A business that issues, converts or custodies payment tokens for use within the United Arab Emirates generally needs either a full CBUAE payment token licence, available only to UAE-incorporated entities, or a registration as a foreign payment token issuer, custodian or transferor. The route a business sits in determines its reserve, capital, AML/CFT and technology obligations. Full licensing carries the heaviest prudential load; registration carries narrower permissions and tighter customer restrictions.
Regulatory mandate and statutory basis
The Central Bank of the UAE regulates payment token activity through the Payment Token Services Regulation, a rulebook that sits within the CBUAE's broader statutory remit over payment systems and stored value. Industry commentary on the regime explains that it establishes licensing and registration conditions specifically for the issuance, conversion and custody or transfer of payment tokens, alongside a requirement that licensees maintain a reserve of assets against each token category they issue.
The rulebook's territorial reach covers payment token activity directed at UAE residents and businesses, regardless of where the issuing entity sits, which is why foreign platforms serving UAE customers cannot simply rely on an offshore licence and ignore the CBUAE's remit. The regulation sits alongside, rather than instead of, other UAE regulatory frameworks. An entity operating from a financial free zone may still need to coordinate with the Dubai Financial Services Authority or the Financial Services Regulatory Authority in Abu Dhabi Global Market, depending on where it is incorporated and which activities it conducts, while VARA retains its own remit over broader virtual asset services in Dubai outside the financial free zones. A payment token business that also runs exchange or broker-dealer activity may need parallel authorisation from more than one regulator.
The Payment Token Services Regulation does not operate in isolation from the UAE's wider financial crime framework either. Federal AML Law, specifically Decree-Law No. 20 of 2018 and its subsequent amendments, supplies the underlying AML/CFT obligations that the CBUAE then applies to payment token issuers, custodians and transferors through its own circulars and supervisory expectations. CBUAE Circular 2/2024 and Circular 15/2021 provide further operational detail that supervised entities are expected to fold into their compliance programmes. For a founder or general counsel mapping out an application, the practical takeaway is that the rulebook cannot be read as a standalone instrument: it sits inside a layered structure of federal law, central bank circulars and, in many cases, overlapping free zone or VARA requirements that must be reconciled before any application is filed.
Definitions and licensable activities under the rulebook
A payment token, in CBUAE terms, is a type of crypto token designed to function as a means of payment and typically pegged to a fiat currency or a basket of assets, which brings most fiat-referenced stablecoins used for payment purposes squarely within scope when they are issued, converted or transferred for use inside the UAE. The regulation does not concern itself with purely speculative tokens that have no payment function, nor with tokens used exclusively as investment instruments elsewhere in the virtual asset ecosystem.
The rulebook organises licensable conduct into three broad categories of payment token service:
- Issuance, meaning the creation and offering of a payment token backed by a reserve of assets, typically the model used by stablecoin issuers targeting UAE users.
- Conversion, meaning the exchange of payment tokens for fiat currency or other payment tokens, a function common to on-ramp and off-ramp providers.
- Custody and transfer, meaning the safekeeping of payment tokens on behalf of customers and the movement of those tokens between wallets or accounts, a function typically performed by custodians, wallet providers and payment processors.
Borderline cases arise frequently in practice. A platform that only facilitates peer-to-peer transfers without holding tokens on its own balance sheet may still fall within the transfer limb of the regulation if it exercises any control over customer tokens during the transaction. A business that converts payment tokens incidentally, as part of a broader e-commerce settlement flow, is still likely to be captured if UAE customers are on either side of that conversion. Our overview of regulated activities under the CBUAE framework sets out how the regulator tends to characterise these grey-area models, which is often the point where founders discover they need authorisation they had not planned for.
Full licence or foreign registration: choosing the right route
Eligibility under the rulebook splits cleanly along one line: UAE incorporation. Industry analysis of the regime confirms that only entities incorporated in the UAE may apply for the full payment token licence, while foreign entities are instead channelled toward registration or no-objection routes that come with narrower permissions. That single incorporation requirement has outsized practical consequences, since it forces many issuers to resolve UAE entity formation and local banking access well before they can even submit a substantive application.
The three main pathways are:
- Licensed payment token issuer (UAE-incorporated). This route permits the full range of issuance, conversion and custody/transfer activity, subject to reserve, capital and governance conditions. It is the only route under which a business can issue AED-denominated payment tokens for circulation among UAE residents, and it typically caps or restricts foreign-currency-denominated issuance to protect monetary sovereignty.
- Registered foreign payment token issuer, custodian or transferor. This route is open to entities incorporated outside the UAE that want to serve UAE customers without local incorporation. It generally restricts the entity to a narrower customer scope, imposes stricter operational limits, and requires extensive documentation proving the home regulator's oversight, the adequacy of reserve arrangements, and the entity's AML/CFT programme.
- Dual authorisation. An organisation that combines payment token issuance with broader virtual asset exchange or broker-dealer activity in Dubai may need both a CBUAE authorisation for the payment token limb and a separate VARA licence for the exchange or custody limb, since the two regulators' remits are not mutually exclusive.
Coordination between CBUAE and VARA becomes unavoidable whenever a business model spans both payment tokens and other virtual asset services, such as running an exchange that also issues its own stablecoin. In those cases, the application strategy has to sequence the two processes deliberately, since each regulator will expect visibility into the other's conditions before granting its own approval. Our CBUAE payment token licensing overview walks through how the two regimes interact article by article.
Reserve, capital and prudential modelling requirements
Prudential soundness sits at the centre of the CBUAE's licensing test, and it starts with the reserve of assets. The regulation requires licensees to hold a reserve of assets matched to each category of payment token they issue, a structural safeguard intended to ensure that every token in circulation is backed by assets of comparable value and liquidity. Reserve composition, custody arrangements and reporting frequency all need to be documented in detail before an application is considered complete, and the reserve itself must typically be segregated from the issuer's own operating funds.
Minimum capital expectations run alongside the reserve requirement rather than replacing it. A licensed issuer has to demonstrate it holds sufficient paid-up capital to absorb operational losses independently of the reserve backing its tokens, since the reserve exists to protect token holders, not to cover the firm's own solvency. Boards should expect the regulator to test capital adequacy against realistic stress scenarios rather than a static balance sheet figure.
Prudential modelling is where many applications stall. The CBUAE expects a licensee to produce stress-test scenarios that model redemption shocks, reserve asset impairment, and liquidity timing mismatches between token redemption requests and the maturity profile of reserve holdings. A well-built model should show how the firm would meet a surge in redemptions within its stated settlement window without forced asset sales that would erode reserve value. Liquidity planning has to sit on top of that modelling, setting out contingency funding lines or committed facilities that could be drawn if reserve liquidity falls short during a stress event.
None of this is a one-time exercise. Licensees face ongoing reporting obligations, typically including periodic reserve attestations from an independent auditor, management reporting on capital adequacy, and disclosure of any material change in reserve composition or custody arrangement. A firm that treats these as annual compliance tasks rather than continuous monitoring disciplines is likely to find its supervisory relationship deteriorating quickly.
Governance, board accountability and control functions
Board-level accountability is not a formality under this regime: it is the mechanism the CBUAE relies on to supervise a licensee between examinations. Directors and senior management are subject to fitness and propriety assessment before authorisation, and the board carries ongoing responsibility for the adequacy of the firm's risk management, prudential position and compliance culture, not merely for setting strategy.
Three control functions are treated as non-negotiable building blocks of a licensable governance structure:
- A compliance function with the authority and resourcing to challenge the business on AML/CFT and conduct matters, reporting independently to the board.
- An AML/CFT function, which may sit within or alongside compliance, responsible for transaction monitoring, sanctions screening and suspicious activity reporting.
- An internal audit function, independent of day-to-day management, tasked with testing the effectiveness of controls across reserve management, custody and AML/CFT.
Segregation of client funds is a related but distinct obligation. Reserve assets backing issued tokens, and any customer funds held incidentally through custody or transfer services, must be kept separate from the firm's own operating accounts and disclosed clearly to customers and to the regulator. A firm that commingles reserve assets with working capital, even temporarily, is likely to face immediate supervisory concern regardless of its stated intentions.
Pro Tip: Map each control function to a named individual with a documented reporting line before filing, since the CBUAE routinely tests governance structures by asking who specifically is accountable for a given control, not just which policy covers it.
AML/CFT obligations and the travel rule in practice
AML/CFT compliance for payment token activity rests on Federal AML Law, specifically Decree-Law No. 20 of 2018 and its amendments, which the CBUAE then layers with activity-specific expectations for transaction monitoring, customer due diligence and ongoing KYC refresh cycles. A licensee's monitoring systems need to be calibrated to the actual risk profile of payment token flows, which often move faster and across more jurisdictions than traditional payment rails, rather than relying on thresholds borrowed from conventional banking.
Sanctions screening has to run in real time against the UAE and relevant international sanctions lists, with enhanced due diligence triggered for higher-risk counterparties, politically exposed persons and cross-border transfers originating from jurisdictions with weaker AML regimes. Record-keeping timelines follow the general standard applied across the UAE's AML framework, meaning transaction and customer records need to be retained and readily retrievable for examination well beyond the life of the underlying relationship.
The travel rule adds a distinct operational layer on top of standard AML/CFT monitoring. Licensees transferring payment tokens above the applicable threshold must capture and transmit originator and beneficiary information alongside the transaction itself, which is straightforward between two licensed UAE entities but becomes considerably harder when the counterparty platform sits in a jurisdiction with no equivalent messaging standard. Firms need to build sunrise-issue protocols, meaning a documented approach for handling transfers to or from counterparties that cannot yet exchange travel rule data, and decide in advance whether to hold, reject or flag such transfers for manual review. Custody architecture also has to accommodate travel rule capture at the point of transfer, not as a bolt-on after the fact, since retrofitting messaging compliance into an existing custody stack is one of the more expensive mistakes firms make post-launch.
Technology, key management and custody controls
Custody architecture is one of the areas regulators scrutinise most closely, because it is where operational failure translates directly into customer loss. The CBUAE expects licensees to run either a captive custody model, where the firm itself holds the cryptographic keys securing reserve assets and customer tokens, or a third-party custody arrangement with a provider that can itself evidence robust key management and segregation practices. Whichever model is chosen, reserve assets backing issued tokens must be held separately from any tokens custodied for third parties, and that separation has to be demonstrable through account structure, not just policy wording.
Key management expectations tend to follow established industry practice rather than inventing a UAE-specific standard: multisignature wallet structures for high-value holdings, hardware security modules or equivalent protections for private key storage, strict role-based access controls governing who can initiate or authorise a transaction, and comprehensive logging of every key-related action. Applicants should expect the regulator to ask for architecture diagrams showing exactly where keys are generated, stored and used, alongside evidence of who holds signing authority and under what approval workflow.

Incident reporting obligations sit alongside these technical controls. A licensee needs a documented process for notifying the CBUAE of security incidents within a defined window, covering anything from a attempted intrusion to an actual loss of customer assets, and that process has to specify escalation paths inside the firm as well as the external notification itself. Penetration testing, run by an independent party rather than internal staff, needs to be current and its findings remediated before submission, since a stale or unaddressed test report tends to raise more questions than it answers. Business continuity evidence, including documented failover procedures for custody infrastructure and a tested disaster recovery plan, completes the technical evidence package. A partner resource worth reviewing for the payments side of this picture is this analysis of tokenisation across cross-border payment rails, which maps the infrastructure choices firms make when building settlement systems around tokenised value.
Preparing and submitting the application
Applicants should treat the CBUAE application as a staged process rather than a single submission, since the regulator's review tends to move in phases that each demand a different evidence package.
- Pre-application scoping. Confirm which of the three licensable activities, issuance, conversion, or custody and transfer, the business model actually falls under, and decide between the full licence and foreign registration routes based on incorporation status and target customer base.
- Core documentation assembly. Prepare a detailed business plan, prudential models covering reserve and capital stress scenarios, AML/CFT policies aligned with Federal AML Law, and technical architecture diagrams covering custody and key management.
- Governance evidence. Compile fitness and propriety documentation for directors and senior management, organisational charts showing control function reporting lines, and board-approved policies for risk management and compliance.
- Formal submission and initial review. Submit the completed application package, after which the CBUAE typically raises an initial round of clarifying questions covering gaps in prudential modelling or ambiguities in custody arrangements.
- Supervisory engagement. Expect follow-up meetings or written queries as the regulator tests the firm's governance structure and technical controls against the documentation provided, often requesting live demonstrations of monitoring or custody systems.
- Decision and conditions. Approval, where granted, frequently comes with ongoing conditions such as enhanced reporting frequency during an initial supervisory period.
Realistic timelines vary with the completeness of the submission, but the most common source of delay is a mismatch between the business plan's stated ambitions and the prudential model's actual stress coverage, closely followed by AML/CFT documentation that references policies in principle without evidencing how they operate in the firm's specific transaction flows. Our CBUAE licensing guide for 2026 sets out a fuller article-by-article breakdown of the documentation the regulator expects at each stage.
Prohibited activities, exemptions and marketing limits
The regulation draws firm lines around what unlicensed and unregistered entities may not do. Selling or marketing payment tokens to UAE residents without the appropriate licence or registration is prohibited outright, as is operating an issuance, conversion or custody business targeting the UAE market under a foreign licence alone with no local registration. Firms cannot simply rely on terms of service excluding UAE users while actively marketing into the jurisdiction.
Exemptions are narrow and should not be assumed. Internal corporate treasury movements that never touch a UAE retail customer, and limited pilot activity conducted under direct regulatory sandbox arrangements where one exists, are the kind of carve-outs that may apply, but they need to be confirmed against the specific facts of a business model rather than assumed from general practice elsewhere.
Marketing and communications restrictions deserve particular attention because they are easy to breach inadvertently. Practitioners note that describing or marketing a token as a recognised means of payment carries specific regulatory consequences under the rulebook, since that designation implies a level of regulatory endorsement the issuer may not actually hold. Firms should review promotional copy, app store listings and even investor decks for language that could be read as claiming a payment designation the CBUAE has not granted.
Enforcement powers and what a finding triggers
The CBUAE's enforcement toolkit runs from informal supervisory guidance through to licence suspension or revocation, with financial penalties, corrective directions and public censure available as intermediate steps. Advisory commentary on the regime points to fines, corrective directions and licence suspension as the recurring outcomes in enforcement cases, with the severity typically scaled to whether the breach involved customer harm, reserve shortfalls or deliberate concealment.
Cross-jurisdictional cooperation is a live risk for firms operating across multiple regulators. A finding against a UAE-licensed entity can prompt referral to VARA, the DFSA or FSRA where the firm also holds authorisation in those regimes, and international information-sharing arrangements mean a UAE enforcement action can surface in a firm's dealings with foreign regulators and banking partners well beyond the immediate penalty.
The practical remediation path after an adverse finding starts with an honest internal assessment of root cause, not just the symptom the regulator identified. Boards should expect to commission an independent review of the control weakness, document a remediation timeline with named owners, and proactively update the regulator on progress rather than waiting for the next scheduled examination. Escalating findings to the full board promptly, rather than managing them solely at compliance officer level, tends to shape how seriously the regulator treats the firm's corrective response.
Structuring the business before you apply
Deciding where to house payment token activity is a commercial decision as much as a legal one. A business with a genuine UAE customer base and ambitions to issue AED-denominated tokens has little choice but to incorporate locally, since that is the only route to a full licence. A business whose UAE exposure is incidental, serving a global customer base with a limited UAE segment, may find the registered foreign issuer or custodian route sufficient, provided its home jurisdiction's oversight is strong enough to satisfy CBUAE's documentation expectations.

Ring-fencing customer assets matters regardless of which route is chosen. A captive custody model gives the firm direct control over key management but concentrates operational risk internally, while a third-party custody arrangement shifts some of that operational burden but requires rigorous due diligence on the custodian's own controls and contractual protections covering liability for loss. Contracts with any third-party custodian, bank or payment rail partner should specify clearly who bears loss risk during a security incident and what notice periods apply before service termination.
Banking and payment rail access should be pursued in parallel with, not after, the licensing application. UAE banks apply their own risk appetite to virtual asset clients, and a firm that waits until licence approval to start banking conversations often faces months of additional delay at the point it is most ready to launch. Early engagement with banking partners, supported by the same prudential and AML documentation prepared for the regulator, tends to shorten that gap considerably.
A practical readiness checklist from CRYPTOVERSE
Firms preparing a CBUAE payment token application benefit from mapping every rulebook obligation to a specific document before submission, rather than discovering gaps during supervisory review. Our checklist groups the core evidence into the categories the regulator actually tests:
- Reserve and capital evidence: reserve composition schedule, custodian agreements for reserve assets, capital adequacy calculations and stress-test outputs.
- Governance evidence: board and senior management fitness and propriety files, organisational charts, and board-approved risk and compliance policies.
- AML/CFT evidence: risk-based customer due diligence procedures, sanctions screening methodology, and travel rule operational workflow documentation.
- Technology evidence: custody architecture diagrams, key management procedures, penetration test reports and business continuity plans.
Most firms that fail on a first submission share the same pattern: prudential models that describe reserve composition without stress-testing redemption shocks, and AML policies that read as generic templates rather than reflecting the firm's actual transaction flows. CRYPTOVERSE Legal Consultancy's CBUAE licence guide highlights insufficient prudential modelling and incomplete AML documentation as the most frequently cited reasons applications stall, a pattern consistent across the advisory commentary on this regime.
Remediation for these deficiencies is usually mechanical once identified: rebuild the stress model around a specific redemption scenario tied to the firm's actual token design, then rewrite the AML narrative around the firm's real customer segments and transaction corridors rather than a generic risk taxonomy. Firms that make this correction before submission, rather than after a regulator query, consistently move through review faster.
What boards should prioritise before applying
The single most common misjudgement we see is a board that treats the CBUAE application as a documentation exercise rather than a governance test. The regulator is not simply checking whether policies exist on paper. It is testing whether the board understands its own prudential exposure and can demonstrate, through specific named accountabilities, that someone is responsible for catching a reserve shortfall or a custody failure before it becomes a customer loss.
Boards preparing for supervisory engagement should prioritise three things ahead of submission: a prudential model the finance function can defend line by line under questioning, a governance structure where every control function reports to a named individual rather than a committee, and a custody architecture that has actually been tested, not just documented. We build our client preparation around exactly this sequence, working from the rulebook's own article structure rather than a generic compliance template, because regulators tend to ask questions in the order the rules are written.
**
How CRYPTOVERSE supports your CBUAE licensing application
A CBUAE payment token application moves faster when the prudential modelling, AML/CFT documentation and custody evidence are built together from the start, rather than assembled piecemeal in response to regulator queries. CRYPTOVERSE Legal Consultancy works across all five UAE crypto regulators and brings that structuring experience directly to payment token applicants.
Our engagement for a payment token applicant typically covers:
- Gap analysis against the rulebook's reserve, capital and governance provisions before drafting begins.
- Application drafting, including the business plan, prudential models and AML/CTF policy suite.
- Regulator liaison throughout the review stages, handling clarification requests and supervisory meetings.
- Post-approval support, covering ongoing reporting, reserve attestations and ad hoc regulatory queries.
If your business issues, converts or custodies payment tokens with any UAE customer exposure, start with our VASP licensing services for the UAE and global markets to scope the right route, or go directly to our regulatory and compliance advisory page if your immediate need is an AML/CTF framework rebuild ahead of submission.
This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.
FAQ
Who actually needs a CBUAE payment token licence?
Any business issuing, converting or custodying payment tokens for UAE customers needs either a full licence, if it is UAE-incorporated, or a registration as a foreign issuer, custodian or transferor if it is not. The specific route depends on incorporation status and the scope of activity targeted at UAE residents.
Can a foreign company serve UAE customers without incorporating locally?
A foreign company can pursue the registered foreign payment token issuer, custodian or transferor route rather than full licensing, but that route carries narrower permitted activities and a more restricted customer scope. Businesses planning AED-denominated issuance or broader UAE-facing operations generally still need UAE incorporation to qualify for the full licence.
How does the travel rule affect payment token transfers?
Licensees transferring payment tokens above the applicable threshold must capture and transmit originator and beneficiary information alongside the transaction itself. This becomes operationally harder when the counterparty platform cannot yet exchange equivalent messaging data, which is why firms need a documented protocol for handling those transfers.
What triggers CBUAE enforcement action against a payment token licensee?
Enforcement typically follows findings such as reserve shortfalls, inadequate AML/CFT controls or custody failures, with outcomes ranging from corrective directions and fines to licence suspension in serious cases. A prompt, board-level remediation response following any supervisory finding tends to shape how the regulator treats the firm going forward.
Does a CBUAE payment token licence cover exchange or broker-dealer activity too?
No, the payment token licence covers only issuance, conversion and custody or transfer of payment tokens. A business also running exchange or broker-dealer activity in Dubai typically needs a separate VARA authorisation alongside its CBUAE payment token licence or registration.

