Dubai’s Virtual Assets Regulatory Authority has published guidance on AML and CFT business risk assessments for licensed virtual asset service providers.
VARA’s rules require VASPs to assess money laundering and terrorist financing risks specific to the nature, size and complexity of their businesses.
Those assessments must be repeated at intervals no longer than three months and whenever a significant change occurs in the assets, technologies, products, services, business practices or other risk factors relevant to the firm.
VARA also requires the results to feed directly into the company’s AML and CFT policies, systems and controls as well as the allocation of resources used to manage those risks.
The significance is less about the existence of another risk assessment and more about its operating frequency.
A risk assessment performed once a year can become an exercise in documenting the business as it existed months earlier. A three month maximum interval forces the assessment closer to changes in products, client behaviour, technology and transaction flows.
That matters in virtual asset businesses because the operating environment can change quickly.
A new asset, execution route, wallet model or customer segment can alter the risk profile without changing the company’s headline business description. A control environment that was appropriate for the previous workflow may no longer address the new one.
VARA also explicitly connects the assessment to resource allocation.
That makes the assessment part of management decision making. If a VASP identifies greater exposure in one activity, it needs to be able to show how controls, systems and people were adjusted in response.
The regulator can therefore examine not only whether the risk was identified, but whether the business acted on the result.
What to watch
The practical test will be how licensed firms maintain evidence between assessment cycles.
A quarterly document by itself is not the objective. The important question is whether changes in risk are reflected in transaction monitoring, customer controls, governance and staffing while the business continues to operate.
For firms building or expanding regulated virtual asset businesses in Dubai, AML governance is becoming a recurring operating process rather than a periodic compliance deliverable.