Singapore's custody authorisation: the regulated basis
Digital-asset custody in Singapore is a regulated activity under the Payment Services Act (the PSA), administered by the Monetary Authority of Singapore (MAS). A business that safeguards or administers digital payment tokens on behalf of customers – holding private keys, managing wallets, or settling positions – requires a Major Payment Institution licence at a minimum, unless a specific exemption applies. Custody is not a residual category in Singapore; MAS treats it as a core financial-services function, and the consequences of operating without authorisation are severe: stop orders, civil penalties, and reputational damage that closes banking relationships across the region.
With MAS tightening its supervisory posture across digital payment token services, inbound businesses can no longer rely on the assumption that a custody operation is incidental to an exchange licence held elsewhere. The regime requires a local authorisation, local governance, and increasingly, local substance. This page sets out the regulated perimeter, the application path, the cross-border tax and banking interaction, and the decision point at which external counsel becomes essential.
Who needs a custody authorisation in Singapore?
Any person carrying on a business of providing digital payment token services from or in Singapore must hold the appropriate licence under the PSA, and custody is one of the defined payment service activities in the legislation. The trigger is functional, not formal: if your platform holds user keys, manages segregated wallets, or acts as an intermediary safeguarding digital assets between trades or transfers, the activity falls within the regulated perimeter. The entity's place of incorporation is secondary. What matters to MAS is where the activity is directed and where it is performed.
Inbound operators face a particularly acute question. A business incorporated in the British Virgin Islands or the Cayman Islands that onboards Singapore-resident customers and holds their assets in custody is likely conducting a regulated activity in Singapore, regardless of the hosting entity's domicile. We regularly advise exactly this profile of client: a fund or exchange operator that assumed its offshore structure insulated it from the PSA, only to discover that MAS takes an activity-based, not entity-based, approach to jurisdiction.
The key threshold distinction is between a Standard Payment Institution (SPI) and a Major Payment Institution (MPI). Custody services that exceed the transaction volume or asset-value thresholds set by MAS trigger the MPI regime. Both licence tiers require registration, fit-and-proper assessment, and compliance programmes. The MPI adds materially more demanding obligations – capital, business conduct, safeguarding of customer assets, and audit requirements. Since those thresholds are set by regulation and subject to revision, we recommend verifying the current figures against MAS guidance at the time of application.
What does the MAS authorisation process involve?
The authorisation process for a digital payment token custody service runs through MAS's licensing gate, and the first submission is the document that sets the tone for the entire relationship with the regulator. MAS expects a complete application: business plan, AML/CFT policies, ownership and control structure, key-management personnel CVs, and evidence of the technical and operational infrastructure supporting the custody function. An incomplete or poorly sequenced filing does not result in a request for information – it results in delay or rejection.
In our practice, applications that move efficiently through the MAS process share several characteristics. The applicant has done a pre-application engagement, where possible, to surface regulator expectations before filing. The AML/CFT framework is not generic – it maps to the specific custody workflow, addressing key custody, wallet segregation, and transaction monitoring in the context of digital-payment-token services. And the governance structure reflects local substance: a responsible executive resident in Singapore, board-level accountability for compliance, and documented escalation procedures.
MAS evaluates both the entity and the individuals. The fit-and-proper standard applied to significant shareholders, directors, and key management personnel is rigorous. MAS will look beyond the Singapore applicant to the ultimate beneficial owners. A structure with opaque holding layers or UBOs in high-risk jurisdictions materially complicates the application, and in some cases makes the process unworkable without prior restructuring. Timing from a complete filing to a decision varies. MAS does not publish a fixed clock; operators in the market have experienced timelines that stretch from several months to over a year, depending on the complexity of the application and the regulator's supervisory caseload.
A process step that applicants consistently underestimate is the technology audit. MAS expects demonstration – not merely assertion – that the custody infrastructure meets the relevant technology risk management guidelines it has published. For key management specifically, operators must address cold-storage architecture, key ceremony procedures, and multi-authorisation controls. Applicants who treat the technology schedule as a formality rather than a substantive filing element typically receive a material query or a request for additional information.
For a scoped assessment of your Singapore custody application, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity structure, the user base, the beneficial-ownership chain, the technical architecture – change the analysis materially, and an early review is far less costly than a mid-application structural change.
AML/CFT obligations and the Travel Rule in Singapore
A licensed digital payment token custodian in Singapore operates within a full AML/CFT compliance framework anchored to FATF Recommendation 15 on virtual assets. MAS has implemented the Travel Rule – the obligation to transmit originator and beneficiary information alongside a digital-asset transfer – for digital payment token service providers, and a custody operator whose platform initiates or receives transfers is squarely in scope.
The practical burden is significant. The custodian must verify that counterpart institutions are themselves licensed or registered in their home jurisdiction, maintain the data infrastructure to transmit and receive Travel Rule information, and monitor for counterparties in non-compliant jurisdictions. For an inbound operator whose users span multiple time zones, the Travel Rule is not a compliance checklist item – it is a live operational obligation that affects every transfer workflow.
MAS has also aligned its customer due-diligence expectations with the FATF grey-listing risk framework. Accounts linked to high-risk jurisdictions trigger enhanced due diligence, and MAS supervisors review CDD records during examinations. In our cross-border practice, we have seen applications stall when the applicant's projected user base included a material proportion of customers from jurisdictions where AML oversight of digital assets was assessed as deficient. Addressing that risk proactively – through geographic restrictions or enhanced-CDD protocols – is part of sound application preparation.
Cross-border banking and tax interaction
Securing the licence is the visible milestone; securing banking is the operational one, and the two are related but distinct processes. Major Singapore banks have become more willing to open accounts for licensed PSA entities, but the relationship is not automatic. Banks conduct their own AML risk assessments, and a custody business with a complex cross-border ownership structure, or one whose projected revenues derive substantially from jurisdictions with weak AML supervision, will face prolonged onboarding or rejection.
The practical sequence we recommend is to run banking outreach in parallel with the licensing process, not after it. A letter of intent or a conditional offer from a bank, evidencing that the institution is prepared to provide settlement accounts to the licensed entity, can itself support the MAS application. Conversely, an application that launches without any banking relationship in view may clear MAS only to find itself commercially inoperable.
On the tax side, Singapore offers a well-developed corporate tax environment, but digital-asset businesses must make deliberate choices. The GST (goods and services tax) treatment of digital payment token transactions has been addressed in MAS and IRAS guidance, and transactions in digital payment tokens that qualify as a medium of exchange are generally outside the scope of GST. Custody fees, management fees, and ancillary service revenues are a different question. The structure – whether the custodian holds assets in its own name or as a trustee, and how fee income is characterised – affects both the Singapore tax position and the cross-border withholding-tax exposure where custodied assets generate yield.
For businesses building a multi-hub structure – custody in Singapore, exchange operations in another jurisdiction, and treasury in a third – the interaction between the regulatory capital requirements, the banking relationships, and the transfer-pricing position across those hubs requires coordinated analysis. Allied counsel in the relevant jurisdictions need to be in the room at the structure-design stage, not called in to fix problems after commitment.
If your custody structure spans multiple jurisdictions and you have already encountered banking friction or a regulator query, write to us at info@oboluslaw.com. A second read can surface the structural reason and the route forward.
How a custody licence question changes in practice
In a recent cross-border licensing matter, a Southeast Asian asset manager had been operating a crypto-custody function for institutional clients under the assumption that its activities were ancillary to a funds management regime and did not independently engage the PSA. When MAS issued a supervisory query, the firm faced the prospect of either unwinding its custody operations or applying on an emergency basis without a structured filing. We were engaged to assess the position, map the gap between the existing compliance framework and the MAS custody requirements, and sequence an application that addressed the regulator's concerns about the prior period of operation. The filing was structured to demonstrate proactive remediation rather than reactivity. The matter was resolved without enforcement action, and the entity proceeded to authorisation. The key lesson: the question of whether an activity is regulated is answered by what you do, not by how you have classified it internally.
Which profile needs which licence tier?
The PSA tier appropriate for a custody operation depends on the volume and nature of the business. Three profiles commonly present themselves in our practice.
A custody-only operator – safeguarding digital assets for institutional clients, with no payment-transfer or exchange function – will generally assess whether its transaction volumes require an MPI licence or whether an SPI can accommodate the business during a ramp-up phase. The risk in choosing SPI is that growth triggers an upgrade obligation, and the MPI application mid-stream is more disruptive than the initial choice of the correct tier.
An exchange operator adding custody – a trading platform that wants to hold user assets between trades rather than returning them to user-controlled wallets – already holds a DPT service licence for the trading activity. The addition of custody services may require a licence variation rather than a fresh application, but MAS must be notified and the variation approved. Operating an expanded service before the variation is granted is a compliance breach. Indicative timeline for a variation: several weeks to a few months, depending on MAS's assessment of the incremental risk.
An inbound institutional custodian – a bank or trust company from another jurisdiction seeking to offer custody services to Singapore-domiciled funds – faces the most complex path. It must decide whether to establish a licensed Singapore entity, seek a representative office first to build the MAS relationship, or work through a locally licensed sub-custodian. The right answer depends on the volume of expected business, the home-jurisdiction regulatory capital it already holds, and whether MAS has an equivalence or co-operation arrangement with the home regulator.
What are the most common mistakes in Singapore custody applications?
The single most common mistake we encounter is treating the PSA application as a compliance exercise rather than a regulatory relationship exercise. MAS examiners are experienced in digital-asset business models. An application that does not show a genuine understanding of how the applicant's specific business model generates risk – and how the proposed controls address that specific risk – is treated with scepticism.
A second recurring error is the misalignment between the legal entity structure and the operational reality. If the entity holding the MAS licence is a shell and the actual custody infrastructure sits in a parent or affiliate offshore, MAS will identify that during review. The licensed entity must have genuine operational control over the functions it is licensed to perform.
A third mistake is failing to address the exit plan. MAS expects applicants to demonstrate what happens to customer assets if the business fails. A credible custody business continuity and wind-down plan is not a boilerplate annex – it is part of the substantive assessment of the business's fitness to hold third-party assets.
A common assumption is that a single PSA licence covers every digital-asset activity the business intends to conduct. It does not. An operator that holds user assets, executes trades on their behalf, provides investment advice, and transfers funds between wallets is likely engaged in multiple distinct regulated activities, each with its own licensing requirement or at minimum its own compliance obligation within the licence. Mapping those activities to the correct PSA service categories – and confirming whether any activity falls outside the PSA into securities regulation administered by the MAS in its securities supervision capacity – is a foundational step.
Related at OBOLUS
Related at OBOLUS
- Licensing and registration for digital-asset businesses – the full licence-stack assessment across operating, custody and payment layers.
- Digital-asset licensing in Gibraltar – DLT Provider authorisation under the Gibraltar Financial Services Commission.
- Token issuance and offering rules in the British Virgin Islands – the BVI FSC VASP Act and the token-offering perimeter for offshore structures.
FAQ
How long does a crypto licence take to obtain?
Timelines vary by jurisdiction, licence tier, and application quality. In Singapore, a PSA Major Payment Institution application that is complete and well-prepared can take several months to over a year from submission to decision, depending on MAS's supervisory caseload and the complexity of the applicant's structure. Incomplete filings, governance queries, or technology-risk concerns extend that timeline materially. Early preparation – before the application window opens – is the single most effective way to compress it.
Which jurisdiction is best for licensing my crypto business?
There is no universal answer. The right jurisdiction depends on your target users, banking relationships, product type, capital position, and appetite for ongoing regulatory engagement. Singapore is well-regarded for custody and exchange operations serving institutional clients in Asia. Other operators choose VARA in Dubai, MiCA authorisation in the EU, or ADGM in Abu Dhabi. The decision matrix involves the licence, the banking, the tax position, and where your users are – not just the licence in isolation. We map that stack before you commit.
Do I need a separate custody licence?
In Singapore, custody of digital payment tokens is a distinct regulated activity under the PSA. An exchange operator whose licence does not cover custody is not automatically authorised to hold customer assets between trades. Whether you need a separate licence, a licence variation, or whether custody is covered within your existing authorisation depends on how MAS has scoped your permitted services. Assuming coverage without verifying it against your actual licence terms is one of the more consequential compliance errors we encounter.
About OBOLUS
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance obligations that sit around them. Digital assets are the entirety of our practice. We map the licence stack across operating, custody and payment layers before you commit – because the cost of an application error is always higher than the cost of getting the analysis right at the outset. Digital assets are the whole of our practice, and we act only for businesses. To discuss your situation, contact info@oboluslaw.com or reach us via t.me/oboluslaw.
By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in PSA authorisation, MAS supervisory engagement, and inbound digital-asset licensing structures for Asia-Pacific operators.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.