EST · MMXXVI
Home/Jurisdictions/Uae Adgm/Digital-asset custody authorisation in Abu Dhabi Global Market (ADGM)
Licensing & Registration

Digital-asset custody authorisation in Abu Dhabi Global Market (ADGM)

Digital-asset custody authorisation in Abu Dhabi Global Market (ADGM). Cross-border digital-asset legal counsel for business – licensing, disputes and structuri

Operating a digital-asset custody business without the right authorisation in Abu Dhabi Global Market exposes the firm to enforcement action, frozen banking rails and reputational damage that can take years to undo. ADGM's Financial Services Regulatory Authority (FSRA) regulates virtual-asset custody as a distinct financial-services activity, and an inbound operator must hold a formal licence before accepting client assets. The analysis below maps the regulated basis, the application path, the cross-border considerations and the practical decision points an operator faces before committing to the ADGM jurisdiction.

Why ADGM custody authorisation matters for inbound operators

ADGM-based custody is a regulated activity, not a registration formality. The FSRA, operating within Abu Dhabi Global Market, applies a principles-based but substantive regime: an entity that holds, stores or safeguards digital-asset keys on behalf of clients requires a financial-services permission under the FSRA's virtual-asset framework before it takes a single client instruction. That threshold applies regardless of where the client is located. An operator that has a crypto licence (a VASP registration or regulatory authorisation) in another jurisdiction – say, an EU MiCA CASP authorisation or a Singapore Payment Services Act licence – cannot rely on that permission when onboarding clients through an ADGM entity. The FSRA does not recognise automatic passporting from outside the UAE free-zone perimeter.

For institutional custodians, fund administrators and exchanges that want to offer custody as part of a broader service stack, ADGM sits alongside DIFC (governed by the DFSA, not the FSRA) as one of two major Abu Dhabi and Dubai financial free-zone options. ADGM operates under a common-law legal system modelled on English law, which matters for contractual enforceability, insolvency segregation and investor confidence. In our practice, institutional investors and family offices seeking UAE-based custody overwhelmingly prefer the common-law framework and the English-law governed contracts that ADGM allows.

The process above describes the standard path. Your facts – the entity, the user base, the banking – change the analysis materially. If you are assessing ADGM as the custody layer in a multi-jurisdictional structure, contact OBOLUS at Map your options for a scoped review before you proceed.

What is the FSRA virtual-asset framework for custody?

The FSRA operates a dedicated virtual-asset regime that classifies activities in a manner broadly analogous to traditional financial-services licensing, but with asset-specific safeguarding expectations layered on top. Custody of virtual assets sits within the regulated-activities catalogue: holding or controlling virtual assets on behalf of another person, including managing private keys, qualifies as a regulated activity under the ADGM Financial Services and Markets Regulations as applied to the virtual-asset sector. The FSRA has also published sector-specific guidance that addresses wallet architecture, key-management standards, hot-cold storage ratios and operational resilience – expectations that go well beyond the threshold question of whether a licence is needed.

The FSRA's concept of a recognised virtual asset is worth noting here. Not every token is automatically eligible to be held under a standard custody permission; the FSRA maintains a list of assets it recognises for regulated activity purposes. An operator seeking to custody tokens outside that list faces a separate recognition process. In practice this means the due-diligence exercise for a custody applicant covers both the entity (ownership, governance, capital, controls) and the asset (technical characteristics, liquidity, market infrastructure). We regularly advise custodians to front-load the asset-eligibility analysis before drafting the application, because a late-stage challenge on asset recognition extends the timeline considerably.

Who needs a custody authorisation in ADGM?

Any entity incorporated or registered in ADGM that holds virtual-asset keys or manages virtual assets on behalf of third parties must hold a custody authorisation from the FSRA. That obligation extends to: exchanges offering custody as a collateral service; fund administrators holding assets for digital-asset funds domiciled in ADGM; custodians acting for family offices or institutional investors with UAE-nexus structures; and wallet providers where the service model involves key management rather than user self-custody.

Two edge cases arise regularly. First, an exchange operator that holds client assets only briefly during settlement – so-called pass-through custody – may still fall within the regulated perimeter. The FSRA's test is functional, not definitional: if client assets are at risk during the period of operator control, the custody-risk element is engaged. Second, a technology vendor providing software infrastructure to a licensed custodian does not itself need a custody licence, but contractual and operational segregation between the vendor and the regulated entity must be demonstrable to the FSRA during inspection. We have seen examinations focus precisely on this vendor-boundary question in recent years, particularly as institutional sub-custody models have grown more common across the UAE.

How does the ADGM custody application process work?

The ADGM custody authorisation process runs through the FSRA and follows a structured multi-stage pathway that experienced practitioners describe as thorough but predictable when preparation is disciplined. The broad sequence is: pre-application engagement with the FSRA; formal application submission (including regulatory business plan, key-management documentation, governance pack and financial-resources analysis); FSRA assessment and query rounds; in-principle approval; and final authorisation once any pre-authorisation conditions are met.

Pre-application engagement is not optional in substance, even if it is not formally mandatory. The FSRA invests significant time in understanding the operator's model before a formal application is logged. Operators that skip or abbreviate this stage routinely face longer query cycles later. In our practice, a well-prepared pre-application meeting – covering the operating model, the asset scope, the ownership structure and the key personnel – substantially shortens the overall timeline. Overall, applicants should model the process as taking a number of months from pre-application through to authorisation, with the length varying by the complexity of the model and the completeness of the submission; consult current FSRA guidance for indicative timelines applicable at the time of your application.

Key documentation includes: a regulatory business plan; policies and procedures for AML/CFT, covering the Travel Rule (the obligation to pass originator and beneficiary data with a virtual-asset transfer) and sanctions screening; governance and management-information frameworks; a technology and operational resilience assessment; financial projections; and details of key individuals subject to the FSRA's fit-and-proper assessment. The FSRA will assess each proposed approved individual separately, which means that candidate selection and preparation is a critical path item from the outset.

What are the capital and safeguarding requirements?

The FSRA sets financial-resource requirements for custody authorisation that vary by the scope and scale of the proposed activity. Because those figures are subject to regulatory update, operators should treat the current FSRA rulebooks and any FSRA guidance as the authoritative source; this page does not state specific capital thresholds, which can change and must be verified against current requirements at the time of application. What is settled in principle is the structure: the FSRA expects base own-funds capital, and may impose additional requirements tied to the value of assets under custody or the risk profile of the operator's technology stack.

Safeguarding expectations are substantive. The FSRA's virtual-asset framework requires physical and logical segregation of client assets from the custodian's proprietary holdings, documented key-management procedures that describe generation, storage and recovery of private keys, and an operational continuity plan that addresses key-loss and business-interruption scenarios. For multi-signature architectures and institutional sub-custody arrangements, the FSRA expects the applicant to document the contractual and technical basis for client-asset segregation at each layer. These expectations broadly align with the direction of travel in other leading regimes – MiCA's safeguarding provisions for CASPs and the FCA's custody-client-asset rules point in the same direction – which creates a degree of harmonisation for operators managing multi-jurisdictional licence stacks.

How does ADGM custody interact with banking and tax across borders?

The cross-border reality of an ADGM-based custodian is more complex than the licence question alone. Banking access, corporate tax treatment and the position of clients in other jurisdictions each create parallel workstreams that, in our experience, determine whether the structure is operationally viable before they determine whether it is legally compliant.

On banking: ADGM-licensed entities generally find UAE banking access more structured than their offshore counterparts, because the FSRA licence provides a regulatory credential that correspondent banks recognise. That said, banks apply their own enhanced due-diligence processes to virtual-asset businesses, and a custody-only entity that relies on omnibus-account structures for fiat settlement will face questions about the underlying client pool and transaction monitoring. We structure banking engagement alongside the licence application, not after it, because the timeline for account opening at a UAE bank can run in parallel with the FSRA process and should not become the post-licence bottleneck.

On tax: the UAE introduced a corporate-tax regime applicable to businesses in the ADGM perimeter, and the treatment of custody fee income, interest on reserves and any token-denominated gains requires analysis under both UAE corporate tax law and the tax law of the jurisdictions where clients are located. For family offices and fund structures using ADGM custody, the interaction with the OECD Pillar Two global minimum-tax framework and the CRS (Common Reporting Standard) reporting obligations of the custodian each demand specific attention. We advise operators to treat the tax analysis as inseparable from the licensing analysis rather than a downstream task, because structural choices made during the ADGM incorporation and licence design stage – entity type, fee model, reserve management – have tax consequences that are difficult to unwind later.

If a prior application stalled or a banking relationship was closed, the structural reason is usually identifiable. To map the ADGM licence, banking and tax stack as an integrated mandate, write to Map your options.

Which operator profiles are best suited to ADGM custody authorisation?

ADGM custody authorisation is the appropriate instrument for a defined set of operator profiles. The following outlines the principal decision branches.

Profile A – Institutional sub-custodian serving Gulf-region investors: An entity whose client base is primarily Gulf Cooperation Council institutional investors or family offices, where clients expect regulated, segregated custody under a common-law framework, and where contractual enforceability under English-law-modelled ADGM rules is a requirement. This profile benefits most from ADGM's common-law system, the FSRA's recognition by institutional counterparties, and the UAE's network of bilateral investment treaties. The key risk is timeline: a complex sub-custody model with multiple token classes and multiple approved individuals takes longer to process, and the operator should not promise go-live dates to clients before the authorisation is in hand.

Profile B – Exchange operator adding custody as a service layer: An exchange already licensed elsewhere – for example, under the FSRA's own exchange regime, under VARA in mainland Dubai, or under MiCA in the EU – that seeks to offer custody as a separate regulated service to UAE-based clients. This profile can leverage existing governance and AML infrastructure, which the FSRA will credit in its assessment, but must still demonstrate that the custody function is operationally and financially ring-fenced from the exchange activity. The key risk is scope creep: regulators expect a custody permission to reflect a custody business, not a bundled exchange-and-custody structure where the lines blur.

Profile C – Fund administrator or prime broker entering the UAE market: An entity that primarily serves digital-asset funds and requires a UAE-nexus regulated custody layer to service ADGM-domiciled funds or Abu Dhabi-based LPs. This profile often involves allied counsel in multiple jurisdictions – the fund-formation jurisdiction, the investor jurisdictions and ADGM itself – and the licence design must account for each layer. The tax and regulatory reporting obligations are heaviest for this profile, given the CRS obligations and the institutional clients' own regulatory requirements in their home jurisdictions.

What are the most common mistakes in ADGM custody applications?

A common assumption is that the governance documentation prepared for another licence – an EU MiCA authorisation or a Singapore MAS application – can be repackaged for the FSRA with minor amendments. In our practice, that approach reliably triggers extended query cycles. The FSRA has its own expectations regarding management-information structures, key-individual responsibilities and operational resilience documentation that do not map neatly onto MiCA or MAS templates. The conceptual framework is similar; the implementation detail is not. Operators that front-load a gap analysis between their existing compliance library and FSRA-specific expectations reduce both query cycles and timeline.

A second mistake is treating asset-recognition as a background task. Applicants that submit an application scoped around tokens that are not yet on the FSRA's recognised-virtual-asset list without a parallel recognition strategy effectively build a condition into their own authorisation that delays the commercial launch. The recognition process and the authorisation process should be managed concurrently, and the application narrative should address the asset-recognition pathway explicitly.

Third, key-individual capacity is routinely underestimated. The FSRA's fit-and-proper process for approved individuals is thorough; it involves background checks, regulatory reference requests and, in some cases, interviews. Where a senior individual holds equivalent approved-person status in another jurisdiction, the FSRA will note that, but it does not short-circuit its own assessment. Firms that identify their proposed approved individuals late in the process, or that propose candidates with complex prior regulatory histories, should build additional time into their project plans.

In a recent licensing matter, we acted for a digital-asset fund administrator seeking ADGM custody authorisation to service institutional clients across the Gulf. The entity had an existing compliance framework built around an EU CASP authorisation. We mapped the gap between that framework and FSRA expectations in the pre-application phase, restructured the key-management documentation to meet ADGM's segregation standards, and coordinated the approved-individual submissions across three proposed senior officers. The authorisation was obtained within a commercially acceptable window, and the entity launched custody operations for its first institutional clients in the same quarter.

Related at OBOLUS

FAQ

How long does a crypto licence take to obtain?

Timeline depends on jurisdiction, licence category and the complexity of the applicant's model. In ADGM, the FSRA process runs through pre-application engagement, formal submission, query rounds and conditions-satisfaction before final authorisation. Operators with well-prepared submissions and clearly scoped business plans typically reach authorisation faster than those who treat preparation as a post-submission exercise. A realistic planning assumption is several months; consult current FSRA guidance for indicative figures applicable at the time of your application.

Which jurisdiction is best for licensing my crypto business?

There is no single best jurisdiction. The right answer turns on where your clients are, where your banking will sit, what activities you will conduct, your capital position and your risk appetite for regulatory scrutiny. ADGM suits operators that need a common-law framework, Gulf-region institutional credibility and a well-developed regulated virtual-asset perimeter. Other profiles point to MiCA, VARA, the Singapore Payment Services Act or an offshore VASP registration. The correct answer is a multi-axis analysis, not a single recommendation.

Do I need a separate custody licence?

In ADGM and most flagship regimes, custody is a distinct regulated activity that requires its own permission, even where the operator holds a separate exchange or broker-dealer authorisation. The FSRA treats custody as operationally and financially ring-fenced from trading activity. An operator that holds client assets as part of an exchange service without a standalone custody authorisation may find itself outside the regulated perimeter for that specific activity. The prudent approach is to assess the custody obligation at the same time as the primary licence, not after.

About OBOLUS. OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit – and we structure licensing, banking and tax as one mandate rather than three disconnected workstreams. To discuss your situation, contact info@oboluslaw.com or reach us via t.me/oboluslaw.

By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in ADGM, VARA and Gulf-region regulatory authorisation for digital-asset businesses.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours