Global VASP regulatory 8 -pole comparison matrix — JP / KR / HK / SG / EU / US / UAE / UK

ConfidenceLikelyUpdated2026-07-29Review by2027-01-29Sources8Machine-translatedOriginal (JA)

On this page

TL;DR

This entry places eight jurisdictions—Japan, Korea, Hong Kong, Singapore, the EU, the US, the UAE, and the UK—side by side as current regulatory verification routes. It does not treat them as converging on one model. Legal sources, licence classes, asset segregation, AML / Travel Rule, stablecoins, cross-border activity, marketing, enforcement, disclosure, and exceptions must be checked in jurisdiction-specific primary materials. For details, start from jp-vasp-regulatory-timeline / eu-mica-casp-regime-overview / us-crypto-licensing-multi-layer-system / hk-sfc-vasp-licensing-overview / sg-mas-dpt-licensing-overview.

Wiki route

This entry sits under exchanges index. It is the cross-cut (横串) counterpart to the per-pole files above and reads against global stablecoin regulatory five-pole matrix for the parallel stablecoin axis, and legal/financial licenses for the system / regulatory boundary on the Japan side.

Key facts

  • Selection: the eight jurisdictions are not an exhaustive global ranking; they are chosen to compare major regulatory designs
  • Method: do not rank fixed cold-storage ratios, capital, thresholds, or implementation dates; align entity, activity, exceptions, and verification date when reading each authority’s current rules

Source: current regulatory entry points for Japan, Korea, Hong Kong, Singapore, the EU, US NYDFS, the UAE, and the UK.

Jurisdiction Main public supervisory entry Scope recorded here
Japan FSA / JVCEA crypto-asset exchange registration and self-regulation
Korea FSC / FIU virtual-asset service-provider supervision
Hong Kong SFC VATP regime
Singapore MAS Payment Services / DPT regime
EU ESMA / national NCAs MiCA / CASP regime
US federal authorities / states / NYDFS layered federal and state regime
UAE VARA / ADGM-FSRA and others emirate- and financial-free-zone regimes
UK FCA cryptoasset registration and regulation

B. License categories / tiers

Source: verify licence names and permitted activities on each authority’s current page linked in section A.

Jurisdiction How to read the regime What to recheck
Japan separate crypto-asset exchange and financial-instruments activities FSA registry and business scope
Korea separate FIU registration and related information-security requirements current law and supervisory materials
Hong Kong consult SFC VATP requirements licence conditions and client scope
Singapore consult Payment Services Act service classes licence class and DPT conditions
EU consult MiCA CASP service authorisations NCA authorisation and passporting
US verify federal, state and activity-specific licences separately state differences and federal business law
UAE separate VARA, ADGM, DIFC and other jurisdictions activity permission and location
UK consult the FCA’s current registration and authorisation scope separate effective requirements from proposals

C. Activity coverage (spot / derivatives / custody / staking / lending / NFT marketplace)

Source: activity permission must be checked by product, client, legal entity and jurisdiction on the authority pages linked in section A rather than reduced to one symbol.

Activity Question to separate What to verify in primary sources
Spot brokerage, dealer activity and venue operation authorised service and client scope
Derivatives VASP rules versus securities or commodities rules need for a separate licence
Custody self-custody, third-party custody and trust segregation and custodian qualification
Staking / lending ancillary exchange service versus financial product product conditions and disclosures
NFT transferability, payment function and investment function function-by-function classification

D. Capital requirements / segregation

Source: capital, segregation and custody requirements can change by amendment and licence class; consult each authority’s current rules linked in section A.

Requirement axis Comparison method Why no fixed value is shown
Capital verify by entity, activity and licence class classes, currencies and requirements differ
Client money distinguish trust, segregated account and bank protection legal structures differ by jurisdiction
Crypto-asset custody distinguish cold/hot, self-custody and third-party custody ratios, exceptions and compensation differ
Insurance / guarantee separate statutory requirements from optional contracts limits and exclusions vary by contract

E. Fit-and-proper / source of capital

Fit-and-proper, management, qualifying-holding, and source-of-funds requirements vary by jurisdiction, licence class, and applicant. Follow each authority’s route in section A to the current application or authorization rules and verify covered persons, review criteria, filing timing, and ongoing duties.

F. AML / Travel Rule implementation

Source: confirm AML and Travel Rule requirements in each authority’s current rules linked in section A and in the jurisdiction’s FATF implementation.

Verification axis What to confirm in primary sources Note
Covered entities definition of VASP / CASP / financial institution coverage is not identical across jurisdictions
Required information originator and beneficiary fields requirements differ by destination type
Thresholds / exceptions current statute and guidance currency conversion and exceptions change
Transmission method legal requirement versus industry protocol do not confuse one vendor with a statutory requirement

Stablecoin issuance and distribution can span banking, payments, e-money, trust, and securities rules outside the VASP regime. Separate effective rules from proposals, and verify issuer eligibility, reserves, redemption, and distribution in dated primary sources. See global-stablecoin-regulatory-five-pole-matrix for jurisdiction-level detail.

H. Cross-border solicitation / passporting

Cross-border solicitation and passporting depend on client location, active versus reverse solicitation, product, provider entity, and licence scope. Avoid fixed country counts or labels such as “foreign-capital exclusion”; verify current authority guidance and registers. For Japan’s warning-check workflow, see fsa-foreign-exchange-warning-system.

I. Marketing / promotion rules

  • Japan: JVCEA advertising guidelines (risk warnings required, exaggerated expressions prohibited, restrictions on the use of celebrities)
  • Korea: Exaggerated advertising prohibited under the User Protection Act; risk-explanation obligation at the listing of new tokens
  • Hong Kong: SFC Code of Conduct applies; for retail, only large-liquidity tokens may be advertised
  • Singapore: 2022-01 MAS guidelines effectively ban retail advertising of DPT services entirely (a symbol of the institution-oriented hub)
  • EU: MiCA Article 7 (white paper) / Article 29 (marketing communications) require fair / clear / not misleading obligations
  • US: By state + SEC Reg BI / FINRA rule apply; influential persons require disclosure
  • UAE: VARA Marketing Regulations 2023-12 set detailed rules, with constraints even on the use of overseas influencers
  • UK: Financial Promotion Order + a cooling-off period of 24 hours (new customers must wait 24h after application), with risk-warning + appropriateness-assessment obligations

J. Representative enforcement cases (1-2 件 / pole)

  • Japan: Coincheck NEM 580 億円 outflow (2018-01) → business improvement order (details coincheck-nem-hack-detailed-analysis) ; DMM Bitcoin Lazarus hack (2024-05) → voluntary closure (dmm-bitcoin-lazarus-hack-detailed-analysis)
  • Korea: Terra-Luna collapse (2022-05) → Do Kwon indicted by Korean prosecutors / arrested in Montenegro ; Korean prosecutor investigation expanded over FTX customer losses
  • Hong Kong: JPEX fraud (2023-09) → 11 名 arrests by Hong Kong police, losses over HK$15 億, a catalyst for improving the Hong Kong SFC warning list
  • Singapore: Three Arrows Capital failure (2022-06) → MAS banned 3AC from business for 9 years; Su Zhu/Kyle Davies in judicial cooperation with the US
  • EU: Binance France AMF warning (2023) → re-authorized in the 2024 SAS Société form ; BaFin’s individual approval of Coinbase Germany 2021-06
  • US: SEC v. Coinbase (filed 2023-06 → dismissed in part 2024-03 ) ; SEC v. Binance.US (2023-06) ; FTX failure → SBF 25 -year prison sentence (2024-03)
  • UAE: Bybit (UAE-headquartered) / withdrawal from the Japanese market (2026-03) ; OKX US settlement over FIU violations 2025
  • UK: Binance UK FCA warning → withdrawal 2024 ; Copper.co accelerating expansion after authorization

K. Disclosure / financial reporting / proof-of-reserves

  • Japan: Monthly submission of customer-asset-segregation status to JVCEA + annual financial-results disclosure (submitted to the FSA)
  • Korea: Monthly STR reporting to the FIU + annual KISA ISMS renewal audit
  • Hong Kong: Monthly returns to the SFC + annual IFRS audited financials + monthly client asset attestation
  • Singapore: Annual financial statement + assurance report to MAS (monthly customer asset report for large MPIs)
  • EU: MiCA Article 67 strengthens annual report + key information disclosure + monitoring
  • US: NY BitLicense requires quarterly financial reports + annual audited financials + recommended monthly proof-of-reserves
  • UAE: verify the current proof-of-reserves and reporting frequency and scope in the VARA Rulebook
  • UK: verify current disclosure under the MLR and implementation status of the FSMA extension against dated official FCA materials

L. Notable carve-outs / exceptions

  • Japan: NFTs are in principle outside the VASP scope (judged individually by function) ; banks / trust banks fall under a separate framework for stablecoin issuance
  • Korea: The User Protection Act fully bans retail derivatives → even CME-affiliated overseas underwriting including institutional is restricted
  • Hong Kong: HKMA stablecoin runs parallel to the SFC VATP, dual supervision
  • Singapore: DBS Digital Exchange is by individual MAS approval (separate from the PSA), institution-only
  • EU: Existing NCA-authorized operators get a 18 -month transitional period (2024-12-30 → 2026-07-01) to migrate to MiCA
  • US: The OCC Federal Trust Charter fully exempts 50 -state MTL (Anchorage Digital was the first to obtain it 2021-01 , Circle obtained it 2025 )
  • UAE: DIFC is outside VARA’s jurisdiction (DFSA alone), ADGM is FSRA-independent (with 3 systems coexisting within the UAE)
  • UK: MLR registration is an AML obligation only; market-conduct regulation depends on the FSMA (a two-stage structure)

Integrated type (single-passport regime)

  • EU MiCA: 1 license → passporting to 27 countries (the world’s widest)
  • Japan: FSA single registration, but two-layer with JVCEA self-regulation
  • Korea: FSC + FIU single, further concentrated by the bank 1:1 rule
  • Singapore / Hong Kong: Single supervision within the city-state / SAR

Fragmented type (multi-layer regime)

  • US: Federal (FinCEN/SEC/CFTC/OCC) + state (50 -state MTL + NY BitLicense), the world’s most complex
  • UAE: VARA + DFSA + ADGM-FSRA + federal SCA + Central Bank, with 5 systems coexisting

Phased build-out type (phased regime)

  • UK: MLR 2017 (AML-centered, current) → FSMA 2023 extension (2026-2027 phased) to shift to full-scale regulation
  • Korea: Specific-Financial-Transaction-Information Act (2021) → User Protection Act (2024) → stablecoin regulation (planned 2026 ), added in phases

3. Implications for global CEX strategy

When assessing location strategy or market access, compare each entity’s authorization, client scope, passporting or solicitation rules, capital and custody requirements, and tax position at the same date. This entry does not establish city-level role allocation, licence cost, headquarters-relocation motives, or a future issuance hub without primary evidence.

Sources

#exchanges#vasp#regulation#comparison#matrix#benchmark

Discovery

Keep reading

Related

Read next

Links here