AML Regulations for CMA-Regulated Investment Management Companies in UAE
Published On: 09/02/2026
Protect your business with reliable and effective AML strategies with AML UAE.
Last Reviewed On: 09/02/2026 | Last Updated On: 09/02/2026
Key Highlights: AML Compliance for UAE Forex Companies
- Fund managers, discretionary portfolio and asset managers, and wealth and private client managers count as financial institutions once the Capital Market Authority licenses them, bringing them within Federal Decree-Law No. 10 of 2025 and the Executive Regulations in Cabinet Resolution No. 134 of 2025.
- The Capital Market Authority (CMA), which took over from the Securities and Commodities Authority (SCA) under Federal Decree-Law No. 32 of 2025, is their AML and CFT supervisor; the Authority, rather than the Central Bank, oversees them.
- Across the national risk work, the securities sector carries a money laundering rating that sits between medium and medium-high, its controls are judged effective, and its proliferation financing rating is low, a picture that holds for the mainland and the financial free zones alike.
- For a manager, the danger clusters around who subscribes; the structures used to disguise beneficial ownership behind pooled, feeder, nominee, and institutional investors; where subscription money originates; sanctions screening of investors and their controllers; and monitoring subscription and redemption flows for anything out of place.
- Layered above federal law, the Capital Market Authority maintains a rulebook chapter, sector guidance, thematic reviews, notices, and reporting standards, and a fund or portfolio manager must fold all of these into its compliance programme.
- Anything touching virtual asset management or services falls under a distinct framework outside this securities regime, while asset managers established in the DIFC and ADGM report to the DFSA and FSRA and fall outside the scope of this guide.
Investment management companies sit between investors and the markets where they deploy capital. They raise subscriptions into funds, run discretionary and advisory mandates, and place client capital across securities and other assets. That business model gives them a money-laundering exposure focused on the investor behind a subscription, where the money came from, and whether a redemption is used to move value out cleanly. Because they operate in securities rather than deposits or payments, they answer to the Capital Market Authority rather than the Central Bank. This guide sets out the AML regulations for CMA-regulated investment management companies in the UAE, which firms are in scope, the regulator, the full legal stack, how the national risk assessments rate the securities sector, and the controls a manager is expected to run. It covers fund and asset managers supervised by the Capital Market Authority outside the DIFC and ADGM.
In short: fund managers, discretionary portfolio and asset managers, and wealth managers that the Capital Market Authority licenses outside the DIFC and ADGM sit inside this regime. Their obligations flow from Federal Decree-Law No. 10 of 2025 and the Executive Regulations in Cabinet Resolution No. 134 of 2025, the targeted financial sanctions regime in Cabinet Resolution No. 74 of 2020, registration and reporting to the UAE FIU through goAML, and the Capital Market Authority rulebook, its notices and reporting standards. A wealth management company licensed in the DIFC or ADGM instead answers to the DFSA or FSRA.
Who is an investment management company for AML purposes?
For AML purposes, this category covers firms the Capital Market Authority licenses to manage funds and investments on behalf of clients. The types below all fall under the AML regulations for CMA-regulated investment management companies in the UAE. The DFSA and FSRA supervise firms established in the DIFC and ADGM, so they are not covered here.
Collective investment fund managers
Fund managers establish and run collective investment funds and manage the capital that investors subscribe. Their ML/TF/PF exposure depends on the subscriber’s identity, the beneficial owners behind pooled and feeder investors, and the source of funds entering the fund.
Discretionary portfolio and asset managers
Discretionary managers invest and trade on a client’s behalf under a mandate. Their ML/TF/PF controls centre on client onboarding, verifying who ultimately owns and controls the account, the source of the assets under management, and monitoring the flows in and out of the portfolio.
Institutional and wholesale asset managers
Firms managing money for institutions, pension schemes and other professional clients face concentrated but complex ownership chains. Their risk lies in understanding the structures behind institutional investors, their reliance on introducers and third parties, and the geography of the capital.
Wealth and private client managers
Wealth and private client managers serve high-net-worth individuals and their vehicles. Their exposure runs through source of wealth and funds, politically exposed persons, complex offshore structures, and the discretion these clients expect, which makes robust due diligence and monitoring essential.
AML Supervisory Authority for Investment Management Companies in UAE
Capital Market Authority (CMA)
The Capital Market Authority is the UAE federal regulator for securities and commodities, created by Federal Decree-Law No. 32 of 2025 to take over the mandate of the Securities and Commodities Authority. Its remit covers licensing and supervising fund managers, portfolio and asset managers, and other investment firms operating outside the DIFC and ADGM, and it acts as their AML and CFT supervisor. Through its rulebook chapter, it shapes how those firms build compliance programmes; it also issues sector guidance, notices, and thematic reviews, collects annual and semi-annual AML returns, conducts examinations, and imposes administrative penalties where needed. For supervisory expectations, a fund or wealth manager turns to the Authority instead of the Central Bank and studies that rulebook alongside the federal AML laws.
UAE FIU and goAML
Each investment management company within scope must register with the UAE Financial Intelligence Unit and route its filings through goAML. Housed inside the Central Bank under Federal Decree-Law No. 10 of 2025, the Unit takes in suspicious transaction reports, suspicious activity reports, and the further reports the framework demands, and it may call for more information and pass intelligence to supervisors and law enforcement. For a manager, reporting on the goAML portal is how an odd subscription, a suspect redemption, a sanctions hit on an investor or an unexplained source of funds is escalated to the authorities. Registering, filing on time, and submitting accurately are legal obligations, and both the Authority and the Unit closely review the quality of a firm’s reports.
AML Legal Framework Applicable to Investment Management Companies in UAE
Four layers make up the AML regulations for capital market firms in the UAE as they apply to an investment manager: the core federal AML laws and their executive regulations, the guidance addressed to every reporting entity, the national and sector risk assessments, and the Capital Market Authority’s own rulebook and guidance. The instruments set out below populate those layers, and each is explained in terms of what it asks of a fund, portfolio or wealth manager day to day.
Federal AML Laws and Executive Regulations Applicable to Investment Management Companies in the UAE
These are the core federal instruments every investment management company builds its programme on.
Federal Decree-Law No. 10 of 2025 on AML, CFT and CPF
Federal Decree-Law No. 10 of 2025 puts the investor and the movement of their money within the UAE’s wider AML/CFT/CPF framework. It sets out suspicious transactions, predicate offences, targeted financial sanctions and the meaning of money laundering, and confirms offences may be committed by digital means. It seats the Financial Intelligence Unit inside the Central Bank as the national recipient of suspicious transaction reports, empowered to demand more information and, via the Head of the Unit, to direct freezing and suspension within statutory bounds. Managers and custodians take on supervisory oversight, face administrative penalties, and must detect, report and back enforcement.
Cabinet Resolution No. 134 of 2025, the Executive Regulations
Cabinet Resolution No. 134 of 2025 promulgates the Executive Regulations of Federal Decree-Law No. 10 of 2025, where high principles become the manual a fund or portfolio manager applies to every subscription and redemption. Its glossary expands to include wire transfers, reasonable measures, beneficial owner, and senior management, and it confirms collective investment activity and fund transfers sit squarely in scope. The concrete duties follow: internal policies with senior-management sign-off, continuous monitoring of portfolio flows, verification of the beneficial owners behind pooled and nominee holdings, due diligence on investors, and a risk-based approach.
Cabinet Decision No. 109 of 2023 on beneficial owner procedures
Feeder structures, holding companies and nominee arrangements can obscure the natural person behind an investment. Cabinet Decision No. 109 of 2023 provides the framework for tracing ownership and control to the ultimate beneficial owner. It sets beneficial ownership procedures for legal persons across the United Arab Emirates, defining the real beneficiary as whoever ultimately owns or controls the entity, whether directly or through an ownership chain. Entities must keep an accurate register, disclose beneficial owner data, flag nominee directors, and refresh the record within fifteen days of any change. Managers checking institutional investors lean on it. It reaches the State and commercial free zones, sparing only the DIFC and ADGM.
Cabinet Resolution No. 132 of 2023 on penalties for beneficial owner violations
The beneficial ownership framework is backed by Cabinet Resolution No. 132 of 2023, which sets out administrative fines for failures to comply with Cabinet Decision No. 109 of 2023. Following an annexed schedule, a registrar may penalise a legal person that keeps no accurate register or withholds information, leaving intact any sanction under the principal anti-money laundering legislation. Repetition sharpens the response: at a third breach, the registrar may suspend the trade licence and seal the premises until the fine is paid and the violation is remedied. The consequence gives the ownership rules real weight, requiring corporate and institutional investors to keep their ownership records accurate and up to date. The framework applies across the UAE and its commercial free zones, but not the DIFC or ADGM.
Cabinet Resolution No. 74 of 2020 on terrorist lists and UNSC resolutions
Every party to a subscription or redemption is screened against the sanctions lists under Cabinet Resolution No. 74 of 2020. It governs the UAE’s operation of the terrorist lists and its implementation of United Nations Security Council measures against terrorism, its financing and proliferation. A local Cabinet list is provided for, de-listing, listing and designation are defined, and freezing must follow without delay, meaning within twenty-four hours. This is the backbone of any investment manager’s sanctions work. Firms enrol on the Executive Office website, run continuous screening of beneficial owners, investors, would-be subscribers and intermediaries, freeze matched securities or funds without notice, and report to the supervisor at once.
Federal Law No. 7 of 2014 on combating terrorism crimes
At the criminal level, Federal Law No. 7 of 2014 on Combating Terrorism Crimes sets out the behaviour a manager’s surveillance hunts for. The statute establishes terrorist offences and their punishments, defining the terrorist person, the terrorist organisation, the terrorist purpose and the terrorist crime, with penalties reaching life imprisonment and, in named cases, death. For a collective investment house, the terrorism-financing dimension matters most: it punishes the collection, provision or upkeep of funds for terrorist ends and enables the freezing of suspect money held with financial institutions. Because the wider framework defines terrorist acts by pointing to this law, managers and custodians consult it to know their targets.
Too Many Instruments to Track Manually?
Between federal law, TFS guidance, and CMA notices, keeping your fund's compliance programme current is a full-time job. We help investment managers map every obligation to a working control.
AML Guidance Applicable to All Reporting Entities
Above the core laws is a body of guidance and typologies from the UAE Financial Intelligence Unit, the Executive Office for Control and Non-Proliferation, and the supervisory authorities, which binds every reporting entity, including investment managers.
UAE FIU Regulation No. 1 of 2026 on Suspension and Freezing Powers, April 2026
Where suspicious funds are at risk of being withdrawn, transferred or dissipated, UAE FIU Regulation No. 1 of 2026, dated April 2026, sets out the framework for postponing transactions and freezing funds. It rests on the AML/CFT Decree-Law and its Executive Regulation, explains how suspicious transactions are postponed or suspended and funds frozen, and runs alongside existing reporting duties. Its innovation is the Postponement Suspicious Transaction Report, an urgent filing used where crime-linked funds risk imminent dissipation, withdrawal or transfer. Freezing up to thirty days and suspensions of up to ten working days rest with the Head of the Unit. For managers and custodians, it swiftly preserves investor assets.
UAE FIU Strategic Analysis Report on Human Trafficking, April 2026
The UAE FIU Strategic Analysis Report on Human Trafficking, dated April 2026, traces how trafficking proceeds move through the financial system and draws on suspicious transaction and activity reports lodged with the Financial Intelligence Unit. Objectives, scope and methodology are set out, the chief forms of exploitation are described, and the findings range from the laundering of trafficking money to its meshing with other criminal ventures. The subjects profiled include money mules, foreign politically exposed persons, and organised crime groups, with indicators built around due diligence, account and transactional behaviour, and customer profile. A fund manager or custodian turns to it to tighten monitoring and lift report quality.
Guidance on Targeted Financial Sanctions for Financial Institutions, DNFBPs and VASPs, March 2026
For a fund or portfolio manager, this guidance from the Executive Office for Control and Non-Proliferation spells out the targeted financial sanctions regime’s demands, first issued in January 2021 and revised again in March 2026. Four duties thread through it: reporting the action taken; freezing assets promptly and keeping them from designated persons; screening investors against the UAE Local Terrorist List and the United Nations Consolidated List; and joining the Executive Office’s Notification Alert System. The March 2026 revision renames the Funds Freeze Report the Confirmed Name Match Report and tackles weekend screening, apt where subscription and redemption cut-offs land on non-working days. It shows how the machinery runs.
Joint Guidance on the Compliance Officer and MLRO, 2026
An investment firm depends on its officer’s power to act; the 2026 joint guidance of the UAE Supervisory Sub-Committee frames the post. It settles the appointment, authority and duties of the Money Laundering Reporting Officer or Compliance Officer for firms overseen by the Ministries of Justice, Economy and Tourism, the Central Bank and the Capital Market Authority. It requires seniority, independence, board access and resources, and points to a manager for a fit and proper appointment.
FIU Strategic Analysis Report on Terrorist Financing, May 2025
This UAE Financial Intelligence Unit strategic analysis of May 2025 anatomises terrorist financing typologies and the facilitators behind them, resting on data spanning 1 January 2021 to 31 December 2024, drawing on suspicious transaction and activity reports together with cases relayed to the authorities. It explains the mechanics of terrorist financing and maps typologies, from real estate and high-value goods to trade-based methods, corporate networks and financial institutions. It then dissects facilitators, professional service providers, corporate nominees, money mules, relatives and designated persons, and finishes with usable indicators. These indicators refine how suspicious mandate and investor-account activity is detected, traced and reported.
