AML Regulations for Lawyers, Notaries, and Other Legal Professionals in UAE

How the Ministry of Justice supervises the sector

Blogs

Published On: 04/29/2026

Table of Contents

Protect your business with reliable and effective AML strategies with AML UAE.

Last Reviewed On: 07/21/2026   |   Last Updated On: 07/21/2026

AML Regulations for Lawyers, Notaries, and Other Legal Professionals in UAE: At a Glance

  • Covered activities: Five activities under Article 3(4) of Cabinet Resolution 134/2025 bring a lawyer, notary, or legal consultant inside the AML regime.
  • Supervisory authority: The Ministry of Justice (MoJ) supervises law firms, legal consultancy offices, and notaries public under Ministerial Resolution 248 of 2025.
  • Primary legislation: Federal Decree-Law 10 of 2025 and Cabinet Resolution 134 of 2025 replace Federal Decree-Law 20 of 2018; all unrepealed circulars remain valid.
  • Administrative penalties: Forty-one violation categories under Cabinet Resolution 71 of 2024 carry fines ranging from AED 50,000 to AED 1,000,000, doubled on repetition.
  • Legal privilege: Article 18(2) of both Federal Decree Law No. (10) of 2025 and Cabinet Resolution No. (134) of 2025 protects defence, representation, arbitration, mediation, and legal opinion activities from the STR duty.
  • Reporting channel: Suspicious transactions go to the Financial Intelligence Unit through the goAML platform.
  • Record retention: Five years for customer records and all AML documentation, starting from the end of the business relationship or the completion of the transaction.
  • Free-zone carve-out: Firms licensed in ADGM and DIFC sit under ADGM (RA) and DFSA respectively; MoJ supervision does not apply to them.

AML Regulations for Lawyers, Notaries, and Other Legal Professionals in UAE

AML regulations for lawyers in UAE place five defined activities inside the anti-money-laundering perimeter and require lawyers, legal consultants, and notaries public under the supervisory remit of the Ministry of Justice. The current framework is anchored in Federal Decree-Law No. (10) of 2025 Regarding Anti-Money Laundering, and Combating the Financing of Terrorism and Proliferation Financing and its Executive Regulations in Cabinet Resolution No. (134) of 2025, both of which repealed Federal Decree-Law No. (20) of 2018 and its earlier Executive Regulations, while preserving every circular and notification that has not been specifically revoked.

This spoke article sits inside the DNFBPs regulatory cluster on AML UAE and focuses only on legal professionals supervised by the Ministry of Justice. Firms licensed in Abu Dhabi Global Market or the Dubai International Financial Centre sit under the ADGM Registration Authority (RA) and the DFSA, respectively, so this guide addresses their position only in the carve-out note at the end of the supervisor section. Every specific article number, penalty figure, timeline, and threshold below is traceable to a named instrument published on uaelegislation.gov.ae or to a named Ministry of Justice publication on moj.gov.ae. For the federal law in its own right, see the guide to anti-money laundering laws in UAE.

Scope of this page:

This page covers lawyers, notaries, and legal consultants performing the five covered activities under Article 3(4) of Cabinet Resolution 134/2025, supervised by the Ministry of Justice. Accountants, auditors, and trust and company service providers are addressed on their own sibling pages in the DNFBPs cluster. Where cross-sector rules are common to every DNFBP (for example beneficial owner disclosure, targeted financial sanctions, and administrative penalties), this page states what they require of legal professionals specifically and links to the pillar page for the wider framing.

Who Counts as a Lawyer, Notary, or Legal Professional for AML Purposes in UAE?

A lawyer, legal consultant, or notary public is inside the UAE AML regime when they prepare, carry out, or assist a client with any of the five activities listed in Article 3, Clause 4 of Cabinet Resolution 134 of 2025.

The Five Covered Activities Under Article 3(4) of Cabinet Resolution 134 of 2025

The Executive Regulations list the activities that bring an independent legal professional inside the AML perimeter. Each is a transactional or representational act carried out for or on behalf of a client; performing any one of them triggers customer due diligence, record keeping, suspicious transaction reporting, and the wider obligations set out in Federal Decree-Law 10 of 2025.

1. Real estate transactions

Buying or selling real estate, whether the professional acts for the buyer, the seller, or holds client funds in the course of the transaction.

2. Managing client money

Managing customer funds, securities, or other assets held in a professional or fiduciary capacity.

3. Account management

Managing bank accounts, savings accounts, or securities accounts for a client.

4. Company contributions

Organising contributions for establishing, operating, or managing companies.

5. Legal persons and arrangements

Establishing, operating, or managing legal persons or legal arrangements, or performing any trading or buying and selling of commercial entities.

Source: Article 3, Clause 4, Cabinet Resolution No. 134 of 2025. The same five activities appear in the definition of designated non-financial businesses and professions in Article 1 of Federal Decree-Law No. 10 of 2025, read with Article 3, Clause 2 of the Executive Regulations. 

Notaries Public

A notary public is a public officer who authenticates signatures, declarations, powers of attorney, contracts, and other legal documents. Notaries working in the private sector, private notaries, and the notarial sections of law firms are brought within the AML, in line with Article 3(4) of Cabinet Resolution 134 of 2025. Ministerial Resolution 248 of 2025 explicitly extends the Ministry of Justice supervisory framework to notaries public alongside law firms and legal consultancy offices.

Work Outside the AML Perimeter

From a professional secrecy perspective, Article 18, Clause 2 of Federal Decree-Law 10 of 2025 and Article 18, Clause 2 of Cabinet Resolution 134 of 2025 both carve out work involving assessing the client’s legal position, defending the client, or representing the client in judicial, administrative, arbitral, or mediation proceedings. Firms must still apply AML controls to the transactional elements of a matter even if the advocacy elements fall within privilege.

AML Supervisory Authority for Lawyers, Notaries, and Other Legal Professionals in UAE

The Ministry of Justice is the supervisory authority for law firms, legal consultancy offices, and notaries public in the Mainland. This was confirmed when Cabinet Resolution No. 134 of 2025 designated the Ministry of Justice as the authority responsible for supervising lawyers and legal firms for AML/CFT purposes. Ministerial Resolution No. (248) of 2025, issued on 29 April 2025, replaces Ministerial Resolutions 532 and 533 of 2019 and sets out the supervisory procedures and controls in their current form.

UAE AML Framework Layers That Apply to Legal Professionals

FEDERAL  FDL 10/2025 and CR 134/2025 (Executive Regulations); FL 7/2014 Combating Terrorism Crimes; FDL 34/2022 Legal Profession; CR 8/2025 Executive Regulations of FDL 34/2022. 
CROSS-SECTOR  CR 74/2020 TFS and UN sanctions; CR 109/2023 Beneficial Owner procedures; CR 132/2023 BO penalties; CR 71/2024 administrative penalties for MoJ and MoE supervisees; EOCN TFS Guideline and CPF Guidance. 
SECTOR-SPECIFIC  MR 248/2025 supervisory controls for law firms, legal consultancies, and notaries public; MoJ Guidebook (November 2025); MoJ circulars from 2020 to 2026. 

How the Ministry of Justice supervises the sector

Three operational building blocks explain how MoJ plans, conducts, and concludes supervisory action over legal professionals.

AML/CTF Department

The dedicated AML/CTF Department inside MoJ is the operational face of supervision, assigning inspectors and issuing guidance.

Risk-based inspections

Inspections follow a risk-based methodology that weights firm size, client profile, and the five covered activities.

Administrative sanctions

Breaches are dealt with under Cabinet Resolution 71 of 2024 and Article 6 of Ministerial Resolution 248 of 2025.

The MoJ AML/CTF Department and Its Fifteen Functions

The Guidebook for Law Firms and Legal Consultancy Offices on Combating Money Laundering, Countering the Financing of Terrorism and Countering Proliferation Financing, Second Edition, published by the Ministry of Justice in November, sets out fifteen functions for the Department. These include, among others, supervising law firms, legal consultancy offices, and notaries public for AML/CFT/CPF compliance; carrying out risk-based on-site and off-site inspections; imposing administrative sanctions and escalating suspected criminal conduct to prosecutors; cooperating with the Financial Intelligence Unit, the Executive Office for Control and Non-Proliferation, and other domestic and foreign counterparts; maintaining typologies; issuing sector guidance; and running awareness programmes.

Risk-Based Supervision and Inspection Readiness

Ministerial Resolution 248 of 2025 requires MoJ to adopt a risk-based approach when planning and conducting inspections and when deciding the scope and depth of each visit. Practically, this means firms are rated using factors such as client geographies, types of covered activities, complexity of legal persons being established or managed, cash handling, and past supervisory history.

A firm that is well prepared keeps a complete documentation pack at all times, including its firm-wide risk assessment, client risk assessments, sanctions screening logs, transaction risk assessments, STR-decision logs, training records, and a corrective action register showing how any previous findings have been closed out.

Inspection readiness is a continuous state, not a reaction

MoJ inspectors are entitled to request any AML document, client file, or system log at short notice. Firms that treat inspection readiness as a perpetual discipline, rather than a pre-visit scramble, consistently score better against the Guidebook’s controls.

Administrative Sanctions and Appeals

Article 6 of Ministerial Resolution 248 of 2025 provides that the AML Department may impose any of the administrative penalties set out in Cabinet Resolution 71 of 2024 on a law firm, legal consultancy office, or notary public that breaches the AML rules. The Guidebook identifies seven types of sanctions, which can include warnings, fines, restrictions on activity, suspension of managers or compliance officers, and suspension or cancellation of the licence.

A grievance may be filed with the Minister of Justice within twenty working days from the date of notification under Article 7 of MR 248 of 2025, with the Ministry responding within thirty working days under Article 8, failing which silence amounts to rejection per the general forty-day rule in Cabinet Resolution 71 of 2024.

Financial Free-Zone Carve-Out

Firms licensed in Abu Dhabi Global Market are supervised by the Registration Authority, and firms licensed in the Dubai International Financial Centre are supervised by the Dubai Financial Services Authority under the DIFC regulatory regime. MoJ supervision does not apply to them. A dual-licensed group of companies can adopt a group-wide AML programme while retaining separate records and applying the rulebook of the authority that licenses each leg of the business.

Dimension Mainland ADGM DIFC
Supervisory authority Ministry of Justice Registration Authority (RA) Dubai Financial Services Authority (DFSA)
Licensing authority  Ministry of Justice; Executive Council decisions for notaries Registration Authority of ADGM DIFC Authority
Core AML rulebook FDL 10/2025, CR 134/2025, CR 71/2024, MR 248/2025 FSRA AML Rulebook under ADGM Financial Services and Markets Regulations DFSA AML Module under the DIFC Regulatory Law
Sector guidance MoJ Guidebook for Law Firms and Legal Consultancy Offices (November 2025) FSRA-issued AML guidance for DNFBPs in ADGM DFSA-issued AML guidance for DNFBPs in DIFC 

Preparing for a MoJ inspection?

AML UAE runs pre-inspection readiness reviews against the MoJ Guidebook's ten obligations and Cabinet Resolution 71 of 2024 violations, with a prioritised remediation plan.

AML Regulations Applicable to Lawyers, Notaries, and Other Legal Professionals in UAE

The AML rulebook for legal professionals in the UAE is a stack. At the base sit the federal law and its Executive Regulations, followed by cross-sector resolutions on sanctions, beneficial ownership, and penalties. Sector-specific layers come next: Ministerial Resolution 248 of 2025 for supervision, the MoJ Guidebook for substantive controls, and a sequence of MoJ circulars that operationalise particular obligations. Overarching guidance from the Executive Office for Control and Non-Proliferation, the Financial Intelligence Unit, and the National Anti-Money Laundering and Combating the Financing of Terrorism Committee completes the picture.

Four groups of instruments every law firm must follow

Each group sits on a distinct tier of the framework; together, they form the complete AML rulebook for MoJ-supervised legal professionals.

1. Federal AML laws

Federal Decree-Law 10 of 2025 and Executive Regulations 134 of 2025, plus terrorism, beneficial owner, sanctions, and penalty resolutions.

2. Overarching guidance

EOCN TFS and CPF guidance, FIU strategic analysis, red flag typologies, and joint guidance on satisfactory practice.

3. NRA and SRA

UAE ML/TF National Risk Assessment 2024 and sectoral risk assessments feeding into MoJ’s supervisory priorities.

4. Sector instruments

MoJ Guidebook (November 2025) and circulars from 2020 to 2026 on CDD, TFS, REAR, high-risk jurisdictions, and policy updates.

Federal AML Laws and Executive Regulations Applicable to Lawyers, Notaries, and Legal Professionals

Eleven federal instruments form the statutory base for AML compliance by lawyers, notaries, and legal consultants in UAE. They range from the primary AML decree law and its Executive Regulations through to sector-neutral resolutions on sanctions, beneficial ownership, and penalties, and two instruments specific to the profession itself.

Ten federal instruments in this section

Each item below is a separate subsection summarising its scope, the articles most relevant to legal professionals, and the key thresholds or penalties.

01. FDL 10/2025

AML/CFT/CPF Federal Decree-Law

02. CR 134/2025

Executive Regulations

03. CR 8/2025

Executive Regulations of Legal Profession Law

04. MR 248/2025

MoJ supervisory procedures 

05. CR 71/2024

Administrative penalties for MoJ/MoE supervisees

06. FDL 34/2022

Legal Profession Law 

07. CR 74/2020

Terrorist lists and UNSC resolutions

08. FL 7/2014

Combating Terrorism Crimes

09. CR 109/2023

Beneficial owner procedures

10. CR 132/2023

BO administrative penalties

1. Federal Decree by Law No. (10) of 2025 Regarding Anti-Money Laundering, and Combating the Financing of Terrorism and Proliferation Financing

Federal Decree-Law No. (10) of 2025, issued on 30 September 2025, is the primary AML statute for the UAE. Article 41 repealed Federal Decree-Law No. (20) of 2018 and superseded its Executive Regulations, subject to any instruments issued under the old law remaining in force until amended, unless inconsistent with the new decree.

For lawyers, notaries, and legal consultants the most important provisions are Articles 2 and 3 which criminalise money laundering, financing of terrorism, and the financing of the proliferation of weapons of mass destruction; Article 18 which imposes the suspicious transaction reporting duty on DNFBPs subject to the privilege carve-out in clause 2; Article 19 on the prohibition on tipping off; Article 26 setting imprisonment from one to ten years and fines from AED 100,000 to AED 5,000,000 for laundering; Article 27 setting legal-person fines of AED 5,000,000 to AED 100,000,000; Article 28 imposing AED 100,000 to AED 1,000,000 for breaches of Article 18; Article 29 setting fines from AED 50,000 for tipping off; and Article 33 setting fines from AED 20,000 for breaches of targeted financial sanctions.

2. Cabinet Resolution No. (134) of 2025 Concerning the Executive Regulations of Federal Decree-Law No. (10) of 2025

Cabinet Resolution No. (134) of 2025 is the operational manual for the federal decree law. Article 3, Clause 4 lists the five covered activities that bring lawyers, notaries, and independent legal professionals inside the AML regime.

Article 18, Clause 2 preserves legal professional privilege over assessment of the client’s legal position, defence, representation, arbitration, mediation, and the issuing of a legal opinion.

Article 19, Clause 2 makes clear that dissuading a client from engaging in an unlawful act is not tipping off.

3. Cabinet Resolution No. (8) of 2025 Regarding the Executive Regulations of Federal Decree-Law No. (34) of 2022 Regulating the Legal Profession and Legal Consultation Profession

Cabinet Resolution No. (8) of 2025 is the Executive Regulations of the Legal Profession Law. While its scope is the profession generally rather than AML specifically, it governs licensing, categories of registration, conduct rules, disciplinary committees, and registers maintained by the Ministry of Justice, and it therefore sets the institutional foundation against which AML sanctions, such as suspension or cancellation of a licence, actually operate. Compliance officers should read it alongside Federal Decree-Law No. (34) of 2022 when assessing the consequences of supervisory action.

4. Ministerial Resolution No. (248) of 2025 on Supervising Law Firms, Legal Consultancy Offices, and Notaries Public

Ministerial Resolution No. (248) of 2025, issued on 29 April 2025, regulates the procedures and controls for supervising and monitoring law firms, legal consultancy offices, and notaries public in the field of combating money laundering and terrorism. It establishes the AML/CTF Department as the competent body; sets out inspection methodology; confirms application of Cabinet Resolution 71 of 2024 penalties through Article 6; provides a twenty-working-day grievance window in Article 7; mandates a thirty-working-day response window in Article 8; and repeals Ministerial Resolutions 532 and 533 of 2019.

5. Cabinet Resolution No. (71) of 2024 Regulating Violations and Administrative Penalties Imposed on Violators of AML/CFT Measures Under the Supervision of MoJ and MoE

Cabinet Resolution No. (71) of 2024, issued on 8 July 2024, is the administrative penalties grid for DNFBPs supervised by MoJ and by the Ministry of Economy. It repeals Cabinet Resolution No. (16) of 2021 and sets out forty-one categories of violation with fines ranging from AED 50,000 to AED 1,000,000. Article 4 provides a twenty-working-day notification window, a thirty-working-day grievance window, and a forty-day deemed-rejection rule where the grievance is not filed. Article 5 allows fines to be doubled on repetition within a set period. A selection of the schedule is reproduced below for orientation; firms should consult the full text for the complete list.

ArtViolation summaryFine (AED) 
1.Failure to apply customer due diligence measures to new or existing clients.50,000 – 200,000
2.Failure to identify the beneficial owner or to take reasonable steps to verify beneficial ownership information.50,000 – 200,000
3.Failure to conduct ongoing monitoring of the business relationship and to scrutinise transactions.50,000 – 500,000
4.Failure to conduct ongoing monitoring of the business relationship and to scrutinise transactions.100,000 – 500,000 

6. Federal Decree-Law No. (34) of 2022 Regulating the Legal Profession and Legal Consultation Profession

Federal Decree-Law No. (34) of 2022 is the governing law of the legal profession. It sets out licensing conditions, categories of lawyers, conduct duties, disciplinary committees, and the powers of the Ministry of Justice and the Executive Council. For AML purposes, it is the upstream instrument that defines who is a lawyer or legal consultant and whose license may be suspended or cancelled when penalties under Cabinet Resolution 71 of 2024 are imposed.

7. Cabinet Decision No. (74) of 2020 Regarding Terrorism Lists and Implementation of UN Security Council Resolutions

Cabinet Decision No. (74) of 2020 regulates the UAE’s domestic terrorism lists and the implementation of United Nations Security Council resolutions on the suppression and combating of terrorism, terrorist financing, countering the proliferation of weapons of mass destruction, and related resolutions. It creates the obligation on every DNFBP, including law firms and notaries, to screen customers, transactions, and related parties against the UN Consolidated List and the UAE Local List; to apply without delay freezing measures on any confirmed match; and to report Confirmed Name Match Reports and Partial Name Match Reports to the FIU.

8. Federal Law No. (7) of 2014 on Combating Terrorism Crimes

Federal Law No. (7) of 2014 on Combating Terrorism Crimes is the criminal statute on terrorism offences, including financing. It defines terrorist acts, terrorist organisations, and the financing of terrorism, and it underpins the obligation in Federal Decree-Law 10 of 2025 to report suspicions of terrorism-related activity. Legal professionals should read it alongside Cabinet Decision 74 of 2020 when drafting STR scripts and training modules.

9. Cabinet Decision No. (109) of 2023 on Regulating the Beneficial Owner Procedures

Cabinet Decision No. (109) of 2023 governs beneficial owner disclosure for legal persons in the UAE. For legal professionals, the instrument is particularly relevant when they establish or manage companies for clients: they must help the entity meet the requirements to maintain a beneficial owner register, a nominee director register where applicable, and a partners or shareholders register; keep the information accurate and current; and file prescribed beneficial owner information with the registrar. The 25 per cent ownership threshold referenced in Cabinet Resolution 134 of 2025 mirrors the BO identification trigger used across the UAE framework.

10. Cabinet Resolution No. (132) of 2023 Concerning Administrative Penalties for Violations of Cabinet Decision No. (109) of 2023

Cabinet Resolution No. (132) of 2023 is the administrative penalties grid for beneficial owner breaches. Law firms that provide company formation and ongoing management services should understand these penalties because, although the penalty is imposed on the legal person, the firm’s role in maintaining the register and filing the data can attract parallel administrative liability under Cabinet Resolution 71 of 2024 as part of its AML obligations.

Quick Reference Timeline of Federal AML Instruments Affecting Legal Professionals

2014   CRIMINAL LAW 

Federal Law No. (7) of 2014 on Combating Terrorism Crimes 

Defines terrorism offences including financing and underpins STR scripts. 

2020   CROSS-SECTOR 

Cabinet Decision No. (74) of 2020 on terrorism lists and UNSC resolutions 

Creates screening, freezing, and EOCN reporting duties for every DNFBP. 

2022   PROFESSION 

Federal Decree-Law No. (34) of 2022 Regulating the Legal Profession 

Governs licensing, categories of lawyer, and disciplinary framework. 

2023   CROSS-SECTOR 

Cabinet Decision No. (109) of 2023 on Beneficial Owner Procedures 

Registers, filings, and 25 per cent identification threshold for legal persons. 

2023   CROSS-SECTOR 

Cabinet Resolution No. (132) of 2023 on BO Administrative Penalties 

Penalty grid for beneficial owner non-compliance. 

2024   CROSS-SECTOR 

Cabinet Resolution No. (71) of 2024 on AML/CFT Administrative Penalties 

Forty-one violations; fines AED 50,000 to AED 1,000,000; doubling on repetition. 

2025   PROFESSION 

Cabinet Resolution No. (8) of 2025 Executive Regulations of FDL 34/2022 

Operational rules for licensing, registers, and disciplinary action. 

2025   SECTOR 

Ministerial Resolution No. (248) of 2025 on supervision of law firms and notaries 

Establishes MoJ AML/CTF Department, inspection methodology, and grievance windows. 

2025   FEDERAL 

Federal Decree-Law No. (10) of 2025 on AML/CFT/CPF 

Primary AML statute; repeals FDL 20/2018; imprisonment and fine bands. 

2025   FEDERAL 

Cabinet Resolution No. (134) of 2025 Executive Regulations of FDL 10/2025 

Five covered activities; privilege carve-out; thresholds; BO rule. 

Need to map these laws to your firm's existing AML manual?

AML UAE performs gap-analysis mapping each article in FDL 10/2025, CR 134/2025, and CR 71/2024 to your current policies and procedures.

Overarching AML Guidance Applicable to Lawyers, Notaries, and Legal Professionals

Beyond federal statutes, legal professionals must follow a library of cross-sector guidance issued by the Executive Office for Control and Non-Proliferation, the Financial Intelligence Unit, and the National AML/CFT Committee. These documents are not stand-alone rulebooks, but failure to act on them is regularly cited as a contributing factor when administrative penalties are imposed under Cabinet Resolution 71 of 2024.

Thirteen cross-sector documents in this section

Dates, issuers, and scope; each gets its own reference card below.

01. TFS Guidance (EOCN)

AML/CFT/CPF Federal DecCore guidance on targeted financial sanctions for FIs, DNFBPs, and VASPs. ree-Law

02. FIU Strategic Analysis

Terrorist financing typologies and facilitators, May 2025

03. Strategic Review

TFS case studies covering 2019 to 2021.

04. PF Institutional RA

Proliferation finance institutional risk assessment guidance.

05. TF and PF Red Flags

Red flag indicators on terrorist and proliferation financing.

06. Unlicensed VA Providers

Joint guidance on combating unlicensed virtual asset providers.

07. CPF Guidance

Counter proliferation financing guidance for FIs, DNFBPs, and VASPs.

08. Satisfactory Practice

Joint guidance on satisfactory and unsatisfactory practice.

09. TFS Typologies

EOCN typologies on circumvention of targeted sanctions.

10. Grievance Guideline

Framework for challenging supervisory decisions.

11. Online Grievance Guide

Step-by-step user guide for the MoJ online grievance system.

12. Combating PF & Sanctions Evasion

Cross-agency publication on PF and sanctions evasion.

13.NAS Simple Guide

How to subscribe to the EOCN Notification Alert System.

1. Guidance on Targeted Financial Sanctions for FIs, DNFBPs and VASPs (EOCN)

Issued January 2021; Last amended March 2026 

Guidance on Targeted Financial Sanctions for Financial Institutions, Designated Non-Financial Businesses and Professions, and Virtual Asset Service Providers 

Central EOCN guidance explaining the legal framework for TFS, scope of application, freezing without delay, reporting of Confirmed Name Match Reports and Partial Name Match Reports, use of the goAML and EOCN Notification Alert System, and expectations on sanctions screening, governance, and training. Published on eocn.gov.ae.

2. FIU Strategic Analysis Report on Terrorist Financing (May 2025)

May 2025 

Terrorist Financing Typologies and Facilitators – A Strategic Analysis Report 

UAEFIU public version strategic analysis setting out TF typologies and facilitator profiles observed in UAE STR data; complements sector red-flag catalogues and informs MoJ risk-based inspection priorities. 

3. Strategic Review on Targeted Financial Sanctions Case Studies (April 2024)

April 2024 (content: November 2021, IEC-SR.01.22) 

Strategic Review on Targeted Financial Sanctions Case Studies 2019-2021 

EOCN review of case studies drawn from UAE TFS implementation, highlighting common failings such as delayed screening, weak governance, and unreported partial matches. Useful for law firms drafting sanctions-screening logs.

4. Proliferation Finance Institutional Risk Assessment Guidance (December 2023)

Published December 2023 

Proliferation Finance Institutional Risk Assessment Guidance for FIs, DNFBPs and VASPs 

Methodology for conducting a firm-level PF risk assessment, including jurisdiction, customer, product, and delivery-channel risk. Expected input into a law firm’s enterprise-wide risk assessment.

5. Terrorist and Proliferation Financing Red Flags Guidance (December 2023)

Published September 2023; updated December 2023 

Terrorist and Proliferation Financing Red Flags Guidance 

Concise catalogue of TF and PF red flags designed to be embedded in STR decision trees. Firms should map each indicator to their goAML reporting workflow.

6. Joint Guidance on Combating the Use of Unlicensed Virtual Asset Providers (November 2023)

Issued March 2022 (Supervisory Authority Sub-Committee) 

Joint Guidance on Combating the Use of Unlicensed Virtual Asset Providers in the United Arab Emirates 

Expectations on DNFBPs, including law firms handling digital-asset company formations, to screen for unlicensed virtual asset activity and reject onboarding where red flags are present

7. Guidance on Counter Proliferation Financing for FIs, DNFBPs, and VASPs (November 2022)

Published 01 November 2022 – EOCN-PF.01.23 

Counter Proliferation Financing Guideline 

Authoritative EOCN guidance on CPF obligations, including understanding dual-use goods typologies, sanctions evasion tactics, and the expected governance response. 

8. Joint Guidance on Satisfactory and Unsatisfactory Practice (June 2021)

June 2021 

Anti-Money Laundering and Countering Terrorist Financing Guidelines – Satisfactory and Unsatisfactory Practice 

Supervisory Authority Sub-Committee guidance contrasting practices that are considered satisfactory with those that are unsatisfactory. A reliable benchmark for internal audits.

9. Typologies on the Circumvention of Targeted Sanctions (March 2021)

Issued 20 March 2021; last amended 11 May 2021 

Typologies on the Circumvention of Targeted Sanctions against Terrorism and the Proliferation of Weapons of Mass Destruction (United Arab Emirates) 

EOCN typology paper focusing on evasion techniques including shell companies, trade-based methods, and misuse of legal persons. Particularly relevant to law firms establishing and managing entities. 

10. Guideline on Grievance Procedures

Undated (EOCN publication) 

Guideline on Grievance Procedures 

Framework guidance on filing grievances against supervisory decisions across federal authorities. Read alongside Articles 7 and 8 of MR 248 of 2025 for timelines. 

11. Online Grievance System User Guide

Undated 

Online Grievance System – User Guide 

Step-by-step walkthrough of the online grievance platform, including registration, grievance submission, and status tracking

12. Combating Proliferation Financing and Sanctions Evasion

EOCN publication 

Combating Proliferation Financing & Sanctions Evasion 

Reference text on PF typologies and evasion techniques; integrates with the CPF Guidance and the Typology Paper.

13. Simple Guide to Subscribe to the EOCN Notification Alert System (NAS)

EOCN publication 

Simple Guide to Subscribe to the EOCN Notification Alert System (NAS) 

Short operational guide to subscribing to the NAS, which delivers near real-time notifications of UN and UAE list updates and is a standard control for every law firm’s sanctions programme. 

Turning guidance into workable controls

AML UAE converts cross-sector guidance into operational checklists, screening-log templates, and STR decision trees tailored to your firm's covered activities.

NRA, SRA, and Other Important Guidelines Applicable to Lawyers and Legal Professionals

The UAE Money Laundering and Terrorist Financing Risk Assessment Report is the single most important cross-cutting risk document for every DNFBP, including law firms and notaries. Published by the National Anti-Money Laundering and Combating the Financing of Terrorism and Financing of Illegal Organisations Committee, it sets the macro picture against which sectoral risk assessments and firm-level risk assessments are calibrated.

UAE Money Laundering and Terrorist Financing Risk Assessment Report – 2024

National AML/CFT Committee 

UAE Money Laundering and Terrorist Financing National Risk Assessment Report 

The NRA assesses ML and TF threats and vulnerabilities across the UAE financial, VASP, and DNFBP sectors. In the UAE, the Law Firms and Legal Consultations Sector is classified as Medium-Low risk for ML since there are no evidence showing that the sector has been abused for ML, or any predicate offences 

to ML. For legal professionals it highlights risks associated with the establishment and management of legal persons and arrangements, real estate transactions, and complex cross-border structures, feeding into the MoJ’s sector supervision plan. Circular No. (2) of 2025 of the Ministry of Justice directly instructs law firms to reflect NRA findings in their firm-wide risk assessments. 

Does your firm's risk assessment reflect the NRA?

AML UAE helps law firms translate NRA findings into firm-specific risk factors and weight them appropriately in the customer risk methodology.

Sector-Specific Guidelines Applicable to Lawyers, Notaries, and Legal Professionals

Sector-specific instruments are issued by the Ministry of Justice. They fall into two groups: the central Guidebook that explains what satisfactory compliance looks like, and a sequence of circulars that direct firms to act on discrete obligations (policy updates, high-risk country lists, TFS implementation, and the real-estate activities report). All circulars listed below are officially published by the Ministry of Justice; the 2023, 2024, 2025, and 2026 policy update circulars are available on the MoJ website, while the earlier circulars are published in Arabic on the MoJ portal.

Twelve sector instruments in this section

The Guidebook plus eleven circulars spanning 2020 to 2026. Each card below states what the instrument requires of a law firm or notary.

01.Circular 1/2026

Updating AML policies, procedures, and controls.

02. MoJ Guidebook (Nov 2025)

Substantive sector reference.

03. Circular 3/2025

Updated list of high-risk jurisdictions.

04. Circular 2/2025

Acting on the UAE National Risk Assessment.

05. Circular 1/2025

Institutional assessment process controls.

06. Circular 1/2024

Simplified due diligence procedures.

07. Circular 2/2023

Obligations concerning high-risk jurisdictions.

08. Circular 1/2023

Commitment to institutional assessment controls.

09. Circular 14/2022

REAR – Real Estate Activities Report.

10. Circular 9/2022

Implementation of TFS under UN resolutions.

11. Circular 11/2021

Lawyers’ obligations on high-risk country lists.

12. Circular 18 + Circular 36/2020

Sanctions-list reporting and UN list implementation.

1. Circular No. (1) of 2026 Concerning the Obligation of Law Firms and Legal Consultancy Offices to Update Policies, Procedures, and Controls Related to AML/CFT/CPF (Arabic only)

Issued 2026 

Circular No. 1 of 2026 – Updated AML/CFT/CPF policies, procedures, and controls 

Directs law firms and legal consultancy offices to refresh their internal AML/CFT/CPF policies, procedures, and controls to reflect Federal Decree-Law 10 of 2025 and Cabinet Resolution 134 of 2025, and to update documentation accordingly. Published by the Ministry of Justice; currently available in Arabic only.

2. Guidebook for Law Firms and Legal Consultancy Offices on AML/CFT/CPF (November 2025)

Second Edition, published 25 November 2025 

Guidebook for Law Firms and Legal Consultancy Offices on Combating Money Laundering, Countering the Financing of Terrorism and Countering Proliferation Financing 

The principal sector reference issued by the Director of the AML/CTF Department at the Ministry of Justice. It covers relevant legislation, supervisory structure, AML Department functions, key obligations, compliance-officer requirements, STR reporting via goAML, five-year record retention, TFS 24-hour freeze and one-business-day EOCN notification, administrative sanctions, appeal procedures, and sources of assistance including amlctf@moj.gov.ae and the EOCN address iec@uaeiec.gov.ae

3. Circular No. (3) of 2025 Regarding the Update of the List of High-Risk Countries and Countries Subject to Enhanced Monitoring (Arabic only)

Issued 2025 

Circular No. 3 of 2025 – Updated list of high-risk countries 

Directs lawyers and law firms to apply enhanced due diligence to clients from the updated FATF high-risk jurisdictions and jurisdictions subject to increased monitoring. Currently available in Arabic only on the Ministry of Justice website. 

4. Circular No. (2) of 2025 Regarding the National Risk Assessment (Arabic only)

Issued 2025 

Circular No. 2 of 2025 – National Risk Assessment 

Requires law firms to align their firm-wide risk assessments, client risk methodologies, and control environments with findings in the UAE National Risk Assessment. Currently available in Arabic only. 

5. Circular No. (1) of 2025 Regarding Commitment of Law Firms to the Controls of Institutional Assessment Processes (Arabic only)

Issued 2025 

Circular No. 1 of 2025 – Institutional assessment process controls 

Sets expectations on the institutional assessment process that law firms must follow, including documentation, sign-off, and periodic review. Currently available in Arabic only.

6. Circular No. (1) of 2024 Regarding Simplified Due Diligence Procedures (Arabic only)

Issued 2024 

Circular No. 1 of 2024 – Simplified due diligence procedures 

Clarifies the circumstances in which simplified due diligence is permitted, aligning with Cabinet Resolution 134 of 2025 on low-risk scenarios. Currently available in Arabic only

7. Circular No. (2) of 2023 Regarding Obligations of Lawyers Concerning the Updated List of High-Risk Countries (Arabic only)

Circular No. 2 of 2023 concerns lawyers’ obligations concerning the updated list of high-risk countries. A copy of this circular was not available to us in PDF form at the time of writing; the text is referenced in the Ministry of Justice archive, but firms should obtain the current version directly from the Ministry before applying it. 

8. Circular No. (1) of 2023 Regarding Commitment of Law Firms to the Controls of Institutional Assessment Processes (Arabic only)

Issued 2023 

Circular No. 1 of 2023 – Institutional assessment controls 

Earlier MoJ circular requiring law firms to commit to the controls of institutional AML assessment processes; superseded in substance by Circular No. 1 of 2025 on the same subject.

9. Circular No. (14) of 2022 Regarding the REAR Real Estate Activities Report (Arabic only)

Issued 2022 

Circular No. 14 of 2022 – REAR (Real Estate Activity Report) 

Instructs law firms involved in real estate transactions to file the Real Estate Activity Report on relevant transactions, consistent with the requirements that apply across DNFBPs handling real estate. 

10. Circular No. (9) of 2022 on Implementation by Lawyers of Targeted Financial Sanctions Under UN Security Council Resolutions (Arabic only)

Issued 2022 

Circular No. 9 of 2022 – Implementation by lawyers of targeted financial sanctions 

Reaffirms that lawyers must implement targeted financial sanctions stipulated by UN Security Council resolutions and the UAE cabinet, with without-delay freezing and reporting via EOCN.

11. Circular No. (11) of 2021 Regarding Lawyers' Obligations on Updated List of High-Risk Countries (Arabic only)

Issued 2021 

Circular No. 11 of 2021 – Lawyers’ obligations on high-risk countries 

Requires lawyers to apply enhanced due diligence to clients from high-risk jurisdictions; predecessor to Circular 3 of 2025 on the same subject. 

12. Circular No. (18) Regarding Lawyers' Implementation of Obligations to Report Clients on Sanctions Lists (Arabic only)

Issued 2020 

Circular No. 18 – Reporting of clients on international or local sanctions lists 

Directs law firms to report clients appearing on international or local sanctions lists in accordance with federal and EOCN procedures.

13. Circular No. (36) of 2020 Regarding the International and Local Sanctions Lists (Arabic only)

Issued 2020 

Circular No. 36 of 2020 – International and local sanctions lists 

Implements UN Security Council and cabinet sanctions lists at the level of lawyers and law firms, including obligations to screen clients and report matches. 

Conclusion

AML regulations for lawyers in UAE are neither a single rulebook nor a single set of penalties. They are a federated framework anchored in Federal Decree-Law No. (10) of 2025 and its Executive Regulations, built up through Cabinet Resolution No. (74) of 2020 on sanctions, Cabinet Decision No. (109) of 2023 on beneficial ownership, Cabinet Resolution No. (132) of 2023 on BO penalties, and Cabinet Resolution No. (71) of 2024 on administrative penalties, and made operational for the legal sector through Ministerial Resolution No. (248) of 2025, the Ministry of Justice Guidebook of November 2025, and a sequence of MoJ circulars from 2020 to 2026. 

What this means in practice for law firms, legal consultancy offices, and notaries public is that compliance is continuous rather than episodic. A satisfactory firm will maintain an enterprise-wide risk assessment that reflects the UAE National Risk Assessment; a client-onboarding process that systematically tests whether a matter falls within one of the five covered activities; sanctions-screening logs and Confirmed Name Match Report workflows that support the 24-hour freeze and one-business-day EOCN reporting; STR decision trees that operate through goAML and respect the privilege carve-out in Article 18, Clause 2 of FDL 10 of 2025 and CR 134 of 2025; a five-year records retention architecture; policies and procedures that are refreshed whenever a new MoJ circular is issued; and a training programme that keeps partners, lawyers, paralegals, and notaries public current on the framework. 

Firms licensed in ADGM or DIFC operate inside their respective free-zone regimes and should look to FSRA and DFSA rulebooks rather than MoJ instruments. For every other MoJ-supervised legal professional, the rulebook above is the benchmark the AML/CTF Department will use on an inspection. 

Found this guide useful?

If this article helped you clarify your firm's AML obligations, a short Google review helps other legal professionals find clear, sourced UAE guidance.

Frequently Asked Questions

When do lawyers and legal consultants fall under UAE AML law?

A lawyer, legal consultant, or notary public falls under UAE AML law when they prepare or carry out any of the five covered activities under Article 3, Clause 4 of Cabinet Resolution 134 of 2025: buying or selling real estate; managing client money, securities, or assets; managing bank, savings, or securities accounts; organising contributions for a company; or establishing, operating, or managing legal persons or arrangements. Pure litigation, arbitration, mediation, and legal opinion work is protected by the privilege carve-out in Article 18, Clause 2 of Federal Decree-Law 10 of 2025. 

The Ministry of Justice supervises law firms, legal consultancy offices, and notaries public through its AML/CTF Department, following Cabinet Decision No. (1/3 W) of 2019 and Cabinet Decision 65 of 2024, which upgraded the AML section into a full department. Ministerial Resolution No. (248) of 2025 sets out the current supervisory procedures and controls. Firms licensed in ADGM are supervised by FSRA; firms licensed in DIFC are supervised by DFSA. 

A law firm should maintain its firm-wide risk assessment; each client risk assessment; CDD and enhanced due diligence files; beneficial ownership information; transaction records and transaction risk assessments for covered activities; sanctions-screening logs, including CNMR and PNMR records and EOCN correspondence; STR decision records and goAML submission receipts; training and attendance records; and a corrective action register. Retention is for five years from the end of the business relationship or completion of the transaction, per the MoJ Guidebook of November 2025 and Cabinet Resolution 134 of 2025. 

Ministerial Resolution No. (248) of 2025, issued on 29 April 2025, replaces Ministerial Resolutions 532 and 533 of 2019. It confirms the MoJ AML/CTF Department as the competent supervisory body for law firms, legal consultancy offices, and notaries public; applies the Cabinet Resolution 71 of 2024 penalty schedule through Article 6; provides a 20-working-day grievance window in Article 7; and requires a 30-working-day response in Article 8. Firms should refresh their sanctions, STR, and governance policies to align with the new instrument. 

Yes. Law firms licensed in Abu Dhabi Global Market are supervised by the Registration Authority and follow the ADGM Financial Services and Markets Regulations together with the FSRA AML Rulebook. Law firms licensed in the Dubai International Financial Centre are supervised by the Dubai Financial Services Authority and follow the DIFC Regulatory Law and DFSA AML Module. These free-zone regimes are distinct from the Mainland MoJ regime described above and are covered on the ADGM and DIFC pages in this cluster.

Talk to AML UAE about your firm's compliance programme

Whether you are setting up a new law firm, responding to a MoJ inspection, or refreshing policies following Circular 1 of 2026, AML UAE helps legal professionals implement the full framework.

Share via :

About the Author

Pathik Shah

FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)

Pathik is an ACAMS-certified AML consultant specialising in governance, risk, and compliance for regulated entities in the UAE. He brings over 28 years of experience, with 1,000+ hours of AML training and 200+ advisory engagements across DNFBPs, VASPs, and FIs. He supports businesses in aligning with AML/CFT requirements from the CBUAE, DFSA, MoET, MoJ, VARA, CMA, FSRA, and FATF. Known for translating complex regulations into audit-ready procedures, Pathik enables operational clarity and compliance readiness.

Reach Out to Pathik

AML Regulations for Dealers in Precious Metals and Stones (DPMS) in UAE

AML Regulations for Dealers in Precious Metals and Stones (DPMS) in UAE

Blogs

Published On: 04/28/2026

Table of Contents

Protect your business with reliable and effective AML strategies with AML UAE.

Last Reviewed On: 07/21/2026   |   Last Updated On: 07/21/2026

Key Highlights

  • DPMS are brought into the AML/CFT perimeter at an AED 55,000 transaction threshold defined in Article 3(3) of Cabinet Resolution 134 of 2025.
  • The Anti-Money Laundering Department of the Ministry of Economy and Tourism supervises DPMS operating in the mainland and commercial free zones.
  • Every threshold-crossing transaction must be captured in a Dealers in Precious Metals and Stones Report (DPMSR) filed on goAML (MoE Circular 08/AML/2021).
  • Gold refiners and supply-chain participants are subject to an additional 5-step responsible sourcing framework under Ministerial Decree 68 of 2024.
  • Administrative fines for AML/CFT violations range from AED 50,000 to AED 1,000,000 per violation under Cabinet Resolution 71 of 2024.
  • The UAE’s 2024 National Risk Assessment rates the sector’s inherent ML/TF risk as medium-to-high.

AML Regulations for Dealers in Precious Metals and Stones (DPMS) in UAE

The AML Regulations for DPMS in UAE sit inside the wider Designated Non-Financial Businesses and Professions (DNFBP) framework explained in our parent guide, AML Regulations for DNFBPs in UAE. Precious metals and stones markets combine high intrinsic value, cross-border mobility and deep cash reliance, which is why Federal Decree Law 10 of 2025, Cabinet Resolution 134 of 2025 and a dedicated set of Ministry of Economy and Tourism (MoET) circulars bring dealers in precious metals and stones inside the UAE’s AML/CFT/CPF perimeter.

This page explains the legal framework, the supervisory architecture, the 5-step gold sourcing overlay and the obligations that every DPMS must meet when it crosses the AED 55,000 threshold set out in Article 3(3) of the Executive Regulations.

At a Glance

Perimeter: Any dealer in precious metals or precious stones carrying out a single cash transaction, or linked cash transactions, equal to or above AED 55,000 (Cabinet Resolution 134/2025, Article 3(3)).

Primary supervisor: Ministry of Economy and Tourism (MoET) for mainland and commercial free zone DPMS.

Governing law: Federal Decree Law 10 of 2025 (AML/CFT/CPF); Cabinet Resolution 134 of 2025 (Executive Regulations).

Reporting trigger: DPMSR filed on goAML for each cash or wire transaction at or above AED 55,000 (MoE Circular 08/AML/2021).

Gold sourcing overlay: Gold refineries and supply chain entities must apply the 5-step Due Diligence Regulations for Responsible Sourcing of Gold (Ministerial Decree 68/2024; Circular 2/2024).

Penalty range: AED 50,000 to AED 1,000,000 per violation (Cabinet Resolution 71 of 2024).

Sector risk rating: Medium-to-high ML/TF risk (UAE National Risk Assessment 2024).

Population on goAML: 8,191 DPMS registered as of 30 June 2025; 1,448,825 DPMSRs filed Jul 2021 – Jun 2025 (UAEFIU Strategic Analysis Report on DPMS, Sept 2025).

Scope note

This page explains AML regulations applicable to dealers in precious metals and stones (DPMS) in the UAE, with specific coverage of gold sourcing and the AED 55,000 reporting threshold. Broader AML obligations that apply across all DNFBPs are explained in AML Regulations for DNFBPs in UAE.

What this DPMS Guide Covers

Three substantive sections walk you through perimeter, supervisor and the layered AML regulations for DPMS in UAE.

1. Who Counts as a DPMS in the UAE

2. AML Supervisory Authority for DPMS

3. AML Regulations Applicable to DPMS

Who Counts as a Dealer in Precious Metals and Stones (DPMS) in the UAE?

A dealer in precious metals and stones (DPMS) is any natural or legal person who, in the course of business, trades in precious metals or precious stones and who carries out a single cash transaction, or several linked cash transactions, at or above AED 55,000. This perimeter is set in Article 3(3) of Cabinet Resolution No. 134 of 2025 concerning the Executive Regulations of Federal Decree Law No. 10 of 2025.

The term covers gold retailers, jewellers, refineries, bullion wholesalers, diamond and coloured-stone traders, pearl traders and recycling operations within the Ministry of Economy and Tourism’s supervisory remit. The trigger is the AED 55,000 cash value; the rule applies equally to a single retail sale and to a string of related transactions that together cross the threshold. Transactions below AED 55,000 remain inside the AML system for record-keeping and suspicious transaction reporting, but they do not by themselves create DPMSR reporting exposure. The DPMSR reporting obligation and the applicability of the AML/CFT federal law are two different things. One should not confuse the applicability of the law with the DPMSR submission obligations.

Legal test

“Dealers in valuable metals and precious stones, when carrying out any single cash transaction or several transactions that appear to be linked and whose value equals or exceeds fifty-five thousand dirhams (AED 55,000).” — Article 3(3), Cabinet Resolution No. 134 of 2025.

Dealers established in the Abu Dhabi Global Market (ADGM) and the Dubai International Financial Centre (DIFC) are supervised by their own regulators (the ADGM RA and the DFSA, respectively) under rulebooks that mirror the federal AML/CFT regime; the substantive obligations and threshold logic track federal law, but the primary touchpoint is the financial free zone regulator rather than MoET.

AML Supervisory Authority for DPMS in the UAE

The Anti-Money Laundering Department within the Ministry of Economy and Tourism (MoET) is the federal supervisor for DPMS operating in the mainland and commercial free zones. This mandate is grounded in Cabinet decisions that assign DNFBP supervision to MoET and is reaffirmed in the DNFBP Guidelines issued by the Ministry in September 2025, which list DPMS among the four supervised categories alongside real estate agents and brokers, independent accountants and auditors, and trust and corporate service providers.

MoET enforces the AML/CFT obligations through on-site inspections, thematic reviews, administrative penalties imposed under Cabinet Resolution No. 71 of 2024, and circular-based guidance. It coordinates closely with the UAE Financial Intelligence Unit (UAEFIU), which operates the goAML reporting platform, and with the Executive Office for Control and Non-Proliferation (EOCN), which administers targeted financial sanctions. DPMS in ADGM and DIFC report to the ADGM RA and DFSA, respectively; DPMS in financial free zones follow the free zone’s AML framework, which cross-references to federal law.

1. Federal Supervisor

MoET is the primary AML/CFT supervisor for DPMS in mainland UAE and commercial free zones.

2. Financial Intelligence Unit

UAEFIU receives all Suspicious Transaction Reports, Confirmed Name Match Reports (CNMRs), PNMRs and DPMSRs through the goAML system.

3. Sanctions Authority

The Executive Office for Control and Non-Proliferation (EOCN) administers targeted financial sanctions and the Notification Alert System (NAS).

4. Financial Free Zone Regulators

ADGM RA and DIFC DFSA supervise DPMS authorised inside their respective jurisdictions under rulebooks aligned with federal AML law.

AML Regulations Applicable to DPMS in the UAE

The AML regulations for DPMS in UAE are organised in five concentric layers: the federal AML statute and its executive and penalty regulations; cross-sector overarching guidance from the National Committee, the EOCN, the UAEFIU and other federal bodies; the National Risk Assessment; DNFBP sector-specific guidance and circulars issued by MoET; and sector-specific DPMS guidance addressing gold sourcing, goAML reporting and precious-metals typologies. The subsections below walk through each layer and cite the applicable instruments.

The Five Regulatory Layers for DPMS

Three substantive sections walk you through perimeter, supervisor and the layered AML regulations for DPMS in UAE.

1. Federal AML Laws and Executive Regulations

2. Overarching AML Guidance

3. NRA, SRA, and Other Important Guidelines

4. DNFBP Sector-Specific Guidance

5. Sector-Specific DPMS Guidelines

Federal AML Laws and Executive Regulations Applicable to Dealers in Precious Metals and Stones

Federal primary and secondary legislation sets the baseline AML/CFT/CPF obligations that every DPMS must meet, regardless of whether it trades in gold bars, loose diamonds or polished jewellery. The federal layer is reinforced by two dedicated penalty resolutions and a beneficial-owner framework that every DPMS legal entity has to implement independently of its AML obligations.

Federal AML laws and executive regulations at a glance

Seven primary and secondary instruments that set the baseline AML/CFT/CPF obligations for every DPMS.

1. Federal Decree Law No. 10 of 2025

2. Federal Law No. 7 of 2014

3. Cabinet Resolution No. 134 of 2025

4. Cabinet Decision No. 74 of 2020

5. Cabinet Resolution No. 71 of 2024

6. Cabinet Decision No. 109 of 2023

7. Cabinet Resolution No. 132 of 2023

Federal Decree by Law No. (10) of 2025 Regarding Anti-Money Laundering, and Combating the Financing of Terrorism and Proliferation Financing

Federal Decree Law No. 10 of 2025 is the current primary AML/CFT/CPF statute in the UAE. It defines Designated Non-Financial Businesses and Professions as persons engaged in commercial or professional activities specified in the Executive Regulations, and makes those persons subject to the full suite of preventive obligations, including customer due diligence, record-keeping, suspicious transaction reporting, internal controls, training and cooperation with supervisory authorities.

Article 10 of the Decree Law (Chapter Four — Disclosure) confirms that every person entering or leaving the State must disclose the carriage of currencies, bearer negotiable instruments, precious metals or valuable stones in accordance with the disclosure system issued by the Federal Authority for Identity, Citizenship, Customs and Port Security in coordination with the Central Bank, which directly supports the precious-metals control environment within which DPMS operate.

The Decree Law establishes the UAEFIU, sets out criminal offences and sanctions, and empowers supervisory authorities to impose administrative penalties alongside judicial consequences. For the details of what each obligation means in practice, DPMS must read the Decree Law together with its Executive Regulations (Cabinet Resolution 134 of 2025) and the MoET DNFBP Guidelines.

Federal Law No. (7) of 2014 Combating Terrorism Crimes

Federal Law No. 7 of 2014 defines terrorism offences, terrorist organisations and the financing of terrorism. It is the criminal-law backbone behind the AML/CFT regime: when a DPMS identifies suspected terrorism-financing activity, the predicate offence is located in this Law and the related UNSC-implementing Cabinet Resolution 74 of 2020. Article 1 of Decree Law 10 of 2025 expressly refers to Federal Law 7 of 2014 in defining terrorist acts, thereby anchoring the AML statute within the criminal framework.

Cabinet Resolution No. (134) of 2025 Concerning the Executive Regulations of Federal Decree Law No. (10) of 2025

Cabinet Resolution 134 of 2025 is the executive regulation for Decree Law 10 of 2025 and contains the operational details that DPMS apply daily. Article 3(3) brings DPMS inside the perimeter at the AED 55,000 cash-transaction threshold. Article 7 sets out the triggers for customer due diligence, commencement of a business relationship, suspicion of a crime, doubts about previously obtained data, and occasional transactions at or above the thresholds. Article 8 requires ongoing monitoring, and subsequent articles set out enhanced due diligence, PEP handling, reliance on third parties, record-keeping and reporting obligations.

Where previous guidance, circulars or notifications refer to Federal Decree Law 20 of 2018 or Cabinet Resolution 10 of 2019, they continue to apply to the extent they are not repealed or inconsistent with Decree Law 10 of 2025 and Cabinet Resolution 134 of 2025. DPMS should therefore read every circular issued prior to 2025 through the lens of the new federal law.

Cabinet Decision No. 74 of 2020 Regarding Terrorism Lists Regulation and Implementation of UN Security Council Resolutions

Cabinet Decision No. 74 of 2020 regulates the UAE Local Terrorist List and the UAE’s implementation of United Nations Security Council resolutions on the suppression of terrorism, terrorism financing and the proliferation of weapons of mass destruction. It creates the legal basis on which DPMS must screen customers, beneficial owners and transaction counterparties against the UAE Local Terrorist List and the UN Consolidated List, apply freezing measures without delay, and report confirmed and partial name matches to the EOCN. The Cabinet Decision is enforced alongside circulars issued by MoET and EOCN that translate the obligations into reporting timelines.

Cabinet Resolution No. (71) of 2024 Regulating Violations and Administrative Penalties for DNFBPs Under the Ministry of Justice and the Ministry of Economy

Cabinet Resolution No. 71 of 2024 replaced Cabinet Resolution 16 of 2021 and sets out the unified list of AML/CFT violations and administrative fines for DNFBPs supervised by the Ministry of Economy (now MoET) and the Ministry of Justice (MoJ). Article 3 authorises the Ministry to impose one of the administrative penalties in Article 14 of the Decree Law, or the administrative fines in the annexed schedule, or both.

The annexed schedule covers more than forty categories of violations. Failure to adopt internal policies and controls is fined between AED 100,000 and AED 200,000. Failure to identify, assess and update crime risks is fined between AED 50,000 and AED 500,000. Failure to apply customer due diligence before or during a transaction at or above AED 55,000 is fined between AED 50,000 and AED 200,000. Failure to promptly file suspicious-transaction reports with the UAEFIU is fined between AED 100,000 and AED 500,000. Failure to implement UN Security Council sanctions decisions, directly relevant to DPMS given typology exposure, is fined between AED 100,000 and AED 1,000,000. Article 4 gives the violator thirty working days to grieve the penalty, and Article 5 permits the Ministry to amend, uphold or cancel the fine on review.

Cabinet Decision No. (109) of 2023 on Regulating the Beneficial Owner Procedures

Cabinet Decision No. 109 of 2023 regulates the identification, verification and continuous maintenance of the real (ultimate) beneficial owners of companies established in the UAE. A DPMS operating as a corporate licensee must maintain a register of beneficial owners, notify the licensing authority of changes within fifteen days and keep information current. Customer due diligence on corporate clients under Article 9 of the AML Executive Regulations draws on the same beneficial-owner concept, so the two frameworks operate in parallel: Decision 109 governs the DPMS’s own legal-person transparency, and the AML rules govern beneficial-owner identification of the DPMS’s customers.

Cabinet Resolution No. (132) of 2023 on Administrative Penalties for Beneficial Owner Violations

Cabinet Resolution No. 132 of 2023 sets out the administrative penalties for breaches of Cabinet Decision 109 of 2023. A DPMS that fails to disclose, update or maintain accurate beneficial-ownership data is exposed to written warnings to the legal person and financial penalties that escalate with repetition of the violation. Under Article 3(2) of Cabinet Resolution 132 of 2023, for violations committed for the third time, the Registrar has the right to suspend the commercial licence and close the commercial store of the violating legal person until the fine is paid and the breach is rectified. The penalty schedule is enforced by the Ministry of Economy and Tourism as the beneficial-owner registrar for most DPMS legal persons.

DPMS policy templates aligned to Decree Law 10/2025 and Cabinet 134/2025

AML UAE maintains up-to-date internal policies, customer due diligence procedures, DPMSR workflows and beneficial-owner registers engineered for the precious metals and stones sector.

Overarching AML Guidance Applicable to DPMS in the UAE

Alongside the federal statute, a catalogue of cross-sector guidance binds DPMS into the national AML/CFT/CPF architecture. These instruments explain how to implement targeted financial sanctions, counter proliferation finance, file reports on goAML and grieve sanctions-related decisions. Where a circular or guideline refers to the old Federal Decree Law 20 of 2018 and its executive regulation, it remains valid to the extent consistent with Decree Law 10 of 2025 and Cabinet Resolution 134 of 2025.

Thirteen cross-sector instruments from the EOCN, UAEFIU and National Committee that frame DPMS sanctions, CPF and reporting obligations.

1. EOCN TFS Guideline (Jan 2021, last amended Jul 2025)

2. UAEFIU TF Strategic Analysis (May 2025)

3. TFS Strategic Review (Nov 2021)

4. PF Institutional Risk Assessment Guidance (Dec 2023)

5. TF and PF Red Flags Guidance (updated Dec 2023)

6. Unlicensed VASP Joint Guidance (2022)

7. Counter Proliferation Financing Guidance (Nov 2022)

8. Satisfactory/Unsatisfactory Practice Joint Guidance (Jun 2021)

9. Sanctions Circumvention Typologies (Mar 2021)

10. EOCN Grievance Procedures Guideline

11. Online Grievance System User Guide

12. Combating PF and Sanctions Evasion

13. EOCN NAS Subscription Simple Guide

1. Guideline on Targeted Financial Sanctions for Financial Institutions, DNFBPs and VASPs — Executive Office for Control and Non-Proliferation (EOCN), issued January 2021, last amended July 2025

The EOCN TFS Guideline is the authoritative reference for how DPMS implement UN-led and UAE-local sanctions obligations. It explains the scope of TFS measures, the concept of ‘funds or other assets’, the screening expectations on customers, beneficial owners and counterparties, and the freezing obligation that must be executed without delay. The Guideline also sets the five-business-day reporting window for Confirmed Name Match Reports (CNMRs) and Partial Name Match Reports (PNMRs) on goAML, and DPMS rely on it to calibrate screening frequency, to interpret partial-match handling and to build CNMR and PNMR workflows.

2. UAEFIU’s Strategic Analysis Report on Terrorist Financing Typologies and Facilitators — May 2025

This UAEFIU strategic analysis sets out the dominant terrorist-financing typologies observed in the UAE and the facilitators most frequently exploited. For DPMS, the relevance lies in the report’s analysis of how precious metals and cash movements intersect with TF networks, and in the red-flag indicators that should feed into the DPMS’s transaction-monitoring rules and staff training.

3. Strategic Review on Targeted Financial Sanctions Case Studies 2019-2021 (IEC-SR.01.22) — Executive Office, November 2021

The Strategic Review compiles sanitised case studies from 2019 to 2021 where UAE private-sector obligations to apply TFS were tested. DPMS use these case studies to benchmark their own sanctions screening, to understand which typologies should trigger enhanced due diligence and to test the strength of their freezing and reporting playbooks.

4. Proliferation Finance Institutional Risk Assessment Guidance for FIs, DNFBPs and VASPs — December 2023

This Guidance explains how an institutional proliferation-finance risk assessment should be structured. DPMS, because of their exposure to dual-use goods pathways and to jurisdictions subject to UNSC proliferation-related sanctions, must run a specific proliferation-finance assessment as part of their wider business-wide risk assessment, separate from the ML and TF analyses.

5. Terrorist and Proliferation Financing Red Flags Guidance — December 2023

This cross-sector red-flag bulletin lists concrete indicators that front-line DPMS staff should watch for in transactions involving gold, bullion, high-value stones and jewellery. Where one or more red flags are present, the DPMS must escalate and, if suspicion persists, file an STR with the UAEFIU without delay.

6. Joint Guidance on Combating the Use of Unlicensed Virtual Asset Service Providers in the UAE — Central Bank, SCA, VARA, DFSA, FSRA and Ministries of Justice and Economy (2022)

DPMS frequently encounter customers who wish to settle precious metals purchases through virtual assets. This Joint Guidance from the Central Bank, CMA, VARA and ADGM/DIFC regulators sets out the obligations to deal only with licensed VASPs, and the red flags that indicate a counterparty is operating without a UAE VASP licence. DPMS integrating virtual-asset settlement must apply these expectations alongside their own AML controls.

7. Guidance on Counter Proliferation Financing for FIs, DNFBPs and VASPs — November 2022

This is the authoritative cross-sector CPF guidance. It explains the definition of proliferation financing in UAE law, the institutional risk assessment framework, the specific red flags linked to dual-use goods and the interaction with UNSC resolutions 1718 (DPRK) and 1737/2231 (Iran). DPMS sourcing or selling bullion and stones in trade-finance-heavy structures use this Guidance to build their CPF controls.

8. Joint Guidance on Satisfactory and Unsatisfactory Practice — June 2021

This joint supervisors’ Guidance contrasts observed satisfactory practice against unsatisfactory practice across governance, risk assessment, CDD, record-keeping and reporting. It is the single most practical benchmarking document for DPMS that want to self-assess the maturity of their AML programme before an inspection.

9. Typologies on the Circumvention of Targeted Sanctions — March 2021

This typology paper walks through common techniques used to circumvent sanctions, including the use of front companies, intermediaries in jurisdictions with lighter controls, and trade-based disguise of value. DPMS face each of these typologies in their own market; the paper informs its enhanced due diligence expectations for trades involving high-risk jurisdictions.

10. Guideline on Grievance Procedures

This EOCN Guideline explains how a DPMS, a customer or a designated person requests de-listing, removal of a freezing measure or permission to use frozen funds. It sets out the information to include, the review process and the timelines. DPMS need it when handling a CNMR or PNMR that is subsequently contested.

11. Online Grievance System User Guide

The Online Grievance System is the digital channel for submitting grievances to the EOCN. The User Guide walks through account creation, grievance submission, document uploads and status checks. DPMS with dedicated compliance functions should register up-front so they are not delayed if a grievance becomes necessary.

12. Combating Proliferation Financing and Sanctions Evasion

This EOCN awareness document synthesises the CPF and sanctions-evasion obligations into a practitioner-oriented narrative. DPMS training curricula should map each module of this document to one or more of their internal controls, so staff can explain the underlying risk in the context of real-world gold and stone transactions.

13. Simple Guide to Subscribe to the EOCN Notification Alert System (NAS)

The NAS is the EOCN’s subscription channel for updates to the UAE Local Terrorist List, the UN Consolidated List and related designations. The Simple Guide explains the step-by-step subscription process. DPMS compliance officers must subscribe to the NAS so that screening lists are refreshed as soon as designations change.

NRA, SRA, and Other Important Guidelines Applicable to DPMS in the UAE

The UAE’s risk-based approach begins with the National Risk Assessment. For DPMS, the NRA sets the baseline expectation on how seriously to treat sector-inherent risks.

UAE ML/TF National Risk Assessment — 2024

The UAE Money Laundering and Terrorist Financing Risk Assessment 2024 rates the inherent risk of the DPMS sector at medium-to-high, highlighting the combination of trade scale, cash intensity, international exposure and the persistent risk of conflict-affected or high-risk gold entering the supply chain. The NRA instructs DPMS to use these findings as a floor for their own business-wide risk assessment, and to apply enhanced due diligence where sectoral risk factors are present. The Practical Guide for DNFBPs, published alongside the NRA, translates the findings into operational actions for DPMS compliance officers.

Align your business-wide risk assessment with the UAE NRA 2024

AML UAE runs NRA-aligned business-wide risk assessments for DPMS, covering customer, geography, product, channel and delivery dimensions.

DNFBP Sector-Specific Guidance Applicable to DPMS in the UAE

MoET issues dedicated circulars and guidance for all DNFBPs under its supervision. These instruments are the everyday operating manual for DPMS compliance officers and are usually addressed to real estate brokers and agents, DPMS, auditors and accountants, and corporate service providers in parallel.

DNFBP sector-specific guidance at a glance

Ten MoET circulars and implementation guides that govern DPMS screening, CDD, risk-based approach and sanctions obligations

1. Circular No. 1 of 2026 — High-Risk Country Lists

2. AML/CFT DNFBP Guidelines (Sep 2025)

3. Circular No. 3 of 2025 — Sanctions and Terrorist List Screening

4. Circular No. 4 of 2025 — Understanding the NRA 2024

5. Circular No. 6 of 2025 — Risk-Based CDD

6. Circular No. 7 of 2025 — Re-Imposition of UN Sanctions on Iran

7. Circular No. 8 of 2025 — High-Risk Country Update

8. CRA Implementation Guide (Nov 2024)

9. CDD Implementation Guide (Nov 2024)

10. Circular No. 2 of 2022 — UNSCRs 1718 and 2231

1. Circular No. (1) of 2026 on Updating the Lists of High-Risk Countries, Countries Subject to Increased Monitoring, and Related Measures

Issued on 11 March 2026 as MOET/AML/001/2026, this Circular transposes National Committee Resolution No. 15 of 2025 into DNFBP practice. It reminds DPMS that the Resolution reaffirms existing obligations, updates country listings, and requires alignment of screening, enhanced due diligence and risk-based measures with the revised lists. The Circular cites Federal Decree Law 10 of 2025, Cabinet Resolution 134 of 2025 and Cabinet Decision 74 of 2020 as its legal basis.

2. AML/CFT Guidelines for Designated Non-Financial Businesses and Professions — September 2025

The Revised DNFBP Guidelines are the consolidated MoET rulebook for DNFBPs. Part I sets out the legal framework; Part II covers compliance administration; Part III sets out the identification and assessment of ML/TF/PF risks; Parts IV and V address mitigation controls, customer due diligence, reporting and record-keeping. The Guidelines name DPMS among the four supervised categories and incorporate the CNMR (Confirmed Name Match Report), PNMR, and DPMSR reporting typologies into the compliance officer’s remit.

3. Circular No. (3) of 2025 on Emphasising the Importance of Screening Sanctions and Terrorist Lists

Issued on 19 March 2025 as MOEC/AML/003/2025, this Circular is the clearest recent statement that DPMS must screen every customer, beneficial owner and transaction counterparty against sanctions and terrorist lists, irrespective of transaction value, payment method or whether the transaction crosses the AED 55,000 reporting threshold. Screening is not optional below the threshold; only the DPMSR reporting trigger is threshold-based.

4. Circular No. (4) of 2025 on the Importance of Understanding the UAE 2024 National Risk Assessment

This Circular directs DPMS to read the National Risk Assessment 2024 and to map its findings into their own business-wide risk assessment, customer risk matrix and transaction-monitoring rules. Where the NRA identifies a sectoral threat or typology, conflict-affected gold, trade-based money laundering, or shell companies, the DPMS is expected to demonstrate that the threat has been analysed and that mitigating controls are in place.

5. Circular No. (6) of 2025 on Emphasising the Implementation of Risk-Based Customer Due Diligence Measures

Issued on 5 August 2025 as MOET/AML/6/2025, this Circular reinforces the risk-based approach and clarifies the appropriate use of simplified due diligence (SDD). DPMS must apply enhanced due diligence to high-risk customers, standard CDD to medium-risk customers where no suspicion exists, and may apply SDD only to low-risk customers where no suspicion of ML, TF or PF exists. The Circular cross-references to the Customer Risk Assessment and CDD implementation guides issued by the Ministry.

6. Circular No. (7) of 2025 Regarding the Re-Imposition of United Nations Sanctions Related to Iran

Issued on 19 December 2025 as MOET/AML/007/2025, this Circular flags the re-imposition of UN sanctions under Security Council Resolution 1737 (2006) and subsequent resolutions. DPMS must update screening systems to the latest UN Consolidated List, re-screen existing customers and counterparties, apply freezing measures without delay, and report confirmed name matches (CNMR) and partial name matches (PNMR) to the EOCN via goAML in accordance with the procedures in the EOCN TFS Guideline (which sets a five-business-day reporting window from the freeze or suspension measure).

7. Circular No. (8) of 2025 on Updating the Lists of High-Risk Countries, Countries Subject to Increased Monitoring, and Related Measures

Issued on 25 December 2025 as MOET/AML/008/2025, this Circular (later superseded by Circular 1 of 2026) updates the high-risk country lists in line with National Committee Resolution 15 of 2025 and the FATF country review. DPMS must monitor the FATF lists, align customer risk categorisation and transaction monitoring, and apply the measures required by the Ministry when a customer, beneficial owner or counterparty is connected to a listed jurisdiction.

8. Implementation Guide for DNFBPs on Customer Risk Assessment (CRA) — November 2024

The CRA Implementation Guide walks DPMS through the construction of a customer risk matrix, identifying customer, product, service, geography, channel and delivery risk factors; weighting them; and assigning a final risk rating that drives the intensity of CDD, monitoring and review frequency. DPMS use the guide to design their client-onboarding questionnaires and periodic-review templates.

9. Implementation Guide for DNFBPs on Customer Due Diligence (CDD) — November 2024

The CDD Implementation Guide is the operational companion to the CRA guide. It explains how to identify and verify customers and beneficial owners, when to apply simplified, standard or enhanced due diligence, how to approach politically exposed persons, and how to document decisions. DPMS staff handling threshold transactions reference this Guide when collecting identification under MoE Circular 08/AML/2021.

10. Circular No. (2) of 2022 on Implementation of Targeted Financial Sanctions under UNSCRs 1718 (2006) and 2231 (2015)

Issued on 31 March 2022, this Circular covers the implementation of TFS related to the Democratic People’s Republic of Korea (DPRK) and Iran. It requires DPMS to screen every transaction party against the DPRK and Iran sanctions regimes, to apply enhanced due diligence to transactions linked to those jurisdictions, to verify cross-border transactions suspected of involving dual-use goods, and to file confirmed and partial name matches via goAML. The Circular has been superseded in part by later EOCN guidance, but its operational obligations continue to apply.

Build DPMS-ready screening and goAML reporting workflows

AML UAE designs sanctions-screening, PEP-screening and goAML-filing workflows engineered to the MoET circular stack and the CNMR/PNMR reporting timelines.

Sector-Specific Guidelines Applicable to DPMS in the UAE

A final layer of guidance targets DPMS directly. These documents address gold sourcing, DPMSR reporting, compliance officer appointment and DPMS typologies. They sit on top of the federal and DNFBP layers and are the instruments regulators cite most often in DPMS inspections.

DPMS sector-specific guidelines at a glance

Eight directly applicable instruments covering gold sourcing, DPMSR reporting, compliance-officer appointment and precious-metals typologies.

1. UAEFIU Strategic Analysis Report on DPMS (Sep 2025)

2. Ministerial Decree No. 68 of 2024 — Gold Refineries

3. MoE Circular No. 2 of 2024 — Responsible Sourcing of Gold

4. Due Diligence Regulation for Responsible Sourcing of Gold

5. MoE Circular No. 2 of 2023 — DPMS Data Disclosure Notice

6. MoE Circular No. 08/AML/2021 — DPMSR Reporting

7. MoET Circular No. 2 of 2021 — DNFBP Obligations

8. Supplemental Guidance for DPMS (May 2019)

1. UAEFIU’s Strategic Analysis Report on Misuse of Precious Metals and Stones in Financial Crime — September 2025

This is the most recent UAEFIU strategic analysis covering the DPMS sector. It notes that UAE foreign trade in precious stones, metals and their articles grew from AED 497 billion in 2021 to more than AED 959 billion in 2024, and that 8,191 DPMS were registered on goAML as of 30 June 2025, an 81 per cent increase over June 2022. The report analyses 1,448,825 DPMSRs filed between July 2021 and June 2025, as well as around 700 STRs and SARs related to the sector. It identifies five dominant typologies: conflict-affected and high-risk gold; gold smuggling; use of front and shell entities; trade-based money laundering; and the use of precious metals and stones in terrorist financing. It concludes with thirty-two DPMS-specific red-flag indicators covering customer due diligence, trade activities and behavioural triggers.

2. Ministerial Decree No. (68) of 2024 Regarding Gold Refineries’ Adherence to the Policy of Due Diligence Regulations for Responsible Sourcing of Gold

Ministerial Decree 68 of 2024 was issued on 29 March 2024 by the Minister of Economy. Article One requires every entity engaged in refining gold or recycling its products, and every supply-chain stakeholder operating in the UAE (including commercial free zones under MoE supervision), to adhere to the attached Due Diligence Policy for Responsible Sourcing of Gold. Supply-chain participants and precious-metals dealers must establish strong management systems, assess gold-supply-chain risks and implement a management strategy to respond to identified risks. Refineries (and recyclers) must additionally appoint an independent third-party auditor and submit a due diligence report on the gold supply chain. Article Three confirms that administrative penalties apply to violations of the Decree and the attached Policy.

3. Circular No. (2) of 2024 regarding Due Diligence Regulation for Responsible Sourcing of Gold

MoE Circular No. 2 of 2024, dated 29 March 2024, directs every regulated entity with gold refineries as an activity in its licence operating in the UAE to undertake the 5-step framework of the Due Diligence Regulation for Responsible Sourcing of Gold. The Circular confirms that from 1 January 2023, gold refineries must conduct an independent third-party audit of their due diligence measures, with audits expected to be completed within 90 days of the effective date (that is, 90 days from 31 December 2023). The Ministry has a dedicated inbox at ResponsibleSourcing@economy.ae. Entities that fail to comply are subject to administrative actions under the AML/CFT framework.

4. The Due Diligence Regulation for Responsible Sourcing of Gold

The Due Diligence Regulation for Responsible Sourcing of Gold is the policy instrument annexed to the Ministerial Decree and referenced in Circular 2 of 2024. It is built around five steps: (1) establishing an effective governance framework, including a board-approved sourcing policy, management structures and a confidential grievance mechanism; (2) identification and assessment of supply-chain risk, including the use of red flags and enhanced due diligence for conflict-affected and high-risk areas (CAHRAs); (3) management of supply-chain risk through a risk-control plan, continuous monitoring and senior-management reporting; (4) an independent third-party audit of the due-diligence measures; and (5) annual reporting on management systems, risk assessment and risk management. The Regulation is the detailed implementation manual behind Ministerial Decree 68 of 2024.

5. Circular No. (2) of 2023 — Data Disclosure Notice for Dealers in Precious Metals and Stones

MoE Circular No. (2) of 2023 instructed DPMS to display prominently in customer-facing premises a notice informing customers that the dealer will collect identification documents, and they should disclose their data.  

6. Ministry of Economy Circular No. (08/AML/2021) on the Dealers in Precious Metals and Stones Report

MoE Circular 08/AML/2021, dated 2 June 2021, is the DPMSR reporting foundation. Effective 12 June 2021, it requires DPMS to: (1) obtain Emirates ID or passport for resident individuals and ID or passport for non-resident individuals on any cash transaction at or above AED 55,000, and register the information in the UAEFIU’s goAML platform using the DPMSR form; (2) obtain trade licence and ID for corporate counterparties on transactions at or above AED 55,000 in cash or by wire transfer, and register the information in goAML as a DPMSR; and (3) keep records of every document and piece of information relating to the above transactions for a minimum of five years. The Circular refers queries to AML@economy.ae and continues in force under the new federal law.

7. MoET Circular No. (2) of 2021 on AML/CFT Obligations for DNFBPs

MoE Circular 2 of 2021, dated 4 February 2021, is the baseline DNFBP implementation circular. It confirms that MoE supervises real estate brokers and agents, dealers in precious metals and stones, account auditors and company services providers. It requires each supervised entity to appoint a compliance officer in accordance with Article 21 of the Executive Regulations, adopt internal policies, deliver staff training, register on goAML and cooperate with supervisory inspections. DPMS compliance officers cite this Circular when explaining the governance perimeter of their role.

8. Supplemental Guidance for Dealers in Precious Metals and Stones — May 2019

The 2019 Supplemental Guidance is the most detailed sector-specific narrative issued for DPMS. It explains why precious metals and stones are inherently vulnerable to ML/TF: high intrinsic value in a compact form, ability to maintain or increase in value, ease of physical transport, cash-based and decentralised markets, difficulty in tracing specific items and low compliance-awareness among smaller participants. It walks through the AED 55,000 ‘covered transactions’ concept, introduces sector-specific red flags and sets out expectations for customer due diligence, record-keeping and reporting. It continues to serve as a training reference for DPMS compliance teams.

Conclusion

The AML regulations for DPMS in UAE are dense but internally coherent. Federal Decree Law 10 of 2025 and Cabinet Resolution 134 of 2025 set the primary obligations; Cabinet Resolutions 71 of 2024, 109 of 2023 and 132 of 2023 govern penalties and beneficial ownership; a stack of EOCN and UAEFIU guidance operationalises targeted financial sanctions, proliferation-finance controls and reporting; the 2024 NRA sets the risk baseline; and a layer of MoET DNFBP and DPMS-specific circulars translates the regime into daily practice. On top of that, Ministerial Decree 68 of 2024 and Circular 2 of 2024 impose a 5-step responsible sourcing overlay on gold refiners and supply-chain participants.

A DPMS that wants to remain compliant must: submit DPMSR wherever applicable; screen every customer, beneficial owner and counterparty against the local terrorist list and the UN Consolidated List, regardless of transaction size; run a proliferation-finance assessment alongside the ML and TF assessments; integrate the five-step gold sourcing framework where applicable; and make sure that every circular, whether issued under the old Decree Law 20 of 2018 or the new Decree Law 10 of 2025, is understood through the lens of the current federal law.

Talk to AML UAE about your DPMS compliance programme

We design, test and audit AML programmes for gold retailers, refineries, jewellers and diamond traders across the UAE. From business-wide risk assessment to goAML DPMSR workflows and health check, we have you covered.

FAQs

Who counts as a DPMS under UAE AML law?

Under Article 3(3) of Cabinet Resolution 134 of 2025, a dealer in precious metals and stones is any person, natural or legal, trading in precious metals or precious stones in the course of business who carries out a single cash transaction, or several linked cash transactions, equal to or above AED 55,000. The definition covers gold retailers, jewellers, refineries, bullion wholesalers, diamond and coloured-stone traders and recyclers. Below AED 55,000, AML obligations still apply for screening, record-keeping and suspicion-based reporting, but no DPMSR is triggered.

MoE Circular 08/AML/2021 requires DPMS to file a Dealers in Precious Metals and Stones Report (DPMSR) on the UAEFIU’s goAML platform for every cash transaction at or above AED 55,000 with a resident or non-resident individual, and for every transaction at or above AED 55,000 with a legal entity, whether paid in cash or by wire transfer. Separately, any suspicion of ML, TF or proliferation financing, regardless of amount, must be filed as a Suspicious Transaction Report via goAML, and confirmed and partial name matches against sanctions lists must be filed as CNMR or PNMR within five business days of the freeze or suspension.

Yes. Under Ministerial Decree 68 of 2024 and MoET Circular 2 of 2024, entities that engage in refining or recycling gold must adhere to the 5-step Due Diligence Regulations for Responsible Sourcing of Gold and, additionally, appoint an independent third-party auditor and submit an annual due diligence report on the gold supply chain. The audit obligation has applied since 1 January 2023. Refineries remain subject to all the generic DPMS obligations under Decree Law 10 of 2025 and Cabinet Resolution 134 of 2025 in parallel.

The UAEFIU Strategic Analysis Report on DPMS (September 2025) lists thirty-two sector-specific indicators. The most common include: refusal to provide identification; inability to demonstrate funding sources; forged certificates of origin, refinery stamps or fake invoices; supply chains transiting conflict-affected or high-risk jurisdictions; large or frequent cash transactions inconsistent with the customer’s profile; structuring through multiple visits or split invoices just below AED 55,000; payments via multiple third parties or offshore entities without clear commercial link; and repeated requests for duplicate invoices or refunds after cash purchases.

DPMS established in ADGM and DIFC are supervised by the AFDGM Registration Authority (RA) and the Dubai Financial Services Authority (DFSA), respectively. Their rulebooks implement UAE federal AML/CFT law and the UAE’s international AML/CFT commitments, so the substantive obligations and the AED 55,000 threshold logic track federal law. The procedural touchpoints licensing, inspections, filings and enforcement are, however, with the financial free-zone regulator rather than MoET. DPMS in commercial free zones outside ADGM and DIFC remain under MoET supervision.

Was this guide useful?

If this DPMS guide helped your compliance team, a short Google review genuinely helps other jewellers, refineries and dealers find the same answers quickly.

Share via :

About the Author

Pathik Shah

FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)

Pathik is an ACAMS-certified AML consultant specialising in governance, risk, and compliance for regulated entities in the UAE. He brings over 28 years of experience, with 1,000+ hours of AML training and 200+ advisory engagements across DNFBPs, VASPs, and FIs. He supports businesses in aligning with AML/CFT requirements from the CBUAE, DFSA, MoET, MoJ, VARA, CMA, FSRA, and FATF. Known for translating complex regulations into audit-ready procedures, Pathik enables operational clarity and compliance readiness.

Reach Out to Pathik

AML Regulations for DNFBPs in UAE

Blogs

Published On: 04/24/2026

Table of Contents

Protect your business with reliable and effective AML strategies with AML UAE.

Last Reviewed On: 07/21/2026   |   Last Updated On: 07/21/2026

AT A GLANCE

What a DNFBP is: A non-financial business or profession listed in Article 3 of Cabinet Resolution 134 of 2025, the Executive Regulations of Federal Decree Law No. 10 of 2025.

Six DNFBP categories: Commercial gaming operators, real estate brokers and agents, dealers in precious metals and stones, lawyers/notaries/legal professionals, independent accountants and auditors, company and trust service providers, and any other businesses added by Supervisory Authority resolution.

Federal AML statute: Federal Decree-Law No. 10 of 2025 (replacing FDL 20 of 2018) and Cabinet Resolution 134 of 2025.

DPMS cash threshold: AED 55,000 threshold for single or linked cash transactions per Article 3(3) of CR 134/2025.

Commercial gaming threshold: AED 11,000 single or linked financial transactions per Article 3(1) of CR 134/2025; gaming chips alone do not count.

Supervisors: MoET for accountants, auditors, TCSPs, DPMS and real estate; MoJ for lawyers and notaries; GCGRA for commercial gaming; DFSA in DIFC; RA in ADGM.

STR channel: All DNFBPs must report suspicious transactions immediately via the goAML portal of the UAE Financial Intelligence Unit per Article 18 of FDL 10/2025.

Maximum administrative fine: AED 5,000,000 per violation under Article 17(1)(b) of FDL 10/2025; criminal penalties on top.

AML Regulations for DNFBPs in UAE

Quick Overview

AML regulations for DNFBPs in UAE are anchored in Federal Decree-Law No. (10) of 2025 on Anti-Money Laundering, Combating the Financing of Terrorism and Proliferation Financing and its Executive Regulations in Cabinet Resolution No. (134) of 2025. Article 3 of CR 134/2025 designates six categories of Designated Non-Financial Businesses and Professions (DNFBPs): commercial gaming operators, real estate brokers and agents, dealers in valuable metals and precious stones, lawyers/notaries/other legal professionals and independent accountants, company and trust service providers, and any other category added by Supervisory Authority resolution. DNFBP-wide guidance issued by the Ministry of Economy and Tourism applies alongside sector-specific instruments, while the Ministry of Justice supervises lawyers and the General Commercial Gaming Regulatory Authority (GCGRA) supervises licensed gaming activity.

This guide explains who qualifies as a DNFBP, the supervisory map across MoET, MoJ and GCGRA, the federal AML legal framework, the cross-sector guidance issued by the Executive Office for Control and Non-Proliferation (EOCN) and the UAE Financial Intelligence Unit (FIU), and the dedicated guides for each DNFBP sector. Common AML obligations are summarised next, with sector-specific depth in the linked child pages.

DEFINITION

A DNFBP is any business or profession listed in Article 3 of Cabinet Resolution 134 of 2025 that, although not a financial institution, is exposed to money-laundering, terrorist-financing or proliferation-financing risk and must therefore meet the same federal AML statute, customer due diligence rules, beneficial-owner reporting and goAML suspicious-transaction reporting obligations as financial institutions.

What Is a DNFBP Under UAE AML Law?

A DNFBP is a non-financial business or profession that, by reason of the activities it carries out, is brought within the federal AML/CFT/CPF perimeter. Article 1 of Federal Decree-Law No. (10) of 2025 defines DNFBPs by reference to Article 3 of its Executive Regulations. Article 3 of Cabinet Resolution No. (134) of 2025 sets out six categories that qualify as DNFBPs in the UAE.

The six categories in Article 3 of Cabinet Resolution 134 of 2025.

1. Trust and company service providers (TCSPs)

2. Real estate brokers and agents (purchase or sale of real estate)

3. Dealers in valuable metals and precious stones (AED 55,000 cash threshold)

4. Lawyers, notaries, other legal professionals and independent accountants

5. Commercial gaming operators (AED 11,000 single or linked threshold)

6. Other businesses or professions added by Supervisory Authority resolution

Company and trust service providers (TCSPs)

Per Article 3(5) of CR 134/2025, TCSPs are DNFBPs when, on behalf of customers, they: act as agent in the incorporation of legal persons; act as a director or secretary, partner or in a similar position; provide a registered office or correspondence address; act as trustee of an express trust or in an equivalent function for another legal arrangement; or act as a nominee shareholder.

Real estate brokers and agents

Per Article 3(2) of CR 134/2025, real estate brokers and agents are DNFBPs when concluding transactions or settlements on behalf of customers in relation to the purchase or sale of real estate. The UAE National Risk Assessment 2024 rates the sector as having a high residual ML risk, given high-value cash dealings and the use of third parties.

Dealers in valuable metals and precious stones (DPMS)

Per Article 3(3) of CR 134/2025, DPMS are DNFBPs when carrying out any single cash transaction or linked transactions equal to or exceeding AED 55,000. The NRA 2024 rates the sector Medium-High residual ML risk on the mainland and in commercial free zones, citing cash intensity and de-risking by some financial institutions.

Lawyers, notaries, other legal professionals and independent accountants

Per Article 3(4) of CR 134/2025, lawyers, notaries, other independent legal professionals and independent accountants are DNFBPs when they prepare, conduct or execute financial transactions on behalf of customers in relation to: (a) buying and selling real estate; (b) managing customer funds; (c) managing bank, savings or securities accounts; (d) organising contributions for the establishment, operation or management of companies; or (e) establishing, operating or managing legal persons or legal arrangements, or selling or purchasing commercial entities.

Commercial gaming operators

Per Article 3(1) of CR 134/2025, commercial gaming operators are DNFBPs when they conduct a single financial transaction or several linked transactions equal to or exceeding AED 11,000, including gaming on board vessels, halls and internet gaming licensed by the General Commercial Gaming Regulatory Authority. A transaction limited to gaming chips or instruments is not a financial transaction for this purpose.

Catch-all category

Per Article 3(6) of CR 134/2025, any other businesses or professions may be brought within the DNFBP perimeter by a resolution issued by the Supervisory Authority in coordination with the National Committee.

Who supervises each DNFBP sector?

Supervisory responsibility is split across three federal authorities and two financial-free-zone authorities:

DNFBP sector Mainland & commercial FZ ADGM DIFC 
Real estate brokers and agents MoETRADFSA
Dealers in precious metals and stones (DPMS) MoETRADFSA
Company and trust service providers (TCSPs)MoETRADFSA
Independent accountants and auditorsMoETRADFSA
Lawyers, notaries and legal professionals MoJRADFSA
Commercial gaming operators GCGRANANA
Federal AML law applies Yes (FDL 10/2025)Yes (FDL 10/2025)Yes (FDL 10/2025)

ADGM AND DIFC READERS

Federal Decree-Law 10 of 2025 applies across the entire UAE, including the Abu Dhabi Global Market and the Dubai International Financial Centre. The difference is operational supervision: DNFBPs in DIFC follow DFSA rules and DNFBPs in ADGM follow FSRA rules. For ADGM-specific or DIFC-specific guidance see our jurisdiction pages.

Need help confirming whether your business is a DNFBP?

AML UAE assists professional firms across real estate, gold and jewellery, accountancy, legal practice and trust services to confirm scope and build a compliant AML programme.

Core AML obligations for DNFBPs

Every DNFBP, regardless of sector, must implement the same core obligations set by Articles 18 to 20 of Federal Decree-Law No. (10) of 2025, as expanded by Cabinet Resolution No. (134) of 2025Cabinet Resolution No. (109) of 2023 on Beneficial Owner Procedures, and the September 2025 AML/CFT Guidelines for DNFBPs. These obligations apply alongside any sector-specific rules and are summarised below. 

Cross-cutting duties under FDL 10/2025, CR 134/2025 and CR 109/2023.

1. Business-wide ML/TF/PF risk assessment and risk-based approach

2. Customer due diligence (CDD), simplified due diligence (SDD), and enhanced due diligence (EDD)

3. Beneficial owner identification, register and ongoing updates

4. Targeted financial sanctions screening against EOCN lists

5. Suspicious transaction reporting via the FIU goAML portal

7. Compliance officer appointment, staff training and independent audit

8. Record-keeping for at least five years and licence-or-registration discipline

Risk-based approach and business-wide risk assessment

Article 19(1)(a) of FDL 10/2025 requires DNFBPs to identify, understand, manage, assess, document and continuously update ML/TF/PF risks in their business, in line with the National Risk Assessment. Article 5 of CR 134/2025 obliges entities to keep this assessment current and to make it available to the Supervisory Authority on request. The Ministry of Economy and Tourism’s Implementation Guide for DNFBPs on Customer Risk-Assessment (CRA), November 2024, sets out the methodology in detail. 

Article 19(1)(b) of FDL 10/2025 requires DNFBPs to apply CDD measures and continuous monitoring, with scope set by the multiple risk dimensions and the NRA outcomes. Articles 6 to 17 of CR 134/2025 expand the rules: identification and verification of the customer, beneficial owner identification, ongoing monitoring, EDD for high-risk situations including PEPs, and SDD only where the documented risk is genuinely low. The Implementation Guide for DNFBPs on Customer Due Diligence (CDD), November 2024 and Circular No. (6) of 2025 on Risk-Based CDD with a Focus on Simplified Due Diligence guide application across DNFBP sectors. 

Beneficial owner identification and reporting

Articles 4 to 8 of Cabinet Resolution No. (109) of 2023 requires legal persons licensed or registered in the UAE (excluding wholly Government-owned companies and entities in financial free zones) to disclose their real beneficiary information to the Registrar, maintain a Real Beneficiary Register and a Partners or Shareholders Register, and notify changes within 15 days. Failures attract administrative fines under Cabinet Resolution No. (132) of 2023, with three-strike escalation that can include suspension of the commercial licence and closure of the commercial store. 

Targeted financial sanctions (TFS) screening

Article 19(1)(e) of FDL 10/2025 requires DNFBPs to implement, without delay, the instructions of the Executive Office for Control and Non-Proliferation (EOCN) and other competent authorities on TFS. Cabinet Decision No. (74) of 2020 governs the UAE Local Terrorist List and the implementation of UN Security Council resolutions on terrorism and the proliferation of weapons of mass destruction. DNFBPs must subscribe to the EOCN’s Notification Alert System (NAS) and the Automatic Reporting System (ARS), screen customers and counterparties pre-transaction and on an ongoing basis, and freeze and report matches without delay. The duty to screen and act applies before any transaction is executed. 

Suspicious transaction reporting via goAML

Article 19(1)(d) of FDL 10/2025 requires DNFBPs to establish internal policies, controls and procedures approved by senior management, applied to all branches and majority-owned subsidiaries, and reviewed continuously. Section 7 of the September 2025 AML/CFT Guidelines for DNFBPs prescribes a designated Compliance Officer, staff training and screening, group oversight, an independent audit function and senior-management responsibility, with proportionality for resource-limited DNFBPs. 

Internal policies, governance and training

Article 18(1) of FDL 10/2025 requires DNFBPs that suspect, or have reasonable grounds to suspect, that a transaction or funds are linked to ML/TF/PF to notify the FIU without delay through the goAML portal with all available data. Article 18(2) carves out a narrow professional-secrecy exception for lawyers, notaries, other legal professionals and independent legal auditors where the information was obtained under circumstances of professional secrecy. Tipping off the customer or third parties is prohibited under Article 24 and carries criminal penalties under Article 29 (imprisonment and a minimum AED 50,000 fine). 

Record-keeping and licensing

Article 19(1)(f) of FDL 10/2025 obliges DNFBPs to retain transaction records, CDD documentation and supporting data and ensure their immediate availability to competent authorities. Section 11 of the September 2025 DNFBP Guidelines confirms a minimum five-year retention period. Article 20 of FDL 10/2025 prohibits any natural or legal person from carrying on DNFBP activities without a licence, registration or enrolment from the competent authority or relevant Supervisory Authority; breach is a criminal offence under Article 32, punishable by imprisonment and a fine of AED 200,000 to AED 10,000,000.

Penalties for non-compliance

Article 17 of FDL 10/2025 empowers Supervisory Authorities to impose administrative penalties on DNFBPs ranging from a written warning to a fine of AED 10,000 to AED 5,000,000 per violation, restriction of board powers, suspension of personnel, suspension or restriction of activity and revocation of licence. Recurrence within one year may attract incremental fines, and penalties may be published. The Unified List of Violations and Administrative Fines under Cabinet Resolution No. (71) of 2024 sets the violation-by-violation tariff for DNFBPs supervised by MoET and MoJ. Criminal penalties under Articles 26, 28, 29, 32, 33 and 35 of FDL 10/2025 apply on top, with imprisonment and fines from AED 10,000 up to AED 100,000,000 for legal persons convicted of ML, TF or PF. 

Build a defensible AML programme that meets all eight core obligations

Our team designs and operates end-to-end AML programmes for UAE DNFBPs, from CDD and goAML setup to staff training, risk assessment and supervisory inspection readiness.

AML Legal Framework Applicable to DNFBPs in UAE

The legal and regulatory framework that governs DNFBPs in the UAE has four layers: (1) the federal AML statute and its executive regulations; (2) overarching guidance issued by the Executive Office for Control and Non-Proliferation (EOCN), the FIU and the Anti-Money Laundering Department of the Ministry of Foreign Affairs and International Cooperation; (3) the National Risk Assessment and supervisory risk reports; and (4) DNFBP-wide guidance and circulars issued by the Ministry of Economy and Tourism (MoET).

Four layers, working from federal statute down to DNFBP-wide guidance.

1. Federal AML laws and Executive Regulations applicable to DNFBPs in UAE

2. Overarching AML guidance applicable to all reporting entities

3. National Risk Assessment, SRA and other important guidelines for DNFBPs

4. DNFBP-wide guidance applicable across all DNFBP sectors

Federal AML Laws and Executive Regulations Applicable to DNFBPs in UAE

The federal layer sets the binding legal duties for every DNFBP. There are seven federal instruments to know.

The statutes and cabinet resolutions every DNFBP compliance officer should keep at hand.

Seven federal instruments that bind DNFBPs

1. FDL 10/2025 — federal AML/CFT/CPF statute (replacing FDL 20/2018)

2. FL 7/2014 — Combating Terrorism Crimes

3. CR 134/2025 — Executive Regulations of FDL 10/2025

4. CD 74/2020 - Terrorist Lists and UNSCR implementation

5. CR 71/2024 — Unified Violations List for MoJ/MoE-supervised DNFBPs

6. CR 109/2023 — Beneficial Owner Procedures

7. CR 132/2023 — Administrative Penalties under CR 109/2023

1. Federal Decree by Law No. (10) of 2025 Regarding Anti-Money Laundering, and Combating the Financing of Terrorism and Proliferation Financing

FDL 10/2025 is the supreme AML statute in the UAE. It defines DNFBPs (Article 1 read with Article 3 of CR 134/2025), prescribes core obligations (Articles 18 to 20), grants Supervisory Authorities supervisory and inspection powers (Article 16), sets administrative penalties up to AED 5,000,000 per violation (Article 17), and prescribes criminal penalties for ML, TF and PF (Articles 26 to 35). Article 41 expressly repeals Federal Decree-Law No. (20) of 2018; existing executive regulations, resolutions and circulars issued under FDL 20/2018 remain effective only insofar as they do not conflict with FDL 10/2025, until superseded. 

2. Federal Law No. (7) of 2014 Combating Terrorism Crimes

FL 7/2014 defines terrorist acts, terrorist purposes, terrorist organisations and terrorist offences, and is the predicate criminal regime cross-referenced by FDL 10/2025 for the financing of terrorism. DNFBPs encountering customers, transactions or counterparties on UAE Local Terrorist Lists must apply CD 74/2020 measures and report immediately to the FIU.

3. Cabinet Resolution No. (134) of 2025 Concerning the Executive Regulations of Federal Decree-Law No. (10) of 2025

CR 134/2025 is the operative rulebook. Article 3 designates the six DNFBP categories and the gaming-AED 11,000 and DPMS-AED 55,000 thresholds. Articles 5 to 17 set the rules for risk assessment, CDD, beneficial owner identification, EDD, PEPs, ongoing monitoring, reliance on third parties, and the conditions for SDD. Articles 18 to 32 cover STR procedures, group-wide AML programmes, training, audit, record-keeping and the conditions on TFS implementation.

4. Cabinet Decision No. (74) of 2020 Regarding Terrorism Lists Regulation and Implementation of UN Security Council Resolutions

CD 74/2020 governs the UAE Local Terrorist List and the operational implementation of UNSCR 1267 / 1989, 1988, 1718 (DPRK) and other targeted sanctions resolutions. DNFBPs must screen against the consolidated lists communicated by the EOCN, freeze without delay any matched funds, and report matches to the EOCN and the FIU.

5. Cabinet Resolution No. (71) of 2024 Regulating Violations and Administrative Penalties for DNFBPs Subject to MoJ and MoE Supervision

CR 71/2024 is the Unified List of Violations and Administrative Fines for DNFBPs supervised by the Ministry of Justice and the Ministry of Economy. It replaces Cabinet Resolution No. (16) of 2021. The schedule sets specific fine ranges for failures of internal policies, CDD, beneficial owner procedures, sanctions screening, STR filing and record-keeping, with the right to double a fine on repeat violation (Article 5(2)).

6. Cabinet Resolution No. (109) of 2023 On Regulating the Beneficial Owner Procedures

CR 109/2023 sets the federal beneficial owner regime that applies to legal persons licensed or registered in the UAE (excluding wholly Government-owned companies and entities in financial free zones). Article 5 sets the test for who is a real beneficiary (25 percent ownership or ultimate effective control) and Articles 6 to 8 prescribe the Real Beneficiary Register, the Partners or Shareholders Register and the obligation to notify changes within 15 days.

7. Cabinet Resolution No. (132) of 2023 Concerning Administrative Penalties under CR 109/2023

CR 132/2023 attaches a tariff of administrative fines to violations of CR 109/2023, with an annexed schedule of fine amounts and a three-strike escalation that empowers the Registrar to suspend the commercial licence and close the commercial store of a violating legal person until the violation is corrected and the fine paid (Article 3).

AML Guidance Applicable to All Reporting Entities

These EOCN, FIU and AMLD publications are written for all reporting entities (FIs, DNFBPs and VASPs) and bind DNFBPs as a matter of supervisory expectation. There are 13 documents to be aware of.

Cross-sector EOCN, FIU and AMLD instruments that DNFBPs must apply.

Thirteen overarching guidance publications

1. EOCN TFS Guidance for FIs, DNFBPs, VASPs (March 2026)

2. FIU Strategic Analysis Report on Terrorist Financing (May 2025)

3. Strategic Review on TFS Case Studies (April 2024)

4. PF Institutional Risk Assessment Guidance (December 2023)

5. Terrorist and Proliferation Financing Red Flags Guidance (December 2023)

6. Joint Guidance on Combating Unlicensed VA Providers (November 2023)

7. Counter Proliferation Financing Guidance for FIs/DNFBPs/VASPs (November 2022)

8. Joint Guidance on Satisfactory and Unsatisfactory Practice (June 2021)

9. Typologies on TFS Circumvention (March 2021)

10. Guideline on Grievance Procedures

11. Online Grievance System User Guide

12. Combating Proliferation Financing and Sanctions Evasion

13. Simple Guide to Subscribe to the EOCN NAS

1. Guidance on Targeted Financial Sanctions for FIs, DNFBPs and VASPs (EOCN, last amended March 2026)

The EOCN’s TFS Guidance is the principal operational manual for sanctions compliance. It prescribes the duty to subscribe to the NAS, the workflow for screening and freezing, the immediate reporting obligation to the EOCN and the FIU, treatment of partial matches and false positives, communication with customers under the no-tipping-off rule, and unfreezing on de-listing. DNFBPs must align internal policies, screening tools and CDD records to this guidance

2. FIU Strategic Analysis Report on Terrorist Financing — May 2025

The UAEFIU’s Strategic Analysis Report on terrorist financing typologies and facilitators sets out current TF typologies, indicator clusters and case observations relevant to UAE DNFBPs. It informs DNFBP risk-assessment scenarios and STR-quality expectations.

3. Strategic Review on Targeted Financial Sanctions Case Studies (EOCN, April 2024)

The Strategic Review for the private sector (IEC-SR 01 22v2) presents anonymised TFS case studies covering 2019 to 2021, drawing common breakdown points and supervisory expectations. DNFBPs should benchmark internal screening practice against the case studies and self-assess against satisfactory and unsatisfactory practice indicators.

4. Proliferation Finance Institutional Risk Assessment Guidance for FIs, DNFBPs and VASPs (EOCN, December 2023)

This guidance walks DNFBPs through the steps of an institutional PF risk assessment: identifying inherent PF risk (customer, geography, product, channel), assessing residual risk after mitigation, documenting controls and reporting findings. It supports the obligations under FDL 10/2025 Article 19(1)(a) and CR 134/2025 Article 5.

5. Terrorist and Proliferation Financing Red Flags Guidance (EOCN, updated December 2023)

This document lists indicators for TF and PF specific to the UAE economy, including red flags relevant to DNFBP touchpoints such as cash-intensive trade, shell companies, dual-use goods and high-risk geographies. It is the reference list for tagging customer behaviours during CDD and ongoing monitoring.

6. Joint Guidance on Combating the Use of Unlicensed Virtual Asset Providers in the UAE (CBUAE/EOCN/FIU, November 2023)

Although directed at FIs and VASPs, this guidance binds DNFBPs that interact with virtual-asset payments. It explains how to detect interactions with unlicensed VA providers, the duty to refuse such transactions, and the STR-filing expectations.

7. Guidance on Counter Proliferation Financing for FIs, DNFBPs and VASPs (EOCN, November 2022)

The original CPF Guidance (PF.01.22) sets the foundational definitions of WMD, PF and dual-use goods and prescribes minimum CPF measures, including BO transparency, sanctions screening and trade-financing red flags.

8. Joint Guidance on Satisfactory and Unsatisfactory Practice (June 2021)

Issued jointly by the AML/CFT Supervisory Authorities, this guidance illustrates supervisory expectations through paired examples of satisfactory and unsatisfactory practice across CDD, screening, STR filing, governance and training. DNFBPs benefit by mapping internal procedures against the satisfactory column.

9. Typologies on the Circumvention of Targeted Sanctions against Terrorism and the Proliferation of Weapons of Mass Destruction (March 2021)

The TFS Typology Paper documents common circumvention techniques, including the use of front companies, nominee shareholders and trade-based laundering. DNFBPs use it to design typology-based monitoring rules and EDD checklists.

10. Guideline on Grievance Procedures (EOCN)

The Guideline on Grievance Procedures sets out the channel and timing for designated persons or third parties to challenge a TFS designation or sanctions match. DNFBPs should be ready to assist customers procedurally without breaching the no-tipping-off rules.

11. Online Grievance System User Guide (EOCN)

The User Guide is the operational manual for filing a TFS grievance through the EOCN’s online portal. DNFBPs should retain the link in their compliance manuals for customers who wish to challenge a designation.

12. Combating Proliferation Financing and Sanctions Evasion (EOCN)

This awareness publication summarises WMD definitions, PF mechanics and sanctions-evasion techniques. It is widely used in DNFBP staff training programmes.

13. Simple Guide to Subscribe to the EOCN Notification Alert System (NAS)

The Simple Guide explains how to register for the EOCN NAS to receive UN and Local list updates via email. NAS registration is the front-line operational requirement for sanctions compliance and is the practical means of complying with the immediacy duty under FDL 10/2025 Article 19(1)(e).

NRA, SRA, and Other Important Guidelines Applicable to DNFBPs Sector

This layer is the national risk evidence base. DNFBPs must align their business-wide risk assessments with NRA findings.

UAE ML/TF National Risk Assessment — 2024

The UAE National ML/TF Risk Assessment 2024 (issued by the National Anti-Money Laundering and Combatting Financing of Terrorism Committee) sets the benchmark for residual ML/TF/PF risk by sector. For DNFBPs, the NRA assesses real estate as High residual ML risk, DPMS as Medium-High, TCSPs as Medium, accounting and audit as Medium-Low, and the legal-professionals sector as Medium-Low. It also notes the establishment of the General Commercial Gaming Regulatory Authority (GCGRA) in September 2023. Every DNFBP must read the NRA findings into its own business-wide risk assessment, as required by Circular No. (4) of 2025 and the November 2024 Implementation Guide on CRA.

DNFBP Sector-Specific Guidance Applicable Across All DNFBP Sectors

These ten MoET publications form the DNFBP-wide baseline that every DNFBP, regardless of sector, must observe alongside any sector-specific instruments.

Ten DNFBP-wide MoET publications

MoET circulars and implementation guides that supplement the federal statute.

1. Circular No. (1) of 2026 — High-Risk Country List update

2. AML/CFT Guidelines for DNFBPs (September 2025)

3. Circular No. (3) of 2025 — Sanctions and terrorist list screening

4. Circular No. (4) of 2025 — Risk-Based CDD with focus on SDD

5. Circular No. (6) of 2025 — Sanctions and terrorist list screening ​

6. Circular No. (7) of 2025 — Re-imposition of UN Iran sanctions (UNSCR 1737)

7. Circular No. (8) of 2025 — High-Risk Country List update

8. Implementation Guide on CRA (November 2024)

10. Circular No. (2) of 2022 — TFS under UNSCRs 1718 and 2231

1. Circular No. (1) of 2026 on Updating the Lists of High-Risk Countries, Countries Subject to Increased Monitoring, and Related Measures

Issued 11 March 2026 (MOET/AML/001/2026), this circular updates the High-Risk Country and Increased-Monitoring lists used by DNFBPs in CDD and EDD decision-making, and prescribes the related counter-measures. DNFBPs must update screening rules and country-risk matrices accordingly.

2. AML/CFT Guidelines for Designated Non-Financial Businesses and Professions — September 2025

The September 2025 DNFBP Guidelines (76 pages) are the consolidated MoET handbook for DNFBPs. They cover the legislative and regulatory framework, statutory obligations, governance, risk-based approach, business-wide risk assessment, CDD/SDD/EDD, ongoing monitoring, STR procedures, record-keeping and the supervisory map (MoET, MoJ, DFSA, FSRA). The Guidelines apply alongside any sector-specific MoET supplemental guidance.

3. Circular No. (3) of 2025 on Emphasising the Importance of Sanctions and Terrorist List Screening

Issued 19 March 2025 (MOEC/AML/003/2025), this circular re-emphasises the duty to screen all customers and counterparties against UN, UAE and other applicable sanctions lists in real time, with documented evidence of screening at onboarding and on an ongoing basis.

4. Circular No. (4) of 2025 on Understanding the Importance of the UAE 2024 National Risk Assessment

Issued 9 June 2025 (MOEC/AML/004/2025), this circular tells DNFBPs how to align internal business-wide risk assessments with the 2024 NRA findings. It is supplemented by the MoE’s NRA 2024 Practical Guide for DNFBPs.

5. Circular No. (6) of 2025 on Emphasising the Implementation of Risk-Based Customer Due Diligence Measures (with a Focus on Simplified Due Diligence)

Issued 5 August 2025 (MOET/AML/6/2025), this circular reinforces the conditions on SDD: SDD is permitted only where the documented risk is genuinely low and may not be applied where TFS, sanctions or higher-risk indicators are present. It also reaffirms that EDD is mandatory for high-risk customers, PEPs and high-risk jurisdictions.

6. Circular No. (7) of 2025 Regarding the Re-Imposition of United Nations Sanctions Related to Iran Pursuant to UNSCR 1737 (2006) and Subsequent Resolutions

Issued 19 December 2025 (MOET/AML/007/2025), this circular communicates the re-imposition of UN sanctions related to Iran, with operational guidance on screening, freezing and reporting. DNFBPs must reassess Iran-linked customers, beneficial owners and counterparties immediately.

7. Circular No. (8) of 2025 on Updating the Lists of High-Risk Countries, Countries Subject to Increased Monitoring, and Related Measures

Issued 25 December 2025 (MOET/AML/008/2025), this circular updates the high-risk country list and the increased-monitoring list communicated to DNFBPs, and prescribes the related counter-measures to be applied in CDD and EDD.

8. Implementation Guide for DNFBPs on Customer Risk Assessment (CRA) — November 2024

This MoE Implementation Guide on CRA (Version 0.3.1.1) sets the methodology for assessing client, geographic, product, channel and transaction risk. It is the practical companion to FDL 10/2025 Article 19(1)(a) and CR 134/2025 Article 5, and must be read with the September 2025 DNFBP Guidelines.

9. Implementation Guide for DNFBPs on Customer Due Diligence (CDD) — November 2024

This MoE Implementation Guide on CDD (Version 0.3.2.1) explains how DNFBPs apply CDD, SDD and EDD measures, including the KYC stage, identification and verification of natural and legal persons, identification of beneficial owners and ongoing monitoring. It supports CR 134/2025 Articles 6 to 17.

10. Circular No. (2) of 2022 regarding Implementation of Targeted Financial Sanctions (TFS) on UNSCRs 1718 (2006) and 2231 (2015)

Issued 31 March 2022, this circular sets the TFS implementation rules for the UNSCR 1718 (DPRK) and UNSCR 2231 (Iran nuclear) regimes. Although issued under FDL 20/2018, it remains in force pursuant to the saving in Article 41(3) of FDL 10/2025 insofar as it does not conflict with FDL 10/2025.

Map your DNFBP obligations to the right circular and guideline

AML UAE maintains a current matrix of every DNFBP obligation against its source instrument and its supervisor. We translate this into your firm's policies, procedures and inspection-readiness pack.

DNFBP Sector Guides

Each DNFBP sector has its own dedicated guide on amluae.com. The cards below summarise the scope and supervisor; click through for the full sector article.

One card per DNFBP sector, with the supervising authority noted.

1. TCSPs — supervised by MoET

2. Accountants and auditors — supervised by MoET

3. Lawyers, notaries and legal professionals — supervised by MoJ

4. Real estate brokers and agents - supervised by MoET

5. Dealers in precious metals and stones — supervised by MoET

6. Commercial gaming operators — supervised by GCGRA

MoET Circular No. (4) of 2021

Supervisor: Ministry of Economy and Tourism (MoET). Company and trust service providers fall within DNFBPs under Article 3(5) of CR 134/2025 when they incorporate legal persons, act as directors or secretaries, provide a registered office, act as trustees of an express trust or act as nominee shareholders for customers.

Read the full guide: AML regulations for TCSPs in UAE.

AML Regulations for Accountants and Auditors in UAE

Supervisor: Ministry of Economy and Tourism (MoET). Independent accountants and auditors are DNFBPs under Article 3(4) of CR 134/2025 when they prepare, conduct or execute financial transactions for a customer in relation to real estate, fund management, account management, company contributions or the establishment, operation or sale of legal persons.

Read the full guide: AML regulations for accountants and auditors in UAE.

AML Regulations for Lawyers, Notaries, and Other Legal Professionals in UAE

Supervisor: Ministry of Justice (MoJ). Lawyers, notaries and other independent legal professionals are DNFBPs under Article 3(4) of CR 134/2025 for the same five trigger activities, with a narrow professional-secrecy carve-out from STR filing under Article 18(2) of FDL 10/2025; MoJ supervises this sector on the mainland.

Read the full guide: AML regulations for lawyers, notaries and legal professionals in UAE.

AML Regulations for Real Estate Agents and Brokers in UAE

Supervisor: Ministry of Economy and Tourism (MoET). Real estate brokers and agents are DNFBPs under Article 3(2) of CR 134/2025 when they conclude transactions or settlements for a customer in relation to the purchase or sale of real estate; the NRA 2024 rates this sector High residual ML risk on the mainland and in commercial free zones.

Read the full guide: AML regulations for real estate agents in UAE.

AML Regulations for Dealers in Precious Metals and Stones (DPMS) in UAE

Supervisor: Ministry of Economy and Tourism (MoET). Dealers in valuable metals and precious stones are DNFBPs under Article 3(3) of CR 134/2025 when carrying out single or linked cash transactions equal to or exceeding AED 55,000; the NRA 2024 rates the sector Medium-High residual ML risk.

Read the full guide: AML regulations for DPMS in UAE.

AML Regulations for Commercial Gaming Operators in UAE

Supervisor: General Commercial Gaming Regulatory Authority (GCGRA). Commercial gaming operators are DNFBPs under Article 3(1) of CR 134/2025 for single or linked financial transactions equal to or exceeding AED 11,000 (gaming chips alone do not count); GCGRA was established in September 2023 and licenses, regulates and supervises commercial gaming activity in the UAE.

Read the full guide: AML regulations for commercial gaming operators in UAE.

Conclusion

AML regulations for DNFBPs in UAE are anchored in a single federal statute, FDL 10/2025, supplemented by Cabinet Resolution 134/2025 and a layered set of overarching guidance, the National Risk Assessment, and DNFBP-wide MoET circulars and implementation guides. Six DNFBP categories are in scope, supervised by MoET (real estate, DPMS, TCSPs, accountants and auditors), MoJ (lawyers, notaries and other legal professionals) or GCGRA (commercial gaming operators). The core AML obligations, business-wide risk assessment, CDD/SDD/EDD, beneficial owner identification, sanctions screening, goAML reporting, governance, training and record-keeping, are the same across sectors; the sector guides linked below detail how each obligation translates into sector practice.

THE SINGLE LEGAL TEST FOR DNFBP SCOPE

If your business carries out one or more activities listed in Article 3 of Cabinet Resolution 134 of 2025, you are a DNFBP and the full federal AML framework applies. Free-zone status does not exclude you, although DIFC and ADGM businesses are operationally supervised by DFSA and ADGM RA respectively.

FAQs

What are DNFBPs under the UAE AML law?

 A DNFBP is a Designated Non-Financial Business or Profession listed in Article 3 of Cabinet Resolution No. (134) of 2025 (the Executive Regulations of FDL 10/2025). Six categories qualify: commercial gaming operators (AED 11,000 threshold); real estate brokers and agents; dealers in valuable metals and precious stones (AED 55,000 cash threshold); lawyers, notaries, other independent legal professionals and independent accountants when carrying out specified financial transactions; company and trust service providers (TCSPs); and any other category added by Supervisory Authority resolution.

Three federal authorities supervise DNFBPs on the mainland and in commercial free zones: the Ministry of Economy and Tourism (MoET) supervises accountants, auditors, TCSPs, dealers in precious metals and stones and real estate brokers and agents; the Ministry of Justice (MoJ) supervises lawyers, notaries and other legal professionals; and the General Commercial Gaming Regulatory Authority (GCGRA) supervises commercial gaming operators. The Dubai Financial Services Authority (DFSA) and the Registration Authority (RA) supervise DNFBPs operating in the DIFC and ADGM, respectively.

 Yes for the federal layer. Every DNFBP is bound by FDL 10/2025, CR 134/2025 and the same DNFBP-wide MoET guidance and circulars. The core obligations, business-wide risk assessment, CDD, beneficial owner identification, sanctions screening, goAML reporting, internal policies, training and record-keeping, are the same. Sector-specific MoET supplemental guidance and the September 2025 DNFBP Guidelines layer on top, calibrated to each sector’s typical customer types and risk drivers.

 All six DNFBP categories warrant a dedicated guide because their CDD trigger activities, customer types and risk profiles diverge. amluae.com publishes individual sector guides for TCSPs, accountants and auditors, lawyers/notaries/legal professionals, real estate agents and brokers, dealers in precious metals and stones, and commercial gaming operators. Each guide explains the sector-specific MoET or MoJ supplemental guidance, registration, goAML enrolment and the typical inspection focus.

Federal Decree-Law No. (10) of 2025 applies across the entire UAE, including the Dubai International Financial Centre and the Abu Dhabi Global Market. The federal AML statute therefore binds DNFBPs in DIFC and ADGM. The difference is operational: in DIFC, the Dubai Financial Services Authority (DFSA) supervises and applies its own AML Module; in ADGM, the Regulatory Authority (RA) supervises and applies its AML and Sanctions Rulebook. For full operational guidance, see our dedicated ADGM and DIFC pages.

Under Article 17(1)(b) of Federal Decree-Law No. (10) of 2025, a Supervisory Authority can impose an administrative fine of not less than AED 10,000 and not exceeding AED 5,000,000 for each violation, alongside warnings, restriction of board powers, suspension of personnel, suspension of activity and revocation of licence. Repeat violations within one year may attract incremental fines. The Unified List under Cabinet Resolution No. (71) of 2024 sets the violation-by-violation tariff for MoJ- and MoE-supervised DNFBPs, and Cabinet Resolution No. (132) of 2023 sets the BO-specific tariff with a three-strike escalation that can include suspension of the commercial licence.

Talk to AML UAE about your DNFBP obligations

Whether you are a real estate broker, gold dealer, accounting firm, law firm, TCSP or licensed gaming operator, we will help you build, run and defend a compliant AML programme.

Legal disclaimer: This guide is for general information only and reflects publicly available UAE law and guidance current as of 18 April 2026. It is not legal advice. AML/CFT/CPF obligations depend on specific facts and the supervisory authority for your business. Consult AML UAE for tailored advice.

Share via :

About the Author

Pathik Shah

FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)

Pathik is an ACAMS-certified AML consultant specialising in governance, risk, and compliance for regulated entities in the UAE. He brings over 28 years of experience, with 1,000+ hours of AML training and 200+ advisory engagements across DNFBPs, VASPs, and FIs. He supports businesses in aligning with AML/CFT requirements from the CBUAE, DFSA, MoET, MoJ, VARA, CMA, FSRA, and FATF. Known for translating complex regulations into audit-ready procedures, Pathik enables operational clarity and compliance readiness.

Reach Out to Pathik

AML Regulations for Accountants and Auditors in UAE

Federal AML Laws and Executive Regulations Applicable to Accountants and Auditors

Blogs

Published On: 04/17/2026

Table of Contents

Protect your business with reliable and effective AML strategies with AML UAE.

Last Reviewed On: 07/20/2026   |   Last Updated On: 07/20/2026

Key Highlights

  • Accountants and auditors become DNFBPs when they carry out covered activities under Article 3 of Cabinet Decision No. 134 of 2025, such as real estate transactions, managing client funds or securities, managing bank, savings or securities accounts, organising contributions for the creation or management of companies, and creating, operating or managing legal persons or arrangements.
  • The Ministry of Economy and Tourism (MoET) is the designated AML/CFT supervisory authority for accountants and auditors operating in the UAE mainland and commercial free zones.
  • Federal Decree-Law No. 10 of 2025 (replacing Federal Decree-Law No. 20 of 2018) and Cabinet Resolution No. 134 of 2025 set the baseline AML/CFT obligations; MoET has issued the DNFBP Guidelines of September 2025 and the Supplemental Guidance for Independent Accountants and Auditors (IAA) of April 2026 to explain sector expectations.
  • The 2024 UAE National Risk Assessment flags audit and accountancy services as exposed to trade-based money laundering, shell company abuse and sanctions evasion risks.

Independent accountants and auditors in the UAE become subject to anti-money laundering (AML) obligations when they prepare for or carry out specified financial transactions for clients. They are designated non-financial businesses and professions (DNFBPs) supervised by the Ministry of Economy and Tourism (MoET). This guide covers the AML regulations for accountants in UAE mainland and commercial free zones, including the Federal Decree-Law No. (10) of 2025 framework, sector-specific MoET guidance, and practical compliance expectations.

At a Glance: Accountants, Auditors and AML Regulations in UAE

Supervisory authority 

Ministry of Economy and Tourism (MoET) for mainland and commercial free zones 

Primary federal law 

Federal Decree-Law No. (10) of 2025 on AML/CFT/PF 

Executive regulation 

Cabinet Resolution No. (134) of 2025 

Beneficial ownership 

Cabinet Decision No. (109) of 2023 

Primary sector guidance 

MoET AML/CFT Guidelines for DNFBPs (September 2025) 

Accountant-specific guidance 

MoET Circular No. (3) of 2021 and Supplemental Guidance for Independent Accountants and Auditors (April 2026) 

STR filing channel 

UAE FIU goAML portal 

NRA 2024 risk rating 

Medium-low inherent vulnerability for independent accountants and auditors 

ADGM accountants 

Supervised by RA under the AML and Sanctions Rulebook 

DIFC accountants 

Supervised by DFSA under the AML Module 

When is an accountant or auditor a DNFBP?

An accountant or auditor becomes a designated non-financial business or profession (DNFBP) under UAE law when they prepare for or carry out financial transactions on behalf of clients, such as buying or selling real estate, managing client money or securities, managing bank accounts, organising contributions for the creation of companies, or creating and managing legal persons or arrangements.

Independent accountants and auditors occupy a critical gatekeeper position in the UAE anti-money laundering (AML) and counter-financing of terrorism (CFT) framework. The moment an accountant or auditor prepares for or carries out specified financial transactions on behalf of a client, the firm becomes a reporting entity for AML compliance for audit firms UAE purposes.

The UAE has placed independent accountants and auditors within the DNFBP category under Federal Decree-Law No. (10) of 2025, Cabinet Resolution No. (134) of 2025, and a layered suite of sector-specific guidance and circulars. The 2024 National Risk Assessment rates accountants and auditors as a medium-low risk DNFBP sector while acknowledging specific vulnerabilities tied to the profession’s gatekeeper role in financial transactions. DNFBP-wide rules set the baseline; sector-specific guidance layers on top.

This article covers the AML/CFT framework applicable to accountants and auditors operating in the UAE mainland and commercial free zones supervised by the MoET. For the broader DNFBP pillar, see our AML Regulations for DNFBPs in UAE guide. For the primary federal legislation, visit our guide to AML laws in UAE and the dedicated federal AML laws and executive regulations page. If your firm operates in a financial free zone, refer to AML Regulations in ADGM or AML Regulations in DIFC respectively.

Scope of this page

This page covers accountants and auditors supervised by MoET in UAE mainland and commercial free zones. For accountants in ADGM and DIFC, refer to the dedicated jurisdiction pages. Lawyers, notaries, trust and corporate service providers have their own sector pages and are only referenced here where covered activities overlap.

Who Counts as an Accountant or Auditor for AML Purposes in the UAE?

Not every accounting professional is a DNFBP. Under Federal Decree-Law No. (10) of 2025 and its Executive Regulations (Cabinet Resolution No. (134) of 2025), accountants and auditors are classified as DNFBPs only when they prepare for or carry out specific financial transactions for their clients.

The covered activities that bring an accountant or auditor into the AML perimeter are the following five transactions, mirrored from the Financial Action Task Force (FATF) definition:

1. Real Estate Transactions

Buying and selling real estate on behalf of a client, including structuring, escrow, or payment handling.

2. Managing Client Money

Managing client money, securities, or other assets held in trust, on account, or under power of attorney.

3. Bank and Savings Accounts

Managing bank, savings, or securities accounts on behalf of a client, including signatory or authorised-user arrangements.

4. Company Contributions

Organising contributions for the creation, operation, or management of companies, including capital raising and share issuance.

5. Legal Persons and Arrangements

Creating, operating, or managing legal persons or legal arrangements, including buying and selling business entities and trust structures.

Key legal test:

If an independent accountant, external auditor or audit firm performs one or more of these covered activities for a client in the ordinary course of business, the full AML/CFT compliance regime under Federal Decree-Law No. 10 of 2025 and its Executive Regulations applies.

These covered activities are specified in Federal Decree-Law No. (10) of 2025 and Cabinet Resolution No. (134) of 2025, as reflected in the AML/CFT Guidelines for DNFBPs (September 2025) published by the Ministry of Economy and Tourism (MoET), and align with FATF Recommendation 22. It is the nature of the financial transaction being prepared or carried out that determines whether AML obligations apply for a given engagement.

The Supplemental Guidance for Independent Accountants and Auditors (April 2026) further clarifies the scope by explaining how the auditing function intersects with AML obligations. Auditors who, in the course of their professional work, encounter indicators of money laundering, terrorist financing, or other financial crimes are expected to take appropriate action, including filing suspicious transaction reports (STRs) via the goAML portal operated by the UAE Financial Intelligence Unit. This is an overlay obligation: even where a routine audit engagement places the firm inside the DNFBP perimeter and the statutory reporting duty under Federal Decree-Law No. (10) of 2025 is triggered.

Engagement-level analysis is therefore essential. Firms should map each client relationship and engagement type to the covered-activity list, document the reasoning, and refresh the assessment whenever the scope of work changes. Cross-link this analysis with the lawyers, notaries and legal professionals page where accountant-lawyer joint engagements on corporate structuring or real estate are common.

AML Supervisory Authority for Accountants and Auditors in UAE

The Ministry of Economy and Tourism (MoET) is the designated AML/CFT supervisory authority for independent accountants and auditors operating in the mainland UAE and in commercial free zones (excluding ADGM and DIFC). MoET is responsible for day-to-day supervision, desk-based reviews, on-site inspections, thematic reviews, and enforcement action.

MoET supervises four DNFBP categories: real estate agents and brokers, dealers in precious metals and stones (DPMS), independent accountants and auditors, and trust and corporate service providers (TCSPs). For a consolidated view of all supervisors, see our AML supervisory authorities in UAE page.

During inspections, MoET follows a structured process. It sends a formal notification letter; conducts the on-site visit; completes structured inspection checklists covering governance, business-wide risk assessment, CRA, CDD, sanctions screening, STR filing, record keeping, and training; and issues a findings report. Firms are expected to remediate any identified deficiencies within the timelines set by the Ministry. Failure to do so may result in administrative sanctions under Cabinet Resolution No. (71) of 2024, which can include written warnings, fines up to AED 5 million, licence suspension, or licence revocation.

Jurisdictional comparison at a glance

Federal Decree-Law No. (10) of 2025 applies across the entire UAE. The operational supervisor, rulebook, and penalty regime differ by jurisdiction.

DimensionMainland & Commercial Free Zone ADGM DIFC 
Federal Decree-Law No. (10) of 2025 applies Yes YesYes 
Primary supervisorMinistry of Economy and Tourism (MoET)Registration Authority (RA)Dubai Financial Services Authority (DFSA)
Operational rulebookMoET AML/CFT Guidelines for DNFBPs (September 2025) and MoET circularsFSRA AML and Sanctions Rulebook (AML)DFSA AML, CTF and Sanctions Module
Reporting channelgoAML operated by the UAE Financial Intelligence UnitgoAML operated by the UAE Financial Intelligence UnitgoAML operated by the UAE Financial Intelligence Unit
Scope of this guide Covered in full on this pageRefer to AML Regulations in ADGMRefer to AML Regulations in DIFC

Unsure whether an engagement makes your firm a DNFBP?

AML UAE helps accounting and audit firms triage engagements, scope covered-activity exposure, and build a proportionate AML/CFT compliance programme aligned with MoET expectations.

AML Regulations Applicable to Accountants and Auditors in UAE

The AML/CFT regulatory framework applicable to accountants and auditors in the UAE is layered. At its foundation sits a suite of federal laws and executive regulations that apply to all reporting entities. Above that foundation sit cross-sector guidance instruments applicable to all DNFBPs, and finally sector-specific guidance directed at the accounting and auditing profession.

The UAE AML/CFT Regulatory Framework for Accountants and Auditors: Three Layers

Each layer builds on the one below it. All three apply simultaneously to accountants and auditors in UAE mainland and commercial free zones.

LAYER 3 (TOP)

Accountant and Auditor Sector-Specific Guidance

MoET Circular No. (3) of 2021 and Supplemental Guidance for Independent Accountants and Auditors (April 2026). Contains obligations calibrated to the accounting and audit profession, including scope of AML work, red flag indicators, and STR filing from an audit lens.

LAYER 2 (MIDDLE)

DNFBP Cross-Sector Guidance

MoET AML/CFT Guidelines for DNFBPs (September 2025), numbered MoET circulars of 2025-2026, CRA and CDD Implementation Guides (November 2024). Shared across every MoET-supervised DNFBP including real estate agents, dealers in precious metals and stones, accountants and auditors, and trust and corporate service providers.

LAYER 1 (FOUNDATION)

Federal Laws and Executive Regulations

Federal Decree-Law No. (10) of 2025 on AML/CFT/PF, Cabinet Resolution No. (134) of 2025, Federal Law No. (7) of 2014 on Combating Terrorism Crimes, Cabinet Decision No. (74) of 2020, Cabinet Decision No. (109) of 2023, and related administrative penalty resolutions. Apply to every reporting entity across the UAE, including ADGM and DIFC.

Federal AML Laws and Executive Regulations Applicable to Accountants and Auditors

Seven federal legislative instruments form the backbone of every accountant’s and auditor’s compliance programme. Non-compliance with any of these can trigger criminal prosecution, administrative fines, licence suspension, or deregistration. These instruments are deliberately broad: they apply to every natural and legal person that is a reporting entity, including MoET-supervised accountants and auditors.

1. Federal Decree-Law No. (10) of 2025

Primary AML/CFT/CPF statute. Confirms accountant/auditor DNFBP status.

2. Cabinet Resolution No. (134) of 2025

Executive regulations. Operational reference for CDD, BRA, record keeping.

3. Cabinet Resolution No. (71) of 2024

Administrative penalties under MoJ/MoE, up to AED 5 million.

4. Cabinet Decision No. (109) of 2023

Beneficial owner identification and UBO register obligations.

5. Cabinet Resolution No. (132) of 2023

Administrative penalties for beneficial ownership violations.

6. Cabinet Decision No. (74) of 2020

Terrorism lists, UNSCRs, WMD proliferation countermeasures.

7. Federal Law No. (7) of 2014

Criminal combating of terrorism crimes and terrorist financing.

1. Federal Decree-Law No. (10) of 2025 Regarding Anti-Money Laundering, and Combating the Financing of Terrorism and Proliferation Financing

Federal Decree-Law No. (10) of 2025 is the primary AML/CFT/CPF statute in the UAE. It replaced and consolidated the earlier Federal Decree-Law No. 20 of 2018 and its amendments. The law defines predicate offences for money laundering, classifies accountants and auditors among the DNFBPs subject to AML/CFT obligations, and establishes the core compliance duties: customer due diligence (CDD), record keeping, suspicious transaction reporting, internal controls, staff training, and the appointment of an anti-money laundering compliance officer (MLCO). The law requires every accountant and auditor performing covered activities to verify the identity of customers and beneficial owners before establishing a business relationship or carrying out an occasional transaction above the prescribed threshold.

2. Cabinet Resolution No. (134) of 2025 Concerning the Executive Regulations of Federal Decree-Law No. (10) of 2025

Cabinet Resolution No. (134) of 2025 is the executive regulation that operationalises the primary AML/CFT law. It sets out the practical requirements for CDD, including the specific documents that must be collected for natural persons, legal persons, and legal arrangements. It defines the triggers for enhanced due diligence (EDD) and the conditions under which simplified due diligence (SDD) may be applied. For accountants and auditors, the resolution prescribes the requirements of a business-wide risk assessment, the frequency of customer file reviews, the qualifications and reporting line of the compliance officer, and the training requirements for staff performing covered activities. It also requires that all CDD documentation, transaction records, and risk assessments be retained for a minimum of five years after the end of the business relationship.

3. Cabinet Resolution No. (71) of 2024 Regulating Violations, Administrative Penalties Imposed on Violators of Measures for Confronting Money Laundering and Combating Financing of Terrorism Subject to the Control of the Ministry of Justice and the Ministry of Economy

Cabinet Resolution No. (71) of 2024 sets out the graduated administrative penalty regime applicable to entities supervised by the MoET and the Ministry of Justice, including accountants and auditors. Its annexed schedule starts at AED 50,000 for lower-severity breaches and rises to AED 1,000,000 for the most serious scheduled violations, with Article 5(2) permitting the Ministry to double the fine on repeat offences, while Article 3(1) preserves the Ministry’s power to stack any of the Article 14 sanctions under Federal Decree-Law No. (10) of 2025, namely written warnings, fines of up to AED 5,000,000 per violation, business restrictions, removal of senior management, and suspension or revocation of the professional licence.

4. Cabinet Decision No. (109) of 2023 on Regulating the Beneficial Owner Procedures

Beneficial ownership transparency is a core element of the UAE AML/CFT framework. This cabinet decision requires company registrars and corporate entities to identify and verify the identity of their beneficial owners, defined as any natural person who ultimately owns or controls 25 per cent or more of the shares or voting rights, or who exercises effective control through other means. Accountants and auditors who assist clients with company formation, corporate secretarial work, or ongoing management must ensure that beneficial ownership information held by the client is accurate, current, and available to competent authorities upon request, and that the UBO register is maintained at the client’s registered office.

5. Cabinet Resolution No. (132) of 2023 Concerning the Administrative Penalties against Violators of Cabinet Decision No. (109) of 2023 on Beneficial Owner Procedures

This companion resolution prescribes the specific fines and administrative measures that apply to entities and individuals that fail to comply with beneficial ownership requirements. Penalties include fines, suspension of activity, public warnings, and referral to criminal prosecution in cases of deliberate concealment of beneficial ownership information. Accountants who advise on corporate structuring should treat the BO regime and its penalty schedule as part of the first-line client-risk assessment.

6. Cabinet Decision No. (74) of 2020 Regarding Terrorism Lists Regulation and Implementation of UN Security Council Resolutions

Cabinet Decision No. (74) of 2020 implements the UN Security Council resolutions on the suppression and combating of terrorism, terrorism financing, and proliferation of armaments. Under Article 15, any person who holds funds on the UN Consolidated Sanctions List or the UAE Local Terrorist List must freeze those funds without prior notice and without delay, and notify the Executive Office for Control and Non-Proliferation (EOCN) within five working days. The operational mechanics for DNFBPs, including subscription to the EOCN Notification Alert System (NAS), filing of Confirmed Name Match Reports (CNMRs) and Partial Name Match Reports (PNMRs), and ongoing sanctions-list screening, are set out in the EOCN Targeted Financial Sanctions Guidance and are supervisory expectations for every accountant and auditor.

7. Federal Law No. (7) of 2014 Combating Terrorism Crimes

The Federal Law No. (7) of 2014 criminalises terrorism-related offences and defines terrorism crimes, terrorist organisations, and associated penalties. Knowingly providing accounting, tax, or corporate services to a designated terrorist or a terrorist organisation can constitute a criminal offence, independent of the firm’s AML reporting obligations.

Ready to map your obligations under Federal Decree-Law No. (10) of 2025?

AML UAE builds policies, business-wide risk assessments, and inspection-ready files aligned with the 2025 federal framework and MoET guidance.

Overarching AML Guidance Applicable to Accountants and Auditors

In addition to the federal legislative framework, accountants and auditors must follow a set of overarching guidance documents issued by national-level bodies including the Executive Office for Control and Non-Proliferation (EOCN) and the UAE Financial Intelligence Unit (FIU). While these are not primary legislation, they represent binding supervisory expectations and are treated as standards during MoET inspections.

1. TFS Guidance for FIs, DNFBPs and VASPs

EOCN. Most current TFS implementation guidance.

2. FIU Strategic Analysis on TF

Terrorist financing trends and red flags.

3. Strategic Review on TFS Case Studies

Real-world TFS implementation and evasion cases.

4. PF Institutional Risk Assessment

PF-IRA methodology for FIs, DNFBPs, VASPs.

5. TF and PF Red Flags Guidance

Indicators for monitoring and staff training.

6. Joint Guidance on Unlicensed VASPs

Identifying and mitigating unlicensed VASP risks.

7. Counter PF Guidance

Dual-use goods screening, trade monitoring, EDD.

8. Satisfactory/Unsatisfactory Practice

Joint good-practice benchmarks for inspections.

9. Typologies on TFS Circumvention

Front companies, nominee structures, layering.

10. Guideline on Grievance Procedures

How designated persons or entities may seek review.

11. Online Grievance System User Guide

Step-by-step instructions for the grievance portal.

12. Combating PF and Sanctions Evasion

Practical controls against sanctions evasion.

13. NAS Subscription Simple Guide

How to subscribe to the EOCN alert system.

1. Guidance on Targeted Financial Sanctions for Financial Institutions, DNFBPs and VASPs (EOCN, March 2026)

The most current TFS guidance from the EOCN. It details the procedures for screening, freezing, unfreezing, and reporting in relation to UN and local sanctions lists. Accountants and auditors must implement screening procedures covering all customers, beneficial owners, authorised signatories, and transaction counterparties. Confirmed matches must be reported via a Confirmed Name Match Report (CNMR) and partial matches via a Partial Name Match Report (PNMR), both submitted through the goAML system. Freezing measures must be implemented without delay upon a confirmed match, which the EOCN interprets as same-business-day at the latest.

2. FIU Strategic Analysis Report on Terrorist Financing — May 2025

The FIU’s strategic analysis report provides insight into current terrorist financing trends, methods, and red-flag indicators in the UAE. Accountants and auditors should use this report to inform their internal risk assessments and to train staff on emerging TF typologies, including small-value transfers layered through professional services, misuse of charitable structures, and abuse of corporate service vehicles.

3. Strategic Review on Targeted Financial Sanctions Case Studies — November 2021 (covering 2019-2021, EOCN reference IEC-SR.01.22)

This strategic review presents anonymised case studies illustrating how targeted financial sanctions have been applied and, in some cases, evaded. It serves as a practical reference for understanding sanctions evasion schemes and how compliance teams should respond, with examples that include the use of nominee directors, complex trust structures, and indirect ownership chains that frustrate first-layer screening.

4. Proliferation Finance Institutional Risk Assessment Guidance for FIs, DNFBPs and VASPs — December 2023

Accountants and auditors are required to incorporate proliferation financing (PF) risks into their business-wide risk assessments. This guidance explains the methodology for conducting a PF Institutional Risk Assessment (PF-IRA), including the identification of PF risk factors, the assessment of existing controls, and the documentation of findings. The PF-IRA is a stand-alone exercise distinct from the AML business-wide risk assessment and must be reviewed at least annually.

5. Terrorist and Proliferation Financing Red Flags Guidance — December 2023

This document sets out the red-flag indicators that may suggest terrorist or proliferation financing activity. Accountants and auditors should embed these indicators into their transaction monitoring processes, CDD escalation triggers, and staff training programmes. Typical red flags include unexplained wire transfers to high-risk jurisdictions, layered corporate structures with no clear commercial rationale, and clients reluctant to disclose the source of wealth.

6. Joint Guidance on Combating the Use of Unlicensed Virtual Asset Providers in the UAE — 1 March 2022

Relevant to accountants and auditors who encounter clients using virtual assets or dealing with virtual asset service providers. It highlights the risks associated with unlicensed VASPs and the steps that DNFBPs should take to identify and mitigate those risks, including refusing to process payments to suspected unlicensed VASPs and filing STRs where appropriate.

7. Guidance on Counter Proliferation Financing for FIs, DNFBPs and VASPs — 1 March 2022 (EOCN reference EOCN-PF.01.22)

This guidance supplements the PF risk assessment guidance by explaining the practical counter-proliferation financing controls, including dual-use goods screening, trade-related transaction monitoring, and enhanced due diligence for clients with links to sanctioned jurisdictions such as the DPRK and Iran.

8. Joint Guidance on Satisfactory and Unsatisfactory Practice — June 2021

Issued jointly by UAE supervisory authorities, this guidance provides examples of good and poor compliance practice observed during inspections. Accountants and auditors should review the examples to benchmark their own compliance programmes and to calibrate remediation plans where MoET has identified a weakness.

9. Typologies on the Circumvention of Targeted Sanctions against Terrorism and the Proliferation of Weapons of Mass Destruction — March 2021

This document examines the techniques used to evade targeted financial sanctions, including the use of front companies, nominee structures, identity concealment, and complex layering schemes. Valuable for training compliance staff and calibrating EDD triggers.

10. Guideline on Grievance Procedures

Sets out how designated persons or entities may seek review of listing decisions and how supervisory authorities and DNFBPs should handle grievance requests. Accountants acting as registered agents or in nominee roles should be familiar with the process so they can respond appropriately where a client is listed.

11. Online Grievance System User Guide

Step-by-step instructions for using the EOCN online grievance portal, including the information required, supporting documents, and processing timelines.

12. Combating Proliferation Financing and Sanctions Evasion

Practical guidance for implementing counter-proliferation and sanctions-evasion controls. Useful when designing transaction monitoring scenarios and calibrating escalation triggers in higher-risk trade corridors.

13. Simple Guide to Subscribe to the EOCN Notification Alert System (NAS)

Explains how accountants and auditors should register for the EOCN NAS to receive real-time alerts when sanctions lists are updated. Subscription to NAS is a mandatory supervisory expectation for DNFBPs and is commonly checked during MoET inspections.

Need a PF-IRA template, TFS screening procedure, or training deck?

AML UAE delivers EOCN-aligned templates and train-the-trainer sessions calibrated to the size and risk profile of accounting and audit firms.

NRA, SRA, and Other Important Guidelines Applicable to Accountants and Auditors

The UAE National Risk Assessment (NRA) is the single most important national-level risk document for every DNFBP. It synthesises risk findings across the UAE economy and prescribes calibration of supervisory and firm-level controls. Accountants and auditors must treat the NRA as a live input into their business-wide risk assessment, not a background reference.

UAE ML/TF National Risk Assessment — 2024

The 2024 National Risk Assessment describes the audit and accounting sector as small, with medium inherent vulnerability and medium-low residual risk. The NRA acknowledges specific vulnerabilities, including the gatekeeper role that accountants play in financial transactions, the potential for professional services to be misused to obscure beneficial ownership, and identified gaps in screening and monitoring practices across parts of the profession.

Accountants and auditors are required to review the NRA findings, conduct a gap analysis between their current compliance programme and the NRA expectations, incorporate the findings into their business-wide risk assessments, and update their internal controls, CRA weighting, and training materials accordingly. MoET has confirmed that inspection teams will probe whether NRA findings are reflected in BRAs and in the calibration of the CRA.

DNFBP Sector-Specific Guidance Applicable to Accountants and Auditors

These guidance and circular instruments are issued by MoET and apply across its DNFBP perimeter. They are not accountant or auditor-specific but form the operational backbone against which inspections are conducted, and they must be read in conjunction with the federal laws above.

1. Circular No. (1) of 2026

Updated high-risk country list and related measures.

2. AML/CFT Guidelines for DNFBPs

Primary compliance manual covering governance, CDD, EDD, STRs.

3. Circular No. (3) of 2025

Sanctions and terrorist list screening at onboarding and continuously.

4. Circular No. (4) of 2025

NRA 2024 is a live input to BRAs.

5. Circular No. (6) of 2025

Risk-based CDD with focus on simplified due diligence.

6. Circular No. (7) of 2025

Reimposition of UN sanctions relating to Iran under UNSCR 1737.

7. Circular No. (8) of 2025

Further high-risk country list updates.

8. CRA Implementation Guide

Methodology for customer risk assessment and review frequencies.

9. CDD Implementation Guide

Identity, verification, beneficial ownership, SDD, EDD.

10. Circular No. (2) of 2022

TFS implementation for UNSCRs 1718 (DPRK) and 2231 (Iran).

1. Circular No. (1) of 2026 on Updating the Lists of High-Risk Countries, Countries Subject to Increased Monitoring, and Related Measures

This circular updates the lists of jurisdictions classified as high-risk (FATF black list) or subject to increased monitoring (FATF grey list) and directs accountants and auditors to apply enhanced due diligence to all relationships and transactions involving those jurisdictions. It also prohibits establishing branches or subsidiaries in high-risk jurisdictions and reliance on third parties in those countries for CDD performance.

2. AML/CFT Guidelines for Designated Non-Financial Businesses and Professions — September 2025

Published by MoET in September 2025, these comprehensive guidelines replace earlier DNFBP guidance and provide the definitive regulatory expectations for all MoET-supervised DNFBPs, including accountants and auditors. They cover the full compliance lifecycle: governance and the MLCO role, business-wide risk assessment, customer risk assessment, CDD (including SDD and EDD), ongoing monitoring, STR filing through goAML, record keeping, staff training, and sanctions screening. This is the single most important reference document for building an AML/CFT compliance programme for accounting and audit firms.

3. Circular No. (3) of 2025 on Emphasising the Importance of Screening Sanctions and Terrorist Lists (MOEC/AML/003/2025, dated 19 March 2025)

This circular reiterates the obligation to screen customer databases against the latest sanctions and terrorism lists without delay. Screening must cover not only the customer but also all beneficial owners, authorised signatories, and transaction counterparties. MoET inspection teams treat sanctions screening evidence as a priority test area.

4. Understanding the Importance of the UAE 2024 National Risk Assessment — A Practical Guide for DNFBPs (Ministry of Economy)

This practical guide directs all MoET-supervised DNFBPs to study the 2024 NRA, incorporate its findings into internal risk assessments, and allocate resources to address identified gaps. The NRA is a binding input to the firm’s compliance programme, not merely a reference document.

5. Circular No. (6) of 2025 on Emphasising the Implementation of Risk-Based Customer Due Diligence Measures (with a Focus on Simplified Due Diligence)

This circular provides practical direction on when and how SDD may be applied. SDD may never be applied where there is any suspicion of money laundering or terrorist financing. Firms must apply EDD for high-risk customers, standard CDD for medium-risk customers, and SDD only for genuinely low-risk customers where the firm has documented its risk rationale and there is no suspicion.

6. Circular No. (7) of 2025 Regarding the Reimposition of United Nations Sanctions Related to Iran pursuant to UNSCR 1737 (2006) and Subsequent Resolutions

This circular requires accountants and auditors to update screening systems with the latest UN Consolidated Sanctions List, re-screen all existing customers and beneficial owners for exposure to Iran sanctions, apply freezing measures without delay upon a confirmed match, and report confirmed matches (via CNMR) and partial matches (via PNMR) through the goAML system.

7. Circular No. (8) of 2025 on Updating the Lists of High-Risk Countries, Countries Subject to Increased Monitoring, and Related Measures

A subsequent update to the high-risk country list published within 2025. The updated lists must be reflected in the firm’s jurisdictional risk assessment, CRA, and CDD policies, and all existing relationships with nexus to the updated jurisdictions must be reviewed for potential EDD.

8. Implementation Guide for DNFBPs on Customer Risk Assessment (CRA) — November 2024

The Ministry of Economy’s Implementation Guide for DNFBPs on Customer Risk Assessment sets out a ten-step methodology for scoring customers across five risk-factor categories, Customer, Geographic, Product/Service/Transaction, Delivery Channel, and Other, using a one-to-five scale from Low to High. The guide requires accountants and auditors to apply the CRA at onboarding, at periodic reviews, and whenever there is a change in risk factors such as a shift in ownership, a new product, adverse media, a sanctions listing, or an update to the National or Sectoral Risk Assessment. It indicates example review cadences of every six months for high-risk clients, every one year for medium and medium-high risk clients, every eighteen months for low-medium risk clients, and every two years for low-risk clients, and it requires DNFBPs to maintain a comprehensive audit trail of all due diligence steps, risk scores, and justifications, available upon request by the competent supervisory authority.

9. Implementation Guide for DNFBPs on Customer Due Diligence (CDD) — November 2024

This companion guide details practical CDD steps, including identity verification for natural and legal persons, beneficial ownership identification using the 25 per cent threshold, SDD and EDD conditions, ongoing monitoring, and procedures when CDD cannot be completed. It also addresses the tipping-off prohibition: once a suspicious transaction is contemplated or reported, the firm must not disclose that fact to the client or to any third party who is not authorised to receive it.

10. Circular No. (2) of 2022 Regarding Implementation of Targeted Financial Sanctions on UNSCRs 1718 (2006) and 2231 (2015)

This circular provides implementation instructions for TFS related to DPRK and Iran proliferation sanctions. EDD is required for all transactions with a nexus to North Korea and Iran, including verification of cross-border transactions for potential dual-use goods, shipment documents, and end-user declarations.

Sector-Specific Guidelines Applicable to Accountants and Auditors

Beyond the DNFBP-wide instruments, the following documents are addressed specifically to the accounting and auditing profession and reflect the sector’s particular risk exposures and operational realities.

Ministry of Economy Circular No. (3) of 2021 (dated 4 February 2021)

Issued by the then Ministry of Economy Anti-Money Laundering Department (prior to the ministry’s rebranding as the Ministry of Economy and Tourism), this circular is addressed directly to independent accountants and auditors. It outlines core AML/CFT obligations, including the requirement to register with the Ministry, appoint a compliance officer, conduct customer due diligence, and file suspicious transaction reports via the goAML system.

Supplemental Guidance for Independent Accountants and Auditors — April 2026

The MoET Supplemental Guidance for the Independent Accountants and Auditors – April 2026, explains how UAE Independent Accountants and Auditors should manage money laundering, terrorism financing and proliferation financing risks under Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025.

It highlights that accountants and auditors act as gatekeepers because they often see ownership structures, financial records, tax information, audit evidence and corporate transactions. This position allows them to identify hidden beneficial ownership, unusual fund movements, false documents, weak controls and suspicious activity.

The guidance expects firms to apply a risk-based AML/CFT/CPF framework. This includes a documented business risk assessment, clear policies and procedures, the appointment of a qualified Compliance Officer or MLRO, staff training, senior management oversight, independent audit, customer due diligence, sanctions screening, ongoing monitoring, suspicious activity reporting, and proper recordkeeping.

Key risks include complex ownership structures, foreign or high-risk jurisdictions, politically exposed persons, shell companies, nominee arrangements, weak beneficial ownership transparency, unusual payment methods, false invoices, unexplained wealth, third-party payments and customers pressuring firms to reduce scrutiny.

The document also provides typologies, red flags and case studies showing how professional services may be misused to create a false appearance of legitimacy, launder corruption proceeds, support trade-based money laundering, misuse real estate structures, hide sanctions exposure or move illicit funds through companies and charities.

Overall, the guidance requires IAAs to combine professional scepticism with a documented judgement on compliance and timely reporting when suspicion arises.

Are you an accountant or auditor in ADGM or DIFC?

Accountants and auditors operating in the Abu Dhabi Global Market are supervised by the ADGM Registration Authority (RA) and must comply with the ADGM AML and Sanctions Rulebook. Those in the DIFC are supervised by the DFSA and must comply with the DFSA AML, CTF and Sanctions Module. The overarching federal laws and cabinet resolutions apply across the entire UAE, including ADGM and DIFC. See our ADGM and DIFC pages for the operational rulebook that applies to your firm.

Conclusion

The AML/CFT regulatory framework for accountants and auditors in the UAE is both comprehensive and continuously evolving. From the primary Federal Decree-Law No. (10) of 2025 through the detailed implementing regulations, overarching EOCN and FIU guidance, DNFBP-wide MoET circulars, and sector-specific MoET guidance, the obligations are clear and enforceable. The common thread is risk-based thinking: firms must identify where they sit in the ML/TF/PF risk landscape, calibrate controls accordingly, and be able to evidence the judgement at inspection.

For accountants and auditors operating in mainland UAE and commercial free zones, the practical priorities are as follows. Firms that invest in the controls below now will be best placed to adapt to future updates to the UAE AML/CFT/CPF framework and to avoid the significant penalties that attach to non-compliance.

1. Conduct and document a business-wide risk assessment (BRA) informed by the 2024 NRA and the September 2025 DNFBP Guidelines. Review at least annually and on trigger events such as new product lines, new jurisdictions, or new circulars.

2. Maintain a proliferation financing institutional risk assessment (PF-IRA) calibrated to client and transaction exposure to DPRK, Iran, and other proliferation-sensitive jurisdictions.

3. Apply a documented customer risk assessment to every client before providing covered services. Verify identity using reliable independent documents. Identify beneficial owners at the 25 per cent ownership or effective-control threshold. Apply EDD for high-risk clients, standard CDD for medium-risk, and SDD only where documented low-risk rationale exists and no suspicion is present.

4. Monitor client relationships continuously for changes in ownership, business activity, transaction patterns, and risk profile. Review frequencies should follow the CRA Implementation Guide: high-risk every 6 months, medium-high every 12 months, medium every 12 months, low-medium every 18 months, and low-risk every 24 months.

5. Screen all clients, beneficial owners, authorised signatories, and transaction counterparties at onboarding and continuously against the UAE Local Terrorist List, UNSC consolidated lists, and FATF-designated jurisdictions. Subscribe to the EOCN NAS for real-time alerts and register with the ARS.

6. File STRs via goAML whenever the firm knows, suspects, or has reasonable grounds to suspect that a transaction relates to ML, TF, or PF. File FFRs for confirmed matches and PNMRs for partial matches. Respect the tipping-off prohibition at all times.

7. Appoint an MLCO with adequate seniority, independence, and direct reporting to senior management. Deliver periodic AML/CFT training covering CDD, red flags, STR filing, sanctions screening, and the tipping-off prohibition to all staff performing covered activities.

8. Retain CDD documentation, transaction records, STR filings, sanctions hits, risk assessments, and training logs for a minimum of five years after the end of the business relationship or the date of the occasional transaction.

Build your accountant or auditor AML programme with AML UAE

We design, document, and stress-test AML/CFT compliance programmes for accounting and audit firms across UAE mainland and commercial free zones, including BRA/PF-IRA, CRA, CDD, screening, STR filing workflows, training, and inspection readiness.

Frequently Asked Questions

When are accountants treated as DNFBPs in the UAE?

Accountants and auditors are treated as DNFBPs when they prepare for or carry out specified financial transactions on behalf of clients. The five covered activities are buying and selling real estate, managing client money or securities, managing bank or savings accounts, organising contributions for the creation or management of companies, and creating or managing legal persons or arrangements. 

The Ministry of Economy and Tourism (MoET) is the designated AML/CFT supervisory authority for independent accountants and auditors operating in mainland UAE and in commercial free zones. Accountants and auditors licensed in the ADGM are supervised by the FSRA, and those in the DIFC are supervised by the DFSA. Federal AML laws apply in all three jurisdictions; the difference is the operational rulebook and the supervisory interface.

Risk-based customer due diligence is expected. This includes verifying the identity of the customer and all beneficial owners at the 25 per cent ownership or effective-control threshold, understanding the purpose and intended nature of the business relationship, conducting ongoing monitoring of transactions and customer information, and keeping records for at least five years. Enhanced due diligence is required for high-risk customers; simplified due diligence may be applied only to genuinely low-risk relationships where no suspicion of ML or TF exists.

Common red flags for accountants include unexplained large cash transactions or payments in rounded amounts, complex multi-jurisdictional structures with no clear business rationale, clients reluctant to provide identification or beneficial ownership information, inconsistencies between reported revenue and observable business activity, transactions involving high-risk or sanctioned jurisdictions, use of nominee directors or shell companies with no substantive operations, and sudden changes in transaction patterns or payment flows without a clear commercial reason.

Yes. ADGM and DIFC are financial free zones with their own regulatory authorities, the ADGM Registration Authority (RA) and the DFSA respectively. Audit firms licensed in those jurisdictions follow the AML/CFT rulebook issued by their regulator. However, the overarching federal laws and cabinet resolutions, including Federal Decree-Law No. (10) of 2025 and Cabinet Decision No. (134) of 2025, apply across the entire UAE, including ADGM and DIFC. The supervisor and the operational rulebook differ by jurisdiction, not the federal statute.

Enjoying this guide?

Leave us a review on Google. It helps other compliance professionals discover AML UAE and supports our ongoing research into UAE AML regulations.

Disclaimer : This article is published by AML UAE (amluae.com) for informational and educational purposes only. It does not constitute legal, regulatory, or compliance advice. The UAE AML/CFT regulatory framework is subject to change, and references to named laws, circulars, and guidance documents reflect the position known at the time of publication. For advice specific to your firm, consult a qualified AML compliance professional or licensed legal advisor. AML UAE accepts no responsibility for decisions taken in reliance on this article alone.

Share via :

About the Author

Pathik Shah

FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)

Pathik is an ACAMS-certified AML consultant specialising in governance, risk, and compliance for regulated entities in the UAE. He brings over 28 years of experience, with 1,000+ hours of AML training and 200+ advisory engagements across DNFBPs, VASPs, and FIs. He supports businesses in aligning with AML/CFT requirements from the CBUAE, DFSA, MoET, MoJ, VARA, CMA, FSRA, and FATF. Known for translating complex regulations into audit-ready procedures, Pathik enables operational clarity and compliance readiness.

Reach Out to Pathik

AML Laws in UAE: Complete Guide to AML/CFT Legislation 2026

AML/CFT/CPF Legal Framework in the UAE

Blogs

Published On: 03/17/2026

Table of Contents

Protect your business with reliable and effective AML strategies with AML UAE.

Last Reviewed On: 07/20/2026   |   Last Updated On: 07/20/2026

Key Highlights:

  • Federal Decree Law No. (10) of 2025 is the principal regulation dealing with AML/CFT/CPF in the UAE
  • Cabinet Resolution No. (134) of 2025 is the implementing regulation of the Federal Decree Law No. (10) of 2025
  • The respective supervisory authorities issue sector-specific guidelines
  • ADGM and DIFC have their Own Rulebooks, and regulated entities operating from financial free zones must follow Federal Law in addition to these rulebooks

A guide to Anti Money Laundering AML Laws in UAE | 2026

The UAE’s AML framework requires regulated entities to identify customers, assess risk, monitor transactions, screen for sanctions and terrorism financing, and report suspicious activity to the UAE FIU through goAML, supported by strong governance, training, and audit controls.

It is critical to combat money laundering and terrorism financing and safeguard the economy.  In these efforts to identify and mitigate the financial crime risks, here is the comprehensive guide to Anti-Money Laundering (AML) Laws in the UAE for various regulated entities.

AML/CFT/CPF Legal Framework in the UAE

As part of the UAE government’s efforts to fight these financial crimes, AML/CFT regulations have been issued, supported by detailed guidelines from various supervisory authorities that lay down the principles and best practices for identifying financial crime instances and mitigating the risks, in accordance with the federal AML regulations.

Federal AML/CFT/CPF Laws and Executive Regulations

The Federal AML/CFT/CPF laws and executive regulations apply to banks, financial institutions, DNFBPs, and VASPs operating in the mainland and free zones (commercial as well as financial free zones).

The following are the key AML regulations setting the foundation for the regulated entities to detect and mitigate the ML/FT and PF risks:

NRA, SRA, and Other Important Guidelines

UAE ML/FT National Risk Assessment

UAE PF National Risk Assessment

The above-referred-to NRAs outline the outcomes of the UAE’s national assessment of financial crime vulnerabilities, threats, and risks across various sectors. It also evaluates the quality of the controls deployed by these regulated sectors to manage the risks.

AML/CFT/CPF Guidance Applicable to All Reporting Entities

The following are the key AML/CFT/CPF and TFS-related guidance and guidelines issued by the concerned authorities, which are relevant to all the regulated entities and guide them in the effective implementation of the federal regulations:

History of UAE AML Regulations

  • The Federal Decree Law No. (10) of 2025 came into effect from October 14, 2025, and it repealed Federal Decree Law No. (20) of 2018 and Federal Decree Law No. (26) of 2021 (amendments to the 2018 AML law).
  • The Cabinet Resolution No. (134) of 2025 came into effect from December 14, 2025, and it repealed Cabinet Decision No. (10) of 2019 and Cabinet Resolution No. (24) of 2022 (amendments to the 2019 Executive Regulation).
  • Federal Law No. (7) of 2014 Combating Terrorism Crimes came into effect from 1st September 2024, and it repealed Federal Decree-Law No. (1) of 2004 on Combating Terrorist Crimes.
  • Cabinet Resolution No. (74) of 2020 Regulating the Terrorist Lists and Implementing the Security Council’s Resolutions Regarding the Prevention and Suppression of Terrorism and its Financing and Proliferation of Armaments and the related Resolutions came into force with effect from 29th October 2020, and it repealed Cabinet Resolution No. (20) of 2019 Concerning the Regulation of Terrorism lists and the application of the Security Council resolutions and the relevant resolutions on the prevention, suppression of terrorism and its financing and the cessation of weapon proliferation and its financing & the Relevant Resolutions.
  • Cabinet Resolution No. (71) of 2024 Regulating Violations, Administrative Penalties Imposed on Violators of Measures for Confronting Money Laundering and Combating Financing of Terrorism Subject to the Control of Ministry of Justice and Ministry of Economy came into force with effect from 8th July 2024, and it repealed the Cabinet Resolution No. (16) of 2021 Concerning the Unified List of Violations and Administrative Fines Imposed on Violators of Measures for Confronting Money Laundering and Combating the Financing of Terrorism Who are Under the Control of the Ministry of Justice and Ministry of Economy.
  • Cabinet Decision No. (109) of 2023 On Regulating the Beneficial Owner Procedures came into force on 6th November 2023, and it repealed the Cabinet Resolution No. (58) of 2020 regulating Real Beneficiary Procedures.
  • Cabinet Resolution No. (132) of 2023 Concerning the Administrative Penalties against Violators of The Provisions of the Cabinet Resolution No. (109) of 2023 Concerning the Regulation of Beneficial Owner Procedures came into force with effect from 30th December 2023, and it repealed The Cabinet Resolution No. (53) of 2021 concerning Administrative Penalties imposed on Violators of the provisions of Cabinet Resolution No. (58) of 2020 concerning Regulating Real Beneficiary procedures.

Who Must Comply with AML Law in the UAE?

The AML Law in the UAE applies to Financial Institutions, Designated Non-Financial Businesses and Professions (DNFBPs), and Virtual Asset Services Providers (VASPs).

AML/CFT Covered Activities for Banks and Financial Institutions

The Financial Institutions undertaking the following activities would be subject to AML compliance:

  • Accepting deposits and other repayable funds from the public.
  • Lending, including consumer credit and mortgage lending and financing commercial transactions, including the purchase of export bills and debts.
  • Financial leasing, excluding financial leasing related to consumer products.
  • Money or value transfer services.
  • Issuing and managing means of payment, such as debit cards, credit cards, cheques, payment orders, banker’s drafts, and electronic money.
  • Financial guarantees and commitments.
  • Trading in money market instruments such as cheques, bills of exchange, certificates of deposit, derivatives and related instruments; or foreign exchange; or currency, interest rate and index instruments; or other financial derivatives; or negotiable financial instruments; and trading in commodity futures contracts.
  • Participating in securities issuance and providing financial services related to such issuances.
  • Managing funds and portfolios of all types.
  • Safekeeping and administration of cash or liquid securities on behalf of others.
  • Other operations involving investment, management, or administration of funds or money on behalf of others.
  • Underwriting or subscribing to life insurance policies and other investment-related insurance products, including those provided by insurance agents and brokers.
  • Currency exchange.

AML/CFT Covered Activities for Designated Non-Financial Businesses and Professions (DNFBPs)

The Designated Non-Financial Businesses and Professions include: 

  • Real estate brokers and agents conduct transactions related to the purchase or sale of real estate on behalf of their customers.
  • Dealers in precious metals and stones.
  • Lawyers, notaries, other independent legal professionals, and independent accountants, when preparing, conducting, or executing financial transactions:
    • Purchase and sale of real estate.
    • Management of funds owned by the Customer.
    • Management of bank accounts, savings accounts, or securities accounts.
    • Organising contributions for the creation, operation, or management of companies.
    • Creating, operating, or managing juristic persons or Legal Arrangements, or the sale or purchase of business entities.
  • Company and trust service providers, when carrying out a transaction in relation to the following activities:
    • Acting as an agent in the incorporation or creation of legal persons.
    • Acting, or arranging for another person to act, as a director or secretary of a company, or as a partner or in an equivalent position in another legal person.
    • Providing a registered office, business address, residence, correspondence address, or administrative address for a company, another legal person, or a legal arrangement.
    • Acting, or arranging for another person to act, as a Trustee of an express trust or performing an equivalent function for another form of legal arrangement.
    • Acting, or arranging for another person to act, as a nominee shareholder for another person.
  • Operators of Commercial Games (included in the definition of the DNFBP vide Cabinet Decision No. (134) of 2025, effective December 14, 2025.)

AML/CFT Covered Activities for Virtual Asset Service Providers (VASPs) in UAE

Virtual Asset Service Providers shall be subject to AML compliance when undertaking the following activities:

  • Exchange between Virtual Assets and fiat currencies.
  • Exchange between one or more types of virtual assets.
  • Transfer of virtual assets.
  • Safekeeping or administration of virtual assets or instruments enabling control over virtual assets.
  • Providing financial services or activities related to the issuer’s offering, sale, or participation in virtual assets.

AML/CFT Supervisory Authorities in the UAE

For overseeing the enforcement of the above-mentioned federal AML regulations and also to issue the relevant guidance to the supervised entities under their respective purview in line with the powers granted under the federal AML regulations, the following authorities have been designated as the AML Supervisory Authorities:

Supervised Entities

Supervisory Authority

Jurisdictions

Financial Institutions

Central Bank of the UAE

Entire UAE (except financial freezones)

Trusts and Company Service Providers

Ministry of Economy and Tourism

Entire UAE (except financial freezones)

Dealers in Precious Metals and Stones

Ministry of Economy and Tourism

Entire UAE (except financial freezones)

Independent Auditors and Accountants

Ministry of Economy and Tourism

Entire UAE (except financial freezones)

Real Estate Brokers and Agents

Ministry of Economy and Tourism

Entire UAE (except financial freezones)

Lawyers, Notaries and Legal Consultants

Ministry of Justice

Entire UAE (except financial freezones)

Capital Market

Capital Market Authority

Entire UAE (except DIFC and ADGM)

Virtual Asset Service Providers

Capital Market Authority

Entire UAE (except Dubai)

Virtual Assets Regulatory Authority

Emirate of Dubai (except DIFC)

All regulated entities in DIFC

Dubai Financial Services Authority

DIFC

All regulated entities in ADGM

Financial Services Regulatory Authority

ADGM

Operators of Commercial Games

General Commercial Gaming Regulatory Authority

Entire UAE (except financial freezones)

Financial Intelligence Unit (FIU): While the above-mentioned authorities supervise AML implementation by regulated entities, the Financial Intelligence Unit (FIU) remains the central reporting authority from an AML perspective, irrespective of the nature of the business or the location of operations in the UAE.

Executive Office for Control and Non-Proliferation (EOCN): The authority enforcing the targeted financial sanctions regime in the UAE is the EOCN, which is also receiving, reviewing and guiding the regulated entities on implementing the TFS and evaluating the reports made by the regulated entities related to sanctions match (reporting is done through the goAML Portal only).

Sector-Specific AML/CFT/CPF Legal Framework in the UAE

The regulatory framework for AML/CFT/CFP in the UAE is structured across multiple sectors, each governed by dedicated laws, executive regulations, supervisory authorities, and guidance frameworks.

The UAE’s AML/CFT framework imposes comprehensive obligations on a wide spectrum of entities. While all regulated sectors must adhere to the core federal legislation, i.e., Federal Decree-Law No. (10) of 2025 and Cabinet Resolution No. (134) of 2025, they are also subject to detailed sector-specific laws, regulations, and guidance from their respective authorities.

To simplify navigation of this landscape, the following consolidates the primary legislation, rulebooks, circulars, guidelines, compliance publications, and regulatory bodies across all sectors.

AML/CFT/CPF Legal Framework for Designated Non-Financial Businesses and Professions (DNFBPS)

DNFBPs encompass a range of non-financial businesses and professions that are particularly vulnerable to money laundering, terrorism financing, and proliferation financing due to the nature of the products or services they offer. These entities, which include dealers in precious metals, real estate agents, legal professionals, corporate service providers, independent accountants and auditors, and operators of commercial games must comply with federal AML/CFT laws, as well as the sector-specific regulations issued by their respective supervisory authorities.

All DNFBPs have to adhere to:

  • Implementation Guide For DNFBPs on Customer Risk Assessment (CRA) – November 2024
    The guide focuses on the customer risk assessment process that DNFBPs must perform as part of customer onboarding. It elaborates on the CRA methodology and the risk factors that different DNFBPs must consider.
  • Implementation Guide For DNFBPs on Customer Due Diligence (CDD) – November 2024
    This guide provides practical insights into the CDD process that DNFBPs follow. It aims to assist entities with their day-to-day challenges related to CDD and to guide them on international best practices for CDD.

AML/CFT/CPF Legal Framework for Dealers in Precious Metals & Stones (DPMS)

Supervisory Authority for Dealers in Precious Metals and Stones Sector: 

The Ministry of Economy and Tourism (MoET) is the AML supervisory authority for the dealers in the precious metals and stones sector operating in and from the UAE Mainland and the commercial free zones.

AML/CFT/CPF Laws, Regulations and Guidance Applicable to DPMS Sector:
DPMS Sector-Specific AML/CFT/CPF Guidelines & Circulars:

Along with the above-referred federal decree laws and implementing regulations, and cabinet decisions, the DPMS is required to adhere to the following guidance documents and relevant ministerial decrees:

  • Circular No. 2/2021 Calls for the implementation of AML/CFT obligations by DPMS and explains the supervisory authority’s procedures for onsite and offsite inspection for the compliance of the same.
  • Supplemental Guidance for Dealers in Precious Metals and Stones – May 2019
    The supplemental guidance document is to be read with the above-mentioned DNFBP guidelines. This supplemental guidance details the DPMS activities that shall be subject to AML compliance. It also includes certain illustrations of the sectoral abuse for money laundering and terrorism financing.

AML/CFT/CPF Legal Framework for Real Estate Agents & Brokers

Supervisory Authority for Real Estate Brokers and Agents: 

The Ministry of Economy and Tourism (MoET) is the AML supervisory authority for real estate agents and brokers operating in the UAE (except those licensed and operating from DIFC and ADGM).

AML/CFT/CPF Laws, Regulations and Guidance Applicable to Real Estate Sector:
Real Estate Sector-Specific AML/CFT/CPF Guidelines & Circulars

Real estate agents and brokers are required to comply with the additional guidance documents, in addition to the above-referred federal decree laws, implementing regulations, and cabinet decisions.

  • Circular No. 1/2021 Calls for the implementation of AML/CFT obligations by real estate agents and brokers and explains the supervisory authority’s procedures for onsite and offsite inspection for the compliance of the same.
  • Supplemental Guidance for the Real Estate Sector – May 2019
    The supplemental guidance document is to be read in conjunction with the DNFBP guidelines. This guidance documents the various real estate-related activities which are vulnerable to financial crime. Various examples of the exploitation of the real estate sector for money laundering and terrorism financing are provided, along with the sectoral ML/FT red flags.

AML/CFT/CPF Legal Framework for Trust & Corporate Service Providers (TCSPs)

Supervisory Authority for Trust & Corporate Service Providers: 

The Ministry of Economy and Tourism is the AML supervisory authority for trust and corporate service providers licensed in the UAE Mainland and the commercial free zones.

AML/CFT/CPF Laws, Regulations and Guidance Applicable to TCSPs:
TCSP Sector-Specific AML/CFT/CPF Guidelines

TCSPs are mandated to adhere to the guidance documents, in addition to the federal AML regulations mentioned above.

  • Circular No. 4/2021 Calls for the implementation of AML/CFT obligations by TCSPs and explains the supervisory authority’s procedures for onsite and offsite inspection for the compliance of the same.
  • Supplemental Guidance for Trust & Company Service Providers – May 2019
    The supplemental guidance must be read in parallel with the DNFBP guidelines referenced above. This guidance lists various activities performed by the TCSP that shall be subject to AML measures, and others that are low risk and do not require risk mitigation measures. It also captures the sectoral red flag indicators that the TCSP must be mindful of.

AML/CFT/CPF Legal Framework for Auditors & Independent Accountants

Supervisory Authority for Auditors and Independent Accountants: 

The independent auditors and accountants (licensed in the UAE, except those licensed by the FSRA and DFSA) are subject to AML supervision by the Ministry of Economy and Tourism.

AML/CFT/CPF Laws, Regulations, and Guidance Applicable to Auditors and Independent Accountants:
Auditors & Independent Accountants Sector-Specific AML/CFT/CPF Guidelines & Circulars

Independent accountants and auditors are required to develop the AML program in accordance with the guidance documents listed below, as well as the federal decree law, the cabinet decision, and general AML publications at the federal level.

  • Circular No. 3/2021 Calls for the implementation of AML/CFT obligations by Accountants and Auditors and explains the supervisory authority’s procedures for onsite and offsite inspection for the compliance of the same.
  • Supplemental Guidance for Auditors – June 2019
    The supplemental guidance for auditors is to be considered as a follow-up document to the above-mentioned DNFBP guidelines. This guidance lists various risks that the independent auditors may encounter while discharging their professional duties. The guidance also documents examples of abuse of auditor services, certain known typologies, and sectoral red flag indicators that the auditor should be mindful of.

AML/CFT/CPF Legal Framework for Lawyers, Notaries & Other Legal Professionals

Supervisory Authority for Lawyers, Notaries, and Other Legal Professionals: 

The Ministry of Justice (MoJ) is the AML supervisory authority for lawyers, notaries and independent legal professionals operating in the UAE (except the financial free zones).

AML/CFT/CPF Laws, Regulations and Guidance Applicable to Lawyers, Notaries, and Other Legal Professionals
Legal Sector-Specific AML/CFT/CPF Guidelines

Legal professionals, lawyers, and law firms are required to implement an AML program in accordance with regulatory documents issued by the MoJ, as well as the federal AML regulations mentioned above.

  • Lawyers’ Guide on AML/CFT (2026) The guide illustrates the best practices that lawyers and legal professionals should adopt to comply with AML obligations regarding the identification, assessment, and mitigation of ML/FT risks they may face. It places emphasis on firm-level accountability, firm-wide risk assessment processes aligned with FATF standards, integration of CPF controls alongside AML/CFT controls, reliance on data analytics and client behaviour patterns beyond traditional ID checks.
  • Circular No. (1) of 2025 regarding the commitment of law firms to the controls of institutional assessment processes (Available only in Arabic) Requires legal professionals and lawyers to conduct and document institutional risk assessments specifically addressing proliferation financing risks and requires them to update their internal AML/CFT controls to align with FATF recommendations and UAE non-proliferation laws, particularly Federal Decree-Law No. 43 of 2021 on the Goods Subject to Non-Proliferation. It further mandates the Compliance Officers to follow guidance issued by the MoJ and the EOCN to prevent involvement of legal professionals and practitioners in transactions linked to weapons proliferation
  • Circular No. (1) of 2024 regarding simplified due diligence procedures. (Available only in Arabic)
    The circular elaborates on the simplified due diligence measures that the law firms and legal professionals may apply to the customers identified as posing low ML/FT risks.

AML/CFT/CPF Legal Framework for Operators of Commercial Games (New Sector)

Supervisory Authority for Operators of Commercial Games: 

The General Commercial Gaming Regulatory Authority (GCGRA) is the AML supervisory authority for the newly brought commercial gaming operators under the AML regime.

AML/CFT/CPF Laws, Regulations and Guidance Applicable to Operators of Commercial Games:

Sector-Specific AML/CFT/CPF Guidelines for Commercial Game Operators: 

For now, the gaming operators are required to comply with the above-referred federal decree laws and implementing regulations, as well as cabinet decisions, while the sector-specific AML/CFT guidelines are yet to be issued by the GCGRA.

Additionally, it is recommended to consider the following:

  • Policy Paper – Commercial Gaming Policy (2025)
    This policy paper has been issued jointly by the NAMLCFTC and GCGRA. The policy paper documents the key ML/FT and PF risks associated with the gaming industry and provides the targeted recommended strategies that can be adopted to mitigate the risks.

AML/CFT/CPF Legal Framework for Virtual Asset Service Providers (VASPs)

All Virtual Asset Service Providers have to adhere to:

VASPs are subject to different authorities depending on the jurisdiction in which they operate. Accordingly, VASPs are expected to comply with the AML guidelines and rulebooks issued by the relevant AML supervisory authority.

In addition to this, the VASPs are required to refer to the following FATF publications when developing their ML/FT risk mitigation framework (mandated by the supervisory authorities):

  • FATF’s Targeted Update on Implementation of FATF Standards on Virtual Assets and VASPs
    The report highlights the FATF’s observations and feedback on the implementation of the FATF standards in the virtual asset sector across various countries. It also discusses the evolving risks and the exploitation of virtual assets for proliferation and terrorism financing. The last section of the report documents the FATF’s recommendations to VASPs and regulatory authorities.

The VASPs are also expected to refer to this report issued by Public Private Partnership Sub Committee and NAMLCFTC  –  Rising Use of Virtual Currencies by Criminals to Launder Their Illegal Profit.” The report documents how virtual currencies are misused for laundering and terrorism financing, lists certain red flag indicators, and includes key recommendations for regulated entities. 

AML/CFT/CPF Legal Framework for VASPs in the Emirate of Dubai

Supervisory Authority for Virtual Asset Service Providers in the Emirate of Dubai

The Virtual Asset Regulatory Authority (VARA) is the AML supervisory authority for the VASPs licensed and operating in or from Dubai.

AML/CFT/CPF Laws, Regulations and Guidance Applicable to VASPs in the Emirate of Dubai:
Sector-Specific AML/CFT/CPF Guidelines for VASPs in the Emirate of Dubai

Along with the above-referred federal decree laws and implementing regulations, and cabinet decisions, the VASPs subject to VARA supervision are required to comply with the following:

  • VARA’s Compliance and Risk Management Rulebook
    Part III of the rulebook provides detailed guidance to the VARA-licensed VASPs on the AML/CFT obligations, including the mandate to adequately assess the business risks arising from virtual asset operations. The rulebook requires VASPs to develop an AML program, led by a fit-and-proper person (Compliance Officer), that assists VASPs with customer onboarding, transaction monitoring, record maintenance, etc.

AML/CFT Legal Framework for VASPs in the UAE (Except in the Emirate of Dubai)

Supervisory Authority for Virtual Asset Service Providers in the UAE (Except in the Emirate of Dubai)

The VASPs, operating in or from anywhere in the UAE, except Dubai and the financial free zones, are subject to AML supervision by the Capital Market Authority of the UAE.

AML/CFT/CPF Laws, Regulations and Guidance Applicable to VASPs in the UAE (Except in the Emirate of Dubai) :
Sector-Specific AML/CFT/CPF Guidelines for VASPs in UAE (Except in the Emirate of Dubai)
  • Guidelines: Regulations of Virtual Assets and VASPs (2023)
    This CMA issued guidelines mandate that VASPs develop and implement a robust AML/CFT and sanctions compliance program, including the appointment of a Compliance Officer, documenting a comprehensive AML/CFT policy and procedures, assessing business and customer risks, applying adequate CDD measures, etc.
  • Circular on CMA’s Examination Observation Report
    The report highlights shortcomings across the sector related to ML/FT and defines expectations for regulated entities to take robust measures to ensure that the developed AML/CFT and sanctions compliance program is aligned with the business risk.
  • CMA Questions and Answers – NRA
    The CMA issued the FAQs in line with the latest NRA, setting out the CMA’s expectations of regulated entities to update their EWRA and align it with the outcome of the latest ML/FT NRA

AML/CFT Legal Framework for Financial Free Zones

The financial free zones in the UAE, i.e. DIFC and ADGM, operate under their own legal and regulatory frameworks that are aligned with federal AML/CFT requirements. These jurisdictions have enacted specific laws and rulebooks to govern business activities within their territories while ensuring consistency with the national AML/CFT strategy.

AML/CFT/CPF Laws, Regulations, and Guidance Applicable to Financial Free Zones

AML/CFT/CPF Legal Framework for Abu Dhabi Global Market (ADGM)

Supervisory Authority for Abu Dhabi Global Market: 

All the entities operating in or from ADGM are subject to oversight and supervision of the Financial Services Regulatory Authority (FSRA).

AML/CFT/CPF Laws, Regulations and Guidance Applicable to ADGM
ADGM AML/CFT/CPF Legal Framework and Key Deviations from the Federal AML/CFT/CPF Law:

Compared to the federal AML regulations, the scope of DNFBP is wide, covering a larger number of entities within the AML ambit, where the possibility of abusing the sector for ML/FT is high. In ADGM, DNFBP includes the following:

  • a real estate agency which carries out transactions with other persons that involve the acquiring or disposing of real property,
  • a dealer in precious metals or precious stones,
  • a dealer in any saleable item of a price equal to or greater than USD 15,000,
  • an accounting firm, audit firm, insolvency firm or taxation consulting firm,
  • law firm, notary firm or other independent legal business, and
  • Company Service Provider.
ADGM-Specific AML/CFT/CPF Laws, Regulations and Guidance

The FSRA-regulated entities are required to adhere to the following additional regulatory rulebook and guidance documents, along with federal decree laws and implementing regulations, as well as cabinet decisions.

  • Review the new laws in detail
  • Analyse the impact of the new law on their AML/CFT and TFS compliance framework
    • Update their AML/CFT and TFS policies, procedures, manuals, and tools to ensure complete alignment with the new laws.
  • FSRA – FCCP – Notice No. 91 of 2025 – Updated on Targeted Financial Sanctions (TFS) Guidance Requires all relevant persons to refer to updated TFS guidance to ensure compliance with screening and ongoing enforcement procedures.
  • goAML Registration Quick Guide (for DNFBPs) This quick guide is aimed at assisting DNFBPs with registering on the goAML system to enable filing mandatory reports with UAEFIU and ensure compliance with ADGM AML requirements.
  • ADGM Quick Guide – Know Your Customer (KYC) (for DNFBPs) The quick guide on KYC helps regulated DNFBPs understand the key elements of the KYC process for onboarding individual and corporate customers. It also includes certain examples of the KYC measures to be followed under different scenarios.
  • RAs Self-Assessment Form for DNFBPs Regulator’s Self-Assessment Form is provided to serve as supplementary information to the ADGM Registration Authority (ADGM RA) as evidence to showcase that DNFBPs have implemented AML/CFT Policies and Procedures in alignment with ADGM AML Rules.
  • Checklist – Appointment of MLRO ADGM RA has published MLRO appointment checklist to enable regulated entities to ensure that they appoint a suitable MLRO by verifying the qualifications, experience, eligibility and independence of the candidate. It also helps ensure that all required documents and information are collected and submitted to the FSRA for approval of the MLRO appointment.  Lastly, the checklist helps regulated entities demonstrate that they have conducted adequate due diligence and governance checks prior to the appointment of an MLRO.
  • 2024 DNFBP Common Findings Report The report gives out common findings identified by the RA during onsite assessments of DNFBPs, especially recurring observations across the majority of the firms.
  • ADGM Financial Crime Report 2021-2022 Elaborates how FSRA supports its objectives of prevention of financial crime and aligns with UAE’s national AML/TFS agenda through RA and the Financial and Cyber-Crime Prevention unit (FCCP).

AML/CFT/CPF Legal Framework for Dubai International Financial Centre (DIFC)

Supervisory Authority: 

The Dubai Financial Services Authority (DFSA) is the licensing and AML supervisory authority for entities operating in or from DIFC, regardless of their nature of activities, whether as a DNFBP, VASP, or a company carrying out financial activities.

AML/CFT/CPF Laws, Regulations and Guidance Applicable to DIFC
DIFC AML/CFT/CPF Legal Framework and Key Deviations from the Federal AML Law:

The definition of DNFBP is different from what is provided under the federal AML law, bringing in more non-financial activities under the AML regime. The entities conducting the following activities are considered DNFBP in DIFC:

  • a real-estate developer or agency which carries out transactions with a customer involving the buying or selling of real property,
  • a dealer in precious metals or precious stones which carries out any single cash transaction or several transactions that appear to be connected and the value of which is equal to or greater than USD 15,000,
  • a person who issues, or provides services relating to Non-Fungible Tokens or Utility Tokens (with certain exceptions),
  • a law firm, notary firm, or other independent legal business,
  • an accounting firm, audit firm or insolvency firm, and
  • a company service provider.
DIFC-Specific AML/CFT/CPF Laws, Regulations and Guidance

Compliance with the rulebook below is mandatory for DFSA-regulated entities, in addition to federal decree laws, implementing regulations, and cabinet decisions.

  • DIFC Anti-Money Laundering, Counter-Terrorist Financing and Sanctions Rulebook The rulebook provides for the key AML/CFT obligations of a regulated entity operating in or from DIFC, guiding them in adequately identifying and mitigating the financial crime risks. The Dubai Financial Services Authority (DFSA) systematically updates its Anti-Money Laundering, Counter-Terrorist Financing and Sanctions (AML) Module to respond to emerging ML/FT and PF risks, technological advancements and shifts in UAE legislation by publishing Rule-Making Instruments (RMIs). The RMIs published from 2024 to date (March 2026) are intended to showcase the trajectory of the DFSA AML regime.

AML/CFT/CPF Legal Framework for Banks and Financial Institutions Supervised by CBUAE

Entities within the UAE’s financial sector operate under a stringent AML/CFT regime supervised primarily by the Central Bank of the UAE (CBUAE) and other specialised authorities like the Capital Market Authority (CMA). Compliance obligations extend across banking, insurance, capital markets, and payment services, and other financial activities, with sector-specific regulations supplementing the federal AML/CFT framework.

All banks and financial institutions have to adhere to:

Along with the above-referred federal decree laws and implementing regulations, and cabinet decisions, the financial institutions shall be subject to the following guiding publications by the relevant supervisory authorities:

AML/CFT/CPF Legal Framework for Insurance Sector (Insurance companies, insurance agents/brokers)

Supervisory Authority: 

CBUAE is the supervisory authority overseeing the effective implementation of AML/CFT regulations by insurance and reinsurance companies, as well as insurance brokers/agents.

AML/CFT/CPF Laws, Regulations and Guidance Applicable to the Insurance Sector
Insurance Sector-Specific AML/CFT/CPF Guidance

Additionally, the adherence to the following regulatory documents is also mandatory:

  • CBUAE AML/CFT Guidance for the Insurance Sector – October 2022
    The guidance focuses on the AML/CFT obligations of the entities engaged in insurance activities. It helps entities understand the potential exposure to financial crime and the mitigation measures required to safeguard the insurance sector and remain compliant with the regulatory regime.

AML/CFT/CPF Legal Framework for Registered Hawala Providers

Supervisory Authority: 

CBUAE is the supervisory authority overseeing the effective implementation of AML/CFT regulations by registered hawala providers.

AML/CFT/CPF Laws, Regulations and Guidance Applicable to the Registered Hawala Providers
Registered Hawala Providers Sector-Specific AML/CFT/CPF Guidance

Additionally, the adherence to the following is also mandatory for the registered hawala providers:

CBUAE AML/CFT Guidance for registered Hawala providers and Licensed Financial Institutions providing services to Registered Hawala Providers – August 2021

The guidance focuses on registered hawala providers’ AML/CFT obligations, including registration requirements, developing their AML/CFT program, and the AML reporting mandate.

AML/CFT/CPF Legal Framework for Exchange Houses

Supervisory Authority: 

CBUAE is the AML supervisory authority for the exchange houses operating in the UAE.

AML/CFT/CPF Laws, Regulations and Guidance Applicable to the Exchange Houses
Exchange Houses Sector-Specific AML/CFT/CPF Guidance

Additionally, the exchange houses must comply with the following:

AML/CFT/CPF Legal Framework for Securities, Commodities and Capital Markets

Supervisory Authority: 

The Capital Market Authority (CMA) of the UAE is the licensing and AML supervisory authority for entities engaged in capital market operations across the entire UAE (except the financial free zones).

AML/CFT/CPF Laws, Regulations and Guidance Applicable to CMA-Regulated Entities
CMA-Specific AML/CFT/CPF Guidance

Along with the above-referred federal decree laws and implementing regulations, and cabinet decisions, the capital market players are required to adhere to the following rulebook, guidance documents, etc., issued by the CMA:

  • Circular on CMA’s Examination Observation Report
    The report highlights shortcomings across the sector related to ML/FT and defines expectations for regulated entities to take robust measures to ensure that the developed AML/CFT and sanctions compliance program is aligned with the business risk.
  • CMA Questions and Answers – NRA
    The CMA issued the FAQs in line with the latest NRA, setting out the CMA’s expectations of regulated entities to update their EWRA and align it with the outcome of the latest ML/FT NRA.
History:

Earlier, the AML/CFT guidance for the CMA-regulated entities was driven through the CMA Board Chairman’s Decision No. (21/Chairman) of 2019, which documented the AML/CFT procedures

UAE’s Strategic Goals related to AML/CFT

First, let’s understand the UAE’s strategic goals related to AML and CFT.

UAE’s 12 Strategic Goals 

Strategic Goal 1: Continue deepening the understanding of risk.

Strategic Goal 2: Increase the standing of the FIU within the UAE’s national AML/CFT framework.

Strategic Goal 3: Improve law enforcement authorities’ efforts in detecting and investigating money laundering (ML).

Strategic Goal 4: Use provisional and confiscation measures more frequently and effectively.

Strategic Goal 5: Adjudicate and prosecute ML effectively and apply proportionate and effective sanctions.

Strategic Goal 6: Improve the effectiveness of regulatory and supervisory efforts for financial institutions and designated non-financial and business and professions, prioritising higher-risk sectors and taking dissuasive enforcement actions.

Strategic Goal 7: More vigorously identify and intercept unlicensed money remittance services.

Strategic Goal 8: Enhance implementation of targeted financial sanctions without delay.

Strategic Goal 9: Align company registration frameworks across the UAE.

Strategic Goal 10: Strengthen the level of assistance the UAE provides to its International Partners

Strategic Goal 11: Continue to effectively investigate, prosecute and convict TF offences

Strategic Goal 12: Continue to modernise the UAE’s legal framework.

AML/CFT Governance & Coordination Structure in UAE

The UAE operates a centralised and multi-layered AML/CFT/CPF governance structure as given below, ensuring strategic oversight, regulatory coordination, and operational execution across all sectors.

1. Supreme Committee for AML/CFT/CPF

It serves as the apex national authority for AML/CFT/CPF and is responsible for setting strategic priorities and the national policy roadmap.

2. National Committee (NAMLCFTC)

It functions as the central coordination body for AML/CFT implementation, driving national strategy, ensuring regulatory alignment, facilitating coordination between the concerned authorities, and representing the UAE at the international level.

3. General Secretariat of NAMLCFTC

The General Secretariat, formerly the Executive Office for AML/CTF, now acts as the operational engine of the national AML framework by facilitating execution, monitoring and inter-agency coordination.

4. Sub-Committees under NAMLCFTC

  • Supervisory Authorities Sub Committee: it ensures supervision across all regulated sectors.
  • Investigative Authorities Sub Committee: it coordinates law enforcement and prosecution efforts.
  • National Risk Assessment (NRA) Sub Committee: it leads the assessment of national ML/TF risks.
  • Terrorism Financing (TF) Sub Committee: it focuses specifically on terrorism-financing threats, typologies, and mitigation measures.
  • Technical Compliance Sub Committee: it examines the legal and regulatory framework, ensuring alignment with FATF requirements and addressing technical compliance gaps.
  • Companies Registrar Sub Committee: it strengthens corporate transparency by overseeing beneficial ownership frameworks and coordinating the national company registry ecosystem.
  • International Cooperation Sub Committee: it manages the UAE’s engagement with FATF and other international bodies, facilitating cross-border collaboration and information exchange.
  • Public–Private Partnership (PPP) Sub Committee: it supports structured engagement between government and the private sector, encouraging information-sharing, and implements strategies for public-private sector collaboration.

What is NAMLCFTC and Its Mandate in UAE?

The National Anti-Money Laundering and Combating the Financing of Terrorism and Financing of Illegal Organizations Committee (NAMLCFTC) is the UAE’s primary policy-making body for combating money laundering, terrorism financing, and proliferation financing.

Legal Basis: Established under Federal Law No. 4 of 2002 (Articles 9 and 10), with expanded mandate under Federal Decree-Law No. 20 of 2018 and continuing under Federal Decree-Law No. 10 of 2025.

Key Mandates:

  • Develops the national AML/CTF strategy, proposes policies, regulations and procedures in coordination with competent authorities, and monitors their implementation.
  • Assesses and determines national ML/TF risks.
  • Identifies high-risk countries, evaluates jurisdictions with weak AML/CTF controls, determines required countermeasures, and instructs supervisory bodies to enforce enhanced due diligence on FIs, DNFBPs, VASPs and NPOs where needed.
  • Facilitates information-sharing and coordination among all represented government and supervisory entities.
  • Collects and analyses statistics and data from competent authorities to evaluate the effectiveness of AML/CTF measures and regulatory outcomes.
  • Represents the UAE internationally in matters related to AML/CTF.
  • Proposes internal regulations for the functioning of the Committee and submits them to the Minister of Finance.
  • Handles any additional AML/CTF matters referred to it under law or by competent authorities.

Common AML compliance mistakes we see in UAE entities

Even well-intentioned organisations fail AML inspections due to avoidable gaps.

Common issues include:

  1. Weak customer risk assessment methodology with no supporting rationale

  2. Beneficial ownership not verified or evidence not retained

  3. Screening done only at onboarding, not ongoing

  4. STR decisions made informally, with no documented reasoning

  5. No clear audit trail for alerts, investigations, or match clearance

  6. Policies copied from templates that do not match business activities

  7. Inadequate staff training, especially for frontline teams

A good AML programme is not only about having documents. It is about proving implementation through records, controls, and consistency.

Key Takeaways: 5 things regulated entities must do

If your business is regulated in the UAE, your AML/CFT programme should, at a minimum, cover:

  1. Risk Assessment: maintain an Enterprise-Wide Risk Assessment (EWRA) and Customer Risk Assessment (CRA)
  2. Customer Due Diligence (CDD): verify identity, beneficial ownership, and purpose of relationship
  3. Screening: conduct sanctions and terrorism financing screening at onboarding and on an ongoing basis
  4. Monitoring and Reporting: detect suspicious activity and file STRs/SARs via the UAE FIU goAML portal

  5. Governance: appoint an MLRO/Compliance Officer, ensure staff training, record-keeping, and an independent AML audit

UAE AML Regulations: A Core Compliance Checklist

Here is the checklist of the core AML/CFT obligations entrusted upon the DNFBPs by the UAE AML Laws: 

  • Have you registered yourself with goAML Portal? 
  • Do you have a competent AML/CFT Compliance Officer to manage your AML compliance? 
  • Have you identified and assessed your business’s exposure to ML/FT risks? 
  • Are your AML/CFT policies, procedures, and controls effective and aligned with AML/CFT laws and Enterprise Wide Risk Assessment (EWRA)? 
  • Is your Customer Due Diligence process well-defined? 
  • Is your implementation of Targeted Financial Sanctions (TFS) effective? 
  • Have you assessed your customers’ risk, considering relevant ML/FT risk factors? 
  • What Enhanced Due Diligence measures do you apply? 
  • Do you have a set process for identifying and reporting Suspicious Transactions and other relevant reports on the goAML Portal? 
  • Do you retain all your AML/CFT records for at least 5 years? 

Need Help Implementing AML Compliance in the UAE?

Understanding AML laws is important, but implementation is what regulators assess.

If you need professional support with:

You can reach out to AML UAE for practical, regulator-aligned assistance.

Share via :

We help you prepare and implement

a robust Anti-Money Laundering Program.

FAQs About UAE AML Law

What is AML compliance, and why is it important in the UAE?

Anti-Money Laundering (AML) refers to laws and regulations designed to detect, prevent, and report disguising of illicit funds. In the UAE, AML compliance is critical for maintaining financial integrity, national security, and ensuring compliance with international standards set by the FATF.

All the financial institutions, DNFPBs, VASPs, Gaming Operators, Non-Profit Organisations, and other Regulated Entities must follow AML laws in the UAE.

The core framework is built on Federal Decree Law 10 of 2025 and its Executive regulations under Cabinet Decision No. 134 of 2025, supported by regulatory guidance, directives, and circulars issued by supervisory authorities, including those related to reporting obligations, sanctions compliance and other sector-specific requirements.

goAML is the official platform for submitting Suspicious Transaction Reports (STRs), Suspicious Activity Reports (SARs), and other AML filings to the UAE’s FIU.

The registration process involves first registering through the FIU’s SACM system to obtain access credentials, followed by completing the entity profile on the goAML portal and appointing a Compliance Officer. Reporting access is granted only after FIU approval of both steps.

CDD is required at customer onboarding, before establishing a business relationship, when conducting transactions above specified thresholds (e.g., AED 55,000), and whenever suspicion arises, regardless of the amount.

CDD may also be required post-transaction if red flags emerge or inconsistencies are identified after the transaction has taken place.

Non-compliance can lead to financial penalties, license suspension, criminal prosecution, business restrictions, asset freezing and reputational damage.

Criminals often use high-value assets like real estate and luxury goods to launder money. Regulating these sectors ensures that illicit funds cannot be easily integrated into the economy through property or valuable commodities.

Under the Federal decree Law 10 of 2025, it is defined as an act involving the transfer, conversion, or concealment of proceeds from a predicate crime (e.g., fraud, corruption) with the intent to disguise its illicit origin, or assisting another person in doing so.

Supervision and enforcement are led by UAE authorities such as the Central Bank, Ministry of Economy and Tourism, Ministry of Justice, Securities & Commodities Authority, Financial Free Zone Regulators (FSRA and DFSA), Free Zone Regulators, General Commercial Gaming Regulatory Authority, and the UAE FIU.

Banks, exchange houses, investment firms, insurers, VASPs, DPMS, auditors and accountants, lawyers, corporate service providers, real-estate brokers, and gaming operators are subject to AML supervision.

Entities must apply CDD/EDD, conduct ongoing monitoring, screen against sanction lists, maintain records for at least five years, and report suspicious activity through goAML while ensuring strong internal policies and risk-based controls.

The primary legal framework for AML/CFT in the UAE is now governed by Federal Decree Law No. 10 of 2025, which replaces the earlier Federal Decree Law No. 20 of 2018. The implementing regulation is set by Cabinet Decision No. 134 of 2025, which has become effective from 14 December 2025, superseding Cabinet Decision No. 10 of 2019.

Money laundering in the UAE carries severe penalties under Federal Decree-Law No. (10) of 2025:

  • Imprisonment: Up to 10 years (life imprisonment in aggravated cases)
  • Individual fines: AED 100,000 to AED 500,000
  • Corporate fines: Up to AED 100 million
  • Additional consequences: Asset confiscation and potential deportation for non-nationals

The UAE’s AML framework is led by Federal Decree Law No. (10) of 2025, supported by Cabinet Resolution No. (134) of 2025, along with sector-based supervisory guidance and compliance requirements.

Yes. DNFBPs such as jewellery traders, real estate brokers, auditors, accountants, TCSPs, commercial gaming operators, and legal professionals must comply with UAE AML obligations based on their regulated status and activities.

Yes. Entities in DIFC and ADGM are required to follow UAE federal AML laws and may also be subject to additional rulebooks and supervisory expectations issued by DFSA and FSRA.

The UAE AML framework aims to prevent and detect money laundering, terrorism financing, and proliferation financing by enforcing strong customer due diligence, monitoring, and reporting systems.

goAML is the UAE FIU’s reporting portal where regulated entities submit suspicious transaction reports and maintain reporting compliance. It plays a central role in enforcement readiness and regulatory supervision.

Penalties may include financial fines, restrictions, licence actions, and regulatory enforcement measures depending on severity, control gaps, and repeat findings.

Common documents include:

  • AML/CFT policy and procedures

  • EWRA and CRA evidence

  • KYC records and risk classification

  • Screening results and clearance rationale

  • Alert investigations and STR documentation

  • Training records and audit reports

Share via :

About the Author

Pathik Shah

FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)

Pathik is an ACAMS-certified AML consultant specialising in governance, risk, and compliance for regulated entities in the UAE. He brings over 28 years of experience, with 1,000+ hours of AML training and 200+ advisory engagements across DNFBPs, VASPs, and FIs. He supports businesses in aligning with AML/CFT requirements from the CBUAE, DFSA, MoET, MoJ, VARA, CMA, FSRA, and FATF. Known for translating complex regulations into audit-ready procedures, Pathik enables operational clarity and compliance readiness.

Reach Out to Pathik

What should the MLRO report contain?

Blogs

Published On: 03/03/2022

Table of Contents

Protect your business with reliable and effective AML strategies with AML UAE.

Last Reviewed On: 07/20/2026   |   Last Updated On: 07/20/2026

Business People Meeting Design Ideas professional investor working new start up project. Concept. business planning in office.

What should the MLRO report contain?

The AML compliance officer plays a pivotal role in assisting businesses in being AML compliant. The Money Laundering Reporting Officer (MLRO) has to submit MLRO report semi-annually and is a crucial element in the AML compliance process, ensuring that the companies adhere to the Anti-Money Laundering and Combatting Financing of Terrorism (AML-CFT) requirements. The MLRO report facilitates the desk-based supervision of companies understanding their AML compliance structure and knowing whether they are continuously complying with the AML laws

Mandatory submission of the MLRO report

Cabinet Resolution No. 134 of 2025 states that the MLRO reports should be submitted twice a year to the senior management. A copy of the MLRO report is sent to the concerned supervisory authority. The officer will review all the internal policies and procedures to ensure adherence to the AML rules and regulations. The officer evaluates the efficiency of the companies in AML compliance and the extent to which they are following the procedures. The MLRO also guides the companies to sync with the AML policies and strengthen the AML compliance program.

Contents of the MLRO's Report

The compliance officer should highlight the glaring gap between the current and existing AML laws compliance requirements. The report should focus on the required remedial measures that the company must follow to be AML compliant.

Essential Elements in the MLRO report

Review of the size and the quality of the Suspicious Activity Reports (SAR) submitted by the employees and the number of SARs submitted. The MLRO report should mention the number of clients rejected due to the absence or insufficient information.

The existing AML –CFT training components- the number of courses and the AML training imparted to the employees and any issues concerning the AML training. The evidence of the training imparted and the company’s competence in adhering to the AML/ CFT laws should be part of the MLRO report

  • The report should also mention if the company needs any resources to stay AML/ CFT compliant. 
  • Mention the sample review of the Customer Due Diligence (CDD) file ensuring the information is updated and holds relevance. 
  • Verify the risk ratings and relevance and updation of the risk assessment report.
  • Evaluating the company’s relevance of the AML compliance process- AML/ CFT policies, procedures, and documentation.

Controls to be Highlighted in the MLRO Report

The MLRO will check the following compliances.

Key focus areas in the MLRO's report

The MLRO report should focus on the AML/ CFT process compliance. The report should confirm that the company has utilized and applied the general risk assessment results. The report should include the corrective measures that correspond to the inadequacies of the existing AML/ CFT compliance program.

 

The recommendations should guide the company to improve the AML/ CFT compliance program and help them achieve 100% AML compliance. A deadline has to be provided, and the AML compliance recommendations, as mentioned in the MLRO report, should be followed. The companies should be monitored as to whether they follow the rules and adhere to the deadline. 

Submission of the MLRO Report

Banks, insurance companies, etc., must submit the MLRO report to the Central Bank of UAE (CBUAE). The DNFBPs – Designated Non-Financial Businesses and Professions (DNFBPs must submit the MLRO report to the Ministry of Economy (MoE). 

Regulated entities that have mandatory compliance with the AML/ CT laws need to follow the AML compliance process diligently. Appointment of an MLRO and submission of report is compulsory. The MLRO report should let the authorities know the shortcomings of the AML/ CFT program of the company. It should also highlight the inefficiency in the AML training, which makes the AML compliance program weak and ineffective.

Businesses should hire an AML consultant with their core expertise in AML services. The consultant will provide the correct guidance in preparing robust AML training for your employees, help in selecting the right AML software, and assist in the appointment of an MLRO.

Conclusion

AML UAE has a vast team of professionals with core expertise in In-house AML compliance and allied services. Get access to various services such as AML/ CFT Policy Controls and Procedures Documentation, in-house AML compliance department set up, AML software selection, Annual AML/ CFT Risk Assessment Report. It also provides AML training services and AML/ CFT Health checks. Mitigate risks and stay AML compliant by following the process carefully. 

FAQs - Essential Elements in the MLRO report

What is the role of the MLRO? 

The responsibilities of MLRO are: 

  • Ensure compliance of daily operations with the company’s AML policies 
  • Be the point of communication between the company and its employees as well as the company and federal authority 
  • Make suspicious transaction reports 
  • Acting in compliance with UAE’s guidelines, notifications, rules, and regulations 
  • Respond if the concerned authority requests any document  

MLRO means Money Laundering Reporting Officer in AML.  

The MLRO must submit the MLRO report to the senior management of the company. They must forward a copy to the Central Bank of UAE (CBUAE) in the case of financial institutions and the Ministry of Economy (MOE) in the case of DNFBPs. 

Add a comment

Share via :

About the Author

Pathik Shah

FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)

Pathik is an ACAMS-certified AML consultant specialising in governance, risk, and compliance for regulated entities in the UAE. He brings over 28 years of experience, with 1,000+ hours of AML training and 200+ advisory engagements across DNFBPs, VASPs, and FIs. He supports businesses in aligning with AML/CFT requirements from the CBUAE, DFSA, MoET, MoJ, VARA, CMA, FSRA, and FATF. Known for translating complex regulations into audit-ready procedures, Pathik enables operational clarity and compliance readiness.

Reach Out to Pathik

A comprehensive AML Guide for ADGM companies 

A comprehensive AML Guide for ADGM companies 

Blogs

Published On: 04/19/2023

Table of Contents

Protect your business with reliable and effective AML strategies with AML UAE.

Last Reviewed On: 07/20/2026   |   Last Updated On: 07/20/2026

A comprehensive AML Guide for ADGM companies 

The Financial Services Regulatory Authority (FSRA) supervises Abu Dhabi Global Market (ADGM) entities. 

FSRA has issued rules and guidelines for implementing AML and Sanctions by ADGM entities to mitigate financial crimes. Though the ADGM’s AML Rulebook considers the Federal AML rules, the regulated entities in ADGM must follow the Rulebook and the Federal AML Law requirements 

This article focuses on the critical AML compliance requirements of entities in ADGM.  

Business Risk Assessment and AML Policies, Procedures and Controls

The FSRA-issued AML rulebook mandates the ADGM entities to assess the ML/FT risks their business is exposed to.  

While conducting AML business risk assessment, the ADGM entities must identify and analyze the ML/FT risk associated with the below-mentioned risks parameters: 

  • Customers  
  • Products, services, and transactions  
  • Geographic risk  
  • Distribution channels 
  • Other risk factors such as technology 
How to conduct AML Business Risk Assessment Priv

Basis the results of the AML Business Risk Assessment, adopting the risk-based approach, the entities must establish AML controls, procedures, policies, and systems aligned with the AML regulations to help entities identify, manage, and mitigate the ML/FT risks.  

To ensure the effectiveness of the ML/FT mitigation measures, it is important to review ML/FT risk factors impacting the business and update the assessment to identify any new risk scenarios and design relevant controls to manage the increased level of risks.  

Customer Risk Assessment and Customer Due Diligence

The entities must assess the customers’ profile, transactions, and business relationships to identify the ML/FT risk such customers pose to the business. Considering various risk parameters, a risk rating should be assigned to the customer, and appropriate Customer Due Diligence measures should be applied before establishing a business relationship. 

For performing Customer Risk Assessment, the entities must consider various factors associated with the customer, a few of them illustrated hereunder: 

  • Ownership, control structure, and nature of customer 
  • Nature of the customer’s business 
  • Nature and purpose of the business relationship  
  • Nationality and residence of the customer 
  • Place of incorporation of the customer who is a legal person. 
Key factors for Customer Risk Assessment under AML regulations

Based on these factors, the risk rating is allocated to each customer – high, medium, or low. For low-risk customers, entities may conduct Simplified or Standard Due Diligence. While for customers identified as high-risk, Enhanced Due Diligence measures must be applied.  

Enhanced Due Diligence measures under UAE AML Regulations

Depending on the risk profiling or risk classification of the customer, the ADGM entities must carry out Customer Due Diligence under the following circumstances: 

  • Before onboarding a customer or establishing a business relationship 
  • Before executing a transaction with an occasional customer for an amount equal to or more than US$15,000 
  • When the customer or transaction is suspected to be related to money laundering or financing of terrorism. 
  • When there is doubt about the authenticity of documents provided by the customers 

As part of the Customer Due Diligence process, the ADGM entities must undertake the following: 

  • Identify the customers, their representatives, and beneficial owners and verify their identities, 
  • Screen the customer, beneficial owners, and senior managerial persons to check if any of these persons are sanctioned under the UAE local list, UNSC Consolidated List or any other relevant international sanctions list, 
Sanctions Screening - Actionable and Reporting under AML UAE
  • Understand the nature and purpose of the business relationship, 
  • Have systems and controls in place to determine whether the customer, beneficial owners, or senior managerial person is a Politically Exposed Person (PEP), 
  • Conduct ongoing monitoring of the business relationships and transactions conducted with the customer to check their consistency with the customer’s business and risk rating 
PEP and PEP Screening under UAE AML Regulations pre

However, when a customer is assigned a high-risk rating, Enhanced Due Diligence (EDD) measures must be applied before establishing a business relationship or executing a transaction with such a customer. Here, the EDD measures would include the following: 

  • Get more information to identify the customer and its beneficial owners,  
  • Identify and verify the source of wealth and funds of the customer and its beneficial owners, 
  • Establishing reasonableness of the purpose of the business relationship, 
  • Seek senior management’s approval to start a business relationship with a high-risk customer, 
  • Insist on getting the first payment through the customer’s account with the bank subject to similar AML standards,  
  • More frequent monitoring of the customer’s profile and transactions. 
A comprehensive AML Guide for ADGM companies 

Money Laundering Reporting Officer (MLRO)

Every ADGM entity must appoint an MLRO to ensure compliance with AML requirements as prescribed under the FSRA-issued AML Rulebook and the AML Federal laws. Such MLROs must be residents of the UAE. 

Further, the FSRA must approve the appointment of the MLRO. 

If an MLRO leaves the company immediately, a new MLRO must be appointed, or at least a Deputy MLRO must be appointed to manage the AML compliance function temporarily until the appointment of an MLRO. FSRA Rulebook allows the ADGM entities to outsource the MLRO position to a third party.  

AML Training and Awareness 

FSRA mandates entities to conduct regular training for its employees responsible for AML compliance. Such training and AML awareness sessions must customize be customized basis the entities’ business operations, products/services, transaction complexities, distribution channels, and customers.  

ADGM entities must conduct such AML training at least once a year and keep it up-to-date. Further, it is mandatory to record details of such training programs, including their dates, duration, nature, and list of participants.  

Designing a comprehensive AML Training Program

Reporting Suspicious Activities  

Every ADGM entity must have procedures, controls, policies, and systems to detect suspicious activities and report them immediately to the Financial Intelligence Unit (FIU) by filing SAR/STR on the goAML portal 

Frontline employees observing the suspicion must report it to the entity’s MLRO and submit all the details about the activity, customer or transaction involving money laundering or terrorist financing activity. When the MLRO receives an internal STR/SAR from an employee, they must investigate the activity. MLRO must submit an external STR/SAR with the FIU based on the evidence collected. 

ADGM entities must maintain a list of ML/FT risk indicators and keep reviewing and updating this list to identify and mitigate the risks effectively. 

AML Record Keeping  

ADGM entities must maintain AML-related records for a minimum period of six (6) years in electronic format. The records to be maintained include the following: 

  • Entities’ AML Business Risk Assessment and the AML framework implemented 
  • Documents and information received from customers during KYC and CDD 
  • Copies of business correspondence with customers, including transactional details 
  • Suspicious activity/transactions reports – internal and external, related investigation records, documents, etc. 
  • Records of communication and correspondence with the FIU 
AML Record Keeping

AML Annual Return

ADGM entities must fill in all the details in the AML Return Form and submit such AML Annual Return with the FSRA for the year starting from 1st January to 31st December every year. Such AML Annual Return is to be furnished with the authorities before the end of April of the following year. 

The key differences between Federal AML Law and the FSRA-issued ADGM AML Rules and Guidance

(a) FSRA AML Rulebook includes the following under the definition of the “Designated Non-Financial Businesses and Professions (DNFBPs), which is not the case under Federal AML Laws:  

  • Dealer engaged in trading of any saleable item where the transaction amount equals to or exceeds US$ 15,000 in cash through a single transaction or series of connected transactions.
  • Tax Consulting Firm

(b) FSRA-regulated entities must appoint a Compliance Officer or Money Laundering Reporting Officer who is a resident of the UAE. No such specific condition around residency is mentioned in the Federal AML Law.  

(c) The minimum period prescribed for maintaining the AML record is six (6) years for ADGM entities, as compared to five (5) years prescribed under the Federal AML Laws.  

(d) AML Annual Return is to be filed by the ADGM entities every year for the period 1st January to 31st December by the end of April of the following year. The AML Annual Return requirement is in addition to the semi-annual report requirement mentioned under Cabinet Resolution No. 134 of 2025.

Need expert assistance to comply with ADGM’s AML Rulebook? 

The companies in ADGM must follow all these requirements as per the ADGM AML Rulebook. Any non-compliance with these requirements calls for heavy administrative fines. The best way to avoid these fines and penalties is to take the help of a professional AML consultant.  

AML UAE is a leading AML consultant in the UAE. Our comprehensive services help you comply with the relevant AML/CFT requirements and mitigate the threats of money laundering and terrorism financing. 

We understand Federal AML laws and ADGM-specific rules to help clients identify and assess their business risk and develop solid and comprehensive AML/CFT policies, procedures, and controls. We can help you set up your in-house AML compliance department and impart AML training to your team, to manage ML/FT compliance competently. 

Our strength lies in our solid team of ADGM compliance specialists and experienced and knowledgeable AML professionals. So, leave your AML compliance worries to us, and focus on your core business operations.  

Avail comprehensive, expert, and efficient services for AML compliance matters

Contact our team at AML UAE.

Share via :

About the Author

Dipali Vora

CAMS, ACS

Dipali is an Associate member of ICSI and a Certified Anti-Money Laundering Specialist (CAMS). She has an overall experience of 8 years in the compliance domain, including Anti-Money Laundering, due diligence, secretarial audit, and managing scrutiniser functions. She currently assists clients by advising and helping them navigate through all the legal and regulatory challenges of Anti-Money Laundering Law. She helps companies to develop, implement, and maintain effective AML/CFT and sanctions programs.

Reach Out to Dipali

TFS Implementation Criteria: Ownership, Control, and Acting on behalf of a Designated Person

TFS Implementation Criteria Ownership, Control, and Acting on behalf of a Designated Person

Blogs

Published On: 02/27/2023

Table of Contents

Protect your business with reliable and effective AML strategies with AML UAE.

Last Reviewed On: 07/20/2026   |   Last Updated On: 07/20/2026

TFS Implementation Criteria

Targeted Financial Sanctions are restrictions imposed on Designated Persons from the financing of terrorism and proliferation perspective, mandating the business organizations not to make any funds or assets available to such Designated Persons.

Targeted Financial Sanctions Legal Framework in UAE:

Article 19(e) of Federal Decree Law 10 of 2025 requires the prompt application of the directives issued by the UAE’s executive officer or other competent authorities for implementing the decisions of the UN Security Council under Chapter (7) of UN Convention for the Prevention and Suppression of the Financing of Terrorism and Proliferation of Weapons of Mass Destruction, and other related directives.

UAE Cabinet Decision No. 74 of 2020 establishes the framework regarding Targeted Financial Sanctions (TFS), including the Local Terrorist List and the UN Consolidated List and the procedures to implement TFS.

Any non-compliance with the obligations of Cabinet Decision No. 74 of 2020 or failure to implement procedures to ensure compliance may result in imprisonment for a minimum period of 1 year, up to 7 years, and/or a fine ranging between AED 50,000 and AED 5,000,000. Further, the Supervisory Authorities may impose any other appropriate administrative sanctions, such as issuing a warning letter or canceling the business license for any violation or shortcoming in implementing TFS obligations.

TFS Implementation Criteria 1: Ownership or Majority Interest

While implementing TFS with respect to designated individuals and entities listed on the UAE Local Terrorist List issued by the UAE Cabinet (in line with UNSC 1373) and on the UNSC Consolidated List issued by the United Nations Security Council, it is essential to take into account the following criteria viz., ownership, control and acting on behalf of a Designated Person.

TFS must be implemented on a legal entity if a Designated Person (natural or legal) owns the entity. Suppose the designated individual or entity owns more than 50% of the proprietary rights or has a controlling interest in the entity. In that case, such an entity is considered owned by the Designated Person and is subject to a freezing mechanism.

TFS Implementation Criteria

Since the Designated Individual/Entity owns more than 51% of the non-designated Company A, the funds or other assets of Company A must be frozen immediately.

Since Entity 1 and Person 1 own 24% and 25% shares of Company A, they will not be treated as designated persons, and the freezing mechanism will not be applied to them.

If the Designated Person holds 50% or less of the proprietary rights of a non-designated entity, such an entity is not subjected to the freezing mechanism.

Any funds or other assets due to the designated person’s 31% ownership of proprietary rights in Company A must be subject to a freezing mechanism.

The reporting entities must remain vigilant on the changes in the ownership structures of non-designated entities where the designated person holds 50% or less of the proprietary rights.

TFS implementation Criteria 2: Control

Suppose the Designated Person has control over the non-designated entity despite having a minority interest in such entity. In that case, Financial Institutions (FIs), Virtual Asset Service Providers (VASPs), and Designated Non-Financial Businesses and Professions (DNFBPs) are required to apply freezing measures.

To determine whether the designated person exerts control over the non-designated entity, the following criteria need to be taken into account:

  1. Check if the Designated Person has the right to appoint or remove a majority of the members of the legal entity’s management,
  2. Check if the Designated Person is appointed solely as a result of the exercise of his voting rights as a majority of the members of the management body of a legal person who has held office during the present and previous financial year,
  3. Check if the Designated Person is, alone, controlling the majority of shareholders’ or members’ voting rights in the legal person, pursuant to an agreement with other shareholders in or members of a legal person,
  4. Check if the Designated Person has the right to exercise a dominant influence over a legal person, pursuant to an agreement entered into with that legal person or to a provision in its Memorandum or Articles of Association, where the law governing that legal person permits its being subject to such agreement or provision,
  5. Check if the Designated Person has the power to exert the right to exercise a dominant influence referred to in point (d) without being the holder of that right,
  6. Check if the Designated Person has the right to use all or part of the assets of that legal person, e.g., managing the business of that legal person on a unified basis while publishing consolidated accounts,
  7. Check if the Designated Person shares jointly and severally the financial liabilities of a legal person or guarantees them,
  8. Check if the Designated Person has a power of attorney or authorized signatory arrangement over a legal person.

In the above scenario, despite holding the minority interest in the non-designated Company A, the freezing measures must be applied without delay as the Designated Individual/Entity exerts control over Company A by holding the majority of the voting rights.

TFS implementation Criteria 3: Acting on behalf or at the Direction of the Designated Person

FIs, DNFBPs, and VASPs must apply TFS measures on individuals and entities holding power of attorney or acting as authorized signatories for designated persons.

In the above scenario, the Designated Person exerts control over Company A through a Power of Attorney issued in favor of a Non-Designated Person. Hence the funds and other assets of Company A must be frozen without any delay as it would be treated as being controlled by the Designated Person via Power of Attorney.

About AML UAE

AML UAE is an AML consulting firm assisting FIs, VASPs, and DNFBPs in complying with the AML Laws in UAE. Be it goAML registration, AML/CFT Program design and implementation, AML training, or TFS implementation, AML UAE is your one-stop solution for all your compliance worries. With AML UAE, ensure a robust TFS framework and fight the financing of terrorism and proliferation.

Avail comprehensive, expert, and efficient services
for AML compliance matters

Contact our team at AML UAE.

Share via :

About the Author

Jyoti Maheshwari

CAMS, ACA

Jyoti has over 11 years of hands-on experience in regulatory compliance, policymaking, risk management, technology consultancy, and implementation. She holds vast experience with Anti-Money Laundering rules and regulations and helps companies deploy adequate mitigation measures and comply with legal requirements. Jyoti has been instrumental in optimizing business processes, documenting business requirements, preparing FRD, BRD, and SRS, and implementing IT solutions.

Reach Out to Jyoti

Role of an Auditor Under UAE AML Compliance

Blogs

Published On: 03/15/2022

Table of Contents

Protect your business with reliable and effective AML strategies with AML UAE.

Last Reviewed On: 07/17/2026   |   Last Updated On: 07/17/2026

Auditor or internal revenue service staff, Business women checking annual financial statements of company. Audit Concept.

Role of an Auditor Under UAE AML Compliance

The UAE has implemented anti-money laundering laws and ensures strict compliance to help fight this rampant financial crime. The objective of the AML laws is to get rid of money laundering and prevent large-scale funding of criminal and terrorist financing. Banks, financial institutions, DNFBPs – Designated Non- Financial Businesses & Professions, and other regulated entities must follow the AML rules. The role of an auditor under UAE AML Compliance is massive. The auditors act as guardians who ensure that the organizations adhere to the compliance rules and do not leave any scope of non-compliance.

DNFBPs subject to AML Compliance in the UAE

The AML law was implemented by Cabinet Resolution No. 134 of 2025, Federal Decree-Law No. 10 of 2025. It strengthens the AML compliance network and has strengthened UAE’s AML/CFT legal and institutional framework per the FATF recommendations

The auditors analyse the nature of the business and their obligations in the context of the UAE Anti-Money Laundering Laws. Every business is unique, so they examine the accounts, documents, control policies to identify suspicious transactions and doubtful accounts with great vigilance. 

What is the role of an auditor under UAE AML Compliance?

There are several duties of an auditor that are performed to prevent money laundering, which has serious financial repercussions on the country’s economic structure and the world economy at large. The duties of an auditor can be defined as follows:

  • Examination of annual records and accounts.
  • Analyse the internal control procedures.
  • Identifying any suspicious transaction and taking the appropriate action to prevent money laundering. 
  • Assessment of money laundering risk and evaluating transactions to detect financial terrorism.
  • Compliance- to check whether the institution complies with rules and regulations laid down by the authorities. 
  • Prevent the clients from AML violation risks by evaluating risks on two parameters-
Difference between suspicious activity and suspicious transaction

(a) Assessment of own risk regarding the nature and type of the business.
(b) Obligation of risk assessment when appointed to carry out the auditing duties.

Auditors perform various duties such as conducting the valuation of the assets and liabilities, approving bad debts, etc. They receive compensation for their duties, and they need to consider other risks that involve service risks, customer risks, location risks, etc.

Businessperson refusing bribe given money by partner with anti bribery corruption concept.

Critical factors for consideration include:

  • Nature and the type of business.
  • Nature and volume of the financial transactions. Country’s origin of the interested or associated parties and determine whether they belong to a high-risk country
  • Communication channels with which clients are introduced. 

Auditors provide their valuable opinion on the transactions that might be associated with money laundering. They will provide their expert opinion on the valuation of the assets and liabilities, approval of mergers and acquisitions or approval of writing off bad debts, etc. The auditors review the internal policies, procedures, and controls. They provide their expertise in appointment compliance officers and ensure that the company adheres to rules and regulations and prevents violation of AML laws. They check the background verification system of CDD using different methods based on the business type, nature, and size. 

Carry out the CDD process

Auditors conduct the Customer Diligence process and follow a strict risk assessment process to evaluate the risk of the company’s AML compliance and those of its clients. The auditors use various resources and ensure that the company they associate with has a clean record. They need to be unbiased in their observation and documentation process to have a clear picture of customer due diligence.

Identifying suspicious transactions and reporting the same to the respective authorities.

Auditors need to keep a vigilant eye on the transactions of the clients. If they find any transaction suspicious and have a reasonable ground for doing so, they have to report the case to the Financial Intelligence Unit using the goAML Portal.

How can AML UAE assist you?

AML UAE is one of the most reputed AML consultants serving thousands of businesses in the UAE and offering robust support in AML compliance. Our panel consists of AML compliance consultants with in-depth knowledge of the UAE AML rules and regulations. Get a risk-based approach for annual AML report filing services. We assist DNFBPs in complying with the AML requirements. To obtain further detailed information about this reputed consultant, feel free to visit AML UAE.

FAQs on Role of an Auditor

What are the duties and responsibilities of an auditor? 

The auditor must perform the following duties under AML Law: 

  • Examine and evaluate AML policy, controls, and procedures to ensure compliance with the law. 
  • Make necessary recommendations in relation to AML policy, controls, and procedures. 
  • Check if those recommendations have been taken into consideration by the management and complied with. 

Add a comment

Share via :

About the Author

Pathik Shah

FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)

Pathik is an ACAMS-certified AML consultant specialising in governance, risk, and compliance for regulated entities in the UAE. He brings over 28 years of experience, with 1,000+ hours of AML training and 200+ advisory engagements across DNFBPs, VASPs, and FIs. He supports businesses in aligning with AML/CFT requirements from the CBUAE, DFSA, MoET, MoJ, VARA, CMA, FSRA, and FATF. Known for translating complex regulations into audit-ready procedures, Pathik enables operational clarity and compliance readiness.

Reach Out to Pathik

How can UAE businesses be AML Compliant?

Blogs

Published On: 02/22/2022

Table of Contents

Last Reviewed On: 07/17/2026   |   Last Updated On: 07/17/2026

MicrosoftTeams-image (5)

How can UAE businesses be AML Compliant?

It is obligatory for banks, financial institutions, and other regulated entities to follow the AML rules and regulations or face penalties. UAE has imposed hefty fines for violation of AML rules and regulations. Administrative fines range from AED 10,000 to AED 5,000,000 per violation (Article 17, Federal Decree-Law No. 10 of 2025; schedule Article 39).  By not being AML compliant, businesses put their reputation at stake and face the government’s ire. So, they need to ensure that they diligently follow the AML rules and make their business AML compliant.

The UAE Ministry of Economy has defined 26 categories of fines for non-compliance with the AML rules and regulations. It’s essential to mitigate the risks involved in non-compliance. AML consultants prove to be of great assistance to be AML compliant.  

With the aid of technology, businesses in UAE and worldwide can harness its power and streamline the AML compliance process. The AML software is a great tool to facilitate the AML process.

Designing a comprehensive AML Training Program

AML software plays a crucial role in being AML compliant

Optimizing the AML compliance program is of paramount importance to ensure that it is efficient, cost-effective, and scalable. It is critical to keep pace with the changing AML rules and leave no scope of non-compliance. The risk profile may also change over a period. So the business needs to ensure that their system is updated and equipped with the knowledge of the latest amendments to comply with the AML rules effectively

There are various aspects to look for following the AML rules and regulations. A business has to create a robust AML/ CFT program, provide AML training to its employees, follow the proper procedure for AML policy, rules and documentation. It also includes the selection of the right AML software.

The AML software will help the business incorporate all these elements into the AML compliance program and avoid any risk of non-compliance. The AML software will enable companies to immediately identify suspicious transactions and strengthen the AML compliance strategy.

The software collects and stores customers’ KYC data and verifies it. It also verifies the customers’ risk and screens against a sanction list. It will provide information about PEPs and enable businesses to be sure about whom they’re entering into a business relationship. The software alerts them on any suspicious transaction or account and provides real-time updates to take the necessary action to prevent money laundering. 

Role of AML Consultants

Businesses are occupied with running their businesses efficiently, providing high customer satisfaction, enhanced customer experience, promoting growth, and maximising profitability. Dealing with the complex AML compliance process can take a back seat in a competitive marketplace.

Businesses are at risk of non-compliance, so following the AML/ CFT Policy, Controls, and Documentation procedure is necessary. With the help of reliable AML consultants, companies can get the proper rules, policies, and systems in place and create a strong AML compliance framework that will help them fight money laundering successfully.

Consequences for Non-compliance with UAE AML Regulations

It is an elaborate process that involves risk identification by analysing the business process and identifying the risk which money launderers will take advantage of and be successful in their criminal intentions. Companies can immediately identify the illegal movement of money. The consultants will also examine the existing AML policies, letting the business know if their current AML compliance procedure is competent enough to keep money launderers at bay.

The gap analysis will clarify the appropriate actions that need to be taken to achieve AML compliance for the business.

The gap analysis report is shared with the AML compliance officer and the stakeholders. After the discussion, the consultants create the best AML/ CFT program.

A customized AML program is required to combat the challenges of the non-compliance risk and fight money laundering. The AML policy, controls, and procedures are created, eliminating or minimising the risk of non-compliance, and businesses can focus on improving customer growth. 

Building an effective AML compliance process

The FATF –Financial Task Force has provided several recommendations for AML rules and regulations that define the AML compliance process. The FATF was founded in 1989 to fight money laundering and terrorist financing. It also aims to prevent the funding of accumulation and expanding weapons of mass destruction. FATF has provided some standard recommendations on the global level which countries can follow to fight the menace of money laundering

In 2020 the Minister of Justice had issued ministerial resolutions for setting up specialised courts for dealing with money laundering cases.

AML Compliance Requirements

This resolution was meant for the judiciary in the courts of Sharjah, Umm AI Quwain and Ajman, and Fujairah. It is noteworthy that each country has particular AML compliance requirements that businesses must follow.

It is crucial to have a robust AML compliance program that will meet all the needs and prevent the risk of non-compliance. Organisations can efficiently fulfil the requirements of AML compliance, avoid penalties, guard their reputation by not associating with suspicious activities or entities, and help the government achieve the goal of preventing money laundering.

UAE has issued the Federal Decree-Law No. 10 of 2025 on the Anti-Money Laundering and Countering the Financing of Terrorism which defines the legal structure to ensure AML compliance with the international standards.

The law aims to prevent money-laundering practices and create a legal framework that assists authorities in ensuring AML compliance and arresting the criminals involved in money laundering. The law aims to counter the financing of terrorist activities and suspicious entities

AML Software

Standardising the AML program is necessary. An AML software will help to fulfil this objective. A reliable AML service provider will assist in selecting the proper AML software. 

It is vital to empower the AML compliance team with the right resources and transparent policies to adhere to without any confusion. 

How to get an effective AML compliance program?

The intricacies involved in the AML compliance program might prove overwhelming for businesses already occupied with keeping the company afloat, providing high customer satisfaction. The complex legislation might prove daunting for companies, so it would be best to hire an AML consultant to create an effective AML compliance program.

So how an AML compliance service provider will help in this arena? They will assist in setting up an AML compliance department and help businesses always stay AML compliant with their services. 

As business owners in the UAE, people need to invest time and energy in the research to follow the AML / CFT policy,  rules,  and documentation process or set up an  In-house AML compliance department. It is compulsory for banks, financial institutions, and other regulated entities to integrate an AML compliance framework into the company. It is best to create an in-house AML compliance department.

In addition to this, an AML compliance officer has to be appointed who will manage the AML compliance process. The AML consultants play a huge role in helping businesses be AML compliant. 

Conclusion

AML UAE is one of the most reliable AML compliance in the UAE, providing services to thousands of businesses and helping in AML risk assessment and mitigation. AML compliance is an absolute necessity. Organisations need to follow the AML rules and regulations to protect their business against financial crime and assist the government in preventing money laundering and funding criminal and terrorist activities. With our array of AML compliance services such as AML/ CFT Policy, Controls, Procedures & Documentation, and in-house AML compliance Department set up, AML trainingAnnual AML/ CFT Risk Assessment reportand AML/ CFT health checkup ; businesses can get complete peace of mind as they can stay AML compliant at all times.

FAQs

Who is responsible for compliance with AML? 

The following businesses must comply with AML: 

  • Banks 
  • Financial institutions 
  • Real estate agents 
  • Dealers in precious metals and gems 
  • Trust and company service providers 
  • Lawyers, notaries, and other legal professionals 
  • Accountants and auditors 

If the employee is compliant with AML regulations, identifying suspicious transactions and carrying out risk assessments would be easier. Also, employees would carry out activities in alignment with internal AML policies, procedures, and controls, and conduct due diligence of customers before onboarding them.  

For everyday AML compliance, an employee’s responsibilities are: 

  • To check daily activities for any suspicion of money laundering or any other financial crime 
  • To ensure KYC and CDD of customers are conducted 
  • To raise complaints if any doubt is raised 
  • To comply with the AML policies, processes, and internal controls implemented in the company 

A company can be tested for AML compliance in the following ways: 

  • Implementation of risk-based AML measures 
  • Identity verification of customers through CDD and EDD measures 
  • Checking customers against Sanctions screening and PEP status 
  • Identifying suspicious transactions and submitting reports 
  • Forming AML team, appointing AML Compliance Officer, and conducting AML training 

Share via :

About the Author

Pathik Shah

FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)

Pathik is an ACAMS-certified AML consultant specialising in governance, risk, and compliance for regulated entities in the UAE. He brings over 28 years of experience, with 1,000+ hours of AML training and 200+ advisory engagements across DNFBPs, VASPs, and FIs. He supports businesses in aligning with AML/CFT requirements from the CBUAE, DFSA, MoET, MoJ, VARA, CMA, FSRA, and FATF. Known for translating complex regulations into audit-ready procedures, Pathik enables operational clarity and compliance readiness.

Reach Out to Pathik