1. PURPOSE
These Rules establish requirements for the protection, control, segregation, reconciliation and recordkeeping of Client Assets connected with activities conducted through the International Digital Securities Exchange (IDSX). They aim to protect Client Assets from misuse, loss, unauthorised transfer and improper commingling; ensure verifiable ownership and entitlement records; establish controls for Digital Securities and blockchain records; ensure complete and reliable Books and Records; support reconciliation, audit, supervision and regulatory oversight; and reduce operational, custody, settlement and insolvency risks to investors. These Rules form part of the IDSX Market Rules and must be read with all other applicable IDSX rules, policies and laws.
2. SCOPE
These Rules apply, where relevant, to Brokers; Custodians; Settlement Providers; Market Participants holding or controlling Client Assets or controlling wallets or private keys for clients; Issuers maintaining records relevant to Digital Securities ownership; third-party providers performing custody, recordkeeping or settlement for a Market Participant; and any other person designated by IDSX. A Market Participant's obligations depend on the functions it actually performs.
3. DEFINITIONS
For these Rules, “Client” means a person for whom a Market Participant provides services in connection with IDSX securities. “Client Assets” means money, securities, Digital Securities, settlement assets or other property held, controlled, administered or safeguarded by a Market Participant for or on behalf of a Client. “Client Money” means money held or controlled for or on behalf of a Client. “Client Securities” means securities held, controlled or administered for or on behalf of a Client. “Digital Securities” means securities represented, recorded, transferred or administered using distributed ledger or blockchain technology under IDSX Rules. “Custodian” means a person providing custody or safekeeping services for Client Assets. “Settlement Provider” means a person or infrastructure provider performing settlement functions for transactions executed through IDSX. “Wallet” means a blockchain address or technological arrangement used to hold, control or interact with Digital Securities or approved digital settlement assets. “Books and Records” includes electronic, transaction, blockchain and wallet records, communications, reconciliations and other information required under these Rules.
4. GENERAL PRINCIPLE
A Market Participant responsible for Client Assets must act with due skill, care and diligence and maintain arrangements reasonably designed to protect those assets. Client Assets must not be used for the Market Participant's own purposes; pledged, lent, transferred or encumbered without proper authority; improperly commingled with proprietary assets; transferred to an unauthorised person; used to satisfy the Market Participant's obligations; or dealt with contrary to applicable law, Client instructions or IDSX Rules.
5. IDSX AND CLIENT ASSETS
Unless expressly stated otherwise, IDSX operates market infrastructure and does not itself act as custodian of Client Assets merely because securities are admitted to trading or transactions are executed through IDSX. Client Assets should ordinarily be held or controlled by appropriately authorised Brokers, Custodians, Settlement Providers or other approved arrangements. IDSX's trading, matching, surveillance, wallet eligibility or blockchain infrastructure does not by itself mean IDSX holds beneficial ownership of Client Assets. If IDSX performs a function constituting custody, safeguarding or control under applicable law, it must comply with the requirements applying to that function.
6. RESPONSIBILITY OF MARKET PARTICIPANTS
Each Market Participant must determine whether its activities involve holding, controlling, safeguarding or administering Client Assets. Blockchain technology does not remove or avoid custody, client money or client property obligations. Responsibility must be assessed by reference to actual legal and operational arrangements, including who controls the asset, account or wallet; who controls private keys; who can initiate or prevent transfers; who maintains the legally recognised ownership record; who is responsible for settlement; and the Client's rights on insolvency.
7. SEGREGATION OF CLIENT ASSETS
Client Assets must be appropriately segregated from a Market Participant's proprietary assets. Segregation may use separate bank or securities accounts, segregated custody accounts, designated blockchain wallets, omnibus client accounts supported by accurate sub-ledgers, or another arrangement permitted by law and approved by IDSX where required. Records must clearly distinguish Client Assets from proprietary assets at all times.
8. CLIENT MONEY
Where a Market Participant receives or holds Client Money, it must maintain arrangements appropriate to protect it. Client Money must be properly identified and promptly recorded, held in an appropriate account, segregated where required, subject to withdrawal controls, regularly reconciled and used only for authorised purposes. It must not finance the Market Participant's operations or another Client's obligations.
9. CLIENT SECURITIES
Client Securities must be held or recorded so the relevant Client entitlement can be identified. Records must establish the Client's identity, the security and quantity held, acquisition and disposal activity, applicable restrictions, corporate actions, transfers and the Client's current entitlement.
10. DIGITAL SECURITIES
Where Client Assets include Digital Securities, a Market Participant must maintain controls appropriate to blockchain-based assets, addressing as applicable wallet ownership and eligibility, private-key control, signing authority, transfer restrictions, whitelisting, blockchain transaction records, smart-contract interaction, recovery, cybersecurity and reconciliation between blockchain and internal records.
11. WALLET IDENTIFICATION
A Market Participant must maintain records identifying wallets used with Client Digital Securities. Records should include, where applicable, blockchain network, wallet address, relevant Client, wallet type, Custodian or controller, approval date, eligibility status, applicable restrictions and date of suspension or removal from the approved wallet list.
12. WHITELISTED WALLETS
Digital Securities subject to IDSX transfer controls may be transferred only to wallets meeting applicable eligibility requirements. A Market Participant must not knowingly facilitate a transfer to an ineligible wallet. Wallet eligibility must be maintained under the IDSX Wallet & On-Chain Transfer Rules.
13. OMNIBUS ARRANGEMENTS
A Market Participant may use an omnibus account or wallet where permitted by law. It must maintain internal records identifying each Client's individual entitlement. The aggregate Client entitlement in its books must be reconcilable against assets held in the omnibus account or wallet.
14. INDIVIDUALLY SEGREGATED ARRANGEMENTS
Where Client Assets are maintained in individually segregated accounts or wallets, the Market Participant must keep records linking each account or wallet to the Client. Individual segregation does not remove reconciliation, security-control or accurate-recordkeeping requirements.
15. PROPRIETARY ASSETS
A Market Participant must clearly separate Client Assets, its own proprietary assets and assets held for another legal entity. Proprietary trading must not use Client accounts or wallets except under a structure expressly permitted by applicable law and approved by IDSX.
16. USE OF CLIENT ASSETS
Client Assets may be used, transferred, pledged, lent or otherwise dealt with only under valid Client instructions; for settlement of authorised transactions; for properly authorised fees or charges; where permitted by a Client agreement and law; or where required by law, court order or competent regulator. Any permitted use must be accurately recorded.
17. NO UNAUTHORISED REHYPOTHECATION
Client Securities or Digital Securities must not be pledged, rehypothecated, lent or used for another person's obligations without appropriate authority and where lawful. Securities lending or similar arrangements must be separately documented and comply with IDSX Rules and law.
18. CLIENT INSTRUCTIONS
A Market Participant must maintain reasonable procedures to receive, authenticate and record Client instructions concerning Client Assets. Records should identify the Client; date and time; instruction; asset and quantity; destination account or wallet, if applicable; authentication method; and execution status.
19. AUTHORISATION CONTROLS
Client Asset transfers must have appropriate authorisation controls proportionate to the nature and value of assets. These may include dual approval, role-based access, transaction limits, multi-signature arrangements, hardware security modules, withdrawal allowlists, independent verification and automated compliance controls.
20. CLIENT ASSET TRANSFERS
A Market Participant must maintain complete Client Asset transfer records. For Digital Securities, records should include, where available, originating and destination wallets, blockchain network, transaction identifier, block or confirmation information, timestamp, quantity, security identifier and transfer status.
21. SETTLEMENT
Market Participants responsible for settlement must keep records sufficient to establish the status and completion of each settlement obligation. Records should distinguish trade execution, settlement instruction, pending, completed, failed, reversed or corrected, and cancelled settlement.
22. DELIVERY VERSUS PAYMENT AND OTHER SETTLEMENT MODELS
Where Delivery versus Payment (DvP), atomic settlement, securities-for-securities settlement or another approved model is used, the responsible Market Participant must keep records demonstrating movement of each settlement leg. Blockchain records may form part of evidence for settlement involving Digital Securities or digital settlement assets, but do not remove the obligation to keep appropriate internal Books and Records.
23. FAILED SETTLEMENT
A Market Participant must maintain procedures to identify and manage failed or delayed settlement. Records must identify the affected transaction, known cause, affected Client, assets involved, corrective action, resolution status and material Client or market impact.
24. CORPORATE ACTIONS
A Market Participant responsible for Client Securities must keep records of corporate actions, including dividends, distributions, voting rights, rights issues, share splits, consolidations, mergers, acquisitions, redemptions and other corporate events. Client entitlements must be accurately calculated and recorded.
25. BENEFICIAL OWNERSHIP RECORDS
Where securities are registered to a nominee, Custodian, Broker or other intermediary, sufficient records must identify the relevant beneficial or underlying Client entitlement where law or IDSX Rules require. Nominee or omnibus structures must not prevent IDSX or a competent authority from obtaining ownership information where legally authorised.
26. LEGAL OWNERSHIP AND BLOCKCHAIN RECORDS
For Digital Securities, the relationship between blockchain records, the securities register, legal ownership, beneficial ownership and internal Client records must be clearly documented. Where a blockchain record is not the legally recognised securities register, it must not be represented as such. Any discrepancy between legally recognised ownership records and blockchain records must be promptly investigated and resolved.
27. BOOKS AND RECORDS
Market Participants must maintain complete, accurate and current Books and Records of IDSX activities, sufficient to reconstruct relevant activity and determine Client identity and assets, transactions, orders, transfers, settlement, custody arrangements, wallet activity, corporate actions, fees and charges, reconciliations and material operational events.
28. RECORD INTEGRITY
Books and Records must be protected against unauthorised alteration, deletion, corruption, loss, access and destruction. Material amendments should be traceable where reasonably practicable, and systems should maintain appropriate audit trails.
29. ELECTRONIC RECORDS
Electronic records are permitted if they remain accurate, accessible, readable, reproducible and appropriately secured; can be provided to IDSX or a competent authority where required; and are retained for the required period.
30. BLOCKCHAIN RECORDS
Blockchain records may support evidence of transactions, ownership movements or settlement, but do not eliminate the obligation to maintain sufficient internal records. Where required, a Market Participant must associate blockchain transactions with the relevant Client, transaction or business event.
31. RECONCILIATION
A Market Participant holding or controlling Client Assets must reconcile at a frequency appropriate to the nature, scale and risk of its activities. Reconciliation should compare, where relevant, internal Client ledgers, bank and custody accounts, securities registers, blockchain wallets, settlement records and third-party statements.
32. RECONCILIATION FREQUENCY
Client Asset reconciliations must be regular and sufficiently frequent to identify discrepancies promptly. IDSX may specify minimum frequencies for asset types, activities or Market Participants. Higher-risk activities may require daily or more frequent reconciliation.
33. RECONCILIATION DIFFERENCES
Material differences must be promptly investigated. The Market Participant must identify the cause and affected Clients, prevent further discrepancies where necessary, correct records, restore any required Client Asset shortfall, document investigation and resolution, and notify IDSX or a competent authority where required.
34. CLIENT ASSET SHORTFALL
A Market Participant must maintain procedures to identify and respond to a Client Asset shortfall. On identifying a shortfall, it must take appropriate steps to protect Clients and resolve it promptly. A material shortfall must be escalated internally and reported to IDSX and relevant authorities where required.
35. WALLET RECONCILIATION
Where Digital Securities are held through blockchain wallets, the Market Participant must reconcile relevant on-chain balances against internal Client entitlement records. The process should identify expected and on-chain balances, pending, unidentified, failed or unauthorised transactions and other discrepancies.
36. PRIVATE KEY MANAGEMENT
Where a Market Participant controls private keys for Client Digital Securities, it must maintain appropriate controls addressing, where applicable, key generation and storage, access, signing authority, multi-signature or equivalent controls, rotation, backup, recovery, compromise procedures and destruction of obsolete keys. No individual may have unrestricted ability to access, transfer or otherwise control Client Digital Securities without appropriate authorisation, segregation of duties and security controls. Keys must be protected against unauthorised access, loss, theft, disclosure, destruction and compromise. On suspected or known compromise, the Market Participant must promptly protect affected assets, investigate, preserve records and notify IDSX, affected Clients and competent regulators where required. Arrangements must be documented, periodically reviewed and tested in light of the nature, scale and complexity of activities.
37. CYBERSECURITY AND ACCESS CONTROLS
A Market Participant responsible for Client Assets or related records must maintain appropriate cybersecurity and access controls, including where applicable identity and access management, multi-factor authentication, privileged access controls, network security, encryption, malware protection, vulnerability management, security monitoring, incident detection, logging and periodic security testing. Access must be limited to authorised persons with a legitimate business need.
38. BUSINESS CONTINUITY AND RECOVERY
A Market Participant must maintain appropriate business continuity and disaster recovery for systems supporting Client Assets. Arrangements should address system or facility outages, cyber incidents, unavailable key personnel, data corruption, loss of wallet infrastructure, blockchain disruption, third-party service failure and other material operational events. Recovery arrangements must be periodically reviewed and tested.
39. BACKUP OF RECORDS
Material Client Asset records must be appropriately backed up and protected against unauthorised access, corruption and loss. A Market Participant must maintain arrangements reasonably designed to recover material records after operational or technology failure.
40. CLIENT ASSET STATEMENTS
Where required by law, Client agreement or IDSX Rules, a Market Participant must provide Clients statements sufficient to understand their holdings and material transactions. Statements may include securities and Digital Securities held, cash or settlement asset balances, transactions, transfers, fees, corporate actions and other material account activity.
41. CLIENT ACCESS TO INFORMATION
A Market Participant should provide Clients reasonable access to information concerning their Client Assets. Public blockchain information must not be relied on solely as a substitute for maintaining or providing accurate Client records. Information should, where applicable, enable the Client to identify securities or other assets held, their quantity or balance, relevant transactions and transfers, pending settlement, restrictions, corporate actions and material fees or charges. A material discrepancy identified by a Client must be investigated within a reasonable period.
42. RECORD RETENTION
A Market Participant must retain required Books and Records for the period prescribed by law and any additional period specified by IDSX. If no period is prescribed, records should be retained for a period appropriate to the activity and sufficient for regulatory, audit, dispute-resolution and enforcement needs. Records must not be destroyed while relevant to an ongoing or reasonably anticipated investigation or litigation, required by IDSX or a competent authority, related to an unresolved Client complaint or dispute, or otherwise required by law.
43. AUDIT TRAIL
A Market Participant must maintain an audit trail sufficient to reconstruct material Client Asset activity. It should identify, where applicable, the person or system initiating and approving an action; date and time; affected Client and asset; previous and resulting balances; transaction or transfer identifier; wallet or account; amendments or corrections; and other information reasonably necessary to reconstruct the event. Audit records must be protected against unauthorised alteration or deletion.
44. IDSX ACCESS TO RECORDS
A Market Participant must provide IDSX access to Books and Records reasonably required for market supervision, compliance, investigation and enforcement, within the period IDSX specifies and subject to law. IDSX may require information on Client Asset holdings, reconciliations, transactions, settlement, wallet activity, custody, shortfalls, operational incidents, internal controls, third-party providers and other IDSX compliance matters. Disclosure is not required where prohibited by law. Where a legal restriction prevents disclosure, the Market Participant must, where legally permitted, notify IDSX and cooperate to identify a lawful means of providing the information.
45. REGULATORY ACCESS
A Market Participant must maintain records to support lawful requests from competent regulatory, supervisory, judicial or law-enforcement authorities. Where legally required, records must be producible in a reasonably accessible and intelligible form. Blockchain, distributed ledger, cloud infrastructure or third-party providers do not remove this obligation.
46. OUTSOURCING AND THIRD-PARTY SERVICE PROVIDERS
A Market Participant may, where law permits, use third parties for custody, technology, wallet, recordkeeping, settlement or other Client Asset functions. Outsourcing does not remove its responsibility to comply with IDSX Rules. Before appointing a material provider, it should conduct due diligence on competence and experience, financial condition and regulatory status where relevant, cybersecurity, operational resilience, custody, data protection, record accessibility, business continuity, subcontracting, termination and ability to meet legal and IDSX requirements. Material arrangements must be documented and overseen on an ongoing basis.
47. THIRD-PARTY CUSTODIANS
Where a third-party Custodian holds Client Assets, the responsible Market Participant must keep sufficient records of the Custodian, account or wallet, assets, Client entitlements, legal ownership structure, material custody terms and jurisdiction. It must conduct reasonable due diligence before appointment and periodically assess whether the arrangement remains appropriate. Use of a Custodian does not eliminate applicable obligations to maintain accurate Client entitlement records.
48. MATERIAL INCIDENTS AND BREACH NOTIFICATION
A Market Participant must promptly assess material incidents affecting Client Assets or records, including loss, unauthorised transfer, material shortfall, private-key compromise, cybersecurity breach, material reconciliation failure, loss or corruption of material records, custody or settlement failure, insolvency or material distress of a relevant Custodian or Settlement Provider, or another event creating material risk. Where IDSX Rules require, it must notify IDSX promptly after becoming aware. To the extent reasonably known, notification should state the incident and when it occurred or was identified; affected assets and Clients; known or estimated financial impact; immediate protective and remediation measures; and whether a competent regulator was notified. An initial notice may be supplemented as information emerges. IDSX notification does not replace legal duties to notify Clients, regulators, law enforcement or others.
49. COMPLIANCE AND ENFORCEMENT
Failure to comply may breach IDSX Market Rules. IDSX may act under its Disciplinary & Enforcement Measures, including requiring corrective action, additional reconciliation, remediation of controls, independent review or audit, additional reporting, activity restrictions, conditions on continued participation, suspension of access to IDSX functions, suspension or termination of participation where permitted, disciplinary referral or referral of suspected legal breaches to a regulator. IDSX may consider seriousness, Client risk, duration, recurrence, cooperation, remediation and other relevant circumstances.
50. INTERACTION WITH APPLICABLE LAW
These Rules establish IDSX market requirements and do not replace, limit or modify legal obligations. Market Participants remain responsible for identifying and complying with all requirements applicable to them, including custody and safeguarding of Client Assets, Client Money, securities ownership and registration, financial-service licensing or registration, financial product markets, AML/CFT, sanctions and financial crime controls, recordkeeping, privacy and data protection, cybersecurity, insolvency and Client Asset protection, taxation, cross-border activities and other financial-market, securities, corporate or commercial law. Mandatory applicable law prevails to the extent of conflict. Compliance with these Rules alone does not constitute compliance with law. These Rules do not permit regulated custody, Client Money, settlement or other services without any required licence, registration, authorisation or approval. IDSX may require information, legal analysis, regulatory confirmation, independent assurance or other evidence reasonably necessary to demonstrate compliance with IDSX requirements.