The central mistake in many crypto projects is to treat the licence as the project. It is not. A licence answers a legal question: may this entity carry on these regulated activities under these conditions? A functioning regulated business must answer several additional questions about people, governance, capital, controls, technology, banking and tax or reporting obligations.
That distinction was already important in 2022. It is clearer now because mature regimes increasingly make the operating model visible inside the licensing process itself.
Key takeaways
- Permission is not an operating model. Authorisation does not create the people, systems, governance or control environment needed to run the business.
- Capital has several jobs. Regulatory capital, liquidity requirements and the cash required to finance payroll and runway are related but different questions.
- Banking and tax remain separate gates. A regulator can authorise an activity without obliging a bank to onboard the firm or determining its tax and reporting position.
What a licence actually answers
Regulated crypto businesses begin with perimeter analysis. What activity will the firm actually perform? Where will it be performed? For whom? Will the firm exchange, broker, custody, lend, advise, manage assets, transfer virtual assets or issue them?
Those facts determine whether an authorisation is required and which regulator or rulebook applies. They also determine what the authorisation does not say.
A licence does not establish that the business has enough runway. It does not promise a bank account. It does not decide the tax residence of the company or its founders. It does not prove that the operating team can deliver the service safely. And it does not eliminate continuing AML, accounting, reporting or supervisory obligations.
The useful sequence is therefore:
activity → perimeter → entity → people and governance → capital → controls and systems → authorisation → banking and operational launch → continuing compliance.
The exact order can overlap in practice, but the dependencies cannot simply be skipped.
The operating business behind the permission
Dubai’s current VARA process makes the distinction unusually visible. For a new firm, VARA describes a two-stage process. The first stage can lead to an Approval to Incorporate, allowing the firm to complete legal incorporation and operational setup, including office space and employee onboarding. VARA expressly states that the firm may not carry on Virtual Asset activities at that point. The full VASP Licence comes later and may itself be subject to operational conditions.
That process is not a universal template for every jurisdiction. It is evidence of a broader principle: regulation attaches to a real operating system, not merely to a certificate.
VARA’s application material asks for information such as beneficial owners, senior management, organisational structure, governance, financial projections, paid-up capital, insurance, succession and wind-down planning. Different regulated activities then bring their own rulebooks and controls.
In practical terms, a credible regulated business needs to know who owns each control, who can move client or company assets, who can approve exceptions, who investigates unusual activity, who reconciles records, how incidents are escalated and what happens if a critical person or provider becomes unavailable.
Policies matter, but only if there is an operating reality behind them.
People and governance are not paperwork
A business plan can be drafted quickly. A qualified person cannot necessarily be created on demand.
Regulated roles can involve experience requirements, fit-and-proper assessment, independence, residency or full-time expectations, depending on the regime and function. A board or senior management team must also understand what it is actually supervising.
This is why the people plan belongs near the beginning of a regulated project. If a firm needs a compliance officer, MLRO, responsible individuals, risk ownership or specialised technology oversight, those dependencies affect cost and timing before the application is complete.
The strongest governance question is not whether the organisational chart looks correct. It is whether responsibility, authority and evidence line up in practice.
Regulatory capital is not runway
The word “capital” creates another source of confusion.
A regulator may require paid-up capital, own funds, prudential safeguards, liquid assets, insurance or other financial resources. Those requirements have regulatory purposes. The business still needs cash to pay salaries, technology providers, auditors, legal and compliance costs, premises, insurance, data services and other operating expenses while revenue is uncertain or delayed.
The distinction is explicit in current frameworks. VARA requires VASPs to maintain Net Liquid Assets worth at least 1.2 times monthly operating expenses. MiCA uses a different prudential architecture for crypto-asset service providers: Article 67 requires safeguards equal to at least the higher of the applicable permanent minimum capital amount and one quarter of the previous year’s fixed overheads, with a projected-overheads rule for new firms.
Neither formula is a business cash-flow forecast.
A founder therefore needs at least two models: what the regulator requires to remain compliant and what the company needs to survive and execute its plan.
Bankability is a separate decision
Banking is where the difference between legal permission and commercial operability becomes most obvious.
A bank has its own AML, customer due-diligence and risk-management obligations. It must understand its customer, ownership, business, expected activity and relevant risks. Those duties do not disappear because another regulator has issued a licence.
A licence can be valuable evidence. It can demonstrate that an identified regulator has admitted the firm to a defined perimeter. But it is not a banking entitlement.
The bank may still need to understand fiat flows, customer types, geographies, token exposure, counterparties, source of funds, custody arrangements and the firm’s own AML controls. Different institutions can reach different risk decisions on the same legally authorised business.
The operational lesson is simple: bankability should be tested as part of the design, not discovered after licensing.
Tax and reporting are a fourth map
Regulation does not determine the tax result either.
A VASP licence does not by itself decide corporate tax residence, permanent establishment, VAT treatment, the tax classification of tokens or the personal tax position of founders and shareholders. Nor does AML compliance substitute for tax-information regimes such as CARF or DAC8 where those regimes apply.
Tax and reporting analysis starts with facts: who the taxpayer is, where people and management are located, what the entity does, what assets and transactions are involved, and which domestic and cross-border rules apply.
This is why a regulated crypto structure can be legally authorised yet still be badly designed if its management, banking, accounting, tax residence or reporting position contradicts the way the business actually operates.
The best objection: some firms do license quickly
They do.
The argument is not that crypto licensing must be slow or that every project requires a large institution before filing. Regulatory frameworks differ, business models differ and some applicants are unusually well prepared.
The point is narrower and stronger: a fast licence does not collapse the other questions into the licensing decision. If people, controls, capital, banking or reporting have not been solved, speed at one gate can simply expose the next unsolved dependency sooner.
What changed since 2022
In late 2022, the direction of travel was already visible: virtual-asset activity was moving from broad AML registration and fragmented national treatment toward more explicit sectoral regulation.
Since then, the distinction between licence and regulated business has become easier to demonstrate from primary law and regulator material. Dubai’s VARA framework now expresses operational setup, key personnel, governance and capital requirements directly in the licensing architecture. In the European Union, MiCA created a common authorisation and prudential framework for crypto-asset service providers, while separate AML and tax-transparency regimes continue to operate alongside it.
The later rules did not create the underlying business problem. They made it harder to ignore.
The practical consequence
Before incorporation or a licence application becomes the centre of the project, a founder should be able to answer five different questions:
- Regulation: what exact activities fall inside which regulatory perimeter?
- Operational readiness: which people, systems, controls and providers must exist before launch?
- Financial capacity: what resources are regulatory, what must remain liquid and what runway funds the business?
- Bankability: can the ownership, flows, counterparties and control environment be explained to financial institutions?
- Tax and reporting: which entities and people bear tax, accounting and information-reporting obligations?
A robust international structure is the point at which those answers stop contradicting each other.
Sources
- VARA — Licence Applications
- VARA — Licensed Activities
- VARA Company Rulebook — Net Liquid Assets
- EUR-Lex — Regulation (EU) 2023/1114 on Markets in Crypto-assets, Article 67
- CBUAE Rulebook — Federal Decree-Law No. 10 of 2025 on AML/CFT/CPF
Disclaimer
This article provides general regulatory and business-structuring information. It is not legal, regulatory, tax, banking, investment or financial advice. Licensing, capital, staffing, AML, banking and tax requirements depend on the exact activity, jurisdiction, entity, clients and facts, and should be verified against the rules in force before action is taken.
