Verifying an On-Ramp and Off-Ramp Counterparty
counterparty verification

Verifying an On-Ramp and Off-Ramp Counterparty


Selecting a provider to move value between fiat and digital assets at size is three decisions taken together. A counterparty decision about who holds your money. A settlement decision about how and when value becomes final. A compliance decision about whose controls you are relying on.

Most selection processes address the first and treat the other two as annexes. The failures cluster in the annexes, and they arrive later, when switching is expensive.

Establish the regulatory position precisely

Ask for the licence by name, the issuing authority, and the specific permissions it carries. Then verify each against the public register rather than against a supplied certificate.

Precision matters because authorisation is not a single object. A firm permitted to operate an exchange holds different permissions from one permitted to provide custody or transfer services. A provider performing an activity outside its permissions is a problem regardless of how impressive the licence looks on a website.

Record the date of your check and the register you checked. Authorisations are varied, surrendered and withdrawn, and a check performed at onboarding and never repeated is a statement about a date rather than about today.

Ask separately whether the firm has been examined by its supervisor, when, and what the outcome was. In a market where a majority of regimes have produced no supervisory output, a firm which has been examined is in a materially different position from one which has only been licensed.

The fiat leg is the fragile one

Ask which banks hold the fiat leg, in which jurisdictions, and how many relationships the provider maintains.

This is the single most predictive question in the set. A provider with excellent controls, a clean licence and one banking relationship is a single point of failure, and the failure mode is sudden. Banking access for this sector is constrained by capital rules and internal appetite rather than by the provider's own quality, which means a good provider loses a bank for reasons unconnected to anything it did.

Ask what happens to client funds and to in-flight transactions if a banking relationship is withdrawn. A provider which has thought about it has an answer involving segregation, alternative rails and a defined communication process. A provider which has not treats the question as hypothetical, which is itself the answer.

Where the relationship justifies it, verify the banking arrangement with the bank rather than with the provider. Not every bank will confirm, and the provider's willingness to facilitate the request is informative regardless of the outcome.

Custody, segregation and the insolvency position

Ask how client assets are held, whether segregated from the provider's own assets, and what a client's position would be in an insolvency.

Segregation is a word with a wide range of meanings. Operationally segregated, held in a separate wallet or account, is weaker than legally segregated, held under a structure which places the assets outside the provider's estate. The two are described identically by most providers and produce entirely different outcomes.

Ask who the custodian is, whether the custodian is a separate legal entity, and whether it is regulated. Ask whether a third party attests to holdings, how often, and whether the attestation is available to you rather than only referenced.

Verify with the custodian or the auditor rather than with the provider. This is the verification step most often skipped and the one which most often changes an assessment.

Travel rule execution and interoperability

Ask how the travel rule obligation is met on transfers in both directions, which protocol is used, and what happens when a counterparty uses a different one.

Multiple competing protocols exist with documented gaps between them, and translation between protocols is where data fields are lost. A provider which names its protocol, its version, and its handling of mismatches has engaged with the problem. A provider which answers by asserting compliance has answered a different question.

Ask specifically what the provider does when required data is missing or unusable on an incoming transfer. Rejection, hold, request, or process and record. All four are defensible positions and they produce sharply different experiences for a client with time-sensitive flows.

Records and production

Ask what the provider records, how long it retains it, and how quickly it produces records on request.

This question predicts your own future more accurately than most of the others, because it determines what happens when your bank asks you about a transaction from eleven months ago. A provider which produces a complete record in two days makes it a routine enquiry. A provider which takes three weeks and produces a partial extract turns it into a problem you own.

Ask for an example of the standard record format rather than a description of it. The gap between the two is frequently large.

The sequence and the reciprocity

Run the steps in order, because each gates the next. Regulatory position. Banking arrangements. Custody and segregation. Travel rule execution. Records. Only then commercial terms.

Verification runs outward at every step. The register, the bank, the custodian, the auditor. A provider comfortable with independent verification says so immediately, and one who is not has told you something more useful than any answer.

The process is reciprocal, and a business which expects rigour should supply it. Providers filter enquiry heavily and a counterparty arriving with a clear description of its own regulatory position, its flows and its requirements is immediately distinguishable from the general volume. Preparation which was built for protection turns out to be the same preparation which wins access.

Two further points worth building into the process.

Re-run the assessment periodically rather than treating it as an onboarding gate. Authorisations change, banking relationships change, custody arrangements change and ownership changes. A provider assessed thoroughly two years ago and never revisited is being relied on against facts which have moved. A light annual refresh covering the register, the banking position and any ownership change costs an hour and catches most of what matters.

And assess the concentration across your providers rather than each provider alone. Three providers relying on the same underlying market access partner, the same custodian or the same correspondent bank present one risk wearing three names. The dependency map is the document worth building, and it is almost never requested because each individual assessment looks complete on its own terms.

Where a provider declines to describe its upstream dependencies, the refusal is a legitimate commercial position on their part and a material gap in your file. Record it as an unknown rather than as an acceptable answer, and factor it into how much of your flow you are willing to concentrate there.

The last observation is about tone. None of this needs to be adversarial, and processes run adversarially get worse answers. A provider treated as a partner in a shared problem, rather than as a suspect, gives more information and gives it faster.

The questions in this piece are ordinary questions any institutional counterparty would ask, and the good providers expect them. Asking them plainly, in a fixed order, and recording the answers is what a competent buyer does. It is also, in a market where most enquiries are casual, a reason for a good provider to take you seriously.

The practical measure of whether the process is working is how quickly a poor fit is identified. A sequence which takes six weeks to reach a negative conclusion is too slow. A sequence which reaches it in ten days, on the first two questions, is doing exactly what it was built for.