The UAE holds its virtual asset firms to some of the highest compliance standards in the world - and in 2026, meeting them is about far more than avoiding penalties. Strong compliance has become the precondition for the things that actually let a crypto business operate: banking relationships, institutional clients, and a licence that survives supervision. Get it right and you build trust; get it wrong and the consequences are now swift and public.
Having helped firms build and upgrade their compliance frameworks, we have found the UAE's expectations rest on three pillars: a solid legal foundation, the new governance layer introduced by the federal framework, and a set of operational duties that are easy to underestimate. Here is what good looks like.
The Legal Foundation
The backbone of the regime is Federal Decree-Law No. 20 of 2018 on anti-money laundering and counter-terrorism financing, reinforced by Cabinet Decision No. 10 of 2019 and supervised by the Supreme Committee for AML/CFT. Every financial firm - crypto businesses very much included - must run a comprehensive AML programme, conduct proper customer due diligence, and report suspicious activity. The UAE's earlier removal from the FATF grey list set the tone: standards are high, internationally aligned, and actively supervised.
The New Governance Layer
CMA Decision No. 4/R.M/2026 adds a governance dimension to these duties. Compliance is no longer something a firm can run remotely or treat as a back-office function. Licensed VASPs must maintain six senior roles, with the Compliance Officer and MLRO required to reside in the UAE and to be individually accredited by the regulator. Nominal or outsourced appointments will not pass. Accountability, in other words, must be real, resourced, and onshore.
Customer Due Diligence: A Risk-Based Approach
At the heart of the regime is a risk-based approach. Firms must first assess their own exposure - to high-risk jurisdictions, products, and customer types - then apply due diligence proportionate to that risk:
- Simplified Due Diligence (SDD): for clearly low-risk relationships.
- Standard CDD: for most customers and transactions.
- Enhanced Due Diligence (EDD): for high-risk clients, politically exposed persons, and large or complex transactions.
Identity must be verified at onboarding and monitored throughout the relationship - not checked once and forgotten. Ongoing transaction monitoring is expected to detect anomalies in real time.
The FATF Travel Rule
One requirement unique to virtual assets is the FATF Travel Rule. Before transferring virtual assets above a set threshold - VARA applies it to transfers exceeding AED 3,500 - a VASP must obtain, hold, and securely share accurate information about both the originator and the beneficiary. This includes a 'Know Your Counterpart VASP' step: verifying that the firm on the other side of a transfer is itself regulated and compliant. It is one of the most operationally demanding obligations in the regime, and one regulators scrutinise closely.
The Operational Duties Firms Underestimate
Beyond AML fundamentals, the federal framework layers on concrete operational requirements:
- Six-year record retention for agreements, transactions, suitability reports, and complaints.
- Client classification as Retail, Professional, or Counterpart, reviewed periodically.
- Annual technology audits for platform operators and custodians.
- Cybersecurity controls with board-level ownership, penetration testing, and prompt incident reporting.
- Timely suspicious-transaction reporting through the UAE's goAML system.
Why It Pays to Build It In
Compliance in the UAE is a continuous commitment, not a milestone ticked at licensing. The firms that build it into their culture and systems from day one move faster through authorisation, face fewer surprises in supervision, and find it markedly easier to open and keep banking relationships. In a market positioning itself as institutional-grade infrastructure, demonstrable compliance is increasingly a competitive advantage - not just a cost.
Key Takeaways
- The foundation is federal law: Decree-Law No. 20 of 2018 and a risk-based AML programme are non-negotiable.
- Compliance must be onshore: the Compliance Officer and MLRO must reside in the UAE and be accredited.
- Tier your due diligence: apply SDD, standard CDD, or EDD based on assessed risk.
- The Travel Rule is operationally heavy: share originator/beneficiary data above AED 3,500 and verify counterpart VASPs.
- Keep records for six years: and report suspicious activity promptly via goAML.
A compliance framework that meets the UAE's 2026 standards is detailed, demanding, and best built early. CFC MENA helps firms design and upgrade AML/CFT programmes - from risk assessment and policy drafting to Travel Rule implementation and senior-role structuring. If you need to build or strengthen your compliance foundation, speak to our team.

Jun 2, 2026
What the CMA Now BansPrivacy tokens, algorithmic tokens and discretionary venues are now banned across the UAE. Here are the CMA's new red lines - and what they mean for your business.
.png)


