EST · MMXXVI
Home/Jurisdictions/Uae Vara/AML and travel rule regime in United Arab Emirates (VARA, Dubai)
Compliance, AML & Travel Rule

AML and travel rule regime in United Arab Emirates (VARA, Dubai)

Aml and travel rule regime in United Arab Emirates (VARA, Dubai). Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. T

Operating a virtual asset business in Dubai without a clear grip on anti-money laundering obligations exposes the firm to enforcement action, suspended licences and severed banking relationships – risks that materialize faster in a jurisdiction where regulators actively supervise rather than simply register. Under VARA (the Virtual Assets Regulatory Authority), Dubai's mainland digital-asset regime, every licensed entity must embed a live AML/CFT program, a qualified Money Laundering Reporting Officer, and a functional Travel Rule (the obligation to pass originator and beneficiary data with every qualifying transfer) before it opens for business. The following analysis maps the regulated basis, the compliance architecture VARA expects, and the cross-border realities that operators need to resolve before going live in the emirate.

What is the regulatory foundation for AML in Dubai's virtual asset sector?

VARA is the sole competent authority for virtual asset businesses operating on Dubai's mainland, and it mandates full alignment with the UAE's AML/CFT framework, which itself implements the FATF Recommendations – including Recommendation 15, the specific FATF standard requiring states to regulate virtual asset service providers as AML-obligated entities. VARA issues activity-based licences covering advisory, broker-dealer, custody, exchange, lending, management, and transfer and settlement services; each licence category carries its own rulebook, and those rulebooks bind licensees to the AML compliance obligations set out in the applicable VARA regulations and the UAE Federal AML Law.

The UAE Federal AML Law and its executive regulations sit above the VARA rulebooks. A Dubai mainland VASP must satisfy both layers simultaneously. VARA's scope is expressly limited to mainland Dubai – it does not extend to the DIFC financial free zone, which operates under a distinct DFSA regime. This distinction matters for firms structuring a group: an entity licensed by VARA and an entity licensed by the DFSA sit in separate regulatory perimeters and cannot cross-sell regulated services without separate authorisations.

In our cross-border practice, we consistently see inbound operators underestimate the dual-layer obligation – treating the federal AML law as a formality that the VARA rulebook already absorbs. It does not. Each layer addresses distinct aspects of the compliance architecture, and VARA's supervisory reviews examine both.

Which businesses must comply with VARA's AML requirements?

Any entity conducting a licensed virtual asset activity on Dubai's mainland – including exchange, custody, transfer and settlement, lending, and advisory services – is directly subject to VARA's AML rulebook obligations from the date of licence issuance. The obligation is not triggered by a volume threshold; it is categorical. A licensed firm with one client is as obligated as one with ten thousand.

Firms in the pre-licence phase face an important timing point. VARA expects to see a credible compliance framework – policies, a designated MLRO, and a CDD (customer due diligence) architecture – as part of the licence application itself. The compliance build is therefore not a post-licence project; it precedes the licence grant. Operators who engage compliance counsel only after receiving approval regularly find themselves in a remediation cycle that delays commercial launch by weeks.

Cross-border groups face an additional layer of analysis. A parent entity domiciled offshore that routes orders through a Dubai subsidiary may trigger VARA's definition of a conducting entity even if the parent holds no local licence. The regulator's rulebooks apply to economic substance, not just to the legal form of the Dubai entity.

To map whether your structure is within VARA's AML perimeter, contact OBOLUS at info@oboluslaw.com. The process above describes the standard categorical obligation. Your facts – the entity structure, the user locations, the product type – may shift the analysis materially.

What does a VARA-compliant AML program look like in practice?

A compliant AML program under VARA requires five interlocking components: a risk-based CDD framework, a transaction monitoring system calibrated to the firm's product risk profile, a sanctions screening function, a Travel Rule mechanism, and a designated MLRO with clear reporting lines to the board.

The CDD (customer due diligence) framework must be risk-based. VARA expects tiered onboarding – simplified due diligence for lower-risk profiles, enhanced due diligence for higher-risk customers including politically exposed persons, high-risk jurisdictions, and complex ownership structures. The risk classification methodology must be documented, reviewed at a defined frequency, and updated when the firm's product or customer profile changes.

Transaction monitoring cannot be static. VARA's rulebooks signal an expectation that monitoring rules are tuned to the specific risk profile of each licensed activity. An exchange monitoring for structuring has a different rule set than a custodian monitoring for unusual withdrawal patterns. In our compliance practice, we regularly advise on the gap between a firm's purchased monitoring tool and the rules it has actually configured – the tool is rarely the problem; the calibration is.

Sanctions screening must cover both customer-level and transaction-level exposure. The UAE enforces UN Security Council designations and its own national sanctions list; firms with US-dollar settlement rails also face OFAC exposure regardless of where they are incorporated. A VASP that settles in USDT or USDC carries the stablecoin issuer's independent freeze capability as a separate risk dimension – Tether and Circle each hold contract-level blacklist authority on their issued tokens, generally exercised on a court order or law-enforcement designation.

How does the Travel Rule apply under VARA, and what does implementation require?

The Travel Rule under VARA requires a licensed VASP to collect, verify and transmit originator and beneficiary information alongside every qualifying virtual asset transfer, consistent with FATF Recommendation 16 as adopted into the UAE AML framework. The rule applies at the point of transfer, not at the point of order or settlement. A firm that executes a transfer without completing the Travel Rule data exchange is in breach regardless of whether the counterparty VASP is cooperative.

Implementation has two technical dimensions: the protocol layer and the counterparty verification layer. On the protocol side, VARA-licensed VASPs typically implement one of the established VASP-to-VASP messaging protocols – TRISA, TRP (Travel Rule Protocol), or a provider running one of these protocols under a commercial solution. The choice of protocol matters because it determines which counterparty VASPs a firm can exchange data with and how disputes over unhosted wallet transfers are handled.

On the counterparty side, the firm must be able to verify that the receiving entity is itself a regulated VASP before sending Travel Rule data. Sending customer data to an unregulated counterparty is a data protection and AML failure simultaneously. VARA's rulebooks expect a documented counterparty due diligence process, including a procedure for transfers to unhosted wallets – typically requiring enhanced source-of-funds checks and a risk decision at the account officer level.

Cross-border groups have the added complexity of operating across jurisdictions with different Travel Rule thresholds. The UAE threshold is determined by the applicable regulations and aligns broadly with the FATF standard, but counterparty jurisdictions – Singapore under the Payment Services Act, the EU under MiCA, the UK under FCA rules – each set their own trigger thresholds. A firm routing transfers between a Dubai entity and an EU subsidiary must satisfy both regimes on every cross-border transfer. In our practice, we have seen firms build a single-threshold policy that exceeds all applicable requirements – a pragmatic solution that avoids per-corridor calibration and reduces compliance overhead.

Who must act as MLRO, and what governance does VARA expect?

VARA requires every licensed entity to designate a qualified MLRO (Money Laundering Reporting Officer) who holds a senior management function, reports directly to the board, and has unfettered authority to file Suspicious Activity Reports with the UAE Financial Intelligence Unit. The MLRO cannot be the CEO, the CFO, or any role that creates a structural conflict between commercial imperatives and compliance escalation. VARA scrutinises the reporting line as part of its supervisory review.

The MLRO must be physically present in the UAE or have a clearly documented arrangement that gives local authorities uninterrupted access. A nominally appointed MLRO based offshore – a common feature of operations that built their compliance architecture around an offshore licence first – will not satisfy VARA's governance expectations.

Beyond the MLRO, VARA expects board-level AML oversight: a designated board member or committee with AML as an explicit responsibility, a documented escalation protocol for high-risk SAR decisions, and an annual AML risk assessment signed off at board level. In our cross-border practice, we regularly assist operators in restructuring their governance documentation when an offshore model transitions to a VARA-regulated entity and the pre-existing governance does not map onto the UAE expectations.

If your governance structure was built for a different regulatory environment, a scoped compliance gap analysis can identify what needs to change before VARA's supervisory review. Contact OBOLUS at info@oboluslaw.com. A prior compliance build for another regime rarely transfers without adjustment.

How do AML compliance obligations interact with banking and cross-border structuring?

Dubai-licensed VASPs operating across multiple jurisdictions face a compounding compliance dynamic: each jurisdiction in which the firm has clients, banking relationships, or group entities may impose its own AML monitoring requirements, and those requirements do not automatically align. The UAE's AML framework is consistent with FATF standards but its supervisory style, reporting timelines and SAR-filing mechanics differ from those of the EU under MiCA, Singapore under the Payment Services Act, or the UK under FCA registration.

Banking is the stress point. UAE correspondent banks and digital-asset-friendly EMIs (electronic money institutions) conducting their own AML due diligence on a VASP client will typically review the VASP's VARA licence, its AML policies, its Travel Rule implementation evidence, and its MLRO's CV. A firm that cannot produce all four in a structured onboarding pack will find banking applications stall, regardless of how recently the licence was issued.

Tax structuring has its own interaction with AML compliance documentation. The beneficial ownership register maintained for VARA compliance purposes is also the primary reference point in transfer-pricing and substance analyses conducted by tax advisers and by foreign tax authorities under the UAE's OECD-aligned information-exchange commitments. A beneficial ownership record that is accurate for AML purposes but inconsistently described in the group's transfer-pricing documentation creates a structural vulnerability. We map the licence, banking and tax stack as a single mandate – the alternative is discovering the inconsistency during an external audit.

A practical example illustrates the point. In a recent licensing mandate, a group operating a custody platform and a transfer service from two separate entities structured both in the Dubai mainland sought VARA licences for both activities. We identified that the beneficial ownership documentation prepared for the custody entity had not been aligned with the holding structure used in the group's tax filing. Correcting the inconsistency before submission avoided what would otherwise have been a material disclosure issue in the licence application. The group launched both activities on schedule.

What are the most common AML compliance mistakes VARA-licensed firms make?

The most common mistake is treating compliance as a documentation exercise rather than a live operational program. VARA's supervisory style is risk-based and examination-led. The regulator does not simply review policies in a file; it tests whether the firm's monitoring rules produce alerts, whether those alerts are investigated, and whether the investigations are documented and resolved. A firm with excellent written policies and no alert history will attract scrutiny, not credit.

A second recurring issue is Travel Rule coverage gaps. Firms frequently implement a Travel Rule solution that works for transfers between two registered VASP counterparties but has no documented procedure for unhosted wallet transfers or for jurisdictions where the counterparty VASP's regulatory status is unclear. VARA expects the gap to be covered by a risk decision, not ignored.

A third issue – and one we see consistently in firms that launched under an offshore structure before VARA – is an MLRO role that is nominally held by a senior employee whose primary function is commercial. The MLRO title appears in the org chart; the function is not actually independent. VARA identifies this quickly in a governance review.

A common assumption is that compliance infrastructure built for an EU or Singapore licence transfers to the UAE without modification. In practice, the regulatory culture, supervisory style, and specific technical requirements of VARA diverge meaningfully from those of ESMA's competent authorities or MAS. The policies need localisation, not just re-branding.

How does VARA conduct AML supervision and what triggers a review?

VARA's supervisory approach combines periodic reviews, event-triggered examinations, and thematic sweeps across its licensed population. A periodic review examines the firm's AML risk assessment, its policies and procedures, its transaction monitoring system, its SAR-filing record, and its MLRO's activity log for the review period. Event triggers include a significant change in the firm's product offering or customer base, a SAR filing involving a material transaction, a complaint from a counterparty regulator, or a media event involving the firm's key management.

Firms should assume that a VARA supervisory review will involve a document request covering a defined historical period – typically twelve months – and an interview with the MLRO and at least one board member. The review may also request samples of CDD files, alert records, and Travel Rule data exchanges. A firm that cannot produce structured, retrievable compliance documentation within the regulator's standard response window is at a procedural disadvantage before the substantive review has even begun.

VARA cooperates with foreign regulators through the UAE Central Bank's international information-exchange arrangements and through FATF mutual evaluation channels. A supervisory concern raised by a counterparty regulator in Singapore, the EU, or the UK about a transaction involving a VARA-licensed entity will typically reach VARA. Cross-border firms should assume their compliance posture is visible across the major supervisory networks.

Related at OBOLUS

FAQ

What does the Travel Rule require from a VASP?

The Travel Rule requires a VASP to collect originator and beneficiary information – including names, account identifiers, and, where applicable, addresses – and transmit that data to the receiving VASP alongside every qualifying virtual asset transfer. The obligation tracks FATF Recommendation 16, which the UAE has incorporated into its AML framework. Transfers to unhosted wallets require a documented risk decision rather than a standard data exchange. Implementation requires both a technical protocol and a counterparty due-diligence procedure.

Who must act as MLRO for a crypto firm?

VARA requires a designated MLRO who holds a senior management function, reports independently to the board, and has authority to file Suspicious Activity Reports without commercial interference. The MLRO cannot be the CEO, CFO, or any dual-role that creates a conflict. VARA expects the individual to be UAE-resident or immediately accessible to local authorities, and will review the reporting line and the MLRO's actual activity record – not merely the title – during a supervisory examination.

How do regulators audit crypto AML programs?

VARA conducts risk-based supervisory examinations that include document reviews, transaction monitoring system testing, and interviews with the MLRO and board members. Examiners typically review the firm's AML risk assessment, CDD file samples, alert-investigation logs, SAR-filing history, and Travel Rule data exchange records for a defined period. Event triggers – a material SAR filing, a product change, a counterparty regulator referral – can prompt an out-of-cycle review. Firms unable to produce structured documentation within a standard response window face a procedural disadvantage before the substantive examination begins.

About OBOLUS

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance obligations that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit – and we structure licensing, banking and tax as one mandate rather than three disconnected workstreams. To discuss your situation, contact info@oboluslaw.com or message us at t.me/oboluslaw.

By Victor Olsen, Regulatory & Compliance Analyst – specialising in VARA and multi-hub AML compliance architecture for virtual asset service providers operating across the Gulf and EU.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours