VARA Proof of Reserves Requirements: A Guide for Dubai VASPs

For Dubai VASPs, proof of reserves is more than a periodic audit. It is a continuous regulatory obligation spanning 100% same-asset backing, daily reconciliations, independent audits, and license-specific requirements. In this article, we dive into the key requirements for Dubai VASPs.

Key Takeaways

  • The Government of Dubai’s Virtual Assets Regulatory Authority (VARA) requires reserve assets held on behalf of customers to be equal to or greater than 100% of client liabilities, held one-to-one in the same virtual asset, not merely at equivalent value.

  • Reserves must be reconciled daily and audited by an independent third-party auditor at least every six months, with the report filed in your next quarterly report to VARA.

  • These are two separate reconciliation requirements; reserve assets under the Company Rulebook, and client virtual asset positions under the Compliance and Risk Management Rulebook.

  • The rule actually headed “Proof of reserves” contains no specific rule-making detail. It delegates to requirements VARA sets at licensing, so your specific “Proof of Reserves” obligation is in your license conditions, not the public rulebooks.

  • VARA does not name an engagement standard or define the criteria for the semi-annual audit. Both are set by you and your practitioner.

First, check you are reading the right article. VARA regulates Dubai mainland and the Dubai free zones with one exception: firms in the Dubai International Financial Centre are regulated by the DFSA instead, and nothing below applies to them. Onshore UAE outside Dubai falls to the federal Capital Market Authority (formerly the Securities and Commodities Authority).

A note on terminology before we start. VARA’s rules require reserve assets to be “audited by an independent third-party auditor”, and we use VARA’s wording throughout when describing what the rules say. Under professional standards, what a CPA or CA firm typically performs over reserves is an attestation engagement, not an audit. The distinction matters when you go to scope the work. Ask the market for an audit and you may be quoted for a financial statement audit, which is a different engagement with a different cost and a different purpose, and the report you eventually receive will not be titled one.

What VARA Requires on Reserve Reporting

The core obligation is Part VI, Section E of VARA’s Company Rulebook, one of the four rulebooks that bind every VASP regardless of activity. It reads in full:

  1. VASPs shall, at all times, maintain reserve assets equivalent to one hundred percent (100%) of the liabilities owed to clients with respect to all VA Activities (“Reserve Assets”).

  2. VASPs must hold Reserve Assets on a one-to-one basis in the same Virtual Asset that liabilities are owed to its clients.

  3. Reserve Assets must be reconciled on a daily basis and audited by an independent third-party auditor no less than every six (6) months. VASPs shall include such audit reports as part of the subsequent quarterly report to VARA required in the Compliance and Risk Management Rulebook.

Rule 2 is stricter than it looks. Reserves must be held in the same virtual asset the liability is owed in. Equivalent value is not enough. A platform that owes clients one asset and backs it with a basket of others, or with fiat, does not meet this rule however sound the economics look.

Rule 3 sets two clocks. Reserve assets are reconciled daily. They are audited by an independent third-party auditor at least every six months. Those are separate obligations with different owners: the first is your operations team, the second is an external practitioner.

The report has a fixed filing deadline. The audit report goes into your next quarterly report to VARA. That means the engagement calendar runs on VARA’s quarterly cycle rather than your financial year end, which is worth confirming before agreeing dates with your independent third-party auditor.

The Second Daily Reconciliation

Reserve assets are not the only item that must be reconciled every day. Part V, Section D of the Compliance and Risk Management Rulebook adds a second obligation:

  1. VASPs must maintain a system to ensure that accurate reconciliations of the Virtual Assets owned by each client are carried out daily. The reconciliation must include:

    a. a full list of individual client credit ledger balances, as recorded by the VASP; and

    b. a full list of individual client debit ledger balances, as recorded by the VASP.

  2. VASPs must notify VARA where there has been a material discrepancy with the reconciliation which has not been rectified.

The rule requires a reconciliation of “the Virtual Assets owned by each client”, and the two lists it names are what that reconciliation “must include”, not what it consists of. VARA sets a minimum content and leaves the rest of internal processes to the VASP.

That gives you two daily obligations, sitting in two different rulebooks:

  • Reserve assets, under the Company Rulebook. Your holdings, which must equal one hundred percent of what clients are owed.

  • Client virtual asset positions, under the Compliance and Risk Management Rulebook. Per client, with the credit and debit ledger lists above as the minimum content.

The two are easy to conflate, and firms preparing for a reserves engagement sometimes find they have been running a single process and reporting it as both.

If you also hold client fiat there is a third, and it is the most prescriptive of them. Part IV, Section E of the same rulebook requires a daily reconciliation of client accounts that must include outstanding lodgements (deposits), client account cash book balances, and formal statements from third-party banks showing balances as at the reconciliation date. You must also check that the previous day’s client account balance covered the aggregate of client credit ledger balances, and investigate shortfalls and unresolved differences, correcting them where necessary from your own funds, and notify VARA of any material discrepancy that has not been rectified.

Demonstrating Control of Digital Assets

A Proof of Reserves-like procedure has to establish two things about the assets held: first, that the assets exist, and second, that they are yours. Querying a blockchain for a given address confirms assets exist. The second comes from your key management, and VARA has rules on that. Part I, Section D of the Technology and Information Rulebook requires that:

  • there is no single point of failure in your access to, or knowledge of, the virtual assets you hold;

  • keys held online, or in any one physical location, are insufficient on their own to transact, unless other controls make physical access insufficient, and backups are stored separately from the primary key or seed phrase;

  • access to keys is strictly controlled, with an audit log of every change of access;

  • when someone with key access leaves, you assess whether a new key has to be generated; and

  • revocation is immediate, with internal audits of access removal carried out quarterly.

What VARA does not prescribe is how you demonstrate control to a practitioner. A signed message, a test transaction, evidence from a key ceremony: all are used, none is mandated.

Staking Client Assets

Staking does not take those assets outside the custody regime. Part IV of the Custody Services Rulebook makes Staking from Custody Services a separate authorisation that has to be expressly stipulated in your license, and treats it as a subset of custody. All custody rules continue to apply throughout.

In practice that means:

  • Each client’s assets stay in wallets holding that client’s assets only, with no pooling across clients and one client per node. This is a relatively strict requirement.

  • You keep control of the keys through which assets can be withdrawn or unstaked.

  • You remain responsible for safekeeping.

  • Staking runs only on a client’s specific instruction, and cannot be offered on an opt-out basis.

Lending or otherwise reusing client assets is separate again, and needs explicit prior client consent and the relevant license.

Your License Conditions are Part of the Requirements

The only rule in any VARA rulebook headed “Proof of reserves” says this:

In addition to the Reserve Assets requirements in the Company Rulebook, VASPs shall comply with all requirements stipulated by VARA from time to time, including as part of a VASP’s licensing process, in order to demonstrate that assets held in reserve cover all of their liabilities with respect to Client VASPs.

The rule delegates specific requirements to each individual license and agreement between the VASP and VARA. Whatever your firm specifically owes by way of proof of reserves was set by VARA during licensing, and it is not in the public rulebooks. Anyone scoping from the published texts alone, including a prospective practitioner, may understate your obligation. Have your license conditions to hand before the first conversation with your independent auditor.

Who can perform these Proof of Reserves engagements?

VARA’s reserves rule requires only an “independent third-party auditor”. Neither the Company Rulebook nor the Virtual Asset Issuance Rulebook defines the term, sets a nationality or location requirement, or points to a list of approved firms. A qualified, independent practitioner based outside the UAE, including a US CPA firm, appears to be able to perform the proof of reserves engagement, unless your license conditions or other rules that apply to your firm say otherwise.

That is different from the other audit engagements VARA requires. The annual financial statement audit, and the internal control attestation that accompanies it, must be performed by an auditor licensed in the UAE and, for a VASP in a free zone, one on that free zone’s approved auditor list.

What type of engagement does this fall under?

VARA sets the obligation and leaves the engagement type and methods open. Nothing in the rulebooks names an engagement accounting or audit standard, and nothing defines the criteria a reserves statement is measured against: which client liabilities are in scope, what counts as a reserve asset and where it may sit, when the measurement is taken, or how control of a wallet address is demonstrated.

Those all have to be settled and documented prior to fieldwork to ensure the scope will be sufficient, and settled in a form that would satisfy a regulator reading them, because the report is going into your quarterly filing. In our experience this is where most of the effort sits on a first engagement, well before anything is tested.

VARA can require a VASP to appoint alternative auditors where its financial statement auditors are not deemed appropriate for the size and complexity of the business, or in terms of reputation (Compliance and Risk Management Rulebook, Rule I.G.1.f). The rules do not say the same for the reserves auditor, but expect VARA to take a similar view of who you appoint.

Stablecoin and Asset-Backed Token Issuers

Stablecoin issuers are on a tighter cycle under the Virtual Asset Issuance Rulebook. A fiat-referenced token (a stablecoin) requires a monthly independent audit of whether it is 100% backed, covering tokens in circulation and the composition and value of reserve assets, with a senior management attestation submitted to VARA on completion. Asset-referenced tokens are audited every six months.

Where to Start

If you are VARA-licensed and preparing for a proof of reserves engagement, three things decide how smoothly it goes:

  • Your license conditions. They carry the proof of reserves requirement written for your firm. Nobody can scope the work properly without them.

  • Evidence that your daily reconciliations were performed. Dated and retained output across the whole period, for both of them.

  • A documented method of proving control of every address you claim.

The Network Firm performs proof of reserves attestations for exchanges, custodians and token issuers.

Talk to a TNF expert or explore our Proof of Reserves services. For a comprehensive overview of Proof of Reserves, download The Practitioner's Guide to Proof of Reserves and subscribe to The Network Firm YouTube Channel.

Author Bio:
Jericho Sarmiento is a Staff Auditor at The Network Firm, where he supports audit and attestation engagements involving digital assets and blockchain-based financial systems. He is a Certified Public Accountant (CPA) with a strong foundation in accounting and assurance.

Jericho brings over five years of professional experience, including one year focused on crypto and digital assets. He has assisted in audit and attestation engagements across industry participants such as exchanges, custodians, and stablecoin issuers. His work includes supporting stablecoin attestations, Proof of Reserves (PoR) procedures, crypto asset verification, and the preparation of detailed audit documentation and workpapers in accordance with evolving assurance standards.

In addition to his professional work, Jericho independently researches smart contract security, focusing on understanding protocol mechanics and analyzing logical behaviors and potential security risks.

Connect with Jericho on LinkedIn for more expert advice

Next
Next

Are Stablecoins Cash Equivalents? Inside FASB's 2026 Proposed ASU