Why Crypto License Applications Get Rejected (and How to Avoid It)

Why Crypto License Applications Get Rejected (and How to Avoid It)
Table of contents
    • Most crypto license applications end without approval. Singapore has received close to 300 applications for a digital payment token license since 2020, and 37 firms hold one today.
    • Many failed applications end in withdrawal. Firms often pull out once they see the regulator is likely to say no.
    • Weak anti-money laundering controls are the problem regulators name most often, from the UK’s FCA to New York’s financial regulator.
    • Regulators judge people as closely as paperwork. One unsuitable director, owner, or compliance officer can sink a strong file.
    • Under MiCA, a company that does most of its real work outside the EU can be refused as a “letter-box” entity.
    • Copy-and-paste policies are a common red flag. Regulators expect every document to describe the applicant’s own business.
    • The UK opens its new crypto application gateway on 30 September 2026, and firms already registered there will not be converted automatically.

    A Tough Gate That Keeps Getting Tougher

    Getting a crypto license is hard, and most companies that try fail at first. Official figures from the UK, Singapore, and Hong Kong all show the same pattern. Many firms apply, a small group is approved, and the rest are rejected, refused, or quietly withdraw. So why do crypto license applications get rejected so often?

    The short answer is that regulators protect customers from money laundering, fraud, and badly run companies. For that reason, they only approve firms that can prove they are ready on day one. The longer answer is a list of weak spots that regulators mention again and again in their guidance, decisions, and reviews.

    That list applies to every type of crypto business. Regulators use different names for these firms, such as virtual asset service providers (VASPs) or, under EU law, crypto-asset service providers (CASPs). Even the spelling changes, since the UK and EU usually write “licence.” Still, the reasons for rejection look remarkably similar everywhere.

    This guide walks through those reasons one by one. First, it explains what a “no” actually looks like. Next, it covers the seven most common reasons behind it and why the bar rose in 2025 and 2026. Finally, it shows what a firm can do before it applies. Every point comes from official sources, such as the UK’s Financial Conduct Authority (FCA), the European Securities and Markets Authority (ESMA), and the Monetary Authority of Singapore (MAS). It also draws on Hong Kong’s Securities and Futures Commission (SFC) and New York’s Department of Financial Services (DFS).

    What a “No” Looks Like: Rejected, Refused, or Withdrawn

    Before looking at the reasons, it helps to know that a failed application can end in different ways. Each outcome means something slightly different.

    The FCA is a useful example because it spells the outcomes out clearly. In the UK, crypto firms currently register under the Money Laundering Regulations. Each application ends in one of four possible outcomes:

    • Registered. The firm meets the standard and can operate.
    • Rejected. The FCA sends the application back without assessing it, because required information is missing.
    • Refused. An FCA decision-maker formally turns the application down after a full assessment.
    • Withdrawn. The firm pulls its own application, usually because it cannot fix the gaps in time or expects a refusal.

    Of those four outcomes, withdrawal rarely makes the news. Even so, it often follows the same concerns that would have led to a refusal. Once the FCA has all the information it needs, it has three months to decide. As a result, a firm that cannot close its gaps in time will often step back before a formal refusal arrives.

    The European Union works in a similar way under the Markets in Crypto-Assets Regulation (MiCA), the EU-wide law for crypto companies. Under Article 63 of MiCA, a national regulator has 25 working days to check whether an application is complete. It may refuse to review a file that stays incomplete. Once the file is complete, the regulator has 40 working days to grant or refuse authorization.

    What the Official Numbers Show

    With those outcomes in mind, the published figures start to make more sense. They come from different regimes and dates, so they cannot be compared like for like. Still, they all point in the same direction. The table below gathers the clearest official data available as of September 2026.

    Regulator License type What the official figures show As of

     

    FCA (UK) Crypto registration under the Money Laundering Regulations About 14% of applications since January 2020 ended in registration September 2024
    MAS (Singapore) Digital payment token license Close to 300 applications since 2020 and 37 licensees August 2026
    MAS (Singapore) Digital token service provider license No licensees listed in the MAS directory September 2026
    SFC (Hong Kong) Virtual asset trading platform license 13 licensed, 6 pending, 16 withdrawn or returned 29 May 2026
    National regulators (EU) MiCA crypto-asset service provider authorization Unauthorized firms had to start winding down EU business after 1 July 2026 June 2026

    Two patterns run through that table. First, approvals are the minority in every regime that publishes numbers. Second, the gap is widest where a regulator has openly set a high bar, as MAS did for digital token service providers in June 2025.

    A Closer Look at Singapore and Hong Kong

    Singapore’s history shows how long this pattern has lasted. In a July 2021 reply to Parliament, MAS said it had received about 170 applications for digital payment token services. By then, 30 had been withdrawn after talks with MAS, 2 had been rejected, and none had yet received a full license. Five years later, in an August 2026 reply, the total had grown to close to 300 applications and 37 licensees. MAS added that most of the others were rejected or withdrawn once applicants saw they could not meet its requirements.

    Hong Kong’s public register tells a similar story in more detail. According to the SFC’s list of trading platforms, 14 applications had been withdrawn and 2 had been returned by the regulator. By comparison, 13 platforms hold a license. Some well-known names appear on the withdrawn list. OKX withdrew in May 2024, and Bybit’s Hong Kong entity withdrew the same month before applying again in June 2025.

    Why Crypto License Applications Get Rejected (and How to Avoid It)
    More Hong Kong trading platform applications have been withdrawn or returned than approved.

    The Seven Most Common Reasons Crypto License Applications Get Rejected

    So what actually goes wrong inside those applications? Regulators explain their decisions, publish guidance, and review each other’s work. Across all of that material, the same seven problems keep coming up.

    1. The Application Is Incomplete or Generic

    The simplest reason an application fails is that something is left out. The FCA says it will reject a submission without assessing it if the minimum information is not there. Austria’s financial regulator, the FMA, takes a similar line under MiCA. It may stop processing an application when missing documents do not arrive on time.

    A complete file can still fail, however, if it reads like a template. The FCA’s guidance for applicants warns against business plans that are generic, off-the-shelf, or high level. It also criticizes risk assessments that list risks unrelated to the business. Other red flags include policies that simply repeat the law and monitoring software left on its default settings.

    In practice, every document should describe how that specific company works. It should name the products the firm offers and the customers it serves. For EU applicants, Coincub’s MiCA license document checklist is a good way to make sure nothing is missing.

    2. Anti-Money Laundering Controls Are Too Weak

    Once a file is complete, the most common hurdle is financial crime. Anti-money laundering (AML) controls are the checks a company uses to stop criminals from moving illegal money through its platform. They include verifying who customers are and watching for suspicious transfers.

    The FCA’s refusal of Zeux Limited shows what failure looks like. Zeux applied in June 2022, and in March 2025 the FCA announced that it had turned the application down. According to the FCA, the firm had not properly identified its money laundering risks. It had also ignored the UK’s National Risk Assessment and had weak procedures for checking customers and reporting suspicious activity. The regulator concluded that registering the firm would have posed a significant risk of harm to the public.

    The same theme appears in other countries. In 2021, MAS told Parliament it would reject applicants that fall short on money laundering and technology risks. Earlier still, in April 2019, New York’s DFS denied Bittrex’s application. One of the reasons it gave was weakness in the exchange’s anti-money laundering and sanctions compliance program.

    A newer part of this test is the Travel Rule. This rule requires crypto firms to send and receive information about who is behind each transfer. The FCA expects applicants to show that data flow in their diagrams. Meanwhile, the FATF reported in July 2026 that 83% of the jurisdictions it surveyed had passed Travel Rule laws.

    3. Key People Fail the Fit and Proper Test

    Strong controls still need the right people to run them, which brings us to the third reason. A fit and proper test is a regulator’s check on whether a company’s leaders are honest, skilled, and able to give the role enough time.

    Under Article 63(10) of MiCA, a regulator must refuse authorization if board members fail the suitability standards in Article 68. ESMA’s supervisory briefing from January 2025 makes those standards more concrete. For example, every executive board member should understand how crypto-assets work. The chief executive should, as a rule, spend all of their working time on the job. Regulators should also consider ongoing criminal cases, even before any conviction. On top of that, people linked to firms that operated without a license elsewhere deserve a closer look.

    The UK applies a similar test to the Money Laundering Reporting Officer (MLRO), the person responsible for spotting and reporting suspicious activity. The FCA flags applications that name only a temporary MLRO. It also looks carefully at MLROs who tend to leave firms soon after those firms are registered. People with certain unspent criminal convictions fail the test automatically. In addition, the FCA treats any failure to disclose relevant information as a serious issue.

    4. Owners, Money, and Capital Cannot Be Explained

    Beyond the management team, regulators want to know who owns the company and where its money comes from. MiCA says a regulator must refuse authorization if major shareholders lack a good enough reputation. A major shareholder here means anyone with a qualifying holding, which is a direct or indirect stake of at least 10% of the capital or voting rights.

    Complicated ownership adds to the challenge. ESMA’s briefing tells regulators to take extra care with complex group structures. The same applies to owners or managers who have already received fines, warnings, or negative reviews from other regulators, including those outside the EU. In the UK, the FCA expects applicants to disclose relevant information about beneficial owners as well as directors.

    Capital is the final piece of this puzzle. Under Article 67 of MiCA, a crypto-asset service provider must hold at least €50,000, €125,000, or €150,000, depending on its services. If one quarter of its fixed running costs from the previous year is higher, that larger amount applies instead. Missing the threshold, or failing to prove where the money came from, is a quick route to refusal. In fact, a capital shortfall was another reason DFS gave for denying Bittrex. Why some crypto licenses cost €15k and others €500k? Well, capital rules affect the total budget.

    5. The Company Has No Real Presence

    Even with clean owners and enough capital, a firm can fail if it only exists on paper. A letter-box entity is a company registered in one country while its real decisions, staff, and systems sit somewhere else.

    MiCA tackles this directly. Article 59(2) sets three basic rules. The firm needs a registered office in an EU country where it provides at least some of its services. It must be managed from inside the EU. At least one director must also live in the EU.

    ESMA’s briefing goes further. It says regulators should look critically at any firm where more work happens outside the EU than inside it. Outsourcing must never go so far that the firm becomes a letter-box entity. Custody of client assets may only be outsourced to providers that are authorized under MiCA.

    Singapore has taken an even firmer stance. In June 2025, MAS said it had set the bar high for firms serving only customers outside Singapore and would generally not issue them a license. Fourteen months later, Coincub found zero digital token service provider licensees in the MAS directory. The UK is moving the same way, as Coincub covered in its report on the FCA’s UK presence rules.

    6. The Business Plan Does Not Add Up

    Once presence is settled, regulators turn to whether the business itself makes sense. ESMA expects a business plan that covers three years and includes clear checkpoints. The plan should start from what the company does today. It should also explain what happens if revenue falls well below forecast.

    The FCA asks for similar depth. A good plan covers every part of the business, including management, IT systems, outsourcing, and the full customer journey. Diagrams should support each part. The FCA also expects realistic financial forecasts and a clear explanation of how controls will grow with the company.

    This area received fresh attention after ESMA reviewed how Malta authorized one crypto firm, covered in more detail below. ESMA found that the firm’s growth forecasts and its ability to onboard clients had not been properly assessed. Separately, ESMA’s briefing notes that firms applying for many crypto services at once can pose a higher risk. An applicant asking for everything on day one should therefore expect harder questions.

    7. Controls Exist Only on Paper

    The final reason ties the other six together, since regulators increasingly want proof that controls actually work. Know Your Customer (KYC) checks confirm who each customer is. Together with custody systems and transaction monitoring, they need to work in real life as well as in a policy document.

    Hong Kong offers the clearest example. In a January 2025 circular, the SFC changed how outside assessors review applicants. Assessors now check whether a platform’s systems are well designed and also properly implemented, after the hardware and software are in place. The SFC made this change because policies often needed major updates once systems went live. Earlier, in a May 2024 statement, the SFC warned that breaking key investor protection rules would lead to a swift refusal. It also said inspections would focus on keeping client assets safe and on KYC processes.

    The FCA takes the same practical view of outsourcing. It expects applicants to keep full oversight of any outside provider. Applicants also need round-the-clock access to data that provider holds, and they should include the service agreements in the application.

    Rejection Reasons at a Glance

    Taken together, those seven reasons form a pattern that is easier to see side by side. The table below sums up what regulators check and the warning signs that most often lead to a “no.”

    Reason What regulators check Common red flag Official source

     

    Incomplete or generic file Every required document, written for the actual business Template policies and unrelated risks FCA, FMA (Austria)
    Weak AML controls Risk assessment, customer checks, suspicious activity reports, Travel Rule Risks missed or ignored FCA (Zeux), MAS, DFS (Bittrex)
    Fit and proper failures Honesty, skills, crypto knowledge, time commitment Undisclosed issues or a temporary MLRO MiCA Article 68, ESMA, FCA
    Owners and capital Reputation of 10%+ owners, source of funds, minimum capital Complex groups or missing capital MiCA Articles 63 and 67, DFS
    No real presence Local office, management, and staff Letter-box setup or heavy outsourcing MiCA Article 59, ESMA, MAS
    Weak business plan Three-year plan, realistic forecasts, growing controls Forecasts disconnected from today’s activity ESMA, FCA
    Paper-only controls Systems tested after they go live Tools on default settings, custody gaps SFC, FCA

    Every row in that table traces back to a published regulatory document. That matters, because it means applicants can check each expectation for themselves before they submit.

    Why Regulators Have Raised the Bar in 2025 and 2026

    Those reasons have existed for years, yet the pressure behind them has grown sharply since 2025. Several official events explain the shift.

    The first came in January 2025, when ESMA published its supervisory briefing. Its goal was to help national regulators across the EU assess applications in the same way. Then, in July 2025, ESMA released a peer review of Malta’s financial regulator, the MFSA. The review found that the MFSA had only partially met expectations when it authorized one crypto firm, because some serious issues were still unresolved at the time. ESMA then urged every national regulator to focus on areas such as business growth, conflicts of interest, governance, and IT systems. No regulator wants to be the next one criticized, so applicants across the EU should expect more follow-up questions.

    The second shift was the end of MiCA’s transition period on 1 July 2026. Shortly before that date, ESMA issued a public statement on firms without authorization. It said they must stop onboarding new EU clients, stop marketing, and wind down their EU business in an orderly way. The statement also accepted that some significant firms might not secure authorization in time.

    Outside Europe, pressure has built in the same direction. MAS set a very high bar for overseas-only token service providers in June 2025. A year later, the FATF’s July 2026 update pointed to ongoing difficulty in identifying and supervising offshore crypto firms. FATF’s president said effective implementation “can no longer be delayed.”

    Why Crypto License Applications Get Rejected (and How to Avoid It)
    Regulators in the EU, Singapore, and the UK have tightened licensing expectations step by step since early 2025.

    The UK’s New Gateway Adds a Fresh Test

    The UK is next in line, and its timetable makes these lessons urgent for many firms. The FCA’s application gateway for its new crypto regime opens on 30 September 2026 and closes on 28 February 2027. The regime itself is due to start on 25 October 2027.

    Importantly, firms already registered under the Money Laundering Regulations will not be converted automatically. Instead, they must win full authorization under the Financial Services and Markets Act (FSMA). The FCA has also said it will turn down requests for pre-application meetings that lack meaningful information. Firms therefore need a detailed business model ready before the first conversation. For a wider view of the UK market, see Coincub’s UK crypto country guide.

    What Happens After a Rejection

    For a firm that has already heard “no,” the next question is what that decision means for the business.

    A formal refusal usually forces a firm to stop serving customers in that market. In 2024, the SFC said platforms whose applications are refused must close their Hong Kong business. In New York, DFS required Bittrex to stop operating in the state and wind down within 60 days of its 2019 denial. In the EU, ESMA expects firms without MiCA authorization to wind down in an orderly way, which includes helping clients move to authorized providers.

    Can a Firm Apply Again?

    In many cases, a firm can apply again, although a second attempt faces closer checks. The FCA says a firm refused under the Money Laundering Regulations could still be authorized under FSMA later, as long as it meets the required standards. Hong Kong’s register shows this in action. Bybit’s Hong Kong entity withdrew in 2024 and returned with a new application in 2025.

    At the same time, regulators remember earlier problems. ESMA tells national regulators to look harder at firms and people with negative records at other authorities. The FCA, for its part, treats non-disclosure seriously. Consequently, a stronger second application should fix the original weaknesses and explain openly what has changed.

    How to Avoid a Crypto License Rejection

    Putting all of this together, the official guidance on crypto license requirements points to a practical checklist. Any firm can work through it before applying.

    1. Talk to the regulator early. The FCA runs pre-application meetings and Austria’s FMA holds one-to-one talks with future applicants, so bring a real business plan to the first meeting.
    2. Write documents for your own business. Every policy, risk assessment, and procedure should describe your actual products, customers, and systems. Coincub’s guide to AI for VASP and CASP applications shows how some firms now organize this evidence.
    3. Hire strong key people before you apply. A full-time, experienced compliance lead and board members who understand crypto are central to passing the fit and proper test.
    4. Map your ownership and funding. Be ready to show who owns at least 10% of the company, where the capital came from, and how you meet the minimum capital rules.
    5. Build real local presence. Place decision-makers, staff, and control functions in the country that grants the license, and keep outsourcing limited and well supervised.
    6. Test your controls in practice. Run your KYC, monitoring, custody, and Travel Rule systems before you submit, so you can show they work.
    7. Disclose everything. Share past regulatory issues, legal cases, and earlier applications upfront, because hidden problems usually surface during checks.
    8. Choose the right license and country. Coincub’s 2026 crypto license map and its guide on how to get a crypto license compare the options by region.

    Most steps on that list line up directly with one of the seven reasons above. A firm that works through the checklist honestly will therefore have answered most of a regulator’s likely questions before it applies.

    Final Thoughts

    Crypto license applications get rejected for reasons that are surprisingly similar across countries. Regulators want complete, tailored applications and strong AML controls. They also want trustworthy people and owners, enough capital, a real local presence, a believable plan, and systems that work in practice. Because the bar rose again in 2025 and 2026, firms that prepare for each of these points give themselves the best chance of hearing “yes” the first time.

    To see where firms are actually getting licensed each month, follow Coincub’s monthly crypto licensing register.

    Frequently Asked Questions (FAQ)

    Why do most crypto license applications fail? +

    Most crypto license applications fail because of weak anti-money laundering controls, incomplete or generic documents, or unsuitable key people. Regulators also refuse firms with unclear ownership, too little capital, no real local presence, or controls that only exist on paper.

    What is the difference between a rejected and a withdrawn crypto license application? +

    A rejected application is sent back by the regulator without a full review, usually because required information is missing. A withdrawn application is pulled by the firm itself, often because it cannot fix the regulator's concerns in time or expects a refusal.

    How long does MiCA authorization take for a crypto company? +

    Under MiCA, a national regulator has 25 working days to check that an application is complete and 40 working days to decide once it is complete. In practice, incomplete files and requests for more information can make the full process much longer.

    Can you reapply for a crypto license after being refused? +

    Yes, many regulators allow a new application after a refusal, as long as the firm fixes the original problems. The FCA says a firm refused registration could still be authorized later, but earlier refusals and past regulatory issues usually lead to closer checks.

    What is a fit and proper test for crypto companies? +

    A fit and proper test checks whether a crypto company's directors, owners, and key staff are honest, skilled, and able to commit enough time. Regulators review criminal records, past regulatory issues, experience, and, under ESMA's guidance, each board member's understanding of crypto.

    Why does the FCA reject so many crypto registration applications? +

    The FCA mainly turns crypto firms away because their anti-money laundering frameworks are weak or generic. Its guidance highlights poor risk assessments, template policies, unsuitable compliance officers, and missing information. Many firms withdraw before a formal refusal once these gaps become clear.

    How much capital do you need for a MiCA license? +

    MiCA requires crypto-asset service providers to hold at least €50,000, €125,000, or €150,000, depending on the services offered. Firms with higher running costs must hold more, because the requirement rises to one quarter of the previous year's fixed overheads.

    Regulation
    Regulatory Capital After a Licensed Company Share Sale
    A share sale leaves the licence inside the same legal entity, so its capital requirement carries straight through signing, completion and integration without any reset. Under MiCA, a crypto-asset service provider (CASP) must hold the higher of its Annex IV floor of €50,000, €125,000 or €150,000 and one quarter of the previous year’s fixed overheads, […]...
    23 hours ago
    Regulation
    Regulatory Fit-and-Proper Tests for Buyers and Key Persons
    A fit and proper test checks that a licensed firm’s owners and senior staff are honest, competent and financially sound, and every major crypto hub runs one. Under the EU’s Markets in Crypto-Assets Regulation (MiCA), buying 10% or more of a crypto-asset service provider, or crossing 20%, 30% or 50%, triggers a regulatory review of […]...
    1 day ago
    Regulation
    Can Stablecoin Issuers Freeze Funds Without a Court Order?
    Section 4(a)(6)(B) allows issuance only where the issuer can comply with a lawful order to seize, freeze, burn or block its tokens. Tether burns frozen balances, Circle blocks transfers without burning, and the Paxos contract behind PYUSD can wipe a frozen address. Both major issuers reserve the right to move before a court order exists, […]...
    1 day ago