Stablecoin issuers and distributors operating across borders face a compliance environment that has fractured along jurisdiction lines. Under MiCA (the EU's Markets in Crypto-Assets Regulation), a stablecoin is either an asset-referenced token (ART) or an e-money token (EMT) – two categories with materially different authorisation, reserve and redemption obligations. In Dubai, the Virtual Assets Regulatory Authority (VARA) applies an activity-based licensing model that treats stablecoin issuance as a discrete regulated activity distinct from exchange or custody. Singapore's Monetary Authority of Singapore (MAS) under the Payment Services Act has developed its own single-currency stablecoin framework, while the UK's Financial Conduct Authority (FCA) has signalled a phased approach to fiat-backed stablecoin recognition. The result is that a business issuing or distributing a stablecoin must answer four questions simultaneously: what category does the token fall into locally, what authorisation does that require, how does the AML and Travel Rule stack apply, and what does the cross-border picture look like for each user jurisdiction. This analysis addresses each question in turn.
Why Classification Is the Threshold Question for Stablecoin Issuers
The classification of a stablecoin – not its commercial label – determines which regulatory regime applies, which authorisation is required and what penalties attach to non-compliance. Regulators in every major hub assess substance over marketing. A token described commercially as a "utility coin" that confers redemption rights against a fiat reserve will almost certainly be treated as an EMT under MiCA or a fiat-backed stablecoin under the MAS framework, regardless of the issuer's preferred terminology. The same token distributed through an exchange in Abu Dhabi falls under the FSRA's recognised virtual-assets framework within ADGM. Classification errors at the outset are among the most expensive mistakes we see in practice – they can require a structural rebuild of the issuance entity months after launch.
The core analytical distinction, applied consistently across MiCA, the MAS single-currency stablecoin regime and most emerging frameworks, turns on two questions: what assets back the token, and what right does the holder have against the issuer? A token backed by a basket of currencies or assets and designed to maintain a stable value by reference to that basket is an ART under MiCA. A token backed by a single fiat currency, issued at par and redeemable on demand, is an EMT. The EMT category sits closer to electronic money regulation and carries correspondingly demanding reserve, redemption and – for significant issuers – interoperability requirements. The ART category brings a distinct authorisation track through ESMA and the relevant national competent authority. Outside the EU, regulators have generally adopted one of these two analytical poles or a hybrid, though the naming conventions differ.
Operating without the correct authorisation exposes the issuer to enforcement, frozen payment rails and loss of banking relationships – exactly the outcome that a pre-launch classification analysis is designed to prevent. In our cross-border practice, we begin every stablecoin mandate by mapping the token's legal character in each jurisdiction where it will be marketed or distributed, before touching the licence application itself.
For a scoped classification assessment before you commit to an issuance structure, contact OBOLUS at info@oboluslaw.com. The process above describes the standard analytical path. Your facts – the reserve composition, the distribution chain, the user geography – change the classification outcome materially. Map your options with counsel before the architecture is set.
MiCA's ART/EMT Divide: What the Distinction Costs an Issuer
Under MiCA, the ART/EMT divide is the single most consequential structural decision for any stablecoin issuer targeting EU or EEA markets. An EMT issuer must hold an e-money institution authorisation or a credit institution authorisation from an EU/EEA competent authority – a threshold that aligns EMT issuance with the existing payments regulatory regime. An ART issuer requires a dedicated CASP-adjacent authorisation as an ART issuer, assessed by the national competent authority with ESMA involvement for significant tokens. Both tracks require a published whitepaper meeting prescribed content standards.
The practical weight of the distinction emerges at the reserve and redemption layers. EMT issuers must maintain reserves that are at minimum equivalent in value to the outstanding supply of the token, held in secure and low-risk assets. Redemption must be available at par at any time. For ARTs, the reserve requirements are calibrated to the basket composition – more complex, more demanding of treasury infrastructure and more exposed to the "significant token" designation that ESMA can apply, triggering enhanced obligations and, for very large issuers, direct ESMA supervision. The specific capital and reserve composition figures are set out in the applicable MiCA provisions and vary by token category and issuance volume; we do not reproduce them here as thresholds are subject to delegated regulation updates.
Passporting is MiCA's structural dividend. A CASP authorised in one EU member state – including as an ART or EMT issuer – may passport that authorisation across the EU and EEA. This makes the choice of home member state a commercial and strategic question as much as a legal one. Lithuania, with the Bank of Lithuania historically processing VASP applications with relative speed, has attracted interest as a passporting base; Malta's MFSA is transitioning its prior VFA framework to the MiCA CASP model. Operators comparing these routes should assess regulator capacity, local substance requirements and the practical timeline to authorisation – not just the nominal process. Timelines vary and are not static; consult current ESMA guidance and the relevant NCA's published processing windows.
One operational reality MiCA does not resolve is banking. Even an issuer with full CASP authorisation will find that EU correspondent banking for stablecoin reserve accounts remains constrained. In our cross-border practice, we routinely advise on the banking and payment-infrastructure layer alongside the licence – the two problems must be solved together.
How Does VARA Regulate Stablecoins in Dubai?
VARA, the Virtual Assets Regulatory Authority, regulates stablecoin activity in mainland Dubai through an activity-based licensing architecture, with separate licences for issuance, exchange, custody, transfer and lending. Stablecoin issuance is a discrete regulated activity that requires a specific VARA licence, not merely a general virtual-asset service provider registration. This is a materially different structure from the EU model and is a common source of compliance gaps for operators entering the Dubai market from a MiCA or MAS background.
VARA's rulebooks – which are published and cover each licensed activity in detail – set out the conduct, capital, reserve and AML expectations for stablecoin issuers. A key structural feature of the VARA regime is its exclusion of the DIFC financial free zone, which operates under the DFSA's separate regulatory framework. An operator holding a VARA licence for mainland Dubai does not thereby hold a DIFC authorisation, and vice versa. This dual-zone architecture is one of the most frequently misunderstood aspects of UAE digital-asset regulation among inbound operators.
The capital and fee requirements for VARA licences are set out in VARA's published fee schedules and vary by activity category. We describe them qualitatively here: the costs are material, the substance requirements are substantive, and the timeline from application to authorisation has historically run to several months. Operators who have attempted to shortcut the process by relying on a general commercial licence or a neighbouring jurisdiction's authorisation have encountered enforcement. VARA has demonstrated a willingness to take action against unlicensed activity.
Abu Dhabi presents a parallel option for operators considering the UAE as a stablecoin issuance base. The FSRA within ADGM operates a separate regime for regulated virtual-asset activities. The ADGM/FSRA framework uses a "recognised virtual assets" concept and has its own capital and conduct requirements. For operators weighing Dubai against Abu Dhabi, the choice turns on the regulatory posture, the asset class, the counterparty network and the banking infrastructure available in each zone.
Singapore and Hong Kong: How the Asia-Pacific Divergence Shapes Stablecoin Strategy
Singapore and Hong Kong have taken divergent approaches to stablecoin regulation that materially affect where a stablecoin issuer chooses to domicile in Asia-Pacific. MAS has published a specific single-currency stablecoin regulatory framework under the Payment Services Act, designed to apply to stablecoins pegged to the Singapore dollar or any G10 currency. This framework sets out reserve, redemption, disclosure and prudential requirements for "MAS-regulated stablecoins" – a designation that, once obtained, provides a degree of market recognition but comes with correspondingly demanding ongoing obligations.
The MAS framework distinguishes between issuers of MAS-regulated stablecoins and distributors or exchanges that handle such tokens. Each role engages different licence categories under the Payment Services Act – the standard payment institution and major payment institution tracks carry different transaction and float thresholds, and the capital requirements associated with each vary accordingly. The specific thresholds are set out in the Payment Services Act and its subsidiary instruments; they are subject to regulatory update and should be confirmed against current MAS guidance.
Hong Kong's SFC operates a VASP licensing regime for virtual-asset trading platforms (VATPs). The SFC's approach to stablecoins has evolved; the Hong Kong Monetary Authority (HKMA) has published consultation conclusions on a stablecoin issuer licensing regime that is distinct from the SFC's VATP framework. For a stablecoin issuer, this means navigating two parallel regulatory bodies in Hong Kong depending on whether the activity is issuance or exchange. Operators we advise routinely encounter the practical challenge of mapping which Hong Kong regulator has primary jurisdiction over their specific activity – an analysis that is not always linear.
The cross-border angle between Singapore and Hong Kong is significant for operators targeting both markets. A Singapore Payment Services Act authorisation does not passport into Hong Kong, and a Hong Kong VASP licence is not recognised by MAS. Each market requires its own regulatory engagement. For a fund or issuer structuring a regional hub, the two jurisdictions offer different strengths: Singapore has a more developed payments infrastructure; Hong Kong has deeper capital-markets connectivity. The right choice depends on the token's use case and the institutional counterparties involved.
The Travel Rule and AML Obligations: What Stablecoin Operators Must Build
The Travel Rule – the obligation under FATF Recommendation 15 to pass originator and beneficiary information alongside a virtual-asset transfer – applies to stablecoin transfers in every major regulated jurisdiction, including under MiCA, MAS, the FCA regime and VARA's rulebooks. The specific data threshold above which the Travel Rule is triggered varies by jurisdiction and is subject to regulatory update; operators should confirm the applicable de minimis with local counsel. What does not vary is the underlying obligation: a VASP (virtual asset service provider) transmitting a stablecoin must collect, verify and transmit counterparty data – and must have a technical and operational solution for doing so.
The operational challenge for stablecoin operators is that the Travel Rule interacts with the technical architecture of the token. An issuer that processes on-chain transfers through a smart contract without an intermediary VASP layer will need to assess whether the Travel Rule applies directly to it and, if so, how the data collection and transmission obligation is technically discharged. In our cross-border practice, we have seen issuers who had a strong AML policy in place but no functioning Travel Rule solution – a gap that regulators in Singapore, the UK and the EU have begun to examine systematically during supervision reviews.
Transaction monitoring is a distinct but related obligation. Every VASP distributing or exchanging stablecoins must maintain a transaction monitoring programme calibrated to the risk profile of its customer base and the typologies associated with stablecoin use – including layering through high-volume stablecoin transfers, OFAC-designated-address exposure and chain-hopping through wrapped token bridges. The KYC framework must be risk-based: enhanced due diligence applies to higher-risk customers, jurisdictions and transaction patterns. These are not aspirational standards; they are the baseline that examiners at the FCA, MAS, ESMA's supervised entities and VARA expect to see in place.
The cross-border AML picture is further complicated by the fact that FATF member states have implemented the Travel Rule at different speeds and with different de minimis thresholds and data-field requirements. A stablecoin operator running a multi-jurisdictional book will have compliance obligations that do not align neatly across its operating entities. Mapping those obligations entity by entity – and building a compliance architecture that satisfies the most demanding applicable standard – is the approach we recommend. It is more expensive up front and far less expensive than an enforcement action.
If your AML and Travel Rule programme has not been stress-tested against the supervisory expectations in each jurisdiction where you operate, write to info@oboluslaw.com. If a prior application stalled or a banking relationship was closed, a second read can surface the structural reason and the route back. Map your options before the next examination cycle.
United Kingdom and United States: The Fiat Stablecoin Regulatory Push
The UK's FCA is developing a dedicated fiat-backed stablecoin regime as part of a broader cryptoasset regulatory build-out. The current position requires stablecoin issuers and operators to engage with the FCA's financial-promotion rules for cryptoassets and with the cryptoasset registration regime under the Money Laundering Regulations. The FCA has signalled that fiat-backed stablecoins used as a means of payment will be brought within a more specific authorisation framework, but that framework was not fully in force at the time this analysis was prepared; operators should confirm the current regulatory position against FCA publications before structuring a UK-facing stablecoin business.
The United States presents the most complex jurisdictional picture. At the federal level, the SEC, CFTC and FinCEN each assert potential jurisdiction over aspects of stablecoin activity depending on how the token is characterised. FinCEN's money services business framework applies to transmitters of value; some stablecoin arrangements may engage the Bank Secrecy Act's requirements without triggering securities regulation. State-level money-transmitter licensing (MTL) requirements apply in many states; the NYDFS BitLicense represents the most demanding state-level regime. Congress has debated stablecoin-specific legislation without enacting a federal framework as of the time of this writing; the jurisdictional patchwork therefore remains the operative reality for US-market access.
For an operator domiciled outside the US, the question of whether and how to access US customers through a stablecoin distribution arrangement requires careful assessment of state MTL requirements, federal securities analysis and the practical realities of US correspondent banking. In our cross-border practice, we regularly work with allied counsel in the US to map this exposure before a client commits to a US-market strategy.
Decision Matrix: Which Issuer Profile Should Choose Which Jurisdiction?
No single jurisdiction is the right home for every stablecoin issuer. The optimal choice turns on the issuer's token design, target market, banking relationships, ownership structure and risk tolerance. The following profiles are illustrative of the decision branches we see most frequently in practice.
Profile A – EU-market access, single-fiat stablecoin, payments use case: An EMT authorisation under MiCA, with a home member state chosen for regulator capacity and passporting reach, is the primary instrument. Lithuania and Malta are historically considered; the timeline to authorisation and the substance requirements have been evolving under MiCA's transition provisions. Banking for the reserve account is the secondary constraint – resolve it before filing. Key risk: the "significant token" threshold, which triggers enhanced ESMA oversight and can impose operational burdens that the issuer's infrastructure is not built to absorb.
Profile B – Gulf and Asia-Pacific distribution, multi-currency basket token: A VARA licence in Dubai for the Gulf distribution leg, combined with a MAS Payment Services Act authorisation for the Singapore leg, provides coverage across two of the most active stablecoin markets outside the EU. Neither licence recognises the other; both require local substance. The ADGM/FSRA route is an alternative for the UAE leg if the DIFC counterparty network is central. Key risk: the cross-border AML and Travel Rule obligations must be met in both jurisdictions independently, and the token's ART-equivalent classification in each regime requires separate analysis.
Profile C – Offshore issuance, institutional-only distribution: A BVI or Cayman structure, with VASP registration under the applicable VASP Act, offers a lighter regulatory framework for issuers limiting distribution to institutional counterparties. This structure does not provide access to retail EU, UK, Singapore or UAE markets and does not constitute a compliant basis for general public offering. Key risk: the institutional-only distribution perimeter must be rigorously maintained; drift into retail or regulated-market distribution without the corresponding authorisation is a recurring enforcement trigger.
A common assumption in the market is that a single offshore registration is sufficient to support global distribution. It is not. Regulators in the EU, UK, Singapore and UAE assess the location of the customer, not just the location of the issuer, when determining whether local authorisation is required. We regularly advise operators who structured around this assumption and are now managing enforcement exposure in one or more retail markets.
Micro-Matter: Restructuring After a Cross-Border Enforcement Trigger
In a recent cross-border restructuring matter, a stablecoin issuer with an offshore corporate base had been distributing to retail users in two EU member states without a MiCA-compliant authorisation. Enforcement inquiries arrived from two national competent authorities simultaneously. We were engaged to map the issuer's legal exposure across the relevant regimes, identify the path to regularisation and manage the dual-authority correspondence. The structural remedy required separating the issuance entity from the distribution entity, filing for transitional authorisation under the applicable MiCA provisions in a chosen home member state and implementing a Travel Rule and transaction monitoring programme that had not previously been in place. The matter resolved without public enforcement action; the client's EU distribution was regularised within the compliance window the regulators provided.
In a second matter, handled in the same period, a stablecoin exchange operating in the Asia-Pacific region had its primary banking relationship suspended following a correspondent bank's de-risking review. The underlying cause was the absence of a transaction monitoring programme that met the correspondent's standards – a gap that the exchange had not identified because its KYC framework was adequate but its monitoring was not calibrated to stablecoin-specific typologies. We assisted in rebuilding the compliance programme, producing the required documentation for the correspondent bank's compliance team and, in parallel, engaging with allied counsel in the relevant jurisdiction on the regulatory disclosure obligations that the banking event had triggered. The banking relationship was restored after a period of several weeks.
What the "One Licence" Assumption Misses
A common assumption among operators new to stablecoin regulation is that a single offshore or lightly regulated licence is sufficient to serve clients globally. This view does not survive contact with the regulatory position in the EU, UK, Singapore, Hong Kong or the UAE. Each of those regimes assesses the location, marketing reach and counterparty nationality of the issuer's users – not merely the legal seat of the issuer – when determining whether local authorisation or registration is required. An issuer domiciled in a lighter-touch jurisdiction that actively markets to EU retail users is marketing without MiCA authorisation. The same activity directed at Singapore retail users engages the MAS regime. The FCA's financial-promotion rules catch UK-directed marketing regardless of the issuer's domicile.
The practical implication is that the licence stack for a stablecoin issuer with genuine cross-border ambition is multi-jurisdictional by design. It covers, at minimum, the operating layer (where the issuer entity sits), the distribution layer (where the users are) and the custody and reserve layer (where the reserve assets are held and who holds them). Mapping that stack before committing to a structure – and identifying where a single authorisation can carry more than one layer through passporting – is the work that prevents a costly restructure after launch.
Regulators in the leading hubs increasingly expect issuers to have done this analysis before approaching them for authorisation. Applications that arrive without a clear cross-border analysis, a functioning AML and Travel Rule programme and a credible reserve and banking solution are returned or delayed. In our cross-border practice, we structure the application package to address all three layers in the first submission.
Related at OBOLUS
Related at OBOLUS
- AML, KYC and Travel Rule compliance for digital-asset businesses – practical programme design and regulatory gap analysis across the leading VASP regimes.
- Sanctions screening for crypto businesses in Poland – EU sanctions obligations for VASPs operating under MiCA and the national AML framework.
- On-chain asset tracing from a cross-border perspective – tracing and recovery of digital assets across common-law and civil-law forums.
FAQ
What does the Travel Rule require from a VASP?
The Travel Rule, derived from FATF Recommendation 15, requires a virtual asset service provider to collect and transmit originator and beneficiary information alongside a virtual-asset transfer. The specific data fields required and the transaction threshold above which the obligation is triggered vary by jurisdiction. In practice, a VASP must have both a legal compliance policy and a functioning technical solution for data collection and transmission – regulators in the EU, Singapore and the UAE now examine both in supervision reviews.
Who must act as MLRO for a crypto firm?
A Money Laundering Reporting Officer (MLRO) is required by most major VASP regimes, including the FCA's MLR registration requirements, MiCA's CASP authorisation framework and the MAS Payment Services Act. The MLRO must be a sufficiently senior individual with the authority and resource to implement the AML programme and report suspicious activity. Some jurisdictions require the MLRO to be locally based. The suitability of the individual is assessed by regulators at authorisation and during supervision; an MLRO who is a nominal appointee without genuine compliance authority is a recurring examination finding.
How do regulators audit crypto AML programs?
Regulators audit crypto AML programmes through a combination of document review, transaction sample testing and interview of key personnel. Examiners typically assess whether the risk assessment is current and reflects the actual customer and transaction profile, whether the KYC framework includes enhanced due diligence for higher-risk customers, whether transaction monitoring alerts are investigated and closed with documented rationale, and whether the Travel Rule solution is operational across all transfer channels. ESMA-supervised entities, FCA-registered firms and MAS-licensed payment institutions have all been subject to formal AML examinations with material remediation requirements following findings.
About OBOLUS
OBOLUS is an independent digital-asset law boutique acting exclusively for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the compliance, AML and Travel Rule programmes that regulators now expect as a baseline for authorisation. We map the licence, banking and reserve stack across operating, custody and payment layers before a client commits to a structure – not after a regulator has raised a concern. Our disputes team coordinates freezing relief and on-chain tracing across leading common-law forums. Digital assets are the entirety of our practice. To discuss your situation, contact info@oboluslaw.com or message us at t.me/oboluslaw.
By Victor Olsen, Regulatory & Compliance Analyst – cross-border VASP authorisation and AML compliance programme design across the EU, UAE and Asia-Pacific stablecoin regimes.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.