Operating without the correct authorisation in a regulated digital-asset market is not merely a compliance gap. It is an existential risk: enforcement action, suspended banking relationships and reputational damage that follows the business into every subsequent licensing conversation. For operators evaluating Central Asia's most developed financial centre, the Astana International Financial Centre (AIFC) – a purpose-built common-law enclave in Astana, Kazakhstan – presents a credible, internationally recognised pathway into a fast-growing regional market. The AIFC's financial regulator, the Astana Financial Services Authority (AFSA), has constructed a digital-asset regime grounded in FATF-aligned AML standards and common-law principles, making it increasingly attractive to exchanges, custodians and asset managers that need a regulated base outside the EU or the Gulf. This page sets out the full picture: the regulatory structure, who needs a licence, how the application process works and where the AIFC fits in a multi-jurisdiction operating model.
The AIFC Regulatory Environment: AFSA and the Common-Law Framework
The AIFC operates as an autonomous financial hub governed by its own legal system, separate from the general law of Kazakhstan. AFSA (the Astana Financial Services Authority) is the sole licensing and supervisory authority within the centre, and it has issued dedicated rules for digital-asset businesses under what is broadly referred to as the AIFC's digital-assets regulatory regime. That regime addresses trading facilities, custody, exchange and related investment activities involving crypto-assets.
The common-law foundation of the AIFC is not incidental. Contracts formed within the centre are governed by English-derived common law. Disputes can be referred to the AIFC Court or to the independent AIFC Arbitration Centre. For a business that banks in London, holds assets through a Cayman structure or works with institutional counterparties in Singapore, that legal continuity matters. It is one reason we regularly see inbound operators choosing the AIFC as a complement to, rather than a substitute for, a Western licence.
AFSA's supervisory posture has tightened steadily. Regulators across the leading digital-asset hubs – VARA in Dubai, the MAS in Singapore, the SFC in Hong Kong – have all signalled higher substance requirements since 2023. AFSA has followed that direction: it expects genuine local presence, not a brass-plate address. Operators we advise are consistently told that the quality of their compliance officer, the robustness of their AML framework and the credibility of their business plan weigh as heavily as the structure of their application paperwork.
Contact OBOLUS before you commit to an AIFC application. The process above describes the standard path. Your facts – the entity structure, the user base, the banking arrangements, the group's existing licences – change the analysis materially. Reach our licensing desk at Map your options.
Who Needs an AIFC Digital-Asset Licence?
Any business carrying on a regulated digital-asset activity within or from the AIFC requires authorisation from AFSA before commencing operations. The trigger is the activity, not the location of the user: an entity incorporated in the AIFC that solicits clients in Kazakhstan or cross-border generally cannot rely on a foreign licence alone.
The regulated activities AFSA recognises in the digital-asset space span several distinct service categories. A Digital Asset Trading Facility (DATF) licence covers the operation of a platform on which buyers and sellers transact in digital assets – broadly, an exchange function. A custody licence covers the safeguarding and administration of digital assets on behalf of third parties. There are also regulated activities relating to digital-asset investment management and certain advisory functions.
The practical scope question turns on whether the business is providing a service to third parties, managing third-party assets, or merely holding its own assets. Holding proprietary digital assets for treasury purposes generally does not by itself require AFSA authorisation. The moment the business begins providing a service – executing orders, safeguarding client assets, managing a fund – the licence obligation attaches.
Businesses that operate across several functions – for example, an exchange that also offers custody and a staking product – will need to map each activity against AFSA's regulated activity list. In our practice, the most common error is under-licensing: an operator obtains a trading facility licence but fails to identify that its custody function requires a separate authorisation. AFSA takes that distinction seriously.
What Are the AIFC Licence Categories for Digital-Asset Businesses?
AFSA has developed a tiered authorisation structure for digital-asset businesses, the principal categories of which are the Digital Asset Trading Facility licence, digital-asset custody authorisation and digital-asset investment management permission.
The Digital Asset Trading Facility (DATF) licence is the most commonly sought by exchange operators. It permits the licensee to operate a multilateral platform on which digital assets are bought and sold. AFSA applies conduct-of-business and market-integrity requirements to DATF licensees that echo those applied to trading venues in more established financial centres.
Custody authorisation addresses the safeguarding of client digital assets. AFSA's custody framework requires meaningful segregation of client assets and robust operational controls – requirements that align, at a structural level, with the safeguarding expectations under MiCA in the EU and the Payment Services Act regime administered by the MAS in Singapore. For an operator building a regional custody offering that needs to satisfy institutional clients familiar with those standards, that alignment is commercially significant.
Investment management permissions cover discretionary management of digital-asset portfolios on behalf of professional clients. This pathway is most relevant for family offices, crypto hedge funds and digital-asset managers seeking a Central Asian regulated base alongside a structure in the Cayman Islands or BVI.
AFSA also recognises ancillary permissions for advisory activities and for certain token-related offerings, subject to specific qualification criteria. The licence category that fits a given business depends on the precise activities it intends to carry on, the client types it will serve, and the degree of asset-handling involved. There is no single universal "crypto licence" – the authorisation must match the activity.
How Does the AIFC Authorisation Process Work?
An AIFC authorisation application proceeds through a structured review by AFSA that covers the legal, financial, operational and compliance dimensions of the proposed business. The process is not a rubber stamp. AFSA expects a complete submission and will issue detailed queries if documentation is deficient.
The standard path begins with pre-application engagement. AFSA offers an initial scoping discussion at which the applicant can outline the proposed business model and obtain preliminary guidance on the applicable licence category. We strongly recommend using this step: it surfaces issues early and allows the applicant to refine the business plan before the formal submission.
The core application package typically includes a detailed business plan covering the proposed activities, the target client base, the revenue model and the technology stack; audited financial statements or projections where relevant; a comprehensive AML/CFT framework document, including policies, procedures and controls; evidence of appropriate personnel – particularly a qualified compliance officer resident in or accessible to the AIFC; and, where the entity is part of a group, information on the group structure and any foreign regulatory status.
AFSA's review timeline varies by complexity and completeness of the submission. Applications for straightforward structures from well-prepared teams are processed in a matter of weeks to a few months; more complex or novel applications, or those requiring additional information rounds, can extend beyond that. Operators should plan their operational timeline with regulatory delay as a realistic scenario, not an exception.
Once in-principle approval is granted, the applicant satisfies any remaining conditions – which may include capitalisation, the appointment of specific personnel and the completion of systems testing – before AFSA issues the final authorisation. Commencing business before final authorisation is a regulatory breach with material consequences.
In a recent licensing matter, an exchange operator had already built its technology platform and assembled a team before approaching us. We restructured the entity to satisfy AFSA's substance expectations, prepared the compliance documentation and managed the application dialogue with AFSA. The operator received its authorisation within the window it needed to meet a commercial launch commitment.
What Substance and Capital Does AFSA Require?
AFSA requires genuine economic substance within the AIFC, not merely a registered address. The regulator expects an identifiable local presence: at minimum, a compliance officer with appropriate qualifications and a demonstrable connection to the business, a physical address within the AIFC precinct and, for most licence categories, at least one officer or director available to engage with AFSA on supervision matters.
Capital requirements vary by licence category and by the scale and nature of the proposed business. Because AFSA sets capital thresholds by reference to the specific licence type and the applicant's operational profile, and those thresholds are subject to periodic revision, the applicable figure must be confirmed from current AFSA guidance at the time of application. Describing a specific capital number here would risk inaccuracy. What we can say from practice is that AFSA's capital expectations for a trading facility are meaningfully higher than for a pure advisory permission, and that undercapitalised applications are routinely returned for revision.
AFSA also scrutinises the fitness and propriety of controllers and senior management. Background checks, source-of-funds analysis and the controller's track record in other jurisdictions all form part of the vetting. A group that has faced enforcement action or licence refusal elsewhere must address that history proactively; AFSA will identify it regardless.
The cross-border dimension of substance is frequently underestimated. An operator running its technology from Singapore, its compliance team from Lithuania and its banking from a Cayman entity, while holding an AIFC licence as its primary regulated vehicle, needs to demonstrate that the AIFC entity is not merely a shell. Regulators across the leading hubs share supervisory concerns and, increasingly, supervisory information. Operators we advise build substance into their AIFC entity from day one rather than retrofitting it under regulatory pressure.
What Are the AML and Travel Rule Obligations Under the AIFC Regime?
AFSA-authorised digital-asset businesses are subject to a comprehensive AML/CFT framework aligned with the FATF Recommendations, including Recommendation 15, which addresses virtual-asset service providers. That framework requires customer due diligence, risk-based transaction monitoring, suspicious transaction reporting and – critically for cross-border operators – compliance with the Travel Rule (the obligation to pass originator and beneficiary identifying information with each qualifying transfer).
The Travel Rule is the compliance pressure point that trips up most operators entering a new regulated market. A business may have a functioning Travel Rule solution in its home jurisdiction that is technically incompatible with the counterparty solutions used by exchanges in the AIFC or its target markets. Before applying for an AIFC licence, operators should confirm that their Travel Rule technology covers the Central Asian and CIS counterparties they expect to transact with.
AFSA expects AML policies to be genuinely risk-based, not boilerplate. The compliance officer must be able to explain the firm's risk assessment methodology to AFSA supervisors, including how it addresses the specific risks posed by the firm's client types, product mix and geographic reach. Generic policies imported from a prior jurisdiction with minimal adaptation are a common reason applications are queried or delayed.
Kazakhstan itself is subject to periodic FATF mutual evaluation. AIFC businesses benefit from the AIFC's distinct supervisory framework, but they operate in a country-level AML context that institutional counterparties and correspondent banks assess. Banking partners – particularly European and US-dollar clearing banks – will conduct their own AML review of an AIFC-licensed entity. The quality of the entity's compliance framework needs to satisfy both AFSA and the entity's banking partners.
How Do Tax and Banking Work for AIFC Digital-Asset Businesses?
The AIFC offers a distinct tax regime that, under the enabling legislation, provides significant exemptions for qualifying entities operating within the financial centre. The specific scope of those exemptions – including their application to digital-asset businesses – should be confirmed against current AIFC legislation and any applicable guidance, because the regime has evolved and individual circumstances vary. What the general framework makes clear is that the AIFC's tax environment is one of the practical reasons operators structure their Central Asian operations through the centre rather than through a standard Kazakhstani entity.
Banking is the operational risk that sinks otherwise well-structured AIFC applications. Correspondent banking for digital-asset businesses remains constrained globally. The AIFC has taken steps to attract financial institutions to the centre, and several banks with AIFC presence do service digital-asset businesses. But operators should not assume that an AIFC licence automatically unlocks banking: the bank will conduct its own due diligence on the business model, the client base and the AML framework before opening an account.
In our practice, the licensing, banking and tax mandates are run as a single workstream. Applying for a licence in isolation – without a confirmed banking path – can leave a newly authorised entity unable to receive client funds or settle transactions. We map the full stack before the application is filed: which bank will service the entity, on what terms, with what AML requirements, and how that interacts with the tax position of the group.
For operators with a group structure spanning multiple jurisdictions, the AIFC entity's position in that structure matters for tax. An AIFC holding company, an operating subsidiary in Malta or Singapore, and a payment processor in Lithuania each carry different tax profiles. A structuring review before licensing avoids costly restructuring later.
How Does the AIFC Compare to Other Digital-Asset Licensing Hubs?
The AIFC is not a direct substitute for a MiCA CASP authorisation in the EU, a VARA licence in Dubai or a Payment Services Act licence from the MAS in Singapore. Each regime serves different client geographies, imposes different substance requirements and carries different reputational weight with institutional counterparties. The relevant question for most operators is not which jurisdiction wins, but which combination of licences serves their user base, satisfies their banking partners and is achievable within their timeline and budget.
The AIFC is structurally positioned as a hub for Central Asia and the CIS market. Operators targeting users in Kazakhstan, Uzbekistan, Azerbaijan and neighbouring states will find AFSA authorisation more directly relevant than a VARA licence, which is scoped to the Dubai market, or a MiCA CASP authorisation, which is designed for EU users.
Compared to EU MiCA, the AIFC offers a more tractable application process for smaller teams without deep EU regulatory counsel on staff, and a regulatory environment that – while demanding – has shorter historical precedent to navigate. MiCA, by contrast, offers EU-wide passporting: a CASP authorised under MiCA by an EU national competent authority may passport into all EU and EEA member states without re-authorisation. The AIFC does not replicate that geographic reach.
Compared to VARA in Dubai, the AIFC offers a common-law legal system and English-language courts without the operator needing to establish a Dubai mainland entity. VARA's activity-based rulebooks are detailed and demanding; the AIFC's framework, while rigorous, is grounded in a legal tradition that many international operators and their counsel find more familiar.
For a fund manager based in Europe seeking a regulated structure for a digital-asset fund targeting Central Asian and Middle Eastern institutional investors, a combination of an AIFC licence and a Cayman fund vehicle – with allied counsel engaged in each jurisdiction – is a pattern we work through regularly. For a stablecoin issuer needing EU market access, MiCA is unavoidable; the AIFC is complementary, not sufficient on its own.
If your application has stalled or a previous structure failed to open banking, a second review can surface the structural reason. Our licensing desk is available at Map your options.
What Are the Most Common Mistakes Operators Make in AIFC Licensing?
The most consistent mistake we encounter is treating the AIFC licence application as a document-filing exercise rather than a regulatory assessment of the business. AFSA reads the business plan. Inconsistencies between the stated business model, the compliance framework, the personnel structure and the capital position are identified – and they generate queries that extend timelines and occasionally result in refusals.
A second common error is the assumption that a single offshore licence is sufficient to serve clients across multiple jurisdictions. An AIFC licence authorises regulated activities within and from the AIFC. It does not authorise the operator to solicit retail clients in Germany, Singapore or the United Kingdom without those jurisdictions' own regulatory permissions. Operators that run their growth strategy on a single-licence model regularly find that banking partners, institutional clients and correspondent exchanges ask for local regulatory status that the AIFC licence alone does not provide.
The third error is under-investing in the compliance officer role. AFSA expects a qualified, engaged compliance officer – not a nominal appointment. In practice, this often means engaging a specialist compliance professional in the AIFC region rather than relying on a group compliance function based elsewhere. The cost of getting this wrong is not just a queried application: it is a condition attached to the licence that constrains the business after authorisation.
The fourth error is sequential working: applying for the licence first, addressing banking second, and considering tax last. The three must be planned together. We have seen operators receive AFSA authorisation and then spend six months searching for a bank willing to service the entity – during which time the licence generates zero revenue and the team's momentum is lost.
Self-Assessment: Is Your Business Ready for an AIFC Digital-Asset Application?
Before engaging AFSA, operators should work through the following readiness indicators. These are not a substitute for legal advice but they identify the gaps that typically require the most preparation time.
- Is the proposed AIFC entity correctly structured – with an appropriate constitutional document, a defined board and a clear group ownership chart?
- Is there a qualified compliance officer identified, with a demonstrable track record in financial services compliance relevant to digital assets?
- Does the business plan accurately describe the proposed activities, client types, revenue model and technology infrastructure?
- Is the AML/CFT framework documented, risk-based and adapted to the specific business model – not a generic template?
- Has the Travel Rule compliance approach been identified, including the technical solution and the list of counterparties it covers?
- Has a banking path been identified, with at least one institution indicating openness to onboarding a digital-asset business with an AIFC profile?
- Has the capital position been confirmed against current AFSA requirements for the relevant licence category?
- Has a tax review been conducted to confirm the AIFC entity's position within the group structure?
If the answer to two or more of these questions is "not yet", the application is not ready to file. Filing prematurely consumes AFSA's review bandwidth, generates queries and resets the effective timeline.
Related at OBOLUS
- Licensing and Registration for Digital-Asset Businesses – our full-service approach to VASP and CASP authorisation across 70+ jurisdictions
- Digital-Asset Custody Authorisation in Singapore – how the MAS Payment Services Act applies to custody service providers
- MiCA Whitepaper Review: The Compliance Burden in Practice – practical analysis of the EU whitepaper obligation for token issuers
FAQ
How long does a crypto licence take to obtain?
Timelines vary by jurisdiction, licence category and the completeness of the application. In the AIFC, a well-prepared application for a straightforward structure can progress through AFSA's review in a matter of weeks to a few months; more complex applications or those requiring additional information rounds take longer. Across other leading hubs, timelines range from several weeks for a BVI VASP registration to six months or more for a MiCA CASP authorisation. Filing a deficient application resets the clock. The most reliable way to reduce elapsed time is to submit a complete, internally consistent package from the outset.
Which jurisdiction is best for licensing my crypto business?
There is no universal best jurisdiction. The right choice depends on the operator's target user geography, the activities it proposes to carry on, its capital position, its banking needs and its appetite for ongoing compliance cost. The AIFC suits operators targeting Central Asia and CIS markets who need a common-law regulatory base. VARA in Dubai suits operators focused on the MENA region. A MiCA CASP authorisation in an EU member state is required for operators that need to solicit EU retail clients. Most scaling businesses ultimately need more than one licence – the question is which to obtain first and in what sequence.
Do I need a separate custody licence?
In most regulated jurisdictions – including the AIFC, MiCA, the MAS Payment Services Act regime and VARA – custody of client digital assets is a separately regulated activity. A trading facility or exchange licence does not, by itself, authorise the licensee to safeguard client assets. Operators that hold client digital assets must confirm whether a standalone custody authorisation is required in the relevant jurisdiction. Failing to do so is one of the most common under-licensing errors in digital-asset businesses, and it creates both a regulatory breach and a potential liability to clients.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence, banking and tax stack across operating, custody and payment layers before you commit – structuring those three workstreams as a single mandate rather than three disconnected engagements. To discuss your AIFC application or multi-jurisdiction structure, contact info@oboluslaw.com or reach us at t.me/oboluslaw.
By Aisha Tan, Licensing and Jurisdictions Analyst – specialising in digital-asset authorisation across the AIFC, VARA, MAS and EU MiCA regimes, with a focus on multi-jurisdiction licence stacks for exchanges and custodians.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.