What is Layering in Money Laundering?

Blogs

Published On: 06/25/2026

Table of Contents

Protect your business with reliable and effective AML strategies with AML UAE.

Last Reviewed On: 07/23/2026   |   Last Updated On: 07/23/2026

Layering at A Glance

  • Layering in money laundering refers to obscuring the origin of illicit funds by moving them through multiple transactions.
  • Criminals use complex transfers, shell companies, and investment instruments to distance the money from its criminal source.
  • The goal of layering is to make detection and tracing extremely difficult.
  • Strong AML controls, transaction monitoring, and risk-based checks are essential to detect and prevent layering activities
MicrosoftTeams-image (1)

What is Layering in Money Laundering?

Layering in money laundering refers to disguising the source of illicit funds through layers of financial transactions, accounts, entities, assets, or jurisdictions. It is usually the second stage of the money laundering process, after placement and before integration. In simple terms, placement puts illegal money into the financial system, layering hides the money trail, and integration makes the funds appear legitimate.

Layering is often the most complex stage of money laundering to detect because the activity may appear normal when each transaction is viewed in isolation. The suspicion usually becomes clearer when the full pattern is reviewed, such as rapid fund movement, unrelated third-party payments, cross-border transfers, shell companies, complex ownership structures, virtual asset movement, or transactions that do not match the customer profile.

For UAE-regulated entities, understanding the layering stage of money laundering is important because criminals may misuse banks, exchange houses, real estate businesses, dealers in precious metals and stones, virtual asset service providers, lawyers, accountants, auditors, and company service providers to disguise the origin of funds.

This guide explains the meaning of layering in money laundering, how it works, common examples, AML red flags, the differences among layering, placement, integration, structuring, and smurfing, and the controls UAE businesses can use to detect and manage layering risks.

Key Takeaways

Layering is the second stage of money laundering, sitting between placement and integration.

Its purpose is to break the audit trail so funds cannot be traced back to a crime.

Common methods include multiple transfers, cross border movement, shell companies, trade, real estate, precious metals, and virtual assets.

A single transaction may look normal. Layering is usually visible only across the full pattern.

UAE obligations sit under Federal Decree by Law No. 10 of 2025 and its executive regulations in Cabinet Resolution No. 134 of 2025, with suspicious transactions reported to the UAE Financial Intelligence Unit through goAML.

Layering Money Laundering Means, in Simple Terms

Layering is the stage where criminals move, split, convert, transfer, or restructure illicit funds to make the money trail harder to follow. The main goal is to separate the funds from their illegal source by creating several layers of financial activity.

A simple example is this:

  1. Illegal money enters the financial system.
  2. The money is transferred through multiple bank accounts.
  3. It is moved to another country or converted into another currency.
  4. It is passed through a company, an asset, an investment, or a virtual asset wallet.
  5. It later appears to come from a legitimate business, sale, loan, investment, or asset transaction.

The more layers criminals create, the harder it becomes for banks, businesses, regulators, and law enforcement agencies to identify the true origin of the funds.

Money Laundering Layering Definition

Layering is the stage of money laundering where illicit funds are moved through complex transactions to conceal their criminal origin, ownership, control, movement, or destination.

Layering can involve financial transactions, legal structures, business arrangements, trade documents, professional intermediaries, physical assets, or digital assets. The objective is to make illegal funds look disconnected from the crime that generated them.

A strong definition of layering should include four elements:

Element  Explanation 
Illicit funds  The money or value comes from criminal activity. 
Complex movement  Funds are transferred, converted, split, combined, or moved through multiple channels. 
Concealment  The activity is designed to hide the source, owner, controller, or destination. 
Broken audit trail  The transaction history becomes harder to trace and verify. 

What does Layering Mean in AML?

In AML, layering means using complex transactions, accounts, entities, assets, or jurisdictions to hide the source, ownership, movement, or destination of illicit funds. AML teams identify potential layering by reviewing customer behaviour, transaction patterns, beneficial ownership, sources of funds and wealth, counterparties, jurisdictional risk, and the commercial purpose of transactions.

Layering in AML matters because the activity may not look suspicious as a single transaction. One transfer, invoice, property purchase, virtual asset transaction, or currency exchange may appear ordinary. The risk often becomes visible only when multiple transactions are reviewed together. For example, a customer may receive funds from one company, transfer them to another entity, move part of the money overseas, use part of it to buy precious metals, and later claim that the funds came from business activity. Each step may look explainable on its own, but the full pattern may show an attempt to disguise the origin of funds.

Layering in the wider financial crime context. The same concealment behaviour is sometimes described simply as layering in financial crime or fraud. The principle is identical: value is moved through deliberate layers so the trail back to the original wrongdoing is broken. In an AML programme, this is managed during the layering stage of money laundering, as described throughout this guide.

AML layering risks may appear in many forms:

AML layering risk  What it may indicate 
Funds move quickly through an account  The account may be used only as a pass through account. 
Multiple unrelated parties are involved  The true owner or controller may be hidden. 
Transactions involve high risk jurisdictions  The money trail may be intentionally complicated. 
The customer cannot explain the source of funds  The funds may not have a legitimate origin. 
The transaction has no clear economic purpose  The activity may be artificial or circular. 
Documents appear weak, vague, or inconsistent  The explanation may be created only to support the transaction. 

AML teams should not look only at transaction value. They should also consider timing, frequency, counterparties, customer profile, expected business activity, documentation, sources of funds, and whether the transaction makes commercial sense.

What is Layering in Banking?

In banking, layering refers to suspicious movement of funds through multiple accounts, transfers, banking products, customers, or jurisdictions to hide the source or ownership of money. Banks may identify possible layering when funds move rapidly in and out, pass through unrelated accounts, involve third-party payments, or do not match the customer’s expected activity.

Banking pattern  Why it may be suspicious 
Funds are received and transferred out quickly  May indicate pass through activity. 
Multiple accounts are opened and closed  May be used to break the audit trail. 
Funds move through unrelated third parties  May hide the true owner or purpose. 
Repeated transfers occur without business rationale  May suggest artificial transaction layers. 
Cross border transfers involve high risk jurisdictions  May increase money laundering risk. 
Activity does not match the customer profile  May indicate misuse of the account. 
Funds move between related companies without clear purpose  May indicate circular movement of funds. 

For banks and exchange houses, layering risk is often detected through transaction monitoring, customer due diligence, source-of-funds checks, enhanced due diligence, sanctions screening, politically exposed person screening, and ongoing monitoring of customer behaviour.

Why Layering Matters in AML Compliance?

Layering matters because it is the stage where the money trail becomes harder to follow. At the placement stage, suspicious funds may still be evident through cash deposits, unusual receipts, or unexplained inflows into the financial system. During layering, criminals attempt to create distance between the money and its illegal source. A single transaction may not be enough to prove suspicion. The risk usually becomes apparent when the business reviews the broader pattern.

Pattern  Why it may indicate layering 
Funds move in and out quickly with no clear reason  May indicate pass through activity. 
Multiple parties are involved without a clear role  May hide the beneficial owner or controller. 
Transactions pass through unrelated jurisdictions  May be used to break the audit trail. 
Funds are converted into assets or virtual assets  May disguise the form, value, or ownership of money. 
Transaction value does not match the customer profile  May indicate activity inconsistent with known income or business. 
Documents do not support the stated purpose  May indicate a false or weak explanation. 
The customer avoids questions  May suggest unwillingness to disclose the real purpose. 

Layering is not limited to financial institutions. It can involve real estate businesses, dealers in precious metals and stones, auditors, accountants, lawyers, trust and company service providers, virtual asset service providers, and other regulated entities.

Where Layering Sits in the Money Laundering Process

Money laundering is commonly explained in three stages: placement, layering, and integration. FATF material refers to the money laundering cycle as including placement, layering and integration. Layering is the second stage. It comes after placement, when illicit funds enter the financial system, and before integration, when the funds are made to appear legitimate.

3 stages of Money Laundering
Stage Meaning Simple example 
Placement Illicit funds are introduced into the financial system. Criminal cash is deposited, exchanged, or used to buy high value goods. 
Layering Funds are moved or converted to hide their origin. Money is transferred between accounts, companies, countries, assets, or wallets. 
Integration Laundered funds re enter the economy as apparently legitimate wealth. Funds are used to buy property, securities, luxury goods, or business assets. 

The three stages can overlap in practice. A criminal does not always complete placement, then layering, then integration in a neat order. Some schemes combine activities from different stages, especially where companies, trade, real estate, virtual assets, and professional intermediaries are involved.

Looking for the full picture of the stages?

This page focuses on layering. For the complete cycle and each stage in depth, see the dedicated guides:

Layering vs Placement vs Integration

Placement, layering and integration are connected, but each stage has a different purpose.

Comparison  Placement  Layering  Integration 
Main purpose  Introduce illicit funds into the system.  Hide the source, ownership, or movement.  Make laundered funds appear legitimate. 
Simple phrase  Put the money in.  Hide the trail.  Use the money as clean wealth. 
Typical activity  Cash deposits, currency exchange, monetary instruments.  Wire transfers, shell companies, trade, asset and virtual asset movement.  Real estate, business investment, luxury assets, dividends, loans. 
AML risk focus  Source of funds and unusual cash activity.  Transaction pattern, beneficial ownership, complexity, jurisdiction risk.  Source of wealth and legitimacy of asset ownership. 
Common red flag  Large cash activity inconsistent with profile.  Complex transactions without clear purpose.  Funds used to buy assets with unclear source of wealth. 

Layering is about hiding the trail. Integration is about using the funds once they look legitimate. Layering makes integration easier because once funds have moved through several layers, criminals may claim the money came from business activity, asset sale proceeds, investment returns, or loan repayments.

The easiest way to remember the difference is this: placement introduces the money, layering hides the trail, and integration makes the money appear legitimate.

How Layering in Money Laundering Works

Layering works by creating complexity. Criminals move funds through several steps so that investigators, compliance officers, financial institutions, and regulated businesses cannot easily connect the funds to their original criminal source. A typical layering process may look like this:

  • Illicit funds are introduced into the financial system.
  • The funds are transferred to another account or entity.
  • The money is split into different amounts or moved through several counterparties.
  • Funds are converted into another currency, an asset, an investment, a precious metal, real estate, or a virtual asset.
  • The funds are moved across jurisdictions or through third parties.
  • Documents are created to make the transactions appear legitimate.
  • The funds are later integrated into the economy as business income, loan repayment, asset sale proceeds, investment returns, or property ownership.

The purpose is not always to make each transaction look perfect. The purpose is to make the overall money trail difficult to understand, verify, and challenge.

Common Methods of Layering in AML

Criminals may use a single method or combine several to layer illicit funds.

Method of layering  How it works  AML concern 
Multiple bank transfers  Funds are moved through several accounts.  Breaks the audit trail and hides the original source. 
Cross border transfers  Money is sent through different countries.  Adds jurisdictional complexity and reduces visibility. 
Shell companies  Companies with little or no genuine activity are used.  Hides beneficial ownership and control. 
Trade based money laundering  Invoices, goods, shipment values, or trade documents are manipulated.  Makes value movement look like normal trade. 
Real estate transactions  Property is bought, sold, transferred, or funded through unclear sources.  Converts illicit funds into high value assets. 
Precious metals and stones  Gold, diamonds, jewellery, or other high value items are bought and resold.  Portable assets can store and move value. 
Virtual assets  Funds move through wallets, exchanges, tokens, or chains.  Creates complex digital movement that needs specialist monitoring. 
Loans and repayments  Fake, circular, or related party loans are created.  Makes funds appear as legitimate debt repayment. 
Investment products  Funds are moved through securities, funds, or insurance.  Adds financial complexity and creates a paper trail. 
Professional intermediaries  Lawyers, accountants, auditors, or company service providers are misused.  Adds credibility and distance from the criminal source. 
Currency conversion  Funds are converted into another currency.  Makes tracing more difficult and may conceal source. 
Purchase and resale of assets  Assets are bought and later sold.  Converts criminal funds into apparently legitimate sale proceeds. 

Examples of Layering in Money Laundering

Example 1: Shell company transfers

A customer receives funds into a company account from an unrelated third party. The funds are quickly transferred to another company in a different jurisdiction. The customer gives a broad explanation, such as consulting services, but cannot provide contracts, invoices, delivery evidence, or a clear commercial purpose.

Why this may be layering: the transaction chain may be designed to separate the funds from their true source and hide the person who controls them.

Example 2: Real estate purchase through unclear funds

A buyer uses a newly formed company to purchase property. The funds come from multiple accounts, some of which are overseas, and the beneficial owner is difficult to identify. The buyer is unwilling or unable to explain the source of funds or wealth.

Why this may be layering: real estate can be used to convert illicit funds into an apparently legitimate asset.

Example 3: Precious metals and stones

A customer makes repeated purchases of gold, diamonds, or jewellery through different payment sources. The goods are later sold or transferred, and the customer claims the proceeds are legitimate business income.

Why this may be layering: high-value portable assets can be used to move, store, and convert value while hiding the source of funds.

Example 4: Virtual asset movement

Funds are converted into virtual assets, transferred across multiple wallets, exchanged into another token, and later converted back into fiat currency.

Why this may be layering: the movement of value across wallets, platforms, tokens, and jurisdictions can make the money trail harder to follow.

Example 5: Circular loan arrangement

Company A sends money to Company B. Company B sends the money to Company C. Company C later sends the money back to Company A as a loan repayment or investment return. The companies are connected, but the customer does not clearly explain the commercial purpose.

Why this may be layering: circular movement of funds may create an artificial paper trail, making illicit money appear to come from a legitimate transaction.

Example 6: Multiple account movement

Activities performed by criminals like changing the nature of the assets, i.e. changing cash into casino chips, gold into real estate, etc., indicate layering. Further, t

A customer opens several accounts or uses accounts held by related parties. Funds are deposited into one account, transferred through several others, then withdrawn or used for asset purchases.

Why this may be layering: multiple account movement can make it harder to identify where the money came from and who controls it.

hey also engage in carrying out a series of transactions to facilitate cross-border money transfer, to complicate the detection of an illicit source.

Layering vs Structuring

Layering and structuring are related, but they are not the same. Layering is a stage of money laundering. Structuring is a technique where transactions are split into smaller amounts to avoid reporting thresholds, monitoring rules, or detection.

Term  Meaning  Example  Relationship to layering 
Layering  Moving or converting funds to hide their source.  Transferring funds through several companies and accounts.  Main money laundering stage. 
Structuring  Splitting transactions into smaller amounts to avoid detection.  Repeated smaller deposits instead of one large deposit.  A technique used during placement or layering. 
Smurfing  Using multiple people or accounts to structure activity.  Several individuals deposit smaller amounts for one controller.  A form of structuring. 
Integration  Reintroducing funds as apparently legitimate wealth.  Buying property or investing in a business.  Usually follows placement and layering. 

Key takeaway: structuring and smurfing are techniques. Layering is a stage. They are connected, but they should not be treated as the same thing.

Red Flags of Layering in Money Laundering

A red flag does not automatically prove money laundering. It means the transaction, customer, or activity should be reviewed and, where necessary, escalated in accordance with the organisation’s AML and CFT procedures.

Red flag  What to review 
Rapid movement of funds in and out of an account  Business rationale, source of funds, customer profile. 
Multiple transfers with no clear economic purpose  Relationship between parties and transaction documents. 
Use of shell companies or complex ownership structures  Ultimate beneficial owner and control structure. 
Unusual cross border transfers  Jurisdiction risk and reason for overseas movement. 
Third party payments unrelated to the customer  Whether the payer or recipient has a legitimate role. 
Transactions inconsistent with customer income or business  Customer due diligence and expected activity profile. 
Purchase and resale of high value assets  Source of funds, asset valuation, and counterparty relationship. 
Circular transactions between related parties  Whether funds move without genuine commercial substance. 
Repeated transactions below monitoring thresholds  Possible structuring or smurfing. 
Customer avoids questions or provides vague documents  Need for enhanced due diligence or escalation. 
Documents do not match the transaction pattern  Possible false or incomplete explanation. 
Funds move through many accounts before being used  Possible attempt to create artificial layers. 

Businesses should treat these red flags as indicators for review. The decision to escalate, reject, continue, apply enhanced due diligence, or report should be documented based on the facts of the case.

Layering Risks for UAE-Regulated Entities

In the UAE, AML obligations apply to financial institutions, designated non-financial businesses and professions, virtual asset service providers, and non-profit organisations. Federal Decree by Law No. 10 of 2025 is the primary statute on anti-money laundering, combating the financing of terrorism, and the financing of the proliferation of weapons of mass destruction. It was published on 30 September 2025 and took effect about two weeks later, replacing Federal Decree-Law No. 20 of 2018. Cabinet Resolution No. 134 of 2025 sets out the executive regulations under that statute. It was published on 15 November 2025 and took effect on 14 December 2025.

Legal Basis in the UAE

  • Primary statute: Federal Decree by Law No. 10 of 2025 on anti money laundering, combating the financing of terrorism, and proliferation financing.
  • Executive regulations: Cabinet Resolution No. 134 of 2025.
  • Designated sectors: six categories of designated non-financial business and profession under Cabinet Resolution No. 134 of 2025, Article 3: commercial gaming operators; real estate brokers and agents; dealers in precious metals and stones; lawyers, notaries and other independent legal professionals and independent accountants; trust and company service providers; and a sixth, catch-all category that allows further businesses to be designated.
  • Reporting: suspicious transactions go to the UAE Financial Intelligence Unit within the Central Bank, through goAML (Federal Decree by Law No. 10 of 2025, Articles 11 and 18; Cabinet Resolution No. 134 of 2025, Article 18).
UAE sector Layering risks to monitor Practical controls 
Banks and exchange houses Rapid fund movement, cross border transfers, third party payments. Transaction monitoring, source of funds checks, enhanced due diligence. 
Real estate brokers and agents Purchases through companies, nominees, or unclear funding. Beneficial owner verification, source of wealth checks, red flag review. 
Dealers in precious metals and stones High value purchases, resale of gold or diamonds, third party payments. Customer identification, transaction review, suspicious activity escalation. 
Lawyers, accountants and auditors Misuse of client accounts, company structures, nominee arrangements. Beneficial ownership checks, engagement risk assessment, matter monitoring. 
Trust and company service providers Shell entities, nominee shareholders, incorporation of entities with unclear purpose, complex control structures. Beneficial owner verification, purpose of entity checks, ongoing monitoring. 
Virtual asset service providers Wallet hopping, chain hopping, high risk wallets, rapid conversion. Wallet screening, blockchain analytics, transaction monitoring. 

Note: the six designated DNFBP categories are set by Cabinet Resolution No. 134 of 2025, Article 3.

Suspicious transactions are reported immediately and directly to the UAE Financial Intelligence Unit through the goAML portal (Federal Decree by Law No. 10 of 2025, Articles 11 and 18; Cabinet Resolution No. 134 of 2025, Article 18). These designated non-financial businesses and professions are supervised by different authorities depending on the sector, for example the Ministry of Economy and Tourism for real estate brokers, dealers in precious metals and stones, accountants and corporate service providers; the Ministry of Justice for lawyers and other independent legal professionals; and the General Commercial Gaming Regulatory Authority for commercial gaming. Each is required to register and report on goAML. The same portal is used for both suspicious transaction reports and activity-based reports.

How Businesses can Detect Layering

Businesses can detect layering by reviewing the full customer and transaction picture rather than looking at transactions in isolation.

1. Know the customer

Customer due diligence should establish who the customer is, what the customer does, who owns or controls the customer, and what level of activity is expected. If the transaction pattern does not match the customer profile, the business should investigate.

Question  Why it matters 
Who is the customer?  Confirms identity and risk profile. 
What does the customer do?  Helps assess whether activity is expected. 
Who owns or controls the customer?  Identifies the beneficial owner. 
What is the expected transaction pattern?  Helps detect unusual activity. 
Is the transaction consistent with the profile?  Identifies possible suspicious behaviour. 

2. Verify source of funds and source of wealth

The source of funds explains where the money for a transaction came from. The source of wealth explains how the customer built their overall wealth. For higher-risk customers or unusual transactions, both may be relevant.

Check  Meaning 
Source of funds  Where the money for this transaction came from. 
Source of wealth  How the customer generated overall wealth. 
Supporting documents  Evidence that supports the customer explanation. 
Consistency check  Whether the explanation matches the customer profile. 

A customer explanation should be reasonable, specific, and supported by documents. Vague explanations such as business income, family funds, or investment returns may not be enough if the transaction is high-risk or unusual.

3. Monitor transaction behaviour

Transaction monitoring should identify unusual volume, speed, frequency, value, destination, counterparties, and transaction purpose. Layering often appears as a pattern rather than a single suspicious transaction.

Factor What to review 
Speed Are funds moving in and out quickly? 
Frequency Are there repeated transactions without clear purpose? 
Value Does the transaction value match the customer profile? 
Counterparty Are the payer and recipient connected to the stated purpose? 
Jurisdiction Are high risk or unrelated countries involved? 
Purpose Is there a clear commercial reason? 
Documentation Do documents support the transaction? 

4. Review beneficial ownership

Complex ownership structures, nominee arrangements, or unexplained control by third parties may indicate that the true owner is being hidden.

Beneficial ownership issue  Risk 
Multiple layers of companies  True ownership may be hidden. 
Nominee shareholders or directors  Control may sit with another person. 
Ownership in high risk jurisdictions  Reduced transparency. 
No clear business purpose for the structure  Possible shell company risk. 
Customer avoids beneficial owner questions  Possible concealment. 

5. Apply enhanced due diligence where risk is high

Enhanced due diligence may be needed for high-risk customers, high-risk jurisdictions, politically exposed persons, unusual transactions, complex structures, or activity that does not match the customer profile.

Enhanced due diligence measure  Purpose 
Additional identity checks  Confirms customer identity. 
Beneficial owner verification  Confirms who owns or controls the customer. 
Source of funds review  Checks where transaction funds came from. 
Source of wealth review  Checks how the customer generated wealth. 
Senior management approval  Adds oversight for high risk cases. 
More frequent monitoring  Tracks ongoing risk. 
Additional documents  Supports or challenges the customer explanation. 

6. Escalate suspicious activity

If suspicion remains after review, the matter should be escalated to the compliance officer or money laundering reporting officer in line with internal AML and CFT procedures. Where reporting is required, suspicious activity or suspicious transactions should be reported through the appropriate channel, such as goAML in the UAE.

How to Prevent Layering in Money Laundering

A single control cannot prevent layering. Businesses should use a risk-based AML framework that combines customer due diligence, transaction monitoring, staff awareness, escalation, and reporting.

AML control  How it helps prevent or detect layering 
Business risk assessment  Identifies where the business is exposed to money laundering risk. 
Customer risk assessment  Identifies customers who need closer monitoring. 
Customer due diligence  Confirms identity, activity, ownership, and expected behaviour. 
Enhanced due diligence  Applies deeper checks to high risk relationships. 
Transaction monitoring  Detects unusual movement, speed, value, or counterparties. 
Sanctions and PEP screening  Identifies designated and politically exposed persons. 
Beneficial ownership checks  Reveals who ultimately owns or controls the customer. 
Source of funds checks  Tests whether transaction funds have a legitimate explanation. 
Source of wealth checks  Tests whether customer wealth is reasonable and supported. 
Staff training  Helps employees recognise and escalate suspicious patterns. 
Independent AML review  Tests whether controls are working effectively. 
STR and SAR reporting procedures  Ensures suspicious activity is escalated and reported correctly. 
Record keeping  Supports auditability and regulatory review. 

The objective is to identify suspicious patterns early, ask the right questions, document decisions, and report suspicious activity where required.

What Should a UAE Business do If It Detects Red Flags of Layering?

If a UAE business detects possible layering, it should not ignore the activity or rely only on the customer’s verbal explanation. The business should follow its AML and CFT policy and apply a documented review process.

  • Review the customer profile, risk rating, and expected activity.
  • Check the transaction purpose, counterparties, jurisdictions, and supporting documents.
  • Request source-of-funds or source-of-wealth information where appropriate.
  • Assess whether the activity has a reasonable commercial or lawful explanation.
  • Escalate the matter internally to the compliance officer or money laundering reporting officer.
  • Decide whether enhanced due diligence, rejection, exit, account restrictions, or reporting is required.
  • Keep records of the review, decision, and supporting evidence.
  • File a suspicious transaction report or suspicious activity report where required.

Do not tip off the customer. Do not inform the customer that a suspicious transaction report has been or may be filed, or that an investigation may be underway. This prohibition on tipping off is a legal requirement (Cabinet Resolution No. 134 of 2025, Article 19), and a breach carries criminal penalties (Federal Decree by Law No. 10 of 2025, Article 29). Internal escalation and external reporting should be handled confidentially.

Practical AML UAE Layering Checklist

Use this checklist when reviewing transactions that may involve layering.

Question  Yes or No 
Is the transaction consistent with the customer known business or income?   
Is the source of funds clear and supported by documents?   
Is the source of wealth reasonable for the customer profile?   
Are the counterparties connected to the stated transaction purpose?   
Are any high risk jurisdictions involved?   
Is there a clear commercial reason for the transaction structure?   
Are funds moving quickly in and out without a business reason?   
Are shell companies, nominees, or complex ownership involved?   
Are payments being made by or to unrelated third parties?   
Has the customer avoided questions or submitted weak documentation?   
Are the transaction documents consistent with the pattern?   
Has the customer risk rating been reviewed?   
Should enhanced due diligence be applied?   
Should the matter be escalated to the compliance officer or MLRO?   
Should a suspicious transaction or activity report be considered?   

This checklist is a practical review tool, not a substitute for legal advice or the organisation’s AML and CFT policies and procedures.

Quick Answers About the Layering Stage

Which money laundering stage refers to the separation of illicit proceeds from their source?

The layering stage refers to the separation of illicit proceeds from their source. This is done by creating complex layers of financial transactions, accounts, entities, assets, or jurisdictions, making the origin of the funds harder to identify.

Which stage involves multiple transactions designed to separate the money from its source?

The layering stage involves multiple transactions designed to separate illicit money from its source. These may include transfers, conversions, purchases, withdrawals, deposits, movement through different accounts, or movement through different jurisdictions.

What is the main goal of the layering stage in money laundering?

The main goal of the layering stage is to hide the origin of illicit funds and break the audit trail, so that banks, regulators, businesses, and law enforcement agencies cannot easily trace the money back to criminal activity.

Which of the following are methods of the layering stage of money laundering?

Common methods of layering include multiple bank transfers, cross-border transactions, currency conversions, shell companies, trade-based transactions, purchases and resales of high-value assets, virtual asset transfers, and movement through multiple financial institutions.

In the context of money laundering, layering refers to the act of what?

In the context of money laundering, layering refers to moving, converting, transferring, splitting, or restructuring illicit funds through complex transactions to disguise their origin, ownership, movement, or destination.

What stage of money laundering is the most complex and difficult to detect?

Layering is often considered the most complex and difficult stage to detect, because it may involve several transactions, accounts, entities, jurisdictions, assets, and documents. The suspicious pattern may only become clear after the full transaction trail is reviewed.

What is the correct sequence of stages of money laundering?

The commonly used sequence is placement, layering, and integration. Placement introduces illicit funds into the financial system, layering hides the trail, and integration makes the funds appear legitimate.

At which stage is money laundering relatively easy to detect?

Money laundering is often easier to detect at the placement stage, because illicit funds are first introduced into the financial system. Unusual cash deposits or unexplained funds may be more visible before the funds are moved through layers of transactions.

How AML UAE Can Help

AML UAE helps businesses build and strengthen AML and CFT compliance frameworks designed to identify, assess, monitor, and report money laundering risks, including layering risks.

AML support area  How it helps 
AML and CFT business risk assessment  Identifies exposure to money laundering, terrorist financing, and proliferation financing risks. 
Customer risk assessment methodology  Helps classify customers based on risk. 
AML and CFT policies and procedures  Documents how the business manages AML obligations. 
Customer due diligence framework  Helps verify customers and understand expected activity. 
Enhanced due diligence framework  Applies stronger checks for higher risk customers and transactions. 
Transaction monitoring rules  Helps identify suspicious layering patterns. 
Red flag indicators  Helps employees identify unusual behaviour. 
Suspicious transaction escalation process  Guides internal review and reporting decisions. 
goAML registration and reporting support  Assists with reporting readiness. 
AML training  Helps employees understand risks and responsibilities. 
Independent AML compliance review  Tests whether controls are working effectively. 

A strong AML framework helps regulated entities detect suspicious patterns early, document decisions properly, and meet their AML and CFT obligations with greater confidence.

Need help identifying layering risks in your business?

Speak with AML UAE to review your AML and CFT controls, red flags, transaction monitoring framework, and suspicious activity escalation process.

Let us together fight money laundering by preventing the layering of illicit funds

This article has been prepared with reference to the following sources, verified against the UAE AML law library.

  • Federal Decree by Law No. 10 of 2025 on Anti Money Laundering, and Combating the Financing of Terrorism and Proliferation Financing. Published in the UAE Official Gazette on 30 September 2025, in force from about 14 October 2025.
  • Cabinet Resolution No. 134 of 2025 on the Executive Regulations of Federal Decree by Law No. 10 of 2025. Published 15 November 2025, in force from 14 December 2025. UAE Official Gazette
  • UAE Financial Intelligence Unit and goAML reporting, and Ministry of Economy and Tourism guidance on designated non-financial businesses and professions registration. moec.gov.ae
  • FATF guidance and materials on the money laundering cycle of placement, layering and integration. fatf-gafi.org

FAQs about Layering on Money Laundering

What is layering in money laundering?

Layering is the stage in which illicit funds are moved through complex transactions, accounts, entities, assets, or jurisdictions to conceal their criminal origin. It is usually the second stage, after placement and before integration.

It is the process of separating illicit funds from their criminal source by moving, converting, or transferring them through multiple transactions, accounts, entities, assets, or jurisdictions.

In AML, layering refers to using complex transactions or structures to conceal the source, ownership, movement, or destination of illicit funds. It is detected through transaction monitoring, customer due diligence, source-of-funds checks, beneficial ownership review, and jurisdiction risk assessment.

The three stages of money laundering are:

  1. Placement
  2. Layering and
  3. Integration

Layering is the second stage of money laundering. What makes layering in money laundering difficult to detect is the way it is broken down into smaller transactions and the conversion of money from one form to another.

Transferring illicit funds through several bank accounts and companies in different jurisdictions, then using the funds to buy property, precious metals, securities, or virtual assets. This creates distance between the funds and their criminal source.

Layering, also known as structuring is the second stage of money laundering. 

Layering in banking is the suspicious movement of funds through multiple accounts, transfers, products, customers, or jurisdictions to hide the source or ownership of money. Banks often detect it through transaction monitoring and customer profile reviews.

Layering is the second stage in money laundering. It is a structuring process in which criminally derived funds are legalized and their ownership and source is disguised.

Structuring is the another word for layering.

Layering is structuring a transaction in such a way that the orgin of the criminal proceeds is disguised for the purpose of money laundering.

Several red flags indicate the layering of funds in money laundering. Banking transactions involving large cash deposits into various banks, international bank transfers, investment and resell of jewellery, art, and other high-value items, fund transfer using shell companies, etc., indicates that the funds are being layered to make the detection of their origin as difficult as possible.

The main goal of the layering stage of money laundering is to make the detection of the source of illicit money as difficult as possible.

Placement is the first stage, where illegal funds are introduced into the financial system through small deposits or cash purchases. Layering is the second stage, where those funds are moved through complex transactions such as trusts, shell companies, etc. to hide their criminal origin.

In simple terms: placement puts the money in; layering hides its trail.

Layering is one of the stages in money laundering where the launderer makes numerous transactions to take the illegal proceeds far from their original source. Launderers layer illicit money with several transactions to hide its source.

The four stages in the money laundering process are placement, layering, integration, and spending. At the placement stage, illicit funds are introduced into the financial system. The stage in which money is dispersed and disguised in the system is known as layering, where complex transactions are used to hide the origin of funds. Integration refers to money re-entering the economy as apparently legitimate earnings or profits.

The stage referred to is layering. The stage in which money is dispersed and disguised in the system is known as layering, where criminals move illicitly obtained funds through multiple financial transactions to conceal their origin.

The primary goal behind the layering stage is to separate the illicit proceeds from their questionable origin through layers of multiple financial transactions, making it difficult for investigators to trace money back to the original source of criminal activity.

Placement introduces illicit funds into the financial system. Layering hides their source and movement through complex transactions. Integration makes the funds appear legitimate by using them for assets, investments, or business activity.

Layering is a stage of money laundering. Structuring is a technique in which transactions are split into smaller amounts to avoid detection by reporting thresholds or monitoring rules. Structuring may be used during placement or layering, but it is not the same as layering.

No. Smurfing is a structuring technique that uses multiple people, accounts, or transactions to split funds into smaller amounts. Layering is a broader stage where funds are moved or converted to hide their origin.

Rapid fund movement, third-party payments, shell companies, unexplained cross-border transfers, circular transactions, complex ownership, inconsistent customer activity, and repeated transactions below monitoring thresholds.

By applying customer due diligence, transaction monitoring, source of funds checks, beneficial ownership verification, enhanced due diligence for higher risk cases, staff training, internal escalation, and suspicious transaction reporting where required.

Review the customer and transaction details, collect supporting information where appropriate, escalate to the compliance officer or MLRO, document the decision, and file a suspicious transaction or activity report where required.

Share via :

About the Author

Pathik Shah

FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)

Pathik is an ACAMS-certified AML consultant specialising in governance, risk, and compliance for regulated entities in the UAE. He brings over 28 years of experience, with 1,000+ hours of AML training and 200+ advisory engagements across DNFBPs, VASPs, and FIs. He supports businesses in aligning with AML/CFT requirements from the CBUAE, DFSA, MoET, MoJ, VARA, CMA, FSRA, and FATF. Known for translating complex regulations into audit-ready procedures, Pathik enables operational clarity and compliance readiness.

Reach Out to Pathik

The New UAE AML/CFT Law – Federal Decree Law No. 10 of 2025 Explained

Key Changes in the New UAE AML Law 2025 and Its Impact on Businesses

Blogs

Published On: 04/12/2025

Table of Contents

Protect your business with reliable and effective AML strategies with AML UAE.

Last Reviewed On: 07/23/2026   |   Last Updated On: 07/23/2026

Key Highlights of Core Changes in the New AML/CFT Law 10 of 2025

  • The New UAE AML/CFT Law, i.e. Federal Decree Law No. 10 of 2025, replaces the old AML Law of 2018, introducing stronger enforcement powers, higher penalties, and new criminal categories, such as Proliferation Financing. It came into force on 14 October 2025.
  • Executive Regulations: Cabinet Resolution No. 134 of 2025 (in force from 14 December 2025)
  • Virtual Assets & VASPs are now directly regulated, with strict licensing and reporting, with added checks on cryptographic technologies.
  • Beneficial Ownership, STR filing, sanctions compliance, and risk assessments face significantly higher scrutiny, backed by extended FIU freezing powers.
  • Businesses must upgrade systems, governance, and internal controls immediately to avoid fines up to AED 100 million and potential dissolution.

The New UAE AML/CFT Law: Federal Decree Law No. 10 of 2025 Explained

The UAE’s financial regulatory landscape has entered a new era. The Federal Decree Law No. 10 of 2025, effective from October 14, 2025, marks the most significant overhaul of the country’s Anti-Money Laundering (AML) and Combating Financing of Terrorism (CFT) framework. This new legislation repeals and replaces Federal Law No. 20 of 2018, arriving almost a year after amendments were made through Federal Decree-Law No. 7 of 2024.

The 2025 law doesn’t merely update the 2018 law; it transforms how businesses must operate across the Emirates. While the New AML Law is now in force, the existing Executive Regulations, Resolutions, and Circulars remain applicable until updated Regulations, Resolutions, and Circulars are issued. Accordingly, Cabinet Resolution No. 10 of 2019 will be repealed by Cabinet Resolution No. (134) of 2025 Concerning the Executive Regulations of Federal Decree-Law No. (10) of 2025 Concerning Combating Money Laundering, Terrorist Financing, and the Financing of the Proliferation of Weapons with effect from 14th December 2025.

This means businesses must apply current rules while preparing systems and governance to meet the requirements of the new framework.

What is Federal Decree Law No. 10 of 2025?

In a decisive move to strengthen its position as a trusted global financial hub, the UAE has introduced Federal Decree Law No. 10 of 2025 Regarding Anti-Money Laundering, and Combating the Financing of Terrorism and Proliferation Financing. The law goes far beyond cosmetic updates.

It introduces new criminal offences, expanding enforcement powers, and imposing penalties that can reach AED 100 million for corporate violations. From the introduction of Proliferation Financing as a distinct crime to explicit regulation of Virtual Assets (VAs) and cryptocurrency transactions, the 2025 law addresses emerging threats in an increasingly digital and interconnected world.

Any business entity handling customer transactions or providing designated services must now meet far more rigorous regulatory obligations. For businesses operating across the Emirates, understanding these changes is essential for maintaining compliance and operational continuity.

This article provides a comprehensive analysis of the Federal Decree Law No. 10 of 2025 Regarding Anti-Money Laundering and Combating the Financing of Terrorism and Proliferation Financing. It shares insights into key changes, examines implications for different stakeholder groups, outlines practical compliance steps, identifies implementation challenges, and offers best practices for navigating this new regulatory environment. For further reading, check a guide to Anti-Money Laundering Laws in the UAE.

Unsure where to start with the new AML/CFT law?

Partner with us to quickly realign your policies and procedures with the new law.

Who are the Stakeholders Under the New UAE AML/CFT Law 2025?

The Federal Decree By Law No. 10 of 2025 casts a wide net across the UAE’s business landscape. It provides a clear overview of all stakeholder groups covered under the 2025 Law.

Understanding whether an entity falls under these regulations is crucial for compliance. The law applies to:

Each category carries specific obligations and faces substantial penalties for non-compliance.

Too busy running the business to decode AML/CFT reforms?

Let AML UAE handle the technical details while you focus on clients and growth.

Key changes introduced by Federal Decree Law 10 of 2025

The Federal Decree By Law No. 10 of 2025 introduces substantial reforms across multiple dimensions of AML/CFT/CPF enforcement. While some provisions build upon the earlier Federal Decree Law No. 20 of 2018 framework, others represent entirely new territory for UAE businesses.

The following key changes, comprising Proliferation Financing, Direct Regulation of Virtual Assets, Increased Penalties, Extended Freezing Powers, Stricter Beneficial Ownership Requirements, Two-Tier Supervisory Framework, and No Statute of Limitations, constitute the most significant shifts that stakeholders must understand and address

Proliferation Financing

The most notable addition to the 2025 law is the introduction of ‘Proliferation Financing’ as a distinct criminal offence. This category did not exist in the 2018 legislation and reflects growing international concerns about weapons of mass destruction.

What It Means: This provision criminalises providing funds for weapons of mass destruction, including nuclear, biological, chemical, or radiological weapons.

Penalties: Temporary imprisonment and fines ranging from AED 1 million to AED 10 million, or twice the value of Criminal Property, whichever is greater.

Impact on Business: Businesses involved in international trade, technology transfers, or dual-use goods (civil and military use goods) require enhanced AML/CFT controls to ensure compliance with proliferation financing restrictions.

Direct Regulation of Virtual Assets

Cryptocurrency and digital assets, which were not addressed under the 2018 law, now receive comprehensive and explicit treatment throughout the 2025 legislation. This change addresses the rapid growth of the crypto economy in the UAE.

What Changed:

  • Virtual Asset Service Providers (VASPs) are now defined as Regulated Entities
  • VASPs are explicitly subject to Suspicious Transaction Reporting (STR) requirements
  • Penalties apply to the use of technologies, accounts, or virtual assets that obscure the Source of Funds or the identity of the Beneficial Owner.
  • Virtual assets that enable total anonymity or obstruct tracing are expressly restricted.

Penalties: Promoting or dealing in totally anonymous virtual assets carries a minimum 3 months imprisonment and a fine not less than AED 50,000 , or either of these two penalties.

Impact on Business: Crypto exchanges, blockchain service providers, and any allied businesses accepting cryptocurrency payments must now implement the same rigorous AML/CFT compliance as imposed on other Regulated Entities

Increased Penalties

While the 2018 law imposed significant penalties, the 2025 version raises the stakes, particularly for corporate entities. The potential financial exposure for violations has multiplied several times over.

What Changed:

  • Money Laundering (Individuals):
    • 2018 Law: Up to 10 years imprisonment + fines up to AED 5 million
    • 2025 Law: 1-10 years imprisonment + fines up to AED 5 million OR value of Criminal Property (whichever is greater)
  • Money Laundering with Aggravated Circumstances:

Money Laundering committed under Aggravating circumstances includes: exploiting position authority, committing through NPOs or organised crime groups, certain serious predicate offences, or recidivism.

2025 Law: Temporary imprisonment + fines AED 1-10 million OR twice the criminal property value (whichever is greater)

  • Legal Entities:
    • 2018 Law: Fines AED 500,000 to AED 50 million
    • 2025 Law: Fines AED 5 million to AED 100 million OR Criminal Property value (whichever is greater)

Impact on Business: A single violation can now cost companies up to AED 100 million, representing a doubling of maximum penalties and creating substantially higher financial risk exposure.

Offence Category

2018 Law (Federal Decree-Law No. 20 of 2018)

2025 Law (Federal Decree-Law No. 10 of 2025)

Analysis

Proliferation Financing (PF)

Not explicitly defined or penalised.

Punishable by temporary imprisonment and a fine between AED 1,000,000–10,000,000, or twice the value of the Criminal Property, whichever is greater.

PF is recognised as a distinct crime with severe penalties, aligning UAE law with FATF standards and addressing Weapons of Mass Destruction (WMD)-related financial risks.

Financing of Terrorism (Individuals)

Life imprisonment or temporary imprisonment (≥  10 years) and a fine between AED 300,000–10,000,000.

Life imprisonment or temporary imprisonment (≥10 years) and a fine between AED 1,000,000–10,000,000, or twice the value of the Criminal Property.

The minimum fine increased more than threefold (from AED 300,000 to AED 1,000,000); it introduces asset-value-based fines, strengthening deterrence and recovery of illicit gains.

Dealing in Anonymous Virtual Assets

Not addressed.

Imprisonment (≥3 months) and/or fine ≥AED 50,000 for promoting, offering, or dealing in completely anonymous virtual assets.

A new and explicit penalty targeting untraceable Virtual Assets, highlighting the 2025 law’s digital-risk focus.

Unlicensed Activities (VASPs / DNFBPs)

Generic penalty of AED 10,000–100,000 for violations.

Imprisonment and/or fine between AED 200,000–10,000,000 or either penalty, for (violating Article 20) engaging in financial/VASP/DNBFP activities without a license.

The 2025 Law introduces a specific and severe penalty for operating without a valid license or registration, reinforcing regulatory control over fintech and VASPs.

Tip-Off / Warning (Breach of Confidentiality)

Imprisonment (≥6 months) and/or fine AED 100,000–500,000.

Imprisonment and/or fine ≥AED 50,000.

The 2025 Law removes the minimum imprisonment period (of 6 months) but maintains the ability to impose imprisonment and a fine while retaining strict confidentiality obligations.

Failure to Report / Gross Negligence

Imprisonment and a fine of AED 100,000 to AED 1,000,000, or either.

Punishment by imprisonment and a fine of not less than AED 100,000 and not exceeding AED 1,000,000, or by either of these two penalties.

The range remains the same, but the 2025 Law rephrases the minimum penalty to state “not less than” AED 100,000.

Violating Targeted Financial Sanctions (TFS) Instructions

Imprisonment or fine AED 50,000–5,000,000  applied to anyone who violates instructions issued by the Relevant Authority for the implementation of UN Security Council directives.

Imprisonment and/or fine ≥AED 20,000, for violating instructions issued by the Executive Office or other Competent Authority related to Targeted Financial Sanctions.

While the 2018 law addressed UN sanctions compliance, the 2025 Law sets a new minimum fine of AED 20,000 for violations against the Executive Office’s sanctions instructions, reflecting the new structure.

Administrative Fines (Supervisory Authorities)

Fine of AED 50,000–5,000,000 per violation.

Fine of AED 10,000–5,000,000 per violation.

The minimum administrative fine is drastically reduced (from AED 50,000 to AED 10,000).

Extended Freezing Powers

Enforcement authorities have gained considerably more time and flexibility to freeze suspicious funds and suspend transactions. These expanded powers enable faster action against potential Money Laundering activities while investigations proceed.

What Changed:

  • Transaction Suspension: The Financial Intelligence Unit (FIU) can suspend suspicious transactions for up to 10 working days without court approval.
  • Fund Freezing: The FIU can freeze funds for up to 30 days (increased from 7 days under the 2018 law), with extension provisions available through the Attorney General.
  • Enhanced Authority: Public Prosecution can directly access accounts, computer systems, and communications without prior notice to account holders.

Impact on Business: Businesses face potential 30-day account freezes that could disrupt operations, affect cash flow, and prevent payment of suppliers or employees during investigation periods.

Stricter Beneficial Ownership Requirements

Under the 2025 law, greater emphasis is placed on establishing Beneficial Ownership across corporate and legal arrangements.

What Changed:

  • More detailed and specific definitions of Beneficial Ownership
  • Enhanced obligations requirements for legal arrangements and trusts
  • Specific obligations imposed on nominee directors and shareholders

Penalties: Providing false Beneficial Ownership information now carries imprisonment plus fines starting at AED 20,000.

Impact on Business: Businesses must maintain Beneficial Ownership records, verify ownership chains at multiple levels, and update information regularly as structures change. This may involve additional documentation during customer onboarding to ensure transparency.

Disclosure Requirements for Cash, Precious Metals/Stones, Negotiable Instruments

The Federal Decree Law No. 10 of 2025 introduces cash, precious metals/stones, and negotiable instruments disclosure requirements for individuals entering or departing from the UAE in accordance with the disclosure system issued by the Federal Authority for Identity, Citizenship, Customs, and Port Security in coordination with the Central Bank.

 Impact on Business: Businesses must ensure that adequate disclosure is made when their staff carry cash, precious metals/stones, and negotiable instruments while entering or departing from the UAE. The AML/CFT policy and procedures must be amended to reflect this mandatory requirement as the UAE Customs Declaration Form.

Two-Tier Supervisory Framework

The 2025 law restructures how Anti-Money Laundering efforts are coordinated and supervised at the national level. The creation of the following dual oversight bodies reflects a more sophisticated approach to governance and enforcement.

  • Supreme Committee: It provides high-level strategy and supervision, affiliated with the Presidential Court, and is responsible for monitoring the National Strategy
  • National Committee: It handles operational coordination and implementation, chaired by the Central Bank Governor.

Impact on Business: More frequent inspections, higher regulatory expectations, dual reporting lines to both strategic and operational oversight bodies, and increased administrative penalty exposure.

Strengthened International Cooperation

The 2025 law enhances cross-border information sharing and mutual legal assistance, introducing streamlined mechanisms that improve coordination with foreign authorities and reduce barriers to international investigations.

Key Changes:

  • Automatic information exchange with counterpart authorities in other jurisdictions
  • Priority handling requirements for international cooperation requests simplified mutual legal assistance procedures
  • Foreign confiscation orders are executable without separate national investigations
  • Tax matters no longer constitute grounds for refusing cooperation requests

Impact on Business: Transactions face greater scrutiny from multiple jurisdictions simultaneously. Moreover, information held by UAE entities can be shared more easily with foreign authorities, and cross-border operations require an understanding of multiple jurisdictions’ AML requirements.

No Statute of Limitations (Continued from 2018)

While not a new provision, the continuation of unlimited prosecution timeframes remains one of the most significant features of UAE’s AML framework. The 2025 law adds Proliferation Financing to the list of crimes with no statute of limitations, whereas the 2018 law only covered Money Laundering and Terrorism Financing.

What It Means: Criminal proceedings for Money Laundering, Terrorism Financing, and Proliferation Financing can be initiated at any time, regardless of how many years have passed since the offence occurred.

Impact on Business: Past violations can be prosecuted indefinitely, creating permanent legal risk. Businesses must maintain compliance records for extended periods, as past transactions remain subject to investigation and prosecution decades later.

Make the New UAE AML 2025 Law Your Competitive Advantage.

Strengthen Your compliance journey with AML UAE by Your side.

Comparative Chart of Changes in Federal Decree Law No. (10) of 2025

To put these developments and key changes into perspective, the following table highlights how core provisions have evolved from Federal Decree Law No. (20) of 2018 to Federal Decree Law No. (10) of 2025. Many of these refinements aim to streamline compliance obligations and enhance alignment with international standards. This comparison helps identify areas where institutions may need to recalibrate their internal processes.

Feature

2018 Law (Federal Decree Law No. 20 of 2018)

2025 Law (Federal Decree Law No. 10 of 2025)

Analysis

Primary Scope 

Focuses on ML, TF, and Financing of Illegal Organisations.

Focuses on ML, TF, and Proliferation Financing (PF).

The 2025 Law introduces PF as a distinct crime and removes the specific term “Financing of Illegal Organisations” (which was present in the 2018 Law).

Definitions and Coverage

Includes definitions for ML, TF and Illegal Organisations.

Introduces detailed definitions for Proliferation, Weapons of Mass Destruction (WMD), and Virtual Assets, alongside expanded definitions for ML/TF.

The 2025 Law incorporates modern financial crime concerns, explicitly covering PF and transactions involving Virtual Assets.

Treatment of Virtual Assets

No reference to Virtual Assets (VA) or Service Providers.

Explicitly addresses VA, including their use in ML & TF. It also defines and regulates Virtual Asset Service Providers (VASPs).

It modernises the AML scope to include digital currencies and crypto-related activities.

Financial Intelligence Unit (FIU)

 The FIU is established within the Central Bank of the UAE (CBUAE), chaired by the Governor.

It retains CBUAE structure but affirms FIU’s independence. Now, the FIU is established as an independent unit within the Central Bank (CBUAE).

It emphasises institutional autonomy and operational independence of the FIU.

National Coordination Framework

It established the National Committee,  chaired by the CBUAE Governor.

It introduces a two-tier structure: a Supreme Committee for the Supervision of the National Strategy for AML, CFT, PF (affiliated with the Presidential Court) and a National Committee, chaired by the Governor

The 2025 Law creates a two-tiered oversight structure, placing strategic supervision under the Supreme Committee while maintaining the National Committee for policy implementation.

FIU Freezing Authority

The Governor or their delegate may freeze suspicious funds up to 7 working daysrenewable by the Public Prosecutor.

The FIU Chief may suspend transactions up to 10 days or freeze funds for 30 days.

It extends FIU’s power and timeframe, allowing faster, independent intervention.

Money Laundering Penalties (Individuals)

Imprisonment not exceeding 10 years and a fine of AED 100,000 to AED 5,000,000, or either penalty;

Aggravated penalty (temporary imprisonment and fine of AED 300,000 to AED 10,000,000) for specific circumstances.

Imprisonment for a term of not less than 1 year and not exceeding 10 years, together with a fine of AED 100,000 to AED 5,000,000, or equivalent Criminal Property value. Aggravated penalty (temporary imprisonment and fine of AED 1,000,000 to AED 10,000,000).

The 2025 Law clarifies the minimum imprisonment term (not less than 1 year) and increases the minimum fine for aggravated offences (from AED 300,000 to AED 1,000,000).

Penalties for Legal Persons

Liquidate and close the office, and a fine of AED 500k –50 M.

Fine AED 5M –100M  or equivalent Criminal property value.

The maximum fine for a Legal Person conviction is doubled (from AED 50 million to AED 100 million) in the 2025 Law, and the minimum fine is significantly increased (from AED 500,000 to AED 5,000,000), reinforcing corporate liability.

Legal Person Conviction for CFT/PF

If convicted of terrorism financing, the Court shall order liquidation and closure of the office premises.

If convicted of Financing of Terrorism or Proliferation Financing, the Court shall order dissolution and closure.

The mandatory dissolution and closure provision now includes PF Convictions.

Professional Secrecy Exemption

Exemption for lawyers, notaries, other legal professionals, and independent legal auditors who obtained information subject to professional confidentiality.

Exemption maintained for lawyers, notaries, other legal professionals, or independent legal auditors if information was obtained under circumstances subjecting them to professional secrecy. maintained with an identical scope.

This core exemption remains largely consistent in both laws, protecting legal professional privilege.

Repeal Status

Repealed by Decree-Law No. 10 of 2025.

Repeals the 2018 Decree-Law.

The 2025 Law is the currently effective legal framework, along with existing resolutions, notifications, and circulars to the extent they aren’t repealed. 

Step-by-Step Guide for the Regulated Entities to Comply with the New UAE AML Law 2025

The following step-by-step guide outlines each compliance step required under the New AML Law 2025.

This section provides a clear overview of the entire process—from Securing Licensing, Conducting Risk Assessments, Establishing Internal Policies, Implementing CDD, Ensuring Beneficial Owner Transparency, Applying TFS Forthwith, Reporting Suspicious Transactions, Avoiding Tipping-Off, Meeting VASP-Specific Obligations, and Keeping Records.

Together, these steps highlight the essential actions businesses must take to meet the law’s requirements, strengthen internal controls, and ensure full alignment with regulatory expectations.

Secure Required Licensing/Registration

Before engaging in any Financial Activities, DNFBP, or VASP activities, the natural or legal person must obtain a license, registration, or enrolment from the Competent Authority or the relevant Supervisory Authority.

Violation of this specific licensing requirement carries a potential penalty of imprisonment and a fine of not less than AED 200,000 and not exceeding AED 10,000,000, or either penalty.

Conduct and Maintain Risk Assessment

The next step for the Regulated Entities is to identify, understand, manage, assess, document, and continuously update the risks of financial crimes such as Money Laundering, Financing of Terrorism, and Proliferation Financing, within their business scope. This assessment is grounded in a risk-based approach, and multiple risk dimensions are considered.

  • Assessing how the new risks (Virtual Assets, Proliferation Financing) can affect specific products, services, and customer base.
  • Allocating more resources to scrutinise high-risk areas (e.g., Politically Exposed Persons, Clients from High-Risk Countries, Complex Crypto Transactions).

Moreover, the Risk Assessment study and related information are retained and provided to the Supervisory Authority upon request.

Establish Robust Internal Policies and Controls

The following step for Regulated Entities is to establish internal AML/CFT policies, controls, and procedures that are approved by Senior Management. These controls enable Regulated Entities to manage and mitigate identified risks.

  • These Policies are applied to all branches and subsidiary companies in which the REs own a majority share.
  • These Policies and Procedures are continuously reviewed and updated.

Implement Customer Due Diligence (CDD) and Monitoring

The next step is implementing CDD measures and continuous monitoring procedures for clients. The scope for these measures is determined based on the multiple ML/TF/PF risk dimensions and the outcomes of the National Risk Assessment (NRA). The CDD process usually consists of,

  • Identifying and verifying the information of the Customer and the Beneficial Owner in a legal person (the natural person exercising ultimate effective control over a corporate person).
  • Identifying the nature of the Customer’s business and the purpose of the business relationship.
  • Ensuring not to open or maintain accounts, or conduct transactions, under anonymous, fictitious, alias, or numbered names, or provide services to such accounts.

Ensure Beneficial Owner Transparency

While onboarding corporate clients, the identification of the Ultimate Beneficial Owner ensures transparency and accountability.  

  • Intentionally providing false or misleading information concerning the Beneficial Owner is subject to criminal punishment (imprisonment and a fine of not less than AED 20,000, or either penalty).

Apply Targeted Financial Sanctions (TFS) Forthwith

For Regulated Entities, applying the instructions issued by the Executive Office or any other Competent Authorities concerning Targeted Financial Sanctions is another essential component of an efficient AML/CFT Compliance Program. This includes,

  • Freezing of funds and prohibition of making them available for designated persons/organisations.
  • Filling relevant reports such as Confirmed Name Match Report (CNMR) and Partial Name Match Report (PNMR), as the case may be.

Violation of these instructions is a serious offence, punishable by imprisonment and a fine of not less than AED 20,000, or either penalty.

Report Suspicious Transactions

In case there is a red flag in the transaction pattern or Regulated Entities have reasonable grounds to suspect that the Transaction or Funds are related to the criminal offences of Money Laundering, Financing of Terrorism, and Proliferation Financing, then taking appropriate steps is required. This includes,

It must be noted that confidentiality provisions cannot be invoked to withhold information requested by the Unit. (Note: This obligation does not apply to legal professionals or independent legal auditors if the information was obtained under professional secrecy).

Avoid "Tipping Off"

After taking the necessary steps required by FIU to file STR or SAR, ensuring the crucial information is not tipped off to the client in question is imperative for Regulated Entities.

Any person who notifies, warns, or discloses information related to Suspicious Transactions under review or investigation (in contravention of confidentiality rules) is subject to punishment with imprisonment and a hefty fine of not less than AED 50,000, or either penalty.

Comply with VASP-Specific Regulations

If the stakeholder is a VASP (defined as a person conducting one or more Virtual Asset activities specified in the Executive Regulations for commercial purposes), then complying with VASP-Specific Regulations (VARA) is required. This includes,

  • Obtaining the required license/registration.
  • Refraining from dealing in, promoting, or offering for sale Virtual Assets characterised by total anonymity or that prevent or obstruct the ability of the Competent Authorities to trace the Transaction or its parties.

Violation of this rule is punishable by imprisonment for a period of not less than three (3) months and a fine of not less than AED 50,000, or either penalty.

Record Keeping

Retaining all records, documents, and data relating to domestic and international transactions, AML/CFT compliance program and measures for the prescribed time is mandatory for Regulated Entities as per the UAE’s AML/CFT Law.

This also ensures their immediate availability to Competent Authorities upon request during regulatory inspections or audits.

Make Compliance Simpler!

Understand the New AML 2025 Framework with AML UAE

Challenges Faced by the Regulated Entities in complying with the legal obligations

While the 2025 law establishes clear compliance requirements, translating these obligations into operational reality presents significant challenges.

This section highlights the most significant hurdles businesses are likely to face under the strengthened AML framework, including Technology Limitations, Cost Burden, Knowledge & Skill Divide, Complex Ownership Structures, Operational Disruption & Impact on Customers. Further, the Cabinet Resolution No. 134 of 2025 will take effect from December 14, 2025, and regulated entities will have to ensure that they follow the regulations. Read our Guide to New Cabinet Resolution No. 134 of 2025 on AML Law No. 10 of 2025.

Technology Limitations

Many businesses rely on legacy systems that cannot support virtual asset monitoring, Screening against local and global watchlists, or real-time sanctions updates. Integrating blockchain analytics, tracking cryptocurrency transactions, and identifying complex ownership structures often requires significant technical upgrades.

Cost Burden

Implementing an enhanced AML framework, including technology, training, governance, and dedicated compliance roles, creates substantial financial strain, particularly for smaller DNFBPs and emerging VASPs.

Knowledge & Skill Divide

Many employees lack understanding of new requirements, particularly regarding virtual assets and Proliferation Financing. This increases the risk of misidentifying red flags or applying due diligence inconsistently.

Complex Ownership Structures

Identifying true Beneficial Owners in complex corporate structures with multiple layers, offshore entities, and nominee arrangements remains extremely difficult. Clients often cannot provide complete ownership information, and cross-border chains require verification in multiple jurisdictions, which can further delay onboarding and monitoring.

Operational Disruption & Impact on Customers

Enhanced CDD, STR reporting, and Sanctions Screening can slow onboarding, increase documentation demands, and create friction for legitimate customers. Businesses must balance regulatory expectations with customer experience.

Don’t Let Trials Obstruct Your Compliance Pathway

Tackle the Toughest Hurdles Along with AML UAE

Best Practices for the Stakeholders to Ensure New UAE AML Law 2025 Compliance

While challenges are common, solutions exist. Businesses that approach AML compliance strategically distinguish themselves as market leaders from those merely avoiding penalties.

This section outlines the essential best practices for building an effective AML compliance under the 2025 framework. These include adopting a Risk-Based Approach, investing in Quality Technology Adoption, building a Strong Compliance Culture, Maintaining Documentation, and Leveraging Expertise.

Adopt Risk-Based Approach

Regulated Entities must allocate compliance resources based on actual risk levels. This includes conducting ML/FT risk assessment in line with NRA and SRA, supervisory guidance, global best practices, and categorising customers into risk tiers (low, medium, high) and applying appropriate due diligence levels, documenting Risk Assessment methodology and reviewing ratings regularly.

Invest in Quality Technology

Regulated Entities must deploy robust AML technology capable of real-time transaction monitoring, automated sanctions screening, blockchain analytics, and scalable case-management systems that integrate smoothly with existing infrastructure.

Build a Strong Compliance Culture

Regulated Entities must foster a culture where compliance is everyone’s responsibility. This requires visible senior management support, regular staff training & internal audits, clear accountability, open communication, and protected whistleblowing mechanisms to encourage internal reporting.

Maintain Documentation

Regulated Entities must maintain detailed records of all compliance decisions, due diligence, risk assessments, onboarding outcomes, suspicious transaction analyses, training sessions, and audits. Employing standardised templates and securing digital storage helps ensure consistency and accessibility.

Leverage Expertise

Regulated Entities must strengthen their AML frameworks by engaging specialised consultants, legal advisors, and technology experts for compliance program design, gap analysis, independent audits, system optimisation, and staff training development.

Reign Over Regulatory Changes

The New UAE AML/CFT Law of 2025, Federal Decree by Law No. 10 of 2025, significantly strengthens the national compliance framework, introducing new offences, virtual asset regulations, and higher penalties, amongst other things. For businesses, strong AML compliance is essential to protect their reputation and adhere to global best practices.

The message is clear: the cost of compliance is always lower than the cost of violation.

How AML UAE can support your transition to the NEW AML/CFT Law 10 of 2025

AML UAE can help you transition from the old Federal Decree Law No. 20 of 2018 to the new law.

Frequently Asked Questions (FAQs)

What happens to violations committed under the Old Law of 2018?

Violations under the previous AML framework remain prosecutable because the UAE imposes no statute of limitations on ML offences, even after the introduction of the New UAE AML law of 2025.

Risk assessments must be continuously monitored and regularly updated.

The business relationship cannot proceed without identifying Beneficial Ownership.

Yes, but only if they comply with AML/CFT requirements, conduct robust KYC procedures, and ensure traceability of all virtual asset transactions.

Businesses enjoy legal immunity for STRs filed in good faith; liability only applies when reporting is made maliciously or with wrongful intent.

While not explicitly criminalised under the New Law of 2025, failure to train staff could constitute a violation of internal policy obligations.

Yes. Foreign nationals convicted under AML offences may face deportation in addition to other penalties under the 2025 law.

 

Compliance Doesn’t Wait - Neither Should You.

Adopt Our Tailored Solutions to Efficiently Navigate New UAE Law 2025

Share via :

About the Author

Pathik Shah

FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)

Pathik is an ACAMS-certified AML consultant specialising in governance, risk, and compliance for regulated entities in the UAE. He brings over 28 years of experience, with 1,000+ hours of AML training and 200+ advisory engagements across DNFBPs, VASPs, and FIs. He supports businesses in aligning with AML/CFT requirements from the CBUAE, DFSA, MoET, MoJ, VARA, CMA, FSRA, and FATF. Known for translating complex regulations into audit-ready procedures, Pathik enables operational clarity and compliance readiness.

Reach Out to Pathik

Regulator-Ready Business Risk Assessment for VASPs in UAE

Benefits of Well-Articulated Business Risk Assessment

Blogs

Published On: 12/09/2025

Table of Contents

Protect your business with reliable and effective AML strategies with AML UAE.

Last Reviewed On: 07/23/2026   |   Last Updated On: 07/23/2026

Business Risk Assessment for VASPs: At a Glance

  • Business Risk Assessment helps VASPs identify, assess and mitigate ML/TF/PF Risks.
  • Covers key risk factors for VASPs: Customers, Geography, Transactions, Products/Services, Delivery Channels.
  • Business Risk Assessment must be aligned with the VARA Rulebook, Federal AML/CFT Laws, UAE NRA and other sectoral risk assessments.
  • VASPs must regularly update BRA to reflect new products, typologies and emerging risks.
  • A Robust BRA supports stronger controls, enhanced decision making and regulator-ready compliance.

Regulator-Ready Business Risk Assessment for VASPs in UAE

A Business Risk Assessment (BRA) is a structured analytical process for Virtual Assets Service Providers (VASPs) in UAE. It assesses the nature of VASP’s business model, customer base, products, technologies and transaction patterns with an aim to determine the impact of these factors in exposing the business to financial crime risks.

The BRA facilitates identification of the inherent risks, evaluation of the already implemented control measures, calculation of the residual risks and is based on the risk appetite of VASPs. BRA provides insights into the actual Money Laundering (ML), Terrorist Financing (TF), and Proliferation Financing (PF) risks the business is exposed to.    

Why VASPs Require a Structured BRA?

VASPs operate in an ecosystem where transactions move fast, across borders and often without traditional financial intermediaries. It offers a platform which covers anonymity in financial transactions. And it is a consensus that where anonymity lies, the chances of ML/TF/PF risks are higher.

Unlike traditional financial transactions, in VASPs, the activities happen without face-to-face interaction, and users may deposit or withdraw funds from anywhere in the world.

This creates a business environment where risks are not always visible on the surface. In order to get a comprehensive view of the ML/TF/PF threats, VASPs are required to undertake a structured BRA.    

Business Risk Assessment through risk weighing and risk scoring provides a foretelling vision into the risk areas that are more vulnerable to the chain of financial crimes.

A well-done BRA helps a VASP break down the risk factors in a systematic way instead of relying on assumptions or scattered observations.

It ensures that the VASP get a full vision to understand where its vulnerabilities lie, how its products can be misused, which controls are working and which aren’t, and how it is exposed to on-chain threats.

Without a structured BRA, VASP is essentially operating in the dark, making decisions without a clear grasp of its own risk exposure. An efficiently conducted Business Risk Assessment not only protects the business from probable financial crimes but also ensures that resources are prioritized in a better manner, specifically in areas that are weak.   

Regulatory Mandate for VASPs to Conduct BRA under AML/CFT Framework of UAE

Virtual Assets Service Providers (VASPs) in UAE are regulated and supervised by Virtual Assets Regulatory Authority (VARA). VARA issues periodic guidelines and rulebooks that VASPs are obligated to adhere.

The Virtual Assets and Related Activities Regulations 2023 recognise the Federal AML/CFT Laws (Federal Decree by Law No. (10) of 2025 Regarding Anti-Money Laundering and Combating the Financing of Terrorism and Proliferation Financing and its implementing Cabinet Resolution No. 134 of 2025).

It mandates VASPs to comply with all Federal AML/CFT Laws, regulatory requirements, rules and directives with respect to VASPs’ AML/CFT obligations.

The Federal Decree by Law No. (10) of 2025 calls for a comprehensive Business Risk Assessment for VASPs to identify, assess and mitigate the ML/TF/PF within the business model.

Additionally, VARA rulebook Part III D talks about the Business Risk Assessment obligations of VASPs.

Rule III.D of VARA rulebook requires VASPs to conduct and maintain a documented and data-driven AML/CFT Business Risk Assessment in order to understand, identify and assess ML/TF risks specific to their business.

BRA must be carried out at least once every 3 months, and when there are changes in business model, products/services, customer base, technology, or new regulatory requirements. The AML/CFT policies, procedures, systems, and controls must align with the BRA, and high-risk areas must be prioritized for resource allocation.

Unsure where to start with the new AML/CFT law?

Partner with us to quickly realign your policies and procedures with the new law.

Key Risk Factors VASPs Must Consider for Effective BRA

An effective BRA starts with identifying what can expose a VASP to financial crime risks. The risk is often enveloped in the form of customers, jurisdictions, transactions, products, services and delivery channels.

Evaluating these areas helps the VASP build a realistic picture of where vulnerabilities exist. While conducting Business Risk Assessment, VASPs must consider risk factors related to these key areas.  

The following infographic depicts the key risk factors VASPs must take into consideration while performing Business-Wide Risk Assessment.

Customer Related Risk Factors

While conducting Enterprise-Wide Risk Assessment (EWRA), the VASP must assess customer profiles, behavior patterns and wallet activities. Factors such as weak KYC data, customers with cloudy sources of funds, PEPs, high-net worth individuals dealing in large volumes or showing inconsistent behavior increase vulnerability.

Assessing these risks helps VASPs understand which customer segments require additional AML/CFT controls, such as Enhanced Due Diligence (EDD) to prevent misuse of the platform.  

Geography Related Risk Factors

Another major key factor to consider while conducting Business-Wide Risk Assessment is to analyze VASP’s risk exposure through where customers and counterparties are located. Crypto flows are borderless, that makes the destination of originators and beneficiaries a major risk factor.

Hence, considering geographic risk in the BRA helps the VASPs to identify potential links to high-risk or sanctioned nations and jurisdictions associated with illicit crypto flows.

Transaction Related Risk Factors

In the Virtual Assets sector, the transactions are pseudonymous, which is a major risk factor for financial crime if controls are not deployed appropriately. Therefore, while conducting a comprehensive Business Risk Assessment, VASPs are required to consider transaction related risk factors.

This includes sudden spikes in transactions, irregular or unusual transaction patterns, bizarre amounts and frequency of transactions that have no logical explanation, source of funds or wealth that have traces to criminal activities.

Products and Services Related Risk Factors

In the Virtual Assets sector, different crypto products carry different inherent risks. These include trading platforms with high-value movement, NFT platforms with anonymized transfers or OTC desks dealing in large, off-exchange transactions.

Evaluating the risk of particular products and services that VASPs offer allows them to understand the offerings which are more vulnerable to ML/TF/PF activities. This facilitates putting additional AML/CFT controls at places that are weak.      

Delivery Channel Related Risk Factors

While developing the business risk profile, VASPs must consider delivery channel related risk factors, as how users access the VASPs affects the likelihood of abuse. For instance, online onboarding may face identity spoofing, API-based services can enable high-speed activities, and integration with third-party platforms may introduce risks that VASPs cannot fully control.

Therefore, assessing delivery channel related risks helps the VASPs to identify where additional verifications or oversight mechanisms are required.

Stay Ahead of Evolving Virtual Assets Risks

Get Expert Guidance to Ensure Your BRA Covers All VA-Specific Typologies.

Step-by-Step Guide for VASPs to Undertake Comprehensive Business Risk Assessment

VASPs often feel overwhelmed to conduct an effective BRA, especially because the Virtual Assets ecosystem moves fast and ML/TF risks evolve even faster. A structured step-by-step approach helps bring clarity to this process.

Key steps for VASPs to undertake an extensive Business Risk Assessment include

  • collecting business data, categorizing risks,
  • developing methodology for risk calculations,
  • assessing inherent risk, evaluating control measures,
  • finding residual risk,
  • conducting gap analysis of findings, documenting it, and
  • preparing the final BRA report.

The below infographic illustrates the chronological approach for VASPs to conduct efficient Enterprise-Wide Risk Assessment.  

Collecting and Mapping Business Data

The process of Business Risk Assessment (BRA) for VASPs begins with collecting all relevant information regarding the operating model through a customized questionnaire. This involves collecting structured data on customer types, regions, products, transactions and delivery channels. Further, the analysis of the National Risk Assessment and Sectoral Risk Assessment is performed to ensure thorough compliance with them.

Through mapping of this information, VASP establishes a factual basis that anchors the entire risk assessment. It ensures that every decision is grounded in how the business truly functions rather than mere assumptions.

Identifying and Categorizing Risks

Once the data mapping process is over, identifying and categorizing risks based on the gathered data takes place. VASPs disambiguate the collected data and scatter into different risk factors.

This includes categorizing possible risks such as risky customers, high-risk countries, complex products, unusual transactions, weak onboarding channel, etc.

These risks are later grouped into categories, so they are easy to analyze. In simpler terms, this step basically is to recognize “Where can things go wrong”.  

Developing a Structured Methodology for Risk Calculation

Post categorizing the risk into different risk factors, VASPs develops a structured methodology for risk calculation.

Designing a repeatable and auditable approach, defining scales and risk weightings (likelihood, impact), outlining qualitative and quantitative thresholds, specifying how to combine scores (matrix, weighted average), and setting governance rules for calibration, helps VASPs in turning a list of risks into a measurable framework.

Assessing Inherent Risks

Post determining a structured methodology for risk calculation, the inherent risk of the VASP’s business model is evaluated. Inherent risk is basically the ML/TF/PF risk that is omnipresent in the business from its inception, before applying any controls.

To assess the inherent risk, the likelihood of occurrence or materialization of identified ML/TF risk and the impact of that risk on the VASP is calculated using both quantitative and qualitative methods.      

Evaluating Mitigation Controls

Once the inherent risk of the VASP is identified, the following process is to evaluate the mitigating controls that are already present in the business.

This includes checking the efficacy of AML/CFT Policies and Procedures, KYC Processes, Screening tools, Transaction Monitoring rules, Regulatory Reporting pathways and other control measures.

Determining the Residual Risks

After evaluating the effectiveness of mitigation controls, the subsequent stage is to determine the level of residual risks. Residual risk is basically ML/TF risk that is remaining in VASP after safeguards.

Residual Risk in VASP business model is calculated through a structured methodology that is inherent risk minus the controls. This uniform approach helps VASPs to produce consistent residual ratings across risk categories.  

Conducting Gap Analysis

After assigning the residual risk score to each risk category, the following workflow is to conduct a gap analysis. Undertaking analysis of differences with reference to the risk appetite of the VASP provides a full insight into the actual weaker areas and facilitates developing a roadmap that is required to fulfill that gap.

These gaps are subjective and can differ from entity to entity, as it depends on the individual risk appetite. For VASPs, conducting a thorough gap analysis is of utmost importance as it shows the strengths and weaknesses of the business through raw approach.

Documenting Findings and Risk Scoring

Following the gap analysis, documenting the findings and ultimate risk scoring captures the full assessment in a structured record for VASPs. This documentation also includes recording risk inventory, scoring rationale, data inputs, control assessments and version history in an organized manner.

The explanation and logic for reaching the final risk scoring are required to be documented. Thorough documentation ensures transparency and reduces the chances of errors.

Preparing the Final BRA Report

The final stage of an effective Business Risk Assessment for VASPs is preparing the final BRA report. It is a consolidated report that summarizes the VASP’s risk posture, high-risk exposure areas, key vulnerabilities, and residual risk priorities, along with a thorough recommended remediation plan.

This action plan outlines resource allocation, suggests updating AML/CFT policies/procedures and provides a roadmap for effective implementation and impactful decision-making to combat the risk of ML/TF/PF activities.

Is Building a Structured Business Risk Assessment Too Cumbersome?

Get Specialized Solutions for End-to-End BRA Support.

Unlocking the Benefits of Business Risk Assessment for VASPs in UAE

The advantages of a well-articulated Business Risk Assessment show up across the entire organization. It sharpens the way business understands its risk exposure, highlights which areas need stronger controls and removes guesswork from decision-making.

Provides a Multidimensional and Balanced View of ML/TF/PF Risks

A robust Business Risk Assessment provides a comprehensive perspective on ML/TF/PF risks that a VASP is exposed to. It takes multiple dimensions into consideration, such as customer related risks, geographical risks, product/services related risks, delivery channel and transaction patterns related risks.

This multidimensional approach offered by BRA enables VASPs to make nuanced risk-based decisions regarding financial crime risk management and controls.

Facilitates the Development of an Informed and Curated ML/TF/PF Risk Appetite

A Well-defined and analyzed Business-Wide Risk Assessment (BWRA) provides VASPs a clear vision into their risk areas.

Moreover, it offers necessary data to VASPs to understand the exposure of financial crimes to their business model. That helps them to develop an informed and carefully curated ML/TF/PF risk appetite commensurate with the nature, size and risk exposure of the VASPs.  

Drives Efficient Allocation of Resources Towards ML/TF/PF Risk Management

An efficient Business Risk Assessment framework ensures that resources are deployed appropriately. It facilitates VASPs to prioritize areas that pose a high risk of ML/TF/PF activities and reduces underutilization of its resources.

By analyzing each risk area it helps VASPs to plan their risk management efforts to optimize their AML/CFT/CPF compliance.

Strengthens Competence in ML/TF/PF Risk Management

An effective BRA framework enhances the overall competency of VASPs in managing financial crime risks. With the right assessment of risk exposure, calculation of inherent risk, residual risks and evaluation of control measures, VASPs help to build a more knowledgeable and risk-aware workforce.

It supports data-driven decision making, ensuring management of financial crime risks.

Ensures Alignment with National Risk Assessment and Sectoral Risk Assessment

An efficient BRA framework ensures that a VASP aligns with the findings of the National Risk Assessment and Sectoral Risk Assessments.

By incorporating outcomes from these assessments, VASPs can enhance their understanding of ML/TF/PF risks.

Supports Long-Term Growth Through Risk-Informed Decisions

A good Business-Risk Assessment helps VASPs to understand where risks are and how to manage them.

This lets the business make smarter decisions, plan safely and grow without unexpected problems. Over time, it builds a stronger and more stable business.

Make Your Business Risk Assessment Work Harder for Your VASP

Develop Methodologies for BRA that Unlock Its Full Potential

Repeated Mistakes VASPs Made While Performing BRA

Despite clearly defined regulatory expectations, many VASPs fall into similar traps when conducting BRA. The basic mistakes often repeated by VASPs often come from rushing the process with unrealistic risk scoring, misalignment with the actual business model, absence of documentation and treating the Business Risk Assessment as a single time exercise.

These mistakes often weaken the objective of conducting Business Risk Assessment and end up introducing VASPs to regulatory penalties when expectations of regulators are not met.

The infographic below demonstrates the common mistakes replicated by VASPs while performing Business Risk Assessment.

Treating BRA as One-Time Exercise

There is a wide-spread misjudgment among VASPs that Business Risk Assessment is a single time exercise. The BRA is mistakenly treated as a static document instead of a living assessment.

This results in BRA that no longer reflects the VASP’s real ML/TF/PF exposure as the risk factors affecting it keep changing. The approach to treating Business Risk Assessment as One-time activity quickly makes it outdated.  

Not Aligning BRA with Actual Business Model

Some VASPs prepare BRA that appears good on paper; however, they lack the substance. The prepared Business Risk Assessment does not resonate with the actual business model, its products, customers, supply chains, or transaction patterns.

Inaccurate representation makes risk assessment theoretical rather than practical. A BRA that is disconnected from the core business model cannot lead to true and effective decision-making.

Ignoring On-Chain Typologies and Virtual Assets Red Flags

One of the major roadblocks for VASPs to conduct an effective Business Risk Assessment is focusing on traditional financial crime risks while ignoring the Blockchain-specific ML/TF/PF Typologies.

The nature of the Virtual Assets (VA) Sector is quite different from the basic financial or DNFBPs sector. And this uniqueness requires a unique approach, which VASPs fail to implement.

Failing to consider VA specific red flags and typologies in the BRA underestimates the real risk exposure and weakens monitoring strategies.

Weak Documentation and Lack of Supporting Evidence

A lot of VASPs lag behind in preparing regulator-ready BRA because the findings are not supported by a clear rationale, data and evidence. The assessment tends difficult to defend during audits or regulatory reviews due to illogical, scattered and undocumented assumptions.

A strong BRA requires a documented methodology, scoring explanations and consistent use of risk metrices. The failure to incorporate these practices in BRA makes it sluggish and incompetent.

Unrealistic Residual Risk Ratings

A very common mistake repeated across multiple VASPs is the inefficiency in realistically rating the residual risks.

Residual Risk is a very important aspect of an accurate Business Risk Assessment, as it paves the way for sound decision-making and gives a real idea of financial crime risk exposure to VASPs.

However, wrongly calculating it by overestimating control effectiveness or underestimating inherent risk exposure creates a false sense of security.

No Scope for Mistakes Anymore

Reign Over Basicness with Regulator-Ready Business Risk Assessment

Best Practices for VASPs to Conduct Robust BRA in Line with Regulatory Expectations

As the regulators often find Business Risk Assessment by VASPs underwhelming, here comes the savior. With the implementation of certain best practices while performing an Enterprise-Wide Risk Assessment ensures that it fulfills the regulator’s expectations.

These best practices include incorporating sector-specific risk indicators, alignment with UAE NRA and VARA, periodic updates in VA-specific typologies, leveraging AI for risk scoring, using qualitative/quantitative scoring, training employees and documenting all assumptions, data, rationale and methodologies.

Moreover, integrating the Business Risk Assessment outcomes into the internal framework and conducting quarterly reviews ensures the robustness of BRA.

The following infographic represents the best practices for VASPs to conduct BRA that are in line with the Regulatory expectations.

Incorporating Sector-Specific Risk Indicators for VASPs

For an accurate Business Risk Assessment, VASPs must include ML/TF/PF risk indicators that are specific to the Virtual Assets Sector. This includes indicators like wallet anonymity, cross-chain transfers, decentralized platforms or high-velocity trading patterns.

Embedding these VA-specific risk indicators into the BRA ensures that VASPs reflect actual threats rather than solely relying on traditional sayings.  

Aligning BRA with the UAE National Risk Assessment and VARA Regulations

VASPs must ensure that it aligns Business Risk Assessment with the results of National Risk Assessment (NRA), VARA Regulations and UAE’s Federal AML/CFT Laws. The risks and industry findings identified in UAE NRA and relevant Sectoral Risk Assessments must be considered in the VASP’s risk rating methodology.

This alignment ensures that VASP’s internal view of risk matches the country’s identified threats and regulatory expectations.

Updating Typologies and Red Flags for Virtual Assets Regularly

Since financial crime methods evolve rapidly in the crypto landscape, VASPs must continuously refresh their knowledge of typologies and red flags.

This includes staying updated on emerging schemes such as Anonymity-Enhanced Transactions, new or evolving Virtual Assets Products etc. Keeping the typology database current ensures that VASP is using the latest intelligence to judge ML/TF/PF risk exposure accurately in BRA.

Leveraging Advanced Technology for Risk Scoring and Weighing

For a robust Business Risk Assessment, VASPs must leverage advanced technology rather than solely relying on manual judgement.

VASPs should integrate help from tools such as blockchain analytics platforms, automated scoring engines, visual heatmaps and AI-based gap detection in BRA. This improves accuracy and consistency in risk scoring.

Using Qualitative and Quantitative Scoring for Balanced Assessment

VASPs must combine qualitative and quantitative scoring scales for a balanced approach in Business Risk Assessment. This includes merging numerical scoring with approximate judgment.

This blending approach in the risk scoring model prevents the BRA from becoming overly mechanical. It ensures that VASPs evaluate the ML/TF/PF risks of their business from both a data-driven and practical perspective.

Documenting All Data Sources, Assumptions and Methodologies

In order to create a structured Business Risk Assessment, VASPs must document every data source used, the assumptions behind scoring, the logic for weightings and the rationale behind the final risk rating.

These are some of the most important aspects of BRA. Such documentation strengthens governance and ensures that BRA can be defended during regulatory audits.  

Training Employees on Risk Assessment Concepts

For an effective and sound Business Risk Assessment, it is essential that VASPs must provide periodic training for their employees on risk assessment concepts.

The accuracy of BRA relies on informed people. Providing training on VA-specific typologies and scoring methodologies builds internal competency. It ensures consistent judgment across VASP and creates shared understanding of how risk decisions are made.

Incorporating BRA Outcomes into the Internal Framework of VASPs

For an effective implementation of Business Risk Assessment, it is crucial that VASPs incorporate the findings and recommendations of BRA Report into the internal framework of their organization.

This includes integrating BRA outcomes into VASP’s AML/CFT Policies and Procedures, Customer Risk Assessment, Transaction Monitoring Calibration, internal audit and other compliance monitoring plans. Allocating Resources as per the results of BRA, increases the efficiency of VASPs.

Conducting Quarterly Reviews of BRA

The best practice to make the BRA current is to conduct periodic reviews of it. VASPs must establish framework to quarterly review the BRA against any new developments, supervisory findings and emerging typologies.

Moreover, VARA expects VASPs to analyze key operational data and material changes, at least once every quarter. This ensures that BRA remains relevant and accurately reflects the risk landscape throughout the year.

Turn Your Business Risk Assessment into Regulator-Ready Backbone for Your VASPs Operations

A well-articulated Business Risk Assessment is not just a compliance requirement, but a foundation for an effective AML/CFT Program for VASPs. As Virtual Assets sector continues to evolve, regulators expect VASPs to display real understanding of their own ML/TF/PF risk exposure. An organized and regularly updated Business Risk Assessment facilitates VASPs to stay ahead of these expectations instead of reacting at the last minute.

AML UAE= Your Trusted Partner to Conduct Robust Business Risk Assessment

Let Us Take Charge of Your Compliance Journey!

Frequently Asked Questions (FAQs)

What is Business Risk Assessment for VASPs in UAE?

Business Risk Assessment is a structured review of the financial crimes risks faced by VASPs’ business model. It gives insight into risk exposure considering wide-ranging factors such as customer base, delivery channels, geographies, transaction patterns, and product/services offered.

VASPs in UAE should update their Business Risk Assessment at every quarter or occurrence of significant events as mandated and expected by the UAE’s regulatory authorities.

VASPs should evaluate customer related risks, transaction related risks, geographical risks, product/services related risks, delivery channel related risk and other relevant risks for an effective Business Risk Assessment.

To perform a Business Risk Assessment, collect mandatory business data, assess inherent risk, evaluate existing control measures, calculate residual risk with a structured methodology, prepare a report and document all the data and rationale.  

Yes, VASPs are required to align their Business Risk Assessment with the outcomes of UAE’s National Risk Assessment and FATF Guidance.

To conduct a Business Risk Assessment for a VASP, first understand the regulatory requirements and the nature of the business, gain a grasp over VA-specific typologies, then determine the risk appetite, develop a board-approved methodology and commence with the assessment with relevant business-related data.

AI facilitates VASPs to perform BRA by analyzing large customer sets, transactions and on-chain data sets more accurately. It also automates scoring and identifies anomalies that a manually conducted Business Risk Assessment may miss.   

Share via :

About the Author

Pathik Shah

FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)

Pathik is an ACAMS-certified AML consultant specialising in governance, risk, and compliance for regulated entities in the UAE. He brings over 28 years of experience, with 1,000+ hours of AML training and 200+ advisory engagements across DNFBPs, VASPs, and FIs. He supports businesses in aligning with AML/CFT requirements from the CBUAE, DFSA, MoET, MoJ, VARA, CMA, FSRA, and FATF. Known for translating complex regulations into audit-ready procedures, Pathik enables operational clarity and compliance readiness.

Reach Out to Pathik

Supplemental Guidance for Real Estate Agents and Brokers – March 2026

Supplemental Guidance for Real Estate Agents and Brokers

Blogs

Published On: 06/01/2026

Table of Contents

Protect your business with reliable and effective AML strategies with AML UAE.

Last Reviewed On: 07/22/2026   |   Last Updated On: 07/22/2026

MoET's REAB Guidance in a Nutshell

  • Issued by the UAE Ministry of Economy and Tourism (MoET), the REAB Guidance sets out AML/CFT/CPF expectations and obligations for real estate agents and brokers as DNFBPs under Federal Decree-Law No. (10) of 2025.
  • Defines eight core obligations: business risk assessment, internal controls, customer due diligence, suspicious transaction reporting, governance, record keeping, targeted financial sanctions, and training.
  • Highlights five sector-critical priorities: beneficial ownership transparency, source of funds and wealth verification, risk-based monitoring across the transaction lifecycle, embedding compliance in daily operations, and cooperation with competent authorities.
  • Mandates Real Estate Activity Reports (REAR) for freehold purchase or sale transactions where: cash payments reach AED 55,000 or more; payment is made using virtual assets; or funds were converted from or to virtual assets at any point in the funding chain. REAR obligations apply in addition to STRs where suspicion arises.
  • Flags common gaps in UAE brokerages: weak beneficial ownership tracing, inconsistent risk-based measures, deferred compliance under commercial pressure, and record keeping shortfalls.
  • Uses ten case studies and key red-flag indicators to show how layered ownership, PEP exposure, virtual assets, and third-party funding can signal ML/TF/PF risk in real estate deals.

In March 2026, the UAE Ministry of Economy and Tourism (MoET) published its Supplemental Guidance for Real Estate Agents and Brokers (REAB), a landmark sector-specific document that sits alongside the broader AML/CFT/CPF Guidelines for Designated Non-Financial Businesses and Professions (DNFBPs). This guidance is not a standalone document. It is grounded in Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025, the operative legal instruments governing anti-money laundering, counter-terrorism financing, and counter-proliferation financing compliance in the UAE today.

For real estate agents, brokers, and brokerage firms operating across the UAE mainland and free zones, this guidance is an important supervisory benchmark MoET may use when assessing whether a real estate firm has met its obligations. It sets out what MoET expects, what risks the sector must manage, and what practical steps must be in place. Whether you run a one-person brokerage in Dubai or a multi-branch firm across the emirates, these obligations apply to you.

This article provides a comprehensive, plain-language breakdown of the MoET REAB Guidance. It is written for real estate professionals, compliance officers within brokerage firms, and senior management who need to understand what the guidance actually requires in practice, not just what it says on paper.

Note

This article is based on the MoET Supplemental Guidance for Real Estate Agents and Brokers published in March 2026. It is intended as a practical commentary and does not constitute legal advice. Regulated entities should read the full guidance document and consult their Compliance Officer or a qualified AML advisory firm for entity-specific implementation.

What Is the MoET REAB Guidance and Why Does It Exist?

The Legal Foundation

The MoET Guidelines for Real Estate Agents and Brokers are formally grounded in Federal Decree-Law No. 10 of 2025 on Combating Money Laundering, Terrorist Financing, and the Financing of the Proliferation of Weapons, as well as its executive regulations under Cabinet Resolution No. 134 of 2025. These instruments replaced the prior 2018 legislation (Federal Decree-Law No. 20 of 2018, repealed by Article 41 of FDL 10/2025) and came into effect on 14 October 2025 and 14 December 2025, respectively, per the entry-into-force provisions of the respective instruments. All compliance frameworks, policies, and procedures for UAE real estate DNFBPs must be anchored to these updated laws.

The guidance itself does not create new law. It interprets and operationalises existing legal obligations in a sector-specific way. When there is any conflict between the guidance and the law, the law prevails. That said, supervisory authorities will use this guidance as a benchmark when assessing whether a real estate firm has met its obligations.

Why Real Estate Carries a High Inherent Risk

The UAE National Risk Assessment (NRA) and Sectoral Risk Assessment (SRA) have both identified the real estate sector as carrying a High inherent ML/TF/PF risk. This is not an arbitrary designation. It reflects specific structural characteristics of the sector:

  • Transaction values are significantly high, making real estate an attractive vehicle for integrating large volumes of illicit funds in a single deal.
  • The sector regularly involves cross-border clients, non-resident investors, and foreign legal structures, many of which introduce opacity into the ownership and funding chain.
  • Intermediaries such as agents, brokers, legal representatives, and notaries can be used knowingly or unknowingly to distance a beneficial owner from the transaction.
  • Complex ownership structures involving holding companies, trusts, foundations, and offshore vehicles are common in the sector and can be deliberately constructed to conceal the ultimate beneficial owner.
  • Cash transactions and virtual asset payments are present in the sector, both of which reduce financial transparency.

These risk factors are not theoretical. They reflect patterns that supervisory authorities and financial intelligence units have identified in real transactions. The guidance asks brokers and agents to internalise these risks and build controls that address them directly.

Who Is Covered

The MoET REAB Guidance applies to all real estate agents and brokers, and to the boards, management, and employees of those entities, operating anywhere in the UAE, including the mainland and Commercial Free Zones (CFZs).

A firm falls within scope as a DNFBP when it concludes or facilitates transactions on behalf of its customers relating to the purchase or sale of real estate. This includes marketing properties, negotiating sale and purchase terms, coordinating payment arrangements, handling deposits, and acting as an intermediary between buyers, sellers, developers, and financial institutions.

The most common misconception we encounter when working with real estate firms is the belief that AML compliance is only relevant when something suspicious happens. The MoET guidance makes clear that compliance is a continuous, embedded obligation, not a reactive process. The question is not whether your firm will encounter risk; it is whether your systems are built to recognise and respond to it when it does.

Pathik Shah - CAMS, FCA, CISA, CS, DISA (ICAI), FAFP (ICAI)

Need a DNFBP gap assessment built for commercial gaming?

AML UAE supports GCGRA licensees with DNFBP scope reviews, enterprise risk assessments and AML programme design tailored to commercial gaming models.

The Eight Core Obligations Every Real Estate DNFBP Must Fulfil

Business Risk Assessment

Every real estate DNFBP must conduct a formal, entity-wide Business Risk Assessment (BRA) that identifies and evaluates the ML/TF/PF risks specific to its business model, client base, transaction types, and geographical exposure. This is not a one-time exercise. The BRA must be reviewed and updated to reflect changes in the business, the regulatory environment, and emerging sector risks.

In practice, we observe that many smaller brokerages either lack a BRA entirely or have adopted a template that does not reflect their actual risk profile. The guidance expects your BRA to genuinely build your policies and procedures.

Policies, Procedures, and Internal Controls

Your policies and procedures must address every stage of the client and transaction lifecycle: customer onboarding, identity verification, beneficial ownership identification, ongoing monitoring, suspicious transaction reporting, staff training, record keeping, and the appointment of a Compliance Officer. These must be documented, accessible to relevant staff, and reviewed regularly to remain current.

IN PRACTICE

One of the most common gaps we observe across the sector is the disconnect between written policies and operational practice. A policy that says ‘enhanced due diligence will be applied to all PEP-connected clients’ is meaningless unless your staff know what a PEP is, how to identify indirect PEP exposure, and what additional steps to take. Policy quality is tested at the transaction level, not the document level.

Customer Due Diligence and Ongoing Monitoring

CDD is the cornerstone of your compliance framework. It covers three levels of intensity: standard CDD, Enhanced Due Diligence (EDD), and Simplified Due Diligence (SDD), each applied based on the assessed risk level of the customer and transaction. EDD is mandatory for higher-risk scenarios, including PEPs, cross-border transactions presenting elevated ML/TF/PF risk, complex structures, and significant cash payments. SDD may only be applied where risk is demonstrably low and must be documented.

Ongoing monitoring is also required throughout the relationship and transaction lifecycle, not just at onboarding. This is a practical challenge in the real estate sector, where many engagements are transactional rather than ongoing, and the guidance acknowledges this. The focus, therefore, shifts to ensuring that CDD at the outset is thorough, complete, and proportionate to the risk.

Suspicious Transaction and Activity Reporting

When a real estate agent or broker has reasonable grounds to suspect that a transaction or activity involves money laundering, terrorist financing, or proliferation financing, they are legally required to submit a Suspicious Transaction Report (STR) or Suspicious Activity Report (SAR) to the UAE Financial Intelligence Unit (FIU). Critically, tipping off the customer, alerting them that a report has been or may be filed, is itself a criminal offence.

Governance and Oversight

A qualified, dedicated, and independent Compliance Officer (CO) must be appointed. This individual is responsible for the implementation of and adherence to the AML/CFT/CPF framework. Senior management holds ultimate accountability. The CO must have clear lines of reporting to senior management and must not be subordinate to commercial or business development functions that could create conflicts of interest.

Record Keeping

All records relating to customer identification, beneficial ownership verification, source of funds and wealth evidence, transaction details, CDD measures, risk assessments, internal escalations, and compliance decisions must be maintained for the period prescribed by UAE law. Records must be organised in a way that allows transactions to be fully reconstructed and made available to supervisory authorities on request.

Targeted Financial Sanctions (TFS) Compliance

Real estate firms must screen all customers, beneficial owners, and relevant counterparties against the UAE Terrorist Lists and the UN Security Council Consolidated Sanctions List before establishing a business relationship or executing any transaction. Screening must also be applied on an ongoing basis.

Where a confirmed or potential sanctions match is identified, the firm must follow applicable EOCN procedures, including internal escalation, freezing where required, and reporting to the Executive Office for Control and Non-Proliferation (EOCN). Operational TFS procedures, including screening, freezing, and reporting timelines, are governed by Cabinet Decision No. (74) of 2020.

Firms should also refer to the EOCN Guidance on Counter Proliferation Financing for FIs, DNFBPs and VASPs, and the EOCN Guidance on Proliferation Financing Institutional Risk Assessment, to understand CPF obligations and incorporate proliferation financing risk into their Business Risk Assessment.

IMPORTANT

TFS compliance is not risk-based. It is absolute. The obligation to screen, freeze, and report applies regardless of the risk rating of the customer or transaction. Failure to screen is not merely an administrative weakness. It may expose the firm to serious regulatory, administrative, and legal consequences.

Training and Awareness

Relevant staff must receive regular, role-specific AML/CFT/CPF training. Generic once-a-year awareness sessions are not sufficient. Training programmes must be tailored to the real estate sector, cover emerging typologies, internal procedures, and reporting obligations, and be updated as the regulatory environment evolves. Front-line staff who interact with clients carry particular responsibility and must be equipped to recognise risk indicators in practice.

Is Your Real Estate Firm Compliant with MoET Requirements?

Our AML advisory team works with real estate DNFBPs across the UAE to design and implement risk-based AML/CFT/CPF frameworks that meet MoET expectations. Request a consultation today.

The Five Sector-Critical Compliance Priorities

Ownership Transparency and Beneficial Ownership Verification

The MoET REAB Guidance stresses that agents and brokers must identify and verify the natural persons who ultimately own or control the property transaction, not just the entity or individual who appears at the front of the deal. Where a corporate vehicle, trust, foundation, or nominee arrangement is involved, the firm must look through the structure to identify the Ultimate Beneficial Owner (UBO).

In practice, this means obtaining corporate documents, including certificates of incorporation, shareholder registers, and director identification, and where structures are layered or multi-jurisdictional, applying enhanced scrutiny to understand the commercial rationale and verify control arrangements. Particular attention must be paid to nominee shareholders and directors, where a third party holds ownership or directorship on behalf of another person. Their presence is not inherently suspicious, but their role must be understood and documented.

In our experience reviewing client files across the sector, UBO documentation is often the weakest link. Firms collect the trading licence and the passport, and they stop there. But the MoET guidance asks for something more substantive: a genuine understanding of who controls the transaction, who benefits from it, and whether the structure around it makes commercial sense. That requires asking harder questions, and training your team to ask them.

Jyoti Maheshwari

Jyoti Maheshwari - Partner, NIYEAHMA Consultants LLP

Source of Funds and Source of Wealth Verification

For every real estate transaction, the MoET REAB Guidance requires the agent or broker to verify not only the immediate source of funds used in the deal, but also, in higher-risk scenarios, the broader source of the customer’s accumulated wealth. These are two distinct concepts that serve different purposes.

  • Source of Funds (SoF) refers to the specific funds being used in this transaction. Acceptable evidence includes bank statements, loan or finance agreements, proof of sale proceeds from a prior property, or income records.
  • Source of Wealth (SoW) refers to how the customer built their overall financial standing over time. This is required for higher-risk clients, including foreign PEPs, customers from high-risk jurisdictions, and those using complex structures.

Real estate agents and brokers should obtain sufficient documentation to form a credible and reasonable view of the funds’ legitimacy, and apply enhanced scrutiny where the explanation provided does not align with the customer’s known profile or the transaction value.

Risk-Based Monitoring Throughout the Transaction Lifecycle

One of the most practically significant aspects of the MoET REAB Guidance is its insistence that AML compliance does not end at onboarding. Agents and brokers are expected to monitor transactions and customer behaviour throughout the lifecycle of the deal, from initial engagement to completion and beyond, where a longer-term relationship exists.

Practical monitoring measures include reviewing payment arrangements for changes from what was originally agreed, monitoring for the introduction of third-party funders or unexplained new parties, checking for rapid resales or sudden changes in transaction value, and updating customer risk assessments when material new information emerges.

COMMON GAP WE OBSERVE

A transaction begins with a UAE-resident individual buyer paying by bank transfer. Three months later, closer to completion, the funds start arriving from a different account held by an offshore entity. This change in funding source is a material red flag. However, we regularly see cases where this shift goes unnoticed because the firm did not have a monitoring process in place post-onboarding. The guidance expects you to catch this.

Compliance Integration into Daily Operations

The MoET guidance is explicit that AML/CFT/CPF compliance must be embedded into the daily operations of the real estate business. It must not be treated as a separate, administrative burden that sits outside the commercial process. This means compliance checkpoints at every key stage of the transaction, clear escalation paths when a red flag is identified, and a Compliance Officer who is empowered to pause or decline a transaction when warranted.

The commercial pressure in real estate is real and intense. Agents are focused on closing deals, and that is understandable. But the guidance makes clear that commercial urgency cannot override compliance obligations. A client who withdraws the moment you ask for source of funds documentation is not a lost deal; they are a risk signal. Your team needs to be confident enough to act on that signal, and your governance structure needs to support them when they do.

Dipali Vora - Partner, NIYEAHMA Consultants LLP

Cooperation with Competent Authorities

Real estate agents and brokers play a direct role in supporting national efforts to combat money laundering, terrorist financing, and proliferation financing. The guidance identifies this as a distinct sector-critical obligation, not a passive by-product of other compliance work.

In practice, it requires maintaining clear, accessible, and accurate records that enable competent authorities to reconstruct transactions and trace ownership and funds when required.

It also requires timely and accurate filing of suspicious transaction reports to the UAE Financial Intelligence Unit (FIU) in accordance with applicable legal and regulatory requirements, and full cooperation with MoET and other supervisory or investigative authorities when information is requested.

Firms that treat record keeping and reporting as internal administrative tasks, rather than as obligations that serve an external investigative function, are likely to fall short of this expectation.

Decoding the federal AML stack for your gaming licence?

We translate Federal Decree-Law No. (10) of 2025 and Cabinet Resolution No. (134) of 2025 into practical policies, risk matrices and monitoring rules calibrated to commercial gaming.

Understanding Customer Due Diligence in Real Estate Practice

When the Business Relationship Is Established

In real estate, the business relationship is established at the earliest point of professional engagement. This includes signing a brokerage contract or listing agreement, receiving instructions to act on behalf of a client, beginning to arrange a purchase, sale, or lease, or receiving fees or commissions for a service. CDD must be completed before or at the time this relationship begins, and before any transaction is executed.

This is a critical point in practice. Many brokers wait until a deal is near completion before collecting CDD documentation. By that stage, commercial pressure is high, and incomplete documentation is far more likely to be overlooked. The MoET guidance expects CDD to be front-loaded, not deferred.

Standard CDD Requirements

For a standard-risk customer, CDD must include:

  1. Identification and verification of the customer using reliable and independent sources.
  2. Identification and verification of the Ultimate Beneficial Owner (UBO) of any corporate or legal entity involved in the transaction.
  3. Understanding the nature and purpose of the transaction.
  4. Verification of the source of funds for the transaction.
  5. Sanctions screening against the UAE Terrorist Lists and the UN Consolidated Sanctions List.
  6. PEP screening and, where appropriate, adverse media and open-source checks.

When Enhanced Due Diligence Is Mandatory

EDD is required, not optional, in the following scenarios:

  • The customer is a Politically Exposed Person (PEP) or has a close association with one.
  • The customer is connected to a high-risk jurisdiction as identified by FATF, the UAE NRA, or other authoritative sources.
  • The transaction involves a significant cash payment.
  • The transaction involves virtual assets or cryptocurrency.
  • Complex or layered ownership structures are present.
  • The source of funds or wealth is not clearly explained or documented.
  • Third-party payments are involved.
  • The transaction value is inconsistent with the customer’s known financial profile.

EDD involves obtaining additional information, deeper verification, and enhanced monitoring. It also requires senior management approval before proceeding with the relationship or transaction in many of these scenarios.

When Simplified Due Diligence May Apply

SDD may be applied only where the ML/TF/PF risk has been assessed and documented as demonstrably low. This is a narrow exception and must be supported by a clear rationale recorded in the customer file. It does not mean skipping CDD; it means applying it at a reduced level of intensity and documentation depth. SDD should not be applied where higher-risk indicators are present, including PEP exposure, high-risk jurisdiction links, significant cash payments, virtual asset involvement, complex ownership structures, or unclear source of funds or source of wealth.

Transaction Risk Matrix: A Practical Reference Guide

The following matrix is a practical reference tool developed by the AML UAE advisory team. It is not part of the official MoET guidance but reflects the risk-based approach the guidance requires. Firms should adapt this to their own risk appetite and documented policies.

Transaction / Customer Type ML/TF/PF Risk Level Minimum CDD Level Key Action Required
UAE resident individual, bank transfer, residential property below AED 2M Low to Medium Standard CDD Identity verification, source of funds confirmation
UAE resident individual, off-plan purchase, bank transfer Medium Standard CDD Identity, SOF, ongoing monitoring at payment milestones
Foreign national, residential property, bank transfer Medium to High Enhanced CDD Identity, SOF, SOW, purpose of purchase, country risk check
Corporate buyer, UAE-registered company, straightforward structure Medium Standard CDD + UBO UBO verification, corporate documents, SOF
Corporate buyer, offshore holding company, multi-jurisdictional structure High Enhanced CDD (EDD) Full UBO trace, legal structure map, SOF + SOW, senior approval
Politically Exposed Person (direct or indirect) High EDD mandatory Senior management sign-off, enhanced SOW, ongoing monitoring
Cash payment of AED 55,000 or more High EDD + REAR filing REAR mandatory, SOF evidence, cash justification
Virtual asset payment or conversion High EDD + REAR filing REAR mandatory, VA traceability, wallet ownership verification
Third-party payment (funds from account not in buyer’s name) High EDD Third-party relationship evidence, SOF for third party, escalation to CO
Rapid resale within 12 months of purchase High Enhanced monitoring Economic rationale, relationship check, STR consideration

NOTE

This matrix is a practical advisory tool developed by the AML UAE team based on the MoET REAB Guidance and our field experience. It is not a substitute for your firm’s own documented risk assessment methodology. Your Compliance Officer should tailor risk thresholds and CDD requirements to reflect your specific business model and client base.

Need a Customised CDD Framework for Your Brokerage?

AML UAE designs sector-specific CDD policies and procedures for real estate DNFBPs, grounded in MoET requirements and built for practical use by your team.

Red Flags in Real Estate: What to Watch For

The MoET REAB Guidance sets out an extensive list of red flag indicators across three categories: customer behaviour, transaction behaviour, and geographical risks. The guidance is explicit that a single red flag does not automatically mean a transaction is suspicious. This means that enhanced professional judgement and additional inquiry are required. Where multiple indicators are present, or where a red flag cannot be satisfactorily explained, escalation and potential STR filing are expected.

Customer Behaviour Red Flags

Identity and Ownership Concealment

  • The beneficial owner is obscured, or the client is reluctant to disclose true ownership.
  • Insistence on using intermediaries for all interactions without a legitimate explanation.
  • Refusal to provide identification documentation or requests to defer UBO verification until late in the process.
  • Use of shell companies, foreign entities, or complex structures that serve no apparent commercial purpose.
  • Attempts to bypass sanctions screening through frequent ownership changes or layered corporate structures.

Suspicious Behaviour and Lack of Transparency

  • Client refuses to cooperate with the source of funds enquiries.
  • Client avoids in-person meetings or direct interaction without a legitimate reason.
  • Sudden introduction of unknown third parties, especially lawyers or financial institutions, where such involvement is not typical for the transaction.
  • Repeated changes in the declared beneficial owner during the transaction lifecycle.
  • Client shows no interest in the property’s characteristics or is unconcerned with negotiating a fair price.
  • Client insists on completing a high-value transaction entirely in cash with no clear source of funds.

High-Risk Client Profiles

  • Foreign national with no established economic ties to the UAE and no clear legitimate purpose for the transaction.
  • The transaction is inconsistent with the client’s professional, educational, or socio-economic background.
  • Client or beneficial owner is a PEP or is linked to someone in a prominent public position.
  • Client or known associates appear on any targeted financial sanctions list.
  • Clients linked to sectors associated with dual-use goods, sensitive technologies, or sanctioned trade.

Transaction Behaviour Red Flags

Concealing the Source of Funds

  • Client cannot explain the source of funds, or the explanation is implausible or unsupported.
  • Transaction involves significant cash, bank drafts, cashier’s cheques, bearer instruments, or third-party cheques.
  • Part or all of the settlement is made in foreign currency with no valid business reason.
  • Escrow account is to be funded by a third party with no connection to the buyer.
  • Payments made to developers from accounts not held in the buyer’s name.

Unusual Transaction Patterns

  • Payments are intentionally split into smaller amounts to avoid detection, a practice known as structuring.
  • Multiple properties being bought, sold, or exchanged consecutively within a short period.
  • Purchase of multiple off-plan properties followed by early resale or assignment shortly after booking.
  • Rapid resale of a property within a short timeframe, particularly at a significantly different price.
  • Transaction value is materially higher or lower than market value without a credible explanation.
  • Repeated cancellations of off-plan purchases with refund requests to different accounts.
  • Requests to backdate contracts or alter transaction dates to predate sanctions designations.

Emerging Risks: Virtual Assets and Non-Traditional Payments

  • Client wishes to use cryptocurrency or digital assets to complete the transaction, particularly where the origin of the assets cannot be explained.
  • Property transactions conducted via blockchain or distributed ledger technology where counterparties, fund trails, or sources of funds are insufficiently verified.
  • Transactions where digital asset ownership is not supported by documentation and has no clear link to a legitimate source.
  • Client insists on alternative payment methods such as digital wallets, peer-to-peer platforms, or offshore transfers that are difficult to trace.

Geographical Risk Indicators

  • Funds received from a foreign country with no apparent connection to the client.
  • Funds originating from a low-tax offshore jurisdiction or a country identified as high-risk by FATF or UAE authorities.
  • Client requests that sale proceeds be sent to a high-risk jurisdiction or to a third party unconnected to the transaction.
  • Use of third parties or overseas accounts in high-risk jurisdictions to channel funds.

What to Do When You Identify a Red Flag

The guidance is clear about the expected response to red flags. The appointed Compliance Officer must assess the circumstances to determine whether the transaction is suspicious. The following steps reflect that expectation:

  • Document the red flag or combination of indicators in the client file.
  • Seek additional information or clarification from the client in a manner that does not constitute tipping off.
  • Escalate to the Compliance Officer for assessment and decision.
  • If suspicion cannot be resolved, submit an STR or SAR to the FIU without delay.
  • Do not inform the client that a report has been or may be filed.
  • Maintain all records of the assessment and decision taken.

Does Your Team Know How to Respond to Red Flags?

Our AML UAE training programmes are designed specifically for real estate professionals. We cover red flag identification, escalation procedures, and STR filing in practical, scenario-based sessions.

Real Estate Activity Reports (REAR): The Threshold-Based Reporting Obligation

One of the most practically significant and least well-understood obligations in the MoET REAB Guidance is the Real Estate Activity Report (REAR). This is a UAE-specific, mandatory threshold-based reporting mechanism. It is separate from, and additional to, the obligation to submit STRs or SARs when suspicion arises.

What Is a REAR and Why Does It Exist?

A REAR is a sector-specific report that real estate agents and brokers must file to declare relevant transactions and activities. Its purpose is to provide supervisory and financial intelligence authorities with visibility over significant real estate transactions that may not give rise to suspicion individually but warrant monitoring due to their value, payment method, or funding characteristics.

KEY POINT

REAR filing is not risk-dependent. You must file a REAR even where your CDD has been completed satisfactorily and no red flags have been identified. The obligation is triggered by the nature and value of the transaction, not by suspicion.

The Three REAR Triggers

A REAR must be filed for any of the following:

  • Purchase or sale of freehold property or real estate where the method of payment includes cash and the amount is AED 55,000 or more, whether in a single payment or across multiple payments.
  • Purchase or sale of freehold property or real estate where the method of payment is a virtual asset, for any portion or the entire property value.
  • Purchase or sale of freehold property or real estate where the funds used to carry out the transaction were converted from or to a virtual asset, for any portion or the entire property value.

What the AED 55,000 Cash Threshold Means in Practice

The threshold of AED 55,000 in cash payments applies in aggregate, not per payment. This means that if a client makes multiple cash payments across the course of a transaction that together reach or exceed AED 55,000, a REAR must be filed. Attempts to structure payments below the threshold to avoid filing constitute a red flag in themselves and may indicate deliberate evasion.

It is important to note that the REAR obligation covers freehold transactions. Agents and brokers should confirm the property type and payment structure at the point of onboarding and build REAR filing into their transaction processing workflow as a standard step, not an exception.

Virtual Assets and REAR

The inclusion of virtual asset transactions in the REAR trigger list reflects the UAE’s recognition that cryptocurrency and digital assets are increasingly present in real estate transactions. Where a client pays using virtual assets, or where the funds used have been converted to or from virtual assets at any point in the funding chain, a REAR must be filed regardless of the amount. This is a zero-threshold obligation for virtual asset involvement.

From a practical standpoint, this means that firms should ask, as part of their standard CDD process, whether any portion of the transaction funding involves or has involved virtual assets. The answer to that question determines both the REAR obligation and the appropriate level of due diligence.

When Both REAR and STR Are Required

Where a transaction meets the REAR threshold, and the agent or broker also has reasonable grounds for suspicion, both reporting obligations must be fulfilled. The REAR does not discharge the STR obligation, and the STR does not substitute for the REAR. Both must be filed through their respective channels in accordance with the applicable timelines and procedures.

Need Help with STR and REAR Filing Procedures?

Our AML UAE team supports real estate firms in establishing compliant internal reporting workflows, including template documentation, Compliance Officer support, and goAML registration guidance.

Common Compliance Gaps We Observe in UAE Real Estate Brokerages

The MoET REAB Guidance dedicates a specific section to common sectoral challenges. Based on our advisory work with real estate DNFBPs across the UAE, we recognise every one of them. The following reflects both what the guidance says and what we observe on the ground.

Fragmented Information Across Transaction Parties

Real estate transactions involve multiple parties, buyers, sellers, developers, agents, legal representatives, and financial institutions, each holding different pieces of information. No single party has the full picture. This fragmentation makes it difficult to consolidate and verify all the information needed for a complete CDD file. The solution is a structured onboarding framework that defines what information must be collected, from whom, and at what stage of the transaction.

Inadequate Beneficial Ownership Tracing

Collecting a trading licence and a passport is not the same as verifying beneficial ownership. For corporate clients, firms must trace the ownership chain to identify the ultimate natural persons who own or control the entity. Where structures are multi-layered or offshore, this requires obtaining corporate documents from each layer of the structure and understanding the rationale for the arrangement.

BEST PRACTICE

Implement a UBO declaration form as a standard part of your onboarding pack for all corporate clients. This form asks the client to declare the ownership and control structure and to identify the ultimate beneficial owners. Pair this with independent verification through public registries, corporate registrar searches, or third-party due diligence providers. Documentation of both the declaration and your verification steps must be retained in the client file.

Inconsistent Application of Risk-Based Measures

In firms with multiple agents, CDD quality often varies significantly from one agent to another. Some apply enhanced due diligence rigorously; others treat it as a box-ticking exercise. This inconsistency is a systemic risk. The solution is a standardised, documented risk assessment methodology applied at the entity level, supported by regular file reviews and internal testing to ensure consistent application.

Commercial Pressure and Deferred Compliance

Time-sensitive deals create pressure to defer or expedite compliance steps. A client who is keen to close quickly, or who hints that they will take their business elsewhere if the process is too slow, may not be simply impatient. The guidance notes this pattern explicitly. Firms whose compliance culture does not empower agents to hold the line on CDD requirements are vulnerable to exactly the kind of risk the guidance is designed to prevent.

Record Keeping Gaps

Incomplete records, documents stored in email threads, WhatsApp messages, or personal drives, and an inability to reconstruct the rationale for compliance decisions are common findings during supervisory inspections. Firms should maintain a centralised, structured client file for every transaction that includes all CDD documents, risk assessments, screening results, and any internal escalations or decisions taken. Digital document management tools need not be expensive; they need to be consistent.

Misunderstanding of REAR Obligations

Many real estate firms are not aware of the REAR filing obligation, or believe it only applies to high-value or suspicious transactions. As the guidance emphasises, it is a threshold-based obligation that applies regardless of risk. Building REAR filing into your transaction completion checklist, alongside contract signing and commission processing, is the most reliable way to ensure compliance.

Ten Case Studies: ML/TF/PF Risk in Real Estate Transactions

The MoET guidance includes ten illustrative case studies drawn from the UAE real estate sector. We summarise each below, along with the key compliance lesson from our perspective as AML practitioners.

Case Study 1: Layered Offshore Ownership

A UAE holding company owned by two foreign entities in separate jurisdictions purchases a high-value residential property. Minor ownership changes occur close to completion, explained as internal restructuring. The lack of a clear link between the corporate structure and the specific property, combined with last-minute changes and pressure to complete quickly, is the key red flag. The lesson: UBO verification must go beyond the UAE entity and trace through the offshore layers. Changes in ownership structure during a transaction must be treated as a new CDD event.

Case Study 2: Indirect PEP Exposure

A locally registered company purchases multiple off-plan properties. A silent shareholder is later identified as a close relative of a senior public official in a high-risk foreign jurisdiction. The client downplays the relevance. The lesson: PEP exposure is not limited to direct PEPs. Close associates and family members of PEPs require EDD. The attempt to minimise the connection is itself a risk indicator.

Case Study 3: Virtual Asset Conversion

A foreign resident purchases a luxury villa using funds converted from virtual assets at a UAE exchange house. Documentation is fragmented and relies on screenshots. The lesson: Virtual asset-sourced funds require enhanced scrutiny and independent verification. Fragmented documentation is not sufficient. REAR filing is mandatory, and STR consideration is required where the audit trail cannot be adequately established.

Case Study 4: Repeated Property Flipping

A property is bought and sold multiple times between apparently unrelated parties within a short period, with prices fluctuating without market justification. Shared contact details and advisors are noticed over time. The lesson: Transaction patterns must be assessed holistically, not in isolation. Repeated involvement of the same intermediaries across different deals, even under different buyer or seller names, is a significant indicator of potential layering.

Case Study 5: Third-Party Family Funding

A UAE resident declares personal savings as the source of funds, but escrow payments are later made by a family-owned company based abroad. Governance arrangements are informal. The lesson: Third-party funding, even from family entities, requires verification of the relationship between the buyer and the payer, and evidence of the funding source at the level of the third party, not just the declared buyer.

Case Study 6: Sanctions Exposure through Jurisdictional Links

A luxury property sale involves a buyer who proposes splitting payments across multiple jurisdictions and a seller whose representative requests proceeds be sent to different accounts in tranches. The agreed price is above market value. The lesson: Structuring of payments on both sides of a transaction, combined with multi-jurisdictional flows and above-market pricing, creates a strong indicator of layering. Each element may be individually explicable; taken together, they require escalation.

Case Study 7: Successive Transactions on the Same Property

A villa is sold within 12 months of acquisition and then sold again shortly after at a higher value, with the same service provider introducing each new buyer through different legal entities. No significant renovations occurred between sales. The lesson: Economic rationale for successive transactions must be established. The same intermediary appearing across multiple deals involving the same property is a pattern that warrants holistic assessment and enhanced monitoring.

Case Study 8: Sequential Transactions Involving Legal Representatives

A high-net-worth individual purchases a luxury waterfront property through a legal representative holding a broad power of attorney. Shortly before completion, the purchasing entity is substituted with a new offshore company, and the funding source shifts to a foreign account. Post-completion, the property is pledged as collateral in a private lending arrangement. The lesson: Late substitution of purchasing entities and changes in funding source during a transaction must trigger immediate reassessment. Post-transaction use of property as collateral in opaque arrangements is also a monitoring concern.

Case Study 9: Gradual Change in Buyer Profile

A UAE trading company purchases multiple off-plan units. Over the course of construction, ownership amendments are requested, and payments begin arriving from related entities and overseas accounts. The client says ownership will be regularised after handover. The lesson: Gradual changes across a long transaction lifecycle can collectively indicate concealment, even when each individual change appears commercially reasonable. Ongoing monitoring must capture the cumulative picture.

Case Study 10: Informal Third-Party Funding

A foreign national purchases a high-value property using multiple third-party transfers from different jurisdictions, described as family loans or personal arrangements. Formal documentation is refused as unnecessary. The purchase is followed immediately by a long-term residency application. The lesson: Informal funding arrangements, particularly across multiple jurisdictions, cannot be accepted without adequate documentation. The link between property purchase and residency incentives is an additional risk indicator that must be considered.

Want Scenario-Based AML Training Using Real UAE Case Studies?

Our training programmes for real estate teams use UAE-specific case studies, including the typologies in the MoET guidance, to build practical risk recognition skills.

The AML UAE Practical Compliance Checklist for Real Estate DNFBPs

The following compliance checklist has been developed by the AML UAE advisory team as a practical reference tool for real estate DNFBPs. It reflects the obligations set out in the MoET REAB Guidance and is organised by compliance area. It is not a substitute for your firm’s own documented AML/CFT/CPF programme.

# Compliance Requirement
1 Business Risk Assessment (BRA) completed, documented, and approved by senior management.
2 BRA reviewed and updated at least annually or when significant business changes occur.
3 AML/CFT/CPF Policy document in place, referencing Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025.
4 Dedicated, qualified, and independent Compliance Officer appointed with a formal mandate.
5 CO has clear reporting lines to senior management and is empowered to pause or decline transactions.
6 Customer onboarding process includes a documented risk assessment for every client and transaction.
7 Standard CDD checklist in place covering identity verification, UBO identification, SOF confirmation, and sanctions screening.
8 EDD procedure documented and applied to all high-risk clients including PEPs, high-risk jurisdiction clients, complex structures, and cash or virtual asset transactions.
9 UBO declaration form used for all corporate, trust, or foundation clients.
10 Sanctions screening conducted against UAE Terrorist Lists and UNSC Consolidated Sanctions List before onboarding and on an ongoing basis.
11 Adverse media and PEP screening conducted at onboarding and periodically throughout the relationship.
12 Ongoing monitoring process in place to detect changes in funding source, ownership, or transaction structure post-onboarding.
13 Internal escalation pathway defined: who to escalate to, when, and how.
14 STR/SAR filing process documented and all staff aware of the obligation and the tipping-off prohibition.
15 REAR filing process embedded into the transaction completion workflow, triggered by cash payments of AED 55,000 or more or any virtual asset involvement.
16 Records retention policy in place covering all CDD documents, transaction records, risk assessments, and compliance decisions.
17 Records stored in a centralised, structured, and retrievable format.
18 Annual AML/CFT/CPF training programme in place for all relevant staff, with role-specific content for front-line agents.
19 Training records maintained showing completion dates and content covered.
20 Internal compliance review or file testing conducted at least annually to assess policy adherence in practice.

FAQs on REAB Guidance

Who does the MoET Supplemental Guidance for Real Estate Agents and Brokers apply to?

It applies to all real estate agents and brokers, and to the management and employees of those entities, operating anywhere in the UAE including the mainland, Comprehensive Free Zones, and Financial Free Zones. It covers any agent or broker who concludes or facilitates transactions relating to the purchase or sale of real estate on behalf of a customer.

An STR (Suspicious Transaction Report) or SAR (Suspicious Activity Report) is filed when you have reasonable grounds to suspect that a transaction involves money laundering, terrorist financing, or proliferation financing. It is suspicion-based. A REAR (Real Estate Activity Report) is filed when a transaction meets specific thresholds, namely cash payments of AED 55,000 or more or any virtual asset involvement, regardless of whether suspicion exists. Both may be required for the same transaction.

Yes. Even smaller firms and sole-proprietor brokerages must allocate responsibility for the compliance function to a competent person. In a small entity, this may be the owner or a senior person, provided the role is clearly documented, conflicts of interest are identified and managed, and the person is genuinely empowered to act on compliance concerns. External advisory support is permitted and can supplement the internal function.

Potentially, but only where you have conducted and documented a risk assessment that clearly supports a low ML/TF/PF risk conclusion. Even for low-risk clients, basic identity verification and source of funds confirmation are still required. SDD reduces the depth and intensity of verification, not the obligation to verify. Any SDD decision must be documented in the client file.

At a minimum, a standard CDD file should include: a copy of the customer’s valid government-issued photo ID; for corporate clients, incorporation documents, shareholder register, and UBO declaration; source of funds confirmation with supporting documentation; a completed sanctions and PEP screening record; a documented risk assessment for the client and transaction; and a record of any ongoing monitoring actions taken.

A client’s refusal or inability to explain the source of their funds is itself a significant red flag. You should not proceed with the transaction and should escalate to your Compliance Officer. Depending on the circumstances, an STR may need to be filed with the FIU. You must not inform the client that you are considering or have filed a report. The client’s withdrawal from the transaction following your enquiry should also be documented.

No. The REAR obligation as set out in the MoET REAB Guidance applies specifically to the purchase and sale of freehold property where cash payments of AED 55,000 or more are involved, or where virtual assets are used. Rental transactions are not currently within the REAR trigger scope, though agents and brokers must still apply appropriate CDD and STR obligations to all their activities as DNFBPs.

The obligation to report applies regardless of whether a transaction is completed, attempted, or discontinued. If you identify reasonable grounds for suspicion after completion, you are still required to file an STR or SAR with the FIU. You should document the basis for your suspicion, the timeline of your discovery, and all steps taken. Retrospective reporting does not protect a firm from regulatory scrutiny if the indicators were or should have been apparent during the transaction.

Ready to Build a Fully Compliant AML Programme for Your Real Estate Business?

AML UAE offers end-to-end AML/CFT/CPF compliance support for real estate agents and brokers across the UAE. From Business Risk Assessments and CDD policy design to Compliance Officer support and staff training, we are with you at every step.

Conclusion: What the MoET REAB Guidance Means for Your Business

The MoET Supplemental Guidance for Real Estate Agents and Brokers is not a theoretical document. It is a detailed, practical framework that reflects the UAE’s commitment to maintaining a transparent, well-governed real estate market that cannot be exploited for financial crime. The legal obligations explained through the guidance, from BRA and CDD through to REAR filing and ongoing monitoring, are enforceable under the UAE AML/CFT/CPF framework, and supervisory authorities are likely to assess implementation with reference to this guidance.

For real estate firms, the guidance presents an opportunity as much as an obligation. A well-structured AML/CFT/CPF programme protects your business from regulatory action, strengthens your professional reputation, and enables you to engage with institutional clients, developers, and international investors who expect strong compliance standards from their counterparties.

The key messages from the guidance, and from our experience working with real estate DNFBPs across the UAE, are straightforward:

  • Know your client fully, not just at the surface level.
  • Trace beneficial ownership beyond the entity you are dealing with directly.
  • Verify source of funds and, where required, source of wealth with proper documentation.
  • Build monitoring into your transaction process, not just your onboarding.
  • File your REARs. They are mandatory, not discretionary.
  • Empower your Compliance Officer. Give them the mandate, the resources, and the support of senior management.
  • Train your team regularly, with content that reflects real scenarios from the UAE real estate sector.
  • Document everything. Your compliance posture is only as strong as your paper trail.

The UAE’s real estate sector is a world-class investment destination. Protecting its integrity is a shared responsibility, and real estate agents and brokers sit at the heart of that effort.

Share via :

About the Author

Pathik Shah

FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)

Pathik is an ACAMS-certified AML consultant specialising in governance, risk, and compliance for regulated entities in the UAE. He brings over 28 years of experience, with 1,000+ hours of AML training and 200+ advisory engagements across DNFBPs, VASPs, and FIs. He supports businesses in aligning with AML/CFT requirements from the CBUAE, DFSA, MoET, MoJ, VARA, CMA, FSRA, and FATF. Known for translating complex regulations into audit-ready procedures, Pathik enables operational clarity and compliance readiness.

Reach Out to Pathik

History of AML Regulations in UAE

Blogs

Published On: 05/08/2026

Table of Contents

Protect your business with reliable and effective AML strategies with AML UAE.

Last Reviewed On: 07/22/2026   |   Last Updated On: 07/22/2026

AT A GLANCE: UAE AML Legislative Timeline

  • Current Primary Law: Federal Decree-Law No. 10 of 2025, entered force October 2025 (Article 42)
  • Current Executive Regulation: Cabinet Resolution No. 134 of 2025 , replaces Cabinet Resolution No. 10 of 2019
  • Counter-Terrorism Law: Federal Law No. 7 of 2014 , remains in force alongside Law 10/2025
  • Targeted Financial Sanctions: Cabinet Resolution No. 74 of 2020 , without-delay asset freeze obligation (Article 15); 24-hour standard per Executive Office guidance
  • Beneficial Ownership Rules: Cabinet Resolution No. 109 of 2023 , 25% threshold; 60-day register deadline (Art. 8)
  • DNFBP Penalty Schedule: Cabinet Resolution No. 71 of 2024 , fines AED 50,000 to AED 1,000,000 (schedule, 41 violations)
  • Financial Intelligence Unit: Receives and analyses SAR/STR
  • ML Criminal Penalty: 1-10 years + AED 100,000-5,000,000; aggravated AED 1M-10M (Article 26, Law 10/2025)
  • FT Criminal Penalty: Life imprisonment or 10+ years + AED 1,000,000-10,000,000 (Article 26, Law 10/2025)
  • Legal Person ML/FT/PF Fine: AED 5,000,000-100,000,000 (Article 27, Law 10/2025)
  • Predecessor Primary Law: Federal Decree-Law No. 20 of 2018 , repealed by Article 41 of Law 10/2025

What Are UAE AML Regulations?

UAE AML regulations are the body of federal laws, cabinet resolutions, and supervisory guidance that require financial institutions, designated non-financial businesses and professions (DNFBPs), and virtual asset service providers (VASPs) to detect, prevent, and report money laundering and terrorism financing.

History of AML Regulations in UAE

The history of AML regulations in UAE is a story of progressive legal reform, shaped by the country’s position as a global financial hub and by successive rounds of international standard-setting from the Financial Action Task Force (FATF) and the United Nations Security Council. This article traces the principal federal instruments that have defined the UAE’s anti-money laundering and counter-terrorism financing (AML/CFT) framework, examining what each law introduced, what it repealed, and how the regulated population and supervisory architecture evolved over time.

The focus of this page is historical and chronological. For a detailed explanation of current compliance obligations, please see Federal AML Laws and Executive Regulations in the UAE. For guidance on which entities must comply, see Who Must Comply with UAE AML Regulations. Primary legislation is available via the UAE Legislation Portal and the National Anti-Money Laundering Committee website.

Note: Scope of This Page

This page covers the chronological legislative history of UAE AML/CFT regulation. It does not cover: (1) current compliance obligations in detail , see the Federal AML Laws page; (2) which entities must comply , see the Who Must Comply page; or (3) sector-specific requirements , see the relevant sector articles. The boundary between this page and the Federal AML Laws page is historical context versus current obligation.

History of AML Regulations in UAE

1. Why AML Became Important

The UAE’s economic role, FATF pressure, and the shift to preventive compliance

2. How the Framework Evolved

Law-by-law analysis of seven key federal instruments from 2014 to 2025

3. Conclusion

Key themes and what the 2025 reforms signal for practitioners

4. FAQs

Seven frequently asked questions answered from primary legal sources

Why AML Regulations Became Important in the UAE

The UAE’s commitment to combating money laundering and terrorism financing reflects both domestic economic priorities and obligations under international law. Three interlocking factors explain why the country developed one of the most comprehensive AML/CFT legislative frameworks in the region.

Why AML Regulations Became Important in the UAE

1. The UAE as a Global Hub

How the country’s financial and trade position creates AML risk and responsibility

2. The Global Push

UN Security Council resolutions, FATF standards, and international treaty obligations

3. From Crime Control to Prevention

The shift from post-facto criminalisation to risk-based preventive compliance

The UAE's Role as a Global Financial, Trade, and Investment Hub

The UAE is a natural crossroads between East and West. Dubai and Abu Dhabi host major international financial centres, one of the world’s highest-volume trade corridors, and a real estate market that attracts substantial cross-border capital. This economic openness is a strategic asset and a regulatory responsibility. A jurisdiction that processes high volumes of capital, provides financial infrastructure for regional commerce, and attracts significant foreign investment must maintain robust controls to prevent those systems from being exploited for illicit purposes.

Federal Decree-Law No. 10 of 2025 acknowledges this reality in its preamble, stating that the legislation is issued in fulfilment of the State’s international obligations and national commitments to protect the integrity of its financial system. The territorial scope set out in Article 2 of the law, which extends to acts committed outside the country where they affect UAE interests or financial institutions, reflects the need to police cross-border flows as well as domestic ones.

The breadth of the sectors brought within the UAE AML framework further illustrates the point. Cabinet Resolution No. 134 of 2025 identifies fourteen categories of financial institution activity in Article 2, six categories of virtual asset service provider activity in Article 4, and a range of designated non-financial businesses and professions in Article 3, from commercial gaming operators to real estate brokers and trust and company service providers. This comprehensive scope maps directly onto the sectors most commonly exploited for illicit financial flows in a highly internationalised economy.

The Global Push for Stronger Anti-Money Laundering Frameworks

The preamble of Cabinet Resolution No. 74 of 2020, which establishes the UAE’s targeted financial sanctions framework, references five UN Security Council Resolutions explicitly: Resolution 1267 (1999), establishing the Al-Qaeda and Taliban sanctions regime; Resolutions 1988 and 1989 (both 2011), which separated and refined those regimes; Resolution 1718 (2006), addressing North Korea’s weapons programme; and Resolution 2231 (2015), concerning Iran’s nuclear activities. The obligation to implement these resolutions without delay is encoded in Article 15 of Cabinet Resolution No. 74 of 2020, which requires asset freezes to be effected within 24 hours of a designation or notification.

The FATF Recommendations form the overarching international standard to which the UAE’s legislative framework must conform. Cabinet Resolution No. 109 of 2023 references Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025. Cabinet Resolution No. 71 of 2024 references Cabinet Resolution No. 16 of 2021 before repealing it. Federal Decree-Law No. 10 of 2025 expressly repeals Law 20 of 2018 in Article 41, completing the most recent reform cycle.

The institutional architecture created by Federal Decree-Law No. 10 of 2025 reflects these international obligations. Article 12 establishes a Supreme Committee for supervising the national AML/CFT strategy. Article 13 establishes the National Committee for Combating Money Laundering and the Financing of Terrorism, charged with coordinating strategy across supervisory authorities. Article 11 embeds the Financial Intelligence Unit within the Central Bank of the UAE, providing the operational infrastructure for the exchange of financial intelligence with foreign counterparts and for the reporting and analysis of suspicious transactions

The Move from Crime Control to Preventive Compliance

A reading of the instruments examined in this article reveals a clear direction of travel: from reactive criminalisation to proactive, risk-based prevention. Federal Law No. 7 of 2014, the oldest instrument discussed here, is principally a criminal statute concerned with terrorism and terrorism financing as offences. Its primary remedies are penal: imprisonment and fines following the commission of a crime, as set out in Articles 29 and 34 of that law.

The instruments from 2020 onwards are primarily preventive. Cabinet Resolution No. 74 of 2020 mandates active screening of customer databases against UN and national sanctions lists and requires institutions to freeze assets before a transaction is completed, an obligation that applies even where no criminal investigation has been opened. Cabinet Resolution No. 109 of 2023 moves further upstream, requiring legal persons to identify and register their real beneficiaries as an ongoing disclosure obligation aimed at eliminating corporate anonymity before any financial transaction is in question.

Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025 complete this transition. Article 19 of Law 10/2025 imposes preventive measures obligations on financial institutions, DNFBPs, and VASPs as ongoing compliance requirements, independent of any specific transaction or suspicious activity. Article 17 empowers supervisory authorities to impose administrative penalties of AED 10,000 to AED 5,000,000 for compliance failures alone, meaning that inadequate internal controls, poor record-keeping, or failure to appoint a compliance officer are themselves punishable, whether or not any money laundering has occurred.

Need guidance on current AML obligations?

This article covers legislative history. For an explanation of what the law requires today, read our guide to Federal AML Laws and Executive Regulations in the UAE.

How the UAE AML Framework has evolved in Substance

The following section examines seven federal instruments in order of their issuance date, most recent first. For each instrument, it sets out the date of issue, the primary purpose, the key provisions, and what the instrument repealed or replaced. All article references are to the specific instruments cited and are traceable to the source legislation texts held in the UAE legislation repository.

How the UAE AML Framework has evolved in Substance

1. Law 10/2025 (October 2025)

Current primary AML statute; repeals Law 20/2018; embeds FIU in CBUAE; new criminal penalties

2. CR 134/2025 (December 2025)

Executive regulation for Law 10/2025; replaces CR 10/2019; introduces VASP and commercial gaming categories

3. CR 71/2024 (July 2024)

DNFBP penalty schedule for MoJ/MoET-supervised entities; 41 violations; fines up to AED 1,000,000

4. CR 109/2023 (November 2023)

Real beneficiary procedures; 25% threshold; 60-day register deadline; replaces CR 58/2020

5. CR 132/2023 (December 2023)

Administrative penalties for CR 109/2023 violations; graduated fines; licence suspension on third offence

6. CR 74/2020 (October 2020)

TFS implementation; UN sanctions screening; 24-hour freeze obligation; replaces CR 20/2019

7. Federal Law 7/2014

Counter-terrorism law; terrorism financing offences; life imprisonment for promotion of terrorism

2025

Primary Law

Federal Decree-Law No. 10 of 2025

Repeals Law 20/2018. Embeds FIU in CBUAE. Introduces FIU suspension and freeze powers. Broad criminal and administrative penalty framework.

2025

Exec. Regulation

Cabinet Resolution No. 134 of 2025

Executive regulation for Law 10/2025. Introduces commercial gaming and VASP categories. Sets CDD thresholds. Replaces CR 10/2019.

2024

DNFBP Penalties

Cabinet Resolution No. 71 of 2024

41 violations; fines AED 50,000-1,000,000. Doubling for repeat offences. Replaces CR 16/2021.

2023

Beneficial Owner

Cabinet Resolution No. 109 of 2023

Real beneficiary register; 25% threshold; 60-day deadline. Replaces CR 58/2020.

2023

UBO Penalties

Cabinet Resolution No. 132 of 2023

Administrative penalties for CR 109/2023 violations. Graduated fines; licence suspension on third offence. Replaces CR 53/2021.

2020

Sanctions/TFS

Cabinet Resolution No. 74 of 2020

Implements UN UNSC Res. 1267, 1718, 1988, 1989, 2231. 24-hour freeze obligation. Replaces CR 20/2019.

2014

Counter-Terrorism

Federal Law No. 7 of 2014

Foundational counter-terrorism and TF statute. Life imprisonment for terrorism financing promotion. Remains in force alongside Law 10/2025.

Federal Decree Law No. 10 of 2025, October 2025

Federal Decree-Law No. 10 of 2025 on Combating Money Laundering and the Financing of Terrorism and Illegal Organisations is the UAE’s current primary AML legislation. Issued on 30 September 2025, it entered into force two weeks after publication in the Official Gazette, per Article 42. The law supersedes Federal Decree-Law No. 20 of 2018, which it expressly repeals under Article 41, whilst preserving circulars, resolutions, and supervisory guidance issued under the repealed law where they do not conflict with the new legislation.

Article 2 defines money laundering as the conversion, transfer, deposit, or acquisition of proceeds with the intent to conceal their illicit origin or to assist in evading criminal liability. Article 3 defines terrorism financing. Article 4 extends criminal liability to legal persons alongside natural persons, meaning that companies, institutions, and other corporate entities face prosecution under the law in addition to the individuals acting on their behalf.

The institutional architecture introduced by Law 10/2025 has three principal elements. Article 11 formally embeds and strengthens the Financial Intelligence Unit within the Central Bank of the UAE (CBUAE). The FIU had operated under the previous Law 20/2018, and the 2025 legislation reinforces its mandate and expands its powers. Article 11 grants the FIU authority to receive and analyse suspicious transaction reports and to disseminate intelligence to competent authorities. Article 12 establishes the Supreme Committee for supervising the national AML/CFT strategy. Article 13 establishes the National Committee for Combating Money Laundering and the Financing of Terrorism, charged with coordinating the national strategy and monitoring its implementation across supervisory authorities.

A significant new power introduced by the 2025 law is Article 5, which gives the FIU the authority to order a cessation of any suspicious activity for a period of up to ten working days, and to impose a freeze on related assets for up to thirty days pending referral to the competent authority. This places the FIU in an active protective role rather than a purely analytical one.

Criminal penalties are set out in Article 26. Money laundering carries one to ten years’ imprisonment and a fine of AED 100,000 to AED 5,000,000; aggravated cases attract a fine of AED 1,000,000 to AED 10,000,000. Financing of terrorism carries life imprisonment or not less than ten years, plus a fine of AED 1,000,000 to AED 10,000,000. Legal persons face fines of AED 5,000,000 to AED 100,000,000 under Article 27. Violations of suspicious transaction reporting obligations carry imprisonment and a fine of AED 100,000 to AED 1,000,000 under Article 28. Tipping off, disclosing a report or investigation to the subject, carries a fine of at least AED 50,000 under Article 29. Supervisory authorities are empowered by Article 17 to impose administrative penalties of AED 10,000 to AED 5,000,000 for compliance failures. For the full obligations framework under the current law, see Federal AML Laws and Executive Regulations in the UAE.

Cabinet Resolution No. (134) of 2025, December 2025

Cabinet Resolution No. 134 of 2025 is the executive regulation of Federal Decree-Law No. 10 of 2025. It provides the operational detail required to convert the primary law’s principles into specific procedural requirements and threshold obligations for supervised entities. Cabinet Resolution No. 134 of 2025 replaces Cabinet Resolution No. 10 of 2019, which had served as the executive regulation for the repealed Law 20 of 2018.

Article 1 introduces a number of defined terms not previously present in UAE AML legislation, including Commercial Gaming, Trust Protector, and Nominator, categories that reflect the expanding scope of the framework under international standards. Article 2 sets out fourteen categories of financial institution activity subject to the AML/CFT framework, providing a comprehensive definition of the population of regulated financial entities. Article 4 identifies six categories of virtual asset service provider activity, bringing VASPs comprehensively within the supervised population under this legislative instrument for the first time.

Article 3 defines DNFBP obligations with specific transaction thresholds. Commercial gaming operations trigger CDD obligations at AED 11,000. Dealers in precious metals and precious stones must apply CDD for occasional transactions of AED 55,000 or more. For financial institutions, Article 7 sets CDD trigger thresholds at AED 55,000 for occasional transactions and AED 3,500 for wire transfers; VASPs are subject to the same AED 3,500 wire transfer threshold. Beneficial ownership identification under Article 10 uses a threshold of 25 per cent shareholding or voting rights.

The Resolution also contains detailed provisions on CDD timing under Article 6, risk identification under Article 5, and the conditions under which entities may commence a business relationship before verification is complete under a risk-based approach. Taken together, Cabinet Resolution No. 134 of 2025 and Federal Decree-Law No. 10 of 2025 constitute the complete 2025 legislative architecture governing AML/CFT compliance in the UAE.

Unsure whether your business is in scope?

Our guide to who must comply with UAE AML regulations sets out the complete list of regulated entity categories and the obligations that apply to each.

Cabinet Resolution No. (71) of 2024, July 2024

Cabinet Resolution No. 71 of 2024 was issued on 8 July 2024. It regulates violations and administrative penalties applicable to designated non-financial businesses and professions that fall under the supervisory oversight of the Ministry of Justice and the Ministry of Economy (MoET). The Resolution’s scope of application, defined in Article 2, covers all DNFBPs under Ministry oversight who violate any provision of the AML Decree-Law, the executive regulation, or any implementing resolutions.

Article 3 empowers the Ministry to impose one or more of the administrative penalties available under Article 14 of the Decree-Law, to impose the administrative fines specified in the schedule annexed to the Resolution, or both, upon commission of any violation listed in that schedule. The schedule lists 41 violation categories. Fines range from AED 50,000 to AED 1,000,000. Selected examples from the schedule include: failure to establish policies and internal controls approved by senior management (AED 100,000-200,000, violation 1); failure to undertake required customer due diligence for transactions at or above AED 55,000 (AED 50,000-200,000, violation 9); failure to report suspicious transactions promptly to the Financial Intelligence Unit (AED 100,000-500,000, violation 22); and failure to freeze funds without prior notice upon a sanctions match (AED 500,000-1,000,000, violation 35).

Article 5 of Cabinet Resolution No. 71 of 2024 provides that the Ministry may double the administrative fine where a violation is repeated. Article 5, clause 3, further provides that imposition of a fine does not prevent the Ministry from also applying any other administrative sanction available under Article 14 of the primary Decree-Law. Cabinet Resolution No. 71 of 2024 repeals Cabinet Resolution No. 16 of 2021 under Article 8, updating the DNFBP penalty regime with a more detailed and higher-ceiling structure.

Cabinet Decision No. (109) of 2023, November 2023

Cabinet Resolution No. 109 of 2023, issued on 6 November 2023, establishes a comprehensive framework for identifying, recording, and disclosing the real beneficiaries of legal persons licensed or registered in the UAE. The Resolution aims to eliminate anonymity from corporate ownership structures, which the FATF has consistently identified as a primary vehicle for money laundering and terrorism financing. Cabinet Resolution No. 109 of 2023 repeals Cabinet Resolution No. 58 of 2020, which had established the earlier real beneficiary framework, under Article 22.

Article 5 defines the real beneficiary of a legal person as the natural person who owns or ultimately controls it through direct or indirect shareholding of 25 per cent or more of the capital, through voting rights of 25 per cent or more, or through the exercise of ultimate control by other means, including the right to appoint or remove the majority of board members. The Resolution establishes a cascading determination method: if no qualifying shareholder can be identified, the natural person exercising control through other means is treated as the real beneficiary; if no such person can be identified, the person holding the most senior management position is deemed the real beneficiary (Article 5, clause 6).

The procedural obligations are set out in Articles 8 to 11. Article 8 requires every legal person to establish and maintain a Real Beneficiary Register within 60 days of the Resolution’s implementation (or from the date of licensing, for newly established entities). Updates to the register must be made within 15 days of any change. A separate Partners or Shareholders Register must be maintained under Article 10, with the same update timeline. Article 11 obliges legal persons to submit the data in both registers to the relevant Registrar within the same 60-day period and to take reasonable measures to preserve these records from damage or loss. The Registrar is required under Article 13 to apply a risk-based approach to registered entities to ensure they are not misused for money laundering and terrorism financing.

Article 3 of the Resolution excludes companies wholly owned by the federal or local government, financial free zones, and entities with a government partner from the scope of the beneficial ownership disclosure obligations. This exemption reflects the different transparency and accountability mechanisms applicable to state-owned or government-linked entities.

Cabinet Resolution No. (132) of 2023, December 2023

Cabinet Resolution No. 132 of 2023, issued on 15 December 2023, sets out the administrative penalty regime for violations of Cabinet Resolution No. 109 of 2023. It gives the real beneficiary disclosure framework its enforcement mechanism and repeals Cabinet Resolution No. 53 of 2021 under Article 8. The Resolution applies to legal persons licensed or registered in the UAE, including in non-financial free zones, that violate the provisions of Cabinet Resolution No. 109 of 2023.

The penalty schedule annexed to the Resolution covers 15 categories of violations related to the real beneficiary and shareholder register obligations. The structure is graduated: a written notice requiring correction within a specified period on the first occurrence, escalating to a monetary fine on the second occurrence, and a higher fine on the third occurrence. Article 3, clause 2, grants the Registrar an additional power on the third offence: suspension of the violating entity’s commercial licence and closure of its commercial premises, pending payment of the fine and correction of the violation.

Fines under the schedule range from AED 5,000 (second-time failure to disclose the details of shares issued in the names of board members, per Article 11/6 of Cabinet Resolution No. 109 of 2023) to AED 100,000 (third-time failure to create and maintain a Real Beneficiary Register at all, per Article 8/1 of Cabinet Resolution No. 109 of 2023). Failure by a liquidator to maintain records for five years after dissolution of a legal person carries a flat fine of AED 100,000 on first occurrence (violation 15, citing Article 11/8 of Cabinet Resolution No. 109 of 2023). Article 4 of Cabinet Resolution No. 132 of 2023 reserves to the Cabinet the power to amend the fine amounts by addition, deletion, or amendment.

Cabinet Resolution No. (74) of 2020, October 2020

Cabinet Resolution No. 74 of 2020 establishes the UAE’s framework for implementing targeted financial sanctions (TFS) and administering terrorist designation lists. It gives domestic legal effect to a series of UN Security Council Resolutions: 1267 (1999) and its successors 1988 and 1989 (both 2011), which govern the Al-Qaeda and Taliban sanctions regimes respectively; 1718 (2006), which addresses North Korea’s weapons of mass destruction programme; and 2231 (2015), which concerns Iran’s nuclear activities. Cabinet Resolution No. 74 of 2020 replaces Cabinet Resolution No. 20 of 2019.

Article 3 of the Resolution sets out the functions of the Supreme Council for National Security in relation to local terrorist lists, including the procedures for nomination, addition, amendment, and de-listing of designated persons and entities. Article 15 is the operational core: it requires all financial institutions, DNFBPs, and other obligated entities to freeze, without prior notice or delay, the funds and other assets of any person or entity appearing on the UN Consolidated List or the national terrorist list, as soon as they become aware of a match. The phrase ‘without delay’ in Article 15 does not specify a time period in the Resolution’s text; the 24-hour operational standard for effecting a freeze is set out in guidance published by the Executive Office for Control and Non-Proliferation, which supervises compliance with the targeted financial sanctions regime.

The administrative consequence of failing to comply with the TFS obligations of Cabinet Resolution No. 74 of 2020 is captured in Cabinet Resolution No. 71 of 2024, which lists violations 33 to 41 in its schedule as explicitly referencing the 2020 Resolution. Relevant violations include: failure to register with the Executive Office for Control and Non-Proliferation (AED 50,000-1,000,000, violation 33); failure to screen databases against designated lists on an ongoing basis (AED 50,000-1,000,000, violation 34); failure to freeze matched funds without prior warning (AED 500,000-1,000,000, violation 35); and failure to report promptly to the Executive Office upon determining any match (AED 100,000-1,000,000, violation 38).

Federal Law No. (7) of 2014 Combating Terrorism Crimes

Federal Law No. 7 of 2014 Concerning Combating Terrorism Crimes and their Financing is the foundational counter-terrorism statute in the UAE. It was enacted before the current AML primary law and continues in force alongside Federal Decree-Law No. 10 of 2025, which preserves prior legislation not specifically repealed or contradicted (Article 41 of Law 10/2025). Federal Law No. 7 of 2014 establishes the criminal framework within which terrorism financing is prosecuted, distinct from the AML framework established by Law 10/2025.

The law defines a range of key concepts, including terrorist crimes, terrorist purposes, terrorist consequences, and terrorist organisations. Article 5 addresses the seizure of vehicles and transport used in the commission of terrorist operations, carrying a maximum sentence of life imprisonment. Article 29 addresses the direct and indirect financing of terrorism, providing for life imprisonment or a term of not less than ten years for persons convicted of terrorism financing offences. Article 34 criminalises the promotion of terrorist organisations, activities, and ideology, imposing a penalty of life imprisonment and a fine ranging from AED 2,000,000 to AED 5,000,000.

The practical significance of Federal Law No. 7 of 2014 for financial institutions and DNFBPs is that it defines the predicate criminal conduct against which their AML/CFT controls must be calibrated. The obligation under Article 18 of Federal Decree-Law No. 10 of 2025 to report suspicion of terrorism financing to the Financial Intelligence Unit operates in conjunction with the criminal offences established in Federal Law No. 7 of 2014. A compliance programme that correctly identifies and reports indicators of terrorism financing is, in effect, providing intelligence relevant to enforcement under both instruments simultaneously.

Federal Law No. 7 of 2014 remains the primary legal basis for terrorism-related prosecutions in the UAE alongside Federal Decree-Law No. 10 of 2025. Its persistence in the legislative framework, even as the AML primary law was replaced in its entirety in 2025, reflects the UAE’s commitment to maintaining a stable and comprehensive counter-terrorism legal framework as a foundation for the preventive compliance obligations layered on top of it.

Speak to an AML compliance specialist

AML UAE provides practical compliance guidance and advisory services tailored to the UAE regulatory framework. Whether you are a financial institution, DNFBP, or VASP, our specialists can help you navigate your obligations under the 2025 legislative framework.

Conclusion

The seven instruments examined in this article trace a coherent legislative trajectory. Federal Law No. 7 of 2014 established the criminal framework for terrorism and terrorism financing. Cabinet Resolution No. 74 of 2020 operationalised international sanctions obligations, introducing a real-time screening and freeze regime. Cabinet Resolutions No. 109 and No. 132 of 2023 addressed the transparency gap in corporate ownership by mandating beneficial ownership registers and attaching a penalty framework. Cabinet Resolution No. 71 of 2024 updated the DNFBP administrative penalty schedule, raising fine ceilings and introducing a doubling mechanism for repeat violations. Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025 completed the current reform cycle, consolidating and updating the entire framework and bringing virtual assets and commercial gaming fully within the regulated population. 

Three themes emerge from this history. First, the shift from crime control to prevention: the framework has moved steadily away from post-facto criminalisation towards ongoing, risk-based obligations that attach before any suspicious activity occurs. Second, the broadening of the regulated population: from banks and financial institutions in the early framework, through DNFBPs and real estate brokers, to virtual asset service providers and commercial gaming operators under the 2025 legislation. Third, the deepening of international alignment: each legislative update has been driven at least in part by FATF standards and UN Security Council obligations, a dynamic that will continue to generate further reform as international standards evolve. 

For practitioners, the key starting points are the primary law and its executive regulation: Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025. For a guide to current compliance obligations, see Federal AML Laws and Executive Regulations in the UAE. For the full list of regulated entities, see Who Must Comply with UAE AML Regulations. The National Anti-Money Laundering Committee website publishes regulatory guidance and updates as they are issued. 

Status of Key Legislative Instruments

The table below sets out the current status of each instrument discussed in this article, whether it remains in force, has been replaced, or has been repealed. Practitioners should confirm the current position against the UAE Legislation Portal before relying on any instrument for compliance purposes.

Instrument Status Notes 
Federal Decree-Law No. 10 of 2025 In Force Current primary AML/CFT statute. In force from October 2025 (Article 42). 
Cabinet Resolution No. 134 of 2025 In Force Current executive regulation for Law 10/2025. Replaces CR 10/2019.
Cabinet Resolution No. 71 of 2024 In Force Current DNFBP administrative penalty schedule. Replaces CR 16/2021.
Cabinet Resolution No. 109 of 2023 In Force Current real beneficiary framework. Replaces CR 58/2020.
Cabinet Resolution No. 132 of 2023 In Force Penalty schedule for CR 109/2023 violations. Replaces CR 53/2021.
Cabinet Resolution No. 74 of 2020 In Force TFS and sanctions framework. Replaces CR 20/2019. Not repealed by 2025 law.
Federal Law No. 7 of 2014 In Force Counter-terrorism statute. Preserved by Article 41 of Law 10/2025.
Federal Decree-Law No. 20 of 2018 Repealed Repealed by Article 41 of Federal Decree-Law No. 10 of 2025.
Cabinet Resolution No. 10 of 2019 ReplacedExecutive regulation for Law 20/2018. Replaced by CR 134/2025. 
Cabinet Resolution No. 16 of 2021 Replaced Prior DNFBP penalty schedule. Replaced by CR 71/2024 (Article 8).
Cabinet Resolution No. 58 of 2020 Replaced Prior real beneficiary framework. Replaced by CR 109/2023 (Article 22).
Cabinet Resolution No. 53 of 2021 Replaced Prior penalty schedule for UBO violations. Replaced by CR 132/2023 (Article 8).
Cabinet Resolution No. 20 of 2019 Replaced Prior TFS framework. Replaced by CR 74/2020.

Frequently Asked Questions

When did the UAE first introduce AML regulations?

The UAE has maintained a formal AML legislative framework for more than two decades. The most recent iteration of the primary AML statute, Federal Decree-Law No. 10 of 2025, expressly repeals Federal Decree-Law No. 20 of 2018 under Article 41, which was the immediately preceding primary AML law. The preambles of Cabinet Resolutions 109/2023, 71/2024, and 134/2025 each reference Law 20 of 2018 and its executive regulation, Cabinet Resolution No. 10 of 2019, as the predecessor instruments they build upon or replace. The seven instruments examined in this article cover the period from 2014 to 2025, representing the modern, internationally aligned phase of UAE AML regulation.

Federal Decree-Law No. 10 of 2025 is the current primary AML/CFT legislation. Article 41 repeals Federal Decree-Law No. 20 of 2018 and any provision that contradicts the new law. However, the same article preserves circulars, resolutions, and decisions issued under the 2018 law to the extent they do not conflict with the 2025 statute or its executive regulation, Cabinet Resolution No. 134 of 2025. This means that supervisory guidance, sector-specific circulars, and administrative decisions issued by the CBUAE, CMA, and other supervisory authorities under the old framework generally remain valid, unless a specific conflict exists with the new legislation. Practitioners should review each item of existing guidance against the new law to confirm its continued applicability.

Frequent legislative updates reflect two primary pressures: evolving international standards and expanding domestic risk categories. The FATF Recommendations are reviewed periodically, and member jurisdictions are expected to align their laws accordingly. The preambles of Cabinet Resolutions 74/2020, 109/2023, 71/2024, and others reference and supersede the instruments that preceded them, illustrating the iterative nature of reform. New risk categories, virtual assets, commercial gaming, trust arrangements, and complex corporate structures require specific legislative responses as they grow in economic significance. The governance architecture of Law 10/2025, including the National Committee under Article 13 and the Supreme Committee under Article 12, is designed to ensure continuous monitoring and timely legislative updating.

The UAE AML framework applies to three broad categories of entities. Financial institutions are defined across fourteen activity types listed in Article 2 of Cabinet Resolution No. 134 of 2025. Designated non-financial businesses and professions (DNFBPs) are defined in Article 3 of the same Resolution and include: commercial gaming operators, real estate brokers, dealers in precious metals and precious stones, lawyers, accountants, notaries, and trust and company service providers. Virtual asset service providers are defined across six activity types in Article 4 of Cabinet Resolution No. 134 of 2025. For a complete breakdown with entity-specific obligations, see Who Must Comply with UAE AML Regulations.

Each authority supervises a distinct population of entities. The Central Bank of the UAE (CBUAE) supervises financial institutions licensed on the UAE mainland, including banks, exchange houses, finance companies, and payment service providers. The Dubai Financial Services Authority (DFSA) supervises financial institutions within the Dubai International Financial Centre (DIFC), a financial free zone that operates under its own legal framework. The Financial Services Regulatory Authority (FSRA) supervises financial institutions within the Abu Dhabi Global Market (ADGM), another financial free zone with a separate regulatory regime. The Capital Markets Authority (CMA) supervises securities and investment businesses. Federal Decree-Law No. 10 of 2025 designates supervisory authorities generically in Article 16 and empowers them to impose administrative penalties of AED 10,000 to AED 5,000,000 per Article 17, with each authority applying these powers within its own supervised population.

The most significant changes for DNFBPs under the 2025 legislative package concern scope, thresholds, and the penalty framework. Cabinet Resolution No. 134 of 2025 introduces commercial gaming as a new DNFBP category under Article 3, with a CDD threshold of AED 11,000 per transaction. The AED 55,000 threshold for precious metals and precious stones dealers is retained. Article 3 also defines the activities of real estate brokers, lawyers, accountants, notaries, and trust and company service providers in updated terms consistent with international standards. The administrative penalty schedule applicable to DNFBPs under Ministry of Justice and MoET oversight was updated by Cabinet Resolution No. 71 of 2024, which replaced the 2021 penalty schedule, raised fine ceilings to AED 1,000,000, and introduced a doubling mechanism for repeated violations under Article 5.

The Financial Intelligence Unit has operated within the UAE’s AML framework since before the 2025 reforms. It functioned under Federal Decree-Law No. 20 of 2018 and was already embedded within the Central Bank of the UAE. Federal Decree-Law No. 10 of 2025 formally re-embeds and significantly strengthens the FIU under Article 11, reinforcing its mandate and conferring new active powers. Under Law 10/2025, the FIU retains its analytical functions, receiving and disseminating suspicious transaction reports, and gains new protective powers under Article 5: the authority to order the suspension of suspicious transactions for up to ten working days and to freeze related assets for up to thirty days pending referral to the competent authority. The expansion of the FIU’s powers beyond analysis into active intervention is one of the most significant institutional developments in the current reform cycle.

Found this article useful?

If this guide helped you understand the history of UAE AML regulations, a Google review would be appreciated. Your feedback helps other compliance professionals find reliable resources.

Legal Disclaimer: This article is provided for general information and educational purposes only and does not constitute legal advice. The information reflects the legislative position as of April 2026. Laws and regulations may change. For advice specific to your situation, consult a qualified legal or compliance professional.

Share via :

About the Author

Pathik Shah

FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)

Pathik is an ACAMS-certified AML consultant specialising in governance, risk, and compliance for regulated entities in the UAE. He brings over 28 years of experience, with 1,000+ hours of AML training and 200+ advisory engagements across DNFBPs, VASPs, and FIs. He supports businesses in aligning with AML/CFT requirements from the CBUAE, DFSA, MoET, MoJ, VARA, CMA, FSRA, and FATF. Known for translating complex regulations into audit-ready procedures, Pathik enables operational clarity and compliance readiness.

Reach Out to Pathik

Guide to New Cabinet Resolution No. 134 of 2025 on AML Law No. 10 of 2025

Guide to New Cabinet Resolution No. 134 of 2025 on AML Law No. 10 of 2025

Blogs

Published On: 11/29/2025

Table of Contents

Protect your business with reliable and effective AML strategies with AML UAE.

Last Reviewed On: 07/22/2026   |   Last Updated On: 07/22/2026

Cabinet Resolution No. (134) of 2025: At a glance

  • Cabinet Resolution No. (134) of 2025 to take effect from December 14, 2025 and it will repeal the Cabinet Resolution No. (10) of 2019
  • The scope expands from AML/CFT to include Proliferation Financing (PF) explicitly across all sectors impacted by the resolution
  • Gaming Operators are now included in the definition of DNFBPs, reporting threshold being AED 11,000
  • The authority, powers, and scope of the UAE FIU increased to include PF risks and the expansion of Freezing and Suspension powers
  • Scope expansion of risks that VASPs must mitigate, increased regulatory scrutiny, and detailed requirements for Virtual Asset Transfers.

The Shift from Cabinet Resolution No. 10 of 2019 to Cabinet Resolution No. 134 of 2025

Starting from December 14, 2025, the Cabinet Resolution No. (134) of 2025 Concerning the Executive Regulations of Federal Decree-Law No. (10) of 2025 Concerning Combating Money Laundering, Terrorist Financing, and the Financing of the Proliferation of Weapons repeals the Cabinet Resolution No. (10) of 2019 and brings forth sweeping changes to the anti-financial crime framework in UAE.

The primary legislative shift is the replacement of the words “Combating the Financing of Illegal Organisations” with the explicit obligations to combat and mitigate the Financing of the Proliferation of Weapons (PF).

This requires all Regulated Entities, i.e., Financial Institutions (FIs), Designated Non-Financial Businesses and Professions (DNFBPs), and Virtual Asset Service Providers (VASPs) to identify, assess, and mitigate PF risks in their AML/CFT compliance framework.

The scope of the resolution is expanded to include Commercial Gaming Operators as the newly introduced category of DNFBPs, subject to AML/CFT and CPF compliance obligations.

VASPs face increased scrutiny and obligations pertaining to wire transfer rules requiring retention of accurate information of originators and beneficiaries according to the “Travel Rule”.

Additionally, the UAE FIU’s powers have significantly increased in the context of freezing of suspicious funds, and new definitions for roles such as Nominee Director and Nominee Shareholder have been included to facilitate beneficial owner (UBO) identification.

Read our comprehensive guide to Anti-Money Laundering (AML) laws in the UAE for a more detailed understanding.

Major Scope Expansions: Proliferation Financing and New Sectors

The 2025 cabinet resolution fundamentally restructures the regulatory landscape by focusing on three major areas, namely: the inclusion of PF, the introduction of the commercial gaming sector into DNFBPs’ definition and the deep integration of AML/CFT and CPF obligations for VASPs.

Integration of Proliferation Financing (PF)

The new resolution explicitly mandates the inclusion of Proliferation Financing risk mitigation for all sectors requiring Regulated Entities to include PF into their:

  • Risk Assessment: Regulated Entities must now identify, assess, and implement control measures to mitigate PF risks to their business through Enterprise-Wide Risk Assessment (EWRA).
  • TFS Measures: Conduct a rigorous review of business relationships to ensure non-violation of Targeted Financial Sanctions (TFS) requirements by detecting and preventing potential TFS violations by identifying PF risks and mitigating them in a timely manner. Regulated Entities must specifically screen business relationships against PF risks.
  • AML Compliance Officer Responsibilities: Must include reviewing internal policies and procedures’ efficacy in the context of mitigating PF risks effectively.

The New "Commercial Gaming" Sector

The Commercial Gaming Sector, which includes Commercial Games and Gaming Operators, are formally recognised and defined as DNFBPs under the new resolution. The AML/CFT and CPF obligations for Gaming Operators get triggered when the threshold of 11,000 (eleven thousand) AED is crossed either through a single or a series of transactions.

Deep Integration of VASPs

The new 2025 resolution solidifies the role of VASPs and enforces detailed operational requirements, which were previously only imposed on traditional FIs. Some of these expanded obligations upon VASPs include compliance with wire transfer obligations as specified under Articles 26 to 33, as specified under Article 36 of the 2025 resolution. These requirements include

  • Originator VASP Obligations
  • Beneficiary VASP Obligations
  • TFS Obligations as applicable to FIs
  • Record-keeping obligations as applicable to FIs.

Operational Impact: Changes to the Core AML Obligations

The operational steps for AML/CFT and CPF compliance remain the same, while the intensity or depth of scrutiny required varies according to the 2025 resolution and can be divided under four major categories such as Governance and Risk Management, Customer Onboarding and Due Diligence, Transaction Monitoring and Regulatory Reporting, and Data Maintenance and Record Keeping.

The Executive Regulations of Federal Decree Law No. (10) of 2025 (Cabinet Resolution No. 134 of 2025), while remaining fundamentally and structurally consistent with repealed legislation, do expand or enhance the scope of earlier provisions, making their compliance an unavoidable obligation upon Regulated Entities.

Governance and Risk Management

The goAML Registration and Reporting methodology remains consistent, while the roles and responsibilities of Senior Management are expanded in terms of having to approve internal policies and controls and approve high-risk business relationships (specifically including PF risk emanating from a business relationship). The Compliance Officer must review the internal AML, CFT and CPF Compliance Framework to manage and mitigate identified PF risks. REs are also required to assess ML, FT and PF risks arising from the introduction of new products, professional services, or technologies prior to their implementation.

Customer Onboarding and Due Diligence

The broadened scope of DNFBPs, now including Gaming Operators, must implement and continue CDD obligations prescribed under the legislation while keeping in mind that the Screening obligations, Customer Risk Profiling, and risk-based due diligence measures are implemented while considering PF risks posed by customers to the business. In simple words, the customer onboarding and due diligence process must be risk-based and recalibrated to include the PF risks faced by the business. The identification of the UBO process is sharpened with definitions clarifying the position of Nominee Shareholders and Nominee Directors, who cannot be deemed as UBOs.

Transaction Monitoring and Reporting

The monitoring of Business Relationships obligations remains consistent; however, VASPs must now comply with Wire Transfer Obligations for obtaining and retaining originator and beneficiary information. All Regulated Entities must continue to file STRs/SARs with FIU immediately without delay, regardless of transaction value.

Data Maintenance and Record Keeping

The mandatory record retention period of 5 (five) years remains the same. Regulated Entities are obligated to update essential information, including the beneficial ownership database, within 15 (fifteen) working days of any change identified. All records must be accessible and retrievable for tracing the legitimacy of transactions.

Operational Impact of Cabinet Resolution No. (134) of 2025 to the 12 Core AML Obligations 

AML/CFT Compliance Obligations  

Comparative Analysis of Cabinet Resolution No. (134) of 2025 vs. Cabinet Resolution No. (10) of 2019 

Action Required by Regulated Entities, including Gaming Operators, as a newly introduced category of DNFBPs 

Governance and Risk Management 

1. Reporting System (goAML) 

Consistent 

Regulated Entities can continue relying on the goAML portal  

2. Appointing Compliance Officer 

Expanded Scope 

The Compliance Officer must review the AML Framework of the Regulated Entity for effective mitigation of Proliferation Financing (PF) risks 

3. Enterprise-Wide Risk Assessment 

Expanded Scope 

Regulated Entities must factor in the PF risks to which their business is exposed while conducting and revising EWRA 

4. Internal Policies & Controls 

Expanded Scope 

RE’s AML Policies must consider PF red-flags, typologies, and control measures to identify, assess and mitigate PF risks  

Customer Onboarding and Due Diligence 

5. CDD Process 

Consistent 

The CDD Process remains largely consistent. 

6. Name Screening (TFS Compliance) 

Enhanced 

Screening of business relationships to identify PF risks is now mandatory, including the identification of foreign PEP and TFS compliance 

7. Customer Risk Profiling 

Expanded Factors 

RE’s customer Risk profiling must take into account the PF risks a customer may pose (for instance, involvement of dual-use goods traders, high-risk jurisdictions for weapons) 

8. Risk-Based Due Diligence 

Refined 

In the case of high-risk customers, Enhanced Due Diligence (EDD) for PF risk clients is now mandatory. While for low-risk customers, Simplified Due Diligence (SDD) is allowed when no suspicion of crime 

Transaction Monitoring and Reporting 

9. Ongoing Monitoring 

Consistent 

Ongoing Monitoring Obligations remain consistent  

10. Suspicious Transaction Reporting 

Strict 

REs are required to report to the UAE Unit (FIU) immediately. The FIU Head has the power to order a 10-day suspension 

Data Maintenance and Record Keeping 

11. Updating Customer Info 

Time-Bound 

Regulated Entities are required to update Beneficial Owner/Nominee info within 15 working days  

12. Record Keeping 

Consistent 

Record-Keeping Obligations Remain consistent 

Critical Updates to Definitions

The following definitions in the 2025 resolution have been introduced to reflect the enhanced scope of the law and improve transparency goals, such as:

  • Commercial Gaming
  • Commercial Gaming Operators
  • Nominee Shareholder
  • Nominee Director

Key Takeaways for UAE Business Owners

Regulated Entities in UAE, including DNFBPs, VASPs, FIs, and Gaming Operators, need to

  1. Develop/Update EWRA to include PF risk oversight
  2. Develop/Update AML/CFT/CPF Policy and Procedures
  3. Develop/Update CDD measures to include PF risk oversight
  4. Develop/Update Customer Risk Assessment Methodology in line with the new regulations
  5. Compliance Officer Job Description expansion to include PF oversight
  6. Identification of Nominee Directors and Shareholders to exclude them from UBO categorisation
  7. Impart training on the updated AML/CFT policy and procedures

To ensure compliance with Cabinet Resolution No. (134) of 2025 and Federal Decree Law No. (10) of 2025.

How AML UAE can help you navigate this regulatory change?

AML UAE can help conduct EWRA, draft updated AML/CFT policies and procedures, impart training, update KYC/CDD forms and procedures, update customer risk assessment methodology, and more.

FAQs on the Cabinet Resolution No. 134 of 2025

What is Cabinet Resolution No. 134 of 2025?

The new Cabinet Resolution No. 134 of 2025 on AML Law No. 10 of 2025 provides the detailed implementing rules that financial institutions, DNFBPs, and VASPs must apply. 

Starting from December 14, 2025, the Cabinet Resolution No. (134) of 2025 Concerning the Executive Regulations of Federal Decree-Law No. (10) of 2025 Concerning Combating Money Laundering, Terrorist Financing, and the Financing of the Proliferation of Weapons comes into effect.

Federal Decree-Law No. (10) of 2025 Concerning Combating Money Laundering, Terrorist Financing, and the Financing of the Proliferation of Weapons is the new law which repealed the Federal Decree Law No. (20) of 2018. The new Cabinet Resolution No. 134 of 2025 on AML Law No. 10 of 2025 provides the detailed implementing rules that financial institutions, DNFBPs, and VASPs must apply and it repeals the Cabinet Resolution No. (10) of 2019. The new Cabinet Resolution no. 134 of 2025 will come into force with effect from December 14, 2025.

Yes, the new Cabinet Resolution No. 134 of 2025 replaces the Cabinet Decision No. 10 of 2019 and its amendments.

The new Executive Regulation applies to:

The new Executive Regulations apply to:

  1. Financial institutions

  2. Virtual asset service providers

  3. DNFBPs including  lotteries and commercial gaming sector

The regulated entities should take the following steps to comply with the requirements of Cabinet Resolution No. 134 of 2025:

  1. Study the Cabinet Resolution No. 134 of 2025 thoroughly
  2. Analyse the new resolution’s impact on the EWRA and AML/CFT policy and procedures
  3. Update EWRA
  4. Update AML/CFT policy and procedures
  5. Update customer risk assessment methodology
  6. Conduct training on the updated policy and procedures
  7. Document the change and maintain version history

Our Timely and Accurate AML consulting Services

For your smooth journey towards your goals

Share via :

About the Author

Pathik Shah

FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)

Pathik is an ACAMS-certified AML consultant specialising in governance, risk, and compliance for regulated entities in the UAE. He brings over 28 years of experience, with 1,000+ hours of AML training and 200+ advisory engagements across DNFBPs, VASPs, and FIs. He supports businesses in aligning with AML/CFT requirements from the CBUAE, DFSA, MoET, MoJ, VARA, CMA, FSRA, and FATF. Known for translating complex regulations into audit-ready procedures, Pathik enables operational clarity and compliance readiness.

Reach Out to Pathik

AML regulations for Virtual Assets Service Providers in UAE

Virtual Asset Service Providers in UAE

Blogs

Published On: 02/08/2023

Table of Contents

Protect your business with reliable and effective AML strategies with AML UAE.

Last Reviewed On: 07/21/2026   |   Last Updated On: 07/21/2026

AML regulations for Virtual Assets Service Providers in UAE - Crypto AML Regulations in UAE

With the growing acceptance and attractiveness of Virtual Assets and the ever-increasing prominence of blockchain technology across various sectors of life, the Virtual Assets industry is booming in leaps and bounds. The virtual assets segment is directly impacting the financial sector and the economy as a whole.  

With the increased movement in Virtual Assets, the need for intermediaries is also rising who can support and facilitate these transactions. We generally call them “Virtual Assets Service Providers.” 

Given the above, it is critical to understand what the terms “Virtual Assets” and “Virtual Asset Service Providers” mean.

What is Virtual Assets?

Before we go to the phrase – Virtual Asset Service Provider, it is very critical to understand what Virtual Asset (“VA”) is and what all can be classified as such. As laymen for us, Virtual Assets are cryptocurrencies. But in reality, the VA is a broad concept evolving every moment, even as we read this. 

Here, we can refer to the definition of “Virtual Asset” as prescribed by FATF, which reads as under: 

“ a digital representation of value that can be digitally traded or transferred and used for payment or investment purposes.” 

Recently, in the Cabinet Resolution No. (111) of 2022, the phrase “Virtual Asset” has been defined as under:

A digital representation of the value that can be traded or transferred digitally, can be used for investment purposes, and does not include digital representations of paper currencies, securities or other funds.

As apparent from the definition, the critical elements of a Virtual Asset are as under: 

  • VAs must be digital 
  • It should have the ability to be traded digitally and transferred so 
  • Should carry some value, as to be used for payment or investment. 

It is all possible and enabled by the use of “Distributed Ledger Technologies” (DLT), which has revamped the financial services sector to a great extent. 

The most common example of VA is virtual currencies such as Bitcoin, Ether, Dogecoin, and Stablecoins. 

It is critical to note that VA does not include digital representations of fiat currencies, shares, securities, or any such financial asset. These are just e-money and not virtual assets. The reason is that mere digital representation of such assets does not easily imbibe a feature to trade or transfer the same digitally. For example, the fiat currency stored in a bank be easily transferred from one account to another, and ownership can be changed but cannot trade the same as such; thus, it lacks one of the fundamental characteristics of VA.  

Accordingly, it is critical to understand and note that for a financial asset to qualify as VA, it should have an inherent quality of being traded and transferred digitally.  

As we are discussing VA, it is to be noted that VA and the phrase “Digital Assets” (DA) are being used interchangeably by the public. It is imperative to understand that term “Virtual Asset” cannot be used in the context of every “Digital Asset,” as every DA need not be a VA, but every VA has to be necessarily a DA. Instead, DA is a broader connotation that includes the non-fungible tokens* (NFT) and VAs. 

*NFTs are unique (may not be interchangeable amongst the NFT community) digital assets used as collectibles rather than as a mode of payment or investment. As such assets do not satisfy the primary feature of being used for payment/investment purposes, the same is not considered as VA, per FATF guidelines.

AML regulations applicable to Virtual Asset Service Providers in UAE

What is Virtual Assets Service Provider?

Having had a brief idea about virtual assets, it is pertinent to understand what Virtual Asset Service Provider (VASP) is. Here also, we would refer to the definition of VASP as provided by FATF, as under: 

a business which conducts one or more of the following activities or operations for or on behalf of another natural or legal person:  

  • an exchange between virtual assets and fiat currencies; 
  • exchange between one or more forms of virtual assets; 
  • transfer of virtual assets; (transfer means to conduct a transaction on behalf of another natural or legal person that moves a virtual asset from one virtual asset address or account to another) 
  • safekeeping and administration of virtual assets or instruments enabling control over virtual assets; 
  • participating in and provision of financial services related to an issuer’s offer or sale of a virtual asset; 

The use of the word “conducts” in the opening line of the definition indicates that for a service provider to qualify as VASP, it need not necessarily be the primary provider but also includes a person who helps in the active facilitation of services, i.e., the person who assists in carrying out of the services. 

Further, the phrase “as a business” in definition clarifies its scope, which is limited to the only person who carries out the VA-related activities for or on behalf of someone else for a commercial reason. It signifies the exclusion of persons carrying out VA activities for their benefit on an irregular or infrequent basis, without any commercial sense or facilitating anyone else.  

Now, we will evaluate each of these five subsections of the definition to understand what all sorts of activities related to VA would get covered here. 

1. The exchange between virtual assets and fiat currencies

A person, natural or legal, carrying out an activity of converting the fiat currency into virtual assets or vice versa in the course of its business, then such a service provider would be construed as VASP. 

2. The exchange between different types of virtual assets

A person carrying out an activity of exchanging one type of virtual assets for another, i.e., a person providing services of offering one form of VA against exchange or payment of a different kind of VA, then such a service provider would be a VASP. 

3. Transfer of virtual assets

Here, it is vital to understand the context in which the term “transfer” has been used. As clarified by FATF, “transfer” means to conduct a transaction on behalf of another natural or legal person that moves a virtual asset from one virtual asset address or account to another. 

Accordingly, any person conducting a business activity, assisting or facilitating the transfer of ownership of the VA or even transfer of own VA of a person from one wallet to another. 

Let us discuss some examples and sample cases around who can be considered as VASP or how to identify VASP in the context of exchange or transfer of VAs.

  • It is pertinent to note that, most of the time, such exchange or transfer of VA takes place using some decentralized technology, where such VA exchange platforms have been created. Such software programs are “Decentralized or Distributed Application (DApp),” which operates on blockchain technology and facilitates digital assets and their transfer. The name suggests that such software or platforms run on a decentralized ledger. However, generally, these applications have a single authoritative party having specific controls over the software or application, which may include control over creating and launching a VA, enhancing the functionalities of the application and user interfaces, or collecting the fees. Thus, such DApp or software collects specific fees (generally in VAs) from the users for using or interacting with the DApp, which facilitates the exchange or transfer of VAs. These fees collected by applications go to the owner/developer, the application operator, or for the benefit of the community of such DApp.  
  • Such applications or software programs cannot be construed as VASP; however, the creator or operator of such application may be construed as VASP, as they are providing services to the users or facilitating the exchange or transfer of the VA using their software or application. 
  • Services related to Virtual Asset Escrow are used when sending/receiving or transferring the fiat currency in exchange for VAs when the custody of the funds is with the service provider. 
  • Brokerage services, where the provider facilitates issuing VAs and trading the same on behalf of the third person.  
  • Advanced trading and Order-book exchange services enable the parties to find each other, discover prices, access more sophisticated trading techniques (trading on margin or algorithm-based trading), and trade VA. 
  • Note that an application merely providing a platform for the buyers and sellers to find each other without facilitating the transaction between them would not be construed as a VASP. 
  • Virtual Asset Exchanges, which facilitates the exchange of VA for fiat currencies (cash, credit cards, wire transfers, etc.) against fees or commissions.  
  • Service providers offering the Crypto-ATMs would be treated as VASPs as they actively facilitate the exchange of VAs and fiat currencies through the kiosks.

4. Safekeeping or administration of virtual assets or instruments enabling control over virtual assets

Generally, the term “safekeeping” and “administration” of VA can be read in the same context, wherein the service provider would have the custody of the VA or the private key unique to the VA and carry out the transactions as instructed by the owner of the VA or the smart contracts on behalf of the service recipient. Further, as an extension, the term “control” indicates that the provider of such services would have capabilities or the power to trade/transfer the VA on behalf of the recipient. 

A few examples of service providers fitting into this basket of services would be the companies providing custodial wallet service as they would be holding someone else’s VA.  

It is critical to note that it would not include the providers offering auxiliary services such as providing internet or data storage services or software to the VASP (who is managing or controlling the VAs of the recipient of services), rather than engaging with ultimate recipients and accessing their VA.  

5. Participating in and provision of financial services related to an issuer's offer or sale of a virtual assets

This clause covers the services concerning Initial Coin Offerings (ICO), a way to raise funds for new projects from early backers. It includes a person participating in ICO or providing financial services related to ICO. It includes purchasing VAs from an issuer to resell and distribute the same, book building, ICO underwriting, etc.  

UAE Blockchain strategy 2021

In 2018, UAE government came up with its blockchain strategy 2021. Given the advantages of blockchain technology, the UAE blockchain strategy aims to transform 50% of government transactions on the blockchain platform by 2021. By adopting blockchain technology, the UAE government intends to save:

  • AED 11 billion in transactions and documents processed routinely
  • 398 million printed documents annually; and
  • 77 million work hours annually.

Regulatory frameworks in UAE to govern the activities related to Virtual Assets

Given the increased popularity and use of virtual assets across the globe, the UAE government has issued various policies to promote the setting up of virtual asset companies in the UAE. The government has started issuing necessary regulations and forming regulatory authorities to regulate this market.

UAE Crypto Regulatory Authorities

Central Bank of the UAE (CBUAE) and the Securities and Commodities Authority (SCA)

UAE financial and capital markets are primarily governed by the Central Bank of the UAE (CBUAE) and the Securities and Commodities Authority (SCA).

The Dubai Multi Commodities Centre (DMCC) has opened a crypto centre, and it houses VASPs offering, issuing, listing, and trading crypto assets. It also welcomes companies developing blockchain trading platforms.

It is noteworthy that the CBUAE, in July 2021, as a part of its 2023-2026 strategy, decided that it would launch its first digital currency by 2026.

The Hon’ble Prime Minister of the UAE has recently issued Cabinet Resolution No. (111) of 2022 Concerning the Regulation of Virtual Assets and their Service Providers, effective from 13th January 2023, to regulate the virtual asset sector by mandating the licensing of specific virtual asset activities by the Securities & Commodities Authority (SCA) of the UAE or the local licensing authorities of specific Emirates. The said cabinet resolution does not apply to virtual assets activities regulated in a Financial Free Zone.

The Dubai Financial Services Authority (DFSA)

The Dubai International Financial Centre (DIFC) based companies are regulated by DFSA.

The Financial Services Regulatory Authority (FSRA)

The Abu Dhabi Global Market (ADGM) based companies are supervised by the FSRA.

The Virtual Asset Regulatory Authority (VARA)

The VASPs operating from the Emirate of Dubai (except for the units registered in the Dubai International Financial Centre).

UAE Crypto Regulations

UAE Crypto Regulations for Onshore Companies

UAE financial and capital markets are primarily governed by the Central Bank of the UAE (CBUAE) and the Securities and Commodities Authority (SCA).

UAE Onshore Companies are governed by SCA’s Decision No. 23 of 2020 concerning Crypto Assets Activities Regulation (CAAR).

CAAR also lays down AML/CFT requirements. CAAR provisions require reporting entities to:

  • Set up a solid AML/CFT compliance framework
  • Define policies and procedures for KYC and AML monitoring
  • Ensure that the deposits and withdrawals are made only from and to a designated bank account of the entity, and the bank account must be maintained with an authorized financial institution. The SCA must have explicitly approved it if it’s a foreign financial institution.
  • Ensure that the crypto assets are traceable

Further, they are also governed by the CBUAE’s Stored Value Facilities (SVF) Regulation 14 (SVF Regulation). The CBUAE has also issued the Retail Payment Services and Card Schemes Regulation (referred to above) (the “RPSCSR”). The RPSCSR applies to those providing payment token service.

The Cabinet Resolution No. (111) of 2022, effective from 13th January 2023, provides that the following activities related to virtual assets shall be licensed by the SCA or Local Licensing Authorities, as the case may be:

  1. provision of Virtual Asset Platform operation and management services,
  2. provision of exchange services between one or more forms of virtual assets,
  3. provision of Virtual Asset transfer services,
  4. provision of brokerage services in virtual assets trading operations,
  5. provision of Virtual Asset custody, management, and control services, and
  6. provision of financial services related to offering and/or selling by the issuer to the Virtual assets or participating in providing those services.

Moreover, the resolution also provides for the following for better compliance and regulation of the activities related to the virtual asset:

  • No provider of virtual asset services shall operate in the UAE without necessary approvals and licensing from the Securities & Commodities Authority or Local Licensing Authority,
  • Oversight of the above-mentioned activities by the Securities & Commodities Authority (SCA),
  • Before issuing the license, the SCA shall verify the applicant’s fulfilment of the capital requirements, credit guarantees, compliance management system, commitment to AML regulations, etc.
  • Compliance with AML regulations by the licensed providers of virtual assets services in terms of Federal Decree by Law No. (10) of 2025 and it’s executive regulations, along with FATF recommendations issued explicitly for virtual asset activities.

Compliance and Risk Management Rulebook for VASP – Emirate of Dubai (except DIFC)

On 11th March 2022, Virtual Assets Law No. 4 of 2022 on the Regulation of Virtual Assets in the Emirate of Dubai came into force. It applies to virtual asset services in Dubai, except in the DIFC.

Further, VARA has been named as the supervisory authority for the virtual asset service providers seeking to operate in Dubai, whether mainland or free zones, except DIFC.

Moreover, in line with Virtual Assets Law No. 4 of 2022, VARA recently issued a detailed VASP compliance and risk management Rulebook to be adhered to by the companies providing services related to virtual assets. The AML/CFT section of the Rulebook provides for various mandatory compliance frameworks that a VASP has to follow mandatorily. The principal AML compliance aspects covered in the Rulebook are as under:

  • Appointment of Money Laundering Reporting Officer (MLRO) with minimum 2 years of experience related to AML/CFT compliance,
  • Conducting AML Business Risk Assessment,
  • Designing and implementing the AML/CFT policies & procedures in line with the VARA Rulebook, AML Federal Laws and the FATF Recommendations related to the virtual assets segment,
  • Client Due Diligence, including screening of clients, UBOs, Virtual Asset transactions and the Virtual Asset Wallet address,
  • Transaction monitoring and suspicious transaction reporting to the FIU and VARA,
  • Compliance with FATF Travel Rule,
  • Maintaining of AML records for a minimum period of 8 years.

UAE Crypto Regulations for Financial Free Zone - Dubai International Financial Centre (DIFC)

The DFSA is a supervisory authority for the companies housed in DIFC. The DFSA has come out with a Consultation Paper No.  138, establishing its own regulatory framework for investment tokens. Very recently, on 8th March 2022 the DFSA came out with Consultation Paper No. 143 for regulating crypto tokens.

UAE Crypto Regulations for Financial Free Zone - Abu Dhabi Global Market

The Financial Services Regulatory Authority (FSRA) is a supervisory authority for the companies housed in Abu Dhabi Global Market (ADGM). The FSRA came out with a regulatory framework in 2015 concerning the crypto asset businesses. Further, The Financial Services and Markets Regulations (FSMRs) 2015 regulates crypto assets in ADGM.

in 2018 FSRA came up with FSRA Rules (Crypto Asset Legislative Framework).

The rules are:

(a) Conduct of Business Rules (COBS_VER04.250618) (see appendix for detailed amendments);

(b) Market Infrastructure Rules (MIR_VER03.250618) (see appendix for detailed amendments);

(c) Glossary (GLO_VER05.250618) (see appendix for detailed amendments ).

In 2020 Financial Services and Markets (Amendment No 2) Regulations were issued.

Several guidelines have also been issued, including:

  • Guidance – Regulation of Virtual Asset Activities in ADGM (“Virtual Assets Guidance”)
  • Guidance – Regulation of Digital Security Offerings and Virtual Assets under the FSMR 
  • Guidance –  Regulation of Initial Coin/Token Offerings and Crypto Assets under the FSMR (“ICO Guidance”)

On 21st March 2022, the ADGM issued a consultation paper No.1 of 2022 seeking proposals for enhancements to capital markets and virtual assets in ADGM.

Guiding Principles for VA Regulations by FSRA

In September 2022, FSRA issued a document laying down the guiding principles around its approach to Virtual Asset Regulation and Supervision for virtual assets companies operating or planning to set up VA units in ADGM. 

These guiding principles suggest the high-level approach that FSRA would adopt to regulate the operation of the virtual asset in ADGM, focusing on maintaining the stability of the ADGM’s ecosystem, the risk associated with VA, protection of the customers using VAs and the ease of entry to new VA players in ADGM. Following are the 6 guiding principles laid down for VA regulation in ADGM: 

Principle 1 – A Robust and Transparent Risk-Based Regulatory Framework 

To oversee the VA activities and mitigate the inherent risk in the VA segment, the FSRA shall regulate the VA operations in ADGM. Its VA regulatory framework includes activity-specific rules and relevant guidance aimed at protecting the customers investing in VA and maintaining the financial stability and integrity of the market. 

Principle 2 – High Standards for Authorisation 

The authorization standards focus on admitting only such VA operators within ADGM who maintains transparency and meets the regulatory framework to prevent market abuse or any damage to ADGM’s ecosystem. For new applications for setting up a VA business unit in ADGM, FSRA shall grant an “in-principle” approval only to the applicants having the business plan and the controls matching the FSRA’s risk appetite. Final approval shall be provided only when the applicant has successfully completed the operational testing to the satisfaction of the FSRA. 

Principle 3 – Preventing Money Laundering and Other Financial Crime 

Owing to anonymity and easy access, FSRA mandates the application of AML/CFT regulations to the VA operators in ADGM. It includes adherence to ADGM-specific rules, Federal Laws and Cabinet Decisions on AML/CFT, FATF Guidance and Recommendations around VA. FSRA insists on transparency around the beneficial ownership and mandates the VA firms not to transact with the counterparty whose identity is unknown at any stage during the transaction 

Principle 4 – Risk-Sensitive Supervision  

FSRA shall follow a risk-based approach to supervise the VA segment, wherein the risk assessment shall be continuously done for the VA firms based on their size, nature and complexity. FSRA aims to ensure that the VA firms have effective controls and adequate risk management strategy, which is commensurate with the size and nature of the firm.  

Principle 5 – Commitment to Enforce Regulatory Breaches  

FSRA shall dedicatedly work towards addressing the ADGM business units’ non-compliance with regulatory requirements. For this, FSRA has powers to collate the information from the ADGM companies, conduct investigations, and take disciplinary actions to prevent non-compliance with ADGM rules. 

Principle 6 – International Cooperation  

Given the global spread of the VA operations, to mitigate the risk and support the mutual exchange of information between international regulators, the FSRA has entered into various bilateral and multilateral Memorandum of Understandings (MoUs). Further, FSRA encourages the development of international best practices for VA’s sustainable growth to be sustainable and is ready to support the principles of global organizations like IOSCO, the Basel Consultative Group and FATF. 

AML regulations applicable to Virtual Asset Service Providers

AML/CFT regulations and obligations on VASP - AML Crypto Regulations in UAE

Given the anonymity involved and lack of central governing authority (as most of the virtual assets-related activities are being carried out through a decentralized platform), the Financial Action Task Force (FATF) recommended that VASPs should also be subject to stringent anti-money laundering and combatting of terrorist financing (‘AML/CTF’) regulations, the way traditional financial institutions are. 

Accordingly, in line with FATF’s recommendations and increased activities related to virtual assets in the UAE, the government recognized the need to regulate the virtual assets segment. Here is the list of important regulations, cabinet decisions, and circulars applicable to Crypto Companies and Virtual Asset Service Providers in UAE.

  • Cabinet Resolution No. (111) of 2022 Concerning the Regulation of Virtual Assets and their Service Providers.
  • Federal Decree by Law No. (10) of 2025 Regarding Anti-Money Laundering, and Combating the Financing of Terrorism and Proliferation Financing
  • Cabinet Resolution No. (134) of 2025 Concerning the Executive Regulations of Federal Decree-Law No. (10) of 2025 Concerning Combating Money Laundering, Terrorist Financing, and the Financing of the Proliferation of Weapons.
  • Cabinet Decision No. (74) of 2020 Regarding Terrorism Lists Regulation and Implementation of United Nations Security Council (UNSC) Resolutions on the Suppression and Combating of Terrorism, Terrorist Financing, Countering the Proliferation of Weapons of Mass Destruction and its Financing and Relevant Resolution.
  • VASP Compliance & Risk Management Rulebook issued by Virtual Asset Regulatory Authority of Dubai (VARA).

(a) VASP obligations under AML/CFT law

As entities being subject to AML/CFT regulations in UAE, VASP would be required to adhere to the following requirements to identify ML/FT risk and mitigate the same: 

  • Appoint the Compliance Officer to manage the AML/CFT program in the company. 
  • Maintenance of AML/CFT policy designed considering the applicable regulations, money laundering and terrorism financing risk the VASPs are exposed to, VA-related red-flag indicators, etc. 
  • Conducting business risk assessment from ML/FT risk perspective (using a risk-based approach) and identify the risk the VASP is exposed to and the controls in place to mitigate it. 
  • Customer screening, risk categorization, and performance of adequate due diligence (generally enhanced, owing to the inherent nature of the VA). 
  • Screening of Virtual Asset transactions and the Virtual Asset wallet address.
  • Reporting suspicious transactions and activities to the authorities. 
  • Imparting adequate training to the employees and senior management.  
  • Periodic audit of the AML/CFT framework adopted for the company by an independent team. 
  • Annual risk assessment reporting. 

(b) Virtual Assets “AML/CFT” Compliance Policy 

Adherence to AML/CFT regulations becomes easy once the entity has set standards and policies to be followed. Accordingly, it is of utmost importance for every VASP to develop and adopt the “Virtual Asset AML/CFT Compliance Policy.” You may refer to the VASP AML Compliance Policy template available on our website. 

(c) Technology-driven KYC, Screening, and Transaction monitoring for VASPs

Since the entire VA network operates on the blockchain or similar technology, the authorities also encourage using technology or digital tools to carry out AML/CFT related compliances.  

  • For the “Know Your Customer” (‘KYC’) process, since most of the transactions between the recipient and the VASP would be non-face-to-face, some authorities suggest deploying tools or software that requests users to upload “selfie” as well as a copy of identity document bearing photo ID. Later, this technology should be able to match and verify the user’s ” selfie ” and the photo appearing on the ID.  
  • Further, various guidelines issued by different authorities encourage VASPs to deploy new technologies to enhance the efficiency of the customer onboarding process. It also includes functionality to screen the name of the user or customer against the international and local sanctions list in real-time, along with VA transactions and the VA wallet address. 
  • As part of transaction monitoring, some authorities insist on implementing the Know Your Transaction measures, enabling the VASPs to monitor the transactions from their origin to the destination effectively. The VASPs must collect every detail relevant to the transaction, about virtual assets, parties involved, locations, etc. 
  • Additionally, it is also recommended by the authorities to obtain the following details about VA or the customer or the transaction, mainly using the new technologies: 
  • Beneficiary and the originator of the VA 
  • The IP address of the customer, with an associated timestamp 
  • Wallet addresses involved. 

ML/FT typologies and red-flag indicators relating to Virtual Assets (VA)

It is critical to understand the key ML/FT typologies associated with VA and VASP, given the great chances of this sector being exploited by the money launderers and for the financing of terrorist activities. 

1. ML/FT typologies related to Virtual Assets (VA)

The repeated withdrawal from one or more bank accounts of substantial amounts in cash, as a whole or in parts and within a relatively short period, without any apparent necessity and in combination with the repeated cashless receipt of sums of money (whereby the amounts received in the case of the trader in virtual currencies originate from the sale of virtual currencies). 

 The purchase of virtual currencies whereby at least two of the following characteristics are fulfilled: 

  1. the buyer offers his services through the internet through supply and demand sites; 
  2. the buyer does not ascertain the identity of the seller; 
  3. the buyer screens off his own identity; 
  4. the buyer pays in cash; 
  5. the buyer charges an unusually high exchange fee percentage; 
  6. the transaction takes place in a (public) space where there are many members of the public present, thereby reducing the security risk for the buyer; 
  7. there is no plausible legal or economic explanation for the method of exchange; 
  8. the scale of the virtual currencies purchased is not likely to concern average private use; 
  9. the buyer is not known to the tax authorities for his exchange establishment. 

 The buyer or seller uses a so-called ‘mixer’ during the sale of virtual currencies.  

 Use non-compliant exchanges to carry out the conversation between fiat and virtual currencies. 

 Use cryptocurrency ATMs to convert the money quickly from fiat to virtual assets and vice versa. 

 Multi-customer cross-wallet activity. 

Virtual Asset Service Providers in UAE

2. ML/FT red flag indicators for VASP

A. Red flags related to VA Transactions (Size and Frequency of the transactions): 

Manipulating VA transactions (e.g., exchange or transfer) in smaller portions to avoid the reporting requirement. 

Multiple high-value transactions carried out – 

  • Within 24 hours or period with minimal time gaps; 
  • Using a new or very old account not used for a long time. 

Transfer of VAs to multiple VASPs, located across different jurisdictions where 

  • there is no interconnection between the customer’s location, or 
  • there are no AML/CFT regulations. 

Firstly depositing VAs at an exchange and then instantly – 

  • withdrawing the VAs without any further activity, indicating redundant transactions and incurring unnecessary costs; 
  • transfer of one VA to another without logical commercial reason, or 
  • immediate withdrawal of the VAs to a private wallet from an exchange. 

Accepting fraudulent or theft funds. 

B. Red flags related to VA Transaction Patterns (Transactions concerning new users): 

  • Depositing a large amount at the time of opening a new account is not consistent with the customer’s profile. 
  • Withdrawal, in a day or two, of the large amount deposited at the time of opening a new account or trades such a large amount on the same day. 
  • Trading the entire amount of VAs or withdrawal of the same to take off the whole funds from the platform by the new user. 

C. Red flags related to Virtual Assets Transaction Patterns (Transactions concerning all users): 

Trading through multiple accounts with no reasonable explanation. 

Regular transfers in a day or a week to the same VA wallet – 

  • by more than one person; 
  • from the same IP address; or 
  • involving huge sums. 

Receipt of VAs from multiple unrelated accounts in smaller portions and immediately transferring the accumulated funds to another wallet or exchanging the entire value against fiat currency.  

Exchanging the VA against the fiat currency at a loss, without any business sense. 

Exchanging vast amounts of fiat currency against VAs, or one type of VA, to other kinds of VAs, without any logical rationale. 

D. Red flags related to Anonymity associated with Virtual Assets (VA): 

  • Customers prefer VAs providing higher anonymity, even when the transaction cost is high. 
  • Moving a VA from a transparent blockchain to a centralized exchange and immediately trading it for Anonymity Enhanced Coins. 
  • An unregistered/unlicensed VASP operating on peer-to-peer (P2P) exchange websites, handling large amounts of VA on their customer’s behalf and levying high transaction costs.  
  • The abnormal volume of VAs exchanged against fiat currency at exchanges, without any business rationale. 
  • Transactions through accounts associated with VASPs, offering mixing or tumbling services. 
  • Transactions are offering to mix and tumbling services to disguise the movement of illegal funds between known wallets and darknet marketplaces. 
  • A transaction with an account or wallet linked with any known suspicious sources, darknet marketplaces, mixing/tumbling services, gambling sites, or illegal activities. 
  • Using decentralized hardware or physical / paper wallets to move the VAs across the countries. 
  • Users register their internet domain names using proxies or domain name registrars (DNS), which offer suppression of the domain names’ owners. 
  • Users getting themselves registered through an IP address associated with a darknet or software allows communication using encrypted emails and VPNs, providing anonymity.  
  • Transactions where unfamiliar encrypted communication means are used instead of a VASP. 
  • Multiple wallets are being controlled from the same IP address, involving shell wallets registered in the name of various users to hide the linkages. 
  • Using inadequately documented VAs or VAs connected with fraud. 
  • Users transacting through VASPs have weak CDD and KYC processes. 
  • Using VA ATMs/kiosks 
  1. Incurring higher costs;  
  2. In high-risk jurisdictions, having a criminal background, or 
  3. multiple times involving small transactions. 

E. Red flags about Sender / Recipients (Irregularities observed during account creation): 

Operating multiple accounts with different names to avoid trading or withdrawal-related restrictions imposed by VASPs. 

Transactions through – 

  • non-trusted IP addresses; 
  • IP addresses from sanctioned jurisdictions; or  
  • IP addresses are flagged as suspicious or “black-listed.” 

Frequent requests to open an account with the same VASP and from the same IP address. 

Corporate users have their Internet domain registrations in a different jurisdiction than their place of establishment. 

F. Red flags about Sender / Recipients (Irregularities observed during CDD process): 

  • Inadequate KYC information or a customer hesitates or refuses to share the KYC documents or information on the source of funds. 
  • The customer shares incorrect information about the transaction, the source of funds, or the association with the counterparty. 
  • The customer provides forged documents, fake photographs, or identification documents as part of the KYC process. 

G. Red flags about Sender / Recipients (Profile): 

  • A customer provides identification or account records shared by some other account. 
  • Differences in the IP addresses associated with the customer’s profile and the transaction-related IP addresses. 
  • Publicly available information about the customer’s wallet address being associated with illegal activity. 
  • Information about customer’s criminal association. 

H. Red flags about Sender / Recipients (Profile of potential money mule or scam victims): 

  • The transferor is unaware of the VA and related blockchain technology. These people could be money mules hired by professional money launderers, or scam victims turned mules who are tricked into transferring illegal funds without knowing their origin. 
  • Significantly aged customers, operating an account and transacting in large volumes, indicating involvement in VA money muling or a victim of elder financial exploitation. 
  • A financially vulnerable person is assisting drug dealers in their illegal business. 
  • Inconsistency between the VA transactions involving significant amounts and the customer’s financial profile indicates the existence of money laundering or a money mule. 

I. Red flags about Sender / Recipients (Other unusual behavior): 

  • Frequent changes in the customer’s identification information, email addresses, IP addresses, or financial information. 
  • A customer enters a transaction with multiple VASPs using different IP addresses daily. 
  • Text in VA message box indicating association of the transactions with criminal activity or the purchase of illegal goods. 
  • Repeated transactions by a customer with a subset of users at considerable profit or loss, indicating potential account takeover & removal of victim balances via trade or ML scheme to disguise the funds using VASP infrastructure. 

J. Red flags related to Source of Funds or Wealth: 

  • Customers using VA wallets, IP addresses, or bank cards are known to have been associated with fraud, sanctioned addresses, ransomware schemes, darknet marketplaces, or illegal websites. 
  • VA transactions are associated with online gambling services. 
  • Using multiple bank cards connected with a VA wallet to withdraw the considerable value of fiat currency (crypto-to-plastic). 
  • Purchasing VAs using funds sourced from cash deposited into credit cards. 
  • The cycle of depositing the substantially high amount into a VA wallet using unknown sources of funds and subsequently converting the same into fiat currency indicates theft of funds. 
  • No information or incomplete information about the origin and owners of the funds, such as the involvement of shell companies. 
  • Placing funds into an Initial Coin Offering (ICO) without giving personal information about the investors. 
  • Transactions using pre-paid cards and immediate withdrawal after that. 
  • A customer sourcing funds from third-party mixing services or wallet tumblers. 
  • The primary source of customers’ wealth is investments in VAs, fraudulent ICOs, etc

K. Red flags related to Geographical Risks: 

  • Trading on an exchange not registered in the customer’s jurisdiction or not at all registered with any jurisdiction. 
  • The customer prefers a VA exchange or MVTS located in high-risk countries, where there are no or weak AML/CFT regulations for VASP. 
  • The customer is setting up a business in a jurisdiction that lacks strong AML/CFT regulations without any logical business explanation. 

AML UAE at Your Service 

As required by the UAE authorities and FATF, VASPs must adhere to international standards and manage their business against the ML/FT risk they are exposed to. Here, we can help you understand whether your business activity fits into the VASP activities charted out by FATF and your obligations as VASP from AML/CFT perspective. Also, we can assist you with documentation of the AML/CFT policies, conducting AML training, etc., and ensuring your AML compliance with the regulations. 

FAQs On AML Regulations for Virtual Assets Service Providers

What is a Crypto Asset?

A Crypto Asset is a record within an electronic network or distribution database functioning as a medium for exchange, storage of value, unit of account, representation of ownership, economic rights, or right of access or utility of any kind, when capable of being transferred electronically from one holder to another through the operation of computer software or an algorithm governing its use.

Cryptoasset exchange is an important part of the cryptoasset ecosystem, where the exchange provides liquidity to the market participants. Unregulated Cryptoasset exchanges pose significant money laundering risks, while regulated ones can also be targeted in money laundering schemes.

The mainland companies or onshore crypto and other virtual assets companies in UAE are regulated by the Central Bank of UAE (CBUAE) and the Securities and Commodities Authority (SCA). Further, Virtual Assets Regulatory Authority (VARA), CBUAE, and SCA control Dubai-based virtual assets service providers.

The Dubai Financial Services Authority (DFSA) is a supervisory authority for companies housed in DIFC.

The Abu Dhabi Global Market (ADGM) based crypto and other virtual asset companies are supervised by the Financial Services Regulatory Authority (FSRA).

Yes, all Virtual Asset Service Providers (VASPs) have to register with the goAML portal in UAE.

Primarily, the crypto, NFT, and other virtual assets companies in UAE have to adhere to the requirements of the following anti-money laundering (AML) laws and regulations:

Following are the Anti-Money Laundering (AML) compliance requirements that Crypto Companies, NFT, and other Virtual Asset Service Providers (VASPs) in UAE have to follow:

Our Timely and Accurate AML consulting Services

For your smooth journey towards your goals

Share via :

About the Author

Pathik Shah

FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)

Pathik is an ACAMS-certified AML consultant specialising in governance, risk, and compliance for regulated entities in the UAE. He brings over 28 years of experience, with 1,000+ hours of AML training and 200+ advisory engagements across DNFBPs, VASPs, and FIs. He supports businesses in aligning with AML/CFT requirements from the CBUAE, DFSA, MoET, MoJ, VARA, CMA, FSRA, and FATF. Known for translating complex regulations into audit-ready procedures, Pathik enables operational clarity and compliance readiness.

