Custodial wallet / SaaS in United Arab Emirates
Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).
Custodial SaaS is conditionally permitted in United Arab Emirates with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- All licensed VASPs (including custodians) must comply with federal AML-CFT laws (Federal Decree-Law No. 26 of 2021) — applies to VA transfers including custodial wallet services.
- Travel Rule compliance required: VASPs must collect/share originator and beneficiary info for VA transfers per FATF Recommendation 15 & 16; enforced by VARA (Rule III.G) and ADGM/FSRA.
- Federal/VARA benchmark threshold for Travel Rule: AED 3,500 (~$950 USD); ADGM has effectively no threshold (zero-threshold regime).
- CBUAE is the goAML reporting authority; post-FATF grey-list exit (Feb 2024), CBUAE escalated AML fines targeting crypto-linked sectors.
- All VASPs must implement transaction monitoring to detect threshold circumvention and evasion.
- Sanctions screening: OFAC SDN designations applicable in the UAE must be complied with.
- VARA's licensing rules include evolving AML/CFT/sanctions requirements per the Virtual Assets and Related Activities Regulations 2023.
- Penalties for money laundering via crypto: up to AED 50 million fines, license revocation, or 10 years imprisonment.
Key Restrictions
- Custody requires a separate, specific custody license from the relevant regulator (VARA: AED 5M minimum capital; ADGM: $500K–$1M+ case-by-case).
- Operator must be licensed in the applicable free zone or federal regime — Dubai (VARA), ADGM (FSRA), DIFC (DFSA — investment/security tokens only), or federally (SCA).
- Client asset segregation and protection standards apply under enhanced custody requirements.
- Privacy tokens (e.g., Monero) prohibited under DIFC/DFSA rules (effective Jan 2026); federal law (Decision No. 4/R.M/2026) bans privacy and algorithmic tokens.
- White-label client (the SaaS customer) may itself need a VASP license if it provides virtual asset services to end users — responsibility split must be contractually and operationally defined.
- Strengthened governance and disclosure requirements under DIFC framework for crypto-related activities.
Key Risks
- Unlicensed custody activity is a criminal offence: penalties up to 5 years imprisonment and AED 250,000–1M fines; unlicensed financial activity fines up to AED 500 million.
- Regulatory fragmentation across Dubai (VARA), ADGM (FSRA), DIFC (DFSA), and federal (SCA) creates jurisdictional ambiguity for SaaS operators serving clients across multiple emirates.
- Post-FATF grey-list exit, CBUAE enforcement is escalating — hundreds of millions AED in fines in 2024–2025 targeting crypto-linked high-risk sectors.
- Privacy/algorithmic token prohibitions (federal and DIFC-level) may restrict supported assets for custody platforms.
- Administrative fines under the New CBUAE Law can reach AED 1 billion for non-compliance.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
VARA — Dubai virtual asset regulation (excluding DIFC) — 7 activity categories. World's first standalone VA regulator.
ADGM FSRA — Abu Dhabi Global Market — institutional focus, common law jurisdiction, ex-FCA/MAS staff
DFSA — DIFC — investment/security tokens only, updated framework Jan 2026
SCA — Federal authority — virtual asset supervision across UAE including Free Zones (Cabinet Resolution 111/2022)
VARA Regulations (Dubai Law No. 4 of 2022) (2023) — 7-category VASP licensing: advisory, broker-dealer, custody, exchange, lending, transfer, VA management
ADGM FSMR / Virtual Asset Framework (2018) — Financial services permission for crypto asset business — amended 2023
SCA Decision No. 4/R.M/2026 (2026) — Federal crypto law update — 8 licensed activities, prohibitions on privacy/algorithmic tokens
VASP: VARA (Dubai): 7 categories. Exchange: AED 15M (~$4.1M). Broker-Dealer/Custody/Transfer: AED 5M each. Advisory: AED 1M. MVP phase before full license. 3-9 months. ADGM (Abu Dhabi): Exchange $2M+ base capital, Custody $500K-$1M+. Federal SCA: AED 500K-4M depending on activity.
CUSTODY: Separate custody authorization required. VARA: AED 5M. ADGM: $500K-$1M+ (FSRA case-by-case). Client money rules apply.
Enhanced custody requirements for regulated firms handling crypto tokens
Client asset segregation and protection standards
Strengthened governance and disclosure requirements for crypto-related activities within the DIFC
Federal Decree-Law No. 26 of 2021 is the current and operative AML/CFT law in the UAE, superseding Federal Decree No. 20/2018.
Federal and free zone implementation: UAE is listed among jurisdictions that have implemented the Travel Rule, aligning with FATF Recommendation 15 and 16. VARA Rule III.G requires VASPs to comply with all federal AML-CFT laws, including Travel Rule, guided by FATF Interpretive Note to Recommendation 15, and to monitor for threshold circumvention.
Key regulatory updates: FSRA revised its AML and Sanctions Rules and Guidance to clarify Travel Rule application to VAs in wire transfer provisions; VARA enforces it as a minimum standard potentially supplemented by federal rules.
Federal/ VARA benchmark: AED 3,500 (approximately $950 USD), mirroring federal AML rules; VARA aligns with this while monitoring for evasion.
ADGM variation: Effectively no threshold (zero-threshold regime).
All licensed VASPs: Applies to Virtual Asset Service Providers handling VA transfers, including exchanges and custodians, requiring sender/recipient identification and counterparty checks under federal AML-CFT laws.
Scope: Full responsibility on VASPs for FATF-aligned compliance, beyond standard AML; enforced in licensing regimes like VARA and ADGM.
Data sharing and controls: VASPs must collect/share originator and beneficiary info (per FATF standards), implement policies guided by FATF Interpretive Note to Recommendation 15, and detect threshold circumvention via transaction monitoring.
Post-FATF grey list exit (Feb 2024), CBUAE escalated fines totaling hundreds of millions AED in 2024–2025, targeting crypto-linked high-risk sectors like exchange houses.
General penalties for unlicensed crypto activities include up to 5 years imprisonment and AED 250,000–1 million fines; money laundering via crypto carries up to AED 50 million fines, license revocation, or 10 years imprisonment.
Regulatory bans (not enforcement actions): DFSA prohibited privacy tokens (e.g., Monero) in Jan 2026; federal law (Feb 2026) bans privacy/algorithmic tokens with fines up to AED 50,000 and 3 months imprisonment.
Engaging in Licensed Financial Activities without a licence is a criminal offence, punishable by imprisonment and/or fines from AED 50,000 to AED 500 million under the UAE Central Bank's consolidated 2023/2025 regulatory framework.
Maximum administrative fines increased to AED 1 billion under the New CBUAE Law, with higher sanctions for unlicensed activity and authorised individuals.White & Case
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — custodial wallet/SaaS providers may operate in the UAE but must obtain a specific custody license from the applicable regulator (VARA, ADGM/FSRA, or federal SCA), meet minimum capital requirements (AED 5M under VARA / $500K–$1M+ under ADGM), comply with client asset segregation rules, and adhere to UAE AML/CFT obligations including Travel Rule compliance with thresholds varying by free zone, while facing significant enforcement risk from escalating CBUAE penalties.
Questions this verdict aims to answer
- What custody license / qualified-custodian status applies?
- What segregation, insurance, and proof-of-reserves rules apply?
- What AML obligations attach to the SaaS vs the white-label client?