Which regulator you answer to — and why it is often more than one
Financial services in the UAE are not supervised by a single authority. The Central Bank of the UAE licenses and supervises banks, exchange houses and payment service providers. The Securities and Commodities Authority regulates federal securities markets. Inside the financial free zones, the DFSA and the FSRA operate their own rulebooks under DIFC and ADGM law respectively. Virtual asset activity in Dubai sits with VARA.
These are separate statutory regimes with separate perimeters. A group with an onshore entity, a DIFC arm and a token offering can be answerable to three of them at once, on three different timetables, with no automatic read-across between an authorisation granted in one and the perimeter of another.
Authorisation and perimeter
Most engagements begin before an application does: establishing which regulated activities a business model actually touches, and therefore which regulator's permission it needs. Perimeter questions are where fintech and virtual asset businesses most often mis-scope, because a product that is unregulated in one jurisdiction of the UAE may be a licensable activity a few kilometres away.
Supervision, investigation and enforcement
Regulatory contact rarely starts with an enforcement notice. It starts with a supervisory request, a thematic review, or a question about a transaction. How a firm answers at that stage materially shapes whether the matter escalates. Our enforcement work covers the full path — supervisory engagement, formal investigation, decision notices, settlement and, where a matter crosses into criminal referral, defence of the individuals as well as the institution.
AML, CFT and sanctions
Anti-money-laundering obligations are the most common source of UAE regulatory exposure, and the one where personal liability for named officers is most real. We advise on programme design and remediation, STR and goAML filing decisions, sanctions screening against both international and local designations, and the defence of MLROs and senior managers when a supervisor questions their conduct.
What we handle
Guides and analysis
Practitioner notes on licensing, supervision, enforcement and AML across the five regimes.
Licensing and authorisation
- UAE fintech licensing — VARA, ADGM FSRA and DIFC DFSA compared
- Dubai VARA virtual asset licensing — application essentials
- FSRA virtual asset licensing — application essentials
- The VARA rulebooks — crypto licensing and AML obligations
- VARA and virtual assets — the full framework
Supervision, investigations and enforcement
- Inside DFSA and FSRA enforcement — how cases actually resolve
- Under CBUAE AML investigation — the first 72 hours for banks and PSPs
- Defending a VARA enforcement action
- Market abuse and insider trading — SCA to CMA
- How a financial crime investigation begins
- Dawn raids and digital evidence
- The privilege trap in internal investigations
AML, CFT and sanctions compliance
- The UAE AML law — what changed
- goAML and STR filing — a playbook
- MLRO and senior manager personal liability
- EOCN sanctions screening and the local terrorist list
- OFAC secondary sanctions
- Beneficial ownership compliance
- Trade-based money laundering
- Proliferation financing and CPF obligations
- Life after the FATF grey list
Governance and personal exposure
Frequently asked questions
Which UAE regulator licenses my business?
It depends on the activity and where it is carried on. Banking, payments and exchange activity onshore fall to the Central Bank; federal securities activity to the SCA; activity conducted in or from the DIFC to the DFSA and in or from ADGM to the FSRA; virtual asset activity in Dubai outside the DIFC to VARA. Groups frequently need more than one permission.
Can a DIFC or ADGM licence cover onshore activity?
No. A DFSA or FSRA permission authorises activity in and from that financial free zone. Carrying on regulated activity onshore is a separate perimeter question requiring separate authorisation.
What should we do when a regulator makes a supervisory request?
Treat it as the start of the matter rather than routine correspondence, preserve the relevant records immediately, and take advice before responding substantively. The response frames how the supervisor understands the issue, and it is materially harder to change that framing later.
Can senior managers be personally liable?
Yes. UAE AML legislation and the free-zone regimes both provide for personal consequences for named officers, including MLROs and senior management, independently of any action against the institution.
Do you act for individuals as well as institutions?
Yes — including where an institution and a named officer need separate representation because their positions may diverge.