Licensed venues operate under requirements that explain most of the friction users encounter, and the requirements have expanded considerably.
Authorisation
Permission to operate, granted after assessment of systems, controls, capital and management.
Which takes months to years and requires substantial documentation.
Authorisations are jurisdiction-specific, which is why venue availability varies by country.
Client asset rules
Segregation of customer assets from firm assets, with reconciliation and reporting.
Which is the requirement most directly addressing what went wrong in past failures.
Some frameworks require holding client assets with a third-party custodian.
Capital requirements
Minimum capital held against operational risk.
Which provides a buffer and is calculated by defined methodologies.
These are generally lower than for banks and higher than for unregulated operators, which hold none.
Market conduct
Surveillance for manipulation, rules on order handling and prohibition of trading against clients without disclosure.
Which addresses conflicts where a venue also operates a trading business.
Several enforcement actions have concerned exactly this conflict.
Customer onboarding
Identity verification, sanctions screening and source of funds assessment.
Which is the friction users encounter first.
Enhanced procedures apply to higher-risk customers and to larger amounts.
Complaints and redress
Defined complaints processes and, in some jurisdictions, access to an ombudsman.
Which provides a route that does not exist with unregulated operators.
Compensation schemes covering some losses exist in a few jurisdictions and generally exclude market losses.
Reporting
Regular reporting to supervisors on financial position, incidents and suspicious activity.
Which is substantial ongoing work requiring dedicated staff.
Marketing restrictions
Rules on how products are promoted, including risk warnings and restrictions on incentives.
Which has produced enforcement against promotional practices in several markets.
What it means for users
More friction, more protection, and a meaningful difference in position if the venue fails.
Operational resilience
Requirements regarding system availability, disaster recovery and incident reporting.
Which have been introduced following outages during volatile periods.
Testing of recovery arrangements is generally required rather than assumed.
Third-party oversight
Firms remain responsible for functions they outsource.
Which includes custody, technology and compliance services.
Due diligence and ongoing monitoring of providers is a supervised obligation.
Product governance
Assessing whether products are appropriate for the customers they are offered to.
Which applies particularly to leveraged and complex instruments.
Several jurisdictions restrict or prohibit offering these to retail customers.
Record keeping
Retention of communications, orders and decisions for defined periods.
Which supports supervision and investigation.
Retention periods are specified and are typically several years.
Cost of compliance
Substantial, and it favours larger operators.
Which is a recognised consequence of the regulatory design and is generally accepted as the price of protection.
Custody arrangements
Some frameworks require client assets to be held by an independent custodian.
Which structurally separates trading from holding.
This is the arrangement that most directly addresses the historical failures.
Proprietary trading restrictions
Rules on whether a venue may trade on its own platform.
Which is a conflict that several jurisdictions now restrict explicitly.
Disclosure requirements apply where it is permitted.
Listing governance
Documented processes for adding and removing assets with defined criteria.
Which reduces discretion and the conflicts that come with it.
Some frameworks require notification of listing decisions to supervisors.
Staff conduct
Personal trading policies for employees with access to sensitive information.
Which addresses front-running of listing announcements.
Enforcement against employees has occurred at major venues.
Choosing a venue
Authorisation status, custody arrangement, segregation, complaints route and incident history.
The direction of travel
Requirements have converged internationally toward segregation, authorisation and conduct rules.
Which is a recognisable pattern following any sector's failures.
The result is fewer operators, higher barriers and materially better customer protection at compliant venues.
A closing note
Rules vary by jurisdiction and change, and this is general description rather than advice.
What users actually notice
Longer onboarding, requests for documentation, restricted product availability and geographic limits.
Which are the visible consequences of everything described above.
Whether the trade is worth it depends on how much weight you place on having recourse if something goes wrong, and the recent history offers a fairly clear answer.
Comparing venues honestly
An authorised venue in a strong framework, an authorised venue in a permissive one and an unauthorised offshore operator are three different propositions marketed identically.
Which is checkable through public registers in a few minutes.
The register entry states what activities are permitted and in which jurisdiction.
A last note
Every requirement described here exists because something went wrong somewhere and somebody lost money. Reading the rules is a fairly efficient way to learn the history.
Summary
Authorisation, segregation, conduct rules, resilience requirements and a complaints route.
Which is what distinguishes a supervised venue from an offshore operator marketing the same service.
Public registers make the distinction checkable, and very few users check.
The entry states which activities are permitted, under which authority, and whether any conditions apply to them.