Financial crime compliance

AML/CFT/CPF as an operating discipline.

For virtual asset businesses, financial-crime risk is inseparable from onboarding, wallet exposure, transaction flows, sanctions, governance, technology and regulatory reporting. The framework must be risk-based, documented and operational.

UAE federal AML/CFT framework and regulator rulebooks reviewed through 31 August 2026.
01

ML/TF/PF risk assessment

Build enterprise-wide risk assessments around products, services, customers, geographies, delivery channels, transactions and virtual asset-specific exposures.

02

Customer due diligence

Design identification, verification, beneficial-ownership, source-of-funds / source-of-wealth and enhanced due-diligence processes as required by the applicable framework.

03

Sanctions & targeted financial sanctions

Operationalise sanctions screening, escalation, restrictions, governance and evidence across customers, counterparties, transfers and relevant assets.

04

Transaction monitoring

Develop risk-based monitoring scenarios, alert handling, investigation, escalation and quality controls that reflect actual transaction patterns.

05

Suspicious transaction reporting

Structure processes for escalation, investigation, decision-making and reporting to the relevant authority, including MLRO accountability where applicable.

06

Travel Rule & transfer controls

UAE Virtual Assets Travel Rule requirements can apply to VASPs within the federal, emirate, free-zone and financial-free-zone perimeter. Controls must address required originator/beneficiary data and risk-based treatment of unhosted-wallet transfers.

UAE regulatory stack

The control framework sits across multiple layers.

Federal

AML/CFT and proliferation-financing law

VARA’s published federal AML/CFT laws register reflects Federal Decree-Law No. (10) of 2025 and Cabinet Resolution No. (134) of 2025, which replaced the prior 2018/2019 framework listed on VARA’s rulebook portal.

Dubai

VARA compliance framework

VARA’s Compliance and Risk Management Rulebook contains compliance management, AML/CFT, risk-assessment, regulatory reporting and related requirements for VASPs licensed by VARA.

Transfer

UAE Virtual Assets Travel Rule

The CBUAE Travel Rule is marked “In-Force” and applies to VASPs within the stated territorial scope, including transfers involving another VASP and specific risk-based controls for transfers to or from unhosted wallets.

International

FATF Recommendations

FATF Recommendation 15 continues to anchor the international AML/CFT framework for virtual assets and VASPs. The 2026 targeted update records ongoing implementation gaps; Recommendation 16 is also evolving globally, with revised standards scheduled for end-2030 implementation.

Regulatory terminology is jurisdiction-specific. “MLRO”, “Compliance Officer”, “Authorised Person”, “VASP”, “Crypto Token”, “Virtual Asset”, “VA Activity” and “Crypto-Asset Service” should not be treated as interchangeable labels.