Skip to main content
TCJ

Crypto

UAE Stablecoin Rules Explained for Payment Businesses

The UAE regulates stablecoin payment activities through a dedicated CBUAE framework. Payment firms, issuers, wallets and merchants should assess licensing, governance and compliance obligations before launching services.

By Mandeep Masoun·Published ·10 min read
UAE Stablecoin Rules Explained for Payment Businesses
UAE Stablecoin Rules Explained for Payment Businesses

UAE Stablecoin Rules Explained for Payment Businesses

Key takeaways

  • UAE payment-token issuance, conversion, custody and transfer are regulated activities.
  • A token’s overseas availability does not make it automatically permitted for UAE payments.
  • Algorithmic stablecoins and privacy tokens are prohibited under the CBUAE framework.
  • Merchants should verify both the provider’s authorisation and the token’s permitted use.
  • The applicable regulator depends on the activity, entity and UAE jurisdiction.

What are the UAE stablecoin rules?

The UAE regulates qualifying stablecoin payment activities through the Central Bank of the UAE Payment Token Services Regulation. The framework covers payment-token issuance, conversion, custody and transfer, while imposing licensing, governance, reserve, disclosure, technology and financial crime controls on businesses operating within its scope.

The regulation took effect on 31 August 2024 and remains in force. It establishes three principal categories of regulated services: Payment Token Issuance, Payment Token Conversion, and Payment Token Custody and Transfer.

For founders and payment businesses, the practical issue is not simply whether a token is described as a “stablecoin”. The business must assess what the token represents, how it maintains its value, which services are being provided, where customers are located, and which UAE regulator has jurisdiction.

A fintech company issuing tokens presents a different regulatory profile from a merchant accepting payments through a third-party provider. A wallet safeguarding customer keys may also face different requirements from a technology company supplying non-custodial software.

Why did the UAE introduce a dedicated payment-token framework?

The framework was introduced to place stablecoin-based payment services within a supervised financial-services environment. Payment tokens can support settlement, merchant payments and cross-border transactions, but they also create risks involving customer funds, reserve quality, redemption, cybersecurity, financial crime and operational continuity.

The CBUAE treats payment-token services as part of the UAE’s regulated digital payments infrastructure rather than as an unrestricted extension of the wider crypto market. This approach gives legitimate businesses a defined route to market while placing customer-facing payment activity under regulatory oversight.

The distinction matters because a token may be technically functional but still unsuitable for regulated payment use. Businesses must consider the issuer, reserve arrangements, redemption rights, applicable currency, distribution model and authorisation status.

A stablecoin project should map its regulated activity before investing heavily in technology, customer acquisition or commercial partnerships. — Consulting Journal consultant observation

What qualifies as a payment token?

A payment token is generally a virtual asset designed to maintain a stable value by reference to a fiat currency and used for payment-related purposes. The regulatory definition and treatment depend on the token’s structure, reference currency, issuance model and intended use.

The framework distinguishes between Dirham Payment Tokens and Foreign Payment Tokens. Tokens issued as Dirham Payment Tokens must be denominated in UAE dirhams, while Foreign Payment Tokens must be denominated in a foreign currency. The regulation also restricts issuers from paying interest based on how long a customer holds a payment token.

Not every virtual asset described commercially as a stablecoin will automatically qualify for payment use in the UAE. A token’s availability on an international exchange does not establish that it can be issued, promoted, converted or used for merchant payments under the applicable UAE framework.

Businesses should therefore avoid relying only on the token’s name, market capitalisation or overseas regulatory position.

Which payment-token services require authorisation?

Businesses generally require the relevant licence or registration when they provide payment-token issuance, conversion, custody or transfer services by way of business. The correct authorisation route depends on the activity, legal entity, existing regulatory status and token type.

Payment Token Issuance

Issuance involves creating and supplying a payment token to customers. An issuer may need to demonstrate appropriate reserve arrangements, redemption procedures, governance, financial resources and customer disclosures.

A payment-token issuer must submit a white paper to the CBUAE for review and acceptance before selling or transferring the token to a person in the UAE, subject to the scope and exclusions set out in the regulation. An audit report relating to the white paper must also be submitted.

Payment Token Conversion

Conversion generally covers buying or selling payment tokens for remuneration, whether the provider acts as principal, agent or facilitates offers between counterparties.

A virtual asset exchange operator, bank or exchange house may follow a registration or non-objection pathway for specified conversion activities, depending on its existing authorisation and the type of payment token involved. Other operators may require a dedicated CBUAE licence.

Payment Token Custody and Transfer

Custody and transfer can include safeguarding payment tokens, holding private cryptographic keys for customers, administering wallets or transferring tokens on a customer’s behalf.

The definition can also cover merchant-acquiring-style arrangements that enable a merchant to receive payment tokens for goods or services. Technology providers that only supply software enabling customers to safeguard their own assets may be treated differently, depending on the actual control they exercise.

Which businesses should review the regulation?

Any organisation participating in a stablecoin payment flow should consider whether it performs a regulated function, even when that function is not described internally as a financial service.

Businesses that commonly require a regulatory-perimeter assessment include:

  • Stablecoin and payment-token issuers
  • Payment service providers
  • Merchant acquirers and payment processors
  • Digital wallet providers
  • Crypto exchanges and brokers
  • Remittance and cross-border payment businesses
  • Banks and exchange houses
  • E-commerce payment gateways
  • Financial technology companies
  • Businesses providing custody or token-transfer services
  • Overseas companies targeting UAE customers

An overseas incorporation does not automatically place a business outside the framework. Foreign issuers and service providers may have UAE registration or licensing obligations depending on how their services are offered and whether UAE persons are targeted.

Example 1:

A Dubai mainland fintech develops a wallet that holds customers’ private keys and allows users to transfer a foreign currency-backed stablecoin to participating merchants. Although the founders describe the company as a software platform, the control of customer keys and execution of transfers may bring the model within payment-token custody and transfer requirements.

Which stablecoin activities are prohibited?

The regulation prohibits issuing or providing services involving algorithmic stablecoins and privacy tokens. Businesses must also avoid promoting regulated payment-token services without the required authorisation.

Algorithmic stablecoins typically attempt to maintain value through software, supply adjustments or related mechanisms rather than qualifying reserve assets. Privacy tokens are designed to disguise or materially obscure transaction details or participant identities.

The CBUAE framework expressly restricts activities and promotions involving these token categories. Similar restrictions also appear in the digital asset frameworks used within ADGM and the DIFC.

A business should not assume that a token is acceptable merely because it is available through a global exchange or decentralised platform. Product approval, service authorisation and geographic availability are separate questions.

What compliance controls should payment businesses establish?

A licence application is only one part of regulatory readiness. Payment-token businesses typically need a working compliance framework covering governance, financial crime, technology, customer protection, recordkeeping and operational resilience.

The CBUAE considers payment-token services to carry heightened money laundering and terrorist financing risk because of their speed, potential anonymity and cross-border nature. Regulated firms are expected to maintain effective AML and counter-terrorist financing policies, procedures and controls.

Businesses should consider establishing:

  • A documented AML and customer due diligence framework
  • Sanctions and transaction-screening procedures
  • Suspicious transaction escalation and reporting controls
  • Governance responsibilities approved by senior management
  • Technology and cybersecurity risk assessments
  • Private-key and wallet-management controls
  • Customer asset segregation procedures
  • Incident response and business continuity plans
  • Complaint handling and customer support procedures
  • Clear fees, risk disclosures and redemption terms
  • Financial records capable of supporting regulatory reporting
  • Outsourcing and third-party risk controls
  • Independent compliance testing and internal audit arrangements

Policies should reflect the actual operating model. Generic templates that do not explain transaction flows, access rights, reserve arrangements, reconciliation processes or customer-fund controls are unlikely to provide a reliable compliance foundation.

Can UAE merchants accept stablecoin payments?

A UAE merchant may be able to accept an approved payment token through an appropriately authorised provider. However, the merchant should verify the regulatory status of the provider, the permitted status of the token and the structure of the settlement arrangement before offering the payment method.

The fact that a customer can send a token to a blockchain address does not mean the merchant has implemented a compliant payment channel. The arrangement may involve conversion, custody, transfer, merchant acquiring, settlement or promotion activities.

Merchants should ask:

  • Is the payment provider licensed or registered for the relevant activity?
  • Is the token permitted for the proposed payment use?
  • Who holds the customer’s assets or private keys?
  • Does the merchant receive tokens or a fiat settlement?
  • Who manages refunds, failed transactions and customer complaints?
  • How are transaction records reconciled with sales invoices?
  • How are VAT, accounting and financial reporting records maintained?
  • What happens if the token temporarily loses its reference value?
  • Which party is responsible for AML and sanctions screening?

Example 2:

An Abu Dhabi retailer plans to accept stablecoins through an overseas payment application. The application immediately converts each customer payment and sends UAE dirhams to the retailer’s bank account. Before launch, the retailer reviews whether the provider is authorised to offer conversion and merchant-payment services to UAE customers and whether transaction records support its Accounting and Tax obligations.

How do the CBUAE, VARA, ADGM and DIFC regimes differ?

The correct regulator depends on the service, token, legal entity and location from which the activity is conducted. Businesses should not treat the UAE as having one interchangeable digital asset licence.

The CBUAE regulates payment-token services and the wider federal payment infrastructure. VARA regulates virtual asset activities conducted in or from Dubai, including Dubai mainland and most free zones, but excluding the DIFC. Firms conducting regulated virtual asset activities in those areas must obtain the appropriate VARA licence before commencing operations.

Within Abu Dhabi Global Market, the Financial Services Regulatory Authority administers the digital asset framework for activities conducted in or from ADGM. Its framework includes authorisation, financial crime, prudential and accepted-asset requirements. ADGM implemented further amendments to its digital asset regime in June 2025.

Within the Dubai International Financial Centre, crypto-token-related financial services are regulated by the Dubai Financial Services Authority. Updated DFSA Crypto Token rules became effective on 12 January 2026, including firm-led suitability assessments for tokens used in regulated financial services.

A company may need to consider more than one regulatory framework when its group entities, technology, customers or transaction flows operate across different UAE jurisdictions.

What common mistakes do payment businesses make?

The most expensive errors often occur before a formal application begins. Founders may select a licence, incorporate an entity or build a product before confirming how the regulator will classify the activity.

Common mistakes include:

  • Treating every fiat-backed stablecoin as automatically permitted
  • Assuming a virtual asset licence covers payment-token services
  • Describing custody as software despite controlling customer keys
  • Launching promotions before obtaining the required authorisation
  • Using overseas providers without checking UAE-facing obligations
  • Overlooking merchant acquiring or settlement functions
  • Relying on generic AML and cybersecurity policies
  • Failing to document reserve, redemption and reconciliation processes
  • Mixing customer assets with operating funds
  • Preparing financial projections that do not match the transaction model
  • Ignoring Accounting, VAT and recordkeeping requirements
  • Assuming a mainland or free zone commercial licence is sufficient
  • Waiting until a banking review to explain the regulatory structure

The one-year transition period provided under the framework has passed. Businesses operating in 2026 should not rely on transitional treatment as an alternative to resolving licensing or registration requirements.

What documents should businesses prepare?

A structured preparation file helps management, advisers and regulators understand the business without reconstructing the model through repeated questions.

Businesses should consider preparing:

  • Group and legal entity structure
  • Trade licence and constitutional documents
  • Ultimate beneficial ownership information
  • Regulatory business plan
  • Detailed product and service description
  • Customer journey and transaction-flow diagrams
  • Token issuance or distribution model
  • White paper, where applicable
  • Reserve asset and redemption framework
  • Three-year Financial projections
  • Capital and funding evidence
  • AML, KYC and sanctions policies
  • Enterprise risk assessment
  • Compliance monitoring programme
  • Technology architecture and cybersecurity assessment
  • Wallet and private-key governance procedures
  • Customer asset segregation controls
  • Outsourcing and vendor register
  • Data protection and retention policies
  • Business continuity and incident-response plans
  • Customer terms, disclosures and complaint procedures
  • Accounting policies and reconciliation procedures
  • Management responsibility matrix
  • Internal audit and independent assurance plan
  • Wind-down and customer-exit arrangements

The exact documents depend on the regulated activity, licence route and operating structure. Businesses should ensure that documents agree with one another. A business plan, technology diagram, AML risk assessment and Financial model should describe the same transaction process.

How can KPM Global Services UAE assist?

KPM Global Services UAE can support founders, payment businesses and established financial institutions with the commercial, Financial, Accounting and compliance preparation needed for a regulatory assessment or licence-readiness project.

Support may include:

  • Reviewing the proposed business and transaction model
  • Identifying activities that require specialist legal classification
  • Preparing regulatory business plans and Financial projections
  • Developing Accounting and reconciliation procedures
  • Documenting AML, governance and internal control frameworks
  • Assessing operational and banking readiness
  • Organising licensing and due diligence documents
  • Coordinating inputs from legal, technology and compliance advisers
  • Reviewing whether policies reflect the company’s actual operating model
  • Supporting management responses to information requests

The appropriate approach depends on the activity, target customers, jurisdiction and regulatory pathway. No adviser can guarantee a licence, registration, banking relationship or authority decision.

This article is for informational purposes and does not constitute legal, tax, accounting, or financial advice.

Final advisory perspective

The UAE stablecoin framework creates a route for regulated payment innovation, but it also draws a clear boundary between an experimental digital asset product and a supervised payment service.

Payment businesses should start with a regulatory-perimeter assessment rather than a licence form. Management must understand which entity issues, converts, safeguards, transfers, promotes and settles the token at every stage of the transaction.

That assessment should then guide incorporation, licensing, technology design, banking arrangements, AML controls, Accounting systems and customer documentation. Addressing these matters before launch is generally more efficient than restructuring a live product after a regulator, bank or commercial partner raises concerns.

Questions and answers

Q: Are stablecoins legal in the UAE?

A: Certain stablecoins may be issued or used within an applicable UAE regulatory framework. The token and the related service must meet regulatory requirements, while algorithmic stablecoins and privacy tokens are prohibited under the CBUAE payment-token regime.

Q: Does every stablecoin business need a CBUAE licence?

A: Not necessarily. The required licence or registration depends on whether the business issues, converts, safeguards or transfers payment tokens and whether another regulated status or financial free zone framework applies.

Q: Can an overseas stablecoin company serve UAE customers?

A: An overseas company may still fall within UAE requirements when it offers regulated services to UAE persons. It should assess registration, licensing, promotion and local establishment obligations before entering the market.

Q: Can a UAE merchant accept US dollar-backed stablecoins?

A: Potentially, but the merchant should confirm that the token and payment provider are permitted for the proposed arrangement. It should also review settlement, refunds, AML responsibilities, Accounting records and customer disclosures.

Q: Is a VARA licence sufficient for stablecoin payment services?

A: Not automatically. VARA and the CBUAE regulate different activities, and the correct authorisation depends on the token, payment function, legal entity and jurisdiction involved.