[codicts-css-switcher id=”346″]

Global Law Experts Logo
digital asset exchange malaysia

Talk with Our Expert

Legal professional smiling at desk with a globe and legal-themed decor in modern office setting.

Jonathon Richards

Global Law Experts

Lead Enquiries Qualification
Delete Article

How to Obtain a Digital Asset Exchange Licence and Run an IEO in Malaysia (DAX & IEO, SC Frameworks Explained)

By Jonathon Richards
– posted 1 hour ago

Launching a digital asset exchange malaysia operators can rely on requires navigating a layered regulatory environment overseen principally by the Securities Commission Malaysia (SC) and supported by anti-money laundering supervision from Bank Negara Malaysia (BNM). This landing page is written for founders, incumbent exchanges, token issuers and in-house counsel who need executable guidance, not summaries, on how to register and operate a regulated Digital Asset Exchange (DAX), run an Initial Exchange Offering (IEO), satisfy AML/CFT obligations, and weigh the Labuan licensing alternative. In 2026 the landscape is shifting: the SC has issued revised Recognised Market Operator (RMO) guidelines, BNM has intensified AML/CFT scrutiny of virtual asset service providers (VASPs), and regulated DAXs recorded substantial trading volume in 2025.

Below you will find a step-by-step DAX licensing process, an IEO operator walkthrough, a comparison between the onshore SC regime and the Labuan FSA route, eligibility checklists, AML/CFT requirements, indicative fees and timelines, and answers to the questions prospective applicants ask most. The aim is practical, source-grounded direction that helps you reach application readiness efficiently.

Regulatory landscape: SC RMO framework, CMSA and market data

Operating a compliant digital asset exchange malaysia founders can scale depends on understanding three interlocking pillars: the SC’s Recognised Market Operator (RMO) regime, the Capital Markets and Services Act 2007 (CMSA) that defines when a token is a regulated instrument, and the AML/CFT framework administered under the Anti-Money Laundering, Anti-Terrorism Financing and Proceeds of Unlawful Activities Act 2001 (AMLA) with BNM oversight.

What the RMO regime covers

Under the SC’s framework, a digital asset exchange is categorised as a Recognised Market Operator, a regulated venue that must be recognised by the SC before it can operate, list digital assets, or offer trading to Malaysian investors. The revised RMO guidelines set out recognition criteria, governance expectations, listing processes and ongoing obligations. The RMO category also covers IEO operators and Digital Asset Custodians (DAC), each with distinct obligations. Recognition is not a formality: applicants must demonstrate operational readiness, financial soundness and robust investor protection before the SC will admit them to the market.

CMSA and scope, when tokens are “securities”

The Capital Markets and Services Act 2007 (CMSA) is the primary statute governing capital markets in Malaysia. Prescription orders made under the CMSA bring certain digital currencies and digital tokens within the definition of “securities,” which triggers SC jurisdiction over their offering, trading and intermediation. Whether a specific token is a regulated “security” or a utility instrument outside the securities perimeter is a legal determination that depends on the token’s economic substance, rights conferred and distribution model. This classification question sits at the centre of both DAX listing decisions and IEO structuring, and it is the first analysis any applicant should resolve. For deeper treatment, see our forthcoming guide on token securities classification in Malaysia.

BNM and AMLA context

DAX and IEO operators are “reporting institutions” for AML/CFT purposes. The AMLA 2001 establishes the money-laundering and terrorism-financing offences and the statutory reporting duties, while Bank Negara Malaysia issues the policy documents and guidance that set out customer due diligence, suspicious transaction reporting and record-keeping expectations. BNM has signalled heightened attention to VASPs, so a credible AML/CFT programme is now a gating condition for SC recognition rather than an afterthought.

Currently recognised and operating market participants, including the recognised DAX operators and approved IEO operators, are published on the SC’s official Digital Assets registry. Applicants and investors alike should treat that registry as the authoritative list of legally operating platforms.

Why 2026 is pivotal for the digital asset exchange Malaysia market

Several developments converge to make 2026 a decisive year for anyone seeking to build a digital asset exchange malaysia participants and regulators will take seriously. The SC’s revised RMO guidelines, announced in 2026, signal a move to streamline and liberalise listing and recognition processes, a sign the regulator wants a competitive, well-governed onshore market. Market momentum supports the policy direction: regulated DAXs recorded RM17. 14 billion in trading value in 2025, according to SC data, underscoring genuine commercial demand. At the same time, intensifying BNM AML/CFT scrutiny raises the compliance bar.

The practical implication for applicants is clear, the window to enter a liberalising but increasingly supervised market is open, and early movers who build strong governance and AML foundations will be best placed. Industry observers expect the revised guidelines to reduce friction in listing new tokens while simultaneously sharpening expectations on custody, surveillance and consumer protection.

How to obtain a Digital Asset Exchange (DAX) licence, step-by-step process

Any entity that intends to operate a trading platform for digital assets accessible to Malaysian investors must be recognised by the SC as an RMO before commencing operations. The process below sets out an ordered, actionable route to recognition, with indicative documents, common pitfalls and time-to-complete estimates for each stage. For a working version of these items, our RMO/DAX registration checklist expands each step into document templates.

  1. Pre-application due diligence and project scoping, Define the entity structure, the precise services offered (spot trading, custody, staking, IEO facilitation), target customer segments and jurisdictional footprint. Produce a business plan with three-to-five-year projections. Common pitfall: an unclear scope that mixes activities requiring different authorisations. Typical time: 2–4 weeks.
  2. Token classification and legal opinion, Assess each asset to be listed against the CMSA and the relevant prescription orders to determine whether it is a regulated security, a utility token or otherwise. Commission a written legal opinion for the listing universe. Common pitfall: listing tokens that are inadvertently securities without the attendant disclosures. Typical time: 3–6 weeks.
  3. Corporate and governance setup, Establish a Malaysian corporate vehicle with an appropriate board, fit-and-proper directors and senior management, and demonstrable local substance. Document governance charters, board committees and reporting lines. Common pitfall: directors who cannot satisfy the fit-and-proper standard or a board lacking relevant expertise. Typical time: 4–8 weeks.
  4. Financial requirements and capital, Meet the SC-prescribed minimum capital and prudential requirements, supported by audited accounts, capital adequacy projections and profit-and-loss forecasts that evidence the resources to operate and wind down safely. Requirements vary by activity and are prescribed by the SC. Common pitfall: thin capitalisation plans that fail prudential review. Typical time: 2–6 weeks to prepare evidence.
  5. AML/CFT programme and BNM alignment, Build a risk-based AML/CFT framework covering KYC/CDD, enhanced due diligence, ongoing monitoring, sanctions screening and suspicious transaction reporting, aligned to BNM guidance and the AMLA 2001. Appoint a Money Laundering Reporting Officer (MLRO). Common pitfall: generic policies not tailored to crypto typologies. Typical time: 4–8 weeks.
  6. Technology, custody and security, Demonstrate secure custody arrangements (segregated client assets, hot/cold wallet controls or third-party custodians), robust key management, penetration testing and proof of custody. Common pitfall: commingled assets or insufficient key-control evidence. Typical time: 4–12 weeks.
  7. Market operations and rulebook, Draft the exchange rulebook, fee schedules, listing and delisting procedures, conflict-of-interest policies and a market surveillance framework capable of detecting manipulation and abusive trading. Common pitfall: vague listing criteria and weak surveillance design. Typical time: 3–6 weeks.
  8. Application submission to the SC and RMO recognition, Compile and submit the full application pack: constitutive documents, directors’ CVs and declarations, audited financials, AML/CFT manual, IT and security reports, custody evidence, legal opinions and the rulebook. Respond promptly to SC queries. Common pitfall: incomplete submissions that trigger rounds of clarification. Typical time: SC review commonly spans 6–12 months depending on completeness.
  9. Post-approval obligations, Once recognised, maintain periodic reporting to the SC, ongoing compliance testing, independent audits, consumer safeguards and prompt incident and breach reporting. Common pitfall: treating recognition as the finish line rather than the start of continuous supervision. Typical time: ongoing.

Across these nine steps the recurring theme is evidence: the SC recognises operators that can prove, in documents and systems, that they can run an orderly, honest and resilient market. Founders seeking a digital asset exchange malaysia regulators will admit should budget realistically for governance, technology and AML build-out well before submission.

How to run an IEO in Malaysia, IEO operator requirements and steps

An Initial Exchange Offering is a regulated fundraising route in which a token issuer raises capital through an SC-approved IEO operator platform. Running or using an IEO channel requires its own discipline distinct from spot-trading recognition.

What is an IEO operator under the SC

An IEO operator is an SC-approved platform authorised to host the offering of digital tokens to investors, subject to the SC’s IEO framework. The operator’s duties include vetting issuers and tokens, ensuring adequate disclosure, implementing investor protection measures, and administering the offering within prescribed limits. The current list of approved IEO operators is published on the SC’s Digital Assets registry. The operator acts as a gatekeeper, it is responsible for the integrity of the offerings it hosts, which is why the SC applies rigorous due diligence to both operator and issuer.

  1. Confirm token classification and offering route, Determine whether the token constitutes a security requiring a prospectus or qualifies for the IEO route under the SC’s framework. This classification governs the entire structure of the raise.
  2. Engage market counsel and prepare IEO documentation, Prepare a disclosure-rich whitepaper, risk disclosures, use-of-proceeds statements and financial information consistent with SC expectations. The operator will assess the completeness and accuracy of these materials.
  3. IEO operator assessment and SC compliance checks, The approved IEO operator conducts issuer due diligence, and SC oversight applies to the operator’s processes. The issuer must satisfy the operator’s criteria on business viability, team integrity and token economics.
  4. Investor protections, Implement KYC onboarding, investment limits, clear disclosure, complaints handling and cooling-off mechanisms where required, calibrated to protect retail participants.
  5. Token listing mechanics and post-IEO obligations, Define listing arrangements, any market-making, lock-up and vesting schedules, ongoing issuer disclosure, and delisting triggers. Post-offering monitoring and reporting continue after the raise concludes.

A practical IEO readiness checklist should cover: full disclosure items and risk factors; escrow and custody arrangements for raised funds; token vesting schedules; independent smart-contract security audits; and a governance plan for post-listing issuer conduct. Our IEO operator application walkthrough sets out the disclosure templates and audit checklists issuers typically need.

Comparison: SC DAX vs Labuan digital asset licence

Founders frequently weigh an onshore SC-recognised DAX against a Labuan FSA digital asset or VASP licence. The two routes serve different commercial objectives, and the right answer depends on target markets, token profile and risk appetite.

Feature SC-recognised DAX (onshore) Labuan digital asset / VASP
Regulator Securities Commission Malaysia Labuan FSA
Typical timeline to authorisation 6–12 months (post-application completeness) 3–6 months
Minimum capital / prudential Higher / SC-prescribed (varies) Lower / Labuan FSA rules
Market access Domestic retail & institutional International / offshore focus
AML/CFT expectations BNM-aligned + SC supervision Labuan FSA + applicable Malaysian AMLA where a Malaysian nexus exists
Use case Full market access, IEO & listing Regional operations, corporate structuring, tax considerations

Takeaway: Choose the SC DAX route when the objective is direct access to Malaysian retail and institutional investors, strong onshore trust, and the ability to list tokens that may be securities under the CMSA. Consider a Labuan VASP licence when the business is regionally or internationally focused, prioritises faster authorisation and corporate/tax structuring, and does not require direct access to Malaysian retail. Many groups adopt a hybrid structure; because a Malaysian nexus can still engage Malaysian AML obligations, a Labuan structure does not eliminate onshore compliance. For a deeper commercial comparison, see our planned guide on Labuan VASP licences.

Key requirements and eligibility for a digital asset exchange licence Malaysia applicants should prepare

Before committing to a submission, applicants should map their readiness against the SC’s core eligibility pillars. A credible application for a digital asset exchange malaysia applicant intends to operate must satisfy each of the following:

  • Fit-and-proper persons: Directors, controllers and senior management must demonstrate integrity, competence and financial soundness, evidenced by CVs, declarations and background checks.
  • Malaysian presence and entity requirements: An appropriate local corporate vehicle with genuine substance, local management and operational presence.
  • Corporate governance: Board composition, committees, risk and compliance functions, conflict-of-interest controls and clear accountability.
  • Capitalisation: Minimum capital and prudential resources prescribed by the SC, supported by audited accounts and forward projections.
  • Technology resilience: Secure architecture, custody controls, key management, business continuity and disaster recovery.
  • Consumer protection: Clear disclosures, complaints handling, asset segregation and safeguards against market abuse.

Documentary evidence typically required with an application includes:

  • Statutory declarations from directors and controllers.
  • Audited accounts and capital adequacy evidence.
  • AML/CFT manual and documented risk assessment.
  • IT and security reports, including penetration-test results and custody design.
  • Legal opinions on token classification and the proposed structure.
  • Directors’ CVs and organisational charts evidencing competence and substance.

Assembling this evidence base early, and remediating gaps before submission, materially shortens the SC review cycle. Our guidance on custody and governance for DAX operators expands on the technology and board-level expectations.

AML/CFT requirements and operational compliance (BNM + SC expectations)

AML/CFT is the single most common cause of application delay and post-authorisation enforcement. DAX and IEO operators are reporting institutions under the AMLA 2001 and must meet the standards set out in BNM policy documents. At a minimum, operators are required to implement:

  • Customer due diligence (KYC/CDD): Identity verification and beneficial-ownership identification at onboarding.
  • Ongoing monitoring: Continuous review of customer activity against expected behaviour and risk profile.
  • Suspicious transaction reporting (STR): Timely reporting of suspicious activity to the competent authority as required by the AMLA.
  • Record-keeping: Retention of transaction and identification records for the statutory period.
  • Risk assessment: A documented, periodically updated enterprise-wide ML/TF risk assessment.

Because crypto presents distinctive typologies, chain-hopping, mixing services, privacy coins and rapid layering, operators must apply enhanced due diligence to higher-risk relationships and deploy transaction-monitoring systems with rules calibrated to detect layering and structuring, alongside blockchain analytics and sanctions screening. Practical build-out steps include: adopting a risk-based AML/CFT manual; appointing a qualified MLRO; commissioning independent AML audits; testing transaction-monitoring thresholds against realistic scenarios; and delivering recurring staff training. For a detailed treatment, our resource on AML/CFT for VASPs in Malaysia sets out sample KYC/CDD flows and crypto-specific risk scenarios.

Fees, timelines and practical costs

Costs vary considerably with scope, token universe and the maturity of an applicant’s systems. The figures below are indicative ranges to support budgeting; SC administrative fees should be confirmed directly against current SC schedules, and legal, technology and compliance costs depend on the complexity of the build.

Item Typical cost range Typical timeline
Legal & regulatory due diligence RM50k–RM250k (varies) 2–6 weeks
Tech/security audits & custody setup RM100k–RM500k+ 4–12 weeks
SC application & review Variable / administrative fees 6–12 months
AML/CFT implementation RM50k–RM200k 4–8 weeks

In practice, end-to-end readiness for a well-prepared applicant, from scoping to a complete SC submission, commonly spans several months of parallel workstreams, with the SC review itself typically running 6–12 months. Running these workstreams concurrently, rather than sequentially, is the single most effective way to compress the overall timeline. See our planned breakdown of typical fees and timelines for DAX applicants for scenario-based budgets.

Operational requirements: custody, security, market surveillance and tech resilience

Operational integrity underpins SC recognition and ongoing confidence in any digital asset exchange malaysia customers will use. Custody arrangements must protect client assets through segregation, robust key management across hot and cold storage, and, where used, reputable third-party custodians with clear accountability and on-chain controls. Security expectations extend to recognised information-security standards, regular penetration testing, vulnerability management, documented disaster recovery and tested business continuity. Market surveillance systems must monitor for manipulation, wash trading and abusive patterns, with escalation protocols and audit trails. Operators are also expected to maintain incident-response procedures and to report material incidents and breaches to the SC promptly.

These controls are not optional extras; they form part of the evidence the regulator reviews at recognition and tests throughout the life of the licence.

Common pitfalls and remediation

Most stalled or rejected applications fail for predictable reasons. Recognising them early allows targeted remediation before submission:

  • Inadequate AML programme: Generic policies that are not tailored to crypto typologies. Remediation: rebuild the manual on a documented risk assessment, calibrate monitoring rules and appoint a competent MLRO.
  • Weak governance or fit-and-proper gaps: Boards lacking relevant expertise or controllers who cannot satisfy integrity standards. Remediation: strengthen the board, add independent directors and document competence.
  • Incomplete token classification: Listing tokens without resolving their legal status under the CMSA. Remediation: obtain written legal opinions for the listing universe.
  • Insufficient capital plans: Thin projections that fail prudential scrutiny. Remediation: present credible, evidenced capital adequacy and wind-down resources.
  • Unclear market rules: Vague listing, delisting and surveillance frameworks. Remediation: produce a comprehensive, enforceable rulebook before filing.

A disciplined pre-application remediation phase, effectively a mock review against the SC’s criteria, consistently reduces the number of clarification rounds and shortens the path to recognition.

Conclusion

Building a compliant digital asset exchange malaysia founders and institutions can trust is an achievable but demanding undertaking in 2026. The SC’s revised RMO guidelines point to a liberalising listing environment, strong 2025 trading volumes evidence real demand, and heightened BNM AML/CFT supervision raises the bar on governance and controls. Success turns on resolving token classification under the CMSA early, assembling a credible board and capital plan, engineering resilient custody and surveillance, and implementing a genuinely risk-based AML/CFT programme supported by an MLRO and independent audit. For some groups, a Labuan VASP licence will complement or substitute the onshore route depending on market focus and structuring needs.

Whichever path you choose, grounding every decision in the primary SC, BNM, AMLA and Labuan FSA sources, and preparing a complete, evidence-rich application, is the most reliable way to reach recognition efficiently and operate with confidence.

Sources

FAQs

Which crypto exchanges are legal in Malaysia?
Only platforms recognised by the SC as Recognised Market Operators may lawfully operate a digital asset exchange for Malaysian investors. The authoritative, up-to-date list of recognised DAX and IEO operators is published on the SC’s Digital Assets registry. Investors should verify a platform’s status there before trading.
Platforms are legal only if they appear as recognised operators on the SC’s Digital Assets registry. Rather than rely on brand recognition, confirm any specific exchange’s current status directly on the SC registry, which reflects the latest recognitions, suspensions or removals.
Whether a particular token may be offered or traded depends on its classification under the CMSA and on whether a recognised operator has approved it for listing. Tokens that qualify as securities attract additional disclosure and oversight. Prospective users should check which assets are available on recognised platforms and seek legal advice on classification where the status is unclear.
Fiat on- and off-ramps are offered through SC-recognised DAX operators that provide compliant withdrawal channels. These conversions are subject to KYC/CDD, transaction monitoring and reporting obligations under the AMLA 2001 and BNM guidance, so expect identity verification and source-of-funds checks when cashing out.
To establish a digital asset exchange malaysia regulators will recognise, follow the SC’s RMO recognition route: scope the business, resolve token classification, build governance and capital, implement an AML/CFT programme and custody controls, prepare the rulebook, and submit a complete application. Review typically takes 6–12 months; see the step-by-step process above and the SC’s revised RMO guidelines.
An IEO operator is an SC-approved platform authorised to host token offerings to investors. It is responsible for vetting issuers and tokens, ensuring adequate disclosure and implementing investor protections. Approved operators are listed on the SC’s Digital Assets registry.
DAX operators are reporting institutions under the AMLA 2001 and must implement KYC/CDD, ongoing monitoring, suspicious transaction reporting, record-keeping and a documented risk assessment, aligned with BNM guidance. They should appoint an MLRO, apply enhanced due diligence to crypto-specific risks and conduct independent AML audits.
It depends on strategy. A Labuan FSA VASP licence can offer faster authorisation and tax-efficient structuring for internationally focused operations, while an SC DAX gives direct access to Malaysian retail and institutional markets. Where a Malaysian nexus exists, Labuan structures may still trigger Malaysian AML obligations, see the comparison table above.

Our Expert

Legal professional smiling at desk with a globe and legal-themed decor in modern office setting.

Jonathon Richards

Global Law Experts

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

How to Obtain a Digital Asset Exchange Licence and Run an IEO in Malaysia (DAX & IEO, SC Frameworks Explained)

Send welcome message

Custom Message