VARA Internal Audit Readiness in the UAE: Requirements, Governance, and a Quarterly Cadence

VARA Internal Audit Readiness in the UAE

Most guidance on conducting Virtual Assets Regulatory Authority (VARA) audits focuses on one particular aspect of the work: the “audit”. In reality, this is a two-part process specified in Part I, Section G of the Compliance and Risk Management Rulebook.

The first is an external audit of financial statements by an independent third party, while the second one deals with a different internal audit function that assesses the firm’s own operations and control systems.

Thus, a virtual asset service provider (VASP) might meet any one of these requirements but still be at risk of failing the other. This article will focus exclusively on the second type of audit, namely, what the VARA requires of a VASP’s internal audit function, and how to prepare for it.

The Rulebook Requirements

Rule G.2 of Part I of the Compliance and Risk Management Rulebook requires a VASP to implement internal audit as a function that is objective and independent from the operational function it audits and reports regularly and directly to senior management. The rule also requires a written policy on the roles, responsibilities, and working relationship between the internal and external auditors to avoid duplication or lack of coverage between the two functions.

Three operational requirements emanate from the rule’s text:

  1. The internal audit function must conduct an audit at least once a quarter.
  2. It must report its findings and recommendations to senior management and the governing body after every cycle of testing and monitoring.
  3. It must follow up on each issue or risk flagged during audit testing and monitoring until it is closed, with verifiable evidence of closure.

The last requirement is where many firms commonly lose marks. A single audit finding that is reported and repeated verbatim in two successive quarters of audit results is a telling sign that the internal audit function hasn’t met the expectation of the rule, regardless of how comprehensive, rigorous, and systematic the audit testing and monitoring process may be.

Governance Above the Audit Function

VARA does not leave an internal audit function isolated on its own. As stated in the Company Rulebook, the board holds all responsibility for VASP’s compliance with all applicable regulatory requirements and for the establishment of a professional compliance culture throughout the organisation. The board is also responsible for defining reporting lines and authorisation processes among senior management, and for the annual evaluation of the VASP’s performance, including senior management.

When read together with Rule G.2, this establishes a governance “chain” that is demonstrable by VARA: the board sets the accountability structure and reporting lines, senior management receives the internal audit’s findings directly on a regular, quarterly basis, and the internal audit function is kept structurally separate from the operations being tested. If a VASP cannot demonstrate each link in this chain, its independence has not been demonstrated.

Independence has a practical test as well. If the person conducting internal audit reports to the same manager whose function they are reviewing, or if the audit’s findings are filtered by the compliance officer before being presented to senior management, this will not withstand scrutiny. The independence requires a direct line to senior management and a mandate that is not subject to the function being audited.

Scoping Internal Audit Against the VASP’s Actual Licence

A VASP’s licence category should guide what internal audit focuses on. For example, a custody licence has different control priorities than a broker-dealer or exchange licence, and an audit plan that treats every VASP the same way misses the point of a risk-based approach. Likewise, wallet key management and proof of reserves weigh more for a custodian, whereas transaction monitoring and order-handling controls weigh more for an exchange.

The internal audit plan should specify the particular activities the VASP is licensed for and the testing priorities to the risks they carry. A generic checklist borrowed from another type of firm will miss the point entirely and serve no purpose.

5 Control Areas Internal Audits Need to Test

For an annual internal audit plan to deliver meaningful findings and not just going through the motions, it should cover these control domains, subject to activity and a risk based approach, with a defined testing method for each:

1. Record-keeping and regulatory reporting controls

Under Part I of the Compliance and Risk Management Rulebook, several sections address books and records, regulatory reporting and notifications, and VASPs must maintain the records required by the rulebook and then submit the reports and notifications to the VARA within the specified timeframe. The internal audit should sample a set of the submitted reports and ensure that each filing is consistent with the transaction or event that prompted it and that the filing was made in a timely manner.

2. AML and financial crime testing

This includes sampling a subset of transactions against the VASPs own risk based thresholds under Part III of the Compliance and Risk Management Rulebook and confirming alerts were actually reviewed and closed out, with documented evidence of said review. Internal audit should also confirm the AML risk assessment itself has been refreshed within the period the rule book requires as a stale risk assessment undermines every control sitting on top of it.

3. Wallet and key management

Internal audit needs to confirm that key recovery procedures have been tested at least once. This is because a documented but unused recovery scheme represents a significant control vulnerability that may reveal itself in the case of an actual key loss.

4. Outsourcing and third-party management

The Company Rulebook’s outsourcing provisions require VASPs to keep risk assessment, due diligence records, and an outsourcing register for each outsourcing arrangement. The internal audit function should review the latter to ensure that it is up to date and that the audit rights over the service provider are being exercised and not a mere contractual formality.

5. Risk management and business continuity

Under the Technology and Information Rulebook’s provisions regarding business continuity, cybersecurity events, and risk VASP’s must maintain and test their plans for operational disruption. Internal audit should verify that these plans have actually been rehearsed within the period set out by the VASP’s own policy, as an unrehearsed plan presents a real risk in the event of a system outage or a site failure. This should include a review of the outcome of the most recent test and confirmation that any weaknesses identified have been addressed and a sample check of the VASP’s risk register to verify that identified risks have an owner, a likelihood and impact assessment, and a mitigation plan which is being tracked.

How to Build a Quarterly Internal Audit Cadence

A generic audit calendar revolves around one main event: one review, one report, filed once a year and repeated the year after. Rule G.2 does not allow internal audit to run on that annual cycle. Internal audits have to be conducted at least once a quarter, with results reported directly to senior management after each cycle, and internal audit itself has to follow up on every finding until it is resolved. This workflow needs to run on a quarterly basis.

  • Refresh the risk assessment against the VASP’s current licence scope and any business changes from the prior year, and use it to set the testing schedule for the year ahead.
  • Confirm the audit charter is current and reflects the VASP’s actual activities and structure
  • Confirm the written policy on the internal-external auditor relationship, required under Rule G.2, is in place and up to date.
  • Carry out testing on the highest-risk control areas identified in the risk assessment, spreading coverage across the year so every area named in the plan gets tested at least once.
  • Report findings and recommendations to the board and senior management after each testing cycle, without holding them back for a single year-end summary.
  • Assign an owner and a target date to every finding raised, then follow up with evidence that remediation actually happened, such as a revised control, an updated policy, or a completed system change.
  • Escalate to the board any finding still open past its target date without a credible remediation plan.
  • Prepare a consolidated annual report for the board once testing across all control areas is complete, confirming every finding from the year has either been closed or carries an active remediation plan with a named owner and a date.
  • Feed any outstanding items and emerging risks into the following year’s risk assessment, so each year’s cycle builds directly on the findings and remediation work carried over from the year before it.

How Can Paragon Consulting Partners Help

Internal audit readiness under VARA is a working cycle with its fair amount of tasks and deliverables: quarterly testing, direct reporting to the board and senior management, and follow up to close findings that should, by no means, reappear quarter after quarter.

Paragon Consulting Partners helps VASPs design and execute this important process, from scoping out an appropriate audit plan according to the company’s specific licence category, to evaluating whether an existing internal audit function would be able to withstand the independence and reporting line tests imposed by VARA.

Request a consultation today!