With regulators across the major hubs tightening asset-segregation expectations in the wake of high-profile exchange collapses, the question every custodian, exchange and funds administrator is asking is no longer theoretical: what does the law actually require you to do with client assets – and what happens when you get it wrong? Custody rules for digital-asset businesses now sit at the intersection of licensing, AML compliance (anti-money-laundering compliance), the Travel Rule (the obligation to pass originator and beneficiary data with a transfer), and KYC frameworks (know-your-customer identity verification) – and the failure of several large centralised exchanges has made regulators across Europe, the Gulf and Asia-Pacific revisit exactly how those rules are enforced. This analysis sets out what the current regime requires, where the cross-border gaps remain, and what a well-structured custody compliance posture looks like today.
Why Exchange Failures Changed the Custody Debate
The core lesson regulators drew from recent exchange collapses was not simply that firms were undercapitalised – it was that client assets were commingled with proprietary funds in ways that made orderly recovery impossible. That finding accelerated a shift already underway in every major licensing regime: from disclosure-and-register to substance-and-segregate.
Before those failures, several jurisdictions operated light-touch VASP registration regimes that imposed AML obligations but said little about how client assets had to be held. The collapses exposed a structural gap. A firm could be technically registered, technically Travel-Rule compliant, and still be running client Bitcoin against its own treasury. Regulators reacted swiftly. Under MiCA (the EU Markets in Crypto-Assets Regulation, overseen by ESMA and national competent authorities), the CASP authorisation framework (crypto-asset service provider authorisation) now imposes explicit asset-segregation obligations tied to the service category. VARA in Dubai has published custody-specific rulebook provisions. The FCA in the United Kingdom has made client-asset protection a standing supervisory priority for registered cryptoasset firms.
In our cross-border practice, we observed the change in tone almost immediately. Regulators that had previously focused their inspection letters on AML policies and transaction-monitoring thresholds began asking a second question: show us the wallet architecture.
What Does Segregation Actually Mean Across Regimes?
Segregation, as applied to digital-asset custody, means that client assets must be held in a way that keeps them legally and operationally distinct from the firm's own funds – and from other clients' funds where individual segregation is required. The precise standard differs meaningfully across regimes, which creates a cross-border compliance problem for any operator serving users in more than one jurisdiction.
Under the MiCA regime, the applicable provisions distinguish between firms providing custody services as a discrete CASP activity and those bundling custody with exchange or transfer services. Each category carries its own segregation expectation. A custodian acting under the full MiCA CASP authorisation is expected to hold client keys – or interests in pooled key structures – in a manner that would survive the firm's insolvency. The CASP must be able to demonstrate, on request, that it can attribute any held asset to the client whose asset it is.
The VARA regime in Dubai takes an activity-based approach. Its custody and transfer/settlement rulebooks address wallet architecture, reconciliation frequency and the conditions under which a firm may move client assets. VARA's rulebook provisions specifically address the distinction between hot and cold wallet allocations, requiring firms to maintain documented policies on the proportion of assets held in each. The FSRA within the Abu Dhabi Global Market operates under a parallel logic: the FSRA framework for virtual-asset activities requires custodians to apply safeguarding measures broadly equivalent to those applied to conventional financial instruments.
Singapore's Payment Services Act, administered by MAS, addresses custody of digital payment tokens within its Major Payment Institution tier. Hong Kong's SFC, through the VASP licensing regime for virtual-asset trading platforms, requires platform operators to keep at least a defined proportion of client assets in cold storage – one of the few jurisdictions where that figure has been stated explicitly in published guidance. The FCA in the UK applies its client-asset sourcebook rules by analogy where cryptoasset firms also hold regulated investments, and has signalled that equivalent principles should apply even where they do not.
The common thread: across every serious licensing regime, the question has moved from "are you registered?" to "can you prove your clients' assets are protected?"
For a scoped assessment of how your custody architecture maps against the regimes relevant to your user base, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity structure, the wallet architecture, the user base geography – change the analysis materially. Map your options
How Does AML Compliance Interact With Custody Obligations?
AML compliance and custody are legally distinct obligations, but they interact in ways that many operators underestimate until an inspection or an enforcement action makes the connection explicit. A custody breach frequently surfaces as an AML deficiency – because commingled wallets obscure the transaction trail that the Travel Rule and KYC framework are designed to maintain.
The Travel Rule – derived from FATF Recommendation 15 on virtual assets – requires a VASP (virtual asset service provider) to pass originator and beneficiary information alongside a transfer. The precise de minimis threshold below which the obligation does not apply varies by jurisdiction and should be confirmed against current local legislation. What does not vary is the underlying logic: the Travel Rule is only practically enforceable if a firm can identify which client's asset is moving. A custody architecture that commingles client funds with proprietary funds – or pools clients without adequate sub-ledger records – makes Travel Rule compliance structurally impossible.
The FATF guidance on virtual assets, which underpins the Travel Rule obligations adopted by VARA, MAS, the FCA and other leading regulators, treats custody infrastructure as a precondition of AML compliance – not a separate subject. An operator cannot have a credible AML programme if it cannot account, at the wallet level, for whose assets it holds.
Transaction monitoring adds a further layer. An effective transaction-monitoring system screens incoming and outgoing transfers against sanctions lists, flags unusual patterns and generates SARs (suspicious activity reports) where warranted. But transaction monitoring at the chain level requires the firm to know which wallet addresses belong to which clients. Again, the custody architecture determines whether monitoring is genuinely possible or merely a compliance artefact.
In our practice, we regularly advise firms that have built strong KYC onboarding processes and then undermined them through wallet management practices that make the ongoing monitoring obligation meaningless. The two have to be designed together.
The MLRO Role and the Accountability Gap
Every serious VASP licensing regime requires the appointment of a Money Laundering Reporting Officer (MLRO) – the individual responsible for the firm's AML compliance programme, including its custody-related controls. The MLRO is not a figurehead. In regulatory investigations following exchange failures, regulators have consistently looked first at what the MLRO knew, when they knew it, and whether they had the authority and resources to act.
Under MiCA's CASP authorisation requirements, the MLRO – or an equivalent function – must have sufficient seniority and independence to escalate custody concerns to the board without obstruction. The VARA regime imposes similar expectations. The FCA in the UK has made individual accountability a recurring theme in its communications with registered cryptoasset firms, applying the logic of the Senior Managers and Certification Regime by analogy even where it does not formally apply to unregulated activities.
The accountability gap that exchange failures exposed was not purely structural. It was, in many cases, a governance failure: a MLRO function that was technically present but operationally sidelined. The compliance team filed reports; the reports were not actioned; the custody architecture was never challenged.
Regulators in the major hubs increasingly expect the MLRO to be able to demonstrate, not just assert, that custody controls are functioning. That means periodic reconciliation testing, documented escalation paths, and – in the larger firms – independent internal audit of the wallet architecture against the stated policy.
Cross-Border Custody: Which Regime Governs?
For an operator structured in one jurisdiction but serving clients in several others, the question of which custody regime applies is genuinely complex – and the answer is frequently "more than one." This is the cross-border reality that a single offshore registration does not resolve.
A common assumption in the market is that licensing in a permissive or early-mover jurisdiction insulates the operator from the custody requirements of the jurisdictions where its clients sit. That assumption is incorrect. MiCA's CASP authorisation regime applies to firms offering crypto-asset services to persons in the EU or EEA, regardless of where the firm is incorporated. An operator licensed in the BVI under the VASP Act 2022 and serving European retail clients must consider whether its custody practices comply with MiCA expectations – because MiCA defines the reach of its obligations by reference to the location of the client, not the location of the operator.
The same logic applies in the Gulf. VARA's mandate covers virtual-asset activity conducted in or from the Emirate of Dubai. A firm operating from an ADGM-licensed entity in Abu Dhabi that solicits clients in mainland Dubai may fall within VARA's remit for those activities. The FSRA within ADGM has its own custody expectations. The two regimes do not conflict, but they do require separate compliance mapping.
In a recent matter, we advised a custodian structured in a common-law offshore centre that had expanded its user base to include institutional clients in the EU. The firm's custody architecture had been designed for its home regime only. We identified four areas where the MiCA-aligned expectations of the relevant national competent authority imposed additional obligations – including reconciliation frequency and the audit-trail requirements for key management. The remediation was achievable, but the cost and time involved were substantially higher than an upfront multi-regime design would have required.
The practical implication is straightforward: custody architecture should be designed for the most demanding regime in which the firm operates, and tested against every other.
If a prior application stalled or a compliance review identified gaps you have not yet resolved, a second assessment can surface the structural reason and the path forward. Write to OBOLUS at info@oboluslaw.com or message us via t.me/oboluslaw. Map your options
What Does a Compliant Custody Framework Look Like in Practice?
A compliant custody framework, as the major regulators now define it, has five identifiable components: legal segregation, wallet-level attribution, a documented key-management policy, a reconciliation process with defined frequency, and an MLRO-led oversight function with genuine escalation authority.
Legal segregation means that the legal title analysis – who owns the assets in the wallet – is clear on the face of the custody agreement. Under English law, used as the governing framework in DIFC Courts and many common-law offshore centres, a bare trust structure is the standard vehicle. The custodian holds the assets on trust for the client; the assets do not form part of the custodian's estate on insolvency. The precise legal vehicle varies by jurisdiction, but the objective is the same: a creditor of the custodian should not be able to reach client assets.
Wallet-level attribution means the firm can produce, at any point in time, a complete sub-ledger mapping each held asset to the client who owns it. This is the operational precondition of both the Travel Rule and effective transaction monitoring. Without it, an AML audit becomes a fire-drill.
The key-management policy addresses how private keys are generated, stored, backed up and accessed. Regulators increasingly expect written policies covering the hot/cold split, the conditions for key recovery, and the controls around multi-signature arrangements. VARA's rulebook provisions address this explicitly; MiCA's implementing technical standards develop the expectation further.
Reconciliation frequency is the control that makes the other components meaningful. A firm that performs monthly reconciliations but processes thousands of transactions a day is, in practice, unaware of mismatches for most of each month. Regulators in the leading hubs – particularly following the exchange failures that exposed late-identified shortfalls – have pushed for daily or intraday reconciliation for any firm holding client assets at scale.
The MLRO oversight function closes the loop. The MLRO must have documented sight of reconciliation exceptions, wallet-level variances and any instances where the custody architecture deviates from the stated policy. Regulators now ask, routinely, to see the MLRO's escalation log.
Contrasting Positions: Principles-Based Versus Rules-Based Custody Regimes
Not every custody regime takes the same approach, and the contrast matters for operators choosing a licensing domicile or managing multi-regime compliance.
MiCA represents a relatively rules-based approach. The CASP authorisation framework specifies the custody-related obligations with considerable granularity, particularly for the custody-and-administration service category. ESMA and the national competent authorities have published technical standards that translate the MiCA principles into specific operational requirements. An operator knows, with reasonable precision, what it must do.
VARA in Dubai operates from a more principles-based starting point. The VARA rulebooks set out the expected outcomes – client assets protected, wallet controls documented, risk of commingling eliminated – but leave substantial room for firms to implement controls in ways appropriate to their scale and architecture. In our experience, this creates flexibility for well-resourced operators but also leaves room for inadequate implementations to pass initial review.
The FCA's approach in the UK sits between the two. The MLR registration requirement focuses primarily on AML rather than custody, but the FCA has increasingly used its existing client-asset rulebook principles and its financial-promotion supervisory role to signal expectations about custody practice. The FCA has explicitly stated that poor custody practice is a factor it considers when assessing whether a firm is fit and proper under the MLR registration regime.
MAS in Singapore takes a granular, rules-based approach comparable to MiCA for major payment institutions, with explicit guidance on cold-storage proportions and reconciliation. The SFC in Hong Kong has published detailed custody-specific requirements for VASP-licensed platforms following the exchange failures that affected Hong Kong-connected entities.
The practical upshot: an operator calibrated only to the most principles-based regime in its stack may be materially non-compliant in the most rules-based one. Multi-regime compliance requires mapping to the highest common standard.
A Decision Matrix for Custody Compliance by Operator Profile
Different operator profiles face different compliance priorities. The matrix below describes the most common profiles we advise, the primary custody obligation they face, and the key risk if they get it wrong.
A centralised exchange serving retail users across multiple EU member states must hold a MiCA CASP authorisation for custody and exchange services. The key obligation is full segregation at the sub-ledger level, Travel Rule compliance on all outgoing transfers above the applicable threshold, and daily reconciliation. The key risk is a supervisory intervention by the relevant national competent authority, with the practical consequence of a suspension of passported services across the EU/EEA.
A custody-only provider serving institutional clients from a Gulf base under the VARA or FSRA regime must implement the activity-specific rulebook requirements of the relevant authority. The key obligation is the documented hot/cold wallet split, the key-management policy and the MLRO escalation framework. The key risk is a VARA or FSRA supervisory review finding a gap between the written policy and the operational architecture – a finding that has led, in other markets, to licence suspension pending remediation.
A crypto fund administrator operating from a common-law offshore centre – BVI, Cayman, or a comparable jurisdiction – that also touches EU or UK clients must contend with a multi-regime custody obligation. The home regime (BVI FSC under the VASP Act 2022; CIMA under the Cayman VASP Act) sets the base standard. MiCA or FCA expectations layer on top for EU and UK clients respectively. The key risk is the gap between home-regime compliance and the additional expectations of the client-facing jurisdictions – a gap that becomes visible only when a regulator with extraterritorial reach initiates a review.
A payments operator holding digital-asset balances for clients incidentally to a payment service must assess whether the custody obligation arises under the applicable payment services regime as well as the VASP licensing regime. In Singapore, MAS's Payment Services Act creates exactly this overlap for operators providing digital payment token services alongside conventional payment functions.
Objection Handler: Is a Single Offshore Licence Really Enough?
