VASP licence application: Legal Counsel for Digital-Asset Firms
Operating a digital-asset business without the correct licence is not a gap to be managed later. Regulators in every major hub – from VARA in Dubai to the FCA in the United Kingdom to MAS in Singapore – treat unlicensed activity as a trigger for enforcement action: trading suspensions, compelled wind-downs and the loss of banking access that follows. A VASP (virtual asset service provider) licence application is the process by which a business obtains formal regulatory authorisation to offer exchange, custody, transfer or related services in a given jurisdiction. The analysis, preparation and presentation of that application require legal precision at every stage.
This page sets out what the VASP application process involves, where the common failures occur, how cross-border structures complicate the picture, and how OBOLUS supports digital-asset firms through the process – from initial regulatory scoping to the moment a licence is in hand.
What triggers a VASP licence obligation?
The obligation to hold a licence arises the moment a business crosses into a regulated activity – and the perimeter is drawn differently in each jurisdiction. Under MiCA, the EU's Markets in Crypto-Assets Regulation, the regulated perimeter covers any entity offering crypto-asset services as a business, including exchange, transfer, custody, portfolio management and advice. Under the VARA regime in Dubai, the perimeter is drawn by activity type: advisory, broker-dealer, custody, exchange, lending, management and transfer/settlement each carry a distinct licence. Under the applicable Payment Services Act provisions in Singapore, a business providing a digital payment token service requires MAS authorisation at the standard or major payment institution level depending on transaction volume.
In each case, the threshold question is not where the company is incorporated – it is where the service is provided and where the customer is located. A BVI entity offering exchange services to EU residents will attract MiCA scrutiny. A Cayman fund holding client digital assets may require separate custody authorisation in the jurisdiction where clients are onboarded. We consistently see founders underestimate the geographic reach of these obligations.
In our practice, the first task is always a regulatory perimeter analysis: a jurisdiction-by-jurisdiction review of whether each proposed activity – and each user base – crosses into a regulated category. That analysis drives the licence architecture. It is the step most operators skip, and the one that causes the most expensive remediation later.
Which regimes govern VASP licence applications across the major hubs?
The applicable regime determines the scope of the application, the documents required, the capital to be demonstrated and the timeline to expect. Each of the following represents a materially different application environment, not a variation on a standard form.
EU / MiCA – CASP authorisation. A CASP (crypto-asset service provider) authorisation under MiCA is granted by the national competent authority of the member state in which the applicant is established. Once granted, it carries passporting rights across the EU and EEA. The application requires a detailed regulatory business plan, governance documentation, an AML/CFT program, custody and safeguarding arrangements, and – for certain token classes – a compliant whitepaper. The Bank of Lithuania and the MFSA in Malta have each established a track record as receptive NCAs for inbound applicants, though both now apply full MiCA standards.
VARA – Dubai. The VARA regime operates in mainland Dubai and applies across the activity categories set out in the VARA rulebooks. Each activity line requires separate authorisation; a business combining exchange and custody services applies for both. The application is structured around a detailed operational and financial submission, with VARA conducting a vetting process that includes background checks on controllers, a technology assessment and a review of the applicant's AML infrastructure.
MAS – Singapore. Under the Payment Services Act, digital payment token service providers must hold a major payment institution licence if their transaction volumes exceed the applicable threshold, or a standard payment institution licence below it. The MAS application process is document-intensive, with close scrutiny of the applicant's management team, technology arrangements and source-of-funds controls.
SFC – Hong Kong. The SFC's VASP licensing regime for virtual-asset trading platforms applies to centralised exchanges offering trading to the public. The vetting process has a strong operational focus: the SFC reviews the exchange's custody arrangements, risk management systems and client asset protection mechanisms in detail.
FCA – United Kingdom. The FCA's cryptoasset registration under the Money Laundering Regulations is, in form, a registration rather than a full authorisation – but the FCA applies demanding standards, and its rejection rate for applicants has been material. Marketing of crypto products to UK clients also triggers the financial promotion regime, independently of registration status.
What does the VASP application process look like in practice?
A well-run VASP licence application moves through five stages, each with its own dependencies and failure points.
Stage 1 – Regulatory scoping. Before a single document is drafted, the business model, product scope, intended user geographies and corporate structure must be mapped against the applicable regime. This scoping determines which licence categories are needed, which regulator has jurisdiction and whether the proposed structure creates any multi-jurisdictional exposure that requires parallel applications.
Stage 2 – Corporate and governance structuring. Most regulators require the applicant entity to be locally established or have a local branch, a locally resident director or representative, and governance arrangements that satisfy fit-and-proper requirements. Structuring decisions at this stage – choice of entity type, directorship arrangements, shareholder disclosure – directly affect the application's prospects. Changes post-submission are expensive and slow.
Stage 3 – Document preparation. The application package is the core deliverable. It typically includes: a regulatory business plan covering the business model, revenue projections and risk governance; an AML/CFT program aligned with FATF standards, including Travel Rule (the obligation to pass originator and beneficiary data with a virtual asset transfer) compliance procedures; a technology and cybersecurity description; custody and client-asset safeguarding policies; and the biographical and financial information on all qualifying controllers and shareholders. We build this package from a structured template aligned to the specific regulator's published requirements – not a generic document that must be reverse-engineered later.
Stage 4 – Regulatory engagement. Sophisticated regulators – VARA, MAS, the SFC – conduct substantive pre-application engagement. Used well, that engagement identifies concerns before they become reasons to refuse. Used poorly, it locks in positions that are difficult to walk back. In our cross-border practice, we treat pre-application dialogue as a strategic step, not an administrative formality.
Stage 5 – Post-submission management. Regulators issue information requests (RFIs) after submission. Response quality and speed directly affect the timeline to decision. We monitor the queue, respond to RFIs on behalf of clients and manage the back-and-forth until the licence is granted – or until we understand precisely why a decision has gone the other way and what the remediation path looks like.
Timelines vary by regime and by the quality of the submission. Some registrations resolve in a matter of weeks. Full authorisation processes in more demanding regimes typically extend to several months, and in some cases longer where the regulator's queue is congested or an RFI round is protracted. We give clients a working estimate at scoping, updated at each stage – but we do not guarantee a specific outcome or timeline.
OBOLUS maps the licence, banking and tax stack for your build before you commit. Write to info@oboluslaw.com or map your options to start that conversation.
The process above describes the standard path. Your facts – the entity structure, the user base and the banking relationships – change the analysis at every stage. A business with a complex group structure or multi-jurisdictional user exposure will need a more granular scoping before a single document is prepared.
What are the most common mistakes in VASP licence applications?
In our experience, applications fail or stall for a predictable set of reasons – and most of them are avoidable with the right preparation.
Mischaracterising the activity. Founders frequently describe their business in terms that minimise the regulated surface area. Regulators read business plans closely and re-characterise activities in their own terms. An applicant that describes a "token marketplace" will be asked, directly, whether it operates an exchange. The application must face this question squarely.
Thin governance documentation. A two-page AML policy will not satisfy any serious regulator. The AML/CFT program must cover customer due diligence, transaction monitoring, Travel Rule compliance, suspicious transaction reporting and the governance structure that sits around it. Regulators will probe the details in RFIs. A generic document exposes the gap immediately.
Inadequate fit-and-proper preparation. Controllers and shareholders with prior regulatory history – even minor matters in another jurisdiction – must be disclosed and contextualised. An undisclosed matter that the regulator discovers independently is far more damaging than a disclosed one. We work through this with clients before submission.
Banking and payment rail assumptions. A licence does not guarantee banking. The business may hold a VARA licence and still be unable to open an operational account without a parallel banking engagement strategy. We address this as part of the initial scoping – not as an afterthought after the licence is granted.
Single-jurisdiction planning in a multi-jurisdiction business. A business with users in multiple jurisdictions cannot satisfy all regulatory obligations with a single licence, regardless of how permissive the issuing jurisdiction is. This is the most expensive misconception we encounter.
How does a cross-border structure change the VASP licensing picture?
For a business sitting between two or more operating environments – say, a Dubai-licensed exchange serving EU retail clients, or a Cayman fund offering tokenised asset exposure to Singapore investors – the legal question turns on which regime's reach extends to each activity and user relationship.
MiCA applies on the basis of where the service recipient is located, not where the provider is established. An entity authorised under VARA in Dubai, providing exchange services to EU residents, must consider whether it requires a parallel CASP authorisation in an EU member state. MAS applies similar logic: serving Singapore residents with a digital payment token service triggers Payment Services Act obligations, regardless of where the service provider is domiciled.
The practical consequence is a licence stack: one entity – or a group of entities – holding authorisations in each relevant jurisdiction, with a group structure designed to segregate regulated from unregulated activities. Building that stack requires co-ordination of legal, tax and compliance work across multiple regimes simultaneously. We manage that co-ordination, working alongside allied counsel in the relevant jurisdiction where local presence is legally required.
The cross-border angle also applies to banking. A firm holding a MiCA CASP authorisation in Lithuania may still need to bank through a financial institution that is comfortable with the specific activity categories on the licence. Banking relationships follow licence design; they do not precede it.
A micro-matter illustrates the point. In a recent licensing engagement, a payment technology group sought to serve clients across two EU member states and the Gulf from a single operating entity. Initial analysis identified that the group's intended custody activities in the Gulf required a separate authorisation from the applicable regulator there, while the EU service model required CASP authorisation with passporting into both target member states. We structured the group across three entities, managed parallel applications, and co-ordinated AML program alignment across the regime requirements in each. The group launched with a compliant structure in place across all three operating environments.
Which licensing profile fits your business?
Not every business needs the same application strategy. The right approach depends on activity type, user geography and the timeline available.
Profile A – EU-focused exchange or custody business. The appropriate instrument is a CASP authorisation under MiCA in a receptive EU member state, with passporting to cover the broader EU user base. The timeline is subject to the NCA's processing queue and the quality of the application. The key risk is that a thin application generates a protracted RFI cycle that doubles the effective timeline.
Profile B – Gulf-based exchange with international users. The appropriate instrument is VARA authorisation for the relevant activity categories, potentially combined with ADGM/FSRA authorisation if the Abu Dhabi market is part of the strategy. For users outside the Gulf, a parallel EU or Asian licence may be required. The key risk is assuming VARA coverage extends to users in jurisdictions with their own VASP regimes.
Profile C – Asia-Pacific exchange or payments business. MAS licensing under the Payment Services Act is the standard route for Singapore-based operations. The SFC regime covers Hong Kong-based trading platforms. Both regulators apply detailed scrutiny to the technology stack and custody arrangements. The key risk is underestimating the operational depth of the application.
Profile D – Global group with multi-hub operations. A co-ordinated multi-jurisdictional application program, sequenced to manage timelines and avoid gaps in coverage. The key risk is misalignment between the legal structures in different jurisdictions, particularly where one regime requires local substance that conflicts with tax efficiency in another.
If a prior application stalled or an account was closed, a second read can surface the structural reason and the route back. Contact OBOLUS at info@oboluslaw.com or map your options.
If a previous submission was rejected or an RFI went unanswered, we review the record, identify the gap and advise on the remediation path before any further application is submitted.
A common assumption: one offshore licence covers everything
A common assumption among founders entering the market is that a permissive offshore registration – in the BVI, Cayman Islands or a small EU member state with a historically light touch – will cover their global user base. It will not. The jurisdictional reach of MiCA, the Payment Services Act and the VARA regime is determined by where services are consumed, not where the provider is incorporated.
The BVI VASP Act 2022 and the Cayman VASP regime provide registration frameworks that are appropriate for certain fund structures and holding vehicles. They do not substitute for operational licences in the jurisdictions where users are actually located. A BVI registration that is marketed as a "global licence" is a mis-statement of the legal position – and one that creates material enforcement risk in the jurisdictions whose regimes are being bypassed.
We encounter this assumption regularly, and we address it early: the initial scoping call maps every jurisdiction where the business has or intends to have users, and identifies the regulatory obligation that user base creates. That mapping is the foundation on which a credible licence strategy is built.
Related at OBOLUS
Related at OBOLUS
- Licensing & Registration for Digital-Asset Businesses – our full licensing practice across 70+ jurisdictions and all major VASP categories
- Legal Counsel for Digital-Asset Custodians – custody-specific regulatory, structuring and compliance advice for custodians
- Security Token vs. Utility Token: Legal Lines – how token classification affects the licence category and the applicable regime
FAQ
How long does a crypto licence take to obtain?
Timelines vary significantly by jurisdiction and application quality. Simpler registrations – such as the BVI or Cayman VASP frameworks – can resolve in a matter of weeks. Full authorisation processes under demanding regimes such as MiCA, VARA or the MAS Payment Services Act typically extend to several months, and longer where the regulator's queue is congested or an information request cycle is protracted. A well-prepared application with complete documentation consistently achieves shorter timelines than a thin submission that generates repeated information requests.
Which jurisdiction is best for licensing my crypto business?
There is no universally best jurisdiction. The right choice depends on your activity type, user geographies, banking requirements and operational footprint. An EU-facing exchange benefits from a MiCA CASP authorisation with passporting. A Gulf-focused business may favour VARA or the ADGM/FSRA regime. A global group typically needs a co-ordinated multi-hub licence structure. We assess each client's profile against those variables and recommend a jurisdiction strategy based on the specific facts – not on a generic ranking.
Do I need a separate custody licence?
In most flagship regimes, custody is a regulated activity that requires its own authorisation, separate from exchange or transfer services. Under MiCA, the provision of crypto-asset custody and administration is a distinct CASP service category. VARA treats custody as a separate activity licence. MAS and the SFC apply similar principles. A business that holds client assets – even incidentally – must assess whether it triggers the applicable custody regime. We map this as part of the initial regulatory perimeter analysis.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the entirety of our practice, and we act only for businesses – not for retail claimants or individuals. We map the licence stack across operating, custody and payment layers before you commit, so the architecture is right the first time. To discuss your situation, contact info@oboluslaw.com or message us via t.me/oboluslaw.
By Aisha Tan, Licensing & Jurisdictions Analyst – specialist in VASP regulatory applications across the EU, Gulf and Asia-Pacific licensing regimes.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.