Operating a digital-asset business without the right regulatory authorisation is not a calculated risk – it is an existential one. Enforcement actions, frozen banking rails and reputational collapse follow quickly. For the founders and general counsel now choosing between a CASP authorisation (the Crypto-Asset Service Provider licence created by the EU's Markets in Crypto-Assets Regulation, MiCA) and a Digital Payment Token service licence under Singapore's Payment Services Act, supervised by the Monetary Authority of Singapore (MAS), the decision turns on more than timeline and cost. It turns on where your users are, where your banking lives, and how your product is classified under each regime.
This analysis maps the two regimes across six decision axes – regulator posture, licence categories, application process, AML and Travel Rule obligations, tax and banking interaction, and cross-border reach – then sets out a decision matrix by operator profile. No verdict crowns a winner, because the right answer depends entirely on your structure.
Regulator Posture: How MiCA and MAS Approach the Market
MiCA establishes a single, harmonised authorisation regime administered by national competent authorities coordinated by ESMA, while MAS operates as a single integrated regulator with decades of fintech engagement and a published policy of calibrated access.
The EU approach is legislative in character. MiCA passed into law following years of parliamentary negotiation, and its requirements are embedded in binding regulation applying uniformly across all member states. A CASP authorised in, say, Ireland or Lithuania may passport that authorisation across the entire EU and EEA without seeking fresh approval in each member state. The scope is broad: it covers exchange, brokerage, custody, portfolio management, transfer, reception and transmission of orders, and more. Each activity category carries its own capital floor, governance expectation and conduct standard. The whitepaper obligation – which requires a standardised disclosure document for tokens offered to the public – adds a layer with no direct equivalent in Singapore.
MAS approaches regulation through the Payment Services Act and its licensing tiers. The framework is outcomes-focused and has been refined through several rounds of consultation. MAS is known for its willingness to engage applicants before submission and to provide substantive feedback during review. In our cross-border practice, we have seen that pre-application engagement with MAS can substantially clarify the scope of required disclosures and the substance of governance expectations. That said, MAS has tightened admission criteria meaningfully over recent years, and the proportion of applications approved relative to those initiated is not disclosed – but the practical bar is high.
The posture difference is consequential. MiCA demands legal compliance with a dense text and with national implementation measures that vary at the margin. MAS demands demonstrated substance, local management and a credible business plan, assessed by a regulator with considerable discretionary latitude. Neither is permissive.
For a business whose primary user base is in Europe, MiCA authorisation is not merely preferable – it is, for most retail-facing activities, legally required. For a business whose user base is in Asia-Pacific, or which requires a common-law seat with strong contract-enforcement infrastructure, Singapore is a more natural anchor.
What Licences Are Available – and What They Actually Cover?
Under MiCA, the CASP authorisation covers a defined list of crypto-asset services; under Singapore's Payment Services Act, Digital Payment Token services are the primary regulated category for crypto businesses, with the licence tier – standard payment institution or major payment institution – determined by transaction volume thresholds.
MiCA's service catalogue is exhaustive by design. If your business performs any of the enumerated activities for clients in the EU, you need authorisation. Custody of crypto-assets on behalf of third parties is a standalone regulated service. Operating a trading platform is regulated. Providing advice on crypto-assets is regulated. The token-issuance side is addressed through distinct obligations for asset-referenced tokens (ARTs) and e-money tokens (EMTs), both of which require authorisation from an NCA and compliance with reserve, redemption and disclosure requirements. Utility tokens and other crypto-assets are addressed through the general whitepaper regime.
Singapore's Payment Services Act covers DPT services: buying and selling digital payment tokens, facilitating the exchange of DPTs between parties, and transferring DPTs. Custody of DPTs is addressed through the regulatory framework but is not, as of the current regime, a separately licensed activity in the same way it is under MiCA – though regulatory expectations on safeguarding are substantive and evolving. Funds managing crypto-assets may be regulated under the Securities and Futures Act rather than the Payment Services Act, depending on the nature of the assets.
The implication for a multi-product business is immediate. An exchange that also offers custody, staking and a token product may need to disaggregate its activities under MiCA and ensure each is authorised. In Singapore, the same business may find the Payment Services Act sufficient for the core exchange and transfer functions, with funds activity addressed separately. Neither regime permits a single authorisation to cover all activities without scrutiny of what, precisely, each activity involves.
How Does the Application Process Compare?
The MiCA CASP application is filed with the national competent authority of the member state in which the applicant is legally established; MAS applications are filed directly with MAS in Singapore, with no equivalent passporting mechanism available at the point of application.
Under MiCA, the NCA has a defined review period after receiving a complete application. That period is set by the regulation itself, though the practical timeline from initial engagement to authorisation varies by NCA, applicant readiness and the complexity of the business model. Lithuania and Malta are frequently discussed as member states with developed regulatory infrastructure for crypto businesses and some prior experience processing VASP applications that preceded MiCA. Irrespective of the chosen member state, the applicant must demonstrate genuine establishment – local directors, substance, a registered office, not a brass plate.
MAS reviews applications in a process that is formally open-ended in timeline. In our practice, we have observed that applications with well-prepared governance documentation, a credible technology risk framework and locally resident management move through review materially faster than those submitted before the substance is in place. MAS publishes its licensing requirements and conducts formal fitness-and-propriety assessments of key personnel. The review of shareholders with significant interests – typically defined by reference to a percentage threshold – is detailed.
A common mistake at the application stage in both jurisdictions is underestimating the AML program documentation burden. Both MiCA and the MAS regime require a comprehensive written AML/CFT program aligned with FATF standards, including a documented Travel Rule compliance framework (the obligation, under FATF Recommendation 15, to transmit originator and beneficiary information alongside virtual asset transfers). Submitting a generic AML policy is a reliable way to draw a request for further information and to extend the review clock by months.
In both regimes, substance is the threshold question. A shell entity with a remote compliance officer and a nominee director will not pass. Local management, a functioning compliance infrastructure and a credible team are expectations, not optional extras.
The process above describes the standard path. Your facts – the entity structure, the user base, the banking relationships – change the analysis materially. For a scoped assessment of where your application stands before you file, contact OBOLUS at info@oboluslaw.com.
AML, Travel Rule and Ongoing Compliance Obligations
Both MiCA and the MAS regime impose FATF-aligned AML/CFT obligations, including Travel Rule compliance for virtual asset transfers above the applicable threshold – but the implementing rules and supervisory culture differ in ways that matter operationally.
Under MiCA, AML/CFT obligations are not technically housed in MiCA itself – they arise under the EU's anti-money-laundering directives and, going forward, the EU AML Regulation, which is being revised to apply directly to CASPs. National competent authorities responsible for CASP authorisation may or may not also be the AML supervisory authority, depending on how each member state has allocated supervisory functions. This split can create dual reporting obligations and dual examination risk. CASPs subject to EU law must apply the Travel Rule in accordance with the Transfer of Funds Regulation, which extends to crypto-asset transfers and sets out the information requirements.
In Singapore, MAS is both the licensing authority and the AML supervisor for DPT service providers. This consolidation simplifies the supervisory relationship. MAS's Notice on Prevention of Money Laundering and Countering the Financing of Terrorism sets out the detailed obligations. The Travel Rule obligations apply to DPT transfers, with MAS having published guidance on implementation. The MAS approach to AML examination tends to be detailed and document-intensive, with inspectors who understand both the regulatory standard and the on-chain mechanics.
In our cross-border practice, businesses licensed in Singapore and serving clients in the EU face a compound obligation. The MAS licence covers the Singapore nexus; but if those European clients are accessing a service that constitutes a regulated crypto-asset service under MiCA, the EU nexus may independently trigger a requirement for CASP authorisation. The assumption that one licence covers all client geographies is the most common structural mistake we encounter.
Tax and Banking: The Hidden Variables
Licensing analysis that ignores tax treatment and banking access is incomplete; a regulated business that cannot open accounts or faces an unexpected tax burden on its token transactions is not a viable business.
Singapore's tax treatment of digital-asset businesses is generally regarded as clear and commercially rational. The Inland Revenue Authority of Singapore (IRAS) has published guidance on the income tax treatment of digital tokens. GST treatment of DPT transactions has also been addressed in official guidance. Specific rates and thresholds are jurisdiction-specific and require current legal advice, but the overall environment has been described by operators across our practice as a meaningful positive factor in the decision to establish in Singapore.
Within the EU, tax treatment is not harmonised by MiCA and varies by member state. A CASP authorised in Lithuania operates under Lithuanian tax law; one authorised in Malta operates under Maltese tax law. The absence of EU-level harmonisation means that the choice of NCA and therefore the choice of member state for establishment has direct tax consequences. VAT treatment of crypto services, the tax characterisation of staking rewards and the treatment of token swaps differ materially across member states. These differences belong inside the licensing decision, not after it.
Banking access is a live operational challenge in both environments. EU-licensed crypto businesses have experienced account closures and de-risking from traditional banks, though the situation has improved as larger institutions develop crypto-specific onboarding policies. EMI (electronic money institution) accounts and bank accounts through crypto-friendly institutions in jurisdictions such as Lithuania, Estonia and Malta are available but require disclosure of the licence status, the business model and the client base.
Singapore-based crypto businesses face similar dynamics. MAS has encouraged banking access for licensed entities, and the largest Singapore banks have developed frameworks for onboarding regulated DPT service providers, though the process involves detailed due diligence. Unlicensed or licence-pending entities face a materially harder access challenge.
What Is the Cross-Border Reach of Each Licence?
The single most decisive differentiator between the two regimes, from a commercial standpoint, is the EU passport available under MiCA – a benefit with no equivalent in Singapore's framework.
A CASP authorised under MiCA in any EU member state may, after completing a straightforward notification process, provide its services to clients across all EU and EEA member states without seeking separate national authorisation in each. For a business whose market is Europe, this is the primary structural advantage of the EU route. The cost and complexity of managing 27 separate national licensing processes is replaced by a single authorisation with a notification mechanism for cross-border activity.
Singapore's Payment Services Act licence applies to the provision of DPT services in Singapore. It does not confer rights to operate in other jurisdictions. A business licensed in Singapore that also serves clients in the EU, Hong Kong or Australia must independently satisfy the regulatory requirements of those jurisdictions. Operators we advise frequently underestimate this. The Singapore licence is a credible reputational signal – MAS's stringent admission criteria are internationally recognised – but it is not a passport.
For businesses targeting Asia-Pacific markets, Singapore's licence is the natural anchor. MAS's reputation carries weight with regulators in Hong Kong, Australia and Japan. For businesses whose primary market is Europe or who intend to raise institutional capital from European investors, a MiCA-authorised entity in an appropriate member state is typically the required structure.
A business serving both markets typically needs both – or a carefully designed group structure with a MiCA entity for European activities and a Singapore-licensed entity for Asia-Pacific activities, with intra-group service arrangements that themselves require legal review.
If a prior application stalled or a banking relationship was closed, a second structural read often surfaces the underlying cause and the route back. Write to OBOLUS at info@oboluslaw.com to discuss the options.
Which Jurisdiction Fits Which Operator Profile?
No single jurisdiction is optimal for all digital-asset businesses; the right choice follows from the operator's market, product, team location and capital position.
Profile A – Exchange serving European retail clients. A CASP authorisation under MiCA, filed with the NCA of an operationally appropriate member state, is effectively required. The passport covers EU distribution. The key risks are the substance requirement and the AML complexity of a dual-supervisor environment. Timeline from a well-prepared application to authorisation is a matter of months, not weeks. Capital requirements vary by the specific services to be authorised and must be confirmed against current implementing measures.
Profile B – Custody-focused business targeting institutional clients globally. Singapore is often the preferred primary seat, given MAS's credibility with institutional counterparties, the common-law contract environment and the availability of competent local legal and compliance infrastructure. If the institutional client base includes EU funds or regulated entities, a secondary MiCA-authorised entity may be required to avoid onboarding friction. Timeline and capital again vary by the specific service scope.
Profile C – Token issuer conducting a public offer to EU persons. MiCA applies regardless of where the issuer is incorporated. A whitepaper meeting MiCA requirements must be published, and depending on the token classification (ART or EMT), NCA approval may be required before the offer can proceed. A Singapore-based issuer offering tokens into the EU cannot avoid MiCA through geographic distance. This is one of the more frequently misunderstood aspects of the regulation.
Profile D – Fund investing in digital assets, managing EU or Singapore-resident capital. The MAS regime may bring the fund within the scope of the Securities and Futures Act rather than the Payment Services Act if the assets are securities tokens. EU funds face AIFMD obligations overlaid with MiCA for any service-layer activities. In our practice, fund structures require a layered analysis of fund regulation, VASP or CASP obligations, and tax treatment before the structure is committed.
Profile E – Early-stage business, limited capital, seeking a rapid first licence. The EU member state route can be faster to a first authorisation than the MAS process for certain business models, particularly for exchange and transfer services. Lithuania and Malta have developed competent regulatory teams with experience reviewing crypto business models. However, "fastest" and "most appropriate" are not synonyms; a licence obtained in haste without adequate substance will attract supervisory attention quickly.
A common assumption among early-stage founders is that a single offshore registration – in the BVI, Cayman Islands or elsewhere – is sufficient to serve clients globally without further licensing. It is not. Offshore registration addresses the entity's home-jurisdiction obligations, not the obligations triggered by the location of the clients. A BVI-registered business with European retail users faces MiCA obligations. A Cayman fund with Singapore-resident investors faces MAS scrutiny. The reach of major regulatory regimes is defined by the location of the client, not the flag of the operator.
Related at OBOLUS
- Licensing and Registration for Digital-Asset Businesses – the full practice overview across 70+ jurisdictions
- VARA Licence Application for Early-Stage Founders – Dubai VARA licence process and requirements for new entrants
- De-Risking and Account Closure Defence in Turkey – managing banking access challenges across borders
FAQ
How long does a crypto licence take to obtain?
Timeline varies by jurisdiction, business model and the state of the application at submission. Under MiCA, the NCA review period is defined by the regulation itself, though total elapsed time from first engagement to authorisation typically runs to several months. MAS does not publish a defined review period; in practice, well-prepared applications with complete governance documentation and local substance in place move faster than those that are not. In both regimes, incomplete applications or weak AML documentation extend the clock materially.
Which jurisdiction is best for licensing my crypto business?
There is no universal answer. For a business serving European retail clients, MiCA authorisation in an EU member state provides the necessary passport and is, for most activities, legally required. For a business targeting Asia-Pacific institutional clients, Singapore is generally the preferred primary seat. A business serving both markets typically requires entities in both regimes. The right structure follows from the product, the user geography, the capital position and the banking relationships – not from a general ranking of jurisdictions.
Do I need a separate custody licence?
Under MiCA, custody of crypto-assets on behalf of third parties is a separately enumerated regulated service requiring CASP authorisation. A business performing custody alongside exchange or transfer services must ensure its authorisation covers each activity. In Singapore, the Payment Services Act addresses DPT services including custody-related functions, but the licensing scope and conditions differ from MiCA's. In both regimes, holding client assets without the appropriate authorisation carries enforcement risk. The precise scope requires analysis of the specific activities performed and the applicable regulatory provisions.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. We map the licence stack across operating, custody and payment layers before you commit – so the structure is sound before the application is filed. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com or reach us via t.me/oboluslaw.
By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in cross-border CASP and VASP authorisation strategy across EU and Asia-Pacific regulatory regimes.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.