EST · MMXXVI
Home/Insights/Regulatory/Reverse Solicitation: A Narrowing Defence for Offshore Operators
Compliance, AML & Travel Rule

Reverse Solicitation: A Narrowing Defence for Offshore Operators

Reverse Solicitation: A Narrowing Defence for Offshore Operators. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. T

Offshore digital-asset operators routinely invoke reverse solicitation to justify serving customers in jurisdictions where they hold no licence. The defence has a legitimate foundation: if a client in a regulated market approaches a foreign firm entirely on their own initiative, several regimes permit that firm to execute the resulting transaction without triggering a local authorisation requirement. In practice, however, regulators across the EU, the UK and the leading Gulf hubs have spent the past two years steadily compressing the space in which the defence actually works.

The core legal question is not whether reverse solicitation exists – it does – but whether the specific facts of a cross-border engagement can still satisfy its conditions. Under the MiCA (Markets in Crypto-Assets Regulation) regime, ESMA has signalled that systematic reliance on reverse solicitation to build a retail book will be treated as a circumvention attempt. The pattern is the same in the VARA environment in Dubai and, increasingly, under the FCA regime in the UK. What follows is a structured assessment of where the defence holds, where it has collapsed, and what offshore operators should be doing instead.

What Reverse Solicitation Actually Means in Crypto Regulation

Reverse solicitation is the principle that a foreign firm may service a client located in a regulated jurisdiction without local authorisation, provided the client initiated contact exclusively on their own initiative and the firm took no active steps to solicit, market or otherwise attract that client. The key word is exclusively. Any marketing activity – targeted digital advertising, referral arrangements, localised landing pages, language-specific content – directed at residents of the jurisdiction destroys the defence before a single transaction executes.

The concept is not new. It has long existed in securities law, and most digital-asset regimes have imported a version of it. MiCA carries an express provision allowing the reverse-solicitation carve-out for clients who approach a third-country CASP (Crypto-Asset Service Provider) on their own initiative. VARA's rulebooks contain a corresponding carve-out for inbound requests from non-UAE persons. The BVI FSC and CIMA both permit offshore firms to serve non-resident clients without a local VASP licence, on the theory that the service is rendered from outside the jurisdiction.

The architecture, then, is not the problem. The problem is how operators apply it. In our practice, we encounter a consistent pattern: a firm treats the reverse-solicitation carve-out as a passive compliance posture rather than a condition that must be affirmatively maintained on a transaction-by-transaction basis. Regulators have noticed exactly this.

How MiCA Has Narrowed the Defence in the EU

MiCA narrows reverse solicitation by making it a client-level exception, not a business-model exception. A third-country CASP may execute a service for an EU client who initiated contact on their own initiative, but the carve-out applies to that specific service requested by that specific client. The CASP may not use that initial contact to solicit or market additional products or services to the same client.

ESMA has been explicit in its guidance to national competent authorities. A third-country firm that systematically onboards EU retail clients by relying on reverse-solicitation documentation – without EU authorisation – is engaged in regulatory arbitrage, not legitimate cross-border business. The passporting architecture of MiCA is the intended channel. NCAs in several member states have already opened inquiries into platforms that appear to have structured their outreach precisely to generate inbound contact while maintaining plausible deniability.

What this means operationally is significant. A firm may not send a newsletter to EU subscribers and then claim that the subsequent trade was client-initiated. A firm may not operate a Telegram channel with EU language options and then argue that subscribers who clicked through reached out on their own initiative. The defence requires genuine passivity on the firm's part. Operators we advise on cross-border compliance regularly underestimate how broadly ESMA reads the concept of "active solicitation."

There is also a temporal constraint that MiCA introduces implicitly. Once a client has made a reverse-solicitation contact, the permissible window for servicing that client is limited to the service or product specifically requested. The firm may not leverage that relationship to upsell, cross-sell or renew under the same carve-out. Each engagement must be independently client-initiated. For any operator running a recurring-revenue model – subscriptions, staking yield products, managed portfolios – this restriction effectively forecloses the reverse-solicitation route as a sustainable structure.

For a scoped review of your EU market access model, contact OBOLUS at info@oboluslaw.com. The analysis above describes the regulatory direction. Your specific entity structure, marketing footprint and product suite change the risk calculation significantly. Map your options.

What VARA and the Gulf Hubs Say About Third-Country Operators

VARA in Dubai approaches the reverse-solicitation question from the activity side rather than the client-intent side. Under the VARA regime, any entity conducting a virtual-asset activity – including exchange, lending, transfer or custody – from within or directed at the Dubai mainland must hold the relevant VARA licence for that activity class. The carve-out for third-country operators is narrower than in MiCA: it applies where the service is rendered entirely offshore and the client is not a UAE resident.

In practice, this means that a Seychelles-incorporated exchange with UAE-resident clients who "found the firm themselves" is in a structurally precarious position. VARA has the authority to take enforcement action against entities it determines are conducting regulated activities in or from Dubai without authorisation, regardless of where the entity is incorporated. The test is the activity and the client, not the corporate address.

The ADGM/FSRA regime in Abu Dhabi takes a similar functional approach. The FSRA has built a "recognised virtual assets" list concept into its framework, and the activity-based trigger means that an unlicensed third-country firm providing services to ADGM participants – even at their request – may nonetheless be in breach of the applicable regime. We have seen operators assume that a BVI or Cayman structure insulates them from Gulf regulatory reach. It does not, where the client base is located in the UAE.

The FCA Position: A Cautionary Benchmark for Offshore Operators

The UK's approach under the FCA regime offers the clearest illustration of how reverse solicitation can collapse under regulatory scrutiny. The FCA does not operate a formal reverse-solicitation carve-out for cryptoassets in the way MiCA does. Instead, the Money Laundering Regulations require any firm conducting cryptoasset activity in the UK – including activity directed at UK consumers – to be registered with the FCA.

The FCA's financial-promotion rules impose an additional constraint: cryptoasset promotions directed at UK persons are prohibited unless made by, or approved by, a registered firm. A firm that geo-targets UK users, even through social media or influencer content, is conducting a financial promotion. The reverse-solicitation argument does not apply to the promotion itself – only, arguably, to the resulting transaction. Since the promotion is typically the first link in the chain, the defence rarely survives FCA scrutiny in practice.

The FCA has also been transparent about its registration refusal rate for cryptoasset firms, and its supervisory approach has become more intensive over time. Offshore operators who structure their UK market access around reverse solicitation – without a compliant entity – should treat the FCA posture as the leading indicator of where other jurisdictions are heading.

How AML and Travel Rule Obligations Interact With the Defence

Reverse solicitation is a market-access argument. It does not address the parallel AML and Travel Rule obligations that attach the moment a firm processes a transaction for any client, regardless of how that client was acquired.

The Travel Rule (the obligation, derived from FATF Recommendation 15, to pass originator and beneficiary identifying information with a virtual-asset transfer above the applicable threshold) applies to every in-scope transfer. A VASP that services a client under a reverse-solicitation argument still carries the originator-data obligation on every transfer that client makes. If the firm is unregistered and unregulated, it typically has no functioning VASP-to-VASP Travel Rule messaging system in place. The compliance gap is therefore dual: no licence, and no Travel Rule infrastructure.

AML obligations compound this. A KYC framework (Know Your Customer), transaction monitoring and suspicious activity reporting are not optional for firms that process virtual-asset transfers. They follow the activity, not the licence status. Regulators in enforcement proceedings against offshore operators frequently cite the absence of adequate AML controls as the substantive harm – the licensing gap is often the jurisdictional hook, but the AML failure is the headline finding.

Operators we advise who are transitioning from an informal reverse-solicitation posture to a properly licensed structure consistently encounter the same challenge: they have been running without documented AML policies, without a designated MLRO (Money Laundering Reporting Officer), and without a travel-rule solution. Retrofitting these controls while simultaneously running a licence application is time-consuming and expensive. The business case for building them from the start – before scale creates a compliance backlog – is consistently strong.

Contrasting Positions: When Reverse Solicitation Still Has Utility

A balanced analysis requires acknowledging that the defence retains genuine utility in specific, narrow scenarios. Not every cross-border engagement requires a local licence.

Institutional counterparty transactions provide the clearest case. Where a licensed institution in jurisdiction A initiates contact with an offshore firm to execute a transaction that the institution itself has determined does not require local intermediary licensing, the reverse-solicitation logic is clean, documented and defensible. The initiating party is sophisticated, the transaction is specific and the offshore firm has not marketed to the initiating party.

Bespoke advisory engagements – where a family office or corporate treasury reaches out to a foreign specialist for a specific structured opinion – present similarly clean facts. The engagement is transactional, non-recurring, and demonstrably initiated by the client. Several jurisdictions, including Singapore under the MAS regime and FINMA-supervised Switzerland, have articulated guidance that permits these engagements without full local licensing.

A micro-matter from our cross-border practice illustrates the distinction. In a recent matter, a corporate treasury in a Gulf-adjacent jurisdiction reached out directly to an offshore digital-asset structure to obtain a single over-the-counter transaction for a defined book of stablecoins. The contact was documented: a written request sent to a generic inquiry address, with no prior marketing contact, no solicited referral and no ongoing relationship. We were asked to assess whether the offshore entity's reverse-solicitation reliance was sound. The answer was yes – because the facts were genuinely clean. The entity had not marketed to the jurisdiction, the client was a corporate entity acting for its own account, and the transaction was singular and specific. We confirmed the defensibility in writing, with a compliance memo that documented the basis. That documentation – not the legal conclusion alone – was what mattered, had a regulator ever asked.

The lesson is not that reverse solicitation is dead. It is that it is a transaction-level argument, not a business-model argument. Operators who use it to justify building a retail client base in a regulated jurisdiction will not sustain the position under scrutiny.

Decision Matrix: Which Profile Can Still Use the Defence?

Profile A – the offshore operator with a small book of documented institutional counterparties who initiated all contact in writing, where no marketing was directed at their jurisdiction, where each engagement is singular and product-specific, and where the operator has AML documentation in place – retains a defensible reverse-solicitation posture. The risk is low, and the primary action item is maintaining the documentation discipline going forward.

Profile B – the offshore exchange with a growing retail user base, a social media presence that geo-targets or is accessible in multiple regulated markets, and a user-agreement clause asserting reverse solicitation for all users – faces material regulatory risk under MiCA, the VARA regime and the FCA framework simultaneously. The defence is nominal. The practical path is a licence in the primary market and a structured review of how the user base is segmented.

Profile C – the offshore operator that has licensed in one hub (say, under the AIFC/AFSA regime in Kazakhstan or the BVI FSC framework) and asserts that the single licence covers all global activity because no active solicitation occurred outside that hub – is in the most common and most precarious position. A single licence does not passport. The AIFC is not the EU. AFSA authorisation does not satisfy ESMA or the FCA. The reverse-solicitation carve-out cannot substitute for jurisdictional coverage.

Profile D – a DeFi protocol operator who argues that a non-custodial, permissionless interface means no entity is "soliciting" anyone – faces a rapidly evolving analysis. Several regulators, including ESMA and the FCA, have signalled that operating a frontend that directs users to a DeFi protocol may itself constitute a regulated activity, regardless of the underlying protocol's non-custodial nature. Reverse solicitation does not map cleanly onto this profile.

If your structure falls into Profile B, C or D, the operational risk of continued reliance on reverse solicitation warrants a formal legal assessment now – before a regulatory inquiry narrows the options. Contact OBOLUS at info@oboluslaw.com or t.me/oboluslaw. Map your options.

Addressing the Common Assumption: One Offshore Licence Covers the World

A common assumption among early-stage operators is that a licence obtained in a permissive offshore jurisdiction – a BVI VASP registration, a Cayman licence, an AIFC authorisation – provides adequate legal cover to serve clients globally, provided no active marketing occurs in the client's home jurisdiction. This assumption does not hold under the regulatory regimes that matter most.

Passporting exists only where a specific treaty or mutual-recognition arrangement provides for it. MiCA's passporting mechanism allows a CASP authorised in one EU member state to operate across the EU/EEA. It does not extend to third-country operators. There is no equivalent passporting arrangement between the BVI and the EU, between Cayman and the UK, or between the AIFC and Dubai. Each jurisdiction applies its own activity-based trigger, and the reverse-solicitation carve-out is the only available bridge – a bridge that, as this analysis has shown, is narrow and condition-dependent.

Operators we advise who have relied on this assumption are generally not acting in bad faith. They have built their structure on advice that was accurate for an earlier regulatory environment and have not revisited it as MiCA came into force, as VARA published its rulebooks and as the FCA tightened its financial-promotion perimeter. The correction requires a licence-stack review: which markets are material, which licence categories those markets require, and what interim structure manages the risk while applications are in progress.

The cross-border reality is that a serious digital-asset business operating across the EU, the Gulf and one or more common-law jurisdictions typically needs three to five regulatory touchpoints – not one. The offshore licence remains relevant, often as the operating entity or the custody layer, but it does not substitute for jurisdictional coverage in the markets where users and revenue actually sit.

Self-Assessment: Can Your Reverse-Solicitation Reliance Withstand Scrutiny?

Before engaging counsel, an operator should be able to answer the following questions honestly. Affirmative answers across all points suggest the defence is maintainable. Negative or uncertain answers identify the specific compliance gap to address.

First: does the firm have a documented record, at the individual-client level, of how each client in a regulated jurisdiction made initial contact? "Documented" means a contemporaneous record – not a retrospective assertion in the user agreement.

Second: has the firm conducted any advertising, content marketing, SEO or social media activity that was directed at, or foreseeably accessible to, residents of jurisdictions where the firm holds no licence? If yes, the marketing-solicitation bar has likely been crossed.

Third: has the firm, following initial contact from a client under the reverse-solicitation route, marketed additional products or services to that client? If yes, MiCA's constraint on the carve-out has likely been exceeded for EU clients.

Fourth: does the firm have functioning AML policies, a designated MLRO, a transaction-monitoring system and a Travel Rule solution? If not, the compliance gap is independent of the licensing argument and will be treated as a substantive enforcement issue by most regulators.

Fifth: has legal counsel reviewed the reverse-solicitation posture within the past twelve months, in light of MiCA entering into force and recent regulatory guidance from ESMA, VARA and the FCA? If not, the analysis is likely outdated.

In our cross-border practice, we regularly advise operators who have answered "no" or "uncertain" to three or more of these questions. The path forward is not typically enforcement exposure – it is a structured transition to a properly licensed and documented posture, executed before a regulator initiates contact.

Related at OBOLUS

FAQ

What does the Travel Rule require from a VASP?

The Travel Rule, derived from FATF Recommendation 15, requires a VASP to collect and transmit identifying information about the originator and beneficiary of a virtual-asset transfer to the receiving VASP. The obligation attaches to transfers above the applicable jurisdictional threshold. The sending VASP must obtain and verify originator data; the receiving VASP must obtain beneficiary data. Non-compliance exposes both the firm and its MLRO to regulatory action, and is frequently cited in enforcement findings against offshore operators with inadequate AML infrastructure.

Who must act as MLRO for a crypto firm?

Most regulated digital-asset regimes – including MiCA, the VARA rulebooks, the FCA's Money Laundering Regulations and the MAS Payment Services Act – require a licensed or registered firm to designate a Money Laundering Reporting Officer (MLRO). The MLRO must be a senior individual with sufficient authority and resources to fulfil the reporting and oversight function. The exact seniority and qualification requirements vary by regime. In our practice, firms that have operated without a formal MLRO designation routinely find this is the first structural issue a regulator raises on examination.

How do regulators audit crypto AML programs?

Regulators audit crypto AML programs through a combination of document review, transaction-sampling and on-site or remote examination. Examiners typically request the firm's AML policies and procedures, customer onboarding records, transaction-monitoring alerts and dispositional logs, suspicious activity reports and MLRO activity reports. ESMA and national competent authorities under MiCA, as well as VARA in Dubai, have signalled that risk-based transaction monitoring and documented source-of-funds checks are minimum expectations. Firms that rely on reverse solicitation but have no functioning AML program will not be able to demonstrate compliance at examination, regardless of their licensing position.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence, AML and Travel Rule stack across operating, custody and payment layers before you commit – and we work alongside forensic partners to convert on-chain evidence into court-ready disclosure applications where recovery matters arise. To discuss your situation, contact info@oboluslaw.com.

By Victor Olsen, Regulatory & Compliance Analyst – specialises in cross-border VASP licensing and AML program design for digital-asset operators entering regulated markets.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours