EST · MMXXVI
Home/Insights/Guides/How to Apply for a VASP Licence: A Step-by-step Guide
Licensing & Registration

How to Apply for a VASP Licence: A Step-by-step Guide

How to Apply for a VASP Licence: A Step-by-step Guide. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOL

A virtual asset service provider (VASP) licence is the regulatory authorisation that permits a business to operate a crypto exchange, provide custody, broker digital assets, or offer related payment services under supervised conditions. Obtaining the right VASP registration in the right forum is not merely a compliance exercise — it determines which banks will open accounts, which institutional counterparties will trade, and whether enforcement action is a question of when rather than if. This guide walks through every material step of the crypto licence application process, names the common mistake at each stage, and addresses the cross-border reality that most operators face: the entity may sit in one jurisdiction while users, banking and custody live in others.

Why the Licence Choice Determines Everything Downstream

The jurisdiction you select for regulatory authorisation sets the ceiling and the floor for your entire operating model. A CASP authorisation under MiCA (the EU Markets in Crypto-Assets Regulation), administered by ESMA and the relevant national competent authority, carries a passport across the EU/EEA — meaning a single authorisation can serve the entire single market. A licence under VARA in Dubai, or under the MAS Payment Services Act in Singapore, carries no such passport. Each regime has a different capital expectation, a different AML posture, and a different relationship with correspondent banks.

Operators we advise routinely underestimate how early that choice locks in downstream decisions. Banking, tax domicile, the corporate holding layer, and the contractual relationship with users all flow from the licence jurisdiction. Choosing the wrong forum because it appeared faster or cheaper is among the most expensive mistakes we see — remediation requires a second application, a restructuring, and sometimes the loss of an existing banking relationship.

The cross-border reality is acute here. A business with EU-resident users, a BVI holding company, and a Singapore-licensed operating entity faces three distinct regulatory perimeters simultaneously. Getting the mapping right before the first filing is material.

Step 1: Determine Which Activities Require Authorisation

Start by identifying precisely which regulated activities your business will perform, because licensing requirements attach to activities, not to labels. A business that holds client assets performs custody — a regulated activity in virtually every flagship regime, from MiCA's CASP authorisation to VARA's custody activity licence to the MAS DPT (Digital Payment Token) service framework under the Singapore Payment Services Act.

The substance-over-label principle is critical here. Calling a product a "wallet" or a "protocol" does not determine whether custody regulation applies. What matters is whether the business controls private keys, whether it can effect transfers without separate client instruction, and whether it holds client funds in the course of a service. Regulators — including the FCA under the UK Money Laundering Regulations, the FSRA in ADGM, and AFSA in the AIFC — assess economic function, not marketing terminology.

The common mistake at this step is mapping only the primary activity. A business that plans to operate an exchange but also plans to hold client assets between trades is both an exchange and a custodian. Both activities need authorisation. Missing the custody layer is one of the most frequent grounds for an incomplete filing.

Cross-border note: where users are located matters as much as where the entity is incorporated. Serving EEA residents without a MiCA CASP authorisation — or a grandfathered national licence during the transition period — exposes the business to enforcement by the relevant national competent authority, regardless of where the entity sits.

Step 2: Build the Corporate Structure Before You File

A well-designed corporate structure is a precondition of a successful application, not something to retrofit after the licence is granted. Most regulators — including VARA in Dubai, the SFC in Hong Kong, and CIMA in the Cayman Islands under the VASP Act — require the applicant entity to be locally incorporated or registered before the application can be accepted.

The structure question has three layers. First, where is the regulated operating entity? This is the entity that holds the licence, employs or contracts the compliance function, and enters into agreements with clients. Second, where is the holding company? A BVI or Cayman holding layer is common and generally uncontroversial, but the regulated entity must have genuine substance in the licence jurisdiction — real directors, real decision-making, a real office. Third, where does the IP, treasury, or token issuance vehicle sit? That question has its own tax and regulatory implications, and answers in one layer create obligations in another.

In our practice, we structure the entity stack before any regulatory conversation begins. Regulators form impressions quickly; a structure that looks like a letterbox arrangement — a local entity with no real management — is a red flag in every leading hub.

Cross-border note: some jurisdictions impose local director requirements. VARA in Dubai expects senior management physically present or operationally based in the UAE. Singapore's MAS has heightened scrutiny of substance. The BVI FSC and CIMA are less prescriptive on physical presence but still require that controllers pass fit-and-proper assessment.

Step 3: Assess Fit-and-Proper Requirements for All Key Persons

Fit-and-proper vetting of ultimate beneficial owners, directors, senior managers, and compliance officers is a universal gating condition across every major licensing regime, and it is the step most likely to generate surprise delays. Under MiCA, VARA, the MAS framework, the SFC's VASP regime in Hong Kong, and the FCA's registration process in the UK, every person in a control or senior management role must satisfy the regulator that they have appropriate experience, a clean regulatory record, and the financial standing to perform their role.

What constitutes a disclosure event varies. A prior regulatory sanction in any jurisdiction, a spent criminal conviction, undisclosed litigation, or a directorship in a failed regulated business can each require a formal explanation. Regulators share information — the FCA communicates with ESMA and national competent authorities; VARA coordinates with Interpol and FATF member bodies. A disclosure that surprises a regulator mid-process is materially worse than a disclosure made proactively with context.

The common mistake at this step is treating fit-and-proper as a form to fill rather than a due-diligence process to manage. We advise clients to conduct a full internal review of all key persons before a single regulatory form is submitted — surfacing issues early, framing context, and deciding whether a particular person should be disclosed as a controller at all.

For a scoped assessment of your entity structure and fit-and-proper position before you file, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts — the entity, the UBO profile, the prior regulatory history — change the analysis materially. Map your options.

Step 4: Prepare the AML/CFT and Travel Rule Programme

A documented, tested, and operationally live AML/CFT programme is a substantive filing requirement — not a post-authorisation task — in every FATF-aligned jurisdiction, and its quality is one of the primary differentiators between applications that proceed and those that stall. Under FATF Recommendation 15 (which applies specifically to virtual asset service providers), a VASP must implement risk-based controls covering customer due diligence, transaction monitoring, suspicious transaction reporting, and sanctions screening.

The Travel Rule — the obligation to pass originator and beneficiary identifying data alongside a virtual asset transfer — adds a technical layer that sits on top of the AML programme. Every major regime has adopted some form of Travel Rule implementation: MiCA, MAS, the FCA's MLR regime, VARA, the SFC in Hong Kong. The practical challenge is not the rule itself but the data standard: complying with the Travel Rule requires a technical solution for inter-VASP messaging, and regulators increasingly expect to see that solution in place, or at minimum contractually committed, at the time of application.

The common mistake here is submitting a policy document rather than an operational framework. A regulator reviewing a MiCA CASP application or a VARA filing wants to see the procedures, the appointed MLRO (money laundering reporting officer), the risk-scoring methodology, the customer onboarding workflow, and the sanctions-list feed. A policy that describes a programme not yet built is a deferral, not an approval.

Cross-border note: where a business operates in multiple jurisdictions, the AML programme must satisfy the most demanding applicable standard across all of them simultaneously. A business with EU users must comply with MiCA's AML expectations even if its licensed operating entity sits elsewhere.

Step 5: Compile and Submit the Application Package

Application packages across the major licensing regimes share a common architecture, though the format, portal, and supporting document requirements differ. The core components are: the regulatory application form; the corporate structure chart with beneficial ownership disclosure; audited or management accounts; a business plan with financial projections; the AML/CFT programme documentation; the IT and cybersecurity assessment; key-person declarations; and evidence of minimum capital or professional indemnity cover.

Under the MiCA CASP authorisation process, the national competent authority in the chosen EU member state receives the application and has a defined review period under the regulation. Under VARA in Dubai, the application follows a staged review process involving activity-specific assessments. Under the MAS DPT service framework in Singapore, the Monetary Authority of Singapore reviews applications against criteria including AML controls, capital adequacy, and technology risk management. None of these processes are purely administrative: each involves substantive dialogue with the regulator, and the quality of the initial submission determines whether that dialogue is brief and constructive or prolonged and adversarial.

In our cross-border practice, we prepare application packages that anticipate the questions a regulator will ask rather than simply answer the form as written. The difference in outcomes is significant.

The common mistake at this step is treating the application as a one-time submission. Every major regulator — including ESMA-aligned NCAs, VARA, and MAS — will issue a request for information (RFI) or additional information notice (AIN) during the review process. Having a response protocol in place, and counsel who can draft timely, accurate responses, materially affects timeline and outcome.

Step 6: Manage the Review Process and Post-Authorisation Obligations

Regulatory review timelines vary by jurisdiction and by the completeness of the initial submission. Generally, reviews in established hubs run from a matter of weeks for more streamlined registrations to several months for full CASP authorisations or complex exchange licences. The timeline stated in legislation or guidance is typically the regulator's target — not a guarantee — and clock-stops (periods during which the regulator is awaiting information from the applicant) do not count against it.

Managing the review means more than waiting. During the review period, the corporate structure should not change materially without disclosure. Key persons should not change roles. Any event that would require a fit-and-proper update — a new litigation, a new UBO, a change in share structure — must be reported promptly in most regimes. Failing to report a material change during a pending application is treated, in some hubs, as a basis to reject the application or to impose conditions on any authorisation granted.

Post-authorisation obligations begin immediately on grant. These typically include: maintaining minimum capital on an ongoing basis; filing periodic compliance reports; notifying the regulator of material operational changes; and maintaining the AML programme and Travel Rule solution in live operation. A licence granted is not a licence secured until the ongoing compliance posture is built and functioning.

If a prior application stalled or an account was closed, a second review can surface the structural reason and the route back. Write to OBOLUS at info@oboluslaw.com or reach us via t.me/oboluslaw. Map your options.

The Cross-Border Reality: One Licence Is Rarely Enough

A common assumption among early-stage operators is that a single offshore registration provides cover for a global user base. It does not. Licensing requirements are jurisdictional: what matters is where the service is provided, where the users are located, and — in some regimes — where the servers sit or where marketing is directed.

A business holding a BVI VASP Act registration and serving EU retail users without a MiCA CASP authorisation is operating without regulatory authorisation in the EU. A Singapore-licensed DPT service provider that markets to Hong Kong residents without an SFC VASP licence may be subject to Hong Kong enforcement. A UK-facing exchange without FCA MLR registration is exposed to the FCA's enforcement regime regardless of its offshore structure.

The practical result is that most serious digital-asset businesses need a licence stack — a primary regulated operating licence, potentially one or more secondary registrations for specific markets, and a clear policy on which jurisdictions are explicitly excluded from the business's service perimeter. That perimeter needs to be real: geofencing, KYC-based residency checks, and contractual exclusions must be consistently enforced, or the exclusion is not credible in a regulatory investigation.

In a recent licensing matter, a payments company had operated for two years under a single EU member-state registration, assuming it covered all EEA activity. When MiCA's CASP regime came into full effect, the transition mapping revealed that the existing registration did not automatically convert to a CASP authorisation and that additional substantive requirements applied. We assisted with the transition filing and the documentation of the enhanced AML programme required under the new regime. The filing proceeded without gap in regulatory cover.

A Note on Banking: The Licence Without Accounts Is Not a Business

Obtaining a VASP licence is a necessary condition for operating a regulated digital-asset business. It is not a sufficient condition. Without a bank account that accepts crypto-related business flows — client fiat settlements, operational accounts, payroll — the licence has limited practical value.

Banking access for crypto businesses remains constrained in most jurisdictions. Licensed businesses in MiCA-regulated EU jurisdictions, in the VARA ecosystem in Dubai, and in the MAS regime in Singapore generally have better banking access than unlicensed or offshore entities, but the relationship is not automatic. Banks conduct their own due diligence on VASP clients, and the quality of the AML programme, the UBO profile, and the business model determine whether an account is opened.

We map the banking and payments layer in parallel with the licence application — because a client that completes a six-month authorisation process and then discovers that no bank in the jurisdiction will open an account has not advanced its operating position.

Related at OBOLUS

FAQ

How long does a crypto licence take to obtain?

Timeline varies significantly by jurisdiction and application quality. Streamlined registrations — such as BVI VASP Act registration or certain AML-only filings — can complete in a matter of weeks. Full CASP authorisations under MiCA, VARA activity licences in Dubai, and MAS DPT licences in Singapore typically take several months, and that timeline extends when the initial submission is incomplete or triggers a request for additional information. Clock-stops during information requests do not count against the regulator's review period.

Which jurisdiction is best for licensing my crypto business?

There is no single answer applicable to every operator. The optimal jurisdiction depends on the business model (exchange, custodian, broker, lender), the user base and its geographic distribution, the banking relationships available, the tax structure, and the operator's appetite for ongoing regulatory engagement. MiCA passporting makes an EU member-state CASP authorisation attractive for businesses serving European markets. VARA and ADGM are well-regarded for Middle East operations. Singapore's MAS regime suits APAC-focused businesses. The right answer is a mapped analysis, not a ranking.

Do I need a separate custody licence?

In most leading regimes, custody of client digital assets is a regulated activity that requires its own authorisation or an express permission within a broader licence. Under MiCA, providing crypto-asset custody and administration is a named CASP service. VARA treats custody as a distinct activity. The MAS DPT framework addresses custody within its service scope. Operating custody as an incidental function of an exchange without specific authorisation for it is a common compliance gap — and one that regulators have begun to scrutinise more actively as institutional asset volumes grow.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. We map the licence stack across operating, custody and payment layers before you commit — so that the authorisation you obtain is the one your business actually needs. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com.

By Aisha Tan, Licensing & Jurisdictions Analyst — specialist in VASP authorisation strategy and multi-jurisdictional licence mapping for exchanges, custodians and token issuers.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours