Client funds safeguarding in Abu Dhabi Global Market (ADGM)
Mishandling client money is the fastest route to a supervision event in any major financial centre – and Abu Dhabi Global Market is no exception. Under the FSRA regime, any firm holding client funds as part of a regulated virtual-asset or payment activity must meet defined safeguarding standards, including segregation from proprietary assets, eligible custodian requirements and reconciliation controls. A business that gets this wrong faces licence suspension, enforcement by the Financial Services Regulatory Authority (FSRA) – the independent regulator within ADGM – and the loss of the banking rails that make the operation viable. This page maps the safeguarding obligation, the inbound process, and the cross-border interaction with banking and payment licensing that every operator entering the ADGM ecosystem must resolve before going live.
What does client funds safeguarding mean under the FSRA regime?
Client funds safeguarding, under the FSRA framework, means holding money or virtual assets that belong to clients in a manner that keeps them identifiable, segregated and recoverable in an insolvency. The FSRA applies this obligation across its regulated-activities perimeter: firms conducting virtual-asset activities – including custody, exchange, lending and management – and payment-related activities within ADGM must meet the standard as a licence condition, not as a best-practice aspiration.
The core obligation has two planks. First, structural segregation: client assets must be held separately from the firm's own assets, typically in a dedicated account or wallet clearly identified as client property. Second, reconciliation discipline: the firm must be able to demonstrate at any moment that its records match the balances held by the custodian or bank. The FSRA's framework requires firms to appoint eligible custodians – institutions meeting defined financial-soundness and prudential criteria – so the choice of banking and custody partner is itself a regulatory decision.
In our practice, we see operators underestimate the reconciliation piece. A system that segregates correctly on day one but drifts – because of gas-fee shortfalls, intraday float usage or staking yield allocation – triggers a breach without any deliberate misconduct. The FSRA expects the architecture to prevent drift, not merely detect it after the fact.
Who needs a licence in ADGM for virtual-asset activities?
Any firm conducting a regulated activity in or from ADGM in relation to virtual assets needs to be authorised by the FSRA. The FSRA maintains a list of "recognised virtual assets" – assets formally accepted into its supervisory perimeter – and the regulated-activities concept tracks what the firm does with those assets, not the label the firm applies to its product.
The relevant activities include operating a virtual-asset exchange, providing custody, managing a virtual-asset fund, and dealing or arranging deals in virtual assets. Payment and money-transmission activities that touch virtual-asset settlement also require authorisation under the applicable FSRA rules. An operator that processes client fiat receipts – even as a step toward a crypto settlement – is likely conducting a regulated payment activity and must satisfy the safeguarding conditions attached to that authorisation.
ADGM's jurisdictional perimeter covers the Al Maryah Island free zone. Firms operating from mainland Abu Dhabi or from Dubai fall under a different supervisor: CBUAE (Central Bank of the UAE) for payment activities in the mainland, and VARA (Virtual Assets Regulatory Authority) for Dubai virtual-asset activities. This distinction matters for fund flows: a business that holds client deposits in one jurisdiction but processes transactions in another must resolve which regulatory obligation bites at each step. We regularly advise clients on exactly this inter-emirate coordination question.
The FSRA's "recognised virtual assets" concept means not every token automatically qualifies for regulated activity; operators should confirm the status of each asset they intend to deal in before applying for an authorisation.
How does the FSRA authorisation process work for a virtual-asset firm?
The FSRA operates a structured application process that begins before a formal submission is made. Firms are expected to hold pre-application engagement with the FSRA – typically a detailed discussion of the business model, the technology stack, the governance arrangements and the proposed safeguarding methodology. This pre-application phase is not optional formality; regulators in ADGM use it to identify structural issues early, and a well-prepared engagement materially improves the outcome.
The formal application requires, among other materials, a detailed business plan, financial projections, governance and compliance policies, evidence of capital adequacy (the specific minimum varies by activity and is set by the FSRA), evidence that key persons are fit and proper, and – critically for safeguarding – a client-asset protection policy document explaining how client funds and virtual assets will be held, segregated and reconciled. Firms must also demonstrate that their proposed eligible custodian or banking partner meets FSRA criteria.
Timeline for authorisation varies by licence category and application quality. In our cross-border practice, well-prepared applications for digital-asset activities in ADGM tend to progress over a period of several months from formal submission to in-principle approval; the total elapsed time including pre-application engagement is typically longer. Operators should plan for this cycle, particularly if the business is expecting to integrate banking or EMI rails that themselves require a separate approval process.
A common mistake at this stage is submitting a generic client-asset policy drafted for another jurisdiction. The FSRA reads these documents carefully. A policy that references the FCA's CASS rules, for example, signals that the firm does not yet understand the ADGM-specific requirements and adds review time to the application.
CTA #1
Starting from a clean slate is easier than repairing a rejected application. If you are mapping the ADGM authorisation process for the first time, the time to surface structural issues is before submission. Map your options with our team before you commit to the application timeline.
What safeguarding architecture does the FSRA expect in practice?
The FSRA expects safeguarding to be embedded in the operating architecture, not documented in a policy that is never stress-tested. The practical requirements resolve into four layers: account structure, custodian selection, reconciliation systems and governance oversight.
On account structure, client funds – whether fiat or virtual asset – must be held in accounts clearly designated as client accounts, with a legal trust or equivalent arrangement protecting those balances in an insolvency of the firm. The firm's own working capital sits in a separate, proprietary account. Commingling, even temporarily for operational reasons such as covering a payment shortfall, is a breach.
On custodian selection, the FSRA's eligible-custodian concept narrows the field significantly. The custodian must meet prescribed financial-soundness criteria. For virtual assets, this means a technology-secure, regulated custodial entity – not a self-custody arrangement where the firm holds its own private keys on behalf of clients unless the firm itself is authorised to provide custody. Many inbound operators discover that their preferred custodian does not meet FSRA criteria and must either change provider or bring a new custodial arrangement into the authorisation scope.
On reconciliation, the FSRA expects a formal, documented process run at defined intervals – typically daily for active trading operations – comparing the firm's internal ledger against the custodian's records. Discrepancies must be investigated and resolved within a defined window. The policy must specify escalation: who sees reconciliation breaks, who authorises remediation, and when the FSRA must be notified.
Governance oversight means that the compliance and risk functions must receive regular safeguarding reports, and senior management must attest to safeguarding adequacy. This is not a back-office function; it sits at the board level in any well-run ADGM-authorised firm.
How do banking and EMI rails interact with ADGM safeguarding obligations?
Banking access is the operational nerve of a digital-asset business, and in ADGM it is also a regulatory compliance mechanism. The firm's ability to hold client fiat in an eligible institution, to remit and receive on behalf of clients, and to convert between fiat and virtual assets all depend on maintaining a viable banking or EMI (electronic money institution) relationship – and those relationships are under increasing scrutiny globally.
Abu Dhabi-based banks operating within the ADGM perimeter have, over recent years, developed more structured onboarding criteria for virtual-asset firms. A firm presenting an FSRA authorisation with a clean client-asset architecture is in a materially better position than an unlicensed entity seeking a fiat account. In this sense, the FSRA licence is not just a regulatory obligation – it is a banking access tool. We have seen operators in other jurisdictions delay licensing on cost grounds, only to find that the unlicensed status makes banking impossible and the eventual licensing cost is compounded by months of lost revenue.
For firms that cannot access a full ADGM bank account during the pre-licence period, an alternative is to onboard with an EMI – a regulated electronic money institution that can provide payment-services functionality including client fiat settlement, IBAN issuance and cross-border rails. The EMI itself must be regulated in a jurisdiction whose prudential standards the FSRA considers adequate. The Travel Rule – the obligation under FATF Recommendation 15 to pass originator and beneficiary data with virtual-asset transfers – applies both to the VASP and, where it overlaps with payment services, to the EMI. An operator using an EMI as a fiat bridge must ensure that the Travel Rule data-sharing obligation flows correctly across the payment chain.
Cross-border complexity enters when the EMI is licensed in a different jurisdiction – say, an EU-authorised EMI under the Payment Services Directive operating alongside an ADGM FSRA licence. The data-sharing obligations, the safeguarding regime that applies to the EMI leg, and the contractual allocation of liability between the VASP and the EMI all require careful structuring. Operators we advise in this situation typically need a legal architecture document that maps each asset-flow step to the regime that governs it.
CTA #2
If a prior banking application stalled or a payment account was closed without clear explanation, the reason is usually structural. A second read of the entity setup, the licence scope and the client-asset architecture often surfaces the issue – and the route back. Map your options at info@oboluslaw.com.
A payment firm's safeguarding restructure before FSRA review
In a recent cross-border matter, a payments and settlement firm operating within the ADGM perimeter came to us after its compliance team identified that the client-fiat segregation architecture did not clearly meet the FSRA's eligible-custodian standard. The firm had grown rapidly from a narrow payment-gateway model into a broader virtual-asset settlement service, and the original banking arrangement – a single omnibus account at an offshore institution – had not been revisited. We undertook a gap analysis mapping each client-money flow to the applicable FSRA requirement, identified two structural deficiencies in the reconciliation process, and worked with the firm's technology team to redesign the account architecture and the daily reconciliation protocol. The restructured arrangement was documented in a new client-asset protection policy and presented to the FSRA in a voluntary disclosure meeting. The FSRA acknowledged the proactive remediation in its response. The firm's licence was maintained without an enforcement step, and the new architecture subsequently supported a successful expansion of the firm's authorised activities.
What are the most common safeguarding mistakes – and how are they avoided?
The most common safeguarding failure in ADGM-regulated digital-asset firms is not deliberate misappropriation. It is an architecture that was adequate at launch but was never scaled alongside the business.
Growth-driven drift is the first category. A firm authorised for a narrow exchange service adds custody, lending or staking over time. Each new product line creates new client-money flows. If the safeguarding policy and account structure are not updated at each expansion, the firm drifts out of compliance while believing it is still within scope. The FSRA expects firms to seek a variation of permission when the business model changes materially.
Key-management failure is the second category, specific to virtual-asset custody. Firms that hold cryptographic keys on behalf of clients – even informally, because a client deposited assets to an exchange wallet rather than a self-custody wallet – are providing custody and must meet the custodial safeguarding standard. Operating in this space without the corresponding authorisation and key-management architecture is a common and serious error.
A common assumption is that a single offshore structure is sufficient to serve clients globally without local authorisation. This is incorrect. The FSRA's jurisdictional reach covers activities conducted in or from ADGM, but the activities of the ADGM entity also interact with the regulatory perimeters of every jurisdiction in which clients are located. Serving EU retail clients from an ADGM entity implicates MiCA's CASP regime for EU-based activity. Serving UK clients attracts the FCA's financial-promotion rules. The licence stack is always multi-jurisdictional; the ADGM licence is one layer, not the whole architecture.
The third category is governance failure: safeguarding is treated as a compliance-team matter rather than a board-level responsibility. The FSRA's Senior Management Regime imposes personal accountability on approved persons. A senior manager who cannot demonstrate active oversight of client-asset compliance is exposed to personal liability in an enforcement event.
Decision point: ADGM or another UAE hub – which profile fits which structure?
Operators entering the UAE digital-asset market face a genuine choice between ADGM, VARA Dubai and the mainland CBUAE framework. The right structure depends on business profile, client base and asset type.
A firm focused on institutional clients – family offices, funds and corporate treasuries – and dealing in sophisticated virtual-asset products including fund management, structured lending or tokenised assets will generally find ADGM's FSRA regime the most compatible. ADGM is a common-law jurisdiction modelled on English law, and its DIFC Courts counterpart provides a litigation forum that institutional counterparties trust. The FSRA's "recognised virtual assets" model gives the regulator flexibility to bring new asset classes in on a reasoned basis, which matters for product-development roadmaps.
A firm focused on retail exchange, broad token listings and high-volume consumer-facing services may find that VARA's activity-based licence model in Dubai better fits the product. VARA's rulebooks are structured around specific service lines – exchange, broker-dealer, transfer and settlement – and the Dubai Financial Centre ecosystem provides a dense network of banking, custody and legal-services partners.
A firm requiring mainland UAE banking access for a non-financial-free-zone entity will need to engage with the CBUAE's payment and stored-value facility framework, which operates independently of both ADGM and VARA.
In each case, the safeguarding obligation follows the licence: wherever the regulated activity sits, the client-asset protection standard of that jurisdiction's regulator applies. A multi-hub structure – an ADGM institutional entity paired with a VARA retail exchange entity – multiplies the compliance obligation and requires a consolidated client-asset governance framework that spans both licences. We map these combined structures regularly, and the architecture decision at the outset determines whether consolidation is manageable or creates irreconcilable conflict.
Related at OBOLUS
- Banking, payments and EMI onboarding for digital-asset businesses – structuring fiat rails, EMI selection and payment-layer licensing for crypto operators.
- Correspondent banking access in Estonia – EU banking access routes for VASP and EMI-adjacent structures.
- Smart contract dispute resolution – what recent enforcement tells operators – enforcement signals from leading forums on on-chain contractual liability.
FAQ
Why do banks close crypto company accounts?
Banks close crypto company accounts most often because the firm's activity triggers an unresolved AML or regulatory-risk flag during periodic review. Common causes include unlicensed status in the operating jurisdiction, inadequate KYC documentation for clients, unclear source-of-funds flows, or a business model that sits outside the bank's approved risk appetite for virtual-asset clients. An FSRA authorisation with a documented client-asset architecture materially reduces that risk signal, though it does not eliminate the bank's discretion to exit a relationship on commercial grounds.
How can a VASP onboard with an EMI?
A VASP (virtual asset service provider) seeking to onboard with an EMI must demonstrate that it meets the EMI's own AML and risk-management criteria – which typically require evidence of regulatory authorisation, a clear business model, transaction monitoring systems and a compliance programme aligned to FATF standards including the Travel Rule. Preparation of a structured onboarding pack, including the regulatory licence, AML policy, governance documentation and a description of client-fund flows, substantially improves the probability and speed of a successful onboarding.
What does client-money safeguarding require?
Client-money safeguarding requires, at minimum, structural segregation of client assets from the firm's proprietary assets, appointment of an eligible custodian meeting the regulator's prudential criteria, a documented and tested reconciliation process run at defined intervals, and governance oversight at senior-management level. In ADGM, these obligations are conditions of the FSRA authorisation. A firm that cannot demonstrate end-to-end compliance with each element is at risk of a licence condition breach, regardless of whether any client has actually suffered loss.
About OBOLUS
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise crypto exchanges, custodians, token issuers and funds on licensing across more than seventy jurisdictions, on disputes and on-chain asset recovery across more than twenty-five forums, and on the tax, banking and compliance that sit around them. We map the licence stack across operating, custody and payment layers before you commit – so the architecture works in practice, not just on the application form. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com or message us at t.me/oboluslaw.
By Victor Olsen, Regulatory & Compliance Analyst – specialising in FSRA, MiCA and cross-border VASP authorisation for digital-asset businesses entering the Gulf and EU markets.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.