EST · MMXXVI
Home/Insights/Glossary/Digital-Asset Custody: A Legal Guide for Digital-Asset Businesses
Licensing & Registration

Digital-Asset Custody: A Legal Guide for Digital-Asset Businesses

Digital-Asset Custody: A Legal Guide for Digital-Asset Businesses. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring.

What Is Digital-Asset Custody – and Why Does the Legal Definition Matter?

Digital-asset custody is the safeguarding and administration of cryptographic private keys on behalf of another party – a function that, across the major regulatory regimes, is now a regulated activity carrying its own licensing, capital and operational requirements. Businesses that hold, control or administer those keys for clients – even incidentally, as part of a broader exchange or payment service – must map that activity against the applicable regime before they launch. Getting the analysis wrong exposes the entity to enforcement, frozen banking rails and potential civil liability to the clients whose assets were held without the right authorisation.

This guide sets out the regulated basis of custody across the flagship jurisdictions, explains the cross-border complications that arise when the custodian sits in one place and the client sits in another, and identifies the decision points at which a business needs specialist counsel. The cross-border angle matters at every stage: the legal question is never just where your entity is incorporated, but where your clients are, where your keys are held, and where your banking sits.

How Do the Major Regulatory Regimes Define Custody?

Every flagship digital-asset regime now recognises custody as a standalone regulated activity, but the precise perimeter differs – and the difference can determine whether your business needs one licence or three.

Under MiCA (the EU's Markets in Crypto-Assets Regulation), custody and administration of crypto-assets on behalf of clients is a named crypto-asset service. A business seeking to offer that service requires a CASP authorisation (crypto-asset service provider authorisation) from a national competent authority, supervised by ESMA. The authorisation regime applies wherever the client base is located within the EU/EEA, regardless of where the custodian is incorporated outside the bloc. The passporting mechanism allows a CASP authorised in one member state to extend that authorisation across the EU, which is a significant structural advantage for businesses building at scale.

In Dubai, VARA (the Virtual Assets Regulatory Authority) operates an activity-based licensing regime in which custody is a discrete licence category. A business that also operates an exchange or offers lending must hold separate activity-specific licences for each. VARA's regime applies to mainland Dubai; the DIFC financial free zone operates under its own framework administered by the DFSA. Operators building a UAE structure must determine from the outset which perimeter they are in.

In Abu Dhabi, the FSRA (Financial Services Regulatory Authority) within the ADGM administers a virtual-asset framework that includes custody of digital assets as a regulated activity. The FSRA maintains a list of recognised virtual assets; a custodian's permissions are bounded by that list. Businesses seeking to custody a wider range of tokens face a more layered analysis.

Singapore's MAS (Monetary Authority of Singapore) regulates custody of digital payment tokens under the Payment Services Act. The relevant licence tier depends in part on transaction volume and the nature of the tokens held. Hong Kong's SFC (Securities and Futures Commission) has introduced a VASP licensing regime that includes custody functions for virtual-asset trading platforms. In each of these hubs, the regulator's expectation around safeguarding, segregation and operational resilience has become materially more detailed over successive consultation rounds.

The UK's FCA requires cryptoasset businesses to register under the Money Laundering Regulations. Custody businesses must meet the FCA's AML and safeguarding expectations. A broader statutory framework for custody is in legislative development. In the BVI, the VASP Act 2022 administered by the BVI FSC brings custody into a registration regime. In Cayman, CIMA's virtual asset framework similarly captures custody as a regulated function requiring registration or licensing depending on the scope of the activity.

The operational principle across regimes is consistent: custody is not a by-product of another service. It is a standalone regulated activity, and treating it as ancillary is the single most common structural mistake we see in cross-border builds.

For a scoped assessment of your custody and licensing position, contact OBOLUS at info@oboluslaw.com. The analysis above describes the standard regulatory perimeter. Your facts – the entity structure, the token scope, the client geography – change the licensing stack. Map your options.

What Does Custody Regulation Actually Require – Operationally?

Beyond obtaining the licence, a regulated custodian must maintain a set of operational capabilities that regulators now treat as threshold requirements rather than best-practice guidance.

Segregation is the starting point. Client assets must be held separately from the custodian's own assets, and the legal mechanism for achieving that separation – whether by wallet structure, contractual arrangement or a trust-law analysis – is a point regulators scrutinise closely. In our practice, the segregation question often surfaces unexpectedly during a banking due-diligence exercise, because correspondent banks ask to see the custody structure before they will open accounts.

Key management is the second operational pillar. The regime under which a custodian operates typically sets expectations around multi-signature arrangements, cold storage proportions and incident-response procedures. The specific thresholds are set by the relevant regulator and vary; what is consistent is that a custodian that cannot demonstrate a documented key-management policy will not obtain or retain authorisation.

Insurance and capital adequacy sit alongside the operational requirements. Capital requirements vary by licence category and jurisdiction – they are set by each regulator and are subject to revision, so we always advise clients to obtain current figures directly from the regulator or through counsel in the relevant hub. Professional indemnity or crime insurance is expected in the leading regimes, with coverage parameters tied to the value of assets under custody.

AML/CFT obligations apply to custodians across every jurisdiction covered in this guide, including the Travel Rule (the obligation to pass originator and beneficiary data with a virtual-asset transfer) under FATF Recommendation 15. Custodians that receive transfers must screen incoming data; those that initiate transfers must transmit it. Regime-specific de-minimis thresholds apply, but the obligation to have a functioning Travel Rule compliance programme is universal in the flagship hubs.

In a recent advisory matter, a custody-adjacent business had built a wallet infrastructure that gave it transient control over client keys during settlement. The business had classified itself as a technology provider, not a custodian. After regulatory analysis across the relevant regimes, the classification was unsupportable – the key-control fact pattern triggered regulated custody in at least two jurisdictions. We restructured the settlement flow to resolve the issue before a licence application was filed in the primary hub.

How Does a Cross-Border Structure Complicate the Custody Analysis?

A custodian incorporated in one jurisdiction and serving clients in another faces a layered regulatory exposure that a single-jurisdiction licence does not resolve.

The threshold question is jurisdictional nexus. Most regimes assert authority when clients are resident in the jurisdiction, regardless of where the custodian entity sits. A BVI-incorporated custodian serving EU clients falls within the MiCA perimeter for those clients. A Cayman entity marketing to Singapore residents engages the MAS regime. The offshore-entity-only approach – treating incorporation in a lightly regulated hub as a substitute for substantive authorisation in the client's market – is a compliance model that no longer works in the major markets and creates serious enforcement exposure.

The second cross-border complication is banking. Regulated custodians depend on banking infrastructure to onboard clients, settle fiat-leg transactions and manage operational accounts. Banks in the leading financial centres conduct their own regulatory due diligence on custodian counterparties, and a custodian that holds only an offshore registration will typically find that correspondent-banking access is limited or unavailable. We regularly advise clients on structuring the licence stack – operating entity, custody entity, payment processing – across two or three jurisdictions to achieve both regulatory authorisation and banking access simultaneously.

The third complication is the tax treatment of the custody service itself. The tax analysis of a custody arrangement – whether the custodian holds assets as agent or holds a beneficial interest, how fees are characterised, how the arrangement is treated for VAT or GST purposes in the client's jurisdiction – is distinct from the regulatory analysis and must be conducted in parallel. The two analyses interact: a structuring choice that resolves a regulatory issue may create an adverse tax outcome, and vice versa.

For businesses sitting between a custody-permissive hub and a client base in a stricter market, the practical path is a dual-entity structure: a regulated custodian in the hub of choice, with a clearly documented scope of service that maps to the authorisation, and local counsel in each client-facing jurisdiction to assess whether the cross-border service triggers local registration. Operators we advise routinely find that two or three licence relationships – rather than one – is the correct answer.

If a prior application stalled or a banking relationship was declined, a second read of the structure often surfaces the reason. Write to info@oboluslaw.com or map your options with our licensing team.

Custody is distinct from exchange, staking, lending and transfer services – and each of those activities typically carries its own licence requirement in the major regimes.

An exchange that also holds client assets between trades is performing a custody function. Under activity-based regimes such as VARA, that function requires a separate activity authorisation. Under MiCA, a CASP may be authorised for multiple services on a single licence, but each service must be within the scope of the authorisation and must meet the relevant operational requirements. A business that has only an exchange authorisation is not automatically permitted to custody assets overnight.

Staking introduces a further layer. Where a custodian facilitates staking on behalf of clients – passing keys to a validator or retaining control during the staking period – the regulatory analysis must address whether the staking arrangement is itself a regulated activity (in some regimes it is characterised as a lending or investment product) and whether the custodial control exercised during staking falls within the existing custody authorisation. This analysis differs across MiCA, MAS, SFC and VARA, and we have not yet seen a major hub produce definitive guidance that covers every staking model.

Tokenised asset custody – holding the private keys that evidence ownership of a tokenised real-world asset, such as a tokenised fund interest or a tokenised bond – may engage securities regulation in addition to the virtual-asset custody regime. The applicable analysis turns on whether the underlying asset is a security in the relevant jurisdiction; if it is, the custodian may need both a virtual-asset custody authorisation and a securities custody or safekeeping authorisation. This is the fastest-evolving area of custody regulation across the major hubs.

The decision matrix, expressed in practical terms, looks like this. A business that only holds client keys in cold storage between client-initiated transactions is a pure custodian. A business that holds keys, executes trades and passes assets to staking validators is a custodian, an exchange and potentially a staking intermediary – each requiring separate authorisation in most leading regimes, or a broadly scoped combined authorisation where the regime permits it. Understanding which activities are genuinely being performed is the starting point for every custody licensing analysis.

A Common Assumption: Why One Offshore Licence Is Not Enough

A persistent assumption among early-stage digital-asset businesses is that a single registration in a lightly regulated offshore hub provides a sufficient legal basis to offer custody services to clients anywhere in the world. That assumption is incorrect, and acting on it creates compounding legal risk.

The practical reality is that the major client markets – the EU, the UK, Singapore, Hong Kong, the UAE – each assert their own regulatory perimeter over custody services directed at clients in those markets. The extraterritorial reach of MiCA, in particular, is explicit: a custodian established outside the EU that solicits EU clients without a CASP authorisation is operating in breach of MiCA, regardless of the offshore registration it holds. Equivalent provisions exist under the MAS and SFC regimes.

The banking consequence is equally practical. A custodian that cannot demonstrate authorisation in the markets it serves will find that regulated financial institutions – payment processors, correspondent banks, stablecoin issuers – decline the relationship or impose conditions that make the service commercially unviable. The offshore-only model creates a licensing gap that banking due diligence will identify.

In our cross-border practice, we have seen businesses that built significant client books on the basis of a single offshore registration, only to face a mandatory restructuring exercise when they sought banking in a leading financial centre or when a client's regulator made an enquiry. The restructuring cost – legal, operational and reputational – is invariably higher than the cost of building the right structure at the outset.

The correct framing is not "which single jurisdiction covers everything" but "which jurisdiction covers the custody entity, which covers the operating entity, and which local registrations are needed in the client-facing markets." That analysis is the work we do at the beginning of an engagement, before capital is deployed and before clients are onboarded.

When Custody Arrangements Trigger Disputes – and How Those Are Resolved

Custody disputes – whether between a custodian and a client, between a liquidator and a custodian, or as part of a broader asset-recovery action – arise with increasing frequency as institutional custody volumes grow.

The primary legal question in a custody dispute is characterisation: does the custodian hold the assets as bare trustee (so that the assets belong to the client and are recoverable in insolvency), as a contractual debtor (so that the client has only an unsecured claim), or under some hybrid arrangement? This question is not settled uniformly across jurisdictions. England and Wales courts have treated cryptographic keys and the assets they control as capable of being held on trust. The DIFC Courts have addressed similar questions in proceedings involving digital-asset intermediaries. The outcome turns on the specific contractual and operational facts, not on the asset class alone.

Where custody assets have been misappropriated or are held by a failed platform, the recovery toolkit available to a business claimant includes worldwide freezing orders (injunctions that freeze a defendant's assets globally), Norwich Pharmacal disclosure orders (orders requiring a third party to identify the wrongdoer), and – where the assets remain on-chain – requests to Tether (USDT) or Circle (USDC) to exercise their contractual freeze capabilities pending a court order. The recovery window for on-chain assets is short: hours to days in many cases. Acting quickly and with the right legal tools simultaneously is essential.

