Operating a digital-asset custody business without the correct regulatory authorisation exposes the venture to enforcement action, frozen payment rails and the permanent loss of banking relationships. As regulators across the leading hubs converge on a common expectation – that anyone holding client crypto assets on a custodial basis must be authorised before they accept a single satoshi – the gap between "we have a company" and "we have a licence" is becoming an existential risk. This page maps where those legal lines fall, across the regimes that matter most to operators building at scale.
Digital-asset custody licensing is the formal authorisation – whether called a VASP registration, a CASP authorisation (crypto-asset service provider, the MiCA term), or a standalone custody permit – that a regulator requires before a firm holds, safeguards or controls virtual assets on behalf of clients. The obligation is not hypothetical. Under MiCA, the EU's directly applicable regulation supervised by ESMA and national competent authorities, custody is a defined, standalone regulated activity. VARA in Dubai, the FSRA in Abu Dhabi's ADGM, the MAS in Singapore, the SFC in Hong Kong and the FCA in the United Kingdom each impose their own version of the same core demand: show authorisation, or stop.
What follows is a cross-border analysis of how each major regime draws the line, what operators most commonly get wrong, and how to build a custody stack that holds up under regulatory scrutiny in more than one jurisdiction at once.
What Does "Custody" Actually Mean Under Digital-Asset Law?
Custody of a digital asset is legally triggered the moment a firm controls private keys – or controls the mechanisms that control private keys – on behalf of a third party. That definition is broader than most operators expect. A firm that holds keys in a multi-signature arrangement where the client cannot unilaterally move funds without the firm's co-signature is almost certainly providing custody as a regulated activity, regardless of what the agreement calls it. The label "co-management" or "technology service" does not change the substance. Regulators in the leading hubs increasingly apply a substance-over-label analysis, and the question they ask is simple: can the firm move the assets without the client's involvement?
Under the MiCA regime, the provision of custody and administration of crypto-assets on behalf of clients is listed as a distinct CASP service requiring separate authorisation. The FSRA in ADGM applies an analogous framework: holding or controlling digital assets for others is a regulated activity that requires a specific permission. VARA in Dubai takes an activity-based approach – custody sits as one of the defined licence categories in the VARA rulebooks, separate from advisory, exchange, lending and transfer activities. The practical consequence is that a firm with a VARA exchange licence is not automatically authorised to provide custody; it must hold the custody licence too.
This is one of the most consistently misunderstood points in our cross-border practice. An operator building a combined exchange and custody offering frequently applies for the exchange licence and overlooks the custody authorisation, only discovering the gap when a regulator queries the safeguarding arrangements during a supervision visit. The cost of fixing the gap after the fact – including the reputational signal it sends – is materially higher than building the right licence stack from the start.
How Do the Leading Regimes Trigger the Custody Obligation?
Each major jurisdiction applies a materially different trigger for when custody becomes a regulated activity, and the differences create real compliance exposure for businesses operating across more than one of them simultaneously.
In the EU under MiCA, the CASP authorisation for custody is required in the member state where the applicant is established, and once granted it may be passported across the EU and EEA. Passporting under MiCA is a significant structural advantage: a CASP authorised in Lithuania or Malta – two historically accessible EU entry points – can serve clients across the bloc without a separate local authorisation in each member state. That said, the passporting notification procedure adds time and administrative steps; it is not instantaneous.
In Dubai, VARA's remit covers the mainland emirate. The DIFC financial free zone operates under its own framework and is outside VARA's direct supervision. A custody business that operates in both Dubai mainland and the DIFC therefore faces dual compliance obligations. This geographic layering is a structural reality that operators often underestimate at the formation stage.
Singapore's MAS regulates custody under the Payment Services Act as a digital payment token (DPT) service activity. The licence tier – standard payment institution or major payment institution – determines the applicable capital and operational requirements, which vary in ways that are material to a custody business's funding model. The MAS regime is considered one of the more demanding in Asia from a due-diligence and fit-and-proper perspective, but it carries significant reputational weight with institutional clients and banking counterparties.
The SFC in Hong Kong has moved to a mandatory VASP licensing regime for virtual-asset trading platforms. Custody, where it is incidental to the platform's operation, falls within the VATP licence scope; standalone custody operations require their own analysis under the applicable SFC requirements. Hong Kong's regime is still maturing post-implementation, and operators entering now are navigating an environment where supervisory expectations are actively being communicated through guidance and early enforcement signals.
The FCA in the United Kingdom requires cryptoasset businesses – including custody providers – to register under the Money Laundering Regulations. The UK regime does not yet offer a full CASP-equivalent authorisation; the register is primarily an AML/CFT control. That may change as the UK's post-MiCA domestic regime develops, but in the interim a UK-registered crypto custody business is not passportable into the EU and cannot rely on its UK registration as an EU market-access tool.
Why Cross-Border Custody Is a Structural Legal Problem
A custody business headquartered in one jurisdiction but holding assets for clients domiciled across several others faces a regulatory exposure that no single licence resolves. The question is not only "where is the entity?" but also "where are the clients?", "where is the key infrastructure?", and "where is the beneficial owner of the business?"
Each of those questions maps to a different jurisdiction's assertion of regulatory authority. ESMA and the NCAs under MiCA apply the regime to services provided to EU-resident clients, irrespective of where the service provider is established. VARA applies its authorisation requirement to businesses operating in or from Dubai. The MAS applies Singaporean regulatory requirements to entities conducting regulated activities with or through Singapore. The extraterritorial reach of these regimes, taken together, means that a custody provider with a client book that spans the EU, the Gulf and Asia may need authorisations in three or more jurisdictions simultaneously.
In our practice, we regularly advise operators who have initially built on a single offshore registration – typically in a lighter-touch jurisdiction – with an assumption that it provides sufficient global cover. It does not. A VASP registration in the BVI or a CIMA-registered fund in the Cayman Islands addresses those jurisdictions' domestic requirements. It does not authorise the provision of custody services to EU retail clients under MiCA, nor does it satisfy VARA's licensing requirement for Dubai-facing operations. The AUDIENCE_MYTH that a single offshore licence suffices for global service delivery is one of the most commercially consequential misconceptions we encounter.
The FATF Recommendation 15 framework – which underpins the virtual asset regulatory regimes of FATF member jurisdictions worldwide – establishes the baseline: jurisdictions should require VASPs to be licensed or registered and should supervise them for AML/CFT compliance. The Travel Rule, the obligation to pass originator and beneficiary data with a transfer, extends this into custody operations that also execute transfers. A custody business that moves assets on client instruction must have a Travel Rule compliance programme in place. The data threshold at which the Travel Rule is triggered varies by jurisdiction; operators should confirm the applicable threshold in each market they serve.
Contact OBOLUS at info@oboluslaw.com to scope the licensing map your custody structure actually requires. The standard path above describes the common architecture; your entity, your client geographies and your key management model will change the analysis materially. Map your options.
What Do Regulators Require of a Custody Applicant?
Custody authorisation applications across the leading regimes share a common core of requirements, even where the specific thresholds and processes differ: demonstrated capital adequacy, a fit-and-proper senior management team, a documented custody and key management framework, AML/CFT policies and procedures, and evidence of operational substance in the licensing jurisdiction.
Capital adequacy requirements for custody activities vary by licence category and jurisdiction. Under MiCA, own-funds requirements are differentiated by service type and, in some cases, by the volume of assets held under custody. The FSRA in ADGM and VARA in Dubai each publish their own capital expectations in the relevant rulebooks; those figures are set by the regulator and should be confirmed directly from current official publications before any application is committed. What can be said with confidence is that the capital requirements for custody are generally higher than for lighter-touch VASP activities, reflecting the systemic risk that flows from holding client assets.
Key management infrastructure documentation is a particular point of regulatory scrutiny. Regulators increasingly expect applicants to demonstrate not just that they use cold storage or HSM (hardware security module) arrangements, but that the governance of those arrangements – who authorises a key ceremony, what happens on the death or incapacity of a key holder, how keys are backed up and how that backup is secured – is formally documented and independently auditable. This level of operational detail is frequently absent from first-draft applications.
Substance requirements have tightened materially across the board. A mailbox in the licensing jurisdiction with a single director who attends the jurisdiction quarterly will not satisfy most leading regulators. The MAS, the SFC, VARA and the FSRA each apply a version of the real-presence test: the risk-management function, the compliance officer and, in most cases, the chief executive or equivalent must be genuinely based in or operationally connected to the jurisdiction. For businesses building from a hub model – a primary licence in one jurisdiction with operational teams distributed globally – this creates a genuine staffing and governance design question.
Which Custody Licence Profile Fits Which Operator?
The right licensing jurisdiction for a digital-asset custody business is not a single answer. It depends on the operator's client profile, institutional counterparty relationships, banking requirements and regulatory risk tolerance. The following decision matrix maps the main profiles we see in practice.
An institutional custody provider serving EU asset managers and family offices as primary clients will almost certainly need a CASP authorisation under MiCA, most likely through a member state that offers a well-developed supervisory pathway and good banking access. The passporting benefit is the key structural advantage: one authorisation, EU-wide reach. The timeline and capital commitment are material, and the compliance infrastructure requirements are substantial. This is the high-cost, high-credibility path – and for institutional clients regulated within the EU, it is frequently non-negotiable.
A custody provider primarily serving professional counterparties in the Gulf – family offices, sovereign-adjacent funds, regional exchanges – will likely need a VARA custody licence for Dubai-facing operations and may need to consider an FSRA permission in ADGM for Abu Dhabi-connected business. The AIFC/AFSA in Kazakhstan offers an additional common-law hub option for operators with a Central Asian or Russian-speaking client base. These Gulf and central-Asian regimes move at different paces and require different operational footprints; they are not interchangeable.
A custody provider targeting Asian institutional clients will typically prioritise Singapore (MAS) or Hong Kong (SFC) as the primary licensing anchor. The MAS DPT regime is considered the more mature; the SFC's VATP framework is newer and still accumulating supervisory practice. Japan's FSA/JVCEA framework is relevant for yen-denominated or Japanese-client-facing operations.
For a custody operation focused on the offshore fund and SPV market – Cayman funds, BVI structures, foundations – the relevant registrations are CIMA in Cayman and the BVI FSC under the VASP Act 2022. These registrations provide domestic regulatory cover for those structures but do not passport into the EU, the UK or the major Asian hubs. They are typically one layer of a multi-jurisdictional stack, not the only layer.
What Are the Most Common Mistakes in Custody Licence Applications?
Application failure in custody licensing is rarely about a single fatal flaw; it is almost always about an accumulation of avoidable gaps. The following are the errors we encounter most consistently.
The first and most common is mischaracterising the activity. Firms that describe their service as "technology" or "infrastructure" rather than custody frequently trigger a regulator's substance-over-label analysis at the screening stage. If the firm controls keys, the regulator will say so. It is far better to characterise the service accurately in the application and address the licensing requirements head-on than to argue for an exemption that the regulatory framework does not actually support.
The second is inadequate governance documentation. Applications that arrive with a draft AML policy downloaded from a compliance vendor and a key management section that consists of a single paragraph describing cold-storage intentions are not competitive. Regulators want evidence of a functioning governance framework, not a plan to build one. Substance in the application – board minutes, committee terms of reference, a documented incident response procedure – signals operational maturity.
Third is the capital-timing problem. Several regimes require the applicant to demonstrate that the required capital is in place, or irrevocably committed, at the point of application rather than contingent on approval. Operators who plan to raise the required capital after approval is granted find themselves in a structural mismatch. Capital structure should be resolved before the application is submitted.
Fourth is the banking gap. A custody licence without a compliant banking relationship to support fiat settlement, fee collection and operational accounts is operationally incomplete. Many applicants treat banking as a post-licence problem. In our experience, banking access should be pursued in parallel with the licence process, because a licence without a bank account does not generate revenue. The banking and licence timelines should be run concurrently.
In a recent matter, a digital-asset custody platform approached us after a first licence application in a leading EU member state had stalled at the capital adequacy review. We identified that the applicant had commingled operating funds and the designated regulatory capital in the same account, which the reviewing authority had flagged as evidence that the capital was not genuinely dedicated. We restructured the capital allocation, produced the necessary documentation demonstrating segregation, and the application progressed to the next stage within weeks. The issue was fixable; identifying it early was what mattered.
If a prior custody licence application stalled or a banking relationship was closed, a second read of the structural position frequently surfaces the reason and the route forward. Contact OBOLUS at info@oboluslaw.com to discuss. Map your options.
A Common Assumption: One Licence Is Enough
A common assumption among early-stage custody operators is that a single, well-chosen licence provides sufficient global cover to begin commercial operations. That assumption has a surface logic – it minimises cost and complexity at launch – but it creates significant legal exposure at scale.
The EU's MiCA regime applies to anyone offering custody to EU-resident clients, regardless of where the custodian is established. Operating custody services for EU retail or professional clients without a CASP authorisation is a direct breach of MiCA's requirements, enforceable by the relevant NCA against the operator regardless of the operator's domicile. ESMA has been explicit in its guidance that the "same activity, same risk, same rule" principle extends across borders. A Cayman or BVI registration does not disapply the EU's market-access rules to EU-facing custody operations.
Similarly, the MAS in Singapore and the SFC in Hong Kong apply their licensing requirements to services provided to their respective domestic markets. An operator based in the EU providing custody services to Singapore-domiciled clients without MAS authorisation is conducting an unlicensed regulated activity in Singapore. The cross-border exposure runs in both directions: inbound clients from a regulated jurisdiction expose the custodian to that jurisdiction's rules, and the custodian's own location may attract additional requirements from its home regulator.
The practical answer is not to obtain a licence in every jurisdiction from day one – that is neither commercially rational nor operationally feasible. The answer is to map the client book, the operating entity, the key infrastructure and the banking against the applicable regulatory perimeters, and to build a licensing roadmap that sequences the authorisations in order of risk and commercial priority. That mapping is the first service we provide to custody operators entering the licensing process.
How Does the Travel Rule Interact with Custody Operations?
The Travel Rule – the obligation, derived from the FATF framework and implemented in jurisdiction-specific form across MiCA, the MAS regime, the SFC framework and most other leading regimes, to pass originator and beneficiary data alongside a virtual-asset transfer – applies directly to custody operations that also execute or instruct transfers.
A custody provider that holds assets and then moves them on client instruction is both a custodian and, in that movement, a transfer-executing VASP. The Travel Rule compliance obligations attach to the transfer function. The firm must collect and transmit the required originator and beneficiary information, verify the identity of the counterpart VASP where one exists, and maintain records in the manner the applicable regime requires. The precise data fields, the de-minimis threshold below which the rule does not apply, and the technical protocol requirements (IVMS-101 is the common data standard) vary by jurisdiction and should be confirmed from current regulatory guidance.
For custody operators building a multi-jurisdictional compliance programme, the Travel Rule creates a harmonisation challenge. The MiCA version of the rule, the MAS version and the FCA's UK version are aligned in principle but differ in detail. A single compliance procedure calibrated to the strictest common denominator is operationally simpler than a jurisdiction-by-jurisdiction patchwork, but requires more upfront investment. We have seen operators who built to the patchwork model incur substantially higher remediation costs when they subsequently needed to harmonise for a primary market authorisation.
Related at OBOLUS
- Licensing and registration for digital-asset businesses – the full-practice overview covering VASP, CASP and related authorisations across 70+ jurisdictions.
- Crypto exchange setup in Canada – FINTRAC registration, MSB requirements and the exchange-to-custody overlap under Canadian law.
- Enforcement of foreign judgment in Liechtenstein – cross-border enforcement options for custody disputes with a Liechtenstein nexus.
FAQ
How long does a crypto licence take to obtain?
Authorisation timelines vary materially by jurisdiction and licence type. In the EU under MiCA, CASP authorisation timelines are set by the regulation but the practical duration – including pre-application engagement and remediation rounds – typically extends beyond the statutory window. In Singapore, the MAS process is known for thoroughness and takes a significant number of months for a first-time applicant. VARA in Dubai and the FSRA in ADGM operate at their own pace. As a working assumption, a serious custody application in any leading hub should be planned on a timeline measured in months, not weeks. Engage early; the application clock does not run until the file is materially complete.
Which jurisdiction is best for licensing my crypto business?
There is no universally "best" jurisdiction. The right answer depends on your client base, your intended business model, your banking requirements and your operational footprint. An EU-facing custody business needs MiCA coverage. A Gulf-facing business needs VARA or FSRA consideration. A business targeting institutional clients across multiple regions may need two or three licences in sequence. The correct analysis starts with where your clients are and what rights you need to serve them – not with which jurisdiction is currently fastest or cheapest to enter.
Do I need a separate custody licence?
In most leading jurisdictions, custody is a standalone regulated activity that requires its own authorisation or permission. Under MiCA, custody is a distinct CASP service category. Under VARA, it is a separate licence activity. Under the MAS framework, holding or controlling DPTs for clients is a regulated activity in its own right. Holding an exchange or broker-dealer licence does not automatically cover custody in these regimes. If your business holds keys or controls access to client assets – even as an ancillary feature of another service – the custody authorisation question must be addressed explicitly.
About OBOLUS
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across more than 70 jurisdictions, on disputes and on-chain asset recovery across more than 25 forums, and on the tax, banking and compliance obligations that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit – and where disputes arise, we work alongside forensic partners to convert on-chain evidence into court-ready disclosure applications. To discuss your custody licensing structure, contact info@oboluslaw.com or message us at t.me/oboluslaw.
By Glen Sorensen, Disputes & Recovery Analyst – specialist in cross-border digital-asset custody enforcement, VASP regulatory exposure and multi-jurisdictional licensing risk across the leading crypto hubs.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.