Operating a digital-asset business without the right authorisation is not a grey-area risk. It is an enforcement trigger. Regulators across the EU, the Gulf, Southeast Asia and the British Isles are actively supervising VASP (virtual asset service provider) populations, and the cost of a missed licence – frozen payment rails, a public enforcement notice, or a criminal referral – lands hardest on early-stage businesses that cannot absorb the disruption. The question for a founder is not whether to licence, but which licences, in which order, and structured around which entity.
A VASP licence application is the formal process by which a business obtains regulatory authorisation to offer virtual-asset services – exchange, custody, transfer, brokerage or advisory – in a given jurisdiction. Under frameworks including MiCA (the EU's Markets in Crypto-Assets Regulation) and the VARA (Virtual Assets Regulatory Authority) regime in Dubai, that authorisation is activity-specific and entity-specific. A licence granted to one group company does not automatically extend to another, and a licence in one jurisdiction does not permit soliciting clients in another without further steps. This page maps the process, the cross-border mechanics and the decision points that matter most at the early stage.
Why Early-Stage Founders Face Asymmetric Licence Risk
The regulatory risk is not distributed evenly across a crypto business's lifecycle. Early-stage founders carry disproportionate exposure because they are building the product and the compliance structure simultaneously – and the licensing clock starts running from first user interaction, not from Series A. A business that on-boards its first paying customer before obtaining the relevant authorisation has already triggered the regulated perimeter in most major jurisdictions.
Under the MiCA regime, a CASP (crypto-asset service provider) authorisation is required before offering services to EU clients, regardless of where the entity is incorporated. VARA in Dubai and the FSRA within the ADGM apply a similar logic: the activity triggers the licence obligation, not the entity's domicile alone. Founders who believe that an offshore incorporation defers or eliminates this obligation are routinely surprised when their payment processor, their exchange partner or their institutional client requests evidence of the relevant regulatory status.
In our practice, we see two failure modes at this stage. The first is the founder who defers licensing because the product is still in beta – and then discovers that the beta already constitutes a regulated activity. The second is the founder who picks a single offshore jurisdiction and assumes it covers all markets. Neither position survives engagement with a sophisticated banking partner or a tier-one user base.
Enforcement risk begins at first customer contact. That is the practical standard regulators apply, and it is the standard founders need to build against from day one.
For a scoped assessment of where your business currently sits on the regulatory perimeter, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity structure, the user base geography, the banking relationships – change the analysis materially.
Mapping the Regulated Perimeter: What Triggers a VASP Licence?
A VASP licence obligation is triggered by the nature of the activity, not the intention behind it. Most flagship regimes define the regulated perimeter by reference to a list of activities: operating a trading platform, providing custody, executing transfers on behalf of users, brokering transactions, or offering investment advice on digital assets. If your product does any of these things commercially, you are presumptively in scope.
The threshold question is whether the activity involves third-party assets or third-party funds. A purely self-custodial wallet tool sits outside the perimeter in most regimes. A platform that holds user assets, matches buyer and seller, or routes a transfer on someone else's behalf is almost universally in scope. Under the Payment Services Act in Singapore, the equivalent trigger is the provision of digital payment token services – a category the Monetary Authority of Singapore (MAS) interprets broadly to include facilitated exchange and cross-border remittance in virtual assets.
Token issuance adds a parallel dimension. Under MiCA, an entity issuing an ART (asset-referenced token) or an EMT (e-money token) faces issuer-level authorisation separate from the CASP regime. A business that both issues a token and operates the secondary trading venue for that token potentially needs both authorisations – a scenario we map explicitly at the structuring stage rather than discovering mid-application.
Geography compounds the analysis. The entity's jurisdiction of incorporation sets the primary supervisory relationship. But the jurisdiction of the users, the jurisdiction of the payment infrastructure, and the jurisdiction of any fund-custody layer each add their own regulatory overlay. A Dubai-licensed exchange serving UK retail users must also satisfy the FCA's financial promotion rules. An EU-passported CASP serving Singapore-resident institutional clients enters MAS supervisory scope for certain activities. Cross-border operations require a licence stack, not a single licence.
How Does the VASP Licence Application Process Work?
The application process for a VASP or CASP authorisation follows a broadly consistent structure across leading jurisdictions, though the depth of the regulator's review and the documentary requirements vary significantly by regime. Understanding the stages prevents the delays that most founders experience.
The process opens with a pre-application engagement. Most regulators – VARA, the FSRA, MAS, and the SFC in Hong Kong – expect or require contact before formal submission. This stage is not ceremonial. It is the moment at which the regulator signals whether the proposed activity fits the current authorisation categories, whether the corporate structure is acceptable, and whether the responsible personnel meet the fitness-and-propriety standard. Founders who skip this stage and file a cold application typically receive a request for fundamental restructuring, adding months to the process.
The formal application assembles the regulatory dossier: the corporate structure chart, the business plan and financial projections, the AML/CFT policies and procedures, the technology and security documentation, the safeguarding and custody arrangements, and the personal declarations and background checks for all controllers and senior managers. The quality of this documentation is the single largest determinant of application timeline. An incomplete or internally inconsistent dossier triggers multiple rounds of regulatory queries. A well-prepared dossier moves through the review queue faster and with fewer follow-up requests.
Review and approval timelines vary by jurisdiction and by the regulator's current caseload. They are described qualitatively in most public guidance – typically a matter of weeks to several months – and the figures we have observed in active matters align with that range. VARA, for example, operates a structured review process tied to its activity-specific licence categories; the SFC in Hong Kong has published a VATP (virtual-asset trading platform) licensing pathway with defined review stages. Timeline estimates we give clients are based on current queue conditions, not on the regulator's published best-case guidance.
Conditional approval or an in-principle approval is common. It signals that the regulator is satisfied with the application in substance but requires completion of specific pre-launch steps – segregated custody arrangements, final technology audit, appointment of a compliance officer, or satisfaction of the minimum capital requirement. Operating on the basis of an in-principle approval before those steps are completed is not the same as holding the licence.
What Are the Most Common Application Mistakes Early-Stage Founders Make?
The five mistakes we see most consistently are structural, not procedural – they originate in decisions made before the application opens, not during it.
The first is entity design that ignores the licensing question. A holding structure optimised for investor equity may place the operating entity in a jurisdiction whose regulator is a poor fit for the planned activity, or may create a group structure that forces the regulated activity through an entity that cannot hold a licence in the target jurisdiction. We review entity structure before the jurisdiction decision is finalised, because restructuring after a licence is granted is costly and disruptive.
The second is premature banking. Founders frequently attempt to open a corporate account before the licence is in place, discover that the bank requires a regulatory reference, and then submit the licence application under time pressure. The resulting application is rushed and the documentation quality reflects it. The sequence should be: entity formation, licensing, banking – in that order, with each step informed by the requirements of the next.
The third is appointing a nominal compliance officer. Most regimes require a named money-laundering reporting officer (MLRO) or compliance officer who satisfies the regulator's fitness-and-propriety criteria. Appointing an individual who has no crypto-specific compliance experience, or who is based in a jurisdiction different from the regulated entity, draws regulatory scrutiny and can result in a requirement to appoint a replacement before the licence is granted.
The fourth is under-developed AML/CFT documentation. The Travel Rule – the obligation under FATF Recommendation 15 to pass originator and beneficiary data with a virtual-asset transfer – is now a baseline expectation in every FATF-member jurisdiction. An application that does not demonstrate a credible Travel Rule compliance programme will not progress. Similarly, a KYC/CDD policy that is copied from a template without adaptation to the specific product and user base is identifiable as such during regulatory review.
The fifth, and most consequential, is single-jurisdiction thinking. A licence obtained in one jurisdiction satisfies the supervisory obligation in that jurisdiction. It does not permit the business to solicit or serve clients in other regulated markets without further steps. We address this in the cross-border section below.
Cross-Border Operations: Why One Licence Is Rarely Enough
A common assumption is that a single offshore licence – a BVI VASP registration, a Cayman VASP authorisation, or an early EU registration – provides a global operating foundation. It does not. Each jurisdiction in which the business solicits, serves, or holds assets for clients applies its own regulatory overlay, and the consequences of operating without the relevant local authorisation are local enforcement, not abstract regulatory disapproval.
The EU passporting mechanism under MiCA is the most powerful cross-border tool in the current regime. A CASP authorised in one EU member state may passport its services across the EU and EEA. This means a Lithuanian authorisation, a Maltese CASP licence, or an authorisation from any other member-state NCA gives the business access to the entire single market for the relevant activity. The passporting notification process requires regulatory steps, but it removes the need for separate national authorisations in each member state. For a business targeting the EU, getting the member-state choice and the initial authorisation right is therefore a multiplier decision, not just a local compliance step.
Outside the EU, bilateral equivalence or mutual recognition arrangements are limited. A MAS-licensed business in Singapore does not automatically have regulatory standing in Hong Kong or the UAE. Each of those jurisdictions has its own regime – the SFC's VATP framework in Hong Kong, VARA and the FSRA in the UAE – and each requires separate engagement. The practical approach for a multi-market operator is to identify the primary market by user-base concentration and anchor the core authorisation there, then build the secondary licence stack based on the business's actual activity in each additional market.
Banking is the layer that makes the cross-border licence decision concrete. A digital-asset business without a licensed status acceptable to its target banking jurisdiction will not hold a fiat account in that market, regardless of the quality of its compliance documentation. The licence, the banking relationship, and the tax structure need to be designed together, not sequentially. In our practice, we map all three layers before the founder commits to a jurisdiction.
In a recent licensing matter, a payments-focused early-stage business had incorporated in a common-law offshore jurisdiction and obtained a local VASP registration, but was unable to open a correspondent banking relationship because its primary user market – the EU – required MiCA CASP status for the relevant activity. We advised on a parallel CASP application in a fast-access EU member state, restructured the group to hold the EU authorisation at the correct operating entity, and the banking relationship was established within the projected window after licence grant.
To map the licence, banking and tax stack for your build, write to info@oboluslaw.com. If a prior application stalled or a banking relationship was refused, a structural review can identify the gap and the route forward.
Decision Matrix: Which Licence Path Fits Which Founder Profile?
Licence strategy is not a one-size outcome. It turns on the operator's activity, the target user base, the capitalisation available, and the desired banking profile. The matrix below is a practical starting point – each profile corresponds to a different primary path.
Profile A – EU-first exchange or brokerage: The primary path is CASP authorisation under MiCA in a member state accessible to the business's structure and personnel. The EU passport then covers the entire member-state market without separate national applications. The key risk is timeline – authorisation in the more established NCAs takes longer than in the newer entrants to the supervision queue. Minimum capital requirements vary by licence category; they are set by the relevant NCA and should be confirmed against current published guidance.
Profile B – Gulf-region trading platform: Dubai's VARA regime is the primary path for mainland Dubai operations; the ADGM/FSRA framework is the equivalent for Abu Dhabi and DIFC-based entities. Activity-specific licensing means the application scope is determined by the exact services offered – exchange, custody, transfer, lending, or some combination. Capital requirements and supervision fees are set by VARA and the FSRA respectively and should be verified against current published rules. Banking in the region requires a licensed status acceptable to UAE-licensed financial institutions.
Profile C – Asia-Pacific operator: MAS licensing under the Payment Services Act is the anchor for Singapore-based operations; the SFC's VATP licensing framework is the anchor for Hong Kong. Both regulators have active supervision programmes and meaningful capital requirements. The key risk is timeline and the depth of the fitness-and-propriety review. AUSTRAC registration in Australia is a parallel obligation for any entity with Australian operations or users. These jurisdictions do not pass-port into each other – a Singapore licence does not cover Hong Kong, and vice versa.
Profile D – Offshore holding with managed market access: BVI or Cayman registration satisfies the local VASP obligation but does not grant market access in the EU, the UAE, Singapore, or Hong Kong. This profile suits a business with a controlled institutional client base where each client relationship is managed through bilateral agreements and the primary regulatory exposure is at the fund or family-office level, not at the platform level. It does not suit a business with broad retail access or public-facing trading infrastructure.
Self-Assessment Checklist: Are You Application-Ready?
Before instructing counsel to file, a founder should be able to answer affirmatively to the following questions. Each "no" is a gap that will surface during regulatory review – better to identify it now than to receive it as a regulatory query after submission.
- Is the regulated entity incorporated in the target jurisdiction, with the correct constitutional documents and share structure?
- Have all ultimate beneficial owners been identified, and is each prepared to submit personal declarations and background checks to the regulator?
- Is there a named, qualified compliance officer (MLRO) who meets the regulator's fitness-and-propriety standard and is based in the correct jurisdiction?
- Does the business have a written AML/CFT policy, a KYC/CDD procedure, and a Travel Rule compliance programme, all tailored to the specific product and user base?
- Has the technology undergone, or is it scheduled for, an independent security audit at the level the target regulator expects?
- Are the custody and safeguarding arrangements for client assets documented, and do they satisfy the segregation requirements of the target regime?
- Is the business plan and financial projection credible over a three-year horizon, with capital adequate to meet the minimum requirement at the date of licence grant?
- Has the cross-border regulatory overlay been mapped – specifically, are there markets in which the business will operate users or hold assets without the relevant local authorisation?
In our practice, founders who have worked through this checklist before the first counsel meeting move through the application process materially faster than those who encounter these questions for the first time during preparation of the regulatory dossier.
Related at OBOLUS
- Licensing and Registration for Digital-Asset Businesses – the full practice overview across 70+ jurisdictions and all major regimes
- VASP Licensing in Australia under AUSTRAC – jurisdiction-specific guide to Australian VASP registration requirements and process
- Crypto Fraud and Asset Recovery in the United Kingdom – how England and Wales courts support digital-asset recovery for business victims
FAQ
How long does a crypto licence take to obtain?
Timeline varies by jurisdiction, regulator caseload, and the quality of the application dossier. In our practice, well-prepared applications in accessible jurisdictions proceed in a matter of weeks to a few months from formal submission to in-principle approval. Regulators with higher application volumes – such as the FCA, MAS and the SFC – typically operate longer review queues. Pre-application engagement with the regulator and a complete first-submission dossier are the two factors most within the applicant's control.
Which jurisdiction is best for licensing my crypto business?
There is no universal answer. The right jurisdiction turns on the activity, the target user base, the available capital, and the banking profile the business needs. For EU market access, a MiCA CASP authorisation with passporting rights is the strongest foundation. For the Gulf, VARA (Dubai) or the ADGM/FSRA (Abu Dhabi) are the primary choices. For Asia-Pacific, MAS (Singapore) and the SFC (Hong Kong) are the anchor regimes. A multi-market operator typically needs a primary authorisation plus secondary registrations in each active market.
Do I need a separate custody licence?
In most flagship jurisdictions, custody of virtual assets is a distinct regulated activity that requires its own authorisation or a specific activity endorsement on an existing licence. Under VARA, custody is one of the named activity categories in the licence structure. Under MiCA, safeguarding and administration of crypto-assets is a listed CASP service. A business that both trades and holds client assets in custody should assume that both activity authorisations are required and confirm this with counsel against the specific regime and the specific assets involved.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. We map the licence stack across operating, custody and payment layers before you commit – so the structure is right from the start, not after the first regulatory query. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com.
By Aisha Tan, Licensing & Jurisdictions Analyst – specialist in multi-jurisdictional VASP authorisation strategy and regulatory dossier preparation for early-stage digital-asset businesses.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.