Supervisors want evidence, not policies
A VASP licence is the start. Inspections now test whether custody, Travel Rule and risk-assessment controls work in practice, and whether you can prove it on the day.
Licence day is not inspection day
Getting licensed as a VASP, payment token issuer or custodian in the UAE is a real achievement. It is also the moment some firms stop treating technology controls as a living system. Supervisors do not. Inspections now ask whether custody, Travel Rule and business risk assessment controls work on the day you are asked—not whether a policy PDF exists in SharePoint.
I work the technology and operating-model side alongside counsel and the MLRO. I do not give legal advice, and I do not recommend buying or selling virtual assets. I do help firms show that the control design matches how the platform actually runs.
What walkthroughs actually probe
Custody designs get tested for hot, warm and cold separation, key ceremony evidence, and what happens when an incident forces a change. Travel Rule integrations get tested for failed sends, incomplete counterparty data and how operations escalate. Risk assessment methods get tested for traceability: can you show how a high-risk flow was scored, approved and monitored?
Firms that fail these moments usually fail on evidence continuity. The architecture diagram and the production configuration disagree. The vendor console and the board pack disagree. The change ticket and the control narrative disagree.
Build evidence into the design
The cheapest time to fix this is before the inspection letter. Map controls to artefacts you can produce under pressure: logs, approvals, reconciliation outputs, vendor attestations and a red-amber-green evidence map with named owners. Then remediate the reds with a plan the technology risk committee will own.
If you are still writing policies without wiring them to systems, you are preparing for a licence interview, not an inspection.