Part 1 of 2
If you have spent any time looking at VARA licensing, crypto regulation in Dubai, or the requirements for obtaining a crypto licence in Dubai, you have probably noticed something quickly:
There is no single “VARA rule.”
Instead, there is a rulebook architecture.
And for many founders, that is where the confusion begins.
They expect one licence, one application form, one compliance manual, and one broad regulator conversation. What they actually find is a layered framework built around:
- the Virtual Assets and Related Activities Regulations 2023,
- a set of compulsory rulebooks that apply across the board,
- and a further layer of activity-specific rulebooks depending on whether the business is an exchange, broker, custodian, transfer provider, issuer, or something else. VARA’s Rulebook portal groups the framework into Compulsory Rulebooks and VA Activity and Other Rulebooks, and specifically lists the four compulsory rulebooks as the Company Rulebook, Compliance and Risk Management Rulebook, Technology and Information Rulebook, and Market Conduct Rulebook.
That structure matters enormously.
Because many businesses still try to understand VARA by looking only at their activity-specific rulebook. An exchange looks only at the Exchange Services Rulebook. A token issuer looks only at the issuance rules. A transfer business looks only at the transfer rulebook.
That is not enough.
Why?
Because VARA’s four core rulebooks are the baseline operating framework for all VASPs licensed by VARA to carry out any VA Activity in the Emirate. The introductory sections of the Company, Compliance and Risk Management, and Market Conduct Rulebooks all state that they apply to all VASPs Licensed by VARA to carry out any VA Activity in the Emirate, and the Technology and Information Rulebook says the same.
That means if you want to understand what regulated life under VARA really looks like, you need to understand these four rulebooks in context.
This article is designed to do exactly that.
If you have searched for:
- VARA Rulebooks explained
- Company Rulebook VARA
- Compliance and Risk Management Rulebook VARA
- Technology and Information Rulebook VARA
- Market Conduct Rulebook VARA
- VARA licence requirements
- VARA compliance requirements
- crypto regulation Dubai
then this guide is built for you.
In Part 1, we will explain:
- how the rulebook framework fits together,
- why the compulsory rulebooks matter so much,
- what the Company Rulebook is really about,
- and what the Compliance and Risk Management Rulebook actually requires in practical terms.
In Part 2, we will then move into:
- the Technology and Information Rulebook,
- the Market Conduct Rulebook,
- how these rulebooks interact with the marketing regime and activity-specific rules,
- and what founders most often misunderstand about the full VARA compliance architecture.
Let’s start with the big picture.
1) The VARA Rulebook is a system, not a single document
The first thing to understand is that VARA’s framework is intentionally layered.
The Rulebook homepage states that the Virtual Assets and Related Activities Regulations 2023 set out a comprehensive virtual assets framework built on principles of economic sustainability and cross-border financial security. Under that broader framework, VARA has issued a structured set of rulebooks rather than one single consolidated licensing code.
That layered structure is one of the reasons Dubai’s approach is more sophisticated than many founders first expect.
At a practical level, the framework works like this:
Layer 1 — The Regulations
These sit at the highest operational level inside the VARA regime and establish the broader regulatory architecture.
Layer 2 — The Compulsory Rulebooks
These apply across all VASPs and form the common baseline:
- Company Rulebook
- Compliance and Risk Management Rulebook
- Technology and Information Rulebook
- Market Conduct Rulebook.
Layer 3 — Activity-specific rulebooks
These apply in addition depending on the activity being licensed:
- Exchange Services,
- Custody,
- Broker-Dealer,
- Lending and Borrowing,
- VA Transfer and Settlement,
- and so on.
This matters because a business does not get to say:
“We are an exchange, so only the Exchange Rulebook matters.”
In reality, the exchange operator is also expected to comply with the four compulsory rulebooks, and then with the Exchange Services Rulebook on top. The same logic applies to other licensed activities.
That is the first major lesson of the VARA regime:
Your activity tells you which extra rules apply.
The compulsory rulebooks tell you what kind of regulated business you must become.
2) Why the compulsory rulebooks matter so much
Many founders think the hardest part of VARA is identifying the right licence activity.
That is certainly important. But once the activity is identified, the compulsory rulebooks are what turn the licence from a formal permission into a full operating standard.
They define how the VASP must function as a regulated business:
- how it is structured,
- how it is governed,
- how it manages risk,
- how it complies with AML/CFT,
- how it handles technology,
- and how it behaves toward customers and the market.
The intros to the four compulsory rulebooks make this very clear. Each one says it is issued pursuant to the Regulations and applies to all VASPs licensed by VARA to carry out any VA Activity in the Emirate.
That means a serious applicant should stop asking:
“Which rulebook do we need?”
and start asking:
“How do these rulebooks work together to define our regulated operating environment?”
That is the question that actually matters in practice.
3) The Company Rulebook: the operating skeleton of the VASP
The Company Rulebook is often underestimated because its title sounds generic.
Some founders assume it is just about incorporation formalities or legal housekeeping.
That is far too narrow.
The Company Rulebook is better understood as the operating skeleton of the VASP. It deals with the legal, governance, personnel, disclosure, prudential, and continuity foundations of the licensed business. The Rulebook PDF itself shows a structure that includes:
- company ownership structure,
- board of directors,
- management structure,
- responsible individuals,
- public disclosures,
- capital and prudential requirements,
- winding up and business continuity,
- and specific provisions on regulatory reporting and corporate controls.
That immediately tells you something important:
VARA is not just licensing the activity.
It is licensing a corporate organism.
And the Company Rulebook is the document that helps define whether that organism looks fit for regulated life.
Why this matters in practice
A founder may think:
- “We have incorporated the entity.”
- “We have directors.”
- “We have a management team.”
- “We have shareholders.”
That is not yet the same as having a VARA-ready company structure.
The Company Rulebook pushes the business to answer more serious questions:
- Who ultimately owns and controls the VASP?
- How is the board structured?
- What management architecture exists?
- Who are the responsible individuals?
- What public disclosures must be made?
- Can the business meet capital and prudential standards?
- What happens if the business needs to wind down?
That is why the Company Rulebook should not be seen as background noise. It is one of the central documents shaping whether the applicant looks like a credible regulated institution.
4) Company ownership structure: VARA wants clarity, not opacity
One of the first things the Company Rulebook addresses is ownership structure.
That is not surprising. A regulator licensing a VASP will want to know who owns it, who controls it, and whether the ownership chain is sufficiently transparent and governable. The Company Rulebook includes a dedicated section on Company Ownership Structure, and the application-document framework separately requires UBO information, source of funds, organisational structure, and close links / associated entities analysis.
This matters especially in crypto, where corporate structures are often:
- cross-border,
- layered,
- founder-heavy,
- SPV-based,
- or connected to broader token, treasury, or group arrangements.
From a VARA perspective, ownership opacity is not merely an inconvenience. It is a governance risk.
That is why the Company Rulebook sits so close to the licensing logic itself. Before VARA is comfortable with the activity, it needs to be comfortable that the company behind that activity is identifiable, accountable, and structurally understandable.
5) Governance under the Company Rulebook: more than just a board on paper
Another core function of the Company Rulebook is governance.
The Rulebook addresses the Board of Directors, the Management Structure, and the role of Responsible Individuals. The presence of these dedicated sections is important because it confirms that VARA expects the VASP to operate through real governance architecture, not just founder intuition.
This is one of the biggest mindset shifts for early-stage crypto businesses.
A startup mindset often assumes:
- founder-led decision-making,
- informal escalation,
- speed over formality,
- and governance that develops later.
The Company Rulebook pushes in a different direction:
- identifiable governance,
- role clarity,
- responsibility allocation,
- and structures that can withstand supervision.
Why does this matter?
Because once a business becomes licensed, the regulator is no longer just looking at the product or the transaction flow. It is looking at whether the business can:
- take decisions properly,
- oversee compliance properly,
- manage risk properly,
- and respond to problems in a structured way.
That is what governance is really about in this context.
So when people search VARA Rulebooks, one of the most useful things to understand is that the Company Rulebook is not just corporate administration. It is the governance backbone of the regulated entity.
6) Prudential requirements sit inside the Company Rulebook for a reason
Another major reason the Company Rulebook matters is that it carries the capital and prudential requirements of the VASP.
The Rulebook PDF includes Part VI – Capital and Prudential Requirements, which covers:
- Paid-Up Capital
- Net Liquid Assets
- Insurance
- Reserve Assets
- Notifications and other Requirements.
This is commercially very important because it shows that prudential standards are not being treated as a separate side issue.
They are part of the company standard itself.
In other words, VARA is saying:
- the company structure,
- the governance structure,
- and the financial resilience structure
all belong together.
This matters because a lot of founders still think:
“We have enough capital for the application fee.”
But the prudential framework is asking a different question:
“Does the VASP itself have the capital, liquidity, insurance, and reserve architecture to be a credible regulated entity?”
That is why the Company Rulebook is so central to the real economics of licensing.
7) Winding up, continuity, and public disclosures: VARA is thinking about the full lifecycle
Another revealing part of the Company Rulebook is that it does not only deal with formation and operation. It also deals with:
- Public Disclosures
- Winding Up
- and Business Continuity. The Company Rulebook PDF explicitly contains parts on public disclosures and winding up/business continuity.
That tells you something very important about the regulator’s mindset.
VARA is not only thinking about how the business starts.
It is thinking about how it behaves while operating, how transparent it is to the market, and how it exits or continues under stress.
This is exactly the kind of full-lifecycle thinking serious regulation requires.
For founders, this is also a useful reminder that a VARA licence is not just a go-live permission. It is part of a broader regulated lifecycle that includes:
- launch,
- governance,
- capital maintenance,
- disclosures,
- continuity,
- and possible wind-down.
That is one of the reasons Dubai’s framework feels more mature than many “crypto-friendly” environments that are really just under-regulated.
8) The Compliance and Risk Management Rulebook: where regulated discipline becomes real
If the Company Rulebook is the operating skeleton, the Compliance and Risk Management Rulebook is the discipline system.
Its introduction states that it forms part of the Regulations and applies to all VASPs licensed by VARA to carry out any VA Activity in the Emirate.
This Rulebook matters because it answers one of the most important practical questions in the entire VARA framework:
How is this VASP expected to control itself?
That includes:
- compliance management,
- risk management,
- AML / CFT,
- Travel Rule requirements,
- reconciliation,
- recordkeeping,
- outsourcing oversight,
- incident notification,
- and wider control architecture. The PDF and the individual rulebook pages show parts covering compliance management, risk management, AML/CFT, reconciliation, and failure-to-comply notification duties.
This is where a lot of crypto businesses get a wake-up call.
They may have:
- legal documents,
- product architecture,
- and some internal monitoring habits.
But the Compliance and Risk Management Rulebook expects something more structured:
- actual control systems,
- actual escalation pathways,
- actual risk methodologies,
- and actual responsibilities.
That is why a generic compliance template is usually not enough under VARA.
The business has to show that compliance is embedded in how it actually operates.
9) Compliance management: VARA expects a real function, not a symbolic title
One of the most important sections of the Compliance and Risk Management Rulebook is Part I – Compliance Management. VARA’s rulebook page for this part makes clear that compliance management is a dedicated component of the required framework for all licensed VASPs.
This matters because many firms still think of compliance as:
- one person,
- one outsourced manual,
- or one MLRO title attached late in the process.
But the VARA framework is looking for more than a compliance label.
It is looking for:
- a compliance function,
- compliance arrangements,
- reporting lines,
- methodologies,
- staffing appropriateness,
- and the effectiveness of the system as a whole. The Risk Management guidance page explicitly refers to the effectiveness of the compliance function, including its mandate, structure, staffing, methodology, reporting lines, and effectiveness.
This means a serious VASP should be able to explain:
- who owns compliance,
- how issues are escalated,
- how monitoring occurs,
- what reporting exists to management and the board,
- and how compliance risk is identified and managed.
That is a very different standard from:
“We hired a compliance person.”
10) Risk management: the Rulebook expects structured risk thinking
The Compliance and Risk Management Rulebook also addresses Risk Management in a substantive way.
The guidance under the risk-management section refers to risks arising from the nature and effectiveness of the systems and procedures used to identify, measure, monitor, and control the VASP’s risks, including examples such as market risk, operational risk, legal risk, and new-product risk.
This is a crucial point for crypto businesses.
A lot of founders still think about risk in very product-specific terms:
- smart-contract risk,
- wallet risk,
- counterparty risk,
- volatility risk.
Those all matter.
But the VARA framework expects risk management to be broader and more institutional. It wants the VASP to think like a regulated business:
- What are our operational risks?
- What are our compliance risks?
- What are our governance risks?
- What are our market or conduct risks?
- What are our technology risks?
- What are our AML risks?
- and how do we identify, measure, monitor, and control them?
That is why the Compliance and Risk Management Rulebook is not just about preventing wrongdoing. It is about building a systematic risk-control culture.
11) AML / CFT and Travel Rule sit inside this rulebook for a reason
One of the most important features of the Compliance and Risk Management Rulebook is that it contains the AML / CFT architecture, including the FATF Travel Rule requirements.
Rule III.G specifically addresses the Travel Rule and states that VASPs must comply with all Federal AML-CFT Laws, including Travel Rule requirements, while VARA may also require reporting on Travel Rule compliance and control effectiveness.
This matters because AML is not separated from compliance and risk management in the VARA framework. It sits inside it.
That is a strong sign that VARA sees AML / CFT not merely as a legal obligation, but as part of the VASP’s wider risk and control architecture.
In practical terms, that means the VASP’s AML programme must fit:
- the customer journey,
- the transaction environment,
- the technology environment,
- and the activity-specific risk profile of the business.
That is especially important for:
- exchanges,
- broker-dealers,
- custodians,
- and transfer and settlement providers.
12) Why Part 1 matters before you ever get to the technology and market-conduct layers
At this point, the pattern should be clear.
The first two compulsory rulebooks already show that VARA is not just asking:
- What service are you offering?
It is asking:
- What kind of company are you?
- How are you governed?
- How are you funded?
- How do you control yourself?
- How do you manage risk?
- and how do you comply with AML/CFT and Travel Rule obligations?
That is the baseline.
Only once that baseline exists does the rest of the framework — especially the technology and market-conduct layers — make sense.
And that is where we turn in Part 2.
We will look at:
- the Technology and Information Rulebook,
- the Market Conduct Rulebook,
- how disclosures, customer treatment, and technology governance fit into the bigger picture,
- and why many founders still underestimate the full breadth of the compulsory-rulebook burden under VARA.
Part 2 of 2
In Part 1, we focused on the first two compulsory rulebooks that shape regulated life under VARA:
- the Company Rulebook
- the Compliance and Risk Management Rulebook
Together, those two rulebooks answer some of the most important structural questions in the Dubai framework:
- what kind of legal and governance architecture a VASP must have,
- how compliance and risk management are expected to function,
- and why AML / CFT and Travel Rule compliance are not side issues, but core operating requirements. VARA’s Rulebook portal identifies these as two of the four compulsory rulebooks that apply to all VASPs licensed to carry out any VA Activity in the Emirate.
Now we move to the other two compulsory rulebooks:
- the Technology and Information Rulebook
- the Market Conduct Rulebook
This is where the framework becomes even more practical.
Why?
Because once a business has:
- a legal entity,
- governance,
- compliance architecture,
- and risk controls,
the next two questions become unavoidable:
How is the business’s technology expected to be governed?
And how is the business expected to behave toward customers, the market, and the wider operating environment?
That is exactly what these two rulebooks are there to answer.
And for many crypto businesses, these are the rulebooks that make the VARA framework feel especially real. Not because they are the most famous documents in the system, but because they touch the areas where a lot of crypto operators still try to rely on habit, speed, and informal practice:
- platform architecture,
- wallet and key management,
- resilience and continuity,
- disclosures,
- conflicts,
- client treatment,
- and the line between aggressive growth and regulated conduct.
So if Part 1 explains the backbone of the VARA framework, Part 2 explains much of the nervous system and outward behaviour of the regulated VASP.
Let’s begin with the technology side.
1) The Technology and Information Rulebook: why VARA treats technology as a regulatory issue
A lot of crypto-native businesses still think about technology mainly as a product advantage.
They think in terms of:
- speed,
- throughput,
- architecture,
- user experience,
- scalability,
- and deployment.
VARA does not ignore those things. But it views technology through an additional lens:
technology as a regulatory risk environment.
The Technology and Information Rulebook is one of the four compulsory rulebooks and, like the others, applies to all VASPs licensed by VARA to carry out any VA Activity in the Emirate. The structure of the rulebook includes:
- Technology Governance and Controls
- Systems and Controls
- Information Security
- Technology Testing
- Technology Audits
- Policies and Procedures
- Cyber Security
- Key and Wallet Management
- Incident Response
- and Business Continuity and Disaster Recovery.
That structure alone tells you something critical:
VARA is not treating technology as a background support function. It is treating it as a central part of whether the VASP can safely operate.
That makes perfect sense in the virtual asset sector.
For many VASPs, the technology stack is not merely adjacent to the business. It is the business:
- the exchange engine,
- the custody architecture,
- the wallet environment,
- the onboarding logic,
- the transaction-routing system,
- the settlement flow,
- the security perimeter.
So if the technology is weak, under-governed, or poorly explained, the regulator is not just seeing an IT problem. It is seeing a business-model problem.
That is one of the most important ideas in the whole VARA rulebook architecture.
2) Technology governance: VARA expects oversight, not just code
One of the first things the Technology and Information Rulebook addresses is Technology Governance and Controls. That is highly revealing because it shows that VARA expects the technology environment to be governable at management and oversight level, not just technically functional.
This matters because crypto founders often default to a different mindset:
- the engineers know the system,
- the CTO oversees it,
- the product evolves quickly,
- security improves over time,
- and deeper governance comes later.
Under VARA, that is not enough.
A regulated VASP must be able to show that the technology environment is:
- understood,
- overseen,
- controlled,
- and integrated into the business’s governance architecture.
This is especially important where:
- customer assets are involved,
- private keys are involved,
- execution or matching systems are involved,
- or outages, breaches, or malfunctions could materially affect customers or the market.
So the first major lesson of the Technology and Information Rulebook is this:
If your technology cannot be governed, it is not ready for regulated life.
That is a much higher bar than:
“The platform works.”
3) Systems, controls, and resilience: the rulebook expects operational maturity
The Technology and Information Rulebook also deals with Systems and Controls, Technology Testing, Technology Audits, Cyber Security, Incident Response, and Business Continuity and Disaster Recovery.
This is where a lot of VASPs discover that VARA is not just interested in theoretical architecture. It is interested in resilience.
The regulator wants to know, in practical terms:
- can the platform keep operating safely,
- can issues be detected,
- can incidents be handled properly,
- can critical services continue,
- and can the business recover if something goes wrong?
That is why the application-document framework separately asks for:
- technology infrastructure design,
- technology risk assessment framework and methodology,
- BCM / IT Disaster Recovery Plan,
- information security policy,
- and penetration testing results. VARA’s application page lists these as part of the required materials.
This matters commercially because many founders still treat these items as “extra documents for the regulator.”
That is the wrong way to think about them.
They are evidence of whether the VASP is technically mature enough to live inside a regulated market.
And that is especially important in crypto because the sector is so exposed to:
- outages,
- cyber threats,
- wallet compromise,
- operational failure,
- and technology-driven customer harm.
VARA is not willing to treat those issues casually.
4) Key and wallet management: one of the most crypto-specific regulatory questions
One of the clearest signs that VARA understands the virtual asset sector in practical terms is that the Technology and Information Rulebook includes a dedicated topic on Key and Wallet Management.
That is extremely important.
Because in many crypto businesses, one of the deepest operational and regulatory questions is not just:
- who owns the customer relationship,
or - who executes the service,
but:
- who controls the keys,
- who controls the wallets,
- how authorisation works,
- how segregation works,
- and what happens if something goes wrong.
This is particularly relevant for:
- custodians,
- exchanges,
- transfer and settlement providers,
- and any model where wallet control or key management sits inside the regulated service environment.
A crypto business may describe itself in any number of ways:
- platform,
- venue,
- infrastructure,
- middleware,
- wallet provider,
- custody partner.
But when the regulator reaches the key-management question, the reality of the operational model becomes much harder to hide behind branding.
That is why strong applicants usually explain wallet and key architecture with great care. Weak applicants often speak in abstractions and hope the details can wait.
Under VARA, those details are not optional.
5) Incident response and cyber security: the regulator assumes things can go wrong
Another strong feature of the Technology and Information Rulebook is that it bakes in the expectation that systems may fail, incidents may happen, and cyber risk is part of normal regulated life.
That is why the rulebook includes explicit focus on:
- Cyber Security
- and Incident Response, alongside continuity and recovery.
This is a very mature regulatory posture.
It means VARA is not licensing businesses on the assumption that:
- nothing bad will happen,
- systems will remain perfect,
- or internal teams will simply “handle it.”
Instead, it expects the VASP to have:
- prepared for problems,
- documented response pathways,
- and embedded response logic into the governance environment.
For crypto businesses, that is especially relevant because cyber risk is not peripheral. It is central.
This is also one of the reasons why technology governance under VARA should never be treated as a side conversation between engineers and outside vendors. It is a board, management, compliance, and regulatory issue.
That is the practical meaning of the Technology and Information Rulebook.
6) The Market Conduct Rulebook: where customer treatment and market behaviour become central
If the Technology and Information Rulebook asks whether the VASP can operate safely, the Market Conduct Rulebook asks whether the VASP can operate fairly, transparently, and responsibly in relation to customers and the market.
Like the other compulsory rulebooks, the Market Conduct Rulebook applies to all VASPs licensed by VARA to carry out any VA Activity in the Emirate. Its structure includes:
- General Conduct
- Client Relationships
- Conflicts of Interest
- Complaints Handling
- and Disclosures and Communications.
This is where the framework becomes especially visible from the client and market perspective.
Many founders still think the hard part of regulation is:
- the licence,
- the capital,
- the AML package,
- the technology documentation.
Those things matter a great deal.
But the Market Conduct Rulebook reminds the business of something else:
How you treat customers, what you disclose, how you manage conflicts, and how you behave in the market are also core regulated issues.
That means a business can be:
- well funded,
- technically strong,
- and even well governed,
but still create major regulatory problems if its conduct and disclosures are poor.
This is one reason the compulsory rulebooks work so well as a system. They do not let a VASP overinvest in one area and ignore the others.
7) General conduct: VARA is regulating behaviour, not just structure
One of the most important sections of the Market Conduct Rulebook is simply General Conduct. Even the existence of that heading is significant because it shows that VARA is not only focused on legal status or technical compliance. It is focused on how the VASP behaves.
That has major implications.
It means the VASP is not judged only by:
- what it is licensed for,
- what policies it has,
- or what systems it says it has.
It is also judged by:
- how it engages with customers,
- how it handles conflicts,
- how it communicates,
- how it treats complaints,
- and how its overall behaviour aligns with the expectations of a regulated market participant.
This is one reason why crypto businesses that come from a purely startup or community-growth culture often find regulated life harder than they first expect. Regulation is not only about what the business is allowed to do. It is also about how the business is expected to conduct itself while doing it.
That is the deeper role of the Market Conduct Rulebook.
8) Client relationships, disclosures, and complaints: the regulated customer-facing layer
The Market Conduct Rulebook also addresses:
- Client Relationships
- Complaints Handling
- and broader communication/disclosure expectations.
This matters because many crypto businesses still think the client-facing layer can be refined after launch.
Under VARA, that is too late.
The application materials themselves give a clue here. VARA’s published documentation examples include:
- customer journey workflows,
- terms and conditions / client agreements,
- privacy policy,
- conflicts of interest policy,
- market conduct policy,
- marketing policy and plan,
- and sample marketing materials.
That is a very important signal.
It shows that the regulator wants to understand not only how the business is built internally, but also:
- how the customer is approached,
- how the customer is informed,
- how the relationship is framed,
- and how complaints or issues are dealt with.
This is another reason why the Market Conduct Rulebook should not be read in isolation. It interacts closely with:
- the application file,
- the marketing framework,
- and the broader customer-facing obligations of the VASP.
A business that wants to look regulator-ready must be able to show that client treatment is already being thought through structurally, not just improvisationally.
9) Conflicts of interest: one of the most underestimated conduct issues
The inclusion of Conflicts of Interest as a dedicated topic in the Market Conduct Rulebook is another important clue about VARA’s priorities.
This matters because conflicts are extremely common in crypto business models, especially where firms combine:
- venue operation,
- custody,
- brokerage,
- treasury exposure,
- affiliated service providers,
- token holdings,
- market-making,
- or related-party structures.
A lot of founders think of conflicts only in the context of traditional finance.
But under a serious VASP regime, conflicts can arise in many ways:
- between customer interests and business incentives,
- between platform roles,
- between related entities,
- between issuer and market participants,
- or between different services offered by the same group.
That is why the Market Conduct Rulebook matters so much. It pushes the business to think beyond the product and into the fairness and integrity of the operating model.
And when you connect that with the Company Rulebook and Compliance and Risk Management Rulebook, the picture becomes very clear:
VARA expects a VASP not only to identify what it does, but also to identify where its own incentives may distort good conduct, and how those risks will be managed.
That is a sophisticated standard.
10) How the Market Conduct Rulebook connects with the Marketing Regulations
One of the most useful context points for founders is that the Market Conduct Rulebook does not sit alone. It exists alongside the separate Marketing Regulations 2024, which apply broadly to marketing of or relating to virtual assets and VA activities in or targeting the UAE.
This matters because some businesses think:
- conduct is one thing,
- marketing is another thing,
- and they can be managed separately.
In reality, they often overlap.
A business that has weak disclosures, weak customer framing, or weak conflict management inside the Market Conduct environment is often the same business that creates risk in:
- ads,
- token campaigns,
- influencer materials,
- event messaging,
- and platform-facing promotional communications.
So while the Marketing Regulations are a separate instrument, they fit naturally beside the Market Conduct Rulebook in the wider conduct architecture.
That is one of the reasons the VARA framework feels more integrated than many crypto operators first expect.
It is not just a licence.
It is a full regulatory environment touching:
- governance,
- compliance,
- technology,
- conduct,
- and market-facing behaviour.
11) What founders most often misunderstand about the four-rulebook framework
By this point, the logic of the compulsory rulebooks should be much clearer.
But it is worth stating directly where founders most often go wrong.
They treat the activity-specific rulebook as the whole regime
It is not. It sits on top of the four compulsory rulebooks.
They think corporate setup equals Company Rulebook readiness
It does not. Incorporation is only a small part of what the Company Rulebook is concerned with.
They reduce compliance to AML
AML is central, but the Compliance and Risk Management Rulebook is broader than AML alone. It also includes compliance management, risk management, reconciliation, outsourcing, and incident notification topics.
They treat technology as an engineering issue only
Under VARA, technology is a regulatory issue too.
They underestimate conduct
A well-funded, technically strong, licensed business can still create major problems if disclosures, client treatment, and conflicts are poorly handled.
This is why understanding the compulsory rulebooks is so important. They show that VARA is regulating the VASP as a complete operating institution, not just licensing a feature set.
12) The real purpose of the four compulsory rulebooks
If you step back, the purpose of the four compulsory rulebooks becomes much easier to see.
The:
- Company Rulebook asks whether the VASP is legally, governably, and prudentially built like a regulated entity.
- The Compliance and Risk Management Rulebook asks whether the VASP can control itself, monitor itself, and manage its risks, including AML/CFT risk.
- Technology and Information Rulebook asks whether the VASP’s systems, infrastructure, and key technical functions are secure, resilient, and governable.
- Market Conduct Rulebook asks whether the VASP behaves fairly and transparently toward customers and the market.
Together, these rulebooks answer the deeper regulatory question:
What kind of business are you, really, once you are licensed?
That is why they matter.
And that is why serious applicants should study them as an integrated framework, not as four unrelated documents.
Final takeaway
If you want to understand VARA rulebooks properly, the first thing to understand is that the compulsory rulebooks are the baseline architecture of regulated life in Dubai.
They are not optional background documents.
They are the framework that every licensed VASP lives inside.
The:
- Company Rulebook
- Compliance and Risk Management Rulebook
- Technology and Information Rulebook
- and Market Conduct Rulebook
together define the minimum corporate, prudential, compliance, technology, and conduct expectations that sit underneath every licensed VA Activity. VARA’s Rulebook portal and the introductory sections of the rulebooks make that structure clear.
That means a serious applicant should not ask only:
“What licence do we need?”
It should also ask:
“Are we prepared to become the kind of business these four rulebooks require us to be?”
That is the more useful question.
And in the long run, the more important one.
How CRYPTOVERSE Legal Can Help
At CRYPTOVERSE Legal Consultancy, we help founders, exchanges, token issuers, brokers, custodians, transfer businesses, and digital asset operators understand how the VARA compulsory rulebooks apply to their business model in practice.
Our support includes activity classification, rulebook mapping, governance and compliance framework analysis, technology and conduct-readiness reviews, Regulatory Business Plan support, and regulator-ready licensing strategy.
We help clients move beyond a narrow focus on the licence itself and toward a fuller understanding of the corporate, compliance, technology, and conduct standards they will be expected to meet once licensed.
If you want tailored guidance on how the VARA Rulebooks apply to your business — and what they mean for your licensing, governance, compliance, and operating model — contact CRYPTOVERSE Legal Consultancy to discuss your regulatory strategy.
FAQs
1. What are the VARA Rulebooks?
The VARA Rulebooks set out the regulatory requirements that licensed Virtual Asset Service Providers (VASPs) must follow in Dubai.
2. How many compulsory VARA Rulebooks are there?
There are four compulsory Rulebooks: Company, Compliance and Risk Management, Technology and Information, and Market Conduct.
3. Do all VARA-licensed VASPs follow the compulsory Rulebooks?
Yes. All VARA-licensed VASPs must comply with the four compulsory Rulebooks, along with any applicable activity-specific Rulebooks.
4. What does the Company Rulebook cover?
It covers corporate governance, ownership, management, capital requirements, public disclosures, and business continuity.
5. Why are the VARA Rulebooks important?
They establish the governance, compliance, technology, and conduct standards that every licensed VASP must meet to operate in Dubai.