Digital-asset custody licensing in Ireland
An exchange operator expanding into the EU faces a structural decision the moment custody enters the picture. Ireland accepts registrations from virtual asset service providers (VASPs – entities offering digital-asset services commercially) under the transposition of the EU Anti-Money Laundering Directives into Irish law, supervised by the Central Bank of Ireland. As the bloc's Markets in Crypto-Assets Regulation (MiCA) takes full effect, that registration pathway is converging with a deeper CASP authorisation (Crypto-Asset Service Provider) requirement that brings capital, governance and safeguarding obligations that no offshore registration replicates. The analysis below maps the regime, the process and the cross-border realities that every inbound operator must price into its decision.
What is the legal basis for digital-asset custody in Ireland?
Digital-asset custody in Ireland sits at the intersection of the Central Bank of Ireland's VASP registration regime and the incoming MiCA CASP authorisation framework. The Central Bank of Ireland became the competent authority for VASP supervision following Ireland's implementation of the relevant EU AML directives, and it is the same body that will administer MiCA authorisations for CASPs operating from Irish soil. Under the applicable VASP provisions, an entity providing custody or administration of virtual assets on behalf of third parties must register before commencing activity. Operating without that registration is a criminal matter under Irish law, and the Central Bank has the power to issue directions, impose sanctions and – in acute cases – seek court orders to halt unlicensed activity.
Custody is specifically carved out as a regulated activity. This is not a borderline question. Holding private keys, controlling wallet infrastructure or maintaining records of ownership on behalf of clients all fall within the perimeter. An entity that provides only software tools without controlling client assets sits outside the perimeter, but the line is drawn by substance, not by label. In our practice, we see operators underestimate how quickly an operational model crosses from "software provider" into "custodian" once client keys are managed on their behalf – even temporarily.
The MiCA transition matters acutely for custody businesses. Under MiCA, custody of crypto-assets is a CASP activity subject to authorisation rather than mere registration. The authorisation standard introduces minimum own-funds requirements, organisational requirements, conflicts-of-interest governance and client asset segregation obligations that represent a material uplift from the prior AML-only registration model. Ireland's national competent authority – the Central Bank – will assess authorisation applications against both the MiCA text and its own supervisory expectations, which have historically been exacting across financial services.
Who needs a custody licence – and when?
Any business that holds, stores, controls or administers digital assets on behalf of clients as a commercial activity needs to register or seek authorisation in Ireland before it commences that activity. The trigger is client-facing custody, not internal treasury management. Self-custodied wallets used solely for the operator's own assets do not trigger the requirement. The following operator profiles regularly encounter this question.
- Exchanges with hot-wallet infrastructure – an exchange that holds client assets between trades is providing custody, regardless of how briefly.
- Institutional custodians – entities offering dedicated custody as a standalone service to funds, family offices or corporates are the clearest case in scope.
- DeFi aggregators and asset managers – where the protocol takes temporary possession of client tokens to execute a strategy, a custody element typically arises.
- Payment processors – firms that hold stablecoin balances pending settlement on behalf of merchants may be custodying within the meaning of the regime.
The cross-border dimension complicates the analysis. A custodian incorporated in the BVI or Cayman Islands that actively markets to Irish-resident clients or EU-resident institutional investors does not escape the Irish/EU perimeter merely because its entity is offshore. MiCA applies on a service-to-the-EU basis. An entity relying on a non-EU registration to serve EU clients operates in a legal environment that is becoming materially more constrained with each quarter of MiCA implementation. We advise operators in this position to map their exposure before their banking relationship surfaces the issue first.
The process above describes the standard path. Your facts – the entity structure, the user base geography and your existing banking – change the analysis materially. To pressure-test your structure before you commit, message us via t.me/oboluslaw or contact OBOLUS at info@oboluslaw.com.
How does the VASP registration process work in Ireland?
The Central Bank of Ireland evaluates VASP registration applications on a fit-and-proper basis, reviewing the entity, its controllers, its business model, its AML/CFT programme and its operational readiness. The application requires a detailed submission: business plan, ownership structure, source-of-funds analysis, AML/CFT policies and procedures, risk assessments and evidence of sufficiently qualified compliance and MLRO (Money Laundering Reporting Officer) personnel.
The Central Bank applies supervisory scrutiny consistent with its approach to other regulated financial service providers. It will request clarifications. A submission that is incomplete or that describes a compliance programme in aspirational rather than operational terms will draw a request for additional information – effectively extending the timeline. Operators we advise routinely underestimate this: a registration timeline in Ireland is not measured in weeks for a materially complex custody model. The regulator's pace reflects its resources and its risk appetite, both of which have been measured rather than rapid in recent years.
Under the MiCA transition, entities registered under the prior VASP regime will be required to seek full CASP authorisation within the transition windows the legislation prescribes. The Central Bank will specify the grandfathering pathway and supplemental documentation requirements. Operators that registered early under the AML-directive-only regime should not assume that registration carries forward automatically into a full custody CASP licence. The authorisation standard is substantively higher.
From a process standpoint, the application requires:
- Pre-engagement assessment of the entity structure and group ownership chain.
- Preparation of the full AML/CFT policy suite, including Travel Rule procedures.
- Drafting of the business plan with a realistic Irish nexus (substance requirements matter).
- Individual questionnaires for all persons discharging managerial functions (PCF holders in Irish parlance).
- Submission to the Central Bank, followed by an iterative clarification phase.
- Registration confirmation – and, under MiCA, the transition to full CASP authorisation.
How does MiCA change the custody authorisation standard?
MiCA's CASP authorisation framework represents the most significant restructuring of the EU crypto-service regulatory environment since the first AML directives were extended to virtual assets. For custody businesses specifically, MiCA introduces binding safeguarding obligations: client assets must be segregated from the firm's own assets, the custody provider must adopt policies to minimise the risk of loss and it must maintain a liability framework for losses attributable to malfunctions or unauthorised access.
Ireland's Central Bank, as the Irish national competent authority under MiCA and under the oversight of ESMA (the European Securities and Markets Authority), will apply the MiCA technical standards as they are finalised by ESMA and published by the European Commission. The body of regulatory technical standards and implementing technical standards that ESMA is developing covers internal governance, capital calculation methodology and the detail of client asset protection – all of which feed directly into the Central Bank's authorisation assessment.
MiCA also introduces a passporting mechanism for CASPs. An entity authorised as a CASP in Ireland may notify other EU/EEA member states and commence activity there without a fresh authorisation in each state. For a custody provider with a pan-European institutional client base, Irish authorisation under MiCA is therefore not simply a single-market licence – it is the gateway to the entire EU/EEA single market. That passportability is a core commercial rationale for licensing through an EU hub like Ireland rather than through an offshore jurisdiction that serves no equivalent function inside the EU perimeter.
What are the cross-border tax and banking considerations?
Custody licensing and tax residency are related but distinct questions, and conflating them is one of the most common structural errors we see. An Irish-registered or Irish-authorised CASP is a regulated entity in Ireland. Its tax residence – and therefore the jurisdiction in which its profits are charged to corporate tax – depends on where its central management and control sits, where its directors make decisions and where its key functions are discharged. Ireland's corporation tax rate is well-known and has long attracted financial services firms, but the Central Bank will also scrutinise substance: a shell entity with a brass-plate office and all management decisions taken elsewhere does not satisfy Irish regulatory expectations.
Banking for crypto businesses is a parallel challenge that the licence itself does not resolve. Irish domestic banks apply their own risk appetite to digital-asset clients. An entity with Irish VASP registration or MiCA authorisation has a stronger counterargument when a bank questions its regulatory status, but it does not have a guaranteed banking relationship. In our cross-border practice, we map the banking options in parallel with the licensing timeline – waiting until authorisation is in hand to begin the banking conversation adds months to go-live.
The Travel Rule (the FATF obligation to pass originator and beneficiary data with a virtual-asset transfer) applies to Irish-regulated custodians as it does across the EU. Operational compliance requires a technical solution – a Travel Rule messaging protocol – and contractual arrangements with counterparty VASPs. Regulators in the leading EU hubs, including Ireland, increasingly expect to see a Travel Rule solution in place before authorisation is granted, not as a post-licensing afterthought.
For a business considering Ireland alongside another EU jurisdiction – Malta, Lithuania or a larger economy like Germany or the Netherlands – the analysis turns on several axes: timeline to authorisation, the Central Bank's supervisory engagement model, the substance requirements, and the quality of the Irish legal and banking infrastructure. Ireland does not operate a zero-scrutiny gateway. What it offers is a credible EU common-law jurisdiction with deep financial-services infrastructure, an English-language supervisory process and the full benefit of MiCA passporting.
A custody registration in practice
In a recent licensing matter, a digital-asset custody provider with operations in a non-EU offshore jurisdiction sought Irish VASP registration as part of a planned MiCA authorisation pathway. The entity's existing compliance programme was built against a lighter AML-only standard. We conducted a gap analysis across the AML/CFT policy suite, identified material shortfalls in the Travel Rule procedures and the MLRO appointment, and restructured the business plan to articulate a credible Irish substance position. Following an iterative clarification process with the Central Bank, the registration was confirmed. The entity then entered the MiCA pre-authorisation workstream with a compliant baseline rather than having to retrofit it under regulatory time pressure.
Which operator profile fits the Irish custody route?
Not every custody operator is the right fit for an Irish registration or MiCA authorisation. The decision is a function of the operator's client base, its institutional ambitions and its compliance capacity.
Profile A – Pan-European institutional custodian. If the client base is EU-domiciled funds, family offices and corporates, an Irish MiCA CASP authorisation is the structurally correct answer. The passporting mechanism eliminates the need for local registrations across EU states. The timeline is meaningful; the compliance investment is real. The commercial case is equally real.
Profile B – Non-EU operator with incidental EU clients. An operator whose primary market is outside the EU but who has some EU institutional clients faces a proportionality question. A full Irish MiCA authorisation is a significant undertaking. Alternatives include appointing a regulated CASP as sub-custodian for EU-client assets, or – depending on the volume and nature of the EU activity – applying for an exemption or a lighter registration where the regime permits. These options narrow as MiCA's third-country provisions are clarified.
Profile C – Start-up custody business seeking EU market entry. For a well-funded start-up with institutional ambitions, Ireland offers a common-law environment, an English-language regulatory process and a sophisticated financial services talent pool. The compliance overhead of MiCA authorisation is high, but it is the same overhead faced in any EU hub. Choosing Ireland over Lithuania or Malta is not primarily a cost question – it is a question of where the business wants to build its regulated substance for the long term.
Profile D – Exchange seeking to bring custody in-house. An exchange already registered or authorised for trading that wants to offer custody directly rather than through a third-party custodian must either extend its existing authorisation or obtain a separate custody CASP authorisation. The Central Bank will assess the combined activity against the full MiCA requirements. In our practice, the governance and capital requirements of adding custody to an exchange licence are routinely underestimated at the business planning stage.
If a prior application stalled or a banking relationship closed, a second read can surface the structural reason and the route back. Contact OBOLUS at info@oboluslaw.com to scope a remediation assessment.
What are the most common mistakes in Irish custody licence applications?
A common assumption among operators entering the Irish market is that VASP registration is a bureaucratic formality comparable to a simple business registration. It is not. The Central Bank applies a financial-services standard. Applications that treat the MLRO role as a part-time administrative appointment, that describe AML policies in generic terms without jurisdiction-specific calibration, or that show no credible Irish substance in the board or management structure are returned for material revision. Revision cycles add time – and time in this market is a competitive cost.
A second common error is treating the current AML-registration as a durable licensing position. Operators that registered under the prior VASP regime and have not begun planning their MiCA CASP transition are exposed. The transition windows are not indefinite, and the Central Bank will not grandfather a registration that was adequate under the AML-only standard into a full custody CASP authorisation without a substantive new application process.
Third, operators frequently underestimate the banking risk. A custody business whose banking arrangements are informal, or that relies on a single domestic account with no institutional-grade custody banking solution, will struggle to satisfy the Central Bank's client-asset safeguarding expectations under MiCA. Banking and licensing are a parallel process, not a sequential one.
How do AML and Travel Rule obligations apply to Irish custodians?
Irish digital-asset custodians are subject to the full FATF Recommendation 15 regime as transposed into EU law. The Travel Rule requires that originator and beneficiary data accompany virtual-asset transfers above the applicable threshold. For a custodian managing institutional client wallets, this means maintaining a Travel Rule messaging infrastructure, screening counterpart VASPs for compliance status and establishing contractual frameworks for data exchange.
ESMA and the European Banking Authority are developing detailed technical standards on Travel Rule implementation under MiCA. Operators entering the Irish market should build their technical architecture against the MiCA Travel Rule standards rather than legacy national implementations, which in some jurisdictions applied lower data-transmission thresholds or narrower scope. The direction of travel is toward stricter, more uniform EU-wide application.
Sanctions screening is a parallel obligation. Irish custodians must screen against EU sanctions lists as well as relevant international designations. For a custodian holding client assets, the ability of token issuers like Circle (USDC) and Tether (USDT) to freeze tokens at the contract level on receipt of a law-enforcement or sanctions designation is an operational reality that feeds into the custodian's own risk management and client disclosure frameworks.
Related at OBOLUS
- Licensing and registration for digital-asset businesses – the full OBOLUS licensing practice across 70+ jurisdictions.
- VARA licence application under heightened scrutiny – navigating a VARA application when the regulator requires additional disclosure.
- DAO legal wrapper in Abu Dhabi Global Market (ADGM) – structuring a DAO legal entity in the ADGM common-law environment.
FAQ
How long does a crypto licence take to obtain?
In Ireland, a VASP registration or MiCA CASP authorisation timeline depends on the completeness of the application, the complexity of the business model and the Central Bank's current processing capacity. A well-prepared submission for a straightforward model may progress in a matter of months; complex custody structures with multi-layered ownership chains or deficient compliance programmes routinely take considerably longer. Planning on a minimum of several months – and building that into go-to-market timelines – is prudent. Across other EU hubs, timelines vary materially by regulator and by the volume of applications in the queue.
Which jurisdiction is best for licensing my crypto business?
There is no universal answer. Ireland offers MiCA passporting, a common-law framework and a deep financial-services environment; it suits institutional custody providers targeting the EU market. Lithuania has historically offered faster registration timelines under MiCA transition. Malta retains its VFA-to-MiCA infrastructure. Offshore jurisdictions like the BVI or Cayman Islands serve fund structuring and privacy use-cases but do not provide EU market access. The right jurisdiction is a function of your client base, banking relationships, substance capacity and growth horizon. We map that decision as a structured analysis before you commit to any single path.
Do I need a separate custody licence?
Under MiCA, custody and administration of crypto-assets on behalf of clients is a distinct regulated activity. An entity authorised only for exchange or transfer services may not provide custody as a bundled offering without the custody CASP authorisation. Whether you need a separate entity or an extension of an existing authorisation depends on the Central Bank's approach to combined-activity applications and your group structure. In most practical cases, an exchange seeking to add custody in-house will require either a fresh authorisation or a formal variation of its existing one. Both involve substantive review.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit, so you understand the total regulatory footprint – not just the filing. Our disputes team coordinates freezing relief and on-chain tracing across leading common-law forums when enforcement action is needed. To discuss your situation, contact info@oboluslaw.com.
By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in EU and offshore VASP and CASP authorisation strategy for exchanges, custodians and institutional digital-asset managers.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.