EST · MMXXVI
Home/Jurisdictions/Kazakhstan Aifc/VASP licensing in Kazakhstan (AIFC): Legal Requirements for Businesses
Licensing & Registration

VASP licensing in Kazakhstan (AIFC): Legal Requirements for Businesses

Vasp licensing in Kazakhstan (AIFC). Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

Operating a digital-asset business without the correct authorisation in Kazakhstan's Astana International Financial Centre (AIFC) – the common-law enclave in the capital Astana – exposes an operator to enforcement action, severed banking relationships and the loss of access to a rapidly developing Central Asian market. The AIFC's regulator, the Astana Financial Services Authority (AFSA), has built a dedicated licensing regime for virtual-asset businesses that operates under English-language common law and sits entirely outside Kazakhstan's civil-law national framework. That combination is unusual in the region, and it is the primary reason inbound operators from Europe, the Gulf and East Asia have chosen the AIFC as their Central Asian hub. This page maps the regulated perimeter, the application process, the cross-border tax and banking considerations, and the decision factors a general counsel needs before committing to a structure.

What the AFSA Regime Covers – and Who Must Be Authorised

Any business carrying on regulated digital-asset activities within or from the AIFC must hold the appropriate authorisation issued by AFSA before commencing operations. The AIFC framework defines a range of regulated activities that touch virtual assets, including operating a digital-asset trading facility, providing custody of digital assets, and acting as an intermediary in digital-asset transactions. Classification is activity-based, not entity-type-based: a single legal entity offering trading, custody and order routing may need authorisation across more than one category.

The AFSA regime applies to AIFC-incorporated or AIFC-registered entities conducting those activities. It does not extend automatically to a holding company sitting outside the AIFC perimeter – though the regulator looks at substance, not just form. An entity incorporated in a foreign jurisdiction but directing regulated activity from within the AIFC cannot rely on an offshore wrapper to avoid AFSA oversight. In our practice, we see this substance-over-structure point arise most often when a group tries to place the licensed entity in a low-cost offshore jurisdiction while running operations from the AIFC. AFSA is alert to that approach and applies a genuine-presence test.

The applicable regime also incorporates FATF Recommendation 15 standards, including the Travel Rule – the obligation to pass originator and beneficiary data alongside a virtual-asset transfer. Operators licensed by AFSA are expected to implement compliant Travel Rule procedures from day one. That obligation sits alongside standard AML/CFT programme requirements, customer due-diligence obligations and suspicious-transaction reporting duties.

For a scoped assessment of whether your activity requires AFSA authorisation and across which licence categories, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity, the user base, the banking – change the analysis.

How Does the AIFC Common-Law Environment Differ From Kazakhstan's National Law?

The AIFC operates under its own independent legal system, modelled on English common law and administered in English, making it structurally distinct from Kazakhstan's civil-law national jurisdiction. AIFC Acts and Regulations are the primary source of law inside the financial centre. The AIFC Court handles disputes between AIFC participants and has jurisdiction to enforce judgments across a range of forums. This matters commercially: an exchange licensing itself inside the AIFC gains access to an internationally recognised dispute-resolution environment, not only a regulatory endorsement.

For digital-asset businesses, the practical implications are significant. Contract enforceability, custody arrangements, and the treatment of digital-asset collateral can all be litigated under a common-law framework that has developed bodies of precedent analogous to English law. Outside the AIFC perimeter, Kazakhstan's civil code applies and the crypto-specific legal architecture is less developed. A business that needs to resolve a counterparty dispute, enforce a security interest or manage an insolvency involving digital assets will find the AIFC environment materially more predictable.

The AIFC's court system also provides a gateway. Decisions of the AIFC Court are recognised across a growing network of bilateral arrangements, and the AIFC Arbitration Centre offers a private-dispute alternative. Operators we advise who are building institutional-grade infrastructure – prime brokerage, lending facilities, structured products – consistently cite the legal environment as the decisive factor over and above the regulatory licence itself.

What Does the AFSA Application Process Look Like?

An AFSA licence application follows a structured pre-application and formal-submission sequence that requires the applicant to demonstrate both its legal eligibility and its operational readiness before AFSA will issue an in-principle approval. The process broadly involves a preliminary engagement with AFSA, preparation and submission of a formal application file, a regulatory assessment period and, where successful, conditional approval followed by licensing.

Pre-application engagement is substantive, not merely procedural. AFSA expects applicants to articulate the specific regulated activities they intend to conduct, the technology infrastructure supporting those activities, the AML/CFT framework in place, and the qualifications of the key individuals who will be approved persons. Controllers and senior managers are individually vetted. A Compliance Officer and a Money Laundering Reporting Officer must be nominated and approved; AFSA has rejected applications where these roles were under-resourced or filled by individuals whose experience was not aligned to digital-asset operations.

The formal application file typically includes constitutional documents, a business plan with financial projections, a regulatory business plan describing the target market and product, AML policies and procedures, IT security documentation, and a description of custody arrangements where applicable. Capital adequacy requirements are set by AFSA and vary by the category of regulated activity sought; applicants should obtain the current figures directly from AFSA or through qualified counsel, as these thresholds are periodically revised and should not be relied upon from secondary sources.

Timeline varies by the complexity of the application and AFSA's current workload. In our experience, straightforward single-activity applications with well-prepared files move more quickly than multi-activity applications or those requiring pre-clearance of novel product structures. Applicants should plan for a process measured in months rather than weeks, and should not commit to go-live dates before at least an in-principle approval is received.

In a recent licensing matter, a fintech operator based in the Gulf sought to establish a digital-asset trading facility in the AIFC to serve institutional counterparties across Central Asia and the MENA region. We structured the AIFC entity, prepared the regulatory business plan and AML framework, and managed the pre-application engagement with AFSA. The in-principle approval was received within the expected window, with no material qualification requests on the AML documentation – a result the client attributed partly to the depth of the pre-submission review.

Cross-Border Tax and Banking Considerations

AIFC-incorporated entities benefit from a specific tax regime that is separate from Kazakhstan's general tax code – AIFC participants operating within the perimeter have historically benefited from defined exemptions, though the precise scope and duration of those exemptions should always be verified against current AIFC Acts and confirmed with qualified Kazakhstani tax counsel, as the regime has evolved. The cross-border tax analysis matters significantly for a holding structure: the AIFC entity is only one layer, and where a parent holds it from a European, Gulf or offshore jurisdiction, the group-level tax position must be modelled before incorporation.

Banking for AIFC-licensed digital-asset businesses is a material operational constraint. Access to correspondent banking in US dollars and euros requires a bank willing to provide services to a crypto-licensed entity in Kazakhstan. Several international banks active in the AIFC market have developed onboarding processes for AFSA-licensed operators, but the due-diligence process is detailed and the timeline for account opening can run in parallel with – or extend beyond – the regulatory authorisation period. Operators we advise routinely underestimate this. A business that receives its AFSA licence but cannot open a functional USD account has a regulatory authorisation and an operational problem simultaneously.

The banking challenge is often a function of the parent's jurisdiction and UBO profile. A holding company domiciled in a Financial Action Task Force-listed jurisdiction, or whose ultimate beneficial owners have exposure to sanctioned entities or jurisdictions, will face disproportionate friction regardless of the AIFC licence. Structuring the holding layer correctly before the banking application – not after the account is declined – is a material part of what we do. We regularly work alongside allied counsel in the relevant jurisdiction to ensure the group structure supports rather than complicates the banking relationship.

How Does the AIFC Compare With Other Licensing Hubs for an Inbound Operator?

The AIFC occupies a specific position in the global licensing environment: a common-law, English-language, regulated hub in a geography – Central Asia – where no comparable alternative exists. That specificity is its primary commercial advantage and, simultaneously, its primary limitation. For a business whose strategic logic is access to Kazakhstan, Uzbekistan, and the surrounding region, the AIFC is structurally the right answer. For a business whose primary market is the EU, the Gulf or Southeast Asia, the AIFC licence alone does not provide sufficient market access and a multi-hub structure is required.

Compared with VARA in Dubai, the AIFC offers a simpler initial fee and capital environment for certain activity categories, but Dubai's VARA licence carries broader regional recognition and a more developed institutional-counterparty ecosystem. Compared with the MiCA CASP authorisation available through an EU member state such as Lithuania or Malta, the AIFC does not provide EU-wide passporting – an operator licensed by AFSA cannot passport to serve EU retail clients under MiCA's framework. That distinction is decisive for any business with a material EU user base.

For businesses sitting between two hubs – say, a Gulf-domiciled group wanting to serve Central Asian institutional clients while retaining a UAE base – the AIFC can function as a complementary licence in a multi-jurisdiction structure rather than a standalone solution. We regularly advise on structures that combine an AIFC trading-facility licence with a VARA advisory or broker-dealer registration, or an AIFC custody authorisation layered alongside an ADGM (FSRA) permission. Each combination has its own regulatory-coordination and compliance-cost implications.

A common assumption among operators is that a single offshore licence – whether from the BVI, the Cayman Islands or another low-cost jurisdiction – is sufficient to serve clients globally. It is not. Regulators in every major hub increasingly focus on where clients are located, not only where the legal entity sits. An operator serving Kazakhstani institutional clients from an offshore shell without local authorisation faces both AIFC enforcement risk and the risk that counterparties and banks will decline to deal with an unregulated entity. The AIFC licence addresses the first problem; the multi-hub structure addresses the second.

If a prior application stalled or a banking relationship was closed, a second read can surface the structural reason and the route back. Write to OBOLUS at info@oboluslaw.com.

Self-Assessment Checklist for Inbound Operators

Before engaging AFSA in a pre-application meeting, an inbound operator should be able to answer the following questions clearly. Gaps in any of these areas will surface during the regulatory assessment and are more efficiently resolved before submission.

  • Which specific regulated activities under the AIFC framework will the entity conduct, and in which sequence?
  • Is the proposed holding structure – parent, intermediate holding company, operating entity – transparent, and does it map cleanly to the UBO register?
  • Who will fill the Compliance Officer and MLRO roles, and do those individuals have documented digital-asset experience?
  • Is the technology infrastructure – matching engine, custody system, transaction monitoring – documented and auditable?
  • Has the AML/CFT programme been adapted to the AIFC regulatory requirements, including Travel Rule implementation?
  • Has a bank been identified that is willing, in principle, to open accounts for an AIFC-licensed digital-asset entity with this UBO profile?
  • Has the tax position of the AIFC entity, and the group holding it, been modelled for the projected transaction volume?

This checklist is not exhaustive. It reflects the questions AFSA most commonly raises early in the assessment process, based on our cross-border practice. Each answer generates its own legal and structural follow-on questions – which is why we map the licence, banking and tax stack before a client commits to an AIFC structure rather than during the application.

Decision Profile: Which Operator Should Choose the AIFC?

The AIFC licence is the right primary jurisdiction for a defined set of operator profiles, and a poor standalone choice for others. The following profiles reflect the analysis we apply when a client first asks whether Kazakhstan should anchor their structure.

Profile A – Central Asian market entry: A business whose primary commercial logic is accessing Kazakhstan and neighbouring markets. For this profile, the AIFC trading-facility or custody licence is the primary regulated instrument, and the timeline and capital requirements are calibrated to that specific market. The key risk is banking access, which must be solved in parallel.

Profile B – Regional hub for a Gulf or CIS holding group: A group already holding a Gulf or CIS regulated entity that wants to add Central Asian reach without replicating its entire regulatory stack. For this profile, the AIFC can function as a complementary permission in a multi-hub structure. The key risk is the interaction between the AIFC regime and the home jurisdiction's regulatory expectations, including treatment of inter-group flows and consolidated AML oversight.

Profile C – EU or UK operator seeking a standalone non-EU licence: A business based in the EU or UK that wants a lower-cost regulated entity outside the MiCA or FCA perimeter for specific non-EU client segments. The AIFC can serve this function, but the EU or UK operator must ensure that its non-AIFC business lines remain properly authorised at home. The key risk is regulatory arbitrage scrutiny: EU and UK regulators are alert to structures that appear designed to serve EU or UK clients through a non-EU wrapper.

Profile D – Pure offshore or fund structure: A fund or holding entity with no operational staff and no intention of conducting regulated activities from within the AIFC perimeter. For this profile, an AIFC licence is generally not required and may not be available; a Cayman or BVI vehicle may be more appropriate, subject to the activity undertaken. The key risk for this profile is miscategorising an activity as non-regulated when it is in fact regulated under the AIFC framework.

Related at OBOLUS

FAQ

How long does a crypto licence take to obtain?

Timeline varies materially by jurisdiction, licence category, complexity of the applicant's structure and the regulator's current assessment workload. For an AIFC digital-asset trading-facility application with a well-prepared file, the process is typically measured in months rather than weeks. Pre-application engagement, document preparation and the regulator's formal review each consume time. Multi-activity applications or novel product structures extend the timeline further. We advise clients to plan conservatively and avoid committing to commercial go-live dates before in-principle approval is confirmed.

Which jurisdiction is best for licensing my crypto business?

There is no universal answer. The right jurisdiction turns on where your users and counterparties are located, the activities you intend to conduct, the holding structure and UBO profile, banking access, and your tax position. A business with EU retail clients needs a MiCA CASP authorisation. A business focused on Central Asian institutional counterparties may be well served by the AIFC. Most multi-market operators require licences in more than one jurisdiction. We map the full licence, banking and tax stack before recommending a structure – not after incorporation.

Do I need a separate custody licence?

In most regulated regimes, custody of digital assets on behalf of third parties is a separately regulated activity that requires its own authorisation or a specific permission added to an existing licence. Under the AIFC framework, digital-asset custody is a distinct regulated activity. Under MiCA, custody and administration of crypto-assets for clients is one of the enumerated CASP services. Under VARA in Dubai, custody is a separate licence category. Whether a business needs a standalone custody permission depends on the precise activity conducted and the jurisdiction – this is one of the first questions we map in a licensing engagement.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the entirety of our practice, and we act only for businesses. We map the licence stack across operating, custody and payment layers before you commit – so the structure you build is one you can defend to a regulator and a bank. To discuss your situation, contact info@oboluslaw.com or message us at t.me/oboluslaw.

By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in regulatory authorisation strategy for digital-asset businesses entering the AIFC, MENA and Central Asian markets.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours