Crypto exchange licensing: The Compliance Burden in Practice
Operating a crypto exchange (a platform that matches and settles digital-asset trades) without the right regulatory authorisation exposes the business to enforcement action, frozen banking rails and, increasingly, personal liability for the operators behind it. As supervisory regimes converge on the CASP (crypto-asset service provider) model pioneered by MiCA and adapted across the Gulf, Asia-Pacific and the offshore centres, the compliance burden has shifted from a one-time licensing exercise to a continuous operational discipline. This analysis maps what that burden looks like in practice, where the structural pitfalls sit, and how a well-advised business works through the multi-jurisdictional stack before it launches.
The compliance burden on a crypto exchange is no longer just a licence fee and a KYC policy. It is a layered set of authorisation obligations, capital adequacy requirements, AML/CFT (anti-money-laundering and counter-financing of terrorism) programme demands, Travel Rule (the obligation to pass originator and beneficiary data with a transfer) infrastructure requirements, and – critically – the question of whether a single home licence actually covers the jurisdictions where the exchange's users reside. Getting that analysis wrong early is expensive to correct.
This page works through the regulated perimeter, the multi-jurisdictional reality, the layers of the compliance programme, common structural mistakes, and the decision framework an operator needs before committing to a licensing strategy.
What activity actually triggers a licence requirement for a crypto exchange?
A crypto exchange triggers a licence requirement the moment it intermediates a trade, holds client assets, or converts one digital asset to another for a third party – regardless of where the entity is incorporated. The most common misconception in our practice is the belief that incorporation in a low-regulation jurisdiction insulates the business from supervision in the markets where its users actually reside. It does not.
Regimes vary in how they draw the perimeter. MiCA in the European Union applies to any entity providing crypto-asset services to persons within the EU, irrespective of where the entity is domiciled. The VARA regime in Dubai treats any solicitation of users in Dubai as sufficient jurisdictional nexus. The SFC in Hong Kong requires a VATP (virtual-asset trading platform) licence for any platform that actively markets to Hong Kong residents, even from an offshore base. The pattern is consistent: where the user is matters as much as where the company is registered.
The regulatory activity categories worth mapping at the outset are: spot trading or exchange (matching buyers and sellers); custody (holding client assets); OTC dealing (bilateral quote-and-trade); transfer and settlement services; staking or yield products; and lending against digital collateral. Each category may require a separate authorisation or may sit within a broader VASP (virtual asset service provider) registration, depending on the jurisdiction. Conflating them is one of the most reliable routes to a compliance gap.
Why does a crypto exchange always face a multi-jurisdictional compliance stack?
No serious crypto exchange operates in a single jurisdiction, and the compliance stack reflects that reality: the entity's home regime governs its authorisation, but the regimes of every market it serves impose their own access rules, AML obligations and consumer-protection conditions. In our cross-border practice, we routinely advise operators who have a licence in one hub and users in six others – and who have never been told that each of those six markets may require a separate registration, a notification, or at minimum a geo-block to avoid an unlicensed-services charge.
The EU illustrates the structure clearly. MiCA's passporting mechanism allows a CASP authorised in one member state to operate across all EU/EEA member states without re-authorising in each. That is a genuine efficiency. But the passport does not extend to the UK, Switzerland, the UAE or Singapore. Each of those markets has its own access regime: FCA cryptoasset registration under the Money Laundering Regulations governs the UK position; FINMA governs Switzerland; MAS under the Payment Services Act governs Singapore. An EU-passported CASP serving clients in all three is still unlicensed in all three.
The offshore centre dimension adds another layer. A BVI or Cayman-incorporated exchange benefits from a relatively low-cost registration regime under the BVI FSC's VASP Act or CIMA's Virtual Asset Service Providers Act, respectively. Those registrations satisfy the home-jurisdiction requirement. They do not satisfy the access requirements of any of the major retail markets. An exchange registered in the Cayman Islands and serving EU residents without MiCA CASP authorisation is, from the EU supervisory perspective, operating an unlicensed service – whatever its home paperwork says.
For a scoped assessment of your entity's jurisdictional exposure before you scale, contact OBOLUS at Map your options or write to us at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity, the user base, the banking rails – change the analysis materially.
What does the compliance programme actually require from an exchange operator?
The compliance programme a licensed exchange must maintain goes well beyond a KYC policy on a PDF. In our experience advising businesses through authorisation and ongoing supervision, the regulator's expectations cluster around five structural pillars: governance, AML/CFT, the Travel Rule, capital and liquidity, and ongoing reporting.
On governance, the major hubs – including VARA, MAS, the SFC and ESMA under MiCA – require a compliant management structure: at minimum a qualified MLRO (money-laundering reporting officer), a compliance function with defined reporting lines, and – in several regimes – a locally resident or locally licensed compliance officer. These are not paper roles. Supervisors are increasingly testing the substance of governance in examination cycles, asking to see evidence of board-level oversight of compliance risk.
On AML/CFT, the baseline is set by the FATF (Financial Action Task Force) Recommendations, in particular Recommendation 15 covering virtual assets. Every licensed exchange must maintain a risk-based AML policy, customer due diligence procedures (including enhanced diligence for higher-risk customers), transaction monitoring, and suspicious activity reporting. The specifics – what a risk rating triggers, what a monitoring threshold looks like – vary by jurisdiction, but the FATF baseline applies across all of them.
The Travel Rule adds a data-transfer layer that many early-stage operators underestimate. When an exchange executes a transfer above the applicable threshold, it must collect and transmit originator and beneficiary information to the receiving VASP. The technical infrastructure to do this – a VASP-to-VASP messaging solution – is a live implementation project, not a policy decision. Regulators in Singapore, the EU and the UAE are actively examining whether exchanges have working Travel Rule solutions deployed, not just documented intentions.
Capital adequacy requirements vary by activity category and jurisdiction. All figures are held as [VERIFY]-tagged placeholders in our internal registry, which means we write about them qualitatively: the capital floor for a trading-platform licence is meaningfully higher than for a pure transfer-services registration, and the major hubs – VARA, MAS, the SFC – set their requirements at a level designed to exclude undercapitalised operators. For a specific business, the right figure is the one confirmed by a licensed local adviser against current legislation.
What are the most common structural mistakes operators make when licensing a crypto exchange?
The most common structural mistake is treating the licence as the finish line rather than the starting gate. Operators we advise regularly arrive having obtained a registration – often in a lighter-touch regime – with the expectation that the compliance work is done. In practice, the registration opens the door to the ongoing compliance obligation, and it is the ongoing programme that supervisors examine, and enforcement actions address.
Four patterns recur with particular frequency.
First, the mismatch between registered activities and actual operations. An exchange registers as a transfer-service provider and then, for commercial reasons, begins offering spot trading or custody without amending its authorisation. From the regulator's perspective, this is unlicensed activity – the same consequence as having no licence at all. We have seen this happen not through bad faith but through the organic growth of a product roadmap that outpaced the compliance review cycle.
Second, the assumption that an offshore registration satisfies market-access requirements in the client's home markets. As described above, it does not. A Cayman-registered exchange with a majority of its user base in Germany and France is operating an unlicensed service under MiCA in two of the EU's largest economies. The marketing and banking relationships built on that structure are at risk the moment a supervisory examination or a user complaint triggers scrutiny.
Third, inadequate Banking and payment-rails due diligence. A licence is necessary but not sufficient for banking. Financial institutions in the major hubs operate their own VASP risk frameworks. An exchange that has not stress-tested its banking relationships – specifically the question of whether the correspondent bank's own compliance policy permits its correspondent to service a VASP – may find its rails closed weeks after launch. We have seen this happen. Banking due diligence is part of the pre-launch compliance stack, not an afterthought.
Fourth, Travel Rule non-implementation at scale. An operator may have a policy and a vendor agreement but no live, tested data-transfer capability. When the regulator or a counterparty VASP conducts diligence, the gap becomes apparent. In several jurisdictions, this is now a standalone supervisory focus, not merely a box on an annual compliance checklist.
How should an operator decide which jurisdiction to license in?
The right licensing jurisdiction for a crypto exchange is the one that matches the operator's actual user geography, capital position, governance substance, and long-term product roadmap – and that decision is almost always multi-variable rather than driven by a single factor such as speed or cost.
A useful framing is to map the decision across three profiles.
Profile A – EU-focused retail exchange: The operator targets European retail customers and wants regulatory credibility with both users and institutional counterparties. The logical path is CASP authorisation under MiCA in a member state with a functioning NCA, using the EU passport to cover the full EEA market. The authorisation process is substantive – governance requirements, capital adequacy, whitepaper obligations where applicable – and the timeline is a matter of months to over a year depending on the NCA's queue. The key risk is underestimating the operational readiness that MiCA NCAs now expect to see demonstrated, not merely documented.
Profile B – Gulf/MENA-focused or global institutional exchange: The operator is building a B2B or institutional platform and the primary commercial hub is Dubai or Abu Dhabi. VARA's activity-based licensing regime in Dubai, or the FSRA's framework within ADGM, provides the regulatory home. Both regimes are well-regarded by institutional counterparties and banking partners. The application process involves detailed business-plan review, governance substance checks, and ongoing supervisory engagement. Neither is a light-touch registration; both are designed for operators who can demonstrate operational and financial depth.
Profile C – Offshore-incorporated exchange with a global retail footprint: The operator wants a fast, cost-efficient home registration while building toward the major-market licences. The BVI or Cayman VASP registration provides the home-jurisdiction piece. The critical discipline here is the geo-blocking and jurisdictional-restriction programme: the operator must credibly restrict access from markets where it does not hold the required authorisation, or the offshore registration provides no cover. In our practice, operators in this profile routinely underestimate the documentation burden and the banking complexity that the offshore base creates.
No profile is universally best. The decision turns on specific facts. A one-size answer is the most expensive advice an operator can receive.
A practical illustration: When an exchange's licensing gap surfaces at the banking layer
In a recent cross-border matter, a payments and exchange business had operated for several years under an offshore registration that matched its original, geographically limited business model. As the business expanded into EU-resident customers, the registered activities and the market-access coverage were never updated. The gap surfaced not from regulatory examination but from the exchange's correspondent bank, which conducted a periodic VASP risk review and identified that a material share of the customer base resided in jurisdictions where the exchange held no recognised authorisation. The bank issued a 60-day notice of account termination. We were engaged to map the remediation path: a phased MiCA authorisation process in a member state, interim geo-restriction of the affected user segments, and a parallel engagement with the bank's compliance team to document the remediation timeline. The exchange retained its banking relationships through the transition period, and the authorisation process advanced within the documented timetable. The matter underlines a pattern we see repeatedly: compliance gaps tend to surface at the banking layer before they surface at the regulatory layer, and the window for remediation is shorter than operators expect.
A common assumption: one offshore licence is enough to serve clients globally
A common assumption among early-stage operators is that a single offshore registration – in the BVI, Cayman Islands or a similar centre – provides adequate legal cover for a global user base. The assumption is incorrect, and the consequences of acting on it are material.
The offshore VASP Acts in both the BVI and the Cayman Islands are home-jurisdiction registration regimes. They govern what the entity must do to operate lawfully in those territories. They have no extraterritorial effect on the access requirements of the EU, the UK, Singapore, Hong Kong, the UAE or any other market with a functioning VASP supervision regime. A Cayman-registered exchange is unlicensed in Singapore for the purposes of the Payment Services Act. The MAS does not recognise the Cayman registration as a substitute for a Digital Payment Token service licence.
The practical consequence is that an exchange relying on a single offshore registration to serve a global user base is carrying unquantified regulatory risk in every market where its users reside. When enforcement attention, a banking review, or a user complaint focuses that risk, the remediation cost – legal, operational and reputational – is almost always higher than the cost of building the right licence stack at the outset.
We are direct about this in our practice: offshore registration is a component of a licensing strategy, not a substitute for one.
If a prior application stalled, a banking relationship closed, or a compliance review surfaced a structural gap, write to OBOLUS at Map your options or contact us at info@oboluslaw.com. A second read frequently surfaces the structural reason and the route back.
When should a crypto exchange operator engage specialist legal counsel?
Specialist digital-asset counsel adds the most value at three specific points: before the jurisdictional decision is made, when the compliance programme is being built for the first time, and when a supervisory or banking event requires rapid response.
Pre-decision engagement – before the entity is incorporated and the licence strategy is fixed – allows the full licence, banking and tax stack to be mapped against the operator's actual user geography, product roadmap and capital position. Changes made at the design stage cost a fraction of what they cost after a structure is committed. In our experience, the operators who engage at this stage consistently build more durable structures than those who engage after a problem has arisen.
Programme-build engagement – when the exchange is designing its AML policy, its Travel Rule solution, its governance structure and its ongoing supervisory reporting – benefits from counsel who understand what regulators in the relevant hubs actually examine in practice, not just what the legislation formally requires. The gap between formal compliance and operational supervisory compliance is where most enforcement actions originate.
Reactive engagement – when a banking notice, a regulatory enquiry, or a user dispute requires immediate legal attention – demands a team with both the regulatory and disputes capability to advise simultaneously on the legal exposure and the recovery path. Cross-border matters frequently require allied counsel in the relevant jurisdiction working in coordination with lead counsel on the strategy.
The common thread is timing. Regulatory risk in digital assets compounds quickly. A licensing gap that takes a few weeks to remediate in month two of operations may take years and a material capital commitment to remediate in year three.
Self-assessment: Is your exchange's compliance programme fit for supervisory examination?
The following questions are not legal advice. They are the questions a regulator conducting a supervisory review is likely to ask. An honest audit against them is a useful diagnostic.
- Does the entity's authorisation cover every activity it actually conducts – including custody, OTC dealing, staking products and any yield feature?
- Has the operator confirmed, with local legal advice, that the home licence satisfies the market-access requirements of every jurisdiction where users reside?
- Is the MLRO role filled by a qualified individual with documented reporting lines to the board and demonstrable compliance with the home regime's fitness-and-propriety requirements?
- Is there a working, tested Travel Rule solution in place – not merely a vendor agreement or a policy document?
- Has the exchange confirmed, with its banking partner, that the correspondent bank's own compliance policy permits the relationship with a VASP of this type?
- Does the AML programme include risk-based transaction monitoring with documented thresholds and a tested suspicious-activity reporting pathway?
- Is there a documented process for updating the authorisation when the product roadmap changes?
A "no" to any of these questions represents a compliance gap that a supervisor or a banking partner may identify before the operator does.
Related at OBOLUS
- Licensing and Registration for Digital Asset Businesses – how OBOLUS maps the full licence, banking and tax stack for exchange and custodian operators across more than seventy jurisdictions.
- Digital Asset Licensing in the Bahamas – a jurisdiction-specific guide to what the Bahamas regulatory regime requires and who it suits.
- Stablecoin Freeze Requests: A Cross-Border Perspective – how freeze requests against USDT and USDC work across jurisdictions and what operators need to know.
FAQ
How long does a crypto licence take to obtain?
Timelines vary significantly by jurisdiction and licence category. A lighter-touch registration in the BVI or Cayman Islands is typically measured in weeks. A full CASP authorisation under MiCA with a substantive NCA – or a VARA activity-based licence in Dubai – is typically measured in months, and can extend well beyond that where the application requires supplementary documentation or a fitness-and-propriety review of senior personnel. Operators should build the licensing timeline into their commercial runway from day one, not treat it as a parallel track to product development.
Which jurisdiction is best for licensing my crypto business?
There is no universally best jurisdiction. The right choice depends on the operator's user geography, product mix, capital position, governance substance and banking strategy. An EU-focused retail exchange and a Gulf-based institutional platform have fundamentally different licensing requirements. A jurisdiction that appears fast or inexpensive at the registration stage may impose a higher ongoing compliance cost or provide inadequate market access for the operator's actual user base. The decision should follow a full mapping of the licence, banking and tax stack against the business's specific facts.
Do I need a separate custody licence?
In most flagship jurisdictions, custody of client digital assets is a regulated activity that requires either a standalone authorisation or an explicit extension of an existing licence. Under MiCA, custody and administration of crypto-assets on behalf of clients is one of the defined CASP service categories. Under VARA and the MAS Payment Services Act, custody is similarly treated as a distinct regulated function. An exchange that holds client assets without the specific custody authorisation is typically conducting an unlicensed activity, even if the exchange itself is licensed. The answer is jurisdiction-specific; a licensing audit should confirm the position for every regime in which the operator is active.
OBOLUS is an independent digital-asset law boutique acting exclusively for businesses. We advise exchanges, custodians, token issuers and funds on licensing across more than seventy jurisdictions, on disputes and on-chain asset recovery across more than twenty-five forums, and on the tax, banking and compliance structures that surround them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit – and across the jurisdictions where your users actually are, not just where your entity is incorporated. We advise crypto exchanges, custodians, token issuers and funds across more than seventy licensing jurisdictions. To discuss your situation, contact us at info@oboluslaw.com or reach our team directly at t.me/oboluslaw.
By Glen Sorensen, Disputes & Recovery Analyst – specialist in cross-border enforcement risk, supervisory exposure and the compliance failures that precede exchange licensing disputes.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.