| 1 | Platform and custody securityOwned by the CISO and security engineering | Can the platform or the keys be broken into?The precondition for everything else | Infrastructure, keys, sessions, withdrawalsCold storage tiers and signing policy | A hardened platform and controlled fund movementPlus incident response when prevention fails |
|---|
| 2 | Customer and funds complianceOwned by the MLRO and the compliance function | Who is this customer, and where did the funds come from?Identity and provenance, not behaviour | Identity documents, sanctions and PEP lists, fund flowsDeposits, withdrawals and counterparties | Verified customers, screened flows, filed reportsFiling-ready SAR cases with an audit trail |
|---|
| 3 | Market-conduct surveillanceOwned by market conduct or compliance surveillance | How are participants behaving in our markets?Behaviour, not identity | Orders, amendments, cancellations, fills, account linksStraight from the matching engine | Manipulation alerts, replay and a defensible case fileSpoofing, wash trading, cross-market patterns |
|---|
| 4 | Asset admission due diligenceOwned by the listing committee | Should this token be listed on our venue at all?A gate, decided once and re-opened on triggers | Contract, holders, liquidity, governance, treasuryPlus the token's own transaction history | A sectioned listing-risk report and a decision recordSeverity on every finding, thresholds set by you |
|---|
| 5 | Protocol dependency reviewOwned by whoever signs off integrations | Is this protocol sound enough to depend on?A gate on what you connect to | Contract logic, privileged roles, oracles, bridgesAnd the economics under stress | Findings with severity, remediation and a re-testA review, never an audit certificate |
|---|