Licensed digital-asset platform

A regulated entity authorised to exchange, transfer or hold digital assets for others, operating under its own licence and screening obligations. The licence is issued to a named legal entity, for a listed set of activities, in one territory, and it binds that entity alone. Where a bullion purchase is funded from digital-asset proceeds, the platform performs the payment leg — it screens the transaction, converts it, and settles the seller in national currency — under supervision the seller does not hold and the buyer does not inherit.

What the licence attaches to

An authorisation narrows in three directions at once, and a compliance file that checks only one of them is checking the wrong thing.

The entity. Permission is granted to a legal person, not to a brand. A group operating one name across several countries typically holds one authorised entity and several unauthorised affiliates; the protections of the regime follow the authorised entity only. ESMA restated this in 2026 as the MiCA transitional period closed: the regime’s protections apply when a client deals with the specific authorised entity, not with other companies in the same group and not with non-EU affiliates trading under a shared brand.

The activity list. Permissions enumerate: custody and administration, exchange of crypto-assets for funds, transfer services, operation of a trading platform, execution or reception and transmission of orders. An authorised firm acting outside its list is acting without authorisation for that act. A licence reference on its own says nothing until the activity in question is matched against the list.

The territory. Within the EEA a MiCA authorisation passports across member states. Outside it, there is no passport at all: an authorisation in one jurisdiction confers nothing in the next, and a firm established outside the EU may not provide crypto-asset services to EU clients other than through the narrow reverse-solicitation exception — a limit ESMA applies in business-to-business dealings, not only retail.

For a reviewer, the practical consequence is that a licence claim resolves to three checkable facts — which entity, which permissions, which market — and to nothing else.

Registered, authorised, prohibited: the three states a platform can be in

The word licensed covers two regulatory conditions that carry different weight, and a third condition is spreading.

Registration is a notification and AML-supervision status. It confirms that a firm is known to an authority and subject to financial-crime rules. It is not permission to conduct a regulated activity. US federal registration with FinCEN as a money services business is a registration in exactly this sense; so is the UK’s cryptoasset registration under the Money Laundering Regulations.

Authorisation adds a conduct and prudential regime: capital, governance, safeguarding of client money and assets, complaints, disclosure, outsourcing limits, supervisory reporting.

Prohibition is the third and least discussed. The FATF’s seventh targeted update on virtual assets, published in July 2026, records the share of surveyed jurisdictions that bar virtual-asset service providers outright rising from 11 per cent in 2023 to 23 per cent.

Status of the main regimes as at August 2026:

RegimeInstrumentPosition
EU / EEAMiCA CASP authorisationThe transitional period closed on 1 July 2026 across the bloc; several member states closed earlier. National registrations ceased to be a legal basis, a pending application never was one, and unauthorised firms were required to execute wind-down plans rather than continue.
United KingdomRegistration under the MLRs now; FSMA authorisation from 25 October 2027The Cryptoassets Regulations were made on 4 February 2026 and the FCA’s final rules followed on 30 June 2026. The authorisation gateway opens 30 September 2026 and closes 28 February 2027. MLR registration does not convert automatically — a registered firm that does not apply in the window is not authorised when the regime commences.
United StatesNo single licenceFederal MSB registration with FinCEN, plus a money transmitter licence in nearly every state, plus New York’s BitLicense, plus California’s Digital Financial Assets Law, whose licence requirement took effect on 1 July 2026 with applications open through NMLS since 9 March 2026.
SingaporePayment Services Act; FSMA Part 9 DTSP regimeThe DTSP regime has applied since 30 June 2025 to digital token services provided from Singapore to customers abroad. MAS set the bar high, stated it would generally not issue such a licence where the substantive activity sits outside its supervisory reach, and granted no transitional period.

The pattern across all four: the perimeter is now drawn by where the activity is supervised, not by where a company is incorporated. A reviewer who reads a corporate address as a regulatory status is reading the wrong field.

How a licence is verified

Authorisation is a matter of public record in every regime that grants it, and the record sits with the authority, not with the firm. ESMA maintains a central MiCA register of authorised CASPs and their notified activities, kept current as applications are approved, refused or withdrawn. The FCA publishes its Financial Services Register and a separate register of MLR-registered cryptoasset firms. MAS publishes its financial institutions directory. US state licences are visible through NMLS, and FinCEN publishes its MSB registrant list.

Three checks close the question: the exact legal name on the entry matches the entity that will contract and receive funds; the permission covers the activity being relied on; the entry is current rather than pending, lapsed or subject to a wind-down instruction. A screenshot of a licence number supplied by the firm itself closes none of them.

What the platform does on the payment leg

The sequence below is the platform’s, performed under the platform’s licence. It runs in parallel with, and does not replace, the seller’s own counterparty checks.

  1. Onboards and identifies the payer, to its own standard, as a client of the platform. This is a separate relationship from the one the payer holds with the metal seller.
  2. Screens the wallet and the transaction using blockchain analytics: attribution of the sending address, exposure to sanctioned entities, mixers, thefts and darknet clusters, and the depth of hops between the funds and any flagged origin.
  3. Applies the Travel Rule, transmitting originator and beneficiary information to the counterparty institution. The threshold is regime-specific and widely misread. In the EU, Regulation (EU) 2023/1113 imposes no de minimis at all for crypto-asset transfers; the €1,000 figure in that regulation triggers verification that a self-hosted address is controlled by the customer, not the duty to send data. Under the US Bank Secrecy Act the transmittal threshold is $3,000. A control set scoped to a threshold borrowed from the wrong regime is under-scoped.
  4. Screens the parties against sanctions lists — typically EU, UN, OFAC and UK consolidated lists — and holds anything that hits.
  5. Converts the digital assets to national currency at its own rate, as principal or through its own venue.
  6. Settles the seller in fiat, against the order reference that identifies the purchase.
  7. Retains records and reports what its regime requires it to report, including suspicious activity, without notice to the payer.

The seller runs its own AML and KYC gating, sanctions screening and source-of-funds review on the counterparty, set out in the AML and KYC controls applied to physical gold transactions. Neither review substitutes for the other, and a payer who clears one has not thereby cleared the other. Golden Ark Reserve receives fiat only, holds no digital assets, and neither converts nor exchanges anything on the payer’s behalf.

What the leg costs and what governs its timing

The cost of the payment leg belongs to the platform and is separate from the price of metal: a conversion spread, a gateway or processing fee, the network fee for the inbound transfer, and whatever the receiving bank charges on the settlement. The seller’s quote covers the bars. None of these components is a published figure — they are set per platform and per transaction, and a purchase priced on the assumption that conversion is free is priced short by an unknown amount.

Timing is governed by screening rather than by conversion. Conversion itself is effectively instantaneous; bank settlement runs on value dates; screening is the step that can extend without warning, because a hit on an address or a missing Travel Rule field stops the payment where it stands rather than slowing it. The exposed interval is between the moment the seller’s quote is fixed and the moment cleared funds are confirmed against the order reference — the one window in the transaction where the price is committed and the money is not yet where it needs to be.

What the leg leaves behind

The payment leg produces four artefacts, and they are the reason it can be reviewed at all:

  • the gateway payment confirmation, bound to the order reference rather than standing as a loose credit;
  • the source-of-funds documentation the payer supplied, which travels into the counterparty file;
  • the fiat settlement confirmation from the receiving bank;
  • the screening outcome, which stays with the entity that performed it.

The fourth is the one that surprises reviewers. A sanctions or wallet-screening report is an internal record of the institution that produced it and is not issued to the payer; what the payer receives is a verification status, dated, with an internal reference. Asking a platform or a seller for the report itself is asking for a document that no regime contemplates releasing.

Against these sit the seller’s own documents — the pro forma invoice for the advance payment, then the allocation record and the final commercial invoice on the actual bars, tied to the same order reference. One reference running through both sets is what makes the chain reconstructible in a later audit.

How the leg fails

Failures here are procedural, and each leaves the buyer holding something specific.

A pending application read as authorisation. The firm can describe itself accurately as “in the process” while having no legal basis to serve the client. In the EU after 1 July 2026 this position is not a grey area: the activity is a breach, and a payment made into it is sitting inside the breach.

The brand read as the entity. Funds are sent to a group company that is not the authorised one. The regime’s safeguarding and segregation rules protect client money at the authorised entity; they do not reach an affiliate that holds none of those permissions.

Payment arriving without the order reference. The credit cannot be posted against the purchase and becomes an unattributed receipt. It is not lost, but it is not applied either, and the return path runs to the account it came from — which for a converted payment is a bank account, not the originating wallet.

Wallet control that cannot be demonstrated. Where funds arrive from a self-hosted address the payer cannot prove control of, the transfer is held pending ownership verification. The buyer’s money is neither returned nor applied while that runs.

Travel Rule data missing or incomplete. The receiving institution may suspend, reject or report the transfer. Rejection is the good outcome; a report the payer never sees is the other one.

De-risking at the receiving bank. The bank declines the inbound settlement on its own policy grounds regardless of the platform’s licence. This is a bank decision, and no licence held by anyone upstream overrides it.

Wind-down mid-instruction. A platform that loses or fails to obtain authorisation must stop, and orderly exit obligations govern client assets, not third-party purchases those clients were funding. The payer is left with a completed transfer and a purchase that never started, and recourse runs against the platform through its wind-down process.

Terms it is confused with

TermWhat it actually is
VASPThe FATF’s category, not a legal status. It has no direct equivalent in some regimes — the US has no VASP licence, and the obligations attach through money-transmitter status instead.
CASPThe EU legal status under MiCA. A firm is a CASP because a national competent authority authorised it as one, and only for the services listed.
MSBUS federal registration with FinCEN. Necessary, not sufficient, and not a licence.
Off-rampA function — converting digital assets to national currency and paying out to a bank account. A licensed platform may perform it; so may an unlicensed one, which is the whole problem.
OTC deskAn execution channel for large size, priced bilaterally. It describes how a trade is executed, not whether the executing firm is authorised.
Payment gatewayThe interface through which the payment is made. The gateway is software; the licence sits with the entity operating it.
CustodianHolds assets for others. Custody is one permission among several, and a platform authorised to exchange is not thereby authorised to hold.

Why the licence is a floor and the evidence is the protection

The FATF’s July 2026 update makes the limit of licensing arithmetic rather than argument. Eighty-three per cent of surveyed jurisdictions now have Travel Rule legislation in force, up from seventy-three per cent a year earlier — and of the jurisdictions that have it, close to half have taken no supervisory or enforcement action on it at all. Technical compliance with Recommendation 15 improved to around a third of assessed jurisdictions rated largely compliant as of April 2026, with a single jurisdiction fully compliant. A licence therefore establishes what a platform is obliged to do. It does not establish that the obligation was supervised, and it says nothing whatever about the transaction in front of the reviewer.

What does say something about that transaction is the artefact each control leaves behind, and the reference that binds them into one chain. That is a different kind of assurance, and it is the kind that survives contact with an auditor.

The structural point follows. Because the seller receives national currency only, holds no digital assets and issues no token or claim on metal, the buyer’s position after settlement does not depend on the platform remaining authorised, remaining solvent, or existing. The platform’s licence bounds the leg where the buyer’s money is exposed; once fiat has settled and bars are allocated by serial number, what the buyer holds is title to specific metal, and the payment leg is closed history. This is why the platform’s identity is not the load-bearing fact a counterparty needs. What is load-bearing is the order reference running from quote to allocation, the evidence set it assembles, and the record naming the buyer against numbered bars — none of which requires the buyer to take a view on a third party’s supervisor.

The funding route these controls sit inside is set out at Buy Gold with Crypto.

Request a LBMA refinery-origin gold proposal

Please submit your request and our team will contact you soon.
goldenarkreserve.com (Request Form)