Losing a crypto licence rarely happens overnight. The more common pattern is slow-moving: a missed regulatory filing here, an outdated AML policy there, a new product line that quietly triggered a fresh authorisation requirement in a second jurisdiction. By the time the enforcement notice arrives, the business has already lost banking access, and the path back is measured in months. Knowing how to maintain a crypto licence in good standing is therefore one of the most commercially important questions for any operator.
A crypto licence (the regulatory authorisation – whether a VASP registration (virtual asset service provider registration), a CASP authorisation under MiCA, a VASP licence under VARA in Dubai, or a Digital Payment Token licence under the MAS Payment Services Act – is not a static document. It is a living obligation. The conditions attached to it multiply as your business scales. This guide walks through the key compliance disciplines that keep an authorisation intact, with the cross-border realities operators actually face.
Step 1: Understand What "Good Standing" Actually Means Under Your Regime
Good standing is not the absence of enforcement; it is demonstrable, continuous compliance with every condition embedded in the original authorisation. Under most flagship regimes – MiCA administered by ESMA and national competent authorities, VARA in Dubai, the FSRA within ADGM in Abu Dhabi, the FCA's cryptoasset registration in the United Kingdom, MAS supervision in Singapore, and the SFC's VATP regime in Hong Kong – "good standing" encompasses capital maintenance, AML/CFT programme currency, ongoing fit-and-proper status of controllers, approved-person notifications, accurate financial reporting, and adherence to any activity-specific conduct rules.
The cross-border reality sharpens immediately. An operator licensed in Lithuania to offer exchange services under the Bank of Lithuania's supervision, but whose users are predominantly in Germany and France, will find that MiCA passporting obligations impose an additional layer of notification requirements toward the German BaFin and the AMF in France. One regime's good standing does not automatically satisfy another's reporting clock.
Common mistake at this step: treating the licence as a checkbox cleared at application, rather than as a compliance programme running in parallel with operations. The businesses that lose authorisations are rarely those that were dishonest at application. They are those that grew faster than their compliance infrastructure.
Step 2: Maintain Minimum Own-Funds and Capital Thresholds at All Times
Capital adequacy is a continuous obligation, not a one-time test at licensing. Every major regime – including MiCA for CASPs, VARA for its activity-based licensees, the FSRA within ADGM, and MAS for major payment institutions – sets ongoing own-funds requirements that a licensee must meet on a rolling basis, not merely at the point of authorisation.
The practical implication: a company that used venture capital to satisfy the initial capital test but then deployed that capital into product development may quietly breach the minimum threshold within its first operating year. Regulators conducting supervisory reviews – which VARA, MAS and the FCA all conduct with increasing frequency – will assess current, not historical, capital positions.
Cross-border note: capital requirements differ by activity category and by jurisdiction. A business holding a custody licence in one jurisdiction and an exchange licence in another must satisfy the capital regime of each independently. Capital held in the entity in Dubai does not count toward the capital requirement of a separately authorised European subsidiary.
Common mistake: treating group-level treasury as a proxy for entity-level capital. Regulators look at the legal entity that holds the licence. Group consolidation does not cure an entity-level deficiency.
For a scoped assessment of your capital structure across your licensed entities, contact OBOLUS at info@oboluslaw.com. The licensing picture above describes the standard structure. Your specific entity architecture, banking arrangements and user base change the analysis. Map your options.
Step 3: Keep Your AML/CFT Programme Current and Tested
An AML/CFT programme that was adequate at authorisation will not remain adequate as your product suite, customer base and transaction volumes evolve – regulators in every major hub have made this explicit. The FATF Recommendations, including Recommendation 15 on virtual assets, require risk-based AML/CFT frameworks that reflect the actual risk profile of the business as it operates today.
The practical pillars of a live AML/CFT programme include: an up-to-date business risk assessment; calibrated customer due diligence and enhanced due diligence triggers; transaction monitoring rules tuned to current products; a designated Money Laundering Reporting Officer (MLRO) who is genuinely available and qualified; staff training refreshed at intervals appropriate to the pace of change in your product; and an annual independent audit of the programme's effectiveness.
The Travel Rule (the obligation to pass originator and beneficiary data with a virtual asset transfer) adds a layer that many operators underestimate at scale. FATF-aligned jurisdictions – including the EU under MiCA, Singapore under MAS, the UAE under VARA, and the United Kingdom under the FCA's amended MLRs – all impose Travel Rule obligations. Failure to maintain compliant data-passing infrastructure is not a minor procedural issue; it has become a leading ground for supervisory action.
Cross-border note: the de-minimis threshold above which the Travel Rule is triggered varies by jurisdiction. A business with a global user base must map the most restrictive threshold across all jurisdictions where it operates and apply that as its operational standard, or maintain jurisdiction-specific controls – both approaches require active management.
Common mistake: treating the Travel Rule as a technology problem delegated to the compliance team and a VASP messaging vendor. The legal obligation sits with the licensed entity. If your counterpart VASP does not meet the data standard, you bear the risk of the transmission.
In our practice, we have seen operators spend considerable resource on their customer onboarding controls while allowing their transaction monitoring to drift – rule sets not updated after a new product launch, alert thresholds not recalibrated after a volume increase. Regulators reviewing supervisory returns will identify that mismatch.
Step 4: Notify the Regulator of Material Changes – and Know What "Material" Means
Every major crypto licensing regime imposes a duty to notify the regulator of material changes before they occur, or within a defined window after they occur, depending on the category of change. Under MiCA, VARA, FSRA within ADGM and MAS, the categories requiring pre-approval or prompt notification typically include: changes to directors, controllers or approved persons; changes to the ownership structure; new or materially different services or products; outsourcing of key functions; and changes to the safeguarding or custody arrangements for client assets.
The risk of non-notification is material. A regulator that discovers a change through a supervisory review rather than a voluntary notification will treat the omission as an aggravating factor in any subsequent enforcement. In our cross-border practice, we regularly advise operators who assumed a change was administrative – a new shareholder at below a nominal threshold, for example – and then discovered the applicable regime had a lower trigger than expected.
Cross-border note: notification thresholds differ significantly across jurisdictions. A shareholding change that is below the notification trigger in one EU member state may require pre-approval under the VARA rulebook in Dubai or the SFC's fit-and-proper assessment in Hong Kong. An operator running a multi-jurisdiction structure cannot apply the most permissive regime's threshold to all entities.
Common mistake: applying domestic logic to a foreign-licensed entity. Each licensed entity operates under the rules of its home regulator. The group legal or compliance team needs a jurisdiction-specific change-management protocol, not a single universal threshold.
Step 5: Manage Annual and Periodic Reporting Obligations Without Missing Deadlines
Regulatory reporting obligations run on their own calendars, independent of the company's financial year, board cycle or product roadmap. A licensed operator will typically face: annual audited financial statements submitted to the regulator; periodic supervisory returns covering transaction volumes, AML statistics and capital positions; renewal of any time-limited registrations (where the regime uses registration cycles rather than indefinite authorisation); and, under some regimes, scheduled on-site inspections or themed reviews.
The interaction between multiple regulatory calendars is the cross-border challenge. An operator licensed under MFSA in Malta, registered with the FCA in the UK, and authorised by MAS in Singapore will face three separate reporting cycles, three different forms, and three different supervisory communication protocols. A missed deadline in Singapore does not pause the Malta calendar.
A practical approach we recommend: a consolidated regulatory calendar maintained by in-house compliance and reviewed quarterly with external counsel, mapping every deadline, every periodic obligation, and every product-triggered notification across all licensed entities.
Common mistake: relying on the regulator to send a reminder. Supervisory bodies in the leading hubs – VARA, MAS, the FCA – increasingly regard missed deadlines as conduct indicators. The regulator's job is not to remind you. The obligation is yours.
If a prior reporting failure has created a gap you need to address, OBOLUS can assist with a remediation analysis. Write to info@oboluslaw.com or message us via t.me/oboluslaw. If an application stalled or an account was closed following a compliance gap, a structured review can identify the underlying cause and the realistic route back. Map your options.
Step 6: Manage Cross-Border Reach – Know When a Second Licence Is Required
A single licence authorises activity in its home jurisdiction only. Operating cross-border on a single authorisation is among the most common licensing errors we encounter – and one of the most expensive to correct after the fact. The question of when a second, third or fourth licence is required turns on: where users are located; where the platform is marketed; where order matching or custody occurs; and where the operator is deemed to be "carrying on business" under local law.
Under MiCA, a CASP passported from one EU member state may serve clients across the EU/EEA following the relevant notification procedure – but that passport does not reach outside the EU. A European-licensed operator with significant user activity in the UAE, Singapore or Hong Kong may be conducting regulated activity in those jurisdictions without a local authorisation.
The micro-matter: in a recent licensing review matter, an exchange operator held a CASP authorisation from an EU national competent authority and a registration with the FCA in the UK. As part of a growth phase, the business began marketing services into the MENA region. A jurisdictional analysis identified that the nature of the activity, combined with the marketing approach and the location of the order-matching infrastructure, brought the business within VARA's regulatory perimeter for certain service categories. The operator paused the MENA expansion while applying to VARA, avoiding the more serious consequence of operating without authorisation in a jurisdiction that enforces its perimeter actively.
Common mistake: assuming that serving customers remotely – without a physical office in the jurisdiction – places the activity outside that jurisdiction's regulatory reach. Most modern crypto licensing regimes apply on the basis of where the customer is and where the service is directed, not only where the operator is incorporated.
Step 7: Keep Banking and Payment Access Aligned With Your Licence Conditions
Regulatory authorisation and banking access are separate but operationally interdependent. A licence without compliant banking infrastructure cannot support a working business. Equally, banking providers conduct their own ongoing due diligence on regulated crypto clients – a deterioration in your regulatory standing will typically prompt a banking review before it prompts a formal enforcement action.
The mechanisms are linked in both directions. Regulators in the leading hubs – particularly VARA, the FSRA within ADGM, and MAS – may require operators to maintain client money in specific segregated accounts, with named banking partners who have been disclosed to the regulator. If a banking relationship ends, the failure to notify the regulator or to replace the arrangement within the required period can itself constitute a breach of licence conditions.
Cross-border note: crypto-friendly banking remains regionally concentrated. An operator licensed in a jurisdiction with strong regulatory standing but limited local banking infrastructure may need to bank across jurisdictions. That arrangement requires its own analysis – the location of the bank, the regulatory treatment of the client account, and the potential need for a payment institution licence in the banking jurisdiction.
Common mistake: treating banking as purely a commercial relationship. It is also a regulatory condition. Changes to banking must be managed in the same compliance workflow as changes to corporate structure.
Step 8: Respond to Supervisory Enquiries Promptly and With Legal Support
A supervisory enquiry – whether a routine information request, a themed review, or a formal supervisory investigation – is the moment at which good standing is most visibly tested. The quality of the response determines, in large part, whether the matter is closed at the supervisory level or escalates to enforcement.
The governing principle is cooperation. Every major licensing regime – MiCA/ESMA, VARA, MAS, the FCA, the SFC in Hong Kong – treats cooperative, accurate and timely disclosure as a mitigating factor in enforcement. Delay, incomplete responses or legal obstruction are treated as aggravating factors. This does not mean producing every document without review. It means engaging legal counsel immediately, triaging what has been requested against what your actual legal obligations are, and responding on the timetable the regulator has set.
We advise operators to have a supervisory-response protocol in place before the enquiry arrives. That protocol should designate a senior point of contact, establish a legal privilege review process, identify which documents are potentially material, and set a response-drafting workflow that does not rely entirely on the compliance team.
Cross-border note: a supervisory enquiry from one regulator may be coordinated with or followed by enquiries from other regulators in jurisdictions where you operate. ESMA, VARA, MAS and the FCA have information-sharing arrangements. Assume a regulatory dialogue in one jurisdiction may have visibility in another.
Common mistake: responding to a regulator without legal counsel on the grounds that the enquiry appears routine. The characterisation of an enquiry as routine is the regulator's, not the operator's.
Related at OBOLUS
- Licensing & Registration for Digital-Asset Businesses – full-scope licensing counsel across 70+ jurisdictions
- VARA Licence Application: What Recent Enforcement Tells Operators – enforcement-informed analysis of VARA applications and conditions
- PSP and Acquiring Agreement in Abu Dhabi Global Market (ADGM) – payment services structuring within the FSRA/ADGM regime
FAQ
How long does a crypto licence take to obtain?
Timelines vary materially by jurisdiction and by the category of authorisation sought. Lighter registration frameworks – such as some offshore VASP registrations – can move in a matter of weeks once documentation is complete. Full authorisation under MiCA, VARA's activity-based licensing, or MAS under the Payment Services Act typically takes longer, running to several months. In our practice, applications with well-prepared documentation and pre-application engagement with the regulator consistently move faster than those submitted cold.
Which jurisdiction is best for licensing my crypto business?
There is no single answer that applies across operator profiles. The right jurisdiction depends on your service type, your target user base, your banking access requirements, your tax structure, and your long-term market strategy. A custody-only business has different considerations from an exchange with retail users. Operators serving EU clients need to account for MiCA's passporting regime. A single offshore licence is not sufficient to serve clients globally – the regulator where your clients are located sets the applicable requirement.
Do I need a separate custody licence?
In most leading regimes, custody of client virtual assets is a separately regulated activity, or a distinct licence category within a broader framework. Under MiCA, VARA, MAS and the SFC's VATP regime in Hong Kong, holding or controlling client assets triggers specific authorisation and safeguarding conditions that are not satisfied by a general exchange or trading licence. An operator that holds client assets as part of an exchange service should obtain a specific legal opinion on whether the custody activity is covered or requires a separate authorisation.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. We map the licence, banking and payment stack across the operating, custody and payment layers before you commit – so the structure you build can scale without triggering enforcement gaps. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com.
By Aisha Tan, Licensing & Jurisdictions Analyst – specialist in multi-jurisdiction digital-asset authorisation, CASP and VASP licensing strategy, and ongoing compliance programme structuring across the leading crypto hubs.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.