Reach Out to Pathik

AML Regulations for Real Estate Agents and Brokers in UAE

At a glance AML regulations for real estate agents in UAE

Blogs

Published On: 04/28/2026

Table of Contents

Protect your business with reliable and effective AML strategies with AML UAE.

Last Reviewed On: 07/21/2026   |   Last Updated On: 07/21/2026

At a glance: AML regulations for real estate agents in UAE

The points below distil the core AML obligations for real estate brokers and agents in the UAE. Every item is traceable to a named law, cabinet resolution or Ministry of Economy circular cited later in this article.

At a glance AML regulations for real estate agents in UAE

Who is regulated

Licensed real estate brokers and agents concluding purchase or sale transactions on behalf of a customer, under Article 3(2) of Cabinet Resolution 134 of 2025.

Supervisor

Ministry of Economy, ADGM RA and DFSA inside the financial free zones.

REAR cash trigger

AED 55,000 or more in physical cash on a single or linked freehold sale or purchase, per MoET Circular 05/2022.

REAR virtual asset trigger

Any freehold transaction settled wholly or partly in a virtual asset, or funded by cash converted from a virtual asset.

Reporting channel

goAML platform of the UAE Financial Intelligence Unit; REAR is additional to STR, SAR, CNMR, PNMR and HRC, HRCA reports

Record retention

Minimum five years for all customer, transaction and REAR documentation, under Article 19(1)(f) of Federal Decree-Law 10 of 2025, Article 25 of Cabinet Resolution 134 of 2025 and MoET Circular 05/2022.

Administrative fines

AED 10,000 to AED 5,000,000 per violation under Article 17 of Federal Decree Law No. 10/2025; line items in Cabinet Resolution 71 of 2024 range from AED 50,000 to AED 1,000,000.

Criminal exposure

Legal-person fines of AED 5,000,000 to AED 100,000,000 for the ML offence under Article 27 of Federal Decree Law No. 10/2025, plus dissolution and premises closure.

National risk rating

High residual ML risk on the mainland under the 2024 UAE National Risk Assessment.

AML regulations for real estate agents in UAE sit at the intersection of federal AML law, Ministry of Economy sector supervision and the UAE Financial Intelligence Unit reporting regime. Every licensed real estate broker or agent concluding a purchase or sale on behalf of a customer is a Designated Non-Financial Business and Profession (DNFBP) under Article 3(2) of Cabinet Resolution 134 of 2025, and must operate a risk-based AML/CFT/CPF programme anchored in Federal Decree-Law 10 of 2025. This article walks through who qualifies as a regulated real estate broker, who supervises the sector, which specific laws and circulars apply, and which obligations actually bite on a typical freehold transaction.

Real estate is not a low-risk sector in the UAE. The 2024 National Risk Assessment rates mainland real estate brokers and agents at high residual ML risk, driven by cash-intensive transactions, foreign buyers and the use of legal persons to hold residential property. The FIU strategic analysis reviewed 976 Real Estate Activity Reports and 405 suspicious reports from real estate agents and brokers for the period 2020 to 2023, and the dominant typologies and red flags from that analysis are now embedded in the Ministry of Economy supervision.

To see how this page fits the wider AML framework, start with the DNFBPs pillar page and the hub guide to AML laws in UAE. If you operate inside the ADGM or DIFC, the regime is materially different and is covered in our ADGM AML regulations and DIFC AML regulations pages.

AML regulations for real estate agents in UAE

Four pillars of sector compliance walked through in this article, each anchored in specific UAE laws, circulars and guidance.

1. Who counts as a broker or agent

The DNFBP scope test under Article 3(2) of Cabinet Resolution 134 of 2025, plus Ministry of Economy scope statements

2. Who supervises the sector

Ministry of Economy and Tourism (MoET) for mainland and Commercial Free Zones, with distinct regimes for ADGM and DIFC.

3. Applicable laws and guidance

Federal decree-law, executive regulations, EOCN and FIU guidance, NRA, DNFBP circulars and real estate sector guidance.

4. Conclusion and obligations

Practical synthesis of CDD, REAR, STR, UBO and record-keeping duties, plus main red flags and penalties.

Who Counts as a Real Estate Agent or Broker for AML Purposes in the UAE?

For AML purposes in the UAE, a real estate agent or broker is any licensed natural or legal person that concludes a purchase or sale of real estate on behalf of a customer. That scope is set by Article 3(2) of Cabinet Resolution 134 of 2025, which replaced Cabinet Decision 10 of 2019 as the executive regulation of the federal AML decree-law.

Cabinet Resolution 134 of 2025 lists seven categories of Designated Non-Financial Businesses and Professions. Brokers and real estate agents are the second category, defined as DNFBPs when concluding transactions or settlements on behalf of their customers for the purchase or sale of real estate. The trigger is the act of concluding a purchase or sale for a client, not the act of holding a trade licence. Marketing, property management, valuation, and pure leasing work fall outside the statutory DNFBP scope, although the Ministry of Economy’s Supplemental Guidance for the Real Estate Sector notes that brokers should apply similar AML controls to lease transactions when the risk profile is comparable.

The Ministry of Economy reinforces the scope in its foundational Circular No. 1/2021 to real estate brokers and agents and in the September 2025 AML/CFT Guidelines for DNFBPs, both of which confirm that every brokerage concluding a purchase or sale for a customer is a DNFBP and must register on goAML, appoint a compliance officer and operate a full AML/CFT/CPF programme.

Lawyers, notaries and independent legal professionals become DNFBPs when preparing, conducting or executing financial transactions for a client concerning the purchase and sale of real estate (Article 3(4)(a) of Cabinet Resolution 134 of 2025). Company and Trust Service Providers become DNFBPs when acting as agents in the incorporation of legal persons that hold real estate. Dealers in precious metals and stones become DNFBPs at the AED 55,000 single or linked cash transaction threshold. Those adjacent categories are covered in the DNFBPs pillar page and in the specific lawyers and notaries, TCSPs and DPMS pages.

Scale of the regulated population: the UAEFIU 2023 Strategic Analysis Report on Real Estate Money Laundering records 4,446 registered real estate agents and brokers as of September 2023. The 2024 National Risk Assessment notes that approximately 99.8 per cent of real estate agents operate in the mainland and commercial free zones under Ministry of Economy oversight, with only a small minority inside the financial free zones supervised by the DFSA and the ADGM.

Scope test in one sentence

If your firm is licensed as a real estate broker or agent in the UAE and you conclude the purchase or sale of real estate for a customer, you are a DNFBP under Article 3(2) of Cabinet Resolution 134 of 2025 and all obligations in this article apply, regardless of brokerage size, nationality of clients or property value.

Not sure whether you are a regulated DNFBP?

If your brokerage wants a second opinion on DNFBP scope, CDD trigger points or REAR reporting boundaries, the AML UAE team runs scoping assessments for real estate firms of every size.

AML Supervisory Authority for Real Estate Agents and Brokers in UAE

The AML supervisory authority for real estate agents and brokers on the UAE mainland and in commercial free zones is the Ministry of Economy and Tourism (MoET). The MoET was designated as the supervisor of DNFBPs in 2019 under Cabinet Resolutions 28/4/M and 3/1 and continues to hold that role under the regime introduced by Federal Decree-Law 10 of 2025 and Cabinet Resolution 134 of 2025.

The Ministry of Economy and Tourism issues binding sector circulars, publishes implementation guides, runs risk-based on-site and off-site inspections, operates the supervisory grievance system and acts as the gateway for administrative fines under Cabinet Resolution 71 of 2024. Every licensed real estate broker or agent on the mainland or in a commercial free zone registers, communicates and reports to the Ministry of Economy and Tourism.

Inside the two financial free zones, supervision is different. The ADGM Registration Authority (ADGM RA) supervises real estate activity within ADGM. The Dubai Financial Services Authority (DFSA) supervises real estate activity within DIFC. These regimes apply their own AML rulebooks and are not covered by this page.

Two other federal authorities form essential touch points for every broker, even under the Ministry of Economy supervision. The UAE Financial Intelligence Unit receives all REAR, STR, SAR, CNMR, PNMR, and HRC reports through goAML. The Executive Office for Control and Non-Proliferation (EOCN) administers the UAE Targeted Financial Sanctions list and the Automatic Reporting System for sanctions screening outcomes. Ministry of Economy and Tourism circulars require brokers to register with the EOCN Notification Alert System (NAS) and to use the Automatic Reporting System on sanctions matches.

A single brokerage can touch more than one supervisor on a given deal. A mainland broker that introduces a property within DIFC to a client, or uses a DIFC-licensed law firm to conclude the transaction, still carries its own Ministry of Economy obligations in parallel with the DIFC obligations of the legal counterpart. See the DIFC AML regulations page and ADGM AML regulations page for each free-zone regime.

AML Regulations Applicable to Real Estate Agents and Brokers in UAE

The AML regulations applicable to real estate agents and brokers in UAE sit in five concentric layers: federal laws and executive regulations, overarching EOCN and FIU guidance, the national risk assessment, DNFBP-wide Ministry of Economy and Tourism circulars, and sector-specific real estate guidance. Each layer speaks to a different part of the compliance programme, and a real estate broker is expected to read down through all five.

Five regulatory layers for real estate brokers and agents

1. Federal AML laws

Federal Decree-Law 10 of 2025, Federal Law 7 of 2014, and the executive, terrorism-list and beneficial-owner cabinet resolutions that form the backbone of the regime.

2. Overarching AML guidance

The UAE ML/TF National Risk Assessment 2024 that frames real estate as a high-residual-risk mainland sector.

3. NRA and other guidelines

The UAE ML/TF National Risk Assessment 2024 that frames real estate as a high-residual-risk mainland sector.

4. NRA and other guidelines

Ministry of Economy circulars applicable to all DNFBPs, including high-risk country lists, sanctions screening and CDD implementation guides.

5. Real estate sector guidance

Real estate specific Ministry of Economy circulars, FIU typology reports and supplemental guidance.

Federal AML Laws and Executive Regulations Applicable to the Real Estate Sector

These seven federal instruments define the offence structure, set the DNFBP scope, regulate beneficial ownership and provide the administrative penalty schedule that the Ministry of Economy applies to real estate brokers. They form the non-negotiable statutory floor for every real estate AML programme.

1. Federal Decree-Law 10 of 2025

The AML/CFT/PF offences, obligations and penalty framework applicable to all DNFBPs including real estate brokers.

2. Federal Law 7 of 2014

Defines terrorism crimes and forms the predicate anchor for terrorism-financing obligations in real estate transactions.

3. Cabinet Resolution 134 of 2025

Executive regulations that fix DNFBP scope, CDD timing, thresholds and record keeping.

4. Cabinet Decision 74 of 2020

UAE terrorism-lists regime and UN Security Council resolution implementation; binding on every broker screening its customers.

5. Cabinet Resolution 71 of 2024

The unified violations and administrative fines schedule imposed by the Ministry of Economy on DNFBPs.

6. Cabinet Decision 109 of 2023

Governs beneficial-owner procedures that brokers rely on when verifying legal-person customers.

7. Cabinet Resolution 132 of 2023

Fines regime for beneficial-owner violations under Cabinet Decision 109 of 2023.

1. Federal Decree-Law No. (10) of 2025 Regarding Anti-Money Laundering, and Combating the Financing of Terrorism and Proliferation Financing

This is the governing AML/CFT/PF statute for every real estate broker in the UAE. Article 2 defines money laundering; Article 3 defines the financing of terrorism and proliferation; Article 18 requires reporting of suspicious transactions through the Financial Intelligence Unit; Article 19(1)(e) imposes targeted financial sanctions duties; Article 24 protects the confidentiality of reports (with tipping-off penalised under Article 29); and Articles 17, 27, 28, 29, 32, 33 and 35 set the administrative and criminal penalty framework. The DNFBP definition that captures real estate brokers sits in the definitions chapter of this decree-law and is fleshed out in its executive regulation, Cabinet Resolution 134 of 2025.

2. Federal Law No. (7) of 2014 Combating Terrorism Crimes

Federal Law 7 of 2014 defines terrorism offences, terrorist organisations and terrorist acts in the UAE. It is the predicate statute that underpins the terrorism-financing obligations imposed on real estate brokers under Federal Decree-Law 10 of 2025, Cabinet Decision 74 of 2020 and the EOCN Targeted Financial Sanctions guidance. Brokers who encounter a customer match on a terrorism sanctions list apply the sanctions regime by reference to this statute.

3. Cabinet Resolution No. (134) of 2025 Concerning the Executive Regulations of Federal Decree-Law No. (10) of 2025 Concerning Combating Money Laundering, Terrorist Financing, and the Financing of the Proliferation of Weapons

Cabinet Resolution 134 of 2025 is the practical rulebook that real estate brokers apply every day. Article 3(2) places brokers and agents within the DNFBP perimeter; Articles 5 to 9 set the risk-based approach and customer due diligence timing; Article 10 addresses beneficial-owner identification; Article 16 governs enhanced due diligence for politically exposed persons; Article 21 fixes internal programme, compliance officer and training requirements; and Article 25 sets the five-year record-keeping duty. This resolution replaces Cabinet Decision 10 of 2019, but circulars issued under the 2019 regulation remain valid unless specifically repealed.

4. Cabinet Decision No. (74) of 2020 Regarding Terrorism Lists Regulation and Implementation of UN Security Council Resolutions on the Suppression and Combating of Terrorism, Terrorist Financing, Countering the Proliferation of Weapons of Mass Destruction and related resolutions

Cabinet Decision 74 of 2020 establishes the UAE Local Terrorism List, governs listing and delisting procedures and implements UN Security Council resolutions 1267, 1373, 1718, 2231 and their successors. Real estate brokers use this instrument, together with the EOCN NAS and Automatic Reporting System, to screen every customer, beneficial owner and counterparty. A confirmed match triggers a freeze, a Confirmed Name Match Report (CNMR) on goAML and immediate notification to the EOCN.

5. Cabinet Resolution No. (71) of 2024 Regulating Violations, Administrative Penalties Imposed on Violators of Measures for Confronting Money Laundering and Combating Financing of Terrorism Subject to the Control of the Ministry of Justice and the Ministry of Economy

Cabinet Resolution 71 of 2024 is the unified penalty schedule that the Ministry of Economy uses against real estate brokers and other DNFBPs. Article 3 empowers the Ministry of Economy to impose the administrative penalties in Article 14 of the previous federal decree-law (now Article 17 of Federal Decree-Law 10 of 2025), the fines in the attached schedule, or both. The schedule includes fines of AED 50,000 to AED 200,000 for CDD failures, AED 100,000 to AED 500,000 for enhanced due diligence failures and AED 50,000 to AED 1,000,000 for failure to act on National Risk Assessment findings, which are the bands real estate brokers see most often.

6. Cabinet Decision No. (109) of 2023 On Regulating the Beneficial Owner Procedures

Cabinet Decision 109 of 2023 governs the UBO regime that real estate brokers rely on when verifying legal-person customers. Article 4 lists the basic data that every legal person must maintain on its beneficial owners, partners and nominee directors; Article 8 sets the duty to keep the UBO register up to date; Article 11 obliges the legal person to disclose UBO information to the registrar, and Article 11(8) fixes a five-year retention duty for UBO records after dissolution or liquidation. MoE Circular 05/2022 requires real estate brokers to collect the UBO register for every legal-person buyer or seller, in addition to the trade licence, articles of association and Emirates ID or passport of each UBO and shareholder.

7. Cabinet Resolution No. (132) of 2023 Concerning the Administrative Penalties against Violators of the Provisions of the Cabinet Resolution No. (109) of 2023 Concerning the Regulation of Beneficial Owner Procedures

Cabinet Resolution 132 of 2023 sets out the specific administrative fines applied to legal persons and their representatives who fail to maintain, update or disclose UBO data under Cabinet Decision 109 of 2023. Real estate brokers do not themselves impose these fines, but they must recognise them when a legal-person customer declines to provide UBO data. A refusal by a counterparty to provide UBO information is itself a CDD red flag and a basis for declining to conclude the transaction.

Want your real estate team trained on AML/CFT compliance obligations?

AML UAE provides practical AML/CFT training tailored to real estate brokerages, helping teams stay informed, inspection-ready, and aligned with the federal law, executive regulation, MoE circular and EOCN guidelines.

Overarching AML Guidance Applicable to Real Estate Agents and Brokers

The EOCN and the UAE Financial Intelligence Unit publish cross-sector guidance and strategic reports that apply to every DNFBP, including real estate brokers. Together they set expectations on targeted financial sanctions, proliferation financing, terrorism-finance red flags and the use of the Automatic Reporting System and grievance channels.

Thirteen cross-sector guidance instruments a real estate broker should treat as mandatory reference material.

1. EOCN TFS Guidance – March 2026

The latest targeted financial sanctions guidance for FIs, DNFBPs and VASPs; supersedes earlier TFS guidelines on sanctions controls.

2. FIU Strategic Analysis on Terrorist Financing – May 2025

Analysis of emerging TF patterns relevant to brokers handling cross-border or high-risk-country customers

3. Strategic Review on TFS Case Studies – April 2024

Worked examples of sanctions evasion patterns and expected broker controls.

4. Proliferation Financing IRA Guidance – December 2023

Institutional risk assessment template for PF risk.

5. TF and PF Red Flags Guidance – December 2023

Behavioural and transactional indicators of TF and PF linked to real estate and other sectors.

6. Joint Guidance on Unlicensed VASPs – November 2023

How to detect buyers settling real estate via unlicensed virtual-asset providers.

7. CPF Guidance – November 2022

Counter proliferation financing programme expectations for DNFBPs and VASPs.

8. Joint Guidance – Satisfactory/Unsatisfactory Practice – June 2021

Side-by-side examples of acceptable and unacceptable AML controls.

9. Typologies on TFS Circumvention – March 2021

Typologies on how sanctioned persons misuse legal and real-estate structures.

10. EOCN Guideline on Grievance Procedures

Formal route to challenge sanctions listings or freezing orders.

11. Online Grievance System User Guide

Operational guide for the electronic grievance platform.

12. Combating Proliferation Financing and Sanctions Evasion

EOCN technical guidance on sanctions evasion red flags.

13. Simple Guide to Subscribe to EOCN NAS

Step-by-step to register for the Notification Alert System used for sanctions list updates.

1. Guidance on Targeted Financial Sanctions for Financial Institutions, Designated Non-Financial Business and Professions (DNFBPs) and Virtual Asset Service Providers (VASPs) issued by the Executive Office for Control and Non-Proliferation (EOCN) – March 2026

This is the most recent cross-sector TFS guideline from the EOCN. It consolidates screening, listing, delisting, reporting and record-keeping expectations for DNFBPs, including real estate brokers, against UN Security Council resolutions and the UAE Local Terrorism List. The guidance fixes expectations on the use of the Automatic Reporting System for Confirmed Name Match Reports and Partial Name Match Reports, and on the integration of NAS alerts into customer screening workflows.

2. FIU’s Strategic Analysis Report on Terrorist Financing – May 2025

The UAEFIU strategic report identifies TF typologies and emerging patterns seen across STR and SAR filings. For real estate brokers, it matters because freehold purchases by or on behalf of designated persons, or using funds routed through high-risk jurisdictions, are persistent patterns the FIU expects brokers to detect and report via goAML.

3. Strategic Review on Targeted Financial Sanctions Case Studies – April 2024

This review from the EOCN collates anonymised case studies on TFS compliance failures and successes in the UAE. Real estate brokers use the case studies to benchmark their own sanctions screening thresholds, their handling of false-positive alerts and their internal escalation procedures.

4. Proliferation Finance Institutional Risk Assessment Guidance for FIs, DNFBPs, and VASPs – December 2023

This EOCN document provides a template for the PF institutional risk assessment that every DNFBP, including real estate brokers, must produce and keep current. The template covers threat, vulnerability and control assessments, and is the document that the Ministry of Economy expects to see during an on-site inspection of any brokerage.

5. Terrorist and Proliferation Financing Red Flags Guidance – December 2023

This red-flag compendium lists customer, transactional and geographic indicators of TF and PF risk relevant to DNFBPs. Several red flags apply directly to real estate transactions, including payments from or to high-risk jurisdictions, structuring cash deposits and use of complex legal persons with no apparent commercial purpose.

6. Joint Guidance on Combating the Use of Unlicensed Virtual Asset Providers in the UAE – November 2023

Issued jointly by the UAEFIU, SCA, EOCN and other authorities, this guidance explains how unlicensed VASPs are used to move illicit funds into and out of the UAE, and how DNFBPs should detect the pattern. It is highly relevant to real estate brokers because virtual-asset settlements or conversions on freehold transactions trigger REAR filing under MoE Circular 05/2022.

7. Guidance on Counter Proliferation Financing for FIs, DNFBPs, and VASPs – November 2022

This older but still binding CPF guideline sets the minimum controls that a real estate brokerage must apply to proliferation financing risk. It has been supplemented by the 2023 PF institutional risk assessment guidance, but has not been repealed; brokers read both together.

8. Joint Guidance – Satisfactory/Unsatisfactory Practice – June 2021

This cross-supervisor joint guidance shows how the UAE regulators score AML control effectiveness. Several examples cover real estate transactions, especially around beneficial ownership, source of funds and suspicious transaction reporting. It is a useful calibration benchmark when a broker is writing its AML policies.

9. Typologies on the circumvention of Targeted Sanctions against Terrorism and the Proliferation of Weapons of Mass Destruction – March 2021

Typologies published by the EOCN that show how sanctioned persons attempt to use legal persons, family members and intermediaries to move funds or acquire assets, including real estate. Real estate brokers use the typologies to design screening rules and to train front-office staff.

10. EOCN Guideline on Grievance Procedures

The grievance procedure lets a listed person or their representative challenge the listing or a resulting freeze action. Real estate brokers keep a copy of the guidelines to answer customer queries where a freeze on a pending property purchase has been applied.

11. Online Grievance System User Guide

The EOCN publishes an electronic portal for submitting grievances against listings and freezing actions. The user guide is a practical reference for compliance officers needing to navigate the portal on behalf of a customer or counterparty.

12. Combating Proliferation Financing and Sanctions Evasion

This EOCN policy document sets out typologies and controls specifically aimed at proliferation financing and sanctions evasion. Real estate brokers use it to supplement the PF institutional risk assessment with scenario-based control testing, especially around corporate buyers linked to high-risk jurisdictions.

13. Simple Guide to Subscribe to the EOCN Notification Alert System (NAS)

The NAS is the free, opt-in subscription service that delivers every update to the UAE Local Terrorism List and the UNSC Consolidated List directly to subscribed compliance officers. The EOCN expects every DNFBP, including real estate brokers, to subscribe to the relevant compliance officer to NAS.

Need help operationalising EOCN and FIU guidance?

AML UAE maps every EOCN and FIU publication to the controls a real estate brokerage actually has to run, from NAS subscription to PF institutional risk assessment to CNMR filing. .

NRA, SRA, and Other Important Guidelines Applicable to Real Estate Agents and Brokers

The national risk assessment tells real estate brokers how the State itself rates ML and TF risk in the sector. The 2024 exercise is the most recent authoritative assessment and is the reference document that Ministry of Economy supervisors benchmark against.

UAE ML/TF National Risk Assessment – 2024

The 2024 National Risk Assessment classifies mainland real estate brokers and agents as high residual ML risk. The assessment highlights cash-intensive transactions, luxury freehold properties, foreign investment and the use of legal persons to hold residential property as the dominant risk drivers. It records that approximately 96 per cent of the circa 16,000 DNFBP firms fall under Ministry of Economy supervision and that 99.8 per cent of real estate agents sit in the mainland and commercial free zones. Brokers must map their own business-wide risk assessment to the 2024 NRA findings; Ministry of Economy Circular 4 of 2025 explicitly requires DNFBPs to integrate the NRA conclusions into their risk management.

DNFBP Sector-Specific Guidance Applicable to Real Estate Agents and Brokers

Ministry of Economy circulars and DNFBP-wide guidance apply to every regulated real estate broker. They translate the federal decree-law and executive regulations into operational expectations, and are the documents that Ministry of Economy supervisors quote during inspections.

Ministry of Economy DNFBP circulars and guides

Ten cross-DNFBP instruments binding on real estate brokers alongside sector-specific circulars.

1. Circular 1 of 2026 – high-risk country list

Latest update to the lists of high-risk countries and jurisdictions under increased monitoring.

2. AML/CFT Guidelines for DNFBPs – September 2025

The foundational MoET DNFBP playbook covering governance, CDD, STR and record keeping.

3. Circular 3 of 2025 - sanctions screening

Reinforces the obligation to screen customers and beneficial owners against sanctions and terrorism lists.

4. Circular 4 of 2025 – NRA 2024

Requires DNFBPs to integrate NRA 2024 findings into business-wide risk assessments.

5. Circular 6 of 2025 – risk-based CDD

Focuses on when simplified due diligence is acceptable versus enhanced due diligence.

6. Circular 7 of 2025 – UN sanctions on Iran

Implements the snapback of UN sanctions under UNSCR 1737 and successors.

7. Circular 8 of 2025 – high-risk country list

Immediate predecessor of Circular 1 of 2026; still relevant for back-book records.

8. Implementation Guide on CRA – November 2024

Step-by-step customer risk assessment methodology for DNFBPs.

9. Implementation Guide on CDD – November 2024

Step-by-step customer due diligence methodology.

10. Circular 2 of 2022 – UNSCRs 1718 and 2231

Updated TFS expectations for DNFBPs under the DPRK and Iran UN sanctions regimes.

1. Circular No. (1) of 2026 on Updating the Lists of High-Risk Countries, Countries Subject to Increased Monitoring, and Related Measures

Circular 1 of 2026 updates the Ministry of Economy list of high-risk countries and countries subject to increased monitoring, in line with the most recent FATF plenary outcomes. Real estate brokers integrate the list into screening and customer risk assessment, apply enhanced due diligence to customers connected to high-risk jurisdictions, and consider filing a High Risk Country Report or High Risk Country Activity Report on goAML where a transaction has a material link to such a country.

2. AML/CFT Guidelines for Designated Non-Financial Businesses and Professions – September 2025

These are the revised Ministry of Economy guidelines for DNFBPs, signed by the Director of the AML Department in September 2025. The guidelines cover governance, compliance officer duties, business-wide risk assessment, customer risk assessment, CDD and enhanced due diligence, STR and SAR filing, record keeping, and staff training. They explicitly identify real estate agents and brokers as a core DNFBP category and are the single most-cited supervisory document in Ministry of Economy inspections.

3. Circular No. (3) of 2025 emphasizes the importance of screening sanctions and terrorist lists

Circular 3 of 2025 reinforces the screening obligation. It requires every DNFBP, including real estate brokers, to screen customers, beneficial owners and relevant counterparties against the UN, UAE Local Terrorism List and Ministry of Economy notifications at onboarding, at every transaction and whenever the lists are updated. The circular ties the obligation to the Automatic Reporting System for CNMR and PNMR filing.

4. Circular No. (4) of 2025 on Understanding the Importance of the UAE 2024 National Risk Assessment

Circular 4 of 2025 instructs DNFBPs to read the 2024 NRA and to integrate its findings into their business-wide risk assessments, customer risk methodology, staff training and internal policies. For real estate brokers, the integration turns the NRA’s high-risk rating on mainland real estate into a concrete risk factor that must be reflected in each customer’s risk score.

5. Circular No. (6) of 2025 on Emphasizing the Implementation of Risk-Based Customer Due Diligence Measures (with a Focus on Simplified Due Diligence)

Circular 6 of 2025 explains the scope and limits of simplified due diligence and reinforces the primacy of the risk-based approach. For real estate brokers, the circular is material because simplified due diligence is almost never appropriate on freehold purchase or sale transactions above AED 55,000 in cash or settled in virtual assets; those transactions trigger full CDD and REAR obligations.

6. Circular No. (7) of 2025 Regarding the Reimposition of United Nations Sanctions Related to Iran Pursuant to United Nations Security Council Resolution No. 1737 (2006) and Subsequent Resolutions

Circular 7 of 2025 implements the reimposed UN sanctions on Iran. It extends the sanctions perimeter and lists the categories of Iranian persons and entities now subject to asset freezing. Real estate brokers update customer screening and beneficial-owner checks in light of this instrument, particularly when a transaction has any Iran nexus.

7. Circular No. (8) of 2025 on Updating the Lists of High-Risk Countries, Countries Subject to Increased Monitoring, and Related Measures

Circular 8 of 2025 is the immediate predecessor of Circular 1 of 2026. It is no longer the operative list but remains part of a broker’s audit trail for customer risk decisions taken during its period of application.

8. Implementation Guide For DNFBPs on Customer Risk Assessment (CRA) – November 2024

The Implementation Guide on CRA sets out the Ministry of Economy’s recommended methodology for scoring customer ML/TF/PF risk. It gives real estate brokers a concrete template that combines customer, geographic, product and delivery-channel factors, and it specifies the frequency of rescoring. Real estate-specific factors such as freehold versus leasehold, cash versus financed and residential versus commercial properties map cleanly into the CRA template.

9. Implementation Guide For DNFBPs on Customer Due Diligence (CDD) – November 2024

The CDD Implementation Guide describes how to conduct identification, verification, beneficial-ownership investigation, source-of-funds review and ongoing monitoring. The guide sets expectations on acceptable identity documents, verification sources and enhanced measures for PEPs and high-risk countries. Real estate brokers use it alongside MoET Circular 05/2022 and the Supplemental Guidance for the Real Estate Sector to build a sector-specific CDD workflow.

10. Circular No. (2) of 2022 regarding Implementation of Targeted Financial Sanctions (TFS) on UNSCRs 1718 (2006) and 2231 (2015)

Circular 2 of 2022 consolidates earlier TFS obligations on the DPRK (UNSCR 1718) and Iran (UNSCR 2231) programmes. It remains in force as a binding instruction to real estate brokers alongside Circular 7 of 2025 and the EOCN guidance. A broker facing a match on either programme must freeze the assets, submit a CNMR through the Automatic Reporting System and notify the EOCN without delay.

Run a quick maturity check on your AML programme

AML UAE offers a one-day diagnostic that maps a brokerage’s current AML controls against every Ministry of Economy circular and EOCN guideline, producing a prioritised remediation plan.

Sector-Specific Guidelines Applicable to Real Estate Agents and Brokers

Four real-estate-specific documents set the sector detail that a broker must master alongside the cross-DNFBP framework. They fix the Real Estate Activity Report trigger points, the typologies the UAEFIU expects brokers to detect, and the baseline compliance programme for the sector.

1. FIU Real Estate ML Typologies – December 2023

UAEFIU strategic analysis of real-estate ML patterns in the UAE, based on 976 REARs and 405 broker STRs.

2. MoE Circular 05/2022 – Real Estate Activity Report

Mandates the REAR for freehold cash and virtual-asset transactions at or above AED 55,000.

3. MoET Circular 1 of 2021

Foundational Ministry of Economy compliance circular to real estate brokers and agents.

4. Supplemental Guidance for the Real Estate Sector – May 2019

Detailed AML/CFT guidance and indicators of suspicious transactions for real estate professionals.

1. FIU’s Strategic Analysis Report on Real Estate Money Laundering Typologies and Patterns – December 2023

The UAEFIU strategic analysis examines 976 Real Estate Activity Reports, 405 suspicious reports from real estate agents and brokers and 612 suspicious reports from other reporting entities between 1 July 2020 and 30 June 2023. The report identifies six dominant typologies for the UAE real estate sector: use of third parties and family members, abuse of legal-person structures and corporate accounts, involvement of DNFBPs and brokers’ own bank accounts, claimed rental income, use of home finance and early settlement and manipulation of the property price. The report also covers unlicensed real estate crowdfunding, hawala and VASP-related patterns. Real estate brokers should map each typology to at least one red flag inside their transaction monitoring rule set. See the full report on the UAEFIU website.

2. Ministry of Economy Circular No. (05/2022) On Real Estate Activity Report

MoE Circular 05/2022, dated 24 June 2022 and effective from 1 July 2022, is the single most operationally important document for real estate brokers. It requires every licensed real estate broker or agent in the UAE to submit a Real Estate Activity Report (REAR) through goAML whenever a freehold purchase or sale transaction involves (a) a single or linked physical cash transaction equal to or exceeding AED 55,000, (b) payment in virtual assets for a portion or the whole of the property value, or (c) funds converted from a virtual asset to cash for a portion or the whole of the property value. The circular mandates the collection of Emirates ID or passport, receipts, contracts and the Purchase and Sale Agreement; for legal-person counterparties, it additionally requires the trade licence, articles of association, UBO register and Emirates ID or passport of every UBO and shareholder. Records must be kept for at least five years. A REAR does not replace STR, SAR, CNMR, PNMR, HRC or HRCA obligations.

3. MoET Circular No. (1) of 2021

MoET Circular 1 of 2021, dated 4 February 2021, is the foundational Ministry of Economy circular to real estate brokers, DPMS, auditors and corporate service providers. It sets the baseline compliance programme: appoint a compliance officer under Article 21 of Cabinet Decision 10 of 2019 (now Article 21 of Cabinet Resolution 134 of 2025), perform customer due diligence, report suspicious transactions via goAML, comply with targeted financial sanctions, and keep records for five years. The circular remains valid because it was issued under the predecessor executive regulation and has not been specifically repealed; it should be read together with the September 2025 DNFBP Guidelines and MoE Circular 05/2022.

4. Supplemental Guidance for the Real Estate Sector – May 2019

The Supplemental Guidance is the detailed sector companion to the DNFBP Guidelines. Section 11.3 covers real estate specifically: scope of DNFBP obligations, sector-specific risk factors, enhanced CDD expectations, ongoing monitoring and an extensive catalogue of typologies and indicators of suspicious transactions. The indicators cover concealment of beneficial ownership, concealment of the illicit source of funds, realisation of value or utility for the perpetrators, and the means of payment. Brokers use the guidance to calibrate their red-flag library and to train transaction-facing staff.

Conclusion: practical AML obligations, REAR, red flags and penalties

This section consolidates the operational duties, the REAR mechanics, the typology-driven red flags and the penalty exposure that a licensed real estate broker must manage in practice.

What a real estate broker must actually do

Four compliance priorities that translate the laws and circulars above into day-to-day work.

1. Core obligations

Register, appoint a compliance officer, assess risk, conduct CDD, monitor ongoing relationships and keep records for five years.

2. Real Estate Activity Report

File a REAR on every freehold cash or virtual-asset transaction above the trigger, in addition to STR, SAR, CNMR and PNMR obligations.

3. Red flags in practice

Six UAEFIU typologies to embed in front-office screening and transaction monitoring rule sets.

4. Penalties and enforcement

Administrative fines under Article 17 of Federal Decree Law No. 10/2025 and Cabinet Resolution 71 of 2024; criminal liability under Articles 27 to 35 of Federal Decree Law No. 10/2025.

Core obligations for real estate brokers

  • Every licensed real estate broker or agent who concludes a purchase or sale for a customer must:
  • Register on goAML and on the EOCN Automatic Reporting System;
  • Appoint a compliance officer under Article 21 of Cabinet Resolution 134 of 2025;
  • Produce and maintain a business-wide risk assessment integrating the 2024 National Risk Assessment findings;
  • Develop AML policies and procedures
  • Conduct risk-based customer due diligence under Articles 5 to 9 of Cabinet Resolution 134 of 2025;
  • Identify and verify the beneficial owner under Article 10 of Cabinet Resolution 134 of 2025 and Cabinet Decision 109 of 2023;
  • Apply enhanced due diligence to politically exposed persons under Article 16 of Cabinet Resolution 134 of 2025 and to high-risk-country customers and complex legal-person structures;
  • Screen against UN, UAE Local Terrorism List and Ministry of Economy notifications;
  • File STRs, SARs, CNMRs, PNMRs, HRC, and HRCA reports via goAML without tipping-off; and
  • Keep all records for at least five years under Article 19(1)(f) of Federal Decree-Law 10 of 2025 and Article 25 of Cabinet Resolution 134 of 2025.

Real Estate Activity Report (REAR) mechanics

MoE Circular 05/2022 mandates a REAR whenever a freehold purchase or sale involves AED 55,000 or more in physical cash (single or linked), or any virtual-asset settlement or cash converted from a virtual asset. The report is submitted on goAML and sits on top of the STR, SAR, CNMR, PNMR, HRC and HRCA regimes; it does not replace them. For a legal person, the broker collects, in addition to the buyer’s or seller’s Emirates ID or passport and the Purchase and Sale Agreement, the trade licence, articles of association, UBO register and identity documents of each UBO and shareholder. Records are kept for at least five years. A broker that fails to submit the REAR, or submits it late or with incomplete data, exposes itself to administrative fines under Cabinet Resolution 71 of 2024 and, where the underlying transaction is linked to an offence, to criminal liability under Federal Decree-Law 10 of 2025.

Typology-driven red flags

The UAEFIU 2023 strategic analysis, the 2019 Supplemental Guidance, and the 2023 TF and PF Red Flags Guidance together give real estate brokers a consolidated red-flag library. Six high-confidence red flags stand out:

High-confidence red flags from UAEFIU typologies

Use the library below to draft your screening procedures and transaction-monitoring thresholds.

1. Third parties and family members

Properties bought in the name of family members with no independent source of funds; powers of attorney used to obscure true buyer.

2. Corporate buyer with no economic substance

Recently incorporated legal persons with no activity, nominee directors or shared addresses across multiple entities.

3. DNFBP or broker bank account misuse

Funds moved through a broker’s own bank account or the client account of a lawyer or notary without a clear purpose

4. Claimed rental income

Cash inflows labelled as rental income but with no visible tenant, lease agreement or market-consistent rent.

5. Rapid home finance and early settlement

Mortgage taken and settled within months using cash of unexplained origin, often following a cross-border transfer.

6. Price manipulation

Sale price significantly above or below market without commercial justification; repeated transactions between connected parties

The Supplemental Guidance adds detailed indicators across customer, transaction and means-of-payment dimensions. Among the most common for UAE brokers are: customer reluctance to explain the source of funds, use of legal persons registered in high-risk jurisdictions, use of bearer instruments or cashier’s cheques that conceal the payer, structuring cash deposits to stay under reporting thresholds, and last-minute changes to buyer identity or contract price. Every red flag should trigger enhanced due diligence, a senior-management review and, where suspicion crystallises, a suspicious-transaction report through goAML.

Penalties for non-compliance

Non-compliance exposes a brokerage to three layers of liability.

1. Administrative action:

  • Under Article 17 of Federal Decree-Law 10 of 2025, the Ministry of Economy can issue warnings, impose fines from AED 10,000 to AED 5,000,000 per violation, ban violators, suspend managers, restrict or cancel the trade licence and close the premises.
  • The unified schedule in Cabinet Resolution 71 of 2024 fixes specific ranges, including AED 100,000 to AED 200,000 for failing to set an AML policy approved by top management, AED 50,000 to AED 500,000 for failing to assess and document crime risks, AED 100,000 to AED 500,000 for failing to apply enhanced due diligence to high-risk customers and AED 50,000 to AED 200,000 for failing to complete CDD before establishing a business relationship. The Ministry may double fines for repeat violations within twelve months.

2. Criminal Liability:

  • Criminal liability under Federal Decree-Law 10 of 2025: Article 27 provides that a legal person whose representatives, directors or agents commit an ML, TF or PF offence on its behalf is punished by a fine of AED 5,000,000 to AED 100,000,000, or an amount equal to the value of the criminal property, whichever is greater, and the Court may order dissolution and closure of premises.
  • Article 28 imposes imprisonment and a fine of AED 100,000 to AED 1,000,000 for deliberate or grossly negligent failure to report suspicious transactions under Article 18; Article 29 imposes imprisonment and a fine from AED 50,000 for tipping-off and for failing to comply with freezing orders; Article 32 imposes AED 200,000 to AED 10,000,000 for engaging in DNFBP activity without the necessary registration; Article 33 imposes a fine from AED 20,000 for violating EOCN targeted financial sanctions instructions; Article 35 imposes a fine from AED 20,000 for providing false beneficial-owner information. An attempt is punished on the same footing as the completed offence (Article 26(5)).

3. Reputational and licensing consequences:

  • The Ministry of Economy publishes enforcement outcomes, the EOCN publishes freezing actions, and supervisors in the ADGM and DIFC cooperate with the Ministry of Economy and UAEFIU on cross-jurisdiction matters.

Build a real estate AML programme that stands up to Ministry of Economy inspection

AML UAE designs, documents and implements end-to-end AML programmes for real estate brokers across the UAE, including goAML registration, REAR workflow automation, NAS and ARS integration, and inspection readiness.

FAQs: AML regulations for real estate agents in UAE

Are real estate brokers and agents subject to AML rules in the UAE?

Yes. Every licensed real estate broker or agent that concludes a purchase or sale of real estate for a customer is a Designated Non-Financial Business and Profession (DNFBP) under Article 3(2) of Cabinet Resolution 134 of 2025, and is subject to the full AML/CFT/PF obligations in Federal Decree-Law 10 of 2025, the Ministry of Economy circulars and the EOCN and FIU guidance. The Ministry of Economy supervises mainland and commercial-free-zone brokerages; ADGM and DIFC brokerages follow their own regimes.

The Real Estate Activity Report (REAR) is a transaction-level filing on the goAML platform required by MoE Circular 05/2022 since 1 July 2022. Brokers file a REAR on every freehold purchase or sale transaction involving AED 55,000 or more in physical cash (single or linked), or any settlement in virtual assets, or any cash funded by conversion from a virtual asset. A REAR is filed in addition to any STR, SAR, CNMR, PNMR, HRC or HRCA obligations, and records are kept for at least five years.

At minimum: identify and verify the customer under Article 9 and the beneficial owner under Article 10 of Cabinet Resolution 134 of 2025; screen every party against UN sanctions, the UAE Local Terrorism List and MoE notifications; understand the source of funds and source of wealth for high-value or cash-intensive transactions; apply enhanced due diligence to politically exposed persons under Article 16 and customers linked to high-risk countries; conduct ongoing monitoring for the duration of the relationship; and report suspicions via goAML. The November 2024 Implementation Guides on CRA and CDD provide the detailed methodology.

The UAEFIU 2023 strategic analysis identifies six dominant typologies: use of third parties and family members, abuse of legal-person structures and corporate accounts, misuse of DNFBPs and brokers’ bank accounts, claimed rental income with no substance, home finance followed by rapid early settlement and manipulation of the property price. The 2019 Supplemental Guidance lists detailed indicators across the customer, the transaction and the means of payment. Any combination of these factors requires enhanced due diligence and, if suspicion remains, an STR via goAML.

Yes. Real estate activity inside the ADGM is supervised by the ADGM Registration Authority and follows the ADGM AML rulebook. Real estate activity inside the DIFC is supervised by the Dubai Financial Services Authority and follows the DFSA AML rulebook. Both regimes align with Federal Decree-Law 10 of 2025 at the principles level, but the specific rules, thresholds, reporting channels, and penalty schedules are different. Brokers operating across the mainland and a financial free zone must comply with both regimes in parallel.

Found this helpful?

If this guide clarified AML regulations for real estate agents in UAE for your brokerage, a short Google review helps the next compliance officer find it.

Share via :

About the Author

Pathik Shah

FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)

Pathik is an ACAMS-certified AML consultant specialising in governance, risk, and compliance for regulated entities in the UAE. He brings over 28 years of experience, with 1,000+ hours of AML training and 200+ advisory engagements across DNFBPs, VASPs, and FIs. He supports businesses in aligning with AML/CFT requirements from the CBUAE, DFSA, MoET, MoJ, VARA, CMA, FSRA, and FATF. Known for translating complex regulations into audit-ready procedures, Pathik enables operational clarity and compliance readiness.

Reach Out to Pathik

AML Regulations for Lawyers, Notaries, and Other Legal Professionals in UAE

How the Ministry of Justice supervises the sector

Blogs

Published On: 04/29/2026

Table of Contents

Protect your business with reliable and effective AML strategies with AML UAE.

Last Reviewed On: 07/21/2026   |   Last Updated On: 07/21/2026

AML Regulations for Lawyers, Notaries, and Other Legal Professionals in UAE: At a Glance

  • Covered activities: Five activities under Article 3(4) of Cabinet Resolution 134/2025 bring a lawyer, notary, or legal consultant inside the AML regime.
  • Supervisory authority: The Ministry of Justice (MoJ) supervises law firms, legal consultancy offices, and notaries public under Ministerial Resolution 248 of 2025.
  • Primary legislation: Federal Decree-Law 10 of 2025 and Cabinet Resolution 134 of 2025 replace Federal Decree-Law 20 of 2018; all unrepealed circulars remain valid.
  • Administrative penalties: Forty-one violation categories under Cabinet Resolution 71 of 2024 carry fines ranging from AED 50,000 to AED 1,000,000, doubled on repetition.
  • Legal privilege: Article 18(2) of both Federal Decree Law No. (10) of 2025 and Cabinet Resolution No. (134) of 2025 protects defence, representation, arbitration, mediation, and legal opinion activities from the STR duty.
  • Reporting channel: Suspicious transactions go to the Financial Intelligence Unit through the goAML platform.
  • Record retention: Five years for customer records and all AML documentation, starting from the end of the business relationship or the completion of the transaction.
  • Free-zone carve-out: Firms licensed in ADGM and DIFC sit under ADGM (RA) and DFSA respectively; MoJ supervision does not apply to them.

AML Regulations for Lawyers, Notaries, and Other Legal Professionals in UAE

AML regulations for lawyers in UAE place five defined activities inside the anti-money-laundering perimeter and require lawyers, legal consultants, and notaries public under the supervisory remit of the Ministry of Justice. The current framework is anchored in Federal Decree-Law No. (10) of 2025 Regarding Anti-Money Laundering, and Combating the Financing of Terrorism and Proliferation Financing and its Executive Regulations in Cabinet Resolution No. (134) of 2025, both of which repealed Federal Decree-Law No. (20) of 2018 and its earlier Executive Regulations, while preserving every circular and notification that has not been specifically revoked.

This spoke article sits inside the DNFBPs regulatory cluster on AML UAE and focuses only on legal professionals supervised by the Ministry of Justice. Firms licensed in Abu Dhabi Global Market or the Dubai International Financial Centre sit under the ADGM Registration Authority (RA) and the DFSA, respectively, so this guide addresses their position only in the carve-out note at the end of the supervisor section. Every specific article number, penalty figure, timeline, and threshold below is traceable to a named instrument published on uaelegislation.gov.ae or to a named Ministry of Justice publication on moj.gov.ae. For the federal law in its own right, see the guide to anti-money laundering laws in UAE.

Scope of this page:

This page covers lawyers, notaries, and legal consultants performing the five covered activities under Article 3(4) of Cabinet Resolution 134/2025, supervised by the Ministry of Justice. Accountants, auditors, and trust and company service providers are addressed on their own sibling pages in the DNFBPs cluster. Where cross-sector rules are common to every DNFBP (for example beneficial owner disclosure, targeted financial sanctions, and administrative penalties), this page states what they require of legal professionals specifically and links to the pillar page for the wider framing.

Who Counts as a Lawyer, Notary, or Legal Professional for AML Purposes in UAE?

A lawyer, legal consultant, or notary public is inside the UAE AML regime when they prepare, carry out, or assist a client with any of the five activities listed in Article 3, Clause 4 of Cabinet Resolution 134 of 2025.

The Five Covered Activities Under Article 3(4) of Cabinet Resolution 134 of 2025

The Executive Regulations list the activities that bring an independent legal professional inside the AML perimeter. Each is a transactional or representational act carried out for or on behalf of a client; performing any one of them triggers customer due diligence, record keeping, suspicious transaction reporting, and the wider obligations set out in Federal Decree-Law 10 of 2025.

1. Real estate transactions

Buying or selling real estate, whether the professional acts for the buyer, the seller, or holds client funds in the course of the transaction.

2. Managing client money

Managing customer funds, securities, or other assets held in a professional or fiduciary capacity.

3. Account management

Managing bank accounts, savings accounts, or securities accounts for a client.

4. Company contributions

Organising contributions for establishing, operating, or managing companies.

5. Legal persons and arrangements

Establishing, operating, or managing legal persons or legal arrangements, or performing any trading or buying and selling of commercial entities.

Source: Article 3, Clause 4, Cabinet Resolution No. 134 of 2025. The same five activities appear in the definition of designated non-financial businesses and professions in Article 1 of Federal Decree-Law No. 10 of 2025, read with Article 3, Clause 2 of the Executive Regulations. 

Notaries Public

A notary public is a public officer who authenticates signatures, declarations, powers of attorney, contracts, and other legal documents. Notaries working in the private sector, private notaries, and the notarial sections of law firms are brought within the AML, in line with Article 3(4) of Cabinet Resolution 134 of 2025. Ministerial Resolution 248 of 2025 explicitly extends the Ministry of Justice supervisory framework to notaries public alongside law firms and legal consultancy offices.

Work Outside the AML Perimeter

From a professional secrecy perspective, Article 18, Clause 2 of Federal Decree-Law 10 of 2025 and Article 18, Clause 2 of Cabinet Resolution 134 of 2025 both carve out work involving assessing the client’s legal position, defending the client, or representing the client in judicial, administrative, arbitral, or mediation proceedings. Firms must still apply AML controls to the transactional elements of a matter even if the advocacy elements fall within privilege.

AML Supervisory Authority for Lawyers, Notaries, and Other Legal Professionals in UAE

The Ministry of Justice is the supervisory authority for law firms, legal consultancy offices, and notaries public in the Mainland. This was confirmed when Cabinet Resolution No. 134 of 2025 designated the Ministry of Justice as the authority responsible for supervising lawyers and legal firms for AML/CFT purposes. Ministerial Resolution No. (248) of 2025, issued on 29 April 2025, replaces Ministerial Resolutions 532 and 533 of 2019 and sets out the supervisory procedures and controls in their current form.

UAE AML Framework Layers That Apply to Legal Professionals

FEDERAL  FDL 10/2025 and CR 134/2025 (Executive Regulations); FL 7/2014 Combating Terrorism Crimes; FDL 34/2022 Legal Profession; CR 8/2025 Executive Regulations of FDL 34/2022. 
CROSS-SECTOR  CR 74/2020 TFS and UN sanctions; CR 109/2023 Beneficial Owner procedures; CR 132/2023 BO penalties; CR 71/2024 administrative penalties for MoJ and MoE supervisees; EOCN TFS Guideline and CPF Guidance. 
SECTOR-SPECIFIC  MR 248/2025 supervisory controls for law firms, legal consultancies, and notaries public; MoJ Guidebook (November 2025); MoJ circulars from 2020 to 2026. 

How the Ministry of Justice supervises the sector

Three operational building blocks explain how MoJ plans, conducts, and concludes supervisory action over legal professionals.

AML/CTF Department

The dedicated AML/CTF Department inside MoJ is the operational face of supervision, assigning inspectors and issuing guidance.

Risk-based inspections

Inspections follow a risk-based methodology that weights firm size, client profile, and the five covered activities.

Administrative sanctions

Breaches are dealt with under Cabinet Resolution 71 of 2024 and Article 6 of Ministerial Resolution 248 of 2025.

The MoJ AML/CTF Department and Its Fifteen Functions

The Guidebook for Law Firms and Legal Consultancy Offices on Combating Money Laundering, Countering the Financing of Terrorism and Countering Proliferation Financing, Second Edition, published by the Ministry of Justice in November, sets out fifteen functions for the Department. These include, among others, supervising law firms, legal consultancy offices, and notaries public for AML/CFT/CPF compliance; carrying out risk-based on-site and off-site inspections; imposing administrative sanctions and escalating suspected criminal conduct to prosecutors; cooperating with the Financial Intelligence Unit, the Executive Office for Control and Non-Proliferation, and other domestic and foreign counterparts; maintaining typologies; issuing sector guidance; and running awareness programmes.

Risk-Based Supervision and Inspection Readiness

Ministerial Resolution 248 of 2025 requires MoJ to adopt a risk-based approach when planning and conducting inspections and when deciding the scope and depth of each visit. Practically, this means firms are rated using factors such as client geographies, types of covered activities, complexity of legal persons being established or managed, cash handling, and past supervisory history.

A firm that is well prepared keeps a complete documentation pack at all times, including its firm-wide risk assessment, client risk assessments, sanctions screening logs, transaction risk assessments, STR-decision logs, training records, and a corrective action register showing how any previous findings have been closed out.

Inspection readiness is a continuous state, not a reaction

MoJ inspectors are entitled to request any AML document, client file, or system log at short notice. Firms that treat inspection readiness as a perpetual discipline, rather than a pre-visit scramble, consistently score better against the Guidebook’s controls.

Administrative Sanctions and Appeals

Article 6 of Ministerial Resolution 248 of 2025 provides that the AML Department may impose any of the administrative penalties set out in Cabinet Resolution 71 of 2024 on a law firm, legal consultancy office, or notary public that breaches the AML rules. The Guidebook identifies seven types of sanctions, which can include warnings, fines, restrictions on activity, suspension of managers or compliance officers, and suspension or cancellation of the licence.

A grievance may be filed with the Minister of Justice within twenty working days from the date of notification under Article 7 of MR 248 of 2025, with the Ministry responding within thirty working days under Article 8, failing which silence amounts to rejection per the general forty-day rule in Cabinet Resolution 71 of 2024.

Financial Free-Zone Carve-Out

Firms licensed in Abu Dhabi Global Market are supervised by the Registration Authority, and firms licensed in the Dubai International Financial Centre are supervised by the Dubai Financial Services Authority under the DIFC regulatory regime. MoJ supervision does not apply to them. A dual-licensed group of companies can adopt a group-wide AML programme while retaining separate records and applying the rulebook of the authority that licenses each leg of the business.

Dimension Mainland ADGM DIFC
Supervisory authority Ministry of Justice Registration Authority (RA) Dubai Financial Services Authority (DFSA)
Licensing authority  Ministry of Justice; Executive Council decisions for notaries Registration Authority of ADGM DIFC Authority
Core AML rulebook FDL 10/2025, CR 134/2025, CR 71/2024, MR 248/2025 FSRA AML Rulebook under ADGM Financial Services and Markets Regulations DFSA AML Module under the DIFC Regulatory Law
Sector guidance MoJ Guidebook for Law Firms and Legal Consultancy Offices (November 2025) FSRA-issued AML guidance for DNFBPs in ADGM DFSA-issued AML guidance for DNFBPs in DIFC 

Preparing for a MoJ inspection?

AML UAE runs pre-inspection readiness reviews against the MoJ Guidebook's ten obligations and Cabinet Resolution 71 of 2024 violations, with a prioritised remediation plan.

AML Regulations Applicable to Lawyers, Notaries, and Other Legal Professionals in UAE

The AML rulebook for legal professionals in the UAE is a stack. At the base sit the federal law and its Executive Regulations, followed by cross-sector resolutions on sanctions, beneficial ownership, and penalties. Sector-specific layers come next: Ministerial Resolution 248 of 2025 for supervision, the MoJ Guidebook for substantive controls, and a sequence of MoJ circulars that operationalise particular obligations. Overarching guidance from the Executive Office for Control and Non-Proliferation, the Financial Intelligence Unit, and the National Anti-Money Laundering and Combating the Financing of Terrorism Committee completes the picture.

Four groups of instruments every law firm must follow

Each group sits on a distinct tier of the framework; together, they form the complete AML rulebook for MoJ-supervised legal professionals.

1. Federal AML laws

Federal Decree-Law 10 of 2025 and Executive Regulations 134 of 2025, plus terrorism, beneficial owner, sanctions, and penalty resolutions.

2. Overarching guidance

EOCN TFS and CPF guidance, FIU strategic analysis, red flag typologies, and joint guidance on satisfactory practice.

3. NRA and SRA

UAE ML/TF National Risk Assessment 2024 and sectoral risk assessments feeding into MoJ’s supervisory priorities.

4. Sector instruments

MoJ Guidebook (November 2025) and circulars from 2020 to 2026 on CDD, TFS, REAR, high-risk jurisdictions, and policy updates.

Federal AML Laws and Executive Regulations Applicable to Lawyers, Notaries, and Legal Professionals

Eleven federal instruments form the statutory base for AML compliance by lawyers, notaries, and legal consultants in UAE. They range from the primary AML decree law and its Executive Regulations through to sector-neutral resolutions on sanctions, beneficial ownership, and penalties, and two instruments specific to the profession itself.

Ten federal instruments in this section

Each item below is a separate subsection summarising its scope, the articles most relevant to legal professionals, and the key thresholds or penalties.

01. FDL 10/2025

AML/CFT/CPF Federal Decree-Law

02. CR 134/2025

Executive Regulations

03. CR 8/2025

Executive Regulations of Legal Profession Law

04. MR 248/2025

MoJ supervisory procedures 

05. CR 71/2024

Administrative penalties for MoJ/MoE supervisees

06. FDL 34/2022

Legal Profession Law 

07. CR 74/2020

Terrorist lists and UNSC resolutions

08. FL 7/2014

Combating Terrorism Crimes

09. CR 109/2023

Beneficial owner procedures

10. CR 132/2023

BO administrative penalties

1. Federal Decree by Law No. (10) of 2025 Regarding Anti-Money Laundering, and Combating the Financing of Terrorism and Proliferation Financing

Federal Decree-Law No. (10) of 2025, issued on 30 September 2025, is the primary AML statute for the UAE. Article 41 repealed Federal Decree-Law No. (20) of 2018 and superseded its Executive Regulations, subject to any instruments issued under the old law remaining in force until amended, unless inconsistent with the new decree.

For lawyers, notaries, and legal consultants the most important provisions are Articles 2 and 3 which criminalise money laundering, financing of terrorism, and the financing of the proliferation of weapons of mass destruction; Article 18 which imposes the suspicious transaction reporting duty on DNFBPs subject to the privilege carve-out in clause 2; Article 19 on the prohibition on tipping off; Article 26 setting imprisonment from one to ten years and fines from AED 100,000 to AED 5,000,000 for laundering; Article 27 setting legal-person fines of AED 5,000,000 to AED 100,000,000; Article 28 imposing AED 100,000 to AED 1,000,000 for breaches of Article 18; Article 29 setting fines from AED 50,000 for tipping off; and Article 33 setting fines from AED 20,000 for breaches of targeted financial sanctions.

2. Cabinet Resolution No. (134) of 2025 Concerning the Executive Regulations of Federal Decree-Law No. (10) of 2025

Cabinet Resolution No. (134) of 2025 is the operational manual for the federal decree law. Article 3, Clause 4 lists the five covered activities that bring lawyers, notaries, and independent legal professionals inside the AML regime.

Article 18, Clause 2 preserves legal professional privilege over assessment of the client’s legal position, defence, representation, arbitration, mediation, and the issuing of a legal opinion.

Article 19, Clause 2 makes clear that dissuading a client from engaging in an unlawful act is not tipping off.

3. Cabinet Resolution No. (8) of 2025 Regarding the Executive Regulations of Federal Decree-Law No. (34) of 2022 Regulating the Legal Profession and Legal Consultation Profession

Cabinet Resolution No. (8) of 2025 is the Executive Regulations of the Legal Profession Law. While its scope is the profession generally rather than AML specifically, it governs licensing, categories of registration, conduct rules, disciplinary committees, and registers maintained by the Ministry of Justice, and it therefore sets the institutional foundation against which AML sanctions, such as suspension or cancellation of a licence, actually operate. Compliance officers should read it alongside Federal Decree-Law No. (34) of 2022 when assessing the consequences of supervisory action.

4. Ministerial Resolution No. (248) of 2025 on Supervising Law Firms, Legal Consultancy Offices, and Notaries Public

Ministerial Resolution No. (248) of 2025, issued on 29 April 2025, regulates the procedures and controls for supervising and monitoring law firms, legal consultancy offices, and notaries public in the field of combating money laundering and terrorism. It establishes the AML/CTF Department as the competent body; sets out inspection methodology; confirms application of Cabinet Resolution 71 of 2024 penalties through Article 6; provides a twenty-working-day grievance window in Article 7; mandates a thirty-working-day response window in Article 8; and repeals Ministerial Resolutions 532 and 533 of 2019.

5. Cabinet Resolution No. (71) of 2024 Regulating Violations and Administrative Penalties Imposed on Violators of AML/CFT Measures Under the Supervision of MoJ and MoE

Cabinet Resolution No. (71) of 2024, issued on 8 July 2024, is the administrative penalties grid for DNFBPs supervised by MoJ and by the Ministry of Economy. It repeals Cabinet Resolution No. (16) of 2021 and sets out forty-one categories of violation with fines ranging from AED 50,000 to AED 1,000,000. Article 4 provides a twenty-working-day notification window, a thirty-working-day grievance window, and a forty-day deemed-rejection rule where the grievance is not filed. Article 5 allows fines to be doubled on repetition within a set period. A selection of the schedule is reproduced below for orientation; firms should consult the full text for the complete list.

ArtViolation summaryFine (AED) 
1.Failure to apply customer due diligence measures to new or existing clients.50,000 – 200,000
2.Failure to identify the beneficial owner or to take reasonable steps to verify beneficial ownership information.50,000 – 200,000
3.Failure to conduct ongoing monitoring of the business relationship and to scrutinise transactions.50,000 – 500,000
4.Failure to conduct ongoing monitoring of the business relationship and to scrutinise transactions.100,000 – 500,000 

6. Federal Decree-Law No. (34) of 2022 Regulating the Legal Profession and Legal Consultation Profession

Federal Decree-Law No. (34) of 2022 is the governing law of the legal profession. It sets out licensing conditions, categories of lawyers, conduct duties, disciplinary committees, and the powers of the Ministry of Justice and the Executive Council. For AML purposes, it is the upstream instrument that defines who is a lawyer or legal consultant and whose license may be suspended or cancelled when penalties under Cabinet Resolution 71 of 2024 are imposed.

7. Cabinet Decision No. (74) of 2020 Regarding Terrorism Lists and Implementation of UN Security Council Resolutions

Cabinet Decision No. (74) of 2020 regulates the UAE’s domestic terrorism lists and the implementation of United Nations Security Council resolutions on the suppression and combating of terrorism, terrorist financing, countering the proliferation of weapons of mass destruction, and related resolutions. It creates the obligation on every DNFBP, including law firms and notaries, to screen customers, transactions, and related parties against the UN Consolidated List and the UAE Local List; to apply without delay freezing measures on any confirmed match; and to report Confirmed Name Match Reports and Partial Name Match Reports to the FIU.

8. Federal Law No. (7) of 2014 on Combating Terrorism Crimes

Federal Law No. (7) of 2014 on Combating Terrorism Crimes is the criminal statute on terrorism offences, including financing. It defines terrorist acts, terrorist organisations, and the financing of terrorism, and it underpins the obligation in Federal Decree-Law 10 of 2025 to report suspicions of terrorism-related activity. Legal professionals should read it alongside Cabinet Decision 74 of 2020 when drafting STR scripts and training modules.

9. Cabinet Decision No. (109) of 2023 on Regulating the Beneficial Owner Procedures

Cabinet Decision No. (109) of 2023 governs beneficial owner disclosure for legal persons in the UAE. For legal professionals, the instrument is particularly relevant when they establish or manage companies for clients: they must help the entity meet the requirements to maintain a beneficial owner register, a nominee director register where applicable, and a partners or shareholders register; keep the information accurate and current; and file prescribed beneficial owner information with the registrar. The 25 per cent ownership threshold referenced in Cabinet Resolution 134 of 2025 mirrors the BO identification trigger used across the UAE framework.

10. Cabinet Resolution No. (132) of 2023 Concerning Administrative Penalties for Violations of Cabinet Decision No. (109) of 2023

Cabinet Resolution No. (132) of 2023 is the administrative penalties grid for beneficial owner breaches. Law firms that provide company formation and ongoing management services should understand these penalties because, although the penalty is imposed on the legal person, the firm’s role in maintaining the register and filing the data can attract parallel administrative liability under Cabinet Resolution 71 of 2024 as part of its AML obligations.

Quick Reference Timeline of Federal AML Instruments Affecting Legal Professionals

2014   CRIMINAL LAW 

Federal Law No. (7) of 2014 on Combating Terrorism Crimes 

Defines terrorism offences including financing and underpins STR scripts. 

2020   CROSS-SECTOR 

Cabinet Decision No. (74) of 2020 on terrorism lists and UNSC resolutions 

Creates screening, freezing, and EOCN reporting duties for every DNFBP. 

2022   PROFESSION 

Federal Decree-Law No. (34) of 2022 Regulating the Legal Profession 

Governs licensing, categories of lawyer, and disciplinary framework. 

2023   CROSS-SECTOR 

Cabinet Decision No. (109) of 2023 on Beneficial Owner Procedures 

Registers, filings, and 25 per cent identification threshold for legal persons. 

2023   CROSS-SECTOR 

Cabinet Resolution No. (132) of 2023 on BO Administrative Penalties 

Penalty grid for beneficial owner non-compliance. 

2024   CROSS-SECTOR 

Cabinet Resolution No. (71) of 2024 on AML/CFT Administrative Penalties 

Forty-one violations; fines AED 50,000 to AED 1,000,000; doubling on repetition. 

2025   PROFESSION 

Cabinet Resolution No. (8) of 2025 Executive Regulations of FDL 34/2022 

Operational rules for licensing, registers, and disciplinary action. 

2025   SECTOR 

Ministerial Resolution No. (248) of 2025 on supervision of law firms and notaries 

Establishes MoJ AML/CTF Department, inspection methodology, and grievance windows. 

2025   FEDERAL 

Federal Decree-Law No. (10) of 2025 on AML/CFT/CPF 

Primary AML statute; repeals FDL 20/2018; imprisonment and fine bands. 

2025   FEDERAL 

Cabinet Resolution No. (134) of 2025 Executive Regulations of FDL 10/2025 

Five covered activities; privilege carve-out; thresholds; BO rule. 

Need to map these laws to your firm's existing AML manual?

AML UAE performs gap-analysis mapping each article in FDL 10/2025, CR 134/2025, and CR 71/2024 to your current policies and procedures.

Overarching AML Guidance Applicable to Lawyers, Notaries, and Legal Professionals

Beyond federal statutes, legal professionals must follow a library of cross-sector guidance issued by the Executive Office for Control and Non-Proliferation, the Financial Intelligence Unit, and the National AML/CFT Committee. These documents are not stand-alone rulebooks, but failure to act on them is regularly cited as a contributing factor when administrative penalties are imposed under Cabinet Resolution 71 of 2024.

Thirteen cross-sector documents in this section

Dates, issuers, and scope; each gets its own reference card below.

01. TFS Guidance (EOCN)

AML/CFT/CPF Federal DecCore guidance on targeted financial sanctions for FIs, DNFBPs, and VASPs. ree-Law

02. FIU Strategic Analysis

Terrorist financing typologies and facilitators, May 2025

03. Strategic Review

TFS case studies covering 2019 to 2021.

04. PF Institutional RA

Proliferation finance institutional risk assessment guidance.

05. TF and PF Red Flags

Red flag indicators on terrorist and proliferation financing.

06. Unlicensed VA Providers

Joint guidance on combating unlicensed virtual asset providers.

07. CPF Guidance

Counter proliferation financing guidance for FIs, DNFBPs, and VASPs.

08. Satisfactory Practice

Joint guidance on satisfactory and unsatisfactory practice.

09. TFS Typologies

EOCN typologies on circumvention of targeted sanctions.

10. Grievance Guideline

Framework for challenging supervisory decisions.

11. Online Grievance Guide

Step-by-step user guide for the MoJ online grievance system.

12. Combating PF & Sanctions Evasion

Cross-agency publication on PF and sanctions evasion.

13.NAS Simple Guide

How to subscribe to the EOCN Notification Alert System.

1. Guidance on Targeted Financial Sanctions for FIs, DNFBPs and VASPs (EOCN)

Issued January 2021; Last amended March 2026 

Guidance on Targeted Financial Sanctions for Financial Institutions, Designated Non-Financial Businesses and Professions, and Virtual Asset Service Providers 

Central EOCN guidance explaining the legal framework for TFS, scope of application, freezing without delay, reporting of Confirmed Name Match Reports and Partial Name Match Reports, use of the goAML and EOCN Notification Alert System, and expectations on sanctions screening, governance, and training. Published on eocn.gov.ae.

2. FIU Strategic Analysis Report on Terrorist Financing (May 2025)

May 2025 

Terrorist Financing Typologies and Facilitators – A Strategic Analysis Report 

UAEFIU public version strategic analysis setting out TF typologies and facilitator profiles observed in UAE STR data; complements sector red-flag catalogues and informs MoJ risk-based inspection priorities. 

3. Strategic Review on Targeted Financial Sanctions Case Studies (April 2024)

April 2024 (content: November 2021, IEC-SR.01.22) 

Strategic Review on Targeted Financial Sanctions Case Studies 2019-2021 

EOCN review of case studies drawn from UAE TFS implementation, highlighting common failings such as delayed screening, weak governance, and unreported partial matches. Useful for law firms drafting sanctions-screening logs.

4. Proliferation Finance Institutional Risk Assessment Guidance (December 2023)

Published December 2023 

Proliferation Finance Institutional Risk Assessment Guidance for FIs, DNFBPs and VASPs 

Methodology for conducting a firm-level PF risk assessment, including jurisdiction, customer, product, and delivery-channel risk. Expected input into a law firm’s enterprise-wide risk assessment.

5. Terrorist and Proliferation Financing Red Flags Guidance (December 2023)

Published September 2023; updated December 2023 

Terrorist and Proliferation Financing Red Flags Guidance 

Concise catalogue of TF and PF red flags designed to be embedded in STR decision trees. Firms should map each indicator to their goAML reporting workflow.

6. Joint Guidance on Combating the Use of Unlicensed Virtual Asset Providers (November 2023)

Issued March 2022 (Supervisory Authority Sub-Committee) 

Joint Guidance on Combating the Use of Unlicensed Virtual Asset Providers in the United Arab Emirates 

Expectations on DNFBPs, including law firms handling digital-asset company formations, to screen for unlicensed virtual asset activity and reject onboarding where red flags are present

7. Guidance on Counter Proliferation Financing for FIs, DNFBPs, and VASPs (November 2022)

Published 01 November 2022 – EOCN-PF.01.23 

Counter Proliferation Financing Guideline 

Authoritative EOCN guidance on CPF obligations, including understanding dual-use goods typologies, sanctions evasion tactics, and the expected governance response. 

8. Joint Guidance on Satisfactory and Unsatisfactory Practice (June 2021)

June 2021 

Anti-Money Laundering and Countering Terrorist Financing Guidelines – Satisfactory and Unsatisfactory Practice 

Supervisory Authority Sub-Committee guidance contrasting practices that are considered satisfactory with those that are unsatisfactory. A reliable benchmark for internal audits.

9. Typologies on the Circumvention of Targeted Sanctions (March 2021)

Issued 20 March 2021; last amended 11 May 2021 

Typologies on the Circumvention of Targeted Sanctions against Terrorism and the Proliferation of Weapons of Mass Destruction (United Arab Emirates) 

EOCN typology paper focusing on evasion techniques including shell companies, trade-based methods, and misuse of legal persons. Particularly relevant to law firms establishing and managing entities. 

10. Guideline on Grievance Procedures

Undated (EOCN publication) 

Guideline on Grievance Procedures 

Framework guidance on filing grievances against supervisory decisions across federal authorities. Read alongside Articles 7 and 8 of MR 248 of 2025 for timelines. 

11. Online Grievance System User Guide

Undated 

Online Grievance System – User Guide 

Step-by-step walkthrough of the online grievance platform, including registration, grievance submission, and status tracking

12. Combating Proliferation Financing and Sanctions Evasion

EOCN publication 

Combating Proliferation Financing & Sanctions Evasion 

Reference text on PF typologies and evasion techniques; integrates with the CPF Guidance and the Typology Paper.

13. Simple Guide to Subscribe to the EOCN Notification Alert System (NAS)

EOCN publication 

Simple Guide to Subscribe to the EOCN Notification Alert System (NAS) 

Short operational guide to subscribing to the NAS, which delivers near real-time notifications of UN and UAE list updates and is a standard control for every law firm’s sanctions programme. 

Turning guidance into workable controls

AML UAE converts cross-sector guidance into operational checklists, screening-log templates, and STR decision trees tailored to your firm's covered activities.

NRA, SRA, and Other Important Guidelines Applicable to Lawyers and Legal Professionals

The UAE Money Laundering and Terrorist Financing Risk Assessment Report is the single most important cross-cutting risk document for every DNFBP, including law firms and notaries. Published by the National Anti-Money Laundering and Combating the Financing of Terrorism and Financing of Illegal Organisations Committee, it sets the macro picture against which sectoral risk assessments and firm-level risk assessments are calibrated.

UAE Money Laundering and Terrorist Financing Risk Assessment Report – 2024

National AML/CFT Committee 

UAE Money Laundering and Terrorist Financing National Risk Assessment Report 

The NRA assesses ML and TF threats and vulnerabilities across the UAE financial, VASP, and DNFBP sectors. In the UAE, the Law Firms and Legal Consultations Sector is classified as Medium-Low risk for ML since there are no evidence showing that the sector has been abused for ML, or any predicate offences 

to ML. For legal professionals it highlights risks associated with the establishment and management of legal persons and arrangements, real estate transactions, and complex cross-border structures, feeding into the MoJ’s sector supervision plan. Circular No. (2) of 2025 of the Ministry of Justice directly instructs law firms to reflect NRA findings in their firm-wide risk assessments. 

Does your firm's risk assessment reflect the NRA?

AML UAE helps law firms translate NRA findings into firm-specific risk factors and weight them appropriately in the customer risk methodology.

Sector-Specific Guidelines Applicable to Lawyers, Notaries, and Legal Professionals

Sector-specific instruments are issued by the Ministry of Justice. They fall into two groups: the central Guidebook that explains what satisfactory compliance looks like, and a sequence of circulars that direct firms to act on discrete obligations (policy updates, high-risk country lists, TFS implementation, and the real-estate activities report). All circulars listed below are officially published by the Ministry of Justice; the 2023, 2024, 2025, and 2026 policy update circulars are available on the MoJ website, while the earlier circulars are published in Arabic on the MoJ portal.

Twelve sector instruments in this section

The Guidebook plus eleven circulars spanning 2020 to 2026. Each card below states what the instrument requires of a law firm or notary.

01.Circular 1/2026

Updating AML policies, procedures, and controls.

02. MoJ Guidebook (Nov 2025)

Substantive sector reference.

03. Circular 3/2025

Updated list of high-risk jurisdictions.

04. Circular 2/2025

Acting on the UAE National Risk Assessment.

05. Circular 1/2025

Institutional assessment process controls.

06. Circular 1/2024

Simplified due diligence procedures.

07. Circular 2/2023

Obligations concerning high-risk jurisdictions.

08. Circular 1/2023

Commitment to institutional assessment controls.

09. Circular 14/2022

REAR – Real Estate Activities Report.

10. Circular 9/2022

Implementation of TFS under UN resolutions.

11. Circular 11/2021

Lawyers’ obligations on high-risk country lists.

12. Circular 18 + Circular 36/2020

Sanctions-list reporting and UN list implementation.

1. Circular No. (1) of 2026 Concerning the Obligation of Law Firms and Legal Consultancy Offices to Update Policies, Procedures, and Controls Related to AML/CFT/CPF (Arabic only)

Issued 2026 

Circular No. 1 of 2026 – Updated AML/CFT/CPF policies, procedures, and controls 

Directs law firms and legal consultancy offices to refresh their internal AML/CFT/CPF policies, procedures, and controls to reflect Federal Decree-Law 10 of 2025 and Cabinet Resolution 134 of 2025, and to update documentation accordingly. Published by the Ministry of Justice; currently available in Arabic only.

2. Guidebook for Law Firms and Legal Consultancy Offices on AML/CFT/CPF (November 2025)

Second Edition, published 25 November 2025 

Guidebook for Law Firms and Legal Consultancy Offices on Combating Money Laundering, Countering the Financing of Terrorism and Countering Proliferation Financing 

The principal sector reference issued by the Director of the AML/CTF Department at the Ministry of Justice. It covers relevant legislation, supervisory structure, AML Department functions, key obligations, compliance-officer requirements, STR reporting via goAML, five-year record retention, TFS 24-hour freeze and one-business-day EOCN notification, administrative sanctions, appeal procedures, and sources of assistance including amlctf@moj.gov.ae and the EOCN address iec@uaeiec.gov.ae

3. Circular No. (3) of 2025 Regarding the Update of the List of High-Risk Countries and Countries Subject to Enhanced Monitoring (Arabic only)

Issued 2025 

Circular No. 3 of 2025 – Updated list of high-risk countries 

Directs lawyers and law firms to apply enhanced due diligence to clients from the updated FATF high-risk jurisdictions and jurisdictions subject to increased monitoring. Currently available in Arabic only on the Ministry of Justice website. 

4. Circular No. (2) of 2025 Regarding the National Risk Assessment (Arabic only)

Issued 2025 

Circular No. 2 of 2025 – National Risk Assessment 

Requires law firms to align their firm-wide risk assessments, client risk methodologies, and control environments with findings in the UAE National Risk Assessment. Currently available in Arabic only. 

5. Circular No. (1) of 2025 Regarding Commitment of Law Firms to the Controls of Institutional Assessment Processes (Arabic only)

Issued 2025 

Circular No. 1 of 2025 – Institutional assessment process controls 

Sets expectations on the institutional assessment process that law firms must follow, including documentation, sign-off, and periodic review. Currently available in Arabic only.

6. Circular No. (1) of 2024 Regarding Simplified Due Diligence Procedures (Arabic only)

Issued 2024 

Circular No. 1 of 2024 – Simplified due diligence procedures 

Clarifies the circumstances in which simplified due diligence is permitted, aligning with Cabinet Resolution 134 of 2025 on low-risk scenarios. Currently available in Arabic only

7. Circular No. (2) of 2023 Regarding Obligations of Lawyers Concerning the Updated List of High-Risk Countries (Arabic only)

Circular No. 2 of 2023 concerns lawyers’ obligations concerning the updated list of high-risk countries. A copy of this circular was not available to us in PDF form at the time of writing; the text is referenced in the Ministry of Justice archive, but firms should obtain the current version directly from the Ministry before applying it. 

8. Circular No. (1) of 2023 Regarding Commitment of Law Firms to the Controls of Institutional Assessment Processes (Arabic only)

Issued 2023 

Circular No. 1 of 2023 – Institutional assessment controls 

Earlier MoJ circular requiring law firms to commit to the controls of institutional AML assessment processes; superseded in substance by Circular No. 1 of 2025 on the same subject.

9. Circular No. (14) of 2022 Regarding the REAR Real Estate Activities Report (Arabic only)

Issued 2022 

Circular No. 14 of 2022 – REAR (Real Estate Activity Report) 

Instructs law firms involved in real estate transactions to file the Real Estate Activity Report on relevant transactions, consistent with the requirements that apply across DNFBPs handling real estate. 

10. Circular No. (9) of 2022 on Implementation by Lawyers of Targeted Financial Sanctions Under UN Security Council Resolutions (Arabic only)

Issued 2022 

Circular No. 9 of 2022 – Implementation by lawyers of targeted financial sanctions 

Reaffirms that lawyers must implement targeted financial sanctions stipulated by UN Security Council resolutions and the UAE cabinet, with without-delay freezing and reporting via EOCN.

11. Circular No. (11) of 2021 Regarding Lawyers' Obligations on Updated List of High-Risk Countries (Arabic only)

Issued 2021 

Circular No. 11 of 2021 – Lawyers’ obligations on high-risk countries 

Requires lawyers to apply enhanced due diligence to clients from high-risk jurisdictions; predecessor to Circular 3 of 2025 on the same subject. 

12. Circular No. (18) Regarding Lawyers' Implementation of Obligations to Report Clients on Sanctions Lists (Arabic only)

Issued 2020 

Circular No. 18 – Reporting of clients on international or local sanctions lists 

Directs law firms to report clients appearing on international or local sanctions lists in accordance with federal and EOCN procedures.

13. Circular No. (36) of 2020 Regarding the International and Local Sanctions Lists (Arabic only)

Issued 2020 

Circular No. 36 of 2020 – International and local sanctions lists 

Implements UN Security Council and cabinet sanctions lists at the level of lawyers and law firms, including obligations to screen clients and report matches. 

Conclusion

AML regulations for lawyers in UAE are neither a single rulebook nor a single set of penalties. They are a federated framework anchored in Federal Decree-Law No. (10) of 2025 and its Executive Regulations, built up through Cabinet Resolution No. (74) of 2020 on sanctions, Cabinet Decision No. (109) of 2023 on beneficial ownership, Cabinet Resolution No. (132) of 2023 on BO penalties, and Cabinet Resolution No. (71) of 2024 on administrative penalties, and made operational for the legal sector through Ministerial Resolution No. (248) of 2025, the Ministry of Justice Guidebook of November 2025, and a sequence of MoJ circulars from 2020 to 2026. 

What this means in practice for law firms, legal consultancy offices, and notaries public is that compliance is continuous rather than episodic. A satisfactory firm will maintain an enterprise-wide risk assessment that reflects the UAE National Risk Assessment; a client-onboarding process that systematically tests whether a matter falls within one of the five covered activities; sanctions-screening logs and Confirmed Name Match Report workflows that support the 24-hour freeze and one-business-day EOCN reporting; STR decision trees that operate through goAML and respect the privilege carve-out in Article 18, Clause 2 of FDL 10 of 2025 and CR 134 of 2025; a five-year records retention architecture; policies and procedures that are refreshed whenever a new MoJ circular is issued; and a training programme that keeps partners, lawyers, paralegals, and notaries public current on the framework. 

Firms licensed in ADGM or DIFC operate inside their respective free-zone regimes and should look to FSRA and DFSA rulebooks rather than MoJ instruments. For every other MoJ-supervised legal professional, the rulebook above is the benchmark the AML/CTF Department will use on an inspection. 

Found this guide useful?

If this article helped you clarify your firm's AML obligations, a short Google review helps other legal professionals find clear, sourced UAE guidance.

Frequently Asked Questions

When do lawyers and legal consultants fall under UAE AML law?

A lawyer, legal consultant, or notary public falls under UAE AML law when they prepare or carry out any of the five covered activities under Article 3, Clause 4 of Cabinet Resolution 134 of 2025: buying or selling real estate; managing client money, securities, or assets; managing bank, savings, or securities accounts; organising contributions for a company; or establishing, operating, or managing legal persons or arrangements. Pure litigation, arbitration, mediation, and legal opinion work is protected by the privilege carve-out in Article 18, Clause 2 of Federal Decree-Law 10 of 2025. 

The Ministry of Justice supervises law firms, legal consultancy offices, and notaries public through its AML/CTF Department, following Cabinet Decision No. (1/3 W) of 2019 and Cabinet Decision 65 of 2024, which upgraded the AML section into a full department. Ministerial Resolution No. (248) of 2025 sets out the current supervisory procedures and controls. Firms licensed in ADGM are supervised by FSRA; firms licensed in DIFC are supervised by DFSA. 

A law firm should maintain its firm-wide risk assessment; each client risk assessment; CDD and enhanced due diligence files; beneficial ownership information; transaction records and transaction risk assessments for covered activities; sanctions-screening logs, including CNMR and PNMR records and EOCN correspondence; STR decision records and goAML submission receipts; training and attendance records; and a corrective action register. Retention is for five years from the end of the business relationship or completion of the transaction, per the MoJ Guidebook of November 2025 and Cabinet Resolution 134 of 2025. 

