The CMA Has Returned Your Licensing Package – What Now?
Sometimes, during the process of obtaining a Virtual Asset License, situations arise where, at first glance, all the documents are prepared and you have already received an In-Principle Approval (IPA) but the Capital Market Authority (CMA) unexpectedly returns your documents, recommending you to obtain an remediation review. Comments at the final licensing stage are a normal part of the process, and they are especially common now that packages prepared under the old SCA rules are assessed against a new framework. An IPA is an intermediate status, not an authorisation: the regulator is prepared to license the applicant once specified conditions are met, and the time to meet them is limited.The return rarely means the business is not viable. More often, the package no longer reads as one coherent whole: a custody policy describes one model, the financial forecast assumes another, and the key-person files do not show who is responsible for either. The answer is not more documents but coherence – and, because the IPA clock keeps running, a controlled plan rather than a rushed resubmission.
What Has Changed: The 2026 Reforms.
In April 2026 the CMA issued Decision No. 04/R.M/2026, which replaces rather than amends the former SCA virtual-asset rules. It introduces eight separately licensed activities in place of a single “platform” licence – among them dealing as principal or agent, custody and operating a multilateral trading facility (MTF); capital of AED 500,000 to AED 4 million plus liquid assets covering six months of expenses; key persons who must be UAE-resident and CMA-accredited; separate approval before holding client assets; a ban on privacy and algorithmic tokens; and a list of approved virtual assets. A new AML law, Federal Decree-Law No. 10 of 2025, has applied since October 2025. A package drafted before April 2026 therefore almost certainly needs updating, even if it was accepted at the IPA stage.
Why the CMA Returns Licensing Packages: The Most Common Gaps.
Returned packages usually fail in the seams between documents. Borrowed templates are the first warning sign: policies copied from VARA, ADGM or foreign regimes that still cite another regulator’s rules or repealed SCA provisions. Inconsistent documents come next – different MLRO names, token lists or activity descriptions across the application forms, business plan and policies, including the separate VASP and VA MTF forms.
Combined activities without safeguards are a frequent problem for multi-licence applicants. Custody raises wallet governance, segregation, key management and reconciliation; dealing as agent raises conflicts of interest and best execution; an MTF must match orders on a non-discretionary basis. One generic policy cannot cover all three. Key persons and Accredited Individuals must have experience, residency, accreditation and reporting lines that match the business, and KYC on shareholders and ultimate beneficial owners must be complete and properly governed, even where it relies on digital tools.
Generic AML/CFT frameworks – with no entity-specific risk assessment, no Travel Rule procedure and transaction monitoring described only in general terms – are another classic gap. Finally, financials that do not add up: projections that do not support the new capital and liquidity requirements. These gaps appear because the rules changed mid-process, documents were drafted by different people at different times, and earlier comments were answered piecemeal. The regulator reads the package as one system, not as several dozen separate files.
How a Remediation Review Works – and What to Ask Your Consultant.
A credible review starts with the regulator’s letter, not with a template. Each comment becomes a line in an evidence matrix: the issue, its legal basis, the owner, the amendment, the supporting evidence and the test for closing it. The work then follows five steps: an inventory of every document against the activities applied for; a gap assessment against the current CMA framework; triage into documents to keep, amend or re-draft; re-drafting followed by a cross-document consistency check; and a structured response to each round of CMA comments. Every control needs a named owner: technology and outsourced vendors do not shift legal responsibility away from the firm.
Why AMLzone – and How We Can Support.
AMLzone is a regulatory advisory and compliance firm that works with the CMA, ADGM, VARA and EU MiCA regimes on a regular basis. Many applications stall for the same reason: the package follows a template path instead of reflecting how the applicant will actually operate under the CMA rules. With our experience across these regulators, we see these gaps at once and know how to fix them – from re-drafting policies and AML/CFT frameworks to preparing key-person files and answering the CMA's comments. And when your IPA period is running out, we work quickly and as one coordinated team, so that your package is ready for the regulator in time.
Send it to us at info@amlzone.com, and we will return a fixed-fee proposal within one to two business days.