EST · MMXXVI
Home/Insights/Regulatory/Regulatory Trends in Digital-Asset Custody Across Common-law Forums
Compliance, AML & Travel Rule

Regulatory Trends in Digital-Asset Custody Across Common-law Forums

Regulatory Trends in Digital-Asset Custody Across Common-law Forums. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring

Digital-asset custody has moved from a legal grey zone to a supervised activity in every major common-law financial centre. Custody – the safeguarding of private keys and the assets they control on behalf of third parties – now sits inside the regulated perimeter in England and Wales, Singapore, Hong Kong, the BVI, the Cayman Islands and, increasingly, the AIFC. Regulators across those forums share a common concern: that assets held by intermediaries carry the same systemic, fraud and AML risks as deposits held by banks, even when the underlying infrastructure is on-chain. This analysis maps the converging custody obligations, contrasts the positions taken by leading regulators and surfaces the cross-border tensions that businesses operating across multiple hubs cannot afford to ignore.

How Common-law Regimes Have Defined Custody as a Regulated Activity

In every leading common-law hub, custody of digital assets is now a regulated activity – meaning a firm may not offer it commercially without authorisation or registration under the applicable regime. The precise trigger differs by jurisdiction. Under MiCA, the provision of crypto-asset custody and administration is one of the nine enumerated CASP (crypto-asset service provider) activities requiring authorisation; a custodian authorised in one EEA member state may passport the service across the bloc. The FCA in the United Kingdom requires cryptoasset custody firms to register under the Money Laundering Regulations, with the financial-promotion rules applying separately to any marketing of those services. The MAS in Singapore captures custody of digital payment tokens within the Payment Services Act licensing tiers, with the major payment institution track applying once prescribed thresholds are met. The SFC in Hong Kong brought virtual-asset trading platforms – including their integrated custody functions – inside the VASP licensing regime. In the offshore common-law centres, the BVI FSC operates a registration track under the Virtual Asset Service Providers Act 2022, and CIMA in the Cayman Islands runs parallel registration and licensing tracks under the Virtual Asset (Service Providers) Act.

The convergence matters. A custodian that structured its operations on the assumption that only one licence was needed has, in our practice, consistently encountered the same problem: user bases span multiple jurisdictions, and regulators in each expect local nexus compliance regardless of where the entity is incorporated.

The AIFC and its regulator, the AFSA, present a parallel common-law framework within the Astana International Financial Centre in Kazakhstan. The AIFC operates an English-law legal system, giving it structural compatibility with London, Singapore and the DIFC Courts. That compatibility has begun to influence how cross-border custody structures are designed: an entity authorised under the AFSA regime can operate across Central Asia and access a court forum that recognises common-law trust and property concepts directly applicable to digital-asset custody disputes.

What AML and KYC Obligations Apply to Custodians Specifically?

Custodians in common-law forums are subject to the full AML/CFT baseline drawn from FATF Recommendation 15 on virtual assets, translated into national law with jurisdiction-specific elaboration. The KYC framework for a custody firm goes beyond onboarding checks. It encompasses ongoing monitoring of transaction patterns, enhanced due diligence for high-risk counterparties and, critically, the Travel Rule – the obligation to pass originator and beneficiary data alongside any qualifying transfer of virtual assets.

The Travel Rule's interaction with custody creates a structural tension. A custodian does not always originate transfers; it may hold assets and execute instructions from its client. Whether the custodian or its client is the "originator" for Travel Rule purposes depends on how the instruction chain is characterised under the applicable regime. The FCA, MAS and SFC each address this in their supervisory guidance, but the answers differ. In our cross-border practice, we regularly advise custodians that the Travel Rule compliance layer must be designed jurisdiction by jurisdiction, not applied uniformly from a single policy document.

Transaction monitoring is the AML obligation most frequently cited in enforcement actions against custodians. Regulators expect systems calibrated to the specific on-chain risk profile of the assets under custody: stablecoins carry different risk signals than privacy-preserving tokens; a custodian holding assets for a fund carries different counterparty risk than one holding assets for a retail exchange. An AML compliance programme that does not differentiate by asset type and client profile will not satisfy supervisory expectations in any of the leading common-law hubs.

CTA #1: If you are assessing whether your custody operation's AML programme meets the standard expected in your target jurisdictions, the gap is rarely obvious until a supervisor asks. The analysis above describes the standard requirements. Your entity structure, asset classes and client base change the specific obligations materially. Map your options with OBOLUS before the gap becomes an enforcement finding.

