Licence renewal and variation sit at the intersection of operational continuity and structural risk. A VASP (virtual asset service provider) that treats renewal as an administrative formality — rather than a moment to reassess the whole licensing stack — routinely discovers that its authorisation no longer matches what the business actually does. With regulatory regimes from MiCA and ESMA to VARA in Dubai and the MAS Payment Services Act in Singapore tightening their scope expectations, the gap between an original licence and a current operating model can become the central enforcement issue of the year. This analysis maps the structural dimension of that problem and the cross-border realities that compound it.
The structuring angle is this: renewal and variation are not passive processes. They are the regulator's scheduled opportunity to re-examine what you are, who you serve, and whether your legal architecture — entity, custody layer, payment rails — still fits the authorisation on the face of the licence. In our cross-border practice, we have seen operators advance to renewal unprepared, only to face scope questions they cannot answer without restructuring first.
Why Renewal Is a Structuring Moment, Not a Filing Exercise
Renewal triggers a fresh regulatory review of your operating model, not merely a clerical stamp on the existing authorisation. Every leading hub — from the FCA's cryptoasset registration regime to the VARA activity-based licence framework — permits the regulator to re-examine the substance of the authorisation at the point of renewal or at any formal variation request. Operators who have grown since the original grant routinely find that the activities they now perform exceed or differ from those originally approved. That divergence is itself a compliance breach independent of the renewal outcome. We advise clients to treat the twelve months before a renewal date as the structuring window, not the filing window.
The structural questions that surface at renewal include: Has the business added custody as a function? Has it expanded from one jurisdiction's user base to another? Has the token mix shifted from utility tokens to instruments that may be classified as asset-referenced tokens under MiCA or as securities under a different regime? Each of those changes is, in most leading frameworks, a variation trigger — requiring a formal application to extend or amend the scope of the licence before the activity begins, not after. The renewal filing is simply the moment at which the regulator confirms it knows the gap exists.
The practical consequence: if you have operated outside your authorised scope between renewals, the renewal application itself creates an admission. That is why structuring advice must precede the renewal filing.
In our practice, we regularly advise operators to conduct an internal scope audit in advance of every renewal cycle — mapping actual activities against the authorised activities list, checking whether the user jurisdictions have shifted, and confirming that any passporting or reliance arrangements are still valid. That audit output becomes the brief for the renewal filing and, where necessary, the variation application that accompanies it.
What Triggers a Variation Under Leading Regulatory Regimes?
A variation of a digital-asset licence is required whenever the regulated business materially changes the activities, instruments, client categories or jurisdictions covered by the original authorisation. The MiCA CASP authorisation regime, the VARA rulebook structure, and the MAS Payment Services Act framework each specify categories of activity that require express authorisation — and adding a category without prior approval is a regulatory breach regardless of commercial rationale. Across the regimes we monitor, variation triggers commonly include: offering custody where only exchange was licensed; adding lending or staking yield products; onboarding clients in a jurisdiction that creates a cross-border regulatory footprint not covered by the original grant; or changing the legal entity that holds the licence through a restructuring, group reorganisation or M&A event.
Entity-level changes are the most structurally consequential variation trigger. A licence belongs to a legal entity, not to a group or a brand. If a corporate reorganisation transfers the operating business to a new entity — even a wholly-owned subsidiary within the same group — the licence does not follow automatically. In several leading frameworks, including the FSRA/ADGM regime in Abu Dhabi and the BVI FSC's VASP Act, a change of control or a structural migration is treated as a fresh authorisation event, not a variation, requiring a new application. Getting that distinction wrong can mean operating without authorisation during the transition period.
The cross-border dimension amplifies the variation risk. A business licensed in one MiCA member state and passporting into others must notify its home NCA (national competent authority) of material changes before they take effect. A change that looks internal from the business perspective — a new product line, a new institutional client category — may require both a variation of the home authorisation and an update to the passporting notification. The passporting architecture does not flex automatically; it reflects the authorised scope at the home-state level.
For a scoped assessment of your variation exposure before filing, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts — the entity, the user base, the banking — change the analysis. A brief pre-filing review typically surfaces the structural questions that would otherwise surface inside the regulator's review window, at a less convenient time.
The Cross-Border Stack: Where Licences, Entities and Activities Diverge
Most digital-asset businesses operate a cross-border stack — the licensing entity sits in one jurisdiction, the users are in another, the custody infrastructure is in a third, and the banking relationships are in a fourth. Each of those layers has its own regulatory logic. The licence renewal or variation exercise is the point at which misalignments in that stack become visible to the regulator simultaneously. In our practice, we regularly advise operators who discovered at renewal that their banking counterparty's home regulator had imposed conditions that were inconsistent with the licensed activities — a conflict that had not surfaced during day-to-day operations but which the renewal review exposed.
The EU passporting model under MiCA creates one variant of this problem. A CASP that is authorised in Lithuania and passports into Germany and France is subject to the home-state regulator for authorisation purposes but to the host-state NCAs for conduct-of-business supervision. When the Lithuanian licence comes up for renewal, the home NCA will examine whether the passported activities remain within scope. If the operator has been offering services in those host states that go beyond what was notified, the renewal review may generate supervisory correspondence from multiple NCAs simultaneously.
Outside the EU, the multi-licence reality is starker. Singapore's MAS does not recognise foreign VASP licences as equivalent; neither does the SFC in Hong Kong. A business that serves both markets needs separate authorisations and must manage each renewal cycle independently. The timing of those cycles may not align, which creates a period during which one licence is in renewal review and the other is current — a gap that banking counterparties and institutional clients increasingly scrutinise. We advise clients to stagger renewals deliberately, maintain a current licence position paper for counterparty due diligence, and brief their banking relationships in advance of any renewal period that involves substantive change.
The economic substance dimension adds another layer. Regulators in the UAE (both VARA and ADGM/FSRA), Singapore, and the leading offshore financial centres increasingly expect substance — staff, infrastructure, decision-making — to be present in the licensing jurisdiction, not simply a registered address. At renewal, a regulator may request evidence that substance has been maintained at the level contemplated by the original authorisation. Where a business has shifted its operational centre of gravity — moving staff, outsourcing functions, relocating management — the renewal review can become a substance adequacy assessment as well as a scope review.
Decision Matrix: Renewal, Variation or Reauthorisation?
The correct regulatory filing depends on the nature and scale of the structural change. The choice between renewal, variation and full reauthorisation is a legal question, but it has significant commercial consequences — a variation application typically adds weeks to months to the regulatory review cycle, and a reauthorisation adds more, during which the operator may be constrained in its ability to offer the new activity. Mapping that timeline against the business's commercial commitments is a core part of the structuring exercise.
Profile A — Stable operating model, same entity, same activities: Standard renewal is the appropriate filing. The structuring work is limited to confirming that actual operations remain within authorised scope and that substance, AML/CFT programmes and key personnel have been maintained. The timeline is that of the regime's standard renewal cycle.
Profile B — New product line or activity within the same entity: A variation application is required before the new activity begins. The variation must be filed and approved — the timeline for which varies by regime and regulator — before revenue from that activity can be booked. The risk is operating in advance of the variation approval; the structuring fix is sequencing the product launch after the regulatory approval, not before.
Profile C — Group restructuring, change of control or entity migration: In most leading frameworks, this is a fresh authorisation event, not a variation. The timing of the corporate change must be coordinated with the regulatory application cycle. A common structural mistake is completing the corporate reorganisation and then applying for the regulatory approval — creating a period of unlicensed operation by the new entity. The correct sequence is regulatory approval first, or a carefully structured parallel-run with the original entity remaining authorised until the new entity is approved.
Profile D — Multi-jurisdictional build-out, new user markets: Each new jurisdiction requires its own analysis. Where MiCA passporting applies, a variation of the home authorisation and a passporting notification may suffice. Outside the EU, separate licences are generally required. The structuring question is whether the business establishes a new legal entity in the target market or uses a branch structure — a choice that affects the regulatory relationship, the tax position and the banking options simultaneously.
A common mistake across all four profiles is treating the renewal or variation as a legal department task disconnected from the CFO's view of the banking stack. In practice, a licence variation that changes the business's activity profile will often require updated banking agreements, revised correspondent banking disclosures and, in some cases, a new banking relationship entirely. We have seen cases where the licence variation was approved and the banking relationship terminated simultaneously — leaving the operator technically licensed but operationally constrained.
The AML/CFT and Travel Rule Interface at Renewal
AML/CFT programme adequacy is assessed at every renewal and is increasingly a substantive rather than procedural review. Regulators operating under the FATF Recommendation 15 framework for virtual assets expect a programme that reflects the current risk profile of the business — not the risk profile assessed at original authorisation. If the business has grown, added new product lines, shifted to institutional from retail clients, or expanded its geographic footprint, the regulator will expect the AML/CFT programme to have evolved accordingly.
The Travel Rule (the obligation to pass originator and beneficiary data with a virtual asset transfer) creates a specific renewal complication. An operator that was licensed before Travel Rule obligations were formally implemented in its jurisdiction may have an AML/CFT programme that predates those obligations. At renewal, the regulator will expect Travel Rule compliance to be embedded — and to be demonstrable. The technical implementation of Travel Rule compliance (VASP-to-VASP messaging, counterparty VASP verification, treatment of unhosted wallets) is a substantive operational question, not merely a policy update. We advise operators to complete a Travel Rule gap analysis as part of the pre-renewal audit rather than presenting a programme with known gaps to the regulator.
The cross-border AML dimension is particularly sharp for businesses with users in multiple jurisdictions. Each jurisdiction's Travel Rule threshold, de-minimis treatment and unhosted wallet rules differs. An operator with a MiCA home authorisation serving users in Singapore must comply with both the EU's implementation and the MAS's Payment Services Act requirements. At renewal of either licence, regulators may request evidence that the operator's AML/CFT programme covers the full jurisdictional footprint, not just the home-state requirements. In our practice, we regularly advise operators to maintain a jurisdiction-by-jurisdiction AML/CFT matrix that is updated as the business grows — because that matrix becomes the primary audit document at renewal.
A Recent Matter: Variation Timing and Cross-Border Complications
In a recent licensing matter, a digital-asset exchange holding an EU CASP authorisation sought to add a custody service following strong institutional client demand. The business assumed that a straightforward variation application to the home NCA would resolve the matter within a standard review period. What the pre-filing review revealed was that the custody infrastructure the exchange intended to use was operated by a related entity in a jurisdiction outside the EU, creating an outsourcing arrangement that required separate regulatory notification under the home NCA's outsourcing rules. The variation application was more complex than a simple scope extension. We worked with allied counsel in the relevant jurisdiction to map the outsourcing structure, prepare the required disclosures, and sequence the institutional client onboarding after — not during — the regulatory review. The business obtained the variation, and the custody service launched without the enforcement exposure that an early commercial commitment would have created.
The lesson is structural. Variation applications rarely present as single-issue filings. The activity change typically sits on top of entity relationships, outsourcing arrangements and cross-border exposures that the original application did not address. The structuring work before the filing — not during the regulator's review — is what determines whether the outcome is clean.
Objection Handler: "One Offshore Licence Is Sufficient for Global Operations"
A common assumption among operators entering the market is that a single well-chosen offshore registration — in the BVI, Cayman Islands or a similar centre — provides a sufficient regulatory basis for serving clients globally. It does not. The BVI FSC's VASP Act and CIMA's Virtual Asset framework are licensing regimes for entities incorporated in those jurisdictions. They do not constitute passports into the EU, the UK, Singapore, Hong Kong or the United States. Each of those markets has its own VASP or equivalent authorisation requirement. Operating in those markets from an offshore entity without local authorisation is an unlicensed activity, regardless of what the offshore licence says on its face.
The banking consequence compounds the regulatory one. Correspondent banks and payment infrastructure providers increasingly conduct their own regulatory mapping. A business that presents a BVI VASP registration as its primary authorisation will face banking counterparty questions about whether it is authorised in the jurisdictions where it actually operates. Those questions may result in the termination of banking relationships — independently of whether any regulatory enforcement action has been taken. Operating without the right licence risks enforcement, frozen rails and lost banking: that risk is not theoretical, and it does not wait for a regulator to act.
The correct model is a jurisdiction-specific licence stack: the licensing entity and authorisation that match the activity and the user base in each market where the business genuinely operates. That stack requires analysis at the outset, maintenance at each renewal cycle, and revision whenever the business expands into a new market. A single offshore registration, held in isolation, is a structural gap — not a global clearance.
If a prior application stalled or an account was closed, a second review can surface the structural reason and the route back. Write to OBOLUS at info@oboluslaw.com or message via t.me/oboluslaw.
Self-Assessment Checklist: Before You File for Renewal or Variation
Working through a structured pre-filing assessment prevents the renewal from becoming an enforcement event. The following questions map the key structural issues that OBOLUS reviews with every licensing client in advance of a renewal or variation cycle.
- Have the business's actual activities remained within the authorised scope since the last renewal or original grant?
- Has the legal entity that holds the licence been subject to any change of control, restructuring or migration since authorisation?
- Have new products, token types or client categories been added that may constitute new regulated activities under the applicable regime?
- Has the geographic footprint of the user base changed — either into new jurisdictions or away from jurisdictions originally disclosed?
- Is the AML/CFT programme current, reflecting the current risk profile of the business and compliant with Travel Rule obligations in all operating jurisdictions?
- Has substance in the licensing jurisdiction — staff, management, infrastructure — been maintained at the level contemplated by the authorisation?
- Are banking relationships aware of the upcoming renewal or variation, and have any banking counterparty disclosures been updated to reflect current activities?
- Does the custody layer — whether in-house or outsourced — operate under a regulatory authorisation that is consistent with the licensed activities and any applicable outsourcing rules?
A "no" or "uncertain" answer to any of these questions is a structuring issue, not a filing question. It should be resolved before the renewal or variation application is submitted, not explained within it.
When to Engage Counsel for Renewal and Variation: The Timeline Argument
The standard answer — engage counsel when you file — is too late for most renewal or variation matters with a structural component. Counsel engaged at filing cannot change what has already happened: the activities operated outside scope, the entity that was restructured, the custody arrangement that was not disclosed. Those facts are fixed. Counsel engaged earlier can sequence the activity changes against the regulatory approval, structure the corporate reorganisation so that it does not create a licence gap, and brief the regulator proactively rather than reactively.
In our practice, we recommend first engagement at least six months before the scheduled renewal date for any business with a material change since the prior renewal — and earlier for multi-jurisdictional operations where the renewal cycles in different markets do not align. For variation applications, the engagement should precede the commercial commitment to the new activity. The moment a business signs a term sheet or a partnership agreement that contemplates a new regulated activity, the variation clock starts — and the commercial pressure to launch increases. That pressure is the structural risk.
For a fresh-build — a business seeking its initial authorisation — the sequencing logic is the same: structure the entity, substance and activity scope before filing, not during regulatory review. The MiCA CASP authorisation process, the VARA application process, and the MAS DPT licensing process each involve detailed regulatory scrutiny of the operating model. A poorly structured filing creates a longer review cycle, additional information requests, and sometimes a refusal that requires a structural fix before reapplication. Early structuring compresses the overall timeline, even if it delays the application date slightly.
Related at OBOLUS
- Licensing & Registration for Digital-Asset Businesses – comprehensive overview of VASP authorisation across leading hubs
- Economic Substance for Licensed VASPs – substance requirements across jurisdictions for institutional digital-asset operators
- Smart Contract Legal Review in Guernsey – technology-layer legal analysis for digital-asset operations
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. We map the licence stack across operating, custody and payment layers before clients commit — because restructuring after a regulatory review costs more than structuring before one. Our disputes team also coordinates freezing relief and on-chain tracing across leading common-law forums when enforcement matters arise. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com.
FAQ
How long does a crypto licence take to obtain?
Timelines vary significantly by jurisdiction, licence category and application quality. In leading hubs, initial authorisation processes range from a matter of weeks for certain registration-track regimes to several months for full licence applications requiring detailed regulatory review. MiCA CASP authorisation, VARA activity licences and MAS Payment Services Act approvals each have their own statutory timelines that regulators may extend when they require additional information. Pre-filing structuring — a complete, well-prepared application — is the single most effective way to compress the review period.
Which jurisdiction is best for licensing my crypto business?
There is no universal answer. The appropriate jurisdiction depends on the specific activities being licensed, the markets being served, the entity structure, the banking options, and the tax position. EU-facing businesses typically need MiCA CASP authorisation in at least one member state. Businesses serving the Gulf markets may need VARA or ADGM/FSRA authorisation. Singapore and Hong Kong remain the primary authorisation hubs for Asia-Pacific. A licence in any one jurisdiction does not authorise activity in others. The structuring question is which combination of authorisations, entities and substance arrangements best matches the operating model.
Do I need a separate custody licence?
In most leading frameworks, custody is a regulated activity that requires express authorisation — either as a separate licence or as an additional activity within an existing authorisation. Under MiCA, custody and administration of crypto-assets is a defined CASP service requiring specific approval. VARA, the FSRA/ADGM framework, MAS and the SFC each treat custody as a regulated function with its own capital, safeguarding and operational requirements. An exchange licence does not automatically include a custody authorisation. Whether a separate legal entity is required for custody — as opposed to a variation of the exchange authorisation — depends on the specific regime and the operating model.
By Roman Levitt, Technology & DeFi Counsel — specialising in the regulatory architecture of digital-asset platforms, smart contract legal risk, and cross-border licensing strategy for exchanges and protocol operators.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.