Crypto Exchange Licensing for Early-Stage Founders
Operating a crypto exchange without the right regulatory authorisation exposes the business to enforcement action, frozen banking rails and, in the most acute cases, forced shutdown before the product even scales. For an early-stage founder, that risk is not abstract – it arrives as a correspondent-bank rejection, a regulator inquiry or an app-store removal. Crypto exchange licensing is the process by which a VASP (virtual asset service provider) obtains the formal permission to operate an exchange, custody assets and, where needed, process payments in each market it serves. The right structure depends on where the entity sits, where the users are and where the banking relationship lives. This page sets out the regulatory basis, the process, the common structural mistakes and a decision matrix for the most common founder profiles.
Why the Licensing Question Cannot Wait
The regulatory exposure clock starts from the first trade matched, not from the date you apply. Most flagship regimes – including MiCA (the EU's Markets in Crypto-Assets Regulation, supervised by ESMA and national competent authorities) and the VARA regime in Dubai – treat unlicensed exchange activity as a continuing violation. The cost of remediation after the fact is consistently higher than the cost of correct licensing at the outset.
In our practice, we see a recurring pattern: a founder launches on a light-touch registration in one jurisdiction, banking works for six months, and then a correspondent bank flags the structure in a periodic review. The account is suspended. Reconstructing a compliant structure under time pressure, while keeping the product live, is substantially harder than building it correctly from the start.
The cross-border dimension makes this more acute. A VASP registered in one jurisdiction that actively solicits users in another may be operating in the second jurisdiction without a licence – regardless of what the corporate structure says. Regulators in the EU, Singapore, Hong Kong and the UAE have all issued public guidance on this point. The entity's registered address is not the answer to the question of where it is regulated.
FATF Recommendation 15, which underpins AML obligations across almost every compliant regime, requires that jurisdictions license or register VASPs and supervise them for AML/CFT compliance. That baseline is now implemented, with varying intensity, across the major financial centres. An unlicensed exchange is therefore not merely a civil compliance problem; it may carry criminal exposure for directors and officers in certain jurisdictions.
To map the regulatory exposure before you commit to an entity structure, contact OBOLUS at info@oboluslaw.com. The process above describes the standard risk profile. Your facts – the product, the user base, the planned banking – change the analysis. Map your options.
What Does a Crypto Exchange Licence Actually Cover?
A crypto exchange licence authorises a defined set of activities – typically the operation of a trading platform, and in some regimes separately the custody of client assets and the execution of transactions on behalf of clients. Understanding the scope of the authorisation you need is the first structural decision, because applying for too narrow a permission forces a second application later.
Under MiCA, a CASP (crypto-asset service provider) authorisation covers a menu of regulated activities: operating a trading platform, exchanging crypto-assets for fiat, exchanging one crypto-asset for another, executing orders, placing crypto-assets, providing custody and administration, providing transfer services, providing advice and portfolio management. A founder who plans to offer spot trading and custody in the EU will need authorisation covering both the trading platform activity and the custody activity. They are not bundled automatically.
In Dubai, VARA's activity-based licensing model makes this explicit. Each regulated activity – exchange services, broker-dealer, custody, transfer and settlement, lending and borrowing, management and investment – is a separate licence permission. An exchange that also holds client assets needs both exchange and custody authorisations under the VARA rulebooks. In our advisory work, we regularly see founders request only the exchange permission and discover the custody gap only when the banking review raises it.
In Singapore, the MAS Payment Services Act creates tiered licensing for Digital Payment Token (DPT) services. The correct tier – money-changing, standard payment institution or major payment institution – turns on transaction volumes and the specific DPT activities conducted. A founder who plans to grow rapidly needs to plan for the tier change and the recapitalisation it may require, not treat the entry-level licence as a permanent solution.
The principle that applies across every regime: the scope of the authorisation must match the scope of the product, including the product's intended growth path. An under-scoped licence is a deferred compliance failure.
How Does the Licensing Process Work, Step by Step?
The licensing process for a crypto exchange follows a consistent logic across jurisdictions, even though the specific steps and timelines differ materially from one regime to the next. The sequence below represents the standard path; your facts alter the duration and complexity at each step.
Step 1 – Activity and jurisdiction mapping. Before any application is drafted, the business needs a clear map of what it does, who its users are, and which jurisdictions have a claim on it. This is not a light exercise. A founder based in Germany, running a Singapore entity, with users in the EU and Southeast Asia, faces regulatory obligations in at least two regimes from day one. The activity map drives the jurisdiction map, which drives the entity structure.
Step 2 – Entity establishment. The licensed entity is typically a local operating company, not the founding holding structure. Most regulators require that the licensed entity be incorporated in the jurisdiction, have locally resident or locally appointed compliance officers, and maintain books and records in the jurisdiction. The holding structure above it – whether a BVI or Cayman parent, or an EU parent for MiCA passporting – is a separate design decision with its own tax and governance implications.
Step 3 – Pre-application engagement. In several of the leading regimes – including VARA in Dubai and AFSA in Kazakhstan's AIFC – informal pre-application engagement with the regulator is either required or strongly advisable. This step surfaces application issues before they become refusals. Regulators generally welcome well-prepared applicants; they have limited patience for incomplete submissions that require multiple rounds of supplementary information requests.
Step 4 – Documentation preparation. A full exchange licence application typically requires: a detailed business plan, AML/CFT policies and procedures, a technology risk assessment, management information on all key personnel (including personal questionnaires and source-of-wealth analysis for significant shareholders), evidence of financial resources and a governance framework. Regulators under MiCA/CASP, VARA and MAS all require policies that are implemented and tested – not templates downloaded and filed.
Step 5 – Submission and regulatory review. The formal review period varies by jurisdiction. Timelines are best described qualitatively: from a matter of weeks for straightforward AML registrations to several months for full exchange licences under more intensive regimes. The MiCA CASP authorisation process, for example, involves a formal completeness check, a substantive assessment period and, for larger entities, consultation between the home NCA and ESMA. Founders who submit an incomplete application reset the clock.
Step 6 – Conditions, ongoing obligations and supervision. Authorisation is not the end of the process. Every major regime imposes ongoing reporting, capital adequacy monitoring, AML/CFT compliance, the Travel Rule (the obligation to pass originator and beneficiary data with each qualifying transfer) and, increasingly, technology and operational resilience requirements. Founders who treat licensing as a one-time event typically encounter supervisory issues within twelve to eighteen months of launch.
What Are the Most Common Structural Mistakes Early-Stage Founders Make?
Early-stage exchange founders consistently make four structural errors that create disproportionate remediation cost later. None of them are inevitable.
Mistake 1 – Conflating registration with licensing. AML registration (as required, for example, under the FCA's Money Laundering Regulations in the UK) is not the same as a full exchange licence. Registration demonstrates AML compliance; it does not authorise the full range of regulated exchange activities. A UK-registered VASP that operates a spot exchange and holds client assets may be conducting activities that require authorisation beyond the registration. The FCA's regime is in active development, and the gap between what registration permits and what founders assume it permits is frequently the source of enforcement risk.
Mistake 2 – Assuming one offshore registration covers global operations. A common assumption among early-stage founders is that a BVI or Cayman VASP registration allows them to serve users globally without further licensing. This is not accurate. The BVI FSC and CIMA VASP frameworks govern activities conducted in or from those jurisdictions. They do not confer any authorisation in the EU, the UAE, Singapore or Hong Kong. A founder serving users in those markets needs to analyse local licensing obligations independently. We address this directly because it is the most persistent myth in the early-stage crypto licensing environment.
Mistake 3 – Under-resourcing the compliance function before application. Regulators in the leading hubs increasingly expect the licensed entity to have a functioning compliance framework – real policies, a real compliance officer and real controls – before authorisation is granted, not as a post-licensing aspiration. An application that presents a compliance framework in draft form, or names a compliance officer who has no crypto-specific background, will receive additional information requests at best and an adverse assessment at worst.
Mistake 4 – Ignoring the banking layer during the licensing design phase. A licence without a banking relationship does not produce a viable exchange. The banking question – which institution, in which jurisdiction, will hold client funds and operate the fiat on/off ramp – needs to be considered in parallel with the licensing structure, not after it. Some jurisdictions with relatively streamlined licensing have a thin banking market for crypto businesses. Others with stronger banking access have more intensive licensing requirements. The optimal structure balances both.
How Does the Cross-Border Reality Affect the Licensing Stack?
For most early-stage founders, the entity structure and the user base are not in the same jurisdiction. The legal consequence is a multi-licence obligation that compounds with growth.
A founder who licenses in an EU member state under MiCA and uses the CASP passporting mechanism can, in principle, serve retail and professional users across the EU/EEA from a single authorisation. That passporting right is one of the core structural advantages of the MiCA regime. However, it covers EU/EEA users only. The same exchange serving users in the UAE, Singapore or Hong Kong faces separate licensing analyses in each of those markets. VARA, MAS and the SFC in Hong Kong do not recognise MiCA passporting as conferring any local authorisation.
In our cross-border practice, we work through the licensing stack in layers. The first layer is the primary operating licence – typically in the jurisdiction where the entity sits and where the majority of users are based. The second layer is the secondary licensing or registration obligations triggered by specific user populations or banking relationships. The third layer is the holding and structuring layer, which intersects with tax and investor access considerations.
A practical example of this complexity: a founder operating a MiCA-licensed CASP that also takes institutional clients from the UAE will need to consider whether that activity requires VARA authorisation or falls within an exemption. VARA's scope covers activities conducted in or directed at users in Dubai's mainland; the analysis is fact-specific and the answer is not always obvious on the face of the rulebook.
Allied counsel in the relevant jurisdiction support our advice where local law opinions or local regulatory filings are required. We coordinate the full licensing stack so that the founder has one consistent strategic view, not competing advice from unconnected local practitioners.
In a recent licensing matter, a payments and exchange business expanding from Southeast Asia into the EU engaged us to design the MiCA-compliant entity structure ahead of a Series A. We mapped the activity scope, identified a second-layer obligation under a national AML regime that the founders had not anticipated, and restructured the holding arrangement to optimise the tax and investor access position. The entity was incorporated, the application prepared and submitted within the timeline the board had set for the funding round.
If your licensing structure spans more than one jurisdiction and you need a single coordinated view, write to us at info@oboluslaw.com. If a prior application stalled or a banking relationship closed, we can surface the structural reason. Map your options.
Decision Matrix: Which Licence Profile Fits Your Build?
Founders at different stages and with different user-base profiles face materially different licensing paths. The following profiles are not exhaustive, but they cover the most common configurations we advise on.
Profile A – EU-focused spot exchange, retail and professional users. The primary instrument is a MiCA CASP authorisation in a selected EU member state, with passporting to cover the full EU/EEA market. The entity requires locally appointed management, a functioning AML/CFT framework and financial resources at the applicable category level. Authorisation timeline is measured in months rather than weeks. The key risk is submitting an incomplete application that resets the formal assessment clock. The passporting benefit makes this the most scalable single-licence structure for EU user acquisition.
Profile B – MENA-focused exchange, institutional and retail, UAE as primary hub. The primary instrument is a VARA licence in Dubai, with the relevant activity permissions for exchange and, if client assets are held, custody. The VARA regime is activity-based; each permission requires separate scoping. The process involves pre-application engagement and a detailed review of the technology and governance stack. Timelines vary by activity scope and application quality. The key risk is underestimating the ongoing compliance burden and the supervision intensity VARA applies post-authorisation.
Profile C – APAC-focused exchange, DPT services, Singapore as primary hub. The primary instrument is an MAS DPT licence under the Payment Services Act, at the appropriate tier. MAS applies a rigorous vetting process, particularly for key personnel and shareholders. The licence tier needs to anticipate growth in transaction volume to avoid a forced recapitalisation mid-operation. The key risk is selecting an entry-level tier to reduce initial capital requirements, only to trigger a reclassification event within the first operating year.
Profile D – Global early-stage launch, minimal initial capital, seeking the fastest viable entry point. The available options include AML-focused registrations in several jurisdictions, which provide a degree of legitimacy and access to some banking relationships, but do not confer the full exchange authorisation needed for institutional clients or regulated banking partners in the major markets. This profile needs a clear view of the short-term structure and the 12–24-month upgrade path to full authorisation. Launching on a registration-only basis without a documented upgrade plan is the structural error that most frequently creates enforcement risk at the Series A stage, when due diligence surfaces the gap.
A Self-Assessment Checklist for Founders Before You Apply
Before engaging the formal licensing process, a well-prepared founder can answer every question on the following checklist. Gaps at this stage indicate where counsel effort is needed first.
First, can you describe the exact activities your exchange performs – matching, execution, custody, fiat conversion, staking – and confirm which regulatory regime treats each as a regulated activity? If the answer is "we are not sure about custody," that uncertainty needs to be resolved before the application is drafted.
Second, have you identified every jurisdiction in which your users are based, where your servers are located, and where your banking relationships sit? Each of these creates a potential regulatory nexus. The entity's registered address is one input, not the complete picture.
Third, do you have a named, qualified compliance officer who is actively engaged in building the AML/CFT framework? A regulatory application in any of the flagship regimes will require demonstrating that this person exists, has relevant experience and has begun implementing controls – not that you plan to hire someone after authorisation.
Fourth, have you confirmed that your planned banking partner will accept the licensed entity as a client? A bank that works with licensed exchanges in one jurisdiction may not extend that acceptance to all licence types or all jurisdictions. Banking access is best confirmed before the licence application is filed, not after.
Fifth, do you have a view on the tax treatment of the operating entity, the holding structure and, where relevant, the token issued? The licensing structure and the tax structure interact. A CASP licence in one member state combined with a non-EU holding company may create permanent establishment exposure that the founding team has not modelled.
An incomplete checklist is not a reason to delay indefinitely. It is a map of the advisory work that needs to happen before the application clock starts.
A Common Assumption Addressed: One Offshore Licence Is Enough
A common assumption among early-stage exchange founders is that a single offshore VASP registration – in the BVI, the Cayman Islands or a similarly light-touch jurisdiction – provides a workable global operating base. The facts do not support this assumption.
The BVI FSC VASP Act and the CIMA VASP framework establish registration obligations for businesses operating in or from those territories. They are not passporting regimes. They do not substitute for MiCA authorisation in the EU, VARA registration in Dubai, MAS licensing in Singapore or SFC authorisation in Hong Kong. A founder who serves users in those markets through an offshore-registered entity is, from the local regulator's perspective, operating without authorisation.
The consequences are not uniform – enforcement intensity varies by regulator and by the scale of the activity – but the legal position is consistent: local regulatory obligations are determined by local law, not by the existence of an offshore registration. We address this assumption directly because it generates the most frequent and the most expensive remediation work we see in early-stage licensing matters. The cost of restructuring an offshore-only structure after a regulator has made an inquiry is a multiple of the cost of correct initial structuring.
For founders who have already launched on a single-jurisdiction registration and are planning to grow into regulated markets, the path forward is a structured upgrade plan, not a defensive posture. We map that path as part of the initial engagement.
Related at OBOLUS
- Licensing and Registration for Digital-Asset Businesses – the full practice overview covering VASP, CASP and VATP authorisations across more than seventy jurisdictions.
- EMI Licence for Crypto Firms: the Compliance Burden in Practice – how electronic money institution authorisation interacts with a crypto exchange structure and what the ongoing compliance obligations look like.
- Staking Service Legal Framework: What Recent Enforcement Tells Operators – the regulatory treatment of staking services and the enforcement signals that exchange operators with staking products need to monitor.
FAQ
How long does a crypto licence take to obtain?
The timeline varies considerably by jurisdiction and by the completeness of the application. AML-focused registrations in some jurisdictions are measured in weeks. Full exchange authorisations under regimes such as MiCA CASP, VARA or the MAS Payment Services Act are measured in months. The single most common cause of delay is an incomplete initial submission, which resets the formal assessment period. A well-prepared, complete application submitted to the right regime is the most reliable way to minimise the authorisation timeline.
Which jurisdiction is best for licensing my crypto business?
There is no single best jurisdiction. The right choice depends on where your users are, where your banking relationships are available, the scope of your regulated activities, your capital position and your growth timeline. MiCA offers EU passporting for a single authorisation; VARA provides access to the MENA market from a well-resourced regulatory environment; MAS in Singapore anchors APAC institutional credibility. Each carries different capital, timeline and ongoing-compliance implications. The optimal structure balances licensing access, banking viability and tax efficiency simultaneously.
Do I need a separate custody licence?
In most flagship regimes, custody of client assets is treated as a distinct regulated activity from the operation of a trading platform. Under MiCA, VARA and the MAS Payment Services Act, an exchange that holds client assets needs either a combined authorisation covering both activities or separate permissions for each. Assuming that an exchange licence automatically covers custody is one of the most common scoping errors in early-stage licensing applications. The scope of any authorisation should be verified against the specific activity being conducted, not assumed from the name of the licence category.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise crypto exchanges, custodians, token issuers and funds across more than seventy licensing jurisdictions, on disputes and on-chain asset recovery across more than twenty-five forums, and on the tax, banking and compliance that sit around every structure. We map the licence stack across operating, custody and payment layers before you commit to an entity design. Digital assets are the whole of our practice. To discuss your licensing situation, contact info@oboluslaw.com or reach us via t.me/oboluslaw.
By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in cross-border VASP and CASP authorisation strategies for exchange and custody businesses at entry and growth stages.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.