ADGM: virtual asset and fiat-referenced token transfers now have their own travel rule

As late as April 2026, one section of the FSRA's Anti-Money Laundering and Sanctions Rulebook covered every kind of transfer. In the FSRA's own words, AML 10.3 "has governed wire transfers and all other value transfer arrangements", transfers of virtual…

Illustration for “ADGM: virtual asset and fiat-referenced token transfers now have their own travel rule”

As late as April 2026, one section of the FSRA’s Anti-Money Laundering and Sanctions Rulebook covered every kind of transfer. In the FSRA’s own words, AML 10.3 “has governed wire transfers and all other value transfer arrangements”, transfers of virtual assets and fiat-referenced tokens included.

That is no longer the structure. In the rulebook AML VER11.210526, Section 10.2 covers electronic fund transfers, and Section 10.3 is headed Transfers of Virtual Assets and Fiat-Referenced Tokens and the travel rule. The FSRA calls these “VA/FRT transfers”, and this briefing does too. It sets out who the section binds, what it asks of the sending and receiving firm, and the points where a transfer has to wait.

Why the FSRA split it out

The FSRA proposed the change in Consultation Paper No. 1 of 2026, dated 30 April 2026, with comments due by 14 May 2026. It gave two reasons: the New Federal AML Laws, meaning Federal Decree-Law No. (10) of 2025 and Cabinet Resolution No. (134) of 2025, and the recent publication by the NAMLCFTC of its expectations on applying the travel rule to VA/FRT transfers by UAE-based firms. The stated aim was regulatory clarity, and consistency for Virtual Asset Service Providers operating across the UAE.

The paper proposed new Rules for VA/FRT transfers, distinct from those in AML 10.2, and separate duties for the originating and the beneficiary institution. It also proposed policy, record-keeping and counterparty due diligence duties for all Authorised Persons and Recognised Bodies, a distinction between domestic or sub-USD 1,000 transfers and cross-border or higher-value ones, and specific requirements for unhosted wallets.

Note the FSRA’s own framing at the proposal stage. It called the VA/FRT changes “of substance”, but said they did not increase regulatory obligations compared with the Rules that then applied to all transfers under Chapter 10. So treat this as a re-mapping exercise first. The rules are now more specific about who does what, and your procedures should cite the new paragraph numbers.

Who it binds

Section 10.3 applies to all Authorised Persons and Recognised Bodies, with two exclusions:

  • a firm that only provides messages or other support systems for VA/FRT transfers;
  • a transfer between Financial Institutions where both the originator and the beneficiary are Financial Institutions acting on their own behalf.

It is not limited to firms that describe themselves as crypto businesses. Any Authorised Person or Recognised Body that sends or receives VA/FRT transfers is in scope.

It does not reach DNFBPs or Representative Offices. Rule 1.2.1(2) applies only Chapters 1 to 9 and 11 to 15 to a DNFBP, and Chapters 1 to 6 and 11 to 14 to a Representative Office. Chapter 10, where this section sits, is in neither list.

The section is also split by role. Rule 10.3.4 applies only when the firm is the originating institution, and Rule 10.3.5 only when it is the beneficiary institution. The Guidance adds that the FSRA considers a firm will act as one or the other, so it “does not prescribe separate obligations for intermediary institutions”.

Definitions that decide scope

Four definitions in Rule 10.3.2 do most of the work.

  • VA/FRT transfer covers any transfer of virtual assets or fiat-referenced tokens to a beneficiary on behalf of an originator through another person acting in the course of business, even where originator and beneficiary are the same person. It also covers any transfer to or from an unhosted wallet.
  • Account includes a digital wallet, and account number includes a wallet address.
  • Unhosted wallet includes a non-custodial wallet operated, held or controlled by the originator or beneficiary, where no third party provides a service beyond the technology to administer the assets or keys.
  • Domestic transfer means one where the originating and beneficiary institutions are both in the UAE, “notwithstanding that the system used to process the VA/FRT transfer may be located in another country”. Everything else is a cross-border transfer.

The relevant transfer information is, unless otherwise specified: the originator’s full name, account number and residential or business address; one of the originator’s national identity number, customer identification number or date and place of birth; and the beneficiary’s full name and account number. The Guidance adds that the address should be the one the firm verified in its CDD on the originator.

What every firm must do

Rule 10.3.3 sets the baseline for both sides of a transfer. The firm must make sure the message or payment instruction carries the relevant transfer information. It must also make sure the information stays with the transfer throughout the payment chain while the transfer is under its control. The Guidance is blunt: concealing or removing that information would breach the Rule.

The firm must also monitor VA/FRT transfers to identify and mitigate money laundering risk. That includes identifying transfers that lack relevant transfer information and following up, and identifying transfers that may be associated with illicit or suspicious activity. It also includes one requirement that goes beyond message content:

> “tracking of the transaction history of Virtual Assets or Fiat-Referenced > Tokens to accurately identify their source and destination”

A firm that sends or receives VA/FRT transfers must have adequate policies and procedures, undertake appropriate Counterparty due diligence, and keep records of everything collected, created and received under the section, detailed enough to reconstruct each transfer. The policies must deal with five named situations: a beneficiary institution that cannot receive the information; an incoming transfer without it; an incoming unhosted-wallet transfer without it; when to report to the Regulator or file a SAR/STR; and the follow-up to each of those.

The Guidance also expects firms to be aware of and comply with FATF Recommendation 15, its Interpretative Note, and Recommendation 16.

If you send: the originating institution

Before effecting a VA/FRT transfer, the originating firm must collect the relevant transfer information and verify it. It must also conduct appropriate due diligence on the beneficiary institution and satisfy itself that the institution is appropriately regulated where it is incorporated and located. The Guidance sets the minimum for that due diligence. It covers the institution’s business, reputation and regulated status, the adequacy of the AML/TFS supervision it is under, the expected volume and value of transfers, and an assessment of its money laundering controls.

Four conditions are easy to lose in a procedure document:

  • The USD 1,000 relief covers verification, not collection. Verification is not required where the daily aggregated value of VA/FRT transfers for the originator is below USD 1,000 and none of the transfers is suspicious. The duty to collect the information still stands.
  • Batch transfers must carry the information in the batch file, verified, and traceable in each beneficiary’s jurisdiction.
  • Domestic transfers may travel with only the two account numbers, but only where the information is available to the beneficiary institution by other means and the account numbers allow the transfer to be traced. The originating firm must then provide the full information within 3 business days of a request from the beneficiary institution or the Regulator, and immediately on request from a law enforcement agency.
  • A counterparty that cannot receive the information triggers best efforts to send it by other means, and a duty to consider ceasing transfers to that institution.

And one hard stop, in Rule 10.3.4(6): a firm “must not effect a VA/FRT transfer where it is unable to comply with the requirements of Rule 10.3.4”.

If you receive: the beneficiary institution

The receiving firm must identify the beneficiary and verify the beneficiary’s identity if it has not already done so. The same USD 1,000 daily-aggregate relief from verification applies, on the same no-suspicion condition. It must take reasonable measures to identify transfers that lack relevant transfer information, including post-event or real-time monitoring where feasible.

When information is missing, Rule 10.3.5(4) sets three steps. The firm must ask the originating institution for it. It must quarantine the transfer and delay making the proceeds available to the customer until the information arrives. And it must consider rejecting or returning the transfer, if technically possible, where the information does not come within a reasonable time.

There is also a reporting duty that points at the counterparty. The firm must report to the Regulator any systemic failure by an originating institution to provide required transfer information, and the steps it took in response.

Unhosted wallets: Enhanced CDD first

Rule 10.3.6 is the strictest part of the section. A firm must conduct Enhanced CDD on its customer before sending or receiving a VA/FRT transfer to or from an unhosted wallet on that customer’s behalf.

  • Outgoing: the firm must request any relevant transfer information it does not already hold, and must not proceed until it is provided.
  • Incoming, without the information or before Enhanced CDD is done: the firm must take reasonable steps to get the missing information from the customer, quarantine the transfer, and hold back the proceeds until the information is received or Enhanced CDD is completed. It must consider rejecting or returning the transfer, if technically possible, where the information is not provided, Enhanced CDD is not completed within a reasonable time, or its outcome is not satisfactory.

For the reject, return or cease decisions under 10.3.4(5)(b), 10.3.5(4) and 10.3.6(3), the Guidance lists the factors to weigh. They include the money laundering risk of the transfer, the results of customer risk assessments and CDD, how often the customer transfers, the value of the transfer and any linked transfers, and what the firm has learned from the counterparty institution.

Four things worth doing

  1. Re-map your citations. If your travel-rule procedure cites AML 10.3 for wire transfers generally, it now points at a crypto-specific section. Fiat electronic transfers are in 10.2. Check the numbering in policies, control libraries and board reporting.
  2. Separate “collect” from “verify” in your workflow. The USD 1,000 relief is daily and aggregated per originator or beneficiary, and it falls away once any transfer is suspicious. A per-transaction threshold switch does not implement that.
  3. Write the quarantine down. Rules 10.3.5(4) and 10.3.6(3) require a transfer to be held and proceeds delayed. Decide who releases a quarantined transfer, on what evidence, and what counts as “a reasonable time” before you consider return.
  4. Make counterparty failure reportable. Track missing-information events by originating institution, so that a systemic failure is visible and can be reported to the FSRA with the steps you took.

SonarPulse in this jurisdiction: AML/CFT screening software for the UAE, ADGM and DIFC


Sources

This article draws on the following sources. Follow the links for the original text.

Start with a compliance health check.

A working session with your compliance team, then a walkthrough against your own risk appetite: the lifecycle end to end, scoring weights set to your policy, and a review of the audit trail the system produces.

Or write to info@sonarpulse.mu