Solutions

Web3 Legal Due Diligence

Whether a project's entities, token, services, controls, records and market access actually comply with applicable law — tested the way an investor, acquirer, lender, exchange, foundation or counterparty should test it before reliance. Labels do not decide legal classification. Evidence does.

Scope a due diligence review
Part 01

The Method

How every review is decided
In essence

Web3 legal due diligence tests whether a project’s entities, token, services, controls, records, and market access comply with applicable law. The question is how an investor, acquirer, lender, exchange, foundation, or counterparty should examine those matters before reliance. No project file, transaction document, product specification, or jurisdiction list was supplied. This session states the general decision method, material issue map, evidence standard, and regional work plan. It does not give any named project a clean legal opinion.

Executive summary
Global

Legal due diligence must start with an activity, actor, control, and territory map. Project labels do not decide legal classification.

Global

The reviewer should match each representation to evidence: official register entries, executed instruments, verified on-chain records, code repositories, financial records, or regulator correspondence. Unsupported management statements remain unverified.

Corporate

A foundation, DAO, laboratory company, token issuer, treasury company, and front-end operator may form one economic project but remain separate legal persons. The review must trace assets, obligations, personnel, intellectual property, revenue, and decision rights across them.

Licensing

Incorporation never acts as a licence or worldwide passport. Each service and solicitation channel must be tested where the service is performed and where users are targeted.

Token

“Utility,” “NFT,” “decentralised,” and “non-custodial” are factual claims, not safe harbours. Rights, economics, marketing, control, and transaction design govern the result.

Assets and controls

Client asset title, key control, segregation, staking, rehypothecation, minting, upgrades, pausing, blacklisting, oracle changes, and treasury access deserve early review. A defect here can create licensing, insolvency, disclosure, and fiduciary exposure at once.

Transaction

Findings should be assigned to four outcomes: stop or restructure; condition precedent; price, escrow, or indemnity protection; or monitored remediation.

Regional plan

The priority sequence is offshore, EU/EEA plus adjacent European hubs, Middle East, Asia, then a United States and United Kingdom exposure overlay. This is a risk-based work order, not a measured ranking of project domiciles.

Analysis by issue

Decision standard and review perimeter

A defensible review must answer a transaction question. The materiality standard differs for an acquisition, token listing, equity investment, lending, custody integration, or service partnership. The first workpaper should state the contemplated decision, risk tolerance, closing date, and available remedies.

No project facts have been supplied. The present answer therefore uses the perspective of an investor or acquirer reviewing a live Web3 project. A later project review must replace every general proposition with verified facts and named authorities.

Legal DD is not only a current-state compliance review. It must capture historic offers, earlier service periods, discontinued interfaces, predecessor entities, old terms, and former wallets. A later cure does not erase accrued liability.

The reviewer should classify each material fact as documented, reported, disputed, inferred, or not verified. On-chain data may prove a transaction, wallet balance, signer set, or contract state. It does not prove legal title, authority, beneficial ownership, or compliance by itself. Marketing may prove what the project represented. It does not prove the representation was true.

Activity, actor, control, and territory map

The first substantive finding should identify who does what, through which system, under whose control, and for which users. Four linked maps are required.

01
Entity map

The entity map covers every company, foundation, trust, partnership, DAO wrapper, branch, nominee, and material natural person. It records formation, status, ownership, directors, officers, employees, contractors, bank accounts, wallets, domains, and contracts.

02
Activity map

The activity map assigns issuance, sale, exchange, matching, dealing, broking, custody, transfer, payments, lending, borrowing, staking, advice, portfolio services, market making, validation, oracle operation, bridge operation, and software access to named actors. A licence analysis that assigns activities only to “the project” is incomplete.

03
Control map

The control map records every power over deployed code and assets. It covers admin, proxy upgrade, pause, mint, burn, blacklist, fee, oracle, bridge, treasury, validator, vesting, and emergency powers. It also records signers, thresholds, hardware custody, rotation, delegation, time locks, and recovery procedures. A DAO vote does not remove central control when another person can override or bypass it.

04
Territory map

The territory map records user residence, active marketing, languages, fiat rails, local affiliates, employees, events, app-store distribution, domains, geoblocking, and support channels. The reviewer should preserve evidence for any claimed exclusion or reverse-solicitation model.

Corporate status and group integrity

A project should fail corporate review when the entities that sign, hold assets, employ staff, and make public claims cannot be reconciled. The cure may require assignments, novations, board approvals, restructuring, or disclosure.

The reviewer should verify existence, good standing, constitutional documents, registers, beneficial owners, share capital, options, warrants, convertibles, side letters, director appointments, delegated authority, and reserved matters. Token rights and token allocations should be reconciled against the equity capitalization. Undisclosed token entitlements can dilute project economics without appearing on the cap table.

The review should test intercompany agreements. A foundation may appear to steward a protocol while a laboratory company owns the code and controls releases. An issuer may have sale proceeds but no contract for development. A treasury company may fund grants without written authority. Those gaps can impair asset ownership, tax positions, director decision-making, and creditor recovery.

Substance also matters. Board minutes, decision records, local officers, premises, payroll, banking, and actual management should match claims about residence and management. Registered-office services alone do not establish operational substance.

Where no effective wrapper exists, local law may characterise participants as an unincorporated association, partnership, joint venture, agents, or direct principals. The review should test who can own property, contract, sue, be sued, pay tax, and bear project liabilities.

Token and product classification

Token analysis must examine each transaction and stage separately. The initial fundraising, current token, staking program, lending interface, wrapping process, bridge, liquidity pool, and secondary-market support may produce different legal outcomes.

The review should identify voting rights, profit rights, revenue sharing, interest, yield, redemption, reserve claims, liquidation rights, asset backing, usage rights, transfer limits, supply changes, burn mechanics, lockups, and reliance on a managerial group. It should compare those terms with white papers, websites, social media, exchange applications, investor decks, sale agreements, and code.

Labels do not control. MiCA excludes qualifying unique and non-fungible crypto-assets, yet it directs a substance-based review of fractional parts and large series or collections. It also excludes financial instruments from its own scope because other Union law applies. Regulation (EU) 2023/1114, recitals 9–11 and art. 2(3)–(4). A regional opinion must therefore test securities, financial instruments, fund interests, derivatives, deposits, payments, electronic money, stablecoins, commodities, and consumer products before applying a crypto-specific statute.

A token opinion has a limited shelf life when rights, code, marketing, or control change. The reviewer should record the tested version, contract addresses, chain, date, factual assumptions, and excluded services. Reliance on an old opinion without that comparison is a red flag.

Licensing, solicitation, and territorial reach

The licensing answer follows the activity map, not the incorporation certificate. The reviewer must identify each regulated act, the actor performing it, the place of performance, the users reached, exemptions, licence scope, and any transition rule.

MiCA states that a person may not provide crypto-asset services within the Union unless authorised or otherwise eligible under Article 60. Regulation (EU) 2023/1114, art. 59. Its reverse-solicitation rule applies only when the client initiates the service on that client’s exclusive initiative. Prior solicitation or promotion defeats reliance, and a disclaimer does not cure the facts. Id. art. 61.

The same method applies elsewhere. The review should check official registers, licence conditions, approved activities, legal entity names, trade names, domains, and branches. A licence held by one group company cannot be attributed to another. A pending application is not a licence. A business-company registration is not authorisation for financial services.

Geoblocking helps only when actual conduct supports it. The reviewer should test IP controls, residence checks, payment methods, affiliate links, local-language content, support tickets, event attendance, and exception logs. A terms clause that excludes a country carries little weight when the product accepts and serves users there.

Financial crime, sanctions, and transfer controls

A policy-only review is inadequate. The reviewer should test whether controls operated during the relevant period and covered the actual products, chains, users, and counterparties.

The review should cover customer and beneficial-owner identification, risk ratings, politically exposed persons, sanctions screening, source of funds, source of wealth, transaction monitoring, blockchain analytics, suspicious-activity escalation, Travel Rule data, self-hosted wallets, record retention, staff training, independent testing, and outsourced vendors. It should sample onboarding files and alerts, not only read manuals.

Sanctions analysis remains separate from licensing and AML registration. A protocol may lack a customer relationship yet still expose controlled persons to prohibited dealings, blocked property, facilitation, or circumvention risk. The review should identify who can block access, freeze assets, reject transactions, alter the interface, or screen wallet addresses. It should compare public claims of permissionlessness with retained controls.

Privacy coins, mixers, bridges, chain hopping, nested services, and high-risk jurisdictions require product-specific testing. The report should state the data sources, detection limits, escalation rules, and treatment of false positives.

Client assets, custody, staking, and insolvency

The reviewer should decide who holds legal title, who controls transfer, where assets sit, and what happens on insolvency. “Non-custodial” is not established by contract wording when a person can move assets unilaterally or jointly.

The evidence should cover wallet architecture, signer sets, key ceremonies, omnibus or segregated wallets, reconciliations, client ledgers, bank accounts, trust terms, liens, set-off, rehypothecation, staking, slashing, validator selection, forks, airdrops, insurance, and recovery plans. Terms must match the code and operations.

MiCA requires crypto-asset service providers holding client assets or access means to protect client ownership rights, particularly on insolvency, and to prevent own-account use. Regulation (EU) 2023/1114, art. 70. Singapore imposes specific client-asset duties on digital payment token service providers under the Payment Services Regulations 2019, regs. 18A–18J. Japan requires crypto-asset exchange service providers to segregate user money and crypto-assets under the Payment Services Act, art. 63-11. Those rules show why generic custody language cannot replace jurisdiction-specific title and insolvency analysis.

Staking creates distinct questions. The reviewer should identify whether the provider transfers title, pools assets, selects validators, promises a fixed return, bears slashing, takes a spread, or can delay withdrawals. Each feature may alter licensing, disclosure, tax, insolvency, and product classification.

Code, intellectual property, and operational resilience

Legal review should establish ownership and lawful use of the project’s code, data, brands, domains, content, and inventions. A technical audit answers different questions and cannot substitute for chain-of-title review.

The file should contain employee and contractor assignments, invention clauses, contributor agreements, open-source notices, third-party licences, trademark records, domain ownership, hosting agreements, audit reports, bug-bounty terms, and incident records. The reviewer should identify copyleft triggers, attribution duties, source-disclosure duties, field restrictions, and incompatible licences.

The control review should compare repositories with deployed bytecode and proxy implementations. It should record unaudited changes, emergency deployments, oracle dependencies, bridge dependencies, sequencer control, validator concentration, cloud concentration, and single-person access. A legal representation that code is immutable is false when upgrade keys remain active.

Operational duties may follow from financial-services law. DORA applies detailed information and communications technology risk, incident, testing, and third-party duties to covered EU financial entities. Regulation (EU) 2022/2554, arts. 2, 5–16, 17–23 and 28–44. The project file should therefore connect security reports to legal obligations and contractual remedies.

Treasury, token economics, and market conduct

The reviewer should reconcile token economics against actual wallets and contracts. Required evidence includes genesis allocations, treasury wallets, vesting contracts, unlocks, emissions, mint authority, burns, grants, employee awards, investor rights, foundation sales, market-maker loans, exchange agreements, liquidity programs, buybacks, and price-support communications.

Insider wallets should be identified and tested against disclosed allocations. Transfers should be compared with lockups, board approvals, tax records, and public statements. Unexplained wallets or discretionary mint rights may affect valuation, control, disclosure, and market-abuse risk.

Market-maker agreements require close review. The file should show loan size, return rights, option terms, spread targets, inventory limits, reporting, venue scope, conflicts, and prohibited conduct. The project should not direct wash trading, spoofing, artificial volume, or undisclosed price support.

MiCA’s market-abuse title reaches conduct concerning crypto-assets admitted to trading or requested for admission and addresses inside information, insider dealing, unlawful disclosure, and manipulation. Regulation (EU) 2023/1114, arts. 86–92. The DD report should connect token unlocks, listing decisions, treasury trades, and market-maker instructions to those rules.

Data, consumer terms, and communications

The project should identify each controller, processor, dataset, purpose, legal basis, recipient, retention period, and transfer route. Wallet addresses, device data, IP addresses, support records, identity files, and behavioural analytics may be personal data when linked or linkable to a person.

The GDPR requires lawful, fair, and transparent processing, purpose limitation, data minimisation, security, and controlled international transfers. Regulation (EU) 2016/679, arts. 5, 6, 13–14, 25, 32 and 44–49. Public-blockchain immutability does not remove those duties. The review should examine off-chain storage, hashing, deletion methods, access controls, and allocation of responsibility.

User terms should match the service. The reviewer should test formation, entity identity, fees, risk disclosures, service scope, suspension, forks, airdrops, staking, title, complaints, unilateral amendment, liability limits, governing law, arbitration, and class-action language. Consumer law may restrict clauses even when users clicked acceptance.

Marketing review should cover websites, social accounts, influencers, referral programs, community moderators, exchange announcements, and paid media. Risk warnings should be prominent and product-specific. An offshore disclaimer does not cure active solicitation into a regulated market.

Common defences and their limits

A project may argue that decentralisation removes any accountable service provider. That argument deserves factual testing. A mature protocol with immutable code, dispersed control, no custody, and no coordinated operator may narrow some licensing and agency theories. It does not resolve the status of issuers, front-end operators, treasury actors, promoters, or earlier conduct.

A non-custodial claim depends on actual transfer power. Joint signatures, recovery keys, upgrade rights, relayers, transaction screening, or emergency modules may show material control. The analysis should distinguish technical participation from legal custody under each statute.

A software-publisher defence also depends on conduct. Fees, routing, order selection, interface design, curated pools, listing decisions, transaction support, and retained control may connect the publisher to a regulated service. Pure publication can present a different case, but the reviewer should not assume it.

A utility or NFT label does not answer product classification. The token’s rights, sale method, marketing, fungibility, series size, managerial reliance, redemption, and secondary-market support remain relevant. The analysis should cover the fundraising transaction and the current asset separately.

An offshore entity does not displace host-country law. A reverse-solicitation defence requires client initiative and absence of prior solicitation. “Code is law” cannot override sanctions, insolvency, consumer, property, or criminal law. Open-source distribution does not prove ownership, licence compliance, or freedom from regulated activity.

Tax, employment, accounting, and substance

Legal DD should identify tax residence, permanent establishments, token-sale treatment, treasury gains, staking income, withholding, value-added or goods-and-services tax, transfer pricing, payroll, token compensation, and reporting. Local tax counsel must confirm the result in each material jurisdiction.

The group should reconcile legal ownership with financial statements and wallet records. The reviewer should test revenue recognition, client-asset treatment, reserves, token liabilities, related-party balances, treasury valuation, and contingent liabilities. Unaudited wallet schedules should not be treated as audited accounts.

Employment review should identify the actual employer, work location, worker status, intellectual-property assignment, confidentiality, token compensation, sanctions restrictions, immigration, payroll, and termination exposure. A distributed team can create local employment and tax duties even when the group has no local subsidiary.

Disputes, incidents, and remedies

The DD file should cover regulator inquiries, licence applications, refusals, warning-list entries, subpoenas, civil claims, arbitration, employment disputes, hacks, exploits, lost keys, sanctions blocks, data breaches, market incidents, and insurance notifications. It should distinguish allegations from findings and closed matters from ongoing exposure.

A past exploit requires more than a post-mortem. The reviewer should test loss allocation, reimbursement, waivers, releases, chain forks, recoveries, insurance, accounting, tax, law-enforcement contact, code changes, and repeated root causes.

Remedies matter to materiality. A legal breach with a clear licence path may support a condition precedent. An historic token sale with uncertain claimant exposure may require escrow and indemnity. A sanctions or client-asset defect may require suspension or restructuring before closing.

Finding levels and transaction treatment

Each finding should state the verified fact, applicable authority, legal rule, analysis, counterargument, probability or uncertainty, financial and operational effect, proposed cure, owner, deadline, and closing treatment.

Stop or restructure findings include an unlicensed core service, false licence claims, sanctions exposure, missing ownership of core code, undisclosed central control, client-asset commingling, or no accountable issuer for binding obligations.

Conditions precedent include licence or registration completion, corporate restructuring, intellectual-property assignments, contract novations, key rotation, wallet segregation, policy implementation, disclosures, or regulator clearance.

Price, escrow, and indemnity findings cover legacy tax, employment, token-sale, customer, intellectual-property, and contractual liabilities that cannot be cured before closing. The protection must match the claimant, limitation period, loss measure, and enforcement forum.

Monitored remediation covers lower-severity gaps with a named owner, objective evidence, deadline, and consequence for failure. A promise to improve without those terms is not a remediation plan.

Priority evidence request

The next project-specific review should begin with this source bundle:

Current group chart; formation and good-standing records; constitutional documents; director and owner registers; cap table; financing instruments; side letters; material resolutions.
Token terms; white papers; sale documents; investor decks; allocation and vesting schedules; contract addresses; audits; token-holder rights; exchange and market-maker files.
Wallet inventory; wallet purpose; beneficial controller; signer list; thresholds; key procedures; treasury history; client-asset reconciliations; staking and validator records.
Licence and registration records; legal opinions; regulator correspondence; warning-list checks; user-country data; marketing files; geoblocking evidence.
AML, sanctions, Travel Rule, transaction-monitoring, privacy, incident, complaints, outsourcing, and business-continuity records, plus operating samples.
Employment, contractor, invention-assignment, contributor, open-source, trademark, domain, hosting, oracle, bridge, cloud, and audit files.
User terms; privacy notices; cookie records; consumer disclosures; influencer and affiliate agreements; referral terms; support scripts.
Financial statements; management accounts; bank records; treasury schedules; tax returns; tax opinions; insurance; disputes; claims; incident losses.
Part 02

Offshore

Cayman · BVI · Bermuda · Bahamas · Seychelles · Mauritius
In essence

This session examines legal due diligence for Web3 projects incorporated, licensed, or operated through the Cayman Islands, British Virgin Islands, Bermuda, The Bahamas, Seychelles, or Mauritius. The question is whether each project entity has legal capacity, the correct regulated status, sufficient local substance, enforceable rights to its assets, compliant client-asset arrangements, and every approval needed for the proposed transaction. No project documents or transaction terms were supplied. This analysis therefore establishes the offshore due-diligence test and does not clear any named project.

Executive summary
Offshore

Incorporation does not authorise virtual-asset activity. The reviewer must match each entity’s actual services, users, assets, and control powers to its licence, registration, waiver, or exclusion.

Cayman Islands

Custody providers and virtual-asset trading platforms require a licence. Other covered virtual-asset services generally require registration, unless a statutory waiver or sandbox status applies. The 2026 amendments also remove qualifying tokenised mutual-fund and private-fund interests from ordinary virtual-asset issuance treatment. Virtual Asset (Service Providers) Act (2024 Revision), ss. 3–4; Virtual Asset (Service Providers) (Amendment) Act 2026, s. 2.

British Virgin Islands

A BVI business company offering virtual-asset services outside the BVI is deemed to provide those services from within the BVI. Software, unhosted-wallet, infrastructure, and network-operation exclusions apply only where the activity remains within the statutory exclusion. Virtual Assets Service Providers Act 2022, ss. 2 and 5.

Bermuda

Digital-asset businesses operate under Class F, M, or T licences. Class M and T licences have defined periods, while Class T covers pilot or beta activity. Except for Class T, a licensed undertaking must maintain its head office in Bermuda and direct and manage the licensed business from Bermuda. Digital Asset Business Act 2018, ss. 12–13 and 21.

The Bahamas

The Digital Assets and Registered Exchanges Act 2024 expressly addresses exchanges, custody, advice, management, staking, token offerings, stablecoins, and market conduct. Material business changes, mergers, asset sales, share transfers, and beneficial-owner changes generally require prior Commission approval. Digital Assets and Registered Exchanges Act 2024, ss. 9 and 17–20.

Seychelles

The FSA identifies four authorisation categories: wallet services, exchange services, broking, and investment services. ICO and NFT projects use a separate registration route. An entity shown as under “Assessment” benefits only from the stated transitional treatment and must not be represented as fully licensed.

Mauritius

The current licence schedule contains Classes M, O, R, I, and S for broker-dealer, wallet, custody, advisory, and marketplace activity. A VASP must have a physical office in Mauritius and direct and manage its business from Mauritius. Initial token issuers use a separate registration route. Virtual Asset and Initial Token Offering Services Act 2021, ss. 7–10 and 23–26.

Client assets

Cayman, Bermuda, The Bahamas, and Mauritius impose express segregation or creditor-protection duties. BVI law requires custody safeguards, detailed client agreements, asset protection, and restrictions on encumbrance. Contract wording alone cannot establish compliance.

Transaction

Unlicensed core activity, false licence claims, client-asset shortfalls, missing regulatory consent, invalid local substance, or misclassified token offerings should stop closing or require restructuring. Historic exposure usually requires escrow, indemnity, price protection, or a retained-liability arrangement.

Analysis by issue

Comparative decision rule

An offshore legal opinion should not answer only whether “the project is incorporated in Cayman” or another offshore jurisdiction. It should answer six linked questions.

1

which legal person performs each activity? The token issuer, foundation, software company, treasury company, front-end operator, custodian, market maker, and development company may be different entities.

2

what activity does each person perform? The review must identify issuance, sale, exchange, transfer, custody, dealing, broking, management, advice, lending, staking, payment, validation, liquidity provision, and interface operation.

3

where is each activity carried on? Relevant facts include incorporation, management, personnel, infrastructure, users, marketing, contracts, fee collection, and wallet control.

4

what control does each person retain? The review must map upgrade keys, pause rights, minting, blacklisting, treasury signers, validator selection, oracle changes, fee changes, token listings, and front-end access.

5

what regulated status covers that activity? The reviewer must obtain the actual licence or registration instrument, conditions, approved activity schedule, official register entry, expiry date, waiver, and regulator correspondence.

6

what evidence supports each conclusion? Articles of association, executed agreements, regulator records, wallet evidence, deployed code, accounting records, user data, and board records carry more weight than management statements.

A legal opinion addressed only to the token issuer is incomplete when another entity operates the interface, controls user assets, collects fees, or markets the product. The review must follow the economic and technical conduct across the full group.

Comparative perimeter

Jurisdiction Principal regulated status Material territorial rule Main product issue Transaction-control issue
Cayman Islands Licence for custody and trading platforms; registration for other covered services Activity carried on in or from the Islands Tokenised fund interests may fall under the Mutual Funds Act or Private Funds Act Ownership, director, officer, licence-condition, and business-scope approvals must be checked
BVI Activity-specific VASP registration A BVI business company serving users abroad is deemed to operate from the BVI Software and network exclusions are narrow and fact-dependent Significant or controlling interests cannot be transferred or acquired without prior FSC approval
Bermuda Class F, M, or T digital-asset business licence Bermuda entities conducting digital-asset business and foreign entities operating in or from Bermuda are covered Token issuance may also engage the Digital Asset Issuance Act Material changes use a notice and non-objection process
The Bahamas Registration by digital-asset activity Local retail solicitation and activity conducted through a place in The Bahamas can create nexus Express rules cover staking, stablecoins, offerings, exchanges, and custody At least 28 days’ advance application applies to listed material changes
Seychelles VASP licence by service class; ICO and NFT registration Services carried on in or from Seychelles Transitional “Assessment” status must not be described as a licence Direct FSA confirmation is required where the public register is ambiguous
Mauritius Class M, O, R, I, or S licence; separate ITO registration Physical office plus direction and management from Mauritius A token classified as a security exits the ITO route and proceeds under securities law Business-scope, legal-structure, merger, share, controller, and officer changes require review

These statutes use different nexus and perimeter tests. A group cannot rely on one generic “offshore” opinion. The analysis must be performed separately for each entity and service.

Cayman Islands

Authorisation perimeter

The Cayman Act permits specified legal forms to provide virtual-asset services in or from the Islands. Covered persons must hold registration, a custody or trading-platform licence, a statutory waiver, or sandbox authorisation. A natural person cannot conduct the regulated business directly. Virtual Asset (Service Providers) Act (2024 Revision), ss. 3–4.

Since 1 April 2025, virtual-asset custody and virtual-asset trading-platform services require a licence. Other covered services remain within the registration route unless a waiver applies to an existing regulated person.

The platform definition deserves technical review. It may capture a centralised or decentralised platform that facilitates third-party exchange for a fee or other benefit and also holds custody, controls assets, or interposes itself between counterparties. A site that only provides a neutral forum, with no further regulated features, can present a different case. Virtual Asset (Service Providers) Act (2024 Revision), s. 2.

The due-diligence team should test:

  • the exact entity named on the CIMA record;

  • whether it holds registration, a licence, a waiver, or sandbox status;

  • the authorised service category;

  • licence conditions and restrictions;

  • approved directors, officers, trustees, and AML officers;

  • all trading names, domains, applications, and contract counterparties;

  • whether the current product differs from the approved business plan.

A registration certificate for issuance or transfer services does not authorise custody or operation of a trading platform. A group licence cannot be attributed to an affiliate.

Tokenised funds and issuance

The Virtual Asset (Service Providers) (Amendment) Act 2026 excludes two forms of tokenised fund issuance from the ordinary definition of virtual-asset issuance. These are a digital equity token issued by a tokenised mutual fund under the Mutual Funds Act and a digital investment token issued by a tokenised private fund under the Private Funds Act. Virtual Asset (Service Providers) (Amendment) Act 2026, s. 2.

That exclusion is not deregulation. It redirects the analysis to the fund statutes. The reviewer must determine whether the entity is a mutual fund or private fund, whether the token represents an equity or investment interest, and whether the fund is registered or licensed correctly.

A tokenised fund opinion should cover:

  • the fund’s legal form and constitutional documents;

  • investor redemption or withdrawal rights;

  • pooling and investment activity;

  • valuation and net-asset-value processes;

  • administrator, auditor, custodian, and operator appointments;

  • token-holder records and transfer restrictions;

  • consistency between the token contract and the fund register;

  • treatment of lost keys, forks, freezes, and court orders.

A token cannot be treated as a simple utility token merely because transfers occur on-chain.

Client assets and custody

The Cayman Act permits CIMA to impose safekeeping, segregation, insurance, cybersecurity, disclosure, and net-worth requirements. It also restricts encumbrance of client virtual assets without the beneficial owner’s agreement. A custody agreement must address holding arrangements, permitted transactions, risks, remuneration, access, termination, safeguards, and remedies. Virtual Asset (Service Providers) Act (2024 Revision), s. 10.

CIMA’s February 2026 Market Conduct measure requires custodians to identify and segregate client assets from their own assets and group assets. It also requires protection of client virtual assets and fiat funds from third-party creditors. Trading platforms and custodians must perform frequent reconciliations. The accompanying guidance states that custodians should reconcile at least daily. The daily interval is guidance, while the duty to conduct suitable, frequent reconciliation is a rule.

The reviewer should obtain:

  • all omnibus, segregated, hot, warm, and cold-wallet addresses;

  • each signer and signing threshold;

  • policies governing key generation, backup, recovery, and rotation;

  • client-level ledgers;

  • daily or other reconciliation records;

  • discrepancy and break reports;

  • evidence of creditor protection;

  • proof that client and proprietary assets are not mixed;

  • staking, airdrop, voting, and fork allocation terms;

  • insurance and incident records;

  • outsourcing and sub-custody agreements.

A clean custody conclusion requires legal and operational evidence. A terms clause cannot cure wallets that mix client and treasury assets.

Cayman finding standard

The project should receive a stop or restructuring finding where:

  • custody or a trading platform operates under registration alone;

  • an affiliate uses another entity’s CIMA status;

  • the project’s deployed functions exceed the approved scope;

  • client assets are commingled;

  • reconciliations are absent or unreliable;

  • tokenised fund interests were treated as ordinary token issuance;

  • required directors or approved officers are missing;

  • the project represented that incorporation or a pending application constituted authorisation.

British Virgin Islands

Territorial reach

The BVI rule is unusually direct. A BVI business company that provides, or holds itself out as able to provide, virtual-asset services outside the BVI is deemed to conduct that business from within the BVI. Virtual Assets Service Providers Act 2022, s. 5(4).

A BVI issuer or laboratory company therefore cannot rely on the absence of BVI users. The reviewer must test what the company itself does worldwide.

Covered activities include fiat-to-virtual-asset exchange, virtual-asset exchange, transfers for others, safekeeping or administration, and financial services connected with an issuer’s offer or sale. Virtual Assets Service Providers Act 2022, s. 2.

Software and network exclusions

The Act excludes several limited activities. These include ancillary infrastructure, pure software development, unhosted-wallet hardware or software, sole creation or sale of an application or platform, and sole operation of a network without customer-facing VASP activity. The exclusions cease to assist when the person actively facilitates covered services for others. Virtual Assets Service Providers Act 2022, s. 2(2).

The reviewer should test whether the purported software company:

  • collects transaction-based fees;

  • selects or routes orders;

  • lists or delists tokens;

  • controls liquidity pools;

  • operates relayers;

  • can pause or upgrade contracts;

  • operates the principal interface;

  • provides customer support;

  • controls access;

  • executes transfers;

  • has custody or joint custody;

  • participates in token sales;

  • contracts with users.

A company that performs these acts should not rely on a “software only” memorandum without a fresh perimeter analysis.

Registration scope and local arrangements

The registration categories distinguish general VASP services, custody, and exchange operation. Custody providers and exchanges also face the activity-specific requirements in Part IV of the Act. Virtual Assets Service Providers Act 2022, ss. 6 and 27–30.

A VASP generally needs an approved authorised representative unless it has sufficient management presence in the BVI. The authorised representative acts as the principal intermediary with the FSC, accepts formal notices, and maintains prescribed records. The VASP must also appoint an auditor unless the FSC grants an exemption. Virtual Assets Service Providers Act 2022, ss. 12–14.

The due-diligence review should verify:

  • the official FSC registration entry;

  • each authorised service;

  • registered office and business address;

  • authorised representative;

  • directors and senior officers;

  • auditor or exemption;

  • financial-resource requirements;

  • regulatory returns;

  • conditions imposed by the FSC;

  • regulatory correspondence;

  • any warning, restriction, suspension, or enforcement action.

Ownership and transaction approvals

A significant or controlling interest cannot be sold, transferred, charged, acquired, increased, or decreased without prior written FSC approval. The rule also covers share issues and capital reorganisations that change such interests. Virtual Assets Service Providers Act 2022, s. 21.

A share acquisition agreement should therefore contain:

  • an FSC approval condition;

  • a covenant against premature control;

  • a long-stop date tied to the regulatory process;

  • information and cooperation duties;

  • a right to terminate if conditions are unacceptable;

  • restrictions on pre-closing integration;

  • treatment of regulatory costs;

  • a mechanism for any required divestment or voting limitation.

Closing without the required approval can expose the VASP and acquirer to enforcement.

Custody

The BVI Act requires adequate security, risk controls, resources, and safekeeping arrangements. Client agreements must address duration, storage, permitted transactions, risks, fees, access, termination, security, and remedies. Client assets cannot be encumbered without the beneficial owners’ agreement. Virtual Assets Service Providers Act 2022, ss. 28–29.

The Act does not support a blanket assumption that every custodial asset is held under one universal trust structure. The reviewer must examine the contract, wallet structure, applicable subordinate rules, and insolvency analysis.

A BVI custody review should test:

  • whether the registrant is approved for custody;

  • the legal title created by the custody agreement;

  • segregation between client, corporate, affiliate, and market-maker assets;

  • entitlement to staking rewards and ancillary proceeds;

  • any lien, set-off, pledge, or rehypothecation;

  • loss allocation;

  • sub-custodian use;

  • wallet and ledger reconciliation;

  • insolvency treatment under the governing documents.

Bermuda

Licence class and activity

Bermuda regulates a broad range of digital-asset business activities. The licence must be checked by entity, class, approved activity, restriction, and expiry date.

A Class F licence can cover the full approved business on an ongoing basis. A Class M licence permits approved activities for a defined period. A Class T licence permits defined pilot or beta activity for a defined period. Digital Asset Business Act 2018, ss. 12–13.

Class M or T status should receive close review. The project may have expanded beyond the tested product, exceeded a licence period, or marketed a pilot approval as unrestricted authorisation.

The licence review should compare:

  • the legal name and trading name;

  • approved activities;

  • licence class;

  • licence restrictions;

  • effective and expiry dates;

  • product descriptions;

  • actual revenue lines;

  • user terms and websites;

  • wallet and custody functions;

  • current business plan filed with the BMA.

Territorial nexus and local substance

A Bermuda-formed entity carrying on a listed digital-asset activity falls within the Act. A foreign entity can also be covered when it carries on the business in or from Bermuda. Digital Asset Business Act 2018, s. 4.

Except for Class T, a licensed undertaking must maintain a head office in Bermuda. The digital-asset business must be directed and managed from Bermuda. The BMA considers the location of strategy, risk management, operational decisions, senior executives, board meetings, management meetings, officers, employees, and directors. Digital Asset Business Act 2018, s. 21.

A registered office and local corporate-services provider do not prove compliance. The evidence should include:

  • board calendars and minutes;

  • attendance records;

  • delegated-authority matrices;

  • senior executive employment and residence;

  • local payroll and office records;

  • risk committee materials;

  • operational decision records;

  • regulator correspondence concerning the head office;

  • evidence that remote founders do not bypass the Bermuda decision process.

A project whose strategic and operational decisions occur elsewhere may have a material licence-condition issue.

Client assets

Bermuda law requires separate accounts for client assets. A licensed undertaking holding client assets must maintain an approved surety bond, trust account, indemnity insurance, or other approved arrangement. Custodied digital assets must be held for the client, must not constitute the undertaking’s property, and must not be subject to claims by the undertaking’s creditors. Digital Asset Business Act 2018, ss. 17–18.

The 2025 custody rules add operational duties concerning segregation, default arrangements, client entitlements, recordkeeping, and beneficial ownership. The review should read those rules with the licence conditions and client contracts.

The legal-DD team should verify that the accounting treatment, wallet controls, contractual title, and insolvency position produce the same result. Any conflict should receive a high-severity finding.

Material changes and M&A

A licensed undertaking cannot implement a material change without completing the BMA notice process. Material changes include a new product, service, or activity; an acquisition or amalgamation; sale of a subsidiary; acquisition of a controlling interest; outsourcing; and changes to the filed business plan. Digital Asset Business Act 2018, s. 22.

The statutory process generally requires written notice. The undertaking can proceed after written non-objection or expiry of the statutory period without a preliminary objection, subject to information requests and other BMA action.

Transaction documents should not assume that corporate closing and regulatory implementation can occur simultaneously. The parties should identify which acts constitute the material change and which preparatory acts can occur before BMA clearance.

Token issuance

A Bermuda token issuer may require analysis under the Digital Asset Issuance Act 2020 as well as the Digital Asset Business Act 2018. The issuer, promoter, exchange, custodian, and service provider may fall under different statutes.

The review should determine:

  • who issued the token;

  • whether the issue was public or private;

  • where the issuer and purchasers were located;

  • what rights the token grants;

  • whether proceeds were received by the issuer;

  • whether a Bermuda digital-asset business supported the issue;

  • whether the offering document matched the deployed token;

  • whether continuing disclosures were made;

  • whether the current product differs from the approved issuance.

The Bahamas

Territorial and activity perimeter

The 2024 Act applies to token formation, promotion, issuance, sale, redemption, and covered digital-asset business. It also contains specific rules for security-token overlap, rewards, gaming assets, NFTs, electronic money, and digital currency. Digital Assets and Registered Exchanges Act 2024, ss. 2–3.

A person can carry on digital-asset business in The Bahamas by offering services to a non-accredited resident, regardless of the provider’s physical location. A person carries on business from The Bahamas when services are offered from or through a place in The Bahamas. Servers alone do not create the statutory nexus. Digital Assets and Registered Exchanges Act 2024, s. 2.

Registration analysis must cover each activity. The Act contains extra requirements for advice, management, staking, exchanges, and custody. Digital Assets and Registered Exchanges Act 2024, ss. 9 and 18–23.

A project should not rely on an exchange registration to support staking or management unless those services fall within the approved registration.

Transaction approvals

A registrant must apply for prior approval at least 28 days before specified changes. Covered changes include:

  • a material expansion or change of activity;

  • a merger or acquisition;

  • sale of all or a substantial part of the assets;

  • issue, transfer, or disposal of shares;

  • a new director or officer;

  • a new chief executive, compliance officer, or MLRO;

  • a shareholder or beneficial-owner change;

  • a trading-name change;

  • a new auditor.

Digital Assets and Registered Exchanges Act 2024, s. 17.

The acquirer should treat this as a closing condition. The parties must also examine whether the transaction changes the approved activity, technology, custody model, or stablecoin structure.

Custody

The Bahamas imposes detailed custody duties. The custodian must separate client assets from its own assets and other non-client assets. It must use separate on-chain addresses and internal ledger accounts, unless an approved omnibus structure applies. Client consent is required for omnibus holding. Client assets must remain insulated from the custodian’s estate and creditors. Digital Assets and Registered Exchanges Act 2024, s. 18.

The custodian cannot lend, reuse, rehypothecate, pledge, encumber, or otherwise use client assets without prior client consent, clear risk disclosure, and compliance with further Commission requirements. The arrangement must preserve the client’s equitable and beneficial interest.

The custodian must also maintain plans for ledger failures, 51 percent attacks, forks, airdrops, court freezes, insolvency transfers, erroneous transfers, and operational disruption. Client-position records and periodic statements are mandatory.

These rules require a combined legal, accounting, and technical review. The work should reconcile:

  • the client agreement;

  • wallet addresses;

  • internal ledgers;

  • financial statements;

  • client statements;

  • sub-custodian records;

  • insolvency and recovery procedures;

  • on-chain balances;

  • management attestations.

Staking

The 2024 Act expressly requires registration and product-specific information for staking services. The application must describe the client agreement, protocol, consensus process, lock-up, rewards, redemption, penalties, and other operational features. Digital Assets and Registered Exchanges Act 2024, s. 20.

A staking DD review should determine:

  • whether the provider takes custody;

  • whether assets are delegated or transferred;

  • whether assets are pooled;

  • whether the provider selects validators;

  • whether returns are fixed, variable, or discretionary;

  • who bears slashing and validator failure;

  • whether rewards are paid in the staked asset or another asset;

  • whether withdrawals can be delayed;

  • whether the provider retains a spread;

  • whether unstaking rights match the interface and disclosures.

Staking should not be analysed only as a token feature. It may create separate custody, management, contractual, tax, and insolvency issues.

Stablecoins

The Bahamas prohibits issuance of a stablecoin that seeks stability by increasing or decreasing its own supply, or another digital asset’s supply, in response to demand. Digital Assets and Registered Exchanges Act 2024, s. 49(1).

Permitted stablecoins must be fully backed with reserve assets whose value remains at least equal to outstanding nominal value. Reserve assets must be segregated, liquid, and insulated from issuer creditors. Holders must receive a timely 1:1 redemption right, net of disclosed ordinary fees, subject to customer identification. Digital Assets and Registered Exchanges Act 2024, ss. 50 and 53.

A stablecoin DD review should test reserve ownership, custody, investment policy, valuation, liquidity, audit reports, redemption records, disclosures, insolvency treatment, and the mechanism used to maintain value.

DAOs

The Decentralised Autonomous Organisations Act 2026 creates a distinct registration route. The applicant must first use an eligible Bahamian legal form under the Act. The DAO then applies for registration with a constitutive document, business plan, token information, treasury procedures, smart-contract details, and a responsible person. The Act gives a registered DAO separate legal personality from its token holders. Decentralised Autonomous Organisations Act 2026, ss. 3–6.

The Act requires a permissionless ledger, publicly available open-source code, security controls, operational resilience, and sufficient decentralisation. It also requires token-holder voting arrangements and at least one accountable responsible person. Decentralised Autonomous Organisations Act 2026, ss. 6 and 11–12.

DAO registration does not remove other legal duties. Token offerings, custody, exchange, staking, investment-fund activity, AML, sanctions, tax, employment, and data rules remain separate questions.

The due-diligence review should inspect:

  • the certificate of DAO registration;

  • the underlying legal form;

  • the constitutive document;

  • the responsible person;

  • token concentration;

  • quorum and voting thresholds;

  • smart-contract audit reports;

  • treasury powers;

  • amendment powers;

  • emergency overrides;

  • regulator approval for amendments;

  • the status of any DARE registration.

The 2026 Act was gazetted. The operation of the registration machinery, published guidance, and current register should be confirmed before transactional reliance.

Seychelles

Authorisation categories

The Seychelles FSA states that it regulates virtual-asset services rather than products. It identifies four principal categories: wallet services, exchanges, virtual-asset broking, and investment services. ICO and NFT projects use a registration process. Eligible VASP applicants are domestic companies and international business companies, not individuals.

This distinction requires an activity map. A company registered for an ICO or NFT project does not thereby hold authority to operate an exchange, custody service, broker, or investment service.

Transitional assessment status

The public page titled “Licensed VASPs” lists several entities with the status “Assessment.” The FSA states that these entities submitted applications under the transitional process and may continue operating until the Authority determines the applications.

“Assessment” should be reported exactly. It is not equivalent to a final licence.

The project file should contain:

  • the complete licence application;

  • evidence of completeness;

  • the FSA’s acceptance or approval notice;

  • transitional-status correspondence;

  • outstanding information requests;

  • all service categories applied for;

  • business restrictions pending determination;

  • any deadlines or undertakings;

  • current FSA confirmation immediately before closing.

The FSA has publicly warned that incorporation under Seychelles company law does not constitute VASP authorisation. It cited an entity that had merely been incorporated and had never been authorised.

Source and closing treatment

The FSA’s current legal-materials page lists the Virtual Asset Service Providers Act 2024 and regulations addressing licensing, advertising, client assets, capital, cybersecurity, ICOs, NFTs, fit and proper tests, substance, and nexus. Direct access to several operative documents redirected to an authentication process during this review.

The Seychelles opinion should therefore require:

  • a certified or gazetted copy of the operative Act and regulations;

  • a local-counsel current-law confirmation;

  • an FSA status letter;

  • a current register extract;

  • the licence or transitional instrument;

  • confirmation of approved activities;

  • confirmation that no enforcement or information request remains unresolved.

A buyer should not close based only on the website label, company certificate, or management’s statement that the application is “approved.”

Mauritius annex

Licence structure

No person may conduct VASP business in or from Mauritius without a licence. Only a company may conduct the business. Virtual Asset and Initial Token Offering Services Act 2021, ss. 7–8.

The FSC’s current schedule identifies:

  • Class M: virtual-asset broker-dealer;

  • Class O: virtual-asset wallet services;

  • Class R: virtual-asset custodian;

  • Class I: virtual-asset advisory services;

  • Class S: virtual-asset marketplace;

  • separate registration for an initial token offering issuer.

The licence review must match the project’s actual services to the licensed class. A wallet licence does not necessarily cover custody, dealing, advisory, or marketplace activity.

Physical office and management

A Mauritius VASP must have a physical office in Mauritius. Its business must be directed and managed from Mauritius. The FSC may consider the location of strategy, risk management, operational decisions, responsible executives, board meetings, management meetings, officers, employees, and directors. Virtual Asset and Initial Token Offering Services Act 2021, s. 10.

The reviewer should test actual conduct. Relevant evidence includes:

  • local premises and lease;

  • local personnel;

  • executive residence and authority;

  • board and committee records;

  • operating and risk decisions;

  • bank and wallet mandates;

  • signing policies;

  • regulator communications;

  • local payroll and expense records.

A local director who approves decisions already made elsewhere may not establish the required direction and management.

Ownership and business changes

A VASP cannot modify its business scope, reorganise its legal structure, merge, change its name, or change its auditor without prior written FSC approval. Virtual Asset and Initial Token Offering Services Act 2021, s. 13.

Shares and legal or beneficial interests also require prior approval, subject to the Act’s notification treatment for transfers below the stated threshold. Virtual Asset and Initial Token Offering Services Act 2021, s. 16.

The transaction should not close until counsel has mapped:

  • direct and indirect share changes;

  • voting arrangements;

  • options, convertibles, and token-based control rights;

  • board appointment rights;

  • legal-structure changes;

  • business-plan changes;

  • merger steps;

  • post-closing service changes.

Client assets

A VASP with custody must hold sufficient assets to meet client obligations. Client assets must be held for the client, must not constitute the VASP’s property, and must not be subject to the VASP’s creditors. Virtual Asset and Initial Token Offering Services Act 2021, s. 17.

The FSC also maintains 2022 rules addressing capital, client disclosures, custody, cybersecurity, advertisements, risk management, returns, and the Travel Rule.

The review should reconcile the statute, custody rules, licence conditions, client agreements, wallets, and accounting records.

Initial token offerings and securities

Only a company may act as an issuer of initial token offerings. The application must be made through a Mauritius virtual exchange, or an equivalent accepted by the FSC, at least 45 days before the offer period. Virtual Asset and Initial Token Offering Services Act 2021, s. 24.

If the FSC determines that the token is a security, the applicant must withdraw the token-registration application and proceed under the Securities Act. Virtual Asset and Initial Token Offering Services Act 2021, s. 25(4).

The DD review should compare the token’s legal rights with its code and marketing. Dividend rights, revenue rights, redemption, asset backing, liquidation rights, pooled investment, managerial reliance, and transferability can alter the classification.

Token, securities, fund, and product classification

No offshore wrapper removes the need to classify the product. The reviewer should conduct separate analyses for:

  • the original fundraising transaction;

  • the token presently in circulation;

  • staking or yield products;

  • wrapped or bridged versions;

  • governance or voting rights;

  • liquidity-pool interests;

  • stablecoins;

  • NFT series;

  • tokenised fund interests;

  • lending and borrowing products.

The original offering may have created liability even if the token now has wider use or greater decentralisation.

The classification work should identify:

  • payment and redemption rights;

  • profit, interest, or revenue rights;

  • claims against reserves or project assets;

  • voting and veto powers;

  • managerial commitments;

  • supply and mint rights;

  • lockups and vesting;

  • secondary-market support;

  • market-maker arrangements;

  • price-support statements;

  • issuer repurchase obligations;

  • pooled investment and fund management;

  • rights on liquidation.

The analysis must compare five records:

  1. constitutional and contractual rights;

  2. deployed smart-contract functions;

  3. white papers and offering documents;

  4. public marketing;

  5. actual operating conduct.

A legal opinion based on one record alone should be treated as incomplete.

Custody, staking, and insolvency

A custody opinion must answer four distinct questions.

1

who has legal title? The answer may depend on the custody agreement, trust terms, property law, and insolvency law.

2

who can cause a transfer? A project may have custody or material control even when several signatures are required.

3

are client assets segregated legally, operationally, and in the accounts? One form of segregation does not prove the others.

4

what happens on insolvency? The reviewer should identify creditor claims, trust treatment, shortfall allocation, tracing, set-off, administrator powers, and transfer procedures.

The work should test every person who holds:

  • private keys;

  • key shares;

  • recovery keys;

  • admin keys;

  • smart-contract upgrade rights;

  • MPC authority;

  • transaction approval rights;

  • withdrawal whitelisting powers;

  • emergency pause powers.

The project’s use of “non-custodial” should be treated as an assertion. The technical facts decide whether it is supportable.

Staking creates added questions. The reviewer must identify custody, title transfer, pooling, delegation, validator selection, lock-up, slashing, withdrawal, reward calculation, commissions, tax, and insolvency treatment. The Bahamas regulates staking expressly, while Cayman’s custody rules address allocation of staking and ancillary benefits. Other jurisdictions may capture staking through custody, management, dealing, lending, or another service category.

DeFi, software, and DAO claims

“Decentralised” is not a complete legal conclusion. The reviewer should identify every person who can influence execution, access, economics, or public communications.

Relevant powers include:

  • contract deployment;

  • proxy upgrades;

  • emergency pause;

  • oracle selection;

  • parameter changes;

  • token listings;

  • front-end control;

  • fee collection;

  • treasury spending;

  • validator selection;

  • relayer operation;

  • blacklist or whitelist control;

  • domain and application ownership.

A protocol can have decentralised transaction validation but centralised product control.

The BVI statutory exclusions show the factual boundary. Pure software creation or network operation may fall outside VASP status. Active customer facilitation, exchange, transfer, custody, or issuer services can move the actor into the regulated category.

Cayman’s trading-platform definition can reach a decentralised platform where the operator receives a benefit and also controls assets, holds custody, or interposes itself in the transaction.

A DAO wrapper can establish legal personality and allocate internal authority. It does not eliminate licensing, offering, AML, sanctions, custody, tax, employment, or tort questions. The Bahamas DAO statute confirms this point by requiring a legal wrapper, responsible person, constitutive document, token disclosures, and smart-contract information.

Corporate ownership and asset chain of title

The project’s corporate chart should reconcile six forms of ownership:

  • equity ownership;

  • token ownership;

  • intellectual-property ownership;

  • domain and application ownership;

  • wallet ownership and control;

  • contractual rights to revenue and data.

A foundation may state that it stewards the protocol while another company owns the repositories and controls releases. An issuer may have raised funds but lack a binding development agreement. A treasury entity may distribute grants without documented authority.

The DD file should contain:

  • certificates of incorporation and good standing;

  • constitutional documents;

  • shareholder and beneficial-owner registers;

  • cap tables;

  • options, warrants, convertibles, and side letters;

  • token allocation and vesting records;

  • board and shareholder approvals;

  • intercompany service agreements;

  • intellectual-property assignments;

  • contributor agreements;

  • domain and repository records;

  • wallet-control resolutions.

The reviewer should reconcile token entitlements against the equity capitalization. Undisclosed token grants can transfer substantial project value without appearing on the share cap table.

Beneficial ownership, economic substance, and tax

Beneficial-ownership and substance compliance should be tested at entity level. A group-wide statement that “all offshore filings are current” is insufficient.

The review should identify:

  • the registered agent or corporate-services provider;

  • the beneficial-owner filings made;

  • changes not yet reflected;

  • nominee arrangements;

  • control through agreements, tokens, or veto rights;

  • substance classifications;

  • annual returns and notifications;

  • local personnel and expenditure;

  • tax residence;

  • permanent establishments;

  • transfer pricing;

  • token-sale treatment;

  • treasury gains;

  • staking income;

  • payroll and token compensation;

  • indirect tax.

The conclusion may differ across the group. A token issuer, foundation, holding company, software company, and licensed VASP can have different filing and substance positions.

The legal report should not state that an entity has “no tax” merely because it is offshore. Tax residence, source, local substance, controlled-foreign-company rules, permanent establishments, withholding, and investor-level taxation require separate analysis.

AML, sanctions, and transfer controls

Every core jurisdiction reviewed subjects regulated virtual-asset businesses to AML and counter-terrorist-financing duties. The project review must test operation, not only policy design.

The evidence should cover:

  • customer and beneficial-owner identification;

  • risk classification;

  • sanctions and PEP screening;

  • source of funds and source of wealth;

  • transaction monitoring;

  • blockchain analytics;

  • Travel Rule records;

  • self-hosted wallets;

  • suspicious-activity escalation;

  • record retention;

  • staff training;

  • independent testing;

  • vendor oversight.

Mauritius expressly includes the Travel Rule within its current VASP rules. The Bahamas Act requires originator and beneficiary controls and risk-based AML measures.

Sanctions analysis remains separate. The reviewer should determine who can block, reject, freeze, pause, or reverse access and transactions. Public claims that the service is permissionless should be compared with actual retained controls.

A sample-based operating review should inspect onboarding files, alerts, case closures, blocked wallets, escalations, and regulator reports. A policy without implementation evidence remains unverified.

Regulatory status verification

A proper status check has at least seven steps.

The reviewer should first search the official register by exact legal name. It should then search trading names, former names, and group entities.

The reviewer should obtain the licence or registration instrument. The public register may omit conditions.

The reviewer should compare the authorised activity with the product. Terms including “exchange,” “custody,” “broker,” “marketplace,” and “wallet” do not have identical scope across jurisdictions.

The reviewer should check status and expiry. Bermuda Class M and T licences, Seychelles transitional assessments, pending applications, waivers, and sandbox permissions require precise treatment.

The reviewer should check regulator correspondence. Conditions may arise through approval letters, directions, undertakings, remediation plans, or business-plan acceptance.

The reviewer should compare every user-facing domain and application with the authorised entity. A licensed entity may not operate every group brand.

The reviewer should repeat the check immediately before signing and closing.

A representation that the project “holds all necessary licences” should not replace this work. The acquisition agreement should schedule each licence, registration, waiver, condition, approved activity, and pending application.

Transaction approvals and closing mechanics

Regulatory consent can affect the acquisition structure, timetable, and allocation of risk.

The parties should determine whether the transaction changes:

  • direct or indirect control;

  • a significant ownership interest;

  • beneficial ownership;

  • voting or veto rights;

  • directors or officers;

  • legal structure;

  • business scope;

  • custody arrangements;

  • outsourcing;

  • trading names;

  • auditors;

  • the filed business plan.

BVI requires prior written approval for significant or controlling interest changes. Bermuda uses a material-change notification and non-objection process for listed changes. The Bahamas generally requires an application at least 28 days before listed changes. Mauritius requires prior approval for specified business and ownership changes.

The acquisition agreement should address:

  • which party prepares each filing;

  • control over submissions;

  • disclosure of regulator communications;

  • acceptable conditions;

  • commitments to modify the transaction;

  • whether a burdensome-condition standard applies;

  • the long-stop date;

  • interim operating covenants;

  • pre-closing integration restrictions;

  • termination rights;

  • regulatory costs;

  • post-closing undertakings.

The buyer should not obtain de facto control before approval through vetoes, wallet authority, management direction, or operational integration.

Red flags and transaction treatment

Stop or restructure

The following findings usually require suspension, abandonment, or restructuring before closing:

  • an unlicensed core service;

  • a pending application represented as a licence;

  • Seychelles “Assessment” status represented as final authorisation;

  • a Cayman registration used for custody or trading-platform activity;

  • a Bermuda Class M or T licence that has expired or does not cover the current product;

  • a BVI company providing services abroad without required registration;

  • failed Bermuda or Mauritius direction-and-management requirements;

  • client-asset commingling or a material shortfall;

  • undisclosed admin or treasury control;

  • missing ownership of core code or domains;

  • a security, fund interest, or stablecoin classified as a simple utility token;

  • an algorithmic-supply stablecoin issued from The Bahamas;

  • an unapproved ownership, control, merger, or business-scope change;

  • false public statements concerning regulatory status.

Conditions precedent

These matters can support a condition precedent where a clear cure exists:

  • receipt of a licence, registration, waiver, consent, or non-objection;

  • correction of the registered scope;

  • corporate restructuring;

  • intellectual-property assignment;

  • contract novation;

  • replacement or approval of directors and officers;

  • establishment of local management;

  • wallet segregation;

  • key rotation;

  • reconciliation and ledger remediation;

  • beneficial-owner and substance filings;

  • revised token documentation;

  • regulator-approved business-plan changes;

  • delivery of local legal opinions and status letters.

Price, escrow, and indemnity

Historic exposure may remain after operational cure. It can require:

  • a purchase-price reduction;

  • specific indemnity;

  • escrow or holdback;

  • retention by the seller;

  • warranty insurance exclusions;

  • special limitation periods;

  • claim-control procedures;

  • security for tax, customer, employment, or regulator liabilities.

Typical retained exposures include historic unlicensed activity, legacy token sales, tax underpayment, customer claims, custody incidents, AML failures, sanctions breaches, employment misclassification, and defective intellectual-property ownership.

Monitored remediation

Lower-severity matters may remain open after closing only where the agreement states:

  • the exact remediation;

  • the responsible person;

  • the evidence required;

  • the completion date;

  • reporting frequency;

  • access and audit rights;

  • consequences of non-completion.

A general promise to improve compliance is not an adequate remediation covenant.

Priority evidence request

The first offshore project data room should contain the following records.

Corporate and ownership

Current group chart.
Incorporation and good-standing records.
Constitutional documents.
Shareholder and beneficial-owner registers.
Cap table, options, warrants, convertibles, and side letters.
Board and shareholder minutes.
Intercompany agreements.
Registered-agent and corporate-services agreements.

Regulatory status

  • Every licence, registration, waiver, sandbox approval, and transitional instrument.

  • Approved activity schedules and conditions.

  • Applications and business plans.

  • Regulator correspondence.

  • Official register extracts.

  • Annual returns, fees, audits, and inspection reports.

  • Pending information requests or remediation plans.

Product and token

  • Current and historic white papers.

  • Token sale agreements.

  • Legal classification opinions.

  • Token-holder rights.

  • Allocation and vesting schedules.

  • Contract addresses and chain information.

  • Mint, burn, pause, blacklist, and upgrade powers.

  • Exchange, listing, liquidity, and market-maker agreements.

  • Stablecoin reserve and redemption records.

Custody and treasury

  • Wallet inventory and purpose.

  • Signers and thresholds.

  • Key-control procedures.

  • Client and proprietary ledgers.

  • Reconciliations.

  • Custody and sub-custody agreements.

  • Staking and validator records.

  • Treasury transfers.

  • Incident and recovery records.

  • Insurance.

Operations and territorial reach

  • Entity-by-activity matrix.

  • User-country data.

  • Marketing and solicitation records.

  • Local-language content.

  • Domains and applications.

  • Fee and revenue flows.

  • Employee and contractor locations.

  • Office, payroll, and local-management records.

Financial crime and privacy

  • AML and sanctions policies.

  • Risk assessments.

  • Onboarding samples.

  • Transaction-monitoring alerts.

  • Travel Rule records.

  • Suspicious-activity files.

  • Privacy notices and data maps.

  • Vendor agreements.

  • Security and breach records.

Intellectual property and technology

  • Employee and contractor assignments.

  • Contributor agreements.

  • Open-source inventory.

  • Repository ownership and access.

  • Deployment records.

  • Audit reports.

  • Bug-bounty terms.

  • Oracle, bridge, cloud, and hosting agreements.

  • Domain and trademark records.

Financial, tax, and disputes

  • Audited financial statements.

  • Management accounts.

  • Bank records.

  • Wallet reconciliations.

  • Tax filings and opinions.

  • Payroll and token-compensation records.

  • Claims and regulator inquiries.

  • Litigation and arbitration records.

  • Insurance notices and settlements.

Part 03

EU / EEA

MiCA, member-state overlays, EFTA and Switzerland
In essence

Web3 legal due diligence in Europe determines whether each token, service, entity, control arrangement, and cross-border activity falls under MiCA or another financial-services statute. The question is how an investor or acquirer should test a project operating in the EU, EEA, selected licensing centres, Liechtenstein, or Switzerland as at 21 July 2026. No project documents or transaction terms were supplied. This session states the regional decision method, evidence requirements, red flags, and transaction treatment. It does not clear any named project.

Executive summary
EU/EEA

MiCA transitional periods have expired. A legacy national registration, grandfathered status, or pending application no longer permits ordinary crypto-asset services. An unauthorised applicant must stop new business and limit activity to a regulator-accepted wind-down. Regulation (EU) 2023/1114, arts. 59 and 143.

Classification

MiCA is not the first answer for every token. The reviewer must first test financial instruments, deposits, funds, electronic money, payment products, securitisations, insurance products, and other exclusions. NFT treatment depends on substance, fungibility, series size, rights, and economic use. Regulation (EU) 2023/1114, art. 2 and recitals 9–11; ESMA Guidelines ESMA75453128700-1323.

Authorisation

Each legal entity needs authority for each service it provides. A MiCA authorisation must identify the permitted services. The authorised entity needs an EU or EEA registered office, effective management in the EU or EEA, and at least one locally resident director. Regulation (EU) 2023/1114, arts. 59–63.

Cross-border services

A MiCA passport follows the authorised entity and approved services. It does not extend to affiliates, subcontractors, offshore issuers, or shared brands. Legacy national VASP status never created an EU-wide passport.

Third-country projects

Reverse solicitation is narrow. Prior advertising, promotion, affiliate solicitation, local events, targeted social media, or intermediary activity can defeat it. A contractual disclaimer cannot change the facts. Regulation (EU) 2023/1114, art. 61.

Issuance and stablecoins

A notified white paper is not regulatory approval. Misleading or incomplete disclosures can create civil liability. Asset-referenced tokens and electronic money tokens have separate issuer, reserve, custody, redemption, and recovery duties. Regulation (EU) 2023/1114, arts. 8, 15, 16–58.

Custody and payments

MiCA requires legal and operational segregation of client crypto-assets. Custodian creditors must have no recourse to them. Certain electronic-money-token transfers and custodial wallets can also require PSD2 payment-services authority. Regulation (EU) 2023/1114, arts. 70 and 75; Directive (EU) 2015/2366.

Technology and financial crime

Authorised CASPs and asset-referenced-token issuers fall under DORA. The Transfer of Funds Regulation applies to covered crypto transfers and reaches self-hosted addresses when a CASP participates. Regulation (EU) 2022/2554; Regulation (EU) 2023/1113.

Acquisitions

A proposed acquisition of a qualifying holding in a CASP requires prior notification. Further notifications apply when holdings reach or cross 20, 30, or 50 percent, or create a subsidiary. The ordinary assessment period is 60 working days. Regulation (EU) 2023/1114, art. 83.

Switzerland

Switzerland does not apply MiCA. It classifies each token and service under the Banking Act, Financial Institutions Act, Financial Market Infrastructure Act, Financial Services Act, Collective Investment Schemes Act, and Anti-Money Laundering Act. A Swiss structure does not remove EU authorisation duties when the project targets EU or EEA clients.

Analysis by issue

Regional decision rule

European Web3 due diligence should begin with four linked schedules:

  1. Every entity, branch, foundation, association, and material natural person.

  2. Every token, service, interface, protocol function, and revenue source.

  3. Every country where users, staff, marketing, decision-makers, or infrastructure exist.

  4. Every power over code, wallets, treasury assets, listings, access, fees, or communications.

The reviewer should then assign each activity to a legal person. “The project” is not a sufficient actor. A token issuer, CASP, software company, foundation, market maker, treasury company, and front-end operator may form one economic group. They remain separate persons for licensing, liability, tax, insolvency, and contractual purposes.

The due-diligence report should classify each assertion as documented, reported, inferred, disputed, or not verified. A register entry proves the stated regulatory status on the check date. It does not prove that every product falls within the approved scope. A white paper proves what the project disclosed. It does not prove that the disclosure was correct.

Historic conduct remains material. MiCA authorisation in 2026 does not cure an unlawful offer, unlicensed service, asset shortfall, data breach, or misleading statement from an earlier period.

Post-transition permission check

As at 21 July 2026, the Article 143 transition has ended. The maximum MiCA transition expired on 1 July 2026. Several states used shorter periods. A project can now provide covered services only through:

  • a CASP authorised under Article 63;

  • an eligible financial entity using the Article 60 notification route;

  • a properly passported EEA entity; or

  • the narrow Article 61 client-initiative route for a third-country firm.

A pending Article 63 application does not create permission to continue ordinary business after transition. The applicant must stop onboarding, opening accounts, active marketing, and other new business. Regulators may permit limited operations needed to return assets or complete an orderly closure.

The status review should verify:

  • the exact legal name and registration number;

  • the home competent authority;

  • the authorisation date;

  • the approved crypto-asset services;

  • restrictions and conditions;

  • the Article 60 status, where relevant;

  • passport notifications;

  • branches and tied arrangements;

  • official ESMA and national register entries;

  • warning-list, suspension, or withdrawal entries;

  • former national VASP registrations;

  • regulator correspondence about transition or wind-down.

MiCA prohibits a person from using a name or communication that suggests CASP status when it lacks that status. Websites, applications, user terms, social media, and exchange profiles must identify the authorised entity accurately. Regulation (EU) 2023/1114, art. 59(5).

An authorisation held by one group company does not protect another company that contracts with users or provides the service. The review should compare the regulatory register with user terms, payment descriptors, wallet controllers, invoices, privacy notices, and customer support signatures.

Classification gate

MiCA applies only after the reviewer excludes other legal classifications. The first classification memorandum should test whether the relevant digital asset is:

  • a transferable security or another MiFID II financial instrument;

  • a unit in a collective investment undertaking;

  • a derivative;

  • a deposit or structured deposit;

  • electronic money;

  • funds under payment law;

  • a securitisation position;

  • an insurance or pension product;

  • an asset-referenced token;

  • an electronic money token;

  • another MiCA crypto-asset;

  • a qualifying unique and non-fungible asset; or

  • outside financial-services law.

Regulation (EU) 2023/1114 excludes financial instruments and several other regulated products from its own scope. Those products do not become unregulated. MiFID II, the Prospectus Regulation, AIFMD, UCITS rules, market-abuse law, payment law, or national securities law may apply instead. Regulation (EU) 2023/1114, art. 2; Directive 2014/65/EU; Regulation (EU) 2017/1129.

The reviewer should classify each transaction and stage separately:

  • the initial fundraising;

  • the present token;

  • private-sale instruments;

  • staking receipts;

  • wrapped tokens;

  • bridge assets;

  • liquidity-pool interests;

  • tokenised shares or debt;

  • voting tokens;

  • reward points;

  • stablecoins;

  • gaming assets;

  • NFTs;

  • tokenised fund interests.

A token can change classification when its rights, use, marketing, control, or operating facts change. An opinion written before deployment should not be relied upon without comparing its assumptions against the live product.

Financial instruments

The financial-instrument test requires economic and legal analysis. The reviewer should examine transferability, standardisation, negotiability, voting rights, profit rights, interest, redemption, liquidation claims, pooled investment, derivative exposure, and dependence on an active managerial group.

ESMA’s final financial-instrument guidelines provide the EU supervisory approach. They do not replace MiFID II or national transposition law. The legal file should record the tested token version, contract addresses, applicable law, factual assumptions, and reasons supporting each element.

A tokenised financial instrument may also engage the DLT Pilot Regime. That regime addresses authorised trading and settlement infrastructure. It is not a general exemption for tokenised securities. Regulation (EU) 2022/858.

NFTs and collections

The NFT exclusion depends on substance. Fractional parts of a unique asset should not be assumed unique. A large series or collection can indicate fungibility. Common pricing, standard rights, interchangeable traits, pooled proceeds, or an expected secondary market can weaken the exclusion. Regulation (EU) 2023/1114, recitals 9–11.

The file should document:

  • the rights attached to each token;

  • uniqueness criteria;

  • collection size;

  • fractionalisation;

  • common pricing;

  • redemption or benefit rights;

  • intellectual-property rights;

  • use within a game or application;

  • secondary-market support;

  • issuer promises;

  • common treasury or revenue exposure.

The word “NFT” carries no independent legal effect.

Classification evidence

A defensible classification file should contain:

  • constitutional and contractual token rights;

  • deployed code and proxy settings;

  • white papers and sale documents;

  • marketing archives;

  • financial models;

  • reserve or redemption terms;

  • voting and control arrangements;

  • transfer restrictions;

  • token allocation and vesting records;

  • technical and legal opinions;

  • a completed joint ESA classification test.

The joint ESA guidelines require an explanation for ordinary MiCA crypto-assets and a legal opinion for asset-referenced-token applications. The templates promote a common classification record across supervisors.

Offers, admission to trading, white papers, and marketing

A project offering a non-ART, non-EMT crypto-asset to the public, or seeking admission to trading, generally needs a compliant white paper. The responsible person must notify it to the home authority at least 20 working days before publication. Prior regulatory approval is not required. Notification and inclusion in an ESMA register do not mean that the authority endorsed the product. Regulation (EU) 2023/1114, arts. 4–12.

The reviewer should verify:

  • who is the offeror;

  • who seeks admission to trading;

  • who operates the trading venue;

  • the home Member State;

  • each host Member State;

  • the notification date;

  • publication date;

  • offer opening date;

  • exact white-paper version;

  • modification history;

  • website availability;

  • marketing communications;

  • exemption reliance;

  • withdrawal rights;

  • token-delivery arrangements;

  • treatment of funds received.

Any exemption should be tested against the full offer. Multiple connected offers should not be divided artificially. An announced plan to seek admission to trading can disapply certain offer exemptions. The review should also test whether a utility token relates to an operating product or only a future promise.

Disclosure liability

Article 15 creates liability where a white paper is incomplete, unfair, unclear, or misleading. Potential defendants include the offeror, person seeking admission, trading-platform operator, and relevant management members. Contractual terms cannot exclude that liability. The holder must prove the infringement, reliance, and resulting loss. National civil law can provide further claims. Regulation (EU) 2023/1114, art. 15.

The DD review should compare the white paper with:

  • deployed supply and minting powers;

  • treasury wallets;

  • token allocations;

  • vesting contracts;

  • admin and upgrade rights;

  • fee rights;

  • reserve assets;

  • market-maker arrangements;

  • code audits;

  • known incidents;

  • material dependencies;

  • financial condition;

  • planned listings;

  • issuer and group identity.

A technically correct description can still mislead when it omits a material control, dependency, conflict, or commercial arrangement.

Marketing

Marketing must be fair, clear, and not misleading. It must remain consistent with the white paper. The review should cover official websites, social accounts, founder accounts, influencers, affiliates, referral programs, community moderators, paid advertising, event presentations, application-store content, and exchange announcements.

Risk statements should match the product. Generic volatility language does not address custody, smart-contract, oracle, bridge, slashing, depeg, reserve, governance-control, or insolvency risks.

CASP service mapping

MiCA identifies ten crypto-asset services. Each one requires separate testing. Regulation (EU) 2023/1114, arts. 3(1)(16) and 59–85.

MiCA service Main DD question
Custody and administration Who safeguards or controls assets or access means, including private keys or key shares?
Operation of a trading platform Does a multilateral system bring together third-party buying and selling interests under non-discretionary rules?
Exchange for funds Does the entity trade against its own inventory for fiat or other funds?
Exchange for other crypto-assets Does the entity trade against its own crypto inventory?
Execution of orders Does the entity enter purchase, sale, or subscription contracts for clients?
Placing Does the entity market crypto-assets to purchasers for an offeror or connected person?
Reception and transmission of orders Does it receive a client order and transmit it for execution?
Advice Does it provide a personal recommendation concerning a transaction or crypto service?
Portfolio management Does it exercise discretion over a client portfolio containing crypto-assets?
Transfer services Does it transfer crypto-assets between addresses or accounts for another person?

The reviewer should map the actual user journey. A single product can contain several services. An exchange can provide custody, order execution, transfer services, staking, and payment functions through one interface.

Fees are relevant but not conclusive. A service performed without a visible user fee can remain a commercial service when the provider receives spreads, token allocations, protocol fees, affiliate revenue, reduced costs, or another economic benefit.

Article 59 authorisation

An Article 63 CASP must have:

  • a registered office in a Member State where it performs at least part of its services;

  • effective management in the EU;

  • at least one EU-resident director;

  • suitable management members;

  • adequate capital or insurance;

  • internal controls;

  • complaint procedures;

  • recordkeeping;

  • outsourcing controls;

  • service-specific systems.

The authorisation must specify each permitted service. Adding a service requires an extension. Regulation (EU) 2023/1114, art. 59.

The application file should be compared with live operations. Material differences can impair continuing compliance even when the licence remains visible on the register.

Article 60 financial entities

Credit institutions and certain regulated financial entities can provide specified equivalent crypto services after completing Article 60 notification. The available scope depends on the entity type. An investment firm, electronic money institution, fund manager, market operator, or central securities depository cannot assume that every crypto service falls within its existing permission.

The reviewer should obtain:

  • the underlying financial-services authorisation;

  • the Article 60 notification;

  • completeness confirmation;

  • the notified service list;

  • internal approval records;

  • supervisory correspondence;

  • the first-service date.

A submitted but incomplete Article 60 notification does not permit service commencement.

Passporting

An authorised CASP can serve other EEA states after the Article 65 notification process. The passport covers only the authorised person and services.

The DD review should reconcile:

  • home-state authorisation;

  • approved service scope;

  • host-state list;

  • notification dates;

  • branches;

  • local-language sites;

  • local agents;

  • user-country records;

  • the entity named in local user terms.

An unlicensed affiliate cannot rely on the passport merely because both entities share management, technology, or branding.

Effective management, personnel, and outsourcing

MiCA requires effective management in the EU. A registered office, nominee director, or rented desk does not establish that fact. The reviewer should trace where strategic, risk, compliance, product, wallet, and incident decisions occur.

Relevant evidence includes:

  • board and committee minutes;

  • decision logs;

  • executive residence;

  • employment records;

  • delegated authorities;

  • product approvals;

  • treasury approvals;

  • key-management records;

  • incident command records;

  • local payroll;

  • premises;

  • regulator meeting records.

ESMA’s supervisory briefing asks national authorities to examine autonomous local operations, sufficient personnel, executive competence, and outsourcing. That briefing is supervisory guidance rather than legislation. It gives a useful indication of the evidence regulators expect.

Outsourcing does not transfer regulatory responsibility. The CASP must retain knowledge, access, control, audit rights, termination rights, and a workable exit route. The arrangement must not turn the authorised entity into an empty shell. Regulation (EU) 2023/1114, art. 73.

High-risk arrangements include:

  • all technology and operations remaining with an offshore group company;

  • offshore persons controlling every production key;

  • no local risk or compliance personnel;

  • boards approving decisions already implemented elsewhere;

  • customer support unable to act without offshore approval;

  • no migration plan for a critical vendor;

  • contracts that restrict regulator or audit access;

  • group services lacking written agreements.

Third-country firms and reverse solicitation

Article 61 applies only where an EU client initiates the relevant service at the client’s exclusive initiative. Solicitation by the third-country firm, an affiliate, a close-linked entity, or an agent defeats the route. A disclaimer stating that every client acted independently has no legal effect. Regulation (EU) 2023/1114, art. 61.

A valid client-initiative file should record:

  • the first contact;

  • the client’s request;

  • the requested service;

  • the communication channel;

  • absence of prior targeting;

  • absence of affiliate solicitation;

  • the date and territorial facts;

  • the limits placed on later marketing.

The third-country firm cannot use the relationship to market new types of crypto-assets or services. Each later service requires its own analysis.

Facts that weaken reverse solicitation include:

  • EU-targeted advertisements;

  • local-language campaigns;

  • EU search-engine purchases;

  • EU-focused social-media accounts;

  • local influencers;

  • affiliate referrals;

  • sponsorship of local events;

  • EU-specific promotions;

  • local customer support;

  • EU payment rails;

  • an EU domain or local application listing;

  • active encouragement to open an account.

Geoblocking supports the factual record only when the project enforces it. Terms that exclude EU users carry little weight when onboarding, payments, and support continue to accept them.

An EU CASP should also test offshore outsourcing. MiCA protection attaches to the authorised EU entity. An unauthorised offshore company should not become the real service provider through user contracts, asset control, or operational conduct.

Asset-referenced tokens, electronic money tokens, and payments

A stablecoin analysis should begin with the stabilization claim. The reviewer should identify the reference asset, reserve, redemption right, holder claim, issuer obligation, stabilization process, and permitted uses.

An asset-referenced token references another value or right, or a combination of them. An electronic money token purports to maintain stable value by reference to one official currency. Regulation (EU) 2023/1114, art. 3.

Asset-referenced tokens

An ART issuer generally needs MiCA authorisation or qualifying credit-institution status. The issuer must address:

  • reserve composition;

  • reserve segregation;

  • custody;

  • investment of reserve assets;

  • liquidity;

  • redemption;

  • complaints;

  • conflicts;

  • own funds;

  • recovery planning;

  • redemption planning;

  • significant-token status;

  • white-paper accuracy.

The legal review should reconcile reserve rights with custody agreements, bank records, financial statements, valuation policies, and redemption data.

Electronic money tokens

An EMT may be offered publicly or admitted to trading only when the issuer is authorised as a credit institution or electronic money institution and complies with the white-paper requirements. EMTs are treated as electronic money. Regulation (EU) 2023/1114, art. 48.

The file should contain:

  • the credit-institution or EMI authorisation;

  • white-paper notification and publication;

  • issuance and redemption terms;

  • funds-safeguarding records;

  • reserve and liquidity data;

  • complaint and redemption records;

  • interest and incentive analysis;

  • recovery and redemption plans;

  • significant-token decisions.

A CASP licence does not authorise issuance of an EMT.

PSD2 overlap

Certain EMT transfer services and custodial wallets with transfer capability can also constitute payment services under PSD2. The project may therefore need a payment-institution, EMI, or credit-institution authorisation, or a compliant arrangement with an authorised payment provider.

The EBA’s transitional supervisory accommodation ended on 2 March 2026. Its later opinion advised national authorities on limited treatment of timely pending applications. That opinion is supervisory advice, not a statutory licence. The reviewer should obtain the actual payment-services status and national-authority correspondence.

The product map should distinguish:

  • token custody without transfer functionality;

  • transfers between wallets controlled by one customer;

  • transfers to third parties;

  • fiat collection;

  • redemption payments;

  • card or merchant use;

  • payment-account functions;

  • outsourcing to payment institutions.

Client assets, custody, and insolvency

A custody review should decide who has legal title, who can cause transfer, how records are maintained, and what occurs on insolvency.

MiCA requires a CASP holding client crypto-assets or access means to protect client ownership and prevent own-account use. Client funds other than EMTs must be placed promptly with a credit institution or central bank in a separately identifiable account. Payment services require separate PSD2 authority. Regulation (EU) 2023/1114, art. 70.

Article 75 requires:

  • a custody agreement;

  • a client-position register;

  • a custody policy;

  • procedures for rights attached to assets;

  • statements at least every three months;

  • return procedures;

  • legal segregation;

  • operational segregation;

  • protection from CASP creditors;

  • controlled sub-custody;

  • responsibility for attributable loss.

Crypto-assets held in custody must be legally separate from the CASP’s estate. The CASP’s creditors must have no recourse to those assets. Operational segregation is also mandatory. Regulation (EU) 2023/1114, art. 75.

The reviewer should obtain:

  • a full wallet inventory;

  • wallet purpose and legal owner;

  • signers and thresholds;

  • private-key or MPC procedures;

  • client-level ledgers;

  • reconciliation records;

  • break and shortfall reports;

  • omnibus-wallet terms;

  • sub-custody agreements;

  • staking and airdrop treatment;

  • incident records;

  • insurance;

  • insolvency opinions;

  • financial-statement treatment.

“Non-custodial” is a factual assertion. Joint signing, recovery authority, upgrade rights, relayers, transaction approval, withdrawal whitelisting, or emergency controls can show custody or material control.

Sub-custody and pre-funding

A MiCA custodian may use only an authorised CASP for sub-custody. The reviewer should not treat an offshore wallet provider as a mere technology vendor when it controls client assets or access means.

Pre-funding a venue with client assets can constitute sub-custody. Ordinary post-trade settlement can present a different case. The legal review should examine title, transfer timing, beneficial ownership, venue authority, and shortfall allocation.

Staking

MiCA does not create one general “staking licence.” The legal result depends on the functions performed. Staking can include custody, transfer services, exchange, portfolio management, advice, lending, or a financial instrument.

The reviewer should identify:

  • who owns the staked asset;

  • who selects validators;

  • whether assets are pooled;

  • whether the provider can transfer them;

  • lock-up and withdrawal rules;

  • slashing allocation;

  • reward calculation;

  • commissions and spreads;

  • liquid-staking receipts;

  • treatment on insolvency;

  • on-chain and contractual rights.

A staking receipt may require its own token classification.

Anti-money laundering, Travel Rule, and sanctions

Regulation (EU) 2023/1113 applies where a covered EU or EEA CASP participates in a crypto transfer. It requires specified originator and beneficiary information. Pure person-to-person transfers without a CASP fall outside its transfer-information rules.

For a transfer involving a self-hosted address, the CASP must collect and assess information. When the amount exceeds EUR 1,000, the CASP must take measures to determine whether the client owns or controls the address. Regulation (EU) 2023/1113, arts. 14–20.

The due-diligence review should test actual operation:

  • customer and beneficial-owner identification;

  • business and risk purpose;

  • sanctions and PEP screening;

  • source of funds;

  • source of wealth;

  • blockchain analytics;

  • originator and beneficiary data;

  • self-hosted-wallet controls;

  • high-risk chain or service rules;

  • transaction alerts;

  • suspicious-activity reports;

  • record retention;

  • vendor testing;

  • independent review.

The EBA Travel Rule guidelines have applied since 30 December 2024. The EBA’s restrictive-measures control guidelines have applied since 30 December 2025. The latter address internal policies, screening systems, exposure assessment, and responsibility allocation.

Sanctions analysis remains separate from AML. The reviewer should identify who can reject, block, freeze, pause, or restrict transactions and access. Public claims of permissionless operation should be compared with the actual control set.

The EU’s 2024 AML legislative package introduces further institutional and substantive changes, many of which apply later. Future duties should not be presented as operative on 21 July 2026.

DORA, cybersecurity, and critical vendors

DORA has applied since 17 January 2025. It covers authorised CASPs and issuers of asset-referenced tokens. Regulation (EU) 2022/2554, arts. 2 and 64.

The DD review should test:

  • management responsibility for ICT risk;

  • system and asset inventories;

  • protection and detection controls;

  • backup and restoration;

  • incident classification;

  • regulator reporting;

  • post-incident analysis;

  • resilience testing;

  • threat-led penetration testing, where applicable;

  • third-party registers;

  • contractual clauses;

  • concentration risk;

  • exit plans;

  • business continuity.

Technology audits and penetration tests are evidence. They do not replace the legal assessment of DORA duties.

On 8 July 2026, ESMA launched a common supervisory action focused on CASP custody resilience. The review addresses distributed-ledger dependencies, key storage, transaction controls, incident response, smart contracts, and third-party dependencies. That exercise makes custody technology and evidence an immediate supervisory issue.

The reviewer should compare the following records:

  • regulatory ICT policies;

  • architecture diagrams;

  • repositories;

  • deployed bytecode;

  • admin-key configuration;

  • audit reports;

  • incident reports;

  • vendor contracts;

  • cloud and oracle dependencies;

  • bridge and sequencer dependencies;

  • recovery testing;

  • regulator submissions.

An unaudited upgrade after the latest security report should receive separate treatment.

Market abuse, treasury conduct, and listings

MiCA prohibits insider dealing, unlawful disclosure of inside information, and market manipulation concerning crypto-assets admitted to trading or requested for admission. The rules can apply to conduct outside a trading venue. Regulation (EU) 2023/1114, arts. 86–92.

The DD review should cover:

  • listing decisions;

  • token unlocks;

  • treasury sales;

  • buybacks;

  • burns and minting;

  • market-maker agreements;

  • liquidity loans;

  • exchange negotiations;

  • issuer announcements;

  • protocol upgrades;

  • security incidents;

  • reserve problems;

  • governance votes affecting value;

  • insider wallets.

The project should maintain:

  • an inside-information identification process;

  • confidentiality controls;

  • disclosure decisions;

  • insider lists or equivalent controls;

  • personal-trading rules;

  • wallet monitoring;

  • market-surveillance escalation;

  • suspicious-order and transaction reporting;

  • market-maker oversight.

The reviewer should compare public supply figures with on-chain balances and vesting contracts. Unexplained wallets, discretionary minting, or undisclosed market support can create disclosure and manipulation exposure.

A market-maker agreement should state inventory, loan terms, return rights, options, venues, reporting, conflicts, and prohibited conduct. The project should not direct wash trading, spoofing, artificial volume, or undisclosed price support.

GDPR, consumer terms, and data transfers

GDPR applies where the project processes personal data within its scope. Wallet addresses, device identifiers, IP addresses, identity records, support records, and transaction analytics can constitute personal data when they identify or can be linked to a person.

The reviewer should identify:

  • each controller and processor;

  • processing purposes;

  • lawful bases;

  • notices;

  • retention periods;

  • automated decisions;

  • data-subject procedures;

  • security controls;

  • processors;

  • third-country transfers;

  • breach records;

  • data-protection impact assessments.

Blockchain publication does not create a GDPR exemption. The project should examine whether personal data, hashes, identifiers, or metadata are written on-chain. It should document minimisation, access, rectification, restriction, deletion methods, and responsibility allocation. Regulation (EU) 2016/679, arts. 5, 6, 13–14, 25, 32 and 44–49.

Travel Rule compliance can increase personal-data transfers between CASPs. Vendor contracts and transfer mechanisms should match those data flows.

Consumer terms should identify the correct entity, service, fees, risks, complaint route, custody status, asset rights, suspension powers, forks, airdrops, staking, liability, governing law, and dispute forum. National consumer law can restrict unilateral amendment, liability exclusions, forum clauses, and unfair terms.

Qualifying holdings and acquisition approvals

A person proposing to acquire a qualifying holding in a CASP must notify the home authority. A qualifying holding generally starts at 10 percent or the ability to exercise significant influence. Notifications also apply when a holding reaches or exceeds 20, 30, or 50 percent, or makes the CASP a subsidiary. Regulation (EU) 2023/1114, arts. 3 and 83.

The ordinary authority assessment lasts 60 working days after written acknowledgement. An information request can suspend the period for up to 20 working days. The suspension can extend to 30 working days for certain third-country acquirers.

The acquisition analysis should include:

  • direct equity;

  • indirect equity;

  • voting agreements;

  • options and convertibles;

  • board appointment rights;

  • veto rights;

  • token-based control;

  • foundation rights;

  • acting-in-concert arrangements;

  • debt covenants;

  • treasury or key control.

Transaction documents should contain:

  • a regulatory approval condition;

  • cooperation duties;

  • control over submissions;

  • disclosure of authority communications;

  • an acceptable-conditions standard;

  • a long-stop date;

  • pre-closing control restrictions;

  • termination rights;

  • treatment of regulatory costs;

  • post-closing undertakings.

The buyer should not obtain de facto control before approval through management direction, wallet authority, veto rights, or operational integration.

A token issuer, EMI, bank, investment firm, fund manager, or payment institution can require separate ownership approval under its own sectoral statute.

Selected EU Member State overlays

MiCA harmonises the core CASP and token rules. National law still determines the competent authority, procedure, criminal sanctions, civil remedies, insolvency details, company law, tax, employment, and parts of consumer protection.

Jurisdiction Current permission position Main local DD issue
France Only MiCA-authorised CASPs and completed Article 60 notifiers may provide covered services. The French transition ended on 1 July 2026. Former PSAN status is no longer enough. Unauthorised service can lead to criminal penalties and website blocking.
Germany MiCA authorisation or Article 60 status is required. BaFin supervises under the KMAG. German law adds white-paper remedies, client-asset insolvency rules, criminal offences, and electronic-securities duties.
Ireland The 12-month transition ended on 29 December 2025. The Central Bank of Ireland is the competent authority. Former VASP registration addressed AML and sanctions. It did not amount to prudential or conduct authorisation.
Malta The MFSA administers MiCA under the Markets in Crypto-Assets Act, Chapter 647. Current service requires MiCA authority. The reviewer should test licence statements, product descriptions, risk disclosures, and services exceeding the approved scope.
Lithuania The transition ended on 31 December 2025. Current service requires MiCA authority from Lithuania or another EEA state. Unlicensed activity can trigger enforcement. Certain EMT operations also need payment-services authority.
Estonia The transition ended on 1 July 2026. Old FIU virtual-currency licences were cancelled for current CASP purposes. Pending applicants must limit activity to client-protective wind-down until authorised.

France

France allowed qualifying legacy digital-asset service providers to continue until 1 July 2026. From that date, only MiCA-authorised CASPs or eligible financial entities with complete Article 60 notifications can provide covered services. The former French PSAN status does not support continued service or an EU passport.

The AMF states that unauthorised provision can expose the provider to two years’ imprisonment and a EUR 30,000 fine under Monetary and Financial Code arts. L.54-10-4 and L.572-23. The AMF can also publish warnings and seek website blocking.

The DD review should verify:

  • removal of obsolete PSAN claims;

  • the exact MiCA-authorised entity;

  • AMF or other EEA passport records;

  • French-language marketing;

  • French retail access;

  • Article 61 reliance by non-EU entities;

  • historic service after 1 July 2026;

  • customer communications and asset return.

Germany

BaFin is the competent authority under the Kryptomärkteaufsichtsgesetz. The current official consolidation states that the KMAG was last amended on 25 March 2026.

German law adds material transaction exposure:

  • KMAG § 19 gives purchasers remedies where a required crypto-asset white paper was not published.

  • KMAG § 45 addresses client crypto-assets and insolvency treatment.

  • KMAG § 46 makes specified MiCA violations criminal offences, with imprisonment up to five years or a fine.

  • The eWpG applies to qualifying electronic securities and crypto-securities registers.

KMAG § 19 can require the issuer and other responsible persons to take back the crypto-assets and reimburse the price and ordinary acquisition costs. A former holder can claim the difference between purchase and sale prices. The rule also addresses foreign issuers where the acquisition or service has a German nexus.

Providing CASP services contrary to MiCA Article 59 can constitute a criminal offence under KMAG § 46.

Tokenised debt or equity should be tested under the eWpG. The review should verify register operator authority, register content, technical documentation, transfer processes, and continuity arrangements. eWpG §§ 4, 16–22; eWpRV §§ 13 and 18–21.

Ireland

Ireland’s MiCA transition ended on 29 December 2025 under Regulation 20 of S.I. No. 607/2024. Current service requires MiCA authorisation or a completed Article 60 notification.

The former Irish VASP registration regime focused on AML, counter-terrorist financing, and financial sanctions. It did not provide prudential, client-asset, or conduct supervision equivalent to MiCA. A buyer should not treat historic VASP registration as evidence of broader compliance.

The Irish file should include:

  • Central Bank authorisation;

  • service scope;

  • Article 60 notification, where used;

  • passport records;

  • payment-services analysis for EMTs;

  • client-asset arrangements;

  • pre-authorisation conduct;

  • wind-down records for any discontinued VASP.

Malta

Malta enacted the Markets in Crypto-Assets Act 2024, Act XXXVI of 2024, now Chapter 647. It supplies national powers and procedures for MiCA supervision by the MFSA.

A company’s incorporation, application, or former virtual-financial-assets status does not amount to current MiCA authorisation. The MFSA has warned publicly where an entity cited incorporation and a pending application while lacking permission.

The MFSA’s 2025 website review identified recurring supervisory concerns:

  • incomplete licence descriptions;

  • hidden or weak risk disclosures;

  • wording that implied investment services beyond CASP authority;

  • promotion of NFTs or staking without clear status explanations;

  • conflicts between product claims and regulatory scope.

These findings state supervisory expectations rather than new statutory tests. They provide a practical website and marketing review checklist.

A May 2026 Malta consultation on tokenised financial products was not operative law on the As-of Date. It should not be treated as a current exemption or licence route.

Lithuania

Lithuania’s transition ended on 31 December 2025. A provider without MiCA authorisation from Lithuania or another EEA state lost the right to continue covered services.

The Bank of Lithuania has stated that unlicensed crypto-asset services constitute illegal financial activity. Available enforcement tools include public warnings and access restrictions. Criminal exposure can also arise under national law.

Lithuania also requires separate payment-services analysis for EMT operations. From 2 March 2026, covered EMT transfer or wallet functions require the relevant payment-services status.

The DD review should inspect:

  • Bank of Lithuania authorisation;

  • passport status;

  • payment-institution or EMI licence;

  • FCIS and AML records;

  • transition-period conduct;

  • customer-asset migration;

  • Lithuanian staff and management;

  • services performed by related entities.

Estonia

From 1 July 2026, Estonia permits covered crypto services only through Finantsinspektsioon authorisation or another EEA MiCA authorisation. Estonia cancelled the former FIU virtual-currency licence entries for current CASP purposes.

An applicant still awaiting a decision must cease ordinary business or limit activity to client-protective steps. It cannot accept new clients, open new accounts, or market actively in the EEA.

The DD review should not rely on a historic FIU licence screenshot. It should obtain:

  • the current Finantsinspektsioon or EEA authorisation;

  • passport evidence;

  • pending-application correspondence;

  • wind-down instructions;

  • customer notices;

  • asset-return records;

  • current AML registration and reporting arrangements.

EEA EFTA states

EEA Joint Committee Decision No. 41/2025 incorporated MiCA into the EEA Agreement, subject to completion of constitutional requirements. Norway, Iceland, and Liechtenstein have since implemented and applied the regime through national measures.

Norway

Norway’s Crypto-Assets Act and TFR II amendments took effect on 1 July 2025. The MiCA transition then ran until 1 July 2026 or an earlier grant or refusal. That transition has expired.

Norway now requires an Article 63 authorisation or eligible Article 60 notification. Finanstilsynet confirms that the passport operates across EEA states after Article 65 notification.

A Norwegian review should verify:

  • Finanstilsynet authorisation;

  • the authorised service list;

  • Article 60 status;

  • fitness records;

  • Norwegian presence and management;

  • passport notifications;

  • Norwegian AML and TFR compliance;

  • conduct after transition.

Iceland

Iceland implemented MiCA through Law No. 101/2025. The Central Bank of Iceland has stated that from 1 July 2026 only authorised providers may continue covered services. Unauthorised providers must stop marketing, new onboarding, and ordinary service. Limited wind-down activity can continue where needed to protect clients.

The project file should contain the Central Bank authorisation, passport details, transition correspondence, and evidence of any permitted wind-down.

Liechtenstein

Liechtenstein’s MiCA transition ended on 1 July 2026. TVTG registrations expired on 2 July 2026 to the extent they covered activities now subject to MiCA authorisation. The FMA register was being updated following that change.

The reviewer must distinguish:

  • services subject to MiCA;

  • roles remaining subject to the TVTG;

  • tokenised financial instruments;

  • payment or electronic-money services;

  • fund activity;

  • trustee or fiduciary activity;

  • AML duties.

A TVTG registration does not replace MiCA authority for a covered CASP service. A MiCA authorisation does not necessarily displace every TVTG role.

The English FMA notice used for this status check is an automated translation. The German text and operative Liechtenstein legislation should control exact legal conclusions.

Switzerland annex

Switzerland does not use MiCA. The reviewer must classify the project under existing Swiss financial-market statutes and civil law.

Possible statutes include:

  • the Banking Act;

  • the Financial Institutions Act;

  • the Financial Market Infrastructure Act;

  • the Financial Services Act;

  • the Collective Investment Schemes Act;

  • the Anti-Money Laundering Act;

  • the Code of Obligations;

  • the Debt Enforcement and Bankruptcy Act.

No single “crypto licence” answers every project.

Token classification

FINMA’s ICO guidance divides tokens by economic function:

  • payment tokens;

  • utility tokens;

  • asset tokens;

  • hybrid tokens.

A utility token falls outside securities treatment only when its sole purpose is digital access and that function exists at issuance. An investment function can make it a security. Asset tokens are generally treated as securities. Payment functions can trigger AML duties.

The guidance reflects FINMA’s supervisory approach. The underlying statutes control.

The Swiss classification file should examine:

  • claims against an issuer;

  • participation and voting rights;

  • dividends or interest;

  • repayment;

  • asset or revenue linkage;

  • transferability;

  • standardisation;

  • payment use;

  • product readiness;

  • collective investment;

  • custody and deposit-taking;

  • secondary trading.

Stablecoins

FINMA’s 2024 stablecoin guidance addresses issuer structures using bank default guarantees. Those structures can avoid a banking licence only when statutory and supervisory conditions are met. FINMA identified risks involving holder protection, guarantor banks, AML, and sanctions.

The review should verify:

  • issuer liability;

  • redemption rights;

  • guarantee terms;

  • guarantee cap;

  • reserve or collateral arrangements;

  • bank counterparty;

  • bankruptcy treatment;

  • customer identification;

  • sanctions screening;

  • public disclosures.

A guarantee is not equivalent to segregated reserve ownership.

Staking

FINMA’s staking guidance treats insolvency segregation as fact-dependent. The legal result can change where assets are transferred, pooled, delegated abroad, subject to lock-up, or exposed to slashing.

The review should examine direct staking, delegated staking, liquid staking, sub-staking, validator control, withdrawal rights, and customer asset records.

Ledger-based securities and DLT trading facilities

Switzerland’s DLT Act has applied fully since 1 August 2021. It introduced ledger-based securities, insolvency rules for certain DLT assets, and DLT trading facilities.

A DLT trading facility licence can be required when a multilateral system trades DLT securities, provides central custody under uniform rules, or clears and settles transactions under uniform rules. The operator must be a Swiss legal entity with its registered office and head office in Switzerland. FinMIA arts. 73a–73f.

FINMA licensed the first Swiss DLT trading facility in March 2025. Its review included business continuity and source-code checks for smart contracts. That decision illustrates the evidence expected from an infrastructure operator.

Future Swiss measures

The Federal Council’s October 2025 proposal for payment-instrument institutions and crypto institutions remained a legislative proposal on the As-of Date. It should not be treated as current law.

The revised Anti-Money Laundering Act and the new beneficial-owner transparency statute enter into force on 1 October 2026. They were future-effective on 21 July 2026. Transaction planning should address implementation without treating the duties as already operative.

Cross-border group design

A common European structure places the MiCA-authorised CASP in one EEA state and retains the issuer, foundation, developer, treasury company, or intellectual-property owner elsewhere. That model can work only when the legal and operating allocation is genuine.

The reviewer should trace:

  • which entity contracts with users;

  • which entity receives fees;

  • which entity controls wallets;

  • which entity employs operational staff;

  • which entity owns the interface;

  • which entity controls smart-contract upgrades;

  • which entity makes listing decisions;

  • which entity owns customer data;

  • which entity bears customer liability;

  • which entity performs AML and Travel Rule duties.

An offshore or Swiss affiliate should not become the de facto CASP through asset control, user-facing activity, or service execution.

Intercompany agreements should cover:

  • service scope;

  • intellectual property;

  • staff and secondments;

  • data processing;

  • regulated responsibilities;

  • service levels;

  • audit and regulator access;

  • incident reporting;

  • fees and transfer pricing;

  • termination;

  • migration;

  • liability.

The agreements must match operations. A paper allocation that differs from conduct carries little weight.

Red flags and transaction treatment

Stop or restructure

The following findings normally require suspension, abandonment, or restructuring before closing:

  • covered services after transition without MiCA authority;

  • reliance on a pending application;

  • use of an expired national VASP registration;

  • false CASP or passport claims;

  • an affiliate using another entity’s authorisation;

  • a financial instrument treated as an ordinary MiCA token;

  • unsupported NFT treatment;

  • an ART or EMT issued by an ineligible entity;

  • qualifying EMT payment services without payment authority;

  • active EU solicitation by a third-country firm relying on Article 61;

  • client-asset commingling;

  • an offshore or unauthorised sub-custodian controlling client assets;

  • a material asset shortfall;

  • no credible EU effective management;

  • material services outside the approved scope;

  • missing ownership approval for the transaction;

  • undisclosed admin, minting, treasury, or listing powers;

  • missing ownership of core code or domains.

Conditions precedent

A clear cure can support a condition precedent:

  • receipt of Article 63 authorisation;

  • completion of Article 60 notification;

  • passport completion;

  • qualifying-holding approval;

  • payment-services authorisation;

  • product reclassification and restructuring;

  • white-paper notification or correction;

  • migration to an authorised custodian;

  • client-asset segregation;

  • key rotation;

  • local management and staffing;

  • contract novation;

  • intellectual-property assignment;

  • DORA remediation;

  • Travel Rule implementation;

  • regulator clearance;

  • customer re-papering.

The condition should identify the evidence required. “Compliance satisfactory to the buyer” is not an objective closing test.

Price, escrow, and indemnity

Operational remediation does not remove historic liability. Price protection, escrow, holdback, or specific indemnity may be needed for:

  • historic unlicensed services;

  • post-transition service;

  • defective white papers;

  • token-sale claims;

  • missing prospectuses;

  • customer-asset losses;

  • data breaches;

  • sanctions exposure;

  • AML failures;

  • market manipulation;

  • tax;

  • employment;

  • intellectual-property defects;

  • regulator investigations.

The protection should identify the claimant class, covered period, loss measure, limitation period, conduct of claims, and available security.

Monitored remediation

Lower-severity matters can remain open only with:

  • a named owner;

  • an exact task;

  • an evidence requirement;

  • a deadline;

  • reporting frequency;

  • buyer access;

  • consequences for non-completion.

Policy drafting without operational testing should not count as completed remediation.

Priority evidence request

The next project-specific data room should contain these records.

Corporate and regulatory status

Current group chart.
Incorporation and good-standing records.
Beneficial-owner and shareholder registers.
MiCA authorisations.
Article 60 notifications.
Passport notifications.
Licence conditions.
Regulator correspondence.
Former national VASP registrations.
Warning-list and enforcement checks.
Qualifying-holding filings.

Tokens and products

  • Current and historic white papers.

  • Classification opinions.

  • Joint ESA classification tests.

  • Sale agreements.

  • Token rights.

  • Contract addresses.

  • Mint, burn, pause, freeze, and upgrade powers.

  • Allocation and vesting records.

  • Stablecoin reserves and redemption records.

  • NFT collection and fractionalisation data.

  • Staking and liquid-staking terms.

Services and market access

  • Entity-by-service matrix.

  • User journeys.

  • Revenue map.

  • User-country data.

  • Marketing archives.

  • Affiliate and influencer agreements.

  • Reverse-solicitation files.

  • Geoblocking records.

  • Host-state passport records.

  • Local-language sites and applications.

Client assets

  • Wallet inventory.

  • Key and MPC records.

  • Signer lists.

  • Client ledgers.

  • Reconciliations.

  • Custody and sub-custody agreements.

  • Pre-funding arrangements.

  • Shortfall records.

  • Insolvency opinions.

  • Insurance.

  • Staking and validator records.

Technology and DORA

  • ICT risk documents.

  • Asset and system inventories.

  • Architecture diagrams.

  • Code repositories.

  • Deployment records.

  • Smart-contract audits.

  • Incident reports.

  • Recovery tests.

  • Vendor register.

  • Cloud, oracle, bridge, and sequencer contracts.

  • Exit plans.

AML, sanctions, privacy, and conduct

  • AML and sanctions policies.

  • Customer files.

  • Transaction alerts.

  • Travel Rule records.

  • Self-hosted-wallet evidence.

  • Suspicious-activity reports.

  • Data maps.

  • Privacy notices.

  • Transfer mechanisms.

  • Breach records.

  • Inside-information records.

  • Treasury and market-maker files.

Financial, tax, and disputes

  • Audited financial statements.

  • Management accounts.

  • Bank and reserve statements.

  • Wallet reconciliations.

  • Tax returns and opinions.

  • Payroll and token-compensation records.

  • Customer complaints.

  • Litigation.

  • Regulator inquiries.

  • Insurance notices.

  • Settlements.

Part 04

Middle East

UAE regulators · Bahrain · QFC · Saudi Arabia
In essence

This session examines legal due diligence for Web3 projects incorporated, licensed, marketed, or operated in the United Arab Emirates, Bahrain, the Qatar Financial Centre, or Saudi Arabia. The question is whether each project entity, token, service, custody arrangement, control structure, and market-access channel has the correct legal classification and permission before an investor or acquirer relies on it. No project documents, regulator instruments, user data, or transaction terms were supplied. This analysis therefore states the regional review method and does not clear any named project.

Executive summary
United Arab Emirates

The UAE does not have one virtual-asset permission that covers every emirate, financial free zone, token, and service. The reviewer must allocate the product and activity among the UAE Capital Market Authority, Central Bank of the UAE, Dubai VARA, DIFC DFSA, and ADGM FSRA. Federal Decree-Law No. 33 of 2025, arts. 1 and 39; Dubai Law No. 4 of 2022; ADGM Financial Services and Markets Regulations 2015; DFSA GEN 3A.

UAE federal

The Capital Market Authority replaced the Securities and Commodities Authority on 1 January 2026. Investment-purpose virtual assets outside the financial free zones fall within the new capital-market statute. A project should not rely on an old SCA approval, register extract, or SCA-VARA arrangement without current CMA confirmation. Federal Decree-Law No. 32 of 2025, arts. 2, 5 and 30; Federal Decree-Law No. 33 of 2025, art. 39.

Payment tokens

The Central Bank regulates covered payment-token issuance, conversion, custody, and transfer. Algorithmic stablecoins and privacy tokens are prohibited under the Payment Token Services Regulation. Issuers face reserve, redemption, white-paper, controller, and technology duties. CBUAE Circular No. 2/2024, Payment Token Services Regulation, arts. 2, 16, 21–23, 26, 31 and 34.

Dubai

VARA regulates virtual-asset activity in Dubai mainland and its non-DIFC free zones. Formation, a commercial licence, an application, or preliminary approval does not prove operational authority. Custody providers face strict asset segregation, no rehypothecation, separate client wallets, and separate-entity requirements. VARA Virtual Assets and Related Activities Regulations 2023, pts. III–V; VARA Custody Services Rulebook, pts. III.B and IV.C.

DIFC

The DFSA applies a financial-services model rather than the VARA model. A firm must hold the correct Financial Services Permission and assess each non-fiat crypto token before use. A Fiat Crypto Token requires DFSA acceptance. Privacy Tokens and Algorithmic Tokens are prohibited. DFSA GEN 3A.2.1–3A.2.3.

ADGM

The FSRA requires the exact regulated activity, permitted client type, Accepted Virtual Asset or Accepted Fiat-Referenced Token, and applicable permission conditions. ADGM added dedicated Fiat-Referenced Token rules from 1 January 2026 and staking rules in April 2026. A DLT Foundation registration is a corporate wrapper, not financial-services authority. FSRA COBS chs. 15, 17 and 19A; ADGM DLT Foundations Regulations 2023, as amended.

Bahrain

A person may not market or perform regulated crypto-asset services in or from Bahrain without a CBB licence. The licence category determines whether the firm may advise, receive orders, hold client assets, deal, manage portfolios, or operate an exchange. A separate regime applies to stablecoin issuance. CBB Rulebook, vol. 6, CRA-1.1 and SIO-1.1.

Qatar Financial Centre

The QFC route supports permitted tokens that represent rights in property and regulated investment tokens. Tokens with no off-chain property right, cryptocurrencies used as substitutes for currency, and stablecoins used as payment instruments are excluded. A QFC permission does not authorise activity elsewhere in Qatar. QFC Digital Asset Regulations 2024, arts. 9 and 18–23; QFCRA TOKN 2.1.1–2.1.5.

Saudi Arabia

No generally available standalone Saudi VASP licensing route was identified in the current official public materials. That finding should not be converted into a claim that every virtual-asset activity is prohibited. Payment services require SAMA authority, investment products can engage Saudi CMA law, and sandbox permission is limited to the approved test. Saudi market access should remain blocked unless Saudi counsel and the relevant regulator confirm a lawful route.

Transaction

Unlicensed service, false licence claims, prohibited token design, client-asset shortfall, unapproved control change, or reliance on a test-only permission should stop closing or require restructuring. Historic exposure normally requires escrow, a specific indemnity, price protection, or retained liability.

Analysis by issue

Regional review sequence

Middle East due diligence should begin with five connected maps.

The entity map identifies every issuer, foundation, developer, front-end operator, custodian, exchange, treasury company, market maker, validator, and service company. It records formation, ownership, management, employees, contractors, domains, bank accounts, wallets, and contractual roles.

The activity map assigns each service to a named person. Relevant services include issuance, sale, placement, exchange, order matching, dealing, broking, advice, management, custody, transfer, staking, lending, payment, validation, token generation, and operation of an interface.

The product map classifies every token and receipt. A fundraising instrument, live token, staking receipt, wrapped token, bridge asset, liquidity-pool interest, stablecoin, NFT, and tokenised security may produce different answers.

The territory map records where services are performed and where users are targeted. Relevant evidence includes user residence, local-language content, payment rails, local staff, events, affiliates, influencers, support channels, domains, and application-store distribution.

The control map records powers over code and assets. It should identify upgrade, pause, mint, burn, freeze, blacklist, fee, oracle, bridge, listing, treasury, validator, and recovery powers. It should also record signers, thresholds, time locks, hardware custody, delegation, and emergency processes.

A licence opinion that refers only to “the project” is incomplete. Each entity remains responsible for its own conduct even when the group presents one brand.

Comparative regulator map

Perimeter Principal authority Main regulated subject Core due-diligence failure
UAE outside financial free zones UAE Capital Market Authority Investment-purpose virtual assets, trading, platforms, and related capital-market services Reliance on a former SCA status or an unavailable current activity approval
UAE payment-token perimeter Central Bank of the UAE Payment-token issuance, conversion, custody, transfer, monetary and payment functions Treating a stable-value payment product as an ordinary virtual asset
Dubai outside DIFC VARA Issuance and licensed virtual-asset activities in Dubai Commercial formation or preliminary status presented as operational permission
DIFC DFSA Financial services, promotions, offers, funds, derivatives, custody, and crypto tokens in or from DIFC FSP scope, token suitability, or client-assets endorsement does not match the live product
ADGM FSRA Financial services involving Accepted Virtual Assets and Accepted Fiat-Referenced Tokens Corporate registration or DLT Foundation status presented as an FSRA permission
Bahrain Central Bank of Bahrain Crypto-asset services, exchanges, custody, digital-token advice, and stablecoin issuance Licence category does not cover the activity or the project operates outside licence conditions
Qatar Financial Centre QFCA and QFCRA Permitted property-backed tokens, token services, and investment tokens Cryptocurrency or stablecoin treated as a permitted QFC token
Saudi Arabia SAMA for payments; Saudi CMA for securities and investment activity Payment services, securities, investment products, and approved tests Sandbox status or foreign authorisation presented as Saudi market authority

The legal result follows the product and conduct. It does not follow the project’s preferred regulator.

UAE regulator allocation

The UAE analysis must separate four geographic and functional areas:

  1. UAE onshore and non-financial free zones under federal law.

  2. Dubai mainland and Dubai non-DIFC free zones under VARA, with federal overlays.

  3. DIFC under DIFC law and DFSA administration.

  4. ADGM under ADGM law and FSRA administration.

The Central Bank’s payment-token jurisdiction can cross the first two areas. Federal AML legislation also applies across the state, with the financial free-zone regulators administering local supervisory duties.

A project can need more than one approval. A Dubai exchange may hold VARA authority for exchange services yet need a Central Bank route for payment-token conversion, custody, or transfer. A token can also engage capital-market law when its rights or use make it an investment-purpose virtual asset.

The first UAE workpaper should therefore state:

  • the emirate and legal zone of each entity;

  • whether the zone is a financial free zone;

  • the exact token classification;

  • every service performed;

  • every regulator claimed;

  • the licence, registration, non-objection, or acceptance relied upon;

  • any coordination or recognition arrangement relied upon;

  • the user territories;

  • the entity named in each user contract.

A statement that the project has “a UAE crypto licence” has little evidentiary value.

UAE Capital Market Authority

2026 statutory change

Federal Decree-Law No. 32 of 2025 established the Capital Market Authority and became effective on 1 January 2026. It transferred the former SCA’s legal and supervisory position to the new authority, subject to the statute and implementing measures. Federal Decree-Law No. 32 of 2025, arts. 2, 5 and 30.

Federal Decree-Law No. 33 of 2025 regulates the capital market. Its definition of financial products includes virtual assets used for investment purposes. The definition excludes fiat digital representations, securities already classified elsewhere, and instruments within the Central Bank’s monetary, payment, or store-of-value competence. Federal Decree-Law No. 33 of 2025, art. 1.

Article 39 places trading and related services involving covered virtual assets within CMA supervision. It also connects lawful trading to the official-list and registration process. Federal Decree-Law No. 33 of 2025, art. 39.

The April 2026 CMA announcement refers to five rule modules and eight regulated virtual-asset activities. An announcement is not a substitute for the operative rules. A project should produce:

  • the current rule modules;

  • its CMA licence or registration instrument;

  • the authorised activity schedule;

  • approved products;

  • platform-list records;

  • licence conditions;

  • transition correspondence;

  • regulator directions;

  • current register evidence.

A prior SCA register entry may remain relevant to history. It does not by itself establish current CMA status, scope, or transition compliance.

Federal and Dubai interaction

Dubai Law No. 4 of 2022 and VARA rules continue to regulate Dubai outside DIFC. The federal capital-market statute also covers investment-purpose virtual assets outside the financial free zones. The project should not infer a national passport from earlier cooperation announcements between SCA and VARA.

A current opinion should identify:

  • whether the activity is licensed directly by VARA or CMA;

  • whether a recognition arrangement applies;

  • whether the activity is confined to Dubai;

  • whether the firm serves other emirates;

  • whether the token is registered or listed through the required federal process;

  • whether both authorities have received required notifications;

  • whether any permission is conditional.

Where the project relies on recognition rather than a direct approval, the data room should contain written regulator confirmation.

Capital-market classification

The term “virtual asset” does not displace securities, fund, derivative, or banking law. The reviewer should test:

  • equity and voting rights;

  • debt and repayment rights;

  • profit or revenue participation;

  • redemption;

  • claims against reserves;

  • pooled investment;

  • discretionary management;

  • derivative exposure;

  • tokenised fund interests;

  • collective-investment features;

  • secondary-market support.

A token sold for fundraising can create a different legal result from the token’s current use. The review must cover both stages.

Central Bank payment-token rules

Perimeter

The Payment Token Services Regulation applies to covered Payment Token Issuing, Payment Token Conversion, Payment Token Custody and Transfer, and connected promotion. It applies in the UAE outside DIFC and ADGM. CBUAE Circular No. 2/2024, Payment Token Services Regulation, arts. 2–3.

A Payment Token is a virtual asset that purports to maintain a stable value by reference to the same fiat currency or another token denominated in that currency. The economic design matters more than the product label.

The Central Bank prohibits a person from performing or directing covered payment-token services to UAE persons without the prescribed licence, registration, or non-objection route. Payment Token Services Regulation, art. 2.

The applicant route depends on the actor and activity. A UAE company may seek a local licence. A foreign or financial-free-zone issuer may require foreign-issuer registration. A VASP already licensed by the CMA or a local authority may use a prescribed non-objection route for limited payment-token functions. The project should not assume that its virtual-asset licence automatically covers payment services.

Prohibited designs

The Payment Token Services Regulation prohibits algorithmic stablecoins and privacy tokens within its scope. It also restricts services involving those products. Payment Token Services Regulation, art. 2.

The review should identify:

  • the reference currency;

  • the stabilization method;

  • reserve composition;

  • mint and burn process;

  • redemption obligation;

  • holder claim;

  • privacy functions;

  • mixer or obfuscation features;

  • chain and bridge design;

  • offshore and UAE issuers;

  • related conversion and custody providers.

A token described as “overcollateralised” or “decentralised” may still have an algorithmic stabilization mechanism.

Reserve and redemption

A licensed issuer must maintain protected reserve assets. The reserve must remain separate from the issuer’s operational estate and third-party claims. The rules require same-currency arrangements, daily reconciliation, and recurring external confirmation. Payment Token Services Regulation, arts. 21–23.

Holders must receive a par redemption right without undue delay. The ordinary expectation is redemption by the next business day, subject to the rule’s conditions and limited cost-based fees. Payment Token Services Regulation, art. 21.

The DD file should reconcile:

  • outstanding token supply;

  • reserve-account balances;

  • asset eligibility;

  • issuer and bank records;

  • daily reconciliations;

  • auditor confirmations;

  • redemption requests;

  • failed or delayed redemptions;

  • liens and security interests;

  • insolvency treatment;

  • reserve-agent contracts.

A reserve report dated before a material supply increase does not establish current backing.

White paper and promotion

The Central Bank must review and accept the prescribed audited white paper before an onshore sale or transfer. The issuer must publish it within the required period. Material amendments require further review and publication. Payment Token Services Regulation, art. 26.

The review should compare the white paper with:

  • live code;

  • reserve policy;

  • redemption records;

  • fee terms;

  • suspension powers;

  • wallet controls;

  • administrator powers;

  • risks;

  • actual marketing.

Central Bank acceptance does not prove that later conduct remained compliant.

Controllers and senior management

A change involving a controller or senior manager can require prior Central Bank approval. The Payment Token Services Regulation uses a 10 percent controller threshold for this purpose. Payment Token Services Regulation, art. 16.

Acquisition agreements should identify direct and indirect holdings, voting arrangements, options, convertibles, veto rights, board rights, and acting-in-concert arrangements. The parties should not transfer de facto control before approval.

Dubai VARA

Territorial and activity perimeter

VARA regulates virtual-asset activity in Dubai mainland and Dubai free zones other than DIFC. VARA Virtual Assets and Related Activities Regulations 2023, pt. I.

Schedule 1 covers the principal licensed activities:

  • advisory services;

  • broker-dealer services;

  • custody services;

  • exchange services;

  • lending and borrowing services;

  • virtual-asset management and investment services;

  • transfer and settlement services.

Issuance is regulated separately.

The reviewer should match the live user journey to every activity. An exchange can also provide custody, transfer, lending, and staking. Each activity needs the correct authority.

The file should contain the final operational licence, not only:

  • a certificate of incorporation;

  • a commercial trade licence;

  • an application acknowledgment;

  • preliminary approval;

  • a regulator discussion;

  • a sandbox or pilot record;

  • a public statement by the project.

The public register should be checked immediately before signing and closing. The licence instrument and conditions remain controlling where the register is abbreviated.

Entity and brand matching

The legal entity named on the VARA licence should match:

  • user terms;

  • application onboarding;

  • website footer;

  • payment descriptor;

  • privacy notice;

  • invoices;

  • customer support;

  • wallet agreements;

  • marketing communications.

An affiliate cannot use another group member’s licence merely because the group shares technology or branding.

The reviewer should identify every unlicensed affiliate that:

  • contracts with users;

  • collects fees;

  • controls wallets;

  • chooses listings;

  • executes orders;

  • provides recommendations;

  • operates transfers;

  • approves withdrawals;

  • performs customer support tied to transactions.

Material conduct by that affiliate can defeat the group’s licence allocation.

Issuance

The VARA Virtual Asset Issuance Rulebook separates Category 1, Category 2, and exempt issuance.

Category 1 includes specified fiat-referenced, asset-referenced, and designated virtual assets. It requires issuer licensing.

Category 2 covers other non-exempt virtual assets. It can avoid issuer licensing only where the issuer follows the prescribed distributor and issuance process.

The exempt route is narrow. It includes defined non-transferable, closed-loop, redeemable, or designated arrangements. The reviewer should test each element.

The issuance category can change when:

  • redemption rights change;

  • backing is added or removed;

  • transferability begins;

  • the product opens to new users;

  • secondary trading begins;

  • supply rights change;

  • the issuer adds yield;

  • the token acquires payment use.

The review should compare current facts with the original classification submission.

Marketing

The VARA Marketing Regulations 2024 cover marketing connected with Dubai-regulated virtual assets and reach campaigns directed into the UAE within their scope. Marketing of a regulated activity should identify the licensed VASP or approved representative. VARA Marketing Regulations 2024, pt. I.

The review should cover:

  • project and founder social accounts;

  • influencers;

  • affiliates;

  • referral programs;

  • event presentations;

  • application stores;

  • token-listing announcements;

  • local-language campaigns;

  • paid search;

  • community moderators.

A disclaimer cannot cure active marketing by an unlicensed entity.

VARA prohibits marketing involving anonymity-enhanced or privacy coins within the stated rules. The project should also test privacy features that are not reflected in the token’s name.

Custody

VARA applies strict custody rules.

Virtual assets held in custody are not assets or depository liabilities of the custodian. The custodian must not rehypothecate them, even with client consent. Each client’s assets must remain in a separate wallet containing only that client’s assets. The custodian must retain control during the custody service. VARA Custody Services Rulebook, pt. III.B.1–4.

A custody provider must be a separate legal entity from group members that perform other virtual-asset activities. VARA can permit a limited transfer-and-settlement combination, subject to approval and operational separation. VARA Custody Services Rulebook, pt. III.B.5–8.

This structure affects acquisitions. The buyer should verify:

  • separate incorporation;

  • separate personnel;

  • information barriers;

  • wallet segregation;

  • service agreements;

  • capital;

  • insurance;

  • audit;

  • customer contracting;

  • intercompany fees;

  • incident responsibility.

A shared key team can undermine the required operational separation.

Staking from custody

VARA requires each client’s staked assets to remain in a separate wallet. The custodian may not pool different clients’ assets to meet protocol thresholds. Each node or instance may hold or receive delegation from one client only. The custodian remains responsible for safekeeping and must control withdrawal keys. VARA Custody Services Rulebook, pt. IV.C.

The review should obtain:

  • client staking instructions;

  • node mapping;

  • wallet-to-client mapping;

  • validator contracts;

  • slashing allocation;

  • reward calculation;

  • withdrawal-key controls;

  • outage and fork procedures;

  • client disclosures.

A pooled staking architecture can require redesign before closing.

Material change and control

A VASP must obtain VARA’s prior written approval before a material change, addition of an activity, or material modification to an authorised activity. VARA Company Rulebook, pt. VIII.A.

No action may produce a change of control without prior VARA approval. The VASP and proposed controller must apply. VARA’s determination period is ordinarily 30 working days after a complete filing, subject to extension. VARA Company Rulebook, pt. VIII.C.

The acquisition agreement should include:

  • a VARA approval condition;

  • filing cooperation;

  • disclosure of regulator communications;

  • an agreed position on licence conditions;

  • restrictions on pre-closing integration;

  • a long-stop date;

  • termination rights;

  • treatment of restructuring requirements.

DIFC and the DFSA

Separate perimeter

DIFC is outside VARA’s jurisdiction. A DIFC entity must assess its activity under DIFC law and the DFSA Rulebook.

The DFSA permission is activity-specific. The reviewer should obtain the Financial Services Permission and identify:

  • every authorised financial service;

  • client classifications;

  • endorsements;

  • product limitations;

  • branch restrictions;

  • conditions;

  • authorised individuals;

  • regulator directions.

A DIFC commercial registration is not a Financial Services Permission.

Token suitability

DFSA GEN 3A.2.1 prohibits specified activity involving a Crypto Token unless the rule’s conditions are met.

For a non-fiat Crypto Token, the person must complete a prior assessment and reach a reasonable suitability conclusion. The assessment covers the token’s purpose, founders, control arrangements, foreign status, market size, liquidity, trading history, technology, and effect on legal compliance. DFSA GEN 3A.2.1(2)–(3).

For a Fiat Crypto Token, the DFSA must be satisfied that the token is suitable for use in DIFC. DFSA GEN 3A.2.1(2)(b).

The assessment is an additional product gate. It does not replace the firm’s Financial Services Permission.

The DD file should contain:

  • the approved assessment methodology;

  • each completed token assessment;

  • committee records;

  • data sources;

  • legal analysis;

  • technical review;

  • ongoing monitoring;

  • suspension and delisting decisions;

  • DFSA correspondence.

A token added before completion of the assessment presents a licensing and conduct issue.

Prohibited tokens

DFSA GEN 3A.2.2 prohibits Privacy Tokens and devices that obscure required information. Current rules also prohibit Algorithmic Tokens. DFSA GEN 3A.2.2–3A.2.3.

The product review should test the token’s actual functions. Privacy-enhancing options, shielded pools, mixers, and default obfuscation can matter even when the issuer uses another label.

Client assets

Revised DFSA Client Assets rules took effect on 1 January 2026. They apply to firms providing or arranging custody and firms holding the Client Assets endorsement.

The buyer should verify:

  • the current endorsement;

  • the assets covered;

  • the client types covered;

  • client-money and client-investment procedures;

  • wallet controls;

  • third-party custody;

  • reconciliation;

  • shortfall handling;

  • auditor reports;

  • regulator notifications;

  • insolvency treatment.

An FSP that permits dealing or advising does not automatically permit custody.

Property and security

DIFC Digital Assets Law No. 2 of 2024 addresses the property characteristics, control, transfer, and dealing rules for digital assets. DIFC also enacted Law of Security No. 4 of 2024 and related amendments.

A transaction opinion should apply those laws to:

  • legal ownership;

  • control;

  • security interests;

  • collateral enforcement;

  • tracing;

  • custody;

  • competing claims;

  • insolvency.

The technical controller and legal owner may differ. The review should not infer title from possession of a private key alone.

Acquisition and controller review

The DFSA Rulebook applies controller and business-transfer requirements to authorised firms. The exact notification or approval route depends on the firm, permission, controller type, and proposed holding.

The transaction should not close until DIFC counsel has confirmed:

  • the direct and indirect controller analysis;

  • required DFSA approval or notification;

  • required Registrar filings;

  • authorised-individual changes;

  • Client Assets endorsement effects;

  • business-plan changes;

  • outsourcing changes;

  • continuity of permissions.

ADGM and the FSRA

Financial Services Permission

An ADGM company or DLT Foundation cannot perform a Regulated Activity merely because it is registered in ADGM. The actor needs the relevant FSRA Financial Services Permission unless a specific exclusion applies.

The reviewer should examine the exact public-register entry and FSP. Relevant details include:

  • regulated activities;

  • Accepted Virtual Asset conditions;

  • Accepted Fiat-Referenced Token conditions;

  • client classifications;

  • retail restrictions;

  • client-money restrictions;

  • custody authority;

  • payment authority;

  • branch and outsourcing conditions.

ADGM register entries often contain firm-specific limitations. A generic statement that the firm is “FSRA regulated” is insufficient.

Accepted Virtual Assets

The FSRA requires a Virtual Asset to meet the acceptance process before an authorised firm uses it in regulated activity. The June 2025 amendments revised that process and confirmed prohibitions involving privacy tokens and algorithmic stablecoins.

The firm should maintain:

  • its assessment of each asset;

  • FSRA acceptance evidence;

  • technical and market data;

  • monitoring;

  • suspension triggers;

  • fork treatment;

  • delisting records;

  • sanctions and financial-crime analysis.

Acceptance of one asset does not extend to wrapped, bridged, staked, or derivative versions without analysis.

Fiat-Referenced Tokens

ADGM’s dedicated Fiat-Referenced Token rules took effect on 1 January 2026. They govern accepted tokens, regulated activities involving them, custody, reserve assets, and issuer duties.

An authorised person must not issue an FRT denominated in UAE dirhams. FSRA COBS 19A.3.2.

An issuer must place issuance proceeds into the prescribed client-money or reserve structure. Reserve investments must remain in segregated reserve accounts. A third-party reserve agent requires the regulator’s non-objection. FSRA COBS 19A.5.

The issuer must obtain a monthly independent attestation approved through the FSRA process. The attestation compares relevant money and reserve investments against outstanding redemption value. FSRA COBS 19A.9.

The review should reconcile:

  • token supply;

  • reserve balances;

  • asset eligibility;

  • reserve agents;

  • regulator non-objections;

  • monthly attestations;

  • redemption records;

  • issuer disclosures;

  • financial statements;

  • reserve investment income;

  • liens and claims.

Custody

The FSRA Safe Custody Rules require client and reserve assets to be recorded, registered, and held separately from the authorised person’s own investments. FSRA COBS 15.3.

Use of client assets requires the relevant authority and client permission. The rules treat staking as use of client assets for this purpose. FSRA COBS 17.5.

Third-party custodians require due diligence, suitable contractual rights, operational review, and continuing monitoring. Material reconciliation discrepancies require escalation and, where applicable, regulator notification. FSRA COBS 15.4, 15.8 and 17.8.

The review should identify each third-party wallet, exchange, validator, bank, and reserve agent. A vendor description does not decide whether that party is a custodian.

Staking

The April 2026 staking rules specify which Authorised Persons may stake client Virtual Assets. The rules extend beyond proof-of-stake where another model has materially similar characteristics.

Rewards provided to clients must use Accepted Virtual Assets or Accepted Fiat-Referenced Tokens. Client terms, risk disclosures, and reports must contain prescribed information.

The file should show:

  • the FSP basis for staking;

  • client consent;

  • asset eligibility;

  • validator selection;

  • lock-up;

  • withdrawal;

  • slashing;

  • reward type;

  • reward calculation;

  • commissions;

  • conflicts;

  • reporting.

Liquid-staking receipts need a separate product classification.

DLT Foundations

The DLT Foundations Regulations 2023 provide an ADGM corporate vehicle for distributed-ledger projects. The May 2026 amendments changed parts of the commercial and beneficial-owner treatment.

A DLT Foundation certificate does not authorise:

  • exchange services;

  • custody;

  • brokerage;

  • investment management;

  • payment services;

  • FRT issuance;

  • regulated staking;

  • public offerings that fall under financial-services law.

The reviewer should inspect the constitutive documents, council powers, token-holder voting, beneficial owners, treasury rules, smart-contract powers, and amendment procedures. It should then allocate regulated conduct to the correct authorised person.

Bahrain

Licensing perimeter

CBB Rulebook CRA-1.1.1 prohibits a person from marketing or performing regulated crypto-asset services in or from Bahrain without a CBB licence.

The territorial test can be satisfied by:

  • Bahrain incorporation;

  • a Bahrain business address;

  • service performance from Bahrain;

  • direct solicitation in Bahrain;

  • Bahrain staff or agents;

  • locally targeted communications.

The covered services include receiving and transmitting orders, dealing as agent or principal, portfolio management, custody, advice, exchange operation, and digital-token advice. CBB Rulebook, vol. 6, CRA-1.1.

The review should identify the exact licence category and activity schedule.

Category 1 has a limited intermediary and advisory scope. It cannot hold client assets or money and cannot operate an exchange.

Category 4 is the exchange category.

Categories 1 to 3 cannot present their businesses as an exchange, public order book, price-discovery venue, or automated matching system unless their permission provides the required authority. CBB Rulebook, vol. 6, CRA-1.1.26–1.1.27.

The project’s user interface can contradict its licence. A firm may call itself a broker while operating a multilateral order book.

Local form and management

The CBB prescribes legal-form and Bahrain-presence requirements by category. The applicant must maintain the designated place of business and the management structure required by its licence.

The reviewer should examine:

  • legal form;

  • registered and head office;

  • local directors and officers;

  • approved persons;

  • employment;

  • premises;

  • board records;

  • decision authority;

  • technology and outsourcing;

  • CBB correspondence.

A Bahrain address without local management does not establish compliance.

New services

A licensee needs prior CBB approval before adding a regulated crypto-asset service. The review should compare the current product with the original application and latest approval.

Potential unapproved additions include:

  • custody;

  • staking;

  • margin;

  • lending;

  • token advice;

  • portfolio discretion;

  • OTC dealing;

  • automated matching;

  • stablecoin activity;

  • new retail access.

Client assets

A Bahrain licensee holding client money or crypto-assets must use specially created segregated accounts. Client assets must remain separate from the licensee’s own assets. CBB Rulebook, vol. 6, CRA-4.5.2.

A third-party account provider must renounce lien, set-off, and competing claims over the client account. CRA-4.5.3.

Client money must remain in designated client accounts with an eligible Bahrain retail bank and cannot be used as the licensee’s own collateral. CRA-4.5.4.

The licensee must perform monthly reconciliations and complete them within the prescribed period. Differences and shortfalls require investigation and correction. CRA-4.5.5–CRA-4.5.8.

The reviewer should reconcile:

  • bank accounts;

  • on-chain wallets;

  • client ledgers;

  • financial statements;

  • reconciliation files;

  • shortfall reports;

  • third-party letters;

  • client statements;

  • custody agreements.

The CBB also requires risk disclosure in Arabic and English before the first transaction. The live onboarding record should prove delivery and acceptance.

Stablecoins

The CBB Stablecoin Issuance and Offering Module applies separately from a crypto-asset service licence. A person cannot issue or actively market a covered stablecoin in or from Bahrain without the prescribed issuer licence. CBB Rulebook, vol. 6, SIO-1.1.

The permitted model is a single-currency stablecoin backed by Bahraini dinar, US dollars, or another CBB-approved currency. Reserve value must remain at least equal to outstanding par value.

The reserve should be liquid, same-currency, segregated, and free of third-party encumbrance. The issuer must conduct daily reconciliation and publish recurring independent assurance. Holders must receive direct redemption at par, ordinarily within five business days. SIO-6.1–SIO-6.5.

The review should obtain:

  • issuer licence;

  • approved currency;

  • white paper;

  • reserve policy;

  • bank and custodian contracts;

  • daily reconciliations;

  • monthly assurance;

  • redemption logs;

  • delayed-redemption records;

  • fee schedule;

  • AML onboarding;

  • wind-down plan.

A crypto-asset service licence does not authorise stablecoin issuance.

Controllers and transactions

New controllers, prospective controllers, and increases in holdings or voting control require prior written CBB approval under the applicable rules.

The CBB also requires advance approval for material transactions and changes, including:

  • merger;

  • acquisition;

  • disposal;

  • new subsidiary;

  • foreign business;

  • transfer of major assets or liabilities;

  • constitutional amendment;

  • material business change;

  • cessation or wind-down.

CBB Rulebook, CRA-10.3 and General Requirements module, GR-7.3.

The purchase agreement should treat each required CBB approval as a condition precedent.

Qatar Financial Centre

Scope of the QFC token regime

The QFC Digital Asset Regulations 2024 establish legal rules for permitted tokens, ownership, transfer, control, cancellation, and licensed token services. They took effect on 1 September 2024.

Licensed token services include:

  • validation;

  • token generation;

  • token custody;

  • operation of a token exchange;

  • token transfer.

QFC Digital Asset Regulations 2024, arts. 18–23.

The QFC route is centred on tokens that represent rights in property. It is not a general cryptocurrency or payment-token licence.

Excluded tokens

A token is excluded where it does not represent a right in property other than the token itself. A token is also excluded where it substitutes for currency, represents currency, or serves as a means of payment. QFCRA TOKN 2.1.2.

The rules identify ordinary cryptocurrencies and stablecoins as examples of excluded tokens. A token representing rights to a commodity can qualify because it represents off-chain property.

The reviewer should test:

  • the legal right represented;

  • title to the underlying property;

  • transfer mechanics;

  • redemption;

  • token-holder remedies;

  • issuer insolvency;

  • custody;

  • register reconciliation;

  • valuation;

  • liens;

  • restrictions on transfer.

A marketing claim that the token is “asset backed” does not prove that the holder owns or can enforce a property right.

Investment tokens

An Investment Token represents a specified product, approved derivative, Islamic financial-contract right, or a substantially similar right. The financial-services rules apply as though the activity concerned the represented right. QFCRA TOKN 2.1.1.

Operating an investment-token exchange and clearing or settling investment-token transactions are regulated activities. QFCRA TOKN 2.1.4.

Custody includes holding or controlling investment tokens. It also includes holding or controlling private keys or another means through which client tokens are recorded and transacted. QFCRA TOKN 2.1.5.

The reviewer should therefore classify the underlying right before analysing the token technology.

Custody

QFCRA INMA 6.1.10A requires resilient token infrastructure, clear segregation of each client’s tokens, accurate execution of client instructions, and protection of cryptographic keys and data.

Where a firm controls the means of transfer, its systems must preserve the client’s transfer power and ownership rights. INMA 6.1.10A(3).

The review should examine:

  • client key control;

  • recovery keys;

  • transaction approval;

  • infrastructure compatibility;

  • wallet segregation;

  • underlying-property register;

  • third-party custodians;

  • incident procedures;

  • ownership remedies.

Geographic limit

The QFC regime applies within the Qatar Financial Centre. A QFC licence does not authorise payment, securities, custody, or marketing activity elsewhere in Qatar.

The project should identify:

  • where staff work;

  • where systems operate;

  • where users are located;

  • where marketing is directed;

  • where contracts are formed;

  • where fiat flows move;

  • whether Qatar Central Bank or Qatar Financial Markets Authority law applies.

Participation in the QFC Digital Assets Lab is a testing and development route. It does not guarantee commercial permission.

Saudi Arabia

Current public position

Official Saudi notices from 2018 and 2019 warned that virtual currencies were not then regulated or approved as official currency and that no licensed Saudi parties offered the identified activities. Those notices also warned against unauthorised marketing and misuse of Saudi names, the Saudi riyal, or national emblems.

Those notices remain relevant to regulator posture and marketing risk. They do not establish a current statutory prohibition covering every token, service, professional counterparty, or technology use.

No generally available standalone VASP licence route was identified in the official public materials reviewed as at 22 July 2026. A project should therefore avoid claiming Saudi authorisation unless it holds a specific current instrument.

Payments

The Payment Services Law and its Implementing Regulations require SAMA authority for regulated payment services. The product review should test:

  • transfer of money;

  • payment accounts;

  • acquiring;

  • remittance;

  • payment initiation;

  • stored value;

  • merchant settlement;

  • conversion;

  • wallets linked to fiat payment functions.

A virtual-asset feature does not remove payment regulation.

The reviewer should search SAMA’s current authorised-institution records and obtain the actual licence. A foreign payment licence has no automatic Saudi effect.

Securities and investments

A token representing shares, debt, fund interests, derivatives, investment management, or another security can engage the Capital Market Law and Saudi CMA rules.

The review should cover:

  • offers to Saudi residents;

  • local intermediaries;

  • local events;

  • Saudi-language marketing;

  • private placement;

  • managed portfolios;

  • advisory services;

  • tokenised securities;

  • secondary trading.

A token’s foreign classification does not control the Saudi result.

Sandbox and experiment permits

SAMA’s Regulatory Sandbox and Saudi CMA financial-technology permits are product-specific testing routes. They do not authorise conduct outside the approved test.

The due-diligence file should contain:

  • the sandbox or permit letter;

  • approved entity;

  • approved users;

  • test duration;

  • transaction limits;

  • permitted functions;

  • reporting terms;

  • expiry;

  • exit requirements;

  • production-authorisation path.

A sandbox participant should not market itself as fully licensed.

Market-access treatment

Absent written Saudi legal and regulator confirmation, the project should block:

  • Saudi retail onboarding;

  • Saudi-targeted advertising;

  • local influencers and affiliates;

  • local events used for solicitation;

  • Saudi riyal payment rails;

  • Saudi-specific referral programs;

  • use of Saudi names, currency branding, or emblems;

  • customer support designed for Saudi acquisition.

The review should preserve evidence that exclusions operate in practice.

Personal data

Saudi Arabia’s Personal Data Protection Law can apply to processing in the Kingdom and foreign processing of personal data relating to Saudi residents. Personal Data Protection Law, art. 2.

A foreign project serving Saudi users should therefore review:

  • privacy notices;

  • legal basis;

  • sensitive data;

  • direct marketing;

  • international transfers;

  • processor contracts;

  • breach response;

  • retention;

  • data-subject rights;

  • appointment of a data-protection officer where required.

Geoblocking Saudi transactions does not remove the law where the project still processes Saudi resident data.

Token classification and issuance

The regional classification should cover each transaction and each stage.

The reviewer should identify whether the asset functions as:

  • an investment-purpose virtual asset;

  • a security;

  • a fund or collective-investment interest;

  • a derivative;

  • a payment token;

  • a fiat-referenced token;

  • an asset-referenced token;

  • a property-backed permitted token;

  • a commodity right;

  • a utility or access right;

  • an NFT;

  • a receipt for staked or deposited assets.

The analysis should compare:

  1. legal rights;

  2. deployed code;

  3. issuer promises;

  4. marketing;

  5. actual operation.

Key questions include:

  • Does the holder have a claim against an issuer?

  • Is there a redemption right?

  • Does the token represent equity, debt, revenue, profit, or reserves?

  • Are assets pooled?

  • Does a manager exercise discretion?

  • Is value maintained against fiat?

  • Can the issuer mint or burn?

  • Is there an operating product at issuance?

  • Does the issuer support secondary trading?

  • Does a market maker receive special rights?

  • Does the token represent enforceable off-chain property?

“Utility,” “NFT,” “stable,” “decentralised,” and “asset backed” are assertions. They do not decide the legal classification.

Custody, staking, and insolvency

Custody test

A custody opinion should answer four separate questions.

1

who holds legal title?

2

who can cause a transfer?

3

are assets segregated legally, technically, and in the accounts?

4

what happens if the provider becomes insolvent?

The reviewer should identify every person who controls:

  • private keys;

  • MPC shares;

  • recovery keys;

  • wallet policies;

  • transaction approval;

  • withdrawal whitelists;

  • upgrade keys;

  • pause functions;

  • bridge controls;

  • validator withdrawals.

A contract can call a service non-custodial while technical powers establish control.

Regional differences

VARA prohibits rehypothecation and requires separate client wallets for custody. It also requires a separate custody entity.

ADGM permits use of client assets only under the applicable authority and permission. Staking counts as use.

Bahrain requires segregated client accounts, third-party renunciation of lien and set-off, and recurring reconciliation.

QFC custody can arise from control of the private key or another means of recording and transacting investment tokens.

The Central Bank requires separate protected wallets and reserves for payment-token business.

The DD report should not import one jurisdiction’s custody conclusion into another.

Insolvency

The legal opinion should address:

  • trust or equivalent status;

  • estate exclusion;

  • creditor recourse;

  • tracing;

  • omnibus shortfalls;

  • set-off;

  • liens;

  • sub-custodian failure;

  • reserve-agent failure;

  • administrator powers;

  • transfer to a replacement custodian;

  • fork and airdrop rights.

An on-chain balance proves that assets exist at an address. It does not prove ownership, segregation, or freedom from claims.

Staking

Staking review should identify:

  • asset ownership;

  • custody;

  • transfer or delegation;

  • pooling;

  • validator selection;

  • lock-up;

  • withdrawal;

  • slashing;

  • reward currency;

  • reward calculation;

  • commissions;

  • liquid-staking receipts;

  • sub-staking;

  • insolvency treatment.

VARA and ADGM apply express staking requirements. Other jurisdictions may capture staking through custody, management, dealing, lending, or token issuance.

DeFi, software, and DAO structures

A decentralised protocol can still have regulated actors.

The review should identify who:

  • deploys contracts;

  • operates the main interface;

  • selects pools or markets;

  • controls upgrades;

  • controls oracles;

  • collects fees;

  • routes orders;

  • approves listings;

  • controls treasury assets;

  • operates relayers;

  • provides customer support;

  • markets the product;

  • can block users or transactions.

A protocol can decentralise transaction validation while retaining central product control.

An open-source licence does not decide financial regulation. It also does not prove ownership of the code.

A DAO wrapper can own assets, contract, and allocate decision rights. It does not remove licensing, AML, sanctions, tax, employment, custody, or token-offering duties.

ADGM DLT Foundation status deserves particular care. The foundation may serve as the treasury or protocol vehicle. An FSRA-authorised entity must perform regulated financial services where the law requires one.

AML, sanctions, and Travel Rule controls

UAE

Federal Decree-Law No. 10 of 2025 replaced the 2018 UAE AML statute. Cabinet Resolution No. 134 of 2025 supplies the current executive provisions.

The executive regulation covers:

  • exchange between virtual assets and fiat;

  • exchange between virtual assets;

  • transfer;

  • safekeeping or administration;

  • control instruments;

  • financial services connected with an issuer’s offer or sale.

Cabinet Resolution No. 134 of 2025, art. 4.

Project documents that still cite only the repealed 2018 statute require amendment. The operating controls must also be tested against the current law.

VARA, DFSA, and FSRA apply local AML, sanctions, and Travel Rule duties to firms within their supervision.

Bahrain and QFC

The CBB CRA and AML modules apply originator and beneficiary information requirements to covered crypto transfers. A receiving institution must identify missing information and apply risk-based action. CBB Rulebook, vol. 6, AML-2A.2.22.

QFC AML rules apply to regulated firms and designated token-service providers within scope.

Operating evidence

The reviewer should sample:

  • customer identification;

  • beneficial-owner verification;

  • source of funds;

  • source of wealth;

  • PEP screening;

  • sanctions screening;

  • blockchain analytics;

  • self-hosted-wallet checks;

  • originator and beneficiary data;

  • transaction alerts;

  • suspicious-activity escalation;

  • blocked and frozen assets;

  • record retention;

  • staff training;

  • independent testing.

A policy proves intended design. It does not prove operation.

Sanctions analysis remains separate from licensing and AML registration. The review should identify who can reject, freeze, pause, block, or restrict a transaction. Public claims of permissionless operation should match the actual controls.

Data, cybersecurity, and communications

Multiple data regimes

The UAE has different data statutes for the federal onshore area, DIFC, and ADGM.

The principal regimes include:

  • Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data;

  • DIFC Data Protection Law No. 5 of 2020, as amended;

  • ADGM Data Protection Regulations 2021.

Bahrain applies Law No. 30 of 2018 on personal-data protection.

QFC has its own data-protection rules.

Saudi Arabia applies the Personal Data Protection Law and its implementing and transfer rules.

The reviewer should not treat a group-wide privacy notice as proof of compliance in each legal zone.

Web3 data

Wallet addresses, IP addresses, identity records, device identifiers, support tickets, transaction analytics, and risk scores can be personal data when linked or linkable to a person.

The project should map:

  • controllers;

  • processors;

  • purposes;

  • legal bases;

  • notices;

  • data sources;

  • recipients;

  • retention;

  • automated decisions;

  • international transfers;

  • breach response;

  • customer rights.

Writing data to a public chain does not remove data-protection duties. The review should identify what appears on-chain and whether it can be minimised, corrected, restricted, or dissociated.

Cybersecurity

The legal review should connect technical reports to licence duties.

The file should contain:

  • architecture diagrams;

  • wallet design;

  • key procedures;

  • source repositories;

  • deployment records;

  • audits;

  • penetration tests;

  • incident files;

  • recovery tests;

  • cloud contracts;

  • oracle and bridge dependencies;

  • vendor exit plans.

A security audit covering an old contract version does not support the current deployment.

Public communications

Websites and applications should state:

  • the correct legal entity;

  • the exact regulatory status;

  • the approved activities;

  • token and service risks;

  • custody status;

  • client-asset treatment;

  • complaints route;

  • geographic restrictions.

The project should remove claims that imply national or regional authority beyond the actual permission.

Corporate integrity, substance, and outsourcing

The corporate review should reconcile:

  • equity ownership;

  • token ownership;

  • intellectual-property ownership;

  • wallet control;

  • domain ownership;

  • data control;

  • revenue rights.

The licensed entity should not be an empty contracting shell while an offshore affiliate performs the regulated service.

Evidence of real operations includes:

  • local management;

  • personnel;

  • board decisions;

  • risk decisions;

  • product approvals;

  • wallet authority;

  • premises;

  • payroll;

  • bank mandates;

  • regulator meetings;

  • incident management.

Outsourcing contracts should give the regulated entity:

  • operational control;

  • information access;

  • audit rights;

  • regulator access;

  • incident notice;

  • confidentiality;

  • data rights;

  • termination rights;

  • transition assistance.

A service agreement that cannot be enforced against the group technology company presents a licence and continuity risk.

Regulatory status verification

A current status review should follow these steps:

  1. Search the regulator’s register by exact legal name.

  2. Search former names, trading names, and group affiliates.

  3. Obtain the licence or permission instrument.

  4. Identify every authorised service.

  5. Identify conditions, client limits, products, and endorsements.

  6. Compare the licence to user terms and operations.

  7. Review regulator correspondence.

  8. Check warnings, suspensions, restrictions, and enforcement.

  9. Repeat the check before signing and closing.

Special caution applies to:

  • former SCA status after the UAE CMA transition;

  • preliminary or application-stage VARA status;

  • DIFC firms without the required endorsement;

  • ADGM DLT Foundations without an FSP;

  • Bahrain firms operating outside their category;

  • QFC lab participants;

  • Saudi sandbox participants.

A representation that all licences are held should attach a schedule of each licence, activity, condition, and pending application.

Change of control and transaction approvals

The transaction team should map every direct and indirect change.

Relevant rights include:

  • shares;

  • voting power;

  • options;

  • convertibles;

  • board appointment;

  • veto rights;

  • acting-in-concert arrangements;

  • token-based voting;

  • foundation-council rights;

  • treasury control;

  • key control;

  • management agreements;

  • debt covenants.

Potential approvals include:

  • UAE CMA approval under current rules;

  • Central Bank controller approval for payment-token business;

  • VARA change-of-control approval;

  • DFSA controller approval or notification;

  • FSRA controller approval or notification;

  • CBB controller and transaction approval;

  • QFCRA or QFCA approval;

  • Saudi SAMA or CMA approval where a licensed activity is acquired.

The parties should not transfer de facto control before the regulator acts. Pre-closing vetoes, management direction, wallet authority, or operational integration can create that risk.

The acquisition agreement should state:

  • filing responsibility;

  • control over submissions;

  • information duties;

  • access to regulator correspondence;

  • acceptable conditions;

  • long-stop date;

  • interim operating covenants;

  • pre-closing integration limits;

  • termination rights;

  • post-closing undertakings.

Red flags and transaction treatment

Stop or restructure

These findings normally require suspension, abandonment, or restructuring:

  • an unlicensed core activity;

  • a former SCA approval presented as current CMA authority;

  • a payment token offered without the required Central Bank route;

  • an algorithmic stablecoin or privacy token within a prohibited perimeter;

  • commercial formation presented as a VARA licence;

  • a DIFC firm using tokens without the required assessment or DFSA acceptance;

  • a DLT Foundation presented as an FSRA-authorised financial firm;

  • a Bahrain intermediary operating an exchange;

  • a QFC entity handling an excluded cryptocurrency or stablecoin;

  • Saudi retail solicitation without a confirmed legal route;

  • client-asset commingling;

  • prohibited rehypothecation;

  • a material reserve or custody shortfall;

  • unapproved change of control;

  • missing ownership of core code, domains, or treasury assets;

  • false regulatory statements.

Conditions precedent

A matter can support a condition precedent where an objective cure exists:

  • receipt of a licence;

  • regulator non-objection;

  • controller approval;

  • activity extension;

  • token acceptance;

  • payment-token registration;

  • corrected white paper;

  • reserve funding;

  • client-asset segregation;

  • custody migration;

  • local staffing;

  • intellectual-property assignment;

  • contract novation;

  • key rotation;

  • data remediation;

  • AML remediation;

  • customer re-papering.

The condition should identify the document or evidence required for satisfaction.

Price, escrow, and indemnity

Historic liability can remain after operational repair.

Protection may be required for:

  • historic unlicensed services;

  • unlawful token offerings;

  • inaccurate white papers;

  • reserve deficiencies;

  • customer-asset losses;

  • AML failures;

  • sanctions exposure;

  • data breaches;

  • market manipulation;

  • tax;

  • employment;

  • intellectual-property defects;

  • regulator investigations.

The provision should define the covered period, claimant group, loss measure, limitation period, claim control, and security.

Monitored remediation

Lower-severity matters should remain open only where the transaction documents identify:

  • the exact task;

  • the owner;

  • the deadline;

  • required evidence;

  • reporting frequency;

  • inspection rights;

  • consequences of non-completion.

A general covenant to improve compliance is not an adequate remedy.

Priority evidence request

Corporate and ownership

Current group chart.
Formation and good-standing records.
Constitutional documents.
Shareholder and beneficial-owner registers.
Cap table, options, convertibles, warrants, and side letters.
Board and shareholder records.
Foundation and council records.
Intercompany agreements.

Regulatory status

  • Every licence, FSP, registration, non-objection, token acceptance, and sandbox instrument.

  • Approved activity schedules.

  • Licence conditions.

  • Current public-register extracts.

  • Applications and business plans.

  • Regulator correspondence.

  • Inspection, remediation, warning, and enforcement records.

  • Change-of-control filings.

Tokens and products

  • Current and historic white papers.

  • Classification opinions.

  • Sale agreements.

  • Token rights.

  • Contract addresses.

  • Supply and vesting records.

  • Mint, burn, pause, freeze, and upgrade powers.

  • Stablecoin reserve and redemption files.

  • Staking and liquid-staking documents.

  • NFT or property-right records.

Market access

  • User-country data.

  • Marketing archives.

  • Affiliate and influencer agreements.

  • Local-language sites.

  • Event records.

  • Payment rails.

  • Geoblocking.

  • Rejected onboarding.

  • Application-store distribution.

  • Reverse-inquiry evidence.

Custody and treasury

  • Wallet inventory.

  • Signers and thresholds.

  • MPC and recovery procedures.

  • Client ledgers.

  • Reconciliations.

  • Shortfall records.

  • Custody and sub-custody agreements.

  • Reserve-agent and bank contracts.

  • Validator records.

  • Treasury transfers.

  • Insurance and incident files.

AML, sanctions, data, and technology

  • AML and sanctions policies.

  • Customer samples.

  • Screening and alert records.

  • Travel Rule records.

  • Self-hosted-wallet controls.

  • Suspicious-activity files.

  • Data maps and privacy notices.

  • International-transfer records.

  • Architecture and repository records.

  • Audit, penetration-test, incident, and recovery reports.

Financial, tax, and disputes

  • Audited financial statements.

  • Management accounts.

  • Bank and reserve statements.

  • Wallet reconciliations.

  • Tax returns and opinions.

  • Payroll and token-compensation records.

  • Customer complaints.

  • Litigation and arbitration.

  • Regulator inquiries.

  • Insurance notices and settlements.

Part 05

Asia

Singapore · Hong Kong · Japan · South Korea
In essence

Web3 legal due diligence in Asia determines whether each project entity, token, service, interface, custody arrangement, control power, and marketing channel complies with the laws of Singapore, Hong Kong, Japan, and South Korea. The question is how a counterparty should examine these matters before signing, closing, listing, lending, or integrating with the project. No project documents, licence instruments, wallet records, user data, technical records, or transaction terms were supplied. This session states the regional review method, current legal cutoffs, evidence requirements, red flags, and transaction treatment. It does not clear any named project.

Executive summary
Asia

There is no regional licence or passport. Singapore, Hong Kong, Japan, and South Korea apply different product definitions, territorial tests, licensing routes, custody models, and market-conduct rules.

Singapore

A person providing a digital payment token service in Singapore generally needs the relevant licence under the Payment Services Act 2019. The regulated scope reaches dealing, facilitating exchange, transmission, and custody-related conduct specified by the Act. A Singapore person providing digital-token services only outside Singapore must also test Part 9 of the Financial Services and Markets Act 2022. Payment Services Act 2019, ss. 2, 5–9 and First Schedule; Financial Services and Markets Act 2022, ss. 137–167. Singapore Security tokens, collective-investment interests, derivatives, and other capital-markets products fall under the Securities and Futures Act 2001 rather than the digital-payment-token route alone. An issuer-pegged fiat token must also be tested as electronic money, a payment service, a deposit, or another regulated product. Securities and Futures Act 2001, ss. 2 and 82 and First and Second Schedules. Hong Kong A centralised virtual-asset trading platform operating in Hong Kong or actively marketing to Hong Kong investors requires SFC authority. Security-token platforms use the Securities and Futures Ordinance route. Non-security-token platforms use the Anti-Money Laundering and Counter-Terrorist Financing Ordinance route. The SFC recommends dual licensing because token classification can change. Hong Kong An applicant, deemed applicant, sandbox participant, or group affiliate is not necessarily licensed. The legal entity on the SFC register, its approved activities, licence conditions, associated entity, responsible officers, domains, and user contracts must match the live business.

Hong Kong stablecoins

The Stablecoins Ordinance has applied since 1 August 2025. Issuing a covered fiat-referenced stablecoin in Hong Kong, or issuing one outside Hong Kong that purports to maintain value against Hong Kong dollars, requires an HKMA licence. The public register currently lists Anchorpoint Financial Limited and The Hongkong and Shanghai Banking Corporation Limited, both effective from 10 April 2026. Stablecoins Ordinance, Cap. 656, ss. 5, 15 and 21. Japan Crypto-asset exchange services require registration under the Payment Services Act. A new electronic-payment-instrument and crypto-asset service intermediary category took effect on 1 June 2026. That category permits limited mediation on behalf of registered providers. It does not provide a general exchange or custody licence. Payment Services Act, arts. 2, 63-2 and 63-25 to 63-42; Act No. 66 of 2025. Custody A registered crypto-asset exchange provider may ordinarily keep no more than five percent of customer crypto-assets outside cold-storage or an equivalent technical arrangement. The provider must maintain segregated performance-guarantee crypto-assets for the exposed portion and obtain recurring independent audits. Payment Services Act, arts. 63-11 and 63-11-2; Cabinet Office Order on Crypto-Asset Exchange Service Providers, arts. 27–29. South Korea A virtual-asset service provider must complete the applicable KoFIU report before conducting covered business. The Virtual Asset User Protection Act requires bank custody of user deposits, direct bank repayment in specified failure cases, at least 80 percent cold storage under the supervisory rule, insurance or reserves, and controls against unfair trading. Act on the Protection of Virtual Asset Users, arts. 6–12. Korea future law The major-shareholder, financial-condition, internal-control, and expanded report-acceptance rules under Act No. 21358 take effect on 20 August 2026. Token-securities amendments are scheduled for 4 February 2027. Neither set of provisions was operative on 22 July 2026. Transaction Unlicensed core activity, false regulatory claims, a prohibited product, client-asset shortfall, undisclosed key control, unlawful local solicitation, or an unapproved control change should stop closing or require restructuring. Historic exposure normally requires escrow, a specific indemnity, a price adjustment, or seller-retained liability.

Analysis by issue

Regional decision sequence

Asia legal due diligence should begin with five linked maps.

The entity map identifies every issuer, foundation, development company, exchange, custodian, treasury company, validator, market maker, front-end operator, and service company. It records ownership, directors, employees, contractors, domains, bank accounts, wallets, licences, and contracts.

The activity map assigns every service to a named person. Relevant conduct includes issuance, sale, exchange, matching, brokerage, dealing, custody, administration, transfer, staking, lending, advice, portfolio management, validation, payment, token generation, and interface operation.

The product map classifies every digital asset and each stage of its use. The original fundraising instrument, live token, wrapped token, bridge asset, liquidity-pool interest, staking receipt, stablecoin, NFT, tokenised security, and redemption claim can produce different legal results.

The territory map records where services are performed and where users are targeted. Relevant evidence includes residence data, local-language content, payment rails, staff, events, influencers, affiliates, customer support, domains, application stores, and rejected onboarding.

The control map records every power over code or assets. It should cover upgrades, pauses, minting, burning, freezing, blacklisting, fee changes, oracle changes, bridge changes, listings, treasury payments, validator selection, and recovery. It should also identify signers, thresholds, key shares, time locks, hardware custody, and emergency powers.

The reviewer should then compare each management statement with primary evidence. A register entry proves the status recorded on the check date. It does not prove that every live product fits the authorised scope. On-chain data proves transactions and contract states. It does not establish legal title, authority, beneficial ownership, or compliance by itself.

Historic conduct remains material. A current licence does not cure an earlier unlawful offer, unlicensed service, customer-asset deficit, misleading statement, sanctions breach, or data incident.

Comparative perimeter

Jurisdiction Main entry route Material territorial trigger Main custody rule Common DD failure
Singapore Payment Services Act licence; Financial Services and Markets Act licence for specified offshore-only services; Securities and Futures Act permission for capital-markets products Provision or solicitation of covered payment services in Singapore; specified digital-token services provided outside Singapore by Singapore persons Customer assets must enter a trust account or be returned by the next business day; daily computation and customer-level records apply A Singapore group treats an overseas-only business, custodian, or token facilitator as unregulated
Hong Kong SFO Types 1 and 7 for security-token platforms; AMLO VASP licence for non-security-token platforms; HKMA licence for specified stablecoin issuance Operating in Hong Kong or actively marketing to Hong Kong investors; special Hong Kong dollar rule for stablecoins VATP assets are held through an associated entity; trust, segregation, cold-storage, and compensation duties apply An applicant, affiliate, or overseas platform presents itself as licensed
Japan Crypto-asset exchange registration; electronic-payment-instrument registration; restricted intermediary registration; FIEA permissions for securities and derivatives Conduct in Japan and prohibited solicitation by unregistered foreign providers Segregated customer property, at least 95 percent cold or equivalent custody, performance-guarantee assets, and audit A broker relies on the new intermediary category while controlling assets or executing a broader service
South Korea KoFIU VASP report; real-name bank account for covered fiat operations; capital-markets permissions for securities Domestic conduct and foreign conduct directed at or producing effects for Korean users Bank-held user deposits, at least 80 percent cold storage, same-type and same-quantity holdings, insurance or reserves A foreign platform serves Korean users without filing or treats its overseas licence as sufficient

The same product can fall under more than one statute. A stablecoin can engage payments, stored value, securities, banking, custody, AML, and consumer rules. A tokenised investment can engage securities law even when the project calls it a utility token.

Classification gate

Each jurisdiction starts from its own statutory definitions. The reviewer should not apply one country’s classification opinion to another country.

The classification memorandum should test:

  • contractual claims against an issuer;

  • payment and redemption rights;

  • equity, debt, profit, or revenue rights;

  • reserve rights;

  • liquidation rights;

  • pooled investment;

  • discretionary management;

  • transferability;

  • standardisation;

  • secondary-market support;

  • staking or yield rights;

  • minting and supply control;

  • managerial promises;

  • rights represented by an NFT;

  • off-chain property rights;

  • derivative or leveraged exposure.

The reviewer should analyse the original fundraising and current product separately. Later utility does not erase liability arising from the sale. Later decentralisation does not erase conduct by the original issuer or promoter.

Five records should be reconciled:

  1. legal terms;

  2. deployed code;

  3. white papers and sale documents;

  4. public marketing;

  5. actual conduct.

A legal opinion with assumptions that no longer match the deployed product should be treated as expired.

Singapore

Payment Services Act perimeter

A person must not provide a regulated payment service in Singapore without the applicable licence or exemption. The Payment Services Act distinguishes standard payment institutions, major payment institutions, and exempt providers. The licence must cover the digital payment token service actually provided. Payment Services Act 2019, ss. 5–13.

The digital-payment-token definition focuses on a digital representation of value that is not denominated in currency, is not pegged by its issuer to currency, functions or is intended to function as a medium of exchange accepted by the public or part of it, and can be transferred, stored, or traded electronically. Payment Services Act 2019, s. 2.

The regulated service analysis should cover whether the entity:

  • buys or sells tokens as principal;

  • facilitates exchange;

  • operates an order book;

  • transmits tokens;

  • arranges transmission;

  • safeguards tokens or access instruments;

  • controls withdrawals;

  • provides brokerage;

  • accepts tokens for merchants;

  • performs a connected domestic or cross-border transfer service.

The 2024 implementation measures expanded the operative perimeter to specified custody, transmission, and exchange-facilitation conduct even where the provider does not possess the money or token at every stage. A legal opinion based on the older dealing-only model should be refreshed.

The data room should contain:

  • the MAS licence;

  • the approved payment services;

  • licence conditions;

  • exemption instruments;

  • business-plan submissions;

  • current MAS directory evidence;

  • every trading name and domain;

  • customer terms;

  • revenue flows;

  • regulator correspondence.

A major payment institution licence for one group entity does not authorise an affiliate. The reviewer should compare the licensed entity with the entity named in customer terms, invoices, bank transfers, wallet records, privacy notices, and support communications. The official MAS directory is the starting point, not the end of the review. Offshore services directed only outside Singapore

A Singapore structure can remain regulated even when it excludes Singapore customers.

Part 9 of the Financial Services and Markets Act 2022 applies to specified digital-token services provided outside Singapore by:

  • an individual or partnership operating from Singapore;

  • a Singapore corporation operating from Singapore or elsewhere;

  • other persons within the statutory nexus.

“Digital token” includes a digital payment token and a digital representation of a capital-markets product. Covered services include dealing, facilitating exchange, transmission, arranging transmission, and other specified services. Financial Services and Markets Act 2022, ss. 137–167 and First Schedule.

The related regulations took effect on 30 June 2025. They address applications, financial requirements, senior management, and audit. A Singapore entity should not represent that an offshore-only customer base removes MAS jurisdiction. The reviewer should test:

  • where management acts;

  • where staff work;

  • where servers and operational teams sit;

  • where wallets are controlled;

  • where contracts are signed;

  • whether the entity serves only foreign customers;

  • whether a licence or exemption exists;

  • whether an offshore affiliate is the true provider.

A foreign subsidiary can still leave the Singapore parent within scope where the parent performs the service or controls its operation.

Capital-markets products

The Payment Services Act does not displace the Securities and Futures Act.

A token can be a share, debenture, unit in a collective investment scheme, derivative contract, or another capital-markets product. The service can then require a capital-markets services licence, recognised market operator approval, prospectus compliance, or another Securities and Futures Act route. Securities and Futures Act 2001, ss. 2, 82 and 285 and First and Second Schedules.

The classification file should examine:

  • rights to project revenue;

  • repayment obligations;

  • voting rights;

  • liquidation rights;

  • pooled subscription proceeds;

  • discretionary asset management;

  • derivative exposure;

  • tokenised fund units;

  • fractionalised investment rights;

  • secondary trading;

  • promises by an active management team.

An NFT can still represent a capital-markets product. Uniqueness of the token identifier does not change the represented legal right.

The reviewer should also test the operator. A marketplace trading capital-markets products can require market-operator approval even when the software uses distributed-ledger technology.

Stable-value tokens

An issuer-pegged currency token does not automatically fit Singapore’s digital-payment-token definition. The reviewer must test whether it constitutes:

  • electronic money;

  • an account-issuance service;

  • a domestic or cross-border money-transfer service;

  • a capital-markets product;

  • a deposit;

  • a debt claim;

  • a trust interest;

  • another regulated payment arrangement.

The file should identify:

  • the reference currency;

  • the legal issuer;

  • the holder’s claim;

  • reserve ownership;

  • redemption rights;

  • permitted reserve assets;

  • bank and custodian arrangements;

  • mint and burn powers;

  • insolvency treatment;

  • marketing concerning value stability.

A project should not rely solely on the phrase “MAS-regulated stablecoin.” The reviewer must identify the exact entity, licence, service, product treatment, and any product-specific MAS communication.

Customer assets and custody

Singapore imposes detailed customer-asset duties on a licensee providing digital-payment-token services.

No later than the next business day after receiving customer assets, the licensee must deposit them into a qualifying trust account or return them. The account must be separately designated. Assets in the account cannot pay the licensee’s debts or be taken under ordinary enforcement against the licensee. Payment Services Regulations 2019, reg. 18B. A licensee must treat customer assets as customer property. It must restrict transfers, disclose permitted commingling, maintain separate customer-level book entries, assess safeguarding persons, obtain lien restrictions, and disclose insolvency consequences. Payment Services Regulations 2019, regs. 18C–18G.

The licensee must complete a customer-asset computation by the end of every business day. It must retain supporting records for at least five years. Payment Services Regulations 2019, reg. 18H.

The DD review should obtain:

  • all trust instruments;

  • wallet and account designations;

  • safeguarding-person contracts;

  • lien and set-off acknowledgements;

  • client ledgers;

  • daily computations;

  • on-chain reconciliations;

  • fiat reconciliations;

  • sub-custody arrangements;

  • borrowing and lending records;

  • staking records;

  • insolvency disclosures;

  • audit reports;

  • shortfall and incident files.

The rules allow limited customer-authorised transfers and some commingling. The reviewer should not convert the trust requirement into a claim that every asset sits in an individually segregated wallet.

“Non-custodial” should be verified through technical evidence. A person can exercise custody or material control through key shares, transaction approval, recovery powers, withdrawal whitelists, relayers, or admin contracts.

Financial crime controls

A DPT licensee must comply with the current MAS AML and counter-terrorist-financing notice and related guidance. The operating review should test:

  • customer and beneficial-owner identification;

  • sanctions and politically exposed person screening;

  • source of funds;

  • source of wealth;

  • transaction monitoring;

  • blockchain analytics;

  • originator and beneficiary information;

  • self-hosted wallets;

  • suspicious-transaction reporting;

  • record retention;

  • correspondent and counterparty controls;

  • independent testing.

The review should sample actual files. A policy states intended conduct. It does not prove that onboarding, monitoring, escalation, and reporting occurred.

The Travel Rule review should reconcile transmitted data with blockchain transactions. It should also identify rejected transfers, missing data, manual overrides, and counterparty VASP assessments.

Controllers, officers, and transactions

The Payment Services Act defines 5 percent, 12 percent, and 20 percent controller categories. A person must obtain prior MAS approval before becoming a 20 percent controller of a Singapore-incorporated licensee. MAS may object to an existing controller where statutory grounds arise. Payment Services Act 2019, ss. 27–33. MAS also requires approval for specified chief executives, directors, and partners. Payment Services Act 2019, ss. 34–36.

The transaction review should cover:

  • direct shares;

  • indirect shares;

  • associates;

  • voting agreements;

  • options and convertibles;

  • board appointment rights;

  • veto rights;

  • policy influence;

  • acting-in-concert arrangements;

  • token-based control;

  • key and treasury control.

A buyer can become an indirect controller through contractual influence without holding 20 percent of the equity.

The acquisition agreement should include:

  • a MAS approval condition;

  • filing cooperation;

  • access to regulator communications;

  • restrictions on pre-closing control;

  • acceptable conditions;

  • a long-stop date;

  • termination rights;

  • treatment of licence variation;

  • post-closing officer approvals.

The parties should also assess whether new services require licence variation and whether the transaction changes the business plan previously supplied to MAS.

Singapore findings

The project should receive a stop or restructuring finding where:

  • a DPT service operates without the correct Payment Services Act licence;

  • a Singapore entity provides offshore-only services without addressing Part 9 of the Financial Services and Markets Act;

  • a security token is treated only as a DPT;

  • the customer contracting entity differs from the licensed entity;

  • customer assets do not enter the required trust arrangement;

  • daily computations or customer ledgers are absent;

  • an unapproved person has become a 20 percent or indirect controller;

  • the group makes false or incomplete MAS status claims.

Hong Kong

VATP licensing and active marketing

A centralised virtual-asset trading platform carrying on business in Hong Kong, or actively marketing to Hong Kong investors, requires SFC authority.

The SFO route applies where the platform provides trading in security tokens through an automated matching engine and provides ancillary custody. The expected permissions are Type 1 regulated activity and Type 7 regulated activity.

The AMLO route applies where the platform provides trading in non-security tokens through an automated matching engine and provides ancillary custody.

The SFC recommends applications under both routes because a token’s classification can change. The territorial review should examine:

  • Hong Kong customers;

  • Hong Kong Chinese or English marketing directed locally;

  • local events;

  • local influencers;

  • Hong Kong dollar rails;

  • local support;

  • affiliates and introducers;

  • application-store availability;

  • domain and search advertising;

  • account-opening flows.

A clause excluding Hong Kong carries little weight when the platform accepts Hong Kong identity documents, addresses, payments, and support requests.

The active-marketing test can reach an overseas platform. An offshore incorporation or foreign licence does not create a Hong Kong exemption.

Scope and entity verification

The SFC register should be checked by exact legal name. The reviewer should then obtain the licence instruments, conditions, responsible-officer approvals, associated-entity records, and regulator correspondence.

An applicant or deemed applicant is not the same as a fully licensed platform. The project should state its status exactly. Public statements should not omit limitations, pending conditions, or restricted client categories.

The entity named in the register should match:

  • customer terms;

  • account-opening screens;

  • trade confirmations;

  • wallet agreements;

  • bank details;

  • privacy notices;

  • invoices;

  • complaints channels;

  • marketing;

  • support communications.

A licensed parent does not authorise an unlicensed operating subsidiary. A licensed subsidiary does not protect an offshore parent that contracts with users or controls their assets.

The review should also identify activities outside the platform licence:

  • OTC dealing;

  • proprietary trading;

  • advisory services;

  • asset management;

  • lending;

  • derivatives;

  • staking;

  • stablecoin issuance;

  • stablecoin offering;

  • market making.

Each activity requires a separate legal and licence analysis.

Custody and associated entity

The VATP custody model uses an associated entity.

The associated entity should be a Hong Kong-incorporated, wholly owned entity with the required trust or company-service-provider status. It should hold client virtual assets on trust and conduct no unrelated business that conflicts with its custody role.

Client assets should be segregated through designated wallet addresses. The associated entity should not lend, pledge, rehypothecate, or otherwise use them outside the permitted rules. Guidelines for Virtual Asset Trading Platform Operators, paras. 10.1–10.8. The guidelines generally require at least 98 percent of client virtual assets to remain in cold storage, subject to the SFC’s accepted arrangements. Key generation, storage, use, backup, recovery, and destruction require documented controls. Guidelines for Virtual Asset Trading Platform Operators, paras. 10.6–10.21. The compensation arrangement should cover at least 50 percent of client assets held in cold storage and 100 percent held in hot and other storage, unless current licence conditions or later SFC requirements state otherwise. Guidelines for Virtual Asset Trading Platform Operators, para. 10.22. The reviewer should obtain:

  • associated-entity corporate records;

  • trust documents;

  • TCSP status;

  • wallet inventory;

  • cold and hot allocation reports;

  • key ceremonies;

  • signer and MPC records;

  • insurance, bank guarantee, or compensation arrangements;

  • customer ledgers;

  • reconciliations;

  • shortfall reports;

  • incident records;

  • audit and external assessment reports.

The legal opinion should address beneficial ownership, trust status, tracing, shortfalls, sub-custody, and insolvency.

Staking

A licensed VATP cannot add staking through an ordinary product update. It needs prior written SFC approval and specific licence conditions.

The VATP must retain possession or control of every medium needed to withdraw the staked assets. Third-party custody of client virtual assets is not permitted under the SFC staking conditions. The platform must disclose fees, lock-up periods, unstaking procedures, outages, custody arrangements, loss allocation, and material risks. It must also review and monitor validators and other service providers. The review should inspect:

  • the SFC approval;

  • modified licence conditions;

  • eligible assets;

  • customer consent;

  • withdrawal-key control;

  • validator contracts;

  • delegation records;

  • lock-up periods;

  • unstaking performance;

  • slashing events;

  • reward calculations;

  • commissions;

  • outage and fork treatment;

  • customer disclosures.

A platform should not pool or route assets through an arrangement that transfers custody to an unapproved third party.

A liquid-staking receipt needs its own classification. It can create a new virtual asset, security, collective-investment interest, debt claim, or derivative exposure.

New products and services

Hong Kong has allowed selected licensed platforms and intermediaries to pursue staking, shared liquidity, affiliated market making, tokenisation, specified stablecoin services, and other products through dedicated circulars, licence conditions, or approvals.

These measures do not create a general right to add the service. The project should produce the exact approval, condition, circular analysis, board approval, and operating procedures for each product.

The due-diligence team should distinguish binding legislation from:

  • SFC circulars;

  • licence conditions;

  • consultation conclusions;

  • policy announcements;

  • sandbox participation;

  • pending applications.

Proposals concerning direct regulation of OTC dealers, stand-alone custodians, advisers, and managers were not treated as enacted licensing statutes on the As-of Date. A transaction expected to close later should monitor the legislative process.

Stablecoins

The Stablecoins Ordinance took effect on 1 August 2025.

A licence is required where a person, in the course of business:

  • issues a specified fiat-referenced stablecoin in Hong Kong; or

  • issues a specified stablecoin outside Hong Kong that purports to maintain stable value by reference to Hong Kong dollars.

Stablecoins Ordinance, Cap. 656, ss. 5 and 15. Licensed issuers face duties concerning:

  • reserve assets;

  • segregation;

  • stabilisation;

  • par redemption;

  • risk management;

  • AML;

  • disclosures;

  • audit;

  • fitness and propriety.

Only specified licensed institutions may offer a covered fiat-referenced stablecoin in Hong Kong. Only a stablecoin issued by a licensed issuer may be offered to retail investors. Advertising restrictions apply to unlicensed issuance. The register listed two licensees as at the research date. Both licences took effect on 10 April 2026. The register entry proves issuer licensing. It does not establish that every token bearing a similar name or ticker was issued by either licensee. The HKMA confirmed on 28 April 2026 that the two licensees had not then issued regulated stablecoins into the market. The stablecoin DD file should contain:

  • the issuer licence;

  • approved business plan;

  • stablecoin terms;

  • reserve policy;

  • reserve-bank and custodian contracts;

  • supply records;

  • reserve balances;

  • reconciliations;

  • independent attestations;

  • redemption logs;

  • complaints;

  • marketing approvals;

  • offeror status;

  • wallet and smart-contract controls.

An exchange or VATP licence does not authorise stablecoin issuance.

Controllers and acquisitions

A proposed substantial shareholder or controller of a licensed corporation, licensed VATP, or licensed VASP can require prior SFC approval under the SFO or AMLO route. Securities and Futures Ordinance, s. 132; Anti-Money Laundering and Counter-Terrorist Financing Ordinance, s. 53ZRQ.

The review should include:

  • direct and indirect equity;

  • voting rights;

  • associates;

  • nominee holdings;

  • options;

  • convertibles;

  • board rights;

  • vetoes;

  • management agreements;

  • token votes;

  • treasury control;

  • key control.

The transaction should not deliver effective control before regulatory approval. Pre-closing integration, wallet authority, management instructions, or extensive vetoes can create that risk.

The acquisition agreement should contain a separate condition for each SFC and HKMA approval. Stablecoin issuer ownership changes can require HKMA engagement in addition to SFC approvals held by group entities.

Hong Kong findings

Stop or restructure findings include:

  • active Hong Kong marketing by an unlicensed platform;

  • reliance on applicant or deemed-applicant status;

  • a licensed entity that does not contract with users;

  • operation outside Types 1 and 7 or AMLO scope;

  • third-party custody contrary to platform or staking conditions;

  • failure to maintain the associated-entity structure;

  • customer-asset shortfalls;

  • unsupported cold-storage or compensation claims;

  • staking without prior written approval;

  • unlicensed stablecoin issuance or retail offering;

  • missing substantial-shareholder approval;

  • false SFC or HKMA statements.

Japan

Crypto-asset exchange registration

Japan requires registration for crypto-asset exchange services. The Payment Services Act covers specified purchase, sale, exchange, intermediary, agency, custody, and management activities. Payment Services Act, arts. 2 and 63-2.

The FSA’s current public materials state that a person conducting exchange between crypto-assets and fiat currency in Japan must register. The FSA maintains lists of registered crypto-asset exchange providers, electronic-payment-instrument service providers, and relevant intermediaries. The reviewer should obtain:

  • the registration entry;

  • filed business categories;

  • handled crypto-assets;

  • approved trade names;

  • customer terms;

  • domestic office and representative records;

  • association membership;

  • regulator inspection and administrative-action records;

  • change notifications;

  • outsourcing records.

A foreign crypto-asset exchange provider cannot solicit customers in Japan without the required Japanese registration. Payment Services Act, art. 63-22.

The territorial review should cover:

  • Japanese-language sites;

  • Japan-focused social accounts;

  • local affiliates;

  • Japanese customer support;

  • yen payment rails;

  • events;

  • local influencers;

  • acceptance of Japanese identity and address documents;

  • application-store access.

A website disclaimer should be compared with actual onboarding and payment conduct.

New intermediary category

Act No. 66 of 2025 created a new electronic-payment-instrument and crypto-asset service intermediary category. The operative provisions and Cabinet Office Order took effect on 1 June 2026. The category permits a registered intermediary, acting under appointment by a registered provider, to conduct only specified mediation:

  • mediation of the purchase, sale, or exchange of electronic payment instruments;

  • mediation of the purchase, sale, or exchange of crypto-assets.

It does not provide a general right to:

  • hold customer money;

  • hold customer crypto-assets;

  • operate a trading venue;

  • deal as principal;

  • execute an unrestricted transfer service;

  • issue stablecoins;

  • manage customer portfolios.

The intermediary file should contain:

  • intermediary registration;

  • each appointing registered provider;

  • agency or appointment agreements;

  • allocated responsibilities;

  • customer disclosures;

  • complaint handling;

  • data exchange;

  • fee arrangements;

  • termination rights;

  • confirmation that the intermediary never controls customer assets.

A platform that controls wallets, executes trades on its own account, or operates the matching system should not rely on intermediary status alone.

Electronic payment instruments and stablecoins

Japan separates crypto-assets from electronic payment instruments.

Fiat-linked stablecoins can fall within the electronic-payment-instrument category. Conduct involving their sale, exchange, brokerage, management, or transfer can require electronic-payment-instrument service-provider registration. Payment Services Act, arts. 2 and 62-3.

The issuer must also have an eligible issuance basis. Depending on the design, the issuer can fall under banking, fund-transfer, trust, or related statutes.

The review should determine:

  • the legal issuer;

  • the holder’s claim;

  • the reference currency;

  • redemption rights;

  • reserve or trust assets;

  • issuer eligibility;

  • transfer restrictions;

  • intermediary status;

  • customer-asset treatment;

  • foreign-issued token treatment;

  • AML and Travel Rule duties.

From 1 June 2026, specified trust-beneficiary stablecoin structures may use certain government bonds and cancellable time deposits within the statutory and subordinate limits. The project should verify the exact trust terms, eligible assets, concentration limits, liquidity, and principal-protection conditions. A product called a stablecoin can instead be a crypto-asset, security, prepaid instrument, deposit claim, or unregulated contractual right. The result depends on its legal terms.

Securities, collective investments, and derivatives

The Financial Instruments and Exchange Act applies where a token represents a security or financial instrument.

Electronically recorded transferable rights can include tokenised collective-investment interests and other securities. Crypto-asset derivatives also fall within the financial-instruments regime. Financial Instruments and Exchange Act, arts. 2 and 29.

The review should test:

  • shares and debt;

  • collective-investment interests;

  • profit participation;

  • trust beneficiary interests;

  • fund rights;

  • derivatives;

  • leverage;

  • tokenised receivables;

  • fractionalised investment assets;

  • secondary trading.

The issuer, broker, placement agent, exchange, custodian, and adviser may need different permissions.

A crypto-asset exchange registration does not authorise financial-instruments business.

Customer assets and custody

A registered crypto-asset exchange provider must segregate customer money and crypto-assets. It must maintain records identifying each customer’s entitlement. Payment Services Act, art. 63-11.

The current Cabinet Office Order permits no more than five percent of customer crypto-assets, measured by value, to remain outside cold-storage or an equivalent technical arrangement. The provider must manage the remainder through offline or equivalent safeguards. Cabinet Office Order on Crypto-Asset Exchange Service Providers, art. 27. A provider must undergo an independent segregated-management audit at least annually. Cabinet Office Order, art. 28.

For the portion exposed outside cold storage, the provider must hold corresponding performance-guarantee crypto-assets. Those assets require separate identification and cold or equivalent custody. Payment Services Act, art. 63-11-2; Cabinet Office Order, art. 29.

The reviewer should obtain:

  • cold, hot, and warm wallet inventories;

  • valuation methodology;

  • daily percentage calculations;

  • customer ledgers;

  • performance-guarantee wallet records;

  • key management;

  • audit reports;

  • customer fiat trust records;

  • sub-custody agreements;

  • incident reports;

  • reconciliation files;

  • proof of restoration after losses.

The 95 percent requirement is a minimum operating safeguard. It does not answer legal title, tracing, shortfall allocation, or foreign sub-custodian insolvency. Japanese insolvency counsel should address those questions.

AML and Travel Rule

Registered providers fall under the Act on Prevention of Transfer of Criminal Proceeds and related rules.

The DD review should test:

  • customer and beneficial-owner identification;

  • transaction purpose;

  • sanctions and PEP screening;

  • suspicious-transaction reporting;

  • originator and beneficiary information;

  • counterparty VASP identification;

  • self-hosted-wallet controls;

  • high-risk jurisdiction rules;

  • record retention;

  • vendor and association controls.

Japan currently limits parts of its foreign Travel Rule operation by reference to designated jurisdictions with equivalent requirements.

The FSA finalised an amendment on 7 July 2026 adding five jurisdictions. That amendment takes effect on 3 August 2026. It was future-effective on the As-of Date and should not be treated as current law. A transaction closing after that date should require implementation evidence. Corporate changes, business transfers, and closure

The Payment Services Act requires specified registration changes and notices when the provider changes its business, organisation, trade name, officers, or other registered matters. Payment Services Act, art. 63-6.

Business transfer, merger, company split, discontinuance, and dissolution can trigger notices, public announcements, customer protection, and return-of-property duties. Payment Services Act, arts. 63-20 and 63-21.

Japan should not be treated as having one generic crypto change-of-control approval identical to Singapore or Hong Kong. The transaction team must analyse:

  • changes to registered information;

  • continued satisfaction of registration criteria;

  • business transfer;

  • merger or company split;

  • change of domestic representative;

  • new outsourcing;

  • new handled assets;

  • custody migration;

  • customer consent and notice;

  • return of customer assets.

The acquisition agreement should require FSA and local-finance-bureau confirmation where the transaction structure creates doubt.

Japan findings

Stop or restructure findings include:

  • unregistered exchange or custody activity;

  • a foreign provider soliciting Japan without registration;

  • intermediary status used for principal dealing or custody;

  • an electronic-payment-instrument service treated as ordinary crypto brokerage;

  • a security token handled only under the Payment Services Act;

  • less than the required cold-storage amount;

  • missing performance-guarantee crypto-assets;

  • incomplete segregated-management audits;

  • unreported business transfers or material registration changes;

  • false FSA registration claims.

South Korea

VASP reporting and local market access

A person conducting covered virtual-asset business must report to the Korea Financial Intelligence Unit before operating. Act on Reporting and Using Specified Financial Transaction Information, art. 7.

Covered conduct includes specified trading, exchange, transfer, custody, administration, brokerage, and intermediation activities.

A VASP conducting won-to-crypto or crypto-to-won business generally needs a qualifying real-name bank-account arrangement. The report also requires the applicable Information Security Management System certification and other statutory conditions.

The reviewer should obtain:

  • current KoFIU report-acceptance evidence;

  • report scope;

  • change reports;

  • renewal records;

  • real-name bank-account contract;

  • ISMS certification;

  • AML inspection reports;

  • current official VASP-list entry;

  • sanctions or business restrictions;

  • business-closure records.

A corporate registration, exchange membership, bank account, or ISMS certificate does not replace the KoFIU report.

Foreign providers

The Korean statute applies to a foreign VASP conducting business directed at Korea. The official indicators include:

  • a Korean-language website;

  • marketing to Korean customers;

  • Korean-user acquisition campaigns;

  • support for won payments.

Act on Reporting and Using Specified Financial Transaction Information, ss. 6(2) and 7. The authority requested blocking of applications and websites used by unreported foreign providers. It can also refer unreported activity for criminal investigation. The project should preserve evidence of any Korean exclusion:

  • blocked Korean IP addresses;

  • rejected Korean identity documents;

  • no Korean-language acquisition content;

  • no won rails;

  • no Korean affiliates;

  • no local events or influencers;

  • exception logs;

  • closed Korean accounts;

  • withdrawal and asset-return records.

Passive internet availability and active Korean business require different analysis. Actual conduct decides the result.

User deposits

The Virtual Asset User Protection Act requires a VASP to place user deposits with a qualifying custodian institution. The implementing decree designates banks.

The VASP and bank must keep the deposits separate from their own property. The bank may invest the deposits only through the permitted safe-asset arrangements. In specified insolvency, cancellation, or business-failure cases, the bank pays users directly after completing the statutory process. Act on the Protection of Virtual Asset Users, art. 6; Enforcement Decree, arts. 8–10. The review should obtain:

  • the bank contract;

  • account designations;

  • customer-level deposit records;

  • reconciliations;

  • interest or usage-fee calculations;

  • bank confirmations;

  • insolvency payment procedures;

  • shortfall reports;

  • regulator notifications.

A general bank account in the VASP’s name does not establish statutory custody.

User virtual assets

A VASP must keep user virtual assets separate from its own assets. It must maintain the same type and quantity owed to users and keep accurate records. Act on the Protection of Virtual Asset Users, art. 7.

The implementing rules require at least 80 percent of the value of user virtual assets to remain disconnected from the internet. The decree establishes a statutory floor of 70 percent and authorises the FSC to set the operative percentage. The supervisory rule sets 80 percent. A provider must obtain insurance or maintain reserves for liability arising from hacking, computer failures, and related incidents. Act on the Protection of Virtual Asset Users, art. 8.

The reviewer should inspect:

  • wallet inventories;

  • cold-storage calculations;

  • monthly valuation inputs;

  • customer ledgers;

  • on-chain reconciliations;

  • insurance;

  • reserves;

  • loss events;

  • security incidents;

  • asset-restoration records;

  • third-party custody;

  • withdrawal controls.

The Korean 80 percent test uses economic value. The calculation method and valuation date should be verified.

AML operating restrictions

The current Enforcement Decree of the Specified Financial Information Act requires a VASP to:

  • keep customer transaction histories separately;

  • segregate customer deposits;

  • restrict transactions until customer verification is complete;

  • avoid business transactions with an unreported VASP;

  • maintain restrictions concerning self-issued assets;

  • restrict specified employee and related-party trading;

  • restrict transactions where the VASP becomes the effective counterparty while acting as intermediary.

Enforcement Decree of the Act on Reporting and Using Specified Financial Transaction Information, art. 10-20. The monitoring review should test actual alerts and blocks. It should not rely only on written policies.

The due-diligence sample should include:

  • customer files;

  • beneficial-owner records;

  • sanctions checks;

  • source-of-funds reviews;

  • suspicious-transaction files;

  • wallet screening;

  • counterparty VASP checks;

  • blocked transfers;

  • employee accounts;

  • proprietary trading;

  • self-issued tokens;

  • Travel Rule data;

  • override logs.

Market conduct

The Virtual Asset User Protection Act prohibits:

  • use of material non-public information;

  • price manipulation;

  • fraudulent trading;

  • specified dealing in assets issued by the VASP or related persons;

  • other unfair conduct defined by the Act and subordinate rules.

Act on the Protection of Virtual Asset Users, art. 10.

Virtual-asset exchanges must monitor abnormal trading continuously. Suspected unfair trading must be reported to the financial authorities without delay. Act on the Protection of Virtual Asset Users, art. 12. The review should cover:

  • listing decisions;

  • insider access;

  • token unlocks;

  • issuer communications;

  • treasury transactions;

  • employee accounts;

  • market-maker arrangements;

  • wash-trading controls;

  • abnormal-trading alerts;

  • regulator reports;

  • delisting decisions;

  • related-party issued assets.

A market-maker agreement should not direct artificial volume, wash trading, spoofing, or undisclosed price support.

Token classification

The Virtual Asset User Protection Act excludes specified products governed elsewhere. The exclusions include certain electronic registered securities, electronic money, prepaid payment instruments, game assets, central-bank digital currency, and qualifying NFTs.

The NFT exclusion is narrow. The implementing rules focus on tokens that exist uniquely, are not replaceable by another electronic token, and serve a collection or transaction-confirmation function. A large interchangeable series, fractionalisation, common pricing, or investment use can move the product back into virtual-asset or securities analysis. What constitutes a security remains subject to the Financial Investment Services and Capital Markets Act. The use of a distributed ledger does not change its substantive securities status.

The review should test:

  • investment-contract rights;

  • fractional interests;

  • profit sharing;

  • revenue sharing;

  • debt;

  • trust interests;

  • fund interests;

  • redemption;

  • active management;

  • secondary trading;

  • platform promises.

Stablecoins and future legislation

No enacted general Korean stablecoin licensing statute was identified as operative on 22 July 2026. Stablecoins remain subject to the existing virtual-asset, AML, payment, banking, foreign-exchange, and securities statutes according to their design.

Policy work on a second-stage digital-asset statute and stablecoin rules remained under development. A project should not treat a proposal, policy statement, or committee paper as current authorisation.

Act No. 21358 amends the Specified Financial Information Act from 20 August 2026. It introduces a “major shareholder” category covering:

  • the largest shareholder;

  • a person holding at least 10 percent;

  • a shareholder exercising prescribed factual influence over major management matters.

It also expands report scrutiny concerning major shareholders, financial condition, social credit, personnel, systems, and internal controls. KoFIU will gain express authority to impose conditions when accepting a report. A transaction signing before 20 August 2026 but closing later should treat those requirements as a closing-planning issue. The target should prepare ownership, fitness, financial, technology, and control records before the effective date.

Korean token-securities amendments are scheduled to take effect on 4 February 2027. They will establish a statutory distributed-ledger route under the Electronic Securities Act. Token securities remain securities in substance before that date. Controllers and transactions

Under the law operative on the As-of Date, a VASP must update or refile specified report information when registered facts change. The transaction team should identify changes to:

  • legal entity;

  • representative;

  • officers;

  • ownership;

  • business address;

  • services;

  • real-name bank arrangements;

  • ISMS status;

  • custody;

  • outsourcing;

  • token handling.

The future 20 August 2026 rules make shareholder identity and influence more material. A purchase agreement expected to close after that date should include:

  • KoFIU acceptance or confirmation;

  • major-shareholder information;

  • fitness and criminal-record materials;

  • financial-condition evidence;

  • internal-control evidence;

  • technology and staffing evidence;

  • a long-stop date;

  • termination rights for unacceptable conditions;

  • pre-closing control restrictions.

The buyer should not exercise management or wallet control before closing.

South Korea findings

Stop or restructure findings include:

  • unreported VASP activity;

  • a foreign provider actively serving Korean users without reporting;

  • missing real-name bank arrangements for covered fiat business;

  • missing or expired ISMS certification;

  • user deposits outside the required bank arrangement;

  • less than the required cold-storage percentage;

  • failure to hold the same type and quantity owed to users;

  • inadequate insurance or reserves;

  • trading with unreported counterparties;

  • self-issued or employee trading contrary to the rules;

  • failure to monitor or report abnormal trading;

  • a security token treated as an ordinary virtual asset;

  • false KoFIU or FSC status claims.

Cross-border group structures

A common Asia structure separates the issuer, exchange, custodian, software company, treasury company, and local regulated entity. That design works only when the allocation is genuine.

The reviewer should trace:

  • who contracts with users;

  • who receives fees;

  • who controls wallets;

  • who operates matching;

  • who performs customer checks;

  • who sends Travel Rule data;

  • who controls listings;

  • who employs operations staff;

  • who manages incidents;

  • who owns customer data;

  • who bears customer liability.

A regulated local company should not function as a paper contracting entity while an offshore affiliate performs the regulated service.

Intercompany agreements should address:

  • exact service scope;

  • intellectual property;

  • personnel;

  • data;

  • regulated responsibility;

  • service levels;

  • audit rights;

  • regulator access;

  • incident reporting;

  • fees;

  • termination;

  • migration;

  • liability.

The agreements must match actual conduct. A written allocation carries little weight when offshore employees control every production key, listing decision, customer withdrawal, and incident response.

DeFi, software, and DAO claims

A protocol can be technically decentralised while material services remain centralised.

The DD review should identify who:

  • deploys contracts;

  • controls upgrades;

  • operates the main interface;

  • selects pools;

  • routes transactions;

  • lists tokens;

  • sets fees;

  • controls oracles;

  • operates relayers;

  • holds recovery powers;

  • receives protocol fees;

  • markets the product;

  • provides customer support;

  • can block users.

A software company can fall within a licensing perimeter where it facilitates exchange, controls assets, transmits tokens, operates matching, brokers transactions, or actively solicits users.

An open-source licence does not decide financial regulation. It also does not prove ownership of the code.

A DAO wrapper can own assets and allocate voting rights. It does not remove licensing, custody, AML, sanctions, tax, employment, or offering duties.

The reviewer should analyse token concentration, delegation, quorum, emergency powers, multisigs, foundation councils, and off-chain influence. A nominal community vote does not remove control retained by founders or service providers.

Custody and insolvency comparison

Jurisdiction Operational minimum Legal DD focus
Singapore Trust placement or return by next business day; customer-level records; daily asset computation Trust validity, safeguarding person, liens, commingling, sub-custody, customer-authorised transfers, insolvency
Hong Kong Associated entity, trust holding, segregated wallets, generally 98 percent cold storage, compensation arrangement Associated-entity status, beneficial ownership, third-party control, staking withdrawal keys, shortfall
Japan Segregated custody, no more than five percent outside cold or equivalent storage, performance-guarantee assets, annual audit Customer property, fiat trust, valuation, guarantee assets, foreign custody, insolvency
South Korea Bank-held deposits, direct bank payment in specified failure cases, at least 80 percent cold storage, same type and quantity Bank contract, valuation, wallet reconciliation, insurance or reserves, third-party failure

These percentages measure different things. They should not be used as a simple ranking of customer protection.

A complete custody opinion should answer:

  1. Who has legal title?

  2. Who can cause a transfer?

  3. Are assets segregated in law, systems, wallets, and accounts?

  4. Who bears a shortfall?

  5. What happens on insolvency?

  6. Who receives forks, airdrops, voting rights, and staking rewards?

  7. Can the provider lend, pledge, or reuse assets?

  8. Which court and law govern the customer’s claim?

The reviewer should map every private key, key share, recovery key, admin key, withdrawal policy, and emergency process.

Staking and yield products

Hong Kong applies an express prior-approval route for licensed VATPs. The other three jurisdictions require a function-by-function analysis.

Staking can include:

  • custody;

  • transfer;

  • brokerage;

  • asset management;

  • lending;

  • issuance of a receipt token;

  • collective investment;

  • a derivative;

  • a payment or reward service.

The review should determine:

  • whether title transfers;

  • whether assets are pooled;

  • who selects validators;

  • who controls withdrawal;

  • lock-up periods;

  • slashing allocation;

  • reward currency;

  • reward calculation;

  • commissions;

  • sub-staking;

  • customer disclosures;

  • insolvency treatment.

A fixed return funded by the provider presents a different legal issue from protocol rewards passed through after deduction of a stated fee.

AML, sanctions, data, and technology

All four jurisdictions require operating controls against money laundering and terrorist financing for covered providers. The legal file should contain evidence of actual use.

The review should sample:

  • customer identification;

  • beneficial-owner records;

  • sanctions screening;

  • PEP screening;

  • source of funds;

  • source of wealth;

  • blockchain analytics;

  • Travel Rule data;

  • self-hosted-wallet checks;

  • high-risk counterparties;

  • suspicious reports;

  • escalation files;

  • blocked transfers;

  • independent reviews.

Sanctions analysis remains separate from AML registration. The reviewer should identify who can reject, freeze, pause, block, or restrict a transaction.

Data review should cover:

  • Singapore’s Personal Data Protection Act 2012;

  • Hong Kong’s Personal Data (Privacy) Ordinance, Cap. 486;

  • Japan’s Act on the Protection of Personal Information;

  • South Korea’s Personal Information Protection Act.

Wallet addresses, device identifiers, identity records, IP addresses, transaction data, support records, and risk scores can constitute personal data when linked to a person.

The project should map:

  • controllers and processors;

  • collection purposes;

  • notices and consent;

  • security;

  • retention;

  • direct marketing;

  • automated decisions;

  • international transfers;

  • incident reporting;

  • customer rights.

The technology file should include:

  • architecture diagrams;

  • repositories;

  • deployment records;

  • bytecode verification;

  • smart-contract audits;

  • wallet design;

  • key ceremonies;

  • penetration tests;

  • incident reports;

  • recovery tests;

  • cloud contracts;

  • oracle and bridge dependencies;

  • vendor exit plans.

A technical audit covering an old contract does not support the current deployment.

Regulatory status verification

A reliable licence check should follow these steps:

  1. Search the official register by exact legal name.

  2. Search former names, brands, and affiliates.

  3. Obtain the licence or registration instrument.

  4. Identify every approved activity and product.

  5. Identify restrictions, client classes, and conditions.

  6. Compare the permission with customer terms and operations.

  7. Review regulator correspondence.

  8. Check warnings, suspensions, and administrative action.

  9. Repeat the check before signing and closing.

Special caution applies to:

  • Singapore exemptions and offshore-only entities;

  • Hong Kong applicants, deemed applicants, and sandbox participants;

  • Japan intermediaries that exceed their narrow role;

  • Korean foreign providers and pending reports;

  • stablecoin issuers whose name is copied by unrelated token promoters.

The acquisition agreement should attach a schedule of each permission, service, condition, product, and pending filing.

Red flags and transaction treatment

Stop or restructure

These findings normally require suspension, abandonment, or restructuring before closing:

  • unlicensed exchange, brokerage, custody, transfer, or payment activity;

  • foreign market access contrary to local law;

  • a capital-markets product treated only as a virtual asset;

  • an issuer-pegged token placed in the wrong statutory category;

  • false licence, applicant, or regulator statements;

  • a licensed entity that does not perform the live service;

  • customer-asset commingling or a material shortfall;

  • missing trust, bank, associated-entity, or guarantee arrangements;

  • insufficient cold storage;

  • unapproved third-party custody;

  • staking outside the permitted route;

  • undisclosed admin, minting, withdrawal, or treasury powers;

  • missing ownership of core code, domains, or wallets;

  • an unapproved controller or substantial shareholder;

  • unresolved AML, sanctions, market-abuse, or data violations.

Conditions precedent

An objective cure can support a condition precedent:

  • receipt of a licence or registration;

  • licence variation;

  • controller or shareholder approval;

  • completion of a KoFIU report;

  • receipt of an SFC staking approval;

  • migration to a qualifying custodian;

  • establishment of a trust or bank arrangement;

  • restoration of the required cold-storage ratio;

  • acquisition of insurance or compensation cover;

  • funding of performance-guarantee assets;

  • customer re-papering;

  • intellectual-property assignment;

  • key rotation;

  • regulator confirmation;

  • correction of public regulatory claims;

  • AML or technology remediation.

The condition should state the evidence needed for satisfaction.

Price, escrow, and indemnity

Operational repair does not erase historic liability.

Price protection, escrow, holdback, or specific indemnity may be required for:

  • historic unlicensed service;

  • unlawful marketing;

  • token-sale claims;

  • customer-asset losses;

  • trust or custody defects;

  • AML failures;

  • sanctions breaches;

  • unfair trading;

  • reserve deficiencies;

  • data breaches;

  • tax;

  • employment;

  • intellectual-property defects;

  • regulator investigations.

The clause should define the covered period, claimant group, loss measure, limitation period, claim control, and security.

Monitored remediation

Lower-severity matters should remain open only where the agreement states:

  • the exact task;

  • the responsible person;

  • the deadline;

  • the required evidence;

  • reporting frequency;

  • inspection rights;

  • consequences of non-completion.

A general promise to improve compliance is not an adequate remedy.

Priority evidence request

Corporate and ownership

Current group chart.
Formation and good-standing records.
Shareholder and beneficial-owner registers.
Cap table, options, warrants, convertibles, and side letters.
Board and shareholder records.
Foundation, trust, and DAO documents.
Intercompany agreements.

Regulatory status

  • MAS licences and exemptions.

  • SFC and HKMA licences.

  • Japanese registrations.

  • KoFIU report-acceptance records.

  • Approved services and products.

  • Licence conditions.

  • Regulator correspondence.

  • Public-register extracts.

  • Inspection and enforcement records.

  • Controller and shareholder filings.

Tokens and products

  • Current and historic white papers.

  • Sale agreements.

  • Classification opinions.

  • Token-holder rights.

  • Contract addresses.

  • Mint, burn, freeze, pause, and upgrade powers.

  • Allocation and vesting records.

  • Stablecoin reserve and redemption files.

  • NFT rights.

  • Staking and receipt-token terms.

  • Market-maker agreements.

Market access

  • User-country data.

  • Marketing archives.

  • Local-language sites.

  • Affiliate and influencer agreements.

  • Event records.

  • Payment rails.

  • Application-store distribution.

  • Geoblocking.

  • Rejected onboarding.

  • Closed accounts and asset-return records.

Custody and treasury

  • Wallet inventory.

  • Signers and thresholds.

  • MPC and recovery procedures.

  • Trust and bank agreements.

  • Associated-entity records.

  • Client ledgers.

  • Daily and monthly reconciliations.

  • Cold-storage calculations.

  • Guarantee assets.

  • Insurance and compensation.

  • Validator records.

  • Treasury transfers.

  • Incident records.

AML, sanctions, data, and technology

  • AML and sanctions policies.

  • Customer samples.

  • Alert and reporting records.

  • Travel Rule records.

  • Self-hosted-wallet files.

  • Counterparty VASP checks.

  • Data maps and privacy notices.

  • International-transfer records.

  • Architecture diagrams.

  • Repository and deployment records.

  • Security audits.

  • Penetration tests.

  • Incident and recovery reports.

Financial, tax, and disputes

  • Audited financial statements.

  • Management accounts.

  • Bank and reserve statements.

  • Wallet reconciliations.

  • Tax filings and opinions.

  • Payroll and token-compensation records.

  • Customer complaints.

  • Litigation and arbitration.

  • Regulator inquiries.

  • Insurance notices and settlements.

Part 06

United States

Federal and state overlay
In essence

United States legal due diligence for a Web3 project tests the project under overlapping federal and state laws. The review must classify every token and transaction, identify each service provider, verify federal and state permissions, trace customer assets, and test U.S. market access. The question is how an investor or acquirer should conduct that review under law current through 22 July 2026. No project documents, licence instruments, wallet records, user data, technical records, or transaction terms were supplied. This session states the United States review method and does not clear any named project.

Executive summary
United States

No single federal licence authorises a Web3 project throughout the country. SEC, CFTC, FinCEN, OFAC, banking, consumer, tax, and state authorities can regulate different parts of one product.

Securities

SEC v. W.J. Howey Co., 328 U.S. 293 (1946), remains controlling. The SEC and CFTC’s March 2026 interpretation distinguishes a crypto asset from the transaction in which it is sold. A nonsecurity asset can be sold through an investment contract, while a tokenised stock, debt instrument, or fund interest remains a security.

Offers

Every offer and sale of a security must be registered or qualify for an exemption. Rule 506(b), Rule 506(c), and Regulation S have distinct solicitation, purchaser, verification, resale, and territorial conditions. A website disclaimer does not cure U.S. marketing or sales. Securities Act of 1933, §§ 5, 12 and 17; 17 C.F.R. §§ 230.501–230.506 and 230.901–230.905.

Stablecoins

The GENIUS Act was enacted on 18 July 2025 but was not yet effective on 22 July 2026. Its fallback effective date is 18 January 2027 unless final implementing rules trigger an earlier date. Current federal proposals are not final rules. Existing securities, banking, money-transmission, AML, sanctions, and state laws continue to control during the transition. Pub. L. No. 119-27, 139 Stat. 419.

Commodities

A nonsecurity crypto asset can remain a commodity under the Commodity Exchange Act. Futures, swaps, options, leveraged retail transactions, commodity pools, and related intermediaries require separate CFTC analysis. CFTC anti-fraud and anti-manipulation authority can also reach spot commodity transactions.

Financial crime

FinCEN applies a functional money-transmission test. An administrator or exchanger that accepts and transmits convertible virtual currency can be a money transmitter. Foreign businesses operating wholly or substantially in the United States can also fall within scope. FinCEN registration is not prudential approval and does not replace state licences.

Custody

The reviewer must determine legal title, transfer control, wallet segregation, customer ledgers, shortfall allocation, and insolvency treatment. The answer can differ under federal securities law, bank law, New York rules, California law, and the customer contract.

States

New York requires a BitLicense or qualifying trust authority for covered activity involving New York or its residents. California’s Digital Financial Assets Law became operative on 1 July 2026. Texas applies money-transmission and customer-asset rules to covered digital-asset service providers. A nationwide project still needs a state-by-state survey.

Acquisitions

A transaction can require state change-of-control approval, Hart-Scott-Rodino filing, CFIUS review, licence variation, and updates to federal or state registrations. Contractual control over wallets or management can matter before legal title closes.

Transaction

Unlicensed U.S. service, an unlawful securities offer, customer-asset shortfall, sanctions exposure, false regulatory claims, or an unapproved control transfer should stop closing or require restructuring. Historic liability may require escrow, a specific indemnity, a price adjustment, or seller retention.

Analysis by issue

Federal and state allocation

The United States regulates conduct rather than the project’s chosen label. One Web3 product can engage several authorities.

Subject Principal authority Core DD question
Securities and investment contracts SEC, federal courts, state securities regulators Is the token, sale, staking receipt, fund interest, or service a security or securities transaction?
Commodities and derivatives CFTC, NFA, federal courts Does the product involve futures, swaps, options, leverage, margin, commodity pools, or commodity advice?
Money transmission and AML FinCEN, Department of Justice, state regulators Does an entity accept and transmit currency, funds, or value substituting for currency?
Sanctions OFAC Does the project deal with blocked persons, property, addresses, jurisdictions, or prohibited services?
Banking and custody OCC, Federal Reserve, FDIC, state banking authorities Is the provider a bank, trust company, custodian, reserve holder, or deposit taker?
Consumer protection and cybersecurity FTC, CFPB where applicable, state attorneys general, state agencies Are marketing, fees, security, insurance claims, disclosures, and customer practices lawful?
Tax IRS, state tax authorities How are token sales, rewards, staking, compensation, treasury transactions, and customer reporting treated?
Acquisition review FTC, Department of Justice, CFIUS, licence authorities Does the acquisition require antitrust, national-security, ownership, or control approval?

The reviewer must identify the actor for each function. The issuer, developer, foundation, front-end operator, exchange, custodian, treasury company, validator, market maker, and promoter may be different persons.

The legal analysis should then map:

  1. each entity and natural person;

  2. each token and transaction;

  3. each regulated service;

  4. each U.S. state and territory reached;

  5. each power over code, assets, listings, or users;

  6. each federal and state permission claimed.

A group-level statement that “the project is regulated” does not establish which entity holds which permission.

Token and transaction classification

Howey remains the controlling judicial test

An investment contract exists where the facts show an investment of money in a common enterprise, with a reasonable expectation of profits derived from the entrepreneurial or managerial efforts of others. SEC v. W.J. Howey Co., 328 U.S. 293, 298–99 (1946).

The test applies to the transaction, contract, or scheme. It does not depend on the technology, token name, legal wrapper, or use of distributed validation.

The project file should identify:

  • consideration paid by purchasers;

  • pooling or common economic exposure;

  • promised profits, appreciation, yield, or liquidity;

  • issuer commitments;

  • development milestones;

  • treasury use;

  • market-making support;

  • exchange-listing efforts;

  • continuing managerial control;

  • purchaser dependence on an identifiable team.

A project can create an investment contract even when the digital object later becomes usable on a network.

March 2026 SEC and CFTC interpretation

The SEC and CFTC’s March 2026 joint interpretation confirms that Howey remains controlling. It supersedes the former SEC staff publication from 2019, but it does not bind courts or amend the federal statutes. SEC Release Nos. 33-11412 and 34-105020, File No. S7-2026-09, effective 23 March 2026.

The interpretation separates five broad categories:

  • digital commodities;

  • digital tools;

  • digital collectibles;

  • certain payment stablecoins;

  • digital securities.

A digital commodity derives value primarily from a functional crypto system, programmed operation, scarcity, and market demand. It does not give the holder rights to passive income, business profits, issuer assets, or essential managerial performance. The interpretation identifies several existing network assets as examples. That classification remains an administrative position, not a statutory safe harbour.

A digital tool can provide access, credentials, identity, tickets, or functional use. It presents a lower securities risk where the purchaser buys present functionality rather than a claim on managerial performance. Deferred functionality, issuer-funded appreciation, or promised secondary trading can change the analysis.

A digital collectible can fall outside securities law where it represents ownership, use, or enjoyment of an item. Fractionalisation, common investment rights, revenue sharing, or project-led price support can produce a different result.

A tokenised share, bond, note, fund unit, derivative, or investment interest remains a security. Recording it on a blockchain does not alter the represented right.

Investment-contract attachment and separation

A nonsecurity token can be sold as part of an investment contract. The contract can arise from express or implied issuer promises concerning development, staffing, use of proceeds, milestones, liquidity, listings, buybacks, yield, or price support.

The token does not remain inseparably tied to that investment contract forever. Separation can occur when the issuer’s promises are performed, withdrawn, or no longer essential to value. The reviewer must analyse each sale period and transaction class.

Relevant evidence includes:

  • original sale documents;

  • white papers and road maps;

  • treasury budgets;

  • founder statements;

  • exchange applications;

  • token-release dates;

  • network launch records;

  • code deployment;

  • decentralisation claims;

  • control changes;

  • later marketing.

A current nonsecurity opinion does not erase an earlier unlawful offering.

Stablecoins

The March 2026 interpretation treats certain fully backed and redeemable payment stablecoins as nonsecurity crypto assets under stated conditions. Other stablecoins remain subject to a fact-specific test.

The reviewer should identify:

  • the legal issuer;

  • fixed redemption obligation;

  • reserve composition;

  • holder rights;

  • issuer discretion;

  • yield or rewards;

  • reserve income allocation;

  • insolvency rights;

  • stabilisation mechanics;

  • marketing claims.

An algorithmic token, yield-bearing token, reserve-participation token, or token backed by risky assets can fall outside the interpretation’s stated stablecoin category.

Wrapping and receipt tokens

A wrapper that only records a redeemable claim to a nonsecurity asset can itself be a nonsecurity. The conclusion depends on custody, redemption, fees, issuer promises, and the rights created by the wrapper.

A wrapper for a security remains tied to a security. A wrapper created during an investment-contract distribution can also remain within that securities transaction.

The review should separately classify:

  • bridged assets;

  • deposit receipts;

  • liquid-staking tokens;

  • vault shares;

  • liquidity-pool tokens;

  • tokenised claims against custodians;

  • bankruptcy claims;

  • tokenised fund interests.

Offers, sales, resales, and U.S. market access

Registration or exemption

Securities Act § 5 prohibits an offer or sale of securities through interstate commerce unless a registration statement is filed and effective, or an exemption applies. 15 U.S.C. § 77e.

The project should identify each offering route:

  • registered offering;

  • Securities Act § 4(a)(2);

  • Rule 506(b);

  • Rule 506(c);

  • Regulation S;

  • Regulation CF;

  • Regulation A;

  • employee compensation exemption;

  • another statutory exemption.

The reviewer should test the exemption as applied, not only the cited legend.

Regulation D

Rule 506(b) generally prohibits general solicitation. It permits sales to unlimited accredited investors and no more than 35 qualifying non-accredited investors, subject to information and sophistication requirements.

Rule 506(c) permits general solicitation only where every purchaser is accredited and the issuer takes reasonable verification steps. A purchaser questionnaire alone may not satisfy that requirement in every case.

Rule 506 securities are restricted securities. Form D is generally due within 15 days after the first sale. State securities regulators can still require notice filings, fees, and anti-fraud compliance.

The DD file should contain:

  • subscription agreements;

  • accredited-investor evidence;

  • verification records;

  • Form D filings;

  • state notice filings;

  • bad-actor questionnaires;

  • solicitation records;

  • purchaser lists;

  • resale legends;

  • transfer restrictions;

  • wallet restrictions.

Open social-media promotion can defeat Rule 506(b). Token transfers to unrestricted wallets can undermine resale controls.

Regulation S

Regulation S requires an offshore transaction and no directed selling efforts in the United States. Further conditions depend on the issuer, security type, distribution category, and resale period. 17 C.F.R. §§ 230.901–230.905.

A foreign project should not rely on a website legend alone. Relevant facts include:

  • U.S. website traffic;

  • U.S. social-media campaigns;

  • U.S. conferences;

  • U.S. affiliates;

  • U.S. influencers;

  • purchaser location;

  • payment origin;

  • identity documents;

  • wallet screening;

  • resale restrictions;

  • prearranged U.S. resales.

An offshore website should use procedures designed to prevent U.S. sales where Regulation S requires them. Publicly accessible material can also affect a concurrent U.S. private placement.

Airdrops, grants, and promotional distributions

A zero-dollar token distribution is not automatically outside the securities laws. Consideration can arise from promotional services, network building, referrals, data, or other value.

The SEC has treated bounty distributions made in exchange for online promotion as securities sales. The reviewer should examine each airdrop, referral reward, ambassador program, liquidity incentive, and employee grant.

If securities are promoted, Securities Act § 17(b) requires disclosure of paid promotional consideration. Influencer agreements, token grants, referral codes, and market-maker compensation should be reviewed.

Civil and enforcement exposure

Securities Act § 12 can permit rescission or damages for certain unlawful offers and material misstatements. Section 17(a), Exchange Act § 10(b), and Rule 10b-5 address fraud.

Material omissions can concern:

  • token supply;

  • insider allocations;

  • minting powers;

  • vesting;

  • market-maker loans;

  • treasury sales;

  • protocol control;

  • security incidents;

  • reserve deficiencies;

  • regulatory status;

  • conflicts.

A later licence or network launch does not extinguish accrued purchaser claims.

Trading venues, brokers, dealers, and securities infrastructure

If a platform trades securities, the reviewer must test Exchange Act registration and exemptions.

An exchange can require registration under Exchange Act § 5 or operation under an alternative trading system route. A person effecting securities transactions for others can be a broker. A person buying and selling securities as part of a regular business can be a dealer. Exchange Act §§ 3(a), 5 and 15(a), 15 U.S.C. §§ 78c, 78e and 78o.

The functional review should identify who:

  • brings together orders;

  • sets execution rules;

  • routes orders;

  • takes principal positions;

  • earns spreads;

  • solicits transactions;

  • handles customer funds;

  • settles trades;

  • controls transfer records;

  • holds security tokens;

  • provides market making.

A project calling itself a swap service, automated market maker, router, vending machine, or software interface can still perform regulated functions.

Clearing-agency and transfer-agent issues can arise where the operator interposes itself in settlement, maintains security-holder records, or performs transfer functions. The exact result depends on the security and system design.

The file should contain:

  • matching logic;

  • order-routing records;

  • liquidity agreements;

  • fee schedules;

  • proprietary trading records;

  • settlement flows;

  • customer terms;

  • asset classifications;

  • broker-dealer opinions;

  • exchange or ATS records;

  • clearing and transfer arrangements.

Stablecoins and the GENIUS Act transition

Current status

The GENIUS Act became law on 18 July 2025. It takes effect on the earlier of:

  • 18 months after enactment, which is 18 January 2027; or

  • 120 days after the primary federal payment-stablecoin regulators issue final implementing regulations.

No final set of implementing regulations was identified as of 22 July 2026. OCC, FDIC, Treasury, FinCEN, OFAC, and Federal Reserve materials remained proposed measures. The statute was therefore not yet operative.

Current stablecoin activity still requires analysis under:

  • federal securities law;

  • Commodity Exchange Act;

  • FinCEN rules;

  • OFAC sanctions;

  • federal and state banking law;

  • state money-transmission law;

  • trust and custody law;

  • consumer-protection law.

A project should not describe itself as a permitted payment-stablecoin issuer before the statutory process applies and the required approval is obtained.

Core GENIUS Act requirements after effectiveness

Once effective, the GENIUS Act generally restricts U.S. payment-stablecoin issuance to permitted issuers. Digital-asset service providers will face restrictions on offering or selling payment stablecoins to U.S. persons unless the issuer satisfies the domestic or qualifying foreign route. 12 U.S.C. §§ 5903–5916.

A permitted issuer must maintain identifiable reserves at least equal to outstanding payment stablecoins. Permitted reserve assets are subject to statutory limits.

The issuer must publish a redemption policy and provide timely redemption at the statutory value.

The issuer becomes a financial institution under the Bank Secrecy Act. AML and sanctions requirements will apply through the Act and implementing rules.

The Act gives payment-stablecoin holders a priority claim against required reserves in issuer insolvency.

The Act also bars misleading claims of federal deposit insurance or government backing. Payment stablecoins are not federally insured deposits merely because reserves sit at an insured bank.

Transition DD

A stablecoin project should provide:

  • a classification memorandum;

  • current state licences;

  • FinCEN registration;

  • reserve records;

  • redemption records;

  • bank and custody agreements;

  • issuer financial statements;

  • current and projected supply;

  • GENIUS implementation plan;

  • intended federal or state issuer route;

  • foreign-issuer analysis;

  • AML and sanctions readiness;

  • wind-down and redemption planning.

The transaction should allocate the risk that final rules differ from current proposals.

Commodities, derivatives, leverage, and DeFi

Commodity status

A crypto asset that is not a security can still be a commodity under the Commodity Exchange Act. The SEC and CFTC’s 2026 interpretation confirms that distinction.

Commodity status alone does not create a general federal spot-exchange licence. It gives the CFTC anti-fraud and anti-manipulation authority over spot commodity transactions. Derivatives and leveraged retail products create broader registration duties.

Derivatives and intermediaries

The reviewer should test:

  • futures;

  • options;

  • swaps;

  • perpetual contracts;

  • leveraged tokens;

  • margin;

  • financed purchases;

  • prediction contracts;

  • synthetic assets;

  • commodity pools;

  • discretionary commodity trading;

  • commodity advice;

  • customer collateral.

Potential registrations include:

  • designated contract market;

  • swap execution facility;

  • futures commission merchant;

  • introducing broker;

  • swap dealer;

  • commodity pool operator;

  • commodity trading adviser.

A project cannot avoid these categories by settling in crypto rather than dollars.

Retail commodity transactions

Commodity Exchange Act § 2(c)(2)(D) generally treats leveraged, margined, or financed retail commodity transactions as futures unless actual delivery occurs within 28 days or another exception applies. 7 U.S.C. § 2(c)(2)(D).

The CFTC withdrew its 2020 digital-asset actual-delivery guidance in December 2025. A current opinion should apply the statute, current regulations, contract terms, and transfer facts rather than treating the former factors as operative guidance.

The review should determine:

  • whether the customer is retail;

  • whether leverage, margin, or financing exists;

  • who retains control;

  • whether the customer can transfer the asset freely;

  • whether the platform retains a lien;

  • whether settlement is real or internal;

  • whether delivery occurs within 28 days.

DAOs and decentralised systems

A DAO or decentralised interface does not receive a statutory exemption.

In CFTC v. Ooki DAO, No. 3:22-cv-05416-WHO, the Northern District of California entered default judgment against a DAO operating unlawful leveraged retail commodity transactions. The court treated the DAO as a person under the Commodity Exchange Act. The decision involved a default, which limits its persuasive weight in contested cases. It still shows that a DAO structure does not prevent suit or liability.

A DeFi review should identify who:

  • deployed the contracts;

  • controls upgrade keys;

  • operates the main interface;

  • sets collateral factors;

  • selects markets;

  • controls oracles;

  • operates liquidations;

  • collects fees;

  • controls the treasury;

  • can pause the system;

  • markets to U.S. users.

Open-source publication does not answer whether a person operates, facilitates, or promotes a regulated service.

Staking, lending, funds, and investment advice

Protocol staking

The March 2026 interpretation states that specified protocol-staking arrangements can fall outside securities transactions where the provider performs administrative or technical functions.

Covered models include certain:

  • self-staking;

  • delegated self-custodial staking;

  • custodial staking;

  • liquid staking;

  • ancillary staking services.

The conclusion weakens where the provider:

  • guarantees rewards;

  • sets the reward rate;

  • decides whether or when to stake;

  • exercises material investment discretion;

  • absorbs or reallocates protocol risk;

  • creates returns from its own business;

  • combines staking with lending or proprietary trading.

A staking receipt can be a nonsecurity where it merely records a claim to a nonsecurity staked asset. A receipt with added yield, management, liquidity promises, or pooled economic exposure needs a separate analysis.

Lending and yield

A crypto lending product can involve:

  • a note;

  • an investment contract;

  • a security-based swap;

  • a commodity interest;

  • banking or deposit-taking;

  • state lending law;

  • state usury law;

  • money transmission;

  • custody.

The reviewer should identify who receives title, who deploys the assets, who sets yield, who bears borrower default, and whether returns come from protocol validation or the provider’s business.

Fixed or advertised yield funded by the provider presents a different issue from the pass-through of protocol rewards.

Funds and advisers

A pooled vehicle investing in tokens can be an investment company under the Investment Company Act of 1940. Exemptions under §§ 3(c)(1) or 3(c)(7) require factual testing.

A person advising others about securities for compensation can be an investment adviser. Registration, exemption, custody, marketing, valuation, and fiduciary duties may apply. Investment Advisers Act of 1940, §§ 202(a)(11), 203 and 206.

The SEC withdrew its proposed adviser safeguarding rule in June 2025. The existing custody rule, Rule 206(4)-2, remained operative on the As-of Date.

A DAO treasury, protocol vault, tokenised fund, or managed yield account can raise fund and adviser issues even when no conventional partnership exists.

Money transmission, AML, and sanctions

FinCEN status

FinCEN applies a functional test to convertible virtual currency.

A user that acquires and uses virtual currency for its own purchases is generally not an MSB on that basis. An administrator or exchanger that accepts and transmits value, or buys and sells convertible virtual currency as a business, can be a money transmitter unless an exception applies.

The statutory and regulatory analysis should cover:

  • exchange;

  • brokerage;

  • transfers;

  • hosted wallets;

  • payment processing;

  • mixers;

  • peer-to-peer dealing;

  • kiosks;

  • stablecoin administration;

  • DeFi interfaces;

  • cross-chain services;

  • merchant settlement.

Software development, mining, validation, or infrastructure can fall outside money transmission when the actor does not accept and transmit value for others. The business model and actual control decide the result.

A foreign-located business can be an MSB where it conducts business wholly or substantially in the United States. U.S. customers, personnel, affiliates, support, payment rails, and solicitation matter.

Registration and operating duties

A covered MSB must register with FinCEN and renew its registration every two years. Registration is not an operating approval or safety assessment.

A money transmitter must maintain a written, risk-based AML program. The program must include internal controls, a compliance officer, training, and independent review. 31 C.F.R. § 1022.210.

A money transmitter generally must file a suspicious activity report for a qualifying suspicious transaction of at least $2,000. Filing is normally due within 30 days after initial detection. 31 C.F.R. § 1022.320.

Nonbank transfer recordkeeping and Travel Rule requirements generally apply at $3,000. 31 C.F.R. § 1010.410(e)–(f).

The DD review should sample:

  • customer files;

  • beneficial-owner records;

  • risk ratings;

  • sanctions screening;

  • source-of-funds reviews;

  • transaction monitoring;

  • blockchain analytics;

  • Travel Rule messages;

  • suspicious activity cases;

  • law-enforcement requests;

  • blocked accounts;

  • independent testing.

A policy without operating evidence remains unverified.

Criminal exposure

Operating an unlicensed money-transmitting business can create criminal exposure under 18 U.S.C. § 1960. The statute can apply where the business lacks a required state licence, fails federal registration, or transmits criminal proceeds.

The maximum imprisonment term is five years. The operator need not know that state law required the licence under the state-licence branch of the offence.

Foreign exchange operators have faced U.S. criminal liability where their written U.S. exclusions differed from actual U.S. customer acquisition and service.

OFAC

OFAC sanctions apply independently of licence status and AML registration.

A project should screen:

  • customers;

  • beneficial owners;

  • counterparties;

  • wallet addresses;

  • validators;

  • liquidity sources;

  • bridges;

  • mixers;

  • jurisdictions;

  • transaction paths.

Blocked virtual currency must be denied access and reported to OFAC within the required period. OFAC does not require conversion into fiat before blocking.

The reviewer should identify who can reject a transaction, freeze assets, disable an account, block an address, or restrict an interface. A project should not claim that sanctions compliance is impossible while retaining those powers.

Custody, customer assets, and insolvency

Core custody questions

A complete custody opinion should answer:

  1. Who holds legal title?

  2. Who controls transfer?

  3. Which entity contracts with the customer?

  4. Are assets separated in wallets, records, and financial accounts?

  5. Can the provider lend, pledge, stake, or rehypothecate them?

  6. Who bears a shortfall?

  7. What happens on insolvency?

  8. Who receives forks, airdrops, rewards, and voting rights?

“Non-custodial” is a factual claim. A provider can exercise material custody through an MPC share, recovery key, transaction approval, withdrawal whitelist, relayer, smart-contract upgrade, or emergency power.

Federal securities custody

If the assets are securities, broker-dealer and investment-adviser custody rules can apply.

A carrying broker-dealer must analyse Exchange Act Rule 15c3-3 and related financial-responsibility rules. The SEC issued a December 2025 staff statement concerning broker-dealers that carry crypto-asset securities. The statement does not bind the Commission or create an exemption from the statutes and rules.

The SEC rescinded Staff Accounting Bulletin No. 121 through SAB 122 in January 2025. That accounting change did not remove custody, capital, disclosure, or customer-protection duties.

The SEC also withdrew its 2019 broker-dealer custody statement in May 2025. Current opinions should not present that statement as operative policy.

Banks

OCC Interpretive Letter 1183 states that national banks and federal savings associations may conduct permissible crypto custody, hold stablecoin reserve deposits, and use distributed-ledger technology and stablecoins for permitted payment activities. The bank remains subject to safety, soundness, risk-management, and other legal duties.

OCC Interpretive Letter 1184 permits specified customer-directed purchases and sales involving custody assets and permits outsourcing under applicable third-party controls. Later OCC letters address limited network-fee holdings and specified riskless-principal activity.

The FDIC removed its former prior-notification expectation in 2025. An FDIC-supervised institution can engage in permissible crypto activity without a special prior approval process, subject to ordinary law and supervisory review.

These bank materials do not authorise a nonbank project. They also do not establish that a bank’s customer, affiliate, or technology provider holds banking authority.

Insolvency evidence

The project should provide:

  • custody agreements;

  • trust instruments;

  • wallet inventory;

  • key-control records;

  • customer ledgers;

  • daily reconciliations;

  • shortfall reports;

  • sub-custody contracts;

  • lien and set-off waivers;

  • staking permissions;

  • insurance;

  • insolvency opinions;

  • financial-statement treatment.

State property law often determines the customer’s ownership before federal bankruptcy law applies. An on-chain balance proves asset existence at an address. It does not prove who owns the asset or whether creditor claims attach.

Selected state overlays

Nationwide state review

FinCEN registration does not replace state authority. A nationwide project should assess every state where it has customers, counterparties, personnel, marketing, or regulated conduct.

State issues can include:

  • money-transmitter licensing;

  • virtual-currency licensing;

  • trust-company authority;

  • state securities registration and exemptions;

  • lending and usury;

  • custody;

  • unclaimed property;

  • consumer protection;

  • privacy and cybersecurity;

  • state tax;

  • change of control.

The final state matrix should identify the service, statutory nexus, licence, exemption, renewal date, bond, capital, reporting, examination, and control-approval requirements.

New York

New York’s Virtual Currency Business Activity rules apply to covered activity involving New York or a New York resident. Covered activity includes:

  • receiving virtual currency for transmission;

  • transmitting virtual currency;

  • custody or control for others;

  • buying and selling as a customer business;

  • exchange services;

  • controlling, administering, or issuing virtual currency.

23 N.Y.C.R.R. Part 200.

An out-of-state provider can fall within scope by serving New York residents. Pure software development can fall outside the rule, but a custodial wallet or service with control can require authority.

FinCEN registration does not replace a BitLicense. A limited-purpose trust company can have broader fiduciary powers, but the charter and conditions must be checked.

The licence file should contain:

  • BitLicense or trust charter;

  • approved activities;

  • licence conditions;

  • New York customer data;

  • authorised coins;

  • capital and bond records;

  • examination reports;

  • regulator correspondence;

  • cybersecurity certifications;

  • transaction-monitoring certifications.

New York’s 2025 custody guidance requires customer-asset segregation on-chain and in internal records. It restricts own-account use and requires protection of the customer’s beneficial interest. Material sub-custody arrangements can require prior DFS approval.

Part 200 requires prior approval for specified new or materially changed products and for acquisitions or changes of control. The control definition reaches direct and indirect influence, not only formal ownership.

DFS-regulated entities must also test 23 N.Y.C.R.R. Part 500 cybersecurity duties and Part 504 transaction-monitoring and sanctions-filtering certification.

California

California’s Digital Financial Assets Law became operative on 1 July 2026. A person may conduct covered digital-financial-asset business with or for a California resident only if:

  • licensed;

  • operating under a timely completed pending application permitted by the transition;

  • exempt.

Cal. Fin. Code §§ 3101–3906, as amended by 2026 Cal. Stat. ch. 52.

The law can reach an out-of-state business serving California residents. Covered activity includes exchange, transfer, storage, custody, and other defined conduct.

Exclusions and exemptions cover specified securities, rewards, game assets, property-linked NFTs, banks, trust companies, pure technical services, own-account consumer conduct, low-volume activity, and other defined cases. Each element requires testing.

A New York BitLicense or qualifying trust authority issued by 1 January 2025 can support a conditional California licence route. It does not create an automatic California exemption.

California regulations require prior approval before a qualifying change of control. Control generally exists at 25 percent, while a 10 percent holding can create a rebuttable presumption in the transaction process. Indirect holdings, voting agreements, and management influence matter.

A licensee holding customer assets must generally maintain the same type and quantity owed to customers. Customer assets receive statutory property and trust protections and should not become ordinary estate assets or creditor collateral.

The DD file should also cover:

  • customer disclosures;

  • token-listing procedures;

  • outage reporting;

  • fraud controls;

  • AML controls;

  • annual reports;

  • material-change notices;

  • complaint records;

  • kiosk rules, where applicable.

The Digital Financial Assets Law does not remove other California licensing duties.

Texas

Texas applies its money-transmission analysis to virtual-currency activity based on the service and flow of value.

Texas Finance Code Chapter 160 adds customer-protection duties for a covered digital-asset service provider that holds a Texas money-transmitter licence and either:

  • serves more than 500 Texas customers; or

  • holds at least $10 million in customer funds.

The provider must avoid prohibited commingling, maintain sufficient reserves, give customers recurring access to account information, and obtain an annual independent audit or attestation.

A fiat-backed stablecoin issuer can also require Texas money-transmitter authority under current state treatment. The GENIUS Act transition does not by itself displace that current analysis.

Texas securities law remains relevant where a token or scheme creates an investment contract, note, fund interest, or another security.

Corporate integrity, DAOs, and ownership

Entity map

The reviewer should reconcile:

  • legal entities;

  • beneficial owners;

  • equity capitalization;

  • token entitlements;

  • voting rights;

  • foundation or council powers;

  • intellectual-property ownership;

  • domain ownership;

  • repository control;

  • wallet control;

  • contractual revenue rights.

A DAO LLC, foundation, nonprofit, or foreign wrapper can hold assets and allocate authority. It does not create a securities, commodities, banking, money-transmission, or custody licence.

Where no effective wrapper exists, participants can face unincorporated-association, partnership, agency, or direct-principal arguments. The Ooki DAO judgment confirms that decentralised administration does not necessarily prevent entity-level liability.

The project should document who can:

  • amend smart contracts;

  • control treasury wallets;

  • appoint signers;

  • change fees;

  • select markets;

  • pause operations;

  • approve listings;

  • direct service companies;

  • alter token rights.

Token voting percentages should be reconciled with delegated voting, multisig powers, founder concentration, and off-chain agreements.

Intellectual property

The file should contain:

  • employee invention assignments;

  • contractor assignments;

  • contributor agreements;

  • open-source inventory;

  • trademark and domain records;

  • repository access;

  • deployment records;

  • third-party code licences;

  • audit rights;

  • infringement claims.

Open-source publication does not establish that the project owned the code before publication. Copyleft obligations, attribution duties, patent clauses, and incompatible licences can affect continued operation.

Corporate Transparency Act

FinCEN’s March 2025 interim final rule exempted domestic U.S. entities and their beneficial owners from Corporate Transparency Act reporting.

Foreign entities registered to do business in a U.S. state or tribal jurisdiction can remain reporting companies, subject to exemptions. U.S. persons who own those foreign reporting entities generally need not be reported under the interim rule.

The domestic exemption does not remove the need for verified beneficial-owner, sanctions, tax, licensing, and change-of-control records.

Acquisitions and regulatory approvals

State control approvals

New York requires prior approval for covered changes of control and specified mergers or acquisitions. California requires a change-control application before the transaction proceeds. Other state licences can carry separate thresholds and procedures.

The analysis should include:

  • direct shares;

  • indirect shares;

  • voting agreements;

  • options;

  • warrants;

  • convertibles;

  • board appointment rights;

  • veto rights;

  • management agreements;

  • token-based voting;

  • treasury control;

  • private-key control;

  • acting-in-concert arrangements.

The buyer should not obtain de facto control before required approvals.

Hart-Scott-Rodino Act

The 2026 Hart-Scott-Rodino size-of-transaction threshold is $133.9 million, effective 17 February 2026. Other thresholds, exemptions, and size-of-person tests can affect reportability.

A reportable transaction cannot close until the waiting period expires or terminates.

Following litigation over the revised HSR form, the FTC currently accepts the pre-10 February 2025 form and voluntarily accepts the later form. The transaction team should confirm the operative filing procedure at signing and filing.

CFIUS

CFIUS can review a transaction that gives a foreign person control of a U.S. business. It can also review specified noncontrolling investments in a TID U.S. business involving critical technology, critical infrastructure, or sensitive personal data.

A Web3 project can present CFIUS issues where it has:

  • cryptographic or critical technology;

  • government customers;

  • critical payment or infrastructure functions;

  • large financial datasets;

  • precise geolocation data;

  • health or identity data;

  • sensitive customer records;

  • foreign-government investors.

Mandatory declarations can apply to specified foreign-government interests and critical-technology transactions. A voluntary declaration or notice can produce safe-harbour protection if CFIUS concludes action.

CFIUS does not issue advance advisory opinions. The parties must assess the facts and filing strategy.

Outbound investment

A U.S. person investing in specified Chinese, Hong Kong, or Macau entities can face prohibition or notification duties under 31 C.F.R. Part 850. Covered sectors include specified semiconductors, quantum technologies, and artificial intelligence systems.

A Web3 project with AI, advanced computing, or relevant cryptographic technology should conduct a separate outbound-investment review.

Tax and information reporting

The IRS treats digital assets as property rather than foreign currency for federal income-tax purposes. Sales, exchanges, payments, and dispositions can create gain or loss.

Staking rewards are generally included in gross income when the taxpayer gains dominion and control over the rewards. The income amount is their fair market value at that time. Rev. Rul. 2023-14.

The DD review should cover:

  • token-sale proceeds;

  • treasury transactions;

  • staking rewards;

  • validator income;

  • mining;

  • airdrops;

  • forks;

  • employee and contractor tokens;

  • vesting;

  • withholding;

  • transfer pricing;

  • basis;

  • loss recognition;

  • state tax;

  • information reporting.

Broker reporting through Form 1099-DA is being phased in. Gross-proceeds reporting applies to specified 2025 transactions, while basis reporting for covered transactions begins with specified 2026 acquisitions and dispositions.

Congress nullified the former DeFi broker reporting rule in April 2025. That nullification removed the rule’s effect. It did not remove income-tax, recordkeeping, or other reporting duties. Pub. L. No. 119-5, 139 Stat. 48.

The project should reconcile tax records against on-chain wallets and financial statements.

Consumer protection, privacy, and cybersecurity

FTC Act § 5 prohibits unfair or deceptive acts or practices. Claims about licensing, security, reserves, insurance, transaction finality, fees, yields, or government approval should match the facts.

The FTC has taken action against crypto businesses for misleading FDIC-insurance and safety claims. Those actions show the need to verify every statement concerning reserve accounts and government protection.

The FTC Safeguards Rule applies to covered nonbank financial institutions. It requires a written information-security program. A qualifying event involving unauthorised acquisition of unencrypted customer information for at least 500 consumers must generally be reported to the FTC within 30 days after discovery. 16 C.F.R. Part 314.

The data review should identify:

  • each controller and processor;

  • customer data categories;

  • wallet and transaction data;

  • biometric or identity data;

  • precise geolocation;

  • marketing data;

  • legal bases and notices;

  • sharing arrangements;

  • international transfers;

  • retention;

  • breach history;

  • deletion and access rights.

Federal sector rules and state privacy, breach, biometric, consumer, and cybersecurity laws can apply concurrently.

The technical evidence should include:

  • system inventory;

  • wallet architecture;

  • source repositories;

  • deployment history;

  • admin-key configuration;

  • penetration tests;

  • smart-contract audits;

  • incident reports;

  • recovery tests;

  • vendor contracts;

  • cloud, oracle, bridge, and sequencer dependencies;

  • exit plans.

An audit of an older contract version does not establish security of the live deployment.

Regulatory status verification

A current United States status check should follow these steps:

  1. Identify the exact legal entity.

  2. Search SEC, FINRA, CFTC, NFA, FinCEN, banking, and state records.

  3. Obtain each licence, registration, charter, exemption, or approval.

  4. Identify the permitted services and products.

  5. Identify conditions, undertakings, and restrictions.

  6. Compare the permission with customer terms and actual operations.

  7. Check all trade names, domains, applications, and affiliates.

  8. Review examination, enforcement, subpoena, and remediation records.

  9. Check renewal, bond, capital, reporting, and certification status.

  10. Repeat the checks before signing and closing.

Particular caution applies where a project claims:

  • “SEC compliant” without an effective registration or exemption;

  • “CFTC regulated” based only on commodity status;

  • “FinCEN licensed” based on MSB registration;

  • “FDIC insured” because reserve funds sit at a bank;

  • “New York approved” based on an affiliate’s BitLicense;

  • “California authorised” based on an incomplete application;

  • “GENIUS compliant” before the Act and final rules apply.

Red flags and transaction treatment

Stop or restructure

The following findings normally require suspension, abandonment, or restructuring before closing:

  • unregistered securities offers or sales;

  • operation of an unregistered securities exchange, broker, dealer, or clearing function;

  • unlawful futures, swaps, leveraged retail commodity transactions, or commodity-pool activity;

  • unregistered federal or state money transmission;

  • active U.S. service by a foreign platform claiming ineffective geoblocking;

  • customer-asset commingling or shortfall;

  • missing New York or California authority;

  • false SEC, CFTC, FinCEN, bank, state, or insurance claims;

  • sanctions dealings or blocked-property failures;

  • missing ownership of core code, domains, or wallets;

  • undisclosed minting, upgrade, treasury, listing, or withdrawal powers;

  • a stablecoin reserve deficiency;

  • an acquisition requiring unreceived control approval;

  • unresolved criminal, regulatory, or customer-asset investigations.

Conditions precedent

A matter can support a condition precedent where an objective cure exists:

  • registration or licence receipt;

  • exemption confirmation;

  • change-of-control approval;

  • HSR clearance;

  • CFIUS clearance;

  • customer-asset segregation;

  • custody migration;

  • reserve funding;

  • key rotation;

  • intellectual-property assignment;

  • contract novation;

  • U.S. market-access controls;

  • customer re-papering;

  • AML remediation;

  • sanctions remediation;

  • corrected marketing;

  • tax filing or reporting correction;

  • regulator confirmation.

The condition should identify the exact document or evidence required.

Price, escrow, and indemnity

Historic liability may remain after operational repair.

Transaction protection may be required for:

  • historic token sales;

  • securities rescission claims;

  • unlicensed services;

  • customer-asset losses;

  • money-transmission violations;

  • AML and sanctions failures;

  • stablecoin reserve deficiencies;

  • tax;

  • market manipulation;

  • data breaches;

  • employment;

  • intellectual-property defects;

  • regulator investigations.

The clause should define the covered period, claimant class, loss measure, limitation period, claim control, and security.

Monitored remediation

Lower-severity matters should remain open only where the transaction documents specify:

  • the exact task;

  • the responsible person;

  • the deadline;

  • the evidence required;

  • reporting frequency;

  • inspection rights;

  • consequences of failure.

A general promise to improve compliance is not an adequate remedy.

Priority evidence request

Corporate and ownership

Current group chart.
Formation and good-standing records.
Shareholder and beneficial-owner registers.
Cap table, options, warrants, convertibles, and side letters.
Token allocation and voting records.
Board, committee, foundation, and DAO records.
Intercompany agreements.
Corporate Transparency Act analysis.

Securities and products

  • Current and historic white papers.

  • Token classification opinions.

  • Sale and subscription agreements.

  • Form D and state notice filings.

  • Regulation S records.

  • Purchaser verification.

  • Token-holder rights.

  • Contract addresses.

  • Mint, burn, pause, freeze, and upgrade powers.

  • Allocation and vesting schedules.

  • Exchange and market-maker agreements.

  • Staking, lending, wrapper, and receipt-token terms.

Federal and state permissions

  • SEC, FINRA, CFTC, NFA, and FinCEN records.

  • Bank or trust charters.

  • State money-transmitter licences.

  • BitLicense and New York trust records.

  • California DFAL licence or transition filing.

  • Texas money-transmitter records.

  • Approved activities and conditions.

  • Regulator correspondence.

  • Examination and enforcement files.

  • Change-control filings.

Market access

  • U.S. and state customer data.

  • IP and device-location data.

  • Marketing archives.

  • Influencer and affiliate agreements.

  • U.S. events.

  • Application-store availability.

  • Payment rails.

  • Geoblocking.

  • Rejected onboarding.

  • Closed accounts.

  • Regulation S controls.

Custody and treasury

  • Wallet inventory.

  • Signers and thresholds.

  • MPC and recovery procedures.

  • Customer ledgers.

  • Daily reconciliations.

  • Shortfall records.

  • Trust and sub-custody agreements.

  • Lien and set-off waivers.

  • Staking and lending records.

  • Stablecoin reserve records.

  • Insurance.

  • Incident files.

  • Treasury transfers.

AML, sanctions, privacy, and technology

  • FinCEN registration.

  • AML program.

  • Customer and beneficial-owner samples.

  • Sanctions-screening records.

  • Travel Rule records.

  • Suspicious activity files.

  • OFAC blocking and reporting records.

  • Data maps.

  • Privacy notices.

  • Security policies.

  • Architecture and repository records.

  • Smart-contract audits.

  • Penetration tests.

  • Incident and recovery records.

  • Vendor and cloud agreements.

Financial, tax, and disputes

  • Audited financial statements.

  • Management accounts.

  • Bank and reserve statements.

  • Wallet reconciliations.

  • Tax returns.

  • Form 1099-DA implementation records.

  • Token-compensation records.

  • Customer complaints.

  • Litigation and arbitration.

  • Subpoenas and regulator inquiries.

  • Insurance notices.

  • Settlements and releases.

Part 07

United Kingdom

FCA perimeter and promotions
In essence

United Kingdom legal due diligence for a Web3 project tests the project under the law presently in force and the broader cryptoasset regime beginning on 25 October 2027. The review must classify each token and service, verify current FCA registration or authorisation, examine UK-facing promotions, trace customer assets, test sanctions and tax reporting, and assess the project’s readiness for the 2027 authorisation gateway. The question is how an investor or acquirer should conduct that review under law current through 22 July 2026. No project documents, regulatory instruments, wallet records, user data, technical records, or transaction terms were supplied. This session states the United Kingdom review method and does not clear any named project.

Executive summary
Current UK perimeter

Until 25 October 2027, the FCA’s ordinary oversight of nonsecurity spot cryptoasset businesses remains focused on Money Laundering Regulations registration and financial promotions. Security tokens, electronic money, payment services, derivatives, collective investment schemes, deposits, and other specified products can already require full FSMA or sector-specific authorisation.

Regulatory status

FCA registration under the Money Laundering Regulations is not product approval, prudential authorisation, or an endorsement of the project. It does not convert automatically into authorisation under the 2027 regime. The licensed or registered entity must match the entity that contracts with users, controls wallets, receives fees, and performs the service.

Financial promotions

The promotion rules have applied since 8 October 2023 to firms marketing qualifying cryptoassets to UK consumers, including overseas firms. A lawful promotion must use one of four statutory routes. Unlawful communication can constitute a criminal offence punishable by up to two years’ imprisonment, an unlimited fine, or both. FSMA 2000, ss. 21 and 25; Financial Promotion Order 2005, art. 73ZA.

AML and sanctions

Current UK cryptoasset exchange providers and custodian wallet providers must operate risk-based customer due diligence, monitoring, suspicious-activity reporting, Travel Rule, sanctions, and recordkeeping controls. From 30 June 2026, mandatory country-based enhanced due diligence under regulation 33 focuses on FATF “Call for Action” jurisdictions, while other geographic risks remain part of the firm’s risk assessment.

2027 authorisation

The Financial Services and Markets Act 2000 (Cryptoassets) Regulations 2026 bring trading platforms, dealers, arrangers, custodians, qualifying stablecoin issuers, and staking arrangers into the FSMA perimeter from 25 October 2027. The application window runs from 30 September 2026 to 28 February 2027. Existing MLR, payment-services, electronic-money, or FSMA status does not remove the need for the correct new permission.

Transition

A timely applicant may use the statutory saving provisions while the FCA decides the application, subject to the conditions in the 2026 Regulations. A late applicant that lacks permission at commencement receives only a restricted pre-existing-contract transition. It cannot enter new UK customer contracts. A firm that never applies must run off its UK business before commencement.

Offers and market conduct

The 2027 regime restricts public offers of qualifying cryptoassets and creates disclosure, admission, civil-liability, and market-abuse duties. Token supply, admin powers, treasury transactions, security incidents, market-maker arrangements, and insider wallets must match the required disclosures.

Stablecoins

Current stablecoin treatment depends on the product’s legal rights and can engage electronic-money, payment-services, deposit, securities, AML, and promotion rules. From 2027, UK issuance of a qualifying stablecoin requires FCA permission and compliance with the FCA’s backing, trust, redemption, and custody rules. Systemic sterling stablecoins will also fall under Bank of England supervision after HM Treasury recognition. The Bank’s June 2026 Code of Practice remained draft on the As-of Date.

Customer assets

Current customer ownership depends on the contract, trust terms, actual key control, segregation, and applicable property and insolvency law. The Property (Digital Assets etc) Act 2025 confirms that an asset is not barred from personal-property treatment merely because it falls outside the two traditional categories. It does not determine ownership, priority, or insolvency treatment in every case.

Transaction

Unregistered current activity, unlawful promotions, an unregulated security or payment product, customer-asset shortfalls, sanctions exposure, an inadequate 2027 application plan, or an unapproved control acquisition should stop closing or require restructuring. Historic exposure may require escrow, a specific indemnity, a price adjustment, or seller-retained liability.

Analysis by issue

United Kingdom decision sequence

United Kingdom legal due diligence should start with five connected maps.

The entity map identifies every issuer, foundation, developer, front-end operator, custodian, exchange, treasury company, market maker, validator, and service company. It records ownership, directors, officers, staff, contractors, domains, bank accounts, wallets, permissions, and contractual roles.

The activity map assigns each service to a named person. Relevant conduct includes issuance, exchange, dealing, order matching, brokerage, arranging, custody, transfer, staking, lending, payment, advice, portfolio management, validation, and interface operation.

The product map classifies each token and transaction. The original fundraising instrument, live token, wrapped asset, bridge asset, liquidity-pool interest, staking receipt, stablecoin, NFT, tokenised security, and redemption claim can produce different legal results.

The territory map records how the project reaches the United Kingdom. Evidence includes user residence, local-language marketing, sterling rails, UK staff, events, affiliates, influencers, customer support, domains, application stores, and onboarding controls.

The control map records every power over code and assets. It should cover upgrades, pauses, minting, burning, freezing, blacklisting, fee changes, oracle changes, bridge changes, listings, treasury transfers, validator selection, and recovery. It should also identify key holders, multisig thresholds, MPC shares, time locks, delegated powers, and emergency processes.

The reviewer should then assign each representation to evidence. An FCA register entry proves the status stated on the check date. It does not prove that every live product fits the registered or permitted scope. On-chain evidence proves transactions and contract states. It does not establish legal title, authority, beneficial ownership, or compliance by itself.

Historic conduct remains material. Later FCA authorisation does not cure an earlier unlawful promotion, unregistered service, customer-asset deficit, sanctions breach, misleading statement, or tax failure.

The current perimeter before 25 October 2027

Product classification comes first

The current UK answer depends on the product’s legal and economic characteristics.

A token can already be:

  • a share, debenture, government or public security, warrant, certificate, or another specified investment;

  • a unit in a collective investment scheme;

  • an option, future, contract for differences, or another derivative;

  • electronic money;

  • a payment instrument or part of a payment service;

  • a deposit;

  • a consumer-credit product;

  • an insurance product;

  • an unregulated exchange token or utility token.

A security token can require authorisation under FSMA 2000 and the Financial Services and Markets Act 2000 (Regulated Activities) Order 2001. An electronic-money token can engage the Electronic Money Regulations 2011. Related transfer, account, redemption, or merchant functions can engage the Payment Services Regulations 2017.

The reviewer should classify each token stage separately:

  • initial sale;

  • present token;

  • staking receipt;

  • wrapper;

  • bridge representation;

  • vault share;

  • liquidity-pool token;

  • yield product;

  • tokenised asset;

  • NFT;

  • stablecoin.

A token described as a utility token can represent debt, equity, profit rights, pooled investment, or another specified investment. An NFT can represent a security, fund interest, debt claim, or fractional asset. The token label carries no independent legal effect.

The classification file should identify:

  • holder rights against an issuer;

  • voting rights;

  • repayment rights;

  • revenue or profit rights;

  • reserve claims;

  • redemption;

  • pooled investment;

  • discretionary management;

  • derivative exposure;

  • transferability;

  • standardisation;

  • promised appreciation;

  • reliance on an active management group;

  • secondary-market support.

The reviewer should compare the token terms with deployed code, white papers, sale documents, investor decks, marketing, and actual operations.

Current FCA cryptoasset registration

A UK cryptoasset exchange provider or custodian wallet provider within regulations 8, 14A and related provisions of the Money Laundering Regulations 2017 must register with the FCA before beginning in-scope business. The current requirement continues until the 2027 regime starts.

The exchange-provider definition reaches specified arrangements involving exchange between cryptoassets and money, exchange between cryptoassets, and qualifying intermediary conduct. The custodian-wallet definition reaches safeguarding or administering cryptoassets or private cryptographic keys for customers.

The territorial test asks whether the person carries on the relevant business in the United Kingdom. Relevant facts include:

  • UK incorporation or establishment;

  • UK offices;

  • UK employees or agents;

  • UK management;

  • UK operational teams;

  • UK wallet control;

  • contracts formed in the UK;

  • services performed from the UK.

The existence of one UK customer does not, alone, settle whether a foreign provider carries on business in the United Kingdom. The same foreign provider can still fall within the financial-promotion rules because those rules use a broader territorial test.

The registration file should contain:

  • the exact registered legal name;

  • company number;

  • approved trading names;

  • registered services;

  • registered domains;

  • business-plan submissions;

  • fit-and-proper records;

  • FCA correspondence;

  • inspection and remediation records;

  • annual returns;

  • current public-register evidence.

The registered entity should match the entity named in:

  • user terms;

  • wallet agreements;

  • application onboarding;

  • website footers;

  • privacy notices;

  • invoices;

  • payment instructions;

  • complaint channels;

  • customer support communications.

A group company cannot rely on another company’s registration merely because both use the same brand.

What MLR registration does not establish

MLR registration is not FSMA authorisation. It does not prove that the FCA approved the token, business model, custody architecture, solvency, disclosures, or investment merits.

An MLR-registered firm does not receive a general right to:

  • issue securities;

  • issue electronic money;

  • provide payment services;

  • accept deposits;

  • operate a securities venue;

  • manage investments;

  • advise on specified investments;

  • operate a collective investment scheme.

Ordinary unregulated cryptoasset activity does not generally receive Financial Ombudsman Service or Financial Services Compensation Scheme protection merely because the provider appears on the FCA’s MLR register.

The due-diligence report should describe the status precisely. “FCA registered under the Money Laundering Regulations” is accurate where supported. “FCA licensed,” “FCA approved,” or “fully regulated” may be misleading when the firm holds only MLR registration.

Financial promotions

Four lawful routes

The UK financial-promotion perimeter can apply even where the underlying spot cryptoasset service is not currently a regulated activity.

Since 8 October 2023, a firm marketing qualifying cryptoassets to UK consumers must use one of four routes:

  1. An FCA-authorised person communicates the promotion.

  2. An unauthorised person communicates a promotion approved by an authorised person with the required approval permission.

  3. An FCA-registered cryptoasset business communicates its own promotion under article 73ZA of the Financial Promotion Order.

  4. The communication satisfies another Financial Promotion Order exemption.

An electronic-money institution or payment institution is not an “authorised person” for section 21 merely because it holds permission under the Electronic Money Regulations or Payment Services Regulations.

A firm using a section 21 approver should produce:

  • the approver’s legal name;

  • the approver’s FCA permission;

  • each approval certificate;

  • approved wording;

  • media and territorial scope;

  • approval date;

  • expiry or withdrawal provisions;

  • supporting evidence reviewed by the approver;

  • monitoring records;

  • change-control procedures.

Approval of a communication is not approval of the token or issuer.

Territorial reach

Section 21 can apply to a communication made outside the United Kingdom where the communication is capable of having an effect in the United Kingdom.

The review should cover:

  • websites;

  • applications;

  • social media;

  • founder accounts;

  • influencer posts;

  • referral programs;

  • affiliate links;

  • event presentations;

  • online communities;

  • app-store descriptions;

  • email campaigns;

  • search advertising;

  • listing announcements;

  • press releases.

A statement that “UK persons are excluded” carries little weight when the platform accepts UK identity documents, addresses, payment methods, telephone numbers, IP addresses, and customer-support requests.

The project should preserve evidence of effective UK restrictions:

  • IP and device controls;

  • residence checks;

  • rejected UK identification;

  • blocked sterling payment methods;

  • marketing exclusions;

  • exception logs;

  • closed UK accounts;

  • customer-asset return records.

Promotion content and customer journey

Cryptoasset promotions must be fair, clear, and not misleading. Current FCA rules include prescribed risk warnings, a 24-hour cooling-off period for first-time investors, personalised risk warnings, client categorisation, and appropriateness assessments. Incentives to invest face restrictions.

The reviewer should test the complete customer journey rather than the final advertisement alone.

Material review points include:

  • prominence of risk warnings;

  • omission of risk information;

  • ease of dismissing warnings;

  • cooling-off timing;

  • client categorisation;

  • appropriateness questions;

  • scoring;

  • repeat attempts;

  • referral rewards;

  • staking or yield claims;

  • price claims;

  • reserve claims;

  • insurance claims;

  • licence claims;

  • comparison with cash or deposits;

  • loss and insolvency disclosures.

An unlawful communication can breach FSMA section 21. The offence can carry up to two years’ imprisonment, an unlimited fine, or both.

Promotions during the 2027 transition

A firm using a section 21 approver may continue doing so before commencement. A timely 2027 applicant may continue under the applicable saving while its application remains under determination.

A firm that does not apply must run off its UK business before the new regime begins. An authorised approver should not approve promotions for a person conducting regulated activity without the required permission.

Money laundering, Travel Rule, and sanctions

Operating duties

An in-scope cryptoasset business must maintain a documented risk assessment and proportionate controls under the Money Laundering Regulations 2017.

The file should address:

  • customer identification;

  • beneficial-owner verification;

  • purpose and intended nature;

  • source of funds;

  • source of wealth;

  • politically exposed persons;

  • sanctions;

  • transaction monitoring;

  • blockchain analytics;

  • suspicious-activity reporting;

  • record retention;

  • employee screening;

  • training;

  • independent testing;

  • group controls;

  • proliferation-financing risk.

The due-diligence team should sample actual customer and transaction files. A policy describes intended conduct. It does not prove operation.

The sample should include:

  • low-, medium-, and high-risk customers;

  • legal persons and trusts;

  • self-hosted wallets;

  • mixers and privacy tools;

  • bridges;

  • chain hopping;

  • high-risk jurisdictions;

  • transaction-monitoring alerts;

  • manually closed alerts;

  • suspicious-activity reports;

  • law-enforcement requests;

  • frozen accounts;

  • customer exits.

Travel Rule

The UK cryptoasset Travel Rule has applied since 1 September 2023. A cryptoasset business must collect, verify, transmit, and retain prescribed originator and beneficiary information for covered transfers.

Use of a third-party Travel Rule vendor does not transfer the firm’s legal responsibility. The firm should assess the counterparty, missing data, rejection rules, secure transmission, data retention, and treatment of self-hosted wallets.

The DD review should reconcile:

  • blockchain transactions;

  • internal transfer records;

  • Travel Rule messages;

  • counterparty VASP identity;

  • missing information;

  • manual overrides;

  • rejected transfers;

  • delayed transfers;

  • exception approvals.

Enhanced due diligence after 30 June 2026

The Money Laundering and Terrorist Financing (Amendment) Regulations 2026 changed regulation 33 from 30 June 2026.

Mandatory country-based enhanced due diligence now applies to business relationships or relevant transactions involving a person established in a FATF jurisdiction subject to a “Call for Action.” It no longer applies automatically merely because a country appears on FATF’s “Increased Monitoring” list.

The firm must still treat FATF evaluations and other geographic evidence as risk factors. It must apply enhanced measures whenever the assessed money-laundering or terrorist-financing risk is high.

The reviewer should check that policies, risk engines, country lists, and customer-rating logic changed on 30 June 2026. Retaining the broader former list does not necessarily breach the law, but the firm should explain its risk basis.

Sanctions

UK financial sanctions apply independently of MLR registration and customer risk ratings.

Cryptoassets can constitute funds or economic resources. The project must identify and freeze property owned or controlled by a designated person where the applicable sanctions regulation requires it. It must also comply with reporting, licensing, and anti-circumvention rules.

Since 28 January 2026, the UK Sanctions List is the sole UK government list for sanctions designations. Systems relying only on the former OFSI Consolidated List are obsolete.

The sanctions review should address:

  • designated persons;

  • ownership and control;

  • wallet addresses;

  • related addresses;

  • counterparties;

  • validators;

  • market makers;

  • bridges;

  • mixers;

  • liquidity pools;

  • jurisdictions;

  • transaction routes;

  • indirect benefits;

  • circumvention.

The reviewer should identify who can:

  • reject a transaction;

  • freeze an account;

  • isolate a wallet;

  • disable withdrawals;

  • block an address;

  • suspend the interface;

  • seek an OFSI licence.

A public claim that the protocol cannot act should be compared with the project’s actual code, keys, interface control, treasury powers, and vendor relationships.

The 2027 FSMA regime

Commencement and application window

The Financial Services and Markets Act 2000 (Cryptoassets) Regulations 2026 were made on 4 February 2026. The main regime begins on 25 October 2027.

Firms wishing to conduct a new regulated cryptoasset activity must obtain FCA authorisation under Part 4A of FSMA. A firm already authorised under FSMA must obtain the necessary variation of permission.

The application window runs from 30 September 2026 to 28 February 2027.

The transaction file should identify:

  • activities requiring permission;

  • applicant entity;

  • proposed senior managers;

  • UK establishment;

  • application timetable;

  • application owner;

  • capital plan;

  • systems gap analysis;

  • outsourcing arrangements;

  • custody model;

  • wind-down plan;

  • regulatory business plan;

  • board approval;

  • evidence package.

A general intention to apply is not sufficient. The target should have an activity map, completed workstreams, accountable executives, budget, and application evidence.

No automatic conversion

The following do not convert automatically into the new cryptoasset permission:

  • MLR registration;

  • existing FSMA authorisation;

  • payment-institution status;

  • electronic-money institution status;

  • current use of a section 21 approver.

A firm within the new perimeter must submit the appropriate Part 4A application or variation.

A buyer should not value a current MLR registration as though it guarantees 2027 authorisation. The FCA will assess the Threshold Conditions, management, financial resources, systems, controls, custody, operational resilience, and conduct arrangements.

Saving and transition

A firm applying within the application window may use the statutory saving provisions if the application and business satisfy the specified conditions. The saving permits continuity while the FCA decides the application, subject to the statutory limit.

A firm applying late and lacking permission at commencement does not receive the same saving. It enters a narrower transition for activity required to perform a contract entered before the transition began. It cannot enter new contracts with existing or new UK customers.

A firm that does not apply must run off the UK business before 25 October 2027. Continuing afterwards can breach FSMA section 19. An already authorised firm acting outside its permission can breach section 20.

The acquisition agreement should not assume that a pending application will be approved before closing. It should address refusal, restrictions, delayed determination, required restructuring, and run-off.

Qualifying cryptoassets and future activity mapping

Qualifying cryptoassets

The 2026 Regulations introduce the concept of a “qualifying cryptoasset.”

The statutory test focuses on fungibility and transferability. The exclusions include relevant specified investments, electronic money, official money, central-bank digital currency, and narrow closed-loop or redeem-only instruments.

The reviewer should classify:

  • the underlying token;

  • each wrapped version;

  • bridged versions;

  • receipt tokens;

  • liquid-staking tokens;

  • liquidity-pool tokens;

  • vault shares;

  • tokenised securities;

  • NFTs;

  • in-game assets;

  • loyalty or closed-loop tokens.

A genuinely unique and nonfungible asset may fall outside the qualifying-cryptoasset definition. Fractionalisation, common economic rights, standardised collections, or interchangeable claims can alter the result.

An asset outside the qualifying-cryptoasset category is not necessarily unregulated. It may remain a security, collective investment, electronic-money instrument, payment product, deposit, derivative, or consumer-credit product.

Qualifying stablecoins

A qualifying stablecoin is a qualifying cryptoasset that seeks to maintain a stable value by reference to a fiat currency where fiat or other assets are held for that purpose.

The analysis should identify:

  • reference currency;

  • issuer;

  • redemption undertaking;

  • backing assets;

  • asset owner;

  • reserve custodian;

  • mint and burn process;

  • reserve income;

  • insolvency rights;

  • chain and bridge versions;

  • secondary-market support;

  • suspension powers.

A token using an algorithmic mechanism without relevant backing assets may fall outside that definition. It can still engage other laws.

New regulated activities

The 2026 Regulations add activities concerning qualifying cryptoassets and qualifying stablecoins to the Regulated Activities Order.

The main activities are:

  • issuing a qualifying stablecoin;

  • safeguarding qualifying cryptoassets or arranging safeguarding;

  • operating a qualifying cryptoasset trading platform;

  • dealing as principal;

  • dealing as agent;

  • arranging deals;

  • arranging qualifying cryptoasset staking.

Each activity requires a separate actor analysis.

A single user journey can contain several activities. An exchange may operate a trading platform, deal as principal, arrange transactions, safeguard assets, and arrange staking. The permissions must match the complete journey.

Safeguarding and control

The future safeguarding activity uses a functional concept of control. A person can control a qualifying cryptoasset through any means that permits the person to bring about a transfer.

Relevant powers include:

  • possession of a private key;

  • one MPC share;

  • recovery authority;

  • transaction approval;

  • wallet-policy control;

  • withdrawal whitelisting;

  • smart-contract admin power;

  • authority over a transfer agent;

  • emergency override.

A contract describing the service as non-custodial does not determine the result.

Trading platforms and dealing

The reviewer should identify whether a person:

  • brings together buying and selling interests;

  • applies non-discretionary execution rules;

  • chooses admitted assets;

  • controls order priority;

  • operates matching;

  • acts as principal;

  • earns a spread;

  • provides liquidity;

  • internalises orders;

  • routes trades;

  • settles transactions.

A front end can perform more than technical publication where it controls market access, order submission, routing, fees, asset selection, or execution.

Arranging

Arranging can include conduct that brings about or makes arrangements for another person to buy, sell, subscribe for, or underwrite a qualifying cryptoasset.

Relevant actors can include:

  • brokers;

  • routers;

  • aggregators;

  • intermediaries;

  • affiliate introducers;

  • application operators;

  • protocol interfaces;

  • token distributors.

The reviewer should identify each entity’s contractual role, technical function, fee, control, and customer communication.

Staking

The future staking activity covers arrangements made on behalf of another person for a qualifying cryptoasset to be used in blockchain validation.

A technical-services exclusion can apply where the person only enables participation and does not hold itself out to the public as offering staking.

The review should determine:

  • who offers the service;

  • who holds the asset;

  • who selects validators;

  • who initiates staking;

  • who controls withdrawal;

  • whether assets are pooled;

  • lock-up period;

  • slashing allocation;

  • reward calculation;

  • commissions;

  • sub-staking;

  • receipt-token rights.

The technical exclusion should not be assumed where the provider markets returns, chooses validators, controls withdrawal, aggregates customers, or receives a service spread.

Lending and borrowing

The 2026 Regulations do not make every activity called crypto lending a single standalone regulated activity. The legal result depends on the actual functions.

A lending product can involve:

  • dealing;

  • arranging;

  • safeguarding;

  • collective investment;

  • a security;

  • consumer credit;

  • payments;

  • deposit taking;

  • staking;

  • derivatives.

The FCA’s final rules impose specific conduct requirements on authorised cryptoasset firms offering lending or borrowing services. The review should examine consent, disclosures, appropriateness, collateral, records, negative balances, liquidation, title transfer, and insolvency.

Territorial reach and international firms

UK consumer activity

The 2026 Regulations amend FSMA’s territorial rules for the new activities.

Transactions involving sale or subscription to or from a UK consumer can be treated as UK activity under the statutory tests. Safeguarding or staking for a UK consumer can also fall within the UK perimeter, subject to the detailed statutory exceptions.

A consumer is generally a UK individual acting outside a trade, business, or profession for these provisions.

The future test is broader than asking where the service company was incorporated. The reviewer should examine:

  • UK customers;

  • UK-facing interfaces;

  • sterling rails;

  • UK support;

  • UK marketing;

  • UK affiliates;

  • UK contract formation;

  • location of wallet control;

  • location of decision-makers.

The statute does not create one general reverse-solicitation safe harbour equivalent to MiCA Article 61. The exact activity and territorial provisions control.

UK presence

The FCA’s stated baseline for an international applicant is a UK legal entity with sufficient UK presence, personnel, management, and decision-making.

An overseas qualifying cryptoasset trading platform may be able to use a UK branch in limited circumstances. Relevant factors include home-state supervision, comparability, client types, business model, and the FCA’s ability to supervise the firm.

The target should document:

  • location of executive management;

  • board and committee decisions;

  • risk management;

  • compliance staff;

  • wallet authority;

  • product approvals;

  • listing decisions;

  • incident command;

  • premises;

  • payroll;

  • delegated authorities;

  • regulator access.

A UK applicant can fail the substance test where an offshore group company retains every production key, operational decision, customer record, and incident-response power.

Authorisation standards and final FCA rules

On 30 June 2026, the FCA published its final rule package for the new regime.

The principal publications cover:

  • admissions, disclosures, and cryptoasset market abuse;

  • qualifying stablecoin issuance;

  • regulated cryptoasset activities;

  • prudential requirements;

  • application of the FCA Handbook;

  • Consumer Duty guidance;

  • operational-resilience guidance;

  • international-firm guidance.

An applicant must meet the Threshold Conditions and maintain compliance after authorisation. Relevant matters include:

  • legal status;

  • UK location;

  • effective supervision;

  • suitable business model;

  • adequate resources;

  • fit and proper controllers;

  • competent senior management;

  • systems and controls;

  • financial-crime controls;

  • operational resilience;

  • custody;

  • complaints;

  • outsourcing;

  • wind-down.

The Senior Managers and Certification Regime applies to the relevant authorised firms and individuals. The project should identify senior-management functions, statements of responsibilities, prescribed responsibilities, certification populations, conduct rules, and fitness assessments.

Prudential requirements

The final prudential rules use COREPRU and CRYPTOPRU requirements according to the firm’s activity and structure.

The file should contain:

  • prudential categorisation;

  • capital calculations;

  • liquid-asset calculations;

  • fixed-overhead data;

  • concentration risks;

  • intra-group exposures;

  • stress testing;

  • recovery indicators;

  • wind-down funding;

  • insurance;

  • financial projections;

  • auditor input.

A token treasury does not necessarily qualify as regulatory capital or liquid assets.

Consumer Duty

Authorised firms serving retail customers must apply the Consumer Duty to the regulated activity and related customer journey.

The review should test:

  • product design;

  • target market;

  • fair value;

  • customer understanding;

  • customer support;

  • foreseeable harm;

  • vulnerability;

  • complaint data;

  • outcome testing;

  • board reporting.

The Duty applies to actual customer outcomes. A disclosure-heavy process can still fail where product design, fees, liquidation mechanics, or customer support produce poor outcomes.

Outsourcing

Outsourcing does not transfer responsibility from the authorised firm.

The regulated entity should retain:

  • information access;

  • operational knowledge;

  • audit rights;

  • FCA access;

  • incident rights;

  • security requirements;

  • business-continuity rights;

  • termination rights;

  • migration assistance;

  • control over critical decisions.

High-risk arrangements include:

  • offshore custody without direct oversight;

  • offshore staff controlling every key;

  • no UK incident authority;

  • no tested vendor exit;

  • agreements that limit FCA access;

  • material services performed under informal group arrangements.

Public offers, admissions, and disclosure

Public-offer restriction

From 25 October 2027, a person generally cannot offer a qualifying cryptoasset to the UK public unless an exception applies.

Material exceptions include:

  • aggregate UK consideration not exceeding £1 million;

  • offers only to qualified investors;

  • offers to fewer than 150 nonqualified persons in the United Kingdom;

  • acquisitions requiring at least £100,000 per purchaser;

  • authorised qualifying stablecoin issuance;

  • offers connected with admission to a UK qualifying cryptoasset trading platform;

  • qualifying employee or director offers.

Connected offers are aggregated where the statutory conditions apply. The review should not divide one financing into several nominally separate sub-threshold offers.

The file should identify:

  • offeror;

  • issuer;

  • creator;

  • purchaser classes;

  • UK purchaser count;

  • consideration;

  • connected offers;

  • offer dates;

  • marketing;

  • admission plans;

  • exemptions;

  • transfer restrictions.

Disclosure documents

The future regime requires a qualifying cryptoasset disclosure document for relevant offers and admissions.

The disclosure should address:

  • holder rights and obligations;

  • issuer or creator;

  • controllers;

  • token technology;

  • protocol;

  • consensus method;

  • minting;

  • burning;

  • supply;

  • distribution;

  • decision rights;

  • conflicts;

  • risks;

  • underlying assets;

  • stable-value mechanism;

  • service providers;

  • custody;

  • material incidents.

Certain exempt offers at or above the statutory materiality threshold also require specified disclosure.

The reviewer should compare the disclosure with:

  • live smart contracts;

  • proxy and admin settings;

  • treasury wallets;

  • supply data;

  • vesting;

  • market-maker loans;

  • exchange arrangements;

  • security audits;

  • incidents;

  • financial condition;

  • related parties.

A technically correct description can still mislead when it omits a material control, dependency, conflict, or commercial arrangement.

Civil liability

The 2027 provisions create potential compensation liability for an untrue or misleading statement or a required omission in relevant disclosure.

The project should preserve:

  • drafting responsibility;

  • verification notes;

  • source evidence;

  • board approval;

  • expert consents;

  • change-monitoring records;

  • supplementary disclosures;

  • publication timestamps.

A disclaimer cannot remove statutory liability where the statute prohibits exclusion.

Cryptoasset market abuse

The 2027 market-abuse rules apply to qualifying cryptoassets admitted, or requested for admission, to a UK qualifying cryptoasset trading platform and related instruments.

The regime addresses:

  • inside information;

  • insider dealing;

  • unlawful disclosure;

  • market manipulation.

Inside information includes precise, nonpublic information relating directly or indirectly to the asset and likely to have a material price effect.

Relevant information can include:

  • listing decisions;

  • token unlocks;

  • treasury sales;

  • minting;

  • burning;

  • buybacks;

  • reserve problems;

  • redemptions;

  • security incidents;

  • protocol upgrades;

  • governance votes affecting value;

  • insolvency;

  • market-maker changes;

  • regulatory action.

Manipulation can include:

  • false or misleading signals;

  • artificial pricing;

  • wash trading;

  • spoofing;

  • undisclosed price support;

  • dissemination of false information;

  • abuse of dominant positions;

  • manipulative algorithmic orders;

  • undisclosed media conflicts.

The FCA’s final rules require platforms and relevant intermediaries to operate admission, monitoring, detection, escalation, and reporting controls. Larger firms should be prepared to monitor on-chain activity.

The DD file should contain:

  • inside-information procedures;

  • disclosure decisions;

  • insider lists;

  • wallet surveillance;

  • employee-trading records;

  • market-maker instructions;

  • abnormal-trading alerts;

  • escalation files;

  • suspicious transaction or order reports;

  • listing and delisting records.

Stablecoins

Current law

Before the 2027 commencement, a stablecoin must be classified under the current statutes.

Relevant questions include whether it constitutes:

  • electronic money;

  • a payment service;

  • a deposit;

  • a security;

  • a collective investment;

  • a debt claim;

  • an exchange token;

  • another contractual asset.

The reviewer should identify:

  • issuer;

  • legal claim;

  • reference currency;

  • redemption;

  • reserve ownership;

  • reserve composition;

  • yield;

  • holder priority;

  • insolvency rights;

  • payment use;

  • merchant use;

  • transfer functionality.

An issuer cannot rely on the future qualifying-stablecoin category as though it were already an operative permission.

FCA-regulated qualifying stablecoins from 2027

Issuing a qualifying stablecoin from a UK establishment becomes a regulated activity.

The FCA’s final stablecoin rules address:

  • backing assets;

  • statutory trust treatment;

  • segregation;

  • redemption;

  • valuation;

  • reconciliation;

  • custody;

  • disclosures;

  • shortfalls;

  • wind-down.

The issuer should reconcile:

  • outstanding supply;

  • backing-account balances;

  • asset eligibility;

  • custody records;

  • mint and burn records;

  • redemption requests;

  • failed or delayed redemptions;

  • reserve income;

  • liens and set-off;

  • financial statements.

A reserve attestation dated before a supply increase does not prove current backing.

Systemic sterling stablecoins

HM Treasury can recognise a stablecoin payment system or service provider as systemic. The Bank of England then supervises the financial-stability aspects, alongside the FCA’s conduct supervision.

On 22 June 2026, the Bank published a policy statement and draft Code of Practice. The proposed model requires at least 30 percent of backing assets at the Bank and permits up to 70 percent in short-dated UK government securities. The draft also proposed an initial £40 billion issuance guardrail for each systemic stablecoin. The Code was not final law on 22 July 2026.

A project should not present the draft Bank requirements as a current licence or final permission.

The stablecoin transaction file should contain:

  • proposed FCA route;

  • systemic assessment;

  • HM Treasury engagement;

  • Bank engagement;

  • backing model;

  • liquidity model;

  • redemption stress tests;

  • transition plan;

  • final-rule change budget.

Draft stablecoin payment amendment

HM Treasury published a draft amendment to the 2026 Regulations on 21 April 2026. It seeks to clarify specified stablecoin payment use and other perimeter issues.

The instrument remained draft on the As-of Date. It should not be treated as current law or a settled exemption.

Custody, property, and insolvency

Current custody analysis

Current MLR registration does not itself create a CASS trust, customer-asset segregation rule, or insolvency priority for ordinary spot cryptoassets.

The legal opinion should answer:

  1. Who owns the asset?

  2. Who controls transfer?

  3. Which entity contracts with the customer?

  4. Are assets separated in wallets, records, and accounts?

  5. Can the provider lend, pledge, stake, or reuse them?

  6. Who bears a shortfall?

  7. What happens on insolvency?

  8. Who receives forks, airdrops, rewards, and voting rights?

The evidence should include:

  • customer agreements;

  • trust declarations;

  • wallet inventory;

  • key-control records;

  • customer ledgers;

  • reconciliations;

  • shortfall files;

  • sub-custody contracts;

  • lien waivers;

  • set-off waivers;

  • staking consents;

  • insurance;

  • insolvency opinions.

One omnibus wallet can still support customer ownership if the legal and accounting structure works. The project must prove the result rather than assume it.

Property (Digital Assets etc) Act 2025

The Property (Digital Assets etc) Act 2025 confirms that a thing is not prevented from attracting personal-property rights merely because it is neither a thing in possession nor a thing in action.

The Act extends to England and Wales and Northern Ireland. It does not extend to Scotland.

The Act does not determine:

  • which digital assets are property;

  • who owns a token;

  • how title transfers;

  • whether a trust exists;

  • security priority;

  • tracing;

  • good-faith acquisition;

  • insolvency distribution.

Those questions remain fact-specific and can require separate English, Northern Irish, or Scots advice.

Future CASS treatment

From 2027, the FCA’s CASS 17 rules apply to relevant safeguarding of qualifying cryptoassets. The rules address ownership rights, records, reconciliations, key management, trust treatment, custody chains, and return of assets.

Relevant specified investment cryptoassets remain subject to the applicable CASS 6 rules. Client money remains subject to CASS 7 where applicable.

The reviewer should test:

  • customer legal title;

  • on-chain segregation;

  • internal ledger segregation;

  • daily records;

  • custody-chain approval;

  • key ceremonies;

  • key backup;

  • business continuity;

  • shortfall funding;

  • return process;

  • wind-down transfer.

A custody architecture designed only for current MLR compliance may require material rebuilding before 2027.

Staking, DeFi, lending, and DAOs

Current analysis

Before 2027, staking can still engage existing law where it involves:

  • a security;

  • a collective investment;

  • electronic money;

  • a payment service;

  • custody;

  • money laundering registration;

  • a financial promotion;

  • consumer credit;

  • a derivative.

The reviewer should not state that staking is unregulated solely because the dedicated future activity has not commenced.

Future staking rules

The 2027 regime regulates arranging qualifying cryptoasset staking.

The FCA’s final conduct rules address customer consent, contractual terms, risk disclosures, records, ongoing arrangements, rewards, fees, lock-up, and withdrawal. Liquid-staking receipts require their own classification.

The due-diligence review should determine:

  • who owns the staked asset;

  • who controls withdrawal;

  • whether assets are pooled;

  • validator selection;

  • lock-up;

  • unstaking;

  • slashing;

  • reward calculation;

  • provider spread;

  • sub-staking;

  • receipt-token rights;

  • insolvency treatment.

A guaranteed return funded by the provider differs from pass-through protocol rewards.

DeFi

The future statute does not create a blanket exemption for decentralised finance.

The FCA’s final policy treats an identifiable person controlling or conducting a regulated activity as potentially within scope. The analysis remains fact-specific, and the FCA plans further DeFi guidance.

The review should identify who:

  • deployed contracts;

  • controls upgrades;

  • operates the main interface;

  • selects pools;

  • routes transactions;

  • controls fees;

  • chooses listed assets;

  • controls oracles;

  • operates relayers;

  • controls liquidations;

  • receives protocol revenue;

  • markets to UK users;

  • provides support;

  • can suspend access.

A protocol can decentralise validation while founders or service companies retain product control.

DAOs

A DAO, foundation, association, or foreign wrapper can own assets and allocate authority. It does not confer FCA permission.

The reviewer should reconcile:

  • token voting;

  • delegated voting;

  • quorum;

  • founder concentration;

  • multisig authority;

  • emergency powers;

  • foundation directors;

  • service-company contracts;

  • treasury control;

  • intellectual-property ownership.

Where no effective wrapper exists, participants can face partnership, agency, unincorporated-association, fiduciary, or direct-principal arguments.

Corporate integrity, management, and intellectual property

The corporate review should reconcile six forms of ownership:

  • equity;

  • tokens;

  • intellectual property;

  • domains and applications;

  • wallets and keys;

  • contractual revenue and data rights.

The data room should contain:

  • incorporation and good-standing records;

  • constitutional documents;

  • shareholder and beneficial-owner registers;

  • cap table;

  • options, warrants, and convertibles;

  • token allocations;

  • board and shareholder approvals;

  • foundation or DAO records;

  • intercompany agreements;

  • employment and contractor assignments;

  • contributor agreements;

  • open-source inventory;

  • domain records;

  • repository access;

  • wallet-control resolutions.

Undisclosed token entitlements can transfer substantial value without appearing on the equity cap table.

A foundation may state that it controls protocol policy while another company owns the code and a third company controls the treasury. The reviewer should trace each right to an executed instrument.

Open-source distribution does not prove that the project owned the code before publication. The review should identify attribution, copyleft, source-disclosure, patent, trademark, and compatibility duties.

Data protection, marketing technology, and cybersecurity

Data protection

The principal UK data laws include:

  • UK GDPR;

  • Data Protection Act 2018;

  • Privacy and Electronic Communications Regulations 2003;

  • Data (Use and Access) Act 2025.

Most remaining data-protection provisions of the 2025 Act commenced on 5 February 2026. The mandatory data-protection complaints process took effect on 19 June 2026.

An organisation must provide a route for data-protection complaints, acknowledge a complaint within 30 days, investigate without undue delay, keep the complainant informed, and communicate the outcome.

The 2025 Act also raised the maximum PECR fine to £17.5 million or 4 percent of worldwide annual turnover, whichever is higher.

Wallet addresses, IP addresses, device identifiers, identity records, support messages, transaction histories, sanctions matches, and risk scores can constitute personal data when linked to an individual.

The review should identify:

  • controllers;

  • joint controllers;

  • processors;

  • purposes;

  • lawful bases;

  • notices;

  • consent;

  • direct marketing;

  • profiling;

  • automated decisions;

  • retention;

  • international transfers;

  • security;

  • data-subject rights;

  • complaint handling;

  • breaches.

Writing data to a public ledger does not remove UK data-protection duties. The project should identify what is written on-chain and whether personal data can be minimised, corrected, restricted, or dissociated.

Cybersecurity and operational resilience

The current review should connect technical findings to existing MLR, data, contractual, consumer, and sectoral duties.

From 2027, authorised firms also face the FCA’s operational-resilience requirements and final cryptoasset guidance.

The evidence should include:

  • system inventory;

  • architecture diagrams;

  • key architecture;

  • code repositories;

  • deployment records;

  • bytecode verification;

  • smart-contract audits;

  • penetration tests;

  • incident reports;

  • recovery tests;

  • cloud contracts;

  • oracle dependencies;

  • bridge dependencies;

  • sequencer dependencies;

  • service-level agreements;

  • vendor exit plans.

An audit of an earlier contract version does not establish the security of the live deployment.

Tax and the Cryptoasset Reporting Framework

Current tax review

HMRC generally determines cryptoasset tax by the nature of the asset, transaction, and taxpayer.

Relevant taxes can include:

  • Corporation Tax;

  • Income Tax;

  • Capital Gains Tax;

  • Corporation Tax on chargeable gains;

  • National Insurance contributions;

  • PAYE;

  • VAT;

  • stamp taxes;

  • Digital Services Tax.

The DD review should cover:

  • token-sale proceeds;

  • treasury disposals;

  • token-for-token exchanges;

  • staking rewards;

  • lending returns;

  • mining;

  • airdrops;

  • employee and contractor tokens;

  • vesting;

  • withholding;

  • transfer pricing;

  • permanent establishments;

  • VAT;

  • loss recognition;

  • related-party transactions.

Cryptoassets received from employment can constitute money’s worth and can require PAYE and National Insurance treatment. Staking, lending, and DeFi receipts can also constitute taxable income.

The reviewer should reconcile tax returns, financial statements, wallet activity, token allocations, and payroll.

Cryptoasset Reporting Framework

The UK Cryptoasset Reporting Framework commenced on 1 January 2026.

A UK reporting cryptoasset service provider must collect due-diligence information and transaction data from that date. The first report covers 1 January to 31 December 2026 and is due by 31 May 2027. Registration and user notification are due by 31 January 2027.

Required information can include:

  • customer name;

  • address;

  • tax residence;

  • taxpayer identification number;

  • controlling-person information;

  • asset type;

  • transaction type;

  • units;

  • value.

The first DD review should test:

  • RCASP classification;

  • UK nexus;

  • onboarding forms;

  • self-certification;

  • controlling-person checks;

  • transaction aggregation;

  • valuation;

  • XML readiness;

  • user notices;

  • vendor arrangements;

  • record retention.

Penalties can reach £300 per user for specified failures.

Future stablecoin tax change

The government published draft legislation on 13 July 2026 to treat eligible stablecoins more like money for tax purposes.

The planned effective dates are:

  • 6 April 2027 for individuals and trustees;

  • 1 April 2027 for companies.

The measure remained draft Finance Bill legislation on 22 July 2026. Current law still controls until enactment and commencement.

Changes of control and acquisitions

Current MLR approval

A person proposing to acquire or increase control over an FCA-registered cryptoasset business must obtain the required FCA approval before completing the acquisition.

Acquiring control without approval can constitute a criminal offence.

Amendments effective from 30 June 2026 introduced a two-track analysis.

Where a person becomes a beneficial owner under regulations 5 or 6, the MLR beneficial-owner thresholds and fit-and-proper test apply.

Where no beneficial owner exists in the controller chain, FSMA controller thresholds and Part XII assessment criteria apply.

The control review should include:

  • direct shares;

  • indirect shares;

  • voting rights;

  • associates;

  • options;

  • convertibles;

  • board rights;

  • veto rights;

  • management agreements;

  • acting-in-concert arrangements;

  • token-based voting;

  • treasury authority;

  • private-key control.

The buyer should not obtain de facto management or wallet control before FCA approval.

Future Part XII treatment

An authorised cryptoasset firm will fall within the applicable FSMA change-in-control regime from 2027.

The transaction team should map:

  • qualifying holdings;

  • indirect control;

  • increases and decreases through statutory thresholds;

  • close links;

  • controller fitness;

  • financial soundness;

  • source of acquisition funds;

  • group supervision;

  • money-laundering risk.

Separate applications can be required where the target also holds payment, electronic-money, investment, banking, or insurance permissions.

National Security and Investment Act

The National Security and Investment Act 2021 can apply to Web3 acquisitions involving cryptographic authentication, artificial intelligence, data infrastructure, computing hardware, critical suppliers, defence, quantum technology, or other sensitive activities.

Mandatory notification can apply where an acquisition of a qualifying entity in one of 17 sectors crosses:

  • 25 percent or less to more than 25 percent;

  • 50 percent or less to more than 50 percent;

  • less than 75 percent to 75 percent or more;

  • voting rights permitting passage or prevention of a class of resolution.

A completed mandatory transaction without approval is void and can produce civil or criminal penalties.

The government can also call in transactions based on material influence. Asset acquisitions can be called in even though mandatory notification generally focuses on entities.

An overseas target can fall within scope where it carries on UK activities or supplies goods or services to the United Kingdom.

The initial review period is 30 working days after acceptance of a notification.

The DD review should identify:

  • encryption and authentication technology;

  • AI systems;

  • sensitive datasets;

  • government customers;

  • critical infrastructure;

  • dual-use technology;

  • foreign-government investors;

  • foreign acquirer ownership;

  • rights over source code;

  • access to sensitive systems.

Competition review

A transaction can also require Competition and Markets Authority analysis under the Enterprise Act 2002.

The parties should assess:

  • UK turnover;

  • shares of supply;

  • overlapping services;

  • vertical relationships;

  • data concentration;

  • wallet, exchange, custody, or payment concentration;

  • minority control and material influence.

Competition clearance and National Security and Investment Act clearance are separate.

Regulatory status verification

A reliable United Kingdom status check should follow these steps:

  1. Identify the exact legal entity.

  2. Search the FCA Financial Services Register and MLR records.

  3. Obtain each registration, permission, variation, exemption, and approval.

  4. Identify the permitted services and products.

  5. Identify restrictions, requirements, and undertakings.

  6. Compare the status with user terms and live operations.

  7. Review all trading names, domains, and applications.

  8. Review FCA warnings and enforcement records.

  9. Review regulator correspondence.

  10. Repeat the check before signing and closing.

Particular caution applies to these statements:

  • “FCA regulated” based only on MLR registration;

  • “FCA approved token” based on registration or promotion approval;

  • “FSCS protected” for ordinary cryptoassets;

  • “authorised payment provider” used to imply crypto permission;

  • “stablecoin authorised” before 2027 permission;

  • “2027 compliant” without an FCA application and evidence plan;

  • “Bank of England approved” based on draft systemic rules.

Red flags and transaction treatment

Stop or restructure

The following findings normally require suspension, abandonment, or restructuring before closing:

  • unregistered current cryptoasset exchange or custody activity;

  • unlawful UK financial promotions;

  • a security token handled as an unregulated exchange token;

  • electronic money or payment services without authority;

  • an unlawful collective investment or derivative;

  • customer-asset commingling or a material shortfall;

  • false FCA, FSCS, reserve, or insurance statements;

  • sanctions dealings or frozen-property failures;

  • a missing or unworkable 2027 authorisation plan;

  • an entity performing activities outside the proposed permission;

  • inadequate UK management or presence;

  • unapproved current control acquisition;

  • an NSI mandatory transaction without clearance;

  • missing ownership of core code, domains, or wallets;

  • undisclosed minting, upgrade, listing, treasury, or withdrawal powers;

  • market manipulation or undisclosed price support.

Conditions precedent

A matter can support a condition precedent where an objective cure exists:

  • MLR registration;

  • FSMA authorisation or variation;

  • payment or electronic-money authorisation;

  • filing of a complete 2027 application;

  • FCA change-of-control approval;

  • NSI clearance;

  • compliant promotion approval;

  • customer-asset segregation;

  • custody migration;

  • trust documentation;

  • reserve funding;

  • key rotation;

  • intellectual-property assignment;

  • contract novation;

  • Travel Rule remediation;

  • sanctions remediation;

  • CARF implementation;

  • disclosure correction;

  • customer re-papering;

  • UK staffing and management.

The condition should identify the exact document, register entry, regulator letter, technical test, or other evidence required.

Price, escrow, and indemnity

Operational repair does not remove historic liability.

Transaction protection may be required for:

  • historic unlawful promotions;

  • unregistered activity;

  • securities or payment claims;

  • customer-asset losses;

  • reserve deficiencies;

  • AML failures;

  • sanctions breaches;

  • market abuse;

  • tax;

  • CARF failures;

  • data breaches;

  • employment;

  • intellectual-property defects;

  • regulator investigations.

The provision should define:

  • covered period;

  • claimant group;

  • loss measure;

  • limitation period;

  • conduct of claims;

  • settlement rights;

  • available security.

Monitored remediation

Lower-severity matters should remain open only where the transaction documents identify:

  • exact task;

  • accountable person;

  • deadline;

  • required evidence;

  • reporting frequency;

  • buyer access;

  • consequence of non-completion.

A general covenant to improve compliance is not an adequate remedy.

Priority evidence request

Corporate and ownership

Current group chart.
Formation and good-standing records.
Constitutional documents.
Shareholder and beneficial-owner registers.
Cap table, options, warrants, convertibles, and side letters.
Token allocation and voting records.
Board, committee, foundation, and DAO records.
Intercompany agreements.

Current permissions and promotions

  • FCA MLR registration.

  • FSMA permissions.

  • Payment Services Regulations permissions.

  • Electronic Money Regulations permissions.

  • Section 21 approval records.

  • Article 73ZA analysis.

  • Register extracts.

  • FCA correspondence.

  • Warning and enforcement checks.

  • Promotion archives.

  • Cooling-off and appropriateness records.

2027 authorisation

  • Regulated-activity map.

  • Applicant-entity decision.

  • Application timetable.

  • Threshold Conditions assessment.

  • Regulatory business plan.

  • Senior-manager map.

  • UK presence plan.

  • Capital and liquidity calculations.

  • Custody gap analysis.

  • Consumer Duty assessment.

  • Operational-resilience assessment.

  • Wind-down plan.

Tokens, offers, and markets

  • Current and historic white papers.

  • Token classification opinions.

  • Sale agreements.

  • Token-holder rights.

  • Contract addresses.

  • Supply and vesting records.

  • Mint, burn, pause, freeze, and upgrade powers.

  • Listing and market-maker agreements.

  • Public-offer records.

  • Draft qualifying cryptoasset disclosure documents.

  • Inside-information and market-surveillance records.

Custody and stablecoins

  • Wallet inventory.

  • Signers and thresholds.

  • MPC and recovery procedures.

  • Customer ledgers.

  • Reconciliations.

  • Shortfall records.

  • Trust instruments.

  • Custody and sub-custody agreements.

  • Lien and set-off waivers.

  • Reserve accounts.

  • Backing-asset records.

  • Redemption records.

  • Staking and validator files.

  • Insurance.

  • Insolvency opinions.

UK market access

  • UK customer data.

  • IP and device data.

  • Sterling payment data.

  • UK marketing.

  • Influencer and affiliate agreements.

  • UK event records.

  • Application-store distribution.

  • Geoblocking.

  • Rejected onboarding.

  • Closed accounts.

  • Customer-asset return records.

AML, sanctions, data, and technology

  • Business-wide risk assessment.

  • AML policies.

  • Customer samples.

  • Transaction-monitoring alerts.

  • Travel Rule records.

  • Suspicious-activity files.

  • UK Sanctions List screening.

  • OFSI reports and licences.

  • Data maps.

  • Privacy notices.

  • Complaint procedures.

  • Architecture diagrams.

  • Repository and deployment records.

  • Smart-contract audits.

  • Penetration tests.

  • Incident and recovery records.

  • Vendor and cloud contracts.

Tax, CARF, and disputes

  • Tax returns and opinions.

  • Wallet-to-ledger reconciliations.

  • Token-compensation records.

  • PAYE and National Insurance records.

  • CARF classification and implementation.

  • Customer tax self-certifications.

  • Reporting-system tests.

  • Customer complaints.

  • Litigation and arbitration.

  • FCA, HMRC, OFSI, ICO, or law-enforcement inquiries.

  • Insurance notices.

  • Settlements and releases.

Ready to test a project before you rely on it?

Book a 30-minute consultation. We'll map the review perimeter and tell you exactly what evidence to request, in plain language.

Book a Consultation