The four-regulator map, and why the boundary is geographic before it is functional
The defining feature of UAE virtual-asset regulation is not the content of any one rulebook. It is that four regulators hold overlapping remits, and the line between them is territorial before it is functional.
VARA, the Virtual Assets Regulatory Authority, was established by Dubai law in 2022. Its jurisdiction is the Emirate of Dubai including the commercial free zones — DMCC, JAFZA, DWTC and the rest — but expressly excluding the Dubai International Financial Centre. That carve-out matters more than any other fact on this page: a firm in DMCC answers to VARA, a firm across the road in the DIFC does not.
The DFSA regulates financial services in the DIFC and built its crypto-token framework inside the existing rulebook rather than alongside it. Its defining mechanic is recognition: a token must be admitted to the DFSA's recognised list before an authorised firm may deal in it. The FSRA performs the equivalent function in ADGM, where a virtual-asset framework has existed since 2018 — the earliest in the region — and likewise operates an accepted-asset list, treating virtual-asset business as a regulated activity under its financial services legislation.
The SCA, the federal Securities and Commodities Authority, holds the national remit for virtual assets outside Dubai's VARA perimeter and outside the two financial free zones. Its regime and VARA's are coordinated rather than merged: a Dubai-licensed firm serving clients elsewhere in the UAE generally needs federal recognition as well as its local licence.
Two rules follow. Ask where the customer is, not only where the entity is — soliciting a Dubai resident is a Dubai act whatever the servers say. And expect no read-across between rulebooks.
| Regulator | Territory | What it regulates | Distinctive mechanic | Courts on dispute |
|---|---|---|---|---|
| VARA | Emirate of Dubai including commercial free zones, excluding the DIFC | Virtual-asset service activity across seven licensable categories, plus token issuance and the marketing of virtual assets | Activity-based licensing with cross-cutting company, compliance, technology and market-conduct rulebooks; promotion regulated as a distinct act | Dubai onshore courts, in Arabic |
| DFSA | Dubai International Financial Centre only | Crypto-token financial services — dealing, arranging, advising, managing and custody — within the existing DFSA regime | Token recognition: a crypto token must be admitted to the DFSA's recognised list before a firm may deal in it | DIFC Courts, common law, in English |
| FSRA | Abu Dhabi Global Market only | Virtual-asset activity as a regulated activity under ADGM financial services legislation, since 2018 | Accepted virtual assets assessed on liquidity, security and traceability; separate DLT foundations vehicle for token projects | ADGM Courts, English common law, in English |
| SCA | Federal — the UAE outside VARA's Dubai perimeter and outside the DIFC and ADGM | Virtual assets and virtual-asset service providers at federal level, alongside its securities remit | Coordinated recognition of VARA licensees for reach beyond Dubai, rather than a duplicate full authorisation | Onshore courts of the relevant emirate, in Arabic |
| CBUAE | Federal, cutting across all of the above | Payment tokens referenced to fiat currency — issuance, conversion and custody, and their use in payments | Dirham-referenced tokens issuable only under Central Bank licence; foreign-currency tokens registrable and restricted in domestic payment use | Onshore courts; overlaps with whichever VASP regulator also applies |
VARA licensing: what the seven categories actually authorise
VARA licenses by activity, not by business model. Seven categories — advisory, broker-dealer, custody, exchange, lending and borrowing, virtual-asset management and investment, and transfer and settlement — and a firm needs each one it performs. Issuance sits under a separate regime rather than being a category of service provision.
The commercial consequence is that most real businesses need more than one licence. An exchange holding client assets needs exchange and custody. A brokerage that routes and settles orders needs broker-dealer and, depending on structure, transfer and settlement. Firms routinely budget for one category and find during the application that their product description implies three — a discovery that arrives as cost, timetable and capital at once.
Alongside the activity rulebooks, VARA applies rules binding every licensee regardless of category: company and governance requirements, compliance and risk management, technology and information security, and market conduct. The technology rulebook is the most consistently underestimated. It is not a policy exercise — it asks for demonstrable controls over key management, wallet architecture, resilience and incident response, examined against what the firm operates rather than what the manual describes.
The application runs in stages — initial approval, then a build-out period during which the operational, governance and technology environment is stood up and inspected, then an operational licence permitting the firm to serve clients. Firms are routinely authorised to exist months before they are authorised to trade. Treating initial approval as a licence, and telling investors so, is a mistake with consequences beyond the regulatory file.
Fit-and-proper assessment of controllers and senior management is substantive, and beneficial ownership must be traceable — a chain terminating in an opaque offshore vehicle stalls. Where a group has legacy entities that once served customers without authorisation anywhere, that history is better disclosed in the application than discovered in it.
Marketing and promotion: the most active enforcement front
VARA treats the marketing, advertising and promotion of virtual assets in Dubai as a regulated activity in its own right, separate from the underlying service. This is the most commonly missed obligation and it produces the most enforcement contact. The logic: if promotion were unregulated, an offshore exchange could reach every consumer in Dubai without touching the licensing regime. Advertising directed at Dubai must carry prescribed risk disclosure and must not overstate returns or understate risk, and depending on promoter and content may require prior engagement with the regulator. An unlicensed firm promoting a service it cannot lawfully provide compounds two breaches rather than one.
Three categories are caught more often than they expect:
- Offshore exchanges and token issuers running paid media. Billboards, airport advertising, sponsored search targeted at UAE geographies and conference sponsorship all promote into the territory. Geo-targeting settings are evidence, and retrievable.
- Influencer and affiliate programmes. A firm is not insulated because a third party posted the content. Arrangements paying for UAE reach are the firm's marketing, and no written control framework over affiliates reads as indifference rather than delegation.
- Groups with a licensed UAE entity and an unlicensed offshore one. Leading a Dubai consumer to the offshore venue under the licensed entity's branding is the pattern regulators find most objectionable: it borrows credibility from an authorisation that does not cover the service delivered.
For a firm that genuinely does not want UAE customers, the defensive position is not a geo-IP block. It is a documented exclusion framework: targeting exclusions on every media platform, contractual prohibitions on affiliates, onboarding controls rejecting UAE residency and documentation, monitoring for circumvention, and evidence it is all reviewed. Firms that can produce that file are in a different conversation from firms that cannot.
ADGM and the DIFC: mature frameworks, different philosophies
ADGM has the longest-running virtual-asset framework in the region and the most institutional character. The FSRA integrated virtual assets into its existing financial services regime rather than building a parallel one, so an applicant is assessed against the same prudential, governance and conduct architecture applied to any regulated firm, with overlays for custody, technology and market surveillance. Its accepted-asset criteria weight liquidity, security, traceability and exchange connectivity. ADGM has also legislated for distributed-ledger foundations, giving token projects a governance vehicle with legal personality — a structure with no direct onshore equivalent.
The DIFC arrived later and built its crypto-token regime on the same recognition principle, licensing firms to deal, arrange, advise, manage or provide custody in respect of recognised tokens. It has separately legislated on digital assets as a matter of property law — how a digital asset is characterised as property, how title passes, how it can be taken as security. For custodians, lenders and insolvency practitioners that is arguably the more consequential contribution: whether a token held by a failed custodian belongs to the client or forms part of the estate turns on exactly that characterisation.
Choosing between them is not a matter of which is easier. Both are demanding and both expect substance: real people, real premises, real systems. The questions that decide it are which asset lists the business needs, which regime's custody and client-money rules fit the operating model, and whether the banks and counterparties the firm depends on are comfortable with the jurisdiction.
The SCA, the Central Bank, and where stablecoins sit
Two federal authorities complicate any map drawn only from the three local regimes.
The SCA holds the federal virtual-asset remit across the UAE outside Dubai's VARA perimeter and outside the DIFC and ADGM. Its practical significance for a Dubai-licensed firm is reach: serving clients in Abu Dhabi, Sharjah or the northern emirates engages the federal regime. The two authorities operate a coordinated arrangement so a VARA licensee can obtain federal recognition rather than a second full authorisation, but recognition is a step to be taken, not an automatic consequence. Firms that assume national coverage from a Dubai licence are describing a footprint they do not have.
The Central Bank occupies a different axis. Its payment token framework, introduced in 2024, regulates tokens referenced to fiat currency — issuance, conversion and custody — irrespective of which other regulator licenses the firm handling them. It distinguishes sharply between dirham-referenced tokens, issuable only by entities licensed by the Central Bank for that purpose, and foreign-currency-referenced tokens, a registrable category subject to restrictions on domestic use, particularly for payments. Reserve composition, redemption at par and segregation of backing assets are the substance of the regime.
The overlap is regularly missed. A Dubai custodian holding a fiat-referenced stablecoin may sit within VARA's custody perimeter and the Central Bank's at once, and a payments business settling merchant transactions in a dollar-referenced token is doing something the Central Bank considers its business whatever the VASP licence says. Map the overlap before the product is built.
Dirham banking access, meanwhile, remains the real bottleneck for many licensed VASPs. A licence is not a banking relationship, and the two should be pursued in parallel.
AML, sanctions and the travel rule
Every UAE virtual-asset regime sits on top of the federal AML and counter-terrorist-financing framework, which treats virtual-asset service providers as designated entities. That framework was tightened materially around the UAE's placement on and removal from the FATF increased-monitoring list in early 2024, and supervisory expectations have not relaxed since exit.
The obligations are familiar in shape to any regulated financial business: customer due diligence, beneficial ownership identification, enhanced diligence for higher-risk relationships, ongoing monitoring, sanctions screening, suspicious transaction reporting and record retention. What differs is execution. Blockchain analytics is not optional — a VASP is expected to screen counterparty addresses for exposure to sanctioned entities, darknet markets, mixers and known theft proceeds, and to hold a documented policy on what exposure level triggers what response.
The travel rule is where technical and legal obligations meet most awkwardly. Originator and beneficiary information must accompany qualifying transfers above the applicable threshold — AED 3,500 in the UAE regime — requiring the sender to identify the receiving institution and transmit data in a format it can consume. Three problems recur: transfers to self-hosted wallets have no institution on the other side; counterparty VASPs on incompatible protocols cannot receive the data; and counterparties in jurisdictions that have not implemented the rule cannot reciprocate. None is solved by procurement. Each requires a documented, risk-based position the regulator can test.
Sanctions exposure deserves separate treatment. A firm can be fully compliant with its UAE obligations and still face secondary exposure under the regimes of jurisdictions whose currency or banking infrastructure it depends on. Screening built only against domestic lists is inadequate for a business with dollar exposure, and boards should understand that gap explicitly.
Disputes: tracing, freezing and the limits of on-chain evidence
Virtual-asset disputes divide into three practical types calling for different tools.
Misappropriation and fraud. Assets are taken by an intruder, an insider or a counterparty who never intended to perform, and recovery depends almost entirely on speed. Chain analysis will usually trace the funds within hours and identify where the trail reaches a regulated exchange. From there the question is legal, not technical: relief compelling that exchange to freeze the account and disclose the holder's identity, in the jurisdiction where it sits. Public ledgers are a real evidential advantage over conventional fraud, but they identify addresses, not people. The bridge from address to person runs through an intermediary, and that is where the litigation is.
Custodial and platform failure. A platform freezes withdrawals or becomes insolvent. The governing question is whether the client has a proprietary claim to identifiable assets or an unsecured contractual claim. That turns on the custody documentation, whether assets were genuinely segregated, and how the asset is characterised in the relevant jurisdiction — which is why client-asset rules are not compliance formalities. They decide who is paid in a failure.
Commercial disputes. Token issuance and investment agreements, listing and market-making arrangements, mining and hosting contracts, and the growing category of disputes about what a founder actually promised a token community. Ordinary contract disputes over unusual subject matter, won on documents in the conventional way.
Forum selection belongs at drafting stage, not at breach. The DIFC and ADGM courts offer English-language common-law procedure and judges accustomed to novel property questions. The onshore courts offer attachment mechanisms with real force where the counterparty holds UAE assets. Arbitration offers confidentiality and cross-border enforcement, and is usually better where the counterparty and its assets sit outside the UAE. The right answer depends on where recovery will actually be attempted.
Where this goes wrong
The failure modes repeat with enough consistency to name.
- Treating one licence as national. A VARA licence does not authorise activity in the DIFC, in ADGM, or in the other emirates without the corresponding federal step. Usually discovered when a client, a bank or a regulator asks a direct question.
- Marketing before licensing. Paid media, influencer campaigns or conference activity aimed at Dubai while the application is pending, or without one. Promotion is regulated independently of the underlying service, and doing it unlicensed converts a licensing conversation into an enforcement one.
- A technology environment that does not match the manual. Key management, wallet architecture and incident response are inspected as operated, not as documented. Policies drafted by counsel and never implemented by engineering fail at first examination.
- Stablecoin activity mapped only against the VASP regime. Fiat-referenced tokens engage the Central Bank's framework in parallel, and a product built without that analysis may need redesigning rather than re-papering.
- Travel-rule compliance treated as a vendor purchase, and sanctions screening limited to domestic lists. Buying a protocol does not answer self-hosted wallets or non-participating counterparties, and a domestic-list-only screen is inadequate for a business dependent on dollar clearing.
- Client assets not genuinely segregated. Commingling survives normal operations and destroys client recovery in a failure — and is the finding most likely to make a regulatory matter personal for management.
- Answering the first information request without a strategy. Scope, privilege, whether to run a parallel internal investigation, what the board is told and when, and whether any external disclosure obligation is triggered.
Every item is cheaper to prevent than to remediate — which is the argument for taking advice at structuring stage rather than once a regulator has written.
Frequently asked questions
Which UAE regulator do we need — VARA, the DFSA, the FSRA or the SCA?
The first question is geographic, not functional. VARA licenses virtual-asset activity in the Emirate of Dubai including its commercial free zones but excluding the DIFC. The DFSA licenses crypto-token activity inside the DIFC. The FSRA licenses virtual-asset activity inside ADGM. The SCA holds the federal remit for the rest of the UAE. The second question is where your customers are, because soliciting a resident of a jurisdiction is an act in that jurisdiction regardless of where your entity or servers sit. Most groups end up with a primary licence and a considered position on the other three perimeters rather than a single answer.
Does a VARA licence let us operate across the UAE?
No. A VARA licence authorises activity in Dubai. It does not extend into the DIFC, into ADGM, or into the other emirates. VARA and the SCA operate a coordinated arrangement under which a VARA licensee can obtain federal recognition to reach clients elsewhere in the UAE, but that recognition is a step to be taken, not an automatic consequence of the Dubai licence. Describing a Dubai licence as national — to clients, investors or banks — is a misstatement with consequences beyond the regulatory file.
We have no UAE entity. Can we still have a VARA problem?
Yes, and marketing is the usual route. VARA regulates the promotion of virtual assets into Dubai as a distinct regulated act. Paid media targeted at UAE geographies, outdoor advertising, sponsored search, influencer and affiliate arrangements paid for UAE reach, and conference sponsorship all engage that perimeter. Targeting settings and affiliate contracts are retrievable evidence. A firm that genuinely does not want UAE customers needs a documented exclusion framework — platform targeting exclusions, affiliate prohibitions, onboarding rejection of UAE residency and documentation, and monitoring — not a geo-IP block on its own.
How many VARA licences does a typical exchange business need?
More than one, almost always. VARA licenses by activity across seven categories: advisory, broker-dealer, custody, exchange, lending and borrowing, virtual-asset management and investment, and transfer and settlement. An exchange that holds client assets needs exchange and custody. A brokerage that routes and settles orders may need broker-dealer plus transfer and settlement. Firms that budget for a single category and describe a multi-activity product in the application face a revised scope, capital requirement and timetable simultaneously — which is why activity mapping belongs at the structuring stage.
How does the Central Bank's payment token regime interact with a VASP licence?
They operate on different axes and can both apply. The Central Bank's framework, introduced in 2024, governs tokens referenced to fiat currency — their issuance, conversion, custody and use in payments — irrespective of which regulator licenses the firm handling them. Dirham-referenced tokens may only be issued under Central Bank licence. Foreign-currency-referenced tokens fall into a registrable category with restrictions on domestic payment use. A Dubai custodian holding a fiat-referenced stablecoin can therefore sit inside VARA's custody perimeter and the Central Bank's payment-token perimeter at once. That overlap should be mapped before the product is built, because it sometimes changes the product.
What does the travel rule require in the UAE, and what breaks in practice?
Originator and beneficiary information must accompany qualifying virtual-asset transfers above the applicable threshold, which in the UAE regime is AED 3,500. Adopting a compliant protocol is the easy part. Three situations break it. Transfers to self-hosted wallets have no receiving institution, so the firm needs a documented substitute verification approach. Counterparty VASPs on incompatible protocols cannot receive the data. And counterparties in jurisdictions that have not implemented the rule cannot reciprocate. Each requires a written, risk-based position that a supervisor can test — a vendor contract on its own does not answer any of them.
What should we do in the first week after a regulatory information request?
Decide five things deliberately rather than by default. The scope of what is being asked and what will be produced. Whether privilege applies to any part of it and how documents are marked from that point forward. Whether to run a parallel internal investigation, and under whose instruction. What the board is told, when, and in what form. And whether any disclosure obligation is triggered — to investors, to a listed parent, or to another regulator in another jurisdiction. Those decisions shape the entire matter, and they are made before anyone has read the substantive file.
Stolen tokens have moved off our platform. Is recovery realistic?
Sometimes, and speed decides it. Chain analysis will usually trace the movement within hours and identify the point where funds reach a regulated exchange. Everything after that is legal work in the jurisdiction where that exchange sits: interim relief to freeze the account and compel disclosure of the account-holder's identity. The public ledger is a real evidential advantage over conventional fraud because the record is complete and available without disclosure — but it identifies addresses, not people. The bridge from address to person runs through an intermediary, and the window before funds are layered through mixers or non-cooperative venues is short.