How Banks in Regulated Markets Can Deploy Digital Asset Custody Without Compromising Data Sovereignty
Overview: Banks in regulated markets can deploy compliant digital asset custody by choosing an architecture – on-premises HSM, MPC-based cloud, or hybrid – that keeps cryptographic key material within their jurisdiction. The right model depends on the country’s data residency rules, the regulator’s custody definitions, and the bank’s existing security infrastructure. Liminal supports all three deployment models with a single governance and wallet infrastructure layer on top.
The Question Every Bank’s Compliance Team Is Now Asking
A bank’s technology team can deploy digital asset custody in weeks. The compliance team’s question takes longer to answer: Where does the key material actually sit, and can we prove it to a regulator?
This question has moved from theoretical to urgent. Taiwan passed its Virtual Asset Service Act at third reading on 30 June 2026; FSC officials have said the Act and its subordinate rules will take effect together, in Q1 2027 at the earliest, moving custody onto an FSC-licensing footing for every custodian operating in the market. Vietnam’s Law on Digital Technology Industry came into force on 1 January 2026, introducing licensing, segregated custody requirements, and data localization expectations. Across Southeast Asia and the Gulf, banking regulators are publishing custody frameworks faster than most institutions can read them.
Banks that get the infrastructure decision right early will be able to demonstrate compliance from day one. Those that bolt on a solution after the fact – or choose a cloud-only vendor who cannot answer the residency question – will face a painful rebuild during the most sensitive part of the licensing process.
This article answers the question your compliance team is asking.
Why Data Sovereignty Is the Core Custody Problem for Banks
Retail investors can use offshore custody without consequence. Banks cannot. A licensed financial institution must be able to demonstrate, at any point, that:
- Customer assets are segregated and attributable to individual clients
- Cryptographic key material – the proof of control over digital assets – is generated, stored, and used within a defined boundary
- That boundary satisfies the data residency and cybersecurity requirements of the relevant regulator
- The institution can produce audit evidence on demand
The technical challenge is that digital assets are inherently borderless. A private key is a string of cryptographic data. Left unmanaged, it can be generated in Singapore, stored on a server in Virginia, and accessed from London – all in the same transaction. That is operationally convenient. It is also precisely what regulators in Taiwan, Vietnam, the UAE, and India are beginning to prohibit, or at minimum require documentation to justify.
The custody infrastructure decision is, fundamentally, a decision about where your key material lives and who controls it.
Learn More – How Banks and Enterprises Can Secure Digital Assets with Certified HSM and MPC Technology
The Three Deployment Models: What They Mean in Practice
Banks evaluating digital asset custody have three architecture options. Each makes a different set of promises to a regulator.
Model 1: On-Premises HSM Vault
What it is: A Hardware Security Module (HSM) – a tamper-proof physical device – is deployed inside the bank’s own data centre. All private key generation, storage, and transaction signing occurs inside that hardware. Key material never leaves the institution’s physical perimeter.
What it tells a regulator: Key material is fully onshore. The bank owns and controls the hardware. There is no third-party cloud dependency for cryptographic operations.
Who it suits:
- Banks in jurisdictions where the regulator explicitly requires key material to remain within national borders
- Institutions with existing HSM investments (e.g. for traditional certificate management) who need to extend custody capability without replacing infrastructure
- Banks responding to procurement RFPs from corporate clients who require proof of on-premises key control – a common requirement in Taiwan’s banking sector today
What to watch: On-premises HSM deployment requires the bank to manage hardware provisioning, redundancy, failover, and maintenance. A single HSM with no backup is a single point of failure. Regulators at FSC FIPS Level 3 – the common benchmark for tamper detection and immediate key zeroization on physical intrusion is worth configuring for now; Taiwan’s FSC hasn’t published a specific HSM certification requirement yet.
Liminal’s HSM Vault is purpose-built for banks that need on-premises deployment. It integrates with Securosys and other enterprise HSM hardware, sits within the bank’s own infrastructure, and connects upward to Liminal’s wallet governance layer – so the bank gets full key custody with the operational control of an enterprise platform.
Model 2: MPC-Based Cloud Deployment
What it is: Multi-Party Computation (MPC) distributes cryptographic key material across multiple independent nodes. No single node holds a complete private key. Transaction signing requires a threshold of nodes to cooperate – and those nodes can be distributed geographically while still meeting residency requirements if configured correctly.
What it tells a regulator: No single point of failure exists. Key material is distributed, not centralised. The architecture is resilient against both external attack and internal compromise.
Who it suits:
- Exchanges and fintech custodians operating at scale who need to sign thousands of transactions daily without operational friction
- Banks launching custody services for retail or corporate digital asset products where high transaction throughput matters
- Institutions in markets where the regulator defines residency at the node level rather than the device level – allowing MPC nodes to be hosted in local cloud regions
What to watch: MPC’s residency story depends on where the nodes are hosted. A cloud-only MPC setup with all nodes in a US region does not satisfy Vietnam’s or Taiwan’s residency expectations. The configuration matters as much as the technology. MPC nodes must be placed in local cloud availability zones – or on infrastructure the bank controls – to make a credible residency argument.
In Vietnam specifically, two requirements layer onto custody infrastructure. Decree No. 53/2022/ND-CP requires certain user and service data to sit on infrastructure located in Vietnam. Resolution No. 05/2025/NQ-CP requires licensed crypto asset providers’ IT systems to meet Level 4 information-security standards, assessed by the Ministry of Public Security. Neither law names cryptographic keys specifically. But together they push custody architecture toward infrastructure that sits and can be inspected inside the country. That is why distributing signing keys across in-country MPC nodes is a credible way to meet that expectation, rather than relying on a single machine or location that could fail or be compromised.
Model 3: Hybrid Deployment
What it is: The bank uses on-premises HSM for cold storage (assets held at rest, rarely transacted) and MPC-based infrastructure for hot and warm wallets (assets needed for operational transactions). A governance layer sits above both, enforcing unified policy, approval workflows, and audit logging.
What it tells a regulator: The bank has matched its security posture to the risk profile of each asset tier. High-value cold reserves are under full hardware control. Operational liquidity uses distributed key management with no single point of failure. All of it is auditable through a single control plane.
Who it suits:
- Most banks with significant custody ambitions – this is increasingly the institutional standard
- Banks running both proprietary treasury and client custody under one infrastructure
- Institutions that need to demonstrate both maximum security for cold reserves and operational efficiency for active positions
Most top-tier custody solutions today combine hardware assurance from HSMs with the flexibility and resilience of MPC.
Liminal’s platform supports hybrid deployment as a native architecture, not a workaround. The same policy engine governs both HSM-connected cold vaults and MPC-based hot wallets. Regulators see a single, auditable system. Operations teams see a single dashboard.
Learn More – Digital Asset Custody for Banks: In-House vs Outsourced vs White-Label
What the Regulators Are Actually Asking For
Taiwan: FSC Under the Virtual Asset Service Act (2026)
Taiwan’s Virtual Asset Service Act – passed 30 June 2026 – moves the entire VASP ecosystem from AML registration to FSC licensing. For banks and custodians, the operative requirements include:
- Segregated custody of customer assets, documented and auditable
- Cybersecurity systems and management meeting FSC standards
- Internal controls and auditing specific to digital asset operations
- Custody provider licensing as one of seven defined VASP categories
The FSC has not yet published the full secondary rules specifying technical custody standards. But the direction is clear: custody is a licensed activity, not a product feature. A bank that wants to offer custody services can either apply for custodian license itself or work with a licensed (or, as of now, registered) Custodian.
The practical implication for banks: Any custodian you work with must be able to document where the clients’ key material sits, how it is protected, and how much control you, as a bank that provides custodian services to your customers, can hold. A vendor who cannot answer this in writing is a vendor who cannot help you get licensed.
Existing AML-registered VASPs have 12 months to file FSC license applications and 21 months to obtain full approval. The clock starts when the Executive Yuan sets the implementation date – expected Q1 2027 at the earliest, per FSC statements. That window is shorter than it looks.
Vietnam: State Bank, Ministry of Finance, and Resolution 05
Vietnam’s framework is among the most structurally restrictive in APAC:
- The Law on Digital Technology Industry (effective 1 January 2026) formally recognises digital assets and requires all trading, custody, and related transactions to be conducted through licensed or Ministry of Finance-approved service providers
- Resolution No. 05/2025 establishes a five-year pilot for licensed VASPs, with custody defined as receipt, storage, safekeeping, and transfer of crypto assets on behalf of clients
- Capital requirements are steep: VND 10 trillion (~USD 380-400 million) for licensed operators, with 65% required from Vietnamese institutions
- The framework carries strict data localization expectations -though neither law names cryptographic keys directly.
For banks serving Vietnamese clients or operating under the pilot regime, the custody infrastructure question is not optional. The Ministry of Finance is licensing entities. Unlicensed custody is prohibited. And the data residency question – where the MPC nodes or HSM hardware sits – is a core part of any credible application.
The Questions Your Regulator Will Ask
Whether you are presenting to the FSC in Taipei, the Ministry of Finance in Hanoi, VARA in Dubai, or MAS in Singapore, expect these questions during any custody review:
| Regulator Question | What Your Infrastructure Needs to Demonstrate |
| Where is key material generated? | On-premises HSM within jurisdiction, or MPC node in local-region cloud |
| Who has access to signing operations? | Role-based access controls with MFA, documented approval workflows |
| How are customer assets segregated? | Wallet-per-client or vault-per-client architecture with attribution logs |
| What happens if a key share is lost? | MPC threshold recovery, HSM backup procedures, tested disaster recovery |
| How do you detect and respond to a breach? | Real-time transaction monitoring, anomaly detection, incident response SLA |
| Can you produce an audit trail on demand? | Immutable transaction logs with timestamps, approver IDs, and policy versions |
If your custody vendor cannot give you written answers to all six, you are not ready for a licensing conversation.
The Architecture Decision: A Framework for Bank Compliance Teams
Use this decision logic when evaluating your custody deployment model:
Start with the regulator’s residency requirement.
- Explicit on-premises mandate → HSM Vault
- Node-level residency acceptable → MPC with local cloud nodes
- No explicit mandate but sovereignty audit expected → Hybrid (safest default)
Then match to your transaction profile.
- High-value, low-frequency reserves → HSM cold vault
- High-frequency operational transactions → MPC hot wallet
- Both → Hybrid
Then confirm your integration constraints.
- Existing HSM infrastructure → extend it with Liminal’s HSM Vault integration
- Greenfield deployment → MPC or hybrid is faster to deploy
- Banking core system integration required → confirm the custody vendor’s API and middleware capability before committing
Finally, verify the governance layer. The deployment model determines where key material sits. The governance layer determines who can use it, under what conditions, and with what audit trail. Both are necessary. A bank can have the most secure HSM in APAC and still fail a regulatory audit if the approval workflows are undocumented or the transaction logs are incomplete.
What “Data Sovereignty” Actually Means in a Custody Contract
When you sign a custody technology agreement, ask for explicit answers to these questions – in the contract, not in a sales deck:
- Where is key material generated? Name the specific location, hardware, and environment.
- Who can access signing operations? List the roles, authentication requirements, and any third-party access rights.
- Is any key material replicated outside my jurisdiction? For backup or disaster recovery – and if so, where, and under what encryption?
- What data leaves my environment? Transaction metadata, policy configurations, audit logs – where do they go, and who can read them?
- What is your incident notification SLA? How quickly will you tell us if key material is at risk?
- What does your SOC 2 / ISO 27001 scope cover? Does it explicitly include the key management infrastructure you are deploying for us?
A custody vendor who cannot answer these in a contract addendum is not ready for a regulated banking client.
How Liminal Approaches This for Banking Clients
Liminal is a digital asset custody and wallet infrastructure platform built for regulated institutions – banks, exchanges, payment firms, and enterprises operating in licensed markets.
Our approach to data sovereignty is direct: you choose where your key material sits; we build the governance, wallet management, and compliance layer on top.
- Liminal HSM Vault integrates with Securosys and enterprise HSM hardware deployed inside your data centre. Your key material stays in your infrastructure. We provide the wallet governance, policy engine, and audit tooling above it.
- Liminal MPC Wallet Infrastructure deploys in your preferred cloud region or on your own servers. Key shares are distributed across nodes you control. We do not hold your key material.
- Hybrid configurations combine both under a single dashboard, with unified policy management across cold and hot tiers.
Every client conversation starts with: What does your regulator expect, and what does your existing infrastructure look like? We design around those constraints, not around a default cloud architecture.
We are actively engaging with banks and financial institutions in Taiwan, Vietnam, Hong Kong, the UAE, and across Southeast Asia – markets where data sovereignty is not a selling point, it is a prerequisite.
Summary
Banks entering digital asset custody face a genuine infrastructure decision, not just a vendor selection. The regulator’s question – where does your key material sit? – determines everything downstream: what deployment model you choose, which vendor can actually support you, and whether your custody solution survives a licensing review.
The three models available are:
- On-premises HSM Vault – full onshore control, highest regulatory defensibility, higher operational cost
- MPC with local-region nodes – scalable, resilient, residency-compliant if configured correctly
- Hybrid – the institutional standard for banks with both cold reserves and active operations
The frameworks in Taiwan and Vietnam make this decision time-sensitive. The FSC licensing clock in Taiwan is about to start. Vietnam’s pilot licensing process has already begun. Banks that delay the infrastructure decision risk missing the transition period entirely.
The right answer depends on your jurisdiction, your regulator, and your transaction profile. But the question you need to answer – in writing, in your vendor contract – is always the same: where does my key material sit, and who controls it?
Shilpa Sharma
Global Compliance Manager
Shilpa is a Global Compliance Manager at Liminal, with over seven years of experience across fintech compliance, financial crime, and AML. Before Liminal, she managed surveillance and compliance functions at Groww and worked as a Senior AML Consultant at Protiviti. She holds a Certified Anti-Money Laundering Expert (CAME) credential and specializes in global regulatory strategy, risk assessment, and compliance process automation.