Jurisdictions
Services are configured against named obligations rather than marketed at regions. Where a framework sets no numeric threshold, your own calibration is bound into the proof.
| Region | Authorities | What is live |
|---|---|---|
| GCC | VARA · CBUAE · DFSA · ADGM FSRA · SAMA | AML and sanctions completeness, proof of solvency, VASP counterparty solvency, client money segregation |
| European Union | MiCA · CSRD · DIRECTIVE (EU) 2023/970 · FATF R.16 | Market abuse surveillance, stablecoin backing, travel rule, pay equity, CSRD emissions |
| Switzerland | FINMA | Proof of solvency, AML and sanctions completeness |
| Singapore | MAS | Proof of solvency, stablecoin backing, client money segregation, AML completeness |
On calibration
Which changes what a proof can honestly claim, and is worth being explicit about before a supervisor asks.
MiCA's market abuse RTS requires systems that "produce alerts indicating activities requiring further analysis". It does not list spoofing, wash trading or layering, and it names no thresholds. The same is true across most of the frameworks above.
So a proof attests that your calibration — agreed with your supervisor — was applied to the whole population. It does not certify that the calibration is the right one. That is a supervisory judgement, and a vendor claiming otherwise is overreaching in a way that would not survive an examination.
What the proof does settle is the question nobody can currently answer: whether the controls actually ran over everything, or whether some records routed around them.
One day. One proof. You decide what comes next.