Operating a virtual asset service provider (VASP) – an entity providing exchange, custody, transfer or related digital-asset services to third parties – without the correct regulatory authorisation now draws consequences that are swift, public and expensive. Regulators across the EU, the Gulf and Asia-Pacific have moved from guidance to enforcement, and the shift is visible in the volume and profile of recent action. The question for any operator is not whether supervisors are watching, but whether the structure you built will survive the scrutiny that is now routine. This analysis draws on the enforcement posture of the major regimes – MiCA/ESMA, VARA, MAS, the FCA and others – to map what the pattern of recent action tells a licensing applicant about what actually matters at the point of application, and what gets businesses into trouble after authorisation is granted.
A VASP licence application (the formal process for obtaining regulatory authorisation to operate a crypto or digital-asset business) is no longer a box-ticking exercise. Enforcement patterns show that supervisors test the quality of governance, the substance of AML/CFT controls and the reality of cross-border exposure – not just whether a form was filed. Operators who approach the process as an administrative hurdle rather than a substantive risk review consistently face the worst outcomes. The sections below decode what recent enforcement signals, jurisdiction by jurisdiction, and translate those signals into actionable preparation steps.
The Enforcement Shift: From Guidance to Action
Across every major digital-asset hub, the supervisory posture has changed materially over the past several years. Regulators who spent the earlier cycle issuing consultation papers and sandbox invitations are now issuing public censures, withdrawal of registrations and, in some cases, criminal referrals. The FCA's publicly disclosed refusal and withdrawal rate for cryptoasset registrations under the Money Laundering Regulations sits at a level that no applicant can afford to ignore. The pattern in Singapore under the Payment Services Act (MAS's primary framework for digital payment token services) is similar: applicants that failed the fit-and-proper and AML substance tests have had applications rejected or approvals withdrawn after the fact.
What unifies the enforcement actions across jurisdictions is their focus. Supervisors are not primarily catching outright fraud at the application stage – those cases exist, but they are not the dominant pattern. The dominant pattern is institutional insufficiency: governance that looks adequate on paper but cannot demonstrate real decision-making accountability; AML frameworks that were drafted by a consultant, adopted without internal ownership and then not implemented; and technology controls that were described in a policy document but never stress-tested. In our cross-border practice, we consistently see these same three gaps surface across applicants in the EU, the UK and the Gulf.
Under MiCA, ESMA and national competent authorities have made clear that CASP authorisation (the crypto-asset service provider licence that allows passporting across EU member states) will be scrutinised at a level aligned with investment-firm standards. The era of lighter-touch EU VASP registration – which characterised certain member-state regimes in the earlier period – is over. Any operator planning a MiCA application should read the post-authorisation enforcement record of the relevant national competent authority before choosing its home-member state.
To assess whether your current structure meets the substance threshold now expected by supervisors, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity, the user base, the banking – change the analysis. Map your options.
What Supervisors Test at the Point of Application
A VASP licence application is, in substance, a structured argument that the applicant can run a financial-services business safely and lawfully – and that the people in charge are fit to do so. Enforcement patterns make clear what that argument must demonstrate and where it most often fails.
The first test is substance of establishment. Every significant regime – VARA in Dubai, the FSRA in ADGM, the FCA in the UK, MAS in Singapore – requires the applicant to demonstrate that the licensed entity has real operational presence in the licensing jurisdiction. This means qualified staff physically present, local decision-making authority and systems actually operated from that location. Shell-entity applications, in which the licensing jurisdiction is used purely for a regulatory passport while all operations run from elsewhere, are increasingly identified and rejected. VARA's activity-based rulebooks (which cover advisory, broker-dealer, custody, exchange, lending, management and transfer/settlement activities separately) impose entity-level operational requirements that make a hollow-shell approach untenable.
The second test is governance accountability. Regulators want named individuals with defined responsibilities, documented decision trails and board minutes that show real oversight – not a template governance manual. The fit-and-proper assessment for senior managers is now deep in most leading jurisdictions. Financial crime history, civil disputes, prior regulatory censures and, in some regimes, the professional reputation of external advisers all feed into it.
The third test is AML/CFT substance. Under FATF Recommendation 15 (the FATF standard that brings virtual assets and VASPs into the core AML/CFT framework) and its local implementations, an applicant must demonstrate that its AML programme is designed specifically for its business model – not adapted from a generic template. The Travel Rule (the obligation to pass originator and beneficiary identification data with every qualifying transfer) is now a live supervisory expectation across the major hubs, and applications that cannot demonstrate a credible Travel Rule compliance solution are increasingly delayed or rejected.
How Does Cross-Border Exposure Affect a VASP Licence Application?
Cross-border exposure is the single most under-disclosed factor in VASP licence applications, and it is the factor that most often triggers post-authorisation enforcement. An operator whose entity sits in one jurisdiction but whose users, counterparties or banking rails span several others is operating across multiple regulatory perimeters simultaneously. Each jurisdiction in which the operator provides services may assert supervisory jurisdiction over that activity, regardless of where the licensed entity is domiciled.
In our practice, we regularly advise operators who discovered after licensing – sometimes after receiving their first enforcement communication – that the authorisation they held did not cover the full scope of their actual business. A crypto exchange licensed in one EU member state under the transitional MiCA provisions that actively markets to users in a jurisdiction outside the EU/EEA may find that its licensing covers only part of its footprint. A VARA-licensed entity providing services to institutional counterparties established in DIFC-regulated entities has a layered regulatory interface that requires separate analysis.
The cross-border dimension also affects the AML/CFT analysis in ways that applications frequently understate. The jurisdictional source of a customer's funds, the routing of transfers through intermediate wallets in high-risk jurisdictions and the nationality or domicile of beneficial owners all increase the complexity of the AML programme required. Supervisors reviewing an application ask whether the applicant has mapped this exposure and built its compliance framework around the actual risk – not the simplified version of it.
For a business sitting between a Gulf licensing hub and an EU or Asia-Pacific user base, the legal question turns on whether the home-jurisdiction authorisation is sufficient for the full operating footprint, or whether it creates a gap that will eventually be filled by enforcement. Resolving that question before the application is filed is incomparably cheaper than resolving it afterward.
The MFSA, VARA and MAS Approaches Compared
Understanding the differences between major licensing regimes is essential for operators choosing where to establish their primary regulated entity. The MFSA in Malta, VARA in Dubai and MAS in Singapore represent three distinct regulatory philosophies – and the enforcement records of each reflect those differences.
The MFSA's VFA framework, now in MiCA transition, was built around a VFA agent (a locally licensed intermediary who submits the application on behalf of the issuer or service provider and carries professional accountability for its completeness). This structure means that application quality is filtered through a licensed professional before it reaches the regulator. Enforcement under the VFA framework has focused on cases where the agent-applicant relationship broke down – where the agent filed an application that the underlying operator could not substantiate. Under MiCA's CASP regime, Malta aligns to the EU-wide standard and the VFA agent concept gives way to the standard CASP authorisation process.
VARA's activity-based licensing model is more granular than most. Each of the eight regulated virtual-asset activities requires its own regulatory approval, and an operator providing both exchange and custody services must satisfy the requirements for both. VARA's enforcement posture has been notably active in requiring operators to cease and desist from activities not covered by the specific licences held. This activity-level granularity means that scope creep – gradually expanding services beyond the licensed perimeter – is both a common mistake and a well-documented enforcement trigger under the VARA regime.
MAS under the Payment Services Act uses a tiered licence structure (standard payment institution and major payment institution being the primary categories for digital payment token services). The MAS approach is notable for its explicit technology-risk expectations: applicants are assessed on their cyber-security posture, business-continuity plans and technology-outsourcing arrangements. Post-authorisation, MAS has taken supervisory action where those technology controls were found to have deteriorated. Singapore's enforcement record provides strong evidence that the initial application assessment is treated as a baseline, not a ceiling.
Why Do VASP Applications Fail or Get Delayed?
The most common reasons VASP applications fail or are delayed are well-documented in the public enforcement record, and they cluster into a short list. First among them is incomplete or inconsistent disclosure. Regulators conduct independent background checks on all senior managers and beneficial owners. Where those checks surface information that is inconsistent with the application – prior directorships in failed or sanctioned entities, undisclosed civil proceedings, discrepancies in financial history – the application is either paused pending explanation or refused. The remedy is comprehensive disclosure at the outset, not reactive disclosure when the regulator asks.
Second is an AML/CFT programme that is generic rather than business-specific. A programme that was developed for a money-services business and adapted for a crypto exchange, or that addresses on-chain risk in general terms without mapping the specific asset classes and transaction flows of the applicant's business, will not satisfy supervisors who are now experienced enough to identify template documents on sight. In our cross-border practice, we have seen applications stall for months over AML quality issues that a thorough pre-submission review would have resolved in weeks.
Third is inadequate capitalisation evidence. Most leading regimes set minimum own-funds or net-asset requirements that vary by licence category. Applications that cannot demonstrate clear, unencumbered access to the required capital – with documented source-of-funds evidence – stall at the initial completeness check. The capital requirement itself varies by category and jurisdiction, and should always be confirmed from current regulatory guidance rather than any secondary source.
Fourth – and increasingly prominent – is the absence of a credible Travel Rule solution. Supervisors no longer accept an assurance that the operator intends to implement Travel Rule compliance; they want to see the specific technical solution, the counterparty-screening process and the policy for handling transfers where the counterparty VASP is unverified. Operators that apply without a working Travel Rule framework in place face a material risk of rejection or post-authorisation enforcement.
A Cross-Border Enforcement Matter: Lessons from Practice
In a recent licensing engagement, a digital-asset exchange operator held a VASP registration in one European jurisdiction and was expanding its institutional business into the Gulf. The operator had designed its compliance framework around its existing registration and assumed that the regulatory requirements for its new Gulf-facing business would be substantially similar. On review, we identified three gaps: the AML programme did not address the transaction-monitoring expectations specific to the VARA regime; the proposed senior manager for the Gulf entity had an undisclosed prior directorship in a company that had received a regulatory censure in an unrelated sector; and the operator's Travel Rule solution covered only transfers between registered VASPs, leaving a gap for transfers to or from unhosted wallets that Gulf supervisors specifically examine. Addressing those gaps before the application was filed avoided the delay – and the reputational exposure – that a mid-process pause would have caused. The operator received its activity licence without a material information request.
Post-Authorisation Enforcement: The Hidden Risk
Obtaining a licence is not the end of the regulatory risk – and in some respects it is the beginning of the more consequential phase. Post-authorisation enforcement is the fastest-growing category of regulatory action against VASPs, and the reasons are instructive. Supervisors are conducting thematic reviews, routine inspections and transaction-monitoring audits on licensed operators at a frequency that was not common in the earlier period. The quality bar expected at authorisation is the minimum expected throughout the licence lifecycle.
The most common post-authorisation enforcement triggers are: failure to notify the regulator of a material change in business (a new product line, a change in beneficial ownership or the addition of a new regulated activity); deterioration in AML controls after the point of initial approval; and technology or operational failures that breach the availability or security standards committed to in the application. Under MiCA, CASP holders are subject to ongoing reporting obligations that include notification of significant incidents and regular regulatory reporting – obligations that were not uniformly present in the earlier EU VASP registration regimes.
The cross-border dimension amplifies post-authorisation risk. An operator whose business grows organically into new markets, new asset classes or new service lines after licensing may find that its licensed perimeter no longer covers its actual activities. VARA's activity-based structure means that adding a lending product to an exchange operation creates a separate licensing obligation. A MiCA CASP that begins providing services to users in a third country may trigger local regulatory obligations in that country. Continuous licence management – not just initial authorisation – is the operational posture that enforcement patterns recommend.
If a prior application stalled or an authorisation is under review, a second read of the structural gaps can surface the route back. Contact OBOLUS at info@oboluslaw.com or map your options here.
Decision Matrix: Which Operator Profile Needs Which Approach
Not all VASP applicants face the same licensing challenge. The right approach depends on the operator's business model, user base, existing regulatory relationships and risk tolerance – and the enforcement record of the relevant regimes provides clear guidance on where each profile faces the greatest exposure.
Profile A – Start-up exchange, EU user base, no prior regulatory relationship. The primary instrument is MiCA CASP authorisation, obtained through a national competent authority in a member state where the operator can establish genuine substance. The process is typically several months end-to-end, with the main risk concentration at the AML quality and capitalisation stages. The cross-border note: if the operator also plans to serve users outside the EU from day one, it needs a parallel analysis of those jurisdictions before launch, not after.
Profile B – Established Web3 protocol converting to a licensed entity, Gulf presence desired. The primary instrument is VARA licensing (activity-specific), likely beginning with exchange or broker-dealer. The key risk is governance: protocol-native organisations typically lack the formal board structure and documented decision-making that VARA expects. The timeline from initial engagement to licence grant varies by activity category and the completeness of the application package. The cross-border note: if the protocol's technology or liquidity infrastructure is managed from outside the UAE, the substance-of-establishment analysis is the first issue to resolve.
Profile C – Institutional asset manager adding a crypto custody offering. Custody is a separately regulated activity in most leading regimes. A MAS major payment institution licence, a VARA custody licence or a CASP authorisation covering custody services each has distinct capital, safeguarding and technology requirements. The existing institutional compliance infrastructure is an advantage – but it must be supplemented with crypto-specific controls (key management, on-chain monitoring, stablecoin-specific safeguarding) that traditional custodians frequently underestimate. The timeline is generally shorter where existing regulatory relationships are in place, but the substance requirements are not reduced.
Profile D – Operator serving users in multiple regions, currently unregulated. This is the highest-risk profile. An unregulated multi-jurisdictional VASP is simultaneously subject to enforcement risk in each jurisdiction where it provides services. The correct first step is a licensing-gap analysis that maps actual services and actual user jurisdictions against the regulatory perimeter of each relevant regime. In our practice, this analysis routinely surfaces obligations that the operator was unaware of. The sequencing of licence applications – which jurisdiction first, which activities first, how to manage the transition period – is itself a strategic decision with meaningful risk consequences.
A Common Assumption: The Offshore-Licence Myth
A common assumption in the operator community is that a single offshore licence is sufficient to serve clients globally. This assumption is incorrect, and the enforcement record demonstrates it with increasing regularity. An offshore registration – in the BVI under the VASP Act 2022, in Cayman under the applicable VASP provisions, or in an equivalent offshore framework – may satisfy the registration obligation in the issuing jurisdiction. It does not create a regulatory passport for the provision of services to users in regulated markets.
The EU's MiCA regime, the FCA's financial-promotion rules, MAS under the Payment Services Act and VARA under its licensing rulebooks all apply to the provision of services to users or counterparties within their respective perimeters, regardless of where the service provider is incorporated or registered. An operator serving EU retail users from an offshore entity is providing crypto-asset services in the EU for the purposes of MiCA – and the absence of CASP authorisation exposes that operator to the full range of supervisory enforcement available under the regime.
The offshore structure serves a legitimate function in the right context: as the holding entity above a regulated operating subsidiary, as the vehicle for a VC fund that does not itself provide services to retail users, or as the issuer in a jurisdiction with a well-developed token-issuance framework. It does not serve as a substitute for the regulated operating licence. Operators who receive advice suggesting that a BVI or Cayman registration alone is sufficient for a service-providing business should treat that advice as a red flag requiring a second opinion.
Related at OBOLUS
- Licensing and Registration for Digital-Asset Businesses – full-scope VASP and CASP licensing across 70+ jurisdictions
- Crypto Exchange Setup in Liechtenstein – licensing pathway and regulatory framework for exchange operators in Liechtenstein
- Tax Regime for Digital Assets in the UAE (VARA / Dubai) – the Dubai tax environment for VARA-licensed digital-asset businesses
FAQ
How long does a crypto licence take to obtain?
Timelines vary significantly by jurisdiction and licence category. In the major hubs – the EU under MiCA, Dubai under VARA, Singapore under the Payment Services Act – the process typically runs from several months to well over a year, depending on the completeness of the application, the complexity of the business model and the regulator's current queue. Applications with material gaps in AML documentation, capitalisation evidence or senior-manager disclosure consistently take longer. A pre-submission readiness review materially reduces the risk of a mid-process information request that extends the timeline.
Which jurisdiction is best for licensing my crypto business?
There is no universally optimal jurisdiction. The right licensing home depends on where your users are, which activities you provide, your operational substance in candidate locations and your banking and tax priorities. A MiCA CASP authorisation suits an EU-facing operator; VARA suits a Gulf-based or Gulf-targeting business; MAS suits an operator with significant Asia-Pacific institutional business. The wrong question is "which jurisdiction is easiest" – supervisors in all leading hubs now scrutinise substance, and a licence obtained by minimising that substance is a liability, not an asset.
Do I need a separate custody licence?
In most leading regimes, custody of virtual assets is a separately regulated activity. Under MiCA, providing custody and administration of crypto-assets on behalf of clients requires specific CASP authorisation covering that activity. Under VARA, custody is one of the eight separately licensed activity types. Under the MAS Payment Services Act and the SFC's VASP regime in Hong Kong, custody-specific requirements apply. An operator that holds client assets without the relevant custody authorisation – even if it holds a separate exchange or transfer licence – faces a meaningful enforcement exposure. The analysis should always be done by reference to the current applicable regime, not by assumption from a related licence category.
About OBOLUS
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit – and we structure licensing, banking and tax as one mandate rather than three disconnected workstreams. To discuss your situation, contact info@oboluslaw.com or reach us at t.me/oboluslaw.
By Roman Levitt, Technology & DeFi Counsel – specialist in the regulatory treatment of protocol-layer businesses, VASP licensing in multi-jurisdictional structures and the enforcement interface between on-chain architecture and traditional supervisory frameworks.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.