Licence Renewal and Variation from a Cross-border Perspective
Operating a digital-asset business across multiple jurisdictions without the right licence in each of them exposes the business to enforcement action, suspended banking relationships and the sudden loss of access to payment rails. Licence renewal (the periodic reauthorisation required by most regulatory regimes) and licence variation (a formal amendment to the scope, conditions or activities covered by an existing authorisation) are not administrative formalities. They are material legal events that can trigger fresh fitness-and-propriety assessments, updated capital reviews and, in cross-border structures, simultaneous obligations to multiple regulators. This page explains what those obligations are, how to manage them, and where the real risks concentrate for operators who sit across more than one regulatory environment.
What Do Licence Renewal and Variation Actually Mean in a Regulated Digital-Asset Business?
A licence renewal is the formal continuation of a regulatory authorisation at the end of its fixed term. Under most VASP (virtual asset service provider) regimes and CASP (Crypto-Asset Service Provider) frameworks, including those supervised by VARA in Dubai, MAS in Singapore and the FCA in the United Kingdom, authorisation does not run indefinitely. The regulator expects the operator to demonstrate, at defined intervals, that it continues to meet the conditions on which the licence was granted. A variation, by contrast, is triggered not by time but by change – when the business wants to add an activity, exit an activity, alter its ownership structure, change a key person or expand into a new product line.
Both processes share a common structure. The operator files a formal application or notification. The regulator reviews updated compliance documentation, financial positions and governance arrangements. A period of regulatory scrutiny follows, and the authorisation is either confirmed, amended or, in adverse cases, refused. The practical difference is that a variation may be filed at any point in the authorisation lifecycle, while renewal is a scheduled event the business must anticipate.
In our licensing practice, operators frequently underestimate the preparation time that serious regulators require. A renewal filed late, or a variation filed after the business change has already occurred, creates a window of unlicensed operation. That window, however brief, is the fact pattern that enforcement actions are built around.
Why Does the Cross-border Dimension Make This Harder?
A business licensed in one jurisdiction but serving users, holding assets or maintaining banking relationships in another is almost always subject to parallel regulatory obligations. The cross-border problem compounds at every stage of the renewal and variation cycle. Consider a common structure: a CASP authorised under MiCA (the EU's Markets in Crypto-Assets Regulation, supervised by ESMA and national competent authorities) that also holds a VASP registration in the BVI under the BVI FSC regime and operates a custody vehicle through ADGM in Abu Dhabi under FSRA supervision. Each of those authorisations has its own renewal calendar, its own variation trigger-list and its own regulator with independent expectations.
When a business event occurs – a new shareholder above a defined threshold, an expansion into lending, a change of the person responsible for compliance – it may require simultaneous notifications to all three regulators. The timing requirements do not align. The documentation standards differ. What satisfies the FSRA may need material re-packaging for the BVI FSC.
We regularly advise operators through exactly this kind of multi-registry coordination. The practical answer is a unified change-management calendar that maps every regulatory trigger across every jurisdiction in the stack, with notification windows pre-loaded. Without that, a material change in one entity slips through before the parallel obligations are identified.
The cross-border mismatch between renewal cycles and corporate change timelines is, in our experience, the leading cause of unintentional unlicensed operation among otherwise well-governed businesses.
Get ahead of your next renewal or variation cycle. The process above describes the standard path. Your facts – the entity, the user base, the banking and the activity scope – change the analysis materially. Map your options with OBOLUS before the deadline moves.
What Business Changes Trigger a Mandatory Licence Variation?
A mandatory variation is triggered whenever a defined threshold in the operating conditions is crossed. The specific triggers vary by regime, but in our cross-border practice we see a consistent set of events that require formal notification to regulators across the major hubs.
Ownership and control changes are the most common trigger. Most regimes require prior approval – not just post-event notification – when a new investor acquires a qualifying stake. Under the VARA rulebooks in Dubai, under MiCA's CASP conditions and under MAS's Payment Services Act regime in Singapore, acquiring a significant interest in a licensed entity without prior regulatory clearance is itself a breach of the licence conditions. The threshold for "significant" differs across these regimes, and for cross-border operators it is the lowest applicable threshold across the stack that governs practical behaviour.
Activity expansion is the second major trigger. An operator licensed for exchange services that begins offering custody, staking or lending has crossed into regulated territory that the original authorisation does not cover. Under the VARA framework, activities are licensed individually. Under MiCA, the CASP authorisation specifies which services are permitted. A business that adds services without a variation is operating outside its licence – the fact that it holds a licence at all does not cure that.
Key-person changes are consistently underestimated. When a money-laundering reporting officer (MLRO) departs, when a director with regulatory approval changes, or when the ultimate beneficial owner changes, most regimes require notification within a defined period. Late notification is a compliance breach in its own right, separate from the underlying change.
Technology and infrastructure changes sometimes trigger notification obligations too. Outsourcing custody to a new third-party provider, migrating to a new trading engine or adopting a new wallet architecture may fall within the material change provisions of an operator's specific licence conditions. Reading those conditions carefully – and not assuming that a technology decision is purely internal – is part of the governance discipline that regulators increasingly expect.
How Does the Licence Renewal Process Work in Practice?
The renewal process, at its core, is a structured opportunity for the regulator to assess whether the business still deserves its authorisation. For operators who have maintained compliance throughout the licence term, it should be an organised exercise in documentation. For operators who have accumulated compliance gaps, changed activities without variation or allowed governance to drift, it becomes a negotiation.
The first step is pre-renewal preparation, typically beginning several months before the renewal date. The operator maps every condition attached to its existing authorisation and assembles evidence of ongoing compliance. This includes updated AML/CFT policies aligned to FATF Recommendation 15 and the Travel Rule (the obligation to pass originator and beneficiary data with a virtual asset transfer), updated financial statements, governance documentation and fitness-and-propriety confirmations for all relevant individuals.
The second step is the formal submission. Most regulators have a defined portal or submission format. Incomplete submissions are returned, and the clock on the regulator's review period may not start until the submission is treated as complete. In jurisdictions where the regulator is actively managing a high volume of applications – as several EU national competent authorities were during the MiCA transition period – an incomplete submission can cost weeks.
The third step is the regulator's review period. During this window the regulator may issue information requests, seek clarifications or require updated documents. Response time matters. A slow response to a regulatory information request is both a compliance signal and a practical delay. Where multiple regulators are reviewing simultaneously, the information requests rarely land in a coordinated way.
The fourth step is the renewal decision. The regulator confirms, amends or refuses. Where conditions are attached to the renewal, those conditions become part of the live licence and must be reflected in the operator's compliance programme immediately.
In our practice, the most common avoidable failure at the renewal stage is submitting a compliance document set that reflects the business at the time of the original authorisation rather than the business as it currently operates. Regulators compare the two. Differences that have not been addressed through a variation application become findings.
What Are the Most Costly Mistakes in Cross-border Renewal and Variation?
The costliest mistakes are structural, not procedural. They stem from treating licences as static documents rather than living regulatory relationships. We outline the most consequential ones below.
First: failing to map the renewal calendar across all jurisdictions in the group structure. A holding company with subsidiaries in Dubai, Singapore and the EU may have renewal or re-registration obligations falling within weeks of each other, or obligations that interact. Managing them independently, without a unified calendar, leads to gaps.
Second: assuming that a change permissible under domestic law does not require regulatory notification. Corporate law and regulatory law operate independently. A share transfer that is valid under BVI company law still requires VASP Act notification. A restructuring that is tax-efficient under Malta's framework still requires MFSA notification under the VFA or MiCA CASP regime. The question is never only "is this lawful?" but "which regulators need to know, and when?"
Third: deferring the variation application until after the business change has occurred. As noted above, many regimes require prior approval. The only safe approach is to file the variation before the change, and in some cases to wait for approval before implementing the change at all.
Fourth: underresourcing the compliance team during the renewal window. Renewal submissions require the same quality of documentation as an initial licence application. Businesses that staff for routine compliance but not for the renewal surge create a bottleneck that regulators notice.
Fifth: ignoring the banking and payment-rail dimension. Banking partners conduct their own periodic reviews of licensed clients. A renewal that surfaces a compliance gap may trigger a bank's internal review simultaneously. In cross-border structures, one regulator's concern can propagate to banking relationships in another jurisdiction within days.
Which Renewal or Variation Route Fits Your Profile?
The right approach to renewal and variation is not uniform. It depends on the operator's regulatory stack, the nature of the change and the tolerance for operational disruption during the review period. The following profiles capture the most common situations we advise on.
Profile A – Single-jurisdiction operator, routine renewal. A business holding one CASP authorisation in an EU member state, with no material changes during the licence term, follows a structured documentation review and submission. The regulator expects updated AML/CFT policies, financial health confirmation and governance records. Timeline is driven by the national competent authority's current processing load. The key risk is an incomplete submission that restarts the clock. Appropriate preparation begins several months before the renewal date.
Profile B – Multi-jurisdiction operator, no material change. An operator holding authorisations in Dubai under VARA, Singapore under MAS and the BVI under the BVI FSC manages three separate renewal processes with independent timelines. The risk here is coordination failure. The practical instrument is a unified renewal calendar with assigned responsibility for each jurisdiction, milestone reviews and a single coordinating legal adviser who understands all three regimes. We have structured cross-border renewal coordination mandates for precisely this profile.
Profile C – Operator planning a material expansion or restructuring. A business that intends to add custody services, onboard institutional clients in a new jurisdiction or restructure its ownership faces variation obligations before the expansion occurs. The variation application may pause or constrain the business plan until regulatory approval is granted. The appropriate instrument is an early variation filing, coordinated across all affected jurisdictions, with the corporate change timed to follow approval. Where the expansion touches a regime with a different capital requirement, the capital planning must also be addressed before filing.
Profile D – Operator whose prior licence was refused or not renewed. A business that has been refused a renewal, or whose authorisation has lapsed, faces a materially different path. In most flagship regimes, a lapsed authorisation is not simply renewed – the operator must re-apply from scratch. This is a more intensive process, typically involving a fitness-and-propriety assessment of the reasons for the lapse and a demonstration that the underlying compliance gap has been remediated. We advise on remediation and re-application strategies for this profile, though outcomes depend on the specific facts and the regulator involved.
A Cross-border Renewal That Almost Missed Its Window
In a recent licensing matter, an operator holding authorisations across two EU jurisdictions and one Gulf hub engaged us after discovering, during a routine internal audit in late spring, that its Gulf-jurisdiction renewal had a submission window opening within weeks. No internal calendar had been maintained for the Gulf authorisation; the team had managed the EU MiCA CASP renewal cycle and assumed the Gulf timeline was aligned. It was not. We conducted an accelerated compliance gap analysis across all three regulatory stacks, identified two activity expansions that had occurred without corresponding variations in the Gulf jurisdiction and a key-person change that required retrospective notification in one EU jurisdiction. The renewal submissions were filed within the required window across all three regulators. The retrospective notifications were filed with explanatory context. No enforcement action resulted. The matter illustrates how a gap in cross-jurisdictional calendar management, rather than any intentional breach, creates the risk of simultaneous regulatory exposure across multiple regimes.
If a prior application stalled, a renewal window is approaching or a business change has already occurred without a variation, a structured second read of the position can surface the route forward. Write to OBOLUS at info@oboluslaw.com or reach us via t.me/oboluslaw for a scoped assessment. Map your options.
A Common Assumption: One Offshore Licence Is Enough
A persistent assumption among early-stage operators is that a single offshore VASP registration – in the BVI, Cayman Islands or a comparable jurisdiction – is sufficient to serve clients globally. That assumption is incorrect, and regulators in the major markets have made it increasingly costly to maintain.
The relevant question is not where the legal entity is incorporated or registered. It is where the clients are located, where the regulated activity is occurring and where the assets are held. An operator registered in the Cayman Islands under the CIMA regime that solicits EU retail clients is subject to MiCA's CASP authorisation requirements in the EU, regardless of its offshore registration. An operator with a BVI VASP registration that markets to UK users is within the FCA's financial-promotion perimeter.
Regulators in the major consumer-facing markets apply an effects-based approach. If your product reaches their residents, the question is whether your authorisation covers that reach. An offshore registration answers the question of where you are registered. It does not answer the question of whether you are authorised to serve the client base you are actually serving.
The practical consequence is that a properly structured multi-jurisdiction operation requires a licence stack – an authorisation in each jurisdiction where the activity occurs or where the client base sits – and a renewal and variation programme that manages that stack as a whole. We map that stack before an operator commits to a structure, and we manage the renewal and variation cycle throughout the operation's life.
Self-assessment: Is Your Renewal and Variation Position Sound?
The following questions are not legal advice. They are a practical starting point for an operator assessing its own position before engaging counsel.
- Do you hold a current, unexpired authorisation for every activity you carry out in every jurisdiction where you operate?
- Have you mapped the renewal date for each authorisation in your group structure?
- Has any change of ownership, key person, activity or significant technology infrastructure occurred since your last authorisation was granted or renewed?
- Have you reviewed the specific conditions attached to each of your authorisations to identify whether any of those changes required prior regulatory notification?
- Are your AML/CFT policies current, and do they reflect the Travel Rule obligations applicable in each jurisdiction where you operate?
- Has your banking partner been informed of any material changes to your business that could affect your account-maintenance representations?
- Do you have a documented process for identifying future triggers that will require a variation filing?
If any of these questions produces an uncertain answer, the right time to address it is before the renewal window opens, not after.
Related at OBOLUS
- Licensing and Registration for Digital-Asset Businesses – the full practice overview covering authorisation across more than seventy jurisdictions
- Digital-Asset Custody Licensing for Established Operators – custody-specific authorisation requirements and the variation implications of adding safeguarding services
- EMI Onboarding for VASPs in Seychelles – jurisdiction-level guidance on electronic money institution access for virtual asset service providers
FAQ
How long does a crypto licence take to obtain?
Timeline varies significantly by jurisdiction, licence category and the completeness of the application. In established hubs, initial authorisation typically takes several months from a complete submission. Renewal timelines are generally shorter but are equally dependent on the regulator's current processing capacity and the quality of the submitted documentation. In cross-border structures, the longest individual timeline governs the overall programme, so early preparation across all jurisdictions is essential.
Which jurisdiction is best for licensing my crypto business?
There is no single best jurisdiction. The right licensing environment depends on your activity type, your target client base, your banking requirements and the regulatory posture you need to support your product. An exchange targeting EU retail clients needs a MiCA CASP authorisation. A custody vehicle for institutional clients may look to ADGM or Singapore. A token issuer raising from global investors faces a different matrix entirely. We map the licence stack against the business model before recommending a structure.
Do I need a separate custody licence?
In most flagship regulatory regimes, custody is a separately regulated activity that requires its own authorisation or a specific extension to an existing one. Under MiCA, custody and administration of crypto-assets on behalf of clients is a defined CASP service. Under VARA, custody is a separately licensed activity. Under MAS, safeguarding of digital payment tokens carries distinct conditions. Operating exchange and custody services under a single authorisation that covers only exchange activities is a compliance breach in most of these regimes. We advise on the variation process for adding custody to an existing structure.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across more than seventy jurisdictions, on disputes and on-chain asset recovery across more than twenty-five forums, and on the tax, banking and compliance that sit around them. We map the licence stack across operating, custody and payment layers before you commit to a structure – and we manage the renewal and variation cycle throughout the operation's life. Digital assets are the whole of our practice. Operators we advise range from early-stage token issuers structuring their first authorisation to established exchanges managing simultaneous renewal obligations across multiple regulatory environments. To discuss your situation, contact info@oboluslaw.com.
By Aisha Tan, Licensing and Jurisdictions Analyst – specialising in multi-regime authorisation strategy, cross-border renewal coordination and licence variation for digital-asset operators.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.