Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · UAE

How to manage crypto sanctions exposure under UAE

A virtual-asset exchange licensed in a Gulf financial centre onboards a corporate client. Wallet-screening flags a transaction linked to an address cluster associated with a designated entity. The compliance team is uncertain: does the UAE's financial-sanctions regime capture this wallet? Which authority governs? Is there a reporting obligation, and within what window? These questions are not hypothetical. They arise in our practice with increasing regularity as the UAE cements its position as a significant virtual-asset hub.

Managing crypto and VASP sanctions compliance under the UAE regime requires a virtual-asset service provider to screen against the UAE's own consolidated target list, apply the financial-sanctions obligations set out under the applicable national regime, and follow the reporting requirements administered by the UAE's competent authorities – including the Executive Office for Control and Non-Proliferation and the relevant supervisory bodies under the UAE's federal and emirate-level financial-crime rules. Non-compliance carries civil and criminal exposure. The regime operates alongside, not in isolation from, the OFAC, OFSI, and EU sanctions systems that many UAE-licensed VASPs face through their correspondent relationships and their clients' global footprints.

This guide works through the key steps for a VASP or crypto business that needs to build or stress-test its UAE sanctions compliance programme: governing authority, the screening obligation, the ownership and control test, cross-border exposure, risk flags, and when to instruct counsel.

What authority governs crypto and VASP sanctions compliance in the UAE?

The UAE's financial-sanctions regime is administered at the federal level, with the Executive Office for Control and Non-Proliferation – known as the Executive Office – holding primary responsibility for maintaining the UAE's local target list and issuing guidance to obligated entities. The Central Bank of the UAE supervises financial institutions, including those handling virtual assets under its remit. The Virtual Assets Regulatory Authority (VARA) in the Emirate of Dubai and the Financial Services Regulatory Authority (FSRA) in Abu Dhabi Global Market (ADGM) carry supervisory responsibility for licensed virtual-asset businesses within their respective jurisdictions.

For a VASP licensed by VARA in Dubai, sanctions obligations flow from the federal regime and are reinforced by VARA's rulebook, which requires VASPs to screen transactions and maintain effective financial-crime controls. For a VASP licensed by the FSRA in ADGM, the position is analogous: the FSRA's financial-crime framework incorporates the federal sanctions obligations and imposes its own supervisory expectations. In practice, this means a UAE-licensed crypto business must answer to multiple supervisors, not a single authority.

The legal basis for the UAE's autonomous sanctions measures draws on the country's federal legislation on combating money-laundering, terrorism financing, and the financing of illegal organisations, as well as its obligations under United Nations Security Council resolutions. The UN Consolidated List is directly operative under UAE law. Any person or entity that appears on the UN Consolidated List is subject to asset-freezing obligations under the applicable UAE federal instruments, without need for a separate domestic listing decision.

For a VASP serving clients or processing transactions with a cross-border dimension, this multi-layered authority structure is not merely academic. In our experience, VASPs that map their obligations only to the VARA or FSRA rulebook, and overlook the federal sanctions layer and the UN list, carry material compliance gaps.

Step 1 – Map the screening obligation and build a list hierarchy

The first operational step is to establish a clear hierarchy of the lists that a UAE-licensed VASP must screen against, and to confirm that its transaction-monitoring and wallet-screening tools cover every list in that hierarchy.

The core lists are: the UAE's own local target list maintained by the Executive Office; the UN Security Council Consolidated List; and, where the VASP's correspondent relationships or client base creates secondary-sanctions exposure, the OFAC SDN List and the EU and UK consolidated lists. A VASP that screens only against one or two of these lists is exposed on the others.

A common structural weakness we see in practice is the treatment of wallet addresses. Many compliance programmes screen counterparty names at onboarding but do not maintain continuous wallet-address screening against updated blockchain analytics outputs. The UAE's supervisors expect controls that reflect the specific risks of virtual-asset transactions, including the pseudonymous nature of on-chain activity. Name-matching alone is insufficient.

Practical steps for the list hierarchy:

  • Confirm that your sanctions-screening system ingests the UAE Executive Office list, the UN Consolidated List, and the relevant international lists on a frequency that reflects the pace of updates.
  • Integrate blockchain analytics tooling so that wallet addresses associated with designated entities trigger alerts at the point of transaction, not only at onboarding.
  • Document the list hierarchy and the update cadence in your compliance-programme policies. Supervisors examine this documentation during inspections.
  • Define clear escalation paths: who reviews an alert, who decides on the transaction, and who reports externally if a match is confirmed.

Does your current tooling produce a match on all four lists, or does it rely on a single consolidated feed that may not capture the UAE domestic list in real time? That is a question worth testing before a supervisor asks it.

Step 2 – Apply the ownership and control test to corporate clients

Screening a client's name against a list is the starting point, not the end. The harder question is whether a non-listed client is caught because of its ownership or control by a listed person or entity. The UAE's federal sanctions obligations, consistent with international norms, extend to entities that are owned or controlled by designated persons, even where the entity itself does not appear on any list.

Under the ownership and control test applied in the UAE (which mirrors the approach taken in the EU and UK regimes), the question is whether a designated person holds a controlling interest in or exercises effective control over the corporate client. This is a broader test than OFAC's 50 percent rule (OFAC's mechanical rule treating entities owned 50 percent or more by blocked persons as themselves blocked). The UAE and EU/UK position requires the VASP to look beyond bare ownership percentages and to assess whether a designated person exercises effective control through contractual arrangements, board composition, veto rights, or economic dependency.

In our cross-border practice, this divergence creates real operational friction. A VASP that applies a strict 50-percent threshold for all clients – because that is how OFAC frames the rule – may clear a corporate client that would be caught under the UAE's and EU's broader control analysis. The safer approach is to apply the most conservative applicable test across the client's full jurisdictional exposure.

For a crypto business, the ownership and control analysis applies not only to the corporate client as a legal entity but also to the beneficial owners behind the wallet. Where a wallet is associated with a legal structure, the VASP must trace through that structure to identify whether any designated person owns or controls it. Layered structures – foundations, trusts, discretionary arrangements – require particular attention.

Step 3 – Identify and manage cross-border sanctions exposure

A UAE-licensed VASP rarely operates in a purely domestic environment. Cross-border exposure arises in at least three ways: through US-dollar correspondent banking relationships that bring OFAC jurisdiction into play; through European clients or counterparties that create EU-regime obligations for the VASP's European group entities; and through the secondary-sanctions risk that US law creates for non-US persons dealing in sectors or with persons targeted by US secondary-sanctions measures.

Secondary sanctions (US measures that expose non-US persons to restrictions for conduct entirely outside the United States) are particularly significant for Gulf-based VASPs. A UAE-licensed exchange that processes transactions for a counterparty targeted by US secondary-sanctions programmes may face the risk of correspondent banking restrictions, even if the transaction is technically lawful under UAE domestic law. The cross-border angle is not optional analysis: it is central to the risk assessment.

In addition, VASPs licensed in ADGM that transact with UK-nexus counterparties must apply the UK's financial sanctions obligations (administered by OFSI, the Office of Financial Sanctions Implementation) to those transactions. OFSI's enforcement posture has strengthened markedly, and its reporting obligation – which requires a firm to report knowledge or reasonable cause to suspect that a person is a designated person or has committed a breach – operates on a short statutory window. Missing that window is itself a breach.

The position above covers the standard cross-border case. Your facts – the counterparty's jurisdiction, the currency and routing of the transaction, the structure of your correspondent relationships – change the analysis materially.

For a confidential review of your cross-border exposure, contact Calder & Vance at info@caldervance.com.

Step 4 – Handle a sanctions alert: the decision sequence

When a screening alert fires – whether at onboarding, at the point of a transaction, or as a result of a retrospective review – the VASP's response must follow a defined decision sequence. Acting without a clear process risks both regulatory non-compliance and unnecessary commercial disruption.

The decision sequence for a UAE-licensed VASP:

  1. Triage the alert. Is this a true match (the client or counterparty is the designated person) or a false positive (a name or identifier that resembles but does not correspond to the listed entry)? Apply your defined triage criteria, document the reasoning, and retain the record.
  2. Freeze pending investigation. Where the alert cannot immediately be resolved as a false positive, freeze the transaction or the account pending a full review. Acting on a transaction while a plausible sanctions match is unresolved is a high-risk decision under any of the UAE, UK, or EU regimes.
  3. Escalate internally. The alert should reach the MLRO (Money Laundering Reporting Officer) or the designated sanctions officer within your defined escalation window. Document the escalation and the decision-maker's assessment.
  4. Assess reporting obligation. The UAE's federal regime and the relevant supervisory frameworks impose reporting obligations where a VASP has knowledge or reasonable cause to suspect that property is subject to a sanctions obligation. Assess whether the facts trigger the reporting threshold, identify the correct reporting channel (the Executive Office, the Central Bank, or the relevant financial-intelligence unit), and act within the statutory window. Do not let uncertainty about the exact window cause delay: report early and preserve the record.
  5. Seek legal advice. Where the matter is ambiguous – ownership structures are unclear, the nexus to the UAE list is indirect, or cross-border issues arise – instruct counsel before making the final decision to proceed or refuse. An early legal review is far less costly than a post-breach enforcement response.
  6. Document everything. Record-keeping obligations under the UAE financial-crime rules and the VARA/FSRA frameworks require that relevant records are retained for a period that reflects the applicable regulatory expectation. Verify the current retention period before relying on any summary of it.

If a transaction has already been processed and a subsequent review reveals a possible sanctions issue, an early assessment can preserve options that narrow with time. For an urgent review, write to info@caldervance.com.

What are the key risk flags specific to crypto and VASP operations in the UAE?

Beyond the standard sanctions-screening risks, virtual-asset businesses operating in the UAE face a set of sector-specific risk flags that a traditional financial-institution compliance programme will not fully address.

Peer-to-peer transaction volumes. P2P transactions are structurally harder to screen than exchange-intermediated transactions. A high volume of P2P flows through the platform, particularly where the counterparty wallet is not identified to a named individual, requires enhanced monitoring logic, not standard name-screening.

Cross-chain and mixer activity. Transactions that pass through mixing or tumbling services, or that route across multiple blockchains before arriving at the VASP's platform, are a recognised red flag under financial-crime typologies. Where blockchain analytics identifies such activity in the chain of custody of incoming funds, the VASP must assess whether the origin includes a sanctioned address cluster.

Jurisdiction of the counterparty VASP. Where your platform receives transfers from a foreign VASP, the risk profile of that VASP matters: its licensing status, its own sanctions-screening standards, and whether its home jurisdiction's regime is regarded as equivalent. A transfer from an unlicensed or weakly supervised VASP in a jurisdiction with limited sanctions-compliance standards warrants enhanced due diligence on the underlying client and transaction.

Rapid onboarding and large initial transactions. A pattern of fast onboarding followed immediately by a high-value transfer is a common indicator in enforcement typologies. Under the VARA and FSRA frameworks, enhanced due diligence is required where the risk profile warrants it.

Inconsistency between stated business and transaction pattern. A client that describes its business as a small trading entity but generates transaction volumes associated with institutional activity raises the question of whether the beneficial ownership and control picture is accurate. This pattern can indicate an undisclosed designated person in the ownership chain.

A myth that circulates in the Gulf VASP sector is that the UAE's sanctions regime is less rigorous than the OFAC or EU regimes, and that a business licensed in the UAE is therefore operating in a lower-risk environment from a sanctions perspective. This is not correct. The UAE has materially strengthened its financial-sanctions architecture in recent years, aligned its regime to FATF standards, and its supervisors – VARA, FSRA, and the Central Bank – conduct active inspections and impose enforcement measures. The severity of the UAE's regime should not be underestimated relative to the major Western regimes.

When should a UAE-licensed VASP involve sanctions counsel?

Certain situations warrant immediate instruction of legal counsel rather than internal resolution alone. The question is not whether counsel can help: it is whether the cost of delay exceeds the cost of early instruction.

Involve counsel when:

  • A screening alert produces a credible match that cannot be resolved as a false positive within your normal triage process, and the transaction or relationship is commercially significant.
  • A retrospective review identifies a transaction that may have involved a designated person, and the reporting obligation is now live or overdue.
  • A regulatory inspection has been notified, or an information request has been received from VARA, the FSRA, the Central Bank, or the Executive Office that touches on sanctions controls.
  • The platform is onboarding a client with a complex ownership structure that raises potential ownership-and-control questions under the UAE regime or any of the international regimes to which the platform has exposure.
  • A correspondent bank has raised concerns or threatened to restrict access based on the VASP's customer base or transaction flows.
  • The VASP is restructuring, being acquired, or seeking a new regulatory licence, and the transaction involves counterparties or assets with any sanctions dimension.

In a recent matter, a digital-asset platform licensed in a Gulf jurisdiction received a correspondent-bank inquiry questioning the platform's exposure to a cluster of wallets flagged in the bank's own blockchain-analytics review. We were instructed to assess the platform's screening coverage, map the ownership-and-control questions for the relevant accounts, and advise on the response to the correspondent. The matter required analysis under the applicable domestic regime, the OFAC SDN framework, and the relevant EU regime. Acting quickly preserved the correspondent relationship and produced a documented compliance position that satisfied the bank's requirements.

Related practices

Frequently asked questions

What are the steps to manage crypto sanctions exposure under UAE?
The core steps are: establish a list hierarchy that covers the UAE Executive Office list, the UN Consolidated List, and the relevant international lists; apply continuous wallet-address screening through blockchain analytics tooling; test every corporate client's ownership and control structure against the UAE's control-based test; define a decision sequence for alerts that includes a triage, a freeze, internal escalation, and a structured assessment of the reporting obligation; document every step; and instruct counsel where the facts are ambiguous or where a reporting obligation has been triggered. The cross-border dimension – OFAC secondary-sanctions risk, OFSI reporting for UK-nexus transactions – must be mapped separately and cannot be assumed to be covered by domestic UAE compliance alone.
What is the most common mistake in crypto and VASP sanctions compliance?
The most common mistake is treating sanctions compliance as a name-matching exercise at onboarding. Name-screening at onboarding is necessary but insufficient. It does not capture wallet-address exposure, does not address the ongoing transaction-monitoring obligation, and does not apply the ownership-and-control test to clients with complex or layered structures. We regularly advise VASPs that have passed regulatory onboarding reviews but carry material gaps in their continuous-monitoring and control-testing capabilities. A programme that is technically documented but not operationally tested is a compliance programme in name only.
How does UAE differ from other regimes here?
The UAE's regime is distinctive in three respects. First, it operates through a federal-plus-emirate supervisory structure: a VASP licensed by VARA in Dubai and one licensed by the FSRA in ADGM face different supervisory relationships, even though the federal sanctions obligations apply to both. Second, the UAE applies a control-based ownership test – broader than OFAC's mechanical 50-percent rule – meaning that a corporate client may be caught even where no single designated person holds a majority interest. Third, the UN Consolidated List is directly operative under UAE law without need for a separate domestic listing decision, which means a UN designation produces immediate obligations for UAE-licensed VASPs without any domestic implementation delay.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.