As Institutional Crypto Scales, Legacy Compliance Programs Fall Behind
By Steve Brown, Head of Business Development, StarCompliance

President Trump’s July 2025 signing of the GENIUS Act, the first federal framework for stablecoins, marked a turning point for institutional digital asset adoption. It also exposed a gap most firms have not yet closed: The compliance infrastructure built for traditional markets was not designed for what tokenization is bringing to trading desks.
Institutional investors expect their digital asset exposure to double within three years, and BCG projects tokenized assets could reach $16 trillion by 2030. That volume is enough to make gaps in transaction surveillance a market-wide problem rather than a firm-by-firm one.
From Experimentation to Regulatory Scrutiny
That surveillance gap is not a technicality. Transaction surveillance, insider trading controls and personal account dealing rules must now extend to blockchain-based activity the same way they cover trades on traditional venues. FINRA has reinforced that expectation through expanded supervisory and enforcement focus on member firms’ crypto asset activities. Compliance teams can no longer treat digital assets as an external curiosity. They need to build tokenized activity into their core market abuse and conduct surveillance programs.
This is not a new problem. Early institutional engagement with crypto was largely exploratory, confined to pilot projects with limited integration into core oversight systems. Tokenization changes that calculus. As blockchain-native representations of equities, funds and real estate increasingly mirror the economic and legal characteristics of traditional securities, the SEC has made clear that tokenization does not alter the underlying nature of the asset. On-chain securities remain subject to the same federal disclosure, record-keeping and market conduct rules as their off-chain equivalents, whether or not the surveillance infrastructure has caught up.
Transaction Blind Spots in a Hybrid Market
The most pressing challenge for compliance officers is closing the visibility gap created by hybrid trading environments. Personal account dealing and trade monitoring systems were built for markets where trades flow through regulated brokers and exchanges. Tokenized markets do not always work that way, and legacy tools are proving ill-equipped to track blockchain-based activity, leaving firms exposed to compliance gaps, as noted in PwC’s 2025 analysis of evolving crypto oversight. These systems struggle to detect and interpret activity occurring on decentralized exchanges, cross‑chain bridges or direct wallet‑to‑wallet transfers.
Decentralized liquidity compounds the problem. Automated market makers and peer-to-peer trading mechanisms fragment the market, which makes it harder for traditional surveillance tools to reconstruct a complete view of trading activity across venues. As a growing share of institutional trading shifts toward tokenized and on-chain assets, compliance teams will need to integrate on-chain analytics and cross-venue reconciliation directly into their surveillance architecture rather than treating it as a separate workstream.
Where the Regulatory Line Is Moving
That surveillance buildout is not optional for long. The GENIUS Act is the clearest signal yet that U.S. policymakers intend to bring digital assets fully inside the regulatory perimeter rather than leave them in a gray zone. The Digital Asset Market Clarity Act would extend that clarity further by defining which digital assets fall under SEC versus CFTC jurisdiction. The bill has cleared committee and sits on the Senate’s calendar, though its passage this year is in doubt as the Senate’s August recess approaches. Together with the SEC’s continued position that existing securities law applies on-chain, the direction for U.S. firms is consistent: tokenize an asset, and it gets treated like the regulated instrument it represents.
Firms with cross-border operations have an added layer to manage. The EU’s Markets in Crypto-Assets regulation and the U.K. Financial Conduct Authority’s tokenized fund sandbox proposal point toward similar principles taking hold overseas, which matters for any U.S. institution trading tokenized assets with European counterparties or listings. For most domestic trading desks, though, the U.S. framework taking shape under the SEC, FINRA and the GENIUS Act is the one that will drive near-term compliance priorities.
Building a Compliance Program That Can Actually See
Those regulatory priorities only matter if compliance programs can actually act on them. The firms that navigate this well will run programs that go beyond policy documents to see what is happening across centralized exchanges, decentralized platforms and direct wallet interactions, and act on it in real time.
For trading and compliance leaders evaluating where to start, the priorities are becoming clear:
- Extend restricted lists and preclearance systems to cover smart contract addresses and token identifiers, not just tickers and CUSIPs.
- Integrate on-chain data feeds directly into existing surveillance engines so patterns indicative of insider trading or front-running do not fall through the cracks between venues.
- Build in configurability across regulatory frameworks, including U.S. securities law and, where relevant, MiCA and the U.K.’s Market Abuse Regulation, so policy updates do not require manual rebuilds.
- Treat on-chain analytics as a core surveillance input rather than a bolt-on, particularly as trading volume continues to migrate toward decentralized venues.
None of this is simple, and the compliance rebuild will take years, not quarters. But as tokenized trading moves from pilot programs into the core of institutional markets, compliance programs that cannot see the full picture of where that activity is occurring will not remain a viable position for long.
Steve Brown is Head of Business Development at StarCompliance, responsible for helping drive growth with a focus on go-to-market planning, data and vendor partnerships, channel sales, new markets and mergers and acquisitions. Steve joined Star in April 2021, and brings 25 years of experience advising financial firms on regulatory compliance.