
Hands-on UAE company-formation specialists since 2020 · Reviewed for accuracy · Updated July 2026
Quick AnswerVASP AML compliance UAE 2026: goAML registration, Travel Rule, MLRO duties, KYC and VARA rules. What virtual-asset firms must do to stay compliant.
Anti-money-laundering compliance is the single most demanding and non-negotiable obligation for any Virtual Asset Service Provider (VASP) operating in the UAE. Whether you run an exchange, a custody business, a broker-dealer or a transfer service, your licence depends on a functioning AML programme built around three pillars: mandatory registration on the Financial Intelligence Unit's goAML platform, adherence to the Travel Rule for virtual-asset transfers, and a properly empowered Money Laundering Reporting Officer (MLRO). Getting any of these wrong risks fines, licence suspension and, in serious cases, criminal liability.
This guide explains VASP AML compliance in the UAE from a licensing and regulatory standpoint only. It is not investment advice and does not comment on any asset. It covers who counts as a VASP, the core AML obligations, how goAML and the Travel Rule work in practice, the role of the MLRO, KYC and transaction monitoring, the regulators involved, VARA licensing costs, tax registration, and the mistakes that most often trigger enforcement.
For any founder entering the UAE virtual-asset market, the message is simple: AML is the obligation on which everything else depends. You can have a brilliant product, strong funding and a talented team, but if your AML programme is weak, your licence is at risk from day one. The UAE has deliberately built a rigorous framework and enforces it, and the firms that thrive are those that treat compliance as a genuine competitive strength rather than a grudging cost. This guide is written to help you build that strength on solid foundations.
What does VASP AML compliance in the UAE require?
VASP AML compliance in the UAE requires registration on the FIU's goAML portal, a risk-based AML programme, a fit-and-proper MLRO, Travel Rule implementation for transfers above the threshold, sanctions and PEP screening, and ongoing transaction monitoring. VARA licences carry fees from AED 40,000 to AED 100,000 application and AED 80,000 to AED 200,000 annual supervision, and non-compliance can cost the licence itself.
A VASP is any business that carries on a virtual-asset activity. In Dubai, the Virtual Assets Regulatory Authority (VARA) licenses and supervises these firms across activities including exchange services, custody, broker-dealer services, lending and borrowing, management and investment, transfer and settlement, and advisory. In ADGM the equivalent oversight sits with the FSRA and in DIFC with the DFSA, while federal AML law applies nationwide. Regardless of which regulator issues the licence, the AML obligations flow from the UAE's federal anti-money-laundering framework and are enforced with real teeth.
The UAE has invested heavily in its AML regime, including its removal from international grey-list scrutiny, and it expects VASPs to operate to a high standard. That means AML is not a box-ticking exercise bolted on after launch β it is a core operating function that must be resourced, tested and continuously improved. Firms that treat it as an afterthought are exactly the ones that attract regulatory action.
| VARA activity | Application fee | Annual supervision fee |
|---|---|---|
| Advisory Services | AED 40,000 | AED 80,000 |
| Transfer & Settlement Services | AED 40,000 | AED 80,000 |
| Broker-Dealer Services | AED 100,000 | AED 200,000 |
| Custody Services | AED 100,000 | AED 200,000 |
| Exchange Services | AED 100,000 | AED 200,000 |
| Lending & Borrowing Services | AED 100,000 | AED 200,000 |
| Management & Investment Services | AED 100,000 | AED 200,000 |
The application fee is due at submission and is non-refundable; the annual supervision fee is payable in advance, per activity, every year. A licence extension for each additional activity costs 50% of the lower application fee. For the full fee picture see our VARA licence cost guide, and for how the activities are defined, the VARA licence categories guide.
Registering and reporting through goAML
goAML is the UAE Financial Intelligence Unit's reporting platform, and registration on it is mandatory for every VASP and other designated reporting entity. Through goAML you file Suspicious Transaction Reports (STRs) and Suspicious Activity Reports (SARs), as well as other required notifications. The registration process links your firm to the FIU and establishes the channel through which you discharge your reporting obligations. No VASP can operate compliantly without being registered.
The obligation is not merely to register but to actually report. Whenever your firm forms a suspicion β during onboarding, transaction monitoring, or through any red flag β that funds may be linked to money laundering, terrorist financing or a predicate offence, you must file promptly through goAML. There is no de minimis exemption for suspicion; the trigger is the suspicion itself, not a monetary threshold. Firms must also respond to FIU requests and cooperate with authorities. Failure to file when you should, or "tipping off" a customer that a report has been made, are serious offences.
Practically, this means your systems and staff must be able to detect, escalate and document suspicion, and your MLRO must have the authority and independence to file without needing commercial sign-off. Good VASPs maintain clear internal escalation procedures so that a front-line analyst's concern reaches the MLRO quickly and is properly assessed and, where warranted, reported.
The Travel Rule for virtual-asset transfers
The Travel Rule is a global standard, derived from Financial Action Task Force recommendations, that requires VASPs to collect and transmit specified originator and beneficiary information alongside virtual-asset transfers above a defined threshold. In plain terms, when value moves between VASPs, identifying data about the sender and receiver must "travel" with the transaction so that both firms β and, if needed, authorities β can trace it. VARA mandates Travel Rule compliance for its licensed firms, and the other UAE regulators impose equivalent expectations.
Implementing the Travel Rule is a genuine technical and operational challenge. VASPs must capture the required data at the point of transfer, transmit it securely to the counterparty VASP, receive and validate incoming data, and handle transfers to and from unhosted (self-custodied) wallets under a risk-based approach. Many firms adopt specialist Travel Rule solutions and interoperability protocols to exchange this information reliably between different providers. The compliance obligation includes screening the counterparty and the transaction data, not merely forwarding it.
Getting the Travel Rule right also intersects with data protection. You are transmitting personal data, so your processes must respect the UAE's Personal Data Protection Law framework and handle that information securely and proportionately. This is one of the areas where crypto-native firms most often need to mature their systems before they can pass regulatory scrutiny.
The role of the MLRO
Every VASP must appoint a Money Laundering Reporting Officer, and this is not a nominal title. The MLRO is a fit-and-proper individual, approved by the regulator, who owns the AML programme end to end: designing and maintaining policies, overseeing KYC and monitoring, receiving internal escalations, deciding on and filing STRs and SARs through goAML, liaising with the FIU and regulator, and training staff. The MLRO must have genuine seniority, independence and access to the board, so that AML decisions cannot be overridden for commercial convenience.
Because the role is so pivotal, regulators assess the proposed MLRO carefully β their experience, competence and integrity. A firm that appoints an underqualified or overstretched MLRO signals weak governance. In smaller firms the MLRO may wear more than one compliance hat, but the function must be real and adequately resourced. The MLRO should also maintain a defensible audit trail of decisions, because in an inspection the question is not only whether you reported, but whether your process for deciding was sound. To understand the wider legal footing that makes all of this enforceable, our guide on whether crypto is legal in the UAE sets out the regulatory foundations.
KYC, sanctions screening and transaction monitoring
Customer due diligence is the foundation of the whole programme. Before onboarding, a VASP must verify the customer's identity using reliable, independent data, understand the nature and purpose of the relationship, and assess the customer's risk. Higher-risk customers β including politically exposed persons (PEPs), those from higher-risk jurisdictions, or those with opaque structures β require enhanced due diligence, including establishing source of funds and source of wealth and obtaining senior management approval.
Sanctions screening is mandatory and continuous. VASPs must screen customers and, where relevant, counterparties and wallet addresses against applicable sanctions lists, and act immediately on matches, including freezing and reporting where required. Ongoing transaction monitoring then watches the relationship over time, using rules and, increasingly, blockchain analytics to flag anomalies β structuring, rapid movement through mixers, exposure to sanctioned or high-risk addresses, and patterns inconsistent with the customer's profile. Every alert must be reviewed and either cleared with reasons or escalated.
The programme must be risk-based and documented. That means a written enterprise-wide risk assessment, policies and procedures approved by senior management, defined thresholds and red flags, record-keeping for the mandated retention period, and independent testing or audit of the programme's effectiveness. Regulators expect the programme to be lived, not shelved.
Who regulates VASP AML in the UAE?
Several authorities work together. The Central Bank of the UAE (CBUAE) plays a central role in the national AML framework and supervises payment-token and stablecoin activity under the Payment Token Services Regulation. VARA is the direct licensing and AML supervisor for virtual-asset firms in Dubai outside the DIFC, issuing detailed rulebooks including compliance and risk-management rules. The Financial Intelligence Unit operates goAML and receives reports. The FSRA (ADGM) and DFSA (DIFC) supervise firms in their respective centres, and the Securities and Commodities Authority (SCA) covers securities-type tokens federally.
For a VASP, the practical takeaway is that your primary licensing regulator sets your specific rulebook, but the federal AML obligations β goAML reporting, sanctions compliance, Travel Rule, MLRO β apply across the board. Your programme must satisfy both your licensing authority's detailed rules and the overarching federal framework simultaneously.
Technology and blockchain analytics in AML
Modern VASP AML compliance is impossible without technology, because the scale and nature of virtual-asset activity outstrips what manual review can handle. Blockchain analytics tools sit at the centre of a mature programme. They trace the provenance and destination of funds across the ledger, assign risk scores to wallet addresses, flag exposure to mixers, darknet markets, sanctioned entities and known illicit sources, and let the firm decide whether to onboard a customer, clear a transaction or escalate. This on-chain visibility is unique to virtual assets and is precisely what regulators expect a VASP to use, because it enables risk decisions that traditional finance cannot make.
Transaction-monitoring systems complement analytics by applying rules and behavioural models to the firm's own activity, surfacing structuring, unusual velocity, patterns inconsistent with a customer's profile, and other red flags for human review. Sanctions-screening engines check customers and counterparties against constantly updated lists. Case-management systems record every alert, its investigation and its disposition, building the audit trail that inspections depend on. Crucially, technology does not replace judgement β every alert still needs a competent human to assess it β but it makes a risk-based programme workable at scale. VASPs should invest in tools proportionate to their volume and risk, integrate them properly, and keep them current, because outdated or poorly configured systems create blind spots that both criminals and regulators will find.
The cost and resourcing of compliance
Founders frequently underestimate what a real AML function costs, and that underestimate is itself a source of failure. A compliant VASP must fund a qualified MLRO and compliance team, licence and maintain blockchain-analytics and monitoring tools, run training programmes, commission independent testing, and keep policies, systems and records current. For a firm processing meaningful volume, this is a substantial and permanent line item, not a one-off setup cost. Treating compliance as an overhead to be minimised, rather than a core function to be resourced, is how thin programmes and enforcement problems arise.
The alternative framing is more accurate: a strong compliance function is what protects the licence, and the licence is the business. The cost of a proper AML programme is trivial compared with the cost of a suspension, a revocation or a criminal referral, to say nothing of the reputational damage. Well-run VASPs therefore build compliance into their business model from the start, size the function to the firm's real risk and volume, and scale it as they grow. They also recognise that regulators and banking partners assess the seriousness of a firm partly by how it resources compliance, so genuine investment here pays dividends in smoother supervision and easier access to banking and partnerships. In this sector, compliance is not a tax on the business β it is the foundation the business stands on.
Tax and AML: separate but both mandatory
AML compliance and tax compliance are distinct obligations, and a VASP must meet both. The UAE levies corporate tax at 9% on taxable profit above AED 375,000, administered by the Federal Tax Authority, with no personal income tax on individuals. Every VASP should register with the FTA and assess its taxable income properly; the authoritative rules are at https://tax.gov.ae/. Being AML-compliant does not discharge tax obligations and vice versa β regulators and the tax authority operate independently, and a firm must be in good standing with both.
Building a risk-based AML programme
At the heart of every compliant VASP is a risk-based approach, and it starts with an enterprise-wide risk assessment. This is a documented analysis of the money-laundering and terrorist-financing risks the firm faces across its customers, products, delivery channels, geographies and technologies. A virtual-asset exchange serving retail customers globally has a very different risk profile from an OTC desk serving a handful of institutional clients, and the AML programme must be calibrated to the actual risks rather than copied from a template. Regulators expect to see that the risk assessment genuinely drives the controls β higher risk areas get stronger controls, and the reasoning is written down.
From the risk assessment flow the policies and procedures: customer due diligence standards, risk-rating methodology, enhanced-due-diligence triggers, transaction-monitoring rules, sanctions-screening processes, escalation and reporting procedures, record-keeping and training. These must be approved by senior management, kept current, and β crucially β actually implemented. A common failing is a beautifully written policy suite that bears no resemblance to what staff actually do day to day. Regulators test the reality against the paper, so the two must match. Independent testing or audit of the programme's effectiveness closes the loop, giving the board assurance and evidence that the controls work.
Training, culture and record-keeping
A programme is only as strong as the people running it. Every VASP must train its staff β not just the compliance team β so that front-line personnel can recognise red flags, understand their reporting obligations, and know how to escalate. Training must be regular, role-appropriate and documented, and it must cover the specific typologies of virtual-asset crime: mixers and tumblers, chain-hopping, use of privacy coins, structuring across wallets, and exposure to sanctioned or darknet addresses. A firm that cannot show current, relevant training records has a visible gap.
Culture matters as much as process. The tone from the top must make clear that compliance is not negotiable and that no commercial relationship is worth a serious AML breach. Where compliance can be overridden by revenue considerations, the programme fails regardless of how good the documents look. Record-keeping underpins everything: KYC records, transaction records, monitoring alerts and their disposition, STR filings, training logs and board minutes must all be retained for the mandated period and be readily retrievable. In an inspection, the ability to produce complete, well-organised records quickly is itself a signal of a healthy programme; disorganised or missing records suggest deeper problems.
Sanctions compliance in depth
Sanctions compliance deserves particular emphasis because breaches carry some of the gravest consequences, including criminal liability, and because virtual assets create novel exposure. A VASP must screen customers at onboarding and continuously thereafter against applicable sanctions lists, and it must also address the blockchain dimension: screening wallet addresses and counterparties for exposure to sanctioned entities, using blockchain-analytics tools that trace the provenance of funds. A transaction that appears clean on its face may be linked, a few hops back, to a sanctioned address or an illicit source, and the firm is expected to detect and act on that.
When a match or exposure is identified, the firm must act immediately β freezing where required, refraining from processing the transaction, and reporting to the relevant authorities. Getting sanctions wrong is not treated as a technical slip; it is among the most serious failures a financial firm can commit. For this reason, VASPs invest in robust screening technology, keep lists current, and maintain clear, well-drilled procedures for handling hits. The stakes are high enough that under-investing here is never justified.
Ongoing supervision and enforcement
AML compliance is a living obligation subject to continuous regulatory supervision. VARA and the other UAE authorities conduct inspections, request information, and expect firms to file periodic returns and to remediate any deficiencies promptly. A finding at inspection is not necessarily fatal, but a failure to remediate, or a pattern of weak controls, escalates quickly. The UAE has demonstrated genuine willingness to enforce, and the range of consequences β fines, restrictions, licence suspension or revocation, and criminal referral for the worst cases β is real, not theoretical.
The practical lesson is that a VASP should treat its AML programme as something it continuously tests, updates and improves, feeding in new typologies, regulatory guidance and lessons from its own monitoring. The firms that stay out of trouble are those that self-identify weaknesses and fix them before a regulator does, and that can demonstrate a credible, well-resourced compliance function to any inspector who asks. Compliance maturity is a journey, and regulators reward firms that are visibly on it.
Common Mistakes in VASP AML Compliance
- Treating AML as a launch checklist. It is a continuous operating function. Firms that set it up once and never test or update it fail inspections and invite enforcement.
- Appointing a weak or overstretched MLRO. An underqualified MLRO without real authority is a governance red flag and undermines the entire programme.
- Delaying or skipping goAML registration and reporting. Registration is mandatory and reporting is triggered by suspicion, not a threshold. Late or missing filings are serious breaches.
- Under-implementing the Travel Rule. Forwarding data without screening it, or failing to handle unhosted-wallet transfers under a risk-based approach, leaves a compliance gap regulators will find.
- Weak sanctions screening. Failing to screen continuously, or ignoring wallet-level exposure, exposes the firm to sanctions breaches with severe consequences.
- Poor documentation. If decisions are not recorded, you cannot demonstrate a sound process. Regulators judge the process, not just the outcome.
- Ignoring tipping-off rules. Alerting a customer that a report has been filed is a criminal offence; staff must be trained to avoid it.
- Forgetting tax registration. AML compliance does not cover tax. Register with the FTA and assess corporate tax separately.
Building Your VASP AML Programme with Noble Core
A defensible AML programme is what stands between a licensed VASP and enforcement action, and it must satisfy both your licensing regulator's rulebook and the federal framework at the same time. Noble Core helps virtual-asset firms design and implement AML programmes end to end: enterprise risk assessment, policies and procedures, goAML registration, Travel Rule implementation, sanctions and PEP screening, transaction-monitoring design, MLRO appointment and approval, staff training and independent testing β alongside FTA corporate-tax registration so your firm is compliant on every front.
Anchor your compliance in the full regulatory context. Our crypto licence UAE pillar guide maps the regulators and licences, the is crypto legal in the UAE guide explains the legal foundations, the VARA licence categories guide defines the activities, and the VARA licence cost guide breaks down the fees. Book a free 20-minute consultation and we will assess your AML readiness and map exactly what your firm needs to stay compliant.
Talk to Our Experts
Noble Core builds AML programmes for VASPs, from goAML registration and Travel Rule to MLRO appointment. Free 20-minute consultation.
Frequently Asked Questions
What is a VASP in the UAE?
A Virtual Asset Service Provider is any firm carrying on a virtual-asset activity such as exchange, custody, broker-dealer or transfer services. In Dubai these are licensed and supervised by VARA.
Do VASPs have to register with goAML?
Yes. All UAE VASPs and other reporting entities must register on the FIU’s goAML platform and file Suspicious Transaction Reports and Suspicious Activity Reports through it. Registration is mandatory.
What is the Travel Rule?
The Travel Rule requires VASPs to collect and transmit originator and beneficiary information alongside virtual-asset transfers above a threshold, so transactions can be traced. VARA mandates it for licensed firms.
Does every VASP need an MLRO?
Yes. Every VASP must appoint a fit-and-proper Money Laundering Reporting Officer responsible for the AML programme, suspicious-transaction reporting and liaison with the Financial Intelligence Unit.
What are the penalties for AML failures?
Penalties range from significant fines to licence suspension or revocation and, for serious breaches, criminal liability. UAE authorities actively enforce AML obligations against virtual-asset firms.
How much does VARA licensing cost?
VARA fees depend on activity: Advisory is AED 40,000 application and AED 80,000 annual, while Exchange, Custody and Broker-Dealer are AED 100,000 and AED 200,000 respectively.
Do VASPs pay corporate tax?
Yes where profitable. UAE corporate tax is 9% on taxable profit above AED 375,000, administered by the FTA. AML compliance and tax registration are separate but both mandatory obligations.
What KYC must a VASP perform?
VASPs must verify customer identity, screen against sanctions and PEP lists, assess risk, conduct enhanced due diligence for higher-risk customers, and monitor transactions on an ongoing basis.
Is crypto legal in the UAE?
Yes, virtual assets are legal and regulated. Firms must be licensed by the relevant authority β VARA in Dubai, FSRA in ADGM, DFSA in DIFC β and comply fully with AML obligations.



