EST · MMXXVI
Home/Clients/Legal Counsel for Digital-Asset Custodians
Licensing & Registration

Legal Counsel for Digital-Asset Custodians

Legal Counsel for Digital-Asset Custodians. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

A digital-asset custodian (a business that holds, safeguards, or controls cryptographic keys on behalf of clients) sits at the intersection of financial regulation, technology law, and cross-border compliance in a way that few other business models do. The regulated perimeter for custody is drawn differently in every major licensing hub – what qualifies as a regulated custody activity under MiCA in the European Union does not map identically onto the VARA rulebooks in Dubai or the Payment Services Act in Singapore. Getting that perimeter wrong at the formation stage costs multiples of the legal fee to fix once clients are onboarded and regulators are watching. This page maps the legal lifecycle for a custodian: from entity formation and licence selection, through ongoing compliance and banking, to the disputes and recovery exposure that makes custody a uniquely high-stakes model.

What Is the Regulated Perimeter for Digital-Asset Custody?

Custody of digital assets is a regulated activity in every major licensing jurisdiction, and the threshold for triggering that regulation is lower than most founders expect. A common assumption is that holding client keys is a purely technical question – a software decision about wallet architecture. That assumption is wrong, and it is the most expensive myth in this sector. Whether you hold private keys on behalf of others, whether you have the technical ability to transfer assets without a separate client instruction, and whether you co-mingle keys in a pooled architecture are all legal questions before they are engineering ones. The answer determines which licence category applies, what capital you must hold, and what segregation and safeguarding obligations attach.

Under MiCA, the provision of custody and administration of crypto-assets on behalf of clients is a named CASP (Crypto-Asset Service Provider) activity. An entity authorised in one EU member state may passport that authorisation across the EEA – a structural advantage that makes the choice of home member state a strategic decision, not just an administrative one. The regime imposes specific safeguarding expectations: client assets must be segregated from the custodian's own assets, and the custodian bears strict liability for loss in most circumstances. Those obligations were drafted with institutional-grade custody in mind, and they have direct implications for insurance programme design and contractual allocation of risk.

In Dubai, VARA operates an activity-based licensing model. Custody and transfer/settlement are separate licence activities under the VARA rulebooks, and an operator that provides both must hold authorisation for both. The VARA regime applies to mainland Dubai; operators in the DIFC financial free zone operate under a different regulatory perimeter. We regularly advise custodians on which geographic scope their client base actually requires and on whether a dual-hub structure – mainland plus free zone – is commercially justified given the associated compliance overhead.

Singapore's MAS, operating under the Payment Services Act, treats digital payment token services as a regulated activity across three licence tiers. A custodian whose activity falls within the DPT service definition must hold the appropriate tier of payment institution licence. The licence tier determines both the capital obligation and the transaction-volume ceiling. An operator that starts at the lower tier and grows into the upper threshold without applying for an upgrade faces a compliance breach – a scenario we have seen more than once in our practice with clients scaling faster than their licence architecture anticipated.

The process above describes the standard path. Your facts – the entity structure, the jurisdictions your clients sit in, and the key-management architecture – change the analysis materially. For a scoped assessment of your custody model, contact OBOLUS at info@oboluslaw.com.

Which Licence Do You Actually Need?

The right licence is determined by three axes: what you do technically, where your clients are, and where you want your regulatory relationship to sit. These three axes rarely point to the same jurisdiction, and the divergence is where most structuring work happens. In our cross-border practice, the custodians that encounter the most friction are those that selected a jurisdiction for tax reasons alone and then discovered that the chosen regime either does not recognise their activity category or imposes capital requirements their business model cannot support at the seed stage.

A custodian holding assets for EU-resident retail clients needs EU-accessible authorisation. A MiCA CASP authorisation issued by a member-state NCA and passported across the EEA is the most direct route, but the home-state selection matters: supervisor expectations, processing timelines, and the practical depth of the authorisation review vary across member states. Lithuania, historically a faster EU entry point, is now aligning to the full CASP standard under MiCA, which adds both rigour and timeline. Malta's MFSA is transitioning its prior VFA framework to MiCA, and operators with existing VFA authorisations face a defined transition window.

For a custodian focused on institutional clients in the Gulf, ADGM (through its regulator, the FSRA) and VARA in Dubai represent the two principal options. ADGM operates under a common-law framework within the AIFC model and maintains a "recognised virtual assets" concept that determines which assets a licensed custodian may hold. VARA's activity-based model is more granular on the custody-versus-transfer distinction. A custodian offering settlement services alongside custody will need to map each activity to its corresponding VARA licence category before applying.

In Hong Kong, the SFC operates a VASP licensing regime for virtual-asset trading platforms, but a standalone custodian must assess whether its activity falls within that perimeter or requires a separate licensing analysis. The SFC has issued guidance on the custody of client assets by licensed platforms, and those expectations increasingly inform market-practice standards even for operators not yet required to hold a VATP licence.

The BVI and Cayman Islands each maintain VASP registration or licensing regimes under their respective acts. These offshore regimes are relevant for fund-custody structures and for entities in a broader group where the operational custodian sits in a licensing hub and a holding or fund-vehicle entity sits offshore. Structuring that relationship correctly – so that the offshore entity does not inadvertently trigger regulated-activity analysis in the licensing hub – is a recurring element of the formation work we do for custodian clients.

How Should a Custody Business Be Structured at Formation?

The entity structure for a digital-asset custodian should be set before the first client key is held, because retroactive restructuring of a live custody business is both costly and operationally disruptive. The core question is whether the regulated custodian – the licensed entity that holds client assets and bears the regulatory obligations – is the same entity as the technology operator, the fee-recipient, and the group parent. In most well-structured custody businesses, the answer is no.

Separating the regulated entity from the technology layer serves three purposes. First, it isolates regulatory capital and balance-sheet obligations inside the licensed perimeter without encumbering the broader group. Second, it creates a clean contractual relationship between the custodian and the technology provider – a relationship that regulators in every major hub will review as part of the authorisation process. Third, it gives the group flexibility to re-domicile the technology entity if the licensing jurisdiction changes, without disturbing the custody authorisation.

The tax dimension of that separation is not secondary. Where the custodian earns custody fees, where the technology entity earns service fees, and how those flows interact with transfer-pricing rules across the group's jurisdictions can determine whether the structure is sustainable at scale. We separate the regulated custody perimeter from the technical one before you build – that principle applies equally to the legal architecture and the tax architecture.

Banking is the third formation variable. A licensed custodian needs banking relationships that are compatible with its activity, its client base, and the currencies it handles. Banks in most jurisdictions apply enhanced due diligence to digital-asset custodians. The licensing documentation, the AML programme, and the governance structure that a custodian presents at account-opening are the same materials it will present to its regulator. Getting the compliance architecture right at formation serves both audiences simultaneously.

What AML and Travel Rule Obligations Apply to a Custodian?

Digital-asset custodians are virtual asset service providers (VASPs) for FATF purposes, and FATF Recommendation 15 applies the full AML/CFT framework to them, including the Travel Rule – the obligation to pass originator and beneficiary data alongside each transfer above the applicable threshold. The Travel Rule is the compliance obligation that most frequently surprises custodians scaling their transfer volumes, because the technical implementation requires either a proprietary Travel Rule solution or an established VASP-to-VASP messaging protocol.

The applicable threshold for Travel Rule data transmission varies by jurisdiction – a fact that creates immediate cross-border complexity for a custodian transferring assets between clients in different regulatory perimeters. A transfer that falls below the de-minimis threshold in the sending jurisdiction may exceed it in the receiving jurisdiction. The safer operational posture, and the one most regulators in the leading hubs now expect, is to apply the lower of the two applicable thresholds for any cross-border transfer.

The AML programme itself – the policies, the customer due diligence standard, the transaction monitoring framework, and the suspicious activity reporting process – is reviewed as part of every authorisation process we have managed. Regulators do not treat the AML programme as a compliance checkbox. They treat it as evidence of the management team's understanding of the risk they are managing. A programme that is clearly templated and not tailored to the custodian's specific client profile, asset classes, and geographic reach will slow an authorisation and, in some hubs, result in a direct request for resubmission.

Operators we advise routinely underestimate the ongoing AML obligation. Authorisation is a starting point, not a conclusion. Annual AML audits, periodic CDD refresh cycles, and the obligation to monitor and update the risk assessment as the client base changes are all ongoing requirements in every major regime. A custodian that treats the AML programme as a formation document rather than a living operational framework will face regulatory friction at the first supervisory review.

How Do Capital Requirements and Insurance Interact for a Custodian?

Custody rules differ sharply by jurisdiction, and that divergence drives both licensing cost and insurance cost – two variables that a custodian's CFO needs to model before the business launches. Capital requirements for a custody CASP under MiCA are set by reference to the licence category and the scale of assets under custody; the regime also permits the use of professional indemnity insurance as a partial substitute for own-funds capital in certain circumstances. That optionality has direct implications for capital-efficiency planning.

The insurance market for digital-asset custody is specialised and limited. Premiums are driven by the custody architecture – cold storage, MPC (multi-party computation) wallet schemes, HSM-based key management – as well as the jurisdiction of the custodian, the asset classes held, and the concentration of assets under any single key or signing quorum. A custodian that has not documented its technical architecture in a form that an insurer's underwriting team can assess will find that the underwriting process extends materially, which in turn delays the launch timeline.

We regularly advise on the interface between the regulatory capital obligation and the insurance programme, including on the contractual language in the custodian's client agreements that allocates liability for loss events. That allocation – how much the custodian bears, how much the insurer covers, and how much passes through to the client in defined circumstances – is a negotiated commercial question. But it is constrained by the strict liability framework that MiCA and comparable regimes impose. A contractual limitation of liability that conflicts with the regulatory framework is unenforceable, and drafting it correctly requires understanding both layers simultaneously.

What Disputes Exposure Does a Custodian Face?

A digital-asset custodian is a natural defendant in two categories of dispute: client claims for losses arising from custody failures, and third-party claims seeking recovery of assets alleged to have been misappropriated and deposited into the custodian's platform. Both categories require a distinct legal response, and the response window in the second category is measured in hours rather than days.

For client loss claims, the central question is whether the loss arose from a breach of the custodian's duty of care, from a covered event under the insurance programme, or from an event that the contract allocates to the client. In practice, the three analyses overlap. We have seen matters where a technically valid contractual limitation failed to engage because the custodian's conduct during the loss event took it outside the contractual scope of the limitation. Getting that analysis right before a claim is filed – in the contract drafting and in the incident-response protocol – is the work that limits exposure.

For third-party recovery actions, the primary tools in the leading common-law forums are worldwide freezing orders (injunctions freezing a defendant's assets globally) and Norwich Pharmacal orders (orders requiring a platform to disclose the identity and transaction history of an account holder). England and Wales remains the leading forum for these remedies in the digital-asset context. The DIFC Courts in Dubai have issued freezing and disclosure orders in support of both local and foreign proceedings, and Singapore and Hong Kong both maintain strong proprietary-relief frameworks for crypto assets.

In a recent recovery matter, a financial services operator discovered that misappropriated stablecoins had been deposited at a custodian in a second jurisdiction. We coordinated a disclosure application and a parallel freezing request across two common-law forums, working with allied counsel in the relevant jurisdiction, and the balance was frozen before the counterparty could complete a further transfer. Speed of instruction and clarity of the forensic chain – the transaction hashes, the wallet addresses, and the on-chain tracing report – were the variables that determined the outcome.

Our disputes team coordinates freezing relief and on-chain tracing across leading common-law forums, and we treat the recovery clock as a constraint rather than a background consideration. If a recovery clock is running, reach our disputes desk now at info@oboluslaw.com.

Decision Matrix: Legal Priorities by Stage of a Custody Business

Not every custodian faces every legal question at the same time. The legal priorities shift materially across the lifecycle of the business, and a counsel engagement that focuses on the wrong stage creates both cost and delay. The following matrix maps the principal legal work by operator profile and stage.

Profile A – Pre-launch custodian, institutional client focus, Gulf or Asia hub. The immediate priority is structure: entity formation, the regulated/technical entity split, and the correct licence category in the target hub. Banking due diligence should begin in parallel with the licence application, not after it. The AML programme should be drafted for the regulatory submission, not as a post-authorisation exercise. Timeline to operational licence in a well-managed application in a Gulf or Asia hub is typically a matter of months, not years, but the quality of the submission documentation is the primary variable. Key risk: selecting a hub based on perceived speed, then discovering that the applicable capital requirement is not supportable at the current funding stage.

Profile B – Operating custodian, EU expansion, MiCA authorisation required. The primary work is the CASP authorisation application – specifically, the selection of home member state, the preparation of the organisational and governance documentation, and the alignment of the existing AML programme to the CASP standard. For a custodian that already holds a registration in a transitioning jurisdiction (Malta's VFA framework, for example), the transition mechanics require early attention. Passporting strategy should be agreed before authorisation is obtained, because the home-state selection determines which NCAs will be notified. Key risk: treating the MiCA transition as a routine renewal when the substantive CASP requirements represent a material step-up from the prior registration standard.

Profile C – Custodian facing a regulatory inquiry or client claim. The immediate priority is engagement with counsel who understands both the regulatory framework and the dispute mechanics simultaneously. A custodian responding to a supervisory inquiry cannot adopt a litigation posture toward the regulator; a custodian defending a client claim cannot make admissions in the regulatory response that create liability in the civil proceeding. Managing the two tracks in parallel, with a consistent factual narrative and differentiated legal strategies, is the work that preserves optionality. Key risk: instructing separate counsel for the regulatory and litigation tracks without a coordinating layer, resulting in inconsistent positions that damage both proceedings.

A Common Assumption: Licensing Can Wait Until Scale

A common assumption among early-stage custodians is that regulatory authorisation is a problem to address once the business has demonstrated product-market fit. The assumption rests on the belief that regulators will accommodate a compliant retrofit. In practice, the leading jurisdictions do not. Operating a custody service without the required authorisation is not a tolerated grey zone – it is a breach of the applicable regime, and the consequences in most major hubs include disgorgement of revenues, civil penalties, and in some jurisdictions criminal exposure for directors.

The more practical version of this risk is subtler. A custodian that raises a Series A and attempts to obtain a licence at scale discovers that the due-diligence process an institutional investor runs on the licence status creates a completion risk for the round. We have seen licensing questions become deal terms in funding rounds where the investors' counsel identifies a gap between the custodian's actual activity and its regulatory authorisation. Addressing that gap after the term sheet is signed is more expensive and more pressured than addressing it at formation. The legal cost of a well-structured launch is a fraction of the legal cost of a regulatory remediation at growth stage.

To pressure-test your custody structure before you commit, message us via t.me/oboluslaw.

Related at OBOLUS

FAQ

How long does a crypto licence take to obtain?

Timeline varies by jurisdiction, licence category, and the quality of the application submitted. In well-prepared applications at the major hubs, the process typically runs from a matter of weeks for a straightforward registration to several months for a full authorisation under a regime like MiCA or VARA. The single largest driver of delay is incomplete or non-tailored documentation – particularly the AML programme and the governance and organisational structure submissions. A realistic timeline assessment should be built into the business plan before the application is filed, not after.

Which jurisdiction is best for licensing my crypto business?

There is no universal answer. The right jurisdiction turns on the client base (where your clients are determines which regimes you must be accessible under), the activity (custody, exchange, brokerage, and lending attract different licence categories), the capital available, and the banking relationships accessible from the chosen hub. A custodian serving EU retail clients needs EU-accessible authorisation. A custodian serving Gulf institutional clients will look to VARA or ADGM. We assess these axes together before recommending a jurisdiction, not in isolation.

Do I need a separate custody licence?

In most major regimes, custody is a distinct regulated activity that requires its own authorisation or a specific activity endorsement on an existing licence. Under MiCA, custody and administration of crypto-assets on behalf of clients is a named CASP activity. Under VARA, custody and transfer/settlement are separate licence activities. A custodian that also operates a trading platform, provides lending, or offers staking services will typically need to map each activity to its corresponding authorisation category. Operating without the required custody authorisation is a regulatory breach regardless of what other licences the entity holds.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise custodians, exchanges, token issuers, and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking, and compliance that surround them. Digital assets are the whole of our practice. We separate the regulated custody perimeter from the technical one before you build – and when a dispute or regulatory inquiry follows, our disputes team coordinates freezing relief and on-chain tracing across leading common-law forums. To discuss your situation, contact info@oboluslaw.com.

By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in cross-border VASP authorisation strategy and regulatory structure for digital-asset custody and exchange businesses.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours