VARA Licence Application for Institutional Clients
Operating a digital-asset business in Dubai without the right authorisation does not merely delay revenue – it exposes the enterprise to enforcement action, frozen banking rails and reputational damage that institutional counterparties find difficult to overlook. The Virtual Assets Regulatory Authority (VARA) – Dubai's dedicated regulator for virtual-asset activity on the mainland – operates an activity-based licensing regime that distinguishes sharply between advisory, custody, exchange and lending functions. For an institutional operator, getting that distinction wrong at the application stage costs months and, in some cases, forces a structural rebuild. This page sets out the regulated basis, the application process, the cross-border pressures and the common mistakes we see in VARA mandates handled for institutional clients.
What does the VARA regime actually regulate?
VARA authorises specific virtual-asset activities, not entities as a whole – meaning an institutional operator that provides custody and exchange services in the same legal vehicle requires authorisation across both activity categories under the VARA rulebooks. That architecture is deliberate: it mirrors the approach regulators in Hong Kong and Singapore have taken under the SFC's VATP licensing regime and the Monetary Authority of Singapore's Payment Services Act respectively. The consequence for a multi-function institutional platform is that the scope of the application – and the compliance infrastructure behind it – must map to every activity the entity actually performs, not to the narrowest description counsel can construct.
Under the VARA regime, regulated activities span at minimum advisory services, broker-dealer execution, custody, exchange operation, lending and borrowing, management and investment, and transfer and settlement services. An institutional client – a proprietary trading desk, a regulated fund manager, a custody provider serving other institutions – will typically touch two or more of those categories from day one. The VARA rulebooks that govern each activity carry distinct requirements around governance, systems controls, client-asset segregation and reporting. Treating the application as a single filing, rather than as a matrix of activity-specific obligations, is the single most common structural error we encounter.
It is equally important to note that VARA's jurisdiction covers mainland Dubai. The Dubai International Financial Centre (DIFC) operates as a separate financial free zone with its own regulatory perimeter. An entity domiciled in the DIFC is not authorised to conduct VARA-licensed activity on the mainland without appropriate recognition or a separate authorisation. Institutional operators building a UAE presence often need to resolve this geography question before the application even begins.
For a scoped assessment of where your activities sit within the VARA perimeter, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity structure, the user base, the banking relationships and the activity mix – change the analysis materially. Map your options
Who needs VARA authorisation as an institutional operator?
Any entity conducting virtual-asset activities in or from Dubai's mainland, whether for institutional or retail counterparties, falls within VARA's regulatory perimeter. For institutional operators specifically, the relevant profiles include: fund managers and trading firms executing proprietary or third-party digital-asset strategies; custodians holding virtual assets on behalf of institutional clients; platforms providing OTC execution, prime brokerage or structured lending to institutional counterparties; and entities operating infrastructure – order-matching engines, settlement rails – that connects institutional participants.
The institutional client profile also intersects with the FATF Recommendations, including FATF Recommendation 15, which brings virtual-asset service providers into the anti-money-laundering and counter-financing-of-terrorism framework. VARA's AML/CFT requirements reflect that international baseline. An institutional operator that has already built an AML programme for a jurisdiction such as Singapore or the UK will recognise the architecture – customer due diligence, enhanced due diligence for high-risk counterparties, transaction monitoring, the Travel Rule obligation to pass originator and beneficiary data alongside a transfer – but the VARA-specific implementation details require careful calibration.
In our cross-border practice, we regularly advise operators who assume their existing AML infrastructure from another jurisdiction can be transplanted directly into a VARA application without adjustment. That assumption almost always proves incorrect. VARA's rulebooks carry specific governance expectations – including the appointment of a UAE-resident compliance officer and, for certain activity categories, a UAE-resident senior executive – that require local substance, not simply a policy reprint.
What does the VARA application process look like in practice?
The VARA application process follows a structured multi-stage pathway that begins well before the formal submission and continues through a period of regulatory dialogue before authorisation is granted. Understanding the full arc – not just the submission gate – is essential for institutional operators who are managing investor timelines or commercial launch commitments.
At a high level, the process moves through the following stages. First, a pre-application phase: the operator must define the activity scope, establish the legal entity in Dubai, and build the governance and compliance architecture that VARA expects to see at submission. This phase is often underestimated. VARA expects institutional applicants to demonstrate substance – a functioning UAE entity, appointed senior personnel, and documented policies – before the formal review begins. Operators who attempt to assemble this infrastructure in parallel with the regulatory review routinely face requests for information that reset the clock.
Second, the formal application submission: VARA requires a comprehensive application package covering the business plan, financial projections, ownership and control disclosures, AML/CFT policies, technology infrastructure descriptions and key personnel fit-and-proper information. For an institutional operator with a complex group structure, the ownership and control disclosure alone can be an exercise requiring significant coordination across holding entities, ultimate beneficial owners and institutional investors.
Third, regulatory review and dialogue: VARA engages with applicants during the review period, issuing queries and requesting supplementary materials. This phase requires a team capable of responding promptly and with precision – slow or imprecise responses extend timelines. The overall authorisation timeline varies by activity category and application quality; it is measured in months rather than weeks for institutional applicants.
Fourth, conditions of authorisation: VARA typically imposes conditions on newly authorised entities that must be satisfied before full operational deployment. Understanding and managing those conditions – and building them into the operational launch plan – is a step that institutional operators occasionally treat as an afterthought.
What mistakes do institutional applicants most commonly make?
The most consequential error in a VARA application for institutional clients is scoping the licence too narrowly relative to the actual business model. An operator that structures its initial application around a single activity to minimise the regulatory burden, then expands operations to adjacent activities post-authorisation, faces a variation process that can be as demanding as a fresh application. VARA expects the application to reflect the genuine intended business from the outset.
A second common error is underestimating the local-substance requirements. VARA is explicit that certain senior roles must be filled by UAE residents with demonstrable expertise. Institutional operators that plan to manage their Dubai entity remotely from a London or Singapore headquarters – appointing a nominal local director while the real decision-makers remain offshore – will encounter friction during the fit-and-proper assessment and may face conditions that require a structural response.
A third error is treating the technology-infrastructure disclosure as a compliance formality. VARA's rulebooks carry specific expectations around cybersecurity, system resilience, custody technology and client-asset segregation. For an institutional operator handling significant assets under custody, the technology and controls section of the application carries as much weight as the governance and financial sections. We have seen applications materially delayed because the technical submission did not align with the operational architecture the applicant had already built.
Finally, institutional operators frequently underestimate the AML/CFT programme requirements at the VARA level. A programme built for MiCA's CASP authorisation in the EU or for FCA registration in the UK shares architectural similarities, but the VARA-specific calibration – including the Travel Rule implementation requirements and the specific CDD thresholds – requires a bespoke build, not a translation of an existing manual.
If a prior application stalled or a regulatory query went unanswered, a structured review can identify the gap and the route back. Write to OBOLUS at info@oboluslaw.com. We have advised operators at every stage of the application cycle, including on remediation of submissions that had already been returned with significant queries. Map your options
How does the VARA licence interact with a cross-border group structure?
For most institutional operators, the VARA authorisation is one component of a multi-jurisdiction licensing stack, not a standalone answer. An institutional platform serving clients in the EU must also contend with MiCA's CASP authorisation framework, administered by ESMA and the relevant national competent authorities, which imposes its own capital, governance and whitepaper obligations. A platform with Singapore-based counterparties operates under the MAS Payment Services Act regime. A custody provider with UK clients must address FCA registration under the Money Laundering Regulations, as well as the FCA's financial-promotion rules as they apply to crypto-asset communications.
The interaction between these regimes creates a structuring question that cannot be resolved by simply stacking licences. The entity that holds the VARA authorisation, the entity that contracts with EU clients under MiCA, and the entity that holds assets in custody in a common-law jurisdiction like the Cayman Islands or the BVI – subject to CIMA's VASP licensing rules and the BVI FSC's VASP Act 2022 respectively – may or may not be the same legal person. Getting that entity architecture wrong means that the VARA licence authorises an activity the contracting entity does not perform, and vice versa.
In our cross-border practice, we map the licence, entity, banking and tax stack as an integrated design exercise before any application is filed. The banking question is particularly acute for Dubai: institutional operators often discover that the banking relationships they assumed would follow a VARA authorisation require separate diligence and, in some cases, a different entity structure than the one the licence application has been built around. We have seen operators complete a VARA application only to find that their intended banking partner requires specific structural features – reserves held in a regulated jurisdiction, a particular entity type – that the approved structure did not anticipate.
The cross-border tax dimension is equally material. A Dubai entity benefits from the UAE's corporate-tax environment and its treaty network, but the interaction with the home-country tax position of the institutional investors or the operating group requires analysis that sits alongside the licensing work, not after it. We structure licensing, banking and tax as one mandate rather than three disconnected workstreams.
Which operator profile fits which VARA authorisation pathway?
Institutional operators do not present a uniform profile. The appropriate VARA authorisation strategy – the activity categories to include, the entity structure to adopt, the phasing of compliance build-out – differs materially depending on what the operator actually does and where its institutional clients sit.
Profile A – Institutional custody provider: An entity whose primary function is holding virtual assets on behalf of institutional clients will centre its application on the custody activity category under VARA. The key risk at this profile is the client-asset segregation and technology-controls expectation, which is demanding and requires early investment in the infrastructure narrative. The timeline for a well-prepared single-activity custody application is typically measured in a small number of months; inadequate preparation can extend that materially. The cross-border note: if the custodian also serves clients under MiCA or the MAS regime, the segregation architecture must be designed to satisfy multiple regulators simultaneously.
Profile B – Institutional exchange or OTC platform: A platform providing exchange or broker-dealer services to institutional counterparties faces a broader activity scope under VARA. The business-plan disclosure requirement is more detailed, the financial-projections section more scrutinised, and the AML/CFT programme more intensively reviewed given the transaction-monitoring obligations on an exchange. Timeline expectations are longer than for a single-activity application. The key risk at this profile is the technology-infrastructure disclosure – order management, matching engine resilience and market-surveillance controls each carry distinct expectations.
Profile C – Multi-function institutional platform: An operator combining custody, exchange and lending functions for institutional clients requires authorisation across multiple activity categories from the outset. This is the most complex VARA application profile and requires the most comprehensive pre-application build. The timeline is measured in several months for a well-resourced applicant. The key risk is internal consistency – the compliance and governance architecture must be demonstrably coherent across all activity categories, and regulators will probe for gaps or conflicts between activity-specific policy sets.
How we handle a complex multi-activity VARA mandate
In a recent licensing matter, an institutional operator with an existing presence in a major Asian financial centre engaged us to structure and file a VARA application covering exchange, custody and management activities. The client had assumed that its MAS-compliant AML/CFT programme could be adapted with minimal changes. Our review identified three structural gaps: the programme did not address VARA's specific Travel Rule implementation expectations, the technology-controls disclosure was drafted at a level of abstraction that would not survive VARA's review, and the proposed compliance officer did not meet VARA's UAE-residency requirement. We restructured the application package, sourced appropriate local senior personnel through our UAE network, and rebuilt the technology narrative to align with the rulebook expectations for each activity. The application was submitted without a pre-submission return and proceeded through the regulatory-dialogue phase without a material reset.
A self-assessment checklist before you file
Before an institutional operator files a VARA application, the following questions should have clear, documented answers. If any are uncertain, the application is not ready.
- Is the Dubai legal entity incorporated and in good standing, with a bank account or a clear banking pathway?
- Have all activity categories that the business will actually perform been identified and included in the scope?
- Are UAE-resident senior personnel appointed for the roles VARA requires to be filled locally?
- Does the AML/CFT programme address VARA's Travel Rule requirements and CDD expectations specifically?
- Has the technology infrastructure – custody technology, order management, cybersecurity controls – been documented at a level of specificity that will withstand regulatory review?
- Has the group ownership and control structure been fully documented, including ultimate beneficial owners and institutional investors above the relevant disclosure threshold?
- Has the cross-border licence stack – MiCA, MAS, FCA or other regimes where the operator has clients – been reviewed for interaction with the VARA structure?
- Has the banking and tax architecture been designed alongside the licence structure, not after it?
This checklist is not exhaustive. Each institutional operator presents a distinct fact pattern, and the pre-application analysis should be calibrated to that pattern rather than to a standard template.
Related at OBOLUS
- Licensing & Registration for Digital Asset Businesses – the full licensing practice overview across 70+ jurisdictions
- Crypto Regulation and Licensing in the British Virgin Islands – BVI VASP Act 2022 and the offshore structuring angle
- VARA Licence Application for Regulated Entities – the parallel service page for already-regulated operators entering Dubai
About OBOLUS
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit – and we structure licensing, banking and tax as one mandate rather than three disconnected workstreams. To discuss your situation, contact info@oboluslaw.com or message us at t.me/oboluslaw.
To pressure-test your VARA application structure before you commit, message OBOLUS via t.me/oboluslaw or write to info@oboluslaw.com. Map your options
FAQ
How long does a crypto licence take to obtain?
Timeline varies by jurisdiction and application quality. Under the VARA regime, a well-prepared single-activity application is typically measured in a small number of months; multi-activity institutional applications take longer. In other hubs – MAS in Singapore, the SFC in Hong Kong, MiCA-CASP authorisation in the EU – timelines similarly range from several months to over a year depending on complexity. Incomplete applications or slow responses to regulatory queries extend every timeline. Early pre-application preparation is the most reliable way to compress the authorisation window.
Which jurisdiction is best for licensing my crypto business?
No single jurisdiction is objectively best. The right choice depends on where your clients are, the activities you perform, your banking options and your tax position. Dubai under VARA suits operators seeking a mainstream-finance-adjacent hub with institutional credibility. Singapore and Hong Kong serve Asia-Pacific-oriented businesses. EU CASPs need MiCA authorisation. Offshore structures – BVI, Cayman – work well for funds and holding layers but rarely satisfy the full licensing requirement for active trading or custody platforms. A decision based on the narrowest licence path often creates compliance gaps elsewhere.
Do I need a separate custody licence?
In most leading jurisdictions, custody of virtual assets is a separately regulated activity requiring its own authorisation or an express inclusion in an existing licence. Under the VARA regime, custody is a distinct activity category with specific client-asset segregation and technology-controls requirements. Under MiCA, crypto-asset custody and administration is a defined CASP service. An operator that holds client assets without the appropriate custody authorisation – even incidentally to a primary activity like exchange operation – risks operating outside its licence perimeter. The answer requires a review of the actual asset-holding arrangement, not just the primary business description.
By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in VARA, MiCA and multi-jurisdiction licence stack design for institutional digital-asset operators.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.