Ministerial Resolution No. (248) of 2025, issued on 29 April 2025, replaces Ministerial Resolutions 532 and 533 of 2019. It confirms the MoJ AML/CTF Department as the competent supervisory body for law firms, legal consultancy offices, and notaries public; applies the Cabinet Resolution 71 of 2024 penalty schedule through Article 6; provides a 20-working-day grievance window in Article 7; and requires a 30-working-day response in Article 8. Firms should refresh their sanctions, STR, and governance policies to align with the new instrument. 

Yes. Law firms licensed in Abu Dhabi Global Market are supervised by the Registration Authority and follow the ADGM Financial Services and Markets Regulations together with the FSRA AML Rulebook. Law firms licensed in the Dubai International Financial Centre are supervised by the Dubai Financial Services Authority and follow the DIFC Regulatory Law and DFSA AML Module. These free-zone regimes are distinct from the Mainland MoJ regime described above and are covered on the ADGM and DIFC pages in this cluster.

Talk to AML UAE about your firm's compliance programme

Whether you are setting up a new law firm, responding to a MoJ inspection, or refreshing policies following Circular 1 of 2026, AML UAE helps legal professionals implement the full framework.

Share via :

About the Author

Pathik Shah

FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)

Pathik is an ACAMS-certified AML consultant specialising in governance, risk, and compliance for regulated entities in the UAE. He brings over 28 years of experience, with 1,000+ hours of AML training and 200+ advisory engagements across DNFBPs, VASPs, and FIs. He supports businesses in aligning with AML/CFT requirements from the CBUAE, DFSA, MoET, MoJ, VARA, CMA, FSRA, and FATF. Known for translating complex regulations into audit-ready procedures, Pathik enables operational clarity and compliance readiness.

Reach Out to Pathik

AML Regulations for Dealers in Precious Metals and Stones (DPMS) in UAE

AML Regulations for Dealers in Precious Metals and Stones (DPMS) in UAE

Blogs

Published On: 04/28/2026

Table of Contents

Protect your business with reliable and effective AML strategies with AML UAE.

Last Reviewed On: 07/21/2026   |   Last Updated On: 07/21/2026

Key Highlights

  • DPMS are brought into the AML/CFT perimeter at an AED 55,000 transaction threshold defined in Article 3(3) of Cabinet Resolution 134 of 2025.
  • The Anti-Money Laundering Department of the Ministry of Economy and Tourism supervises DPMS operating in the mainland and commercial free zones.
  • Every threshold-crossing transaction must be captured in a Dealers in Precious Metals and Stones Report (DPMSR) filed on goAML (MoE Circular 08/AML/2021).
  • Gold refiners and supply-chain participants are subject to an additional 5-step responsible sourcing framework under Ministerial Decree 68 of 2024.
  • Administrative fines for AML/CFT violations range from AED 50,000 to AED 1,000,000 per violation under Cabinet Resolution 71 of 2024.
  • The UAE’s 2024 National Risk Assessment rates the sector’s inherent ML/TF risk as medium-to-high.

AML Regulations for Dealers in Precious Metals and Stones (DPMS) in UAE

The AML Regulations for DPMS in UAE sit inside the wider Designated Non-Financial Businesses and Professions (DNFBP) framework explained in our parent guide, AML Regulations for DNFBPs in UAE. Precious metals and stones markets combine high intrinsic value, cross-border mobility and deep cash reliance, which is why Federal Decree Law 10 of 2025, Cabinet Resolution 134 of 2025 and a dedicated set of Ministry of Economy and Tourism (MoET) circulars bring dealers in precious metals and stones inside the UAE’s AML/CFT/CPF perimeter.

This page explains the legal framework, the supervisory architecture, the 5-step gold sourcing overlay and the obligations that every DPMS must meet when it crosses the AED 55,000 threshold set out in Article 3(3) of the Executive Regulations.

At a Glance

Perimeter: Any dealer in precious metals or precious stones carrying out a single cash transaction, or linked cash transactions, equal to or above AED 55,000 (Cabinet Resolution 134/2025, Article 3(3)).

Primary supervisor: Ministry of Economy and Tourism (MoET) for mainland and commercial free zone DPMS.

Governing law: Federal Decree Law 10 of 2025 (AML/CFT/CPF); Cabinet Resolution 134 of 2025 (Executive Regulations).

Reporting trigger: DPMSR filed on goAML for each cash or wire transaction at or above AED 55,000 (MoE Circular 08/AML/2021).

Gold sourcing overlay: Gold refineries and supply chain entities must apply the 5-step Due Diligence Regulations for Responsible Sourcing of Gold (Ministerial Decree 68/2024; Circular 2/2024).

Penalty range: AED 50,000 to AED 1,000,000 per violation (Cabinet Resolution 71 of 2024).

Sector risk rating: Medium-to-high ML/TF risk (UAE National Risk Assessment 2024).

Population on goAML: 8,191 DPMS registered as of 30 June 2025; 1,448,825 DPMSRs filed Jul 2021 – Jun 2025 (UAEFIU Strategic Analysis Report on DPMS, Sept 2025).

Scope note

This page explains AML regulations applicable to dealers in precious metals and stones (DPMS) in the UAE, with specific coverage of gold sourcing and the AED 55,000 reporting threshold. Broader AML obligations that apply across all DNFBPs are explained in AML Regulations for DNFBPs in UAE.

What this DPMS Guide Covers

Three substantive sections walk you through perimeter, supervisor and the layered AML regulations for DPMS in UAE.

1. Who Counts as a DPMS in the UAE

2. AML Supervisory Authority for DPMS

3. AML Regulations Applicable to DPMS

Who Counts as a Dealer in Precious Metals and Stones (DPMS) in the UAE?

A dealer in precious metals and stones (DPMS) is any natural or legal person who, in the course of business, trades in precious metals or precious stones and who carries out a single cash transaction, or several linked cash transactions, at or above AED 55,000. This perimeter is set in Article 3(3) of Cabinet Resolution No. 134 of 2025 concerning the Executive Regulations of Federal Decree Law No. 10 of 2025.

The term covers gold retailers, jewellers, refineries, bullion wholesalers, diamond and coloured-stone traders, pearl traders and recycling operations within the Ministry of Economy and Tourism’s supervisory remit. The trigger is the AED 55,000 cash value; the rule applies equally to a single retail sale and to a string of related transactions that together cross the threshold. Transactions below AED 55,000 remain inside the AML system for record-keeping and suspicious transaction reporting, but they do not by themselves create DPMSR reporting exposure. The DPMSR reporting obligation and the applicability of the AML/CFT federal law are two different things. One should not confuse the applicability of the law with the DPMSR submission obligations.

Legal test

“Dealers in valuable metals and precious stones, when carrying out any single cash transaction or several transactions that appear to be linked and whose value equals or exceeds fifty-five thousand dirhams (AED 55,000).” — Article 3(3), Cabinet Resolution No. 134 of 2025.

Dealers established in the Abu Dhabi Global Market (ADGM) and the Dubai International Financial Centre (DIFC) are supervised by their own regulators (the ADGM RA and the DFSA, respectively) under rulebooks that mirror the federal AML/CFT regime; the substantive obligations and threshold logic track federal law, but the primary touchpoint is the financial free zone regulator rather than MoET.

AML Supervisory Authority for DPMS in the UAE

The Anti-Money Laundering Department within the Ministry of Economy and Tourism (MoET) is the federal supervisor for DPMS operating in the mainland and commercial free zones. This mandate is grounded in Cabinet decisions that assign DNFBP supervision to MoET and is reaffirmed in the DNFBP Guidelines issued by the Ministry in September 2025, which list DPMS among the four supervised categories alongside real estate agents and brokers, independent accountants and auditors, and trust and corporate service providers.

MoET enforces the AML/CFT obligations through on-site inspections, thematic reviews, administrative penalties imposed under Cabinet Resolution No. 71 of 2024, and circular-based guidance. It coordinates closely with the UAE Financial Intelligence Unit (UAEFIU), which operates the goAML reporting platform, and with the Executive Office for Control and Non-Proliferation (EOCN), which administers targeted financial sanctions. DPMS in ADGM and DIFC report to the ADGM RA and DFSA, respectively; DPMS in financial free zones follow the free zone’s AML framework, which cross-references to federal law.

1. Federal Supervisor

MoET is the primary AML/CFT supervisor for DPMS in mainland UAE and commercial free zones.

2. Financial Intelligence Unit

UAEFIU receives all Suspicious Transaction Reports, Confirmed Name Match Reports (CNMRs), PNMRs and DPMSRs through the goAML system.

3. Sanctions Authority

The Executive Office for Control and Non-Proliferation (EOCN) administers targeted financial sanctions and the Notification Alert System (NAS).

4. Financial Free Zone Regulators

ADGM RA and DIFC DFSA supervise DPMS authorised inside their respective jurisdictions under rulebooks aligned with federal AML law.

AML Regulations Applicable to DPMS in the UAE

The AML regulations for DPMS in UAE are organised in five concentric layers: the federal AML statute and its executive and penalty regulations; cross-sector overarching guidance from the National Committee, the EOCN, the UAEFIU and other federal bodies; the National Risk Assessment; DNFBP sector-specific guidance and circulars issued by MoET; and sector-specific DPMS guidance addressing gold sourcing, goAML reporting and precious-metals typologies. The subsections below walk through each layer and cite the applicable instruments.

The Five Regulatory Layers for DPMS

Three substantive sections walk you through perimeter, supervisor and the layered AML regulations for DPMS in UAE.

1. Federal AML Laws and Executive Regulations

2. Overarching AML Guidance

3. NRA, SRA, and Other Important Guidelines

4. DNFBP Sector-Specific Guidance

5. Sector-Specific DPMS Guidelines

Federal AML Laws and Executive Regulations Applicable to Dealers in Precious Metals and Stones

Federal primary and secondary legislation sets the baseline AML/CFT/CPF obligations that every DPMS must meet, regardless of whether it trades in gold bars, loose diamonds or polished jewellery. The federal layer is reinforced by two dedicated penalty resolutions and a beneficial-owner framework that every DPMS legal entity has to implement independently of its AML obligations.

Federal AML laws and executive regulations at a glance

Seven primary and secondary instruments that set the baseline AML/CFT/CPF obligations for every DPMS.

1. Federal Decree Law No. 10 of 2025

2. Federal Law No. 7 of 2014

3. Cabinet Resolution No. 134 of 2025

4. Cabinet Decision No. 74 of 2020

5. Cabinet Resolution No. 71 of 2024

6. Cabinet Decision No. 109 of 2023

7. Cabinet Resolution No. 132 of 2023

Federal Decree by Law No. (10) of 2025 Regarding Anti-Money Laundering, and Combating the Financing of Terrorism and Proliferation Financing

Federal Decree Law No. 10 of 2025 is the current primary AML/CFT/CPF statute in the UAE. It defines Designated Non-Financial Businesses and Professions as persons engaged in commercial or professional activities specified in the Executive Regulations, and makes those persons subject to the full suite of preventive obligations, including customer due diligence, record-keeping, suspicious transaction reporting, internal controls, training and cooperation with supervisory authorities.

Article 10 of the Decree Law (Chapter Four — Disclosure) confirms that every person entering or leaving the State must disclose the carriage of currencies, bearer negotiable instruments, precious metals or valuable stones in accordance with the disclosure system issued by the Federal Authority for Identity, Citizenship, Customs and Port Security in coordination with the Central Bank, which directly supports the precious-metals control environment within which DPMS operate.

The Decree Law establishes the UAEFIU, sets out criminal offences and sanctions, and empowers supervisory authorities to impose administrative penalties alongside judicial consequences. For the details of what each obligation means in practice, DPMS must read the Decree Law together with its Executive Regulations (Cabinet Resolution 134 of 2025) and the MoET DNFBP Guidelines.

Federal Law No. (7) of 2014 Combating Terrorism Crimes

Federal Law No. 7 of 2014 defines terrorism offences, terrorist organisations and the financing of terrorism. It is the criminal-law backbone behind the AML/CFT regime: when a DPMS identifies suspected terrorism-financing activity, the predicate offence is located in this Law and the related UNSC-implementing Cabinet Resolution 74 of 2020. Article 1 of Decree Law 10 of 2025 expressly refers to Federal Law 7 of 2014 in defining terrorist acts, thereby anchoring the AML statute within the criminal framework.

Cabinet Resolution No. (134) of 2025 Concerning the Executive Regulations of Federal Decree Law No. (10) of 2025

Cabinet Resolution 134 of 2025 is the executive regulation for Decree Law 10 of 2025 and contains the operational details that DPMS apply daily. Article 3(3) brings DPMS inside the perimeter at the AED 55,000 cash-transaction threshold. Article 7 sets out the triggers for customer due diligence, commencement of a business relationship, suspicion of a crime, doubts about previously obtained data, and occasional transactions at or above the thresholds. Article 8 requires ongoing monitoring, and subsequent articles set out enhanced due diligence, PEP handling, reliance on third parties, record-keeping and reporting obligations.

Where previous guidance, circulars or notifications refer to Federal Decree Law 20 of 2018 or Cabinet Resolution 10 of 2019, they continue to apply to the extent they are not repealed or inconsistent with Decree Law 10 of 2025 and Cabinet Resolution 134 of 2025. DPMS should therefore read every circular issued prior to 2025 through the lens of the new federal law.

Cabinet Decision No. 74 of 2020 Regarding Terrorism Lists Regulation and Implementation of UN Security Council Resolutions

Cabinet Decision No. 74 of 2020 regulates the UAE Local Terrorist List and the UAE’s implementation of United Nations Security Council resolutions on the suppression of terrorism, terrorism financing and the proliferation of weapons of mass destruction. It creates the legal basis on which DPMS must screen customers, beneficial owners and transaction counterparties against the UAE Local Terrorist List and the UN Consolidated List, apply freezing measures without delay, and report confirmed and partial name matches to the EOCN. The Cabinet Decision is enforced alongside circulars issued by MoET and EOCN that translate the obligations into reporting timelines.

Cabinet Resolution No. (71) of 2024 Regulating Violations and Administrative Penalties for DNFBPs Under the Ministry of Justice and the Ministry of Economy

Cabinet Resolution No. 71 of 2024 replaced Cabinet Resolution 16 of 2021 and sets out the unified list of AML/CFT violations and administrative fines for DNFBPs supervised by the Ministry of Economy (now MoET) and the Ministry of Justice (MoJ). Article 3 authorises the Ministry to impose one of the administrative penalties in Article 14 of the Decree Law, or the administrative fines in the annexed schedule, or both.

The annexed schedule covers more than forty categories of violations. Failure to adopt internal policies and controls is fined between AED 100,000 and AED 200,000. Failure to identify, assess and update crime risks is fined between AED 50,000 and AED 500,000. Failure to apply customer due diligence before or during a transaction at or above AED 55,000 is fined between AED 50,000 and AED 200,000. Failure to promptly file suspicious-transaction reports with the UAEFIU is fined between AED 100,000 and AED 500,000. Failure to implement UN Security Council sanctions decisions, directly relevant to DPMS given typology exposure, is fined between AED 100,000 and AED 1,000,000. Article 4 gives the violator thirty working days to grieve the penalty, and Article 5 permits the Ministry to amend, uphold or cancel the fine on review.

Cabinet Decision No. (109) of 2023 on Regulating the Beneficial Owner Procedures

Cabinet Decision No. 109 of 2023 regulates the identification, verification and continuous maintenance of the real (ultimate) beneficial owners of companies established in the UAE. A DPMS operating as a corporate licensee must maintain a register of beneficial owners, notify the licensing authority of changes within fifteen days and keep information current. Customer due diligence on corporate clients under Article 9 of the AML Executive Regulations draws on the same beneficial-owner concept, so the two frameworks operate in parallel: Decision 109 governs the DPMS’s own legal-person transparency, and the AML rules govern beneficial-owner identification of the DPMS’s customers.

Cabinet Resolution No. (132) of 2023 on Administrative Penalties for Beneficial Owner Violations

Cabinet Resolution No. 132 of 2023 sets out the administrative penalties for breaches of Cabinet Decision 109 of 2023. A DPMS that fails to disclose, update or maintain accurate beneficial-ownership data is exposed to written warnings to the legal person and financial penalties that escalate with repetition of the violation. Under Article 3(2) of Cabinet Resolution 132 of 2023, for violations committed for the third time, the Registrar has the right to suspend the commercial licence and close the commercial store of the violating legal person until the fine is paid and the breach is rectified. The penalty schedule is enforced by the Ministry of Economy and Tourism as the beneficial-owner registrar for most DPMS legal persons.

DPMS policy templates aligned to Decree Law 10/2025 and Cabinet 134/2025

AML UAE maintains up-to-date internal policies, customer due diligence procedures, DPMSR workflows and beneficial-owner registers engineered for the precious metals and stones sector.

Overarching AML Guidance Applicable to DPMS in the UAE

Alongside the federal statute, a catalogue of cross-sector guidance binds DPMS into the national AML/CFT/CPF architecture. These instruments explain how to implement targeted financial sanctions, counter proliferation finance, file reports on goAML and grieve sanctions-related decisions. Where a circular or guideline refers to the old Federal Decree Law 20 of 2018 and its executive regulation, it remains valid to the extent consistent with Decree Law 10 of 2025 and Cabinet Resolution 134 of 2025.

Thirteen cross-sector instruments from the EOCN, UAEFIU and National Committee that frame DPMS sanctions, CPF and reporting obligations.

1. EOCN TFS Guideline (Jan 2021, last amended Jul 2025)

2. UAEFIU TF Strategic Analysis (May 2025)

3. TFS Strategic Review (Nov 2021)

4. PF Institutional Risk Assessment Guidance (Dec 2023)

5. TF and PF Red Flags Guidance (updated Dec 2023)

6. Unlicensed VASP Joint Guidance (2022)

7. Counter Proliferation Financing Guidance (Nov 2022)

8. Satisfactory/Unsatisfactory Practice Joint Guidance (Jun 2021)

9. Sanctions Circumvention Typologies (Mar 2021)

10. EOCN Grievance Procedures Guideline

11. Online Grievance System User Guide

12. Combating PF and Sanctions Evasion

13. EOCN NAS Subscription Simple Guide

1. Guideline on Targeted Financial Sanctions for Financial Institutions, DNFBPs and VASPs — Executive Office for Control and Non-Proliferation (EOCN), issued January 2021, last amended July 2025

The EOCN TFS Guideline is the authoritative reference for how DPMS implement UN-led and UAE-local sanctions obligations. It explains the scope of TFS measures, the concept of ‘funds or other assets’, the screening expectations on customers, beneficial owners and counterparties, and the freezing obligation that must be executed without delay. The Guideline also sets the five-business-day reporting window for Confirmed Name Match Reports (CNMRs) and Partial Name Match Reports (PNMRs) on goAML, and DPMS rely on it to calibrate screening frequency, to interpret partial-match handling and to build CNMR and PNMR workflows.

2. UAEFIU’s Strategic Analysis Report on Terrorist Financing Typologies and Facilitators — May 2025

This UAEFIU strategic analysis sets out the dominant terrorist-financing typologies observed in the UAE and the facilitators most frequently exploited. For DPMS, the relevance lies in the report’s analysis of how precious metals and cash movements intersect with TF networks, and in the red-flag indicators that should feed into the DPMS’s transaction-monitoring rules and staff training.

3. Strategic Review on Targeted Financial Sanctions Case Studies 2019-2021 (IEC-SR.01.22) — Executive Office, November 2021

The Strategic Review compiles sanitised case studies from 2019 to 2021 where UAE private-sector obligations to apply TFS were tested. DPMS use these case studies to benchmark their own sanctions screening, to understand which typologies should trigger enhanced due diligence and to test the strength of their freezing and reporting playbooks.

4. Proliferation Finance Institutional Risk Assessment Guidance for FIs, DNFBPs and VASPs — December 2023

This Guidance explains how an institutional proliferation-finance risk assessment should be structured. DPMS, because of their exposure to dual-use goods pathways and to jurisdictions subject to UNSC proliferation-related sanctions, must run a specific proliferation-finance assessment as part of their wider business-wide risk assessment, separate from the ML and TF analyses.

5. Terrorist and Proliferation Financing Red Flags Guidance — December 2023

This cross-sector red-flag bulletin lists concrete indicators that front-line DPMS staff should watch for in transactions involving gold, bullion, high-value stones and jewellery. Where one or more red flags are present, the DPMS must escalate and, if suspicion persists, file an STR with the UAEFIU without delay.

6. Joint Guidance on Combating the Use of Unlicensed Virtual Asset Service Providers in the UAE — Central Bank, SCA, VARA, DFSA, FSRA and Ministries of Justice and Economy (2022)

DPMS frequently encounter customers who wish to settle precious metals purchases through virtual assets. This Joint Guidance from the Central Bank, CMA, VARA and ADGM/DIFC regulators sets out the obligations to deal only with licensed VASPs, and the red flags that indicate a counterparty is operating without a UAE VASP licence. DPMS integrating virtual-asset settlement must apply these expectations alongside their own AML controls.

7. Guidance on Counter Proliferation Financing for FIs, DNFBPs and VASPs — November 2022

This is the authoritative cross-sector CPF guidance. It explains the definition of proliferation financing in UAE law, the institutional risk assessment framework, the specific red flags linked to dual-use goods and the interaction with UNSC resolutions 1718 (DPRK) and 1737/2231 (Iran). DPMS sourcing or selling bullion and stones in trade-finance-heavy structures use this Guidance to build their CPF controls.

8. Joint Guidance on Satisfactory and Unsatisfactory Practice — June 2021

This joint supervisors’ Guidance contrasts observed satisfactory practice against unsatisfactory practice across governance, risk assessment, CDD, record-keeping and reporting. It is the single most practical benchmarking document for DPMS that want to self-assess the maturity of their AML programme before an inspection.

9. Typologies on the Circumvention of Targeted Sanctions — March 2021

This typology paper walks through common techniques used to circumvent sanctions, including the use of front companies, intermediaries in jurisdictions with lighter controls, and trade-based disguise of value. DPMS face each of these typologies in their own market; the paper informs its enhanced due diligence expectations for trades involving high-risk jurisdictions.

10. Guideline on Grievance Procedures

This EOCN Guideline explains how a DPMS, a customer or a designated person requests de-listing, removal of a freezing measure or permission to use frozen funds. It sets out the information to include, the review process and the timelines. DPMS need it when handling a CNMR or PNMR that is subsequently contested.

11. Online Grievance System User Guide

The Online Grievance System is the digital channel for submitting grievances to the EOCN. The User Guide walks through account creation, grievance submission, document uploads and status checks. DPMS with dedicated compliance functions should register up-front so they are not delayed if a grievance becomes necessary.

12. Combating Proliferation Financing and Sanctions Evasion

This EOCN awareness document synthesises the CPF and sanctions-evasion obligations into a practitioner-oriented narrative. DPMS training curricula should map each module of this document to one or more of their internal controls, so staff can explain the underlying risk in the context of real-world gold and stone transactions.

13. Simple Guide to Subscribe to the EOCN Notification Alert System (NAS)

The NAS is the EOCN’s subscription channel for updates to the UAE Local Terrorist List, the UN Consolidated List and related designations. The Simple Guide explains the step-by-step subscription process. DPMS compliance officers must subscribe to the NAS so that screening lists are refreshed as soon as designations change.

NRA, SRA, and Other Important Guidelines Applicable to DPMS in the UAE

The UAE’s risk-based approach begins with the National Risk Assessment. For DPMS, the NRA sets the baseline expectation on how seriously to treat sector-inherent risks.

UAE ML/TF National Risk Assessment — 2024

The UAE Money Laundering and Terrorist Financing Risk Assessment 2024 rates the inherent risk of the DPMS sector at medium-to-high, highlighting the combination of trade scale, cash intensity, international exposure and the persistent risk of conflict-affected or high-risk gold entering the supply chain. The NRA instructs DPMS to use these findings as a floor for their own business-wide risk assessment, and to apply enhanced due diligence where sectoral risk factors are present. The Practical Guide for DNFBPs, published alongside the NRA, translates the findings into operational actions for DPMS compliance officers.

Align your business-wide risk assessment with the UAE NRA 2024

AML UAE runs NRA-aligned business-wide risk assessments for DPMS, covering customer, geography, product, channel and delivery dimensions.

DNFBP Sector-Specific Guidance Applicable to DPMS in the UAE

MoET issues dedicated circulars and guidance for all DNFBPs under its supervision. These instruments are the everyday operating manual for DPMS compliance officers and are usually addressed to real estate brokers and agents, DPMS, auditors and accountants, and corporate service providers in parallel.

DNFBP sector-specific guidance at a glance

Ten MoET circulars and implementation guides that govern DPMS screening, CDD, risk-based approach and sanctions obligations

1. Circular No. 1 of 2026 — High-Risk Country Lists

2. AML/CFT DNFBP Guidelines (Sep 2025)

3. Circular No. 3 of 2025 — Sanctions and Terrorist List Screening

4. Circular No. 4 of 2025 — Understanding the NRA 2024

5. Circular No. 6 of 2025 — Risk-Based CDD

6. Circular No. 7 of 2025 — Re-Imposition of UN Sanctions on Iran

7. Circular No. 8 of 2025 — High-Risk Country Update

8. CRA Implementation Guide (Nov 2024)

9. CDD Implementation Guide (Nov 2024)

10. Circular No. 2 of 2022 — UNSCRs 1718 and 2231

1. Circular No. (1) of 2026 on Updating the Lists of High-Risk Countries, Countries Subject to Increased Monitoring, and Related Measures

Issued on 11 March 2026 as MOET/AML/001/2026, this Circular transposes National Committee Resolution No. 15 of 2025 into DNFBP practice. It reminds DPMS that the Resolution reaffirms existing obligations, updates country listings, and requires alignment of screening, enhanced due diligence and risk-based measures with the revised lists. The Circular cites Federal Decree Law 10 of 2025, Cabinet Resolution 134 of 2025 and Cabinet Decision 74 of 2020 as its legal basis.

2. AML/CFT Guidelines for Designated Non-Financial Businesses and Professions — September 2025

The Revised DNFBP Guidelines are the consolidated MoET rulebook for DNFBPs. Part I sets out the legal framework; Part II covers compliance administration; Part III sets out the identification and assessment of ML/TF/PF risks; Parts IV and V address mitigation controls, customer due diligence, reporting and record-keeping. The Guidelines name DPMS among the four supervised categories and incorporate the CNMR (Confirmed Name Match Report), PNMR, and DPMSR reporting typologies into the compliance officer’s remit.

3. Circular No. (3) of 2025 on Emphasising the Importance of Screening Sanctions and Terrorist Lists

Issued on 19 March 2025 as MOEC/AML/003/2025, this Circular is the clearest recent statement that DPMS must screen every customer, beneficial owner and transaction counterparty against sanctions and terrorist lists, irrespective of transaction value, payment method or whether the transaction crosses the AED 55,000 reporting threshold. Screening is not optional below the threshold; only the DPMSR reporting trigger is threshold-based.

4. Circular No. (4) of 2025 on the Importance of Understanding the UAE 2024 National Risk Assessment

This Circular directs DPMS to read the National Risk Assessment 2024 and to map its findings into their own business-wide risk assessment, customer risk matrix and transaction-monitoring rules. Where the NRA identifies a sectoral threat or typology, conflict-affected gold, trade-based money laundering, or shell companies, the DPMS is expected to demonstrate that the threat has been analysed and that mitigating controls are in place.

5. Circular No. (6) of 2025 on Emphasising the Implementation of Risk-Based Customer Due Diligence Measures

Issued on 5 August 2025 as MOET/AML/6/2025, this Circular reinforces the risk-based approach and clarifies the appropriate use of simplified due diligence (SDD). DPMS must apply enhanced due diligence to high-risk customers, standard CDD to medium-risk customers where no suspicion exists, and may apply SDD only to low-risk customers where no suspicion of ML, TF or PF exists. The Circular cross-references to the Customer Risk Assessment and CDD implementation guides issued by the Ministry.

6. Circular No. (7) of 2025 Regarding the Re-Imposition of United Nations Sanctions Related to Iran

Issued on 19 December 2025 as MOET/AML/007/2025, this Circular flags the re-imposition of UN sanctions under Security Council Resolution 1737 (2006) and subsequent resolutions. DPMS must update screening systems to the latest UN Consolidated List, re-screen existing customers and counterparties, apply freezing measures without delay, and report confirmed name matches (CNMR) and partial name matches (PNMR) to the EOCN via goAML in accordance with the procedures in the EOCN TFS Guideline (which sets a five-business-day reporting window from the freeze or suspension measure).

7. Circular No. (8) of 2025 on Updating the Lists of High-Risk Countries, Countries Subject to Increased Monitoring, and Related Measures

Issued on 25 December 2025 as MOET/AML/008/2025, this Circular (later superseded by Circular 1 of 2026) updates the high-risk country lists in line with National Committee Resolution 15 of 2025 and the FATF country review. DPMS must monitor the FATF lists, align customer risk categorisation and transaction monitoring, and apply the measures required by the Ministry when a customer, beneficial owner or counterparty is connected to a listed jurisdiction.

8. Implementation Guide for DNFBPs on Customer Risk Assessment (CRA) — November 2024

The CRA Implementation Guide walks DPMS through the construction of a customer risk matrix, identifying customer, product, service, geography, channel and delivery risk factors; weighting them; and assigning a final risk rating that drives the intensity of CDD, monitoring and review frequency. DPMS use the guide to design their client-onboarding questionnaires and periodic-review templates.

9. Implementation Guide for DNFBPs on Customer Due Diligence (CDD) — November 2024

The CDD Implementation Guide is the operational companion to the CRA guide. It explains how to identify and verify customers and beneficial owners, when to apply simplified, standard or enhanced due diligence, how to approach politically exposed persons, and how to document decisions. DPMS staff handling threshold transactions reference this Guide when collecting identification under MoE Circular 08/AML/2021.

10. Circular No. (2) of 2022 on Implementation of Targeted Financial Sanctions under UNSCRs 1718 (2006) and 2231 (2015)

Issued on 31 March 2022, this Circular covers the implementation of TFS related to the Democratic People’s Republic of Korea (DPRK) and Iran. It requires DPMS to screen every transaction party against the DPRK and Iran sanctions regimes, to apply enhanced due diligence to transactions linked to those jurisdictions, to verify cross-border transactions suspected of involving dual-use goods, and to file confirmed and partial name matches via goAML. The Circular has been superseded in part by later EOCN guidance, but its operational obligations continue to apply.

Build DPMS-ready screening and goAML reporting workflows

AML UAE designs sanctions-screening, PEP-screening and goAML-filing workflows engineered to the MoET circular stack and the CNMR/PNMR reporting timelines.

Sector-Specific Guidelines Applicable to DPMS in the UAE

A final layer of guidance targets DPMS directly. These documents address gold sourcing, DPMSR reporting, compliance officer appointment and DPMS typologies. They sit on top of the federal and DNFBP layers and are the instruments regulators cite most often in DPMS inspections.

DPMS sector-specific guidelines at a glance

Eight directly applicable instruments covering gold sourcing, DPMSR reporting, compliance-officer appointment and precious-metals typologies.

1. UAEFIU Strategic Analysis Report on DPMS (Sep 2025)

2. Ministerial Decree No. 68 of 2024 — Gold Refineries

3. MoE Circular No. 2 of 2024 — Responsible Sourcing of Gold

4. Due Diligence Regulation for Responsible Sourcing of Gold

5. MoE Circular No. 2 of 2023 — DPMS Data Disclosure Notice

6. MoE Circular No. 08/AML/2021 — DPMSR Reporting

7. MoET Circular No. 2 of 2021 — DNFBP Obligations

8. Supplemental Guidance for DPMS (May 2019)

1. UAEFIU’s Strategic Analysis Report on Misuse of Precious Metals and Stones in Financial Crime — September 2025

This is the most recent UAEFIU strategic analysis covering the DPMS sector. It notes that UAE foreign trade in precious stones, metals and their articles grew from AED 497 billion in 2021 to more than AED 959 billion in 2024, and that 8,191 DPMS were registered on goAML as of 30 June 2025, an 81 per cent increase over June 2022. The report analyses 1,448,825 DPMSRs filed between July 2021 and June 2025, as well as around 700 STRs and SARs related to the sector. It identifies five dominant typologies: conflict-affected and high-risk gold; gold smuggling; use of front and shell entities; trade-based money laundering; and the use of precious metals and stones in terrorist financing. It concludes with thirty-two DPMS-specific red-flag indicators covering customer due diligence, trade activities and behavioural triggers.

2. Ministerial Decree No. (68) of 2024 Regarding Gold Refineries’ Adherence to the Policy of Due Diligence Regulations for Responsible Sourcing of Gold

Ministerial Decree 68 of 2024 was issued on 29 March 2024 by the Minister of Economy. Article One requires every entity engaged in refining gold or recycling its products, and every supply-chain stakeholder operating in the UAE (including commercial free zones under MoE supervision), to adhere to the attached Due Diligence Policy for Responsible Sourcing of Gold. Supply-chain participants and precious-metals dealers must establish strong management systems, assess gold-supply-chain risks and implement a management strategy to respond to identified risks. Refineries (and recyclers) must additionally appoint an independent third-party auditor and submit a due diligence report on the gold supply chain. Article Three confirms that administrative penalties apply to violations of the Decree and the attached Policy.

3. Circular No. (2) of 2024 regarding Due Diligence Regulation for Responsible Sourcing of Gold

MoE Circular No. 2 of 2024, dated 29 March 2024, directs every regulated entity with gold refineries as an activity in its licence operating in the UAE to undertake the 5-step framework of the Due Diligence Regulation for Responsible Sourcing of Gold. The Circular confirms that from 1 January 2023, gold refineries must conduct an independent third-party audit of their due diligence measures, with audits expected to be completed within 90 days of the effective date (that is, 90 days from 31 December 2023). The Ministry has a dedicated inbox at ResponsibleSourcing@economy.ae. Entities that fail to comply are subject to administrative actions under the AML/CFT framework.

4. The Due Diligence Regulation for Responsible Sourcing of Gold

The Due Diligence Regulation for Responsible Sourcing of Gold is the policy instrument annexed to the Ministerial Decree and referenced in Circular 2 of 2024. It is built around five steps: (1) establishing an effective governance framework, including a board-approved sourcing policy, management structures and a confidential grievance mechanism; (2) identification and assessment of supply-chain risk, including the use of red flags and enhanced due diligence for conflict-affected and high-risk areas (CAHRAs); (3) management of supply-chain risk through a risk-control plan, continuous monitoring and senior-management reporting; (4) an independent third-party audit of the due-diligence measures; and (5) annual reporting on management systems, risk assessment and risk management. The Regulation is the detailed implementation manual behind Ministerial Decree 68 of 2024.

5. Circular No. (2) of 2023 — Data Disclosure Notice for Dealers in Precious Metals and Stones

MoE Circular No. (2) of 2023 instructed DPMS to display prominently in customer-facing premises a notice informing customers that the dealer will collect identification documents, and they should disclose their data.  

6. Ministry of Economy Circular No. (08/AML/2021) on the Dealers in Precious Metals and Stones Report

MoE Circular 08/AML/2021, dated 2 June 2021, is the DPMSR reporting foundation. Effective 12 June 2021, it requires DPMS to: (1) obtain Emirates ID or passport for resident individuals and ID or passport for non-resident individuals on any cash transaction at or above AED 55,000, and register the information in the UAEFIU’s goAML platform using the DPMSR form; (2) obtain trade licence and ID for corporate counterparties on transactions at or above AED 55,000 in cash or by wire transfer, and register the information in goAML as a DPMSR; and (3) keep records of every document and piece of information relating to the above transactions for a minimum of five years. The Circular refers queries to AML@economy.ae and continues in force under the new federal law.

7. MoET Circular No. (2) of 2021 on AML/CFT Obligations for DNFBPs

MoE Circular 2 of 2021, dated 4 February 2021, is the baseline DNFBP implementation circular. It confirms that MoE supervises real estate brokers and agents, dealers in precious metals and stones, account auditors and company services providers. It requires each supervised entity to appoint a compliance officer in accordance with Article 21 of the Executive Regulations, adopt internal policies, deliver staff training, register on goAML and cooperate with supervisory inspections. DPMS compliance officers cite this Circular when explaining the governance perimeter of their role.

8. Supplemental Guidance for Dealers in Precious Metals and Stones — May 2019

The 2019 Supplemental Guidance is the most detailed sector-specific narrative issued for DPMS. It explains why precious metals and stones are inherently vulnerable to ML/TF: high intrinsic value in a compact form, ability to maintain or increase in value, ease of physical transport, cash-based and decentralised markets, difficulty in tracing specific items and low compliance-awareness among smaller participants. It walks through the AED 55,000 ‘covered transactions’ concept, introduces sector-specific red flags and sets out expectations for customer due diligence, record-keeping and reporting. It continues to serve as a training reference for DPMS compliance teams.

Conclusion

The AML regulations for DPMS in UAE are dense but internally coherent. Federal Decree Law 10 of 2025 and Cabinet Resolution 134 of 2025 set the primary obligations; Cabinet Resolutions 71 of 2024, 109 of 2023 and 132 of 2023 govern penalties and beneficial ownership; a stack of EOCN and UAEFIU guidance operationalises targeted financial sanctions, proliferation-finance controls and reporting; the 2024 NRA sets the risk baseline; and a layer of MoET DNFBP and DPMS-specific circulars translates the regime into daily practice. On top of that, Ministerial Decree 68 of 2024 and Circular 2 of 2024 impose a 5-step responsible sourcing overlay on gold refiners and supply-chain participants.

A DPMS that wants to remain compliant must: submit DPMSR wherever applicable; screen every customer, beneficial owner and counterparty against the local terrorist list and the UN Consolidated List, regardless of transaction size; run a proliferation-finance assessment alongside the ML and TF assessments; integrate the five-step gold sourcing framework where applicable; and make sure that every circular, whether issued under the old Decree Law 20 of 2018 or the new Decree Law 10 of 2025, is understood through the lens of the current federal law.

Talk to AML UAE about your DPMS compliance programme

We design, test and audit AML programmes for gold retailers, refineries, jewellers and diamond traders across the UAE. From business-wide risk assessment to goAML DPMSR workflows and health check, we have you covered.

FAQs

Who counts as a DPMS under UAE AML law?

Under Article 3(3) of Cabinet Resolution 134 of 2025, a dealer in precious metals and stones is any person, natural or legal, trading in precious metals or precious stones in the course of business who carries out a single cash transaction, or several linked cash transactions, equal to or above AED 55,000. The definition covers gold retailers, jewellers, refineries, bullion wholesalers, diamond and coloured-stone traders and recyclers. Below AED 55,000, AML obligations still apply for screening, record-keeping and suspicion-based reporting, but no DPMSR is triggered.

MoE Circular 08/AML/2021 requires DPMS to file a Dealers in Precious Metals and Stones Report (DPMSR) on the UAEFIU’s goAML platform for every cash transaction at or above AED 55,000 with a resident or non-resident individual, and for every transaction at or above AED 55,000 with a legal entity, whether paid in cash or by wire transfer. Separately, any suspicion of ML, TF or proliferation financing, regardless of amount, must be filed as a Suspicious Transaction Report via goAML, and confirmed and partial name matches against sanctions lists must be filed as CNMR or PNMR within five business days of the freeze or suspension.

Yes. Under Ministerial Decree 68 of 2024 and MoET Circular 2 of 2024, entities that engage in refining or recycling gold must adhere to the 5-step Due Diligence Regulations for Responsible Sourcing of Gold and, additionally, appoint an independent third-party auditor and submit an annual due diligence report on the gold supply chain. The audit obligation has applied since 1 January 2023. Refineries remain subject to all the generic DPMS obligations under Decree Law 10 of 2025 and Cabinet Resolution 134 of 2025 in parallel.

The UAEFIU Strategic Analysis Report on DPMS (September 2025) lists thirty-two sector-specific indicators. The most common include: refusal to provide identification; inability to demonstrate funding sources; forged certificates of origin, refinery stamps or fake invoices; supply chains transiting conflict-affected or high-risk jurisdictions; large or frequent cash transactions inconsistent with the customer’s profile; structuring through multiple visits or split invoices just below AED 55,000; payments via multiple third parties or offshore entities without clear commercial link; and repeated requests for duplicate invoices or refunds after cash purchases.

DPMS established in ADGM and DIFC are supervised by the AFDGM Registration Authority (RA) and the Dubai Financial Services Authority (DFSA), respectively. Their rulebooks implement UAE federal AML/CFT law and the UAE’s international AML/CFT commitments, so the substantive obligations and the AED 55,000 threshold logic track federal law. The procedural touchpoints licensing, inspections, filings and enforcement are, however, with the financial free-zone regulator rather than MoET. DPMS in commercial free zones outside ADGM and DIFC remain under MoET supervision.

Was this guide useful?

If this DPMS guide helped your compliance team, a short Google review genuinely helps other jewellers, refineries and dealers find the same answers quickly.

Share via :

About the Author

Pathik Shah

FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)

Pathik is an ACAMS-certified AML consultant specialising in governance, risk, and compliance for regulated entities in the UAE. He brings over 28 years of experience, with 1,000+ hours of AML training and 200+ advisory engagements across DNFBPs, VASPs, and FIs. He supports businesses in aligning with AML/CFT requirements from the CBUAE, DFSA, MoET, MoJ, VARA, CMA, FSRA, and FATF. Known for translating complex regulations into audit-ready procedures, Pathik enables operational clarity and compliance readiness.

Reach Out to Pathik