Do we need a VARA licence or an ADGM authorisation?
It depends on where the activity is performed and which regulatory perimeter it falls into. VARA supervises virtual asset activity in the Emirate of Dubai outside the DIFC. ADGM operates its own framework through the FSRA, and the SCA has a role at federal level. The right answer follows from the business model, the jurisdiction of the operating entity and where clients are solicited — which is why EGRC starts with an activity mapping rather than a licence choice.
What does the Travel Rule mean in practice?
For qualifying virtual asset transfers, originator and beneficiary information must travel with the transaction. Practically, this means being able to send the required data, receive and validate it on inbound transfers, handle counterparties who cannot support the standard, and apply a documented policy to transfers involving unhosted wallets. It is as much a data and vendor question as a compliance one.
Is blockchain analytics a substitute for customer due diligence?
No. On-chain analytics tells you about wallet behaviour and exposure to illicit clusters; customer due diligence tells you who the customer is and why they are transacting. They answer different questions. A defensible framework uses analytics to inform risk ratings and monitoring, while keeping identification, verification and source-of-funds work in the CDD process.
How is proliferation financing relevant to a virtual asset business?
Counter-proliferation financing obligations sit alongside AML and CFT in the UAE framework. For virtual asset businesses the practical exposure is exposure to sanctioned jurisdictions and designated parties through pseudonymous transfers, which is why sanctions screening, wallet screening and escalation procedures need to be designed together rather than as separate controls.
We are pre-launch. When should compliance work start?
Before the application, not after. Authorisation assessments look for controls that exist and operate, so the risk assessment, policies, monitoring approach, custody model and governance need to be built into the launch plan. Retro-fitting a control environment onto a live platform is consistently slower and more expensive than designing it in.