EST · MMXXVI
Home/Jurisdictions/Ireland/Crypto exchange setup in Ireland: Legal Requirements for Businesses
Licensing & Registration

Crypto exchange setup in Ireland: Legal Requirements for Businesses

Crypto exchange setup in Ireland. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

Operating a crypto exchange in Ireland without the correct regulatory registration exposes the business to enforcement action, disrupted banking and potential criminal liability under Irish anti-money-laundering law. The Central Bank of Ireland (CBI) supervises virtual asset service providers (VASPs) – businesses that exchange, transfer, custody or administer virtual assets – under a registration regime grounded in the EU's anti-money-laundering directives and, increasingly, the expectations of MiCA (the EU's Markets in Crypto-Assets Regulation, which brings a full harmonised authorisation standard for crypto-asset service providers across the EU/EEA). This page sets out what an inbound operator must know before committing to Ireland as a base: the regulatory perimeter, the CBI process, the cross-border reality, and the decision point at which legal counsel changes the trajectory of an application.

What Activities Require Registration or Authorisation in Ireland?

Any business operating as a VASP in Ireland – or marketing virtual-asset services into Ireland from abroad – must either hold a CBI registration or qualify for an express exemption. The Irish regime, administered by the Central Bank of Ireland under the Criminal Justice (Money Laundering and Terrorist Financing) Acts, requires registration before a VASP commences activities. Covered activities include exchange between virtual assets and fiat currencies, exchange between virtual assets, transfer of virtual assets, custody and administration of virtual assets, and the provision of financial services related to an issuer's offer or sale of a virtual asset. Operating outside that perimeter without registration is a criminal offence.

The scope is deliberately broad. A business that routes order flow through an Irish entity, employs staff in Dublin, or simply holds itself out to Irish customers may fall within the supervised perimeter regardless of where its servers sit. The CBI has been explicit that substance in Ireland – directors, decision-making, customer-facing activity – is determinative. Remote arrangements do not cure the registration gap.

With MiCA now progressively applying across the EU, operators seeking a CASP authorisation (crypto-asset service provider, the MiCA licence category) via Ireland will eventually operate under a passport that covers all EU/EEA member states. That passporting dimension makes the Irish option structurally attractive for businesses targeting the EU market. But the transition timetable and the CBI's current supervisory posture mean the near-term path is the existing AML-based VASP registration, layered with MiCA readiness planning.

The process above describes the standard path. Your facts – the entity structure, the user base, the banking arrangements – change the analysis materially. For a scoped assessment of your Irish registration obligations, contact OBOLUS at info@oboluslaw.com or map your options here.

How Does the CBI VASP Registration Process Work?

Registration with the Central Bank of Ireland requires a formal application demonstrating that the business has adequate AML/CFT controls, a fit and proper management team, and sufficient operational substance in Ireland. The application is document-intensive. The CBI expects a detailed business plan, an AML/CFT risk assessment, policies and procedures aligned with Irish AML legislation, and complete fit-and-proper profiles for each beneficial owner, director and senior manager.

The assessment is not a tick-box exercise. The CBI scrutinises the genuineness of the Irish presence. A brass-plate entity with no local decision-making will not satisfy the substance test. In our practice, we regularly advise operators who underestimate this requirement. An experienced team on the ground, a credible compliance officer and a governance structure that reflects where the business actually operates are baseline expectations, not optional enhancements.

Timeline varies by the completeness of the application and the CBI's current case load. Operators should plan for a process measured in months, not weeks, from submission of a complete file. The CBI may issue a request for further information – each such round adds time. Businesses that submit prematurely, before the AML framework is fully built, routinely extend the process significantly. We have seen applications that were conceptually sound but procedurally incomplete add months of delay at this stage.

For businesses planning to use Ireland as the EU passporting hub under MiCA, the VASP registration is a staging step toward the fuller CASP authorisation. Early engagement with the CBI – before the formal application – is standard practice in the leading EU licensing hubs and is something the CBI itself has signalled it welcomes. A pre-application meeting can surface objections early and allow the operator to address them before the clock starts on the formal review.

What AML and Travel-Rule Obligations Apply to Irish VASPs?

Irish VASPs operate under the Travel Rule – the obligation, derived from FATF Recommendation 15, to pass originator and beneficiary information alongside virtual-asset transfers above a defined threshold. Compliance requires both technical infrastructure (a Travel-Rule-compliant messaging solution interoperable with counterpart VASPs) and a legal framework governing what the VASP does when a counterpart cannot be identified or is unhosted. The CBI expects a documented Travel-Rule compliance programme as part of the registration file.

Beyond the Travel Rule, Irish VASPs must conduct customer due diligence aligned with the EU's AML framework, file suspicious-transaction reports with the Financial Intelligence Unit of An Garda Síochána, and maintain records for the required retention period. The AML obligations are not light. They mirror the standard applied to regulated financial institutions. Compliance costs – particularly for businesses onboarding high-volume retail customers – are material and must be modelled before committing to the Irish structure.

Cross-border complexity arises when the Irish entity transacts with VASPs in jurisdictions where Travel-Rule standards differ or where counterpart identification is impractical. Operators we advise build a tiered counterpart-management policy that distinguishes regulated-hub VASPs from others and applies enhanced due diligence to the latter. The CBI's supervisory focus on AML makes this not a theoretical concern but a live inspection point.

How Does the Cross-Border Structure Affect the Irish Entity?

For a business that sits between Ireland and a non-EU hub – Dubai, Singapore, the BVI – the Irish entity typically plays one role in a multi-entity structure, and that role must be defined precisely. The Irish VASP might hold the EU customer-facing licence while a VARA-licensed entity in Dubai serves MENA customers and a separate custodian holds assets. Each entity must be independently compliant with its home regime, and the group's intercompany arrangements – fee flows, data sharing, order-routing agreements – must not create a regulatory gap in any jurisdiction.

Banking is the operational pressure point. Irish VASPs interact with the Irish banking system, which means EU payment-service-provider rules apply to fiat on/off-ramps. Securing a banking relationship for a VASP in Ireland is achievable but requires a credible compliance posture: a complete AML programme, a registered status (or clear registration timetable), and a transparent business model. Banks in Ireland have declined to onboard VASPs that could not demonstrate regulatory standing, even where the underlying business was legitimate. Registration is a prerequisite, not a follow-on.

Tax is a separate but interrelated workstream. Ireland's corporation-tax regime is well-known. The interaction with a VASP business – where revenue streams include trading fees, staking rewards, OTC spreads and proprietary positions – requires analysis of how each stream is characterised. Mischaracterisation of income at the entity level can create unexpected tax exposures. The Irish Revenue Commissioners have issued guidance on the taxation of crypto-asset activities, and compliance with that guidance is part of the overall structuring exercise.

If a prior application stalled or a banking relationship was closed, a structural review can surface the cause and identify the route back. Write to OBOLUS at info@oboluslaw.com or open a conversation here.

How Does MiCA Change the Irish Licensing Picture?

MiCA represents the most consequential shift in EU crypto regulation since the AML directives extended to virtual assets. Under MiCA, a CASP authorisation replaces the patchwork of national registrations with a single harmonised licence that passports across the EU/EEA. For a business that wants EU-wide reach from a single entity, that passport is the primary structural argument for a MiCA-hub strategy – and Ireland is a credible candidate hub.

The CBI, as the Irish national competent authority, will be the authorising body for CASPs incorporated in Ireland. The ESMA technical standards and guidelines that accompany MiCA set out the content expectations for CASP applications in detail: governance requirements, capital adequacy by activity class, client-asset safeguarding rules, operational resilience standards, and disclosure obligations. These are materially more demanding than the current VASP registration. Operators that treat VASP registration as the endpoint and MiCA compliance as a future problem will face a disruptive uplift when the transition timetable crystallises.

In our cross-border practice, we structure Irish applications from the outset against MiCA's CASP standard – building governance frameworks, compliance programmes and capital structures that will satisfy both the current CBI registration and the forthcoming CASP authorisation. That approach avoids the cost and disruption of a two-stage rebuild and gives the operator a credible MiCA-readiness narrative to present to institutional counterparts and banking partners now.

Which Operator Profile Is Best Suited to the Irish Route?

The Irish route suits a defined set of operator profiles, and it is not the right answer for every business. Understanding which profile applies shapes the structure, the timeline and the risk budget.

Profile A – the EU-passporting exchange: A business targeting retail or institutional customers across multiple EU/EEA member states needs a single CASP authorisation under MiCA or an interim VASP registration. Ireland offers English-language supervision, a common-law legal environment and a well-developed financial-services infrastructure. The process is demanding but the outcome – EU-wide access – justifies the investment for operators of sufficient scale. Timeline to registration, assuming a complete file, is measured in months; MiCA CASP authorisation will take longer.

Profile B – the fintech holding company: A group already operating in Ireland for fintech or payments reasons may add a VASP registration to an existing regulated entity or a closely related affiliate. The CBI will assess the new activity on its merits, but an established relationship with the regulator and an existing compliance infrastructure can shorten the preparation phase materially.

Profile C – the early-stage token issuer: A business issuing tokens to EU investors under MiCA's whitepaper regime may not need a full CASP authorisation for the issuance itself, but any ongoing secondary-market or exchange functionality triggers the VASP/CASP requirement. Conflating the token-issuance rules with the exchange rules is a recurring structural error. They are distinct regulatory obligations.

Profile D – the offshore operator testing EU access: A BVI or Cayman entity seeking to onboard EU customers without an EU presence will not be able to rely on an offshore structure for MiCA-covered activities directed at EU users. The extraterritorial reach of MiCA – services provided to EU clients by non-EU entities – means the choice is to establish in the EU or to ring-fence EU clients. Ireland is one of the cleaner paths to the former.

A Recent Cross-Border Application: Turning a Stalled File into a Registered VASP

In a recent licensing matter, a payments technology company incorporated in two jurisdictions – one inside the EU, one outside – sought VASP registration in Ireland to consolidate its EU customer-facing activity into a single regulated entity. The application had been prepared in-house and submitted without a pre-application engagement with the CBI. The regulator's initial response flagged gaps in the AML risk assessment, an incomplete fit-and-proper file for two senior managers, and an absence of a documented Travel-Rule compliance programme. We were retained to conduct a structural review of the submission. We rebuilt the AML framework, prepared the missing governance documents and facilitated a pre-submission meeting with the CBI. The application was resubmitted with a complete file and registration was achieved within the following quarter. The operator then used the registered Irish entity to open a banking relationship it had previously been unable to secure.

What Are the Most Common Mistakes in Irish VASP Applications?

The single most common mistake is submitting before the compliance infrastructure is built. The CBI's review is substantive. An application that arrives without a complete AML/CFT policy suite, a credible compliance officer and a fit-and-proper file for every beneficial owner and senior manager will generate an information request. Each round of requests extends the timeline and signals to the regulator that the applicant is not ready.

The second most common error is treating the Irish registration as isolated from the broader group structure. Regulators ask: who owns this entity, who controls it, and where does the money flow? An Irish subsidiary of an opaque offshore group will face deeper scrutiny than a clean structure with transparent beneficial ownership. Building the structure for transparency before applying – not after – is materially easier.

A common assumption is that a single offshore licence or an EU registration in one member state automatically covers all relevant activities and jurisdictions. It does not. MiCA passporting covers EU/EEA-authorised CASP activities directed at EU/EEA clients. Activities directed at clients outside the EU, or activities not covered by the CASP authorisation, require separate regulatory analysis. We map the full activity matrix – exchange, custody, transfer, staking, lending – against the relevant regime in each jurisdiction before the structure is finalised. That mapping frequently reveals gaps that a single-licence approach would leave open.

Related at OBOLUS

FAQ

How long does a crypto licence take to obtain?

Timeline varies by jurisdiction, regulator and the completeness of the application file. In Ireland, VASP registration with the Central Bank of Ireland typically takes several months from submission of a complete file. Incomplete applications extend that window materially through requests for further information. Under MiCA, a full CASP authorisation will involve a longer substantive review. Pre-application engagement with the regulator is standard practice and generally reduces overall elapsed time.

Which jurisdiction is best for licensing my crypto business?

There is no universal answer. The right jurisdiction depends on the operator's target market, activity profile, ownership structure, banking needs and growth horizon. Ireland suits EU-facing exchanges seeking MiCA passporting access. Dubai's VARA regime suits businesses targeting MENA markets. Singapore's MAS Payment Services Act suits operators building in South-East Asia. We assess each of those axes before recommending a licensing path, rather than defaulting to a single hub.

Do I need a separate custody licence?

Custody of virtual assets is a regulated activity in most leading regimes, including under the Irish VASP framework and MiCA's CASP authorisation. An exchange that also holds client assets – whether on a combined platform or through a related entity – generally needs the custody activity to be covered by its own regulatory authorisation. Operating an exchange and a custody function under a single authorisation is possible in some regimes; in others, a separate licence or a distinct regulatory condition applies. The answer is fact-specific and turns on how client assets are held and controlled.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around each engagement. We structure licensing, banking and tax as one mandate rather than three disconnected workstreams – mapping the licence stack across operating, custody and payment layers before you commit. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com or message us at t.me/oboluslaw.

By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in VASP and CASP authorisation strategies for inbound operators across EU and common-law jurisdictions.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours