VARA Licence Application in Singapore: Legal Requirements for Businesses
A digital-asset business expanding into Singapore quickly discovers that the regulatory question is not simply whether to apply – it is which payment-service licence category applies, what the Monetary Authority of Singapore (MAS) expects at the point of application, and how that licence interacts with the entity's banking, custody and tax posture elsewhere. Operating without the right authorisation exposes the business to enforcement action, frozen payment rails and the loss of correspondent banking relationships that took months to build. The cost of getting this wrong is not theoretical. MAS has acted against unlicensed operators, and the downstream consequences – account closures, reputational damage, regulator scrutiny in other hubs – compound quickly.
Singapore's licensing regime for digital-asset businesses sits within the Payment Services Act (the PSA), administered by MAS. A business providing digital payment token (DPT) services – buying, selling, exchanging or facilitating the transfer of cryptocurrencies – must hold a valid licence under the PSA before operating. The regime is layered: a standard payment institution licence and a major payment institution licence apply at different transaction thresholds, and a DPT service licence sits alongside other regulated payment-service activities. This page sets out the legal requirements, the application process, the cross-border interactions that matter most to an inbound operator, and the decision points that define whether Singapore is the right primary hub for your build.
Who Needs a Licence Under the Payment Services Act?
Any person carrying on a business of providing a DPT service in Singapore – or where the solicitation, marketing or onboarding of Singapore-resident customers is involved – must hold a licence issued by MAS under the Payment Services Act. The scope is broader than many operators assume. The activity-based definition means that an entity incorporated offshore but actively serving Singapore customers will likely fall within the MAS perimeter, regardless of where its servers sit or where the contracting entity is registered.
MAS distinguishes three licence tiers under the PSA: a money-changing licence (narrow, FX-only); a standard payment institution (SPI) licence, available to businesses operating below specified transaction-volume thresholds; and a major payment institution (MPI) licence, required once a business crosses those thresholds or carries a broader suite of payment-service activities. DPT service providers typically enter via the SPI or MPI track. The specific volume thresholds that separate SPI from MPI classification are set by the MAS and are subject to periodic review – operators should confirm current thresholds directly with MAS or with counsel before structuring their entity.
A business that holds an Exemption Notice under the transitional provisions introduced when the PSA first came into force is not permanently exempt. MAS has made clear that transitional protection does not constitute ongoing authorisation. Any business operating under a legacy exemption must assess whether its activities require a full PSA licence under current law.
What Does the MAS Application Process Involve?
The MAS licensing process for DPT service providers is detailed, documentation-intensive and requires the business to demonstrate substance in Singapore before approval is granted. MAS assesses the applicant's fit-and-proper status, its financial soundness, the adequacy of its AML/CFT controls and the competence of its senior management – not just its compliance team.
At a structural level, MAS expects a locally incorporated entity with resident directors who have genuine oversight responsibility. Nominee directors without operational authority do not satisfy this expectation. The business plan submitted at application must address the specific DPT activities to be conducted, the anticipated customer profile and volume, the technology architecture and the safeguarding model for customer assets.
The AML/CFT documentation package is substantial. MAS expects a customer due-diligence policy, transaction-monitoring procedures and a Travel Rule compliance framework – the Travel Rule being the obligation to pass originator and beneficiary data with virtual-asset transfers, consistent with FATF Recommendation 15. Singapore has implemented the Travel Rule with specific threshold requirements; businesses must demonstrate that their technology stack can meet those obligations at the point of application, not retrospectively. The current de-minimis threshold for Travel Rule compliance in Singapore should be confirmed against the current MAS Notice on PSA, as MAS has updated these requirements over successive issuances.
MAS also expects disclosure of all material relationships – parent entities, beneficial owners, group companies and any shared technology or compliance infrastructure. For an inbound operator with a group structure spanning multiple jurisdictions, this means the MAS application file will reference entities in, say, the BVI, the Cayman Islands or a European licensed entity. Each cross-jurisdictional relationship requires a narrative explanation and, in many cases, supporting documentation from the foreign regulator or corporate records from the relevant jurisdiction.
To map the MAS application requirements against your specific entity structure, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity, the user base, the banking stack – change the analysis materially.
How Long Does the MAS Licensing Process Take?
The MAS review process for a DPT service licence is not a matter of weeks. In our practice, we observe that well-prepared applications – those submitted with a complete documentation package, a clear business plan and a resolved entity structure – move more predictably than applications submitted speculatively. MAS does not publish a fixed processing timeline, and the regulator has significant discretion to request supplementary information, which resets the clock on practical review timelines.
Operators we advise routinely underestimate the pre-submission preparation window. Building the AML/CFT framework, appointing qualified resident directors, establishing a local bank account and preparing a compliant Travel Rule implementation takes time. The submission-ready state is not the same as the incorporated-entity state. Businesses that attempt to compress the pre-application phase typically face avoidable requests for information during review.
