EST · MMXXVI
Home/Insights/Glossary/Reverse Solicitation: A Legal Guide for Digital-Asset Businesses
Licensing & Registration

Reverse Solicitation: A Legal Guide for Digital-Asset Businesses

Reverse Solicitation: A Legal Guide for Digital-Asset Businesses. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. T

Reverse solicitation is a regulatory carve-out that permits a business operating outside a jurisdiction to serve a customer in that jurisdiction — without holding a local licence — provided the customer approached the firm entirely on its own initiative, without any prior marketing, inducement or promotional activity by the firm directed at that customer or at customers in that market. The concept appears, in varying forms, across MiCA, the ADGM/FSRA regime, the MAS Payment Services Act and most other major digital-asset regulatory regimes. For operators, it is not a general licence substitute; it is a narrow fact-specific exemption that regulators are actively narrowing.

This guide sets out what reverse solicitation means in practice, how the leading regimes define its boundaries, where businesses routinely misapply it, and what the cross-border consequences look like when the exemption fails.

What Is Reverse Solicitation and Why Does It Matter for Crypto Operators?

Reverse solicitation is a condition-based exemption, not a standing permission. A firm may rely on it only when a specific customer contacted the firm without any prior act by the firm — no advertisement, no referral incentive, no targeted communication of any kind — directed at that customer or at the jurisdiction in which that customer resides. The word "reverse" is precise: the flow of commercial initiation runs backward from the normal direction, from customer to firm rather than from firm to customer.

For a digital-asset business, this matters because the default rule in almost every regulated hub is simple: serve customers in a jurisdiction, hold a licence in that jurisdiction. Reverse solicitation breaks that default — but only in a defined set of facts. Regulators treat it as an exception to be demonstrated, not a right to be assumed.

Under MiCA, the EU's regime for crypto-asset service providers, the reverse-solicitation window is explicit and intentionally narrow. A CASP (crypto-asset service provider) may provide services to an EU customer at that customer's own exclusive initiative without a full MiCA authorisation. The moment the firm responds to that customer contact by offering additional services, or by extending the relationship in a way that was not driven entirely by the customer's own request, the exemption falls away for the entirety of the relationship going forward. ESMA and the national competent authorities have signalled clearly that they regard this provision as a genuine last resort, not a structural feature of a cross-border business model.

In our licensing practice, we see operators underestimate how quickly an apparently legitimate reverse-solicitation fact pattern converts into an unlicensed activity problem. The common trigger is a marketing programme — a referral code, a social media campaign, a geo-targeted advertisement — that preceded customer contact, even if the operator believes the contact itself was spontaneous.

How Do the Major Licensing Regimes Treat Reverse Solicitation?

The principal digital-asset regimes each address reverse solicitation differently, and the differences carry real operational risk for a business that assumes one version of the rule applies everywhere.

MiCA (EU/EEA). The carve-out is codified. A customer's own exclusive initiative is the threshold test. ESMA guidance emphasises that the test is evaluated at the level of each customer and each service. A firm that ran an EU-facing social media account, even one that stopped short of a direct offer, will find it difficult to demonstrate that subsequent customer contact was entirely unsolicited. The regime also extends MiCA obligations — including full whitepaper and disclosure requirements — to arrangements that nominally rely on reverse solicitation but in substance constitute a distribution strategy.

VARA (Dubai). VARA's activity-based licensing structure makes the reverse-solicitation question secondary to the activity question. If a firm is providing virtual-asset exchange, transfer or custody services and any of those activities touch Dubai-based customers, VARA's expectation is authorisation. VARA has not published a codified reverse-solicitation safe harbour equivalent to MiCA's. Operators seeking to serve UAE customers from an offshore base should treat the position as regulated unless specifically confirmed by VARA in writing.

ADGM/FSRA (Abu Dhabi). The FSRA within the Abu Dhabi Global Market takes a similar position: regulated activities involving virtual assets require permission; any reliance on a solicitation-direction argument must be supported by documented evidence of the customer's initiation and the absence of any marketing directed at the UAE market.

MAS (Singapore). Under the Payment Services Act, a digital payment token service provider serving Singapore customers without a DPT licence can invoke reverse solicitation, but the Monetary Authority of Singapore has issued guidance that applies the test strictly. The MAS focuses on whether the firm took any step — direct or indirect — to attract Singapore-based users, including through app-store availability, social media presence targeting Singapore users, or referral programmes accessible from Singapore.

FCA (United Kingdom). The FCA's financial-promotion rules impose a separate layer. Even where the activity itself might qualify for a reverse-solicitation carve-out under the general authorisation regime, communicating a financial promotion to a UK person — including a post, a reply, a push notification — requires either FCA authorisation or an exemption. The financial-promotion regime operates independently of the solicitation-direction question. An operator can be compliant on one and non-compliant on the other simultaneously.

BVI FSC and CIMA (Cayman). The BVI VASP Act 2022 and the Cayman VASP Act both contemplate registration or licensing of virtual-asset service providers. Neither regime has a detailed codified reverse-solicitation safe harbour. The practical effect is that offshore structures relying on these registrations to serve customers in regulated markets must independently satisfy the reverse-solicitation test of each destination market, not merely hold a registration in the offshore jurisdiction.

CTA #1

If you are relying on reverse solicitation across multiple markets, the exposure point is rarely where you think it is. The process above describes the standard analysis. Your specific facts — the entity's marketing history, the customer's jurisdiction, the nature of each service — change the conclusion materially. For a scoped assessment of your current exposure, contact OBOLUS at info@oboluslaw.com.

Where Does Reverse Solicitation Break Down in Practice?

Reverse solicitation fails most often not because the law is unclear but because the facts that operators create around their businesses are inconsistent with the exemption's requirements.

The most common failure mode is prior marketing. A firm that geo-targeted advertisements, maintained a social media account with followers in a regulated market, appeared in a third-party comparison or ranking site, participated in a public conference in that jurisdiction, or ran a referral programme accessible from that market has, in all probability, already disqualified itself from relying on reverse solicitation for customers who come from that market afterward. Regulators do not require a direct causal link between the marketing and the specific customer who contacts the firm. The standard is whether the firm directed activity at that market.

The second failure mode is service extension. Even where the initial contact was genuinely customer-initiated, a firm that subsequently cross-sells, upsells or otherwise extends the relationship on its own initiative loses the exemption for the extended services — and, under MiCA, potentially for the whole of the ongoing relationship. Operators who treat reverse solicitation as a licence to begin a relationship and then manage it as a normal client engagement are misreading the rule.

Third, the documentation problem. If an enforcement authority asks whether a particular customer contact was unsolicited, the burden of demonstrating that fact rests on the operator. Firms that cannot produce contemporaneous evidence of customer initiation — a record of the customer's first inbound contact, the absence of any prior outbound communication to that customer, the IP logs confirming no geo-targeted advertising preceded the contact — cannot rely on the exemption after the fact.

In a recent licensing matter, a payment services company had been operating across three EU markets on the assumption that its customer relationships were all reverse-solicitation compliant. A preliminary audit of its CRM records and advertising data showed that campaigns had run in two of those markets in the eighteen months prior to the customer relationships in question. We worked through the factual record, identified which customer cohorts remained defensible and which did not, and structured a voluntary notification approach to the relevant national competent authority alongside an accelerated MiCA authorisation process. The outcome was controlled. An enforcement-led discovery process would not have been.

Why Does Reverse Solicitation Create a Cross-Border Compounding Problem?

A digital-asset business operating across five markets does not have one reverse-solicitation question; it has at least five, each assessed under a different regulatory regime with different standards, different enforcement cultures and different documentation expectations.

The compounding problem arises because the marketing and outreach activities that disqualify a business from relying on the exemption in one market are typically not market-specific. A social media account, an app-store listing, a referral programme — these reach all markets at once. An operator that deploys any of these tools in the course of building its business is simultaneously creating a disqualification event in every regulated market where the tool had reach.

The entity structure adds another layer. A group with an offshore holding company and an operating subsidiary in one jurisdiction often assumes that the subsidiary's licence covers the group's global service delivery. It does not. Each legal entity providing services to customers in a regulated market is assessed independently. Where services are provided by an entity that holds no licence in the customer's market and cannot demonstrate reverse solicitation, the activity is unlicensed regardless of what other entities in the group hold.

Banking is the practical enforcement mechanism in many cases. When a bank or payment-rail provider conducting its own due diligence identifies that a business is providing regulated services in markets where it holds no licence and cannot demonstrate a valid exemption, the common result is account termination or transaction blocking — not after a regulatory enforcement order, but as a unilateral risk decision. The business discovers its banking problem before it discovers its regulatory problem, but both are symptoms of the same underlying structure.

For operators sitting between two or more of the leading hubs, the licence map and the reverse-solicitation analysis must be constructed together. Choosing to license in one hub but rely on reverse solicitation in others requires a market-by-market assessment, documented and reviewed regularly, not a one-time legal opinion.

A Common Assumption: Is a Single Offshore Licence Enough?

A widely held assumption among early-stage digital-asset businesses is that a registration in a permissive offshore jurisdiction — the BVI, Cayman, or a similarly accessible regime — provides a sufficient legal basis for serving clients globally. This assumption is incorrect, and it is one of the more consequential misreadings of how cross-border licensing works.

An offshore VASP registration in the BVI or under the Cayman VASP Act confers authority to carry on virtual-asset service provider activities under those jurisdictions' laws. It does not confer any permission to serve customers in the EU, the UK, the UAE, Singapore or any other regulated market. Each of those markets applies its own licensing or registration requirements to businesses that serve customers in that market, and the question of whether those requirements are triggered is answered by looking at the nature of the service and the direction of any solicitation — not by looking at what the operator holds offshore.

The reverse-solicitation exemption is the narrow bridge between an offshore-only structure and legitimate multi-market activity. But as the preceding sections show, it is a bridge that requires precise engineering to be usable. A firm that relies on it without detailed market-by-market documentation is, in practice, operating unlicensed in those markets even if it holds a registration offshore.

This is not a theoretical risk. Regulators in the leading hubs have brought enforcement actions against businesses operating precisely this model. The EU's national competent authorities have used MiCA's transitional period to identify businesses that previously relied on reverse solicitation or cross-border exemptions and are now directing them toward full CASP authorisation. The FCA's financial-promotion enforcement record includes crypto businesses that assumed their offshore registrations provided UK marketing permissions they never held.

CTA #2

If a prior application stalled or a banking relationship was closed following a licensing review, the structural reason is often traceable. A second read of the entity structure, the licence map and the solicitation facts can surface the route forward. To map your licence, banking and compliance stack across each active market, write to OBOLUS at info@oboluslaw.com.

When Does Reverse Solicitation Trigger a Disputes Question?

Reverse solicitation is primarily a licensing question, but its consequences can extend into disputes — and the disputes context is one that operators rarely anticipate before it arrives.

The most direct route from a failed reverse-solicitation analysis to a disputes outcome is regulatory enforcement. Where a regulator determines that a business was providing regulated services without authorisation, the remedies available to the regulator typically include disgorgement, restitution orders and in some regimes the power to void contracts entered into in breach of the licensing requirements. A business that contracted with hundreds or thousands of customers on the basis of an unlicensed activity faces potential claims from those customers as well as the regulator, not merely a licensing deficiency.

The second disputes pathway is the bank-led freeze. As noted above, banks act on their own risk assessments. Where a bank identifies that a client's revenue derives from unlicensed activity in regulated markets, the response can include freezing accounts, filing a suspicious activity report and terminating the relationship. For a digital-asset business dependent on fiat rails, a bank-led account freeze is operationally equivalent to a regulatory enforcement action. Reversing it requires demonstrating either that the activity was licensed or that the reverse-solicitation exemption was properly satisfied, backed by contemporaneous documentation.

Third, disputes arise between counterparties when one seeks to avoid a contract on the basis that the other lacked the required authorisation when the contract was made. In several common-law forums — including England and Wales, the DIFC Courts and Singapore — courts have applied contract avoidance principles to arrangements entered into with unlicensed providers. For a digital-asset business, the practical effect of a successful avoidance claim is an obligation to return fees received, potentially with interest, and the loss of the counterparty relationship.

In a separate matter involving a custodial arrangement, a client we advised was faced with a counterparty assertion that the custodian lacked the necessary regulatory permission at the time of contracting. We worked through the factual chronology of the solicitation, reviewed the authorisation position at the relevant dates and identified that the reverse-solicitation exemption applied to the original relationship, though a subsequent variation in service scope had moved outside it. That distinction was central to the resolution. The earlier the analysis is done, the more options remain available.

Which Operators Need Full Licences and Which Can Rely on Reverse Solicitation?

The answer depends on the profile of the business: the markets it serves, the nature of its services, and the commercial infrastructure — primarily marketing and banking — it has deployed.

Profile A: Early-stage operator, no active marketing in regulated markets, customer inquiries arrive organically. Reverse solicitation may be defensible for a limited number of relationships in a limited number of markets. The requirement is contemporaneous documentation of each customer's initiation, the absence of any prior directed marketing, and a clear policy preventing service extension beyond what the customer requested. This profile should be treated as transitional: as the business scales, the facts that support the exemption become harder to maintain.

Profile B: Growth-stage operator, active social media, referral programmes, exchange listings or comparison-site presence in regulated markets. Reverse solicitation is not available. The marketing activity has disqualified the business in each market where it had reach. The appropriate path is a phased licensing programme covering the markets that generate material revenue, beginning with the highest-enforcement-risk jurisdictions — typically EU member states under MiCA, Singapore under the Payment Services Act and the UK under the FCA regime — and extending to secondary markets on a defined timeline.

Profile C: Established operator with an offshore registration (BVI, Cayman) serving a mix of institutional and retail customers across multiple time zones. The offshore registration does not provide a basis for serving regulated-market customers. The operator needs a market-by-market analysis of where customers are located, which activities trigger licensing, and whether any customer relationships can be grandfathered under a reverse-solicitation analysis while a licensing programme is underway. The CASP passporting mechanism under MiCA makes a single EU hub authorisation the most efficient route for EU coverage, while Singapore and Hong Kong require separate applications.

Profile D: Token issuer making offers to investors in multiple jurisdictions. Reverse solicitation applies differently to securities-law-adjacent offers than to service licensing. In most regimes, a public offer — including a public website, a Telegram channel or a Twitter announcement — eliminates any claim to reverse solicitation for the investors who respond. Issuers targeting institutional investors in specific markets need placement agent arrangements and targeted exemptions, not a blanket reverse-solicitation position.

What Documentation Does a Defensible Reverse-Solicitation Position Require?

A defensible reverse-solicitation position is documented, not simply asserted. Regulators and courts assess the exemption on the basis of evidence, and the operator bears the burden of establishing the facts that trigger it.

The minimum documentation set for any customer relationship on which reverse solicitation is relied comprises the following elements: a record of the customer's first inbound contact, including the channel, the date and the content of that contact; a confirmation that no outbound marketing was directed at the customer's market in the period before the contact; a geo-targeting and advertising log demonstrating the absence of targeted campaigns in the relevant market; a copy of the firm's reverse-solicitation policy at the time of the contact; and a record of the scope of services provided, demonstrating that no extension of services was made other than at the customer's own subsequent initiative.

This documentation set must be created and maintained contemporaneously. A policy document created after an enforcement inquiry, or a CRM record reconstructed from memory, will not satisfy a regulator's evidentiary standard. In our practice, we recommend that businesses with any meaningful volume of cross-border customer relationships build the documentation discipline into their onboarding process from the start — not as a reactive exercise when the regulatory question arises.

The policy itself should be approved at a senior level, reviewed on a regular schedule — at least annually and on each material change to the business's marketing activities — and linked explicitly to the firm's AML/KYC and compliance documentation. Where the business crosses a threshold at which voluntary registration or notification is available in a given market, that route should be considered alongside the reverse-solicitation analysis rather than treating the two as mutually exclusive.

How Do AML and the Travel Rule Interact with Reverse Solicitation?

Reverse solicitation addresses the threshold question of whether a firm must hold a licence to serve a particular customer. It does not address what obligations apply once the firm decides to serve that customer.

The Travel Rule (the FATF obligation to pass originator and beneficiary information with a virtual-asset transfer) applies to virtual-asset service providers regardless of how they came to hold the customer relationship. A firm relying on reverse solicitation to serve EU or Singapore customers is still a VASP for FATF purposes and is subject to the Travel Rule requirements of its home jurisdiction — and potentially of the customer's jurisdiction, depending on how the transaction routing works. Regulators in the leading hubs have clarified that the licensing threshold and the AML compliance threshold are independent questions.

FATF Recommendation 15 brought virtual assets within the FATF framework, and the application of AML/CFT obligations to VASPs is now a baseline expectation in every market covered by this guide. An operator relying on reverse solicitation must maintain AML/KYC standards appropriate to its home-jurisdiction registration and the standards expected in the customer's market. The failure to do so is an independent compliance exposure, separate from the licensing question.

In practice, this means that a business building a reverse-solicitation programme must think about two compliance stacks simultaneously: the licensing and exemption analysis for each market, and the AML/KYC and Travel Rule obligations that apply to the resulting customer relationships. Getting the licensing analysis right while neglecting the AML layer creates a different but equally serious exposure.

Related at OBOLUS

FAQ

How long does a crypto licence take to obtain?

Timelines vary considerably by jurisdiction and licence category. A MiCA CASP authorisation in an EU member state typically takes a number of months from a complete application submission, with the specific timeline set by the national competent authority. Singapore's MAS DPT licence process and the Hong Kong SFC VATP authorisation are both known for thoroughness and can extend well beyond initial estimates. Building in preparation time — for entity structuring, AML documentation and capital readiness — before the formal application is submitted is the most reliable way to control the overall timeline. We advise clients to plan the application phase and the pre-application phase as a combined programme.

Which jurisdiction is best for licensing my crypto business?

No single jurisdiction is universally "best." The right licensing hub depends on your service model, your customer markets, your banking needs and your AML/compliance capacity. A MiCA CASP licence in a well-resourced EU member state provides passport access across the EU and EEA, which is valuable for EU-focused businesses. VARA in Dubai suits operators targeting the UAE and the Gulf. MAS in Singapore anchors Southeast Asian market access. Businesses serving multiple regions typically need a multi-hub licence strategy rather than a single registration. We map this across operating, custody and payment layers before advising on a specific path.

Do I need a separate custody licence?

In most major regimes, custody of virtual assets is a regulated activity distinct from exchange or transfer services, and it requires its own authorisation or a licence with a custody permission attached. Under MiCA, custody and administration of crypto-assets on behalf of clients is a defined CASP service. VARA, the FSRA within ADGM, the MAS and the SFC each treat custody as a regulated activity subject to safeguarding, segregation and capital requirements. An operator that combines exchange and custody services within one entity typically requires a licence that covers both activities. Relying on a licence that covers only one to carry on both is a common and consequential mistake.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across more than seventy jurisdictions, on disputes and on-chain asset recovery across more than twenty-five forums, and on the tax, banking and compliance that sit around them. We map the licence stack across operating, custody and payment layers before you commit to a structure. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com.

By Aisha Tan, Licensing & Jurisdictions Analyst — specialising in cross-border VASP authorisation strategy and multi-hub licensing structures for digital-asset businesses.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours