EST · MMXXVI
Home/Services/Licensing Registration/Licence renewal and variation for Established Operators
Licensing & Registration

Licence renewal and variation for Established Operators

Licence renewal and variation for Established Operators. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OB

Licence renewal and variation for Established Operators

An established digital-asset operator already carries a VASP registration (virtual asset service provider authorisation) or a CASP authorisation (Crypto-Asset Service Provider licence under the MiCA regime). What it may not carry is the right scope for what the business does today. Regulatory authorisation granted two or three years ago rarely mirrors the current product set, jurisdictional footprint or user volume. The gap between the licence as issued and the business as operated is where enforcement risk accumulates – quietly, until it does not.

This page sets out the renewal and variation process for operators with an existing licence, the cross-border complexity that built business creates, the most common errors we see at this stage, and a decision matrix for matching your profile to the right next step.

Why renewal and variation matter more than initial licensing

The first licence application is a threshold decision. Renewal and variation, by contrast, are operational discipline – and the stakes are higher because the business is live. A regulator reviewing a renewal or a variation request is reading it against the entire operating history to date: past filings, incident reports, complaint volumes, audit findings and AML programme performance. That review can surface a gap the operator assumed was covered.

As major hubs tighten supervision under MiCA and the VARA rulebooks, the expectation is not just that you renew on time. It is that you demonstrate continuous compliance across the licence period. Operators who treat renewal as a form-filling exercise – rather than a structured regulatory event – routinely discover problems that a proactive review would have caught months earlier.

We regularly advise businesses that secured an initial registration in a lighter-touch regime and now face a conversion deadline: the regulator is withdrawing the transitional window and requiring full authorisation. The renewal and the upgrade are the same event. Missing that window means operating without a valid licence, which carries enforcement consequences that can include suspension, public censure and in some regimes criminal liability for the responsible managers.

What triggers a variation request?

A variation is required whenever the operator proposes to conduct an activity that falls outside the express scope of the current authorisation – or whenever a material change to the business model, ownership or structure occurs. The specific triggers differ across regimes, but the categories are consistent across the leading hubs.

Common variation triggers in our practice include:

  • Adding a custody function to an exchange-only licence
  • Expanding into lending, margin or staking services not covered by the original application
  • Onboarding institutional clients where the licence was issued for retail scope only
  • A change of control, merger, or acquisition that alters the ultimate beneficial owner profile
  • Relocating the regulated entity or its senior management to a different jurisdiction
  • Adding a new fiat currency pair or an asset class not listed in the original application

Under MiCA, the CASP authorisation specifies the crypto-asset services the firm may provide. Providing a service not listed – even temporarily while a variation is in review – is unlicensed activity. Under the VARA activity-based model in Dubai, each activity (advisory, broker-dealer, custody, exchange, lending, transfer and settlement) requires its own approval within the licence structure. Operators expanding their Dubai offering without updating the activity permissions face a clear compliance gap.

The same logic applies in Singapore under the Payment Services Act, where the tier of the licence (major payment institution versus standard payment institution) controls the permissible transaction volumes. An operator whose volumes have grown past the standard threshold must upgrade the licence proactively – not after the fact.

The process above describes the standard path. Your facts – the entity type, the jurisdictions, the user base and the banking arrangements – change the analysis materially. For a scoped assessment of where your current licence sits against your current operations, contact OBOLUS at info@oboluslaw.com.

What does the renewal process look like in practice?

Renewal timelines vary across regimes, but the procedural structure is similar. A well-run renewal follows five stages: pre-submission audit, document assembly, regulator dialogue, review and determination, and post-renewal compliance mapping.

Stage one: pre-submission audit. Before preparing any renewal filing, we map the gap between the current licence and the current business. This includes reviewing the original authorisation conditions, the operational changes since issuance, AML/CFT programme updates, board and senior management changes, and any incidents reported to the regulator or internally flagged. If a variation is also needed, that is identified at this stage – not after the renewal has been submitted.

Stage two: document assembly. Renewal packs typically require updated financial statements, refreshed fit-and-proper evidence for responsible managers, an updated AML/CFT policy suite, a compliance report covering the licence period, and a written narrative addressing any conditions attached to the original authorisation. Under MiCA, the CASP renewal framework requires the NCA to be satisfied that the firm continues to meet all initial authorisation conditions. Under VARA, the renewal and fee cycle follows a structured annual timeline.

Stage three: regulator dialogue. Regulators in leading hubs increasingly expect dialogue before the formal renewal submission – not just the filing itself. In our cross-border practice, we have seen renewal applications move significantly faster when the operator has proactively flagged issues in advance and proposed remediation steps, compared with those that surface problems only under review.

Stage four: review and determination. The regulator's review window varies qualitatively by jurisdiction and by complexity. A straightforward renewal with no outstanding conditions or incidents typically concludes faster than one that flags a material change or requires an additional inspection. For operators managing licences across multiple jurisdictions, the review windows rarely align – creating a period when some licences are active, some are under review and some have lapsed pending renewal. That gap requires careful operational management.

Stage five: post-renewal compliance mapping. Renewal is not the end of the cycle. The conditions attached to the new term – updated or additional – need to be wired into the compliance programme. We build a conditions register after every renewal that maps each condition to the team member, system or process responsible for it.

How does cross-border complexity affect established operators?

An established operator almost always operates across more than one regulatory perimeter. The entity may be licensed in the EU under MiCA, hold a VARA authorisation in Dubai, and rely on an offshore registration in the BVI or Cayman Islands for fund-facing structures. Each of those licences runs on its own renewal cycle, managed by a different regulator, requiring different documentation.

The cross-border reality creates three compounding risks for operators who manage renewals in isolation.

First, a condition added to the Dubai licence may conflict with the structural requirements of the MiCA authorisation. AML programme standards, data-localisation rules and user-disclosure obligations are not uniform across regimes. Where they diverge, the higher standard must prevail – which may require amending the programme before either licence renews.

Second, banking is a licence-adjacent risk that established operators often underestimate. A renewal filing that discloses a change in banking relationships – particularly a shift to a crypto-friendly institution that the regulator views as lower-grade – can trigger an inquiry that delays the renewal. We map banking arrangements alongside the licence review, not separately.

Third, the Travel Rule (the obligation to pass originator and beneficiary data with a virtual asset transfer, derived from FATF Recommendation 15) is increasingly an enforcement focus at renewal. Regulators in Singapore, the EU and Hong Kong have made Travel Rule compliance a specific renewal condition. Operators whose technical implementation was provisional at initial licensing face a harder conversation at renewal if the implementation has not matured.

In a recent matter, an exchange operator held registrations across three jurisdictions. Two were due for renewal in the same quarter. During our pre-submission audit, we identified that a product added the prior year was not within the scope of any of the three authorisations. We advised on the variation filings in parallel with the renewals, sequenced the submissions to minimize the period of operational exposure, and worked with allied counsel in the relevant jurisdictions to align the AML programme updates across all three regimes. All three renewals completed without conditions being added.

If a renewal filing is approaching or a product gap has been identified, the earlier we engage, the more options remain available. Write to OBOLUS at info@oboluslaw.com to scope the review.

What are the most common mistakes established operators make at renewal?

Operators who have managed their own licence for several years sometimes approach renewal with a confidence that the process does not warrant. These are the errors we see most frequently.

Treating renewal as administrative. The renewal is a new regulatory decision. The regulator has the power to add conditions, reduce scope, or – in cases of serious concern – refuse renewal. An operator that submits a thin renewal pack, assuming approval is automatic, is taking a material risk.

Missing variation triggers. The product or service has evolved. The original licence has not. Operators often do not connect a new feature launch to a licence variation obligation, particularly when the legal team is not integrated with the product team. By the time renewal arrives, the operator has been conducting an unlicensed activity for months.

Stale fit-and-proper evidence. Responsible managers change. Directors join and leave. Fit-and-proper submissions that were accurate at initial licensing may no longer reflect the current board. Submitting renewal documentation with a stale management structure is a straightforward rejection risk.

AML programme drift. The AML/CFT programme approved at licensing reflected a specific product set and customer base. As the business grew, transaction volumes increased, new asset classes were added and the customer risk profile changed – but the programme was not updated to match. Renewal forces a reconciliation the operator would rather have controlled on its own timeline.

Ignoring the conditions register. Every licence is issued with conditions. Some are standard; others are bespoke to the application. Operators who cannot produce a coherent record of how each condition was met during the licence period face difficulty during renewal review.

Decision matrix: which path fits your profile?

Not every established operator faces the same renewal and variation challenge. The appropriate approach turns on four variables: the number of active licences, the regulatory complexity of the business model, the time remaining before the next renewal deadline, and whether a variation is needed alongside renewal.

Profile A – Single licence, renewal only, no product changes. The operator holds one registration in a single regime, the product set has not changed materially, and the renewal deadline is approaching. The priority is a structured pre-submission audit to confirm that the conditions register is complete, the AML programme is current and fit-and-proper evidence is refreshed. The process is straightforward but should not be delegated entirely to a compliance team without legal oversight. Timeline: allow adequate runway before the expiry date to address any gaps identified in the audit.

