AML Compliance for VASPs in the UAE: 2026 VARA Guide

AML compliance for VASPs in the UAE moved from a licensing formality to a supervised, enforceable obligation the moment Federal Decree-Law No. 10 of 2025 came into force on 14 October 2025. A virtual asset service provider operating in Dubai or anywhere in the Emirates is now held to the same anti-money laundering and counter-terrorist financing standards as a bank, and the Virtual Assets Regulatory Authority (VARA) has made the crypto Travel Rule a live supervisory test rather than a future plan. This guide sets out what a VASP must actually do to stay compliant in 2026, written from the perspective of a UAE practitioner who builds and audits these programmes.

Quick Answer

VASPs in the UAE must hold the correct licence from their regulator (VARA in mainland Dubai, the FSRA in ADGM, the DFSA in DIFC, or the SCA for security tokens), run a full AML/CFT programme under Federal Decree-Law No. 10 of 2025, register with the goAML portal, and apply the Travel Rule to every qualifying virtual asset transfer at or above AED 3,500. The programme has to cover a business risk assessment, customer due diligence, sanctions and PEP screening, transaction monitoring with blockchain analytics, and suspicious-transaction reporting. Privacy-enhancing tokens are prohibited under Dubai’s framework, and enhanced due diligence applies to self-hosted wallet transfers. Penalties for legal persons reach AED 100 million.

Key Takeaways

  • One activity, one licence: No firm can conduct a virtual asset activity in Dubai without a VASP licence from VARA, and each regulated activity carries its own AML expectations.
  • FI-grade standards apply: Under Federal Decree-Law No. 10 of 2025, VASPs carry the same AML/CFT and proliferation-financing duties as licensed financial institutions.
  • Travel Rule is enforced: Originator and beneficiary data must be collected, verified, and transmitted for transfers at or above AED 3,500.
  • goAML is mandatory: Registration on the UAE FIU’s goAML portal and timely STR/SAR filing are non-negotiable.
  • Privacy coins are out: Dubai’s Travel Rule framework bars transfers involving anonymity-enhancing tokens.
  • Self-hosted wallets need EDD: Unhosted-wallet transactions call for extra identification and source-of-funds checks.
  • Penalties are severe: Legal persons face fines from AED 5 million to AED 100 million, with possible dissolution in serious cases.

Who Counts as a VASP in the UAE

A virtual asset service provider is any business that conducts a virtual asset activity for or on behalf of another person. The complication in the UAE is that more than one regulator can supervise that activity, depending on where the firm is licensed. Getting this mapping right is the first step, because it decides which rulebook, which reporting channel, and which supervisor a VASP answers to.

The five authorities that touch virtual assets

UAE virtual asset oversight is split across five bodies. A VASP needs to know which one supervises it before drafting a single policy.

Authority Scope What it means for a VASP
VARA Virtual assets in the Emirate of Dubai, including most free zones (excluding DIFC) Primary licensing and AML supervisor for Dubai mainland crypto firms
FSRA Abu Dhabi Global Market (ADGM) Supervises VASPs licensed inside ADGM
DFSA Dubai International Financial Centre (DIFC) Supervises crypto token businesses inside DIFC
SCA Securities-related and certain federal virtual assets Relevant where a token behaves like a security
CBUAE Federal monetary and payment policy Sets the overarching AML/CFT framework that filters down to all supervisors

Above all of them sits the federal AML framework and the UAE Financial Intelligence Unit, which runs goAML. Whatever the licensing authority, every VASP reports suspicious activity into the same national channel. For a fuller breakdown of how jurisdiction shapes obligations, see our guide on AML requirements across Mainland, DIFC, and ADGM.

VARA’s seven licensed activities

VARA regulates seven distinct virtual asset activities. A firm needs a separate authorisation for each one it carries out, and the AML risk profile changes with the activity. An exchange faces different layering risks than a custodian, and a payments-and-remittance provider faces different velocity risks than an advisory firm.

VARA activity Core AML risk to manage
Advisory services Client onboarding and conflicts, lower transaction risk
Broker-dealer services Order matching, counterparty identification
Custody services Segregation, source of assets, wallet attribution
Exchange services Layering, wash trading, fiat on-ramp and off-ramp abuse
Lending and borrowing services Collateral provenance, circular financing
Payments and remittance services High velocity, Travel Rule exposure, structuring
Management and investment services Beneficial ownership of pooled funds, investor screening

Obtaining the licence is only the entry ticket. The AML programme behind it is what supervisors actually inspect.

The Legal Backbone: Federal Decree-Law No. 10 of 2025

Federal Decree-Law No. 10 of 2025 replaced the earlier Federal Decree-Law No. 20 of 2018 and reset the baseline for the entire supervised population. For VASPs, the headline change is one of status: virtual asset businesses are no longer treated as a lighter-touch category. They sit alongside financial institutions in the eyes of the law.

VASPs now carry financial-institution duties

The 2025 law confirms that VASPs must meet the same AML, CFT, and counter-proliferation-financing standards as conventional financial institutions. That includes a documented enterprise-wide risk assessment, a board-approved compliance programme, an appointed compliance officer or MLRO, ongoing staff training, independent testing, and full record-keeping. The Travel Rule for virtual asset transfers is written into this framework rather than treated as an optional control. Our full explainer on Federal Decree-Law No. 10 of 2025 walks through the wider obligations for every supervised entity.

What the penalties look like

The 2025 law raised the ceiling on financial penalties and widened the consequences for management. A risk-based approach is not a defence on its own, but a documented one materially reduces exposure when a supervisor reviews a file.

Exposure Detail under the 2025 framework
Fines for legal persons AED 5 million up to AED 100 million (previously capped at AED 50 million)
Value-linked fines Penalties can be tied to the value of the criminal property involved
Corporate measures Courts may order dissolution of the entity or closure of premises in serious cases
Time limits Proceedings for these offences do not lapse with the passage of time
Management liability Representatives, managers, and agents can trigger entity liability

For a VASP, the practical reading is simple. A weak control environment is now an enterprise risk, not a compliance line item.

The Crypto Travel Rule in Dubai

The Travel Rule is the single most VASP-specific control in the UAE framework, and it is the one most often implemented late or incompletely. It applies the FATF Recommendation 16 standard to virtual asset transfers, requiring information to move with the value.

The AED 3,500 threshold and the data that must travel

For every qualifying transfer at or above AED 3,500, both the originating and beneficiary VASP must obtain, hold, and where required verify a defined set of data. Verification is also triggered, regardless of value, where suspicious activity is identified.

Originator information Beneficiary information
Full name Full name
Account number or wallet address Account number or wallet address
Physical address (or equivalent identifier) Held and matched on receipt

The rule applies where at least one regulated VASP is part of the transfer. That scope is what brings self-hosted wallet interactions into play and is why a counterparty-VASP due diligence process is now part of a credible programme.

Self-hosted wallets and prohibited tokens

Two design decisions sit at the centre of Dubai’s framework. First, transfers to or from self-hosted, or unhosted, wallets require enhanced due diligence, including additional customer identification and source-of-funds verification. Second, VASPs must not execute transfers involving privacy or anonymity-enhancing tokens, because the obfuscation features defeat the data requirements the Travel Rule is built on. A VASP that lists or supports such assets is carrying a live, unmanaged risk.

Automate the Travel Rule data flow. First Compliance handles CDD, real-time sanctions and PEP screening, and the structured data capture that Travel Rule transfers demand, with 1,800+ sanction lists and 5.5M+ PEP records behind every check. See how First Compliance fits a VASP onboarding stack.

Building a VASP AML/CFT Programme: a Day-1 Setup

A newly licensed VASP often has the licence before it has a working programme. The fastest route to inspection readiness is to build the five core controls in sequence, each one feeding the next. None of this is generic. Each control has to reflect virtual asset typologies and the firm’s specific activities.

1. Enterprise-wide risk assessment

The risk assessment is the foundation that every other control points back to. For a VASP it has to weigh customer types, the virtual assets supported, geographic exposure, delivery channels, and the specific activities licensed under VARA. A custody-only firm and an exchange should not produce identical assessments. Supervisors read this document first, so it cannot be a template.

2. Customer due diligence and enhanced due diligence

CDD for virtual asset customers blends standard identity verification with chain-level attribution. Wallet screening, source-of-funds and source-of-wealth checks, and counterparty risk all sit inside the onboarding flow. Higher-risk customers, including those transacting through self-hosted wallets, move to enhanced due diligence. Our detailed guides on customer due diligence in the UAE and enhanced due diligence set out the steps in full.

3. Sanctions and PEP screening

Screening for a VASP runs in two directions: the customer and the wallet. Names, entities, and beneficial owners are screened against UAE and international sanctions lists, while wallet addresses are screened against known illicit-activity clusters. Targeted financial sanctions obligations apply in full, and a missed listing is one of the costliest errors a VASP can make. See our explainer on targeted financial sanctions in the UAE for the obligations and timelines.

4. Transaction monitoring with blockchain analytics

Transaction monitoring for virtual assets has to combine traditional rules, such as velocity and structuring patterns, with on-chain analytics that trace funds across wallets and flag exposure to mixers, darknet markets, or sanctioned addresses. Alerts feed a documented investigation workflow that ends, where warranted, in a report. The methodology behind effective alerting is covered in our guide to AML transaction monitoring in the UAE.

5. Governance, training, and independent testing

An appointed compliance officer, board oversight, role-based staff training, and periodic independent testing turn a set of controls into a programme. Training is not a once-a-year slide deck. Front-line, onboarding, and monitoring staff each need content matched to their role. The framework for a complete build is set out in our walkthrough on building an AML compliance programme in the UAE.

Get an independent read before the regulator does. ADZ conducts independent AML/CFT audits for VARA, CBUAE, and DFSA-regulated entities, testing your programme against the 2025 framework and the Travel Rule. Book a VASP AML audit or gap analysis.

goAML Registration and Reporting for VASPs

Every VASP must register on the goAML portal operated by the UAE Financial Intelligence Unit. Registration is the gateway to filing suspicious transaction reports (STRs), suspicious activity reports (SARs), and the funds-transfer reports the system requires. A VASP that holds a licence but has not completed goAML registration has a visible, immediate gap.

Registration runs in two stages. First, the firm registers in the Service Access Control Manager to obtain a username and secret key. Second, it completes the goAML organisation profile and names its compliance officer. The compliance officer details on file have to stay current, because a stale or absent contact is one of the first things a supervisor notices. The portal is also where registration-related goods reports and dealer filings are handled for firms that touch both crypto and high-value goods, so a VASP with a mixed model should map every reporting obligation to a single owner.

Filing suspicious reports on time

When monitoring or screening surfaces a genuine suspicion, the VASP files through goAML without tipping off the customer. Quality matters as much as speed: a vague narrative weakens the report and the institution’s standing. Our step-by-step guides on goAML portal registration and how to file an STR in the UAE cover the timing rules and narrative standards in detail.

Common Compliance Gaps We See in VASPs

Across audits and onboarding engagements, the same weaknesses recur. Checking your own programme against this list is a quick way to find exposure before a supervisor does.

  • Travel Rule implemented for fiat logic, not crypto reality: Firms apply a payments mindset and miss the wallet-attribution and counterparty-VASP steps.
  • No counterparty-VASP due diligence: Transfers go to unknown receiving institutions with no assessment of their controls.
  • Static risk assessment: The document is written once at licensing and never updated for new tokens or new corridors.
  • Screening without on-chain analytics: Name screening runs, but wallet addresses are never checked against illicit clusters.
  • goAML registered but unused: Registration is completed, then no monitoring output ever reaches a filing decision.
  • Privacy tokens still listed: Assets that cannot satisfy the Travel Rule remain available to customers.

With the FATF mutual evaluation of the UAE underway in mid-2026, supervisors are applying a low-tolerance stance. A gap that might once have drawn a warning is now more likely to draw an action.

How a UAE Practitioner Approaches VASP Compliance

The difference between writing about AML and running it shows up in the detail. A VASP programme that survives inspection is one where the risk assessment, the onboarding flow, the screening engine, the monitoring rules, and the reporting workflow all reference each other and all reflect virtual asset typologies. ADZ builds these programmes, supplies the First Compliance platform that runs the daily controls, trains the teams that operate them through Compliance 360, and audits the result. That full stack, advisory plus software plus training plus independent audit, is what lets a VASP move from a licence to a defensible compliance position.

Map your VASP obligations once, correctly. ADZ’s compliance advisory team helps virtual asset firms scope their VARA, FDL 10/2025, and Travel Rule duties and build the programme to match. Talk to ADZ’s AML advisory team.

Frequently Asked Questions

What is the VARA Travel Rule threshold in the UAE?

The Travel Rule applies to qualifying virtual asset transfers at or above AED 3,500. At or above that figure, both the originating and beneficiary VASP must obtain and hold the required originator and beneficiary information. Verification is also required, regardless of value, where suspicious activity is identified.

Do VASPs need to register with goAML in the UAE?

Yes. Every VASP must register on the goAML portal run by the UAE Financial Intelligence Unit. Registration is what allows the firm to file suspicious transaction reports and the other reports the system requires. Holding a licence without completing goAML registration is a compliance gap a supervisor will flag.

Which regulator licenses crypto companies in the UAE?

It depends on location. VARA licenses virtual asset firms in mainland Dubai and most Dubai free zones, the FSRA covers ADGM, the DFSA covers DIFC, and the SCA is relevant where a token behaves like a security. CBUAE sets the overarching federal AML framework that applies across all of them.

Are privacy coins allowed under Dubai’s Travel Rule?

No. Dubai’s framework prohibits VASPs from executing transfers involving privacy or anonymity-enhancing tokens. The obfuscation features of these assets defeat the originator and beneficiary data requirements that the Travel Rule depends on, so supporting them creates an unmanageable risk.

What are the penalties for AML breaches by VASPs in the UAE?

Under Federal Decree-Law No. 10 of 2025, legal persons face fines from AED 5 million up to AED 100 million, and penalties can be linked to the value of the criminal property involved. Courts may also order dissolution of the entity or closure of premises in serious cases, and proceedings do not lapse with time.

Do VASPs have to apply enhanced due diligence to self-hosted wallets?

Yes. Transfers to or from self-hosted, or unhosted, wallets call for enhanced due diligence. That means additional customer identification and source-of-funds verification on top of standard onboarding checks, because the receiving or sending wallet is not controlled by a regulated institution.

How does Federal Decree-Law No. 10 of 2025 change things for VASPs?

The 2025 law, in force since 14 October 2025, confirms that VASPs carry the same AML, CFT, and proliferation-financing obligations as financial institutions. It replaced the earlier 2018 law, raised the penalty ceiling, and embedded the Travel Rule into the framework, so a lighter-touch reading of crypto compliance is no longer available.

Related Reading

Closing Note

Virtual asset compliance in the UAE has matured into one of the most demanding parts of the AML framework, and the firms that treat it that way are the ones that keep their licences and their banking relationships. A VASP that maps its regulator correctly, builds a real risk-based programme, implements the Travel Rule for how crypto actually moves, and reports through goAML on time is in a defensible position for the FATF mutual evaluation and beyond. If you want that programme reviewed, built, or audited, ADZ’s compliance team can help.

Disclaimer: This article is general information for UAE businesses and does not constitute legal advice. Regulatory requirements change and apply differently to each firm. Verify your obligations with your supervisor or a qualified adviser. Official sources: VARA, CBUAE, FATF, and goAML (UAE FIU).

Scroll to Top