One Country, Five Regulators: What VASPs Actually Need in Their AML/CFT Policy to Operate in the UAE

One Country, Five Regulators: What VASPs Actually Need in Their AML/CFT Policy to Operate in the UAE

The United Arab Emirates has positioned itself as the world’s most ambitious hub for virtual assets — and simultaneously, one of the most complex compliance landscapes any crypto founder or compliance officer will ever navigate. With five distinct regulatory authorities overseeing virtual asset service providers (VASPs), the question isn’t simply “Are we licensed?” but rather “Does our AML/CFT policy survive scrutiny from every authority that can touch us?”

Federal Decree-Law No. 10/2025 changed everything. VASPs are no longer lightly supervised startups operating in regulatory grey zones. They are now bank-grade AML/CFT subjects, held to standards that mirror — and in some respects exceed — what the UAE expects from traditional financial institutions. This article is a practical roadmap for founders, MLROs, and compliance leads who need to understand exactly what “compliant” means in 2025 and beyond.

 

 

The Multi-Regulator Reality: Five Authorities, One Country

Most jurisdictions have one financial regulator — maybe two. The UAE has five bodies that can assert authority over VASPs, each with its own licensing regime, rulebook, and supervisory temperament. Understanding who does what isn’t academic; it’s existential for your compliance program.

Regulator Jurisdiction / Scope Key Focus for VASPs
VARA Dubai (onshore, excl. DIFC) Full VA activity regulation; BRA, Travel Rule, on-chain monitoring
ADGM / FSRA Abu Dhabi Global Market (free zone) FSMR-based framework; institutional-grade custody & exchange licensing
DFSA DIFC (Dubai free zone) Recognised Crypto Token regime; firm-led suitability shifting Jan 2026
CMA (SCA) Federal — all emirates (onshore, excl. free zones) New federal Virtual Assets Framework (April 2026); Green List
CBUAE Federal — payment tokens, stablecoins Payment token services; AED-denominated stablecoin oversight
⚠️ Risk Alert

 

Picking your licensing jurisdiction is no longer just a legal formality — it’s a commercial decision that determines your customer base, product scope, and the entire architecture of your AML/CFT policy. Multi-licensed VASPs face the compounding burden of satisfying multiple rulebooks simultaneously, and gaps between frameworks create real supervisory risk.

The Federal AML/CFT Backbone Every VASP Must Build On

Regardless of which regulator issues your license, Federal Decree-Law No. 10/2025 and its companion Cabinet Resolution No. 134/2025 set the minimum floor for every VASP operating anywhere in the UAE. These aren’t optional overlays — they’re the bedrock your compliance program must be anchored to.

What the federal framework demands:

  • Full alignment with FATF Recommendations 15 and 16 — the VA-specific standards including the Travel Rule
  • goAML registration and active reporting to the UAE Financial Intelligence Unit (FIU)
  • Business Risk Assessment (BRA) that is documented, board-approved, and updated at minimum quarterly
  • Suspicious Activity/Transaction Reports (SAR/STR) filed through goAML with no exceptions or workarounds
  • 48-hour notification rule to regulators for material compliance breaches or system failures

“Federal Decree-Law No. 10/2025 has effectively erased the distinction between traditional financial institutions and VASPs for AML/CFT purposes. If you’re handling virtual assets in the UAE, you are held to the same standard as a bank.”— Compliance Advisory, UAE FIU Guidance (2025)

 

 

What “Good” Actually Looks Like: Core Provisions of a Compliant AML/CFT Policy

This is the section you’ll want to bookmark. Below is a practical, shareable checklist of what your AML/CFT policy must contain to survive regulatory scrutiny in the UAE — across any of the five authorities.

1
Governance Structure

 

Appoint an MLRO and a COMLRO (deputy). Ensure Board-level AML/CFT oversight via an Audit or Risk Committee. All senior management must pass fit-and-proper assessments — not just the MLRO.

2
Business Risk Assessment (BRA)

 

Implement the three lines of defence model. Update quarterly. Treat technology and AI risk as its own risk category — not a footnote under operational risk.

3
CDD/EDD with Customer Risk Assessment

 

Tiered due diligence — simplified for low-risk, enhanced for high-risk. Include specific procedures for unhosted wallets: document the wallet address, assess counterparty risk, and apply EDD where appropriate.

4
Customer Identification Program (CIP)

 

Cover natural persons, legal entities, and DAOs. Yes — if you onboard a DAO treasury or a DAO-governed protocol participant, your CIP must address how you identify the beneficial owners behind that structure.

5
PEP & Sanctions Screening + Travel Rule Compliance

 

Automated screening against UAE, UN, OFAC, and EU sanctions lists. Travel Rule data fields (originator name, account number, beneficiary details) must be transmitted for transactions above the applicable threshold. Document your workflow end-to-end.

 
Now Enrolling

Master AML, AI & Financial Crime Compliance

CAMS-aligned, practitioner-led courses built for compliance professionals who want to stay ahead of the technology reshaping their profession.

Explore Courses →

 
6
Transaction Monitoring, SARs, and Everything Else

 

Implement both on-chain (KYT — Know Your Transaction) and off-chain monitoring. SAR/STR procedures via goAML. Tipping-off controls. Exit and blacklisting management. Record-keeping (minimum 5 years). A documented training program. Independent audit/testing. Jurisdiction-specific annexes if you hold multiple licenses.

💡 Key Insight

 

If you hold licenses from both VARA and ADGM, your AML/CFT policy cannot be a single monolithic document. You need a federal core with jurisdiction-specific annexes that address each regulator’s unique requirements — from VARA’s on-chain monitoring expectations to ADGM’s FSMR-aligned custody controls. The federal framework is the floor; each regulator builds a different ceiling.

 

 

The 2026 Shift Points VASPs Cannot Afford to Ignore

Compliance is not a snapshot — it’s a moving target. Several regulatory changes taking effect in late 2025 and into 2026 will materially reshape what VASPs must demonstrate to their regulators.

 

January 2026 — DFSA Firm-Led Token Suitability

The DFSA is shifting responsibility for token suitability assessments from the regulator to the firm. This means VASPs operating in the DIFC must create and maintain internal frameworks for evaluating which Recognised Crypto Tokens they can offer — with full documentation trails and board sign-off.

 

 

2025–2026 — VARA BRA Thematic Review

VARA is conducting thematic reviews of VASPs’ Business Risk Assessments and has made clear its expectation of a mature three-lines-of-defence model. VASPs whose BRAs lack depth, quarterly cadence, or board-level engagement should expect supervisory action.

 

 

April 2026 — CMA Federal Virtual Assets Framework & Green List

The CMA (formerly SCA) will launch a comprehensive federal framework for VASPs operating onshore outside free zones. The “Green List” will define approved virtual assets. VASPs not on it — or not aligned with it — will face restricted operations.

 

AED 5M
Minimum penalty for legal persons under Federal Decree-Law 10/2025
AED 100M
Maximum penalty for serious AML/CFT violations
48 hrs
Mandatory notification window for material compliance breaches
⚠️ Risk Alert

 

The penalty range under the new federal law — AED 5 million to AED 100 million for legal persons — represents a tenfold increase from previous regimes. Criminal liability for individuals, including senior management and compliance officers, is now explicitly codified. This is not theoretical risk.

✅ Best Practice

 

Build your AML/CFT policy as a modular framework: a federal core document covering Decree-Law 10/2025 requirements, with separate jurisdiction-specific annexes for each regulator. This approach lets you update individual annexes when VARA, DFSA, or CMA requirements change — without rewriting the entire policy. Include a version control matrix and a regulatory change log that is reviewed monthly.

 

 

Frequently Asked Questions

❓ Can a single AML/CFT policy cover multiple UAE regulatory licenses?
It can — but only if structured correctly. You need a federal core that addresses Decree-Law 10/2025 and Cabinet Resolution 134/2025, with separate annexes tailored to each regulator’s specific requirements (e.g., VARA’s on-chain monitoring rules vs. DFSA’s token suitability framework). A flat, single-document approach will fail inspection.
❓ How does the Travel Rule apply to unhosted wallets in the UAE?
Transactions involving unhosted (self-hosted) wallets require enhanced due diligence. VASPs must document the wallet address, assess the counterparty risk, and in many cases apply the same Travel Rule data collection requirements to the originator side. VARA has been particularly explicit that “inability to identify the counterparty” is not an acceptable compliance position — it’s grounds for blocking the transaction.
❓ What does the 48-hour notification rule cover?
Under the new federal framework, VASPs must notify their primary regulator within 48 hours of discovering a material compliance breach, significant system failure affecting AML/CFT controls, or any event that could impact their ability to meet regulatory obligations. This includes cyber incidents that compromise transaction monitoring or customer screening capabilities.
❓ Do I need to include DAOs in my Customer Identification Program?
Yes. If your VASP onboards a DAO treasury, accepts funds from a DAO-governed protocol, or provides services to entities structured as DAOs, your CIP must include procedures for identifying the ultimate beneficial owners behind that structure. The absence of a traditional corporate form does not exempt you from CDD obligations.

Conclusion: This Is Not a Template Exercise

Building an AML/CFT policy that survives scrutiny across the UAE’s multi-regulator landscape requires more than downloading a template and filling in blanks. It demands a deep understanding of the interplay between federal law, free-zone-specific rulesets, and the practical expectations of each supervisory authority.

The VASPs that will thrive in the UAE’s next chapter are the ones that treat compliance as architecture — modular, auditable, responsive to regulatory change, and embedded into the business rather than bolted on. The penalties for getting it wrong have never been higher. But the opportunity for those who get it right — operating in one of the world’s most dynamic digital asset ecosystems with genuine regulatory credibility — has never been greater either.

💡 Next Step

 

If you’re building or updating your AML/CFT framework and need clarity on how your policy stacks up against current VARA, ADGM, DFSA, and CMA requirements, consider commissioning a gap assessment — a structured review that maps your existing controls against each regulator’s expectations and identifies exactly where remediation is needed before your next supervisory engagement.

Compliance Advisory

Need Expert AML/CFT & RegTech Guidance?

17+ years across FATF, CBUAE, VARA & NRB. Visit our website for consultancy services tailored to your organization.

“Your compliance programme looks good on paper.
But will it survive a regulatory examination?”

Get Consultancy →

Leave a Reply

Your email address will not be published. Required fields are marked *