Skip to content
ZKCAPZKCAP — global business and capital infrastructure
Permission familySingaporeHong KongUnited Arab Emirates

Virtual asset services

Providing virtual asset services to other people: exchange, transfer, custody, brokerage or platform operation.

Published jurisdictions
Singapore, Hong Kong, United Arab Emirates
Regulators involved
3 distinct authorities

Scope

What this permission family covers

Regulators assess the activity, not the product name. This is the activity that brings a business inside this family.

Providing virtual asset services to other people: exchange, transfer, custody, brokerage or platform operation.

Instruments in this family

  • Payment Services Act licence (digital payment token services)

    Singapore · Monetary Authority of Singapore

  • Virtual asset trading platform licence

    Hong Kong · Securities and Futures Commission (Hong Kong)

  • Virtual asset service provider licence (zone or emirate-level regime)

    United Arab Emirates · The applicable UAE virtual-asset regulator or free-zone financial services authority for the chosen regime

Fit

Who needs this, and who does not

The negative list matters as much as the positive one. Businesses waste months applying for permissions they do not need.

Typically needed by

  • Exchanges and trading platforms serving retail or institutional users
  • Custody and wallet providers holding customer assets
  • Businesses converting between fiat and digital assets for customers

Usually not needed by

  • Protocol development with no customer funds, custody or exchange service
  • Businesses that only accept digital assets as payment for their own goods, subject to local rules

Jurisdiction variant

The instrument depends on where you are authorised

Virtual assets (VASP) is not a single permission. Choose a jurisdiction to see the instrument that applies there, the regulator that grants it, and what that regulator examines.

Singapore

Payment Services Act licence (digital payment token services)

Regulator-granted
Regulator
Monetary Authority of Singapore
Scope of the authorisation
Dealing in digital payment tokens, facilitating their exchange, and related custodial and transfer services as specified in the licence.

What this regulator examines

7

Each area below is assessed against your actual business. Open one for the detail and the evidence normally expected.

Governance, fitness and propriety of controllersMandatory

Regulators assess who owns and runs the business: the board and senior management, the fitness and propriety of each controller, and the reporting lines that make the arrangement credible.

  • Evidence: Organisational chart with reporting lines
  • Evidence: Controller questionnaires and identity evidence
  • Evidence: Curriculum vitae and regulatory history for senior appointments
Financial-crime frameworkMandatory

A documented framework covering customer due diligence, sanctions and PEP screening, transaction monitoring, suspicious-activity reporting and record keeping — proportionate to the business model and geography.

  • Evidence: AML/CFT policy and procedures
  • Evidence: Risk assessment covering customer, product, geography and channel
  • Evidence: Named compliance officer and reporting arrangement
Business plan and financial projectionsMandatory

A regulator-grade business plan: the model, target customers, distribution, volumes, cost base and funding, with projections that reconcile to the capital and liquidity position.

  • Evidence: Business plan
  • Evidence: Financial projections
  • Evidence: Funding and capital evidence
Operational resilience and technology controlsMandatory

Information security, change management, outsourcing oversight, business continuity and incident reporting arrangements appropriate to the permission being sought.

Local presence and substanceMandatory

A Singapore entity with a permanent place of business and locally accountable senior management.

Custody and key-management controlsConditional — Applies where the business holds customer tokens

Where customer tokens are held, the regulator examines custody architecture, key management, segregation and reconciliation.

Consumer-protection and marketing restrictionsMandatory

Token services are subject to specific conduct and public-communication restrictions, which shape both product and marketing.

After authorisation

Authorisation begins a supervisory relationship. These obligations continue for as long as the permission is held.

  • Regulatory reporting and audit obligations
  • Travel-rule and transaction-monitoring compliance
  • Custody control attestations where customer tokens are held
  • Notification of control and key-appointment changes

Project model

How the programme runs

Three of these stages belong to the regulator. The platform records what the regulator has recorded and never anticipates a determination.

  1. Readiness and gap analysis

    You

    Structured questions establish which requirement areas you already satisfy and which are open. The result is a gap list, not an assessment of whether a regulator will authorise you.

  2. Scoping with a licensing specialist

    Qualified provider

    A qualified licensing provider reviews the gap list, confirms the target permission and scopes the work into a proposal.

  3. Application programme

    Qualified provider

    Policies, governance arrangements, controls documentation and the application pack are produced against the regulator's published requirements, tracked as milestones with document requirements.

  4. Submission to the regulator

    Qualified provider

    The provider submits the application and records the submission evidence. From this point the state shown reflects the regulator's position.

  5. Regulatory assessment

    External authorityOutcome not controlled by ZKCAP

    The regulator reviews the application and normally raises information requests. Each request appears as a first-class item with a response path, not as an email thread.

  6. Determination

    External authorityOutcome not controlled by ZKCAP

    The regulator authorises, refuses, or authorises with conditions or limitations. The platform records whichever determination is issued, including refusal and its remediation path.

  7. Ongoing supervision and renewals

    External authorityOutcome not controlled by ZKCAP

    Authorisation begins a supervisory relationship: reporting, notifications, attestations and periodic fees become tracked obligations.

Where this comes from

How this information is maintained

Boundary

Who is responsible, and who decides

A readiness assessment is not an application.