← Insights

AML Compliance for Crypto Businesses in UAE

Federal AML law, the VARA and FSRA regimes, and what virtual asset service providers must put in place

How federal law and the VARA and ADGM regimes apply AML obligations to virtual asset service providers. Covers the risk-based approach, customer and enhanced due diligence, wallet screening and transaction monitoring, and suspicious transaction reports. Then the Travel Rule, DeFi, blockchain analytics and the MLRO.

Reviewed by Mohamed Noureldin, Founder, Managing Partner & Senior Legal Consultant

A crypto business licensed in the UAE does not answer to a single set of anti-money laundering rules. Federal law applies to it, and so do the rules of the authority that licenses it, such as VARA in the Emirate of Dubai outside the DIFC or the FSRA in Abu Dhabi Global Market. Failure to comply exposes the business to large financial penalties, operational restrictions and severe reputational damage.

The UAE has become a global hub for financial technology and virtual assets, with regulatory bodies such as VARA and the FSRA driving its stance. That growth is tied to stringent obligations, particularly on Anti-Money Laundering (AML) and Counter-Terrorist Financing (CTF). For any entity in the virtual asset space, from exchanges and custodians to DeFi platforms and token issuers, AML compliance is more than a legal requirement. It underpins trust in the business and its ability to keep operating. See our crypto regulation compliance advisory.

Federal law is the foundation

The UAE's regulation of virtual assets involves both federal laws and specific free zone regulations. Working out which rules apply to which VASP takes care.

At the federal level, the cornerstone of AML regulation is Federal Decree by Law No. (10) of 2025 Regarding Anti-Money Laundering, and Combating the Financing of Terrorism and Proliferation Financing. This legislation mandates that Designated Non-Financial Businesses and Professions (DNFBPs) and, as a separate category, VASPs must establish and maintain effective AML/CTF programmes.

Federal bodies involved include:

  • The Central Bank of the UAE (CBUAE), which oversees financial institutions and sets broad AML standards.
  • The Financial Intelligence Unit (FIU), which receives and analyses Suspicious Transaction Reports (STRs).

See also our crypto regulation compliance services.

VARA in Dubai, the FSRA in ADGM

The UAE's financial free zones, ADGM and the Dubai International Financial Centre (DIFC), have their own regulatory bodies. These often impose even stricter requirements.

Dubai: the Virtual Assets Regulatory Authority

VARA is the primary regulator for virtual assets in the Emirate of Dubai, excluding the DIFC. Its regulations impose requirements on licensed VASPs, with significant emphasis on risk management, governance and AML protocols.

More on our crypto regulation compliance team.

Abu Dhabi Global Market

The FSRA in ADGM was one of the first regulators globally to introduce a framework for virtual assets. Its AML rules are set out in the Anti-Money Laundering and Sanctions Rulebook (AML). They demand high standards of due diligence and transaction monitoring from ADGM-licensed VASPs.

Risk assessment comes before the controls

The risk-based approach (RBA) is central to the UAE's AML philosophy. VASPs must not treat all customers or transactions equally. Instead, they must:

  • Identify risks. Conduct a thorough institutional risk assessment, analysing geographical risks, customer types, products and services offered (for example, mixing services and privacy coins), and delivery channels.
  • Mitigate risks. Develop controls commensurate with the risks identified. For instance, a VASP dealing primarily with high-volume, cross-border transactions must implement more stringent controls than one dealing with small, localised transactions.
  • Document. Maintain detailed records of the risk assessment and the rationale behind the mitigation strategies.

See our AML compliance advisory.

Knowing the customer and who stands behind it

Know Your Customer (KYC) protocols are the first line of defence against money laundering.

Standard customer due diligence

  • Identity verification: obtaining and verifying the identity of the customer, whether an individual or a corporate entity.
  • Beneficial ownership: identifying and verifying the natural persons who ultimately own or control the customer, the Ultimate Beneficial Owners (UBOs).
  • Purpose of the relationship: understanding the nature and purpose of the business relationship.

Enhanced due diligence

Enhanced due diligence (EDD) is mandatory for high-risk customers, including:

  • Politically Exposed Persons (PEPs).
  • Customers from high-risk jurisdictions, as identified by the Financial Action Task Force (FATF).
  • Customers engaging in complex, unusual or high-value transactions.
  • Corporate structures that appear overly complex or opaque.

For crypto businesses, this also extends to verifying the source of funds and the source of wealth, especially for large initial deposits or withdrawals.

More on our AML compliance services.

Screening wallets and flagging transactions

Virtual assets move fast and across borders. That makes real-time transaction monitoring crucial.

VASPs must screen customer and counterparty wallets against global sanctions lists, for example those of the UN and OFAC, and against internal blacklists. Specialised blockchain analytics tools are essential for identifying wallets associated with illicit activities, for example darknet markets, ransomware and sanctioned entities.

Systems must be in place to flag transactions that exceed pre-defined monetary thresholds or show suspicious patterns, such as:

  • Structuring, which means breaking large transactions into smaller ones to evade reporting.
  • Rapid, unexplained movements of funds.
  • Transactions involving unhosted or decentralised wallets where the counterparty's identity is unknown.

Reporting to the FIU without tipping off the customer

A transaction or activity is suspicious when it potentially relates to money laundering or terrorist financing. When a VASP identifies one, it must file a Suspicious Transaction Report (STR) or Suspicious Activity Report (SAR) with the UAE FIU.

  • Confidentiality: reporting must be done immediately and confidentially. Tipping off the customer that a report has been filed is a serious offence.
  • Documentation: all internal investigations, and the rationale for filing or not filing an STR, must be thoroughly documented and retained.

Where the technology makes compliance harder

The regulatory framework is clear. Implementing it presents challenges for VASPs because of the technology itself.

The Travel Rule

The FATF Travel Rule requires VASPs to obtain, hold and transmit specific originator and beneficiary information for virtual asset transfers exceeding a certain threshold. VASPs must implement technological solutions, for example VASP-to-VASP messaging protocols, so that the required data accompanies the transfer.

Compliance becomes complex when transacting with unhosted (self-custodied) wallets. VASPs must develop risk-mitigation procedures, such as requiring proof of ownership or limiting transaction amounts with unverified wallets.

Decentralised finance

DeFi platforms present a significant regulatory hurdle because they often lack a central intermediary. UAE regulators are increasingly scrutinising DeFi activities. Platforms that enable regulated activities, for example lending or trading, must identify the responsible entity, for example a foundation or developers. They must also ensure they comply with the UAE's crypto AML requirements.

See our crypto regulatory compliance practice.

Sanctions screening and blockchain analysis

Traditional AML systems are insufficient for virtual assets. VASPs must integrate advanced blockchain analytics tools to:

  • Trace the history of funds.
  • Identify exposure to high-risk entities.
  • Continuously monitor customer wallets for changes in risk profile.

The MLRO and the written programme

A successful virtual asset compliance programme in the UAE must be dynamic and fully integrated into the VASP's operational structure.

Every VASP must appoint a designated Money Laundering Reporting Officer (MLRO). This individual must be:

  • Senior and competent: with sufficient seniority, authority and expertise in both AML regulations and virtual asset technology.
  • Independent: reporting directly to senior management or the board.

The MLRO is responsible for overseeing the entire AML programme, managing internal controls, and acting as the liaison with regulatory authorities and the FIU. The VASP must also document and implement internal policies and procedures.

Nour Attorneys offers crypto regulation compliance advisory, AML compliance advisory, data regulation compliance advisory and legal consultation services.

Disclaimer: the information in this article is for general informational purposes only and does not constitute legal advice. Readers should seek professional legal advice tailored to their specific circumstances before making any decisions or taking any action based on it.

Further reading

Call Us NowChat With Our Team On WhatsApp