From Regulation to Data: A New Chapter in Digital Asset Supervision
Note: This article reflects the personal opinion of the writer and does not represent the views of the CNBC Indonesia editorial team.
In the era of digital finance, a regulator’s strength is no longer determined solely by how complete its rules are, but by how quickly risks can be seen. When transactions run around the clock, products evolve rapidly, and interconnections between market participants grow increasingly complex, supervision that relies on formal compliance alone is no longer sufficient. Data has now become part of the infrastructure of stability and market trust.
It is in this context that Financial Services Authority (OJK) Commissioner Member Regulation No. 3 of 2026 on the Organisation of Digital Financial Asset Trading, Including Crypto Assets, merits attention. Taking effect on 1 September 2026, the regulation appears at first glance to address something technical: mechanisms, formats, types and reporting deadlines. Yet behind this administration lies a more strategic agenda — a shift towards data-driven supervision.
PADK No. 3/2026 is not a new crypto asset regime. Its foundations were laid through POJK No. 27 of 2024, later amended by POJK No. 23 of 2025. PADK No. 3/2026 operationalises that architecture through digital financial asset evaluation reports, monthly reports, self-assessments of risk management, annual and ad hoc reports, as well as notifications of clearing, guarantee and settlement activities for digital financial asset derivative transactions.
This is where something seemingly administrative takes on strategic meaning. Modern financial regulation no longer stops at the question, “which rules must be complied with?”, but moves towards the more important question: “what risks can be read from the data?”
From Regulatory Transfer to Supervisory Deepening
Indonesia has passed the first phase, in which the regulation and supervision of digital financial assets, including crypto, transferred to the OJK in 2025 as mandated by the P2SK Law. The market can no longer be regarded as peripheral.
As of July 2026, the number of consumer accounts for digital financial asset trading had reached 22.93 million. In the same month, crypto asset transaction value reached Rp20.52 trillion, plus derivative transactions of Rp3.41 trillion.
Market infrastructure is increasingly complete: two digital financial asset exchanges, two clearing, guarantee and settlement institutions, two custodians, and 26 licensed traders. The CFX exchange lists 1,214 assets and 49 derivatives, whilst ICEX records 871 tradable assets.
These figures transform the supervision problem. When the market involves nearly 23 million consumer accounts, thousands of assets and transactions worth tens of trillions of rupiah each month, the question is no longer whether digital assets need regulating. The question is how the regulator gains visibility over the risks moving within it.
An entity-based supervision approach alone is increasingly inadequate. The regulator needs to understand relationships between participants, transaction concentrations, asset flows, liquidity, exposures, trading anomalies, and the possibility of risk transmission.
Paradoxically, the digital economy does not lack data — it is flooded with it. Data abundance can produce information scarcity when millions of data points cannot be translated into information relevant to supervision. That is the difference between reporting and intelligence.
Data as a Supervisory Sensor
PADK No. 3/2026 builds one of its foundations through the standardisation of reporting. Operators must submit periodic monthly, quarterly and annual reports as well as ad hoc reports. The regulation also governs asset evaluation reports for the Digital Financial Asset List and notifications of clearing, guarantee and settlement activities for derivative transactions.
Reporting thus has the potential to transform from an administrative obligation into a supervisory sensor. This does not yet mean real-time supervision; reporting periodicity remains. It is therefore more accurate to read PADK as a foundation for improving risk visibility — the regulator’s capacity to see patterns and concentrations of risk more systematically.
The European Union’s experience shows the direction of evolution. The Markets in Crypto-Assets Regulation (MiCA) did not stop at licensing and compliance obligations. ESMA developed data standards for crypto asset service providers’ record-keeping, including standardised machine-readable JSON schemas for orders and transactions.
The aim is clear: to make transaction structures and metadata uniform, improve comparability, facilitate data exchange with authorities, and strengthen market surveillance.
The lesson is not that Indonesia should copy MiCA. Market structures and institutions differ across jurisdictions. The lesson is more fundamental: a strong regulatory perimeter must be underpinned by an equally strong information architecture.
Singapore moves with a similar philosophy through the Monetary Authority of Singapore’s supervision of digital payment token services: digital innovation is brought within the perimeter of financial regulation, rather than being left to develop as a world separate from standards of governance, risk management and consumer protection.
Indonesia has in fact begun entering territory broader than crypto trading. As of July 2026, the OJK’s regulatory sandbox has produced business models declared to have passed — from gold tokenisation, securities tokenisation and property ownership benefit tokenisation, to the rupiah stablecoin, custody of non-tradable digital financial assets, and crypto fund managers. This means supervision is facing not only market growth, but also a change in the market’s very shape.
From Risk Visibility to Predictive Supervision
IOSCO points further ahead. Its global recommendations place market surveillance as a key element in the oversight of crypto asset markets. Authorities need the capability to detect suspicious transactions and orders, respond quickly to suspected market abuse, share information, and monitor both on-chain and off-chain activity.
This is where Indonesia’s next agenda should move. Standardised reporting must not stop at the digitisation of forms. If thousands of data columns simply move from industry spreadsheets to the regulator’s servers, technology has not yet changed the paradigm of supervision.
Added value is only created when trading, clearing, custody, capital, risk profile, ownership concentration, consumer complaint and irregular transaction data can be interconnected. From there, the regulator can build early-warning indicators, detect anomalous patterns and map risk interconnections.
The evolution can be summarised in three stages: from compliance reporting towards risk visibility, and then developing into predictive supervision. Supervision no longer stops at compliance with reporting obligations, but moves towards the ability to read concentrations of risk and, at a more advanced stage, to identify early signals before risks develop into problems.
The first stage answers whether participants comply with the rules. The second stage shows where risk is beginning to concentrate. The third is more advanced: using SupTech, network analytics, machine learning and artificial intelligence to read weak signals before they develop into problems.
Imagine nearly 23 million consumer accounts and transactions worth tens of trillions of rupiah no longer being read as standalone tables, but as a network of financial relationships. Supervisors could identify concentrations in particular assets, unusual surges in volume, changes in transaction patterns, relationships between participants, and indications of operational risk and market conduct issues.
This is where data changes from a compliance burden into a supervisory asset. Yet predictive supervision does not mean handing supervisory decisions over to algorithms. The broader the use of AI, the more important human judgement, data quality, model governance, auditability and the control of false positives become. Technology must strengthen the supervisor’s capacity, not replace its accountability.
Regulation as Trust Infrastructure
This transformation is all the more important because the future of digital assets does not stop at retail crypto trading. Tokenised real-world assets, digital securities, stablecoins, digital custody and distributed ledger-based investment instruments are increasingly bringing the digital asset world together with the formal financial system. Indonesia’s sandbox experiments show this convergence is no longer mere discourse.
IOSCO offers a relevant principle: same activity, same risk, same regulation/regulatory outcome. The technology may change, but similar activities and economic risks should receive comparable standards of protection. Regulation should therefore not be positioned as the enemy of innovation. Good regulation is, in fact, trust infrastructure.
Institutional investors do not enter a market merely because its technology is attractive. They require legal certainty, governance, asset protection, market integrity, risk management and trustworthy data. The stronger these foundations, the greater the chance that digital assets move from dominance by speculative trading towards becoming a productive part of the financial system.
In that perspective, PADK No. 3/2026 is indeed only one piece of a larger architecture. But it affirms something fundamental: good supervision begins with the ability to see.
The first chapter of Indonesia’s digital asset transformation was expanding the regulatory perimeter. The second was consolidating regulation and institutions. The next chapter is building intelligent supervision.
Indonesia already has the scale: nearly 23 million consumer accounts, two exchanges, two clearing institutions, two custodians, dozens of licensed traders, thousands of tradable assets, and innovation moving from crypto towards tokenisation and stablecoins. The challenge now is not producing ever more data, but making the data speak.
For in a market that moves 24 hours a day, the future regulator’s advantage is determined not by how many reports it receives, but by how quickly data can be turned into risk signals, and how early those signals can be translated into supervisory action.