Dubai’s Virtual Assets Regulatory Authority, or VARA, has tightened its anti-money laundering expectations for licensed crypto firms. Under the revised framework, companies are no longer allowed to rely on static compliance checklists. They must conduct ongoing reviews of customer profiles, transaction types, products and services, distribution channels, and geographic exposure. Jurisdictions identified by the Financial Action Task Force, or FATF, as high risk or under enhanced monitoring must also be folded into those assessments without delay.
Risk reviews must now track live business activity
The updated guidance turns risk assessment into a continuous process rather than a periodic licensing exercise. Firms must review their risk assessments at least once every three months. If there are changes in products, services, business models, partnerships, or corporate structure, the reassessment has to happen sooner. VARA also says companies can no longer group money laundering, terrorist financing, proliferation financing, and targeted financial sanctions into a single combined risk category.
That shifts compliance from a documentation exercise to an operating requirement tied to current activity. Sanctions screening, customer due diligence, risk-based monitoring, and compliance with the Travel Rule are all treated as enforceable parts of the existing regime.
Senior executives are expected to know current residual risk
VARA is also placing more responsibility on top management. Senior executives, board members, and compliance officers are expected to hold direct and current knowledge of their organization’s residual risk levels and the measures used to manage them. The guidance points to several areas that need closer attention, including risks linked to artificial intelligence and machine learning, anonymity-enhancing transactions, and mass funding activity.
Data cited from NeosLegal shows that regulators across the United Arab Emirates, including VARA, ADGM, DFSA, the UAE Central Bank, and CMA, have licensed or authorized more than 100 virtual asset service providers so far. The market is established; the oversight is getting tighter.
Dubai remains open to crypto, but compliance costs are rising
The new guidance is broadly aligned with FATF standards, which may make some parts familiar to firms already operating under stricter regimes in the European Union, Singapore, Switzerland, or the United States. Still, Dubai is pushing harder in several areas. The guidance highlights expectations for up-to-date sanctions screening solutions, automated monitoring tools, wallet address analysis, distributed ledger reviews, and more granular controls around geographic risk.
Firms that depend on basic compliance manuals may struggle under this setup. Holding a license is no longer enough on its own. Companies are now expected to show, on an ongoing basis, that their risk management systems match the size, complexity, and exposure of their actual operations.
Wider UAE enforcement is also intensifying
The VARA update comes as financial crime enforcement is tightening across the UAE. Since the start of 2025, the UAE Central Bank has imposed penalties totaling more than 370 million dirhams, or over $100 million, on banks, exchange houses, insurance companies, and other financial institutions for failures tied to money laundering and terrorist financing controls.
Regulators in Dubai are also reported to be scrutinizing privacy-focused assets and related transactions more closely because of elevated money laundering risk. The market remains open to crypto businesses, but the standard has changed: firms must continuously prove that their controls are scaled to the real risks in their business.

