Operating a regulated digital-asset business means that a licence, once granted, is never truly static. Product lines expand, user geographies shift, and regulators across the major hubs periodically revise their supervision models. When any of those variables move, the obligation to keep the authorisation current – and to notify, apply or reapply before the change, not after – falls entirely on the regulated entity. A missed renewal window or an undisclosed material change can trigger enforcement, suspension of activities, or the loss of correspondent banking relationships that took years to build.
This page explains the legal basis for licence renewal and variation across the leading VASP (virtual asset service provider) and CASP (crypto-asset service provider) regimes, sets out the practical process at each stage, and identifies the structural mistakes that turn a routine administrative exercise into a crisis.
Why Renewal and Variation Are Higher-Stakes Than the Original Application
The original licence application is a discrete event. Renewal and variation are recurring obligations that sit inside a live business – one with existing users, active counterparties and a banking stack that has commercial relationships contingent on the authorisation remaining current. Any lapse or condition attached at the renewal stage is therefore immediately operational, not merely regulatory.
Regulators across the EU under MiCA, in Dubai under VARA, in Singapore under the MAS Payment Services Act, and in Hong Kong under the SFC VASP licensing regime have each built notification and pre-approval obligations into their licence conditions for precisely this reason. The expectation is that the regulator knows the shape of the business at all times – not just at inception.
In our practice, we observe that enforcement proceedings against regulated entities more commonly originate from a variation that was not pre-approved than from an outright unlicensed operation. The entity believed it was operating within its authorisation. It was not.
The process above describes the standard path. Your facts – the entity, the user base, the banking stack, the product additions – change the analysis significantly. For a scoped assessment of where your authorisation currently sits and what it covers, contact OBOLUS at info@oboluslaw.com.
What Triggers a Variation Obligation Across the Leading Regimes?
A variation obligation arises whenever a regulated entity wishes to carry on an activity – or carry it on in a manner – that falls outside the scope of its current authorisation. The specific triggers differ by regime, but the following categories are consistently material.
Activity expansion is the most common trigger. A custodian that begins offering brokerage or lending; an exchange that adds staking or yield products; a transfer-and-settlement provider that starts accepting fiat – each of these adds a regulated activity that requires either a variation of conditions or an entirely new licence category. Under VARA's activity-based licensing model, each activity (advisory, broker-dealer, custody, exchange, lending, management, transfer and settlement) carries its own approval. Adding one requires a discrete application, not just a notification.
Under MiCA, a CASP authorisation specifies the crypto-asset services the entity is permitted to provide. Any expansion of that list requires pre-approval from the relevant national competent authority. The passporting mechanism – which allows a CASP authorised in one EU member state to operate across the EEA – does not extend automatically to services added after the original authorisation. That is a common and costly assumption.
Change of control is equally significant. In most flagship regimes, a change of qualifying ownership – whether through a direct transfer of shares or a restructuring of the upstream holding chain – is a notifiable event and, in many cases, requires the regulator's prior consent. The thresholds vary by regime; the principle is uniform.
Key-person changes, significant technology changes affecting custody or settlement infrastructure, and the addition of new client categories (for instance, institutional versus retail) also fall within the variation perimeter across most regimes. The obligation to notify typically arises before the change, not on or after it.
Renewal Mechanics Across the Major Regimes
Not every regime operates on a periodic renewal cycle in the traditional sense. Understanding the form of your ongoing obligation is the starting point.
Under the FCA's registration regime for cryptoasset businesses under the Money Laundering Regulations in the United Kingdom, registration does not lapse automatically, but the FCA may review and revoke it. Renewal is continuous: the obligation is to maintain the conditions at all times and to notify material changes.
Under MiCA, authorisation is granted without an expiry date, but the national competent authority may impose conditions or time-limits, and the annual supervisory review process is substantive. Failing to satisfy the ongoing conditions – including capital adequacy, governance and AML compliance – can result in a suspension or withdrawal of the authorisation without a formal renewal window as a backstop.
In Singapore, the MAS Payment Services Act creates a licensing cycle for Digital Payment Token service providers. Licences are granted for a term and are subject to formal renewal, with application windows that close before the current licence expires. Missing the window is not merely an administrative failure – it creates a gap in authorisation during which the entity cannot legally operate the relevant service.
In Hong Kong, the SFC VASP licensing regime for virtual-asset trading platforms also runs on a licence term with formal renewal. The renewal application must demonstrate continuing compliance across all conditions, including financial resources, cybersecurity, custody arrangements and AML programme quality.
In jurisdictions like the BVI under the VASP Act 2022 and the Cayman Islands under the Virtual Asset (Service Providers) Act, registration and licensing are subject to annual fees and periodic compliance attestations. A failure to file those attestations on time is a notifiable breach and may attract regulatory action that is disproportionate to the administrative oversight.
The Cross-Border Reality: One Licence Does Not Follow the Business
One of the most persistent misconceptions in digital-asset business planning is that a single offshore authorisation is sufficient to serve clients globally. It is not.
The jurisdictional reach of a VASP or CASP licence is determined by the regulatory perimeter of the issuing jurisdiction – not by the technology used to deliver the service or the corporate law of the entity's domicile. A business licensed in one EU member state under MiCA can passport across the EEA for the services listed in its authorisation. That same licence provides no authorisation to solicit or serve users in Singapore, Hong Kong, the UAE or the United Kingdom, where independent regulatory obligations apply.
When a business adds a new geography – whether by marketing to users there, onboarding institutional counterparties there, or banking with a correspondent there – it almost certainly adds a regulatory obligation in that jurisdiction. In some cases, a local entity and a local licence are required. In others, a lighter registration or notification regime applies. In all cases, the analysis must be done before the expansion, not after the regulator in the new market has opened an inquiry.
We regularly advise businesses that discovered the gap only when a banking counterparty in the new market conducted its own regulatory due diligence and declined the relationship. Banking is, in practice, the first compliance checkpoint for a digital-asset business expanding across jurisdictions. Banks apply their own version of the licence-stack analysis, and they apply it conservatively.
The cross-border answer is a licence matrix: for each activity, each user geography, and each banking relationship, the matrix identifies the authorisation currently held, the authorisation required, the gap, and the timeline and path to close it. That matrix is what we build.
The Five Structural Mistakes That Turn Routine Renewal Into a Regulatory Event
These are not hypothetical. They recur across the businesses we advise.
Treating renewal as administrative, not substantive. In most regimes, a renewal is not a rubber stamp. The regulator will assess whether the business continues to meet the conditions of authorisation. If the AML programme has not been updated to reflect expanded activities, if the responsible persons have changed without prior approval, or if capital has dipped below the required level, the renewal application surfaces those issues in a formal context where the regulator must act on them.
Assuming past approval covers future activity. A licence granted for exchange services does not cover lending. A licence granted for institutional clients does not automatically cover retail. Every expansion of activity requires a fresh analysis of the authorisation perimeter – and in most cases, a variation application before the activity begins.
Missing notification windows. Most regimes impose a pre-notification obligation: the regulator must be notified before a qualifying change, not after. The window is typically measured in weeks, not months. Entities that reorganize their ownership structure or replace key persons and then disclose this at the next annual review are almost certainly in breach of their licence conditions.
Conflating group licences with entity-level authorisation. A group that holds a VARA licence for one Dubai entity does not thereby authorise a second group entity to carry on virtual-asset activities in Dubai. The authorisation is entity-level. A new entity requires a new application or a variation of the existing authorisation to cover the new entity, depending on the regime's structural rules.
Overlooking the AML/CFT dimension. Under FATF Recommendation 15 and the domestic legislation that implements it, VASPs and CASPs have AML and Travel Rule (the obligation to pass originator and beneficiary data with virtual-asset transfers) compliance obligations that are a licence condition, not a separate matter. At renewal, the regulator will often ask for a current AML/CFT programme, an independent audit, and evidence of Travel Rule compliance. An entity that has not built that programme into its operations will not be able to produce it at renewal without a significant period of remediation.
A Matter from Our Practice
In a recent cross-border matter, a digital-asset exchange operating under an EU-jurisdiction CASP authorisation sought to add a lending product to its platform. The business had assumed the product fell within its existing authorisation as a service ancillary to exchange. It did not: the applicable regime treated the lending activity as a separate regulated service requiring a variation of the authorisation with additional capital and governance conditions. We were instructed shortly before the product launch. We mapped the variation obligations across the operating jurisdiction and two secondary markets where the product would be offered, prepared the variation application and the required governance documentation, and coordinated the pre-approval timeline against the planned product release. The product launched on a compliant basis, within the original commercial schedule. The alternative – launching without the variation – would have triggered an immediate supervisory inquiry.
Decision Matrix: Which Process Applies to Your Situation?
The right process depends on the nature of the change and the regime under which the entity operates. The following outlines the main analytical branches.
Profile A: Periodic renewal, no material change. The entity's activities, personnel, capital and ownership are unchanged from the prior period. The applicable process is a renewal application demonstrating continuing compliance – financial resources, governance, AML programme, Travel Rule compliance, and key-person standing. Timeline varies by regime from several weeks to several months; some regimes permit a streamlined renewal where compliance is attested without full re-documentation. In all cases, the application must be submitted before the current licence expires or the relevant window closes.
Profile B: Renewal with a change in scope. The entity is renewing but has also added or is proposing to add activities, key persons, client categories or geographies. This is the most complex scenario. The renewal and the variation may be processed together, or the variation may need to be filed and approved before the renewal is considered complete. The sequencing matters and depends on the specific regime. Key risk: filing the renewal without disclosing the change, then discovering the change required pre-approval – at which point the entity is in breach of its licence conditions while operating under a renewed licence.
Profile C: Mid-term variation, no renewal due. The licence term is current, but a material change has occurred or is planned. This requires a standalone variation application. The entity must continue to operate only within its existing authorisation until the variation is approved; it may not pre-empt the regulator's decision by beginning the expanded activity. Timeline here varies meaningfully by jurisdiction and by the nature of the change.
Profile D: Group restructuring or change of control. A corporate restructuring affects qualifying ownership above the regime's notification threshold. This almost universally requires prior regulatory consent, not merely notification. The process involves a detailed fit-and-proper assessment of the incoming controlling person and, in some regimes, a fresh review of the business plan and capital adequacy. The timeline is typically the longest of any variation type.
If a prior application stalled or a variation was filed without the outcome you expected, a second read of the application and the regulator's position can surface the structural issue and the route forward. Write to OBOLUS at info@oboluslaw.com or message us at t.me/oboluslaw.
Self-Assessment: Is Your Authorisation Currently Fit for Purpose?
The following questions identify the most common gaps. A "no" or "uncertain" answer to any item warrants immediate review.
- Does your current authorisation list every activity your business is currently performing for clients?
- Does it cover all the client categories – retail, professional, institutional – you are currently serving?
- Is your capital at or above the minimum required for each activity your licence covers?
- Are all key persons named in or approved under the current authorisation still in their licensed roles?
- Have any qualifying ownership changes occurred since the last regulatory notification?
- Is your AML/CFT programme current, documented and capable of being produced to the regulator on request?
- Are you compliant with the Travel Rule in every jurisdiction where you operate?
- Have you mapped the regulatory obligations in each jurisdiction where you have users, not just where you are incorporated?
- Do you know the date of your next renewal window and the documents you will need to file?
Operators we advise regularly use this checklist as the starting point for a pre-renewal audit – a structured review of the authorisation against the current business, conducted before the regulatory deadline rather than in response to a supervisory query.
How OBOLUS Advises on Renewal and Variation
We act only for business clients. Our licensing work across more than 70 jurisdictions means we understand both the formal requirements of each regime and the informal expectations regulators bring to renewal and variation applications.
For renewal matters, we conduct a pre-renewal compliance audit, identify any conditions that have not been continuously met, advise on remediation steps where necessary, prepare the renewal application and supporting documentation, and manage the submission and regulatory correspondence through to decision.
For variation matters, we begin with the authorisation perimeter analysis – mapping precisely what the current licence covers and where the proposed activity or change falls outside it. We then identify the applicable variation process, the required pre-notifications, the sequencing of filings across multiple jurisdictions where the entity operates in several markets, and the documentation required to support the application. We have seen regimes where a variation can be completed in a matter of weeks and others where a full reauthorisation process is effectively required. The analysis must come first.
We also coordinate with allied counsel in the relevant jurisdictions for businesses operating across markets where we do not hold the primary instruction – ensuring the variation or renewal filed in each market is consistent with the overall structure and does not inadvertently trigger an obligation in a third market.
Related at OBOLUS
- Licensing and Registration for Digital-Asset Businesses – the full scope of OBOLUS licensing services across 70+ jurisdictions
- Digital-Asset Licensing in Georgia – jurisdiction-specific analysis for operators considering a Georgia authorisation
- How to Enforce a Foreign Judgment Over Digital Assets – cross-border enforcement guide relevant to regulated entities facing asset-recovery situations
FAQ
How long does a crypto licence take to obtain?
Timeline varies significantly by jurisdiction and licence category. In some EU member states under MiCA's CASP framework, authorisation processes are measured in months; in offshore centres such as the BVI or Cayman Islands, registration timelines can be shorter. Factors that extend the timeline include incomplete applications, gaps in the AML programme, unresolved fit-and-proper queries on key persons, and novel business models requiring regulatory guidance. We advise clients to plan for the longest credible timeline in the target jurisdiction, not the minimum.
Which jurisdiction is best for licensing my crypto business?
There is no universal answer. The right jurisdiction depends on the activities you intend to carry out, the markets where your users are located, your banking requirements, your tax position, and the regulatory reputation that your institutional counterparties and banking partners will require. A Dubai VARA licence, a Malta or Lithuanian CASP authorisation under MiCA, a Singapore MAS licence and a BVI VASP registration each serve different operator profiles. We map the full licence, banking and tax stack before recommending a jurisdiction – not a single variable in isolation.
Do I need a separate custody licence?
In most flagship regimes, custody of digital assets for clients is a regulated activity distinct from exchange or transfer services. Under MiCA, custody and administration of crypto-assets is a named CASP service. Under VARA, custody is a separate licensed activity. Under the SFC regime in Hong Kong, safeguarding arrangements are a core licensing condition for VATPs. Whether your current authorisation covers custody depends on the precise terms of the licence – not on how the service is described commercially. If you hold client assets in any form, you should verify that this activity is within your licence perimeter before your next supervisory contact.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance obligations that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit – and we coordinate freezing relief and on-chain tracing through leading common-law forums when matters escalate. To discuss your renewal, variation or cross-border licence strategy, contact info@oboluslaw.com.
By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in multi-jurisdiction VASP and CASP authorisation, licence variation strategy and pre-renewal compliance audits across the EU, UAE, Asia-Pacific and offshore centres.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.