Practice · Financial Services Regulation

Five financial regulators. Separate rulebooks, separate enforcement powers, and one institution usually answering to more than one.

The Central Bank, the Securities and Commodities Authority, the DFSA in the DIFC, the FSRA in ADGM and VARA in Dubai each licence, supervise and enforce on their own terms. Most regulatory difficulty in the UAE begins with a firm treating them as one regime.

The structural point

One licence does not travel across the UAE.

A DFSA permission authorises activity in and from the DIFC. An FSRA permission does the same for ADGM. Neither authorises the same activity onshore, where the Central Bank and the Securities and Commodities Authority set the perimeter, and neither speaks to virtual asset activity in Dubai, which sits with VARA. A group operating across these does not hold one authorisation with variations. It holds several, and answers to several supervisors who form their own views independently.

The question asked too late

Whether the activity is regulated at all, and by whom.

Perimeter is the first question and it is routinely the last one asked. A product built to sit outside regulation in one part of the UAE can be a licensable activity a few kilometres away, and the answer turns on where the activity is carried on as much as on what it is. Getting that wrong is not a documentation problem — it is unauthorised business, and it is expensive to unwind after launch.

5

Regulators, not one

The Central Bank, the Securities and Commodities Authority, the DFSA, the FSRA and VARA. Separate rulebooks, separate perimeters, separate enforcement powers.

Personal

Liability reaches individuals

UAE AML legislation and the free-zone regimes both provide for consequences for named officers — including MLROs and senior management — independently of any action against the institution.

Day 1

Supervision starts before enforcement

Most matters open with a supervisory request rather than a notice. How that first response is framed shapes whether the matter escalates, and it is difficult to reframe later.

Which regulator you answer to — and why it is often more than one

Financial services in the UAE are not supervised by a single authority. The Central Bank of the UAE licenses and supervises banks, exchange houses and payment service providers. The Securities and Commodities Authority regulates federal securities markets. Inside the financial free zones, the DFSA and the FSRA operate their own rulebooks under DIFC and ADGM law respectively. Virtual asset activity in Dubai sits with VARA.

These are separate statutory regimes with separate perimeters. A group with an onshore entity, a DIFC arm and a token offering can be answerable to three of them at once, on three different timetables, with no automatic read-across between an authorisation granted in one and the perimeter of another.

Authorisation and perimeter

Most engagements begin before an application does: establishing which regulated activities a business model actually touches, and therefore which regulator's permission it needs. Perimeter questions are where fintech and virtual asset businesses most often mis-scope, because a product that is unregulated in one jurisdiction of the UAE may be a licensable activity a few kilometres away.

Supervision, investigation and enforcement

Regulatory contact rarely starts with an enforcement notice. It starts with a supervisory request, a thematic review, or a question about a transaction. How a firm answers at that stage materially shapes whether the matter escalates. Our enforcement work covers the full path — supervisory engagement, formal investigation, decision notices, settlement and, where a matter crosses into criminal referral, defence of the individuals as well as the institution.

AML, CFT and sanctions

Anti-money-laundering obligations are the most common source of UAE regulatory exposure, and the one where personal liability for named officers is most real. We advise on programme design and remediation, STR and goAML filing decisions, sanctions screening against both international and local designations, and the defence of MLROs and senior managers when a supervisor questions their conduct.

What we handle

Licensing & authorisation Perimeter analysis Supervisory engagement Enforcement defence AML/CFT programmes Sanctions screening Internal investigations Senior manager liability Virtual asset regulation Market abuse Whistleblowing Regulatory remediation

Guides and analysis

Practitioner notes on licensing, supervision, enforcement and AML across the five regimes.


Frequently asked questions

Which UAE regulator licenses my business?

It depends on the activity and where it is carried on. Banking, payments and exchange activity onshore fall to the Central Bank; federal securities activity to the SCA; activity conducted in or from the DIFC to the DFSA and in or from ADGM to the FSRA; virtual asset activity in Dubai outside the DIFC to VARA. Groups frequently need more than one permission.

Can a DIFC or ADGM licence cover onshore activity?

No. A DFSA or FSRA permission authorises activity in and from that financial free zone. Carrying on regulated activity onshore is a separate perimeter question requiring separate authorisation.

What should we do when a regulator makes a supervisory request?

Treat it as the start of the matter rather than routine correspondence, preserve the relevant records immediately, and take advice before responding substantively. The response frames how the supervisor understands the issue, and it is materially harder to change that framing later.

Can senior managers be personally liable?

Yes. UAE AML legislation and the free-zone regimes both provide for personal consequences for named officers, including MLROs and senior management, independently of any action against the institution.

Do you act for individuals as well as institutions?

Yes — including where an institution and a named officer need separate representation because their positions may diverge.

Related practices

Know your perimeter before a regulator tests it.

Tell us what activity you carry on and where it is carried on. We will tell you which permissions it needs, which authority supervises it, and where your current documentation would not withstand a supervisory request.

Speak with a partner