Authorising a stablecoin for institutional distribution is one of the most technically demanding exercises in digital-asset law. The token must clear a classification analysis – is it an asset-referenced token (ART, a token that references a basket of currencies, commodities or other assets) or an e-money token (EMT, a token pegged to a single fiat currency) or, in some regimes, an unregulated payment instrument? – before a single application document is filed. Get that classification wrong and a product launch can become an unregistered securities or e-money offering overnight. This page maps the regulated basis, the authorisation process, the common structural mistakes, and the cross-border reality that every institutional issuer must plan around before committing capital to a launch.
Why token classification determines everything that follows
The first question any institutional issuer must answer is not "which regulator do I approach?" but "what type of instrument am I actually creating?" Every downstream decision – the regulator, the reserve structure, the whitepaper obligation, the distribution model – flows from that classification. Under MiCA (the EU's Markets in Crypto-Assets Regulation, supervised by ESMA and national competent authorities), a stablecoin referencing a basket of assets is an ART; a stablecoin pegged to one fiat currency is an EMT. Each carries its own authorisation track, its own reserve and redemption requirements, and its own ongoing prudential obligations. Neither classification is inherently preferable: the choice is a structural one, not a marketing one.
A common assumption is that labelling a token "utility" on a whitepaper settles the legal classification. It does not. Regulators and courts assess the substance of the rights attached to a token – economic exposure, redemption expectations, governance rights – not the language an issuer chose for its marketing deck. We assess classification against those substantive criteria from the outset, because a reclassification after launch is structurally disruptive and, in some regimes, carries enforcement consequences.
Outside the EU, the classification logic differs but the principle is the same. Under the VARA regime in Dubai, the FSRA framework in Abu Dhabi's ADGM, the MAS Payment Services Act in Singapore and the SFC VASP licensing regime in Hong Kong, the nature of the rights the token confers determines which regulatory gate applies. Institutional issuers operating across multiple user bases routinely face a classification that is clean in one regime and contested in another.
What stablecoin authorisation actually requires
Authorisation for a stablecoin is not a single filing; it is a sequenced programme involving legal structuring, a reserve architecture, an operational policy suite and – under most flagship regimes – a formal whitepaper disclosure obligation. Under MiCA, an ART issuer requires explicit authorisation from the relevant national competent authority before offering tokens to the public or seeking admission to a trading platform. An EMT issuer must be either a credit institution or a licensed e-money institution in an EU or EEA member state. Both tracks carry whitepaper obligations: the document must meet prescribed content standards, be approved by the competent authority in the relevant cases, and be published before distribution begins.
The reserve architecture is non-negotiable at this scale. Institutional stablecoin programmes are expected to hold reserves that match the outstanding token supply, meet defined composition and segregation standards, and support redemption on demand. The precise reserve rules vary by licence category and jurisdiction. What is consistent across the leading regimes is the expectation of demonstrable segregation, independent custody or custody oversight, and a redemption mechanism that a regulator can audit. Issuers that structure reserves to minimise operational cost – rather than to meet the regulatory expectation – typically encounter the hardest questions during authorisation review.
In our cross-border practice, we have seen institutions underestimate the policy workload that sits alongside the licence application itself. AML/CFT policies, Travel Rule compliance (the obligation, under FATF Recommendation 15, to pass originator and beneficiary data with each transfer), a token-holder redemption policy, conflict-of-interest procedures and an ongoing reporting framework all need to be in place – not promised – before an authorisation is granted in most leading jurisdictions.
For a scoped assessment of your stablecoin structure and the authorisation track it triggers, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity's domicile, the target user base, the reserve custodian, the banking relationship – change the analysis materially.
The EU MiCA track: what institutional issuers need to know
MiCA is the most detailed stablecoin authorisation regime currently in force among major financial markets, and it sets the benchmark that other jurisdictions are beginning to reference. An ART authorisation under MiCA requires the issuer to be a legal entity established in an EU member state, to submit a detailed application to the competent national authority, and to publish a whitepaper that meets the regulation's prescribed content requirements. The whitepaper is not a marketing document; it is a legal disclosure instrument that binds the issuer to the rights and mechanics it describes.
Significant issuers – those whose ART or EMT reaches defined thresholds of outstanding token value or user count – move into a more demanding supervisory category, with ESMA taking a direct role. The implications for operational structure, capital and governance are considerable. Operators we advise routinely treat the threshold analysis as a planning exercise, not a post-launch problem: if the token is designed to scale, the authorisation architecture must anticipate the supervision tier it will attract.
