An established operator moving into stablecoin issuance faces a more demanding legal question than a startup. The business already carries regulatory relationships, banking dependencies and a user base – any misstep in classification can convert a product launch into an unregistered securities offering or an unlicensed payment-instrument issuance. Stablecoin issuance authorisation turns on which regime governs the instrument, which authorisation track applies and how those requirements interact across every jurisdiction where the token circulates. This page maps that analysis and explains how OBOLUS structures the mandate for operators who cannot afford a false start.
Why Stablecoin Issuance Requires Formal Authorisation
A stablecoin is not a neutral payment tool sitting outside the regulatory perimeter. In every leading regime, a token that stabilises its value against a fiat currency or a basket of assets attracts specific regulatory classification – and that classification determines the authorisation track. Under MiCA (the EU's Markets in Crypto-Assets Regulation), a euro-referenced token is an EMT (e-money token) if it references a single fiat currency, or an ART (asset-referenced token) if it references a basket. Each category carries its own authorisation obligation, reserve requirements and whitepaper regime. The ESMA and national competent authorities administer those requirements across the EU and EEA. Outside Europe, VARA in Dubai, the FSRA within ADGM in Abu Dhabi, and MAS in Singapore each maintain their own stablecoin or payment-token authorisation concepts. The principle is consistent: if the token is designed to hold a stable value and is offered to the public, some form of issuer authorisation is almost certainly required.
Operators already licensed as exchanges or custodians sometimes assume their existing permission covers issuance. It does not. Issuing a token is a distinct regulated activity in most flagship regimes. A CASP (crypto-asset service provider) authorisation under MiCA allows a business to provide services in relation to crypto-assets; it does not by itself authorise the business to issue an EMT or ART. That requires a separate, issuer-specific authorisation, in some cases equivalent to an e-money licence. This distinction is one of the most consequential errors we see operators make when they begin a stablecoin programme.
For a scoped assessment of your stablecoin programme before the build phase begins, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the peg mechanism, the reserve structure, the intended user base, the entity domicile – change the analysis materially.
Token Classification: The First Question Every Stablecoin Issuer Must Answer
Token classification is not a marketing exercise. The regulatory classification of a stablecoin is determined by the substance of the rights it confers and the mechanism by which it maintains its peg – not by what the whitepaper calls it. A common assumption is that placing a utility label on a token settles the legal classification. Regulators and courts are consistent in rejecting that position. ESMA has made clear that the classification of a crypto-asset under MiCA is an objective assessment based on the token's features, regardless of the issuer's stated intention.
For an established operator, the classification analysis typically follows this sequence. First, does the token reference a single fiat currency? If so, it is likely an EMT under MiCA, and the issuer must either hold an e-money licence in an EU member state or obtain standalone EMT authorisation. Second, does the token reference a basket of currencies, commodities or other crypto-assets? If so, it is likely an ART, which triggers a distinct – and generally more demanding – authorisation track under MiCA. Third, does the token, despite the stability mechanism, carry rights that resemble equity, debt or profit participation? If it does, the token may be a security in one or more jurisdictions, with consequences under national securities law, the FCA regime in the UK, the SEC and CFTC in the US, and equivalent bodies elsewhere.
The classification question is rarely answered for a single jurisdiction only. A stablecoin issued by an entity in the ADGM may circulate to users in the EU, the UK, Singapore and the US simultaneously. Each of those regimes may reach the instrument differently. We assess classification against the substance of rights across every material jurisdiction from the outset, not after the token is in circulation.
What Does the Authorisation Process Actually Involve?
The authorisation process for a stablecoin issuer involves several distinct workstreams that must proceed in parallel, not in sequence. The first is the entity structuring decision: which legal entity issues the token, in which jurisdiction, and does that entity already hold a relevant licence? For EU issuance, the entity must be authorised in a member state – passporting then carries the permission across the EEA. For UAE issuance, VARA's activity-based licensing regime governs what the Dubai entity may do; ADGM's FSRA framework governs Abu Dhabi-based issuers separately. For Singapore-linked programmes, MAS administers the Payment Services Act, which covers digital payment token services and, increasingly, stablecoin-specific requirements.
The second workstream is the whitepaper. Under MiCA, an issuer of an EMT or ART must publish a compliant whitepaper before offering the token to the public. The whitepaper must contain specific disclosures about the token's features, the rights it confers, the reserve assets backing it, the redemption mechanics and the risks. It must be notified to the relevant national competent authority before publication. A whitepaper is not a marketing document – it is a regulated disclosure instrument with legal consequences for the issuer if it contains errors or omissions. We draft and review whitepapers as a legal instrument, not as a product brief.
The third workstream is the reserve and safeguarding structure. EMT and ART issuers under MiCA are required to hold reserve assets of a defined composition, segregated from the issuer's own funds, with redemption rights for token holders. The specific reserve composition rules are set by the applicable regime and vary by token category. In our cross-border practice, we regularly advise on structuring the reserve and custody arrangements so that they satisfy both the issuer's home-jurisdiction requirements and the expectations of banking partners, who conduct their own due diligence on reserve quality.
The fourth workstream is AML/CFT compliance. Every stablecoin issuer is a VASP (virtual asset service provider) for FATF purposes, and most major regimes require the issuer to implement an AML programme, conduct customer due diligence and comply with the Travel Rule (the obligation to pass originator and beneficiary data with each transfer above the applicable threshold). The Travel Rule threshold varies by jurisdiction and is designated qualitatively here because the applicable de-minimis figures require jurisdiction-specific verification.
Cross-Border Issuance: Where the Entity Sits vs Where the Token Circulates
The central tension in any cross-border stablecoin programme is that the issuer's domicile and licence do not define the regulatory perimeter of the token. A stablecoin issued by an ADGM-licensed entity and offered to EU residents is subject to MiCA's requirements regardless of where the issuer is incorporated. A stablecoin offered to US persons may attract the SEC's securities jurisdiction and FinCEN's money-transmission framework regardless of the issuer's offshore domicile. The UK's FCA financial-promotion rules apply to stablecoins marketed to UK persons even when the issuer is based elsewhere.
Operators we advise routinely underestimate the extraterritorial reach of the major regimes. The practical consequence is that a stablecoin programme with a global ambition requires not one authorisation but a layered stack: an issuer licence in the home jurisdiction, a distribution or marketing authorisation (or exemption analysis) in each target market, and a clear contractual structure between the issuer entity, the distributor entities and the reserve custodian. Gaps in that stack are where enforcement exposure concentrates.
The cross-border banking question is equally material. Reserve assets must be held in accounts that satisfy the issuer's home-jurisdiction safeguarding rules, but the banks willing to hold reserve accounts for stablecoin issuers operate their own onboarding criteria. In our practice, we structure the banking and licensing workstreams together, because a licence obtained without a viable banking path is a licence with limited commercial utility. We have seen operators secure MFSA and CASP authorisations in the EU only to find that their reserve-banking arrangements could not be confirmed until the licensing process was already advanced. Sequencing those two tracks matters.
If you are mapping the licence, banking and reserve structure for a stablecoin programme, write to info@oboluslaw.com. If a prior application stalled or a banking relationship was declined, a second structural read can surface the issue and identify the route forward.
Common Mistakes Established Operators Make in Stablecoin Authorisation
Established operators bring real advantages to a stablecoin programme – existing compliance infrastructure, regulatory relationships and operational capacity. They also bring ingrained assumptions that can become liabilities. The following patterns appear with enough regularity that we address them explicitly.
The first is treating the stablecoin as an extension of an existing product rather than a new regulated instrument. An exchange that holds a CASP authorisation for trading services cannot assume that authorisation extends to token issuance. Issuance is a separate activity. The failure to seek a separate issuer authorisation is one of the most direct paths to enforcement exposure.
The second is launching on a whitepaper drafted by the product team rather than as a legal document. A MiCA-compliant whitepaper has specific mandatory content, a defined liability regime and a regulatory notification requirement. A document that reads well as a product brief but omits mandatory disclosures is not compliant. The issuer carries civil liability for material omissions.
The third is selecting the issuer jurisdiction for tax or speed reasons without fully mapping the distribution jurisdiction obligations. A BVI or Cayman issuer entity may be appropriate for certain offshore programmes, but if the token is distributed to EU or UK persons, the distribution-side requirements of MiCA or the FCA regime apply regardless. The choice of issuer domicile is one input into a multi-variable decision, not the only input.
The fourth is under-resourcing the AML/CFT build. Regulators in the leading hubs increasingly expect a stablecoin issuer's AML programme to address not just the issuer's own onboarding obligations but also the Travel Rule compliance of downstream distribution partners. An issuer that cannot demonstrate that its distribution chain is Travel-Rule compliant faces questions at renewal and examination.
Decision Matrix: Which Authorisation Profile Fits Your Stablecoin Programme
Different operator profiles require different authorisation approaches. The following matrix describes the principal profiles we work with and the general path each follows.
Profile A: EU-licensed operator seeking to issue a euro-pegged EMT. The issuer entity must hold an e-money licence or standalone EMT authorisation in an EU member state. MiCA's whitepaper notification and reserve-segregation requirements apply. Passporting carries the EMT permission across the EEA. The primary risk is reserve-quality compliance and ongoing own-funds obligations. Timeline is determined by the national competent authority's queue and the issuer's existing licence status – an operator with an existing e-money licence may move faster than one building from scratch.
Profile B: UAE-based operator seeking to issue a multi-currency stablecoin for MENA distribution. VARA in Dubai and the FSRA within ADGM each have stablecoin-specific expectations under their respective activity-based regimes. The issuer must determine which free zone or mainland structure best fits the programme's banking and distribution model. The ART analogy under MiCA does not apply directly, but the substance of VARA's requirements – issuer oversight, reserve management, consumer protection – tracks similar principles. Cross-border distribution into the EU would layer MiCA obligations on top.
Profile C: Singapore-based operator seeking a globally distributed stablecoin. MAS administers specific requirements for stablecoin issuers under the Payment Services Act, distinct from general digital payment token licensing. A major payment institution licence is typically required at scale. Distribution into the EU, UK or US layers additional regime requirements. The entity-structure question – whether to issue from the Singapore entity or a separate issuer vehicle – has tax and regulatory consequences that must be mapped in advance.
Profile D: Established non-financial business seeking to launch a branded stablecoin. This profile carries the highest classification risk. A branded stablecoin offered as a loyalty or payment instrument may, depending on its features, attract EMT, ART or securities treatment. The business may have no existing financial services infrastructure. Authorisation will require building a regulated entity from the ground up, and the timeline is correspondingly longer. We typically recommend beginning the regulatory analysis before any product design is finalised.
A Recent Stablecoin Reserve-Structure Engagement
In a recent matter, a payments group with existing EU licensing sought to extend its product suite to include a euro-denominated stablecoin. The group's existing authorisation did not cover EMT issuance. We advised on the separate EMT authorisation process under MiCA, drafted and reviewed the regulatory whitepaper as a compliant disclosure instrument and structured the reserve custody arrangements across two EU-regulated banks to satisfy the national competent authority's safeguarding expectations. The banking workstream ran in parallel with the authorisation process, not after it, which allowed the group to demonstrate a confirmed reserve structure to the regulator at the point of application. The authorisation was granted without a request for substantial additional information – an outcome that, in our experience, reflects the value of front-loading the reserve and banking analysis.
Self-Assessment: Is Your Stablecoin Programme Authorisation-Ready?
The following checklist reflects the questions a regulator will ask. If any answer is "unclear" or "not yet addressed," the programme is not ready for a licence application.
- Has the token been classified under the applicable regime (EMT, ART, payment token, or other) on the basis of its substantive features, not its marketing label?
- Does the issuer entity hold, or is it applying for, the specific authorisation required for that token category in the issuer's home jurisdiction?
- Has the whitepaper been drafted as a legally compliant disclosure document, with mandatory content reviewed against the applicable regime?
- Are the reserve assets defined, segregated and held in accounts that satisfy the home-jurisdiction safeguarding rules and the banking partner's own criteria?
- Has the AML/CFT programme been extended to cover the Travel Rule obligations of the issuance and distribution chain?
- Has the distribution jurisdiction analysis been completed, with authorisation or exemption conclusions reached for each target market?
- Is the tax treatment of issuance proceeds, reserve income and token-holder redemption settled in each material jurisdiction?
If any of these points remains open, we recommend a structured pre-application review before the formal authorisation process begins. A gap identified at the application stage extends the timeline; a gap identified by the regulator can stall or terminate the process.
Related at OBOLUS
- Token Offerings & Securities practice – the full legal framework for token issuance, classification and cross-border distribution
- Security token offering structuring in South Africa – jurisdiction-specific guidance on STO structuring under South African law
- NFT project legal structuring – legal counsel for digital-asset firms building NFT programmes and tokenised products
FAQ
Is my token a security?
Whether a token is a security depends on the rights it confers and the economic substance of the arrangement – not the label applied by the issuer. In the US, the SEC applies a functional test focused on investment of money in a common enterprise with an expectation of profit from others' efforts. Under MiCA, the classification turns on whether the token resembles a transferable security, an ART or an EMT. In most leading jurisdictions, a utility label on a whitepaper does not determine the outcome. Classification must be assessed jurisdiction by jurisdiction, on the substance of the token's features, before any public offering or distribution.
Do I need a MiCA whitepaper?
An issuer of crypto-assets to the public in the EU or EEA is generally required to publish a MiCA-compliant whitepaper before the offering commences, subject to limited exemptions. EMT and ART issuers face additional whitepaper content requirements and must notify the whitepaper to the relevant national competent authority before publication. The whitepaper is a regulated disclosure document – not a marketing brochure – and the issuer carries civil liability for material errors or omissions. Whether a specific token or offering qualifies for an exemption requires a fact-specific analysis against the applicable MiCA provisions.
How should an airdrop be structured legally?
An airdrop is not automatically outside the regulatory perimeter. If tokens distributed in an airdrop carry rights that attract securities classification, or if the airdrop constitutes a public offer of crypto-assets under MiCA, the distribution triggers the applicable disclosure and authorisation obligations. Structuring an airdrop legally requires first classifying the token, then determining whether the distribution method constitutes a public offer in any target jurisdiction, and then documenting the basis for any exemption claimed. Airdrops to existing users under a clearly defined non-commercial rationale are treated differently from open public distributions, but that distinction must be demonstrated, not assumed.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We assess token classification against the substance of rights, not the marketing label, and we structure licensing, banking and tax as one mandate rather than three disconnected workstreams. To discuss your stablecoin programme, contact info@oboluslaw.com or message us at t.me/oboluslaw.
By Roman Levitt, Technology & DeFi Counsel – specialising in token classification, smart-contract legal analysis and cross-border stablecoin issuance authorisation for established operators.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.