Important: This article presents an independent analysis and does not represent the official position of the Virtual Assets Regulatory Authority (VARA) or any other regulatory authority of the United Arab Emirates. The content herein does not constitute legal advice and is exclusively informative in nature, intended for entrepreneurs, executives, legal professionals, and virtual asset specialists seeking to understand how the UAE Travel Rule applies to the structuring, governance, and operation of virtual asset service providers that operate or intend to operate in the Dubai market.
On 24 February 2026, the Virtual Assets Regulatory Authority (VARA) issued a Circular directed to all Virtual Asset Service Providers (VASPs) licensed or authorised in Dubai, setting out guidelines regarding the implementation of the UAE Virtual Asset Travel Rule.
Established by Cabinet Decision No. 134 of 2025, which sets out the Implementing Regulation of Federal Decree-Law No. 10 of 2025 on combating money laundering, the financing of terrorism, and the financing of the proliferation of weapons, the Travel Rule represents a significant milestone in the evolution of the virtual assets regulatory framework of the United Arab Emirates, with direct and immediate operational implications for all service providers operating in this ecosystem.
The Travel Rule establishes mandatory obligations for the collection, verification, secure transmission, monitoring, and retention of information relating to the originator and beneficiary of a transaction in connection with qualifying virtual asset transfers. Its scope of application is territorial and comprehensive, encompassing all VASPs operating in the UAE, including all Free Zones and Financial Free Zones.
It is important to note that transaction fees, or gas fees, fall outside the scope of application of the Travel Rule, and no information is required to be provided in relation to them.
For the purposes of applying the rule, the concept of “executing” a virtual asset transfer is interpreted broadly, comprising not only the initiation and completion of the transfer, but also its facilitation, enablement, or any material contribution to its execution.
With regard to mandatory information, the Travel Rule requires that, before executing any qualifying transfer, the originator’s VASP must collect, verify, and securely transmit a specific set of data that must accompany the transfer, such as the full legal name, account or wallet identifier, and at least one verified contact detail, which may be a residential address, national identity document number, or date and place of birth. With respect to the beneficiary, the full legal name and wallet or account identifier are required.
The requirement is not, however, absolute and may be subject to exceptions depending on the volume transacted. By way of example, for transfers with a daily aggregated amount equal to or exceeding AED 3,500, beneficiary identity verification is mandatory where it has not been previously carried out. On the other hand, for transfers below that amount, although originator and beneficiary information must still accompany the transaction, identity verification may be dispensed with, unless there is suspicion of criminal activity or the presence of other heightened risk indicators.
The Travel Rule entered into force in accordance with the commencement provisions set out in Cabinet Decision No. 134 of 2025, published in Official Gazette No. 811 on 15 November 2025, with effect from 14 December 2025. The VARA Circular stipulates that all VASPs must be in full compliance from the applicable effective date, with no additional adaptation period granted following the publication of the Circular.
With regard to companies that do not yet hold a licence and intend to obtain one from VARA, compliance with the Travel Rule is treated as a prior licensing requirement and not as an obligation to be met after the licence has been granted.
Accordingly, applicants must demonstrate, at the time of submitting their authorisation request, how they intend to comply with the Travel Rule requirements, including the policies, procedures, and technological solutions to be adopted, as well as their approach to addressing the so-called “sunrise issue”, that is, the fact that not all VASPs in foreign jurisdictions are subject to equivalent obligations, which requires VASPs in Dubai to establish clear procedures for situations in which a counterparty is unable to receive or transmit the required information in a cross-border transaction.
Although the Travel Rule applies to all activities licensed by VARA, including but not limited to exchanges, custodians, broker-dealers, investment managers, lending platforms, and transfer and settlement services, the specific content of the obligations may vary according to the nature of the activity carried out and the associated risk profile. This is because VARA assesses whether each VASP’s Travel Rule controls are proportionate and adequate to the type, volume, and complexity of the transfers conducted within the scope of its licence and the activities performed.
For VASPs acting as intermediary providers, the obligations are additionally demanding, as these providers must confirm and verify the regulatory status of both VASPs, the originator and the beneficiary, transmit all required information throughout the entire transfer chain or retain it where technical limitations apply, identify and address transfers with missing information, and maintain complete records and logs of all transfers, including rejected or failed attempts.
From the perspective of internal policies that need to be reviewed and updated, VASPs must assess the impact of the Travel Rule on their overall AML/CFT policy framework, with particular attention to five areas:
- The procedures for the collection, verification, and secure transmission of originator and beneficiary information;
- Counterparty due diligence policies, which must include verification of the regulatory status of each counterparty VASP prior to executing any transfer;
- Exception handling procedures, clearly defining the criteria for rejecting, delaying, permitting, or returning transfers with missing or incomplete information;
- Policies for unhosted wallets, which must provide for the application of enhanced due diligence, including additional customer identification and source of funds verification; and
- Record retention policies, given that VASPs must maintain AML/CFT-related records for a minimum period of eight years, in accordance with VARA’s Rulebooks.
Additionally, VASPs must ensure that their Travel Rule controls are aligned with the applicable VARA Rulebooks and that relevant personnel receive appropriate training on the requirements of the rule.
With regard to information reporting and communication with the authorities, VASPs must observe two main channels. The first is the goAML portal, the official platform of the UAE Financial Intelligence Unit (“FIU”) for the submission of Suspicious Transaction Reports (“STRs”), which must be filed in near real time whenever the applicable legal threshold is met. VARA requires VASPs to maintain continuous monitoring systems and escalation chains that enable compliance with this requirement without delay. The second channel is the IEMS (Integrated Enquiry Management System), a system introduced by the FIU for direct communication between regulatory authorities, law enforcement, and VASPs, through which official guidelines and requests are sent directly to regulated entities. VASPs must remain registered and operational on IEMS, with the Money Laundering Reporting Officer (“MLRO”) and Compliance Officers duly registered, and must respond to any request from VARA or the FIU within a maximum period of 48 hours.
The consequences of non-compliance with the Travel Rule are serious in nature and may fall upon both the legal entity and its managers individually. At the administrative level, VARA is authorised to impose sanctions including fines ranging from AED 10,000 to AED 5 million per violation, operational restrictions, licence suspension and revocation, as well as the removal of senior management members.
At the criminal level, Federal Decree-Law No. 10 of 2025 — the UAE’s new AML law, in force since October 2025 — substantially expanded the penalty regime. Legal entities are subject to fines ranging from AED 5 million to AED 100 million, depending on the severity and extent of the violations, while individuals may be sentenced to imprisonment for up to 10 years.
A particularly significant aspect introduced by the new legal framework is the possibility of personal liability for managers, given that non-compliance with AML/CFT obligations, including those arising from the Travel Rule, may fall directly upon directors, MLROs, and other responsible individuals, independently of any penalty imposed on the legal entity.
In light of all of the foregoing, the implementation of the Travel Rule is not merely the emergence of a new compliance obligation, but a structural transformation in the way VASPs must conceive and operate their virtual asset transfer infrastructures.
For already licensed companies, all necessary updates must be implemented without delay, proportionate to the nature, scale, and risk profile of their activities.
For companies and entrepreneurs considering obtaining a licence from VARA, understanding and internalising these requirements from the structuring phase is indispensable for building a sustainable operation aligned with the regulatory framework of the United Arab Emirates, one of the most advanced and stringent in the world.
Having your business properly structured and in full compliance with UAE regulations means having the solidity to operate and compete at the highest level in virtually any virtual asset market globally.
Should you wish to explore in greater depth how the Travel Rule may impact your firm’s structure, operations, systems, or licensing strategy, our team remains available to discuss these matters and assist in developing practices consistent with VARA’s expectations and with the regulatory environment of the United Arab Emirates.
Contact Details
Email: admin@bankslegal.com
WhatsApp: +971 55 655 2447