Custody of digital assets inside an investment fund is one of the most consequential structural decisions a fund manager makes – and one of the most frequently deferred until it causes a problem. As major financial regulators converge on explicit safeguarding requirements for fund-held crypto assets, the compliance burden attached to custody is rising steeply across every leading fund domicile. A fund that built its structure around an informal custody arrangement two years ago may already be operating outside current regulatory expectations. This analysis maps the legal and operational dimensions of that burden, examines how the question plays out across competing domiciles, and offers a decision matrix for fund managers choosing or reconsidering their approach.
What Does Regulated Custody Actually Cover for a Digital-Asset Fund?
Regulated custody for a digital-asset fund means more than holding private keys. In every major fund-regulation regime, custody is a distinct regulated activity carrying its own authorisation, conduct and reporting obligations – separate from the licence required to manage the fund itself. The core obligation is safeguarding: client assets must be held in a way that segregates them from the custodian's own assets, ensures their return if the custodian fails, and preserves the fund's ability to exercise title against third parties.
For traditional securities, the mechanics of segregation are well-established. For digital assets, they are not. A private key is the functional analogue of a bearer instrument – whoever controls it controls the asset. The regulatory response across leading regimes has been to treat custody of digital assets as a regulated activity requiring specific technical and legal controls, not merely an extension of conventional securities safekeeping.
Under MiCA (the EU's Markets in Crypto-Assets Regulation), the provision of custody and administration of crypto assets on behalf of clients is a named service that a CASP (Crypto-Asset Service Provider) must be specifically authorised to provide. ESMA has issued guidance clarifying that fund managers relying on an external custodian must satisfy themselves that the custodian holds a valid CASP authorisation for custody – not merely an AML registration. The same principle applies in Singapore under the Payment Services Act administered by MAS, in Hong Kong under the SFC's VASP regime, and in the UAE under VARA's activity-based licence structure, where custody is one of the enumerated activities requiring a separate rulebook sign-off.
The cross-border dimension compounds the issue. A fund domiciled in the Cayman Islands whose custodian is based in Singapore and whose assets include tokens issued under EU law is subject to overlapping regulatory expectations. None of those regimes acts as a clean backstop for the others. In our practice, we see fund managers regularly underestimate how many concurrent obligations that triangulation creates.
For a scoped assessment of where your fund's custody arrangement sits against current regulatory expectations, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity structure, the investor base, the asset mix – change the analysis significantly.
How Does Fund Domicile Shape the Custody Obligation?
Domicile is not merely a tax and distribution decision – it is the primary determinant of which custody regime your fund must comply with, and which custodians are legally eligible to serve it. A fund domiciled in a jurisdiction that imposes substantive custody rules cannot cure those obligations by appointing a custodian located elsewhere, unless the receiving regulator specifically permits that arrangement.
The leading fund domiciles each take a distinct approach.
In the EU, the Alternative Investment Fund Managers Directive (AIFMD) has long required EU-regulated AIFs to appoint a depositary – a specific type of custodian subject to a separate licence, liability regime and oversight obligation. MiCA layers additional CASP authorisation requirements on top of that. The combined effect is that an EU-domiciled digital-asset fund faces the most demanding custody regime currently in force. The benefit is that ESMA's consistent interpretation provides relative certainty about what "compliant custody" means.
The Cayman Islands and the BVI offer lighter-touch custody frameworks. Under the Cayman VASP Act and the BVI VASP Act 2022, custody is a regulated activity, but the prescriptive conduct obligations are less extensive than under MiCA or AIFMD. This creates genuine cost and flexibility advantages for fund managers – but it also means that institutional investors domiciled in the EU or the UK may apply their own home-jurisdiction expectations to the fund's custody arrangements as a condition of investing. The "offshore vehicle works equally" assumption – the myth we address later in this analysis – stems directly from this gap.
Singapore's MAS and Hong Kong's SFC represent an intermediate position. Both regulators require that digital assets held on behalf of fund clients be held by an entity holding the appropriate payment-services or VASP licence. Both place an affirmative obligation on the fund manager to conduct due diligence on the custodian's regulatory status. MAS's published guidance on the Payment Services Act is explicit: a fund manager who delegates custody to an unlicensed entity does not thereby shed the regulatory risk – it absorbs it.
The AIFC/AFSA regime in Kazakhstan is worth noting for managers serving CIS-region investors. AFSA has moved to align its digital-asset custody standards with IOSCO principles, and the AIFC's common-law framework means that fund documents drafted in other common-law jurisdictions translate with relatively low friction.
What Compliance Obligations Attach to a Fund's Custody Arrangement?
A fund manager's compliance obligations in relation to custody span four distinct layers, each with a different risk profile and a different enforcement pathway. Conflating them is one of the most common structural errors we encounter.
Layer one: custodian due diligence. Every serious fund regulation regime – MiCA/ESMA, MAS, SFC, VARA – places an ongoing obligation on the fund manager to verify that its custodian holds the appropriate licence, maintains adequate segregation, and has not had that licence suspended or revoked. This is not a one-time check at onboarding. It is a periodic obligation, typically embedded in the fund's compliance calendar. A custodian that was compliant at inception may not be compliant twelve months later.
Layer two: segregation and title. The fund's assets must be segregated from the custodian's proprietary assets in a legally effective way. For digital assets, that means either on-chain segregation (separate wallets attributable to the fund) or a custodian structure that provides legally enforceable trust or agency arrangements over a pooled wallet. On-chain segregation is increasingly the standard regulators prefer, because it provides audit-ready proof of the fund's title that does not depend on the custodian's solvency or record-keeping integrity.
Layer three: AML and the Travel Rule. The Travel Rule (the FATF obligation to pass originator and beneficiary data with a virtual asset transfer) applies at the point of transfer between the fund's custody wallet and any counterparty. Where the custodian and the fund manager are separate entities, the allocation of Travel Rule obligations between them must be expressly agreed and documented. In our cross-border practice, we regularly find that service-level agreements between fund managers and custodians simply do not address this – leaving both parties exposed.
Layer four: operational resilience and key management. Regulators increasingly expect fund managers to document the key-management architecture used by their custodian: how keys are generated, how they are stored (hardware security modules, multi-party computation, or other institutional-grade methods), what the recovery procedure is if a key is lost, and what access controls apply. VARA's rulebooks are explicit on this; ESMA's CASP guidance points in the same direction.
Self-Custody Versus Third-Party Custody: The Contrasting Positions
Some fund managers – particularly those operating quantitative or algorithmic strategies – argue for self-custody on the grounds that it eliminates counterparty risk and gives the fund direct control over its assets. The argument has technical merit. It has serious legal and regulatory weaknesses.
In most regulated fund domiciles, a fund manager acting as its own custodian creates a direct conflict between the manager's investment role and its safekeeping role. AIFMD was built, in part, on the principle that these functions should be separated. Regulators in the EU, Singapore and Hong Kong have each signalled that self-custody by a fund manager – absent an explicit exemption or a specific regulatory approval – is incompatible with investor-protection standards. The FCA in the UK has expressed similar reservations through its cryptoasset registration and financial-promotion guidance.
The counter-position, advanced by some practitioners, is that for small or emerging-market-focused funds, third-party custodians meeting regulatory standards simply do not exist in the relevant jurisdiction, making self-custody a practical necessity. This is a credible operational argument in some markets. It does not resolve the regulatory conflict: it merely shifts the fund's strategy from compliance to managed exception, which requires its own disclosure and structuring logic.
In practice, the institutional market has largely settled on qualified third-party custody for any fund seeking capital from EU-regulated investors, pension funds, family offices or other institutional allocators. Their own internal policies – and increasingly their own regulatory obligations – require it. A fund that cannot demonstrate third-party custody to institutional standards will find its addressable investor market materially narrowed.
If your fund's custody model is being built or revisited ahead of an institutional raise, write to OBOLUS at info@oboluslaw.com. If a prior application stalled or a banking or custody relationship was closed, a second structural read can surface the reason and the route forward.
How Does Cross-Border Operation Complicate Fund Custody?
A fund operating across borders faces custody complications that a purely domestic vehicle does not. The fund domicile determines the primary custody regulatory regime; but the location of the custodian, the location of the investors, and the location of the assets each introduce additional legal layers that must be mapped and managed.
Consider a Cayman-domiciled fund with a Singapore-based custodian, marketing to EU-qualified investors and holding a portfolio of tokens issued under EU law. The Cayman VASP framework sets the minimum standard for the fund itself. MAS requires the Singapore custodian to meet its own Payment Services Act obligations. EU investors will expect – and their own managers may contractually require – custody standards consistent with AIFMD or MiCA. The tokens, if they constitute crypto-assets within MiCA's scope, may carry obligations on the issuer side that affect how the custodian can hold or transfer them.
None of these regimes defers to the others. The fund manager must satisfy each one on its own terms, or consciously accept and disclose the gap. The most common gap we see in cross-border fund structures is the failure to document which entity holds the Travel Rule obligation and how the fund's AML program maps across each jurisdiction's requirements.
A further cross-border consideration is enforcement. If the custodian fails, where does the fund sue? Where is its title claim heard? Common-law forums – England and Wales, the DIFC Courts, Singapore, Hong Kong, the BVI and Cayman courts – have each developed bodies of law treating digital assets as property capable of being the subject of proprietary claims and freezing orders. For a fund relying on a custodian in a jurisdiction without comparable legal infrastructure, the enforcement position in an insolvency scenario may be materially weaker. This is a domicile-selection consideration that is often overlooked until it becomes a crisis.
In a recent matter, a fund manager identified a gap in its custody documentation during a pre-raise due-diligence review: the service-level agreement with its custodian did not address jurisdiction for enforcement of title claims on held assets. We worked with allied counsel in the custodian's jurisdiction to restructure the agreement and establish a contractual framework that was enforceable in a common-law forum. The revised structure satisfied both the lead investor's legal counsel and the regulator's subsequent inquiry.
Which Custody Structure Fits Which Fund Profile?
The appropriate custody structure depends on a fund's domicile, investor base, asset type and operational model. There is no single right answer – but there is a structured way to choose.
Profile A: EU-domiciled AIF targeting institutional investors. This fund needs a MiCA-authorised CASP for custody, likely combined with an AIFMD-compliant depositary. The compliance cost is the highest of any profile, but the investor-acceptance benefit is commensurately large. Timeline to stand up a fully compliant structure is measured in months, not weeks. The key risk is choosing a custodian that holds an AML registration but not a full CASP authorisation.
Profile B: Cayman or BVI fund targeting US and Asian institutional capital. A qualified custodian holding relevant regulatory approvals in Singapore, Hong Kong or a major common-law jurisdiction will generally satisfy institutional investor requirements. The Cayman or BVI VASP registration covers the fund vehicle itself. The key risk is the mismatch between the fund's light-touch home-jurisdiction obligations and the investor's home-jurisdiction expectations – the gap must be bridged in the fund documentation and the investor due-diligence materials.
Profile C: AIFC/AFSA-based fund targeting CIS and Gulf investors. The AIFC common-law framework supports qualified custody structures, and AFSA's alignment with IOSCO principles gives institutional investors reasonable comfort. Allied counsel in the AIFC jurisdiction is advisable for fund document review. The key risk is that the pool of AFSA-approved custodians for digital assets is smaller than in Singapore or the EU, which may create operational constraints.
Profile D: Emerging-market fund with no custodian meeting institutional standards. This profile requires the most careful structuring. Self-custody may be operationally necessary but requires explicit regulatory analysis, investor disclosure, and a governance framework that addresses the conflict of interest between manager and custodian roles. This structure will limit the addressable institutional investor base unless and until a qualified third-party custodian is appointed.
What Are the Most Frequent Custody Compliance Failures?
Custody compliance failures in digital-asset funds cluster around a small number of recurring structural errors. Identifying them before a regulator or a lead investor does is the purpose of pre-raise legal review.
The first and most common failure is appointing a custodian based on market reputation rather than regulatory status. A custodian may be operationally excellent and widely used in the market and not hold the specific licence required by the fund's domicile or the investor's home jurisdiction. The fund manager who relies on the custodian's own representations without independent verification of its regulatory status bears the compliance risk if the appointment later turns out to be non-compliant.
The second failure is inadequate segregation documentation. Even where a custodian maintains separate wallets for each fund client, the legal basis for that segregation – whether trust, agency or contractual arrangement – must be clearly documented and enforceable. Wallet-level separation without a legally sound framework for the fund's title claim is operationally useful but legally thin.
The third failure is the Travel Rule gap described earlier. Service agreements between fund managers and custodians that predate the Travel Rule's extension to digital assets, or that were drafted before the jurisdiction's implementation, frequently do not allocate the obligation clearly. This leaves both parties in a position where they may each believe the other is responsible – and neither is in compliance.
The fourth failure is static due diligence. A custodian review conducted at fund launch and never revisited is a governance weakness. Custodian regulatory status, operational resilience and key-management practices all evolve. The fund's compliance program should include a schedule of periodic custodian review, documented in board minutes.
A common assumption in the market is that any offshore vehicle works equally well for a digital-asset fund's custody needs. This assumption is wrong on two counts. First, different offshore jurisdictions impose materially different custody obligations, and the gap between the lightest and the most demanding is significant. Second, even if the fund's own jurisdiction imposes light obligations, the fund's investor base will impose its own. A Cayman fund marketing to EU pension funds operates, in practice, under EU-level custody expectations regardless of what Cayman law requires. Ignoring that reality is the single most predictable cause of a failed institutional due diligence.
When Should a Fund Manager Engage Specialist Counsel on Custody?
Specialist legal input on custody is most valuable at three points in a fund's lifecycle, and the cost of engaging it at those points is a fraction of the cost of correcting a structural failure later.
The first is at domicile selection, before the fund vehicle is established. The choice of domicile locks in the primary regulatory custody requirement. It also determines which investor types can practically access the fund and which custodians are eligible to serve it. A decision made on the basis of tax efficiency alone, without accounting for the custody and distribution implications, will often need to be reversed – at considerable cost and delay.
The second is at custodian appointment. The service-level agreement between a fund manager and a custodian is the primary legal instrument governing the custody relationship. It should address segregation methodology, title protection, key-management practices, Travel Rule allocation, liability in the event of loss, jurisdiction for enforcement, and the custodian's obligation to maintain its regulatory authorisation. A market-standard custodian agreement typically does not cover all of these adequately. Specialist review and negotiation at this stage is not optional for a fund seeking institutional capital.
The third is at any material change to the fund's strategy, investor base or asset mix. A fund that adds a new asset class – for example, moving from liquid tokens to staked positions or to tokenised real-world assets – may find that its existing custody arrangement does not cover the new assets. The same applies when a fund begins marketing to investors in a new jurisdiction.
In our practice, we see funds that have operated for several years with custody arrangements that were adequate at inception but have not kept pace with regulatory change. The correction is usually straightforward when identified early. When it surfaces during an investor due diligence or a regulatory examination, the consequences – delay, cost, and reputational damage – are disproportionately larger.
Related at OBOLUS
- Funds and Investment Vehicles for Digital-Asset Businesses – how we structure, advise and support fund managers across 70+ licensing jurisdictions
- Tokenised Fund Structuring in South Africa – the regulatory position and structuring options for tokenised vehicles in South Africa
- Custody Arrangements for Established Fund Operators – a scoped service for managers reviewing or upgrading an existing custody structure
FAQ
Where should a crypto fund be domiciled?
Domicile selection for a digital-asset fund turns on three factors: the target investor base, the asset mix, and the regulatory cost the manager is willing to absorb. The Cayman Islands and BVI remain common choices for flexibility and market recognition. EU domiciles provide the strongest investor-acceptance profile for institutional European capital but carry the highest custody and regulatory compliance cost. Singapore and Hong Kong suit managers targeting Asian institutional investors. There is no universally optimal domicile; the decision requires a mapped analysis of each variable.
Does a digital-asset fund manager need a licence?
In most leading jurisdictions, yes. Managing assets on behalf of third parties is a regulated activity regardless of whether the assets are digital or traditional. MiCA, the Payment Services Act, the SFC's VASP regime and VARA's activity-based licences each apply to fund managers meeting the applicable thresholds. Exempt categories exist – for example, for funds below a certain asset threshold or serving exclusively professional investors – but these exemptions are jurisdiction-specific and often narrower in practice than managers expect. Confirmation of licensing status should be obtained before any capital is accepted.
How is custody arranged for a crypto fund?
Custody for a digital-asset fund is typically arranged through a third-party custodian holding the relevant regulatory authorisation in the fund's domicile jurisdiction or the custodian's home jurisdiction. The custodian maintains segregated wallets or equivalent on-chain structures attributable to the fund, supported by a legal framework – trust, agency or custody agreement – that protects the fund's title. The fund manager remains responsible for ongoing due diligence on the custodian's regulatory status and for documenting the allocation of Travel Rule obligations under the applicable AML regime.
OBOLUS is an independent digital-asset law boutique acting exclusively for businesses. We advise fund managers, custodians, token issuers and institutional investors on licensing across 70+ jurisdictions, on cross-border fund structuring, and on the compliance, AML and operational frameworks that surround digital-asset investment vehicles. We match domicile to investor base, asset mix and redemption profile – because the wrong structure locks in tax leakage and limits which investors you can accept. Digital assets are the whole of our practice. To discuss your fund's custody structure, contact info@oboluslaw.com.
By Roman Levitt, Technology & DeFi Counsel – specialises in the technical and regulatory architecture of digital-asset fund structures, custody frameworks and on-chain compliance obligations across multiple jurisdictions.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.