Failing to manage licence renewal and variation: the compliance burden that accumulates across operating, custody and payment layers is one of the fastest ways to lose banking relationships and trigger regulatory scrutiny simultaneously. VASP registration and regulatory authorisation are not static events – they are living obligations that require sustained monitoring, periodic re-filing and, whenever the business model shifts, a formal variation process that can run for months. The analysis below maps the full compliance lifecycle, identifies the structural traps operators walk into at the renewal and variation stage, and explains how cross-border operations multiply every one of those obligations.
This page is structured for the general counsel or COO who already holds a licence and is now asking whether what was approved eighteen months ago still covers the business as it operates today.
Why Licence Renewal Is Not a Simple Formality
Renewal is the moment a regulator re-evaluates the business against the current version of its rules – and those rules have changed materially in almost every major jurisdiction over the past several years. Under MiCA, the transition from prior national VASP (virtual asset service provider) registrations to the new CASP (crypto-asset service provider) authorisation model creates a re-authorisation exercise, not a rubber-stamp renewal. Operators who assumed their legacy registration would carry forward are discovering that the CASP authorisation is a substantive new assessment. The same structural re-evaluation is occurring in the BVI under the VASP Act framework and in Cayman under the Virtual Asset Service Providers Act, where regulators are progressively tightening their expectations around governance, AML controls and prudential standing.
In our cross-border practice, we see a consistent pattern: the business has grown, the product set has expanded and the client base has diversified – but the licence still describes the original, narrower activity. The gap between what the licence authorises and what the business actually does is the compliance exposure that enforcement actions are built on.
Renewal submissions require updated financial statements, revised AML/KYC policies calibrated to the current FATF Recommendations (including Recommendation 15 on virtual assets), refreshed fitness-and-propriety disclosures for controllers and senior managers, and in many regimes a current technology and systems audit. The documentation burden at renewal can approach or exceed the original application – yet operators routinely under-resource it.
The practical risk is concrete: a renewal that is submitted late, incomplete or without addressing intervening regulatory guidance can result in a conditional renewal with remediation conditions, a suspension of the authorisation pending further review, or in the most serious cases a formal refusal. Any of those outcomes triggers disclosure obligations to banking partners and, in some regimes, to the public register.
What Triggers a Variation Application?
A variation is required whenever a licensed operator proposes a material change to its regulated activities, its organisational structure or the conditions under which it was authorised – and the threshold for "material" is set by the regulator, not by the operator's internal judgment. Operators we advise routinely underestimate how low that threshold is in practice.
The common variation triggers we see in practice include: adding a new product line (moving from spot exchange services to staking, lending or derivatives); onboarding a new asset class (adding a token not covered by the original authorisation, particularly relevant under the VARA activity-based licensing model in Dubai where each activity has its own approval track); appointing a new controller, ultimate beneficial owner or senior manager who requires regulatory approval; materially changing the corporate structure through a merger, acquisition or group reorganisation; and crossing a transaction-volume or balance threshold that shifts the operator into a higher licence tier – the standard payment institution to major payment institution distinction under the MAS Payment Services Act framework in Singapore being one well-documented example.
What makes variation particularly demanding in a cross-border context is that a structural change in one jurisdiction can simultaneously trigger variation filings in two or three others. A group that holds a CASP authorisation through an EU entity, a VARA licence in Dubai and an MAS-regulated Singapore entity will find that a change to the group's beneficial ownership structure requires parallel regulatory notifications and, in many cases, parallel formal variation applications, each governed by its own procedural timeline and its own information requirements.
The process above describes the standard path. Your facts – the entity, the user base, the banking – change the analysis materially.
To map the variation obligations across your current licence stack, contact OBOLUS at info@oboluslaw.com.
The Compliance Burden: Structure and Scale
The total compliance burden attached to a multi-jurisdiction licence portfolio is best understood as three distinct cost layers running simultaneously: the periodic reporting layer, the event-driven layer and the regulatory-change layer. Most operators budget for the first. They frequently underestimate the second and are almost never prepared for the third.
The periodic reporting layer covers the obligations that run on a fixed calendar: annual AML/CFT reports, prudential returns, transaction-monitoring statistics, and the personal questionnaire refreshes for approved persons. The cadence and format vary by regime – the FCA in the UK, FINMA in Switzerland and the AFSA within the AIFC each impose their own returns schedules and their own definitions of what constitutes a reportable event.
The event-driven layer is triggered by facts outside the operator's control as much as by internal decisions. A change in the FATF Mutual Evaluation Report for the jurisdiction where the operator holds its licence can prompt the regulator to issue new AML guidance with a short implementation window. A new ESMA supervisory opinion on CASP governance can require immediate policy updates. A court judgment clarifying the boundary between a utility token and a security can require an operator to re-examine whether its token offerings still sit within the scope of its existing authorisation or require a variation.
The regulatory-change layer is the least predictable. MiCA represents the most significant regulatory-change event in European digital-asset licensing in a generation. For operators licensed through a national VASP regime – Lithuania and Malta in particular – the transition to CASP authorisation is not simply administrative. It requires a full re-submission, a capital adequacy assessment against the new class-based own-funds requirements and, where the operator provides custodial services, an analysis of whether the custody regime under MiCA imposes obligations that the existing operational model does not yet meet.
How Cross-Border Operations Multiply Every Obligation
For a business operating across multiple jurisdictions, every compliance obligation at the home regulator is paired with a mirror obligation at each host regulator where the operator serves clients or relies on a passport or equivalence determination. The multiplication effect is structural, not incidental.
Consider the Travel Rule – the obligation under FATF Recommendation 15 to pass originator and beneficiary data with a virtual asset transfer. Every major licensing jurisdiction now imposes a version of the Travel Rule. But the implementing rules differ: the de minimis threshold above which the obligation activates varies by jurisdiction, the data fields required are not fully harmonised and the technical standards for counterparty verification are still evolving. An operator licensed in the EU under MiCA, serving clients in Singapore through a cross-border arrangement and holding assets in a Cayman structure, is managing three distinct Travel Rule regimes simultaneously – and a non-compliance finding in any one of them can trigger a fitness review at the others.
The same multiplication applies to governance and fit-and-proper expectations. Where a group appoints a new Chief Compliance Officer or Chief Executive, the individual may require regulatory pre-approval in each jurisdiction where the group holds a licence. In a three-jurisdiction group, that can mean three parallel approval processes running on three different timelines, during which the individual may be subject to interim restrictions.
Banking relationships amplify the cross-border burden further. In our practice, we regularly advise operators whose banking partners have required the production of current regulatory certificates, updated AML policies and variation confirmation letters as a condition of account maintenance. Those requests frequently arrive outside the renewal cycle and on short timelines. An operator that is mid-variation – formally notified to the regulator but awaiting approval – is in a particularly vulnerable position with its banks, because the variation creates an ambiguity about the scope of the current authorisation that conservative compliance departments at financial institutions will often resolve by suspending the account pending confirmation.
Decision Matrix: Which Profile Faces Which Variation Risk?
The compliance burden at renewal and variation is not uniform across operator profiles. The risk concentrates differently depending on the business model, the licence architecture and the jurisdictional spread.
Profile A: Single-jurisdiction exchange operator holding a national VASP registration transitioning to MiCA CASP. The primary risk is timing – the transition window is defined by the regulator, not the operator, and missing the grandfathering deadline can result in needing to apply for full authorisation from scratch. The key variation trigger is the product scope: if the operator has added staking, lending or any derivative product since its original registration, those activities require specific authorisation under MiCA and cannot be assumed to pass through the transition automatically. Timeline: the transition process is substantive and, where the operator needs to address governance or capital gaps, should be treated as a multi-month engagement from the outset.
Profile B: Multi-jurisdiction custodian licensed in two or three hubs (ADGM, Singapore, a Cayman registration). The primary risk is the parallel-variation trap: a structural change at holding company level triggers simultaneous filings across each jurisdiction, each with its own information package, its own timeline and its own discretion to impose conditions. The compliance burden here is coordination as much as substance. Where the group's external counsel in each jurisdiction is not actively coordinating, gaps open between what is disclosed in one jurisdiction and what is disclosed in another – a consistency problem that regulators share information with each other to detect.
Profile C: Token issuer adding a secondary service – moving from token distribution into exchange or custody services. This is the profile most likely to require a de novo application rather than a variation, because the proposed activity may not fall within the scope of the existing authorisation at all. The analysis begins with a careful mapping of what the existing licence actually covers. In our practice, we have seen operators assume a variation is sufficient and submit variation paperwork, only to be told by the regulator that the new activity requires a separate authorisation. That resets the clock entirely and may require the operator to cease the new activity in the interim period.
Profile D: Group undergoing M&A with a licensed entity on either side of the transaction. Change of control is a mandatory variation trigger in virtually every licensing regime. In most regimes it requires prior regulatory consent – meaning the transaction cannot complete until the regulator approves the change of control, which inserts a regulatory timeline into the deal timetable that is not always visible to the acquirer's transaction team until late in the process. In a competitive process, an operator that discovers the regulatory consent requirement at the exclusivity stage faces a material extension of the expected closing timeline.
The Five Structural Mistakes Operators Make at Renewal and Variation
Across the renewals and variation applications we have worked through, the same structural mistakes appear with regularity. Identifying them early reduces both the timeline risk and the regulatory relationship risk.
The first is treating the renewal as a document-production exercise rather than a compliance gap analysis. Renewal is the regulator's opportunity to measure the business against current standards. An operator that submits its renewal without first conducting an internal audit against the current version of the applicable rules risks the regulator identifying the gaps. A regulator-identified gap at renewal is always more consequential than a self-identified gap disclosed proactively.
The second is failing to log variation triggers in real time. Operators that do not maintain a live regulatory-change register miss variation triggers as they accumulate. A business that has added three new senior managers, crossed a transaction threshold and added a new product line over an eighteen-month period without filing variations is carrying a material undisclosed compliance exposure.
The third is misclassifying the scope of the existing authorisation. This is particularly acute under activity-based regimes like VARA in Dubai, where the authorisation is specific to enumerated activities. An operator that adds a new service and treats it as incidental to an existing authorised activity, rather than as a new activity requiring its own approval, may be operating without authorisation for that service.
The fourth is underestimating the banking dimension. As noted above, banking partners frequently impose their own verification requirements on the licence status of digital-asset clients. An operator that is in the middle of a renewal or variation should brief its banking partners proactively, rather than waiting for the bank's compliance team to flag the gap.
The fifth is failing to engage allied counsel in each relevant jurisdiction when a structural change triggers multi-jurisdictional variation obligations. Coordinated disclosure – ensuring that what is stated to regulator A is consistent with what is stated to regulator B – requires active project management across the group's external counsel network.
If a prior application stalled or an account was closed, a second review can surface the structural reason and the route forward. Contact OBOLUS at info@oboluslaw.com to discuss your situation.
Practice Illustration: Multi-Jurisdiction Variation Under Pressure
In a recent matter, a digital-asset exchange operator holding licences in two EU member states and a registration in a common-law offshore centre approached us mid-variation. The business had added a staking product several months earlier and had not filed a variation, operating under the assumption that staking was incidental to its existing spot exchange authorisation. One of the national competent authorities, conducting a supervisory review, identified the staking service and issued a formal request for an explanation of the regulatory basis under which it was being offered.
We conducted a rapid perimeter analysis across all three jurisdictions. In one EU jurisdiction, a variation was required and could be filed retroactively with a remediation letter explaining the operator's good-faith but incorrect assessment. In the second, the regulator required a separate notification but treated the staking product as within the CASP perimeter with a condition attached. In the offshore centre, the existing registration did not cover the activity and a new application was required, with the operator needing to suspend the service for that jurisdiction's clients in the interim period.
The outcome was manageable – no enforcement action was taken – but the process required several months of parallel regulatory engagement and consumed significant management bandwidth. Had the variation analysis been conducted at the point the product was being designed, the operator would have filed proactively, avoided the supervisory inquiry entirely and preserved the full service offering throughout.
Self-Assessment: Is Your Licence Architecture Current?
The following checklist identifies the most common gaps between an operator's current licence position and its actual business activities. Each item that cannot be answered with a clear affirmative represents a compliance exposure that warrants legal review.
- Has every change to the list of approved persons, controllers and ultimate beneficial owners been notified to each relevant regulator within the required period?
- Does the current authorisation expressly cover every product or service the business offers to clients, including any product added since the original application?
- Has the business crossed any transaction-volume, asset-under-custody or client-number threshold that shifts it into a higher regulatory tier or triggers additional obligations?
- Has the business's geographic client footprint changed in a way that triggers cross-border licensing obligations in jurisdictions not currently covered?
- Have AML/KYC policies been updated to reflect the current version of the applicable FATF-aligned guidance and any jurisdiction-specific supervisory expectations published since the last regulatory filing?
- Is the Travel Rule compliance program technically and procedurally current in each jurisdiction where the business receives or sends virtual asset transfers?
- Has any material change to the group structure been notified to all relevant regulators, not only the home supervisor?
- Does the business's banking relationship documentation reflect its current regulatory status, including any conditions attached to its authorisation?
A common assumption in the market is that a single offshore registration is sufficient to serve clients globally. It is not. The regulatory authorisation requirement is triggered by the jurisdiction where the client is located, by the jurisdiction where the server infrastructure operates and, in some regimes, by the jurisdiction where the assets are held – not only by where the operator is incorporated.
Objection: "Our Offshore Licence Covers Our Global Client Base"
This assumption is the most persistent structural error we encounter in the digital-asset licensing market. The analysis of whether a particular client or transaction is within the scope of an offshore licence requires a jurisdiction-by-jurisdiction assessment of each target market's rules on cross-border service provision. Many jurisdictions – the EU under MiCA, the UK under the FCA regime, Singapore under the MAS Payment Services Act, Hong Kong under the SFC VATP regime – impose licensing obligations based on where the client is located or where the services are actively marketed, regardless of where the operator is incorporated.
An operator incorporated in Cayman or BVI with a registration under the applicable VASP framework in those jurisdictions is not thereby authorised to solicit or serve retail or institutional clients in the EU, the UK, Singapore or Hong Kong. Serving those clients without the applicable local authorisation is, in those jurisdictions, a criminal offence for which the operator's directors and senior managers may carry personal liability.
The practical implication is that the licence architecture for a globally-facing digital-asset business needs to be designed around the client base, not around the incorporation jurisdiction. Where the operator serves EU clients, a CASP authorisation through an EU entity is required. Where it serves Singapore clients, an MAS DPT licence is required. Where it serves Hong Kong clients, an SFC VATP licence is required. The offshore holding structure can be retained for corporate efficiency and capital management purposes, but it does not substitute for local authorisation in the markets where clients are located.
We map the licence stack across operating, custody and payment layers before any commitment is made – that analysis prevents the costly remediation exercise that follows from discovering the gap after the fact.
Related at OBOLUS
- Licensing and registration for digital-asset businesses – the full licence architecture across 70+ jurisdictions, from initial application to renewal.
- Crypto exchange setup in Guernsey – the Guernsey FSC regime, the application process and the cross-border interaction with EU and UK rules.
- AML/CFT policy drafting in Gibraltar – the Gibraltar DLT framework, the GFSC supervisory expectations and practical policy drafting for licensed operators.
FAQ
How long does a crypto licence take to obtain?
The timeline varies significantly by jurisdiction, licence type and the completeness of the application submitted. In our cross-border practice, initial authorisation under regimes such as MiCA CASP or the MAS Payment Services Act typically runs for several months from submission of a complete application. More complex applications – those involving novel business models, significant capital adequacy questions or multi-activity authorisations – routinely take longer. Incomplete applications that require supplemental information rounds extend the process further. Budget conservatively and engage counsel before the filing, not after.
Which jurisdiction is best for licensing my crypto business?
There is no universally correct answer. The right jurisdiction depends on the operator's client base, the activities it proposes to conduct, its capital position, its banking requirements and its long-term market access objectives. A CASP authorisation in an EU member state provides passporting across the EU/EEA. A VARA licence covers Dubai mainland operations. An MAS licence covers Singapore. The licence architecture question is almost always a multi-jurisdiction analysis, not a binary choice. OBOLUS maps the full operating, custody and payment stack before recommending a structure.
Do I need a separate custody licence?
In most leading regimes, custody of virtual assets on behalf of clients is a regulated activity that requires specific authorisation – it is not automatically covered by an exchange or brokerage licence. Under MiCA, custody and administration of crypto-assets on behalf of clients is one of the enumerated CASP activities requiring express authorisation. VARA in Dubai similarly treats custody as a distinct licensed activity. The analysis turns on whether the operator holds client assets, has discretionary access to client wallets or acts as the technical counterparty to client transactions. If any of those apply, a custody authorisation analysis is required.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before any commitment is made – preventing the remediation burden that follows from licensing gaps discovered after the fact. We also work alongside forensic partners to convert on-chain evidence into court-ready disclosure applications where disputes arise. To discuss your situation, contact info@oboluslaw.com.
By Lydia Brennan, Tax & Structuring Analyst – specialises in cross-border licence architecture, tax treatment of digital-asset activities and the structural interaction between licensing obligations and banking relationships.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.