EST · MMXXVI
Home/Jurisdictions/Liechtenstein/Client funds safeguarding in Liechtenstein
Banking, Payments & EMI Onboarding

Client funds safeguarding in Liechtenstein

Client funds safeguarding in Liechtenstein. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

With regulatory scrutiny of digital-asset businesses tightening across Europe, getting client funds safeguarding right is not a compliance formality – it is the structural condition on which your banking, your licence and your cross-border operations all depend. Liechtenstein sits at a distinctive intersection: a full member of the European Economic Area, home to a mature regulatory regime under the Financial Market Authority Liechtenstein (FMA), and one of the few jurisdictions that enacted dedicated blockchain legislation before the EU's MiCA (Markets in Crypto-Assets Regulation) framework crystallised. For digital-asset businesses operating between Liechtenstein and the broader EU/EEA, the safeguarding question is both technically precise and operationally urgent.

Client funds safeguarding in Liechtenstein means holding client assets – whether fiat, e-money or tokenised value – in a manner that isolates them from the firm's own capital, ensures they survive insolvency, and satisfies the FMA's conduct expectations. The applicable regime draws on Liechtenstein's Token and Trusted Technology Service Provider Act (TVTG), its Payment Institutions Act implementing the EU Payment Services Directive, and the e-money provisions that mirror the EU's e-money framework. A business that mischaracterises its safeguarding obligations – or relies on a single offshore registration without regard to where users and funds actually sit – exposes itself to enforcement, frozen payment rails and account closure.

This page sets out the regulated basis, the practical process, the cross-border interaction with tax and banking, and the decision point for an inbound operator building or reviewing a Liechtenstein structure.

What is the regulated basis for safeguarding client funds in Liechtenstein?

Client funds safeguarding in Liechtenstein rests on two parallel regulatory pillars: the FMA's supervision of payment institutions and e-money institutions, and the TVTG regime governing token service providers. Both regimes require that client assets be held separately from proprietary assets and be recoverable on insolvency without becoming part of the general estate.

Under the payment institution and EMI frameworks, a safeguarding obligation applies from the moment a firm receives funds for the purpose of executing a payment transaction. The firm must either deposit those funds in a segregated account with a credit institution or invest them in secure, liquid, low-risk assets as defined by the applicable regulations. The FMA supervises compliance, requires ongoing reporting, and expects firms to document the safeguarding method clearly in their licence application and subsequent periodic filings.

The TVTG – Liechtenstein's foundational blockchain law – goes further in one important respect. It establishes a property-law container for tokens: the concept of a token as a container for rights. When client assets are represented as tokens on a distributed ledger, the token holder's rights follow the token, and the legal basis for segregation is grounded in property law, not merely contract. That distinction matters in a recovery or insolvency scenario: a token representing a client's fiat claim against the firm is not simply an unsecured creditor position. Liechtenstein was among the first jurisdictions in the EEA to provide this statutory property-law basis for tokenised rights, making it a structurally sound domicile for custody and safeguarding arrangements.

For businesses that hold both fiat and crypto: the two regimes interact. An operator that accepts fiat, converts it to a stablecoin for internal settlement, and maintains a redemption obligation in fiat must satisfy safeguarding requirements at both the entry and exit points of that value flow. In our cross-border practice, we have seen operators overlook the fiat-leg safeguarding requirement while focusing exclusively on the custody mechanics of the crypto position. Both legs need to be addressed.

Which businesses need a safeguarding structure in Liechtenstein?

Any firm that holds client funds – whether as e-money, payment balances or tokenised assets – while providing services to EEA customers needs to address safeguarding under the applicable Liechtenstein or EEA regime. The obligation is activity-driven, not entity-type-driven.

The businesses we regularly advise in this context fall into four broad categories. First, exchanges and trading platforms that hold fiat balances pending execution – these are almost always within scope of the payment institution or e-money regime, even if they self-describe as crypto-only. Second, custodians holding digital assets on behalf of clients – TVTG registration as a token custodian is the primary route. Third, payment-adjacent DeFi protocols with a fiat on-ramp or off-ramp – the on/off-ramp operator holds the regulatory exposure, not the protocol itself. Fourth, token issuers that receive subscriber funds prior to token delivery – these face a safeguarding question that intersects with the MiCA whitepaper regime for asset-referenced and e-money tokens.

A common assumption we encounter is that a single offshore registration – in a non-EEA jurisdiction with lighter requirements – is sufficient to serve European clients. That assumption does not survive contact with FMA scrutiny or EEA passporting reality. The question is not only where the entity is registered, but where the users are, where the funds flow and where the firm operates in fact. Regulators increasingly look through structures to the underlying activity.

For a scoped assessment of your safeguarding structure, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity type, the user base, the banking relationships – change the analysis materially. Map your options.

How does the FMA application process work for a payment or EMI licence?

A Liechtenstein payment institution or e-money institution licence application is submitted to the FMA and follows a structured pre-application, application and review process, with the timeline varying by the completeness of the submission and the complexity of the business model.

Pre-application engagement with the FMA is standard practice and strongly advisable. The FMA accepts formal pre-application meetings in which the proposed business model, the safeguarding method, the AML/CFT programme and the governance structure are discussed before the full dossier is filed. This stage materially reduces rework. The formal application then requires, at minimum: a detailed programme of operations; a safeguarding plan specifying the method, the account structure and the credit institution relationship; an AML/CFT policy meeting the requirements under Liechtenstein's Due Diligence Act; governance documentation including fitness-and-propriety evidence for directors and qualifying shareholders; and, where applicable, a business plan with financial projections.

The FMA's assessment period runs from the point of a complete submission. Incomplete applications reset the clock. Operators regularly underestimate the time needed to establish the banking relationship required for the safeguarding account before the licence is granted – and some banks will not open a safeguarding account until the licence is in prospect or granted. Managing that sequencing is one of the more practically challenging elements of the process. In our cross-border practice, we address the banking relationship in parallel with the licence preparation, not after it.

For businesses structured as token service providers under the TVTG rather than as payment institutions, the registration process with the FMA differs in scope but shares the core demands: beneficial ownership disclosure, a description of the token service, AML/CFT documentation, and evidence of organisational fitness. TVTG registration does not grant passporting rights across the EEA – payment institution or EMI authorisation remains the route to cross-border service provision under the EEA umbrella.

How does Liechtenstein's safeguarding regime interact with cross-border tax and banking?

Liechtenstein's EEA membership means a payment institution or EMI authorised by the FMA can passport its services into EU member states without local re-licensing – a structural advantage that is absent from most offshore alternatives and distinguishes Liechtenstein from Switzerland, which sits outside the EEA despite its geographic proximity.

The cross-border layer adds complexity in three directions. First, banking: a Liechtenstein-licensed firm needs a bank account in a jurisdiction whose banks are willing to maintain it. Correspondent banking for digital-asset businesses remains constrained. The FMA's credibility does help – Liechtenstein-licensed entities are generally viewed more favourably by EEA correspondent banks than entities from non-EEA offshore registries. Even so, onboarding a bank as the safeguarding institution requires a detailed AML/CFT presentation and often a personal relationship with the account-opening team. We regularly advise on structuring that presentation. Second, tax: Liechtenstein has competitive corporate tax treatment for qualifying structures, and the interplay between where the licence sits, where management and control is exercised, and where revenue is booked determines the effective tax outcome. A Liechtenstein holding company with management exercised elsewhere may not achieve the tax outcome the founders expect. Third, the Travel Rule (the obligation to pass originator and beneficiary data with a virtual asset transfer): Liechtenstein transposes the FATF Travel Rule through its AML framework. An operator moving funds between Liechtenstein and other jurisdictions must ensure the counterparty VASP is Travel Rule-compliant; gaps in that chain expose both parties to regulatory risk.

For businesses sitting between Liechtenstein and non-EEA hubs – a UAE holding company with a Liechtenstein payment institution subsidiary, for instance – the legal question turns on whether the EU/EEA regulatory perimeter applies to the group's activities, not only to the licensed entity. In our practice, we see this question arise most acutely when the parent entity is providing services that, in substance, are intermediating EEA user funds even if the contractual relationship is structured offshore.

What does the AML and Travel Rule posture look like in Liechtenstein?

Liechtenstein's AML/CFT regime is grounded in its Due Diligence Act, which aligns with the FATF Recommendations and the EU's successive AML Directives. For digital-asset businesses, the key obligations are: customer due diligence (CDD) at account opening and on a risk-based ongoing basis; enhanced due diligence for higher-risk customers and transactions; suspicious activity reporting to the Financial Intelligence Unit (FIU); and, for VASPs, compliance with the Travel Rule obligation to transmit originator and beneficiary information alongside virtual asset transfers above the applicable threshold.

The Travel Rule threshold under Liechtenstein's implementation aligns with EEA-level requirements. The practical challenge for most operators is not knowing the threshold – it is building the technical and operational infrastructure to collect, transmit and receive Travel Rule data in a format that counterparty VASPs can consume. Interoperability between Travel Rule solutions remains uneven globally. An operator whose counterparties are based in jurisdictions with different technical standards or no Travel Rule requirement at all faces a compliance gap that the FMA will expect to be documented and managed, not ignored.

In our cross-border practice, we have seen FMA-supervised firms receive formal supervisory inquiry precisely because their Travel Rule programme covered outbound transfers adequately but had no documented process for unhosted wallets or for transfers received from non-compliant jurisdictions. A complete programme addresses both directions of the flow.

A recent example: restructuring a safeguarding failure before enforcement

In a recent matter, a digital-asset payments business operating under a TVTG registration had been commingling client fiat balances in an operating account, relying on a contractual undertaking to clients rather than a structural segregation arrangement. The FMA had issued a supervisory letter questioning the arrangement. We were instructed to analyse the exposure and restructure the safeguarding model before the supervisory process escalated. Working through the applicable payment institution requirements and the existing banking relationship, we designed a dual-account structure – a segregated safeguarding account with a credit institution, clearly documented in the firm's updated safeguarding plan – and assisted with the response to the FMA. The supervisory matter was resolved without formal enforcement proceedings. The firm subsequently filed a payment institution licence application on the corrected basis. The structural error, caught early, was remediable. Left unaddressed, it would have exposed the firm to licence suspension and client claims.

Which operator profile should choose a Liechtenstein safeguarding structure?

Liechtenstein is the right jurisdiction for a specific set of operator profiles; it is not the default answer for every digital-asset business seeking European access.

Profile A – a digital-asset exchange or custodian building for EEA distribution with a preference for a smaller, responsive regulator rather than a large-jurisdiction NCA – will find the FMA's accessibility and the TVTG's property-law foundation genuinely useful. The EEA passport is the prize; the timeline and the banking search are the costs. Profile B – a payment institution or EMI seeking a fast EU entry and planning to passport into Germany, France and the Nordics – will compare Liechtenstein against Lithuania (where the Bank of Lithuania supervises and where MiCA CASP authorisation is available) and Malta (where the MFSA administers the transitioning VFA-to-CASP framework). Liechtenstein's structural advantage is the TVTG property-law layer for tokenised assets; Lithuania and Malta may offer faster initial registration timelines for businesses without a tokenisation use case. Profile C – a token issuer raising under MiCA – needs both the whitepaper regime and the safeguarding regime addressed simultaneously; Liechtenstein can accommodate this, but the MiCA NCA coordination question (which competent authority leads the whitepaper review for a Liechtenstein-domiciled issuer) requires early clarification with the FMA.

No single jurisdiction is universally optimal. The right answer turns on the entity structure, the user jurisdictions, the asset types, the banking relationships already in place, and the desired timeline. We map those factors before the commitment, not after.

If a prior application stalled or a banking relationship was closed, a structural review can surface the reason and identify the path forward. Contact OBOLUS at info@oboluslaw.com or message us via t.me/oboluslaw. Map your options.

A common assumption: one offshore licence is enough for global operations

A common assumption among founders entering the digital-asset space is that a single offshore registration – in a jurisdiction with lighter regulatory requirements – is sufficient to serve clients globally, including in the EEA. That assumption does not hold under scrutiny from the FMA, ESMA or the national competent authorities of EU member states.

The EEA regulatory perimeter applies to activity directed at EEA users, regardless of where the entity is incorporated. An exchange incorporated in a non-EEA jurisdiction that actively markets to and holds funds for German or French users is, in substance, operating in those jurisdictions. The question is not entity domicile; it is the location of the activity and the users. Regulators have become increasingly effective at identifying this pattern. Enforcement action – account freezes, injunctions, criminal referrals in some cases – follows the activity, not the corporate registry entry.

The correct structure for a business with EEA users is an EEA-authorised entity, properly capitalised, with a compliant safeguarding programme and a banking relationship that the authorisation can support. Liechtenstein, as an EEA member with a well-developed digital-asset legal tradition, is one of the most credible homes for that structure. The FMA is accessible and technically literate on digital-asset questions. The TVTG provides a statutory basis for tokenised assets that most EU member states lack at the domestic level. And the EEA passport enables cross-border service provision without repeated local authorisation. Those are real structural advantages – but they require a real authorisation, not a registration proxy.

Related at OBOLUS

FAQ

Why do banks close crypto company accounts?

Banks close digital-asset business accounts primarily because of perceived AML/CFT risk, regulatory uncertainty about the business model, or deficiencies in the operator's compliance documentation. A business that cannot clearly demonstrate its licence basis, its customer due diligence programme and its safeguarding structure is likely to fail the bank's onboarding risk assessment. The solution is a well-documented compliance presentation prepared before the account-opening meeting, not after the closure notice arrives. Jurisdiction of authorisation also matters: a firm licensed by the FMA or another credible EEA regulator is materially easier to bank than an unlicensed entity.

How can a VASP onboard with an EMI?

A VASP (virtual asset service provider) onboards with an EMI (e-money institution) by presenting the EMI with its regulatory status, ownership structure, AML/CFT programme and a clear description of the transaction types and volumes expected. Most EMIs have internal crypto-sector risk policies that determine whether they will accept a VASP at all. VASPs that are licensed or registered by a credible regulator – the FMA, the Bank of Lithuania, the MFSA, MAS or equivalent – face a materially lower rejection rate than unregistered operators. The onboarding process typically involves an enhanced due diligence review, a legal opinion on the VASP's regulatory status and, in some cases, an ongoing monitoring agreement. Preparation is the differentiator.

What does client-money safeguarding require?

Client-money safeguarding requires, at minimum, that funds received from clients be held in an account or investment structure that is legally separated from the firm's own assets, cannot be used for the firm's operating purposes, and will be returned to clients without passing through the general insolvency estate if the firm fails. In Liechtenstein, a payment institution or EMI must document its safeguarding method in its licence application and maintain it on an ongoing basis under FMA supervision. A TVTG token custodian satisfies the segregation requirement through the property-law structure of the token container. Both routes require a credit institution relationship and periodic reporting to the FMA.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. We map the licence stack across operating, custody and payment layers before you commit – and our disputes team coordinates freezing relief and on-chain tracing across leading common-law forums when matters escalate. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com or message us at t.me/oboluslaw.

By Victor Olsen, Regulatory & Compliance Analyst – specialising in EEA payment institution and VASP licensing, with a focus on Liechtenstein FMA applications and cross-border safeguarding structures.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours