Crypto Exchange Coinbase Germany Ordered by Regulator to Tackle 'Organizational Deficiencies'

The Federal Financial Supervisory Authority (BaFin) said the company needs to address a range of issues including ensuring adequate risk management, staffing and IT systems.

AccessTimeIconNov 8, 2022 at 12:07 p.m. UTC
Updated Nov 9, 2022 at 3:52 p.m. UTC

Germany's financial watchdog ordered cryptocurrency exchange Coinbase's local unit to ensure it has effective risk management and internal controls in place after uncovering "organizational deficiencies" during an audit of the firm's financial statements, according to a statement published Tuesday.

The Federal Financial Supervisory Authority, known as BaFin, said Coinbase Germany was in violation of standards set by the German Banking Act. The announcement referenced Section 25a (1) of the Act, which lays out requirements for firms to maintain risk-bearing capacity, adequate staffing, emergency management mechanisms such as IT systems and transparent remuneration systems for employees – including management.

The requirements also include setting up "appropriate arrangements that allow the institution's financial position to be determined at all times with reasonable accuracy."

Crypto firms the world over are facing increased scrutiny from regulators after a turbulent year that has seen some big industry names go bankrupt, in part because of poor risk-management strategies. Even countries with comprehensive regimes in place to regulate crypto, like Germany and Singapore, are taking a closer look at service providers.

"An audit of the annual financial statements revealed organizational deficiencies at the institute. The regularity of the business organization was not given in all audited areas," BaFin said in its statement. The order to address the organizational issues has been in effect since Oct. 27.

Coinbase Germany received permission from BaFin to provide crypto custody services in the country last year.

"Coinbase is committed to providing customers in Germany and around the world with the most trusted and easy to use crypto services," the company said in a blog post at the time. "Becoming licensed in Germany marks an important milestone as we strive to enable economic freedom around the world."

In addition to internal controls, BaFin found Coinbase Germany lacking "appropriate and effective risk management" for when transactions or services that are typically conducted by the firm are outsourced to other parties. According to the portions of the Banking Act referenced in its statement, BaFin wants Coinbase to ensure maintenance of “an outsourcing register as part of its risk management."

Coinbase is "cooperating fully" to address the findings of the audit, a spokesperson said in an emailed statement to CoinDesk following the publication of this article.

"We have developed a remediation plan fully addressing each finding of the audit report to address BaFin’s concerns. To date, we have made substantial progress on this plan,” the statement said.

Update (13:18 UTC, Nov. 8, 2022): Adds comment from Coinbase.


Please note that our privacy policy, terms of use, cookies, and do not sell my personal information has been updated.

CoinDesk is an award-winning media outlet that covers the cryptocurrency industry. Its journalists abide by a strict set of editorial policies. In November 2023, CoinDesk was acquired by the Bullish group, owner of Bullish, a regulated, digital assets exchange. The Bullish group is majority-owned by; both companies have interests in a variety of blockchain and digital asset businesses and significant holdings of digital assets, including bitcoin. CoinDesk operates as an independent subsidiary with an editorial committee to protect journalistic independence. CoinDesk employees, including journalists, may receive options in the Bullish group as part of their compensation.

Sandali Handagama

Sandali Handagama is CoinDesk's deputy managing editor for policy and regulations, EMEA. She does not own any crypto.