EST · MMXXVI
Home/Services/Licensing Registration/Licence renewal and variation for Institutional Clients
Licensing & Registration

Licence renewal and variation for Institutional Clients

Licence renewal and variation for Institutional Clients. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OB

For an institutional digital-asset business, a licence is never truly static. Regulators across every major hub now require periodic renewal, and the scope of an original authorisation rarely matches what the business actually does two or three years later. Operating outside the precise perimeter of your current licence – even briefly, even inadvertently – exposes the entity to enforcement, suspended payment rails and the kind of banking friction that can ground a platform in days. The question is not whether to manage the renewal and variation cycle. It is whether you manage it on your own timetable or on the regulator's.

Licence renewal and variation are the formal processes by which a regulated VASP (virtual asset service provider) or CASP (crypto-asset service provider) maintains its authorisation in good standing and amends the activities, financial instruments or client categories it is permitted to serve. Under the dominant regimes – MiCA administered by ESMA and national competent authorities, the VARA rulebooks in Dubai, and the MAS Payment Services Act framework in Singapore – both processes carry their own timelines, documentary obligations and consequences for non-compliance. This page maps the regulated basis, the practical process, and where institutional operators typically go wrong.

What does the renewal obligation actually require?

Renewal is a positive obligation: the licensee must demonstrate continued fitness, not merely the absence of a disqualifying event. Most flagship regimes attach renewal to an annual or multi-year cycle, and the trigger is the anniversary of authorisation rather than a change in business. Under MiCA, a CASP authorisation does not expire on a fixed date in the same way as some prior national regimes, but the ongoing obligations – capital maintenance, governance fitness, audit submissions – operate as a de facto rolling renewal test. A failure on any one dimension allows the national competent authority to suspend or withdraw the authorisation without a separate renewal proceeding.

VARA in Dubai operates a more explicit annual fee and review cycle. Licensees must submit updated compliance attestations, governance confirmations and financial evidence within a defined window. Miss the window and the licence lapses. Reinstatement is treated as a new application in most cases – a materially slower and more expensive path. MAS under the Payment Services Act similarly requires major payment institution licensees to maintain continuous compliance across capital, safeguarding and audit obligations, with periodic MAS review of the licensee's standing.

In our practice, the most common renewal failure is not a deliberate omission. It is a governance change – a new director, a revised ownership structure, a shift in beneficial ownership – that the business completed without notifying the regulator. By the time the renewal window opens, the entity is technically non-compliant with its fit-and-proper and ownership-disclosure obligations. Rectifying that position under time pressure is costly and occasionally impossible within the renewal cycle.

For a scoped review of your renewal obligations and timeline, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity structure, the personnel changes, the jurisdiction – change the analysis materially.

How does a licence variation work in practice?

A variation is required whenever a licensee seeks to carry on an activity, or serve a client category, that is not covered by the original authorisation. In practice, institutional operators need variations far more often than they expect. Adding custody to an exchange licence is a variation. Extending from spot trading to derivatives is a variation. Onboarding institutional counterparties in a new jurisdiction, launching a staking product or introducing a tokenised fund structure will each trigger a variation assessment in most regulated markets.

Under VARA, activity-based licences are specific: an exchange licence does not cover advisory or lending activities. Each additional activity requires a separate rulebook application and approval. Under MiCA, a CASP wishing to add a new crypto-asset service category must notify the home-state NCA and, in most cases, submit supplementary documentation demonstrating it meets the requirements for the expanded activity. The passporting benefit of MiCA attaches to the authorised activity set; add an activity without variation approval and the passport does not cover it.

The variation process typically involves a formal application to the relevant regulator, updated financial projections, revised governance documentation, an amended AML/CFT programme and, depending on the activity, a revised custody or safeguarding framework. Under MAS, a standard payment institution seeking to move to major payment institution status – effectively a variation in licence tier – must satisfy the capital and transaction-volume thresholds applicable to the higher tier and submit a formal application. Timelines vary by regulator and by the complexity of the expanded activity, but institutional operators should plan for a process that takes at minimum several weeks and often several months.

Why does cross-border structure complicate renewal and variation?

An institutional digital-asset business rarely operates from a single regulated entity. The typical structure separates the exchange or trading function, the custody layer and the payment or banking interface across two or three jurisdictions – each carrying its own licence, its own renewal cycle and its own variation rules. Coordinating those cycles is itself a material compliance function.

Consider a common architecture: a CASP authorised in an EU member state under MiCA holds a Malta MFSA legacy authorisation transitioning to the MiCA regime, while its custody subsidiary operates under the ADGM FSRA framework in Abu Dhabi and its payment flow runs through a Singapore MAS-licensed entity. Each of those licences renews on its own timetable. A variation approved by the EU NCA does not automatically extend to the ADGM entity. A governance change at the group level – a new ultimate beneficial owner, a board reconstitution – must be disclosed to each regulator on that regulator's own timeline and in its own format.

In our cross-border practice, we have seen institutional clients discover mid-renewal that a parent-level corporate restructuring – completed for tax or holding-company reasons – triggered a change-of-control notification obligation in two or three jurisdictions simultaneously. Managing those parallel disclosures, each with its own regulator's temperament and preferred evidence package, requires co-ordination across the licence stack before the restructuring closes, not after.

Where allied counsel in the relevant jurisdiction is required, we co-ordinate the engagement so that the institutional client receives a consolidated view of all disclosure and renewal obligations rather than parallel advice that can conflict on timing.

If a prior application stalled or a renewal window is approaching under time pressure, a structured second read can surface the reason and the route forward – write to info@oboluslaw.com. Many of the renewal difficulties we encounter had a straightforward resolution once the full licence stack was mapped.

What are the most costly mistakes in licence renewal and variation?

The costliest mistakes are structural, not procedural. Procedural errors – missing a document, supplying the wrong form version – are correctable. Structural errors create enforcement exposure that can take months to resolve and, in some cases, require the business to cease certain activities while the position is rectified.

The first structural error is scope creep without a variation. An institutional operator begins offering a product – staking rewards, yield on deposited assets, a tokenised money-market instrument – that the original licence does not cover. The operator reasons that it is a minor extension. The regulator disagrees. Under most regimes, an activity carried on without the applicable authorisation is a regulatory breach regardless of whether it is intentional. Regulators in the major hubs increasingly treat unlicensed activity as an aggravating factor in any subsequent supervisory matter.

The second error is failing to maintain the AML/CFT programme in line with the expanded activity. When a variation application arrives, the regulator scrutinises the programme for the new activity as well as the existing one. An AML framework that has not been updated since the original authorisation – and that does not address the new product's specific risks – is a near-certain cause of variation delay or refusal.

The third error is personnel change without notification. Many institutional operators maintain a healthy separation between their legal and HR functions. A departing Chief Compliance Officer or a new Responsible Manager is an employment matter. It is also, in most flagship regimes, a material change requiring prompt notification to the regulator. Under VARA, designated senior persons must be approved; replacing one without prior or prompt notification is a breach. Under MiCA, key function holders are subject to fitness and propriety assessment; an unapproved replacement can trigger supervisory scrutiny of the entire governance framework.

Which profile requires which approach?

Institutional operators are not a homogeneous group. The renewal and variation strategy that fits a mature exchange with multiple regulated entities differs significantly from that of a custodian seeking to expand its service range for the first time. The following matrix sets out the main profiles and the indicative approach for each.

Profile A – Established exchange expanding activity scope. The operator holds a primary licence in good standing but wishes to add a custody or lending activity. The variation path requires an updated capital assessment, a revised governance framework for the new activity and a full AML programme extension. In our experience, this profile benefits most from a pre-application meeting with the regulator – where the regime allows it – to align on evidence expectations before the formal submission. Timeline: variable, typically several months for a substantive activity addition.

Profile B – Multi-entity group managing parallel renewal cycles. The group holds licences in two or more jurisdictions, each renewing on a different cycle. The immediate priority is a consolidated licence calendar that maps every renewal deadline, every change-of-control trigger and every personnel notification obligation across the stack. Without that map, a deadline in one jurisdiction is routinely missed because attention was on another. We build that calendar at the outset of any multi-entity mandate.

Profile C – Institutional fund or custodian adding a new jurisdiction. The entity is fully licensed in its home regime and wishes to add authorisation in a second hub – for example, adding an AIFC/AFSA authorisation in Kazakhstan alongside an existing MiCA CASP licence for a Central Asian institutional client base. This is not a variation of the existing licence; it is a new application in the second jurisdiction. But it is substantially facilitated by the existing compliance infrastructure. The key risk is assuming that a regime-compliant programme in jurisdiction one will satisfy the requirements in jurisdiction two without adjustment. Every regulator has its own priorities, and those priorities are not always identical to the flagship documentation.

Profile D – Early-stage institutional operator approaching first renewal. The first renewal cycle is a calibration exercise: the regulator reviews whether the entity has operated in conformity with its authorisation. Operators who have maintained clean compliance records, filed all periodic reports and kept their AML programme current typically find the first renewal straightforward. Those who have informally extended scope, changed personnel without notification or allowed their capital to drift below the required minimum face a substantive remediation exercise before the renewal can close.

How do AML and Travel Rule obligations affect the renewal process?

Every renewal submission in every flagship regime will be assessed against the current state of the operator's AML/CFT programme. Regulators do not simply roll over the previous approval. They test whether the programme has kept pace with the business – new products, new counterparty types, new transaction volumes – and with the current FATF Recommendations, including the Travel Rule (the obligation to pass originator and beneficiary data with a virtual-asset transfer).

For institutional operators, Travel Rule compliance is increasingly a renewal-critical item. MiCA aligns its travel-rule requirements with the EU Transfer of Funds Regulation as extended to crypto-assets. VARA has its own travel-rule expectations within the Dubai regime. An operator whose Travel Rule solution is technically implemented but operationally patchy – failing on unhosted wallet attribution, missing counterparty VASP data for a material share of transfers – will face renewal scrutiny on that point specifically.

In a recent renewal matter, an institutional custodian discovered during its pre-renewal internal review that its Travel Rule solution had a systematic gap for transfers to one category of counterparty VASP. We worked with the client to document the gap, implement a remediation programme and present a credible remediation timeline to the regulator ahead of the renewal submission. The renewal proceeded, with the remediation programme attached as a condition. That outcome was available because the gap was identified and disclosed proactively. A regulator discovering the same gap during its own review arrives at the matter in a materially different posture.

A common assumption: does an offshore licence cover global operations?

A common assumption among institutional operators – particularly those structured through BVI, Cayman or other offshore holding jurisdictions – is that a single offshore VASP registration is sufficient to serve clients globally, or at least to serve clients who are themselves offshore entities. That assumption is incorrect, and it is an increasingly costly one to hold.

The relevant test in most regulated markets is not where the operator is incorporated. It is where the service is provided and where the clients are located. An exchange incorporated in the BVI under the BVI FSC VASP Act 2022, serving institutional clients resident in the EU, is providing crypto-asset services into the EU. Under MiCA, reverse solicitation is a narrow carve-out – available only where the client has solicited the service entirely on their own initiative, with no prior marketing by the provider. Most institutional commercial relationships do not meet that standard.

The same analysis applies to the UK under the FCA's financial-promotion regime, to Singapore under MAS where DPT services are provided to Singapore persons, and to Hong Kong under the SFC VASP licensing regime. Each of these regulators has moved, at different speeds, to assert jurisdiction over inbound digital-asset services regardless of the provider's domicile.

An institutional operator relying on an offshore licence as a global-service wrapper is not simply under-licensed. It is operating in multiple jurisdictions without the authorisation those jurisdictions require. The enforcement risk is not theoretical: regulators in the major hubs have shown increasing willingness to pursue offshore operators serving their domestic markets. The structural correction – a properly licensed entity, or a set of licensed entities, covering the markets actually served – is the only durable solution.

Self-assessment: is your licence renewal position sound?

Before the renewal window opens, institutional operators should assess their position across the following dimensions.

Capital. Does the entity currently hold own funds at or above the minimum required for its licence category? Has capital been drawn down, distributed or otherwise reduced since the last annual attestation? Capital below the required floor is a material breach at renewal and often triggers a more intensive supervisory review.

Personnel and governance. Have any approved persons or designated senior functions changed since the original authorisation or last renewal? Have those changes been notified to the relevant regulator on the required timeline? Is the current governance structure consistent with the structure described in the authorisation file?

AML/CFT programme. When was the programme last reviewed and updated? Does it address the current product range and client profile? Is Travel Rule compliance fully operational across all counterparty VASP relationships?

Scope. Is the entity's current commercial activity fully covered by the existing authorisation? Have any products, services or asset classes been introduced since the original licence or last variation that require a formal variation application?

Periodic filings. Are all periodic supervisory reports, financial statements and AML reports filed and current? A gap in periodic filings is one of the most common causes of renewal delay – and one of the most easily preventable.

Cross-border notifications. For multi-entity groups: have all change-of-control, ownership and key-personnel notifications been made to each relevant regulator? Are the renewal calendars for each entity co-ordinated so that no deadline in one jurisdiction is obscured by activity in another?

A credible "yes" across all six dimensions is the baseline for a clean renewal. Where the answer is "uncertain" or "no", the remediation work should begin well before the renewal window opens.

Related at OBOLUS

About OBOLUS

OBOLUS is an independent digital-asset law boutique acting exclusively for businesses. We advise crypto exchanges, custodians, token issuers and funds across more than seventy licensing jurisdictions, across more than twenty-five dispute and recovery forums, and on the tax, banking and compliance obligations that sit around every regulated structure. We map the full licence stack – operating, custody and payment layers – before a client commits to a structure, and we manage the renewal and variation cycle once it is in place. Digital assets are the whole of our practice. To discuss your licence position, contact info@oboluslaw.com or reach us via t.me/oboluslaw.

To map the licence, banking and compliance stack for your institutional build or renewal, write to info@oboluslaw.com.

By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in multi-regime CASP and VASP authorisation, renewal cycle management and variation strategy for institutional digital-asset operators.

FAQ

How long does a crypto licence take to obtain?

Timelines vary considerably by jurisdiction and licence category. In the major hubs, initial authorisation processes typically run from several weeks for a registration-track regime to several months for a full activity-based licence requiring capital approval, governance review and AML assessment. Renewal is generally faster where the entity's compliance record is clean. Variation of an existing licence depends on the complexity of the new activity; substantive additions – custody, lending, derivatives – typically require more time than administrative amendments. Build in buffer before the commercial launch date for any new activity.

Which jurisdiction is best for licensing my crypto business?

There is no universal answer, and any adviser who offers one without knowing your client profile, activity set and banking requirements should be treated with caution. The relevant variables are: where your institutional clients are located, which activities you intend to carry on, the capital and governance the target regime requires, and the banking and custody infrastructure available in that market. Dubai under VARA, Singapore under MAS, the EU under MiCA and Hong Kong under the SFC each represent a credible primary jurisdiction for institutional operators – but the right choice turns on your specific facts. We map the options before you commit.

Do I need a separate custody licence?

In most flagship regimes, custody of digital assets is a regulated activity distinct from exchange or brokerage. Under MiCA, crypto-asset custody and administration is a defined CASP service requiring specific authorisation. Under VARA, custody is a separately licensed activity. Under MAS, safeguarding obligations attach to certain payment-token activities and require their own compliance framework. An exchange licence does not, as a general rule, authorise the operator to hold client assets in custody. If your business model involves holding keys or controlling wallets on behalf of institutional clients, a dedicated custody authorisation is likely required.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours