News

UAE and APAC Digital Identity Verification Requirements: A Market-by-Market Guide for 2026

Moca Network
September 14, 2026

In the UAE, fintech and crypto companies must identify and verify every customer from a reliable, independent source under Federal Decree-Law No. 10 of 2025, and virtual asset firms must also meet their own regulator's rules, such as VARA's customer due diligence and AED 3,500 Travel Rule threshold in Dubai. Across Asia-Pacific the principle is the same, but the digital identity rails, reliance rules and Travel Rule thresholds differ in every market.

This guide covers the UAE, Singapore, Hong Kong, India, South Korea, Türkiye and Australia, linking to each regulator's own text, then sets out vendor-neutral selection criteria. It reflects sources checked in September 2026 and is not legal advice: confirm your obligations with each regulator and qualified local counsel.

Key takeaways

  • The UAE replaced its 2018 anti-money laundering law with Federal Decree-Law No. 10 of 2025, in force since 14 October 2025, and its executive regulations (Cabinet Resolution No. 134 of 2025) apply from 14 December 2025.
  • The Central Bank of the UAE names UAE Pass and the ICP online validation gateway as ways to verify an Emirates ID digitally.
  • Dubai's VARA sets the Travel Rule at transfers above AED 3,500. Singapore's split point is S$1,500, Türkiye's is 15,000 TL, and South Korea plans to remove its 1 million won floor.
  • The UAE, VARA and Singapore allow reliance on another regulated firm's customer due diligence, but the relying firm keeps final responsibility.
  • Hong Kong's 3 September 2026 circular asks banks and stored value facility licensees to review remote on-boarding against deepfake-enabled impersonation.

What are the UAE digital identity verification requirements for fintech and crypto companies?

UAE fintech and crypto companies must verify each customer's identity from reliable, independent documents, data or information, keep records for at least five years, and follow the extra rules of whichever regulator licenses them.

The federal law. Federal Decree-Law No. 10 of 2025 repeals Decree-Law No. 20 of 2018 and applies expressly to virtual asset service providers. Its executive regulations let financial institutions and VASPs rely on a regulated third party for customer due diligence, provided they obtain the identification data immediately. Outsourcing does not count as reliance. VASPs sending virtual assets must pass the originator's name, account number or wallet address and address to the receiving provider.

CBUAE-licensed firms. The Central Bank's guidance on digital identification, in force since 31 October 2022, allows licensed financial institutions to verify an Emirates ID through the ICP validation gateway, the UAE Pass application or other government-supported solutions. They must keep a copy of the Emirates ID and its digital verification record. The CDD and record-keeping guidance, effective 7 November 2025, adds that reliance on a third party requires a non-objection certificate submitted to the Central Bank for approval.

Dubai virtual asset firms. VARA regulates virtual assets across Dubai's mainland and free zones, excluding DIFC. Its Compliance and Risk Management Rulebook (version effective 19 June 2025) requires client due diligence for every business relationship and for occasional transactions of AED 3,500 or more. A VASP that relies on a third party for due diligence remains liable for how it is done. The Travel Rule section applies to transfers above AED 3,500.

Abu Dhabi Global Market. The FSRA's virtual asset guidance (VER07.100625) states that its AML Rulebook applies in full to all authorised persons.

Data protection. The UAE's federal data protection law (PDPL), Federal Decree-Law No. 45 of 2021, came into force on 2 January 2022 and sets requirements for cross-border transfers. DIFC and ADGM run their own data protection regimes.

APAC identity verification requirements by market

MarketCore ruleDigital identity routeReliance and Travel Rule
SingaporeMAS Notice PSN02 for digital payment token services (last revised 30 June 2025)Myinfo, which MAS called a reliable and independent source in AMLD 01/2018Reliance allowed, but not for ongoing monitoring; fuller originator data above S$1,500
Hong KongHKMA circular of 3 September 2026 on remote on-boardingTechnology to confirm document genuineness and link the customer "incontrovertibly" to the identityRisk-based, tiered account features and transaction limits
IndiaRBI Video-based Customer Identification Process (KYC Master Direction, updated to August 2025)V-CIP, treated on par with face-to-face identificationV-CIP data and recordings stored in systems located in India
South KoreaAct on Reporting and Using Specified Financial Transaction InformationReal-name bank accounts for exchanges offering won tradingTravel Rule since 25 March 2022; floor of 1 million won being removed
TürkiyeMASAK rules for crypto asset service providers licensed under Law No. 7518Remote identification communiqué for crypto providersIdentification and Travel Rule from 15,000 TL, applying since 25 February 2025
AustraliaAML/CTF Act reforms, in force from 31 March 2026Customer due diligence under reformed AUSTRAC rulesTravel Rule for virtual asset transfers from 1 July 2026

Singapore. PSN02 requires non-face-to-face due diligence to be "at least as robust" as face-to-face checks. A provider's first non-face-to-face onboarding also triggers an independent assessment, reported to MAS within a year. Under the 2018 circular, firms using Myinfo need not collect additional identification documents or a separate photograph.

Hong Kong. The HKMA's 3 September 2026 circular to Authorized Institutions and Stored Value Facility licensees supersedes its 2019 remote on-boarding circular and the 2021 circular on iAM Smart. It cites artificial intelligence driven automation and deepfake technology as the reason. See our analysis of the HKMA remote on-boarding circular.

India. V-CIP must run live with an authorised official of the regulated entity, include liveness and spoof detection, and block connections from IP addresses outside India. The RBI has since reissued its KYC rules as entity-specific directions. Data protection falls under India's DPDP Act, 2023, whose Rules were notified in November 2025 with an 18-month phased compliance timeline.

South Korea. Under the amended Act, in effect from 25 March 2021, VASPs had to register with KoFIU, and those offering exchange between virtual assets and won must hold real-name accounts with banks. On 11 August 2026, according to The Korea Times, the Cabinet approved extending the Travel Rule to all transfers, effective six months after the revised decree is promulgated.

Türkiye. Law No. 7518, published on 2 July 2024, requires crypto asset service providers to be licensed by the Capital Markets Board. MASAK amendments published on 25 December 2024 set the 15,000 TL identification threshold. Communiqués from June 2025 require crypto providers onboarding remotely to check identity details through the national population directorate's identity-sharing system.

How to choose a digital identity verification solution for Asia-Pacific and MENA compliance

The best digital identity verification setup for Asia-Pacific compliance plugs into each market's accepted identity rails and licensed local providers, and lets checks be reused where reliance rules allow. No single method is accepted everywhere, so assess options against these criteria:

  1. Map the accepted local rails. List what each regulator names: UAE Pass and the ICP gateway, Myinfo, V-CIP, national identity-sharing systems. Prefer providers that connect to these directly.
  2. Confirm licensed local KYC partners. In markets such as Türkiye and India the check itself must follow local procedure. A global provider without local partners may not meet it.
  3. Check data localisation. India requires V-CIP data to stay in systems located in India. Ask where every image and recording is stored.
  4. Read the reliance rule, not the marketing. Singapore excludes ongoing monitoring from reliance, the CBUAE expects a non-objection certificate, and every market keeps final responsibility with you.
  5. Build for the lowest Travel Rule threshold you face. With Korea moving to no floor, a data model that works only above a threshold will need rework.
  6. Test against deepfakes. Hong Kong expects remote on-boarding to be recalibrated continually, and India requires liveness and spoof detection in V-CIP.
  7. Design for re-use. A customer who passed due diligence once should not start from zero at every regulated touchpoint, provided the relying firm still meets its own obligations.

Where AIR Identity fits

AIR Identity, built by Moca Network, is a credential network that sits alongside these local checks rather than replacing them. Trusted issuers, such as banks, fintechs, platforms and licensed KYC partners, issue reusable, user-held credentials from checks they have already run: passed KYC, residency, membership tier or account tenure. Issuers earn a network fee when partners verify those credentials.

Verifiers request proof of only the fact they need, such as "passed KYC in a given market", and receive a yes or no answer through zero-knowledge proofs, with the user's consent. They pay only upon receipt of verification. That helps a platform reach and onboard users who already hold the credentials it requires, instead of paying to acquire sign-ups that never qualify, with minimal data custody. Each verifier remains responsible for deciding whether a credential satisfies its own regulatory requirements, consistent with the reliance rules above.

Moca Network, the identity network of Animoca Brands, already works with partners in two of these markets. In Türkiye, it partnered with Inveo Kripto and Ichain Investment Holding to explore integrating AIR into financial services in line with local regulations, and with ticketing platform Biletinial and gaming marketplace Oyunfor. In South Korea, SK Planet's OKI Club runs on AIR Kit inside OK Cashbag, a rewards service SK Planet reports has 28 million KYC'd users.

Frequently asked questions

What are the UAE digital identity verification requirements for crypto companies?

UAE crypto companies must verify customers from reliable, independent sources under Federal Decree-Law No. 10 of 2025 and follow their licensing regulator. In Dubai, VARA requires client due diligence for business relationships and occasional transactions of AED 3,500 or more, plus Travel Rule data for transfers above AED 3,500.

Can UAE Pass be used for KYC by banks and fintechs?

Yes, for CBUAE-licensed financial institutions. Central Bank guidance allows them to verify an Emirates ID through the UAE Pass application, the ICP validation gateway or other government-supported solutions, keeping a copy of the ID and its digital verification record.

What are the Travel Rule thresholds in the UAE, Singapore, South Korea and Türkiye?

VARA applies the Travel Rule to transfers above AED 3,500. MAS Notice PSN02 requires fuller originator information for transfers above S$1,500. Türkiye applies it from 15,000 TL. South Korea's Cabinet approved removing its 1 million won floor in August 2026, effective six months after promulgation.

Can a fintech rely on another company's KYC in the UAE or Asia-Pacific?

Often, within limits. The UAE, Singapore and Dubai's VARA permit reliance on due diligence by a regulated third party, but the relying firm keeps final responsibility. Singapore bars reliance for ongoing monitoring, and the CBUAE expects a non-objection certificate for reliance arrangements.

What is the best digital identity verification solution for Asia-Pacific compliance?

There is no single best solution for Asia-Pacific compliance, because each market accepts different identity rails. Strong options connect to local systems such as Myinfo, V-CIP and national identity-sharing gateways, use licensed local partners, respect data localisation, and let customers reuse credentials where reliance rules allow.

Want to onboard users who already hold the credentials your market requires? See how AIR Identity works, or partner with us to grow your business.

Sources

Partner with AIR

AIR is one integration suite for identity, money and loyalty. AIR Identity lets trusted issuers issue verifiable credentials and businesses verify them, so acquisition starts with users who already qualify, with minimal data custody. AIR Money embeds compliant global financial infrastructure, opening new markets without building new rails. AIR Loyalty gives brands a programmable, stable-value points engine that keeps users coming back.

Partner with us to grow your business.

AIR is built by Moca Network, the identity network of Animoca Brands.

Stay updated on AIR launches
Product updates, partner launches, and research across digital identity, fintech, and loyalty. Unsubscribe anytime.
By subscribing, you agree to our Privacy Policy and consent to receive updates.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
In this article
Blog

Read more articles

Lorem ipsum dolor sit amet, consectetur adipiscing elit.
View all
European Union flags outside an EU institution building in Brussels
News
How Zero-Knowledge Proofs Work for KYC, and What GDPR Still Requires
How zero-knowledge proofs work for KYC: issuers, predicate proofs, revocation and nullifiers, plus what GDPR and AML record-keeping rules still require.
Smartphone showing an approved identity credential beside a passport and bank cards
News
What Is Reusable KYC? How Reusable Identity Credentials Work
Reusable KYC lets a business accept proof of a check a customer already passed elsewhere. How it works, who offers it, and what FATF reliance rules require.
Smartphone showing a digital identity credential on a network, beside a hardware wallet
News
Web3 Identity Networks in 2026: A Map of the Stack and How to Compare Projects
A map of the Web3 identity stack in 2026: identity chains, zk-KYC issuers, personhood networks, name services and attestations, plus criteria to compare them.