EST · MMXXVI
Home/Jurisdictions/Switzerland/Digital-asset custody authorisation in Switzerland
Licensing & Registration

Digital-asset custody authorisation in Switzerland

Digital-asset custody authorisation in Switzerland. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

Custodying digital assets in Switzerland requires regulatory authorisation, and the consequences of operating without it are immediate and severe. A business holding client crypto-assets without the correct FINMA authorisation faces enforcement action, account freezures and the near-certain loss of Swiss banking relationships. As custody obligations tighten across every major hub, getting the structure right before client onboarding is not procedural caution – it is commercial survival.

Switzerland regulates digital-asset custody (the holding of cryptographic keys or assets on behalf of clients) as a financial service. FINMA (the Swiss Financial Market Supervisory Authority) governs the activity, and the applicable regime depends on how the custody service is structured, what assets are held, and whether the activity is combined with other services such as trading or lending. Most inbound operators need either a banking licence, a FinTech licence, or – where custody is bundled with securities functions – a securities firm authorisation.

This page sets out the regulated basis, the applicable FINMA licence routes, the cross-border realities for an inbound operator, and the decision point that determines which path your build must follow.

Why custody is regulated in Switzerland – and what triggers the requirement

Digital-asset custody is a regulated activity in Switzerland when a business holds client assets or controls the private keys on behalf of third parties. The key trigger is client-asset exposure: if a counterparty can lose cryptographic access because of your operational failure or insolvency, FINMA treats the activity as requiring authorisation. This is not a marginal reading – FINMA has consistently applied a substance-over-form approach, meaning the legal label a business places on its service is far less important than the economic reality of what it does.

Switzerland's token taxonomy – which distinguishes payment tokens, utility tokens and asset tokens – also matters for custody because asset tokens and payment tokens with investment characteristics attract securities-layer obligations on top of the base custody requirement. An operator custodying tokenised equities or structured products sits in a different regulatory perimeter than one custodying pure payment-layer assets such as Bitcoin or Ether.

The cross-border dimension sharpens this quickly. A business incorporated in a non-Swiss jurisdiction but offering Swiss-resident clients a custody service will, in FINMA's analysis, be conducting regulated activity in Switzerland. We regularly advise operators who assumed that an offshore domicile insulated them from Swiss authorisation requirements – it does not, and FINMA has issued public guidance confirming that the place of service delivery, not the place of incorporation, is the relevant test.

What are the FINMA licence routes for digital-asset custody?

Three principal FINMA authorisation routes apply to digital-asset custody businesses, and the correct path depends on the volume of client funds held and whether custody is bundled with other financial services.

The FinTech licence was designed for innovators operating below the threshold of a full banking licence. It permits the acceptance of public deposits up to a specified ceiling for innovation-led services and covers safeguarding and custody activity within that ceiling. It carries lower capital requirements and a proportionate regulatory burden, and it has become the entry route of choice for pure-play digital-asset custodians whose client base and asset volume sit within the applicable ceiling. Critically, a FinTech licence does not permit the reinvestment or on-lending of client assets – the business model must be genuinely custodial, not quasi-banking.

The banking licence is the appropriate route for a custodian whose client asset volumes exceed the FinTech ceiling, whose model contemplates any form of lending against or use of client assets, or whose counterparty base includes institutional clients expecting full prudential-grade safeguards. Swiss banking authorisation carries materially higher minimum capital requirements, governance expectations and ongoing reporting obligations. It is the benchmark that global institutional investors and prime brokerage clients require, and operators building at that scale should plan for it from the outset.

A securities firm authorisation applies where the custody service is bundled with trading in tokenised securities, issuing or underwriting activity, or portfolio management over asset tokens. FINMA's token taxonomy determines whether the assets involved are "securities" for this purpose – and that analysis is not always straightforward, particularly for tokens with hybrid characteristics.

In our practice, we see the most common structuring error at this exact decision point: founders plan for the FinTech licence and build an asset book that pushes them into banking territory before launch. The fix is upstream diligence, not a retrofit.

Contact OBOLUS before you commit to a licence route. The process above describes the standard path. Your facts – the entity, the asset types, the client base, the banking – change the analysis materially. For a scoped assessment of your custody structure, contact OBOLUS at info@oboluslaw.com.

What does the FINMA authorisation application process involve?

A FINMA authorisation application for digital-asset custody is a structured process with defined phases: pre-consultation, formal submission, assessment and – where FINMA requires it – supplemental inquiry before authorisation is granted or conditioned.

The pre-consultation phase is not optional in practice. FINMA expects applicants to engage with its supervisory team before formal submission, particularly for novel business models. This preliminary dialogue surfaces the classification questions early – asset taxonomy, activity perimeter, group structure – and reduces the risk of a formal submission being returned for structural reconfiguration. Operators who skip pre-consultation typically face longer overall timelines, not shorter ones.

The formal application requires a detailed business plan, ownership and governance documentation, a risk and compliance framework, capital adequacy evidence, fit-and-proper assessments for key personnel, and – for custody specifically – a safeguarding and segregation policy covering how client assets are held, how private keys are managed (hot vs cold, custodian vs sub-custodian), and what happens to client assets on insolvency. FINMA's safeguarding expectations for digital-asset custody have become progressively more detailed; the documentation standard now approaches that of a traditional securities custodian.

The overall authorisation timeline varies by licence type, complexity and the completeness of the submission. For a FinTech licence, the process typically runs a matter of months from a complete, well-prepared filing. A banking licence application is more demanding and the timeline reflects that. These figures are qualitative because FINMA does not publish fixed processing periods, and the applicant's preparation quality is the dominant variable – a well-constructed file moves faster.

One practical point that applicants consistently underestimate: Swiss banking access for a digital-asset business is a parallel workstream, not a downstream consequence of FINMA authorisation. Swiss banks remain selective about digital-asset custodians, and securing a banking relationship while the FINMA file is open requires a separate commercial and compliance engagement. We have seen operators receive authorisation and then spend additional months resolving banking access – the correct approach is to run both tracks simultaneously.

AML, the Travel Rule and ongoing compliance obligations for Swiss custodians

Swiss digital-asset custodians operate within a mature AML/CFT regime that tracks the FATF Recommendations, including Recommendation 15 on virtual assets. Switzerland's AML framework requires affiliation with a self-regulatory organisation (SRO) recognised by FINMA, or direct FINMA supervision, as the compliance baseline. This obligation applies before authorisation is granted – SRO affiliation is typically a condition precedent to a FinTech or banking application, not an afterthought.

The Travel Rule (the obligation to pass originator and beneficiary data with a virtual-asset transfer) applies to Swiss VASPs above the applicable threshold. The specific data threshold is set by the applicable regulations and varies slightly depending on whether the counterparty is another regulated VASP or an unhosted wallet. Swiss implementation of the Travel Rule is enforced by FINMA and the relevant SRO, and non-compliance at this level generates supervisory findings that can affect an authorisation's conditions.

For cross-border operators, the Travel Rule creates an immediate operational design question: what technology stack handles the data exchange with overseas VASPs, how are unhosted wallet interactions documented, and how does the compliance posture hold in the event of a counterparty in a jurisdiction with a divergent Travel Rule threshold? These are not theoretical questions – they arise in practice on the first day of live operations, and FINMA expects answers in the application file, not post-authorisation.

Ongoing FINMA supervision for authorised custodians includes periodic reporting, annual audit by a FINMA-approved audit firm, and event-driven notifications for material changes to the business or its risk profile. Swiss regulatory capital must be maintained at all times, not merely at the point of authorisation. Operators managing a multi-jurisdictional custody stack should plan Swiss reporting obligations into their operational infrastructure from day one.

How does cross-border structure interact with tax and banking for a Swiss custodian?

For a business entering Switzerland as a foreign operator, the legal entity question sits at the intersection of FINMA authorisation, Swiss tax treatment and banking access – and the three do not always point to the same structure.

FINMA generally requires the authorised entity to be a Swiss-incorporated company or a Swiss branch of a foreign firm with adequate local governance. A pure foreign entity cannot hold a Swiss FinTech or banking licence. The practical consequence is that an inbound operator must establish a Swiss legal presence, which creates Swiss corporate tax filing obligations, Swiss withholding tax considerations on income flows, and – for groups with entities in multiple jurisdictions – transfer pricing and substance requirements that must be managed as a matter of course.

Switzerland's corporate tax rate varies by canton and commune. Several cantons have pursued competitive digital-asset and fintech clusters – Zug (the so-called "Crypto Valley") being the most prominent – but the tax rate differential between cantons has narrowed following the OECD minimum tax initiative, which Switzerland implemented for large corporate groups. For smaller operators outside that threshold, canton selection remains a meaningful decision. The tax question is jurisdiction-specific and should be modelled for the actual projected revenue flows, not estimated generically.

Banking access deserves its own paragraph. Swiss banks have historically been the gold standard for digital-asset business banking, but many have simultaneously been the most selective. The banks that actively serve digital-asset custodians have their own AML/KYC requirements, often more granular than FINMA's minimum, and a business plan that satisfies FINMA may not immediately satisfy a bank's credit and compliance committee. Early engagement – ideally before the FINMA application is filed – is the only way to de-risk this track. Allied counsel in the relevant jurisdiction can facilitate banking introductions as part of the overall establishment process.

A micro-matter from our recent cross-border practice: in a recent authorisation matter, a payments infrastructure operator sought to provide digital-asset custody alongside an existing e-money function. The question was whether the combined activity triggered a banking licence or could be structured within the FinTech perimeter. We mapped the asset-by-asset classification, identified that one asset class in the portfolio carried securities characteristics, and restructured the custody scope to maintain FinTech eligibility while establishing a securities-firm vehicle for the residual activity. The operator was able to proceed without the capital burden of full banking authorisation, and the dual-entity structure was accepted by FINMA at the pre-consultation stage.

How does Switzerland compare with other custody authorisation hubs?

Switzerland occupies a distinct position in the global custody authorisation environment. Its combination of legal certainty, FATF-compliant AML infrastructure, established institutional investor base and FINMA's well-developed digital-asset supervisory approach makes it one of a small number of jurisdictions where a custody authorisation carries genuine institutional credibility. The comparable hubs – Singapore under the MAS Payment Services Act, Hong Kong under the SFC VASP regime, and the UAE under either VARA or the ADGM/FSRA framework – each offer distinct advantages.

Singapore's DPT licensing regime under the MAS Payment Services Act is procedurally mature and benefits from strong judicial infrastructure for disputes. Hong Kong's SFC VATP regime is newer but backed by active regulatory commitment. The VARA regime in Dubai offers activity-based licences calibrated to the specific service bundle – useful for combined custody and trading operations. None of these regimes is universally superior; the right choice depends on where the clients are, where the banking lives, and where the founders can establish credible local governance.

Switzerland's comparative edge is institutional trust. For a custodian whose target market is family offices, private banks or institutional fund managers – particularly European clients – Swiss authorisation carries a weight that a newer regime cannot yet replicate. The trade-off is higher regulatory cost and a more demanding application process. For operators who need speed-to-market above institutional credibility, a different hub may be the right first step.

A common assumption among operators we advise is that a single offshore licence is sufficient to serve clients globally. In our practice, this is rarely true for custody. Most institutional clients – and many regulators – require the custody activity to be conducted by an entity locally authorised in the client's jurisdiction of residence, or at minimum in a jurisdiction whose regime is recognised as equivalent. Switzerland's bilateral recognition footprint is strong, but it does not eliminate local-authorisation requirements in every client jurisdiction. A realistic custody build plans for multiple licensing nodes, not one.

If a prior application stalled or a banking relationship closed, a structural review can identify the reason and the route forward. Contact OBOLUS at info@oboluslaw.com to open the conversation.

Who specifically needs digital-asset custody authorisation in Switzerland?

The question of who needs Swiss custody authorisation is answered by reference to two axes: what the business does with client assets, and where the client relationship is managed.

A business needs Swiss custody authorisation if it holds digital-asset private keys on behalf of third parties as a commercial activity, if it manages discretionary digital-asset portfolios for clients, or if it operates an omnibus custody account structure in which client assets are commingled at the on-chain level and clients hold only a contractual claim against the operator. Each of these structures creates the client-asset exposure that FINMA treats as the authorisation trigger.

A business does not automatically need Swiss authorisation if its custody activity is purely self-custodial (holding assets for its own account), if it acts as a pure technology provider with no legal title to or control over client assets, or if it operates in a genuinely non-Swiss market with no Swiss-resident clients and no Swiss infrastructure. The practical difficulty is that these carve-outs are not self-executing: each requires a documented legal analysis demonstrating that the activity falls outside the perimeter, and that analysis must be robust enough to withstand FINMA scrutiny if the question is ever raised.

For inbound operators, the threshold question is often whether their existing offshore licence suffices. Under FINMA's analysis, it generally does not if Swiss clients are being onboarded or Swiss infrastructure (banking, operations) is being used. The prudent step is a written legal opinion on the perimeter question before onboarding begins – not after a FINMA inquiry letter arrives.

Decision matrix: which custody licence profile fits your business?

Profile A – Pure-play digital-asset custodian, launch-stage, client assets below the FinTech ceiling, payment and utility tokens only, no lending or investment activity: the FinTech licence is the correct first instrument. Timeline to authorisation is a matter of months from a complete application. Key risk: asset book growing beyond the ceiling before the second-year review, triggering an upgrade requirement.

Profile B – Institutional custodian, large-scale client asset base, client mix includes banks, funds or family offices, or the model contemplates any use or lending of client assets: the banking licence is the correct authorisation. Timeline is materially longer and capital requirements are substantially higher. Key risk: underestimating the governance and reporting burden that Swiss banking supervision imposes on a digital-native business without legacy banking infrastructure.

Profile C – Combined custody and securities function, portfolio includes asset tokens or tokenised securities, or business offers custody alongside trading in instruments that FINMA classifies as securities: a securities firm authorisation, or a dual-entity structure separating the custody and securities functions. Timeline and cost depend on the final perimeter determination. Key risk: proceeding on the assumption that all tokens held are payment or utility tokens without formal FINMA confirmation of the classification.

Profile D – Foreign operator serving Swiss clients from outside Switzerland, existing offshore authorisation, exploring whether Swiss authorisation is required: a written perimeter opinion is the correct first step, not an application. The opinion may confirm that existing authorisation and operational controls are sufficient; it may identify that Swiss authorisation is required before further Swiss onboarding. Key risk: continuing Swiss onboarding without that opinion and receiving a FINMA enforcement letter instead.

In our cross-border practice, we map the licence, banking and tax stack together before the client commits to a jurisdiction. The three interact, and optimising for one while ignoring the others produces structures that work on paper but fail in practice.

Related at OBOLUS

FAQ

How long does a crypto licence take to obtain?

Timeline varies significantly by jurisdiction and licence type. In Switzerland, a FinTech authorisation from a complete, well-prepared filing typically takes a matter of months; a banking licence takes materially longer. The applicant's preparation quality is the dominant variable – FINMA will return an incomplete file, restarting the clock. Pre-consultation with the regulator before formal submission is strongly advisable and generally shortens the overall process.

Which jurisdiction is best for licensing my crypto business?

There is no universally correct answer. Switzerland offers institutional credibility and a mature regulatory regime, making it well-suited for custodians targeting European institutional clients. Singapore, Hong Kong, Dubai's VARA regime and the ADGM in Abu Dhabi each serve different operator profiles and client bases. The right jurisdiction depends on where your clients are, where your banking sits, and what your business model requires. A multi-node licence stack is often more appropriate than a single-jurisdiction approach.

Do I need a separate custody licence?

In Switzerland, custody of digital assets for third parties triggers a distinct FINMA authorisation requirement. Whether that is the FinTech licence, a banking licence or a securities firm authorisation depends on asset types, volumes and whether custody is bundled with other regulated activities. Simply holding a trading or exchange licence does not cover custody. A written perimeter analysis is the correct first step before onboarding custodial clients.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance obligations that sit around them. Digital assets are the entirety of our practice. We map the licence, banking and tax stack across operating, custody and payment layers before you commit to a structure – not after the first enforcement letter arrives. To discuss your situation, contact info@oboluslaw.com.

By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in FINMA authorisation pathways and multi-jurisdictional licence structuring for digital-asset custodians and exchanges.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours