Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · UAE

Crypto and VASP sanctions compliance under UAE: procedure and pitfalls

A virtual-asset exchange registered in the UAE onboards a new institutional client. The compliance officer runs the wallet address and the beneficial owner through the firm's screening system. One name returns a partial match against a UN Consolidated List entry. The officer is unsure whether the UAE regime requires immediate blocking, a licence, or a suspicious-transaction report – and unsure whether OFAC's secondary-sanctions reach makes the question simultaneously a US problem. As of July 2026, the UAE's regulatory architecture for virtual-asset service providers has matured considerably, but the intersection of blockchain traceability, multi-regime designation lists, and real-time transaction flows creates compliance questions that differ in texture from those facing traditional financial institutions.

Crypto and VASP sanctions compliance under UAE requires a VASP to screen customers, wallet addresses, and transaction counterparties against the UAE's own local terrorist-financing and sanctions lists, the UN Consolidated List, and – critically – the major extraterritorial regimes including OFAC's SDN List (OFAC's list of Specially Designated Nationals and blocked persons) and the EU consolidated list. The UAE's financial-sanctions obligations are administered by the Executive Office for Control and Non-Proliferation (EOCN) and enforced through the Central Bank of the UAE and the Virtual Assets Regulatory Authority (VARA) in Dubai, together with the Financial Services Regulatory Authority (FSRA) in Abu Dhabi Global Market and the Dubai Financial Services Authority (DFSA) in the Dubai International Financial Centre. A VASP that screens only one list and ignores the others is exposed across multiple simultaneous regimes.

This guide sets out the governing authority, the step-by-step screening and reporting procedure, the cross-regime comparison that every UAE-based VASP must understand, the risk flags that most commonly produce enforcement referrals, and the point at which in-house teams should involve external sanctions counsel.

Who governs VASP sanctions compliance in the UAE?

The UAE sanctions compliance architecture for virtual-asset businesses is built across several parallel regulatory bodies, each with distinct but overlapping remits, and the starting obligation for any VASP is to identify which authority licenses it and which designation lists it must screen.

The EOCN coordinates the UAE's national Local Terrorist Designation List (the domestic list of individuals and entities designated under UAE law) and the Cabinet List (designations issued by UAE Cabinet resolution, often mirroring UN Security Council listings). Both lists generate hard prohibitions on dealing: a VASP must freeze assets and report immediately on a hit, with no room for a business-judgement delay.

VARA issues the primary framework for VASPs operating in the Emirate of Dubai outside the financial free zones. The FSRA governs VASPs in Abu Dhabi Global Market. The DFSA governs those in the Dubai International Financial Centre. Each authority incorporates the UAE's national financial-sanctions obligations and adds sector-specific AML and controls requirements relevant to virtual assets. In our experience, VASPs that operate across more than one of these zones frequently under-estimate the extent to which the AML and sanctions obligations of each authority layer on top of, rather than replace, the national baseline.

The UN Security Council Consolidated List is incorporated by reference into UAE law. A listing by the Security Council creates an immediate obligation under the applicable UAE Cabinet instruments, without the need for a separate domestic designation act. That automatic incorporation mechanism is often overlooked by compliance teams focused only on the EOCN lists.

Step 1 – Build the right screening scope before the first transaction

Effective sanctions screening for a UAE VASP begins not at onboarding but at programme design: the compliance team must define the complete universe of lists it will screen against, the minimum data fields it will collect, and the technical approach for wallet-address monitoring before any customer relationship opens.

At a minimum, a UAE VASP should screen against: the EOCN's Local Terrorist Designation List; the Cabinet List; the UN Security Council Consolidated List; OFAC's SDN List and, where relevant to the customer base, OFAC's other programme lists; the EU consolidated list; and the OFSI (UK) Consolidated List. VASPs serving institutional counterparties in or connected to Canada, Australia, Switzerland, or Japan should add the relevant national lists from those jurisdictions. The argument that "our licence is UAE, so we only screen UAE lists" is technically indefensible once a payment routes through a correspondent bank with US-dollar clearing, because at that point OFAC's rules apply regardless of the VASP's place of incorporation.

Wallet-address screening is a UAE-specific operational challenge. Unlike a traditional bank account, a wallet address is pseudonymous and its beneficial ownership is not self-evident. A VASP should use blockchain analytics to map known addresses against published sanction-associated clusters, and should document its methodology. The documentation is not merely good practice; it is a demonstrable element of the proportionality defence available in enforcement proceedings if a transaction is later found to involve a sanctioned address.

How often should the screening universe be refreshed? As a practical matter, OFAC updates its SDN List without advance notice, and UN listings can follow emergency Security Council procedures within hours of a trigger event. The programme must handle intraday list updates for any VASP operating at meaningful volume. A nightly batch refresh is not adequate for that operating model.

Step 2 – Customer onboarding and the travel-rule intersection

The UAE has implemented a version of the Financial Action Task Force travel rule, requiring originating VASPs to transmit identifying information about the originator and beneficiary to the receiving VASP for transactions above the applicable threshold. That transmission obligation and the sanctions-screening obligation interact in a way that creates a sequencing decision for compliance teams.

The correct sequence is: screen the originator, the beneficiary, and the receiving VASP against all applicable lists before transmitting the transaction data or completing the transfer. If a match arises at any point in that sequence, the transaction must be paused and the hit assessed before proceeding. Transmitting first and screening later is an error we see regularly in smaller VASPs that built their travel-rule compliance workflow before building their sanctions workflow, and then bolted the two together without re-sequencing them.

At onboarding, a VASP must collect sufficient information to screen the beneficial owner, not just the account holder. The 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked) applies to the wallet-holding entity just as it applies to a corporate bank-account holder. Where a customer is a corporate entity, the VASP needs the ownership chain to a level of confidence sufficient to confirm that no blocked person holds 50 percent or more, directly or indirectly. Under OFSI and EU rules the test extends to ownership and control (the UK and EU test for whether a non-listed entity is caught through a listed person), which can catch entities where a blocked person exercises dominant influence without reaching the 50 percent threshold. A UAE VASP serving customers with UK or EU nexus should apply the stricter test.

In a recent matter, a payment-infrastructure firm providing services to a UAE-licensed VASP identified at the travel-rule data stage that the receiving VASP's largest institutional client had a beneficial owner with a name matching an OFSI designation. The payment firm paused settlement, notified its own compliance function, and engaged us to assess whether the match was a false positive. We conducted an accelerated ownership-and-control analysis. The matter was resolved, and the payment firm was able to document to OFSI that it had acted promptly and in good faith.

Step 3 – What to do when a hit arises: freeze, report, and seek a licence

When a VASP identifies a match against a sanctions list, the immediate action is asset-freezing and internal escalation – not a unilateral decision to proceed or a quiet decline of the transaction without documentation.

Under the UAE national obligations, an asset freeze must be implemented and a report made to the relevant authority within a short statutory window. The exact reporting timeline is set by the applicable UAE Cabinet instrument and VARA / FSRA / DFSA rules; verify the current position before relying on it, as timelines have been tightened in recent amendments. What is certain is that delay in freezing, or failure to report within the prescribed window, is itself an offence separate from the underlying sanctions violation.

Alongside the UAE reporting obligation, the VASP must consider whether a parallel OFAC reporting obligation arises. OFAC requires that persons subject to US jurisdiction report blocked transactions. A UAE VASP is not itself subject to US jurisdiction unless it has a US nexus – US shareholders, US customers, US-dollar clearing, or a US-based technology provider. Each of those connections, individually, can create a reporting obligation. We advise clients to map their US nexus annually and update the conclusion after any material change in their business model.

If the blocked assets belong to a party who has a legitimate business case for a licence – for example, to repatriate funds or to complete a humanitarian transaction – the UAE regime provides a licensing mechanism through the EOCN. Under OFAC, a specific licence (a case-by-case authorisation to conduct an otherwise prohibited transaction) can be applied for from the Office of Foreign Assets Control. Under OFSI, a comparable specific licence is available. The three licensing processes run on different timelines and require different supporting documentation; running them in parallel is possible and sometimes necessary, but it requires coordination across jurisdictions from the outset.

How does UAE VASP compliance compare with OFAC and OFSI requirements?

The UAE, OFAC, and OFSI regimes share a common prohibition structure – freeze assets, do not deal, report – but they diverge in ways that directly affect a VASP's compliance architecture, and those divergences are most acute in the virtual-asset context.

The first divergence is the ownership and control test. OFAC's 50 percent rule is a hard numerical threshold. OFSI and the EU apply a control test that can capture entities below the 50 percent threshold if a blocked person can veto board decisions, appoint a majority of directors, or otherwise direct strategy. For a UAE VASP with institutional customers that have UK or EU shareholders or governance structures, the OFSI and EU position can sweep in customers that OFAC's test would leave unaffected. Applying the most restrictive test across the board is the safest operational approach.

The second divergence is in reporting timelines. OFSI requires reporting to the Secretary of State as soon as practicable once a person knows or suspects they hold funds or economic resources of a designated person; the reporting obligation is ongoing. OFAC's reporting requirements operate on a different cycle and with different form requirements. The UAE national obligation has its own timeline. A VASP that receives instructions from a customer who may be designated must satisfy all three reporting obligations simultaneously if any US, UK, or UAE nexus is present.

The third divergence is enforcement posture and the treatment of voluntary self-disclosure. Under OFAC's penalty framework, a VSD (voluntary self-disclosure to a regulator) is a significant mitigating factor and can reduce the base penalty substantially. OFSI's enforcement guidance similarly treats voluntary self-disclosure as a mitigating factor. The UAE authorities have signalled alignment with international best practice on this point, though the formal treatment of VSDs in UAE proceedings is still developing. In our cross-border practice, we counsel clients to consider a coordinated multi-regime disclosure where a violation has a cross-border dimension – making a disclosure in one regime without considering the others can produce inconsistencies that complicate the position rather than improving it.

Does your compliance programme treat UAE, OFAC, and OFSI as three independent silos, or as three simultaneous obligations that require a unified response? For most VASPs with a cross-border customer base, the siloed approach is the one that produces enforcement risk.

Risk flags most likely to attract regulatory attention

Experience in advising VASPs across the UAE, US, and UK regimes produces a clear picture of the patterns that most often precede a regulatory inquiry or an enforcement referral. Understanding these flags in advance is more useful than diagnosing them after the fact.

The most common structural risk is an incomplete screening universe. A VASP that screens only the EOCN list and not the UN, OFAC, and OFSI lists will at some point permit a transaction involving a person listed on one of the others. The argument that the VASP was "only required" to screen the national list fails as soon as the transaction has a US-dollar leg, a correspondent bank with OFAC exposure, or a counterparty with UK nexus.

The second risk flag is a weak false-positive resolution process. Screening tools produce alerts. Many alerts are false positives – a name match that, on investigation, does not correspond to the listed individual. The risk is not false positives per se; it is false positives resolved without documentation, or resolved by someone without the authority or the analytical tools to make that determination. An escalation policy that routes every alert to a senior compliance officer, requires a documented match-or-no-match conclusion, and retains that record is the baseline expectation of every regulator we encounter.

Third is inadequate wallet-address and blockchain analytics. A VASP that screens customer names but does not screen wallet addresses against known sanctions-associated clusters is operating a compliance programme that will miss a material category of exposure. Blockchain analytics tools have matured to the point where regulators consider their deployment a minimum expectation for any VASP of scale.

Fourth is the failure to re-screen on list updates. Existing customers who passed screening at onboarding can become designated after the relationship opens. Programme design must include a process for re-screening the active customer book whenever a material list update occurs.

Fifth is the travel-rule sequencing error described earlier. It is worth isolating because it is so frequent: completing a transfer before the compliance check is done, on the basis that "we will check it after," is a structural breach, not a process oversight.

If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com for a confidential assessment of your exposure.

When should a UAE VASP involve external sanctions counsel?

There are five situations in which the cost of not involving external counsel is materially higher than the cost of engaging early, and experience across UAE, OFAC, and OFSI matters makes those situations predictable.

First, when a screening alert cannot be resolved as a clear false positive by the internal team within the reporting window. The reporting window is short; a decision made under time pressure without adequate legal analysis is a decision made at risk.

Second, when the beneficial ownership of a customer entity cannot be confirmed through standard KYC procedures and the customer has a connection to a jurisdiction covered by a major sanctions programme. The ownership-mapping exercise, and the legal conclusion on whether the 50 percent or control test is met, requires a practitioner who can apply the rules of at least two simultaneous regimes.

Third, when a VASP is approached by a regulator – VARA, the FSRA, the DFSA, or a correspondent bank's compliance team – with questions about a specific transaction or customer. Responding without legal advice on the scope and limits of the inquiry is an unnecessary risk.

Fourth, when the VASP is planning a new product line, entering a new market, or onboarding a new institutional counterparty with a materially different risk profile. Programme design at that point is far cheaper than remediation after an incident.

Fifth, when a VASP discovers that a past transaction involved a person who was designated at the time, and the VASP did not identify the match. That is a potential violation. The question of whether to make a VSD, how to structure it, and whether to make it across multiple regimes simultaneously is a legal question with real consequence for the eventual outcome.

We regularly advise VASPs and the financial institutions that service them on compliance-programme design, transaction reviews, and escalation protocols across the UAE, OFAC, and OFSI regimes. The position above covers the standard case. Your facts – the counterparty, the asset type, the correspondent chain, the regimes in play – change the analysis.

For an assessment of your VASP's sanctions exposure under the UAE regime and across the major extraterritorial frameworks, contact Calder & Vance at info@caldervance.com.

Related practices

Frequently asked questions

What are the steps to manage crypto sanctions exposure under UAE?
The steps are: establish a complete screening universe covering EOCN, UN, OFAC, and OFSI lists; screen customers, beneficial owners, and wallet addresses at onboarding and on every material list update; implement a documented false-positive resolution process; sequence travel-rule data transmission after, not before, the compliance check; freeze and report immediately on a confirmed match; and maintain records of every alert, resolution, and decision for the period required by the applicable UAE and international standards. Verify current reporting timelines before relying on any figure cited here.
What is the most common mistake in crypto and VASP sanctions compliance?
The most common mistake is screening only the national UAE list and ignoring the UN Consolidated List, OFAC's SDN List, and the OFSI Consolidated List. A VASP whose correspondent bank has US-dollar clearing, or whose customer base includes persons with UK or EU nexus, is exposed to all those regimes simultaneously. Treating UAE sanctions compliance as a purely local exercise is the single structural error that most frequently produces multi-regime enforcement risk.
How does UAE differ from other regimes here?
The UAE national regime incorporates UN Security Council listings by reference, creating automatic obligations that do not require a separate domestic designation act. OFAC's ownership test is a hard 50 percent numerical threshold; OFSI and the EU apply a control test that can capture entities below that line. The UAE's licensing mechanism operates through the EOCN and differs in process and timeline from both OFAC's specific-licence procedure and OFSI's comparable process. A VASP with cross-border exposure must satisfy all applicable regimes, and where they diverge, the stricter obligation governs.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.