Operating a crypto exchange without the right licence is not a calculated risk – it is a timed exposure. Regulators across the major hubs are closing the gap between enforcement notice and account suspension. When banking rails freeze and users lose access to their funds, the reputational and financial damage compounds within hours. Legal counsel for crypto exchanges means mapping the full regulatory lifecycle – formation, VASP registration (the formal process of recording a virtual asset service provider with a national supervisor), regulatory authorisation, banking access, compliance architecture, and dispute readiness – before any of those risks become live events.
This page sets out how OBOLUS approaches the legal mandate for a crypto exchange, from entity selection through to enforcement defence, across the multiple jurisdictions an exchange typically touches. The cross-border dimension is not optional: where your entity sits, where your users are, and where your banking lives are three different legal questions, and the answers rarely point to the same regime.
Why Exchanges Face a Harder Legal Problem Than Most
A crypto exchange sits at the intersection of more regulatory regimes simultaneously than almost any other digital-asset business model. The exchange activity itself triggers licensing requirements under VASP or CASP frameworks. The custody of user funds triggers a separate regulated activity in most flagship regimes. Fiat on-ramps and off-ramps engage payment services law. Marketing to users in a given country can engage financial promotion rules independently of where the entity is licensed. Each layer carries its own capital, AML/CFT, and reporting obligations.
Regulators have also moved toward activity-based analysis. VARA in Dubai licenses exchange activity, custody, and transfer functions as distinct activities, each with its own rulebook and capital expectation. MiCA, the EU's Markets in Crypto-Assets Regulation, creates a CASP (Crypto-Asset Service Provider) authorisation that passports across the EU and EEA – but the authorisation scope must match the activities actually performed. An exchange that begins offering staking, lending, or tokenised product access after authorisation may have crossed into a category its licence does not cover.
The risk is not theoretical. In our practice we regularly advise exchanges that have operated under a VASP registration that covers AML obligations but does not authorise the full range of exchange services they provide to EU users. The structural gap between what the entity holds and what the business actually does is the most common enforcement trigger we see.
The process above describes the standard path. Your facts – the entity, the user base, the banking – change the analysis. For a scoped assessment of where your exchange sits against current crypto licence requirements, contact OBOLUS at info@oboluslaw.com.
The Legal Lifecycle of a Crypto Exchange
The legal mandate for an exchange does not begin at the licence application. It begins at formation, and every structural decision made before the application affects both the licensing outcome and the tax and banking positions that follow.
The lifecycle runs in recognisable stages. Entity selection determines which jurisdictions are available, what the minimum capital requirements will be, and how profits flow to founders and investors. A BVI or Cayman holding structure above a licensed operating entity is a common architecture – but the regulated entity must itself meet the capital, governance, and local-presence requirements of its jurisdiction. A shell with a warm body does not satisfy a well-developed regulator's substance expectations.
The licensing phase is the most operationally demanding. Under VARA, the application covers the full rulebook for each licensed activity. Under the MAS Payment Services Act in Singapore, the tier of licence – standard payment institution or major payment institution – turns on transaction volume thresholds. Under the SFC regime in Hong Kong, VATP (virtual asset trading platform) applicants face a detailed vetting process covering governance, custody, cybersecurity, and market-integrity controls. None of these are paper exercises.
Post-authorisation, the compliance phase is continuous. AML/CFT programmes must reflect the FATF Travel Rule (the obligation to pass originator and beneficiary data with a transfer above the applicable de minimis threshold). Suspicious transaction reporting, transaction monitoring calibration, sanctions screening, and periodic internal audits are ongoing obligations, not one-time deliverables. The exchange that treats licensing as the finish line rather than the starting gate is the one that attracts supervisory attention within two years.
How Does the Cross-Border Reality Bite for an Exchange?
A crypto exchange cannot be treated as a domestic business that happens to accept foreign users. The moment a user in a regulated jurisdiction accesses the platform – and in many regimes, the moment the platform markets to them – the exchange has a regulatory nexus in that jurisdiction. Managing that nexus is not optional.
The EU MiCA passporting mechanism allows a CASP authorised in one member state to provide services across the EU. That is a genuine structural advantage – one authorisation, twenty-seven markets. But the authorisation must cover the correct activity categories, the home-state NCA (national competent authority) must have capacity, and the passporting notification process takes time. Operators who assume the passport is automatic have, in our experience, been surprised by the lead time.
Outside the EU, the position is more fragmented. The FCA in the United Kingdom requires cryptoasset businesses to register under the Money Laundering Regulations – a regime separate from any MiCA or VARA authorisation. FINMA in Switzerland applies its own token taxonomy and licence analysis. The AIFC/AFSA regime in Kazakhstan offers a common-law digital-asset framework for exchanges serving Central Asian and CIS-adjacent markets. Each of these is a distinct application, a distinct set of ongoing obligations, and a distinct relationship with a supervisor.
The practical answer for most exchanges is a tiered licence strategy: one primary operating jurisdiction with the strongest regulatory credibility for institutional counterparties, complemented by targeted registrations in user-concentration markets. We map that stack before the client commits capital to any single jurisdiction.
What Does the Banking Problem Actually Look Like?
Banking remains the single most persistent operational risk for a licensed exchange. Regulatory authorisation does not guarantee banking access. Financial institutions apply their own risk frameworks, and a crypto exchange – even a well-licensed one – sits in a category that many correspondent banking chains treat as high-risk or excluded.
In our cross-border practice, we have seen exchanges obtain a VARA licence or a MiCA-pathway authorisation and then spend months without a fiat settlement account. The problem is structural: the bank's compliance function needs to understand the exchange's AML programme, its user base, its transaction monitoring, and its governance before it will open an account. Presenting a licence certificate without that supporting narrative is insufficient.
EMI (electronic money institution) licences in EU jurisdictions, ADGM in Abu Dhabi, and specialist payment-service-provider relationships in Singapore are among the routes exchanges use to solve the fiat layer. None of them is frictionless. The exchange that builds its banking strategy in parallel with its licence application – not after it – is materially better positioned. We integrate the banking and payments analysis into the licensing mandate from day one.
The tax layer compounds this. Where profits are recognised, how token inventory is treated on the balance sheet, whether a permanent establishment has been created in a user-concentration market – these are live questions for any exchange with multi-jurisdictional operations. We structure licensing, banking, and tax as one mandate rather than three disconnected workstreams.
Decision Matrix: Which Legal Path Fits Your Exchange Profile?
No two exchange operators reach the licensing question from the same position. The right instrument, timeline, and risk tolerance depend on the business model, the target user base, and the capital available. The following profiles describe the most common situations we advise on.
Early-stage operator, primarily retail, EU-facing. The MiCA CASP authorisation is the logical primary licence. It provides passporting across the EU, it is now the standard credential institutional payment partners expect from a European-facing exchange, and it brings the exchange into a supervisory regime that correspondent banks understand. The timeline varies by NCA and the complexity of the application, but it is not a short process. Planning should begin well before the intended commercial launch.
Established operator, institutional focus, MENA market. VARA in Dubai or the FSRA within ADGM are the primary options, depending on whether the business will operate within or outside the DIFC financial free zone. Both regimes are activity-based. An exchange providing custody, trading, and transfer functions needs separate approval for each activity under VARA. The capital and compliance requirements are material; the reputational outcome – for institutional counterparties and banking access – is strong.
Exchange serving Asian markets, with significant retail volume. MAS under Singapore's Payment Services Act and the SFC's VATP regime in Hong Kong are the two dominant options. The MAS DPT (Digital Payment Token) service licence subjects the operator to AML/CFT standards that are among the most operationally demanding in Asia. The SFC VATP approval is a high-bar process but gives access to Hong Kong's institutional and retail market under a credible regulatory credential. A dual Singapore/Hong Kong structure is not unusual for exchanges targeting the full Asia-Pacific user base.
Early-stage, non-EU, seeking speed to market. The AIFC/AFSA regime in Kazakhstan and certain Caribbean frameworks – BVI FSC under the VASP Act 2022, or CIMA in Cayman – offer faster paths to a registered entity. These are not full CASP/VARA equivalents in regulatory weight, but they provide a compliant operating base while the primary licence application is in progress. The risk is that banking access and institutional counterparty relationships will be more limited until the primary-jurisdiction application completes.
A micro-matter from our recent practice: in a recent licensing matter, a spot exchange operator with a growing EU user base came to us holding a legacy VASP registration in a Baltic jurisdiction. The registration covered AML obligations but did not authorise the range of trading services the platform actually provided. We mapped the activity gap, scoped the MiCA CASP application in coordination with allied counsel in the relevant member state, and restructured the operating entity to meet the substance and governance requirements the NCA expected. The application was submitted before the operator's banking counterparty issued a termination notice under its periodic review cycle.
If a prior application stalled or a banking relationship ended, a second read of the structure can surface the gap and the route forward. Write to OBOLUS at info@oboluslaw.com – or message us via t.me/oboluslaw if the clock is running.
Compliance Architecture: What Does Good Look Like?
A well-structured compliance programme for a crypto exchange is not a policy library. It is a set of operational controls that survive a regulatory inspection, a correspondent bank's due-diligence questionnaire, and, if the worst happens, a court's scrutiny of whether the operator acted reasonably.
The AML/CFT programme must be risk-based. That means a written risk assessment that reflects the exchange's actual user base, product set, and jurisdictional reach – not a generic template downloaded from a compliance vendor. The Travel Rule implementation must identify the solution the exchange uses to pass originator/beneficiary data, how that solution handles transfers to or from non-obliged entities, and what the fallback procedure is when the counterpart VASP does not respond. These are questions a well-resourced supervisor will ask within the first hour of an inspection.
Under MiCA, CASPs are subject to detailed record-keeping, complaint-handling, and conflicts-of-interest requirements that go well beyond AML. Under VARA's operating rulebooks, market-integrity controls – order-book transparency, insider-trading prohibition, client-asset segregation – are enforceable obligations. Exchanges that have grown organically and then sought regulatory status often discover that their internal processes were not designed to the regulatory standard. Retrofitting is possible; it takes time and a clear gap analysis.
In our practice, the compliance elements that most consistently require pre-application remediation are: the beneficial-ownership register (regulators expect it to be current and complete before the application is filed, not as a condition of approval); the MLRO appointment (the individual must meet the regulator's fit-and-proper criteria and must have genuine operational authority); and the transaction-monitoring calibration (alert thresholds set too high are a red flag in any inspection).
Disputes and Enforcement: What Happens When It Goes Wrong?
Every licensed exchange carries enforcement risk. The question is not whether a dispute or regulatory inquiry will arise but whether the business has the legal infrastructure to respond quickly and effectively when it does.
Regulatory inquiries – a request for information from a supervisor, a notification of a themed review, a dawn visit – require an immediate legal response. The instinct to respond fully and quickly is usually correct; the instinct to respond without legal review is usually not. Statements made to regulators carry weight in any subsequent enforcement proceeding. The legal privilege position on internal documents prepared in connection with an inquiry is a real consideration.
Exchange disputes arise in several forms: user claims over frozen withdrawals, counterparty claims over settlement failures, insolvency-adjacent disputes where a user or creditor asserts a proprietary claim over assets held on the exchange. In England and Wales, courts have confirmed that crypto assets are capable of being property – establishing the doctrinal basis for proprietary claims, injunctions, and recovery orders that crypto exchange operators must now treat as genuine litigation risk. The DIFC Courts have similarly confirmed the availability of worldwide freezing orders in crypto disputes. Singapore and Hong Kong have well-developed jurisprudence in the same direction.
For exchanges that operate custodially – holding user assets rather than simply facilitating non-custodial transactions – the insolvency dimension is significant. How client assets are segregated, whether they sit on the exchange's balance sheet or in a structurally separate custody vehicle, and what the applicable insolvency law says about proprietary claims are questions that should be answered at the architecture stage, not when a liquidity event makes them urgent.
The Common Assumptions We Correct Before They Become Problems
A common assumption among exchange founders is that a single offshore licence is enough to serve clients globally. It is not. A VASP registration in the BVI or Cayman satisfies AML/CFT obligations in those jurisdictions. It does not authorise the operator to provide exchange services to users in the EU, the UK, Singapore, or Hong Kong. Each of those jurisdictions has its own licensing requirements, and each can take enforcement action against a non-licensed operator that is actively serving its residents.
A related assumption is that if the entity is not incorporated in a regulated jurisdiction, the local regulator cannot reach it. That analysis has not held up across major enforcement actions. Regulators apply nexus tests – where the service is accessed, where it is marketed, where the users are – not just where the company is registered. The FCA, ESMA's national competent authorities, and MAS have each taken action against entities with no local incorporation but a demonstrable local user base.
A third assumption is that licensing is the end of the legal work. In our experience, post-authorisation compliance, banking maintenance, and the ongoing monitoring of regulatory change – particularly as MiCA secondary legislation develops and VARA publishes updated rulebooks – represent the majority of the legal work over a business's lifetime. The licence is the credential. The ongoing compliance programme is what protects it.
We map the licence stack across operating, custody, and payment layers before clients commit. That mapping prevents the structural gaps that generate enforcement risk downstream.
Related at OBOLUS
- Licensing and Registration for Digital-Asset Businesses – the full regulatory authorisation practice, across 70+ jurisdictions
- VARA Licence Application in Guernsey – jurisdiction-specific analysis of the VARA authorisation process
- Fund Manager Licensing for Early-Stage Founders – structuring the regulatory and fund layer for digital-asset investment vehicles
FAQ
How long does a crypto licence take to obtain?
Timeline varies significantly by jurisdiction and licence category. A VASP registration in a Caribbean framework typically completes faster than a CASP authorisation under MiCA or a VATP approval under the SFC regime in Hong Kong. The preparation phase – governance, AML programme, capital documentation – often takes longer than the regulatory review itself. For most flagship licences, operators should plan for a process measured in months rather than weeks, and begin preparation well before the intended commercial launch date.
Which jurisdiction is best for licensing my crypto business?
There is no single answer. The right jurisdiction depends on your primary user geography, your business model, your banking strategy, and your capital position. VARA in Dubai, MiCA passporting through an EU member state, MAS in Singapore, and the SFC regime in Hong Kong each serve different operator profiles and offer different regulatory credentials to institutional counterparties. The licence that provides EU passporting will not serve an MENA-focused exchange as efficiently as a VARA authorisation. We assess these variables before recommending a primary-jurisdiction strategy.
Do I need a separate custody licence?
In most well-developed regimes, custody of client assets is a regulated activity distinct from exchange or trading services. Under VARA, custody is a separately licensed activity with its own rulebook. Under MiCA, the safekeeping and administration of crypto assets is a discrete CASP service category. An exchange that holds user funds – whether in a hot wallet, a cold storage facility, or a third-party custodian arrangement – must analyse whether its licence covers that custody function or whether a separate authorisation is required. Holding client assets without the right authorisation is among the most serious compliance gaps a supervisor can identify.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers, and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking, and compliance structures that sit around them. We structure licensing, banking, and tax as one mandate rather than three disconnected workstreams – mapping the operating, custody, and payment layers before you commit. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com.
By Aisha Tan, Licensing and Jurisdictions Analyst – specialising in multi-jurisdictional VASP and CASP authorisation strategies for exchange and custody operators.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.