CRYPTO & DIGITAL ASSETS · CRYPTO TURNING POINTSINS-20221115-01

FTX: Compliance Theatre Is Not Governance

FTX became a case study in the difference between appearing controlled and being constrained by real segregation, permissions, conflicts management and independent oversight.

Libertax editorial visualization for “FTX: Compliance Theatre Is Not Governance”
A Libertax editorial composition about FTX: Compliance Theatre Is Not Governance.

KEY TAKEAWAYS

KEY POINT 01A control is real only if it constrains behaviour. Policies, risk engines and formal roles are not substitutes for enforceable permissions, segregation and reconciliation.
KEY POINT 02Related-party conflicts must be designed out or controlled. The relationship between FTX and Alameda showed why privileged access and weak separation can become an operating-system risk.
KEY POINT 03Regulation, banking and tax each remain separate questions. None of them can substitute for internal governance, and internal governance does not by itself determine the legal, banking or tax outcome.

Four days after FTX entered Chapter 11, the central lesson could not yet be stated as a final account of criminal conduct. The facts were still emerging. What could already be asked was more fundamental: what does governance mean if impressive policies, risk language and institutional appearances do not actually constrain the movement of money or conflicts of interest?

Later criminal proceedings supplied facts that were not knowable on 15 November 2022. They make the governance question sharper, not less important.

Key takeaways

  • A control is real only if it constrains behaviour. Policies, risk engines and formal roles are not substitutes for enforceable permissions, segregation and reconciliation.
  • Related-party conflicts must be designed out or controlled. The relationship between FTX and Alameda showed why privileged access and weak separation can become an operating-system risk.
  • Regulation, banking and tax each remain separate questions. None of them can substitute for internal governance, and internal governance does not by itself determine the legal, banking or tax outcome.

What was knowable on 15 November 2022

FTX had filed for Chapter 11 on 11 November. A major crypto exchange had failed abruptly, customers faced uncertainty over access to assets and the relationship between FTX and Alameda Research had become central to public scrutiny.

At that point, an archive article written honestly could not declare the later trial record as fact. It could identify the questions exposed by the collapse:

  • Were customer and company assets genuinely segregated?
  • Could an affiliated trading firm receive privileges that ordinary customers could not?
  • Who had authority to override risk controls?
  • Were related-party exposures visible to independent decision-makers?
  • Could financial records be reconciled quickly enough to show what the organisation actually owned and owed?

Those were governance questions before the later criminal case answered important parts of them.

What later proceedings established

In November 2023, a jury convicted Sam Bankman-Fried on seven fraud and conspiracy counts. In March 2024, he was sentenced to 25 years in prison.

The U.S. Department of Justice described a scheme in which billions of dollars of FTX customer funds were misappropriated. It stated that Bankman-Fried repeatedly represented that customer deposits were safe, kept separate and not used by FTX, while funds were in fact channelled to Alameda. The DOJ also described altered computer code that allowed Alameda to withdraw effectively unlimited amounts of cryptocurrency from the exchange.

Those are later-established facts and belong in the “what changed since” part of a retrospective, not in the knowledge available on 15 November 2022.

Separately, in December 2022 the SEC alleged that FTX investors had been told about sophisticated automated risk measures while Alameda received special treatment, including a virtually unlimited line of credit and exemption from certain risk-mitigation measures. The distinction matters: SEC complaint allegations should be described as allegations, not silently converted into judicial findings.

Governance is a system of constraints

Corporate governance is often described through nouns: board, policy, committee, compliance, audit, risk.

The stronger test uses verbs:

Who can approve? Who can block? Who can move assets? Who can see the exposure? Who reconciles? Who challenges a related party? Who receives an exception report? Who can act when the founder wants a different answer?

A governance system becomes meaningful when authority is divided, records are reliable and exceptions become visible to people who have both the independence and power to respond.

That is why formal sophistication can coexist with weak governance. A company can possess manuals, dashboards and risk terminology while the actual permission structure allows a small number of people to bypass them.

Compliance theatre begins where the evidence of control is stronger than the control itself.

Segregation is not merely an accounting preference

For a business that holds or controls customer assets, segregation is part of the architecture of trust.

The key issue is not only whether accounts are labelled separately. It is whether systems, legal rights, permissions and reconciliations prevent customer assets from being treated as the firm’s unrestricted financing source.

If an affiliate can access customer value through hidden privileges, the problem crosses several layers at once:

  • governance: related-party conflict and control failure;
  • operations: permissions, ledgers, reconciliation and treasury;
  • regulation: customer-asset and conduct obligations where applicable; and
  • bankability: financial institutions and counterparties must assess whether flows and controls make sense.

The same failure can therefore appear in different legal and operational languages without becoming the same question.

Affiliates are not inherently improper. Groups routinely use subsidiaries, service companies, treasury entities and related-party contracts.

The governance problem begins when the economic relationship cannot be tested independently.

A credible related-party framework needs to identify the relationship, price and document transactions, limit conflicts, define information access, set approval thresholds and produce records that an auditor, regulator or counterparty can follow.

Where one affiliate is both commercially important and structurally privileged, ordinary controls require more—not less—attention.

FTX and Alameda became an extreme example of why a group chart is not enough. Legal separateness on paper does not prove operational separateness in systems or cash flows.

The best objection: FTX was fraud, not a governance lesson

Fraud and governance are not the same thing.

A governance framework cannot guarantee that no determined person will ever commit fraud. Rules can be deceived, collusion can defeat segregation and records can be falsified.

But that does not make governance irrelevant. Governance determines how much unilateral power exists, how quickly unusual activity becomes visible, whether independent people can challenge it and how much evidence survives when something goes wrong.

The correct lesson is therefore not “better governance prevents every fraud”. It is:

A system that depends on the virtue of a dominant individual is not a robust control system.

Regulation cannot substitute for internal reality

Regulators can impose governance, custody, conduct, capital and reporting requirements. They can inspect, supervise and enforce.

But regulation does not operate the company minute by minute.

A licence or registration is not a continuous external guarantee that every internal control is functioning. The firm’s operating data, permissions, reconciliations, governance and people still determine what can actually happen between supervisory touchpoints.

This is why regulated-business due diligence should not stop at “who is the regulator?” It should ask how the business works.

Bankability and counterparty risk see the same facts differently

Banks and counterparties are not substitute regulators either. They assess their own exposure.

A bank may care about ownership, source of funds, expected transaction patterns, affiliates and governance because those facts affect its risk assessment. A trading counterparty may care about custody, settlement, solvency and withdrawal rights. An investor may focus on financial statements and conflicts.

Each observer can look at the same organisation through a different mandate.

Good governance makes those explanations consistent. Weak governance produces different stories for different audiences.

Tax and reporting were not the central FTX lesson

FTX’s collapse should not be forced into a tax-transparency article.

Tax, accounting and information-reporting obligations remain important, but they answer different questions. A tax return cannot demonstrate that customer assets are operationally segregated. An AML file cannot determine the tax character of a gain. A regulatory licence cannot prove the balance sheet is accurate.

The broader international lesson is coherence: entity structure, contracts, custody, accounting, banking, ownership and reporting should describe the same economic reality.

When those layers diverge, the problem is not merely technical. It becomes a governance signal.

What to test in a regulated business

The practical governance review is less glamorous than a licence announcement. It is also more useful:

  1. Map every entity and related party that can touch money or customer assets.
  2. Identify who can initiate, approve and override transfers.
  3. Separate customer, corporate and affiliate balances in law, systems and reconciliation.
  4. Test whether risk exceptions are logged and independently reviewed.
  5. Ask whether senior management receives information capable of contradicting the founder’s preferred narrative.
  6. Make related-party exposures visible in financial and operational reporting.
  7. Ensure incident, whistleblowing and escalation channels can bypass conflicted managers.

That is what turns compliance from presentation into infrastructure.

Sources

Disclaimer

This article is general historical, governance and regulatory commentary. It is not legal, investment, tax, banking or financial advice. It distinguishes later criminal findings from contemporaneous allegations and should not be read as making claims about persons or entities beyond the cited public record.