A common assumption among operators entering the digital-asset space is that a single offshore licence – in the BVI, Cayman, or an early-mover EU jurisdiction – provides a sufficient legal basis to serve clients globally. It does not.
The assumption confuses the jurisdictional reach of a licence with the jurisdictional reach of an obligation. A BVI VASP registration confirms that the firm has met BVI FSC requirements. It says nothing about whether the firm's custody practices comply with MiCA for EU clients, with FCA expectations for UK clients, or with VARA for clients in Dubai. Each of those regimes defines its reach by reference to the client's location, not the operator's domicile.
Enforcement actions in multiple jurisdictions over the past several years have consistently confirmed this point. Operators that treated an offshore registration as a global licence found, at the point of enforcement, that their regulatory position was not what they believed it to be.
The correct approach is a licence-stack analysis: map the licensing obligation in each jurisdiction where the firm has clients, assess the custody requirements imposed by each relevant regime, identify the highest common standard across the stack, and design the custody architecture to that standard. The offshore registration may still be one element of the stack – but it is not the whole answer.
We map the licence stack across operating, custody and payment layers before our clients commit to an architecture. That work surfaces conflicts and gaps before they become enforcement events.
Self-Assessment Checklist for Custody Compliance
Before engaging counsel, operators can use the following markers to identify where their current custody posture is likely to draw regulatory scrutiny.
First, legal segregation: does the firm's custody agreement clearly establish that client assets are held on trust or equivalent, separate from the firm's own assets? Is that structure validated under the governing law of each jurisdiction in which the firm operates?
Second, wallet-level attribution: can the firm produce, within 24 hours of a regulator's request, a complete sub-ledger mapping every held asset to the client who owns it? Is that sub-ledger reconciled against on-chain balances daily?
Third, key management: does the firm have a written policy covering key generation, storage, backup and access? Is the hot/cold split documented and reviewed quarterly? Are multi-signature arrangements governed by a formal approval framework?
Fourth, Travel Rule integration: does the firm's custody architecture make it possible to identify the originator wallet for every outgoing transfer above the applicable threshold? Is originator and beneficiary data captured at the point of transaction, not retrospectively?
Fifth, MLRO oversight: does the MLRO have documented sight of reconciliation exceptions? Is the escalation log maintained? Has the MLRO confirmed in writing, within the last 12 months, that the custody architecture complies with the stated policy?
A negative answer to any of these questions is, in the current supervisory environment, a material compliance risk. It is also the kind of finding that appears in the first page of a regulatory inspection report.
Related at OBOLUS
- Compliance, AML and Travel Rule for Digital-Asset Businesses – our full practice overview on AML, KYC and Travel Rule obligations across jurisdictions
- Sanctions Screening for Crypto: Institutional Clients – targeted guidance on sanctions screening architecture for custodians and exchanges
- Redemption and Liquidity Terms: What Recent Enforcement Tells Operators – enforcement-informed analysis of liquidity and redemption obligations for funds and exchanges
FAQ
What does the Travel Rule require from a VASP?
The Travel Rule, derived from FATF Recommendation 15, requires a VASP to transmit originator and beneficiary information – name, account identifier and, where available, address – alongside a virtual-asset transfer. The obligation applies above a de minimis threshold that varies by jurisdiction. The practical effect is that a firm must be able to identify the client behind every wallet address before initiating a transfer, making robust KYC and wallet-level attribution preconditions of Travel Rule compliance.
Who must act as MLRO for a crypto firm?
Every VASP operating under a serious licensing regime – including MiCA's CASP authorisation, VARA's activity licences, the MAS Payment Services Act and the FCA's MLR registration – must appoint a Money Laundering Reporting Officer (MLRO) with sufficient seniority and independence to run the AML programme and escalate concerns to the board. The MLRO must have documented oversight of custody controls, transaction-monitoring exceptions and suspicious-activity reporting. A nominal appointment that lacks operational authority will not satisfy regulatory expectations.
How do regulators audit crypto AML programs?
Regulators at the major hubs – ESMA's national competent authorities, VARA, MAS and the FCA – audit AML programmes through a combination of document review, system-access testing and interviews with the MLRO and compliance team. Inspectors typically request the AML policy, the transaction-monitoring configuration, a sample of KYC files, the reconciliation records and the MLRO escalation log. Following recent exchange failures, custody architecture and wallet-level attribution have been added to the standard inspection scope in several jurisdictions.
About OBOLUS
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before clients commit to an architecture – identifying cross-border gaps before they become enforcement events. We also work alongside forensic partners to convert on-chain evidence into court-ready disclosure applications. To discuss your situation, contact info@oboluslaw.com.
By Victor Olsen, Regulatory & Compliance Analyst – specialising in multi-jurisdiction VASP licensing, AML programme design and custody compliance across the EU, Gulf and Asia-Pacific hubs.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.