In short
Under MiCA an authorised exchange must segregate client crypto-assets under Article 75 and safeguard client funds under Article 70, proving both continuously. That means reconciling hot and cold wallets, venue positions, fiat safeguarding accounts and the internal ledger against client entitlement, without gaps at the fiat and crypto boundary.
Two segregation regimes running through one business
An exchange holds two categories of client property simultaneously. Crypto-assets held for clients fall under the custody and administration requirements of Article 75. Client funds in fiat fall under Article 70, which requires them to be safeguarded with a credit institution or central bank by the end of the following business day.
The two regimes have different mechanics, different counterparties and different failure modes, but they meet inside every trade. A client selling an asset moves value from one regime to the other, and the reconciliation must remain intact across that boundary.
Most exchange reconciliation designs handle each side well and the boundary poorly, because the boundary belongs to neither the digital asset operations team nor the treasury function.
That gap is where entitlement errors accumulate quietly, particularly around fees, spreads, failed settlements and reversals.
Article 70 and the fiat safeguarding obligation
Client funds must be placed with a credit institution or central bank by the end of the business day following receipt, held in accounts identifiable separately from any accounts used to hold the provider's own funds.
That is functionally equivalent to the safeguarding obligation on payment institutions, and it fails in the same ways: mixed receipts that are not decomposed correctly, late segregation, accounts opened without correct designation and balances that are not confirmed daily against internal records.
Safeheld reconciles fiat safeguarding balances against the client fiat liability continuously and treats late or missing bank data as an exception, so that a gap in confirmations does not present as a clean reconciliation.
Excess balances are surfaced as well as shortfalls, because holding proprietary funds in a client account undermines the separation the account exists to establish.
Reconciling across the trading engine, wallets and venues
Exchange reconciliation has to account for internal transfers that never touch a chain, positions held at external venues for liquidity, hot wallet operational floats, cold storage and, where the exchange runs market making inventory, proprietary positions that must never merge with client holdings.
The entitlement ledger produced by the trading engine is the primary record, but it is not self-proving. It must be reconciled against controlled balances and against the transaction population that produced it.
Where an exchange routes to external venues, positions held there are still client property in substance and must be included in the segregation proof rather than treated as a treasury matter.
Safeheld reconciles at this level continuously rather than nightly, which matters on a venue that operates without a settlement cut-off.
Managing break volume at exchange transaction rates
Transaction volumes on an exchange make manual break handling arithmetically impossible. Even a very low exception rate produces a daily population that exceeds any realistic analyst capacity.
Autonomous investigation is therefore not an efficiency measure but a feasibility requirement. Each break is investigated before a person sees it, supporting records are gathered, an explanation is formed and the reasoning is retained.
Only low confidence items reach a reviewer, and they arrive with the evidence already assembled rather than as an unmatched row.
The retained reasoning is what allows an exchange to demonstrate to a competent authority that its exception population was handled rather than absorbed.
Detection, escalation and incident response
Detected variances enter a six-level escalation ladder with defined triggers, recipients, channels and timings, with notification triggers NT-1 to NT-4 encoded so that the artefact required at each stage is prepared from reconciliation data when the trigger fires.
For an exchange, the speed of that path is directly connected to the size of the eventual problem. A segregation variance detected within minutes is an operational correction. The same variance detected during a withdrawal surge is an incident.
Escalation should distinguish between the crypto and fiat sides, because the remediation paths and the responsible functions differ, while still rolling into a single view of client property coverage.
Board reporting is generated from the same data, so the coverage position described upward is provably the position the control produced.
Evidence as a commercial asset in a low trust market
Exchange failures over the past several years have left institutional counterparties, banking partners and clients unwilling to accept assurance without evidence.
Sealing each reconciliation run under a SHA-256 Merkle root that can be verified independently allows an exchange to demonstrate coverage without exposing client level data, and without asking a counterparty to trust an internally produced report.
The same evidence serves the competent authority, the banking partner performing periodic review, and the institutional client conducting counterparty due diligence.
In a market where the principal constraint on institutional participation is confidence in custody, that is a commercial capability as much as a compliance one.
Frequently asked questions
How do MiCA Articles 68 and 70 differ for an exchange?
Article 68 governs custody and administration of clients' crypto-assets, requiring segregation and a register of positions. Article 70 governs client funds in fiat, requiring them to be placed with a credit institution or central bank by the end of the following business day in separately identifiable accounts. Both apply simultaneously and meet inside every trade.
Where do exchange reconciliation designs usually fail?
At the boundary between the crypto and fiat regimes. Each side is typically reconciled competently by the team that owns it, while the crossing point, where fees, spreads, reversals and failed settlements are applied, belongs to neither. Entitlement errors accumulate there because no single control proves the crossing.
Do positions held at external venues count as client property?
In substance, yes, where they represent client assets routed for liquidity. They must be included in the segregation proof rather than treated as a treasury position, because entitlement follows the client irrespective of which venue currently controls the balance.
Why is autonomous investigation a feasibility requirement for exchanges?
At exchange transaction rates, even a very low exception rate generates a daily break population beyond any realistic analyst capacity. Investigating each item automatically, with reasoning retained and only low confidence items routed to a reviewer, is the only way the exception population can be genuinely handled rather than absorbed.
How can an exchange prove coverage without exposing client data?
By sealing each reconciliation run under a SHA-256 Merkle root that a third party can verify independently. The counterparty confirms that a run occurred on a given date with a given outcome and that the record has not been altered, without receiving client level detail or access to the exchange's environment.