EST · MMXXVI
Home/Jurisdictions/Uae Adgm/CASP authorisation under mica in Abu Dhabi Global Market (ADGM)
Licensing & Registration

CASP authorisation under mica in Abu Dhabi Global Market (ADGM)

Casp authorisation under mica in Abu Dhabi Global Market (ADGM). Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Ta

CASP Authorisation Under MiCA in Abu Dhabi Global Market (ADGM)

Operating a digital-asset business in the UAE without a properly scoped licence exposes the entity to enforcement action, debanking and the permanent loss of operating rails. The Abu Dhabi Global Market (ADGM) – governed by the Financial Services Regulatory Authority (FSRA) – is the UAE's common-law financial free zone and one of the few jurisdictions outside the European Union where regulators have formally aligned their virtual-asset regime with the MiCA (Markets in Crypto-Assets Regulation) model. For a business choosing between Abu Dhabi and the EU for its primary regulated entity, the ADGM FSRA framework deserves direct comparison. This page sets out the regulated perimeter, the authorisation process, cross-border considerations, and the decision logic for an inbound operator.

What Does the ADGM FSRA Actually Regulate in the Crypto Space?

The FSRA regulates virtual-asset activities conducted within or from ADGM, covering trading platforms, custody, brokerage, management, and advisory services in relation to recognised virtual assets. The FSRA maintains a recognised virtual-assets list – assets that pass its review for admissibility – and activity conducted in relation to listed assets triggers full authorisation requirements under the FSRA's virtual-asset framework. This is the structural parallel to the MiCA category system, where the classification of the asset determines the regulatory obligation that attaches to the service provider.

The FSRA's regime does not automatically accept an asset because it is widely traded elsewhere. A prospective operator must confirm that each asset it intends to offer is either already on the recognised list or can be submitted for review. This recognition gate is an early-stage planning point that operators – accustomed to simply listing assets on offshore platforms – frequently miss. In our licensing practice, we identify this confirmation step as a threshold issue before any application is filed.

ADGM sits wholly outside the UAE mainland and outside the DIFC financial free zone. Authorisation from the FSRA covers activities conducted from the ADGM perimeter. Serving customers outside ADGM – including on the UAE mainland – requires separate analysis and, in many cases, coordination with the mainland VARA regime or with the regulators in the user's home jurisdiction. The cross-border overlay is not optional.

How Does the ADGM Virtual-Asset Regime Compare to MiCA CASP Authorisation?

MiCA establishes a single EU-wide authorisation for crypto-asset service providers, covering exchange, custody, brokerage, portfolio management, advice and transfer services, with passporting across all EU/EEA member states once a CASP is authorised in one jurisdiction. The ADGM FSRA framework is structurally similar in that it regulates by activity type, imposes capital adequacy and conduct requirements, and requires a local substance presence – but it operates within a single jurisdiction rather than offering a passport bloc.

The key difference is geographic reach. A MiCA CASP authorisation secured in an EU jurisdiction – such as through the Lithuania or Malta route – enables EU/EEA passporting; ADGM authorisation provides standing in the ADGM free zone and, by bilateral recognition or equivalence discussions, potential access to other Gulf and international markets. For a business whose primary user base is in the Gulf, South Asia or Africa, ADGM can be the more commercially efficient primary licence. For a business targeting the EU, a CASP authorisation in an EU member state is still the operative instrument.

That said, ADGM's common-law base, its alignment with FATF standards, and the FSRA's stated intent to benchmark against leading international regimes make it a credible anchor for an operator that subsequently seeks EU access via a separately authorised EU entity. Operators we advise regularly run a dual-entity structure: an ADGM-authorised entity serving the Gulf and international markets alongside a MiCA-authorised CASP for EU user access.

Relevant here is the FATF Travel Rule, which requires the transmission of originator and beneficiary data with virtual-asset transfers above defined thresholds. Both the FSRA framework and the MiCA AML package impose Travel Rule obligations on authorised service providers. Any operator building a multi-entity structure must map data-sharing obligations across both regimes before go-live – the compliance architecture for Travel Rule compliance cannot be an afterthought bolted onto the licensing structure.

To map the ADGM and EU licensing stack for your specific activity set and user base, contact OBOLUS at info@oboluslaw.com. The process above describes the standard comparison. Your entity structure, the assets you plan to offer and the jurisdictions your users sit in will change the analysis materially.

Who Needs Authorisation from the ADGM FSRA?

Any entity that carries on a regulated virtual-asset activity from ADGM must be authorised by the FSRA – there is no registration-only track for substantive activity of the kind that MiCA requires a CASP authorisation for. The regulated activities include operating a virtual-asset exchange, providing custody or safeguarding of virtual assets, brokerage and dealing in virtual assets as principal or agent, virtual-asset management, and providing advice on virtual assets. The FSRA also applies its financial-promotion rules, so marketing virtual-asset services into or from ADGM by an unauthorised entity is itself a regulated action.

The perimeter question matters for two types of inbound business. First, a business already operating elsewhere – say, under a VARA licence on the Dubai mainland or under an offshore structure – may be providing services accessible to ADGM-based counterparties and require separate FSRA authorisation. Second, a business structuring for the first time may target ADGM specifically for its common-law environment, its DIFC Courts adjacency, and its banking ecosystem. For both profiles, the starting point is a precise activity analysis before entity formation.

What Is the ADGM FSRA Authorisation Process and What Should an Operator Expect?

The FSRA authorisation process follows a staged review. The operator submits a formal application package that includes a business plan, a regulatory business plan addressing the specific virtual-asset activities, a financial analysis demonstrating capital adequacy against the FSRA's requirements for the proposed activities, governance documents, an AML/CFT framework and policies, individual applications for approved persons, and a technology and cybersecurity assessment where relevant.

The FSRA operates a pre-application engagement model. Prospective applicants may request a consultation with the FSRA to discuss the proposed business model before submitting a formal application. This pre-application meeting is genuinely valuable – it allows the regulator to flag concerns at the design stage and gives the operator an opportunity to confirm that the proposed activities are within scope of the recognised virtual-assets list. Skipping this step and filing a cold application is an approach we advise against.

Timelines vary by the complexity of the proposed business and the quality of the application materials. A well-prepared application with a clear activity scope, complete governance documentation and a substantive AML framework will progress more quickly than a high-complexity application or one that requires iterative requests for further information. Operators should build a realistic planning window that accounts for the FSRA's review period, any request-for-information cycle, and the approved-persons vetting process. We describe timelines qualitatively because they vary; current indicative windows should be confirmed directly with the FSRA or through counsel with active files.

Capital adequacy requirements are set by the FSRA for each regulated activity category. As with MiCA's tiered own-funds requirements, the capital threshold depends on what the entity is authorised to do. Custody and exchange activities typically carry higher capital expectations than advisory or brokerage. Operators should not assume that the capital level adequate for a lighter-touch activity class will cover an expanded scope added later – a material change in regulated activity requires a variation of authorisation.

How Do Tax, Banking and Cross-Border Structure Interact With ADGM Authorisation?

An ADGM entity benefits from the UAE's zero-rate corporate tax environment for income earned within the free zone, subject to the qualifying-income conditions introduced under the UAE corporate tax regime. This is a material consideration for operators comparing ADGM with EU CASP jurisdictions, where corporate tax rates, VAT on crypto services and withholding tax on distributions represent a meaningfully higher structural cost. However, the qualifying-income analysis is fact-specific and changes materially with the entity's revenue mix, its contractual counterparties and whether it has substance obligations in the UAE. Any tax framing in the business plan must be cleared by a tax adviser with current UAE free-zone expertise.

Banking for virtual-asset businesses in the UAE has improved since the FSRA and VARA regimes formalised the sector, but it remains relationship-intensive. UAE banks with a formal virtual-asset policy will typically require sight of the FSRA authorisation, an AML policy and a client-onboarding framework before opening an account for a crypto business. Correspondent banking for fiat settlement – particularly USD rails – requires a bank that is itself comfortable with the regulatory posture of the UAE, which major international banks generally are given the FSRA's FATF-aligned framework.

For cross-border payment flows, the Travel Rule (the obligation to transmit originator and beneficiary data with a virtual-asset transfer, consistent with FATF Recommendation 15) applies to ADGM-authorised operators above applicable thresholds. This creates a practical compliance burden when sending to counterparties in jurisdictions that have implemented different Travel Rule standards or that use different technical messaging formats. Operators building a cross-border transfer capability should not simply assume that compliance in ADGM satisfies obligations in the recipient jurisdiction – a bilateral mapping of each corridor is needed.

A second cross-border consideration is the relationship between ADGM authorisation and user-protection obligations in the user's home jurisdiction. An ADGM-authorised entity serving retail users in the EU, the UK, Singapore or Hong Kong may trigger separate regulatory obligations in each of those jurisdictions. The FSRA licence is not a global passport. Operators we advise routinely receive this analysis as a condition of our engagement before any application is filed.

A Recent ADGM Authorisation and Structuring Matter

In a recent matter, an exchange operator with existing offshore infrastructure approached us after its primary banking relationship was terminated following a compliance review at the bank. The operator held an offshore registration that had been adequate at inception but did not meet the bank's updated virtual-asset policy, which required an authorisation from a FATF-aligned regulator. We mapped the activity scope, confirmed asset eligibility under the FSRA's recognised virtual-asset framework, and structured a dual-entity model with the ADGM entity as the primary regulated vehicle and the offshore entity retained for a non-UAE user segment. The pre-application engagement with the FSRA identified a capital-adequacy point that was resolved at the design stage rather than during formal review. Banking access was restored following authorisation, and the operator was able to onboard institutional counterparties that had declined to engage with the prior structure. No specific financial figures are cited; the engagement involved a mid-market exchange with a material daily volume.

What Is the Decision Point: ADGM Versus Other UAE and International Licence Routes?

For an operator deciding between ADGM FSRA authorisation, a VARA licence on the Dubai mainland, and an EU MiCA CASP authorisation, the choice turns on four axes: user geography, activity scope, capital efficiency and banking access.

A business whose primary users are in the Gulf, South Asia or Africa and whose activity set includes exchange, custody and institutional brokerage will typically find ADGM a strong fit. The common-law governance, the FSRA's FATF alignment and the proximity to the DIFC Courts ecosystem for dispute resolution create a stable operating environment. Capital requirements are set against institutional-grade activity expectations.

A business targeting retail users in the EU, or one that needs the passporting benefit of a MiCA CASP authorisation across the EU/EEA, should pursue a CASP in an EU member state as its primary EU instrument. Lithuania and Malta both offer CASP authorisation routes under the MiCA transitional and full-authorisation regimes respectively. ADGM can serve as a parallel entity for non-EU activity in this structure.

A business targeting the Dubai mainland – retail exchanges, consumer-facing services – will fall under VARA rather than FSRA. VARA and FSRA are separate regulators in separate jurisdictions. An entity authorised by the FSRA is not authorised for mainland Dubai activity by virtue of that authorisation alone. A dual ADGM/VARA structure is possible but involves separate applications, separate capital and separate governance requirements.

Operators choosing between these routes should not treat licensing as a one-time cost. The ongoing supervision burden – regular reporting, approved-persons notifications, AML audits, variation applications for new activities or new assets – is an operating cost that accumulates over the licence life and should be factored into the business case.

If a prior application stalled or a banking relationship was withdrawn, a structured review of the entity architecture can identify the compliance gap and map the route back. To pressure-test your structure before you commit, message us via t.me/oboluslaw.

A Common Assumption Worth Correcting: Does One Offshore Licence Cover Global Operations?

A common assumption among founders structuring for growth is that a single offshore registration – or even a well-regarded offshore VASP registration – provides adequate regulatory cover for a global user base. It does not. The FATF Travel Rule, the EU's MiCA extraterritorial reach for services offered into the EU, the UK's financial-promotion regime, MAS rules on digital-payment-token services in Singapore, and the SFC's VATP licensing requirements in Hong Kong all operate on a services-into-jurisdiction basis. The regulator in the user's jurisdiction evaluates whether the service is accessible to its residents, not where the operator's entity is incorporated.

Operators who have built on an offshore structure and are now facing debanking, institutional counterparties requiring a licensed entity, or regulatory correspondence from a jurisdiction where users are active are in a position that is not irreversible – but that does require a structured multi-jurisdiction analysis. The solution is rarely a single additional licence. It is a sequenced stack: primary operating licence in the jurisdiction where substance sits, secondary licences or registration in jurisdictions with material user populations, and a banking structure that supports the full payment corridor.

In our practice, we regularly see the gap between what an operator assumed a licence covered and what it actually authorised. Closing that gap before enforcement is far less costly than responding to it afterwards.

Related at OBOLUS

FAQ

How long does a crypto licence take to obtain?

Timelines vary significantly by jurisdiction and the complexity of the proposed activity. In ADGM, a well-prepared application progresses more quickly than one requiring iterative information requests. Operators should plan for a multi-month process from pre-application engagement through final authorisation. In EU MiCA jurisdictions, transitional timelines are being set by the relevant national competent authority. Building a realistic timeline into the business plan – rather than assuming a minimum – is the standard approach for any licensed entity launch.

Which jurisdiction is best for licensing my crypto business?

There is no single answer. The right jurisdiction depends on where your users are, what activities you conduct, your capital position and your banking requirements. ADGM suits operators focused on the Gulf and international institutional markets; MiCA CASP jurisdictions suit operators targeting the EU. A multi-entity structure serves businesses with diversified user geographies. We map the licence, banking and tax stack for each client's specific profile before recommending a jurisdictional path.

Do I need a separate custody licence?

In most leading jurisdictions – including under the ADGM FSRA regime and under MiCA – custody of virtual assets is a separately regulated activity. An entity authorised for exchange or brokerage is not automatically authorised to provide custody. If your business model involves holding client assets, you will need either a custody authorisation of your own or a custody arrangement with an appropriately authorised custodian. The structure of the custody layer also has AML, segregation and capital implications that must be addressed in the application.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit – and our disputes team coordinates freezing relief and on-chain tracing across leading common-law forums when it matters most. To discuss your situation, contact info@oboluslaw.com.

By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in ADGM FSRA authorisations, MiCA CASP structuring, and multi-jurisdiction licensing stacks for exchange and custody businesses.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours