Self-custody meets institutional control: where the legal line actually sits
A joint analysis by Infinilex and Reah on what “non-custodial” actually has to mean, jurisdiction by jurisdiction, to hold up under real regulatory scrutiny.
“Non-custodial” is not a self-certifying label anywhere. The US asks who can move funds unilaterally. The EU asks who controls the means of access. India and the UAE ask what function the platform performs in substance. Singapore regulates facilitation even without possession. Canada asks what the user legally received. One multi-sig architecture, six different tests, and the label decides none of them.
Overview
Platforms building on stablecoin rails increasingly lead with the same pitch: self-custody wallets, multi-sig protection, “institutional-grade” security. Reah’s own positioning, “self-custody meets institutional-grade security”, is a good example of how the industry frames this today. We wanted to pick up that thread from the legal side, because security and compliance are often talked about as though they’re the same conversation. They’re not. More broadly, a wallet can be perfectly secure and still fall within a licensing regime, depending on how regulators assess its underlying structure. Here’s where that line actually sits: the US asks who can move funds unilaterally; the EU asks who controls access; India and the UAE ask what function a platform actually performs; Singapore regulates even without possession; and Canada asks a different question entirely: what did the user legally receive? This piece walks through what “non-custodial” actually has to mean, jurisdiction by jurisdiction, to hold up under real regulatory scrutiny.
Platforms often describe their wallet infrastructure as “self-custody” or “non-custodial”, paired with multi-signature controls. That framing is common across the industry, and for good reason: it signals that the user, not the platform, retains meaningful control over their assets. But from a compliance standpoint, “non-custodial” is not a self-certifying label. Regulators don’t ask what a product calls itself. They ask a narrower, more mechanical question: who can actually move the funds, and under what conditions?
That question, and not the marketing term, is what determines whether custody-related licensing applies.
The US stance on custody
The clearest official articulation of this comes from the U.S. Financial Crimes Enforcement Network (FinCEN). In its 2019 interpretive guidance on convertible virtual currency business models, FinCEN drew a direct, mechanical line:
- Software / “unhosted” wallet providers. Platforms that give users tools to hold their own keys are not regulated as money transmitters under the Bank Secrecy Act, because they never accept or transmit funds on the user’s behalf.
- Multi-signature wallet providers. Just like software and unhosted wallet providers, multi-sig wallet providers are treated the same way, but only if they lack the unilateral ability to execute a transaction. If a platform holds one key in a multi-sig scheme but cannot move funds without the user’s separate signature, FinCEN’s guidance places that outside money-transmitter status.
Key takeaway. The operative fact isn’t the number of keys or the word “non-custodial” on a landing page. It’s whether any single party, including the platform itself, can move a client’s assets alone.
The EU draws the line differently, and more broadly
Under the EU’s Markets in Crypto-Assets Regulation (MiCA), the analysis doesn’t hinge on “custodial vs. non-custodial” as a binary at all. MiCA defines “providing custody and administration of crypto-assets on behalf of clients” as “the safekeeping or controlling, on behalf of clients, of crypto-assets or of the means of access to such crypto-assets, where applicable in the form of private cryptographic keys” and treats it as a licensable activity requiring authorization as a Crypto-Asset Service Provider (CASP).
Notice the phrase “or of the means of access.” This matters because, under MiCA, you don’t need to hold a client’s assets outright to be considered a custodian; simply controlling access to those assets can be enough. Holding even one key in a multi-sig setup is, on a plain reading, controlling a “means of access.” And once a platform is treated as offering custody, it takes on real obligations under Article 75 of the MiCA regulation: it must have a custody agreement with each client, keep client assets separate from its own, and report on asset status at least every three months. The wider authorisation decision is mapped in MiCA vs VARA, and the application mechanics in our MiCA CASP readiness checklist.
Key takeaway. A structure that clears FinCEN’s narrower “unilateral control” test in the US will not automatically clear MiCA’s broader “controlling means of access” test in the EU. These are two different legal tests, not two phrasings of the same one.
India doesn’t ask what you call yourself, it asks what you do
India’s framework, administered by the Financial Intelligence Unit (FIU-IND) under the Prevention of Money Laundering Act, 2002, takes this a step further. The Ministry of Finance’s notification in March 2023 brought “safekeeping or administration of virtual digital assets or instruments enabling control over virtual digital assets” within the definition of a reporting entity, regardless of whether the entity is based in India, and regardless of how the platform describes its own custody model.
Legal commentary tracking FIU-IND’s enforcement pattern has been explicit about this: platforms that brand themselves “non-custodial” are not automatically outside scope. Regulators in India and elsewhere increasingly apply a functional test: who, in practice, controls the use of the assets, regardless of the technical architecture or the label the platform uses. Who the notification catches, and the registration sequence that follows, are covered in our FIU-IND registration guide and the step-by-step checklist.
Key takeaway. The single most important sentence for any founder building wallet infrastructure to internalize: the label is not the analysis, the control structure is the analysis.
The UAE: custody is its own licence, full stop
Dubai’s Virtual Assets Regulatory Authority (VARA) removes almost all ambiguity by treating custody as a separate, standalone licensable activity, not a feature bundled into a trading or wallet licence. VARA’s Virtual Assets and Related Activities Regulations 2023 define custody as “safekeeping Virtual Assets for or on behalf of another Entity and acting only on verified instructions from or on behalf of such Entity” (VARA defines “Entity” as any legal entity or individual), and its Custody Services Rulebook requires custody to be conducted through its own legal entity, segregated from any other virtual asset activity the group performs, subject to a limited exception for VA Transfer and Settlement Services.
Two details make VARA’s regime relevant to any “self-custody meets multi-sig” claim specifically:
- VARA requires VASPs providing custody to maintain control of each virtual asset at all times while segregating each client’s holdings into that client’s own wallet, a structural requirement that sits independently of how many signatures a transaction needs.
- VARA’s regime works, in substance, the way India’s does: what matters is not whether a firm considers itself a custodian, but whether it performs custodial functions. A firm that holds even one key in a client transaction flow, or that influences whether a transaction is verified and executed, risks being read as performing a custodial function under VARA’s activity-based rules, regardless of what the product page calls it.
How VARA sits against the UAE’s two other virtual-asset regimes is mapped in VARA vs ADGM vs DIFC; the UAE VASP licensing-readiness checklist is the pre-application gap analysis we run with clients.
Key takeaway. In Dubai, “we’re not a custodian” is not a determination a platform gets to make for itself. It’s a determination VARA makes, based on what the platform’s technical setup actually allows it to do.
Singapore: custody is regulated even without full possession
Singapore’s Monetary Authority of Singapore (MAS) offers a useful contrast because it shows the perimeter can extend even further than “who holds a key.” Following the Payment Services (Amendment) Act 2021, with the relevant provisions taking effect in April 2024, the Payment Services Act was expanded to bring custodial services for digital payment tokens (DPTs) within MAS’s licensing regime, alongside the facilitation of DPT transfers and exchanges.
Notably, MAS’s own guidance makes clear that transfer and exchange-facilitation services fall within scope “even where the service provider does not come into possession of the moneys or DPTs.” In other words, MAS will still regulate a platform simply for enabling a transfer or exchange, whether or not it ever actually holds the assets.
Licensed DPT service providers in Singapore are required to safeguard customer assets, including by depositing them into a trust account, separate from the platform’s own holdings.
Key takeaway. MAS doesn’t wait for a platform to hold assets before stepping in; simply enabling a transfer or exchange can be enough to fall under regulation. And once a platform is in scope, keeping customer assets in a separate trust account isn’t optional; it’s a baseline legal requirement, not a discretionary security feature.
Canada: a different question entirely, what did you actually sell the user?
Canada’s approach, developed by the Canadian Securities Administrators (CSA), is worth including precisely because it doesn’t ask “who holds the key” at all. It asks a different question: what is the legal nature of the user’s claim against the platform?
Under CSA Staff Notice 21-327, if a user pays for crypto but the platform doesn’t hand over that exact asset right away, even a short delay, the user hasn’t really bought the crypto itself. They’ve bought a promise that the platform will give it to them. Canadian regulators treat that promise as a security or derivative. So a platform can call itself “non-custodial”, but if there’s a payment-to-delivery gap, that label doesn’t matter; the user’s claim is what gets regulated.
Where a platform does perform a custody function, the CSA and IIROC’s joint guidance is explicit that the risk being regulated, loss, theft, or bankruptcy of custodied assets, exists regardless of which technical custody mechanism a platform uses, because “the mechanism for ‘custody’ in the crypto asset context may be different between business models, yet a risk of loss, theft or bankruptcy remains.”
Key takeaway. Canadian regulators may look past the custody architecture altogether and ask whether, functionally, the user has an immediate, unconditional claim to a specific on-chain asset or a contractual promise from the platform. If it’s the latter, “non-custodial” framing may not change the underlying securities-law analysis at all.
Conclusion
This isn’t an academic distinction. It determines which licence, if any, a platform needs (money-transmission registration in the US, CASP authorization in the EU, FIU-IND reporting-entity registration in India, and their equivalents in the UAE, Singapore, and Canada, each triggered by a different, specific test), where a platform can operate without a local partner or licence, and what it can legally promise its users. “Your keys, your crypto” is only a meaningful claim if it’s technically true under the applicable test, not just true in spirit. For a platform like Reah, which brings banking, wallets, cards, and treasury into one platform, custody analysis is not a one-time determination; the applicable test depends on the specific service and jurisdiction. The applicable test must be considered separately in each jurisdiction where the relevant service is offered, because the frameworks above do not apply the same standard. Canada, in particular, stands apart, asking less about who holds the keys and more about the legal nature of the user’s claim to the asset.
For any builder evaluating a multi-sig or “non-custodial” product, including relying on someone else’s marketing claim about theirs, three questions cut through the noise: Can any single party, including the platform, move funds without the client’s separate signature? Does the platform control any credential that acts as a “means of access” or “verified instruction” checkpoint, even without holding the asset itself? And has the structure been tested against the specific legal standard in every jurisdiction the platform operates in, not just where it was formed? Get those answers right, and “non-custodial” is a claim a platform can defend to a regulator, not just to a user. Get them wrong, and it’s a marketing line that creates a licensing problem nobody saw coming.
Frequently asked questions
Is calling a wallet "non-custodial" or "self-custody" enough to stay outside custody licensing?
No. Regulators do not treat "non-custodial" as a self-certifying label. They apply a functional test: who can actually move the funds, and under what conditions. The control structure, not the marketing term, is what determines whether custody-related licensing applies.
Does holding one key in a multi-signature wallet make a platform a custodian?
It depends on the jurisdiction's test. Under FinCEN guidance in the US, a multi-signature provider stays outside money-transmitter status only if it cannot move funds without the user's separate signature. Under the EU's MiCA, holding even one key can amount to controlling a "means of access," which is itself a licensable custody activity. The same architecture can pass one test and fail another.
How does the US decide whether a wallet provider needs a licence?
FinCEN's 2019 guidance asks a narrow, mechanical question: can any single party, including the platform, move a client's assets unilaterally? Software and unhosted wallet providers are not money transmitters because they never accept or transmit funds. A multi-signature provider is treated the same way, provided it lacks the unilateral ability to execute a transaction.
Does the EU's MiCA treat controlling a key as custody?
Potentially, yes. MiCA defines custody as safekeeping or controlling, on behalf of clients, crypto-assets "or of the means of access" to them. On a plain reading, holding even one key in a multi-signature setup can be controlling a means of access, which triggers authorization as a Crypto-Asset Service Provider and obligations such as a custody agreement, asset segregation, and quarterly reporting.
How do India and the UAE decide whether a platform performs custody?
Both apply a functional, activity-based test rather than accepting a label. India's FIU-IND framework covers the safekeeping or administration of virtual digital assets, or instruments enabling control over them, regardless of how the platform describes itself. Dubai's VARA treats custody as its own standalone licence and asks whether a firm performs custodial functions in substance, including whether it holds a key or influences whether a transaction is verified and executed.
Can a platform be regulated in Singapore or Canada without holding customer assets?
Yes. In Singapore, MAS regulates the facilitation of digital-payment-token transfers and exchanges "even where the service provider does not come into possession of the moneys or DPTs," and licensed providers must safeguard customer assets in a separate trust account. In Canada, the CSA looks at the legal nature of the user's claim: if there is a gap between payment and delivery of the specific asset, the user may hold only a contractual promise, which can be regulated as a security or derivative.
Building wallet, custody or multi-sig infrastructure across borders?
Tell us where your users, your keys and your entities sit, and we will map which custody test each market applies to your architecture, and what licensing follows, before a regulator maps it for you.
Further reading
From Infinilex: The Web3 legal-readiness checklist · MiCA vs VARA · VARA vs ADGM vs DIFC · FIU-IND registration for crypto businesses in India · The UAE VASP licensing-readiness checklist
From Reah: reah.com
Contributor note
Reah contributed the product and platform perspective on multi-signature wallet architecture, treasury workflows and institutional controls. Infinilex contributed the legal and regulatory analysis across the six jurisdictions covered in this article.
About Reah
Reah is a financial operating system for global businesses managing both fiat and onchain finance. It brings banking, non-custodial multi-signature wallets, corporate cards, treasury workflows, and AI-native execution into one platform. Its wallet architecture preserves self-custody, while team permissions, approval policies, and a unified ledger provide the governance and auditability finance teams need. Reah is a financial technology company, not a bank, broker-dealer, or investment adviser. Product availability is subject to eligibility, geography, and partner availability.
About Infinilex
Infinilex is a legal and regulatory advisory practice for Web3 and digital-asset projects, helping founders structure operations, tokens, and platform-level compliance across India, the UAE, and the US. Rather than coordinating three disconnected local counsel across three jurisdictions, Infinilex handles the work itself across all three, which is the corridor most Web3 businesses building out of the US, India or the UAE actually run on. Rather than treating jurisdiction selection as an afterthought, Infinilex works with teams at the design stage, mapping which regulator actually governs the given product, and building the entity, licensing, and compliance structure around that answer before the product ships.
This article is general information for founders, not legal, tax or investment advice for your specific company or product. It does not assess any specific platform’s custody architecture, including Reah’s. Regulatory positions across the US, the EU, India, the UAE, Singapore and Canada change. Confirm every point against current law for your facts, and have your structure reviewed before you rely on a custody classification.