AML Training in UAE

AML training is the ongoing programme that teaches your people to recognise money laundering, terrorism financing, and proliferation financing risk, and to act on it correctly. In the UAE it is not optional. Article 21 of Cabinet Resolution No. 134 of 2025 requires reporting entities to maintain continuous training and development programmes for employees, and supervisors expect you to prove the training happened. We deliver that AML training programme, role by role, with the records that make it defensible.

Here is how inspections actually test it. The inspector rarely starts with your compliance officer, who knows the answers. They ask a sales agent red flags related to money laundering, terrorist financing, and proliferation financing. What they would do if a buyer’s name flagged on a screening list. If the answer is a shrug, no policy document on the shelf will save the finding. Under Article 17 of Federal Decree-Law No. 10 of 2025, that gap can cost between AED 10,000 and AED 5,000,000 per violation, with no money laundering required.

Trained people. Evidenced records.

Get role-based AML/CFT/CPF training built on your risk assessment and your sector's real red flags.

What Is AML Training?

In legal terms, it is the continuous training and development programme your business must maintain so that employees understand the money laundering, terrorism financing, and proliferation financing risks they encounter and the controls they are expected to operate [Cabinet Resolution No. 134 of 2025, Article 21]. Your supervisor, auditor, or bank may call it AML/CFT training, AML awareness training, anti-money laundering training, AML compliance training, or AML/CFT/CPF training. Whatever the label, it is the same obligation: your people, trained to their role, with proof.

Effective AML training does three things a slide deck cannot. It converts legal obligations into decisions a specific person makes at a specific moment, such as what to ask when the source of funds sounds implausible. It gives staff the escalation route, so a concern reaches the compliance officer instead of dying in a corridor conversation. And it produces evidence: attendance, content, assessment, dates, retained and retrievable.

One point most firms miss: training is the only AML control an inspector can test without reading a single document. They simply talk to your staff. That makes it the fastest way to fail an inspection, and the fastest to pass one.

Is AML Training Mandatory in the UAE?

Yes, for every financial institution, DNFBP, and VASP within the scope of the Executive Regulations. Article 21 of Cabinet Resolution No. 134 of 2025 requires ongoing employee training and development programmes on ML, TF, and PF, together with an independent audit function to test whether the programme works. The duty sits inside the wider preventive framework of Article 19 of Federal Decree-Law No. 10 of 2025, which makes the risk-based approach and its internal controls mandatory, and it connects directly to Article 22, which requires your compliance officer to have appropriate competence. Competence is not assumed; it is developed and evidenced.

Training also carries a second, quieter function. Article 5(2) of Cabinet Resolution No. 134 of 2025 requires you to monitor implementation of your policies and assess their effectiveness. Staff who cannot describe a control are evidence that it is not implemented, and your own training assessments are one of the few tools that surface that gap before a supervisor does.

Not sure your last training session would satisfy an inspector?

Send us your most recent attendance register and agenda, and we will tell you what is missing against Article 21, with no obligation.

The UAE Laws Your AML Training Must Reflect

Every curriculum we build is mapped to the instruments that create the duty and set the content: 

Legal InstrumentWhat It DoesWhat It Means for Your Training
Federal Decree-Law No. 10 of 2025 The primary AML/CFT/CPF statute, in force 14 October 2025, repealing FDL No. 20 of 2018 (Article 41). Sets preventive obligations (Article 19), STR reporting duties (Article 18), supervisory powers (Article 16), administrative penalties of AED 10,000 to AED 5,000,000 per violation (Article 17), and criminal penalties (Articles 26 to 35). The legal module of every session. Staff learn the offences, the objective knew or ought to have known standard, the reporting duty, and what non-compliance costs the business and them personally.
Cabinet Resolution No. 134 of 2025 The Executive Regulations, effective 14 December 2025. Mandates ongoing training and independent audit (Article 21), the compliance officer's competence (Article 22), senior-management-approved controls with monitored implementation (Article 5), CDD and thresholds (Articles 6 to 9), PEPs (Article 16), tipping-off rules (Article 19), and record keeping (Article 25). This is the syllabus in law: what the training must cover, who must be competent, and how long the training records must be kept.
Cabinet Decision No. 74 of 2020 The targeted financial sanctions framework: screening against UN and UAE Local Terrorist Lists, freezing without delay, and reporting to the Executive Office for Control and Non-Proliferation (EOCN). The sanctions module: what a screening hit means, why a freeze cannot wait for a manager's holiday to end, and who reports to the EOCN.
Cabinet Resolution No. 71 of 2024 The administrative penalty schedule for DNFBPs supervised by the MoET and MoJ: 41 listed violations with fines of AED 50,000 to AED 1,000,000, which the ministry may double where the same violation recurs within one year. Turns training from a cost into a number. Staff and owners see exactly which failures are penalised and what the repeat multiplier does.
Cabinet Resolution No. 109 of 2023 Real Beneficiary Procedures: the beneficial ownership register, the 25% threshold, and update deadlines. The beneficial ownership module, including the fifteen-working-day update discipline the front line often breaks without realising.
Sectoral guidance issued by supervisory authorities Supervisory expectations issued by the CBUAE, CMA, DFSA, FSRA, MoET, MoJ, GCGRA, and VARA, including the MoET Guidelines for DNFBPs (September 2025), plus the National Risk Assessment and Sectoral Risk Assessment. Your supervisor's own expectations and the national risk picture, so the red flags taught are the ones your regulator is looking for.

Entities in the DIFC and ADGM follow the DFSA AML Module and FSRA AML Rulebook respectively, layered on the federal framework, each with its own training and awareness requirements and MLRO regime. We deliver to whichever rulebook governs your licence.

Need your annual AML training delivered in Arabic?

No worries. We speak your language.

Who Needs AML Training?

The obligation covers employees, but the content should not be identical for all of them. We build the programme in tiers:

Board and senior management.

A short, focused briefing on accountability: what they approve, what they oversee, the risk appetite they are endorsing, and the questions a supervisor will put to them directly. This is the session most often skipped and the one with personal consequences attached.

[Cabinet Resolution No. 134 of 2025, Article 5(2)(a)]

Compliance officer and MLRO.

Deeper technical training on risk assessment methodology, CDD and EDD decisions, screening disposition, STR drafting and goAML filing, and the evidence trail their own role must leave behind.

[Cabinet Resolution No. 134 of 2025, Article 22]

Front-line and customer-facing staff.

Sales agents, brokers, relationship managers, tellers, and reception: identification and verification in practice, the questions to ask, the red flags in their sector, and the escalation route. No legal theory they will never use.

Support functions.

Finance, operations, HR, and IT, whose systems, payments, and records carry AML consequences even though they never meet a customer.

New joiners.

Induction training before or as they assume duties, not at the next annual cycle. An untrained new starter onboarding customers is a control gap from day one.

The scope of who is caught by the obligation follows the Executive Regulations: banks and financial institutions carrying out the fourteen listed financial activities [Article 2]; DNFBPs including real estate brokers and agents, dealers in precious metals and stones, lawyers and notaries, independent accountants, company and trust service providers, and commercial gaming operators [Article 3]; and virtual asset service providers [Article 4].

What Your AML Training Must Cover

A defensible curriculum is not a tour of the law. It is the set of things your people must be able to do, each traceable to a legal provision:

The UAE legal framework.

FDL No. 10 of 2025 and Cabinet Resolution No. 134 of 2025 in plain language: the offences, the objective knowledge standard, proliferation financing as a standalone offence, and the penalties.

Your own risk assessment.

The ML/TF/PF risks your business actually carries, drawn from your Enterprise-Wide Risk Assessment and mapped to the National and Sectoral Risk Assessments, so staff learn your risks and not a textbook’s.

[Cabinet Resolution No. 134 of 2025, Article 5(1)]

Customer due diligence in practice.

Identification and verification, the AED 55,000 and AED 3,500 thresholds where they apply, and ongoing monitoring across the relationship.

[Cabinet Resolution No. 134 of 2025, Articles 6 to 9]

Enhanced due diligence and high-risk situations.

What triggers EDD, source of funds and source of wealth questioning, and the senior management approval that must precede a high-risk relationship.

[Cabinet Resolution No. 134 of 2025, Article 5(2)(c)]

Beneficial ownership.

The 25% test, the fallback cascade to persons exercising control and then senior management, and how nominee and layered structures obscure it.

[Cabinet Resolution No. 134 of 2025, Article 10; Cabinet Resolution No. 109 of 2023]

PEPs, sanctions, and TFS.

Identifying politically exposed persons, their families and close associates; screening against UN and UAE Local Terrorist Lists; freezing without delay; and reporting to the EOCN.

[Cabinet Resolution No. 134 of 2025, Article 16; Cabinet Decision No. 74 of 2020]

Sector red flags and typologies.

Real cases and indicators from your industry, because a rapid buy-and-sell pattern in gold and a third-party payment on a property deal are not the same lesson.

Escalation, STR reporting, and tipping off.

The internal route, the compliance officer’s decision, filing through goAML under Article 18 of FDL No. 10 of 2025, and the absolute prohibition on telling the customer.

[Cabinet Resolution No. 134 of 2025, Article 19]

Record keeping.

What staff must capture and retain, why five years is the floor, and why records must be retrievable promptly on request.

[Cabinet Resolution No. 134 of 2025, Article 25]

How Often Is AML Training Required, and How Do You Prove It?

Article 21 requires training to be ongoing, which in practice means an annual cycle for all staff plus event-driven sessions. Five triggers should force training outside the annual calendar: a change in the law or your supervisor’s guidance, a new product, market, or delivery channel, a new joiner or an internal role change, an audit or inspection finding, and a material update to your risk assessment.

Proof matters as much as delivery. For every session we hand you the evidence pack a supervisor asks for: the attendance register with signatures or system logs, the agenda and materials delivered, the date and duration, the trainer and their credentials, and assessment results where a test is used. These are retained with your AML records for at least five years and must be retrievable promptly on request [Cabinet Resolution No. 134 of 2025, Article 25]. Training you cannot evidence is, for inspection purposes, training that never happened.

What Non-Compliance Costs in the UAE

Administrative penalties.

Fines from AED 10,000 to AED 5,000,000 per violation, plus warnings, licence suspension or cancellation, restrictions on responsible individuals, and public naming. Inadequate training is punishable in itself, with no money laundering required.

[Federal Decree-Law No. 10 of 2025, Article 17]

The DNFBP penalty schedule.

Forty-one listed violations at AED 50,000 to AED 1,000,000 for MoET and MoJ supervised businesses, which the ministry may double where the same violation recurs within one year.

[Cabinet Resolution No. 71 of 2024]

The indirect cost.

Untrained staff do not just fail interviews. They miss the red flag that becomes an unreported suspicious transaction, and an unreported STR carries far heavier consequences than a training gap.

[Federal Decree-Law No. 10 of 2025, Article 18]

Personal liability.

Senior management carries explicit responsibility for approving the framework and overseeing its implementation, and executives can face personal consequences where supervision failures contribute to violations.

[Cabinet Resolution No. 134 of 2025, Article 5(2)(a)]

Does your work keep you on your toes?

Different timezone, busy showroom, client meetings back to back, we get it. That's why ProAML Training moves with you. Learn on your phone, your laptop, or wherever you are, at your own pace, on your own time.

AML Training Matrix by Role

We deliver training in the format that fits how your business actually operates, in person at your premises or live online for multi-branch and remote teams. Recorded modules are available for induction and refreshers where attendance and assessment can still be evidenced.

Participant groupTraining objective / Core topicsRecommended timing / DurationAssessment method / Evidence to retain
Board and senior management
Training objective

Enable effective oversight of the AML/CFT/CPF framework and informed approval of risk-based controls.

Core topics

Governance responsibilities, risk appetite, Enterprise-Wide Risk Assessment, material compliance risks, adequacy of resources, significant breaches, STR governance, regulatory developments, management information.

Recommended timing

On appointment, annually, after major legal, regulatory or business changes.

Duration

60 to 90 minutes

Assessment method

Scenario discussion, acknowledgement of responsibilities, short knowledge check.

Evidence to retain

Attendance record, presentation, board briefing note, acknowledgement, assessment results.

Compliance officer and MLRO
Training objective

Develop the technical competence required to operate, oversee and evidence the AML/CFT/CPF programme.

Core topics

EWRA, customer risk assessment, CDD and EDD, beneficial ownership, PEPs, sanctions and TFS, transaction monitoring, internal escalation, STR/SAR decision-making, goAML reporting, record keeping, regulatory inspections.

Recommended timing

On appointment, at least annually, whenever laws, guidance, systems or risks change.

Duration

3 to 6 hours, depending on scope

Assessment method

Technical case studies, written assessment, report-drafting exercise.

Evidence to retain

Attendance, course materials, assessment and score, case-study responses, trainer credentials, certificate.

Deputy MLRO and compliance team
Training objective

Support consistent case handling, investigation and regulatory reporting.

Core topics

Alert review, false-positive disposition, EDD, source of funds and source of wealth, adverse media, investigation documentation, internal reports, STR drafting, tipping-off controls, audit trail.

Recommended timing

On joining the role, annually, after material process or system changes.

Duration

2 to 4 hours

Assessment method

Case-based assessment, practical file review.

Evidence to retain

Attendance, agenda, completed exercises, assessment results, remedial actions.

Front-line and customer-facing employees
Training objective

Help employees identify risk indicators, obtain required information and escalate concerns promptly.

Core topics

Customer identification, verification, purpose of relationship, beneficial ownership, sector red flags, unusual customer behaviour, third-party payments, PEP and sanctions alerts, internal escalation, tipping off.

Recommended timing

Before or when assuming customer-facing duties, annual refresher, trigger-based sessions.

Duration

90 to 150 minutes

Assessment method

Role-specific scenarios, multiple-choice assessment, verbal questioning.

Evidence to retain

Attendance, materials, assessment results, acknowledgement of escalation procedure.

Sales agents, brokers and relationship managers
Training objective

Integrate AML controls into customer acquisition and transaction handling without creating avoidable commercial disruption.

Core topics

Customer and transaction risk, high-risk customers, payment red flags, unexplained urgency, complex structures, source of funds, customer resistance, escalation before completing a transaction.

Recommended timing

On joining, annually, when products, markets or thresholds change.

Duration

90 to 120 minutes

Assessment method

Sales scenarios, decision-tree exercise, knowledge test.

Evidence to retain

Attendance, scenario responses, assessment scores, red-flag guide issued.

Customer onboarding and KYC teams
Training objective

Ensure accurate and risk-based completion of CDD, EDD and customer risk assessment.

Core topics

Identification and verification, legal persons and arrangements, UBO determination, ownership and control, document reliability, PEPs, sanctions screening, customer risk scoring, EDD, periodic review.

Recommended timing

Before independently processing files, annual refresher, after form, policy or system changes.

Duration

2 to 4 hours

Assessment method

Mock customer file, document-review exercise, written assessment.

Evidence to retain

Attendance, sample-file results, assessment, quality-review findings, certificate.

Finance and accounts teams
Training objective

Identify AML risks arising from receipts, payments, refunds and accounting records.

Core topics

Third-party payments, split payments, unusual refunds, overpayments, cash transactions, inconsistent payer details, payment routing, record keeping, internal escalation.

Recommended timing

On joining, annually, after payment-process changes.

Duration

60 to 120 minutes

Assessment method

Transaction scenarios, knowledge check.

Evidence to retain

Attendance, materials, assessment, payment red-flag checklist.

Operations and administration teams
Training objective

Recognise operational activity that may indicate control failure or suspicious behaviour.

Core topics

Record keeping, document retention, transaction processing, customer-data changes, ownership changes, unusual instructions, exception handling, escalation.

Recommended timing

On joining, annually, after process changes.

Duration

60 to 90 minutes

Assessment method

Scenario-based quiz.

Evidence to retain

Attendance, assessment, operating checklist, acknowledgement.

Screening and sanctions analysts
Training objective

Ensure sanctions, PEP and adverse-media alerts are handled consistently and promptly.

Core topics

List coverage, name matching, false and potential matches, ownership and control, escalation, freezing requirements, reporting, ongoing screening, record keeping, audit trail.

Recommended timing

Before independent alert handling, periodic technical refreshers, after list, system or guidance changes.

Duration

2 to 4 hours

Assessment method

Alert-disposition exercise, practical assessment.

Evidence to retain

Attendance, completed alerts, assessment, quality-assurance results, trainer credentials.

Transaction monitoring analysts
Training objective

Improve the quality and consistency of alert investigation and escalation.

Core topics

Monitoring scenarios, expected activity, investigation steps, linked transactions, customer profile, documentation, closure rationale, escalation, STR indicators.

Recommended timing

Before independent case handling, annually, after scenario or system changes.

Duration

2 to 4 hours

Assessment method

Alert-investigation case study, written rationale.

Evidence to retain

Attendance, investigation exercise, score, QA feedback, remedial plan.

Human resources
Training objective

Ensure AML obligations are incorporated into recruitment, induction, competence and disciplinary processes.

Core topics

Employee screening, fit and proper considerations, training assignment, new-joiner induction, role changes, attendance monitoring, breaches, disciplinary escalation, training records.

Recommended timing

On joining the function, annually, after HR-process changes.

Duration

60 to 90 minutes

Assessment method

Process walkthrough, short quiz.

Evidence to retain

Attendance, assessment, induction checklist, training tracker.

IT and system administrators
Training objective

Enable secure and reliable operation of AML systems and protect the integrity of compliance data.

Core topics

System access, role-based permissions, audit logs, data quality, system changes, screening and monitoring feeds, cybersecurity incidents, record retention, escalation of system failures.

Recommended timing

On joining the role, annually, before major system changes.

Duration

60 to 120 minutes

Assessment method

System-control walkthrough, scenario exercise.

Evidence to retain

Attendance, materials, assessment, access-control acknowledgement.

Internal audit and assurance personnel
Training objective

Enable independent evaluation of the design and operating effectiveness of AML controls.

Core topics

Risk-based audit planning, testing methodology, sampling, governance, CDD and EDD, screening, monitoring, STR controls, training evidence, issue grading, remediation validation.

Recommended timing

Before AML audit work, periodic technical refresher, after regulatory change.

Duration

2 to 4 hours

Assessment method

Audit-planning case, control-testing exercise.

Evidence to retain

Attendance, assessment, sample audit programme, completed exercise.

New joiners
Training objective

Provide basic awareness before employees undertake activities that may expose the entity to AML/CFT/CPF risk.

Core topics

AML/CFT/CPF fundamentals, employee responsibilities, relevant red flags, internal escalation, confidentiality, tipping off, consequences of non-compliance.

Recommended timing

Before or when assuming duties, followed by role-specific training.

Duration

45 to 90 minutes

Assessment method

Basic knowledge check, acknowledgement.

Evidence to retain

Attendance or LMS record, assessment, signed acknowledgement, certificate.

Employees moving into higher-risk roles
Training objective

Ensure competence before expanded responsibilities begin.

Core topics

Role-specific risks, relevant controls, approval limits, escalation duties, systems, reporting and documentation.

Recommended timing

Before or immediately upon the role change.

Duration

60 to 180 minutes

Assessment method

Role-based assessment.

Evidence to retain

Attendance, assessment, manager confirmation, updated training record.

Employees requiring remedial training
Training objective

Correct identified knowledge or control weaknesses.

Core topics

Topics linked to the audit finding, assessment failure, quality-review issue, breach or incident.

Recommended timing

Promptly after the weakness is identified.

Duration

Based on deficiency

Assessment method

Reassessment, supervised case exercise.

Evidence to retain

Finding, remedial materials, attendance, reassessment results, closure evidence.

All employees
Training objective

Maintain general awareness of emerging risks and changes affecting the business.

Core topics

Regulatory updates, new typologies, internal incidents, policy changes, new products, emerging sanctions risks, lessons from audits and inspections.

Recommended timing

Annual refresher plus event-driven updates.

Duration

60 to 120 minutes

Assessment method

Technical case studies, written assessment, quiz,

Evidence to retain

Attendance, course materials, assessment and score, case-study responses, trainer credentials, certificate.

Not sure which sessions your team needs?

A 15-minute call is usually enough. Tell us your licence and headcount and we will map the training plan, the tiers, and the annual cycle.

Sector-Specific AML Training

The legal duty is identical across sectors. The content should not be, because the risks are not:

Real estate brokers and agents.

Third-party payments, cash deals, complex ownership structures, cross-border buyers, and the REAR reporting obligation, taught so agents in every branch know when to raise an internal alert.

Dealers in precious metals and stones.

The AED 55,000 cash threshold, rapid buy-and-sell patterns, split payments, opaque beneficial ownership, and DPMSR reporting, delivered at the pace of a trading floor.

Trust and company service providers.

Nominee arrangements, layered offshore structures, purpose and rationale questioning, and monitoring triggers for ownership changes.

Lawyers, notaries, and legal professionals.

When a matter triggers DNFBP obligations and when it does not, client and matter risk assessment, and escalation that a fee earner will actually use, aligned to Ministry of Justice expectations.

Accounting and auditing firms.

Client risk assessment inside professional workflows, engagement acceptance red flags, and record keeping that satisfies MoET expectations without creating bureaucracy.

Banks and financial institutions.

Transaction monitoring alerts, correspondent and cross-border exposure, PEP handling at scale, and STR quality, aligned to CBUAE expectations.

Virtual asset service providers.

Travel Rule obligations, wallet and chain analytics indicators, the AED 3,500 occasional transaction threshold, and speed-of-transaction risk, aligned to VARA or your federal supervisor.

Commercial gaming operators.

Player due diligence, rapid fund movement, player behaviour indicators, and reporting readiness under GCGRA expectations.

How We Deliver Training

1. Training needs assessment.

We review your licence, supervisor, risk assessment, organisation chart, and any inspection findings, then map which roles need what, and how often.

2. Curriculum design.

We build the syllabus around your risks and sector typologies, tiered by role, with your own policies and escalation routes embedded so staff learn your framework rather than a generic one. [Cabinet Resolution No. 134 of 2025, Article 21]

3. Delivery.

In person or live online, case-led and interactive, with scenarios drawn from your business. Sessions are sized for attention, not for a certificate.

4. Assessment.

Short role-relevant tests that show comprehension, giving you a measurable result and an early warning where a control is not understood.

5. Records and evidence pack.

Attendance register, agenda, materials, dates, trainer credentials, assessment results, and certificates, packaged for your AML records. [Cabinet Resolution No. 134 of 2025, Article 25]

6. Annual plan and refresh.

A training calendar for the year with the triggers that force sessions outside it, and content refreshed when the law, your supervisor’s guidance, or your business changes.

7. Validation

We walk the draft through with your team to confirm it fits how the business actually runs, not how an org chart says it does.

8. Independent quality review

A second qualified reviewer checks the framework before it reaches you.

9. Senior management approval and rollout

We prepare the AML policy document for the senior management sign-off the law requires, evidence the approval, and support you in briefing the staff who will live with the manual. [Cabinet Resolution No. 134 of 2025, Article 5(2)(a)]

What Is Included in Our AML Training Service?

You receive

What it does

Tailored curriculum and materials

Built on your risk assessment, sector typologies, and your own policies, not a stock deck

Role-based sessions

Separate content for board, compliance officer, front line, support functions, and new joiners

Sector red-flag guides

Practical indicator sheets your staff can keep at their desk

Assessment and results summary

Comprehension tested and scored, with weak areas flagged for follow-up

Attendance register and training records pack

The evidence a supervisor asks for, retained with your AML records for at least five years

Certificates of completion

Issued to each participant for their personal file

Annual training calendar

Who is trained, on what, and when, with event-driven triggers built in

Post-training support

Follow-up questions answered, and remedial sessions where an audit or inspection identifies a gap

What We Need from You

What Happens Next

01

Scoping discussion

02

Written training plan

03

Curriculum approval

04

Delivery and assessment

05

Certificates and evidence pack

Why AML UAE: Training Experience You Can Verify

We are an AML consulting firm working only on AML/CFT compliance in the UAE, and training is where our practitioners spend a large share of their year:

3,000+

hours of AML/CFT/CPF training delivered

750+

professionals trained on AML/CFT/CPF compliance

50+

webinars and knowledge-sharing sessions hosted

500+

published articles, infographics, and educational booklets, including our widely read analyses of FDL No. 10 of 2025 and Cabinet Resolution No. 134 of 2025

300+

AML compliance projects across FIs, DNFBPs, and VASPs, which is where the case studies in every session come from

Scale matters in training because reach is the whole point. For one real estate engagement we enabled REAR reporting and trained more than 650 agents, which is what the obligation looks like when it actually reaches the front line rather than stopping at head office.

The Practitioners Who Deliver Your Training

Sessions are delivered by working AML consultants, not career trainers, so the cases are real and the answers hold up under follow-up questions:

Pathik Shah

CAMS, FCA, CS, CISA, DISA (ICAI), FAFP (ICAI)

Experience

28+ years

Regulatory Coverage

MoET, MoJ, CBUAE, CMA, FSRA, DFSA, VARA · AML/CFT framework design, RegTech

Jyoti Maheshwari

CAMS, ACA

Experience

11+ years

Regulatory Coverage

MoET, MoJ, CBUAE, CMA, FSRA, DFSA, VARA · AML/CFT/CPF framework, health checks

Dipali Vora

CAMS, ACS

Experience

10+ years

Regulatory Coverage

MoET, MoJ, CBUAE, CMA, FSRA, DFSA, VARA · Consulting, training, implementation

Monika Shah

CAMS

Experience

3+ years

Regulatory Coverage

MoET, MoJ, CBUAE, CMA, FSRA, DFSA, VARA · managed KYC, consulting, goAML reporting

Every curriculum carries a named reviewer and a review date, and we are straight about scope: how much training your business needs depends on your licence, headcount, risk profile, and supervisor, and we will tell you plainly what you need and what you do not.

Training Engagements Across UAE Sectors

A real estate group taking training to the branches

Head office was trained; the branches were not, which is where the customers are. We ran role-based sessions for more than 650 agents alongside the REAR reporting workflow, so a broker who spots a third-party payment knows precisely who to tell and what to write down. The compliance officer gained a pipeline of internal alerts instead of a blind spot.

A DNFBP after an inspection finding

The finding was not the absence of training but the absence of proof: sessions had run without registers or assessments. We rebuilt the curriculum against Article 21, re-delivered by role, and handed over an evidence pack with attendance, agendas, and scored assessments, documented as corrective action for the supervisor.

A VASP training ahead of supervision

A young team, fast transactions, and a regulator paying attention. Training covered Travel Rule obligations, chain and wallet indicators, and the escalation route, tested by assessment so the compliance officer knew which topics needed a second pass before the business went live.

FAQs on AML Training in the UAE

Yes. Article 21 of Cabinet Resolution No. 134 of 2025 requires reporting entities to put in place ongoing training and development programmes for employees on money laundering, terrorism financing, and proliferation financing, alongside an independent audit function to test the programme. Failure to train is independently punishable with administrative penalties of AED 10,000 to AED 5,000,000 per violation under Article 17 of Federal Decree-Law No. 10 of 2025, and for DNFBPs it appears in the penalty schedule under Cabinet Resolution No. 71 of 2024.

Everyone whose role touches customers, money, or records, not only the compliance team. In practice that means the compliance officer or MLRO, senior management and the board who approve and oversee the framework, front-line staff who onboard customers and take payments, and support functions such as finance, operations, and IT. Training should be role-based, because a receptionist, a sales agent, and a board member each need a different version of the same obligation.

The law requires training to be ongoing, so annual refresher training is the practical baseline for all staff. On top of that, training is triggered by events: induction for new joiners before or as they assume duties, a briefing when the law or your supervisor’s guidance changes, a session when you launch a product or enter a new market, and remedial training after an audit or inspection finding.

At minimum: the UAE legal framework under Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025, your own risk assessment and risk-based approach, customer due diligence and enhanced due diligence, beneficial ownership to the 25% standard, PEP handling, targeted financial sanctions and freeze obligations, sector-specific red flags, the internal escalation route, suspicious transaction reporting through goAML, the prohibition on tipping off, and record keeping duties.

Attendance registers, the training content or agenda delivered, dates, the trainer, and assessment results where a test is used, retained for at least five years and retrievable promptly on request (Cabinet Resolution No. 134 of 2025, Article 25). Training you cannot evidence counts, in an inspection, as training that did not happen.

Yes, provided it is relevant to the role, delivered to the people who actually need it, and evidenced with attendance and assessment records. What supervisors challenge is not the format but the substance: a generic deck emailed to all staff with no attendance record, no assessment, and no sector-specific typologies will not satisfy Article 21.

Yes. Participants receive a certificate of completion, and you receive the full training records pack: attendance register, agenda, assessment results, and a summary you can hand to an auditor or inspector. Separately, professional credentials such as CAMS are awarded by their own certifying bodies and are not the same as the entity training obligation the law places on your business.

The legal duty is the same, but the content should not be. Red flags, customer types, and thresholds differ sharply between a real estate brokerage, an exchange house, a law firm, and a virtual asset service provider, and supervisory expectations differ with them. We build the curriculum around your sector’s typologies and your own risk assessment rather than a single generic syllabus.

Yes, and it is the session most often skipped. Senior management approves the internal policies, controls, and procedures and oversees their implementation [Cabinet Resolution No. 134 of 2025, Article 5(2)(a)], and can face personal consequences where supervision failures contribute to violations. Board-level briefings are short, focused on accountability, risk appetite, and the questions a supervisor will ask them directly.

They should be trained before or as they assume duties, not at the next annual session. A new employee who onboards a customer without knowing your escalation route is a control gap from day one, which is why induction training and its attendance record form part of the programme we set up.

Administrative penalties run from AED 10,000 to AED 5,000,000 per violation under Article 17 of Federal Decree-Law No. 10 of 2025, alongside warnings, licence restrictions, and public naming. For DNFBPs supervised by the MoET and the Ministry of Justice, inadequate training sits within the 41 listed violations carrying AED 50,000 to AED 1,000,000 under Cabinet Resolution No. 71 of 2024, which the ministry may double where the same violation recurs within one year.

Yes. DIFC firms are Relevant Persons under the DFSA AML Module, which sets its own training and awareness requirements alongside the MLRO regime and the annual AML return. ADGM entities follow the FSRA AML Rulebook, with DNFBPs supervised by the ADGM Registration Authority. We deliver training to the rulebook that governs your licence, with the federal obligations mapped underneath it.

Yes. We have a team of AML trainers who can deliver the training programme in Arabic, English, Hindi, Gujarati, Marathi, Kannada, Tamil, and Malayalam.

Train your team to the current law.

One short form, one focused conversation, and a training plan sized for your business. A CAMS-certified specialist will come back with the tiers, the calendar, and the price.

Our latest blogs