Regulatory perimeter

Four regulatory frameworks. Different legal concepts.

The strategic question is not which jurisdiction sounds most attractive. It is which regulator, licence / permission, activity definition, client perimeter and control framework fit the proposed business model.

Verified regulatory baseline: 31 August 2026.
Dubai · VARA

Virtual Assets Regulatory Authority

VARA regulates virtual asset activities in and from Dubai outside the Dubai International Financial Centre. Relevant businesses may require a VASP licence for specified VA Activities; the framework includes compulsory rulebooks plus activity-specific requirements.

Abu Dhabi · ADGM

Financial Services Regulatory Authority

ADGM’s FSRA regulates financial services involving Virtual Assets through its financial services framework. Applicants seeking regulated activities in relation to Virtual Assets apply for a Financial Services Permission and must address the applicable FSRA rules and guidance.

DIFC · DFSA

Crypto Token framework

In the DIFC, the DFSA regulates financial services activities involving Crypto Tokens. The updated Crypto Token regime took effect on 12 January 2026 and places responsibility on firms to determine, document and monitor token suitability under the applicable rules.

Bahrain · CBB

Crypto-asset Module (CRA)

The Central Bank of Bahrain regulates crypto-asset services through Volume 6 (Capital Markets), Module CRA. The module addresses licensing, licensing conditions, minimum capital, business standards and ongoing obligations.

The perimeter decision

Start with activities, not branding.

Scope

What is the firm doing?

Exchange, broker-dealer, custody, transfer/settlement, management/investment, lending/borrowing, advisory, issuance, or a regulated financial service involving Crypto Tokens / Virtual Assets.

Location

Where is the activity conducted and from where?

Dubai outside DIFC, ADGM, DIFC and Bahrain apply distinct supervisory perimeters and licensing concepts.

Clients

Who is being served?

Retail, qualified, institutional and other client classifications can affect permissions, controls and disclosures depending on the framework.

Controls

What must operate on day one?

AML/CFT, risk management, governance, technology, custody / client asset controls and reporting should be treated as operating capabilities, not application paperwork.