A crypto or blockchain business licensed or operating in the UAE is a regulated reporting entity: it must register on goAML, run risk-based customer due diligence, screen every transaction against its risk appetite, and file suspicious transaction reports with the UAE Financial Intelligence Unit — with penalties for failure reaching AED 5,000,000 under Federal Decree-Law No. 20 of 2018 on Anti-Money Laundering.
The legal backbone
Federal Decree-Law No. 20 of 2018, as amended by Federal Decree-Law No. 26 of 2021, is the core AML/CFT statute: it obliges financial institutions and designated non-financial businesses and professions (DNFBPs) to identify customers, keep records and report suspicions. Cabinet Decision No. 10 of 2019 (Article 20) makes registration on the goAML portal of the UAE Financial Intelligence Unit mandatory, and reporting is done exclusively through that platform (Ministry of Economy & Tourism, goAML registration). Virtual asset service providers are explicitly in scope — the UAE added VASPs to the reporting framework in line with FATF Recommendation 15.
Which regulator applies
The superviser depends on where and how the business operates: VARA (Dubai's Virtual Assets Regulatory Authority) licenses and supervises VASPs in Dubai (outside DIFC) and enforces its rulebook, including AML/CFT rules and mandatory goAML reporting; the DFSA supervises within the DIFC; the CBUAE supervises certain payment-token activities; and free zones such as ADGM apply their own regimes. In every case the FIU reporting obligation through goAML is federal and applies regardless of the supervisor.
The core compliance programme
| Obligation | What it requires | Practical evidence |
|---|---|---|
| National Risk Assessment alignment | Understand the ML/TF risks specific to virtual assets and document them | Business-wide risk assessment, reviewed annually |
| CDD / KYC | Identify and verify customers and beneficial owners before or during onboarding | ID records, UBO declarations, source-of-funds evidence |
| Enhanced due diligence | Apply to higher-risk customers, PEPs and unusual transaction patterns | EDD files, senior-management approvals |
| Sanctions and PEP screening | Screen customers and transactions against UN/UAE lists | Screening logs with match disposition |
| Transaction monitoring | Detect unusual patterns — structuring, mixers, rapid pass-through | Blockchain analytics reports, alert dispositions |
| goAML registration and STR filing | Register the entity and MLRO; file STRs/SARs without delay | goAML entity ID, filed-report records |
| Record keeping | Keep CDD and transaction records at least 5 years (Federal Decree-Law 20 of 2018) | Archived KYC files and audit trails |
| MLRO and training | Appoint a compliance officer; train staff; retain AML compliance officer certificates | Appointment letters, training records |
A practical setup sequence
- Confirm the supervising authority and licence scope (VARA, DFSA, ADGM or CBUAE) — each has its own rulebook layer on top of federal law.
- Register the company and its MLRO on goAML; goAML is the only STR channel.
- Build the risk assessment first, then size CDD and monitoring to it — regulators test proportionality, not tool count.
- Add blockchain analytics for on-chain exposure screening (mixers, sanctions-listed addresses, darknet flows) — this is what distinguishes a defensible VASP programme from a paper one.
- Date-stamp and version every policy; UAE supervisors increasingly request evidence that policies were live at the time of the customer relationship, not retrofitted.
Penalties worth knowing
Failure to register with the FIU, failure to report a suspicion, and failure to keep records each attract administrative penalties — and criminal liability can attach to the firm and its managers where failure to report is intentional. The practical consequence of a weak programme is not only fines but loss of the licence the business model depends on.
FAQ
Do all UAE crypto companies have to register on goAML? Any VASP or other reporting entity subject to Federal Decree-Law No. 20 of 2018 must register on goAML before it can file suspicious transaction reports — and reporting obligations apply from the moment suspicion arises.
Who is accountable inside the company? A designated Money Laundering Reporting Officer (MLRO) owns the programme day to day; senior management remains accountable to the supervisor for its effectiveness.
How long are AML records kept? At least five years under Federal Decree-Law No. 20 of 2018, covering CDD files, transaction records and training logs.
Finanshels provides AML compliance services for UAE crypto and blockchain companies, including risk assessments, policy documentation and goAML registration support. For the accounting side of a virtual-asset business, see our guide to bookkeeping for crypto companies.






