EST · MMXXVI
Home/Insights/Regulatory/Passporting a Crypto Licence: Myth and Reality
Compliance, AML & Travel Rule

Passporting a Crypto Licence: Myth and Reality

Passporting a Crypto Licence: Myth and Reality. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

Crypto operators expanding across borders frequently assume that a licence obtained in one jurisdiction automatically permits them to serve clients in others. That assumption is wrong – and acting on it can expose the business to enforcement, frozen payment rails and sudden loss of banking. Under the MiCA (Markets in Crypto-Assets Regulation) regime, a CASP (Crypto-Asset Service Provider) authorised in one EU member state may passport that authorisation across the EEA – but only for the specific activities covered, only after the correct notification procedure, and only where the host-state competent authority has not exercised its power to impose additional conditions. Outside the EU, no comparable automatic mechanism exists. This analysis maps what passporting actually delivers, where it stops, and what a multi-market digital-asset business must put in place when a single licence genuinely does not reach.

What Does Passporting Actually Mean for a Crypto Business?

Passporting is the right to provide regulated services in a second jurisdiction on the strength of a home-state authorisation, without obtaining a separate licence in each host state. Within the EU under MiCA, this is a real and enforceable mechanism: a CASP authorised by a national competent authority in, say, an EU member state may notify ESMA and the relevant host-state regulator of its intention to passport, after which it may serve clients in that host state subject to the passported activity scope and the applicable CASP conduct obligations.

Two limits constrain that right immediately. First, the passport travels with the activity. A firm authorised for custody services cannot use that authorisation to operate an exchange in a host state. Second, conduct-of-business rules in the host state still apply. A firm passporting into a jurisdiction with stricter marketing or disclosure requirements must comply with those requirements even though it holds no local licence. The passport is a market-access right, not a compliance exemption.

In our practice, we regularly advise operators who have over-read the MiCA passport. They have treated the notification as a formality and launched services before the host-state regulator acknowledged the notification. That sequencing error has triggered correspondence that delayed product launches by weeks and, in one instance, required a temporary withdrawal from the market.

Where Does Passporting Simply Not Exist?

Outside the EU/EEA single market, there is no automatic passporting mechanism for digital-asset businesses. Each of the major licensing hubs operates its own standalone regime, and a licence from one does not extend reach into another.

Under the VARA (Virtual Assets Regulatory Authority) regime in Dubai, a licence covers activities conducted from or within the emirate – not globally. A firm licensed by VARA that solicits clients in Singapore must separately satisfy MAS (Monetary Authority of Singapore) requirements under the Payment Services Act. Similarly, a firm registered with the FCA (Financial Conduct Authority) under the UK Money Laundering Regulations holds an anti-money-laundering registration, not a passport into the EU or any Gulf jurisdiction. The ADGM/FSRA regime in Abu Dhabi and the AIFC/AFSA regime in Astana each impose their own authorisation requirements irrespective of what a firm holds elsewhere.

The practical consequence is a licence stack. A business operating an exchange, a custody service and a payment leg across three jurisdictions may require three to six regulatory approvals, each with its own capital, governance and AML/CFT (anti-money-laundering and counter-financing-of-terrorism) requirements. Operators we advise routinely underestimate this stack at inception and discover the gap only when a banking counterpart or institutional client requests evidence of local authorisation.

For a scoped assessment of your cross-border licence requirements, contact OBOLUS at info@oboluslaw.com. The process above describes the standard exposure. Your facts – entity domicile, user geography, payment structure – change the analysis materially. Map your options.

How Does the EU CASP Passport Work in Practice?

The MiCA passport follows a notification model: the home-state competent authority transmits a file to ESMA and to each host-state authority, and the firm may generally begin providing services in the host state after a defined period unless the host-state authority raises objections within the applicable window. The home-state authorisation covers only the crypto-asset services listed in the CASP licence – advisory, custody, exchange, portfolio management and other specific CASP activities each require explicit inclusion in the original authorisation before they can travel.

Operators considering a Lithuania-based CASP as an EU entry point should note the transition dynamic. Lithuania historically offered a fast VASP registration. Under MiCA, the Bank of Lithuania supervises CASP authorisations, and the full MiCA conduct-of-business regime applies to any firm that then passports. The administrative speed advantage at the authorisation stage does not reduce the compliance obligations that attach once the passport is exercised.

Malta presents a structurally similar picture. The MFSA administers the transition from the prior VFA (Virtual Financial Assets) framework to MiCA CASP authorisation. Firms that held a VFA licence have needed to reassess their activity scope and documentation to confirm that the MiCA CASP authorisation covers every service they intend to passport.

In our cross-border practice, we have seen firms build a MiCA passport strategy around a single member-state authorisation, only to find that the activity scope approved by the home-state regulator was narrower than the firm's commercial model required. Correcting the scope after authorisation – through a licence variation – adds time and regulatory dialogue that a well-structured application would have avoided.

Does AML Compliance and the Travel Rule Travel with the Licence?

AML obligations do not passport. Each jurisdiction in which a firm operates – whether under a local licence, a passport or a cross-border exemption – applies its own AML/CFT requirements independently, and a VASP that fails to implement a jurisdiction-specific AML program risks enforcement in that market regardless of what its home regulator has approved.

The Travel Rule (the obligation, derived from FATF Recommendation 15, to pass originator and beneficiary identification data with virtual-asset transfers above the applicable threshold) applies in every major licensing hub, but the specific threshold, technical standard and counterparty-screening obligation vary by jurisdiction. A firm operating under the EU's MiCA-aligned Travel Rule obligations and simultaneously serving clients through a Singapore DPT (Digital Payment Token) licence must satisfy MAS Travel Rule requirements separately. The same applies to a firm with a Dubai VARA exchange licence where clients transfer assets to wallets outside the VARA-supervised environment.

The Travel Rule's counterparty-VASP screening obligation is particularly acute in a multi-market stack: a firm must assess whether the receiving VASP is registered in a jurisdiction with a compliant Travel Rule regime, and it must manage the data-transfer mechanics for each corridor it operates. We have seen this screening obligation catch operators off-guard when they expand a service to a new corridor without first updating their transaction monitoring and VASP-due-diligence procedures.

A robust KYC framework (know-your-customer framework) and transaction monitoring program must, in our view, be built to the most demanding applicable standard in the stack – not the most permissive. A firm whose home-state regime allows simplified due diligence for certain categories of users cannot apply that simplification to users located in a jurisdiction that mandates enhanced due diligence across equivalent categories.

The Myth of the Single Offshore Licence

A persistent assumption in the digital-asset industry is that a single offshore registration – typically in a jurisdiction with lighter initial requirements – confers the right to serve clients worldwide. That assumption has no legal basis and, in practice, it regularly produces the outcome it was intended to avoid: regulatory action, account termination and loss of the registration itself.

A common assumption among early-stage operators is that registering in a low-friction jurisdiction and describing the business as "serving non-local clients" satisfies the regulatory requirements of the jurisdictions where those clients actually are. Regulators in the EU, UK, Singapore and Hong Kong apply a substance-and-nexus analysis. If a firm solicits clients in those jurisdictions, offers them services in their language and currency, or processes their transactions through local banking, the firm is typically within the regulatory perimeter of those jurisdictions – irrespective of where it is incorporated or registered.

The BVI FSC's VASP Act 2022 and the Cayman CIMA VASP Act both require registration for virtual-asset service activity regardless of where clients are located, but registration in either jurisdiction does not create any access right in another. An exchange registered under the BVI VASP Act that actively onboards EU residents without a MiCA CASP authorisation is operating in breach of MiCA's market-access provisions.

Enforcement in this area is no longer theoretical. Regulators in the major hubs have moved against firms that operated without local authorisation or that treated offshore registrations as a global licence. The consequences – enforcement orders, fines, account freezes and reputational damage – are materially more costly than the licence stack would have been.

If a prior application stalled or a banking relationship was closed following a regulatory question about your licence scope, a second structural read can identify the gap and the route to resolution. Contact OBOLUS at info@oboluslaw.com or message us via t.me/oboluslaw. Map your options.

Which Licence Structure Fits Which Operator Profile?

Selecting the right licensing architecture depends on the operator's commercial model, user geography and the activities being performed – not on the easiest or cheapest single jurisdiction available.

Profile A – Exchange serving EU retail and institutional clients: The primary instrument is a MiCA CASP authorisation for exchange services, obtained in a well-resourced member state capable of administering a timely review. Passporting then covers EEA expansion. Key risk: activity-scope completeness at the initial authorisation stage. Timeline: varies by member state; qualitatively a matter of several months under MiCA's full regime. The AML/KYC framework must meet the most demanding standard within the passport scope.

Profile B – Custody and transfer business operating across Dubai, Singapore and the EU: Three separate authorisations are required – VARA for Dubai activities, a MAS Digital Payment Token service licence for Singapore, and a MiCA CASP for EU operations. No cross-recognition exists between these regimes. Capital and governance requirements accumulate. Banking becomes the binding constraint: a multi-licensed business needs banking in or accessible to each regulated perimeter. Timeline and cost scale with the number of applications run sequentially or in parallel.

Profile C – Early-stage token issuer seeking the fastest compliant EU entry with future passporting upside: A MiCA whitepaper obligation attaches at the token level; the CASP authorisation attaches at the service level. These are separate instruments with separate timelines. An issuer that also operates a secondary-market exchange must hold a CASP exchange authorisation in addition to filing a whitepaper. Lithuania or another member state with a developed MiCA implementation process may offer timeline advantages at authorisation, though the compliance load once passported is uniform across the EEA.

Profile D – Fund or institutional desk seeking a recognised jurisdiction with a common-law backdrop: ADGM/FSRA or AIFC/AFSA offer recognised regulatory regimes within a common-law legal environment. Neither regime passports into the EU. A fund serving EU investors must independently satisfy MiCA or the applicable national placement regime in each EU member state. The AIFC/AFSA structure may offer advantages for Central and South Asian investor access that neither VARA nor ADGM reaches.

How Does the Licence Stack Interact with Banking and Compliance Infrastructure?

Licensing and banking are inseparable in digital-asset business, but they are not the same thing. A valid licence does not guarantee banking access, and banking access in one jurisdiction does not substitute for a licence in another. Operators we advise consistently identify banking as the most difficult operational constraint in a multi-jurisdiction build – more difficult, in practice, than the regulatory authorisation itself.

Correspondent banking for digital-asset businesses is concentrated among a small number of institutions. Each has its own jurisdiction-acceptance policy, AML due-diligence standard and transaction monitoring expectation. A firm that holds a VARA licence but does not also demonstrate MiCA-compatible AML procedures may find that an EU correspondent bank declines the relationship, because the correspondent's own compliance team is assessing the firm against MiCA-equivalent standards regardless of where it is licensed.

The implication is that the AML program, the KYC framework and the transaction monitoring system must be designed for the most demanding jurisdiction in the stack from the outset. Retrofitting an AML program after a banking relationship is threatened is significantly more disruptive and expensive than building it correctly at inception. We have seen firms spend more on emergency remediation than the original compliance build would have cost.

A micro-matter from our practice illustrates the point. In a recent structuring engagement, a payments company with a single offshore registration sought EU banking. The bank's correspondent-risk team identified a gap in the firm's VASP Travel Rule implementation for transfers above the applicable threshold and a KYC framework that did not address enhanced due diligence for high-risk corridors. We restructured the AML policy, updated the transaction monitoring parameters and coordinated a parallel MiCA pre-authorisation consultation with a member-state regulator. The firm secured a provisional banking relationship within a matter of weeks and progressed its CASP application without the structural impediment that had delayed it for months.

What Do Regulators Now Expect from a Cross-Border VASP?

Regulators across the major hubs increasingly expect digital-asset businesses to demonstrate that their compliance infrastructure matches the geographic scope of their commercial operations – not merely the regulatory perimeter of their home jurisdiction. This is a structural shift from the earlier period, when many VASPs were registered but only lightly supervised.

ESMA and the national competent authorities within the MiCA regime have published expectations around CASP governance, conflict-of-interest management and complaint-handling that apply in full to any firm using the CASP passport. The VARA rulebooks in Dubai impose activity-specific compliance obligations – for exchange, custody and transfer/settlement activities – that go beyond a simple AML registration. MAS in Singapore applies enhanced AML/CFT expectations to DPT service providers, including specific guidance on Travel Rule implementation and VASP counterparty due diligence.

The SFC in Hong Kong, under the VATP (virtual-asset trading platform) licensing regime, requires licensed platforms to demonstrate adequate cybersecurity, client-asset safeguarding and market-integrity controls. These obligations are not satisfied by reference to a licence held in another jurisdiction.

Common to all regimes is an expectation that the MLRO (Money Laundering Reporting Officer) function is adequately resourced, sufficiently senior and able to exercise independent judgment. An MLRO who sits in one jurisdiction managing AML obligations across three or four regulatory perimeters without appropriate delegation and local support is a governance risk that regulators in multiple jurisdictions have identified as a red flag during supervisory reviews.

What Are the Most Costly Passporting and Licensing Mistakes?

The mistakes we see most frequently in cross-border licensing are structural – they arise from decisions made at formation or early growth that become progressively more expensive to correct as the business scales.

The first is assuming that the activity scope of an initial licence covers the full commercial model. An exchange licence does not cover custody, and a payment-service licence does not cover exchange activity. Operators that expand their product suite without reassessing their licence scope are operating unlicensed for the new activity from the day it launches.

The second is treating AML compliance as a document exercise rather than an operational program. A policy that describes a Travel Rule process without the technical implementation – the data-capture fields, the screening workflow, the counterparty-VASP assessment procedure – will not satisfy a regulatory audit. Transaction monitoring that produces alerts without a documented alert-handling and escalation process is similarly deficient.

The third is deferring the banking build until after the licence is granted. A licence without banking is a regulatory credential with no operational utility. The banking analysis – which counterparts will accept the business, under what AML conditions, in which jurisdictions – should run in parallel with the licensing process, not after it.

The fourth is failing to map user geography before launch. A business that is licensed in one jurisdiction but whose marketing, app stores or payment infrastructure reaches users in another is operating in the regulatory perimeter of the second jurisdiction from the first transaction. Regulators apply nexus tests that catch this exposure regardless of the operator's intent.

The fifth, in our experience, is the most avoidable: selecting a jurisdiction based on perceived ease of registration without assessing whether that jurisdiction's authorisation is recognised by the counterparts – banks, institutional clients, correspondent VASPs – the business needs to operate. A registration that satisfies the home regulator but is treated as insufficient by the firm's banking partners or by the regulators of its largest user markets provides less protection than its cost suggests.

Related at OBOLUS

FAQ

What does the Travel Rule require from a VASP?

The Travel Rule, derived from FATF Recommendation 15, requires a VASP (virtual asset service provider) to collect and transmit originator and beneficiary identification data alongside virtual-asset transfers that meet or exceed the applicable threshold. The specific threshold varies by jurisdiction. The transmitting VASP must screen the receiving VASP to confirm it operates under a compliant regime, and both parties must retain the transmitted data for the applicable record-keeping period. Technical implementation – the data-capture and transmission mechanism – is a separate compliance obligation from the policy itself.

Who must act as MLRO for a crypto firm?

Most major licensing regimes require a firm to designate a MLRO (Money Laundering Reporting Officer) – an individual with sufficient seniority, independence and AML knowledge to oversee the firm's compliance program, receive internal suspicious-activity reports and determine whether to make external disclosures to the relevant financial intelligence unit. Regulators assess whether the MLRO is adequately resourced and genuinely empowered. In a multi-jurisdiction business, the MLRO governance model – whether centralised, regional or delegated – requires explicit design and documented accountability at each regulatory perimeter.

How do regulators audit crypto AML programs?

Regulators in the major hubs audit AML programs by examining both documentation and operational evidence. They review the AML policy, the risk assessment, the KYC onboarding records and the transaction monitoring configuration. Critically, they test whether the program operates as written: they pull samples of customer files, review alert-handling logs and assess escalation decisions. A policy that describes a compliant process but is unsupported by operational records – timestamped files, documented decisions, training records – will not satisfy a supervisory review. Annual independent audits of the AML program are expected or required in most established regimes.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before clients commit to a structure, and our disputes team coordinates freezing relief and on-chain tracing across leading common-law forums. To discuss your situation, contact info@oboluslaw.com.

By Victor Olsen, Regulatory & Compliance Analyst – specialising in multi-jurisdiction VASP authorisation, AML program design and cross-border compliance architecture for digital-asset businesses.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours