EST · MMXXVI
Home/Insights/Tax/Vara licence application: The Structuring Angle
Licensing & Registration

Vara licence application: The Structuring Angle

Vara licence application: The Structuring Angle. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

A Dubai-based token issuer building out an exchange function discovers, weeks before launch, that its group structure was assembled for speed rather than regulatory fit. The entity holding user funds sits in a jurisdiction that does not map cleanly to VARA (Virtual Assets Regulatory Authority) – Dubai's mainland virtual-asset regulator – and the activity-based licence it needs. Banking conversations stall. The launch slips. This is the cost of treating a VARA licence application as a compliance exercise rather than a structuring decision.

A VARA licence (regulatory authorisation from Dubai's Virtual Assets Regulatory Authority to conduct defined virtual-asset activities on the Dubai mainland) is the primary gateway for crypto businesses operating in the Emirate outside the DIFC financial free zone. The structuring angle is decisive: which entity applies, which activities it covers, how group capital flows, and how the Dubai structure interacts with parallel licences or registrations elsewhere in the world. Getting that analysis wrong before filing is expensive. Getting it right before the group is incorporated is the difference between a clean application and a material restructuring mid-process.

This analysis works through the key structuring decisions a VARA applicant faces, from entity design and activity scope through to the cross-border implications that determine whether a Dubai licence becomes a genuine operating hub or a regulatory ornament.

What VARA Regulates and Why the Activity Map Comes First

VARA operates an activity-based licensing regime: authorisation is granted for specific virtual-asset activities, not for a generic "crypto business" status. The defined activities span advisory, broker-dealer, custody, exchange, lending and borrowing, management and investment, and transfer and settlement. A business conducting more than one of these functions requires authorisation for each. That is the first structuring decision – the activity map.

In our practice, the most common mistake at the pre-application stage is understating the activity perimeter. An operator building an exchange that also holds client assets pending settlement is conducting custody as well as exchange services. An advisory platform that routes orders to a third-party venue may fall within broker-dealer scope depending on the degree of discretion involved. VARA's rulebooks attach separate conduct obligations, capital expectations and operational requirements to each activity category. Adding an activity post-authorisation requires a variation application, which consumes time and management bandwidth that most operators cannot afford mid-growth.

The activity map exercise should precede entity selection. Before a decision is made on whether to operate through a VARA-regulated entity in a Dubai mainland free zone or through a different group vehicle, the full functional perimeter of the business – today and across the next operating plan horizon – needs to be laid on the table. Regulators in the leading hubs increasingly expect applicants to demonstrate that the proposed licence scope was chosen deliberately, not by default.

CTA #1 – Early-stage structuring analysis
The process above describes the standard path. Your facts – the entity, the user base, the banking – change the analysis. Map your options with OBOLUS before the application window opens.

How Should the Applying Entity Be Structured for VARA?

The applying entity must be incorporated in Dubai (on the mainland or in an approved free zone) and the VARA-licensed activities must be conducted through that entity. A common structuring error is to assume that a holding company incorporated elsewhere – a BVI or Cayman parent, for instance – can hold the licence on behalf of the operating business. It cannot. VARA authorisation attaches to the Dubai entity, not to the group.

This has material implications for group design. The Dubai operating entity needs to be adequately capitalised in its own right; capital held at a parent or sibling entity does not substitute for the regulated entity's own-funds requirement. It needs governance – a board with sufficient local presence and a management team that can satisfy VARA's fit-and-proper review. And it needs clean contractual and IP arrangements with the rest of the group, because VARA's rulebooks scrutinise intra-group arrangements that could compromise the regulated entity's ability to meet its obligations.

Groups that operate across multiple jurisdictions face an additional layer of analysis. A business that holds a MAS Digital Payment Token licence in Singapore and is applying for VARA authorisation in Dubai will be operating two regulated entities in parallel. The question of which entity contracts with which category of user – and therefore which regulatory regime governs that relationship – is not purely academic. It affects where revenue is recognised, which AML/KYC obligations apply, how the Travel Rule (the obligation to pass originator and beneficiary data with a virtual-asset transfer) is implemented across jurisdictions, and what consolidated supervision, if any, either regulator will expect.

Capital and Financial Resource Planning: What the Structuring Angle Reveals

Capital adequacy for a VARA-licensed entity varies by activity category, and the specific figures are set out in VARA's regulatory documents and subject to periodic revision – treat the published rulebooks as the authoritative source, not any secondary summary. What the structuring angle reveals is not the number itself but the planning implications around it.

First, the capital must be held at the regulated entity. Groups accustomed to centralising treasury at a parent will need to plan for a permanent capital allocation to the Dubai vehicle. That allocation has a cost: opportunity cost if the funds would otherwise be deployed, and a governance cost in maintaining the requisite level and demonstrating it continuously to VARA. In our cross-border practice, we regularly advise groups on the interaction between capitalising a regulated entity and the group's overall funding structure.

Second, the capital requirement scales with activity scope. A custody-only operation carries a different capital profile from a combined exchange and custody entity. An operator who builds in excess activity scope to avoid a future variation application will carry a higher capital requirement from day one. The trade-off between application scope and capital cost is a genuine financial modelling exercise, not a regulatory formality.

Third, groups with entities in multiple jurisdictions need to think about consolidated capital adequacy. Neither VARA nor any other single regulator sees the full group picture unless a group-level supervisor exists. For most Dubai-licensed crypto businesses, there is no group-level supervisor. That means the operator must maintain compliant capital at each regulated entity independently, without netting benefits across the group. Planning for this early avoids the unpleasant surprise of discovering that the Dubai entity is undercapitalised because its internal allocation was absorbed by a sister entity's operational draw.

How Does a VARA Entity Interact With Offshore and Other Regulated Entities?

A VARA-licensed entity in Dubai does not, by itself, authorise the business to serve users in other jurisdictions. The VARA regime covers virtual-asset activities conducted in Dubai – on the mainland, outside the DIFC – and does not confer passporting rights across the region or globally. This is the sharpest contrast with the EU's MiCA (Markets in Crypto-Assets Regulation) regime, under which a CASP (Crypto-Asset Service Provider) authorised in one EU member state can passport its services across the EEA.

For a business with a genuinely global user base, the structuring question is which entity serves which users, and what additional regulatory authorisation is required in each market. A VARA-licensed exchange serving users in the EU will need either a MiCA CASP authorisation in an EU member state or a clear legal analysis of whether its activities constitute regulated conduct in each relevant EU jurisdiction. Serving users in Singapore requires engagement with the MAS Payment Services Act regime. Serving institutional counterparties in the UK raises FCA MLR registration considerations at minimum.

We have seen operators attempt to manage this by routing all user-facing activity through a single offshore entity and treating the VARA entity as an operational back-office. That structure tends to fail on two fronts: VARA expects the licensed entity to conduct the activities it is authorised for in substance, not in form only; and the offshore entity faces its own regulatory exposure in the jurisdictions where users sit. A cleaner approach is an explicit entity map: operating entity A (VARA-licensed) serves the Dubai and GCC market; entity B (MiCA CASP or EU-registered) serves EU users; group IP and technology infrastructure sit in a suitable holding vehicle. The intra-group agreements that bind these entities together are as important as the individual licence applications.

Tax and Banking: The Two Variables That Decide Whether the Structure Holds

A VARA licence application is a structuring exercise, not just a regulatory one, and the two variables that most often determine whether the structure is operationally sustainable are tax treatment and banking access.

On the tax side, the UAE corporate tax regime – introduced in recent years and now applying to businesses operating in the country – means that a Dubai operating entity generating revenue from virtual-asset services is subject to corporate tax in the same way as other businesses. The question of where economic value is created, where management and control sit, and how intra-group fees and royalties are priced is therefore directly relevant to the VARA application. A structure designed to park a licence in a zero-tax entity while substance sits elsewhere will face scrutiny from two directions: VARA, which requires genuine substance in the licensed entity; and the UAE tax authority, which applies transfer-pricing principles to intra-group arrangements. These two pressures reinforce each other. Building genuine regulatory substance in Dubai – a real management team, real decision-making, real infrastructure – is also the foundation of a defensible tax position.

On the banking side, a VARA licence does not guarantee banking access. The UAE banking market for virtual-asset businesses has developed significantly, but it remains selective. Banks in the UAE will typically want to see the VARA licence in place, a clear business model, an AML/KYC programme that meets their own compliance expectations, and evidence of the management team's track record. A Dubai entity that cannot open a bank account cannot operate as a settlement hub regardless of its regulatory status. In our practice, we map the banking angle in parallel with the licence application, not as a downstream afterthought.

CTA #2 – Stalled applications and banking obstacles
If a prior application stalled or an account was closed, a second read can surface the structural reason and the route back. Map your options with OBOLUS.

Which Operator Profile Should Structure How: A Decision Matrix

There is no single correct structure for a VARA application. The right configuration depends on the operator's activity profile, existing group structure, geographic user base, and growth horizon. The following profiles illustrate the key decision branches.

Profile A – A single-jurisdiction exchange start-up with no existing group structure. This operator has the most flexibility. A clean incorporation in Dubai, structured around the specific VARA activity categories required, with adequate own-funds capitalised from the outset, is typically the most efficient path. The key risks are underestimating the activity perimeter and underestimating the timeline to authorisation. This profile should resist the temptation to overbuild the legal structure before the licence is granted: a complex multi-entity group is harder to explain to VARA and generates compliance overhead without corresponding benefit at the early stage.

Profile B – An established crypto business with an existing offshore holding structure applying to add a VARA-licensed operating entity. This is the most common profile we encounter. The risk here is that the existing structure was designed for a different purpose – speed, investment-round flexibility, a prior jurisdiction's licensing requirements – and does not map cleanly onto VARA's substance and governance expectations. The intra-group arrangements need to be reviewed and, in many cases, revised. The capital allocation question is live. IP ownership and licensing needs to be examined. This profile typically benefits from a pre-application structural review before a VARA consultant or local sponsor is engaged, because those advisers will be working on the application itself, not on the underlying group design.

Profile C – A regulated entity in a third jurisdiction (MAS, FCA, or MiCA CASP) looking to add a VARA-licensed hub to serve the GCC market. This profile has the most complexity and, done well, the most potential. The existing regulated entity provides credibility for the VARA application, but it also creates consolidated-supervision questions and potential conflicts between regulatory regimes on topics like AML, Travel Rule data sharing, and client asset segregation. The entity map needs to address not just which entity serves which users but how the two regulatory programmes interact at the operational level. Allied counsel in the relevant jurisdictions need to be consulted on the interaction between the home regime and VARA's requirements.

AML and the Travel Rule Under the VARA Regime

AML/CFT compliance is a threshold requirement for VARA authorisation, not an add-on, and the Travel Rule – the obligation, derived from FATF Recommendation 15, to pass originator and beneficiary data with virtual-asset transfers above the applicable threshold – applies to VARA-licensed entities conducting transfer and settlement activities. The structuring angle here is practical: a business applying for VARA authorisation that has not yet implemented a Travel Rule solution is signalling operational unreadiness to the regulator.

For a multi-entity group, the Travel Rule raises an additional cross-border question. Where transactions flow between a VARA-licensed entity and a MiCA CASP, or between a VARA entity and an unregulated or lightly regulated entity in a third jurisdiction, the Travel Rule obligations on each leg of the transfer need to be mapped. The data-sharing infrastructure – the messaging protocol and the counterparty identification system – needs to function across both entities and both regulatory regimes. This is an operational requirement but it is also a structuring consideration: choosing a Travel Rule protocol that works across multiple regulatory regimes is easier to do before the group is live than after.

Applicants frequently underestimate the AML programme review that VARA conducts as part of the licensing process. The programme needs to be live, not in draft: policies, procedures, a risk assessment specific to the activities to be conducted, a designated MLRO of appropriate seniority and experience, and evidence that the programme has been tested. Groups that arrive at the application stage with a generic AML policy downloaded from a template provider face delays.

A Structuring Problem in Practice: How the Wrong Entity Map Surfaces at the Wrong Time

In a recent cross-border structuring matter, a payments group that had been operating in the GCC under a light-touch offshore registration engaged us to manage its VARA authorisation process. On review of the existing structure, we found that the entity holding client virtual-asset balances was incorporated in a jurisdiction whose regulatory regime did not align with VARA's custody and segregation requirements. Migrating those balances to a new Dubai entity required not only a VARA application but a client notification process, contractual novations and a banking transition managed in parallel. The original structure had been designed by a corporate services provider focused on speed and cost, without regard to the regulatory destination. The remediation timeline extended the operator's launch by several months. We worked with the client to sequence the steps – entity incorporation, banking engagement, AML programme build, and the VARA application itself – so that each dependency was resolved before the next began. The application ultimately succeeded, but the cost of the structural mismatch was real and quantifiable.

A Common Assumption About Offshore Licensing and Why It Fails for VARA

A common assumption among founders and CFOs approaching the GCC market is that a single offshore licence – a BVI FSC registration under the VASP Act 2022, or a Cayman CIMA registration – is sufficient to serve clients globally, including in Dubai. It is not, and VARA's enforcement posture has made that increasingly clear. The VARA regime applies to virtual-asset activities conducted in Dubai and to marketing directed at UAE residents, regardless of where the operating entity is incorporated. An offshore structure conducting VARA-regulated activities in the Dubai market without authorisation is subject to VARA's enforcement powers.

This does not mean that offshore entities have no role in a VARA-centric group structure. A Cayman holding company for investment purposes, or a BVI entity holding IP, may sit legitimately above a VARA-licensed Dubai operating entity. The point is that the offshore entity cannot be the one conducting regulated activities in Dubai. The structuring question is not "offshore versus onshore" but "which entity conducts which activity in which market, and what authorisation does that activity require in that market." Answering that question properly before the structure is built is the work that saves the most time and cost downstream.

The parallel question for operators in the EU is equally sharp: MiCA's passporting regime means that a EU CASP can serve EU users across the EEA, but it does not extend to the UAE. A MiCA-authorised entity serving UAE residents is conducting activities outside its passport scope and needs to consider whether VARA authorisation is required for that market specifically.

Related at OBOLUS

FAQ

How long does a crypto licence take to obtain?

Timeline varies by jurisdiction and activity scope. A VARA authorisation in Dubai typically takes a number of months from submission of a complete application; the process includes a regulatory review of the business plan, governance, AML programme and financial resources. Incomplete applications, structural issues identified during review, or the need to vary activity scope mid-process all extend the timeline. Planning for the full authorisation period before committing to a launch date is strongly advised.

Which jurisdiction is best for licensing my crypto business?

There is no single best jurisdiction. The right choice depends on where your users are, where your banking sits, what activities you conduct, and what your tax position requires. Dubai under VARA is well-suited to GCC-facing businesses with genuine UAE substance; the EU's MiCA CASP regime suits businesses targeting the EEA with passporting benefits; Singapore's MAS regime suits Asia-Pacific operators. In our practice, we assess the full licence, banking, and tax stack before recommending a primary hub, because optimising one variable at the expense of the others produces a structure that cannot operate.

Do I need a separate custody licence?

Under VARA's activity-based regime, custody is a distinct licensed activity. If your business holds client virtual assets – even incidentally, as part of an exchange or transfer function – custody authorisation is likely required in addition to the primary activity licence. The same principle applies under MiCA, MAS, and the ADGM FSRA framework. Whether a single entity can hold multiple activity licences, or whether separate entities are preferable, depends on the capital and governance implications of combining activities – a structuring question that should be addressed before filing.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. We map the licence stack across operating, custody and payment layers before you commit, and we structure licensing, banking and tax as one mandate rather than three disconnected workstreams. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com.

By Lydia Brennan, Tax & Structuring Analyst – specialises in cross-border digital-asset structuring, with a focus on the tax and regulatory interaction in UAE, EU and Asia-Pacific licensing mandates.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours