AML/CFT Policy, Controls, and Procedures Documentation in UAE
An AML/CFT policy and procedures manual is the written framework, approved by senior management, that sets out how your business prevents, detects, and reports money laundering, terrorism financing, and proliferation financing under UAE law. Federal Decree-Law No. 10 of 2025 and its Executive Regulations in Cabinet Resolution No. 134 of 2025 make this documentation a legal obligation for every financial institution, DNFBP, and VASP in the UAE. We draft that manual for you, built on your actual risks, and aligned article by article with the current law.
The stakes changed on 14 October 2025. The new AML law repealed the 2018 framework [Federal Decree-Law No. 10 of 2025, Article 41], introduced a standalone proliferation financing offence, lowered the evidentiary bar to an objective “knew or ought to have known” standard, and gave supervisors the power to fine each compliance failure between AED 10,000 and AED 5,000,000 [Federal Decree-Law No. 10 of 2025, Article 17]. If your manual still cites Federal Decree-Law No. 20 of 2018, it is now evidence of non-compliance, not proof of it.
Complete. consistent. Accurate.
Get an AML/CFT policy and procedures manual written for your business, your sector, and the law as it stands today.
What Is an AML/CFT Policy and Procedures Manual?
In legal terms, it is the set of internal policies, controls, and procedures your business uses to manage and mitigate its money laundering, terrorism financing, and proliferation financing risks.
UAE law requires these to be approved by senior management, proportionate to the nature and size of your business, monitored for effectiveness, and reviewed and updated on an ongoing basis [Cabinet Resolution No. 134 of 2025, Article 5(2)(a)]. Your bank, your auditor, or your supervisor may call it an anti-money laundering policy, an anti-money laundering policies and procedures manual, or simply your AML compliance manual, your AML policy, AML programme manual, controls, and procedures (PCP) manual, or your AML/CFT policy or AML/CFT/CPF policy. Whatever the label, this is the document they are asking for.
The three words in the name do different jobs.
The AML policy
states what your business commits to and who is accountable.
The Controls
are the checks that enforce it: screening, approvals, transaction thresholds, escalation triggers.
The AML procedures
tell your staff exactly what to do, step by step, when they onboard a customer, hit a sanctions match, or need to file a report through goAML.
One point most firms miss: a manual that does not match how your business actually runs hands the inspector written proof that you are not following your own rules.
What is an AML policy and procedures documentation service in the UAE?
An AML policy and procedures service in the UAE prepares the written AML/CFT/CPF framework a regulated business must maintain by law, tailored to its licence, sector and supervisor. When an inspection or review begins, three things are requested before almost anything else: your AML policy and procedures, your business risk assessment, and your AML/CFT compliance officer’s appointment. Together, they answer the question a supervisor keeps returning to: whether you understand the money laundering, terrorism financing, and proliferation financing risks your business carries and are controlling them in a way you can evidence. Our AML policy documentation service exists to make sure the answer is yes.
Why generic AML policy templates and compliance manuals are not enough?
An AML policy template downloaded from the internet, or an AML compliance manual built for a different sector, tends to describe controls you do not operate, name roles you have not filled, and set thresholds that do not match how your customers actually pay. That gap is exactly what a trained inspector looks for, and it is the most common reason a business receives a finding it could have avoided.
Supervisors expect an entity-specific framework built on your own business risk assessment, not a generic document (MoET Guidelines for DNFBPs, September 2025). We prepare AML programme documentation that reflects your licence, customers, products and supervisor, grounded in the current law and written so your team can put it into practice from day one.
The UAE Laws Your AML Policy Documentation Must Follow
Every AML/CFT manual we draft is mapped to the specific legal instruments that govern your obligations. These are the laws we write your documentation against:
| Legal Instrument | What It Does | What It Means for Your Manual |
|---|---|---|
| Federal Decree-Law No. 10 of 2025 | The primary AML/CFT/CPF statute, in force 14 October 2025. Repeals FDL No. 20 of 2018 (Article 41). Sets preventive obligations (Article 19), supervisory powers (Article 16), administrative penalties of AED 10,000 to AED 5,000,000 per violation (Article 17), and criminal penalties (Article 26). | Your AML policy, controls, and procedures manual's core obligations, governance duties, and penalty exposure it protects you from all originate here. It also adds proliferation financing as a standalone offence and applies the objective knowledge standard. |
| Cabinet Resolution No. 134 of 2025 | The Executive Regulations, effective 14 December 2025, replacing Cabinet Decision No. 10 of 2019. Defines Risk (Article 2), DNFBPs (Article 3), and VASPs (Article 4); sets risk assessment and internal policy duties (Article 5), CDD rules and thresholds (Articles 6 to 9), and beneficial ownership identification (Article 10). | This is the operative code your AML procedures must implement: who is in scope, when CDD triggers, how the 25% beneficial ownership test works, and what your senior-management-approved policies must contain. |
| Cabinet Decision No. 74 of 2020 | The targeted financial sanctions (TFS) framework implementing UN Security Council and UAE Local Terrorist List obligations, including screening, freezing without delay, and reporting to the Executive Office (EOCN). | Your sanctions screening procedure, freeze protocol, and reporting workflow are drafted to this instrument. |
| Federal Law No. 7 of 2014 | The Combating Terrorism Crimes law that defines terrorist acts, organisations, and offences cross-referenced by the AML framework for terrorism financing. | Anchors the CFT definitions and escalation rules in your manual. |
| Cabinet Resolution No. 71 of 2024 | The administrative penalty schedule for DNFBP violations: 41 listed violations with fines from AED 50,000 to AED 1,000,000, doubling for repeat offences. | The exact violations your documentation must prevent. We map each relevant violation to a control in your manual. |
| Cabinet Resolution No. 109 of 2023 | Real Beneficiary Procedures: the beneficial ownership register, the 25% threshold, and update deadlines. | Your BO identification and register maintenance procedures are drafted to this resolution alongside Article 10 of CR 134/2025. |
| Sectoral Guidance Issued by Supervisory Authorities | Sector-specific supervisory expectations are enumerated in the guidance issued by the CBUAE, CMA, DFSA, FSRA, MoET, MoJ, ADGM RA, and VARA. | AML policy manual must incorporate the supervisory expectations to remain compliant. |
Is an AML policy mandatory in the UAE?
Yes. Under Article 19 of Federal Decree-Law No. 10 of 2025, every financial institution, designated non-financial business or profession and virtual asset service provider must apply a risk-based approach and maintain documented internal policies, controls and procedures, approved by senior management. Cabinet Resolution No. 134 of 2025, the Executive Regulations, then sets out what each of those controls must cover, from customer due diligence and beneficial ownership through to targeted financial sanctions, monitoring, reporting and record-keeping.
This is not guidance you can take or leave. A supervisory authority can act where the framework is missing or inadequate, and the cost of that is set out in What Non-Compliance Costs in the UAE below. The safer and far cheaper position is a framework that is right before anyone asks to see it.
Not sure your current manual covers all of this?
Send us your existing policy and we will map it against FDL 10/2025 and CR 134/2025 and tell you exactly where the gaps are, with no obligation.
Who Must Maintain AML Policies and Procedures in the UAE?
The obligation applies to three categories of regulated entities, each defined in the Executive Regulations:
Banks and Financial institutions
Banks, lenders, finance companies, exchange houses, insurers, payment providers, capital market firms, and other licensed financial institutions carrying out any of the fourteen financial activities listed in the law.
[Cabinet Resolution No. 134 of 2025, Article 2]
DNFBPs
Real estate brokers and agents; dealers in precious metals and stones; lawyers, notaries, and independent accountants when executing financial transactions for clients; company and trust service providers; and commercial gaming operators.
[Cabinet Resolution No. 134 of 2025, Article 3]
VASPs
Virtual asset service providers conducting exchange, transfer, safekeeping, or issuance-related activities, now brought fully into the AML framework.
[Cabinet Resolution No. 134 of 2025, Article 4]
Your supervisor depends on your sector, and the regulator routes above name the authority for each. Suspicious transaction reports from all of them flow to the UAE Financial Intelligence Unit through the goAML portal, and targeted financial sanctions matters go to the Executive Office for Control and Non-Proliferation (EOCN). Your AML/CFT/CPF policy manual must name your supervisor, reflect its guidance, and evidence your goAML registration.
AML Consulting Engagement Process
AML Consulting engagement process with us includes structured, risk-based stages which are designed to align UAE AML regulatory requirements with operational realities on the ground and support auditable AML compliance, balancing business growth while meeting supervisory expectations.
Customer due diligence
Identification and verification before or during onboarding, for financial institutions, CDD for occasional transactions of AED 55,000 or more and wire transfers of AED 3,500 or more, an AED 3,500 occasional-transaction threshold for VASPs, and ongoing monitoring across the relationship. Your KYC controls and CDD policy and procedures live here.
[Cabinet Resolution No. 134 of 2025, Articles 6 to 9]
Senior-management approved policies and controls
Internal policies, controls, and procedures proportionate to the nature and size of your business, with implementation monitored and effectiveness assessed to evidence the governance. This includes your top-level AML policy statement and the systems and controls that sit beneath it.
[Cabinet Resolution No. 134 of 2025, Article 5(2)]
Enhanced due diligence
Documented EDD triggers and measures for high-risk customers: source of funds and wealth checks, more frequent reviews, closer transaction scrutiny, and senior management approval to start or continue the relationship.
[Cabinet Resolution No. 134 of 2025, Article 5(2)(c)]
Risk Assessment
How your firm identifies, understands, and documents its ML/TF/PF risks across customers, geographies, products, and delivery channels, taking into account the National Risk Assessment, with the study retained and updated on an ongoing basis.
[Cabinet Resolution No. 134 of 2025, Article 5(1)]
Beneficial ownership
Identification of every natural person holding 25% or more ownership or control, with the legal fallback cascade to persons exercising control and then to senior management, aligned with your BO register duties.
[Cabinet Resolution No. 134 of 2025, Article 10; Cabinet Resolution No. 109 of 2023]
PEP procedures
Screening for politically exposed persons, their family members, and close associates, with risk-rated approval and monitoring rules.
[Cabinet Resolution No. 134 of 2025, Article 16]
Sanctions and TFS compliance
Screening against UN and UAE Local Terrorist Lists, freezing without delay, prohibition of dealings, and reporting to the Executive Office.
[Cabinet Decision No. 74 of 2020]
Proliferation financing controls
Enhanced internal controls where high PF risks are identified, with documented records of measures taken and periodic control reviews. This is new territory for most UAE AML policy manuals.
[Cabinet Resolution No. 134 of 2025, Article 5(4)]
STR reporting and tipping-off
Internal escalation, the compliance officer’s decision process, filing through goAML under Article 18 of Federal Decree-Law No. 10 of 2025, and strict confidentiality rules that prohibit informing the customer. Beyond STR, SAR, CNMR, PNMR, HRC, and HRCA, your procedures should cover the sector reports your supervisor expects, such as REAR for real estate and, where applicable, DPMSR for dealers in precious metals and stones.
[Cabinet Resolution No. 134 of 2025, Article 19]
Compliance officer and governance
Appointment of a compliance officer at management level with independence in decision-making and appropriate competence, plus defined senior management oversight duties and periodic reporting to senior management.
[Cabinet Resolution No. 134 of 2025, Article 22]
Record keeping
Retention of CDD records, transaction records, and supporting analysis for a minimum of five years, extendable where investigations, wire transfer rules, or supervisory and judicial processes require it, with beneficial ownership records updated within fifteen working days of any change. All records must remain accessible and retrievable.
[Cabinet Resolution No. 134 of 2025, Article 25]
Training and independent review
Role-based AML/CFT/CPF training with attendance records your inspector can test, and periodic independent audit of the programme itself.
[Cabinet Resolution No. 134 of 2025, Article 21]
Simplified due diligence
Simplified due diligence. Where the risk genuinely allows it, applied only on a documented basis and never where the risk profile says otherwise.
[Cabinet Resolution No. 134 of 2025, Article 5(3)]
Reliance on a third party
The conditions under which you may rely on another party’s customer due diligence, and the records you must still hold yourself.
[Cabinet Resolution No. 134 of 2025, Article 20]
Countermeasures for high-risk countries
Enhanced measures, and countermeasures where directed, for customers and transactions connected to high-risk jurisdictions.
[Cabinet Resolution No. 134 of 2025, Article 23]
Risk assessed. Risk managed. Compliant.
Ask for an AML/CFT framework mapped clause by clause to FDL 10/2025 and CR 134/2025.
What Non-Compliance Costs in the UAE
The penalty framework is the strongest business case for getting your documentation right:
1. Administrative penalties
[Federal Decree-Law No. 10 of 2025, Article 17]
Choosing a UAE-focused AML Consultant helps Regulated Entities with local regulatory understanding, shaped by jurisdiction/supervisory authority-specific laws, practices across mainland and financial free zones. AML obligations are regulated by various federal authorities or free zone regulators, such as the Dubai Financial Services Authority (DFSA), the Financial Services Regulatory Authority (FSRA), the Capital Market Authority (CMA) or the Virtual Assets Regulatory Authority (VARA).
2. The DNFBP penalty schedule
[Cabinet Resolution No. 71 of 2024]
UAE-centric AML Consultants bring practical implementation experience across FIs, DNFBPs, VASPs and Capital Market participants, enabling the AML/CFT Compliance framework to reflect control measures aligned with prevailing AML laws in the UAE. UAE-focused consultants understand how regulators assess internal controls, systems, policies and procedures and remediation during inspections, thus supporting auditable AML compliance outcomes, smoother supervisory engagement, and sustained regulatory readiness across UAE supervisory authorities.
3. Criminal exposure
[Federal Decree-Law No. 10 of 2025, Articles 26 to 35]
The law prescribes imprisonment and heavy fines for money laundering, terrorism financing, and proliferation financing offences, with corporate offenders facing fines of up to AED 100,000,000 and possible dissolution.
4. Personal liability
[Cabinet Resolution No. 134 of 2025, Article 5(2)(a) Federal Decree-Law No. 10 of 2025, Article 17]
Senior management now carries explicit responsibility for approving internal policies, overseeing high-risk relationships, and monitoring programme implementation. Executives can face personal consequences where supervision failures contribute to violations.
AML policy services by UAE regulatory framework
We work across the three frameworks most UAE businesses fall under, and each has its own dedicated page.
Mainland and commercial free zones
On the mainland and in the commercial free zones, your supervisor follows your activity. Most designated non-financial businesses are supervised by the Ministry of Economy and Tourism (MoET), applying the federal law and the Ministry’s Guidelines. Banks and financial institutions are supervised by the Central Bank of UAE (CBUAE), capital market companies by the Capital Market Authority (CMA), and commercial gaming operators by the General Commercial Gaming Regulatory Authority (GCGRA). Lawyers, notaries and other legal professionals are supervised by the Ministry of Justice (MoJ). Virtual asset service providers are supervised by the Virtual Assets Regulatory Authority (VARA) in Dubai, and by either the CBUAE or the CMA outside Dubai and the financial free zones. In every case, registration and reporting run through the goAML portal.
Dubai International Financial Centre (DIFC)
Firms in the DIFC are Relevant Persons supervised by the Dubai Financial Services Authority (DFSA), and their framework follows the DFSA AML Module, including the business AML risk assessment, the MLRO regime and the annual AML return, applied alongside the federal law.
Abu Dhabi Global Market (ADGM)
Entities in ADGM are supervised under the Financial Services Regulatory Authority (FSRA) AML Rulebook, with designated non-financial businesses supervised by the ADGM Registration Authority (ADGM RA) and financial institutions by FSRA, and beneficial ownership identified to the 25% standard under the ADGM regulations.
What is included in our AML policy and procedures service?
You receive a complete, approval-ready documentation set, not a single file. It is built to be used, audited and defended, and every item is tailored to your business rather than lifted from a library.
You receive
What it does
Tailored AML/CFT/CPF policy and procedures manual
The core framework, aligned to your supervisor and sector; can also be presented as your AML compliance manual
Risk-based Approach
A documented, defensible method for risk-based approach assessing inherent risk, controls and residual risk as evidenced by the ML/FT Enterprise-Wide Risk Assessment (EWRA).
Customer risk assessment and rating model
Risk factors, ratings, overrides and the triggers that require a review
CDD, EDD, PEP and source-of-funds forms
Ready-to-use onboarding and due diligence templates
Beneficial ownership templates and registers
Aligned to the 25% standard and the register obligations
Sanctions screening and TFS procedures
Screening, match handling, freezing and escalation, with forms
Registers
Customer, supplier, employee, screening and transaction registers; SAR and STR logs; CNMR, PNMR, HRC and HRCA; sector-report tracking registers for REAR, and DPMSR and the semi-annual report template
Transaction monitoring and red-flag guidance
Sector-specific indicators and an unusual-activity review process
STR and goAML reporting workflow
Internal escalation, the MLRO decision log and the reporting register
Training plan and register, and a gap assessment with an implementation tracker
So the policy moves from document to daily practice, with a management approval pack
Compliance Calendar
AML/CFT/CPF compliance calendar highlighting various obligations and their timelines
See which documents in the set your licence actually needs
A 15-minute call is usually enough. Tell us what you are licensed for and we will confirm which parts of this set apply to you, and which you can leave out.
Our AML Policy Drafting Process
Our AML policy development work follows the same disciplined sequence for every engagement, whether you are a two-person real estate brokerage in Deira or a multi-branch exchange house. Most clients reach an operational compliance baseline within 2 to 6 weeks.
1. Risk identification and mapping
We study your Enterprise-Wide Risk Assessment, your business processes, especially every point where money or value moves, and map where launderers, terrorism financiers, or proliferation networks could exploit them. We further map everything with the National Risk Assessment and Sectoral Risk Assessment and ensure that your policy, controls and procedures counter the identified risks effectively. [Cabinet Resolution No. 134 of 2025, Article 5(1)]
2. Review of your existing AML policies
If you already have documentation, we test it against the current law and against how your teams actually work. Most manuals we review were written under Federal Decree-Law No. 20 of 2018 and Cabinet Decision No. 10 of 2019, both now repealed.
3. AML gap analysis
We walk your compliance officer and stakeholders through every shortfall we find, so you see exactly what is missing before we write a word. The section below sets out the exercise in full.
4. Customer risk model
We design how you will rate, review and re-rate customers: the risk factors, the ratings, the override rules and the triggers that force a fresh review.
5. Drafting the manual
We write your AML/CFT/CPF policy, controls, and procedures as one coherent framework: customised to your sector and supervisor, proportionate to your size, and with a named owner for every control. Each obligation carries its legal citation so your team and your inspector can trace it.
6. Registers, forms and the control matrix
We build the tools that turn the policy into daily practice: the registers, the CDD, EDD, PEP and source-of-funds forms, and a control matrix that ties each control to its owner.
7. Validation
We walk the draft through with your team to confirm it fits how the business actually runs, not how an org chart says it does.
8. Independent quality review
A second qualified reviewer checks the framework before it reaches you.
9. Senior management approval and rollout
We prepare the AML policy document for the senior management sign-off the law requires, evidence the approval, and support you in briefing the staff who will live with the manual. [Cabinet Resolution No. 134 of 2025, Article 5(2)(a)]
What information do we need from the client to design an AML policy manual?
- Trade or commercial licence, activities and supervisor
- Ownership and control structure and beneficial ownership information
- Customer, product/service, channel and geography profile
- Past transaction history and statistical information around customers, suppliers, employees and third parties
- Payment and cash profile
- Existing policies, registers and systems
- Compliance Officer and MLRO (if any) of the Company
- Any inspection findings, letters of concern or deadlines
Policy implementation, training and ongoing review
A policy that sits in a drawer fails at inspection. We support implementation with role-based training for front-line staff, the compliance officer and senior management, and we set a review cycle so the framework keeps pace with your business, the National Risk Assessment and changes in the law. Where a supervisor updates its expectations or a new circular lands, we can refresh the affected sections rather than starting again.
AML Policy Gap Analysis: Know What Is Missing Before the Regulator Does
An AML policy gap analysis compares your current policies, controls, and procedures against your risk assessment and the current legal framework, then lists every shortfall with a fix. We offer it as part of the full documentation service or as a standalone review of an existing AML programme manual.
Right now the single most common gap is legacy alignment.
AML policy documents drafted before October 2025 do not cover the standalone proliferation financing offence, the objective knowledge standard, the expanded DNFBP definition that now includes commercial gaming operators, or the tightened beneficial ownership verification rules. Mainland and free-zone supervisors alike are now examining for it.
Firms typically come to us after three triggers:
1. A supervisor's inspection notice
2. A bank requesting an updated anti-money laundering policy
3. A new regulation that the regulated entity isn’t sure their manual reflects.
Beyond the Core Manual
Alongside the package described above, and depending on your sector, we also draft:
- Precious Metals Supply Chain Policy and Global Precious Metals Code documentation aligned with OECD and LBMA requirements, for gold and jewellery businesses
- Anti-Bribery and Corruption policy to close the risk areas that sit next to money laundering
Why AML UAE: Drafting Experience You Can Verify
We are an AML consulting firm working only on AML/CFT compliance in the UAE, and policy documentation is the single thing we have delivered most often:
1000+
EWRA and AML/CFT/CPF policies and procedures delivered to UAE reporting entities
300+
successful AML compliance projects across FIs, DNFBPs, and VASPs
750+
professionals trained, across 3,000+ hours of AML/CFT/CPF training
500+
published articles, guides, and educational resources, including our widely read analyses of FDL No. 10 of 2025 and Cabinet Resolution No. 134 of 2025
The results show in delivery: DNFBP clients typically reach compliance readiness around 35% faster than the industry average; we enabled REAR reporting and trained more than 650 real estate agents for one engagement, and a recent VASP client reached full compliance, including audit-readiness, within four weeks.
The AML Policy Consultants Behind Your Manual
Your manual is drafted and reviewed by certified specialists with UAE jurisdictional experience across every supervisory authority:

Pathik Shah
CAMS, FCA, CS, CISA, DISA (ICAI), FAFP (ICAI)
Experience
28+ years
Regulatory Coverage
MoET, MoJ, CBUAE, CMA, FSRA, DFSA, VARA · AML/CFT framework design, RegTech

Jyoti Maheshwari
CAMS, ACA
Experience
11+ years
Regulatory Coverage
MoET, MoJ, CBUAE, CMA, FSRA, DFSA, VARA · AML/CFT/CPF framework, health checks

Dipali Vora
CAMS, ACS
Experience
10+ years
Regulatory Coverage
MoET, MoJ, CBUAE, CMA, FSRA, DFSA, VARA · Consulting, training, implementation

Monika Shah
CAMS
Experience
3+ years
Regulatory Coverage
MoET, MoJ, CBUAE, CMA, FSRA, DFSA, VARA · managed KYC, consulting, goAML reporting
Every obligation in your document traces to a specific article of UAE law or supervisory guidance, so your compliance officer can defend any line of it in an inspection. Every framework carries a named reviewer and a review date, and passes an independent quality review under a documented delivery and quality assurance method before it reaches you, which is what separates a tailored framework from a sold template. We are also straight about scope: what your policy must contain depends on your licence, your activities, your regulatory perimeter and your risk profile, and we will tell you plainly what you need and what you do not. And we stay engaged after delivery: training, health checks, annual reviews, and realignment when the law or your business changes.
AML policy engagement case studies and client testimonials
A law firm in UAE
The practice handles conveyancing alongside general corporate advice, so the AML policy manual had to draw a clear line between the matters that trigger DNFBP obligations and the advisory work that does not. We built the risk-based approach around client type, matter type and source of funds, sized the controls for a firm with one compliance officer rather than a compliance department, and drafted the escalation route so that no partner can overturn an MLRO decision.
A corporate service provider in ADGM
As a company and trust service provider registered with the ADGM Registration Authority, the entity sits under the FSRA AML Rulebook with the federal framework underneath it. We drafted an AML/CFT/CPF policy to the Rulebook’s terminology and structure, tested beneficial ownership to the 25% standard through the nominee and trustee arrangements the business administers, and wrote enhanced due diligence triggers for the offshore structures it actually handles rather than a generic high-risk list.
A capital market company supervised by CMA
Onboarding, custody and trade monitoring each carry a different risk profile, so the AML policy framework treats them as separate control environments instead of one process. Transaction monitoring and red-flag guidance were written around securities typologies, and the review cycle was scaled to the firm’s transaction volumes rather than defaulting to an annual refresh.
Get your AML policy and procedures right the first time
One short form, one focused conversation, and a clear plan for the framework your business needs. Fill in the form below and a CAMS-certified specialist will come back to you with the scope, the timeline and the price.
FAQs on AML Policy Documentation in the UAE
An AML policy is your business’s written commitment to prevent money laundering, terrorism financing, and proliferation financing, together with the controls and procedures that put that commitment into practice. In the UAE, it must be approved by senior management, proportionate to the entity’s risks and size, and kept current with Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025, NRA, SRA, and supervisory guidance.
Senior management. Article 5(2)(a) of Cabinet Resolution No. 134 of 2025 requires internal policies, controls, and procedures to be approved by senior management, reviewed, and updated on an ongoing basis. Supervisors expect documented evidence of that approval, such as a signed and dated policy or a board minute. Senior management approval is also required to begin or continue high-risk business relationships.
AML (anti-money laundering) targets the disguising of criminal proceeds as legitimate money. CFT (countering the financing of terrorism) targets funds flowing toward terrorist activity, whatever their origin. CPF (counter-proliferation financing) targets funds connected to weapons of mass destruction programmes, and became a standalone offence under Federal Decree-Law No. 10 of 2025. UAE law regulates all three in one framework, which is why we draft the manual as a single AML/CFT/CPF document.
Yes. Every financial institution, DNFBP, and VASP in scope of Articles 2 to 4 of Cabinet Resolution No. 134 of 2025 must establish senior-management-approved internal policies, controls, and procedures under Article 5(2). Failure is independently punishable with administrative penalties of AED 10,000 to AED 5,000,000 per violation under Article 17 of Federal Decree-Law No. 10 of 2025.
It needs realignment. Federal Decree-Law No. 10 of 2025 expressly repealed the 2018 law with effect from 14 October 2025, and Cabinet Resolution No. 134 of 2025 replaced the 2019 Executive Regulations from 14 December 2025. A pre-2025 manual will not cover the proliferation financing offence, the objective knowledge standard, the expanded DNFBP scope, or the current thresholds, and supervisors, including the ADGM FSRA and DIFC DFSA, have directed firms to update their documentation accordingly.
Most organisations reach an operational compliance baseline within 2 to 6 weeks, depending on readiness and complexity. In our standard roadmap, the approved Enterprise-Wide Risk Assessment lands in week two and the AML policy and procedures manual is designed in week three, followed by templates, training, and audit-readiness review.
Review it at least annually, and immediately after any change in the law, new supervisory guidance, a material change to your business such as new products, markets, or channels, changes in the FATF grey list or blacklist, requirements of NRA and SRA, or findings from an audit or inspection. The law itself requires policies to be reviewed and updated on an ongoing basis, and a manual with no revision history is a red flag to inspectors.
A generic template will not survive an inspection. Article 5(2)(b) of Cabinet Resolution No. 134 of 2025 requires policies, controls, and procedures to be proportionate to the nature and size of your business, with implementation monitored and effectiveness assessed. A template cannot reflect your customers, products, geographies, or delivery channels, and supervisors now test whether controls operate, not whether documents exist. We build the manual from your business risk assessment, which is the approach the law demands.
Yes. Free zone financial entities follow the FSRA and DFSA AML rulebooks layered on the federal framework, and both regulators have instructed firms to align their AML/CFT and TFS policies with FDL No. 10 of 2025 and Cabinet Resolution No. 134 of 2025. We draft an AML policy for the rulebook that governs your licence and map the federal obligations underneath it.
The AML policy states what you will do and why, in line with the law. The procedure explains how your team does it, step by step. The control is the specific check that makes sure it happens, with an owner and evidence. A regulator expects to see all three, joined up.
At least five years from the completion of a transaction or the end of the business relationship, and retrievable promptly on request (Cabinet Resolution No. 134 of 2025, Article 25).
A suitably qualified and independent person at management level, with the authority and access to carry out the role and reporting to senior management; in DNFBPs the appointment is subject to the supervisory authority’s approval (Cabinet Resolution No. 134 of 2025, Article 22; MoET Guidelines for DNFBPs, September 2025).
Achieve AML and sanctions compliance.
Put your AML/CFT policy, controls, and procedures in the hands of specialists who write them to the current law every week.