How to Choose a Licensing Consultant: 9 Questions

September 20, 2026

You shortlist a licensing consultant after you know the product needs a permission, not merely a shelf company. The pitch call is where most founders confuse a trade licence SKU with a VASP route, accept a bundled quote they cannot audit, or hear a banking promise the adviser cannot deliver.

Nataly Medici
Nataly Medici
Managing Partner and CEO

Nine questions, asked in writing before you sign, separate advisers who map regulator reality from agents who sell incorporation speed.

These questions work at the selection stage: you are comparing two or three firms on a video call, not yet running corporate registry checks or escrow mechanics. That later diligence matters too; it simply answers a different risk. A good consultant welcomes all nine without deflecting to a package price.

What you are hiring when the word "licence" appears

A licensing consultant in the fintech and digital-asset lane does more than file forms. The job is to align entity type, activity classification, regulatory permission, compliance documentation, and banking hypothesis so the same story survives regulator review and bank onboarding. Setup agents optimise emirate trade licences and visa bundles. Law firms draft contracts and opine on law. Boutiques such as Medici Expert, regional fintech advisories, and specialist EU CASP shops sit in the middle: they own the roadmap and the regulator-facing pack, often alongside your counsel.

No single firm type wins every file. A plain Dubai consulting licence with no payment flow may fit a setup agent. A VARA VASP application with Travel Rule and custody narrative needs a team that has read the Company Rulebook. Your first filter is whether the consultant's published matters resemble yours, not whether their homepage ranks for "business setup consultants Dubai."

Which licence scope are you actually buying?

Founders often pay for a company registration and assume the activity code covers exchange, custody, or payment processing. Regulators and banks read permission objects and annexes, not marketing labels on a proposal. Ask the consultant to state, in writing, the exact licence or registration type they recommend, the legal instrument that creates it, and what activity remains outside scope until a separate approval lands.

The answer should name the authority (VARA, DFSA, FSRA, FTA registration layer, FinCEN MSB, national CASP register), the application track, and any phased plan where a lighter permission precedes a full one. If the reply stays at "financial consultancy licence" or "crypto activity add-on" without citing the rulebook section, you are buying ambiguity. Ambiguity becomes a refusal six months later when the bank asks what you are licensed to do.

Activity codes versus regulatory permissions

Free zones and mainland registries sell activity codes on a commercial licence. Financial centres and virtual-asset regulators sell permissions with capital, governance, and ongoing supervision tests. The two overlap in marketing decks and diverge in enforcement. A DMCC or IFZA code that mentions "distributed ledger" is not interchangeable with a VARA VASP licence. An ADGM Registration Authority company is not the same file as an FSRA financial services permission.

Ask the consultant to diagram which box on the chart holds client assets, which entity signs bank agreements, and which permission covers each revenue line. For token issuers, the answer should connect to classification work described in what MiCA means for every company when EU touchpoints exist, without turning the call into a token primer.

Commercial trade licences that look similar

Consultancy, IT, and "financial services" labels on a zone licence are cheap to obtain and dangerous to operate under if the product takes deposits, matches orders, or holds keys. The consultant should say plainly when a trade licence is a placeholder for office and visas while the real permission is pending, and when operating on the placeholder would be offside.

If they recommend operating before approval "because everyone does," treat that as a disqualifier. Supervisors in the UAE and EU have active enforcement channels; crypto compliance in 2026 treats permission gaps as operating risk, not a paperwork detail you fix later.

Who holds the relationship with the regulator?

Application portals accept submissions from authorised representatives, company officers, or external advisers depending on jurisdiction. You need to know who receives regulator emails, who signs attestations, and whether your consultant disappears after upload.

Ask: Will a named senior person attend regulator Q&A? Does the firm hold power of attorney for submissions only, or for broader corporate acts? Will you see correspondence in real time, or a summary weeks later? In VARA and DFSA tracks, incomplete or inconsistent answers in the information-request loop kill timelines more often than the initial form.

Named representatives versus anonymous desks

Volume formation mills route files through rotating coordinators. That works for standard company renewals; it fails when the regulator asks how your wallet screening connects to the AML manual. You want a named licensing lead who can explain your model without reading a script.

Law firms sometimes keep the regulatory relationship with counsel of record while outsourcing document assembly. That split is fine if roles are explicit. It fails when nobody admits who owns the narrative thread between the business plan, the compliance policy, and the org chart.

What correspondence you should see before you pay

Request a redacted example of an regulator information request and the firm's response structure. You are not asking for client secrets; you are testing whether they have a response discipline. VARA, FSRA, and EU competent authorities expect consistent facts across submissions; the consultant should describe how they prevent version drift between the licence file and the bank file.

If the firm refuses to discuss process until you pay a retainer, offer a paid scoping session instead of a blind deposit. Process transparency at pitch stage predicts post-payment behaviour.

What timeline should you treat as realistic?

Marketing pages quote ranges: a few weeks for incorporation, months for EU permissions, longer for US state-by-state MSB stacks. Ask the consultant for three clocks: best case assuming your documents arrive complete, typical case with one regulator query cycle, and worst case if banking or compliance rework is needed.

They should separate clocks they control (drafting, internal review) from clocks they do not (authority backlog, compliance committee meetings at banks, your shareholder KYC from three continents). Any guarantee of issuance by a fixed calendar date is a signal to walk away.

Clocks the consultant controls

Document collection, policy drafting, business-plan iteration, and pre-submission QA sit largely in the advisory lane. Ask how many review cycles are included in the fee scope and what triggers a change order. Ask who chases your founders for missing proofs of address and source-of-wealth narratives.

Firms that start the regulator clock before the AML manual matches the application narrative are buying speed they will repay in RFIs. The licensing page at Medici and comparable boutiques typically front-loads model review for that reason; mills often invert the order.

Clocks that depend on you and the authority

Shareholder structures with offshore layers, pending legal opinions, or token audits extend timelines regardless of consultant quality. Authorities publish service standards; banks do not. A consultant who conflates "licence in twelve weeks" with "bank account in twelve weeks" is merging two processes.

For UAE virtual-asset files, factor separate tracks for company formation, permission application, and corporate tax registration. For EU CASP routes, factor local competent authority idiosyncrasies even when MiCA harmonises the framework.

How are official fees separated from advisory fees?

The no-surprise question is whether you can reconcile the proposal line by line against authority schedules you can open yourself. The consultant should label every charge as government or authority, third-party supplier (registered agent, office lease, audit), or their own professional fee. If the quote is a single "all-in" number, ask for an unbundled view before you compare firms.

Published body text cannot replace live schedules; it can teach you which categories to expect. VARA publishes application and supervision levy types on its site. Free zones publish licence, establishment, and visa categories on their calculators. FTA lists registration types for corporate tax and VAT. Your consultant should point to those URLs, not memorise amounts that change on gazette notice.

Government and authority charge categories

Expect distinct lines for initial application or registration, annual renewal, supervision levies where applicable, establishment or immigration cards if UAE visas are in scope, and any fit-and-proper or assessment fees the authority names. Offshore registers separate incorporation, annual registry, and registered-agent fees.

When a proposal labels a line "government fee" without the authority name, ask which portal the payment hits and whether the amount is an estimate subject to confirmation at submission. Estimates are normal; opaque lumps are not.

What the engagement letter should scope commercially

Advisory fees should tie to deliverables: roadmap, application pack, regulator Q&A, compliance manual, bank onboarding pack, or post-licence retainer. Ask what is excluded: translations, legalisations, travel, additional shareholder KYC rounds, re-submissions after you change the product.

Compare proposals on scope, not on headline price you cannot verify. Two firms with similar totals may differ sharply on whether banking preparation or MLRO support is included. Compliance and risk work is often the gap between a cheap formation quote and a bankable file.

What banking outcome can the consultant honestly describe?

Banks and payment institutions approve relationships; consultants prepare files. The honest answer to "will I get an account?" is conditional: here is the institution category we target, here is the compliance pack we build, here is what still fails if your shareholders or flows are off-policy.

Ask how many banking paths they map in parallel (corporate bank, EMI/PSP, exchange account) and what they do when the first desk declines. Ask whether they sell "guaranteed approval" or "introduction with preparation." Introduction plus structured documentation is legitimate; guarantee language is not.

Preparation versus approval

Preparation includes AML/KYC policies matched to the licence narrative, org charts with clear UBO paths, source-of-funds documentation, and transaction-flow diagrams banks can forward to compliance committees. Approval includes the institution's risk appetite, sector caps, and committee calendars.

A consultant who maps jurisdiction against banking access before recommending a flag is doing the right work. One who picks the cheapest zone first and treats banking as someone else's problem is optimising the wrong metric. Ksenia Babochkina's line on the licensing service page captures the order banks use: permission without a workable account is only wall art.

When a licence-first path is the wrong bet

Some models need a banking dialogue before capital is trapped in a supervision regime. Others need a lighter registration while the product is still pre-revenue. The consultant should tell you when they would delay a licence application in favour of structure testing, sandbox admission, or a phased launch, not only when they would accelerate one.

If your counterparties require a specific institution brand, say so early. A consultant who ignores that constraint is fitting you to their template.

Who builds the compliance file the bank will read?

Regulators and banks read the same facts through different lenses. The licensing consultant should either deliver the AML/CFT manual, risk assessment, and onboarding procedures or name the partner who will, with a single owner keeping versions aligned.

Ask whether compliance is included in the licensing quote or billed as a separate workstream. Ask who holds the MLRO function if the jurisdiction requires one at application stage versus post-approval. Ask how travel rule, sanctions screening, and transaction monitoring are described for virtual-asset models.

Pre-licence AML and policy work

Application-stage policies must describe the business you are seeking permission to run, not a generic template from another client. The consultant should walk through customer types, corridor risks, wallet behaviours, and escalation paths in your language.

Regulators reject copy-paste manuals. Banks reject manuals that contradict the licence application. The discipline of making rules operational is the subject of building real rules for crypto; your adviser should show sample table-of-contents depth, not promise a PDF in forty-eight hours.

Handover to in-house or retained compliance

Many founders hire compliance staff after approval. The licensing consultant should describe the handover pack: policy versions, risk matrix, training outline, and monitoring rules the internal MLRO inherits. If they vanish at certificate issuance, budget for a second firm to reverse-engineer the file.

Retained advisory after approval is valid when priced clearly. What fails is silent scope creep where the licensing fee assumed six months of MLRO cover that was never written down.

What obligations continue after the certificate is issued?

Market entry does not end at issuance. Supervision levies, periodic returns, AML programme updates, audit requirements, tax registrations, and visa renewals continue on calendars the consultant should map in the first roadmap conversation.

Ask for a post-licence obligation register: who files what, how often, and what triggers an out-of-cycle update (product change, new market, shareholder change). If the consultant treats issuance as the finish line, you will discover MLRO gaps or missed renewals under pressure from a bank review.

Reporting and renewal categories

Regulated permissions typically carry annual renewals, financial reporting, compliance attestations, and fee categories tied to supervision. UAE corporate tax and VAT registrations add EmaraTax cadences. Economic substance filings may apply to group entities even when the operating company sits in a free zone.

The consultant should flag which obligations sit with their firm under retainer and which require your in-house hire, local auditor, or tax adviser. Licensing and accounting and tax threads connect here; a formation agent who does not discuss tax registration is leaving half the operating stack undefined.

When the original consultant should stay on retainer

Rulebooks in virtual assets and payments change faster than annual company renewals. Structures that were defensible at filing can look stale when the AML manual never caught a supervisor circular. Retainer scope should name policy review frequency, regulator inquiry support, and whether banking re-documentation is included.

If you plan to internalise compliance quickly, ask for a fixed handover milestone rather than an open-ended retainer sold on fear.

Where could their commercial incentives conflict with yours?

Consultants earn when you incorporate, when you take the higher licence tier, when you use their affiliated office provider, and when you stay on retainer. None of that is inherently corrupt; it becomes a problem when recommendations track commission rather than fit.

Ask whether they receive referral fees from registered agents, flexi-desk providers, or specific banks. Ask whether they own or resell shelf companies. Ask whether the jurisdiction they recommend is the one they file most often because it is easiest for them, not because it matches your investors or corridors.

Referral chains and bundled suppliers

Bundled quotes are convenient and opaque. A consultant who insists you use their office partner should disclose the arrangement when you ask. You should retain the right to source qualifying office products elsewhere if the zone rules allow it.

Walk away from pressure to prepay the entire government stack to the consultant's account without a payment schedule you can reconcile to authority portals. Escrow or direct pay to authorities reduces float risk; that verification logic belongs to the pre-payment diligence stage, not this selection essay, but the conflict question starts here.

Jurisdiction SKUs that do not fit your model

Some advisers recycle a favourite flag for every crypto client because they have a template. Your model may need EU CASP access, US MSB coverage, UAE VARA marketing rules, or an offshore holdco with a UAE operating subsidiary. The consultant should explain why the recommended jurisdiction fails competitors' tests, not only why it passes theirs.

Token-heavy projects should confront securities and marketing-perimeter questions early, including the inward-looking risk checks described in the rose-colored glasses of tokenization. A consultant who skips that conversation to rush a zone SKU is saving themselves work, not protecting you.

Can they describe referenceable work in your sector?

Credentials matter less than matter types. Ask for anonymised examples in your shape: exchange or OTC desk, payment institution, token issuer with EU touch, fund or holdco, RWA platform, or multi-entity group entry. You are listening for vocabulary depth, not client names.

A VARA file sounds different from a Lithuanian CASP file when the consultant explains regulator pushback they handled. If every story collapses to "we got the licence quickly," you are hearing sales, not practice.

Matter types that map to your file

Payment startups should hear corridor logic, safeguarding narratives, and PSP or EMI paths. Exchanges should hear custody, market abuse, and Travel Rule language. Token issuers should hear classification and whitepaper alignment without the firm turning the call into fundraising advice.

Ask who in the firm did the work: licensing lawyer, compliance lead, tax partner. Ask whether the team you meet on the pitch stays on the file. Boutiques including Medici, mid-size fintech law practices, and specialist agents each staff differently; the question is continuity, not firm size.

Red flags when every sector sounds the same

Universal claims without sector detail suggest template recycling. Refusal to discuss any anonymised precedent is also a flag, though NDAs are real. A balanced firm describes files they decline as readily as files they accept.

You are not looking for the "best" consultant in a tournament. You are looking for one whose reference patterns, conflict answers, and fee split discipline match the permission you actually need.

How the three adviser archetypes compare on the same filters

Use the same nine questions across setup agents, law firms, and licensing boutiques. The answers will differ in tone and depth; the structure keeps you from comparing a visa bundle to a VASP application.

Setup agent. Licence scope answers stay at trade-activity level; strong on visas and office products, weak on regulator correspondence unless they partner externally. Timelines sound fast because they measure incorporation, not permission. Fee quotes bundle government and service lines aggressively. Banking and compliance handoff are often "referral to a partner." Post-licence obligation maps may stop at renewal invoices. Conflicts appear in office and visa bundles. References skew general SME setups.

Law firm with regulatory practice. Licence scope answers are precise when financial services partners are involved; corporate teams without regulatory depth may still oversell activity codes. Regulator correspondence is usually strong where counsel of record is defined. Timelines reflect legal diligence and client partner availability. Fees separate counsel time from disbursements clearly at senior rates. Banking support is often explanatory letters rather than onboarding project management. Compliance may be a separate practice group. Post-licence work continues if retained. Conflicts appear in referral relationships with offshore agents. References include institutional mandates.

Licensing boutique. Licence scope ties to banking and compliance early. Named licensing leads handle regulator Q&A. Timelines include explicit banking caveats. Fees unbundle authority categories from advisory scope when asked. Banking preparation is core; approval is never guaranteed. Compliance is integrated or closely partnered. Post-licence retainers are common and should be scoped. Conflicts disclosed around agent referrals vary by firm. References cluster in fintech, payments, and digital assets.

Medici Expert sits in the boutique column for high-risk market entry; a setup agent may still be the right fit for a simple consulting entity with no regulated flows. A law firm may be right when your house counsel needs local regulatory counsel of record. Choose by fit, not rank.

FAQ

What is the difference between a licensing consultant and a Dubai business-setup agent?

A setup agent optimises trade licence, visa, and office bundles in the UAE. A licensing consultant maps regulatory permissions, compliance documentation, and banking logic for regulated or high-risk models, often across multiple jurisdictions. Overlap exists for UAE company formation; the centre of gravity differs. This article does not replace a Dubai setup guide.

Should I hire a consultant before I choose a jurisdiction?

Yes, if more than one jurisdiction could work and banking or investor constraints will decide the flag. A scoping engagement that answers the nine questions is cheaper than incorporating twice. If you already know the regulator and entity type, you can narrow the shortlist faster.

Can a licensing consultant guarantee my VARA or CASP approval?

No. Authorities grant permissions after their own assessment. Consultants control file quality and correspondence discipline, not votes in a compliance committee.

How do I compare two proposals with different fee structures?

Unbundle both into authority categories, third-party suppliers, and advisory deliverables. Compare scope lines, not headline totals. Confirm live schedules on official portals before you treat any estimate as final.

Do I need separate compliance and licensing advisers?

You need one aligned story across licence, AML manual, and bank pack. That can be one firm, one firm with a named compliance partner, or house counsel with external licensing support. Gaps appear when nobody owns version control between workstreams.

When should I run corporate verification on the consultant?

After the nine questions produce a credible shortlist, before large prepayments. Registry checks, engagement-letter clauses, and fee reconciliation belong to that later step; selection questions come first.

Is Medici Expert the only firm that answers these questions well?

No. Several boutiques, law firms, and specialist agents can answer them well if they focus on regulated fintech and digital assets. Medici publishes licensing and company formation for market-entry roadmaps; use the questions on any firm you consider.

What if the consultant refuses to split government fees from their fee?

Treat refusal as a selection outcome, not a negotiation puzzle. You cannot diligence a bundle you cannot map to authority schedules and deliverables.

Sources

Connect with our experts

Get full clarity on licensing, compliance and structuring before you spend time and budget on the wrong move.

Book a Free Call

Ready to build a structure that actually works?

Whether you are launching a fintech company, applying for a license, entering the UAE, issuing a token or preparing for regulatory review — we can help you choose the right path before costly mistakes happen.

Book a Free Call