Guide
Blockchain Company or VASP? Drawing the UAE Regulatory Line
The short answer
Using blockchain does not automatically make a company a virtual asset service provider. The important facts are whether the business safeguards assets or keys, executes or arranges transactions, operates a venue, manages portfolios, transfers value, lends assets, advises on investments or issues tokens.
The first document to write is not an application; it is an honest description of who touches assets, keys and client money. Map those flows, then separate ordinary company formation from virtual-asset authorisation. The two are routinely confused in this sector, and the confusion is expensive: a commercial licence is not VASP permission and never becomes one. For those looking to establish a crypto exchange setup in UAE, understanding these distinctions is crucial.
Why the operating model comes before the jurisdiction
For virtual-asset businesses, labels are unreliable. The perimeter is shaped by what the business does: whether it takes custody, matches orders, deals as principal, arranges transactions, manages assets, transfers value, issues a token or markets an investment-like product. A crypto custody provider must particularly focus on custody arrangements and compliance.
An entity with a crypto-sounding activity description proves nothing to a regulator, a bank or an exchange counterparty. What matters is whether the firm can evidence fit-and-proper management, financial resources, custody arrangements and compliance staffing for the functions it actually performs. The useful question is not which licence sells fastest. It is which regulated functions the model performs, and what the firm must hold β capital, people, systems β to perform them lawfully. For example, a proprietary crypto-trading company must ensure it meets all regulatory requirements.
Start by choosing which of these models most closely describes the plan:
- Blockchain development with no asset control
- Enterprise ledger or tokenisation software sold to licensed firms
- Non-custodial interface or analytics product
- Business performing one or more regulated virtual-asset services
If more than one model applies, the group may need separate entities or licensed partners for separate functions. Regulators assess each regulated function on its own terms; bundling custody, dealing and issuance into one company multiplies capital, governance and conflicts requirements rather than averaging them. For those considering a crypto broker or otc desk, understanding these distinctions is essential.
Where ordinary company formation may stop
Test these against the virtual-asset perimeter before any jurisdiction or activity is selected:
- Custody or control of virtual assets or private keys
- Exchange, broker-dealer, transfer or settlement activity
- Advisory, management, lending or borrowing services
- Token issuance and distribution
- Marketing into a jurisdiction even when the entity is elsewhere
A hit on this list does not automatically mean authorisation is required β it means the perimeter needs a fact-based assessment. And the label game does not work in reverse: calling the business a technology platform, a proprietary desk or a marketplace does not keep it outside regulation if the customer journey performs a controlled function. Establishing a crypto market-making company involves understanding these regulatory boundaries.
The output should be a written perimeter position: what the company does, what it will not do, which functions sit with licensed partners, and which roadmap features would flip the conclusion. Authority discussions, bank onboarding and counterparty diligence all draw on exactly this analysis.
Structure decisions that change the answer
Before comparing routes β virtual-asset regimes or ordinary commercial licensing β fix the variables that determine capital and staffing:
- Exact customer journey and asset flow
- Control of wallets, keys and smart contracts
- Revenue from software fees versus transaction activity
- Retail, professional or institutional customer focus
- Dubai, DIFC, ADGM or another operating footprint
The customer-facing entity must hold the substance a regulator expects: resident senior management, compliance and MLRO cover, financial resources and systems matched to the licensed functions. SPVs, an IP company or an overseas parent can sit alongside it, but a structure designed mainly to display a low setup price reads as exactly that to an authorisation team, and to every bank after it.
Cost and timeline: use layers, not one headline number
For regulated virtual-asset models, formation fees are the smallest line in the budget. The floor is set by financial resources and mandatory people. Budget in layers:
- Entity formation: registration, constitutional documents, establishment card, workspace and immigration capacity.
- Authorisation: application preparation, legal and compliance advisers, policy suites, business plans, financial models and supervisory fees.
- Regulatory financial resources: paid-up capital or net-asset requirements that must be funded and stay in place β capital is held and monitored, not spent, but it must exist.
- Mandatory people: senior executive, compliance and MLRO, risk and technology roles β some resident, some hired before approval, all on payroll regardless of revenue.
- Recurring obligations: supervision fees, external audit, regulatory reporting, tax filings, licence and registration renewals.
The timeline runs in stages: perimeter classification, structure decision, entity formation, application drafting, regulator review and follow-up questions, conditional approval, operational build-out, launch. Authorisation review moves in regulator time, not applicant time, and a commercial registration date is not a launch date while the authorisation is pending.
Banking, investor and commercial readiness
Banks and institutional counterparties treat virtual-asset firms as enhanced-due-diligence clients by default. Prepare the following before onboarding begins:
- Service and transaction-flow diagrams
- Wallet and key-control analysis
- Regulatory perimeter memorandum
- Customer and geography matrix
- Compliance build plan if authorisation is required
The aim is a file in which the regulatory story, the flow-of-funds story and the marketing story match. Coherence shortens onboarding; nothing guarantees an account, investment or approval, and no serious adviser will say otherwise.
Questions to answer before paying for setup
- Can the company move, block or recover customer assets?
- Does it match, route, negotiate or execute transactions?
- Who deploys and controls each smart contract?
- Is any token issued or promoted?
- Where are users and counterparties located?
Unanswered questions are fine; unrecorded ones are not. Note the assumption and who must verify it, before a formation package decides the perimeter by default.
Common mistakes
- Relying on βnon-custodialβ as a complete legal conclusion
- Obtaining a commercial blockchain activity before analysing services
- Launching marketing before territorial rules are reviewed
- Assuming a technology-provider contract removes all regulatory exposure
And the classic mistake survives: comparing incorporation fees. Compare full routes β year-one and renewal cost, capital held, mandatory hires, permitted functions, banking realities and the cost of re-papering the structure after launch.
What Velarozone assesses
Velarozoneβs adviser-led assessment turns the token, custody and dealing mechanics into a setup decision. Depending on the facts, the written plan can cover:
- Which virtual-asset functions the model performs and which route categories fit them.
- The line between commercial registration and virtual-asset authorisation for this specific model.
- Capital, staffing, custody and banking dependencies that gate launch.
- Cost layers in which held capital and mandatory hires β not formation fees β set the floor.
- Documents, open questions and assumptions requiring specialist confirmation.
- A filing sequence that begins only after the client understands and approves the route.
The final authority shortlist, exact activity selection, current requirements and filing path are confirmed against the live facts. They are decision outputs, not generic website claims.

