Operating a crypto exchange (a platform that enables users to buy, sell or swap digital assets) without the correct regulatory authorisation exposes a business to enforcement action, termination of banking relationships and, in the most serious cases, criminal liability for directors. Regulators across the major hubs – VARA in Dubai, ESMA and national competent authorities under MiCA across the EU, the SFC in Hong Kong, MAS in Singapore – have all signalled that the supervisory environment is tightening and that previously tolerated operating gaps will not survive the next inspection cycle. For a regulated entity considering or already running crypto exchange activity, the question is not whether to licence but how to structure that licensing mandate correctly across every layer of the business.
This page sets out the regulated basis for crypto exchange activity, the application process across the leading licensing centres, common structural mistakes we see in our practice, and the cross-border factors that determine whether a single licence is ever sufficient. It is written for general counsel, compliance officers and CFOs at institutions that already carry regulatory obligations and are now adding digital-asset exchange capacity.
Why Regulated Entities Face a Different Licensing Problem
A regulated entity – whether a payments institution, a bank, a broker-dealer or a fund – enters the crypto exchange environment carrying existing supervisory relationships. Those relationships create both advantages and complications. The advantage is credibility: regulators weight the compliance history of an applicant heavily, and an institution with clean books and a functioning AML programme is better placed than a greenfield startup. The complication is exposure: the parent entity's existing licence does not automatically cover the new digital-asset activity, and the regulator supervising the parent may take a negative view of unlicensed crypto activity appearing on a prudential return.
Under MiCA, a CASP (crypto-asset service provider) authorisation is required for exchange-type activities in the EU, regardless of whether the operator already holds a MiFID investment firm licence. The two regimes overlap but do not substitute. The same logic applies under the VARA rulebooks in Dubai: holding a mainland UAE financial services permission does not extend to virtual-asset exchange activity without a separate VARA authorisation. In our practice, we regularly advise institutions that have been operating in a gap – processing crypto flows under a payments licence or a broker exemption – only to discover that the activity is squarely within the scope of a separate VASP regime.
The cost of that gap is not theoretical. Frozen correspondent banking, withdrawal of custodian relationships and regulatory referrals from one jurisdiction to another are outcomes we have seen materialise for institutions that delayed the licensing question.
The process above describes the standard path. Your facts – the entity type, the user base, the banking relationships – change the analysis materially. To map your specific exposure before you commit resources to an application, contact OBOLUS at Map your options.
What the Major Regimes Require for Exchange Activity
Every leading licensing centre defines exchange activity broadly and requires authorisation before operations begin. The specific instrument, the capital requirement and the application process differ – but the regulatory baseline is consistent: you must be authorised, you must maintain adequate own funds, and you must demonstrate operational and compliance competence before trading begins.
Under MiCA, operating a crypto-asset trading platform for third parties is a regulated CASP service. An entity authorised in one EU member state may passport that authorisation across the EEA without a separate application in each country – a structural advantage that makes EU licensing strategically valuable for businesses with a pan-European user base. Lithuania and Malta both retain active CASP authorisation pipelines as MiCA transition completes; each NCA applies the same MiCA framework but with different procedural rhythms and supervisory emphasis.
In Dubai, VARA issues activity-based licences across categories including exchange services, broker-dealer services and custody. A regulated entity building an exchange in the DIFC financial free zone is subject to a different regime – the DIFC's own financial services framework – rather than VARA's mainland Dubai rulebooks. Getting that perimeter question right at the outset determines which application goes to which desk.
In Hong Kong, the SFC's VASP licensing regime for virtual-asset trading platforms applies to any platform conducting exchange activity in or from Hong Kong. Singapore's MAS oversees crypto exchange activity under the Payment Services Act, under which a digital payment token service licence is required. The AIFC in Kazakhstan, supervised by AFSA, operates a common-law framework for digital-asset trading facilities that appeals to operators building a CIS-facing platform.
In every case, the regulatory authorisation is the precondition – not an administrative formality to resolve in parallel with go-live.
How Does the Licensing Application Process Work?
The application process for a crypto exchange licence follows a broadly consistent structure across jurisdictions, though timelines and documentation depth vary by regime and by the complexity of the applicant's structure. Understanding the sequence prevents the most common cause of delay: submitting an incomplete or structurally incoherent application that triggers rounds of regulatory questions.
The first phase is jurisdictional selection and entity structuring. This is not a formality. The licensing entity must sit in the right place relative to where its users are, where its banking will be held and where its custodian operates. A mismatch at this stage – for example, a Cayman-incorporated entity attempting to serve EU retail users under a non-EU licence – creates a gap that no subsequent filing will cure.
The second phase is documentation assembly. Regulators across the major hubs require a detailed business plan, an AML/CFT programme, a governance framework with fit-and-proper assessments of controllers and senior managers, an operational resilience plan and, in most cases, evidence that the capital requirement is met or committed. For a regulated entity, some of this material exists in adapted form; it still requires translation into the format the licensing regulator expects.
The third phase is submission and regulatory dialogue. Most regulators will conduct a completeness review before formally starting the clock on the assessment period. Responding to the regulator's questions promptly, accurately and without overpromising on operational timelines is a discipline that separates well-managed applications from those that stall. In our cross-border practice, we have seen applications in well-functioning regimes take a matter of weeks from submission to in-principle approval, and others in the same jurisdiction take considerably longer when the applicant's responses were slow or the business model required clarification.
The fourth phase is post-authorisation setup: completing any residual conditions, onboarding the compliance infrastructure and, critically, confirming that the banking and custody arrangements are in place before the exchange goes live.
What Are the Most Common Mistakes Regulated Entities Make?
Regulated entities entering crypto exchange licensing tend to make a predictable set of mistakes – not from ignorance of regulation generally, but from underestimating how differently the digital-asset regulatory regimes operate compared with the frameworks their compliance teams know.
The first and most damaging mistake is treating the licence as a single-layer question. Crypto exchange activity typically involves at least three regulated layers: the exchange or trading activity itself, the custody of client assets and, where the platform handles fiat flows, the payment or money transmission activity. Each layer may require a separate authorisation. Operators we advise routinely discover that their initial licence application covers only one of the three – and that they are operating the other two in an unregulated gap.
The second mistake is assuming that an existing group licence extends to the new activity. A bank that adds a crypto trading desk, a payments institution that begins settling token transactions or a broker-dealer that lists tokenised securities will, in most major regimes, require a new or extended authorisation. The principle that digital-asset activity is not automatically carved into an existing financial services permission is now consistently applied by regulators across the EU, the UK, the UAE and Southeast Asia.
The third mistake is selecting the licensing jurisdiction based on speed or cost rather than user geography and banking access. A jurisdiction that issues a licence quickly but whose banks will not open accounts for crypto businesses, or whose authorisation is not recognised in the markets where the client base sits, provides only the appearance of compliance. Regulators in the jurisdictions where users are located will apply their own perimeter tests regardless of where the entity is licensed.
The fourth mistake is submitting an application before the business model is sufficiently defined. Regulators ask detailed questions about order-flow mechanics, token listing criteria, conflict management and fee structures. An application that cannot answer those questions specifically – because the product is still in design – is likely to generate a volume of regulatory questions that extends the timeline significantly.
The Cross-Border Licensing Reality for Exchange Operators
A single offshore licence is not enough to serve clients globally. This is the most persistent misconception we encounter among regulated entities that are new to the digital-asset space.
The perimeter test in most major jurisdictions is based on where the service is provided to users, not merely where the operating entity is incorporated. A platform incorporated in the BVI or the Cayman Islands and licensed under the BVI VASP Act 2022 or the Cayman Virtual Asset (Service Providers) Act may be fully compliant in those jurisdictions and simultaneously in breach of the regime applicable in the EU, the UK, Hong Kong or Singapore – if users in those markets are being actively solicited or served.
For an exchange with users in multiple markets, the licensing question is therefore a matrix. The relevant variables are: where the entity is incorporated; where it is licensed; where its users are located; where its banking is domiciled; and whether any of those jurisdictions apply a passporting or equivalence mechanism that reduces the number of separate licences required. The EU's MiCA passporting mechanism is the most developed of these, but it applies only within the EEA and only to CASP-authorised entities.
In our practice, we work through this matrix with operators before the application is filed. The output is a licence map that identifies which authorisations are required, which can be sequenced and which can be covered by a passportable primary licence. We also engage allied counsel in the relevant jurisdiction where local filing or local regulatory dialogue is required. The cross-border angle is not an afterthought – it is the primary driver of the licensing strategy.
A micro-matter illustrates the point. In a recent licensing mandate, a regulated payments institution with a pan-European user base sought to add crypto exchange functionality to its existing platform. Initial internal analysis suggested that the institution's existing EU authorisation covered the new activity. We reviewed the regulatory perimeter under MiCA and confirmed it did not. We mapped the CASP authorisation requirements across the relevant member states, identified a primary NCA for the anchor authorisation and structured the passporting notification to cover the remaining EEA markets. The institution went live with full regulatory coverage rather than the partial coverage its initial analysis had assumed.
If a prior application has stalled or an account has been closed, a second read can surface the structural reason and the route back. Write to OBOLUS at Map your options.
Decision Matrix: Which Licensing Structure Fits Which Operator Profile?
The right licensing structure depends on the operator's profile, not on a generic preference for any particular jurisdiction. The following matrix sets out four common profiles, the instrument that typically fits each and the primary risk at each path.
Profile A – EU-regulated institution adding crypto exchange capacity. A MiFID investment firm or an e-money institution seeking to offer crypto trading to existing EU clients will generally require a CASP authorisation under MiCA in addition to its existing licence. The anchor authorisation should be sought from the NCA in the entity's home member state, with passporting notifications covering other EEA markets where users are located. The primary risk is the gap period between application and authorisation: operating crypto trading before the CASP authorisation is granted is a regulatory breach even where the underlying firm is fully licensed for its existing activity.
Profile B – Non-EU institution building a global exchange from scratch. An institution with no existing EU presence that wants to serve EU users will need a CASP authorisation in a chosen EU member state. It will also need to assess whether its home-market licence (or absence of one) creates any additional exposure. For this profile, the sequencing question is critical: the EU authorisation typically has the longest lead time and should be started first, with other jurisdictions filed in parallel where possible.
Profile C – Exchange operator with a concentration in the Gulf. A business whose primary user base is in the UAE and the broader Gulf region should assess the VARA regime for Dubai activity and the ADGM/FSRA framework for Abu Dhabi. Operating across both requires separate engagement with each authority. Banking in the Gulf for crypto businesses remains an operational constraint; demonstrating a credible banking plan is a non-trivial part of each application.
Profile D – Asia-Pacific-focused operator. An exchange serving users in Hong Kong, Singapore and potentially Japan faces three separate regulatory regimes – the SFC's VASP licensing, MAS's Payment Services Act framework and the FSA/JVCEA structure in Japan. Each requires a standalone application. For this profile, the structural question is which entity holds the primary licence in each jurisdiction: a single group entity cannot typically hold licences in multiple Asian jurisdictions simultaneously, so the group structure needs to accommodate separate licensed subsidiaries.
AML, Travel Rule and Compliance Architecture
A crypto exchange licence is not obtained and then forgotten. It comes with ongoing compliance obligations that are operationally intensive and – for a regulated entity – layered on top of existing AML/CFT requirements.
The Travel Rule (the obligation, derived from FATF Recommendation 15, to pass originator and beneficiary data with a virtual-asset transfer) applies in every major licensing jurisdiction. For an exchange, compliance with the Travel Rule means integrating with a Travel Rule solution, vetting counterparty VASPs and maintaining records of transfers in the format each jurisdiction's regulator specifies. The data threshold above which the Travel Rule applies varies by jurisdiction and should be confirmed against current local legislation rather than assumed to be uniform.
Customer due diligence standards at crypto exchanges supervised under MiCA, VARA, MAS and the SFC's regime are materially higher than those that applied under earlier VASP registration-only regimes. Regulators increasingly expect transaction monitoring that is calibrated to crypto-specific risk typologies – not a repurposed fiat AML system with a crypto overlay.
For a regulated entity, the compliance architecture of the new crypto exchange activity must integrate with the group's existing AML framework without creating conflicts between the two sets of obligations. In practice, that integration work is often underestimated at the licensing stage and surfaces as a significant operational cost after authorisation. Addressing it before the application is filed produces a more credible submission and a lower post-authorisation burden.
A Common Assumption Worth Examining
A common assumption among regulated entities entering crypto exchange licensing is that their existing compliance infrastructure – policies, systems, trained staff – can be adapted quickly to meet the new regulatory obligations. The assumption is understandable: a firm that already runs a sophisticated AML programme is genuinely better placed than one starting from nothing.
In practice, however, the gap between an adapted fiat compliance programme and what regulators in the major crypto exchange licensing centres now expect is larger than most internal assessments project. Token classification, blockchain analytics integration, Travel Rule tooling, virtual-asset-specific risk assessments and the handling of self-hosted wallets are all areas where regulators have developed specific expectations that go beyond what a standard financial services AML framework covers. Operators we advise at this stage regularly find that their compliance teams need external input on the crypto-specific elements even where the general compliance capability is strong.
The implication is not that existing infrastructure is worthless – it is that it needs to be supplemented with crypto-specific capability before the licence is applied for, not after it is granted.
Related at OBOLUS
- Licensing and Registration for Digital-Asset Businesses – our practice overview across 70+ licensing jurisdictions
- CASP under MiCA: A Legal Guide – what CASP authorisation means in practice under the EU regime
- Crypto Exchange Licensing for Early-Stage Founders – the licensing path for pre-institutional operators
FAQ
How long does a crypto licence take to obtain?
Timeline varies significantly by jurisdiction, licence category and the completeness of the application. In well-functioning regimes with a clear VASP or CASP authorisation path, the period from a complete submission to in-principle approval can run from a matter of weeks to several months. More complex structures – involving multiple licence layers, fit-and-proper vetting of multiple controllers or a novel business model – typically extend that timeline. Beginning the process before the intended go-live date by a substantial margin is essential.
Which jurisdiction is best for licensing my crypto business?
There is no universally best jurisdiction. The right answer depends on where your users are located, where your banking can be established, whether passporting reduces your total licence count, and the supervisory culture of the regulator relative to your business model. The EU's MiCA CASP regime offers passporting across the EEA. VARA in Dubai suits Gulf-facing businesses. MAS and the SFC serve Asia-Pacific operators. We map these variables against each client's specific profile before recommending a primary licensing jurisdiction.
Do I need a separate custody licence?
In most major regimes, custody of client virtual assets is a separately regulated activity. Under MiCA, providing custody and administration of crypto-assets for clients is a distinct CASP service requiring its own authorisation or an extension of an existing one. VARA, MAS and the SFC similarly treat custody as a standalone regulated function. An exchange that holds client assets on an omnibus basis – rather than directing them to a separately licensed custodian – will typically need custody authorisation in addition to the trading or exchange licence.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit, and we structure licensing, banking and tax as one mandate rather than three disconnected workstreams. To discuss your situation, contact info@oboluslaw.com.
By Aisha Tan, Licensing and Jurisdictions Analyst – specialising in multi-jurisdictional VASP and CASP authorisations for institutional and regulated-entity clients.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.