TaxAdvisors

ESR, UBO & AML

AML Compliance in the UAE: Building and Running the Programme

The ten parts of a UAE AML programme, each cited to the 2025 Decree-Law and executive regulation that replaced the instruments most guidance still quotes.

aml compliance uae

AML compliance in the UAE is a continuous programme, not a one-off registration. Federal Decree-Law No. 10 of 2025 and Cabinet Decision No. 134 of 2025 require a documented business risk assessment, customer due diligence with the beneficial owner identified at 25%, sanctions screening, a compliance officer with independent decision-making, suspicious transaction reporting without delay, five-year records, staff training and an independent audit function.

Basis: UAE Financial Intelligence Unit

Governing law
Federal Decree-Law No. 10 of 2025 — No. 20 of 2018 is repealed

Article 41(1), Federal Decree-Law No. 10 of 2025, issued 30 September 2025

Governing executive regulation
Cabinet Decision No. 134 of 2025 — No. 10 of 2019 is repealed

Article 70, Cabinet Decision No. 134 of 2025, issued 29 October 2025

Beneficial owner test in a customer
25% or more of the ownership interest or shares, then control, then senior management

Article 10(1), Cabinet Decision No. 134 of 2025

Sanctions freeze
Without delay — within 24 hours — and without prior notice to the designated person

Executive Office for Control and Non-Proliferation, Sanctions Implementation guidance, read 17 August 2026; Article 21(3), Cabinet Decision No. 74 of 2020

Record retention
At least five years, counted from the most recent of the listed events

Article 25(1) and 25(2), Cabinet Decision No. 134 of 2025

Fine for no compliance officer
AED 50,000 to AED 200,000

Item 24 of the list annexed to Cabinet Resolution No. 71 of 2024, English text published by the Ministry of Economy and Tourism, read 17 August 2026

Statutory administrative fine range
AED 10,000 to AED 5,000,000 for each violation

Article 17(1)(b), Federal Decree-Law No. 10 of 2025

#What the obligation actually is: ten parts that run continuously

Most UAE material answering "what is AML compliance" defines money laundering and stops. That is not what an inspection looks at. Anti-money-laundering compliance is a programme with named components, each traceable to an article of the executive regulation, and each producing a document, a record or a decision that can be put on a table.

Two instruments govern it and both are recent. Federal Decree-Law No. 10 of 2025, issued 30 September 2025, repeals Federal Decree-Law No. 20 of 2018 outright (Article 41(1)). Cabinet Decision No. 134 of 2025, issued 29 October 2025, is its executive regulation and repeals Cabinet Decision No. 10 of 2019 (Article 70). Checked 17 August 2026: a great deal of AML material in circulation here — including policy templates sold as part of a compliance package — is still written against the 2018 and 2019 pair, which means its article numbers point at regulations that no longer exist.

The programme below is what those two instruments require. Registering on goAML is one line in it, not the whole of it.

The AML programme, component by component, under the 2025 instruments
ComponentWhere the duty sitsWhat evidence looks like
Business risk assessmentArticle 19(1)(a) of the Decree-Law; Article 5(1) of the RegulationA dated, documented assessment covering customer, country, product, service, transaction and delivery-channel risk, retained, updated and produced on request
Internal policies, controls and proceduresArticle 21 of the RegulationA policy set approved by senior management, proportionate to the nature and size of the business, reviewed and updated on an ongoing basis
Customer due diligence and ongoing monitoringArticles 6 to 9 of the RegulationIdentity evidence from a reliable and independent source, the purpose of the relationship, and transaction scrutiny against what you know of the customer
Beneficial owner identificationArticle 10 of the RegulationThe natural person at 25% or more, or the control test, or senior management — with the route you took recorded
Enhanced due diligence, PEPs and high-risk countriesArticles 5(2)(c), 16 and 23 of the RegulationSource of funds and wealth, senior-management approval, and enhanced ongoing monitoring
Sanctions screeningArticle 21 of Cabinet Decision No. 74 of 2020Registration for the Executive Office's alerts, screening records, and freeze and reporting evidence where a match appears
Compliance officerArticles 21(3) and 22 of the RegulationAppointment at management level, a fit-and-proper file, and periodic reports going directly to senior management
Suspicious transaction reportingArticle 18 of the Decree-Law and Article 18 of the RegulationIndicators, escalation records, goAML submissions, and the officer's stated reasons where the decision was not to report
Record keepingArticle 25 of the RegulationFive years minimum, organised so individual transactions can be reconstructed and traced
Training and independent auditArticles 21(5) and 21(6) of the RegulationA training plan with attendance records, and an audit function independent of the compliance function

#The risk-based approach and the business risk assessment

Everything else is calibrated from this document, which is why it is the first thing a supervisor asks for and the most common thing missing.

Article 19(1)(a) of the Decree-Law requires a supervised business to identify, understand, manage, assess, document and continuously update its crime risks, retain the assessment and provide it to the supervisory authority on request. Article 5(1) of the executive regulation adds the method: consider all relevant risk factors — customer risk, country and geographic risk, product, service, transaction and delivery-channel risk — before determining the overall level of risk and the level of mitigation to apply, take the National Risk Assessment into account, and document the process itself, not only the conclusion.

Article 5(2) then requires you to act on the result: internal policies, controls and procedures approved by senior management, proportionate to the nature and size of the business, with implementation monitored and effectiveness assessed. Article 5(4) singles out proliferation financing — where those risks are high, enhanced internal controls, documented records of the measures taken, and periodic review of the controls as the risk level changes.

The Ministry of Economy and Tourism's Guidelines for Designated Non-Financial Businesses and Professions of March 2026 add the operating detail. In most cases the business-wide assessment should be performed at least annually. Senior management must formally certify that it accurately reflects the entity's risk exposure. And where the exercise is bought in, the Guidelines are explicit that it must not be a "black box": the business has to understand the vendor's methodology, data sources and assumptions, review the output critically, and remains accountable for the adequacy of an assessment it outsourced.

Business-wide is not the same as customer-level

The Guidelines separate two assessments that are routinely merged in practice. A Customer Risk Assessment rates an individual customer at onboarding and at periodic review, and sets the due diligence and monitoring that customer gets. A Business-wide Risk Assessment rates the firm: its inherent exposure, how internal controls mitigate it, and the residual risk and control gaps that remain. A file of customer risk ratings is not a business risk assessment, and producing one when the other is asked for is a visible gap.

Simplified due diligence is conditional, not a discount

Article 5(3) permits simplified measures where low risk is identified — but only after the identification and mitigation duties in Article 5(1) and (2) are met, in coordination with the supervisory authority, and never where there is a suspicion that a crime has been committed. The permitted relaxations are named: verifying identity after the relationship begins, longer intervals between data updates, less frequent monitoring, and inferring the purpose of the relationship from its type. Even then, the Article requires full implementation of the Executive Office's targeted financial sanctions instructions. Sanctions screening is not something a low-risk rating switches off.

#CDD and KYC: what the difference is, and the 25% test

"KYC" and "AML compliance" are used interchangeably in the market and they are not the same thing. Know-your-customer is the identification and verification step. Customer due diligence, as the Regulation defines it operationally, is wider: identify and verify the customer, verify anyone acting on their behalf, understand the purpose and intended nature of the relationship, understand the customer's business and its ownership and control structure, identify the beneficial owner, and then monitor the relationship for as long as it lasts.

Article 6 sets the timing — identity is verified before or during the establishment of a business relationship, or before carrying out a transaction for someone with whom no relationship exists. Deferral is allowed only in low-risk cases, only if it is necessary so as not to disrupt normal business, only with measures to control the risk in the meantime, and it must be completed as soon as possible. Article 7 sets the trigger points: on commencement of a relationship, where there is suspicion of a crime, and where there is doubt about the accuracy or adequacy of identification data already held.

Article 9 prescribes the data. For a natural person: name as stated in the identity card or travel document, nationality, address, date and place of birth, employer name and address where applicable, and a true copy of a valid identity document. For a legal person or legal arrangement: name, legal form, memorandum of association, the tax registration number of legal persons subject to corporate tax, any unique reference number, the registered address and the local representative of a foreign person, the articles of association, and the names of the people in senior management positions. That corporate tax reference is new in the 2025 regulation and does not appear in the older templates.

Article 10 is the beneficial ownership test, and it runs as a cascade. First, the natural person who ultimately owns — individually or jointly — an actual controlling ownership interest or shares of 25% or more. Where there is doubt about that person, or where nobody controls through ownership at all, the natural person who exercises legal or actual control by any other means, directly or indirectly. Where neither identifies anyone, the relevant natural person holding a senior management position. There is no honest outcome in which a corporate customer has no identified beneficial owner; there is only a record of which limb you fell to and why.

When a value threshold applies, and when it does not

The thresholds in this regime attach to particular categories, and merging them produces a wrong answer. Article 7(2) requires financial institutions to apply due diligence on occasional transactions of AED 55,000 or more, and on wire transfers of AED 3,500 or more; Article 7(3) applies the AED 3,500 figure to virtual asset service providers. On the non-financial side the thresholds sit in the definition in Article 3: AED 11,000 for commercial gaming operators, and AED 55,000 in cash for dealers in valuable metals and precious stones. For lawyers, notaries, other independent legal professionals, independent accountants and company and trust service providers there is no value threshold at all — the listed customer activity is itself the trigger.

When you cannot complete due diligence

Article 14 prohibits establishing or continuing a business relationship, or executing a transaction, where customer due diligence cannot be applied, and requires you to consider filing a suspicious transaction report. Article 14(2) covers the awkward case: where a crime is suspected and there are reasonable grounds to believe that carrying out due diligence would alert the customer, the measures may be left undone — but a report must then be filed stating the reasons why they were not applied. Article 15 puts two absolute bars alongside these: no dealing with shell banks in any manner, and no anonymous or obviously fictitious accounts. Article 11 provides the one genuine relief — where the customer or its controlling owner is a company listed on a securities market subject to disclosure requirements that already ensure transparency about the beneficial owner, its shareholders need not be identified.

#Enhanced due diligence, politically exposed persons and high-risk countries

Enhanced due diligence is not a vague instruction to be careful. Article 5(2)(c) lists seven measures by way of example, and a supervisor will look for the ones that fit the risk: obtaining and verifying additional information on the customer's identity and occupation and on the beneficial owner, including from public databases and open sources; obtaining more on the purpose of the relationship or the reasons for the transactions; updating due diligence information more regularly; taking reasonable measures to identify the source of funds and the source of wealth; increasing the degree and level of ongoing monitoring and selecting transaction patterns for further scrutiny; requiring the first payment to come through an account in the customer's name at an institution subject to equivalent standards; and obtaining senior-management approval to start or continue the relationship.

Article 23 attaches enhanced measures to business with natural or legal persons from countries the National Committee identifies as high risk, or from countries with deficiencies in their anti-money-laundering systems, together with any countermeasures the supervisory authority requires.

Who counts as a politically exposed person

The definition in Article 1 of the Regulation covers natural persons entrusted, now or previously, with prominent public functions in the UAE or in any other country — heads of state or government, senior politicians, senior government officials including judicial and military officials, senior executives of state-owned enterprises, senior political party officials — and people entrusted with the management of, or a prominent function in, an international organisation. It expressly extends to immediate family members (spouses, children and their spouses, and parents) and to known close associates, including a person holding joint beneficial ownership of a legal person or legal arrangement with a PEP, a person with other close professional or social relationships with one, and a person holding sole beneficial ownership of a vehicle established for a PEP's benefit.

Foreign and domestic PEPs are treated differently

Article 16(1)(a) applies to foreign PEPs unconditionally: risk management systems to determine whether the customer or beneficial owner is one, senior-management approval before establishing or continuing the relationship, reasonable measures to identify the source of funds and wealth, and enhanced ongoing monitoring. Article 16(1)(b) treats domestic PEPs and people holding a prominent function in an international organisation differently: you must take adequate measures to determine whether the customer or beneficial owner falls into those categories, and apply the approval, source-of-funds and enhanced-monitoring measures where the relationship is high risk. PEP status is a trigger for scrutiny, not a prohibition, and refusing an entire category on principle is not what the Article asks for.

#Sanctions screening: the Local Terrorist List and the UN Consolidated List

This is the part of the programme most often missing from UAE advisory pages, and it is the part with the fastest clock.

Targeted financial sanctions are implemented through Cabinet Decision No. 74 of 2020, which the Executive Office for Control and Non-Proliferation administers. Two lists matter, and the Executive Office refers to them together as the Sanctions List: the UAE Local Terrorist List, issued by the Cabinet under UN Security Council Resolution 1373 (2001), and the UN Consolidated List issued by the Security Council. Article 21 of that Decision sets the obligations for financial institutions and DNFBPs, and Federal Decree-Law No. 10 of 2025 carries the definition through: targeted financial sanctions are the freezing of funds, and the prohibition on making them available, for anyone designated by Cabinet resolutions on terrorist lists or by the Security Council under Chapter VII.

Article 21(2) defines the scope of a screening run, and it is broader than a customer list: the customer database, the names of parties to any transaction, the names of potential clients, the names of beneficial owners, and the names of persons and organisations with a direct or indirect relationship — with a continuous search before any operation or serious business relationship begins.

  1. Register for the alerts

    Article 21(1) requires registration on the Executive Office's website to receive notifications of any new listing, re-listing, update or de-listing issued by the Security Council, the Sanctions Committee or the Cabinet. The Office runs this as its Notification Alert System, which sends automated emails when a list changes. Failing to register is a separate violation in the schedule to Cabinet Resolution No. 71 of 2024, at item 33.

  2. Screen, and screen again on every update

    The Executive Office's own guidance requires screening on any update to the lists, before onboarding a new customer, at periodic reviews or on a material change in a customer's nature or ownership, and before processing any counterparty transaction. On an update, it must be immediate, so that a freeze can be applied without delay.

  3. Freeze within 24 hours, without telling anyone

    Article 21(3) requires the freezing measure to be taken without delay and without prior notice to the listed person as soon as a match appears; the Executive Office states that plainly as within 24 hours. The freeze covers funds owned or controlled wholly or jointly, directly or indirectly, by a designated person, anything derived from them, and anyone acting on their behalf or at their direction. Providing funds, assets or services for their benefit is separately prohibited.

  4. Report the match through goAML

    A Confirmed Name Match Report or a Partial Name Match Report goes to the Executive Office and the supervisory authority through the goAML platform within five business days of the freezing, rejection or suspension measure. A partial match — where identifiers overlap but you cannot conclude either way — requires you to suspend or reject the transaction and report; a false positive requires no report, but the reasoning has to be documented internally.

  5. Plan for weekends and for de-listing

    The Executive Office expects internal procedures that keep screening effective across weekends and public holidays where customers can still reach their assets; where a business is genuinely closed, the obligation restarts at the first minute of business. Article 21(4) requires de-listing decisions to be implemented without delay too — a freeze that stays on after the person is removed from the list is also a failure.

#The compliance officer: competence, independence, and the decision that stays with you

Article 21(3) requires appropriate compliance management arrangements including the appointment of a compliance officer at management level. Article 22 sets the standard for the person: appointed at management level and under the entity's responsibility, with independence in decision-making and appropriate competence and experience. Five duties follow — monitoring transactions related to the crime; reviewing records and receiving, examining and assessing suspicious transaction data and deciding whether to notify the Unit or to retain the matter with the reasons stated, in full confidentiality; reviewing internal systems against the Decree-Law and the Regulation and reporting periodically and directly to senior management, copied to the supervisory authority on request; developing, implementing and documenting training; and cooperating with the supervisory authority and the Unit.

The second duty is the load-bearing one. The decision whether a report is filed belongs to the officer, and the March 2026 Guidelines state that no individual, including senior management, may interfere with or influence it. That is what "independence in decision-making" is protecting, and it is why the reporting decision cannot be contracted out to an adviser whatever else is.

On the role itself the Guidelines are more flexible than the market assumes. Where a business cannot appoint a suitably qualified and independent officer internally, a third-party compliance officer may be permitted — subject to the person having the necessary qualifications, experience and understanding of the business model, a documented fit-and-proper evaluation, independence from operational and revenue-generating roles, unrestricted access to records, systems and staff, and a written contract. Ultimate accountability does not move: it stays with the entity's senior management and board, and the officer remains accountable for validating and supervising any third-party system or consultant used in the programme.

Is there an AML compliance certification the UAE requires?

Nothing we read prescribes one. Federal Decree-Law No. 10 of 2025, Cabinet Decision No. 134 of 2025, Cabinet Resolution No. 71 of 2024 and the Ministry's March 2026 Guidelines all describe the standard in terms of competence, experience and fitness, and none of them names a course, an examination or an awarding body. What the Guidelines do set out is the fit-and-proper assessment a business should run before appointing: demonstrated understanding of UAE AML law, the executive regulation, Cabinet decisions, supervisory guidance and the FATF Recommendations; familiarity with typologies and red flags; competence in running a risk-based programme and an STR process; practical experience in compliance, audit, legal or risk work in a comparable industry; and organisational positioning senior enough to challenge behaviour without conflict of interest. Records of that assessment must be kept, and the supervisory authority notified of changes to the role.

We therefore do not endorse any particular AML qualification, and we will not tell you that one is required. If a training provider says a specific certificate is mandated by the Ministry or the Financial Intelligence Unit, ask them to point to the article. There is no accredited-course list published by either body that we could find.

#Reporting without delay, and the prohibition on tipping off

Article 17 of the Regulation comes before the reporting duty for a reason: a business must establish indicators through which it can identify suspicion of a crime, and update them on an ongoing basis as methods change, in line with its supervisor's instructions. A programme with no indicators has no mechanism for a report to arise from.

Article 18(1) is the duty itself. Where a business suspects, or has reasonable grounds to suspect, that a transaction, an attempted transaction, or funds in whole or in part constitute proceeds, are related to the crime, or are intended to be used in it — regardless of value — it must, without invoking banking secrecy, professional secrecy or contractual liability, immediately and without delay notify the Unit with all available data through the Unit's electronic system, and respond promptly to requests for more. Article 19(1) then prohibits the business, its directors, officers and employees from disclosing to the customer or anyone else that a report has been or is about to be made, that any data relates to one, or that an investigation is under way. The only carve-out in Article 19(2) is that an attempt to dissuade a customer from committing an unlawful act is not a disclosure.

The mechanics of registering for and filing on goAML — the report types, the submission route, and what registration produces — sit on our goAML page rather than here.

A wording difference worth reading carefully

Article 3(4) of Cabinet Decision No. 134 of 2025 brings "independent accountants" into the DNFBP definition, alongside lawyers, notaries and other independent legal professionals, when they prepare, conduct or execute transactions for a customer in the five listed activities. The professional-privilege exemptions are worded differently: Articles 18(2) and 19(2) exempt lawyers, notaries, other independent legal professionals and "independent statutory auditors" where the information was obtained while assessing a customer's legal position, defending or representing them before courts or in arbitration or mediation, advising on judicial proceedings, or otherwise in circumstances subject to professional secrecy.

The two phrases are not interchangeable and should not be paraphrased into one another. Separately, the Ministry of Economy and Tourism's own online self-check is broader than either: it returns a positive result on "an auditing or accounting firm" as a category, without asking which activity is being performed. Where a supervisor screens categorically and the Regulation defines by activity, an accounting, audit or corporate services firm should assume it is in scope and take the privilege exemption as narrow — it protects legal-position work, not ordinary accounting, bookkeeping or company administration.

#Records, training and the independent audit function

Article 25 requires all records, documents, instruments and data relating to domestic and international financial and cash transactions and commercial dealings to be kept for not less than five years from completion of the transaction or the end of the relationship. Clause 2 extends the same period to due diligence records, ongoing monitoring, account files, business correspondence, copies of identification documents, suspicious transaction reports, the results of any analysis, and CCTV and ATM recordings — with the clock running from the most recent of: the end of the relationship, account closure, completion of an occasional transaction, completion of a supervisory inspection, completion of an investigation, or a final court judgment. Clause 3 adds a quality standard: the records must be organised so that individual transactions can be reconstructed, data analysed and financial flows traced, well enough to serve as evidence in a prosecution.

Article 21(4) requires screening procedures ensuring high standards of fitness and propriety when employees are appointed, and Article 21(5) requires periodic anti-crime programmes and workshops to build the capability of the compliance function and other relevant staff. Article 22(4) puts the design, delivery and documentation of that training on the compliance officer.

Article 21(6) requires an independent audit function to test the effectiveness and adequacy of the internal policies, controls and procedures. The March 2026 Guidelines set out how it is expected to work: internal or external, but genuinely independent of the compliance and operational functions and free of conflicts; smaller firms may engage qualified external auditors, in which case the firm must verify their competence and regulatory standing and formalise scope, confidentiality and data protection in a written contract. Frequency and depth are set on a risk basis, informed by the National Risk Assessment, the firm's own risk assessment, its size and geography, and supervisory findings. The minimum scope named is the design and operating effectiveness of policies and systems, the adequacy of training, outsourcing arrangements, transaction monitoring and case management, remediation of earlier findings, and record-keeping. Findings go to senior management and the board — the function must report above the compliance officer, not to them — and where significant deficiencies cannot be mitigated within an acceptable time, the supervisory authority must be told.

#AML enforcement in the UAE: who supervises, and what follows a finding

Supervision is split by sector. The Ministry of Economy and Tourism supervises independent accountants and auditors, company and trust service providers, dealers in precious metals and stones, and real estate brokers and agents, in the mainland and in the commercial free zones. The Ministry of Justice supervises legal professionals. Financial institutions answer to their own prudential regulator rather than to the Ministry, and businesses licensed in the financial free zones to the Dubai Financial Services Authority or to the Financial Services Regulatory Authority of Abu Dhabi Global Market. The Decree-Law itself defines a supervisory authority generically, as the federal or local authority entrusted under the legislation with supervising the sector — so the practical first question is which authority issued your licence.

Article 17(1) of the Decree-Law gives a supervisory authority seven administrative responses to a violation of the law, the regulation or any decision issued under them: a warning; an administrative fine of not less than AED 10,000 and not more than AED 5,000,000 for each violation; a ban on operating in the relevant sector; restrictions on the powers of responsible board members, executives, supervisors or owners, including the appointment of a temporary supervisor; suspension or replacement of responsible directors and officers; suspension or restriction of the activity or profession; and revocation of the licence. Article 17(2) allows an order to report periodically on the remedy; Article 17(3) allows an incremental fine where the same violation recurs within a year; Article 17(4) allows the authority to publish the penalties it imposes.

The per-violation amounts for the sectors supervised by the Ministry of Economy and the Ministry of Justice come from the list annexed to Cabinet Resolution No. 71 of 2024, issued 8 July 2024, whose Article 8 repeals Cabinet Resolution No. 16 of 2021 — an instrument several competitor pages still quote. Under Article 5(2) the Ministry may double a fine on repetition. Under Article 4, a grievance is filed within 30 working days, no reply within 40 working days counts as a rejection, and an appeal is not admissible before the grievance route has been used.

Programme failures and their fines, from the schedule annexed to Cabinet Resolution No. 71 of 2024
ItemViolationMinimumMaximum
22Failure to submit suspicious transaction reports promptly on reasonable grounds of suspicion, or to provide additional information the Unit requestsAED 100,000AED 500,000
23Failure to register on the electronic system approved at the Financial Intelligence UnitAED 50,000AED 200,000
24Failure to appoint a compliance officer with the appropriate competence and expertise to perform the dutiesAED 50,000AED 200,000
28Disclosing, directly or indirectly, to the customer or anyone else that a report has been or will be made, or that there is an investigationAED 100,000AED 500,000

#AML software, AML services, and what we will not tell you

Two of the searches this page answers are commercial, so here is the honest position on both.

Software. No instrument we read requires a product. The Ministry's March 2026 Guidelines state that monitoring systems may be automated, semi-automated or manual, provided the systems and procedures are documented, reviewed periodically for effectiveness, and approved by senior management with oversight responsibilities assigned. On politically exposed persons the same document says identification systems "may include" automated screening tools, or manual and digital background checks using internet and media searches, subscription or publicly available databases, and background investigation services — proportionate to the nature and size of the business. What the law fixes is the outcome: screening that catches an update to the Sanctions List quickly enough to freeze within 24 hours, monitoring that can flag a transaction inconsistent with what you know of a customer, and records that can reconstruct a transaction years later. A small firm can meet that on a documented manual process; a large book cannot.

We name no vendor. We found no approved, accredited or endorsed software list published by the Ministry of Economy and Tourism, the Financial Intelligence Unit or the Executive Office, so treat "FIU-approved" or "Ministry-approved" as a marketing claim to be checked, not a certification. Where a tool or a consultant is used, the Guidelines keep the compliance officer accountable for understanding, validating and supervising it.

Services. A provider can genuinely help with the parts of the programme that are drafting, design and capability: facilitating the business risk assessment while leaving you able to explain its methodology, drafting policies, controls and procedures for senior management to approve, designing the due diligence file and the customer risk model, building the indicator set, running training, and — if genuinely independent of your compliance function and free of conflicts — performing the independent audit. What does not move is accountability. The compliance officer's decision whether to report is theirs, the assessment remains yours to stand behind, and appointing anyone external does not relieve the business of its obligations.

What this site will not do: we make no claim to be licensed, registered, accredited or credentialled for AML work, and none should be read into anything above; we publish no fee, package or price for our own work; we publish no office address, location or telephone number; we cannot and do not file suspicious transaction reports, name-match reports or any other filing on a client's behalf; and we do not publish another country's AML regime — everything here is the UAE federal framework, checked on 17 August 2026, and nothing on this page is advice on your own facts.

Sources and legal basis

This page relies on

  • Federal Decree-Law No. 10 of 2025 on Anti-Money Laundering, Combating the Financing of Terrorism and Proliferation Financing
  • Cabinet Decision No. 134 of 2025 (Executive Regulation)
  • Federal Decree-Law No. 20 of 2018 (repealed)
  • Cabinet Decision No. 10 of 2019 (repealed)
  • Cabinet Resolution No. 71 of 2024 on violations and administrative fines
  • Cabinet Resolution No. 16 of 2021 (repealed)
  • Cabinet Decision No. 74 of 2020 on the UAE List of Terrorists and the implementation of UN Security Council resolutions
  • Article 5 of Cabinet Decision No. 134 of 2025 (risk identification and mitigation)
  • Article 10 of Cabinet Decision No. 134 of 2025 (beneficial owner, 25%)
  • Article 16 of Cabinet Decision No. 134 of 2025 (politically exposed persons)
  • Article 17 of Cabinet Decision No. 134 of 2025 (suspicion indicators)
  • Article 18 of Cabinet Decision No. 134 of 2025 (reporting duty)
  • Article 19 of Cabinet Decision No. 134 of 2025 (tipping off)
  • Article 21 of Cabinet Decision No. 134 of 2025 (internal policies, training, independent audit)
  • Article 22 of Cabinet Decision No. 134 of 2025 (compliance officer)
  • Article 25 of Cabinet Decision No. 134 of 2025 (record keeping)
  • Article 17(1)(b) of Federal Decree-Law No. 10 of 2025 (AED 10,000-5,000,000)
  • Article 33 of Federal Decree-Law No. 10 of 2025 (targeted financial sanctions offence)
  • UAE Local Terrorist List
  • UN Consolidated List
  • Targeted Financial Sanctions
  • Executive Office for Control and Non-Proliferation
  • Notification Alert System (NAS)
  • Confirmed Name Match Report (CNMR)
  • Partial Name Match Report (PNMR)
  • UAE Financial Intelligence Unit
  • goAML
  • Ministry of Economy and Tourism
  • Ministry of Justice
  • Designated Non-Financial Businesses and Professions (DNFBPs)
  • Business-wide Risk Assessment (BRA)
  • Customer Risk Assessment (CRA)
  • Customer Due Diligence (CDD)
  • Enhanced Due Diligence (EDD)
  • Politically Exposed Persons (PEPs)
  • National Risk Assessment
  • DNFBP Guidelines, March 2026
  • Suspicious Transaction Report (STR)
  1. Federal Decree-Law No. 10 of 2025 on Anti-Money Laundering and Combating the Financing of Terrorism and Proliferation FinancingUAE Financial Intelligence Unit
  2. Cabinet Decision No. 134 of 2025 — Executive Regulation of Federal Decree-Law No. 10 of 2025UAE Financial Intelligence Unit
  3. Cabinet Resolution No. 71 of 2024 regulating violations and administrative penalties (English text with the annexed fine schedule)UAE Ministry of Economy and Tourism
  4. Cabinet Decision No. 74 of 2020 concerning the UAE list of terrorists and the implementation of UN Security Council resolutions (English translation)UAE Ministry of Economy and Tourism
  5. Targeted financial sanctions — legal framework, the Local Terrorist List, screening, freezing and reporting obligationsExecutive Office for Control and Non-Proliferation
  6. Guidelines for Designated Non-Financial Businesses and Professions, March 2026UAE Ministry of Economy and Tourism
  7. Anti-money laundering crimes legislation indexUAE Ministry of Economy and Tourism
  8. Combatting money laundering and terrorism financing — DNFBP supervision, circulars and self-checkUAE Ministry of Economy and Tourism
  9. Compliance and guidance — reporting obligations and submission manualsUAE Financial Intelligence Unit
  10. Understanding the law — the UAE AML/CFT legislative frameworkUAE Financial Intelligence Unit

Rates, thresholds and deadlines change. Every figure above is linked to the authority that publishes it — if the two ever disagree, the authority is right and this page is out of date. Tell us and we will fix it.

FAQ Answers to the questions people actually ask

Frequently asked questions

What is AML compliance?

AML compliance is the continuous programme a supervised business runs to stop money laundering, terrorist financing and proliferation financing passing through it. In the UAE it means a documented business risk assessment, customer due diligence, beneficial owner identification, sanctions screening, a compliance officer with independent decision-making, suspicious transaction reporting, record keeping, training and an independent audit, under Federal Decree-Law No. 10 of 2025 and Cabinet Decision No. 134 of 2025.

What is AML KYC compliance?

Know-your-customer is the identification and verification step inside the wider due diligence duty. Under Cabinet Decision No. 134 of 2025 you must identify and verify the customer from reliable independent sources, verify anyone acting for them, understand the purpose of the relationship and the customer's ownership and control structure, identify the beneficial owner at 25% or more, and then monitor transactions for as long as the relationship lasts. KYC alone is not compliance.

What are the AML CFT compliance requirements in the UAE?

Ten, running continuously: a business risk assessment; internal policies approved by senior management; customer due diligence and ongoing monitoring; beneficial owner identification; enhanced due diligence for high-risk customers, politically exposed persons and high-risk countries; sanctions screening against the UAE Local Terrorist List and the UN Consolidated List; a compliance officer at management level; suspicious transaction reporting without delay; five-year record keeping; and staff training with an independent audit function.

Who can be an AML compliance officer in the UAE?

Someone appointed at management level with independence in decision-making and appropriate competence and experience, under Article 22 of Cabinet Decision No. 134 of 2025. The Ministry's March 2026 Guidelines allow a qualified third-party officer where no suitable internal candidate exists, subject to a fit-and-proper assessment, independence from revenue-generating roles, unrestricted access and a written contract. Accountability and the decision whether to file a report never leave the business.

Is an AML compliance certification required in the UAE?

No UAE instrument we read names one. The Decree-Law, the executive regulation, the 2024 penalty schedule and the March 2026 Guidelines all express the standard as competence, experience and fitness for the role, assessed and documented by the business itself. We do not endorse any particular qualification, and we found no accredited AML course list published by the Ministry of Economy and Tourism or the Financial Intelligence Unit.

Next

Continue reading

Ask

Have a question this page did not answer?

This is where a question goes once the channel is open. It is not open yet, so there is no form here to type one into — see the note opposite.

Not open yet

There is nowhere for this to send

No enquiry address has been set up for this site, so a form here would take your question, your name and your email and throw them away while telling you they had arrived. Rather than do that, it is switched off.

When it opens, what is promised is a written answer citing the instrument it rests on, and no phone number will be asked for. Until then the pages are the answer: every one names its sources and links them.