Getting a VARA licence is one stage of running a virtual asset business in Dubai. Keeping that licence is an ongoing job.
A licensed Virtual Asset Service Provider, or VASP, must maintain its AML framework, monitor transactions, screen customers and wallets, meet Travel Rule requirements and keep VARA informed through recurring regulatory reports. Governance, cybersecurity, record keeping and staff training also sit inside the compliance framework.
The VARA compliance requirements became more significant in 2026 because the UAE introduced an updated federal AML framework. Cabinet Resolution No. 134 of 2025, which implements Federal Decree-Law No. 10 of 2025, became effective on 14 December 2025 and applies to VASPs. VARA followed with several 2026 circulars covering the Travel Rule, AML/CFT implementation, proliferation financing and business risk assessments.
VARA Compliance Requirements at a Glance
Area | Main 2026 requirement |
AML/CFT | Risk-based AML/CFT and proliferation financing controls |
KYC/CDD | Customer and beneficial-owner verification with enhanced checks for higher-risk cases |
Risk assessment | Business and client AML risk assessments reviewed at least every three months |
Travel Rule | Originator and beneficiary information for qualifying VA transfers |
Sanctions | Real-time screening and immediate freezing when required |
Governance | Board oversight, independent compliance function and clear segregation of duties |
Reporting | Monthly, quarterly and annual regulatory submissions |
Records | Generally at least eight years under VARA requirements |
STR reporting | Immediate reporting through the UAE FIU system when suspicion arises |
Training | Regular AML/CFT training for relevant staff |
VARA's Compliance and Risk Management Rulebook applies to all licensed VASPs alongside the Company, Technology and Information and Market Conduct Rulebooks. Activity-specific requirements apply on top of these compulsory rules.
1. Build an AML/CFT Programme Around Actual Risk
VARA expects your AML programme to reflect what your business actually does. A broker serving retail clients, for example, does not have the same exposure as a custodian handling institutional wallets.
Your controls should cover customer risk, geographic exposure, products, delivery channels, virtual assets used and transaction patterns. VARA specifically expects VASPs to consider risks linked to unhosted wallets, anonymity-enhanced transactions, DeFi activity, cross-border transfers, stablecoins and emerging fraud techniques.
Blockchain transaction monitoring also plays a direct role. VARA expects appropriate distributed-ledger analytics or investigative capabilities for screening transactions and wallet addresses. The effectiveness and weaknesses of those tools should be documented rather than treated as a one-time software purchase.
For a broader explanation of UAE AML duties, see Nexture's UAE AML compliance guide.
- Update AML Risk Assessments Every Three Months
This is one of the easier VARA requirements to underestimate.
VARA requires AML/CFT business risk assessments and client risk assessments to be carried out at intervals of no longer than three months. A new assessment may also be needed when the business introduces a new product, technology or service or when its risk profile changes materially.
In June 2026, VARA published specific Business Risk Assessment guidance based on its supervisory review of licensed VASPs. The guidance says a strong assessment should use operational evidence such as customer-risk distributions, transaction-monitoring alerts, STR trends, sanctions results, geographic exposure and audit findings. Board approval and documented challenge are also treated as strong practice.
So a generic AML template that gets updated once a year is unlikely to match current supervisory expectations.
- Apply Proper KYC and Customer Due Diligence
A VASP must identify and verify customers and, where applicable, their ultimate beneficial owners.
CDD is required when establishing a business relationship and for occasional transactions of AED 3,500 or more, including linked transactions. It also applies when there is suspicion of criminal activity or doubt about previously obtained customer information. Higher-risk relationships require enhanced due diligence, which can include additional identification, source-of-funds and source-of-wealth checks and greater transaction monitoring.
The federal rules also require VASPs to identify a natural person who ultimately owns or controls 25% or more of a legal person where applicable, followed by further control tests if that does not identify the beneficial owner.
- Follow the UAE Virtual Assets Travel Rule
The Travel Rule deserves particular attention in 2026 because VARA issued an implementation circular on 24 February, the UAE Virtual Assets Travel Rule published in the CBUAE Rulebook.
For qualifying VASP-to-VASP transfers, the originator's VASP must collect, verify and securely transmit required originator and beneficiary information so that it accompanies the transfer. VARA also expects the originating VASP to confirm that the beneficiary VASP is appropriately regulated.
There is an important detail around the AED 3,500 figure. Under VARA's 2026 circular, transfers below the daily aggregated AED 3,500 threshold still need the required originator and beneficiary information to accompany them. The threshold affects identity verification: at AED 3,500 or more, beneficiary verification is required where the beneficiary has not previously been verified. Below the threshold, verification is generally not required unless there is suspicion or another higher-risk indicator.
For transfers involving unhosted wallets, VARA expects enhanced due diligence, including additional customer identification and source-of-funds verification. If the required information cannot be obtained or the risk cannot be sufficiently managed, the VASP may need to decline, delay or return the transfer.
- Screen Customers, Transactions and Wallets for Sanctions
Sanctions screening should operate continuously rather than sitting only at onboarding.
VARA requires VASPs to screen customers and transactions against applicable United Nations and UAE sanctions lists. Automated screening systems should remain updated and operate in real time. Where a confirmed designation requires freezing, the relevant virtual assets or funds must be frozen without delay and cannot be transferred or withdrawn.
The 2026 focus also extends to proliferation financing. VARA's June 2026 circular required VASPs to review their exposure against the UAE Proliferation Financing National Risk Assessment, update controls and policies and retain evidence of the work undertaken. The circular gave affected VASPs 30 calendar days to complete the alignment review.
- Give Compliance Direct Access to the Board
VARA expects compliance to be independent of revenue-generating and operational functions.
The Compliance Officer must have at least five years of relevant compliance experience, meet VARA's Fit and Proper standard, be a UAE resident or UAE passport holder, work full time for the VASP and report directly to the Board.
A separate MLRO is also required. The VARA rulebook states that the MLRO must have at least two years of AML/CFT experience and meet Fit and Proper requirements. The MLRO must report on the effectiveness of the AML framework to the Board quarterly.
The Board itself retains responsibility for regulatory compliance. Compliance, internal audit and operational duties should be appropriately separated so that the same people are not effectively checking their own work.
- Report Suspicious Activity Without Delay
A transaction does not need to be proven criminal before reporting becomes relevant.
VASPs must continuously monitor business relationships and escalate suspicious transactions to the MLRO. When the required suspicion threshold is met, the MLRO must report to the UAE Financial Intelligence Unit through the approved electronic reporting system. VARA's rulebook also requires responses to additional FIU or VARA information requests promptly and, under the relevant rule, within 48 hours.
VARA's March 2026 circular again stated that suspicious transactions and activities should be reported to the UAE FIU immediately and without delay.
- Prepare for Monthly, Quarterly and Annual VARA Reporting
Compliance continues after the licence is issued.
Monthly submissions include financial information such as the balance sheet, profit and loss information, cash-flow statements, VA wallet addresses and certain related-party and group transactions.
Quarterly reporting includes Board and committee minutes, evidence of compliance with financial requirements, financial projections and risk exposure reporting.
Annual submissions include audited financial statements, an independent auditor's assessment of internal controls, Senior Management's compliance assessment, company and UBO information and governance details. VARA also requires a representative sample of client-onboarding records, including documentation for the first 100 clients onboarded during the year.
- Keep an Eight-Year Audit Trail
VARA generally requires AML and wider compliance records to be maintained for at least eight years.
That can include transaction records, customer due diligence files, monitoring records, STR information, wallet data, Board minutes, complaints and evidence supporting regulatory compliance.
You should be able to retrieve those records when VARA asks for them. Storing data without a clear audit trail, ownership structure or retrieval process creates a practical compliance problem even if the information technically exists.
In a 30-minute call we map your situation against jurisdiction, activity and cost — no commitment required.
Building VARA Compliance Into Your Dubai VASP
The easiest time to build compliance controls is before operations begin.
Map each licensed activity against the applicable VARA rulebooks. Define who owns KYC, transaction monitoring, Travel Rule checks, sanctions alerts and regulatory reporting. Set recurring dates for the three-month AML risk reviews and monthly, quarterly and annual submissions. Then test whether your systems produce evidence that an auditor or VARA supervisor can actually follow.
We’ll model the requirements and send back a single-page breakdown within 24 hours.
Conclusion
The VARA compliance requirements in 2026 go well beyond basic KYC.
Licensed VASPs need an independent compliance structure, active Board oversight, regular AML risk assessments, transaction and wallet monitoring, Travel Rule controls, sanctions screening and a disciplined regulatory reporting process. The updated UAE federal AML framework and VARA's 2026 supervisory circulars make it especially important to work from current rules rather than older compliance templates.
VARA continues to issue guidance and supervisory updates, so policies should be treated as working documents and reviewed whenever rules, risks or the VASP's business model change. FATF's July 2026 virtual-assets update also notes that Travel Rule implementation and supervision continue to develop internationally.
Frequently Asked Questions
What are the main VARA compliance requirements in 2026?
A licensed VASP generally needs AML/CFT controls, customer due diligence, transaction monitoring, Travel Rule procedures, sanctions screening, governance controls, regulatory reporting, staff training, auditing and adequate record-keeping.
What is the VARA Travel Rule threshold?
AED 3,500 is an important verification threshold, but it should not be treated as meaning that transfers below AED 3,500 have no Travel Rule requirements. Under VARA's February 2026 circular, required originator and beneficiary information must still accompany qualifying transfers below the threshold, while identity verification rules change based on the amount and risk.
How often must a VASP update its AML risk assessment?
VARA requires both business and client AML/CFT risk assessments to be conducted at intervals of no longer than three months, with additional reviews when significant changes occur.
How long must VARA VASPs keep AML records?
VARA requires relevant AML/CFT records to be retained for at least eight years.
Does VARA require a Compliance Officer and MLRO?
Yes. VARA sets separate qualification and responsibility requirements for the Compliance Officer and MLRO, although certain non-client-facing roles may be combined where permitted and conflicts are properly managed.


