A practical route through official records, with EU, UK and US examples. Learn which entity to search, how to read the permission, and what to do when details do not match.
An exchange can advertise a licence belonging to a company that will never hold your account. The brand may operate through several entities, and the product you choose can have different permissions from its spot trading service. Before relying on a regulatory badge, identify the company in your agreement and the country whose rules apply to your use.
We reviewed official sources on 28 September 2026. The checks below cover selected EU, UK and US records; readers elsewhere should begin with their local regulator’s guidance. They explain how to investigate a claim, not certify an exchange or provide a complete legal assessment of every jurisdiction.
1. Identify the entity behind your account
Start with the customer agreement or legal information page. Save the full company name, country, product and website address. A store listing or familiar logo can help identify an app, but neither establishes which company owes you the contractual service.
The term crypto-asset service provider covers more than a retail trading screen. A custodian and an exchange operator may be different firms. Our centralized exchange explanation separates an account balance from direct control of on-chain assets; here, the task is to match the service with its responsible entity.
2. Choose the register for your location and service
| Location | Starting point | Limit to remember |
|---|---|---|
| European Union | ESMA MiCA provider register and the relevant national authority | Match the entity, permitted service and status; do not search only the white-paper list. |
| United Kingdom | FCA register and current crypto registration guidance | AML registration is not a blanket approval of every crypto product. |
| United States | Relevant state regulator; FinCEN MSB record where applicable | An MSB entry is not a nationwide crypto licence or government endorsement. |
If you live elsewhere, use your own regulator’s current guidance. A foreign licence should not be treated as permission to serve you everywhere. Likewise, a website accepting a signup does not establish that its product is available to residents of your country or state.
EU: read the provider record, not the token’s white paper
Open the ESMA MiCA register page and select the provider dataset. At our review date, the page offered separate downloads for providers, issuers, white papers and non-compliant entities. A token appearing in a white-paper file is not evidence that the exchange selling it has the right permission.

The official field descriptions distinguish legal name, trading name, website, competent authority, service codes and withdrawal date. Match the legal entity first, then inspect the service you intend to use and any end date or comment. Do not assume that finding a row means an authorisation remains active.
ESMA explains that national updates may precede its periodically refreshed register. If records conflict, check the responsible national authority’s current information and retain the dates. An empty search result needs investigation; it should not be silently converted into either approval or an accusation.
UK: separate AML registration from product protection
The FCA’s crypto AML/CTF guidance says registration under the money-laundering rules is not an endorsement. Read the firm’s registration category and the current rules for the particular activity. A firm can have permissions for one financial service without every crypto offering having the same treatment.
Customer KYC and AML checks do not prove that an exchange has the permissions it claims. Nor should a regulatory badge be read as deposit insurance. The FCA’s consumer crypto guidance warns that buyers should not expect compensation to cover crypto losses. Check the specific product instead of importing protections from a bank account or another service.
US: a FinCEN entry is not the whole licensing check
FinCEN’s MSB registration explanation states that inclusion is not a certification of legitimacy or an endorsement. Registration data is supplied by the registrant. Save the legal name and any trade name, but do not stop at a screenshot labelled “FinCEN registered”.
Check the regulator relevant to your state and activity. For example, New York DFS’s virtual currency page lists regulated entities and licence or charter types for its jurisdiction. That is a New York example, not a claim that one state record settles access in every state or covers every product. Securities or derivatives offerings may require different checks; a spot-exchange registration should not be stretched to cover them.
3. Match the website and contact details
Clones can copy a real company’s name and registration number while using another domain or phone number. Compare the register’s contact information, where supplied, with the site you are using. The FCA’s firm-checking guide explains this impersonation problem and distinguishes registered activities from permissions.
Navigate independently rather than following the same message whose authenticity you are testing. If the register does not publish a website, record that gap and seek confirmation through an independently established company channel. A padlock in the browser shows an encrypted connection; it does not resolve the identity or permissions question. For wallet requests, our phishing and suspicious-signature guide covers the separate risks of connecting or signing.
Worked example: a real name on the wrong account
Imagine a hypothetical “Example Markets EU Ltd” listed for an applicable service. An advert redirects you to another domain whose customer agreement names “Example Global Ltd”. Even if both names share a brand, you have not matched the contract to the record. The registration number pasted in the advert does not close the gap.
Write down the mismatch before sending money or identity documents. Ask which entity provides the service for your location, then verify that answer against the appropriate record. If the new entity cannot be reconciled with the claim, leave the check unresolved. A successful small withdrawal would test one transfer, not the legal status of the firm.
4. Keep a dated evidence note
A short record makes the next review easier. Keep the following information together without uploading identity documents into a public note:
- The full entity name, jurisdiction, product and agreement version.
- The regulator, register name, exact record URL and date checked.
- The observed registration or permission, service scope and any restrictions or end date.
- The domain and independently checked contact details.
- Any unresolved difference, with the question still needing an answer.
Recheck when the contract, operator, domain or service changes. Preserve an old record as dated evidence; do not present it as today’s status. If access to a register is temporarily unavailable, delay the conclusion rather than substituting a marketing page.
5. Evaluate commercial terms separately
A correct identity match does not measure solvency, cybersecurity or the price risk of a token. Low trading fees and high reported volume do not fill a missing permissions record either. Once the regulatory question is clear, our US-focused crypto exchange comparison helps separate product access, fees and practical trade-offs.
The useful outcome is a specific statement: which entity, which service, which jurisdiction and which date you checked. “Regulated everywhere” is too broad to do that job.



















