You’re reading Crypto for Advisors, CoinDesk’s weekly newsletter that unpacks digital assets for financial advisors. Subscribe here to get it every Thursday.
You’re reading Crypto for Advisors, CoinDesk’s weekly newsletter that unpacks digital assets for financial advisors. Subscribe here to get it every Thursday.
In today’s newsletter, Maria Golenkov explains how the EU’s MiCA framework is the blueprint for future U.S crypto regulation. Learn why your governance and controls need to align now to avoid scrambling later.
Then, in “Ask an Expert,” Felix Xu answers questions around why operational risk is the primary investment risk in digital assets, explaining the specific internal controls advisors must demand.
MiCA’s final deadline just hit in Europe. U.S. advisors should be taking notes.
Right now, America's crypto regulatory landscape is fragmented across multiple agencies. The Securities and Exchange Commission (SEC) regulates one thing, the (CFTC) another, FinCEN handles its piece, and then you have state-level requirements on top. No master playbook. No unified vision. The European Union, meanwhile, finished writing theirs in 2023, implemented it through 2024 and has been enforcing it since. The Markets in Crypto-Assets Regulation, or MiCA, is now the standard everyone in Europe has to meet. And as of July 1, 2026, the grace period is over. The transitional window that let firms keep operating under old national rules expired with no extensions. Serve EU clients now and you need full authorization, or you wind down.
This matters because Europe always moves first on financial regulation, and America follows. It's happening now, and most advisors aren't paying attention yet.
So what does MiCA require? If you offer crypto services like custody, advisory or exchange, you need a license and a regulator watching what you do. Client assets get segregated, independently audited and monitored in real time. Capital and transparency requirements apply. Companies explain risks to clients in plain language, not legalese.
I raise this because what happens without those controls is ugly. Galois Capital lost 50% of assets on FTX, which wasn't even a qualified custodian. Binance faced SEC and CFTC enforcement in 2023 for improper asset segregation and inadequate risk disclosures. It managed billions. It still didn't have proper governance. This wasn't incompetence; this was what happened when the rules were unclear, so companies gambled on legality.
For years, the US operated in enforcement mode. Coinbase launched staking and got sued. Binance took deposits and got sued. Nobody knew if they were inventing a service or breaking a law. The agencies weren't being malicious; they just didn't have a framework. That shifted in September 2025, when the SEC and CFTC issued a joint statement clarifying that registered exchanges could facilitate trading of certain spot crypto products. Then in March 2026 they went further, publishing joint guidance on which crypto assets are securities and which aren't, and how stablecoins fit in.
The pattern is hard to miss. The U.S. is running roughly a year behind the EU, and its guidance isn't binding rulemaking yet. The enforceable version is still coming, and it will look a lot like MiCA.
If you manage digital assets for clients, governance frameworks aren't something you build, hand off to compliance and forget about. They're your fiduciary baseline. Fidelity surveyed institutional investors and found 58% are already allocating to digital assets, yet custody security and regulatory clarity remain their biggest concerns. Your clients are entering this space. Your job is proving you have controls in place, not a checklist you downloaded.
Start by auditing what you're doing now. Do you have documented governance? Has anyone independently verified your controls? Are you managing cyber risk or just hoping nothing breaks? Then get specific about what you offer. Custody is different from advisory. If you're holding assets, you need segregated accounts and real-time monitoring. If you're giving advice, you need suitability documentation and conflict-of-interest disclosures.
Then build incrementally. Doing it properly takes time, sometimes a year or more, depending on your gaps and whether your team understands segregation of duties. No two frameworks end up identical, because no two firms operate alike.
I've built these frameworks for firms in exactly this position, and the pattern never changes: teams estimate implementation time and miss it by a factor of two or three. They plan for nine months; it takes eighteen. The rules are rarely the hard part. Retrofitting controls into systems built without them is.
The firms winning right now started early. The ones that waited until enforcement hit spent the next two years writing settlement checks and rebuilding trust.
Here's my question: if you launched a governance framework today, how long would it take your firm to run it effectively? Double that number. Maybe triple it. Then work backward to when you should start. The regulators have shown their hand. Europe built the model. America is building the same thing. The only variable is whether you're ready first, or scrambling to catch up.
- Maria Golenkov, partner and head of digital assets, governance, risk & controls, DLA LLC
Q. What internal controls framework should advisors demand before allocating to digital assets?
The first thing advisors should understand is that operational risk in digital assets is not a secondary consideration. It is part of the investment risk. In traditional markets, investors can often rely on a mature network of custodians, administrators, prime brokers, auditors and standardized reporting systems. In digital assets, those protections are less consistent, and the manager’s internal control environment carries much more weight. Before discussing returns, advisors should understand who controls the assets, who can move them, how transactions are approved and how positions are independently reconciled.
I would focus on whether the structure makes sense in practice. No single person should be able to initiate, approve and settle a transaction. Wallet permissions should be limited by role, transaction size, counterparty and approved address. Custody, trading, valuation and reconciliation should be sufficiently independent from one another. Advisors should also ask how exceptions are handled, because that is often where the risk is. What happens when a trader needs to use a new protocol, transfer assets outside normal hours or respond to a market disruption? A credible framework should make those decisions controlled and traceable without making the business unable to operate.
Q. What is unique about digital asset management when it comes to ensuring timely and accurate reporting, reducing regulatory scrutiny and potential penalties?
The main difference is that the transaction record is highly visible, but the accounting meaning is often not. A blockchain can show that an asset moved from one address to another, but it does not tell you whether that movement was a trade, collateral transfer, bridge transaction, staking deposit, internal reorganization, fee payment or something else. That distinction matters for valuation, financial reporting, tax treatment and regulatory review. The data is available, but turning it into a reliable set of books requires strong systems and consistent judgment.
The firms that run into problems are the ones with too much fragmented data and no disciplined process for classifying it. By the time an audit or regulatory request comes in, the team may be trying to reconstruct activity from wallet histories, spreadsheets and employee knowledge. That is where small inconsistencies become expensive. The better approach is to build reporting into the transaction process itself. Every material transaction should have a clear business purpose, an approver, a valuation source, and a documented accounting treatment at the time it occurs. Accurate reporting is usually the result of good operational design rather than a more sophisticated year-end cleanup.
Q. Best way for people to stay on top of crypto accounting, governance and technological change.
The answer is not to follow every headline. In a market that changes this quickly, information without a framework can create more noise than insight. Firms should establish a disciplined review process that separates changes requiring immediate action from developments that are merely interesting. Regulatory releases, accounting guidance, custody rules, tax interpretations and material protocol changes should be assigned to specific owners and reviewed on a defined schedule. External accountants, legal counsel, administrators and technical specialists can provide important perspective, but someone inside the organization must remain accountable for translating that advice into policies, controls and operating decisions.
The strongest organizations also create a feedback loop between the investment, operations, finance, legal and technology teams. A new protocol feature may appear to be an investment opportunity, but it can also change custody assumptions, valuation methods, liquidity risk or reporting obligations. Those implications need to be considered before capital is deployed, not discovered during an audit. Digital asset firms do not need to predict every technological or regulatory development. They need governance structures that allow them to evaluate change consistently, document their decisions and adapt without weakening the controls around client capital.
- Felix Xu, co-founder, ZX Squared Capital
- MARKETS: For the first time ever, the S&P 500 to bitcoin ratio has broken and held above its 200-week moving average.
- Western Union has launched Stablecard, a Rain-powered Visa card for holding and spending dollar-backed stablecoins.
Looking for more? Receive the latest crypto news from coindesk.com and market updates from coindesk.com/institutions.
Binance remains crypto’s leading exchange, expanding from spot and derivatives into RWAs, payments, savings, yield, and broader financial services.