THE PERIMETER

Regulation has caught up with virtual assets.

The UAE now supervises virtual asset activity through several distinct frameworks. The practical difficulty is rarely the rules themselves — it is working out which perimeter a specific business model falls inside.

Which framework applies to your model?

Activity, jurisdiction and client base determine the answer. EGRC maps the business against the regulatory perimeter before any licence conversation begins.

FRAMEWORKS

Four things every virtual asset business has to answer to.

Supervision, transfers, analytics and jurisdiction shape almost every control decision a virtual asset business makes.

DUBAIVARA

The Virtual Assets Regulatory Authority supervises virtual asset activity in Dubai outside the DIFC, with its own rulebooks by activity type.

ADGMFSRA

Abu Dhabi Global Market operates a long-established framework for virtual assets and distributed ledger technology under the FSRA.

TRANSFERSTravel Rule

Originator and beneficiary information must accompany qualifying virtual asset transfers, with checks on inbound data.

ON-CHAINAnalytics

Wallet screening and blockchain analytics extend financial crime controls to counterparties who never appear in a customer file.

LICENSING PATH

Authorisation is an evidence exercise.

Applications succeed when the control environment described in the documentation is the one that actually operates. These are the four stages EGRC works through with virtual asset clients.

01 / PERIMETER

Define the regulated activity

The first question is not which licence to apply for, but which regulated activities the business model actually performs. Exchange, broker-dealer, custody, transfer and settlement, lending and management each carry different obligations, and most real businesses touch more than one.

02 / READINESS

Build the control environment

Applications are assessed on substance: governance, fit-and-proper personnel, AML/CFT framework, technology and cyber resilience, client asset segregation, and market conduct arrangements. Documentation that describes controls which do not yet operate is the most common reason for delay.

03 / SUBMISSION

Evidence the model

Business plans, financial projections, risk assessments, policies, wallet and custody architecture and outsourcing arrangements are presented as one coherent package that matches what the systems actually do.

04 / SUPERVISION

Operate under scrutiny

Authorisation is the start of the obligation, not the end. Reporting, monitoring, incident notification and periodic review continue for the life of the licence.

ACTIVITY MAP

Different activities, different obligations.

Most virtual asset businesses perform more than one regulated activity. Each carries its own control expectations — scroll across to see how the obligations change.

EXCHANGE

Exchange services

Order books, matching, listing governance and market conduct controls, with clear rules on which assets may be admitted.

CUSTODY

Custody and wallets

Key management, segregation of client assets, hot and cold wallet architecture and recovery arrangements.

BROKER

Broker-dealer

Client onboarding, suitability where relevant, order handling and best-execution style obligations.

TRANSFER

Transfer and settlement

Travel Rule data, counterparty VASP due diligence and handling of transfers to unhosted wallets.

LENDING

Lending and borrowing

Collateral management, liquidity and disclosure of risk to clients.

ADVISORY

Management and advisory

Discretionary arrangements, marketing rules and the boundary with regulated financial advice.

CAPABILITY

Where EGRC supports virtual asset businesses.

From perimeter analysis and licensing readiness through to ongoing monitoring, reporting and independent review.

VARA·FSRA · ADGM·SCA·Travel Rule·Wallet screening·Blockchain analytics·Custody·Market conduct·Proliferation financing·Tokenisation·VARA·FSRA · ADGM·SCA·Travel Rule·Wallet screening·Blockchain analytics·Custody·Market conduct·Proliferation financing·Tokenisation·
COMMON QUESTIONS

What virtual asset businesses ask first.

Practical answers to the questions that come up before a formal scope is agreed.

Do we need a VARA licence or an ADGM authorisation?
It depends on where the activity is performed and which regulatory perimeter it falls into. VARA supervises virtual asset activity in the Emirate of Dubai outside the DIFC. ADGM operates its own framework through the FSRA, and the SCA has a role at federal level. The right answer follows from the business model, the jurisdiction of the operating entity and where clients are solicited — which is why EGRC starts with an activity mapping rather than a licence choice.
What does the Travel Rule mean in practice?
For qualifying virtual asset transfers, originator and beneficiary information must travel with the transaction. Practically, this means being able to send the required data, receive and validate it on inbound transfers, handle counterparties who cannot support the standard, and apply a documented policy to transfers involving unhosted wallets. It is as much a data and vendor question as a compliance one.
Is blockchain analytics a substitute for customer due diligence?
No. On-chain analytics tells you about wallet behaviour and exposure to illicit clusters; customer due diligence tells you who the customer is and why they are transacting. They answer different questions. A defensible framework uses analytics to inform risk ratings and monitoring, while keeping identification, verification and source-of-funds work in the CDD process.
How is proliferation financing relevant to a virtual asset business?
Counter-proliferation financing obligations sit alongside AML and CFT in the UAE framework. For virtual asset businesses the practical exposure is exposure to sanctioned jurisdictions and designated parties through pseudonymous transfers, which is why sanctions screening, wallet screening and escalation procedures need to be designed together rather than as separate controls.
We are pre-launch. When should compliance work start?
Before the application, not after. Authorisation assessments look for controls that exist and operate, so the risk assessment, policies, monitoring approach, custody model and governance need to be built into the launch plan. Retro-fitting a control environment onto a live platform is consistently slower and more expensive than designing it in.
START WITH CLARITY

Discuss your virtual asset requirements.

Speak with EGRC about VARA licensing, VASP compliance, Travel Rule and on-chain monitoring.

Discuss Virtual Assets