EST · MMXXVI
Home/Insights/Tax/VASP licence application: Practical Lessons for Boards
Licensing & Registration

VASP licence application: Practical Lessons for Boards

Vasp licence application: Practical Lessons for Boards. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBO

Boards approving a VASP licence application (an application for authorisation as a virtual asset service provider) routinely underestimate how much the outcome turns on preparation rather than paperwork. A single misjudged answer about beneficial ownership, a funding source the regulator views as unexplained, or a business-model description that straddles two licence categories can stall a file for months – sometimes fatally. The cost is not only the licence fee. It is frozen banking, delayed product launches, and the compounding risk of operating in a grey zone while the application sits undecided.

This analysis sets out the practical lessons boards should absorb before a VASP registration or regulatory authorisation file is submitted anywhere. It addresses the pre-application decisions that determine success, the cross-border reality that a single licence rarely resolves, the most common board-level mistakes, and the structural questions every general counsel should be able to answer before the firm's name goes on a form.

Why preparation determines outcome more than the application itself

The single strongest predictor of a smooth VASP authorisation is the quality of the legal and commercial analysis done before the application is filed. Regulators across the major hubs – from VARA in Dubai to the Bank of Lithuania under the evolving MiCA regime – now run detailed pre-application engagement programs precisely because they have seen the costs of processing poorly structured files. A regulator that grants a deferred review, requests extensive supplementary information, or suspends the clock on a statutory timeline is not being obstructive. It is signalling that the application did not answer the question the regime was designed to ask.

In our licensing practice, we see two categories of preparation failure. The first is definitional: the applicant has not correctly mapped what it actually does to the licence categories available. An exchange that also settles transactions on behalf of institutional clients may need both an exchange licence and a transfer/settlement authorisation under regimes such as the VARA activity-based rulebooks. Filing under only one category creates a scope problem the regulator will flag. The second category is structural: the entity seeking the licence is not the right entity. Ownership chains that run through multiple offshore holding companies without documented commercial purpose, or boards that include individuals who cannot satisfy fit-and-proper requirements, create problems that cannot be resolved by stronger narrative.

The practical lesson is that pre-application structuring – not application drafting – is where the real work happens. That means a candid mapping of every activity the business performs, a clean analysis of who owns and controls the applicant, and a realistic assessment of whether the chosen jurisdiction's capital and governance expectations can be met.

To assess whether your proposed structure is application-ready before you commit a filing fee, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity, the user base, the banking – change the analysis.

How do you choose the right jurisdiction for a VASP licence?

Choosing the right jurisdiction means matching the business's operating model, ownership structure, and target user base to the regulatory environment that best accommodates all three – not selecting the regime that appears fastest on a licensing-services brochure. No single jurisdiction answers every question, and the board that treats jurisdiction selection as a cost-minimisation exercise routinely ends up relicensing within two years.

The principal axes of comparison are: the regulatory perimeter (what activities are regulated and at what threshold), the fitness and capital expectations, the banking ecosystem, the tax treatment of operating income and token transactions, and the reputational weight the licence carries with counterparties and banking relationships in the target markets. A licence issued under the AIFC/AFSA regime in Kazakhstan is structurally clean and carries common-law protections, but a business whose primary banking relationships and institutional counterparties sit in Western Europe will need to demonstrate that the licence satisfies their compliance frameworks. A MiCA CASP authorisation granted by a national competent authority in an EU member state solves the European passporting question definitively, but the capital and governance expectations are higher than many early-stage operators anticipate.

Operators targeting global institutional clients frequently need what we call a primary licence – one that anchors the entity to a well-regarded regulatory hub and supports banking and prime-brokerage relationships – and one or more operating licences in the specific jurisdictions where users or counterparties sit. The ADGM/FSRA regime in Abu Dhabi, the SFC's VATP licensing framework in Hong Kong, and MAS's Payment Services Act licensing tiers in Singapore each occupy a distinct position in the global hierarchy of crypto-friendly, institution-friendly regimes.

Boards should resist the temptation to select a jurisdiction based on a single variable. Timeline is not a strategy. A jurisdiction that grants registration quickly may impose significant ongoing supervisory obligations, or may not produce a licence that banking counterparties in the target market recognise as adequate.

What does a regulator look for in a VASP application file?

Regulators assessing a VASP licence application are asking a small number of questions, even when the form appears to ask hundreds. Those questions are: who ultimately owns and controls this business; is the business model financially viable and internally consistent; can the applicant demonstrate that it understands and can manage the specific risks of the activities it proposes to conduct; and is the AML/CFT architecture proportionate to the transaction flows and client profile the business expects?

On ownership: fit-and-proper assessment across the FATF-aligned regimes requires the applicant to demonstrate clean regulatory history, adequate financial standing, and relevant competence for every director, senior manager, and beneficial owner above a defined threshold. Where the ownership chain passes through entities in multiple jurisdictions, the applicant must be able to produce clean ownership maps, corporate documents, and source-of-funds explanations for each layer. Regulators will ask. The business that has not prepared this documentation before filing will lose weeks, sometimes months, gathering it under time pressure.

On the business model: the regulator expects internal consistency between the services described, the revenue model, the projected transaction volumes, the capital held, and the risk management architecture proposed. A file that describes high-volume institutional order flow but projects minimal compliance staffing will attract challenge. Projections that are not grounded in contractual pipeline or documented commercial history are treated sceptically.

On AML/CFT: the FATF Travel Rule (the obligation to pass originator and beneficiary data with a virtual asset transfer) is now a baseline expectation in every leading hub. The applicant must demonstrate a credible technical solution for Travel Rule compliance at the point of application, not as a post-authorisation project. Regulators are also asking how the business will screen for sanctioned addresses, what blockchain analytics tools are deployed, and how transaction monitoring thresholds are calibrated to the risk profile.

Cross-border reality: Why one licence is rarely enough

One of the most persistent misconceptions a board can hold is that a single well-chosen offshore licence is sufficient to serve clients in multiple jurisdictions. It is not. The regulatory obligation typically follows the user, the marketing, or the transaction – not the entity's registered address. A business licensed in one hub that actively markets to users in the EU is subject to MiCA's third-country provisions. A business that settles transactions in US dollars through US correspondent banking faces FinCEN and potential state money-transmitter licensing exposure regardless of where its operating entity sits.

In our cross-border practice, we map what we call the licence stack: the combination of entity domicile, operating licences, AML registrations, and banking arrangements that together cover the business's actual risk perimeter. For a mid-market exchange with users in multiple regions, that stack typically involves at minimum a primary operating licence, a separate analysis of each major user-base jurisdiction, and a specific review of the banking and payment-processing layer – because banks impose their own compliance requirements on crypto clients independently of what any regulator has authorised.

The cross-border dimension also affects post-licensing compliance. A business that holds a MiCA CASP authorisation and then onboards a significant volume of US-based institutional clients faces a discrete legal analysis under US federal and state frameworks. The fact of EU authorisation does not export compliance into other regimes. Boards must build a jurisdiction-monitoring function that tracks regulatory change in every market where the business has material exposure.

A practical illustration: in a recent licensing matter, an exchange operator had obtained registration in a well-regarded offshore hub and assumed that served as the global operational licence. When a major institutional counterparty's compliance team reviewed the structure prior to onboarding, they identified that the operator's marketing was reaching users in jurisdictions where a separate registration was required. The business had to pause onboarding, obtain supplementary registrations, and restructure its marketing reach – at a cost in time and relationship capital that a pre-launch analysis would have avoided entirely.

Common board-level mistakes in VASP licensing

Boards that have not been through a regulated financial-services authorisation before make a predictable set of errors in the VASP licensing process. Identifying them in advance is the fastest route to avoiding them.

The first is delegating the application entirely to external counsel without retaining internal ownership. The application requires authoritative answers about the business that only the founders and senior management hold. External counsel can structure and draft, but the underlying facts about ultimate beneficial ownership, source of capital, and forward business model must come from inside the organisation. An application that misrepresents these facts – even inadvertently – creates a regulatory record that is very difficult to correct.

The second is treating the business plan section as a formality. Regulators read business plans closely. A plan that describes an ambitious global exchange but contains no credible analysis of how the entity will manage liquidity risk, counterparty exposure, or a stress scenario is a red flag. Boards should expect the regulator to probe the plan, and should prepare management to respond.

The third – and, in our experience, the most costly – is inadequate source-of-funds documentation. Every founding investment, every convertible note, every angel contribution requires clean documentary evidence of origin. Where the business has taken investment from entities in jurisdictions the regulator treats as higher-risk, the documentation burden increases substantially. Boards should conduct a source-of-funds review of their own cap table before filing.

The fourth mistake is a failure to prepare the compliance architecture before the application is submitted. Regulators in leading hubs – including VARA, the FCA, and the Bank of Lithuania – increasingly expect to see a functioning AML program, not a roadmap. Hiring a compliance officer and implementing transaction monitoring as post-authorisation steps is no longer sufficient at the point of application in the more demanding regimes.

How tax and banking interact with the licence decision

Boards sometimes treat the licence application, the banking arrangement, and the tax structure as three separate work streams. They are not. The jurisdiction in which the operating entity holds its licence determines the tax treatment of operating income, the VAT or analogous obligations on fee revenue, and the withholding exposure on distributions. The banking relationships the business can access are directly conditioned on both the licence it holds and the jurisdiction in which it holds it. A structure that is optimal from a licensing standpoint may create inefficiencies on the tax or banking side that materially affect the business's economics.

In our tax and structuring practice, we see several recurring patterns. The first is a mismatch between the entity that holds the licence and the entity that books revenue. An operating model in which the licensed entity refers business to a holding-company entity for fee processing may create permanent establishment exposure in the licensing jurisdiction and transfer-pricing questions that require active management. The second is a failure to account for the evolving tax treatment of staking rewards, lending income, and token appreciation in the licensing jurisdiction's domestic regime.

Banking is the sharper pressure point. Correspondent banks impose their own de facto licensing standards on crypto clients, independent of regulatory authorisation. A business with a valid VASP licence that cannot demonstrate to its banking relationship the robustness of its AML program, the cleanliness of its transaction monitoring, and the substance of its governance will lose the banking relationship regardless of regulatory status. Boards should treat banking-relationship maintenance as a compliance discipline in its own right, not as a consequence of good licensing.

The practical sequencing for a well-structured build is: define the target user base and the commercial model first; run the licence, tax, and banking analysis in parallel; and commit to the jurisdiction only when all three are aligned. Committing to a jurisdiction because the licence process looks manageable, only to discover the banking environment for that licence is restrictive, is a common and expensive mistake.

If your licensing, tax and banking analysis are running on separate tracks, OBOLUS can consolidate them. Write to info@oboluslaw.com to map the full stack. If a prior application stalled or an account was closed, a second read can surface the structural reason and the route back.

Decision matrix: Matching operator profile to licence strategy

Different operator profiles require materially different licensing strategies. The following matrix – framed in prose, not a table – describes the principal profiles we advise and the approach each warrants.

Profile A: Early-stage retail exchange targeting EU users. The operative question for this profile is whether to seek MiCA CASP authorisation directly or to operate under an existing registration in an EU member state while pursuing the full authorisation. The CASP authorisation route is more demanding on capital and governance, but it produces a passport that works across the EU/EEA and carries growing institutional recognition. Timeline varies by member state and the quality of the pre-application preparation; in well-prepared files, the process typically runs over several months rather than weeks. The key risk is undercapitalisation relative to the category sought.

Profile B: Institutional OTC desk or custody provider serving professional counterparties. This profile typically requires a primary-hub licence in a jurisdiction with strong institutional recognition – ADGM/FSRA, the SFC VATP framework, or MAS under the Payment Services Act are the most common choices – combined with a specific analysis of each major counterparty's own compliance requirements. Capital and governance expectations in these regimes are material. Timeline is typically a matter of many months, and the application process involves detailed supervisory engagement rather than a documentary filing. The key risk is misclassifying the activity and landing in a higher-licence-burden category than anticipated.

Profile C: Token issuer seeking to run a regulated exchange for its own issued asset. This profile stacks a licence question on top of a securities-classification question. The token's legal character must be resolved before the appropriate exchange licence category can be identified. A token that constitutes a security or an asset-referenced token under MiCA carries a different, and more demanding, regulatory pathway than a utility token. Filing an exchange application before the token classification analysis is complete is a structural error. Timeline is non-linear and depends heavily on the classification outcome.

Profile D: Payments business seeking to add crypto-to-fiat settlement to an existing product. This profile frequently involves an operator that already holds an e-money or payment institution licence and is expanding into digital assets. The question is whether the existing authorisation covers the proposed activity or whether a separate VASP registration is required. In most MiCA-aligned regimes, the answer is that a separate authorisation or notification is required even for regulated entities. The key risk is scope creep – operating outside the licensed perimeter on the assumption that an existing payments licence covers the expansion.

What boards should ask before filing

A board that can answer the following questions clearly – and document the answers – is ready to file. A board that cannot should pause and build the analysis before submitting anything to a regulator.

First: what activities does the business actually perform, at the granular level the regulatory regime distinguishes? Exchange, custody, advisory, transfer/settlement, lending, and management are separate regulated activities in regimes such as VARA and MiCA. Bunching them into a single description invites a regulatory question about scope.

Second: who are the ultimate beneficial owners, what is the documented source of their investment, and does any of them have a regulatory history that requires disclosure? This question must be answered with documentation in hand, not in principle.

Third: what is the capitalization of the applicant entity, and is it adequate for the licence category sought? Capital requirements vary by category and jurisdiction; in every flagship regime, the regulator will verify that the capital is held by the applicant, is unencumbered, and meets the relevant standard.

Fourth: does the business have a functioning AML/CFT program, including a designated MLRO (Money Laundering Reporting Officer), transaction monitoring calibrated to the risk profile, and a Travel Rule compliance solution? In the most demanding regimes, the regulator will ask to see evidence of this at the application stage.

Fifth: what is the banking arrangement for the licensed entity, and has the banking provider confirmed it will service a VASP of this type? A licence application that is approved while the banking arrangement fails is not a successful outcome.

A common assumption is that the regulator will guide the applicant through these questions during the process. In practice, regulators provide limited advisory guidance once a file is under formal review. Pre-application engagement meetings are valuable precisely because they happen before the clock starts. Boards that use them to surface and resolve structural issues shorten their overall timeline materially.

In a recent matter, a custodian applicant in a leading common-law hub had prepared detailed technical documentation but had not resolved the source-of-funds question for a minority investor whose capital had passed through two intermediate entities. The regulator suspended the clock pending documentation. We were engaged to work through the ownership chain, obtain the necessary declarations, and restructure one of the intermediate entities to produce a clean corporate map. The file was reactivated and proceeded to authorisation. The lesson was not that the investor's funds were problematic – they were not. The lesson was that the applicant had not anticipated the regulator's standard of proof for beneficial ownership.

Related at OBOLUS

FAQ

How long does a crypto licence take to obtain?

Timeline varies significantly by jurisdiction, licence category, and the completeness of the application. In the most demanding regimes – including MiCA CASP authorisation and the SFC VATP framework in Hong Kong – the process typically runs over many months and involves active regulatory engagement. Simpler registration-based regimes can move faster when the application is well prepared. Pre-application preparation is the most reliable way to shorten the overall timeline; incomplete files routinely extend it by months.

Which jurisdiction is best for licensing my crypto business?

There is no universally best jurisdiction. The right choice depends on the business's operating model, target user base, capital position, banking relationships, and long-term institutional ambitions. A business targeting EU users benefits from a MiCA CASP authorisation's passporting rights. An institutional operator may prioritise ADGM, MAS or the SFC framework. Selecting a jurisdiction without running the parallel banking and tax analysis first is a common and expensive error. OBOLUS maps the full licence, banking and tax stack before a jurisdiction decision is made.

Do I need a separate custody licence?

In most leading regimes, custody of virtual assets is a separately regulated activity that requires either a dedicated authorisation or a specific inclusion in an existing VASP licence. Under MiCA, custody and administration of crypto-assets on behalf of clients is one of the enumerated CASP services. Under VARA's activity-based rulebooks, custody is a discrete licence category. An exchange or payments operator that also holds client assets without the relevant custody authorisation is typically operating outside its licensed perimeter. The analysis must be done activity by activity, not assumed.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit – and our disputes team coordinates freezing relief and on-chain tracing across leading common-law forums when recovery is required. To discuss your situation, contact info@oboluslaw.com or reach us at t.me/oboluslaw.

By Lydia Brennan, Tax & Structuring Analyst – specialising in the intersection of entity structuring, tax efficiency and licensing strategy for cross-border digital-asset operators.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours