A guide To establishing an Effective AML/CFT Framework in your business

Regulatory Obligations and AML-CFT Framework

A Guide to Establishing an Effective AML/CFT Framework in Your Business

Published On: 05/02/2024

Table of Contents

Protect your business with reliable and effective AML strategies with AML UAE.

Last Reviewed On: 07/17/2026   |   Last Updated On: 07/17/2026

A Guide to Establishing an Effective AML/CFT Framework in Your Business

Financial Institutions and Designated Non-Financial Businesses and Professions that do not abide by the Money-Laundering laws or regulations have to pay heavy penalties and face severe reputational losses. Therefore, every business has to establish an effective AML/CFT framework to operate as per the legal requirements of the country.

So, the question arises: what should you consider when managing AML/CFT compliance in your business? This article provides the best practices for establishing an effective AML/CFT framework in your business.

Compliance. Trust. Transparency

Customized and cost-effective AML compliance services to support your business always

What is an Anti-Money Laundering Framework?

Implementing elements of the Anti-money laundering (AML) framework using a risk-based approach is crucial for preventing money laundering, financing terrorism, and proliferation financing (ML/FT and PF). The AML framework is a set of policies, procedures and controls that are formed to detect, deter, and report ML/FT and PF activities.

The AML framework lays down a structured strategy that aims to fulfil regulatory obligations and achieve mitigation of ML/FT and PF risks.

Importance of an Anti-Money Laundering Framework

The following is a list of factors stating why the AML framework is essential:

Ensure regulatory compliance:

DNFBPs are required to comply with different AML regulations, including regulations imposed by national and international regulators. In case it fails to comply with such regulatory requirements, penalties and fees are imposed on DNFBPs. Therefore, with the implementation of an effective AML framework, they can ensure compliance with these regulations and stay away from associated penalties and fines.

Risk mitigation:

The major threat to DNFBPs is using their platforms to facilitate financial risks. Criminals often use them to indulge in criminal activities because of inherent vulnerabilities. The AML framework employs measures that help DNFBPs in detecting ML/FT and PF activities and further aid in combating ML/FT and PF risks.

Protect business’s reputation:

As DNFBPs work in a highly competitive market, it is essential for them to maintain a good reputation to attract and retain clients and customers. Commitment to AML compliance can act as a deciding factor for clients to enter into a business relationship with the DNFBP. Any linkage to ML/FT and PF activities can damage its reputation, which results in client and business loss. The AML framework helps DNFBPs avoid risk and maintain their reputation by laying down the best strategy within its framework.

Maintain the integrity of the financial system:

By promoting stability, preventing illicit activities, risk management, and regulatory compliance, the AML framework helps maintain the integrity of the financial system. With such measures, the AML framework enables a safe, secure and strong global economy.

Regulatory requirements around AML/CFT framework

AML regulatory framework in the UAE includes national regulations, international regulatory framework and national AML strategy.

National Regulatory Framework

The national regulatory structure in the UAE contains federal civil, commercial and criminal regulations. Because criminal legislation comes under federal jurisdiction throughout the country, the ML/FT and PF criminal activities are covered under it. The following are such regulations within the country:

  • Federal Decree-Law No. 10 of 2025 on Anti-Money Laundering and Combating the Financing of Terrorism and Illegal Organisations.
  • Cabinet Resolution No. 134 of 2025 Concerning the Implementing Regulation of Federal Law No. 10 of 2025.
  • Cabinet UBO Resolution No. 58 of 2020 on the Regulation of the Procedures of the Real Beneficiary (UBO Resolution)

International regulatory framework

The AML framework in the UAE is aligned with the international bodies network, which implements international treaties and conventions for combating illicit crimes. These integrated laws are supervised by the regional regulatory authorities.

For such an integrated framework, the government and competent authorities in the UAE collaborated with various international bodies such as:

  • United Nations
  • Financial Action Task Force (FATF)
  • Middle East and North Africa Financial Action Task Force (MENAFATF)
  • Egmont Group of Financial Intelligence Units

National AML Strategy

The UAE government has implemented strategic decisions in the form of the National Strategy on Anti-Money Laundering and Countering the Financing of Terrorism. The strategy shapes the key initiative of the country’s national action plan. This strategy is based on four pillars that include:

  • Legislative & Regulatory Measures
  • Transparent Analysis of Intelligence
  • Domestic and International Cooperation & Coordination
  • Compliance and Law Enforcement

Furthermore, the National Committee for Combating Money Laundering and the Financing of Terrorism and Illegal Organisations looks into the implementation of strategy, emphasising effective coordination between different authorities, compliance with regulations and awareness of ML/FT risks among DNFBPs.

Compliance. Trust. Transparency

Customized and cost-effective AML compliance services to support your business always

Regulatory Obligations and AML/CFT Framework

The AML framework needs to be aligned with the statutory obligations of DNFBPs as follows:

ML/FT Enterprise-Wide Risk Assessment

ML/FT Enterprise-Wide Risk Assessment, also known as Business Risk Assessment, is an assessment that lays down an extensive plan that needs to be carried out to manage ML/FT and PF risks at an enterprise level. EWRA is a key pillar of a risk-based approach that addresses business-specific AML risks, threats, and vulnerabilities and further takes action to mitigate them.

EWRA is a continuous process to identify and assess ML/FT and PF risks that DNFBPs face in business lines, their products, and services and associated with different customers. While conducting the assessment, it considers various internal and external factors such as geographical risks, customer behavior, distribution channels and adequacy of the current AML policies.

DNFBPs with EWRA can effectively detect money laundering risks, identify mitigating measures, point out gaps and take cautious decisions relating to risk appetite and allocation of resources.

Customer Due Diligence

Customer Due Diligence (CDD) is an extensive process to identify and verify customer identity with the help of verified documents. CDD process also includes assessing customer risk profile, understanding the nature of transactions and monitoring customer activities. Additionally, it also focuses on assessing risk associated with customer’s business relationships and transactions.

Further, the CDD process differs depending on the ML/FT and PF risks that customers are associated with. CDD comes in three types: Simplified Due Diligence, Standard Due Diligence and Enhanced Due Diligence. Different CDD types are employed for each customer to mitigate ML/FT and PF risks, depending on the circumstance.

Ongoing Monitoring

Only after CDD measures are employed for customers can DNFBPSs establish business relationships with them. Once they enter into these relationships, DNFBPS must undertake ongoing monitoring measures. This measure is crucial as it continuously detects and reports suspicious activities.

Further, as part of ongoing monitoring, DNFBPs monitor business relationships with each customer on an ongoing basis to prevent any probable ML/FT and PF activities which an existing customer can pose.

DNFBPs also need to undertake ongoing monitoring of transactions. In order to undertake such a measure, they need to implement a robust transaction monitoring system that can detect suspicious activity effectively by pointing out unusual patterns and frequent transactions and alerting the involvement of high-risk jurisdictions.

Regulatory Reporting

It is a regulatory obligation under the UAE’s AML regulatory framework to swiftly report suspicious transactions or any reasonable situation where any suspicion relating to proceeds is in question. DNFBPs in the UAE must put in place and update indicators that could be used to identify possible suspicious transactions.

Regulatory reporting means submitting various reports provided under the AML/CFT regulatory framework to the relevant authorities. In the UAE, Suspicious Activity Report (SAR) or Suspicious Transactions Report (STR) are standard reports filed by DNFBPs to report any suspicious activity they come across.

Furthermore, in addition to SAR/STR, they must also file reports depending on the circumstances and nature of their business. These include filing of Partial Name Match Report (PNMR), Confirmed Name Match Report (CNMR), Real Estate Activity Report (REAR), Dealers in Precious Metals and Stones Report (DPMSR), High-Risk Country (HRC), and High-Risk Customer Activity (HRCA) reports.

AML/CFT Governance

For an effective AML framework, DNFBPs must include AML/CFT governance within their AML framework. This governance measure acts as a foundational structure. DNFBPs must include the following measures within AML/CFT governance:

  • AML governance must include compliance staffing and training to ensure that compliance officers and employees understand their responsibilities surrounding AML and further effectively undertake them.
  • It is mandated by the UAE’s regulatory framework that senior management is involved in the institution of the AML framework. Further, the law imposes various responsibilities on it, such as implementing governance and operating systems, approval of internal policies, procedures, and controls, application of the directives of Competent Authorities, and oversight of the AML/CFT compliance programme.
  • The AML framework must include an AML/CFT health check mechanism within DNFBPs that evaluates the business’s performance against all applicable AML/CFT obligations. This measure establishes ways to oversee vulnerabilities across DNFBPs, thereby strengthening the effectiveness of AML policies.
  • AML governance must include AML Independent Audit measures to evaluate efficacy and adherence to AML measures. It is an essential factor of the AML framework to engage auditors for conducting thorough reviews of current policies, procedures, and controls.

Record Keeping

Having a record-keeping system is essential within the AML framework. Records are an important source of information not only for DNFBPs but also for regulators. With record keeping, it is easier to undertake investigations and ensure transparency. As per the UAE’s AML regulatory framework, it is mandated that DNFBPs keep comprehensive information related to transactions, CDD, and any SAR/STR for five years.

Maintaining such records helps in identifying potential ML/FT and PF activities and underscores regulatory oversight. By keeping such records, DNFBPs can effectively counter ML/FT crimes and further safeguard themselves. Furthermore, having robust record-keeping practices, DNFBPs can effectively respond to regulators and commit to having a transparent and answerable culture.  

Targeted Financial Sanctions

Targeted Financial Sanctions (TFS) include measures that the regulatory authority imposes to restrict financial transactions with specific individuals, entities, or countries. DNFBPs must undertake such measures to prevent transactions with sanctioned individuals or entities and freeze their assets when identified.

To avoid indulgence with ML/FT and PF risk, DNFBPs, as part of this measure, undertake screening procedures for customers against relevant sanctions lists released by national and international bodies and further report any matches to the appropriate authorities.

How to frame effective AML Controls framework?

Here are a few ways in which you can effectively build AML Controls Framework:

1 - Having Qualified Compliance Professionals

The first and foremost step to building an effective AML and CFT framework is to have an effective and efficient AML expert who wouldn’t shy away from taking the help of creativity and innovation.

A practical AML/CFT framework requires a structure of corporate governance that incorporates compliance professionals or officers who are fluent in terms of legal regulations requirements.

A guide To establishing an Effective AMLCFT Framework in your business

Anti-money laundering professionals are basically responsible for making sure that the reported issues within the organization are addressed or looked after within the organization and within a time frame that will restrict you from further damage.

In addition to that, it is your moral duty to make all the employees of your organization and not just AML professionals know about the legal and ethical responsibilities that need to be effectively managed at an individual level as well in order to comply with the legal AML regulations.

Furthermore, all the employees must understand the fundamental idea of AML/CFT. In order to effectively comply with AML or CFT regulations, all the employees must undergo interdisciplinary training or certification programs in order to identify potential risks.

2 - Training of Anti-Money Laundering Experts

Anti-money laundering is a pretty dynamic subject. There is always some sort of updates, changes in regulations, proposals, or laws happening. In addition to that, various methods continue to find channels in criminals with every passing day.

Improving the overall skill set of your employees is essential in order to ensure that AML/CFT measures are actually implemented in the best possible way.

Professionals from the finance department must clearly understand the AML and CFT legislation and regulations for identifying and reporting any suspicious transactions.

Likewise, management employees who have direct contact with customers or the ones who process documents and money must understand the requirements of the Anti-Money Laundering Laws in the UAE.

Your entire staff must be well aware of the AML/CFT Framework and various roles of the consultants, compliance officers, officers, senior management, and the board of directors.

In addition to that, all of your staff members must be aware of ways in which they are supposed to react if at all they encounter suspicious activity.

3 - Risk Assessment And Risk-Based Approach

The foundation of a practical counter-terrorism financing framework (CFT) and anti-money laundering (AML) is actually based on a risk-based approach.

Business enterprises should determine the risk level of the clients by conducting an accurate risk assessment during the process of client
recruitment.

Post this, enterprises should aim to implement an efficient and effective AML compliance program in accordance with the AML/CFT Framework. By developing a tailor-made control program in accordance with the risk levels of your respective clients.

  • Building policies and adequate controls to reduce the risk and even the potential of money laundering
  • Understanding the overall levels of risks associated with business transactions and relationships
  • Identifying various sources of risks and evaluating all the potential risk reduction controls
  • Effectively running the successful AML compliance programs
  • Making accurate risk-based decisions about the employees as well as customers.

In addition to that, a risk-based approach is adopted in order to detect and prevent all sorts of money laundering activities.

However, risk-bearing capacity and the risk appetite of all the companies and customers are pretty different from one another. As a result, companies would be failing miserably if they try to implement the same AML controls for every customer.

There are basically two fundamental steps for organizations to move ahead with a risk-based approach. The first one is undoubtedly assessing the risk and the second one is to appropriate control processes to various risk levels.

4 - Advanced Anti-Money Laundering Policies

Highly dynamic anti-money laundering policies are needed to protect a business enterprise from criminal activities like money laundering and fully comply with relevant regulations and laws.

Enterprises need to implement robust risk-based governance to guide systems and processes. Providing a practical anti-money laundering policy framework is the topmost priority when it comes to meeting AML obligations.

Anti-money laundering policies should be easily verifiable by the authorized regulators, reflecting the overall risk appetite.

For instance, your AML policies should incorporate customer risk ranking during the recruitment process and due diligence.

Business enterprises should know their customers in order to comply with local and global legal anti-money laundering requirements and operate within the purview of the established AML/CFT Framework.

5 - Know Your Customer (KYC)

Know your customer processes incorporate the process of accurately and completely defining the information of the respective customers. Generally, KYC is the most critical step in the entire anti-money laundering control process.

Once you are sure of who your customers really are, the risk levels of these customers can be evaluated without any hassle, and post which, you can apply customer due diligence (CDD) processes.

Determining the level of risks of your customers or even potential customers with the help of CDD makes the AML control process much faster and efficient for the company.

During the process of CDD, the potential customer must be screened in politically exposed persons (PEPs) and the sanction list.

If any politically exposed person is found in this list, then the need and importance of enhanced due diligence (EDD) come into the picture.

This is simply because politically exposed persons are usually considered as individuals who hail from a high-risk profile, and thus, merely CDD processes might not be sufficient. As a result, the risks and threats related to the customer’s account opening can be detected, allowing you to take more effective AML controls and establish a highly-effective AML/CFT Framework.

6 - Ongoing Monitoring

Information or risks of institutions or customers may change over a period of time. For example, individuals who are not PEP might become politically exposed person by taking up any new task.

Hence, it is essential to be familiar with the information of the customer that may change over a period, also changing the risk levels of that particular customer.

Therefore, all of this information should be updated in your systems at regular intervals.

In addition to that, the accuracy of this information should also be confirmed so that it does not lose its functions of the risk-based approach.

If you are unable to keep up with the constantly changing customer information, you have to be prepared for some severe consequences.

The AML and CFT framework or policies makes an effective risk management tool. Additionally, an effective AML and CFT regime also reduces the probability of damage to the organization due to fraudulent activities.

7 - Detecting And Reporting Any Suspicious Transactions

The primary purpose of anti-money laundering checks is to detect financial crimes and suspicious transactions. Financial crimes must be detected, and necessary precautions must be taken in order to bring your AML processes to their actual purpose.

Although it is pretty challenging to check suspicious transactions almost instantly, they can be detected with the help of transaction monitoring solutions available to you. All of these transactions are stopped immediately and passed onto some other AML experts.

8 - Upgrade The Anti-Money Laundering System With AI-Powered Solutions

With the constant technological change, crimes are also changing their pace and ways dramatically, resulting in the evolution and development of the regulations. With this given, manual anti-money laundering controls remain insufficient in organizations that are prone to the risk of money laundering activities.

AI-powered anti-money laundering software solutions help you track the unusual transactions for the known patterns, and they reduce the risk of ML to a greater extent and thereby help in implementing an effective AML/CFT Framework.

Conclusion on Effective AML/CFT Framework in Your Business

The anti-money laundering (AML) framework is vital for preventing ML/FT and PF risks. Policies, procedures, and controls established under the AML framework help to detect, mitigate, and report illicit activities, including ML/FT and PF.

Additionally, as a structured strategy, the AML framework aids in a better understanding of the UAE’s AML/CFT regulatory compliance, thus ensuring compliance and avoiding penalties and fines. Therefore, with the implementation of the AML framework, DNFBPs can protect themselves from ML/FT and PF activities.

FAQs on Effective AML/CFT Framework

Why is AML/CFT important?

AML/CFT is essential for the following reasons.

  • In order to protect the financial systems
  • In order to prevent criminals or money launderers from enjoying the proceedings of the money laundering activities
  • In order to restrict the criminals to develop formidable economic powers and challenge the stability.

If you are a financial institution or a designated non-financial business or profession, then the chances are pretty high that you are more prone to encounter pretty risky situations on a daily basis. Hence, each employee should be aware of the AML/CFT policies of your company so that they can also play their part effortlessly.

However, it will be the responsibility of the AML Compliance Officer to ensure that an effective AML/CFT Framework is implemented in the company.

Begin your AML compliance journey with a positive first step.

Contact our team to handle your goAML registration process.

About the Author

Pathik Shah

FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)

Pathik is an ACAMS-certified AML consultant specialising in governance, risk, and compliance for regulated entities in the UAE. He brings over 28 years of experience, with 1,000+ hours of AML training and 200+ advisory engagements across DNFBPs, VASPs, and FIs. He supports businesses in aligning with AML/CFT requirements from the CBUAE, DFSA, MoET, MoJ, VARA, CMA, FSRA, and FATF. Known for translating complex regulations into audit-ready procedures, Pathik enables operational clarity and compliance readiness.

Reach Out to Pathik

A detailed guide of AML compliance requirements for auditors and accountants in the UAE

Blogs

Published On: 10/13/2021

Table of Contents

Protect your business with reliable and effective AML strategies with AML UAE.

Last Reviewed On: 07/17/2026   |   Last Updated On: 07/17/2026

A detailed guide of AML compliance requirements for auditors and accountants in the UAE

The profession of auditors and accountants is not an easy thing. They have access to the financial records and activities of their clients. This accessibility to financial records increases their vulnerability to money laundering. The involvement of their clients in money laundering activities also increases their exposure.

So, they must be extra vigilant to the risks of money laundering and terrorism financing. In this article, we list down the red flags of money laundering that auditors and accountants must be aware of. We also mention the important AML requirements that they must fulfil to remain in compliance with UAE’s AML regulations.

Key aspects that make auditors and accountants vulnerable to money laundering and financial crime

Some of aspects of the profession of auditors and accountants make them vulnerable to financial crimes. They must be aware of these factors to save themselves from becoming a victim of money laundering and terrorism financing. These factors include:

AML regulation for auditors and accountants in UAE

Federal Decree-Law No. 10 of 2025 on Anti-Money Laundering and Combating the Financing of Terrorism and Illegal Organizations is the primary law for AML in UAE. The Cabinet Resolution No. 134 of 2025 concerning the Implementing Regulation of this Decree-Law makes accountants and auditors subject to the AML law. This means that the AML law applies to all auditors and accountants in UAE.

The Cabinet Decision provides a list of Designated Non-Financial Businesses and Professions (DNFBPs). AML regulations apply to these DNFBPs that include auditors and accountants. Given the nature of their profession and the content of their duties, accountants and auditors must comply with AML requirements as stated in the regulations for DNFBPs.
Their exposure to money laundering and financial crime activities is high because of the nature of their profession. They are responsible for financial management, examination of financial records and accounts, and assessment of governance structure and control procedures. These activities are the reason why illicit organizations or individuals exploit or bribe auditors and accountants to launder money.
The Ministry of Economy of UAE provides a Supplemental Guidance for auditors and accountants. It mentions in detail the AML/CFT obligations for both of these professions. These obligations include risk identification, customer due diligence, identification and reporting of suspicious transactions, and internal control and governance frameworks.

Complying with AML and CFT

requirements just got easier

AML/CFT compliance requirements for auditors and accountants in UAE

Auditors and accountants must comply with the following requirements under the AML regulations of UAE:

Understand possible ML/FT risk exposure

You must have a detailed understanding of how your accounting and auditing business can be exposed to ML and FT risks. This requires an assessment at both the enterprise level and customer level. For this:

  • You must adopt a risk-based approach to identify risks in your business transactions. These risks may be of different types based on business nature, type of service, the operational environment, and other factors. Accordingly, you must adopt risk mitigation measures. 
  • You must be aware of the source of ML/FT risks and the phase in which the money laundering risk is high. You must know the client who is exposing you to such money laundering risks. 
  • You must know the transactions of clients that are making you vulnerable to financial crimes – valuation of certain types of assets or liabilities, approval of changes in a company’s capital structure, approval of company restructuring option, use of reserve account, approval of write-off of uncollected debt, payments from clients that are proceeds of financial crimes, or any other. 
  • You must consider different types of risks to your business due to money laundering. These risks include customer risk, geographic risk, transaction risk, channel risk, or any other. You must be able to identify each type and strategize for their elimination. 
  • You must conduct a risk assessment to understand the impact of these risks on your business. You must also analyze it in depth, document it, and update it as and when the changes occur. 
You must conduct a similar assessment of ML/FT risks on your client’s business. You must identify potential risks, adopt a risk-based approach, and document the methodologies adopted. Also, based on the client’s type and nature of business, you must appoint Compliance Officer and relevant team members to facilitate compliance with AML regulations.

Put in place internal policies, controls, and procedures

Auditors and accountants must implement necessary measures to manage and mitigate the ML/FT risks. One of the key measures is the implementation of strong and effective internal policies, controls, and procedures. You must assess these policies for effectiveness and update them accordingly as and when the need arises. 

These policies must relate to customer due diligence and suspicious transaction reporting. It must also include requirements for governance and record-keeping. Overall, such procedures must ensure management and mitigation of risks. 

Auditors and accountants must apply the same for their client’s businesses as well. They must check whether the client has implemented relevant internal policies and control measures related to AML/CFT. They must ensure that these policies and procedures are in alignment with the risk appetite of the client.

Implement customer due diligence measures

Auditors and accountants must apply the necessary customer due diligence (CDD) measures based on the category and profiling of the ML/FT risk. If there is any change in the risk category, they must be ready to update the due diligence measures as well. You must apply these measures during or before the transaction happens or the business relationship starts.

You need to apply similar CDD measures for your clients as well. These due diligence measures include the following:

Seek expert assistance of AML UAE

for your AML compliance requirements and enjoy an AML-compliant business

Report suspicious transactions to Financial Intelligence Unit (FIU)

Auditors and accountants must report any kind of suspicious transactions to the Financial Intelligence Unit as and when they suspect it. You must add all the relevant information for the suspected transaction and keep it updated. You must be extra vigilant to identify any suspicion in any transaction or customer.
Some of the indicators for suspicious transactions in their own business or client’s business include:
  • Unnecessary complex transactions whose purpose or beneficial owner is not known
  • Transactions that are inconsistent with the customer’s risk profiling
  • Large transactions (relatively large to a customer’s income or turnover) that are unusual for that client
  • Large deposits or withdrawals inconsistent with customer’s business nature
  • Unexplained changes in the ownership of entities or unnecessary involvement of a third party
  • Transactions involving high-risk countries or third parties with no relationship with customers
  • Unclear or dubious sourcing of funds for a transaction
  • Refusal of customers to provide relevant information or proofs required for due diligence measures

Ongoing monitoring of their and clients’ activities

Auditors and accountants must be vigilant of their clients’ activities and transactions. They must protect their business transactions and their clients’ from possible misuse by terrorists or criminals. So, you must check the client’s business and transactions often to be sure of no involvement of financial crime.
You must do continuous monitoring of the following activities of your client’s business:
  • You must check for any unexpected changes, amendments, or transfers that are unusual to your client’s routine transactions. 
  • You must keep a check on any changes in ownership, capital contributions, dividend payments, powers of attorney, or any other transaction that changes the control of the client’s business.
  • You must monitor any unusual transaction, which does not align with the client’s expected business activity. This may include funds transfers or financial transactions, or any other transaction that does not give the correct source of financing. 
  • An important consideration for auditors and accountants must be to check the source of the payments received from clients. You must ensure that the payments come from known sources and not from any unknown foreign accounts or third parties. The mode of payment must be such that it does not hide the origin of funds and must be the usual mode used by the client. 

Access the best AML advisory services

for making your business AML-compliant

Conclusion

Auditors must understand the vulnerability of their professional activities to money laundering risks. With that understanding, they must implement the above measures to comply with UAE’s AML/CFT regulations. These measures ensure that they themselves and their clients are not exposed to money laundering or terrorism financing activities.

To plan and implement any of these measures, you can also take the support of AML consultants in the UAE. A professional, AML consultant will be better equipped to help accountants and auditors with the right, relevant measures against money laundering. The consultant will ensure that industry-specific steps are taken in the fight against money laundering and terrorism financing.

Role of AML UAE

AML UAE is a leading AML compliance services provider in UAE. We help you with fulfilling all the requirements for AML and CFT in UAE. Our spectrum of AML compliance services is not restricted to national boundaries, but we also make sure that you comply with the global regulations of AML.

We can help you with:

Frequently Asked Questions (FAQs)

Here are a few frequently asked questions when it comes to the need and importance of sanction and PEP screening in the customer onboarding process.

Are the means of payment used by a client, possible red flags of ML/FT risks?

Yes, the means of payment used by the client to pay to the auditor or accountant can be an indicator of ML/FT risks. Some of the possible red flags are:

  • If the payment is divided into several, small parts
  • If the relevant documents submitted for the transaction are not trustworthy
  • If the payment is done via an unrelated third party with no connection to the client or no legal explanation for the same
  • If the mode of payment used is such that it hides the true payer of the money. 

The auditor and accountant must have the following information about the beneficial owner of the company:

  • Identification details
  • Source of wealth
  • Corporate history and business activities
  • Business relationships
  • Business transactions with third parties in foreign jurisdictions
  • Any connections with criminals or past allegations of criminal activities

Share via :

Add a comment

About the Author

Pathik Shah

FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)

Pathik is an ACAMS-certified AML consultant specialising in governance, risk, and compliance for regulated entities in the UAE. He brings over 28 years of experience, with 1,000+ hours of AML training and 200+ advisory engagements across DNFBPs, VASPs, and FIs. He supports businesses in aligning with AML/CFT requirements from the CBUAE, DFSA, MoET, MoJ, VARA, CMA, FSRA, and FATF. Known for translating complex regulations into audit-ready procedures, Pathik enables operational clarity and compliance readiness.

Reach Out to Pathik

A deep dive into the AML compliance requirements for the real estate sector in the UAE

Blogs

Published On: 04/18/2023

Table of Contents

Protect your business with reliable and effective AML strategies with AML UAE.

Last Reviewed On: 07/17/2026   |   Last Updated On: 07/17/2026

AML compliance requirements for the real estate sector in the UAE

The real estate sector is one of the main non-financial sectors that is highly vulnerable to money laundering activities. Large sums of money are involved in real estate transactions with limited regulatory scrutiny, so money laundering activities and terrorist financing transactions are quite common in the real estate sector.

As per the Central Bank of the UAE’s ‘Financial Stability Report, 2022’, the real estate sector (real estate and construction) contributed 18.5% of the UAE’s 2021 real non-oil GDP and 22% of UAE banking sector loans.

It becomes essential for the regulators to make the sector more regulated and controlled. It is also important to identify the possible suspicious transactions and conduct regular monitoring of real estate transactions. UAE has made special provisions for AML requirements in the real estate sector.

In the blog, we list down the situations that real estate businesses must be aware of to identify money laundering. We also cover the UAE regulations that govern AML/CFT provisions in the country. Lastly, we include the AML requirements that real estate agents and brokers must fulfill.
AML Compliance Requirements in UAE

Untangle the Web of AML Compliance with AMLUAE

Establish clear, relevant, and comprehensive AML Program with our expert assistance

Suspicious transactions in the real estate sector that raise a concern for money laundering

Following are the possible situations that raise suspicion regarding involvement of money laundering or any financial crime in the real estate sector:

In regards to these possibilities, the UAE government introduced AML/CFT regulations. Let us look at the key regulations and directives that control the real estate sector’s compliance with AML/CFT.

AML regulation for real estate sector in UAE

Do AML regulations apply to real estate brokers in the UAE?

Federal Decree-Law No. 10 of 2025 on Anti-Money Laundering and Combating the Financing of Terrorism and Illegal Organizations is the primary law for AML in UAE. The Cabinet Decision No. 134 of 2025 concerning the Implementing Regulation of this Decree-Law makes real estate agents and brokers subject to the AML law. This means that the AML law applies to real estate agents and brokers in the UAE.

These regulations are necessary since the real estate sector has a lower level of awareness of possible suspicious ML/FT transactions. Also, the real estate sector is big with not many rules to invest or do business in it. This makes the sector highly exposed to ML/FT activities that disturb the economy and income distribution of the country.

The Cabinet Decision provides a list of Designated Non-Financial Businesses and Professions (DNFBPs) that includes real estate brokers and agents. These define the various CDD obligations of the real estate industry and ways to identify risk factors. Let us look at the AML/CFT compliance requirements for the real estate sector in the UAE.

AML/CFT compliance requirements for real estate brokers and agents in UAE

Real estate agents and brokers must comply with the following requirements under the AML regulations of UAE:

Understand possible ML/FT risk exposure

You must have a detailed understanding of how your real estate business can be exposed to ML and FT risks. For this:

  • You must adopt a risk-based approach to identify risks in your business transactions. These risks may be of different types based on business nature, type of service, the operational environment, and other factors. Accordingly, you must adopt risk mitigation measures. 
  • You must be aware of the source of ML/FT risks and the phase in which the money laundering risk is high. 
  • You must know the latest ML/FT trends and understand the various customer risks, channel risks, and geographic risks to the real estate industry.  You must be able to identify each type and strategize for their elimination. 
  • You must be aware of the type, size, complexity, transparency, geographic origins, or any unusual nature of financial arrangements or instruments related to the buying and selling of property.
  • Brokers and agents must have full information on a customer’s residence status, type of real estate transaction, and speed and frequency of transactions to gauge the risk. 
  • You must keep all this information related to risk profiling documented and saved. The information must include methods of risk identification used, models used, and overall risk score. 

Understand the Money Laundering Risk Exposure to Your Business

AML UAE provides expert assistance in conducting AML Enterprise-Wide Risk Assessment

Implement Customer Due Diligence measures

Real estate brokers and agents must apply the necessary customer due diligence (CDD) measures based on the category and profiling of the ML/FT risk. If there is any change in the risk category, they must update the due diligence measures as well. You must apply these measures during or before the transaction happens or the business relationship starts.

These due diligence measures include the following:

Sanctions Screening - Actionable and Reporting under AML UAE
  • You must have in place a defined process for screening customers and prospects against Sanctions Lists. You must conduct background checks on your customers and prospects to identify any association with financial crimes.
  • You must be vigilant of the identity of the beneficial owner of your client. You must obtain all relevant proofs for establishing their identity and the source of funding. 
  • You must check for the compatibility of the customer’s profile with the relevant real estate transaction to see if it suits their financial stature and professional circumstances.
  • You must track the legal arrangement or structure used in the transaction, as it may result in hiding the identity of the owner or source of funds. 
  • You must also keep an eye on any association with Political Exposed Persons (PEPs), specifically in the case of foreign buyers or sellers. 
PEP and PEP Screening under UAE AML Regulations pre
  • You must check for any previous business transaction or relationship between buyer and seller. 

Ongoing monitoring of transactions

Whenever you identify high-risk customers, you must conduct a regular check of their transactions. You must monitor the frequency and type of real estate transactions they have been involved in. You must check the status of the financial instrument during the lifecycle of the transaction or you must check the land registry details.

Put in place internal policies, controls, and procedures

What are the basic elements of AML Policy in UAE Pre

The real estate brokers and agents must implement necessary measures to manage and mitigate the ML/FT risks. One of the key measures is the implementation of strong and effective internal policies, controls, and procedures. You must assess these policies for effectiveness and update them accordingly as and when the need arises. 

These policies must relate to customer due diligence and suspicious transaction reporting. It must also include requirements for governance and record-keeping. Overall, such procedures must ensure management and mitigation of risks.

Report suspicious transactions to Financial Intelligence Unit (FIU)

You must report any kind of suspicious transactions to the Financial Intelligence Unit as and when you suspect it. You must add all the relevant information for the suspected transaction and keep it updated. You must be extra vigilant to identify any suspicion in any transaction or customer.

Some of the indicators for suspicious transactions include:

  • Unnecessary complex transactions whose purpose or beneficial owner is not known
  • Transactions that are inconsistent with the customer’s risk profiling
  • Large transactions (relatively large to a customer’s income or turnover)
  • Unexplained changes in the ownership of entities or unnecessary involvement of a third party
  • Transactions involving high-risk countries or third parties with no relationship with customers
  • Unclear or dubious sourcing of funds for a transaction
  • Refusal of customers to provide relevant information or proofs required for due diligence measures

Real Estate Activity Report Submission

Ministry of Economy has recently issued a Circular (No. 05/2022 dated 24th June 2022), requiring the real estate brokers to report the specified transactions pertaining to real estate in the new report named as – Real Estate Activity Report (‘REAR’). The reporting entities have to submit REAR with the FIU UAE.

Read more about REAR here.

Filing of Real Estate Activity Report (REAR) on goAML under UAE AML Law

Devise and implement a sound governance structure

You must formulate a governance structure to ensure your business complies with AML/CFT requirements. For this, you must appoint a fit and capable compliance officer. He/she must be capable of handling Ml/FT reporting, AML/CFT program management, and training and development of the team.

You must keep your employee up-to-date on AML/CFT laws, policies, and norms. You must design a training manual and impart it to relevant team members. You must also assess the effectiveness of these training programs to ensure the right knowledge development.

A well-functioning governance structure is tested by an independent audit frequently. This auditing procedure will check the risk profile of products and services, customers, and target markets. If it is not possible for you to keep an internal audit team, then you can hire a third-party auditing team.

Free Download AML Policy Template for Real Estate Agents and Brokers in UAE

Responsibilities of Senior Management around AML program under UAE AML Laws

Reliable and Robust AML Services for Real Estate Agents and Brokers

From EWRA to filing REAR, get end-to-end AML compliance services with AML UAE

Anti-money laundering regulations for real estate transactions

The real estate sector brings a huge difference to UAE’s economy. So, it is immensely critical to keep money laundering and terrorism financing in check in this sector. You must implement all the above-mentioned measures to comply with national and global AML regulations.

The compliance with the anti-money laundering regulations for real estate transactions will enable you to save yourself and your business from any fraudulent transaction or business relationship. This, in turn, helps you to minimize your exposure to money laundering and terrorism financing risks. These measures also help you to be in congruence with international AML/CFT regulations and best practices.

To plan and implement any of these measures, you can also take the support of AML consultants in the UAE. A professional, AML consultant will be better equipped to help real estate brokers and agents with the right, relevant measures against money laundering. The consultant will ensure that industry-specific steps are taken in the fight against money laundering and terrorism financing.

Role of AML UAE

AML UAE is a leading AML compliance services provider in UAE. We help you with fulfilling all the requirements for AML and CFT in UAE. Our spectrum of AML compliance services is not restricted to national boundaries, but we also make sure that you comply with the global regulations of AML.

We can help you with:

FAQs - AML Compliance Requirements for Real Estate

Here are a few frequently asked questions About AML For Real Estate Sector.

What is AML in real estate? 

There are AML regulations for estate agents in the UAE, including implementation of necessary CDD measures, identification of ML/TF risks and reporting, internal policies, and sound governance structure.  

Yes. The primary reasons for the high risks of money laundering in the real estate sector are transactions involving large sums of money and limited regulations and laws. Also, more cash transactions, undervaluation or overvaluation of property, and involvement of PEPs or unknown third parties as investors expose the industry to higher risks.  

It is essential to conduct customer due diligence in the real estate sector to comply with know your customer, know your business, and ultimate beneficial owner regulations. For this, collect clients’ information, verify them with identity documents, verify UBO, check against PEPs or Sanction lists, and prepare risk profiles.  

Anti-money laundering in the real estate sector is essential. So, estate agents must do AML checks to identify customers, transactions, and their links with any financial crimes.  

Estate agents must do AML checks to avoid the possibility of engaging in business transactions with financial criminals, drug traffickers, money launderers, or terrorism sponsors.  

The factors that contribute to the vulnerability of the real estate sector to money laundering and other financial criminal activities are:

  • It is possible to launder big amounts of money in buying, selling, and leasing property. 
  • The prices are subjective like some prime locations have high property prices, leading to no suspicion based on prices.
  • It is seen as one of the best investment options.
  • There is a lesser degree of regulatory oversight and regulations for the real estate sector.

In the case of undervaluation of a property, the seller agrees to sell the property to the buyer at a lesser price than the market value. The buyer pays the difference between the two amounts with illicit funds to the seller. 

In the case of overvaluation of a property, the buyer buys the property at a higher price than the market value. This allows the buyer to obtain a large loan from the bank. Then the buyer uses illicit money to repay debts, thereby laundering illicit money into the legal financial system. 

– Federal Decree-Law No. (20) of 2018 On Anti-Money Laundering and Combating the Financing of Terrorism and Financing of Illegal Organizations,
– Implementing regulation, Cabinet Decision No. (10) of 2019 Concerning the Implementing Regulation of Decree-Law No. (20) of 2018 On Anti-Money Laundering and Combating the Financing of Terrorism and Illegal Organizations,
– Cabinet Decision No. (20) of 2019 Regarding Terrorism Lists Regulation and Implementation of UN Security Council Resolutions On the Suppression and Combating of Terrorism, Terrorists Financing & Proliferation of Weapons of Mass Destruction, and Related Resolutions,
– AML/CFT Guidelines for Financial Institutions and Designated Non-Financial Businesses and Professions issued by supervisory authority (such as FSRA or DFSA),
– UAE Ministry of Economy’s Guidelines for Designated Non-Financial Businesses and Professions,
– UAE Ministry of Economy’s Supplemental Guidance for specific sector (such as Real Estate Sector, Dealers in Precious Metals and Stones, etc.)

Share via :

Add a comment

About the Author

Pathik Shah

FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)

Pathik is an ACAMS-certified AML consultant specialising in governance, risk, and compliance for regulated entities in the UAE. He brings over 28 years of experience, with 1,000+ hours of AML training and 200+ advisory engagements across DNFBPs, VASPs, and FIs. He supports businesses in aligning with AML/CFT requirements from the CBUAE, DFSA, MoET, MoJ, VARA, CMA, FSRA, and FATF. Known for translating complex regulations into audit-ready procedures, Pathik enables operational clarity and compliance readiness.

Reach Out to Pathik

AML Regulations for Capital Market Firms in UAE

AML Regulations for Capital Market Firms in UAE

Blogs

Published On: 07/13/2026

Table of Contents

Protect your business with reliable and effective AML strategies with AML UAE.

Last Reviewed On: 07/13/2026   |   Last Updated On: 07/13/2026

Key Highlights

  • Capital market firms, including broker-dealers, fund and asset managers, investment advisers, and custodians, are financial institutions under Federal Decree-Law No. 10 of 2025 and its Executive Regulations in Cabinet Resolution No. 134 of 2025.
  • They are supervised for AML by the Capital Market Authority, established under Federal Decree-Law No. 32 of 2025 as the successor to the Securities and Commodities Authority, not by the Central Bank.
  • The national risk assessment rates the securities sector’s money laundering risk in the medium to medium-high range with controls assessed as effective, and its proliferation financing risk as low.
  • On top of the federal laws, the Capital Market Authority issues its own AML rulebook chapter, sector guidance, notices, thematic reviews, and reporting standards.
  • Virtual asset service providers fall under a separate framework rather than this securities regime: the federal CMA regime applies outside the financial free zones and works alongside local licensing authorities such as Dubai’s Virtual Assets Regulatory Authority. We cover it on a dedicated page rather than here.
  • Firms in the DIFC and ADGM answer to the DFSA and FSRA and sit outside this guide.

Capital market firms sit at a different point in the UAE financial system from banks, payment institutions and remittance houses. They deal, manage, advise, and hold securities rather than take deposits or send remittances. They also answer to a different regulator, the Capital Market Authority, rather than the Central Bank. This guide sets out the AML regulations for capital market firms in the UAE: which activities are in scope, who supervises them, the full legal framework that applies, and how the national risk assessments rate the sector’s money laundering, terrorist financing, and proliferation financing risk. It covers securities and commodities firms supervised by the Capital Market Authority, outside the DIFC and ADGM.

In short: CMA-regulated capital market firms in the UAE, including broker-dealers, fund and asset managers, investment advisers and custodians outside the DIFC and ADGM, must comply with Federal Decree-Law No. 10 of 2025, its Executive Regulations in Cabinet Resolution No. 134 of 2025, the targeted financial sanctions framework under Cabinet Resolution No. 74 of 2020, UAE FIU reporting through goAML, and the Capital Market Authority’s own rulebook and reporting standards. Firms in the DIFC and ADGM follow the separate DFSA and FSRA AML regimes.

What activities are covered in the capital market sector?

The capital market sector, for AML purposes, covers firms licensed by the Capital Market Authority to carry on securities and commodities activities. The categories below all sit inside the AML regulations for capital market firms in the UAE. Firms established in the DIFC and ADGM are supervised by the DFSA and FSRA and are not covered here.

Brokerage and dealing in securities

Broker-dealers execute and arrange trades in securities and commodities for clients. Their exposure runs through client onboarding, the source of investment funds, and the risk that trading and settlement are used to move or layer value.

Fund and asset management

 Fund and asset managers invest and manage money on behalf of clients and funds. Their controls centre on the investor behind the money, the beneficial owners of corporate and pooled investors, and the source of subscriptions.

Investment advisory

Investment advisers arrange and advise on securities business. Even where they do not hold client assets, they are inside the AML perimeter for the relevant business they introduce and service.

Custody and other market intermediaries

Custodians hold securities, and other market intermediaries support trading and settlement. Their duty is to know the client whose assets they hold and to monitor for activity that does not fit the account.

AML Supervisory Authority for the Capital Market Firms in UAE

For capital market firms outside the Financial Free Zones, the Capital Market Authority is the primary sector supervisor for AML, CFT and CPF compliance. The UAE Financial Intelligence Unit and the Executive Office for Control and Non-Proliferation also play roles in reporting and targeted financial sanctions.

Capital Market Authority (CMA)

The Capital Market Authority, established under Federal Decree-Law No. 32 of 2025 as the successor to the Securities and Commodities Authority, licenses and supervises capital market firms, issues the AML rulebook and guidance they follow, and inspects them through thematic reviews and examinations. It can require reporting, direct remediation, and the imposition of penalties for breaches. Virtual asset activity sits under a separate framework rather than this securities regime: the federal CMA regime applies outside the financial free zones and works alongside local licensing authorities, including Dubai’s Virtual Assets Regulatory Authority. Our dedicated guide to AML for VASPs outside Dubai covers it in full. Firms established in the DIFC and ADGM are supervised instead by the DFSA and FSRA and fall outside this guide.

UAE FIU and goAML

In-scope capital market firms register with the UAE Financial Intelligence Unit on the goAML platform and report through it. Registration on goAML is a baseline obligation, and suspicious transaction reports, suspicious activity reports, and related filings are submitted through it where required. See our goAML registration guide for the practical steps.

AML Legal Framework Applicable to Capital Market Firms in UAE

The framework has four layers: the core federal laws, the guidance that applies to all reporting entities, the national risk assessments, and the Capital Market Authority’s sector-specific material. This section catalogues each layer, grounded in the Capital Market CMA library. Some older SCA, FIU and supervisory materials were issued under the 2018 AML framework; they should be read subject to Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025, and only to the extent they remain in force and are not inconsistent with the current framework.

Layer Instrument Why it matters 
AML statute Federal Decree-Law No. 10 of 2025 Core AML, CFT and CPF offences, FIU powers, reporting duties and penalties 
Executive Regulations Cabinet Resolution No. 134 of 2025 Practical obligations: risk-based approach, CDD and EDD, beneficial ownership, monitoring, reporting and record keeping 
TFS framework Cabinet Decision No. 74 of 2020 and EOCN guidance Screening, freezing without delay and reporting of confirmed and partial name matches 
Capital market laws Federal Decree-Law No. 32 and No. 33 of 2025 Establish the Capital Market Authority and govern licensing and supervision of capital market activities 
CMA and SCA materials Rulebook Chapter Five, notices, thematic reviews and returns Sector-specific AML expectations and reporting standards 
NRA and PF NRA UAE ML and TF NRA 2024 and UAE PF NRA 2026 Baseline for the business-wide and enterprise-wide risk assessment and risk calibration 

Federal AML Laws and Executive Regulations Applicable to Capital Market Firms in UAE

These instruments are the legal foundation for every capital market firm in scope.

Federal Decree-Law No. 10 of 2025 on AML, CFT and CPF

For a securities or commodities firm, Federal Decree-Law No. 10 of 2025 is the foundational statute behind every anti-money laundering control a broker-dealer, asset manager, adviser or custodian must run. It defines money laundering, predicate offences, targeted financial sanctions and suspicious transactions, and confirms that offences may be committed through digital systems. It creates the Financial Intelligence Unit within the Central Bank as the national central agency for receiving suspicious transaction reports, empowered to demand further information and, through the Head of the Unit, to issue suspension and freezing measures within the limits and procedures set by the Decree-Law and the UAE FIU regulation on suspension and freezing powers. The Decree-Law places market intermediaries under supervisory oversight, exposes them to administrative penalties, and imposes the duty to detect, report and support enforcement.

Cabinet Resolution No. 134 of 2025, the Executive Regulations

Cabinet Resolution No. 134 of 2025 issues the Executive Regulations of Federal Decree-Law No. 10 of 2025, converting the statute into the operating rulebook that market intermediaries follow day to day. It expands the definitions, adding senior management, beneficial owner, reasonable measures and wire transfers, and confirms that securities activities and funds transfers fall squarely within the scope. For a broker-dealer, fund manager, adviser or custodian, it prescribes the substantive obligations: a risk-based approach, customer due diligence, identification and verification of beneficial owners behind corporate clients, ongoing monitoring of trading and settlement activity, and internal policies approved by senior management. These are the concrete procedures supervisors will test in examinations.

Cabinet Resolution No. 109 of 2023 on beneficial owner procedures

Cabinet Decision No. 109 of 2023 regulates beneficial owner procedures for legal persons in the United Arab Emirates. It defines the real beneficiary as the natural person who ultimately owns or controls a legal person, directly or through a chain of ownership, and requires legal persons to obtain, maintain and disclose accurate beneficial owner information, identify nominee board members, and keep a real beneficiary register updated within fifteen days of any change. For a securities firm, this underpins due diligence, since brokers and custodians rely on trustworthy ownership data to verify corporate clients. These procedures apply to legal persons licensed or registered in the State, including commercial free zones, but exclude the financial free zones, the DIFC and ADGM, which operate their own beneficial ownership regimes.

Cabinet Resolution No. 132 of 2023 on penalties for beneficial owner violations

Cabinet Resolution No. 132 of 2023 sets the administrative penalties for breaches of the beneficial owner procedures under Cabinet Decision No. 109 of 2023. It empowers the registrar to fine legal persons that fail to keep accurate registers or supply required information, following an annexed schedule, without prejudice to other sanctions under the primary anti-money laundering legislation. Consequences escalate: on a third violation, the registrar may suspend the commercial licence and close the premises until the fine is paid and the breach corrected. For a securities or commodities firm, this explains why corporate clients must keep ownership data current. These penalties apply to legal persons licensed or registered in the State, including commercial free zones, but not to the financial free zones, the DIFC and ADGM, which follow their own regime.

Cabinet Resolution No. 74 of 2020 on terrorist lists and UNSC resolutions

Cabinet Resolution No. 74 of 2020 governs how the United Arab Emirates applies the terrorist lists and gives effect to United Nations Security Council sanctions on terrorism, its financing and proliferation. It provides for a local Cabinet list, defines designation, listing and de-listing, and requires freezing measures to be applied without delay, meaning within twenty-four hours. For a securities or commodities firm, this is the backbone of transaction monitoring. Brokers, dealers, managers and custodians must register on the Executive Office website, continuously screen clients, prospective investors, beneficial owners and counterparties against the lists, freeze any matched funds or securities without prior notice, and report promptly to the supervisor.

Federal Law No. 7 of 2014 on combating terrorism crimes

Federal Law No. 7 of 2014 on Combating Terrorism Crimes is the criminal statute defining terrorist offences and their penalties in the United Arab Emirates. It sets out concepts such as terrorist crime, terrorist purpose, terrorist organisation and terrorist person, and prescribes severe penalties up to life imprisonment and, in specified cases, death. Of direct interest to a securities or commodities firm is its treatment of terrorism financing: it penalises providing, collecting or maintaining funds for terrorist ends and addresses freezing suspect funds held in financial institutions. Because the wider framework defines terrorist acts by reference to this law, market intermediaries use it to understand the conduct their controls target.

AML Guidance Applicable to All Reporting Entities

Beyond the core laws, the FIU and the Executive Office issue guidance and typologies that apply to all reporting entities, capital market firms included.

UAE FIU Regulation No. 1 of 2026 on Suspension and Freezing Powers, April 2026

UAE FIU Regulation No. 1 of 2026, dated April 2026, governs the postponement or suspension of suspicious transactions and the freezing of funds. Issued under the AML/CFT Decree-Law and its Executive Regulation, it applies to reporting entities and complements existing reporting duties. It introduces the Postponement Suspicious Transaction Report, an urgent filing where there is a risk of imminent transfer, withdrawal or dissipation of funds suspected of being linked to crime. The Head of the Unit may issue a Suspension Order of up to ten working days and a Freezing Order of up to thirty days. For dealers, managers and custodians, it creates a fast-track mechanism to preserve investor funds.

UAE FIU Strategic Analysis Report on Human Trafficking, April 2026

The UAE FIU Strategic Analysis Report on Human Trafficking, dated April 2026, analyses money laundering and financial flows connected to trafficking, drawing on suspicious transaction and activity reports filed with the Financial Intelligence Unit. It sets out its objectives, methodology and scope and covers the main forms of exploitation. Findings span the laundering of trafficking proceeds and convergence with other criminal enterprises, profiling subjects including organised crime groups, foreign politically exposed persons and money mules. It develops risk indicators around customer profile, behavioural activity, account and transactional activity, and due diligence. For dealers, managers, advisers and custodians, it is a detection resource for refining monitoring and improving report quality.

Guidance on Targeted Financial Sanctions for Financial Institutions, DNFBPs and VASPs, March 2026

Issued by the Executive Office for Control and Non-Proliferation, first published in January 2021 and last amended in March 2026, this guidance clarifies the obligations of reporting entities under the UAE’s targeted financial sanctions framework. It sets out four duties: registering in the Executive Office’s Notification Alert System; screening clients against the UAE Local Terrorist List and the United Nations Consolidated List; freezing assets without delay and not making them available to designated persons; and reporting the measures taken. The March 2026 update renames the Funds Freeze Report as the Confirmed Name Match Report and addresses weekend screening. For a securities firm, it defines how screening, freezing and reporting operate.

Joint Guidance on the Compliance Officer and MLRO, 2026

Issued in 2026 by the UAE Supervisory Sub-Committee, this joint guidance sets a unified framework for the appointment, authority and responsibilities of the Compliance Officer or Money Laundering Reporting Officer across regulated sectors. It applies to firms supervised by authorities, including the Securities and Commodities Authority, the Central Bank and the Ministries of Justice, Economy and Tourism, building on Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025. It treats the role as a cornerstone of an effective programme, requiring appropriate seniority, experience, operational independence, board access and adequate resources. For a securities firm, it clarifies how to appoint a fit and proper officer.

FIU Strategic Analysis Report on Terrorist Financing, May 2025

Published in May 2025 by the UAE Financial Intelligence Unit, this strategic analysis on terrorist financing typologies and facilitators draws on data held from 1 January 2021 to 31 December 2024, including suspicious transaction and activity reports and cases disseminated to authorities. It explains how terrorist financing works and sets out typologies such as moving and obscuring funds through financial institutions, corporate networks, trade-based methods, high-value goods and real estate. It also examines facilitators, including designated persons, family members, money mules, corporate nominees and professional service providers, closing with practical indicators. For an investment firm or custodian, these indicators sharpen the detection, tracing and reporting of suspicious securities-account activity.

Federal Decree-Law No. 6 of 2025 on the Central Bank (regulatory background)

Federal Decree-Law No. 6 of 2025 is the Central Bank law governing the licensing and supervision of financial institutions. It is not the AML statute, but it sits in the overarching framework because it underpins the wider UAE financial system that capital market firms interact with, from settlement banks to custodians. For a CMA-regulated brokerage or fund manager, it matters mainly at the perimeter: knowing which counterparties are Central Bank-licensed, and how the two supervisory regimes, the CMA under Federal Decree-Law No. 32 of 2025 and the Central Bank, fit together across the sector.

goAML FAQs, April 2024

The goAML FAQs, version 2.1 dated 18 April 2024, are a practical question-and-answer guide from the UAE Financial Intelligence Unit helping reporting entities use the goAML reporting system and its registration and access services. It addresses common registration and login problems with step-by-step remedies, including expired one-time passwords at first login, pop-up authentication requiring the system-issued username with a Google Authenticator passcode, the correct login sequence, and resetting a forgotten password. It sets out where to enter credentials and who to contact when errors persist. For dealers, managers, advisers and custodians, reliable goAML access underpins timely suspicious reporting, so this guidance keeps compliance teams connected without avoidable delays.

PF Institutional Risk Assessment Guidance for FIs, DNFBPs and VASPs, December 2023

Published in December 2023, this guidance sets out how firms should assess and manage their exposure to proliferation financing. It explains a methodology built around inherent risks, control effectiveness and residual risks, and identifies the risk categories and factors institutions consider when scoring their business. It describes supporting measures, covering client onboarding, know your customer and due diligence, enhanced due diligence, screening for sanctions and adverse media, ongoing and transaction monitoring, and suspicious activity reporting. A customer risk scoring questionnaire, elevated risk factors and worked case studies show how scores are applied. For a brokerage or fund manager, it turns proliferation financing obligations into a repeatable framework that supervisors can review.

Terrorist and Proliferation Financing Red Flags Guidance, December 2023

Updated in December 2023, the Terrorist and Proliferation Financing Red Flags Guidance gives a consolidated set of indicators to help firms detect suspicious financing and evasion of targeted financial sanctions imposed under United Nations resolutions or local designations. It explains how sanctioned parties disguise involvement through renaming, intermediaries and front companies, useful when screening the beneficial owners behind corporate brokerage and fund clients. Indicators are grouped by customer profile, account, transaction activity, maritime and trade finance. For dealers, managers, advisers and custodians, it sharpens front-line and compliance awareness, supporting decisions on when securities dealing or account activity should trigger a report to competent authorities.

Suspicious Activity and Transaction Reporting Thematic Review, January 2023

Issued in January 2023, this Suspicious Activity and Transaction Reporting Thematic Review sets out key findings and regulatory expectations from the 2022 AML/CFT examination of licensed financial institutions and designated non-financial businesses and professions. It focuses on the suspicious transaction and activity reporting framework and the transaction monitoring systems that feed it, read alongside existing guidance on reporting and on monitoring and screening. It is organised around expectations with acceptable and deficient practices across governance, policies, risk-based monitoring controls, data management, alert review, case investigation, reporting decisions and the post-reporting process. For a brokerage or fund manager, it is a practical benchmark for testing, monitoring and reporting before inspection.

Counter Proliferation Financing Guideline, November 2022

Published in November 2022 by the Executive Office for Control and Non-Proliferation, this guideline supplements the wider Guidance on Targeted Financial Sanctions and raises awareness of proliferation financing threats among regulated firms. It explains what proliferation financing means, sets out its stages, and describes the UAE counter-proliferation framework, the interagency mechanism and the relevant federal laws. For a securities house, fund manager or custodian, it shows how to fold proliferation financing risk into the firm’s own risk assessment and apply mitigating measures, including enhanced due diligence on clients and transactions, scrutiny of shell and front companies, dual-use trade exposure and staff training. Red flags help detect sanctions evasion.

goAML Web Submission Guide, July 2022

The goAML Web Submission Guide, issued by the UAE Financial Intelligence Unit in July 2022, sets out how to submit a report to the FIU through the goAML platform. It is addressed to the designated Compliance Officer or Money Laundering Reporting Officer of a registered reporting entity, or the deputy where the lead officer is unavailable. It gives an overview of report types, including the Suspicious Transaction Report and the Suspicious Activity Report, the latter covering suspected activity or an attempted, non-executed transaction, alongside the Additional Information File, Request for Information and High Risk Country reports. For dealers, managers, advisers and custodians, it standardises how suspicions are reported promptly.

Joint Guidance on Combating the Use of Unlicensed Virtual Asset Providers, March 2022

Issued in March 2022, this joint guidance from the UAE Supervisory Authorities, including the Securities and Commodities Authority and the Central Bank, addresses the risks posed by providers operating outside the licensing regime. It reminds regulated firms of their anti-money laundering obligations and urges the public to deal only with licensed entities. It sets expectations to stay vigilant, factor emerging risks into risk assessments, conduct adequate due diligence, identify clients who seek out unlicensed providers, and report suspicions. Red flags include the absence of a regulatory licence, no physical presence, unrealistic promises or Ponzi schemes, and pressure to invest quickly. For a brokerage, it sharpens the screening of exposed client flows.

IEMS User Guide for Reporting Entities, March 2022

Dated March 2022, the IEMS User Guide for Reporting Entities is a practical manual from the UAE Financial Intelligence Unit for its Integrated Enquiry Management System, which automates information requests, the implementation of public prosecutions’ decisions and other requests from domestic authorities. It explains how firms register and log in, noting that entities already on the goAML system reuse the same credentials. It walks through the dashboard, request management and the reply and attachments workflow, covering account, account holder and signatory details, sets out the Admin, Maker and Checker roles, and stresses meeting due dates and implementing freeze orders immediately. For a securities firm, it shows how enquiries are handled.

goAML Pre-Registration Guide, March 2022

The goAML Pre-Registration Guide, issued by the UAE Financial Intelligence Unit in March 2022, explains how reporting entities secure access to the Services Access Control Manager, or SACM, before reaching the goAML application to register and file suspicious reports. The application is available through a public portal for entities not regulated by the Central Bank, with others following their Supervisory Body’s steps. SACM hosts links to the production and testing environments, controlled by a time-based one-time password from Google Authenticator. It covers pre-registration, confirmation of intent and safeguarding a personal Secret Key. For dealers, managers, advisers and custodians, correct pre-registration is a prerequisite for secure reporting access.

goAML Registration Guide, March 2022

The goAML Registration Guide, issued by the UAE Financial Intelligence Unit in March 2022, sets out the steps an organisation follows when registering with the FIU on its reporting platform. It applies to registration as a reporting entity, stakeholder or supervisory body, confirming that every accountable and reporting entity in the United Arab Emirates, whatever its regulator, must register to submit suspicious reports. It explains reaching the portal through the Services Access Control Manager, then selecting the registration type, entering the organisation and addresses, adding the registering person and setting user access rights. For dealers, managers, advisers and custodians, correct registration is the foundation of compliant, timely reporting.

Strategic Review on Targeted Financial Sanctions Case Studies, November 2021

Dated November 2021, this Strategic Review on Targeted Financial Sanctions Case Studies examines sanctions reporting in the UAE over the period reviewed. It sits within the framework under which the country, through Cabinet Resolution No. 74 of 2020, implements United Nations Security Council Resolutions on terrorism, terrorist financing and the financing of proliferation, including freezing measures and prohibitions on providing funds and services. The review explains its methodology, then classifies sanctions reports by source, by suspicion and by the instruments involved, drawing out patterns that distinguish terrorist financing from proliferation financing and presenting red flags and recommendations. For a brokerage, it shows how sanctions suspicions arise and are reported.

Typologies on the Circumvention of Targeted Sanctions, November 2021

Last amended in November 2021 and issued by the Executive Office, this typologies report compiles cases showing how sanctioned persons and entities attempt to circumvent targeted sanctions relating to terrorism and the proliferation of weapons of mass destruction. Drawing on public sources from the UAE and abroad, it presents methods used to evade United Nations resolutions and the national terrorist list. Typologies are grouped by channel and sector, covering online payment facilities, trade in dual-use goods, elaborate legal entity structures, cyberactivity and economic resources, illustrated with named networks and red flags. For dealers, managers, advisers and custodians, it turns evasion tactics into practical learning for screening, due diligence and monitoring.

Update to the List of High Risk Jurisdictions, November 2021

This November 2021 decision of the National Anti-Money Laundering Committee updates the list of high-risk jurisdictions subject to a call for action, the list of jurisdictions under increased monitoring and the counter-measures to apply, superseding an earlier March 2021 decision. Addressed to the supervisory authorities and the Financial Intelligence Unit, it reflects the Committee’s mandate to identify countries with weak controls, set proportionate counter-measures and direct supervisors to ensure the required due diligence is applied. For dealers, managers, advisers and custodians, country risk is a core input to controls, signalling which jurisdictions warrant enhanced due diligence on investors and securities flows and requiring risk assessments to track the latest listings.

Joint Guidance on Satisfactory and Unsatisfactory Practice, June 2021

Issued in June 2021, this joint guidance from the UAE Supervisory Authorities, including the Securities and Commodities Authority, the Central Bank and the Ministries of Justice and Economy, draws on themes seen during supervisory inspections between January 2020 and May 2021. It contrasts satisfactory and unsatisfactory practices across the anti-money laundering framework, targeted financial sanctions and counter-proliferation financing. For a brokerage or fund manager, it addresses governance and management oversight, risk assessment, three lines of defence, policies, training and the compliance officer role, alongside client onboarding, monitoring, risk rating, due diligence, transaction monitoring, sanctions screening and reporting. It turns inspection findings into concrete examples, helping firms benchmark controls beforehand.

Typologies on the Circumvention of TFS, PF and WMD, May 2021

Last amended in May 2021 and issued by the Executive Office, this typologies report examines how sanctioned persons and entities obtain financing in violation of or evasion of United Nations resolutions on terrorism and the proliferation of weapons of mass destruction. It explains that targeted financial sanctions cover both asset freezing and prohibitions on making funds or assets available, directly or indirectly, to designated parties. Organised by financing method, it addresses trade in goods, economic resources, online payment facilities, cyberactivity against financial institutions and the misuse of legal entities or arrangements, closing with red flags. For dealers, managers, advisers and custodians, it strengthens the screening, monitoring and reporting of attempted circumvention.

goAML FAQs, September 2020

The goAML FAQs Guide, issued by the UAE Financial Intelligence Unit in September 2020, is a practical question-and-answer reference for reporting entities using the goAML platform, through which suspicious reports are filed in the United Arab Emirates. It compiles the queries most commonly raised once an organisation is registered and active, with step-by-step responses. It explains resetting a forgotten password, updating organisation details such as name, licensed activity, address and contacts, and how the Money Laundering Reporting Officer, as admin, delegates reporting to a third party subject to Supervisory Body approval. For dealers, managers, advisers and custodians, accurate registration data and managed access underpin compliant, uninterrupted reporting to the FIU.

goAML Registration Guide Stage 2, September 2020

The goAML Registration Guide Stage 2, issued by the UAE Financial Intelligence Unit in September 2020, outlines the steps an organisation follows when registering with the FIU on its reporting platform. It applies to registration as a reporting entity, stakeholder or supervisory body, confirming that every accountable and reporting entity in the United Arab Emirates must register to submit suspicious reports, and noting that since 27 June 2019 such reports must be filed electronically through goAML. It covers reaching the portal through the Services Access Control Manager, selecting the registration type and registering an organisation. For dealers, managers, advisers and custodians, proper registration is the gateway to lawful electronic reporting.

Guideline on Grievance Procedures

The Guideline on Grievance Procedures comes from the Executive Office for Control and Non-Proliferation, the authority that receives grievance requests linked to the UAE Local Terrorist List and the United Nations Consolidated List, together the Sanctions Lists. Under Cabinet Resolution No. 74 of 2020, three types are handled: de-listing of a designation, cancellation of freezing measures, and permission to use frozen assets, each distinguished by whether the designation sits on the Local or United Nations List. For a brokerage, fund manager or custodian, it maps the lawful routes an affected client may use to challenge a designation or seek access to frozen securities and funds.

Online Grievance System User Guide

The Online Grievance System User Guide comes from the Executive Office for Control and Non-Proliferation, which receives grievance requests tied to the UAE Local Terrorist List and the United Nations Consolidated List, together the Sanctions Lists. Launched to streamline submissions, the system is explained step by step in this manual. It covers three online request types: de-listing, cancellation of freezing measures, and permission to use frozen funds. It walks the user through identifying the aggrieved individual or legal entity, selecting the grievance type, declaring earlier requests and appeals, and attaching documents. For a custodian, it explains how an affected client may challenge a designation or seek access to frozen assets.

Simple Guide to Subscribe to the EOCN Notification Alert System (NAS)

This short guide explains how to subscribe to the Notification Alert System operated through the Executive Office’s website, so users receive timely updates to the sanctions lists applied in the UAE. Targeted financial sanctions rest on designations across two lists, together the Sanctions Lists: the UAE Local Terrorist List issued by the Cabinet and the United Nations Consolidated List issued by the Security Council, each updated periodically. It shows where the lists can be accessed and gives step-by-step subscription instructions, from the webpage to entering details and confirming. For a securities firm, this supports a core control: screening works only against current lists.

Emerging ML, TF and PF Risks and Trends in the Financial Sector

Issued by the Supervisory Subcommittee under Article 16 of Federal Decree-Law No. 10 of 2025, this report gives regulated firms a current view of the money laundering, terrorist financing and proliferation financing threats reshaping the financial sector amid technological change, geopolitical shifts and evolving criminal methods. After setting out the scope and methodology, it examines emerging risks such as artificial intelligence exploitation, greenwashing and ESG-related fraud, trade finance abuse, and sanctions evasion linked to the Commonwealth of Independent States. Case studies cover money mule networks, trade-based laundering, free-zone corporate structures and fraudulent green schemes. Brokers and asset managers should feed these typologies and red flags into risk assessments and detection systems.

Typologies in the Financial Sector

Typologies in the Financial Sector is a joint report by the Supervisory Authorities Sub-Committee and the Financial Intelligence Unit, prepared with the Executive Office and a pilot group of institutions. It shares money laundering, terrorist financing, sanctions, fraud and corruption typologies observed in the market, several arising during the COVID-19 period, to help firms anticipate emerging risks. Sitting above the National Risk Assessment, it describes risk indicators that combine to obscure the true nature of transactions and flags links to modern slavery and human trafficking. For dealers, asset managers, advisers and custodians, it works as an early-warning tool for updating risk assessments, refining monitoring scenarios and engaging authorities.

NRA, SRA, and Other Important Guidelines for the Capital Market Sector in the UAE

The UAE assesses its money laundering, terrorist financing, and proliferation financing risk at the national level, and capital market firms must align their own business and enterprise-wide risk assessments with those findings.

UAE PF National Risk Assessment 2026

The UAE Proliferation Financing National Risk Assessment 2026 examines exposure to the financing of weapons of mass destruction and the evasion of targeted financial sanctions under United Nations resolutions on North Korea and Iran. Prepared in response to the Financial Action Task Force’s revised Recommendation 1, it rates the securities sector low for proliferation financing in both the mainland and the financial free zones. It sets an overall country risk of medium-high. Banks, exchange houses and registered hawala providers are rated medium-high in the mainland, and maritime insurance is rated medium. For dealers, managers, advisers and custodians, it clarifies where risk concentrates and should inform screening and due diligence.

The table below summarises the residual risk ratings that the capital market sector should reflect in its own risk assessment.

UAE ML and TF National Risk Assessment 2024

The UAE Money Laundering and Terrorist Financing National Risk Assessment 2024 is the country’s second such assessment, prepared using the World Bank methodology and drawing on data from 2019 to 2023. It rates the securities sector’s residual money laundering risk in the medium to medium-high range, reflecting its diverse activities, while noting effective AML controls across the sector, and it covers both the mainland and financial free zones. Among other sub-sectors, banking and exchange houses are rated medium-high, registered hawala providers high, and finance companies and insurance medium. Overall, the national money laundering residual risk is medium-high. For dealers, managers, advisers and custodians, it sets the baseline informing their risk-based approach.

Assessment  Capital market (securities) sector residual risk 
Money laundering and terrorist financing (NRA 2024)  Medium to medium-high, with the sector’s AML controls assessed as effective 
Proliferation financing (PF NRA 2026)  Low in both the mainland and the financial free zones 
Sr Sub-Sector Residual ML Risk as per NRA 2024 
1 

Market Institutions and 

Brokers 

Medium-High 
2 

Investment Management  

 

Medium 
3 

Forex Companies  

 

Medium-High 
4 

Advisors and Promoters 

 

Medium 

Alongside the national assessments, sector risk assessments, red flag guidance, and typologies reports give capital market firms the detail they need to keep their enterprise-wide risk assessment current and defensible.

CMA-Regulated Capital Market Sector-Specific Guidance

Beyond the federal framework, the Capital Market Authority issues the rulebook, guidance, notices, and reporting standards that govern AML in the sector. The documents below make up that set.

A note on transition: the Capital Market Authority is the legal successor to the Securities and Commodities Authority under Federal Decree-Law No. 32 of 2025, so references to older SCA decisions, notices and guidance below should be read as references to the CMA where they remain in force, and subject to Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025.

Federal Decree-Law No. 32 of 2025 on the Capital Market Authority

Federal Decree-Law No. 32 of 2025 on the Capital Market Authority establishes the Capital Market Authority, successor to the Securities and Commodities Authority, as the federal regulator of securities, markets, central clearing and central depository institutions across the mainland and free zones, excluding the Financial Free Zones. It defines Licensed Persons, Approved Persons and Self-Regulatory Organisations, and gives the Authority objectives including market integrity and efficiency, investor protection and mitigation of systemic risk. Article 5 grants powers to license, supervise and inspect firms conducting financial activities, issue rules, impose sanctions and cooperate with relevant authorities. For broker-dealers, fund managers, advisers and custodians, it is the constitutional foundation of supervision.

Federal Decree-Law No. 33 of 2025 on the Regulation of the Capital Market

Federal Decree-Law No. 33 of 2025 on the Regulation of the Capital Market is the substantive rulebook governing securities activities under the Capital Market Authority. Article 3 lists the financial activities requiring a licence, spanning market operation, central clearing, central depository and custody services, dealing, asset management, investment funds and advisory work. It prohibits conducting these activities or performing approved functions without authorisation, and defines securities, issuers, foreign issuers, investment funds, insiders and inside information. The law restricts insider dealing and imposes prohibited dealing periods on those listed on the Market, protecting investors from market abuse. It also frames the settlement, restructuring and liquidation of Licensed Persons.

CMA Key AML/CFT/CPF Obligations, Risks and Supervisory Observations, 2025

This 2025 Capital Market Authority letter to Chief Executive Officers sets out Key AML/CFT/CPF Obligations, Emerging Risks and Supervisory Observations for securities firms. During the 2025 supervision cycle, the CMA ran its annual risk assessment across the sector, gauging inherent money-laundering, terrorist-financing and proliferation-financing risk against each firm’s nature, scale, customer base, products, delivery channels and geographic exposure, informed by the FATF Recommendations and the UAE National Risk Assessment. Through onsite inspections, desk-based reviews, MLRO report reviews and thematic work, it identified recurring deficiencies requiring remediation under board governance. It reminds broker-dealers and asset managers to track suspicious-reporting trends, sanctions-screening outcomes and beneficial-ownership data, warning of Article 17 enforcement.

CMA Instructions for the 2024 Annual Return AML/CFT and TFS Risk Assessment

The CMA Instructions for the 2024 Annual Return set out how licensed securities firms complete their AML, CFT and targeted financial sanctions risk assessment return. Broker-dealers, fund and asset managers, custodians and investment advisers report across five tabs: customer risk, products and services risk, distribution channel risk, controls and the quality of risk mitigation, and signatories. The Capital Market Authority requires full completion, monetary values in dirhams, and country breakdowns using standard country names or codes. The return captures inherent risk from investors, securities business, correspondent relationships, payment forms and onboarding channels, alongside controls covering the compliance officer, enhanced due diligence, transaction monitoring, sanctions screening and internal audit.

CBUAE AML and CFT Guidelines for Financial Institutions, July 2023

These CBUAE Anti-Money Laundering and Combating the Financing of Terrorism Guidelines for Financial Institutions, dated July 2023, are general financial-institution guidance that the Capital Market Authority points its firms toward for detailed expectations. Grounded in Federal Decree-Law No. 10 of 2025 and its implementing regulation, they explain the risk-based approach, business-wide risk assessment across customer, geographic, product and delivery-channel factors, and mitigation through internal controls and customer due diligence, including beneficial-owner identification, wire transfers and ongoing monitoring. For broker-dealers, fund managers, custodians and advisers, they translate statutory obligations, typologies and reporting duties into practical benchmarks that reinforce sound onboarding, screening and monitoring of investors and securities accounts.

CMA Minimum Standards for the Semi-Annual AML and CTF Report, 2023

These CMA Minimum Standards, dated 2023, guide the semi-annual Compliance Officer and Money Laundering Reporting Officer reports for securities firms, framed under Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025. Broker-dealers, fund managers and custodians must prepare bi-annual reports for the periods ending 30 June and 31 December, review them at board level, and submit a copy with the Board’s comments to the Capital Market Authority within two months of each period end. The prescribed structure runs from an executive summary through governance, the enterprise-wide risk assessment, policies, customer risk rating and due diligence, a gap analysis, action plan, findings and board approval.

CMA Implementation of Targeted Financial Sanctions, May 2022

CMA Notice 1/2022, dated 19 May 2022, directs all licensed financial institutions to implement Targeted Financial Sanctions under UN Security Council Resolutions 1718 (2006) and 2231 (2015), pursuant to Cabinet Resolution No. 74 of 2020. Broker-dealers, asset managers and custodians must screen every party to a financial transaction, apply enhanced due diligence to dealings linked to relevant countries, and verify cross-border flows suspected of unauthorised trade in dual-use goods. Confirmed matches require a Funds Freeze Report through goAML within five business days, potential matches a Partial Name Match Report, and suspicious activity an STR to the Financial Intelligence Unit. Firms should consult Executive Office guidance and prevent sanctions evasion.

CMA Awareness of Cabinet Resolution No. 111 of 2022 on Virtual Assets and their Service Providers

Cabinet Resolution No. 111 of 2022 regulates virtual assets and virtual asset service providers in the UAE, setting the federal framework that sits alongside the securities regime. For capital market firms, it matters wherever a product, custodian or client touches virtual assets: it defines VASP activities, licensing and the supervisory perimeter, and feeds the enhanced due diligence and reporting a securities or fund business must apply to virtual-asset exposure. It anchors the CMA’s own virtual-asset expectations and the UAE travel rule that follows.

CMA Thematic Review on Reliance on Third Parties, December 2021

This second CMA thematic review, dated December 2021, examined the five firms licensed for custody of securities, all banks or local branches of foreign banks holding Central Bank licences, testing compliance with FATF Recommendation 17 on reliance on third parties. Because custodians safeguard investors’ securities and cash and serve largely institutional and offshore clients, they frequently outsource customer due diligence. A twenty-one-question survey drew a hundred per cent response: four of five engaged third parties, two within their financial group and two external, all regulated or listed entities governed by service level agreements. Reasons cited were cost, specialist skills and technology; ultimate due diligence responsibility remains with the custodian.

CMA Thematic Review of Targeted Financial Sanctions in the Capital Market Sector, November 2021

This CMA thematic review, dated November 2021, assessed how securities brokerage firms understand and comply with Targeted Financial Sanctions, international and domestic, under Cabinet Resolution No. 74 of 2020. Brokers, the gateway for capital market investors and rated medium-high vulnerability in the National Risk Assessment, answered a twenty-nine-question survey with a ninety-six per cent response rate. Findings show sixty-five per cent ran separate sanctions risk assessments, seventy per cent used third-party screening systems, and eighty-one per cent screened daily; one firm found, reported and froze a match in 2021. Good practices cover senior-management approval, verifying vendor coverage of domestic lists, clear reporting responsibilities and Executive Office monitoring.

CMA AML and CFT Guidance for the Capital Market Sector, September 2021

The Capital Market Authority AML/CFT Guidance for the Capital Market Sector, dated September 2021, supplements the main Financial Institutions Guidelines and sets out the Securities and Commodities Authority’s expectations for firms it licenses. It applies to boards, management and employees of institutions carrying out securities activities in the UAE, read with those wider guidelines. Part 1 surveys sector typologies, including trade-based money laundering through mis-invoicing and misrepresentation of price, quantity or quality, and cash-based laundering, with red-flag indicators. Parts 2 and 3 explain the risk-based approach, business-wide risk assessment and the customer, product, delivery-channel and geographical risk factors that brokers, asset managers and advisers must identify, assess and mitigate.

CMA Notice 3/2021 on the Immediate Reporting Mechanism

Notice 3/2021, dated 26 July 2021, addressed all licensed entities and licensed securities and commodities exchanges on the immediate reporting mechanism for financial institutions implementing Cabinet Resolution No. 74 of 2020 on Terrorism Lists Regulation and the implementation of UN Security Council Resolutions on suppression of terrorism, terrorist financing and proliferation of weapons of mass destruction. Referring to Article 21, clause 5, it advised that the goAML system had been upgraded with a new feature so that reports on matched names and actions taken pass directly to the Executive Office for goods subject to import and export control. Broker-dealers, fund managers and custodians must update policies and implement the process.

CMA Notice 4/2021 on Targeted Financial Sanctions Reporting

Notice 4/2021, dated 4 August 2021, addressed all licensed entities and licensed securities and commodities exchanges on Targeted Financial Sanctions reporting, following the earlier 26 July notice. Under Cabinet Resolution No. 74 of 2020, the Central Bank of the UAE, coordinating with the Executive Office of the Committee for goods subject to import and export control, established a unified mechanism using the Financial Intelligence Unit’s goAML platform. It introduced two reports: the Funds Freeze Report for a confirmed match, requiring freezing within two business days, and the Partial Name Match Report for a potential match, requiring suspension. Broker-dealers, fund managers and custodians report simultaneously to the Executive Office and Authority. These notices predate the March 2026 sanctions guidance, so current goAML filings use the renamed Confirmed Name Match Report and the Partial Name Match Report; older notices should be read with that change in mind.

CMA Notice 6/2021 on the Update to High Risk Jurisdictions

CMA Notice 6/2021, dated 22 November 2021, updates the National Committee’s lists of High Risk Jurisdictions subject to a Call for Action and Jurisdictions under Increased Monitoring for all licensed entities and securities and commodities exchanges, superseding Notice 1/2021. Broker-dealers, fund managers, custodians and advisers must apply enhanced due diligence to relationships and transactions touching listed countries, adopt the Recommendation 19 countermeasures for the Black List, and refresh geographic risk scoring for investors. Firms are prohibited from relying on third parties based in Black List jurisdictions, must file High Risk Jurisdiction reports through goAML, and re-evaluate measures where countries are delisted, proportionate to securities-account risk.

SCA Board Chairman's Decision No. 21 of 2019 on AML and CFT Procedures

The SCA Board Chairman’s Decision No. 21/Chairman of 2019, issued on 8 May 2019 and active from 7 May 2019, applied anti-money laundering, counter-terrorism financing and illegal-organisations financing procedures to the capital market. Signed by Sultan bin Saeed Al Mansouri, it required every financial entity licensed or approved by the Securities and Commodities Authority, and its stakeholders, to comply with Federal Decree-Law No. 10 of 2025, its executive regulation under Cabinet Resolution No. 134 of 2025, and the Authority’s instructions, guidelines and circulars. It empowered the Authority to supervise and inspect firms without notice, demand information, and impose administrative sanctions on brokers, fund managers and other market participants.

CMA Guidelines for Combating Money Laundering and Terrorist Financing (Chapter Five)

Chapter Five of the Capital Market Authority rulebook sets out the Guidelines for Combating Money Laundering, Counter-Terrorism Financing and Funding of Illegal Organisations. It provides mandatory standards requiring each supervised firm to build a compliance programme tailored to its activities, risk profiles and controls, read with Federal Decree-Law No. 10 of 2025. The chapter defines suspicious transactions, ultimate beneficial owners and targeted financial sanctions, and directs firms to apply a proportionate risk-based approach to customer due diligence, focusing resources on higher-risk clients. It fixes board and senior-management responsibility, mandates suspicious-activity reporting as a legal duty, and covers screening, record-keeping and training that broker-dealers, fund managers and custodians must embed operationally. To the extent Chapter Five still refers to the 2025 framework, those references should now be read in light of Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025.

CMA AML and Financial Crimes Framework and Controls: Good and Weak Practices

Prepared by Mendy Ghaleb of the Capital Market Authority’s AML and Financial Crimes Department, this presentation contrasts good practices and common weaknesses in AML and financial-crime frameworks and controls. It anchors expectations in Federal Decree-Law No. 10 of 2025, Cabinet Resolution No. 134 of 2025, and the beneficial-owner, terrorism-list and sanctions decisions, alongside Chapter 5 of the CMA Rulebook. Through field inspections and desk-based analysis it flags recurring failings for securities firms, including generic business-wide risk assessments misaligned with activities, template risk-appetite statements without thresholds, and copied policies with limited board oversight. Under Article 17, the CMA may issue warnings, fines to AED 5,000,000, sector bans and licence revocation.

CMA Obligations to Implement the Business-Wide Risk Assessment (BWRA)

This Capital Market Authority material explains a securities firm’s obligation to implement a Business-Wide Risk Assessment, described as a fundamental, strategic discipline for an effective AML and CFT compliance framework. The BWRA requires firms to identify, understand and assess the full spectrum of money-laundering, terrorist-financing, targeted-financial-sanctions and proliferation-financing risks, examining client types, products, delivery channels, geographic locations and new technologies. It runs in three phases: planning and scoping across business units, legal entities, divisions and regions; implementation, assessing inherent risk with empirical data and designing controls; and results, defining residual risk against a risk-appetite statement with action plans. Broker-dealers, fund managers and custodians must keep it dynamic and updated.

CMA Thematic Review of Screening Systems

This CMA Thematic Review of Screening Systems, a market-wide horizontal assessment, examined name and transaction screening across the UAE capital market sector under Federal Decree-Law No. (10) of 2025 and FATF standards. The Capital Market Authority tested forty-six screening systems at twenty-six Licensed Financial Institutions using control, variation and clean datasets covering United Nations and UAE sanctions lists. Systems were widely embedded across broker-dealer, fund and custody onboarding and monitoring and identified clear matches well, but performance varied under complex scenarios such as spelling differences and Arabic-Latin transliteration. Elevated alert volumes signalled tuning opportunities. Supervisory expectations stress calibration, governance, management information, defined metrics like false positive rates, and ongoing optimisation.

CMA Questions and Answers on the National Risk Assessment

These CMA Questions and Answers explain how securities firms should align their Enterprise-Wide Risk Assessment with the 2024 National Risk Assessment. Broker-dealers, fund managers, custodians and advisers must map NRA typologies to their business, such as onboarding offshore special purpose vehicles, layering through securities trading, weak beneficial-owner documentation and misuse of layering and shell companies. Even low-risk firms must review the NRA, document relevance and reassess annually. The Capital Market Authority expects an audit trail: a date-stamped updated assessment, revised onboarding, screening and third-party reliance policies, staff training logs, board minutes and a gap analysis. Firms must reflect changes in the annual AML Return and evidence real implementation.

CMA Circular on the Examination Observations Report

This CMA circular reports examination observations drawn from securities firms’ annual AML/CFT and sanctions risk assessment returns, assessed under a risk-based approach against Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025. The Capital Market Authority found common shortcomings: outdated governance policies, weak testing of sanctions controls, incomprehensive risk assessments, gaps in customer due diligence and beneficial-ownership understanding of investors, incomplete sanctions compliance programmes lacking the eight essential components, and poor suspicious-transaction procedures. Firms should remediate, involve the board and auditors, and maintain adequate oversight. Non-compliance may trigger enforcement, including administrative penalties from AED 50,000 to AED 5,000,000 per violation and licence cancellation.

UAE Virtual Assets Travel Rule

The UAE Virtual Assets Travel Rule applies to virtual asset service providers across the federal, emirate and free-zone space, requiring originator and beneficiary information to travel with virtual-asset transfers. Capital market firms dealing in or advising on virtual-asset products, or holding them in custody, use it to understand the information that must accompany transfers and the risk-based and enhanced due diligence expected. It aligns the UAE with the FATF travel-rule standard and shapes how a securities business documents and screens virtual-asset movements.

CMA Chapter Five Outreach

Chapter Five Outreach explains the CMA’s Chapter Five Regulations for combating money laundering, terrorism financing and the financing of illicit organisations in plain, presentation form. It walks capital market firms through the mandatory standards, their grounding in federal AML law, and how the CMA expects brokerages, custodians and fund managers to apply them day to day. As an outreach companion to the binding Chapter Five guidelines, it is a practical reference for onboarding, monitoring and reporting across the securities sector.

CMA and FIU Joint Awareness Session on Suspicious Reporting Effectiveness

Delivered by the Capital Market Authority’s AML and Financial Crimes Department with the Financial Intelligence Unit, this joint session focuses on the effectiveness of suspicious reporting by capital market firms. It restates the key legislation, the obligations of financial institutions and the internal controls and governance the CMA expects, then presses on report quality: filing complete, timely and well-reasoned suspicious transaction and activity reports through goAML rather than defensive or low-value submissions. For a securities or fund business it sharpens what good reporting looks like.

CMA Examination Observations, Appendix of Detailed Findings

This appendix accompanies the CMA and Securities and Commodities Authority examination observations, collecting the detailed findings behind the headline review. It sets out, area by area, the weak and better practices inspectors saw across capital market firms, from governance and risk assessment to screening and reporting. For a brokerage or fund manager it doubles as a self-assessment checklist: read against your own programme, it flags the specific control gaps the regulator has already penalised in the sector.

Core AML Obligations for Capital Market Firms at a Glance

Whatever the licence, the AML regulations for capital market firms in the UAE turn on a common set of duties.

  • A business and enterprise-wide risk assessment aligned to the national risk assessments, submitted through the Capital Market Authority’s annual return.
  • Customer due diligence on investors and clients, and, for higher-risk relationships, enhanced due diligence, including source of funds for subscriptions and trades.
  • Ongoing monitoring of trading and settlement, and sanctions screening of clients and beneficial owners.
  • Suspicious transaction and activity reporting through goAML, an MLRO, and the Authority’s semi-annual and annual AML reporting.
  • Identifying the ultimate beneficial owner of corporate and pooled investors.
Control area  What CMA-regulated firms should evidence 
Business and enterprise-wide risk assessment  Risk assessed by customer, product, geography, delivery channel and new technology, aligned to the national risk assessments 
Investor onboarding  Customer identity, beneficial ownership, and source of funds and wealth for subscriptions and trades where relevant 
Sanctions screening  Screening of clients, prospective investors, beneficial owners and counterparties against the UAE Local Terrorist List and the UN Consolidated List 
Transaction monitoring  Monitoring of trading, settlement, subscriptions, redemptions and unusual investor activity 
Third-party reliance  A written reliance framework and audit trail, with final responsibility retained by the firm 
MLRO and reporting  Semi-annual AML and CTF report, annual AML, CFT and TFS return, and suspicious reporting through goAML 
Record keeping and governance  Records retained and retrievable for inspection, with board approval, risk appetite and compliance independence 

Practical Compliance Note:

Capital Market Authority supervisory materials and thematic reviews show recurring attention to sanctions-screening effectiveness and reliance on third parties for customer due diligence. Capital market firms should document how their screening system is calibrated and tested, how potential matches are handled, and the point at which reliance on an introducer ends and the firm’s own due diligence resumes.

Conclusion

AML regulations for capital market firms in the UAE run on two tracks: the federal AML law that applies to every financial institution, and the Capital Market Authority’s own rulebook, guidance, and reporting regime on top. Broker-dealers, fund and asset managers, investment advisers, and custodians all sit inside that framework, supervised by the Authority rather than the Central Bank. The sector’s money laundering risk is rated in the medium range with effective controls, and its proliferation financing risk is low, but the reporting and examination expectations are demanding. Use the national risk assessments to calibrate, and read across to our guide to anti-money laundering laws in the UAE and the pillar on AML regulations for banks and financial institutions in the UAE.

Frequently Asked Questions

Which capital market firms are subject to AML rules in the UAE?

Broker-dealers, fund and asset managers, investment advisers, custodians, and other market intermediaries licensed by the Capital Market Authority are financial institutions under Federal Decree-Law No. 10 of 2025 and must run a full AML programme. Firms in the DIFC and ADGM are supervised separately by the DFSA and FSRA.

The Capital Market Authority, established under Federal Decree-Law No. 32 of 2025 as the successor to the Securities and Commodities Authority, supervises AML compliance for capital market firms outside the financial free zones. It issues the sector rulebook and guidance and runs examinations and thematic reviews.

Firms must maintain a business-wide risk assessment, perform customer due diligence and enhanced due diligence on investors and beneficial owners, screen against sanctions lists, monitor trading and settlement, keep records, and report suspicious activity through goAML. The Authority pays particular attention to screening systems and reliance on third parties.

Yes. Firms must appoint a money laundering reporting officer, file suspicious transaction and activity reports through goAML, and submit the Capital Market Authority’s semi-annual AML and CTF report and annual AML/CFT and TFS risk assessment return.

Virtual asset service providers sit under a separate framework, distinct from the securities regime covered here: the federal CMA regime applies outside the financial free zones and works alongside local licensing authorities, including Dubai’s Virtual Assets Regulatory Authority. Firms with that exposure should refer to our dedicated guide to AML for VASPs outside Dubai, which addresses that demand in full.

Yes, where they remain in force and are not inconsistent with the 2025 framework. The Capital Market Authority is the legal successor to the Securities and Commodities Authority under Federal Decree-Law No. 32 of 2025, so older SCA decisions, notices and guidance are read as CMA materials, subject to Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025.

Yes. The Capital Market Authority requires a business-wide or enterprise-wide risk assessment covering customer, product, delivery-channel, geographic, targeted financial sanctions, proliferation financing and new-technology risks, aligned to the UAE national risk assessments and reflected in the Authority’s annual AML return.

Need help building or reviewing your capital market firm AML programme?

Get expert support to develop a robust AML programme that protects your business, manages risk, and meets regulatory expectations.

Share via :

About the Author

Pathik Shah

FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)

Pathik is an ACAMS-certified AML consultant specialising in governance, risk, and compliance for regulated entities in the UAE. He brings over 28 years of experience, with 1,000+ hours of AML training and 200+ advisory engagements across DNFBPs, VASPs, and FIs. He supports businesses in aligning with AML/CFT requirements from the CBUAE, DFSA, MoET, MoJ, VARA, CMA, FSRA, and FATF. Known for translating complex regulations into audit-ready procedures, Pathik enables operational clarity and compliance readiness.

Reach Out to Pathik

AML Regulations for Exchange Houses in UAE

AML Regulations for Exchange Houses in UAE

Blogs

Published On: 07/13/2026

Table of Contents

Protect your business with reliable and effective AML strategies with AML UAE.

Last Reviewed On: 07/13/2026   |   Last Updated On: 07/13/2026

Key Highlights

  • Exchange houses are Licensed Financial Institutions under Federal Decree-Law No. 10 of 2025 and its Executive Regulations in Cabinet Resolution No. 134 of 2025, so CBUAE guidance for LFIs is relevant to them, some of it applying generally and some depending on the firm’s products, customers, corridors and delivery channels.
  • The Central Bank of the UAE is the primary AML/CFT/CPF supervisor for exchange houses, while the UAE FIU, the Executive Office and other competent authorities carry reporting, sanctions and enforcement roles. Money service businesses in the DIFC and ADGM answer to the DFSA and FSRA and sit outside this guide.
  • The sector’s residual money laundering risk is rated medium-high in the national risk assessment, driven by banknote shipments, reliance on foreign remittance partners, and third-party transactions.
  • The risks that matter most are structured cash at the counter, high-risk remittance corridors, and third-party senders and beneficiaries, so transaction monitoring and sanctions screening are central.
  • On top of the general LFI framework, the Central Bank issues guidance written specifically for exchange houses, including a dedicated typologies report on money and value transfer services.
  • Registered hawala providers are covered under their own framework, which we treat separately, and this article links across to it.

Exchange houses move money for millions of people in the UAE, sending remittances home for workers, exchanging currency, and trading banknotes at scale. That same speed, cash intensity, and cross-border reach are exactly what make the sector attractive to money launderers and sanctions evaders, which is why the Central Bank supervises it closely. This guide sets out the AML regulations for exchange houses in the UAE: who is in scope, who supervises them, the full legal framework that applies, and how the national risk assessments rate the sector’s money laundering, terrorist financing, and proliferation financing risk. It covers exchange houses and money transfer businesses licensed by the Central Bank of the UAE.

Exchange houses licensed by the Central Bank of the UAE must comply with the applicable UAE AML/CFT/CPF framework, including Federal Decree-Law No. 10 of 2025, Cabinet Resolution No. 134 of 2025, Cabinet Resolution No. 74 of 2020, the CBUAE exchange business standards, relevant CBUAE AML/CFT guidance, and UAE FIU goAML reporting requirements. The sector’s key AML risks are cash-intensive transactions, cross-border remittances, high-risk corridors, banknote shipments, third-party senders, and sanctions exposure.

Who counts as operating in the Exchange House Sector for AML purposes in the UAE?

An exchange house, for AML purposes, is a business licensed by the Central Bank of the UAE to carry on exchange business, whether that is currency exchange, remittance, or the wholesale movement of banknotes. The categories below all sit inside the AML regulations for exchange houses in the UAE. Registered hawala providers operate under a separate registration framework and are dealt with on their own page, and money service businesses in the DIFC and ADGM are supervised by the DFSA and FSRA and are not covered here.

Currency exchange and money changing

Firms that buy and sell foreign currency for retail and corporate customers, often on a walk-in, one-off basis, sit at the front of the sector. Their exposure runs through cash, rapid conversion between currencies, and customers the firm may deal with only once.

Remittance and money transfer

Outbound and inbound remittance is the sector’s highest-volume activity, moving value across borders through corridors that vary widely in risk. Reliance on foreign remittance partners, third-party senders and beneficiaries, and the Wage Protection System all shape the money laundering and sanctions risk here.

Wholesale banknote trading

Exchange houses that import and export physical banknotes in bulk carry a distinct risk, since large cross-border banknote shipments can be used to move value outside the transparent payment system.

AML Supervisory Authority for Exchange Houses in the UAE

The Central Bank is the primary supervisor for exchange houses, while other competent authorities carry reporting, sanctions and enforcement roles.

Central Bank of the UAE (CBUAE)

The Central Bank of the UAE licenses exchange houses, sets the exchange business standards they operate under, supervises their AML programmes, issues sector guidance, and inspects them. It can impose administrative and financial penalties, restrict activities, or withdraw a licence for breaches. It is the primary AML/CFT/CPF supervisor for the sector, working alongside the UAE FIU, the Executive Office for Control and Non-Proliferation and other competent authorities that carry reporting, sanctions and enforcement roles. Money service businesses established in the DIFC and ADGM are supervised instead by the DFSA and FSRA under their own AML rulebooks, while still operating within the wider UAE AML/CFT framework, and fall outside this guide.

UAE FIU and goAML

In-scope exchange houses must register on the UAE Financial Intelligence Unit’s goAML platform and use it to submit suspicious transaction reports, suspicious activity reports, targeted financial sanctions filings and other required reports where applicable. See our goAML registration guide for the practical steps.

AML Legal Framework Applicable to Exchange Houses in the UAE

The framework has five layers: the core federal laws, the guidance that applies to all reporting entities, the national risk assessments, the Central Bank’s general guidance for licensed financial institutions, and the Central Bank’s exchange-house-specific guidance. This section catalogues each layer, grounded in the official CBUAE AML/CFT and exchange business materials. Because exchange houses are Licensed Financial Institutions, CBUAE guidance for LFIs is relevant to them, some of it applying generally and some depending on the firm’s products, customers, corridors and delivery channels. Older guidance, standards and outreach material should be read together with, and subject to, Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025, to the extent they remain in force and are not inconsistent with the current framework.

The table below shows how these layers fit together, from the core statute down to the risk assessments that calibrate day-to-day controls.

Layer Instrument Why it matters 
AML statute Federal Decree-Law No. 10 of 2025 Core AML/CFT/CPF offences, FIU powers, reporting and penalties 
Executive regulation Cabinet Resolution No. 134 of 2025 Practical duties: risk-based approach, CDD, EDD, monitoring, beneficial owner, STR and records 
Central Bank regulatory law Federal Decree-Law No. 6 of 2025 Central Bank and licensed financial activity framework (regulatory background) 
Sanctions framework Cabinet Resolution No. 74 of 2020 and EOCN guidance Screening, freezing, confirmed and partial name match reporting, and sanctions reporting 
Exchange-house standards CBUAE Standards for Exchange Business, Chapter 16 Sector-specific AML/CFT compliance programme 
CBUAE LFI guidance STR, CDD, transaction monitoring, TFS, payments, PEPs, VASPs, PF and TBML Supervisory expectations for licensed financial institutions 
NRA and PF NRA UAE ML/TF NRA 2024 and UAE PF NRA 2026 Baseline for the exchange house risk assessment 

Federal AML Laws and Executive Regulations Applicable to Exchange Houses in the UAE

These instruments are the legal foundation for every exchange house in scope.

Federal Decree-Law No. 10 of 2025 on AML, CFT and CPF

For an exchange house moving outbound and inbound remittances and dealing in currency, Federal Decree-Law No. 10 of 2025 is the source of the whole obligation to fight money laundering, terrorist financing and proliferation financing. It fixes the definitions that shape how the firm screens walk-in and one-off customers, third-party senders and beneficiaries, and recognises that the crime can travel through digital systems, virtual assets and cryptographic technologies. It establishes the Financial Intelligence Unit as the destination for the exchange house’s suspicious transaction reports, empowers that Unit to demand further information, and provides for temporary suspension and freezing measures within the limits and procedures set by the law and the related FIU regulation. Supervision and penalties flow from here.

Cabinet Resolution No. 134 of 2025, the Executive Regulations

Cabinet Resolution No. 134 of 2025 issues the Executive Regulations of Decree-Law No. 10 of 2025, turning the statute into the working rulebook a money transfer business runs on. It confirms that funds transfers and money and currency exchange fall within scope, including services offered through agents and brokers, and defines wire transfers, intermediary and beneficiary institutions, and beneficial owners. From here come the substantive duties: a risk-based approach, customer due diligence and beneficial owner verification on customers and originators, screening of beneficiary information, and ongoing monitoring with refreshed records. The exchange house must adopt internal policies approved by senior management and proportionate to its remittance and cash-intensity risks, and meet the wire transfer requirements that supervisors test.

Cabinet Resolution No. 109 of 2023 on beneficial owner procedures

When a corporate customer walks in to send a wholesale remittance or trade banknotes, the exchange house must know who really stands behind it, and Cabinet Resolution No. 109 of 2023 supplies that transparency. It defines the real beneficiary as the natural person who ultimately owns or controls a legal person, or on whose behalf transactions are conducted. It obliges legal persons to obtain accurate, up-to-date beneficial owner information, identify nominee board members, and maintain a real beneficiary register and a shareholders register, updated generally within fifteen days of any change. These records feed the firm’s due diligence. They apply to legal persons licensed or registered in the State, including commercial free zones, but exclude the financial free zones, the DIFC and ADGM, which operate their own beneficial ownership regimes.

Cabinet Resolution No. 132 of 2023 on penalties for beneficial owner violations

Cabinet Resolution No. 132 of 2023 puts teeth behind the beneficial ownership rules by setting the penalties for breaching Cabinet Resolution No. 109 of 2023. It empowers the registrar to fine legal persons that fail their obligations, such as keeping accurate registers, per a schedule annexed to the Resolution and without prejudice to other sanctions. Consequences escalate: on a third violation, the registrar may suspend the licence and close the premises until the fine is paid and the breach is corrected. For an exchange house, this shows why the corporate remitters it onboards must keep ownership data current. These penalties apply to legal persons licensed or registered in the State, including commercial free zones, but not to the financial free zones, the DIFC and ADGM, which follow their own regime.

Cabinet Resolution No. 74 of 2020 on terrorist lists and UNSC resolutions

Sanctions screening sits at the core of an exchange house, and Cabinet Resolution No. 74 of 2020 defines it. It regulates the UAE terrorist lists, gives effect to the local Cabinet list and the United Nations Security Council lists, and requires that freezing measures be applied without delay, meaning within twenty-four hours. Practically, the firm must register on the Executive Office website to receive designation and de-listing notices, then continuously screen its customer database, potential clients, beneficial owners and the parties to every remittance, including third-party senders and beneficiaries, both routinely and whenever the lists change. On any match, the exchange house freezes without delay, enforces unfreezing decisions and reports to its supervisor.

Federal Law No. 7 of 2014 on combating terrorism crimes

Federal Law No. 7 of 2014 on Combating Terrorism Crimes is the criminal statute that these controls serve. It defines terrorist crime, terrorist purpose, terrorist organisation and terrorist person, distinguishes conventional from nonconventional weapons, and prescribes penalties up to life imprisonment and, in cases, death. For a money transfer business, the sharpest edge is terrorism financing: it penalises anyone who provides, collects, prepares or maintains funds, or helps obtain them, for a terrorist organisation, person or crime, and addresses freezing funds suspected of such a purpose held with financial institutions. Because the wider framework defines terrorist acts by reference to this law, it explains what an exchange house’s remittance screening must detect.

Some of the CBUAE, FIU and supervisory materials below were first issued under the earlier 2018 and 2019 AML frameworks. They should be read subject to Federal Decree-Law No. 10 of 2025, Cabinet Resolution No. 134 of 2025 and later rulebook updates, and only so far as they remain in force and are not inconsistent with the current framework.

AML Guidance Applicable to All Reporting Entities

Beyond the core laws, the Central Bank, the FIU, and the Executive Office issue guidance and typologies that apply to all reporting entities, exchange houses included.

UAE FIU Regulation No. 1 of 2026 on Suspension and Freezing Powers, April 2026

UAE FIU Regulation No. 1 of 2026, dated April 2026, governs the postponement or suspension of suspicious transactions and the freezing of funds. Issued under the AML/CFT Decree-Law, it applies to reporting entities, including exchange houses, and complements existing suspicious transaction reporting duties. It introduces the Postponement Suspicious Transaction Report, an urgent filing where a remittance or withdrawal suspected of criminal links is about to be transferred, drawn down or dissipated. It sets a monetary threshold that falls away for higher-threat predicate offences, third-party laundering, organised crime or terrorist financing, and defines a Suspension Order of up to ten working days and a Freezing Order of up to thirty days.

UAE FIU Strategic Analysis Report on Human Trafficking, April 2026

The UAE FIU Strategic Analysis Report on Human Trafficking, dated April 2026, analyses money laundering flows tied to trafficking, drawing on suspicious transaction and activity reports filed with the Financial Intelligence Unit. It covers objectives, methodology and scope, and the main forms of trafficking, including sexual exploitation, forced labour and organ removal. It sets out patterns across themes such as adult and child exploitation, forced labour and proceeds laundering, profiles the subjects involved, including designated traffickers, organised crime groups, foreign politically exposed persons and money mules, and assesses vulnerable sectors. It then develops risk indicators around customer profile, behaviour and transactional activity, helping exchange houses spot mules moving trafficking money.

Guidance on Targeted Financial Sanctions for Financial Institutions, DNFBPs and VASPs, March 2026

First published in January 2021 and last amended in March 2026, this Executive Office guidance clarifies targeted financial sanctions obligations for financial institutions, DNFBPs and VASPs. It sets out four duties central to any exchange house: registering in the Notification Alert System; screening customers, senders and beneficiaries against the UAE Local Terrorist List and the United Nations Consolidated List; freezing funds without delay and never releasing them to designated persons; and reporting the measures taken. It explains ownership, control and acting-on-behalf concepts that matter for third-party remittances. The March 2026 update renames the Funds Freeze Report as the Confirmed Name Match Report and addresses screening during weekends and public holidays.

Joint Guidance on the Compliance Officer and MLRO, 2026

Issued in 2026 by the UAE Supervisory Sub-Committee, this joint guidance sets a unified framework for appointing, empowering and defining the Compliance Officer or Money Laundering Reporting Officer across regulated sectors, including firms supervised by the Central Bank that licenses exchange houses. Building on Federal Decree-Law No. 10 of 2025, Cabinet Resolution No. 134 of 2025 and the 2025 legal framework, it treats the role as a cornerstone of effective AML, CFT and counter-proliferation work. It sets expectations on appointment and resignation, requiring seniority, experience, operational independence, freedom from conflicts, direct board access and adequate resources, and covers the compliance function, its outsourcing and the officer’s duties.

FIU Strategic Analysis Report on Terrorist Financing, May 2025

Published in May 2025 by the UAE Financial Intelligence Unit, this strategic analysis on terrorist financing typologies and facilitators draws on Unit data from 2021 to 2024, including suspicious transaction and activity reports, disseminated cases and open source material. For exchange houses it is especially pointed, identifying how terrorist funds move through financial institutions, unlicensed hawala, corporate networks, trade-based schemes, high-value goods, real estate, virtual assets and crowdfunding. It profiles facilitators such as designated individuals, family members, money mules, corporate nominees and professional intermediaries who sit behind third-party senders and beneficiaries. The developed risk indicators help remittance staff detect, trace and report attempts to obscure funds through one-off and layered transfers.

goAML FAQs, April 2024

The goAML FAQs, version 2.1 dated 18 April 2024, is a practical question and answer guide from the UAE Financial Intelligence Unit to help reporting entities use the goAML system and its registration and access services. It walks through common snags such as expired one-time passwords at first login, pop-up authentication screens requiring the system-issued username with a Google Authenticator passcode, the correct login sequence through the services portal, and resetting a forgotten password. It sets out where to enter credentials, which emails issue usernames and codes, and who to contact when errors persist. For an exchange house, reliable goAML access underpins timely reporting.

PF Institutional Risk Assessment Guidance for FIs, DNFBPs and VASPs, December 2023

Published in December 2023, this guidance sets out how financial institutions should assess and manage exposure to proliferation financing, built around inherent risks, control effectiveness and residual risks. It names the risk categories and factors an exchange house should weigh when scoring its remittance and currency exchange business. Mitigating measures span client onboarding, know your customer and due diligence, enhanced due diligence, screening customers for sanctions and adverse media, ongoing and transaction monitoring, suspicious activity reporting, and employee training. A customer risk scoring questionnaire, elevated risk factors and worked case studies, including sanctions and adverse media matches, show how to calibrate controls and document risk decisions supervisors can review.

Terrorist and Proliferation Financing Red Flags Guidance, December 2023

Updated in December 2023, this Red Flags Guidance gives exchange houses a consolidated set of indicators for spotting terrorist and proliferation financing, including attempts to evade targeted financial sanctions imposed under UN Security Council Resolutions or local designations. It flags evasion tactics such as renaming, front companies, intermediaries and alternative financial networks that a walk-in remitter or third-party sender might exploit. The document first sets out the legal basis for reporting, then lists terrorist financing indicators followed by proliferation ones grouped by customer profile, account and transaction activity, maritime and trade finance, with sanctions appendices. For counter staff and compliance teams it sharpens detection and guides reporting decisions.

Suspicious Activity and Transaction Reporting Thematic Review, January 2023

Issued in January 2023, this thematic review sets out findings and regulatory expectations from the 2022 AML and CFT examination of licensed financial institutions and DNFBPs, focusing on the suspicious transaction and activity reporting framework and the transaction monitoring systems that feed it. It is meant to be read alongside existing guidance on reporting and on monitoring and sanctions screening. It contrasts acceptable and deficient practice across governance, policies, risk-based deployment of monitoring, data management, alert review, case investigation, reporting decisions and the post-reporting process. It applies expressly to exchange houses alongside banks, finance companies and payment providers, offering a benchmark to test remittance monitoring and close gaps before inspection.

Counter Proliferation Financing Guideline, November 2022

Published in November 2022 by the Executive Office for Control and Non-Proliferation, this guideline supplements the wider Guidance on Targeted Financial Sanctions and raises awareness of proliferation financing threats among regulated entities. For an exchange house, it explains how weapons-related funds can be raised or moved through remittances and currency exchange, and how to fold proliferation risk into the firm’s own risk assessment. It sets out preventive measures including enhanced due diligence on customers and transactions, alertness to shell and front companies, dual-use goods and trade routes, and staff training. The red flag list helps counter staff spot sanctions evasion attempts by walk-in and corporate senders.

goAML Web Submission Guide, July 2022

The goAML Web Submission Guide, issued by the UAE Financial Intelligence Unit in July 2022, sets out how to submit a report to the FIU through the goAML platform. It is addressed to the designated Compliance Officer or Money Laundering Reporting Officer of a registered reporting entity, or the deputy where the lead officer is unavailable. It reviews the report types, including the Suspicious Transaction Report and the Suspicious Activity Report, the latter covering suspected activity or an attempted, non-executed transaction, plus Additional Information Files and High Risk Country reports. It explains access for Central Bank-regulated and other entities, then covers selecting a report, completing the cover, and submitting.

Joint Guidance on Combating the Use of Unlicensed Virtual Asset Providers, March 2022

Issued in March 2022, this joint guidance from the UAE Supervisory Authorities, including the Central Bank, the Securities and Commodities Authority and the Virtual Assets Regulatory Authority, aligns with FATF’s risk-based approach and warns the public and regulated firms about unlicensed virtual asset providers. It urges confining virtual asset dealings to licensed entities and reminds exchange houses of their AML obligations. Expectations include vigilance to fraud, factoring emerging risks into assessments, adequate due diligence, spotting customers who seek unlicensed providers, and reporting suspicions. Red flags include no licence, no physical presence, unrealistic promises or Ponzi schemes, poor websites and pressure to invest quickly, helping counter staff intercept suspect remittances.

IEMS User Guide for Reporting Entities, March 2022

Dated March 2022, this practical manual from the UAE Financial Intelligence Unit explains its Integrated Enquiry Management System, which automates information requests, prosecution decisions and other AML and CFT instructions from domestic authorities. It provides an end-to-end flow between the Unit, the authorities and reporting entities such as exchange houses. Firms already registered on goAML reuse those credentials, reaching the system through the Services Portal or eServices Portal. The guide walks through the dashboard, request management and the reply workflow covering account holder and signatory details, and sets out Admin, Maker and Checker roles. It stresses meeting due dates and implementing freeze orders immediately on the amount or whole balance.

goAML Pre-Registration Guide, March 2022

The goAML Pre-Registration Guide, issued by the UAE Financial Intelligence Unit in March 2022, explains how reporting entities gain access to the Services Access Control Manager, or SACM, before reaching goAML to register and file suspicious reports. The application is reached through a public portal for entities not regulated by the Central Bank of the UAE, except hawaladars, with entities under various Supervisory Bodies following the stated steps. SACM hosts the links to the production and testing environments, secured by a time-based one-time password from Google Authenticator. The guide covers pre-registration, confirming intent, and safeguarding a personal Secret Key issued after FIU due diligence, which cannot be shared.

goAML Registration Guide, March 2022

The goAML Registration Guide, issued by the UAE Financial Intelligence Unit in March 2022, sets out how an organisation registers with the FIU on its reporting platform, goAML. It applies to registration as a reporting entity, a stakeholder or a supervisory body, and confirms that every accountable and reporting entity in the UAE, whoever its regulator, must register to submit suspicious reports. Access runs through the Services Access Control Manager, with Central Bank-regulated institutions needing a dedicated MPLS link and others over the internet. It walks through selecting the registration type, entering organisation and address details, adding the registering person, uploading attachments, setting access rights and resetting passwords.

Strategic Review on Targeted Financial Sanctions Case Studies, November 2021

Dated November 2021, this strategic review examines targeted financial sanctions reporting in the United Arab Emirates, sitting within the framework by which the UAE, through Cabinet Resolution No. 74 of 2020, implements United Nations Security Council Resolutions on terrorism, terrorist financing and proliferation, including freezing measures and prohibitions on providing funds. It sets out its methodology, then classifies sanctions reports by source, by suspicion and by instrument. It distinguishes terrorist financing patterns from proliferation patterns and presents red flags, statistics and recommendations, plus the Executive Office’s role in circulating list updates. For an exchange house, it shows how sanctions suspicions arise and are reported, sharpening screening across remittance flows.

Typologies on the Circumvention of Targeted Sanctions, November 2021

Last amended in November 2021 and issued by the Executive Office, this typologies report compiles cases showing how sanctioned persons, groups and entities try to circumvent targeted sanctions relating to terrorism and the proliferation of weapons of mass destruction. Drawing on public UAE and foreign sources, it groups methods by channel, expressly covering exchange houses alongside banking services, money remitters, hawala and similar providers, online payment facilities, misused non-profits, cash and gold smuggling, trade in dual-use goods, misused legal entities and virtual assets, plus proliferation-side banking and cyberactivity. Illustrated with named case networks and red flags, it turns evasion tactics into learning that sharpens screening, due diligence, monitoring and reporting.

Update to the List of High Risk Jurisdictions, November 2021

This November 2021 decision of the National Anti-Money Laundering and Combating the Financing of Terrorism and Financing of Illegal Organizations Committee updates the list of high-risk jurisdictions subject to a call for action, the list under increased monitoring, and the counter-measures to apply. It is addressed to bodies including the supervisory authorities and the Financial Intelligence Unit, and revises an earlier March 2021 decision. Reflecting the Committee’s mandate to identify high-risk countries and set proportionate counter-measures, it instructs supervisors to ensure due diligence is applied. For exchange houses, it signals which remittance corridors warrant enhanced due diligence and keeps customer and transaction risk ratings aligned with the latest listings.

Joint Guidance on Satisfactory and Unsatisfactory Practice, June 2021

Issued in June 2021 by the UAE Supervisory Authorities, including the Central Bank, the DFSA, the FSRA, the Securities and Commodities Authority and the Ministries of Justice and Economy, this joint guidance draws on inspections between January 2020 and May 2021. It contrasts satisfactory and unsatisfactory practice across the AML framework, targeted financial sanctions and counter proliferation financing. For an exchange house it covers governance and management oversight, the risk assessment, three lines of defence, policies, training and the compliance officer or MLRO role, plus customer onboarding, monitoring, risk rating, due diligence, transaction monitoring, sanctions screening and record keeping, letting firms benchmark controls before an examination exposes weaknesses.

Typologies on the Circumvention of TFS, PF and WMD, May 2021

Last amended in May 2021 and issued by the Executive Office, this typologies report examines how sanctioned persons and entities receive financing in violation or evasion of UN Security Council Resolutions on terrorism and the proliferation of weapons of mass destruction. It explains that targeted financial sanctions cover both asset freezing and bans on making funds available, directly or indirectly, to designated parties. Organised by method, it addresses the misuse of banking services, money remitters, hawala and similar providers, online payment facilities, non-profits and cash smuggling on the terrorist side, and banking, cyberactivity, trade and legal entities on the proliferation side, closing with red flags drawn from real cases.

goAML FAQs, September 2020

The goAML FAQs Guide, version 1.5 dated 8 September 2020 from the UAE Financial Intelligence Unit, answers the practical questions reporting entities raise while using the goAML portal, from resetting a forgotten password to fixing a rejected submission. For an exchange house filing frequent remittance-related suspicious transaction reports, it is a quick reference for the operational snags that would otherwise stall a filing, covering login and access, report status and common submission errors. It sits alongside the newer April 2024 FAQs and keeps the compliance team moving when the portal behaves unexpectedly.

goAML Registration Guide Stage 2, September 2020

The goAML Registration Guide, version 3.3 dated 16 September 2020, sets out how an organisation registers with the UAE Financial Intelligence Unit as a reporting entity, stakeholder or supervisory body. It applies to every accountable and reporting entity whatever its regulator, so a newly licensed exchange house follows it to secure goAML access before filing its first suspicious transaction or activity report. It works through organisation and user details, document uploads and approval, giving the exchange house its onboarding path onto the single national reporting channel.

Guideline on Grievance Procedures

Issued by the Executive Office for Control and Non-Proliferation, this guideline explains how grievance requests tied to the UAE Local Terrorist List and the United Nations Consolidated List, collectively the Sanctions Lists, are submitted and reviewed. Under Cabinet Resolution No. 74 of 2020 it covers three request types: de-listing a designation, lifting freezing measures, and seeking permission to use frozen funds. For each it distinguishes Local List designations by the UAE Cabinet from United Nations designations by the Security Council. It clarifies the procedures apply only to Sanctions List freezes, not court orders. For an exchange house, it maps the lawful routes a frozen remittance customer can take.

Online Grievance System User Guide

This user guide from the Executive Office for Control and Non-Proliferation walks applicants through its Online Grievance System, launched to streamline requests relating to the UAE Local Terrorist List and the United Nations Consolidated List, collectively the Sanctions Lists. It explains how to submit the three online request types: de-listing, cancellation of freezing measures, and permission to use frozen funds. Users identify the aggrieved individual or entity, select the relevant list and grievance type, declare previous requests, attach documents and give contact details. It notes the form is in Arabic while the manual is in English. For exchange houses, it shows the route a frozen remittance customer can follow.

Simple Guide to Subscribe to the EOCN Notification Alert System (NAS)

This short guide explains how to subscribe to the Notification Alert System on the Executive Office’s website so users receive timely updates to the sanctions lists applied in the United Arab Emirates. Targeted financial sanctions rest on two lists, collectively the Sanctions Lists: the UAE Local Terrorist List issued by the Cabinet, and the United Nations Consolidated List issued by the Security Council, both updated periodically. It shows where the lists sit and gives step by step subscription instructions through to confirmation. For an exchange house, this supports a core control: screening senders and beneficiaries only works against current lists, and prompt alerts let counter staff apply freezes without delay.

Emerging ML, TF and PF Risks and Trends in the Financial Sector

Issued by the Supervisory Subcommittee under Article 16 of Federal Decree-Law No. 10 of 2025, this report gives regulated firms a current picture of the money laundering, terrorist financing and proliferation financing threats reshaping the sector. Its typologies and red flags can be factored into exchange house risk assessments and monitoring. It examines abuse of artificial intelligence, greenwashing and ESG-related fraud, trade finance misused for proliferation, growth in illicit virtual asset transactions, and sanctions evasion linked to the Commonwealth of Independent States. Case studies on money mule networks, trade-based laundering and virtual asset conversion, plus typologies in stored value and retail payment services, sharpen detection of layered remittance flows.

Typologies in the Financial Sector

Typologies in the Financial Sector is a joint report from the Supervisory Authorities Sub-Committee and the Financial Intelligence Unit, developed with the Executive Office and a pilot group of firms. It shares money laundering, terrorist financing, sanctions, fraud, and bribery and corruption typologies seen in the market, several surfacing during the COVID-19 pandemic, to help the private sector anticipate emerging risks. Sitting above the National Risk Assessment, it flags the growing use of unlicensed money service operators that settle books over time rather than moving each transfer individually, lists indicators that combine to obscure a transaction, and notes links to modern slavery and human trafficking.

NRA, SRA, and Other Important Guidelines for Exchange Houses in UAE

The UAE assesses its money laundering, terrorist financing, and proliferation financing risk at national level, and exchange houses must align their own business and enterprise-wide risk assessments to those findings.

UAE PF National Risk Assessment 2026

The UAE Proliferation Financing National Risk Assessment 2026 rates exchange houses medium-high in the mainland, exposed mainly through currency exchange and cross-border transfers that sanctioned networks may exploit to evade targeted financial sanctions relating to the Democratic People’s Republic of Korea and Iran. Prepared in response to FATF revised Recommendation 1, it examines threats and vulnerabilities across mainland and free zone sectors on a low-to-high scale, with overall country risk medium-high. Virtual asset service providers rate highest at high; banks and hawala providers medium-high; free zone banks and money service businesses medium; maritime insurance medium to medium-low; and stored value facilities medium-low. It should shape sanctions screening and due diligence.

The table below summarises the residual risk ratings the exchange house sector should reflect in its own risk assessment.

UAE ML and TF National Risk Assessment 2024

The UAE Money Laundering and Terrorist Financing National Risk Assessment 2024, the country’s second, rates the exchange house sub-sector residual medium-high, driven by cash intensity, banknote shipments, reliance on foreign remittance partners and third-party transactions. Prepared using the World Bank methodology on data from 2019 to 2023, it identifies threats, vulnerabilities and residual risks across the mainland and financial free zones, with overall national money laundering risk medium-high and drug trafficking and fraud among the highest threats. Registered hawala providers are rated high, banks medium-high, finance companies and insurance medium, and securities medium to medium-high. For exchange houses, it sets the baseline that should shape customer risk ratings and controls.

Assessment Exchange house sector residual risk 
Money laundering and terrorist financing (NRA 2024) Medium-high, driven by banknote shipments, reliance on foreign remittance partners, and third-party transactions 
Proliferation financing (PF NRA 2026) Medium-high in the mainland, through currency exchange and cross-border transfers 

Alongside the national assessments, sector risk assessments, red flag guidance, and typologies reports give exchange houses the detail they need to keep their enterprise-wide risk assessment current and defensible.

CBUAE Guidance Applicable to Exchange Houses in UAE

The Central Bank’s guidance for licensed financial institutions applies to exchange houses as Licensed Financial Institutions. The documents below make up that guidance set.

CBUAE Best Practices for Licensed FIs on Implementing Role-Based AML/CFT/CPF Training, October 2025

Published in October 2025, the CBUAE Best Practices on Implementing Role-Based AML/CFT/CPF Training shows exchange houses how to tailor learning to each job rather than issuing one generic course. Counter and teller staff handling walk-in remittances, and compliance teams overseeing corridors, receive content matched to their own exposure and to the red flags of money laundering, terrorist financing and proliferation financing they realistically meet. The guidance applies a risk-based approach so frequency and intensity track each role’s risk, spanning regulatory requirements, global standards, internal policies, products, customers and geographies. It covers the Board, senior management, the three lines of defence, delivery methods, documentation and records.

CBUAE Best Practices for Licensed FIs on a Risk-Based Approach and Institutional Risk Assessments, October 2025

Dated October 2025 and issued under article 44.11 of Cabinet Decision No. 10 of 2019 (now repealed and replaced by Cabinet Decision No. 134 of 2025, under which supervisory guidance is issued pursuant to Article 49.4), this CBUAE Best Practices document guides exchange houses in building a risk assessment methodology, running an institutional risk assessment and embedding a risk-based approach across money laundering, terrorist financing and proliferation financing. It explains the framework, appropriate granularity, accountability and assessment frequency, then how to score inherent risk across customers, products, delivery channels, geographies and operating structure before weighing controls to reach residual risk. For a remittance and currency-exchange business, this means scaling scrutiny to the corridors served and the exposure each carries. It expressly applies to exchange houses alongside banks and other institutions.

CBUAE Guidance for Licensed FIs on Correspondent Banking, October 2025

Exchange houses depend on foreign remittance partners and correspondent relationships to settle cross-border transfers, and this October 2025 CBUAE Guidance explains how to control the money laundering, terrorist financing and proliferation financing risks that dependence brings. It describes correspondent banking, the requirements for processing cross-border funds transfers, and the risk factors attaching to respondent institutions, including third-party transaction risk from nested relationships and payable-through accounts, geography, ownership, products and customer base. On mitigation it covers enterprise-wide and relationship-specific risk assessment, standard, specific and enhanced due diligence, ongoing monitoring, suspicious activity reporting, targeted financial sanctions, governance, independent audit, training and record-keeping. Robust due diligence guards against exposure to unknown parties.

CBUAE Guidance for Licensed FIs on Customer Due Diligence and Record-Keeping, October 2025

For exchange houses serving walk-in and one-off remittance and currency-exchange customers, this October 2025 CBUAE Guidance on Customer Due Diligence and Record-Keeping sets out controls the regulator calls foundational to fighting financial crime. It stresses understanding each customer’s occupation, source of funds, source of wealth and expected activity so suspicious transactions surface. The document details general principles, identification and verification for natural persons, legal persons, arrangements and those acting on a customer’s behalf, then risk profiling through segmentation and geography. It addresses ongoing monitoring, simplified and enhanced due diligence, non-face-to-face relationships, name screening, customer rejection and exit, third-party reliance, record-keeping and red flag indicators. Reliable records underpin reporting.

CBUAE Guidance for Licensed FIs on Risks Related to Proliferation Finance, October 2025

Issued in October 2025, this CBUAE Guidance on Proliferation Finance helps exchange houses counter the financing of weapons of mass destruction as it moves through cross-border payments and banknote flows. Read alongside the CBUAE Procedures and Guidelines, it states regulatory expectations rather than new law, defining proliferation financing before examining the vulnerable channels it exploits, including correspondent banking, hawala and other alternatives to traditional banking, offshore accounts, free trade zones and shell companies. It sets out UNSC and FATF obligations, local requirements, and a risk-based approach across customer, product, geographic and operational risk. Controls span due diligence, transaction monitoring, suspicious reporting, targeted financial sanctions, governance, audit, training and record keeping.

CBUAE Guidance for Licensed FIs on Risks Related to Trade-Based ML and Transshipment, October 2025

Published in October 2025, this CBUAE Guidance on Trade-Based Money Laundering and Transshipment helps exchange houses recognise how criminals abuse international trade, cross-border payments and the movement of goods and banknotes. It explains trade finance, distinguishing documentary from non-documentary and open account trade, then sets out typologies including over- and under-invoicing, over- and under-shipment, multiple invoicing, falsely described goods, shell, front and shelf companies, free trade zones, illicit cash integration, third-party intermediaries and pass-through accounts. It also covers services-based laundering, vulnerable sectors such as gold and precious metals, and illicit transshipment. On mitigation, it addresses enterprise-wide risk assessment and enhanced due diligence. Trade can disguise value or movement.

Federal Decree-Law No. 6 of 2025 on the Central Bank (regulatory background)

Federal Decree-Law No. 6 of 2025 on the Central Bank, Regulation of Financial Institutions and Activities, and Insurance Business, issued on 8 September 2025, is not the AML law, but it matters as regulatory background for a CBUAE-licensed exchange house. It governs the Central Bank’s role and the regulation of licensed financial institutions and financial activities, which is the regime under which the firm holds its licence and answers to its supervisor. An exchange house should read it alongside the AML framework when assessing its licensing, conduct and supervisory position.

CBUAE AML and CFT Guidelines for Financial Institutions, July 2023

Dated July 2023, the CBUAE AML/CFT Guidelines for Financial Institutions name exchange houses, money service businesses and hawaladars expressly among those they bind, so a remittance operator cannot treat them as banking-only material. Prepared jointly by the country’s Supervisory Authorities, they consolidate the minimum expectations for identifying, assessing and mitigating money laundering, terrorist financing and illegal organisation risks into one reference. For a money transfer business, the value lies in the risk-based approach chapters covering business-wide assessment and the customer, product, delivery channel and geographic factors that shape a remittance book. They anchor the firm’s compliance programme, customer due diligence on remitters and beneficiaries, and reporting practices in supervisory expectations.

CBUAE Guidance for Licensed FIs on Risks Related to Virtual Assets and VASPs, February 2023

Issued on 20 February 2023, this CBUAE Guidance helps exchange houses grasp the money laundering and terrorist financing risks where remittances are funded from, or converted into, virtual assets, and where customers deal with virtual asset service providers. It sets out the threats and vulnerabilities, the routes by which an institution becomes exposed, and the UAE framework covering the SCA, CBUAE, VARA and FSRA. It explains the CBUAE non-objection required before opening administrative or transactional accounts for such providers. On mitigation, it addresses the risk-based approach, customer due diligence for provider customers, and enhanced measures for higher-risk customers and transactions. Value can move rapidly and pseudonymously.

CBUAE Guidance for Licensed FIs on Digital Identification for Customer Due Diligence, October 2022

As remittance onboarding moves to apps and remote channels, this CBUAE guidance of 31 October 2022 helps an exchange house understand how digital identity systems can identify and verify customers and support ongoing due diligence. It explains the systems and their participants, key terminology, identity proofing and enrolment, authentication, lifecycle management, and the portability that lets a remitter onboard once. It then covers using such systems for identification and verification, ongoing due diligence and third-party reliance. It examines the risks, from proofing weaknesses to authentication failures, and explains how to assess a system’s assurance and reliability. For app-based money transfer businesses, sound digital identification supports remote onboarding while introducing risks to control.

CBUAE Guidance for Licensed FIs on Suspicious Transaction Reporting, August 2022

Suspicious remittances are the daily bread of an exchange house, and this CBUAE guidance of 3 August 2022 explains how to identify, investigate and report them. It sets out the legal basis for filing, the protection for those who disclose, the meaning of a suspicious transaction, and the consequences of staying silent on structured cash or unusual transfer patterns. The document maps the three lines of defence, the role of the compliance officer or MLRO, transaction monitoring methods from manual to intelligence-led, and how to draft and submit a report. It also covers immediate-attention activity, confidentiality and the strict prohibition on tipping off remittance customers.

CBUAE Guidance for Licensed FIs on Risks Relating to Payments, August 2022

Payments are the very trade of an exchange house, and this CBUAE guidance of August 2022 addresses the money laundering and terrorist financing risks running across the sector. Issued under article 44.11 of Cabinet Decision No. 10 of 2019 (now repealed and replaced by Cabinet Decision No. 134 of 2025, under which supervisory guidance is issued pursuant to Article 49.4), it applies to institutions providing payment products directly and to those serving other payment participants. It explains what makes payments vulnerable: the speed at which funds move, peer-to-peer transfers, cross-border movement, regulatory gaps, intermediation, nesting, and the use of agents. Mitigation covers risk assessment, customer and enhanced due diligence, ongoing monitoring, wire transfer requirements, targeted financial sanctions and suspicious transaction reporting, helping a money transfer business calibrate controls to a fast, intermediated flow.

CBUAE Guidance for Licensed FIs on Risks Relating to Politically Exposed Persons, August 2022

A prominent remittance customer can be a politically exposed person, and this CBUAE guidance of August 2022 sets out how an exchange house identifies and manages the heightened risks they bring. Issued under article 44.11 of Cabinet Decision No. 10 of 2019 (now repealed and replaced by Cabinet Decision No. 134 of 2025, under which supervisory guidance is issued pursuant to Article 49.4), it stresses that the aim is not to refuse such customers but to complete thorough due diligence before accepting or continuing a relationship. It distinguishes domestic and foreign politically exposed persons and heads of international organisations, extending to family and close associates. It covers classification, time limits on status, screening, risk rating, enhanced due diligence, monitoring, reporting, governance and training, with an annex of red flags for high-value transfers.

CBUAE Guidance for Licensed FIs on Transaction Monitoring and Sanctions Screening, September 2021

Issued on 8 September 2021, this CBUAE guidance tells exchange houses how to design, operate and maintain the systems that flag suspicious remittances and identify sanctioned parties on transfers. On transaction monitoring, it covers risk assessment, risk-based deployment, data management, rule definition and pre-implementation testing, alert scoring, outcomes analysis and reporting, plus post-implementation tuning and validation. On sanctions screening, it addresses name and transaction screening design, list management and testing so remitters, beneficiaries and counterparties are caught reliably. A governance section covers oversight, vendor use, role-specific training and record keeping. For a money transfer business, well-calibrated, regularly validated systems are the difference between spotting structured cash and missing it.

CBUAE Guidance for Licensed FIs to Cash-Intensive Businesses, September 2021

No customer type sits closer to an exchange house than the cash-intensive business, and this CBUAE guidance of September 2021 addresses precisely the risks that arise when clients handle large volumes of notes at the counter. Issued under article 44.11 of Cabinet Decision No. 10 of 2019 (now repealed and replaced by Cabinet Decision No. 134 of 2025, under which supervisory guidance is issued pursuant to Article 49.4), it explains why cash is so vulnerable to abuse, the risks of bearer negotiable instruments and prepaid cards, and specific concerns including cross-border cash movement, couriers and currency exchange. On mitigation, it sets a risk-based approach built on enterprise and customer risk assessment, enhanced due diligence, beneficial owner identification, ongoing and transaction monitoring, suspicious transaction reporting, governance and training for high cash flows.

CBUAE Guidance for Registered Hawala Providers and LFIs, August 2021

Issued in August 2021, this CBUAE combined Guidance for Registered Hawala Providers and the Licensed Financial Institutions serving them reaches exchange houses as LFIs providing services and as remittance businesses operating near this space. Read alongside the CBUAE Procedures and Guidelines, it states regulatory expectations rather than new law and is organised in parts covering each audience. It draws on the FATF description of hawaladars as money transmitters who arrange transfers and settle through trade, cash and long-term net settlement, often tied to particular regions. It sets out global risks, UAE regulation, permitted and non-permitted services, sanctions and freezing without delay, registration, a bank account, and a full AML/CFT programme.

CBUAE Guidance for Licensed FIs on Implementation of Targeted Financial Sanctions, July 2021

Exchange houses should screen customers, originators, beneficiaries, beneficial owners and counterparties to a transfer against applicable sanctions lists, and this CBUAE guidance of 4 July 2021 sets out how to identify, freeze and report assets connected to designated persons. Read with the Executive Office guidance, it builds a sanctions programme from senior management commitment, risk assessment and risk appetite through internal controls, training, audit and record keeping. It then addresses screening against the UN Consolidated List and Local Terrorist List, name and payments screening of remitters and beneficiaries, false positive verification and confirmed matches. Red flag indicators for terrorist financing, proliferation financing and evasion help catch counterparties routing funds through the firm’s counters.

CBUAE Guidance for Licensed FIs to Legal Persons and Arrangements, June 2021

When a corporate remitter approaches the counter, this CBUAE guidance of June 2021 governs how an exchange house manages the money laundering and terrorist financing risks that companies, other legal persons and legal arrangements carry. It explains how such structures obscure identity and beneficial ownership, hide the purpose of a transfer, and conceal the source of funds, and it sets out common typologies of abuse. It then covers formation requirements, beneficial owner identification, record keeping, and how legal persons operate under UAE law, including economic substance. Mitigation runs through the risk-based approach, customer risk rating, institutional risk assessment and enhanced due diligence on opaque remitters.

CBUAE Guidance for Licensed FIs to the Real Estate and Precious Metals and Stones Sectors, June 2021

Issued on 16 June 2021, this CBUAE guidance matters to an exchange house whose remittance customers include dealers in precious metals and stones or parties moving funds tied to real estate, both flagged as higher-risk. It is organised around understanding and mitigating the risks each sector presents, describing the features that increase vulnerability, relevant typologies, and how the sectors are regulated in the UAE. On mitigation, it explains applying a risk-based approach, conducting customer and enhanced due diligence, reporting suspicious transactions, and maintaining governance and training. Common requirements sit alongside sector-specific considerations, and annexes provide red flags for spotting illicit value passing through gold traders and property-linked transfers.

CBUAE STR Outreach for Banks and Finance Companies, March 2021

Delivered on 10 March 2021, this Financial Intelligence Unit outreach session briefed banks and finance companies on suspicious transaction reporting, with input from the Ministry of Interior. Although addressed to banks and finance companies, its expectations reach any licensed institution that files through goAML, so an exchange house can read across the same messages: when a report is warranted, the quality the FIU expects, goAML as the sole channel, and the compliance officer’s duties. It reinforces prompt, well-grounded reporting of remittance and currency-exchange suspicions rather than defensive or late filing.

CBUAE Board of Directors Decision No. 59/4/2019 on AML and CFT procedures

Board of Directors Decision No. 59/4/2019, issued on 13 June 2019, is the supervisory bedrock on which every exchange house builds its AML programme. Made under Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025, it cancels the old Circular No. 24/2000 and confirms that a licensed money transfer business, conducting remittance operations for customers, counts as a financial institution bound by the law, its implementing regulation and Central Bank instructions. It empowers the CBUAE to examine the firm’s branches, with or without notice, demand records on cross-border transfers, impose sanctions for breaches, permit appeals and publish penalties against non-compliant houses.

CBUAE Guidance Note on Responsible Use of AI and ML by LFIs

As exchange houses turn to artificial intelligence and machine learning to monitor remittance flows, this CBUAE Guidance Note on the Responsible Use of AI and Machine Learning sets out principles for consumer-focused, ethical adoption, including generative AI. It is non-binding, helping institutions shape internal policies that protect consumers and support good market conduct, and its principles are flexible so they evolve with the technology. The Note covers governance and accountability, placing responsibility for systems and outcomes with senior management and the Board and calling for a documented framework, regular reporting and a model inventory. It addresses fairness, transparency, data quality, privacy, continuous monitoring, human oversight, outsourcing and ethical innovation.

CBUAE List of Administrative and Financial Sanctions

The CBUAE List of Administrative and Financial Sanctions records the penalties the Central Bank can impose, and it applies to all licensed institutions, including exchange houses. It confirms the CBUAE as the supervisory authority for shortcomings in the anti-money laundering and sanctions compliance frameworks of those it licenses. Under Article 17 of Federal Law No. 10 of 2025, it can impose administrative penalties from a warning to licence revocation, and financial penalties from ten thousand to five million dirhams per violation. Under Article 137 of the Central Bank Law, fines reach two hundred million dirhams

Exchange House Sector-Specific CBUAE Guidance

Alongside its general guidance, the Central Bank issues material aimed specifically at exchange houses and money or value transfer services.

Typologies in the Money or Value Transfer Services (MVTS), June 2022

Typologies in the Money or Value Transfer Services of June 2022 is a joint report by the Supervisory Authorities Sub-Committee, the FIU and the Executive Office, built from a pilot of exchange houses and registered hawala providers. It maps emerging ML, TF and sanctions risks across currency exchange and money remittance during 2021 to 2022, drawn from products, processes and transactional data. The report lists nineteen typologies with red flags relevant to exchange houses: structuring, third-party smurfing, unusually high-value transactions, sudden turnover spikes at one branch, trade-based money laundering, fabricated transaction receipts, cash couriers, WPS salary changes, remittances to varied beneficiaries, high-risk-country corridors, frequent currency conversion and cash-against-credit-card advances.

CBUAE Standards for Exchange Business, Chapter 16 (AML/CFT), November 2021

Chapter 16 is the binding AML/CFT rulebook every licensed exchange house must follow, set within the CBUAE Standards for the Regulation of Exchange Business, Version 1.20 of November 2021, amending Version 1.10 of February 2018. It codifies the full compliance programme for money exchange and remittance: an enterprise-wide ML/FT risk assessment, KYC and customer due diligence for walk-in natural persons, enhanced due diligence, PEP checks, and special wire-transfer rules for ordering, intermediary and beneficiary institutions. It also covers agents and correspondent counterparties, third-party transactions, sanctions screening, transaction monitoring, suspicious transaction reporting, tipping-off prohibitions, know-your-employee vetting, record retention, remittance data uploads and bi-annual compliance reporting.

CBUAE Guidance for Licensed Exchange Houses, November 2021

The CBUAE Guidance for Licensed Exchange Houses of November 2021 explains how exchange houses should meet their statutory AML/CFT obligations, read alongside Chapter 16 of the Standards. It flags why the sector rates highly for risk and materiality in the UAE, driven by cash intensity, speed, worldwide reach and the many occasional, walk-in transactions that limit customer understanding. It sets out ten essential programme components and a six-step risk assessment covering customer, product, delivery channel, new technology, jurisdiction and counterparty risk, plus corridor and agent exposure. It details customer due diligence, transaction monitoring with red flags, sanctions freezing without delay, training, audit, record keeping, employee risk, and FIU reporting.

CBUAE STR Outreach for Exchange Houses, March 2021

The CBUAE STR Outreach for Exchange Houses of March 2021 is a joint awareness session by the Financial Intelligence Unit, CBUAE AML/CFT supervision and the Ministry of Interior, aimed at exchange-house compliance officers. It explains when and what to report under Article 15 of the AML law, using goAML as the only channel for STRs, SARs and related report types. It stresses the source of funds and wealth information for remittance customers, monitoring triggers and alerts, tipping-off and confidentiality rules after filing, and securing funds on flagged accounts. It shares FIU-noted deficiencies in timeliness and accuracy, plus Ministry of Interior red flags such as credit turnover inconsistent with the customer profile.

Core AML Obligations for Exchange Houses at a Glance

Whatever the licence, the AML regulations for exchange houses in the UAE turn on a common set of duties.

  • A business and enterprise-wide risk assessment aligned to the national risk assessments, with corridor and product risk built in.
  • Customer due diligence on customers and originators, with collection and screening of beneficiary information, and enhanced due diligence where the transaction, corridor, customer or counterparty risk is higher, including source of funds for large or unusual transfers.
  • Ongoing transaction monitoring for structuring and unusual patterns, and sanctions screening of customers, originators, beneficiaries, beneficial owners, counterparties and relevant transaction parties, including parties to cross-border payments.
  • Suspicious transaction and activity reporting through goAML, full record keeping, and a qualified compliance officer and MLRO.
  • Identifying the ultimate beneficial owner of corporate remitters.

In practice, supervisors expect an exchange house to be able to evidence controls across the areas below.

Control area  What an exchange house should evidence 
Enterprise-wide and business-wide risk assessment  Corridor, product, customer, delivery channel, branch and counterparty risk 
Customer onboarding  Customer identity, purpose, expected activity and source of funds where relevant 
Remittance controls  Originator and beneficiary information, wire-transfer data quality including incomplete or rejected transfers with escalation and record evidence, and third-party transaction handling 
Bulk cash and banknote handling  Supplier and counterparty due diligence, shipment reconciliation, corridor risk, sanctions screening and source-of-cash checks 
Sanctions screening  UAE Local Terrorist List, UN Consolidated List, customers, beneficiaries, counterparties and ownership or control 
Transaction monitoring  Structuring, smurfing, high-risk corridors, repeated beneficiaries and unusual branch activity 
Agent and partner due diligence  Foreign remittance partner assessment, correspondent risk and ongoing review 
goAML reporting  STR and SAR, confirmed and partial name match reports where relevant, and no tipping-off 
Governance  Compliance officer and MLRO independence, board oversight, training, audit and remediation tracking 

Expert Tip:

For an exchange house, most risk sits in three places: structured cash just under thresholds at the counter, remittances to and from high-risk corridors, and third parties who are not the customer being served. Build monitoring rules around corridor risk and one-off customer behaviour rather than long-term relationships, because that is where the sector’s typologies actually appear.

Conclusion

AML regulations for exchange houses in the UAE come down to a clear chain: exchange houses are Licensed Financial Institutions, the Central Bank supervises them, and the applicable framework includes Federal Decree-Law No. 10 of 2025, Cabinet Resolution No. 134 of 2025, the targeted financial sanctions rules, and relevant Central Bank general and exchange-house-specific rules, standards and guidance. The sector’s cash intensity and cross-border reach put it at medium-high risk, so the controls that matter most are screening, monitoring, and knowing who is really sending and receiving the money. Use the national risk assessments to calibrate, use this guide as an overview, and read across to our guide to anti-money laundering laws in the UAE and the pillar on AML regulations for banks and financial institutions in the UAE.

Frequently Asked Questions

Which AML rules apply to exchange houses in the UAE?

Exchange houses are Licensed Financial Institutions under Federal Decree-Law No. 10 of 2025 and its Executive Regulations, supervised by the Central Bank of the UAE. They must apply customer due diligence, sanctions screening, transaction monitoring, record keeping, and suspicious transaction reporting through goAML, and they follow both the general LFI guidance and the Central Bank’s exchange-house-specific guidance.

The national risk assessment rates the sector medium-high, driven by cash intensity, banknote shipments, reliance on foreign remittance partners, and third-party transactions. In practice the biggest risks are structured cash at the counter, remittances through high-risk corridors, and senders or beneficiaries who are not the customer being served.

Monitoring should be built around corridor and product risk rather than long-term relationships, watching for structuring below thresholds, sudden spikes in a branch’s turnover, remittances to many unrelated beneficiaries, and transfers to high-risk countries. The Central Bank’s transaction monitoring and sanctions screening guidance and the money or value transfer typologies report set out what to look for.

Both move value across borders, and the Central Bank studies them together in its money or value transfer typologies. The key difference is the licence: exchange houses hold an exchange business licence, while hawala providers hold a separate registration. Registered hawala providers are covered under their own framework, which we address on a dedicated page.

Yes. Money service businesses established in the Abu Dhabi Global Market and the Dubai International Financial Centre are supervised by the FSRA and DFSA under their own AML rulebooks, while still operating within the wider UAE AML/CFT framework. They fall outside this guide, which covers exchange houses licensed by the Central Bank.

The firm should identify and verify the customer, understand who the beneficiary is, screen both against sanctions and terrorist lists, risk-rate the corridor and the transaction, and establish the source of funds for large or unusual transfers, applying enhanced due diligence where the risk is higher before the transfer proceeds.

Common indicators include structured cash just below reporting thresholds, a customer sending to many unrelated beneficiaries, sudden turnover spikes at one branch, fabricated receipts, cash couriers, unexplained changes to Wage Protection System salaries, and frequent currency conversion, all of which feature in the Central Bank’s money or value transfer typologies.

Are exchange houses required to screen every remittance?

Yes. The exchange house should screen the relevant parties to a remittance, including customers, originators, beneficiaries and counterparties, against the applicable sanctions lists and internal risk controls before processing or releasing funds.

Yes. The exchange house should maintain a business-wide or enterprise-wide risk assessment that reflects its products, branches, customers, delivery channels, foreign remittance partners, corridors, sanctions exposure and the findings of the national ML/TF and PF risk assessments.

Need help building or reviewing your exchange house AML programme?

Whether you're building an AML programme from scratch or enhancing an existing one, our experts provide practical, risk-based solutions to help your exchange house stay compliant and confident.

Share via :

About the Author

Pathik Shah

FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)

Pathik is an ACAMS-certified AML consultant specialising in governance, risk, and compliance for regulated entities in the UAE. He brings over 28 years of experience, with 1,000+ hours of AML training and 200+ advisory engagements across DNFBPs, VASPs, and FIs. He supports businesses in aligning with AML/CFT requirements from the CBUAE, DFSA, MoET, MoJ, VARA, CMA, FSRA, and FATF. Known for translating complex regulations into audit-ready procedures, Pathik enables operational clarity and compliance readiness.

Reach Out to Pathik

AML Regulations for Insurance Companies and Brokers in UAE

AML Regulations for Insurance Companies and Brokers in UAE

Blogs

Published On: 07/09/2026

Table of Contents

Protect your business with reliable and effective AML strategies with AML UAE.

Last Reviewed On: 07/09/2026   |   Last Updated On: 07/09/2026

Key Highlights

  • Insurance firms carrying on life and investment-linked business are financial institutions under Federal Decree-Law No. 10 of 2025 and its Executive Regulations in Cabinet Resolution No. 134 of 2025.
  • The Central Bank of the UAE supervises the mainland insurance sector, while the DFSA and FSRA supervise insurers and intermediaries in the DIFC and ADGM.
  • The sector’s residual money laundering and terrorist financing risk is rated medium in the national risk assessment, and maritime insurance carries a medium proliferation financing risk on the mainland.
  • Insurers, reinsurers, brokers, and agents carrying on in-scope insurance business must apply customer due diligence, sanctions screening, transaction monitoring, record keeping, and suspicious transaction reporting through goAML, proportionate to their role, products and risk.
  • On top of the federal laws, the Central Bank issues both general guidance for all licensed financial institutions and guidance specific to the insurance sector, including a dedicated insurance broker regulation.
  • This article catalogues the whole framework and links up to the banks and financial institutions pillar for the wider view.

Insurance is not the first sector people associate with money laundering, but life and investment-linked policies can be used to place, layer, and integrate illicit funds, and that is why the UAE brings insurers and brokers inside its anti-money laundering regime. This guide sets out the AML regulations for insurance companies in the UAE, covering insurers, agents and brokers: who is in scope, who supervises the sector, the full legal framework that applies, and how the national risk assessments rate the sector’s money laundering, terrorist financing, and proliferation financing risk. It is CBUAE-centric, since the Central Bank supervises mainland insurance, with the DIFC and ADGM regulators noted for firms in the financial free zones.

In short: UAE insurers, reinsurers, brokers and agents carrying on life, investment-linked or other relevant insurance business must comply with Federal Decree-Law No. 10 of 2025, its Executive Regulations in Cabinet Resolution No. 134 of 2025, the sanctions rules in Cabinet Resolution No. 74 of 2020, the CBUAE’s insurance-sector and licensed-institution guidance, and the UAE FIU’s goAML reporting duties. The clearest money laundering risks are single-premium policies, third-party premium payments, top-ups, early surrender, beneficiary changes, opaque corporate policyholders and sanctions exposure in marine or cargo cover.

Who counts as operating in the Insurance Sector for AML purposes in UAE?

AML obligations in the UAE insurance sector attach most clearly to the firms and people that write or arrange life and investment-linked business, the lines through which value can be stored, moved or returned, with further exposure in assignable, high-value, marine, cargo and cross-border insurance activity. General insurance and pure protection products usually present lower money laundering and terrorist financing risk, but CBUAE-licensed insurers, reinsurers, agents and brokers should still assess their own obligations against their licence, the applicable CBUAE guidance and the risk profile of their products, customers and claims activity.

Insurance companies

Insurers carrying on life insurance and investment-linked business are financial institutions for AML purposes. These products can hold and transfer value, can, in higher-risk cases, be funded in cash or cash-like means, and can be surrendered or assigned, which is what gives them money laundering relevance. Such insurers must run a full AML programme scaled to their products and customers.

In short, for life and investment-linked insurance, AML risk is highest where policies store value, accept top-ups, permit early surrender, allow assignment, or involve third-party premium funding.

Insurance brokers

Brokers arrange cover between clients and insurers and often handle client information and premium flows, which places them inside the AML perimeter for relevant business. The Central Bank maintains a dedicated regulation for insurance brokers, and brokers must apply customer due diligence, screening, and reporting appropriate to their role.

Insurance agents and intermediaries

Agents and other intermediaries who introduce or service relevant insurance business are also captured where they carry on activities that fall within the financial institution definition. Their obligations follow the nature of the business they handle and the customers they deal with.

AML Supervisory Authority for the Insurance Sector in UAE

Supervision of the insurance sector is shared between the federal regulator and the two financial free zone authorities. Your supervisor determines which rulebook and guidance apply to you.

Central Bank of the UAE (CBUAE)

The Central Bank is the AML supervisor for the mainland insurance sector, having taken on insurance supervision in addition to banking. It issues both general guidance for licensed financial institutions and guidance specific to insurance, inspects firms, and can impose administrative and financial penalties for breaches.

Dubai Financial Services Authority (DFSA)

The DFSA supervises insurers and insurance intermediaries established in the Dubai International Financial Centre, under its own AML rulebook that sits alongside the federal law.

Financial Services Regulatory Authority (FSRA)

The FSRA supervises insurance firms in the Abu Dhabi Global Market, maintaining its own AML rulebook and enforcement within the wider federal framework.

UAE FIU and goAML

In-scope insurers, reinsurers, brokers and agents register on the UAE Financial Intelligence Unit’s goAML platform and report through it. Registration on goAML is a baseline obligation, and suspicious transaction and activity reports, along with related filings, are submitted through it. See our goAML registration guide for the practical steps.

AML Legal Framework Applicable to Insurance Companies in UAE

The framework has five layers: the core federal laws, the guidance that applies to all reporting entities, the national risk assessments, the Central Bank’s general guidance for licensed financial institutions, and the Central Bank’s insurance sector-specific guidance. This section catalogues each layer, grounded in the Insurance CBUAE library.

At a glance, the instruments that make up this framework sit in the following hierarchy: 

Layer Instrument Why it matters 
AML statute Federal Decree-Law No. 10 of 2025 Core AML, CFT and CPF offences, the Financial Intelligence Unit, reporting duties and penalties 
Executive regulation Cabinet Resolution No. 134 of 2025 Working duties: risk-based approach, CDD, EDD, beneficial owner, monitoring, STRs and record keeping 
Central Bank law Federal Decree by Law No. 6 of 2025 The Central Bank, licensed financial institutions and insurance business framework 
Sanctions and TFS Cabinet Resolution No. 74 of 2020, with EOCN and CBUAE guidance Screening, freezing without delay, name-match reporting and sanctions duties 
Insurance conduct CBUAE Insurance Brokers’ Regulation and insurance-sector rules Licensing, conduct, governance and broker obligations 
CBUAE guidance Insurance-sector guidance and the CDD, monitoring, TFS, PEP, PF and TBML guidance Supervisory expectations for insurers and intermediaries 
National risk UAE ML and TF NRA 2024 and UAE PF NRA 2026 Baseline for the insurance sector’s risk assessment 

Federal AML Laws and Executive Regulations Applicable to Insurance Companies and Brokers in the UAE

These instruments are the legal foundation for every insurer and broker in scope.

Federal Decree-Law No. 10 of 2025 on AML, CFT and CPF

For an insurer writing life or investment-linked cover, or a broker placing it, Federal Decree-Law No. 10 of 2025 is the statute everything else answers to. It is the principal UAE law on money laundering, terrorist financing and proliferation financing, fixing the definitions that frame your obligations, including predicate offences, targeted financial sanctions and suspicious transactions, and recognising that abuse may run through virtual assets and cryptographic technology. It establishes the Financial Intelligence Unit within the Central Bank as the central agency that receives and analyses suspicious transaction reports, whether the trigger is an odd single-premium payment or an early surrender, and through the Head of the Unit, it may request further information and order the suspension or freezing of suspicious funds within the limits and procedures set by the law and the FIU regulation. It also places insurers under supervisory oversight and exposes them to administrative penalties.

Cabinet Resolution No. 134 of 2025, the Executive Regulations

Cabinet Resolution No. 134 of 2025 issues the Executive Regulations of Decree-Law No. 10 of 2025 and is the working rulebook that a compliance team actually opens. It expressly brings life insurance and other investment-related insurance products within scope, including cover distributed through agents and brokers, and adds concepts such as senior management, beneficial owner and reasonable measures. From these pages flow the daily duties: a risk-based approach, customer due diligence, verifying the beneficial owners behind corporate policyholders, and ongoing monitoring kept current across top-ups, assignments and changes of beneficiary. Insurers and brokers must maintain internal policies and controls approved by senior management and proportionate to their risks.

Cabinet Resolution No. 109 of 2023 on beneficial owner procedures

When a corporate policyholder sits behind a life or investment-linked contract, Cabinet Resolution No. 109 of 2023 shapes what an insurer or broker can learn about who really controls it. It regulates beneficial owner procedures for licensed or registered legal persons, defining the real beneficiary as the natural person who ultimately owns or controls the entity, directly or through a chain of ownership. Each legal person must keep accurate beneficial owner information, identify nominee board members, maintain a real beneficiary register and a shareholders register, and update them within short deadlines, generally fifteen days. These procedures apply to legal persons licensed or registered in the State, including commercial free zones, but exclude the financial free zones, the DIFC and ADGM, which operate their own beneficial ownership regimes.

Cabinet Resolution No. 132 of 2023 on penalties for beneficial owner violations

Cabinet Resolution No. 132 of 2023 puts teeth behind the beneficial ownership duties in Cabinet Resolution No. 109 of 2023 and explains why a corporate policyholder should keep its ownership data current. It empowers the registrar to fine legal persons that fail to maintain accurate registers or supply required data, following an annexed schedule of violations, without prejudice to other AML sanctions. Consequences escalate: on a third violation, the registrar may suspend the commercial licence and close the premises until the fine is paid. For an insurer or broker verifying the people behind a corporate contract, non-compliance carries a cost. These penalties apply to legal persons licensed or registered in the State, including commercial free zones, but not to the financial free zones, the DIFC and ADGM, which follow their own regime.

Cabinet Resolution No. 74 of 2020 on terrorist lists and UNSC resolutions

Sanctions screening for insurers and brokers begins with Cabinet Resolution No. 74 of 2020, which regulates the terrorist lists and gives effect in the UAE to United Nations Security Council resolutions on terrorism, its financing and the proliferation of weapons of mass destruction. It sets up a local Cabinet list alongside the Security Council lists, defines designation, listing and de-listing, and demands freezing measures without delay, within twenty-four hours. In practice an insurer or broker must register on the Executive Office website for notifications and continuously screen policyholders, prospective clients, beneficial owners of corporate policyholders and parties to transactions, whenever a list changes. On a match, freeze without notice and report promptly.

Federal Law No. 7 of 2014 on combating terrorism crimes

Federal Law No. 7 of 2014 on Combating Terrorism Crimes is the criminal statute that tells insurers and brokers what their controls are ultimately built to catch. It defines terrorist crime, terrorist purpose, terrorist organisation and terrorist person, distinguishes conventional from nonconventional weapons including toxins and radioactive materials, and prescribes penalties reaching life imprisonment and, in specified cases, death. It penalises anyone who provides, collects, prepares or maintains funds, or facilitates obtaining them, for a terrorist purpose, and addresses freezing suspect funds held within financial institutions. Because the AML framework defines terrorist acts partly by reference to this law, insurers use it to read the conduct behind a suspicious premium.

AML Guidance Applicable to All Reporting Entities

Beyond the core laws, the Central Bank, the FIU, and the Executive Office issue guidance and typologies that apply to all reporting entities. The instruments below sit in the overarching guidance set for licensed financial institutions.

UAE FIU Regulation No. 1 of 2026 on Suspension and Freezing Powers, April 2026

Dated April 2026, UAE FIU Regulation No. 1 of 2026 governs the postponement or suspension of suspicious transactions and the freezing of funds. Issued under the AML/CFT Decree-Law, it applies to reporting entities, including insurers as financial institutions, and complements existing reporting duties. It introduces the Postponement Suspicious Transaction Report, an urgent filing where funds suspected of crime face imminent transfer, withdrawal or dissipation, and sets a monetary threshold that does not apply to higher threat offences, third party laundering, organised crime or terrorist financing. It defines a Suspension Order of up to ten working days and a Freezing Order of up to thirty days, letting insurers hold at-risk payouts.

UAE FIU Strategic Analysis Report on Human Trafficking, April 2026

Dated April 2026, the UAE FIU Strategic Analysis Report on Human Trafficking analyses money laundering and financial flows tied to trafficking, drawing on suspicious transaction and activity reports filed with the Financial Intelligence Unit. It sets out objectives, methodology and scope, and covers the main forms, including sexual exploitation, forced labour and organ removal. It profiles subjects such as designated traffickers, organised crime groups, foreign politically exposed persons and money mules, assesses vulnerable sectors, then develops indicators grouped around customer profile, behaviour, transactional activity and documentation. For insurers and brokers it is a detection resource, helping firms link trafficking methods to behaviour across policyholders and beneficiaries and improve their reports.

Guidance on Targeted Financial Sanctions for Financial Institutions, DNFBPs and VASPs, March 2026

First published in January 2021 and last amended in March 2026, the Guidance on Targeted Financial Sanctions for Financial Institutions, DNFBPs and VASPs is issued by the Executive Office for Control and Non-Proliferation. It sets out four core obligations: registering in the Notification Alert System, screening against the UAE Local Terrorist List and the United Nations Consolidated List, freezing assets without delay while not making them available to designated persons, and reporting measures taken. The March 2026 update renames the Funds Freeze Report as the Confirmed Name Match Report. For insurers and brokers, it defines how to screen policyholders, beneficiaries and owners, and freeze payouts where a designation matches.

Joint Guidance on the Compliance Officer and MLRO, 2026

Issued in 2026 by the UAE Supervisory Sub-Committee, this Joint Guidance establishes a unified framework for appointing, empowering and holding to account the Compliance Officer or Money Laundering Reporting Officer across regulated sectors. Building on Federal Decree-Law No. 10 of 2025, Cabinet Resolution No. 134 of 2025 and the 2025 legal framework, it treats the role as a cornerstone of an effective AML, CFT and counter-proliferation regime. It sets expectations on appointment and resignation, requiring seniority, experience, operational independence, freedom from conflicts, board access and adequate resources, and addresses the compliance function and outsourcing. For insurers and brokers, it clarifies appointing a fit and proper officer over underwriting and claims.

FIU Strategic Analysis Report on Terrorist Financing, May 2025

Produced by the UAE Financial Intelligence Unit and published in May 2025, this strategic analysis report, subtitled Terrorist Financing Typologies and Facilitators, draws on the Unit’s databases for 2021 to 2024, including suspicious transaction and activity reports. It explains how terrorist financing works and maps typologies for moving and obscuring funds through financial institutions, unlicensed hawala, corporate networks, high-value goods, real estate, virtual assets and crowdfunding. It also profiles facilitators such as money mules, corporate nominees and professional service providers. For insurers and brokers, the developed risk indicators sharpen scrutiny of premium sources, third-party payers, sudden surrenders and changes of beneficiary that could disguise the movement of terrorist funds.

goAML FAQs, April 2024

Version 2.1, dated 18 April 2024, the goAML FAQs is a practical question and answer guide published by the UAE Financial Intelligence Unit to help reporting entities use the goAML system and its registration and access services. It addresses common registration and login problems with step by step remedies, covering expired one-time passwords at first login, pop-up authentication screens needing the system-issued username with a Google Authenticator passcode, the correct login sequence through the services portal, and resetting a forgotten password. For insurers and brokers, timely suspicious transaction and activity reporting depends on reliable goAML access, so this guidance helps compliance teams stay connected and meet reporting duties promptly.

PF Institutional Risk Assessment Guidance for FIs, DNFBPs and VASPs, December 2023

Published in December 2023, the Proliferation Financing Institutional Risk Assessment Guidance shows firms how to assess and manage their exposure to proliferation financing. It sets out a methodology built on inherent risks, control effectiveness and residual risk, names the risk categories and factors to score, and describes supporting measures across onboarding, KYC and customer due diligence, enhanced due diligence, sanctions and adverse media screening, ongoing monitoring, suspicious activity reporting and employee training. A customer risk-scoring questionnaire, elevated risk factors and worked case studies illustrate the approach. For insurers and brokers, it offers a repeatable framework to score corporate policyholders and beneficial owners, calibrate controls and document decisions supervisors can review.

Terrorist and Proliferation Financing Red Flags Guidance, December 2023

Updated in December 2023, the Terrorist and Proliferation Financing Red Flags Guidance gives insurers and brokers a consolidated set of indicators for spotting suspicious terrorist and proliferation financing, including evasion of targeted financial sanctions under United Nations Security Council Resolutions or local designations. It explains how sanctioned parties rename themselves and hide behind intermediaries and front companies, then presents terrorist financing red flags followed by proliferation indicators grouped by customer profile, account and transaction activity, maritime sector and trade finance. For life and investment-linked writers and for marine and cargo underwriters, this is a working reference that sharpens detection of evasion and clarifies when a suspicious report should be filed.

Suspicious Activity and Transaction Reporting Thematic Review, January 2023

Issued in January 2023, the Suspicious Activity and Transaction Reporting Thematic Review sets out findings and regulatory expectations from the 2022 AML and CFT examination of licensed financial institutions and designated non-financial businesses and professions. It focuses on the suspicious transaction and activity reporting framework and the transaction monitoring systems feeding it, organised around expectations and acceptable versus deficient practice across governance, policies, risk-based deployment of monitoring, data management, alert review, case investigation, reporting decisions and the post-reporting process. It applies expressly to insurers among other firms. For insurers and brokers, it is a practical benchmark to test monitoring of premiums, surrenders and claims before an inspection finds gaps.

Counter Proliferation Financing Guideline, November 2022

Published in November 2022 by the Executive Office for Control and Non-Proliferation, this guideline supplements the wider Guidance on Targeted Financial Sanctions and helps regulated firms identify, assess and mitigate proliferation financing risk in line with FATF standards. It explains what proliferation financing is, its stages and the UAE framework, then folds that risk into a firm’s own risk assessment. For insurers and brokers the document is directly relevant, because it names insurance products among the areas needing enhanced due diligence, alongside shell and front companies and dual-use goods. It matters especially to marine and cargo underwriters, supplying red flags that signal sanctions evasion tied to weapons of mass destruction.

goAML Web Submission Guide, July 2022

Issued by the UAE Financial Intelligence Unit in July 2022, the goAML Web Submission Guide sets out the steps for submitting a report to the FIU through the goAML platform. It is addressed to the designated Compliance Officer or Money Laundering Reporting Officer of a registered reporting entity, or the deputy when the lead officer is unavailable, guiding them through the submission process. It overviews report types, including the Suspicious Transaction Report and the Suspicious Activity Report, the latter covering suspected activity or an attempted, non-executed transaction, plus Additional Information File and Request for Information reports. For insurers and brokers, it standardises reporting, helping officers file correct reports promptly.

Joint Guidance on Combating the Use of Unlicensed Virtual Asset Providers, March 2022

Issued in March 2022 by the UAE Supervisory Authorities, including the Central Bank, the Securities and Commodities Authority and the Virtual Assets Regulatory Authority, this Joint Guidance aligns with FATF’s risk-based approach and warns the public and regulated firms about unlicensed virtual asset service providers. It urges confining virtual asset dealings to licensed entities and expects firms to stay vigilant to fraud, factor emerging risks into assessments, conduct due diligence, spot customers seeking unlicensed providers, and report suspicions. Red flags include no regulatory licence, no physical presence, unrealistic promises and pressure to invest quickly. For insurers and brokers, it helps flag policyholders whose premiums trace to unlicensed virtual asset activity.

IEMS User Guide for Reporting Entities, March 2022

Dated March 2022, the IEMS User Guide for Reporting Entities is a practical manual from the UAE Financial Intelligence Unit for its Integrated Enquiry Management System, which automates information requests, prosecution decisions and other AML and CFT instructions from domestic authorities. It covers registration and login, noting goAML-registered firms reuse those credentials, and walks through the dashboard, request management, and the reply workflow for account and signatory details. It sets out Admin, Maker and Checker roles, due dates, and implementing freeze orders immediately on the amount specified or the whole balance. For insurers and brokers, it shows how to action enquiries and freeze instructions touching policy accounts and payout balances.

goAML Pre-Registration Guide, March 2022

Issued by the UAE Financial Intelligence Unit in March 2022, the goAML Pre-Registration Guide explains how reporting entities gain access to the Services Access Control Manager, or SACM, before reaching the goAML application to register and file suspicious reports. The application is available through a public portal for entities not regulated by the Central Bank, except hawaladars, while entities under various Supervisory Bodies follow the set steps. It describes SACM as the gateway hosting links to the goAML production and testing environments, secured by a Google Authenticator one time password, and covers safeguarding a personal Secret Key that cannot be shared. For insurers and brokers, it precedes secure reporting access.

goAML Registration Guide, March 2022

Issued by the UAE Financial Intelligence Unit in March 2022, the goAML Registration Guide sets out the steps an organisation follows when registering with the FIU on its reporting platform, goAML. It covers registration as a reporting entity, stakeholder or supervisory body, and confirms that all accountable and reporting entities in the United Arab Emirates must register to submit suspicious reports; registration grants the right to file. It explains reaching the portal through the Services Access Control Manager, then covers selecting the registration type, entering organisation and address details, adding the registering person and passport data, uploading attachments and setting access rights. For insurers and brokers, it underpins compliant reporting.

Strategic Review on Targeted Financial Sanctions Case Studies, November 2021

Dated November 2021, the Strategic Review on Targeted Financial Sanctions Case Studies examines sanctions reporting in the United Arab Emirates, sitting within the framework by which the UAE, through Cabinet Resolution No. 74 of 2020, implements United Nations Security Council Resolutions on terrorism, terrorist financing and proliferation, including freezing measures and prohibitions on providing funds and services. It explains its methodology and timeline, then classifies reports by source, suspicion and instrument, drawing out terrorist financing and proliferation financing patterns with red flags, statistics and recommendations. For insurers and brokers, it shows how sanctions suspicions actually arise, helping sharpen screening of policies and payouts.

Typologies on the Circumvention of Targeted Sanctions, November 2021

Amended in November 2021 and issued by the Executive Office, this typologies report compiles cases showing how sanctioned persons, groups and entities try to circumvent targeted sanctions relating to terrorism and the proliferation of weapons of mass destruction. Drawing on public sources, it groups methods by channel: banking, money remitters, exchange houses, hawala, online payments, misuse of non-profit organisations, cash and gold smuggling, trade in dual-use goods and natural resources, legal-entity misuse and virtual assets, with named networks and red flags. For insurers and brokers, especially those underwriting corporate policyholders or marine and cargo risks, it turns evasion tactics into practical learning that strengthens screening, due diligence and monitoring.

Update to the List of High Risk Jurisdictions, November 2021

This November 2021 decision of the National Anti-Money Laundering and Combatting the Financing of Terrorism and Financing of Illegal Organizations Committee updates the list of high risk jurisdictions subject to a call for action, the list under increased monitoring and the counter-measures to apply, revising an earlier March 2021 decision. Addressed to bodies including the supervisory authorities and the Financial Intelligence Unit, it reflects the Committee’s mandate to identify higher-risk countries and set proportionate counter-measures. For insurers and brokers, country risk is a core input to risk-based controls: it signals which jurisdictions warrant enhanced due diligence on policyholders, beneficiaries and corporate owners, obliging firms to keep risk assessments current.

Joint Guidance on Satisfactory and Unsatisfactory Practice, June 2021

Published in June 2021 by the UAE Supervisory Authorities, including the Central Bank, the DFSA, the FSRA, the Securities and Commodities Authority and the Ministries of Justice and Economy, this Joint Guidance distils themes from inspections run between January 2020 and May 2021. It contrasts satisfactory and unsatisfactory practice across the AML framework, targeted financial sanctions and counter proliferation financing, covering governance, the three lines of defence, risk assessment, policies, training and the compliance officer role, plus onboarding, customer risk rating, due diligence, monitoring, screening and reporting. For insurers and brokers, it turns findings into benchmarks, helping firms test controls over policyholder onboarding and payout monitoring before an examiner does.

Typologies on the Circumvention of TFS, PF and WMD, May 2021

Amended in May 2021 and issued by the Executive Office, this typologies report examines how sanctioned persons, groups and entities receive financing in violation of or evasion of United Nations Security Council Resolutions on terrorism and the proliferation of weapons of mass destruction. It notes that targeted financial sanctions cover both asset freezing and bans on making funds available, directly or indirectly, to designated parties. Organised by financing method, it addresses misuse of banking, money remitters, hawala, online payments, non-profit organisations, cash smuggling, trade in goods and legal-entity misuse. For insurers and brokers, it explains how value moves past controls and reinforces the duty to report evasion.

goAML FAQs, September 2020

Issued by the UAE Financial Intelligence Unit in September 2020, the goAML FAQs Guide is a practical question-and-answer reference for reporting entities using goAML, the system through which suspicious reports are filed in the United Arab Emirates. It compiles queries commonly raised once an organisation is registered and active, with step-by-step responses. It explains how to reset a forgotten password, update organisation details such as name, licensed activity, address and contacts, and how the Money Laundering Reporting Officer, as admin user, delegates reporting to a third party subject to Supervisory Body approval. For insurers and brokers, accurate data and managed user access underpin timely reporting.

goAML Registration Guide Stage 2, September 2020

Issued by the UAE Financial Intelligence Unit in September 2020, the goAML Registration Guide Stage 2 outlines the steps an organisation follows when registering with the FIU on its reporting platform, goAML. It applies to registration as a reporting entity, stakeholder or supervisory body, and confirms that all accountable and reporting entities in the United Arab Emirates must register to submit suspicious reports. It notes that, since 27 June 2019, entities must submit reports electronically through goAML. It explains reaching the portal through the Services Access Control Manager and covers registering an organisation, setting access rights and resetting passwords. For insurers and brokers, it enables compliant reporting.

Guideline on Grievance Procedures

Issued by the Executive Office for Control and Non-Proliferation, the Guideline on Grievance Procedures explains how affected parties challenge designations on the UAE Local Terrorist List and the United Nations Consolidated List, together the Sanctions Lists. Under Cabinet Resolution No. 74 of 2020, it recognises three application types: de-listing a designation, lifting freezing measures, and permission to use frozen funds, distinguishing Local List designations by the Cabinet from United Nations designations by the Security Council. Crucially, it applies only to freezes arising from Sanctions List designations, not court orders or investigations. For insurers and brokers, it maps the lawful routes a frozen policyholder or beneficiary may pursue.

Online Grievance System User Guide

The Online Grievance System User Guide, issued by the Executive Office for Control and Non-Proliferation, walks users through the form for challenging designations on the UAE Local Terrorist List and the United Nations Consolidated List, together the Sanctions Lists. The Executive Office launched the online system to streamline three request types: de-listing, cancelling freezing measures, and permission to use frozen funds. The guide covers identifying the aggrieved individual or entity, selecting the relevant list and grievance type, declaring previous requests and appeals, and attaching documents. It clarifies that only Sanctions List freezes are covered. For insurers and brokers, it shows the route by which a frozen policyholder can seek relief.

Simple Guide to Subscribe to the EOCN Notification Alert System (NAS)

This short guide explains how to subscribe to the Notification Alert System on the Executive Office’s website so users receive timely updates to the sanctions lists applied in the United Arab Emirates. It notes that targeted financial sanctions rest on two lists, together the Sanctions Lists: the UAE Local Terrorist List issued by the Cabinet and the United Nations Consolidated List issued by the Security Council, both updated periodically. The guide shows where to access the lists and gives step-by-step subscription instructions. For insurers and brokers, it supports a core control: screening of policyholders and payees only works against current lists, so prompt alerts help firms freeze and report quickly.

Emerging ML, TF and PF Risks and Trends in the Financial Sector

Issued by the Supervisory Subcommittee under Article 16 of Federal Decree-Law No. 10 of 2025, this report gives regulated firms a current view of the money laundering, terrorist financing and proliferation financing threats reshaping the sector as technology, geopolitics and criminal methods evolve. It examines emerging risks such as artificial intelligence exploitation, greenwashing and ESG-related fraud, trade finance abuse, illicit virtual asset flows and sanctions evasion linked to the Commonwealth of Independent States. For insurers and brokers, the value lies in typologies and red flags to fold into risk assessments, particularly where corporate policyholders, opaque free-zone structures or single-premium life products might be exploited to place and layer illicit funds.

