AML Regulations for Insurance Companies and Brokers in UAE

AML Regulations for Insurance Companies and Brokers in UAE

Blogs

Published On: 07/09/2026

Table of Contents

Protect your business with reliable and effective AML strategies with AML UAE.

Last Reviewed On: 07/09/2026   |   Last Updated On: 07/09/2026

Key Highlights

  • Insurance firms carrying on life and investment-linked business are financial institutions under Federal Decree-Law No. 10 of 2025 and its Executive Regulations in Cabinet Resolution No. 134 of 2025.
  • The Central Bank of the UAE supervises the mainland insurance sector, while the DFSA and FSRA supervise insurers and intermediaries in the DIFC and ADGM.
  • The sector’s residual money laundering and terrorist financing risk is rated medium in the national risk assessment, and maritime insurance carries a medium proliferation financing risk on the mainland.
  • Insurers, reinsurers, brokers, and agents carrying on in-scope insurance business must apply customer due diligence, sanctions screening, transaction monitoring, record keeping, and suspicious transaction reporting through goAML, proportionate to their role, products and risk.
  • On top of the federal laws, the Central Bank issues both general guidance for all licensed financial institutions and guidance specific to the insurance sector, including a dedicated insurance broker regulation.
  • This article catalogues the whole framework and links up to the banks and financial institutions pillar for the wider view.

Insurance is not the first sector people associate with money laundering, but life and investment-linked policies can be used to place, layer, and integrate illicit funds, and that is why the UAE brings insurers and brokers inside its anti-money laundering regime. This guide sets out the AML regulations for insurance companies in the UAE, covering insurers, agents and brokers: who is in scope, who supervises the sector, the full legal framework that applies, and how the national risk assessments rate the sector’s money laundering, terrorist financing, and proliferation financing risk. It is CBUAE-centric, since the Central Bank supervises mainland insurance, with the DIFC and ADGM regulators noted for firms in the financial free zones.

In short: UAE insurers, reinsurers, brokers and agents carrying on life, investment-linked or other relevant insurance business must comply with Federal Decree-Law No. 10 of 2025, its Executive Regulations in Cabinet Resolution No. 134 of 2025, the sanctions rules in Cabinet Resolution No. 74 of 2020, the CBUAE’s insurance-sector and licensed-institution guidance, and the UAE FIU’s goAML reporting duties. The clearest money laundering risks are single-premium policies, third-party premium payments, top-ups, early surrender, beneficiary changes, opaque corporate policyholders and sanctions exposure in marine or cargo cover.

Who counts as operating in the Insurance Sector for AML purposes in UAE?

AML obligations in the UAE insurance sector attach most clearly to the firms and people that write or arrange life and investment-linked business, the lines through which value can be stored, moved or returned, with further exposure in assignable, high-value, marine, cargo and cross-border insurance activity. General insurance and pure protection products usually present lower money laundering and terrorist financing risk, but CBUAE-licensed insurers, reinsurers, agents and brokers should still assess their own obligations against their licence, the applicable CBUAE guidance and the risk profile of their products, customers and claims activity.

Insurance companies

Insurers carrying on life insurance and investment-linked business are financial institutions for AML purposes. These products can hold and transfer value, can, in higher-risk cases, be funded in cash or cash-like means, and can be surrendered or assigned, which is what gives them money laundering relevance. Such insurers must run a full AML programme scaled to their products and customers.

In short, for life and investment-linked insurance, AML risk is highest where policies store value, accept top-ups, permit early surrender, allow assignment, or involve third-party premium funding.

Insurance brokers

Brokers arrange cover between clients and insurers and often handle client information and premium flows, which places them inside the AML perimeter for relevant business. The Central Bank maintains a dedicated regulation for insurance brokers, and brokers must apply customer due diligence, screening, and reporting appropriate to their role.

Insurance agents and intermediaries

Agents and other intermediaries who introduce or service relevant insurance business are also captured where they carry on activities that fall within the financial institution definition. Their obligations follow the nature of the business they handle and the customers they deal with.

AML Supervisory Authority for the Insurance Sector in UAE

Supervision of the insurance sector is shared between the federal regulator and the two financial free zone authorities. Your supervisor determines which rulebook and guidance apply to you.

Central Bank of the UAE (CBUAE)

The Central Bank is the AML supervisor for the mainland insurance sector, having taken on insurance supervision in addition to banking. It issues both general guidance for licensed financial institutions and guidance specific to insurance, inspects firms, and can impose administrative and financial penalties for breaches.

Dubai Financial Services Authority (DFSA)

The DFSA supervises insurers and insurance intermediaries established in the Dubai International Financial Centre, under its own AML rulebook that sits alongside the federal law.

Financial Services Regulatory Authority (FSRA)

The FSRA supervises insurance firms in the Abu Dhabi Global Market, maintaining its own AML rulebook and enforcement within the wider federal framework.

UAE FIU and goAML

In-scope insurers, reinsurers, brokers and agents register on the UAE Financial Intelligence Unit’s goAML platform and report through it. Registration on goAML is a baseline obligation, and suspicious transaction and activity reports, along with related filings, are submitted through it. See our goAML registration guide for the practical steps.

AML Legal Framework Applicable to Insurance Companies in UAE

The framework has five layers: the core federal laws, the guidance that applies to all reporting entities, the national risk assessments, the Central Bank’s general guidance for licensed financial institutions, and the Central Bank’s insurance sector-specific guidance. This section catalogues each layer, grounded in the Insurance CBUAE library.

At a glance, the instruments that make up this framework sit in the following hierarchy: 

Layer Instrument Why it matters 
AML statute Federal Decree-Law No. 10 of 2025 Core AML, CFT and CPF offences, the Financial Intelligence Unit, reporting duties and penalties 
Executive regulation Cabinet Resolution No. 134 of 2025 Working duties: risk-based approach, CDD, EDD, beneficial owner, monitoring, STRs and record keeping 
Central Bank law Federal Decree by Law No. 6 of 2025 The Central Bank, licensed financial institutions and insurance business framework 
Sanctions and TFS Cabinet Resolution No. 74 of 2020, with EOCN and CBUAE guidance Screening, freezing without delay, name-match reporting and sanctions duties 
Insurance conduct CBUAE Insurance Brokers’ Regulation and insurance-sector rules Licensing, conduct, governance and broker obligations 
CBUAE guidance Insurance-sector guidance and the CDD, monitoring, TFS, PEP, PF and TBML guidance Supervisory expectations for insurers and intermediaries 
National risk UAE ML and TF NRA 2024 and UAE PF NRA 2026 Baseline for the insurance sector’s risk assessment 

Federal AML Laws and Executive Regulations Applicable to Insurance Companies and Brokers in the UAE

These instruments are the legal foundation for every insurer and broker in scope.

Federal Decree-Law No. 10 of 2025 on AML, CFT and CPF

For an insurer writing life or investment-linked cover, or a broker placing it, Federal Decree-Law No. 10 of 2025 is the statute everything else answers to. It is the principal UAE law on money laundering, terrorist financing and proliferation financing, fixing the definitions that frame your obligations, including predicate offences, targeted financial sanctions and suspicious transactions, and recognising that abuse may run through virtual assets and cryptographic technology. It establishes the Financial Intelligence Unit within the Central Bank as the central agency that receives and analyses suspicious transaction reports, whether the trigger is an odd single-premium payment or an early surrender, and through the Head of the Unit, it may request further information and order the suspension or freezing of suspicious funds within the limits and procedures set by the law and the FIU regulation. It also places insurers under supervisory oversight and exposes them to administrative penalties.

Cabinet Resolution No. 134 of 2025, the Executive Regulations

Cabinet Resolution No. 134 of 2025 issues the Executive Regulations of Decree-Law No. 10 of 2025 and is the working rulebook that a compliance team actually opens. It expressly brings life insurance and other investment-related insurance products within scope, including cover distributed through agents and brokers, and adds concepts such as senior management, beneficial owner and reasonable measures. From these pages flow the daily duties: a risk-based approach, customer due diligence, verifying the beneficial owners behind corporate policyholders, and ongoing monitoring kept current across top-ups, assignments and changes of beneficiary. Insurers and brokers must maintain internal policies and controls approved by senior management and proportionate to their risks.

Cabinet Resolution No. 109 of 2023 on beneficial owner procedures

When a corporate policyholder sits behind a life or investment-linked contract, Cabinet Resolution No. 109 of 2023 shapes what an insurer or broker can learn about who really controls it. It regulates beneficial owner procedures for licensed or registered legal persons, defining the real beneficiary as the natural person who ultimately owns or controls the entity, directly or through a chain of ownership. Each legal person must keep accurate beneficial owner information, identify nominee board members, maintain a real beneficiary register and a shareholders register, and update them within short deadlines, generally fifteen days. These procedures apply to legal persons licensed or registered in the State, including commercial free zones, but exclude the financial free zones, the DIFC and ADGM, which operate their own beneficial ownership regimes.

Cabinet Resolution No. 132 of 2023 on penalties for beneficial owner violations

Cabinet Resolution No. 132 of 2023 puts teeth behind the beneficial ownership duties in Cabinet Resolution No. 109 of 2023 and explains why a corporate policyholder should keep its ownership data current. It empowers the registrar to fine legal persons that fail to maintain accurate registers or supply required data, following an annexed schedule of violations, without prejudice to other AML sanctions. Consequences escalate: on a third violation, the registrar may suspend the commercial licence and close the premises until the fine is paid. For an insurer or broker verifying the people behind a corporate contract, non-compliance carries a cost. These penalties apply to legal persons licensed or registered in the State, including commercial free zones, but not to the financial free zones, the DIFC and ADGM, which follow their own regime.

Cabinet Resolution No. 74 of 2020 on terrorist lists and UNSC resolutions

Sanctions screening for insurers and brokers begins with Cabinet Resolution No. 74 of 2020, which regulates the terrorist lists and gives effect in the UAE to United Nations Security Council resolutions on terrorism, its financing and the proliferation of weapons of mass destruction. It sets up a local Cabinet list alongside the Security Council lists, defines designation, listing and de-listing, and demands freezing measures without delay, within twenty-four hours. In practice an insurer or broker must register on the Executive Office website for notifications and continuously screen policyholders, prospective clients, beneficial owners of corporate policyholders and parties to transactions, whenever a list changes. On a match, freeze without notice and report promptly.

Federal Law No. 7 of 2014 on combating terrorism crimes

Federal Law No. 7 of 2014 on Combating Terrorism Crimes is the criminal statute that tells insurers and brokers what their controls are ultimately built to catch. It defines terrorist crime, terrorist purpose, terrorist organisation and terrorist person, distinguishes conventional from nonconventional weapons including toxins and radioactive materials, and prescribes penalties reaching life imprisonment and, in specified cases, death. It penalises anyone who provides, collects, prepares or maintains funds, or facilitates obtaining them, for a terrorist purpose, and addresses freezing suspect funds held within financial institutions. Because the AML framework defines terrorist acts partly by reference to this law, insurers use it to read the conduct behind a suspicious premium.

AML Guidance Applicable to All Reporting Entities

Beyond the core laws, the Central Bank, the FIU, and the Executive Office issue guidance and typologies that apply to all reporting entities. The instruments below sit in the overarching guidance set for licensed financial institutions.

UAE FIU Regulation No. 1 of 2026 on Suspension and Freezing Powers, April 2026

Dated April 2026, UAE FIU Regulation No. 1 of 2026 governs the postponement or suspension of suspicious transactions and the freezing of funds. Issued under the AML/CFT Decree-Law, it applies to reporting entities, including insurers as financial institutions, and complements existing reporting duties. It introduces the Postponement Suspicious Transaction Report, an urgent filing where funds suspected of crime face imminent transfer, withdrawal or dissipation, and sets a monetary threshold that does not apply to higher threat offences, third party laundering, organised crime or terrorist financing. It defines a Suspension Order of up to ten working days and a Freezing Order of up to thirty days, letting insurers hold at-risk payouts.

UAE FIU Strategic Analysis Report on Human Trafficking, April 2026

Dated April 2026, the UAE FIU Strategic Analysis Report on Human Trafficking analyses money laundering and financial flows tied to trafficking, drawing on suspicious transaction and activity reports filed with the Financial Intelligence Unit. It sets out objectives, methodology and scope, and covers the main forms, including sexual exploitation, forced labour and organ removal. It profiles subjects such as designated traffickers, organised crime groups, foreign politically exposed persons and money mules, assesses vulnerable sectors, then develops indicators grouped around customer profile, behaviour, transactional activity and documentation. For insurers and brokers it is a detection resource, helping firms link trafficking methods to behaviour across policyholders and beneficiaries and improve their reports.

Guidance on Targeted Financial Sanctions for Financial Institutions, DNFBPs and VASPs, March 2026

First published in January 2021 and last amended in March 2026, the Guidance on Targeted Financial Sanctions for Financial Institutions, DNFBPs and VASPs is issued by the Executive Office for Control and Non-Proliferation. It sets out four core obligations: registering in the Notification Alert System, screening against the UAE Local Terrorist List and the United Nations Consolidated List, freezing assets without delay while not making them available to designated persons, and reporting measures taken. The March 2026 update renames the Funds Freeze Report as the Confirmed Name Match Report. For insurers and brokers, it defines how to screen policyholders, beneficiaries and owners, and freeze payouts where a designation matches.

Joint Guidance on the Compliance Officer and MLRO, 2026

Issued in 2026 by the UAE Supervisory Sub-Committee, this Joint Guidance establishes a unified framework for appointing, empowering and holding to account the Compliance Officer or Money Laundering Reporting Officer across regulated sectors. Building on Federal Decree-Law No. 10 of 2025, Cabinet Resolution No. 134 of 2025 and the 2025 legal framework, it treats the role as a cornerstone of an effective AML, CFT and counter-proliferation regime. It sets expectations on appointment and resignation, requiring seniority, experience, operational independence, freedom from conflicts, board access and adequate resources, and addresses the compliance function and outsourcing. For insurers and brokers, it clarifies appointing a fit and proper officer over underwriting and claims.

FIU Strategic Analysis Report on Terrorist Financing, May 2025

Produced by the UAE Financial Intelligence Unit and published in May 2025, this strategic analysis report, subtitled Terrorist Financing Typologies and Facilitators, draws on the Unit’s databases for 2021 to 2024, including suspicious transaction and activity reports. It explains how terrorist financing works and maps typologies for moving and obscuring funds through financial institutions, unlicensed hawala, corporate networks, high-value goods, real estate, virtual assets and crowdfunding. It also profiles facilitators such as money mules, corporate nominees and professional service providers. For insurers and brokers, the developed risk indicators sharpen scrutiny of premium sources, third-party payers, sudden surrenders and changes of beneficiary that could disguise the movement of terrorist funds.

goAML FAQs, April 2024

Version 2.1, dated 18 April 2024, the goAML FAQs is a practical question and answer guide published by the UAE Financial Intelligence Unit to help reporting entities use the goAML system and its registration and access services. It addresses common registration and login problems with step by step remedies, covering expired one-time passwords at first login, pop-up authentication screens needing the system-issued username with a Google Authenticator passcode, the correct login sequence through the services portal, and resetting a forgotten password. For insurers and brokers, timely suspicious transaction and activity reporting depends on reliable goAML access, so this guidance helps compliance teams stay connected and meet reporting duties promptly.

PF Institutional Risk Assessment Guidance for FIs, DNFBPs and VASPs, December 2023

Published in December 2023, the Proliferation Financing Institutional Risk Assessment Guidance shows firms how to assess and manage their exposure to proliferation financing. It sets out a methodology built on inherent risks, control effectiveness and residual risk, names the risk categories and factors to score, and describes supporting measures across onboarding, KYC and customer due diligence, enhanced due diligence, sanctions and adverse media screening, ongoing monitoring, suspicious activity reporting and employee training. A customer risk-scoring questionnaire, elevated risk factors and worked case studies illustrate the approach. For insurers and brokers, it offers a repeatable framework to score corporate policyholders and beneficial owners, calibrate controls and document decisions supervisors can review.

Terrorist and Proliferation Financing Red Flags Guidance, December 2023

Updated in December 2023, the Terrorist and Proliferation Financing Red Flags Guidance gives insurers and brokers a consolidated set of indicators for spotting suspicious terrorist and proliferation financing, including evasion of targeted financial sanctions under United Nations Security Council Resolutions or local designations. It explains how sanctioned parties rename themselves and hide behind intermediaries and front companies, then presents terrorist financing red flags followed by proliferation indicators grouped by customer profile, account and transaction activity, maritime sector and trade finance. For life and investment-linked writers and for marine and cargo underwriters, this is a working reference that sharpens detection of evasion and clarifies when a suspicious report should be filed.

Suspicious Activity and Transaction Reporting Thematic Review, January 2023

Issued in January 2023, the Suspicious Activity and Transaction Reporting Thematic Review sets out findings and regulatory expectations from the 2022 AML and CFT examination of licensed financial institutions and designated non-financial businesses and professions. It focuses on the suspicious transaction and activity reporting framework and the transaction monitoring systems feeding it, organised around expectations and acceptable versus deficient practice across governance, policies, risk-based deployment of monitoring, data management, alert review, case investigation, reporting decisions and the post-reporting process. It applies expressly to insurers among other firms. For insurers and brokers, it is a practical benchmark to test monitoring of premiums, surrenders and claims before an inspection finds gaps.

Counter Proliferation Financing Guideline, November 2022

Published in November 2022 by the Executive Office for Control and Non-Proliferation, this guideline supplements the wider Guidance on Targeted Financial Sanctions and helps regulated firms identify, assess and mitigate proliferation financing risk in line with FATF standards. It explains what proliferation financing is, its stages and the UAE framework, then folds that risk into a firm’s own risk assessment. For insurers and brokers the document is directly relevant, because it names insurance products among the areas needing enhanced due diligence, alongside shell and front companies and dual-use goods. It matters especially to marine and cargo underwriters, supplying red flags that signal sanctions evasion tied to weapons of mass destruction.

goAML Web Submission Guide, July 2022

Issued by the UAE Financial Intelligence Unit in July 2022, the goAML Web Submission Guide sets out the steps for submitting a report to the FIU through the goAML platform. It is addressed to the designated Compliance Officer or Money Laundering Reporting Officer of a registered reporting entity, or the deputy when the lead officer is unavailable, guiding them through the submission process. It overviews report types, including the Suspicious Transaction Report and the Suspicious Activity Report, the latter covering suspected activity or an attempted, non-executed transaction, plus Additional Information File and Request for Information reports. For insurers and brokers, it standardises reporting, helping officers file correct reports promptly.

Joint Guidance on Combating the Use of Unlicensed Virtual Asset Providers, March 2022

Issued in March 2022 by the UAE Supervisory Authorities, including the Central Bank, the Securities and Commodities Authority and the Virtual Assets Regulatory Authority, this Joint Guidance aligns with FATF’s risk-based approach and warns the public and regulated firms about unlicensed virtual asset service providers. It urges confining virtual asset dealings to licensed entities and expects firms to stay vigilant to fraud, factor emerging risks into assessments, conduct due diligence, spot customers seeking unlicensed providers, and report suspicions. Red flags include no regulatory licence, no physical presence, unrealistic promises and pressure to invest quickly. For insurers and brokers, it helps flag policyholders whose premiums trace to unlicensed virtual asset activity.

IEMS User Guide for Reporting Entities, March 2022

Dated March 2022, the IEMS User Guide for Reporting Entities is a practical manual from the UAE Financial Intelligence Unit for its Integrated Enquiry Management System, which automates information requests, prosecution decisions and other AML and CFT instructions from domestic authorities. It covers registration and login, noting goAML-registered firms reuse those credentials, and walks through the dashboard, request management, and the reply workflow for account and signatory details. It sets out Admin, Maker and Checker roles, due dates, and implementing freeze orders immediately on the amount specified or the whole balance. For insurers and brokers, it shows how to action enquiries and freeze instructions touching policy accounts and payout balances.

goAML Pre-Registration Guide, March 2022

Issued by the UAE Financial Intelligence Unit in March 2022, the goAML Pre-Registration Guide explains how reporting entities gain access to the Services Access Control Manager, or SACM, before reaching the goAML application to register and file suspicious reports. The application is available through a public portal for entities not regulated by the Central Bank, except hawaladars, while entities under various Supervisory Bodies follow the set steps. It describes SACM as the gateway hosting links to the goAML production and testing environments, secured by a Google Authenticator one time password, and covers safeguarding a personal Secret Key that cannot be shared. For insurers and brokers, it precedes secure reporting access.

goAML Registration Guide, March 2022

Issued by the UAE Financial Intelligence Unit in March 2022, the goAML Registration Guide sets out the steps an organisation follows when registering with the FIU on its reporting platform, goAML. It covers registration as a reporting entity, stakeholder or supervisory body, and confirms that all accountable and reporting entities in the United Arab Emirates must register to submit suspicious reports; registration grants the right to file. It explains reaching the portal through the Services Access Control Manager, then covers selecting the registration type, entering organisation and address details, adding the registering person and passport data, uploading attachments and setting access rights. For insurers and brokers, it underpins compliant reporting.

Strategic Review on Targeted Financial Sanctions Case Studies, November 2021

Dated November 2021, the Strategic Review on Targeted Financial Sanctions Case Studies examines sanctions reporting in the United Arab Emirates, sitting within the framework by which the UAE, through Cabinet Resolution No. 74 of 2020, implements United Nations Security Council Resolutions on terrorism, terrorist financing and proliferation, including freezing measures and prohibitions on providing funds and services. It explains its methodology and timeline, then classifies reports by source, suspicion and instrument, drawing out terrorist financing and proliferation financing patterns with red flags, statistics and recommendations. For insurers and brokers, it shows how sanctions suspicions actually arise, helping sharpen screening of policies and payouts.

Typologies on the Circumvention of Targeted Sanctions, November 2021

Amended in November 2021 and issued by the Executive Office, this typologies report compiles cases showing how sanctioned persons, groups and entities try to circumvent targeted sanctions relating to terrorism and the proliferation of weapons of mass destruction. Drawing on public sources, it groups methods by channel: banking, money remitters, exchange houses, hawala, online payments, misuse of non-profit organisations, cash and gold smuggling, trade in dual-use goods and natural resources, legal-entity misuse and virtual assets, with named networks and red flags. For insurers and brokers, especially those underwriting corporate policyholders or marine and cargo risks, it turns evasion tactics into practical learning that strengthens screening, due diligence and monitoring.

Update to the List of High Risk Jurisdictions, November 2021

This November 2021 decision of the National Anti-Money Laundering and Combatting the Financing of Terrorism and Financing of Illegal Organizations Committee updates the list of high risk jurisdictions subject to a call for action, the list under increased monitoring and the counter-measures to apply, revising an earlier March 2021 decision. Addressed to bodies including the supervisory authorities and the Financial Intelligence Unit, it reflects the Committee’s mandate to identify higher-risk countries and set proportionate counter-measures. For insurers and brokers, country risk is a core input to risk-based controls: it signals which jurisdictions warrant enhanced due diligence on policyholders, beneficiaries and corporate owners, obliging firms to keep risk assessments current.

Joint Guidance on Satisfactory and Unsatisfactory Practice, June 2021

Published in June 2021 by the UAE Supervisory Authorities, including the Central Bank, the DFSA, the FSRA, the Securities and Commodities Authority and the Ministries of Justice and Economy, this Joint Guidance distils themes from inspections run between January 2020 and May 2021. It contrasts satisfactory and unsatisfactory practice across the AML framework, targeted financial sanctions and counter proliferation financing, covering governance, the three lines of defence, risk assessment, policies, training and the compliance officer role, plus onboarding, customer risk rating, due diligence, monitoring, screening and reporting. For insurers and brokers, it turns findings into benchmarks, helping firms test controls over policyholder onboarding and payout monitoring before an examiner does.

Typologies on the Circumvention of TFS, PF and WMD, May 2021

Amended in May 2021 and issued by the Executive Office, this typologies report examines how sanctioned persons, groups and entities receive financing in violation of or evasion of United Nations Security Council Resolutions on terrorism and the proliferation of weapons of mass destruction. It notes that targeted financial sanctions cover both asset freezing and bans on making funds available, directly or indirectly, to designated parties. Organised by financing method, it addresses misuse of banking, money remitters, hawala, online payments, non-profit organisations, cash smuggling, trade in goods and legal-entity misuse. For insurers and brokers, it explains how value moves past controls and reinforces the duty to report evasion.

goAML FAQs, September 2020

Issued by the UAE Financial Intelligence Unit in September 2020, the goAML FAQs Guide is a practical question-and-answer reference for reporting entities using goAML, the system through which suspicious reports are filed in the United Arab Emirates. It compiles queries commonly raised once an organisation is registered and active, with step-by-step responses. It explains how to reset a forgotten password, update organisation details such as name, licensed activity, address and contacts, and how the Money Laundering Reporting Officer, as admin user, delegates reporting to a third party subject to Supervisory Body approval. For insurers and brokers, accurate data and managed user access underpin timely reporting.

goAML Registration Guide Stage 2, September 2020

Issued by the UAE Financial Intelligence Unit in September 2020, the goAML Registration Guide Stage 2 outlines the steps an organisation follows when registering with the FIU on its reporting platform, goAML. It applies to registration as a reporting entity, stakeholder or supervisory body, and confirms that all accountable and reporting entities in the United Arab Emirates must register to submit suspicious reports. It notes that, since 27 June 2019, entities must submit reports electronically through goAML. It explains reaching the portal through the Services Access Control Manager and covers registering an organisation, setting access rights and resetting passwords. For insurers and brokers, it enables compliant reporting.

Guideline on Grievance Procedures

Issued by the Executive Office for Control and Non-Proliferation, the Guideline on Grievance Procedures explains how affected parties challenge designations on the UAE Local Terrorist List and the United Nations Consolidated List, together the Sanctions Lists. Under Cabinet Resolution No. 74 of 2020, it recognises three application types: de-listing a designation, lifting freezing measures, and permission to use frozen funds, distinguishing Local List designations by the Cabinet from United Nations designations by the Security Council. Crucially, it applies only to freezes arising from Sanctions List designations, not court orders or investigations. For insurers and brokers, it maps the lawful routes a frozen policyholder or beneficiary may pursue.

Online Grievance System User Guide

The Online Grievance System User Guide, issued by the Executive Office for Control and Non-Proliferation, walks users through the form for challenging designations on the UAE Local Terrorist List and the United Nations Consolidated List, together the Sanctions Lists. The Executive Office launched the online system to streamline three request types: de-listing, cancelling freezing measures, and permission to use frozen funds. The guide covers identifying the aggrieved individual or entity, selecting the relevant list and grievance type, declaring previous requests and appeals, and attaching documents. It clarifies that only Sanctions List freezes are covered. For insurers and brokers, it shows the route by which a frozen policyholder can seek relief.

Simple Guide to Subscribe to the EOCN Notification Alert System (NAS)

This short guide explains how to subscribe to the Notification Alert System on the Executive Office’s website so users receive timely updates to the sanctions lists applied in the United Arab Emirates. It notes that targeted financial sanctions rest on two lists, together the Sanctions Lists: the UAE Local Terrorist List issued by the Cabinet and the United Nations Consolidated List issued by the Security Council, both updated periodically. The guide shows where to access the lists and gives step-by-step subscription instructions. For insurers and brokers, it supports a core control: screening of policyholders and payees only works against current lists, so prompt alerts help firms freeze and report quickly.

Emerging ML, TF and PF Risks and Trends in the Financial Sector

Issued by the Supervisory Subcommittee under Article 16 of Federal Decree-Law No. 10 of 2025, this report gives regulated firms a current view of the money laundering, terrorist financing and proliferation financing threats reshaping the sector as technology, geopolitics and criminal methods evolve. It examines emerging risks such as artificial intelligence exploitation, greenwashing and ESG-related fraud, trade finance abuse, illicit virtual asset flows and sanctions evasion linked to the Commonwealth of Independent States. For insurers and brokers, the value lies in typologies and red flags to fold into risk assessments, particularly where corporate policyholders, opaque free-zone structures or single-premium life products might be exploited to place and layer illicit funds.

Typologies in the Financial Sector

Produced jointly by the Supervisory Authorities Sub-Committee and the Financial Intelligence Unit with a pilot group of institutions, Typologies in the Financial Sector shares money laundering, terrorist financing, sanctions, fraud and bribery typologies seen in the market, several emerging during the COVID-19 pandemic. It describes risks sitting above the National Risk Assessment, including growing use of unlicensed money service operators that balance books over time, and lists indicators that combine to obscure transactions, with links to modern slavery and human trafficking. For insurers and brokers, it works as an early warning tool, helping firms refresh policyholder and beneficiary risk assessments, refine monitoring scenarios and engage authorities when comparable patterns surface.

NRA, SRA, and Other Important Guidelines for the Insurance Sector

The UAE assesses its money laundering, terrorist financing, and proliferation financing risk at the national level, and insurers and brokers must align their own business and enterprise-wide risk assessments with those findings.

UAE PF National Risk Assessment 2026

The UAE Proliferation Financing National Risk Assessment 2026 rates maritime insurance at medium in the mainland and medium-low in the free zones, ratings that speak directly to marine and cargo underwriters. Prepared in response to the Financial Action Task Force’s revised Recommendation 1, it examines the financing of weapons of mass destruction and evasion of targeted financial sanctions relating to the Democratic People’s Republic of Korea and Iran, with overall country risk medium-high. For context, virtual asset service providers are rated high in the mainland; banks, exchange houses and registered hawala medium-high; free zone banks and money service businesses medium; stored value facilities medium-low. It should inform insurers’ sanctions screening.

The table below summarises the residual risk ratings insurers and brokers should reflect in their own risk assessments.

UAE ML and TF National Risk Assessment 2024

The UAE Money Laundering and Terrorist Financing National Risk Assessment 2024 rates the insurance sector at medium residual risk, with inherent risk also medium, a rating insurers and brokers should treat as their baseline. Prepared by the National Committee using the World Bank methodology on data from 2019 to 2023, this second assessment covers financial institutions across the mainland and free zones, with overall national money laundering residual risk medium-high and drug trafficking and fraud among the highest threats. Other sub-sectors are rated for context: banking medium-high, exchange houses medium-high, registered hawala high, finance companies medium, securities medium to medium-high. It should inform each insurer’s risk-based approach and policyholder ratings.

Insurance segment  ML and TF residual risk  PF residual risk 
Life and investment-linked insurance  Medium  Comparatively low, non-depository 
Maritime insurance  Within the medium sector rating  Medium (mainland); medium-low (free zones) 
General and protection insurance  Limited AML exposure  Low 

CBUAE Guidance Applicable to the Insurance Sector

Older CBUAE guidance, standards and outreach material below should be read together with, and subject to, Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025, to the extent they remain in force and are not inconsistent with the current framework.

The Central Bank’s guidance for licensed financial institutions applies to insurers and brokers as it does to other supervised firms. The documents below make up that general guidance set.

CBUAE Best Practices for Licensed FIs on Implementing Role-Based AML/CFT/CPF Training, October 2025

Published in October 2025, the CBUAE Best Practices on Role-Based AML/CFT/CPF Training show insurers and brokers how to shape learning around each job rather than a single generic course. The guidance asks firms to match content, frequency and intensity to the risks a role actually carries, so underwriters, claims handlers and broker-facing staff each learn the red flags that surface in their own work. It sets expectations for the Board, owners, senior management and the three lines of defence, and explains how to document the programme, refresh it, choose delivery methods and keep records. For insurers, well-targeted training sharpens the judgement staff need when assessing life and investment business.

CBUAE Best Practices for Licensed FIs on a Risk-Based Approach and Institutional Risk Assessments, October 2025

Insurers and brokers sit squarely within the scope of the CBUAE Best Practices on the Risk-Based Approach and Institutional Risk Assessments, dated October 2025, which names insurance and reinsurance companies, agents and brokers among the institutions it covers. Issued under Article 44.11 of Cabinet Decision No. 10 of 2019, it helps firms build an assessment methodology and scale controls to their money laundering, terrorist financing and proliferation risks. It sets out how to weigh inherent risk across customers, products, channels, geographies and operating structure, then evaluate controls to reach residual risk. Life and single-premium investment lines usually warrant deeper scrutiny than pure protection cover, and the assessment should reflect that.

CBUAE Guidance for Licensed FIs on Correspondent Banking, October 2025

Cross-border money movement is a daily reality for insurers settling international premiums, ceding risk to overseas reinsurers and paying claims abroad, and the CBUAE Correspondent Banking Guidance of October 2025 speaks to how those flows are controlled. It explains requirements for institutions that process cross-border funds transfers, and the risk factors attached to a counterparty, including nested relationships, payable-through accounts, geography, ownership structures and customer base. On mitigation, it addresses risk assessment, standard, specific and enhanced due diligence, ongoing monitoring, sanctions screening with confirmed and partial match reporting, governance, audit and training. For insurers, robust checks matter because reinsurance settlement chains expose a firm to parties it never directly onboards.

CBUAE Guidance for Licensed FIs on Customer Due Diligence and Record-Keeping, October 2025

For insurers and brokers, policy onboarding is where financial crime controls begin, and the CBUAE Customer Due Diligence and Record-Keeping Guidance of October 2025 sets the foundation. It describes due diligence as the cornerstone for understanding a customer, including occupation, source of funds, source of wealth and expected activity, which is especially telling for single-premium and investment-linked business. The guidance covers identifying customers, beneficial owners and those acting on a policyholder’s behalf, building a risk profile through segmentation, and applying simplified or enhanced measures by risk. Sections on beneficiaries, name screening, non-face-to-face onboarding, exit and record-keeping, supported by red flag indicators, help firms detect and report suspicious activity.

CBUAE Guidance for Licensed FIs on Risks Related to Proliferation Finance, October 2025

Marine, cargo and reinsurance underwriters have a direct stake in the CBUAE Guidance on Proliferation Finance of October 2025, which expressly names insurance and reinsurance among the channels through which the financing of weapons of mass destruction can flow. Read alongside the Central Bank’s Procedures and Guidelines, it explains what proliferation financing is, then examines the vulnerable structures it exploits, including trade finance, free trade zones and shell and front companies. It addresses United Nations Security Council and FATF obligations, local requirements and a risk-based approach across customer, product, geographic, channel and operational risk. Mitigating controls span due diligence, transaction monitoring, suspicious activity reporting, targeted sanctions, governance, audit and training.

CBUAE Guidance for Licensed FIs on Risks Related to Trade-Based ML and Transhipment, October 2025

Marine and cargo cover follows goods across borders, which places the CBUAE Guidance on trade-based money laundering and Transshipment of October 2025 firmly within an insurer’s field of view. It provides background on the trade system and trade finance, then sets out typologies criminals use, including over- and under-invoicing, over- and under-shipment, multiple invoicing, falsely described goods, shell, front and shelf companies, free trade zones and back-to-back letters of credit. It also covers services-based laundering, vulnerable sectors such as gold and precious metals, and illicit transhipment. On mitigation, it addresses enterprise-wide risk assessment and enhanced due diligence, since trade can disguise the true value or movement of insured goods.

Federal Decree by Law No. 6 of 2025 on the Central Bank and the insurance business

Federal Decree by Law No. 6 of 2025 is not the AML law, but it sits underneath it for insurers. Concerning the Central Bank, the Regulation of Financial Institutions and Activities, and Insurance Business, it treats banks, (re)insurance companies and other financial institutions as licensed financial institutions under Central Bank licensing and supervision, replacing the earlier Central Bank law of 2018. An insurer, broker or agent should read it alongside Federal Decree-Law No. 10 of 2025 when working out its licensing, conduct and supervisory position, because it defines who the Central Bank licenses and oversees in the insurance market.

CBUAE AML and CFT Guidelines for Financial Institutions, July 2023

Dated July 2023, the CBUAE AML/CFT Guidelines for Financial Institutions are the consolidated reference that shapes how insurers and brokers run their compliance programmes. Prepared jointly by the UAE Supervisory Authorities, they state minimum expectations for identifying, assessing and mitigating money laundering, terrorist financing and illegal organisation risks. Crucially, they apply expressly to insurance companies, agencies and brokers, alongside their boards, management and staff. The guidelines outline the legal framework, summarise statutory obligations, and explain money laundering, predicate offences and typologies. A substantial part addresses the risk-based approach, covering business-wide risk assessment and risk factors tied to policyholders, products, channels and geography, guiding due diligence and reporting across your book.

CBUAE Guidance for Licensed FIs on Risks Related to Virtual Assets and VASPs, February 2023

When a policyholder funds a premium from cryptocurrency or is otherwise exposed to digital assets, the CBUAE Guidance on Virtual Assets and Virtual Asset Service Providers of 20 February 2023 becomes relevant to insurers and brokers. It explains the threats and vulnerabilities virtual assets create, the ways firms may become exposed, and the UAE framework spanning the SCA, CBUAE, VARA and FSRA. It sets out the non-objection requirement before opening accounts for such providers and covers the risk-based approach, due diligence and enhanced measures for higher-risk customers and transactions. Because virtual assets move value rapidly and pseudonymously, understanding a crypto-exposed client’s source of funds is central to protecting the firm.

CBUAE Guidance for Licensed FIs on Digital Identification for Customer Due Diligence, October 2022

Issued on 31 October 2022, the CBUAE Guidance on Digital Identification for Customer Due Diligence helps insurers and brokers understand how digital identity systems can verify clients and support ongoing due diligence, particularly valuable when policies are sold non-face-to-face online. It reflects CBUAE’s expectations. The guidance explains digital identity systems and their participants, identity proofing and enrolment, authentication, lifecycle management, and portability and interoperability. It then shows how such systems support identification, verification, ongoing due diligence and third-party reliance. It examines the risks these systems present and how to assess reliability through assurance levels. Reliable digital identification strengthens remote policy onboarding while introducing risks insurers must manage.

CBUAE Guidance for Licensed FIs on Suspicious Transaction Reporting, August 2022

Issued on 3 August 2022, the CBUAE Guidance on Suspicious Transaction Reporting shows insurers and brokers how to identify, investigate and report suspicious activity, whether it surfaces in an inflated premium, an early surrender or a questionable claim. It explains the legal basis for reporting, the protection given to those who disclose, the consequences of failing to report, and the meaning of a suspicious transaction. It details the three lines of defence, the role of the compliance officer or MLRO, transaction monitoring methods, and how to draft, structure, submit and amend a report. Further sections cover alert timing, matters needing immediate attention, and the strict prohibition on tipping off policyholders.

CBUAE Guidance for Licensed FIs on Risks Relating to Payments, August 2022

Dated August 2022, the CBUAE Guidance on the Risks Relating to Payments addresses the laundering and terrorist financing risks moving through the payments sector, relevant to insurers and brokers who collect premiums and disburse claims through varied payment channels. Issued under Article 44.11 of Cabinet Decision No. 10 of 2019, it states regulator expectations rather than new law. It explains what makes payments vulnerable: the speed of funds, peer-to-peer transfers, cross-border movement, intermediation, nesting, and the use of agents. On mitigation it references risk assessment, customer and enhanced due diligence, ongoing monitoring, wire transfers, sanctions and suspicious transaction reporting, helping insurers calibrate controls to a fast-moving payment environment.

CBUAE Guidance for Licensed FIs on Risks Relating to Politically Exposed Persons, August 2022

Dated August 2022, the CBUAE Guidance on Politically Exposed Persons shows insurers and brokers how to manage the heightened risk carried by prominent clients, a live concern for high-net-worth life and investment policyholders. Issued under Article 44.11 of Cabinet Decision No. 10 of 2019, it stresses that such clients need not be avoided but do require thorough due diligence before onboarding or continuing. It distinguishes domestic and foreign politically exposed persons and heads of international organisations, extending to family members and close associates. It covers classification, time limits on status, screening, risk rating, enhanced due diligence, transaction monitoring, suspicious transaction reporting, governance and training, with an annex of red flags.

CBUAE Guidance for Licensed FIs on Transaction Monitoring and Sanctions Screening, September 2021

Issued on 8 September 2021, the CBUAE Guidance on Transaction Monitoring and Sanctions Screening explains how insurers and brokers should design, run and maintain the systems that detect suspicious activity and identify sanctioned parties. On monitoring, it covers risk assessment, risk-based deployment, data management, rule definition and testing, alert scoring, outcomes analysis and ongoing tuning. On screening, it addresses name and transaction screening design, list management, testing and validation, essential when checking policyholders, beneficiaries and payees. A governance section covers management reporting, auditing, use of vendors, training and record keeping. Well-calibrated, validated systems help insurers spot suspicious premium or claim flows and avoid dealings with sanctioned persons.

CBUAE Guidance for Licensed FIs to Cash-Intensive Businesses, September 2021

Published in September 2021, the CBUAE Guidance on Cash-Intensive Businesses helps insurers and brokers manage the laundering and terrorist financing risks that surface when policyholders settle premiums in large volumes of cash. Issued under Article 44.11 of Cabinet Decision No. 10 of 2019, it sets regulator expectations rather than new law. It explains why cash is vulnerable, the risks of alternatives such as bearer instruments and prepaid cards, and concerns around cross-border cash movement and couriers. On mitigation, it prescribes an enterprise risk assessment, customer and beneficial owner identification, enhanced due diligence, ongoing and transaction monitoring, suspicious transaction reporting, governance and training, so cash-paying clients face proportionate scrutiny.

CBUAE Guidance for Registered Hawala Providers and LFIs, August 2021

Issued by the CBUAE in August 2021, this combined guidance addresses both registered hawala providers and the licensed financial institutions that serve them, and because insurers rank as LFIs, its expectations for those institutions reach the insurance sector. It explains what hawala is, drawing on the FATF description of hawaladars as money transmitters who arrange transfers and settle through trade, cash and long-term net settlement, often tied to particular regions or communities. It describes the global risks of hawala, its regulation and supervision in the UAE, and permitted and non-permitted services. Further parts cover sanctions and freezing without delay, and an AML/CFT programme spanning customer, enhanced and agent due diligence.

CBUAE Guidance for Licensed FIs on Implementation of Targeted Financial Sanctions, July 2021

Dated 4 July 2021, the CBUAE Guidance on the Implementation of Targeted Financial Sanctions helps insurers and brokers meet their duty to identify, freeze and report assets and transactions linked to designated persons. Read with the CBUAE procedures and Executive Office guidance, it sets out how to build a sanctions compliance programme: senior management commitment, risk assessment and appetite, internal controls, training, independent audit and record keeping. It then addresses screening operations, evasion, the United Nations Consolidated List and Local Terrorist List, verifying false positives, and handling confirmed matches. For insurance, this means screening policyholders, beneficiaries and payees before paying claims or surrenders, and notifying the authorities of any hit. Screening should cover policyholders, beneficiaries, payees, beneficial owners, assignees, reinsurers and relevant counterparties, and any entity owned or controlled by a designated person, not only the named customer.

CBUAE Guidance for Licensed FIs to Legal Persons and Arrangements, June 2021

Dated June 2021, the CBUAE Guidance on Legal Persons and Arrangements helps insurers and brokers manage the risks that arise when a policyholder is a company, other legal person or legal arrangement rather than an individual. It explains how such structures can obscure identity and beneficial ownership, hide the purpose of a policy or transaction, and conceal the source of funds. It then covers mitigating controls: formation requirements, identifying and reporting beneficial owners, record keeping, economic substance, customer risk rating, the institutional risk assessment, and enhanced due diligence. For insurers, piercing corporate policyholders to their true owners is central to preventing misuse of your products.

CBUAE Guidance for Licensed FIs to the Real Estate and Precious Metals and Stones Sectors, June 2021

Issued on 16 June 2021, the CBUAE Guidance on the Real Estate and Precious Metals and Stones Sectors helps insurers and brokers understand the risks that arise when clients are active in these two higher-risk sectors. Read with the CBUAE procedures, it does not replace legal obligations, which prevail in any conflict. Organised around understanding and mitigating risk, it describes risk-raising features, typologies, and how each is regulated in the UAE. On mitigation it explains the risk-based approach, customer and enhanced due diligence, suspicious transaction reporting, governance and training, with annexed red flags. For insurers exposed to property developers or bullion dealers, it frames the expected scrutiny.

CBUAE STR Outreach for Banks and Finance Companies, March 2021

Delivered on 10 March 2021, this Financial Intelligence Unit outreach session briefed banks and finance companies on suspicious transaction reporting, with input from the Ministry of Interior. Its expectations reach every institution that files through goAML, so an insurer or insurance broker can read across the same messages: when a report is warranted, the quality the FIU expects, goAML as the sole channel, and the compliance officer’s role. For life and investment-linked business it reinforces prompt, well-grounded reporting of unusual premium, surrender or beneficiary activity rather than defensive or late filing.

CBUAE Board of Directors Decision No. 59/4/2019 on AML and CFT procedures

Board of Directors Decision No. 59/4/2019, dated 13 June 2019, remains a supervisory and historical source that brought UAE insurers and brokers under CBUAE anti-money laundering supervision. Issued under the Central Bank Law, Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025, it treats any entity conducting financial operations for a customer as a financial institution, capturing life offices and their intermediaries. It obliges them to observe the law, the implementing regulation and CBUAE instructions. For insurers, it means the regulator may examine your files without notice, demand information on policyholders and premiums, and impose sanctions, which it may publish, for compliance failures. It should be read subject to Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025, which now set the current framework.

CBUAE Guidance Note on Responsible Use of AI and ML by LFIs

As insurers adopt models to price risk, screen applications and monitor transactions, the CBUAE Guidance Note on the Responsible Use of Artificial Intelligence and Machine Learning offers principles for doing so ethically and with the consumer in mind, including generative AI. It is non-binding and meant to help firms shape their own internal policies, treating its principles as flexible so they evolve with the technology. It places responsibility for AI systems and outcomes with senior management and the Board, and calls for a documented governance framework and an inventory of all models. It addresses fairness, transparency, data quality, privacy, monitoring and meaningful human oversight, so automated decisions affecting policyholders are governed responsibly.

CBUAE List of Administrative and Financial Sanctions

Enforcement reaches every licensed institution, insurers included, and the CBUAE List of Administrative and Financial Sanctions records the penalties the Central Bank can impose for shortcomings in anti-money laundering and sanctions compliance. Under Article 14 of Decretal Federal Law No. 20 of 2018, as amended by Federal Decree Law No. 26 of 2021, the CBUAE can impose administrative penalties from a warning up to licence revocation, and financial penalties of no less than fifty thousand and no more than five million dirham per violation. Under Article 137 of the Central Bank Law, penalties reach a fine of up to two hundred million dirham, with licence withdrawal and striking off.

CBUAE Insurance Sector-Specific Guidance

Alongside its general guidance, the Central Bank issues material aimed specifically at the insurance sector.

CBUAE Insurance Brokers' Regulation, Circular No. 1/2024 (1 April 2024)

The CBUAE Insurance Brokers’ Regulation is the prudential and conduct framework governing the licensing and supervision of insurance brokers in the UAE. It sets out licensing conditions, the rights and obligations of brokers towards insurance companies and clients, prudential requirements addressing financial soundness, risk management, internal controls and disclosure, and the Central Bank’s supervisory powers. It is structured around articles covering definitions, licensing, the fit and proper process, brokerage agreements, premiums and claim settlements, corporate governance, accounting, conduct of business, record-keeping, outsourcing and enforcement. The Central Bank applies proportionality according to the nature, scale and complexity of a broker’s business. It matters because it defines the standards brokers must satisfy. It was issued as Circular No. 1/2024, dated 1 April 2024.

CBUAE Guidance for the Insurance Sector, October 2022

The Guidance for the Insurance Sector, issued by the CBUAE’s AML/CFT Supervision Department in October 2022, helps licensed insurers, agents and brokers understand and manage the money laundering and terrorist financing risks specific to insurance. Issued under Article 44.11 of Cabinet Decision No. 10 of 2019 and read alongside the CBUAE’s Procedures and Guidelines, it sets out expectations firms must demonstrate rather than new legislation. It examines risks in life and investment products across product, distribution channel, customer and geographic factors, then turns to mitigation, covering the risk-based approach, enterprise risk assessment, customer due diligence including simplified and enhanced measures, and suspicious transaction reporting. It helps insurers calibrate controls proportionately.

CBUAE Insurance STR Outreach, March 2021

The CBUAE Insurance STR Outreach, delivered in March 2021, is an awareness session prepared by the Financial Intelligence Unit and the CBUAE to strengthen suspicious transaction reporting across the insurance sector. It covers when to report, grounding the duty in Article 15 of Federal Decree-Law No. 20 of 2018 and Article 17 of Cabinet Decision No. 10 of 2019, and what to report: any suspicion that funds are proceeds of crime or relate to terrorist financing. It sets out insurance-specific red flags, including borrowing against surrender value, single large premiums, bearer policies and unclear beneficial ownership. It confirms goAML is the only channel and helps insurers recognise and report suspicion.

Core AML Obligations for Insurers and Brokers at a Glance

Whatever the licence, the AML regulations for insurance companies and brokers in the UAE turn on a common set of duties.

The controls a supervisor expects to see evidenced, and the guidance behind them, map onto these areas:

Law or guidance  Control area  What insurers and brokers should evidence 
CBUAE RBA and Institutional Risk Assessment guidance; Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025  Business and enterprise-wide risk assessment  Risk rated by product, customer, channel, geography, premium flow and claims exposure, aligned to the national risk assessments 
CBUAE Customer Due Diligence and Record-Keeping Guidance, October 2025  Onboarding  Policyholder and beneficial owner identity, purpose of cover, and source of funds or wealth where the risk is higher 
CBUAE Guidance for the Insurance Sector, October 2022  Product risk  Closer scrutiny of life, investment-linked, single-premium and assignable policies 
CBUAE Transaction Monitoring and Sanctions Screening Guidance, September 2021  Ongoing monitoring  Top-ups, early surrender, cancellation, beneficiary changes, third-party premium funding and claims payouts 
CBUAE Implementation of Targeted Financial Sanctions Guidance, July 2021; EOCN Guidance on Targeted Financial Sanctions  Sanctions screening  Policyholders, beneficiaries, payees, beneficial owners and assignees, screened on every list change 
CBUAE Insurance Brokers’ Regulation, Circular No. 1/2024  Broker controls  A clear role, client information, premium handling and escalation of suspicion 
CBUAE Suspicious Transaction Reporting Guidance, August 2022; UAE FIU goAML  goAML reporting  STR and SAR decisions filed through goAML, no tipping-off, with the investigation rationale recorded 
CBUAE Best Practices on Role-Based Training, October 2025; Cabinet Resolution No. 134 of 2025  Governance and training  Compliance officer or MLRO independence, senior management and board oversight, training, audit and remediation 

Expert Tip:

For life and investment insurers, the moments that matter most are top-ups, early surrenders, and changes of beneficiary. Build monitoring around those events, because that is where laundering through insurance actually shows up, not in the routine premium.

Conclusion

AML regulations for insurance companies and brokers in the UAE follow the same logic as the wider financial sector: if you carry on life or investment-linked business, you are a financial institution, the Central Bank or your free zone regulator supervises you, and the federal laws, the executive regulations, the sanctions rules, and the Central Bank’s general and insurance-specific guidance all apply. The sector’s risk is rated medium rather than high, but the obligations are real, and supervisors expect a programme that matches the actual product and customer risk. Use the national risk assessments to calibrate, and treat this guide as the map. For the wider view, see our guide to anti-money laundering laws in the UAE and the pillar on AML regulations for banks and financial institutions in the UAE.

Frequently Asked Questions

Are insurance companies subject to AML regulations in the UAE?

Yes. Insurers carrying on life and investment-linked business are financial institutions under Federal Decree-Law No. 10 of 2025, supervised for the mainland by the Central Bank, and must run customer due diligence, screening, monitoring, and reporting. General and protection insurance carries limited AML exposure.

Yes. Brokers that arrange relevant insurance business are inside the AML perimeter, and the Central Bank maintains a dedicated insurance broker regulation. Brokers must apply customer due diligence, sanctions screening, and suspicious transaction reporting appropriate to their role.

The UAE ML and TF National Risk Assessment 2024 rates the insurance sector at medium residual risk, with a medium inherent risk, reflecting the limited ways life and investment products can be abused. Maritime insurance carries a medium proliferation financing risk in the mainland and medium-low in the financial free zones.

The Central Bank of the UAE supervises the mainland insurance sector. Insurers and intermediaries in the DIFC are supervised by the DFSA and those in the ADGM by the FSRA, each under its own AML rulebook alongside the federal law.

Life insurance and investment-linked products carry the most risk, because they can store and transfer value, can, in higher-risk cases, be funded in cash or cash-like means, and can be surrendered or assigned. Monitoring should focus on top-ups, early surrenders, and beneficiary changes.

Yes. Insurers, brokers, and agents in scope must register on the UAE Financial Intelligence Unit’s goAML platform and file suspicious transaction and activity reports, along with related filings, through it.

The Central Bank issues insurance-specific material including the CBUAE Insurance Brokers’ Regulation, the CBUAE Guidance for the Insurance Sector of October 2022, and insurance STR outreach, in addition to its general guidance for all licensed financial institutions. This CBUAE insurance AML guidance sits on top of the federal AML rules for insurers.

Insurers and brokers must identify and verify the customer and any beneficial owner, screen against sanctions and politically exposed person lists, and risk-rate the relationship before cover incepts. For investment-linked and higher-value life business they should establish the source of funds and, where risk is higher, apply enhanced due diligence. Onboarding checks then feed ongoing monitoring across the life of the policy.

Typical indicators include premiums settled in cash or by an unrelated third party, early surrender or cancellation with the refund directed elsewhere, frequent unexplained top-ups, cover that does not fit the customer’s profile or means, and reluctance to provide beneficial owner or source of funds information. These signs, drawn from the sector typologies and red flag guidance, should trigger escalation and, where suspicion remains, a report through goAML.

No. General insurance usually carries lower money laundering risk than life or investment-linked cover, but a CBUAE-licensed insurer, agent or broker should still assess its own position under the Central Bank’s rules and guidance, its licence, its sanctions duties and the risk profile of its products and customers.

The ones where value can move or change hands: single large premiums, third-party premium payments, frequent top-ups, early surrender or cancellation with a refund sent elsewhere, beneficiary or assignee changes, and any claim or payout involving sanctioned, high-risk or opaque parties.

Need help building or reviewing your insurance AML programme?

Strengthen your AML framework with practical solutions designed to help insurance providers meet regulatory requirements and reduce compliance risks.

Share via :

About the Author

Pathik Shah

FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)

Pathik is an ACAMS-certified AML consultant specialising in governance, risk, and compliance for regulated entities in the UAE. He brings over 28 years of experience, with 1,000+ hours of AML training and 200+ advisory engagements across DNFBPs, VASPs, and FIs. He supports businesses in aligning with AML/CFT requirements from the CBUAE, DFSA, MoET, MoJ, VARA, CMA, FSRA, and FATF. Known for translating complex regulations into audit-ready procedures, Pathik enables operational clarity and compliance readiness.

Reach Out to Pathik

AML Regulations for Banks and Financial Institutions in UAE

AML Regulations for Banks and Financial Institutions in UAE

Blogs

Published On: 07/09/2026

Table of Contents

Protect your business with reliable and effective AML strategies with AML UAE.

Last Reviewed On: 07/09/2026   |   Last Updated On: 07/09/2026

Key Highlights

  • The principal statute is Federal Decree-Law No. 10 of 2025 on anti-money laundering, combating the financing of terrorism, and proliferation financing, read together with its Executive Regulations in Cabinet Resolution No. 134 of 2025.
  • Financial institutions are a defined class under UAE AML law. Banks, insurance firms, exchange houses and money service businesses, registered hawala providers, capital market firms, finance companies, and other licensed financial institutions all fall inside it.
  • Supervision is shared. The Central Bank of the UAE oversees most mainland financial institutions, the Capital Market Authority oversees the capital market, and the DFSA and FSRA supervise firms in the DIFC and ADGM financial free zones.
  • Every regulated institution reports suspicious activity to the UAE Financial Intelligence Unit through the goAML platform.
  • The national risk assessments rate residual money-laundering risk as highest for registered hawala providers and medium-high for banks and exchange houses, with proliferation-financing risk concentrated in trade finance (UAE ML and TF National Risk Assessment 2024; UAE PF National Risk Assessment 2026).
  • Core obligations span the sector: risk assessment, customer due diligence, sanctions screening, transaction monitoring, recordkeeping, and suspicious transaction reporting.
  • This page is the overview. Each sector has its own dedicated guide for the finer details.

Banks and financial institutions sit at the centre of the UAE’s fight against money laundering. They move most of the money, so they carry most of the responsibility to spot and stop it. This guide sets out the AML regulations for banks and financial institutions in the UAE. It discusses which institutions are covered, who supervises them, the full legal framework they answer to, and how the national risk assessments rate the money laundering, terrorist financing, and proliferation financing risk of each sub-sector. It is a map of the whole regime, with links out to detailed sector guides where you need to go deeper.

Banks and financial institutions in the UAE are subject to Federal Decree-Law No. 10 of 2025, Cabinet Resolution No. 134 of 2025, targeted financial sanctions rules, and the guidance or rulebook issued by their relevant AML supervisor. Mainland banks, exchange houses, finance companies, insurers and registered hawala providers are generally supervised by the Central Bank of the UAE. Mainland capital market firms are supervised by the Capital Market Authority, formerly SCA. DIFC firms are supervised by the DFSA, and ADGM firms by the FSRA. Suspicious reports are filed with the UAE FIU through goAML.

Which banks and financial institutions are covered by UAE AML Law?

Under Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025, a “financial institution” is any entity that carries on one or more defined financial activities, whether licensed onshore by the Central Bank or in one of the financial free zones. If your business takes deposits, moves money, underwrites insurance, deals in securities, or lends, you are almost certainly inside the AML regulations for banks and financial institutions in the UAE. The categories below each have their own dedicated guide.

Banks

Banks are the widest and most heavily supervised group. The category covers commercial banks, wholesale banks, and the branches of foreign banks licensed by the Central Bank of the UAE. They take deposits, lend, run payment and correspondent banking relationships, and provide trade finance, so almost every money laundering, terrorist financing, and sanctions typology touches a bank at some point. Their scale, openness, and extensive cross-border networks are exactly what make them attractive to criminals, which is why they sit at the front line of the UAE regime and carry the deepest set of obligations. Read the dedicated guide: AML regulations for banks in the UAE.

Insurance

Life insurance and investment-linked products can be used to place and layer illicit funds, particularly where premiums can be settled in cash or policies surrendered early. The category captures insurers, brokers, agents, and other intermediaries carrying on relevant life and investment-related business. General insurance and pure protection products normally present lower ML and TF risk, but licensed insurers, brokers and agents supervised by the Central Bank should still assess their AML obligations and apply controls proportionate to their products and customers. Firms in this sector are treated as financial institutions and must run customer due diligence, screening, and reporting on the relevant lines. Read the dedicated guide: AML regulations for insurance companies and brokers in UAE.

Exchange houses and MSBs

Exchange houses and money service businesses handle currency exchange, remittance, wage payments, and banknote trading, which makes them a classic conduit for structuring and the cross-border movement of value. Because they deal in cash and often route payments through foreign correspondents, they carry a heightened risk of layering and third-party laundering. They are licensed and supervised by the Central Bank and must apply the same core AML controls as other licensed institutions. Read the dedicated guide: AML regulations for exchange houses in UAE.

Registered hawala providers

Hawala and other informal value transfer systems are legal in the UAE only when the provider holds a registration certificate from the Central Bank. Registered hawala providers carry AML duties in their own right, including customer identification, record-keeping, and suspicious transaction reporting through goAML. Their cash-based, relationship-driven model is inherently harder to monitor, so supervision of the sector is close. Read the dedicated guide: AML regulations for registered hawala providers in UAE.

Capital Market

The capital market covers brokerages, custodians, fund managers, investment managers, and other firms dealing in or advising on securities and commodities. These firms are financial institutions for AML purposes and are supervised for the capital market under the framework of the Capital Market Authority. Although securities firms do not take cash deposits, they must still identify their clients, screen against sanctions lists, and monitor for market-based laundering. Read the dedicated guide: AML regulations for capital market firms in UAE.

Finance Companies

Finance companies provide credit, consumer and commercial financing, and related lending services, and are licensed and supervised by the Central Bank of the UAE. They are captured as financial institutions and carry the full set of core AML obligations, scaled to their products and customer base. Their exposure tends to be lower than that of deposit-taking banks, but lending can still be used to integrate illicit funds. Read the dedicated guide: AML regulations for finance companies in the UAE.

Other LFIs

The financial institution definition is deliberately broad, so other licensed financial institutions carrying on defined activities are captured even where they do not fit the labels above. This includes certain payment and stored value activities and other specialist licensed models. Where a firm carries on a regulated financial activity, it should assume the AML framework applies and confirm its status with its supervisor. Read the dedicated guide: AML regulations for other LFIs in the UAE.

AML Supervisory Authority for Banks and Financial Institutions in UAE

Supervision in the UAE is shared between the federal financial regulators and the two financial free zone authorities. Knowing your supervisor matters because it determines which rulebook, guidance, and enforcement powers apply to you.

Central Bank of the UAE (CBUAE)

The Central Bank is the AML supervisor for most mainland financial institutions, including banks, exchange houses, finance companies, registered hawala providers, insurers, and money service businesses. It issues sector guidance, inspects licensed institutions, and can impose administrative and financial penalties for breaches. Institutions should expect their AML programme to be tested by thematic inspections.

Capital Market Authority

The capital market is supervised by the Capital Market Authority, formerly the Securities and Commodities Authority, under Federal Decree-Law No. 32 of 2025. It sets AML expectations for brokerages, custodians, fund managers, and other securities and commodities firms, and monitors their compliance.

Dubai Financial Services Authority (DFSA)

The DFSA is the independent regulator for firms established in the Dubai International Financial Centre. It runs its own AML rulebook that applies alongside the federal law, so a DIFC firm answers to the DFSA for day-to-day supervision while still meeting the UAE’s overarching AML obligations.

Financial Services Regulatory Authority (FSRA)

The FSRA is the independent regulator for firms established in the Abu Dhabi Global Market. Like the DFSA, it maintains its own AML rulebook and supervises and enforces against firms in its free zone, within the wider federal framework.

UAE FIU and goAML

Whoever supervises you, every regulated financial institution reports to a single national body. The UAE Financial Intelligence Unit receives and analyses suspicious transaction reports, suspicious activity reports, and related filings, all submitted through the goAML platform.

Registration on goAML is a baseline obligation, and timely, good-quality reporting is one of the clearest signals of an effective AML programme.

See our goAML registration guide and the difference between a suspicious activity and a suspicious transaction for the practical steps.

Firms in the DIFC and ADGM file suspicious reports with the UAE FIU through goAML in the same way, and may also carry parallel notification duties to the DFSA or FSRA under their own rulebooks.

The table below shows which authority supervises each type of financial institution.

Financial institution 

Primary AML supervisor 

Mainland banks 

Central Bank of the UAE (CBUAE) 

Exchange houses and MSBs 

CBUAE 

Registered hawala providers 

CBUAE 

Finance companies 

CBUAE 

Insurers, brokers and agents 

CBUAE 

Mainland capital market firms 

Capital Market Authority 

DIFC firms 

DFSA 

ADGM firms 

FSRA 

AML Legal Framework Applicable to Banks and Financial Institutions in UAE

The framework has four layers: the core federal laws and regulations, the guidance that applies to all reporting entities, the Central Bank’s own guidance for licensed financial institutions, and the national and sector risk assessments that tell you where the threats actually are. This section catalogues each layer. It stays at overview depth on purpose, because the detailed obligations live in the sector guides.

Federal AML Laws and Executive Regulations Applicable to Banks and Financial Institutions

These four instruments are the legal foundation for every financial institution in the UAE.

Federal Decree-Law No. 10 of 2025 on AML, CFT and CPF

Federal Decree-Law No. 10 of 2025 is the principal UAE statute governing anti-money laundering, terrorism financing, and proliferation financing. It sets the core definitions, recognises offences through virtual assets, and establishes the Financial Intelligence Unit within the Central Bank as the independent body that receives and analyses suspicious transaction reports. Powers to suspend or freeze suspicious transactions and funds sit with the FIU and the competent authorities under the law, Cabinet Resolution No. 74 of 2020 and UAE FIU Regulation No. 1 of 2026. For banks and insurers, it is the source of core reporting and oversight duties.

Cabinet Resolution No. 134 of 2025, the Executive Regulations

Cabinet Resolution No. 134 of 2025 issues the Executive Regulations of Federal Decree-Law No. 10 of 2025, translating the statute into detailed rules. It defines scope, including banking, securities, and life insurance, and requires a risk-based approach, customer due diligence, beneficial owner verification, ongoing monitoring, and approved internal policies. For banks and insurers, it is the practical rulebook of procedures and controls that supervisors test.

Cabinet Resolution No. 74 of 2020 on terrorist lists and UNSC resolutions

Cabinet Resolution No. 74 of 2020 regulates the terrorist lists and how the UAE implements United Nations Security Council resolutions on terrorism, its financing, and weapons proliferation. Freezing must be applied within twenty-four hours. Financial institutions must register with the Executive Office, continuously screen customers and beneficial owners against the lists, freeze matches without prior notice, and report promptly, establishing core sanctions screening duties.

Federal Law No. 7 of 2014 on combating terrorism crimes

Federal Law No. 7 of 2014 on Combating Terrorism Crimes defines terrorist offences in the UAE and fixes their penalties, up to life imprisonment or death. It penalises providing, collecting, or maintaining funds for terrorist purposes and addresses freezing suspected funds held in financial institutions. Banks and insurers rely on it to understand the predicate conduct their controls detect, deter, and report.

AML Guidance Applicable to All Reporting Entities

Beyond the core laws, the Central Bank and the FIU issue a large body of guidance, guidelines, and typologies that shape day-to-day compliance. The instruments below sit in the overarching guidance set for licensed financial institutions.

UAE FIU Regulation No. 1 of 2026 on Suspension and Freezing Powers, April 2026

UAE FIU Regulation No. 1 of 2026, dated April 2026, governs the postponement or suspension of suspicious transactions and the freezing of funds. Applying to financial institutions, designated non-financial businesses and virtual asset service providers, it introduces the urgent Postponement Suspicious Transaction Report, plus a Suspension Order of up to ten working days and a Freezing Order of up to thirty days. For firms, it preserves funds at risk.

UAE FIU Strategic Analysis Report on Human Trafficking, April 2026

The UAE FIU Strategic Analysis Report on Human Trafficking, dated April 2026, analyses money laundering flows linked to human trafficking using suspicious reports filed with the Financial Intelligence Unit. It covers sexual exploitation, forced labour and organ removal, profiles traffickers, organised crime and money mules, assesses vulnerable sectors, and develops risk indicators. For financial institutions, it is a detection resource that improves reporting quality.

Guidance on Targeted Financial Sanctions for Financial Institutions, DNFBPs and VASPs, March 2026

The Guidance on Targeted Financial Sanctions for Financial Institutions, DNFBPs and VASPs, from the Executive Office for Control and Non-Proliferation, was first published in January 2021 and last amended in March 2026. It sets four obligations: registering in the Notification Alert System, screening against the Local and UN lists, freezing assets without delay, and reporting. The 2026 update renames the confirmed-match report, previously the Funds Freeze Report or FFR, as the Confirmed Name Match Report, and reports of partial matches as the Partial Name Match Report.

Joint Guidance on the Compliance Officer and MLRO, 2026

The Joint Guidance on the Compliance Officer and Money Laundering Reporting Officer, issued in 2026 by the UAE Supervisory Sub-Committee, establishes a unified framework for the officer’s appointment, authority, and responsibilities across regulated sectors. Recognising the role as a cornerstone of effective AML defences, it sets expectations on seniority, experience, independence, board access, and resources, clarifying how institutions appoint and empower a fit and proper officer.

FIU Strategic Analysis Report on Terrorist Financing, May 2025

The FIU Strategic Analysis Report on Terrorist Financing, published in May 2025, is produced by the UAE Financial Intelligence Unit using data from 2021 to 2024. It sets out typologies such as unlicensed hawala, corporate networks, trade-based financing, real estate, and virtual assets, and examines facilitators, concluding with risk indicators that help institutions detect, trace, and report suspicious terrorist financing activity.

goAML FAQs, April 2024

The goAML FAQs, version 2.1 dated 18 April 2024, are a question-and-answer guide from the UAE Financial Intelligence Unit helping reporting entities use the goAML system and its access services. It gives step-by-step remedies for registration and login problems, including expired one-time passwords, Google Authenticator passcodes and password resets. For financial institutions, it supports reliable access, underpinning timely reporting.

PF Institutional Risk Assessment Guidance for FIs, DNFBPs and VASPs, December 2023

The Proliferation Financing Institutional Risk Assessment Guidance, published in December 2023, sets out how financial institutions should assess and manage exposure to proliferation financing. It explains a methodology built around inherent risks, control effectiveness, and residual risks, describes mitigating measures and a customer risk scoring questionnaire with worked case studies, helping firms recognise elevated risk customers, calibrate controls, and document risk decisions for supervisors.

Terrorist and Proliferation Financing Red Flags Guidance, December 2023

The Terrorist and Proliferation Financing Red Flags Guidance, updated December 2023, consolidates indicators helping financial institutions detect suspicious terrorist and proliferation financing, including evasion of targeted sanctions under United Nations Resolutions or local designations. It explains tactics such as front companies, sets out the legal basis for reporting, and groups proliferation indicators by customer profile, transaction, maritime and trade finance. It is a working reference for detection.

Suspicious Activity and Transaction Reporting Thematic Review, January 2023

The Suspicious Activity and Transaction Reporting Thematic Review, issued in January 2023, sets out findings and expectations from the 2022 AML/CFT examination of financial institutions and designated non-financial businesses. It contrasts acceptable and deficient practices across governance, policies, risk-based monitoring, data, alert review, investigation and reporting. For financial institutions, it is a practical benchmark to test monitoring and reporting arrangements and close gaps before inspection.

Cabinet Resolution No. 109 of 2023 Regulating the Real Beneficiary Procedures

Cabinet Resolution No. 109 of 2023 regulates beneficial owner procedures for legal persons in the UAE, requiring accurate, up-to-date ownership information and registers updated within short deadlines. Banks and insurers rely on this data for customer due diligence on corporate customers. These procedures apply to legal persons licensed or registered in the State, including commercial free zones, but exclude the financial free zones, the DIFC and ADGM, which operate their own beneficial ownership regimes.

Cabinet Resolution No. 132 of 2023 on Administrative Penalties for Real Beneficiary Violations

Cabinet Resolution No. 132 of 2023 sets the administrative penalties for violations of the beneficial owner procedures under Cabinet Resolution No. 109 of 2023, empowering the registrar to fine and, on a third violation, suspend licences. It reinforces why corporate customers must keep ownership data current. These penalties apply to legal persons licensed or registered in the State, including commercial free zones, but not to the financial free zones, the DIFC and ADGM, which follow their own regime.

Counter Proliferation Financing Guideline, November 2022

The Counter Proliferation Financing Guideline, published in November 2022 by the Executive Office for Control and Non-Proliferation, supplements the Guidance on Targeted Financial Sanctions. It helps financial institutions identify, assess, and mitigate Proliferation Financing risks in line with Financial Action Task Force standards, covering the UAE framework, risk assessment, preventive measures such as enhanced due diligence and trade finance controls, and red flags for sanctions evasion.

goAML Web Submission Guide, July 2022

The goAML Web Submission Guide, issued by the UAE Financial Intelligence Unit in July 2022, sets out how the Compliance Officer or Money Laundering Reporting Officer submits reports through goAML. It covers report types, including Suspicious Transaction and Suspicious Activity Reports, accessing the system, completing the cover and submitting. For financial institutions, it standardises reporting and helps officers file complete reports promptly.

IEMS User Guide for Reporting Entities, March 2022

The IEMS User Guide for Reporting Entities, dated March 2022, is a manual from the UAE Financial Intelligence Unit for its Integrated Enquiry Management System, which handles information requests, prosecution decisions, and freeze orders between the Unit, authorities, and reporting entities. It explains login, the dashboard, the reply workflow, and Admin, Maker, and Checker roles, showing institutions how to action enquiries and freeze instructions compliantly.

Joint Guidance on Combating the Use of Unlicensed Virtual Asset Providers, March 2022

The Joint Guidance on Combating the Use of Unlicensed Virtual Asset Providers, issued in March 2022 by the UAE Supervisory Authorities, including the Central Bank and the Virtual Assets Regulatory Authority, educates the public and regulated entities on the risks of unlicensed providers. It reminds institutions of their AML obligations, sets expectations on due diligence and reporting, and provides red flags such as missing licences and unrealistic promises.

goAML Pre-Registration Guide, March 2022

The goAML Pre-Registration Guide, issued by the UAE Financial Intelligence Unit in March 2022, explains how reporting entities secure access to the Services Access Control Manager, or SACM, before reaching goAML to register and file suspicious reports. It covers the gateway, a Google Authenticator one-time password, and safeguarding a personal Secret Key. For financial institutions, correct pre-registration is a prerequisite for secure reporting.

goAML Registration Guide, March 2022

The goAML Registration Guide, issued by the UAE Financial Intelligence Unit in March 2022, sets out how an organisation registers with the FIU on the goAML platform as a reporting entity, stakeholder or supervisory body. All accountable and reporting entities must register to submit suspicious reports. It covers portal access, selecting registration type, entering data, access rights and password resets. For financial institutions, it underpins compliant reporting.

Strategic Review on Targeted Financial Sanctions Case Studies, November 2021

The Strategic Review on Targeted Financial Sanctions Case Studies, dated November 2021, examines how sanctions-related reports arise in the UAE under Cabinet Resolution No. 74 of 2020, which implements United Nations freezing measures on terrorism and proliferation financing. It classifies reports by source, suspicion and instrument, distinguishes terrorist from proliferation patterns, and presents red flags, statistics and recommendations. For financial institutions, it strengthens detection, screening and reporting.

Typologies on the Circumvention of Targeted Sanctions, November 2021

This typologies report, amended in November 2021 and issued by the Executive Office, compiles cases showing how sanctioned parties circumvent targeted sanctions on terrorism and proliferation, evading United Nations Resolutions and the national terrorist list. It groups methods by channel, covering banking, remitters, exchange houses, hawala, smuggling, dual-use trade, legal entities and virtual assets, with red flags. For financial institutions, it strengthens screening, due diligence and reporting.

Update to the List of High Risk Jurisdictions, November 2021

This November 2021 decision of the National AML/CFT Committee updates the lists of high-risk jurisdictions subject to a call for action and under increased monitoring, and the counter-measures to apply, updating an earlier March 2021 decision. For financial institutions, country risk is a core input: it signals which jurisdictions warrant enhanced due diligence and keeps risk assessments aligned with the latest listings.

Joint Guidance on Satisfactory and Unsatisfactory Practice, June 2021

The Joint Guidance on Satisfactory and Unsatisfactory Practice, issued in June 2021 by the UAE Supervisory Authorities, draws on inspections between January 2020 and May 2021. It contrasts satisfactory and unsatisfactory practices across governance, risk assessment, policies, training, customer due diligence, monitoring, sanctions screening, and reporting. It translates real inspection findings into concrete examples of supervisory expectations, helping firms benchmark their controls and remediate weaknesses before examination.

Typologies on the Circumvention of TFS, PF and WMD, May 2021

This typologies report, amended in May 2021 and issued by the Executive Office, examines how sanctioned parties receive financing in evasion of United Nations Resolutions on terrorism and proliferation of weapons of mass destruction. Organised by method, it covers banking, money remitters, hawala, online payments, non-profits, cash smuggling, cyberactivity, trade and legal entities, with red flags. For financial institutions, it supports stronger screening, monitoring and reporting.

goAML FAQs, September 2020

The goAML FAQs Guide, issued by the UAE Financial Intelligence Unit in September 2020, is a question-and-answer reference for reporting entities using the goAML platform. It gives step-by-step help on resetting passwords, updating organisation and personal details, and delegating reporting subject to Supervisory Body approval. For financial institutions, accurate registration data and managed access underpin timely, compliant reporting to the FIU.

goAML Registration Guide Stage 2, September 2020

The goAML Registration Guide Stage 2, issued by the UAE Financial Intelligence Unit in September 2020, outlines how an organisation registers with the FIU on the goAML platform as a reporting entity, stakeholder or supervisory body. All accountable and reporting entities must register, with electronic submission required since 27 June 2019. It covers portal access, registration type, access rights and password resets.

Emerging ML, TF and PF Risks and Trends in the Financial Sector

Emerging ML, TF, and PF Risks and Trends in the Financial Sector is a Supervisory Subcommittee report giving financial institutions an overview of current threats. Issued under Article 16 of Federal Decree-Law No. 10 of 2025, it examines artificial intelligence exploitation, ESG fraud, trade finance abuse, virtual assets, and sanctions evasion, with banking case studies, highlighting typologies and red flags for risk assessments and controls.

Guideline on Grievance Procedures

The Guideline on Grievance Procedures is issued by the Executive Office for Control and Non-Proliferation, which receives grievance requests related to the UAE Local Terrorist List and the UN Consolidated List. Under Cabinet Resolution No. 74 of 2020, it processes three types: de-listing, cancellation of freezing measures, and permission to use frozen assets. It explains the lawful routes affected customers may use, informing how institutions respond.

Online Grievance System User Guide

The Online Grievance System User Guide is issued by the Executive Office for Control and Non-Proliferation, which receives grievance requests related to the UAE Local Terrorist List and the UN Consolidated List. It walks users through the application form for three request types: de-listing, cancellation of freezing measures, and permission to use frozen funds, explaining the route affected customers use to challenge designations or access frozen assets.

Simple Guide to Subscribe to the EOCN Notification Alert System (NAS)

This short guide explains how to subscribe to the Notification Alert System operated through the Executive Office’s website, so users receive timely updates to the UAE sanctions lists: the Local Terrorist List and the UN Consolidated List. It gives step-by-step subscription instructions. For financial institutions, it supports a core control, since sanctions screening is only effective when firms work from current lists.

Typologies in the Financial Sector

Typologies in the Financial Sector, produced jointly by the Supervisory Authorities Sub-Committee and the Financial Intelligence Unit with the Executive Office, shares money laundering, terrorist financing, sanctions, fraud and corruption typologies observed in the market, several arising during COVID-19. It covers risks beyond the National Risk Assessment, including unlicensed money service operators and links to human trafficking. For financial institutions, it is an early warning tool.

CBUAE Guidance for Licensed Financial Institutions

Alongside the guidance that reaches every reporting entity, the Central Bank issues a dedicated body of guidance, rules and thematic reviews for the licensed financial institutions it supervises. These set the CBUAE’s specific expectations for banks and other financial institutions across risk assessment, due diligence, sanctions, reporting and sector-specific exposure.

CBUAE Thematic Review on Sanctions List Screening in the Banking Sector, May 2026

Conducted by the CBUAE’s AML/CFT Supervision Department and published in May 2026 under Cabinet Resolution No. 74 of 2020, this thematic review assessed how banks screen customers and transactions against the UAE Local Terrorist List and the UNSC Sanctions List. It examined whether banks screen at onboarding, periodically and on list updates, freeze without delay and notify the authorities of matches. For banks, it flags where sanctions screening programmes fall short.

CBUAE Best Practices on Implementing a Risk-Based Approach, October 2025

Published by the CBUAE in October 2025, this best-practice paper explains how licensed FIs should design a risk-based approach and run an institutional ML, TF and PF risk assessment. It covers assessing inherent risk across customers, products, delivery channels and geographies, testing the control environment, and determining residual risk. For banks, it clarifies expected methodology, granularity, governance and review frequency, so their programme is genuinely risk-driven rather than tick-box.

CBUAE Best Practices on Role-Based AML/CFT/CPF Training, October 2025

Released by the CBUAE in October 2025, this paper sets expectations for tailoring AML/CFT/CPF training to staff roles. It separates training for the board, owners and senior management from the three lines of defence, and covers new-hire, annual enterprise-wide, group and localised training. Banks are expected to match content, frequency and intensity to each function’s risk exposure, document a training plan, and keep records evidencing delivery and effectiveness.

CBUAE Guidance on Customer Due Diligence, KYC and Record-Keeping, October 2025

Published by the CBUAE in October 2025, this guidance treats CDD, KYC and record-keeping as the cornerstone of AML, sanctions and anti-fraud compliance. It covers identifying and verifying customers and beneficial owners, building a risk profile from source of funds, wealth and expected activity, ongoing monitoring, simplified and enhanced due diligence, name screening, non-face-to-face relationships, third-party reliance and customer exit. Banks must evidence robust CDD and retain supporting records.

CBUAE Guidance on Correspondent Banking, October 2025

Released by the CBUAE in October 2025, this guidance addresses how licensed FIs should manage correspondent banking relationships and cross-border payments. It examines risk factors such as nested relationships, payable-through accounts, geography, ownership and customer base, and sets out standard, specific and enhanced due diligence, ongoing monitoring, sanctions obligations and reporting. Annexes cover the SWIFT to ISO 20022 transition and RMA relationships, helping banks scrutinise respondent institutions proportionately.

CBUAE Guidance on Risks Related to Trade-Based Money Laundering and Transshipment, October 2025

Issued by the CBUAE in October 2025, this guidance helps licensed FIs understand and mitigate trade-based money laundering and illicit transhipment risks. It explains documentary and open-account trade finance, typologies such as over-invoicing and under-invoicing, multiple invoicing, shell companies and free-trade-zone misuse, and vulnerable sectors like gold and vehicles. For banks, it prescribes enterprise-wide risk assessment, customer and enhanced due diligence, sanctions screening, transaction monitoring and reporting.

CBUAE Guidance on Risks Related to Proliferation Finance, October 2025

Issued by the CBUAE in October 2025, this guidance helps licensed FIs counter the financing of weapons of mass destruction proliferation. It maps threats and vulnerabilities across trade finance, correspondent banking, hawala, free trade zones, shell companies and precious metals, then sets out risk assessment, customer and enhanced due diligence, transaction monitoring and targeted financial sanctions duties. In practice, banks must build proliferation finance risk into their controls and export-control screening.

Federal Decree-Law No. 6 of 2025 on the Central Bank and the regulation of financial institutions

Federal Decree-Law No. 6 of 2025 is not the AML law, but it is the licensing and supervisory foundation for the Central Bank-regulated institutions covered here, including banks, exchange houses, finance companies, insurers and hawala providers. Issued on 8 September 2025, it governs the Central Bank and the regulation of licensed financial institutions and activities and insurance business. It repealed Federal Decree-Law No. 14 of 2018, the previous Central Bank law, and Federal Decree-Law No. 48 of 2023 on insurance activities, and regulations and circulars issued under those laws remain in force until they are replaced.

CBUAE AML/CFT Guidelines for Financial Institutions, July 2023

Issued by the CBUAE in July 2023, these are the flagship AML/CFT guidelines for financial institutions. They walk banks and other FIs through the UAE legal framework, the risk-based approach, business-wide risk assessment, customer due diligence and enhanced due diligence, wire transfers, ongoing monitoring, suspicious transaction reporting and record-keeping. In practice, they set the baseline compliance expectations against which supervised institutions must show they meet their statutory obligations.

CBUAE Guidance on Risks Related to Virtual Assets and VASPs, February 2023

Issued by the CBUAE on 20 February 2023, this guidance sets out how licensed FIs should identify and mitigate money laundering and terrorist financing risks from virtual assets and virtual asset service providers. It covers the UAE regulatory framework, the non-objection process for opening VASP accounts, customer due diligence, enhanced measures for higher-risk customers, transaction monitoring, sanctions obligations and proprietary virtual asset investments, giving banks concrete red flags and expectations.

CBUAE Guidance on Digital Identification for Customer Due Diligence, October 2022

Dated 31 October 2022, this CBUAE guidance explains how licensed FIs may use digital identity systems for customer due diligence. It describes identity proofing, enrolment, authentication and lifecycle management, and the risks these systems present. Crucially, it helps banks assess a system’s reliability and independence through assurance levels and decide on appropriate use in the context of risk, including customer verification, ongoing due diligence and third-party reliance.

CBUAE Guidance on Suspicious Transaction Reporting, August 2022

Published by the CBUAE on 3 August 2022, this document guides licensed FIs on identifying and reporting suspicious transactions across the three lines of defence. It addresses the compliance officer and MLRO role, manual and automated monitoring, how to draft and submit STRs and SARs through goAML, review and filing timelines, tipping-off prohibitions and record retention. For banks, it clarifies disclosure duties, legal protections and the consequences of failing to report.

CBUAE Guidance on the Risks Relating to Politically Exposed Persons, August 2022

The CBUAE issued this guidance on 1 August 2022 to help licensed FIs manage risks from politically exposed persons. It sets out the requirements for classifying customers as PEPs and related customers, time limits on PEP status, screening, risk rating and enhanced due diligence. It also covers transaction monitoring, suspicious transaction reporting, governance and training, and gives red flag indicators so banks can apply proportionate scrutiny to higher-risk relationships.

CBUAE Guidance on the Risks Relating to Payments, August 2022

Dated 1 August 2022, this CBUAE guidance addresses money laundering and terrorist financing risks in the payments sector. It examines peer-to-peer and cross-border payments, intermediation, nesting, use of agents and merchant risks, alongside obligations for stored value facilities, retail payment services and card schemes. Banks are directed to conduct risk assessment, apply customer and enhanced due diligence, wire transfer controls, correspondent due diligence, sanctions screening and reporting.

CBUAE Guidance on Transaction Monitoring and Sanctions Screening, September 2021

The CBUAE issued this guidance on 8 September 2021, requiring licensed FIs to show compliance within one month. It explains how to build risk-based transaction monitoring and sanctions screening programmes, covering risk assessment, data management, rule definition and testing, alert scoring, name and transaction screening, list management, and post-implementation tuning. In practice, banks must govern, audit and staff these systems, manage third-party vendors and keep supporting records.

CBUAE Guidance for Cash-Intensive Businesses, September 2021

Dated 27 September 2021, this CBUAE guidance addresses the money laundering vulnerabilities of cash, bearer instruments, prepaid cards, cash couriers and currency exchanges. It expects licensed FIs to run enterprise risk assessments, apply customer and enhanced due diligence, monitor transactions and file suspicious transaction reports. For banks, that means tighter scrutiny of customers who handle large volumes of cash and clearer expectations on documenting the source of those funds.

CBUAE Guidance for Registered Hawala Providers and LFIs, August 2021

Issued by the CBUAE on 15 August 2021, this guidance covers both registered hawala providers and the banks that serve them. It sets registration, sanctions freezing, AML/CFT programme, customer due diligence, record-keeping and goAML reporting duties for hawala providers, and a risk-based approach for licensed FIs banking them. In practice, banks must understand and manage the money laundering and terrorist financing risks these money remitters bring into the system.

CBUAE Guidance on the Implementation of Targeted Financial Sanctions, July 2021

Issued by the CBUAE on 4 July 2021, this guidance directs licensed FIs on implementing targeted financial sanctions. It requires a sanctions compliance programme with senior management commitment, risk assessment, internal controls, training, independent audit and record-keeping, plus screening against the UN Consolidated List and Local Terrorist List, handling of false positives, and payment screening. Banks must freeze without delay on a confirmed match and notify the CBUAE and Executive Office.

CBUAE Guidance on Services to Legal Persons and Arrangements, June 2021

Published by the CBUAE on 7 June 2021, this guidance tackles how companies, trusts and similar structures can obscure beneficial ownership, purpose and source of funds. It explains formation, beneficial owner identification and UAE economic substance rules, and requires licensed FIs to risk-rate such customers, verify ownership and control, monitor them and file suspicious transaction reports. For banks, it sharpens expectations on unwrapping who really owns and controls corporate clients.

CBUAE Guidance for the Real Estate and Precious Metals and Stones Sectors, June 2021

Issued by the CBUAE on 16 June 2021, this guidance helps licensed FIs manage ML and TF risk when serving real estate businesses and dealers in precious metals and stones. It explains sector-specific risks, typologies and red flags, then sets out mitigating measures covering the risk-based approach, customer and enhanced due diligence, suspicious transaction reporting, governance and training. For banks, it means calibrating controls to these high-value, cash-exposed sectors.

CBUAE STR Outreach for Banks and Finance Companies, March 2021

Delivered on 10 March 2021, this CBUAE outreach session brought together the Financial Intelligence Unit, AML/CFT Supervision and the Ministry of Interior to brief banks and finance companies on suspicious transaction reporting. Drawing on the AML law, it explains when and what to report, goAML as the sole reporting channel, the different report types and the compliance officer’s duties. It reinforces prompt, well-grounded STR filing as a core supervisory expectation.

CBUAE Board of Directors Decision No. 59/4/2019 on AML/CFT Procedures, 2019

Issued by the CBUAE Board of Directors on 13 June 2019, Decision No. 59/4/2019 sets the procedures for anti-money laundering and combating the financing of terrorism and illicit organisations. It requires every financial institution and its concerned persons to comply with the federal AML law, its Executive Regulation and Central Bank instructions, guidelines and notices, and empowers the Central Bank to impose administrative sanctions, subject to a right of appeal. It replaced Circular No. 24/2000.

CBUAE Guidance Note on the Responsible Use of AI and Machine Learning by LFIs

This CBUAE guidance note sets principles for the responsible, consumer-focused use of artificial intelligence and machine learning by licensed FIs. It addresses governance and board accountability, fairness and non-discrimination, transparency and explainability, data quality and privacy, continuous monitoring, human oversight and third-party risk. It flags high-impact decisions such as loan or insurance outcomes and expects banks to build these principles into their AI and machine learning policies and existing risk frameworks.

CBUAE List of Administrative and Financial Sanctions

This CBUAE document explains the Central Bank’s enforcement powers over financial institutions with weak AML and sanctions frameworks. Penalties range from a warning through mandatory remediation to restrictions, senior-management removal and licence revocation, alongside financial fines set per violation. The scale can reach very substantial sums under the Central Bank Law. For banks, it signals that supervisory consequences are dissuasive, proportionate and consistently applied across the sector.

NRA, SRA, and Other Important Guidelines Applicable to Banks and Financial Institutions in UAE

The UAE assesses its money laundering, terrorist financing, and proliferation financing risk at the national level, and the law expects every financial institution to align its own business and enterprise-wide risk assessment with those findings. The two assessments below are the anchor documents, and the sector ratings that follow show where banks and financial institutions actually sit, in the mainland and in the financial free zones.

UAE PF National Risk Assessment 2026

The UAE Proliferation Financing National Risk Assessment 2026 examines exposure to the financing of weapons of mass destruction and evasion of targeted sanctions on the DPRK and Iran. Overall country risk is medium-high. Virtual asset service providers are high in the mainland, banks, exchange houses and hawala providers medium-high, free zone banks and money service businesses medium, stored value facilities medium-low. For financial institutions, it guides screening and controls.

The table below summarises the residual risk ratings that banks and financial institutions should reflect in their own risk assessments.

UAE ML and TF National Risk Assessment 2024

The UAE Money Laundering and Terrorist Financing National Risk Assessment 2024, the country’s second, rates threats and residual risks across mainland and free zone financial sectors using 2019 to 2023 data. Overall, the national money laundering risk is medium-high. Banking, exchange houses and securities are medium-high; hawala providers are high; finance companies and insurance are medium. For financial institutions, it sets the national baseline for their risk-based controls.

Sub-sector 

ML and TF residual risk 

PF residual risk 

Banking 

Medium-high (mainland); medium to medium-high (free zones) 

Medium-high (mainland); medium (free zones) 

Exchange houses and MSBs 

Medium-high 

Medium-high (mainland); medium for free zone MSBs 

Registered hawala providers 

High 

Medium-high (mainland); not permitted in free zones 

Finance companies 

Medium 

Not separately rated 

Insurance 

Medium 

Medium for maritime (mainland); medium-low (free zones) 

Capital market and securities 

Medium range, effective controls 

Low (mainland and free zones) 

Alongside the national assessments, sector risk assessments, red flag guidance, and typologies reports give financial institutions the detail they need to keep their enterprise-wide risk assessment current and defensible.

Core AML Obligations at a Glance

Whatever the sector, the AML regulations for banks and financial institutions in the UAE turn on a common set of duties. This is the overview; each is covered in depth in its own guide.

Expert Tip:

Supervisors usually look beyond a single alert in isolation. They test whether the institution has a risk assessment aligned to the national risk assessment, documented alert handling and escalation, and a compliance officer who can show independence and authority. Systemic weaknesses and high-risk or sanctions-related failures that are poorly documented are what draw findings. Get the risk assessment and the compliance function right, and the rest becomes defensible.

Sub-Sector Guides for Financial Institutions in UAE

Use this page as the map, then go to the sector guide that fits your licence for the detailed rules, checklists, and templates.

  • AML regulations for banks in UAE: the deposit-taking, lending, payments, and trade finance obligations that carry the deepest AML duties.
  • AML regulations for insurance companies and brokers in UAE: how life and investment business is brought inside the AML perimeter, and what insurers and intermediaries must do.
  • AML regulations for exchange houses in UAE: currency exchange, remittance, and banknote controls for a cash-intensive, cross-border sector.
  • AML regulations for registered hawala providers in the UAE: registration, record-keeping, and reporting duties for the highest residual-risk financial sub-sector.
  • AML regulations for capital market firms in UAE: client onboarding, screening, and monitoring for brokerages, custodians, and fund managers under the Capital Market Authority.
  • AML regulations for finance companies in UAE: how credit and financing providers apply the core AML controls, scaled to their products.
  • AML regulations for other LFIs in UAE: the catch-all for payment, stored value, and other licensed financial activities captured by the definition.

Conclusion

AML regulations for banks and financial institutions in the UAE come down to three questions: are you a financial institution, who supervises you, and which parts of the framework apply? For the great majority of licensed firms, the answer is that you are covered, the Central Bank or your free zone regulator supervises you, and the full stack of Federal Decree-Law No. 10 of 2025, its Executive Regulations, the sanctions rules, and the supporting guidance all apply. Use the national risk assessments to calibrate your programme to the real threats in your sub-sector, treat this page as your starting point, and use the sector guides to turn the framework into day-to-day controls. This is a fast-moving area, so review your obligations against the latest guidance regularly. For a wider view, see our guide to anti-money laundering laws in the UAE.

Frequently Asked Questions

What is the AML risk rating for banks in the UAE?

The UAE ML and TF National Risk Assessment 2024 rates the banking sector at medium-high residual risk, with an inherent risk of high because of the sector’s size, cross-border reach, and exposure to high-risk customers. For proliferation financing, mainland banks are rated medium-high, largely through trade finance, while banks in the financial free zones are rated medium.

Yes. Hawala is legal only when the provider is registered with the Central Bank, and registered hawala providers must run customer identification, record-keeping, and suspicious transaction reporting. The sector carries the highest residual money laundering rating of any financial sub-sector, and hawala is not permitted to operate in the financial free zones.

Among the core financial institutions, registered hawala providers carry the highest residual money laundering risk. For proliferation financing, virtual asset service providers carry the highest exposure, which is relevant to any bank or institution that services them.

Exchange houses are rated medium-high for money laundering and terrorist financing, driven by cash handling, banknote shipments, reliance on foreign remittance partners, and third-party transactions. They are supervised by the Central Bank and must apply full customer due diligence and screening.

Firms in the DIFC are supervised by the DFSA and firms in the ADGM by the FSRA, each under its own AML rulebook that sits alongside the federal law. In practice, financial free zone banks and money service businesses tend to carry lower proliferation financing risk than their mainland counterparts because they are account-based, cash is not permitted, and many are branches of global banks.

The insurance sector is rated medium for money laundering, reflecting the limited ways life and investment products can be abused, and maritime insurance is rated medium for proliferation financing in the mainland. Insurers and intermediaries carrying out relevant business are financial institutions and must apply customer due diligence, screening, and reporting.

No. Securities firms are rated low for proliferation financing in both the mainland and the free zones, and their money laundering risk sits in the medium range, with controls assessed as effective. They do not take cash deposits, but they must still identify clients, screen against sanctions lists, and monitor for market-based laundering under the Capital Market Authority framework.

Yes. Finance companies are licensed by the Central Bank, are rated medium residual risk for money laundering, and must run the full set of core AML controls scaled to their credit and financing products.

Need help mapping these obligations to your licence?

Understand your AML obligations with expert guidance tailored to your banking licence and regulatory requirements.

Share via :

About the Author

Pathik Shah

FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)

Pathik is an ACAMS-certified AML consultant specialising in governance, risk, and compliance for regulated entities in the UAE. He brings over 28 years of experience, with 1,000+ hours of AML training and 200+ advisory engagements across DNFBPs, VASPs, and FIs. He supports businesses in aligning with AML/CFT requirements from the CBUAE, DFSA, MoET, MoJ, VARA, CMA, FSRA, and FATF. Known for translating complex regulations into audit-ready procedures, Pathik enables operational clarity and compliance readiness.

Reach Out to Pathik

AML Regulations for Banks in UAE

AML Regulations for Banks in UAE

Blogs

Published On: 07/07/2026

Table of Contents

Protect your business with reliable and effective AML strategies with AML UAE.

Last Reviewed On: 07/07/2026   |   Last Updated On: 07/07/2026

Key Highlights

  • Banks are Licensed Financial Institutions under Federal Decree-Law No. 10 of 2025 and its Executive Regulations in Cabinet Resolution No. 134 of 2025, so CBUAE AML/CFT/CPF guidance for LFIs applies to them where relevant to their activities, products, customers, delivery channels and geographic exposure.
  • The Central Bank of the UAE is the primary AML supervisor for banks in mainland UAE and the commercial free zones. Banks in the DIFC and ADGM answer to the DFSA and FSRA and sit outside this guide.
  • The banking sector’s residual money laundering risk is rated medium-high in the national risk assessment, with an inherent risk of high, and its proliferation financing risk is medium-high, mainly through trade finance.
  • Core obligations run across every bank: risk assessment, customer due diligence, sanctions screening, transaction monitoring, record-keeping, and suspicious transaction reporting through goAML.
  • On top of the federal laws, the Central Bank issues a deep body of guidance for licensed financial institutions that shapes day-to-day banking compliance.
  • This article catalogues the whole framework and links up to the banks and financial institutions pillar for the wider view.

Banks are among the most important and closely supervised parts of the UAE financial system for anti-money laundering. They take deposits, lend, move money across borders, and finance trade, so many major money laundering, terrorist financing and sanctions typologies involve banks directly or indirectly. This guide sets out the AML regulations for banks in the UAE: who is in scope, who supervises them, the full legal framework that applies, and how the national risk assessments rate the banking sector’s money laundering, terrorist financing, and proliferation financing risk. It covers banks licensed by the Central Bank of the UAE in mainland UAE and the commercial free zones.

Question Direct answer 
Who supervises UAE banks for AML? The CBUAE, for banks it licenses outside the DIFC and ADGM. 
What is the main AML law? Federal Decree-Law No. 10 of 2025. 
What is the executive regulation? Cabinet Resolution No. 134 of 2025. 
Where are suspicious reports filed? With the UAE FIU through goAML. 
What are the main bank AML controls? AML Programme consisting of ML/FT risk assessment, policy, controls, and procedures, customer due diligence, beneficial ownership checks, sanctions screening, transaction monitoring, STR and SAR reporting, record-keeping, governance and training. 

What counts as a bank for AML purposes in the UAE?

A bank, for AML purposes, is any institution licensed by the Central Bank of the UAE to carry on banking business, whether it operates in mainland UAE or in a commercial free zone. The categories below all sit inside the AML regulations for banks in the UAE. Banks established in the financial free zones of the DIFC and ADGM are supervised by the DFSA and FSRA under their own rulebooks and are not covered here.

Commercial banks

Commercial banks take retail and corporate deposits, lend, and provide payment, card, and everyday banking services. Their scale, their reach across the customer base, and their exposure to cash, wire transfers, and high-risk customers put them at the front line of AML risk and give them the deepest set of obligations.

Wholesale banks

Wholesale banks focus on corporate, institutional, and high-value business rather than retail customers. Their exposure runs through corporate structures, trade finance, and cross-border flows, which is where much of the sector’s proliferation financing and trade-based laundering risk concentrates.

Branches of foreign banks

Branches of foreign banks licensed by the Central Bank must run a full local AML programme, even where their head office operates its own global controls. They remain answerable to the Central Bank for their UAE activities and must meet the same core local AML/CFT/CPF obligations for their UAE activities, subject to the terms of their CBUAE licence.

AML Supervisory Authority for Banks in the UAE

Supervision of banks in mainland UAE and the commercial free zones rests with a single authority.

Central Bank of the UAE (CBUAE)

The Central Bank of the UAE licenses banks, supervises their AML programmes, issues the guidance that shapes their controls, and inspects them. It runs thematic reviews and skilled persons’ reviews of bank AML programmes and can impose administrative and financial penalties, restrict activities, or withdraw a licence for breaches. Banks in the DIFC and ADGM are supervised instead by the DFSA and FSRA and fall outside this guide.

UAE FIU and goAML

Banks in scope of this guide submit suspicious transaction and activity reports and related filings to the UAE Financial Intelligence Unit through goAML. Registration on goAML is a baseline obligation, and suspicious transaction reports, suspicious activity reports, and related filings are submitted through it. See our goAML registration guide for the practical steps.

AML Legal Framework Applicable to Banks in the UAE

The framework has four layers: the core federal laws, the guidance that applies to all reporting entities, the national risk assessments, and the Central Bank’s guidance for licensed financial institutions. This section catalogues each layer, grounded in the Banks CBUAE library. Because banks are Licensed Financial Institutions, every instrument addressed to LFIs applies to them.

Federal AML Laws and Executive Regulations Applicable to Banks in the UAE

These instruments are the legal foundation for every bank in scope.

Federal Decree-Law No. 10 of 2025 on AML, CFT and CPF

Federal Decree-Law No. 10 of 2025 is the principal statute governing anti-money laundering, counter-terrorist financing, and proliferation financing in the United Arab Emirates. It sets the core definitions, including money laundering, predicate offences, targeted financial sanctions, and suspicious transactions, and it recognises offences committed through digital systems, virtual assets, and cryptographic technologies. It establishes the Financial Intelligence Unit within the Central Bank as the independent body to which banks must submit all suspicious transaction reports exclusively, empowering the Unit to request information and freeze suspect funds. For banks, the Decree-Law is the source of their core duties, supervisory oversight, and administrative penalties, functioning as the layer beneath every subordinate regulation.

Cabinet Resolution No. 134 of 2025, the Executive Regulations

Cabinet Resolution No. 134 of 2025 issues the Executive Regulations of Federal Decree-Law No. 10 of 2025, translating the statute into the operating rules that financial institutions must follow. It carries over the Decree-Law definitions and adds concepts such as senior management, beneficial owner, reasonable measures, correspondent and payable-through accounts and wire transfers. It identifies in-scope activities, expressly including banking, securities, funds transfers, and money and currency exchange. The Regulations set the substantive obligations: a risk-based approach, customer due diligence, beneficial owner identification and verification, ongoing monitoring, and internal policies approved by senior management. For banks, this is the practical rulebook that supervisors test in examinations and enforcement.

Cabinet Resolution No. 109 of 2023 on beneficial owner procedures

Cabinet Resolution No. 109 of 2023 regulates the beneficial owner procedures for legal persons licensed or registered in the United Arab Emirates. It defines the real beneficiary as the natural person who ultimately owns or controls a legal person, whether directly or through a chain of ownership or other indirect means. It requires legal persons to maintain accurate information on their beneficial owners, identify board nominee members, and keep beneficial owner and shareholder registers updated, generally within fifteen days of changes. This matters to banks, which rely on ownership data to verify beneficial owners behind corporate customers. These procedures apply to legal persons licensed or registered in the State, including commercial free zones, but exclude the financial free zones, the DIFC and ADGM, which operate their own beneficial ownership regimes.

Cabinet Resolution No. 132 of 2023 on penalties for beneficial owner violations

Cabinet Resolution No. 132 of 2023 sets out the administrative penalties for violations of the beneficial owner procedures established under Cabinet Resolution No. 109 of 2023. It empowers the registrar to impose fines, under an annexed schedule of violations and penalties, on legal persons that fail to maintain accurate registers or provide required information. Consequences escalate: on a third violation, the registrar may suspend the commercial licence and close the premises until the fine is paid and the breach corrected. For banks, this reinforces why corporate customers must keep beneficial ownership data current. These penalties apply to legal persons licensed or registered in the State, including commercial free zones, but not to the financial free zones, the DIFC and ADGM, which follow their own regime.

Cabinet Resolution No. 74 of 2020 on terrorist lists and UNSC resolutions

Cabinet Resolution No. 74 of 2020 regulates the terrorist lists and governs how the United Arab Emirates implements United Nations Security Council resolutions on terrorism, its financing, and the proliferation of weapons of mass destruction. It provides for a local list issued by the Cabinet, gives effect to the Security Council sanctions lists, and defines designation, listing, and de-listing. Freezing measures must be applied without delay, within twenty-four hours. For banks, it establishes the core sanctions duties: registering on the Executive Office website for notifications, continuously screening customers, beneficial owners, and transaction parties against the lists, freezing any match without prior notice, and reporting promptly to the supervisory authority.

Federal Law No. 7 of 2014 on combating terrorism crimes

Federal Law No. 7 of 2014 on Combating Terrorism Crimes is the criminal statute that defines terrorist offences in the United Arab Emirates and fixes the penalties attached to them. It sets out concepts such as terrorist crime, terrorist purpose, terrorist organisation, and terrorist person, and it distinguishes conventional from nonconventional weapons, including toxins, pathogenic agents, and radioactive materials. Penalties reach life imprisonment and, in specified circumstances, the death penalty. Of direct relevance to banks is its treatment of terrorism financing: it penalises providing, collecting, preparing, or maintaining funds for a terrorist purpose, and addresses freezing suspect funds, including those deposited in financial institutions.

AML Guidance Applicable to All Reporting Entities

Beyond the core laws, the Central Bank, the UAE FIU and the Executive Office issue guidance, typologies and reporting materials that banks should consider where relevant to their AML/CFT/CPF obligations and risk exposure.

UAE FIU Regulation No. 1 of 2026 on Suspension and Freezing Powers, April 2026

UAE FIU Regulation No. 1 of 2026, dated April 2026, governs the postponement or suspension of suspicious transactions and the freezing of funds. Issued under the AML/CFT Decree-Law and its Executive Regulation, it applies to reporting entities, including financial institutions. It introduces the Postponement Suspicious Transaction Report, an urgent filing where funds suspected of crime risk imminent transfer, withdrawal or dissipation, with a monetary threshold that does not apply to higher threat offences, third party laundering, organised crime or terrorist financing. It defines a Suspension Order of ten working days and a Freezing Order of thirty days. For banks, it is a fast-track mechanism preserving funds at risk.

UAE FIU Strategic Analysis Report on Human Trafficking, April 2026

The UAE FIU Strategic Analysis Report on Human Trafficking, dated April 2026, analyses money laundering and related financial flows connected to human trafficking, drawing on suspicious transaction and activity reports filed with the Financial Intelligence Unit. It sets out objectives, methodology and scope, covering sexual exploitation, forced labour and organ removal. It identifies patterns, including child sexual abuse material, laundering of trafficking proceeds and convergence with other crime, and profiles subjects such as organised crime groups, foreign politically exposed persons and money mules. It assesses the vulnerability of sectors, including financial institutions, and develops indicators around customer profile, behaviour, transactions and due diligence. For banks, it links trafficking to behaviour.

Guidance on Targeted Financial Sanctions for Financial Institutions, DNFBPs and VASPs, March 2026

The Guidance on Targeted Financial Sanctions for Financial Institutions, DNFBPs and VASPs, issued by the Executive Office for Control and Non-Proliferation, was first published in January 2021 and last amended in March 2026. It clarifies reporting entities’ obligations under the UAE’s targeted financial sanctions framework, which prevents misuse of the financial system for terrorism financing, proliferation financing and sanctions evasion. It sets out four obligations: registering in the Notification Alert System, screening against the Local Terrorist List and United Nations Consolidated List, freezing assets without delay, and reporting measures taken. The March 2026 update renames the Funds Freeze Report as the Confirmed Name Match Report, defining compliant screening for banks.

Joint Guidance on the Compliance Officer and MLRO, 2026

The Joint Guidance on the Compliance Officer and Money Laundering Reporting Officer, issued in 2026 by the UAE Supervisory Sub-Committee, establishes a unified framework for the appointment, authority and responsibilities of the officer across regulated sectors. It applies to institutions supervised by the Central Bank of the UAE, the Securities and Commodities Authority, the Ministry of Justice and the Ministry of Economy and Tourism, building on Federal Decree-Law No. 10 of 2025, Cabinet Resolution No. 134 of 2025 and the 2025 framework. Recognising the role as a cornerstone of compliance, it sets expectations on seniority, experience, independence and board access. For banks, it clarifies how to appoint a fit officer.

FIU Strategic Analysis Report on Terrorist Financing, May 2025

The FIU Strategic Analysis Report on Terrorist Financing, published in May 2025 and subtitled Terrorist Financing Typologies and Facilitators, is produced by the UAE Financial Intelligence Unit. It draws on data from January 2021 to December 2024, including suspicious transaction and activity reports, cases disseminated to authorities, counterpart requests and open source material. It explains how terrorist financing works and reviews global typologies. It sets out transactional patterns such as moving funds through banks, unlicensed hawala, corporate networks, trade-based financing, high-value goods, real estate, virtual assets and crowdfunding. It examines facilitators and concludes with risk indicators that help banks detect, trace and report suspicious terrorist financing activity.

goAML FAQs, April 2024

The goAML FAQs, version 2.1 dated 18 April 2024, are a practical question-and-answer guide published by the UAE Financial Intelligence Unit to help reporting entities use the goAML reporting system and its registration and access services. It addresses common problems users encounter when registering and logging in, providing step-by-step remedies. It walks through expired one-time passwords during the first login, pop-up authentication requiring the system-issued username with a Google Authenticator passcode, the correct login sequence, and resetting a forgotten password. It sets out whom to contact when errors persist. For banks, the FAQs reduce friction in reporting, helping compliance teams meet obligations without avoidable delays.

PF Institutional Risk Assessment Guidance for FIs, DNFBPs and VASPs, December 2023

The Proliferation Financing Institutional Risk Assessment Guidance, published in December 2023, sets out how banks and other financial institutions should assess and manage exposure to proliferation financing. It explains a methodology built around inherent risks, control effectiveness and residual risks, and identifies the risk categories and factors institutions should consider when scoring their business. It describes mitigating measures covering client onboarding, customer due diligence, enhanced due diligence, sanctions and adverse media screening, ongoing and transaction monitoring, suspicious activity reporting, and employee training. It provides a customer risk scoring questionnaire, elevated risk factors and worked case studies. For banks, it translates proliferation financing obligations into a practical framework for calibrating controls.

Terrorist and Proliferation Financing Red Flags Guidance, December 2023

The Terrorist and Proliferation Financing Red Flags Guidance, updated in December 2023, gives banks a consolidated list of indicators to identify suspicious terrorist financing and proliferation financing activity, including evasion of targeted financial sanctions imposed under United Nations Security Council Resolutions or local designations. It explains how sanctioned parties evade controls through renaming, intermediaries, front companies and alternative networks. After setting out the legal basis for reporting, it presents terrorist financing red flags, then proliferation indicators grouped into customer profile, account and transaction activity, maritime and trade finance categories. For banks, it is a working reference for front-line and compliance teams, sharpening detection and informing reporting decisions.

Suspicious Activity and Transaction Reporting Thematic Review, January 2023

The Suspicious Activity and Transaction Reporting Thematic Review, issued in January 2023, sets out the key findings and regulatory expectations from the 2022 AML/CFT examination of licensed financial institutions and designated non-financial businesses and professions. It focuses on the suspicious transaction and activity reporting framework and the transaction monitoring systems feeding it, and is read alongside existing reporting and monitoring guidance. Organised around regulatory expectations with acceptable and deficient practices, it covers governance, policies, risk-based deployment of monitoring controls, data management, alert review, case investigation and reporting decisions. It applies across banks, exchange houses, finance companies and payment service providers, giving banks a practical benchmark before inspection.

Counter Proliferation Financing Guideline, November 2022

The Counter Proliferation Financing Guideline, published in November 2022 by the Executive Office for Control and Non-Proliferation, supplements the wider Guidance on Targeted Financial Sanctions. It raises awareness among banks and other regulated entities of proliferation financing threats, risks and vulnerabilities, helping them identify, assess and mitigate those risks in line with Financial Action Task Force standards. It explains what proliferation financing means, its stages and the UAE framework, including the interagency mechanism and federal laws. It covers building this risk into a bank’s assessment, preventive measures such as enhanced due diligence, correspondent banking, trade finance and dual-use goods, staff training, and red flags, clarifying obligations under Security Council Resolutions.

goAML Web Submission Guide, July 2022

The goAML Web Submission Guide, issued by the UAE Financial Intelligence Unit in July 2022, sets out the steps to follow when submitting a report to the FIU through the goAML platform. It is addressed to the designated Compliance Officer or Money Laundering Reporting Officer of a registered reporting entity, or the deputy where the lead officer is unavailable. It provides an overview of report types, including the Suspicious Transaction Report and the Suspicious Activity Report covering attempted, non-executed transactions, plus Additional Information Files, Request for Information and High Risk Country reports. It explains accessing goAML and completing the report cover. For banks, it standardises reporting.

Joint Guidance on Combating the Use of Unlicensed Virtual Asset Providers, March 2022

The Joint Guidance on Combating the Use of Unlicensed Virtual Asset Providers in the UAE, issued in March 2022, is a joint publication of the UAE Supervisory Authorities, including the Central Bank of the UAE, the Securities and Commodities Authority and the Virtual Assets Regulatory Authority. Aligned with Financial Action Task Force guidance on a risk-based approach, it educates the public and regulated entities on the risks of unlicensed virtual asset service providers. It reminds banks of their anti-money laundering obligations, setting expectations on vigilance, due diligence, transaction analysis, controls and reporting. It provides red flags such as absent licences, no physical presence, unrealistic promises and pressure to invest quickly.

IEMS User Guide for Reporting Entities, March 2022

The IEMS User Guide for Reporting Entities, dated March 2022, is a practical manual from the UAE Financial Intelligence Unit for its Integrated Enquiry Management System. The system automates requesting information, implementing public prosecutions’ decisions and handling other anti-money laundering and counter-terrorist financing requests from domestic authorities, providing an end-to-end flow between the Unit, authorities and reporting entities. It explains how banks register and log in, reuse goAML credentials, and reach the system through the Services or eServices portals. It describes the dashboard, request management and the reply and attachments workflow, and the Admin, Maker and Checker roles. For banks, it shows how to action enquiries and freeze instructions.

goAML Pre-Registration Guide, March 2022

The goAML Pre-Registration Guide, issued by the UAE Financial Intelligence Unit in March 2022, explains how reporting entities secure access to the Services Access Control Manager, known as SACM, before reaching the goAML application to register and file suspicious reports. The application is available through a public portal for reporting entities not regulated by the Central Bank of the UAE, except hawaladars, while entities under various Supervisory Bodies follow the steps set out. It describes SACM as the gateway to the goAML environments, with access controlled by a time-based one-time password through Google Authenticator, and explains how to secure a personal Secret Key. For banks, correct pre-registration enables secure access.

goAML Registration Guide, March 2022

The goAML Registration Guide, issued by the UAE Financial Intelligence Unit in March 2022, sets out the steps an organisation follows when registering with the FIU on its reporting platform, goAML. It applies to registration as a reporting entity, stakeholder or supervisory body, and explains that all accountable and reporting entities in the United Arab Emirates, regardless of their regulator, must register to submit suspicious reports. It describes reaching the portal through the Services Access Control Manager, noting that Central Bank-regulated institutions require a dedicated MPLS link while others use the internet, then covers registration type, organisation and person data and access rights. For banks, correct registration underpins timely reporting.

Strategic Review on Targeted Financial Sanctions Case Studies, November 2021

The Strategic Review on Targeted Financial Sanctions Case Studies, dated November 2021, examines targeted financial sanctions reporting in the United Arab Emirates over the review period. It sits within the framework under which the UAE, through Cabinet Resolution No. 74 of 2020, implements United Nations Security Council Resolutions on terrorism, terrorist financing and the financing of the proliferation of weapons of mass destruction, including freezing measures and prohibitions on providing funds and services. It sets out its methodology, then classifies reports by source, suspicion and instruments involved, distinguishing terrorist financing from proliferation financing, with red flags and recommendations. For banks, it shows how sanctions-related suspicions arise and are reported.

Typologies on the Circumvention of Targeted Sanctions, November 2021

This typologies report, last amended in November 2021 and issued by the Executive Office, compiles cases showing how sanctioned persons, groups and entities attempt to circumvent targeted sanctions relating to terrorism and the proliferation of weapons of mass destruction. Drawing on public sources from the UAE and abroad, it presents methods used to evade United Nations Security Council Resolutions and the UAE’s national terrorist list. It groups typologies by channel and sector, covering banking services, money remitters, exchange houses, hawala, online payments, non-profit misuse, cash and gold smuggling, dual-use goods, virtual assets and legal entities. For banks, it turns evasion tactics into learning that strengthens screening, monitoring and reporting.

Update to the List of High Risk Jurisdictions, November 2021

This November 2021 decision of the National Anti-Money Laundering and Combatting the Financing of Terrorism and Financing of Illegal Organisations Committee updates the list of high-risk jurisdictions subject to a call for action, the list under increased monitoring, and the counter-measures to apply, replacing an earlier March 2021 decision. Addressed to the supervisory authorities and the Financial Intelligence Unit, it reflects the Committee’s mandate to identify high-risk countries and instruct supervisors to ensure due diligence is applied by financial institutions. For banks it matters because country risk is a core input to risk based controls, signalling which jurisdictions warrant enhanced due diligence and keeping risk assessments current.

Joint Guidance on Satisfactory and Unsatisfactory Practice, June 2021

The Joint Guidance on Satisfactory and Unsatisfactory Practice, issued in June 2021, is a joint publication of the UAE Supervisory Authorities, including the Central Bank of the UAE, the Dubai Financial Services Authority, the Financial Services Regulatory Authority, the Securities and Commodities Authority and the Ministries of Justice and Economy. Drawing on supervisory inspections between January 2020 and May 2021, it contrasts satisfactory and unsatisfactory practices in the anti-money laundering framework, targeted financial sanctions and counter proliferation financing. For banks it covers governance, risk assessment, three lines of defence, policies, training, the compliance officer role, onboarding, monitoring, due diligence, sanctions screening and suspicious transaction reporting, helping firms benchmark controls.

Typologies on the Circumvention of TFS, PF and WMD, May 2021

This typologies report, last amended in May 2021 and issued by the Executive Office, examines how sanctioned persons, groups and entities receive financing in violation or evasion of United Nations Security Council Resolutions on terrorism and the proliferation of weapons of mass destruction. It explains that targeted financial sanctions cover asset freezing and prohibitions on making funds available to designated parties. Organised by financing method, it addresses the misuse of banking services, money remitters, hawala, online payments, non-profit organisations and cash smuggling, and, for proliferation, banking sector abuse, cyberactivity, economic resources, trade and legal entities. For banks it details concrete evasion techniques, supporting stronger screening, monitoring and reporting.

goAML FAQs, September 2020

The goAML FAQs Guide, issued by the UAE Financial Intelligence Unit in September 2020, is a practical question and answer reference for reporting entities that use the goAML platform, through which suspicious reports are filed in the United Arab Emirates. It compiles the queries most commonly raised by users and gives step by step responses for tasks arising once an organisation is registered. It explains how to reset a forgotten password, update organisation details through the My Org Details menu, and change personal details, and describes delegation of reporting to a third party by the Money Laundering Reporting Officer, subject to Supervisory Body approval. For banks it resolves routine issues.

goAML Registration Guide Stage 2, September 2020

The goAML Registration Guide Stage 2, issued by the UAE Financial Intelligence Unit in September 2020, outlines the steps an organisation follows when registering with the FIU on its reporting platform, goAML. It applies to registration as a reporting entity, stakeholder or supervisory body, and confirms that all accountable and reporting entities in the United Arab Emirates, whatever their regulator, must register to submit suspicious reports, noting that since 27 June 2019, reports must be submitted electronically. It explains reaching the portal through the Services Access Control Manager, noting that Central Bank-regulated institutions need a dedicated MPLS link while others use the internet. For banks, registration enables lawful reporting.

Guideline on Grievance Procedures

The Guideline on Grievance Procedures is issued by the Executive Office for Control and Non-Proliferation, the authority receiving grievance requests related to the UAE Local Terrorist List and the United Nations Security Council Consolidated List, together the Sanctions Lists. It clarifies how requests are submitted, the types available and how they are reviewed. Under Cabinet Resolution No. 74 of 2020, it processes three types of requests: to remove or de-list a designation, to cancel or lift freezing measures, and to permit use of frozen assets. Procedures apply only to freezes based on Sanctions List designations. For banks, it explains the lawful routes customers use to challenge designations or access frozen assets.

Online Grievance System User Guide

The Online Grievance System User Guide is issued by the Executive Office for Control and Non-Proliferation, the authority receiving grievance requests related to the UAE Local Terrorist List and the United Nations Security Council Consolidated List, together the Sanctions Lists. The Executive Office launched the system to streamline submissions, and this manual walks users through the application form. It explains the steps for the three request types: de-listing, cancellation of freezing measures, and permission to use frozen funds. It covers identifying the aggrieved party, selecting the relevant lists and grievance type, and attaching documents. For banks, it explains the route through which affected customers challenge designations or access frozen assets.

Simple Guide to Subscribe to the EOCN Notification Alert System (NAS)

This short guide explains how to subscribe to the Notification Alert System operated through the Executive Office’s website, so that users receive timely updates to the sanctions lists applied in the United Arab Emirates. It notes that targeted financial sanctions rest on two lists, together the Sanctions Lists: the UAE Local Terrorist List issued by the UAE Cabinet, and the United Nations Consolidated List issued by the Security Council. The guide sets out where the lists can be accessed and gives step-by-step subscription instructions. For banks, it supports a core control: screening only works from current lists, and prompt notification helps them freeze without delay.

Emerging ML, TF and PF Risks and Trends in the Financial Sector

Emerging ML, TF and PF Risks and Trends in the Financial Sector, issued by the Supervisory Subcommittee, gives banks a current overview of the money laundering, terrorist financing and proliferation financing threats reshaping the sector. Responding to technological innovation, geopolitical shifts and evolving criminal methods, it is issued under Article 16 of Federal Decree-Law No. 10 of 2025. It examines emerging risks, including exploitation of artificial intelligence, greenwashing and ESG-related fraud, trade finance abused for proliferation financing, illicit virtual asset transactions in banking, and sanctions evasion. Banking case studies cover money mule networks, trade-based laundering and virtual asset conversion, highlighting typologies and red flags for risk assessments and controls.

Typologies in the Financial Sector

Typologies in the Financial Sector is a report produced jointly by the Supervisory Authorities Sub-Committee and the Financial Intelligence Unit, with the Executive Office and a pilot group of financial institutions. It shares money laundering, terrorist financing, sanctions, fraud, and bribery and corruption typologies observed in the market, several emerging during the COVID-19 pandemic, to help firms anticipate and mitigate risks beyond those in the National Risk Assessment. It examines proactive analysis, the increased use of unlicensed money service operators that balance books over time, and combinations of risk indicators, noting links to modern slavery. For banks, it is an early warning tool to refine monitoring and engage authorities.

NRA, SRA, and Other Important Guidelines for Banks

The UAE assesses its money laundering, terrorist financing, and proliferation financing risk at the national level, and banks must align their own business and enterprise-wide risk assessments with those findings.

UAE PF National Risk Assessment 2026

The UAE Proliferation Financing National Risk Assessment 2026 examines the country’s exposure to proliferation financing, meaning financing of weapons of mass destruction and evasion of targeted financial sanctions under United Nations Security Council resolutions on the Democratic People’s Republic of Korea and Iran. Prepared under the Financial Action Task Force’s revised Recommendation 1, it rates threats across mainland and free zone sectors; overall risk is medium-high. Banks are rated medium-high in the mainland, exposed through trade finance and open account transactions, while virtual asset service providers are high, and exchange houses and hawala are medium-high. Free zone banks are medium, maritime insurance medium, stored value medium-low. It shows where risk sits.

The table below summarises the residual risk ratings that the banking sector should reflect in its own risk assessment (from the UAE ML and TF National Risk Assessment 2024 and the UAE PF National Risk Assessment 2026).

UAE ML and TF National Risk Assessment 2024

The UAE Money Laundering and Terrorist Financing National Risk Assessment 2024 is the country’s second national assessment, prepared using the World Bank methodology by the National Committee. Drawing on data from 2019 to 2023, it rates threats, vulnerabilities and residual risks, including a sectoral assessment of financial institutions across the mainland and financial free zones. Overall money laundering residual risk is medium-high, with drug trafficking and fraud among the highest threats. The banking sector is rated medium-high, reflecting its attractiveness and exposure to fraud and third-party laundering. Exchange houses are medium-high, registered hawala high, finance companies and insurance medium, and securities medium to medium-high. It sets the baseline for banks.

Assessment  Banking sector residual risk 
Money laundering and terrorist financing (NRA 2024)  Medium-high, on an inherent risk of high, with controls assessed as largely effective 
Proliferation financing (PF NRA 2026)  Medium-high in the mainland, mainly through trade finance and open account transactions 

Alongside the national assessments, sector risk assessments, red flag guidance, and typologies reports give banks the detail they need to keep their enterprise-wide risk assessment current and defensible.

CBUAE Guidance Applicable to Banks in the UAE

The Central Bank’s guidance for licensed financial institutions applies to banks as Licensed Financial Institutions. The documents below make up that guidance set.

CBUAE Thematic Review on Sanctions List Screening in the Banking Sector, May 2026

Issued in May 2026, this CBUAE thematic review examines how banks screen against the UAE Local Terrorist List and the United Nations Security Council Consolidated List. It sets out findings and supervisory expectations on the quality of sanctions screening, name matching, and the timeliness of freezing and reporting, and it is read alongside the Central Bank’s guidance on the implementation of targeted financial sanctions.

CBUAE Best Practices for Licensed FIs on Implementing Role-Based AML/CFT/CPF Training, October 2025

The CBUAE Best Practices for Licensed Financial Institutions on Implementing Role-Based AML/CFT/CPF Training, published in October 2025, sets out how banks and other institutions should design and deliver training tailored to the specific responsibilities and risk exposure of each role. It treats a comprehensive programme as critical to compliance, helping staff identify money laundering, terrorist financing and proliferation financing red flags within their own functions. Content, frequency and intensity follow a risk-based approach. The document addresses scope, guidance for the Board, senior management and the three lines of defence, and how to document, update and record training. For banks, well-targeted training equips staff with the judgement their duties demand.

CBUAE Best Practices for Licensed FIs on a Risk-Based Approach and Institutional Risk Assessments, October 2025

The CBUAE Best Practices for Licensed Financial Institutions on Implementing a Risk-Based Approach and Conducting Institutional Risk Assessments, dated October 2025, assists banks and other licensed institutions in developing a methodology, conducting an institutional risk assessment, and applying a risk-based approach across money laundering, terrorist financing and proliferation financing risk. Issued under Article 44.11 of Cabinet Decision No. 10 of 2019 (now repealed and replaced by Cabinet Decision No. 134 of 2025, under which supervisory guidance is issued pursuant to Article 49.4), it sets expectations without replacing binding requirements. It describes an effective methodology, granularity, accountability and frequency, then best practices for assessing inherent risk across customers, products, channels and geographies, evaluating controls, and determining residual risk. It applies to banks and other institutions. Sound assessment underpins proportionate, compliant controls.

CBUAE Guidance for Licensed FIs on Correspondent Banking, October 2025

The CBUAE Guidance for Licensed Financial Institutions on Correspondent Banking and Managing Correspondent Banking Relationships, published in October 2025, explains how banks should understand and control the money laundering, terrorist financing and proliferation financing risks arising from correspondent banking and cross-border payments. It describes what correspondent banking involves and the requirements for processing cross-border transfers. It sets out respondent risk factors, including nested relationships, payable-through accounts, geography, ownership and customer base. On mitigation, it covers risk assessment, standard, specific and enhanced due diligence, ongoing monitoring, suspicious activity reporting, sanctions obligations, governance, audit, training and record-keeping. For banks, correspondent relationships can expose them to parties they do not themselves know.

CBUAE Guidance for Licensed FIs on Customer Due Diligence and Record-Keeping, October 2025

The CBUAE Guidance for Licensed Financial Institutions on Customer Due Diligence and Record-Keeping, published in October 2025, addresses controls foundational to anti-money laundering, counter-terrorist financing, counter-proliferation financing, sanctions, counter-fraud and anti-bribery compliance. It treats due diligence and know your customer processes as the cornerstone for banks seeking to understand customers, including occupation, source of funds, wealth and expected activity, so suspicious activity can be detected. It covers identification and verification of customers, beneficial owners and those acting on a customer’s behalf, risk profiling, ongoing monitoring, simplified and enhanced due diligence, non-face-to-face relationships, name screening, exit, third-party reliance and record-keeping. Reliable records underpin the ability to report financial crime.

CBUAE Guidance for Licensed FIs on Risks Related to Proliferation Finance, October 2025

The Guidance for Licensed Financial Institutions on Risks Related to Proliferation Finance, issued by the CBUAE in October 2025, helps banks understand and counter the financing of the proliferation of weapons of mass destruction. Read alongside the CBUAE’s Procedures and Guidelines, it sets expectations rather than new legislation. It explains what proliferation financing is, then the threats and vulnerable channels, including trade finance, correspondent banking, hawala, offshore accounts, free trade zones, shell and front companies, and dealers in precious metals. It addresses United Nations and FATF obligations, local requirements, a risk-based approach, and mitigating controls covering due diligence, monitoring, reporting, sanctions, governance, audit, training and record-keeping. It exploits legitimate structures.

CBUAE Guidance for Licensed FIs on Risks Related to Trade-Based ML and Transshipment, October 2025

The CBUAE Guidance for Licensed Financial Institutions on Risks Related to Trade-Based Money Laundering and Transhipment, published in October 2025, helps banks understand and manage the risks criminals exploit through international trade and the movement of goods. It provides background on the trade system and trade finance, distinguishing documentary finance from open account trade. It sets out typologies, including over- and under-invoicing, over- and under-shipment, multiple invoicing, falsely described goods, shell and front companies, free trade zones, back-to-back letters of credit and registered hawala providers. It addresses services-based money laundering, vulnerable sectors such as gold, and transhipment risks, then mitigation through risk assessment and enhanced due diligence.

Federal Decree-Law No. 6 of 2025 on the Central Bank and the regulation of financial institutions

Federal Decree-Law No. 6 of 2025 is not the AML law, but it sits directly behind a bank’s licence. Issued on 8 September 2025, it governs the Central Bank and the regulation of licensed financial institutions and activities and insurance business, and it confirms that no person may carry on a licensed financial activity in the State without Central Bank authorisation. It repealed Federal Decree-Law No. 14 of 2018, the previous Central Bank law, and regulations, decisions and circulars issued under the old law remain in force until they are replaced.

CBUAE AML and CFT Guidelines for Financial Institutions, July 2023

The CBUAE Anti-Money Laundering and Combating the Financing of Terrorism Guidelines for Financial Institutions, dated July 2023, help supervised institutions, banks among them, understand and perform their statutory obligations under the framework in force in the United Arab Emirates. Prepared jointly by the Supervisory Authorities, they set out minimum expectations for identifying, assessing and mitigating money laundering and terrorist financing risks. They apply to all financial institutions and their boards, management and employees. They summarise the legal frameworks, statutory obligations and typologies, and devote substantial attention to the risk-based approach across customers, products, channels and geography. For banks, they consolidate supervisory expectations into a reference that shapes compliance and due diligence.

CBUAE Guidance for Licensed FIs on Risks Related to Virtual Assets and VASPs, February 2023

The CBUAE Guidance for Licensed Financial Institutions on Risks Related to Virtual Assets and Virtual Asset Service Providers, issued on 20 February 2023, helps banks understand and manage the money laundering and terrorist financing risks arising from exposure to virtual assets and the businesses that deal in them. It explains the associated threats and vulnerabilities and how institutions may become exposed. It describes the UAE legal framework, including the roles of the SCA, CBUAE, VARA and FSRA, and the requirement for CBUAE non-objection before opening accounts for such providers. On mitigation, it addresses the risk-based approach, general, specific and enhanced due diligence. Virtual assets can move value rapidly and pseudonymously.

CBUAE Guidance for Licensed FIs on Digital Identification for Customer Due Diligence, October 2022

The CBUAE Guidance for Licensed Financial Institutions on Digital Identification for Customer Due Diligence, issued on 31 October 2022, helps banks understand how digital identity systems can be used to identify and verify customers and to conduct ongoing due diligence. It reflects the CBUAE’s expectations and should be read with the wider legal framework. It provides an overview of digital identity systems and their participants, explaining identity proofing and enrolment, authentication and lifecycle management. It sets out how such systems may support customer identification, ongoing due diligence and third-party reliance, and examines their risks. It explains how banks should assess a system’s reliability through its assurance levels.

CBUAE Guidance for Licensed FIs on Suspicious Transaction Reporting, August 2022

The CBUAE Guidance for Licensed Financial Institutions on Suspicious Transaction Reporting, issued on 3 August 2022, explains how banks and other institutions should identify, investigate and report suspicious transactions and activity. It sets out the legal basis for reporting, the consequences of failing to disclose, the protection afforded to those who report, and the meaning of a suspicious transaction. It describes the roles of the three lines of defence and the money laundering reporting officer, transaction monitoring methods, and the procedures for filing, structuring, submitting and amending reports. Further sections address confidentiality and the prohibition on tipping off. For banks, timely, well-drafted reporting is central to disrupting financial crime.

CBUAE Guidance for Licensed FIs on Risks Relating to Payments, August 2022

The Guidance for Licensed Financial Institutions on the Risks Relating to Payments, issued by the CBUAE in August 2022, addresses the money laundering and terrorist financing risks that arise across the payments sector and for the institutions, banks included, that serve it. Issued under Article 44.11 of Cabinet Decision No. 10 of 2019 (now repealed and replaced by Cabinet Decision No. 134 of 2025, under which supervisory guidance is issued pursuant to Article 49.4), and read with the CBUAE’s Procedures and Guidelines, it sets out expectations rather than creating new law. It explains what makes payments vulnerable, including the speed of funds movement, peer-to-peer and cross-border payments, intermediation, nesting, agents and merchant risks. On mitigation, it covers risk assessment, customer and enhanced due diligence, ongoing monitoring, wire transfer and correspondent requirements.

CBUAE Guidance for Licensed FIs on Risks Relating to Politically Exposed Persons, August 2022

The Guidance for Licensed Financial Institutions on the Risks Relating to Politically Exposed Persons, issued by the CBUAE in August 2022, sets out how banks should identify, understand and manage the heightened money laundering and terrorist financing risks associated with politically exposed persons. Issued under Article 44.11 of Cabinet Decision No. 10 of 2019 (now repealed and replaced by Cabinet Decision No. 134 of 2025, under which supervisory guidance is issued pursuant to Article 49.4), and read with the CBUAE’s Procedures and Guidelines, it explains that such customers warrant special attention not because banks should avoid them, but because thorough due diligence is needed before accepting a relationship. It distinguishes domestic and foreign politically exposed persons and heads of international organisations, reaching family and close associates, and covers screening.

CBUAE Guidance for Licensed FIs on Transaction Monitoring and Sanctions Screening, September 2021

The CBUAE Guidance for Licensed Financial Institutions on Transaction Monitoring and Sanctions Screening, issued on 8 September 2021, sets out how banks should design, operate and maintain the systems that detect suspicious activity and identify sanctioned parties. It reflects the CBUAE’s expectations for compliance and should be read alongside the wider legal framework. On transaction monitoring, it addresses risk assessment, risk-based deployment, data management, rule definition and testing, alert scoring, outcomes analysis and validation. On sanctions screening, it covers programme design and testing for name and transaction screening, and list management. A further section deals with governance, vendors, training and record-keeping. For banks, validated monitoring and screening are essential.

CBUAE Guidance for Licensed FIs to Cash-Intensive Businesses, September 2021

The Guidance for Licensed Financial Institutions Providing Services to Cash-Intensive Businesses, issued by the CBUAE in September 2021, helps banks manage the money laundering and terrorist financing risks that arise when customers handle large volumes of cash. Issued under Article 44.11 of Cabinet Decision No. 10 of 2019 (now repealed and replaced by Cabinet Decision No. 134 of 2025, under which supervisory guidance is issued pursuant to Article 49.4), and read with the CBUAE’s Procedures and Guidelines, it sets out expectations rather than new legal requirements. It explains why cash is vulnerable, the risks of alternatives such as bearer negotiable instruments and prepaid cards, and concerns including cross-border movement, couriers and currency exchanges. On mitigation, it sets out a risk-based approach, enhanced due diligence, beneficial owner identification and monitoring.

CBUAE Guidance for Registered Hawala Providers and LFIs, August 2021

The Guidance for Registered Hawala Providers and Licensed Financial Institutions Providing Services to Registered Hawala Providers, issued by the CBUAE in August 2021, addresses the money laundering and terrorist financing risks of hawala activity. Because banks are licensed financial institutions, this combined guidance reaches banks through the LFI side, addressing those that serve registered hawala providers as well as the providers themselves. Drawing on the FATF description of hawaladars, it explains what hawala is, its global risks, and UAE regulation, including permitted and non-permitted services. It addresses sanctions and freezing without delay, registration and operating requirements, the need for a bank account, and an AML/CFT programme covering due diligence.

CBUAE Guidance for Licensed FIs on Implementation of Targeted Financial Sanctions, July 2021

The CBUAE Guidance for Licensed Financial Institutions on the Implementation of Targeted Financial Sanctions, issued on 4 July 2021, helps banks meet their obligations to identify, freeze and report assets and transactions connected to designated persons and entities. Read alongside the CBUAE’s procedures and the Executive Office’s guidance, it sets out expectations for demonstrating compliance. It describes a sanctions compliance programme: senior management commitment, risk assessment and appetite, internal controls, training, independent audit and record-keeping. It then covers screening operations, evasion, the United Nations Consolidated List and Local Terrorist List, false positives, payments screening, confirmed matches and notification duties. Effective sanctions implementation is essential to avoid facilitating prohibited activity.

CBUAE Guidance for Licensed FIs to Legal Persons and Arrangements, June 2021

The Guidance for Licensed Financial Institutions Providing Services to Legal Persons and Arrangements, issued by the CBUAE in June 2021, helps banks manage the money laundering and terrorist financing risks that arise when customers are companies, other legal persons or legal arrangements. Read with the CBUAE’s Procedures and Guidelines, it sets out expectations rather than creating new law. It explains how such structures can be misused to obscure beneficial ownership, hide the purpose of an account, and conceal the source of funds. It covers formation requirements, beneficial owner identification, economic substance, and mitigation through the risk-based approach, customer risk rating and enhanced due diligence. Understanding ownership and control is central.

CBUAE Guidance for Licensed FIs to the Real Estate and Precious Metals and Stones Sectors, June 2021

The CBUAE Guidance for Licensed Financial Institutions Providing Services to the Real Estate and Precious Metals and Stones Sectors, issued on 16 June 2021, helps banks understand and manage the money laundering and terrorist financing risks that arise when they serve customers active in these two higher-risk sectors. Read alongside the CBUAE’s AML/CFT procedures, it does not replace any legal obligation; where a discrepancy arises, the legal framework prevails. It examines the risks presented by dealers in precious metals and stones and by real estate, the features that increase risk, and how each sector is supervised. On mitigation, it explains the risk-based approach, customer and enhanced due diligence, and reporting.

CBUAE STR Outreach for Banks and Finance Companies, March 2021

The CBUAE STR Outreach for Banks and Finance Companies, delivered in March 2021, is an awareness session prepared by the Financial Intelligence Unit and the CBUAE to strengthen suspicious transaction reporting across banks and finance companies. Prepared with input from the FIU, the AML/CFT supervision function and the Ministry of Interior, it explains reporting obligations and practical steps. It covers when to report, grounding the duty in Article 15 of Federal Decree-Law No. 10 of 2025 and Article 17 of Cabinet Resolution No. 134 of 2025, and what to report regardless of value. It confirms goAML as the only channel and addresses compliance officer tasks and common deficiencies.

CBUAE Board of Directors Decision No. 59/4/2019 on AML and CFT procedures

Central Bank Board of Directors Decision No. 59/4/2019, issued on 13 June 2019, sets out anti-money laundering and combating the financing of terrorism procedures for financial institutions supervised by the Central Bank of the United Arab Emirates, including banks. Made under Decree Federal Law No. 14 of 2018, repealed and replaced with Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025, it cancels the earlier Circular No. 24/2000. It requires banks and their concerned persons to comply with the law, the implementing regulation and related Central Bank instructions. It empowers the Central Bank to supervise, examine, request information and impose administrative sanctions, establishing the supervisory basis underpinning bank compliance.

CBUAE Guidance Note on Responsible Use of AI and ML by LFIs

The CBUAE Guidance Note on the Responsible Use of Artificial Intelligence and Machine Learning by Licensed Financial Institutions sets out principles for the consumer-focused, ethical adoption of AI and machine learning, including generative AI, by banks. It is non-binding, intended to help institutions formulate internal policies focused on areas bearing on consumers, promoting consumer protection and good market conduct, with principles that can evolve as the technology develops. It covers governance and accountability, placing responsibility with senior management and the Board, a documented framework, reporting and a model inventory. It addresses fairness, transparency, data quality, privacy, monitoring, human oversight, outsourcing and ethical innovation.

CBUAE List of Administrative and Financial Sanctions

The CBUAE List of Administrative and Financial Sanctions records the penalties the Central Bank can impose under the Central Bank Law and the Anti-Money Laundering and Combating the Financing of Terrorism Law. It applies to all licensed institutions and persons, including banks. It explains that the CBUAE is the supervisory authority responsible for addressing shortcomings in compliance frameworks. Under Article 14 of Decretal Federal Law No. 20 of 2018, as amended, it can impose penalties from a warning to licence revocation, and fines of fifty thousand to five million dirhams per violation. Under Article 137, fines reach two hundred million dirhams. It shows a methodical, dissuasive approach to enforcement.

Core AML Obligations for Banks at a Glance

Whatever the licence, the AML regulations for banks in the UAE turn on a common set of duties.

Expert Tip:

For a bank, the two areas that draw the most supervisory attention are correspondent banking and trade finance, because both move value across borders through third parties. Build your enhanced due diligence and transaction monitoring around those flows and document the rationale, and the rest of the programme becomes far easier to defend.

Conclusion

AML regulations for banks in the UAE come down to a simple chain: banks are Licensed Financial Institutions, the Central Bank supervises them, and Federal Decree-Law No. 10 of 2025, its Executive Regulations, targeted financial sanctions rules, and relevant CBUAE LFI guidance form the core framework for banks licensed by the Central Bank. The banking sector carries the deepest obligations in the financial system because it carries the highest inherent risk. Use the national risk assessments to calibrate your programme, treat this guide as the map, and read across to the wider view in our guide to anti-money laundering laws in the UAE and the pillar on AML regulations for banks and financial institutions in the UAE.

Frequently Asked Questions

Are banks subject to AML regulations in the UAE?

Yes. Banks are Licensed Financial Institutions under Federal Decree-Law No. 10 of 2025, supervised by the Central Bank of the UAE, and must run customer due diligence, sanctions screening, transaction monitoring, record-keeping, and suspicious transaction reporting through goAML.

The Central Bank of the UAE supervises banks in mainland UAE and the commercial free zones. Banks established in the DIFC and ADGM are supervised by the DFSA and FSRA under their own AML rulebooks.

The UAE ML and TF National Risk Assessment 2024 rates the banking sector at medium-high residual risk, with an inherent risk of high. For proliferation financing, mainland banks are rated medium-high, mainly through trade finance and open account transactions.

A bank must maintain a risk assessment aligned with the national risk assessments, perform customer due diligence and enhanced due diligence, screen against sanctions and PEP lists, monitor transactions, report suspicious activity through goAML, keep records, and appoint a qualified compliance officer and MLRO.

A bank must identify and verify the customer and any beneficial owner, screen against sanctions and politically exposed person lists, risk-rate the relationship, and establish the source of funds where relevant, applying enhanced due diligence to higher-risk customers before the relationship proceeds.

Common indicators include structuring of cash deposits, unexplained or rapid cross-border wire transfers, trade finance documents that do not match the underlying goods, money mule activity, and transactions that do not fit the customer’s known profile. The red flags and typologies guidance sets these out for detection and reporting.

Yes. A branch of a foreign bank licensed by the Central Bank must run a full local AML programme and remain answerable to the Central Bank for its UAE activities, even where the head office operates its own global controls.

This guide focuses on banks licensed and supervised by the Central Bank of the UAE outside the financial free zones. Banks in the DIFC and ADGM are supervised by the DFSA and FSRA, respectively, under their own AML rulebooks, while UAE federal AML legislation also forms part of the applicable framework in those financial free zones.

Need help building or reviewing your bank's AML programme?

Ensure your bank's AML programme is effective, compliant, and aligned with regulatory expectations. Get expert advice tailored to your business.

Share via :

About the Author

Pathik Shah

FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)

Pathik is an ACAMS-certified AML consultant specialising in governance, risk, and compliance for regulated entities in the UAE. He brings over 28 years of experience, with 1,000+ hours of AML training and 200+ advisory engagements across DNFBPs, VASPs, and FIs. He supports businesses in aligning with AML/CFT requirements from the CBUAE, DFSA, MoET, MoJ, VARA, CMA, FSRA, and FATF. Known for translating complex regulations into audit-ready procedures, Pathik enables operational clarity and compliance readiness.

Reach Out to Pathik

Why is Record-Keeping of Customer Identity and Transactions necessary?

Blogs

Table of Contents

Protect your business with reliable and effective AML strategies with AML UAE.

Why is Record-Keeping of Customer Identity and Transactions necessary?

Illicit financial activities, such as money laundering, financing terrorism, and proliferation financing (ML/FT and PF), hamper the integrity of the economy as well as the operations of business entities. To combat these illicit activities, businesses adopt robust Anti-Money Laundering and Combating the Financing of Terrorism (AML/CFT) measures, which are aligned with the regulatory framework.

As part of the UAE’s AML/CFT regulatory framework, all regulated entities, including Financial Institutions, Designated Non-Financial Businesses and Professions (DNFBPs), and Virtual Asset Service Providers (VASPs), are required to maintain records of KYC, CDD, EDD, transactions, audit logs, software audit trail, AML/CFT policy, procedures, etc.

In this article, we’ll discuss why record keeping of customer identity and transactions is important and what its best practices are.

What is AML Record-Keeping?

Whenever regulated entities undertake measures and activities to mitigate ML/FT and PF risks, such as customer due diligence, transaction monitoring and AML audit, they generate several documents in the process. Maintaining these documents is necessary as it makes it easier for them to access data as and when required, which is crucial for combating financial crimes, including ML/FT and PF.

This is the essence of AML record-keeping. Therefore, record-keeping in the AML framework means maintaining documents pertaining to AML measures that include customer identity records, transaction records, adverse media checks, etc. Record-keeping thus carries a significant purpose in ensuring AML compliance.

With our AML expert guidance,

Start your AML compliance journey smoothly.

What type of records are required to be maintained?

The types of records that regulated entities need to maintain depend on the regulations they need to follow. In the UAE, regulated entities must maintain records related to various compliance measures undertaken by them.

Here is a comprehensive list of customer-related information and transactions which require record-keeping in the UAE:

1. EWRA, Internal policies, Procedures and Control Measures

The Regulated Entities must take a Risk-Based Approach and conduct an ML/TF/PF Enterprise-Wide Risk Assessment. Regulated entities are required to establish internal policies and procedures as part of their AML framework and maintain their version history.

As part of policies and procedures, regulated entities need to establish a risk appetite statement that provides the entity’s stand on accepting risks and sets a base to analyse trade-off decisions. A risk appetite statement helps everyone understand the level of risks the entity is willing to take and accordingly apply suitable control measures. 

Furthermore, based on risk appetite, the regulated entity must also identify and enforce AML control measures to combat ML/FT and PF risks associated with the entity.

2. Customer Due Diligence

It is essential for regulated entities to conduct the CDD process to measure ML/FT and PF risks associated with customers. There are various elements for an effective CDD. The CDD process includes conducting know-your-customer (KYC) measures to verify the customer’s identity. It is required to maintain KYC records along with supporting documents like Emirates ID, Passport, Utility Bill, etc.

Customer risk assessment is a key component of the CDD process that helps detect and prevent ML/FT and PF risks by evaluating the risk associated with each customer. Regulated entities must maintain customer risk assessment documents as evidence of their risk profiling.

Based on customer risk assessment, regulated entities are needed to undertake Enhanced Due Diligence (EDD) for higher-risk customers that pose ML/FT and PF risks and thus present increased exposure to them. They need to maintain any additional information related to customers within CDD records concerning EDD.

3. Transactional Records

Regulated entities have to keep a record of the business relationship- transactions involved from five years of completing the transaction. Regulated entities must store the records of all the transactions and commercial relationship at least for a period of five years under article 19(1)(f) of Federal Decree-Law No. 10 of 2025 and Article 25 of Cabinet Resolution No. 134 of 2025 from the completion of the transaction or end of relationship. The various transaction records involve purchase orders, sales orders, invoices, receipts, payments, credit and debit notes and correspondence with the business. Regulated entities must maintain all the documents to establish a proper audit trail.

4. Regulatory Reports

To meet the internal and external reporting requirements, regulated entities must maintain all submissions made to the regulatory authorities.

As a part of his responsibility, the compliance officer prepares a semi-annual AML compliance report, which he submits to the senior management. These reports must be preserved. Further, semi-annual reports submitted to the regulatory authorities must be preserved for a period of 5 years.

However, the record keeping duration varies from one supervisory authority to another. 

  • The Virtual Assets Regulatory Authority (VARA) mandates Virtual Assets Service Providers (VASPs) to maintain records for a duration of 8 years
  • Dubai International Financial Centre (DIFC) requires DNFBPs to maintain AML/CFT compliance and CDD records for 6 years.
  • Abu Dhabi Global Market (ADGM) requires DNFBPs and VASPs to maintain AML/CFT compliance and CDD records for 6 years.

The AML regulations in the UAE mandate the regulated entities to identify suspicions related to ML/FT and PF and report such suspicions by filing a Suspicious Activity Report (SAR) or Suspicious Transaction Report (STR). As part of record-keeping compliance, they must keep records of STR/SAR.

In addition to MLRO and STR/SAR, the regulated entity needs to submit additional reports based on the nature of the customer’s business, circumstances and place of the customer’s business or transactions. These reports include the High-Risk Country Report, High-Risk Country Activity Report, Real Estate Activity Report, Fund Freeze Report, Partial Name Match Report and Dealers in Precious Metals and Stones Report. Regulated entities in the UAE are mandated to maintain such reports.

An Independent AML Audit report issued by the external auditor must be preserved for at least 5 years.

5. Correspondence and Directives Issued by Regulatory Authorities

Regulated entities should also keep records related to communication and directives issued by regulatory bodies, ensuring compliance with applicable laws and regulations. With such records, regulated entities in the UAE can effectively manage risks associated with their customers and transactions and help supervisory authorities keep checks and balances.

6. Training Logs

Training logs are key tools within the AML/CFT framework. They ensure that staff and employees within businesses are adequately trained to fulfill their responsibilities effectively. By maintaining comprehensive training logs, regulated entities demonstrate their commitment to AML/CFT compliance, fostering a culture of compliance within the organization and empowering staff to detect and prevent financial crimes effectively.

Make your record-keeping accurate, easier, and effective.

Why is record-keeping of customer-related information necessary?

Why is record-keeping of customer-related information necessary?

Record-keeping is an integral part of the AML/CFT framework. It supports various compliance activities like customer due diligence, transaction monitoring, reporting, compliance documentation, regulatory examinations, and investigations. Properly maintained customer records are essential for compliance with AML regulations.

Here is the list of reasons that make record-keeping of customer information and transactions necessary:

Differences-between-AML-risk-management-and-AML-compliance

Legal and Regulatory Compliance

The AML/CFT regulatory framework requires regulated entities to maintain customer-related AML records. If a regulated entity fails to maintain records, it can result in legal consequences, fines, or penalties. Therefore, having a system for record-keeping helps in avoiding legal implications.

Customer Due Diligence

AML regulations require regulated entities to conduct due diligence on their customers to assess their risk levels and verify their identities. Record keeping helps regulated entities maintain proper documentation of customer information, identity verification, and risk assessments. Furthermore, it helps them avoid any financial and reputational loss in case a customer is engaged in illicit activities.

Proactive Monitoring

Regulated entities are required to monitor customer transactions for suspicious activities that may indicate money laundering or other illicit activities. Record-keeping plays a vital role in enabling proactive monitoring from an AML/CFT standpoint.

Regulatory Reporting

When suspicious activities are detected, financial institutions must file SAR/STR with the appropriate regulatory authorities. Proper record-keeping ensures that all necessary information related to the customer’s suspicious activity is documented and can be provided to regulatory authorities.

Performance Evaluation

Record-keeping helps regulated entities assess the performance of AML measures across the entire organisation, including those measures incorporated for customers. By tracking KPIs over time, regulatory entities can easily identify AML measures’ strengths, weaknesses, and gaps for improvement.

Decision Making

Records provide valuable data and insights that aid in making informed decisions. Whether it’s about customer-business relationships, control measures, or strategic direction, having access to historical records enables better decision-making. A well-structured record-keeping system allows for better tracking of suspicions, which in turn helps in making informed decisions.

Independent AML Audit

Regulated entities need to appoint an independent AML auditor to carry out the audit of their AML/CFT compliance. Record-keeping facilitates such audits.

Inspections and Investigations

Often, regulatory authorities come for inspections and ask for various compliance records. Record-keeping also helps investigators conduct investigations into cases related to money laundering and terrorist financing.

How do you maintain customer identity and transaction records?

Record keeping procedure depends on local and global regulatory requirements. The number of records required to be maintained affects the manner in which such records are maintained. The records can be maintained physically or in an electronic form. Ideally, the following documents should be maintained:

  • Original documents
  • Photocopies of original documents
  • Documents stored in electronic form

It is noteworthy that the records maintained should be easily accessible. If the source documents are available in a foreign language, then translated copies must be made available to ensure AML/CFT compliance.

Ensure accurate maintenance of AML records,

With the expertise of AML UAE

Challenges for maintaining customer records

Although it is necessary to keep records of customer information and transactions, regulated entities face various challenges in maintaining an efficient system.

The following are some major challenges:

Large and Complex Data

Customer records are comprehensive data that include information relating to customer due diligence, transactions, ongoing monitoring, suspicion reports and internal policies, procedures, and controls. Thus, handling the large volume and complexity of AML records becomes challenging for businesses.

Regulatory Variations

Global businesses have to adhere to multiple laws and regulations. Such variations in regulatory requirements pose a constant challenge as every jurisdiction requires different record-keeping obligations, making adherence to regulatory frameworks challenging for the entities.

Privacy and Consent

KYC information is personal in nature. Before keeping records, regulated entities must obtain consent from the person to whom such information belongs. However, customers are hesitant to provide information due to privacy concerns. Further, remote onboarding procedures require liveness checks, IP address logging, etc. If customers are not willing to part such information, it becomes difficult to onboard customers.

Data Security

Keeping a large amount of data requires effective security measures. Businesses face challenges in ensuring the security of sensitive data. Additionally, information pertaining to customers and their transactions is very sensitive and is targeted by criminals for facilitating their illicit activities. This obligates regulated entities to deploy enhanced data security measures.

Incomplete and Inaccurate Data

There is an abundance of information collected by the regulated entity from various sources while undertaking AML measures. However, not all information is relevant, complete, or accurate. It becomes a challenge to segregate qualitative and accurate data from the amount of information available.

Best practices for effective record-keeping of customer information

It is essential for regulated entities to implement effective record-keeping measures to maintain accurate documentation concerning customers and third parties.

Here are some best practices that regulated entities can establish for record-keeping of customer information:

Implement Document Management Software

Document management tools provide a harmonious and logical filing system that is easy to understand and use. Regulated entities can implement such tools to standardise AML record-keeping processes for maintaining customer information and transactions across their operations.

Use Cloud-based Storage

Regulated entities collect a large volume of customer data for which they can use cloud-based storage. The transition to cloud-based storage solutions can help them store records while providing scalability and accessibility.

Implement Security and Privacy Guidelines

Customers have privacy concerns about data usage and retention, which makes it difficult for regulated entities to obtain consent from them. Thus, to maintain their trust, they should establish clear data usage and retention policies which comply with relevant privacy regulations.

Deploy Data Security Tools

Keeping a large amount of data requires effective security measures. For this purpose, regulated entities should implement encryption technology, firewalls, etc., to limit unauthorised access and tackle data breaches.

Backup and recovery

Maintaining customer information is very important for regulated entities, and any loss of data can lead to major repercussions. Thus, regulated entities must implement backup procedures for records to prevent data loss by system failure or cyber-attacks. Further, they should also develop a recovery plan to ensure that records can be quickly restored in the event of loss.

Regular Updates and Review

Regulated entities must regularly update their systems and underlying procedures to remain compliant with the ever-changing regulatory environment. Internal health-check reviews must be conducted to find discrepancies in record-keeping and take immediate remedial measures.

Final Words on Maintaining Effective Customer-related Records

For regulated entities, record-keeping of the identities of their customers and transactions is crucial to ensure compliance with regulations, manage risks, and easily access data for submitting it to the authorities as and when required.

AML UAE is a global AML/CFT consulting firm assisting regulated entities in deploying countermeasures to curb financial crimes.

FAQs related to record-keeping under the AML Regulatory Framework

What is the record-keeping law in UAE?

Record-keeping in the UAE’s AML regulatory framework means maintaining documents related to AML measures that include customer identity records, transaction records, adverse media checks, etc.

As per the UAE’s AML regulations, regulated entities need to maintain AML records for five years. However, for ADGM and DIFC-regulated entities, it is necessary to keep the AML records for six years. For VASPs based out of VARA, it is required to maintain records for eight years.

Record keeping is an integral part of AML compliance as it acts as a proof of having followed regulatory requirements and risk-based approach.

The types of records that must be maintained are as follows:

  • Customer information
  • Transactional information
  • Internal/External suspicious reported
  • Records pertaining to ongoing monitoring
  • Training Logs
  • Compliance officer reports
  • Copies of reports filed on the goAML portal

Record-keeping is an integral part of the AML framework. A well-structured record-keeping system allows for easy tracking of any suspicious transactions and facilitates effective AML compliance measures with AML regulations.

Want to have an effective record-keeping strategy for your business?

Let’s connect and discuss your requirements.

Share via :

About the Author

Pathik Shah

FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)

Pathik is an ACAMS-certified AML consultant specialising in governance, risk, and compliance for regulated entities in the UAE. He brings over 28 years of experience, with 1,000+ hours of AML training and 200+ advisory engagements across DNFBPs, VASPs, and FIs. He supports businesses in aligning with AML/CFT requirements from the CBUAE, DFSA, MoET, MoJ, VARA, CMA, FSRA, and FATF. Known for translating complex regulations into audit-ready procedures, Pathik enables operational clarity and compliance readiness.

Reach Out to Pathik

Addressing an Existing Low-Risk Customer’s Shift to High-Risk Status

Addressing an Existing Low-Risk Customer's Shift to High-Risk Status

Table of Contents

Protect your business with reliable and effective AML strategies with AML UAE.

Addressing an Existing Low-Risk Customer's Shift to High-Risk Status

Financial institutions, Designated Non-Financial Businesses and Professions (DNFBPs), and Virtual Asset Service Providers (VASPs) in UAE are required to follow a systematic mechanism to conduct a customer risk assessment, determine the money laundering, terrorism financing, and proliferation financing (ML/FT and PF) associated with each customer, and deploy adequate measures to manage the identified risks.

Based on the risk assessment, customers are categorised into three risk levels: low-risk, medium-risk, and high-risk. Based on this risk score, proportionate risk mitigation measures are adopted.

In the course of the business relationship, the level of risk the customer poses to the business may change, which requires immediate attention. Thus, the AML laws require the regulated entity not to stop at the initial assessment but also implement ongoing monitoring to observe and track the changes to the customer information and its impact on the risk profile.

When undertaking ongoing monitoring, the regulated entity might encounter a situation where a customer initially designated as low-risk shifts to the high-risk category. Such a shift may occur due to his engagement in certain transactions or his behaviour, which has subsequently changed, indicating increased ML/FT risk. Therefore, understanding the factors contributing to this shift and undertaking appropriate measures are crucial to mitigating ML/FT and PF risk and continuous AML regulatory compliance.

Customer Risk Rating

An essential aspect of risk assessment and adopting the risk-based approach is evaluating the risk the customer poses to the business, assigning the risk score in line with the identified risk and allocating an appropriate risk rating. Such a rating shall help entities determine the level of customer due diligence (CDD) measures to be deployed at the time of onboarding and on an ongoing basis.

Furthermore, risk rating enables regulated entities to make informed decisions about entering into business relationships with customers whose risk is within acceptable parameters.

The risk-based approach and the enterprise-wide risk assessment are required under Article 19(1)(a) of Federal Decree-Law No. 10 of 2025 read with Article 5 of Cabinet Resolution No. 134 of 2025.

Risk Rating’s nexus with customer onboarding and post-onboarding measures

The UAE AML laws mandate regulated entities to perform appropriate customer due diligence processes before establishing a business relationship. In this context, based on the outcome of the customer risk profiling and the assigned risk rating, the regulated entities determine the nature and the degree of the CDD measures to be applied.

Here, the regulated entities must apply Enhanced Due Diligence (EDD) measures when the customer is identified as posing higher ML/FT/PF risk, in addition to the standard CDD process. Similarly, for a customer classified as “low-risk”, the regulated entities are permitted to use relaxed CDD measures, i.e., Simplified Customer Due Diligence.

Thus, the customer risk rating shall empower the regulated entities to optimally use the resources and effectively manage the risk, adopting a risk-based approach.

We understand that the customer risk is dynamic and may change over time. Hence, the process of evaluating the customer profile does not end with customer onboarding. Even post-establishing a business relationship with the customers, the regulated entity is obligated to implement measures to monitor customer activities and transactions continuously to ensure that the customer profile developed at the time of onboarding holds good and the transactions executed by the customer do not contradict the original customer risk profile.

The frequency and degree of the ongoing monitoring measures to be applied varies for each customer, depending on the results of the risk assessment and risk rating given to them. As part of the ongoing monitoring of business relationships, the regulated entities must reassess the level of customer risk and decide whether there is a need to adopt enhanced due diligence measures to manage any changes in the risk level.

Detect and Deter ML/FT and PF risk

With the help of our expert AML team

Factors Shifting Low-Risk Customers to High-Risk Category

Risk scoring, or risk rating, or customer classification varies from entity to entity based on AML policies, procedures, and controls. But primarily, during the initial customer onboarding journey, the customers would be categorised as low-risk, medium-risk, and high-risk (the nomenclature or the methodology to bifurcate customers into three brackets may differ).

Notwithstanding the initial risk classification, the regulated entity might encounter a few instances during ongoing monitoring that warrant a detailed review of the customer, including reassessing the customer risk profile.

Here is the list of such factors that cause the shift in risk rating from low to high due to the following factors:

Being a PEP or association with PEP

A politically exposed person (PEP) is an individual who has been entrusted with a prominent public function and, through their prominent position or influence, is more susceptible to being involved in financial crimes like bribery or corruption.

When first onboarded with a low-risk rating, the customer may subsequently become a PEP or a close associate of a PEP, which increases the potential ML/FT and PF vulnerabilities.

Factors Shifting Low-Risk Customers to High-Risk Category

The regulated entity can detect a customer’s transition to PEP through ongoing monitoring of the customer profile, possibly through screening against the PEP database. This continuous screening of the customer scrutinises the data to look for any changes in their status and triggers an alert when any update is observed.

Therefore, when such a shift is detected from non-PEP to PEP, the regulated entity must reassess the customer risk and employ enhanced due diligence measures to manage the increased risk.

Accused with Criminal Charges or Adverse Media Coverage

Any involvement in criminal activities raises questions about the customer’s risk profile and indulgence in illicit financial crimes, necessitating heightened scrutiny.

Similarly, if any adverse media (unfavourable information about individuals, entities, or organisations that could indicate potential involvement in financial crimes, corruption, or other illicit activities) is found, the same indicates reputational risk to the regulated entity and potential involvement of customers in illicit activities.

When the regulated entities initially onboarded a customer, the customer was not involved in any criminal activity. However, after the regulated entity onboarded the customer, the customer engaged in criminal activities and was proven guilty. Such criminal acts of customers raise questions about the customers’ ethics and possible criminal association.

The regulated entity can detect criminal charges associated with the customer by implementing the latest innovations in background screening and continuous ongoing monitoring, which can give alerts when engaged with such charges. This allows the regulated entity to monitor better the customer profile, which is the key to a safe strategy from onboarding to the business relationship ends.

After a shift is detected, the regulated entity should evaluate the customer’s risk profile, monitor the customer’s activities, and, if necessary, terminate the business relationship if the customer is suspected of attempting money laundering or other financial crimes. Considering the nature of the criminal charges or additional suspicion related to ML/FT and PF, an STR/SAR must be reported on the goAML Portal.

Suspicious and Non-Cooperative Behavior

Customer monitoring does not stop with the customer’s onboarding but extends to post-onboarding decisions. It aims to monitor customers and their activities to ensure no ML/FT and PF activities are initiated.

When an existing customer designated as a low-risk customer demonstrates behaviour that deviates from the standard patterns, does not cooperate with the monitoring inquiries or is reluctant to provide any additional information, it raises red flags, which the regulated entity should be aware of and attentive to.

The regulated entity can use a transaction-based ongoing monitoring system to detect any change in the customer’s transactional pattern, which he usually does not engage in, or the overall transactional trend is contrary to the known customer profile.

To effectively counter the change in customer risk rating from low-risk category to high-risk, the regulated entity must initiate a training program to make the employees aware of the red flags and measures to identify such suspicion. Such a training program shall be conducted for compliance officers and staff, as well as methods to be used for handling such alerts, reviewing them, and taking action accordingly.

Once suspicious behaviour or transactional pattern is observed, the regulated entity must evaluate and understand the reasonableness of such change. Considering the changed circumstances and rationale, the regulated entity must reassess the risk and, if required, apply the EDD measures.

Further, if the changes suggest a potential involvement of the client in ML/FT and PF activities, the regulated entity must terminate the business relationship and file SAR/STR on goAML.

Unreasonable Growth in Net Worth

When a low-risk category customer’s profile suggests swift growth and an unexplained increase in wealth without any plausible explanations, such incidents question their engagement in criminal activities and potential illicit sources of funds.

The regulated entity can detect such exponential growth using threshold-based monitoring rules that help to identify any changes in the customer’s profile, such as increasing involvement in high-valued transactions without any economic rationale. This indicates significant growth in wealth; however, the escalated increase shows a linkage with unknown sources of funds and wealth.

The regulated entity should undertake detailed inquiries into this change and apply additional checks and verification measures to understand the legitimacy of the customer’s source of funds and wealth and evaluate its potential connection with ML/FT and PF activities.

Conducts Unusual Transaction

When a customer engages in a transaction that deviates from normal behaviour or industry standards, such incidents warrant investigation to determine and check the transaction’s legitimacy.

When a low-risk customer engages in unusual transactions, which he usually does not engage in or associates with high-value transactions, it increases concerns about their legitimacy and linkage to ML/FT and PF activities.

The regulated entity can install transaction-based and threshold-based monitoring parameters to detect unusual patterns by continuously collecting data, employing detection algorithms, and setting thresholds to identify deviations from standard business practices. Alerts generated based on these monitoring rules must be further investigated to check their authenticity and understand the purpose of such transactions.

The regulated entities must employ EDD measures to understand the source of funds/wealth involved in such unusual transactions and ensure that appropriate risk-mitigating measures are applied.

Shifts in customer’s location from Low-risk to High-risk Jurisdiction

Relocation to or conducting business in high-risk jurisdictions increases exposure to regulatory and financial risks.

A. When a customer moves to a high-risk country

It is one of the red flag indicators for AML/CFT when customers or their representatives are situated in a country prone to high risks. High-risk jurisdictions often lack stringent laws, providing a platform for criminals to engage in illicit activities.

Therefore, when a low-risk customer relocates to a high-risk country, the exposure to ML/FT and PF risk associated with the customer increases.

The regulated entity can detect shifts in customer locations to high-risk jurisdictions by implementing location-based monitoring mechanisms and regularly reviewing customer information and transaction data for any indications of change in location.

The regulated entity, upon obtaining adequate and appropriate consent from the customer under relevant and applicable data privacy laws, deploy geolocation technologies when undertaking an ongoing monitoring process of existing business relationship with a customer so that they may obtain real-time updates on customer whereabouts.

B. When a customer’s country’s status changes to a high-risk jurisdiction 

Various factors, such as political instability, global assessment by international overseeing bodies like FATF, economic unrest, and emerging issues, change a country’s status from low risk to high ML/FT risk. Thus, when a country’s status changes from a low-risk jurisdiction to a high-risk jurisdiction, a customer belonging to such a jurisdiction needs more scrutiny and monitoring as they become more vulnerable to ML/FT and PF activities.

When undertaking Know Your Customer (KYC) remediation to validate the customer details, the regulated entity can spot the change in the customer’s jurisdictional risk. Furthermore, the regulated entity must keep tracking independent sources like the FATF site or other local authorities’ websites to stay updated with the countries listed identified or notified as high-risk jurisdictions.

When the customer’s risk profile changes from low to high on account of a change in jurisdiction, the regulated entity must reassess the customer risk, identify the level of increased exposure and deploy additional CDD measures. When the shift in jurisdiction emits risk beyond the regulated entity’s risk appetite, the regulated entity must consider terminating the business relationship.

Further, under UAE AML regulations, the regulated entities are also required to file HRC or HRCA (High-Risk Country Transaction or Activity Report) when the remittances are expected from North Korea, Iran and Myanmar. Thus, if the risk shift suggests the involvement of these countries, the regulated entity must comply with the reporting.

Insistence on involving third parties in executing the transaction or for processing the payment

After onboarding, if the customers insist on involving third parties in executing transactions or paying bills, this practice diverges from standard practice and raises suspicion. Third-party involvement by a low-risk customer, without any business logic, amplifies the risk of financial irregularity. It’s important to note that this risk would vary for each business and is crucial in determining risk tolerance.

The regulated entity can detect such factors by implementing a transaction-based monitoring method to track the name of the party to whom the invoice is being issued or the party involved in processing the payment. In such cases, the regulated entity must reassess the ML/FT/PF risk associated with the business relationship and carry out necessary measures to identify the third party, its location, its activities, etc.

AML Measures upon the shift of a Low-Risk Customer to a High-Risk

It is of utmost importance to know about the factors that lead to the transition of a low-risk customer to a high-risk one. With such knowledge, the regulated entity can take sufficient measures for better regulatory compliance, help avoid penalties, and safeguard itself from any risk associated with such customers.

The UAE’s AML/CFT regulatory framework mandates the regulated entity to conduct an Enhanced Due Diligence process for every high-risk customer. Similarly, EDD measures must be undertaken when a low-risk customer shifts to a high-risk status. With EDD, adequate increased controls and risk mitigation measures can be taken to manage the heightened risk.

The following EDD measures should be taken by the regulated entity when a low-risk customer shifts to a high-risk status:

Request Additional Information and Conduct Verification

The primary measure that every regulated entity should undertake to tackle such customers is to seek supplementary information to validate their identities and transactions. Updating the current information and documents according to changes in risk rating helps it implement a better monitoring system and manage risks.

Details regarding Customer’s Source of Funds and Wealth

The regulated entity should thoroughly examine the source of funds and wealth to ensure legality and legitimacy and restrict the facilitation of transactions involving funds whose source is unknown or linked to any criminal activity. 

The regulated entity must make independent inquiries and use reliable documents to establish the legitimacy of the source of funds and wealth involved in the transaction.

Review Criminal Charges and Adverse Media and connection with Financial Crimes

When the regulated entity encounters information related to criminal charges or adverse media concerning a customer, it must thoroughly investigate the nature and circumstances of these allegations. This measure differentiates between criminal charges and adverse media related to financial crimes, including activities concerning ML/FT and PF and those unrelated to financial misconduct. Upon finding such an assessment, the regulated entity must evaluate the potential inferred risk associated with the customer profile and subsequently take measures.

Additionally, when the customer profile shifts due to adverse media, the regulated entity must ensure that it rules out fake news or news posts not backed by reliable data sources. Such measures are required to protect customers and maintain the integrity of the regulated entities.

Furthermore, in cases where the criminal charges are unrelated to financial crimes, the regulated entity should maintain enhanced observation of such customer’s activities. However, in cases where the criminal charges are related to ML/FT and PF, thorough investigations are needed, necessitating vigilant customer monitoring. If it is determined that the customer is still engaged in ML/FT and PF activities, the regulated entity must immediately report them on the goAML Portal and terminate the business relationship.

Obtain Management approval

In cases where a customer is initially categorised as low-risk, however, employing ongoing monitoring shifts to the high-risk category, the regulated entity is mandated to seek management to proceed with the existing business relationship with such a customer.

This measure helps safeguard the regulated entity by validating the business’s commitment to risk management protocols and regulatory compliance standards in dealing with high-risk customers.

Get the payment from the customer’s bank account

For enhanced traceability and transparency, the regulated entity should demand payment from the customer’s bank account, as prescribed under the UAE AML laws as one of the EDD measures. Thus, for the low-risk customer now rated as high-risk, the regulated entity must not accept the payment using alternate modes like cash or a third-party bank account.

This helps document financial transactions and makes monitoring for AML regulatory compliance easier. By aligning payments with the customer’s bank account, the regulated entity can mitigate the risk of transferring funds to an unauthorised channel and prompt greater accountability throughout the transaction.

Increased ongoing monitoring

For the customer now classified as high-risk, the regulated entity must enhance the degree and frequency of ongoing monitoring of the business relationship, transactions and CDD updates. This continuous review shall help the regulated entity keep a close eye on this customer and spot any red flags that may potentially arise during the course of the business relationship.

Continue your AML compliance journey smoothly with handholding

from an AML expert.

Determining future relations with the High-Risk Customer

When a customer shifts from a low-risk category to high-risk, careful consideration and strategic actions are required to manage associated risks and ensure regulatory compliance. For which the regulated entity takes EDD measures. The analysis and implementation of such EDD measures determine how to proceed with such customers. Here is the list of findings and recommendations which regulated entities can adopt to address the challenges posed by high-risk customers effectively:

Continue Business Relationships with Increased Monitoring

Determining future relations with the High-Risk Customer

When customers are designated as high-risk, the regulated entity continues to engage with them to conduct transactions but with a more stringent monitoring system.

Similarly, when a low-risk category customer shifts to a high-risk status, the regulated entity shall maintain the business relationship while intensifying monitoring efforts to detect any associated risks promptly.

Terminate Business Relationship

In certain circumstances, the regulated entity must terminate the business relationship with a customer when its status changes from low-risk category to high-risk.

When the increased risk exceeds the management-approved risk appetite

In cases where the risk rating exceeds the regulated entity’s management-approved risk appetite, termination of the business relationship may be necessary to mitigate exposure. Risk appetite is set for the degree of risk a business is willing to accept, and it helps the regulated entity make decisions regarding customer onboarding.

Therefore, when a low-risk category customer shifts to a high-risk status, the regulated entity must ensure that the customer remains within its risk appetite after a change in risk profile before continuing with the business relationship.

When there’s a lack of Information

Insufficient information or the inability to verify critical details raises concerns about involvement in ML/FT and PF and also hinders the entity’s efforts toward applying the EDD process. Therefore, to safeguard itself from probable ML/FT and PF risk, the regulated entity may terminate the business relationship to avoid risk and also comply with the requirement of not transacting with the customer without the successful completion of adequate CDD measures.

File SAR/STR on the goAML Portal

As part of regulatory requirements in the UAE, the regulated entity must file a Suspicious Activity Report (SAR) or Suspicious Transaction Report (STR) on the goAML portal when suspicious activity pertaining to ML/FT and PF is detected.

If the customer’s risk shift is attributed to engagement in such suspicious activity, the regulated entity must file SAR or STR on the goAML Portal while ensuring compliance with the “no tipping off” requirement.

Concluding thoughts on addressing the shift of low-Risk customers to high-Risk status

The transition of a customer from a low-risk category to a high-risk underlines the changing nature of financial risk associated with customers. Timely evaluation of the customer’s shift is not just a necessity but an essential component for maintaining the integrity of the AML framework. This shift demands vigilant monitoring, proactive measures, and adherence to robust AML compliance protocols, which are vital in mitigating potential risks.

With a proactive approach and robust measures, regulated entities can effectively address such shifts and mitigate the risks associated with high-risk customers. Implementing measures related to such shifts helps to make decisions that underscore its commitment to uphold its regulatory obligations to combat illicit financial crimes.

FAQs about Customer Risk Ratings and AML Measures

What is risk assessment under the UAE’s AML compliance framework?

The Customer Risk Assessment is a critical AML measure that identifies each customer’s money laundering, financing of terrorism or proliferation financing (ML/FT and PF) risk and categorises them according to their associated risk. Customer risk assessment is crucial as it helps the entity determine the nature of CDD measures to be applied.

In the UAE, customers are classified into three main categories: low risk, medium risk, and high risk, based on ML/FT/PF risk associated with the customer.

Customers classified as high-risk require enhanced due diligence (EDD) measures to mitigate the elevated risk associated with their business relationship. EDD measures include conducting additional background checks, verifying the source of funds and wealth, obtaining approval from senior management before establishing or continuing the relationship, and monitoring transactions with more scrutiny.

Ongoing monitoring refers to continuously reviewing the customer profile and transactions throughout the business relationship. It involves regularly reviewing customer information, transaction patterns, and any relevant changes in risk factors.

Begin your AML compliance journey with a positive first step.

Contact our team to handle your Ongoing Monitoring.

About the Author

Pathik Shah

FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)

Pathik is an ACAMS-certified AML consultant specialising in governance, risk, and compliance for regulated entities in the UAE. He brings over 28 years of experience, with 1,000+ hours of AML training and 200+ advisory engagements across DNFBPs, VASPs, and FIs. He supports businesses in aligning with AML/CFT requirements from the CBUAE, DFSA, MoET, MoJ, VARA, CMA, FSRA, and FATF. Known for translating complex regulations into audit-ready procedures, Pathik enables operational clarity and compliance readiness.

Reach Out to Pathik

AML Compliance for Online Jewellery Marketplace

AML Compliance for Online Jewellery Marketplace

Blogs

Table of Contents

Protect your business with reliable and effective AML strategies with AML UAE.

AML Compliance for Online Jewellery Marketplace

Precious metals and stones and jewellery made from such precious metals/stones are prone to high risk of money laundering, irrespective of the channel through which commercial transactions take place. Thus, anti-money laundering (AML) compliance is equally essential for online jewellery marketplaces to safeguard the penetration of the launderers in the virtual commercial platform.

Before discussing AML compliance for the online jewellery marketplace, let us understand what an online marketplace is.

Detect and deter money laundering in the
online jewellery marketplace

With our expert AML compliance services

What is an Online Marketplace?

Online marketplaces are e-commerce platforms enabling sellers and buyers to connect and conduct business. Such platforms are often known as online, electronic, or digital marketplaces. These platforms act as intermediaries, facilitating transactions between buyers and sellers. Online marketplaces offer convenience to both buyers and sellers across the globe and usually allow for cross-border transactions, enabling sellers to reach buyers beyond their local or national borders. The operators of online marketplaces provide several services to buyers and sellers using their platform, such as payment processing, order placement and customer support.

Online jewellery marketplace

The online jewellery marketplace refers to the segment of the e-commerce industry that facilitates the purchase and sale of jewellery, providing a platform to various customers and dealers in precious metals and stones.

Who qualifies as a “Customer” for online jewellery marketplaces?

As we understand it, a customer is a person who purchases goods or services from a supplier who is engaged in the supply of relevant goods or services. A customer can be an individual or a business.

Since the online marketplaces provide services to buyers and sellers to connect and deal in transactions, it can be said that both-

  1. the sellers listed on the online marketplace to sell their products
  2. the end consumer using the platform to buy the listed items

would come under the umbrella of “customer” for an online jewellery marketplace.

Let us first explore why AML compliance is essential for online jewellery marketplaces.

Why is the online jewellery marketplace prone to ML/FT risks?

There is a high level of anonymity on online platforms, giving an opportunity to money launderers and making it difficult to track down the sellers and buyers involved in such activities.

In general, the jewellery market involves high-value transactions. With online platforms, dealing in high-value transactions for jewellery can easily be done across borders within a split of a second with less suspicion. Thus, it becomes an attractive medium for money launderers.

Fake transactions have risen with the advancement of online marketplaces. Money launderers can form fake or mispriced transactions through online jewellery marketplaces to move high-value funds. Further, the risk of impersonation or using fake identities is rising in virtual commercial platforms.

Globalisation has increased cross-border transactions. However, there isn’t a coherence between the regulatory frameworks of the countries. Different regulatory regimes in different countries affect global transactions. Some countries have strict regimes, while others have few to no restrictions. Also, some jurisdictions do not pay heed to the supervision and monitoring of every transaction. Thus, because of the lack of a standard regulatory regime across the globe, the possibility of attempted money laundering transactions through online jewellery marketplace may go unnoticed.

ML, FT and PF typologies associated with online jewellery marketplaces

a. How are online jewellery marketplaces used by Money Launderers to carry out “Structuring”?

Money launderers use a structuring methodology for conducting transactions, breaking down large transactions into smaller ones to avoid suspicion. Generally, a transaction involving a large amount attracts suspicion and regulatory attention. In the case of online jewellery marketplaces, money launderers might conduct multiple transactions below the reporting threshold under a regulatory framework to avoid detection and consequences. Additionally, money launderers use the layering method, in which small transactions are conducted using different accounts.

b. Trade-Based Money Laundering using online jewellery marketplaces

Money launderers often exploit online jewellery marketplaces to engage in ML/FT activities and conceal and circulate illicit proceeds easily. This is due to the convenience of conducting transactions from anywhere, the global reach, and the anonymity offered by online platforms.

  • Circular transactions – Circular transactions refer to deceptive financial activities conducted among companies within a single group or under the control of a single owner. They are designed to obscure the origin and movement of illicit funds, posing a significant challenge to AML efforts.
  • Invoice tampering – Launderers can manipulate invoices related to jewellery transactions by increasing or decreasing prices, allowing them to move funds across borders.
  • False Documentation – Money launderers use false documentation related to jewellery transactions to legitimise the movement of illicit funds, making them appear legitimate transactions.

These methods show how money launderers can exploit online jewellery marketplaces.

Regulatory Framework for Online Marketplace

Telecommunications and Digital Government Regulatory Authority (TDRA) regulates the e-commerce framework and transactions in the UAE. TDRA approval is sought after obtaining the necessary eCommerce business license from the respective licensing authority, such as the Department of Economic Development (DED) for the UAE Mainland entities.

Laws pertaining to e-commerce/online marketplaces

The online jewellery marketplaces are subject to e-commerce laws as prevalent in the UAE.

Federal Decree-Law No. 14 of 2023 Concerning the Modern Technology-based Trade outlines regulations governing modern technology-based trade (Federal Decree no. 14 of 2023) is the primary law governing e-commerce, including an online jewellery marketplace.

This broadly encompasses how business is carried out by online marketplaces, which provide a platform to buyers and sellers and enable them to buy and sell goods and services through websites and applications.

AML Compliance for Online Jewellery Marketplace

Is there any mention of AML compliance in such laws?

Laws regulating the online marketplace do not cover the requirements needed to combat ML/FT and PF. To address the risk of ML/FT and proliferation financing of weapons of mass destruction, the UAE government, in accordance with the Financial Action Task Force (FATF) recommendations, has enacted laws and regulations to combat these.

AML Compliance for online marketplace, including online jewellery marketplace, can be linked to the following AML regulations due to its nature of dealing and facilitating transactions that involve Dealers in Precious Metals and Stones (DPMS):

  • Federal Decree by Law No. (10) of 2025 Regarding Anti-Money Laundering, and Combating the Financing of Terrorism and Proliferation Financing
  • Cabinet Resolution No. (134) of 2025 Concerning the Executive Regulations of Federal Decree-Law No. (10) of 2025 Concerning Combating Money Laundering, Terrorist Financing, and the Financing of the Proliferation of Weapons.
  • Cabinet Decision No. (74) of 2020 Regarding Terrorism Lists Regulation and Implementation of United Nations Security Council (UNSC) Resolutions on the Suppression and Combating of Terrorism, Terrorist Financing, Countering the Proliferation of Weapons of Mass Destruction and its Financing and Relevant Resolution.

Additionally, the UAE authorities have issued Supplemental Guidance for Dealers in Precious Metals & Stones (DPMS) as part of Guidelines for Designated Non-Financial Businesses and Professions. These guidelines help DPMS, including the online jewellery marketplace, better understand and implement the AML compliance measures.

AML Compliance measures to be undertaken by online jewellery marketplaces

An online jewellery marketplace should set certain requirements for both buyers and sellers to ensure smooth transactions and a safe environment. By implementing these requirements, an online jewellery marketplace can provide a safe and transparent environment for transactions, enhancing trust and confidence among users. Here is the list that should be considered before facilitating any transaction:

Requirement for Buyers and Sellers

  • The online jewellery marketplace should create a system allowing buyers to create an account on the platform and provide necessary information such as name, email address, and password to continue with transactions. Only with such a personal account would buyers be allowed to make and buy jewellery.
  • The online jewellery marketplace should create a system allowing sellers or suppliers to create an account on the platform. The platform should also have a system for necessary business information and documentation as per the country’s law.
  • The online jewellery marketplace shall establish a system for identifying buyers who need to verify their identity. This requirement is necessary to ensure security and prevent fraud, as jewellery involves high-value purchases.
  • The online jewellery marketplace should provide clear terms and conditions for buyers & sellers to establish rights and responsibilities when using the platform. The language of such terms and conditions should be simple for a clear understanding.
  • For listing sellers, the platform must carry out verification to ensure compliance with platform standards and regulations before allowing sellers to engage in business through its platform.
  • The online jewellery marketplace makes sure that sellers on its platform are able to provide the necessary information, records, and documents for inspection, especially concerning compliance with AML laws and regulations.
  • The online jewellery marketplace should allow buyers to make payments only through secure payment options available to them, ensuring convenience and security during transactions. Additionally, restrictions should be imposed on cash transactions involving high-value transactions.
  • The online jewellery marketplace should incorporate a robust customer support system to assist buyers with inquiries, issues, or disputes they may encounter during the purchasing process. It should also include a system for sellers to leave reviews to provide feedback on their experiences and reporting of transactions where the buyer is suspected of being involved in ML/FT cases.

Insistence on AML Compliance from DPMS listed on the Platform

An online jewellery marketplace platform should ensure that all suppliers willing to list themselves comply with AML obligations defined under the respective country’s AML regulations before allowing them access to the platform to execute commercial transactions.

Before listing themselves on an online marketplace platform, jewellery suppliers must take necessary measures to mitigate ML/FT risks. One key measure is implementing strong and effective internal policies, controls, and procedures. Suppliers of jewellery must periodically assess these policies for effectiveness and update them accordingly as and when the need arises to ensure that no criminals exploit their business under the guise of the online marketplace.

The following is the list of policy requirements that jewellery suppliers on an online platform must include in their AML/CFT Policy Manual:

Additionally, an online jewellery marketplace should check that all DPMS sellers listed on its platform comply with the requirement of filing the Dealers in Precious Metals and Stones Report (DPMSR) on the goAML portal for the specified transactions exceeding a certain amount.

Implementation of a Risk-Based Approach

The online jewellery marketplace that facilitates jewellery transactions should have policies, procedures, systems, and controls in place in accordance with the risk-based approach (RBA) as prescribed by the UAE federal laws and FATF while supervising the transactions between buyers and sellers that it facilitates. The RBA calls for applying risk mitigation measures proportionate to the ML/FT and PF risk the business is exposed to.

As part of the risk assessment process, an online jewellery marketplace must identify specific areas of business that customers are more likely to use in order to conduct any ML/FT or PF. The online marketplace must consider the following risk factors:

  • Customer risk – In any online jewellery marketplace, customer risk refers to customer categories based on the assessment of factors that may expose them to potential financial crimes. This risk may arise from dealing with PEP (Politically Exposed Persons) or Sanctioned Individuals.
  • Geographic risk – Geographic risk for an online jewellery marketplace would mean the risk associated with transactions from which the seller/buyer originates. This may relate to jurisdictions with a higher likelihood of financial crime or inadequate regulatory frameworks.
  • Product risk – Product risk means assessing how vulnerable the product is to the online jewellery marketplace. Naturally, dealing in precious metals and stones is a risky affair, and the probability that sellers or buyers will engage in unethical or illegal activities must be assessed by the online jewellery marketplace.
  • Transactional and Delivery-Channel Risk – This relates to the potential risk for financial crime facilitated by the method of delivery, mode of payment or transfer of funds within and to the online jewellery marketplace by using wire transfers, virtual assets, routing transactions through multiple accounts and complex web of transactions.

Establishing AML Governance within the online jewellery marketplace

An Online jewellery marketplace should ensure that ML/FT and PF risk is minimised through the platform and establish a robust AML governance by formulating and implementing comprehensive AML/CFT policies and procedures to safeguard the platform from illicit activities.

  • An Online jewellery marketplace should enforce stringent AML/CFT policies and procedures encompassing customer due diligence (CDD) processes, including verifying customer identities and monitoring transactions for suspicious activities.
  • It should also employ such technologies to enhance the detection of irregular or high-value transactions and ensure compliance with regulatory requirements.
  • Additionally, suppliers’ role in maintaining the integrity of the marketplace is very critical. An online marketplace should also conduct periodic assessments and audits of suppliers to ensure ongoing compliance and mitigate potential risks.
  • An online marketplace should appoint an AML Compliance Officer, who would be responsible for designing, implementing, and monitoring our AML/CFT policies and procedures. Further, an online marketplace shall also make sure that its suppliers appoint an AML Compliance Officer to oversee their respective AML/CFT efforts.
  • As regulatory compliance, an online jewellery marketplace should register themselves on the goAML portal. It must also mandate the goAML registration of the listed suppliers.

Customer Due Diligence (CDD)

An Online jewellery marketplace should conduct comprehensive CDD procedures for customers and suppliers engaging in transactions on an online platform to verify their identities and assess the nature of their activities. Similarly, the suppliers listed on the platform must apply necessary CDD measures to mitigate the risk arising from buyers who are proposed to be onboarded through the online platform.

Know Your Customer

Know Your Customer (KYC) is a process of identifying and verifying customers before commencing a business relationship.

  • Online Marketplace:- To combat ML/FT threats, Online jewellery marketplaces must implement an adequate KYC program. An online marketplace must identify the natural or legal person with whom the business is proposing to transact, including their background, so it does not expose the platform to such criminals. For verification of identity, necessary documents must be obtained, such as identity and address proof.
  • Supplier:- An online marketplace should also ensure that its suppliers implement KYC measures and monitor their customers obtained through online and offline jewellery marketplaces. For verification, the supplier can use and rely on the documents obtained from the buyer by the online marketplace.

Customer Risk Assessment

The Customer Risk Assessment is all about identifying and evaluating the ML/FT risk the buyer and seller pose to the business.

  • Online jewellery marketplace:- An Online jewellery marketplace must conduct a Customer Risk Assessment by evaluating various factors such as transaction volume, geographical locations, frequency of transactions, and the type of jewellery sold. Additionally, the buyers must be segmented based on risk levels such as low-risk, medium-risk, and high-risk. It should also assess supplier risk based on factors like location, reputation, compliance history, and the nature of the jewellery supplied and classify the suppliers into different risk categories.
  • Supplier:- An online jewellery marketplace should also ensure that its suppliers are performing customer risk profiling to better understand the risks involved with customers obtained through the online marketplace. The risk assessed by the online marketplace and the supplier for the same buyer may differ, considering each of their business risk assessment.

Enhanced Due Diligence (EDD)

As part of CDD, if the customer’s risk is identified as high, the online jewellery marketplace must implement EDD measures to further mitigate risks associated with ML/FT. This would include the application of enhanced checks on the identity of the customers, seeking additional documents pertaining to the customer’s sources of funds, and onboarding customers only after senior management approval. Similar EDD measures must be implemented by the suppliers when the customer risk profiling suggests increased ML/FT risk.

Ongoing Monitoring of Business Relationships and Transactions

Ongoing monitoring of business relationships within an online jewellery marketplace should include the continuous evaluation of customer interactions and transactions to assess the legitimacy of these relationships. This includes keeping detailed records of customer profiles, transaction histories, and communication exchanges to facilitate ongoing monitoring and analysis.

The fundamental goal of this ongoing monitoring is to uncover suspicious activity.

  • Online jewellery marketplace:- An online jewellery marketplace must engage in continuous surveillance of transactions occurring on its platform to identify and mitigate potential risks associated with financial crimes. Transaction monitoring must include monitoring for unusually large transactions, transactions involving the same parties, and transactions that deviate from typical customer behaviour. Upon detection of suspicious activity, it should conduct reviews and take necessary actions to mitigate the risk, including reporting the same on the goAML Portal. Similarly, it must monitor business relationships with suppliers on an ongoing basis to ensure compliance with regulatory requirements and mitigate risks associated with financial crimes. This includes regular reviews of supplier performance, transactional performance, and compliance with contractual obligations.
  • Supplier:- Additionally, an online jewellery marketplace should ensure that its suppliers have an ongoing monitoring program in place for their customers and that such procedures are mentioned in their AML/CFT policies and procedures.

Reporting of Suspicious Activities/ Transactions  

An online jewellery marketplace shall ensure that all transactions likely to be part of an ML/FT and PF deal are reported to the regulatory authority in a manner prescribed by law. Thus, an online marketplace should document the relevant red flags that suggest the transaction’s likely association with ML/FT activities.  

Red flags and the Importance of Red Flag Warning

Red Flags are indicators that can help identify illegal activities like ML/FT. They are also called suspicion indicators or risk indicators. Generally, red flags are warning signs that businesses should remain alert for potential money laundering and terrorists.

The growing online jewellery marketplace has made jewellery dealings diverse. This interconnectedness of the online jewellery system has created opportunities for criminals to engage in ML/FT and PF.

List of Red Flags applicable to online jewellery marketplace

  • Customer uses more than one national or foreign bank account under his name.
  • The seller is selling products to selective customers.
  • Sudden change in the mode of payment at the time of conclusion of the transactions without any explainable or logical reason.
  • DPMS sellers frequently enter transactions of an abnormally large amount.
  • DPMS has multiple bank accounts without any business sense or DPMS entities operating bank accounts in the employee’s name.
  • Unreasonable behaviour of large complex transactions by newly formed/listed DPMS entities.
  • Irregular shipping methods inconsistent with the standard business practice of DPMS.
  • Inconsistent documentation or forged documents to disguise the transaction.

After being aware of red flags, an organisation needs to take action to report such transactions. Online jewellery marketplace and the suppliers should keep track of questionable transactions and customers and if any ML/FT/PF suspicion is observed, reporting the same with the FIU by filing suspicious transaction report (STR) or a suspicious activity report (SAR).

Sanctions Compliance Program

To ensure complete regulatory compliance for AML/CFT requirements, an online jewellery marketplace should develop a comprehensive Targeted Financial Sanctions (TFS) program that is designed to ensure adherence to relevant sanctions regimes and mitigate the risk of engaging with sanctioned individuals, entities, or jurisdictions.

  • online jewellery marketplace must have its sanctions compliance policy, which provides the procedures to carry out screening of the customers and suppliers against relevant sanctions lists and implement appropriate controls to prevent engagement with sanctioned entities.
  • A similar sanction compliance program is expected to be implemented by the suppliers, ensuring dual checks for the sanctions and restricting the access of the platform to such criminals.

Maintenance of Records

Entities subject to AML compliance must retain all records, documents, data, and statistics for all transactions for the period required under the applicable law.

  • Online jewellery marketplace needs to maintain comprehensive records of AML policies, relevant documents, transaction monitoring activities, and any remedial actions taken in response to identified risks. These records should be securely recorded and regularly reviewed to ensure accuracy and completeness and must be made readily available to the authorities when requested.
  • Further, the supplier must also retain all the records of the e-commerce transactions routed through the online jewellery marketplace.

With AML UAE, let’s make your online jewellery marketplace a safe business spot!

An online jewellery marketplace demands a vigilant approach to AML/CFT compliance due to the expansion of digital platforms, which may facilitate illicit activities. Therefore, it’s important for online jewellery marketplaces to implement AML/CFT measures in accordance with relevant regulatory frameworks.

Implementing a dedicated framework to combat ML/TF safeguards an online marketplace, upholds regulatory standards, and maintains trust among suppliers and buyers. Thus, by prioritising AML/CFT compliance, online jewellery marketplaces contribute to a safer and more secure digital marketplace for the global jewellery industry.

FAQs on AML Compliance for Online Jewellery Marketplace

What is an Online Marketplace?

An online marketplace is a centralised online platform where buyers and sellers of goods and services conduct business.

The Telecommunications and Digital Government Regulatory Authority (TDRA) regulates the licensing and supervision of online marketplaces, and the Central Bank of the UAE (CBUAE) and the Securities and Commodities Authority (SCA) govern and supervise the digital currency transaction services provided by such online marketplaces.

Online jewellery marketplaces, because of their nature of dealing in jewellery, are required to register themselves on the goAML Portal.

Begin your AML compliance journey with a positive first step.

Contact our team to handle your goAML registration process.

Share via :

About the Author

Pathik Shah

FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)

Pathik is an ACAMS-certified AML consultant specialising in governance, risk, and compliance for regulated entities in the UAE. He brings over 28 years of experience, with 1,000+ hours of AML training and 200+ advisory engagements across DNFBPs, VASPs, and FIs. He supports businesses in aligning with AML/CFT requirements from the CBUAE, DFSA, MoET, MoJ, VARA, CMA, FSRA, and FATF. Known for translating complex regulations into audit-ready procedures, Pathik enables operational clarity and compliance readiness.

Reach Out to Pathik

Top 5 methods Criminals use to Launder money

Blogs

Table of Contents

Protect your business with reliable and effective AML strategies with AML UAE.

Top 5 methods Criminals use to Launder money

Money Laundering has become a massive problem for governments as the issue is escalating daily. It hits the world economy badly as the vast amount of money is used to fund illegal activities and fund terrorism. As per a recent UN report, approximately $ 800 billion – USD 2 trillion is laundered every year, accounting for 2-5% of global GDP. Anti-money laundering laws, rules, and regulations are implemented to detect suspicious accounts and transactions and trace the source of the illegal money. Now the question arises: what are the products and services that can be potentially used for money laundering activity, and how? So, let’s jump into it and discuss the top 5 methods criminals use to launder money and evade government scrutiny. 

Top 5 Money Laundering techniques used by criminals in modern era

Top 5 Money Laundering techniques used by criminals in modern era

1. Instant Messaging

Who would have thought the instant messaging platform would become a popular choice for criminals to launder their dirty money? Criminals use instant messaging apps, which are more than messaging apps, and offer services that make payment facilities available.

Online transfers have reduced cash transactions to a great extent. With the vast amount of transactions being made on messaging platforms, tracking might be a problem, so businesses need to be vigilant and track down suspicious transactions and fake accounts. Companies will require resources and a team to identify such doubtful transactions.

AML training can help companies stay ahead of the criminals and know if the messaging platforms are misused. Training will equip them with updated knowledge of the technology being used and adopt a proactive approach to detect any suspicious transaction immediately. 

2. Online Games

The online gaming industry today is growing by leaps and bounds. Criminals have found the gaming platforms to be a potential opportunity to launder money. The games use virtual currencies which users can trade for real cash.

There are no specific regulations for online trading in the gaming industry, so criminals set up numerous accounts in different jurisdictions to transfer money. They purchase in-game credits and transfer them to launder money. They also create fake accounts or hack existing accounts to steal other players’ credits, and all these attempts are made to increase the virtual currencies, which they can later trade for cash.

3. Gift Cards

Gift cards enjoy immense popularity. After the card is activated, criminals quickly transfer the funds available or use them to buy products sold for cash. Stolen debit or credit cards are rampantly used to purchase prepaid cards, and then they are further sold for money.

The method adopted by the criminals is to copy the serial numbers of the cards, scratch the security code and later cover them up. So, it’s essential to catch the criminals when the cards are stolen as these can be used to launder money. A method adopted to prevent prepaid cards for money laundering is that retailers limit the number of prepaid cards anyone can buy in a day.

4. Cryptocurrency

Cryptocurrency is one of the most popular virtual currencies, and criminals are using this newest kid on the block to launder money. This digital currency is protected by encryption which prevents double-spending. But this currency is not issued by the central government and not regulated by the government, so they become a favourite method of the money launderers. Moreover, it is also banned in some countries.

For instance, the Chinese government has stated that all transactions in cryptocurrency are invalid. Though cryptocurrency may not pose a massive threat to a particular country’s currency, its increased use and entry into the mainstream medium of value exchange is undoubtedly something to worry about.

Today, the digital world is expanding, and many large-scale companies accept this modern currency for providing their products and services. So, it allows criminals to make transactions and indulge in financial terrorism. A recent study has revealed that approximately 56 % of worldwide crypto exchanges do not have a robust KYC process. People use this loophole and use digital currency to launder money.

5. Shell Companies

Criminals often use shell companies or front companies to launder money to hide the identity of the true beneficiary of the proceeds or the profit of the illegal activities. The modus operandi is to sell goods at discounted prices and show false profits. The legal and illicit money is mixed to make them appear legal and avoid scrutiny. This money is used to fund illegal activities.

Conclusion

Governments rely on the newest technology and software solutions, such as the AML software dedicated to identifying and detecting money-laundering activities with advancements in technology. Technologies such as Blockchain are being considered to combat money laundering offences successfully. On the flip side, criminals, too, are using technology to their advantage and using innovative ways to launder money. Criminals use various money laundering methods, and the regulated entities must be prepared to counter them.

Criminals will do whatever it takes to make their fraudulent activities successful. They use creative ways to launder money. A proactive approach is required to help the business stay ahead of the criminals as a business owner. It is crucial to have a robust AML compliance program, exposure to technology, and the right team to help identify the criminals.

It’s better to be prepared and choose a reliable AML service provider that will bring value to the table with its array of services. Right from AML/ CFT policy, controls and Procedure documentation to the creation of Risk assessment report and AML health check-up to the

proper AML software selection, the provider will help your business avoid the risk of non-compliance and follow the AML rules and regulations at all times. 

AML UAE is on the mission to empower companies to make them AML compliant. With end-to-end AML compliance services, get complete peace of mind and keep a vigilant eye on the criminals indulging in money laundering and other financial crimes. 

FAQs

What methods are used to launder money? 

The various methods used to launder money include: 

  • Using smurfs, mules, or shells 
  • Gambling 
  • Investing in real estate and then selling it  
  • Investing in jewellery and moving it to other jurisdictions 
  • Online auctions and sales 
  • Virtual currencies 
  • Anonymous online payment services 
  • Fake identities 
  • Counterfeiting 

The most common method of money laundering is using smurfs, shells, or mules.  

  • Smurfing means dividing large sums of money into smaller transactions. 
  • Mules are individuals smuggling money. 
  • Money launderers create shell companies to hide illegal transactions and evade taxes. 

Businesses primarily used for money laundering are: 

  • Financial institutions 
  • Real estate agents 
  • Dealers in precious metals and gems 
  • Trust and company service providers 
  • Lawyers, notaries, and other legal professionals 
  • Accountants and auditors 

Most money laundering activities happen because of the illegal activities of terrorism, drug and sex trafficking, smuggling, gambling, cybercrime, and many others.  

Share via :

About the Author

Jyoti Maheshwari

CAMS, ACA

Jyoti has over 11 years of hands-on experience in regulatory compliance, policymaking, risk management, technology consultancy, and implementation. She holds vast experience with Anti-Money Laundering rules and regulations and helps companies deploy adequate mitigation measures and comply with legal requirements. Jyoti has been instrumental in optimizing business processes, documenting business requirements, preparing FRD, BRD, and SRS, and implementing IT solutions.

Reach Out to Jyoti

Mistakes to avoid during goAML registration

Common-goAML-registration-mistakes-to-tackle

Blogs

Table of Contents

Protect your business with reliable and effective AML strategies with AML UAE.

Mistakes to avoid during goAML registration

Every regulated entity – a Financial Institution, Designated Non-Financial Business and Profession (DNFBP) and a Virtual Asset Service Provider (VASP) is required to access the Financial Intelligence Unit’s (FIU) goAML Portal for submitting various AML reports. Under Article 18 of Federal Decree-Law No. 10 of 2025, read with Articles 17 to 19 of Cabinet Resolution No. 134 of 2025, a regulated entity that suspects a transaction is linked to a crime must file a report with the UAE Financial Intelligence Unit through the goAML portal without delay, and must not tip off the customer. This calls for mandatory registration on the goAML Portal.

The goAML registration involves a 2-stages, but it is a simple and straightforward process. So, you must ensure that you do not commit the usual blunders.

This blog lists these typical errors you must avoid while registering on UAE’s goAML Portal.

Detect and deter money laundering in the real estate sector with our expert AML compliance services.

Take action now!

Common goAML registration mistakes to tackle

As a regulated entity subject to AML compliance in the UAE, you must take care of the following mistakes while registering the business on the UAE FIU’s goAML Portal:

Not following the step-by-step procedure of goAML registration

Any new business incorporated in UAE that qualifies as a financial institution, a DNFBP, or a VASP under the AML regime must register on the goAML Portal. While registering on the portal, you must follow each step in the correct sequence. Missing any instruction or doing it inaccurately will disturb the entire registration flow, ending up in an error message or rejection email from the supervisory authority or the FIU.

If the assistance text on the portal offers any notes or directives, follow that. For example, if the instruction mentions avoiding using “+” while entering the contact details, this must be complied with.

So, you must follow the step-by-step procedure to complete your goAML registration. Follow whatever is asked in each step to avoid mistakes and last-minute hassles. You can find the sequence of goAML registration in our publication – goAML Registration Guide.

Erroneous, insufficient, or missing documents

To proceed with the goAML registration, reporting entities must submit relevant documents. These documents serve as proof of the business’s identity and the identification of the person nominated as AML Compliance Officer. These documents include:

  • A copy of the regulated entity’s trade license
  • Authorization letter authorising a person’s appointment as the entity’s AML Compliance Officer
  • A copy of the AML Compliance Officer’s identity documents – Emirates ID, passport, and resident visa

You must ensure that you do not miss attaching any of these documents. Also, these must be accurate and up-to-date. Only valid and legible copies of the required documents must be attached.

If you miss any document or attach an inaccurate copy, a rejection email from the supervisory authority would become inevitable. This will delay the registration process. So, ensure not to make this error for a smooth goAML registration.

Outdated or wrong information

Another mistake most regulated entities make while registering on the goAML portal is feeding incorrect information.

While filling in the information on the portal, you need to provide the following details:

  • Registration type
  • Company name
  • ID number
  • Supervisory body
  • Individual’s name representing the company and making the application on the goAML portal
  • Nationality of the individual
  • Contact details (phone number and email address)

Make sure that you fill in accurate information in these fields. If you have mentioned an incorrect email ID, you will never hear back from the FIU on your goAML registration application status.

Also, once you are registered on the goAML portal, if there are any changes in the details already furnished on the portal (such as a change in the Compliance Officer or the registered mobile number), you must change it on the goAML portal. Maintaining incorrect or outdated information might lead to missing out on critical communication from FIU or even cancelling the goAML registration.

So, submit and maintain error-free data for a smooth ride through the goAML Portal.

Not using a valid email address and mobile number for registration

The first stage of goAML registration involves registering on the Service Access Control Manager (SACM) system. This step gives you a username and Secret Key to access the Google Authenticator.

You need a registered email ID to access this username and Secret Key. Also, you need a registered UAE mobile number to download the Google Authenticator app.

Mistakes to avoid during goAML registration

So, you must use a valid email address and mobile number in the first stage.

In this first step, you must access the webpage:  https://services.uaefiu.gov.ae/sacm/registration.php.

You must fill in all the details on the form. It includes an email address and phone number where you will receive the OTPs. You will then receive the email OTP and URL, after which you can access the Secret Key and username. After this, you must download the Google Authenticator app on your registered mobile number to create your account.

Upon signing in to this account on SACM, you are directed to the goAML page for the next steps of the registration process.

So, if you don’t have a valid mobile number and email ID, you cannot proceed with the goAML registration.

Weak system security

Security of your login credentials to the goAML portal is essential. It might result in compromising your goAML account’s security. So, you must be careful about it by managing the following:

  • Ensure your Google Authenticator is set up on a secure and safe device from unauthorised users.
  • Use strong IDs and passwords to avoid possible hacking.
  • Keep changing passwords at regular intervals.
  • Do not share the login credentials with anyone.
  • If any new user is to be set up on the goAML Portal under your business’s registration, obtain necessary approval from the senior management and AML Compliance Officer.

Thus, keeping your goAML portal secure and confidential can protect your account from a possible security breach and inadvertent access.

Missing relevant notifications from regulatory authorities

Your concerned regulatory authority or the FIU might send you notifications for goAML registration or related matters. If required, whitelist the email IDs to which the FIU responds or sends an update around the registration application.

You must keep yourself abreast of these notifications coming from the FIU. Such notifications may request additional details or highlight any inconsistency in the goAML registration application you have made.

If you miss these notifications, it might delay the registration process. So, ensure that you pay attention to every communication received from the FIU.

AML UAE as your goAML Registration Partner

AML UAE is a distinguished and trustworthy provider of AML compliance services in the UAE. We help you with all the documentation, formalities, and reporting to comply with AML laws. Our legal experts and AML professionals ensure the best AML advice for your business.

Our team understands the gravity of AML laws for any business. If these laws’ provisions and requirements are not met, you can face penalties. So, we provide our AML expertise to your business to enable smooth and hassle-free AML compliance. Our services include help in goAML registration and report submission, among others.

Begin your AML compliance journey with a positive first step.

Contact our team to handle your goAML registration process.

Share via :

About the Author

Pathik Shah

FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)

Pathik is an ACAMS-certified AML consultant specialising in governance, risk, and compliance for regulated entities in the UAE. He brings over 28 years of experience, with 1,000+ hours of AML training and 200+ advisory engagements across DNFBPs, VASPs, and FIs. He supports businesses in aligning with AML/CFT requirements from the CBUAE, DFSA, MoET, MoJ, VARA, CMA, FSRA, and FATF. Known for translating complex regulations into audit-ready procedures, Pathik enables operational clarity and compliance readiness.

Reach Out to Pathik

A Guide to Avoiding Common Mistakes in AML Compliance for VASPs

http://13.233.15.5/a-guide-on-mistakes-to-avoid-in-aml-compliance-for-vasps/

Blogs

Table of Contents

Protect your business with reliable and effective AML strategies with AML UAE.

A Guide to Avoiding Common Mistakes in AML Compliance for VASPs

With the rise of instances of money laundering in the virtual assets ecosystem, the UAE government introduced anti-money laundering regulations to supervise and safeguard this sector. Virtual asset service providers (VASPs) operating in the UAE must know these rules. Virtual asset service providers are regulated under Articles 19 and 20 of Federal Decree-Law No. 10 of 2025 and Articles 4 and 36 of Cabinet Resolution No. 134 of 2025, and must be licensed or registered before carrying on any virtual asset activity. You must create a customised AML framework aligning with these rules and regulations, in sync with the nature and size of the virtual asset activities. While implementing them, be careful of the common mistakes to avoid in AML compliance for VASPs for effective results.

This blog explores these common AML compliance challenges that a VASP must avoid. By avoiding them, you are adopting an effective methodology for achieving your AML compliance obligations and protecting virtual assets from ML/FT vulnerabilities. Before covering the mistakes, we’ll understand why the money laundering threats affect VASPs’ businesses.

Stay ahead in the fight against financial crimes.

Join AML UAE’s hands to sidestep common pitfalls.

Why is the threat of money laundering looming over VASP businesses?

What is the primary factor influencing money laundering activities? Disguised or concealed identities. By hiding their identities, money launderers bring illicit money into the legal financial system and layer it with other transactions.

This is so much possible in the case of cryptocurrencies and virtual assets. The reasons being:

  • The virtual asset transactions are decentralised
  • These transactions allow anonymity or pseudo-anonymity
  • High-value and high-frequency transactions are common
  • Easy and quick transfer of virtual assets from one person to another across boundaries
  • Regulatory frameworks for VASPs and virtual assets are still evolving

All these reasons increase their vulnerability to money laundering threats. So, virtual asset service providers must stay alert to the standard red flags and ML/FT typologies. These indicators must warn you of suspicious activity, which you can investigate further and prevent financial crime. You can find these red flags in our blog: Unusual Transaction Trends for VASPs.

These red-flag indicators help you spot a suspicious customer or transaction. After spotting, you can avoid or stop them. Besides this, you must follow the AML regulations as applicable to the VASPs (such as the Compliance and Risk Management Rulebook issued by VARA or the rulebooks issued by the ADGM’s FSRA or DIFC’s DFSA, along with Federal AML regulations). Per these regulations, you can achieve AML compliance by applying the following AML measures:

Mistakes to avoid in AML compliance for VASPs

VASPs invest in these measures and implement them in their operations. But during their planning or execution, you might face challenges. The following are the common mistakes to avoid in AML compliance for VASPs:

Inability to manage changes per AML regulatory updates

The world of virtual assets is a new and emerging business territory. People are still understanding its uses and benefits. Meanwhile, money launderers have already started using it for their illicit activities. They are leveraging the characteristics of virtual assets to launder dirty money. That is why the rules for VASPs are still evolving in the UAE to manage criminals’ new and sophisticated money laundering methods.

With such an evolutionary nature, you must keep track of regulatory changes. As and when laws change, you need to adjust your AML policies to them. If you miss these changes, your compliance will be incomplete or inaccurate, leading to penalties.

So, one key AML compliance challenge for a VASP to avoid is operating in an uncertain regulatory market. This leads to inconsistent AML practices. To cover this challenge, monitor the AML updates. As and when new rules are introduced, understand them and make relevant changes in your AML strategies. Thus, you can bring consistent and AML-compliant business practices to your virtual asset activities.

Difficulty in keeping pace with the technological innovations and developments

One common mistake to avoid in AML compliance by VASPs is not upgrading their technologies related to the compliance function.

Blockchain, cryptocurrency, and virtual asset worlds witness new technologies daily. Such technological innovations are a big challenge for VASPs.

You must up your game in the technological development space to bridge the gaps between the tools deployed by the criminals and the technologies you use for combating these crimes. Keep your systems updated and in alignment with the market requirements and the newer money laundering trends and patterns. Upgrade your system’s security and work on data protection. Investing in cybersecurity measures can reduce your vulnerability to security breaches and help mitigate ML/FT exposure.

Failure to assess risks to your business

You are a virtual asset service provider. So, you must know the potential risks to your business. If not, it is one of the severe mistakes around AML compliance. You must immediately get it done to identify and understand the risks and plan their AML control measures accordingly.

You must conduct an enterprise-wide risk assessment (EWRA) to identify the potential exposure to all aspects of your business. The risks can be from any or all of the following-

  • Customers and other parties involved
  • Products and services
  • Geographies of your business or where your customers are from
  • Delivery or distribution channels
  • Nature, size and complexity of the transactions
  • Technologies deployed

These factors might expose you to money laundering or terrorism financing risks. So, identify them, analyse their possible impact, and their level. You must be able to build your own business’s risk profile. A comparison of the risk profile with your risk appetite is the gap you want to fill with your AML efforts.

Remember to repeat this exercise regularly to stay on top of your business’s potential risks. You must update the risk assessment when business conditions and elements change.

The absence of a well-defined, customised AML framework

One of the critical aspects of AML compliance is the documented comprehensive AML framework. Without an AML framework, you do not have the policies, strategies, procedures, and controls. You must have a well-defined AML framework tailored to your business and the outcome of the ML/FT business risk assessment. These help you follow the AML compliance requirements and safeguard your virtual asset activities.

After the risk assessment, you need an AML compliance program to mitigate or manage these risks. It must have the following:

  • Relevant AML policies per your AML goals
  • Procedures for due diligence before customer onboarding and during business relationship
  • Checklist of red flags and process to spot them
  • Record-keeping and reporting systems for AML
  • Internal controls to combat these risks
  • Norms to comply with KYT and travel rule requirements
  • Procedures for ensuring effective implementation of the targeted financial sanctions

You must communicate these to all your departments and employees. Also, get approval from the senior management. Also, you must update the framework with regulatory amendments and revisions in business risks.

No focus on the customer due diligence

Customer due diligence is a critical part of any AML compliance program. Its correct and on-time performance is a vital AML compliance challenge for VASPs. However, this process is crucial for identifying suspicious customers and managing vulnerabilities.

Your CDD process must include:

  • Knowing your customer: You must collect the identity details of your customer, along with evidence. For legal entities, collect information on beneficial ownership, nature of business, etc.
  • Knowing your transaction: You must know the originator and beneficiary of a virtual asset transaction. Collect details on wallet addresses, transaction hashes, device identifiers, and other points that help you know it better.
  • Customer screening: The pseudo-anonymity of a virtual asset transaction makes it riskier. So, you need to be extra careful with whom you are dealing. You must match your customers against lists of sanctions, PEPs, terrorists, and adverse media. If matched, make informed decisions to ensure compliance with laws and management-approved risk appetite.
  • Customer risk profiling and enhanced due diligence for high-risk customers: The above three assessments help determine whether a customer or a transaction is high, medium, or low risk. Once you know the high-risk customers, you must apply enhanced due diligence for extra care. Seek information on the source and destination of funds, check their legitimacy, and double-check beneficial owners. Do not form a business relationship or conduct the transaction if it is doubtful.

Thus, all these steps of customer due diligence ensure you are in a better AML compliance position. You know your customers and their risk profiles so that you can decide accordingly. Such risk assessment allows you to take a risk-based approach to AML compliance.

No plan in place to Know Your Counterparty VASP

A virtual asset service provider sells, holds, exchanges, converts, safe-keeps, or transfers virtual assets on behalf of other legal or natural persons. So, in such virtual assets activities, more than one VASP is involved, and thus, such counterparty VASP may also pose a certain degree of risk, influencing the transaction. So, knowing your counterparty VASP is crucial for any virtual asset service provider.

http://13.233.15.5/a-guide-on-mistakes-to-avoid-in-aml-compliance-for-vasps/

Failing to do this is a crucial mistake to avoid in AML compliance for VASPs. So, you must make it a practice to check and know your VASP before engaging in a transaction. You can check the importance of this requirement on our blog: FATF Travel Rule and Know Your Corresponding VASPs.

Like customer profiling, check your counterparty VASP’s beneficial ownership. Make it a practice to check their compliance with the AML regulations. All these details will give you a better view of how legitimate or illegitimate their business is and what sort of risk it can bring to the virtual asset transaction.

Lack of AML training for employees

You must be aware of the applicable AML regulatory landscape. Besides, everyone in your team handling customers, transactions, or any other AML compliance procedure must learn about the process, including the senior management. All this knowledge enables the adequate performance of your business responsibilities while considering the AML measures and compliance obligations.

So, you must design a comprehensive AML training program for your employees. Include theoretical and practical training to facilitate a better understanding of procedures. Provide practical examples of cases with relevant live training on CDD, transaction monitoring, and sanction screening. It makes the conceptual clarity better and more accurate.

If not internally, you can hire an external AML consultant for imparting training. Partner with someone with expertise and experience in training different industries. Missing such training is a big mistake to avoid in AML compliance for VASPs.

Inability to find the right balance between user privacy and AML compliance requirements

The design and delivery of virtual assets is such that you can ensure anonymity. However, AML compliance requires you to gather all details on your customers. So, a proper balance between the two is essential. This is a big AML compliance challenge that VASP must avoid.

Virtual asset transactions sometimes enable the concealment of true identities. Some cryptocurrencies, like privacy coins, enhance anonymity and privacy.

This is in contrast to the AML requirements that VASPs must adhere to. You must get the customers’ identity and other details to fulfil the needs of KYC and CDD under AML. So, you need to find a balance between this anonymity and AML requirements.

Insufficient and incomplete records and reports

Another mistake to avoid in AML compliance for VASPs is insufficient recording and reporting. If you don’t keep records, it would be treated as non-compliance with record-keeping requirements, and also, you won’t have evidence to prove your regulatory compliance. Also, you’ll be unable to submit reports to authorities without such records. So, pay close attention to maintaining records and submitting reports to authorities.

Maintain records of KYC, CDD, customer screening, EDD, KYT, transactions executed, etc. Also, create and save records of transaction monitoring and suspicious transactions identified. These records must be up-to-date, comprehensive, and accurate. Authorities might ask for them during audits and investigations.

Another need is to create comprehensive reports of your AML measures and submit them to the necessary authorities. One mandatory provision is submitting a report on suspicious transactions and activities. Forgetting to do so leads to non-compliance and penalties. So, comply with the reporting and recording requirements of AML compliance in UAE.

You must be aware of and avoid these common mistakes in AML compliance for VASPs. By avoiding them, you make your AML compliance practices effective.

AML UAE – your partner for professional AML consulting services

AML UAE is one of the leading providers of AML consulting services to the VASPs operating in the UAE. We help clients face AML compliance requirements with complete preparations. You can find help with:

For any help in AML compliance, you’ll have the support of AML UAE.

Lacking AML compliance strategies?

Get in touch with us for AML services.

Share via :

About the Author

Jyoti Maheshwari

CAMS, ACA

Jyoti has over 11 years of hands-on experience in regulatory compliance, policymaking, risk management, technology consultancy, and implementation. She holds vast experience with Anti-Money Laundering rules and regulations and helps companies deploy adequate mitigation measures and comply with legal requirements. Jyoti has been instrumental in optimizing business processes, documenting business requirements, preparing FRD, BRD, and SRS, and implementing IT solutions.

Reach Out to Jyoti

A Guide to Sanction and PEP Screening in Customer Onboarding Process

A-Guide-to-Sanction-and-PEP-Screening-in-Customer-Onboarding-Process feature image

A guide to sanction and PEP screening in customer onboarding process

Table of Contents

Protect your business with reliable and effective AML strategies with AML UAE.

What are the various types of sanctions?

There are undoubtedly many types of sanctions. The sanctions are based on different reasons. The reasons and various kinds of sanctions are significant for business enterprises.

A guide to sanction and PEP screening in customer onboarding process

Sanctions are basically the penalties imposed on institutions or organizations that fail to comply with laws and regulations. Government or global organizations usually apply a sanction decision to other individuals or states. A sanction check is taken in order to prevent transactions with persons prohibited from certain activities and transactions.

There could be various reasons behind sanctions. However, the primary reasons behind sanctions could be economic or political disputes. Economic and political conflicts between two or more countries lead to
sanctions against each other.

In this article, we will discuss the importance of sanctions and PEP screening during the customer onboarding process.

1 - Economic Sanctions

Economic sanctions are basically a foreign policy instrument between war
and diplomacy. There are three main objectives of economic sanctions.

  • Undermining the target country
  • Punish the target country
  • Change the behavior of the target company.

2 - Military Sanctions

Some countries do not produce their own military equipment. Hence, the most common type of military sanctions is actually the prohibition of the sale of military equipment. With the help of this advantage, stronger states warn the weak states.

3 - Diplomatic Sanctions

Diplomatic sanctions are the political measures taken in order to express dissatisfaction between two or more governments. A few of the political sanctions are the cancellation of senior government visits and the withdrawal of diplomatic persons from the target country.

Compliance. Trust. Transparancy

Customized and cost-effective AML compliance services
to support your business always

Sanctions on Individuals

Sanctions on individuals are nothing but the sanctions imposed on economic persons, political leaders, or any illegal identities. Organizations sanction terrorists or governments, money launderers, drug traffickers are the people who are more likely to perform any sort of illicit activities, resulting in blockage of bank accounts.

Many local and global regulators effectively control financial institutions. The sole purpose of these sanction checks is to combat financial crimes. Regulators need these financial institutions to know their customers. Therefore, regulators regularly publish new customer guidelines.

Sanction and politically exposed person screening - PEP screening in customer onboarding process

For financial institutions (FIs), and Designated Non-Financial Businesses and Professions, the customer onboarding process is quite tedious and challenging. As per the know your customer (KYC) requirements, enterprises have to make some checks in the process of onboarding the customers.

Know Your Customer-KYC Requirements under AML regulations in UAE Min

The purpose behind PEP screening is to identify the ability of the customers to pose any threat or risks. The accuracy of the information of the customer is verified at the first stage. Once the customer identification information is confirmed, the level of risk of that particular customer is also identified.

Customer Due Diligence (CDD) and Enhanced Due Diligence (EDD) procedures enable the FIs and DNFBPS to identify the overall risk level involved.

Enhanced Due Diligence measures under UAE AML Regulations

PEP Screening Process

During the PEP Screening process, the customer is screened against the global list of PEPs. Politically exposed persons must be subject to the enhanced measures in Article 16 of Cabinet Resolution No. 134 of 2025, including senior-management approval and establishing the source of funds and wealth. The implementation of Targeted Financial Sanctions designed by the competent authority is expressed under Article 19(1)(e) of Federal Decree-Law No. 10 of 2025, implemented through Cabinet Resolution No. 74 of 2020 and the EOCN Guidance on Targeted Financial Sanctions (March 2026). The relatives and close associates (RCA) of a PEP are also screened. If there are positive matches, EDD is performed and depending upon the risk appetite of the management; customer onboarding is performed. 

Ongoing monitoring of PEPs is one of the most crucial aspects of PEP screening. PEP screening tools support ongoing monitoring and help comply with legal obligations.

Why is the sanction check and PEP check required for business companies?

Bribery, financing of terrorists, money laundering, and corruption are financial crimes that are considered highly hazardous all over the world. The majority of these financial crimes occur because of the loopholes in the law and economic systems.

Regulators try to prevent all of these financial crimes by thoroughly regulating the companies in the financial sector. Many anti-money laundering regulations have been published to serve this purpose individually.

In order to comply with these anti-money laundering regulations, financial institutions and DNFBPs should get involved in some sort of control process. Therefore, a sanction search and PEP screening are essential processes for financial institutions and DNFBPs to ensure AML compliancePEP and Sanctions checks help businesses take a risk-based approach and determine if they want to onboard a customer or continue with a business relationship.

AML Compliance Requirements in UAE

Sanction and PEP screening in the process of transaction screening

PEP Screening

Quite a lot of transactions take place throughout the day in your financial systems. Therefore, as per the anti-money laundering regulations, financial institutions should monitor the financial operations of their clients. If the financial transactions are not monitored, severe financial crimes like money laundering and terrorist financing come into play.

However, manually monitoring all your financial transactions can be a cumbersome and time-consuming process. Hence, you can use automated
tools to carry out sanctions and PEP screening.

Compliance. Trust. Transparancy

Customized and cost-effective AML compliance services to
support your business always

Politically exposed person screening in the process of background check

The most essential thing for companies or business enterprises is their reputation. If any business enterprise loses its reputation, it directly loses its customers or clients.

Enterprises make internal controls regularly in order to avoid all of these risks. Pre-employment background checks, employment background checks, and company background checks are taken by the companies in
order to protect the reputation of the company.

PEPs screening is performed against the politically exposed person list on the employees in order to check for the possibility of any sort of risk for the company. 

Watchlist and PEP screening helps regulated entities implement necessary controls while onboarding high-risk customers.

How do business enterprises comply with anti-money laundering regulations?

Financial institutions (FIs) and DNFBPs have to apply PEP sanctions checks on their clients in order to comply with anti-money laundering regulations.

Financial institutions need sanction screening in order to protect the reputation of the company and not to violate any sanctions-related decisions. With the ever-evolving technology, manual sanction checks and PEP screening have lost all the points and have become merely a way of wasting time.

There are pretty many sanctions listed across the world, and enterprises can practically and logically not check them all manually.

Hence, the need and importance of anti-money laundering screening software come into the picture. This type of software automates the complete compliance process of the enterprises.

In addition to that, financial institutions and DNFBPs can quickly check their clients with the help of automated compliance software. This type of PEP and Sanctions check software scans the sanction lists and instantly intimates the positive matches.

PEP Screening Software: Enhancing Due Diligence and Regulatory Compliance

To comply with the UAE AML Regulations, it’s essential that regulated entities carry out screening before onboarding a customer.

There are PEP Screening Tools available in the market which maintain a global database of politically exposed persons. The database is refreshed every hour making sure you always have access to the latest list. PEP Screening Software also supports ongoing monitoring of PEPs and Relatives and Close Associates (RCA) of PEPs. PEP Screening solutions help you meet legal obligations, and take a risk-based approach while onboarding a customer or entering into a transaction with him and record-keeping requirements.

In order to identify individuals holding prominent public positions or persons associated with individuals, the implementation of Politically Exposed Persons Screening Software is a must. PEP Screening Software helps regulated entities to identify and mitigate risks associated with PEPs.

Politically Exposed Person Screening under UAE AML Regulations

AML compliance Services

For FIs and DNFBPs, it is of utmost importance to apply sanctions and PEP screening mechanisms. AML UAE, with its team of professionals, provides expert advisory services in AML compliance. Get in touch with us to simplify your anti-money laundering compliance.

FAQs - A Guide to sanction and PEPs screening

Here are a few frequently asked questions About Sanction and PEP Screening

What is a PEP check?

AML PEP check means screening individuals against an already existing register of Politically Exposed Persons (PEPs) with their names, associates, and close family members.  

The PEP screening process is a part of the AML and KYC program of entities. It is a process by which companies can conduct due diligence on any individual or company with which it is entering into a business relationship to compare with the global lists of politically exposed persons. 

PEP means Politically Exposed Person. These are some high-profile roles, such as government leaders, politicians, military or judiciary officials, etc., who can be involved in money laundering or financial fraud activities because of their high-profile positions, which create prominent influence.  

Companies must collect information on their clients, such as their business name, registration details, geographical presence, beneficial owners, etc. You can match this information with the list of Politically Exposed Persons and identify if the client is a PEP or not.  

PEPs are of three types: 

  • Domestic: A high-profile person in the national government body 
  • Foreign: A high-profile person in a foreign government body, including foreign PEPs working in the domestic country.  
  • International: A high-profile person in an international organisation 

It is critical for organisations to know about the risks from customers or suppliers. For this, you need to collect information from them and verify it against the lists of PEPs or Sanctioned individuals. If they do not feature in the list, you can have a business relationship with them; if they feature,  you are supposed to carry out Enhanced Due Diligence (Obtain information about their source of funds), and with the management’s approval you can enter into business with them. 

PEPs can be any one of the following: 

  • Heads of countries or Government 
  • Senior politicians 
  • Officials holding senior positions in the Government 
  • Military or judiciary officials 
  • Officials of key political parties 
  • Senior executives from government companies 

Companies collect data on their customers, employees, and suppliers to check their names against the list of terrorists, PEPs, or Sanctions. This screening process helps to know your customers/clients better, serving as the best tool to avoid money laundering and terrorism financing activities.  

Pep screening means verifying an individual’s presence in the list of Politically Exposed Persons (PEPs) to identify them as high-risk customers.  

Sanction checks mean checking whether an individual or a company features in a list of sanction databases of governments to prohibit the possibility of money laundering or terrorist financing. 

Sanction list screening means verifying individuals and entities against the Sanction lists of countries to check if they are prohibited from carrying out certain activities.  

Customer screening to verify the data on customers against external data sources such as PEP list, Sanction list, Watch list, or adverse media to check their risks to the company.  

Here are a few best practices that you need to follow in order to ensure the efficacy and reliability of your sanction and PEP screening.

  • Integrate with a wide range of and high quality trusted data sources
  • Follow a risk-based approach
  • Conduct ongoing monitoring in the most effective and deliberate manner
  • Relying on best technological platforms
The answer to the above question is a legitimate NO. However, these can still be high-risk because of the nature and scope of their business. For example, they could be involved with terrorist financing, drug smuggling, and any other criminal activities. Hence proper customer due diligence (CDD) on beneficial ownership is needed based on their internal and risk- based approaches.
Global Sanctions are part of foreign policy, covering financial restrictions and prohibitions imposed by a country or groups of countries to ban another country, individuals/entities from doing business with them.
Politically Exposed Persons (PEPs) are natural persons involved in any prominent public function and have power or influence over the spending of government funds.
Through sanctions screening, the entities can avoid the risk of being vulnerable in the hands of money launderers or terrorists. At the same time, PEP screening aids in determining if the person is using the bad influence of their powers to exploit government funds and commit any financial crimes. Without adequate screening, the entities would be subject to non-compliance, exposed to financial crimes, and adversely impacted their reputation.
The following positions would be construed as a PEP:
– Head of Government
– Senior Politician
– Sr. Government Official
– Judicial/Military Official
– Sr. Executive of Government Corporation
– Sr. Official of Political Party
– Management of the international organization
Any family member and close business associates of the above would also be considered as an associated PEP.

Join the Fight against Financial Crimes!

Protect your business with reliable and effective
AML strategies with AML UAE.

Share via :

About the Author

Pathik Shah

FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)

Pathik is an ACAMS-certified AML consultant specialising in governance, risk, and compliance for regulated entities in the UAE. He brings over 28 years of experience, with 1,000+ hours of AML training and 200+ advisory engagements across DNFBPs, VASPs, and FIs. He supports businesses in aligning with AML/CFT requirements from the CBUAE, DFSA, MoET, MoJ, VARA, CMA, FSRA, and FATF. Known for translating complex regulations into audit-ready procedures, Pathik enables operational clarity and compliance readiness.

Reach Out to Pathik