In a recent recovery matter, a fund had placed a seven-figure stablecoin balance with a custody intermediary that subsequently became insolvent. The question of whether the balance was a client asset held on trust or an unsecured liability of the estate was central to the insolvency proceedings. We advised on the trust characterisation analysis and the applicable forum strategy, and the assets were recognised as client property before distribution was finalised.

Custody businesses facing a dispute – whether as claimant or respondent – need counsel who can work simultaneously on the regulatory characterisation, the contractual analysis and the procedural steps across forums. The DIFC Courts, England and Wales, and Singapore are the most frequently used forums for custody-related disputes involving cross-border digital-asset businesses.

Self-Assessment: Does Your Business Need a Custody Licence?

A custody licence requirement is triggered when your business meets the operative test in the applicable regime – and that test turns on fact, not on how the service is labelled.

The following questions map the most common trigger points. If the answer to any of them is yes, a formal regulatory analysis is warranted before the service is launched or expanded.

Do you hold, control or administer private keys on behalf of clients – even temporarily, during settlement or during a staking period? If so, the custody perimeter is engaged in most flagship regimes.

Do you have clients resident in the EU, UK, Singapore, Hong Kong or the UAE? If so, the relevant regime in that market applies to the service you are providing to those clients, regardless of where your entity is incorporated.

Do you hold client assets in a wallet you control, pending their instruction to withdraw or trade? That fact pattern is custody, not a technology service. The label on the service agreement does not change the regulatory analysis.

Have you obtained a legal opinion – not a marketing memo – confirming that your activity falls outside the custody perimeter in each of your client-facing markets? If not, the gap between commercial activity and legal authorisation is a risk that needs to be quantified.

Does your banking due-diligence questionnaire ask whether you are a regulated custodian? It will. Banks and payment processors conducting counterparty due diligence on digital-asset businesses routinely require evidence of regulatory authorisation as a condition of account opening.

Regulators in the leading hubs increasingly expect that a business can demonstrate, at any point, that it understood its regulatory perimeter and took affirmative steps to operate within it. The self-assessment process is not simply a precursor to filing a licence application; it is the documented evidence of that understanding.

Related at OBOLUS

FAQ

How long does a crypto licence take to obtain?

Timelines vary significantly by jurisdiction and licence type. In the EU under MiCA, a CASP authorisation process is measured in months, with the length determined by the national competent authority and the completeness of the application. In Singapore and Hong Kong, the MAS and SFC processes are similarly multi-month exercises. Lighter-touch registrations – in the BVI or Cayman – are generally faster, but those registrations do not substitute for authorisation in the client-facing markets. The most reliable predictor of timeline is application quality: incomplete or inconsistent submissions reliably extend the process.

Which jurisdiction is best for licensing my crypto business?

There is no single correct answer. The right jurisdiction turns on the scope of activities, the target client geography, the banking infrastructure required and the entity's operational capacity to meet local regulatory expectations. For EU client-facing businesses, a MiCA CASP authorisation in a member state with passporting is often the most efficient path. For businesses focused on the Gulf or Asia, VARA, ADGM, MAS or SFC authorisation may be more appropriate. In our practice, we build a jurisdiction matrix at the start of each licensing engagement rather than defaulting to a single recommended hub.

Do I need a separate custody licence?

In most flagship regimes, yes – if custody is a material part of your service offering. Under activity-based regimes such as VARA, custody is a discrete licence category separate from exchange or advisory activities. Under MiCA, a single CASP authorisation may cover multiple services, but custody must be explicitly within its scope and must meet the relevant operational requirements. A business that holds client keys as part of an exchange or payment service without a custody authorisation is likely operating in breach of the applicable regime. The analysis is fact-specific and should be conducted before the service is designed, not after it is live.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the entirety of our practice, and we act only for businesses. We map the licence, banking and custody stack before you commit – not after the regulator calls. To discuss your situation, contact info@oboluslaw.com.

By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in custody authorisation, CASP licensing and cross-border digital-asset regulatory structuring across the EU, UAE and Asia-Pacific.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours