Centralized exchange in Malaysia
Order-book exchange that takes custody of user assets and matches trades between users.
CEX is conditionally permitted in Malaysia with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- DAX operators must comply with AMLATFPUAA 2001 (Anti-Money Laundering, Anti-Terrorism Financing and Proceeds of Unlawful Activities Act 2001) enforced by BNM
- Must implement Customer Due Diligence (CDD) including identity verification (name, address, DOB, nationality, ID document) for individuals
- For legal entities: collect legal name, legal form, proof of existence, registered address, directors/partners/trustees, shareholders/UBOs, governing documents
- Beneficial ownership identification — look through layers of ownership to identify the natural person who ultimately owns/controls the customer
- Ongoing monitoring of business relationships and transactions against customer risk profile and source of funds
- Enhanced Due Diligence (EDD) for PEPs, high-risk customers, and high-risk products/services (e.g., privacy coins, mixers)
- Non-face-to-face CDD measures required (multi-factor auth, video verification, independent source cross-referencing)
- Travel Rule applies: collect, transmit, and retain originator and beneficiary information for all cross-border virtual asset transfers regardless of amount, and for domestic transfers ≥ MYR 3,000
- For domestic transfers < MYR 3,000, certain fields may be omitted but must be producible within 3 working days upon request
- Sanctions screening of both originator and beneficiary against relevant sanctions lists
- Record keeping for at least 7 years under AMLA
- Suspicious Transaction Reports (STRs) must be filed with BNM's FIU
- Compliance with SC's Guidelines on Recognised Markets and BNM's AML/CFT and TFS Policy Document (Paragraph 10.1.2 extends Travel Rule to virtual assets)
Key Restrictions
- Must register as a Recognised Market Operator (RMO) / DAX with Securities Commission Malaysia — only 5 operators registered to date (Luno, Tokenize, MX Global, Sinegy, Hata); SC is known to be strict and slow on new registrations (6–12 months)
- Minimum shareholders' funds of MYR 5 million (~USD 1.1M)
- Customer assets must be segregated from operator assets under DAX registration custody rules
- Initial Exchange Offering (IEO) framework requires separate SC approval
- Unregistered operation exposes the entity to cease-and-desist orders (enforced against Binance in 2021) and criminal liability under CMSA 2007
- Digital currency and digital tokens are deemed 'prescribed securities' under the Capital Markets and Services (Prescription of Securities) Order 2019
Key Risks
- SC has a proven enforcement record — issued cease-and-desist orders against Binance and other unregistered operators; risk of license revocation or suspension for non-compliance
- Penalties include significant monetary fines and imprisonment for responsible individuals (directors, compliance officers)
- Only 5 registered operators exist — regulatory gatekeeping is tight, registration is not guaranteed
- Travel Rule compliance is operationally complex — requires inter-VASP data transmission infrastructure for every withdrawal
- Regulatory dual-oversight by SC (licensing/securities) and BNM (AML/CFT) creates layered compliance burden
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
SC Malaysia — Digital asset exchange registration, IEO oversight, cease-and-desist enforcement
Capital Markets and Services (Prescription of Securities) Order 2019 (2019) — Digital currency and digital token as prescribed securities
Guidelines on Digital Assets (2020) — DAX operator requirements
VASP: Recognized Market Operator (RMO) — DAX registration with SC. Only 5 operators registered (Luno, Tokenize, MX Global, Sinegy, Hata). SC strict and slow on registrations. 6-12 months.
CUSTODY: Included under DAX registration; customer asset segregation required
EXCHANGE: DAX registration with SC — MYR 5M (~$1.1M USD) minimum shareholders' funds. SC issued cease-and-desist orders against unregistered operators (incl. Binance 2021). IEO framework requires separate SC approval.
Anti-Money Laundering, Anti-Terrorism Financing and Proceeds of Unlawful Activities Act 2001 (AMLATFPUAA 2001)
AML/CFT and Targeted Financial Sanctions for Financial Institutions (AML/CFT TFS for FIs) Policy Document (BNM Policy Document): Issued by Bank Negara Malaysia, this comprehensive policy document provides detailed guidance and requirements for reporting institutions to comply with AMLATFPUAA 2001. This document has specific sections/appendices applicable to "Digital Currencies" or "Virtual Assets."
Capital Markets and Services Act 2007 (CMSA): For digital assets that are deemed "securities," the Securities Commission Malaysia (SC) regulates entities like Digital Asset Exchanges (DAX) under this Act and its accompanying guidelines. These entities are also subject to specific AML/CFT requirements imposed by the SC.
Guidelines on Recognised Markets (SC Guidelines): Specifically for operators of recognised markets, including DAX, detailing operational, conduct, and AML/CFT requirements.
Customer Identification and Verification:
Obtain and verify the identity of individual customers (name, address, date of birth, nationality, identification document details, contact information).
For legal entities/corporate customers, obtain and verify: legal name, legal form, proof of existence (e.g., certificate of incorporation), address of registered office, names of directors/partners/trustees, details of shareholders and beneficial owners, and constitution/governing documents.
For partnerships and trusts, similar information must be collected for partners, trustees, settlors, and beneficiaries.
Beneficial Ownership: Identify and verify the ultimate beneficial owner (UBO) for all corporate and legal arrangements. This involves looking through layers of ownership to identify the natural person(s) who ultimately own or control the customer, or on whose behalf a transaction is being conducted.
Purpose and Intended Nature of Business Relationship: Understand the rationale behind the customer's request to use the VASP's services and the anticipated level and type of activity.
Source of Funds/Wealth: For higher-risk customers or transactions, obtain information on the source of funds or source of wealth.
Ongoing Monitoring: Continuously monitor the business relationship and transactions to ensure consistency with the VASP's knowledge of the customer, their business, risk profile, and source of funds. Update customer information regularly.
Non-Face-to-Face (NFF) Customers: Given the online nature of many VASPs, robust measures for NFF CDD are crucial, including multi-factor authentication, video verification, and cross-referencing with reliable independent sources.
Politically Exposed Persons (PEPs): Implement Enhanced Due Diligence (EDD) measures for PEPs, their family members, and close associates, including obtaining senior management approval to establish or continue the relationship and taking reasonable measures to establish the source of wealth and funds.
High-Risk Customers: PEPs, customers from high-risk jurisdictions (e.g., those identified by FATF), customers involved in cash-intensive businesses.
High-Risk Products/Services: Products or services that facilitate anonymity (e.g., privacy coins, mixing services).
Travel Rule adopted — threshold: MYR 3,000
Bank Negara Malaysia (BNM) Policy Document on Anti-Money Laundering, Counter-Terrorism Financing and Targeted Financial Sanctions for Financial Institutions (AML/CFT and TFS Policy Document): This is the primary document.
Specifically, Paragraph 10.1.2 states: "A reporting institution that conducts virtual asset transfers shall apply the obligations outlined in this policy document relating to funds or wire transfers to virtual assets." This explicitly extends the Travel Rule to virtual assets.
Securities Commission Malaysia (SC) Guidelines on Digital Assets: These guidelines govern Digital Asset Exchanges (DAX) and other entities dealing with digital assets. They mandate compliance with BNM's AML/CFT framework.
Section 9 (Anti-Money Laundering and Counter-Terrorism Financing): Requires registered Digital Asset Exchanges (DAX) to comply with the AMLA and BNM's AML/CFT and TFS Policy Document.
Cross-Border Transfers (both traditional and virtual assets): All required originator and beneficiary information must be obtained and transmitted, regardless of the amount.
Domestic Transfers (both traditional and virtual assets):
For transfers equal to or exceeding RM3,000 (or equivalent in foreign currency/virtual assets): All required originator and beneficiary information must be obtained and transmitted.
For transfers below RM3,000 (or equivalent): Reporting institutions are permitted to omit certain information (e.g., originator's address or national identity number, beneficiary's address), provided they can produce this information within 3 working days if requested by authorities.
Information Collection: VASPs must collect the required originator (sender) and beneficiary (recipient) information, including names, account numbers (or wallet addresses), and physical addresses or national identity numbers/customer identification numbers.
Information Holding: This information must be securely stored and readily retrievable.
Information Transmission: The collected information must be transmitted to the beneficiary VASP during or before the virtual asset transfer.
Sanctions Screening: Both originator and beneficiary information must be screened against relevant sanctions lists.
Record Keeping: Records of all transactions and the associated Travel Rule data must be maintained for a prescribed period (typically at least 7 years under AMLA).
Risk-Based Approach: VASPs are expected to adopt a risk-based approach to assess and mitigate ML/TF risks, which includes enhanced due diligence where appropriate.
Fines: Significant monetary penalties, which can run into millions of Ringgit for entities.
Imprisonment: Individuals (e.g., directors, compliance officers) found responsible for non-compliance may face imprisonment.
Revocation or Suspension of Licenses: For regulated entities like DAXes, their licenses can be revoked or suspended by the SC or BNM.
Entity Targeted: Binance Holdings Limited and its CEO, Changpeng Zhao (CZ). Violation Type: Operating a Digital Asset Exchange (DAX) without registration/license, which is a violation under the Capital Markets and Services Act 2007. The SC considers digital assets as securities, and operating a platform for trading them requires authorization. Penalty Amount: No explicit monetary fine was announced at the time of the public reprimand. The penalties were operational: a public reprimand, an order to cease all operations in Malaysia, disable access to its website and mobile applications, and cease all media and marketing activities targeting Malaysian investors. Outcome: Binance was forced to shut down its direct operations in Malaysia. Malaysian users were advised to withdraw their funds. The action led Binance to later pursue a compliant pathway to re-enter the Malaysian market by acquiring a stake in and partnering with a licensed local Digital Asset Exchange (DAX), MX Global, demonstrating the effectiveness of the SC's enforcement in driving regulatory compliance.
Entity Targeted: Various unauthorized digital asset platforms, investment schemes involving crypto, and individuals promoting them. (Specific names are too numerous to list here, but are updated frequently). Violation Type: Operating or promoting unauthorized investment schemes, digital asset exchanges, or services without the necessary licenses or approvals from the SC Malaysia. Penalty Amount: Typically no specific monetary penalty is announced publicly for being added to the alert list. The "penalty" is a public warning, which often leads to the platform being unable to operate effectively in Malaysia and subsequent cessation of operations or blocking of access. Outcome: Public awareness is raised, and investors are warned against dealing with these entities. This often leads to reduced or ceased operations for the targeted entities within Malaysia.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- high
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a centralized exchange may operate in Malaysia only by registering as a Recognised Market Operator (DAX) with the Securities Commission, maintaining MYR 5M minimum shareholders' funds, segregating customer assets, and complying with BNM's AML/CFT framework including Travel Rule obligations at a MYR 3,000 threshold, but the SC's strict registration pipeline (only 5 approved operators) and active enforcement against unregistered entities make this a high-barrier jurisdiction.
Questions this verdict aims to answer
- What exchange / VASP license applies?
- What custody segregation rules apply to user assets?
- What market-conduct and listing rules apply?
- What travel-rule obligations apply on withdrawals?