The United Arab Emirates (UAE) has implemented the Travel Rule as part of its AML/CFT framework, aligning with the Financial Action Task Force (FATF) Recommendation 16.
The regulation applies to all Virtual Asset Service Providers (VASPs) operating within the UAE, including federal jurisdictions, Emirates, Free Zones, and Financial Free Zones.
It establishes mandatory requirements for the collection, verification, transmission and retention of originator and beneficiary information for virtual asset transfers, while introducing enhanced due diligence obligations for transfers involving self-hosted wallets.
The framework also requires VASPs to assess the regulatory status of counterparties, implement risk-based compliance procedures, maintain transaction records, and report suspicious activity to the UAE Financial Intelligence Unit (FIU).
All applicable VASPs operating within the UAE must comply with the UAE Virtual Assets Travel Rule.
What is the scope of the Travel Rule in the UAE?
The UAE Travel Rule applies to Virtual Asset Service Providers (VASPs) operating within the territorial scope of the UAE Federal and Emirate Laws, including Free Zones and Financial Free Zones.
The regulation applies whenever a virtual asset transfer is:
- executed by a VASP acting on behalf of an originator and transferred to another VASP acting on behalf of a beneficiary;
- received by a VASP acting on behalf of a beneficiary from another VASP acting on behalf of an originator.
Transaction fees ("gas fees") are explicitly excluded from the scope of the regulation.
Who is the supervisory body for VASPs in the UAE?
The applicable supervisory authority depends on where the VASP is licensed.
Supervisory authorities include:
- Virtual Assets Regulatory Authority (VARA)
- Securities and Commodities Authority (SCA)
- Dubai Financial Services Authority (DFSA)
- Financial Services Regulatory Authority (FSRA)
- Other competent UAE supervisory authorities
What is the Travel Rule threshold in the UAE?
Travel Rule information requirements apply to all qualifying virtual asset transfers between VASPs.
Obligations of originator virtual asset service providers
Before executing a virtual asset transfer, the originator VASP must collect, verify and securely transmit the following information:
- originator's full name,
- originator’s wallet or account number (if neither exists, a unique transaction reference must be provided),
- originator's address, national identity number or travel document number, customer identification number, date and place of birth,
- beneficiary's full name,
- beneficiary's wallet or account number (if neither exists, a unique transaction reference must be provided).
For domestic transfers, where this data is available to the counterparty through another means, the originator VASP is only required to the wallet, or account number, or the unique reference number. However, if the required Travel Rule information is requested by the beneficiary VASP or its supervisory authority, the originator VASP must provide the complete data set within 3 working days of the request.
For batched transfers, the above information must accompany every individual transfer contained within the batch.
Prior to executing the transfer, the originator VASP must also:
- confirm that the receiving VASP is appropriately regulated within its jurisdiction. If a VASP is not regulated, the transfer must not be executed, whether domestic or cross-border;
- ensure the required Travel Rule data has been verified*.
*Verification of data is not required for transfers below AED 3,500 unless suspicious activity is identified. Moreover, beneficiary identity verification only becomes mandatory where daily aggregated virtual asset transfers equal or exceed AED 3,500.
Originator VASPs must have risk-based procedures in place to help identify counterparties that cannot receive Travel Rule information. If the originator realises the beneficiary cannot securely receive the Travel Rule information, an alternative means of communication must be established.
If no communication means can be set up, the originator must assess the level of risk presented by the counterparty to determine whether future transfers will be declined.
Factors to consider include:
- relationship with the customer;
- value of the transfer and previously linked transactions;
- transaction frequency;
- counterparty’s location and reputation;
- regulatory framework of the counterparty’s location.
Originator VASPs must also maintain appropriate records in accordance with the UAE AML/CFT Decision.
Obligations of beneficiary virtual asset service providers
Beneficiary VASPs must implement measures to ensure that incoming transfers include all required Travel Rule information. This can include real time or post-event monitoring tools.
Should information be missing, beneficiary VASPs must request the information and determine when to:
- reject, permit, or delay the execution of the transfer;
- return the assets to the to the sender
- as appropriate report to a supervisory authority, and where appropriate take follow-up action
When determining the course of action, beneficiary VASPs must consider the level of money laundering, terrorist financing, and proliferation financing risk presented by the transaction, using their risk-based policies and procedures.
For customers whose daily aggregated transfers equal or exceed AED 3,500, the beneficiary's identity must be verified if this has not already been completed. For transfers below AED 3,500, identity verification is only required where suspicious activity is identified.
Beneficiary VASPs must also maintain appropriate records in accordance with the UAE AML/CFT Decision.
Obligations of intermediary virtual asset service providers
Intermediary providers must:
- verify the regulatory status of both originator and beneficiary VASPs;
- maintain a log of all transfers, including attempts that were rejected due to non-compliance;
- transfer all required originator and beneficiary information to its counterparty;
- if the information cannot be forwarded, retain a record of all information received from the originator VASP or another intermediary provider, in accordance with Article 25 of the Decision.
Where information is missing, intermediary VASPs must request the information and determine when to
- delay the execution of the transfer until the data is received, or
- return the assets to the sender if the data is not received.
When determining the course of action, intermediary VASPs must consider the level of money laundering, terrorist financing, and proliferation financing risk presented by the transaction, using their own risk-based policies and procedures.
When assessing risk, intermediaries should consider the purpose and nature of the business relationship with the originator VASP, the value of the transfer and previously linked transactions.
Does the UAE's Travel Rule apply to self-hosted wallets?
Transfers involving self-hosted wallets are subject to enhanced due diligence requirements. This mayy include requesting additional identification and source of funds verification from the customer.
For inbound transfers from self-hosted wallets that lack the required originator or beneficiary information, VASPs must request the information and determine whether to:
- reject, permit, or delay the execution of the transfer;
- return the assets to the to the sender;
- as appropriate report to a Supervisory Authority, and where appropriate take follow-up action .
For transactions from an originator to a self-hosted wallet, VASPs must request any missing Travel Rule information relating to the customer that it does not already hold. If the information is not provided, the VASP must decline the transfer.
When determining the course of action, VASPs must consider the level of money laundering, terrorist financing, and proliferation financing risk presented by the transaction.
When assessing risk, VASPs should consider the purpose and nature of the business relationship with the originator, the value of the transfer and any previously linked transactions, and the frequency of the customer's transactions.
When do you need to comply with the UAE’s Travel Rule?
Now - The Travel Rule is live.
Become Travel Rule Compliant with 21 Analytics
Which regulations are applicable to the UAE’s Travel Rule?
Found in the CBUAE Rulebook:
