hoot.
Position
← Positions · the record

What does VARA expect your compliance function to produce?

The position

A VARA compliance function is not a posture; it is a production system.

The opening · read the position in full

01 Section I

The short answer

A VARA compliance function is not a posture; it is a production system. The Compliance and Risk Management Rulebook defines its outputs by name, puts most of them on fixed clocks, monthly, quarterly, annual, immediate and forty-eight-hour, and builds an inspection loop around the whole of it: records kept for eight years in native form, an annual external audit, an internal audit at least quarterly, and a standing power in VARA to demand more at any time. Since June 2026 the regulator has also published guidance describing what good looks like for the system’s centrepiece output, the business risk assessment. What follows in this article is the machine, part by part; the people who run it were the subject of the companion article “Who is personally accountable when a VASP breaks the rules?”.

Two features of the rulebook itself shape everything inside it. It is issued pursuant to, and forms part of, the Regulations, and applies to every licensed VASP in addition to the other three compulsory rulebooks and the rulebooks of the firm’s licensed activities (Compliance and Risk Management Rulebook, Introduction, current as at 1 July 2026). And it states its own reading rule: unless otherwise stated, all requirements in it “are Rules and have binding effect” (Introduction). The practical instruction runs opposite to how firms often read regulatory text: nothing in this rulebook is best-practice colour unless it is expressly marked as Guidance. The binding form is the default, and the exception is labelled.

Beneath the rules sits a baseline that binds in spirit, which is broader than it sounds. VASPs must comply with the spirit of seven principles across all business conducted from, through, or servicing the Emirate: integrity, acting truthfully and in clients’ best interests yet at all times preserving market integrity, a qualifier that ranks the market above the client where the two diverge; diligence to the standard of a comparable VASP; capabilities, actually holding and deploying the resources the business needs; prompt and proper accounting for client assets; disclosures that are clear, effective and current; compliance, expressly extending beyond laws and licence conditions to the firm’s own constitutional documents and internal policies, so a breach of the firm’s own policy is itself a principle-level failure; and open, transparent dealings with regulators at all times (Rule I.A). Because the principles bind in spirit and the reading rule makes them Rules, they function as an enforceable floor beneath the specific requirements, reaching conduct no individual rule names.

The system itself is specified as engineering. Every VASP must maintain a compliance management system that covers all relevant aspects of its operations with unfettered access to records for the Board and relevant staff, is independent of all operational and business functions, notifies the Compliance Officer of any material non-compliance promptly, carries the technical competence and resources the job requires, and runs a risk-based testing and monitoring programme that regularly selects areas of the business for review against key performance and risk indicators (Rule I.B.1). Its policies must equip staff and Board to comply with everything applicable, route client complaints to staff not involved in the subject matter, and keep pace with the changing global sector (Rules I.B.3 and I.B.4). And the system’s jurisdiction is not Dubai: to the extent the firm carries out VA activities or similar business anywhere else, it must comply with all applicable law in every jurisdiction where it does so (Rule I.B.6).

What the system must produce is best understood as a calendar. Monthly, the firm delivers to VARA its balance sheet with off-balance-sheet items, profit and loss, income and cashflow statements, the addresses of its VA wallets, a full list of group entities actively investing in virtual assets with a complete record of transactions with them, and its related-party transactions (Rule I.H.1). Quarterly, it delivers the minutes of every Board and committee meeting, a statement demonstrating compliance with its financial requirements including Reserve Assets, its projections and strategic plans, and the risk exposure report its head of risk owes the Board on the same cycle (Rules I.H.2 and I.D.4), while inside the firm the business risk assessment, the client risk assessment and the MLRO’s effectiveness report to the Board all run on the same three-month clock (Rules III.D.3, III.D.8 and III.A.2.f). Annually, it delivers audited financial statements with an auditor’s attestation on internal controls, Senior Management’s own assessment of the year’s compliance, a certification of the statements’ truth signed by a Board member or Responsible Individual, a representative onboarding sample that must include the actual documentation of the first one hundred clients onboarded that year, product descriptions, the group structure with every ultimate beneficial owner, and the biographies, committees and meeting records of its governance (Rule I.H.3). Some duties carry no calendar at all: any breach of any law, Regulation, Rule or Directive related to a VA activity is reported immediately on discovery, as is any action, charge or investigation against the firm, its Board, its ultimate beneficial owners or its Senior Management (Rules I.I.1 and I.I.2); a follow-up request from the Financial Intelligence Unit or VARA is answered within forty-eight hours (Rule III.F.3); changed AML policies are re-attested by a competent third party and resubmitted within twenty-one calendar days (Rule III.B.4); and a new hire receives the operational policies within thirty days (Rule I.J.6). Above the whole calendar sits VARA’s open-ended power to require more (Rule I.H.4).

The loop closes with inspection. Everything the system produces is kept in its original or native file format, distributed-ledger records included, for no less than eight years, indefinitely where national security is touched, and furnished to VARA on demand (Rules I.F.1 to I.F.3). An independent external auditor reports annually, with VARA holding sole discretion to require a replacement auditor it considers inadequate to the firm’s size, complexity or reputation, and the internal audit function, where applicable, works at least quarterly and reports to Senior Management (Rule I.G). The rest of this article follows the machine through its parts: the system and its baseline in depth, the risk engine at its centre and the guidance that now frames it, the client-facing machinery of diligence and monitoring, the transparency machinery of records, audit and reporting, the self-reporting duties that make the firm its own first supervisor, and finally what is settled and what remains open.

02 Section II

The system and its baseline

Section I described what the machine must produce. This section opens the housing: the principles the whole function stands on, the design specification of the compliance management system itself, the operational controls around it, and the staff rules that turn the capabilities principle into headcount. The theme running through all four is that the rulebook regulates the function’s design, not only its results.

The principles come first because everything else is measured against them. VASPs must comply with the spirit of seven principles across all business conducted from, through, or servicing the Emirate (Compliance and Risk Management Rulebook, Rule I.A, current as at 1 July 2026), and each carries an operative edge worth isolating. Integrity requires acting truthfully, justly and in good faith in the client’s best interests, yet at all times preserving market integrity, so where the client’s interest and the market’s diverge, the principle itself ranks the market first. Diligence is benchmarked to the skill and care reasonably expected of a VASP of a similar nature or activity, an external standard under which peer practice becomes legally relevant to what is expected of the firm, a consequence drawn from the benchmark’s own words. Capabilities requires the firm not merely to have but to effectively employ the financial, technical and other resources its operations need. Client assets must be promptly and properly accounted for and adequately safeguarded. Disclosures must be clear, concise, effective, current, and dispatched in a timely manner where ongoing disclosure is owed to a regulator or under a fiduciary duty. Compliance requires effective strategies covering not only every legal and regulatory requirement and licence condition but the firm’s own constitutional documents, internal policies and controls, and the rule states its purpose, promoting the clients’ best interests and the market’s integrity, so a firm that breaks its own policy manual has a principle-level problem before any specific rule is reached. And dealings with regulators must be open and transparent at all times. Because the rulebook’s reading rule makes these binding and the principles bind in spirit, they operate as an enforceable floor beneath the specific requirements, reaching conduct no individual rule names.

The compliance management system is then specified like infrastructure, in five design features. It must cover all relevant aspects of the operations, with unfettered access to necessary records for the Board and relevant staff; it must be independent of all operational and business functions; it must notify the Compliance Officer of any material non-compliance promptly; it must comprise the technical competence, resources and experience its functions require; and it must run a testing and monitoring programme that is risk-based, regularly selecting different areas of the business for review and analysing key performance and risk indicators, all in order to identify potential violations and ensure compliance with every applicable requirement and the firm’s own internal policies at all times (Rule I.B.1). The officer ultimately responsible for establishing and administering it, and for notifying VARA of material non-compliance by the firm, its Board or its staff, was the subject of the companion article “Who is personally accountable when a VASP breaks the rules?” (Rule I.B.2).

Around the system sit its policies, and three of their features do quiet work. The policies must enable all staff and the Board to comply with everything applicable, licence conditions, record keeping, business practices, AML and the client, proprietary and staff dealing requirements included (Rule I.B.3.a). Client complaints must be handled and investigated by staff who are not directly involved in the subject matter of the complaint (Rule I.B.3.b), a miniature independence rule inside the complaints process itself. And the whole apparatus must be reviewed and updated to stay aligned with the changing business and regulatory landscape of the global virtual-asset sector (Rule I.B.4), an update duty benchmarked to the sector worldwide rather than to the Emirate’s own instruments. Everyone performing compliance work must be fit and proper with the necessary skills (Rule I.B.5), and to the extent the firm carries out VA activities or similar business anywhere else, it must comply with all applicable law in every jurisdiction where it does so (Rule I.B.6).

The operational controls translate the principles into dealing-room conduct. Operational policies must ensure regular information exchange with clients, the group and counterparties, the integrity of dealing practices with all clients treated fairly, honestly and professionally, the safeguarding of the firm’s own assets and all virtual assets including clients’ under this rulebook and the technology rulebook together, reliable records, and staff-wide legal compliance (Rule I.E.1). Where the firm acts on a client’s behalf in operating an account, it must communicate the procedures and terms under which it will act, consistent with the client’s stated objectives, and then strictly follow them (Rule I.E.2), so the mandate’s boundaries are set in advance and adherence is not discretionary. Safeguards must exist against any staff member or Board member taking advantage of confidential or inside information, in addition to the Market Conduct Rulebook’s own regime (Rule I.E.3), and robust anti-theft and anti-fraud procedures must govern how anyone, Board included, acquires, transfers or disposes of the firm’s or clients’ virtual assets (Rule I.E.4). The committees rule then ends on a compulsion: firms may establish whatever committees they consider appropriate, and VARA may require a firm to establish any committee VARA deems appropriate, as a condition of the licence or at any stage thereafter (Rule I.E.6). The reconciliation duty that completes this Part belongs with the transparency machinery and is taken up in Section V.

The staff rules are where the capabilities principle becomes headcount, and they contain the framework’s one deliberate flexibility. Firms may employ only suitably qualified individuals, registered with the applicable professional bodies, in numbers sufficient to discharge the duties effectively (Rules I.J.1 and I.J.2). Staff are not required to be physically located in the Emirate, provided the firm can ensure that all supervisory, monitoring and enforcement functions are effectively implemented “to VARA’s satisfaction” (Rule I.J.2), a discretionary threshold the firm carries the burden of meeting. Read against the officer rules, in which the Compliance Officer and the Responsible Individuals must be UAE residents or passport holders, the design is deliberate: the framework localises the accountable individuals and frees the workforce, an observation from the two rules together rather than a stated policy. The workforce it frees, it still trains: adequate role-suitable training at the start of employment and on an ongoing basis, regular AML training with compliance monitored, operational policies communicated to every new hire within thirty calendar days, and prompt communication and permanent availability of every update (Rules I.J.3 to I.J.7).

So the housing is engineered before the machine runs: principles that reach where rules do not, a system specified for independence and evidence, dealing controls that bind the Board as tightly as the staff, and a workforce that may sit anywhere so long as the named individuals sit here and supervision satisfies the regulator. At the centre of the housing sits the function’s engine, the risk apparatus that decides where all of this effort is pointed, and Section III turns to it.

03 Section III

The risk engine: the taxonomy, the assessment, and the guidance

At the centre of the compliance function sit two engines that firms often conflate, and the rulebook keeps them distinct. The enterprise risk function of Part I.D covers every risk the firm runs, financial, technological or otherwise. The business risk assessment of Part III.D covers financial crime. Both report on a quarterly clock, both are owned above the function that runs them, and since June 2026 the second has a published description of what good looks like. This section takes each engine in turn, then reads the guidance.

The enterprise function is specified by proportion and by ownership. Every VASP must maintain a risk management function, policies and measurement methodologies, each commensurate with its nature, size, complexity and risk profile, to identify, measure, quantify, manage and monitor its risks, followed strictly so that risks are maintained at levels the rule calls acceptable and appropriate, a standard the rulebook does not further define (Compliance and Risk Management Rulebook, Rule I.D.1, current as at 1 July 2026). The head of the function must hold the qualifications and the authority to oversee the firm’s overall exposures, may be the Compliance Officer, and where separate must report directly to the Board (Rule I.D.2). The Board owns the comprehensive review of the risk policies, particularly on any material change in the business, the management, the market or the applicable law (Rule I.D.3), and the head of the function delivers a risk exposure report to the Board identifying all actual or potential risks at least quarterly, more often where a specific identified risk demands it (Rule I.D.4).

What those quarterly reports must contain is set by the taxonomy of Rule I.D.5, and the taxonomy repays reading as a map of the whole framework. Four families of risk must be considered and reported to the extent applicable. Financial stability covers soundness against the capital and prudential requirements, market risk with mitigations the rule itself prescribes, including value-at-risk or equivalent modelling for unspecified adverse movements such as flash crashes and tail events, sensitivity measurement against individual market factors, and quantitative and qualitative stress testing, credit risk with a rating system, objective client and counterparty measures, limits enforced at all times and full margin-policy architecture down to escalation on successive failed calls, and liquidity risk with concentration limits, maturity-mismatch monitoring and default procedures that give management time to act. Market conduct covers business strategy, client onboarding and the depth of due diligence applied, the structure and responsibilities of owners, Board and management, operational failure, the quality of governance and compliance culture, cybersecurity including its reputational dimension, and, notably, the firm’s relationship with its regulators including its recent regulatory history, so the firm must risk-rate its own standing with VARA. Compliance covers financial crime, outsourcing and counterparty dependence including on the firm’s own group and owners, the effectiveness of the risk systems themselves, business continuity, and, in the taxonomy’s most reflexive cell, the compliance function itself, its mandate, structure, staffing, methodology, reporting lines and effectiveness, so the function’s own weakness is an item on the register it maintains. Consumer protection covers promotions, contractual legal risk, disclosure and client assets. Several items are expressly framed as including non-compliance with the other rulebooks, which produces the integration effect this series has met before, stated here as a consequence of the drafting: the taxonomy converts every other rulebook’s failure into a reportable risk item in a quarterly Board document, so a breach elsewhere surfaces here even when no one reports it as a breach.

The financial-crime engine is the business risk assessment, and its specification is tighter. Every VASP must conduct documented AML/CFT business risk assessments designed to understand, identify and assess the money-laundering risks specific to its own business and operations, expressly including the risks of new or existing virtual assets, in particular anonymity-enhanced cryptocurrencies, of technologies, products or services, in particular the methods by which anonymity-enhanced transactions can be conducted, of business and professional practices, of technologies not specific to virtual assets, artificial intelligence and machine learning named, and of other emerging risks (Rules III.D.1 and III.D.2). The clock is the framework’s most demanding: at regular intervals no longer than every three months, and again on any significant change or advancement in any listed area (Rule III.D.3).

Two rules then give the assessment its teeth. The firm must ensure, and be able to demonstrate to VARA on request, that the assessment’s outcomes directly inform both the development of its AML policies, systems and controls and the areas where it prioritises its compliance resources (Rule III.D.4), so the document is connected by rule to the budget and the controls, not filed beside them. And where a firm enables anonymity-enhanced transactions at all, a defined term reaching transactions in ordinary assets that nonetheless defeat tracing or ownership records, not only privacy coins, it owes proportionately enhanced controls, enhanced due diligence on each client using those services verified every six months, and, where the risks cannot be adequately mitigated, the rule’s own conclusion: “such products or services should not be offered” (Rule III.D.5). The client-side twin follows the same pattern: a client risk assessment with prescribed content, the criteria and methodology for categorising each client’s risk, the documentation and courses of action by tier and probability, and comprehensive audit trails, refreshed on the same three-month cycle (Rules III.D.6 to III.D.8).

The guidance published on 12 June 2026, announced on VARA’s own site and drawing directly on VARA’s supervisory observations from its 2026 thematic review of business risk assessments, is expressly illustrative rather than binding, and it describes the assessment in terms the rule’s verbs already imply: a well-constructed assessment is “the foundation of an effective financial crime compliance programme”, thorough, evidence-based, and operationally connected to daily control decisions. Its emphases land on exactly the points where a quarterly document degenerates into a ritual. Each quarterly review should be substantive, incorporating updated operational data, an assessment of external developments, and a review of whether any risk rating has changed since the previous version. Version control is treated as the evidentiary basis for demonstrating that the assessment is a live document. The governance framework should specify escalation triggers for material changes in the risk environment, and the guidance names them: regulatory or national-risk-assessment updates including new FATF jurisdiction listings, adverse supervisory, audit or law-enforcement findings, the sanctions designation of a counterparty VASP or of a virtual asset listed on the platform, and material changes to the programme or its key personnel, including a change of MLRO. It also carries a worked remediation example as strong three-lines-of-defence practice: inspection findings escalated immediately to the Board, a Board-approved remediation plan, an independent third-party audit notified to VARA, and a milestone log appended to the assessment with quarterly updates evidencing completion. Practitioner coverage of the guidance adds that its methodology emphasis extends to quantitative risk scoring, documented aggregation approaches and the ability to trace how individual inputs translate into overall ratings, a characterisation reported at secondary level and consistent with the document’s own framing. One live illustration of the guidance’s trigger list sits on VARA’s own announcements page beside it: a circular of 1 June 2026 publishing the UAE Proliferation Financing National Risk Assessment 2026 with required actions, an instrument this article identifies by existence and date without a loaded reading, and precisely the category of national-risk-assessment update the guidance says should move a firm’s assessment between quarters.

Read together, the rule and the guidance change what the assessment is. The rule supplies the clock, the enumerated risk areas and the duty to demonstrate that outcomes drive policies and resources. The guidance supplies the evidence standard: substantive quarterly versions, controlled and comparable, escalated on defined triggers, with remediation tracked inside the document itself. The combined effect, drawn here as a consequence of the two texts rather than stated in either, is that the business risk assessment is not a report about risk but an audit trail of decisions, the single document through which a firm proves, quarter by quarter, that its compliance spending followed its stated risks. What the engine points at, the clients, the transactions and the diligence applied to them, is the machinery of the next section.

04 Section IV

The client-facing machinery: diligence, monitoring, transmission and screening

The machinery that touches clients runs in four movements: the firm risk-rates and verifies who it deals with, monitors what they do, transmits information alongside what they move, and screens everyone against the sanctions lists. Two numbers organise most of it, AED 3,500 and forty-eight hours, and one definition sets its width.

Diligence fires on five triggers, and the second is the one walk-in business misses. VASPs apply due diligence on a risk-based footing in accordance with the Federal AML-CFT Laws, rate every client using the criteria and methodology of the client risk assessment Section III described, and verify the identity of the client and every ultimate beneficial owner before or during the establishment of the relationship, or before executing any transaction for a client with no relationship at all (Compliance and Risk Management Rulebook, Rules III.E.1 to III.E.3, current as at 1 July 2026). The triggers are: establishing a relationship; carrying out occasional transactions at or above AED 3,500, whether in one transaction or several that appear linked; an instruction to handle a potential suspicious transaction; doubts about the veracity or adequacy of identification already held; and any transaction for a high-risk client as the federal laws characterise one (Rule III.E.4). The AED 3,500 figure is the same floor the federal Executive Regulations set for VASPs, as the companion article “Which federal laws stand behind a VARA licence?” verified, so the two layers meet on one number, an alignment observed here from the two instruments read in their own turns.

What verification collects is itemised, and several items surprise. For an individual: the full name as shown on a valid identification card or travel document with a copy of the original, nationality, address, place of birth, and the name and address of the employer, and where the client is a politically exposed person, approval from both the MLRO and a member of Senior Management before any relationship is established (Rule III.E.6.a). For an entity: its full name and type, its constitutional documents attested by competent authorities within the UAE, a localisation requirement that reaches foreign paperwork, its principal place of business, the names of the individuals in its senior management, and the same dual approval where an ultimate beneficial owner is politically exposed (Rule III.E.6.b). Anyone purporting to act for the client is verified for both authority and identity, the purpose and intended nature of the relationship must be understood, and where the client is itself a business serving others, the firm must understand the ownership and control structure, including the identity of every ultimate beneficial owner, whether the structure includes a decentralised autonomous organisation and, if so, what that DAO is for, and the type, nature and pursuits of the client’s own clientele, with due diligence carried out on that clientele where necessary (Rule III.E.7). That last duty is not an add-on; the rulebook’s own definition of due diligence includes diligence on the clientele of a VASP’s client, so the perimeter of knowing your customer extends, by definition, one layer beyond the customer.

Two rules then set the machinery’s floor and its boundary. Where appropriate diligence cannot be completed, the firm shall not establish or maintain the relationship and shall not execute any transaction for that client (Rule III.E.8), the same hard stop the federal layer imposes, and the diligence may be performed by third parties without the liability moving: a firm relying on others to conduct diligence remains liable for ensuring it is performed to the required standard (Rule III.E.9).

For the high-risk client, the diligence deepens into a seven-part package. Where the client risk assessment assigns a high rating, or the ultimate beneficial owner is politically exposed, the firm must obtain additional identification information on the client and every owner, additional information on the relationship’s intended nature and the reasons for transactions, refresh its records more frequently, identify and verify both the source of funds and the source of wealth, intensify its monitoring and determine which transaction groups need further examination, obtain Senior Management approval to commence the relationship, require the first transaction into the client’s account to come through an account in the customer’s own name at a licensed institution supervised to FATF-equivalent standards, and, for a natural person, verify the current residential address, a post office box not sufficing (Rule III.E.10). Ordinary relationships carry their own continuing duty: transactions audited through the life of the relationship for consistency with the file, including source of funds where necessary, and records kept current, particularly for the high-risk book (Rule III.E.5).

Monitoring is built around a definition whose width is the point. A Suspicious Transaction is any transaction, attempted transaction or funds the firm has reasonable grounds to suspect constitute, in whole or in part, and “regardless of the amount or the timing”, the proceeds of crime, misdemeanour or felony, committed in the Emirate or in another country where it is also a crime, or anything related to or intended for money laundering, terrorist financing or the financing of illegal organisations (Schedule 1). No de minimis, no staleness, and a cross-border reach conditioned only on dual criminality. Against that trigger, firms must run continuous monitoring methods appropriate to their own activities, documented, approved by Senior Management, periodically reviewed, engineered so that no tipping-off occurs and so that every suspicion reaches the MLRO immediately (Rule III.F.1), with indicators of suspicion maintained and updated (Rule III.F.2). The MLRO’s duties then run on clocks: immediate reporting to the UAE Financial Intelligence Unit through the GoAML platform in the form the Unit and VARA require, responses to any further request from the Unit or VARA within forty-eight hours, additional actions within whatever timeframe the request specifies, and, where the MLRO and Compliance Officer are different people, immediate notice to the Compliance Officer provided that notice is not itself tipping-off (Rules III.F.3 and III.F.4). A transaction that has been reported is not released from attention: the firm continues monitoring it, on a near-real-time basis where appropriate (Rule III.F.5). And the report set is wider than the suspicious-transaction report alone; the defined AML-CFT Reports run to suspicious activity, high-risk country transactions and activity, funds freezes and partial name matches, as the Unit requires from time to time (Schedule 1).

The travel rule is the transmission movement, and the rulebook states it as a minimum that the federal layer supplements. Before initiating any transfer of virtual assets exceeding AED 3,500 in equivalent value, the originating firm must obtain and hold required and accurate originator and beneficiary information and make it available to VARA and other authorities on request; before permitting a client access to received assets above the same value, the beneficiary firm must hold the mirror set (Rules III.G.1 to III.G.3). The minimum fields are the originator’s name, account number or wallet address, and residential or business address, and the beneficiary’s name and account or wallet address (Rules III.G.4 and III.G.5), the same minimums the federal Executive Regulations prescribe, as the companion article verified. Around the transmission duty sit five operational obligations that distinguish a real programme from a policy document: risk-based due diligence on every counterparty VASP before the first transaction, refreshed where heightened risk appears (Rule III.G.6); considered handling of non-compliant deposits and withdrawals, of unhosted wallets, and of anonymity-enhanced transactions (Rule III.G.7); demonstration of travel-rule compliance during licensing, including the firm’s plan for counterparties in jurisdictions where the rule is not yet legislation, the sunrise issue by name (Rule III.G.8); guidance taken from the FATF’s interpretive note and, notably, monitoring for any transaction or series of transactions that seeks to circumvent the thresholds, so structuring under AED 3,500 is itself a monitored risk (Rule III.G.9); and reporting on travel-rule compliance whenever VARA requires it (Rule III.G.10).

Screening closes the machinery, and it is specified for speed. Every client and every transaction is screened against the designated-entity lists of the United Nations Security Council frameworks and the Federal AML-CFT Laws, through automated systems that operate in real time and are updated regularly (Rules III.H.1 and III.H.2). A match triggers immediate freezing of the associated assets, virtual assets and money alike, with no withdrawal, transfer or use during the freeze (Rule III.H.3), internal policies that make the freeze immediate and keep records of every freezing action for no less than eight years (Rule III.H.4), and a blocking duty that reaches past the list itself: the firm must block and prohibit not only transactions involving listed parties but any attempt by a client to bypass the frameworks (Rule III.H.5). Everything this machinery generates, the diligence files, the monitoring alerts, the reports, the freezing records, flows into one place: the books, audits and regulatory submissions through which VARA watches the whole system work. Section V turns to that transparency machinery.

05 Section V

The transparency machinery: records, reconciliation, audit and the calendar

Everything the machinery of the earlier sections produces converges here, into the apparatus that keeps it, checks it, audits it and delivers it. The design premise is stated in the Regulations rather than the rulebook: a firm must ensure that VARA is able to determine its financial condition, the safety and soundness of its conduct, its policies and its compliance (Virtual Assets and Related Activities Regulations 2023, Regulation IX.B.2, current as at 1 July 2026). The firm carries the duty of being legible, and the rules in this section are how that duty is engineered.

The record set is enumerated, and its form is prescribed before its content. Books and records are kept in their original form or native file format, including as recorded on distributed ledgers where appropriate, across nine categories: audit trails of every transaction, specified down to amount, date and time, payment instructions, total fees, the names, account or wallet details and country of residence of the clients and, to the extent practicable, of every other entity involved, drawn expressly so the firm can thoroughly investigate any suspicious transaction; client information produced by third parties; records sufficient to prove compliance itself; records organised for convenient audit; a general ledger covering all assets including virtual assets, liabilities, equity, income and expenses; the statements and valuations sent to clients and counterparties; the Board’s minutes; the communications and documents of complaint investigations, error resolutions and any facts suggesting a potential violation; and the conflicts register (Compliance and Risk Management Rulebook, Rule I.F.1). Each is retained for no less than eight years, and indefinitely where it may relate to the national security of the UAE, with copies furnished to VARA in accordance with the framework (Rules I.F.2 and I.F.3). The AML machinery of Section IV carries its own overlay on the same floor: transaction records whether or not on public ledgers, the diligence files and the analysis of client activity, third-party diligence engagements, monitoring records and the reports themselves, all kept no less than eight years (Rule III.I).

The eight-year floor, however, is not the only clock, and the second one is in a different instrument. A VASP remains subject to the Regulations, the Marketing Regulations, the Rules and Directives “for a period of ten (10) years following the date” it is no longer regulated by VARA (Regulation IX.A.3). The two clocks run from different start points, the retention period from the record and the amenability period from the firm’s exit, so a record lawfully destroyed at year eight can, on the face of the two provisions, still be within the reach of an examination the firm remains subject to. The interaction is a reading of the two rules together rather than a stated requirement, and the prudent resolution it points to is alignment: a firm that keys its retention to the longer horizon will never face a demand it can no longer answer, and a firm that keys it to the floor may.

Reconciliation is where the record set is tested against the world. Firms must regularly check all records and reports issued by third parties, banks, other VASPs, and virtual-asset service providers outside the Emirate, and all relevant information recorded on all systems including distributed ledgers, and reconcile them against internal records for the purpose of identifying errors, omissions or misplacement of assets, virtual assets included (Rule I.E.5). Read closely, the rule treats the distributed ledger as one more external record to be reconciled, not as self-verifying truth, a characterisation drawn from where the rule places the ledger in its own list, and the operational consequence is that a firm’s books are its own only after the check, not before.

The audit rules then put an external witness on the whole structure, twice over. Externally, an independent third-party auditor produces the annual report, with the auditor’s identity notified to VARA on appointment, the report promptly available to clients and to VARA on request, the accounts prepared to generally accepted accounting principles, counterparties procured to cooperate, and VARA holding sole and absolute discretion to require an alternative auditor where the original is not adequate to the business’s size, complexity and reputation (Rule I.G.1). One clause in that rule deserves isolation, because it assigns the firm homework on its own auditor: the VASP should understand the steps the auditor takes in “proving the existence and ownership of Virtual Assets” and in testing the reasonableness of their valuation (Rule I.G.1.c). In this sector the audit’s hardest question is whether the assets exist and whose they are, and the rulebook makes understanding that answer the firm’s own obligation, not a matter it may leave inside the engagement letter. Internally, where applicable, an objective audit function independent of operations reports directly to Senior Management, works at least quarterly, informs management of findings and follows matters through to resolution, with written policies defining how the two audit functions relate (Rule I.G.2). The remediation example VARA’s guidance held up as strong practice, met in Section III, is this architecture working as designed.

The reporting calendar is the machinery’s output schedule, and its standouts reward attention. Monthly, the firm delivers its balance sheet with all off-balance-sheet items, profit and loss, income and cashflow statements, the addresses of its VA wallets, a full list of group entities actively investing their own or the group’s portfolio in virtual assets together with a complete record of all transactions with them, loans included, and its related-party transactions (Rule I.H.1). The wallet-address item is the one with no analogue in conventional supervision: it hands the regulator standing on-chain visibility of the firm’s holdings, a consequence of the rule rather than a stated purpose, and it means the monthly submission is verifiable against the ledger itself. Quarterly, the firm delivers the minutes of every Board and committee meeting, so the record the companion article “Who is personally accountable when a VASP breaks the rules?” made decisive does not stay inside the building, a statement demonstrating compliance with its financial requirements including Reserve Assets, its projections and strategic plans, and the risk exposure report of Section III (Rule I.H.2). Annually, it delivers the audited statements with the auditor’s opinion and an attestation on the effectiveness of internal controls, Senior Management’s own assessment of the year’s compliance, a certification of the statements’ truth and correctness signed by a member of the Board or a Responsible Individual, personal attestations whose weight that companion article set out, a representative onboarding sample that must include the actual documentation of the first one hundred clients onboarded that year, product descriptions, the group chart with shareholding and every ultimate beneficial owner, the biographies and outside positions of the Board and Senior Management, any independent directors, and the committees, their mandates, their year’s activities, their meeting counts and their attendees (Rule I.H.3). The first-hundred-clients item quietly disciplines the calendar: the year’s opening onboarding is always the following year’s inspection material, so January’s diligence is examined in arrears, every year, by rule. And above the whole schedule sits VARA’s power to require more, on request, at any time (Rule I.H.4).

So the transparency machinery closes the loop the earlier sections opened: what the diligence and monitoring generate is kept in native form on an eight-year floor beneath a ten-year shadow, tested against the ledger and the banks, witnessed by two audit functions, and delivered to the regulator on a calendar that runs from monthly wallet addresses to the annual certification a named individual signs. One category of output remains, the hardest one, because it is the firm speaking against its own interest: the reports a VASP must make about its own failures. Section VI turns to the self-reporting duties, and to the anti-bribery regime whose investigations feed them.

06 Section VI

The self-reporting duties: the firm as its own first supervisor

The hardest outputs the compliance function produces are the ones made against the firm’s own interest, and the rulebook requires three kinds: the firm’s report of its own breaches, its notice of its principals’ legal troubles, and the findings of its own bribery investigations. Behind all three stands the seventh principle of Section II, open and transparent dealings with regulators at all times; these rules are that principle converted into deadlines.

The breach self-report is drawn to maximum width. A VASP must submit a report to VARA immediately upon the discovery of “any violation or breach of any law, Regulation, Rule or Directive” related to the conduct of any VA activity (Compliance and Risk Management Rulebook, Rule I.I.2, current as at 1 July 2026). Each word carries load: any violation, so there is no materiality filter; any law, so the duty is not confined to VARA’s own instruments and reaches the federal layer this series has mapped; and immediately upon discovery, so the clock runs from the moment the firm knows, not from the moment it finishes assessing.

That width sits beside a second, narrower channel, and reading the two together shows the design. The Compliance Officer is independently responsible for notifying VARA and other relevant authorities of any material non-compliance by the VASP, its Board or its Staff with applicable legal and regulatory requirements (Rule I.B.2). The two triggers differ in reporter, threshold and scope: the firm reports every breach connected to a VA activity, while the officer reports material non-compliance across the whole of the firm’s obligations, expressly including non-compliance by the Board itself. How they fit is a reading of the two rules rather than a stated scheme, but the architecture it suggests is deliberate: a material breach travels to VARA twice, once from the firm and once from the officer, and the officer’s channel exists precisely for the case in which the firm’s own report does not come.

The principals’ notification reaches earlier in time than firms expect. VARA must be notified in writing of any changes to the items in the annual report of Section V, and, immediately after commencement, of any criminal or material civil action, charge or proceedings or insolvency proceedings, or any investigation, inspection or enquiry which may lead to any such action, made against the VASP or any of its Board members, ultimate beneficial owners or Senior Management (Rule I.I.1). The operative words are the ones that move the trigger forward: an enquiry that may lead to proceedings is reportable when it commences, so the duty fires at the investigation stage, before any charge exists, and it covers the people as well as the firm, wherever the matter arises. Around it sit two routing rules: on request, the firm discloses its activities in other jurisdictions (Rule I.I.3), and cyber incidents, including any loss of information or anything affecting personal data, are notified under the Technology and Information Rulebook’s own regime (Rule I.I.4).

The anti-bribery Part is conduct regulation and reporting machinery in one, and its prohibitions are wider than the classic bribe. It is prohibited for the firm, any Board member or any staff member to give, promise or offer a payment, gift or hospitality expecting or rewarding a business advantage; to give, promise or offer anything to facilitate or expedite a routine procedure, the facilitation payment named as such; to accept a payment, gift or hospitality known or suspected to carry an expectation of advantage in return; to threaten or retaliate against a Board member or staff member who refused to commit a bribery offence or who raised concerns, so retaliation is itself a prohibited act; and to engage in anything that might lead to a breach of the Part (Rule VI.A.3). The corrupt-payments bar reaches beyond the firm’s own people to its group companies, agents, business partners, contractors and suppliers, and it triggers on any reason to believe that all or part of a payment will go toward a bribe, with every payment required to be appropriate and justifiable for legitimate services (Rule VI.B). The approach is stated as zero tolerance (Rule VI.A.2), the one carve-out is normal and appropriate hospitality under the firm’s own gifts policy, which must say clearly what may and may not be given or received (Rule VI.A.4), and the posture is not private: the zero-tolerance approach and the relevant policies must be disclosed to the public and communicated at the outset of business relationships (Rule VI.D.4).

What makes the Part belong in this section is its machinery, which is a self-reporting engine by construction. The firm must establish and publish methods of contact, including a telephone line, for receiving reports of violations, must accept reports from entities outside the firm, and must protect the reporter’s identity and confidentiality at all times (Rules VI.A.1 and VI.C.1), an external whistleblowing channel prescribed by rule. Every Board member and staff member must report belief or suspicion to the Compliance Officer as soon as possible (Rule VI.C.2). The investigation that follows is proceduralised: a file is opened, an oral report is reduced to writing, the Compliance Officer appoints an independent entity to conduct the investigation, the Board is advised that an investigation exists, the facts, entities, times and dates are documented, a written investigation report is delivered, and where unlawful conduct is found, the Board sets the remedial action and the investigating entity records it, with the report and the remediation summary retained by the Compliance Officer for no less than eight years from completion and available to VARA on request (Rule VI.C.3). The Board owns the policy’s currency across every jurisdiction of operation; the Compliance Officer carries its day-to-day implementation and monitors its effectiveness (Rules VI.E and VI.A.5). Breach carries severe internal consequences including termination without notice (Rule VI.F.1), and the Part closes with the duty that connects it to everything above: the firm should immediately report to VARA any finding of unlawful conduct in breach of these rules (Rule VI.F.2). An investigation that finds unlawfulness does not end in the file. It ends at the regulator’s door.

Taken together, the self-reporting duties complete the system this article has described: a firm that reports its breaches on discovery, its principals’ enquiries on commencement, and its corruption findings on completion is a firm supervising itself in real time, with VARA’s continuous visibility from Section V making silence impractical and the personal accountability of the companion article “Who is personally accountable when a VASP breaks the rules?” making it dangerous. What remains is to draw the whole machine together, what is settled, what is open, and what must be watched, and Section VII closes there.

07 Section VII

What is settled, and what remains open

Nearly all of this machine is settled, and settled coherently. The rulebook binds by default, with Guidance the labelled exception, and beneath the rules sits a principles floor that binds in spirit and reaches conduct no specific rule names (Section II). The system itself is engineered for independence and evidence, its workforce free to sit anywhere while its accountable individuals sit here (Section II). Two engines drive it: an enterprise taxonomy that converts every other rulebook’s failure into a quarterly Board item and puts the compliance function itself on its own register, and a business risk assessment on a three-month clock whose outcomes must demonstrably drive policies and spending, now with published guidance describing what good looks like (Section III). The client machinery runs on two numbers and one wide definition: diligence and transmission duties keyed to AED 3,500, response duties keyed to forty-eight hours, and a suspicious-transaction trigger with no floor, no staleness and cross-border reach (Section IV). The transparency machinery keeps everything in native form on an eight-year floor, reconciles the ledger like any other external record, audits it twice, and delivers it on a calendar that runs from monthly wallet addresses to an annual certification signed by name (Section V). And the self-reporting duties make the firm its own first supervisor, reporting breaches on discovery, principals’ enquiries on commencement, and corruption findings on completion (Section VI).

What remains open sits, as in the companion pieces, at the points where the framework keeps its own discretion, plus one interaction of this article’s own finding. The standards left to judgment are real: risks held at acceptable and appropriate levels, non-compliance that is material, supervision of remote staff effective to VARA’s satisfaction, each a threshold the rulebook names without defining, so a firm operating near any of them is operating inside VARA’s judgment rather than a published line. The two-clock interaction between the eight-year retention floor and the ten-year post-exit amenability is a reading of two instruments rather than a stated rule, prudently resolved by aligning retention to the longer horizon, but not yet resolved by any authority. The guidance layer is open by design, illustrative, weeks old at this article’s date, with the supervisory posture it signals due to show in inspections before it shows in instruments. And one identified instrument awaits a loaded reading before any reliance: the circular of 1 June 2026 publishing the UAE Proliferation Financing National Risk Assessment 2026 with required actions, named here by existence and date only.

If the question in the title has a single answer, it is this: the function’s product is proof. Every rule this article has worked through converges on evidence of the machine’s own working, the version-controlled assessment that shows risk driving spend, the reconciliations that show the books tested against the world, the minutes that leave the building quarterly, the certification a named individual signs, the reports the firm makes against itself. A function that generates activity without generating that evidence has, on this rulebook’s terms, produced nothing, because every duty here is drafted to be demonstrated, on request, from the record.

This analysis rests on the Compliance and Risk Management Rulebook in the version effective 19 June 2025 on VARA’s live rulebook, read with the Virtual Assets and Related Activities Regulations 2023 for the examination and post-exit provisions, and on VARA’s AML/CFT Business Risk Assessment Guidance, published 12 June 2026 and non-binding, with the federal counterparts of the diligence thresholds, the travel rule and the hard stop verified in the companion article “Which federal laws stand behind a VARA licence?”. Each is live. A new version of the rulebook, a further thematic review or change to the guidance, a loaded reading of the proliferation-financing circular, or movement in the 2025 federal instruments would each be a reason to read this analysis again against the source.

This is our published view

For your facts, in confidence, put the question to the firm.

makkikairisbabikerhowdariziayuki The bench stands behind it
Put it to a partner