AML Regulations for CMA-Regulated Advisors and Promoters in UAE
Published On: 09/09/2026
Protect your business with reliable and effective AML strategies with AML UAE.
Last Reviewed On: 09/09/2026 | Last Updated On: 09/09/2026
Key Highlights
- Financial advisors, promoters and marketers, arrangers, introducers and placement agents fall within the definition of financial institution set by Federal Decree-Law No. 10 of 2025 and the Executive Regulations in Cabinet Resolution No. 134 of 2025.
- For AML and CFT purposes, their supervisor is the Capital Market Authority, created by Federal Decree-Law No. 32 of 2025 to take over from the Securities and Commodities Authority, and not the Central Bank.
- Across the national risk assessments, the securities sector carries a money laundering rating between medium and medium-high, its controls judged effective, while its proliferation financing exposure is marked low throughout the mainland and the financial free zones.
- Since advisors and promoters seldom take custody of assets or place orders themselves, their vulnerability sits with the people they counsel and refer, the origin of money they hear about while advising, the schemes and providers they put their name behind, and the risk of making an unlicensed provider or a fraud look respectable.
- Beyond the federal statute book, the Capital Market Authority layers on a rulebook chapter of its own, plus sector guidance, notices, thematic reviews and reporting standards, all of which an advisory or promotion programme must absorb.
- Advising on or marketing virtual assets belongs to a distinct regime and not to these securities rules, while advisory and promotion firms based in the DIFC and ADGM report to the DFSA and FSRA and fall outside this guide.
Financial advisors, promoters and marketers, arrangers, introducers and placement agents licensed by the Capital Market Authority (CMA) outside the DIFC and ADGM count as CMA-regulated advisors and promoters. Their obligations flow from Federal Decree-Law No. 10 of 2025 and the Executive Regulations in Cabinet Resolution No. 134 of 2025, the sanctions regime in Cabinet Resolution No. 74 of 2020, registration and reporting to the UAE FIU via goAML, and the Capital Market Authority rulebook, notices and reporting standards.
Financial advisors and promoters rarely touch the money, and that is exactly what makes their AML role distinctive. They recommend investments, market and promote securities and funds, and introduce clients to product providers, without executing trades or holding client assets themselves.
Their exposure is that of a gatekeeper: the clients they advise and introduce, the products and providers they lend credibility to, and the promotion that can pull investors toward a scheme. Because they operate in securities and investments, they answer to the Capital Market Authority rather than the Central Bank.
This guide sets out the AML regulations for CMA-regulated advisors and promoters in the UAE: which firms are in scope, the regulator, the full legal framework, how the national risk assessments rate the securities sector, and the controls an advisory or promotion business is expected to run. It covers CMA-licensed financial advisors and promoters outside the DIFC and ADGM.
Who is an advisor or promoter for AML purposes?
For AML purposes, this category covers firms the Capital Market Authority licenses to advise on, or promote, arrange, introduce and place securities and investment products. The types below all fall under the AML regulations for CMA-regulated advisors and promoters in the UAE. The DFSA and FSRA supervise firms established in the DIFC and ADGM, which are not covered here.
Financial advisors
Financial advisors licensed by the CMA recommend securities and investment products to clients. Their exposure runs through the client they advise, the source of the funds behind an intended investment, and the suitability and know-your-client information they gather in the course of giving advice.
Financial promoters and marketers
Financial promoters and marketers advertise and promote securities, funds and investment opportunities, increasingly online and across borders. Their risk lies in the products and providers they promote, the integrity of their communications, and the danger of drawing investors towards unlicensed or fraudulent schemes.
Arrangers and introducers
Arrangers and introducers connect clients with product providers or deals in return for a fee. Their controls centre on due diligence on the parties they introduce, the higher-risk clients or providers they connect, and referral arrangements that could move or disguise value.
Placement agents and distributors licensed in the UAE
Placement agents and distributors place securities and fund interests with investors on behalf of issuers and managers. Their exposure sits in the investors they place with, the beneficial owners behind them, and the source of the subscription funds they help bring in.
AML Supervisory Authority for Advisors and Promoters in UAE
Capital Market Authority (CMA): the AML supervisor for advisors and promoters in UAE
The Capital Market Authority is the UAE federal regulator for securities and commodities activity, established by Federal Decree-Law No. 32 of 2025 to take over the mandate of the Securities and Commodities Authority.
CMA authorises and oversees financial advisors, promoters and marketers, arrangers, introducers, and placement agents operating outside the DIFC and ADGM, and supervises them for both AML and CFT. Through its rulebook chapter, it dictates how firms build their compliance programmes, publishes sector guidance, notices and thematic reviews, collects annual and semi-annual AML returns, conducts examinations, and has the power to levy administrative penalties. For its supervisory expectations, an advisory or promotion firm looks to the Authority rather than the Central Bank and applies that rulebook alongside the federal AML laws.
From the SCA to the CMA: what changed for advisors and promoters
The Capital Market Authority took over the mandate of the Securities and Commodities Authority under Federal Decree-Law No. 32 of 2025. The supervisor’s name changed; the regulated perimeter did not. In practice, an advisory or promotion firm should treat every SCA-era instrument, the Chapter Five rulebook guidelines, SCA Board Chairman’s Decision No. 21 of 2019 and the 2021 and 2022 notices, as continuing to apply unless it has been repealed, superseded or replaced, and should verify the status of each one rather than assume it survives. Licence conditions, filing routes and the goAML reporting channel carry over. Where an older instrument refers to the SCA, read the reference as the CMA.
UAE FIU and goAML
Each advisor and promoter within scope must complete goAML registration with the UAE Financial Intelligence Unit and lodge its reports on the goAML platform. Housed within the Central Bank under Federal Decree-Law No. 10 of 2025, the UAE FIU receives suspicious transaction reports, suspicious activity reports, and any further filings the framework requires, and may request additional detail and share intelligence with supervisors and law enforcement. For a firm that advises and introduces, goAML carries to the authorities the warning signs it meets: a client who does not add up, an investment whose money has no clear origin, a name that hits a sanctions list, or a marketing push that channels investors into an unlicensed scheme. Enrolling, filing on time, and filing accurately are matters of law, and both the Authority and the Unit weigh how good those submissions are.
CMA enforcement and unlicensed activity
The Authority can levy administrative penalties on the firms it supervises, and Article 17 of Federal Decree-Law No. 10 of 2025 sets the administrative fine for an AML violation at between AED 10,000 and AED 5,000,000 for each breach. Unlicensed activity sits at the centre of that enforcement interest.
Article 3 of Federal Decree-Law No. 33 of 2025 fixes which financial activities need a CMA licence, so a firm that advises, arranges, promotes or places outside that licence is carrying on a regulated activity without authorisation.
The exposure runs the other way too. A licensed promoter that markets an unlicensed provider’s product lends its own authorisation to that provider, which is the precise risk the March 2022 joint guidance on unlicensed virtual asset providers was issued to address. Before promoting or introducing a product, verify the regulatory status of the product, the fund, and the provider; keep evidence of that check; and treat a request to market an unlicensed provider as a reportable concern rather than a commercial decision.
AML Legal Framework Applicable to Advisors and Promoters in UAE
The rules that bind a CMA-regulated advisor or promoter stack up in four tiers: the federal AML statutes and their executive regulations covered in the guide to AML laws in UAE, the guidance addressed to every reporting entity, the national and sector risk assessments, and the Capital Market Authority’s own rulebook and guidance, all of which build on the capital market firms AML guide. Each instrument set out below is unpacked for what it asks of an advisory, promotion, arranging or placement business day-to-day.
Federal AML Laws and Executive Regulations Applicable to Advisors and Promoters in UAE
These are the core federal instruments every advisor and promoter builds its programme on.
Federal Decree-Law No. 10 of 2025 on AML, CFT and CPF
Every recommendation an advisor puts to a client, and every fund or product a promoter markets, answers to Federal Decree-Law No. 10 of 2025, the statute anchoring the UAE regime. It defines money laundering, its predicate offences, suspicious transactions and targeted financial sanctions, and confirms these can be committed through digital channels, including online promotion. It creates, inside the Central Bank, the Financial Intelligence Unit as the central agency for suspicious transaction reports, able to seek more detail and, via the Head of the Unit, to impose suspension and freezing. For an advisor or promoter, it brings supervisory oversight, penalties and the duty to spot, report and back enforcement.
Cabinet Resolution No. 134 of 2025, the Executive Regulations
Cabinet Resolution No. 134 of 2025 issues the Executive Regulations of Federal Decree-Law No. 10 of 2025, converting broad principles into the working rulebook an advisor or promoter applies each day. It widens the defined terms to include beneficial owner, wire transfers, senior management and reasonable measures, and confirms that advisory work, arranging and funds transfers sit within the scope. For an advisory or promotion firm, it fixes the core duties: a risk-based approach, due diligence on the clients it advises and introduces, verification of beneficial owners standing behind corporate investors, ongoing monitoring of the relationships it services, and internal policies approved by senior management.
Cabinet Decision No. 109 of 2023 on beneficial owner procedures
A corporate investor an advisor onboards, or an institutional subscriber a promoter introduces, has a real person behind it, and Cabinet Decision No. 109 of 2023 governs how that individual is identified. It sets the beneficial owner rules for legal persons across the United Arab Emirates, treating the real beneficiary as the individual who ultimately owns or controls the entity, directly or up an ownership chain. Beneficial owner verification is therefore a front-of-onboarding control for any corporate investor. Such entities must obtain, keep and disclose accurate ownership data, flag nominee directors, and bring the register current within fifteen days of a change. It applies onshore and in the commercial free zones, while the DIFC and ADGM keep their own regimes.
Cabinet Resolution No. 132 of 2023 on penalties for beneficial owner violations
The penalties behind the beneficial owner regime come from Cabinet Resolution No. 132 of 2023, enforcing the procedures under Cabinet Decision No. 109 of 2023. Under an annexed schedule, the registrar may fine a legal person that keeps inaccurate registers or withholds required information, without prejudice to other sanctions under that principal statute. Sanctions climb with repetition: a third breach lets the registrar suspend the trade licence and shut the premises until it is settled and corrected. So an advisor or promoter should press corporate investors to keep ownership records current.
Cabinet Resolution No. 74 of 2020 on terrorist lists and UNSC resolutions
Screening the investors an advisor recommends, and the parties a promoter introduces, begins with Cabinet Resolution No. 74 of 2020. It sets out how the United Arab Emirates operates the terrorist lists and implements United Nations Security Council sanctions covering terrorism, its financing and proliferation. The Decision lays out a local Cabinet list, sets out how designation, listing and de-listing work, and requires assets to be frozen without delay, within twenty-four hours. For advisors and promoters, it is the spine of screening. Such firms register on the Executive Office website, screen prospective investors, clients, beneficial owners and referral partners against the UAE sanctions list and the United Nations Consolidated List continuously, freeze any match without notice, and notify the supervisor promptly.
Federal Law No. 7 of 2014 on combating terrorism crimes
An advisor’s or promoter’s controls exist to catch conduct criminalised by Federal Law No. 7 of 2014 on Combating Terrorism Crimes. This statute defines terrorist offences and their punishments, naming concepts such as terrorist purpose, terrorist crime, terrorist organisation and terrorist person, with sentences reaching life imprisonment and, in defined cases, death. What matters most to an advisory business is its handling of terrorism financing: it criminalises providing, collecting or holding funds for terrorist purposes and covers freezing suspect funds at financial institutions. Because the wider regime defines terrorist acts by pointing to this law, firms that advise and introduce use it to grasp what their screening targets.
Too Many Instruments to Track Manually?
Between federal law, TFS guidance, and CMA notices, keeping your fund's compliance programme current is a full-time job. We help investment managers map every obligation to a working control.
AML Guidance Applicable to All Reporting Entities
Sitting above the primary legislation, the UAE Financial Intelligence Unit, the Executive Office for Control and Non-Proliferation and the sector supervisors publish guidance and typologies binding on all reporting entities, advisors and promoters among them.
UAE FIU Regulation No. 1 of 2026 on Suspension and Freezing Powers, April 2026
When suspicious funds are at risk of being transferred or dissipated, UAEFIU Regulation No. (1) of 2026 provides a framework for postponing or suspending transactions and freezing funds. Grounded in the AML/CFT Decree-Law and Executive Regulation, it deals with holding back or suspending suspicious transactions and freezing funds, and binds reporting entities alongside existing duties. It introduces the Postponement Suspicious Transaction Report, an urgent filing where suspect funds face swift transfer, withdrawal or removal. The Head of the Unit may suspend a transaction for up to ten working days and freeze funds for up to thirty. For advisors and promoters, it protects investor money fast.
UAE FIU Strategic Analysis Report on Human Trafficking, April 2026
Dated April 2026, the UAE FIU Strategic Analysis Report on Human Trafficking studies the laundering and money movements linked to trafficking, built on suspicious transaction and activity reports lodged with the Financial Intelligence Unit. It lays out objectives, methodology and scope, then covers the principal kinds of exploitation. Its findings track how trafficking proceeds are laundered and merge with other criminal ventures. It profiles subjects from organised crime groups and money mules to foreign politically exposed persons, and frames indicators around customer profile, behaviour, account and transaction patterns, and due diligence. For an advisor or promoter, it sharpens the suitability and source-of-funds questions asked during advice.
Guidance on Targeted Financial Sanctions for Financial Institutions, DNFBPs and VASPs, March 2026
This guidance from the Executive Office for Control and Non-Proliferation, first issued in January 2021 and amended most recently in March 2026, explains what the sanctions framework asks of an advisor or promoter. It sets out four duties: enrolling in the Executive Office’s Notification Alert System; screening clients against the UAE Local Terrorist List and the United Nations Consolidated List; freezing assets at once and keeping them from designated persons; and reporting the steps taken. The March 2026 revision rebrands the Funds Freeze Report as the Confirmed Name Match Report and treats weekend screening as relevant to cross-border promotion.
