Why High-Risk Activities (Crypto, Gold, Brokerage) Face Extra UAE Banking Scrutiny
Many founders are surprised when a licensed UAE company in crypto, gold or brokerage waits weeks for a bank account — or is asked for source-of-wealth files that a trading company never sees. The reason is not personal. It is how UAE banks apply a risk-based standard under Central Bank of the UAE (CBUAE) rules, the national AML/CFT framework, and the country’s National Risk Assessment. Understanding why high-risk activities (crypto, gold, brokerage) face extra UAE banking scrutiny is the first step toward preparing a file that a compliance officer can actually defend.
This article is educational. It explains the regulatory
logic banks follow, the documents they typically request, and the gaps that
slow onboarding. If you are also mapping how a corporate account is assembled
in practice, our overview of UAE corporate bank account opening sets out the standard file banks expect before enhanced
checks begin.
What “high-risk” means to a UAE bank
In banking language, “high-risk” is not a moral label. It
is a residual-risk rating after the bank looks at the customer, the activity,
the geography, the delivery channel and the expected transaction pattern. Under
CBUAE guidance and Cabinet-level AML implementing rules, licensed financial
institutions must apply customer due diligence (CDD) to every relationship and
enhanced due diligence (EDD) where risk is higher.
Crypto, physical gold and securities brokerage sit in
that higher band for structural reasons: value can move quickly, often across
borders, sometimes with limited visibility of the original payer, and the same
product can be used for legitimate trade or for layering proceeds of crime. The
UAE’s second National Risk Assessment has treated virtual assets and dealers in
precious metals and stones as elevated-risk sectors. Banks take that national
picture and translate it into onboarding questions.
A grocery importer and a VARA-facing virtual-asset firm
can hold the same free-zone licence class on paper and still receive two
completely different compliance paths. The bank is rating the activity, not the
free zone.
The legal frame banks are protecting
UAE banks do not invent this intensity. They implement
it.
•
Federal AML/CFT law (the
current framework updated by Federal Decree-Law No. 10 of 2025, building on
Decree-Law No. 20 of 2018) and its Cabinet implementing regulations.
•
CBUAE rulebook requirements
on CDD, beneficial ownership, politically exposed persons, high-risk countries,
new technologies, and ongoing monitoring.
•
Sector supervisors: VARA in
Dubai (excluding DIFC) for many virtual-asset activities; the Securities and
Commodities Authority (SCA) for investment-related virtual assets and brokerage
on the mainland; CBUAE for banks themselves and for payment-token activity.
•
Ministry of Economy
supervision of designated non-financial businesses and professions (DNFBPs),
including dealers in precious metals and stones once a cash or linked
transaction reaches AED 55,000.
•
FATF standards on virtual
assets, precious metals and securities, which the UAE has spent several years
aligning with after leaving the grey list.
When a bank refuses a thin file, it is usually protecting
its own licence. CBUAE enforcement in recent years has included large fines on
banks and exchange houses for weak CDD, late suspicious-transaction reporting
and inadequate EDD on higher-risk customers. Compliance officers remember those
cases when they open a crypto or gold file.
Why crypto attracts extra banking scrutiny
Virtual assets combine speed, cross-border reach and, in
some models, limited identification of the counterparty. CBUAE guidance for
licensed financial institutions on virtual assets and VASPs asks banks to treat
VASP customers as a distinct class, not as ordinary corporates that happen to
mention “blockchain” on a website.
What banks look for in a crypto file
•
Whether the company is a
licensed VASP, an unlicensed introducer, an OTC broker, or a firm that only
invests its own treasury.
•
The tokens handled: privacy
coins, mixers, unhosted wallets and DeFi bridges raise the rating; a narrow,
licensed list lowers it.
•
Travel Rule readiness,
wallet screening and sanctions controls if the firm touches client assets.
•
Volume expected to pass
through the fiat account: converting client crypto to dirhams or dollars is a
different risk from paying office rent.
•
Jurisdictions of
counterparties. FATF high-risk and increased-monitoring lists are now expected
to sit inside the firm’s own risk assessment, not only the bank’s.
Peer-to-peer activity run through personal accounts,
“crypto hawala,” and nested VASP relationships appear repeatedly in UAE
Financial Intelligence Unit typology work. That is why a bank may ask for
wallet-flow evidence, a list of exchange counterparties, and proof that client
funds will not sit in the company’s operating account without a custody trail.
A common misunderstanding is that a free-zone trading
licence that mentions “technology” is enough. Banks distinguish a software
studio from a firm that transmits, exchanges or custodians virtual assets. If
the website, invoices or expected SWIFT traffic look like VASP activity, the
bank will apply VASP-level questions even if the licence wording is broader.
Why gold and precious metals attract extra
banking scrutiny
Gold is compact, globally priced, easy to melt and
re-paper, and historically used in trade-based money laundering. The UAE is one
of the world’s major gold hubs. That commercial strength is exactly why
supervisors treat dealers in precious metals and stones as a high-vulnerability
DNFBP sector.
Typical gold-sector red flags banks are trained to see
•
Bullion or scrap sourced
from countries with little or no mine production.
•
Large cash or near-cash
settlements just under reporting thresholds.
•
Invoices that do not match
assay, weight, purity or shipping documents.
•
Rapid in-and-out flows with
limited inventory or warehouse evidence.
•
Customers who cannot show a
coherent source of wealth for repeated high-value purchases.
Dealers crossing the AED 55,000 threshold must apply CDD
and report to the FIU. Banks, watching from the other side of the payment, want
to see that the customer already behaves like a supervised dealer: KYC on its
own buyers, responsible-sourcing records, and books that reconcile metal
movements with bank credits.
Enforcement has been visible. Inspection campaigns have
suspended refineries and fined dealers for weak customer checks and ignored
suspicious activity. A bank that onboards a gold trader without asking where
the metal and the money come from is taking a documented national risk onto its
own balance sheet.
Why brokerage faces extra banking scrutiny
Securities and commodities brokers, advisors and
investment managers are financial institutions under UAE AML rules, not
ordinary consultancies. Client money, omnibus accounts, introducing-broker
chains and cross-border execution create the same layering opportunity that
banks already monitor in correspondent relationships.
SCA-licensed brokerage and investment activity, and
VARA-licensed virtual-asset brokerage, both imply that third-party funds may
touch the firm. The bank therefore asks:
•
Is this proprietary trading
only, or are client assets involved?
•
Where is custody held, and
under which licence?
•
How are commissions,
spreads and client withdrawals booked?
•
Which markets and which
introducing brokers feed the flow?
•
Are there retail clients in
jurisdictions the bank itself would not onboard?
A brokerage that describes itself as “advisory only” but
expects large incoming wires from many unrelated individuals will be treated as
a payments business. Consistency between the licence, the website, the
contracts and the expected account activity is what shortens the review.
What extra scrutiny looks like in practice
Founders often describe the process as “the bank asking
the same question five times.” From the bank’s side, each question maps to a
control.
1. Source of funds and source of wealth
Source of funds explains this transfer. Source of wealth
explains how the shareholder built the capital behind the company. For crypto,
that may mean exchange statements, wallet history and tax filings from the home
country. For gold, it may mean historic trading books, refinery invoices and
audited accounts. For brokerage, it may mean prior regulatory licences and
capital-introduction records. Bank statements alone are rarely enough if the
trail stops at another high-risk account.
2. Ultimate beneficial ownership
UAE rules require identification of beneficial owners.
Complex holding stacks, nominee arrangements and last-minute shareholder
changes delay files. Banks will compare the UBO register, the memorandum, the
bank form and the passport copies until they match.
3. Economic substance and purpose of account
A one-person free-zone company expecting AED 40 million a
month in gold or token conversion will be asked where the team, warehouse,
custody or licensed platform sits. Substance is not only a corporate-tax topic.
It is how a bank tests whether the story is commercial.
4. Ongoing monitoring after the account opens
EDD does not end at approval. Expected-activity letters
become a measuring stick. Sudden spikes, new corridors, cash-heavy patterns or
payments to unlicensed VASPs can freeze credits or trigger a refresh of KYC.
Keeping books that match the original narrative is part of staying bankable.
A customer’s experience: opening a bank file
in a high-risk activity
I came to Dubai to set up a small precious-metals trading
company after years of dealing with refiners from home. The licence was issued
in three weeks. I assumed the bank account would follow. It did not.
The first bank took the licence, passports and a one-page
plan. Two weeks later compliance asked for personal tax returns, a letter from
my previous refiner, storage photos, a monthly-ounce forecast, and an
explanation of inbound transfers from buyers I had not met yet. I felt they
were treating me as a suspect. They were treating the sector.
What changed the file was a coherent pack: licence,
website and trade name saying the same thing; a source-of-wealth note that
started with my earlier company; and a metal trail from assay and logistics to
payment. The accountant set the ledger so future statements would match that
story.
The account still took longer than a consulting firm’s
account. A later review on a new corridor closed because the books matched the
original expected-activity letter. A friend who used personal accounts “just
for the first deals” is still answering questions. Extra scrutiny is real. It
is manageable when banking is treated as a compliance file, not a formality
after the licence.
How firms in these sectors usually
strengthen the file
None of the steps below replace a bank’s own decision.
They reduce the number of times the file is returned.
•
Match the licence to the
real activity. If you exchange, broker
or custody virtual assets, the licence and supervisor should say so. If you
only sell software, the website should not look like an exchange.
•
Write the
expected-activity letter in numbers.
Corridors, currencies, monthly ranges, and whether funds are proprietary or
client money.
•
Document source of
wealth before the first application.
Older companies, audited accounts and tax filings travel better than a single
recent crypto liquidation.
•
Keep UBO and shareholder
documents identical across every page.
Inconsistencies are treated as a risk indicator, not as a typing error.
•
Build bookkeeping that a
compliance officer can read. Invoices,
inventory or wallet references, and bank credits should tell the same story.
Clean ledgers also support VAT and corporate tax later.
•
Do not run regulated
activity through personal accounts “temporarily.” FIU typology work already flags that pattern.
Companies that treat formation, banking and accounting as
one file — rather than three disconnected vendors — tend to answer EDD
questions faster because the narrative already exists.
What extra scrutiny is not
It is not a ban on crypto, gold or brokerage in the UAE.
The country has built dedicated supervisors precisely so these activities can
operate in public view. It is not a guarantee of refusal. Many licensed firms
bank successfully once the file matches the risk. And it is not something a
consultant can waive. Banks remain independently responsible for their
customers.
The practical distinction is between a company that can
show a supervised model and a company that only has a generic trading licence
and a high-risk website. The first still faces EDD. The second faces EDD plus
doubt.
Key takeaways
•
UAE banks apply extra
checks to crypto, gold, and brokerage because national risk assessments and
CBUAE guidance classify those activities as higher ML/TF exposure.
•
Enhanced due diligence
usually means deeper source-of-funds and source-of-wealth evidence, tighter UBO
checks, and closer monitoring after the account is live.
•
Licence wording, website
claims, and expected SWIFT traffic must describe the same business.
•
Personal-account
workarounds and unlicensed VASP or OTC flows are known red flags.
•
Preparation of the file is
the part a company can control; approval remains the bank’s decision.
About the author
This article was written by Exactitude Business Services
(www.exactitudebusiness.com), a Dubai-based corporate services firm that
supports business formation, corporate accounting and bookkeeping, PRO
services, attestation and legal documentation, and visa processing in the UAE.
Our work sits next to bank onboarding every week, which is why this briefing
focuses on how compliance teams actually read a file rather than on marketing
claims.

Comments
Post a Comment