Crypto and Fintech Under the Accounting Microscope: OJK’s Draft Rules on Financial Reporting Integrity
Indonesia’s financial regulator, the Financial Services Authority (Otoritas Jasa Keuangan or “OJK”) has opened public consultation on a new draft regulation governing financial reporting integrity for fintech, digital financial assets, and crypto asset providers (the “Draft POJK”). If issued as currently drafted, the Draft POJK would establish a dedicated financial reporting integrity and internal control regime for the IAKD sector, comprising technological innovation in the financial sector (ITSK), digital financial assets, and crypto assets.
The initiative builds on the transfer of regulatory and supervisory authority over digital financial assets, including crypto assets, from Bappebti to OJK under Law No. 4 of 2023 on the Development and Strengthening of the Financial Sector (the “P2SK Law”). It also reflects a broader concern: given the sector’s complex and distinctive risk profile, OJK wants to ensure that financial information and financial statements must be honest, accurate, complete and reliable. The P2SK Law already prohibits anyone, including directors, commissioners and employees, from making false entries, omitting entries, or altering, obscuring, concealing or deleting records in a provider’s books or reports. The Draft POJK would give more specific effect to that prohibition for IAKD Providers. Its key features are summarized below.
Affected Parties and Obligations
The Draft POJK applies to IAKD Providers (Penyelenggara IAKD), meaning any party conducting activities in the ITSK, digital financial asset or crypto asset sectors. This covers digital financial asset trading providers (exchanges, clearing institutions, guarantee institutions and settlement institutions, storage managers, digital financial asset traders, and any other party designated by OJK), as well as ITSK providers. Importantly, the Draft POJK distinguishes between licensed and registered providers, applying different obligations and sanction thresholds to each.
These obligations extend beyond the provider entity to the Board of Directors, Board of Commissioners, controlling shareholders (Pemegang Saham Pengendali or “PSP”, defined as holders of 25% or more of voting shares, or holders of less than 25% proven to exercise control either directly or indirectly), employees, and affiliated parties.
Under Article 2, every IAKD Provider must maintain a financial reporting process with integrity, ensuring the truth, accuracy and transparency of the financial information and financial statements it produces. The elucidation defines “truth” as free from material misstatement; “accuracy” as neutral and free from bias; and “transparency” as accessible to those who need the information and inclusive of all relevant information.
Financial statements must be prepared correctly, completely and on time. They must also meet the qualitative characteristics prescribed in the Draft POJK, including relevance, materiality and faithful representation. Faithful representation requires information to be complete, neutral and free from error, though the elucidation acknowledges that estimates need not be entirely accurate in every respect.
Prohibited Conduct
Article 3 of Draft POJK prohibits directors, commissioners, controlling shareholders and employees from intentionally causing any of the following:
financial information and/or financial statements that misrepresent the provider’s true condition;
concealment of material information concerning the provider’s business, risks, financial condition or business continuity;
interference — direct or indirect — with the independence of internal audit;
failure to follow up internal audit findings and recommendations that have a material impact;
manipulation of the provider’s financial statements;
financial statements that fail to comply with accounting standards and OJK recording rules; and/or
financial information and/or statements that fail to comply with financial-sector laws and regulations.
The elucidation of Article 3 illustrates this with several examples: manipulating or falsifying accounting records, omitting transactions, misapplying recognition, measurement, presentation or disclosure principles, obscuring or destroying records of the provider’s financial statement, and permitting manipulation of a subsidiary’s financial statements, in each case where the conduct is intended to benefit the person concerned or another party. It also gives two more-pointed examples: directors deliberately concealing significant liabilities or costs to inflate profit and their bonuses, and a controlling shareholder directing the artificial inflation of digital asset or crypto transaction volumes through transactions lacking genuine economic substance, creating a false appearance of increased activity and revenue.
This latter example appears squarely aimed at conduct commonly known as wash trading or other forms of artificial volume inflation, though the Draft POJK itself never uses that term.
Internal Control Over Financial Reporting and Fraud Prevention
Article 4 requires IAKD Providers to establish, adopt and implement internal control policies and procedures over financial reporting. These controls must be designed to ensure the truth, accuracy, currency and transparency of financial information; improve operational efficiency and effectiveness; ensure regulatory compliance; and ensure financial statements are prepared in accordance with OJK reporting rules.
The Draft POJK would also require a licensed IAKD Provider to establish a dedicated function responsible for preventing fraud or manipulation in their financial information and statements, a function that may be combined with risk management or compliance function. Registered IAKD Provider, by contrast, would only need to appoint an officer or employee responsible for preventing fraud or manipulation in its financial statements.
Responsibilities of the Board of Directors and Board of Commissioners
Article 8 makes the Board of Directors (“BOD”) responsible for the preparation and presentation of financial information and financial statements, their conformity with OJK reporting rules, the completeness and accuracy of their contents, and the implementation of internal control over financial reporting. The BOD must also ensure that financial reporting is prepared by employees with the necessary knowledge and skills, which, per the elucidation, may be evidenced by finance-related training or certification.
The BOD must also submit an internal control report to OJK, in the form prescribed in the Annex, together with its annual financial statements audited by a public accountant. This report covers three areas: entity-level controls (organizational structure, control environment, internal and external communication, and monitoring); process-level controls (risk identification, mitigation and follow-up plans); and the identification and evaluation of internal control weaknesses. Under the prescribed template, weaknesses must be classified as control deficiencies, significant deficiencies or material weaknesses, each supported by remediation measures, responsible persons and target completion dates. The report concludes with a directors’ statement on the overall effectiveness of internal control and the accuracy of the report itself.
Article 9 requires the Board of Commissioners (“BOC”) to supervise the implementation of internal control policies and procedures over the preparation and reporting of financial statements, as well as the conformity of those statements with OJK reporting rules. The BOC must discharge these duties in good faith and with prudence. The results of this supervision must be submitted together with either the realization of the business plan (for digital financial asset trading providers) or the BOC activity report required under governance reporting rules (for IAKD Providers or ITSK providers generally).
Sanctions and Disgorgement
The Draft POJK gives OJK a broad set of administrative sanctions, with the consequences varying depending on whether the breach is committed by the provider, its principal parties or other individuals involved.
For IAKD Providers, Article 6 allows OJK to impose a written warning, suspend all or part of the provider’s activities (including cooperation arrangements), impose an administrative fine, place the relevant principal parties on the financial sector’s list of disgraceful persons, and/or revoke the provider’s business license. OJK is not required to issue a written warning first and may proceed directly to other sanctions where warranted.
The fine exposure is material. Registered providers face fines of between Rp10 million and Rp500 million per violation, while licensed providers face fines of between Rp10 million and Rp1 billion per violation.
The regime also reaches individuals. Under Articles 6, 10 and 13, directors, commissioners and controlling shareholders may receive a written warning and/or be barred from serving as a director, commissioner or controlling shareholder. Controlling shareholders may also be fined up to Rp1 billion, while affiliated parties may receive a written warning.
The consequences may extend beyond immediate sanction. Articles 7, 10 and 14 authorize OJK to reassess relevant principal parties and to record the track record of related parties in OJK’s electronic system. The Draft POJK, however, does not specify what further legal consequences that record may carry.
Article 17 also gives OJK a disgorgement power. Directors, commissioners, controlling shareholders and employees who breach Article 3, controlling shareholders who breach Article 11(2), and affiliated parties who breach Article 12(1) may be ordered to return any profits obtained to the IAKD Provider.
In determining administrative sanctions under Article 6, OJK will weigh several factors: the impact of the breach on consumer losses and on the condition of the provider and the financial services sector; the complexity of the breach; the provider’s financial condition; and any history of repeated breaches. Where the relevant requirements have been met, OJK may revoke a sanction. Article 6(8) provides a cure mechanism: where a breach has already been remedied, OJK will still impose a written warning, but one that lapses automatically, leaving no lasting sanction. Comparable cure provisions apply to controlling shareholders and affiliated parties under Article 13.
ABNR Commentary
Draft POJK is more than an accounting rule. It would introduce an extended accountability framework for financial reporting integrity that reaches beyond the provider itself to directors, commissioners, controlling shareholders, employees and affiliated parties. For digital financial asset exchanges, clearing, guarantee and settlement institutions, storage managers, traders and ITSK providers, the combination of mandatory internal controls, formal governance accountability, regulatory reporting and personal sanction exposure would represent a material increase in supervisory expectations.
Four points deserve particular attention. First, the prescribed annual internal control report is likely to be the regime’s most operationally demanding feature. It requires providers to conduct and document a structured assessment of internal control over financial reporting, classify identified deficiencies and commit to remediation measures, responsible persons and completion dates. This is therefore not merely a procedural filing; it calls for an evidence-based control assessment capable of supporting a signed directors’ conclusion.
Second, Draft POJK targets the governance drivers behind reporting failures, not just the resulting misstatements. Controlling shareholders face direct obligations and sanction exposure, while affiliated parties may be sanctioned and ordered to disgorge profits where they improperly intervene in the financial reporting process. The example involving transactions lacking reasonable economic substance also indicates that artificial transaction-volume inflation could be treated as both a market-conduct issue and a financial-reporting integrity issue.
Third, Article 15 creates a potentially broad notification obligation. It applies wherever a weakness or condition in the financial reporting process may endanger the provider’s business continuity, and the elucidation confirms that such a weakness can exist even absent a material misstatement. Providers should therefore establish a documented escalation and assessment process to identify potentially reportable matters, gauge their significance and support consistent notification to OJK.
Fourth, the transitional provisions warrant careful treatment. For providers licensed before promulgation, the specified internal-control and anti-fraud requirements would apply no later than one year after promulgation, while the administrative fine provisions are intended to take effect two years after the regulation comes into force. The current wording of Article 19 is incomplete, however, and the precise scope and operation of that two-year period will need to be confirmed in the final regulation.
As this remains a consultation draft, there is scope to seek clarification on several points. Relevant stakeholders may use the consultation period to submit comments, suggestions and practical perspectives to OJK on the proposed requirements. This is an important opportunity to identify ambiguities, implementation challenges and areas requiring further clarification before the Draft POJK is finalized.
In the meantime, IAKD Providers should begin mapping the proposed requirements against their governance arrangements, financial reporting systems, internal-control documentation, fraud-prevention responsibilities and regulatory escalation protocols, while preserving flexibility to adjust for changes in the final POJK.
By Partners Ayik C. Gunadi (agunadi@abnrlaw.com), Monic Devina (mdevina@abnrlaw.com), Meitiara Bakrie (dbakrie@abnrlaw.com), and associate Beverly Laza (blaza@abnrlaw.com)
This ABNR client alert is intended solely to provide a general overview, for informational purposes, of selected recent developments in Indonesian law. It does not constitute legal advice and should not be relied upon as such. ABNR accepts no liability of any kind in respect of any statement, opinion, view, error or omission that may be contained in this update. You are strongly advised to consult a licensed Indonesian legal practitioner before taking any action that could affect your rights and obligations under Indonesian law.
More Legal Updates
- 02 Oct 2026 ABNR Advises Telkom Indonesia on IDR 49.85 Trillion InfraNexia Spin-Off, Completing an IDR 85.63 Trillion Digital Infrastructure Transformation
- 01 Oct 2026 ABNR Represented Yulong Int’l Business (HK) Co. in the PKPU Restructuring of PT Wanxiang Nickel Indonesia
- 01 Oct 2026 2nd ABNR Morning Dialogue on 24 September 2026: Preparing for International Arbitration
- 28 Sep 2026 Indonesia's OECD Journey: ABNR Shares Competition Law Insights with the OECD
- 22 Sep 2026 Indonesia: OJK Proposes a New Risk-Based Capital and Dedicated Solvency Framework for Insurers and Reinsurers
- 18 Sep 2026 ‘Denied by LPS? See You in Court’: New Commercial Court Procedures for Deposit Insurance and Bank Liquidation Disputes
NEWS DETAIL
05 Oct 2026
Crypto and Fintech Under the Accounting Microscope: OJK’s Draft Rules on Financial Reporting Integrity
Indonesia’s financial regulator, the Financial Services Authority (Otoritas Jasa Keuangan or “OJK”) has opened public consultation on a new draft regulation governing financial reporting integrity for fintech, digital financial assets, and crypto asset providers (the “Draft POJK”). If issued as currently drafted, the Draft POJK would establish a dedicated financial reporting integrity and internal control regime for the IAKD sector, comprising technological innovation in the financial sector (ITSK), digital financial assets, and crypto assets.
The initiative builds on the transfer of regulatory and supervisory authority over digital financial assets, including crypto assets, from Bappebti to OJK under Law No. 4 of 2023 on the Development and Strengthening of the Financial Sector (the “P2SK Law”). It also reflects a broader concern: given the sector’s complex and distinctive risk profile, OJK wants to ensure that financial information and financial statements must be honest, accurate, complete and reliable. The P2SK Law already prohibits anyone, including directors, commissioners and employees, from making false entries, omitting entries, or altering, obscuring, concealing or deleting records in a provider’s books or reports. The Draft POJK would give more specific effect to that prohibition for IAKD Providers. Its key features are summarized below.
Affected Parties and Obligations
The Draft POJK applies to IAKD Providers (Penyelenggara IAKD), meaning any party conducting activities in the ITSK, digital financial asset or crypto asset sectors. This covers digital financial asset trading providers (exchanges, clearing institutions, guarantee institutions and settlement institutions, storage managers, digital financial asset traders, and any other party designated by OJK), as well as ITSK providers. Importantly, the Draft POJK distinguishes between licensed and registered providers, applying different obligations and sanction thresholds to each.
These obligations extend beyond the provider entity to the Board of Directors, Board of Commissioners, controlling shareholders (Pemegang Saham Pengendali or “PSP”, defined as holders of 25% or more of voting shares, or holders of less than 25% proven to exercise control either directly or indirectly), employees, and affiliated parties.
Under Article 2, every IAKD Provider must maintain a financial reporting process with integrity, ensuring the truth, accuracy and transparency of the financial information and financial statements it produces. The elucidation defines “truth” as free from material misstatement; “accuracy” as neutral and free from bias; and “transparency” as accessible to those who need the information and inclusive of all relevant information.
Financial statements must be prepared correctly, completely and on time. They must also meet the qualitative characteristics prescribed in the Draft POJK, including relevance, materiality and faithful representation. Faithful representation requires information to be complete, neutral and free from error, though the elucidation acknowledges that estimates need not be entirely accurate in every respect.
Prohibited Conduct
Article 3 of Draft POJK prohibits directors, commissioners, controlling shareholders and employees from intentionally causing any of the following:
financial information and/or financial statements that misrepresent the provider’s true condition;
concealment of material information concerning the provider’s business, risks, financial condition or business continuity;
interference — direct or indirect — with the independence of internal audit;
failure to follow up internal audit findings and recommendations that have a material impact;
manipulation of the provider’s financial statements;
financial statements that fail to comply with accounting standards and OJK recording rules; and/or
financial information and/or statements that fail to comply with financial-sector laws and regulations.
The elucidation of Article 3 illustrates this with several examples: manipulating or falsifying accounting records, omitting transactions, misapplying recognition, measurement, presentation or disclosure principles, obscuring or destroying records of the provider’s financial statement, and permitting manipulation of a subsidiary’s financial statements, in each case where the conduct is intended to benefit the person concerned or another party. It also gives two more-pointed examples: directors deliberately concealing significant liabilities or costs to inflate profit and their bonuses, and a controlling shareholder directing the artificial inflation of digital asset or crypto transaction volumes through transactions lacking genuine economic substance, creating a false appearance of increased activity and revenue.
This latter example appears squarely aimed at conduct commonly known as wash trading or other forms of artificial volume inflation, though the Draft POJK itself never uses that term.
Internal Control Over Financial Reporting and Fraud Prevention
Article 4 requires IAKD Providers to establish, adopt and implement internal control policies and procedures over financial reporting. These controls must be designed to ensure the truth, accuracy, currency and transparency of financial information; improve operational efficiency and effectiveness; ensure regulatory compliance; and ensure financial statements are prepared in accordance with OJK reporting rules.
The Draft POJK would also require a licensed IAKD Provider to establish a dedicated function responsible for preventing fraud or manipulation in their financial information and statements, a function that may be combined with risk management or compliance function. Registered IAKD Provider, by contrast, would only need to appoint an officer or employee responsible for preventing fraud or manipulation in its financial statements.
Responsibilities of the Board of Directors and Board of Commissioners
Article 8 makes the Board of Directors (“BOD”) responsible for the preparation and presentation of financial information and financial statements, their conformity with OJK reporting rules, the completeness and accuracy of their contents, and the implementation of internal control over financial reporting. The BOD must also ensure that financial reporting is prepared by employees with the necessary knowledge and skills, which, per the elucidation, may be evidenced by finance-related training or certification.
The BOD must also submit an internal control report to OJK, in the form prescribed in the Annex, together with its annual financial statements audited by a public accountant. This report covers three areas: entity-level controls (organizational structure, control environment, internal and external communication, and monitoring); process-level controls (risk identification, mitigation and follow-up plans); and the identification and evaluation of internal control weaknesses. Under the prescribed template, weaknesses must be classified as control deficiencies, significant deficiencies or material weaknesses, each supported by remediation measures, responsible persons and target completion dates. The report concludes with a directors’ statement on the overall effectiveness of internal control and the accuracy of the report itself.
Article 9 requires the Board of Commissioners (“BOC”) to supervise the implementation of internal control policies and procedures over the preparation and reporting of financial statements, as well as the conformity of those statements with OJK reporting rules. The BOC must discharge these duties in good faith and with prudence. The results of this supervision must be submitted together with either the realization of the business plan (for digital financial asset trading providers) or the BOC activity report required under governance reporting rules (for IAKD Providers or ITSK providers generally).
Sanctions and Disgorgement
The Draft POJK gives OJK a broad set of administrative sanctions, with the consequences varying depending on whether the breach is committed by the provider, its principal parties or other individuals involved.
For IAKD Providers, Article 6 allows OJK to impose a written warning, suspend all or part of the provider’s activities (including cooperation arrangements), impose an administrative fine, place the relevant principal parties on the financial sector’s list of disgraceful persons, and/or revoke the provider’s business license. OJK is not required to issue a written warning first and may proceed directly to other sanctions where warranted.
The fine exposure is material. Registered providers face fines of between Rp10 million and Rp500 million per violation, while licensed providers face fines of between Rp10 million and Rp1 billion per violation.
The regime also reaches individuals. Under Articles 6, 10 and 13, directors, commissioners and controlling shareholders may receive a written warning and/or be barred from serving as a director, commissioner or controlling shareholder. Controlling shareholders may also be fined up to Rp1 billion, while affiliated parties may receive a written warning.
The consequences may extend beyond immediate sanction. Articles 7, 10 and 14 authorize OJK to reassess relevant principal parties and to record the track record of related parties in OJK’s electronic system. The Draft POJK, however, does not specify what further legal consequences that record may carry.
