Grade B AI-Researched

Labuan (Malaysia) -- Custody Regulations Regulatory Overview

Published: 2026-08-17 Updated: 2026-04-22 Author: SearXNG+LLM Version 1 Sources cited in: English (1)

Methodology

AI-generated synthesis from web search results.

Limitations

  • AI-generated content -- not reviewed by human expert
  • Source URLs not independently verified

Labuan, an international business and financial centre within Malaysia, operates under its own distinct regulatory framework supervised by the Labuan Financial Services Authority (LFSA). LFSA has been proactive in establishing a framework for digital asset businesses, including custody services.

The primary regulatory document governing digital asset businesses in Labuan is the "Guidelines on Digital Asset Business" issued by the LFSA. This document outlines the requirements for entities wishing to operate in the digital asset space, including those providing custody services.


Cryptocurrency/Digital Asset Custody Regulations in Labuan

Primary Regulator: Labuan Financial Services Authority (LFSA) Overarching Legislation:

  • Labuan Financial Services and Securities Act 2010 (LFSSA 2010)
  • Labuan Islamic Financial Services and Securities Act 2010 (LIFSSA 2010)

Specific Regulatory Document for Digital Assets:


Here's a breakdown of the requirements based on the "Guidelines on Digital Asset Business":

1. Custodial License Requirements

To offer digital asset custody services in Labuan, an entity must obtain a Digital Asset Business license from the LFSA. The Guidelines define "digital asset business" to include "providing custody services for digital assets."

Key requirements for obtaining this license include:

  • Entity Type: Must be incorporated or registered as a Labuan company under the Labuan Companies Act 1990.
  • Physical Presence: Must have a substantive presence in Labuan.
  • Capital Requirements: Maintain adequate paid-up capital and working capital, as determined by LFSA based on the nature, scale, and complexity of the business (Section 4.1.3 & 5.1).
  • Fit and Proper Criteria: Directors, controllers, and key management personnel must meet LFSA's "fit and proper" criteria (Section 4.1.5 & 4.1.6).
  • Business Plan: Submission of a comprehensive business plan detailing services offered, target market, operational procedures, risk management framework, and technology infrastructure.
  • Internal Controls & Risk Management: Robust internal control systems, governance framework, and risk management policies, particularly addressing cybersecurity, operational risks, and market risks (Section 5.3).
  • AML/CFT Compliance: Strict adherence to anti-money laundering and countering financing of terrorism (AML/CFT) requirements in line with the Anti-Money Laundering, Anti-Terrorism Financing and Proceeds of Unlawful Activities Act 2001 (AMLA) and LFSA's relevant guidance (Section 5.4).
  • Technology & Security: Demonstrate robust IT systems, security protocols, and expertise in distributed ledger technology (DLT) and cybersecurity (Section 5.3).

2. Segregation of Client Assets Rules

The Guidelines explicitly mandate the segregation of client assets:

  • Section 5.3.1 (e): "The entity shall establish robust internal controls and safeguards to segregate and protect clients' assets from its own assets. Client funds and digital assets must be held in designated segregated accounts or wallets and must not be commingled with the company's proprietary assets."
  • This ensures that in the event of insolvency or other financial distress of the custodian, client assets are protected and not treated as assets of the firm.

3. Insurance/Bonding Requirements

The Guidelines do not explicitly mandate a specific amount of insurance or a bonding requirement similar to some other jurisdictions. However, the expectation of robust risk management and capital adequacy indirectly addresses potential losses:

  • Section 5.3.1 (c): Requires the entity to "establish an adequate capital management framework to ensure sufficient capital is maintained to absorb potential losses arising from its business activities."
  • Section 5.3.1 (e): Implies the need for safeguards to protect client assets, which can include various risk mitigation strategies, potentially including insurance coverage for certain risks (e.g., cyber theft) as part of a comprehensive risk management framework.

While not a direct "X amount of insurance is required" rule, a licensed entity would be expected to demonstrate how it manages and mitigates risks, including potential losses of client assets, which could involve obtaining relevant insurance policies as part of its overall risk strategy.

4. Cold Storage Mandates

The Guidelines emphasize the importance of secure storage solutions:

  • Section 5.3.1 (g): "The entity shall implement appropriate and comprehensive cybersecurity measures and controls to safeguard clients' digital assets from theft, loss, and unauthorised access, which include, but are not limited to, the use of secure private key management, multi-signature wallets, and cold storage for a significant portion of digital assets."
  • This explicitly mandates the use of cold storage (offline storage) for a significant portion of digital assets, alongside other security measures like multi-signature wallets and robust private key management.

5. Qualified Custodian Definitions

In the context of Labuan, a "qualified custodian" for digital assets is an entity that has been licensed by the LFSA to conduct Digital Asset Business specifically involving custody services. The license itself confers the "qualified" status, as it implies the entity has met all the stringent requirements set out in the "Guidelines on Digital Asset Business," including capital, governance, security, and AML/CFT standards. There isn't a separate "qualified custodian" designation beyond holding the appropriate LFSA license.

6. Any Pending Custody Legislation

As of the latest updates to the "Guidelines on Digital Asset Business" (January 2023) and LFSA's public announcements, there is no widely publicized new specific custody legislation currently pending that would fundamentally overhaul the existing framework.

The LFSA continuously monitors the evolving digital asset landscape and international best practices (such as those from FATF). It reserves the right to review and amend its guidelines and regulations as necessary to ensure robust supervision and maintain market integrity. Any future changes would likely be through updated versions of the "Guidelines on Digital Asset Business" or new guidance notes. For the most current information, it is advisable to regularly check the LFSA's official website.


Summary:

Labuan provides a clear regulatory framework for digital asset custody through its "Guidelines on Digital Asset Business." Entities must obtain a specific license, adhere to strict segregation rules, implement robust cybersecurity (including cold storage mandates), and maintain strong internal controls and risk management frameworks. The LFSA acts as the sole regulator, ensuring that licensed entities meet high standards, effectively functioning as "qualified custodians" within the jurisdiction.

Source Data

17 fact(s) collected but awaiting source verification. View in explorer →

References

This article was generated by SearXNG+LLM .

Primary Sources

lfsa.gov.my. (n.d.). lfsa.gov.my. Retrieved April 22, 2026, from https://www.lfsa.gov.my/document/guidelines-on-digital-asset-business

Edit History

2026-04-22 — auto-publish-pipeline: reviewed — Auto-promoted to review: grade C
2026-08-17 — auto-publish-pipeline: published — Auto-published: grade B

This article is maintained by AI research workers and reviewed by human editors. Learn about our methodology →