The formal review period – from a complete submission to a determination – can span several months, and MAS may conduct interviews with proposed key personnel before granting approval. Building this into the project timeline, alongside the parallel work of establishing Singapore banking and operational infrastructure, is essential. A conservative planning assumption for the full licensing cycle, from pre-submission preparation through to licence issuance, is typically measured in months rather than weeks.
How Does a Singapore Licence Interact With Cross-Border Operations?
A Singapore MAS licence does not provide passporting to other jurisdictions – unlike a MiCA CASP authorisation, which allows an EU-authorised entity to operate across all EU/EEA member states. A business holding a Singapore DPT service licence and also serving customers in the UAE, the UK or the EU must hold separate regulatory authorisation in each relevant jurisdiction, or structure its operations so that the regulated activities in each territory are appropriately licensed or exempt.
For many inbound operators, Singapore serves as the Asia-Pacific hub in a multi-hub structure. In our cross-border practice, we regularly advise businesses that hold – or plan to hold – a Singapore PSA licence alongside a VARA licence in Dubai and a CASP authorisation under MiCA in an EU member state. Each licence governs a defined perimeter of activities and customers. The interaction between those perimeters – which entity contracts with which customer, where the regulated activity occurs and where the economic substance sits – is the legal design question that determines whether the group structure holds under scrutiny.
Tax treatment follows the structural choices. A Singapore operating entity may benefit from Singapore's corporate tax regime and its extensive tax treaty network, but the intercompany arrangements that flow from a multi-hub structure require transfer-pricing analysis. Where MAS-licensed activities generate fee income that is also subject to analysis under a foreign tax authority's permanent-establishment rules, the entity design work and the licensing work must be aligned from the outset.
Banking is the practical constraint that shapes structure as much as regulatory design does. Singapore-licensed entities can generally access Singapore-based banks with digital-asset policies, but correspondent banking for crypto businesses remains selective globally. Operators should not assume that a Singapore MAS licence unlocks banking in every jurisdiction where the group operates. Each banking relationship requires its own assessment, and some banks distinguish between exchange businesses, custodians and stablecoin-adjacent models in their onboarding criteria.
Does a Singapore Licence Cover Custody of Customer Assets?
Custody of customer digital assets is a regulated activity in Singapore, and a DPT service licence does not automatically authorise all custody arrangements. MAS has imposed specific safeguarding requirements on DPT service providers: customer assets must be held separately from the firm's own assets, and the safeguarding model must be documented and disclosed to customers. The applicable MAS Notice sets out the specific obligations, and operators must ensure their custody architecture – whether in-house or via a third-party custodian – satisfies those requirements.
For businesses that intend to offer standalone custody as a distinct revenue line – rather than simply safeguarding assets as an incident of their trading or exchange activity – the regulatory analysis may lead to a broader PSA activity scope or, depending on the asset types, to additional authorisations. This is a structural question that must be resolved before the application is submitted, not after the licence is granted. Adding regulated activities to a PSA licence post-issuance requires MAS approval and restarts elements of the review process.
In a recent licensing matter, a digital-asset trading platform sought to expand its Singapore MAS authorisation to include customer-asset safeguarding as a distinct service line. We identified that the proposed custody model required a change to the entity's AML/CFT risk framework and a revision to its customer-disclosure materials, in addition to the regulatory variation application. Addressing those issues in parallel – rather than sequentially – reduced the overall time to approval.
What Are the Most Common Mistakes in Singapore Crypto Licensing?
The most frequent failure point we observe is submitting a technically complete application with an entity that lacks genuine Singapore substance. MAS is not looking for a shell. The regulator expects a business that operates in Singapore, employs or retains qualified personnel there and has a compliance function with access to management. An application that cannot demonstrate this – however polished the documentation – will stall at the management-interview stage or face a formal objection to proposed key personnel.
A second recurring issue is the Travel Rule gap. Operators that build a compliant AML/CFT framework for their onboarding and monitoring obligations but do not simultaneously implement a technology solution for Travel Rule compliance will face a deficiency finding. MAS has been explicit about this expectation. The Travel Rule is not a post-licensing obligation – it is a pre-condition to demonstrating AML readiness at application.
A common assumption among operators entering Singapore is that a well-established offshore licence – from the BVI, the Cayman Islands or an earlier EU VASP registration – provides a credibility shortcut with MAS. It does not. MAS conducts its own assessment of fit-and-proper status and regulatory standing. A prior licence is relevant context, not a substitute for a Singapore-specific compliance programme. Operators who design their Singapore application around their existing offshore structure, rather than around MAS's own requirements, typically need to redesign mid-process.
Which Operator Profile Should Choose Singapore as the Primary Hub?
Singapore is not the right answer for every digital-asset business. The decision depends on the operator's customer geography, activity scope, entity structure and banking relationships. The following profiles reflect the analysis we work through with clients.
An operator whose primary market is Asia-Pacific – covering institutional counterparties in Hong Kong, Japan and Southeast Asian retail markets – has a strong case for a Singapore MAS DPT licence as the primary hub. MAS is a credible, internationally recognised regulator. A Singapore licence carries weight with institutional counterparties and banking providers in the region. The entity substance requirements are achievable for a business with genuine Asia-Pacific operations.
An operator whose primary market is the EU or the UK should consider whether a Singapore licence is the right primary authorisation at all. A MiCA CASP authorisation – obtained via a passporting-friendly member state – covers the EU/EEA perimeter with a single licence. The FCA's registration regime covers the UK. Singapore adds a layer of cost and operational complexity that is justified only if the Asia-Pacific market is a genuine and material revenue line, not a future aspiration.
An operator in a dual-hub structure – Asia-Pacific and the Gulf – may hold a Singapore MAS licence alongside a VARA licence in Dubai. This is a workable structure, but it requires that the two perimeters are clearly delineated: which entity contracts with which customers, how funds flow between the two licensed entities and how each regulator's requirements apply to the group's shared technology and compliance infrastructure. We regularly advise businesses building this structure, and the design work is not trivial.
If a prior application stalled or an account was closed, a second read can surface the structural reason and the route forward. Contact OBOLUS at info@oboluslaw.com.
Does an Offshore Licence Make a Singapore Application Unnecessary?
A common assumption among operators entering Singapore is that a robust offshore licence – from the Cayman Islands, the BVI or an EU member state – removes the need for a Singapore-specific authorisation. This assumption is incorrect, and acting on it creates significant legal exposure.
The PSA applies to the provision of DPT services to Singapore-based customers and to activity carried on in Singapore. The jurisdiction of incorporation of the contracting entity is relevant but not determinative. If the activities fall within the PSA's perimeter – and MAS has interpreted that perimeter broadly – the business requires a Singapore PSA licence regardless of what it holds elsewhere.
The "offshore licence is enough" assumption also misunderstands how Singapore banking works. Singapore-based banks will, in most cases, require a locally licensed entity as the account-holding vehicle for a regulated digital-asset business. An offshore entity without a Singapore licence is unlikely to access Singapore banking – which undermines the commercial rationale for the Singapore operation in the first place.
Global regulatory convergence, driven by FATF standards and the adoption of MiCA-influenced frameworks across the major hubs, means that the era of effective regulatory arbitrage – using one offshore registration to serve multiple markets – is closing. Regulators increasingly share supervisory information and are alert to structures designed to avoid local authorisation. Building a compliant multi-jurisdiction licence stack is not a cost of growth; it is the condition for sustained operation.
Related at OBOLUS
- Licensing and Registration for Digital-Asset Businesses – full-scope licensing counsel across 70+ jurisdictions for exchanges, custodians and token issuers
- How to Set Up a Licensed Crypto Exchange – step-by-step guide to the exchange licensing process, entity structure and compliance requirements
- KYC and Onboarding Framework in Guernsey – analysis of customer due-diligence and onboarding requirements in Guernsey for digital-asset businesses
FAQ
How long does a crypto licence take to obtain?
The timeline varies significantly by jurisdiction and the completeness of the application. In Singapore, a well-prepared MAS application – with a resolved entity structure, qualified personnel and a complete AML/CFT package – typically takes several months from submission to approval. Pre-submission preparation adds to the overall timeline. Operators should build a conservative multi-month planning window for the full licensing cycle, not a matter of weeks.
Which jurisdiction is best for licensing my crypto business?
There is no single answer. The right primary hub depends on your target customer geography, activity scope, banking relationships and operational substance. Singapore suits Asia-Pacific-focused operators. Dubai's VARA regime suits Gulf and global exchange businesses. A MiCA CASP authorisation covers the EU/EEA perimeter. Most institutional-scale businesses require more than one licence. We map the full licence stack across operating, custody and payment layers before you commit to a structure.
Do I need a separate custody licence?
In Singapore, custody of customer digital assets is a regulated activity under the Payment Services Act, and specific safeguarding obligations apply to DPT service providers. Whether a separate authorisation is required depends on the scope of the custody activity and how it is structured relative to the core DPT service licence. Offering standalone third-party custody as a distinct business line typically requires a careful analysis of the applicable MAS Notices and may require an expanded or varied licence. This should be resolved before application, not after.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the entirety of our practice, and we act only for businesses – not retail. We map the licence stack across operating, custody and payment layers before you commit to a structure. To discuss your situation, contact info@oboluslaw.com or message us at t.me/oboluslaw.
By Aisha Tan, Licensing & Jurisdictions Analyst – specialises in MAS Payment Services Act licensing, multi-hub licence stack design and inbound operator structuring for the Asia-Pacific market.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.