
The opportunity is real, and so is the complexity
The United Arab Emirates (UAE) has established itself as one of the world's most attractive markets for virtual asset businesses. Supported by dedicated regulatory frameworks, a sophisticated investor base, an active civil society network, and a consistently pro-innovation policy stance, the country continues to attract firms from across the globe seeking a credible presence in a high-growth, well-regulated market.
Many new entrants to the UAE market assume that pro-growth means light-touch regulation. It does not. While the country does have a regulatory framework that balances financial stability, consumer protection, growth and innovation, there is minimal tolerance for practices that give rise to financial crime. The Anti-Money Laundering and Countering the Financing of Terrorism (AML/CFT) landscape is often more complex than anticipated. Firms frequently assume that compliance frameworks developed in other jurisdictions can be transferred to the UAE with minimal adaptation. In practice, that assumption can create significant regulatory risk.
Financial crime in the UAE is a criminal matter governed by the Federal Law1. These requirements apply consistently across the country. However, oversight of compliance sits within a broader regulatory ecosystem, with supervisory authorities responsible for assessing compliance, conducting inspections, and enforcing regulatory expectations within their respective remit.
For Virtual Asset Service Providers (VASPs) and digital assets activity more broadly, understanding this distinction is critical. Success in the UAE requires more than compliance with the Law itself; it requires understanding how that Law is supervised and enforced by the regulator responsible for your business.
The opportunity is significant, but firms that underestimate UAE specific AML/CFT expectations may face licensing delays and costly remediation efforts.
Why the UAE regulatory setup is unlike anywhere else
One of the first challenges firms encounter when entering the UAE virtual asset market is understanding the regulatory landscape itself. Unlike many jurisdictions, the UAE does not operate through a single virtual asset regulator. Instead, the framework has multiple possible entry points across federal, Emirate-level and financial free zone regulators. A single business model may require more than one regulator’s licence.
Importantly, differing regulatory approaches do not create weak points for entry.
For firms operating in jurisdictions with a single regulator and a single rulebook, this makes early regulatory mapping essential. Common questions include which regulator applies to the proposed business model, whether multiple licenses may be required, and what a robust UAE ready compliance programme should look like from day one.
The regulatory map: who does what?
The relevant regulator will depend on where the business is established and the activities it intends to undertake.
Capital Markets Authority (CMA), which replaced the Securities and Commodities Authority (SCA) on 1 January 2026
Regulates virtual asset activities at the federal level outside the Financial Free Zones (FFZ). Its Decision No. 4/R.M/2026 framework sets out eight licensed activities, from dealing and custody to portfolio management, each with its own capital and compliance requirements.
Central Bank of the United Arab Emirates (CBUAE)
Relevant where the business model touches banks, exchange houses, payment service providers, stored value facilities, or payment token services. All AED payment activity ultimately falls within the CBUAE's remit. Recent regulatory developments have also enabled CBUAE-regulated institutions (other than insurance companies) to undertake certain virtual asset activities, further strengthening the link between the traditional financial sector and the UAE's virtual asset ecosystem.
Dubai Financial Services Authority (DFSA) and Financial Services Regulatory Authority (FSRA)
The DFSA and FSRA regulate the Financial Free Zones of the UAE. They regulate virtual asset activities in or from the Dubai International Financial Centre (DIFC) and Abu Dhabi Global Market (ADGM), relevant for firms choosing the DIFC or ADGM ecosystem.
Virtual Assets Regulatory Authority (VARA)
Regulates virtual asset activities in Dubai outside the DIFC, with activity-specific licensing and dedicated AML/CFT expectations for VASPs.
Critical insight
The choice of regulator shapes how AML/CFT obligations are supervised, assessed and enforced in practice.
What regulators actually expect: the AML/CFT framework
UAE regulators are not looking for compliance on paper. They assess whether controls exist, whether they are proportionate to risk, and whether they operate effectively in practice. Recent enforcement actions have made this clear, targeting VASPs for governance failures and unlicensed activities.
The AML/CFT areas that regulators focus on most consistently include:
- Governance structures and accountability: who is responsible, at what level, and how oversight is exercised in practice.
- Senior management: qualifications, experience, and fit and proper assessments for key roles.
- Policies and procedures: tailored to UAE legal requirements.
- Business-wide and customer-level risk assessments: reflecting the specific risks of the business model, product set, and customer base.
- Know Your Customer (KYC), Customer Due Diligence (CDD), and Enhanced Due Diligence (EDD): with appropriate differentiation based on risk, and evidence of how decisions are made.
- Sanctions and Politically Exposed Person (PEP) screening: with clear methodologies, escalation paths, and documentation.
- Transaction monitoring: calibrated to the firm's risk profile, with documented rationale for alert thresholds and dispositions.
- On-chain analytics: increasingly expected for businesses dealing in virtual assets, as a tool for assessing counterparty and transaction risk.
- Travel Rule compliance: including the technical and operational capacity to share and receive required originator and beneficiary information.
- Suspicious Transaction/Activity Reporting (STR/SAR) and recordkeeping: timely, accurate, and in line with the goAML reporting obligations applicable across the UAE.
The depth and emphasis placed on each of these areas will vary across regulators. What does not vary is the expectation of genuine effectiveness, regulators will assess not only whether a framework exists, but whether it works in practice.
How to get it right: a practical roadmap
Firms entering the UAE virtual asset market can reduce regulatory friction considerably by focusing on five key steps from the outset.
The choice of jurisdiction should be driven by the proposed business model, target market, and long-term operating strategy rather than speed of market entry alone.
Before starting the licensing process, firms should establish which activities are regulated, which regulator applies, and whether multiple regulatory touchpoints may exist.
The compliance programme should align with the federal AML/CFT framework while also reflecting the supervisory expectations of the chosen regulator.
Early engagement helps clarify expectations and supports a smoother authorisation process.
AML/CFT is not solely a licensing exercise. It is a living framework that evolves alongside the business.
Key takeaways
- The UAE remains one of the world's most attractive markets for virtual asset businesses, but regulatory complexity should be addressed early in the market entry process.
- For financial crime compliance, the legal framework is unified at the federal level, while supervisory expectations vary across regulators.
- Jurisdiction selection is not solely a licensing decision; it is also a strategic AML/CFT decision.
- While regulators may differ, the underlying financial crime risks remain consistent, including money laundering, terrorist financing, proliferation financing, sanctions evasion, and illicit value transfer.
- Firms that invest early in regulatory mapping, governance, and UAE tailored controls will be better positioned to enter the market, scale sustainably, and withstand supervisory scrutiny.
How we support you
Few advisers see all five UAE regulators at work across a single market. Our team at Grant Thornton does. That means we can tell you not just what one regulator requires, but how the CMA, CBUAE, DFSA, FSRA and VARA differ in practice, and where a business model needs more than one licence.
From regulatory mapping and licensing strategy to the design of UAE-tailored AML/CFT/CPF frameworks, we help clients enter the market with a compliance model built for how it is actually supervised here, not how it works somewhere else.
Our support extends across both dimensions of compliance: understanding the federal AML/CFT framework and addressing the supervisory expectations of the regulator responsible for the business. We work with clients to align their operating model with applicable regulatory requirements and implement effective controls across governance, risk assessments, transaction monitoring, sanctions compliance, and regulatory reporting.
Special thanks to Christophe Sebaaly for contributing to this article.
1 Federal Decree-Law No. (10) of 2025 Regarding Anti-Money Laundering, and Combating the Financing of Terrorism and Proliferation Financing, together with its implementing regulations issued under Cabinet Resolution No. (134) of 2025