Skip to main content
TCJ

Crypto

Client Asset Segregation in UAE Virtual Asset Businesses: Why Structure Matters

Client asset segregation is more than separate crypto wallets. This UAE-focused guide explains how VASPs can align ownership, client money, custody, reconciliation, governance and third-party controls.

By Mandeep Masoun·Published ·10 min read
Client Asset Segregation in UAE Virtual Asset Businesses: Why Structure Matters
Client Asset Segregation in UAE Virtual Asset Businesses: Why Structure Matters

Client Asset Segregation in UAE Virtual Asset Businesses: Why Structure Matters

Key takeaways

  • Client asset segregation requires legal, operational and Accounting separation; creating additional wallet addresses alone is not sufficient.
  • Dubai VASPs should distinguish Client Money, Client Virtual Assets and assets held under Custody Services because different requirements can apply.
  • Daily reconciliation is a core control for demonstrating that client records correspond with assets actually held.
  • Custody Services under VARA are subject to stricter client-specific wallet segregation and rehypothecation restrictions.
  • Banks and third-party custodians can support segregation, but outsourcing does not remove the need for appropriate governance, records and oversight.
  • Management should test whether individual client entitlements could still be identified accurately during a disruption, regulatory review or insolvency scenario.

What does client asset segregation mean for a virtual asset business?

Client asset segregation means maintaining a clear and defensible separation between assets belonging to customers and assets belonging to the VASP. The separation should allow the business to identify what is held for clients, determine each client's entitlement and distinguish those balances from corporate treasury, operating cash and proprietary virtual assets.

In practice, a segregation framework may involve:

  • Dedicated Client Accounts for qualifying client fiat money.
  • Separate wallets for client virtual assets and corporate virtual assets.
  • Client-level sub-ledgers capable of identifying individual entitlements.
  • Defined controls over deposits, withdrawals, transfers and fees.
  • Reconciliation between accounting records, bank balances and blockchain records.
  • Restrictions on the use of client property for corporate purposes.
  • Clear legal and contractual treatment of ownership.

A platform can therefore have several blockchain addresses and still have weak segregation if its Accounting records cannot establish who owns the balances.

Strong client asset protection is demonstrated by how assets move, remain identifiable and reconcile in practice—not by policy wording alone. — Consulting Journal editorial observation

Why is client asset segregation a regulatory priority in Dubai?

Segregation reduces the risk that customer assets become mixed with a VASP's own financial position, used for unauthorised purposes or made difficult to identify during financial distress. For regulators, the concern therefore extends beyond cybersecurity to ownership, governance, accounting accuracy, liquidity practices and insolvency protection.

VARA's Client Money rules state that Client Money held by a VASP is not owned by the VASP and should not form part of its estate if it becomes insolvent. The rules require qualifying Client Money to be maintained in Client Accounts and require systems that keep those funds identifiable and secure.

VARA applies a corresponding principle to Client Virtual Assets. Its rules state that Client VAs are not owned by the VASP and should not form part of the VASP's estate on insolvency. They must also be held separately from the VASP's proprietary virtual assets.

International regulatory thinking follows a similar direction. IOSCO's recommendations on crypto and digital asset markets emphasise adequate protection of client assets, accurate records and controls capable of establishing their nature, amount, location and ownership status.

Why are separate crypto wallets not enough?

Wallet separation is an important technical control, but effective segregation also requires the legal, Financial, Accounting and operational records to agree. A VASP should be able to connect blockchain balances to internal client entitlements and explain every movement between client, settlement, treasury, fee and other operational wallets.

Consider a business that places client virtual assets in designated wallets but records transactions through an incomplete internal ledger. The blockchain may show sufficient assets in aggregate, yet management may still be unable to determine how much belongs to each client.

The opposite problem can also occur. An Accounting system may accurately record customer balances while actual assets have moved through an inappropriate wallet or bank account.

Good segregation therefore requires the records and the assets to tell the same story.

How should client money and client virtual assets be treated differently?

Client fiat money and client virtual assets present different operational risks and should not be treated as one control category. Fiat arrangements normally rely on banking infrastructure and cash ledgers, while virtual asset controls also involve wallet ownership, private keys, blockchain records, custody systems and transaction-authorisation mechanisms.

Under VARA's framework, Client Money does not include Virtual Assets held on behalf of clients. Client Money is subject to specific requirements concerning Client Accounts, payments, record keeping and reconciliation.

The distinction matters operationally. A Dubai VASP may have strong wallet security yet still create risk if customer fiat passes through an ordinary corporate operating account.

Likewise, well-managed banking arrangements cannot compensate for weak wallet governance.

Example 1:

A fictional Dubai broker, Gulf Digital Markets LLC, receives client dirham deposits for transactions while also receiving operating revenue into corporate bank accounts.

Its Finance team initially relies on payment references to distinguish customer money from business revenue. As volumes increase, unidentified receipts and timing differences accumulate.

A stronger approach would separate qualifying Client Money through correctly structured accounts, maintain client-level ledgers and establish daily reconciliation and escalation procedures. The key improvement is not simply adding another bank account. It is connecting the account structure to the Accounting process and client records.

Why does reconciliation make segregation credible?

Reconciliation provides evidence that the assets recorded as belonging to clients correspond with what the VASP actually holds. Without regular reconciliation, differences between bank accounts, blockchain balances, wallet systems and internal ledgers can remain undetected until a withdrawal request, audit, regulatory review or liquidity event exposes them.

VARA requires VASPs subject to its Client Money rules to maintain daily Client Account reconciliation processes. These include comparisons between individual client ledger balances, Client Account cash-book balances and third-party bank balances, together with investigation and corrective action for relevant differences.

The VARA framework also requires daily reconciliation of virtual assets owned by each client and notification where a material discrepancy remains unresolved.

For management, reconciliation should therefore be treated as a control process rather than a month-end Accounting exercise.

A practical process should define:

  • Which systems constitute the official source of client balances.
  • Who prepares the reconciliation.
  • Who independently reviews it.
  • How timing differences are documented.
  • How shortfalls or unexplained movements are escalated.
  • When senior management and compliance teams are notified.
  • What evidence is retained for audit and regulatory review.

Who should be able to control client assets?

Access to client assets should follow defined roles, approval limits and segregation of duties. A technically segregated wallet remains vulnerable if one individual can initiate, approve, execute and reconcile transactions without independent oversight.

Depending on the VASP's scale and operating model, businesses should consider controls such as:

  • Role-based wallet and banking access.
  • Maker-checker approval for transfers.
  • Transaction thresholds and approval limits.
  • Restricted access to private-key or signing infrastructure.
  • Independent reconciliation.
  • Complete audit trails.
  • Documented emergency-access processes.
  • Immediate removal of access when responsibilities change.

For UAE businesses, these controls should also align with the organisation's broader governance, compliance, Finance and cybersecurity frameworks rather than operating as an isolated custody procedure.

Does using a bank or third-party custodian remove the VASP's responsibility?

Outsourcing can reduce certain operational burdens, but it does not automatically resolve segregation risk. The VASP should understand how the provider holds the assets, how ownership is recorded, what contractual rights exist and what would happen if the provider or the VASP experienced financial difficulty.

Due diligence should examine matters such as account designation, access rights, contractual liens or set-off provisions, reporting arrangements, reconciliation support and insolvency treatment.

VARA's Client Money framework includes requirements concerning third-party banks and acknowledgement of the nature of Client Accounts. This reinforces an important practical point: choosing a reputable bank is not the same as establishing an appropriately structured client-money arrangement.

Example 2:

A fictional UAE virtual asset platform, Crescent Token Services, outsources custody technology to an established international provider.

Management assumes the outsourcing arrangement means its segregation obligations have been addressed. During an internal review, however, the business discovers that operational teams cannot readily reconcile the custodian's records to individual customer balances in the platform's own ledger.

The response should not be limited to renegotiating the vendor contract. The VASP would also need to examine data feeds, internal records, reconciliation ownership, access permissions, escalation procedures and the legal custody structure.

Can a VASP use or rehypothecate client virtual assets?

A VASP should never assume customer assets are available for its own liquidity, lending, staking or collateral purposes. Whether any use is permitted depends on the licensed activity, contractual authority and applicable rulebook, and businesses need to distinguish general client-asset arrangements from regulated Custody Services.

This distinction is particularly important under VARA.

The general Client VA rules permit rehypothecation only where specified conditions are met, including explicit prior client consent and the appropriate VARA authorisation and licensing for the relevant activity.

Custody Services are stricter. VARA's current Custody Services Rulebook prohibits rehypothecation of virtual assets held as part of Custody Services even where client consent has been obtained. It also requires Custody Services providers to segregate each client's virtual assets into separate client-specific wallets.

Businesses should therefore map the exact service being provided before deciding what can be done with client assets.

What common mistakes do virtual asset businesses make?

Many segregation weaknesses originate in business architecture rather than deliberate misuse.

Common issues include:

  • Treating multiple wallet addresses as sufficient evidence of segregation.
  • Allowing corporate and customer funds to pass through the same banking workflow.
  • Failing to maintain reliable individual client ledgers.
  • Reconciling only periodically when more frequent reconciliation is required.
  • Allowing unexplained reconciliation differences to remain open.
  • Giving excessive wallet, banking or private-key access to operational staff.
  • Failing to define the treatment of fees, network charges and settlement differences.
  • Using client balances as operational liquidity without analysing the relevant regulatory restrictions.
  • Assuming an outsourced custodian or bank carries all compliance responsibility.
  • Allowing contractual descriptions of client assets to differ from actual operational practices.
  • Adding new products without reassessing existing segregation controls.

Rapid growth often makes these weaknesses more visible. A control structure designed for a small number of customers may not remain effective as transaction volumes, products, entities and jurisdictions increase.

What documents should a VASP prepare or review?

A useful segregation review starts by tracing every location where client money or virtual assets are received, held, transferred, controlled or returned.

Management should typically prepare or review:

  • Corporate and group structure charts.
  • VARA licence scope and permitted activities.
  • Client agreements and terms of service.
  • Client-money bank account documentation.
  • Bank acknowledgements and account mandates.
  • Complete wallet inventories.
  • Identification of client and proprietary wallets.
  • Private-key and signing-control policies.
  • Client-level ledger structures.
  • Wallet-to-ledger reconciliation procedures.
  • Bank reconciliation procedures.
  • Daily control reports and review evidence.
  • Deposit and withdrawal workflows.
  • Fee and network-cost treatment.
  • Custodian and banking agreements.
  • Outsourcing and vendor due-diligence records.
  • Access-control matrices.
  • Shortfall and discrepancy escalation procedures.
  • Insolvency and business-continuity documentation.
  • Internal and external audit findings.

Documentation should describe what actually happens operationally. Policies that are technically well written but inconsistent with system behaviour can create additional compliance risk.

How can KPM Global Services UAE assist?

KPM Global Services UAE can support virtual asset businesses with the Financial, Accounting and operational elements that sit behind a workable segregation framework.

Depending on the activity and regulatory perimeter, support may include reviewing client-money and Accounting workflows, mapping transaction flows, improving reconciliation procedures, documenting Financial controls, reviewing ledger structures, preparing supporting schedules and coordinating information required for management, auditors or specialist regulatory advisers.

For businesses preparing for licensing, operational changes or regulatory review in Dubai or the wider UAE, an early assessment can also identify where written procedures differ from the way funds and virtual assets actually move through the organisation.

Regulatory interpretation and legal ownership questions should be addressed with appropriately qualified legal and regulatory advisers where required.

What should management focus on next?

Client asset segregation should be tested as an operating system rather than treated as a compliance statement. Management should be able to trace a client balance from the customer ledger to the relevant bank account or wallet, explain each movement and demonstrate that corporate assets remain distinguishable.

For Dubai VASPs, the specific requirements depend on the licensed activity. Custody Services can carry requirements that differ from broader Client VA arrangements, and Client Money follows a separate framework again. Businesses should therefore assess segregation at legal, operational, technology and Accounting levels before launching new products or changing asset flows.

This article is for informational purposes and does not constitute legal, tax, accounting, or financial advice.

Questions and answers

Q: What is client asset segregation in a UAE virtual asset business?

A: Client asset segregation is the separation of customer-owned money and virtual assets from property belonging to the VASP. In practice, it can involve bank accounts, virtual asset wallets, client ledgers, access controls, reconciliation procedures and contractual arrangements.

Q: Does every client's crypto need a separate wallet under VARA?

A: Not for every type of VASP arrangement, so the exact licensed activity matters. However, VARA's Custody Services Rulebook specifically requires VASPs providing Custody Services to segregate each client's virtual assets in separate wallets containing only that client's assets.

Q: How often should a Dubai VASP reconcile client money?

A: VARA's Client Money rules require accurate Client Account reconciliations to be performed daily. The process includes comparing client ledger balances with cash-book and third-party bank balances and addressing relevant shortfalls or unresolved differences.

Q: Can a VARA-regulated VASP use client assets for its own liquidity?

A: A VASP should not treat client assets as freely available corporate liquidity. VARA restricts the use of Client Money for the VASP's own balance-sheet purposes, while rules governing the use or rehypothecation of Client VAs depend on the licensed activity and applicable regulatory conditions.

Q: Does outsourcing custody solve client asset segregation requirements?

A: No. Outsourcing may provide custody infrastructure, but the VASP should still assess ownership records, contractual terms, reconciliation, access controls, reporting and insolvency treatment. The applicable responsibilities depend on the VASP's licence, service model and regulatory framework.