Crypto Exchange Licensing from a Cross-border Perspective
Operating a crypto exchange (a platform that matches buyers and sellers of digital assets or facilitates conversion between assets and fiat) across multiple markets is one of the most regulatory-intensive structures a business can attempt. The regulated perimeter shifts depending on where the entity sits, where users are located, where funds settle and where banking lives. A licence that satisfies one regulator may be invisible to the next. The stakes are concrete: operating without the right authorisation risks enforcement action, terminated banking relationships and frozen payment rails — losses that compound daily once they begin.
This page sets out the legal basis for crypto exchange licensing, the structure of a compliant cross-border operation, the process for obtaining regulatory authorisation (formal permission from a regulator to carry on a regulated activity), and the decisions operators must take before committing capital to an application.
What Activity Triggers a Licensing Requirement?
The regulated perimeter for a crypto exchange is activity-based, not entity-based. Matching buy and sell orders for digital assets, holding customer funds between trades, converting crypto to fiat and providing access to order books are each independently capable of triggering a licence obligation — in every jurisdiction where a user connects, not only where the operator is incorporated.
Under MiCA (the Markets in Crypto-Assets Regulation), the EU's harmonised regime administered by ESMA and national competent authorities, operating a crypto-asset trading platform requires CASP authorisation (Crypto-Asset Service Provider authorisation). The same legal person may be required to hold authorisation in the member state of establishment and to register with every national competent authority where it actively markets to users. Passporting reduces — but does not eliminate — the compliance burden.
Outside the EU, each major hub runs its own activity map. VARA (Dubai's Virtual Assets Regulatory Authority) operates an activity-specific licence model: exchange services, custody, transfer and settlement, and lending are each separately regulated. The BVI Financial Services Commission administers a registration track under the VASP Act 2022. In Singapore, the Monetary Authority of Singapore licenses digital payment token services under the Payment Services Act. In Hong Kong, the SFC runs a mandatory VATP (virtual-asset trading platform) licensing regime for platforms serving retail users.
The practical consequence: a business that onboards users from three regions simultaneously may face concurrent licence obligations in each. Operators we advise routinely discover mid-build that their initial entity design assumed one regulatory home when the user base required three.
For a first read on where your activity falls within the regulated perimeter, contact OBOLUS at info@oboluslaw.com. The process above describes the standard regulatory map. Your facts — the product, the user base, the settlement rails — change the analysis. Map your options.
Why a Single Licence Rarely Covers a Real Business
A common assumption in the market is that one well-chosen offshore registration is sufficient to serve clients worldwide. That assumption is incorrect and carries real enforcement risk.
Every meaningful licensing regime restricts the scope of permission to the jurisdiction that grants it. MiCA passporting, the clearest example of a multi-market right, applies only within the EU and EEA — it confers no permission to actively solicit users in Singapore, the UAE or the United States. VARA authorisation covers mainland Dubai activity; it does not extend to DIFC-based financial services, which are separately regulated by the DFSA. A BVI VASP registration confirms a baseline of AML-compliance recognition; it does not substitute for a local money-transmitter licence in a US state or for FCA registration in the UK.
The result, in practice, is a licence stack: a set of authorisations held across the operating entity, the custody vehicle and (where applicable) the payment or settlement layer, each licensed in the jurisdiction where that function is actually performed and where the users of that function are located.
In our cross-border practice, we work through three questions before advising on a licensing strategy:
- Where is each regulated activity actually performed — and by which legal entity?
- Where are users located, and do those jurisdictions impose a local-licence obligation on the platform serving them?
- Where does banking and settlement sit, and does that jurisdiction impose its own registration on the entity holding the account?
Each answer narrows the viable structure. Answering all three in sequence — before committing to a domicile — is the discipline that separates a durable structure from one that breaks at the first regulator inquiry.
How Does the Licence Application Process Work?