Federal Decree-Law No. 6 of 2025 on the Central Bank
Federal Decree-Law No. 6 of 2025 provides the legal framework for the Central Bank’s regulation and supervision of CBUAE-licensed financial institutions and activities. Its relevance to a CMA-regulated investment manager is mainly at the points where the two regulatory frameworks meet, such as banking, custody, settlement and payment relationships. This makes it important to understand the regulatory status of banks, custodians and other CBUAE-regulated counterparties that form part of an investment manager’s operating and transaction chain, and how their Central Bank obligations interact with the CMA’s supervisory framework.
goAML FAQs, April 2024
Version 2.1 of the goAML FAQs, dated 18 April 2024, is the Financial Intelligence Unit’s question-and-answer aid for reporting entities using the goAML platform, together with its access and registration services. It works through the familiar sign-in and registration hurdles with step-by-step remedies: resetting a lost password, the proper login order, the pop-up seeking the system-issued username plus a Google Authenticator code, and one-time passwords that lapse at first login. It sets out where credentials go and whom to approach when errors persist. For a manager or custody desk, dependable access keeps a suspicious transaction report on time, sparing compliance needless delay.
PF Institutional Risk Assessment Guidance for FIs, DNFBPs and VASPs, December 2023
This December 2023 guidance lays out how a firm gauges and manages its proliferation financing exposure. Its methodology rests on residual risk, control effectiveness and inherent risk, and it names the categories and factors a manager weighs in scoring the book. The supporting measures are taken in turn: suspicious activity reporting, ongoing and transaction monitoring, screening for adverse media and sanctions, enhanced due diligence, and investor onboarding with know-your-customer checks. A customer risk scoring questionnaire, worked case studies, and a set of elevated risk factors show how the scoring lands. The guidance converts proliferation financing duty into a repeatable, supervisor-reviewable framework.
Terrorist and Proliferation Financing Red Flags Guidance, December 2023
At the core of the Terrorist and Proliferation Financing Red Flags Guidance, refreshed in December 2023, sits one consolidated set of indicators for spotting suspicious financing and attempts to dodge targeted financial sanctions imposed by United Nations resolutions or local designations. It describes how sanctioned parties mask their role through front companies, intermediaries and renaming, which helps a manager screen the beneficial owners behind nominee, feeder and pooled investors. The indicators are divided across trade finance and maritime, transaction activity, and account and customer profile. The guidance sharpens desk and compliance alike, guiding when investor or portfolio activity ought to prompt a report to the competent authorities.
Suspicious Activity and Transaction Reporting Thematic Review, January 2023
This January 2023 thematic review compresses, into expectations and findings, the AML/CFT examination run in 2022 across licensed financial institutions and designated non-financial businesses. It trains on the reporting framework for suspicious transactions and activity and on the monitoring systems feeding it, to be taken with existing guidance on screening, monitoring and reporting. Organised by expectation, it sets acceptable against deficient practice through the post-reporting process, reporting decisions, case investigation, alert review, data management, risk-based monitoring controls, policies and governance.
Counter Proliferation Financing Guideline, November 2022
Sitting on top of the wider Guidance on Targeted Financial Sanctions, this November 2022 guideline from the Executive Office for Control and Non-Proliferation heightens regulated firms’ alertness to proliferation financing threats. It defines proliferation financing, charts its stages, and sketches the relevant federal laws, the interagency mechanism and the UAE counter-proliferation framework. For a fund manager or custodian, it demonstrates how to weave proliferation financing risk into the house assessment and to apply mitigations: staff training, dual-use trade scrutiny, attention to shell and front companies among corporate subscribers, and enhanced due diligence on investors and transactions. Its red flags help surface attempted sanctions evasion.
goAML Web Submission Guide, July 2022
The goAML Web Submission Guide, released by the UAE Financial Intelligence Unit in July 2022, describes how a report reaches the FIU over the goAML platform. Its audience is the registered entity’s designated Compliance Officer or Money Laundering Reporting Officer, or the deputy when the lead is away. It steps through the report categories: the High Risk Country report, the Request for Information, the Additional Information File, and the Suspicious Activity Report, which captures suspected activity or a subscription or redemption attempted but never completed, alongside the Suspicious Transaction Report. For a fund manager or custodian, it standardises the prompt, correctly formatted filing of a suspicion.
Joint Guidance on Combating the Use of Unlicensed Virtual Asset Providers, March 2022
Providers working outside the licensing regime drive this March 2022 joint guidance from the UAE Supervisory Authorities, the Central Bank and the Securities and Commodities Authority among them. It reaffirms regulated firms’ anti-money laundering duties and steers the public to licensed entities only. Firms should stay alert, thread emerging risks into their assessments, apply adequate due diligence, spot investors gravitating to unlicensed providers, and report suspicions. Among the red flags: pressure to commit quickly, unrealistic promises or Ponzi arrangements, no physical presence, and no licence at all. For a fund manager, it tightens the screening of subscription flows brushing against unlicensed virtual-asset activity.
IEMS User Guide for Reporting Entities, March 2022
A hands-on manual from the UAE Financial Intelligence Unit for the Integrated Enquiry Management System, the IEMS User Guide for Reporting Entities is dated March 2022. It automates information requests, the execution of public prosecutions’ decisions and other calls from domestic authorities. The guide covers login and registration, firms already on goAML reusing those credentials, and takes in signatory, account-holder and account details through the attachments and reply workflow, request management and the dashboard. It assigns the Checker, Maker and Admin roles and presses firms to meet due dates and act at once on freeze orders. For a manager or custodian, it shows how an investor enquiry is handled.
goAML Pre-Registration Guide, March 2022
A firm cannot even open the goAML application to register and file until it holds access to the Services Access Control Manager, or SACM, and this March 2022 Pre-Registration Guide from the UAE Financial Intelligence Unit explains the route. For entities beyond Central Bank regulation, the application opens via a public portal; others take their Supervisory Body’s path. SACM holds the links to the testing and production environments and is locked behind a time-based one-time password from Google Authenticator. It addresses safeguarding a personal Secret Key, confirming intent and pre-registration itself. For a fund manager or custodian, sound pre-registration must come before any secure reporting access.
goAML Registration Guide, March 2022
Getting an organisation onto the FIU’s reporting platform is walked through, step by step, in the goAML Registration Guide of March 2022 from the UAE Financial Intelligence Unit. It addresses registration as a supervisory body, stakeholder or reporting entity, and states that each accountable and reporting entity in the UAE, under any regulator, must register before it can submit suspicious reports. It describes reaching the portal via the Services Access Control Manager, then selecting the registration type, keying in the organisation and its addresses, naming the registering person and assigning user access rights. For a fund or portfolio manager, clean registration is what all downstream reporting rests on.
Strategic Review on Targeted Financial Sanctions Case Studies, November 2021
This November 2021 Strategic Review on Targeted Financial Sanctions Case Studies examines UAE sanctions reporting across the period under review. It belongs to the regime whereby the country, under Cabinet Resolution No. 74 of 2020, enacts United Nations Security Council Resolutions targeting proliferation financing, terrorist financing and terrorism, including freezing, with bans on furnishing funds or services. After its method, the review sorts sanctions reports by the instruments involved, by suspicion and by source, surfacing the patterns that mark proliferation financing off from terrorist financing and supplying recommendations and red flags. It illustrates how concerns that a portfolio holding may involve a sanctioned person or entity are identified and reported.
Strategic Review on Targeted Financial Sanctions Case Studies, April 2024
The Strategic Review on Targeted Financial Sanctions Case Studies examines 33 TF and PF cases from 2019 to 2023, drawing out the methods, instruments, sources of information and typologies used to evade targeted financial sanctions. The cases show how illicit actors can use front companies, third parties, high-volume transfers involving high-risk jurisdictions, forged documents and investment structures to move or disguise funds linked to terrorist financing or proliferation financing. For investment management companies, the review provides practical risk indicators for investor due diligence, beneficial ownership checks, sanctions screening and monitoring of investment-related flows. It also calls on Financial Institutions to reflect the findings in their policies, controls, training and institutional TF/PF risk assessments, and to report identified sanctions-evasion, TF and PF activity promptly through goAML.
Typologies on the Circumvention of Targeted Sanctions, November 2021
Instances of sanctioned persons and entities trying to slip past targeted sanctions bound up with terrorism and weapons-of-mass-destruction proliferation are assembled in this Executive Office typologies report, last amended in November 2021. Working from public sources at home and abroad, it maps the methods deployed to evade the national terrorist list and United Nations resolutions. The typologies are ordered by sector and channel: economic resources, cyberactivity, intricate legal-entity structures, dual-use goods trading and online payment facilities, each carrying red flags and named networks. Here, sanctions evasion tactics become practical lessons for monitoring investor activity, conducting due diligence and strengthening screening.
Update to the List of High-Risk Jurisdictions, November 2021
Geographic risk begins with country lists, and this November 2021 decision of the National Anti-Money Laundering Committee updates the UAE’s lists of high-risk jurisdictions and jurisdictions under increased monitoring, replacing the March 2021 decision. It also specifies the countermeasures to be applied, requiring supervisory authorities to ensure firms apply proportionate due diligence to higher-risk jurisdictions. Accordingly, jurisdictions appearing on these lists require enhanced due diligence for investors and cross-border transactions, with business-wide risk assessments updated to reflect the latest changes.
Joint Guidance on Satisfactory and Unsatisfactory Practice, June 2021
Drawing on themes from inspections held between January 2020 and May 2021, this June 2021 joint guidance is issued by the UAE Supervisory Authorities, among them the Ministries of Justice and of Economy and Tourism, the Central Bank and the Securities and Commodities Authority, whose capital market mandate has since passed to the Capital Market Authority. It weighs satisfactory practice against unsatisfactory practice across counter-proliferation financing, targeted financial sanctions and the anti-money laundering framework. The guidance covers reporting, sanctions screening, transaction monitoring, due diligence, risk rating, monitoring and investor onboarding, plus the compliance officer role, training, policies, the three lines of defence, risk assessment and management oversight. Rendering findings as concrete examples, it lets a firm benchmark controls before the examiner.
Typologies on the Circumvention of TFS, PF and WMD, May 2021
Raising finance in breach or evasion of United Nations resolutions on terrorism and weapons-of-mass-destruction proliferation is the theme of this Executive Office typologies report, last amended in May 2021. It notes that targeted financial sanctions cover both the ban on placing funds or assets, directly or indirectly, at designated parties’ disposal and the freezing of assets. Sorted by financing method, it runs through the abuse of legal entities and arrangements, cyberattacks on financial institutions, online payment facilities, economic resources and trade in goods, ending with red flags. For fund managers, advisers and custodians, it hardens how attempted circumvention through investor accounts is screened, monitored and reported.
goAML FAQs, September 2020
After an organisation is registered and active on goAML, the recurring questions are collected, each with a stepwise answer, in the September 2020 goAML FAQs Guide from the UAE Financial Intelligence Unit, goAML being the channel for filing suspicious reports in the UAE. It walks through how the Money Laundering Reporting Officer, as admin, may hand reporting to a third party with Supervisory Body approval, how organisation details such as contacts, address, licensed activity and name are updated, and how a forgotten password is reset. The correct registration data and controlled access keep FIU reporting compliant and unbroken.
goAML Registration Guide Stage 2, September 2020
The goAML Registration Guide Stage 2, put out by the UAE Financial Intelligence Unit in September 2020, steps an organisation through registering on the FIU’s platform. Registration as a supervisory body, stakeholder or reporting entity is covered, and it confirms that each accountable and reporting entity in the country must register to file suspicious reports; since 27 June 2019, filing must be electronic through goAML. It runs through reaching the portal via the Services Access Control Manager, picking the registration type and enrolling an organisation. Proper registration is the route into lawful electronic reporting.
Guideline on Grievance Procedures
Requests for grievance linked to the UAE Local Terrorist List and the United Nations Consolidated List, jointly the Sanctions Lists, reach the Executive Office for Control and Non-Proliferation, and this Guideline on Grievance Procedures explains their handling. Under Cabinet Resolution No. 74 of 2020, three sorts arise: permission to use frozen assets, cancellation of freezing measures, and de-listing of a designation from the sanctions list, each hinging on whether the designation rests on the United Nations or the Local List. The procedures chart the lawful paths an affected investor may take to seek access to frozen securities and cash in a mandate or to contest a designation.
Online Grievance System User Guide
Designed to smooth submissions, the Executive Office for Control and Non-Proliferation’s online grievance system is set out step by step in this User Guide, the Office receiving grievance requests bound to the UAE Local Terrorist List and the United Nations Consolidated List, jointly the Sanctions Lists. It covers three online request types: permission to use frozen funds, cancellation of freezing measures, and de-listing. It steers the user through attaching documents, declaring earlier appeals and requests, choosing the grievance type, and identifying the aggrieved legal entity or individual. Holding an investor’s frozen cash and securities, it shows how that investor contests a designation or seeks access.
Simple Guide to Subscribe to the EOCN Notification Alert System (NAS)
Keeping sanctions data current is the point of this brief guide to the Notification Alert System hosted on the Executive Office’s website, delivering timely updates to the lists the UAE enforces. Targeted financial sanctions hinge on designations across two lists, jointly the Sanctions Lists: the United Nations Consolidated List issued by the Security Council and the UAE Local Terrorist List issued by the Cabinet, updated periodically. It shows where the lists sit and gives stepwise subscription steps, from the webpage through entering details to confirmation.
Emerging ML, TF and PF Risks and Trends in the Financial Sector
The Supervisory Subcommittee issues this report under Article 16 of Federal Decree-Law No. 10 of 2025 to hand regulated firms a live reading of the proliferation financing, terrorist financing and money laundering threats reshaping the sector as criminal methods, geopolitics and technology move. With scope and methodology set, it examines emerging risks: sanctions evasion linked to the Commonwealth of Independent States, trade finance abuse, greenwashing and ESG-related fraud, and the exploitation of artificial intelligence. Case studies cover fraudulent green schemes, free-zone corporate structures, trade-based laundering and money mule networks. Fund managers and custodians should feed these red flags and typologies into their detection systems and risk assessments.
Typologies in the Financial Sector
A joint product of the Supervisory Authorities Sub-Committee and the Financial Intelligence Unit, developed with a pilot group of institutions and the Executive Office, Typologies in the Financial Sector passes on corruption, fraud, sanctions, terrorist financing and money laundering typologies seen in the market, several emerging during the COVID-19 period, so firms can get ahead of risk. Ranked above the National Risk Assessment, it sets out the indicators that combine to disguise the real nature of transactions and notes links to human trafficking and modern slavery.
Is Your Business-Wide Risk Assessment CMA-Ready?
Examiners consistently flag generic, template-style risk assessments. We'll help you build one that reflects your actual funds, clients, and channels.
NRA, SRA, and Other Important Guidelines for Investment Management Companies in UAE
The UAE assesses its money laundering, terrorist financing and proliferation financing risk at the national level, and investment management companies must align their business-wide and enterprise-wide risk assessments with those findings.
UAE PF National Risk Assessment 2026
The UAE Proliferation Financing National Risk Assessment 2026 looks at how far the country is exposed to funding for weapons of mass destruction and to breaches of targeted financial sanctions imposed through United Nations resolutions on North Korea and Iran. Drawn up to meet the Financial Action Task Force revised Recommendation 1, it places the securities sector at low proliferation financing risk in the mainland and the financial free zones, while putting overall country risk at medium-high. These risk indicators show where screening and due diligence should respond more closely to the investors involved and the people who ultimately control them.
UAE ML and TF National Risk Assessment 2024
The UAE Money Laundering and Terrorist Financing National Risk Assessment 2024 is the second of its kind, built on the World Bank methodology and using data spanning 2019 to 2023. Its residual money laundering rating for the securities sector falls in the medium to medium-high band, reflecting the range of work spanning fund management, discretionary mandates, and custody, though it records the sector’s AML controls as effective. Both the mainland and the financial free zones fall within its scope. For an investment management company, it sets the starting point for a risk-based approach.
The ratings summarised in the table below are the residual risk figures a fund or portfolio manager should carry through into its own assessment.
| Capital market (securities) sector residual risk | Rating |
| Money laundering and terrorist financing (NRA 2024) | Medium to medium-high, with the sector’s AML controls assessed as effective |
| Proliferation financing (PF NRA 2026) | Low in both the mainland and the financial free zones |
Beyond the national picture, sector risk assessments, red flag material and typologies supply the granularity a manager relies on to keep both its enterprise-wide assessment and its customer risk assessment factors up to date and defensible.
CMA-Regulated Investment Management Sector-Specific Guidance
Above the federal framework sits a sector-specific layer that investment management companies apply directly: the Capital Market Authority rulebook chapter, its guidance, notices, thematic reviews and reporting standards. The instruments listed below form that layer.
Federal Decree-Law No. 32 of 2025 on the Capital Market Authority
The regulator a fund or portfolio manager answers to was constituted by Federal Decree-Law No. 32 of 2025. The law establishes the Capital Market Authority as the successor to the Securities and Commodities Authority and as the federal supervisor of securities, markets, and central clearing and depository institutions across the mainland and the free zones, but outside the Financial Free Zones. It defines Licensed Persons, Approved Persons and Self-Regulatory Organisations, and frames its objectives around market integrity, investor protection and systemic risk. Article 5 gives the Authority its powers to license, supervise, inspect, make rules and impose sanctions. For an investment manager, this is the statute from which the supervisor draws its authority.
Federal Decree-Law No. 33 of 2025 on the Regulation of the Capital Market
The activities a collective investment fund, its manager or an adviser may carry on only under licence are set out in Federal Decree-Law No. 33 of 2025, the substantive rulebook for securities work under the Authority. Asset management, investment funds and advisory business appear in the Article 3 list, alongside market operation, central clearing, central depository and custody services, and dealing. Performing any of these, or an approved function, without authorisation is barred. The law discusses securities, issuers, foreign issuers, investment funds, insiders and inside information, curbs insider dealing through prohibited dealing periods for listed persons, and sets out how a Licensed Person is settled, restructured or wound up.
CMA Key AML/CFT/CPF Obligations, Risks and Supervisory Observations, 2025
This 2025 letter from the Capital Market Authority, addressed to chief executives, gathers the AML, CFT and CPF obligations, the emerging risks and the supervisory observations that a fund or portfolio manager should act on. During the cycle, the Authority scored each firm’s inherent money-laundering, terrorist-financing and proliferation-financing exposure against its size, client base, products, distribution channels and geography, guided by the FATF Recommendations and the National Risk Assessment. Inspections, desk reviews, MLRO report reviews and thematic work surfaced repeat weaknesses for boards to remediate. Managers should track their reporting trends, screening outcomes and the beneficial-ownership data behind their investors, mindful that Article 17 carries enforcement.
CMA Instructions for the 2024 Annual Return AML/CFT and TFS Risk Assessment
Five tabs organise the annual AML, CFT and targeted financial sanctions return that these CMA instructions walk licensed firms through: customer risk, products and services risk, distribution channel risk, controls and the quality of mitigation, and signatories. Fund managers, portfolio managers, custodians and investment advisers must complete it in full, state monetary values in dirhams, and break down countries using standard names or codes. Inherent risk is assessed based on the investors behind subscriptions, securities business, correspondent relationships, payment forms, and onboarding channels. Against that sit the controls: the compliance officer, enhanced due diligence, transaction monitoring, sanctions screening and internal audit.
CBUAE AML and CFT Guidelines for Financial Institutions, July 2023
Even though the Central Bank issued these July 2023 guidelines, the Capital Market Authority points its firms to them for detailed expectations. The guidance sets out the risk-based approach and a business-wide risk assessment spanning customer, geographic, product and delivery-channel factors, then explains mitigation through internal controls and customer due diligence, including beneficial-owner identification, funds transfers and ongoing monitoring. In practice, it turns statutory duties, typologies and reporting obligations into workable benchmarks that support onboarding investors, verifying who sits behind pooled and nominee holdings, and monitoring subscription and redemption flows.
CMA Minimum Standards for the Semi-Annual AML and CTF Report, 2023
These 2023 minimum standards set out what belongs in the semi-annual report that a manager’s compliance officer and money laundering reporting officer must prepare. The report covers the half-years to 30 June and 31 December, goes to the board for review, and reaches the Capital Market Authority, with the board’s comments attached, within two months of each period end. Its prescribed contents run from an executive summary and governance through the enterprise-wide risk assessment, policies, customer risk rating and due diligence, and on to a gap analysis, action plan, findings and board sign-off. It serves as the periodic health check on the effectiveness of the AML programme as a whole.
CMA Implementation of Targeted Financial Sanctions, May 2022
Notice 1/2022, dated 19 May 2022, explains how licensed firms give effect to targeted financial sanctions arising from United Nations Security Council Resolutions 1718 of 2006 and 2231 of 2015, in line with Cabinet Resolution No. 74 of 2020. The steps follow a practical sequence: screen every investor and controller behind a subscription, apply enhanced due diligence where a mandate or fund touches the relevant countries, and watch cross-border movements that could mask trade in dual-use goods. A confirmed match calls for a Confirmed Name Match Report via goAML within five business days, a possible match for a Partial Name Match Report, and genuine suspicion for a suspicious transaction report to the Financial Intelligence Unit, all read with Executive Office guidance.
CMA Awareness of Cabinet Resolution No. 111 of 2022 on Virtual Assets and their Service Providers
Wherever a fund’s holdings, a custody arrangement or an investor touches virtual assets, Cabinet Resolution No. 111 of 2022 comes into play for a capital market firm. It regulates virtual assets and virtual asset service providers across the UAE, establishing a federal framework that sits beside the securities regime. The Resolution defines VASP activities, the licensing route and the supervisory perimeter. It also underpins the Authority’s own virtual-asset expectations and the UAE travel rule that follows on from it.
CMA Thematic Review on Reliance on Third Parties, December 2021
Dated December 2021, this second CMA thematic review looked at the five firms then licensed to provide custody of securities, each a bank or a local branch of a foreign bank under a Central Bank licence, and tested compliance with FATF Recommendation 17 on relying on third parties. Because custodians hold investors’ securities and cash and serve mostly institutional and offshore clients, they often outsource parts of customer due diligence. A twenty-one-question survey drew a complete response: four of the five used third parties, two inside their group and two outside, all regulated or listed and covered by service level agreements. Cost, specialist skill and technology explained the reliance, yet the custodian keeps ultimate responsibility.
CMA Thematic Review of Targeted Financial Sanctions in the Capital Market Sector, November 2021
Issued in November 2021, this CMA thematic review measured how well the capital market sector understands and applies international and domestic targeted financial sanctions under Cabinet Resolution No. 74 of 2020, a sector the National Risk Assessment rates at medium-high vulnerability. Firms answered a twenty-nine-question survey, with a ninety-six per cent response rate; about two-thirds kept a separate sanctions risk assessment, seventy per cent relied on third-party screening tools, and eighty-one per cent screened daily, while one firm detected, reported and froze a match during the year. For a fund or portfolio manager, the good-practice markers matter most: board approval of the sanctions framework, confirming that a vendor covers the UAE domestic lists, clear escalation lines, and continued Executive Office monitoring.
CMA AML and CFT Guidance for the Capital Market Sector, September 2021
Published in September 2021 as a supplement to the wider Financial Institutions Guidelines, this guidance records what the Securities and Commodities Authority expected of the firms it licensed, written for their boards, managers and staff. Its first part surveys the typologies the sector faces, from trade-based laundering through mis-invoicing and the misstatement of price, quantity or quality, to cash-based laundering, each with red-flag indicators. The later parts explain the risk-based approach, the business-wide risk assessment, and the customer, product, delivery-channel and geographical factors a firm must identify, weigh and mitigate.
CMA Notice 3/2021 on the Immediate Reporting Mechanism
Issued on 26 July 2021 to every licensed entity, Notice 3/2021 concerns the immediate reporting mechanism supporting Cabinet Resolution No. 74 of 2020 on the terrorism lists and the United Nations resolutions against terrorism, its financing and weapons-of-mass-destruction proliferation. Referring to Article 21(5) of that Resolution, which requires immediate reporting to the supervisory authority, it records an upgrade to goAML that routes reports of a matched investor name and the action taken straight to the Executive Office responsible for goods under import and export control. The goal is to build the mechanism into its screening procedures and revise its policies so a sanctions hit on a subscriber reaches the authorities without delay.
CMA Notice 4/2021 on Targeted Financial Sanctions Reporting
Following the July notice, Notice 4/2021 of 4 August 2021 set out how firms report targeted financial sanctions. Under Cabinet Resolution No. 74 of 2020, the Central Bank worked with the Executive Office of the Committee for goods subject to import and export control to build a single mechanism on the goAML platform. It introduced two reports: a Confirmed Name Match Report for a confirmed match and a Partial Name Match Report for a possible match, calling for suspension, both filed at once to the Executive Office and the Authority. The freezing obligation is not deferred to the reporting deadline: under Cabinet Resolution No. 74 of 2020, Article 21(3), a match must be frozen without delay and without prior notice to the designated party, and the Office must be notified within five business days of the freeze under Article 15(2).
CMA Notice 6/2021 on the Update to High Risk Jurisdictions
Issued on 22 November 2021 and replacing Notice 1/2021, CMA Notice 6/2021 updates the National Committee’s two lists, the High Risk Jurisdictions subject to a Call for Action and the Jurisdictions under Increased Monitoring, for all licensed firms. The notice requires firms to apply enhanced due diligence to any relationship or investment linked to a listed country, adopt the Recommendation 19 countermeasures for the Black List, and refresh the geographic risk scoring for the investors behind their funds and mandates. It cannot rely on third parties based in Black List jurisdictions, must file High Risk Jurisdiction reports through goAML, and should re-assess its measures, in proportion to each investor’s risk, when a country leaves a list.
SCA Board Chairman's Decision No. 21 of 2019 on AML and CFT Procedures
Before the current statutes, the sector framework ran through SCA Board Chairman’s Decision No. 21 of 2019. Signed by Sultan bin Saeed Al Mansouri and in force from 7 May 2019, a day before its 8 May issue, it brought anti-money laundering, counter-terrorism financing and illegal-organisation financing procedures to the capital market. Every firm licensed or approved by the Capital Market Authority, along with its stakeholders, must comply with the UAE AML framework and the Authority’s instructions, guidelines and circulars. The Authority can inspect firms, request information and impose administrative sanctions where requirements are not met. These powers apply across the capital market, including fund managers, portfolio managers and other regulated participants.
CMA Guidelines for Combating Money Laundering and Terrorist Financing (Chapter Five)
The binding AML rules for the sector live in Chapter Five of the Capital Market Authority rulebook, the Guidelines for Combating Money Laundering, Counter-Terrorism Financing and Funding of Illegal Organisations. Chapter Five requires each firm to build a compliance programme fitted to its own activities, risks and controls. It defines suspicious transactions, ultimate beneficial owners and targeted financial sanctions, and presses a proportionate, risk-based approach to due diligence that concentrates effort on higher-risk investors. It places responsibility with the board and senior management, makes suspicious-activity reporting a legal duty, and covers the screening, record-keeping and training a manager must embed.
CMA AML and Financial Crimes Framework and Controls: Good and Weak Practices
Good practices and common weaknesses in AML and financial-crime frameworks and controls appear side by side in this presentation by Mendy Ghaleb of the Capital Market Authority’s AML and Financial Crimes Department. Its expectations rest on Federal Decree-Law No. 10 of 2025, Cabinet Resolution No. 134 of 2025, the beneficial-owner, terrorism-list and sanctions decisions, and Chapter 5 of the CMA Rulebook. Field inspections and desk analysis expose recurring failings for fund and portfolio managers: generic business-wide risk assessments misaligned with activities, template risk-appetite statements lacking thresholds, and copied policies with thin board oversight. Article 17 of Federal Decree-Law No. 10 of 2025 lets the Authority issue warnings, fines from AED 10,000 to AED 5,000,000 per violation, sector bans and licence revocation.
CMA Obligations to Implement the Business-Wide Risk Assessment (BWRA)
The Capital Market Authority casts the Business-Wide Risk Assessment as the strategic foundation of an effective AML and CFT programme, and this material sets out the duty to run one. A firm must identify, understand and assess its full spread of money-laundering, terrorist-financing, sanctions and proliferation-financing risk, looking across client types, products, delivery channels, geographies and new technologies. The work moves through three phases: planning and scoping over business units, legal entities, divisions and regions; implementation, where inherent risk is measured with real data and controls are designed; and results, where residual risk is set against a risk-appetite statement and action plans.
CMA Thematic Review of Screening Systems
Screening is only as good as the system behind it, and this horizontal CMA review put the sector’s tools to the test under Federal Decree-Law No. 10 of 2025 and the FATF standards. Working from control, variation and clean datasets built out of United Nations and UAE sanctions lists, the Authority examined forty-six screening systems running at twenty-six Licensed Financial Institutions. The tools were embedded through fund and portfolio onboarding and monitoring and handled clear matches reliably, yet they stumbled on harder cases such as spelling variants and Arabic-Latin transliteration, a real concern when checking international investors and their controllers. High alert volumes pointed to tuning work. The Authority expects calibration, governance, management information, measures such as false-positive rates, and steady optimisation.
CMA Questions and Answers on the National Risk Assessment
Presented as questions and answers, this CMA material shows a manager how to line its enterprise-wide risk assessment up with the 2024 National Risk Assessment. It asks firms to map the assessment’s typologies onto their own business, such as taking on offshore special purpose vehicles, layering through securities trading, thin beneficial-owner records, and the misuse of nominee and shell structures behind investors. Even a firm that sees itself as low risk must read the assessment, record why it applies, and revisit it each year. The Authority wants an audit trail: a dated, updated assessment, revised onboarding, screening and third-party policies, training logs, board minutes and a gap analysis, with the changes carried into the annual AML Return and genuinely put into effect.
CMA Circular on the Examination Observations Report
Drawing on the annual AML, CFT and sanctions risk-assessment returns firms submit, this CMA circular publishes what examinations found, assessed on a risk basis. The recurring gaps read as a checklist for a fund manager to avoid: governance policies left out of date, sanctions controls that go untested, risk assessments that miss whole areas, thin customer due diligence and a shaky grasp of the beneficial owners behind investor accounts, sanctions programmes that lack the eight essential components, and weak suspicious-transaction procedures. The Authority expects remediation with board and audit involvement, and warns that breaches can bring administrative penalties and, at worst, licence cancellation. The statutory band runs from a warning through a fine of AED 10,000 to AED 5,000,000 per violation to revocation of the licence (Federal Decree-Law No. 10 of 2025, Article 17).
UAE Virtual Assets Travel Rule
Originator and beneficiary information must travel with every virtual-asset transfer under the UAE Virtual Assets Travel Rule, which binds virtual asset service providers across the federal, emirate and free-zone space. A fund or portfolio management business that deals in or advises on virtual-asset products, or holds them in custody, relies on it to know what information must accompany a transfer and what risk-based and enhanced due diligence is expected. The rule brings the UAE into line with the FATF travel-rule standard and governs how such a business documents and screens the virtual-asset movements passing through its investors’ holdings.
CMA Chapter Five Outreach
Chapter Five Outreach is the presentation-style companion to the binding Chapter Five rules, setting them out in plain terms. It takes a firm through the mandatory standards, shows how they rest on the federal AML laws, and explains how the Authority expects them to work in everyday practice. This is a practical reference for onboarding investors, monitoring activity across subscriptions and redemptions, and reporting, sitting alongside rather than replacing the binding Chapter Five guidelines.
CMA and FIU Joint Awareness Session on Suspicious Reporting Effectiveness
Run jointly by the Capital Market Authority’s AML and Financial Crimes Department and the Financial Intelligence Unit, this awareness session turns on the quality of suspicious reporting. After recapping the governing legislation, the duties that fall on financial institutions and the internal controls and governance the Authority looks for, it concentrates on what a useful report contains: complete, timely and reasoned suspicious transaction and activity reports filed through goAML, rather than defensive or low-value submissions made to tick a box. The report clarifies what strong reporting on unusual subscriptions, redemptions and investor behaviour should look like.
CMA Examination Observations, Appendix of Detailed Findings
Behind the headline review sit the detailed findings that this appendix to the CMA examination observations collects. Area by area, it records the weak and the better practices inspectors saw across capital market firms, running from governance and risk assessment through to sanctions screening and reporting. The examination doubles as a self-assessment checklist: read against your own programme, it exposes the very control gaps the regulator has already penalised in the sector, whether in investor onboarding, beneficial-ownership work or suspicious reporting.
Core AML Obligations for Investment Management Companies at a Glance
A CMA-regulated investment management company should operate a full, risk-based AML programme.
Concretely, that starts with a business-wide risk assessment mapped to the firm’s funds, mandates, clients, products and channels; runs through customer due diligence at investor and client onboarding, following the elements of the customer due diligence process, under Articles 6 to 15 of the Executive Regulations in Cabinet Resolution No. 134 of 2025, with enhanced due diligence for higher-risk clients under Article 12, politically exposed person measures under Article 16, and identification of the beneficial owners behind pooled, feeder, nominee and institutional investors under Article 9; establishes and tests the source of subscription and investment funds; keeps subscriptions, redemptions and portfolio activity under ongoing watch for unusual patterns; screens investors and their controllers against the UAE Local Terrorist List, the United Nations Consolidated List and other applicable sanctions lists, freezing and reporting at once on a match; installs a qualified compliance officer and money laundering reporting officer backed by the board; files suspicious transaction and activity reports through goAML without delay (Federal Decree-Law No. 10 of 2025, Article 18; Cabinet Resolution No. 134 of 2025, Articles 17 and 18) and without tipping off the customer (Article 19 of the Executive Regulations; Federal Decree-Law No. 10 of 2025, Article 29); and maintains record keeping under Article 25 of the Executive Regulations, staff training and the annual and semi-annual returns the Authority requires.
The board and senior management own this framework, and the Authority probes it through returns, examinations and thematic reviews.
Conclusion
For investment management companies, the regulatory framework joins up clearly: they are financial institutions under the UAE AML/CFT framework, their relevant capital market activities are supervised by the Capital Market Authority, and the applicable provisions of the federal AML legislation, its Executive Regulations, the targeted financial sanctions regime, UAE FIU reporting requirements through goAML, and the Authority’s rulebook and guidance all form part of their compliance framework. Their sharpest exposures lie in investor onboarding, the beneficial ownership behind pooled and institutional investors, the source of subscription money, sanctions screening, and the monitoring of subscriptions and redemptions. A manager that anchors its programme in the instruments above, refreshes its risk assessment and files promptly and accurately through goAML will comfortably meet both the letter and the spirit of the UAE regime.
FAQs
Which investment management companies are subject to AML rules in the UAE?
Fund managers, discretionary portfolio and asset managers, institutional and wholesale managers, and wealth and private client managers carrying on CMA-regulated activities outside the DIFC and ADGM fall within the UAE AML/CFT framework as Financial Institutions. They are subject to the applicable AML obligations and supervisory requirements. Firms in the DIFC and ADGM follow the separate DFSA and FSRA regimes.
Who supervises AML compliance for fund and asset managers outside ADGM and DIFC?
For investment management companies in the mainland and the commercial free zones, the AML and CFT supervisor is the Capital Market Authority, which succeeded the Securities and Commodities Authority under Federal Decree-Law No. 32 of 2025. It maintains the rulebook chapter, publishes guidance and notices, collects AML returns, conducts examinations, and levies penalties. For these CMA-regulated investment management activities, the Authority, rather than the Central Bank, oversees AML/CFT supervision.
How should a fund manager verify the beneficial owners behind pooled and feeder investors?
A fund manager should establish the ownership and control structure of corporate, institutional, pooled, nominee, and feeder-fund investors and identify the natural persons who ultimately own or control the customer, where required under the applicable CDD framework. Complex or offshore ownership structures may require enhanced due diligence and additional information to establish who ultimately controls or benefits from the investments. Where a regulated third party is relied upon for elements of CDD, the applicable legal conditions and the firm’s continuing responsibility should also be considered.
What source of funds checks are expected on subscriptions?
Managers should establish and, where risk requires, corroborate the source of the subscription and investment funds, and understand the investor’s source of wealth. Unexplained, third-party or high-risk funding should be treated as a red flag warranting enhanced measures. The depth of these checks should be proportionate to the investor’s risk profile and the size and nature of the subscription.
Do investment management companies need a business-wide risk assessment?
Yes. The federal AML framework requires Financial Institutions to conduct a business-wide risk assessment, while CMA-supervised firms are expected to maintain one as part of their AML programme. For an investment management company, an AML business risk assessment should cover its own funds, mandates, client types, products, distribution channels, and geographies; align with the national and sector risk assessments; and remain current and defensible, since the Authority checks it through returns and examinations.
How should managers treat exposure to virtual asset service providers?
Virtual asset activities are subject to a separate regulatory framework. Where an investment management company has exposure to virtual assets or virtual asset service providers, it should identify and manage the associated risks, apply enhanced due diligence where appropriate, and comply with applicable Travel Rule requirements. Treat dealings with unlicensed providers as higher risk and subject to closer scrutiny.
Are older SCA AML notices still relevant now that the CMA has replaced the SCA?
Yes. Existing SCA notices, decisions and guidance may continue to apply where they remain in force and are not inconsistent with the current Capital Markets legislation or subsequent regulations. Federal Decree-Law No. 10 of 2025, Article 41(3) is the authority for this: regulations, resolutions and circulars issued under the repealed Federal Decree-Law No. 20 of 2018 remain in force only so far as they do not conflict with the new statute, and only until they are replaced. A fund or wealth manager should continue to consider instruments such as SCA Board Chairman’s Decision No. 21 of 2019 and the 2021 notices, while reading references to the earlier AML framework in light of Federal Decree-Law No. 10 of 2025 and its Executive Regulations.
Expert tip
For an investment management company, one of the most important controls is looking beyond the investor’s name to understand who ultimately owns or controls the relationship. A subscription may come through a company, trust, nominee, feeder fund or institutional vehicle, making the underlying ownership and control structure less immediately visible. Build onboarding to establish and verify the beneficial owners where required, understand the source of subscription funds, and screen the relevant persons against applicable sanctions lists. Keep that ownership and control picture current throughout the life of the relationship, particularly when ownership, control, or investor structure changes. That is where gaps in CDD can become visible during examinations and thematic reviews.
Still Have Questions on CMA AML Rules?
Every fund manager's exposure looks a little different once you factor in feeder structures, institutional investors, and cross-border flows. Get a straight answer from someone who's done this before.
Share via :
About the Author
Pathik Shah
FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)
Pathik is an ACAMS-certified AML consultant specialising in governance, risk, and compliance for regulated entities in the UAE. He brings over 28 years of experience, with 1,000+ hours of AML training and 200+ advisory engagements across DNFBPs, VASPs, and FIs. He supports businesses in aligning with AML/CFT requirements from the CBUAE, DFSA, MoET, MoJ, VARA, CMA, FSRA, and FATF. Known for translating complex regulations into audit-ready procedures, Pathik enables operational clarity and compliance readiness.
Reach Out to Pathik