The UAE has established one of the region’s most developed frameworks for regulating virtual assets and preventing financial crime. For businesses operating in this sector, AML compliance in the UAE is not an optional administrative exercise. It is a fundamental licensing and operational requirement.
Whether you are establishing a crypto exchange, providing custody services, facilitating transfers, or offering another regulated virtual asset activity, you must understand the interaction between federal UAE anti-money laundering laws, supervisory rulebooks, and reporting obligations.
This guide explains the main requirements for virtual asset service providers (VASPs), including VARA Dubai, the Central Bank of the UAE (CBUAE), the UAE Financial Intelligence Unit (FIU), the Travel Rule, and the new Federal Decree-Law No. (10) of 2025.
What Is AML Compliance for Virtual Assets in the UAE?
Anti-money laundering (AML) compliance refers to the policies, procedures, systems, and controls used to prevent businesses from being misused to conceal or transfer proceeds of crime. In the virtual asset sector, AML is closely connected with:
- Know Your Customer (KYC) procedures
- Customer due diligence (CDD)
- Beneficial ownership verification
- Enhanced due diligence (EDD)
- Sanctions and politically exposed person (PEP) screening
- Transaction and wallet monitoring
- Suspicious transaction reporting
- Record-keeping and regulatory audits
- Counter-terrorist financing (CFT) and proliferation financing controls
Virtual assets can move rapidly across borders and wallets. This creates notable virtual asset risks involving anonymity-enhancing technologies, mixers, high-risk exchanges, fraudulent investment schemes, and transactions involving sanctioned persons or jurisdictions.
For this reason, AML/CFT UAE virtual assets requirements are designed to provide traceability while supporting responsible innovation.
UAE AML Regulations: The Federal Legal Framework
The federal framework is the foundation of AML compliance throughout the UAE. The current framework includes:
- Federal Decree-Law No. (10) of 2025 on Anti-Money Laundering, Combating the Financing of Terrorism and Financing of Proliferation
- Cabinet Resolution No. (134) of 2025, which provides implementing measures
- Applicable UAE sanctions and targeted financial sanctions requirements
- Relevant FATF Recommendations and national supervisory guidance
These laws require obliged entities, including applicable VASPs, to take a risk-based approach. This means your controls should reflect the risks presented by your products, customers, jurisdictions, delivery channels, and transaction activity.
A VASP should not rely on a generic compliance manual. Your programme must be proportionate to your actual business model and capable of demonstrating effective implementation to the regulator.
Who Regulates VASPs in the UAE?
The relevant regulator depends on where your business operates and the nature of its activities.
The Virtual Assets Regulatory Authority (VARA) regulates and oversees the provision, use, and exchange of virtual assets in and from the Emirate of Dubai. Businesses should review the official VARA website and its regulatory rulebooks before offering services.
A company incorporated in Dubai is not automatically authorised to conduct regulated virtual asset activities. VASP licensing in the UAE must be assessed separately from company formation. Operating without the appropriate licence can result in enforcement action, reputational damage, account closures, and serious disruption to your business.
VARA Dubai Compliance Rules for Virtual Asset Providers
VARA’s framework includes the Virtual Assets and Related Activities Regulations 2023, the Compliance and Risk Management Rulebook, and other applicable rulebooks and directives. These requirements operate alongside the federal AML framework.
A VARA-regulated VASP will generally need to implement the following:
1. Governance and a Money Laundering Reporting Officer
A VASP must appoint a suitably qualified Money Laundering Reporting Officer (MLRO) in the UAE. The MLRO should have appropriate AML/CFT experience, authority, independence, access to relevant information, and a direct reporting line to senior management or the governing body.
The MLRO’s responsibilities may include:
- Maintaining the AML/CFT framework
- Reviewing internal suspicious activity escalations
- Filing reports through goAML
- Coordinating with VARA and other competent authorities
- Overseeing sanctions screening and transaction monitoring
- Delivering compliance training
- Maintaining regulatory records
A nominal appointment without sufficient resources is unlikely to satisfy the regulator. The MLRO must be able to perform the role effectively.
2. Business-wide risk assessment
Your VASP should conduct and regularly update an AML/CFT business risk assessment covering:
- Products and virtual asset activities
- Customer types and beneficial owners
- Geographic exposure
- Wallet and blockchain risks
- Transaction volumes and values
- Use of intermediaries and third-party providers
- Technology and remote onboarding channels
VARA published AML/CFT Business Risk Assessment Guidance on 11 June 2026, reinforcing the importance of a documented and evidence-based risk assessment.
3. CDD, EDD and beneficial ownership
Before establishing a business relationship, you should identify and verify the customer and understand the purpose and intended nature of the relationship. For corporate customers, this includes identifying the beneficial owner and understanding the ownership and control structure.
Enhanced due diligence may be necessary for:
- PEPs and their close associates
- Customers linked to higher-risk jurisdictions
- Complex or opaque ownership structures
- High-value or unusual transactions
- Privacy-enhancing tools or mixing services
- Customers using unlicensed or high-risk VASPs
If you cannot complete the required due diligence, you may need to refuse onboarding, restrict activity, or terminate the relationship. Proceeding despite unresolved identity or source-of-funds concerns could thwart your business plans and expose the company to enforcement risk.
The UAE AML Virtual Assets Travel Rule
The FATF Travel Rule requires relevant information about the originator and beneficiary to accompany certain virtual asset transfers. Its purpose is to improve transparency and enable VASPs and financial institutions to identify suspicious cross-border activity.
Under the current VARA framework, the Travel Rule applies to specified virtual asset transfers exceeding AED 3,500. A VASP should be prepared to:
- Determine whether the threshold is met
- Collect required originator information
- Collect required beneficiary information
- Verify information where required
- Transmit the information securely to the receiving VASP or financial institution
- Maintain records of the transfer and information exchange
- Apply risk-based controls where information is missing or inconsistent
The Travel Rule is not simply a form to complete manually. It requires an operational process, appropriate technology, counterparty procedures, and escalation rules. Your compliance team should also monitor updates from VARA, the CBUAE, the FIU, and the FATF.
goAML and UAE FIU Reporting Obligations
VASPs must establish procedures for identifying, investigating, escalating, and reporting suspicious activity. Reports are submitted to the UAE FIU through the goAML platform.
The UAE Financial Intelligence Unit provides access to reporting resources, guidance, and the goAML portal.
Your reporting framework should address:
- Who can raise an internal alert
- How alerts are assessed
- When the MLRO must be notified
- How supporting evidence is preserved
- When an STR or SAR is filed
- How requests from the FIU are handled
- How tipping-off risks are prevented
Suspicious reporting must be handled confidentially. You must not inform the customer that a report has been filed or disclose information in a way that could compromise an investigation.
The CBUAE’s AML/CFT Rulebook is particularly relevant to CBUAE-supervised institutions and provides important guidance on AML/CFT governance, customer due diligence, risk management, reporting, and virtual asset risks.
AML Compliance UAE Checklist for VASPs
Use this checklist as a starting point, not as a substitute for a tailored legal review:
- Confirm the correct regulatory perimeter and licence category
- Obtain the required VASP licence before conducting regulated activities
- Appoint a suitably qualified MLRO
- Complete and document an AML/CFT business risk assessment
- Create board-approved AML/CFT policies and procedures
- Implement customer identification and beneficial ownership controls
- Apply EDD to high-risk customers, jurisdictions, products, and transactions
- Screen customers, counterparties, wallets, and transactions against sanctions data
- Implement blockchain and wallet-address monitoring
- Establish Travel Rule procedures for applicable transfers over AED 3,500
- Register for and maintain access to goAML
- Create documented STR/SAR escalation and reporting procedures
- Train staff on AML, CFT, sanctions, red flags, and tipping-off restrictions
- Maintain required records, including KYC, transactions, alerts, investigations, and reports
- Test and independently review the programme regularly
- Track VARA, CBUAE, FIU, SCA, FATF, and other applicable regulatory updates
Conclusion
Effective AML compliance in Dubai and across the UAE requires more than a policy document. You need a coordinated framework that connects licensing, governance, customer onboarding, transaction monitoring, reporting, and ongoing regulatory implementation.
We can help you assess your regulatory position, prepare for VASP licensing in the UAE, review AML/CFT policies, structure MLRO responsibilities, and strengthen your response to VARA and federal requirements.
Contact us now to get started


This Post Has 0 Comments