EST · MMXXVI
Home/Services/Token Offerings Securities/Stablecoin issuance authorisation for Early-stage Founders
Token Offerings & Securities

Stablecoin issuance authorisation for Early-stage Founders

Stablecoin issuance authorisation for Early-stage Founders. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to

On paper, launching a stablecoin looks like a product decision. In practice, it is a regulated financial activity in every major jurisdiction – and an early-stage founder who launches without the right authorisation can convert a product launch into an unregistered securities offering, an unlicensed payment service, or both. The legal question is not whether a stablecoin is regulated. It is which regime applies, how the instrument is classified, and what authorisation must be obtained before a single token is issued or distributed.

Stablecoin issuance authorisation is the process by which a founder obtains the regulatory permissions required to issue, offer and distribute a pegged digital asset. The applicable regime turns on the token's design: a fiat-referenced coin may trigger e-money token (EMT) rules under MiCA (the EU's Markets in Crypto-Assets Regulation), payment-institution licensing under the FCA in the UK, a money-transmitter licence in the United States, or activity-based permissions under VARA in Dubai – often in parallel. This page sets out the classification logic, the authorisation process, the cross-border stack, and the practical choices an early-stage founder faces before launch.

How are stablecoins legally classified?

Legal classification drives every downstream decision: the licence you need, the whitepaper you must publish, the capital you must hold, and the jurisdictions in which you can distribute. Classification turns on the substance of the rights the token confers, not the label in your marketing deck.

Under MiCA, the primary EU classification framework, three categories matter. An asset-referenced token (ART) references a basket of assets – currencies, commodities or other crypto-assets. An e-money token (EMT) references a single official currency and promises to maintain a stable value by reference to it. All other crypto-assets fall into a residual category with lighter whitepaper obligations. Most fiat-pegged stablecoins intended for payment use will qualify as EMTs. That matters because EMT issuers must be authorised as credit institutions or e-money institutions under the applicable EU framework, or obtain a specific CASP (Crypto-Asset Service Provider) authorisation covering the EMT issuance activity.

Outside the EU, the analysis diverges. The FCA in the UK treats fiat-backed stablecoins used as a means of payment as a form of electronic money, requiring FCA authorisation. The MAS in Singapore treats single-currency stablecoins above a defined threshold as a regulated instrument under the Payment Services Act. In the United States, the SEC and CFTC have both claimed jurisdiction over particular stablecoin designs, and state money-transmitter licensing adds a further layer. VARA in Dubai regulates stablecoin issuance as one of its named activities under the virtual assets rulebooks, separate from mainland UAE rules.

A common assumption is that calling a token a "utility token" or marking it as non-transferable during an early phase settles classification. It does not. Regulators in every leading hub assess what the token does – the rights it confers on holders, the mechanism stabilising its value, the economic exposure it creates – not what the issuer calls it. In our practice we assess classification against the substance of rights from the outset, before any whitepaper is drafted.

Stablecoin issuance authorisation at OBOLUS starts with a formal classification opinion covering every jurisdiction in the intended distribution path. That opinion drives the licence selection that follows.

For a scoped classification opinion on your stablecoin design, contact OBOLUS at info@oboluslaw.com before your whitepaper is finalised. The process above describes the standard analytical path. Your facts – the peg mechanism, the reserve structure, the user base, the banking – change the analysis materially. Map your options.

Which authorisations does a stablecoin issuer actually need?

A stablecoin issuer typically needs multiple authorisations running in parallel, one for each jurisdiction in which it issues, distributes or allows secondary trading of the instrument. The stack is cumulative, not alternative.

Within the EU, an EMT issuer must hold authorisation either as an e-money institution or as a credit institution, or – depending on the business model – it must obtain a CASP authorisation covering EMT issuance from the national competent authority of the chosen member state. MiCA passporting then allows a single authorisation to support distribution across the full EU/EEA. Early-stage founders frequently target Lithuania, Malta or another smaller member state for initial CASP authorisation, given the relative efficiency of those processes – though MiCA aligns the substantive standards regardless of which NCA supervises.

In the UK, fiat-backed stablecoins used as a means of payment require FCA authorisation as an e-money institution or, once the FCA's stablecoin-specific rules take effect, under the dedicated regime the FCA is developing. Distribution to UK users without that authorisation constitutes an unlicensed payment service.

In the UAE, VARA's activity-based framework requires a virtual asset licence covering issuance and transfer/settlement activities for any stablecoin operating within Dubai's mainland. ADGM's FSRA applies a parallel framework for operations within the Abu Dhabi Global Market. An issuer operating across both zones needs to map activities to the correct regulator.

For Singapore-resident issuers or issuers distributing materially to Singapore users, the Payment Services Act and MAS oversight applies. The JVCEA self-regulatory framework and FSA licensing govern Japan-facing distribution. BVI and Cayman structures frequently appear in early-stage stablecoin builds as the issuing entity vehicle, but those structures still require VASP registration under the BVI FSC's VASP Act or CIMA's applicable regime, and they do not eliminate the distribution-jurisdiction analysis.

The practical result: an early-stage founder launching a fiat-pegged stablecoin with global distribution ambitions may need four to six authorisations before launch, plus ongoing compliance with AML/CFT requirements including the Travel Rule (the obligation to pass originator and beneficiary data with each transfer) across multiple regimes.

What does the stablecoin authorisation process involve?

The authorisation process, at its core, requires the founder to demonstrate to each regulator that the issuing entity is fit to hold client funds or maintain a reserve, that its governance is sound, that its systems can operate the stabilisation mechanism reliably, and that its compliance programme meets AML/CFT standards.

The standard application package across most flagship regimes includes a detailed business plan, a description of the stabilisation mechanism and reserve management, an organisational chart with key function holders, AML/KYC policies, a technology and security assessment, and – where required by the regime – a published whitepaper. Under MiCA, the whitepaper for an EMT or ART must be notified to the national competent authority and contain prescribed disclosures covering the token design, the reserve composition, the redemption rights of holders, and the risks. The whitepaper is a legal document, not a marketing instrument. Errors or omissions in the whitepaper create liability.

Timelines vary by jurisdiction and category. Founders consistently underestimate the elapsed time from structuring decision to first authorisation. Regulators in the leading hubs expect a polished, complete application; incomplete submissions extend the clock materially. In our cross-border practice we see applications stall at the AML/KYC policy stage, at the governance documentation stage, and – most commonly – at the point where the regulator asks for a banking partner confirmation that the reserve account is in place. Securing a banking relationship for the reserve is often the longest path item, and it runs in parallel with, not after, the licence application.

A process note: in most regimes the founder cannot distribute the stablecoin to users until authorisation is granted and the whitepaper (where required) has been notified or approved. Soft-launching or "beta-testing" with real users before authorisation is a regulatory risk that regulators in the EU, UK and UAE have each actioned in recent cycles.

Operators we advise routinely begin the authorisation process six to twelve months before their intended public launch date. That lead time reflects the reality of regulatory review periods, banking onboarding, and the iterative nature of whitepaper drafting with a competent authority.

Cross-border structure: which profile should pick which path?

There is no single optimal structure for a stablecoin issuer. The right entity and licence stack depends on the peg mechanism, the intended user base, the distribution model, the banking geography, and the founder's risk tolerance for regulatory scrutiny.

Profile A – EU-first, payment-focused issuer. A founder targeting European users with a euro-pegged EMT, intending to distribute through licensed exchanges and wallets within the EU, should pursue CASP EMT-issuer authorisation in a single member state. Lithuania and Malta are both practicable entry points under MiCA, with the passporting benefit providing access to the full EU/EEA distribution channel. The key constraint: the issuing entity must be incorporated in an EU/EEA member state and must hold an e-money institution or equivalent authorisation. Indicative timeline from a complete application: several months, though this varies by NCA workload. Key risk: reserve account banking must be confirmed before authorisation is granted.

Profile B – MENA-first issuer, AED or USD peg. A founder building for Gulf Cooperation Council users with a dollar or dirham peg should engage VARA for Dubai-mainland activities and FSRA for ADGM, concurrently. VARA's activity licences for transfer/settlement and issuance apply. The DIFC operates a separate financial free zone regime. Key risk: VARA's capital and governance expectations are evolving, and the application requires local presence.

Profile C – Global stablecoin with US distribution ambitions. This is the most complex profile. Federal banking regulators, FinCEN's money-service-business registration, state MTL requirements, and potential SEC/CFTC jurisdiction over the token itself all apply. Many early-stage founders structure the issuing entity outside the US initially and restrict US-person distribution until the US regulatory environment for stablecoins stabilises. Allied counsel in the relevant US jurisdictions is essential here.

Profile D – BVI or Cayman issuer for institutional distribution only. Founders distributing exclusively to verified institutional counterparties sometimes structure through BVI or Cayman entities, relying on the applicable VASP registration regimes and limiting distribution-jurisdiction risk through careful contractual restrictions. This profile requires rigorous KYC/AML infrastructure and does not eliminate the need to analyse the law of each jurisdiction where institutional counterparties are located.

What are the most common mistakes early-stage founders make?

The single most consequential error is treating token classification as a marketing decision rather than a legal one. A founder who drafts a whitepaper calling a fiat-pegged token a "utility token" because it is used to pay platform fees does not change the regulatory outcome. If the token maintains a stable value by reference to a currency and is redeemable by holders, it will be assessed as an EMT or equivalent by any competent regulator. The utility label does not travel.

The second major mistake is launching distribution before authorisation. We have seen founders distribute tokens to users in test phases, token sales, or airdrops on the basis that the product is "not yet public." Regulators treat the offer, sale or distribution of an instrument that requires authorisation as a regulated activity from the first transaction. An airdrop of a stablecoin to a large user base in advance of authorisation is an enforcement risk in the EU, UK, UAE and Singapore simultaneously.

The third mistake is structuring the issuing entity without solving the banking problem first. Reserve accounts for fiat-backed stablecoins require banking partners willing to hold ring-fenced client funds for a digital-asset issuer. That is a constrained market. Founders who complete the licence application without a committed banking partner frequently find themselves holding an authorisation they cannot operationalise.

A fourth common mistake is underestimating the ongoing obligations post-authorisation: reserve reporting, redemption facility maintenance, annual AML/CFT reviews, Travel Rule compliance infrastructure, and whitepaper update obligations when the product changes materially. In our practice we see post-authorisation compliance failures as frequently as pre-launch structuring failures, and regulators are increasingly focused on ongoing supervisory compliance rather than solely on the entry gate.

If a prior structuring decision has created a compliance gap, a second read can surface the issue and the route to remediation. Write to OBOLUS at info@oboluslaw.com. Map your options.

AML/CFT, the Travel Rule, and whitepaper obligations

Stablecoin issuers face a three-layered compliance obligation: AML/CFT programme requirements, Travel Rule data transfer obligations, and – where required – whitepaper disclosure obligations. All three apply from authorisation; all three are subject to ongoing supervisory review.

The AML/CFT baseline is set by the FATF Recommendations, in particular Recommendation 15, which brings virtual asset service providers (VASPs) within the AML/CFT perimeter. Every major licensing regime – MiCA/ESMA, VARA, MAS, FCA, AIFC/AFSA – implements FATF standards through its applicable VASP provisions. For a stablecoin issuer, this means a risk-based AML/KYC policy, customer due diligence at onboarding, transaction monitoring, suspicious activity reporting, and sanctions screening. The policy must be drafted for the specific business model, not copied from a generic template.

The Travel Rule requires that originator and beneficiary information travels with each virtual asset transfer above the applicable threshold. Stablecoin issuers are at the intersection of the Travel Rule in a structurally significant way: they are both the issuer and often the transfer gateway. Building Travel Rule-compliant data infrastructure before launch is not optional in any of the major licensing jurisdictions. The threshold for Travel Rule application varies by jurisdiction, and the specific data fields required also vary – the EU's implementation under MiCA differs in detail from the MAS implementation in Singapore and the FCA's implementation in the UK.

Whitepaper obligations under MiCA require disclosure of the stabilisation mechanism, the reserve composition and management, the redemption rights of token holders, the risks associated with the instrument, and the conflicts of interest of the issuer. The whitepaper must be notified to the national competent authority before publication and cannot be amended materially without a further notification process. For an EMT issuer, the whitepaper is also the document against which holders may assert civil liability claims if the disclosures prove misleading. Early-stage founders consistently underestimate the legal precision required in whitepaper drafting.

Self-assessment: is your stablecoin project authorisation-ready?

Before engaging a regulator, an early-stage stablecoin founder should be able to answer the following questions clearly. Gaps in any answer typically indicate a structural or compliance issue that should be resolved before the application is filed.

First: has a formal legal classification opinion been obtained for the token design across all intended distribution jurisdictions? A single-jurisdiction opinion is not sufficient for a project with global distribution ambitions. The classification may differ by jurisdiction, and the authorisation path follows the classification.

Second: is the issuing entity incorporated in a jurisdiction whose regulatory regime permits the intended stablecoin activity, and is that entity capable of satisfying the governance and fitness-and-propriety requirements of the target regulator? Offshore holding companies often need a separate regulated operating entity.

Third: is there a committed banking partner for the reserve account, and does that partner's account agreement satisfy the segregation and ring-fencing requirements of the target regime? A letter of intent is not sufficient; many regulators require a confirmed account.

Fourth: is the AML/CFT programme complete, including a risk assessment, a customer due diligence policy, transaction monitoring procedures, and a Travel Rule data infrastructure decision? The programme must be operational, not aspirational, at the point of application.

Fifth: is the whitepaper complete, legally reviewed, and consistent with the actual product design? Inconsistencies between the technical implementation and the whitepaper disclosures are a primary ground for regulator objections and post-authorisation enforcement.

In a recent authorisation matter, an early-stage EMT issuer had completed its technical build and was ready to launch into the EU market before engaging legal counsel. The classification analysis revealed the token structure triggered EMT status under MiCA in all five target member states, requiring CASP authorisation that had not been obtained. We restructured the distribution model, identified the appropriate NCA, managed the whitepaper notification process, and secured the banking relationship in parallel. The issuer launched on schedule, with authorisation in place.

Related at OBOLUS

FAQ

Is my token a security?

Whether a token is a security depends on the rights it confers and the expectations it creates in holders, not on the label attached to it. In the EU, the test turns on whether the token qualifies as a financial instrument under MiCA or prior securities frameworks. In the US, the SEC applies an economic-substance analysis focused on the investment of money in a common enterprise with an expectation of profit from others' efforts. In the UK, the FCA assesses whether the token falls within the specified investments perimeter. A formal classification opinion is required before any public offer or distribution.

Do I need a MiCA whitepaper?

Most stablecoin issuers distributing to EU/EEA users will require a MiCA whitepaper. EMT issuers and ART issuers face mandatory whitepaper requirements with prescribed content covering the token design, reserve management, redemption rights and risk factors. The whitepaper must be notified to the national competent authority before publication. Exemptions exist for certain private placements and offerings below defined thresholds, but for a publicly distributed stablecoin those exemptions are unlikely to apply. Non-compliance with the whitepaper obligation is an enforcement risk across the EU simultaneously due to MiCA's pan-EU scope.

How should an airdrop be structured legally?

An airdrop of a stablecoin carries the same classification and authorisation analysis as any other form of distribution: if the token requires authorisation in the recipient's jurisdiction, the airdrop does not exempt the issuer from that requirement. The structuring considerations include the classification of the distributed token, the jurisdiction of recipients, whether consideration passes (even indirect consideration can engage securities law), and whether the airdrop constitutes a public offer under applicable regimes. Targeted airdrop restrictions, eligibility criteria, and jurisdiction blocks are standard mitigation tools – but they require legal review, not template implementation.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We assess token classification against the substance of rights, not the marketing label – a discipline that has guided stablecoin founders through the most demanding regulatory environments. To discuss your situation, contact info@oboluslaw.com.

By Roman Levitt, Technology & DeFi Counsel – specialising in token design, smart-contract legal architecture, and cross-border regulatory classification for digital-asset issuers.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours