The UAE Travel Rule: What VASPs Need to Know
The United Arab Emirates (UAE) has implemented the Travel Rule, with the regulation applied to all Virtual Asset Service Providers (VASPs) operating across the UAE, including federal jurisdictions, Emirates, Free Zones, and Financial Free Zones.
TL;DR
- The UAE has implemented the FATF Travel Rule under its AML/CFT framework.
- VASPs must collect, verify, transmit, and retain required originator and beneficiary information.
- There is no de minimis threshold for Travel Rule information requirements; they apply to all qualifying VASP-to-VASP transfers.
- Identity verification is mandatory for transfers of AED 3,500 or more, or where suspicious activity is identified.
- Originator VASPs must ensure counterparties are appropriately regulated before executing transfers.
- Beneficiary and intermediary providers must monitor incoming transfers and manage incomplete or non-compliant transactions using a risk-based approach.
- Transfers involving self-hosted wallets require enhanced due diligence.
- Each Emirate will be supervised by its applicable supervisory authority, for example Dubai is overseen by VARA.
Understanding the Regulatory Obligations for Virtual Asset Service Providers
Scope of the Travel Rule in the UAE
The regulation applies to all Virtual Asset Service Providers (VASPs) operating within the UAE, including those licensed in the federal jurisdiction, individual Emirates, Free Zones, and Financial Free Zones.
The Travel Rule applies whenever a VASP transfers virtual assets on behalf of an originator to another VASP acting for a beneficiary, or receives virtual assets from another VASP on behalf of a beneficiary. Transaction fees (gas fees) are expressly excluded from the scope of the regulation.
Beyond the exchange of Travel Rule information, the framework requires VASPs to implement risk-based compliance controls, verify that counterparties are appropriately regulated, retain transaction records, monitor transfers for suspicious activity, and apply enhanced due diligence where higher-risk scenarios arise, including transactions involving self-hosted wallets.
Compliance Obligations for VASPs
The UAE Travel Rule requires VASPs to review their existing compliance frameworks and ensure that their policies, procedures, and technical controls adequately support Travel Rule compliance.
This includes implementing processes for collecting and transmitting Travel Rule information, conducting counterparty due diligence, managing incomplete or non-compliant transfers, maintaining appropriate records, and ensuring employees understand their regulatory responsibilities.
Where deficiencies are identified, firms should take prompt remedial action to avoid supervisory or enforcement measures by the relevant competent authority.
Regardless of whether a VASP is acting as the originator, beneficiary, or an intermediary provider, decisions to execute, delay, reject, or return a virtual asset transfer must be based on a risk-based assessment.
Where required Travel Rule information is missing, cannot be securely transmitted, or other compliance concerns arise, VASPs must evaluate the money laundering, terrorist financing, and proliferation financing risks associated with the transaction before determining the appropriate course of action.
This assessment should take into account factors such as the nature of the business relationship, the value and frequency of the transaction, previously linked transfers, the regulatory status and jurisdiction of the counterparty, and any other relevant risk indicators established within the VASP's AML/CFT policies and procedures.
Required Travel Rule Data
Before executing a virtual asset transfer, the originator VASP must obtain and securely transmit sufficient information to identify both the originator and the beneficiary.
The required information includes:
- originator's full name;
- originator's wallet or account number (or a unique transaction reference where neither exists);
- originator's address, national identity number or travel document number, customer identification number, or date and place of birth;
- beneficiary's full name; and
- beneficiary's wallet or account number (or a unique transaction reference where neither exists).
For domestic transfers where the beneficiary VASP already possesses the required customer information, only the wallet address, account number, or unique transaction reference is required to accompany the transfer. However, the complete Travel Rule dataset must be provided within three working days if requested by the beneficiary VASP or its supervisory authority.
The information requirements apply to all qualifying transfers between VASPs. Verification is generally required for transfers of AED 3,500 or more, although verification must also be performed whenever suspicious activity is identified, regardless of the transaction value.
Self-Hosted Wallets
The UAE also extends the Travel Rule framework to transfers involving self-hosted wallets by requiring VASPs to apply enhanced due diligence measures.
Depending on the circumstances, this may include requesting additional customer identification, verifying the source of funds, or obtaining further documentation to support the transaction.
Where an inbound transfer from a self-hosted wallet lacks the required information, the VASP must determine whether to permit, delay, reject, or return the transfer, taking into account its assessment of the associated financial crime risks.
Similarly, where a customer initiates a transfer to a self-hosted wallet and the VASP does not hold all required Travel Rule information, it must request the missing information. If the customer fails to provide it, the transfer must not proceed.
In conclusion
The UAE has established a comprehensive Travel Rule framework that applies across its federal jurisdictions, Emirates, Free Zones, and Financial Free Zones.
By requiring VASPs to collect and exchange Travel Rule information, verify counterparties, implement robust risk-based controls, and apply enhanced due diligence to self-hosted wallet transactions, the UAE continues to strengthen its AML/CFT framework while aligning with FATF Recommendation 16.
21 Analytics and the UAE’s Travel Rule
21 Analytics helps VASPs comply with the UAE Travel Rule by addressing key compliance challenges around interoperability, counterparty due diligence, privacy, and security.
Through connectivity to both TRUST, which includes many of the world's largest exchanges, and open-network alternatives such as TRP, 21 Analytics enables secure communication with counterparties across different Travel Rule ecosystems, helping VASPs meet the UAE's requirements for exchanging originator and beneficiary information.
The solution also simplifies counterparty verification through automated discovery and due diligence tools, allowing VASPs to verify whether counterparties are appropriately regulated before executing transfers, reducing the risk of non-compliant transactions and unnecessary asset returns.
Built as an on-premises solution, 21 Travel Rule allows VASPs to retain full control over sensitive customer data while supporting the UAE's expectations for robust data governance, cybersecurity, and recordkeeping. By prioritising peer-to-peer data exchange rather than centralised data sharing, 21 Travel Rule reduces exposure risks, minimises single points of failure, and helps VASPs comply with the UAE's AML/CFT framework while maintaining operational efficiency.
Become Travel Rule Compliant with 21 Analytics
Further Reading
Found in the CBUAE Rulebook:
Disclaimer
This material is provided for educational and informational purposes only and is not intended to be a substitute for professional advice or detailed research.
