Resolving Crypto Regulation Compliance Advisory Disputes Effectively
Scope, assumptions and the date of the advice decide these cases long before anyone reaches a tribunal.
Disputes between crypto firms and their compliance advisers turn on the retainer, not the rules. What the engagement letter should record, how to map obligations across several advisers, and how to draft a dispute clause that names an institution and a seat.
Reviewed by Mohamed Noureldin, Founder, Managing Partner & Senior Legal Consultant
The typical dispute between a crypto business and its compliance adviser does not begin with a disagreement about the law. It begins with a letter from a regulator, followed by a conversation in which the client says the adviser should have raised the point and the adviser says the point was never within the retainer. Both are usually describing the same engagement letter, and neither has read it since it was signed.
That is worth knowing before drafting the dispute resolution clause, because it tells you where these matters are actually decided. The contested question is rarely what the rules require. It is what was asked for, what was advised, what the client told the adviser, and when.
Related: our crypto regulation compliance practice advises firms and their advisers.
Be specific about which regime the advice covers
A firm with a UAE presence may be dealing with more than one regulator at once. The Dubai International Financial Centre operates under a common-law framework supervised by the Dubai Financial Services Authority. The Abu Dhabi Global Market has its own common-law regime supervised by the Financial Services Regulatory Authority. Requirements sit at federal level as well, and a group with entities in more than one place is subject to more than one set of obligations at the same time.
Advice written for one of those regimes and applied by the client to another is a common origin of these disputes. The remedy is drafting rather than argument: state on the face of the advice which entity, which regime and which activity it addresses, and say expressly what it does not cover. An adviser who writes “this note concerns the DFSA-regulated entity only and does not address the ADGM subsidiary or any federal requirement” has removed a whole category of later disagreement in one sentence.
What the engagement letter has to record
A compliance retainer that will survive being read back in anger sets out more than a fee. The items that decide these disputes are these.
- Scope, with exclusions. Which entities, which activities, which regimes. What is outside: tax, employment, data protection, sanctions screening, marketing approval, or whatever the client is going to assume was included.
- The information the advice rests on. Advice is only as good as the description of the business it was given. Record the documents and the client statements relied on, and say that the adviser has not verified them.
- Assumptions. Written out, not implied. Product design in this sector changes faster than advice does, and an assumption that a token is not offered to retail users is worth stating.
- A date and a review trigger. Say the advice reflects the position at the date given, and identify the events – a change in the product, a new licence application, a regulatory consultation closing – that should bring the client back.
- Who may rely on it. Advice circulated to investors, banking partners or an acquirer generates claims from people who never paid for it.
- The form of the deliverable. If only written advice counts, say so. Otherwise a remark in a call becomes the pleaded case.
Liability provisions matter too, but they operate on whatever scope the rest of the letter has defined. A cap on liability is of limited use if the retainer is written so broadly that everything the client does falls inside it.
Related: we advise on the same questions in data protection engagements through our data regulation compliance practice.
Map the retainers against each other
Crypto businesses rarely have one adviser. There is usually a regulatory adviser, an auditor, a tax adviser and sometimes a separate anti-money-laundering consultant, each with its own scope. Obligations fall between them because nobody owns the gap. Value added tax is a recurring example: it applies at 5 per cent under the federal VAT regime, and the question of which supplies are taxable is a tax question that a regulatory retainer will not have touched. Corporate tax under Federal Decree-Law No. 47 of 2022 sits in the same category.
The exercise is simple and rarely done. List the firm’s obligations, write the name of the adviser responsible next to each, and circulate the list. Whatever has no name against it is the client’s own responsibility, which is at least better than believing it is someone else’s.
Related: our VAT and tax advisory team covers the tax side of the same operations.
When a dispute starts, protect the file first
Before positions harden, secure the record: the engagement letter and any variations, every version of the advice, the instructions and information the client supplied, meeting notes, and the correspondence in which scope was discussed. In a sector where teams turn over quickly and communication happens on messaging platforms, this material disappears unless someone acts to keep it.
Keep the private dispute separate from the regulatory one. If the regulator has opened an inquiry or a notification is due, that process has its own deadlines and its own consequences, and it does not pause while the client and the adviser argue about the retainer. Attend to the regulator on its timetable and run the contractual dispute behind it.
Choosing where the dispute goes
Confidentiality usually points these matters towards arbitration. The advice under examination will describe the firm’s product, its customer base and its control weaknesses, none of which the client wants on a public record while it holds or is applying for a licence.
If arbitration is the choice, name a real institution and a real seat: DIAC administering, with a seat in the DIFC or the ADGM, is a straightforward combination for parties already operating in those jurisdictions. Alternatively the DIFC or ADGM courts can be given exclusive jurisdiction, which suits parties who prefer a common-law court to a tribunal. What does not work is a clause that names a city and nothing else.
Where the disagreement is narrow and technical – whether a particular deliverable met a defined standard – expert determination by an agreed specialist resolves it faster than either. A staged clause requiring a meeting between senior people, then mediation, then arbitration, filters out the disputes that only needed a conversation, provided the steps have time limits so they cannot be used to stall.
The short version
Write the scope so that the exclusions are as clear as the inclusions. Date the advice and say what would change it. Map every obligation to a named adviser so nothing sits in a gap. Keep the file. And put a clause in the retainer that names an institution, a seat and a sequence, so that when the letter from the regulator arrives, the only argument is about the substance.
Related Services: speak to our crypto regulation compliance advisory team about retainer terms and disputes.
Disclaimer: The information provided in this article is for general informational purposes only and does not constitute legal advice. Readers should seek professional legal advice tailored to their specific circumstances before making any decisions or taking any action based on the content of this article.
Nour Attorneys Team
Additional Resources
Explore more of our insights on related topics: