zkFMI
日本語

Regulation

A map of the accounts and statutes a live deployment touches, drawn so that the engineering does not walk into a structural problem late. This is not legal advice. Whether any of it is lawful depends on who operates it and where, and that question belongs to counsel. What the map can do is narrow the search.

source: defmi/REGULATION.md, qomm/REGULATION.md · sources listed there

What the architecture needs from a legal system

  • N1: a venue category that permits a system to evaluate orders it does not publish. QOMM never discloses a quote pre-trade, by construction. It needs a regime where that is permitted as a matter of rule, not tolerated as a matter of practice.
  • N2: a legal record that the settlement ledger can be. DeFMI either mirrors an authoritative register kept elsewhere, or it is the register. The second requires a statute saying that an entry in a ledger constitutes title. Whether such a statute exists is the single largest difference between jurisdictions.
  • N3: a cash leg with real finality that a distributed ledger can reach. Without it, DvP is atomic on one side only.

Two further costs are independent of all three: the seven node operators are seven third parties whose availability the venue still owns, and no supervisor anywhere accepts "we are unable to show you".

Five jurisdictions

N1: non-disclosing venueN2: ledger as titleN3: cash legalready exists
JapanPTS authorisation, art. 30: heavyNo on the book-entry rail; yes on the FIEA art. 2(3) rail, security tokens onlyBOJ-NET; PSA electronic payment instrumentsSTART (ODX), ST PTS since Dec 2023
SwitzerlandDLT trading facility licence, purpose-built; one licence covers trading, settlement and custodyYes: CO arts. 973d–973i, in force 1 Feb 2021. The register entry is the right.SDX plus SNB wholesale CBDCBX Digital, first DLT trading facility licence, Mar 2025; SDX since Sep 2021; six digital bonds over CHF 750m in wCBDC
EUMTF/OTF, plus DLT MTF and DLT TSS under Reg. 2022/858member state by member state; Germany's eWpG register constitutes the securityT2; MiCA e-money tokens; ECB DLT settlement workthree authorised DLT infrastructures at 31 May 2025
UKMTF/OTF, plus the Digital Securities Sandboxwithin the sandbox perimeter, yesstrongest available: the BoE omnibus account puts central bank money under a DLT payment systemDSS open since Sep 2024; Fnality live in sterling since Dec 2023 with finality designation
SingaporeRecognised Market Operator, institutional tier is exactly wholesaleweakest: no statute making the ledger entry the rightMAS stablecoin framework; Project OrchidProject Guardian: real institutions, real trades, the regulator in the room

Japan: DeFMI cannot be the book-entry register

Under the Book-Entry Transfer Act the right is the entry in the register kept by the transfer institution and account management institutions, not a commitment ledger kept alongside it. Two options remain. (a) Run as a mirror, a control plane: DeFMI reflects the register, checks rules, state and receipts, and is never authoritative; the price is double bookkeeping in which the register is always right. That is the default, and the reconciliation proof is its cost. (b) Issue on the electronically recorded rights rail under FIEA art. 2(3), where DeFMI's record can be the record, for security tokens only and never for listed equities.

What DeFMI is not: the existing chain decomposes into execution, confirmation, clearing (JSCC: novation, netting, margin, guarantee), securities delivery (JASDEC) and cash delivery (BOJ-NET). DeFMI touches delivery. Exchanging two parties' tokens simultaneously does not reproduce a CCP, and DeCCP is the component that supplies novation and a waterfall rather than a claim the code does not support.

Japan: self-custody and client-asset key management

Sources checked 2026-09-12. Holding the spending key for one's own assets does not by itself constitute a business managing another person's assets. Key storage is not universally unrestricted: the legal right represented by a note, the operator's regulated role, and actual spending and recovery powers must be assessed separately.

  • Cryptoasset management: the FSA considers whether a business, alone or together with related businesses, can transfer a user's assets without the user's involvement. Calling a system MPC or splitting keys does not automatically remove it from scope. The guidance also gives examples where the businesses' combined information cannot authorize a transfer, or where an encrypted key cannot be decrypted by the business.
  • Client security tokens: financial instruments business operators accepting custody of electronically recorded transferable securities rights face segregation and offline key management or equivalent technical safeguards, among other requirements. This is a different setting from an ordinary holder's self-custody.
  • Design implications: distinguish decryption-only keys, spending keys and recovery or reissuance powers. Determine whether the operator only verifies proofs or can spend without the holder. The cryptoasset management test cannot simply be carried over to securities, electronic payment instruments or other claims.

This maps regulatory questions; it is not a determination that zkFMI is lawful or exempt. An operational service needs specialist and regulatory review of the asset classification, users, and both normal and recovery authority.

FSA cryptoasset management guidance · FSA supervisory guidelines IV-3-7-6

The finding that changes what to build

The 2024 MiFIR review narrowed pre-trade publication for bonds, structured products and emission allowances to central limit order books and periodic auctions, and removed the RFQ waiver as no longer needed. In EU non-equity markets an RFQ system is not required to publish quotes before the trade: the confidentiality QOMM provides is the baseline the legislator chose, not a tolerated edge. Equities are the reverse. So QOMM's natural home in the EU and UK is bonds and derivatives, which is also where RFQ is how the market already trades, and that cuts against Japan, where the friction lives on the equity book-entry rail.

A second consequence: the RTS 27/28 execution-quality reports were abolished because nobody could verify them, while the article 27 best-execution duty survives. QOMM produces the verifiable version of exactly the thing that was abolished for being unverifiable. That is the strongest regulatory argument the system has, and it does not depend on any DLT regime.

Where the nodes sit, and under whose law

Two tiers face two adversaries: a regional committee under one supervisor faces an adversary that must go through lawful access, and a spread committee faces one that must corrupt operators in several legal orders. Routing is by instrument, because the register decides the law. The placement measurements price the spread committee at 26 s a quote and show it is affordable exactly in the market that most needs it.

On a pure crypto rail the argument inverts. N2 is free: the chain is the record because no competing register exists, so DvP on one ledger is available at all. But the chain gives the record without the enforcement: a Swiss ledger entry is a right a court enforces, a chain entry is a record nothing off-chain must honour, and finality of the transfer is not finality of the claim, which a stablecoin transfer illustrates exactly. With no authorising supervisor there is no lawful-access channel substituting for geographic spread, so the spread committee is the answer rather than a luxury, and what decides the committee becomes an operator rather than a register.

What may and may not be claimed

May

  • A price can be produced without the order reaching the makers or any single node. Measured.
  • That the returned price was the minimum under the registered rules can be proved in a form anyone can check.
  • Node inaction, double signing and reuse of stale state are detectable and attributable.
  • Settlement checks conservation, non-negativity and double-spend without reading amounts, prices or instrument names.
  • Selective disclosure is built at three grains: one committed field, one scope of a wallet to a named auditor, and a quorum-assembled statement about a value none of them holds.

May not

  • "This is compliant." Lawfulness depends on the operator and the jurisdiction.
  • "Confidential computation makes it safe for retail." Investor protection is a different layer.
  • "DeFMI replaces the book-entry register." Under the Act it does not.
  • "A CCP is no longer needed." Two-party simultaneous exchange is not novation.
  • "It is auditable, therefore controls exist." Evidence is material for control, not control.