Select Page
Dubai VARA Publishes AML/CFT Business Risk Assessment Guidance Following 2026 Thematic Review

On 12 June 2026, the Dubai Virtual Assets Regulatory Authority (VARA) published good practice guidance on AML/CFT Business Risk Assessments for licensed virtual asset service providers. The guidance draws on VARA's 2026 review, which covered every licensed VASP through a structured questionnaire and supervisory analysis of submitted Business Risk Assessments documents. It anchors to Rule III.D of the VARA Compliance and Risk Management Rulebook. VASPs must maintain a Business Risk Assessments, review it at intervals of no longer than three months, and update it on any significant change. VASPs must also demonstrate that Business Risk Assessments outcomes directly inform AML/CFT policies, controls and resource allocation. The guidance states that a Business Risk Assessments not informed by quantitative operational evidence is, at best, a judgement. Ratings must respond to data. The document is styled as illustrative. Its examples come from actual peer submissions, and VARA will continue assessing Business Risk Assessments quality through supervisory engagement.

Governance and the three lines of defence

The Business Risk Assessments must be formally approved by the Board, documented with the approval date and a record of substantive challenge. Senior management approval alone does not suffice. The MLRO owns the document; the Board challenges residual ratings, control assumptions and risk appetite. Internal audit, or an independent external party where audit capacity is limited, must validate the methodology and control effectiveness assumptions. A VASP relying on Board presentation as its only independent review operates with a single challenge mechanism. Escalation routes for adverse findings, typology developments and sanctions changes must be defined and must trigger Business Risk Assessments updates.

Methodology and mandatory data inputs

Strong practice uses numerical five-point likelihood and consequence scales, weighted category aggregation through a documented heat map, and separate ML and TF assessment before aggregation. Any score must be traceable from inputs to overall rating. Management overlays require documented rationale. Eight data categories must feed scoring: customer risk distribution, transaction monitoring alert and conversion data, STR/SAR trends, sanctions screening outcomes, product and flow volumes, customer nationality concentration, audit and supervisory findings, and offboarding and EDD statistics. The UAE NRA, FATF lists and typologies, MENAFATF guidance and UAE FIU strategic analysis must be explicitly referenced, with each development logged, dated and impact-assessed even where no rating changes.

VA-specific categories and proliferation financing

Beyond the standard categories, VASPs must formally score unhosted wallet exposure, anonymity enhanced assets and transactions, DeFi and smart contract structures, cross-border transfers including Travel Rule data integration, stablecoin specific typologies, and emerging fraud including AI enabled identity fraud and deepfake account takeover. Geographic risk requires jurisdiction-by-jurisdiction percentages from actual KYC nationality data. Proliferation financing must be scored as a distinct category with its own residual rating, linked operationally to the TFS framework: EOCN registration for designation notifications, without-delay asset freezing consistent with Cabinet Decision No. 74 of 2020, and CNMR and PNMR reporting to the UAE FIU through goAML. Named evasion techniques include nested accounts, layered transactions, front companies and cross-chain bridges.

The eight thematic areas of the review

  1. Governance and senior management accountability
  2. Scope and methodology
  3. Data sources and evidential grounding
  4. Inherent risk category coverage
  5. Proliferation financing treatment
  6. Control effectiveness assessment
  7. Operationalisation of Business Risk Assessments findings
  8. Review cycle and version control

What VASPs should do

Every licensed VASP has a quarterly review falling due within three months of the guidance under Rule III.D.3. That review should be the alignment exercise. Map the current Business Risk Assessments against the eight thematic areas. Build data feeds for the eight operational input categories, because the next cycle will be judged on whether ratings moved with the data. Separate PF into its own scored category and document the full TFS chain. Confirm Board approval mechanics, including the record of challenge, and appoint third-line validation if internal audit cannot provide it. Unchanged ratings now require documented rationale. Start the version control log immediately, recording the guidance itself as the first external development reviewed and impact-assessed. Group subsidiaries relying on group KYC, monitoring or screening must assess that dependency and evidence local MLRO oversight.

(Source: https://www.vara.ae/en/news/, https://media.umbraco.io/dwtc/thylprns/vara-amlctf-business-risk-assessment-guidance.pdf)