Custody is the tightest chokepoint in digital-asset regulation. As supervisory expectations converge on a MiCA-aligned model across Europe, the Gulf and Asia, regulators increasingly treat custody as a standalone regulated activity – one that demands its own authorisation, capital base and operational controls, separate from any exchange or brokerage licence the same entity already holds. Operators who assume their existing VASP (virtual asset service provider) registration covers custody are discovering, often at the worst moment, that it does not.
The legal question this page answers is precise: what does obtaining and maintaining a custody-specific licence actually require in 2025, what are the cross-border complications, and where do applicants lose time and money unnecessarily? OBOLUS acts for custodians, exchanges adding custody desks and asset managers onboarding digital-asset allocation mandates. In each case the process is more structured than it appears from the outside – and more consequential if misread.
What follows maps the regulated perimeter, the application process, the cross-border interaction and the decision matrix an operator needs before committing to a structure.
What does "custody" mean as a regulated activity?
Custody of digital assets is a regulated activity in every major licensing regime, defined generically as holding, storing or controlling cryptoassets – or the private keys that access them – on behalf of a third party. The definition matters because it is broader than most operators assume. A fund administrator that controls multisig keys for an institutional client may be within scope. A neobank that holds stablecoins in an omnibus wallet for retail users almost certainly is. A DeFi protocol that takes custody of collateral is fact-specific and contested, but regulators are increasingly cautious.
Under MiCA, the EU's Markets in Crypto-Assets Regulation administered by ESMA and national competent authorities, custody and administration of crypto-assets on behalf of third parties is a named CASP (crypto-asset service provider) activity requiring explicit authorisation. The same activity is separately classified under VARA in Dubai and under the FSRA regime in ADGM, each of which issues activity-specific licences. Singapore's MAS treats custody of digital payment tokens as a licensed service under the Payment Services Act. The FCA's regime in the UK anchors custody to safeguarding obligations under the Money Laundering Regulations and, increasingly, its consumer asset protection rules.
In our licensing practice, we see a consistent pattern: businesses already operating under a general VASP registration reach a scale or institutional-client threshold at which a dedicated custody authorisation becomes non-negotiable. At that point, the gap between what they have and what they need is wider than expected.
Who actually needs a dedicated custody authorisation?
A dedicated custody licence is required whenever an entity holds client assets under a legal obligation – not merely as a technical necessity of operating a product. The distinction between "holding keys as infrastructure" and "holding assets as a fiduciary" is the line regulators draw, and it is drawn earlier than most operators expect.
The clearest cases are: institutional custodians acting for funds or family offices; exchanges that offer off-exchange settlement or cold storage services as a standalone product; prime brokerage desks managing digital-asset portfolios for professional clients; and stablecoin issuers whose reserve model involves segregated client funds. A payments processor that briefly holds stablecoins in transit may fall outside the custody perimeter in some regimes – but only if the holding period and operational structure meet specific tests that vary by jurisdiction.
The cross-border dimension is acute here. An entity licensed in one jurisdiction that provides custody services to clients in another faces a layered question: does its home licence passport, does the target market require local registration, or does the activity trigger a separate onshore authorisation requirement? Under MiCA, passporting applies within the EU and EEA. Outside that perimeter – in the Gulf, in Asia, in the UK – there is no equivalent mechanism. Each market applies its own tests.
Regulators in the leading hubs increasingly expect that custody entities can demonstrate substance: local governance, qualified custodians or control officers, and documented key-management procedures – not just a registered address. Operators who rely on a shell structure with outsourced operations face the highest friction during authorisation review.
For a scoped assessment of your custody footprint and the licences it triggers, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity structure, the client base, the key-management architecture – change the analysis materially. Map your options.
How does the custody licence application process work?
The custody authorisation process follows a structured sequence across most flagship regimes, and understanding where it diverges is where preparation pays. A well-prepared application reduces the risk of a request-for-information pause that can add months to a timeline.
The sequence, in broad terms, runs as follows. First, the applicant must confirm regulatory perimeter: is the specific activity within scope, and under which regime? This is not always obvious where the entity straddles multiple activities or serves multiple markets. Second, the applicant builds the legal entity and governance structure the target regulator expects – a locally incorporated or registered company in most cases, with board composition and senior management qualifications meeting the regime's fit-and-proper standards.
Third, the applicant prepares the substantive application pack. For custody, this typically includes: a detailed business plan describing the custody model, client types and asset classes; key-management documentation (hardware security module policy, multisig governance, disaster-recovery procedures); AML/CFT policies calibrated to the FATF Travel Rule (the obligation to pass originator and beneficiary data with a virtual asset transfer); client-asset segregation policies; and an ICT and cyber-resilience framework. MiCA's technical standards add further layers around custody-specific operational requirements.
Fourth, the application is submitted. Most flagship regulators apply a completeness check before the substantive review clock starts. A submission that fails completeness is returned, and the clock does not start. This is a common and avoidable delay. Fifth, the regulator conducts its review, which may include management interviews, third-party technology assessments and, in some regimes, a site visit. Authorisation is granted, conditioned or refused. Conditions are common, particularly for first-time applicants; they typically relate to capital adequacy, outsourcing controls or enhanced reporting.
In our cross-border practice, we regularly advise on parallel applications – a custody filing in one hub while a second regime's requirements are mapped for a later application. The documentation overlap is significant, and building a modular application pack from the outset reduces total cost and elapsed time across the portfolio.
What are the most common mistakes in custody licence applications?
Custody applications fail – or stall – for identifiable, avoidable reasons. Understanding them before submission is the difference between a first-round authorisation and a multi-year process.
The most frequent error is mischaracterising the business model. Applicants describe their custody operation in the language of their technology rather than the language the regulator uses. A "self-custody infrastructure product with optional institutional vaulting" that functions as a third-party custody service will be read by the regulator as a custody service – and the application will be assessed accordingly, even if the applicant's documentation does not frame it that way. We have seen this cause a full re-work of an application pack at the request-for-information stage.
The second common error is underestimating the capital and governance requirements. Capital thresholds for custody authorisations vary by regime and licence category and are set by the relevant regulator – they are not published as simple tables, and they interact with the applicant's projected asset-under-custody volumes. A business plan that does not model capital requirements against growth scenarios will draw regulator questions.
Third: insufficient AML/CFT documentation. Custody entities sit at the heart of the Travel Rule obligation. A policy that says "we comply with FATF standards" without specifying the technical means of data transmission, the counterparty screening process and the treatment of unhosted wallets will not pass a competent authority's review. This applies equally under MiCA CASP rules, the VARA custody rulebook, the MAS Payment Services Act requirements and the FCA's MLR registration standards.
Fourth: inadequate outsourcing governance. Most custody businesses outsource some element of key management, infrastructure or operations. The regulator expects contractual arrangements, exit plans and oversight mechanisms that demonstrate the licence-holder retains control. A bare sub-custody agreement without governance provisions is a red flag in any regime.
In a recent matter, a digital-asset fund manager sought a custody authorisation in a leading EU jurisdiction. The initial application pack was based on the manager's existing fund-administration documentation, which described custody in operational terms rather than regulatory ones. We identified the mismatch at the pre-submission review stage, restructured the key-management and client-asset documentation, and the application proceeded to substantive review without a completeness rejection.
If a prior application stalled or a completeness rejection was received, a second read can surface the structural reason and the route back. Contact OBOLUS at info@oboluslaw.com. Map your options.
How does custody licensing interact with tax, banking and cross-border structure?
The custody licence question does not sit in isolation – it sits at the intersection of the entity's licensing stack, its banking relationships and its tax residency, and getting one wrong creates problems in the other two.
On banking: custodians require segregated client-account banking, and in many jurisdictions the regulator will ask how client assets are segregated at the banking layer before granting authorisation. Banks, in turn, conduct their own due diligence on custodians, which increasingly mirrors regulator expectations. An entity that is licensed but cannot demonstrate to its bank why the custody model satisfies AML expectations may find its accounts closed after authorisation – a problem we have seen arise with businesses that treated the banking relationship as an afterthought.
On tax: a custody entity that is registered in one jurisdiction but has its key personnel and decision-making in another faces potential tax residency questions in the second jurisdiction. This is not a theoretical risk; it is a live issue in structures where the licensing jurisdiction was chosen for speed and the operational substance is elsewhere. The tax analysis must track the licensing analysis, not follow it after the fact.
On cross-border structure: for a business operating between a Dubai VARA-licensed entity and an EU-based client base, the custody perimeter question in both jurisdictions must be answered. A VARA custody licence does not passport into the EU; a MiCA CASP authorisation does not cover the UAE market. An operator with a cross-border model needs a licensing stack, not a single licence. In our practice, we map that stack – licence, banking and tax – as one mandate before a structure is committed.
Allied counsel in the relevant jurisdiction are engaged where local law advice is required. The cross-border coordination between the licensing analysis in the home jurisdiction and the market-access analysis in the target market is where the most significant risks concentrate.
Which custody licensing path fits which operator profile?
Custody licensing decisions turn on the operator's profile, client base and growth trajectory. A single path is not optimal for every business.
Profile A – an emerging institutional custodian with a global client mandate: The primary authorisation is typically sought in an EU jurisdiction for MiCA CASP access, or in Singapore under the MAS Payment Services Act for Asia-Pacific reach, supplemented by VARA authorisation for Gulf-based institutional clients. The timeline is measured in months from a complete submission, and the key risk is documentation quality at the first submission. This profile benefits from a modular application pack built for parallel filings.
Profile B – an exchange adding a custody desk for existing clients: The existing VASP or CASP authorisation may already include custody as a permitted activity – but this must be confirmed, not assumed. Where it does not, a variation or a separate custody authorisation is required. The timeline for a variation is generally shorter than a new application, but the substantive requirements – governance, key-management documentation, client-asset segregation – are the same. The key risk here is assuming the existing licence covers the new activity without a formal legal read of the authorisation scope.
Profile C – a fund manager or family office seeking to self-custody a digital-asset allocation: Self-custody for own assets may fall outside the custody licensing perimeter in some regimes, but this depends on the legal structure. Where assets are held in a segregated fund vehicle and the manager controls the keys, the activity may constitute custody of third-party assets. This profile requires a fact-specific analysis before any keys are generated. A common mistake here is treating "own-account" custody as categorically unregulated; it may not be, depending on the fund structure and the relevant regime.
In each profile, the banking and tax analysis runs alongside the licensing analysis. We have seen businesses in all three profiles reach the banking stage without having resolved a jurisdiction question that the bank then raises – adding material delay to the launch timeline.
Is a single offshore licence enough to run a custody business globally?
A common assumption among operators is that a single well-chosen offshore registration – a BVI FSC VASP registration or a Cayman CIMA licence, for example – provides a sufficient legal basis to offer custody services to clients anywhere in the world. This assumption is incorrect, and acting on it is one of the most expensive regulatory mistakes a custodian can make.
The offshore registration removes the licensing requirement in the home jurisdiction. It does not affect the licensing or market-access requirements in any jurisdiction where the custodian solicits, onboards or services clients. Most major markets – the EU under MiCA, Singapore under the MAS Payment Services Act, the UK under FCA rules, the UAE under VARA – apply their own licensing requirements to entities that serve clients in those markets, regardless of where the entity is incorporated or registered.
The enforcement consequence of getting this wrong is not theoretical. Regulators in the EU, UK and Singapore have each moved against unlicensed custody operations serving local clients, and the outcomes have included public censure, mandatory client notification and enforced wind-down of the custody activity. Banking relationships for unlicensed custodians are increasingly refused, not just in the target market but in the home jurisdiction too, as correspondent banks apply their own regulatory risk criteria.
The correct model is a licensing stack calibrated to the actual client base and the markets served. That stack may include an offshore foundation combined with one or two onshore authorisations – or it may be a single onshore authorisation with a passporting strategy, where the regime allows it. The analysis is specific to the operator's facts. Generic offshore planning is not a substitute for it.
Operators we advise routinely begin with the assumption that their existing structure is adequate. The first deliverable in most mandates is a gap analysis that maps the actual client base against the licensing perimeter in each market. The gap is almost always present; the question is how material it is and how quickly it can be closed.
Self-assessment: is your custody structure licence-ready?
Before submitting a custody authorisation application – or before adding a custody activity to an existing VASP or CASP registration – the following questions identify the highest-risk gaps:
- Has the custody activity been legally defined in the terms the target regulator uses, not just in the applicant's own product documentation?
- Is the entity incorporated or registered in the target licensing jurisdiction, with locally qualified management or a local controller?
- Does the key-management architecture (HSM policy, multisig governance, cold/warm/hot allocation) meet the regime's operational standards?
- Is the client-asset segregation model documented at the contractual and banking levels, not just the operational level?
- Does the AML/CFT policy address the Travel Rule specifically, including unhosted-wallet treatment and counterparty screening?
- Have outsourcing arrangements been reviewed against the regulator's sub-custody and outsourcing expectations?
- Has the capital requirement for the specific custody licence category been modelled against projected assets under custody?
- Have banking relationships been pre-qualified against the custody model?
- Has a tax residency analysis confirmed that the licensing jurisdiction aligns with the operational substance?
- Has the cross-border client base been mapped against the market-access requirements in each target jurisdiction?
A "no" or "uncertain" answer to any of these questions identifies a risk that should be resolved before submission. We have seen applications fail at the competent authority's completeness check for gaps that were identifiable – and addressable – at the pre-submission stage.
Related at OBOLUS
- Licensing and registration for digital-asset businesses – the full OBOLUS licensing practice across 70+ jurisdictions and all activity types.
- VASP licensing in Seychelles – a detailed guide to Seychelles registration as an offshore licensing foundation.
- Token sale agreement drafting: where the legal lines are drawn – structuring the contractual layer around a token issuance.
FAQ
How long does a crypto licence take to obtain?
Timeline varies materially by jurisdiction and licence category. In flagship EU jurisdictions under MiCA, a CASP authorisation is typically measured in months from a complete and compliant submission – but the completeness review adds time if the application pack has gaps. VARA and MAS processes are similarly structured. Offshore registrations can move faster. The most reliable way to forecast your specific timeline is a pre-submission assessment of the application against the target regime's completeness criteria.
Which jurisdiction is best for licensing my crypto business?
There is no universally optimal jurisdiction. The right choice depends on your client base, the activities you conduct, your banking requirements and your tax position. An EU CASP authorisation under MiCA offers passporting across member states. A VARA licence provides credibility in the Gulf. Singapore's MAS regime is preferred for Asia-Pacific institutional business. A multi-market model typically requires a licensing stack rather than a single authorisation. We map that stack before you commit.
Do I need a separate custody licence?
In most flagship regimes, yes – if custody is a meaningful part of your service offering. Under MiCA, custody is a named CASP activity requiring explicit authorisation; holding a trading-platform or exchange CASP does not automatically cover it. The same applies under VARA, MAS and the FCA's framework. If your current authorisation does not expressly list custody, you should obtain a formal legal read of the authorisation scope before offering custody services to clients or institutional counterparties.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. We map the licence stack across operating, custody and payment layers before you commit – and we structure licensing, banking and tax as one mandate rather than three disconnected workstreams. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com or message us at t.me/oboluslaw.
By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in custody and exchange authorisation across EU, Gulf and Asia-Pacific licensing regimes.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.