EST · MMXXVI
Home/Services/Licensing Registration/VASP licence application under Heightened Scrutiny
Licensing & Registration

VASP licence application under Heightened Scrutiny

Vasp licence application under Heightened Scrutiny. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

A VASP licence application under heightened scrutiny (a licensing process where regulators apply elevated due diligence to the applicant's ownership, governance, business model and financial crime controls) is no longer an edge case. With supervisory expectations rising across every major hub, from VARA in Dubai to the FCA in the United Kingdom to ESMA and national competent authorities administering MiCA across the EU, the standard application has quietly become the exception. What most operators encounter today is a process defined by enhanced information requests, prolonged vetting of beneficial owners and, increasingly, a forensic read of prior jurisdictional history. Operating without the right authorisation exposes the business to enforcement action, frozen payment rails and the loss of banking relationships that took years to build.

This page explains what heightened scrutiny means in practice, where it typically arises, how a well-prepared application navigates it and where poorly structured applications collapse. It is written for general counsel, founders and compliance officers at exchanges, custodians, token issuers and payment platforms who are already deep in the process – or who recognise that a prior attempt failed for reasons that were never fully diagnosed.

What Does Heightened Scrutiny Mean in a VASP Licence Application?

Heightened scrutiny in a VASP registration (the process of obtaining regulatory authorisation to operate as a virtual asset service provider) is a formal or informal elevation of the regulator's review standard, applied when the applicant's profile triggers risk indicators that a baseline application does not address. It is not a separate licence category. It is a mode of assessment.

In practice, heightened scrutiny is triggered by a combination of factors: ownership structures involving trusts, foundations or nominee arrangements; applicants with a prior regulatory footprint in a jurisdiction where a licence was refused or withdrawn; business models that combine multiple regulated activities under a single entity; and geographic exposure to user bases in jurisdictions that the licensing regulator considers high-risk. MiCA explicitly requires competent authorities to assess the reputation and experience of proposed management, and regulators administering VARA and the FCA's MLR registration process have each signalled publicly that governance quality is a primary filter.

In our licensing practice, heightened scrutiny almost always surfaces at two specific stages: the completeness review, where the regulator's case officer returns the file with a list of additional questions, and the fit-and-proper assessment, where beneficial owners and senior management are individually vetted. Applicants who enter those stages without a fully prepared, internally consistent file consistently find that the process extends far beyond the regulator's published indicative timeline.

To map which scrutiny triggers apply to your entity before you submit, contact OBOLUS at Map your options. The process above describes the standard path. Your facts – the entity structure, the user base, the banking history – change the analysis significantly.

What Is the Regulatory Basis for VASP Authorisation?

The obligation to hold a licence before operating as a VASP (virtual asset service provider) arises under domestic legislation that typically implements the FATF Recommendation 15 standard on virtual assets, though the specific requirements vary materially by jurisdiction.

In the EU, MiCA created a harmonised authorisation regime for CASPs (crypto-asset service providers), replacing the patchwork of national VASP registration regimes with a single, passportable authorisation. The regulation distinguishes between licence categories based on the services offered – exchange, custody, transfer, advice and portfolio management each carry distinct capital and governance requirements. A CASP authorised in one EU member state may passport across the EEA without a separate application, but the passporting notification process is itself subject to review.

Outside the EU, the licensing regimes are structurally independent. VARA in Dubai operates an activity-based licence model: advisory, broker-dealer, custody, exchange, lending, management and transfer/settlement activities are licensed separately, and a multi-activity business must apply for each relevant activity endorsement. The FCA in the UK currently requires cryptoasset registration under the Money Laundering Regulations, with financial promotions rules adding a parallel compliance layer for businesses that market to UK persons. The MAS in Singapore administers Digital Payment Token service licensing under the Payment Services Act, with tiered licence categories that carry different capital and threshold requirements. The SFC in Hong Kong operates a VATP licensing regime for virtual-asset trading platforms.

The AIFC's AFSA in Kazakhstan, the FSRA in Abu Dhabi's ADGM, and the BVI FSC and CIMA in the Cayman Islands each operate distinct regimes with their own application mechanics. In our cross-border practice, the most common structural error is assuming that the licence obtained in the incorporation jurisdiction covers the business's actual operating footprint. It rarely does.

Which Applicant Profiles Typically Attract Heightened Scrutiny?

Heightened scrutiny is not random. Regulators across the leading hubs apply elevated review to specific applicant profiles, and understanding those profiles in advance is the single most effective way to prepare an application that does not stall.

The profiles that consistently attract elevated review include: entities where the ultimate beneficial owner holds interests through multiple holding layers, particularly where those layers cross high-risk jurisdictions; applicants whose business model involves custody of client assets combined with trading facilitation, since regulators treat multi-activity models as carrying compounded risk; businesses that have previously operated in the relevant jurisdiction under an informal or transitional registration and are now seeking formal authorisation; and applicants whose proposed management team includes individuals with prior involvement in regulated entities that were sanctioned, fined or had licences revoked in any jurisdiction.

Geography adds a second layer. An exchange whose user acquisition strategy targets jurisdictions with immature AML supervision, or whose on-chain transaction history shows exposure to flagged counterparties, will face detailed questions about its transaction monitoring architecture, its Travel Rule compliance (the obligation to pass originator and beneficiary data alongside a virtual asset transfer), and its approach to politically exposed persons. These questions are not answered in a form. They are answered in documented policy, tested procedure and, increasingly, in live demonstration of system capability.

In recent months, we have seen regulators also apply heightened review to applicants whose banking relationships are with institutions that the regulator considers to have weak AML controls. The logic is direct: the quality of your banking tells a regulator something about what a diligent bank concluded when it ran its own due diligence on you.

What Are the Most Common Mistakes in a High-Scrutiny Application?

The most destructive mistake is treating a heightened-scrutiny application as a standard filing with more documents. The failure mode is not missing a document. It is submitting a file whose internal logic cannot survive a competent case officer's cross-examination.

The specific errors we see most frequently are these. First, applicants submit ownership charts that are accurate but unexplained – a regulator looking at a four-layer holding structure between a Cayman fund and a Dubai operating entity will not assume innocent efficiency. Each layer needs a documented business rationale. Second, applicants provide AML policies that were drafted generically and do not map to the business's actual transaction types, customer base or risk appetite. A policy that names a risk category without explaining how the business detects and manages it is a red flag, not a comfort. Third, business plans describe revenue projections without a credible client acquisition pathway – regulators administering MiCA and VARA have each indicated that overstated volume projections in business plans are a filter for applicants who have not genuinely analysed their market.

A fourth, less obvious error is poor sequencing. In jurisdictions where the regulator may communicate informally with the applicant's banking counterpart, submitting an application before the banking relationship is confirmed can create a gap in the file that compounds into a delay measured in months.

In a recent licensing matter, a payments company with an existing EU presence applied for a MiCA CASP authorisation in a northern EU member state. The initial file was returned within weeks with a detailed request for information on the beneficial owner's prior involvement in a fintech entity that had been wound down after a supervisory review in a different jurisdiction. We restructured the ownership disclosure, produced a documented narrative of the prior entity's wind-down and resubmitted. The application proceeded to assessment without further ownership questions. The lesson was simple: regulators find what applicants do not volunteer, and the cost of omission is always higher than the cost of explanation.

How Does the Cross-Border Reality Affect the Licence Strategy?

A VASP licence application does not exist in isolation. The licensing decision in one jurisdiction is increasingly informed by the applicant's regulatory and operational history in every other jurisdiction where it has touched users, held assets or processed payments.

The cross-border dimension operates on three axes. The first is the entity axis: where the legal entity is incorporated, where it holds the licence, and where it actually directs its operations may be three different answers – and a regulator will probe the gap. Under MiCA, the passporting benefit attaches to the authorised entity, not to a group. Operating out of a subsidiary that holds no licence, while the licensed parent provides services, is a structure that competent authorities have scrutinised aggressively. The second axis is the user axis: the jurisdictions in which the business's users are located determine which licensing obligations apply in those jurisdictions, independent of where the operator is licensed. A CASP authorised in Lithuania under MiCA may passport freely across the EU, but serving users in the UK, Singapore or the UAE requires separate analysis of each of those regimes. The third axis is the banking axis: the jurisdiction in which the business maintains its client money accounts affects both the banking bank's own regulatory obligations and the operator's ability to satisfy the regulator about its safeguarding arrangements.

Operators we advise routinely underestimate the time required to align these three axes. The licence strategy and the banking strategy must be developed in parallel, not sequentially. A licence obtained without a confirmed banking relationship in the same regulatory perimeter is operationally incomplete.

For applicants with a complex cross-border footprint, we work with allied counsel in the relevant jurisdiction to map the full obligation set before a primary application is filed. This avoids the scenario – which we see regularly – where an operator learns, post-authorisation, that serving its existing user base requires three additional registrations it did not anticipate.

If a prior application stalled or banking was refused after an application was filed, a second review often surfaces the structural cause. Write to OBOLUS at Map your options.

Which Licensing Path Fits Which Operator Profile?

The right licensing strategy depends on the specific combination of activities, entity structure and user geography – not on which jurisdiction offers the shortest published timeline.

Profile A – Exchange seeking EU market access with a clean ownership structure. The appropriate instrument is a MiCA CASP authorisation in a member state with a well-resourced competent authority and a clear processing record. The process runs through a defined authorisation timeline that varies by member state and by the regulator's current caseload. The primary risk is business-plan quality: a regulator that has processed dozens of CASP applications in a short window is attuned to templated filings and will return incomplete or generic business plans without hesitation.

Profile B – Multi-activity operator (exchange + custody + lending) seeking to serve a global user base. A single CASP authorisation is unlikely to cover all activities across all user jurisdictions. The more common approach is a primary EU authorisation for the exchange activity, a separate custody licence or endorsement where required, and a jurisdiction-specific registration for the lending activity in the markets where lending to clients is a regulated activity. This structure typically requires two to three licensing workstreams running in parallel, each with its own AML policy, capital base and governance documentation. Timelines are measured in months to over a year depending on the jurisdiction combination.

Profile C – Operator with prior regulatory history (refused licence, supervision action or affiliated-entity issue). This profile almost always triggers heightened scrutiny regardless of the jurisdiction selected. The application requires a fully documented narrative of the prior history before the file is submitted. The choice of jurisdiction matters here: a licensing regime with a smaller competent authority and less investigative infrastructure may appear attractive but in practice may lack the procedural mechanisms for an applicant to address a prior-history disclosure in a structured way. Jurisdictions with established case management processes – including the MAS regime in Singapore and VARA in Dubai – allow for pre-application engagement that experienced counsel can use to frame the prior-history disclosure constructively.

Profile D – Early-stage exchange seeking a rapid authorisation to demonstrate regulatory standing to investors. The fastest authorisations available in credible jurisdictions are not always the most strategically sound. A registration obtained quickly in a jurisdiction where the regulator does not actively supervise creates a compliance posture that institutional investors and tier-one banks will discount. The more effective approach is often a parallel track: an accelerated registration in a jurisdiction with a defined short-form process, combined with a longer-form application in the primary target market, so that the business can demonstrate regulatory intent without betting its banking on a single outcome.

Self-Assessment: Is Your Application File Ready for Heightened Scrutiny?

Before an application is submitted in a heightened-scrutiny context, a file should satisfy a set of structural tests that go beyond document completeness.

Ownership and control documentation should trace every layer from the applicant entity to the ultimate natural-person beneficial owner, with a written rationale for each holding layer. The UBO narrative should address, not avoid, any prior regulatory history involving any layer of the structure. The AML/CFT policy should map explicitly to the business's specific transaction types, customer segments and geographic risk profile, and should cross-reference the business's technology stack for transaction monitoring and sanctions screening. The business plan should reflect realistic volume assumptions, supported by a client acquisition pathway that the regulator can interrogate. Proposed management and senior function holders should each have a current, accurate CV and a documented disclosure of any prior regulatory involvement, whether as a licensee, a director or an AML officer.

Banking documentation – either a confirmed account or a credible pathway to one with a named institution that has completed preliminary due diligence – should be part of the file before submission, not a deliverable to be arranged after authorisation. Finally, the Travel Rule compliance approach should be documented, including the technical solution, the jurisdiction-specific thresholds the business applies and the counterparty VASP identification process. Regulators across the major hubs have made Travel Rule compliance a primary assessment criterion, and a file that does not address it directly will receive a detailed information request on the point.

In our licensing practice, running this checklist against a draft file before submission typically identifies between three and seven gaps that, if left unaddressed, would generate a regulatory information request adding weeks or months to the process.

A Common Assumption That Costs Operators Time and Money

A common assumption among operators entering a licensing process for the first time is that a single offshore registration, obtained in a jurisdiction with minimal supervision and low fees, is sufficient to operate globally. It is not, and regulators, banks and institutional counterparties all know it.

The practical consequence of this assumption plays out in three ways. Tier-one banks performing their own due diligence on an exchange or custodian will assess the quality of the licensing jurisdiction, not merely the existence of a registration. An operator holding only a registration from a jurisdiction that a major bank considers low-quality will fail the bank's CDD screen regardless of the operator's own AML posture. Institutional clients – funds, family offices and corporate treasuries – have their own compliance obligations, which require them to assess the counterparty's regulatory standing in a jurisdiction that their own regulator would consider credible. And, crucially, operating without a required authorisation in a jurisdiction where users are located creates enforcement risk in that jurisdiction, independent of whatever registration the operator holds elsewhere.

The correct framing is not "which single licence do I need" but "what is the complete licence, banking and compliance stack required for the specific activities I conduct with the specific users I serve in the specific markets where I operate." That question has a different answer for every business, and it rarely resolves to a single jurisdiction.

We map the licence stack across operating, custody and payment layers before an operator commits to a filing strategy. The cost of that analysis is materially lower than the cost of a refused application, a withdrawn banking relationship or an enforcement action in a jurisdiction the operator did not realise required a local licence.

Related at OBOLUS

FAQ

How long does a crypto licence take to obtain?

Timelines vary significantly by jurisdiction, licence category and the completeness of the application file. In straightforward cases with a well-prepared submission, some jurisdictions process applications in a matter of weeks. Heightened-scrutiny applications – where ownership complexity, prior regulatory history or multi-activity models trigger elevated review – regularly extend to several months or longer. Parallel workstreams across multiple jurisdictions compound the timeline further. Experienced preparation of the file is the single most reliable way to reduce elapsed time.

Which jurisdiction is best for licensing my crypto business?

There is no universally optimal jurisdiction. The right choice depends on the activities conducted, the user geographies served, the banking strategy and the operator's existing regulatory history. MiCA passporting makes an EU CASP authorisation attractive for businesses targeting EU users. VARA in Dubai suits multi-activity operators building a Middle East presence. MAS licensing is appropriate for Southeast Asian market access. Each carries distinct capital, governance and AML requirements. The correct answer requires a structured analysis of the full operating footprint – not a comparison of published fees alone.

Do I need a separate custody licence?

In most flagship regimes, custody of client virtual assets is a separately regulated activity. Under MiCA, providing custody and administration of crypto-assets on behalf of clients is a distinct CASP service requiring explicit authorisation. VARA in Dubai treats custody as a standalone licensed activity. MAS and the SFC in Hong Kong each impose specific safeguarding and operational requirements on entities holding client assets. An operator that combines trading and custody functions without the relevant custody authorisation is exposed to enforcement risk in each jurisdiction where client assets are held, regardless of the trading licence it holds.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the entirety of our practice, and we act only for businesses. We map the licence stack across operating, custody and payment layers before you commit to a filing strategy – so the structure is sound before capital is deployed. To discuss your situation, contact info@oboluslaw.com.

By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in VASP and CASP authorisation strategy across EU, UAE and Asia-Pacific licensing regimes under heightened regulatory scrutiny.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours