Dubai's VARA Rolls Out Digital Asset Rules, Bans Privacy Coins
Dubai's Virtual Asset Regulatory Authority (VARA) has published one of the most expansive crypto regulatory frameworks seen anywhere in the world, covering licensing, AML/CFT obligations, market conduct, custody, and a flat prohibition on privacy coins. For accounting firms, auditors, and CFOs serving virtual asset service providers (VASPs) operating in or considering the UAE, this is a material compliance event, not background noise. The rulebooks are in force and they carry teeth.
What VARA Is and Why It Matters for Crypto Accounting
VARA was established as the world's first crypto-specific regulatory authority, purpose-built for Dubai's ambition to become a global hub for digital asset innovation. Unlike financial regulators that have adapted legacy frameworks to cover crypto, VARA was designed from the ground up with virtual assets at its centre. The more than a dozen rulebooks it has now released give it a comprehensive perch over every major VASP activity: exchange, custody, brokerage, lending, and issuance.
The breadth matters for firms advising clients in this space. A single VASP may now be subject to simultaneous obligations spanning AML/CFT, market conduct, advertising, asset segregation, and capital adequacy, all under one regulatory roof. For crypto accounting software stacks and compliance teams supporting those VASPs, the obligations translate into specific data, reporting, and control requirements that need to be mapped and tested.
Alignment with FATF Standards
VARA's AML/CFT requirements are explicitly aligned with Financial Action Task Force (FATF) standards. That includes customer due diligence, ongoing transaction monitoring, and compliance with the FATF Travel Rule, which requires VASPs to pass originator and beneficiary information along with transfers above certain thresholds. VASPs must also demonstrate how they intend to manage risks arising from transactions with unhosted wallets, those held outside a regulated VASP's custody.
Critically, VARA expects firms to monitor blockchain data for risk indicators tied to customer transactions and to evaluate the adequacy of available blockchain analytics tools to support effective screening. This is not a soft expectation. It is written into the compliance guidelines and implies a minimum standard for the technology infrastructure a VASP must deploy.
The Privacy Coin Ban: Scope and Regulatory Context
The most immediately headline-grabbing measure is VARA's prohibition on VASPs offering trading in anonymity-enhanced cryptocurrencies (AECs), commonly called privacy coins. Coins such as Monero and Zcash, which feature protocol-level privacy by default, fall within this category.
How VARA's Approach Compares with Other Jurisdictions
VARA's ban puts Dubai alongside Japan's Financial Services Agency (JFSA), which has similarly prohibited licensed exchanges from handling privacy coins. The approach differs from that taken by some other regulators: the New York Department of Financial Services (NYDFS) has previously permitted limited privacy coin services where a VASP can demonstrate sufficient transaction visibility, a nuance VARA does not appear to accommodate.
For VASPs operating multi-jurisdiction platforms, this creates a genuine compliance architecture question. A service permissible in one jurisdiction may be flatly prohibited in Dubai. Any firm that consolidates its VASP clients' books across jurisdictions needs to flag these product-level differences and ensure that AEC exposure in Dubai is zero, not just disclosed.
Accounting Implications of the Ban
From a digital asset accounting software perspective, the ban creates a few practical obligations. Any VASP that previously held Monero, Zcash, or similar assets on behalf of Dubai customers will need to demonstrate orderly wind-down of those positions, with clear audit trails showing the disposal date, method, and pricing basis. Accounting teams should also verify that no residual AEC balances sit in custody wallets, including in cold storage. A gap here is not a rounding error; it is a regulatory breach.
Market Conduct, Advertising, and Segregation Rules
VARA's rulebooks extend well beyond AML/CFT. VASPs are prohibited from proprietary trading on their own account, a direct response to the kind of customer fund misuse that became a defining scandal in the broader crypto industry. Customer assets must be segregated from a VASP's proprietary assets, and VASPs must be able to demonstrate adequate financial resources held on behalf of customers.
Market Manipulation and Insider Dealing Controls
Compliance arrangements must be in place to prevent insider dealing, unlawful disclosures, and market manipulation. These requirements map closely to market abuse frameworks already familiar to firms advising clients in the UK and EU, where similar provisions sit within MiCA and the UK's Financial Services and Markets Act regime. For CFOs and compliance officers at VASPs with cross-border operations, the convergence is helpful: controls built for MiCA will likely cover much of what VARA demands, but the specifics should be reviewed line by line rather than assumed equivalent.
Advertising and Consumer Protection
VASPs must have compliant marketing arrangements in place. Advertising to customers is governed, and firms should expect that risk disclosures, promotional restrictions, and approval processes will need to be documented. For accounting firms preparing regulatory compliance reports for VASP clients, this is another line item to include in scoping discussions.
Exchange-Specific Requirements and Market Surveillance
VARA's guidance for crypto exchanges includes a requirement to share data with VARA to enable market surveillance and to maintain resilient, continuous trading systems. These are not aspirational standards. An exchange operating in Dubai will need to build data-sharing infrastructure that connects to VARA's supervisory function, and its books must be able to support that linkage.
For firms whose clients operate exchanges, this creates a clear dependency on crypto bookkeeping software that can produce VARA-compatible reporting outputs. Any gap between a client's existing accounting infrastructure and what VARA will actually request is worth identifying now, before VARA asks for it.
SEC Enforcement on Staking: A Parallel Pressure Point
Separate from the VARA framework, the US Securities and Exchange Commission reached a settlement with crypto exchange Kraken over its staking-as-a-service programme. The SEC determined that the programme, which involved Kraken pooling customer assets and offering returns, constituted an unregistered securities offering. Kraken agreed to pay $30 million and committed to discontinuing similar services for US investors.
What the Kraken Settlement Signals for Staking Accounting
SEC Chair Gary Gensler stated that staking-as-a-service providers must register and provide full disclosure alongside investor protection. While the settlement is specific to Kraken and does not automatically prohibit all staking services, it signals that the SEC views pooled, custodied staking arrangements with significant scepticism. The settlement followed charges against other firms and a separate $45 million settlement with crypto exchange Nexo, suggesting a sustained enforcement pattern rather than a one-off action.
For accounting and audit teams, the staking classification question is not purely a legal one. If staking rewards from a pooled programme are re-characterised as securities income rather than yield, the accounting treatment, recognition timing, and disclosure requirements all shift. Firms advising clients with US staking exposure should review how those arrangements are currently recorded and whether the Kraken settlement changes the risk profile of that treatment.
Joint US-UK Ransomware Sanctions and Crypto Address Risk
The United States Office of Foreign Assets Control (OFAC) and the UK's Office of Foreign Sanctions Implementation (OFSI) issued joint sanctions against seven members of the Trickbot cybercrime group, marking OFSI's first ransomware-related sanctions action. The individuals are connected to major ransomware campaigns. OFSI also published fresh guidance on the sanctions compliance implications of ransomware payments.
Neither OFAC nor OFSI published crypto addresses on their sanctions lists for these individuals at the time of the action. However, the joint action reinforces that ransomware-linked actors are an active sanctions screening concern. VASPs and their advisers should ensure that blockchain screening tools are updated promptly when new designations appear and that ransomware payment compliance policies reference both OFAC and OFSI requirements, particularly for firms with operations in both jurisdictions. Given recent enforcement actions, including those covered in our analysis of the Manhattan US Attorney's sanctions probe of a major exchange, the direction of travel from US and UK authorities is unmistakably toward tighter enforcement.
Kazakhstan's AFSA Launches Crypto Regulatory Consultation
The Astana Financial Services Authority (AFSA), the independent regulator for the Astana International Financial Center in Kazakhstan, has opened a consultation on a proposed crypto regulatory framework. The AFSA is seeking to raise local regulatory standards for digital assets with the twin aims of attracting investment and managing the risks associated with the sector. Firms with clients operating in or considering Central Asian markets should monitor the AFSA consultation, as its outcome will define the licensing and compliance baseline for that jurisdiction.
Practical Next Steps for Accounting Firms and CFOs
The VARA framework, the SEC's staking enforcement, and the joint US-UK ransomware sanctions action together represent a significant uplift in the compliance demands facing VASPs and the firms that advise them. Taken together, they point toward a few concrete priorities.
Audit and Remediation Checklist
First, any VASP with a Dubai presence or ambitions to obtain a VARA licence should conduct a gap analysis against the full suite of rulebooks, covering AML/CFT controls, Travel Rule compliance, unhosted wallet risk management, blockchain analytics capability, market conduct policies, advertising review processes, and asset segregation procedures.
Second, any AEC exposure in Dubai-facing operations must be identified and eliminated, with documentation supporting the clean-up. Third, staking arrangements with US investor access should be reviewed in light of the Kraken settlement, with particular attention to whether the pooling and custody structure resembles what the SEC found objectionable. Fourth, sanctions screening workflows should be confirmed to cover both OFAC and OFSI designations, with documented processes for acting on new additions to either list.
Firms already working through the implications of tightening AML rules globally, including across recent UAE enforcement actions, will recognise these steps as part of a consistent pattern of supervisory escalation. The VARA framework is a signal, not just a rulebook: Dubai is serious about being a well-regulated hub, and the compliance bar has been set high.
Source: Elliptic
Frequently Asked Questions
What does VARA's privacy coin ban mean for a VASP with existing Monero or Zcash holdings?
Any VASP operating under VARA's jurisdiction must not offer trading in anonymity-enhanced cryptocurrencies. If a firm previously held Monero, Zcash, or similar assets on behalf of Dubai customers, it needs to wind down those positions in an orderly and documented way, with clear accounting records showing disposal date, pricing, and method. Residual balances in custody or cold storage would constitute a regulatory breach, not just an accounting issue.
Does the Kraken SEC settlement mean all staking services are now prohibited in the US?
No. The settlement is specific to Kraken's staking-as-a-service model, which involved pooling customer assets under Kraken's custody in exchange for returns. The SEC has not issued a blanket prohibition on all staking services. However, the settlement signals that similar pooled, custodied arrangements will attract scrutiny, and VASPs offering comparable products to US investors should take legal and accounting advice on how those programmes are structured and disclosed.
How does VARA's AML/CFT framework relate to FATF standards?
VARA has explicitly aligned its AML/CFT requirements with FATF standards, including the Travel Rule. VASPs must conduct customer due diligence, monitor transactions for suspicious activity, comply with the Travel Rule for qualifying transfers, and manage risks from unhosted wallet interactions. The alignment means that VASPs already meeting FATF-compliant frameworks in other jurisdictions will have a familiar baseline, though VARA's specific implementation requirements still need to be mapped carefully.
What do the joint OFAC and OFSI ransomware sanctions mean for VASPs with cross-border operations?
VASPs operating in both the US and UK must screen against both OFAC and OFSI sanctions lists. The joint action targeting Trickbot members, and OFSI's new guidance on ransomware payment compliance, confirm that both regulators treat ransomware-linked activity as a live enforcement priority. Screening workflows should be confirmed to cover both lists, and any ransomware payment compliance policy should reference both jurisdictions' requirements explicitly.
How should crypto accounting software handle the VARA asset segregation requirement?
VARA requires VASPs to keep customer assets strictly segregated from proprietary assets and to hold adequate financial resources on customers' behalf. From an accounting infrastructure perspective, this means the chart of accounts and wallet management systems must maintain a clear, auditable separation between customer-facing and firm-facing balances at all times. Any digital asset accounting software supporting a Dubai-licensed VASP should be capable of producing segregated balance reports on demand for regulatory review.
