Guide
How to Set Up a Crypto Custody Provider in the UAE
The short answer
Custody turns technical access into a fiduciary and operational responsibility. Regulators and institutional customers will examine who can move assets, how keys are generated and recovered, how client holdings are segregated, how forks and airdrops are treated, and what happens after a cyber or operational failure.
The first document to write is not an application; it is an honest description of who touches assets, keys and client money. Map those flows, then separate ordinary company formation from virtual-asset authorisation. The two are routinely confused in this sector, and the confusion is expensive: a commercial licence is not VASP permission and never becomes one. For those interested in broader crypto ventures, consider exploring how to set up a crypto market-making company in the UAE.
Why the operating model comes before the jurisdiction
For virtual-asset businesses, labels are unreliable. The perimeter is shaped by what the business does: whether it takes custody, matches orders, deals as principal, arranges transactions, manages assets, transfers value, issues a token or markets an investment-like product. For those navigating the regulatory landscape, understanding blockchain business licensing in the UAE is crucial.
An entity with a crypto-sounding activity description proves nothing to a regulator, a bank or an exchange counterparty. What matters is whether the firm can evidence fit-and-proper management, financial resources, custody arrangements and compliance staffing for the functions it actually performs. The useful question is not which licence sells fastest. It is which regulated functions the model performs, and what the firm must hold β capital, people, systems β to perform them lawfully. Those considering investment management might look into setting up a crypto fund or virtual-asset manager in the UAE.
Start by choosing which of these models most closely describes the plan:
- Qualified institutional custody
- Retail hosted wallets
- Technology-only key management without legal custody
- Sub-custody or white-label custody for another licensed firm
If more than one model applies, the group may need separate entities or licensed partners for separate functions. Regulators assess each regulated function on its own terms; bundling custody, dealing and issuance into one company multiplies capital, governance and conflicts requirements rather than averaging them. For those interested in trading, consider how a proprietary crypto-trading company might fit into your strategy.
Where ordinary company formation may stop
Test these against the virtual-asset perimeter before any jurisdiction or activity is selected:
- Legal and practical control of private keys
- Safeguarding and segregation of client assets
- Transfer and settlement functionality
- Staking, lending or other use of safeguarded assets
- Outsourced wallets, MPC and technology dependencies
A hit on this list does not automatically mean authorisation is required β it means the perimeter needs a fact-based assessment. And the label game does not work in reverse: calling the business a technology platform, a proprietary desk or a marketplace does not keep it outside regulation if the customer journey performs a controlled function.
The output should be a written perimeter position: what the company does, what it will not do, which functions sit with licensed partners, and which roadmap features would flip the conclusion. Authority discussions, bank onboarding and counterparty diligence all draw on exactly this analysis.
Structure decisions that change the answer
Before comparing routes β virtual-asset regimes or ordinary commercial licensing β fix the variables that determine capital and staffing:
- Hot, warm, cold or hybrid architecture
- Omnibus versus segregated wallets and records
- MPC, HSM and recovery model
- Supported networks, tokens and protocol events
- Insurance and liability allocation
The customer-facing entity must hold the substance a regulator expects: resident senior management, compliance and MLRO cover, financial resources and systems matched to the licensed functions. SPVs, an IP company or an overseas parent can sit alongside it, but a structure designed mainly to display a low setup price reads as exactly that to an authorisation team, and to every bank after it.
Cost and timeline: use layers, not one headline number
For regulated virtual-asset models, formation fees are the smallest line in the budget. The floor is set by financial resources and mandatory people. Budget in layers:
- Entity formation: registration, constitutional documents, establishment card, workspace and immigration capacity.
- Authorisation: application preparation, legal and compliance advisers, policy suites, business plans, financial models and supervisory fees.
- Regulatory financial resources: paid-up capital or net-asset requirements that must be funded and stay in place β capital is held and monitored, not spent, but it must exist.
- Mandatory people: senior executive, compliance and MLRO, risk and technology roles β some resident, some hired before approval, all on payroll regardless of revenue.
- Recurring obligations: supervision fees, external audit, regulatory reporting, tax filings, licence and registration renewals.
The timeline runs in stages: perimeter classification, structure decision, entity formation, application drafting, regulator review and follow-up questions, conditional approval, operational build-out, launch. Authorisation review moves in regulator time, not applicant time, and a commercial registration date is not a launch date while the authorisation is pending.
Banking, investor and commercial readiness
Banks and institutional counterparties treat virtual-asset firms as enhanced-due-diligence clients by default. Prepare the following before onboarding begins:
- End-to-end key-management documentation
- Reconciliation and proof-of-assets approach
- Business continuity and recovery tests
- Vendor and sub-custodian due diligence
- Experienced custody, security and compliance leaders
The aim is a file in which the regulatory story, the flow-of-funds story and the marketing story match. Coherence shortens onboarding; nothing guarantees an account, investment or approval, and no serious adviser will say otherwise.
Questions to answer before paying for setup
- Who can initiate, approve and recover a transfer?
- How are legal records reconciled to on-chain balances?
- Are assets ever reused, staked or lent?
- Which failures are covered by contract and insurance?
- What services sit around custody?
Unanswered questions are fine; unrecorded ones are not. Note the assumption and who must verify it, before a formation package decides the perimeter by default.
Common mistakes
- Calling a wallet non-custodial when recovery powers exist
- Relying on a technology vendor without mapping legal control
- Using client assets for staking or yield without clear authority
- Treating insurance as a substitute for operational controls
And the classic mistake survives: comparing incorporation fees. Compare full routes β year-one and renewal cost, capital held, mandatory hires, permitted functions, banking realities and the cost of re-papering the structure after launch.
What Velarozone assesses
Velarozoneβs adviser-led assessment turns the token, custody and dealing mechanics into a setup decision. Depending on the facts, the written plan can cover:
- Which virtual-asset functions the model performs and which route categories fit them.
- The line between commercial registration and virtual-asset authorisation for this specific model.
- Capital, staffing, custody and banking dependencies that gate launch.
- Cost layers in which held capital and mandatory hires β not formation fees β set the floor.
- Documents, open questions and assumptions requiring specialist confirmation.
- A filing sequence that begins only after the client understands and approves the route.
The final authority shortlist, exact activity selection, current requirements and filing path are confirmed against the live facts. They are decision outputs, not generic website claims.

