EST · MMXXVI
Home/Services/Licensing Registration/Digital-asset custody licensing for Established Operators
Licensing & Registration

Digital-asset custody licensing for Established Operators

Digital-asset custody licensing for Established Operators. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to

Established operators building or scaling a custody business face a precise legal question: which regulatory authorisation is required, in which jurisdiction, and how does it interact with the licences already held? The answer turns on the activities performed, the assets held, and where the clients sit – not on the label the business applies to itself. Digital-asset custody licensing – the regulatory authorisation that permits a firm to hold or safeguard virtual assets (crypto-assets and their associated private keys) on behalf of clients – sits within a tightening multi-jurisdictional regime. VARA in Dubai, the FSRA in Abu Dhabi, the SFC in Hong Kong, ESMA under MiCA across the EU, and the FCA in the UK all treat custody as a regulated activity in its own right. Getting the stack wrong costs more than the application fee: enforcement, closed banking rails and suspended operations are the realistic outcomes.

Why Is Custody Regulated as a Separate Activity?

Custody is regulated separately because the risk it creates – a third party holding client assets with the power to move or lose them – is structurally distinct from exchange or brokerage risk. Most leading regimes now require a dedicated regulatory authorisation before a firm may safeguard digital assets for clients, regardless of what other licences it holds. Under MiCA, custody and administration of crypto-assets for third parties constitutes a defined CASP (crypto-asset service provider) activity requiring standalone authorisation from the relevant national competent authority. The same logic applies under the VARA regime in Dubai, where custody forms its own activity-based licence category with its own rulebook obligations. FINMA in Switzerland and the SFC in Hong Kong both require firms to meet safeguarding, segregation and operational-resilience standards that go beyond a general trading permission.

The practical consequence for an established operator is that holding client assets under an exchange or brokerage licence – without a custody permission – puts the business out of compliance the moment assets are segregated and controlled on a client's behalf. Regulators in the leading hubs increasingly expect operators to map their actual activity against the licence they hold, not against the activity they intended to perform when they first applied.

In our cross-border practice, we regularly advise operators who discover mid-audit that their existing VASP registration did not cover custody as then performed. The gap is rarely intentional. The licensing environment moved; the business did not.

Which Regulatory Regimes Cover Digital-Asset Custody?

The principal licensing regimes for digital-asset custody are those in the EU under MiCA, Dubai under VARA, Abu Dhabi under the FSRA, Hong Kong under the SFC, Singapore under the MAS Payment Services Act, the UK under FCA registration, the BVI under the VASP Act, and the Cayman Islands under CIMA. Each treats custody as a regulated activity; each applies different capital, segregation and operational requirements. No two are identical, and – critically – none provides automatic recognition in the others.

For an operator already licensed in one hub, the question is whether that permission extends to clients in other jurisdictions. It does not, as a general rule. MiCA passporting allows a CASP authorised in one EU member state to provide custody services across the EU/EEA – a genuine structural advantage for firms targeting European clients from a single authorisation. Outside the EU, passporting does not exist; each jurisdiction requires its own application or at minimum a formal assessment of whether a local presence or registration is triggered.

Three additional regimes are relevant for common corporate structures. The AIFC/AFSA in Kazakhstan provides a common-law custody permission useful for operators with a CIS or Central Asian client base. Japan's FSA/JVCEA self-regulatory model imposes some of the most rigorous custody standards globally. And FINMA in Switzerland takes a principle-based approach that rewards operators with mature segregation and governance frameworks. All three interact with where the entity is incorporated, not just where it operates.

What Does a Custody Licence Application Require in Practice?

A custody licence application requires the operator to demonstrate, in documented form, that it can hold client assets safely, keep them segregated, and return them on demand – across the technical, operational and governance dimensions the regulator prescribes. The specific deliverables vary by jurisdiction, but the core package across the leading regimes consistently includes: a detailed description of the custody model (hot/warm/cold, key management, multi-party computation or hardware security module architecture); evidence of segregation arrangements; a business continuity and disaster recovery plan; fitness and propriety documentation for key individuals; AML/CFT policies aligned to the Travel Rule (the FATF obligation to pass originator and beneficiary data with virtual-asset transfers); and – in most flagship regimes – audited financials and evidence of minimum capital.

Capital requirements are set by each regime and vary by licence category; the exact figures are published by the relevant regulator and should be verified against current rules before any application is submitted. The same applies to application and supervision fees. Writing qualitatively: capital requirements for custody permissions in the leading hubs are material, often exceeding those for lighter-touch VASP registrations, and operators should model the capital commitment before selecting a jurisdiction.

Timeline varies. Straightforward applications in jurisdictions with well-developed digital-asset regimes typically resolve in a matter of months; more complex applications, or those submitted at a time of regulatory backlog, take longer. No timeline is guaranteed, and the most common cause of delay we observe in practice is an incomplete application package submitted before the internal governance framework is fully documented.

For an initial read of whether your existing permissions cover your current custody model, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity structure, the client base, the asset types and the banking – change the analysis materially.

What Are the Most Common Mistakes Established Operators Make?

Established operators make a distinct set of licensing errors that early-stage applicants rarely encounter, precisely because the business has grown beyond the licence that was fit for purpose at an earlier stage. The most frequent errors we identify fall into four patterns.

First, activity creep without a licence extension. An operator licensed to exchange or broker begins holding client assets for settlement convenience. The custody activity is incidental at first; over time it becomes systematic. The original licence did not contemplate it. The regulator eventually asks.

Second, geographic expansion without a local permission. An EU CASP authorisation provides MiCA passporting within the EU. It provides nothing for Hong Kong, Singapore or Dubai clients. Serving those clients from the EU entity – at scale – almost always triggers a local registration or licensing obligation.

Third, a mismatch between the corporate structure and the licensed entity. It is common to find a group where the operating company holds the licence but custody is actually performed by a separate group entity – a treasury vehicle or a subsidiary – that holds no permission at all. Regulators examining the group structure during a renewal or an audit will identify this immediately.

Fourth, inadequate Travel Rule compliance documentation. Custody operators are subject to the Travel Rule, and the obligation to collect and transmit originator/beneficiary data does not disappear because assets are held in custody rather than transferred on behalf of a client at their instruction. The specific data threshold varies by jurisdiction; the principle applies everywhere FATF standards have been implemented.

How Do Established Operators Structure Multi-Jurisdictional Custody?

Multi-jurisdictional custody structuring requires a deliberate decision about where to incorporate the custody entity, where to obtain the primary licence, and which other jurisdictions require local registration, a branch or an allied-counsel assessment. This is not a one-size answer. The right structure depends on where the clients are, what assets are held, where the banking sits and the operator's existing group structure.

Three operating models recur in our practice. In the first, the operator selects a single EU member state for CASP authorisation and uses MiCA passporting to serve all EU/EEA clients. Non-EU jurisdictions are served by separate entities – typically a VARA-licensed Dubai entity for the Middle East and a Singapore MAS-licensed entity for Southeast Asia. This model works well for large operators with the capital and compliance resource to maintain three regulated entities.

In the second model, a smaller operator concentrates its custody activity in one leading-hub jurisdiction – Singapore or Dubai, most commonly – and restricts its client base to jurisdictions where that licence provides sufficient comfort or where a formal marketing exclusion applies. The jurisdictional restriction is documented and enforced.

In the third model, a group structures custody into a separate legal entity that obtains its own licence. The operating company (exchange, fund, payment processor) contracts with the custody entity on arm's-length terms. This segregates custody risk from operational risk and allows the custody entity to be capitalised and regulated independently. It is the structure many institutional-grade operators prefer and the one increasingly expected by institutional clients demanding proof of regulated, segregated custody.

In each model, the cross-border tax interaction – transfer pricing between the operating entity and the custody entity, permanent establishment risk, and VAT/GST on custodial fees – requires coordinated analysis. The licensing question and the tax question are not separable once the group has reach across multiple jurisdictions.

To map the licence, banking and tax stack for your custody build, write to info@oboluslaw.com. If a prior application stalled or an account was closed, a second read can surface the structural reason and the route back.

From Practice: Addressing a Custody Permission Gap

In a recent licensing matter, a payments and exchange group operating across three jurisdictions approached us after a banking partner raised questions about the scope of its regulatory permissions. The group held an EU VASP registration and a registration in a Gulf hub; a separate treasury entity within the group was holding client assets as a settlement float. On review, the treasury entity had no custody permission in any jurisdiction where it was active. We conducted a gap analysis, restructured the custody activity into the licensed operating entity under an amended permission scope, and prepared the regulatory notifications required in each jurisdiction. The banking relationship was preserved and the group proceeded to a full CASP authorisation in one EU member state with passporting across its target markets. The process took several months and required coordinated submissions to regulators in two jurisdictions simultaneously.

Which Custody Licensing Profile Fits Your Business?

Not every operator needs the same licence in the same jurisdiction. The right choice depends on the profile of the business.

An operator serving EU retail and institutional clients from a single regulated entity should seek CASP authorisation in an EU member state with an active and accessible national competent authority. The MiCA passport covers the full EU/EEA market. The capital commitment is material; the passporting benefit is substantial. Timeline to authorisation is measured in months rather than weeks.

An operator serving a Gulf client base with no EU exposure should examine VARA in Dubai or the FSRA in Abu Dhabi. VARA's activity-based licensing model is detailed; the FSRA's recognised-virtual-assets framework imposes clear asset-scope rules. Both require demonstrable local substance. Neither passports into the EU. Timeline for either is typically several months for a well-prepared application.

An operator primarily serving Asian institutional clients should assess Hong Kong's SFC VATP (virtual-asset trading platform) regime or Singapore's MAS major payment institution licence. Hong Kong's custody standards are rigorous and well-regarded by institutional counterparties. Singapore's regime applies transaction-volume thresholds that determine which licence tier is required; operators above the relevant threshold face full MAS licensing with heightened capital and compliance obligations.

An operator seeking a lighter-touch offshore structure for a restricted client base may consider the BVI VASP Act or the Cayman CIMA regime. Both are recognized, well-developed regimes. Both are less demanding than the flagship onshore hubs. Neither is a substitute for a local licence where the operator's clients actually sit.

In all cases, the custody permission must be matched to the actual client base. Marketing a custody service to a client in a jurisdiction where the operator holds no permission – even informally – creates regulatory risk in that client's jurisdiction, not only in the operator's home jurisdiction.

Addressing a Common Assumption: One Offshore Licence Covers Global Operations

A common assumption among operators entering custody for the first time is that a single offshore registration – obtained in a permissive jurisdiction – is sufficient to serve clients in any country. That assumption is incorrect, and regulators in the major onshore hubs have said so explicitly.

An offshore VASP registration creates a compliance baseline. It does not provide access to the EU, UK, US, Singapore, Hong Kong or Japanese markets on its own. Each of those jurisdictions applies its own regulatory perimeter test: if you are providing custody services to clients who are residents or entities in that jurisdiction, you are likely performing a regulated activity there. The relevant question is not where you are incorporated; it is where the regulated activity is performed and where the client is located.

The practical risk for an established operator relying on a single offshore licence is not theoretical. Regulators share information through FATF-aligned mutual-assistance channels. Banking correspondents conduct their own regulatory-perimeter analysis. Institutional clients increasingly require counterparties to hold local permissions before onboarding. An operator that expands its custody client base internationally without expanding its licence stack is building exposure in every jurisdiction it enters without authorisation.

We map that exposure as the first step in every custody licensing engagement. The output is not a recommendation to obtain twenty licences; it is a prioritised, risk-ranked roadmap of where a permission is required, where a legal-opinion approach may be defensible and where the business should simply not operate until it is ready to comply.

Related at OBOLUS

About OBOLUS

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack – operating, custody and payment layers – before you commit, so structural gaps surface before the regulator finds them. We advise crypto exchanges, custodians, token issuers and funds across more than seventy licensing jurisdictions. To discuss your situation, contact info@oboluslaw.com or reach us via t.me/oboluslaw.

FAQ

How long does a crypto licence take to obtain?

Timeline varies by jurisdiction, licence category and the completeness of the application package submitted. In well-developed digital-asset regimes, a straightforward application typically resolves in a matter of months. Complex applications, or those filed during periods of regulatory backlog, take longer. The single most common cause of delay is an incomplete package – missing governance documentation, unresolved fitness-and-propriety questions or an AML policy that does not meet the regulator's current standard. A well-prepared application from day one is the most reliable way to manage timeline risk.

Which jurisdiction is best for licensing my crypto business?

There is no universal answer. The right jurisdiction depends on where your clients are, what activities you perform, where your banking sits and what your capital position supports. An EU CASP authorisation with MiCA passporting is the right answer for operators targeting European clients. A VARA licence is the right answer for operators building a Gulf presence. Singapore MAS and Hong Kong SFC serve operators targeting Asian institutional clients. The licensing question and the client-target question must be answered together, not separately.

Do I need a separate custody licence?

In most leading regulatory regimes, custody is a defined regulated activity that requires its own permission – separate from an exchange, brokerage or payment licence. Under MiCA, VARA, the SFC regime in Hong Kong, and Singapore's Payment Services Act, holding or safeguarding virtual assets for clients constitutes a discrete activity with its own authorisation requirements. Whether your existing licence covers custody depends on the specific terms of that licence and the regulatory perimeter rules in each jurisdiction where you serve clients. A gap analysis before expanding into custody is strongly advisable.

By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in multi-jurisdictional CASP and VASP authorisation strategies for established digital-asset operators.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours