Insurance gaps in director liability, custody and wallets often surface only after crypto firms relocate, says Relm’s global distribution chief
Dubai — Europe’s Markets in Crypto-Assets regulation crossed its transitional deadline on 1 July 2026, and unlicensed crypto firms lost the right to serve EU clients overnight. Dubai has absorbed much of the resulting migration, with legal advisors reporting a surge of European founders exploring the UAE as an alternative base. But relocating a company’s headquarters does not automatically relocate its regulatory exposure, according to Christian Ogden Davies, Global Head of Distribution and Innovation at Relm, a Bermuda-licensed specialty insurer for digital-asset, fintech and emerging-technology firms.
Founders redomiciling from Europe to Dubai often assume MiCA no longer applies once they hold a VARA licence, Ogden Davies says, but firms still serving European users remain bound by both frameworks at once. Gaps tend to surface in director liability, custody, wallet infrastructure and cross-border coverage, particularly when founders assume a single “crypto insurance” policy covers every scenario from hot wallet theft to a regulatory investigation. Specialist underwriting capacity in the Gulf remains limited too, meaning well-governed firms that can explain their risk clearly will fare better than those simply banking on relocation alone.
Below, Ogden Davies unpacks where the real insurance gaps lie, and what regulators and insurers can do together to close them.
Interview excerpts
What insurance exposures do crypto founders underestimate most when redomiciling from Europe to Dubai after the MiCA deadline?
The first thing to say is that moving to Dubai does not mean you are no longer thinking about MiCA. If you want to carry out crypto activities with European users, you are still going to have to think about MiCA. Simply saying “we are now based in Dubai, so Europe no longer applies” is not accurate. Some founders underestimate this point. A common assumption is that redomiciling changes the whole risk picture, but in reality, it can add another layer to it. Firms may now have Dubai requirements on one side, and European obligations on the other, if still serving that market. A good example is Tether and USDT. Tether has not gone down the MiCA route in the same way as some other issuers, and European platforms have had to look at whether they can continue supporting USDT under the MiCA framework. This shows the point: sitting outside Europe does not mean European regulation disappears if a product is still touching European users. From an insurance perspective, the exposures founders often underestimate are the less glamorous ones: regulatory liability, D&O, custody, wallet infrastructure, crime, cyber, professional indemnity, and how those policies respond when the business is operating across more than one jurisdiction.
Does the Gulf’s specialist insurance capacity have the depth to absorb a wave of European crypto firms, or is a coverage crunch inevitable?
Specialist capacity in the region is not sufficient to absorb a major wave of crypto firms without pressure. Very few insurers really understand digital asset risks and are willing to put meaningful capacity behind them, and this is the core issue. This is not just a question of insurance capital being available in the region, but rather whether underwriting expertise exists that understands the risks, the exposures, and how these businesses actually operate. The Gulf market is growing, and we are seeing more support from the region, but if firms need larger limits, a lot of that excess capacity still has to come from international markets. So I would not say a coverage crunch is inevitable, but capacity is definitely restricted. Companies that are well run, well governed, and can explain their risk properly will be in a much better position.
Firms that assume insurance will just be available because they have relocated are likely to find it much harder.
Which coverage gaps, from director liability to custody risk, do founders typically discover only after they have relocated?
The main point is that insurance requirements are not the same across regimes. VARA and MiCA are different frameworks. VARA requires professional indemnity, directors’ and officers’ insurance, and commercial crime insurance for virtual assets held in hot wallets. MiCA approaches the issue differently, with prudential and custody obligations, including requirements around client assets and liability where client crypto-assets are lost because of something attributable to the provider. So founders can find the cover they had in one jurisdiction does not neatly map into what is expected in another. The common gaps tend to be D&O, custody, crime, wallet infrastructure, cyber, professional indemnity, and cross-border coverage. A founder may think they have “crypto insurance,” but the question is what this actually means. Does it cover hot wallet loss? Cold storage? Employee theft? A third-party technology failure? A regulatory investigation? A customer claim? Loss of client assets? This is where the gaps usually appear. Insurance is not always absent altogether; rather, the policy does not match the business model. Mismatches with the regulator’s expectations or the jurisdictions the company is operating in are also common.
How should purpose-built regulators and insurers work together to close the gap between licensing a crypto firm and actually protecting it?
I think it’s always important to point out that licensing and protection aren’t the same thing. A regulator can create a regime and say to a company, “If you want to operate here, you need to have X, Y, and Z in place.” The company can then come back and say, “We have X, Y, and Z.” This is the licensing piece. But if something goes wrong, this does not automatically mean the clients, the directors, or the wider market are protected. This is where insurance can play a really important role. Regulators can use insurance almost as a second pair of eyes, and Relm has often been that pair of eyes helping regulators regulate. When VARA was developing its framework, Relm was consulted on the potential insurance requirements that could sit within the regulation. This kind of collaboration matters because insurance is not just a box to tick. Insurance can give regulators another practical lens on how these businesses operate and where risk may sit. So if an insurer is willing to provide capacity to a company, this can give the regulator an extra line of defence. Regulators are not the only ones looking at the business. A third party with capital at stake is also assessing the risk. This matters in emerging sectors because specialist insurers often see a lot more of the market than any one local regulator. VARA may see the firms it has licensed locally, while Relm has worked with crypto clients across many countries, giving us a broad view of how these risks show up in practice. Insurance should not replace regulation, but it can reinforce it, giving regulators, clients, and the market another layer of confidence that the business has been looked at through a risk lens, not just a licensing lens.
Source: Tahawul Tech

