ChainCatcher, citing Bitcoin.com, reported that Dubai’s Virtual Assets Regulatory Authority (VARA) has recently issued updated anti-money laundering (AML) regulatory guidance. The guidance applies to cryptocurrency companies operating in Dubai and requires them to incorporate FATF high-risk and blacklisted country data into their risk scoring models in real time.
Real-time list data replaces static compliance tracking
According to the report, the new requirements are intended to replace the previous static compliance tracking mechanism. Under the updated framework, companies must connect FATF high-risk and blacklist data directly to their risk scoring process, rather than relying only on a fixed or periodically reviewed compliance record. The guidance places ongoing data inclusion at the center of how firms identify and score risk.
The rules also require companies to update their risk assessments at least once every three months. If a company’s operating structure or product line undergoes a significant change, the risk assessment must be updated immediately. This means the guidance combines a regular review schedule with an event-driven update requirement tied to major changes in operations or products.
VARA further requires proliferation financing risk and targeted financial sanctions risk to be assessed separately. These areas cannot be broadly merged into general AML compliance treatment. As a result, firms operating in Dubai must distinguish these risk categories in their compliance work, risk scoring and internal responsibility arrangements, rather than grouping them under a single AML heading.
AI-assisted operations and anonymity-enhanced exchanges must be recorded
The updated guidance also states that companies must formally record the risks arising from AI-assisted operations and anonymity-enhanced exchanges. By placing these items within formal compliance records, VARA is requiring firms to document how these operations and transaction environments affect their risk management process.
VARA said compliance officers, senior management and board members must take full responsibility for the company’s residual risk rating. The regulator described its direction as moving from after-the-fact punishment toward proactive and systematic risk control. For crypto companies operating in Dubai, the updated AML guidance connects real-time data use, quarterly updates, immediate updates after major changes, separate treatment of specific risk categories and management accountability into a more detailed compliance framework.

