Operating a custody function for digital assets without the correct authorisation is not a grey area. Enforcement action, suspended banking relationships and investor-level reputational damage are the practical consequences – and regulators across every major hub have made clear that the regulated perimeter includes custody. Digital-asset custody licensing refers to the process by which a regulated entity obtains the authorisation, registration or licence specifically required to hold, safeguard and administer client digital assets on a professional basis. For a bank, asset manager, broker or existing payment institution looking to add a custody layer, the question is not whether a licence is required – it almost certainly is – but which regime applies, in which jurisdiction, and how the resulting authorisation interacts with the entity's existing regulatory permissions. This page maps that analysis from the first threshold question to the final authorisation decision.
Why Digital-Asset Custody Is a Separately Regulated Activity
Custody of digital assets is a regulated activity in its own right across every significant financial hub, and an entity's existing financial licence does not automatically extend to it. The principle holds consistently: under MiCA (the EU's Markets in Crypto-Assets Regulation), custody and administration of crypto-assets on behalf of third parties is one of the defined CASP (crypto-asset service provider) activities requiring specific authorisation. Likewise, VARA in Dubai treats custody and transfer as standalone licensed services under its activity-based licence architecture. The SFC in Hong Kong, FSRA in Abu Dhabi's ADGM, and MAS in Singapore each treat safeguarding of client digital assets as a distinct regulated function. A regulated entity – a fund, a bank, a broker – that assumes it may hold client digital assets under its existing permissions is relying on an analogy that regulators have consistently refused to accept.
The structural reason is straightforward. Digital-asset custody involves private-key control, on-chain segregation, and the operational risk of irreversible loss. Those risks are distinct from traditional securities safekeeping. Regulators designed new permissions to address them. The result is a layered authorisation picture: an entity may need its existing licence, a new CASP or VASP registration covering custody, and – where the entity interacts with users in multiple territories – additional local permissions or notifications in each. Operators we advise routinely underestimate this layering at the outset.
Contact OBOLUS before you commit to a custody build. The entity structure, the jurisdiction of the client base and the banking relationships all shape the authorisation path. For a scoped assessment of your custody licensing position, contact OBOLUS at info@oboluslaw.com.
Which Regulated Entities Need a Dedicated Custody Authorisation?
Any regulated entity that controls private keys for client digital assets, or that administers client assets on-chain on a discretionary or non-discretionary basis, will need the appropriate custody permission in almost every leading regime – regardless of its existing licence.
In our cross-border practice, we regularly advise entities across four profile types. First, traditional asset managers and fund administrators that want to add a digital-asset custody layer for institutional clients. Second, payment institutions and e-money institutions that are expanding into crypto storage as an ancillary service. Third, broker-dealers and trading platforms that retain client assets between trades. Fourth, crypto-native exchanges that have grown to the point where an institutional custody arm – operationally and legally separate from the trading business – becomes commercially and regulatorily necessary.
The threshold test is consistent across regimes: if the entity controls, even temporarily, the private keys or the on-chain mechanism that authorises movement of client assets, custody permission applies. "We use a sub-custodian" does not fully extinguish the requirement in most regimes; it shifts which entity holds the primary permission, but the sub-custodian itself must typically be authorised. Under the applicable CASP provisions of MiCA, both the appointing entity and the sub-custodian carrying the key-management function may need authorisation where the custody function is material.
How Does the Licensing Process Work for a Regulated Entity?
The licensing process for a regulated entity seeking a custody authorisation follows a broadly consistent arc across jurisdictions, though the sequencing and document intensity vary considerably by regime and by the entity's existing regulatory status. The general arc runs: pre-application engagement, documentation and fit-and-proper assessment, technical due diligence, and then the formal review period that leads to authorisation or a request for further information.
Pre-application engagement is not optional in the leading hubs. VARA in Dubai, the FSRA in Abu Dhabi, the FCA in the UK and ESMA-era NCAs in the EU all maintain pre-application or supervisory-contact processes. Regulators use those conversations to signal expectations on governance, safeguarding architecture and key-management standards before the formal file is submitted. An entity that bypasses pre-application contact and submits a cold application typically receives a request for further information – effectively resetting the clock.
Fit-and-proper assessments for controlled-function holders are deeper for custody licences than for many other activity categories. The rationale is the irreversibility point: a custody failure, unlike a trading failure, may not be recoverable through market mechanisms. Regulators across the Singapore MAS regime, the SFC in Hong Kong and the FCA each look closely at the proposed key-management officer, the technology stack and the insurance or indemnity arrangements.
Timeline for the formal review period varies by regime and by whether the entity has an existing regulatory relationship. Broadly, where an entity already holds a permission with the same regulator, an extension application tends to progress faster than a first-licence application. Timelines across the major hubs range from a matter of weeks for relatively straightforward registrations to several months for full authorisation in demanding regimes – write to us and we will give you a jurisdiction-specific estimate based on current processing patterns.
What Are the Most Common Mistakes in Custody Licence Applications?
The most consequential mistake we see is submitting a custody application with governance documentation that was drafted for a securities safekeeping function and transposed without material adaptation. Regulators are experienced enough to identify the copy-paste; it signals to the examiner that the applicant does not yet understand the operationally distinct risks of digital-asset custody.
A second recurring error is the failure to address the cross-border user base at the application stage. An entity seeking a custody licence in, say, Lithuania under the MiCA transition framework, while serving clients domiciled in Singapore, Hong Kong and the UAE, faces a much more complex regulatory picture than an entity serving only EU clients. The target market defines which additional notifications, registrations or "reverse solicitation" analyses are needed. Applications that omit this analysis create a compliance gap that regulators in secondary jurisdictions may later exploit.
A third category of error is the technology annexe. Most leading regimes require applicants to describe their key-management architecture, backup procedures, access-control protocols and incident-response plan. Entities that treat this as a form-filling exercise – rather than a substantive technical document reviewed by both the legal team and the technology function – face follow-up questioning that can add weeks or months to the review period.
We have also seen applications fail at the level of the safeguarding and segregation analysis. Under the applicable VARA rulebooks, custody providers must demonstrate that client assets are operationally and legally segregated from proprietary assets, with documentation that maps the on-chain address structure to the legal title analysis. An entity that cannot produce that documentation should not file.
How Does Digital-Asset Custody Licensing Interact With the Cross-Border Regulatory Stack?
The cross-border reality for a regulated entity adding a custody function is that a single authorisation almost never covers the full scope of the commercial activity – and the gap between what the licence permits and what the commercial activity requires is where enforcement risk concentrates.
Consider a fund administrator domiciled in the Cayman Islands that is adding digital-asset custody for institutional clients in the EU, the UAE and Singapore. CIMA in the Cayman Islands governs the administrator's home-market status under the applicable VASP Act provisions. But servicing EU clients involves the MiCA regime and the relevant NCA. Servicing Dubai-based clients may engage VARA even where the administrator has no physical presence in Dubai, depending on the solicitation and the client's domicile. Singapore's MAS takes a similarly territorial view under the Payment Services Act.
In our cross-border practice, we map the full jurisdiction footprint before the first application is filed. The question is not just "which licence do we need" but "which licences are required now, which can be deferred and managed by operational controls, and which require allied counsel in the relevant jurisdiction." The banking layer adds another dimension: custody businesses require stablecoin settlement rails or fiat banking that is crypto-tolerant, and the jurisdiction in which banking is established must be consistent with the regulatory authorisations in place.
A recent matter illustrates the stakes. A regulated investment manager wanted to launch a digital-asset custody arm for its existing institutional client base. In the initial engagement, the team assumed a single EU MiCA authorisation would be sufficient. Working through the client list, it became clear that a material share of assets under management came from GCC-based investors, triggering a parallel VARA analysis. We identified the gap before the application was filed and restructured the entity architecture to address both regimes concurrently, avoiding what would have been an enforcement exposure the moment the first GCC-based client assets went on-chain.
If your custody build spans more than one jurisdiction, the analysis must start with the full footprint, not the home market. To map the licence, banking and tax stack for your custody build, write to OBOLUS at info@oboluslaw.com.
Decision Matrix: Which Custody Licensing Path Fits Your Profile?
The right authorisation path depends on the entity type, the jurisdictions involved, the client profile and the commercial timeline. The following profiles represent the scenarios we encounter most frequently.
Profile A – EU-based asset manager adding institutional crypto custody: The primary instrument is a MiCA CASP authorisation for custody and administration, filed with the relevant NCA. The existing MiFID authorisation does not extend to digital assets. The indicative review period is measured in months rather than weeks. The key risk is governance documentation – the regulator will assess whether the custody function is genuinely governed separately from the trading desk.
Profile B – Dubai-licensed exchange seeking a standalone institutional custody arm: The instrument is a separate VARA custody licence, distinct from the exchange licence. VARA's activity-based architecture requires each licensed service to be separately authorised. The timeline varies by preparation quality. The key risk is the safeguarding and segregation documentation – VARA's rulebooks are prescriptive on on-chain address structure and client-asset reporting.
Profile C – Cayman-domiciled fund wanting to self-custody for cost efficiency: The primary route runs through CIMA under the applicable VASP Act provisions. If the fund also serves EU or Singapore investors, parallel CASP or DPT service notifications may be required in those jurisdictions. The key risk is the cross-border user base – self-custody at the fund level without addressing the investor jurisdictions creates a gap that regulators in the secondary markets can act on.
Profile D – UK-regulated payment institution adding crypto storage: The FCA registration under the Money Laundering Regulations is a threshold requirement. As the UK's crypto-financial-services regime develops, that registration baseline is expected to evolve toward a fuller permissions model. The key risk is the marketing and financial-promotion layer: FCA financial-promotion rules apply to communications about the custody service, with a separate compliance obligation that sits alongside the registration requirement.
Self-Assessment: Is Your Entity Ready to File?
Before filing a custody licence application, a regulated entity should be able to answer the following questions affirmatively. These are the points on which we advise clients to prepare before the pre-application engagement meeting with the regulator.
First, do the proposed controlled-function holders meet the fit-and-proper standards of the target regime, including technology competency and prior regulatory history? Second, does the governance documentation address digital-asset-specific operational risk – key management, cold/warm/hot wallet architecture, access controls, incident response – rather than relying on a securities-safekeeping template? Third, is the client asset segregation model documented both legally and on-chain, with a clear map between wallet addresses and the underlying client accounts? Fourth, has the full jurisdiction footprint of the proposed client base been assessed and addressed in the application, or at least identified as a parallel workstream? Fifth, is the banking structure – both fiat settlement and any stablecoin rails – in place or under active development, and is it consistent with the regulatory authorisations being sought?
Entities that cannot answer all five questions affirmatively will benefit from a scoped preparation mandate before the formal application is filed. In our experience, an application filed before the entity is operationally and documentarily ready generates regulatory follow-up that costs significantly more time than the preparation would have.
A Common Assumption: One Licence Covers Global Operations
A common assumption among regulated entities entering the digital-asset custody space is that a well-regarded offshore authorisation – a Cayman VASP registration, a BVI FSC approval, a Malta MFSA legacy permission – is sufficient to service clients globally without additional local permissions. That assumption is incorrect and, in our experience, increasingly tested by regulators in the major markets.
The practical position is that most leading jurisdictions apply a territorial or client-domicile-based nexus to their licensing requirements. The MAS in Singapore, the SFC in Hong Kong and ESMA NCAs in the EU each have supervisory tools to reach entities that service local clients without local authorisation. The enforcement consequence ranges from a supervisory letter requiring remediation to an outright prohibition on continued servicing of local clients. For a custody business, the latter is operationally catastrophic: client assets already on-chain create a complex unwinding problem on top of the regulatory one.
The correct model is a jurisdiction matrix. The home-market licence is the anchor. Secondary licences, notifications, or allied-counsel-managed registrations address the client base. The offshore holding structure may provide tax and operational advantages, but it does not substitute for the regulatory permissions required at the point of client service. We structure that matrix before the first application is filed – not as a reactionary fix after the regulator has already written.
Related at OBOLUS
- Licensing and registration for digital-asset businesses – the full practice overview, covering all activity categories and jurisdictions
- Crypto exchange setup in Australia under AUSTRAC – jurisdiction-specific guide to Australian VASP registration requirements
- Digital-asset custody licensing for established operators – the equivalent service page for operationally mature crypto-native businesses
FAQ
How long does a crypto licence take to obtain?
The timeline depends on the jurisdiction, the licence category and the completeness of the application. Straightforward registrations in some offshore centres can complete in a matter of weeks. Full CASP authorisations under MiCA or custody licences in Singapore and Hong Kong are measured in months, with pre-application engagement adding time at the front end. Preparation quality is the primary variable the applicant controls: complete, well-organised files move faster than those that generate follow-up requests.
Which jurisdiction is best for licensing my crypto business?
There is no universal answer. The right jurisdiction depends on where your clients are, where your banking will sit, the activity type and your existing regulatory relationships. Dubai under VARA, the EU under MiCA, Singapore under MAS and Hong Kong under the SFC each suit different operator profiles. The offshore centres – BVI, Cayman, Malta – offer different access and cost profiles. OBOLUS maps the licence, banking and tax interaction before recommending a jurisdiction to ensure the choice holds under regulatory and commercial scrutiny.
Do I need a separate custody licence?
In most leading regimes, yes. Custody is a separately defined regulated activity under MiCA, VARA, the MAS Payment Services Act, the SFC's VASP regime and the FCA's registration framework. An existing financial services licence – for fund management, payment services or brokerage – does not automatically extend to custody of digital assets. Entities that hold client private keys without the relevant custody permission are operating outside their regulatory perimeter. The position should be verified jurisdiction by jurisdiction before any client assets are taken on-chain.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit – and we structure licensing, banking and tax as one mandate rather than three disconnected workstreams. To discuss your custody licensing situation, contact info@oboluslaw.com.
By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in cross-border custody and VASP authorisation across EU, GCC and Asia-Pacific regimes.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.