On 5 October 2026, the UAE Financial Intelligence Unit (UAE FIU) and Dubai’s Virtual Assets Regulatory Authority (VARA) signed a Memorandum of Understanding that formalises the exchange of financial intelligence, joint identification of risk and sharing of supervisory insights across the virtual-assets sector. The MoU was signed by UAE FIU Chief Ali Faisal Ba Alawi and VARA CEO Matthew White.
What was signed
The MoU is not a new licensing procedure, nor an expansion of either authority’s remit. It is a framework for operational interaction between two bodies that until now had mostly intersected through written alerts and ad hoc requests. Under the agreement, the parties will:
- exchange relevant financial intelligence and expertise — within applicable legislation and confidentiality rules;
- jointly identify and respond to financial-crime risks in the virtual-assets sector;
- share supervisory insights and emerging typologies — the case patterns each side accumulates in its own perimeter;
- coordinate action on suspicious activity that requires both STR-level analysis (FIU) and a supervisory response (VARA).
Ba Alawi framed the move as a response to the growing technological complexity and cross-border nature of financial crime: cooperation and information exchange are no longer a convenience but a necessity. White said the MoU “consolidates and strengthens” the collaboration already in place between VARA and the UAE FIU — some channels were working before; now they are set out in a document.
UAE FIU and VARA — who they are, why they are now side by side
UAE FIU is an independent financial intelligence unit established within the Central Bank of the UAE (CBUAE). Its remit: receiving suspicious transaction reports (STRs) from financial institutions, designated non-financial businesses and professions (DNFBPs) and virtual asset service providers (VASPs); analysing them; and sharing results with competent UAE authorities to support efforts against money laundering, terrorist financing and proliferation financing. The FIU engages with national supervisors and foreign counterparts; the UAE is a member of the Egmont Group of Financial Intelligence Units.
VARA was established in March 2022 under Dubai Law No. 4 of 2022. It is the first independent, dedicated virtual-assets regulator at the emirate level anywhere in the world. VARA regulates, licenses and supervises virtual-asset activities across Dubai — commercial zones, Special Development Zones and Free Zones — excluding the Dubai International Financial Centre, which has its own regulator (DFSA).
The logic of cooperation runs like this: VARA sees the sector “from inside” — through licensing files, supervisory visits and operational metrics from VASPs. FIU sees it “from the flow” — through STRs arriving from banks, DNFBPs and VASPs themselves, and from behavioural analytics on suspicious transactions. Put together, the two cross-sections give a sharper picture of risk than either body has alone. For Dubai’s crypto infrastructure, that is a meaningful shift.
What this does for the fight against crypto financial crime
Three practical effects the MoU enables not as a declaration but as a routine:
Speed of response. When suspicious transactions on a Dubai exchange or wallet require both a supervisory move (freeze, document request) and analytical work (comparison with STR patterns already held by FIU on that address), coordination between VARA and FIU now runs on a framework rather than ad hoc. In investigations, that is the difference between days and weeks.
Shared typologies. Crypto crime evolves fast — from classic layering through mixers to stablecoin flows, DeFi mule wallets, OTC-linked chains and attacks on custody platforms. VARA’s accumulated licensee cases plus the FIU’s STR mass are two different data types; joint analysis turns them into typologies faster than either source does alone.
Coordinated supervisory response. The MoU explicitly covers “coordinated action against illicit activity”. If FIU identifies a scheme touching a licensed VASP, VARA receives it in a form that fits its supervisory toolkit — notices, directives, licence suspension where needed. And in reverse: when VARA spots risk at a supervised entity, FIU gets context, not just a raw signal.
What changes for VASPs and financial institutions
The MoU does not introduce new direct obligations on business — those flow from UAE AML/CFT law and the VARA rulebook. But the operational risk profile for crypto-market participants in Dubai has clearly shifted after 5 October:
- For licensed VASPs. Assume VARA’s supervisory profile and the FIU’s STR analytics are now connected. Any weakness in internal controls — a missed STR, an overlooked red flag, misalignment with the licensed scope — becomes visible from both sides at once. Near-term priority: refresh AML/CFT policies against current VARA and FIU typologies; verify STR submission to UAE FIU through goAML / IEMS; update staff training on crypto-ML red flags.
- For banks and DNFBPs. Banks running VASP accounts, exchange houses, corporate service providers serving crypto businesses now work in an environment where the VASP regulator and the FIU reconcile indicators with each other. Not a formal tightening, but a higher bar on evidence: any crypto-perimeter STR has a greater chance of becoming a case VARA also sees.
- For companies in the licensing pipeline. The framework raises the weight of the AML/CFT section in a VARA application: policies, procedures, MLRO appointment, monitoring systems, training. We cover the shape of the process in our guide “VARA crypto licence in Dubai: how to open a crypto business”.
Context: the MoU in the UAE’s 2026 AML architecture
The FIU-VARA agreement is not a standalone move. It joins a series of AML/CFT upgrades the UAE has rolled out since 2024: CBUAE’s 2026 operational-risk package for banks, Cabinet Decisions 55 and 56 that launched a national KYC verification system, FTA Decision 13/2026 which from 1 October makes supplier verification (Know Your Supplier) mandatory for input VAT recovery, VARA’s refreshed custody and staking rules — all under the national coordination of the Executive Office of AML/CTF.
Against that backdrop, the FIU-VARA MoU is the operational seam that connects several parallel initiatives into a more joined-up supervisory loop. For the business environment, it signals that the UAE’s financial-integrity drive is not a one-off FATF-cycle event but a steady institutional build-out. For how these layers fit together in 2026, see our overview “UAE business regulation 2026”.
What Garant clients should do
Three actions worth closing before the end of Q4 2026 — regardless of sector:
1. If the business is VARA-regulated — run an AML/CFT control review: policies, SAR/STR process, appointments, training, monitoring. Confirm that STRs are actually reaching UAE FIU through the correct channel (goAML / IEMS) and on time, and that an internal red-flag decision log is maintained.
2. If the business interacts with the crypto sector as a bank, exchange house, corporate service provider or DNFBP — refresh customer risk profiles: add criteria tied to counterpart’s VARA licensing status, settlement currency, wallet jurisdiction. This reduces the probability of a “quiet” STR the supervisor reconstructs after the fact.
3. If the company is preparing to enter Dubai’s crypto market — budget the AML/CFT block of the VARA licence as a standalone workstream, not an add-on. In practice, the depth of AML/CFT in the application is what paces review and shapes the questions VARA raises during assessment.
The 5 October MoU is not a formality. For Dubai’s crypto market, it is a step from the parallel work of two strong institutions to coordinated oversight. For a business that intends to grow in this jurisdiction for the long term, it is a cue to revisit its AML/CFT architecture and make sure it clears the bar of both regulators at once.


