Digital-asset custody is a regulated activity in every major financial center. A custodian holding client private keys or digital-asset balances without the right authorisation faces enforcement action, account closure and – in some regimes – criminal liability for directors. As regulators from MiCA/ESMA in the EU to VARA in Dubai to MAS in Singapore tighten their grip on safeguarding obligations, the cost of getting the licence wrong now exceeds the cost of getting it right.
The core question for any institutional operator is whether custody is licensed as a standalone activity or bundled into a broader VASP (virtual asset service provider) authorisation. The answer turns on which regime governs your entity, where your clients are, and what assets you hold. This page maps the regulated perimeter, the application process and the cross-border interactions that determine whether one licence – or three – is the right answer for your structure.
What the regulated perimeter actually covers
Custody is defined differently across regimes, but the common thread is control: any arrangement where a business holds private keys, manages wallets or exercises discretion over a client's digital assets falls within the regulated perimeter. The precise scope of that perimeter – and the licence it triggers – varies by jurisdiction.
Under MiCA, custody and administration of crypto-assets on behalf of third parties is a named CASP (crypto-asset service provider) activity requiring formal authorisation from the relevant national competent authority. A CASP authorised in one EU member state may passport that activity across the entire EU/EEA. That passporting mechanism is one of MiCA's most commercially significant features for institutional operators building a pan-European custody business.
In Dubai, VARA operates an activity-based licensing model. Custody is a distinct, separately licensed activity under the VARA rulebooks. An entity wishing to provide custody alongside exchange or lending services must satisfy VARA's conditions for each activity. Combining activities under one application does not reduce the scrutiny applied to any single one.
Singapore's MAS regime under the Payment Services Act treats digital payment token custody as a regulated service, with licence tier determined partly by the scale and type of assets under administration. Hong Kong's SFC applies its VATP (virtual-asset trading platform) licensing framework and has signalled that off-platform custody – custody by an entity that does not itself operate the trading venue – may require its own authorisation. The BVI's VASP Act 2022 and Cayman's equivalent VASP regime both capture custody as a registrable activity, making those jurisdictions relevant not only for fund domicile but for service-company structuring.
The practical implication: an operator that passports custody services into multiple jurisdictions without checking whether each destination regime independently requires local authorisation is exposed. We regularly see businesses that obtained a single licence in good faith only to discover that their client base in a second jurisdiction triggers a separate filing obligation.
Who needs a custody licence – and who is caught by surprise
Most institutional operators know they need a licence. The surprises come at the margin. Fund administrators that hold wallet credentials as part of a NAV reconciliation process may be inadvertently acting as custodians. Technology vendors that operate "hot wallet infrastructure" under a service agreement with a licensed exchange may be within the regulated perimeter if they exercise any discretionary control over the keys. Sub-custodians, prime brokers and collateral agents in digital-asset lending structures are equally at risk of crossing the regulatory line.
The FATF Recommendation 15 framework – which underpins AML/CFT rules for virtual assets in most jurisdictions – uses the concept of a VASP that "transfers" or "safeguards" virtual assets. Regulators have generally read "safeguards" broadly. The UK's FCA under the Money Laundering Regulations applies the same logic: if you safeguard or administer a cryptoasset on behalf of a client, registration is required. The FCA's scrutiny of that boundary has increased materially in recent supervisory cycles.
Switzerland's FINMA adds a further layer. A custodian that also provides staking services, yield strategies or any discretionary management function may need a banking licence or a fintech licence depending on the volume of assets and the nature of the activity. The distinction between passive safeguarding and active portfolio management is critical – and not always obvious to operators building multi-product custody propositions.
The cross-border angle is acute here. An entity incorporated in the BVI, operating technology from Singapore, holding assets for EU-based pension funds and banking in the UAE is simultaneously within scope of at least four regulatory regimes. Getting one licence and ignoring the others is not a compliance posture; it is a liability.
The process above describes the standard regulated perimeter. Your facts – the entity structure, the client base, the asset types, the banking – change the analysis materially. For a scoped assessment of which regime applies to your custody model, contact OBOLUS at info@oboluslaw.com.
How the custody licence application process works
The custody licence application is, in most jurisdictions, a documentary and evidential exercise: regulators want to see that the applicant is fit and proper, that its systems and controls are capable of safeguarding client assets, and that its governance is aligned with the applicable rulebook.
The documentation burden varies by regime but generally covers the following elements across the flagship hubs:
- Corporate and ownership structure – beneficial ownership charts, group structure diagrams and evidence of substance in the licensing jurisdiction (office, staff, directors resident or present).
- Technology and operational controls – key management procedures (how private keys are generated, stored, backed up and recovered), multi-signature or MPC (multi-party computation) architecture, penetration test results and disaster recovery documentation.
- Governance and compliance framework – board composition, compliance officer appointment, AML/KYC policies aligned with FATF standards including the Travel Rule (the obligation to pass originator and beneficiary data with each transfer above the applicable threshold), and internal audit arrangements.
- Financial resources – evidence of minimum capital, own-funds projections and insurance arrangements where required by the applicable regime.
- Client asset segregation – documentation demonstrating that client assets are held separately from proprietary assets and that the custodian cannot commingle them.
In the EU under MiCA, the CASP authorisation process includes a formal review period by the national competent authority. The process is front-loaded: submitting an incomplete file restarts the clock. Operators in our experience consistently underestimate the time required to prepare custody-specific documentation – particularly the key management procedures, which require input from both legal and technology teams.
VARA operates a staged review process. The initial application triggers a period of supervisory dialogue, during which the regulator may request additional information or require amendments to the applicant's compliance documentation. The final licence is conditional on satisfying any post-grant conditions before commencing operations. Operators who attempt to launch before conditions are cleared face both licence-related risk and reputational exposure with banking partners.
Under the MAS Payment Services Act, the licensing timeline depends in part on the completeness of the submission and the volume of applications before the regulator at the time of filing. Applicants for major payment institution licences – the tier typically required for institutional-scale custody – face the most comprehensive review. In our practice, we have seen timelines extend significantly when the application file is submitted without a coherent key management policy or when the applicant's AML program lacks explicit Travel Rule coverage.
What goes wrong – and why it is usually avoidable
The most common failure mode in custody licence applications is structural misalignment: the legal entity seeking authorisation does not match the operational entity that actually controls the keys. Regulators examine the flow of control, not the corporate organogram. If the technology is operated by a subsidiary in one country while the licence is sought in another, the regulator will ask pointed questions about where custody substantively occurs.
A second recurring problem is underestimating the AML/CFT component. Custody is a high-risk activity for financial crime purposes because custodians have direct control over the movement of client assets. The FCA, MAS and ESMA (acting through national competent authorities) all expect robust Travel Rule implementation, blockchain analytics integration and documented procedures for handling suspicious activity. An application that treats AML as a box-ticking exercise – a generic policy copied from a non-crypto MSB – typically fails or is returned with extensive remediation requirements.
Third: insurance gaps. Some regimes require crime insurance or professional indemnity cover as a condition of licence. The market for digital-asset custody insurance is specialist and capacity-constrained. Operators who begin the insurance procurement process after they have filed the application commonly discover that the lead time for a suitable policy exceeds the remaining application window. Insurance should be scoped in parallel with the application, not after it.
Finally, custody applicants often underestimate the banking interaction. A custody licence does not, by itself, produce a bank account. In fact, the licence may increase the scrutiny a banking partner applies, because the bank now knows the applicant is a regulated custodian holding client digital assets. We regularly advise clients on the sequence: banking due diligence before or in parallel with the licence application, not as an afterthought.
The cross-border custody reality: one entity, many obligations
No institutional custody business operates in a single jurisdiction. The entity is typically domiciled for regulatory or tax purposes in one place; the technology runs from a data center in a second; the clients are spread across the EU, the Gulf, Southeast Asia and offshore structures; and banking is maintained in a third or fourth jurisdiction. Each of those geographic touchpoints may independently trigger a regulatory filing obligation.
The principle that cuts across nearly all regimes is this: it is the activity, not the entity's home address, that determines which rules apply. A BVI-incorporated custodian marketing services to MiCA-jurisdiction clients is, as a practical matter, within the scope of MiCA's provisions on third-country providers. The SFC in Hong Kong takes a similarly expansive view of activities directed at Hong Kong investors, regardless of where the operator is incorporated.
The AIFC's AFSA in Kazakhstan and the ADGM's FSRA in Abu Dhabi both offer common-law environments with custody-specific regulatory categories and the credibility that comes with a named regulator. For operators building a bridge between Western institutional money and Gulf or Central Asian markets, those jurisdictions are worth a serious look – not as lighter-touch alternatives, but as substantive, well-developed regulatory homes that carry weight with institutional LPs and banking partners.
In our cross-border practice, we consistently advise clients to build a jurisdiction map before committing to any single structure. The map plots the entity location, the client base, the banking, the technology infrastructure and the assets under custody, and then identifies every regulatory trigger across that geography. An operator that skips this step typically ends up either over-licensed (maintaining filings in jurisdictions where it has no real activity) or under-licensed (exposed in jurisdictions where it does).
Allied counsel in the relevant jurisdictions – activated for the local filings that require domestic authorisation – are part of how we execute cross-border mandates. No single office can be the exclusive expert in every licensing regime, and we do not pretend otherwise.
Decision matrix: which custody structure fits which operator profile
The right custody licensing structure depends on the operator's business model, client profile and growth trajectory. The following profiles represent the most common configurations we encounter in practice.
Profile A – EU-focused institutional custodian: An operator whose primary client base is EU-regulated funds, pension schemes and family offices. The optimal structure centres on a MiCA CASP authorisation obtained in a member state with a credible NCA and a pragmatic application process, combined with EU passporting for client coverage. The key risk is the timeline from submission to authorisation, which under MiCA's formal review provisions can be material. Early engagement with the NCA – before the application is filed – is a documented best practice in the jurisdictions we work in.
Profile B – Gulf and Asian dual-market custodian: An operator serving sovereign wealth vehicles, family offices and high-net-worth structures across the UAE and Southeast Asia. A VARA custody licence in Dubai gives the Gulf market credibility; a MAS major payment institution licence covers Singapore and the broader ASEAN reach. These two licences in parallel represent a significant investment in time and capital, but they are the configuration that institutional allocators in those markets expect. Sub-custody arrangements with locally regulated entities can bridge the gap while primary applications are in progress.
Profile C – Offshore fund administrator entering custody: An existing Cayman or BVI fund administrator adding custody services to its offering. Registration under the applicable VASP regime in the Cayman Islands (CIMA) or the BVI (BVI FSC) is the starting point. The critical analysis is whether the custody activity extends beyond the offshore domicile into jurisdictions where clients or assets are located – if it does, those jurisdictions may require additional filings. The offshore registration alone is rarely sufficient if the fund's investors are primarily in MiCA-scope or MAS-scope locations.
Profile D – Technology platform seeking to custody assets for its clients: A DeFi or CeFi platform that has, by commercial evolution, ended up holding user assets in a manner that regulators classify as custody. This profile carries the most acute risk because the custody function arose organically rather than by design. Remediation requires a jurisdictional assessment followed by an expedited licensing strategy, often running in parallel with changes to the technology architecture to clarify the control model. We have managed this pattern on multiple occasions; early legal engagement materially reduces the enforcement risk.
From the practice: a custody licensing matter
In a recent matter, a Singapore-based technology group had operated a digital-asset infrastructure platform for several years, holding private keys for institutional clients under a service agreement that characterised the arrangement as "technical administration." A change in supervisory guidance by MAS made clear that the arrangement fell within the definition of custody for Payment Services Act purposes. We were engaged to manage the transition. We mapped the activity against the applicable licensing tier, restructured the service agreement to distinguish the custodial and non-custodial components, filed the relevant notification with MAS and prepared the full licensing application for the custodial activity. The client retained its institutional relationships throughout the process and completed the regulatory transition without enforcement action. The matter concluded within a single quarter.
Self-assessment: are you already in the custody perimeter
Before engaging counsel, the following questions help clarify whether your activity triggers a custody licence requirement. A "yes" to any of them warrants a formal review.
- Does your business hold, generate or manage private keys for digital assets belonging to clients?
- Do you operate wallets into which client funds are deposited and from which they can be withdrawn at your instruction or under your control?
- Do your service agreements include any obligation to "safeguard," "administer" or "protect" digital assets on behalf of the counterparty?
- Do you provide staking, yield or lending services in a way that involves taking control of the underlying assets even temporarily?
- Is your client base located in one or more of the EU, UAE, Singapore, Hong Kong or the UK – regimes where custody is explicitly regulated?
- Have your banking partners or institutional clients recently asked for evidence of your regulatory status in connection with your custody activity?
Operating outside the regulated perimeter – even inadvertently – creates liability for the entity and, in some jurisdictions, personal liability for directors. Proactive licensing is cheaper than reactive remediation.
If a prior application stalled or your banking partner has raised questions about your custody activity, a second read of the structure can surface the issue and the route back. Reach our licensing desk at info@oboluslaw.com.
Related at OBOLUS
- Licensing and registration for digital-asset businesses – the complete map of VASP authorisation across 70+ jurisdictions
- VASP licence application in Australia – AUSTRAC – how the AUSTRAC registration process works for digital-asset service providers
- PSP and acquiring agreement in South Africa – payment and digital-asset regulatory structuring for the South African market
FAQ
How long does a crypto licence take to obtain?
Timelines vary substantially by jurisdiction, licence category and the completeness of the application file. In well-resourced regimes with a defined review window – such as MiCA's CASP authorisation process or the MAS Payment Services Act licensing track – the formal review period runs for a matter of weeks to several months. In practice, preparation time before submission often exceeds the regulator's formal review period. An incomplete file, an AML gap or a missing key-management document restarts or extends the clock. Early pre-application engagement with the relevant regulator, where permitted, consistently reduces total elapsed time.
Which jurisdiction is best for licensing my crypto business?
There is no universally "best" jurisdiction; the right answer depends on your client base, the activities you conduct, your banking requirements and your growth plans. An EU-facing custody business needs MiCA coverage. A Gulf-market operator needs VARA or FSRA. A Southeast Asia-facing business needs MAS or SFC. In our practice, we map the licence stack against the operator's actual geography and client profile before recommending a primary jurisdiction. A single offshore registration almost never covers the full operating reality of an institutional custody business.
Do I need a separate custody licence?
In many jurisdictions, yes. Under MiCA, custody is a named CASP activity that must be explicitly included in an authorisation – it is not implied by, for example, an exchange licence. VARA treats custody as a separately licensed activity within its activity-based model. MAS requires that custody of digital payment tokens be within the scope of the applicable payment institution licence. Where custody is incidental to a broader financial service, some regimes allow it to be covered by the primary authorisation, but that analysis is jurisdiction-specific and should not be assumed. Confirm the scope of any existing licence before adding custody services.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance structures that sit around them. We map the licence, custody and payment stack before you commit – so the structure you build is the one that holds. Digital assets are the entirety of our practice. To discuss your situation, contact info@oboluslaw.com.
By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in multi-jurisdictional VASP and custody authorisation mandates for institutional operators.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.