UAE Virtual Asset Regulatory Authority (VARA) Regulations
Evidence request list. 30 controls, 30 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
AML/CFT
Per VARA + UAE Central Bank: AML/CFT + Travel Rule + KYC + EDD + sanctions screening.
- VARA evidence for UAEVARA-3
- licensing + Travel Rule partial
Client Assets and Custody
Segregate client digital assets and fiat from firm assets and maintain independent reconciliations, with restrictions on use, lending or rehypothecation of client digital assets.
- Segregation policy and procedures
- Wallet inventory distinguishing client and firm wallets
- Daily reconciliation reports between ledger and on chain or custodian balances
- Independent review of reconciliations
- Restrictions on client asset use documented in client agreements
- Single omnibus wallet without sub ledger discipline
- Reconciliation breaks not aged or escalated
- Use of client digital assets in firm activities not blocked
- No independent assurance over segregation
Operate custody of client digital assets with multi signature or equivalent controls, key management, business continuity and insurance arrangements proportionate to assets held.
- Key generation and storage standards
- Multi party approval workflows for transfers
- Hot wallet and cold storage threshold policy
- Business continuity and disaster recovery tests
- Insurance policies covering custodied digital assets
- Hot wallet limits not enforced by automation
- Single point of failure in key custody
- No regular recovery test for cold storage
- Insurance coverage materially below holdings
Conduct
Per VARA Rulebooks: market conduct + customer protection + marketing restrictions + suitability + risk disclosures + segregation of customer assets.
- VARA evidence for UAEVARA-2
- licensing + Travel Rule partial
Cybersecurity
Per VARA TMS: technology risk + cybersecurity + system resilience + business continuity.
- VARA evidence for UAEVARA-4
- licensing + Travel Rule partial
Financial Crime Compliance
Operate an AML, counter terrorist financing and sanctions programme aligned with UAE federal law and VARA guidance covering risk assessment, customer due diligence, screening and reporting.
- Enterprise financial crime risk assessment
- Customer due diligence and enhanced due diligence procedures
- Sanctions and PEP screening logs
- Suspicious activity report register and submissions
- Independent AML audit reports
- Risk assessment generic and not specific to virtual asset products
- Screening lists outdated
- SAR thresholds set too high causing under reporting
- Senior management not engaged on financial crime risks
Implement travel rule controls to collect, transmit and verify originator and beneficiary information for transfers of digital assets above defined thresholds.
- Travel rule policy and procedures
- Travel rule message logs with success and failure rates
- Counterparty virtual asset service provider due diligence files
- Sunrise period and self hosted wallet handling procedure
- Audit trail of transmitted and received data
- Transfers processed without counterparty verification
- Self hosted wallet flows not analysed
- No fallback when counterparty not reachable
- Travel rule data retained beyond required period
Licensing
Per UAE VARA (Virtual Asset Regulatory Authority): activity-based licensing. Requirements include (a) Advisory Services + (b) Exchange Services + (c) Custody Services + (d) Broker-Dealer + (e) Lending and Borrowing + (f) Payments and Remittance Services + (g) Mining + Issuance + (h) cooperate with VARA.
- VARA evidence for UAEVARA-1
- licensing + Travel Rule partial
Licensing and Prudential Requirements
Obtain a VARA licence appropriate to the categories of permitted activities the virtual asset service provider intends to perform in or from Dubai, with conditions and restrictions documented and adhered to.
- VARA licence certificate with permitted activity categories
- Mapping of business lines to licence categories
- Records of variation or extension requests
- Internal sign off when launching new products or markets
- Periodic confirmation that activities remain within licensed scope
- Activities offered outside the permitted categories
- Marketing presents future activities as currently licensed
- No internal owner for ongoing licence condition monitoring
- Variation requests delayed leading to gap operation
Ensure that senior management, controllers and approved individuals satisfy fit and proper requirements with documented assessments and ongoing monitoring.
- Fit and proper assessment files per approved individual
- Background and qualification verification records
- Annual fit and proper attestations
- Trigger event monitoring procedure
- Records of notifications to VARA on changes
- Initial check only, no ongoing reassessment
- Approved individuals retained after disqualifying events
- No central register of approved roles
- Background checks missing for non UAE residents
Maintain minimum paid up capital and additional prudential buffers required by VARA for the licensed activities, with regular monitoring and reporting.
- Audited capital adequacy calculations
- Bank statements supporting required capital
- Internal monitoring dashboard for capital headroom
- Regulatory returns submitted to VARA
- Board approved capital management policy
- Capital monitoring only at year end
- Mix of fiat and digital asset holdings without policy
- Returns reconciled to ledger only after submission
- No early warning thresholds before breach
Market Conduct and Disclosure
Operate market surveillance to detect and deter manipulation, wash trading, spoofing and insider activity in markets for digital assets and tokenized instruments.
- Market abuse policy and standards
- Surveillance alert configurations and tuning records
- Investigation case files with outcomes
- Suspicious trade reporting register
- Annual review of surveillance effectiveness
- Alert thresholds left at vendor default
- False positive rate not measured
- Insider lists not maintained
- No surveillance over related affiliate flows
Provide fair, clear and not misleading disclosures to clients about virtual asset risks, fees and the regulatory status of products, with VARA approval where required for marketing.
- Risk disclosure templates per product
- Marketing approval workflow with VARA submissions
- Archive of approved marketing materials
- Influencer and affiliate disclosure controls
- Periodic review of website and app disclosures
- Marketing emphasises returns over risks
- Influencer arrangements lack written approval and disclosure
- Disclosures missing on key purchase steps
- Stale materials still in circulation
Conduct suitability and appropriateness assessments for clients accessing complex virtual asset products including tokenized instruments and leveraged offerings.
- Suitability questionnaire and scoring methodology
- Onboarding workflow with progression gates
- Sample case files showing assessment outcomes
- Retail versus professional client classification records
- Periodic reassessment for active clients
- Questionnaire optional or skipped
- Scoring not linked to product access
- No reassessment after material risk profile changes
- Professional client status granted without robust evidence
Identify, document and manage conflicts of interest including proprietary trading, related party transactions and incentive structures, with disclosure where management is not sufficient.
- Conflicts of interest policy
- Conflicts register with mitigation actions
- Personal account dealing rules and monitoring
- Disclosure templates for unavoidable conflicts
- Annual review of conflicts management
- Register not maintained or out of date
- Personal account dealing not monitored
- Related party transactions not flagged
- Incentives drive activity that conflicts with client interest
Records and Independent Assurance
Maintain accurate, complete and tamper evident records of transactions, communications, decisions and approvals for the retention period required by VARA.
- Records retention schedule aligned with VARA
- Audit trail configuration for trading and custody systems
- Voice and electronic communications archive
- Integrity controls including immutable logging
- Periodic retrieval tests
- Communications recordings incomplete
- Audit trails editable by privileged users
- Retrieval untested under regulator scenarios
- Different retention rules across systems
Obtain independent audits and assurance reports as required by VARA including financial audits, technology audits and proof of reserves arrangements where applicable.
- Annual financial audit reports
- Technology and custody assurance reports
- Proof of reserves methodology and reports
- Management response and remediation plans
- Disclosures published to clients where applicable
- Proof of reserves methodology not validated by independent party
- Findings open across multiple audit cycles
- Assurance scope limited to financial statements only
- No client facing disclosure of assurance outcomes
Reporting
Per VARA: reporting + governance + ESG + enforcement including fines + suspension + revocation.
- VARA evidence for UAEVARA-5
- licensing + Travel Rule partial
Risk Management and Regulatory Reporting
Operate an enterprise risk management framework covering market, credit, liquidity, operational, conduct, technology and financial crime risks with board oversight.
- Risk management policy and framework
- Risk appetite statement approved by board
- Risk register with owner and treatment plans
- Quarterly risk reports to executive and board
- Stress testing and scenario analysis
- Risk appetite not aligned with permitted activities
- Risks identified but not actively monitored
- Stress testing absent or shallow
- Limited integration between risk and compliance
Submit accurate and timely regulatory reports to VARA including periodic returns, material change notifications and ad hoc disclosures.
- Calendar of regulatory submissions
- Reconciliation files supporting each return
- Material change and incident notifications archive
- Internal sign off for each submission
- Quality assurance review records
- Submissions reconciled to ledgers only after filing
- Material changes notified retrospectively
- No central register of submissions
- Sign off below appropriate seniority
Operate a complaints handling and dispute resolution process accessible to clients with timely investigation, response and reporting of complaints data to senior management.
- Complaints policy and procedure
- Complaints register with classification and outcomes
- Sample case files
- Periodic complaints analysis and root cause reports
- Notifications to VARA where required
- Complaints not centrally captured
- Root cause analysis missing
- Slow response times against published SLA
- Recurring themes not driving change
Apply a product approval process for new digital assets and tokenized instruments listed or supported including risk, legal and compliance assessments.
- Token and product assessment template
- Approval committee minutes
- Delisting and end of support procedures
- Ongoing monitoring of approved assets
- Records of VARA engagement when required
- Assets listed without formal approval
- No ongoing monitoring of listed assets
- Delisting decisions delayed
- Approval criteria not documented
Technology and Operational Resilience
Operate technology and cyber risk management covering platform security, key management, smart contract review, monitoring, vulnerability management and incident response.
- Information security policies aligned with recognised frameworks
- Smart contract audit reports and remediation records
- Penetration test and vulnerability scan reports
- Cyber incident response plan and exercises
- Logging and monitoring coverage analysis
- Smart contracts deployed without independent audit
- Vulnerability remediation SLAs missed
- Monitoring gaps on critical custody systems
- Incident response not tested for digital asset specific scenarios
Maintain business continuity and disaster recovery capabilities for critical services with tested recovery time objectives and client communication procedures.
- Business continuity and disaster recovery plans
- Recovery time and recovery point objectives per service
- BCP and DR test reports with results
- Client communication templates for outages
- Crisis management exercise outputs
- Plans not tested for custody specific scenarios
- RTO and RPO not measured during tests
- Single region cloud dependency
- Client communication ad hoc during outages
Operate an outsourcing and third party risk programme covering custody providers, market makers, technology vendors and other critical service providers.
- Inventory of outsourced functions with criticality ratings
- Outsourcing policy aligned with VARA expectations
- Contracts with audit, exit and continuity clauses
- Annual oversight reviews
- VARA notifications for material outsourcing
- Critical outsourcing not notified to VARA
- No exit plan or substitutability analysis
- Sub outsourcing not visible
- Oversight limited to onboarding only
VARA Compliance and Risk Management Rulebook
VASPs must implement robust anti-money laundering and counter-terrorism financing controls and client risk assessments.
- AML programme document and risk based approach
- Customer due diligence and EDD records
- Sanctions screening tool configuration and audit
- SAR or STR filing records
- Risk based approach not evidenced
- Screening lists not refreshed daily
- Travel rule data omitted from outbound transfers
- Beneficial ownership data stale
VASPs must screen transactions and counterparties against applicable sanctions lists and enforce prohibitions.
- AML programme document and risk based approach
- Customer due diligence and EDD records
- Sanctions screening tool configuration and audit
- SAR or STR filing records
- Risk based approach not evidenced
- Screening lists not refreshed daily
- Travel rule data omitted from outbound transfers
- Beneficial ownership data stale
VASPs must establish and maintain a comprehensive enterprise risk management framework with regular assessments.
- Documented procedure addressing risk management framework
- Evidence of executive or risk owner approval
- Operational records demonstrating execution
- Independent assurance or review report
- Procedure exists but execution inconsistent
- Owner accountability not codified
- Review cadence missed or undocumented
- Coverage gaps for in scope entities or systems
VASPs must conduct periodic business risk assessments addressing operational, financial, and reputational risks.
- Risk assessment report covering business risk assessment scope
- Risk register entries with owner, likelihood, and impact
- Treatment plan linked to identified risks
- Evidence of management review and acceptance
- Risk register not refreshed after material change
- Treatment owners undefined or unaccountable
- Residual risk acceptance lacks executive sign-off
- Inherent versus residual scoring not clearly distinguished
VASPs licensed for transfers must collect and share originator and beneficiary details for transactions above thresholds.
- AML programme document and risk based approach
- Customer due diligence and EDD records
- Sanctions screening tool configuration and audit
- SAR or STR filing records
- Risk based approach not evidenced
- Screening lists not refreshed daily
- Travel rule data omitted from outbound transfers
- Beneficial ownership data stale
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the UAE Virtual Asset Regulatory Authority (VARA) Regulations framework page.