Building a digital asset business in The Bahamas through effective governance

By L. Ryan Pinder K.C. | Pinder Commercial Chambers

For a digital asset business choosing The Bahamas, registration is the beginning of a continuing regulatory relationship. The durability of the business depends on how it safeguards client assets, manages conflicts, controls technology and responds when conditions change. Those questions matter to founders, directors, investors and the institutions considering whether to do business with it.

My position in discussions about fintech has been that measured regulation can support innovation by providing a credible environment in which to operate. That credibility must be demonstrated in practice. A business should be able to explain how its legal commitments, technology and everyday decisions protect its clients.

Build the operating model around the regulatory perimeter

The Digital Assets and Registered Exchanges Act, 2024 took effect on 29 July 2024. It provides the central statutory framework for digital asset businesses operating in or from within The Bahamas, including specific provisions for custody, advice and management, staking, exchanges and stablecoins. [1] [2]

A proposed business should map each activity before selecting its application route. Operating an exchange, safeguarding assets and managing investments involve different functions and risks. The analysis must also consider whether another Bahamian regulatory regime applies. A digital asset registration should not be assumed to authorise every securities, banking or payment activity the business wishes to undertake.

This exercise is particularly important when a group operates internationally. The Bahamian entity’s responsibilities should be identifiable within the wider organisation. Group policies can assist, but the local board and management must understand which decisions, records and controls they are responsible for.

Custody requires legal and technical clarity

Client-asset protection is a central feature of the 2024 Act. Section 18 requires a registered custody provider to segregate client digital assets from its own holdings, with separation on distributed-ledger addresses and in internal accounts. It also addresses client consent for omnibus arrangements and procedures intended to insulate custodial assets from the provider’s estate. [1]

For a client or institutional counterparty, the practical questions are direct. Who controls the keys? How are assets attributed to each client? Who can approve a transfer? How will access be maintained if an employee leaves or a service provider fails? The answers should be consistent with the custody agreement and the actual technical arrangements.

Client consent must correspond to the service provided

The Act places conditions on lending, reusing, pledging or otherwise encumbering assets entrusted for safekeeping, including prior client consent and clear risk disclosure. It also requires custody agreements and accessible disclosures. A firm should distinguish ordinary safekeeping from arrangements that expose assets to additional investment, lending or staking risks. [1]

A broad statement in a customer agreement is a poor substitute for a service that clients can understand. Boards should ask whether disclosures accurately describe the movement and use of assets, withdrawal arrangements and material dependencies. Product design and communications should be reviewed together.

For illustration, a platform introducing a yield product should assess whether assets remain in custody or become subject to a different legal arrangement, which entity owes the client obligations and what happens on default. That review should precede launch and address the permissions required for the proposed activity.

Effective controls must remain effective under pressure

The Act sets requirements for exchange systems and controls, recordkeeping, protection against unauthorised data access and conflicts of interest. It also provides for compliance and money laundering reporting functions. These requirements should inform the operating model rather than remain confined to an application document. [1]

As a governance matter, directors should receive useful information about asset reconciliation, incidents, unresolved control weaknesses and material client complaints. Reporting should identify decisions that require attention, the person responsible and the action taken. A board needs enough information to challenge management and understand whether the business is operating within its approved scope.

Operational resilience also requires practical preparation. The firm should test how it responds to compromised credentials, unavailable infrastructure, disrupted withdrawals and the loss of a key service provider. The legal team, technical team and management should understand their respective responsibilities during an incident.

Group relationships and outsourcing need scrutiny

Technology infrastructure, custody functions and support services may depend on other entities. The business should document those dependencies, the information it can obtain, its rights to intervene and its ability to change provider. Contracts should support regulatory access, incident management and an orderly exit where necessary.

The Act expressly requires prior Commission approval before outsourcing the compliance-officer or money-laundering-reporting-officer functions. Other outsourcing arrangements must be assessed against the applicable requirements and the firm’s particular business. Delegation should be accompanied by clear oversight and access to reliable evidence of performance. [1]

Conflicts require decisions and controls

A group may combine exchange operations, custody, investment activity and affiliated service providers. The board should understand where those relationships create competing interests. Decisions about asset use, related-party arrangements and the treatment of clients should be supported by clear policies, appropriate approvals and records that demonstrate how conflicts were managed.

For institutional investors conducting due diligence, this means looking beyond the existence of a registration. They should assess the scope of authorised activities, the quality of the management team, contractual protections and the evidence that controls operate as described. Regulatory status is a necessary part of that analysis, not an assurance against every commercial or technological risk.

Expansion should trigger a fresh legal review

New products, a change in custody arrangements or a proposed acquisition can alter the risk profile and regulatory position. Section 17 of the Act addresses prior approval for specified changes and requires a plan when a registrant seeks to change or expand its activities. Management should build the necessary regulatory review into product and transaction timetables. [1]

Stablecoins require particular attention. The Act contains dedicated provisions addressing issuers, reserve assets, reporting and redemption. A business considering a stablecoin should assess the proposed rights, backing and operating arrangements against that framework before making commitments to investors or users. [1]

The Bahamas’ opportunity in digital assets depends on combining legal development with responsible execution. In my view, the strongest businesses will be those that can demonstrate both technical competence and disciplined governance. At PCC, we help clients assess regulatory scope, structure their arrangements and translate obligations into workable governance and contractual protections.

Discuss digital asset regulation and governance with PCC

Adapted from L. Ryan Pinder K.C.’s addresses to the D3 Bahamas conference on 11 October 2023 and the BFSB CEO Conclave on 29 January 2026. Updated for publication.

Sources and further reading

[1] Digital Assets and Registered Exchanges Act, 2024 — sections 6–9, 17–24, 29–35 and 49–53.

[2] Digital Assets and Registered Exchanges Act, 2024 (Appointed Day) Notice, 2024 — S.I. No. 54 of 2024.

This article provides general information and commentary as at 10 September 2026. It is not legal or tax advice. Application depends on the facts, the relevant documents and the laws of each jurisdiction concerned.

Scroll to Top