[codicts-css-switcher id=”346″]

Global Law Experts Logo
digital asset custody liechtenstein

How to Set Up Digital Asset Custody in Liechtenstein (2026): FMA Authorisation, TVTG & Banking Rules

By Global Law Experts
– posted 2 hours ago

Digital asset custody Liechtenstein has become one of the most closely watched authorisation routes in European regulatory compliance, and recent banking-rule and EU-level updates have sharpened both the demand for guidance and the scrutiny applied by the supervisor. This guide sets out, step by step, how a prospective custodian obtains authorisation from the Financial Market Authority Liechtenstein (FMA), how the Token and TT Service Provider Act (TVTG) interacts with banking supervision, and what documentation, timelines and costs to plan for. It is written for fintech founders, in-house counsel and compliance officers who need an application-ready procedure rather than a high-level market overview. Throughout, statutory and supervisory points are anchored to primary sources, the FMA and the official legislative database Gesetze.

li, so that each obligation can be traced and verified.

Overview: why Liechtenstein for digital asset custody

Liechtenstein remains an attractive base for regulated custody because it combines EEA market access, a codified token framework and a single, accessible regulator. The country’s early adoption of a dedicated token law, the TVTG, in force since 1 January 2020, gave it a first-mover advantage that many prospective custodians still cite when choosing a jurisdiction. For firms weighing digital asset custody Liechtenstein against other European options, the appeal lies in legal clarity around token classification, asset segregation and the treatment of custodial holdings.

Why Liechtenstein for custody (brief)

The TVTG provides a purpose-built legal container for token-related services, including safekeeping. That means custody activities are not forced awkwardly into legacy securities or banking categories; instead, they are assessed against provisions designed for the technology. Combined with EEA membership, this allows an authorised provider to structure cross-border services within a recognised European framework, subject to the relevant EU regimes and their transitional arrangements. The compact size of the market also means engagement with the FMA is direct and, for well-prepared applicants, relatively predictable.

2026 regulatory update snapshot (FMA and EU rules)

The most significant current development is the phased application of the EU’s Markets in Crypto-Assets Regulation (MiCA), whose rules for crypto-asset service providers, including the custody and administration of crypto-assets on behalf of clients, apply across the EEA. As an EEA member, Liechtenstein is implementing MiCA, and the FMA has indicated that crypto-asset custody now falls primarily to be assessed under the MiCA framework, with the TVTG continuing to govern token classification and matters not covered by MiCA. Applicants should therefore analyse whether their activity requires authorisation as a crypto-asset service provider under MiCA, registration or authorisation under the TVTG, or a banking licence.

The practical effect is that applicants must demonstrate insolvency-remote asset segregation and robust key management early in the process. Confirm the current position and any transitional windows directly with the FMA, as the interaction between MiCA and the TVTG continues to be clarified.

Eligibility: who needs FMA authorisation for crypto custody in Liechtenstein

Before drafting a single policy, establish precisely which authorisation your business model triggers. Crypto custody Liechtenstein activities can fall under the MiCA crypto-asset service provider regime, under the TVTG token-service regime, or, where deposit-taking or other banking activities are involved, under a full banking licence. Getting this classification right at the outset determines the entire application strategy, cost base and timeline.

Which business models require FMA authorisation

Any firm that safekeeps digital assets on behalf of clients, holds private keys, or provides token-transfer and administration services will generally engage authorisation or registration requirements administered by the FMA under MiCA and/or the TVTG. Pure software providers that never control client keys sit differently from custodians that hold, move or control assets. The distinguishing factor the FMA examines is control: if your infrastructure can move a client’s assets, you are almost certainly within scope of FMA custody requirements.

When a banking licence may be needed

A banking licence becomes relevant where the business takes deposits, holds client fiat as repayable funds, or performs classic banking functions alongside custody. If your model combines fiat accounts with token safekeeping, you must analyse the deposit-taking threshold under the Liechtenstein Banking Act (Bankengesetz) available on Gesetze.li. Many custodians deliberately structure to avoid deposit-taking, partnering with a licensed bank for fiat rails rather than absorbing the full banking capital and liquidity regime themselves.

Step-by-step: how to get FMA authorisation for digital asset custody in Liechtenstein

The following procedure sets out the crypto custodian authorisation pathway in the order a well-run project should follow. Each step lists the practical deliverables and the owner responsible. The consolidated timeline table below maps every step to a responsible party and an expected duration so that project managers can build a realistic plan from the outset.

  1. Step 1, Pre-application (feasibility, model choice, legal opinion). Confirm your regulatory classification, choose the entity type, and commission a written legal opinion on whether MiCA authorisation, TVTG authorisation/registration or a banking licence applies. Produce a short feasibility memo covering target clients, asset types, custody model (hot/cold, single-signature, multisig) and the fiat handling approach. This step de-risks everything downstream; skipping it is a common cause of rejected or stalled applications.
  2. Step 2, Prepare governance, policies and technical controls. Draft the governance framework, AML/KYC policy suite, custody operations manual and segregation policy in parallel with the technical build. The FMA expects fit-and-proper board members, clear segregation of duties, and documented conflict-of-interest controls. Sample governance statements should describe reporting lines, escalation procedures and the four-eyes principle applied to asset movements.
  3. Step 3, Prepare documentation and submit the application (forms). Compile the full document set (see the required-documents table), complete the FMA application forms available on the FMA website, and cross-check every appendix against the checklist. Ensure custody agreements contain explicit asset-segregation and insolvency-treatment clauses, and that financial projections align with your stated capital position.
  4. Step 4, FMA review, queries and interviews. After submission, the FMA acknowledges receipt and then conducts substantive review. Expect written queries and, for more complex models, interviews with senior management. Responding quickly, completely and consistently is the fastest way through this phase; contradictory answers between documents trigger further rounds.
  5. Step 5, Post-authorisation compliance setup and reporting. On authorisation, activate ongoing controls: transaction monitoring, periodic reporting to the FMA, internal audit cadence and the first regulatory reports. Any conditions attached to the licence must be evidenced within the deadlines the FMA sets.

Step 1: Pre-application feasibility and model choice

The pre-application phase is where legal strategy is decided. Determine whether your custody activity is a MiCA crypto-asset service, a TVTG token-service, whether you will hold fiat, and whether any activity crosses into deposit-taking. A clear written legal opinion at this stage becomes the backbone of the application narrative and reassures the FMA that classification has been properly analysed. Engage a Liechtenstein-qualified adviser early to shorten this phase and identify structuring options.

Step 2: Governance, policies and technical controls

Governance and technology should be built together, not sequentially. The FMA custody requirements place equal weight on human controls (fit-and-proper management, segregation of duties, independent compliance) and technical controls (hardware security modules, key ceremonies, multisig thresholds). Draft the AML programme against FATF standards for virtual asset service providers, referencing the FATF guidance on virtual assets, and ensure the custody operations manual maps every asset movement to an authorised and logged process.

Step 3: Documentation and submission

Submission is a compilation exercise, but quality varies enormously. The strongest applications present a coherent story: the business plan, the technical architecture, the financials and the governance framework all describe the same firm, with no gaps between them. Use the FMA’s current forms and fee schedule from the FMA, and prepare a short cover memo that signposts where each required element sits within the bundle.

Step 4: FMA review, queries and interviews

Substantive review is iterative. The FMA will test segregation arrangements, insolvency treatment, key management and the adequacy of AML monitoring. Treat every query as an opportunity to demonstrate control maturity rather than a hurdle. Maintain a query log, assign owners, and answer with evidence, updated policies, architecture diagrams, or vendor attestations, rather than assertions.

Step 5: Post-authorisation compliance setup

Authorisation is the start of the supervisory relationship, not the end of the project. Stand up your reporting calendar immediately, confirm the first reporting dates with the FMA, and ensure the compliance function can evidence ongoing monitoring from day one. The FMA expects the controls described in your application to be operational, not aspirational.

Step / Who / Duration timeline

Step Who is responsible Expected duration (indicative)
1. Pre-application advice & model selection (legal, business and tech review) Applicant, external counsel, technical security advisor 2–6 weeks
2. Governance & policies drafting (AML, compliance, custody ops) Applicant compliance team + counsel 3–8 weeks (parallel)
3. Technical & security readiness (wallets, HSM, SOC 2 plans) CTO, security provider 4–12 weeks (depends on build)
4. Compile application & required documents Applicant (legal + finance) 2–4 weeks
5. Submit application to FMA Applicant FMA acknowledgment following receipt
6. FMA substantive review & queries FMA (with applicant responses) Several months (depending on complexity)
7. Decision & licence issue / conditions FMA Subject to statutory assessment periods; confirm with FMA
8. Post-authorisation onboarding & ongoing reporting Applicant compliance/ops Ongoing; first reporting as scheduled

The MiCA regime prescribes statutory assessment periods for crypto-asset service provider authorisations (with the clock pausing while the applicant supplies missing information). Confirm the applicable statutory timeframe and any completeness checks with the FMA before planning around fixed dates.

Required documents for the FMA application, checklist

The document set is the evidentiary core of any digital asset custody Liechtenstein application. The FMA assesses whether your firm is legally sound, financially viable, technically secure and operationally controlled. The table below sets out each required document, its purpose and typical content. Treat it as a checklist: every row should be present, current and internally consistent before you submit.

Corporate documents and fit-and-proper evidence

Provide certified corporate formation documents, the commercial register extract and beneficial ownership information. Fit-and-proper evidence covers board CVs, references, criminal record extracts and confirmation that key function holders have relevant experience. The FMA scrutinises ownership and control structures closely, so map ultimate beneficial owners transparently.

Business plan, governance and AML controls

The business plan must demonstrate a sustainable custody model, covering services, target markets, pricing and client segments. Governance documentation shows how the firm is directed and controlled, while the AML/KYC policy demonstrates customer due diligence, risk assessment and suspicious-activity reporting aligned to Liechtenstein’s Due Diligence Act (Sorgfaltspflichtgesetz) and international standards.

Technical and security architecture documents

Digital asset safekeeping Liechtenstein controls must be documented in detail: HSM specifications, key generation and storage, multisig thresholds, backup and recovery, and incident response. Third-party assurance, such as SOC 2 reports and penetration test results, strengthens the application materially.

Financials and capital adequacy documentation

Submit audited financial statements where available and multi-year projections that evidence capital adequacy and liquidity. The projections must be consistent with the fee model in the business plan and with the own-funds and safeguarding requirements applicable under the relevant regime.

Document Purpose / what the FMA expects Notes / sample details
Corporate formation documents (articles, registration) Proof of legal entity and owners Certified extracts, beneficial ownership information
Business plan & model description Demonstrate a sustainable custody model Services, markets, pricing, target clients
Governance documents (board, policies) Show fit-and-proper governance Board CVs, conflict policies, segregation of duties
AML & KYC policy Demonstrate AML controls Risk assessment, CDD procedures, SAR reporting
Technical architecture & security policy Show safekeeping and incident response HSM specs, key management, backup, recovery plans
Custody agreements & client terms Terms of service and segregation treatment Insolvency treatment and asset segregation clauses
Audited financial statements / projections Capital adequacy and liquidity Multi-year projections and current statements
IT / operational audit reports (SOC 2 / penetration tests) Evidence of controls Up-to-date third-party assurance reports
Internal controls & compliance manuals Day-to-day compliance operations Reporting lines, monitoring, training programmes
Letters from service providers (bank, custody tech) Verify external dependencies Banking relationships, custody vendors, insurers

Timeline and deadlines, what to expect in 2026

Realistic planning for digital asset custody Liechtenstein authorisation means budgeting several months from submission to decision for a complex model, with pre-application preparation adding further weeks. The timeline table above is the planning baseline; the notes below explain where time is won or lost.

Typical review phases and time ranges

After the FMA acknowledges receipt, it carries out a completeness check followed by substantive assessment. Under MiCA, the assessment of a crypto-asset service provider application runs to a statutory period once the file is complete, and the clock is suspended while further information is requested. Incomplete applications therefore extend the effective timeline; confirm the applicable statutory periods with the FMA.

Responding to FMA queries efficiently

The biggest controllable variable is response quality. Maintain a single query log, assign clear owners, and reply with evidence in one consolidated response rather than piecemeal emails. Applicants who answer promptly and completely routinely shorten the overall timeline.

Deadlines under TVTG, MiCA or AML reporting

Once authorised, regulatory reporting and ongoing AML reporting obligations apply on a continuous basis. Diarise these deadlines before the licence is granted so that the compliance function is never caught reacting after the fact; confirm exact first-report dates with the FMA.

Costs and fees for a Liechtenstein custodian licence

Budgeting realistically prevents the most damaging pitfall of all, undercapitalisation mid-application. The figures below are indicative planning ranges only; confirm current FMA fees against the published schedule and obtain tailored quotations for legal and technical work. Treat every figure as a planning estimate, not a fixed price.

FMA fees and application fees

Application and supervisory fees vary with complexity and supervision class and are set by the FMA’s applicable fee regulations. Always check the current schedule on the FMA website, because fee bands and supervisory classifications are updated periodically.

One-off set-up: legal, technology build and audits

The largest one-off variable is the technical build. A custodian running hardware security modules, redundant cold storage and multisig infrastructure at scale sits at the upper end of the range, while a leaner model using proven vendor infrastructure sits lower.

Ongoing: compliance, audit and capital costs

Recurring costs, compliance staffing, annual audits, insurance and capital buffers, often exceed the one-off build over a multi-year horizon. Model these carefully in the projections you submit to the FMA.

Cost item Indicative range (EUR) Notes
FMA application / supervisory fees Per current FMA schedule Depends on complexity and supervision class; check the published FMA fee schedule
Legal & consultancy (application, policies) Significant one-off Depends on scope and counsel rates
Technical implementation (HSM, wallet infrastructure) Varies widely Depends on scale and redundancy
Third-party audits / SOC 2 / pentests Recurring Regular security assurance needed
Capital / own-funds requirements Set by applicable regime See MiCA / FMA solvency rules; working capital and buffer
Ongoing compliance & reporting staff Recurring Salary, training and AML monitoring systems
Insurance (custody / cyber) Recurring Higher for combined fiat and crypto custody

Under MiCA, crypto-asset service providers must maintain minimum own funds (the higher of a fixed floor set by the regulation or a proportion of fixed overheads, depending on the services provided). Confirm the exact own-funds figure applicable to your service classification with the FMA and current EU rules.

TVTG custody requirements and interaction with banking rules

The TVTG remains central to understanding digital asset custody Liechtenstein obligations, because it defines token-service activities and sets out segregation and trustee-style duties for custodians. Where crypto-assets fall within scope of MiCA, the custody and administration of those assets is governed by the MiCA regime, while the TVTG continues to apply to token classification and services outside MiCA’s scope. The statutory text is available on Gesetze.li; where only the German text is available, obtain a professional translation and retain a translator’s note for your file.

What is TVTG (short statutory summary)

The TVTG (Token- und VT-Dienstleister-Gesetz) establishes a legal framework for tokens and for the providers of token-related services, including the safekeeping of tokens on behalf of others. It defines categories of TT service provider and attaches duties around registration, organisation and the protection of client assets. Custody sits within this framework where a firm holds tokens or the keys controlling them and the activity is not otherwise governed by MiCA.

When custody is a regulated activity

Custody is a regulated activity whenever a provider safekeeps crypto-assets or tokens, or the private keys to them, for clients. The distinguishing test is control over the asset: technical ability to move client assets brings a provider within scope of the applicable custody obligations, under MiCA for in-scope crypto-assets and under the TVTG for token-services outside MiCA, including segregation and organisational duties.

Insolvency and segregation under TVTG/MiCA vs banking law

Both the TVTG and MiCA address segregation and safekeeping duties for custodians, aiming to keep client assets separate from the provider’s own estate. Banking law, by contrast, offers depositor protection and a comprehensive insolvency regime for deposit-taking institutions. The practical consequence is that a custodian must evidence insolvency-remote segregation of client assets even where it does not hold a banking licence, and must analyse which regime governs any fiat it handles.

Practical compliance steps for alignment

Align your custody agreements, operations manual and technical architecture with the applicable segregation and organisational duties. Ensure client terms state clearly how assets are segregated and how they are treated on insolvency, and that these statements match what your infrastructure actually does. For comparative context, the EU’s MiCA framework on the European Commission site and prudential guidance from the European Banking Authority indicate the direction of supervisory expectations.

Feature / obligation MiCA crypto-asset service provider (custody) Banking licence TVTG (token-service, outside MiCA)
Primary regulator FMA FMA (banking supervision) FMA (for TVTG activities)
Scope Custody and administration of crypto-assets on behalf of clients Broader banking, deposits, payments Token issuance and service-provider activities outside MiCA
Capital & prudential rules Minimum own-funds and safeguarding requirements under MiCA Comprehensive capital and liquidity regime Segregation and organisational duties for token custodians
Insolvency treatment Client-asset segregation required to protect holdings Depositor protection and insolvency regime Addresses token segregation and trustee-style obligations
Licensing threshold Authorisation required for in-scope custody services Required for deposit-taking / banking activities Registration/authorisation for TVTG token-service providers

Operational controls: AML, KYC, security and audits

Authorisation depends on operational controls that work in practice. The FMA and international standard-setters expect a custodian to run a demonstrable, tested control environment across financial crime, key management and assurance.

AML and KYC: required policies and monitoring technology

Implement risk-based customer due diligence, ongoing transaction monitoring, sanctions and PEP screening, and suspicious-activity reporting to the Financial Intelligence Unit (FIU) Liechtenstein. These controls should reflect the Liechtenstein Due Diligence Act and the FATF standards for virtual asset service providers set out in the FATF guidance, including the travel rule for transfers between providers. Monitoring technology must be calibrated to the risk profile of your client base and asset types.

Key management and technical controls

Private key management is the heart of digital asset safekeeping. Document key generation ceremonies, storage (cold and warm), multisig or MPC thresholds, backup, and recovery procedures. Hardware security modules and strict segregation of signing authority reduce single points of failure, and every asset movement should be logged, authorised under the four-eyes principle and reconcilable.

Insurance, audits, reporting and continuous compliance

Maintain custody and cyber insurance sized to your holdings, commission regular security assurance such as SOC 2 and penetration testing, and run an internal audit function independent of operations. Continuous compliance means monitoring regulatory change and updating policies promptly, not revisiting them only at renewal.

Sample KPIs and monitoring cadence

Define measurable indicators: percentage of alerts cleared within target, time to complete customer due diligence, reconciliation break rates, penetration-test remediation times and training completion rates. Review core KPIs regularly, escalate breaches immediately, and report material issues to the board and, where required, to the FMA.

After authorisation: compliance, reporting and inspections

Once your digital asset custody Liechtenstein authorisation is granted, the focus shifts to sustaining it. The FMA supervises on an ongoing basis, and the quality of your first year of compliance sets the tone of the supervisory relationship.

Reporting obligations and supervisory fees

Submit periodic regulatory reports on schedule and pay ongoing supervisory fees as set by the FMA. Diarise every reporting deadline and confirm the first due dates directly with the regulator so nothing is missed in the transition from applicant to licensee.

Handling FMA inspections

Prepare for inspections by keeping evidence current: policies, logs, audit reports and board minutes should be retrievable on request. An inspection tests whether the controls described in your application operate as documented, so maintain a live evidence library rather than reconstructing records reactively.

Adapting to regulatory change (2026 and beyond)

The regulatory landscape continues to move as MiCA implementation and related technical standards reshape supervisory expectations. Assign clear ownership for horizon-scanning, and update governance, AML and technical policies whenever the framework shifts.

Common pitfalls and how to avoid them

Most failed or delayed applications share a small set of avoidable weaknesses. Address these before submission rather than in response to FMA queries.

  • Weak segregation wording. Custody agreements that fail to state clearly how assets are segregated and treated on insolvency undermine the whole application; align the drafting with the applicable statutory duties.
  • Inadequate AML processes. Generic AML policies that do not reflect FATF virtual-asset standards or the travel rule are a frequent cause of queries.
  • Insufficient technical controls. Missing HSM specifications, undocumented key ceremonies or absent recovery plans signal immature safekeeping.
  • Poor vendor contracts. Reliance on third parties without robust due diligence and contractual protection creates unmanaged operational risk.
  • Undercapitalisation. Projections that do not evidence adequate own funds and buffers raise viability concerns.
  • Wrong entity or licence choice. Misclassifying the model, for example, missing a deposit-taking trigger or a MiCA scope point, forces costly restructuring mid-process.
  • Delayed responses to the FMA. Slow or inconsistent answers extend the review period and erode supervisory confidence.
  • Inconsistent documentation. Business plan, financials, governance and technical documents that describe different firms undermine credibility.

Quick remedies and red flags to fix pre-submission

Run a pre-submission review that reconciles every document against the checklist, stress-tests the segregation and insolvency wording, and confirms that the AML programme maps to FATF standards and the Due Diligence Act. Where you have any doubt on classification, obtain a written legal opinion before filing.

Conclusion

Setting up digital asset custody Liechtenstein authorisation in 2026 is achievable for well-prepared firms, but success depends on getting classification right across MiCA, the TVTG and banking law, evidencing insolvency-remote segregation, and presenting a coherent, consistent application to the FMA. Budget realistically, build governance and technology together, and treat segregation duties and AML controls as core rather than peripheral. Request a pre-application review to pressure-test your model before you file. Readers exploring related jurisdictional questions may also find the guide When to hire a tax lawyer in Liechtenstein (2026) useful for structuring decisions.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Julia von der Osten at VON DER OSTEN Legal, a member of the Global Law Experts network.

Sources

  1. Financial Market Authority Liechtenstein (FMA)
  2. Rechtsinformationssystem Liechtenstein (Gesetze.li)
  3. Government of Liechtenstein
  4. Landtag of Liechtenstein
  5. European Commission, Markets in Crypto-Assets Regulation (MiCA)
  6. Financial Action Task Force (FATF), Virtual Assets
  7. European Banking Authority (EBA)
  8. University of Liechtenstein

FAQs

Do crypto custodians need FMA authorisation or a banking licence in Liechtenstein?
Custodians that safekeep crypto-assets or client keys generally require authorisation from the FMA, under the MiCA crypto-asset service provider regime for in-scope crypto-assets, or under the TVTG for token-services outside MiCA, rather than a full banking licence. A banking licence becomes relevant only where the firm takes deposits or holds repayable client fiat. Confirm the correct classification with a written legal opinion before applying, referencing the FMA and Liechtenstein banking legislation.
The FMA expects corporate and beneficial-ownership documents, a business plan, governance and AML/KYC policies, technical and security architecture, custody agreements with segregation clauses, audited financials or projections, and third-party assurance reports such as SOC 2 and penetration tests. The required-documents table above sets out each item, its purpose and typical content.
Timelines depend on the applicable regime and the complexity of the model. Under MiCA there is a statutory assessment period once the application is complete, and the clock is suspended while further information is requested. Pre-application preparation adds further weeks, and incomplete filings extend the effective timeline. Confirm the applicable statutory periods with the FMA.
The TVTG defines token-service providers and imposes segregation and trustee-style duties designed to keep client tokens separate from the provider’s estate, including on insolvency, for services outside MiCA’s scope. Custody agreements and technical controls must reflect these duties. The statutory text is available on Gesetze.li; where only German is available, use a professional translation.
Firms providing custody within Liechtenstein generally need an appropriately authorised presence, and the FMA scrutinises ownership, control and substance. Depending on the model, EEA passporting under MiCA may permit cross-border provision by an authorised provider. Foreign providers should analyse whether a local entity, branch or passport applies before assuming cross-border provision is permissible, and obtain jurisdiction-specific advice early.
Custodians must implement risk-based customer due diligence, transaction monitoring, sanctions and PEP screening, the travel rule for provider-to-provider transfers, and suspicious-activity reporting to the FIU. These should reflect the Liechtenstein Due Diligence Act and the FATF standards for virtual asset service providers set out in the FATF guidance and be evidenced through monitoring technology and internal audit.
warranty and indemnity insurance indonesia
By Global Law Experts

posted 9 minutes ago

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

How to Set Up Digital Asset Custody in Liechtenstein (2026): FMA Authorisation, TVTG & Banking Rules

Send welcome message

Custom Message