EST · MMXXVI
Home/Services/Licensing Registration/Crypto exchange licensing under Heightened Scrutiny
Licensing & Registration

Crypto exchange licensing under Heightened Scrutiny

Crypto exchange licensing under Heightened Scrutiny. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS

What "heightened scrutiny" means for a crypto exchange licence

Regulators in every major hub have moved crypto exchange licensing from a notification regime to a full merit-based authorisation process. A crypto exchange now faces the same fitness-and-propriety, capital adequacy and AML/CFT interrogation that a traditional payment institution would face – often with additional layers specific to virtual assets. In our licensing practice, we see applicants underestimate the gap between submitting an application and receiving approval. The process above describes the standard path. Your facts – the entity, the user base, the banking – change the analysis.

An exchange that operates without the correct regulatory authorisation (the positive permission to carry out regulated virtual-asset activities) does not simply face a warning. It faces enforcement action, account termination by its banking partners, and potential personal liability for directors. That risk compounds when the business has users in multiple jurisdictions, each with its own VASP (virtual asset service provider) registration or licensing requirement.

The following sections map the current regime, the process, the most common structural errors and the cross-border realities that determine whether a licence actually works in practice.

What activities trigger a licensing obligation?

The answer depends on the jurisdiction, but the convergence across leading regimes is striking. Under MiCA, the EU's Markets in Crypto-Assets Regulation supervised by ESMA and national competent authorities, operating a crypto-asset trading platform is a regulated activity requiring CASP authorisation (Crypto-Asset Service Provider). Under the VARA regime in Dubai, exchange services are one of several activity-based licence categories. MAS in Singapore captures crypto exchange functionality under Digital Payment Token service licensing within the Payment Services Act framework. The SFC in Hong Kong requires a VATP (virtual-asset trading platform) licence. Across all of them, the trigger is the same in substance: intermediating trades between buyers and sellers of virtual assets for commercial benefit.

The perimeter expands quickly for a multi-product exchange. Order-book trading, OTC desks, earn products, staking-as-a-service, lending and fiat on-ramps each attract distinct licence categories in at least some of the major frameworks. An exchange that adds a yield product mid-operation without revisiting its licence scope is a pattern we encounter regularly. The regulatory consequence ranges from a variation requirement to a stop notice.

Custody deserves separate treatment. Most leading regimes classify the safekeeping of client virtual assets as a standalone regulated activity. An exchange that holds client keys – even as a byproduct of operating the trading layer – is also acting as a custodian. We return to this when discussing the decision matrix below.

What triggers heightened scrutiny on a crypto exchange application?

A "heightened scrutiny" designation is not always a formal label – it describes the material increase in review depth that regulators apply to crypto exchange applications relative to other financial services applications. Several factors trigger this elevated review, and understanding them determines how a well-prepared application is assembled.

First, business model risk. An exchange that lists a large number of tokens, including tokens of unclear classification, will face detailed questions about the process by which it assesses whether a token is a security, an ART, an EMT or an "other" crypto-asset under the applicable regime. Regulators do not want to inherit the classification problem. The application must demonstrate a repeatable, documented listing process.

Second, financial crime risk. Exchanges are the primary point of fiat-to-crypto conversion and therefore the primary vector for money laundering in the digital-asset sector. Under the Travel Rule (the obligation under FATF Recommendation 15 to pass originator and beneficiary data with a virtual-asset transfer), a licensed exchange is obligated to collect, screen and transmit counterparty data. Regulators will examine the technical and operational readiness of the applicant to fulfil this obligation from day one of operation.

Third, governance and beneficial ownership transparency. In our practice, the most common cause of application delay is incomplete or inconsistent disclosure of the ownership chain. Where a layered holding structure sits between the exchange and its ultimate beneficial owners, every layer must be documented and every owner above the relevant threshold must pass a fit-and-proper assessment. If there is a sanctioned jurisdiction in the ownership chain, the application will stall irrespective of the quality of the business plan.

Fourth, the cross-border user question. A regulator authorising an exchange in its jurisdiction expects that exchange to have analysed where its users are located and to have a plan for each significant user jurisdiction. An exchange licensed in Lithuania that markets to users in Germany, France and the Netherlands is exercising EU passporting rights – which is a defined process under MiCA. An exchange licensed in ADGM that markets to users outside the UAE must have mapped the applicable restrictions. Presenting that analysis proactively transforms a scrutiny risk into a demonstrable competence.

To discuss how these factors apply to your specific application, contact OBOLUS at info@oboluslaw.com. The process above maps the general path. Your specific ownership structure, product set and user geography will each carry their own analytical weight.

How does the crypto exchange licensing process work in practice?

The licensing process for a crypto exchange under heightened scrutiny follows a common architecture across the leading regimes, even though the specific requirements vary. The stages are: pre-application engagement, document assembly, formal submission, regulator review, clarification rounds and – where approval is granted – conditions fulfilment before the licence takes effect.

