2026-10-09
Added · Updated
The Securities Commission of The Bahamas reports on the supervision of digital asset businesses registered under the Digital Assets and Registered Exchanges Act, 2024, covering the period from 1 January 2021 to 30 September 2026. As of August 2026, the register included 35 firms with 20 active registrants holding combined client assets of USD 33.65 billion. The report details a 2026 onsite examination programme testing AML/CFT/CPF compliance across 17 active registrants and Travel Rule compliance for 1,831 sampled transfers. It also outlines market surveillance findings showing estimated on-chain volumes of USD 401.9 million between September 2024 and December 2025, with illicit exposure consistently below 3 per cent.
SCB published 4 documents in the last 30 days — get each new one by email the day it lands.
1 JANUARY 2021 TO 30 SEPTEMBER 2026
DIGITAL ASSET SUPERVISION
AND SURVEILLANCE
REPORT
PUBLISHED DATE: 9 OCTOBER 2026
Securities Commission of The Bahamas Digital Asset Supervision and Surveillance Report Securities Commission of The Bahamas All rights reserved. No part of this publication may be reproduced or distributed without the prior written permission of the publisher. This document does not constitute legal advice. This publication is available at www.scb.gov.bs. © Copyright 2026 Securities Commission of The Bahamas
Securities Commission of The Bahamas Digital Asset Supervision and Surveillance Report CONTENTS
Securities Commission of The Bahamas Digital Asset Supervision and Surveillance Report
Securities Commission of The Bahamas Digital Asset Supervision and Surveillance Report offering facilitation, at very different stages of operational maturity and in several cases within international groups. The Digital Assets and Registered Exchanges Act, 2024 replaced the 2020 Act, strengthening the Commission’s inspection, information-gathering and sanctioning powers and the obligations of registrants. Registrants under the Digital Assets and Registered Exchanges Act, 2024, while defined as financial institutions under the Financial Transactions Reporting Act, 2018, are regulated for AML/CFT/CPF purposes pursuant to that Act, the Financial Transactions Reporting Act, the Anti-Terrorism Act, the Proceeds of Crime Act and the Digital Assets and Registered Exchanges (AML/CFT/CPF) Rules, 2022, a framework compliant with and guided by FATF Recommendation 15 on virtual asset service providers. As at Registered digital asset businesses Ratings for year Rating profile 31 December 2021 First registrants licensed in Q4 2021 – – 31 December 2022 10 2021 100% medium 31 December 2023 18 2022 100% medium 31 December 2024 25 2023 100% medium 31 December 2025 32 2024 100% medium 31 August 2026 35, of which 20 active 2025 22% low, 69% medium-low, 9% medium-high
Table 1: The registered population at each date, with risk ratings stated by the year rated.
Source: Commission Annual Reports, the Commission’s supervisory risk records, and the register of digital asset businesses published on the Commission’s website (35 registered firms as at 31 August 2026, with one former registrant in official liquidation listed separately). Ratings are stated by the year they rate: the rating for a year is computed from that year’s data in the following cycle, so the ratings in force at each date shown are those for the preceding rated year, and every registrant has been rated in every cycle. For the rated years 2021 through 2024 the population was rated in the medium band throughout, with no registrant rated high risk or low risk, reflecting a young sector with substantial inherent risk met by intensive supervision. The 2025 ratings are computed under the Commission’s strengthened risk methodology and are those published in the Commission’s sectoral risk assessment of the digital asset sector; the finer-grained distribution reflects the enhanced methodology. Active registrants are those conducting or authorised to commence live business; the remainder are pre-operational, dormant or in wind-down. Custody arrangements across the registered population are predominantly third-party, with recognised institutional custodians and wallet-infrastructure providers in widespread use alongside a small number of in-house, group-affiliated and hardware-based arrangements.
4. Market activity and surveillance
4.1 The surveillance programme
The Commission operates a continuous market surveillance programme over digital asset activity connected to the jurisdiction, using commercial blockchain analytics alongside its supervisory data. The programme estimates on-chain activity originating from the jurisdiction, verifies the on-chain attribution of registered digital asset businesses and analyses their counterparty exposure, screens flows for exposure to illicit and sanctioned counterparties, and identifies suspected unregistered services. Surveillance results are reported to the Commission on a periodic cycle and inform examination scoping, enforcement referral and international cooperation.
4.2 Market trajectory
Securities Commission of The Bahamas Digital Asset Supervision and Surveillance Report On-chain activity connected to the jurisdiction peaked in late 2022. From that peak to the trough at the end of 2023, estimated transaction volumes contracted by more than 70 per cent in both directions, reflecting the exit of the jurisdiction’s largest market participant and the global market cycle. Activity since has been materially smaller and event-driven: an estimated USD 401.9 million in total on-chain volume across wallets connected to the jurisdiction between September 2024 and December 2025, and an estimated USD 70.1 million between January and July 2026, concentrated in a small number of quarters. These figures measure on-chain transfers between wallets connected to the jurisdiction; they are not measures of trading volume on registered exchanges or of conversions to or from fiat currency. The composition of activity has also shifted, with decentralised finance protocols overtaking centralised exchanges as the dominant counterparty type from 2024. At 31 December 2025, the registered sector served 2,159,398 clients and held combined client assets of USD 33.65 billion. The client base is overwhelmingly international: clients resident in The Bahamas numbered 1,376, with client assets of USD 16.5 million, so that more than 99.9 per cent of clients and of client assets related to clients resident abroad.
4.3 Illicit exposure
The surveillance programme also traces where flows connected to the jurisdiction go. Destinations are classified by the analytics into legitimate services, services associated with criminal activity (such as scams, darknet markets, stolen-funds wallets and sanctioned platforms), and higher-risk services such as exchanges without customer identification requirements. Some measured exposure to such destinations exists in every jurisdiction’s flows, because the measurement covers all wallets connected to the jurisdiction, including personal wallets outside any registrant; the Commission measures it so that it can see such exposure and act on it. The measured exposure here is consistently small. Inflows from higher-risk sources were estimated at 0.16 per cent of inbound value in the period to May 2024, a decline from previous years. Of flows traced to classified destinations between September 2024 and December 2025, an estimated 97.7 per cent went to legitimate services, 2.03 per cent to services associated with criminal activity and 0.27 per cent to higherrisk services. Between January and July 2026, the corresponding estimates were 97.12 per cent, 2.80 per cent and 0.07 per cent; the 2.80 per cent is driven principally by flows to a single international exchange designated by a foreign sanctions authority in May 2026, most of which predate the designation, and amounts in absolute terms to an estimated USD 468,376, or 0.67 per cent of total period volume. Period Estimated on-chain volume (USD) To legitimate services To services associated with criminal activity To higher-risk services September 2024 to December 2025
401.9 million 97.7% 2.03% 0.27%
January to July 2026 70.1 million 97.12% 2.80% 0.07%
Table 2: Market surveillance snapshot. Shares are of flows traced to classified destinations in each period.
Source: Commission market surveillance programme, estimates derived through commercial blockchain analytics. Figures are conservative lower-bound estimates based on on-chain observation and do not capture activity conducted wholly within custodial platforms. The on-chain attribution of the registered population is verified periodically. At the most recent attribution check, 10 registered digital asset businesses were attributed on-chain and are analysed individually for counterparty and direct exposure; the remainder principally comprise pre-operational registrants and businesses whose models do not generate attributable on-chain footprints.
Securities Commission of The Bahamas Digital Asset Supervision and Surveillance Report
4.4 Suspicious transaction reporting
Sector 2021 2022 2023 2024 2025
Suspicious transaction reports filed by digital asset registrants 4 342 34 164 206
Table 3: Suspicious transaction reports filed by the digital asset sector, calendar years.
Source: Financial Intelligence Unit quarterly statistics, stated for calendar years. Of the 2022 reports, 330 related to the collapse of a single exchange, then the second largest digital asset exchange globally; measured against the scale of its transaction volumes, the reporting level was proportionate to the events. The growth in 2024 and 2025 reflects the expansion of the supervised population and intensified supervisory attention to reporting obligations.
5. Perimeter monitoring
Supervision of a registered sector is only as strong as the perimeter around it. The surveillance programme applies conservative analytical parameters to distinguish service-like on-chain behaviour from personal wallet activity connected to the jurisdiction, and flags suspected unregistered services for assessment. Each flagged service is assessed for scale, counterparty exposure and indications of illicit exposure, and is kept under continuing review. As at the reporting date, a small number of suspected unregistered services connected to the jurisdiction are under monitoring: three services, of which two remain active and one has shown no activity since August
2025. One of the monitored services shows exposure to higher-risk counterparty categories and is
prioritised accordingly. Where monitoring supports it, the Commission’s gateways are available to identify the operators, including information requests to service providers, cooperation with registered and foreign exchanges, referral to the Commission’s enforcement function and international cooperation with counterpart authorities. Conducting digital asset business from or within the jurisdiction without registration is an offence, and the Commission treats the perimeter accordingly.
6. The supervisory programme, 2021 to 2026
The Commission’s supervision of the sector has followed a deliberate sequence: bring the market inside the perimeter, risk-rate it, diagnose the state of every registrant to a uniform standard, strengthen the statute, communicate expectations individually, and then test compliance intensively where it matters most. The
table below sets out the sequence.
Year Supervisory activity
2021 First registrants licensed under the 2020 Act in the final quarter; sector enters the supervisory perimeter. 2022 Entity risk ratings in place across the registered population from the 2021 rating year; failure of the sector’s largest registrant in November 2022; intensive supervisory engagement and event-driven reporting (342 suspicious transaction reports). 2023 Two onsite examinations of registrants; the Commission engages an externally supported diagnostic review of the entire registered population (thirteen entities). 2024 Digital Assets and Registered Exchanges Act, 2024 comes into force; review fieldwork continues; onsite coverage of the sector provided through the review.
Securities Commission of The Bahamas Digital Asset Supervision and Surveillance Report Year Supervisory activity 2025 Firm-specific review reports disseminated to registrants on a rolling basis from December; onsite coverage of the sector provided through the review. 2026 (to 30 September) Thematic AML/CFT/CPF and CRS onsite examination programme reaching seventeen of the twenty active registrants, with Travel Rule compliance tested across 1,831 sampled transfers reaching back to 2021; structured quarterly engagement meetings begin in September.
Table 4: The supervisory sequence for the digital asset sector.
Source: Commission supervisory records and the Examinations Department examinations register. The 2023 examination figure appears in the Examinations Report 2021-2025 and reconciles to it.
7. The sector-wide diagnostic review, 2023 to 2025
7.1 Why the review was conducted
By 2023, the Commission supervised a young and heterogeneous registered population operating under international attention following the failure of its largest registrant in November 2022. The Commission determined to satisfy itself, entity by entity, of the state of governance, controls and risk management across the whole registered population, and commissioned an externally supported diagnostic review of every registered digital asset business for that purpose. The review was conceived as a supervisory improvement exercise: the Commission committed to registrants at the outset that the review would not be used for enforcement purposes. That commitment was deliberate. It secured the candid access and full cooperation on which a diagnostic of this depth depends, and it reflected the Commission’s judgment that the fastest route to raising standards across the whole population was the intensive identification of areas for improvement at every registrant simultaneously, rather than case-by-case enforcement against a maturing industry. Conducted across the transition from the 2020 Act to the 2024 Act, the review also gave the Commission a population-wide baseline against which the sector’s adoption of the strengthened framework can be measured.
7.2 What was done
The review comprised 12 reviews spanning the 13 registered entities then on the register, with two affiliated entities reviewed together. Fieldwork was conducted under a framework developed by the Commission with external assistance, through documentation review, written questionnaires and structured interviews with management, across five areas of assessment: governance and operational resilience, regulatory compliance, digital assets operations, financial analysis and reporting, and financial risk management. Each registrant received an individualised set of observations, prioritised for its attention.
7.3 What the review found
Every registrant was examined against the same five areas to the same level of granularity, and each review produced a substantial and broadly consistent body of observations, between 25 and 45 per registrant. That consistency reflects the uniform depth of the review framework rather than the condition of any particular firm: a diagnostic that sets out to identify every area for improvement will, at any well-run institution, produce a substantial list, and the observations are areas for improvement rather than findings of breach. The dominant patterns are the classic markers of institutional maturity applied to a new asset class:
alignment of policy frameworks to current legislation, evidence of board approval and version control for
Securities Commission of The Bahamas Digital Asset Supervision and Surveillance Report policies, formalisation of custody key-management and blockchain-event procedures, proof-of-reserves discipline, and the development of stress testing and contingency funding capability. Two themes spanned the entire population: documentation discipline, the ability to evidence on demand what is claimed to operate, and the absence of documented procedures for blockchain events such as hard forks, airdrops and network attacks, a genuinely sector-specific gap. The population divided into an operational cohort of five registrants and a pre-operational or dormant cohort of seven, and for the pre-operational cohort most observations are readiness gaps to be closed before commencement of live business rather than live exposures.
7.4 What followed, and next steps
Firm-specific reports were disseminated to registrants on a rolling basis beginning in December 2025, giving each registrant an individualised and prioritised roadmap. The Commission monitors progress against each registrant’s observations through structured quarterly engagement meetings, conducted on a confidential basis consistent with the terms of the review, with readiness matters for the pre-operational cohort treated as conditions of commencement. Sector-wide themes identified by the review inform the Commission’s instruments and guidance for the sector, including Travel Rule compliance guidance published in August 2026, guidance under development on the custody of client digital assets and the management of digital asset events, and amendments to the sector’s AML/CFT/CPF rules issued for consultation in 2026. The review’s non-enforcement terms gave up nothing in supervisory reach: the obligations it examined remain fully enforceable, and the review sharpened the risk basis on which the 2026 examination programme was scoped and targeted.
8. The 2026 onsite examination programme
Since January 2026 the Commission’s examiners have conducted a thematic onsite examination programme across the digital asset sector, testing compliance directly against the obligations at the core of the FATF standards as they apply to registrants: targeted financial sanctions and sanctions screening, customer due diligence, ongoing monitoring, suspicious transaction reporting, risk assessment, training and record keeping, anchored to the Digital Assets and Registered Exchanges (AML/CFT/CPF) Rules, 2022, the Financial Transactions Reporting Act, 2018, the International Obligations (Economic and Ancillary Measures) Act orders and the Anti-Terrorism Act, 2018, together with Common Reporting Standard obligations. The programme carries the Commission’s full supervisory and enforcement toolkit. In the reporting period the programme comprised 16 thematic AML/CFT/CPF examinations and five focused Travel Rule reviews, reaching 17 of the 20 registrants on the active register; Travel Rule testing ran across the programme and is reported in section 9. Two thematic examinations concluded with no deficiencies identified. Across the 16 thematic examinations, 82 findings were recorded, an average of just over five findings per examination, together with 16 non-binding recommendations; the results of the focused Travel Rule reviews are reported, with all Travel Rule testing, in section 9. No Common Reporting Standard findings were recorded. Area of obligation Findings Annual sanctions declarations (International Obligations (Economic and Ancillary Measures) Act orders) 35
Securities Commission of The Bahamas Digital Asset Supervision and Surveillance Report Area of obligation Findings Quarterly terrorist property reporting (Anti-Terrorism Act, 2018) 9 Customer risk assessment and rating 8 Customer due diligence, identification and verification 7 Ongoing monitoring 7 AML/CFT/CPF training 6 Record keeping 4 Money laundering reporting officer arrangements 3 Travel Rule and transaction records 2 Enhanced due diligence 1 Total 82
Table 5: Findings of the 2026 thematic examination programme by area of obligation.
Source: Examinations Department reports and letters, 2026 programme. The table covers the 16 thematic examinations only:
breaches identified through the focused Travel Rule reviews are reported in section 9, so the Travel Rule row does not state the sector’s full Travel Rule results. Remediation timelines are set per finding under the Commission’s remediation framework, and remediation is verified against an evidence-based standard before a finding is closed. Two patterns dominate. First, more than half of all findings concern periodic statutory filings: annual declarations under the sanctions orders and quarterly terrorist property reports, where filings were late or could not be evidenced. These are remediable by calendar discipline, and the Commission’s published guidance sets the expected standard. It bears stating plainly what the findings do not show: no finding in the programme indicated that a designated or sanctioned person went unreported, that a positive screening match was missed, or that assets that should have been frozen were not. The deficiencies concern the discipline of periodic filings, not missed sanctions exposure. The Commission’s published sectoral risk assessment supports the same conclusion: reporting registrants screen 100 per cent of transactions through blockchain analytics, including against designated wallet addresses, it is that screening which identified and quantified the sector’s indirect exposure to sanctioned addresses, with findings disclosed to the Commission, and no registrant reports clients resident in a jurisdiction subject to a FATF call for action. Second, the remaining findings concentrate in the core preventive controls: customer due diligence, ongoing monitoring, risk assessment and training. The profile corroborates the diagnostic review from the compliance-testing side: the areas the review identified as the sector’s most prevalent areas for improvement are the areas where examinations now find deficiencies, and the examination programme tests precisely those obligations with the full supervisory toolkit available where findings warrant it.
Securities Commission of The Bahamas Digital Asset Supervision and Surveillance Report
9. Travel Rule testing
The Travel Rule requires originator and beneficiary information to accompany digital asset transfers. In The Bahamas, the Travel Rule obligations of registrants are set out in the Digital Assets and Registered Exchanges (AML/CFT/CPF) Rules, 2022. The Commission collects information on registrants’ Travel Rule compliance each year through the Risk Data Return: registrants report complete originator and beneficiary information for approximately 99 per cent of transfers sent and received, weighted by the sector’s client base, and 96 per cent on a simple average across reporting registrants, as published in the Commission’s sectoral risk assessment. The Commission also collects a quarterly Travel Rule compliance return; returns for the quarter ended 30 June 2026 were being received and verified at the reporting date and will be reported in a future edition. Dedicated Travel Rule compliance guidance was published in August 2026. Travel Rule compliance is tested as a standing component of the examination programme, not as a separate exercise, through dedicated Travel Rule testing within thematic examinations and through focused Travel Rule reviews. Separate Travel Rule examinations were conducted for each year Travel Rule compliance was applicable for the respective registrant. The 2026 programme delivered 44 Travel Rule examinations across the years 2021 to 2026, sampling 1,831 transfers, and in every year examined it covered the full population of registrants to which the Travel Rule applied in that year. Four registrants were not tested because they have no clients and no in-scope transfers, and one further registrant without clients was tested on its proprietary transfers notwithstanding. Eight breaches were identified across the 44 examinations, concerning three registrants. Year of tested transfers Travel Rule examinations Breaches identified 2021 1 0 2022 2 1 2023 7 1 2024 11 2 2025 12 2 2026 (partial year) 11 2 Total 44 8
Table 6: Travel Rule testing and results by year of the tested transfers.
Source: Examinations Department reports and letters, 2026 programme, per the Examinations Department’s examination records. Examinations and breaches are counted by the year of the transfers tested: an examination whose sample spanned several years is counted in each of those years, as is a breach whose transfers fell in more than one year. 2026 is a partial year, with testing running to July and August 2026. In every breach the deficiency was the same in kind: documentary evidence of required originator or beneficiary information was not maintained or could not be produced for tested transfers, and each of the three registrants concerned carries a remediation deadline under the Commission’s remediation framework. The examination results corroborate the compliance registrants report through the annual Risk Data Return, and show a compliance base that is substantially sound and a regime that has been strengthened while testing was under way. Travel Rule testing remains a standing component of the examination programme, alongside the annual Risk Data Return and the quarterly Travel Rule compliance return.
Securities Commission of The Bahamas Digital Asset Supervision and Surveillance Report
10. Supervisory effect and the forward programme
The supervisory sequence described in this report is designed to produce measurable change, and its instruments are now all in operation at once: individualised roadmaps at every registrant reviewed, quarterly engagement meetings monitoring remediation, an examination programme testing compliance with remediation deadlines attached to every finding, a strengthened statute, published guidance, annual risk and Travel Rule reporting through the Risk Data Return and quarterly Travel Rule reporting, and continuous market surveillance across and beyond the registered perimeter. Remediation of the 2026 examination findings is tracked finding by finding and verified against an evidence-based standard before closure, and progress against review observations is monitored through the quarterly engagement cycle. The forward programme continues on a risk-sensitive basis. Examination selections are drawn against current entity risk ratings, with the diagnostic baseline informing scoping; the quarterly engagement cycle continues until observations are satisfactorily addressed, with readiness matters treated as conditions of commencement for pre-operational registrants; guidance on the custody of client digital assets and the management of digital asset events will address the review’s most prevalent sector-specific gap; and amendments to the sector’s AML/CFT/CPF rules, issued for consultation in 2026, will carry the framework’s alignment forward. The Commission expects the standards evidenced by this population to converge on those of the jurisdiction’s established securities industry, and will report against that expectation in future editions of this report.
Annex A. Glossary and abbreviations
Term Meaning
AML/CFT/CPF Anti-money laundering, countering the financing of terrorism and countering proliferation financing CRS Common Reporting Standard DARE 2020 / DARE 2024 Digital Assets and Registered Exchanges Act, 2020; Digital Assets and Registered Exchanges Act, 2024 DARE Rules 2022 Digital Assets and Registered Exchanges (AML/CFT/CPF) Rules, 2022 DeFi Decentralised finance FTRA Financial Transactions Reporting Act, 2018 IOEAMA International Obligations (Economic and Ancillary Measures) Act MLRO Money laundering reporting officer On-chain Recorded on a public blockchain STR Suspicious transaction report Travel Rule The requirement that originator and beneficiary information accompany digital asset transfers VASP Virtual asset service provider
Read the rest free
Source: Securities Commission of The Bahamas — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works