Arlo Devlin-Brown on Corporate Compliance and Digital Asset Enforcement

July 7, 2026
55
CRYPTOMEGAPHONE IN YOUR SOCIAL FEED

Arlo Devlin-Brown is a former federal prosecutor who served for more than a decade in the U.S. Attorney’s Office for the Southern District of New York, where he investigated and prosecuted complex financial fraud and corporate misconduct. After serving as a Partner at Covington & Burling LLP, he co-founded Treanor Devlin Brown PLLC, a litigation boutique that advises companies and individuals in emerging technologies, with a particular focus on blockchain and digital assets. Drawing on his experience prosecuting complex financial crimes and representing clients in some of the most prominent blockchain-related enforcement matters in private practice, he brings a unique perspective to the rapidly evolving regulatory and enforcement landscape surrounding digital assets.

In this interview with CryptoMegaphone, Devlin-Brown discusses how enforcement authorities distinguish isolated compliance failures from broader institutional problems, the role of corporate culture in regulatory investigations, the evolution of digital asset enforcement priorities, and the governance standards that will shape the industry’s long-term institutional maturity.

Throughout your career, you have worked on complex investigations involving financial misconduct and corporate wrongdoing. When enforcement authorities first begin examining an organization, what indicators typically suggest a deeper institutional problem rather than an isolated compliance failure?

Several signals tend to emerge in the course of an investigation that point to something deeper than a one-off lapse. The first is simply scope: the more instances of the problem, and the more widely they are spread across the organization, the harder it is to characterize the conduct as isolated. The second is seniority. When the people involved sit near the top, it suggests the conduct was sanctioned, or at least tolerated, rather than the work of a few employees acting on their own.

But the indicator prosecutors weigh most heavily is tone from the top. They are really trying to assess the culture of the organization. Is the compliance function adequately resourced, or is it an afterthought? When employees raise concerns, are those concerns taken seriously and run to ground, or are they brushed aside and the people who raised them quietly sidelined? Those cultural signals, including what leadership says and how it behaves, often tell the government more about the health of an organization than any single transaction does.

As digital asset regulation continues to evolve in the United States and internationally, which categories of conduct do you believe are most likely to remain enforcement priorities regardless of how regulatory frameworks develop?

The current administration is plainly friendlier to digital assets than its predecessor, and the regulatory posture will continue to shift from one administration to the next. The constant across all of them is fraud. The core mission of regulators and prosecutors in this space is to keep people from getting ripped off. So where a project promises things it cannot deliver, or where promoters make claims they know to be false in order to attract customer money, you will see enforcement actions and prosecutions regardless of which party holds the White House. A friendlier tone about the industry in general does not change the government’s appetite for pursuing outright deception.

Many firms invest heavily in written compliance policies and internal controls. From an investigative perspective, what distinguishes a compliance program that exists primarily on paper from one that genuinely reduces regulatory and enforcement risk?

This comes up constantly. Companies come to counsel asking us to build out a robust set of written compliance policies, which they see as prophylactic—a kind of insurance against future trouble. My advice is usually that the only thing worse than having no written policies is having written policies you do not actually follow. Once you commit a set of practices and procedures to paper, you have set the standard you will be measured against. So you had better be able to show that the policies are followed in practice, that the program is resourced to do what the policy contemplates, and that there are real consequences when the rules are broken. A program that genuinely reduces risk is one where the documents describe what the company actually does, not what it aspires to do.

Institutional participation in digital asset markets has increased substantially in recent years. Which governance, reporting, or control standards do you believe regulators and enforcement authorities will scrutinize most closely as the sector continues to mature?

As institutional participation grows, I expect a sharp focus on whether the assets that are supposed to back a given product actually exist and are properly segregated in custodial accounts. The government does not want another FTX, where assets that were supposed to be held for each customer simply were not there. You can already see that concern reflected in the recent stablecoin legislation and in the market structure debate. As the sector matures, the questions will be straightforward but unforgiving: Are the assets real? Are they where they are supposed to be? Can an independent party verify it?

The “independent party” piece deserves emphasis. Self-reported proof of reserves is not particularly compelling. What regulators and institutional counterparties will increasingly expect is something closer to what traditional finance has long required: genuine third-party attestation by qualified auditors operating under real professional standards, and boards with members who actually understand what they are overseeing.

Organizations often view regulatory examinations, investigations, and enforcement actions as separate processes. In practice, how are these stages connected, and what mistakes most frequently cause routine regulatory concerns to escalate into more serious matters?

Two points. First, sometimes the facts are simply what they are. If the underlying problem is serious enough, it may be referred for investigation no matter how skillfully the regulatory phase is handled, and there is only so much that approach can do about that.

Second, and more within a company’s control, there are unforced errors that turn manageable matters into serious ones. There are two things you should never do with regulators. Do not be dismissive of their concerns, even concerns you do not fully share; engage with them seriously. And never lie to them or obstruct, even on a small point. Regulators are people. If they come to believe something is being hidden from them, even a minor misstatement will make them assume there is a larger problem underneath, and the matter will not go well from there. Many escalations I have seen come less from the original conduct than from how the company handled the people looking into it.

From your experience, what are the most common misconceptions organizations have about how regulators, prosecutors, and enforcement authorities evaluate corporate conduct during an investigation?

The most common misconception is confusing the general enforcement climate with how a specific case will be handled. It may well be true that this administration brings fewer investigations and less scrutiny in the digital asset space than the last one. But the fact that fewer matters are opened cuts the other way once yours is one of them. The decision to open an investigation in a less aggressive environment signals that someone looked at the facts and concluded they warranted attention anyway.

To be fair, there may come a point later in the process, once an investigation has developed and you have genuine arguments that there is nothing to see, where contending that an enforcement action is not warranted given the broader impact on the space can get some resonance. The mistake companies make is reaching for that argument at the very beginning. Raised that early, it tends to go nowhere, and it can actually make things worse by getting the regulators’ backs up. In the end, most of what gets evaluated is your conduct on its own terms, and that is where the defense has to be made.

Looking ahead, what developments would convince you that the digital asset sector has reached a level of governance, transparency, and institutional maturity comparable to other established areas of financial services?

I doubt there will be a single line or milestone, at least not one visible in advance. Maturity of this kind is usually only clear in hindsight, and it arrives as a continuum rather than a moment. What I would look for is steady movement: firms building out real compliance, risk, and custody functions; hiring serious people with genuine backgrounds to run them; giving those people an actual voice within the organization rather than a title; and developing policies and processes and then enforcing them. None of those is the finish line on its own. But as you see more of them, and see them treated as core to the business rather than as overhead, that is the sector growing up.

While there is no single marker, this would be an interesting test: can the industry absorb a serious scandal or criminal conduct at a leading digital asset company without the entire industry being put on trial? Traditional finance has bad actors on a regular basis. Those failures are consequential, but they do not typically call into question whether the asset class itself should exist. Digital assets will have reached comparable maturity when a major fraud or collapse is treated as a failure of the individuals and the firm involved, rather than as evidence that the entire enterprise is illegitimate.