Pre-application engagement is not optional in most leading jurisdictions. VARA in Dubai, FSRA in ADGM and the FCA in the UK all maintain structured pre-application processes. MAS in Singapore expects applicants to engage through its formal gateway. In our experience, exchanges that skip this phase waste significant time responding to preliminary questions that a direct conversation would have resolved in days.

The document set for a crypto exchange application is substantially larger than for a standard payment institution. Expect the regulator to require: a detailed business plan covering all product lines; AML/CFT policies and procedures specific to virtual assets; a Travel Rule compliance architecture; governance documents and organisational charts; a capital adequacy calculation and supporting evidence; individual questionnaires for each director, controller and key function holder; cybersecurity and technology risk documentation; a token listing policy; and a client asset protection framework addressing how client virtual assets are held and segregated.

Each jurisdiction sets its own review timeline. These vary and are subject to the completeness of the application, the regulator's current caseload and the number of clarification rounds required. The practical reality is that a well-prepared application moves faster than one that is submitted speculatively and then revised iteratively. We have seen applications stall for a period running to many months where the initial submission was incomplete on ownership or AML policy grounds.

Post-approval, most regimes impose conditions that must be satisfied before the licence becomes active. These include demonstrating that minimum capital is in place, that the technical infrastructure meets prescribed standards, and that key function holders have completed vetting. The gap between approval and operational authorisation is a phase that well-run applications plan for from the outset.

What are the most common mistakes in a crypto exchange licensing application?

In our licensing practice, the errors that delay or derail crypto exchange applications fall into a consistent pattern. Identifying them early is the purpose of a pre-engagement review.

The most frequent single cause of rejection or material delay is inadequate AML/CFT documentation. A policy that is generic – adapted from a template not specific to virtual assets – will not satisfy a regulator applying heightened scrutiny. The policy must address Travel Rule compliance technically, describe the specific screening tools in use, and be proportionate to the actual product mix. A platform offering perpetual futures requires a different risk framework from a spot-only exchange.

The second most common issue is capital structure misalignment. An applicant that plans to hold client assets through the exchange entity, rather than through a separate regulated custodian, must be capitalised appropriately for both the exchange and custody activities. Operators who design the capital structure without this in mind face a restructuring requirement mid-application.

Third: premature launch. Operating in a jurisdiction before the licence is in place – even in beta, even to a limited user group – is a material enforcement risk. Some regulators apply a strict liability standard. The existence of a pending application does not provide a defence to operating without authorisation.

A micro-matter from our recent practice: an exchange operator had obtained registration in one EU member state and was accepting users from across the bloc. The operator assumed that registration created automatic rights to passport the service. Under the MiCA CASP framework, passporting requires a positive notification process through ESMA and the host NCA. We identified the gap during a cross-border compliance review, structured the passporting notifications before the operator's launch in two further member states, and the operator proceeded without enforcement exposure.

How does the multi-jurisdiction reality affect crypto exchange licensing?

The cross-border dimension is where crypto exchange licensing under heightened scrutiny departs most sharply from traditional financial services licensing. A conventional broker can often identify its regulatory perimeter by reference to where it is established and where it is actively marketed. A crypto exchange faces a harder question: the internet is always the distribution channel, and the exchange may have users in jurisdictions it has not actively targeted.

The operative principle across VARA, MiCA, MAS and the SFC regime is that the relevant test is where the service is received, not merely where it is marketed. An exchange established in the BVI under the VASP Act that has significant user populations in Singapore or Hong Kong is within the supervisory perimeter of MAS or the SFC, regardless of the BVI registration. Most regulators have published guidance on the geolocation and IP-blocking measures they expect exchanges to implement for jurisdictions where they do not hold a licence.

For a business that intends to serve users in multiple regulated jurisdictions, the licensing question therefore becomes a licensing stack. The typical architecture for a multi-jurisdiction exchange involves: an EU CASP authorisation (for the EU user base, with MiCA passporting), a UAE licence for the MENA segment (VARA or FSRA depending on where the entity sits), a Singapore DPT licence for Southeast Asia, and a separate entity structure for jurisdictions where the regime is not yet settled. That stack has tax and banking implications at each layer. We regularly advise on the interaction between the jurisdictional licensing choices and the group's banking and tax position.

For operators that cannot immediately achieve the full stack, the priority question is: which user jurisdictions carry the highest enforcement risk? The answer is not simply the largest markets. It is the jurisdictions with the most active enforcement posture and the lowest threshold for extra-territorial jurisdiction claims. VARA and the SFC have both demonstrated willingness to pursue operators that serve their user populations without authorisation.

Allied counsel in the relevant jurisdiction is essential where the operator's licensed entity has no physical presence. Regulators in the leading hubs are increasingly expecting local substantive presence, not merely a registered address.

Which licensing approach fits which exchange profile?

The right licensing path depends on the exchange's product architecture, user geography and capital position. The following profiles describe the most common configurations we encounter, each requiring a different approach to the licence stack.

Profile A – Spot-only exchange, EU focus, seeking EU passporting rights. The path here runs through MiCA CASP authorisation in a member state. The choice of NCA (national competent authority) depends on the quality of the local regulatory process and the applicant's ability to establish substantive local presence. The timeline from a complete application to operational authorisation varies, but applicants should plan for a process measured in months, not weeks, with conditions attached. The key risk is underestimating the AML and Travel Rule documentation requirements. We map the NCA selection and the full document set before submission.

Profile B – Multi-product exchange (spot, derivatives, earn), global user base. This profile requires a multi-entity structure. The EU component needs CASP authorisation. The MENA component needs a VARA or ADGM-FSRA licence, depending on whether the entity is in mainland Dubai or within ADGM. The Southeast Asia component needs a MAS DPT licence. The governance and capital requirements at each layer must be designed as a coherent group structure, not as independent applications. The cross-entity custody arrangement is the most structurally complex element.

Profile C – Exchange operating in the AIFC in Kazakhstan, targeting CIS and Central Asian users. The AFSA within the AIFC operates a digital-asset trading facility concept under a common-law framework. For operators targeting this region, the AIFC structure offers a common-law anchor, exchange and custody licence options, and a banking environment that is distinct from the EU or UAE. The interaction between an AIFC licence and the applicable AML/CFT requirements for the target user base requires careful analysis of the Travel Rule obligations applicable to each user jurisdiction.

Profile D – Exchange seeking a lightweight offshore registration while building toward a full licence. BVI FSC registration under the VASP Act and CIMA registration in the Cayman Islands under the Virtual Asset (Service Providers) Act are used by operators at earlier stages of development. These registrations are not equivalent to a CASP authorisation or a MAS DPT licence. An exchange that routes material user volume from regulated markets through an offshore registered entity without the underlying jurisdiction's licence is taking on the enforcement risk described above. The offshore structure can be a transitional step, not a permanent solution.

If a prior application stalled or your banking relationship was closed, a second-read review can identify the structural cause. Write to OBOLUS at info@oboluslaw.com or message us via t.me/oboluslaw.

A common assumption: a single offshore licence covers global operations

A common assumption among exchange founders is that obtaining a licence in a single offshore jurisdiction – or even in one of the leading hubs – creates a compliant basis to serve users globally. It does not.

Regulatory authorisation is territorial. A CASP authorisation in Estonia (now transitioning to full MiCA compliance) covers the EU/EEA under the passporting mechanism – but only for the activities and categories covered by the authorisation and only after the passporting notification process is complete. It creates no rights in Singapore, no rights under the VARA regime, and no safe harbour from the FCA's financial promotion rules for UK users.

The practical consequence is that an exchange with a single licence and a global user base is unlicensed in the majority of the jurisdictions where it operates. Enforcement in those jurisdictions proceeds independently. A VARA enforcement action in Dubai is not stayed because the exchange holds a MiCA CASP authorisation in Lithuania. The regulators are different legal entities with different enforcement mandates.

We map the user base against the licensing requirement before an operator commits to a structure. This analysis is the foundation of a defensible global compliance position – and the step most often skipped by operators building on a compressed timeline.

Related at OBOLUS

FAQ

How long does a crypto licence take to obtain?

The timeline varies materially by jurisdiction, regulator capacity and application completeness. In the leading hubs, a well-prepared application with complete ownership documentation and a compliant AML policy typically moves faster than one submitted speculatively. Operators should plan for a process measured in months from formal submission to operational authorisation. Pre-application engagement and document preparation add to the overall timeline and are not optional in most leading frameworks. We assess indicative timelines in the pre-application phase.

Which jurisdiction is best for licensing my crypto business?

There is no universally correct answer. The right jurisdiction depends on your product architecture, your target user base, your capital position and where your banking relationships live. An EU CASP authorisation under MiCA offers passporting across the bloc. VARA in Dubai and the FSRA in ADGM serve the MENA market. MAS in Singapore is the standard gateway for Southeast Asia. We map the trade-offs across the leading options before an operator commits, including the tax and banking implications at each layer.

Do I need a separate custody licence?

In most leading regimes, yes – if the exchange holds client virtual assets on their behalf. Under MiCA, custody and administration of crypto-assets is a distinct regulated service requiring its own CASP authorisation or a specific authorisation scope. VARA, the FSRA and MAS treat custody as a standalone regulated activity. An exchange that holds client keys is acting as a custodian, regardless of whether it calls itself one. We assess the custody perimeter as part of every exchange licensing engagement.

About OBOLUS

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit – so the structure works from day one, not after the first enforcement letter. We also work alongside forensic partners to convert on-chain evidence into court-ready disclosure applications where recovery matters arise. To discuss your situation, contact info@oboluslaw.com.

By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in multi-hub VASP authorisation strategy and cross-border licensing stack design for exchange and custody operators.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours