CryptaCount
EN
EnglishENDeutschDEEspañolESFrançaisFRItalianoIT日本語JA한국어KONederlandsNLPolskiPLPortuguêsPT
Log in Start Free

Capital Vault Secures UAE CMA Virtual Asset License for Spot Crypto Dealing and Custody

CryptaCount Editorial · · 9 min read
AML / KYC / LICENSING Capital Vault Secures UAE CMA VirtualAsset License for Spot Crypto Dealingand Custody

Capital Vault, the virtual-asset affiliate of CFD broker Capital.com, has been granted a license by the UAE Capital Market Authority (CMA) to deal in and provide custody of digital assets on behalf of clients. The approval means UAE residents will soon be able to buy and hold actual cryptocurrency through the Capital.com app, rather than gaining price exposure through contracts for difference. For accounting firms, auditors, and CFOs operating in or advising clients across the UAE, a regulated spot custodian entering the market is a material development that affects counterparty assessment, balance-sheet treatment, and AML onboarding workflows.

Capital Vault Secures UAE CMA Virtual Asset License for Spot Crypto Dealing and Custody

What the CMA License Actually Permits

The license granted to Capital Vault covers two distinct regulated activities under the UAE's virtual asset framework: dealing in virtual assets (as an agent or matching principal) and providing custody on behalf of clients. These are not the same activity, and the distinction matters for how the arrangement is accounted for and audited.

Dealing as Agent vs. Matching Principal

When Capital Vault acts as an agent, it executes a client's order on an external venue and the trade is attributed to the client. When it acts as a matching principal, it interposes itself between buyer and seller, becoming the counterparty to both legs before immediately closing its own position. Each mode creates a different liability profile on Capital Vault's own balance sheet and a different disclosure obligation for the client entity. Accounting teams should confirm, before any client assets are placed, which mode applies to each transaction type.

Custody as a Separate Regulated Function

Custody, for regulatory purposes, means Capital Vault holds private keys or controls access to the underlying assets on a client's behalf. Under the CMA framework, this is a separately licensed activity, not a by-product of the dealing license. That separation has direct implications for how client assets are classified in financial statements: assets held in custody with a regulated third party are typically off the custodian's balance sheet, but the accounting treatment depends on whether the arrangement meets the derecognition criteria under IFRS 9 and IFRS 10 (or IAS 38 for intangible asset classification of the crypto itself). Firms should not assume that a regulatory custody license automatically settles the accounting question.

How This Differs from Capital.com's Existing CFD Business

Capital.com's core UAE offering has, until now, been CFD-based. A CFD on Bitcoin, for example, gives a client economic exposure to the price of Bitcoin without ever holding the asset. From an accounting standpoint, a CFD is a derivative and is measured at fair value through profit or loss under IFRS 9. The client has a financial asset or liability on their books, not a crypto holding.

Spot crypto purchased through Capital Vault is a different beast. The client owns the underlying asset, and accounting for it follows IAS 38 (intangible assets at cost less impairment, unless the revaluation model is elected under IAS 38.75) or, for entities that are commodity brokers or traders, potentially IAS 2. IFRS does not yet have a dedicated standard for crypto assets, so the classification judgement remains live. US GAAP filers face a different path: the FASB's ASC 350-60 now requires most crypto assets to be measured at fair value with changes recorded in net income each period.

The practical upshot for accounting teams is that a single client who previously held only CFDs may now hold both derivative and spot positions within the same app. Consolidating those positions correctly in financial statements, and flagging the change in accounting policy if the client transitions from derivative-only to spot, will require careful ledger segmentation. This is exactly the kind of scenario where fit-for-purpose VASP onboarding and AML due diligence obligations need to be revisited at the client level, not just at the platform level.

Capital Vault as a Separate Regulated Entity

Capital Vault is structured as a legally separate entity from Capital.com's other businesses. Its governance, risk management, and custody arrangements are independently maintained. Capital Vault has established a physical office in Abu Dhabi and is building a dedicated local virtual-asset team.

Why Entity Separation Matters for Auditors

The ring-fenced structure has two immediate implications for auditors and CFOs. First, when assessing counterparty risk for a client that uses Capital Vault for custody, the relevant entity to evaluate is Capital Vault, not the Capital.com group as a whole. Group-level financial statements may not reflect the capital adequacy or liquidity position of the custody subsidiary. Firms should obtain Capital Vault's standalone regulatory filings from the CMA once available, rather than relying solely on consolidated group accounts.

Second, if a client has assets held at Capital Vault and separately holds CFD positions under Capital.com's broker license, those relationships are with two distinct regulated entities. Any netting or offset treatment in the client's financial statements would need to meet the strict criteria in IAS 32.42, which generally requires a legally enforceable right to offset and an intention to settle net or simultaneously. In the absence of a master netting agreement covering both entities, offset is unlikely to be permissible.

The UAE CMA's April 2026 Framework: Context for Accounting Firms

Capital Vault's approval sits within a broader regulatory expansion. The UAE's CMA published a virtual asset regulatory framework in April 2026 that increased the number of regulated virtual asset activities from three to eight. The framework also introduced requirements across business conduct, alternative trading systems, AML controls, and prudential standards.

Eight Regulated Activities and What They Signal

The expansion from three to eight regulated activities is significant for firms advising UAE-based virtual asset service providers (VASPs). Previously, a VASP might have operated certain ancillary services without a specific license requirement. Under the updated framework, those activities now potentially require separate authorisation. Accounting firms conducting VASP audits or providing AML compliance support should map their client's current business lines against the new eight-activity taxonomy to identify any licensing gaps.

The prudential standards element of the framework is also new and consequential. Prudential requirements for VASPs typically cover minimum capital thresholds, liquidity buffers, and restrictions on how client assets may be deployed. Where a VASP client is subject to these standards, the auditor will need to assess compliance as part of the engagement, including whether capital is being correctly measured and whether client asset ratios are being reported accurately to the CMA.

AML Obligations Under the Expanded Framework

The CMA's framework explicitly covers AML controls. For accounting firms that provide AML compliance services to UAE VASPs, or that are assessing a VASP as a business partner under their own AML programmes, the existence of a CMA license is a threshold indicator, not a complete answer. A CMA license confirms that Capital Vault met the CMA's standards at the point of authorisation. Ongoing transaction monitoring, customer due diligence, and suspicious activity reporting obligations remain active and subject to annual review.

Firms assessing what the HSBC and Standard Chartered tokenised deposit transfer means for digital asset accounting will recognise a parallel dynamic: regulated entry into a new activity class does not suspend the need for ongoing compliance architecture. The same principle applies here. A regulated custodian is not a zero-risk custodian.

Practical Steps for Accounting Firms and CFOs

The Capital Vault license is not merely a market structure story. It creates near-term action items for firms advising or auditing UAE digital asset clients.

Counterparty and Custody Due Diligence

Any client intending to use Capital Vault for spot custody should be subject to a refreshed counterparty assessment. That assessment should include a review of Capital Vault's CMA authorisation scope, its prudential position once disclosed, and the contractual terms governing custody, particularly around asset segregation, insolvency treatment, and key-management procedures. The CMA's licensing of an entity does not substitute for contractual due diligence.

Balance Sheet Classification and Disclosure

Clients transitioning from CFD positions to spot holdings face a change in asset class on their balance sheet. If that change is material, it may require disclosure of a change in accounting policy or estimate, depending on whether the entity previously held no crypto assets or held them under a different classification. CFOs should flag this to their auditors before the transition occurs, not after.

Digital Asset Accounting Software Alignment

As regulated spot custodians like Capital Vault come online in the UAE, the volume and variety of digital asset transactions flowing through client books will grow. Firms that are not yet using dedicated digital asset accounting software, or crypto bookkeeping software capable of handling custody-based spot positions separately from derivative positions, will find manual reconciliation increasingly difficult to sustain at scale. This is not a future concern; it is a present operational one as the UAE's regulatory landscape broadens.

Capital Vault Secures UAE CMA Virtual Asset License for Spot Crypto Dealing and Custody

Frequently Asked Questions

What is the difference between a CFD on crypto and a spot crypto position for accounting purposes?

A CFD is a financial derivative measured at fair value through profit or loss under IFRS 9. The client does not own the underlying asset. A spot crypto position represents ownership of the asset itself, typically classified as an intangible asset under IAS 38 and measured at cost less impairment (or fair value under the revaluation model). The two require different ledger entries, different disclosure notes, and different audit procedures.

Does a CMA virtual asset license mean Capital Vault is a safe counterparty?

A CMA license confirms that Capital Vault met the regulator's authorisation criteria at the time of approval, including governance, AML, and prudential standards. It does not guarantee ongoing financial soundness or eliminate operational risk. Accounting firms and CFOs should conduct independent counterparty due diligence, review Capital Vault's standalone regulatory filings when available, and assess custody contract terms separately from the licensing question.

How should client assets held with Capital Vault be classified on a client's balance sheet?

Assets held in custody with a regulated third party are generally recognised on the beneficial owner's balance sheet, not the custodian's, provided the client retains control of the assets. Under IFRS, the appropriate classification is typically as an intangible asset (IAS 38) or, for commodity broker-traders, inventory (IAS 2). US GAAP filers should apply ASC 350-60. The accounting team should obtain and review the custody agreement to confirm the nature of the arrangement before determining classification.

What does the UAE CMA's expansion to eight regulated activities mean for existing VASPs?

VASPs operating in the UAE before the April 2026 framework may find that some of their current services now fall under newly defined regulated activities requiring separate authorisation. Accounting firms providing compliance advisory or audit services to UAE VASPs should map the client's full business model against the updated eight-activity taxonomy and identify any gaps before the CMA begins active supervision under the new rules.

Is crypto bookkeeping software necessary if a client uses a regulated custodian?

Yes. A regulated custodian handles execution and asset safekeeping, but it does not produce the general ledger entries, tax computations, or financial statement disclosures the client's accountant needs. Custody statements from a VASP need to be imported, reconciled, and classified within the client's accounting system. As spot holdings grow alongside derivative positions, manual processes become error-prone and difficult to audit. Dedicated digital asset accounting software provides the audit trail and classification logic that a custody relationship alone does not.

Source: Cointelegraph

AEGeneralAdoptedAML/KYC & Licensing

Related articles

AML/KYC & Licensing
Four Financial Centres Racing to Lead on Crypto Regulation
AML/KYC & Licensing
Dubai VARA Reaches 50 Licensed VASPs: What the Operational Gap Means for Firms
AML/KYC & Licensing
Flowdesk Secures Dubai VARA Broker-Dealer Licence After French MiCA Approval
AML/KYC & Licensing
ARP Digital Secures VARA Broker-Dealer Licence: What Accounting Firms and CFOs Must Assess Now