[codicts-css-switcher id=”346″]

Global Law Experts Logo

How to Set Up Custody and Wallet Controls for a Malta Crypto Business

By Anton Dalli
– posted 4 hours ago

If you are preparing to set up custody and wallet controls in Malta, the regulatory landscape demands far more than a secure wallet and a strong password. The Malta Financial Services Authority (MFSA) expects operators to demonstrate documented procedures, layered access controls, formal approval workflows, and an auditable evidence trail, all before the commencement of the actual operations. With the EU’s Markets in Crypto-Assets Regulation (MiCA) now fully applicable, Crypto Asset Service Providers (CASPs) seeking authorisation in Malta are required to comply with the requirements imposed by MiCA relating to custody arrangements. 

This guide walks through the practical steps I advise clients on at A2CO, from the initial regulatory trigger assessment through to assembling a regulator-ready evidence package that can withstand supervisory scrutiny.

This article is written for compliance officers, founders, CTOs, and in-house counsel at Malta-based crypto businesses. 

Quick Regulatory Decision, Does Your Activity Trigger Custody Authorisation in Malta?

The first question every operator must answer is whether the business model actually involves custody. Not every crypto-asset activity triggers a custody authorisation requirement, but the threshold is lower than many founders expect. MiCA defines the service of providing custody and administration of crypto-assets on behalf of clients as the safekeeping or controlling on behalf of clients, of crypto-assets or of the means of access of such crypto-assets, where applicable in the form of private cryptographic keys. 

In my experience, the following decision framework helps operators reach a clear answer quickly:

Activity Control Test Likely Regulatory Consequence
Holding private keys on behalf of clients Direct control over client assets MiCA authorisation required, MFSA and MiCA safeguarding and custody obligations apply.
Pre-funding or netting client transactions before settlement Temporary control of client crypto-assets during a window Likely triggers MiCA authorisation. Analysis of the operations would need to be done and guidance from the MFSA would need to be sought. 
Operating a non-custodial platform (keys remain with the user at all times) No control over private keys or assets MiCA authorisation generally not triggered, but evidence of non-control must be maintained.
Exchange operating omnibus wallets for client funds Full control and commingling risk Full MiCA authorisation. Rules relating to segregation also need to be adhered to in order to segregate proprietary assets of the exchange from those assets of the client. 

If any of the scenarios in the first, second, or fourth rows apply to your operation, MiCA authorisation would need to be sought before offering these services. Even operators in the third row should maintain technical flow diagrams  that demonstrate non-custodial status as to able to demonstrate to any regulatory authority that the service being offered shall not be deemed to fall within the definition of ‘providing custody and administration of crypto-assets on behalf of clients’. 

Key MFSA Expectations

The MFSA rulebook and MiCA establish several baseline expectations for any authorised custody operation in Malta:

  • Dual control. No single individual should have unilateral access to client private keys.
  • Local personnel. Custody operations must have locally based, competent personnel with defined roles and clear reporting lines.
  • Asset segregation. Client assets must be segregated from the operator’s proprietary assets, with clear on-chain and off-chain audit trails.
  • Regulatory reporting. Periodic and event-driven reporting obligations to the MFSA must be embedded in operational procedures.
  • AML/KYC alignment. Custody operations must integrate with the operator’s broader  anti-money laundering and know-your-customer framework.

Design Principles for Regulator-Ready Custody Wallet Controls in Malta

Designing custody arrangements that satisfy the MFSA requires more than technical security, it requires governance architecture that produces verifiable evidence. In my advisory work, I recommend operators build their custody framework around five core principles:

  • Dual control at every critical step. Every action involving private keys, transaction signing, or configuration changes must require two or more authorised individuals.
  • Least privilege access. Each team member should have only the minimum access permissions necessary for their role. Over-provisioned access is a common audit finding.
  • Separation of duties. The person who initiates a transaction must not be the person who approves it. Similarly, key generation, backup, and recovery should involve different personnel.
  • Proof of procedures. Written policies alone are insufficient. The MFSA expects to see evidence that procedures are followed in practice, signed logs, timestamped records, and audit trails.
  • Immutable, auditable logs. Transaction approval logs, key access records, and configuration changes should be stored in tamper-evident formats with retention periods aligned to regulatory expectations.

Technical Wallet Options and Recommended Controls

Choosing the right wallet architecture is a foundational decision that affects both security posture and regulatory compliance. National competent authorities expects operators to justify their technology choices and demonstrate that controls are proportionate to the risks involved. Below is a practical comparison of the main wallet types that are used in practice.

Wallet Type Key Characteristics Recommended Controls
Hot wallet (software, internet-connected) Fastest transaction execution; highest exposure to online threats Strict value caps, real-time monitoring, automated alerts, frequent sweeps to cold storage
Warm wallet (semi-online, restricted access) Balances speed and security; typically used for operational liquidity IP whitelisting, time-delayed withdrawals, dual-approval for transfers above threshold
Cold wallet (offline, air-gapped) Highest security for long-term storage; slower access Air-gapped key generation, geographically distributed backup, physical access logs
Multi-signature wallet Requires multiple private keys to sign a transaction (e.g., 2-of-3, 3-of-5) Key holders across separate departments, documented signing ceremony, on-chain audit trail
MPC wallet (multi-party computation) Splits key material across parties; no single complete private key exists Defined computation quorum, key-share rotation schedule, vendor due diligence documentation

For operators who adopt a secure custodial strategy implement a small hot wallet for immediate operational needs, a warm wallet for intraday liquidity, and cold storage for the majority of client assets. The exact ratio depends on transaction volume. 

Evidence and Audit Package, What to Prepare for MFSA Review

In my experience, MFSA supervisory teams assess not just whether controls exist, but whether the operator can produce evidence of their consistent application. The following checklist covers the artefacts I recommend every Malta custody operation maintain at all times:

  • Custody and key management policy. Board-approved document covering key generation, storage, rotation, backup, and destruction procedures.
  • Transaction approval logs. Complete, timestamped records of every transaction initiated, approved, executed, or rejected.
  • Key access and signing logs. Records of every instance a private key (or key share) was accessed, by whom, and for what purpose.
  • System architecture diagrams. Current diagrams showing wallet infrastructure, network segmentation, and data flows.
  • Personnel records. Fit-and-proper assessments, appointment letters, role descriptions, and training completion records for all custody-related staff.
  • Penetration test and vulnerability assessment reports. At least annual, conducted by an independent third party.

MFSA Authorisation for Custody Services 

For operators who determine that their activity triggers custody authorisation, the next step is engaging with the MFSA’s licensing process. While the procedural details merit a dedicated guide, the following practical observations reflect what I consistently see in applications at A2CO.

The process broadly follows these stages:

  1. Pre-application engagement. Reach out to the MFSA informally to discuss your business model, proposed custody arrangements, and technology stack. This step is not mandatory, but in my experience it significantly reduces the risk of surprises later.
  2. Submission of Intent. A letter of intent, a legal opinion and an introductory presentation is presented to the MFSA so they will preliminary assess whether they foresee any objections in the operators to submit the formal application for authorisation. 
  3. Formal submission. Submit the application through the MFSA’s designated channels with all supporting annexes.
  4. Review and iteration. The MFSA will issue queries and requests for clarification. Expect multiple rounds, response times vary, but a well-prepared application typically reaches a decision faster.
  5. Authorisation and ongoing compliance. Upon approval, the operator must comply with all licence conditions, reporting obligations, and ongoing supervisory requirements.

Common pitfalls I see in applications include: incomplete AML frameworks that do not address crypto-specific typologies; custody policies that lack certain safeguards; and key personnel who lack demonstrable experience in the crypto industry. Addressing these gaps before submission saves months of back-and-forth.

Emerging Trends 

MiCA, the MFSA rulebook and ESMA RTS already address standards and obligations that are to be adopted by operators who offer custody services. 

On 8 July 2026, ESMA launched a coordinated Common Supervisory Action (CSA) on the digital operational resilience of CASPs, with a particular focus on custody services. 

The review will be conducted by national competent authorities, including the MFSA, under ESMA’s coordination and is intended to assess whether CASPs’ custody arrangements are not only compliant on paper but also effective and resilient in practice. The supervisory exercise will run from the second half of 2026 through the first half of 2027, covering areas such as governance and custody arrangements, private-key and storage management, transaction authorisation and controls, incident detection and response, smart-contract risks, and dependencies on third-party technology and infrastructure providers.

ESMA expects the consolidated findings of the exercise to be presented to its Board of Supervisors in the second half of 2027. The initiative demonstrates an increasing regulatory focus on the practical effectiveness, resilience and evidential support of CASP custody arrangements, meaning that firms should be able to demonstrate not only that appropriate policies and controls exist, but also that they operate effectively in practice and can withstand operational, technological and security risks.

Conclusion and Recommended Next Steps

The process to set up custody and wallet controls for a Malta crypto business is demanding, but the regulatory expectations are clear: documented governance, layered technical controls, operational SOPs, and a comprehensive evidence package. Operators who invest in building these foundations from the outset position themselves for faster licensing, smoother supervisory reviews, and stronger client trust. In my view, the single most valuable step any operator can take today is to run a gap assessment against the evidence checklist outlined above, identify what is missing, assign owners, and close the gaps before engaging with the MFSA.

Need Advice?

For specialist advice on this topic, contact Anton Dalli at A2CO.

Sources

    1. Malta Financial Services Authority, Official Website
    2. European Commission, Overview of Markets in Crypto-Assets Regulation (MiCA)
    3. EUR-Lex, Official EU Legislation Database (MiCA Regulation)
    4. ESMA launches Common Supervisory Action

 

FAQs

How do I set up a self-custody wallet?
Choose the appropriate wallet type (hardware, software, or multisig), generate private keys in an air-gapped environment where possible, securely document seed phrase storage, and implement a signing and recovery SOP that defines who can access backups and under what conditions.
Yes, custodial risk exists through hacking, insolvency, or operational mismanagement. Mitigate this through thorough due diligence on the custodian, contractual segregation requirements, adequate insurance coverage, and robust audit rights.
Receiving cryptocurrency as payment is not per se illegal in Malta. However, tax reporting obligations and AML requirements apply. Operators and individuals should consult MFSA guidance and Malta’s tax rules for the correct treatment of crypto-asset income.
Custody authorisation is triggered when an operator exercises control over private keys on behalf of clients, or temporarily assumes control of client crypto-assets, for example, during pre-funding or netting. The MFSA’s custody guide identifies these control scenarios as authorisation triggers.
Multisig distributes complete private keys among multiple signers, with each signature visible on-chain. MPC splits key material across parties so that no single complete key ever exists, but produces a single on-chain signature. Both reduce single-point-of-failure risk, but differ in auditability and implementation complexity.
At minimum: a board-approved custody and key management policy, transaction approval and signing logs, system architecture diagrams, personnel fit-and-proper records, penetration test reports, reconciliation reports, and an incident response runbook.
Use value-based thresholds with escalating sign-off requirements, enforce separation of duties between initiators and approvers, require independent reconciliation for high-value transactions, and store every approval decision in an immutable, timestamped log.
how much does it cost to start a foundation in switzerland
By Global Law Experts

posted 11 hours ago

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Join
who are already getting the benefits
0

Sign up for the latest legal briefings and news within Global Law Experts’ community, as well as a whole host of features, editorial and conference updates direct to your email inbox.

Naturally you can unsubscribe at any time.

About Us

Global Law Experts is dedicated to providing exceptional legal services to clients around the world. With a vast network of highly skilled and experienced lawyers, we are committed to delivering innovative and tailored solutions to meet the diverse needs of our clients in various jurisdictions.

Global Law Experts App

Now Available on the App & Google Play Stores.

Social Posts
[wp_social_ninja id="50714" platform="instagram"]
[codicts-social-feeds platform="instagram" url="https://www.instagram.com/globallawexperts/" template="carousel" results_limit="10" header="false" column_count="1"]

See More:

Contact Us

Stay Informed

Join Mailing List
About Us

Global Law Experts is dedicated to providing exceptional legal services to clients around the world. With a vast network of highly skilled and experienced lawyers, we are committed to delivering innovative and tailored solutions to meet the diverse needs of our clients in various jurisdictions.

Social Posts
[wp_social_ninja id="50714" platform="instagram"]
[codicts-social-feeds platform="instagram" url="https://www.instagram.com/globallawexperts/" template="carousel" results_limit="10" header="false" column_count="1"]

See More:

Global Law Experts App

Now Available on the App & Google Play Stores.

Contact Us

Stay Informed

GLE

Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

How to Set Up Custody and Wallet Controls for a Malta Crypto Business

Send welcome message

Custom Message