Most licensing conversations focus on capital, custody technology and AML controls. Fewer applicants stop to read the single sentence in the Virtual Assets Act, 2026 that sets the legal standard for how a licensed virtual asset service provider must treat every customer relationship once it holds a licence.
That sentence sits in section 24(3), inside the chapter on prudential requirements, safeguarding and custody. It does not create a new duty in isolation — it sits alongside the segregation obligation in section 24(1), the insolvency ring-fence in section 24(2), and the anti-rehypothecation rule in section 24(4). Together they form the core of how the Act protects a customer’s virtual assets and cash while they sit with a licensed firm.
This article reads section 24(3) on its own terms: what “fiduciary duty” means in the statute, how it differs from an ordinary commercial contract, and what it is likely to mean in practice for a firm building its compliance framework.
What does section 24(3) of the Virtual Assets Act 2026 say?
Section 24(3) states that a Licensee owes a fiduciary duty to its customers and must act honestly, fairly and in the best interests of its customers at all times when dealing with Customer Assets. This is a standalone statutory duty, not a term implied from a customer agreement, and it applies for as long as the licence is held.
The operative text reads:
Licensee owes a fiduciary duty to its customers and shall at all times act honestly, fairly, and in the best interests of its customers when dealing with Customer Assets.
Three elements are worth separating. First, the duty is expressed as a status — “owes a fiduciary duty” — rather than a standard of care that has to be proven from the facts of each relationship, as it typically would in general trust or agency law. Second, the Act names three conduct standards inside the duty: honesty, fairness, and acting in the customer’s best interests. Third, the duty is scoped to “dealing with Customer Assets” — it attaches to the handling of the customer’s virtual assets and fiat balances, not necessarily to every commercial interaction a Licensee has with a customer.
“Customer Assets” is itself a defined term. Section 3(1)(vii) defines it as virtual assets and fiat currency belonging to a customer that a virtual asset service provider holds, safeguards, or otherwise has custody or control over on that customer’s behalf, expressly excluding assets owned by the provider itself. “Customer” is defined in section 3(1)(vi) as any natural or legal person who obtains or uses a virtual asset service from a Licensee, or who enters into a business or contractual relationship with a Licensee for such a service.
How is a fiduciary duty different from an ordinary contract duty?
An ordinary contract duty asks whether a party performed the specific promises it made. A fiduciary duty asks something broader — whether the fiduciary put the beneficiary’s interests ahead of its own, avoided conflicts, and dealt with the beneficiary’s property with loyalty, not merely with technical compliance.
In conventional legal doctrine, a fiduciary relationship typically arises from features such as one party holding power or property on behalf of another, an expectation of trust, and vulnerability of the beneficiary to the fiduciary’s discretion — the classic examples being a trustee and a beneficiary, or a company director and the company. A contract duty, by contrast, is bounded by its own terms: a firm that does exactly what its customer agreement says has usually discharged its contractual obligations, even if a more favourable outcome for the customer was available.
Section 24(3) imports the fiduciary standard directly into statute rather than leaving it to be argued from the facts. That has a practical consequence: a Licensee cannot contract out of it. A customer terms-of-service clause that purports to limit the firm’s duty to “acting reasonably” or to the four corners of the agreement does not displace a fiduciary duty that Parliament has imposed by statute. Our reading is that any such clause would sit in tension with section 24(3) and would not reduce the Licensee’s exposure if the Authority or a court found conduct that fell short of honesty, fairness or the customer’s best interests.
What conduct does the “best interests” standard rule out?
At minimum, it rules out treating a customer’s assets as a source of the firm’s own liquidity, prioritising the firm’s revenue over a customer’s outcome in a conflicted transaction, and using discretion over customer assets for any purpose other than the customer’s benefit. The Act reinforces this with two further, more concrete rules sitting either side of section 24(3).
Section 24(1) requires a Licensee to hold Customer Assets in segregated accounts, separate from its own assets, in the manner prescribed by Regulations. Section 24(2) then provides that, notwithstanding anything to the contrary in any other law, Customer Assets held by a Licensee do not form part of the Licensee’s estate in the event of insolvency or liquidation — meaning the firm’s creditors cannot reach customer holdings to satisfy the firm’s own debts. Read together with section 24(3), the structure is coherent: the fiduciary duty sets the conduct standard, segregation is the operational mechanism that makes it real, and the insolvency ring-fence is the legal backstop if the firm fails anyway.
Outside Chapter 4, section 41(1) imposes a parallel but broader duty: a Licensee must conduct its business honestly, fairly and professionally, in accordance with the best interests of its customers, and in a manner that upholds the integrity of the market. Section 44 adds a specific conflict-of-interest obligation, requiring a Licensee to identify, manage and disclose conflicts of interest and not place its own interests above those of its customers. Section 24(3)’s fiduciary duty over Customer Assets should be read as the asset-handling core of this wider market-conduct regime, not as a separate, narrower rule.
Does the fiduciary duty apply to every service a VASP provides?
The text of section 24(3) is anchored to “dealing with Customer Assets”, so its clearest application is to services where a Licensee actually holds, moves or exercises discretion over a customer’s virtual assets or fiat balance — custody, exchange execution, transfer and settlement, lending, and discretionary investment management among them. Where an activity does not involve possession or control of Customer Assets at all, section 41’s general duty of integrity and fair dealing is the more directly applicable standard.
Schedule I of the Act, referenced in section 18, lists the ten categories of licensed virtual asset service, and several build fiduciary-style language directly into their definitions. Service category 7, Virtual Asset Management and Investment Services, is defined as “acting in a fiduciary or agency capacity for the purpose of managing or administering another Person’s Virtual Assets”, including discretionary portfolio management and discretionary staking on a customer’s behalf. For a Licensee providing that service, the fiduciary standard is not just a background statutory duty — it is written into the definition of the licensed activity itself.
By contrast, Advisory Services under category 1 are defined as personalised recommendations rather than the exercise of control over assets. A pure advisory firm that never takes custody or discretion may fall more naturally under the section 41 conduct duty than the section 24(3) fiduciary duty, though where that firm also provides another licensed service involving Customer Assets, section 24(3) will apply to that part of its business.
What happens if a Licensee breaches the fiduciary duty?
The Act does not set out a bespoke penalty specific to section 24(3). Instead, breach of the fiduciary duty is a contravention of the Act, which brings it within the Authority’s general enforcement toolkit under Chapter 10 — administrative sanctions, licence variation, suspension or revocation, and, in serious cases, court proceedings.
Section 59(1) allows the Authority, where satisfied that a person has contravened any provision of the Act, to impose one or more sanctions: a written reprimand or public censure, a directive to cease or remedy the contravention, a financial penalty up to the prescribed maximum, suspension or revocation of the licence, or disqualification of a person from holding office in a Licensee. Section 59(4) sets a general fine ceiling of up to twenty-five million rupees for a contravention of the Act’s provisions. Separately, section 23(1)(a) lists contravention of any provision of the Act as a ground on which the Authority may vary, suspend or revoke a licence, after written notice and an opportunity to be heard.
Where a breach of the fiduciary duty coincides with dishonesty in disclosures to the Authority — for example, misrepresenting how customer assets were being handled — section 54(4) separately criminalises knowingly making a false or misleading statement in any application, return or document submitted to the Authority, carrying imprisonment of up to three years, a fine of up to twenty million rupees, or both. A Licensee aggrieved by an Authority decision under any of these routes may appeal to the Virtual Assets Appellate Tribunal under section 63, within thirty days of the order being communicated.
Is the fiduciary duty in the Act the same as the fit-and-proper standard?
No. They are related but distinct. The fit and proper standard under section 20 is a gate that Controllers, Sponsors, the Chief Executive Officer, directors and other Key Individuals must pass to be approved to run or control a Licensee in the first place, and it is continuing in nature. The fiduciary duty under section 24(3) is an operational conduct standard that governs how the licensed entity, once approved, actually deals with a customer’s assets day to day.
A person can pass the fit-and-proper test at licensing and still cause the firm to breach its fiduciary duty later — for example, by approving a business practice that treats customer holdings as available for the firm’s own working capital. The Authority’s fit-and-proper assessment is forward-looking, about character and competence; section 24(3) is a live, ongoing legal duty attaching to conduct.
How should a Licensee build the fiduciary duty into its compliance framework?
Regulations giving detailed content to section 24(3) had not, at the time of writing, been published, so firms should not wait for a prescriptive checklist before acting. The safer approach is to treat the statutory language — honesty, fairness, and best interests — as the design brief for internal policy, and to test every process that touches Customer Assets against it.
Practical starting points include:
- mapping every point in the customer journey where the firm takes possession, custody or discretion over a customer’s virtual assets or fiat balance, and confirming each is covered by a segregation control under section 24(1)
- reviewing fee structures, spreads and order-routing practices for any feature that could reward the firm at the customer’s expense in a way inconsistent with “best interests”
- documenting, under section 44, how conflicts of interest are identified, managed and disclosed wherever the firm’s own trading, market-making or affiliate arrangements touch a customer transaction
- confirming that no customer consent to lending, pledging or encumbering assets under section 24(4) is obtained through unclear or bundled terms, since that consent must be explicit, informed and revocable
- building the section 27 annual audit and proof-of-reserves cycle into the compliance calendar early, since that audit is the mechanism that verifies segregation is actually happening in practice, not merely promised in policy
Firms structuring their corporate setup and internal governance around the licence should treat this as a board-level standard, not solely a compliance-department one, given that section 59(1)(e) allows the Authority to disqualify individuals from holding office in a Licensee for a contravention of the Act.
About this analysis
This analysis was prepared by the CoinConnect research desk from the Virtual Assets Act, 2026, read as published. Where practice is not yet settled or guidance has not been issued, that is stated in the text above.
Regulatory positions change and specific requirements should be verified against the current position published by the relevant authority before you act on them. This is information and analysis, not legal advice, and it does not create an advisory relationship. Take professional advice on your own circumstances.
Entering Pakistan's crypto market?
CoinConnect handles market entry, partnerships, PR and launch for exchanges and Web3 companies moving into Pakistan and South Asia.
Visit CoinConnect