top of page
Vector.png

Stay up to date with our latest news

By Mark Scott, Executive Director - Risk Management, j. awan & partners


Most VARA-licensed firms spent the first phase of regulation focused on getting authorised. Whether the governance infrastructure they built for licensing is actually functioning as VARA intended, and whether it will hold up under live supervisory scrutiny, is a different matter. For a number of firms, the evidence suggests it will not.

 

What the rulebook requires


VARA’s Compliance and Risk Management Rulebook sets out internal audit as a mandatory obligation for all licensed Virtual Asset Service Providers. Internal audits must be conducted quarterly, with findings and recommendations reported to senior management. Firms must also appoint an independent external auditor for annual financial statement reviews.

 

Beyond the cadence, the rulebook requires firms to put in place a dedicated risk management function staffed by suitably qualified personnel, with risk reports submitted to the board at least quarterly. The head of that function must have the authority and qualifications to oversee the firm’s risk exposures, not just document them.

 

These are not light-touch expectations. For many VASPs, particularly those that grew out of technology or trading backgrounds, building this governance infrastructure from scratch has been the harder part of the licensing journey.

 

Where VARA is finding weaknesses


VARA has been clear that supervision is no longer at an early stage. Between August 2024 and August 2025, the authority issued enforcement notices against 36 firms, with penalties ranging from AED 50,000 to AED 600,000. In August 2025, VARA issued a public notice of fines against a licensed VASP for serious governance and AML breaches, including weaknesses in the AML programme, non-disclosure of material facts, and conducting unlicensed activity. A skilled person was appointed to oversee remediation and the firm was placed under ongoing supervision.

 

The pattern in these cases is consistent. Breaches at the compliance and AML level went undetected because the internal audit function either did not exist in a meaningful sense, was not operating with sufficient independence, or lacked the technical capability to assess what was actually happening in the business.

 

Following supervisory reviews in 2024 and 2025, VARA formally warned a number of VASPs of major weaknesses in their AML and CFT Business Risk Assessments. The specific failures identified included a lack of data-driven methodology, unrealistic residual risk ratings, and a failure to account for emerging threats including AI-enabled typologies, proliferation financing, and targeted financial sanctions risk. VARA has since mandated quarterly reviews of these assessments and is conducting a thematic review of BRA frameworks across the sector.

 

The FATF dimension


The timing matters. The UAE’s next FATF mutual evaluation onsite visit is scheduled for June 2026. Virtual assets have been identified as a high-risk sector in the UAE’s 2025 National Risk Assessment, and VARA-regulated firms will receive close scrutiny as part of that evaluation. FATF assessors will look at whether supervision is effective in practice, which means looking at whether licensed VASPs actually have functioning internal audit and risk management frameworks, not just documentation that says they do.

 

Firms that cannot demonstrate a working audit trail, independent quarterly reviews with board oversight, and documented remediation of findings are carrying a compliance exposure that goes beyond their own regulatory relationship with VARA.

 

What firms should be asking themselves


The internal audit obligation is specific enough that there are concrete questions worth working through now, before a supervisory visit prompts the same conversation under pressure.

 

Is your internal audit function independent from the compliance and operations teams it is reviewing? Independence on paper is not the same as independence in practice, particularly in smaller firms where the same people often wear multiple hats.

 

Are your quarterly audit findings reaching the board in a form that enables oversight, or are they filed as a compliance record without meaningful board engagement? VARA expects board-level oversight of risk exposures, and the documentation of that oversight will be assessed.

 

Does your Business Risk Assessment reflect the firm’s actual risk profile today, including the transaction types, counterparty relationships, and emerging threat categories that VARA has specifically flagged? An assessment built for the licence application and not reviewed since is unlikely to meet the current standard.

 

When an internal audit finds a weakness, is there a documented remediation process with ownership and timelines? The absence of that trail is itself a finding in VARA’s eyes.

 

The practical gap


Many VARA-licensed firms are running internal audit in name rather than in substance. Quarterly reviews that simply confirm controls are in place, without testing whether they are working, do not meet the intent of the obligation. VARA has made clear it expects audit to function as an independent assurance mechanism, not a self-certification exercise.

 

For firms where the internal audit capability is thin, the question is not whether to address it but how quickly. The thematic review underway in Q2 2026, the approaching FATF evaluation, and VARA’s track record of public enforcement all point in the same direction.

 

J. Awan & Partners supports VARA-licensed firms with internal audit, AML/CFT risk assessments, governance framework reviews, and regulatory readiness. For a conversation, contact info@jawanpartners.com or visit jawanpartners.com.

VARA internal audit: what licensed firms must have in place now

VARA is moving beyond licensing and increasingly scrutinising whether internal audit and risk management functions operate effectively in practice. Firms that cannot demonstrate independent audits, board oversight, and timely remediation of findings face growing regulatory and enforcement risk.

VARA internal audit: what licensed firms must have in place now

VARA is moving beyond licensing and increasingly scrutinising whether internal audit and risk management functions operate effectively in practice. Firms that cannot demonstrate independent audits, board oversight, and timely remediation of findings face growing regulatory and enforcement risk.

By Mark Scott, Executive Director - Risk Management, j. awan & partners


Most VARA-licensed firms spent the first phase of regulation focused on getting authorised. Whether the governance infrastructure they built for licensing is actually functioning as VARA intended, and whether it will hold up under live supervisory scrutiny, is a different matter. For a number of firms, the evidence suggests it will not.

 

What the rulebook requires


VARA’s Compliance and Risk Management Rulebook sets out internal audit as a mandatory obligation for all licensed Virtual Asset Service Providers. Internal audits must be conducted quarterly, with findings and recommendations reported to senior management. Firms must also appoint an independent external auditor for annual financial statement reviews.

 

Beyond the cadence, the rulebook requires firms to put in place a dedicated risk management function staffed by suitably qualified personnel, with risk reports submitted to the board at least quarterly. The head of that function must have the authority and qualifications to oversee the firm’s risk exposures, not just document them.

 

These are not light-touch expectations. For many VASPs, particularly those that grew out of technology or trading backgrounds, building this governance infrastructure from scratch has been the harder part of the licensing journey.

 

Where VARA is finding weaknesses


VARA has been clear that supervision is no longer at an early stage. Between August 2024 and August 2025, the authority issued enforcement notices against 36 firms, with penalties ranging from AED 50,000 to AED 600,000. In August 2025, VARA issued a public notice of fines against a licensed VASP for serious governance and AML breaches, including weaknesses in the AML programme, non-disclosure of material facts, and conducting unlicensed activity. A skilled person was appointed to oversee remediation and the firm was placed under ongoing supervision.

 

The pattern in these cases is consistent. Breaches at the compliance and AML level went undetected because the internal audit function either did not exist in a meaningful sense, was not operating with sufficient independence, or lacked the technical capability to assess what was actually happening in the business.

 

Following supervisory reviews in 2024 and 2025, VARA formally warned a number of VASPs of major weaknesses in their AML and CFT Business Risk Assessments. The specific failures identified included a lack of data-driven methodology, unrealistic residual risk ratings, and a failure to account for emerging threats including AI-enabled typologies, proliferation financing, and targeted financial sanctions risk. VARA has since mandated quarterly reviews of these assessments and is conducting a thematic review of BRA frameworks across the sector.

 

The FATF dimension


The timing matters. The UAE’s next FATF mutual evaluation onsite visit is scheduled for June 2026. Virtual assets have been identified as a high-risk sector in the UAE’s 2025 National Risk Assessment, and VARA-regulated firms will receive close scrutiny as part of that evaluation. FATF assessors will look at whether supervision is effective in practice, which means looking at whether licensed VASPs actually have functioning internal audit and risk management frameworks, not just documentation that says they do.

 

Firms that cannot demonstrate a working audit trail, independent quarterly reviews with board oversight, and documented remediation of findings are carrying a compliance exposure that goes beyond their own regulatory relationship with VARA.

 

What firms should be asking themselves


The internal audit obligation is specific enough that there are concrete questions worth working through now, before a supervisory visit prompts the same conversation under pressure.

 

Is your internal audit function independent from the compliance and operations teams it is reviewing? Independence on paper is not the same as independence in practice, particularly in smaller firms where the same people often wear multiple hats.

 

Are your quarterly audit findings reaching the board in a form that enables oversight, or are they filed as a compliance record without meaningful board engagement? VARA expects board-level oversight of risk exposures, and the documentation of that oversight will be assessed.

 

Does your Business Risk Assessment reflect the firm’s actual risk profile today, including the transaction types, counterparty relationships, and emerging threat categories that VARA has specifically flagged? An assessment built for the licence application and not reviewed since is unlikely to meet the current standard.

 

When an internal audit finds a weakness, is there a documented remediation process with ownership and timelines? The absence of that trail is itself a finding in VARA’s eyes.

 

The practical gap


Many VARA-licensed firms are running internal audit in name rather than in substance. Quarterly reviews that simply confirm controls are in place, without testing whether they are working, do not meet the intent of the obligation. VARA has made clear it expects audit to function as an independent assurance mechanism, not a self-certification exercise.

 

For firms where the internal audit capability is thin, the question is not whether to address it but how quickly. The thematic review underway in Q2 2026, the approaching FATF evaluation, and VARA’s track record of public enforcement all point in the same direction.

 

J. Awan & Partners supports VARA-licensed firms with internal audit, AML/CFT risk assessments, governance framework reviews, and regulatory readiness. For a conversation, contact info@jawanpartners.com or visit jawanpartners.com.

bottom of page