A crypto platform can look like one product to the customer while performing three legally different functions.
The customer sees one application. Behind it, the operator may run the trading venue, receive and execute the customer’s order, and control the wallets holding the customer’s assets.
Under Pakistan’s PVARA framework, those functions may require three separate licence categories:
- Exchange Services for operating the market or matching infrastructure;
- Broker-Dealer Services for receiving, transmitting or executing customer orders and dealing as agent or principal; and
- Custody Services for safeguarding or controlling customer virtual assets or their means of access.
The licence classification follows what the business actually does—not whether the product is marketed as an “exchange,” “broker,” “OTC desk,” “wallet” or “all-in-one platform.”
Exchange, Broker-Dealer and Custody — trust bar
- Exchange: Operates the venue, order book or matching system Broker-Dealer: Handles and executes Client Orders or deals as agent or principal
- Custody: Safeguards or controls Client Assets or private keys
- Capital floors: Exchange PKR 500 million; Broker-Dealer PKR 75 million; Custody PKR 200 million
- Multi-category floor: Generally the highest applicable requirement, subject to risk-based additions
- Incidental asset holding: Temporary and strictly necessary for execution, transfer or settlement
- Typical custodial centralized exchange: May require all three categories
The three licences at a glance
Issue | Exchange Services | Broker-Dealer Services | Custody Services |
Core function | Operate the market infrastructure | Intermediate, execute or deal | Safeguard or control assets and access |
Typical activity | Order book, matching engine, swap facility, Trading Rules | Order receipt, routing, agency execution, RFQ, OTC or principal dealing | Wallet operation, private-key control, safekeeping and administration |
Main regulatory risk | Market integrity, fair access, listing, surveillance and system resilience | Best Execution, Fair Pricing, order priority and conflicts | Loss, theft, key compromise, segregation and insolvency protection |
| Minimum paid-up capital | PKR 500 million | PKR 75 million | PKR 200 million |
| Does it automatically permit the other two? | No | No | No |
The Virtual Assets Act, 2026, Pakistan Virtual Asset Services Regulations, 2026 and Activity-Specific Regulations, 2026 must be read together. PVARA also summarises each category on its official licensing page.
Exchange Services: Operating the market
An Exchange licence concerns the infrastructure and rules through which buying and selling interests meet.
The Exchange Services Regulations permit a licensee to:
- operate a trading venue, order book, Matching System, swap facility or similar arrangement;
- establish and enforce rules for access and participation;
- determine matching logic and order types;
- admit, suspend, restrict or delist virtual assets;
- supervise orderly trading and market integrity; and
- perform functions directly necessary to operate the venue.
A Matching System is defined broadly. It can include an order book, algorithm, crossing engine, request-for-quote arrangement, swap facility or another mechanism that brings together or executes buying and selling interests.
The legal question is therefore not limited to whether the platform displays a traditional order book. A system that establishes the market rules and systematically brings together multiple trading interests may fall within Exchange Services even if its user interface looks like a simple “convert” function.
Principal Exchange obligations
An Exchange must establish:
- transparent Trading Rules and access criteria;
- listing and ongoing-monitoring standards;
- fair and non-discriminatory market operations;
- controls over matching, cancellations and erroneous trades;
- market surveillance for manipulation, wash trading, spoofing, layering and abusive self-trading;
- conflict controls for related-party listings, affiliated participants and proprietary activity;
- procedures for outages, Trading Halts, suspensions and reopening;
- reliable pricing and market-data methodologies; and
- orderly settlement and default-management arrangements.
Final settlement should ordinarily occur within 24 hours of execution where within the Exchange’s reasonable control. A longer ordinary cycle must be notified to PVARA before implementation and disclosed to participants.
What an Exchange licence does not automatically permit
Operating the venue does not automatically authorise the operator to:
- receive and execute orders for customers as their intermediary;
- act as an OTC or RFQ counterparty;
- hold customer private keys or provide ongoing wallet custody;
- lend customer assets or provide standalone margin financing;
- manage customer portfolios; or
- offer derivatives or leveraged products.
Those features must be mapped to the relevant additional categories or express permissions.
Broker-Dealer Services: Handling and executing orders
A Broker-Dealer sits between the customer and the transaction.
Under the Broker-Dealer Services Regulations, the licensee may, subject to its licence:
- receive and transmit Client Orders;
- execute orders on behalf of clients;
- deal in virtual assets as agent or principal;
- trade on its own account where expressly permitted; and
- provide placement or distribution services for an issuer as intermediary.
A Client Order is broad enough to include an instruction, indication of interest, request for quote, acceptance of quote, dealing instruction, subscription or placement instruction.
The category can therefore cover several models:
- agency brokers routing orders to external exchanges;
- OTC desks sourcing liquidity for clients;
- request-for-quote dealers quoting from their own inventory;
- aggregators selecting among several venues;
- principal dealers internalising Client Orders; and
- intermediaries placing or distributing virtual assets for issuers.
Agency execution and Best Execution
Where the Broker-Dealer acts as agent, it must take all reasonable steps to obtain the best possible result, considering price, costs, speed, likelihood of execution and settlement, size, nature and other relevant factors.
Best Execution is not a guarantee of the best price in every case. It requires a documented Execution Policy, rational venue selection, ongoing monitoring and evidence that customer interests drive the execution process.
Principal execution and Fair Pricing
Where the Broker-Dealer deals against the customer as principal—including through RFQ, internalisation or its own inventory—it must provide pricing that is fair, transparent and non-discriminatory.
The price should be assessed against prevailing market conditions and reasonably available liquidity. Customers must not be systematically disadvantaged because the dealer controls the quote or trades from its own book.
The Broker-Dealer conflict problem
The firm must state whether it acts as agent, principal, market maker, RFQ counterparty, placement intermediary or proprietary trader. It must manage conflicts arising from:
- routing orders to affiliated exchanges;
- receiving rebates or revenue shares;
- internalising customer flow;
- prioritising proprietary trades;
- warehousing inventory; and
- supporting affiliated issuers or tokens.
Where 20% or more of quarterly customer order flow is routed to one liquidity source or affiliated venue, the identity and relevant conflicts must be disclosed to PVARA within 30 Business Days after the quarter ends.
What a Broker-Dealer licence does not automatically permit
It does not itself authorise discretionary portfolio management, ongoing custody, standalone transfer and settlement services, lending and borrowing, derivatives, leverage or issuance where those functions fall within another category.
Custody Services: Controlling assets or keys
Custody concerns control, not merely where software is hosted.
The Custody Services Regulations cover safekeeping or administration for customers of:
- virtual assets; or
- private keys, seed phrases, signing devices, authorisation credentials or other means of access enabling transfer or disposal.
Providing non-custodial software or hardware does not, by itself, constitute Custody where the customer retains exclusive control of the private keys.
The perimeter changes where the operator can unilaterally or jointly initiate, approve or prevent a transfer, recover credentials, control withdrawal permissions or otherwise exercise effective control over customer assets.
Principal Custody obligations
A Custodian must maintain:
- legal and operational segregation of Client Assets;
- wallet and ledger records identifying each customer’s entitlement;
- insolvency arrangements supporting exclusion from the Custodian’s estate;
- controlled hot, warm and cold wallet allocation;
- secure key generation, storage, backup, rotation and recovery;
- multi-factor, multi-approval, multi-signature or equivalent controls where appropriate;
- daily reconciliations, with greater frequency where risk requires;
- proof-of-reserves or equivalent assurance;
- incident, migration and recovery procedures; and
- clear custody agreements and monthly statements, unless another permitted frequency applies.
A material discrepancy not rectified within 24 hours must be notified to PVARA. Where a customer-asset shortfall exists, the Custodian must take immediate steps to make it good from its own resources or other available arrangements and notify PVARA and affected clients without delay.
Customer consent does not expand the licence
A Custody licence does not itself authorise lending, staking, pledging, rehypothecation, investment, issuance or other deployment of customer assets.
Even where the customer provides prior, explicit and informed consent, the Custodian must hold any additional licence required by the substance of the activity. Ownership remains with the customer unless the law and a separately regulated arrangement provide otherwise.
Custody cannot be outsourced in substance
A Custodian may use wallet-infrastructure and technology providers in a limited supporting capacity. It cannot transfer its principal custody responsibility or cease exercising effective control, governance and oversight.
Ultimate safeguarding responsibility, wallet architecture, key-management governance, reconciliations and access supervision must remain with the licensed Custodian.
Incidental activity is not a shortcut
The general Activity-Specific Regulations permit a licence category to include an activity reasonably necessary or ancillary to the authorised service only where it is:
- subordinate to the main service;
- not marketed, offered or remunerated separately;
- not an independent business line;
- not materially different in risk; and
- conducted under the relevant safeguarding, conduct and AML controls.
The activity must be described to PVARA and receive written approval. PVARA can require another category if its scale, frequency, risk or commercial significance makes it a substantive service.
For a Broker-Dealer, incidental asset holding is narrower still. It must be temporary operational possession strictly necessary for execution, transfer or settlement. It cannot amount to ongoing custody, independent safeguarding or unrestricted control.
Calling an omnibus customer wallet “settlement support” will not avoid a Custody licence if the platform continuously controls the assets.
When are multiple licences required?
The right classification comes from mapping each functional layer.
Exchange only
A venue operates market rules and matching infrastructure, while approved participants trade directly and independent custodians control assets. The operator does not handle orders as intermediary or hold customer keys.
Likely requirement: Exchange Services, with analysis of any settlement or ancillary functions.
Broker-Dealer only
An OTC or aggregation platform receives customer instructions and routes or executes them on external venues. Customer assets remain with an independent licensed custodian, apart from genuinely temporary settlement possession.
Likely requirement: Broker-Dealer Services.
Custody only
An institutional wallet provider safeguards keys and transfers assets only under customer instructions. It does not match trading interests, recommend trades or execute transactions as dealer.
Likely requirement: Custody Services.
Exchange plus Broker-Dealer
The operator runs a venue and also receives, routes, internalises or executes customer orders, acts as market maker or deals against customers from inventory.
Likely requirement: Exchange and Broker-Dealer Services.
Broker-Dealer plus Custody
An OTC platform executes customer orders on external venues and maintains customer wallets before and after execution.
Likely requirement: Broker-Dealer and Custody Services.
Exchange plus Custody
The operator provides the venue and ongoing customer wallets, while customers enter orders directly without the operator acting as their execution intermediary.
Likely requirement: Exchange and Custody Services, subject to the precise order-handling model.
Exchange, Broker-Dealer and Custody
A centralized platform operates the matching engine, receives and executes Client Orders, trades as principal or agent, and controls customer deposits, balances and withdrawals.
Likely requirement: All three categories.
The same platform may additionally require Transfer and Settlement, Lending and Borrowing, Derivatives, Management and Investment, Advisory or Issuance permission depending on its functions.
Multi-licence capital requirements
The statutory floors are:
- Broker-Dealer Services: PKR 75 million;
- Custody Services: PKR 200 million; and
- Exchange Services: PKR 500 million.
For a VASP holding several categories, regulation 32 states that the applicable prudential floor is generally the highest requirement—not automatically the sum—unless PVARA determines that another activity creates a separate, non-overlapping risk requiring an additional amount.
An Exchange–Broker-Dealer–Custody applicant should therefore treat PKR 500 million as the starting floor, not promise that it is the final requirement. PVARA may impose additions for custody exposure, market risk, technology, operational complexity, customer scale or cross-border risk.
The VASP must also maintain net liquid assets of at least 1.2 times adjusted monthly operating expenses and satisfy insurance, customer-asset safeguarding and other continuing requirements.
Governance for an integrated platform
One legal entity may hold multiple categories, but its control framework must distinguish them.
An integrated platform should maintain:
- separate responsibility maps for venue operation, brokerage and custody;
- independent market surveillance and compliance;
- separation between proprietary trading and Client Order information;
- controls over affiliated venue routing and liquidity sources;
- distinct wallet, reconciliation and safeguarding accountability;
- committees for listing, risk, custody and market conduct;
- category-specific management information; and
- incident escalation covering market, execution and asset-protection failures.
The principal licensed activity cannot be outsourced. Supporting technology or operational functions may be outsourced subject to due diligence, written controls, PVARA access and continuing responsibility.
Practical perimeter questions
Before selecting the licence categories, ask:
- Who establishes the market and matching rules?
- Who receives the customer’s instruction?
- Who decides where and how the order is executed?
- Does the operator trade as agent, principal or both?
- Can the operator access or control customer keys or withdrawals?
- Are assets held only momentarily for settlement or continuously?
- Does the platform internalise orders or route to affiliates?
- Who performs settlement, and is it a separate commercial service?
- Are margin, lending, derivatives, staking or portfolio management offered?
- Which entity bears legal responsibility when execution, custody or settlement fails?
The answers should match the transaction diagrams, customer agreement, wallet architecture, revenue model and licence application.
Common classification mistakes
- Applying only for Exchange because the product is called an exchange. Branding does not classify the underlying functions.
- Treating every order as an Exchange activity. Customer intermediation may be Broker-Dealer Services.
- Treating wallets as an Exchange feature. Ongoing asset or key control may require Custody.
- Overusing incidental custody. Temporary settlement possession cannot become continuous safeguarding.
- Assuming customer consent replaces licensing. Consent does not authorise an unlicensed lending, staking or deployment service.
- Ignoring principal-dealing conflicts. Internalisation and proprietary inventory require fair-pricing and information-barrier controls.
- Adding the three capital floors automatically. The starting multi-category floor is generally the highest, subject to PVARA additions.
- Outsourcing the regulated core. Technology support may be outsourced; regulatory responsibility cannot.
- Forgetting connected categories. Transfer, lending, derivatives, management or issuance may also apply.
- Using one generic policy pack. Each category creates different risks, evidence and management reporting.
Final word
Exchange, Broker-Dealer and Custody licences regulate different positions in the same transaction.
The Exchange creates and governs the market. The Broker-Dealer handles the customer’s route into that market. The Custodian protects the assets before, during or after the trade.
When one platform occupies all three positions, it assumes all three sets of risks: market integrity, execution conduct and customer-asset protection. The correct licensing model must reflect that reality.
Start with the transaction lifecycle, not the product name. Follow the order, follow the asset and identify who has control at every stage. The required PVARA categories will usually become clear.
Legal disclaimer: This article provides general information as at 28 August 2026 and does not constitute legal, regulatory, financial or investment advice. Licence classification depends on the platform’s actual order, execution, venue, wallet, settlement and revenue arrangements. PVARA may impose additional categories, conditions, prudential requirements or interpretations. Applicants should obtain professional advice and confirm the current position directly with PVARA and other relevant authorities.
FAQs
1. Does every crypto exchange need all three licences?
No. A non-custodial venue that does not intermediate customer orders may need Exchange Services only. A typical centralized platform that runs the venue, executes customer orders and controls wallets may require Exchange, Broker-Dealer and Custody Services.
2. Can a Broker-Dealer hold customer assets?
Only incidentally where temporary possession is strictly necessary for execution, transfer or settlement and appropriate safeguarding applies. Ongoing holding or control requires Custody analysis.
3. Is a self-custody wallet provider a Custodian?
Not merely because it supplies software or hardware. If the customer retains exclusive key control, the Custody definition excludes the mere provision of that infrastructure. Recovery, co-signing or withdrawal controls may change the analysis.
4. Can an Exchange trade against its customers?
Only with the required licence and permissions, clear disclosure and strict conflict, market-conduct and proprietary-trading controls. Exchange authorisation alone should not be assumed sufficient for Broker-Dealer activity.
5. Must multi-licence capital be added together?
Not automatically. The highest applicable floor generally applies, but PVARA may require additional capital for separate and non-overlapping risks.
6. Does Custody permit staking customer assets?
No. Custody alone does not authorise staking or other deployment. Prior informed consent and any additional applicable licence are required.