Segregation and Safeguarding: Where the Standards Are Converging

Across common-law regulators, the expectation that custodied digital assets be held separately from a firm's own assets has hardened from a best-practice recommendation into a regulatory requirement. The principle is consistent; the mechanics vary. The FCA expects custodians to maintain clear segregation records and to demonstrate operational separation. The MAS has issued detailed guidance on safeguarding, including wallet-management standards and the treatment of assets held with sub-custodians. The SFC's requirements for virtual-asset trading platforms extend to the custody functions operated within those platforms, with prescribed cold-storage ratios and insurance or equivalent cover expectations.

The BVI FSC and CIMA have each moved toward requiring registered VASPs to maintain demonstrable segregation, though the specific standards remain less prescriptive than those of the Tier 1 hubs. For funds domiciled in the Cayman Islands or BVI using a third-party custodian, the analysis runs in two directions: the fund itself may be subject to CIMA or FSC oversight, and the custodian – if operating in a jurisdiction with its own requirements – must comply independently. Operators we advise routinely underestimate this two-layer exposure.

Sub-custody adds a further dimension. When a licensed custodian delegates safeguarding to a sub-custodian – whether an exchange, a hardware provider or another licensed entity – the regulatory expectation in most leading forums is that the primary custodian retains liability and oversight responsibility. A contractual pass-through is not a regulatory pass-through. We have seen several structures collapse at the due-diligence stage of an institutional mandate because the sub-custody arrangements had not been stress-tested against this principle.

Cross-border Custody: Where Multi-hub Structures Break Down

A custodian structured to serve institutional clients across London, Singapore and a GCC hub is almost certainly subject to concurrent regulatory obligations – and the obligations do not always align. The most common structural failure we observe is the assumption that licensing in the most permissive jurisdiction provides a compliance umbrella for activity directed at clients in more demanding ones.

The FCA applies a "UK nexus" test: if a firm's custody services are directed at UK-based clients, UK registration requirements apply regardless of where the entity is incorporated or licensed. MAS applies a comparable analysis for Singapore persons. The SFC's VASP regime captures platforms that actively market to Hong Kong investors even if the platform is offshore. VARA in Dubai applies its regime to activity conducted in or from the Emirate of Dubai – which includes mainland Dubai but excludes the DIFC financial free zone, where the DIFC's own framework applies.

The practical consequence is that a multi-hub custodian must hold, or be exempt from holding, a licence or registration in each jurisdiction where it has clients or from which it operates. A single offshore licence – whether from the BVI FSC, CIMA or the AFSA – is sufficient only for operations genuinely confined to that jurisdiction's perimeter. It is not, by itself, a passport. Regulators in the leading hubs increasingly expect evidence of local compliance infrastructure, not just a foreign authorisation letter.

DIFC Courts in Dubai have established themselves as a recovery and dispute forum with jurisdiction over digital-asset disputes, distinct from the VARA regulatory regime. The intersection of a VARA-regulated entity and a DIFC Courts dispute requires careful analysis of which rules govern which aspect of the relationship – a question we regularly work through with clients whose custody operations span both environments.

How Does the Travel Rule Apply to Custodial Transfers in Practice?

The Travel Rule – drawn from FATF Recommendation 15 and implemented with jurisdiction-specific thresholds and carve-outs – requires that a VASP (virtual asset service provider) transmitting virtual assets above the applicable threshold pass originator and beneficiary information to the receiving VASP or financial institution. For custodians, the rule bites whenever assets leave custody: a withdrawal instruction, a settlement to a trading venue, a transfer to an unhosted wallet or a movement to a sub-custodian can all trigger the obligation.

The threshold at which the Travel Rule applies varies by jurisdiction. The FCA, MAS and SFC each implement the rule in their own supervisory guidance, and the data fields required – and the treatment of unhosted wallets – differ in material respects. What is consistent across the leading common-law hubs is the principle: information must travel with the asset. A custodian that processes withdrawal requests without a Travel Rule compliance check is operating a structural AML gap, even if no individual transaction has been flagged by its monitoring system.

The unhosted-wallet problem sits at the centre of current supervisory attention. Regulators in Singapore, the UK and Hong Kong have each signalled concern about transfers from custodians to self-custody addresses. The expectation – enforced with varying degrees of prescription – is that custodians undertake due diligence on the beneficial ownership of the destination wallet before processing the transfer. In our practice, we have seen this expectation translate into specific questionnaire requirements, blockchain analytics obligations and, in some cases, enhanced approval workflows for large unhosted-wallet withdrawals.

Who Leads AML Governance at a Custodian – and What Do Regulators Expect?

Every custody firm operating in a regulated common-law hub must designate a Money Laundering Reporting Officer (MLRO) – a senior individual with responsibility for the firm's AML compliance programme, suspicious activity reporting and regulator liaison. The MLRO role is not a nominal one. Regulators in the FCA, MAS and SFC regimes each expect the MLRO to have genuine authority, appropriate seniority and demonstrable competence in both AML principles and the specific risk profile of digital-asset custody.

The governance structure around the MLRO matters as much as the individual. A small custodian that appoints a junior compliance officer as MLRO and fails to resource the role with adequate systems, data access and board-level support will fail a supervisory review even if the individual is technically qualified. Regulators increasingly examine the MLRO's actual access to transaction data, the frequency and quality of their board reporting and whether the firm's culture treats AML compliance as a cost to minimize or a risk to manage.

For cross-border custody operations, the MLRO structure is more complex. A firm with entities in two or more jurisdictions must determine whether a single MLRO can satisfy the requirements of each regime or whether local MLRO appointments are required. The answer varies. Some regulators accept a group MLRO with local deputies; others require a locally resident, locally accountable officer. Getting this wrong – particularly in the FCA and MAS regimes, where individual accountability expectations are high – exposes both the firm and the individual.

CTA #2: If a prior licensing application stalled, or if a correspondent bank raised concerns about your AML governance structure, the structural reason is usually identifiable. A second read of your MLRO arrangements, policy framework and Travel Rule posture can surface the issue before a regulator does. Map your options with OBOLUS.

How Do Regulators Audit a Custodian's AML Programme?

Regulatory audits of custody-firm AML programmes in common-law hubs follow a broadly consistent pattern, even where the specific requirements differ. Supervisors examine the written compliance framework – policies, procedures, risk appetite statements – before assessing whether the operational reality matches the documentation. A custody firm with a sophisticated AML policy document and an under-resourced monitoring team will fail the operational assessment regardless of how well the policy reads.

The FCA in the UK conducts both desk-based reviews and on-site inspections of cryptoasset-registered firms. The MAS in Singapore uses a combination of regulatory returns, mandatory audits and thematic reviews to assess compliance across the digital-payment-token sector. The SFC in Hong Kong has signalled a heightened supervisory posture for VASP licensees, with particular attention to governance, safeguarding and AML controls. In each case, the audit process tests whether the firm's controls are proportionate to its actual risk profile, not just whether a policy document exists.

Transaction monitoring is the most frequently scrutinised element. Regulators expect evidence that alert thresholds are calibrated to the specific risk of the firm's client base and asset mix, that alerts are investigated and closed with documented rationale, and that the results feed back into the firm's risk assessment. A static monitoring system – one whose rules have not been updated since the firm was registered – is a red flag in every leading forum. Operators we advise conduct periodic reviews of their monitoring parameters specifically to be able to demonstrate that the system has evolved with the firm's risk profile.

The anonymized micro-matter that follows illustrates the audit dynamic in practice. In a recent supervisory preparation matter, a custody firm holding a multi-jurisdictional client base had not updated its transaction monitoring rules following a significant expansion of its institutional client segment. The rules had been calibrated for retail-scale transactions. We identified the gap during a pre-audit review, rebuilt the risk classification framework and retuned the monitoring parameters before the regulator's on-site inspection. The inspection concluded without a remediation notice.

Which Regulatory Profile Fits Which Custody Business?

Custody businesses differ substantially in client base, asset mix and operational footprint, and the right regulatory profile is a function of those variables, not of which jurisdiction has the lowest fees or the fastest application process.

Profile A – Institutional custodian serving funds and family offices from a single hub. This business typically has a concentrated, high-value client base, a limited asset range and a clear geographic centre of gravity. The most suitable registration is in the jurisdiction where the majority of clients are based or where the AUM is concentrated: for a London-centric operation, FCA registration; for a Singapore-centric one, MAS licensing. The key risk is underestimating the ongoing supervisory burden – institutional custodians attract higher supervisory attention, not lower. Indicative timeline to authorisation is a matter of months in each of the leading hubs, varying by completeness of the application and the regulator's current queue.

Profile B – Multi-hub custodian serving exchanges, funds and corporate treasuries across three or more jurisdictions. This business cannot be served by a single licence. It requires a licence-stack analysis: a primary authorisation in the jurisdiction of primary business, one or more secondary registrations for jurisdictions where the client nexus triggers local requirements, and a clear policy on which activities are permissible under each authorisation. The key risk is assuming that a primary authorisation extends further than it does. The AIFC/AFSA regime is increasingly used as a gateway for operations that span Central Asia and the Middle East without a Dubai VARA licence – but that analysis requires careful boundary-drawing.

Profile C – Offshore custody vehicle serving a single institutional client or fund. This structure – common in the Cayman Islands and BVI – is typically subject to lighter registration requirements under CIMA or the BVI FSC, but it is not exempt. The key risk is that the fund's investment manager or the ultimate beneficial owners are in a jurisdiction (UK, Singapore, Hong Kong) that treats the custody arrangement as subject to its own rules. The interaction between the offshore custodian's registration and the onshore manager's obligations requires explicit analysis before the structure is committed.

In each profile, the AML compliance programme – including the Travel Rule layer, the MLRO structure and the transaction monitoring system – must be designed for the actual client base, not the nominal one. A Profile C vehicle whose single institutional client is itself a VASP with thousands of end users carries a very different AML risk profile than its single-client description suggests.

A Common Assumption: Offshore Registration Covers the Risk

A common assumption among operators building custody operations is that registration in a favourable offshore jurisdiction – the Cayman Islands, the BVI or a similar centre – provides sufficient regulatory cover for a globally directed business. This assumption is incorrect, and acting on it consistently produces the same chain of consequences: a banking relationship that cannot be opened because the bank's correspondent requires evidence of home-country regulation; a client that cannot onboard because its own regulator requires the custodian to be locally authorised; or an enforcement inquiry from a regulator whose jurisdiction was engaged by the direction of the services even though the entity is incorporated elsewhere.

The offshore registration is not worthless. For a genuinely offshore-confined operation, it is the correct and necessary step. But the definition of "offshore-confined" is narrower than most operators assume. As soon as the client base includes persons in the UK, Singapore or Hong Kong, or as soon as the firm markets its services into those markets, the home-jurisdiction authorisation of each of those markets becomes relevant. The question is not where the custodian is incorporated; it is where its services are directed and where its clients are.

We structure the licence, banking and AML stack as one mandate. We map the actual client base – current and projected – against the regulatory perimeters of each relevant jurisdiction before advising on the entity structure. That process consistently surfaces compliance obligations that the offshore-only approach misses.

Related at OBOLUS

FAQ

What does the Travel Rule require from a VASP?

The Travel Rule, drawn from FATF Recommendation 15 and implemented by leading regulators including the FCA, MAS and SFC, requires a VASP to collect originator and beneficiary information and transmit it to the receiving VASP or financial institution alongside any qualifying virtual-asset transfer. The specific threshold above which the rule applies, and the data fields required, vary by jurisdiction. For unhosted wallets, most leading common-law regulators expect enhanced due diligence before the transfer is processed.

Who must act as MLRO for a crypto firm?

Every custody firm and VASP operating in a regulated common-law jurisdiction must designate a Money Laundering Reporting Officer (MLRO) – a senior individual accountable for the AML compliance programme, suspicious-activity reporting and regulatory liaison. Regulators including the FCA and MAS expect the MLRO to hold genuine authority, adequate seniority and documented competence in digital-asset AML risk. Cross-border firms operating across multiple hubs must assess whether each jurisdiction requires a locally resident and locally accountable officer, as requirements differ materially.

How do regulators audit crypto AML programs?

Supervisors in the leading common-law hubs – including the FCA, MAS and SFC – audit AML programmes by examining both the written compliance framework and the operational reality behind it. Key focus areas include whether transaction monitoring alerts are calibrated to the firm's specific risk profile, whether alert investigations are documented, and whether the MLRO has genuine access to data and meaningful board-level authority. A policy document that does not match operational practice will not pass a supervisory review. Firms should conduct periodic internal reviews to close any gap before a regulator identifies it.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the AML, Travel Rule and compliance obligations that run through every layer of a digital-asset operation. We structure the licensing, banking and tax stack as one mandate rather than three disconnected workstreams, and we map the licence stack across operating, custody and payment layers before you commit. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com.

By Victor Olsen, Regulatory & Compliance Analyst – specialising in AML, Travel Rule compliance and regulatory structuring for custodians and VASPs across common-law hubs.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours