One Country, Five Regulators: What VASPs Actually Need in Their AML/CFT Policy to Operate in the UAE
The United Arab Emirates has positioned itself as the world’s most ambitious hub for virtual assets — and simultaneously, one of the most complex compliance landscapes any crypto founder or compliance officer will ever navigate. With five distinct regulatory authorities overseeing virtual asset service providers (VASPs), the question isn’t simply “Are we licensed?” but rather “Does our AML/CFT policy survive scrutiny from every authority that can touch us?”
Federal Decree-Law No. 10/2025 changed everything. VASPs are no longer lightly supervised startups operating in regulatory grey zones. They are now bank-grade AML/CFT subjects, held to standards that mirror — and in some respects exceed — what the UAE expects from traditional financial institutions. This article is a practical roadmap for founders, MLROs, and compliance leads who need to understand exactly what “compliant” means in 2025 and beyond.
◆
The Multi-Regulator Reality: Five Authorities, One Country
Most jurisdictions have one financial regulator — maybe two. The UAE has five bodies that can assert authority over VASPs, each with its own licensing regime, rulebook, and supervisory temperament. Understanding who does what isn’t academic; it’s existential for your compliance program.
Picking your licensing jurisdiction is no longer just a legal formality — it’s a commercial decision that determines your customer base, product scope, and the entire architecture of your AML/CFT policy. Multi-licensed VASPs face the compounding burden of satisfying multiple rulebooks simultaneously, and gaps between frameworks create real supervisory risk.
The Federal AML/CFT Backbone Every VASP Must Build On
Regardless of which regulator issues your license, Federal Decree-Law No. 10/2025 and its companion Cabinet Resolution No. 134/2025 set the minimum floor for every VASP operating anywhere in the UAE. These aren’t optional overlays — they’re the bedrock your compliance program must be anchored to.
What the federal framework demands:
- Full alignment with FATF Recommendations 15 and 16 — the VA-specific standards including the Travel Rule
- goAML registration and active reporting to the UAE Financial Intelligence Unit (FIU)
- Business Risk Assessment (BRA) that is documented, board-approved, and updated at minimum quarterly
- Suspicious Activity/Transaction Reports (SAR/STR) filed through goAML with no exceptions or workarounds
- 48-hour notification rule to regulators for material compliance breaches or system failures
“Federal Decree-Law No. 10/2025 has effectively erased the distinction between traditional financial institutions and VASPs for AML/CFT purposes. If you’re handling virtual assets in the UAE, you are held to the same standard as a bank.”— Compliance Advisory, UAE FIU Guidance (2025)
◆
What “Good” Actually Looks Like: Core Provisions of a Compliant AML/CFT Policy
This is the section you’ll want to bookmark. Below is a practical, shareable checklist of what your AML/CFT policy must contain to survive regulatory scrutiny in the UAE — across any of the five authorities.
Appoint an MLRO and a COMLRO (deputy). Ensure Board-level AML/CFT oversight via an Audit or Risk Committee. All senior management must pass fit-and-proper assessments — not just the MLRO.
Implement the three lines of defence model. Update quarterly. Treat technology and AI risk as its own risk category — not a footnote under operational risk.
Tiered due diligence — simplified for low-risk, enhanced for high-risk. Include specific procedures for unhosted wallets: document the wallet address, assess counterparty risk, and apply EDD where appropriate.
Cover natural persons, legal entities, and DAOs. Yes — if you onboard a DAO treasury or a DAO-governed protocol participant, your CIP must address how you identify the beneficial owners behind that structure.
Automated screening against UAE, UN, OFAC, and EU sanctions lists. Travel Rule data fields (originator name, account number, beneficiary details) must be transmitted for transactions above the applicable threshold. Document your workflow end-to-end.
Implement both on-chain (KYT — Know Your Transaction) and off-chain monitoring. SAR/STR procedures via goAML. Tipping-off controls. Exit and blacklisting management. Record-keeping (minimum 5 years). A documented training program. Independent audit/testing. Jurisdiction-specific annexes if you hold multiple licenses.
If you hold licenses from both VARA and ADGM, your AML/CFT policy cannot be a single monolithic document. You need a federal core with jurisdiction-specific annexes that address each regulator’s unique requirements — from VARA’s on-chain monitoring expectations to ADGM’s FSMR-aligned custody controls. The federal framework is the floor; each regulator builds a different ceiling.
◆
The 2026 Shift Points VASPs Cannot Afford to Ignore
Compliance is not a snapshot — it’s a moving target. Several regulatory changes taking effect in late 2025 and into 2026 will materially reshape what VASPs must demonstrate to their regulators.
January 2026 — DFSA Firm-Led Token Suitability
The DFSA is shifting responsibility for token suitability assessments from the regulator to the firm. This means VASPs operating in the DIFC must create and maintain internal frameworks for evaluating which Recognised Crypto Tokens they can offer — with full documentation trails and board sign-off.
2025–2026 — VARA BRA Thematic Review
VARA is conducting thematic reviews of VASPs’ Business Risk Assessments and has made clear its expectation of a mature three-lines-of-defence model. VASPs whose BRAs lack depth, quarterly cadence, or board-level engagement should expect supervisory action.
April 2026 — CMA Federal Virtual Assets Framework & Green List
The CMA (formerly SCA) will launch a comprehensive federal framework for VASPs operating onshore outside free zones. The “Green List” will define approved virtual assets. VASPs not on it — or not aligned with it — will face restricted operations.
The penalty range under the new federal law — AED 5 million to AED 100 million for legal persons — represents a tenfold increase from previous regimes. Criminal liability for individuals, including senior management and compliance officers, is now explicitly codified. This is not theoretical risk.
Build your AML/CFT policy as a modular framework: a federal core document covering Decree-Law 10/2025 requirements, with separate jurisdiction-specific annexes for each regulator. This approach lets you update individual annexes when VARA, DFSA, or CMA requirements change — without rewriting the entire policy. Include a version control matrix and a regulatory change log that is reviewed monthly.
◆
Frequently Asked Questions
Conclusion: This Is Not a Template Exercise
Building an AML/CFT policy that survives scrutiny across the UAE’s multi-regulator landscape requires more than downloading a template and filling in blanks. It demands a deep understanding of the interplay between federal law, free-zone-specific rulesets, and the practical expectations of each supervisory authority.
The VASPs that will thrive in the UAE’s next chapter are the ones that treat compliance as architecture — modular, auditable, responsive to regulatory change, and embedded into the business rather than bolted on. The penalties for getting it wrong have never been higher. But the opportunity for those who get it right — operating in one of the world’s most dynamic digital asset ecosystems with genuine regulatory credibility — has never been greater either.
If you’re building or updating your AML/CFT framework and need clarity on how your policy stacks up against current VARA, ADGM, DFSA, and CMA requirements, consider commissioning a gap assessment — a structured review that maps your existing controls against each regulator’s expectations and identifies exactly where remediation is needed before your next supervisory engagement.
Need Expert AML/CFT & RegTech Guidance?
17+ years across FATF, CBUAE, VARA & NRB. Visit our website for consultancy services tailored to your organization.
“Your compliance programme looks good on paper.
But will it survive a regulatory examination?”
