If you are preparing to set up custody and wallet controls in Malta, the regulatory landscape demands far more than a secure wallet and a strong password. The Malta Financial Services Authority (MFSA) expects operators to demonstrate documented procedures, layered access controls, formal approval workflows, and an auditable evidence trail, all before the commencement of the actual operations. With the EU’s Markets in Crypto-Assets Regulation (MiCA) now fully applicable, Crypto Asset Service Providers (CASPs) seeking authorisation in Malta are required to comply with the requirements imposed by MiCA relating to custody arrangements.
This guide walks through the practical steps I advise clients on at A2CO, from the initial regulatory trigger assessment through to assembling a regulator-ready evidence package that can withstand supervisory scrutiny.
This article is written for compliance officers, founders, CTOs, and in-house counsel at Malta-based crypto businesses.
The first question every operator must answer is whether the business model actually involves custody. Not every crypto-asset activity triggers a custody authorisation requirement, but the threshold is lower than many founders expect. MiCA defines the service of providing custody and administration of crypto-assets on behalf of clients as the safekeeping or controlling on behalf of clients, of crypto-assets or of the means of access of such crypto-assets, where applicable in the form of private cryptographic keys.
In my experience, the following decision framework helps operators reach a clear answer quickly:
| Activity | Control Test | Likely Regulatory Consequence |
|---|---|---|
| Holding private keys on behalf of clients | Direct control over client assets | MiCA authorisation required, MFSA and MiCA safeguarding and custody obligations apply. |
| Pre-funding or netting client transactions before settlement | Temporary control of client crypto-assets during a window | Likely triggers MiCA authorisation. Analysis of the operations would need to be done and guidance from the MFSA would need to be sought. |
| Operating a non-custodial platform (keys remain with the user at all times) | No control over private keys or assets | MiCA authorisation generally not triggered, but evidence of non-control must be maintained. |
| Exchange operating omnibus wallets for client funds | Full control and commingling risk | Full MiCA authorisation. Rules relating to segregation also need to be adhered to in order to segregate proprietary assets of the exchange from those assets of the client. |
If any of the scenarios in the first, second, or fourth rows apply to your operation, MiCA authorisation would need to be sought before offering these services. Even operators in the third row should maintain technical flow diagrams that demonstrate non-custodial status as to able to demonstrate to any regulatory authority that the service being offered shall not be deemed to fall within the definition of ‘providing custody and administration of crypto-assets on behalf of clients’.
The MFSA rulebook and MiCA establish several baseline expectations for any authorised custody operation in Malta:
Designing custody arrangements that satisfy the MFSA requires more than technical security, it requires governance architecture that produces verifiable evidence. In my advisory work, I recommend operators build their custody framework around five core principles:
Choosing the right wallet architecture is a foundational decision that affects both security posture and regulatory compliance. National competent authorities expects operators to justify their technology choices and demonstrate that controls are proportionate to the risks involved. Below is a practical comparison of the main wallet types that are used in practice.
| Wallet Type | Key Characteristics | Recommended Controls |
|---|---|---|
| Hot wallet (software, internet-connected) | Fastest transaction execution; highest exposure to online threats | Strict value caps, real-time monitoring, automated alerts, frequent sweeps to cold storage |
| Warm wallet (semi-online, restricted access) | Balances speed and security; typically used for operational liquidity | IP whitelisting, time-delayed withdrawals, dual-approval for transfers above threshold |
| Cold wallet (offline, air-gapped) | Highest security for long-term storage; slower access | Air-gapped key generation, geographically distributed backup, physical access logs |
| Multi-signature wallet | Requires multiple private keys to sign a transaction (e.g., 2-of-3, 3-of-5) | Key holders across separate departments, documented signing ceremony, on-chain audit trail |
| MPC wallet (multi-party computation) | Splits key material across parties; no single complete private key exists | Defined computation quorum, key-share rotation schedule, vendor due diligence documentation |
For operators who adopt a secure custodial strategy implement a small hot wallet for immediate operational needs, a warm wallet for intraday liquidity, and cold storage for the majority of client assets. The exact ratio depends on transaction volume.
In my experience, MFSA supervisory teams assess not just whether controls exist, but whether the operator can produce evidence of their consistent application. The following checklist covers the artefacts I recommend every Malta custody operation maintain at all times:
For operators who determine that their activity triggers custody authorisation, the next step is engaging with the MFSA’s licensing process. While the procedural details merit a dedicated guide, the following practical observations reflect what I consistently see in applications at A2CO.
The process broadly follows these stages:
Common pitfalls I see in applications include: incomplete AML frameworks that do not address crypto-specific typologies; custody policies that lack certain safeguards; and key personnel who lack demonstrable experience in the crypto industry. Addressing these gaps before submission saves months of back-and-forth.
MiCA, the MFSA rulebook and ESMA RTS already address standards and obligations that are to be adopted by operators who offer custody services.
On 8 July 2026, ESMA launched a coordinated Common Supervisory Action (CSA) on the digital operational resilience of CASPs, with a particular focus on custody services.
The review will be conducted by national competent authorities, including the MFSA, under ESMA’s coordination and is intended to assess whether CASPs’ custody arrangements are not only compliant on paper but also effective and resilient in practice. The supervisory exercise will run from the second half of 2026 through the first half of 2027, covering areas such as governance and custody arrangements, private-key and storage management, transaction authorisation and controls, incident detection and response, smart-contract risks, and dependencies on third-party technology and infrastructure providers.
ESMA expects the consolidated findings of the exercise to be presented to its Board of Supervisors in the second half of 2027. The initiative demonstrates an increasing regulatory focus on the practical effectiveness, resilience and evidential support of CASP custody arrangements, meaning that firms should be able to demonstrate not only that appropriate policies and controls exist, but also that they operate effectively in practice and can withstand operational, technological and security risks.
The process to set up custody and wallet controls for a Malta crypto business is demanding, but the regulatory expectations are clear: documented governance, layered technical controls, operational SOPs, and a comprehensive evidence package. Operators who invest in building these foundations from the outset position themselves for faster licensing, smoother supervisory reviews, and stronger client trust. In my view, the single most valuable step any operator can take today is to run a gap assessment against the evidence checklist outlined above, identify what is missing, assign owners, and close the gaps before engaging with the MFSA.
For specialist advice on this topic, contact Anton Dalli at A2CO.
posted 8 minutes ago
posted 3 hours ago
posted 4 hours ago
posted 7 hours ago
posted 10 hours ago
posted 11 hours ago
posted 11 hours ago
posted 11 hours ago
posted 11 hours ago
posted 11 hours ago
posted 11 hours ago
posted 12 hours ago
No results available
Find the right Legal Expert for your business
Sign up for the latest legal briefings and news within Global Law Experts’ community, as well as a whole host of features, editorial and conference updates direct to your email inbox.
Naturally you can unsubscribe at any time.
Global Law Experts is dedicated to providing exceptional legal services to clients around the world. With a vast network of highly skilled and experienced lawyers, we are committed to delivering innovative and tailored solutions to meet the diverse needs of our clients in various jurisdictions.
Global Law Experts is dedicated to providing exceptional legal services to clients around the world. With a vast network of highly skilled and experienced lawyers, we are committed to delivering innovative and tailored solutions to meet the diverse needs of our clients in various jurisdictions.
Send welcome message