The position
Accountability under this framework is personal by design.
Accountability under this framework is personal by design. VARA does not regulate the firm alone and leave the people inside it as an internal matter. It requires named individuals to be appointed, approved, and answerable for the firm’s compliance; it tests their fitness at entry and keeps testing it for as long as they serve; and it holds powers that end careers, and licences, on the strength of one person’s failure. Above the VARA layer sits the federal one, examined in the companion article “Which federal laws stand behind a VARA licence?”, which reaches the person directly with imprisonment, fines, professional bars and, for foreign nationals, deportation.
The centre of the VARA architecture is a pair of named individuals. Every VASP must appoint two Responsible Individuals of sufficient seniority who are responsible for the firm’s compliance with “all legal and regulatory obligations” (Company Rulebook, Rule I.C.1, current as at 1 July 2026). Each must be a full-time employee, a Fit and Proper Person, a UAE resident or passport holder, and notified to and approved by VARA at licensing (Rule I.C.2). Their continuing compliance with those conditions must be validated, and the validation recorded, every year (Rule I.C.3), and no change of Responsible Individual happens without VARA’s prior approval, save genuinely unforeseen circumstances with immediate notice (Rule I.C.4). The remit is worth reading slowly: “all” is unqualified, so on the rule’s own words the two named individuals answer for everything from the rulebooks to the federal layer this series has mapped, a reading of the rule’s breadth rather than a list the rule itself provides.
Around that pair, the rulebook constructs a full cast. Part I builds the structure: the Board, Senior Management and the Company Secretary each have their own rules, taken up in Section II. Part II imposes the governance duties that bite on individuals, competence, segregation of duties, conflicts, insiders’ and related-party transactions, and loans to the board or staff, taken up in Section IV. And alongside the Company Rulebook sit the control officers the framework requires and VARA approves, the Compliance Officer and the Money Laundering Reporting Officer, taken up in Section V together with the risk-assessment guidance VARA has published for the function they run.
Fitness is not a licensing hurdle cleared once. When a firm assesses whether an individual remains a Fit and Proper Person, it must assess the role that individual is actually performing at the time of the assessment (Rule III.G.1), so fitness follows function rather than title, and the entry tests of Part III, qualification, industry experience, management experience, financial status, and honesty, integrity and reputation, are the standing standard the person is held to, not a form completed at application. Section III works through what each test demands.
The consequences make the design unmistakable. Where VARA takes the view that an individual is no longer fit and proper, it may revoke or suspend the approval granted to that individual or the licence of the VASP itself, reprimand the individual publicly or privately, prohibit them from ever applying again, fine a material breach, require the firm to implement additional controls, and take any other enforcement action it determines (Rule III.G.2). The first limb deserves its own sentence: on the rule’s face, one person’s lost fitness can cost the whole firm its licence. And the federal layer stacks its own consequences on the same person, the manager punished where aware and in breach of duty, board members suspended or barred by the supervisory authority, and the professional position itself an aggravating circumstance in sentencing, each verified in the companion article “Which federal laws stand behind a VARA licence?”.
So the honest short answer is that in this framework the firm’s compliance has names attached to it, the names are approved and continuously tested, and both regulators, VARA and the federal layer above it, are built to reach the people and not only the company. The rest of this article works through that design: the named roles and what each owns, the fitness tests at entry and as a standing condition, the governance duties that bite on individuals, the approved compliance officers and the guidance that now frames their work, the federal layer on the person, and finally what is settled and what remains open.
Part I of the Company Rulebook reads less like incorporation formality and more like a map of who answers for what. It constructs four roles, the Board, the Responsible Individuals, Senior Management and the Company Secretary, and attaches to each a defined remit, a fitness condition, and in most cases VARA’s own approval. Accountability in this framework is distributed by name before a single activity rule applies.
The Board is built person by person. Every member must be suitably qualified for the firm’s actual activities and must be assessed by the firm and approved by VARA as a Fit and Proper Person against the Part III criteria (Company Rulebook, Rule I.B.1.a, current as at 1 July 2026). The Board then polices itself: it must confirm each member’s fitness at least annually, must promptly reassess any member it has reason to doubt at any time, and where a member is no longer fit and proper, it must remove that member with written notice and appoint a successor through the procedures its own constitutional documents are required to contain (Rules I.B.1.b and I.B.1.c). A chairman is elected with authority over the Board’s overall effective functioning, and the Board assesses itself, its committees and its individual members annually, with external experts if needed (Rules I.B.1.e and I.B.1.f).
What the Board owns is stated in terms that deserve a slow read. The Board “and each of its members shall assume full responsibility” for the operation of the business in a manner conducive to fair and orderly virtual-asset markets, for the firm’s compliance with all applicable laws and regulatory requirements, and for implementing a professional compliance culture (Rule I.B.2.b). The words “each of its members” carry the weight: responsibility is individual as well as collective on the rule’s face, and a director cannot point to the room. The Board must keep itself continually and timely apprised of the business through regular communication with committees, Senior Management and staff (Rule I.B.2.c), must map the authorisations, authority and reporting lines of Senior Management in written policies (Rule I.B.2.d), and may delegate to committees and Senior Management, but in doing so it must supervise what it delegated and remains primarily responsible for its duties (Rule I.B.2.e). Delegation moves the work; it does not move the accountability. The rulebook even obliges the firm to train the people it holds responsible: new members receive structured training on the business, their own duties and liabilities, and the risks of the global sector, reviewed annually (Rule I.B.3).
Beside the Board stand the two named individuals Section I introduced. Every VASP appoints two Responsible Individuals of sufficient seniority who are responsible for the firm’s compliance with all legal and regulatory obligations; each is a full-time employee, a Fit and Proper Person, a UAE resident or passport holder, and approved by VARA at licensing, with the conditions validated and recorded annually and any change pre-approved save genuinely unforeseen circumstances with immediate notice (Rules I.C.1 to I.C.4). How this pair sits with the Board is not stated by the rulebook and is read here from the two rules together: the Board owns compliance as a matter of governance, while the Responsible Individuals are the named, regulator-facing pair answerable for it day to day, which is why their identity, unlike a director’s, is fixed into the licence itself.
Senior Management is where accountability is made an engineering requirement. The firm must establish, document and maintain a management structure that clearly sets out the roles, responsibilities, authority and accountability of Senior Management (Rule I.D.1); the org chart is required to say who answers for what. Its members must be suitably qualified for the global sector, are appointed by the Board through procedures in the constitutional documents, act under the Board’s direction and oversight, and run the day-to-day in compliance with all applicable laws and in line with Board-approved objectives (Rules I.D.2 to I.D.4), with the Board assessing their performance at least annually on information they are obliged to furnish (Rule I.D.7). Outside positions are gated: a Board seat elsewhere needs the Board’s prior written approval and a conflicts screen, and employment elsewhere its prior written consent (Rules I.D.5.b and I.D.5.c). And one clause does quiet structural work: any member of Senior Management may hold a seat on the firm’s own Board, except the Compliance Officer and the head of any internal audit function (Rule I.D.5.a). The two control functions are the only people in the firm barred from the Board by rule, because they must remain answerable to it rather than part of it, a design Section V returns to.
The Company Secretary is the role that makes the rest provable. The Board must appoint a secretary independent of Senior Management, reporting directly to the Board (Rule I.E.1), whose duties are drawn in unusual detail: documenting Board meetings in minutes that record the discussions and deliberations, the resolutions and voting results, the attendees and any expressed reservations, signed by all attending members; keeping every report to and from the Board; ensuring members actually comply with what the Board approved; informing staff and Senior Management of the resolutions relevant to them and reporting on implementation; and regulating the Board’s disclosure record under the Market Conduct Rulebook (Rules I.E.2.a to I.E.2.l). The consequence, drawn here from the design rather than stated in it, is that this office builds the evidence on which individual accountability is later judged: a director’s recorded reservation is the difference between provable dissent and presumed assent, and the rule requires the reservation to be minuted. An external secretary is permitted, but the appointment is an outsourcing and carries the whole of Part IV’s controls with it (Rule I.E.3).
So Part I distributes responsibility by name: a Board whose members are individually approved, individually responsible and obliged to remove their own unfit colleagues; two named individuals fixed into the licence; a management layer whose accountability must be drawn on paper; and a secretary whose records make the whole structure auditable. Every one of these roles rests on the same condition, that the person is and remains a Fit and Proper Person, and that condition is a regime of its own. Section III turns to what it demands.
Every role Section II named rests on one defined condition, and Part III is where the framework defines it. A Fit and Proper Person must possess the necessary academic qualifications and, in all cases, relevant professional knowledge or industry qualifications having regard to the functions actually to be performed; be honest, reputable, of integrity, and hold to the ethical standards reasonably expected of the role; possess adequate relevant global virtual-asset sector and management experience, or such experience in another relevant sector; have a good understanding of the regulatory framework governing the role and the market; and be financially sound (Company Rulebook, Rule III.A.1, current as at 1 July 2026). Five elements, and the rest of the Part turns each into something assessable.
The assessment is role-specific from the first step. A firm assessing fitness must consider the nature, scale and complexity of its own business and whether the individual has the knowledge, skills and experience for the specific role that individual is intended to perform (Rule III.A.2), which is the entry-side twin of the continuing rule Section I met, that fitness is assessed against the role actually performed. And for Board appointments there is an overlay that changes hiring arithmetic: the firm must ensure that, with the appointment made, the Board as a whole will at all times possess adequate knowledge, skills and experience for the business (Rule III.A.3). An individually excellent candidate can still be the wrong appointment if the Board they join ends up collectively short.
Part III then does something rulebooks rarely do: it describes how the regulator will exercise its own judgment. VARA assesses case by case, taking into account the firm’s licence conditions, business model and market, its governance and the competence of its staff, decisions made about the individual by any authority in the Emirate or in other jurisdictions, and the state of any other business the individual runs or proposes to run (Rule III.A.4.a). It will “look to the substance of the requirements and the materiality of any failure” (Rule III.A.4.b). The gate is hard, VARA will not grant approval unless satisfied (Rule III.A.5), but the test is not mechanical in either direction: an individual who misses individual elements may still satisfy VARA on all the factors together (Rule III.A.6). Substance over form is not a gloss on this test; it is the test’s own stated method.
Qualification is drawn the same way. A relevant degree is a factor, and the rule says in terms that its absence does not prevent employment where the individual has relevant professional or industry qualifications or experience (Rule III.B.1.a). What must be demonstrable is understanding: of the structure of the regulatory framework applying to the job, of the particular Regulations, Rules, Directives and Guidance applying to the individual’s own functions, of the fiduciary obligations owed to clients, of the VA activities the individual helps the firm undertake, and of the market in which the services are provided (Rule III.B.1.b). The credential can be substituted; the understanding cannot.
Experience is tested for substance, in two registers. Industry experience means hands-on working experience, acquired through VA activities in the Emirate or activities of a similar nature in other industries or jurisdictions, assessed for whether its substance is directly relevant or crucial to the activities the individual will carry out, with the whole career history available to count (Rules III.C.1 to III.C.3). Management experience, for Board and Senior Management roles, means hands-on experience supervising and managing essential VA activities and staff in a business setting, and the rule adds its own edge: experience which is purely administrative would be less relevant (Rule III.D.1). Titles held do not answer the question; what the person actually ran does.
Financial soundness is the shortest test and the most mechanical. The rule names the disqualifying territory: the undischarged bankrupt, the person currently in bankruptcy proceedings or only recently discharged, the person in receivership or similar, and the person who has failed to meet a judgment debt, assessed with regard to the circumstances and the recency of the failure (Rule III.E.1). This is the one element where the framework’s flexibility narrows to almost nothing.
Honesty, integrity and reputation is where the factor list repays the slowest reading, because several of its edges cut earlier than an applicant expects, and all of them reach conduct in any jurisdiction (Rule III.F.1). Convictions count, with particular weight on dishonesty, fraud, financial crime and offences under companies, banking, insolvency, money-laundering and insider-dealing laws, but so do adverse findings and settlements in civil proceedings, so settling does not erase the event. An existing or previous investigation counts, and so does having been notified of a potential one, before any proceeding exists. Regulatory breaches, justified complaints in any jurisdiction, dismissal for cause, and disqualification from directorship all count. Two factors carry precise edges: having been a director or senior manager of a business that went into insolvency, liquidation or administration while connected with it or within one year of that connection, so leaving shortly before a failure does not clear the record; and having compromised with a creditor in any amount greater than AED 50,000, a specific and low threshold. And the list closes with the factor that functions as the test’s memory: whether the individual has been candid and truthful in all past dealings with any regulatory body, and demonstrates readiness to comply (Rule III.F.1.j). The counterweights are stated with equal care: a criminal conviction is not an automatic bar, and VARA may weigh its seriousness, circumstances, the explanation offered, relevance to the role, the passage of time, rehabilitation, and the controls the individual and the firm will put around it (Rule III.F.2); and reputation is assessed for whether it has or might have an adverse impact on the performance or market perception of the VASP itself (Rule III.F.3), so one person’s history is tested for its contagion to the firm.
Two boundary points complete the standard. First, its continuation: fitness is reassessed against the role actually performed, and the consequences of losing it, up to the licence of the firm itself, were set out in Section I (Rules III.G.1 and III.G.2). Second, its reach: the loaded rules attach the fit-and-proper condition to Board members and to the Responsible Individuals, and apply its standard to Board and Senior Management assessment; whether a person acquiring or exercising control over a VASP is separately assessed is a matter for the change-of-control rules in Part VIII rather than this Part, a boundary this article notes without asserting, since nothing in this section turns on it. What the standard governs, for everyone it reaches, is the person. What the framework then regulates is their conduct in office, and Section IV turns to the governance duties that bite there.
Part II converts the role map of Section II into conduct rules, and several of them reach the individual directly. The quietest of them, buried in the related-party rule, makes a director’s personal liability turn on what the Board minutes show, which is why this section ends where Section II began, with the record.
The base layer is competence and separation. Firms must maintain policies ensuring that every member of the Board, Senior Management and staff is suitably qualified for their actual post, assessed against criteria including academic credentials, professional qualifications and experience, honours, and professional memberships, and the Board may appoint to supervisory positions only staff whose experience and qualifications match the responsibilities of the role and the firm’s activities (Company Rulebook, Rules II.A.1 and II.A.2, current as at 1 July 2026). Duties are then separated three ways: policy formulation, supervisory, advisory and internal review functions segregated from operations, so controls hold and abuses do not go undetected; the operational duties themselves, sales, dealing, accounting, settlement and the safekeeping of virtual assets, segregated from one another; and compliance and internal audit segregated from, and independent of, both the operational and the supervisory functions, with the Compliance Officer and any head of internal audit reporting directly to the Board (Rules II.B.1 to II.B.3). Read with the rule from Section II that bars those same two officers from Board seats, the design is symmetrical: they cannot sit on the Board, and they must answer to nothing less than the Board.
Conflicts of interest are governed as a lifecycle. The firm must use all reasonable efforts to avoid conflicts across its group, itself, its Board, its staff, its clients and its investors, and where a conflict genuinely cannot be avoided, it must be disclosed to the affected clients and those clients treated fairly (Rule II.C.1). Where a firm, a director or a staff member has an interest that may reasonably impair objectivity in a client transaction, the firm must promptly disclose the conflict’s nature to the affected client and, where the client’s interests can be sufficiently protected, manage the conflict with appropriate measures including information barriers between teams (Rule II.C.2). And the whole lifecycle must be written down: internal policies for identifying and managing conflicts, and a special register recording each conflict and the measures taken, in detail (Rule II.C.3).
The conflicted director gets a procedure of their own, and it is built to be evidenced. A Board member who discloses a material interest in a transaction is judged by their peers: the remaining members consider whether the conflict affects the member’s objectivity, may ask the member to leave the meeting, and the member does not vote. The rule then reaches further than the meeting room: the member is not entitled to use personal influence on the issue whether in or outside the meeting. And the Company Secretary records the conflict in the minutes (Rule II.C.4). Disclosure, exclusion, abstention and record, each step generating the evidence that the next rule in this section will make decisive.
One conduct rule is triggered by a word. A firm that represents itself as independent in conducting an activity may not receive fees, commissions or any benefit, directly or indirectly, from anyone other than the end client in relation to that activity, and may not maintain close links or economic relationships with third parties likely to impair that independence (Rule II.C.5). Independence is not a marketing adjective in this framework; using it places the firm under two hard prohibitions, so the compliance state is created by the claim itself.
The related-party rule is where governance failure becomes personal liability, and its architecture deserves to be read in full. A firm may not enter a transaction with a related party whose value exceeds five percent of its issued share capital without the Board’s prior written consent, renewed if the terms significantly change, and the interested related party does not vote (Rules II.G.1 and II.G.2). VARA receives prior notice identifying the party and the transaction, with a written confirmation that its terms are fair, reasonable and proportional to the shareholders’ interests; clients and shareholders may review the records; and VARA, clients and shareholders alike may go to court to compel disclosure, cancel the transaction, strip the related party’s profit back to the firm, and recover compensation (Rule II.G.5). A register is kept, and every related-party transaction is reported to VARA monthly (Rules II.G.6 and II.G.7). Then the liability rule: where a transaction breaches this Part, or proves unfair or conflicted and damages the firm or its shareholders, the related party is liable in damages, and so is the Board itself where the decision was issued by consensus (Rule II.G.3). Where the decision was by majority, a dissenting member is not liable, but only where they “recorded their objection in the Board minutes”, and an absent member remains responsible unless they prove they were unaware of the decision, or knew of it but could not object (Rule II.G.4). This is the rulebook’s clearest statement that accountability follows the record: the Company Secretary’s minutes, met in Section II, are not administration, they are the only shield the rule recognises, and a director’s silence in them reads as assent.
Two shorter rules complete the Part. The Board must implement rules governing and monitoring the transactions of its own members and staff, for compliance with the Regulations and the Market Conduct Rulebook, which is where the substantive insider-dealing regime lives (Rule II.F.1). And no loan may be made to a member of the Board, of Senior Management or to a Responsible Individual without notifying VARA and obtaining approval first, with the recipient’s name, the amount and the purpose disclosed in full (Rules II.H.1 and II.H.2), so credit from the firm to the people who run it passes through the regulator, by name. What Part II assumes throughout is that the control functions doing this policing, the Compliance Officer above all, are themselves properly constituted, independent and answerable. Section V turns to those officers, and to the guidance VARA has now published for the risk assessment they own.
Beside the governance roles of Section II, the framework requires three officers whose entire job is control: the Compliance Officer, the Money Laundering Reporting Officer, and the Chief Information Security Officer. Each is a named individual, each is held to the fit-and-proper standard of Section III, and the rulebook that creates the first two closes with a rule stating that enforcement may be taken against them personally. This section sets out who they must be, what they owe, how their roles may and may not be combined, and the guidance VARA has now published for the risk assessment at the centre of their work.
The Compliance Officer is the most heavily conditioned appointment in the framework. The officer must have at least five years of relevant compliance experience, be a Fit and Proper Person as approved by VARA, be a UAE resident or passport holder, be a full-time employee, and report directly to the Board, with the appointment reviewed annually and VARA holding sole discretion to demand evidence that every condition remains satisfied (Compliance and Risk Management Rulebook, Rule I.C.1, current as at 1 July 2026). The duties run from training the staff and Senior Management, through developing the compliance policies including the business-continuity plan, to assessing emerging risks, reporting compliance activities and audits to the Board, and driving corrective action (Rule I.C.2). The compliance management system the officer administers must be independent of all operational and business functions, and everyone performing compliance work must themselves be fit and proper (Rules I.B.1.b and I.B.5). And one duty sets the office apart from every other in the firm: the Compliance Officer is ultimately responsible for notifying VARA and other relevant authorities of any material non-compliance by the VASP, its Board or its Staff (Rule I.B.2). The framework has placed inside every firm an officer whose written duty includes reporting the firm’s own Board to the regulator, which is the practical meaning of the Board-seat bar and the direct reporting line Sections II and IV described.
The Money Laundering Reporting Officer is conditioned differently, and the difference is instructive. The stated entry conditions are lighter, at least two years of experience handling AML/CFT matters and fit-and-proper status, reviewed annually with VARA’s evidence power (Rule III.A.1). But the same rule adds a sentence that makes the office self-referential: VARA shall take into consideration any failures by the individual to comply with Part III itself when assessing whether that individual is fit and proper. The MLRO’s own AML compliance record is a standing input to the MLRO’s own approval. The duties are the operating core of the financial-crime programme: training the Board and staff, building the AML policies, conducting the risk assessments, monitoring and reporting suspicious transactions, and driving corrective action against the Federal AML-CFT Laws (Rule III.A.2). Two of them deserve emphasis. The MLRO reports to the Board quarterly on the effectiveness of the firm’s AML framework, identifying failures and non-compliance, and each quarterly report must include a summary of all anonymity-enhanced transactions and the clients involved, available to VARA on request (Rules III.A.2.f to h). And the reporting duty is personal and clocked: on suspicion, the MLRO is responsible for immediately reporting to the UAE Financial Intelligence Unit and for answering any further request from the Unit or VARA within forty-eight hours (Rule III.F.3). Above the VARA layer, the federal Executive Regulations make the appointment itself subject to the Supervisory Authority’s prior approval, as the companion article “Which federal laws stand behind a VARA licence?” verified.
How these offices may be combined is drawn with more precision than firms often assume, and the two rulebooks read together produce a clean architecture. The Compliance Officer may hold more than one non-client-facing role where the roles do not conflict, expressly including the MLRO and the head of the risk function, with VARA weighing the stack in the fit-and-proper assessment (Rule I.C.4, mirrored at Rule III.A.4). The head of the risk function may be the Compliance Officer, and where the roles are separate, the head of risk also reports directly to the Board and delivers a risk exposure report at least quarterly (Rules I.D.2 and I.D.4). The Chief Information Security Officer, by contrast, “must be a separate individual from the CO”, though the CISO may take on the Data Protection Officer’s responsibilities (Technology and Information Rulebook, Rule I.I.1, current as at 1 July 2026). Reading the permissions and the one prohibition together, the control function’s irreducible headcount is two: one individual may lawfully stack compliance, money-laundering reporting and risk, a second must hold information security, and may stack data protection on top. That two-person floor is a consequence drawn from the combination rules rather than a stated rule, and it is the number around which every lean licence application is actually built.
The CISO’s own remit is stated briefly and reaches widely: responsibility for the firm’s compliance with the whole of the technology-governance, controls and security Part and the confidential-information Part of the Technology and Information Rulebook, held by an individual of “sufficiently good standing and appropriately experienced”, with Senior Management obliged to assess the effectiveness of the firm’s technology compliance regularly and to allocate roles so conflicts do not arise (Rules I.I.1 to I.I.3). In a sector whose defining operational risk is the loss of keys and client assets, this is the officer on whom Section II’s segregation architecture ultimately leans.
None of the three offices can be delegated away. Compliance activities and AML activities may be delegated to appropriate professionals or entities, but in each case the rule is explicit that the officer continues to be held accountable for all responsibilities and obligations, and the Company Rulebook’s outsourcing controls apply in full (Rules I.C.3 and III.A.3). A firm may buy the work; it cannot buy out the accountability. The officer whose name is on the appointment answers for the outsourced function as if it were performed in-house.
At the centre of the MLRO’s duties sits the business risk assessment, and it is the most demanding recurring obligation in the compliance calendar. Every VASP must conduct a documented AML/CFT business risk assessment that identifies and assesses the risks specific to its business, expressly including anonymity-enhanced cryptocurrencies and transaction methods, new technologies such as artificial intelligence, and other emerging risks, refreshed at intervals no longer than every three months and on any significant change (Rules III.D.1 to III.D.3). The assessment cannot be a shelf document: the firm must be able to demonstrate to VARA that its outcomes directly inform the AML policies and the allocation of compliance resources (Rule III.D.4), the client risk assessment runs on the same quarterly cycle (Rule III.D.8), and where a firm enables anonymity-enhanced transactions at all, it owes proportionately enhanced controls with client-level enhanced due diligence verified every six months, and must not offer the product where the risks cannot be mitigated (Rule III.D.5). On 12 June 2026 VARA published guidance on exactly this obligation, announced on its own site and drawing, in the document’s own words, on VARA’s supervisory observations from its 2026 thematic review of business risk assessments. The guidance is expressly illustrative rather than binding, and its emphasis falls where the rule’s verbs already point: the assessment as the foundation of the financial-crime programme, evidence-based and operationally connected to daily control decisions; a transparent, repeatable methodology; a three-lines-of-defence structure; version control as the evidentiary proof that the assessment is a live document; and defined escalation triggers, including adverse findings, sanctions designations and changes of MLRO. One placement note for the careful reader: as at the date of this article the guidance sits on VARA’s main site and has not yet been listed in the rulebook site’s Guidance section, an observation about where to find it rather than about its status, which is non-binding either way.
The Part that creates these offices closes by saying what happens when they fail, and it says it about people. A VASP that fails to comply with Part III faces enforcement under the Regulations and the Federal AML-CFT Laws, and that enforcement may be taken directly against the VASP, “its directors, Responsible Individuals, MLRO and/or Senior Management” (Rules III.J.1 and III.J.2). Every thread of this article so far, the named roles, the fitness condition, the governance duties, the approved officers, runs into that sentence. And above it stands the federal layer, where the consequences stop being administrative altogether. Section VI turns to it.
The companion article “Which federal laws stand behind a VARA licence?” read the 2025 AML law for the firm. Read for the person, the same statute is a ladder of individual exposure that begins where VARA’s administrative reach ends, and every rung below is the same law arriving at a named individual, the director, the Responsible Individual, the MLRO, the manager, whom the earlier sections of this article identified.
The first rung is supervisory, and three of its measures name people. For any violation of the law, its Executive Regulations or connected decisions, the Supervisory Authority, which for a Dubai VASP is VARA, as the companion article verified, may impose penalties running from a warning and a fine of AED 10,000 up to AED 5,000,000 per violation to suspension of the activity and revocation of the licence (Federal Decree-Law No. 10 of 2025, Article 17(1), current as at 1 July 2026). Within that menu, three measures are aimed at individuals: prohibiting the violator from engaging in the relevant sector for a period the authority sets; restricting the powers of board members, executive, supervisory or managerial personnel, or owners proven responsible, including by appointing a temporary supervisor; and suspending directors, board members or executive or supervisory personnel proven responsible, or requiring their replacement (Articles 17(1)(c) to (e)). Fines escalate on repetition within a year, and the authority may publish what it imposes (Articles 17(3) and 17(4)). A career in this sector can therefore be interrupted, supervised or ended administratively, before any criminal question arises.
The criminal rungs begin with a knowledge standard that reaches the conscientious and careless alike. Money laundering is committed by one who knows, or where sufficient indications or evidence exist to believe, that funds are proceeds of a predicate offence, and knowledge may be inferred from the factual and objective circumstances (Articles 2(1) and 2(3)), with the same inference rule applying to terrorist and proliferation financing (Article 3(4)). For an officer, the consequence, drawn here from the standard rather than stated in it, is that ignored red flags are the factual and objective circumstances: the escalation the firm’s own systems generated and the officer set aside is the evidence from which a court may later infer what the officer believed. And the statute prices seniority into sentencing: committing money laundering by exploiting influence or authority conferred by one’s position or professional activity is an aggravating circumstance that hardens the penalty to temporary imprisonment and a fine of AED 1,000,000 to 10,000,000 or twice the property’s value (Article 26(2)(a)). Reading that against Part I of the Company Rulebook, the seniority the framework requires of its named roles is the same fact the criminal statute treats as aggravation, an observation about how the two texts meet rather than a stated rule in either.
Then come the offences of office, the provisions written for exactly the duties Sections II through V described. The reporting duty is criminal to breach: a deliberate or grossly negligent failure to notify the Financial Intelligence Unit carries imprisonment and a fine of AED 100,000 to 1,000,000, or either (Article 28), and gross negligence suffices, so the MLRO’s exposure does not require intent. Tipping off a customer that a report or inquiry exists carries imprisonment and a fine of at least AED 50,000 (Article 29(1)). The custodial provision deserves its own sentence for this sector: whoever deliberately or through gross negligence breaches the duties of managing funds entrusted to them, or violates a seizure or freezing order, faces the same penalties, and where the act results in the proceeds becoming unseizable, destroyed or stripped of value, the penalty hardens to imprisonment of no less than one year and a fine equal to the value of the proceeds, with a floor of AED 100,000 (Articles 29(2) and 29(3)). An officer administering frozen client virtual assets, the situation the companion article’s freezing mechanics contemplate, is standing inside that provision. Violating targeted-financial-sanctions instructions is an offence (Article 33); breaching the preventive duties themselves, the risk assessment, due diligence, the anonymous-account bar, senior-management-approved policies, sanctions implementation and records, is an offence carrying imprisonment (Article 35(3)); and enabling another to benefit from one’s account with a financial institution or a VASP, knowing or having sufficient grounds to believe the account will be misused, is an offence (Article 35(2)). Against all of this stands one protection the framework’s officers should know as well as the offences: no criminal, civil or administrative liability attaches to a firm, its board members, employees or authorised representatives for good-faith reporting, even where the reporter was not fully aware of the crime’s nature and even where no crime occurred, unless the report was made in bad faith to harm (Article 37(1)). The statute punishes silence and protects disclosure, in terms.
Above the offences of office sits the manager rule, and its width is the point. Where a legal person’s representatives, directors or agents commit the core crimes in its name, the firm faces AED 5,000,000 to 100,000,000 or the value of the criminal property, whichever is greater; where they commit the operational offences, the firm faces AED 200,000 to 10,000,000 (Articles 27(1) and 27(2)). In either case, the person responsible for the actual management of the legal person is punished by imprisonment and a fine, or either, where it is proven they were aware and the crime was committed “due to their breach of the duties of their position” (Article 27(5)). The rule spans both clauses, so the manager’s personal liability does not require money laundering on the premises: an unreported suspicion, a tip-off, an anonymity product, an unlicensed line of business or a falsified beneficial-owner record, done by the firm’s people with the manager aware and derelict, is enough. Dissolution is mandatory on the firm’s conviction for terrorist or proliferation financing and discretionary for money laundering, and the court may publish the judgment at the convict’s expense (Articles 27(3), 27(4) and 27(6)).
The last rungs are the ones that do not reverse. A foreign individual given a custodial sentence for money laundering or any felony under the law must be deported, and for the law’s misdemeanours the court may deport, or substitute deportation for the custody itself (Article 36). The criminal case, the penalties and the civil actions arising from these crimes are all exempt from prescription (Article 37(2)), so personal exposure under this statute never ages out. Operating without the required licence, registration or enrolment is itself an offence carrying imprisonment and AED 200,000 to 10,000,000 (Articles 20 and 32), which is the provision that reaches founders in the period before a licence exists. And the one door that opens rather than closes: the court may mitigate or exempt an offender who voluntarily gives the authorities information leading to the disclosure of the crime, the identification or arrest of its perpetrators, the proof against them or the seizure of the property (Article 26(6)).
Stacked with the earlier sections, the full ladder for one person now stands visible end to end: fitness revoked and careers barred at the VARA layer, enforcement taken directly against directors, Responsible Individuals, the MLRO and Senior Management under the compliance rulebook, powers restricted and positions suspended under the federal supervisory article, the offences of office for the duties actually held, aggravated core liability where seniority was the instrument, the manager rule where awareness met dereliction, and deportation with no limitation period at the top. At every rung, what protects the individual is the same thing Sections II and IV kept returning to: the record, the minuted dissent, the documented reservation, the version-controlled risk assessment, the report filed in good faith. What remains is to say what in all of this is settled and what is still open, and Section VII closes there.
Nearly all of this architecture is settled, and its coherence is the finding. Accountability is distributed by name: a Board whose members are individually approved and individually responsible, obliged to remove their own unfit colleagues; two Responsible Individuals fixed into the licence itself; a management layer whose accountability must be drawn on paper; and a secretary whose records make the whole structure auditable (Section II). The condition every role rests on is a continuing, substance-over-form fitness test, assessed against the role actually performed, whose loss can end not only an approval but the firm’s licence (Section III). The governance duties bite on individuals, and the sharpest of them makes a director’s liability on a related-party decision turn on whether dissent was minuted (Section IV). Three approved officers carry the control function, on an architecture whose irreducible headcount is two, and the rulebook that creates them states that enforcement may be taken against them personally (Section V). And above the VARA layer, the federal statute builds a ladder of individual exposure from supervisory suspension through offences of office to the manager rule, deportation and liability that never ages out (Section VI).
What remains open is narrower than in the companion pieces, and it sits at the edges rather than the centre. Whether a person acquiring or exercising control over a VASP is separately assessed as fit and proper is a matter for the change-of-control rules in Part VIII of the Company Rulebook, marked in Section III as a boundary this article did not need to cross. The substantive insider-dealing regime lives in the Market Conduct Rulebook, and this article carried it at pointer level only. Two applications are untested rather than unclear: how the federal custodian offence operates on frozen virtual assets, the same seam the companion article “Which federal laws stand behind a VARA licence?” identified in the freezing mechanics; and where, in practice, ignored escalations become the factual and objective circumstances from which a court will infer an officer’s knowledge. And the guidance layer is open by design: the business risk assessment guidance is expressly illustrative, published weeks before this article’s date, and how VARA’s supervisory posture develops around it will show in inspections before it shows in instruments.
If this article carries a single practical instruction, the framework wrote it itself: keep the record. A director’s liability on a conflicted transaction turns on whether the objection appears in the minutes the Company Secretary is obliged to keep. An officer’s defence to an inferred-knowledge case is the documented handling of every escalation. The risk assessment proves itself a live document through version control, in the guidance’s own emphasis. The good-faith report is the one act the criminal statute shields in terms. At every point in this framework where liability attaches to a person, the difference between exposure and defence is a document the framework already requires that person to create.
This analysis rests on the Company Rulebook, the Compliance and Risk Management Rulebook and the Technology and Information Rulebook, each in the version effective 19 June 2025 on VARA’s live rulebook; on Federal Decree-Law No. 10 of 2025, in force since 14 October 2025 and loaded from the official register; and on VARA’s AML/CFT Business Risk Assessment Guidance, published 12 June 2026 and non-binding. Each is live. A new version of any of the three rulebooks, movement in the 2025 federal instruments, or a change in the guidance would each be a reason to read this analysis again against the source. The question in the title, on that basis, has a precise answer: the named, the approved and the aware. The Board member who is individually responsible on the rule’s face; the two Responsible Individuals whose remit is everything; the officers whose duties are personal and clocked; and the actual manager, wherever awareness met dereliction. The framework’s design is that compliance failure always has an address.
For your facts, in confidence, put the question to the firm.





The bench stands behind it