EST · MMXXVI
Home/Services/Licensing Registration/Digital-asset custody licensing from a Cross-border Perspective
Licensing & Registration

Digital-asset custody licensing from a Cross-border Perspective

Digital-asset custody licensing from a Cross-border Perspective. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Ta

Custody is the layer regulators scrutinize most. A business that holds client digital assets – even briefly – crosses into regulated activity in nearly every flagship jurisdiction. The question is not whether a custody function requires authorization; it does. The question is which regimes apply, simultaneously, across the entities and user-base locations the business actually operates.

A digital-asset custody licence (or the custody component within a broader VASP (virtual asset service provider) authorization) gives a business the legal right to hold, safeguard and administer client virtual assets. Under MiCA, the EU's Markets in Crypto-Assets Regulation, custody of crypto-assets for clients is a defined crypto-asset service requiring CASP (crypto-asset service provider) authorization. Under VARA in Dubai, custody is a discrete licensed activity within its rulebook. In Singapore, holding client digital-payment tokens engages the MAS Payment Services Act licensing regime. The regime is named; the gaps are costly.

This page maps the regulated perimeter, the application process, the cross-border complications that trip experienced operators, and the decision logic a business needs before committing to a structure.

What Triggers a Custody Licensing Obligation?

Custody authorization is triggered when a business holds private keys – or controls the means of control – over client virtual assets on a commercial basis. The perimeter is broader than most founders assume at the outset.

Holding keys on a multisig basis, operating a proprietary staking vault for client assets, providing sub-custody services to an exchange, or running a wallet infrastructure product where the business can unilaterally move assets – all of these activities engage the regulated custody perimeter in the leading hubs. The legal test is not the label applied to the product; it is the substance of the control exercised over client assets.

MiCA defines custody and administration of crypto-assets for third parties as a standalone crypto-asset service. A CASP seeking to offer this service must obtain authorization from the relevant national competent authority and may then passport the service across the EU and EEA. Critically, an entity that only holds a payment-services license or a prior VASP registration does not automatically carry the right to provide custody under MiCA – a specific authorization is required.

VARA's custody activity licence in Dubai operates on a similar principle. The activity is defined by reference to the safeguarding and administration of virtual assets on behalf of clients, and an entity must hold the relevant VARA approval before undertaking that activity. The same logic applies under the ADGM/FSRA regime in Abu Dhabi, under the SFC's VASP licensing regime in Hong Kong, and under the BVI FSC's VASP Act. Custody is a regulated activity in its own right.

The practical consequence is that a business building a multi-product stack – exchange, custody, and on-chain staking – faces multiple authorization requirements, potentially across multiple entities. In our practice, the failure to disaggregate the custody layer from the broader trading or exchange business is one of the most common structural mistakes we see at the pre-application stage.

The custody perimeter under MiCA, VARA, and the MAS Payment Services Act each define the obligation independently of the other. A business serving EU clients from a Dubai entity still engages the MiCA regime if it is targeting EU users. Jurisdiction of incorporation does not determine the licensing obligation.

CTA #1 – Early-stage operator

The perimeter analysis above is the starting point, not the end point. Your specific product architecture – how keys are held, where client assets sit, which users you serve – determines whether one license suffices or whether a stack is required. The process above describes the standard path. Your facts – the entity, the user base, the banking – change the analysis entirely. Map your options

How Does a Custody Licence Application Work in Practice?

A custody authorization application is a multi-stage process that moves through internal preparation, regulator engagement, documentation submission, and active review – the timeline varies by jurisdiction and by how well-prepared the applicant is at the outset.

The preparation phase is typically where applications succeed or fail. Regulators in every leading hub expect a complete application package on first submission. An incomplete package is not declined outright; it is returned, extended, or placed in a queue that moves slowly. The preparation work generally covers the following:

  • Legal analysis of the custody perimeter as applied to the specific product architecture and user base.
  • Entity structuring – identifying which legal vehicle will hold the licence, where it is incorporated, and how it connects to the operating group.
  • Governance documentation – board composition, key function holders, fitness and propriety evidence for approved persons.
  • Operational policies – custody safeguarding framework, segregation of client assets, key-management procedures, incident response, business continuity.
  • AML/CFT program – policies, procedures, and controls meeting the FATF Recommendations, including the Travel Rule (the obligation to pass originator and beneficiary data with a virtual-asset transfer), which applies in the EU under MiCA, in Singapore under MAS rules, and across most flagship regimes.
  • Capital evidence – demonstrating that the applicant meets the minimum own-funds requirement for the relevant licence category. The specific threshold varies by category and by jurisdiction; we describe this qualitatively, as the regulator sets figures that change with rule updates.
  • Technology and security audit – most regulators expect an independent assessment of the key management and custody infrastructure before or shortly after authorization.

In our experience advising on applications across EU member states, Dubai, and the offshore hubs, the most common reason for delay is not a substantive objection from the regulator – it is a gap in the governance or AML documentation package. Regulators issue information requests; each request adds time to the review clock.

Timelines vary meaningfully across jurisdictions. Under MiCA, the authorized review period begins when the application is deemed complete; the actual elapsed time from first submission to authorization depends on the national competent authority's workload and the completeness of the file. Under VARA, the process involves preliminary approval and a formal licence grant; the timeline is driven by documentation completeness and by the regulator's current pipeline. In Singapore, MAS applies formal review periods under the Payment Services Act, but pre-application engagement is generally expected and reduces friction.

Post-authorization, a custody licensee is subject to ongoing obligations – periodic reporting, change-of-control notifications, capital adequacy monitoring, and Travel Rule compliance. These are not one-time tasks; they require an embedded compliance infrastructure.

Why Does Cross-border Custody Present Distinct Regulatory Risk?

The central challenge of cross-border custody licensing is that no single authorization confers a global right to serve clients – and most digital-asset businesses are, by nature, multi-jurisdictional from day one.

A business incorporated in the BVI, operating its technology from Singapore, and holding assets for clients in the EU, the UAE and the United States faces at least four distinct regulatory environments simultaneously. The BVI VASP Act governs the entity. The MAS Payment Services Act may engage the Singapore technology node. MiCA engages the EU client relationship. US federal and state money-transmission licensing engages the American user base. Each regime has its own custody perimeter, its own authorization requirements, and its own enforcement posture.

The most serious cross-border trap is the marketing and distribution overlap. Under MiCA, providing crypto-asset services to EU clients on a commercial basis – regardless of where the provider is incorporated – can engage the EU authorization requirement. The ESMA guidance on reverse solicitation is narrow; relying on it as a structural compliance position is high-risk. Operators we advise routinely underestimate the territorial reach of MiCA in their first compliance assessment.

A second cross-border complication is banking. A custody entity holding a valid VARA licence or a CASP authorization may still find itself unable to open operating accounts or segregated client-asset accounts at mainstream banks in the jurisdiction, because those banks apply their own institutional risk assessments to digital-asset businesses. The licensing solution and the banking solution are separate problems that must be worked through in parallel. We have seen well-structured licence applications delayed by six months or more because the banking infrastructure question was left to the post-authorization stage.

A third dimension is the relationship between the custody vehicle and the trading or exchange entity in the same group. Transfer of assets between group companies can trigger the Travel Rule. Intra-group custodial arrangements may engage the regulated-activity perimeter in the jurisdiction of the asset-holding entity. Regulatory perimeters do not pause at corporate boundaries.

A Cross-border Custody Matter: Entity Triage Across Three Regimes

In a recent instruction, a digital-asset fund administrator had built a custody function for institutional clients across EU, Gulf and offshore structures, relying on a single offshore registration as the authorization basis. As the MiCA transition deadline approached, it became clear that the EU client relationships engaged the CASP authorization requirement independently of the offshore registration, and that the Dubai-based operational entity required a VARA custody activity licence for the Gulf-facing client book. We mapped the licence obligations across the three vehicles, sequenced the applications to avoid a regulatory gap during transition, and worked through the AML program uplift required to meet MiCA and VARA standards simultaneously. The fund administrator maintained continuity of service to institutional clients without an enforcement exposure during the transition period.

What Are the Most Common Mistakes in Custody Licence Applications?

The most common mistake in a custody licence application is the belief that a prior or lighter-touch registration automatically covers the custody function.

AML registration with the FCA in the UK, VASP registration under a legacy EU regime, or an offshore company-level registration does not equate to an authorization to provide custody services in the jurisdictions relevant to the operator's actual client base. The MiCA CASP authorization is a higher-order requirement with a distinct application process, capital expectations, and governance standards. Treating registration as a proxy for authorization is the source of a significant proportion of the enforcement exposures we see in the market.

A second common mistake is preparing the governance documentation without reference to the specific requirements of the target regulator. MiCA competent authorities, VARA, and the MAS each publish detailed expectations for key function holders, board composition, and the qualifications of the person responsible for the custody function. A governance framework that is generic – not anchored to the regime in question – invites extended information requests and delays.

A third mistake is underestimating the AML/CFT requirement. The Travel Rule applies across all flagship regimes; most require VASP-to-VASP Travel Rule compliance before or shortly after authorization. An applicant that cannot demonstrate a credible Travel Rule solution – technology, policy, and counterparty onboarding process – at the application stage is not yet ready to apply.

A fourth mistake is sequencing. Applying for a custody licence before resolving the entity structure, the banking arrangements, and the technology audit creates dependencies that collide mid-process. In our cross-border practice, we structure applications sequentially where possible: entity clean-up first, then the AML program, then the governance framework, then submission. That sequence is rarely the instinct of a fast-moving founding team.

Which Custody Licensing Profile Fits Your Business?

The right licensing strategy turns on the operator profile, the client base geography, and the custodied asset types.

Profile A – EU-focused institutional custodian. An entity serving EU institutional clients with crypto-asset custody as its primary product should pursue CASP authorization in a single EU member state with a strong competent authority and manageable application timelines. The authorization passports across the EU/EEA, removing the need for additional national authorizations. The core risk at this profile is timeline – CASP authorization is not a short process, and a business relying on a transitional registration must plan for the conversion window.

Profile B – Gulf-facing custody arm of a larger group. An entity providing custody in Dubai operates under VARA. A separate ADGM/FSRA authorization covers Abu Dhabi-based operations. If the same group also serves EU clients, the MiCA CASP obligation engages independently. Groups in this profile routinely need two or three parallel authorizations; the most efficient approach is a co-ordinated application strategy where the AML program and governance framework are built once and adapted to each regime's documentation requirements.

Profile C – Offshore custodian serving a global institutional base. An entity in the Cayman Islands or BVI holding a VASP registration can serve clients in jurisdictions that do not require a local authorization for inbound services. However, this profile shrinks as MiCA, VARA and the MAS each extend their territorial reach. Operating under an offshore-only registration while actively marketing to EU, UAE or Singapore-based clients is a structural risk position, not a compliance position. Transitioning to a multi-hub authorized structure typically requires advance planning of at least twelve months.

Profile D – Technology-layer custody provider. A business providing white-label key-management or sub-custody technology to licensed custodians faces a distinct question: does the technology layer itself constitute regulated custody activity, or is it a service to a regulated entity? The answer is jurisdiction-specific and depends on the precise control structure. In several major regimes, a technology provider that can unilaterally move client assets – even within a white-label model – is itself in the regulated perimeter. In our practice, this analysis is required before any white-label custody product launches.

Addressing a Common Assumption About Offshore Licensing

A common assumption in the market is that a single offshore authorization – an established BVI, Cayman, or similar registration – is sufficient to serve a global client base commercially. That assumption does not reflect the current enforcement environment.

MiCA's territorial reach is explicit: providing crypto-asset services to clients located in the EU on a commercial basis requires CASP authorization, irrespective of where the provider is licensed. VARA applies to activity targeting UAE clients from any location. The MAS Payment Services Act engages Singapore-based users regardless of the operator's home jurisdiction. The FCA's financial-promotion rules engage UK-targeted marketing. The AIFC/AFSA regime in Kazakhstan applies to activity in that free zone.

The offshore-only model was a workable interim position while most jurisdictions were developing their regimes. It is not a durable compliance position for a business with clients in the leading regulated markets. The question is not whether to transition to authorized structures – it is how to sequence and resource that transition without creating a gap in client service. We regularly advise businesses through that sequencing exercise, and it is more manageable than it appears when approached early.

CTA #2 – Operator who has already attempted a structure or hit a compliance wall

If a prior application stalled, a banking account was closed, or a regulator has issued a query about your custody activity, the structural reason is usually identifiable and addressable. A second read of the entity structure, the AML program, and the regulatory perimeter analysis can surface both the gap and the route forward. If a prior application stalled or an account was closed, a second read can surface the structural reason and the route back. Map your options

Self-Assessment: Is Your Business Ready to Apply?

Before committing resources to a formal custody licence application, the following questions determine whether the business is structurally ready.

  • Has the custody perimeter been mapped against the product architecture – specifically, does the business hold or control private keys or the means of control over client assets on a commercial basis?
  • Has the entity structure been confirmed – is the licensing vehicle the correct legal entity, and does it hold the assets that the licence will cover?
  • Is the board and key-function-holder composition adequate for the target regulator's fitness-and-propriety requirements?
  • Is the AML/CFT program – including a credible Travel Rule solution – documented and tested?
  • Has the capital position been assessed against the target jurisdiction's minimum requirements?
  • Has an independent technology and key-management security assessment been commissioned or scoped?
  • Has the banking strategy been resolved in parallel with the licensing strategy?
  • For multi-jurisdiction operations – has each discrete regulatory obligation been identified, and is there a sequenced application plan?

A negative answer to any of these questions does not prevent an application – it identifies the preparation work to be completed first. Applying before the preparation is complete almost always extends the overall timeline rather than shortening it.

Related at OBOLUS

FAQ

How long does a crypto licence take to obtain?

Timelines vary significantly by jurisdiction, licence category, and application completeness. In leading EU jurisdictions under MiCA, a CASP authorization process typically runs from several months to well over a year from first submission, depending on the national competent authority's pipeline and the quality of the application file. Offshore registrations can move faster, but they carry narrower territorial coverage. The preparation phase – entity structure, AML program, governance framework – usually takes longer than founders anticipate and directly determines how smoothly the formal review proceeds.

Which jurisdiction is best for licensing my crypto business?

There is no single best jurisdiction. The right licensing location depends on where your clients are, what activities you intend to carry out, the asset types involved, your capital position, and your banking strategy. EU authorization under MiCA provides passport coverage across the EU and EEA. VARA and ADGM/FSRA serve the Gulf market. MAS suits Asia-Pacific-facing operations. Offshore structures may be appropriate for fund vehicles or as a complement to onshore authorizations. A custody-specific analysis of your product and client base is the necessary first step.

Do I need a separate custody licence?

In most flagship jurisdictions, yes. Custody of digital assets for clients is a regulated activity in its own right under MiCA, VARA, the MAS Payment Services Act, and other leading regimes. A broader exchange or trading licence does not automatically confer the right to provide custody services. If your business holds client assets – keys, staked assets, or wallet infrastructure where you exercise control – the custody authorization requirement needs to be assessed independently of any other licence your business holds or is applying for.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. We map the licence stack across operating, custody and payment layers before a client commits to a structure – not after. We work alongside forensic partners to convert on-chain evidence into court-ready disclosure applications when recovery matters arise. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com.

By Aisha Tan, Licensing & Jurisdictions Analyst – specializes in cross-border custody and VASP authorization strategy across EU, Gulf and offshore hub regimes.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours