Subscribe

Dubai Makes AML Risk Assessment a Continuing Operating Requirement for VASPs

Dubai’s VARA is requiring virtual asset firms to treat financial crime risk assessment as an active operating process. The rule links recurring assessment directly to controls and resource allocation rather than leaving it as a static compliance document.

Audio Audio version is being prepared.
Dubai financial regulation and virtual asset compliance infrastructure.

Dubai’s Virtual Assets Regulatory Authority has published guidance on AML and CFT business risk assessments for licensed virtual asset service providers.

VARA’s rules require VASPs to assess money laundering and terrorist financing risks specific to the nature, size and complexity of their businesses.

Those assessments must be repeated at intervals no longer than three months and whenever a significant change occurs in the assets, technologies, products, services, business practices or other risk factors relevant to the firm.

VARA also requires the results to feed directly into the company’s AML and CFT policies, systems and controls as well as the allocation of resources used to manage those risks.

The significance is less about the existence of another risk assessment and more about its operating frequency.

A risk assessment performed once a year can become an exercise in documenting the business as it existed months earlier. A three month maximum interval forces the assessment closer to changes in products, client behaviour, technology and transaction flows.

That matters in virtual asset businesses because the operating environment can change quickly.

A new asset, execution route, wallet model or customer segment can alter the risk profile without changing the company’s headline business description. A control environment that was appropriate for the previous workflow may no longer address the new one.

VARA also explicitly connects the assessment to resource allocation.

That makes the assessment part of management decision making. If a VASP identifies greater exposure in one activity, it needs to be able to show how controls, systems and people were adjusted in response.

The regulator can therefore examine not only whether the risk was identified, but whether the business acted on the result.

What to watch

The practical test will be how licensed firms maintain evidence between assessment cycles.

A quarterly document by itself is not the objective. The important question is whether changes in risk are reflected in transaction monitoring, customer controls, governance and staffing while the business continues to operate.

For firms building or expanding regulated virtual asset businesses in Dubai, AML governance is becoming a recurring operating process rather than a periodic compliance deliverable.