Operating a crypto exchange (a platform facilitating the buying, selling or trading of virtual assets on behalf of users) without the correct regulatory authorisation is not simply a compliance gap — it is an enforcement risk that can close banking rails, attract civil and criminal liability, and freeze the business overnight. As major hubs tighten their VASP (virtual asset service provider) supervision in parallel with the maturation of regimes such as MiCA (the EU's Markets in Crypto-Assets Regulation) and VARA's activity-based rulebooks, the window for operating on legacy registrations or informal arrangements is narrowing sharply. This guide maps the full sequence: from entity formation to live regulatory authorisation, with the cross-border decisions that determine which path is available to your business.
Step 1: Understand Exactly What You Need a Licence For
A crypto exchange requires regulatory authorisation in every jurisdiction where it carries out regulated exchange activities — which means the location of your entity, the location of your users, and sometimes the location of your banking each impose independent obligations. Most flagship regimes define regulated activity by function: matching buy and sell orders, executing trades as principal, transferring digital assets, and providing custody of client funds are each separately regulated acts in advanced regimes such as those administered by MAS (the Monetary Authority of Singapore) under the Payment Services Act, the SFC in Hong Kong under the VASP licensing regime, and VARA in Dubai. A business that combines exchange and custody functions frequently requires authorisation under more than one activity category.
The cross-border reality bites immediately here. A Cayman-domiciled entity serving EU-resident users faces MiCA's CASP (Crypto-Asset Service Provider) authorisation requirements regardless of where the legal entity sits. An exchange structured through a BVI holding company but operating through a Singapore-registered subsidiary must satisfy MAS at the operating layer even if the holding structure sits offshore. The regulated perimeter follows the activity and the user, not only the registration address.
Common mistake at this step: businesses assume that a single VASP registration — often a lightly supervised offshore filing — covers all activity globally. It does not. Regulators in the EU, UK, Singapore, Hong Kong and Dubai each apply their own nexus tests. Serving residents of those jurisdictions from an unrecognised offshore entity exposes the business to direct enforcement in each of those markets.
The process above describes the standard licensing analysis. Your facts — the entity, the user base, the banking — change which regime applies first. For a scoped assessment of the regulatory perimeter your exchange will face, contact OBOLUS at info@oboluslaw.com or map your options here.
Step 2: Choose Your Primary Licensing Jurisdiction
Choosing the primary licensing jurisdiction is the most consequential structural decision the business will make, and it turns on four axes: the activity scope the regime covers, the capital and compliance overhead, the banking environment, and the passporting or market-access rights the licence carries. There is no single correct answer — the right jurisdiction is the one that matches your user base, your capitalisation stage and your operational model.
For a business targeting EU users, MiCA CASP authorisation in a member state — accessed through a regulator such as the Bank of Lithuania or the MFSA in Malta, both of which are transitioning their prior VASP frameworks into the MiCA model — delivers EU-wide passporting. A single authorisation in one member state allows the exchange to serve the entire EU/EEA market without a local licence in each country. That passporting right has significant commercial value and is the dominant reason EU-focused operators are accelerating their CASP applications.
For a business targeting the Gulf, VARA's activity-based licences in mainland Dubai and the FSRA within the ADGM in Abu Dhabi represent the two principal routes. These regimes operate independently; a VARA licence does not extend to the DIFC or ADGM financial free zones, and vice versa. Operators targeting both markets commonly hold parallel authorisations.
For Asia-Pacific exposure, MAS licensing under the Payment Services Act (standard payment institution or major payment institution track, depending on transaction volumes) or SFC's VATP (virtual-asset trading platform) authorisation in Hong Kong are the natural anchors. Each regime carries different capital expectations and compliance obligations; the choice depends partly on whether the exchange handles securities-classified tokens, which triggers additional SFC oversight in Hong Kong.
The AIFC in Kazakhstan, regulated by the AFSA (Astana Financial Services Authority), provides a common-law environment with a digital-asset trading facility concept well suited to operators seeking Central Asian market access or a CIS-facing licence with institutional-grade legal infrastructure.
Common mistake at this step: selecting jurisdiction on headline ease of registration rather than on substance-over-form analysis. Regulators in the EU and the Gulf now conduct nexus reviews; an entity with no genuine economic activity in the licensing jurisdiction faces authorisation refusal or post-grant revocation.
Step 3: Build the Legal Entity and Corporate Structure
The operating entity that holds the licence must satisfy the regulator's substance requirements — which, across every major regime, means local directors, a compliance officer, a local office and genuine decision-making in the jurisdiction. A shell with a registered address and a nominee director will not satisfy the substance tests applied by VARA, MAS, the SFC or MiCA competent authorities. Regulatory expectations have converged on the requirement that the licensed entity actually controls the regulated activity.
The broader group structure — holding companies in the BVI, Cayman Islands, or a low-tax EU jurisdiction; intellectual property entities; and treasury vehicles — sits around the operating entity but must be disclosed at application. Regulators examine beneficial ownership to the natural-person level. Undisclosed holding structures are a leading cause of application stalls and post-authorisation enforcement action.
A cross-border note: if the business intends to offer services in the United States, the federal layer (SEC, CFTC and FinCEN) and state money-transmitter licensing, including the NYDFS BitLicense for New York users, must each be assessed independently of any offshore licence. No offshore authorisation substitutes for US-specific registration where US nexus exists.
Common mistake at this step: building the holding structure without involving licensing counsel until the application stage. Restructuring an incorporated group to satisfy regulatory substance requirements after formation is significantly more costly and time-consuming than building the structure correctly from the outset.
Step 4: Design the AML, KYC and Travel Rule Programme
Every licensed crypto exchange must operate an AML/CFT programme that satisfies both the applicable national regime and the FATF Recommendations — specifically Recommendation 15, which applies the FATF standards to virtual asset service providers. This is not a paper compliance exercise: regulators conducting authorisation reviews expect to see a functioning programme, not a policy document drafted at the point of application.
The Travel Rule (the obligation, derived from FATF Recommendation 16, to pass originator and beneficiary identification data alongside virtual asset transfers above the applicable threshold) applies to licensed exchanges in the EU under MiCA, in Singapore under the MAS regime, in Hong Kong under the SFC regime, and in the UAE under VARA. The precise threshold below which the Travel Rule de-minimis applies varies by jurisdiction — treat this as a jurisdiction-specific compliance design question, not a universal standard.
The practical programme at the exchange layer must cover: customer due diligence (CDD) and enhanced due diligence (EDD) for higher-risk accounts; transaction monitoring calibrated to the asset classes traded; sanctions screening against current OFAC, UN and EU designation lists; and a suspicious activity reporting workflow to the relevant financial intelligence unit. Where the exchange serves institutional counterparties, the programme must extend to correspondent-VASP due diligence — the exchange must assess the AML programme of every VASP whose customers deposit or withdraw through the platform.
Common mistake at this step: treating AML as a condition to be satisfied at application and not as an ongoing obligation. Regulators in Singapore, Hong Kong, and the EU have issued enforcement actions against licensed entities for programme failures after authorisation. The application-stage review is the beginning of supervisory scrutiny, not the end.
Step 5: Prepare and Submit the Regulatory Application
The application package for a CASP authorisation under MiCA, a VATP licence under the SFC regime, or a VARA licence is a substantive legal and operational document — not a form. It typically comprises: a business plan with financial projections, a governance structure chart with role descriptions, the AML/CFT programme, IT security and business continuity policies, a custody and safeguarding framework, the qualifications and integrity assessments of key personnel, and the regulated entity's constitutional documents and proof of capitalisation. Regulators review the package in detail; incomplete or inconsistent applications are returned, restarting the clock.
Timeline is a function of the regime, the completeness of the application, and the regulator's current processing capacity. Write this as a planning assumption: timelines vary considerably across regimes and are not fixed. Some regulators publish target review periods; others do not. In our practice, the applications that move fastest are those submitted with a complete, internally consistent package — not the ones submitted early with the intention of supplementing later.
A micro-matter from our cross-border practice: a payments company expanding into the Gulf region engaged us to prepare a VARA licence application. The initial internal preparation had produced a governance framework that described a compliance function located outside the UAE. We restructured the compliance reporting lines, drafted a UAE-resident MLRO appointment, and revised the business plan accordingly. The application was submitted as a coherent package and the regulator did not raise a supplementary information request on governance. The business reached provisional authorisation within the timeframe the regulator had indicated at pre-application outreach.
Common mistake at this step: submitting a generic application adapted from a prior jurisdiction rather than one built for the specific regime's expectations. VARA, MAS and the SFC each have distinct application templates and reviewer priorities; a document drafted for one regulator will draw supplementary requests from another.
If a prior application stalled or a supplementary information request went unanswered, a second read of the file can surface the structural reason and the route forward. Write to OBOLUS at info@oboluslaw.com or discuss your situation here.
Step 6: Secure Banking and Payment Rails in Parallel
A crypto exchange licence without a functioning bank account is an authorisation without a business. Banking for digital-asset businesses remains the hardest operational challenge in the sector — not because the law prohibits it, but because correspondent banking risk-appetite remains conservative in most markets. Starting the banking process early, in parallel with the licence application and not after it, is not optional planning advice; it is a structural necessity.
The cross-border banking note is critical. Exchanges commonly require at least two banking relationships: one in the licensing jurisdiction for regulatory capital and client-money segregation, and one in a second jurisdiction for operational purposes. The two are not always available from the same institution. In our practice, operators who model their banking dependency against their licensing jurisdiction before submitting the application avoid the scenario where the licence is granted but the business cannot open.
Payment rails — including the PSP relationships that connect the exchange to fiat on- and off-ramp infrastructure — must themselves satisfy the AML programme requirements. A PSP relationship that introduces unscreened fiat flows is a compliance liability, not a commercial convenience.
Common mistake at this step: treating banking as a post-licence item. The application process for a regulated banking relationship for a crypto exchange is itself a multi-month process; sequential rather than parallel execution delays go-live by a quarter or more in almost every case we have seen.
Step 7: Build the Post-Authorisation Compliance Infrastructure
Regulatory authorisation is the start of an ongoing supervisory relationship, not the end of the compliance programme. Licensed exchanges under MiCA, the SFC regime, MAS and VARA each face periodic reporting obligations, audit requirements, change-of-control notification obligations, and the requirement to seek regulator approval before adding new regulated activities or making material changes to the business model. Failing to manage these post-authorisation obligations is the most common compliance failure among businesses that obtained their licence smoothly.
The minimum post-authorisation infrastructure for an exchange includes: a designated compliance function with a qualified MLRO or compliance officer, an internal audit programme, a regulatory change monitoring process (regimes are actively evolving, particularly under the MiCA transition and the VARA rulebook update cycles), a client-asset reconciliation and reporting process, and a board-level governance cadence that formally receives and acts on compliance reports.
Common mistake at this step: scaling down the compliance team after the licence is granted on the assumption that the hard work is done. Regulators in Singapore and Hong Kong, in particular, have demonstrated a willingness to impose conditions, suspend activities or revoke licences where post-authorisation supervisory standards are not maintained. The licence is a permission that requires continuous justification.
Related at OBOLUS
- Licensing and Registration for Digital Asset Businesses – the full scope of OBOLUS licensing practice across 70+ jurisdictions
- Licence Renewal and Variation for Established Operators – managing post-authorisation change, expansion and renewal
- Pre-Exit Tax Restructuring in Kazakhstan (AIFC) – structuring considerations for operators in or exiting the AIFC environment
FAQ
How long does a crypto licence take to obtain?
Timelines vary materially by regime and by the completeness of the application. Some regulators publish indicative review windows; others do not. In practice, the variables that most affect duration are the completeness of the initial submission, the volume of supplementary information requests, and the regulator's current processing capacity. Build a conservative planning assumption of several months at minimum, and begin banking and operational infrastructure in parallel with the application process.
Which jurisdiction is best for licensing my crypto business?
There is no single best jurisdiction. The right answer turns on your user base, activity scope, capitalisation and market-access goals. EU-focused businesses generally evaluate MiCA CASP authorisation for passporting rights. Gulf-facing operators consider VARA or ADGM/FSRA. Asia-Pacific operators weigh MAS and SFC licensing. Each regime carries distinct capital, compliance and governance expectations. A licensing analysis should map the full stack — entity, activity, user geography and banking — before selecting the primary jurisdiction.
Do I need a separate custody licence?
In most flagship regimes, custody of client virtual assets is a separately regulated activity. Under MiCA, providing crypto-asset custody and administration is an enumerated CASP service requiring explicit authorisation. MAS, the SFC and VARA each treat custody as a discrete regulated function. An exchange that holds client assets — rather than requiring clients to self-custody — typically requires authorisation covering both exchange and custody activities. Confirm the applicable scope with counsel before building the custody model into your architecture.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance architecture that sits around them. Digital assets are the whole of our practice. We map the licence, custody and payment-rail stack before you commit to a structure — and we coordinate with allied counsel in the relevant jurisdiction where local presence is required. To discuss your exchange build, contact info@oboluslaw.com or message us at t.me/oboluslaw.
By Aisha Tan, Licensing & Jurisdictions Analyst — specialising in multi-jurisdiction VASP authorisation strategy and application management for crypto exchanges and custodians.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.