Passporting is a real advantage of the MiCA CASP authorisation pathway: a CASP (crypto-asset service provider) authorised in one EU or EEA member state may offer its services across the bloc without additional national authorisations. For a stablecoin programme, this means the entity and jurisdiction selection at the outset of the authorisation process directly determines the geographic reach of the launch. Lithuania and Malta are both MFSA and Bank of Lithuania-supervised jurisdictions that have received institutional attention as authorisation venues under the transitional and full MiCA regimes, though the choice between them turns on operational, tax and banking factors that vary by applicant profile.
The cross-border reality: where the entity sits versus where users are
A stablecoin issued from an EU-authorised entity does not automatically satisfy the regulatory requirements in every market where its tokens trade or circulate. This is the central structural challenge for institutional programmes: the issuer's home regime governs the issuance and the token itself, but secondary market activity, distribution partnerships and wallet integrations in third countries each carry their own regulatory exposure. An EMT freely distributable under MiCA may be treated as a regulated payment instrument in Singapore, a securities product in the United States under an SEC or CFTC analysis, or an exchange-listed asset requiring VARA notification in Dubai.
The entity structure that serves the EU distribution may not be the right entity for the Asia-Pacific distribution. Institutional programmes routinely operate through a holding structure with a licensed issuer in one jurisdiction and licensed distribution or service entities in others. The cross-border compliance map – which entity holds the reserve, which entity contracts with institutional distributors, which entity interacts with end users in each market – must be designed before authorisation, because the authorisation application will ask for it.
Banking is the practical bottleneck that most issuers discover too late. Reserve custodians and settlement banks for stablecoin programmes are a limited universe. The institutions willing to hold fiat reserves for a token issuer, process redemptions at institutional scale and survive their own compliance review of the programme are not numerous. In our practice, we engage the banking question in parallel with the licence application, not after it: a completed authorisation without a viable banking relationship is commercially inert.
What goes wrong: five structural mistakes in stablecoin authorisation
Mis-classifying the token at the design stage is the most consequential error, but it is not the only one. Based on the authorisation programmes we have supported, the following mistakes recur.
Designing the reserve for cost efficiency rather than regulatory adequacy. Regulators across MiCA, VARA and the FSRA framework all expect reserves that are segregated, independently held or overseen, and redeemable on demand. A reserve held in a single institution without contractual segregation will fail the application review in most flagship jurisdictions.
Treating the whitepaper as a marketing exercise. The whitepaper under MiCA is a statutory disclosure document with prescribed content requirements. Errors of omission – missing redemption mechanics, undisclosed fee arrangements, inadequate risk disclosures – expose the issuer to liability and to the regulator's refusal to accept the filing.
Underestimating the AML build. A stablecoin issuer is a financial institution subject to AML/CFT obligations and, in most regimes, to Travel Rule compliance. The compliance infrastructure – KYC/KYB onboarding, transaction monitoring calibrated for token transfers, Travel Rule data transmission capability – must be operational, not planned, before authorisation is granted.
Choosing the issuer jurisdiction without a banking analysis. The most favourable regulatory regime is of limited practical value if the chosen jurisdiction lacks banking infrastructure willing to service a stablecoin reserve programme at institutional scale.
Ignoring the distribution layer. Authorisation covers the issuer. Secondary distribution – through exchanges, custodians, institutional desks or wallet providers – creates separate regulatory touchpoints in each market, each of which requires its own analysis.
If a prior application stalled or a reserve banking relationship failed, a structural review can surface the reason and the route forward. Contact OBOLUS at info@oboluslaw.com. A second read of a stalled programme frequently identifies a classification or reserve architecture issue that can be resolved without restarting the process from the beginning.
Decision matrix: which authorisation path fits your institution?
The right authorisation path depends on three axes: the token's economic design, the institution's existing regulatory footprint, and the target distribution geography. The following profiles represent the patterns we encounter most frequently.
Profile A: a bank or payment institution seeking to issue a single-currency stablecoin for institutional settlement. This profile typically fits the EMT track under MiCA. The issuer is already a regulated financial institution; the authorisation extends an existing licence or triggers an e-money institution registration. Timeline and capital requirements reflect the existing regulatory relationship. The primary work is the reserve architecture, the whitepaper, and the Travel Rule build. The cross-border risk is the distribution map – if institutional counterparties sit outside the EU, a separate analysis is required for each relevant market.
Profile B: a non-bank fintech or digital-asset firm launching a multi-currency or commodity-referenced stablecoin. This profile requires an ART authorisation under MiCA, which demands entity establishment in an EU or EEA state, a full authorisation application, a prescribed whitepaper, and ongoing prudential oversight. The authorisation timeline is longer than for a bank EMT track. The entity and jurisdiction selection is a material decision, both for the authorisation process and for the tax and banking architecture that sits around it.
Profile C: a global institution seeking multi-regime authorisation for a widely distributed stablecoin. This profile requires a structured sequencing: lead jurisdiction for the authorisation (typically an EU or UK entity for Atlantic distribution, a Singapore or ADGM entity for Asia-Pacific distribution), with distribution-side registrations or notifications in secondary markets. The legal workstream is parallel across jurisdictions, requiring coordination between the lead authorisation and the secondary-market analysis. Timeline is measured in quarters, not weeks. The risk is fragmentation: a change to the token's mechanics to satisfy one regulator that inadvertently affects the classification in another.
In each profile, the banking relationship must be mapped before the application is filed. We regularly advise institutions that the jurisdiction with the most accommodating regulator is not always the jurisdiction with the most accommodating banking environment, and that the optimal structure requires balancing both.
How OBOLUS approaches stablecoin authorisation for institutional clients
We structure stablecoin authorisation programmes as a sequenced legal workstream: classification analysis, entity and jurisdiction selection, reserve architecture review, whitepaper drafting and regulatory pre-submission engagement, AML/Travel Rule build, and cross-border distribution mapping. The sequence is not arbitrary; each phase informs the next, and a gap in the classification phase creates compounding problems downstream.
In a recent authorisation matter, an institutional payments firm sought to launch a euro-denominated stablecoin for cross-border settlement among corporate counterparties. The initial structure proposed a reserve held in a non-segregated account with a single banking partner and a whitepaper drafted primarily for marketing. We identified the reserve architecture as non-compliant with EMT reserve expectations under MiCA and the whitepaper as missing prescribed content elements. We restructured the reserve arrangement with a qualified custodian, rewrote the whitepaper to meet statutory disclosure standards, and rebuilt the AML policy suite to address Travel Rule obligations. The application proceeded to submission without the regulator requesting a pre-submission meeting to resolve structural concerns – an outcome that is far from automatic in this authorisation track.
We work with allied counsel in relevant jurisdictions where the distribution map requires local advice outside our primary coverage. For programmes requiring forensic support – whether in a token freeze, an issuer dispute or a reserve audit – we work alongside forensic partners to convert on-chain evidence into structured legal instruments.
Our assessment of a token's classification is always against the substance of the rights it confers, not the label its marketing team applied. That discipline protects the institution both from enforcement risk and from the reputational cost of a regulatory reclassification after launch.
Related at OBOLUS
- Token Offerings & Securities for Digital-Asset Businesses – the full practice overview covering token structuring, securities analysis and regulatory strategy across markets.
- Stablecoin Issuance Authorisation: Legal Counsel for Digital-Asset Firms – focused guidance on the authorisation process for digital-asset-native issuers seeking regulatory approval.
- Stablecoin Issuance Authorisation for Established Operators – tailored analysis for operators with an existing regulatory footprint seeking to add a stablecoin product.
FAQ
Is my token a security?
Whether a token is a security depends on the rights it confers and the economic substance of the arrangement, not the label applied in its documentation. In the United States, the SEC applies a functional investment-contract analysis; in the EU, MiCA carves out tokens that qualify as financial instruments, which remain governed by securities law rather than the CASP regime. The analysis is jurisdiction-specific and fact-dependent. A token that is not a security in one regime may be classified as one in another. Classification must be assessed against the substantive rights of the instrument before any public offering or distribution is structured.
Do I need a MiCA whitepaper?
Most public offerings of crypto-assets in the EU require a whitepaper under MiCA, published before the offer is made. ART and EMT issuers face additional whitepaper requirements, including competent-authority review or approval in prescribed cases. The whitepaper must meet defined content standards – including a description of the token's rights, the reserve architecture for stablecoins, risk factors and redemption mechanics. Exemptions exist for offers limited to qualified investors, offers below defined volume thresholds, and certain utility-type tokens, but each exemption requires a documented legal basis. Assuming an exemption applies without analysis is among the more common mistakes in EU token programmes.
How should an airdrop be structured legally?
An airdrop – the distribution of tokens to recipients without direct monetary payment – is not automatically exempt from securities or AML analysis. In several jurisdictions, regulators have treated airdrops as a form of token offering subject to disclosure or registration obligations, particularly where the distributed tokens carry economic rights or where recipients must perform actions to claim them. The legal structure of an airdrop should address token classification, the jurisdiction of each recipient cohort, KYC obligations triggered by the distribution mechanic, and the tax treatment of the tokens in the hands of recipients. Generic airdrop mechanics that ignore these points carry regulatory and tax exposure that is not always apparent until after distribution.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We assess token classification against the substance of rights conferred, not the marketing label – a discipline that protects institutional clients from enforcement risk and post-launch reclassification. To discuss your stablecoin programme, contact info@oboluslaw.com or message us at t.me/oboluslaw.
By Roman Levitt, Technology & DeFi Counsel – specialising in token classification, smart-contract legal architecture and the regulatory treatment of stablecoin and DeFi instruments across MiCA, VARA and Asia-Pacific digital-asset regimes.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.