Joint Guidance on the Compliance Officer and MLRO, 2026
An advisor or promoter needs a compliance officer with real authority, and this 2026 joint guidance from the UAE Supervisory Sub-Committee frames the role. It addresses the appointment, powers and duties of the Compliance Officer or MLRO across regulated sectors, reaching firms overseen by the Capital Market Authority, the Central Bank and the Ministries of Justice, Economy and Tourism. The provision calls for suitable seniority and experience, board access, operational independence and adequate resources, clarifying for an advisory firm how to bring in a fit and proper officer.
FIU Strategic Analysis Report on Terrorist Financing, May 2025
Released in May 2025 by the UAE Financial Intelligence Unit, this strategic analysis of terrorist financing typologies and facilitators draws on data covering 1 January 2021 to 31 December 2024, among them suspicious transaction and activity reports filed and cases sent to authorities. It describes how terrorist financing works and charts typologies such as moving and hiding funds through corporate networks, financial institutions, high-value goods, trade-based methods and real estate. It examines facilitators, from money mules and corporate nominees to designated persons, family members and professional service providers, ending with indicators. These indicators sharpen the questions asked on suitability and an investor’s source of wealth.
Federal Decree-Law No. 6 of 2025 on the Central Bank (regulatory background)
Federal Decree-Law No. 6 of 2025 is not an AML/CFT law. It establishes the Central Bank’s regulatory and supervisory framework for licensed financial institutions and activities. This matters at the boundary between capital-market and Central Bank-regulated activities, particularly where an advisor or promoter interacts with banks or other Central Bank-licensed financial institutions. Article 61 also identifies arranging, promoting and marketing licensed financial activities as activities subject to Central Bank licensing. For CMA-regulated firms, the relevant perimeter must therefore be considered alongside the capital-market framework established by Federal Decree-Laws No. 32 and 33 of 2025.
goAML FAQs, April 2024
Version 2.1 of the goAML FAQs, dated 18 April 2024, is a question-and-answer reference published by the UAE Financial Intelligence Unit to help reporting entities work the goAML platform and its access services. It focuses on the everyday challenges of getting in: a one-time password that has expired at first sign-in, pop-up authentication that expects the system-issued username together with a Google Authenticator code, the correct login order, and recovery of a lost password. It says where each credential belongs and whom to contact when a fault persists. Easy access to the relevant regulatory information helps teams complete their reports without unnecessary delays.
PF Institutional Risk Assessment Guidance for FIs, DNFBPs and VASPs, December 2023
This December 2023 guidance sets out how a firm gauges and manages its proliferation financing exposure. It sets a methodology resting on control effectiveness, inherent risk and residual risk, and names the categories and factors a firm weighs in scoring its book. It then works through supporting measures, from onboarding and know-your-customer checks to standard and enhanced due diligence, sanctions and adverse-media screening, both transaction and ongoing monitoring, and the reporting of suspicious activity. A customer scoring questionnaire, higher-risk factors and worked examples show how a score is reached. The guidance makes proliferation financing a repeatable, reviewable discipline for supervisors.
Terrorist and Proliferation Financing Red Flags Guidance, December 2023
The Terrorist and Proliferation Financing Red Flags Guidance, refreshed in December 2023, gathers indicators to help a firm notice suspicious financing and attempts to evade targeted financial sanctions set under UN resolutions or domestic designations. It shows how sanctioned parties conceal their hand through front companies, intermediaries and renaming, useful when an advisor or promoter looks behind a corporate investor at its beneficial owners. The indicators are sorted by customer profile, account, transaction activity, and maritime and trade finance. The guidance strengthens both the client-facing team and compliance, guiding when a relationship or promoted product should prompt a report to the authorities.
Suspicious Activity and Transaction Reporting Thematic Review, January 2023
This thematic review, released in January 2023, gathers findings and expectations from the 2022 examination of licensed financial institutions and DNFBPs conducted under AML/CFT rules. Its focus is the framework for suspicious transaction and activity reporting, together with the monitoring systems that feed it, read with the standing guidance on monitoring, screening and reporting. It works through expectations, setting acceptable standards against deficient practice across governance, policies, data management, risk-based monitoring controls, case investigation and alert review, the reporting decision and the steps after it. The review is a working benchmark for testing how the firm spots and reports concerns before an inspection lands.
Counter Proliferation Financing Guideline, November 2022
The Counter Proliferation Financing Guideline, published in November 2022 by the Executive Office for Control and Non-Proliferation, supplements the broader Guidance on Targeted Financial Sanctions for DNFBPs, FIs, and VASPs, and raises firms’ awareness of proliferation financing threats. It explains what proliferation financing is, walks through its stages, and sets out the interagency mechanism, the relevant federal laws and the UAE counter-proliferation framework. The guidelines show how to weave proliferation-financing risk into its own assessment and apply mitigations: enhanced due diligence over clients and promoted products, scrutiny of shell and front companies, dual-use trade exposure and staff training. Its red flags help expose attempted sanctions evasion.
goAML Web Submission Guide, July 2022
The goAML Web Submission Guide, put out by the UAE Financial Intelligence Unit in July 2022, describes how a report reaches the FIU via goAML. It is written for a registered entity’s Compliance Officer or Money Laundering Reporting Officer, or a deputy standing in when that officer is away. It surveys the report types, among them the Suspicious Transaction Report and the Suspicious Activity Report, the latter capturing suspected activity or a transaction attempted but never completed, plus the Additional Information File, Request for Information and High Risk Country reports. The guide standardises how a concern about a client or deal is filed promptly and correctly.
Joint Guidance on Combating the Use of Unlicensed Virtual Asset Providers, March 2022
This March 2022 joint guidance from the UAE Supervisory Authorities, among them the Securities and Commodities Authority and the Central Bank, tackles providers working beyond the licensing regime. It reminds firms of their AML duties and tells the public to use only licensed entities. It wants firms to be watchful, emerging risks folded into assessments, due diligence done, clients drawn to unlicensed providers flagged, and suspicions reported. Warning signs include a missing licence, no physical presence, unrealistic promises, Ponzi structures and pressure to commit quickly. The guidance warns against lending legitimacy: marketing an unlicensed provider’s product is the very exposure it targets.
IEMS User Guide for Reporting Entities, March 2022
The IEMS User Guide for Reporting Entities, dated March 2022, is a hands-on manual from the UAE Financial Intelligence Unit for its Integrated Enquiry Management System, which handles information requests, the carrying out of public prosecutions’ decisions and other demands from authorities. It sets out sign-up and login, and points out that firms already on goAML reuse their existing credentials. It covers the dashboard, request handling and the reply-and-attachments flow, names the Admin, Maker and Checker roles, and insists on hitting deadlines and executing freeze orders immediately. The guide maps the way an authority’s enquiry about a client gets handled.
goAML Pre-Registration Guide, March 2022
The goAML Pre-Registration Guide, from the UAE Financial Intelligence Unit in March 2022, sets out how a reporting entity obtains access to the Services Access Control Manager, or SACM, the gateway to the goAML application where it registers and files reports. Entities outside Central Bank regulation use a public portal, while others follow their Supervisory Body’s route. SACM stores the production and testing environment links and runs on a time-based passcode from Google Authenticator. It walks through pre-registration, the confirmation of intent and the safekeeping of a personal Secret Key. Correct pre-registration is the condition for secure reporting access.
goAML Registration Guide, March 2022
Issued by the UAE Financial Intelligence Unit in March 2022, the goAML Registration Guide lays out how an organisation registers with the FIU on its platform. It applies whether the registrant is a reporting entity, a stakeholder or a supervisory body, and states that each accountable or reporting entity in the country, whatever supervises it, has to register before submitting suspicious reports. It walks through reaching the portal via the Services Access Control Manager, then selecting the type of registration, keying in the organisation and its addresses, naming the registering person and assigning user access rights.
Strategic Review on Targeted Financial Sanctions Case Studies, November 2021
This November 2021 Strategic Review on Targeted Financial Sanctions Case Studies revisits how sanctions reporting has run in the UAE. It sits within the framework by which the country, through Cabinet Resolution No. 74 of 2020, puts United Nations Security Council Resolutions on terrorism, its financing and proliferation into effect, applying asset freezes and barring the supply of funds and services. It sets out its method, then classifies sanctions reports by source, suspicion and the instruments in play, teasing out what separates terrorist financing from proliferation financing, and closes with red flags and recommendations. For an advisor or promoter, it shows how a sanctions concern around an investor or product surfaces.
Typologies on the Circumvention of Targeted Sanctions, November 2021
Issued by the Executive Office and last amended in November 2021, this report collects cases showing how designated persons and entities try to sidestep targeted sanctions connected to terrorism and the spread of weapons of mass destruction. From public sources inside and outside the UAE, it lays out the tricks used to evade United Nations resolutions and the national terrorist list. They are arranged by channel and sector, spanning trade in dual-use goods, online payment facilities, complex legal-entity structures, economic resources and cyber activity, each with its networks and warning signs. The review turns evasion tactics into practical learning for screening, due diligence and monitoring introduced relationships.
Update to the List of High Risk Jurisdictions, November 2021
The National Anti-Money Laundering Committee, in a November 2021 decision, revises the list of high-risk jurisdictions subject to a call for action, the list of jurisdictions under increased monitoring and the counter-measures that follow, replacing a March 2021 decision. Directed to the supervisory authorities and the Financial Intelligence Unit, it reflects the Committee’s remit to flag weakly controlled countries, calibrate counter-measures and steer supervisors towards the required due diligence. For an advisor or promoter, country risk is a core input: it signals which jurisdictions warrant enhanced due diligence on investors and on cross-border promotion and referral, and it obliges risk assessments to keep pace with the latest listings.
Joint Guidance on Satisfactory and Unsatisfactory Practice, June 2021
This June 2021 joint guidance from the UAE Supervisory Authorities, among them the Securities and Commodities Authority, whose mandate has since passed to the Capital Market Authority, the Central Bank, the Ministry of Justice and the Ministry of Economy, now the Ministry of Economy and Tourism (MoET), builds on patterns observed across supervisory inspections held between January 2020 and May 2021. It measures good practice against poor practice across anti-money laundering controls, counter-proliferation financing and targeted financial sanctions. Its practical scope spans board and management oversight, risk assessment, policies, training, the three lines of defence and the compliance officer role, alongside customer onboarding, risk rating, due diligence, transaction monitoring, sanctions screening and reporting. By turning supervisory findings into practical examples, the guidance gives regulated firms a benchmark against which to assess their controls before an inspection.
Typologies on the Circumvention of TFS, PF and WMD, May 2021
Issued by the Executive Office and last amended in May 2021, this report looks at how designated persons and entities raise financing while breaching or evading United Nations resolutions on terrorism and weapons-of-mass-destruction proliferation. It notes that targeted financial sanctions extend to both asset freezing and a ban on providing funds or assets, directly or indirectly, to those listed. Set out by financing method, it addresses economic resources, trade in goods, the abuse of legal structures and arrangements, online payment facilities and cyberattacks on financial institutions, ending with red flags. For an advisor or promoter, it reinforces screening, monitoring and reporting of circumvention through the investors and products they connect.
goAML FAQs, September 2020
The goAML FAQs Guide, released by the UAE Financial Intelligence Unit in September 2020, is a question-and-answer reference for entities operating goAML, the channel by which suspicious reports reach the FIU in the United Arab Emirates. It draws together the queries raised most often once an organisation is active, each answered step by step. Among them are resetting a lost password, refreshing organisation details, from name and licensed activity to address and contacts, and how the Money Laundering Reporting Officer, acting as admin, may hand reporting to an outside party with Supervisory Body approval. Sound registration data and controlled access keep FIU reporting unbroken.
goAML Registration Guide Stage 2, September 2020
Released by the UAE Financial Intelligence Unit in September 2020, the goAML Registration Guide Stage 2 takes an organisation through registration with the FIU on its filing platform. It covers registration as a reporting entity, a stakeholder or a supervisory body, notes that every accountable and reporting entity across the country must register to file suspicious reports, and records that electronic filing through goAML has been in place since 27 June 2019. It deals with reaching the portal via the Services Access Control Manager, picking the registration type and setting up the organisation record.
Guideline on Grievance Procedures
The Guideline on Grievance Procedures is issued by the Executive Office for Control and Non-Proliferation, the body that receives grievances tied to the UAE Local Terrorist List and the United Nations Consolidated List, together with the Sanctions Lists. Under Cabinet Resolution No. 74 of 2020, it handles three kinds of requests: removing a designation, lifting freezing measures, and permission to use frozen assets, each depending on whether the name appears on the Local or the United Nations List. The procedures chart the lawful routes an affected client may take to contest a designation or free frozen funds, useful when one surfaces among investors the firm advises or introduces.
Online Grievance System User Guide
This manual for the Online Grievance System comes from the Executive Office for Control and Non-Proliferation, which fields grievances connected to the UAE Local Terrorist List and the United Nations Consolidated List, together with the Sanctions Lists. Built to ease submissions, the manual sets the system out step by step. It supports three online requests: de-listing, lifting freezing measures, and permission to use frozen funds. It leads the user through naming the aggrieved person or entity, picking the grievance category, listing any prior requests and appeals, and uploading supporting files. For an advisor or promoter, it shows how an affected client challenges a designation or seeks access to frozen assets.
Simple Guide to Subscribe to the EOCN Notification Alert System (NAS)
This short guide walks a user through subscribing to the Notification Alert System on the Executive Office’s website, so a firm gets timely updates to the UAE sanctions lists. Targeted financial sanctions hinge on two lists, together the Sanctions Lists: the UAE Local Terrorist List published by the Cabinet and the United Nations Consolidated List published by the Security Council, each revised periodically. It shows where the lists sit and gives step-by-step sign-up instructions, running from the web page to the final confirmation. The guide supports a basic control, since screening an investor or a referral works only against current lists.
Emerging ML, TF and PF Risks and Trends in the Financial Sector
Prepared by the Supervisory Subcommittee under Article 16 of Federal Decree-Law No. 10 of 2025, this report hands regulated firms an up-to-date reading of the money-laundering, terrorist-financing and proliferation-financing threats reshaping the sector as tech, geopolitics and criminal tactics evolve. After setting scope and methodology, it looks at emerging risks such as artificial-intelligence misuse, trade finance abuse, greenwashing and ESG-related fraud, and sanctions evasion linked to the Commonwealth of Independent States. The case studies range across trade-based laundering, money-mule networks, fraudulent green schemes and free-zone corporate structures. These typologies and red flags belong in the risk assessment and in what the firm watches for.
Typologies in the Financial Sector
A joint report from the Supervisory Authorities Sub-Committee, the Financial Intelligence Unit, and the Executive Office for AML/CFT. It shares typologies of money laundering, terrorist financing, fraud, corruption and sanctions evasion seen in the market, including a few from the COVID-19 period, so firms can anticipate new threats. Positioned above the National Risk Assessment, it sets out the indicators that together disguise the true nature of transactions and points to modern slavery and human-trafficking links. These are early warnings for refreshing the risk assessment, tuning checks on advised and introduced business, and engaging authorities.
Is Your Business-Wide Risk Assessment CMA-Ready?
Examiners consistently flag generic, template-style risk assessments. We'll help you build one that reflects your actual funds, clients, and channels.
NRA, SRA, and Other Important Guidelines for Advisors and Promoters in UAE
The UAE assesses its money laundering, terrorist financing and proliferation financing risk at the national level, and advisors and promoters must align their business-wide and enterprise-wide risk assessments with those findings.
UAE PF National Risk Assessment 2026
The UAE Proliferation Financing National Risk Assessment 2026 looks at how far the country is exposed to funding for weapons of mass destruction and to breaches of targeted financial sanctions imposed by United Nations resolutions covering North Korea and Iran. Written in response to the Financial Action Task Force revised Recommendation 1, it scores the securities sector low on proliferation financing across the mainland and the financial free zones alike, while placing overall country risk at medium-high.
UAE ML and TF National Risk Assessment 2024
The UAE Money Laundering and Terrorist Financing National Risk Assessment 2024 is the nation’s second exercise of its kind, built on the World Bank methodology and resting on figures gathered between 2019 and 2023. It puts the securities sector residual money laundering risk somewhere between medium and medium-high, a reflection of the breadth of activity it spans, yet records the sector’s AML controls as effective. Its findings reach across the mainland and the financial free zones. For a firm that advises and promotes, this is the starting point its risk-based approach should be measured against.
Set out below are the residual ratings that an advisory or promotion firm ought to carry across into its own risk assessment.
| Capital market (securities) sector residual risk | Rating |
| Money laundering and terrorist financing (NRA 2024) | Medium to medium-high, with the sector’s AML controls assessed as effective |
| Proliferation financing (PF NRA 2026) | Low in both the mainland and the financial free zones |
Beyond the national picture, sector risk assessments, red flag material and typologies hand advisors and promoters the granularity that keeps an enterprise-wide risk assessment fresh and defensible.
CMA-Regulated Advisors and Promoters Sector-Specific Guidance
Layered over the federal framework, the Capital Market Authority puts out its guidance, notices, thematic reviews, reporting standards and rulebook chapter for an advisory or promotion firm to work with first-hand. Those instruments form the sector-specific tier listed below.
Federal Decree-Law No. 32 of 2025 on the Capital Market Authority
Federal Decree-Law No. 32 of 2025 establishes the Capital Market Authority (CMA) as the UAE’s federal capital-market regulator, succeeding the Securities and Commodities Authority (SCA). The law sets out the CMA’s objectives, including maintaining the integrity and efficiency of the capital market, promoting fair competition, developing the market and protecting investors and other market participants. It also gives the Authority broad supervisory powers, including verifying compliance, overseeing persons subject to its supervision, conducting inspections and taking regulatory measures. For firms providing financial advice or promotion within the CMA’s perimeter, these powers form the supervisory backdrop against which their activities are conducted.
Federal Decree-Law No. 33 of 2025 on the Regulation of the Capital Market
Federal Decree-Law No. 33 of 2025 sets out the UAE’s substantive framework for regulating the capital market and the financial activities that fall within the CMA’s licensing and supervisory remit. Article 3 covers a broad range of activities, including financial advice, dealing, asset management, investment funds, market operations, central clearing, central depository and custody services. The law also sets requirements around carrying out regulated activities and performing approved functions, while defining key concepts such as securities, issuers, foreign issuers, investment funds, insiders and inside information. Its market-conduct provisions address insider dealing and other forms of market abuse, including restrictions on dealing by certain persons during specified periods. The law also provides a framework for the settlement, restructuring and liquidation of Licensed Persons.
CMA Key AML/CFT/CPF Obligations, Risks and Supervisory Observations, 2025
The CMA’s 2025 regulatory communication brings together key AML/CFT/CPF obligations, emerging risks and supervisory observations relevant to firms under its regulatory oversight. It highlights the need for firms to assess their exposure to money laundering, terrorist financing and proliferation financing in light of factors such as their size, customer base, products and services, delivery channels and geographic exposure, while keeping their frameworks aligned with the UAE’s national risk assessment and the FATF Recommendations. The communication also draws attention to weaknesses identified through the CMA’s supervisory work, giving firms a practical reference for reviewing areas such as risk assessment, customer due diligence, sanctions screening, transaction monitoring, beneficial ownership and regulatory reporting.
CMA Instructions for the 2024 Annual Return AML/CFT and TFS Risk Assessment
Each licensed entity files a yearly return covering AML, CFT and targeted financial sanctions, and these instructions walk through it. Submissions span five tabs. A firm records customer risk, then risk from its products and services, its distribution channels, the controls and mitigation quality it maintains, and lastly its signatories. Full entries are compulsory, sums must be stated in dirhams, and countries named with standard labels or codes. Captured on the inherent side is exposure from customers, products and services, and distribution channels.
CBUAE AML and CFT Guidelines for Financial Institutions, July 2023
These are Central Bank guidelines, prepared jointly by the UAE Supervisory Authorities, and they apply to financial institutions including securities and commodities brokers, dealers, advisors and investment managers. They cover a risk-based approach, including business-wide assessment of customer, geographic, product and delivery-channel risks, and mitigation through internal controls and due diligence. They also cover beneficial-owner identification, wire transfers and ongoing monitoring. For advisory and promotion firms within their scope, the Guidelines provide practical guidance on applying these AML/CFT requirements.
CMA Minimum Standards for the Semi-Annual AML and CTF Report, 2023
These 2023 standards set out the requirements for the semi-annual AML/CFT report prepared by the Compliance Officer or MLRO of a CMA-licensed financial institution. The report covers each six-month period ending on 30 June and 31 December and must be submitted to the Authority within two months of the reporting period, together with the comments of the Board or relevant senior management. The standards set out the report structure, covering areas such as the executive summary, governance, the enterprise-wide risk assessment, policies and procedures, customer risk assessment and due diligence, gap analysis, action plans and findings. They also require the report to be reviewed and approved by the appropriate senior management or Board.
CMA Implementation of Targeted Financial Sanctions, May 2022
Dated 19 May 2022, CMA Notice 1/2022 tells licensed institutions to give effect to targeted financial sanctions under UN Security Council Resolutions 1718 (2006) and 2231 (2015), pursuant to Cabinet Resolution No. 74 of 2020. Advisors, arrangers and promoters within the scope of the notice must screen parties to financial transactions, apply enhanced due diligence where dealings involve relevant countries, and examine cross-border transactions that may indicate unauthorised trade in dual-use goods. Where a name is confirmed as a match, a report must be submitted through goAML within five business days. The notice calls this the Funds Freeze Report; the March 2026 Executive Office guidance renamed it the Confirmed Name Match Report, and that is the filing an advisor or promoter makes today. A potential match requires a Partial Name Match Report, while genuine suspicion of money laundering or terrorist financing requires an STR to the Financial Intelligence Unit. Firms are also expected to follow relevant Executive Office guidance and take measures to prevent sanctions evasion.
CMA Awareness of Cabinet Resolution No. 111 of 2022 on Virtual Assets and their Service Providers
Cabinet Resolution No. 111 of 2022 governs virtual assets and their service providers across the Emirates, establishing a federal framework for licensing and supervising virtual-asset activities, subject to the jurisdictions and exclusions set out in the Resolution. It is relevant to an advisor or promoter where its activities involve virtual assets or virtual-asset service providers. The Resolution sets out the regulatory framework for virtual-asset activities and gives the SCA, whose functions have since passed to the Capital Market Authority under Federal Decree-Law No. 32 of 2025, responsibility for supervising and overseeing VASPs within its jurisdiction. It also requires compliance with applicable AML/CFT requirements and gives the Authority powers to issue further decisions and guidance for the sector.
CMA Thematic Review on Reliance on Third Parties, December 2021
Dated December 2021, this second CMA thematic review turned to the five securities-custody licensees, each a bank or a local branch of a foreign bank under Central Bank licence, and gauged them against FATF Recommendation 17 on relying on third parties. Custodians guard client securities and cash and lean towards institutional and offshore business, so outsourced due diligence is common. The twenty-one-item questionnaire came back complete: four of the five firms leaned on outside parties, all regulated or listed and bound by service level agreements. For advisors and promoters who depend on introducers, the review highlights the importance of maintaining responsibility for due diligence even when relying on a third party.
CMA Thematic Review of Targeted Financial Sanctions in the Capital Market Sector, November 2021
Investors reach the market through brokers, so this November 2021 review examined how securities brokerage firms understand and comply with targeted financial sanctions, domestic and international alike, under Cabinet Resolution No. 74 of 2020. Brokers were assessed as having a medium-high vulnerability in the National Risk Assessment and returned a twenty-nine-question questionnaire at a ninety-six per cent response rate. Two in three kept a standalone sanctions assessment, seven in ten ran vendor screening, and over four in five screened daily. One firm identified, reported and froze a match during 2021. The review provides relevant good practices, including senior-management approval, checking that screening vendors cover domestic lists, clear reporting lines and monitoring by Executive Office.
CMA AML and CFT Guidance for the Capital Market Sector, September 2021
From September 2021, this guidance supplements the main Financial Institutions Guidelines and sets out the expectations the Capital Market Authority looks for its licensees. Boards, managers and staff at institutions carrying out securities activities in the UAE are its audience, and it is intended to be read alongside the wider guidance. The opening part covers sector typologies, including trade-based money laundering through mis-invoicing and misrepresentation of quality, quantity or price, as well as cash-driven laundering. Later parts explain the risk-based approach, the business-wide risk assessment and the customer, product, channel and geographic factors that firms in the capital market sector must identify, assess and mitigate.
CMA Notice 3/2021 on the Immediate Reporting Mechanism
Dated 26 July 2021, CMA Notice 3/2021 was issued to all licensed entities and licensed securities and commodities exchanges on the immediate reporting mechanism for implementing Cabinet Resolution No. 74 of 2020 on terrorism lists and relevant UN Security Council resolutions concerning terrorism, terrorist financing and the proliferation and financing of weapons of mass destruction. Referring to Article 21(5), the notice states that the goAML system had been upgraded to allow reporting of matched names and the actions taken in response, with these reports submitted directly to the Executive Office. Licensed entities were required to incorporate the mechanism into their reporting processes.
CMA Notice 4/2021 on Targeted Financial Sanctions Reporting
Dated 4 August 2021, Notice 4/2021 was issued to all licensed entities and licensed securities and commodities exchanges on sanctions reporting, following the 26 July notice. Under Cabinet Resolution No. 74 of 2020, the Central Bank, in coordination with the Executive Office for Control and Non-Proliferation, established a unified reporting mechanism through the Financial Intelligence Unit’s goAML platform. Two reports were introduced: the Funds Freeze Report for a confirmed match, since renamed the Confirmed Name Match Report by the March 2026 Executive Office guidance, and the Partial Name Match Report for a potential match. A confirmed match required the relevant funds or assets to be frozen without delay, while a potential match required suspension pending further instructions.
CMA Notice 6/2021 on the Update to High Risk Jurisdictions
Dated 22 November 2021, CMA Notice 6/2021 updates the National Committee’s lists of High Risk Jurisdictions subject to a Call for Action and Jurisdictions under Increased Monitoring, for licensed entities and exchanges, superseding Notice 1/2021. An advisor, arranger or promoter within its scope must apply enhanced due diligence where a business relationship or transaction involves a listed jurisdiction, apply the relevant countermeasures to jurisdictions subject to a Call for Action, and reassess geographic risk as the lists change. The notice also sets requirements around reliance on third parties in high-risk jurisdictions and reporting through goAML. Measures should be proportionate to the risk presented by the particular relationship or transaction.
SCA Board Chairman's Decision No. 21 of 2019 on AML and CFT Procedures
SCA Board Chairman’s Decision No. 21/Chairman of 2019 sets out AML/CFT procedures for entities regulated by the Securities and Commodities Authority. The decision was approved by the SCA Board on 30 April 2019 and was issued under the then-applicable UAE AML/CFT framework. It requires entities licensed or approved by the SCA to comply with the applicable AML/CFT laws, regulations and the Authority’s instructions. It also gives the Authority supervisory powers, including access to records and information and the ability to examine an entity’s AML/CFT systems and procedures.
CMA Guidelines for Combating Money Laundering and Terrorist Financing (Chapter Five)
Chapter Five of the CMA rulebook contains the Authority’s Guidelines for Combating Money Laundering, Counter terrorism Financing and Funding of Illegal Organisations. The chapter sets out mandatory standards for the concerned entities and requires them to develop and implement an AML/CFT compliance programme appropriate to their activities. It covers money laundering risks, suspicious transactions, beneficial ownership, targeted financial sanctions, customer due diligence, and risk-based measures for higher-risk customers. It also addresses senior management responsibilities, reporting, screening, record-keeping and training. The chapter is intended to be read together with the federal AML/CFT legislation and other applicable requirements.
CMA AML and Financial Crimes Framework and Controls: Good and Weak Practices
Prepared by Mendy Ghaleb of the Authority’s AML and Financial Crimes Department, this presentation compares good practices with common weaknesses in AML and financial-crime frameworks and controls. It draws on Federal Decree-Law No. 10 of 2025, Cabinet Resolution No. 134 of 2025 and the decisions relating to beneficial ownership, terrorism lists and targeted financial sanctions, together with Chapter Five of the CMA rulebook. Drawing on inspections and desk-based analysis, it identifies recurring weaknesses in AML frameworks, including business-wide risk assessments that are not sufficiently aligned with the firm’s activities, risk-appetite statements without clear thresholds, and policies that have been adopted without adequate board oversight.
CMA Obligations to Implement the Business-Wide Risk Assessment (BWRA)
This Authority material sets out the requirement for regulated firms to carry out a Business-Wide Risk Assessment as a core part of their AML and CFT framework. The assessment requires a firm to identify, understand, and assess its money-laundering, terrorist-financing, sanctions and proliferation-financing risks, across client types, products, channels, geographies and new technology. It moves through three stages: first, scoping the units, entities, divisions and regions in play; second, measuring inherent risk on hard data and building controls; and third, assessing residual risk against the firm’s risk appetite and developing action plans where needed. For advisors and promoters, the assessment should be kept current and updated as the firm’s risk changes.
CMA Thematic Review of Screening Systems
Conducted across the UAE capital markets sector, this CMA thematic review assessed name and transaction screening systems at 26 Licensed Financial Institutions. The review covered 46 screening systems and tested their effectiveness using control and variation-based datasets, including United Nations and UAE sanctions lists. The systems generally identified direct matches during onboarding and routine screening, but performance was less consistent with misspelt, rearranged, abbreviated and translated names, including Arabic-Latin variations. The review also highlighted the importance of system calibration, particularly where restrictive settings can result in missed matches and overly sensitive settings can generate excessive false positives. The CMA emphasised gap analysis, regular testing, appropriate thresholds, governance, data quality, management oversight and ongoing review of screening systems.
CMA Questions and Answers on the National Risk Assessment
This CMA question-and-answer set explains how regulated firms should align their Enterprise-Wide Risk Assessment with the 2024 National Risk Assessment. Firms are expected to consider the NRA findings and typologies in relation to their own business, assess their relevance and reflect them in their risk assessment and AML/CFT controls. Even a low-risk house must study the NRA, note its bearing and revisit it each year. The CMA expects firms to document this process, identify any gaps and update their controls where necessary. The assessment should be reviewed regularly and kept up to date as the firm’s business and risk profile change.
CMA Circular on the Examination Observations Report
This CMA circular sets out examination observations based on firms’ AML/CFT and targeted financial sanctions risk assessments and related supervisory work. The observations identify recurring weaknesses in areas such as governance policies, sanctions controls, risk assessments, customer due diligence, beneficial-ownership information and suspicious transaction reporting. The circular also highlights gaps in the sanctions compliance programme and weaknesses in the oversight and testing of AML/CFT controls. Firms are expected to address identified weaknesses, involve senior management and the Board in remediation, and maintain appropriate oversight of their AML/CFT framework.
UAE Virtual Assets Travel Rule
The UAE Virtual Assets Travel Rule applies primarily to virtual asset service providers and sets requirements for information accompanying qualifying virtual-asset transfers. Financial institutions may also be subject to applicable virtual-asset transfer requirements when sending or receiving virtual assets on behalf of a customer. For financial advisors, the relevance therefore depends on the activities they perform and whether those activities fall within the applicable virtual-asset regulatory framework.
CMA Chapter Five Outreach
Chapter Five Outreach puts the Authority’s Chapter Five Regulations against money laundering, terrorism financing and the funding of illicit organisations into plain, slide-form language. It takes capital market firms through the mandatory standards, their roots in federal AML law, and the key areas covered by Chapter Five. Serving as the companion to the mandatory Chapter Five rules, it offers a practical reference for understanding the requirements around AML/CFT programmes, risk-based customer due diligence, senior management responsibilities, suspicious activity reporting and other key controls. It helps firms understand how the Chapter Five requirements apply within their AML/CFT framework.
CMA and FIU Joint Awareness Session on Suspicious Reporting Effectiveness
Run jointly by the Authority’s AML and Financial Crimes Department and the Financial Intelligence Unit, this session focuses on the effectiveness of suspicious reporting by licensed financial institutions. It covers the quality of STRs and SARs, reporting practices, internal controls and key strategic insights, with particular attention to the quality of reports submitted through goAML. It provides practical context on what effective suspicious reporting should look like, rather than treating reporting as a procedural requirement alone.
CMA Examination Observations, Appendix of Detailed Findings
This appendix to the CMA’s examination observations sets out detailed findings from its supervisory examinations. It covers areas including governance, risk assessment, customer due diligence, beneficial ownership, sanctions screening and suspicious transaction reporting, highlighting both stronger practices and areas requiring improvement. For advisors and promoters, the findings provide a useful basis for reviewing their AML/CFT frameworks, assessing the effectiveness of their controls and identifying areas for improvement ahead of a supervisory examination.
Core AML Obligations for Advisors and Promoters at a Glance
A CMA-regulated advisor or promoter must operate a risk-based AML programme appropriate to the nature and size of its business. In practice, a financial consultant or promoter regulated by the CMA must maintain the following.
- Risk assessment: a business-wide assessment covering the firm’s client base, the products and providers it markets, its channels and its introducers.
- Due diligence: The customer due diligence process applied at the required points in the customer relationship, extending to checks on ultimate beneficial ownership, identification and enhanced scrutiny of politically exposed persons, and heavier scrutiny of higher-risk clients.
- Source of funds: grasping, and when risk demands corroborating, where the money behind a planned investment came from.
- Sanctions screening: running a sanctions compliance program that screens clients and, where relevant, referred parties against the UAE Local Terrorist List, the United Nations Consolidated List and any other applicable lists, freezing and reporting the moment a name matches.
- Product diligence: on the schemes and providers it promotes, with a watchful eye against dressing up unlicensed activity as legitimate.
- Third-party reliance: retained responsibility for customer due diligence even where it relies on an introducer or other third party.
- Governance: a competent compliance officer and money laundering reporting officer backed by the board, whose duties include the compliance officer’s semi-annual report.
- Reporting: suspicion through goAML without tipping off.
- Record keeping: holding customer due diligence files, advice and transaction records, screening results, risk assessments and internal reports for ten years, the retention period the Capital Market Authority requires of its supervised firms. Where that period exceeds the federal record-keeping obligation in Article 25 of Cabinet Resolution No. 134 of 2025, the longer period governs. The records must allow the firm to reconstruct a client relationship end to end and produce it to the Authority or the Unit on request; for an advisory or promotion business, the suitability file and the marketing material issued to each client matter as much as the identification documents.
- Staff training: an ongoing programme that reaches advisors, marketers and introducer-facing staff as well as the board, not only the compliance function, and that is pitched at the typologies this business actually meets, unlicensed schemes dressed as legitimate offerings, source of funds a client will not explain, and pressure to keep an arrangement off the record. Document attendance and content, because examinations test the training file.
- Regulatory returns: lodging the annual and semi-annual returns the Capital Market Authority calls for.
The board and senior management own this framework, and the Authority probes it through returns, examinations and thematic reviews.
Key AML deadlines for CMA-regulated advisors and promoters in UAE
- Freeze on a confirmed sanctions match: without delay, and within twenty-four hours, under Cabinet Resolution No. 74 of 2020.
- Confirmed Name Match Report through goAML: within five business days of confirming the match, under CMA Notice 1/2022, the report previously filed as the Funds Freeze Report.
- Beneficial owner register update: within fifteen days of a change, under Cabinet Decision No. 109 of 2023.
- Record retention: ten years for customer due diligence files, transaction and advice records, screening results and internal reports, under the retention period the Capital Market Authority applies to its supervised firms.
- Semi-annual AML and CFT report to the Authority: within two months of each period ending 30 June and 31 December, under the CMA Minimum Standards of 2023.
- Annual AML, CFT and TFS risk assessment return: filed yearly across five tabs, with all sums stated in dirhams, under the CMA Instructions for the 2024 Annual Return.
- FIU suspension and freezing: a transaction may be suspended for up to ten working days and funds frozen for up to thirty, under Article 5 of Federal Decree-Law No. 10 of 2025, with the operating procedure set out in UAE FIU Regulation No. 1 of 2026.
Conclusion
For CMA-regulated advisors and promoters in the UAE, the AML framework brings together the federal AML legislation, its Executive Regulations, the targeted financial sanctions regime, UAE FIU reporting requirements and the CMA’s own AML/CFT rules and guidance. The 2024 National Risk Assessment separately identifies Advisors and Promoters as a capital-market sub-sector, with its own risk profile. Their exposure therefore needs to be assessed against the nature of their customers, products and services, delivery channels and geographic reach, with controls maintained and updated as those risks change. A firm that documents its risk assessment, maintains appropriate CDD and sanctions controls, reports suspicions through goAML and keeps its AML/CFT framework current is better positioned to meet its regulatory obligations.
FAQs
Which financial advisors and promoters are subject to AML rules in the UAE?
Advisors, promoters, arrangers, introducers and placement agents carrying on activities regulated by the Capital Market Authority are subject to the AML/CFT requirements applicable to their regulated activities. The 2024 National Risk Assessment identifies Advisors and Promoters as a distinct sub-sector within the securities sector. Firms operating in the DIFC or ADGM are subject to the respective DFSA or FSRA frameworks rather than the CMA framework.
Do financial consultants and promoters have AML duties if they never hold client money?
Yes. Not holding client money does not by itself remove a firm from the AML/CFT framework where its regulated activities fall within the applicable financial activities. The firm’s obligations depend on the nature of its activities and business relationships and can include risk assessment, customer due diligence, beneficial-owner identification, ongoing monitoring, sanctions controls and suspicious transaction reporting.
How should a promoter avoid lending legitimacy to an unlicensed or fraudulent scheme?
A promoter should assess the products, funds and providers it markets, verify the relevant regulatory status and consider whether the activity or provider falls within the applicable licensing requirements. Requests to promote unlicensed activities, opaque structures or unrealistic investment returns should be treated as potential risk indicators and assessed accordingly. Where the firm’s obligations give rise to a suspicion of a crime, the matter should be handled through the applicable AML/CFT reporting framework.
What source of funds checks are expected when advising or arranging an investment?
Where required by the risk profile or circumstances of the relationship, an advisor or arranger should obtain information concerning the source of funds and take reasonable measures to verify it. Unexplained or inconsistent funding can increase the risk associated with a relationship and may require enhanced measures or, where there are grounds for suspicion, a suspicious transaction report.
Do financial advisors and promoters need a business-wide risk assessment?
Yes. The Capital Market Authority requires supervised firms to maintain a business-wide risk assessment, and the federal framework requires an enterprise-wide risk assessment. For an advisory or promotion firm, the exercise needs to capture its client base, the products and providers it markets, its channels and introducers, and the geographies it touches, sit in step with the national and sector risk assessments, and stay current and defensible. Firms without the in-house capacity to run it often commission a business risk assessment and refresh it annually.
How should financial advisors and promoters treat exposure to virtual assets?
Advising on or promoting virtual assets can raise regulatory questions beyond the firm’s ordinary securities activities, depending on the nature of the product and service. A firm should therefore determine whether the activity falls within the CMA’s virtual-asset or securities framework or another applicable UAE regime, and assess the associated AML/CFT/CPF risks. Where a firm is itself carrying out a regulated virtual-asset activity, the requirements applicable to VASPs, including the Travel Rule where relevant, may apply, as set out in the AML regulations for virtual asset service providers in UAE. Simply having a client involved in virtual assets does not by itself make the advisor a VASP.
Are older SCA AML notices still relevant now that the CMA has replaced the SCA?
Older SCA AML decisions, notices, and guidance may remain relevant where they have not been repealed, superseded, or otherwise replaced, and continue to form part of the applicable regulatory framework. They should, however, be read against the current legal and regulatory framework, including Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025, where applicable. Firms should therefore verify the current status of each older instrument rather than assume that every SCA instrument remains in force.
Expert tip
For an advisor or promoter, the risk that is easy to underrate is reputational transfer. When you recommend a product, promote a fund or introduce a client to a provider, you lend your licence and your credibility to that transaction. Build due diligence not only on your client but on the products, schemes and providers you put in front of them, deal only with licensed entities, and keep evidence of the checks you ran on both sides. Treat any pressure to promote unlicensed providers, unrealistic returns or opaque structures as a reason to stop and report. That gatekeeper discipline is what examinations look for.
Still Have Questions on CMA AML Rules?
Every fund manager's exposure looks a little different once you factor in feeder structures, institutional investors, and cross-border flows. Get a straight answer from someone who's done this before.
Share via :
About the Author
Pathik Shah
FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)
Pathik is an ACAMS-certified AML consultant specialising in governance, risk, and compliance for regulated entities in the UAE. He brings over 28 years of experience, with 1,000+ hours of AML training and 200+ advisory engagements across DNFBPs, VASPs, and FIs. He supports businesses in aligning with AML/CFT requirements from the CBUAE, DFSA, MoET, MoJ, VARA, CMA, FSRA, and FATF. Known for translating complex regulations into audit-ready procedures, Pathik enables operational clarity and compliance readiness.
Reach Out to Pathik