Regulation & Policy
Share
Dubai's VARA has issued a circular tightening independent audit requirements for VASPs' client reserves, specifying that auditors must verify wallet custody, asset segregation, daily reconciliation, and any rehypothecation or lending of client assets across the full review period.
Dubai’s Virtual Assets Regulatory Authority (VARA) has clarified the minimum requirements for independent audits of client reserves held by virtual asset service providers (VASPs), tightening the scrutiny applied to how firms safeguard customer assets.
The regulator issued its Reserve Assets Audit Report circular on October 6 following a thematic review of all Proof of Reserve Assets reports submitted by VASPs in 2025. VARA said the guidance is intended to establish a more consistent and detailed approach to independently verifying the existence, custody, reconciliation and protection of client virtual assets.
The circular does not introduce a new reserve ratio. Instead, it clarifies what independent auditors are expected to examine when assessing compliance with requirements that were already part of VARA’s regulatory framework.
Under VARA’s existing rules, VASPs must maintain reserve assets equal to 100% of liabilities owed to clients, with reserves held on a one-to-one basis in the same virtual asset as the corresponding client liability. The assets must also be reconciled daily and independently audited.
The new circular specifies what auditors must verify when carrying out those reviews.
Auditors must confirm that reserve assets remained at or above 100% of aggregate client liabilities throughout the review period and that the reserves were held in the same type of virtual asset as the corresponding liability, without substitution by another digital asset or equivalent value.
The audit must also cover all wallets used to hold client assets, including hot, warm and cold wallets, assets held through wallet infrastructure providers and assets held with third-party custodians.
VARA is also requiring auditors to examine how client assets are separated from a VASP’s own assets.
The circular requires auditors to assess whether client virtual assets were segregated from proprietary and operational assets and identify any instances of commingling.
Auditors must also confirm whether the VASP maintained control over all wallets holding client assets during the review period and document the custody arrangements for those wallets. This includes assets held with licensed third-party custodians as well as self-custody solutions and wallets operated through third-party wallet technology providers.
The requirements build on VARA’s existing client-asset safeguarding rules, which require client virtual assets to be held separately from a VASP’s own assets and prohibit rehypothecation unless applicable client consent and VARA licensing requirements are satisfied.
The scope also extends to how client assets were used during the review period.
Auditors must confirm that reserve assets were subject to daily reconciliation against client liabilities and review evidence demonstrating that the reconciliation process was effective.
They must also determine whether any client virtual assets were rehypothecated, lent, pledged or otherwise used during the review period. If such activity occurred, the audit report must provide details of the arrangements and the assets involved.
This moves the audit beyond simply checking whether a VASP holds sufficient assets at a particular point in time. Auditors are expected to examine the firm's reserve position and custody arrangements across the review period and identify how client assets were handled.
The regulator is also setting expectations for the quality of the audit reports themselves.
Auditors must document the procedures performed, evidence obtained, sampling methodology, reliance on third parties and any limitations on the scope of the engagement. Reports must distinguish between compliant outcomes, identified exceptions, scope limitations and matters that could not be independently verified.
VARA also states that management representations alone should not be treated as sufficient audit evidence where independent evidence is reasonably available.
The regulator further emphasizes that appointing an external auditor does not reduce the VASP’s responsibility for ongoing compliance or the safeguarding of client assets.
The circular therefore strengthens the assurance process around Proof of Reserves rather than changing the underlying reserve requirement. For Dubai-licensed VASPs, the focus is increasingly on demonstrating not only that client assets are fully backed, but also that their custody, segregation, reconciliation and use can be independently verified.
Disclaimer of Warranty
The information provided in this article is for general informational purposes only. We make no warranties about the completeness, reliability, and accuracy of this information. Read full disclaimer
Editor's Picks

When Assets Move—or Stop—Without Consent: The Limits of Crypto Wallet Control
Walid Abou Zaki
Sep 29, 2026
6 min

Where Do the Dollars Behind the UAE’s Crypto Economy Sit?
Anna K.
Sep 21, 2026
9 min

As U.S. Crypto Legislation Stalls, Circle Launches Its Own Financial Network
Walid Abou Zaki
Sep 16, 2026
9 min
Read More Articles
In the Same Space

UAE FIU and VARA Join Forces to Crack Down on Virtual Asset Crime
News Desk
Oct 5, 2026
3 min

Coinbase Completes Deribit Integration, Expanding Global Crypto Derivatives Access
News Desk
Oct 7, 2026
3 min

Rakbank Islamic Explains Shari’ah Framework Behind Bitcoin Service
Salma Naueihed
Sep 30, 2026
4 min

The Gulf to Tokenize $500 Billion in Assets by 2030. Who Gets Them On-Chain?
Anna K.
Sep 30, 2026
6 min



