virtual-asset-regulatory-advisory

By July 25th, 2026compliant-growth12 min read

Virtual Asset Regulatory Advisory: Licensing and Compliance in the GCC

The Gulf Cooperation Council (GCC) has emerged as a global laboratory for virtual asset regulation, with Bahrain, the United Arab Emirates and Saudi Arabia each building distinct but increasingly convergent frameworks. Virtual asset service providers (VASPs) operating in or targeting the region must navigate a complex matrix of federal laws, central bank rulebooks, free-zone regimes and evolving international standards from the Financial Action Task Force (FATF). This guide provides a comprehensive overview of virtual asset regulatory advisory across the GCC, covering licensing pathways, AML/CFT obligations, custody rules, marketing restrictions, stablecoin frameworks and cross-border considerations.

Published: July 2026  |  Last updated: July 2026  |  Author: Bitrixme Regulatory Advisory Team

What Virtual Asset Regulation Means

Virtual asset regulation refers to the set of laws, rules and supervisory practices that govern the issuance, trading, custody and transfer of digital assets. It covers cryptocurrencies, stablecoins, asset-referenced tokens, non-fungible tokens (NFTs) when they carry investment characteristics, and any other digital representation of value that can be digitally traded or transferred. The regulatory approach in the GCC has shifted from观望 (wait-and-see) to active rule-making, driven by FATF Recommendation 15, which requires all member jurisdictions to regulate VASPs. The GCC states are now at varying stages of implementation, creating both compliance burdens and competitive advantages for firms that engage early with the right regulatory advisory support.

JurisdictionPrimary RegulatorKey FrameworkVASP Licensing
UAE (Dubai)VARA (Virtual Assets Regulatory Authority)VARA Rulebook (2023, updated 2025)Mandatory for all VA activities in Dubai
UAE (Federal)SCA / Central BankFederal AML/CFT Law, SCA Decision for securities tokensDual registration with SCA and local regulator
BahrainCBB (Central Bank of Bahrain)CBB Crypto-Asset Module (Volume 6, 2019, updated 2025)Mandatory for all crypto-asset services
Saudi ArabiaSAMA / CMASAMA framework for virtual assets, CMA for security tokensLicensing required, limited licences issued
ADGM (Abu Dhabi)FSRA (Financial Services Regulatory Authority)ADGM FSRA Crypto Asset RegimeMandatory for spot and衍生品 activities
QatarQatar Financial Centre Regulatory Authority (QFCRA)QFC Digital Asset Framework (2025)Licensing for QFC-established firms

UAE VARA Framework

The Virtual Assets Regulatory Authority (VARA) is the first specialised virtual asset regulator in the world. Established under Dubai Law No. 4 of 2022, VARA has exclusive jurisdiction over virtual asset activities in the Emirate of Dubai, excluding the Dubai International Financial Centre (DIFC). VARA’s rulebook is structured into multiple compendiums covering issuance, brokerage, exchange, custody, advisory and management services. In early 2025, VARA extended its framework to cover real-world asset (RWA) tokenisation through the Asset-Referenced Virtual Asset (ARVA) category, with full issuer obligations set out in the Virtual Asset Issuance Rulebook.

Licensing under VARA is activity-based and tiered. A firm conducting one activity requires a single-activity licence; a firm conducting multiple activities requires a multi-activity licence with higher capital requirements and more extensive governance obligations. The licensing process includes a fit and proper assessment of all controllers and senior management, submission of a detailed business plan, AML/CFT policies, custody arrangements and wind-down plans. VARA also requires a virtual asset compliance officer registered with the regulator and a board-approved compliance programme.

VARA Licence TypeActivities CoveredMinimum CapitalAdditional Requirements
VA ExchangeOrder matching, trading, executionAED 10 millionCold wallet custody, insurance, market surveillance
VA Broker-DealerOrder execution, placing, dealingAED 5 millionBest execution policy, conflict of interest management
VA CustodianSafekeeping and administration of VAAED 5 millionSegregated accounts, audit trail, SOC 2 or equivalent
VA Issuer (ARVA)Issuance of asset-referenced tokensAED 15 millionFull prospectus, reserve assets, regular audits
VA Management & AdvisoryPortfolio management, investment adviceAED 2 millionClient categorisation, disclosure, suitability assessment
VA Service ProviderTransfer, settlement, payment servicesAED 2 millionTransaction monitoring, travel rule compliance

Bahrain CBB Digital Asset Rules

Bahrain was the first GCC country to introduce a comprehensive regulatory framework for crypto-assets. The CBB’s Crypto-Asset Module, part of Volume 6 of the CBB Rulebook, was launched in 2019 and updated in 2025 to include a stablecoin framework issued in July 2025. The module covers licensing, capital requirements, custody, AML/CFT, market conduct and reporting for all crypto-asset services. Bahrain is widely regarded as a MENA leader on digital asset regulatory clarity and has positioned itself as a testing ground for regulated crypto innovation.

Crypto-asset licences in Bahrain fall into four categories: Crypto-Asset Exchange, Crypto-Asset Custodian, Crypto-Asset Broker and Crypto-Asset Payment Service Provider. All licences require a minimum paid-up capital of BHD 500,000 (approximately USD 1.33 million), though higher amounts apply for exchange and multi-service licences. Applicants must submit a comprehensive application including a risk management framework, AML/CFT policies, IT security audit, business continuity plan and ring-fenced client asset arrangements. The CBB conducts on-site inspections before issuing a licence and annually thereafter.

Saudi Arabia CMA Regulations

Saudi Arabia’s approach to virtual asset regulation is more cautious. The Saudi Central Bank (SAMA) and the Capital Market Authority (CMA) jointly oversee the virtual asset space. The CMA has issued regulations for security tokens under the Capital Market Law, treating any token that carries investment characteristics as a security. SAMA has issued guidance on virtual asset activities for financial institutions and has piloted limited digital asset initiatives through its sandbox programme. The CMA also regulates crowdfunding platforms that issue tokens and has established requirements for offer documents, investor protection and disclosure. Full VASP licensing is expected as Saudi Arabia continues its alignment with FATF Recommendations.

Licensing Requirements across the GCC

Despite differences in regulatory architecture, the core licensing requirements across GCC jurisdictions share common features:

  • Fit and proper assessment: All controllers, directors and senior managers must pass a fit and proper test evaluating honesty, integrity, competence and financial soundness. Criminal record checks and regulatory references are required.
  • Minimum capital: Paid-up capital requirements range from approximately USD 500,000 for advisory licences to USD 15 million for issuance and exchange licences. Capital must be maintained at all times and reported regularly.
  • Local presence: Most jurisdictions require a physical office in the jurisdiction, with a licensed manager or compliance officer resident in the country. Virtual asset businesses cannot operate remotely without a local establishment.
  • Business plan and financial projections: A detailed three-year business plan with revenue models, cost projections, break-even analysis and scenario planning is required. The plan must demonstrate sustainability under stressed conditions.
  • Governance and compliance: A board-approved governance framework, compliance programme, risk management framework and internal controls must be in place before licensing. Independent audit and compliance functions are mandatory.
  • Insurance and security: Cybersecurity insurance, professional indemnity insurance and, for custodians, crime or fidelity insurance are required. IT systems must be independently audited for security.

AML/CFT Obligations for VASPs

Virtual asset service providers across the GCC are subject to comprehensive AML/CFT obligations aligned with FATF Recommendations 15 and 16. The key requirements include:

ObligationRequirementJurisdictional Notes
Customer Due Diligence (CDD)Identify and verify all customers before any transaction. Ongoing monitoring of all activity.Bahrain: BHD 6,000 threshold. UAE: AED 55,000. Saudi: SAR 10,000.
Enhanced Due Diligence (EDD)Apply EDD for PEPs, high-risk jurisdictions, complex transactions and non-face-to-face relationships.All jurisdictions require written EDD procedures and escalation to senior management.
Travel Rule (FATF Recommendation 16)Transmit originator and beneficiary information for all VA transfers above USD 1,000.VARA and CBB both require travel rule compliance. Technical solutions include Sygna, Notabene and open-source protocols.
Suspicious Transaction Reporting (STR)Report suspicious transactions to the FIU within prescribed timelines.Bahrain: 14 days. UAE: 30 working days. Saudi: Immediate.
Sanctions ScreeningScreen all customers and transactions against UN, OFAC and local sanctions lists in real time.UAE and Saudi Arabia require screening against local proscribed lists in addition to UN lists.
Record KeepingMaintain all records for a minimum of 5 to 10 years after the business relationship ends.Bahrain and Saudi: 10 years. UAE: 5 years.

Custody and Segregation Requirements

All GCC virtual asset regulators require clear segregation of client assets from the firm’s proprietary assets. Custody frameworks typically require the following: client virtual assets must be held in segregated wallets that are clearly identified as belonging to clients, not the firm; a minimum percentage of client assets must be held in cold storage (typically 95 per cent or more); private keys must be managed through multi-signature arrangements with geographic distribution of key holders; regular reconciliation of client assets against wallet balances must be conducted daily; and an independent audit of custody arrangements must be conducted at least annually. Firms must also publish clear custody terms, disclose their insurance coverage and provide clients with regular statements of holdings.

Marketing Restrictions for Virtual Asset Services

Marketing of virtual asset services is regulated across the GCC. The key restrictions include: all marketing materials must be approved by the compliance function before publication; performance projections or promises of returns are prohibited unless they are based on regulated financial instruments; risk warnings must be prominently displayed in Arabic and English; targeted marketing to retail investors is restricted in certain jurisdictions; and social media promotions must comply with advertising standards codes. VARA’s Marketing Rulebook requires all communications to be fair, clear and not misleading, with specific requirements for risk disclosure. Bahrain’s CBB requires all marketing communications for crypto-asset services to be pre-approved by the regulator. Penalties for non-compliance include fines of up to AED 5 million under VARA and suspension of the marketing approval.

Stablecoin Regulation

Stablecoin regulation has become a priority for GCC regulators following the global focus on payment stablecoins and the FATF’s updated guidance. Bahrain took the lead by issuing a dedicated stablecoin framework in July 2025 under the CBB Crypto-Asset Module. The framework requires stablecoin issuers to hold reserve assets at least equal to the outstanding stablecoin value, with reserves composed of cash, cash equivalents or short-term government securities denominated in the reference currency. Monthly attestation reports and quarterly audits are mandatory. The UAE is developing its own stablecoin regulation under the Central Bank’s Payment Token Regulation framework, which is expected to classify stablecoins as either payment tokens or asset-referenced tokens depending on their structure. Saudi Arabia has not yet issued specific stablecoin regulation but is expected to align with the GCC common framework under discussion.

Cross-Border Considerations

Virtual asset firms operating across multiple GCC jurisdictions face additional compliance burdens. Each jurisdiction requires a separate licence, separate capital maintenance and separate compliance arrangements. There is no passporting regime for virtual asset services within the GCC, though discussions are ongoing under the GCC Financial Cooperation Committee. Firms must also navigate cross-border data transfer restrictions, particularly under Bahrain’s PDPL and the UAE’s Federal Data Protection Law. The travel rule adds complexity for cross-border VA transfers, requiring the transmission of originator and beneficiary information for every transfer. Firms operating across multiple jurisdictions should establish a group-wide compliance framework with jurisdictional-specific modules, maintain a single customer view across all entities for AML purposes and engage regulatory advisory counsel in each jurisdiction of operation.

Frequently Asked Questions

What is the difference between VARA and SCA in the UAE?

VARA regulates virtual asset activities in Dubai (excluding DIFC). The Securities and Commodities Authority (SCA) regulates virtual assets at the federal level, including those classified as securities or commodities. Firms conducting virtual asset activities in the UAE outside of Dubai may require dual registration. The SCA and VARA have signed a cooperation agreement to harmonise their frameworks.

Does the CBB licence crypto-asset firms in Bahrain?

Yes. The CBB’s Crypto-Asset Module under Volume 6 of the CBB Rulebook provides licensing for crypto-asset exchanges, custodians, brokers and payment service providers. Bahrain was the first GCC country to establish a dedicated crypto-asset regulatory framework and is considered a MENA leader in this space.

What are the AML obligations for VASPs in the GCC?

VASPs must implement customer due diligence, enhanced due diligence for high-risk customers, ongoing transaction monitoring, suspicious transaction reporting, sanctions screening and travel rule compliance. They must appoint a registered AML compliance officer and maintain records for 5 to 10 years depending on the jurisdiction.

Is real-world asset (RWA) tokenisation regulated in the GCC?

Yes. VARA has issued the Asset-Referenced Virtual Asset (ARVA) category specifically for RWA tokenisation in Dubai. Bahrain’s CBB framework covers tokenised assets under its crypto-asset module. Abu Dhabi’s ADGM also permits tokenisation of real-world assets under its existing framework. Each jurisdiction requires a full prospectus or equivalent disclosure document.

Can a virtual asset firm operate in multiple GCC countries with one licence?

No. There is no passporting regime for virtual asset services across the GCC. Each jurisdiction requires a separate licence with separate capital, compliance and governance arrangements. Firms must establish a local presence in each jurisdiction where they operate.

What insurance is required for virtual asset custodians?

Virtual asset custodians must typically hold crime or fidelity insurance covering both hot and cold wallet assets. The coverage amount varies by jurisdiction but commonly ranges from AED 5 million to AED 50 million depending on the assets under custody. Professional indemnity insurance and cybersecurity insurance are also mandatory.

Ready to navigate virtual asset regulation in the GCC? Contact our regulatory advisory team for a licensing readiness assessment or jurisdictional comparison, or message us on WhatsApp for an immediate consultation.


Disclaimer: This article provides general guidance on virtual asset regulation across the GCC and does not constitute legal advice. Organisations should consult qualified legal and regulatory professionals for advice specific to their circumstances and jurisdictions of operation.