Overview
The Central Bank is the federal financial regulator. Its mandate covers monetary policy, the supervision of banks and other licensed financial institutions, payment systems, AML/CFT supervision of those institutions, and consumer protection.
For a virtual-asset business it matters in three ways: it regulates payment tokens, it regulates the payment rails the business wants to use, and it stands behind every bank that will decide whether to open the account.
What it regulates
Payment tokens. The Payment Token Services Regulation brings payment token issuance, conversion and custody or transfer inside the Central Bank perimeter, sets out how dirham-backed payment tokens work, provides for registration of foreign payment tokens, and restricts the use of non-dirham tokens for domestic payments.
Payment services and stored value. The Retail Payment Services and Card Schemes Regulation and the Stored Value Facilities Regulation apply wherever a crypto business touches fiat wallets, on and off-ramps, or payment initiation. A firm that describes itself as an exchange but holds client fiat balances should read these before it reads anything else.
Financial institutions. Banks, finance companies, exchange houses and insurers, including their AML/CFT obligations.
Who needs a licence
Any person issuing a payment token, converting one, or holding or transferring one on behalf of others. Any person providing retail payment services or operating a stored value facility. The test is functional: what the arrangement does with client money, not what the product is called.
The perimeter question that matters most in practice is where the Central Bank ends and VARA, the SCA or a financial free-zone regulator begins. Payment activity, investment activity and virtual-asset activity are separate characterisations, and one arrangement can attract more than one.
Requirements
Legal form and minimum capital set by activity. Fit-and-proper assessment of controllers and senior management. Local presence and governance that demonstrably operates in the UAE. Outsourcing rules for anything material. IT and cyber standards. Safeguarding of client funds, which is a structural requirement and not a policy document. Compliance with the Consumer Protection Regulation and Standards, including disclosure and complaints handling.
Banking and legalisation of the business
Opening and keeping a UAE bank account is the step most businesses underestimate. Banks apply enhanced due diligence to virtual-asset clients as a matter of course. They will want the operating licence, the ownership chain to natural persons, credible source-of-funds evidence, a transaction-monitoring design they can understand, and a named compliance contact.
An operating licence is a precondition, not a decision. Where a bank declines, regulated electronic money institutions and payment service providers are sometimes a workable alternative, with their own limits that should be understood before they are relied on.
Protection and enforcement
Depositor and consumer protection, complaints escalation to the financial ombudsman, confidentiality and data protection obligations, and sanctions screening against the lists maintained by the UAE Executive Office for Control and Non-Proliferation.
The Central Bank imposes administrative sanctions, can revoke a licence, and publishes penalties. Enforcement is visible and should be treated as a live risk, not a remote one.
How we help
We characterise the flow of funds before anyone builds it, so the perimeter question is answered on paper rather than discovered in an application. We prepare payment token and payment services applications, draft the safeguarding and consumer-protection arrangements, and prepare the banking file — including the parts a bank will ask for that no regulator requires.
- 01
Structuring
Activity mapping, regulator selection, group and holding structure.
Not yet verified
- 02
Entity incorporation
Trade name, initial approval, lease, corporate documents.
Not yet verified
- 03
Regulatory initial approval
Permission to incorporate and build. Not permission to operate.
Not yet verified
- 04
Policies and technology build
Rulebook-mapped policies, custody and key management, technology audits.
Not yet verified
- 05
MLRO appointment and goAML registration
Entity and officer registration, sanctions screening, reporting workflow.
Not yet verified
- 06
Bank or EMI onboarding
Frequently the longest single dependency, and outside the regulator control.
Not yet verified
- 07
Full licence
Operational permission granted.
Not yet verified
- 08
Ongoing supervision
Reporting, audits, filings, variation of permission.
Not yet verified
Fees
These are the charges a licensee actually meets. Amounts are left blank until each one has been checked against the authority published schedule — an unverified figure is worse than none.
Licence or registration application
Differs between issuer, converter and custodian or transferor.
One-off
Not yet verified
Annual fee
Annual
Not yet verified
Client-fund safeguarding arrangements
Annual
Not yet verified
Capital to be held, not a fee
Minimum capital
Not a fee.
Variable
Not yet verified
Documents
Indicative categories. The exact bundle is activity-specific and the regulator may ask for more.
- Passport copy, valid at least six months
- Passport photograph, white background
- Proof of residential address, dated within three months
- Curriculum vitae
- Bank or professional reference letter
- Police clearance or good conduct certificate — Attestation chain required
- Source of wealth and source of funds evidence
- UAE entry stamp or visa page
- Certificate of incorporation — Attestation chain required
- Memorandum and articles of association — Attestation chain required
- Certificate of incumbency or good standing — Attestation chain required
- Board resolution approving the UAE entity — Attestation chain required
- Register of members and directors
- Ultimate beneficial owner declaration
- Group structure chart to natural persons
- Audited financial statements, most recent two years
- Power of attorney for the UAE representative — Attestation chain required
- Business plan with three-year financial projections
- AML/CFT policy and procedures manual
- Enterprise-wide money laundering risk assessment
- MLRO appointment letter and fit-and-proper file
- Compliance monitoring programme
- Targeted financial sanctions screening procedure
- Governance map and senior management functions
- Outsourcing register and material outsourcing agreements
- Complaints handling and consumer protection policy
- Technology architecture and infrastructure description
- Custody and key management model
- Hot, warm and cold wallet policy
- Penetration test and vulnerability assessment report
- Business continuity and disaster recovery plan
- Cyber incident response plan
- Transaction monitoring and blockchain analytics arrangements
Interaction with other regulators
Common questions
Are virtual assets legal tender in the UAE?
No. Virtual assets are not legal tender. The Central Bank regulates certain token activities as payment activities, which is a different question from whether anything is money.
Do we need CBUAE permission as well as a VARA licence?
If the business touches fiat, issues a payment token, or performs a payment service, quite possibly. The perimeters are drawn around different things, and it is common to sit inside two at once. The answer turns on the precise mechanics of the flow of funds, not on the label the business uses.
Why is the bank account harder than the licence?
Because a bank makes its own risk decision and is supervised on it. A licence is a precondition, not a guarantee. Enhanced due diligence, source-of-funds evidence and a credible transaction-monitoring story decide the outcome.
Sources
- CBUAE Payment Token Services Regulation — Licensing and registration of payment token issuers, converters and custodians
- CBUAE Retail Payment Services and Card Schemes Regulation
- CBUAE Stored Value Facilities Regulation
- CBUAE Consumer Protection Regulation and Standards