Skip to content

Evidence request lists

UAE Virtual Asset Regulatory Authority (VARA) Regulations

Evidence request list. 30 controls, 30 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

AML/CFT

UAEVARA-3
AML/CFT and FATF Travel Rule

Per VARA + UAE Central Bank: AML/CFT + Travel Rule + KYC + EDD + sanctions screening.

Artefacts an auditor will ask for
  • VARA evidence for UAEVARA-3
Where this commonly fails
  • licensing + Travel Rule partial

Client Assets and Custody

VARA-04
Client Asset Segregation

Segregate client digital assets and fiat from firm assets and maintain independent reconciliations, with restrictions on use, lending or rehypothecation of client digital assets.

Artefacts an auditor will ask for
  • Segregation policy and procedures
  • Wallet inventory distinguishing client and firm wallets
  • Daily reconciliation reports between ledger and on chain or custodian balances
  • Independent review of reconciliations
  • Restrictions on client asset use documented in client agreements
Where this commonly fails
  • Single omnibus wallet without sub ledger discipline
  • Reconciliation breaks not aged or escalated
  • Use of client digital assets in firm activities not blocked
  • No independent assurance over segregation
VARA-05
Custody Arrangements

Operate custody of client digital assets with multi signature or equivalent controls, key management, business continuity and insurance arrangements proportionate to assets held.

Artefacts an auditor will ask for
  • Key generation and storage standards
  • Multi party approval workflows for transfers
  • Hot wallet and cold storage threshold policy
  • Business continuity and disaster recovery tests
  • Insurance policies covering custodied digital assets
Where this commonly fails
  • Hot wallet limits not enforced by automation
  • Single point of failure in key custody
  • No regular recovery test for cold storage
  • Insurance coverage materially below holdings

Conduct

UAEVARA-2
Market Conduct, Customer Protection, Marketing Rules

Per VARA Rulebooks: market conduct + customer protection + marketing restrictions + suitability + risk disclosures + segregation of customer assets.

Artefacts an auditor will ask for
  • VARA evidence for UAEVARA-2
Where this commonly fails
  • licensing + Travel Rule partial

Cybersecurity

UAEVARA-4
Technology Risk and Cybersecurity

Per VARA TMS: technology risk + cybersecurity + system resilience + business continuity.

Artefacts an auditor will ask for
  • VARA evidence for UAEVARA-4
Where this commonly fails
  • licensing + Travel Rule partial

Financial Crime Compliance

VARA-06
AML, CFT and Sanctions

Operate an AML, counter terrorist financing and sanctions programme aligned with UAE federal law and VARA guidance covering risk assessment, customer due diligence, screening and reporting.

Artefacts an auditor will ask for
  • Enterprise financial crime risk assessment
  • Customer due diligence and enhanced due diligence procedures
  • Sanctions and PEP screening logs
  • Suspicious activity report register and submissions
  • Independent AML audit reports
Where this commonly fails
  • Risk assessment generic and not specific to virtual asset products
  • Screening lists outdated
  • SAR thresholds set too high causing under reporting
  • Senior management not engaged on financial crime risks
VARA-07
Travel Rule Compliance

Implement travel rule controls to collect, transmit and verify originator and beneficiary information for transfers of digital assets above defined thresholds.

Artefacts an auditor will ask for
  • Travel rule policy and procedures
  • Travel rule message logs with success and failure rates
  • Counterparty virtual asset service provider due diligence files
  • Sunrise period and self hosted wallet handling procedure
  • Audit trail of transmitted and received data
Where this commonly fails
  • Transfers processed without counterparty verification
  • Self hosted wallet flows not analysed
  • No fallback when counterparty not reachable
  • Travel rule data retained beyond required period

Licensing

UAEVARA-1
Activity Licensing (Advisory, Exchange, Custody, Broker-Dealer, etc.)

Per UAE VARA (Virtual Asset Regulatory Authority): activity-based licensing. Requirements include (a) Advisory Services + (b) Exchange Services + (c) Custody Services + (d) Broker-Dealer + (e) Lending and Borrowing + (f) Payments and Remittance Services + (g) Mining + Issuance + (h) cooperate with VARA.

Artefacts an auditor will ask for
  • VARA evidence for UAEVARA-1
Where this commonly fails
  • licensing + Travel Rule partial

Licensing and Prudential Requirements

VARA-01
Licensing and Permitted Activities

Obtain a VARA licence appropriate to the categories of permitted activities the virtual asset service provider intends to perform in or from Dubai, with conditions and restrictions documented and adhered to.

Artefacts an auditor will ask for
  • VARA licence certificate with permitted activity categories
  • Mapping of business lines to licence categories
  • Records of variation or extension requests
  • Internal sign off when launching new products or markets
  • Periodic confirmation that activities remain within licensed scope
Where this commonly fails
  • Activities offered outside the permitted categories
  • Marketing presents future activities as currently licensed
  • No internal owner for ongoing licence condition monitoring
  • Variation requests delayed leading to gap operation
VARA-02
Fit and Proper Senior Management

Ensure that senior management, controllers and approved individuals satisfy fit and proper requirements with documented assessments and ongoing monitoring.

Artefacts an auditor will ask for
  • Fit and proper assessment files per approved individual
  • Background and qualification verification records
  • Annual fit and proper attestations
  • Trigger event monitoring procedure
  • Records of notifications to VARA on changes
Where this commonly fails
  • Initial check only, no ongoing reassessment
  • Approved individuals retained after disqualifying events
  • No central register of approved roles
  • Background checks missing for non UAE residents
VARA-03
Capital and Prudential Requirements

Maintain minimum paid up capital and additional prudential buffers required by VARA for the licensed activities, with regular monitoring and reporting.

Artefacts an auditor will ask for
  • Audited capital adequacy calculations
  • Bank statements supporting required capital
  • Internal monitoring dashboard for capital headroom
  • Regulatory returns submitted to VARA
  • Board approved capital management policy
Where this commonly fails
  • Capital monitoring only at year end
  • Mix of fiat and digital asset holdings without policy
  • Returns reconciled to ledger only after submission
  • No early warning thresholds before breach

Market Conduct and Disclosure

VARA-08
Market Conduct and Surveillance

Operate market surveillance to detect and deter manipulation, wash trading, spoofing and insider activity in markets for digital assets and tokenized instruments.

Artefacts an auditor will ask for
  • Market abuse policy and standards
  • Surveillance alert configurations and tuning records
  • Investigation case files with outcomes
  • Suspicious trade reporting register
  • Annual review of surveillance effectiveness
Where this commonly fails
  • Alert thresholds left at vendor default
  • False positive rate not measured
  • Insider lists not maintained
  • No surveillance over related affiliate flows
VARA-09
Disclosures and Marketing

Provide fair, clear and not misleading disclosures to clients about virtual asset risks, fees and the regulatory status of products, with VARA approval where required for marketing.

Artefacts an auditor will ask for
  • Risk disclosure templates per product
  • Marketing approval workflow with VARA submissions
  • Archive of approved marketing materials
  • Influencer and affiliate disclosure controls
  • Periodic review of website and app disclosures
Where this commonly fails
  • Marketing emphasises returns over risks
  • Influencer arrangements lack written approval and disclosure
  • Disclosures missing on key purchase steps
  • Stale materials still in circulation
VARA-10
Suitability and Onboarding

Conduct suitability and appropriateness assessments for clients accessing complex virtual asset products including tokenized instruments and leveraged offerings.

Artefacts an auditor will ask for
  • Suitability questionnaire and scoring methodology
  • Onboarding workflow with progression gates
  • Sample case files showing assessment outcomes
  • Retail versus professional client classification records
  • Periodic reassessment for active clients
Where this commonly fails
  • Questionnaire optional or skipped
  • Scoring not linked to product access
  • No reassessment after material risk profile changes
  • Professional client status granted without robust evidence
VARA-11
Conflicts of Interest

Identify, document and manage conflicts of interest including proprietary trading, related party transactions and incentive structures, with disclosure where management is not sufficient.

Artefacts an auditor will ask for
  • Conflicts of interest policy
  • Conflicts register with mitigation actions
  • Personal account dealing rules and monitoring
  • Disclosure templates for unavoidable conflicts
  • Annual review of conflicts management
Where this commonly fails
  • Register not maintained or out of date
  • Personal account dealing not monitored
  • Related party transactions not flagged
  • Incentives drive activity that conflicts with client interest

Records and Independent Assurance

VARA-19
Recordkeeping and Audit Trails

Maintain accurate, complete and tamper evident records of transactions, communications, decisions and approvals for the retention period required by VARA.

Artefacts an auditor will ask for
  • Records retention schedule aligned with VARA
  • Audit trail configuration for trading and custody systems
  • Voice and electronic communications archive
  • Integrity controls including immutable logging
  • Periodic retrieval tests
Where this commonly fails
  • Communications recordings incomplete
  • Audit trails editable by privileged users
  • Retrieval untested under regulator scenarios
  • Different retention rules across systems
VARA-20
Independent Audit and Assurance

Obtain independent audits and assurance reports as required by VARA including financial audits, technology audits and proof of reserves arrangements where applicable.

Artefacts an auditor will ask for
  • Annual financial audit reports
  • Technology and custody assurance reports
  • Proof of reserves methodology and reports
  • Management response and remediation plans
  • Disclosures published to clients where applicable
Where this commonly fails
  • Proof of reserves methodology not validated by independent party
  • Findings open across multiple audit cycles
  • Assurance scope limited to financial statements only
  • No client facing disclosure of assurance outcomes

Reporting

UAEVARA-5
Reporting, Governance, Enforcement

Per VARA: reporting + governance + ESG + enforcement including fines + suspension + revocation.

Artefacts an auditor will ask for
  • VARA evidence for UAEVARA-5
Where this commonly fails
  • licensing + Travel Rule partial

Risk Management and Regulatory Reporting

VARA-15
Risk Management Framework

Operate an enterprise risk management framework covering market, credit, liquidity, operational, conduct, technology and financial crime risks with board oversight.

Artefacts an auditor will ask for
  • Risk management policy and framework
  • Risk appetite statement approved by board
  • Risk register with owner and treatment plans
  • Quarterly risk reports to executive and board
  • Stress testing and scenario analysis
Where this commonly fails
  • Risk appetite not aligned with permitted activities
  • Risks identified but not actively monitored
  • Stress testing absent or shallow
  • Limited integration between risk and compliance
VARA-16
Regulatory Reporting

Submit accurate and timely regulatory reports to VARA including periodic returns, material change notifications and ad hoc disclosures.

Artefacts an auditor will ask for
  • Calendar of regulatory submissions
  • Reconciliation files supporting each return
  • Material change and incident notifications archive
  • Internal sign off for each submission
  • Quality assurance review records
Where this commonly fails
  • Submissions reconciled to ledgers only after filing
  • Material changes notified retrospectively
  • No central register of submissions
  • Sign off below appropriate seniority
VARA-17
Complaints and Dispute Resolution

Operate a complaints handling and dispute resolution process accessible to clients with timely investigation, response and reporting of complaints data to senior management.

Artefacts an auditor will ask for
  • Complaints policy and procedure
  • Complaints register with classification and outcomes
  • Sample case files
  • Periodic complaints analysis and root cause reports
  • Notifications to VARA where required
Where this commonly fails
  • Complaints not centrally captured
  • Root cause analysis missing
  • Slow response times against published SLA
  • Recurring themes not driving change
VARA-18
Token and Product Approval

Apply a product approval process for new digital assets and tokenized instruments listed or supported including risk, legal and compliance assessments.

Artefacts an auditor will ask for
  • Token and product assessment template
  • Approval committee minutes
  • Delisting and end of support procedures
  • Ongoing monitoring of approved assets
  • Records of VARA engagement when required
Where this commonly fails
  • Assets listed without formal approval
  • No ongoing monitoring of listed assets
  • Delisting decisions delayed
  • Approval criteria not documented

Technology and Operational Resilience

VARA-12
Technology and Cyber Risk

Operate technology and cyber risk management covering platform security, key management, smart contract review, monitoring, vulnerability management and incident response.

Artefacts an auditor will ask for
  • Information security policies aligned with recognised frameworks
  • Smart contract audit reports and remediation records
  • Penetration test and vulnerability scan reports
  • Cyber incident response plan and exercises
  • Logging and monitoring coverage analysis
Where this commonly fails
  • Smart contracts deployed without independent audit
  • Vulnerability remediation SLAs missed
  • Monitoring gaps on critical custody systems
  • Incident response not tested for digital asset specific scenarios
VARA-13
Business Continuity and Resilience

Maintain business continuity and disaster recovery capabilities for critical services with tested recovery time objectives and client communication procedures.

Artefacts an auditor will ask for
  • Business continuity and disaster recovery plans
  • Recovery time and recovery point objectives per service
  • BCP and DR test reports with results
  • Client communication templates for outages
  • Crisis management exercise outputs
Where this commonly fails
  • Plans not tested for custody specific scenarios
  • RTO and RPO not measured during tests
  • Single region cloud dependency
  • Client communication ad hoc during outages
VARA-14
Outsourcing and Third Party Risk

Operate an outsourcing and third party risk programme covering custody providers, market makers, technology vendors and other critical service providers.

Artefacts an auditor will ask for
  • Inventory of outsourced functions with criticality ratings
  • Outsourcing policy aligned with VARA expectations
  • Contracts with audit, exit and continuity clauses
  • Annual oversight reviews
  • VARA notifications for material outsourcing
Where this commonly fails
  • Critical outsourcing not notified to VARA
  • No exit plan or substitutability analysis
  • Sub outsourcing not visible
  • Oversight limited to onboarding only

VARA Compliance and Risk Management Rulebook

CRM-1
AML/CFT Compliance

VASPs must implement robust anti-money laundering and counter-terrorism financing controls and client risk assessments.

Artefacts an auditor will ask for
  • AML programme document and risk based approach
  • Customer due diligence and EDD records
  • Sanctions screening tool configuration and audit
  • SAR or STR filing records
Where this commonly fails
  • Risk based approach not evidenced
  • Screening lists not refreshed daily
  • Travel rule data omitted from outbound transfers
  • Beneficial ownership data stale
CRM-2
Sanctions Compliance

VASPs must screen transactions and counterparties against applicable sanctions lists and enforce prohibitions.

Artefacts an auditor will ask for
  • AML programme document and risk based approach
  • Customer due diligence and EDD records
  • Sanctions screening tool configuration and audit
  • SAR or STR filing records
Where this commonly fails
  • Risk based approach not evidenced
  • Screening lists not refreshed daily
  • Travel rule data omitted from outbound transfers
  • Beneficial ownership data stale
CRM-3
Risk Management Framework

VASPs must establish and maintain a comprehensive enterprise risk management framework with regular assessments.

Artefacts an auditor will ask for
  • Documented procedure addressing risk management framework
  • Evidence of executive or risk owner approval
  • Operational records demonstrating execution
  • Independent assurance or review report
Where this commonly fails
  • Procedure exists but execution inconsistent
  • Owner accountability not codified
  • Review cadence missed or undocumented
  • Coverage gaps for in scope entities or systems
CRM-4
Business Risk Assessment

VASPs must conduct periodic business risk assessments addressing operational, financial, and reputational risks.

Artefacts an auditor will ask for
  • Risk assessment report covering business risk assessment scope
  • Risk register entries with owner, likelihood, and impact
  • Treatment plan linked to identified risks
  • Evidence of management review and acceptance
Where this commonly fails
  • Risk register not refreshed after material change
  • Treatment owners undefined or unaccountable
  • Residual risk acceptance lacks executive sign-off
  • Inherent versus residual scoring not clearly distinguished
CRM-5
FATF Travel Rule

VASPs licensed for transfers must collect and share originator and beneficiary details for transactions above thresholds.

Artefacts an auditor will ask for
  • AML programme document and risk based approach
  • Customer due diligence and EDD records
  • Sanctions screening tool configuration and audit
  • SAR or STR filing records
Where this commonly fails
  • Risk based approach not evidenced
  • Screening lists not refreshed daily
  • Travel rule data omitted from outbound transfers
  • Beneficial ownership data stale
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the UAE Virtual Asset Regulatory Authority (VARA) Regulations framework page.