Malaysia's IEO and Digital Offering Framework: The SC's Digital Offering Guidelines, Whitelisting, Due Diligence, and Token Listing Process

InfrastructureRegulation/ComplianceWhite Label SolutionAugust 12, 2026

Malaysia is one of the first Southeast Asian countries to bring digital asset offerings under formal securities regulation. Since the Securities Commission Malaysia (SC) first issued the Guidelines on Digital Assets in 2019, it has built a licensing and supervisory framework for Digital Asset Exchanges (DAX), Initial Exchange Offering (IEO) platforms, digital-asset issuers, and digital custodians, with multiple rounds of revisions between 2022 and 2025 that tightened issuer admission, strengthened disclosure, and introduced Shariah screening and investor protection. For projects, raising funds publicly through a licensed platform in Malaysia is no longer as simple as "listing a token"; it is a structured path involving prospectus-equivalent documents, due diligence, whitelisting, retail caps, and ongoing disclosure. This article maps the SC's IEO and digital-offering framework across platform eligibility, issuer admission, whitelists, prospectus content, due-diligence checklists, asset-backed and security tokens, Shariah screening, secondary trading, investor protection, advertising restrictions, and delisting, to give projects and operators a realistic view of what "compliant token issuance in Malaysia" means.

1. Overall Structure of the Regulatory Framework

Malaysia's digital-asset offering regulation centers on the SC and draws its highest legal authority from the Capital Markets and Services Act 2007 (CMSA). Under section 304 of CMSA, the SC issued the Guidelines on Digital Assets and the Guidelines on Digital Offerings, classifying digital assets by economic substance into three categories.

Security tokens that represent shares, debt, collective-investment-scheme interests, derivatives, or other securities are fully subject to securities laws. Offerings require a prospectus or exemption, SC registration or filing, and ongoing disclosure.

Utility tokens grant access to a product or service. They generally do not constitute securities, but when offered publicly through an IEO platform they remain subject to the platform's due-diligence and disclosure obligations under the Guidelines.

Non-fungible tokens are generally treated as digital collectibles or credentials rather than securities. However, fractional ownership, revenue rights, or dividends attached to NFTs may recharacterize them as securities, and large-scale public NFT offerings may still be regulated as digital assets.

The most compliant route to raise funds publicly in Malaysia is through an SC-recognized IEO platform. The platform itself must be SC-registered or recognized, and it is responsible for issuer due diligence, investor suitability, custody of funds, and secondary-market oversight. Projects cannot directly offer tokens to the Malaysian public without going through this route without risking unauthorized-offering liability.

2. IEO Platform Eligibility

Not every exchange can run an IEO business in Malaysia. The SC imposes higher requirements on IEO platforms than on ordinary DAXs because primary-market fundraising demands stronger investor protection.

First, legal personality and local presence. The operator must be a Malaysian-incorporated company with a local board, compliance officer, risk officer, and a physical office in Malaysia. Pure offshore entities serving Malaysian investors remotely are not permitted.

Second, capital and finance. IEO platforms must meet minimum paid-up capital, typically in the millions of ringgit, maintain liquid reserves, file annual audited financials, and report capital adequacy to the SC as required.

Third, governance and compliance. The board must include independent directors and audit, risk, and compliance committees. The firm must maintain written compliance, AML, conflict-of-interest, and cybersecurity policies, and the compliance officer must report directly to the board.

Fourth, technology and custody. Trading systems must pass SC-recognized third-party audits covering smart contracts, wallets, matching engines, and KYC. Customer assets must be segregated from proprietary assets, at least 80 percent of customer crypto in cold storage, with MPC or multi-signature controls and insurance or risk reserves for hacks and losses.

Fifth, market surveillance and anti-manipulation. Real-time surveillance must detect self-trading, spoofing, insider trading, and pump-and-dump schemes, with clear enforcement procedures and regular suspicious-transaction reports to the SC.

Sixth, IEO due-diligence capability. The platform needs a dedicated listing-review team that runs business, technical, legal, financial, and Shariah due diligence on each issuer and produces a written assessment.

These requirements mean that IEO platforms in Malaysia effectively play a role analogous to traditional exchange listing review, not just a token-sale website. Projects should evaluate a platform's license status, diligence standards, and track record as core decision criteria. It is also worth noting that the SC applies different intensity to different platforms: a platform with a clean supervisory history, strong capital, and mature surveillance infrastructure may see its IEO submissions processed faster than a newer entrant. Building a long-term working relationship with the SC is itself part of the cost of operating in Malaysia.

For foreign projects, an additional practical consideration is the appointment of a local sponsor. Most SC-recognized IEO platforms require a Malaysian-resident director or sponsor who interfaces with the SC, attends meetings, and takes responsibility for local regulatory communications. This is not merely an administrative formality; the sponsor is personally accountable for the accuracy of submissions and can be called in for explanations when issues arise. Choosing a sponsor with prior SC listings materially shortens the timeline and reduces the risk of rejection late in the process.

3. Issuer Admission Criteria

The SC also sets clear admission criteria for IEO issuers, and platforms cannot list arbitrarily.

Entity form: issuers are generally expected to be duly incorporated companies, whether Malaysian or foreign with a legal opinion confirming valid existence in their home jurisdiction. Projects initiated by individuals with no legal entity are typically rejected.

Business viability: projects need a credible business plan, clear roadmap, and verifiable team background. Whitepapers must cover technical architecture, token economics, use of proceeds, and risk factors, not just marketing copy.

Operating history: the SC does not impose a one-size-fits-all minimum, but platform due diligence generally favors projects with prototypes, user data, or partnerships. Pure idea-stage projects rarely pass.

Financial disclosure: issuers must submit audited or reviewed financial statements, with alternatives for projects under a year old. Budgets for raised funds must be itemized, and funds are released in tranches from a custody account to prevent lump-sum diversion.

Team and advisor compliance: directors, executives, and major shareholders pass KYC and suitability checks. Individuals with fraud, money-laundering, or securities-violation histories are rejected, and advisors, market makers, and law firms must be disclosed.

Clear token characterization: whitepapers must state whether the token is a security, utility, or asset-backed instrument. Utility tokens must specifically articulate what holders can do with them, rather than vague "ecosystem rights."

Shariah compliance is optional but recommended, as discussed later.

Prohibited categories: gambling, adult content, high-interest lending, high money-laundering risk, and associations with sanctioned parties are excluded outright.

4. Whitelisting and Investor Caps

IEOs are not open-ended public sales. The SC requires whitelisting and suitability assessment.

KYC and CDD are mandatory for every participant, covering ID, proof of address, tax residency, and a risk-tolerance questionnaire. Malaysian citizens and foreigners can participate, but sanctioned and high-risk jurisdictions are blocked.

Investor categories: sophisticated or accredited investors such as high-net-worth individuals, corporations, trusts, and institutions face no investment limits. Retail investors are capped per IEO and per year, typically at a few thousand ringgit per project.

Risk profiling: retail investors complete a risk assessment before first participation, and the outcome determines the projects and amounts accessible to them.

Cooling-off and withdrawal: for certain categories, retail investors have a short cooling-off period, such as 24 hours after placing an order, within which they can withdraw without penalty, mirroring traditional IPO protections.

AML and sanctions screening: platforms continuously screen investors against OFAC, UN, EU, and Malaysian home-ministry lists, as well as PEPs and adverse media.

Airdrops and zero-cost distributions of tokens with security characteristics to Malaysian users may themselves be offerings and require prior coordination with the platform and SC.

5. Prospectus and Disclosure Documents

Public offerings of security tokens generally require an SC-approved prospectus comparable to a traditional IPO. Utility tokens offered through an IEO do not require a full prospectus, but platforms must submit extensive offering documents to the SC, including:

whitepaper covering project overview, technical architecture, consensus mechanism, token standard, allocation, vesting, use of proceeds, governance, team, roadmap, and risks. Chinese and English or Malay versions must be consistent and signed off by directors.

term sheet covering total supply, issue price, sale rounds, lock-ups, market-making arrangements, refund policy, and treatment of unsold tokens.

Governance and operational documents such as articles of association, shareholder agreements, token-holder agreements, smart-contract audit reports, custody agreements, and market-making agreements.

legal opinion from a Malaysian-qualified lawyer confirming the token's characterization, compliance with CMSA and the Guidelines, and the issuer's legality in its home jurisdiction.

Shariah opinion where applicable from an SC-recognized Shariah advisor confirming compliance.

risk-disclosure statement in plain language warning investors that they may lose their entire principal, with no "guaranteed return" or "capital-protected" language.

continuing-disclosure undertaking committing the issuer to quarterly or annual operational and use-of-proceeds reports and immediate disclosure of material events such as team changes, hacks, or regulatory developments.

These documents are not only for the SC. They provide investors with legal protection; misstatements can constitute false or misleading statements under CMSA, with civil liability and criminal penalties.

6. The Core Platform Due-Diligence Checklist

IEO platform due diligence typically runs four to eight weeks across several dimensions.

Commercial diligence covers industry, market size, competitive landscape, product differentiation, user growth, partnership verification, and revenue-projection sanity checks. Platforms verify claimed contracts, patents, and licenses.

Technical diligence covers smart-contract audits by SC-recognized third parties, code quality, testnet performance, incident history, technical capability, hidden backdoors, and transparent upgrade authorities.

Legal diligence covers issuer incorporation, cap tables, token characterization, IP ownership, employment and contractor agreements, litigation and regulatory history, and enforcement in other jurisdictions.

Financial diligence covers historical statements, source-of-funds legitimacy, budget sanity, related-party transactions, token pricing and lock-ups for market makers and early investors, and hidden liabilities.

Team diligence covers background checks, credential verification, social-media history, criminal and credit records, and sanctions or PEP screening.

Shariah diligence where applicable verifies business, financial ratios, token function, underlying assets, and revenue structure.

AML diligence covers source of funds, early-investor addresses, OTC counterparties, and exposure to high-risk jurisdictions.

Diligence reports are filed with the SC. Platforms that fail to conduct reasonable review may face joint liability for project failures or fraud, which explains their conservatism on listings.

7. Asset-Backed and Security Tokens

Asset-backed tokens are an important subcategory in Malaysia. They represent partial ownership of underlying physical or financial assets such as real estate, gold, receivables, Sukuk, or private equity. They are inherently securities and face the strictest requirements.

Beyond standard IEO requirements, asset-backed token issuances require legal isolation of the underlying asset through an SPV or trust so it is bankruptcy-remote from the issuer; independent valuation and audit with periodic disclosure; custody arrangements with approved custodians for physical assets and trust banks for financial assets; investor redemption mechanisms that make holders' rights to the asset or its cash flows legally enforceable; and ongoing disclosure of asset performance, rents, interest, and defaults.

Security and asset-backed tokens in Malaysia can benefit from flexibilities not available to traditional securities, such as longer investor-onboarding cycles and less frequent reporting than IPO quarterly cycles, but they must still be issued and traded through SC-recognized platforms.

8. Shariah Compliance as an Option

As a global Islamic-finance center, Malaysia explicitly supports Shariah-compliant digital-asset business. Projects seeking broader investor access can pursue Shariah certification.

Shariah review focuses on business activity free from Riba, Gharar, Maysir, and haram sectors; financial ratios that keep interest-bearing debt, interest-bearing assets, and non-compliant income within accepted thresholds; token function as utility or profit-sharing tied to real assets rather than pure speculation; smart-contract logic without hidden interest, excessive uncertainty, or unfair liquidations; and fund flows that avoid haram sectors and sanctioned entities.

A Shariah pronouncement opens the project to Malaysian Islamic funds, retail Muslim investors, and Islamic-bank investment accounts. It also brings annual Shariah audits and income-cleansing obligations.

9. Secondary Trading and Market-Making

After an IEO, tokens trade on the IEO platform or a DAX, subject to SC requirements.

Fair access: every KYC-verified user trades under the same rules with no preferential access for insiders.

Market-maker arrangements: issuers may hire market makers but must disclose their identities, funding, obligations, and prohibited conduct. Market makers may not mark the close, wash trade, or place misleading orders.

Lock-ups: team, advisor, and early-investor tokens typically lock for six to twenty-four months, enforced by smart contracts and supervised by the platform.

Position disclosure: addresses holding above thresholds such as 5 percent must be disclosed, and issuer treasury wallets must be publicly tagged.

Insider-trading restrictions: teams, advisors, and platform employees cannot trade on non-public information, with blackout windows around major announcements.

Continuous surveillance: the platform's surveillance system monitors for anomalies in real time and escalates them to the SC.

10. Investor Protection Funds and Compensation

To strengthen confidence, the SC encourages IEO platforms to establish Investor Protection Funds funded from platform revenue, listing fees, and fines. Funds compensate investors under defined rules when customer assets are lost due to system failures, hacks, insider crime, proven issuer fraud, or market-maker default.

Funds do not cover market losses from price declines, user-compromised keys, or mistaken dispute outcomes. Fund size, payout caps, and application procedures must be public. Some platforms also add risk reserves for extreme-market clawbacks and commercial insurance covering hacks, insider crime, and custody errors. Together these form the infrastructure of investor confidence.

11. Advertising, Marketing, and Social Media

The SC imposes strict rules on IEO and digital-asset marketing. The core principles are clarity, balance, non-misleading content, and prominent risk warnings.

Pre-marketing limits: before the SC approves offering documents, projects cannot publicly announce specific terms in Malaysia. Brand or educational content is allowed, but calls to action such as "coming soon," "investment opportunity," or "early-bird bonus" are not.

Risk warnings: every marketing piece must carry a prominent warning that digital assets are high-risk and investors may lose all principal, in type no smaller than the body text.

Celebrity endorsements: SC-approved celebrities may be used only under specific conditions, KOL sponsorships must be disclosed, and KOLs may not promise specific returns.

Social media and communities: Telegram, Discord, X, and WeChat posts are within the SC's jurisdiction. Projects must retain marketing archives for inspection.

Roadshows and events: public offline roadshows require filing with the platform and SC. Closed-door presentations to accredited investors are more flexible but still cannot contain false statements.

Foreign content: ads on overseas platforms such as YouTube or X that materially target Malaysian users may still be caught by local rules.

12. Suspension, Delisting, and Failure Handling

Not every IEO succeeds. The SC requires clear mechanisms.

Suspension: platforms can immediately halt secondary trading during material non-disclosure, critical contract vulnerabilities, missing teams, regulatory investigations, or anomalous trading, and must report to the SC within 24 hours.

Compulsory delisting follows persistent disclosure breaches, business cessation, proven fraud, prolonged illiquidity, or revocation of Shariah status. Delisting is announced in advance to allow orderly exit.

Refunds: if an IEO fails to hit its soft cap or cannot proceed for regulatory reasons, the custody account refunds investors per the offering documents; funds released to the issuer are settled against milestones with usage reporting.

Insolvency: token-holder legal status depends on token type. Security-token holders may rank as creditors or shareholders; utility-token holders have weaker recovery rights. Issuing documents must spell this out.

Dispute resolution: investor complaints go first through the platform, then to the SC's investor-complaint function, and ultimately to Malaysian courts or arbitration such as through the AIAC.

Conclusion

Malaysia's IEO and digital-offering framework is the product of repeated calibration between investor protection and innovation. It is neither the loosest nor the harshest regime in the world, but it offers a clear, predictable path that connects to traditional capital markets. For projects, issuing tokens in Malaysia means stricter diligence, fuller disclosure, and stronger investor protection, but it also grants access to Islamic-finance markets, ASEAN family offices, and institutional investors. For operators, building an SC-compliant IEO platform requires long-term investment across legal, technical, risk, Shariah, and investor education, but once built it forms a hard-to-replicate moat in Southeast Asia. In an era where "issuing a token is easy but issuing one compliantly is hard," Malaysia does not offer a shortcut; it offers a path that goes further.

FAQ

Q1: Does Malaysia allow ICOs, or is IEO the only option?

A: Direct ICOs to the Malaysian public without SC recognition are not permitted. The compliant route is an SC-registered or recognized IEO platform satisfying the Guidelines on Digital Assets and Guidelines on Digital Offerings. Private placements to foreign accredited investors may rely on exemptions but require a legal opinion.

Q2: Are there retail investment caps for IEOs in Malaysia?

A: Yes. Retail investors typically face per-project and annual maximums, must complete KYC and risk profiling, while sophisticated or accredited investors such as high-net-worth individuals and institutions face no limits. Exact caps are set by SC rules and platform policy and may evolve.

Q3: Do utility tokens need a prospectus?

A: Utility tokens offered through an IEO generally do not require a full prospectus, but they require extensive documents including a whitepaper, term sheet, and legal opinion filed with the SC. If the token's economics make it a security—dividends, profit-sharing, voting rights—then it is treated as a security token and may require a prospectus.

Q4: Is Shariah compliance mandatory?

A: No, but it is strongly recommended for projects targeting Muslim investors, Islamic funds, and Islamic-bank capital. It requires business, financial, and contract screening and annual renewal. Non-Shariah projects may still list legally in Malaysia but with a narrower investor base.

Q5: Can investors recover funds if a project fails or the team absconds?

A: It depends on the cause. If an IEO misses its soft cap, the custody account refunds investors. Proven issuer fraud can be compensated through the investor-protection fund after court or arbitration. Platform hacks and insider crime are covered by the fund and insurance within stated limits. Market losses, user key compromise, and user error are not.

Q6: Where can the token trade after an IEO?

A: Typically on the issuing platform's secondary market, and potentially on other SC-recognized DAXs. Listing on overseas exchanges requires confirmation that post-offering disclosure and advertising restrictions are respected and should be coordinated with the SC and issuing platform in advance.

🌐 Build secure and scalable Web3 platforms with SoonTech.

Explore our solutions for White Label Crypto Exchanges, Prediction Markets, MPC Wallets, Matching Engines, Liquidity Integration, and Compliance.

Start your blockchain journey

Professional team will provide you with free solution consultation

Contact us