EST · MMXXVI
Home/Jurisdictions/Uae Adgm/Travel rule compliance program in Abu Dhabi Global Market (ADGM)
Compliance, AML & Travel Rule

Travel rule compliance program in Abu Dhabi Global Market (ADGM)

Travel rule compliance program in Abu Dhabi Global Market (ADGM). Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. T

For a virtual-asset firm licensed – or seeking a licence – in the Abu Dhabi Global Market, the Travel Rule (the obligation under FATF Recommendation 15 to pass originator and beneficiary identifying information with every qualifying virtual-asset transfer) is not a paperwork exercise. It is the line between keeping banking relationships and losing them. The Financial Services Regulatory Authority (FSRA), the prudential and conduct regulator operating within ADGM, applies a rules-based AML and counter-financing-of-terrorism regime that incorporates the Travel Rule as a live supervisory expectation – not a future aspiration. This page sets out what a credible Travel Rule compliance program looks like inside that regime, where cross-border complexity enters, and when external counsel adds the most value.

What is the FSRA's regulatory basis for Travel Rule enforcement?

The FSRA administers a standalone financial-services regime within ADGM, a common-law free zone on Al Maryah Island, and its AML framework aligns directly with FATF Recommendation 15, which requires virtual-asset service providers to collect, verify and transmit originator and beneficiary data for transfers at or above a defined threshold. The FSRA has incorporated those obligations into its AML and sanctions rulebook, making Travel Rule compliance a licence condition rather than a soft guidance aspiration. A firm operating a regulated virtual-asset activity in ADGM without a functioning Travel Rule program is in breach of its licence – full stop.

The FSRA regime covers entities carrying on "regulated activities" in relation to virtual assets as defined in its framework. That includes operating a virtual-asset trading facility, providing custody, and certain intermediary functions. Each activity category carries specific AML obligations. The Travel Rule applies across all of them where transfers are involved. ADGM's status as a common-law jurisdiction – its courts apply English legal principles directly – reinforces the enforceability of those obligations through civil as well as regulatory channels.

Internationally, the FSRA sits alongside VARA, which governs mainland Dubai, and the two regimes are structurally distinct. A firm licensed by VARA in Dubai does not hold an ADGM licence and vice versa. Operators expanding across the UAE must understand that each jurisdiction requires its own compliance architecture. In our practice, we regularly see businesses assume that a mainland UAE authorisation covers the free zones. It does not.

The process above describes the standard framework. Your facts – entity structure, user base, counterparty jurisdictions, banking stack – change the analysis materially. For a scoped assessment of your ADGM compliance position, contact OBOLUS at info@oboluslaw.com or map your options.

Who in ADGM needs a Travel Rule compliance program?

Any entity holding an FSRA authorisation to conduct virtual-asset activities that involve the transfer of virtual assets between wallets or accounts must maintain a Travel Rule compliance program. The scope is broad. A custodian that facilitates client withdrawals, a trading facility that processes on-chain settlements, an OTC desk routing stablecoin payments – all fall within the transfer obligation when the relevant threshold is met. The data-threshold question turns on FSRA and FATF guidance, and because the relevant thresholds carry a [VERIFY] status in our registry, operators should confirm the current figure directly from FSRA rulebook publications rather than rely on any third-party summary.

The compliance obligation extends to both sides of a transfer. Where your firm initiates a transfer, you must collect and verify the originator's information and transmit it to the receiving VASP (virtual-asset service provider). Where you receive a transfer, you must obtain and verify beneficiary data. In both cases, you must screen counterparty VASPs for sanctions exposure and assess whether they operate under a regime with materially equivalent AML standards. That last point is where many ADGM-licensed firms run into practical difficulty.

Firms that serve clients across the GCC, Europe and Asia often deal with counterparty VASPs whose jurisdictional frameworks range from fully equivalent (MiCA-authorised CASPs, MAS-regulated DPT services, SFC-licensed VATPs) to entirely unrecognised. Routing a transfer to or from an unvetted counterparty exposes the ADGM entity to a potential regulatory breach, regardless of the commercial relationship underlying it.

How do you build a Travel Rule compliance program that satisfies FSRA expectations?

A credible Travel Rule compliance program in ADGM rests on four operational pillars: data collection and verification, transmission technology, counterparty due diligence, and governance. Each must be documented, tested and owned by a named individual in your compliance structure.

Data collection and verification requires your firm to capture, at minimum, the originator's full legal name, account number or wallet address, and a unique transaction identifier for outgoing transfers. Beneficiary data must be collected in the same depth for incoming transfers. That data must be verified against your KYC framework (know-your-customer onboarding and identity-verification controls) – not treated as a separate stream. The practical issue is that most onboarding platforms are not natively configured to tag and transmit customer data in the formats required by Travel Rule messaging protocols. Retrofitting that capability after licensing is significantly more expensive than building it into the onboarding architecture from the outset.

Transmission technology is the layer that carries Travel Rule data between counterparty VASPs. Several interoperability solutions exist in the market – notably protocol-based messaging networks – but the FSRA does not mandate a single solution. What the FSRA does require is that whatever solution you use produces a verifiable audit trail and that data reaches the counterparty reliably before or simultaneous with the asset transfer. In our practice, we have seen firms deploy technically compliant solutions but fail to complete counterparty onboarding in time for go-live, leaving a gap between the technical capability and the operational reality.

Counterparty due diligence means maintaining a live register of VASPs with whom you transact, with a documented assessment of their regulatory status, AML framework and Travel Rule capability. Where a counterparty cannot share or receive Travel Rule data, the FSRA expects the originating firm to assess whether to proceed, delay or decline. A blanket policy of proceeding regardless is not defensible in a supervisory review.

Governance requires the program to be owned at the senior management level. The FSRA expects a named MLRO (money laundering reporting officer) who has the authority, budget and independence to escalate compliance failures without commercial interference. The MLRO is personally responsible for the adequacy of the AML program, including the Travel Rule component. ADGM's common-law framework gives that obligation teeth: a deficient program is not merely a regulatory risk but a personal-liability exposure for the individual who signs the compliance attestations.

How does transaction monitoring integrate with the Travel Rule?

Transaction monitoring – the automated and manual screening of transfers against risk indicators, sanctions lists and behavioural patterns – is the operational counterpart to Travel Rule data collection. Collecting originator and beneficiary data is of limited value if the firm cannot screen it. Under the FSRA regime, transaction monitoring and the Travel Rule sit inside the same AML framework and must be documented as integrated controls, not parallel systems.

The screening dimension has two layers. The first is sanctions compliance: every party to a transfer must be checked against applicable sanctions lists, including those maintained by the UN Security Council, OFAC, the UK OFSI and the UAE's own designated-persons list. ADGM firms are exposed to US sanctions extraterritorially where USD-denominated stablecoins or US-connected counterparties are involved – a point that catches many GCC operators off-guard. The second layer is behavioural monitoring: detecting structuring, layering and other typologies specific to virtual-asset flows.

A practical complication arises with unhosted wallets. Where a transfer originates from or terminates in a self-custodied wallet, the VASP cannot obtain counterparty Travel Rule data in the standard way. The FSRA, consistent with FATF guidance, expects firms to apply enhanced due diligence in those cases and to document the risk-based decisions made. An MLRO who applies the same policy to a small retail self-custody withdrawal as to a large commercial transfer to an unknown wallet address has not made a defensible risk-based decision.

What cross-border complications arise for ADGM firms with global user bases?

The cross-border reality for an ADGM-licensed firm is that the Travel Rule obligation does not end at the ADGM perimeter. A firm serving clients in the EU, the UK, Singapore or Hong Kong must simultaneously satisfy the Travel Rule expectations of those regimes – each of which has its own threshold, data-standard and timing rule. Where those rules diverge, the compliant position is the intersection of all applicable obligations, not the most permissive single standard.

Under MiCA, the EU's Markets in Crypto-Assets Regulation, the Travel Rule applies to transfers involving EU-authorised CASPs and carries specific data requirements that may differ from FSRA standards in their formatting and verification expectations. A single transfer from an ADGM firm to an EU CASP must satisfy both regimes simultaneously. In our cross-border practice, we regularly advise on building a "highest common denominator" data model that meets the most demanding applicable standard rather than maintaining separate workflows per jurisdiction.

Banking is a further pressure point. ADGM-licensed firms that hold banking relationships with UAE or international banks will find that those banks independently assess the firm's AML and Travel Rule program when onboarding and on a periodic review basis. A program that satisfies the FSRA's minimum expectations may not satisfy a correspondent bank's own compliance posture. We have seen ADGM firms lose or fail to open banking relationships not because the FSRA had concerns but because the bank's own AML team assessed the Travel Rule documentation as insufficient. The compliance program, in this sense, is also a banking-relationship document.

A recent cross-border Travel Rule matter

In a recent engagement, an institutional trading desk had obtained its ADGM authorisation and was preparing to go live. Its Travel Rule solution was technically deployed, but the counterparty-onboarding register was incomplete: fewer than half of its anticipated trading counterparties had been assessed for regulatory status and Travel Rule capability. The firm's banking partner had flagged the gap during its own onboarding review and placed the account opening on hold. We were engaged to audit the existing program, identify the structural deficiency – counterparty due diligence was being treated as a legal task rather than a compliance operations task – and rebuild the register to a standard that satisfied both the FSRA framework and the bank's requirements. The account was opened and the firm went live on its planned schedule. No supervisory notification was required.

What are the most common Travel Rule compliance failures in ADGM?

The most prevalent failure we observe is treating Travel Rule compliance as a technology problem rather than a legal and operational program. Firms that purchase a messaging solution and consider the obligation discharged routinely fail on the governance, counterparty-diligence and documentation axes when the FSRA conducts a thematic review or an individual-file inspection.

A close second is the assumption that an AML program built for a prior jurisdiction – a UK FCA MLR registration, an EU VASP registration, a BVI FSC registration – can be transplanted into ADGM with minimal adjustment. The FSRA has its own rulebook. It expects a program written for that rulebook, not a document that references it as an appendix to a policy designed for another regime.

A common assumption among operators entering ADGM is that their offshore licence – whether in the BVI, Cayman Islands or another well-regarded jurisdiction – provides adequate coverage for clients they serve from within ADGM. It does not. If the activity is conducted from ADGM or targeted at counterparties within the UAE, the FSRA's jurisdictional perimeter applies. The practical exposure is real: enforcement action in ADGM, frozen banking relationships and the reputational damage of a supervisory finding. Building the compliance program correctly from day one is materially less costly than rebuilding it under regulatory scrutiny.

If a prior compliance build stalled, a banking relationship was placed on hold, or a supervisory query has arrived, a second read of the program can surface the structural issue and the route forward. Write to OBOLUS at info@oboluslaw.com or map your options.

Which operator profile needs what level of program?

Not every ADGM-licensed firm faces the same compliance build. The scope of the required program tracks the nature of the authorised activity, the volume and geography of transfers, and the firm's counterparty base.

A trading facility or exchange routing significant daily transfer volumes across multiple jurisdictions needs a fully automated Travel Rule solution with real-time sanctions screening, a staffed MLRO function, a documented counterparty register covering all active VASP relationships, and a board-level compliance oversight framework. The timeline to build this to FSRA standard – from initial scoping to operational readiness – typically spans several months, depending on the complexity of the technology stack and the depth of the counterparty base.

An institutional OTC desk or custodian with a smaller, more homogeneous counterparty set can operate a more targeted program: a semi-automated solution with manual review protocols for non-standard transfers, a part-time or shared MLRO arrangement where the FSRA permits it, and a lighter counterparty register built on formal due diligence questionnaires. The risk of this profile is that volume growth can outpace the compliance architecture if the program is not designed with scalability in mind from the outset.

A fund or investment manager conducting virtual-asset transactions as part of a broader investment mandate typically faces a narrower Travel Rule surface but must still address the unhosted-wallet and counterparty-screening dimensions wherever the fund transacts on-chain. The banking-interaction issue is particularly acute for fund structures: prime brokers and fund administrators increasingly require independent audits of the fund's AML and Travel Rule program as a condition of service.

Across all three profiles, the cross-border question – which other regimes apply to the firm's transfers, and how do their requirements interact with the FSRA's? – is the variable that most frequently requires external legal input rather than internal compliance engineering.

Related at OBOLUS

FAQ

What does the Travel Rule require from a VASP?

The Travel Rule, as incorporated in FATF Recommendation 15 and adopted by the FSRA within ADGM, requires a VASP initiating a virtual-asset transfer to collect the originator's full name, account or wallet identifier and a transaction reference, and to transmit that data to the receiving VASP. The receiving VASP must collect and verify corresponding beneficiary data. Both firms must retain records and screen all parties against applicable sanctions lists. The precise data threshold varies by jurisdiction and should be confirmed against current FSRA rulebook publications.

Who must act as MLRO for a crypto firm?

Under the FSRA regime in ADGM, every authorised firm must appoint a money laundering reporting officer (MLRO) who is a fit-and-proper individual with sufficient authority, independence and resource to discharge the role. The MLRO is personally responsible for the adequacy of the AML and Travel Rule program and for filing suspicious-activity reports where required. The FSRA assesses the MLRO's competence as part of the authorisation process and may review the appointment on an ongoing basis. External or shared MLRO arrangements may be permissible for certain firm profiles, subject to FSRA approval.

How do regulators audit crypto AML programs?

The FSRA conducts both thematic reviews – sector-wide assessments of a specific AML or Travel Rule topic – and individual-firm inspections. In an inspection, supervisors typically request the firm's AML policy documentation, its risk assessments, transaction-monitoring configuration and alert-disposition records, MLRO reports to the board, and its counterparty due-diligence register. Gaps in documentation or evidence that policies are not operationally embedded – controls written but not followed – are the most common basis for supervisory findings. External compliance audits commissioned before an inspection are a standard risk-mitigation tool in our practice.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the AML, Travel Rule and compliance programs that sit around them. Digital assets are the whole of our practice. We map the licence, banking and compliance stack across operating, custody and payment layers as one mandate – not three disconnected workstreams. To discuss your ADGM compliance program or a cross-border AML build, contact info@oboluslaw.com or message us at t.me/oboluslaw.

By Victor Olsen, Regulatory & Compliance Analyst – specialising in AML program design, Travel Rule implementation and supervisory engagement for virtual-asset firms operating in the Gulf and across multi-jurisdictional licensing stacks.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours