Operating a digital-asset business without the correct regulatory authorisation is not a compliance technicality. It is an existential risk. Regulators across the major hubs are tightening supervision of virtual asset service providers (VASPs – businesses that exchange, transfer, custody or issue digital assets for others), and enforcement actions now routinely result in frozen banking rails, mandatory wind-downs and personal liability for directors. The question a general counsel should be asking is not whether to licence, but which licences, in which sequence, and whether the current structure can survive regulatory scrutiny.
A VASP licence application (regulatory authorisation permitting a business to provide defined virtual-asset services) is not a standalone event. It is the output of a structured analysis covering entity design, activity perimeter, user geography, banking connectivity and AML posture. Businesses that treat it as a form-filling exercise consistently face delays, rejection or – worse – a licence that covers only part of what they actually do. This page sets out the regime basis, the process, the cross-border complications and the common failure modes we observe in practice.
What triggers the obligation to obtain a VASP licence?
The obligation to hold a regulatory authorisation arises the moment a business performs a regulated virtual-asset activity – and "regulated" is defined by the jurisdiction where the user is located, not only where the company is incorporated. That asymmetry is where most enforcement exposure begins.
Under MiCA (the EU's Markets in Crypto-Assets Regulation, supervised by ESMA and national competent authorities), any business offering crypto-asset services to EU clients must hold a CASP (crypto-asset service provider) authorisation, regardless of where it is headquartered. The activity perimeter covers exchange, custody, transfer, placing and reception-and-transmission of orders, among others. MiCA's passporting mechanism then allows a CASP authorised in one member state to serve the entire EU/EEA without a separate authorisation in each country – a structural advantage that makes entry-point selection strategically significant.
In Dubai, VARA (the Virtual Assets Regulatory Authority) applies an activity-based licensing model. Each regulated activity – exchange services, custody, lending, advisory, broker-dealer – requires its own licence endorsement under the applicable VARA rulebooks. Mainland Dubai operations are within VARA's scope; the DIFC financial free zone operates under a separate FSRA-adjacent regime. Businesses building multi-activity platforms in the region therefore face a multi-licence stack from day one.
Across Singapore, the MAS Payment Services Act creates a tiered licensing structure for digital payment token services, with capital and safeguarding requirements that escalate with transaction volume. In Hong Kong, the SFC VASP licensing regime for virtual-asset trading platforms carries robust vetting requirements for controllers and key personnel. In the UK, the FCA requires cryptoasset businesses to register under the Money Laundering Regulations before commencing regulated activities, with financial promotion rules adding a separate compliance obligation for marketing to UK persons.
The practical implication: any business serving users across more than one major hub is almost certainly operating under multiple simultaneous regulatory obligations, whether or not it has obtained the corresponding licences.
Operating without the right authorisation exposes the business to enforcement, frozen banking relationships and loss of market access. In our practice, we see inbound operators discover this exposure only after a banking correspondent terminates the account or a regulator opens an enquiry.
The process above describes the standard perimeter analysis. Your facts – the entity structure, the user base, the activities performed – change the analysis entirely. For a scoped assessment of your licence obligation, contact OBOLUS at info@oboluslaw.com.
How does a VASP licence application process work?
A well-run VASP licence application follows a defined sequence: activity scoping, entity and group structure review, jurisdiction selection, document preparation, regulatory submission and post-authorisation compliance build. Each stage carries its own failure modes.
The first stage – activity scoping – defines the exact perimeter of what the business does and maps each activity to the applicable regulatory category in each target jurisdiction. This sounds mechanical; it is not. An exchange that also provides custody, generates yield on client assets and settles in its own token may be performing five or more regulated activities simultaneously. Mischaracterising any one of them produces a licence that is under-scoped on day one.
Entity and group structure review follows immediately. Regulators in virtually every flagship hub now scrutinise the full group – parent, subsidiaries, sister companies, controlling persons. A holding structure that was optimised for tax or investment purposes may create ownership transparency problems that delay or prevent authorisation. Under MiCA and the VARA regime, for example, fit-and-proper assessments extend to ultimate beneficial owners and to any person who exercises significant influence over the business. Regulators increasingly expect to see the corporate chain resolved to natural persons before they will progress an application.
Jurisdiction selection is not simply a matter of choosing the fastest or cheapest option. The correct jurisdiction is determined by where the regulated activity is performed, where the users are, where banking is available and what passporting or mutual-recognition options exist. For EU-facing businesses, a MiCA CASP authorisation through an appropriately chosen member state provides EU-wide access through passporting – but the choice of NCA matters, because processing timelines and supervisory expectations vary. Lithuania's Bank of Lithuania built a reputation as a responsive EU entry point under the prior VASP regime; under MiCA, that positioning continues to be tested against the broader CASP authorisation standard.
Document preparation is resource-intensive. A standard application to a major-hub regulator requires a detailed business plan, AML/CFT policies and procedures, organisational charts, IT and cybersecurity assessments, financial projections, outsourcing arrangements and, in many regimes, a record-keeping and custody framework. Applications to VARA in Dubai or the SFC in Hong Kong additionally require evidence of a functioning compliance function and a nominated Money Laundering Reporting Officer in place before submission.
Post-submission, the timeline is determined by the regulator's current caseload and the completeness of the application. Regulators in every major hub reserve the right to issue information requests – gaps in the initial submission reliably extend the process. In our experience advising across the leading hubs, an incomplete or inconsistently structured application almost always triggers a material delay.
What does the cross-border licence stack actually look like?
Most digital-asset businesses are structurally multi-jurisdictional before they obtain their first licence. The entity may be incorporated in one jurisdiction, the banking in a second, the technology infrastructure in a third and the user base spanning a fourth and fifth. Each layer carries its own regulatory consequence.
The dominant mistake is optimising for one jurisdiction in isolation. A crypto exchange that obtains a BVI FSC VASP registration under the BVI VASP Act 2022 and then serves EU retail clients without a MiCA CASP is not protected by the offshore registration – ESMA's position on reverse-solicitation exceptions is strict, and the practical effect is that the business is operating without authorisation in the EU. The same analysis applies to businesses serving Singapore or Hong Kong residents from an unrecognised offshore entity.
The practical structure for a business operating across multiple major hubs therefore typically involves a principal regulated entity in a flagship jurisdiction (often an EU member state under MiCA, or Singapore under the MAS Payment Services Act), with activity-specific supplementary registrations in each additional market. The Cayman Islands and BVI structures that remain common for fund and investment vehicles carry their own VASP obligations under CIMA and the BVI FSC respectively – and both now require FATF-compliant AML programmes regardless of the primary business jurisdiction.
Banking connectivity compounds the analysis. Most Tier 1 banking relationships for crypto businesses require the business to hold a recognised regulatory authorisation in a jurisdiction the bank considers credible. An AIFC/AFSA authorisation in Kazakhstan may satisfy banking relationships focused on the CIS corridor that a Caribbean registration would not. A FINMA-supervised Swiss entity may unlock relationships closed to an entity regulated only in a smaller jurisdiction. The banking stack and the licence stack must be planned together.
The Travel Rule (the FATF obligation requiring VASPs to pass originator and beneficiary data with virtual-asset transfers) also creates a structural incentive to consolidate licensing: a VASP without a recognised authorisation in a major hub may find that counterpart VASPs in regulated jurisdictions refuse to transact with it, because the counterpart cannot satisfy its own Travel Rule compliance obligations without a verified counterpart registration.
In our cross-border practice, we map the licence, banking and AML stack together before a client commits to an entity structure. Changing the structure after banking is in place or after an application is submitted is substantially more expensive and more disruptive than getting the sequence right at the design stage.
What are the most common mistakes in VASP licence applications?
The most common failures in VASP licence applications are structural, not documentary – and they are almost always correctable before submission if identified in time.
Under-scoped activity perimeter. A business describes its services conservatively in the application to simplify the regulatory analysis, and obtains a licence that does not cover all of what it actually does. This creates an ongoing compliance gap that is typically discovered during the first regulatory examination or when a banking correspondent requests confirmation of the scope of authorisation.
Beneficial ownership opacity. The application cannot resolve the corporate chain to natural persons because the holding structure involves nominee arrangements, discretionary trusts or complex multi-jurisdictional layers. Regulators do not approve applications where the ultimate controller is unclear. We regularly advise on restructuring the ownership chain to achieve the transparency regulators require without compromising legitimate structural objectives.
AML programme deficiency. The policies submitted are generic templates rather than business-specific programmes. A crypto exchange, a custody provider and a token issuer have materially different AML risk profiles and require materially different programmes. Submitting a template that does not address the specific risk factors of the business – including on-chain transaction monitoring, Travel Rule compliance, stablecoin-specific risks – is one of the most reliable predictors of a regulator's information request.
Key personnel gaps. The compliance officer, MLRO or chief technology officer listed in the application is not in post, or has not been assessed for fit-and-proper purposes in advance of submission. Regulators in major hubs increasingly assess key personnel before approving the application, and a gap discovered mid-process delays the timeline materially.
Jurisdiction selection driven by cost alone. Choosing the jurisdiction with the lowest stated fees and fastest advertised processing time, without accounting for banking availability, user base regulation and the credibility of that authorisation with banking correspondents and institutional counterparts, is a decision that creates problems in the operating phase even where the licence itself is obtained.
A micro-matter illustrates the structural risk. In a recent licensing engagement, an established payments company sought to add virtual-asset exchange services to its existing business. The initial application, prepared by its domestic corporate advisers, described the activity perimeter in terms drawn from the domestic financial services act rather than the applicable VASP regime. The regulator's first information request identified the mismatch. We were engaged at that stage, revised the activity description, restructured the AML programme to address crypto-specific risk factors and assisted the client in addressing the regulator's queries on an accelerated basis. Authorisation was obtained in the following quarter.
If a prior application has stalled or an account was closed following a regulatory enquiry, a second structural read often surfaces the cause and the route forward. To discuss a current application or a stalled process, write to info@oboluslaw.com or message us at t.me/oboluslaw.
Which licence structure fits which operator profile?
Licence selection is not one-size-fits-all. The appropriate structure turns on the business model, the user geography, the activity perimeter and the banking requirements. The following profiles describe the typical decision paths we work through with clients.
Profile A – EU-facing exchange or custody provider. The business serves or intends to serve retail or institutional clients across EU member states. The primary instrument is a MiCA CASP authorisation through an appropriately selected EU member state, with passporting used to cover additional member states. The key risk is the NCA selection: processing timelines and supervisory expectations vary across member states, and the choice of entry point affects the speed of passporting notification in each additional market. Timeline from application submission to authorisation varies by NCA and application quality; planning for a process measured in months rather than weeks is prudent.
Profile B – Dubai or wider MENA-facing operator. The business operates in or out of Dubai and serves regional clients. VARA authorisation is the applicable instrument for mainland Dubai operations, with activity-specific endorsements required for each regulated function. The ADGM/FSRA regime covers Abu Dhabi and is frequently chosen by institutional operators targeting MENA and international clients from a common-law environment. The key risk is the activity-by-activity endorsement structure: expanding services post-authorisation requires additional regulatory approval, so the activity perimeter must be planned in full at the outset.
Profile C – Asian hub operator. The business is building a regulated exchange or custody business for Asian institutional and retail clients. Singapore's MAS Payment Services Act provides a well-developed DPT licensing structure with clear capital tiers; Hong Kong's SFC VASP regime is the applicable instrument for trading platform operators serving Hong Kong clients. Both jurisdictions carry substantial vetting requirements for controllers and key personnel. Timeline from application to authorisation is typically a process measured in months, subject to application quality and regulatory caseload. The key risk is the fit-and-proper vetting timeline for proposed directors and officers.
Profile D – Offshore fund or investment vehicle. The structure is primarily a Cayman or BVI vehicle for investment purposes. Both the CIMA regime and the BVI FSC VASP Act 2022 create registration obligations for virtual-asset services performed from or within those jurisdictions. The key risk is assuming the offshore registration satisfies obligations in the jurisdictions where investors or users are located – it does not, and a supplementary regulatory analysis for each investor jurisdiction is required.
Profile E – UK or Swiss precision operator. The business is building a regulated entity in a respected single-jurisdiction environment, often to support institutional counterpart relationships. FCA registration under the Money Laundering Regulations is the entry point for UK crypto businesses; the FINMA licensing route in Switzerland (fintech licence, banking licence or SRO affiliation) provides a strong institutional credibility signal. Both jurisdictions carry detailed AML and financial-promotion obligations. The key risk is underestimating the compliance infrastructure required to satisfy ongoing supervisory expectations post-registration.
Is a single offshore licence sufficient for a global crypto business?
A common assumption is that a single offshore VASP registration – BVI, Cayman or a smaller jurisdiction – is sufficient to provide services globally because the business is not incorporated in the jurisdictions where users are located. That assumption is incorrect, and it is one of the most reliable predictors of enforcement exposure we observe in practice.
Regulatory jurisdiction over a digital-asset business is determined by the location of the activity and the location of the user, not the location of the company. A business incorporated in the BVI that markets exchange services to EU residents is performing a regulated activity in the EU under MiCA, regardless of what its BVI FSC registration says. The reverse-solicitation exception available under MiCA is narrow and requires genuine unsolicited client approach; regulators and courts have consistently scrutinised claims of reverse solicitation made to excuse the absence of an EU authorisation.
The same jurisdictional reach applies across Singapore, Hong Kong, the UK and the UAE. MAS, SFC, FCA and VARA each assert regulatory authority over businesses that actively market to or serve clients in their respective jurisdictions, irrespective of where the legal entity is established.
The practical consequence is that a business operating at scale across multiple major markets almost always requires a multi-licence stack. The offshore registration may remain relevant – for specific activities, for the fund/investment vehicle layer or as part of a legitimate group structure – but it cannot substitute for regulatory authorisation in the markets where the business is actually active.
We map the full licence obligation across operating, custody and payment layers before a client commits to a structure. That mapping consistently reveals obligations the business did not know it had – and the cost of addressing them at the design stage is a fraction of the cost of addressing them in enforcement.
Self-assessment: Is your current licence position adequate?
The following questions are not exhaustive, but they identify the most common gaps in a business's current regulatory authorisation position. A "no" or "uncertain" answer to any of them warrants a structured review.
- Does the current licence or registration cover every activity the business performs – exchange, custody, transfer, advisory, token issuance?
- Does the licence cover the jurisdictions where the business's users are actually located, not only where the entity is incorporated?
- Has the beneficial ownership chain been resolved to natural persons in a form that satisfies the regulator's fit-and-proper requirements?
- Is the AML programme specific to the crypto activities performed – including on-chain transaction monitoring and Travel Rule compliance?
- Are all key personnel (compliance officer, MLRO, responsible managers) formally appointed and assessed for fit-and-proper purposes?
- Does the banking correspondent accept the current regulatory authorisation as satisfying its own AML due-diligence requirements?
- If the business holds an offshore registration, has a supplementary legal opinion been obtained on its sufficiency for each jurisdiction where users are located?
Operators we advise regularly discover that one or more of these questions exposes a gap they had not previously identified. The consequence of discovering that gap in an enforcement context is materially worse than discovering it in a structured pre-enforcement review.
Related at OBOLUS
- Licensing and registration for digital-asset businesses – the full scope of OBOLUS's regulatory authorisation practice across 70+ jurisdictions.
- EMI licensing for crypto firms: the disputes angle – how e-money institution licensing intersects with crypto enforcement and disputes risk.
- Real-world asset tokenization in Guernsey – structuring tokenized assets in a regulated offshore environment.
FAQ
How long does a crypto licence take to obtain?
Timeline depends on the jurisdiction, the regulator's current caseload and the quality of the application. For major-hub regimes – MiCA CASP, MAS Payment Services Act, SFC VASP, VARA – a realistic planning assumption is a process measured in months from submission to authorisation. Incomplete applications reliably extend the timeline. Pre-submission preparation – including entity structuring, AML programme development and key personnel vetting – typically takes additional weeks. We advise building the full timeline into your operating plan before committing to a launch date.
Which jurisdiction is best for licensing my crypto business?
There is no universally optimal jurisdiction. The right choice is determined by where your users are located, what activities you perform, what banking connectivity you need and what passporting or mutual-recognition options are available. EU-facing businesses typically require a MiCA CASP authorisation. MENA-focused operators evaluate VARA and ADGM/FSRA. Asian operators assess MAS and SFC. Offshore registrations in BVI or Cayman supplement but do not replace major-hub authorisations for businesses serving clients in regulated markets. We map the full stack before you commit to a structure.
Do I need a separate custody licence?
In most flagship regimes, custody of virtual assets is a separate regulated activity that requires its own authorisation or endorsement. Under MiCA, custody and administration of crypto-assets is a distinct CASP service category. VARA treats custody as a separate activity endorsement. MAS and SFC similarly distinguish custody from exchange and transfer services. A business that holds client assets – even incidentally as part of an exchange or settlement function – must confirm whether that holding constitutes custody under the applicable regime and obtain the corresponding authorisation before commencing the activity.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on regulatory authorisation across more than 70 jurisdictions, mapping the licence, banking and AML stack together before a client commits to a structure. We also advise on disputes and on-chain asset recovery across more than 25 leading forums, and our disputes team coordinates freezing relief and on-chain tracing across leading common-law jurisdictions. Digital assets are the whole of our practice. To discuss your VASP licence application or your current regulatory authorisation position, contact info@oboluslaw.com or message us at t.me/oboluslaw.
By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in VASP authorisation strategy and multi-jurisdiction licence stack design for digital-asset businesses.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.