Insights · Web3 and digital assets

Where should you incorporate? Answer these five questions first

Every Web3 team arrives with a jurisdiction already in mind. Dubai, Singapore, Cayman, Delaware, BVI, Estonia. Each of those is a good answer for somebody, and the question of whether it is good for your business is one almost nobody has actually sat down and worked through. Incorporating in a jurisdiction defines what you are permitted to do inside it, so the list of things you intend to do has to exist before the container is chosen. Incorporation is the last question in the sequence. Five questions come before it, and getting them in the wrong order is expensive, because most of what you settle in the first six months cannot be undone later.

One product, four regulators, and none of them asked where you registered

Take a build with a UAE entity, engineers in India, US investors and users everywhere. The UAE leg runs into VARA, which licenses against a detailed activity map rather than a company type, and which expects custodial activity to sit in a separate legal entity from the licensed trading business whatever category of licence is held. The India leg runs into FIU-IND, whose perimeter is activity-based and reaches businesses touching Indian users. The US leg raises how ownership rights are granted to investors, which drives both structure and registrations. And marketing into the EU or the UAE brings those regimes' marketing rules with it, whether or not you hold a licence there.

Four regulatory regimes engaged by one product, and not one of them began by asking where the company was incorporated. That is the whole argument for changing the order.

The five questions

1. What will the business actually do?

Not what the product is called, but which functions it performs. Trading, routing, lending, running vaults, holding assets, moving value across chains or into fiat, giving recommendations. Each maps to its own authorisation, and a single roadmap routinely triggers several. The activity list is written first, and the jurisdiction is then chosen to fit it.

2. Is the token a security or a utility?

This is not a question your white paper gets to answer. It takes real legwork: testing the token's design against the law in each market where buyers sit, before issuance. What decides it is economics, not vocabulary. A token that promises a yield to holders, or carries a buyback, reads as a security in the US analysis and opens up the compliance and geo-blocking questions that follow. A utility token that is genuinely consumed in using the product is a different instrument. A Delaware entity, for instance, cannot comfortably issue a token outright without carrying the risk that it is treated as a security.

And this one is final. Once buyers have paid and a regulator has formed a view, there is no reclassifying. You comply with the view or you accept the consequences.

3. Who are you marketing to?

It does not matter where you are set up. What matters is who you market to, today and in the future. VARA's marketing rules bind projects that market into Dubai, MiCA governs the EU, and Singapore and now South Korea each regulate the marketing of crypto businesses to their own citizens. The EU made this concrete in July 2026, when the transitional window closed and a number of international players simply stopped being able to operate in the bloc because they had not completed authorisation or passporting. We compared the two main corridors for our clients in MiCA vs VARA.

4. How does the money move?

Your investors, your banking setup, and the AML systems behind both. Every institution you approach for a relationship asks the same things: what KYC and AML controls exist, which compliance obligations attach to you, and therefore how risky you are to bank. The structure also has to read coherently. A token issued in one place, a company in another and a bank application in a third, with nothing connecting them, gets declined on the story alone.

5. Who actually controls the asset?

Control means more than control of the company. It means the asset: whether the activity is genuinely custodial or non-custodial, and who can move what. No regulation takes your word for this. Every regime judges custody on facts, on how the technology is set up and whether you hold any level of control over assets or money changing hands. Saying you are non-custodial does not make you non-custodial.

Then build in this order

Once the five are answered, the structure has a sequence, and the sequence is the discipline. Our Web3 legal-readiness checklist runs the same order in more detail.

  • Entity and tax. A real Web3 business is usually several entities: a foundation, a devco, a holding company, sometimes a trading entity, each doing one thing so liability is contained and flows stay compliant. Watch permanent establishment. You can sit in Dubai and incorporate a Delaware C-corp, but tax authorities look at where the economic activity actually happens, and this cannot be reordered after a token exists.
  • Token and licensing. Classification, then the authorisations it triggers, including a compliance officer or MLRO where the regime requires one. Both VARA and MiCA do.
  • AML, KYC and the Travel Rule. These are not policies you draft and file. They have to be enforced at the technology level. AML failure is the most common mistake we see in Web3 projects.
  • Contracts, IP and data. Employees, contributors, vendors. The IP has to sit with the right entity, and the data has to be protected. Investors will ask who holds the IP, and in a multi-entity setup that answer has to be deliberate. If it is gone, it is gone.
  • Governance. A DAO needs a legal wrapper on top of it. Without one, members can be left with unlimited liability, which is why serious DAOs now sit inside a limited liability vehicle rather than relying on a co-operative structure, which centralises voting and is not a separate legal person.

The catch-22, honestly stated

Founders push back on all of this, and the objection is fair: decentralisation was supposed to make this unnecessary. A genuinely decentralised system can operate today. The open question is for how long, because regulators keep arriving. That is the situation the industry is actually in, and the working answer is that we deal with what is, instead of what should be. None of that is a reason to skip the homework. It is the reason the homework is worth doing early, while it is still cheap.

Where founders get caught

  • Picking the jurisdiction at a conference. A peer incorporated in Dubai, or Cayman, and it worked for them. Their activity list was not yours.
  • Treating offshore as outside. Marketing rules and AML perimeters follow the audience and the activity, not the certificate.
  • Asserting the token classification instead of testing it. The document says utility. The economics say otherwise, and the economics win.
  • Leaving the IP with individuals. Discovered in diligence, long after the contributors have moved on.
  • Running a DAO without a wrapper. Members carry the liability that no entity is there to absorb.

Frequently asked questions

Why is incorporation the last question and not the first?

Because incorporating in a jurisdiction defines what you are permitted to do inside it, so the permitted-activity list has to exist before the jurisdiction is chosen. A founder who picks the country first then spends the next year bending the business to fit the container, and most of what gets decided in that period, the entity structure, the token classification, the custody arrangement, cannot be undone afterwards. The address is the output of the analysis, not the input.

Does the jurisdiction you incorporate in decide which regulators apply to you?

No. Marketing rules across the major regimes attach to who you target, not to where you registered, and AML perimeters are typically activity-based. A business licensed in one jurisdiction that markets into another picks up the second jurisdiction's marketing regulations, and India's FIU-IND obligations attach to notified virtual digital asset activity irrespective of where the entity is incorporated. Your audience selects your regulators more reliably than your registrar does.

Can you rely on calling your product non-custodial?

Not as a label. Regulators assess custody on facts: how the technology is built, and whether you hold any level of control over assets or money changing hands. Dubai adds a structural requirement on top, because VARA expects custodial activity to sit in a separate legal entity from the licensed trading entity whatever category of licence is held. Discovering that after one combined entity has been built is a restructuring, not a policy amendment.

Can a token be reclassified after it has been issued?

No. Classification follows what the token does, how it is rewarded, and whether it carries yield, a buyback or a return, and it is assessed in each market where buyers sit. Once buyers have paid and a regulator has formed a view, the founder complies with that view or accepts the consequences of non-compliance. Describing a token as a utility token in the token documents does not settle the question, which is why classification is tested before the sale rather than asserted after it.

In what order should a cross-border Web3 structure be built?

Entity and tax first, because the multi-entity setup and any permanent-establishment exposure have to be right before a token exists. Then token classification and the licensing that follows it, including a compliance officer or MLRO where the regime requires one. Then AML, KYC and Travel Rule controls, enforced at the technology level rather than drafted as policy. Then contracts, IP assignment and data protection, so ownership sits with the right entity. Governance last, including a legal wrapper for any DAO, because an unwrapped DAO can leave members with unlimited liability.

Next step

Not sure which jurisdiction fits what you are building?

Send us the short version: what the product does, whether there is a token, who your users are and where your team sits. We will run these five questions against it and tell you what the structure has to look like, before anything is registered.

Further reading

VARA vs ADGM vs DIFC · MiCA vs VARA · Launching a token from India · Where the legal line on custody actually sits · The Web3 legal-readiness checklist

This article is general information for founders, not legal advice for your specific business, token or structure. It is drawn from a public educational session and the outcomes described depend entirely on your facts. Have your structure reviewed by counsel qualified in the relevant jurisdiction before anything is registered, issued or sold.