Navigating digital asset risk in the evolving regulatory landscape
Digital assets introduce distinct risk, compliance, and supervisory expectations. Traditional control frameworks don’t always map cleanly to blockchain-based activity (e.g., immutability, pseudonymity, smart contracts, third-party protocols, 24/7 markets).
PwC helps clients identify the regulatory perimeter, design fit-for-purpose controls, integrate digital assets into enterprise risk management, and build regulator-ready programs across AML/sanctions, fraud, licensing, and financial/non-financial risk.
Regulator-ready typically means you can demonstrate a clear regulatory perimeter, sound governance, and effective controls before launch. Supervisors generally expect evidence such as a board-approved business and risk strategy, defined decision rights and accountable owners, documented policies and procedures (AML/sanctions, fraud, custody/key management, third-party risk, incident response), end-to-end process maps and control points, risk assessments specific to the product and blockchain activity, testing results (UAT/control testing, tabletop exercises, resiliency tests), third-party due diligence packages, and a complete audit trail/recordkeeping approach (including how onchain evidence is captured and retained). They also look for credible staffing and training, clear customer disclosures, and a plan for ongoing monitoring, issue management, and independent assurance.
AML and sanctions programs need to incorporate onchain risk signals and controls that do not exist in traditional payments. In practice, this means updating your AML risk assessment to cover blockchain networks and protocols, wallet types like hosted and unhosted, and transaction typologies like mixers, chain-hopping, and rapid layering. These enhanced programs typically:
Add blockchain analytics to support wallet attribution, exposure tracing, and alert enrichment;
Implement wallet and sanctions screening, including relevant smart contract interactions where exposure is plausible;
Enhance KYC and KYB and wallet provenance standards covering ownership, control, beneficial owner, and high-risk indicators;
Operationalize AML investigations with defensible documentation and SAR or STR decisioning using onchain evidence; and
Where applicable, operationalize Travel Rule data capture and exchange and strengthen recordkeeping so the program is exam-ready.
Because transactions are often final and difficult to reverse, the most effective controls emphasize prevention, friction for high-risk activity, and rapid detection. Common leading practices include strong identity and account security using MFA, device binding, behavioral signals, and step-up authentication. They also include transaction guardrails like limits, allowlists, velocity checks, beneficiary change controls, and time delays for large or unusual withdrawals. Many firms deploy real-time monitoring that combines traditional signals with onchain indicators. They implement targeted controls against customer harm patterns, especially scams and social engineering. An effective program also includes incident and recovery playbooks that cover trace, escalate, and freeze where feasible, coordination with custodians and exchanges, law enforcement workflows, and clear customer communication and remediation governance.
Applicable licenses and registrations depend on what you do, where you do it, and for whom, such as custody, trading, brokerage, payments, stablecoin issuance, and tokenization platform services. Common regulatory touchpoints can include money transmission and MSB obligations, state licensing regimes, bank or trust authorities for custody, and depending on product features, securities or commodities related requirements. The fastest compliant path is usually achieved by confirming the regulatory perimeter for the specific product and jurisdictions, choosing a launch scope that minimizes licensing complexity like limited geography, narrow features, or institutional-only, and using a phased strategy. Many firms partner with appropriately licensed entities for initial launch while building their own licensing footprint and controls for scale. This approach helps reduce time-to-market while keeping the long-term target state clear and defensible.
Stablecoin models introduce redemption timing commitments and potential run dynamics, so liquidity planning typically needs to be more explicit and operational than in many traditional products. Firms generally need a clearly defined redemption policy covering timing, fees, limits, and exceptions, a reserve strategy aligned to required liquidity, and multiple tested monetization paths to convert to cash under normal and stressed conditions. Stress testing usually focuses on severity and speed, large redemptions over short windows, concentration risk among large holders, market liquidity haircuts, and operational or settlement outages. Funding and liquidity buffers are then calibrated to the modeled scenarios and supported by contingency funding plans, clear escalation triggers, and pre-defined operational playbooks that include communications, execution steps, and decision documentation during stress.
A common effective model is central standards with embedded execution. Centralized enterprise risk functions typically set the firmwide risk appetite, define minimum control standards, and own key decision rights like approving new digital asset activities, interpreting regulatory obligations, and establishing escalation and incident governance. Product and operations teams then embed those standards into day-to-day workflows and own control execution, including onboarding procedures, transaction operations, monitoring and escalation, reconciliations, and issue remediation. This structure creates consistent governance and supervisory clarity while keeping accountability close to where the product is built and operated.