The cost of a regulated crypto business is not the licence fee plus minimum capital. A real operating budget must fund the people who govern, monitor, reconcile, secure and report the business after authorisation.
That does not mean every regulated crypto company needs the same large team. It means every required function needs a credible owner, enough capacity and a budget.
Key takeaways
- Model functions before salaries. Compliance, AML, senior accountability, finance, reconciliation, technology and operations create recurring work even where some roles may be combined or outsourced.
- A regulatory role is not automatically one employee. Current VARA rules illustrate that some non-client-facing roles can be combined if conflicts and fit-and-proper requirements are satisfied; generic headcount tables therefore mislead.
- Payroll is operating capital, not regulatory capital. The cash required to employ and support the team belongs in runway planning, while bankability and tax/reporting remain separate workstreams.
The hidden cost is recurring, not one-off
Formation and licensing are visible transactions. Payroll is quieter.
That can distort the first budget. Founders see incorporation fees, application fees, legal advice and minimum capital because those amounts are easy to quote. The cost of maintaining a control environment month after month is harder to compress into a headline.
A regulated business must continue to work after the licence arrives. That means decisions, monitoring, reconciliations, incident handling, reporting, training, vendor oversight and audit evidence all need people behind them.
The useful question is not “How many employees does a crypto licence require?”
It is:
Which functions must operate continuously, who owns each one, and what does it cost to keep them credible?
Start with the regulatory functions
Dubai’s current VARA framework demonstrates the principle clearly.
A VASP must appoint two Responsible Individuals of sufficient seniority. It must have a Compliance Officer meeting specific experience, fit-and-proper, employment, residence and reporting conditions. It must also appoint an MLRO meeting the relevant AML/CFT experience and fit-and-proper requirements.
Those named functions are only the visible part of the operating model.
The rulebooks also create continuing work around risk management, books and records, audit, regulatory reporting, training, client due diligence, transaction monitoring, client money or client virtual assets where applicable, reconciliation and technology controls.
The exact burden depends on the licensed activities. An exchange is not a custody business, and a broker-dealer model is not identical to either.
A function map is better than a headcount table
A generic article that says “you need seven employees” would create false precision.
Current VARA rules expressly allow the Compliance Officer or MLRO to hold more than one non-client-facing role where there is no conflict and the individual remains fit and proper. Activities can also be delegated in certain circumstances while accountability remains with the designated officer.
That means two businesses with the same regulator can organise themselves differently.
The more robust model maps functions first:
- senior regulatory accountability;
- compliance management;
- AML/CFT and suspicious-transaction reporting;
- risk management;
- finance, books and records;
- reconciliation and safeguarding;
- technology and information security;
- customer operations and complaints;
- vendor and outsourcing oversight; and
- regulatory, accounting and tax reporting.
Only then should the business decide which functions require separate employees, which can legitimately be combined and which can be supported externally.
The cheap organisation chart can be expensive in practice
Combining roles can reduce payroll. It can also create concentration risk.
If one person is simultaneously responsible for compliance, AML and risk, what happens during leave, an investigation or a major incident? Who challenges the decision? Who performs the work when transaction volumes double? Does the role combination create conflicts between commercial urgency and control responsibilities?
A lean structure can be excellent when the activity is simple and the people are strong.
The error is to treat the lowest theoretical headcount as the normal operating model.
Regulated staffing should be stress-tested against workload and absence, not only against the wording of an organisational chart.
Finance and reconciliation belong in the people budget
Crypto businesses often focus staffing discussions on compliance because the job titles are regulator-facing.
But finance and reconciliation are just as operationally important.
A company needs reliable books and records. Where it handles client assets or client money, balances and movements need to be reconciled. Management needs financial information. Auditors and regulators need evidence. Exceptions need to be investigated.
Automation can reduce manual work. It does not remove accountability for whether the records are complete and correct.
This is one reason a “licence cost” and a “regulated operating cost” can be very different numbers.
Technology creates human obligations too
A regulated digital-asset business is technology-intensive, but technology does not eliminate staffing.
Cybersecurity, access control, wallet architecture, change management, incident response, data retention and vendor oversight all require decisions and evidence. A third-party custody, analytics or cloud provider can supply infrastructure without becoming the regulated firm’s management.
The more the business outsources, the more important it becomes to know who internally owns the outsourcing relationship and can challenge the provider.
Operational readiness is therefore a combination of systems and people.
Regulatory capital does not pay the payroll twice
This is the financial distinction that matters most.
A regulator may require paid-up capital, own funds, liquid assets, insurance or other prudential resources. Those requirements serve regulatory purposes. The company separately needs cash to fund monthly salaries, recruitment, visas or relocation where relevant, professional support, training and the rest of the operating model.
Some prudential formulas reference operating expenses. That does not transform the prudential amount into a complete runway forecast.
A budget should therefore separate:
regulatory requirement → restricted/liquid resources → recurring payroll and vendors → runway → contingency.
Giving the same cash two jobs is not a financing plan.
Bankability sees the organisation from another angle
A bank does not simply ask whether the VASP has paid its staff.
It may want to know who owns compliance and AML decisions, whether the finance function understands expected flows, whether customer and company assets are distinguishable, how exceptions are handled and whether senior management can explain the business consistently.
A well-designed team can strengthen the bankability case.
It still cannot guarantee onboarding. The bank has its own obligations and risk appetite.
Tax and reporting need explicit ownership
Another hidden payroll problem appears when every obligation is assigned vaguely to “compliance”.
Regulatory reporting, AML reporting, accounting, Corporate Tax, VAT where relevant, CARF/DAC8 and other information reporting can require overlapping data but different legal judgments.
Someone needs to own the data architecture and the filings. Someone needs to reconcile what the regulator, bank, auditor and tax authority are being told.
That work can be supported externally, but the business needs an internal operating model capable of producing consistent facts.
The best objection: automation will shrink the team
It should.
A modern regulated business should automate screening, reconciliations, case management, reporting workflows and evidence collection wherever that improves reliability.
But automation changes the shape of the work more than it eliminates responsibility.
Automated controls require configuration, exception handling, data quality, access governance and periodic testing. When the system produces an alert or fails, a person still needs authority to decide what happens next.
The correct economic question is therefore not “people or software?” It is “what combination produces a reliable control at the lowest sustainable total cost?”
What changed since 2022
In 2022, the market conversation often treated staffing as a late implementation issue. Current regulatory frameworks make it easier to see that people are embedded in the regulated model itself.
VARA’s current rulebooks show both sides of the issue: specific named roles and responsibilities, but also controlled flexibility in combining or delegating some functions.
That is a better planning basis than either extreme—pretending the licence is just a document, or assuming every function requires a separate executive.
The practical consequence
Before comparing jurisdictions or licence packages, build a twelve-to-eighteen-month operating model that answers:
- What regulated functions exist for the exact activity?
- Which functions require named individuals and regulatory approval?
- Which roles can be combined without creating conflicts or capacity problems?
- What work can be outsourced and what accountability remains internal?
- What finance, reconciliation, technology and operations work exists outside the named regulatory roles?
- What is the monthly people-and-vendor cost before meaningful revenue?
- What contingency is required if licensing or banking takes longer?
The payroll is hidden only if the project chooses not to model it.
Sources
- VARA — Company Rulebook
- VARA — Compliance and Risk Management Rulebook
- VARA — Duties of the Compliance Officer
- VARA — Appointment and Duties of Money Laundering Reporting Officer
- VARA — Responsible Individuals
Disclaimer
This article provides general regulatory and business-planning information. It is not a staffing prescription or legal, regulatory, employment, tax, banking or financial advice. Required roles, outsourcing permissions, conflicts rules and operating costs vary by activity and jurisdiction and must be checked against the rules and facts applicable to the business.
