← Back to blog

What is a virtual asset service provider: 2026 guide

July 12, 2026
What is a virtual asset service provider: 2026 guide

TL;DR:

  • A virtual asset service provider (VASP) is anyone conducting specified virtual asset activities as a business, subject to regulation worldwide. Each jurisdiction requires VASPs to obtain proper licenses, implement AML/CFT measures, and verify compliance with local rules. Operating without regulation or proper preparation increases enforcement risks, penalties, and operational challenges.

A virtual asset service provider (VASP) is defined by the Financial Action Task Force (FATF) as any natural or legal person that conducts one or more specified virtual asset activities as a business on behalf of another person. FATF's 2019 update to Recommendation 15 introduced this category formally, placing VASPs within the same regulatory perimeter as traditional financial institutions. The definition carries direct licensing, governance, and AML/CFT consequences of more than 100 jurisdictions, including the UAE's five crypto regulators: VARA, SCA, DFSA, FSRA, and CBUAE. Understanding what qualifies a business as a VASP is the first step toward building a compliant, regulator-ready operation.


What is a virtual asset service provider under FATF and UAE law?

A VASP is defined by the activities it performs, not by the technology it uses. FATF's five core activities that trigger VASP status are: exchanging virtual assets for fiat currency, exchanging one virtual asset for another, transferring virtual assets, safekeeping or administering virtual assets or instruments enabling control over them, and participating in or providing financial services related to an issuer's offer or sale of virtual assets. Any business conducting even one of these activities for others falls within the VASP definition and assumes the associated regulatory obligations.

UAE regulators apply this framework with jurisdiction-specific precision. VARA, established under Dubai Law No. 4 of 2022, regulates virtual asset activities within the Emirate of Dubai and free zones other than the DIFC. The DFSA governs VASPs operating within the Dubai International Financial Centre under its Rulebooks, including COBS, AML, and GEN. The FSRA administers the Virtual Asset Framework within Abu Dhabi Global Market. Each regulator maps FATF's five activities onto its own authorised activity categories, but the underlying definitional logic is consistent.

Pro Tip: If your business model touches any of the five FATF activities, even incidentally, seek a regulatory opinion before launch. Regulators assess substance over form, and a product marketed as "software" can still constitute a licensable VASP activity.

The table below maps FATF's five activities against the VARA and DFSA frameworks to clarify where obligations arise.

ActivityFATF definitionVARA categoryDFSA category
VA to fiat exchangeExchange between virtual assets and fiat currenciesVA Exchange ServicesAccepted Virtual Asset (AVA) trading
VA to VA exchangeExchange between one or more forms of virtual assetsVA Exchange ServicesAVA trading
TransferMoving virtual assets on behalf of anotherVA Transfer ServicesVA transfer
SafekeepingCustody or administration of virtual assetsVA Custody ServicesCustody of AVAs
Financial servicesParticipation in token issuance or saleVA Issuance ServicesArranging deals in AVAs

Infographic comparing FATF activities and UAE VASP regulations

Understanding which column your business falls into determines which rulebook applies, which capital thresholds you must meet, and which supervisory body will examine your governance arrangements.


How do licensing requirements govern VASPs globally and in the UAE?

Licensing is a non-negotiable precondition for operating as a VASP in any FATF-aligned jurisdiction. Registration requirements carry statutory weight: operating without registration is a criminal offence in jurisdictions including Australia, the UAE, and across the EU under MiCA. Regulators hold powers to suspend, cancel, or refuse registration, and those powers are exercised with increasing frequency as supervisory capacity matures.

VARA mandates full licensing before any virtual asset service commences, with licences subject to renewal every three years. Capital adequacy, governance structures, and AML/CFT programmes must all be in place at the point of application, not retrofitted after approval. VARA is also empowered to impose conditions on licences, restrict activities, and refer matters for criminal prosecution under UAE Federal AML Law, Decree-Law No. 20 of 2018 and its amendments.

Hands preparing VARA licensing paperwork in modern office

The table below summarises key licensing requirements across four major jurisdictions.

JurisdictionRegulatorLicence typeCapital requirementRenewal
UAE (Dubai)VARAVASP LicenceActivity-dependentEvery 3 years
UAE (DIFC)DFSALicence to conduct Financial ServicesDetermined by COBS RulebookAnnual review
UAE (ADGM)FSRAFSP LicenceRisk-based prudential modelAnnual review
EUNational CAs under MiCACASP Authorisation€150,000 minimumOngoing supervision
SingaporeMASMajor Payment Institution LicenceSGD 250,000Annual

Prudential modelling is a board-level obligation, not a finance team exercise. Boards must approve capital adequacy assessments, stress-test assumptions, and recovery plans. Client asset segregation is equally non-negotiable: VARA, DFSA, and FSRA all require VASPs to hold client assets separately from proprietary assets, with clear reconciliation and reporting obligations. Failure to segregate is treated as a governance failure, not merely an operational lapse.

Pro Tip: When preparing a VARA licence application, map each proposed business activity to a specific VARA authorised activity category before drafting your governance documents. Misalignment between your activity description and VARA's taxonomy is one of the most common reasons licence applications are rejected.


What AML/CFT and Travel Rule obligations apply to VASPs?

VASPs carry AML/CFT obligations equivalent to those of regulated financial institutions. FATF's compliance standards require VASPs to implement the following across all jurisdictions where they operate:

  • Customer due diligence (CDD) and KYC: Verify the identity of all customers before onboarding, apply enhanced due diligence to high-risk customers, and maintain records for a minimum of five years.
  • Transaction monitoring: Deploy systems capable of detecting unusual patterns, flagging transactions above reporting thresholds, and generating suspicious transaction reports (STRs) for submission to the relevant financial intelligence unit.
  • Sanctions screening: Screen all customers and counterparties against UN, OFAC, EU, and UAE sanctions lists in real time, with automated alerts for matches.
  • Travel Rule compliance: Share originator and beneficiary information for all virtual asset transfers above the applicable threshold. Travel Rule obligations apply in over 100 jurisdictions and require VASPs to identify the sending and receiving institutions, not just the end customers.
  • Risk-based approach: Conduct a documented business-wide risk assessment, updated at least annually, covering customer risk, product risk, geographic risk, and channel risk.
  • Suspicious transaction reporting: File STRs with the UAE Financial Intelligence Unit (FIU) or the relevant national body without tipping off the subject of the report.

The Travel Rule deserves particular attention. It requires the originating VASP to transmit name, account number, address, and date of birth of the originator, along with the name and account number of the beneficiary, to the receiving VASP before or during the transfer. This mirrors the wire transfer rules applied to banks under FATF Recommendation 16. VASPs that cannot technically comply with the Travel Rule face transaction blocking obligations, which creates operational risk if not addressed at the infrastructure design stage.

Virtual assets are inherently borderless, which means compliance cannot be a static, jurisdiction-specific exercise. A VASP serving customers in multiple countries must maintain a compliance programme that meets the highest applicable standard across all markets it touches. VARA, DFSA, and FSRA each reference FATF standards as the baseline, with additional UAE-specific requirements layered on top under Federal AML Law and CBUAE Circular 2/2024.

For practical guidance on structuring a UAE-compliant AML programme, the UAE virtual asset AML guide published by Cryptoverselawyers sets out the key obligations and common gaps in existing programmes.


What operational and technology controls must VASPs maintain?

Governance, custody, and cybersecurity controls are not optional features of a VASP's operating model. VARA's governance standards require board-level oversight of all material risks, with documented policies covering at minimum:

  • Board composition and oversight: At least one director with demonstrable virtual asset expertise. Board minutes must evidence active oversight of compliance, risk, and capital adequacy.
  • Capital adequacy: VASPs must maintain minimum capital at all times, with a documented process for notifying VARA if capital falls below the required threshold.
  • Client asset segregation: Client virtual assets and fiat must be held in designated accounts or wallets, separately from the VASP's own assets, with daily reconciliation.
  • Cybersecurity controls: Technology controls must address hot and cold wallet security, private key management, multi-signature authorisation, penetration testing, and incident response procedures.
  • Operational resilience: Business continuity plans must cover system outages, cyber incidents, and key person dependencies, with tested recovery time objectives.

Enforcement exposure under VARA is material. VARA holds powers to issue fines, suspend licences, restrict activities, appoint monitors, and refer cases for criminal prosecution. The DFSA's enforcement framework under its GEN and MIR Rulebooks similarly provides for financial penalties, public censure, and licence withdrawal. Boards that treat compliance as a back-office function rather than a governance priority face personal liability exposure in addition to institutional sanctions.

The VARA supervision and enforcement framework is detailed and actively applied. VASPs operating in Dubai should expect periodic supervisory reviews, thematic examinations, and data requests as standard features of the regulatory relationship, not exceptional events.


The compliance trap most VASPs walk straight into

Working with VASPs across the UAE and over 30 jurisdictions, the pattern Cryptoverselawyers sees most consistently is not wilful non-compliance. It is under-preparation at the point of application, followed by reactive remediation that costs far more than early-stage legal structuring would have.

The most common failure mode is treating the licence application as a documentation exercise rather than a governance exercise. Applicants submit policies that describe a compliance programme they have not yet built. Regulators, particularly VARA and the DFSA, conduct substance assessments. They ask whether the board has actually approved the AML risk assessment, whether the compliance officer has the authority and budget to act, and whether the technology infrastructure can deliver Travel Rule compliance from day one.

The second failure mode is jurisdictional overconfidence. A VASP licensed in one jurisdiction assumes that licence provides a degree of comfort in others. It does not. MiCA authorisation does not satisfy VARA's requirements. A DFSA licence does not cover activities conducted outside the DIFC. Each regulatory perimeter is distinct, and operating across borders without a clear jurisdictional map is a material enforcement risk.

Cryptoverselawyers' position is that compliance readiness must be built into the business model at the design stage, not bolted on after the licence is granted. The regulatory compliance advisory work we do with founders and boards consistently shows that early legal input reduces both application timelines and post-licence remediation costs. The Singapore virtual asset regulatory framework and the UAE frameworks share structural similarities, but the differences in supervisory culture and enforcement appetite are significant enough to require jurisdiction-specific advice.

Compliance is a continuous, dynamic obligation. That is not a regulatory platitude. It reflects the reality that FATF updates its guidance, regulators issue new circulars, and enforcement priorities shift. A programme that was adequate in 2024 may not satisfy a 2026 supervisory examination.

— CRYPTOVERSE


How Cryptoverselawyers supports VASP licensing and compliance

Cryptoverselawyers is a Dubai-based law firm advising exclusively on virtual assets, blockchain, and fintech regulation. The firm guides clients through the full VASP licensing lifecycle, from pre-application structuring through to post-licence governance and ongoing compliance.

https://cryptoverselawyers.io

For businesses seeking VARA licensing and regulatory compliance in Dubai, or navigating the DFSA, FSRA, or international frameworks including MiCA, MAS, and FCA, Cryptoverselawyers provides regulator-ready legal solutions. The firm's compliance advisory practice covers AML/CFT programme design, Travel Rule implementation, board governance frameworks, and capital adequacy modelling. With offices in Dubai, Fujairah, the USA, and Nigeria, and active coverage across 30+ jurisdictions, Cryptoverselawyers delivers the jurisdictional depth that multi-market VASP operations require. For founders and compliance officers who need clarity on payment compliance obligations and VASP licensing, the firm offers structured advisory engagements calibrated to your business model and target markets.


FAQ

What is the FATF definition of a VASP?

FATF defines a VASP as any natural or legal person that conducts one or more of five specified virtual asset activities as a business on behalf of another person. These activities include exchange, transfer, safekeeping, and financial services related to virtual asset issuance.

Which activities trigger VASP licensing requirements?

Five core activities trigger VASP status under FATF: exchanging virtual assets for fiat, exchanging virtual assets for other virtual assets, transferring virtual assets, safekeeping virtual assets, and participating in virtual asset issuance or sale. Conducting any one of these for others as a business requires registration or licensing.

What AML/CFT obligations do VASPs have?

VASPs must implement KYC, transaction monitoring, sanctions screening, and Travel Rule compliance equivalent to regulated financial institutions. AML/CFT obligations apply across all jurisdictions where the VASP operates, with FATF standards as the baseline.

How does the Travel Rule apply to VASPs?

The Travel Rule requires VASPs to transmit originator and beneficiary information to the receiving VASP for every qualifying virtual asset transfer. This obligation applies in over 100 jurisdictions and mirrors the wire transfer rules applied to banks under FATF Recommendation 16.

Does a VASP licence in one jurisdiction cover operations in another?

No. Each regulatory perimeter is distinct. A VARA licence covers activities within Dubai's jurisdiction; a DFSA licence covers the DIFC. Operating across borders without jurisdiction-specific authorisation is a material enforcement risk under both UAE law and international regulatory frameworks.