If there is one document that quietly shapes the strength of a VARA licence application, it is the Regulatory Business Plan (RBP).

A lot of applicants still treat the RBP as a narrative attachment — something to make the file look polished after the “real” work has been done elsewhere. Under the VARA framework, that is the wrong approach. VARA’s official Licence Applications page includes the Regulatory Business Plan in its published application-document list and groups the overall submission into four major categories: Corporate Structure and Governance, Risk and Compliance, Technology, and Other. VARA also says the list is non-exhaustive, which means the regulator may ask for additional material depending on the business model and the review process.

That matters because a strong RBP is not just a business summary. It is the document that helps VARA understand what exact regulated business it is being asked to license, how that business actually works, who controls it, how risks are managed, how the technology is governed, and how clients will be treated. And because all licensed VASPs must comply with the compulsory Company, Compliance and Risk Management, Technology and Information, and Market Conduct Rulebooks, the RBP must be capable of supporting all four of those regulatory lenses at once.

So the right question is not:
“What sounds good in an RBP?”

It is:
“What must be in the RBP so that founders, exchanges, brokers, custodians, managers, transfer businesses, lenders, and token issuers all present a regulator-ready story to VARA?” That is what this checklist is designed to answer.

1) Start with the first mandatory item: a clear statement of the exact VA Activity or activities

Before anything else, the RBP should clearly identify the exact VA Activity or activities the applicant wants licensed. This is not optional. The Rulebook’s licensing requirements say entities wishing to carry out one or more VA Activities in the Emirate must seek authorisation from VARA before conducting any VA Activity, and must obtain and maintain a licence for each VA Activity they will conduct. VARA’s public Licensed Activities page similarly presents the regime as an activity-based framework rather than one generic crypto licence.

That means the first checklist item in the RBP is straightforward but critical:

State the activity scope clearly and early.

For example:

  • Advisory Services
  • Broker-Dealer Services
  • Custody Services
  • Exchange Services
  • Lending and Borrowing Services
  • VA Management and Investment Services
  • VA Transfer and Settlement Services
  • Category 1 VA Issuance.

For founders, this matters because many weak RBPs stay in branding language:

  • “platform,”
  • “liquidity layer,”
  • “wallet solution,”
  • “token ecosystem,”
  • “institutional rails.”

VARA does not license slogans. It licenses functions. So the RBP should state:

  1. the specific VA Activity or activities,
  2. why those categories apply,
  3. and, just as importantly, what the business is not doing within the requested scope. 

That last point often helps reduce ambiguity and shows regulatory discipline.

2) Include a precise legal-entity and jurisdiction section

The next essential item is a clear description of:

  • the applicant legal entity,
  • the ownership and group structure,
  • where the business will be established,
  • and why VARA is the relevant regulator.

This matters because VARA regulates virtual assets across Dubai mainland and Dubai free zones, except DIFC, and its licensing framework applies to firms carrying on VA Activities in or from Dubai. That means the RBP should show clearly why the proposed entity is within the VARA perimeter and how it sits in the wider group structure if a foreign parent or affiliated entities exist.

So the checklist here should include:

  • name of the applicant entity,
  • place of incorporation or intended incorporation,
  • whether it is mainland or free-zone based,
  • whether there is an offshore parent or holding company,
  • whether there are related entities performing other functions,
  • and a short explanation of how the Dubai entity fits into the broader structure.

This is especially important for exchanges and token issuers with group structures that span multiple jurisdictions. If the RBP does not explain clearly which entity will hold the licence, which entity owns the IP, which entity contracts with clients, and which entity performs key functions, the application can start to feel structurally unclear very early. The Company Rulebook makes clear that VASPs must maintain a clear and transparent company structure conducive to sound and effective operation and oversight.

3) Explain the business model in functional, regulator-facing language

Once the entity and activity scope are clear, the RBP should explain the business model in plain functional language.

This is where a lot of applicants go wrong. They write as though the RBP were for investors rather than regulators. But the purpose of the RBP is not to market the business. It is to make the business legible to VARA. That means the RBP should explain, in practical terms:

  • what service the firm provides,
  • to whom,
  • how revenue is generated,
  • and what regulated function the firm is performing.

A good checklist for this section is:

  • What is the core service?
  • Who are the clients?
  • Is the firm advising, broking, holding, exchanging, lending, managing, transferring, settling, or issuing?
  • Does the firm act as principal, intermediary, manager, or service provider?
  • Does the firm use third parties for custody, execution, settlement, liquidity, or technology?
  • What services are out of scope?

For exchanges, this section should explain:

  • whether there is an order book,
  • how matching works,
  • whether fiat conversion is involved,
  • and whether custody is in-house or outsourced.

For token issuers, it should explain:

  • the token type,
  • the use case,
  • the issuance structure,
  • and whether the model also involves exchange, brokerage, custody, or transfer/settlement functions.

For founders generally, the guiding rule is simple:
describe the regulated function, not the startup branding.

4) Add a full customer and counterparty journey

VARA’s public application page expects customer-journey-related materials in the application file, which means the RBP should not leave the customer lifecycle vague. This is one of the most important checklist items because customer flow often reveals the true activity more clearly than the branding does.

A strong RBP should therefore include:

  • who the target customers are,
  • how they are sourced,
  • how they are onboarded,
  • how they are classified,
  • what agreements they sign,
  • how they access the service,
  • how they give instructions,
  • how transactions or services are completed,
  • and how the relationship ends. The Market Conduct Rulebook makes clear that client agreements, complaints handling, investor classifications, public disclosures, market transparency, and related conduct obligations are core parts of the VASP framework.

This is especially important for:

  • founders building broker-style models that may drift into exchange or custody,
  • exchanges that also custody client VAs,
  • token issuers that also allow secondary-market or transfer functionality,
  • and management businesses that may also give advice or route execution.

A regulator-ready RBP should allow VARA to follow the customer path step by step. If the customer journey is abstract, the real activity may remain unclear — and that is exactly where the file begins to weaken.

5) Include a clear transaction, wallet, and asset-flow narrative

This is one of the most important checklist items of all.

The RBP should explain:

  • how money moves,
  • how VAs move,
  • who controls wallets,
  • who receives instructions,
  • who routes or executes them,
  • when assets are held,
  • and whether any third party takes custody or performs settlement. That is because many VA Activities are distinguished by these exact mechanics.

For example:

  • an exchange that also controls client wallets may raise custody issues,
  • a token issuer that also enables transfer or settlement may trigger additional activity analysis,
  • a founder-led “advisory” business that also routes client execution may start to look like broker-dealer activity.

A strong RBP should therefore include:

  • a narrative flow,
  • and ideally a visual or schematic logic,
    that makes clear where value enters, how it moves, and where regulatory control points sit. This is also important because the Technology and Information Rulebook includes rules on cryptographic keys and VA wallets management, virtual asset transactions, testing, incident management, and technology governance. If the asset and transaction flows are unclear in the RBP, the technology section will also usually feel incomplete.

So the checklist is:

  • client money flow,
  • client VA flow,
  • wallet/key control,
  • counterparties,
  • internal vs external execution/settlement,
  • and points of client-asset exposure.

6) Include a governance and key-personnel section that feels real

VARA’s published application list includes:

  • UBO details,
  • fit and proper confirmations,
  • organisational structure,
  • governance framework,
  • key personnel,
  • succession planning,
  • and wind-down planning.

That means the RBP should not treat governance as a cosmetic chapter.

The Company Rulebook requires a clear and transparent company structure, appropriate segregation of duties, and suitably qualified senior management. It also says the board and senior management are ultimately responsible for internal controls and sound governance.

So the governance checklist in the RBP should include:

  • UBO and ownership summary,
  • board or governing-body structure,
  • senior-management structure,
  • role descriptions for key people,
  • reporting lines,
  • committee or oversight structure if relevant,
  • succession logic,
  • and wind-down responsibility.

For founders, the key point is not to overstate maturity. VARA does not need a fictional institutional chart. It needs a structure that is realistic, proportionate, and clear. A small but honest governance model is usually stronger than a grand but artificial one.

7) Add a real compliance and risk-management section

The RBP should include a practical summary of the compliance and risk architecture.

This is essential because the Compliance and Risk Management Rulebook applies to all VASPs and covers:

  • compliance management,
  • AML/CFT,
  • books and records,
  • client money rules,
  • client virtual asset rules,
  • anti-bribery and corruption,
  • and related governance expectations.

That means the RBP checklist should include:

  • who owns compliance,
  • who the Compliance Officer is or will be,
  • how the compliance function reports,
  • how risk management is structured,
  • how AML/CFT works,
  • how suspicious activity is escalated,
  • how records are maintained,
  • how staff training and control monitoring work,
  • and how conflicts of interest are managed.

This is especially important for:

  • exchanges,
  • custodians,
  • broker-dealers,
  • lenders,
  • managers,
  • and transfer/settlement businesses,
    because those activities are inherently close to client assets or value flows.

A weak RBP uses generic phrases like:

  • “We will maintain strong compliance controls.”

A strong one explains how compliance actually works inside the proposed model.

8) Include a technology-governance section, not just a product summary

The Technology and Information Rulebook is one of VARA’s compulsory rulebooks and requires a technology governance and risk-assessment framework, cybersecurity policy, cryptographic key and VA wallet management, testing and audit, incident and continuity planning, and the appointment of a Chief Information Security Officer.

So the RBP checklist should include a section covering:

  • core architecture,
  • key systems,
  • integrations,
  • cybersecurity governance,
  • wallet/key management where relevant,
  • testing and audit approach,
  • business continuity,
  • incident response,
  • and technology leadership / CISO oversight.

This matters particularly for founders, exchanges, and token issuers because these models are often highly technology-dependent:

  • exchanges need explainable matching and transaction systems,
  • token issuers may need to explain issuance infrastructure, reserve logic, or interaction with wallets and distribution mechanics,
  • founders building “infrastructure” businesses often need to show that the technology is governable, not just innovative.

A strong RBP explains the technology as a control environment.
A weak one describes it like a product brochure.

9) Include prudential and financial-readiness items

VARA’s public application page asks for:

  • financial projections,
  • group and entity financial statements,
  • proof of paid-up capital,
  • available capital locked-up,
  • reserve account report,
  • and insurance certificates.

And the Company Rulebook makes clear that the prudential framework includes:

  • paid-up capital,
  • net liquid assets,
  • insurance,
  • and reserve assets.

So the RBP checklist should include:

  • business revenue model,
  • operating-cost structure,
  • capital position,
  • activity-linked paid-up capital logic,
  • prudential assumptions,
  • insurance coverage approach,
  • and, where relevant, reserve-asset logic.

This is where exchanges and token issuers need to be particularly careful.

For exchanges, the RBP should explain:

  • whether custody is internal or external,
  • how that affects capital and prudential treatment,
  • and how client-asset protections operate.

For token issuers, the RBP should explain:

  • the token structure,
  • whether reserves are relevant,
  • how issuance obligations are funded,
  • and what prudential implications flow from the model.

A good RBP does not only say:

  • “We have enough money.”

It explains:

  • “We understand the prudential burden of this regulated activity and can support it.”

10) Include outsourcing, dependencies, and third-party arrangements

The Company Rulebook addresses outsourcing management, and many crypto businesses depend heavily on third parties:

  • custodians,
  • liquidity providers,
  • wallet infrastructure,
  • cloud providers,
  • AML vendors,
  • settlement providers,
  • market-data vendors,
  • token-issuance service providers.

So the RBP checklist should include:

  • which critical functions are outsourced,
  • which third parties are essential,
  • why they are used,
  • how they are selected,
  • how oversight is maintained,
  • and what happens if a provider fails.

This is particularly important for founders and token issuers, because early-stage businesses often rely on external infrastructure more than they admit. A regulator-ready RBP does not hide those dependencies. It explains them and shows that they are governed.

11) Add a conduct, disclosure, and client-documentation section

The Market Conduct Rulebook applies to all VASPs and includes:

  • marketing, advertising, and promotions,
  • client agreements,
  • complaints handling,
  • investor classifications,
  • public disclosures,
  • market transparency,
  • trading own account,
  • and VA standards.

That means the RBP checklist should include:

  • how the service will be described to clients,
  • what agreements clients will sign,
  • what disclosures are provided,
  • how complaints are handled,
  • how clients are classified where relevant,
  • and how marketing and public statements align with the licensed scope.

This matters because many otherwise strong applications become weak at the edge:

  • the RBP says one thing,
  • but the website says another,
  • and the customer documentation suggests something broader or riskier.

The RBP should therefore make clear that client-facing conduct has been thought through, not left for later.

12) Finally, make sure the RBP aligns with the rest of the file

The last checklist item is not a section. It is a test:
Does the RBP align with everything else in the application?

Because once VARA reviews the file, it will not read the RBP in isolation. It will read it against:

  • the org chart,
  • the customer journey,
  • the compliance materials,
  • the technology description,
  • the financials,
  • the insurance,
  • and the client-facing documents. VARA’s own application structure and compulsory rulebooks make that integrated review inevitable.

So before filing, founders, exchanges, and token issuers should pressure-test the RBP against the rest of the file:

  • Does the activity scope match everywhere?
  • Do the flows make sense across the documents?
  • Does the governance section match the named personnel?
  • Do the prudential assumptions match the financial model?
  • Does the client-facing conduct match the proposed business?

A strong RBP does not compete with the file.
It makes the whole file make sense.

Final takeaway

If you want the cleanest practical answer to:
“What must founders, exchanges, and token issuers include in a VARA RBP?”

it is this:

A strong VARA RBP must do much more than describe the business. It must clearly identify the licensed VA Activity scope, explain the operating model, map customer and asset flows, show real governance and compliance, address technology and prudential readiness, disclose key third-party dependencies, and align with the rest of the application file. VARA’s public application page and compulsory rulebooks show that the regulator is assessing governance, risk, technology, and conduct together — not in isolation.

That means the right founder question is not:

“What looks good in an RBP?”

It is:

“What must be in the RBP so VARA can understand, assess, and trust the business we are asking it to license?”

That is the real checklist.

How CRYPTOVERSE Legal Can Help

At CRYPTOVERSE Legal Consultancy, we help founders, exchanges, token issuers, brokers, custodians, managers, lenders, and other digital asset businesses prepare VARA-ready Regulatory Business Plans that are aligned with the activity scope, rulebooks, and wider licence application file. Our support includes activity classification, RBP structuring, governance and prudential alignment, compliance and technology narrative review, customer-journey mapping, and end-to-end VARA application strategy.

If you want tailored guidance on building a VARA RBP that includes what founders, exchanges, and token issuers actually need for a strong crypto licence application in Dubai, contact CRYPTOVERSE Legal Consultancy to discuss your licensing readiness.

FAQs

1. What is a VARA Regulatory Business Plan (RBP)?

A VARA Regulatory Business Plan (RBP) is a document that explains your business model, licensed activities, governance, compliance, technology, and risk framework for a VARA licence application.

2. Is an RBP mandatory for a VARA licence application?

Yes. VARA includes the Regulatory Business Plan as part of its licence application documentation and may request additional information based on the proposed business model.

3. What should a VARA RBP include?

A strong RBP should cover the licensed VA activities, business model, customer journey, governance, compliance, technology, financial readiness, and third-party arrangements.

4. Who needs a VARA Regulatory Business Plan?

Founders, exchanges, broker-dealers, custodians, token issuers, lending platforms, investment managers, and other Virtual Asset Service Providers (VASPs) applying for a VARA licence need an RBP.

5. Why is a well-prepared VARA RBP important?

A clear and comprehensive RBP helps VARA understand your business, assess regulatory compliance, and evaluate your readiness for licensing.