Guide
How to Set Up a Crypto Custody Provider in the UAE
The short answer
The regulator that decides depends on where the custody business is based and served: the Virtual Assets Regulatory Authority (VARA) in Dubai, the Financial Services Regulatory Authority (FSRA) in ADGM, or the Dubai Financial Services Authority (DFSA) in DIFC. Custody is a licensed virtual-asset activity, not a commercial licence with a crypto description. The one thing that most often decides the route is who holds legal and practical control of the private keys.
Who decides, and why the location matters
Three regulators sit in the sources reviewed for this guide. VARA publishes activity rulebooks for Dubai, and its rulebooks include a Custody Services rulebook. ADGM's FSRA and DIFC's DFSA each run their own regime for crypto activity within their financial centres.
These regimes are separate. A firm authorised in one does not carry that permission into another, and each defines the activity, the applicant and the evidence in its own terms. Choosing the regulator is therefore a business decision about where the entity sits and who its clients are, not a formality after incorporation. A federal route through the Securities and Commodities Authority (SCA) or the Central Bank of the UAE (CBUAE) is outside the sources checked here and needs separate confirmation.
If the plan also includes managing client money in a fund structure, that is a different regulated function. Those considering it might look at setting up a crypto fund or virtual-asset manager as a separate entity.
Key control decides the perimeter
Regulators and bank compliance teams look at what the firm can do, not what it calls itself. In custody the test is practical. Who can initiate, approve and recover a transfer? If the firm, or a vendor acting for it, can move client assets alone, the firm has control, whatever the product page says.
Four situations come up repeatedly:
- A wallet described as non-custodial, where the provider holds recovery powers.
- A technology vendor running multi-party computation (MPC) or hardware security modules, with no map of who holds legal control.
- Staking, lending or reuse of client assets, which needs clear client authority and its own regulatory analysis.
- Sub-custody for another licensed firm, where the contract allocates liability but the authorisation question remains.
The useful output is a written perimeter position: what the company does, what it will not do, which functions sit with licensed firms, and which roadmap features would change the conclusion. An authorisation has to cover the business as it will run, not only the launch version.
What the regulator will want to see
The rulebooks and pages cited below are the authority for the detailed requirements. VARA's Custody Services rulebook, FSRA's virtual-asset framework and the DFSA's crypto-token pages could not be re-read when this guide was last checked, so no figure, deadline or category name is quoted here. Confirm each against the live text before you commit to a structure.
What can be said safely is the shape of the evidence. An authorisation team will look for a coherent file: the business plan, the custody architecture, the people who run it, the financial resources behind it and the compliance framework. Business plans and documentation work is where that consistency is built or lost.
Design choices that change capital and staffing questions should be fixed before the application, not during it:
- Hot, warm, cold or hybrid storage.
- Omnibus or segregated wallets and ledgers.
- MPC, HSM and recovery model.
- Supported networks, tokens and protocol events such as forks and airdrops.
- Insurance and the allocation of liability.
For the Dubai route, the structure of a VARA and virtual-asset setup depends on these answers.
How money and assets move, and what a bank looks at
Banks treat virtual-asset firms as enhanced-due-diligence clients. They want the regulatory story, the flow-of-funds story and the marketing story to match.
For a custodian that means preparing:
- End-to-end key-management documentation.
- A reconciliation and proof-of-assets approach linking legal records to on-chain balances.
- Business continuity and recovery tests.
- Vendor and sub-custodian due diligence.
- The track record of the custody, security and compliance leaders.
Source of funds for the shareholders matters as much as the operating model. Evidence for that is built through source of wealth and funds work, and the account application itself through corporate bank account readiness. Coherence shortens onboarding. It does not guarantee an account.
Ownership, substance and the roles that must be filled
A custody firm cannot be a shell. The customer-facing entity needs the people and systems matched to the functions it performs: senior management, a compliance officer and money-laundering reporting officer (MLRO), and security and technology leadership. The exact roles, residency expectations and financial resources are set by the chosen regulator, so they are stated there, not here.
An overseas parent, an IP company or a special-purpose vehicle can sit beside the licensed entity. A structure designed mainly to show a low setup price reads that way to the authorisation team, and to every bank afterwards. Where the ownership is layered, a wider regulated and complex ownership setup review should come before any filing.
What commonly goes wrong
- Buying a commercial licence first. A trade licence is not virtual-asset permission and does not become one.
- Mapping the vendor, not the control. Relying on a technology provider without writing down who holds legal control of the keys.
- Treating insurance as a control. Insurance supports operational controls. It does not replace them.
- Comparing incorporation fees. The meaningful comparison is the whole route: permitted functions, capital that must be held, mandatory hires, banking realities and the cost of re-papering the structure after launch.
- Bundling functions. Custody, dealing and issuance in one company multiplies governance and conflicts questions.

