Our Expert in Liechtenstein
No results available
Digital asset custody Liechtenstein has become one of the most closely watched authorisation routes in European regulatory compliance, and recent banking-rule and EU-level updates have sharpened both the demand for guidance and the scrutiny applied by the supervisor. This guide sets out, step by step, how a prospective custodian obtains authorisation from the Financial Market Authority Liechtenstein (FMA), how the Token and TT Service Provider Act (TVTG) interacts with banking supervision, and what documentation, timelines and costs to plan for. It is written for fintech founders, in-house counsel and compliance officers who need an application-ready procedure rather than a high-level market overview. Throughout, statutory and supervisory points are anchored to primary sources, the FMA and the official legislative database Gesetze.
li, so that each obligation can be traced and verified.
Liechtenstein remains an attractive base for regulated custody because it combines EEA market access, a codified token framework and a single, accessible regulator. The country’s early adoption of a dedicated token law, the TVTG, in force since 1 January 2020, gave it a first-mover advantage that many prospective custodians still cite when choosing a jurisdiction. For firms weighing digital asset custody Liechtenstein against other European options, the appeal lies in legal clarity around token classification, asset segregation and the treatment of custodial holdings.
The TVTG provides a purpose-built legal container for token-related services, including safekeeping. That means custody activities are not forced awkwardly into legacy securities or banking categories; instead, they are assessed against provisions designed for the technology. Combined with EEA membership, this allows an authorised provider to structure cross-border services within a recognised European framework, subject to the relevant EU regimes and their transitional arrangements. The compact size of the market also means engagement with the FMA is direct and, for well-prepared applicants, relatively predictable.
The most significant current development is the phased application of the EU’s Markets in Crypto-Assets Regulation (MiCA), whose rules for crypto-asset service providers, including the custody and administration of crypto-assets on behalf of clients, apply across the EEA. As an EEA member, Liechtenstein is implementing MiCA, and the FMA has indicated that crypto-asset custody now falls primarily to be assessed under the MiCA framework, with the TVTG continuing to govern token classification and matters not covered by MiCA. Applicants should therefore analyse whether their activity requires authorisation as a crypto-asset service provider under MiCA, registration or authorisation under the TVTG, or a banking licence.
The practical effect is that applicants must demonstrate insolvency-remote asset segregation and robust key management early in the process. Confirm the current position and any transitional windows directly with the FMA, as the interaction between MiCA and the TVTG continues to be clarified.
Before drafting a single policy, establish precisely which authorisation your business model triggers. Crypto custody Liechtenstein activities can fall under the MiCA crypto-asset service provider regime, under the TVTG token-service regime, or, where deposit-taking or other banking activities are involved, under a full banking licence. Getting this classification right at the outset determines the entire application strategy, cost base and timeline.
Any firm that safekeeps digital assets on behalf of clients, holds private keys, or provides token-transfer and administration services will generally engage authorisation or registration requirements administered by the FMA under MiCA and/or the TVTG. Pure software providers that never control client keys sit differently from custodians that hold, move or control assets. The distinguishing factor the FMA examines is control: if your infrastructure can move a client’s assets, you are almost certainly within scope of FMA custody requirements.
A banking licence becomes relevant where the business takes deposits, holds client fiat as repayable funds, or performs classic banking functions alongside custody. If your model combines fiat accounts with token safekeeping, you must analyse the deposit-taking threshold under the Liechtenstein Banking Act (Bankengesetz) available on Gesetze.li. Many custodians deliberately structure to avoid deposit-taking, partnering with a licensed bank for fiat rails rather than absorbing the full banking capital and liquidity regime themselves.
The following procedure sets out the crypto custodian authorisation pathway in the order a well-run project should follow. Each step lists the practical deliverables and the owner responsible. The consolidated timeline table below maps every step to a responsible party and an expected duration so that project managers can build a realistic plan from the outset.
The pre-application phase is where legal strategy is decided. Determine whether your custody activity is a MiCA crypto-asset service, a TVTG token-service, whether you will hold fiat, and whether any activity crosses into deposit-taking. A clear written legal opinion at this stage becomes the backbone of the application narrative and reassures the FMA that classification has been properly analysed. Engage a Liechtenstein-qualified adviser early to shorten this phase and identify structuring options.
Governance and technology should be built together, not sequentially. The FMA custody requirements place equal weight on human controls (fit-and-proper management, segregation of duties, independent compliance) and technical controls (hardware security modules, key ceremonies, multisig thresholds). Draft the AML programme against FATF standards for virtual asset service providers, referencing the FATF guidance on virtual assets, and ensure the custody operations manual maps every asset movement to an authorised and logged process.
Submission is a compilation exercise, but quality varies enormously. The strongest applications present a coherent story: the business plan, the technical architecture, the financials and the governance framework all describe the same firm, with no gaps between them. Use the FMA’s current forms and fee schedule from the FMA, and prepare a short cover memo that signposts where each required element sits within the bundle.
Substantive review is iterative. The FMA will test segregation arrangements, insolvency treatment, key management and the adequacy of AML monitoring. Treat every query as an opportunity to demonstrate control maturity rather than a hurdle. Maintain a query log, assign owners, and answer with evidence, updated policies, architecture diagrams, or vendor attestations, rather than assertions.
Authorisation is the start of the supervisory relationship, not the end of the project. Stand up your reporting calendar immediately, confirm the first reporting dates with the FMA, and ensure the compliance function can evidence ongoing monitoring from day one. The FMA expects the controls described in your application to be operational, not aspirational.
| Step | Who is responsible | Expected duration (indicative) |
|---|---|---|
| 1. Pre-application advice & model selection (legal, business and tech review) | Applicant, external counsel, technical security advisor | 2–6 weeks |
| 2. Governance & policies drafting (AML, compliance, custody ops) | Applicant compliance team + counsel | 3–8 weeks (parallel) |
| 3. Technical & security readiness (wallets, HSM, SOC 2 plans) | CTO, security provider | 4–12 weeks (depends on build) |
| 4. Compile application & required documents | Applicant (legal + finance) | 2–4 weeks |
| 5. Submit application to FMA | Applicant | FMA acknowledgment following receipt |
| 6. FMA substantive review & queries | FMA (with applicant responses) | Several months (depending on complexity) |
| 7. Decision & licence issue / conditions | FMA | Subject to statutory assessment periods; confirm with FMA |
| 8. Post-authorisation onboarding & ongoing reporting | Applicant compliance/ops | Ongoing; first reporting as scheduled |
The MiCA regime prescribes statutory assessment periods for crypto-asset service provider authorisations (with the clock pausing while the applicant supplies missing information). Confirm the applicable statutory timeframe and any completeness checks with the FMA before planning around fixed dates.
The document set is the evidentiary core of any digital asset custody Liechtenstein application. The FMA assesses whether your firm is legally sound, financially viable, technically secure and operationally controlled. The table below sets out each required document, its purpose and typical content. Treat it as a checklist: every row should be present, current and internally consistent before you submit.
Provide certified corporate formation documents, the commercial register extract and beneficial ownership information. Fit-and-proper evidence covers board CVs, references, criminal record extracts and confirmation that key function holders have relevant experience. The FMA scrutinises ownership and control structures closely, so map ultimate beneficial owners transparently.
The business plan must demonstrate a sustainable custody model, covering services, target markets, pricing and client segments. Governance documentation shows how the firm is directed and controlled, while the AML/KYC policy demonstrates customer due diligence, risk assessment and suspicious-activity reporting aligned to Liechtenstein’s Due Diligence Act (Sorgfaltspflichtgesetz) and international standards.
Digital asset safekeeping Liechtenstein controls must be documented in detail: HSM specifications, key generation and storage, multisig thresholds, backup and recovery, and incident response. Third-party assurance, such as SOC 2 reports and penetration test results, strengthens the application materially.
Submit audited financial statements where available and multi-year projections that evidence capital adequacy and liquidity. The projections must be consistent with the fee model in the business plan and with the own-funds and safeguarding requirements applicable under the relevant regime.
| Document | Purpose / what the FMA expects | Notes / sample details |
|---|---|---|
| Corporate formation documents (articles, registration) | Proof of legal entity and owners | Certified extracts, beneficial ownership information |
| Business plan & model description | Demonstrate a sustainable custody model | Services, markets, pricing, target clients |
| Governance documents (board, policies) | Show fit-and-proper governance | Board CVs, conflict policies, segregation of duties |
| AML & KYC policy | Demonstrate AML controls | Risk assessment, CDD procedures, SAR reporting |
| Technical architecture & security policy | Show safekeeping and incident response | HSM specs, key management, backup, recovery plans |
| Custody agreements & client terms | Terms of service and segregation treatment | Insolvency treatment and asset segregation clauses |
| Audited financial statements / projections | Capital adequacy and liquidity | Multi-year projections and current statements |
| IT / operational audit reports (SOC 2 / penetration tests) | Evidence of controls | Up-to-date third-party assurance reports |
| Internal controls & compliance manuals | Day-to-day compliance operations | Reporting lines, monitoring, training programmes |
| Letters from service providers (bank, custody tech) | Verify external dependencies | Banking relationships, custody vendors, insurers |
Realistic planning for digital asset custody Liechtenstein authorisation means budgeting several months from submission to decision for a complex model, with pre-application preparation adding further weeks. The timeline table above is the planning baseline; the notes below explain where time is won or lost.
After the FMA acknowledges receipt, it carries out a completeness check followed by substantive assessment. Under MiCA, the assessment of a crypto-asset service provider application runs to a statutory period once the file is complete, and the clock is suspended while further information is requested. Incomplete applications therefore extend the effective timeline; confirm the applicable statutory periods with the FMA.
The biggest controllable variable is response quality. Maintain a single query log, assign clear owners, and reply with evidence in one consolidated response rather than piecemeal emails. Applicants who answer promptly and completely routinely shorten the overall timeline.
Once authorised, regulatory reporting and ongoing AML reporting obligations apply on a continuous basis. Diarise these deadlines before the licence is granted so that the compliance function is never caught reacting after the fact; confirm exact first-report dates with the FMA.
Budgeting realistically prevents the most damaging pitfall of all, undercapitalisation mid-application. The figures below are indicative planning ranges only; confirm current FMA fees against the published schedule and obtain tailored quotations for legal and technical work. Treat every figure as a planning estimate, not a fixed price.
Application and supervisory fees vary with complexity and supervision class and are set by the FMA’s applicable fee regulations. Always check the current schedule on the FMA website, because fee bands and supervisory classifications are updated periodically.
The largest one-off variable is the technical build. A custodian running hardware security modules, redundant cold storage and multisig infrastructure at scale sits at the upper end of the range, while a leaner model using proven vendor infrastructure sits lower.
Recurring costs, compliance staffing, annual audits, insurance and capital buffers, often exceed the one-off build over a multi-year horizon. Model these carefully in the projections you submit to the FMA.
| Cost item | Indicative range (EUR) | Notes |
|---|---|---|
| FMA application / supervisory fees | Per current FMA schedule | Depends on complexity and supervision class; check the published FMA fee schedule |
| Legal & consultancy (application, policies) | Significant one-off | Depends on scope and counsel rates |
| Technical implementation (HSM, wallet infrastructure) | Varies widely | Depends on scale and redundancy |
| Third-party audits / SOC 2 / pentests | Recurring | Regular security assurance needed |
| Capital / own-funds requirements | Set by applicable regime | See MiCA / FMA solvency rules; working capital and buffer |
| Ongoing compliance & reporting staff | Recurring | Salary, training and AML monitoring systems |
| Insurance (custody / cyber) | Recurring | Higher for combined fiat and crypto custody |
Under MiCA, crypto-asset service providers must maintain minimum own funds (the higher of a fixed floor set by the regulation or a proportion of fixed overheads, depending on the services provided). Confirm the exact own-funds figure applicable to your service classification with the FMA and current EU rules.
The TVTG remains central to understanding digital asset custody Liechtenstein obligations, because it defines token-service activities and sets out segregation and trustee-style duties for custodians. Where crypto-assets fall within scope of MiCA, the custody and administration of those assets is governed by the MiCA regime, while the TVTG continues to apply to token classification and services outside MiCA’s scope. The statutory text is available on Gesetze.li; where only the German text is available, obtain a professional translation and retain a translator’s note for your file.
The TVTG (Token- und VT-Dienstleister-Gesetz) establishes a legal framework for tokens and for the providers of token-related services, including the safekeeping of tokens on behalf of others. It defines categories of TT service provider and attaches duties around registration, organisation and the protection of client assets. Custody sits within this framework where a firm holds tokens or the keys controlling them and the activity is not otherwise governed by MiCA.
Custody is a regulated activity whenever a provider safekeeps crypto-assets or tokens, or the private keys to them, for clients. The distinguishing test is control over the asset: technical ability to move client assets brings a provider within scope of the applicable custody obligations, under MiCA for in-scope crypto-assets and under the TVTG for token-services outside MiCA, including segregation and organisational duties.
Both the TVTG and MiCA address segregation and safekeeping duties for custodians, aiming to keep client assets separate from the provider’s own estate. Banking law, by contrast, offers depositor protection and a comprehensive insolvency regime for deposit-taking institutions. The practical consequence is that a custodian must evidence insolvency-remote segregation of client assets even where it does not hold a banking licence, and must analyse which regime governs any fiat it handles.
Align your custody agreements, operations manual and technical architecture with the applicable segregation and organisational duties. Ensure client terms state clearly how assets are segregated and how they are treated on insolvency, and that these statements match what your infrastructure actually does. For comparative context, the EU’s MiCA framework on the European Commission site and prudential guidance from the European Banking Authority indicate the direction of supervisory expectations.
| Feature / obligation | MiCA crypto-asset service provider (custody) | Banking licence | TVTG (token-service, outside MiCA) |
|---|---|---|---|
| Primary regulator | FMA | FMA (banking supervision) | FMA (for TVTG activities) |
| Scope | Custody and administration of crypto-assets on behalf of clients | Broader banking, deposits, payments | Token issuance and service-provider activities outside MiCA |
| Capital & prudential rules | Minimum own-funds and safeguarding requirements under MiCA | Comprehensive capital and liquidity regime | Segregation and organisational duties for token custodians |
| Insolvency treatment | Client-asset segregation required to protect holdings | Depositor protection and insolvency regime | Addresses token segregation and trustee-style obligations |
| Licensing threshold | Authorisation required for in-scope custody services | Required for deposit-taking / banking activities | Registration/authorisation for TVTG token-service providers |
Authorisation depends on operational controls that work in practice. The FMA and international standard-setters expect a custodian to run a demonstrable, tested control environment across financial crime, key management and assurance.
Implement risk-based customer due diligence, ongoing transaction monitoring, sanctions and PEP screening, and suspicious-activity reporting to the Financial Intelligence Unit (FIU) Liechtenstein. These controls should reflect the Liechtenstein Due Diligence Act and the FATF standards for virtual asset service providers set out in the FATF guidance, including the travel rule for transfers between providers. Monitoring technology must be calibrated to the risk profile of your client base and asset types.
Private key management is the heart of digital asset safekeeping. Document key generation ceremonies, storage (cold and warm), multisig or MPC thresholds, backup, and recovery procedures. Hardware security modules and strict segregation of signing authority reduce single points of failure, and every asset movement should be logged, authorised under the four-eyes principle and reconcilable.
Maintain custody and cyber insurance sized to your holdings, commission regular security assurance such as SOC 2 and penetration testing, and run an internal audit function independent of operations. Continuous compliance means monitoring regulatory change and updating policies promptly, not revisiting them only at renewal.
Define measurable indicators: percentage of alerts cleared within target, time to complete customer due diligence, reconciliation break rates, penetration-test remediation times and training completion rates. Review core KPIs regularly, escalate breaches immediately, and report material issues to the board and, where required, to the FMA.
Once your digital asset custody Liechtenstein authorisation is granted, the focus shifts to sustaining it. The FMA supervises on an ongoing basis, and the quality of your first year of compliance sets the tone of the supervisory relationship.
Submit periodic regulatory reports on schedule and pay ongoing supervisory fees as set by the FMA. Diarise every reporting deadline and confirm the first due dates directly with the regulator so nothing is missed in the transition from applicant to licensee.
Prepare for inspections by keeping evidence current: policies, logs, audit reports and board minutes should be retrievable on request. An inspection tests whether the controls described in your application operate as documented, so maintain a live evidence library rather than reconstructing records reactively.
The regulatory landscape continues to move as MiCA implementation and related technical standards reshape supervisory expectations. Assign clear ownership for horizon-scanning, and update governance, AML and technical policies whenever the framework shifts.
Most failed or delayed applications share a small set of avoidable weaknesses. Address these before submission rather than in response to FMA queries.
Run a pre-submission review that reconciles every document against the checklist, stress-tests the segregation and insolvency wording, and confirms that the AML programme maps to FATF standards and the Due Diligence Act. Where you have any doubt on classification, obtain a written legal opinion before filing.
Setting up digital asset custody Liechtenstein authorisation in 2026 is achievable for well-prepared firms, but success depends on getting classification right across MiCA, the TVTG and banking law, evidencing insolvency-remote segregation, and presenting a coherent, consistent application to the FMA. Budget realistically, build governance and technology together, and treat segregation duties and AML controls as core rather than peripheral. Request a pre-application review to pressure-test your model before you file. Readers exploring related jurisdictional questions may also find the guide When to hire a tax lawyer in Liechtenstein (2026) useful for structuring decisions.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Julia von der Osten at VON DER OSTEN Legal, a member of the Global Law Experts network.
posted 3 minutes ago
posted 11 minutes ago
posted 20 minutes ago
posted 29 minutes ago
posted 37 minutes ago
posted 44 minutes ago
posted 52 minutes ago
posted 58 minutes ago
posted 1 hour ago
posted 1 hour ago
posted 2 hours ago
posted 2 hours ago
No results available
Find the right Legal Expert for your business
Send welcome message