top of page

VARA Licence in Dubai: Activities, Application Process and Compliance

Jul 8
22 min read

Updated: Aug 3

Dubai has established a dedicated regulatory framework for virtual assets and Virtual Asset Service Providers. The Virtual Assets Regulatory Authority, commonly known as VARA, regulates virtual asset activities conducted in or from the Emirate of Dubai.


VARA’s jurisdiction covers Dubai’s mainland and Free Zones, with the exception of the Dubai International Financial Centre, which operates under a separate financial-services regulatory framework. 


A business intending to provide regulated virtual asset services in or from Dubai must obtain the appropriate VARA Virtual Asset Service Provider Licence. The application must be submitted through a legal entity established with the Dubai Department of Economy and Tourism or an eligible Dubai Free Zone outside the DIFC. A commercial trade licence alone does not authorise the company to begin regulated virtual asset operations. 


VARA currently identifies eight regulated activity categories:


  • Advisory Services

  • Broker-Dealer Services

  • Custody Services

  • Exchange Services

  • Lending and Borrowing Services

  • Management and Investment Services

  • Transfer and Settlement Services

  • Category 1 Virtual Asset Issuance


A Virtual Asset Service Provider may apply for several activities under one overarching licence, although certain Custody Services must remain segregated. The applicant must satisfy the requirements applicable to every activity it intends to conduct. 


VARA applies a staged licensing process. Receiving In-Principle Approval does not permit the applicant to begin operations, conduct virtual asset activities, or serve clients. Commercial activity may commence only after the full VASP Licence has been issued and the applicable licensing conditions have been satisfied. 


This guide explains which businesses require a VARA licence, the regulated activity categories, the application process, governance and compliance expectations, operational requirements, and the principal matters investors should evaluate before establishing a virtual asset business in Dubai.


What is VARA?


The Virtual Assets Regulatory Authority (VARA) was established by the Government of Dubai in 2022 to regulate, supervise, and oversee virtual asset activities across the Emirate of Dubai.


Its primary objective is to create a secure, transparent, and innovation-friendly environment while protecting investors and maintaining the integrity of the financial system.


Unlike many jurisdictions where cryptocurrency regulation remains uncertain, Dubai has introduced clear licensing pathways for companies wishing to operate legally.


This clarity has attracted global exchanges, blockchain developers, fintech startups, and institutional investors to establish operations in Dubai.


Who Needs a VARA Licence in Dubai?


Any entity intending to conduct a regulated virtual asset activity in or from Dubai must obtain the appropriate VARA authorisation before commencing that activity.


This requirement applies whether the business:


  • Serves retail, qualified, or institutional clients

  • Operates through the Dubai mainland or a Dubai Free Zone

  • Provides services through a website, application, platform, or other digital channel

  • Is incorporated in the UAE or forms part of an international group

  • Uses another regulated company for custody, execution, settlement, or technology

  • Describes its service as fintech, blockchain, Web3, tokenisation, or digital assets


The licensing assessment is based on what the business actually does, not only on the activity name selected for its commercial licence.


Businesses should therefore analyse:


  • The services offered to clients

  • Whether the company receives or transmits orders

  • Whether it controls or safeguards client virtual assets

  • Whether it exchanges virtual assets for fiat currency or other virtual assets

  • Whether it manages, invests, lends, borrows, transfers, or settles virtual assets

  • Whether it provides personalised virtual asset recommendations

  • Whether it issues or distributes a virtual asset

  • Whether it trades solely for its own account


No regulated virtual asset activity is automatically exempt from regulatory oversight. Depending on the business model, the company may require a VASP Licence, VARA approval, registration, or a No Objection Certificate.


Proprietary trading requires a VARA No Objection Certificate. Proprietary trading above the applicable threshold must also be registered with VARA. The current threshold is AED 1 billion in trading volume calculated on a rolling 30-day basis.


A technology provider does not avoid regulation merely because it describes itself as a software or distributed-ledger business. Where the service falls within a regulated virtual asset activity, the appropriate VARA authorisation is required.


The regulatory-perimeter assessment should be completed before incorporation, technology development, customer onboarding, marketing, or contractual commitments.


VARA Licensed Virtual Asset Activities


VARA applies an activity-based licensing framework. The applicant must identify each regulated activity included in its proposed business model and satisfy the requirements applicable to every selected activity.


Advisory Services


Advisory Services involve providing a personal recommendation concerning one or more virtual asset transactions or actions.

The provider must assess matters such as the client’s knowledge, experience, objectives, risk tolerance, financial circumstances, and ability to bear losses.


Broker-Dealer Services


Broker-Dealer Services can include arranging or accepting orders, matching buyers and sellers, dealing in virtual assets, making a market, and providing certain placement or distribution services.


Custody Services


Custody Services involve safeguarding virtual assets for another person and acting on verified instructions concerning those assets.


Custody creates specific requirements concerning wallet management, asset segregation, cryptographic keys, security, reconciliation, and client-asset protection.


Certain Custody Services must be conducted through a legally separate entity and cannot simply be combined with every other activity under the same operating company.


Exchange Services


Exchange Services generally involve operating facilities through which clients can exchange virtual assets for fiat currency or other virtual assets.


The applicant must address matters including market operation, execution, liquidity, surveillance, technology, client access, and asset admission.


Lending and Borrowing Services


These services involve facilitating or providing arrangements under which virtual assets are lent, borrowed, or otherwise made available subject to repayment or return obligations.


Management and Investment Services


Management and Investment Services can include managing or investing virtual assets on behalf of clients, including through discretionary or collective investment arrangements where applicable.


Transfer and Settlement Services


Transfer and Settlement Services involve transmitting, transferring, or settling virtual assets between wallets, persons, platforms, or counterparties.


Category 1 Virtual Asset Issuance


Category 1 issuance is subject to the Virtual Asset Issuance Rulebook and the requirements applicable to the particular virtual asset and issuance model.


Other issuances falling within Category 2 require the applicable VARA approval process and supporting documentation, which may include a whitepaper, issuer information, technical controls, data-protection measures, and Anti-Money Laundering compliance.


A VASP may apply for several activities under one overarching licence. Each activity must be expressly included, and the corresponding rulebook requirements apply cumulatively.


Businesses should not select activities merely to preserve future options. Every additional activity can affect the application documents, governance framework, capital requirements, compliance resources, fees, technology controls, and continuing supervision obligations.


VARA Licence Application Process


A new applicant generally completes two principal regulatory stages through the Dubai Department of Economy and Tourism or the selected Dubai Free Zone.


Stage 1: Approval to Incorporate


The applicant begins by submitting an Initial Disclosure Questionnaire through its proposed commercial licensing authority.


The initial submission generally includes:


  • Proposed virtual asset activities

  • Business model and operating plan

  • Ownership and group structure

  • Ultimate Beneficial Owner information

  • Details of directors, senior management, and responsible individuals

  • Target clients and markets

  • Proposed technology and custody arrangements

  • Financial projections and funding information

  • Initial compliance and risk information


VARA may request additional information before deciding whether the applicant is suitable to proceed.


The applicant must also pay the initial application charges, which are typically 50% of the relevant licence application fee.


Where the initial assessment is successful, the applicant may receive an Approval to Incorporate, commonly referred to as an ATI. This allows the applicant to complete the legal incorporation and begin operational setup, including securing premises, recruiting employees, developing systems, and preparing the full licence application.


An ATI does not authorise the company to:


  • Conduct regulated virtual asset activities

  • Onboard or serve clients

  • Hold or control client assets

  • Process client transactions

  • Represent itself as a fully licensed VASP


Stage 2: Full VASP Licence Application


After the Approval to Incorporate, the applicant submits the detailed documentation required for the selected activities.


The review may include:


  • Detailed business and financial plans

  • Governance and ownership documents

  • Fit-and-proper assessments

  • Compliance and Anti-Money Laundering frameworks

  • Risk-management procedures

  • Technology, cybersecurity, and wallet controls

  • Client-asset and client-money arrangements

  • Market-conduct documentation

  • Outsourcing and third-party agreements

  • Internal policies and operating procedures

  • Capital, insurance, and prudential evidence

  • Business continuity and wind-down planning

  • Meetings and interviews with VARA


VARA may issue questions, request amendments, require further evidence, or impose specific operational conditions.


The applicant must pay the remaining application fee and the applicable first-year supervision fees before final authorisation.


Only after VARA issues the full VASP Licence, and any pre-operational conditions have been satisfied, may the company begin the authorised virtual asset activities.


Commercial Licence, ATI, IPA and VASP Licence


These approvals should not be confused:


  • commercial licence establishes the legal entity and records its commercial activities. It does not independently authorise regulated virtual asset services.

  • An Approval to Incorporate allows a new applicant to establish the entity and prepare its regulated operation. It does not permit client activity.

  • An In-Principle Approval is a conditional regulatory status allowing an applicant to complete remaining requirements. It does not permit operations or client servicing.

  • full VASP Licence authorises only the activities recorded on the licence, subject to its conditions and continuing regulatory obligations.


Investors should not announce a launch date, accept customer funds, or begin regulated operations based solely on incorporation, an ATI, or an IPA.


Governance, Ownership and Management Requirements


VARA assesses not only the proposed virtual asset activities but also whether the applicant has a clear, transparent, and effective corporate structure.


A VASP must maintain a legal entity in Dubai in a form accepted by the relevant commercial licensing authority. Its ownership structure must allow VARA to identify:


  • Direct and indirect shareholders

  • Controlling entities

  • Ultimate Beneficial Owners

  • Voting rights

  • Delegated authority

  • Group companies and related entities

  • Any nominee, trust, DAO, or decentralised-governance arrangement


Complex ownership structures must be commercially justified and must not prevent effective regulatory supervision or decision-making.


VARA’s prior written approval may be required before implementing a material change to the company’s ownership, control, governance, authorised activities, or business model.


Board and Senior Management


The applicant must establish a board and senior-management structure appropriate to the nature, scale, and complexity of the proposed activities.


Directors and senior managers should collectively possess sufficient:


  • Virtual asset and financial-services knowledge

  • Regulatory and compliance experience

  • Risk-management capability

  • Technology and cybersecurity understanding

  • Operational and commercial experience

  • Financial competence


Board members, senior managers, shareholders, and other relevant individuals may be subject to fit-and-proper assessment. VARA may consider their qualifications, experience, financial standing, integrity, reputation, regulatory history, and ability to perform the proposed role.


Responsible Individuals


A VASP must appoint two Responsible Individuals who are accountable for the company’s compliance with its legal and regulatory obligations.


Each Responsible Individual must:


  • Be a full-time employee of the VASP

  • Hold a sufficiently senior position

  • Be resident in the UAE or hold a UAE passport

  • Satisfy VARA’s fit-and-proper requirements

  • Be notified to and approved by VARA


The appointment should not be treated as a nominal designation. The individuals must have sufficient authority, knowledge, access, and resources to perform their responsibilities.


Compliance Officer and MLRO


The VASP must appoint a Compliance Officer who:


  • Has at least five years of relevant compliance experience

  • Is a full-time employee of the VASP

  • Is resident in the UAE or holds a UAE passport

  • Reports directly to the board

  • Is approved by VARA as fit and proper


The VASP must also appoint a Money Laundering Reporting Officer with at least two years of experience handling Anti-Money Laundering and Counter-Terrorist Financing matters.


The Compliance Officer may hold another non-client-facing control role, including the MLRO role, where this does not create conflicting duties and VARA considers the arrangement appropriate.


Applicants should identify suitable candidates early. Licensing can be delayed where the proposed management or control-function appointments do not demonstrate sufficient experience, independence, authority, or local availability.


VARA Licence Fees and Capital Requirements


The cost of establishing a regulated virtual asset business includes more than the company-incorporation and commercial-licence fees.


VARA’s published application and annual supervision fees currently include:


Licensed Activity

Application Fee

Annual Supervision Fee

Advisory Services

AED 40,000

AED 80,000

Transfer and Settlement Services

AED 40,000

AED 80,000

Broker-Dealer Services

AED 100,000

AED 200,000

Custody Services

AED 100,000

AED 200,000

Exchange Services

AED 100,000

AED 200,000

Lending and Borrowing Services

AED 100,000

AED 200,000

Management and Investment Services

AED 100,000

AED 200,000

Category 1 Virtual Asset Issuance

AED 100,000

AED 200,000


Where the applicant requests several activities, an extension fee applies for each additional activity. VARA may also impose additional supervision fees according to the VASP’s risk profile, complexity, client base, market share, and regulatory history.


These fees are separate from:


  • Mainland or Free Zone incorporation fees

  • Trade-licence and annual renewal costs

  • Office and facility costs

  • Employee visas and insurance

  • Compliance and senior-management salaries

  • Legal, regulatory, accounting, and consulting fees

  • Technology and cybersecurity infrastructure

  • Independent audits and testing

  • Professional indemnity and other insurance

  • Banking, custody, liquidity, and operational costs


Paid-Up Capital


The minimum paid-up capital depends on the licensed activity and, in several cases, the VASP’s fixed annual overheads.


Current principal requirements include:


  • Advisory Services: AED 100,000

  • Broker-Dealer Services using an approved external custodian: the higher of AED 400,000 or 15% of fixed annual overheads

  • Other Broker-Dealer models: the higher of AED 600,000 or 25% of fixed annual overheads

  • Custody Services: the higher of AED 600,000 or 25% of fixed annual overheads

  • Exchange Services using an approved external custodian: the higher of AED 800,000 or 15% of fixed annual overheads

  • Other Exchange models: the higher of AED 1.5 million or 25% of fixed annual overheads

  • Lending and Borrowing Services: the higher of AED 500,000 or 25% of fixed annual overheads

  • Management and Investment Services using an approved external custodian: the higher of AED 280,000 or 15% of fixed annual overheads

  • Other Management and Investment models: the higher of AED 500,000 or 25% of fixed annual overheads

  • Transfer and Settlement Services: the higher of AED 500,000 or 25% of fixed annual overheads


Capital requirements for Category 1 Virtual Asset Issuance depend on the applicable issuance rules and the type of asset.


Where several activities are licensed, capital must be calculated for each activity. The applicable amounts are not replaced by one single minimum.


Liquidity, Insurance and Reserve Assets


VASPs must also maintain net liquid assets equal to at least 1.2 times their monthly operating expenses. Net liquid assets must be reconciled daily and reported to VARA monthly.


Required insurance may include:


  • Professional indemnity insurance

  • Directors’ and officers’ insurance

  • Commercial crime or equivalent insurance for virtual assets stored in hot wallets

  • Any additional cover imposed through the licence conditions


Where the VASP owes virtual assets to clients, it must maintain equivalent reserve assets on a one-to-one basis in the same virtual asset. These reserves are subject to daily reconciliation and periodic independent audit.


VARA may impose higher capital, liquidity, insurance, or reserve requirements according to the size, complexity, geographic exposure, and risk of the VASP.


Investors should prepare a detailed regulatory budget and financial model before applying. The company must be capable of funding the licensing process, maintaining the required resources, and operating during the period before revenue-generating activity is permitted.


Compliance, Risk Management and AML Requirements


Every licensed VASP must comply with VARA’s compulsory rulebooks:


  • Company Rulebook

  • Compliance and Risk Management Rulebook

  • Technology and Information Rulebook

  • Market Conduct Rulebook


The VASP must also comply with every activity-specific rulebook corresponding to the services included on its licence.


Compliance Management


The company must establish a compliance-management system proportionate to its activities, client base, products, delivery channels, technology, geographic exposure, and operational complexity.


The framework should address:


  • Regulatory responsibilities and reporting lines

  • Compliance monitoring and testing

  • Regulatory reporting and notifications

  • Policies and operating procedures

  • Staff training

  • Record keeping

  • Internal and external audit

  • Breach identification and remediation

  • Conflicts of interest

  • Complaints and client protection

  • Outsourcing and third-party oversight


The board and senior management remain responsible for the adequacy and effectiveness of the control framework. Appointing a Compliance Officer or using external advisers does not transfer this responsibility.


Anti-Money Laundering and Counter-Terrorist Financing


The VASP must establish a risk-based AML/CFT programme covering:


  • Business-wide risk assessment

  • Customer and institutional due diligence

  • Verification of beneficial ownership

  • Source-of-funds and source-of-wealth assessment

  • Politically Exposed Person controls

  • Sanctions screening

  • Ongoing transaction monitoring

  • Enhanced due diligence for higher-risk relationships

  • Suspicious transaction reporting

  • Record retention

  • Staff screening and training

  • Independent review of the AML framework


The risk assessment should consider:


  • Client type

  • Jurisdiction

  • Products and virtual assets

  • Transaction value and frequency

  • Wallet and blockchain exposure

  • Delivery channel

  • Use of privacy-enhancing technologies

  • Counterparties and external VASPs

  • Fraud, market-abuse, proliferation-financing, and sanctions risks


The company may also need systems capable of blockchain analytics, wallet screening, transaction tracing, sanctions detection, Travel Rule compliance, case management, and regulatory reporting.


Outsourcing and Third Parties


A VASP may use external providers for technology, cloud hosting, custody, compliance support, blockchain analytics, payment services, cybersecurity, or other functions.


Outsourcing does not remove the VASP’s regulatory accountability.


Before appointing a provider, the VASP should conduct due diligence covering:


  • Regulatory status

  • Financial and operational capability

  • Cybersecurity and data protection

  • Service continuity

  • Geographic and cross-border risks

  • Subcontracting arrangements

  • Audit and access rights

  • Incident reporting

  • Termination and data-return arrangements


Material outsourcing arrangements must be supported by written agreements, governance controls, monitoring, and any regulatory notification or approval required by VARA.


The compliance framework should be designed before the full licensing submission. Policies copied from another jurisdiction or business model are unlikely to demonstrate that the applicant understands and controls the risks of its proposed Dubai operation.


Technology, Cybersecurity and Operational Resilience


Technology risk is a central component of the VARA licensing assessment. The applicant must demonstrate that its systems, infrastructure, governance, security controls, and technical personnel are appropriate for the proposed virtual asset activities.


The technology framework should cover:


  • System architecture and infrastructure

  • Technology governance and accountability

  • Cybersecurity risk assessments

  • Access controls and privileged accounts

  • Cryptographic-key and wallet management

  • Secure software development

  • Change and release management

  • Vulnerability management

  • Penetration testing

  • Transaction monitoring

  • Data integrity and availability

  • Cloud and third-party technology providers

  • Incident detection and response

  • Business continuity and disaster recovery


Cryptographic Keys and Wallets


Where the business controls virtual assets or cryptographic keys, its procedures should address:


  • Wallet creation and approval

  • Hot, warm, and cold-wallet arrangements

  • Key generation, storage, use, rotation, and destruction

  • Multi-signature and multi-party authorisation

  • Separation of duties

  • Withdrawal approval limits

  • Wallet-address verification

  • Backup and recovery

  • Emergency access

  • Monitoring of unauthorised or unusual transactions


Access should be limited according to role and supported by appropriate authentication, approval, logging, and review controls.


Testing and Independent Review


The VASP should conduct periodic testing proportionate to its systems and risks. This may include:


  • Vulnerability assessments

  • Penetration testing

  • Source-code or smart-contract reviews

  • Wallet and key-management testing

  • Access-control reviews

  • Incident-response exercises

  • Disaster-recovery testing

  • Independent technology audits


Material findings should be documented, prioritised, remediated, and reported through the appropriate governance structure.


Business Continuity and Disaster Recovery


The VASP must maintain a Business Continuity and Disaster Recovery Plan capable of supporting the recovery of critical operations after a technology failure, cyber incident, data-integrity problem, network disruption, loss of facilities, or other operational event.


The plan should identify:


  1. Events that trigger activation

  2. Critical systems and services

  3. Recovery priorities and timeframes

  4. Responsible personnel

  5. Alternative facilities and systems

  6. Internal and external communications

  7. Data recovery and integrity checks

  8. Client and regulatory notifications

  9. Procedures for returning to normal operations

  10. Post-incident review and remediation


VARA requires the Business Continuity and Disaster Recovery Plan to be maintained, tested, and updated at least annually. It must address virtual-asset-specific risks, including network malfunction, loss or corruption of data, key storage, and authorisation controls.


Applicants should develop the technology framework during the licensing process rather than after receiving authorisation. VARA’s Technology and Information Rulebook addresses technology governance, cybersecurity, key and wallet management, testing, algorithms, business continuity, information security leadership, staff competence, and regulatory notification.


Client Protection, Marketing and Market Conduct


A licensed VASP must conduct its business honestly, fairly, transparently, and in a manner that protects clients and market integrity.


The market-conduct framework should address:


  • Marketing and promotional communications

  • Client classification and onboarding

  • Written client agreements

  • Fees and charges

  • Risk disclosures

  • Conflicts of interest

  • Complaints handling

  • Public disclosures

  • Virtual asset admission and review standards

  • Trading by the VASP, directors, and employees

  • Prevention of misleading or abusive practices


Marketing and Promotions


Marketing includes advertisements, invitations, promotions, endorsements, sponsored content, social media, websites, videos, podcasts, events, and other communications intended to promote a virtual asset or related service.


Marketing material should:


  • Be clear, fair, and not misleading

  • Accurately describe the company’s regulatory status

  • Avoid implying that an ATI or IPA is a full operational licence

  • Identify material risks

  • Avoid guaranteed-return or risk-free claims

  • Be approved through an internal compliance process

  • Be retained as part of the company’s regulatory records


The company should not market services outside its authorised activities or represent itself as fully licensed before the VASP Licence has been issued.


Client Agreements and Disclosures


The VASP must enter into a written agreement with each client covering the services provided and the parties’ respective rights and obligations.


Depending on the activity, the agreement should address:


  • The authorised service

  • Fees, spreads, commissions, and charges

  • Order handling and execution

  • Custody and wallet arrangements

  • Client-asset treatment

  • Transaction limits

  • Risks and potential losses

  • Conflicts of interest

  • Suspension or termination of services

  • Complaints procedures

  • Governing law and dispute resolution

  • Use of third-party providers


Licence details, authorised activities, and appropriate risk disclosures should be made publicly available.


Complaints Handling


The VASP must maintain a clear and accessible complaints procedure.


The process should:


  1. Explain how a complaint can be submitted

  2. Identify the channels monitored for complaints

  3. Acknowledge and investigate complaints promptly

  4. Treat clients fairly and consistently

  5. Maintain records of the complaint, action taken, and outcome

  6. Identify recurring or systemic causes

  7. Correct weaknesses affecting other clients or processes


Clients must not be charged for submitting or having a complaint handled. Where a third-party provider is involved, the VASP remains responsible for facilitating and managing the resolution.


VARA’s Market Conduct Rulebook covers marketing, written client agreements, complaints, investor classification, public disclosures, market transparency, proprietary trading, and standards governing the virtual assets supported by a VASP.


Client Assets, Custody and Wallet Controls


A VASP that holds, controls, transfers, or safeguards client virtual assets must establish controls appropriate to its licensed activity and operating model.


The applicant should clearly identify:


  • Whether it or another entity controls the private keys

  • Which legal entity provides custody

  • Where client assets are held

  • Whether wallets are individual or omnibus

  • How client ownership is recorded

  • How deposits and withdrawals are verified

  • How assets are reconciled

  • What happens if the VASP or a service provider becomes insolvent

  • Which third-party custodians, banks, or settlement providers are used


Client assets should not be confused with the company’s own funds or virtual assets.


Relevant controls may include:


  • Segregation of client and company assets

  • Separate accounting and wallet records

  • Daily reconciliations

  • Withdrawal authorisation procedures

  • Restrictions on employee access

  • Monitoring of wallet balances and transactions

  • Investigation of reconciliation differences

  • Incident and loss reporting

  • Independent assurance or audit

  • Procedures for returning assets to clients


Custody Services


A VASP licensed for Custody Services must treat client virtual assets as assets held for the client rather than as assets or depository liabilities of the custodian.


VARA’s Custody Services rules prohibit rehypothecation of client virtual assets held in custody. They also require each client’s assets to be segregated in separate wallets and require the custodian to maintain control of the assets while providing the service.


The Custody Services entity must generally remain legally separate from group entities conducting other regulated virtual asset activities. Its custody personnel and operations must also be sufficiently separated from other group businesses to manage conflicts of interest.


Where another regulated custodian is used, the VASP should conduct due diligence covering:


  • Licensing and regulatory status

  • Wallet and key-management arrangements

  • Financial resources and insurance

  • Cybersecurity and incident history

  • Asset segregation

  • Reconciliation and reporting

  • Access and audit rights

  • Sub-custody arrangements

  • Insolvency treatment

  • Business continuity

  • Termination and transfer of client assets


Appointing a third-party custodian does not remove the VASP’s responsibility to understand, monitor, and disclose the arrangement accurately.


The custody and client-asset model should be designed before the licence application is finalised because it can affect the legal entity structure, licensed activities, capital requirements, technology controls, client agreements, insurance, and operational procedures. 


Financial Records, Audit and Regulatory Reporting


A licensed VASP must maintain complete, accurate, and current books and records that allow transactions, client activity, regulatory compliance, and financial resources to be reconstructed and verified.


The record-keeping framework should cover:


  • Client identification and onboarding information

  • Transaction dates, times, values, fees, and payment instructions

  • Wallet addresses and relevant counterparties

  • Client Money and Client Virtual Asset movements

  • Reconciliations and identified differences

  • Related-party and group transactions

  • Compliance monitoring and risk assessments

  • Complaints, incidents, breaches, and remediation

  • Board and committee decisions

  • Outsourcing and service-provider records

  • Regulatory submissions and correspondence


Records should remain accessible in their original or native file format, including information recorded through distributed-ledger systems where applicable.


Monthly Reporting


VARA’s current rules require VASPs to submit specified financial and operational information each month, including:


  • Balance sheet and off-balance-sheet items

  • Profit and loss information

  • Income statement

  • Cash-flow statement

  • Addresses of the VASP’s virtual asset wallets

  • Relevant group virtual asset transactions

  • Related-party transactions


Quarterly Reporting


Quarterly submissions include:


  • Board and board-committee minutes

  • Evidence of compliance with financial requirements

  • Financial projections and strategic business plans

  • Risk-exposure reports submitted to the board


Annual Reporting and Audit


Annual submissions include audited financial statements and an independent auditor’s opinion and attestation concerning the effectiveness of the VASP’s internal control structure.


The annual reporting package may also include:


  • Senior-management compliance assessment

  • Board or Responsible Individual certification of the financial statements

  • Samples of client-onboarding records

  • Product and service descriptions

  • Updated group and Ultimate Beneficial Owner structure

  • Details of directors, senior management, and committees


The VASP should design its accounting, compliance, technology, and management-information systems so that required reports can be produced accurately and within the applicable deadlines.


Regulatory reporting should not be assembled manually only when a filing becomes due. The underlying information should be reconciled continuously and reviewed through appropriate management controls.


Ongoing Supervision and Material Changes


Obtaining a VASP Licence is not the end of the regulatory process. The company remains subject to continuing supervision, reporting, inspection, audit, notification, and approval requirements.


The VASP should maintain a compliance calendar covering:


  • VARA reporting deadlines

  • Commercial licence and regulatory renewals

  • Financial-resource and liquidity monitoring

  • Insurance renewal

  • Independent audit and testing

  • Policy and risk-assessment reviews

  • Staff training

  • Outsourcing reviews

  • Technology and cybersecurity testing

  • Board and committee meetings

  • Regulatory notifications


VARA’s prior written approval may be required before the company implements a material change.


Changes requiring regulatory assessment may include:


  • Adding a new virtual asset activity

  • Materially changing the scope of an authorised activity

  • Changing the business model

  • Changing ownership, control, or Ultimate Beneficial Owners

  • Merging with or acquiring another business

  • Restructuring the group

  • Making material changes to governance or management

  • Changing custody, technology, or outsourcing arrangements

  • Introducing materially different products, clients, or markets

  • Taking on debt that may materially affect the VASP


The VASP should not implement a material change first and notify VARA afterwards.


Proposed changes should be assessed internally before any contractual commitment is made. The assessment should identify:


  1. Whether prior VARA approval is required

  2. Which licence conditions or rulebooks are affected

  3. Whether capital, insurance, technology, or staffing must change

  4. Which client disclosures and agreements require amendment

  5. Whether another commercial or regulatory authority must also approve the change


Shareholders and group management should understand that control of the licensed entity is constrained by its regulatory obligations. Commercial decisions must remain consistent with the scope and conditions of the VASP Licence.


Wind-Down Planning and Cessation of Business


Every VASP must maintain a wind-down plan designed to support the orderly closure or transfer of its regulated operations.


The plan should address:


  • Risks and obstacles affecting an orderly closure

  • Financial and operational resources required

  • Safeguarding and returning Client Money and Client Virtual Assets

  • Transfer of clients and services to another authorised provider

  • Suspension of new client onboarding

  • Employee and contractor arrangements

  • Client and regulatory communications

  • Technology access, system continuity, and data retention

  • Settlement of liabilities

  • Termination or transfer of outsourcing arrangements

  • Preservation of regulatory records


Client assets should not be treated as resources available to fund the company’s closure or satisfy its own creditors.


The wind-down framework should be tested against scenarios such as:


  • Voluntary discontinuation of an activity

  • Financial distress

  • Loss of banking, custody, liquidity, or technology services

  • Cybersecurity or operational failure

  • Regulatory suspension or licence withdrawal

  • Insolvency


Where the VASP decides voluntarily to discontinue its business or operations, VARA must be notified promptly and provided with the current wind-down plan. The company must then implement the plan subject to VARA’s instructions and continue providing progress reports during the closure process.


A commercial licence cancellation should not be initiated independently of the VARA process. The regulated activities, client assets, records, contracts, employees, financial obligations, and regulatory permissions must be closed or transferred in the correct order.


The wind-down plan should be prepared during the licensing process and updated when the VASP’s activities, clients, technology, service providers, or financial position change.


Common VARA Licence Application Mistakes


Applicants should avoid:


  • Incorporating a company before confirming whether the proposed business model falls within VARA’s regulatory perimeter

  • Assuming that a commercial trade licence authorises regulated virtual asset activity

  • Treating Approval to Incorporate or In-Principle Approval as permission to serve clients

  • Selecting activities based only on commercial licence descriptions

  • Omitting a regulated activity performed indirectly through technology, affiliates, or service providers

  • Marketing virtual asset services before obtaining the required authorisation

  • Describing the applicant publicly as fully licensed while its application remains conditional

  • Underestimating licensing, supervision, capital, staffing, insurance, technology, audit, and compliance costs

  • Appointing senior management, Responsible Individuals, the Compliance Officer, or MLRO too late in the application process

  • Using generic compliance policies copied from another jurisdiction or business model

  • Failing to explain the ownership structure, Ultimate Beneficial Owners, group relationships, or source of funds clearly

  • Designing custody, wallet, client-asset, or outsourcing arrangements after submitting the application

  • Relying on a third-party provider without completing documented due diligence and continuing oversight

  • Launching technology without sufficient cybersecurity, testing, incident-response, and recovery controls

  • Failing to prepare reliable financial projections and evidence of continuing funding

  • Adding products, markets, ownership changes, or activities without assessing whether prior VARA approval is required

  • Treating regulatory reporting as an annual exercise rather than a continuing operational process

  • Cancelling the commercial licence before completing the required regulatory wind-down process


The application should present one consistent operating model across:


  • The commercial licence

  • Initial Disclosure Questionnaire

  • Regulatory business plan

  • Financial projections

  • Governance structure

  • Technology architecture

  • Client agreements

  • Compliance policies

  • Marketing materials

  • Outsourcing contracts


Material inconsistencies can create questions about whether the applicant understands its proposed activities and can operate them safely.


VARA’s licensing process requires applicants to obtain Approval to Incorporate before completing operational setup and then undergo the full VASP Licence review. Firms remain prohibited from conducting regulated activities until the full licence and applicable operational conditions are satisfied.


Why Dubai is Becoming a Global Crypto Hub


Dubai's approach to digital assets is based on responsible innovation.

Rather than banning or leaving the sector unregulated, the government has introduced clear legislation designed to encourage legitimate businesses while maintaining strong regulatory oversight.


Several factors continue to attract crypto companies to Dubai:


Regulatory Certainty


Businesses benefit from clear legal frameworks and defined licensing procedures.


Global Connectivity


Dubai provides access to investors and markets across Europe, Asia, Africa, and the Middle East.


Business-Friendly Environment


The UAE offers efficient company formation procedures, modern infrastructure, and access to highly skilled international talent.


Government Support for Innovation


Artificial Intelligence, blockchain technology, Web3, and digital finance all form part of the UAE's long-term economic strategy.


This combination has made Dubai one of the fastest-growing destinations for virtual asset companies worldwide.


Frequently Asked Questions


What is a VARA Licence?


A VARA Virtual Asset Service Provider Licence authorises a Dubai legal entity to conduct the regulated virtual asset activities specifically recorded on its licence, subject to the applicable conditions and continuing regulatory obligations.


Does a Dubai trade licence allow a company to provide crypto or virtual asset services?


No. A commercial licence establishes the legal entity and records its commercial activities. Regulated virtual asset services require the relevant VARA authorisation before operations begin.


Does VARA regulate every part of Dubai?


VARA regulates virtual asset activities conducted in or from Dubai’s mainland and Free Zones, except within the Dubai International Financial Centre.


Can a foreign investor apply for a VARA Licence?


Yes. VARA does not impose a general nationality restriction on applicants. The application must be made through a legal entity established with the Dubai Department of Economy and Tourism or an eligible Dubai Free Zone outside the DIFC.


Can a sole proprietorship apply?


VARA’s current FAQ states that sole-proprietorship applications are not accepted. An LLC or Free Zone company is generally the preferred structure.


Can a company operate after receiving Approval to Incorporate?


No. Approval to Incorporate allows the entity to complete incorporation and operational preparation. It does not permit regulated virtual asset activity or client servicing.


Is In-Principle Approval the same as a full licence?


No. In-Principle Approval is conditional. The applicant cannot begin regulated operations until the full VASP Licence is issued and any pre-operational conditions are completed.


Can one company apply for several virtual asset activities?


Yes. Several activities may be included under one overarching licence, but the applicant must satisfy the requirements applicable to each activity. Certain Custody Services require legal and operational separation.


Does proprietary virtual asset trading require a licence?


Proprietary trading requires a VARA No Objection Certificate. Registration is additionally required when trading volume exceeds AED 1 billion over a rolling 30-day period.


Can the company advertise before obtaining its full licence?


Marketing of regulated virtual asset activities in or targeting the UAE is subject to VARA’s Marketing Regulations. Marketing relating to a regulated activity must be conducted by, or on behalf of and approved by, a VASP licensed for that activity.


How long does a VARA Licence remain valid?


A VARA Licence is issued on an annual basis and is renewed for 12 months. The applicable annual supervision fee is payable upon renewal.


Does using an external custodian or technology provider reduce the company’s responsibility?


No. The VASP remains responsible for understanding, controlling, monitoring, and accurately disclosing outsourced arrangements.


Can the company add another virtual asset activity later?


Potentially, but it must obtain VARA’s written approval before adding an activity or materially modifying the scope of an authorised activity.


Does the company need a UAE-based compliance team?


VARA requires two full-time UAE-based Responsible Individuals. The Compliance Officer must also be a full-time employee and UAE resident or UAE passport holder, subject to the applicable fit-and-proper requirements.


Can the company close by simply cancelling its trade licence?


No. A regulated VASP must coordinate cessation with VARA, protect and return client assets, maintain records, settle obligations, and implement its approved wind-down plan before completing commercial closure.


These answers reflect VARA’s current licensing process, regulatory perimeter, marketing requirements, renewal framework, and material-change controls.


How NUR Advisors Group Can Help


Establishing a virtual asset business in Dubai requires coordination between commercial incorporation, VARA authorisation, governance, compliance, technology, financial resources, banking, staffing, and continuing regulatory obligations.


NUR Advisors Group assists investors with:


  • Initial assessment of the proposed virtual asset business model

  • Coordination of mainland or Free Zone company formation

  • Identification of the relevant VARA activity categories

  • Preparation and organisation of commercial and regulatory application documents

  • Coordination with specialist legal, compliance, technology, cybersecurity, and audit advisers

  • Support with ownership, management, and Ultimate Beneficial Owner documentation

  • Residence visas, work permits, and establishment services

  • Corporate banking preparation

  • Corporate Tax, VAT, accounting, and bookkeeping support

  • Commercial licence renewals, amendments, and continuing government services


Our role is to help investors establish an organised and commercially practical foundation for the regulatory application. VARA retains complete discretion over licensing, approvals, conditions, supervision, and enforcement.


Plan Your Dubai Virtual Asset Business


A VARA application should begin with a clear regulatory-perimeter assessment, realistic financial resources, qualified management, suitable technology, and a business model capable of meeting continuing compliance obligations.


Investors should not incorporate, market, onboard clients, or commit to operational launch dates without understanding the distinction between the commercial licence, Approval to Incorporate, In-Principle Approval, and the full VASP Licence.


Contact NUR Advisors Group for professional assistance with Dubai company formation, VARA application coordination, tax registration, banking preparation, immigration, and ongoing corporate services.


Dubai skyline with Bitcoin coins, blockchain technology and cybersecurity symbols representing virtual asset regulation

Comments


Follow Us: 

  • Instagram
  • Facebook
  • Linkedin

© 2026 NUR Advisors Group. All rights reserved.

© NUR Advisors Group. This content may not be copied or reproduced without permission.
bottom of page