Crypto AML Compliance in the UAE: What Every VASP Has to Build

At Ontrax Risk and Compliance Ltd., we deliver tailored Anti-Money Laundering (AML) compliance solutions that protect your business, ensure regulatory alignment, and foster long-term credibility. Whether you’re a financial institution, a crypto business, or part of a DNFBP sector, our specialized services are built to meet your unique compliance challenges.

Crypto AML compliance UAE framework for VASPs across VARA, DFSA, FSRA, CBUAE and CMA

There is a version of this conversation we have almost every week. A crypto firm has a licence, or is close to one, and someone senior asks whether the AML framework is in good shape. The answer usually is that it was built for a different regulator, or for a bank, or downloaded from somewhere and lightly edited.

That was survivable a couple of years ago. Crypto AML compliance is no longer a document exercise. Crypto AML compliance UAE regulators expect in 2026 is specific, testable, and enforced by a supervisor who will ask to see the system rather than the policy.

Short answer:  Crypto AML compliance in the UAE means meeting Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025, plus the rulebook of whichever of five regulators licenses you. For most Dubai firms that is VARA, whose Rulebook version 2.0 has applied since 19 June 2025. The obligations include a virtual-asset-specific risk assessment, KYC with wallet attribution, Travel Rule data on transfers at or above AED 3,500, sanctions screening, blockchain analytics, an appointed MLRO, goAML registration, and eight-year record retention.

Crypto AML compliance UAE: which regulator supervises you?

Start here, because every other crypto AML compliance decision follows from it, and it is where most firms lose time.

crypto AML compliance UAE

The UAE runs a multi-layered structure that has no real equivalent elsewhere. The EU has MiCA. Singapore has MAS. The UAE has five supervisors, and which one applies depends on where you are incorporated and what your token does.

RegulatorCoversFramework
VARAThe Emirate of Dubai, excluding the DIFC — mainland and most Dubai free zonesVirtual Assets and Related Activities Regulations 2023, Rulebook v2.0 in force since 19 June 2025
DFSAThe DIFCCrypto Token Framework — activity permitted only in relation to Recognised Crypto Tokens
FSRAADGMFSMR 2015, COBS Section 17 and the AML Rulebook, with firms maintaining their own Accepted Virtual Assets list
CBUAEPayment tokens and stablecoins, federallyPayment Token Services Regulation 2024 — dirham-backed stablecoins licensed, algorithmic tokens banned
CMAFederal securities and investment tokensSucceeded the Securities and Commodities Authority on 1 January 2026 under Federal Decree-Laws Nos 32 and 33 of 2025

A detail worth catching: the SCA no longer exists in this role. The Capital Market Authority took over federally on 1 January 2026. A great deal of published guidance — including material dated this year — still names the SCA. If a provider’s framework references it as your current supervisor, that framework has not been reviewed recently.

Two practical points people miss. Free zone authorities like DMCC, IFZA and Meydan license the corporate vehicle, not the activity — VARA or the relevant financial services regulator is still your conduct supervisor. And a DIFC entity needs two things: formation through the DIFC Authority and authorisation from the DFSA.

What does the federal AML law require of VASPs?

Direct answer:  Federal Decree-Law No. 10 of 2025, in force since 14 October 2025, brought virtual asset service providers directly and explicitly into the UAE AML perimeter rather than addressing them by implication. VASPs now carry the same core obligations as a bank: risk assessment, customer due diligence, screening, monitoring, suspicious transaction reporting through goAML, record keeping and an independent audit function.

This is the crypto AML compliance change that matters most, and it is easy to underrate because it sounds technical. Under the previous framework, virtual asset businesses were pulled in through a patchwork. Now the statute names them.

Cabinet Resolution No. 134 of 2025, effective 14 December 2025, then supplied the executive regulations — including the federal Virtual Asset Travel Rule that now sits above the emirate-level rules.

The practical consequence is that your regulator’s rulebook is a floor, not a ceiling. VARA compliance does not discharge the federal duty; it sits on top of it. An AML risk assessment written only against a VARA rulebook will be missing the federal layer, and vice versa.

The Travel Rule in crypto AML compliance: AED 3,500, and where it does not apply

crypto AML compliance UAE

Direct answer:  Under the VARA and federal frameworks, the Travel Rule applies to qualifying virtual asset transfers at or above AED 3,500. Both the originating and beneficiary VASP must obtain and hold the required originator and beneficiary information. ADGM applies no threshold at all — under the FSRA framework, Travel Rule data accompanies every transfer regardless of value.

That divergence is the single most useful crypto AML compliance point in this article if you operate across more than one UAE jurisdiction. A firm with a Dubai entity and an ADGM entity cannot run one threshold configuration across both. We have seen this configured once, globally, at AED 3,500, and it under-complies on the ADGM side from day one.

Verification is also required regardless of value where suspicious activity is identified. The threshold governs routine transfers, not suspicion.

crypto AML compliance UAE

Mechanically, the originating VASP collects and transmits the required data, the beneficiary VASP receives and verifies it, and where the information cannot be provided or the risk cannot be mitigated, the transaction is declined, delayed, or the assets returned. What you cannot do is execute first and reconcile the data afterwards.

VARA issued a circular to Dubai VASPs on 24 February 2026 setting out supervisory expectations for implementing the UAE Virtual Asset Travel Rule under Cabinet Decision 134 of 2025. Supervisory examinations now treat Travel Rule implementation as a primary indicator of whether the wider AML programme works. The gap examiners find is rarely awareness of the threshold — it is the distance between a policy that adopts it and a system that enforces it.

Four things a UAE VASP simply cannot do

crypto AML compliance UAE

Most crypto AML compliance obligations are risk-based: assess, mitigate, document. A handful in this sector are not. They are flat bans, and treating them as risk factors to be managed is a serious error.

  1. Privacy tokens. Dubai’s framework prohibits VASPs from executing virtual asset transfers involving privacy or anonymity-enhancing tokens, because their obfuscation features cannot be reconciled with Travel Rule obligations. The prohibition attaches to executing transfers, not to every licensed activity.
  2. Unregulated counterparties. Counterparty VASPs must be appropriately regulated in their home jurisdiction, and transfers to unregulated counterparties are prohibited. This makes counterparty due diligence a gating control rather than a periodic review.
  3. Commingled client assets. Client virtual assets must be segregated from the firm’s own and held on a one-to-one basis. This is a custody rule with direct AML consequences, because commingling destroys transaction attribution.
  4. Unlicensed marketing. VARA’s marketing regulations reach all crypto market participants promoting into Dubai, including firms based in ADGM or the DIFC where marketing is directed at onshore UAE residents, and including firms VARA does not license. Marketing is one of the most common ways an offshore business acquires a UAE regulatory problem.

Record keeping: eight years, not five

crypto AML compliance UAE

Here is a quiet crypto AML compliance requirement that catches firms out. The federal baseline for reporting entities is five years. VASPs under the Dubai framework must maintain customer records for a minimum of eight.

If your AML manual was adapted from a generic UAE template — and many are — it almost certainly says five. That three-year gap is invisible until an examiner asks for records from year six, and it is entirely avoidable at the policy development stage. It also has architecture consequences: eight years of customer and transaction records is a storage and retrieval design decision, not a filing preference.

What a crypto AML compliance programme has to contain

crypto AML compliance UAE

Crypto AML compliance breaks into twelve components, and the licensing process will test every one of them. Taking them in the order they usually get built:

ComponentWhat it means for a virtual asset business
Enterprise risk assessmentWritten against virtual asset typologies — mixers, chain-hopping, unhosted wallets, cross-chain bridges — not a bank template with the word crypto inserted
AML policyMapped to your specific regulator’s rulebook and the federal law together, not one or the other
KYC and wallet attributionIdentifying the customer and linking them to the wallets they control. Traditional KYC stops at the person; crypto KYC has to reach the address
Sanctions and PEP screeningScreening people and screening addresses. Both, continuously, with an audit trail
Blockchain analyticsExposure scoring on counterparty addresses. This is what a supervisor means by knowing your transaction
Travel Rule solutionTechnology plus counterparty due diligence plus procedures for declining. All three, not just the vendor
Transaction monitoringTuned to on-chain behaviour: structuring below AED 3,500, rapid in-out patterns, chain-hopping, unhosted wallet concentration
MLROA named individual with authority, resourcing and board access. The role is not a title
goAML registrationMandatory. Holding a licence without completing goAML registration is a gap a supervisor will flag immediately
Record retentionEight years for Dubai VASP customer records, retrievable on request
TrainingRole-specific and evidenced. Front-line staff are tested by being asked, not by document review
Independent auditA separate firm testing whether all of the above actually operates

Two of these are worth separating out. KYC for virtual asset businesses is genuinely different from KYC anywhere else, because identity has to be connected to on-chain addresses to mean anything. And transaction monitoring and screening tuned to fiat payment patterns will produce an alert queue that is simultaneously enormous and empty of signal.

Who has to be your MLRO, and can it be outsourced?

Direct answer:  Every UAE VASP must appoint an MLRO with genuine authority, adequate resourcing and a direct reporting line to senior management. The role can be outsourced or provisioned, and frequently is at earlier-stage firms, but the individual normally needs to be UAE resident and must have enough engagement time to understand the business rather than simply sign filings.

Crypto AML compliance has a hiring problem. There are more licensed virtual asset entities in the UAE than there are people who have run a crypto AML function through a supervisory examination. That pushes firms toward provisioned arrangements, which is a reasonable answer as long as the substance is real.

What supervisors look for is whether the MLRO can actually stop something. An MLRO provision arrangement where the officer has no authority to decline a transfer, no access to the board, and no time booked beyond quarterly returns is an MLRO in name only — and that is visible in a review within an hour. If you are in the DIFC or ADGM, the MLRO framework for those centres adds rulebook-specific reporting duties on top of the federal ones.

One structural constraint worth planning around: whoever provides your outsourced AML function cannot also perform your independent AML audit. Independence rules out reviewing your own work, and a supervisor will spot the conflict immediately.

How to get your crypto AML compliance in shape

If you are licensed, or in application, a sensible crypto AML compliance sequence looks like this.

  1. Confirm your regulator, in writing. Not your free zone. Your conduct supervisor. Everything downstream depends on the answer, and a surprising number of firms have it wrong.
  2. Open your AML policy and search for three things. “SCA” as your current supervisor, “20 of 2018” as the governing law, and “five years” as your retention period. Each one dates the document.
  3. Test your Travel Rule threshold configuration. Specifically per-entity. If you operate in Dubai and ADGM, one global threshold is wrong.
  4. Check counterparty due diligence is a gate, not a review. Can your system actually block a transfer to an unregulated counterparty before it executes?
  5. Confirm goAML registration is complete. Not started. Complete, with the ability to file.
  6. Book an independent review before your supervisor books one. Findings you generate yourself come with a timeline you control.

If steps two and three surface more than you expected, that is normal and it is fixable. A focused crypto AML compliance gap analysis takes weeks rather than months, and it is considerably cheaper than remediating under examination.

What crypto AML compliance failures actually cost

Article 17 of Federal Decree-Law No. 10 of 2025 provides for administrative fines from AED 10,000 to AED 5,000,000 per violation. Per violation is the phrase to sit with — these are not capped at one penalty per examination, and a systemic control failure generates findings across every affected transfer.

The regulatory consequences run wider than fines. VARA can impose licence conditions, issue cease-and-desist directions, and take licence action. For a virtual asset business, a licence condition restricting an activity is usually more damaging than the fine attached to it, because it lands in the public record and in every counterparty’s due diligence file.

Then there is the commercial layer, which firms consistently underestimate. Banking relationships for virtual asset businesses are hard-won and easily lost. A crypto AML compliance finding surfaces in banking questionnaires, in counterparty VASP due diligence, in institutional client onboarding and in any funding round where a buyer’s advisers read the compliance file. The fine is a line item. The de-banking is existential.

The pattern we see: the failures that generate enforcement are rarely exotic. They are a Travel Rule threshold configured once and never revisited, counterparty checks that run after execution instead of before, and screening that stops at onboarding. All three are cheap to fix in advance and expensive to explain afterwards.

The findings we see most often

Across crypto AML compliance reviews, the same gaps recur:

  • An AML policy adapted from a bank or generic UAE template, with fiat typologies and a five-year retention period
  • A single Travel Rule threshold applied globally across entities in different jurisdictions
  • Counterparty VASP due diligence performed periodically rather than before each new relationship goes live
  • Wallet attribution missing entirely — the customer is identified, but their addresses are not linked to them
  • Blockchain analytics purchased but not wired into any decision, so exposure scores are generated and ignored
  • Screening at onboarding with no ongoing rescreening against updated sanctions lists
  • goAML registration started but never completed
  • An MLRO with a title, no authority to decline a transfer, and no board access
  • Documents citing the SCA, Federal Decree-Law No. 20 of 2018, or a superseded VARA rulebook version

Most of these are design problems rather than effort problems. They come from building crypto AML compliance against the wrong reference — a bank framework, an older rulebook, or another jurisdiction’s rules — and then maintaining it faithfully. A single independent AML audit surfaces the whole list in a few weeks.

Crypto AML compliance UAE: frequently asked questions

What is crypto AML compliance in the UAE?

Crypto AML compliance in the UAE is the set of anti-money laundering obligations applying to virtual asset service providers under Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025, together with the rulebook of the licensing regulator. It covers risk assessment, KYC and wallet attribution, screening, blockchain analytics, Travel Rule data, monitoring, goAML reporting, retention, training and independent audit.

Which regulator supervises crypto businesses in the UAE?

One of five, depending on location and token type: VARA for the Emirate of Dubai excluding the DIFC, the DFSA for the DIFC, the FSRA for ADGM, the CBUAE for payment tokens and stablecoins, and the CMA federally for securities and investment tokens. The CMA succeeded the SCA on 1 January 2026.

What is the Travel Rule threshold in the UAE?

AED 3,500 for qualifying virtual asset transfers under the VARA and federal frameworks. At or above that value, both the originating and beneficiary VASP must obtain and hold required originator and beneficiary information. ADGM applies no threshold — data accompanies every transfer.

Does the Travel Rule apply below AED 3,500?

Reduced information requirements may apply to routine transfers below the threshold, but verification is required regardless of value where suspicious activity is identified. Systems must also detect deliberate structuring just below the line.

Can UAE VASPs handle privacy coins?

No. Dubai’s framework prohibits VASPs from executing virtual asset transfers involving privacy or anonymity-enhancing tokens. The prohibition applies to executing transfers and does not extend to other licensed activities that do not involve such execution.

How long must a VASP keep records in the UAE?

Dubai VASPs must maintain customer records for a minimum of eight years, longer than the five-year federal baseline that applies to other reporting entities. Policies adapted from generic UAE templates commonly get this wrong.

Do VASPs need to register on goAML?

Yes. Every VASP must register on the goAML portal operated by the UAE Financial Intelligence Unit in order to file suspicious transaction reports. Holding a licence without completing goAML registration is a compliance gap supervisors flag.

Does a VASP need an MLRO?

Yes. An MLRO must be appointed with real authority, resourcing and a reporting line to senior management. The role may be outsourced, but the individual normally needs to be UAE resident and genuinely engaged with the business.

Is VARA compliance enough on its own?

No. VARA’s rulebook sits on top of the federal AML framework rather than replacing it. A programme built only against VARA will be missing federal obligations, and one built only against federal law will miss the emirate-specific rules.

Can we transfer to any counterparty VASP?

No. Counterparty VASPs must be appropriately regulated in their home jurisdiction, and transfers to unregulated counterparties are prohibited. Counterparty due diligence needs to function as a pre-transaction gate.

Do ADGM and DIFC firms need to follow VARA rules?

Not for licensing or conduct, which sit with the FSRA and DFSA respectively. But VARA’s marketing regulations can reach firms in those centres where marketing is directed at onshore UAE residents.

Does a VASP need an independent AML audit?

Yes. The independent audit function under Article 21 of Cabinet Resolution No. 134 of 2025 applies to VASPs as it does to financial institutions and DNFBPs, and the firm operating your AML function cannot also audit it.

What are the penalties for crypto AML failures?

Article 17 of Federal Decree-Law No. 10 of 2025 provides for administrative fines from AED 10,000 to AED 5,000,000 per violation. Regulators can also impose licence conditions, cease-and-desist directions and licence action.

How long does it take to build a VASP AML programme?

Three to five months from a standing start to a defensible framework, assuming management attention and a technology budget. Travel Rule and blockchain analytics integration is usually the long pole.

Crypto AML compliance: where this leaves you

The UAE has built one of the most developed virtual asset regimes anywhere, and crypto AML compliance UAE standards have risen with it. More than a hundred licensed entities now operate across the five regimes. The trade-off for that speed is a framework that changes often and differs by jurisdiction in ways that are easy to miss and expensive to get wrong.

Almost everything in this article is less than eighteen months old. The federal law, the executive regulations, the Travel Rule circular, the VARA rulebook version, the regulator that supervises federal securities tokens — all of it postdates most of the AML frameworks currently in use. That is the gap worth closing.

Ontrax provides crypto AML compliance advisory from DIFC, Dubai, for exchanges, brokers, custodians, wallet providers and token issuers across VARA, DFSA, FSRA and the federal regimes. We build to your actual supervisor, not to a template, and we tell you plainly where the frameworks diverge.

To scope a gap analysis, or to talk through which regulator applies to your model, get in touch.

Primary sources and further reading

Leave a Reply

Your email address will not be published. Required fields are marked *

At Ontrax Risk and Compliance Ltd., we deliver tailored Anti-Money Laundering (AML) compliance solutions that protect your business, ensure regulatory alignment, and foster long-term credibility. we ensure your business stays compliant with evolving AML regulations. Our expert-driven AML solutions help you mitigate risks, prevent financial crime, and meet global compliance standards.

NEWSLETTER

    Quick Links
    LOCATION
    Contact Us
    © 2026 Ontrax Risk and Compliance Ltd. | All Rights Reserved. Designed & Developed by Inspia Technologies