Custody Technology and the Evidence Underwriters Demand

For a firm that holds crypto assets, the quality of your custody technology is no longer just a security question — it is an insurability question. Insurers and, increasingly, regulators want specific technical evidence of how client assets are secured, and firms consistently struggle to produce it. The gap between “our custody is secure” and …

Read more

Stablecoins and Tokenised Deposits: A Technology Governance Reading

Stablecoins and tokenised deposits are converging on the same use — money that moves on a ledger — from opposite regulatory starting points, and the technology decisions a firm makes early determine which obligations it inherits. This is a governance question before it is a product question. A firm that designs the token first and …

Read more

RWA Tokenisation for Funds: Five Technology Decisions That Lock You In

Tokenising a real-world asset — a fund unit, a share, a bond — is one of the genuinely promising moves in regulated finance, and Luxembourg is one of the places it is happening fastest. But the pitch decks understate a hard truth: the early technology choices are difficult to reverse. Tokenising a fund is not …

Read more

Travel Rule and Multi-Regulator VASP Operations (MiCA, VARA, MAS, FCA)

A crypto firm operating in one jurisdiction implements the Travel Rule once. A firm operating across several implements it several times, differently, and then has to make the versions coexist in a single platform. The FATF Travel Rule — the requirement to send originator and beneficiary information alongside a crypto transfer — is a global …

Read more

MiCA CASP Operational Resilience: A Technology Function’s Reading of Article 68

Most of the public MiCA conversation has been about the licence: who has one, in which member state, and how long it took. That conversation is closing. The transitional period that let legacy providers keep operating has now run out across most of the EU — the longest national windows ended on 1 July 2026, …

Read more

AML Transaction Monitoring for VASPs: Architecture Patterns

More than 60 jurisdictions now require VASP registration or licensing, and the pattern across all of them is consistent: registration was only ever the first hurdle. What regulators are actually auditing now is whether the transaction monitoring behind the registration is functioning in practice, not just documented in a policy. FATF’s June 2025 Targeted Update …

Read more

Why Crypto Exchanges Fail Their First Regulatory Audit

A study of 75 centralised exchanges operating in Europe, examining 143 legal documents against MiCA and DORA requirements, found just seven exchanges with formal security certifications — ISO 27001, PCI DSS, or SOC — despite widespread claims of security compliance across the sample. The gap between what exchanges claim and what an audit actually finds …

Read more

Multi-Regulator VASP Operations: Architecting for MiCA, VARA, MAS, and FCA

MiCA, VARA, and MAS all require licensing, fit-and-proper assessments, capital requirements, and AML controls — which invites the assumption that they’re converging variants of the same regime. They’re not. A firm applying to all three is making three different commitments to three different regulators with three different theories of what a licensed crypto firm should …

Read more

Smart Contract Risk for Centralised Exchanges: The Blind Spot in Traditional Security Reviews

“Centralised exchange” describes a business model, not a technical architecture free of smart contracts. Custody wallets built on multi-party computation, DeFi bridges used for liquidity, and treasury automation modules increasingly run on smart contract logic — and a traditional infrastructure security review, focused on servers, networks, and access control, routinely misses this specific attack surface …

Read more