Profile B – Single licence, renewal plus variation required. The operator has launched a new service – custody, lending or a new asset class – that falls outside the current scope. The variation must be submitted before or alongside the renewal, and the regulator will review the new activity against the initial authorisation conditions as well as the operating history. This is a more demanding filing. Legal drafting of the variation narrative and regulatory dialogue support are material to the outcome.

Profile C – Multiple licences across jurisdictions, renewals unsynchronized. The operator holds licences in two or more regimes, each with different renewal cycles. The cross-jurisdictional AML programme must be consistent across all of them. The priority is a multi-licence audit that maps all renewal deadlines onto a single timeline, identifies interdependencies between regimes, and sequences submissions to avoid operational gaps. Allied counsel in the relevant jurisdictions coordinates on local procedural requirements.

Profile D – Transitional window expiring, conversion to full authorisation required. The operator registered under a lighter transitional regime and now faces a conversion deadline under MiCA, VARA or another upgrading framework. The renewal and the upgrade are a single combined event. This is the highest complexity profile. Capital requirements, governance standards and compliance programme depth are all under review simultaneously. Early engagement – ideally six or more months before the deadline – is essential.

A common assumption: one offshore licence covers global operations

A common assumption among established operators is that a single registration – typically in a light-touch offshore jurisdiction – is sufficient to serve clients globally, particularly if the entity does not have a physical presence in the clients' home countries. This assumption is incorrect and carries serious operational consequences.

Most leading regimes – MiCA, the VARA framework, the Singapore Payment Services Act, and the Hong Kong VASP licensing regime – apply to the provision of services to clients located in those jurisdictions, regardless of where the operator is incorporated. Active marketing, onboarding, or providing exchange, custody or transfer services to users in a regulated jurisdiction without the relevant authorisation is unlicensed activity under that jurisdiction's law.

The practical consequence is that an established operator relying on a single offshore registration may have been conducting unlicensed activity in multiple jurisdictions for years, without enforcement action. Enforcement action can arrive as a result of a user complaint, a banking suspicious activity report, a cross-border information request between regulators, or a referral from a law-enforcement agency. At that point, the operator is not in a position of proactively renewing and varying – it is responding to an investigation.

In our practice, we map the full licence stack before any renewal filing: the jurisdictions where the entity is licensed, the jurisdictions where clients are located, and the jurisdictions where the banking and payment rails sit. That mapping frequently identifies a variation or an additional registration that should have been filed earlier. The earlier it is identified, the more measured the remediation path.

Related at OBOLUS

FAQ

How long does a crypto licence take to obtain?

Timelines vary materially by jurisdiction, licence category and application completeness. In lighter-touch offshore regimes, registration can complete in a matter of weeks. In major hubs – under MiCA, VARA or the Singapore Payment Services Act – full authorisation typically takes several months, and in complex cases longer. Renewal timelines are generally shorter than initial authorisation, provided the operator's compliance record is clean and documentation is complete. Engage your legal team well in advance of any deadline.

Which jurisdiction is best for licensing my crypto business?

There is no universal answer. The optimal jurisdiction turns on the operator's business model, target client base, banking relationships and capital position. MiCA provides EU-wide passporting for operators based in a member state. VARA and ADGM serve operators focused on the Gulf. Singapore and Hong Kong anchor the Asia-Pacific licensing stack. A multi-jurisdiction operator typically holds more than one licence. We map the licence, banking and tax stack against the specific business model before advising on jurisdiction selection.

Do I need a separate custody licence?

In most leading regimes, custody of virtual assets is a distinct regulated activity that requires either a separate authorisation or an explicit extension of an existing licence. Under MiCA, custody and administration of crypto-assets is a named CASP service. Under VARA, custody is a separate activity licence. Under the Singapore Payment Services Act and the Hong Kong VASP framework, safeguarding of client assets is subject to specific regulatory requirements. Operating custody services under an exchange-only licence is a common and consequential variation error.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the entirety of our practice, and we act only for businesses – not retail clients. We map the licence stack across operating, custody and payment layers before you commit, and we stay engaged through renewal, variation and the compliance obligations that follow. To discuss your situation, contact info@oboluslaw.com or message us via t.me/oboluslaw.

By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in multi-jurisdiction VASP and CASP authorisation, renewal cycles and variation filings for established digital-asset operators.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours