A virtual-asset business expanding into Dubai faces a precise legal question at the outset: which VARA (Virtual Assets Regulatory Authority) activity licence is required to move client funds, and what must the payment and banking layer look like around it? Operating without the correct authorisation under the VARA regime exposes the business to enforcement action, frozen payment rails and the near-certain closure of any UAE bank account that learns of the gap. This page maps the regulated basis for payment-related activity under VARA, the application process, the cross-border interaction with tax and banking, and the decision points that determine whether Dubai is the right hub for your build.
The VARA regulatory basis for payment and transfer activity
VARA is the licensing authority for virtual-asset activity on mainland Dubai, operating under its own rulebooks and distinct from the financial free zones of DIFC and ADGM. Any business that moves, settles, or facilitates the transfer of virtual assets as a commercial service in or from Dubai must hold the relevant VARA activity licence before it operates. The regime is activity-based: the licence authorises a named list of regulated activities, and adding a new activity – such as transfer and settlement after an initial exchange licence – requires a separate approval from VARA.
VARA's activity categories are defined in its published rulebooks. The categories most relevant to a payment or settlement function are the Transfer and Settlement Services licence and, where a platform also holds client assets between transactions, the Custody Services licence. A business that is also quoting prices and matching orders will need the Exchange Services licence in addition. VARA applies the principle that the substance of what the business does determines the licence it needs, not the label the business places on itself.
The VARA regime operates on mainland Dubai only. Businesses structured within the DIFC fall under the FSRA of ADGM's sister free zone, not VARA. This distinction matters for banking: a mainland VARA-licensed entity banks with UAE-licensed commercial banks that have their own virtual-asset customer policies, whereas a DIFC entity operates in a separate legal order. Operators choosing between the two structures should analyse not just the licence but where their banking relationships can actually live.
The Travel Rule (the obligation under FATF Recommendation 15 to pass originator and beneficiary data with a virtual-asset transfer) applies to VARA-licensed transfer and settlement operators. VARA has incorporated Travel Rule compliance into its AML/CFT rulebook requirements. Operators must have a technical and procedural solution in place at the point of licence activation, not as a post-licence project.
Addressing the concern early – Operating without the right licence risks enforcement, frozen rails and lost banking. We have seen businesses reach advanced product stages, sign commercial agreements and open merchant accounts before discovering that the VARA licence required for their transfer function is a separate authorisation from the one they already hold. The cost of that discovery late is always higher than the cost of the analysis early.
To map the licence, banking and tax stack for your Dubai build, write to OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity structure, the user base, the banking – change the analysis.
Who needs a VARA licence for payment and transfer services?
Any business providing virtual-asset transfer or settlement services to UAE-based clients, or operating from a Dubai mainland entity, falls within VARA's regulatory perimeter regardless of where its servers are located. The regulator applies a substance-and-effects test: if the commercial activity is directed at or conducted from Dubai, the licence requirement applies.
The categories of business that routinely require transfer-and-settlement authorisation under VARA include: crypto payment processors facilitating merchant acceptance of digital assets; remittance businesses routing cross-border value via virtual-asset rails; exchanges that operate a built-in settlement or wallet function for withdrawals; and custodians that sweep client funds between internal sub-wallets on instruction. In each case, the common element is the movement of virtual assets on behalf of another person in exchange for consideration.
Two categories frequently misread their position. First, a business that holds a foreign VASP licence – in Lithuania, the BVI, or the Cayman Islands – and directs activity into Dubai is not exempt. VARA's jurisdiction is territorial: the foreign licence is irrelevant to the Dubai requirement. Second, a business that describes its product as a "payment gateway" or a "treasury management tool" does not escape the transfer-and-settlement definition if, in practice, it is moving client virtual assets. The myth that a single offshore licence is enough to serve clients globally is precisely the gap that VARA enforcement addresses.
Operators also need to assess whether any fiat component of their service triggers a separate money-services or payment institution requirement under UAE Central Bank regulation. VARA covers virtual assets; the UAE Central Bank governs fiat payment services. A hybrid business – for instance, one that converts dirhams to stablecoins and remits cross-border – may need authorisation from both bodies. That intersection is one of the most common structural gaps we identify in inbound mandates.
What does the VARA application process involve?
The VARA application process for a transfer-and-settlement licence proceeds in a defined sequence: entity incorporation or conversion on the Dubai mainland, pre-application engagement with VARA, formal submission of the application package, regulatory review, and conditional approval before live operation. The timeline from submission to approval varies by the complexity of the applicant's structure and the completeness of the file; VARA has published indicative processing windows in its guidance, but the actual duration depends on the information it receives.
The application package covers several substantive workstreams. Corporate documentation – constitutional documents, group structure chart, ultimate beneficial owner declarations – forms the base. A detailed business plan, including the intended service scope, target client profile, jurisdictions of operation and revenue model, is required. The AML/CFT framework submission includes the policies, procedures, compliance officer appointment and Travel Rule solution. Technology documentation covers system architecture, security posture, and custody arrangements where applicable.
VARA also requires a Minimum Viable Product assessment for certain activity categories, meaning the business must demonstrate a working or near-working product, not just a concept. This requirement distinguishes VARA's process from lighter-touch registration regimes and means that early-stage businesses should plan their regulatory timeline around their product readiness, not only their legal readiness.
A minimum capital threshold is set by VARA for each activity category and is stated in the relevant rulebook. Because VARA updates its rulebooks and fee schedules periodically, any capital or fee figure cited at the planning stage must be verified against the current published version before the application is submitted. We do not state the current figures here; we verify them directly with the regulator as part of the scope of each engagement.
Post-approval, the operator receives a conditional licence that becomes a full licence on satisfaction of named conditions – typically the completion of a technology audit, proof of capital injection, and confirmation of the AML officer's appointment. Operating before satisfaction of those conditions is a breach of the licence terms and triggers VARA's enforcement powers.
In a recent licensing matter, a payments company incorporated in a free zone sought to move its transfer-and-settlement function to the Dubai mainland to access local banking. We advised on the structural conversion, prepared the full application package including the AML/CFT framework and Travel Rule documentation, and managed VARA's information requests through the review period. The conditional licence was granted within the regulator's published indicative window, and the capital condition was satisfied before the client's commercial launch date.
How do banking and fiat rails work alongside a VARA licence?
Holding a VARA licence significantly improves a business's banking position in the UAE but does not guarantee account approval. UAE commercial banks have their own onboarding criteria for virtual-asset customers and apply those criteria independently of VARA's authorisation decision. A licensed entity that approaches a bank with an incomplete compliance framework, an unclear source-of-funds narrative, or a client profile that the bank's own risk appetite does not cover will still face rejection.
The practical banking picture for a VARA-licensed transfer-and-settlement operator involves two layers. The first is the operational account – the business's own dirham and dollar accounts for expenses, payroll and treasury. This layer is relatively accessible for a licensed entity with a clean compliance framework. The second is the client-money or settlement account, where the operator holds or passes client funds in connection with the licensed service. This layer attracts the highest level of bank scrutiny, because the bank is effectively becoming part of the payment chain for virtual-asset flows.
The EMI onboarding (the process of connecting a business to an electronic money institution for fiat rails) is a parallel workstream to the VARA licence application. EMIs licensed in the EU – under MiCA and the Payment Services Directive framework – and in the UK – under the FCA – do service UAE-licensed entities, but each EMI applies its own geographic and sector risk policy. We regularly advise clients on which EMI profiles are appropriate given the business model, the client base and the stablecoin or token flows involved, and we manage the KYB submission as part of the same engagement as the VARA licence work.
Stablecoin flows introduce a specific banking sensitivity. Banks and EMIs that see USDT or USDC flows treat them differently from tokenised assets or exchange tokens. The business model narrative to a banking partner must explain the stablecoin function clearly – whether it is a settlement layer, a client-held balance, or a conversion instrument – and must address how the operator monitors the sanction exposure of those flows. VARA-licensed operators with stablecoin functions will typically face a more detailed bank onboarding process than those with pure fiat operations.
If your fiat rails are stalled or your banking application has been declined, contact OBOLUS at info@oboluslaw.com to assess the structural reason and the route forward. If a prior application stalled or an account was closed, a second read can surface the structural reason and the route back.
What is the tax position for a VARA-licensed payment operator?
The UAE imposes no personal income tax, and the corporate tax regime introduced in recent years applies at a relatively low rate to qualifying income, with a free-zone exemption track that may be relevant depending on the operator's structure. For a mainland VARA-licensed entity, the applicable corporate tax rules and the interaction with the free-zone exemption need to be assessed against the substance-and-activity profile of the business, not assumed on the basis of general commentary.
VAT applies in the UAE at the standard rate to most financial services where the supply is explicitly taxable. The VAT treatment of virtual-asset transfer and exchange services in the UAE has been addressed in regulatory guidance, but the position should be verified against current FIRS and Federal Tax Authority publications for each activity type before the business model is finalised. Crypto businesses that also supply fiat payment processing, advisory services or software-as-a-service functions need a VAT analysis of each supply line separately.
Cross-border structuring questions arise when a VARA-licensed UAE entity is part of a group with entities in other jurisdictions – for instance, a BVI holding company, a Singapore operating entity, or a Cayman fund. Transfer pricing, the permanent-establishment question in each jurisdiction where the UAE entity contracts with customers or partners, and the interaction between the UAE's tax treaty network and the home jurisdiction of the ultimate beneficial owner are all live issues that must be addressed at the structuring stage. We advise on the full cross-border structure as one workstream rather than treating the UAE licence as an isolated exercise.
Economic substance requirements also apply in the UAE context. A VARA-licensed operator that performs its core income-generating activity from Dubai must demonstrate genuine physical and management presence. An entity that holds a Dubai licence but directs its operations entirely from another country risks both regulatory challenge and substance-related tax exposure. VARA's own minimum viable product and key-person requirements serve as a partial check on this, but the tax-substance analysis is broader than the regulatory one.
How does the Dubai VARA regime compare for an inbound operator?
Dubai's VARA regime occupies a specific position among the leading virtual-asset licensing hubs. It is more demanding in product-readiness terms than Lithuania's MiCA-transition registration track and more flexible in commercial scope than Singapore's MAS Payment Services Act tiers. For a business that has a working product and wants a hub that gives it access to Gulf capital, Middle Eastern institutional clients, and a zero-personal-tax environment for its key employees, Dubai is highly competitive.
The comparison against ADGM within the UAE itself is often the first structural question for inbound operators. ADGM under the FSRA offers a common-law jurisdiction with English-language courts and a recognised virtual-asset framework aimed at institutional and professional counterparties. VARA on the mainland reaches a wider retail and commercial audience and offers greater flexibility for exchange and transfer services directed at a broad client base. The choice between the two turns on the client profile, the banking relationships already in place, and whether the operator values the DIFC legal order for dispute resolution.
For an operator already licensed under MiCA in the EU, Dubai can function as the hub for non-EU activity – specifically for serving clients in the Gulf, Africa and South and Southeast Asia where the MiCA passport does not run. The structural question is how to manage the inter-entity flows between the EU CASP entity and the VARA entity without triggering either entity's regulatory perimeter in the other jurisdiction. That analysis is jurisdiction-specific and must be done before the structure is committed.
Decision framework in brief: an operator with a working transfer-and-settlement product, a Gulf or MENA client focus, and a preference for local banking relationships should look closely at the mainland VARA licence. An operator whose clients are primarily institutional, whose product is asset management or structured finance, and whose priority is an English common-law legal order should evaluate ADGM first. A business serving primarily EU retail clients with an eye to passporting should begin with MiCA authorisation and consider Dubai as a second-hub expansion.
Related at OBOLUS
- Banking, Payments & EMI Onboarding for digital-asset businesses – How OBOLUS structures the banking and payment layer for licensed operators across hubs.
- EMI onboarding for VASPs in Malta – The EU-based EMI pathway for MiCA-transition entities seeking fiat rails.
- DeFi protocol legal structuring in Canada – Cross-border structuring considerations for decentralised-finance operators seeking a regulated presence.
Self-assessment checklist before applying for a VARA payment licence
Before submitting to VARA, a business should be able to answer each of the following questions affirmatively. A gap in any of them will delay or prevent approval.
- Is your entity incorporated on the Dubai mainland, and does it have a physical office address in Dubai?
- Have you identified the exact VARA activity categories that your business model requires, and confirmed there are no additional categories you have overlooked?
- Do you have a compliance officer with relevant AML/CFT experience appointed and available to engage with VARA during the review?
- Is your Travel Rule solution selected, tested and documented, including your approach to unhosted wallets?
- Have you prepared a business plan that addresses your target client profile, geographic scope, revenue model and key risk controls?
- Have you verified the current minimum capital requirement for your activity categories and confirmed you can evidence the required capital at the point of application?
- Have you assessed whether your fiat component requires separate UAE Central Bank authorisation alongside the VARA licence?
- Have you identified your target banking partner and begun the onboarding conversation in parallel with the licence application?
A common assumption among inbound operators is that the VARA application is primarily a corporate-documentation exercise. In practice, the AML/CFT and technology-readiness workstreams are the most time-consuming and the most likely to generate information requests. Starting the compliance and tech documentation in parallel with the corporate setup, rather than sequentially, typically shortens the overall timeline by several weeks.
FAQ
Why do banks close crypto company accounts?
Banks close virtual-asset company accounts primarily because of perceived compliance risk, not legal prohibition. The most common triggers are: the absence of a local regulatory licence, an unclear source-of-funds narrative, unexplained stablecoin or high-volume crypto flows, and a mismatch between the declared business activity and the actual transaction pattern. A VARA-licensed operator with a documented AML framework, a clear client-money policy and an account-opening narrative that matches the licence scope materially reduces each of those triggers – but does not eliminate them. Banking is a separate risk-appetite decision by each institution.
How can a VASP onboard with an EMI?
A VASP (virtual asset service provider) seeking fiat rails through an EMI (electronic money institution) must satisfy the EMI's own KYB process, which typically requires: the regulatory licence or registration from the relevant authority, a full AML/CFT policy pack, an explanation of the stablecoin or crypto flows the EMI will see, the ultimate beneficial owner profile, and financial projections. EMIs vary significantly in their appetite for crypto clients. Matching the VASP's activity profile to the right EMI – by sector, by geography, and by transaction type – before submitting is the single factor most correlated with a successful onboarding outcome.
What does client-money safeguarding require?
Client-money safeguarding requires that assets held on behalf of clients are segregated from the operator's own funds and protected against the operator's insolvency. Under the VARA regime, the specific safeguarding obligations depend on the activity licence held and are set out in the relevant VARA rulebook. For operators also holding fiat client money – whether directly or through an EMI – the safeguarding rules of the EMI's home regulator (for instance, the FCA in the UK or the applicable national competent authority under the EU Payment Services framework) will also apply. A VARA-licensed operator must have its safeguarding structure reviewed against both the VARA rules and the rules of any fiat-payment partner before it accepts client funds.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We structure licensing, banking and tax as one mandate rather than three disconnected workstreams – mapping the licence stack across operating, custody and payment layers before you commit capital. To discuss your situation, contact info@oboluslaw.com or message us at t.me/oboluslaw.
By Victor Olsen, Regulatory & Compliance Analyst – specialising in VARA licensing, MiCA CASP authorisation and cross-border virtual-asset regulatory strategy for payment and exchange operators.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.