Field guides
Token-launch partner due diligence
Due diligence should match the access a partner receives. A partner handling tokens, accounts, claims or confidential information needs deeper review than a one-off supplier.
01
Verify the entity and team
Confirm the legal entity, ownership, operating locations, signatory and delivery team. Check references for work that resembles your scope.
Understand which services are delivered by employees, affiliates or subcontractors.
- Legal entity and signatory
- Ownership and key people
- Relevant references
- Subcontractors
02
Map access and control
List every wallet, exchange account, social account, analytics tool, customer dataset and confidential document the partner may access.
Use least privilege, named users, multi-factor authentication and a written offboarding plan. Avoid shared credentials.
03
Review incentives and conduct
Understand compensation, token exposure, trading permissions, referral fees and other clients that could create a conflict. Require prompt conflict disclosure.
For trading or promotion work, document prohibited conduct, approval controls and the records you expect the partner to retain.
04
Make delivery auditable
Define scope, owners, measurable outputs, reporting cadence, incident notification, confidentiality, intellectual property and termination rights.
Set review dates. Re-check the relationship when scope, team, jurisdiction or access changes.
- Measurable scope
- Incident and escalation path
- Data and IP terms
- Exit and access recovery
Official references
- IOSCO policy recommendations for crypto and digital asset markets
- FCA guidance on cryptoasset financial promotions
Requirements vary by market and jurisdiction. Use qualified legal advice for your launch.