Guide
How to Set Up an RWA Tokenisation Platform in the UAE
The short answer
The regulator is chosen by where the token is issued and offered, not by where the company is incorporated. Dubai's Virtual Assets Regulatory Authority (VARA) covers issuance in Dubai. The Dubai Financial Services Authority (DFSA) in DIFC and the Financial Services Regulatory Authority (FSRA) in ADGM each run their own regimes for tokenised instruments. What decides the route most often is the legal right the token represents: a debt claim, a fund interest and a fractional property share are different instruments, with different regulators asking different questions.
Where the perimeter sits and who decides
Tokenisation does not remove the legal work attached to an asset. It makes that work visible. A regulator will want to know what one token confers, who holds title to the asset, how a holder enforces or redeems, and whether the token is a security, a fund interest, a payment token or something else.
Three regimes are in play, and each is published by its own authority:
- Dubai: VARA publishes a Virtual Asset Issuance Rulebook within its wider rulebooks.
- DIFC: the DFSA publishes a Tokenisation Regulatory Sandbox.
- ADGM: the FSRA supervises regulated activity, and ADGM publishes its DLT Foundations framework.
The three pages above could not be re-read for this update, so the detail of each regime (eligibility, approval steps, fees) is not stated here. Confirm it against the regulator before relying on it.
If the model also touches securities offered onshore, the federal securities position has to be established as well. Do that analysis before choosing an entity.
What the token confers, and which record is legal
Fix these variables before comparing routes, because they decide which functions the business performs:
- Right conferred: direct title, beneficial interest, contractual claim or fund unit.
- Register: whether the on-chain record or an off-chain register is the legal record of ownership.
- Distribution: public, private or professional-investor only.
- Roles: issuer, asset owner, SPV, servicer, custodian and platform operator, and which of these sit in the same company.
- Exit: redemption, enforcement and default mechanics.
If more than one model applies, separate entities or licensed partners for separate functions are usually cleaner than one company doing everything. Bundling custody, dealing and issuance into one firm raises the governance and conflicts burden rather than averaging it. The same logic applies if you are weighing a crypto broker or OTC desk or crypto market making alongside the issuance business. Those are separate functions with separate tests.
Substance and the roles that must be filled
The entity facing investors needs resident senior management, compliance and money-laundering reporting cover, and systems that match the functions it performs. SPVs, an IP company or an overseas parent can sit beside it. A structure built to display a low setup price will read as exactly that to an authorisation team and, later, to a bank.
Capital and mandatory hires are where the cost sits. The figures are set by the regulator for the specific activity, so they are not quoted here. Where a regime requires paid-up capital or named roles, those must exist and stay in place whether or not the platform has revenue. The wider VARA and virtual-asset setup work and the regulated and complex ownership setup route are built for this stage.
Cost is built in layers, and the firm's fee is itemised in the engagement letter; how Velarozone works sets out the approach.
How money moves and what a bank looks at
Banks and institutional counterparties treat virtual-asset firms as enhanced-due-diligence clients. For tokenisation the file has to show one story in three places: the legal rights, the flow of funds and the marketing.
Prepare these before onboarding starts:
- A diagram of legal rights and cash flows, from investor payment to asset to redemption.
- The asset due-diligence and valuation policy.
- A draft term sheet and disclosure framework.
- A technology control and smart-contract audit plan.
- A map of licensed partners wherever a function is outsourced, such as custody or escrow.
Decide early where investor money sits between payment and issuance. A licensed escrow institution or a VARA-licensed desk is a better answer than the operating account, and the regime for the activity says what is required. Evidence of where capital and investor funds come from is part of the same file, and source of wealth and funds work gets ready before the bank asks. Corporate bank account readiness covers the account itself. Nothing guarantees an account, an investment or an approval.
What commonly goes wrong
- Tokenising a story, not a right. If a holder cannot enforce anything against anyone, the token is a marketing device and a regulator will treat it as one.
- Assuming an SPV gives bankruptcy remoteness. It does so only if the documents and the asset transfer are built to achieve it.
- Adding secondary trading late. A transfer or matching feature turns an issuance platform into a venue question. Roadmap features count at authorisation.
- Forgetting servicing. Valuation, disclosure, payment of income and handling of default continue long after the token sale.
- Comparing incorporation fees. Compare complete routes: year-one and renewal cost, capital held, mandatory hires, permitted functions and the cost of re-papering after launch.
- Promoting without care. Where a virtual-asset offering is marketed in Dubai, VARA's Marketing Regulations apply. Promotional material must match the authorisation and the risk position. Virtual assets are volatile, and investors can lose all or part of their money.
A written business plan and supporting documentation pack that records these answers is what authority discussions, bank onboarding and counterparty diligence all draw on. Fintech-led models may also fit the fintech setup route.

