AML Compliance Requirements for Businesses in UAE

One of the obligations that no business in the UAE can afford to take lightly is anti-money laundering compliance.

One of the obligations that no business in the UAE can afford to take lightly is anti-money laundering compliance. A firm that manages client funds or operates in an industry the legislation deems susceptible to financial crime needs to implement controls that determine who its clients are and recognises suspicious activity to report it to the authorities. This is not a process in which you fill out one form and then you’re done. It is an ongoing commitment that is assessed during regulatory inspections.

The stakes are very high. The country overhauled is entire anti-money laundering framework in late last year, and punishment for errors now extends to the millions of dirhams. They also may be held personally liable to managers. This article clarifies the concept of anti-money laundering compliance and for which businesses it is applicable. It outlines the exact measures that a company must implement and what the repercussions are if it fails to do so.

What Anti-Money Laundering Compliance Means

Usually, anti-money laundering is shortened to AML. It is a term for the laws and procedures used to prevent criminals from laundering illegally acquired funds as legal funds. There are three stages to money laundering. Placement involves the dirty money being introduced into the financial system. Layering: Moves to cover where it came from. When the criminal receives the money as a result of integration, the money appears to be clean. The purpose of AML controls is to break the cycle and to notify the state when it occurs.

A few terms recur throughout this area. Customer Due Diligence or CDD is the process of identifying and verifying a customer before doing business with them. A verification process is part of that, which is known as Know Your Customer or KYC. Ultimate Beneficial Owner (UBO) is a natural person that ultimately owns or controls a company through any corporate structure. Politically Exposed Persons (PEPs) are individuals who have prominent public roles and are deemed to be at increased risk of being involved in corruption. A Suspicious Transaction Report or STR is a report made by a business when it suspects money laundering.

The framework is based on a risk based approach. A business cannot treat all customers equally, and should focus more on the customers and transactions with the greatest potential for financial crime. This is not met by the use of a generic template which was copied from another company. Controls must be in line with the real business.

The Legal and Regulatory Framework

Much of the guidance still around refers to the anti-money laundering law of 2018 and the executive regulations of 2019. That framework has been superseded and companies with a legacy compliance manual are vulnerable. The current main law is Federal Decree Law No. 10 of 2025 which entered into effect on 14 October 2025 and which superseded the 2018 law. It came into force through Cabinet Resolution No. 134 of 2025 to replace the 2019 rules and came into force on 14 December 2025. The new framework is expressly extended to virtual assets, and to financing of proliferation. That word is for the financing of weapons of mass destruction. The changes also include significantly higher penalties.

There is a division of responsibility around oversight, rather than centralisation of oversight. Banks and exchange houses together with finance and insurance companies are supervised by the Central Bank of the United Arab Emirates. The control of most designated non financial businesses is the responsibility of the Ministry of Economy as well as the Ministry of Justice. The financial free zones use their own rulebooks in addition to the federal rulebook. In the Dubai International Financial Centre, it is done by the Dubai Financial Services Authority and in the Abu Dhabi Global Market, it is done by the Financial Services Regulatory Authority. By their side stands the Financial Intelligence Unit.

It is important to understand Financial Intelligence Unit or FIU as a lot of businesses do the mistake of calling their supervisor Financial Intelligence Unit. It became an independent function of the Central Bank in the 2025 legislation. Its mandate is to accept and process the regulated businesses’ reports and to share the intelligence with law enforcement. The body that inspects a company or issues fines, is not the body. Those powers are held by the supervisory authority in each sector. The fact that a report has been submitted to the FIU does not relieve of the separate requirement to satisfy the supervisor and vice versa.

Which Businesses Must Comply

Two general categories of people are responsible for the obligations. The first one is Financial Institutions. Banks and exchange houses, insurance and finance companies and payment service providers. The second is Designated Non Financial Businesses and Professions. This group is typically reduced to DNFBPs and it represents businesses that can be used for the regular course of business to facilitate movement of illegal money.

It is important to note the DNFBP categories under the current executive regulations because the perimeter has changed. They are real estate brokers/agents. They have dealers of precious metals and stones. They include lawyers and notaries as well as other independent legal practitioners. They include independent accountants and auditors, company and trust service providers. Commercial gaming operators is a new category added to the regulations for 2025, acknowledging the licensing of regulated gaming in the country.

Virtual Asset Service Providers or VASP is not classified as a DNFBP[1]. Cryptocurrency exchanges and custodians/transfer services are now clearly in the federal framework and are the lowest trigger for customer due diligence in the regime. If it is not certain the business should evaluate its licensed activity against these categories instead of assuming that it is not subject to these categories.

The Core Compliance Requirements

A compliant programme is a combination of individual controls. These are different, separate duties and a deficit in any one of these is a default in itself which is punishable in the existing law.

Þ    Business risk assessment. This is the base. A business’ risk of money laundering needs to be assessed in relation to the type of customers and products/services they provide and delivery methods and countries they serve. The assessment should be recorded and monitored frequently. It directs all the other controls, as it determines where effort is to be given.

Þ    Customer Due Diligence. Before a business can commence it is fundamental that it have the ability to recognise and confirm each customer, and understand the nature of the relationship. Verified duty is an action to be carried out when a relationship is created. This is also the case when a customer does a transaction of AED 55,000 or above occasionally, and for transactions where money laundering is suspected. The threshold for virtual asset providers is AED 3,500 and for commercial gaming operators it is AED 11,000.

Þ    Ultimate Beneficial Owner verification It is a requirement for a business to trace the corporate structure to the natural person who is the owner or controller of the customer. A 25% or more stake in a company is the threshold for beneficial ownership. The records of this analysis shall be accurate and updated because one of the principal methods of transacting with illicit funds is to conceal ownership.

Þ    Enhanced Due Diligence. If the risk is more significant, the investigation needs to be more indepth. Politically exposed persons, customers from high risk countries and complex customers all require extra checks and closer monitoring beyond the standard checks.

Þ    Ongoing transaction monitoring and screening. Compliance is not a one time occurrence onboarding. A company should be alert in case of any transactions that do not match the customer profile. It also has to perform checks against relevant watchlists and sanctions on customers at the time of onboarding and as part of the ongoing relationship. Customer information and risk ratings should be updated on a regular basis and re-evaluated when there has been a significant change in customer ownership or activity.

Governance Reporting and Record Keeping

There must be a person responsible for a programme. A business should designate a fit and proper compliance officer, with sufficient rank to be independent. Must have an officer approved by the appropriate supervisory authority prior to assuming duties. According to the current guidance, that officer must have at least 2 years’ experience in AML or CFT matters. The officer is responsible for the policies and responsible for reporting and co-ordinating with regulators and conducts staff training.

There shall be documented policies behind the officer. They should encompass due diligence and risk assessment, monitoring and reporting, record retention and they should be reviewed at least annually to ensure they stay up to date with regulatory changes. Staff training is not merely good practice but a legal requirement, since it is employees who are usually the first to notice any unwarranted activity within the business.

Suspicious activity has to be reported through the goAML portal operated by the FIU. There is no minimum dollar amount for a transaction that requires the submission of an STR, and the law mandates an STR be submitted as soon as reasonable suspicion is reached. Suspicion is sufficient. While the time limits are made tighter for financial institutions when filling internal applications with the Central Bank, the common denominator for all reporting entities is that the report should be filed promptly, which does not necessarily correspond to a set number of days.

Records link the entire programme. Customer identification and beneficial ownership data, risk assessments, transaction records and training logs shall be kept for a period of not less than five years following the transaction or the termination of the relationship. They also need to be sufficiently specific to be able to recreate transactions, if an investigation requires it.

Common Mistakes and the Cost of Non Compliance

Most compliance violations are due to deficiencies in compliance implementation, not because there are no policies in place. Common issues include weak customer due diligence practices, and outdated risk assessments and beneficial owner identification. Lastly, delayed reporting and poor staff training, record keeping. All of these are easy to correct if they are found and these are all points an inspector will check.

The current law has harsh penalties and they are intended that way. Supervisory authorities can impose administrative fines ranging from AED 50,000 to AED 5,000,000 for each violation and the amount can be doubled for repeat breaches. Not reporting a suspicious transaction constitutes an offence and a fine of between AED 100,000 and AED 1,000,000 and imprisonment. In the most severe cases of corporate violations, the fines can be as high as AED 100,000,000.

The 2025 law has two aspects that warrant special attention. The first is that for the first time, individual managers, directors and compliance officers may face personal criminal liability, in addition to a company being liable. This applies where there is wilful misconduct or where there is no proper control in place in the event of a breach. The second is that a failure of compliance is a punishable offence, on its own account. A penalty can be incurred, even if no money laundering takes place, due to inadequate controls, poor records or lack of a compliance officer.

The fine is seldom the only penalty. Authorities have powers to suspend or revoke licences and limit business operations. Weak AML controls are also a common ground to pull back or hesitate on a relationship with a bank. The penalty itself is not actually the biggest problem for many companies it is more the challenge of getting the money they need to remain in business.

Conclusion

The UAE is mandating AML compliance for financial institutions and designated non financial businesses and virtual asset providers. It is assessed based on the effectiveness of the controls and not the presence of policies. In all sectors the building blocks are the same. They are a known risk assessment profile and CDD in line with the risk, as well as continued monitoring and ST reporting via goAML and robust record keeping and a compliance officer that has ownership of the programme.

The first and foremost thing for every company to understand when looking at their situation is if the legal framework has changed. A manual which was written against the 2018 legislation and the 2019 regulations is now obsolete and therefore using it is itself a risk.

Each assessor shall take their assessment based on Federal Decree Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025 and confirm the current situation with the relevant supervisory body prior to action. Compliance is a lifelong discipline for a business, not a onetime formality, and it is the best way to avoid a penalty and promote the overall integrity of the market it operates in.

WhatsApp