> For the complete documentation index, see [llms.txt](https://vnx.gitbook.io/vnx-global/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://vnx.gitbook.io/vnx-global/institutional/regulatory/regulatory-framework.md).

# Regulatory Framework

*Bermuda DABA Class M licence: scope, supervisory authority, and authorised activities of VNX Global Ltd.*

## Scope

VNX Global Ltd is a Bermuda exempted company limited by shares which holds a Class M digital assets business license issued by the Bermuda Monetary Authority (BMA). The Class M licence is the broadest authorisation under the Digital Asset Business Act 2018 (DABA) and covers the full perimeter of VNX's institutional product set: digital-asset exchange, payment services for digital assets, and digital-asset service vendor activities. Authorised activities apply to retail, high-net-worth, and institutional segments.

## Principles

* **Single supervisory authority** — the BMA exercises ongoing oversight under DABA, including conduct, capital, cybersecurity, and customer-asset rules.
* **100% reserve backing** — every VNX stablecoin in circulation is matched by reserve assets in segregated, ring-fenced structures.
* **Conservative risk posture** — VNX operates well inside regulatory capital tolerances rather than at the limit, with risk appetite approved annually by the Board.
* **Currency matching** — reserves are held in the same currency as outstanding stablecoin liabilities unless specifically approved by the BMA.
* **Three lines of defence** — operational ownership, an independent risk/compliance function, and an independent internal audit.

## Governance

Regulatory governance framework is structured around clearly allocated Board, Committee and control-function responsibilities. The Board retains ultimate responsibility for corporate governance, the risk management and internal controls framework, approval of the Business Risk Assessment and Risk Appetite Statement, and oversight of delegated or outsourced risk-management activities.

The Audit, Risk and Compliance Committee supports the Board by overseeing legal and regulatory compliance, risk management policies and procedures, the internal audit function, the risk profile, risk appetite and aggregate risk exposures.

The Senior Representative acts as the supervisory interface with the Bermuda Monetary Authority and performs the early-warning notification role required under DABA.

The Chief Compliance Officer is responsible for implementing effective legal and regulatory compliance procedures, advising the CEO on compliance matters, monitoring AML training, and coordinating the risk-assessment process and updates to the Business Risk Assessment and Risk Appetite Statement.

Risk management functions are performed by the Risk Management Officer appointed by the Board, with risk owners assigned where appropriate to manage specific risks in accordance with the Risk Management Officer’s instructions.

## Reporting and review

The Enterprise Risk Management Policy is reviewed and approved annually by the Board in connection with the annual risk-exposure review. Material risk events and BMA-notifiable incidents follow defined escalation paths to the Senior Representative within 24 hours, with full reports within 14 days. External audit performs statutory audits and the Bermuda Cybersecurity Rules compliance assessment annually.

## Related policies and pages

* [AML CTF Travel Rule](/vnx-global/institutional/regulatory/aml-ctf-travel-rule.md)
* [Reserve Management](/vnx-global/institutional/reserve/reserve-management.md)
* [Investment Policy](/vnx-global/institutional/reserve/investment-policy.md)
* [VNX Global Ltd](/vnx-global/vnx-global-ltd.md)