Article 17 also gives OJK a disgorgement power. Directors, commissioners, controlling shareholders and employees who breach Article 3, controlling shareholders who breach Article 11(2), and affiliated parties who breach Article 12(1) may be ordered to return any profits obtained to the IAKD Provider.
In determining administrative sanctions under Article 6, OJK will weigh several factors: the impact of the breach on consumer losses and on the condition of the provider and the financial services sector; the complexity of the breach; the provider’s financial condition; and any history of repeated breaches. Where the relevant requirements have been met, OJK may revoke a sanction. Article 6(8) provides a cure mechanism: where a breach has already been remedied, OJK will still impose a written warning, but one that lapses automatically, leaving no lasting sanction. Comparable cure provisions apply to controlling shareholders and affiliated parties under Article 13.
ABNR Commentary
Draft POJK is more than an accounting rule. It would introduce an extended accountability framework for financial reporting integrity that reaches beyond the provider itself to directors, commissioners, controlling shareholders, employees and affiliated parties. For digital financial asset exchanges, clearing, guarantee and settlement institutions, storage managers, traders and ITSK providers, the combination of mandatory internal controls, formal governance accountability, regulatory reporting and personal sanction exposure would represent a material increase in supervisory expectations.
Four points deserve particular attention. First, the prescribed annual internal control report is likely to be the regime’s most operationally demanding feature. It requires providers to conduct and document a structured assessment of internal control over financial reporting, classify identified deficiencies and commit to remediation measures, responsible persons and completion dates. This is therefore not merely a procedural filing; it calls for an evidence-based control assessment capable of supporting a signed directors’ conclusion.
Second, Draft POJK targets the governance drivers behind reporting failures, not just the resulting misstatements. Controlling shareholders face direct obligations and sanction exposure, while affiliated parties may be sanctioned and ordered to disgorge profits where they improperly intervene in the financial reporting process. The example involving transactions lacking reasonable economic substance also indicates that artificial transaction-volume inflation could be treated as both a market-conduct issue and a financial-reporting integrity issue.
Third, Article 15 creates a potentially broad notification obligation. It applies wherever a weakness or condition in the financial reporting process may endanger the provider’s business continuity, and the elucidation confirms that such a weakness can exist even absent a material misstatement. Providers should therefore establish a documented escalation and assessment process to identify potentially reportable matters, gauge their significance and support consistent notification to OJK.
Fourth, the transitional provisions warrant careful treatment. For providers licensed before promulgation, the specified internal-control and anti-fraud requirements would apply no later than one year after promulgation, while the administrative fine provisions are intended to take effect two years after the regulation comes into force. The current wording of Article 19 is incomplete, however, and the precise scope and operation of that two-year period will need to be confirmed in the final regulation.
As this remains a consultation draft, there is scope to seek clarification on several points. Relevant stakeholders may use the consultation period to submit comments, suggestions and practical perspectives to OJK on the proposed requirements. This is an important opportunity to identify ambiguities, implementation challenges and areas requiring further clarification before the Draft POJK is finalized.
In the meantime, IAKD Providers should begin mapping the proposed requirements against their governance arrangements, financial reporting systems, internal-control documentation, fraud-prevention responsibilities and regulatory escalation protocols, while preserving flexibility to adjust for changes in the final POJK.
By Partners Ayik C. Gunadi (agunadi@abnrlaw.com), Monic Devina (mdevina@abnrlaw.com), Meitiara Bakrie (dbakrie@abnrlaw.com), and associate Beverly Laza (blaza@abnrlaw.com)
This ABNR client alert is intended solely to provide a general overview, for informational purposes, of selected recent developments in Indonesian law. It does not constitute legal advice and should not be relied upon as such. ABNR accepts no liability of any kind in respect of any statement, opinion, view, error or omission that may be contained in this update. You are strongly advised to consult a licensed Indonesian legal practitioner before taking any action that could affect your rights and obligations under Indonesian law.

