The official VARA Rulebooks are hosted on VARA's dedicated portal at rulebooks.vara.ae, alongside the Virtual Assets and Related Activities Regulations 2023, published on 7 February 2023. Every virtual asset service provider (VASP) operating in, or targeting clients in, Dubai must read and apply these instruments. There is no substitute document and no unofficial consolidation that carries legal weight.
The five core rulebooks every applicant and regulated firm must download are:
- Company Rulebook — governance, board composition, Fit and Proper standards
- Compliance and Risk Management Rulebook — AML/CFT, Travel Rule, risk frameworks
- Technology and Information Rulebook — custody, key management, cyber resilience
- Market Conduct Rulebook — client-facing conduct, disclosure and fair dealing
- VA Activity Rulebook(s) — activity-specific obligations layered on top of the above
Version control matters. VARA timestamps each PDF with an "Effective From" date displayed on the rulebook's portal page. The Company Rulebook page currently shows an effective date of 19 June 2025. Always download from the portal's "current version" link rather than saving an older PDF, and record the file name and effective date in your compliance register at the point of download.
What do the official VARA rulebooks cover?
VARA structures its regulatory framework as a suite of rulebooks, each governing a distinct compliance domain. The table below sets out each core rulebook, its subject matter, and the current PDF download link.
| Rulebook | Subject matter | Current PDF |
|---|---|---|
| Company Rulebook | Corporate governance, board duties, Fit and Proper, induction and training | Download |
| Compliance and Risk Management Rulebook | AML/CFT, Travel Rule, compliance management, suspicious transaction reporting | Download |
| Technology and Information Rulebook | Custody, key management, cyber security, outsourcing, incident response | Available on portal |
| Market Conduct Rulebook | Client disclosure, fair dealing, conflicts of interest, marketing standards | Available on portal |
| VA Activity Rulebook(s) | Activity-specific obligations for each licensed VA service (exchange, custody, transfer, etc.) | Available on portal |
Both the Company Rulebook and the Compliance Rulebook carry the file-name suffix VER20250519, indicating the operative version was effective from 19 May 2025 (with the portal page confirming 19 June 2025 as the effective date). Firms should treat the portal page date as the operative date and the file name as the version identifier.
VARA also maintains historical versions on the portal. Where a legacy version is relevant to an ongoing supervisory review or enforcement matter, the archived PDF remains accessible. Compliance teams should note which version was in force at the time of any alleged breach, as VARA will apply the rulebook operative at that date.
What is the legal basis for VARA's regulatory mandate?
VARA derives its authority from the Virtual Assets and Related Activities Regulations 2023, issued under Dubai Law No. 4 of 2022 on the Regulation of Virtual Assets and their Service Providers. The Regulations were published on 7 February 2023 and establish VARA as the competent authority for virtual assets across the Emirate of Dubai, including most free zones, with the notable exception of the Dubai International Financial Centre (DIFC), which falls under the DFSA's jurisdiction.
The Regulations define the scope of VARA's remit across two dimensions: territorial and subject-matter.
Territorial scope:
- Applies to all persons conducting VA activities in or from Dubai (mainland and most free zones)
- Excludes the DIFC, where the DFSA's COBS and AML rulebooks govern
- The Abu Dhabi Global Market (ADGM) falls under the FSRA's Virtual Asset Framework, not VARA
Subject-matter scope:
- Covers VA issuance, exchange, transfer and settlement, custody, lending and borrowing, staking, and tokenisation services
- Applies to both retail and institutional offerings
- Captures firms incorporated outside Dubai that solicit or serve clients within Dubai
Independent legal commentary on VARA's regulatory architecture confirms that the Regulations function as the primary legislative instrument, with the rulebooks sitting beneath them as binding secondary instruments. A breach of a rulebook is therefore a breach of the Regulations, carrying the same enforcement consequences.
Which activities does VARA licence, and what triggers a licensing obligation?
A firm requires a VARA licence before conducting any regulated virtual asset activity in or from Dubai. The licensing obligation is activity-based, not entity-based, so the legal form of the entity does not determine whether a licence is required.
Licensable activities under the VA Activity Rulebook framework:
- Virtual asset issuance (including token sales, stablecoin issuance, and NFT platforms with financial characteristics)
- VA exchange services (spot and derivatives)
- VA transfer and settlement services
- VA custody services (holding client private keys or controlling client assets)
- VA lending and borrowing
- VA staking services
- VA management and investment services
- Tokenisation services for real-world assets
Practical triggers that create a licensing obligation:
- Holding, controlling, or managing client private keys on a commercial basis
- Operating a platform that matches buy and sell orders for VAs from Dubai-based users
- Soliciting Dubai-resident investors for a token issuance, regardless of where the issuer is incorporated
- Providing custody of client VA assets as part of a broader financial service
Branches and representative offices of foreign entities are not exempt. If a branch conducts licensable activity in Dubai, it requires its own VARA authorisation. A representative office that does no more than market services may fall below the threshold, but VARA takes a substance-over-form approach, and any activity that involves client onboarding, asset handling, or order execution will be treated as licensable. Firms should assess their licensing position carefully before commencing operations.
Capital, prudential standards and governance obligations under the rulebooks
Board-level governance
The Company Rulebook (Parts I–III) sets binding governance obligations for all VARA-licensed entities. The board of directors bears ultimate responsibility for the firm's regulatory compliance and must include individuals who satisfy VARA's Fit and Proper criteria. Those criteria assess integrity, competence, financial soundness, and the absence of disqualifying regulatory history.

Senior management appointments, including the Chief Executive Officer, Chief Compliance Officer, and Money Laundering Reporting Officer (MLRO), require VARA pre-approval. The Company Rulebook's governance framework mandates documented reporting lines between the board, senior management, and the compliance and risk functions, with clear escalation pathways for material breaches.
Internal control expectations include a documented risk appetite statement approved by the board, an annual internal audit cycle covering all material risk areas, and a formal board-level review of the compliance function's findings at least quarterly.
Capital and prudential requirements
VARA sets minimum paid-up capital requirements that vary by activity type and the risk profile of the firm's business model. Firms must maintain net liquid assets above the prescribed minimum at all times and must model prudential buffers against stress scenarios relevant to their activity. Capital must be held in acceptable forms, which typically means cash or near-cash instruments held in a UAE-regulated bank account in the firm's name.
Prudential modelling is not a one-time exercise. VARA expects firms to maintain rolling capital adequacy assessments and to notify VARA promptly if capital falls below the required threshold or if a material adverse event threatens the firm's financial position.
Client asset segregation
Client assets must be segregated from the firm's own assets at all times. This applies to both fiat currency held on behalf of clients and virtual assets held in custody. Segregation must be maintained at the account level (for fiat) and at the wallet level (for VAs), with daily reconciliation records retained for a minimum period specified in the rulebooks. Any shortfall identified during reconciliation must be remediated immediately and reported to VARA if it exceeds the materiality threshold set out in the relevant rulebook.

AML/CFT and the Travel Rule: required controls and cross-border implications
VARA's AML/CFT framework, set out in the Compliance and Risk Management Rulebook, operates alongside the UAE's Federal AML Law (Decree-Law No. 20 of 2018, as amended). The Compliance Rulebook is the primary instrument for day-to-day AML/CFT obligations; the Federal Law sets the criminal law backdrop and the penalties for money laundering and terrorist financing offences.
Required AML/CFT controls:
- Customer due diligence (CDD) and enhanced due diligence (EDD) for higher-risk clients, including politically exposed persons (PEPs) and clients from high-risk jurisdictions
- Know Your Business (KYB) procedures for corporate clients, including beneficial ownership verification to the ultimate natural person
- Risk-based transaction monitoring calibrated to the firm's client base and activity type
- Real-time and retrospective sanctions screening against UAE, UN, and relevant international sanctions lists
- Suspicious Transaction Reports (STRs) filed with the UAE Financial Intelligence Unit (goAML platform) within the prescribed timeframe
- Record retention for a minimum of five years from the end of the business relationship
Travel Rule obligations:
The Compliance Rulebook references the FATF Travel Rule, requiring VASPs to transmit originator and beneficiary information alongside VA transfers above the applicable threshold. VARA aligns with the FATF standard of USD 1,000 (or equivalent) as the threshold above which full originator and beneficiary data must accompany a transfer. For transfers below that threshold, a reduced data set is still required.
For UK-based firms operating between FCA-regulated and VARA-regulated entities, the Travel Rule obligations are broadly consistent: the FCA's implementation under the Money Laundering Regulations 2017 (as amended) requires the same originator/beneficiary data fields. The practical challenge lies in counterparty verification, where the sending VASP must confirm the receiving VASP is itself subject to equivalent AML/CFT supervision. Firms should maintain a counterparty VASP register and conduct periodic due diligence reviews of counterparties. Cryptoverselawyers advises on transfer and settlement compliance under both VARA and FCA frameworks.
CBUAE Circular 2/2024 and Circular 15/2021 are relevant cross-reference instruments for firms that also hold a CBUAE-regulated licence or that process payments through UAE-licensed payment service providers. Those circulars address AML/CFT expectations for payment service providers and should be reviewed where a VASP's settlement infrastructure involves a CBUAE-regulated counterparty.
Technology and custody controls required by the rulebooks
The Technology and Information Rulebook sets the technical baseline for all VARA-licensed firms. Its requirements are not aspirational; they are conditions of licence, and VARA will assess compliance with them during the application review and in subsequent supervisory visits.
Custody and key management
Firms providing custody services must document their cryptographic key management architecture in detail. VARA expects private keys to be held in hardware security modules (HSMs) or equivalent certified secure storage, with multi-signature or threshold signature schemes applied to wallets holding client assets above defined value thresholds. Hot wallet exposure must be minimised, with the majority of client assets held in cold storage with documented access controls.
Required technical controls
- Segregation of duties between personnel who can initiate transactions and those who can authorise them
- Encryption of data at rest and in transit, with documented key rotation schedules
- Change control procedures for all material changes to systems that handle client assets or personal data
- Incident response plans tested at least annually, with defined escalation to the board and to VARA within the notification window specified in the rulebook
- Access control logs retained for the minimum period prescribed, with anomaly detection in place
Third-party outsourcing
Where critical functions are outsourced to third-party providers (cloud infrastructure, custody technology, transaction monitoring software), VARA requires documented vendor due diligence, contractual service level agreements that meet the rulebook's minimum standards, and a notification obligation to VARA before material outsourcing arrangements are entered into or materially changed. The firm remains fully responsible for the outsourced function and cannot delegate regulatory liability to the vendor.

What enforcement powers does VARA hold, and how should firms respond?
VARA's enforcement toolkit is broad. The Regulations and rulebooks give VARA authority to:
- Conduct on-site inspections and request documents, records, and system access at any time
- Issue formal warnings and remediation directions with binding timelines
- Impose financial penalties for rulebook breaches
- Suspend or restrict a licence pending investigation
- Revoke a licence for serious or repeated breaches
- Refer matters to UAE law enforcement or overseas regulators under mutual cooperation arrangements
Enforcement powers are stated in the Virtual Assets and Related Activities Regulations 2023 and cross-referenced in the relevant rulebook parts. VARA's supervisory and enforcement approach is risk-based: firms with weaker governance, inadequate AML controls, or capital shortfalls attract closer scrutiny.
When VARA notifies a firm of an inspection or a potential breach, the immediate priorities are:
- Preserve all records relevant to the matter — do not delete, alter, or archive documents pending the outcome
- Notify the board and appoint a single senior point of contact for VARA communications
- Instruct external legal counsel before responding to any formal VARA request
- Prepare an interim remediation plan addressing the identified gap, even before VARA formally requests one
- Assess whether the matter triggers cross-border reporting obligations to overseas regulators (e.g., the FCA, where the firm holds a UK registration)
Cross-border cooperation is a live consideration. VARA participates in information-sharing arrangements with overseas regulators, and a supervisory action in Dubai may prompt parallel enquiries from the FCA or other competent authorities where the firm operates.
Practical structuring and application readiness checklist for UK businesses
Firms based in the UK that intend to operate in Dubai under a VARA licence should begin their readiness assessment at least six to nine months before the intended launch date. The VARA licensing process involves multiple sequential stages, and gaps in documentation are the most common cause of delay.
- Corporate structure review — confirm the Dubai entity type (LLC, free zone company, or branch), shareholding structure, and ultimate beneficial ownership chain. VARA requires a clean, documented ownership structure with no unexplained intermediate holding layers.
- Governance framework — appoint board members and senior management who satisfy Fit and Proper criteria. Prepare CVs, regulatory history declarations, and criminal record certificates for each proposed appointee.
- AML/CFT policy suite — draft a complete AML/CFT policy manual aligned to the Compliance Rulebook and Federal AML Law, including a Business Risk Assessment (BRA), Customer Risk Assessment (CRA), and MLRO appointment letter.
- Technology architecture documentation — prepare a technical architecture diagram, custody model description, key management policy, and incident response plan. If using third-party custody or cloud infrastructure, include vendor due diligence files and draft SLAs.
- Capital evidence — provide bank statements or audited accounts evidencing paid-up capital at or above the minimum required for the intended activity. Prepare a prudential model showing projected capital adequacy over a 12-month horizon.
- Client asset model — document the segregation model for client fiat and VA assets, including the reconciliation process and the escalation procedure for shortfalls.
- Legal opinions — obtain a legal opinion confirming the entity's compliance with the UAE corporate law requirements and, where relevant, confirming that the proposed activity does not require a separate CBUAE or SCA licence.
- Application submission — submit via VARA's portal with all required annexes. VARA typically issues a completeness acknowledgement within a few weeks of submission; substantive review then follows.
Estimated timeline: from a complete submission to initial approval, firms should budget four to eight months, depending on the complexity of the activity and the quality of the application. Incomplete submissions reset the clock.
Documents and internal owners:
- AML/CFT policy suite — Chief Compliance Officer / MLRO
- Technical architecture documentation — Chief Technology Officer / Head of Security
- Capital and prudential model — Chief Financial Officer
- Governance declarations — Company Secretary / General Counsel
- Legal opinions — external legal counsel
Pro Tip: Firms that complete a pre-application gap analysis against each rulebook section before submitting materially reduce the number of VARA information requests during review. Cryptoverselawyers structures this gap analysis as a structured readiness matrix mapped to each rulebook part, which also serves as the firm's ongoing compliance monitoring tool post-licensing.
How does VARA publish updates and manage rulebook versions?
VARA versions its rulebooks by assigning each PDF a version identifier embedded in the file name (e.g., VER20250519) and displaying an "Effective From" date on the corresponding portal page. The portal page is the authoritative reference: the file name records the version, and the page records the operative date. Where the two dates differ, the portal page date governs.
VARA does not currently operate a public RSS feed or email subscription service for rulebook amendments. Firms should therefore adopt a structured monitoring process:
- Assign a named internal owner (typically the MLRO or Head of Compliance) to check the VARA Rulebooks portal at least monthly
- Set a calendar reminder to review all rulebook portal pages on the first working day of each month
- Subscribe to legal bulletins from specialist VA law firms that track VARA consultation notices and amendment publications
- Monitor VARA's official communications channels for consultation papers, which typically precede formal rulebook amendments by several weeks
When a new version is published, the compliance owner should conduct a gap analysis between the prior version and the new version, document any changes that affect the firm's policies or procedures, and present a remediation plan to the board within 30 days of the effective date. VARA expects firms to implement rulebook amendments by the effective date, not after it.
What practitioners consistently underestimate about VARA compliance
Boards and senior management frequently treat VARA licensing as a one-time project rather than an ongoing supervisory relationship. That framing is the single most common source of post-licensing compliance failures. VARA's rulebooks impose continuous obligations, and the regulator conducts periodic supervisory reviews that assess whether the firm's live operations match the governance and control frameworks described in its application.
Three priorities that boards should address before and after licensing:
Governance before capital. Firms that invest heavily in capital modelling but appoint a board without genuine Fit and Proper credentials consistently face the longest application delays. VARA's assessment of board quality is substantive, not procedural. A board member with a prior regulatory sanction, even from a different jurisdiction, will trigger an extended review. Appoint qualified, experienced individuals early and document their credentials thoroughly.
AML readiness is not a policy document. A well-drafted AML/CFT manual is necessary but not sufficient. VARA assesses whether the firm's transaction monitoring system is calibrated to its actual client base and transaction patterns. A generic, off-the-shelf monitoring ruleset applied to a high-volume exchange will not satisfy a supervisory review. Firms should invest in calibrating their monitoring parameters before the application is submitted, not after the licence is granted.
Capital modelling must reflect the worst case. Prudential buffers calculated on optimistic revenue projections will fail under stress. VARA expects firms to model capital adequacy against scenarios that include a significant reduction in trading volumes, a major operational incident, and a regulatory enforcement action. Boards that present only base-case projections signal to VARA that their risk management culture is immature.
Two compliance gaps that are consistently under-estimated: the Travel Rule counterparty verification obligation (firms often have the policy but lack the operational process to verify counterparty VASP status at the point of transfer) and the outsourcing notification requirement (firms routinely change cloud infrastructure providers or custody technology vendors without notifying VARA, which constitutes a rulebook breach regardless of the operational rationale).
Primary sources and further reading
Compliance teams should download and preserve the following primary sources for audit files and licence applications:
- VARA Rulebooks portal — the central repository for all rulebooks and the Virtual Assets and Related Activities Regulations 2023; bookmark the portal page rather than saving individual PDFs, to ensure you always access the current version
- Company Rulebook (current PDF) — binding governance, Fit and Proper, and board obligations; essential for all VARA applicants
- Compliance and Risk Management Rulebook (current PDF) — AML/CFT framework, Travel Rule obligations, and suspicious transaction reporting; required reading for MLROs and compliance officers
- Company Rulebook portal page — confirms the operative "Effective From" date and links to the current version; use this page to verify version currency before relying on a saved PDF
- Lexology: VARA regulatory framework commentary — independent legal analysis of VARA's architecture; useful for interpreting technical drafting in the rulebooks
- UAE Federal AML Law (Decree-Law No. 20 of 2018, as amended) — the criminal law backdrop to VARA's AML/CFT rulebook obligations; firms must comply with both instruments concurrently
- CBUAE Circular 2/2024 and Circular 15/2021 — relevant for VASPs whose settlement infrastructure involves CBUAE-regulated payment service providers; review alongside the Compliance Rulebook
- DFSA COBS, AML, GEN, and MIR Rulebooks — applicable to firms operating in or from the DIFC; not substitutes for VARA instruments but essential cross-reference material for multi-jurisdiction structures
- FSRA Virtual Asset Framework (ADGM) — governs VA activities in the Abu Dhabi Global Market; relevant for firms considering a dual-licence structure across Dubai and Abu Dhabi
This article provides general regulatory information and does not constitute legal advice. Firms should confirm current rulebook versions and applicable requirements with the VARA portal directly and seek advice from a qualified legal adviser before making compliance or licensing decisions.
This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.
Sources
- Welcome to the VARA Rulebook | Virtual Assets Regulatory Authority (VARA)
- Download — Company Rulebook current version
- Compliance and Risk Management Rulebook (PDF)
- Company Rulebook | Virtual Assets Regulatory Authority (VARA)