Obtaining a VASP registration (virtual asset service provider registration, the most common form of authorisation for smaller exchanges) or a full exchange licence follows a broadly consistent process across the major hubs, though timelines and documentary requirements differ materially.
The standard stages are:
- Pre-application structuring. Entity incorporation, ownership structure and the fitness-and-propriety profile of directors and beneficial owners are fixed before the application is filed. Regulators review the entire group structure, not only the applicant entity. A holding company with an unsuitable shareholder in a non-cooperative jurisdiction will delay or block approval.
- Policy and control documentation. An AML/CFT programme, a Travel Rule compliance procedure — the Travel Rule being the obligation to pass originator and beneficiary data with a virtual-asset transfer — and an operational risk framework must be finalised and board-adopted before submission.
- Application filing and regulatory dialogue. The regulator reviews the application, issues queries and may request revised documentation. This stage is where most applications stall. Regulators at the leading hubs increasingly expect evidence of operational readiness, not only paper policies.
- Approval and conditions. Authorisation typically arrives with conditions — minimum capital maintenance, reporting obligations, periodic audits. These must be built into the operating budget from day one.
Timelines vary by category and jurisdiction and should be confirmed with current regulatory guidance before any business plan is committed. In our experience, operators that engage legal counsel before designing the entity structure rather than after filing the first application consistently achieve faster approvals and fewer condition letters.
Which Jurisdiction Should You Choose — and for Which Function?
There is no single best jurisdiction for licensing a crypto exchange. The right answer depends on the operator's business profile, user base, capital position and banking requirements. What follows is a practical decision matrix across the profiles we see most often in our practice.
Profile A — EU-market-facing exchange, institutional and retail. MiCA CASP authorisation in a member state with a well-resourced national competent authority gives full EU passporting rights. The application is document-intensive and the capital requirements vary by licence class, but the single-passport outcome is the most efficient structure for a business whose primary users are in Europe. Indicative timeline for a full CASP authorisation: a matter of months following a complete file submission, subject to regulatory workload at the relevant NCA. Key risk: post-authorisation compliance obligations under ESMA guidelines are ongoing and resource-intensive.
Profile B — MENA-facing exchange, seeking a regulated hub with clear activity rules. VARA (Dubai) offers a well-defined activity-based licence map and a regulator that is actively resourced for crypto businesses. The VARA regime suits an operator wanting a mainstream Gulf presence with a credible regulatory mark. Custody, exchange and transfer activities each require a separate authorisation. Key risk: the scope of VARA authority does not extend to DIFC; a dual-hub structure requires parallel engagement with the DFSA.
Profile C — Asia-Pacific exchange, institutional focus. Singapore's MAS Payment Services Act regime and Hong Kong's SFC VATP licensing are the two primary frameworks. Singapore offers a well-developed framework for digital payment token services with MAS's established track record. Hong Kong's regime, post-2023, is mandatory for platforms serving retail users in Hong Kong. Operators serving both markets typically need both licences — the regimes do not passport between jurisdictions. Key risk: both regulators apply substantial fitness-and-propriety scrutiny to controllers and key individuals.
Profile D — Early-stage operator, primarily B2B or institution-only. A BVI VASP registration under the VASP Act 2022, combined with a well-drafted user-access policy that excludes restricted jurisdictions, provides a recognised compliance baseline while the business builds capital and a compliance track record. Key risk: the BVI registration is not a licence for active retail solicitation in major markets; it must be paired with legal geo-restriction enforcement and ongoing market monitoring.
In each profile, the custody function deserves a separate analysis. Where an exchange holds client assets — even briefly between trade and settlement — a custody licence obligation may arise independently of the trading platform licence.
What Are the Most Common Licensing Mistakes Operators Make?
The most expensive licensing mistakes we encounter are structural, not procedural — they are built into the entity design before any application is filed.
Mistake 1: Conflating incorporation with authorisation. An entity incorporated in a crypto-friendly jurisdiction is not automatically authorised to carry on regulated activity. Incorporation is a legal prerequisite, not a substitute for a licence. We regularly advise operators who built and launched on the assumption that their registered office address conferred regulatory standing.
Mistake 2: Overlooking the custody trigger. An exchange that holds user funds between order matching and settlement is performing a custody function. In most flagship regimes, custody is a separately regulated activity. An operator holding a trading platform licence without a custody authorisation may be operating unlawfully — and may not realise it until a banking partner or auditor raises the point.
Mistake 3: Failing to map the user base before choosing a domicile. Choosing a domicile for tax or cost reasons without first mapping where users will connect produces a licensing gap. If a significant proportion of users are in the EU, MiCA applies regardless of where the entity sits. If US persons access the platform, FinCEN, SEC and state money-transmitter considerations arise on the US side.
Mistake 4: Treating Travel Rule compliance as a post-licence problem. FATF Recommendation 15 and the Travel Rule are AML/CFT requirements that regulators expect to be operational at the point of authorisation, not implemented later. An application that describes the Travel Rule as a future project consistently attracts additional regulatory scrutiny and conditions.
A micro-matter from our practice: in a recent application matter, a payments company had structured its exchange entity in a well-regarded EU jurisdiction but had inadvertently placed the custody function in a holding company that held no authorisation in any market. We identified the gap during a pre-filing review, restructured the custody vehicle into a separately authorised subsidiary, and the consolidated application proceeded to approval without a custody-related condition. The restructuring added several weeks to the preparatory timeline — but months less than a remediation process after filing would have required.
How Do AML and the Travel Rule Interact with Exchange Licensing?
AML/CFT compliance and the Travel Rule are not ancillary to exchange licensing — they are conditions embedded in the authorisation itself, and their adequacy is assessed at application, at periodic review and at any supervisory inspection.
Under the FATF framework — specifically FATF Recommendation 15, which applies virtual asset service providers to the full FATF standards — an exchange must conduct customer due diligence, monitor transactions for suspicious activity and transmit originator and beneficiary information with each qualifying transfer. The de-minimis threshold above which the Travel Rule applies varies by jurisdiction and should be confirmed from current regulatory guidance rather than assumed.
In our cross-border practice, Travel Rule compliance raises a specific cross-border complication: the obligation to transmit data applies to transfers between VASPs, but not all counterparty VASPs are registered or identifiable. Where a counterparty VASP cannot be verified, the originating VASP must apply a risk-based approach — which must itself be documented and proportionate. Regulators increasingly scrutinise the quality of that risk-based approach, not merely whether a Travel Rule policy exists on paper.
The interaction with licensing is direct: a Travel Rule solution must be in place and tested before application. An exchange applying for CASP authorisation under MiCA, for VARA licensing in Dubai or for SFC approval in Hong Kong without a demonstrably operational Travel Rule procedure will consistently attract regulator queries and conditions that extend the approval timeline.
If your Travel Rule implementation or AML programme is not yet licence-ready, contact OBOLUS at info@oboluslaw.com before you file. A prior application that stalled on AML grounds often has a structural cause — a second read can surface the issue and the route forward. Map your options.
How Do Banking and Tax Sit Around a Cross-Border Licence?
A licence without banking is inoperable. This is one of the most consistent pain points for newly licensed exchanges, and one the regulatory framework itself does not solve.
Regulated exchanges require fiat banking to process user deposits and withdrawals, to pay staff and suppliers and to segregate client funds. Banks globally have applied heightened due diligence to crypto-exchange accounts — not uniformly, but consistently enough that securing a banking relationship is often a longer and more conditional process than obtaining the licence itself. Operators we advise are routinely surprised to find that a newly granted licence from a credible regulator does not automatically open banking doors.
The cross-border angle intensifies this. An exchange licensed in Singapore, banking in a third jurisdiction and settling in USDC through a US-based stablecoin issuer is simultaneously a customer of three separate compliance programmes. Each relationship must independently satisfy its counterpart's AML and risk appetite — a process that requires documented compliance infrastructure, not merely a licence certificate.
On tax: the jurisdiction of licensing and the jurisdiction of taxable profit are not the same question. A VARA-licensed Dubai entity may be tax-resident in the UAE — where corporate tax obligations now apply — while its parent holding company sits in a jurisdiction with a different tax treatment for dividend flows and capital gains. The licence decision and the holding structure decision must be coordinated, not treated as sequential. We map the licence, banking and tax stack together before any commitment is made.
Separately, token classification for accounting and tax purposes affects the exchange directly: whether digital assets held by the exchange are treated as inventory, financial instruments or intangible assets varies by jurisdiction, and the treatment affects capital adequacy reporting and tax liability simultaneously.
A Common Assumption — and Why It Does Not Hold
A common assumption among early-stage exchange operators is that the licensing process can be handled internally by the compliance team once the build is complete. In our experience, this assumption consistently produces delayed timelines and avoidable conditions.
Regulators at the leading hubs — ESMA's national competent authorities under MiCA, VARA, MAS, the SFC — have raised the evidentiary standard for exchange licence applications materially over the past several years. An application now requires board-level governance documentation, substance in the licensing jurisdiction, demonstrably operational AML and Travel Rule procedures, and a management team whose fitness and propriety can be evidenced through documentation, not asserted. Compliance teams building the application while simultaneously building the product will struggle to meet that standard on the first filing.
Early legal engagement — at the entity-design stage, before domicile is committed — consistently reduces total time from concept to authorisation, because structural problems identified before filing take days to correct; the same problems identified by the regulator take months.
We map the licence stack across operating, custody and payment layers before you commit. That is the engagement model that produces approvals rather than conditions.
Related at OBOLUS
- Licensing & Registration for Digital-Asset Businesses – the full OBOLUS licensing practice across 70+ jurisdictions and licence categories
- VARA Licence Application in Luxembourg – jurisdiction-specific analysis of the VARA licensing process and requirements
- Sanctions Screening for Crypto in Brazil – AML and sanctions compliance for digital-asset businesses operating in the Brazilian market
FAQ
How long does a crypto licence take to obtain?
Timelines vary materially by jurisdiction, licence category and the completeness of the application file at submission. A well-prepared application to a major regulator — ESMA's national competent authorities under MiCA, VARA or the MAS — typically takes a matter of months from a complete submission to a decision. Incomplete files, structural issues with the applicant entity or AML programme gaps each extend that timeline. Early legal preparation is the single most reliable way to compress the process.
Which jurisdiction is best for licensing my crypto business?
There is no universal answer. The right jurisdiction depends on where your users are, which regulated activities your product performs, your capital position, your banking requirements and your tax structure. For an EU-facing retail exchange, MiCA CASP authorisation offers passporting efficiency. For a MENA-focused platform, VARA's defined activity model is well-suited. The correct answer for your business requires mapping all four factors against each other — not selecting a jurisdiction for cost reasons alone.
Do I need a separate custody licence?
In most flagship licensing regimes, yes. Where an exchange holds client assets — including during the period between order matching and settlement — a custody function arises. Custody is a separately regulated activity under MiCA, VARA, and the SFC regime in Hong Kong, among others. An exchange licence without a custody authorisation in those jurisdictions does not cover asset safeguarding. The two applications can often be filed concurrently, but the custody function must be assessed separately from the trading platform activity.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across more than seventy jurisdictions, on disputes and on-chain asset recovery across more than twenty-five forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit — a discipline that consistently reduces the distance between a concept and an authorisation. To discuss your situation, contact info@oboluslaw.com or reach us at t.me/oboluslaw.
By Aisha Tan, Licensing & Jurisdictions Analyst — specialising in cross-border exchange authorisation strategy, VASP registration and multi-hub licence stack design for digital-asset businesses.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.