July 29, 2026
11 min read

Exchange Transparency Controls: Best Practices for Crypto Compliance Teams

Strong exchange transparency controls help crypto businesses build trust, reduce compliance risk, and demonstrate operational integrity. This guide explores the key controls every crypto exchange should implement, including proof of reserves, reserve attestations, governance, wallet monitoring, transaction oversight, internal controls, and regulatory reporting to strengthen transparency and compliance.

Ian Hart
Crypto exchange transparency dashboard showing proof of reserves, wallet verification, audits, reporting, asset segregation and real-time compliance monitoring.

Customers using a centralised crypto exchange must rely on the platform to safeguard their digital assets, maintain accurate account records and process withdrawals when required. However, customers cannot always see where their assets are held, whether they are being reused or whether the exchange has enough liquid reserves to meet its obligations.

Exchange transparency controls help reduce this information imbalance. They provide customers, management and regulators with clearer evidence about asset backing, customer liabilities, custody arrangements, reserve levels and the financial and operational risks affecting the platform.

Proof of Reserves is one important transparency mechanism, but it is not sufficient on its own. A credible transparency framework also requires reliable liability reporting, wallet ownership verification, customer-asset segregation, custody controls, regular reconciliations, governance oversight and accurate public disclosures.

These controls sit within a wider PoR and assurance framework. For the complete view of how Proof of Reserves, attestations and transparency controls work together, see Proof of Reserves, Attestations and Exchange Transparency Controls.

What Are Exchange Transparency Controls?

Exchange transparency controls are the policies, systems, verification processes and disclosures used to demonstrate how a crypto exchange holds, protects and manages customer assets.

These controls should allow the exchange to answer several important questions:

  • What assets does the exchange owe its customers?

  • Where are the corresponding cryptoassets held?

  • Does the exchange control the relevant wallets?

  • Are customer assets separated from company assets?

  • Are any assets lent, pledged, staked or otherwise restricted?

  • Can the exchange meet expected withdrawal demand?

  • How are custody incidents and reserve shortfalls handled?

  • What information is provided to customers and regulators?

Transparency is not achieved by publishing a reserve percentage without explaining how it was calculated. A meaningful framework connects customer-liability records with verifiable assets, custody evidence, internal controls and clear reporting.

Proof of Reserves as a Transparency Control

Proof of Reserves, or PoR, is a process through which an exchange demonstrates that it controls specified assets intended to support customer balances.

A typical PoR calculation compares verified reserve assets with the customer liabilities included in the assessment:

Reserve ratio = Verified reserve assets ÷ Included customer liabilities

A reserve ratio of 100% means that the verified assets equal the customer liabilities included in the calculation. A ratio above 100% means the reported assets exceed those included liabilities.

Proof of Reserves can improve transparency by:

  • Providing evidence that reserve assets exist

  • Connecting customer balances with identifiable wallets

  • Allowing customers to verify their inclusion

  • Supporting internal asset reconciliations

  • Identifying possible reserve shortfalls

  • Increasing management accountability

However, PoR reports may cover only selected assets, liabilities, products or legal entities. They may also represent a single point in time rather than continuous reserve availability.

The PCAOB has warned that Proof of Reserves reports are not financial audits and may not address all liabilities, customer rights, temporary borrowing or future asset availability. The procedures used also differ because PoR engagements are not performed under one uniform auditing standard.

Teams new to PoR should start with a clear explanation of what Proof of Reserves is and how reserve verification works before relying on headline reserve ratios.

Proof of Liabilities Reporting

Proof of Assets shows what an exchange holds. Proof of Liabilities shows what it owes to customers.

A meaningful reserve calculation requires accurate information on both sides.

Customer liabilities may include:

  • Spot-account balances

  • Custody balances

  • Funding accounts

  • Pending withdrawals

  • Margin-account entitlements

  • Staking balances

  • Lending-product claims

  • Other contractual customer obligations

Exchanges may use Merkle trees or similar cryptographic structures to represent customer balances while protecting individual account information. Customers can then verify that their own balances were included in the liability dataset.

However, a customer’s successful verification does not prove that every other liability was included. Compliance and assurance teams should reconcile the published liability dataset with the exchange’s complete customer ledger.

They should also review whether:

  • All eligible customer accounts were included

  • Suspended and inactive accounts were captured

  • Pending withdrawals were treated correctly

  • Negative balances improperly reduced total liabilities

  • Margin and lending products were calculated consistently

  • Different legal entities were included or excluded appropriately

  • The correct reporting time was applied across every system

Incomplete liability reporting can make an exchange appear better backed than it actually is.

Wallet Ownership Verification

Public blockchain records can show the balance held at an address, but they do not automatically prove that the exchange controls that address.

Wallet ownership or control should be supported through additional verification procedures, such as:

  • Cryptographic message signing

  • Small test transactions

  • Third-party custodian confirmations

  • Multi-signature approval records

  • Key-management documentation

  • Access-control testing

  • Independent assurance procedures

Cryptographic message signing enables an exchange to demonstrate access to the relevant private key without transferring the reserve assets.

Compliance teams should also understand whether control is held directly by the exchange or through a custodian, shared-signature arrangement or other third party.

Under the FCA’s final 2026 cryptoasset framework, the concept of safeguarding focuses on whether a firm has sufficient control to bring about a transfer of a client’s cryptoassets. The rules recognise that control can arise through direct access, appointed custodians or shared arrangements. These UK rules are scheduled to apply to authorised firms from October 25, 2027.

Wallet verification should therefore examine both technical access and the legal and operational arrangements surrounding the assets.

Segregation of Customer and Company Assets

Customer assets should be clearly separated from assets belonging to the exchange.

Segregation reduces the risk that customer property will be used to fund operating expenses, proprietary trading, lending or obligations to other creditors.

A crypto exchange may use omnibus wallets containing assets for multiple customers. Omnibus custody does not necessarily mean that customer and corporate assets are improperly mixed, provided that reliable internal records clearly identify each customer’s entitlement and distinguish customer assets from company property.

Effective segregation controls should include:

  • Separate customer and corporate wallet structures

  • Distinct internal ledger accounts

  • Daily reconciliation of customer entitlements

  • Restrictions on transfers from customer wallets

  • Clear approval requirements

  • Identification of assets held for affiliates

  • Legal analysis of customer ownership rights

  • Documented insolvency treatment

IOSCO recommends that cryptoasset service providers make arrangements to safeguard client assets and segregate them from the provider’s own assets. A 2025 IOSCO implementation review also identified both operational and legal segregation as important elements of effective custody frameworks.

MiCA similarly requires cryptoasset custodians to maintain custody policies and procedures for segregating clients’ cryptoassets and funds.

Digital Asset Custody Controls

Exchange transparency depends on strong custody arrangements. An exchange may report sufficient reserves but still expose customers to loss through weak private-key security, poor access management or an unreliable custodian.

Important custody controls include:

Key Management

The exchange should document how private keys are generated, stored, backed up, recovered and destroyed.

Access Controls

Only authorised individuals should be able to initiate or approve transfers. Access should be removed promptly when employees change roles or leave the organisation.

Multi-Party Approval

High-value transactions should require approval from more than one authorised person or system.

Hot and Cold Wallet Management

The exchange should define how much value may be held in internet-connected hot wallets and how excess balances are transferred to more secure storage.

Third-Party Custodian Oversight

Where external custodians are used, the exchange should assess their financial condition, security controls, insurance, regulatory status, operational resilience and incident-reporting arrangements.

Incident Response

Procedures should explain how the exchange responds to lost keys, compromised wallets, unauthorised transfers and custodian outages.

Customers should also receive clear information about the custody model and any material third-party dependencies.

Governance and Internal Controls

Exchange transparency must be supported by governance rather than being treated solely as a marketing exercise.

Senior management should approve the transparency framework and receive regular reporting on:

  • Reserve ratios

  • Customer liabilities

  • Reconciliation differences

  • Encumbered assets

  • Liquidity levels

  • Significant wallet movements

  • Custody incidents

  • Third-party failures

  • Control exceptions

The exchange should clearly assign responsibility among compliance, finance, treasury, custody, technology, risk and internal audit teams.

Material reserve shortages or reconciliation breaks should trigger documented escalation procedures. The policy should identify who must be informed, which transactions may be restricted and how customer or regulatory communications will be handled.

Internal audit or another independent control function should periodically test whether the transparency framework operates as described.

Continuous Reserve Monitoring

A quarterly or monthly reserve snapshot can become outdated quickly. Customer deposits, withdrawals, market prices and wallet balances change continuously.

Continuous reserve monitoring allows an exchange to identify changes in backing and liquidity before they develop into a serious customer-protection issue.

Monitoring should compare:

  • Customer liabilities

  • On-chain reserve balances

  • Third-party custodian balances

  • Pending deposits and withdrawals

  • Locked or staked assets

  • Assets pledged as collateral

  • Available withdrawal liquidity

Automated alerts should be generated when reserve ratios fall below internal thresholds, reconciliations remain unresolved or unusually large assets move from customer wallets.

The platform should also perform stress testing. A reserve ratio may appear adequate under normal conditions while the exchange remains unable to meet a sudden concentration of withdrawals.

Continuous monitoring does not remove the need for independent verification. It provides management with current control information between formal attestations or audits.

Public Disclosures and Reporting

Public disclosures should be accurate, understandable and sufficiently detailed for customers to interpret them correctly.

A useful transparency report should explain:

  • The reporting date and time

  • Legal entities covered

  • Cryptoassets included

  • Customer products included

  • Liability-calculation methodology

  • Reserve-wallet verification procedures

  • Treatment of third-party custody

  • Treatment of staked, lent or pledged assets

  • Reserve ratios by asset

  • Independent assurance performed

  • Report limitations

  • Significant methodology changes

Exchanges should avoid describing a limited PoR engagement as a financial audit. They should also avoid implying that a 100% reserve ratio guarantees solvency or withdrawal availability.

Disclosures should be updated when the methodology, product coverage or custody arrangements change. Historical reports should remain accessible so customers can compare reserve information over time.

Compliance Team Responsibilities

The compliance team may not calculate every wallet balance, but it plays an important role in governing the transparency framework.

Its responsibilities may include:

  1. Reviewing whether public claims are accurate and not misleading.

  2. Confirming that transparency practices meet applicable regulatory requirements.

  3. Assessing customer-asset and custody risks.

  4. Challenging exclusions from reserve and liability reporting.

  5. Monitoring whether restricted assets are reported correctly.

  6. Reviewing material reconciliation breaks.

  7. Coordinating regulatory notifications.

  8. Assessing conflicts involving affiliates or related parties.

  9. Maintaining evidence supporting disclosures.

  10. Escalating suspected misuse of customer assets.

Compliance teams should work closely with finance, custody and technology specialists rather than relying entirely on vendor-generated reserve dashboards.

Regulatory Expectations

Regulatory requirements differ by jurisdiction, but international frameworks increasingly focus on customer-asset safeguarding, segregation, custody governance, accurate records and transparent disclosures.

IOSCO’s recommendations address custody-related risks and the protection and segregation of client money and assets.

MiCA requires European cryptoasset custodians to maintain custody policies, keep records of client positions and establish procedures for segregating client cryptoassets from their own holdings.

In the United Kingdom, the FCA published final cryptoasset rules and guidance on June 30, 2026. Firms carrying out in-scope activities must assess their authorisation requirements, and the new safeguarding and wider cryptoasset rules are due to apply from October 25, 2027.

Voluntary reserve reporting should not be assumed to satisfy every custody, safeguarding, disclosure or financial-reporting obligation. Exchanges must assess the requirements applying to each legal entity and jurisdiction.

Exchange Transparency Checklist

Crypto compliance teams can use the following checklist:

Reserve and Liability Controls

  • Are all material customer products included?

  • Are assets reconciled with customer liabilities?

  • Are reserve calculations performed frequently?

  • Are negative customer balances treated appropriately?

  • Are pending withdrawals included?

Wallet and Custody Controls

  • Has control of each reserve wallet been verified?

  • Are customer and corporate assets separated?

  • Are private-key controls documented and tested?

  • Are third-party custodians monitored?

  • Are hot-wallet limits and approvals clearly defined?

Asset Availability

  • Are pledged, lent, staked or locked assets identified?

  • Are borrowed assets excluded or disclosed?

  • Is withdrawal liquidity monitored?

  • Are stress scenarios tested?

Governance and Assurance

  • Does senior management review reserve reporting?

  • Are material exceptions escalated?

  • Is independent assurance performed?

  • Does internal audit test the framework?

  • Are methodology changes approved and recorded?

Public Reporting

  • Are the scope and reporting date clearly stated?

  • Are exclusions and limitations disclosed?

  • Can customers verify their inclusion?

  • Are reserve attestations described accurately?

  • Are previous reports available for comparison?

Frequently Asked Questions

What Are Exchange Transparency Controls?

Exchange transparency controls are systems, policies and disclosures that show how a crypto exchange holds customer assets, calculates liabilities and manages custody, reserves and liquidity.

Is Proof of Reserves an Exchange Transparency Control?

Yes. Proof of Reserves demonstrates that an exchange controls specified assets supporting included customer balances. It should be combined with other financial and custody controls.

Why Is Proof of Liabilities Important?

Reserve assets cannot be assessed properly without knowing how much the exchange owes its customers. Incomplete liabilities can produce a misleading reserve ratio.

Does Publishing Wallet Addresses Prove Ownership?

No. Public balances show that assets exist at an address, but additional evidence is required to demonstrate that the exchange controls the wallet.

Can Customer Assets Be Held in Omnibus Wallets?

Yes, but the exchange should maintain reliable internal records identifying each customer’s entitlement and clearly separating customer assets from company property.

What Is Continuous Reserve Monitoring?

Continuous reserve monitoring compares changing customer liabilities with reserve assets, custody balances and available liquidity on an ongoing basis.

Who Is Responsible for Exchange Transparency?

Responsibility is shared among senior management, finance, treasury, custody, compliance, risk, technology and internal audit. Clear ownership should be documented.

Does Proof of Reserves Prove an Exchange Is Solvent?

No. Proof of Reserves may not include corporate debt, legal liabilities, operational losses or all liquidity risks.

Conclusion

Exchange transparency controls help customers, management and regulators understand whether a crypto platform holds and protects the assets it owes to customers.

To build a practical working understanding of reserve reporting, attestations and transparency governance, explore Proof of Reserves, Attestations and Exchange Transparency Controls. The course is designed for compliance teams that need to evaluate PoR reports, liability coverage, wallet-control evidence, segregation, custody governance and disclosure risks.