AML for Virtual Asset Service Providers in the UAE: VARA's AML Rulebook, the Travel Rule, goAML and Fines (2026)

What UAE virtual asset service providers must do on AML in 2026: who regulates them (VARA, the CMA, the CBUAE, ADGM and DIFC), the 2025 federal law, the UAE Virtual Assets Travel Rule and its AED 3,500 daily aggregate, VARA's AML rulebook, goAML and sanctions reporting, the risk picture and VARA's fines.

CS
Creodata Solutions Team
AML for Virtual Asset Service Providers in the UAE: VARA's AML Rulebook, the Travel Rule, goAML and Fines (2026)

Short answer: Virtual asset service providers (VASPs) in the UAE carry the same anti-money laundering duties as banks under Federal Decree-Law No. (10) of 2025. They must be licensed, run due diligence on occasional transactions from AED 3,500, report suspicion to the Financial Intelligence Unit (FIU) through goAML without delay, and freeze sanctioned customers' assets within 24 hours. The UAE Virtual Assets Travel Rule requires originator and beneficiary data on every transfer, with the beneficiary verified from AED 3,500 a day. In Dubai, VARA's rulebook adds an experienced MLRO, quarterly risk assessments and eight-year records, and VARA has fined licensed firms for failings in their AML programmes.

This guide is for founders, MLROs and compliance teams at exchanges, brokers, custodians and other VASPs in the UAE, and at banks that serve them. It is a practical guide, not legal advice: the federal texts, your regulator's rulebook and its circulars are the authoritative sources.


Who regulates VASPs

Where, or whatRegulatorFramework
Dubai, including its free zones, but not the DIFCVirtual Assets Regulatory Authority (VARA)Dubai Law No. (4) of 2022, VARA's Regulations and Rulebooks
The rest of the mainland and the commercial free zonesCapital Market Authority (CMA), the former Securities and Commodities Authority, renamed on 1 January 2026Cabinet Decision No. 111 of 2022, and the CMA's Virtual Assets Framework announced on 13 April 2026
Payment tokens (fiat-backed stablecoins used for payment)Central Bank of the UAE (CBUAE)Payment Token Services Regulation, Circular No. 2/2024
Abu Dhabi Global Market (ADGM)Financial Services Regulatory Authority (FSRA)ADGM's own rules
Dubai International Financial Centre (DIFC)Dubai Financial Services Authority (DFSA)The DFSA's Crypto Token regime

VARA and the CMA. Under their 2024 agreement, a VARA licensee is "registered by default" with the federal regulator to serve the wider UAE, and each entry on VARA's public register carries a CMA registration number. On 1 October 2026 the register listed 56 VASP licences. VARA also lists firms it suspects of operating without a licence.

The CMA's framework. It has five modules, one of them anti-money laundering and counter-terrorist financing, and it expands the regulated activities from three to eight.

Payment tokens. The CBUAE's regulation treats payment-token services as high money laundering risk and bans algorithmic stablecoins and privacy tokens for anyone in or targeting the UAE. VARA told Dubai VASPs with fiat-backed payment token activity to register with the CBUAE.


What the 2025 federal law requires

The Decree-Law defines a virtual asset as a "digital representation of value" that can be traded or transferred and used for payment or investment. A VASP is anyone who, as a business, carries out virtual asset activities for others (Article 4 of Cabinet Resolution No. 134 of 2025):

  • exchange between virtual assets and fiat currencies;
  • exchange between virtual assets;
  • transfer;
  • safekeeping or administration;
  • financial services for an issuer's offer or sale;
  • any other activity a supervisor designates with the National Committee.

VARA says the Decree-Law took effect on 14 October 2025, and the regulations on 14 December 2025.

Duties. VASPs sit alongside financial institutions and DNFBPs in every core duty:

  • report suspicion to the FIU "without delay and directly", whatever the value;
  • assess their risks, and assess new products and technologies before launch;
  • apply due diligence and ongoing monitoring;
  • implement targeted financial sanctions forthwith;
  • keep records.

Due diligence applies at the start of a relationship and to occasional transactions of AED 3,500 or more, single or linked: far below the AED 55,000 line for financial institutions.

Offences specific to virtual assets:

OffencePenalty
Operating as a VASP without a licence, registration or enrolment (Articles 20 and 32)Imprisonment and a fine of AED 200,000 to AED 10,000,000, or either
Promoting, selling, servicing or dealing in virtual assets "characterized by total anonymity", or in technologies that hide transactions from the authorities (Article 30)At least three months' imprisonment and a fine of at least AED 50,000, or either
Letting someone use your VASP account, knowing it is meant for misuse (Article 35)Imprisonment and a fine, or either

Supervisors can also fine AED 10,000 to AED 5,000,000 per violation (Article 17).


The UAE Virtual Assets Travel Rule

A national Travel Rule applies to VASPs everywhere in the UAE, financial free zones included. It is published in the CBUAE Rulebook and listed by VARA among the federal AML laws.

The data. Each transfer must carry:

  • the full names of the originator and the beneficiary;
  • their wallet or account numbers, or a unique reference that lets the transfer be traced;
  • the originator's address, national ID or travel-document number, customer number, and date and place of birth.

Network ("gas") fees are outside the rule.

The threshold is a daily aggregate. "For Virtual Asset Transfers of daily aggregated amounts of AED 3,500 or more", the beneficiary's VASP must verify the beneficiary's identity if it has not already done so. Below that, the data still travels but need not be verified unless crime is suspected. VARA's own rule speaks of transfers "exceeding AED 3,500"; follow the stricter national rule.

Counterparties. A VASP must not send to another VASP that is not appropriately regulated where it is incorporated and located. It needs risk-based policies to reject, permit, delay or return transfers that arrive without the data. It reports a counterparty's systemic failures to its supervisor, and intermediaries log every transfer, rejected attempts included.

Unhosted wallets. Before sending to or receiving from a self-hosted wallet, the VASP carries out enhanced due diligence on its customer, including extra identification and source-of-funds verification. For an outgoing transfer, it collects the required data from its customer or declines.

Privacy tokens. "No UAE Virtual Asset Service Provider shall Execute a Virtual Asset Transfer of a Privacy Token." Dubai separately bans anonymity-enhanced cryptocurrencies and all activity related to them.

Suspicion. A suspicious transaction report must consider both sides of the transfer.


VARA's AML rulebook

Part III of VARA's Compliance and Risk Management Rulebook (current version effective 19 June 2025) sets Dubai's AML rules, on top of the federal law:

AreaVARA's rule
MLROAt least two years' AML/CFT experience, fit and proper, appointment reviewed annually; quarterly reports to the board, including a summary of all anonymity-enhanced transactions
PoliciesAttested by a competent third party; filed with VARA at licensing and within 21 days of any change
Screening and monitoringScreen clients, beneficial owners, transactions and wallet addresses; use blockchain ("distributed ledger") analytics; build the FATF's 2020 virtual-asset red flags into monitoring scenarios
Risk assessmentsBusiness-wide and client assessments at least every three months, and on significant change
Due diligenceAt onboarding, for occasional transactions of AED 3,500 or more, on instructions involving a potential suspicious transaction, and for every transaction of a high-risk client; MLRO and senior-management approval for politically exposed persons
Enhanced due diligenceSource of funds and wealth, senior-management approval, and a first payment from the customer's own account at a regulated institution
ReportingSuspicious transactions reported to the FIU immediately on goAML; FIU and VARA requests answered within 48 hours
SanctionsAutomated, real-time screening; immediate freezing; block attempts to bypass sanctions
RecordsAt least eight years: longer than the federal five

VARA can take action directly against directors, responsible individuals, the MLRO and senior management.

VARA's circulars since 2025:

  • 24 November 2025: a clause-by-clause gap assessment against the 2025 Decree-Law, with a board-approved remediation plan within 60 days and all gaps closed within 120.
  • 24 February 2026: a Travel Rule circular telling VASPs to update their transfer and counterparty controls, and to expect inspections and thematic reviews.
  • 4 March 2026: proliferation financing treated as a distinct risk in the business risk assessment.
  • Business risk assessments: VARA reported significant deficiencies in inspections in 2024 and 2025, and scheduled a thematic review for the second quarter of 2026.
  • FIU enquiries: registration on the FIU's Integrated Enquiry Management System (IEMS) by 30 May 2025, and answers to FIU requests within five working days.

goAML and reporting

The Executive Office for Control and Non-Proliferation (EOCN) states that any VASP licensed or registered by a supervisor "has an obligation to register on goAML". goAML carries suspicious transaction and activity reports to the FIU, and sanctions reports to the EOCN and the supervisor; unregistered VASPs risk sanctions. The FIU's registration guide says every reporting entity registers "irrespective of whom they are regulated by", and each supervisor approves the registrations of its own entities.

What a VASP files. VARA's rulebook lists:

  • STRs and SARs;
  • high-risk country transaction and activity reports (HRC, HRCA);
  • the Confirmed Name Match Report (CNMR), formerly the Funds Freeze Report;
  • the Partial Name Match Report (PNMR).

Fraud is not a separate goAML report type: the FIU asks for it as an STR or SAR with the best-fitting reason for reporting. See our guide to goAML report types in the UAE and our goAML registration guide.

What the FIU sees. Its 2024 annual report says VASPs, while still a small share of reporting, "saw the fastest growth rate among all sectors", and the FIU added a crypto analytics module for tracing. Its December 2025 study of reports from July 2023 to June 2025 found fraud the most common typology, with growing use of stablecoins, decentralised platforms, peer-to-peer activity and money-mule accounts.


Sanctions screening and freezing

The EOCN's guidance on targeted financial sanctions names VASPs. For a VASP, freezing can mean blocking trading and transfer services and suspending account access. "Without delay" means within 24 hours of a listing. A confirmed match is frozen and reported as a CNMR through goAML within five business days, and a partial match is suspended and reported as a PNMR. Breaching sanctions instructions is punishable by imprisonment and a fine of at least AED 20,000, or either (Article 33).


The risk picture

  • Money laundering. The 2024 National Risk Assessment rates the virtual asset sector High. It cites cyberattacks, international criminal networks, regulatory gaps and easy cross-border transfers. Virtual-asset abuse appeared in under 2% of money-laundering cases.
  • Proliferation financing. The EOCN's 2026 assessment names VASPs as the sector with the highest exposure in the UAE: High on the mainland and Medium-High in the financial free zones. It points to the speed and pseudo-anonymity of transfers and to state-sponsored hacking.
  • Customers. The Ministry of Economy & Tourism tells DNFBPs that customers linked to unlicensed virtual asset services became riskier after the assessment.

Enforcement

DateAction by VARAGrounds
May 2023 (notice August 2023)OPNX fined AED 10,000,000, and its founders and CEO AED 200,000 eachA market offence and marketing breaches, not AML
October 2024Seven unlicensed firms fined AED 50,000 to AED 100,000, with cease-and-desist ordersUnlicensed activity and marketing breaches
August 2025Morpheus Software Technology ("Fuze") fined, amount not published, with a skilled person appointedFailures in its AML programme, governance and controls, and unlicensed activity
October 202519 firms fined AED 100,000 to AED 600,000Unlicensed activity and marketing breaches
June 2026CoinMENA fined, amount not publishedFailures in its AML programme
June 2026MEXC and KuCoin fined, amounts not publishedServing Dubai customers without a licence; MEXC also onboarded users without required KYC
July 2026Shelbit General Trading finedContinuing unlicensed services and onboarding without KYC after a cease-and-desist order

The courts act too. In a 2023 case cited in the National Risk Assessment, 11 people and 4 companies running unlicensed VASPs were convicted. The court seized AED 18.9 million in cash and AED 59.2 million in virtual assets, and imposed fines of AED 200,000 to AED 5 million.


Compliance checklist

  1. Confirm which regulator licenses you, and that every activity you offer is on your licence.
  2. Register on goAML, IEMS and the EOCN's notification system, and keep the registrations active.
  3. Collect and transmit Travel Rule data on every transfer, verify beneficiaries from AED 3,500 a day, and check that counterparty VASPs are regulated.
  4. Apply enhanced due diligence before any transfer to or from an unhosted wallet, and refuse privacy tokens.
  5. Run due diligence on occasional transactions from AED 3,500, aggregating linked transactions.
  6. Screen customers, beneficial owners and wallet addresses continuously; freeze within 24 hours; file CNMR or PNMR within five business days.
  7. Use blockchain analytics in monitoring, and file STRs immediately, answering FIU requests within the set times.
  8. Keep records for at least eight years in Dubai, five elsewhere.

Frequently asked questions

Who regulates crypto companies in the UAE?

VARA in Dubai (except the DIFC), the Capital Market Authority (formerly the SCA) on the rest of the mainland and in commercial free zones, the CBUAE for payment tokens, the FSRA in ADGM and the DFSA in the DIFC. All of them apply Federal Decree-Law No. (10) of 2025 on AML.

What is the UAE travel rule threshold?

AED 3,500 as a daily aggregate: at that level the beneficiary's VASP must verify the beneficiary's identity. Below it, originator and beneficiary data must still accompany the transfer, but need not be verified unless crime is suspected.

Do VASPs have to register on goAML?

Yes. The EOCN states that every licensed or registered VASP must register on goAML to file suspicious transaction and activity reports with the FIU and sanctions reports with the EOCN.

What is VARA's MLRO requirement?

A fit and proper money laundering reporting officer with at least two years' AML/CFT experience, whose appointment is reviewed annually and who reports to the board every quarter.

How long must VASPs keep records in the UAE?

At least five years under the federal law. VARA requires Dubai VASPs to keep AML records, including transaction records, for at least eight years.

Are privacy coins allowed in the UAE?

No. The national Travel Rule prohibits VASPs from transferring privacy tokens, the CBUAE's payment-token regulation bans privacy tokens for anyone in or targeting the UAE, Dubai bans anonymity-enhanced cryptocurrencies, and the Decree-Law makes dealing in fully anonymous virtual assets an offence.


See how Creodata's AML compliance software in the UAE handles screening, monitoring and goAML reporting for virtual asset service providers: book a demo.

More guides for the UAE

See AML Compliance Software in action.