EST · MMXXVI
Home/Services/Licensing Registration/VASP licence application for Institutional Clients
Licensing & Registration

VASP licence application for Institutional Clients

Vasp licence application for Institutional Clients. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

Operating without the correct VASP licence (virtual asset service provider authorisation) exposes an institutional digital-asset business to enforcement action, account closures and permanent reputational damage across every jurisdiction where its users sit. VASP licence application is not a one-time filing; it is a multi-layer process that maps the business model, the client base and the banking architecture to the applicable regulatory authorisation before a single form is submitted. The sections below set out the regulated basis, the application process, the cross-border reality and the decision matrix that institutional operators need before they commit to a licensing path.

Why VASP licensing matters for institutional operators

Institutional digital-asset businesses face a more demanding regulatory scrutiny than retail-facing platforms. Counterparties – prime brokers, custodians and banking correspondents – increasingly require sight of a current regulatory authorisation before they will open an account or extend a credit line. VASP registration is the baseline; in the leading hubs, it is a full regulatory authorisation (a licence, not a mere notification) that triggers prudential capital requirements, AML/CFT program expectations and ongoing supervisory reporting.

In our practice, the businesses that run into the most serious difficulties are those that assume a historical registration in a less-supervised jurisdiction still satisfies their counterparties and regulators elsewhere. It rarely does. As VASP supervision tightens across the major hubs – from ESMA enforcing the MiCA regime across the EU to VARA in Dubai running full rulebook reviews – the gap between a registration and an operating licence has become a material legal risk.

The loss-aversion framing is direct: an institutional operator that has invested eight figures in technology and staff can see its banking rails frozen within days of a regulatory referral. The cost of a proper licence application is a fraction of the cost of unwinding an enforcement situation.

The process above describes the standard path. Your facts – the entity structure, the user base, the banking architecture – change the analysis materially. For a scoped assessment of your licensing position, contact OBOLUS at info@oboluslaw.com or map your options here.

What activities require a VASP licence?

The activities that trigger a licensing obligation depend on the regime, but four categories appear across every major framework: exchange services (crypto-to-crypto and crypto-to-fiat), custody and safeguarding, transfer and settlement services, and brokerage or advisory services connected to digital assets. Under MiCA, these are defined as CASP (crypto-asset service provider) activities, and a business conducting any one of them for clients in the EU/EEA must hold a CASP authorisation or passport from a member-state competent authority.

Under the VARA regime in Dubai, the framework is activity-specific: separate rulebook modules govern exchange, custody, lending, broker-dealer, management and transfer/settlement services. An institutional operator running a multi-product platform may trigger two or three VARA activity licences simultaneously. In Singapore, the MAS Payment Services Act distinguishes between digital payment token (DPT) services, e-money services and account issuance – and the applicable tier (standard payment institution or major payment institution) carries meaningfully different capital and compliance obligations.

The common error at this stage is modelling the business around one activity and ignoring the others. A custodian that also executes client orders is conducting exchange or brokerage activity. A lending desk that holds collateral is conducting custody activity. Each additional activity layer adds a licensing obligation – and regulators in the leading hubs have demonstrated a willingness to take enforcement action against operators who licence one activity and operate several.

How does the VASP licence application process work?

A well-run VASP licence application follows five sequential stages: pre-application structuring, documentation, submission, regulatory dialogue, and licence grant with conditions. At each stage, the quality of the legal and compliance work determines the speed of the outcome.

Stage 1 – Pre-application structuring. The applicant must establish the correct legal entity in the chosen jurisdiction, confirm the fitness-and-propriety profile of its senior management and ultimate beneficial owners, and draft the group structure chart that the regulator will review. Under MiCA and VARA alike, the entity structure must match the activity scope. A holding company that owns an operational subsidiary may need the subsidiary – not the parent – to hold the licence.

Stage 2 – Documentation. Core documents include the business plan (with financial projections covering the regulator's prescribed horizon), the AML/CFT policy and procedures manual, the internal controls framework, the custody or safeguarding policy, the risk management framework and the IT security summary. In our experience, the business plan and the AML manual are the two documents that most frequently trigger a regulatory request for additional information – either because the financial projections are not credible or because the AML policy does not map to the specific activities being licensed.

Stage 3 – Submission and fee payment. Regulatory filing portals, fee schedules and submission formats differ materially between ESMA/national competent authorities under MiCA, VARA, MAS, the SFC in Hong Kong and the FCA in the UK. Each has a different completeness-check process; an incomplete submission restarts the clock.

Stage 4 – Regulatory dialogue. All major regulators conduct a review period during which they raise queries, request supplementary documents and may invite the applicant for a management meeting. Institutional operators should treat this phase as a negotiation, not an administrative formality. The regulator's questions reveal its concerns; addressing them with precision shortens the review materially.

Stage 5 – Licence grant and conditions. Most licences are granted with conditions: capital maintenance obligations, reporting timelines, restrictions on the scope of permitted activities, and ongoing supervisory cooperation expectations. Conditions must be mapped to internal compliance workflows before the business goes live. A condition that is breached in the first operating quarter is a significant regulatory event.

How long does a VASP licence application take?

Timeline varies materially by jurisdiction and by the completeness of the application at submission – qualitative ranges reflect the operational reality, and hard figures should be confirmed against current regulatory guidance before any business plan is finalised. Under MiCA, the prescribed review period for a CASP authorisation runs from the date the application is declared complete; member-state competent authorities differ in how quickly they reach that completeness determination. Under VARA, the review process is structured around defined stages, but the overall timeline depends on the complexity of the activity scope and the management vetting queue. In Singapore, MAS has published indicative review periods that differ between the standard and major payment institution tiers.

Operators regularly underestimate the pre-submission phase. Assembling a credible business plan, vetting the entire UBO chain through the fitness-and-propriety process, drafting a MiCA-compliant AML manual and building the IT security documentation takes weeks even for well-resourced teams. In our cross-border practice, we have seen pre-submission preparation consume more calendar time than the formal regulatory review in jurisdictions with a defined statutory clock.

The cross-border reality adds a further dimension. An operator that files in an EU member state under MiCA must also consider whether its activities in the UK require FCA registration, whether its US-facing business triggers FinCEN VASP obligations, and whether its Dubai or Singapore entity needs its own local authorisation. Each filing runs on its own timeline. Managing four simultaneous applications without a coordinated legal structure is a common source of delay and of conflicting regulatory commitments.

Common mistakes in VASP licence applications

The five mistakes we encounter most often have two things in common: they are avoidable, and they are expensive to correct after the regulator has already seen the application.

First, mismatch between the entity and the activity scope. A single-purpose entity licensed for custody that then begins executing client orders has breached its licence conditions before it has generated meaningful revenue.

Second, UBO chain not fully resolved before filing. Most institutional digital-asset businesses have complex multi-jurisdictional ownership structures. Regulators require full disclosure of the ultimate beneficial owner chain. An application that discloses an intermediate holding company without tracing the chain to the natural-person UBO will be held incomplete.

Third, AML manual copied from a template without jurisdiction-specific customisation. A VARA examiner reviewing a document that references European-style entity classifications, or an MAS examiner reviewing a document built for a UK MLR registration, will identify the mismatch immediately. The credibility cost is significant.

Fourth, insufficient financial projections. Institutional operators sometimes submit projections that show profitability without showing the capital adequacy pathway – that is, how the own-funds position is maintained through the regulatory-prescribed horizon even under stress scenarios.

Fifth, no plan for the regulatory dialogue phase. The pre-submission effort is front-loaded, but operators who treat the review period as passive waiting frequently miss the window to address regulator concerns before they crystallise into formal objections.

Cross-border licensing requirements for institutional digital-asset firms

Institutional digital-asset businesses rarely operate from a single jurisdiction. The entity may sit in Dubai or Singapore; the custodian may be in Cayman or BVI; the treasury account may be in Switzerland or the UK; and the client base may span the EU, the Gulf and Asia-Pacific. Each layer of this structure carries its own licensing requirement, and VASP registration in one jurisdiction does not create a passportable right in another – except within the EU/EEA under MiCA's passporting mechanism for CASP authorisations.

The AIFC/AFSA regime in Kazakhstan has emerged as a common-law hub for digital-asset businesses serving Central Asian and CIS markets. The BVI FSC and CIMA in the Cayman Islands remain standard fund and holding-structure jurisdictions, each with their own VASP Act requirements. A business that structures its fund in Cayman, its operating entity in ADGM and its retail-facing exchange in a MiCA-passporting EU member state needs three separate applications, three separate compliance programs and three sets of ongoing reporting obligations – coordinated through a single legal architecture.

In our practice, we map the full licence, banking and tax stack before a client commits to a jurisdiction. The choice of operating jurisdiction is not only a licensing decision; it determines the banking relationships available, the corporate tax exposure, the treatment of staking and lending income, and the AML/CFT standards that will govern the customer onboarding process.

A practical note on allied counsel: where an application requires local counsel in a jurisdiction outside our direct footprint, we work with allied counsel in the relevant jurisdiction – coordinating the multi-jurisdiction filing process and ensuring that the legal architecture is consistent across each entity.

If a prior application stalled, an account was closed or a regulatory query has arrived, a second read of the structure can surface the issue and the route forward. Write to us at info@oboluslaw.com or map your options here.

Decision matrix: which licensing profile fits your business?

The right licensing path turns on four variables: the activity scope, the client base, the entity structure and the banking requirements. The following profiles capture the most common institutional configurations we advise on.

Profile A – Single-jurisdiction institutional exchange or custody desk. The operator runs one activity (exchange or custody) from one entity, serves professional and institutional clients only, and has a defined geographic footprint. The preferred path is a single full regulatory authorisation in a tier-one hub: CASP under MiCA if the user base is EU/EEA-concentrated; VARA in Dubai if the client base is Gulf and MENA-focused; MAS DPT licence if the focus is Asia-Pacific. Timeline is measured in months from a complete submission; the key risk is the UBO vetting queue.

Profile B – Multi-product institutional platform (exchange + custody + lending). The operator runs three or more activities from a single entity or a closely connected group. VARA's activity-specific rulebook is built for this structure; MiCA's CASP authorisation also covers multiple activities under a single instrument. The key risk is that each additional activity adds a compliance layer; the regulatory review is longer and the capital requirement is higher. Building a modular compliance program – one that can be audited activity by activity – shortens the dialogue phase.

Profile C – Fund structure with a trading or management mandate. The manager entity needs a management or advisory VASP authorisation; the fund itself may need registration under the applicable fund regime (Cayman, BVI, ADGM). The licensing and fund-registration processes run in parallel; misaligning the two timelines is a common source of delay at investor onboarding.

Profile D – Cross-border group with EU, UAE and APAC entities. Three separate applications are running simultaneously: a MiCA CASP in an EU member state, a VARA authorisation in Dubai and a MAS DPT licence in Singapore. Each requires a separate entity, a separate AML program and separate ongoing reporting. The legal architecture must ensure that intercompany transactions, custody delegation arrangements and shared infrastructure do not create unlicensed activity in any of the three jurisdictions.

Micro-matter: multi-jurisdiction platform launch

In a recent licensing engagement, an institutional trading platform sought to launch simultaneous exchange and custody operations across an EU member state and the Gulf. The group had been advised informally that a single offshore registration would satisfy both regimes. On review, the EU entity required full MiCA CASP authorisation – not a transitional notification – and the Gulf entity required a VARA exchange licence with a separate custody activity endorsement. We restructured the entity architecture, prepared the full documentation set for both applications and managed the regulatory dialogue in parallel with allied counsel in the relevant jurisdiction. The platform obtained both authorisations within the combined timeline its board had set for the product launch. No activity was conducted before authorisation was in place.

What does the VASP licensing process cost?

Regulatory fees are set by each authority and change periodically; they should be confirmed from official sources before budgeting. Legal fees for a full VASP licence application vary by the complexity of the activity scope, the number of jurisdictions involved and the state of the documentation at the point of engagement. OBOLUS offers transparent fixed-scope packages with a stated starting fee for defined application types, and hourly engagements for complex multi-jurisdiction projects where the scope is open-ended. All pricing is set out on our Fees page and confirmed in the initial scoping call – there are no surprises mid-application.

The scoping call is free, confidential and conducted under NDA on request. It takes approximately forty-five minutes and produces a clear scope-of-work estimate before any commitment is made.

A common assumption worth correcting

A common assumption among institutional operators entering this process is that a single offshore VASP registration is sufficient to serve clients globally. It is not. Offshore registrations – whether in a less-supervised jurisdiction or in a recognised offshore financial centre – are treated by EU, UK, US, Singapore and UAE regulators as the legal baseline for the registering jurisdiction only. They do not create a right to solicit, onboard or service clients in those jurisdictions. An institutional operator that routes EU-resident clients through an entity with only an offshore registration is operating without regulatory authorisation in the EU – full stop. The consequence is not a warning letter; it is an enforcement referral, account closures and, in serious cases, personal liability for senior management.

The practical corrective is a licence-stack analysis before the commercial model is finalised. Map where the clients are, map where the revenues are booked, and map the regulatory authorisation required in each of those jurisdictions. The stack will almost always include more than one licence.

Related at OBOLUS

FAQ

How long does a crypto licence take to obtain?

Timeline varies materially by jurisdiction, activity scope and the completeness of the application at the point of submission. The formal review period begins once the regulator declares the application complete – and pre-submission preparation often takes as long as the review itself. Operators should budget several months from initial engagement to licence grant in the leading regulated hubs, and longer for complex multi-product or multi-jurisdiction applications. Confirm current timelines with the relevant authority before finalising any business plan.

Which jurisdiction is best for licensing my crypto business?

There is no universally correct answer. The right jurisdiction turns on the activity scope, the client base, the banking relationships required and the long-term operating model. MiCA passporting is attractive for EU-facing businesses; VARA suits Gulf-and-MENA-focused operators; MAS is the benchmark for Asia-Pacific institutional platforms. An operator that selects a jurisdiction on cost alone, without mapping the banking and client-reach implications, typically needs to re-licence within two years. We map the full licence, banking and tax stack before recommending a path.

Do I need a separate custody licence?

In most leading jurisdictions, custody of client digital assets is a regulated activity that requires either a standalone custody authorisation or an explicit custody endorsement on an existing licence. Under MiCA, custody and administration of crypto-assets is a defined CASP service. Under VARA, custody is a separate activity module with its own rulebook. An operator that holds client assets – even temporarily – without the appropriate custody authorisation is in breach of the regime. Whether a separate entity or a single multi-activity entity is the right structure depends on the business model and the applicable regulatory requirements.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance structures that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit – so that the structure you build is the one you can operate and grow. To discuss your licensing situation, contact info@oboluslaw.com or message us at t.me/oboluslaw.

By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in multi-jurisdiction VASP authorisation strategy and regulatory application management for institutional digital-asset businesses.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours