From the journal

Securities Commission Malaysia Issues 14th Revision of Digital Asset Exchange Guidelines, Effective 20 May 2026

On 20 May 2026, the Securities Commission Malaysia issued the 14th revision of its Guidelines on Recognised Markets. The revised rules strengthen governance and accountability standards for digital asset exchange operators, streamline new product approvals, and extend Financial Markets Ombudsman Service membership to digital asset exchanges.

2 min read

On 20 May 2026, the Securities Commission Malaysia published the 14th revision of its Guidelines on Recognised Markets. The guidelines govern digital asset exchange operators under the Capital Markets and Services Act 2007. The revision took effect immediately on publication.

The Capital Markets and Services Act 2007, section 34, authorises the SC to prescribe operational, governance, and client-asset standards for Recognised Market Operators. Digital asset exchange operators hold Recognised Market Operator status under that Act. The 14th revision updates conduct-of-business rules, governance expectations, and client-asset protection requirements applicable to all registered DAX platforms in Malaysia.

DAX operators must now meet tighter governance and accountability standards, including stricter client-asset safeguards. From 2026, DAX operators must join the Financial Markets Ombudsman Service, giving retail investors a formal dispute-resolution mechanism. A streamlined product approval process applies to new digital asset listings. The SC took administrative action against four exchanges operating without SC registration. It coordinated with Google to block unregistered operators from advertising to Malaysian users from 14 April 2026.

The revised guidelines include a practice note on digital asset broking services. Updated ETF guidelines permit DAX operators to offer digital currency ETFs. Operators not yet in compliance with the new governance standards should engage directly with the SC to confirm applicable timelines.

Licentium advises on digital asset regulatory matters in Southeast Asia and maintains a partner network in Malaysia and the wider APAC region. Entities seeking Recognised Market Operator status or reviewing their obligations under the revised guidelines may contact us. Work we undertake includes DAX authorisation, regulatory engagement with the Securities Commission Malaysia, digital asset product registration, and exchange governance reviews.

Source: Securities Commission Malaysia, Media Release: SC Issues Revised Guidelines on Recognised Markets for Digital Asset Exchange, 20 May 2026

Crypto Regulatory

More from the journal

See all
Illia Prokopiev

From Cloud Concentration to AI Dependence: The UK’s Critical Third Parties Regime

The United Kingdom now directly oversees designated technology suppliers whose service failures could threaten financial stability. The question is whether the first cloud designations show a legal expansion toward AI-model providers, and what the present regime requires. This analysis assumes the quoted statement concerns the UK financial-services Critical Third Parties regime and assesses the law through 14 July 2026.

Alberta Regulated iGaming Market Launched on 13 July 2026 with 22 Operators

Alberta's regulated private iGaming market launched on 13 July 2026, making Alberta the second Canadian province to permit private online gambling operators after Ontario. The Alberta Gaming, Liquor and Cannabis Commission serves as market regulator and the Alberta iGaming Corporation oversees commercial operations and operator contracts. Twenty-two operator sites went live on day one, including FanDuel, DraftKings, BetMGM, and BetRivers. Operators must fully launch or exit the Alberta market by 13 October 2026.

European Commission Presents Cybersecurity and AI Action Plan on 7 July 2026

On 7 July 2026, the European Commission presented an Action Plan on Cybersecurity and Artificial Intelligence. The plan directs the Commission and ENISA to evaluate advanced AI models before they reach the EU market, establish a secure testing platform for critical-sector organisations, and launch an EU Grand Challenge on AI-powered cybersecurity solutions. It operates alongside the AI Act, NIS2 Directive, DORA, Cyber Resilience Act, and Cyber Solidarity Act, and introduces no new directly binding obligations.