A licensed virtual-asset business in Dubai that cannot secure a payment service provider relationship or a merchant-acquiring agreement is, in practical terms, a car without fuel. The VARA regime (the regulatory framework administered by the Virtual Assets Regulatory Authority) issues activity-specific licences that determine exactly which fiat rails a licensee may touch – and which PSP or acquiring partner will agree to serve it. Getting this wrong costs operators their banking, their compliance standing and, ultimately, their licence.
Under VARA, a digital-asset business in mainland Dubai must hold the appropriate activity licence before any regulated PSP or acquiring institution will open a fiat settlement account or process merchant receipts on its behalf. The regime is activity-based: crypto banking, custody, exchange, transfer and settlement each require separate authorisation, and the fiat-onramp dimension sits squarely within that perimeter. Operating without the right structure exposes the business to enforcement, frozen rails and the reputational damage that follows.
This page sets out the regulated basis for PSP and acquiring agreements under the VARA regime, the practical steps for securing fiat rails, the cross-border interaction with EMI onboarding, and the decision points every inbound operator should resolve before committing to a structure.
What does VARA regulate, and why does it govern your PSP relationship?
VARA's authority extends to all virtual-asset activities conducted in or from mainland Dubai, and its rulebooks define the permitted activities that a licensee may perform. The regime is not a single licence: it is a set of activity-specific authorisations – advisory, broker-dealer, custody, exchange services, lending and borrowing, management and investment, and transfer and settlement services. Each activity has its own capital, governance and operational requirements under the VARA rulebooks. A PSP or acquiring bank evaluating a new client will check which activity licences are in place before agreeing to process fiat flows, because those licences define the perimeter of what the business may lawfully do with the funds it receives.
The fiat interface is not incidental. When a crypto exchange in Dubai settles trades into dirhams or routes stablecoin conversions through a payment processor, that flow intersects with the transfer and settlement activity category under VARA. If the business also holds client funds pending settlement, custody-layer obligations apply. The practical consequence is that a business seeking a PSP or acquiring agreement must first confirm that its existing VARA licence covers the activity generating the fiat flow – or obtain the relevant supplementary authorisation.
VARA sits alongside the DIFC financial free zone and the ADGM regime in Abu Dhabi, administered by the Financial Services Regulatory Authority (FSRA). The VARA perimeter covers mainland Dubai; it does not extend to the DIFC. Operators with a footprint in both zones require separate regulatory analysis. In our cross-border practice, we regularly advise businesses that assumed their VARA licence covered DIFC-based activities – it does not, and the PSP relationship is the point at which the gap becomes visible.
What does a PSP or acquiring agreement actually require under the VARA regime?
Securing a PSP or acquiring agreement in the VARA environment requires the business to satisfy three overlapping sets of requirements: those imposed by VARA itself, those imposed by the UAE Central Bank on licensed payment institutions, and those imposed by the acquiring bank or PSP as a counterparty commercial matter. The UAE Central Bank's oversight of licensed PSPs and payment service providers means that any institution processing fiat for a virtual-asset business must itself comply with UAE AML and counter-financing-of-terrorism obligations – and will conduct enhanced due diligence on any VASP client.
For the inbound VARA licensee, the practical requirement set looks like this. The business must present its VARA licence in the relevant activity category, its approved AML/CFT policies and procedures, evidence of a UAE-based compliance officer or MLRO, its corporate structure documentation, and an audited or management-reviewed set of accounts demonstrating financial standing. Where the business is part of a group with offshore entities – a common structure for crypto businesses with a Dubai operating entity and a BVI or Cayman holding company – the PSP will require consolidated group structure charts and an explanation of how funds flow between entities.
The Travel Rule (the obligation, derived from FATF Recommendation 15, to pass originator and beneficiary identification data with each qualifying virtual-asset transfer) is a live diligence point. A PSP evaluating a VASP client will expect to see a Travel Rule compliance solution already in place, not in implementation. Operators that arrive at the PSP onboarding process without a deployed Travel Rule solution routinely find the application paused or declined. The timeline to address that gap varies, but it adds weeks to the onboarding process at minimum.
To discuss your PSP or acquiring structure under VARA, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the activity licence, the entity structure, the banking relationships already in place – change the analysis materially.
How does EMI onboarding interact with a VARA-licensed entity?
EMI onboarding (the process by which a virtual-asset business establishes an account relationship with a licensed e-money institution) is the most common route to fiat rails for VARA-licensed operators that cannot obtain a direct relationship with a UAE correspondent bank. The EMI sits between the VARA entity and the traditional banking system, holding a payment institution or e-money licence in a jurisdiction with established fiat infrastructure – typically the United Kingdom under the FCA, a European Union member state under the Electronic Money Directive transitioning to the Payment Services Directive 3 regime, or Lithuania under the Bank of Lithuania's MiCA-adjacent supervision.
The cross-border dimension creates a layered compliance picture. The VARA-licensed entity must satisfy VARA's own AML/CFT requirements. The EMI must satisfy its home-jurisdiction regulator's requirements for virtual-asset business clients – and those requirements have tightened substantially as regulators in the EU, the UK and Lithuania have applied heightened scrutiny to crypto-sector accounts. In our practice, we have seen EMI applications for VARA-licensed businesses stall because the applicant's AML policies were drafted for VARA compliance only and did not address the EMI's home-regulator's specific expectations around transaction monitoring, sanctions screening and adverse-media checks.
The structural point that operators frequently miss is that the EMI relationship does not replace the need for a UAE-based bank account. VARA expects its licensees to maintain verifiable fiat infrastructure within the UAE for regulatory reporting, fee payment and client-fund safeguarding purposes. The EMI relationship supplements that infrastructure; it does not substitute for it. Operators that structure their fiat rails entirely outside the UAE and present an EMI account as their primary banking relationship face questions from VARA during licence renewal and supervision cycles.
What are the most common structural mistakes operators make with fiat rails in Dubai?
The most consequential mistake operators make is sequencing the PSP or acquiring agreement after the VARA application rather than alongside it. By the time a VARA licence is granted, the operator has typically already committed to a corporate structure, an entity jurisdiction for the holding company and an approach to client-fund custody. Those decisions shape – and sometimes foreclose – the available PSP relationships.
A second common error is treating the UAE Central Bank's payment-institution regime and the VARA regime as separate, non-interacting systems. They interact constantly. A VARA-licensed exchange that processes card payments or SWIFT receipts from retail clients is touching the Central Bank's regulatory perimeter. The acquiring bank processing those card transactions will conduct its own AML review of the VARA entity independently of VARA's own authorisation process. Operators that have not coordinated their AML documentation across both review tracks arrive at the acquiring bank with a file that satisfies VARA but not the acquiring bank's financial crime team.
A third error – and one we encounter regularly in our cross-border practice – is using an offshore entity as the contracting party for the PSP agreement while the VARA licence is held by a separate Dubai mainland entity. The PSP or acquirer will ask how funds flow from the offshore entity to the licensed entity, and the answer must be fully documented and compliant with both VARA transfer and settlement rules and the home-jurisdiction requirements of the PSP. Where that documentation is absent or ambiguous, account applications are declined or suspended.
What is the process for an inbound operator seeking PSP and acquiring access in Dubai?
For an inbound operator building toward a PSP or acquiring agreement in Dubai, the process follows a defined sequence, each step contingent on the last. The first step is activity mapping: identifying which VARA activity licences are required by the business model, including whether transfer and settlement services are within scope. This is not a rubber-stamp exercise. Operators with combined custody and exchange functions routinely need multiple activity authorisations, and the licence application timeline is shaped by the completeness and quality of the regulatory business plan submitted to VARA.
The second step is entity and structure finalisation. The UAE mainland entity must be properly constituted, with a physical presence in Dubai, a UAE-resident compliance officer and an auditor acceptable to VARA. Where a group structure involves offshore holding entities – BVI, Cayman and Delaware are the most common – the inter-entity agreements governing fund flows must be drafted before the PSP onboarding process begins, because the PSP will ask to see them.
The third step is AML/CFT infrastructure buildout. This means written AML policies aligned to both VARA's requirements and the applicable FATF standards, a deployed Travel Rule solution, a sanctions screening process, and documented transaction-monitoring rules. The Travel Rule component must be in place before any serious PSP engagement, not in progress.
The fourth step is PSP and acquiring bank selection and pre-application engagement. Not every PSP licensed to operate in the UAE will serve virtual-asset businesses, and those that do will have their own risk-appetite thresholds. Pre-application engagement – a preliminary discussion of the business model, the activity licences held and the AML infrastructure – saves time by surfacing appetite mismatches before a formal application is submitted.
The fifth step is formal onboarding. Timeline at this stage varies by institution and by the completeness of the application file. Operators who arrive with a complete, well-organised file – VARA licences, corporate documents, AML policies, Travel Rule solution documentation, financial projections and group structure – move through the PSP onboarding process materially faster than those who respond to information requests reactively.
How does this work in practice?
In a recent onboarding matter, a digital-asset exchange holding a VARA exchange-services licence sought a merchant-acquiring agreement with a UAE-licensed payment institution to settle card-funded crypto purchases. The exchange had a well-developed VARA compliance file but had not deployed a Travel Rule solution and had not documented the inter-entity fund flows between its Dubai operating entity and its Cayman holding company. The acquiring bank's financial crime team flagged both gaps and suspended the application pending remediation.
We were engaged to advise on the remediation path. We mapped the Travel Rule solution options against the exchange's transaction volumes and counterparty network, coordinated implementation with the exchange's technology team, and drafted the inter-entity agreement governing fund flows in a form the acquirer's legal team could review. We also revised the AML policy documentation to address the acquirer's specific requirements under the Central Bank's AML/CFT guidelines for payment institutions. The application was resubmitted with a complete file and the acquiring relationship was established. The process from engagement to account opening took approximately two months.
Is a single VARA licence sufficient for cross-border digital-asset payments?
A common assumption among operators entering the VARA regime is that a Dubai licence, once granted, provides a sufficient regulatory foundation for serving clients in multiple jurisdictions. That assumption is incorrect, and acting on it is one of the most expensive structural errors a digital-asset business can make.
VARA's authority is territorial: it covers mainland Dubai. It does not constitute a licence, registration or authorisation in any other jurisdiction. A VARA-licensed exchange offering services to clients in the European Union, the United Kingdom, Singapore or Hong Kong is subject to the regulatory requirements of those jurisdictions independently of its VARA status. Under MiCA, an operator providing crypto-asset services to EU users from a third-country entity must either obtain a CASP authorisation in an EU member state or rely on the reverse-solicitation exemption – which is narrow and actively scrutinised by ESMA and national competent authorities. Under the FCA's financial-promotion regime, marketing crypto services to UK persons without FCA registration triggers enforcement exposure regardless of any VARA authorisation.
The PSP and acquiring dimension compounds this. A PSP serving a VARA-licensed entity that also processes payments from EU, UK or Singaporean users will conduct its own cross-border regulatory analysis. If the operator cannot demonstrate a credible licensing position in those user jurisdictions, the PSP's risk team will flag the exposure and the relationship will be restricted or declined. In our cross-border practice, we map the full licence stack – VARA operating licence, EU or UK CASP/MLR registration, and the relevant payment-service authorisations – before any operator commits to a structure. The cost of remediation after a PSP relationship is declined or withdrawn is substantially higher than the cost of getting the structure right at the outset.
If a prior application stalled or a banking relationship was closed, contact OBOLUS at info@oboluslaw.com. A second read of the structure can identify the reason and the path forward.
What does client-money safeguarding require for a VARA-licensed PSP relationship?
Client-money safeguarding is a non-negotiable element of both the VARA regime and any PSP or acquiring agreement involving retail client funds. VARA imposes segregation and safeguarding obligations on licensees holding client assets, whether those assets are virtual or fiat. For the fiat dimension, this means that client funds held pending settlement must be maintained in accounts that are segregated from the business's own operating funds and clearly identified as client money.
The PSP or acquiring bank will typically require confirmation, through the onboarding documentation, of how client-money segregation is maintained. This is not a formality. An acquiring bank that processes card-funded crypto purchases and routes the fiat proceeds to an account that is commingled with operating funds is itself exposed to regulatory risk. The bank's financial crime and compliance teams will ask to see the account structure, the internal controls around fund segregation and the board-approved policy governing client-money handling.
Where a VARA-licensed business also operates in an EMI relationship, the safeguarding obligations of the EMI's home jurisdiction apply to the funds held in the EMI account. Under the FCA's safeguarding regime, for example, an EMI must hold client funds in a segregated account with a credit institution or invest them in liquid, low-risk assets, and must be able to demonstrate compliance with that requirement at any time. Operators that have not aligned their internal client-money procedures to both the VARA and the EMI home-jurisdiction requirements face a documentation gap that surfaces during PSP or acquirer due diligence.
The practical implication is that client-money procedures must be designed from the outset to satisfy the most demanding requirements across the jurisdictions in which the business holds a regulated relationship – not the minimum required by any single jurisdiction.
Related at OBOLUS
- Banking, Payments and EMI Onboarding for Digital-Asset Businesses – our core practice covering fiat rails, PSP relationships and payment licence strategy.
- EMI Onboarding for VASPs: Established Operators – the specific EMI onboarding process for licensed VASPs seeking fiat access.
- Enforcement of Foreign Judgment in El Salvador – cross-border enforcement mechanics for recovery situations involving Central American jurisdictions.
FAQ
Why do banks close crypto company accounts?
Banks close crypto company accounts primarily because of AML/CFT risk concerns. A bank's financial crime team assesses whether a virtual-asset business has adequate transaction monitoring, Travel Rule compliance and sanctions screening. Where those controls are absent, unclear or not documented to the bank's standard, the account is treated as a material compliance risk. VARA-licensed businesses that have not aligned their AML documentation to the bank's own regulatory requirements – rather than VARA's requirements alone – are disproportionately affected. Structural mismatches, such as an offshore holding entity receiving client funds, compound the risk assessment.
How can a VASP onboard with an EMI?
A VASP seeking EMI onboarding must demonstrate that it holds the appropriate virtual-asset licence in its operating jurisdiction, has deployed a Travel Rule compliance solution, maintains documented AML/CFT policies aligned to both its own regulator and the EMI's home-jurisdiction regulator, and can evidence client-fund segregation. The EMI will conduct enhanced due diligence, often including a review of the VASP's ownership structure, UBO documentation and financial projections. Pre-application engagement with the EMI to confirm its risk appetite for VASP clients saves time and reduces the likelihood of a declined application.
What does client-money safeguarding require?
Client-money safeguarding requires a licensed business to hold client funds in accounts that are segregated from its own operating funds, clearly identified as client money and subject to board-approved written policies governing access and reconciliation. Under VARA, the safeguarding obligation applies to both virtual-asset and fiat balances held for clients. Where a VARA-licensed business also uses an EMI relationship, the safeguarding requirements of the EMI's home jurisdiction apply to funds held in that account. The most demanding requirements across all relevant jurisdictions set the effective compliance floor.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance structures that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit, and our disputes team coordinates freezing relief and on-chain tracing across leading common-law forums. To discuss your PSP, acquiring or fiat-rail structure, contact info@oboluslaw.com or message us at t.me/oboluslaw.
By Victor Olsen, Regulatory and Compliance Analyst – specialising in VARA, MiCA and cross-border VASP licensing with a focus on fiat-rail and payment-institution onboarding structures.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.