UAE regulation — VARA
Dubai's Virtual Assets Regulatory Authority expects licensed VASPs to screen customers and counterparties, monitor for sanctions exposure, and keep files a regulator can inspect. We deliver exactly that.
VARA-licensed and licence-applicant virtual asset firms in Dubai need to show that they know their customers and counterparties, monitor them, and can produce the file behind any decision. Here is the order we build that in.
Step by step
Exchange, broker-dealer, custody, lending, transfer, advisory — each activity brings different counterparties and different risk. List them before designing controls.
A named, empowered compliance officer for Dubai operations, with a documented reporting line and the authority to refuse or exit a relationship.
Rate retail versus institutional flows, jurisdictions served, and product risk. This is the document that explains your onboarding thresholds.
Sanctions, PEP and adverse-media screening at onboarding for customers, beneficial owners, market makers and institutional counterparties, plus identity-fraud signals through Emailage.
Ongoing re-screening with alert workflows, so a counterparty's change in status reaches your compliance team the day it happens rather than at the next review.
Every search, alert and disposition recorded in a structured file you can hand over on request — the same pack that supports a licence application.
What we deliver
Screen retail and institutional customers at onboarding and continuously thereafter against sanctions, PEP and adverse-media sources.
Ongoing monitoring with alert workflows, so a change in a counterparty's status surfaces the day it happens.
Enhanced reports on institutional counterparties, market makers and corporate clients — ownership, reputation, litigation.
Digital identity risk scoring through Emailage and related tools to catch synthetic and stolen identities at onboarding.
Every search, alert and disposition recorded in a structured case file you can hand to VARA on request.
Help shaping screening procedures and training compliance staff on investigation and escalation.
FAQs
A mapped list of your licensed activities, a named compliance officer, a risk assessment, screening of customers, beneficial owners and institutional counterparties, ongoing monitoring, and case files a regulator can inspect. We provide the screening data and the record-keeping behind them.
Yes. Applicants often need to evidence credible screening and due-diligence arrangements in their application pack, so we set those up before a licence is granted and keep them running afterwards.
VARA-licensed firms are expected to know who they are dealing with — customers, counterparties and beneficial owners — and to screen them against sanctions and other risk sources. We supply the data and workflows; your compliance officers set the risk appetite.
Our focus is the legal-entity and identity side — who owns and controls the parties you deal with. Blockchain analytics tools cover on-chain wallet risk, and we can work alongside whichever chain-screening provider you use.
Yes. Many applicants need to show credible screening and due-diligence arrangements as part of their application pack. We can stand those up before your licence is granted.
Standard list screening can typically be operational within days once scope is agreed. More complex institutional due-diligence programmes are scoped individually.
This page describes the services ICG MECOS provides to regulated businesses. It is not legal advice, and it does not reproduce or summarise UAE law — always refer to the published requirements of your supervisor.
All regulators