Virtual asset services
Providing virtual asset services to other people: exchange, transfer, custody, brokerage or platform operation.
- Published jurisdictions
- Singapore, Hong Kong, United Arab Emirates
- Regulators involved
- 3 distinct authorities
Scope
What this permission family covers
Regulators assess the activity, not the product name. This is the activity that brings a business inside this family.
Providing virtual asset services to other people: exchange, transfer, custody, brokerage or platform operation.
Instruments in this family
Payment Services Act licence (digital payment token services)
Singapore · Monetary Authority of Singapore
Virtual asset trading platform licence
Hong Kong · Securities and Futures Commission (Hong Kong)
Virtual asset service provider licence (zone or emirate-level regime)
United Arab Emirates · The applicable UAE virtual-asset regulator or free-zone financial services authority for the chosen regime
Fit
Who needs this, and who does not
The negative list matters as much as the positive one. Businesses waste months applying for permissions they do not need.
Typically needed by
- Exchanges and trading platforms serving retail or institutional users
- Custody and wallet providers holding customer assets
- Businesses converting between fiat and digital assets for customers
Usually not needed by
- Protocol development with no customer funds, custody or exchange service
- Businesses that only accept digital assets as payment for their own goods, subject to local rules
Jurisdiction variant
The instrument depends on where you are authorised
Virtual assets (VASP) is not a single permission. Choose a jurisdiction to see the instrument that applies there, the regulator that grants it, and what that regulator examines.
Choose a jurisdiction
Virtual assets (VASP) exists as a different instrument in each published jurisdiction, with a different regulator and a different requirement set.
Choosing one keeps it in the address, so the variant can be shared and reopened.
Project model
How the programme runs
Three of these stages belong to the regulator. The platform records what the regulator has recorded and never anticipates a determination.
Readiness and gap analysis
YouStructured questions establish which requirement areas you already satisfy and which are open. The result is a gap list, not an assessment of whether a regulator will authorise you.
Scoping with a licensing specialist
Qualified providerA qualified licensing provider reviews the gap list, confirms the target permission and scopes the work into a proposal.
Application programme
Qualified providerPolicies, governance arrangements, controls documentation and the application pack are produced against the regulator's published requirements, tracked as milestones with document requirements.
Submission to the regulator
Qualified providerThe provider submits the application and records the submission evidence. From this point the state shown reflects the regulator's position.
Regulatory assessment
External authorityOutcome not controlled by ZKCAPThe regulator reviews the application and normally raises information requests. Each request appears as a first-class item with a response path, not as an email thread.
Determination
External authorityOutcome not controlled by ZKCAPThe regulator authorises, refuses, or authorises with conditions or limitations. The platform records whichever determination is issued, including refusal and its remediation path.
Ongoing supervision and renewals
External authorityOutcome not controlled by ZKCAPAuthorisation begins a supervisory relationship: reporting, notifications, attestations and periodic fees become tracked obligations.
Where this comes from
How this information is maintained
Boundary
Who is responsible, and who decides
A readiness assessment is not an application.