AML Regulations for CMA-Regulated Market Institutions and Brokers in UAE
Published On: 08/12/2026
Protect your business with reliable and effective AML strategies with AML UAE.
Last Reviewed On: 08/12/2026 | Last Updated On: 08/12/2026
Key Highlights
- Capital market institutions and brokers, including licensed exchanges, clearing and settlement institutions, central securities depositories, and brokerage and dealer firms, are financial institutions under Federal Decree-Law No. 10 of 2025 and its Executive Regulations in Cabinet Resolution No. 134 of 2025.
- They are supervised for AML by the Capital Market Authority, established under Federal Decree-Law No. 32 of 2025 as the successor to the Securities and Commodities Authority, not by the Central Bank.
- The national risk assessment rates the securities sector money laundering risk in the medium to medium-high range, with controls assessed as effective, and its proliferation financing risk as low in both the mainland and the financial free zones.
- The exposure for a trading business concentrates in client onboarding, beneficial ownership behind corporate, nominee and omnibus accounts, the source of trading and margin funds, sanctions screening of every party to a trade, and surveillance of execution and settlement for layering and manipulation.
- On top of the federal laws, the Capital Market Authority issues its own rulebook chapter, sector guidance, notices, thematic reviews and reporting standards that brokers, dealers and market operators must build into their programme.
- The AML obligations of virtual asset service providers fall under a separate framework rather than this securities regime, and firms in the DIFC and ADGM answer to the DFSA and FSRA and sit outside this guide.
Capital market institutions and brokers sit at the point where trades happen in the UAE financial system. Exchanges match orders, clearing houses and depositories settle them, and brokerage firms open the accounts and route the client money and securities that move through the market. That places them under the Capital Market Authority rather than the Central Bank, and it gives them a money-laundering exposure that runs through account opening, order execution, settlement, and custody rather than deposits or remittances.
This guide sets out the AML regulations for CMA-regulated market institutions and brokers in the UAE: who is in scope, the regulator, the full legal stack, how the national risk assessments rate the securities sector, and the controls a trading business is expected to run. It covers securities and commodities market institutions and brokers supervised by the Capital Market Authority outside the DIFC and ADGM.
In short: CMA-regulated market institutions and brokers in the UAE, including licensed exchanges, clearing houses and central depositories, and brokerage firms, broker-dealers, dealers and trading members outside the DIFC and ADGM, must comply with Federal Decree-Law No. 10 of 2025, its Executive Regulations in Cabinet Resolution No. 134 of 2025, the targeted financial sanctions framework under Cabinet Decision No. 74 of 2020, UAE FIU reporting through goAML, and the Capital Market Authority rulebook, notices and reporting standards. Firms in the DIFC and ADGM follow the separate DFSA and FSRA AML regimes.
Who Counts as a Capital Market Institution or Broker for AML Purposes?
For AML purposes, this category covers entities the Capital Market Authority licenses to operate market infrastructure or to execute and arrange trades in securities and commodities. The types below all sit inside the AML regulations for CMA-regulated market institutions and brokers in the UAE. The DFSA and FSRA supervise entities established in the DIFC and ADGM and are not covered here.
Licensed securities and commodities markets
Licensed exchanges operate the venues where securities and commodities are listed and traded. Their AML exposure runs through membership admission, the conduct of trading members, and surveillance of order flow for manipulation, wash trades and layering that can disguise the movement of value.
Clearing, settlement and central depositories
Clearing houses, settlement systems and central securities depositories complete and record the transfer of cash and securities after a trade. Their controls centre on the participants they admit, the accounts they maintain, and the risk that settlement and safekeeping are used to obscure ownership or move value.
Brokerage and dealing firms (stockbrokers)
Brokerage firms, broker-dealers, dealers and market makers open accounts and execute or arrange trades for clients. Their exposure is heaviest at onboarding, in the beneficial owners behind corporate, nominee and omnibus accounts, in the source of trading and margin funds, and in introduced or remotely onboarded clients.
Trading members and market intermediaries
Trading members and other market intermediaries access the market on behalf of clients or their own book. Their risk sits in client due diligence, the screening of counterparties to each trade, and the handling of client securities and cash held in the course of business.
AML Supervisory Authority for Capital Market Institutions and Brokers in UAE
Supervision of banks in mainland UAE and the commercial free zones rests with a single authority.
Capital Market Authority (CMA)
The Capital Market Authority is the federal regulator for the UAE securities and commodities sector, established under Federal Decree-Law No. 32 of 2025 as the successor to the Securities and Commodities Authority. It licenses and supervises exchanges, clearing and settlement institutions, depositories, brokers and dealers outside the DIFC and ADGM, and it is the AML and CFT supervisor for those entities. The Authority sets the rulebook chapter that governs their compliance programmes, issues sector guidance, notices and thematic reviews, collects annual and semi-annual AML returns, runs examinations, and can impose administrative penalties. A market institution or broker looks to the Capital Market Authority, not the Central Bank, for its supervisory expectations, and reads that rulebook alongside the federal AML laws.
UAE FIU and goAML
Every market institution and broker in scope registers with the UAE Financial Intelligence Unit and files through the goAML system. The Financial Intelligence Unit, established within the Central Bank under Federal Decree-Law No. 10 of 2025, is the national body that receives suspicious transaction reports, suspicious activity reports, and the other reports the framework requires, and it can request further information and share intelligence with supervisors and law enforcement. For a trading business, filing STR and SAR on the goAML portal is how a suspicious order, a questionable settlement, a sanctions match or an unusual funding pattern reaches the authorities. Registration, timely reporting and accurate goAML submissions are a legal duty, not a courtesy, and the quality of those reports is something the Capital Market Authority and the Unit both scrutinise.
AML Legal Framework Applicable to Market Institutions and Brokers in UAE
The legal framework for a CMA-regulated market institution or stockbroker has four layers: the core federal AML laws and executive regulations, the guidance that applies to all reporting entities, the national and sector risk assessments, and the Capital Market Authority’s own rulebook and guidance. The instruments below make up that framework, which sits within the AML regulations for capital market firms in the UAE. Each is described for what it means to an exchange, a clearing house, a depository or a brokerage firm in practice.
Federal AML Laws and Executive Regulations Applicable to Capital Market Institutions and Brokers in UAE
These are the core federal instruments every market institution and broker builds its programme on.
Federal Decree-Law No. 10 of 2025 on AML, CFT and CPF
Every trading account a brokerage opens, and every settlement a clearing house completes, sits under Federal Decree-Law No. 10 of 2025, the statute at the base of the UAE anti-money laundering regime. It defines money laundering, predicate offences, terrorism financing, proliferation financing, and targeted financial sanctions while establishing the framework for suspicious transaction reporting. The law applies equally to regulated capital market activities carried out through electronic trading and settlement systems. It establishes the Financial Intelligence Unit within the Central Bank as the national body receiving suspicious transaction reports, able to demand further information and, through the Head of the Unit, to order suspension and freezing within the Decree-Law’s limits. Exchanges, brokers and custodians sit under its supervisory oversight and administrative penalties, with a duty to detect, report and support enforcement.
Cabinet Resolution No. 134 of 2025, the Executive Regulations
Where the statute sets principles, Cabinet Resolution No. 134 of 2025 turns them into the day-to-day rulebook a broker, market operator or depository actually runs. By issuing the Executive Regulations of Federal Decree-Law No. 10 of 2025, it broadens the defined terms to cover senior management, beneficial owners, reasonable measures, and wire transfers. It puts securities activities and funds transfers squarely in scope. It fixes the substantive duties: a risk-based approach, customer due diligence on trading clients, identification and verification of the beneficial owners behind corporate and nominee accounts, continuous monitoring of trading and settlement flows, and internal policies signed off by senior management. These are the exact procedures examiners test on inspection.
Cabinet Decision No. 109 of 2023 on beneficial owner procedures
Behind the corporate, nominee and omnibus accounts a brokerage or custodian opens sits a real person, and Cabinet Decision No. 109 of 2023 governs how that person is identified. It regulates beneficial owner procedures for legal persons in the United Arab Emirates, defining the real beneficiary as the natural person who ultimately owns or controls a legal person, directly or through a chain of ownership. Legal persons must obtain, maintain and disclose accurate beneficial owner data, flag nominee board members, and refresh a register within fifteen days of any change. Brokers and market intermediaries lean on this data to verify corporate clients. It reaches legal persons in the State and commercial free zones, but not the DIFC or ADGM.
Cabinet Resolution No. 132 of 2023 on penalties for beneficial owner violations
Cabinet Resolution No. 132 of 2023 gives the beneficial owner rules their teeth, setting the administrative penalties for breaches of the procedures under Cabinet Decision No. 109 of 2023. The registrar may fine legal persons that fail to keep accurate registers or hand over required information, following an annexed schedule and without prejudice to any penalties or procedures under the AML Decree-Law and other applicable legislation. Penalties escalate: on a third violation, the registrar may suspend the commercial licence and close the premises until the fine is paid and the breach cured.
Cabinet Resolution No. 74 of 2020 on terrorist lists and implementation of UNSC resolutions
Sanctions screening of every party to a trade and settlement traces back to Cabinet Resolution No. 74 of 2020, which sets how the United Arab Emirates applies the terrorist lists and gives effect to United Nations Security Council sanctions on terrorism, its financing and proliferation. It provides for a local Cabinet list, defines designation, listing and de-listing, and requires freezing without delay, which the Executive Office guidance treats as immediate action on receipt of a designation rather than a fixed grace period. For an exchange, broker or clearing house, this is the backbone of screening. Firms register on the Executive Office website, continuously screen clients, prospective investors, beneficial owners and trade counterparties against the lists, freeze any matched funds or securities without prior notice, and report promptly to the supervisor.
Federal Law No. 7 of 2014 on combating terrorism crimes
Federal Law No. 7 of 2014 on Combating Terrorism Crimes is the criminal code behind the conduct that a broker’s or custodian’s controls are built to catch. It defines terrorist offences and their penalties, setting out concepts such as terrorist crime, terrorist purpose, terrorist organisation and terrorist person, with punishment reaching life imprisonment and, in specified cases, death. Of direct relevance to a market institution is its treatment of terrorism financing: it penalises providing, collecting or maintaining funds for terrorist ends. It addresses the freezing of suspect funds held in financial institutions. Because the wider AML framework defines terrorist acts by reference to this law, exchanges, brokers and depositories use it to understand exactly what their monitoring and screening target.
AML Guidance Applicable to All Reporting Entities
Beyond the core laws, the UAE Financial Intelligence Unit, the Executive Office for Control and Non-Proliferation, and the supervisory authorities issue guidance and typologies that apply to every reporting entity, including market institutions and brokers.
UAE FIU Regulation No. 1 of 2026 on Suspension and Freezing Powers, April 2026
When a suspect settlement is about to complete, or a client is about to withdraw cash from a trading account, UAE FIU Regulation No. 1 of 2026, dated April 2026, sets out how it can be stopped. Issued under the AML/CFT Decree-Law and its Executive Regulation, it governs the postponement or suspension of suspicious transactions and the freezing of funds. It applies to reporting entities alongside their existing reporting duties. It introduces the Postponement Suspicious Transaction Report, an urgent filing where funds suspected of links to crime risk imminent transfer, withdrawal or dissipation. The Head of the Unit may order suspension of up to ten working days and freezing of up to thirty days. For brokers and custodians, it is a fast-track tool to preserve client funds and securities.
UAE FIU Strategic Analysis Report on Human Trafficking, April 2026
The UAE FIU Strategic Analysis Report on Human Trafficking, dated April 2026, examines the money laundering and financial flows tied to trafficking, drawing on suspicious transaction and activity reports filed with the Financial Intelligence Unit. It sets out its objectives, methodology and scope and covers the main forms of exploitation, with findings spanning the laundering of trafficking proceeds and its convergence with other criminal enterprises. It profiles subjects including organised crime groups, foreign politically exposed persons and money mules, and builds risk indicators around customer profile, behavioural activity, account and transactional activity, and due diligence. Brokerages and market institutions can use it as a detection resource, sharpening trade surveillance and lifting the quality of the reports they file.
Guidance on Targeted Financial Sanctions for Financial Institutions, DNFBPs and VASPs, March 2026
Issued by the Executive Office for Control and Non-Proliferation, first published in January 2021 and last amended in March 2026, this guidance spells out what the targeted financial sanctions framework demands of a market institution or broker. It sets four duties: registering in the Executive Office’s Notification Alert System; screening clients against the UAE Local Terrorist List and the United Nations Consolidated List; freezing assets without delay and never making them available to designated persons; and reporting the measures taken. The March 2026 update renames the Funds Freeze Report as the Confirmed Name Match Report and deals with weekend screening, relevant where markets settle across non-trading days. It defines how screening, freezing and reporting actually run inside an exchange or brokerage.
Joint Guidance on the Compliance Officer and MLRO, 2026
Every brokerage, exchange and clearing house needs a compliance officer who can act, and this joint guidance, issued in 2026 by the UAE Supervisory Sub-Committee, sets a unified framework for that role. It covers the appointment, authority and responsibilities of the Compliance Officer or Money Laundering Reporting Officer across regulated sectors, applying to firms supervised by authorities including the Capital Market Authority, the Central Bank and the Ministries of Justice, Economy and Tourism, and building on Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025. It treats the post as a cornerstone of an effective programme, demanding proper seniority, experience, operational independence, board access and adequate resources. Market institutions should read it before appointing a compliance officer, since it sets the fit-and-proper standard for the post.
FIU Strategic Analysis Report on Terrorist Financing, May 2025
Published in May 2025 by the UAE Financial Intelligence Unit, this strategic analysis on terrorist financing typologies and facilitators rests on data held from 1 January 2021 to 31 December 2024, including suspicious transaction and activity reports and cases passed to authorities. It explains how terrorist financing works and maps typologies such as moving and obscuring funds through financial institutions, corporate networks, trade-based methods, high-value goods and real estate. It also examines facilitators, from designated persons and family members to money mules, corporate nominees and professional service providers, closing with practical indicators. These indicators sharpen how a broker or custodian detects, traces and reports suspicious securities-account and settlement activity.
Federal Decree-Law No. 6 of 2025 on the Central Bank, Regulations of Financial Institutions and Activities, and Insurance Business
Federal Decree-Law No. 6 of 2025 is the Central Bank law governing the licensing and supervision of financial institutions. It is not the anti-money laundering statute, but it belongs in the surrounding framework because it underpins the wider financial system a market institution deals with every day, from the settlement banks that move trade proceeds to the banks that act as custodians. For a CMA-regulated exchange, broker or depository, it matters chiefly at the perimeter: knowing which counterparties and settlement partners hold Central Bank licences, and how the two supervisory regimes, the CMA under Federal Decree-Law No. 32 of 2025 and the Central Bank, fit together across the market.
goAML FAQs, April 2024
The goAML FAQs, version 2.1 dated 18 April 2024, are a practical question-and-answer guide from the UAE Financial Intelligence Unit for reporting entities using the goAML system and its registration and access services. They work through the common registration and login snags with step-by-step fixes, including expired one-time passwords at first login, pop-up authentication that wants the system-issued username with a Google Authenticator passcode, the correct login sequence, and resetting a forgotten password. They set out where credentials go and who to contact when errors persist. For a broker or custody desk, dependable goAML access is what keeps a suspicious transaction report moving on time, so this note keeps compliance teams connected without avoidable delay.
PF Institutional Risk Assessment Guidance for FIs, DNFBPs and VASPs, December 2023
Published in December 2023, this guidance shows a firm how to assess and manage its exposure to proliferation financing. It lays out a methodology built on inherent risk, control effectiveness and residual risk, and names the risk categories and factors an institution weighs when scoring its business. It runs through the supporting measures, from client onboarding, know your customer and due diligence to enhanced due diligence, screening for sanctions and adverse media, ongoing and transaction monitoring, and suspicious activity reporting. A customer risk scoring questionnaire, elevated risk factors and worked case studies show how the scores land. It converts proliferation financing duties into a repeatable framework that a supervisor can review, which is what a brokerage, exchange or depository needs on file.
Terrorist and Proliferation Financing Red Flags Guidance, December 2023
Updated in December 2023, the Terrorist and Proliferation Financing Red Flags Guidance pulls together a single set of indicators to help a firm spot suspicious financing and the evasion of targeted financial sanctions imposed under United Nations resolutions or local designations. It explains how sanctioned parties bury their involvement through renaming, intermediaries and front companies, useful when a broker or custodian screens the beneficial owners behind corporate and nominee accounts. The indicators are grouped by customer profile, account, transaction activity, maritime and trade finance. For dealers, market makers and custodians, it sharpens both the trading desk and compliance, guiding the call on when securities dealing or account activity should trigger a report to the authorities.
Suspicious Activity and Transaction Reporting Thematic Review, January 2023
Issued in January 2023, this thematic review distils the key findings and regulatory expectations from the 2022 AML/CFT examination of licensed financial institutions and designated businesses. It concentrates on the suspicious transaction and activity reporting framework and the transaction monitoring and trade surveillance systems that feed it, read together with existing guidance on reporting, monitoring and screening. It is built around expectations, contrasting acceptable and deficient practice across governance, policies, risk-based monitoring controls, data management, alert review, case investigation, reporting decisions and the post-reporting process. Treat it as a benchmark: test surveillance, monitoring and reporting against it before the regulator does.
Counter Proliferation Financing Guideline, November 2022
Published in November 2022 by the Executive Office for Control and Non-Proliferation, this guideline supplements the wider Guidance on Targeted Financial Sanctions and raises awareness of proliferation financing threats among regulated firms. It defines what proliferation financing is, sets out its stages, and describes the UAE counter-proliferation framework, the interagency mechanism and the relevant federal laws. Exchanges, brokerages and custodians can use it to build proliferation financing risk into their own risk assessment and apply mitigating measures, including enhanced due diligence on clients and transactions, scrutiny of shell and front companies, exposure to dual-use trade, and staff training. A set of red flags helps detect attempted sanctions evasion.
goAML Web Submission Guide, July 2022
Issued by the UAE Financial Intelligence Unit in July 2022, the goAML Web Submission Guide sets out how a report reaches the FIU through the goAML platform. It is written for the designated Compliance Officer or Money Laundering Reporting Officer of a registered reporting entity, or the deputy when the lead officer is away. It runs through the report types, including the Suspicious Transaction Report and the Suspicious Activity Report, the latter covering suspected activity or an attempted trade that never executed, alongside the Additional Information File, Request for Information and High Risk Country transaction reports. It standardises how a broker, dealer or custodian files a suspicion around a trade or account, promptly and in the right form.
Joint Guidance on Combating the Use of Unlicensed Virtual Asset Service Providers, March 2022
Issued in March 2022 by the UAE Supervisory Authorities, including the Capital Market Authority and the Central Bank, this joint guidance tackles the risks from providers operating outside the licensing regime. It reminds regulated firms of their anti-money laundering duties and urges the public to deal only with licensed entities. It expects firms to stay alert, feed emerging risks into their risk assessments, run adequate due diligence, flag clients who gravitate to unlicensed providers, and report suspicions. Red flags include no regulatory licence, no physical presence, unrealistic promises or Ponzi structures, and pressure to invest fast. A brokerage will use it to sharpen screening of client flows that brush against unlicensed virtual-asset activity.
IEMS User Guide for Reporting Entities, March 2022
Dated March 2022, the IEMS User Guide for Reporting Entities is a working manual from the UAE Financial Intelligence Unit for its Integrated Enquiry Management System, which automates information requests, the implementation of public prosecutions’ decisions and other requests from domestic authorities. It explains how a firm registers and logs in, noting that entities already on goAML reuse the same credentials. It walks through the dashboard, request management and the reply and attachments workflow, covering account, account holder and signatory details, sets out the Admin, Maker and Checker roles, and stresses meeting due dates and acting on freeze orders at once. It shows how an authority’s enquiry into a client or account is handled at an exchange, broker or custodian.
goAML Pre-Registration Guide, March 2022
The goAML Pre-Registration Guide, issued by the UAE Financial Intelligence Unit in March 2022, explains how a reporting entity secures access to the Services Access Control Manager, or SACM, before it can reach the goAML application to register and file suspicious reports. The application is open through a public portal for entities not regulated by the Central Bank, while others follow their Supervisory Body’s steps. SACM holds the links to the production and testing environments and is controlled by a time-based one-time password from Google Authenticator. The note runs to pre-registration, confirming intent and safeguarding a personal Secret Key. Correct pre-registration is what gives a broker, dealer or custodian secure reporting access in the first place.
goAML Registration Guide, March 2022
The goAML Registration Guide, issued by the UAE Financial Intelligence Unit in March 2022, sets out the steps an organisation takes to register with the FIU on its reporting platform. It covers registration as a reporting entity, stakeholder or supervisory body, and confirms that every accountable and reporting entity in the United Arab Emirates, whatever its regulator, must register to submit suspicious reports. It explains reaching the portal through the Services Access Control Manager, then choosing the registration type, entering the organisation and its addresses, adding the registering person and setting user access rights. Sound registration is the base on which compliant, timely reporting rests, whether the firm is a market institution or a brokerage.
Strategic Review on Targeted Financial Sanctions Case Studies, November 2021
Dated November 2021, this Strategic Review on Targeted Financial Sanctions Case Studies looks at how sanctions reporting worked in the UAE over the period reviewed. It sits inside the framework under which the country, through Cabinet Resolution No. 74 of 2020, gives effect to United Nations Security Council Resolutions on terrorism, terrorist financing and proliferation financing, including freezing measures and bans on providing funds and services. The review explains its method, then sorts sanctions reports by source, by suspicion and by the instruments involved, drawing out the patterns that separate terrorist financing from proliferation financing and offering red flags and recommendations. It shows how a sanctions suspicion around a trade or holding arises in a brokerage and how it is reported.
Strategic Review on Targeted Financial Sanctions Case Studies, April 2024
Published by the Executive Office for Control & Non-Proliferation, this strategic review analyses 33 terrorism financing and proliferation financing cases investigated between 2019 and 2023 to identify the methods, instruments, reporting triggers and sanctions evasion typologies encountered across the UAE. Rather than introducing new legal obligations, it helps financial institutions understand how designated persons and entities attempt to bypass targeted financial sanctions through front companies, third-party intermediaries, forged documents, high-risk jurisdictions and investment structures. For an exchange, broker, clearing house or custodian, it demonstrates how sanctions risks can emerge during onboarding, securities transactions, custody relationships and fund movements, reinforcing the importance of effective sanctions screening, customer due diligence, transaction monitoring and timely reporting of suspicious activity.
Typologies on the Circumvention of Targeted Sanctions, November 2021
Last amended in November 2021 and issued by the Executive Office, this typologies report gathers cases showing how sanctioned persons and entities try to get around targeted sanctions linked to terrorism and the proliferation of weapons of mass destruction. Drawing on public sources from the UAE and abroad, it lays out the methods used to dodge United Nations resolutions and the national terrorist list. The typologies are grouped by channel and sector, covering online payment facilities, trade in dual-use goods, elaborate legal entity structures, cyberactivity and economic resources, each with named networks and red flags. For dealers, market makers and custodians, it turns evasion tactics into concrete learning for screening, due diligence and trade monitoring.
Update to the List of High Risk Jurisdictions, November 2021
This November 2021 decision of the National Anti-Money Laundering Committee refreshes the list of high-risk jurisdictions subject to a call for action, the list of jurisdictions under increased monitoring and the counter-measures to apply, replacing an earlier March 2021 decision. Addressed to the supervisory authorities and the Financial Intelligence Unit, it reflects the Committee’s mandate to name countries with weak controls, set proportionate counter-measures and direct supervisors to ensure the required due diligence is done. For a broker, exchange or custodian, country risk is a core input to controls, signalling which jurisdictions call for enhanced due diligence on investors and cross-border securities flows and requiring risk assessments to track the latest listings.
Joint Guidance on Satisfactory and Unsatisfactory Practice, June 2021
Issued in June 2021 by the UAE Supervisory Authorities, including the Capital Market Authority, the Central Bank and the Ministries of Justice and Economy, this joint guidance draws on themes seen during inspections between January 2020 and May 2021. It sets satisfactory against unsatisfactory practice across the anti-money laundering framework, targeted financial sanctions and counter-proliferation financing. For a brokerage or market institution, it spans governance and management oversight, risk assessment, the three lines of defence, policies, training and the compliance officer role, alongside client onboarding, monitoring, risk rating, due diligence, transaction monitoring, sanctions screening and reporting. By turning inspection findings into concrete examples, it lets firms benchmark their own controls before the examiner does.
Typologies on the Circumvention of TFS, PF and WMD, May 2021
Last amended in May 2021 and issued by the Executive Office, this typology report examines how sanctioned persons and entities raise financing in breach or evasion of United Nations resolutions on terrorism and the proliferation of weapons of mass destruction. It notes that targeted financial sanctions reach both asset freezing and the prohibition on making funds or assets available, directly or indirectly, to designated parties. Organised by financing method, it covers trade in goods, economic resources, online payment facilities, cyberattacks on financial institutions and the misuse of legal entities and arrangements, closing with red flags. For dealers, market makers and custodians, it reinforces the screening, monitoring and reporting of attempted circumvention through securities accounts.
goAML FAQs, September 2020
The goAML FAQs Guide, issued by the UAE Financial Intelligence Unit in September 2020, is a practical question-and-answer reference for reporting entities using the goAML platform, through which suspicious reports are filed in the United Arab Emirates. It gathers the queries most often raised once an organisation is registered and live, each with a step-by-step answer. It explains resetting a forgotten password, updating organisation details such as name, licensed activity, address and contacts, and how the Money Laundering Reporting Officer, acting as admin, can delegate reporting to a third party subject to Supervisory Body approval. Accurate registration data and managed access are what keep a broker, dealer or custodian reporting to the FIU without interruption.
goAML Registration Guide Stage 2, September 2020
The goAML Registration Guide Stage 2, issued by the UAE Financial Intelligence Unit in September 2020, walks an organisation through the steps of registering with the FIU on its reporting platform. It applies to registration as a reporting entity, stakeholder or supervisory body, confirming that every accountable and reporting entity in the United Arab Emirates must register to submit suspicious reports, and noting that since 27 June 2019 those reports must be filed electronically through goAML. It covers reaching the portal through the Services Access Control Manager, selecting the registration type and registering an organisation. Proper registration is the gateway to lawful electronic reporting for any market institution or brokerage.
Guideline on Grievance Procedures
The Guideline on Grievance Procedures comes from the Executive Office for Control and Non-Proliferation, the body that receives grievance requests tied to the UAE Local Terrorist List and the United Nations Consolidated List, together the Sanctions Lists. Under Cabinet Resolution No. 74 of 2020, it handles three types: de-listing of a designation, cancellation of freezing measures, and permission to use frozen assets, each turning on whether the designation sits on the Local or the United Nations List. For an exchange, broker or custodian, it maps the lawful routes an affected client can take to challenge a designation or seek access to frozen securities and funds held in a trading account.
Online Grievance System User Guide
The Online Grievance System User Guide also comes from the Executive Office for Control and Non-Proliferation, which receives grievance requests linked to the UAE Local Terrorist List and the United Nations Consolidated List, together the Sanctions Lists. Built to streamline submissions, the system is explained step by step in this manual. It covers three online request types: de-listing, cancellation of freezing measures, and permission to use frozen funds. It guides the user through identifying the aggrieved individual or legal entity, choosing the grievance type, declaring earlier requests and appeals, and attaching documents. For a custodian holding a client’s frozen securities and cash, it shows how that client can challenge a designation or seek access to the assets.
Simple Guide to Subscribe to the EOCN Notification Alert System (NAS)
This short guide explains how to subscribe to the Notification Alert System run through the Executive Office’s website, so a firm receives timely updates to the sanctions lists applied in the UAE. Targeted financial sanctions rest on designations across two lists, together the Sanctions Lists: the UAE Local Terrorist List issued by the Cabinet and the United Nations Consolidated List issued by the Security Council, each updated from time to time. It shows where the lists can be found and gives step-by-step subscription instructions, from the webpage to entering details and confirming. It underpins a core control at an exchange or brokerage, since screening every party to a trade works only against current lists.
Emerging ML, TF and PF Risks and Trends in the Financial Sector
Issued by the Supervisory Subcommittee under Article 16 of Federal Decree-Law No. 10 of 2025, this report gives regulated firms a current read on the money laundering, terrorist financing and proliferation financing threats reshaping the financial sector as technology, geopolitics and criminal methods shift. After setting scope and methodology, it examines emerging risks such as the exploitation of artificial intelligence, greenwashing and ESG-related fraud, trade finance abuse, and sanctions evasion tied to the Commonwealth of Independent States. Case studies cover money mule networks, trade-based laundering, free-zone corporate structures and fraudulent green schemes. Brokers, market operators and custodians should feed these typologies and red flags into their risk assessments and surveillance systems.
Typologies in the Financial Sector
Typologies in the Financial Sector is a joint report by the Supervisory Authorities Sub-Committee and the Financial Intelligence Unit, prepared with the Executive Office and a pilot group of institutions. It shares money laundering, terrorist financing, sanctions, fraud and corruption typologies seen in the market, several surfacing during the COVID-19 period, to help firms get ahead of emerging risks. Sitting above the National Risk Assessment, it describes the risk indicators that combine to hide the true nature of transactions and flags links to modern slavery and human trafficking. For dealers, market makers, advisers and custodians, it works as an early warning for updating risk assessments, refining surveillance scenarios and engaging the authorities.
NRA, SRA, and Other Important Guidelines for Market Institutions and Brokers in UAE
The UAE assesses its money laundering, terrorist financing and proliferation financing risk at the national level, and market institutions and brokers must align their business-wide and enterprise-wide risk assessments with those findings.
UAE PF National Risk Assessment 2026
The UAE Proliferation Financing National Risk Assessment 2026 examines the country’s exposure to the financing of weapons of mass destruction and the evasion of targeted financial sanctions under United Nations resolutions on North Korea and Iran. Prepared in response to the Financial Action Task Force revised Recommendation 1, it rates the securities sector low for proliferation financing in both the mainland and the financial free zones, and sets an overall country risk of medium-high. It clarifies where proliferation risk concentrates and how screening and due diligence on parties to trades and settlements should respond at an exchange, broker or depository.
UAE ML and TF National Risk Assessment 2024
The UAE Money Laundering and Terrorist Financing National Risk Assessment 2024 is the country’s second such assessment, prepared using the World Bank methodology and drawing on data from 2019 to 2023. It rates the securities sector residual money laundering risk in the medium to medium-high range, reflecting the diverse activities across trading, clearing and custody, while noting that AML controls across the sector are assessed as effective. It covers both the mainland and the financial free zones. It sets the baseline that a market institution or broker should feed into its risk-based approach.
The table below summarises the residual risk ratings that a market institution or broker should reflect in its own risk assessment.
| Capital market (securities) sector residual risk | Rating |
| Money laundering and terrorist financing (NRA 2024) | Medium to medium-high, with the sector’s AML controls assessed as effective |
| Proliferation financing (PF NRA 2026) | Low in both the mainland and the financial free zones |
Alongside the national assessments, sector risk assessments, red flag guidance and typologies give market institutions and brokers the detail they need to keep their enterprise-wide risk assessment current and defensible.
CMA-Regulated Market Institutions and Brokers Sector-Specific Guidance
On top of the federal framework, the Capital Market Authority issues the rulebook chapter, guidance, notices, thematic reviews and reporting standards that market institutions and brokers must apply directly. The instruments below make up that sector-specific layer.
Federal Decree-Law No. 32 of 2025 on the Capital Market Authority
An exchange, clearing house or brokerage firm answers to the Capital Market Authority, and Federal Decree-Law No. 32 of 2025 is what created that supervisor. It establishes the Authority as successor to the Securities and Commodities Authority and as the federal regulator of securities, markets, central clearing and central depository institutions across the mainland and free zones, outside the Financial Free Zones. It defines Licensed Persons, Approved Persons and Self-Regulatory Organisations, and sets objectives spanning market integrity, investor protection and systemic risk. Article 5 grants powers to license, supervise, inspect, issue rules and regulations in carrying out its functions. For a market operator or trading member, this is the constitutional foundation of oversight.
Federal Decree-Law No. 33 of 2025 on the Regulation of the Capital Market
For a firm that runs a market, clears trades or executes orders, Federal Decree-Law No. 33 of 2025 is the substantive rulebook that says which activities need a licence. Article 3 lists them, covering market operation, central clearing, central depository and custody services, dealing, investment funds and advisory work. It bars anyone from carrying on these activities or performing approved functions without authorisation, and defines securities, issuers, foreign issuers, funds, insiders and inside information. The law restricts insider dealing and imposes prohibited dealing periods on listed persons, guarding against market abuse. It also frames how a Licensed Person is settled, restructured or liquidated.
CMA Key AML/CFT/CPF Obligations, Risks and Supervisory Observations, 2025
Addressed to Chief Executive Officers, this 2025 Capital Market Authority letter sets out the key AML, CFT and CPF obligations, emerging risks and supervisory observations that trading and settlement firms must act on. Across the 2025 cycle, the Authority ran its annual risk assessment, weighing each firm’s inherent money-laundering, terrorist-financing and proliferation-financing exposure against its nature, scale, client base, products, delivery channels and geography, guided by the FATF Recommendations and the National Risk Assessment. Onsite inspections, desk reviews, MLRO report reviews and thematic work exposed recurring deficiencies for board-led remediation. Brokers and market institutions must track reporting trends, screening outcomes and beneficial-ownership data, mindful of Article 17 enforcement.
CMA Instructions for the 2024 Annual Return AML/CFT and TFS Risk Assessment
Every licensed brokerage, exchange member and clearing participant completes an annual AML, CFT and targeted financial sanctions return, and these CMA instructions explain how. The return runs across five tabs: customer risk, products and services risk, distribution channel risk, controls and quality of mitigation, and signatories. The Authority insists on full completion, monetary values in dirhams, and country breakdowns using standard names or codes. It captures inherent risk from the investors behind trading accounts, securities business, correspondent relationships, payment forms and onboarding channels, set against controls covering the compliance officer, enhanced due diligence, trade and transaction monitoring, sanctions screening and internal audit.
CBUAE AML and CFT Guidelines for Financial Institutions, July 2023
Although issued by the Central Bank, these July 2023 guidelines are where the Capital Market Authority points its firms for detailed expectations. Built on Federal Decree-Law No. 20 of 2018 and its implementing regulation, they explain the risk-based approach, a business-wide risk assessment across customer, geographic, product and delivery-channel factors, and mitigation through internal controls and customer due diligence, including beneficial-owner identification, wire transfers and ongoing monitoring. Together they translate statutory duties, typologies and reporting obligations into benchmarks a broker, exchange or clearing house can work to that reinforce sound onboarding of trading accounts, sanctions screening of every party, and monitoring of settlement flows.
CMA Minimum Standards for the Semi-Annual AML and CTF Report, 2023
These 2023 minimum standards govern the semi-annual reports that a brokerage or market institution’s Compliance Officer and Money Laundering Reporting Officer must produce, framed under Federal Decree-Law No. 20 of 2018 and Cabinet Decision No. 10 of 2019. Firms prepare bi-annual reports for the periods ending 30 June and 31 December, review them at board level, and file a copy with the Board’s comments to the Capital Market Authority within two months of each period end. The prescribed structure runs from an executive summary through governance, the enterprise-wide risk assessment, policies, customer risk rating and due diligence, a gap analysis, action plan, findings and board approval.
CMA Implementation of Targeted Financial Sanctions, May 2022
CMA Notice 1/2022, dated 19 May 2022, directs licensed institutions to implement targeted financial sanctions under UN Security Council Resolutions 1718 (2006) and 2231 (2015), pursuant to Cabinet Resolution No. 74 of 2020. A broker, dealer or clearing member must screen every party to a financial transaction, apply enhanced due diligence to dealings linked to relevant countries, and check cross-border flows suspected of unauthorised trade in dual-use goods. A confirmed match needs a Funds Freeze Report through goAML within five business days, a potential match a Partial Name Match Report, and suspicious activity an STR to the Financial Intelligence Unit. Firms should follow Executive Office guidance and block sanctions evasion.
CMA Awareness of Cabinet Resolution No. 111 of 2022 on Virtual Assets and their Service Providers
Cabinet Resolution No. 111 of 2022 regulates virtual assets and their service providers in the UAE, setting the federal framework that runs alongside the securities regime. For an exchange, broker or depository, it bites wherever a listed product, custody arrangement or trading client touches virtual assets: it defines VASP activities, licensing and the supervisory perimeter, and drives the enhanced due diligence and reporting a market institution must apply to virtual-asset exposure. It also anchors the Authority’s own virtual-asset expectations and the UAE travel rule that follows.
CMA Thematic Review on Reliance on Third Parties, December 2021
This second CMA thematic review, dated December 2021, looked at the five firms licensed for custody of securities, all banks or local branches of foreign banks holding Central Bank licences, testing compliance with FATF Recommendation 17 on third-party reliance. Because custodians safeguard investors’ securities and cash and serve largely institutional and offshore clients, they often outsource customer due diligence. A twenty-one-question survey drew a full response: four of five used third parties, two within their group and two external, all regulated or listed and governed by service level agreements. Cost, specialist skills and technology drove the practice; ultimate due diligence responsibility stays with the custodian.
CMA Thematic Review of Targeted Financial Sanctions in the Capital Market Sector, November 2021
Brokers are the gateway through which investors reach the market, and this November 2021 CMA thematic review tested how securities brokerage firms understand and apply targeted financial sanctions, international and domestic, under Cabinet Resolution No. 74 of 2020. Rated medium-high vulnerability in the National Risk Assessment, brokers answered a twenty-nine-question survey with a ninety-six per cent response rate. Sixty-five per cent ran separate sanctions risk assessments, seventy per cent used third-party screening systems, and eighty-one per cent screened daily; one firm found, reported and froze a match in 2021. Good practice covers senior-management approval, verifying vendor coverage of domestic lists, clear reporting lines and Executive Office monitoring.
CMA AML and CFT Guidance for the Capital Market Sector, September 2021
Dated September 2021, this guidance supplements the main Financial Institutions Guidelines and states the Securities and Commodities Authority’s expectations for the firms it licenses. It reaches boards, management and staff of institutions carrying on securities activities in the UAE, read with those wider guidelines. Part 1 surveys sector typologies, including trade-based money laundering through mis-invoicing and the misrepresentation of price, quantity or quality, and cash-based laundering, with red-flag indicators. Parts 2 and 3 set out the risk-based approach, the business-wide risk assessment, and the customer, product, delivery-channel and geographical risk factors that brokers, dealers and market operators must identify, assess and mitigate.
CMA Notice 3/2021 on the Immediate Reporting Mechanism
Notice 3/2021, dated 26 July 2021, went to all licensed entities and licensed securities and commodities exchanges on the immediate reporting mechanism for firms implementing Cabinet Resolution No. 74 of 2020 on the terrorism lists and the UN Security Council Resolutions on suppressing terrorism, its financing and the proliferation of weapons of mass destruction. Citing Article 21, clause 5, it advised that goAML had been upgraded with a new feature so reports on matched names and actions taken pass directly to the Executive Office for goods subject to import and export control. Brokers, exchanges and clearing houses must update policies and put the process into effect.
CMA Notice 4/2021 on Targeted Financial Sanctions Reporting
Notice 4/2021, dated 4 August 2021, addressed all licensed entities and licensed securities and commodities exchanges on sanctions reporting, following the 26 July notice. Under Cabinet Resolution No. 74 of 2020, the Central Bank, coordinating with the Executive Office of the Committee for goods subject to import and export control, built a unified mechanism on the Financial Intelligence Unit’s goAML platform. It introduced two reports: the Funds Freeze Report for a confirmed match, requiring freezing within two business days, and the Partial Name Match Report for a potential match, requiring suspension. Firms report simultaneously to the Executive Office and Authority. These notices predate the March 2026 sanctions guidance, so current goAML filings use the renamed Confirmed Name Match Report and the Partial Name Match Report; read the older notices with that change in mind.
CMA Notice 6/2021 on the Update to High Risk Jurisdictions
CMA Notice 6/2021, dated 22 November 2021, refreshes the National Committee’s lists of High Risk Jurisdictions subject to a Call for Action and Jurisdictions under Increased Monitoring for all licensed entities and exchanges, superseding Notice 1/2021. A broker, dealer, custodian or clearing member must apply enhanced due diligence to relationships and trades touching listed countries, adopt the Recommendation 19 countermeasures for the Black List, and refresh geographic risk scoring for the investors behind trading accounts. Firms may not rely on third parties based in Black List jurisdictions, must file High Risk Jurisdiction reports through goAML, and re-evaluate measures when countries are delisted, proportionate to account risk.
SCA Board Chairman's Decision No. 21 of 2019 on AML and CFT Procedures
The SCA Board Chairman’s Decision No. 21/Chairman of 2019, issued on 8 May 2019 and effective from 7 May 2019, applied anti-money laundering, counter-terrorism financing and illegal-organisations financing procedures to the capital market. Signed by Sultan bin Saeed Al Mansouri, it required every financial entity licensed or approved by the Capital Market Authority, and its stakeholders, to comply with Federal Decree-Law No. 20 of 2018, its executive regulation under Cabinet Resolution No. 10 of 2019, and the Authority’s instructions, guidelines and circulars. It empowered the Authority to supervise and inspect firms without notice, demand information, and impose administrative sanctions on brokers, dealers and other market participants.
CMA Guidelines for Combating Money Laundering and Terrorist Financing (Chapter Five)
Chapter Five of the Capital Market Authority rulebook carries the Guidelines for Combating Money Laundering, Counter-Terrorism Financing and Funding of Illegal Organisations. It sets mandatory standards requiring each supervised firm to build a compliance programme tailored to its activities, risk profiles and controls. It defines suspicious transactions, ultimate beneficial owners and targeted financial sanctions, and directs firms to apply a proportionate risk-based approach to customer due diligence, focusing resources on higher-risk clients. It fixes board and senior-management responsibility, makes suspicious-activity reporting a legal duty, and covers the screening, record-keeping and training that brokers, exchanges and clearing houses must embed. Where Chapter Five still cites the 2018 and 2019 framework, read those references in light of Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025.
CMA AML and Financial Crimes Framework and Controls: Good and Weak Practices
Prepared by Mendy Ghaleb of the Capital Market Authority’s AML and Financial Crimes Department, this presentation contrasts good practice with common weaknesses in AML frameworks and controls. It roots expectations in Federal Decree-Law No. 10 of 2025, Cabinet Resolution No. 134 of 2025, and the beneficial-owner, terrorism-list and sanctions decisions, alongside Chapter 5 of the CMA Rulebook. Field inspections and desk analysis flag recurring failings for trading and settlement firms, such as generic business-wide risk assessments misaligned with activities, template risk-appetite statements without thresholds, and copied policies with thin board oversight. Under Article 17, the Authority may issue warnings, fines of up to AED 5,000,000, sector bans and licence revocation.
CMA Obligations to Implement the Business-Wide Risk Assessment (BWRA)
This Capital Market Authority material explains a market institution’s duty to run a Business-Wide Risk Assessment, described as a fundamental, strategic discipline underpinning an effective AML and CFT framework. The BWRA requires firms to identify, understand and assess the full range of money-laundering, terrorist-financing, targeted-financial-sanctions and proliferation-financing risks, examining client types, products, delivery channels, geographies and new technologies. It runs in three phases: planning and scoping across business units, legal entities, divisions and regions; implementation, assessing inherent risk with empirical data and designing controls; and results, defining residual risk against a risk-appetite statement with action plans. Brokers, exchanges and clearing houses must keep it dynamic and current.
CMA Thematic Review of Screening Systems
A market-wide horizontal assessment, this CMA thematic review examined name and transaction screening across the UAE capital market sector under Federal Decree-Law No. 10 of 2025 and the FATF standards. The Authority tested forty-six screening systems at twenty-six Licensed Financial Institutions using control, variation and clean datasets covering United Nations and UAE sanctions lists. Systems were widely embedded across brokerage, market and custody onboarding and monitoring and caught clear matches well, but performance varied under complex scenarios such as spelling differences and Arabic-Latin transliteration. Elevated alert volumes signalled tuning opportunities. Supervisory expectations stress calibration, governance, management information, defined metrics such as false positive rates, and continuous optimisation.
CMA Questions and Answers on the National Risk Assessment
These CMA questions and answers show how a trading or settlement firm should align its Enterprise-Wide Risk Assessment with the 2024 National Risk Assessment. Brokers, dealers, exchanges and clearing houses must map NRA typologies to their business, such as onboarding offshore special purpose vehicles, layering through securities trading, weak beneficial-owner documentation, and the misuse of nominee structures and shell companies. Even low-risk firms must review the NRA, document its relevance and reassess annually. The Authority expects an audit trail: a date-stamped updated assessment post 2024 NRA, revised onboarding, screening and third-party reliance policies, training logs, board minutes and a gap analysis. Firms must reflect changes in the annual AML Return and evidence real implementation.
CMA Circular on the Examination Observations Report
This CMA circular reports examination observations drawn from firms’ annual AML/CFT and sanctions risk assessment returns, judged under a risk-based approach against Federal Decree-Law No. 20 of 2018 and Cabinet Decision No. 10 of 2019. The Authority found common shortcomings: outdated governance policies, weak testing of sanctions controls, incomplete risk assessments, gaps in customer due diligence and beneficial-ownership understanding of the investors behind accounts, incomplete sanctions programmes missing the eight essential components, and poor suspicious-transaction procedures. Firms should remediate, involve the board and auditors, and maintain proper oversight. Non-compliance may trigger enforcement, including administrative penalties.
UAE Virtual Assets Travel Rule
The UAE Virtual Assets Travel Rule reaches virtual asset service providers across the federal, emirate and free-zone space, requiring originator and beneficiary information to travel with virtual-asset transfers. A market institution or brokerage that deals in or arranges virtual-asset products, or holds them in custody, uses it to understand the information that must accompany transfers and the risk-based and enhanced due diligence expected. It brings the UAE into line with the FATF travel-rule standard and shapes how a trading and settlement business documents and screens virtual-asset movements.
CMA Chapter Five Outreach
Chapter Five Outreach explains the Authority’s Chapter Five Regulations for combating money laundering, terrorism financing and the financing of illicit organisations in plain, presentation form. It walks brokers, exchanges and clearing houses through the mandatory standards, their grounding in federal AML law, and how the Authority expects them to be applied in daily trading and settlement work. As an outreach companion to the binding Chapter Five guidelines, it is a practical reference for onboarding trading accounts, monitoring activity and reporting across the securities sector.
CMA and FIU Joint Awareness Session on Suspicious Reporting Effectiveness
Delivered by the Capital Market Authority’s AML and Financial Crimes Department with the Financial Intelligence Unit, this joint session focuses on how effectively market institutions and brokers file suspicious reports. It restates the key legislation, the obligations of financial institutions and the internal controls and governance the Authority expects, then presses on report quality: filing complete, timely and well-reasoned suspicious transaction and activity reports through goAML rather than defensive or low-value submissions. Brokerages and exchanges get a sharper picture of what good reporting on trade and settlement suspicions actually looks like.
CMA Examination Observations, Appendix of Detailed Findings
This appendix accompanies the CMA and Securities and Commodities Authority examination observations, gathering the detailed findings behind the headline review. Area by area, it records the weak and better practices inspectors saw across trading and settlement firms, from governance and risk assessment to sanctions screening and reporting. Read against your own programme, it doubles as a self-assessment checklist for a broker, exchange or clearing house, flagging the specific control gaps the regulator has already penalised in the sector.
Core AML Obligations for Market Institutions and Brokers at a Glance
A CMA-regulated market institution or broker is expected to run a complete, risk-based AML programme. In practice that means a business-wide risk assessment that reflects the firm activities, clients, products and channels; customer due diligence at account opening and admission, with enhanced measures for higher-risk clients and verification of the beneficial owners behind corporate, nominee and omnibus accounts; ongoing monitoring of trading, settlement and funding for unusual patterns; sanctions screening of clients and every party to a trade against the UAE Local Terrorist List, the United Nations Consolidated List and other applicable sanctions lists, with immediate freezing and reporting on a match; a qualified compliance officer and money laundering reporting officer with board-level support; suspicious transaction and activity reporting through goAML without tipping off; record keeping; staff training; and the annual and semi-annual returns the Capital Market Authority requires. Boards and senior management own the framework, and the Authority tests it through returns, examinations and thematic reviews.
Expert Tip:
For a trading business, the single most tested control is sanctions screening at the point of execution and settlement. Screen not only the account holder but every party to a trade, including counterparties, beneficial owners and, where relevant, the ultimate recipients of securities and cash, against the UAE Local Terrorist List and the United Nations Consolidated List. Build screening into onboarding and into the trade and settlement flow so that a match triggers an immediate freeze and report, and keep evidence of the screening you ran. This is where examinations and thematic reviews most often find gaps.
Conclusion
For market institutions and brokers, the AML picture is a clear chain: they are financial institutions under Federal Decree-Law No. 10 of 2025, the Capital Market Authority supervises them, and the full stack of the Decree-Law, its Executive Regulations, the sanctions framework, UAE FIU reporting through goAML, and the Authority’s own rulebook and guidance applies to them.
The risk concentrates where trading businesses are most exposed, in onboarding, beneficial ownership, source of funds, sanctions screening and surveillance of execution and settlement.
A firm that grounds its programme in the instruments set out above, keeps its risk assessment current, and reports promptly and accurately through goAML is well placed to meet both the letter and the intent of the UAE regime.
For the federal framework that sits above this sector regime, see our guide to anti-money laundering laws in the UAE.
Disclaimer: This guide is for general information only and does not constitute legal advice. Market institutions and brokers should confirm their obligations against the latest UAE legislation, Capital Market Authority rules, UAE FIU guidance, Executive Office for Control and Non-Proliferation guidance, and professional advice for their specific licence, activities, clients, products, and risk profile.
Frequently Asked Questions
Which market institutions and brokers are subject to AML rules in the UAE?
Licensed securities and commodities exchanges, clearing houses, settlement systems and central depositories, and brokerage firms, broker-dealers, dealers, market makers and trading members supervised by the Capital Market Authority outside the DIFC and ADGM are financial institutions under Federal Decree-Law No. 10 of 2025 and must run a full AML programme. Entities in the DIFC and ADGM follow the separate DFSA and FSRA regimes.
How does a broker register and report on goAML?
The firm registers as a reporting entity on the UAE FIU goAML portal, nominates a compliance officer and an MLRO as registered users, and files under the correct report type: an STR where there is suspicion of money laundering, an SAR for other suspicious activity, and the fund-freeze and partial-name-match reports where a sanctions hit arises. Reports must be filed without delay once suspicion is formed, supported by the underlying trade, account and screening records, and the firm must not tip off the customer. Registration details and the filing walkthrough are in our goAML registration guide.
Who supervises AML compliance for brokers and exchanges outside ADGM and DIFC?
The Capital Market Authority, established under Federal Decree-Law No. 32 of 2025 as the successor to the Securities and Commodities Authority, is the AML and CFT supervisor for market institutions and brokers in the mainland and the commercial free zones. It sets the rulebook chapter, issues guidance and notices, collects AML returns, runs examinations and imposes penalties. The Central Bank does not supervise these firms.
What AML controls are expected from a brokerage firm?
A brokerage firm is expected to run a business-wide risk assessment, design AML/CFT/CPF policy, controls and procedures, carry out customer due diligence and beneficial owner checks at account opening, apply enhanced measures to higher-risk clients, verify source of trading and margin funds, screen clients and counterparties against sanctions lists, monitor trading and settlement for unusual patterns, appoint a compliance officer and MLRO, report suspicious activity through goAML, with registration and reporting mechanics set out in our goAML registration guide, keep records, train staff, and file the Capital Market Authority annual and semi-annual returns.
How should market institutions and brokers treat exposure to virtual asset service providers?
Virtual asset trading and service provision sit under a separate framework rather than this securities regime. Market institutions and brokers should still identify and manage exposure to virtual asset providers, apply the relevant joint guidance and the travel rule where the activities involve virtual asset flows, and treat dealings with unlicensed virtual asset providers as a higher-risk factor. The Capital Market Authority has also issued its own virtual assets framework, which a firm should track where relevant.
Do market institutions and brokers need a business-wide risk assessment?
Yes. The Capital Market Authority requires supervised firms to implement a business-wide risk assessment, and the federal framework requires an enterprise-wide risk assessment. That assessment should reflect the firm’s own activities, client types, products, delivery channels and geographies, align with the national and sector risk assessments, and be kept current and defensible, because the Authority tests it through returns and examinations.
Are older SCA AML notices still relevant now that the CMA has replaced the SCA?
Yes. The notices, decisions and guidance issued under the former Securities and Commodities Authority remain in force until they are replaced. A market institution or broker should continue to apply instruments such as the SCA Board Chairman decision and the 2021 notices, reading any references to the older 2018 and 2019 framework in light of Federal Decree-Law No. 10 of 2025 and its Executive Regulations.
What are the penalties for AML breaches by a CMA-regulated broker or market institution?
Exposure runs on two tracks. The Capital Market Authority can impose administrative measures on the firm and its officers under Article 17 of Federal Decree-Law No. 10 of 2025, from warnings and remedial directions to fines of AED 10,000 to AED 5,000,000 per violation, restrictions on activity, suspension or cancellation of the licence and removal of approved persons, and it publishes enforcement outcomes. Separately, the money laundering, terrorist financing and proliferation financing offences carry criminal liability: Article 26 sets imprisonment of one to ten years and a fine of AED 100,000 to AED 5,000,000 for money laundering, and Article 27 exposes a legal person to a fine of AED 5,000,000 to AED 100,000,000. Failure to report a suspicious transaction is itself an offence under Article 28, not merely a supervisory breach.
What does the Capital Market Authority look for in an examination?
The Authority tests whether the firm risk assessment is genuine and current, whether customer due diligence and beneficial owner checks are complete, whether sanctions screening and immediate reporting work in practice, whether monitoring detects unusual trading and settlement, and whether the compliance officer and MLRO have the standing and resources to do the job. Its examination observations and thematic reviews set out the good and weak practices it has seen.
How is money laundered through a brokerage or exchange account?
Placement is the funding step: an account funded from third-party, corporate or nominee sources whose link to the client is unclear. Layering is the trading itself, and it is where a broker sees the activity first: rapid in-and-out trades with no economic rationale, matched or offsetting trades between related accounts, wash trading in illiquid stocks, mirror trades across two custodians, and heavy use of omnibus accounts that obscure the underlying beneficial owner. Integration is the withdrawal of apparently clean trading proceeds to a bank account or a further investment. Trade surveillance and settlement monitoring should be calibrated to the layering stage, and unexplained patterns escalated to the MLRO for a goAML filing decision.
Need help building or reviewing your market institution or brokerage AML programme?
Get expert guidance to strengthen your AML programme, manage regulatory requirements, and build a robust compliance framework for your market institution or brokerage.
Share via :
About the Author
Pathik Shah
FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)
Pathik is an ACAMS-certified AML consultant specialising in governance, risk, and compliance for regulated entities in the UAE. He brings over 28 years of experience, with 1,000+ hours of AML training and 200+ advisory engagements across DNFBPs, VASPs, and FIs. He supports businesses in aligning with AML/CFT requirements from the CBUAE, DFSA, MoET, MoJ, VARA, CMA, FSRA, and FATF. Known for translating complex regulations into audit-ready procedures, Pathik enables operational clarity and compliance readiness.
Reach Out to Pathik