet LFSA fit-and-proper criteria
- Must submit comprehensive business plan covering services, target market, operational procedures, risk management, and technology infrastructure
Key Risks
- Enforcement risk: Labuan FSA has power to revoke licenses or impose sanctions for non-compliance with AML/CFT and custody segregation rules
- OFAC/EU sanctions not directly enforceable as Malaysian law, but compliance is practically mandatory for international operations and correspondent banking
- Capital requirements are not fixed but assessed on a case-by-case basis, creating uncertainty for operators during licensing
- No specific travel-rule technical standard published — operators may need to implement FATF-compliant solutions without local regulatory specification of method
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Labuan Financial Services and Securities Act 2010 (LFSSA 2010)
Guidance Note on the Offering and Trading of Digital Assets in Labuan IBFC (the DA Guidance Note): This is the most crucial document, specifically outlining the regulatory requirements for digital asset businesses. It was initially issued in 2019 and may undergo updates.
Anti-Money Laundering, Anti-Terrorism Financing and Proceeds of Unlawful Activities Act 2001 (AMLA 2001): The national AML/CFT law applicable to Labuan entities.
LFSA's Guidelines on AML/CFT: Specific guidelines issued by LFSA to complement AMLA 2001.
For Digital Asset Exchanges (DAX):
Required License: A Labuan company intending to operate a digital asset exchange (i.e., operating a trading platform, brokering, dealing, or acting as an intermediary for digital assets) must obtain a license as a Labuan Digital Asset Exchange or generally fall under the scope of a Labuan Digital Asset Business as defined in the DA Guidance Note.
This license permits the licensee to:
Operate a platform for the primary and secondary trading of digital assets.
Facilitate the matching of buy and sell orders.
Provide related services like listing new digital assets.
Strict compliance with AMLA 2001 and LFSA's AML/CFT guidelines.
Implementation of comprehensive Customer Due Diligence (CDD) and Enhanced Due Diligence (EDD) procedures.
Robust transaction monitoring systems.
Reporting of suspicious transactions (STRs) to the Financial Intelligence Unit (FIU) of Bank Negara Malaysia.
For full-fledged digital asset exchanges or complex operations, LFSA will expect significantly higher capital, potentially in the range of RM 500,000 to RM 1,000,000 or more, depending on the business model and risk assessment.
Guidelines on Digital Asset Business (LFSA/GL/2020-002, last updated January 2023)
Entity Type: Must be incorporated or registered as a Labuan company under the Labuan Companies Act 1990.
Physical Presence: Must have a substantive presence in Labuan.
Capital Requirements: Maintain adequate paid-up capital and working capital, as determined by LFSA based on the nature, scale, and complexity of the business (Section 4.1.3 & 5.1).
Fit and Proper Criteria: Directors, controllers, and key management personnel must meet LFSA's "fit and proper" criteria (Section 4.1.5 & 4.1.6).
Business Plan: Submission of a comprehensive business plan detailing services offered, target market, operational procedures, risk management framework, and technology infrastructure.
Section 5.3.1 (e): "The entity shall establish robust internal controls and safeguards to segregate and protect clients' assets from its own assets. Client funds and digital assets must be held in designated segregated accounts or wallets and must not be commingled with the company's proprietary assets."
Section 5.3.1 (c): Requires the entity to "establish an adequate capital management framework to ensure sufficient capital is maintained to absorb potential losses arising from its business activities."
Section 5.3.1 (g): "The entity shall implement appropriate and comprehensive cybersecurity measures and controls to safeguard clients' digital assets from theft, loss, and unauthorised access, which include, but are not limited to, the use of secure private key management, multi-signature wallets, and cold storage for a significant portion of digital assets."
This explicitly mandates the use of cold storage (offline storage) for a significant portion of digital assets, alongside other security measures like multi-signature wallets and robust private key management.
Anti-Money Laundering, Anti-Terrorism Financing and Proceeds of Unlawful Activities Act 2001 (AMLA 2001): This is the cornerstone legislation. It imposes obligations on reporting institutions (which include VASPs) to detect, deter, and report suspicious transactions, and to implement robust AML/CFT measures, including sanctions screening.
Labuan FSA Guidelines on Digital Asset Businesses (2020, with subsequent updates)
Labuan FSA Guidelines on Anti-Money Laundering and Countering Financing of Terrorism (AML/CFT)
Customer Due Diligence (CDD) / Know Your Customer (KYC)
Risk-Based Approach: VASPs must adopt a risk-based approach to CDD, meaning the intensity of verification should be commensurate with the assessed money laundering/terrorism financing risk of the customer, product, service, or transaction.
Identification and Verification:
Natural Persons: Obtain and verify identity through reliable, independent sources (e.g., government-issued ID, proof of address, date of birth, nationality).
Legal Entities: Obtain and verify legal name, legal form, proof of existence, powers that bind the entity, names of relevant persons (directors, senior management), and crucially, the beneficial owners.
Beneficial Ownership: Identify and take reasonable measures to verify the identity of the beneficial owner(s) – the natural person(s) who ultimately own or control the customer, or the natural person(s) on whose behalf a transaction is being conducted. This is particularly critical for VASPs dealing with potentially opaque structures.
Enhanced Due Diligence (EDD): Apply EDD for higher-risk customers and transactions, including:
Ongoing Monitoring: Regularly scrutinize transactions undertaken throughout the course of the relationship to ensure consistency with the VASP’s knowledge of the customer, their business, and risk profile. This includes reviewing CDD information periodically.
Bank Negara Malaysia (BNM) - Financial Intelligence Unit (FIU)
Legal Basis: Implemented through the Financial Sanctions Act 2009 and specific Financial Sanctions Orders issued by the Minister of Finance.
Legal Basis: While OFAC (U.S.) and EU sanctions are not directly enforceable as Malaysian law, compliance is critical and practically mandatory for Labuan VASPs due to several factors:
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a centralized exchange may operate in Labuan IBFC only as a licensed Labuan Digital Asset Exchange with a locally incorporated entity, mandatory client asset segregation (cold storage, non-commingled wallets), fit-and-proper management, risk-based AML/KYC/EDD, STR reporting to BNM's FIU, and case-by-case capital adequacy determined by LFSA.
Questions this verdict aims to answer
- What exchange / VASP license applies?
- What custody segregation rules apply to user assets?
- What market-conduct and listing rules apply?
- What travel-rule obligations apply on withdrawals?