Typologies in the Financial Sector

Produced jointly by the Supervisory Authorities Sub-Committee and the Financial Intelligence Unit with a pilot group of institutions, Typologies in the Financial Sector shares money laundering, terrorist financing, sanctions, fraud and bribery typologies seen in the market, several emerging during the COVID-19 pandemic. It describes risks sitting above the National Risk Assessment, including growing use of unlicensed money service operators that balance books over time, and lists indicators that combine to obscure transactions, with links to modern slavery and human trafficking. For insurers and brokers, it works as an early warning tool, helping firms refresh policyholder and beneficiary risk assessments, refine monitoring scenarios and engage authorities when comparable patterns surface.

NRA, SRA, and Other Important Guidelines for the Insurance Sector

The UAE assesses its money laundering, terrorist financing, and proliferation financing risk at the national level, and insurers and brokers must align their own business and enterprise-wide risk assessments with those findings.

UAE PF National Risk Assessment 2026

The UAE Proliferation Financing National Risk Assessment 2026 rates maritime insurance at medium in the mainland and medium-low in the free zones, ratings that speak directly to marine and cargo underwriters. Prepared in response to the Financial Action Task Force’s revised Recommendation 1, it examines the financing of weapons of mass destruction and evasion of targeted financial sanctions relating to the Democratic People’s Republic of Korea and Iran, with overall country risk medium-high. For context, virtual asset service providers are rated high in the mainland; banks, exchange houses and registered hawala medium-high; free zone banks and money service businesses medium; stored value facilities medium-low. It should inform insurers’ sanctions screening.

The table below summarises the residual risk ratings insurers and brokers should reflect in their own risk assessments.

UAE ML and TF National Risk Assessment 2024

The UAE Money Laundering and Terrorist Financing National Risk Assessment 2024 rates the insurance sector at medium residual risk, with inherent risk also medium, a rating insurers and brokers should treat as their baseline. Prepared by the National Committee using the World Bank methodology on data from 2019 to 2023, this second assessment covers financial institutions across the mainland and free zones, with overall national money laundering residual risk medium-high and drug trafficking and fraud among the highest threats. Other sub-sectors are rated for context: banking medium-high, exchange houses medium-high, registered hawala high, finance companies medium, securities medium to medium-high. It should inform each insurer’s risk-based approach and policyholder ratings.

Insurance segment  ML and TF residual risk  PF residual risk 
Life and investment-linked insurance  Medium  Comparatively low, non-depository 
Maritime insurance  Within the medium sector rating  Medium (mainland); medium-low (free zones) 
General and protection insurance  Limited AML exposure  Low 

CBUAE Guidance Applicable to the Insurance Sector

Older CBUAE guidance, standards and outreach material below should be read together with, and subject to, Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025, to the extent they remain in force and are not inconsistent with the current framework.

The Central Bank’s guidance for licensed financial institutions applies to insurers and brokers as it does to other supervised firms. The documents below make up that general guidance set.

CBUAE Best Practices for Licensed FIs on Implementing Role-Based AML/CFT/CPF Training, October 2025

Published in October 2025, the CBUAE Best Practices on Role-Based AML/CFT/CPF Training show insurers and brokers how to shape learning around each job rather than a single generic course. The guidance asks firms to match content, frequency and intensity to the risks a role actually carries, so underwriters, claims handlers and broker-facing staff each learn the red flags that surface in their own work. It sets expectations for the Board, owners, senior management and the three lines of defence, and explains how to document the programme, refresh it, choose delivery methods and keep records. For insurers, well-targeted training sharpens the judgement staff need when assessing life and investment business.

CBUAE Best Practices for Licensed FIs on a Risk-Based Approach and Institutional Risk Assessments, October 2025

Insurers and brokers sit squarely within the scope of the CBUAE Best Practices on the Risk-Based Approach and Institutional Risk Assessments, dated October 2025, which names insurance and reinsurance companies, agents and brokers among the institutions it covers. Issued under Article 44.11 of Cabinet Decision No. 10 of 2019, it helps firms build an assessment methodology and scale controls to their money laundering, terrorist financing and proliferation risks. It sets out how to weigh inherent risk across customers, products, channels, geographies and operating structure, then evaluate controls to reach residual risk. Life and single-premium investment lines usually warrant deeper scrutiny than pure protection cover, and the assessment should reflect that.

CBUAE Guidance for Licensed FIs on Correspondent Banking, October 2025

Cross-border money movement is a daily reality for insurers settling international premiums, ceding risk to overseas reinsurers and paying claims abroad, and the CBUAE Correspondent Banking Guidance of October 2025 speaks to how those flows are controlled. It explains requirements for institutions that process cross-border funds transfers, and the risk factors attached to a counterparty, including nested relationships, payable-through accounts, geography, ownership structures and customer base. On mitigation, it addresses risk assessment, standard, specific and enhanced due diligence, ongoing monitoring, sanctions screening with confirmed and partial match reporting, governance, audit and training. For insurers, robust checks matter because reinsurance settlement chains expose a firm to parties it never directly onboards.

CBUAE Guidance for Licensed FIs on Customer Due Diligence and Record-Keeping, October 2025

For insurers and brokers, policy onboarding is where financial crime controls begin, and the CBUAE Customer Due Diligence and Record-Keeping Guidance of October 2025 sets the foundation. It describes due diligence as the cornerstone for understanding a customer, including occupation, source of funds, source of wealth and expected activity, which is especially telling for single-premium and investment-linked business. The guidance covers identifying customers, beneficial owners and those acting on a policyholder’s behalf, building a risk profile through segmentation, and applying simplified or enhanced measures by risk. Sections on beneficiaries, name screening, non-face-to-face onboarding, exit and record-keeping, supported by red flag indicators, help firms detect and report suspicious activity.

CBUAE Guidance for Licensed FIs on Risks Related to Proliferation Finance, October 2025

Marine, cargo and reinsurance underwriters have a direct stake in the CBUAE Guidance on Proliferation Finance of October 2025, which expressly names insurance and reinsurance among the channels through which the financing of weapons of mass destruction can flow. Read alongside the Central Bank’s Procedures and Guidelines, it explains what proliferation financing is, then examines the vulnerable structures it exploits, including trade finance, free trade zones and shell and front companies. It addresses United Nations Security Council and FATF obligations, local requirements and a risk-based approach across customer, product, geographic, channel and operational risk. Mitigating controls span due diligence, transaction monitoring, suspicious activity reporting, targeted sanctions, governance, audit and training.

CBUAE Guidance for Licensed FIs on Risks Related to Trade-Based ML and Transhipment, October 2025

Marine and cargo cover follows goods across borders, which places the CBUAE Guidance on trade-based money laundering and Transshipment of October 2025 firmly within an insurer’s field of view. It provides background on the trade system and trade finance, then sets out typologies criminals use, including over- and under-invoicing, over- and under-shipment, multiple invoicing, falsely described goods, shell, front and shelf companies, free trade zones and back-to-back letters of credit. It also covers services-based laundering, vulnerable sectors such as gold and precious metals, and illicit transhipment. On mitigation, it addresses enterprise-wide risk assessment and enhanced due diligence, since trade can disguise the true value or movement of insured goods.

Federal Decree by Law No. 6 of 2025 on the Central Bank and the insurance business

Federal Decree by Law No. 6 of 2025 is not the AML law, but it sits underneath it for insurers. Concerning the Central Bank, the Regulation of Financial Institutions and Activities, and Insurance Business, it treats banks, (re)insurance companies and other financial institutions as licensed financial institutions under Central Bank licensing and supervision, replacing the earlier Central Bank law of 2018. An insurer, broker or agent should read it alongside Federal Decree-Law No. 10 of 2025 when working out its licensing, conduct and supervisory position, because it defines who the Central Bank licenses and oversees in the insurance market.

CBUAE AML and CFT Guidelines for Financial Institutions, July 2023

Dated July 2023, the CBUAE AML/CFT Guidelines for Financial Institutions are the consolidated reference that shapes how insurers and brokers run their compliance programmes. Prepared jointly by the UAE Supervisory Authorities, they state minimum expectations for identifying, assessing and mitigating money laundering, terrorist financing and illegal organisation risks. Crucially, they apply expressly to insurance companies, agencies and brokers, alongside their boards, management and staff. The guidelines outline the legal framework, summarise statutory obligations, and explain money laundering, predicate offences and typologies. A substantial part addresses the risk-based approach, covering business-wide risk assessment and risk factors tied to policyholders, products, channels and geography, guiding due diligence and reporting across your book.

CBUAE Guidance for Licensed FIs on Risks Related to Virtual Assets and VASPs, February 2023

When a policyholder funds a premium from cryptocurrency or is otherwise exposed to digital assets, the CBUAE Guidance on Virtual Assets and Virtual Asset Service Providers of 20 February 2023 becomes relevant to insurers and brokers. It explains the threats and vulnerabilities virtual assets create, the ways firms may become exposed, and the UAE framework spanning the SCA, CBUAE, VARA and FSRA. It sets out the non-objection requirement before opening accounts for such providers and covers the risk-based approach, due diligence and enhanced measures for higher-risk customers and transactions. Because virtual assets move value rapidly and pseudonymously, understanding a crypto-exposed client’s source of funds is central to protecting the firm.

CBUAE Guidance for Licensed FIs on Digital Identification for Customer Due Diligence, October 2022

Issued on 31 October 2022, the CBUAE Guidance on Digital Identification for Customer Due Diligence helps insurers and brokers understand how digital identity systems can verify clients and support ongoing due diligence, particularly valuable when policies are sold non-face-to-face online. It reflects CBUAE’s expectations. The guidance explains digital identity systems and their participants, identity proofing and enrolment, authentication, lifecycle management, and portability and interoperability. It then shows how such systems support identification, verification, ongoing due diligence and third-party reliance. It examines the risks these systems present and how to assess reliability through assurance levels. Reliable digital identification strengthens remote policy onboarding while introducing risks insurers must manage.

CBUAE Guidance for Licensed FIs on Suspicious Transaction Reporting, August 2022

Issued on 3 August 2022, the CBUAE Guidance on Suspicious Transaction Reporting shows insurers and brokers how to identify, investigate and report suspicious activity, whether it surfaces in an inflated premium, an early surrender or a questionable claim. It explains the legal basis for reporting, the protection given to those who disclose, the consequences of failing to report, and the meaning of a suspicious transaction. It details the three lines of defence, the role of the compliance officer or MLRO, transaction monitoring methods, and how to draft, structure, submit and amend a report. Further sections cover alert timing, matters needing immediate attention, and the strict prohibition on tipping off policyholders.

CBUAE Guidance for Licensed FIs on Risks Relating to Payments, August 2022

Dated August 2022, the CBUAE Guidance on the Risks Relating to Payments addresses the laundering and terrorist financing risks moving through the payments sector, relevant to insurers and brokers who collect premiums and disburse claims through varied payment channels. Issued under Article 44.11 of Cabinet Decision No. 10 of 2019, it states regulator expectations rather than new law. It explains what makes payments vulnerable: the speed of funds, peer-to-peer transfers, cross-border movement, intermediation, nesting, and the use of agents. On mitigation it references risk assessment, customer and enhanced due diligence, ongoing monitoring, wire transfers, sanctions and suspicious transaction reporting, helping insurers calibrate controls to a fast-moving payment environment.

CBUAE Guidance for Licensed FIs on Risks Relating to Politically Exposed Persons, August 2022

Dated August 2022, the CBUAE Guidance on Politically Exposed Persons shows insurers and brokers how to manage the heightened risk carried by prominent clients, a live concern for high-net-worth life and investment policyholders. Issued under Article 44.11 of Cabinet Decision No. 10 of 2019, it stresses that such clients need not be avoided but do require thorough due diligence before onboarding or continuing. It distinguishes domestic and foreign politically exposed persons and heads of international organisations, extending to family members and close associates. It covers classification, time limits on status, screening, risk rating, enhanced due diligence, transaction monitoring, suspicious transaction reporting, governance and training, with an annex of red flags.

CBUAE Guidance for Licensed FIs on Transaction Monitoring and Sanctions Screening, September 2021

Issued on 8 September 2021, the CBUAE Guidance on Transaction Monitoring and Sanctions Screening explains how insurers and brokers should design, run and maintain the systems that detect suspicious activity and identify sanctioned parties. On monitoring, it covers risk assessment, risk-based deployment, data management, rule definition and testing, alert scoring, outcomes analysis and ongoing tuning. On screening, it addresses name and transaction screening design, list management, testing and validation, essential when checking policyholders, beneficiaries and payees. A governance section covers management reporting, auditing, use of vendors, training and record keeping. Well-calibrated, validated systems help insurers spot suspicious premium or claim flows and avoid dealings with sanctioned persons.

CBUAE Guidance for Licensed FIs to Cash-Intensive Businesses, September 2021

Published in September 2021, the CBUAE Guidance on Cash-Intensive Businesses helps insurers and brokers manage the laundering and terrorist financing risks that surface when policyholders settle premiums in large volumes of cash. Issued under Article 44.11 of Cabinet Decision No. 10 of 2019, it sets regulator expectations rather than new law. It explains why cash is vulnerable, the risks of alternatives such as bearer instruments and prepaid cards, and concerns around cross-border cash movement and couriers. On mitigation, it prescribes an enterprise risk assessment, customer and beneficial owner identification, enhanced due diligence, ongoing and transaction monitoring, suspicious transaction reporting, governance and training, so cash-paying clients face proportionate scrutiny.

CBUAE Guidance for Registered Hawala Providers and LFIs, August 2021

Issued by the CBUAE in August 2021, this combined guidance addresses both registered hawala providers and the licensed financial institutions that serve them, and because insurers rank as LFIs, its expectations for those institutions reach the insurance sector. It explains what hawala is, drawing on the FATF description of hawaladars as money transmitters who arrange transfers and settle through trade, cash and long-term net settlement, often tied to particular regions or communities. It describes the global risks of hawala, its regulation and supervision in the UAE, and permitted and non-permitted services. Further parts cover sanctions and freezing without delay, and an AML/CFT programme spanning customer, enhanced and agent due diligence.

CBUAE Guidance for Licensed FIs on Implementation of Targeted Financial Sanctions, July 2021

Dated 4 July 2021, the CBUAE Guidance on the Implementation of Targeted Financial Sanctions helps insurers and brokers meet their duty to identify, freeze and report assets and transactions linked to designated persons. Read with the CBUAE procedures and Executive Office guidance, it sets out how to build a sanctions compliance programme: senior management commitment, risk assessment and appetite, internal controls, training, independent audit and record keeping. It then addresses screening operations, evasion, the United Nations Consolidated List and Local Terrorist List, verifying false positives, and handling confirmed matches. For insurance, this means screening policyholders, beneficiaries and payees before paying claims or surrenders, and notifying the authorities of any hit. Screening should cover policyholders, beneficiaries, payees, beneficial owners, assignees, reinsurers and relevant counterparties, and any entity owned or controlled by a designated person, not only the named customer.

CBUAE Guidance for Licensed FIs to Legal Persons and Arrangements, June 2021

Dated June 2021, the CBUAE Guidance on Legal Persons and Arrangements helps insurers and brokers manage the risks that arise when a policyholder is a company, other legal person or legal arrangement rather than an individual. It explains how such structures can obscure identity and beneficial ownership, hide the purpose of a policy or transaction, and conceal the source of funds. It then covers mitigating controls: formation requirements, identifying and reporting beneficial owners, record keeping, economic substance, customer risk rating, the institutional risk assessment, and enhanced due diligence. For insurers, piercing corporate policyholders to their true owners is central to preventing misuse of your products.

CBUAE Guidance for Licensed FIs to the Real Estate and Precious Metals and Stones Sectors, June 2021

Issued on 16 June 2021, the CBUAE Guidance on the Real Estate and Precious Metals and Stones Sectors helps insurers and brokers understand the risks that arise when clients are active in these two higher-risk sectors. Read with the CBUAE procedures, it does not replace legal obligations, which prevail in any conflict. Organised around understanding and mitigating risk, it describes risk-raising features, typologies, and how each is regulated in the UAE. On mitigation it explains the risk-based approach, customer and enhanced due diligence, suspicious transaction reporting, governance and training, with annexed red flags. For insurers exposed to property developers or bullion dealers, it frames the expected scrutiny.

CBUAE STR Outreach for Banks and Finance Companies, March 2021

Delivered on 10 March 2021, this Financial Intelligence Unit outreach session briefed banks and finance companies on suspicious transaction reporting, with input from the Ministry of Interior. Its expectations reach every institution that files through goAML, so an insurer or insurance broker can read across the same messages: when a report is warranted, the quality the FIU expects, goAML as the sole channel, and the compliance officer’s role. For life and investment-linked business it reinforces prompt, well-grounded reporting of unusual premium, surrender or beneficiary activity rather than defensive or late filing.

CBUAE Board of Directors Decision No. 59/4/2019 on AML and CFT procedures

Board of Directors Decision No. 59/4/2019, dated 13 June 2019, remains a supervisory and historical source that brought UAE insurers and brokers under CBUAE anti-money laundering supervision. Issued under the Central Bank Law, Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025, it treats any entity conducting financial operations for a customer as a financial institution, capturing life offices and their intermediaries. It obliges them to observe the law, the implementing regulation and CBUAE instructions. For insurers, it means the regulator may examine your files without notice, demand information on policyholders and premiums, and impose sanctions, which it may publish, for compliance failures. It should be read subject to Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025, which now set the current framework.

CBUAE Guidance Note on Responsible Use of AI and ML by LFIs

As insurers adopt models to price risk, screen applications and monitor transactions, the CBUAE Guidance Note on the Responsible Use of Artificial Intelligence and Machine Learning offers principles for doing so ethically and with the consumer in mind, including generative AI. It is non-binding and meant to help firms shape their own internal policies, treating its principles as flexible so they evolve with the technology. It places responsibility for AI systems and outcomes with senior management and the Board, and calls for a documented governance framework and an inventory of all models. It addresses fairness, transparency, data quality, privacy, monitoring and meaningful human oversight, so automated decisions affecting policyholders are governed responsibly.

CBUAE List of Administrative and Financial Sanctions

Enforcement reaches every licensed institution, insurers included, and the CBUAE List of Administrative and Financial Sanctions records the penalties the Central Bank can impose for shortcomings in anti-money laundering and sanctions compliance. Under Article 14 of Decretal Federal Law No. 20 of 2018, as amended by Federal Decree Law No. 26 of 2021, the CBUAE can impose administrative penalties from a warning up to licence revocation, and financial penalties of no less than fifty thousand and no more than five million dirham per violation. Under Article 137 of the Central Bank Law, penalties reach a fine of up to two hundred million dirham, with licence withdrawal and striking off.

CBUAE Insurance Sector-Specific Guidance

Alongside its general guidance, the Central Bank issues material aimed specifically at the insurance sector.

CBUAE Insurance Brokers' Regulation, Circular No. 1/2024 (1 April 2024)

The CBUAE Insurance Brokers’ Regulation is the prudential and conduct framework governing the licensing and supervision of insurance brokers in the UAE. It sets out licensing conditions, the rights and obligations of brokers towards insurance companies and clients, prudential requirements addressing financial soundness, risk management, internal controls and disclosure, and the Central Bank’s supervisory powers. It is structured around articles covering definitions, licensing, the fit and proper process, brokerage agreements, premiums and claim settlements, corporate governance, accounting, conduct of business, record-keeping, outsourcing and enforcement. The Central Bank applies proportionality according to the nature, scale and complexity of a broker’s business. It matters because it defines the standards brokers must satisfy. It was issued as Circular No. 1/2024, dated 1 April 2024.

CBUAE Guidance for the Insurance Sector, October 2022

The Guidance for the Insurance Sector, issued by the CBUAE’s AML/CFT Supervision Department in October 2022, helps licensed insurers, agents and brokers understand and manage the money laundering and terrorist financing risks specific to insurance. Issued under Article 44.11 of Cabinet Decision No. 10 of 2019 and read alongside the CBUAE’s Procedures and Guidelines, it sets out expectations firms must demonstrate rather than new legislation. It examines risks in life and investment products across product, distribution channel, customer and geographic factors, then turns to mitigation, covering the risk-based approach, enterprise risk assessment, customer due diligence including simplified and enhanced measures, and suspicious transaction reporting. It helps insurers calibrate controls proportionately.

CBUAE Insurance STR Outreach, March 2021

The CBUAE Insurance STR Outreach, delivered in March 2021, is an awareness session prepared by the Financial Intelligence Unit and the CBUAE to strengthen suspicious transaction reporting across the insurance sector. It covers when to report, grounding the duty in Article 15 of Federal Decree-Law No. 20 of 2018 and Article 17 of Cabinet Decision No. 10 of 2019, and what to report: any suspicion that funds are proceeds of crime or relate to terrorist financing. It sets out insurance-specific red flags, including borrowing against surrender value, single large premiums, bearer policies and unclear beneficial ownership. It confirms goAML is the only channel and helps insurers recognise and report suspicion.

Core AML Obligations for Insurers and Brokers at a Glance

Whatever the licence, the AML regulations for insurance companies and brokers in the UAE turn on a common set of duties.

The controls a supervisor expects to see evidenced, and the guidance behind them, map onto these areas:

Law or guidance  Control area  What insurers and brokers should evidence 
CBUAE RBA and Institutional Risk Assessment guidance; Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025  Business and enterprise-wide risk assessment  Risk rated by product, customer, channel, geography, premium flow and claims exposure, aligned to the national risk assessments 
CBUAE Customer Due Diligence and Record-Keeping Guidance, October 2025  Onboarding  Policyholder and beneficial owner identity, purpose of cover, and source of funds or wealth where the risk is higher 
CBUAE Guidance for the Insurance Sector, October 2022  Product risk  Closer scrutiny of life, investment-linked, single-premium and assignable policies 
CBUAE Transaction Monitoring and Sanctions Screening Guidance, September 2021  Ongoing monitoring  Top-ups, early surrender, cancellation, beneficiary changes, third-party premium funding and claims payouts 
CBUAE Implementation of Targeted Financial Sanctions Guidance, July 2021; EOCN Guidance on Targeted Financial Sanctions  Sanctions screening  Policyholders, beneficiaries, payees, beneficial owners and assignees, screened on every list change 
CBUAE Insurance Brokers’ Regulation, Circular No. 1/2024  Broker controls  A clear role, client information, premium handling and escalation of suspicion 
CBUAE Suspicious Transaction Reporting Guidance, August 2022; UAE FIU goAML  goAML reporting  STR and SAR decisions filed through goAML, no tipping-off, with the investigation rationale recorded 
CBUAE Best Practices on Role-Based Training, October 2025; Cabinet Resolution No. 134 of 2025  Governance and training  Compliance officer or MLRO independence, senior management and board oversight, training, audit and remediation 

Expert Tip:

For life and investment insurers, the moments that matter most are top-ups, early surrenders, and changes of beneficiary. Build monitoring around those events, because that is where laundering through insurance actually shows up, not in the routine premium.

Conclusion

AML regulations for insurance companies and brokers in the UAE follow the same logic as the wider financial sector: if you carry on life or investment-linked business, you are a financial institution, the Central Bank or your free zone regulator supervises you, and the federal laws, the executive regulations, the sanctions rules, and the Central Bank’s general and insurance-specific guidance all apply. The sector’s risk is rated medium rather than high, but the obligations are real, and supervisors expect a programme that matches the actual product and customer risk. Use the national risk assessments to calibrate, and treat this guide as the map. For the wider view, see our guide to anti-money laundering laws in the UAE and the pillar on AML regulations for banks and financial institutions in the UAE.

Frequently Asked Questions

Are insurance companies subject to AML regulations in the UAE?

Yes. Insurers carrying on life and investment-linked business are financial institutions under Federal Decree-Law No. 10 of 2025, supervised for the mainland by the Central Bank, and must run customer due diligence, screening, monitoring, and reporting. General and protection insurance carries limited AML exposure.

Yes. Brokers that arrange relevant insurance business are inside the AML perimeter, and the Central Bank maintains a dedicated insurance broker regulation. Brokers must apply customer due diligence, sanctions screening, and suspicious transaction reporting appropriate to their role.

The UAE ML and TF National Risk Assessment 2024 rates the insurance sector at medium residual risk, with a medium inherent risk, reflecting the limited ways life and investment products can be abused. Maritime insurance carries a medium proliferation financing risk in the mainland and medium-low in the financial free zones.

The Central Bank of the UAE supervises the mainland insurance sector. Insurers and intermediaries in the DIFC are supervised by the DFSA and those in the ADGM by the FSRA, each under its own AML rulebook alongside the federal law.

Life insurance and investment-linked products carry the most risk, because they can store and transfer value, can, in higher-risk cases, be funded in cash or cash-like means, and can be surrendered or assigned. Monitoring should focus on top-ups, early surrenders, and beneficiary changes.

Yes. Insurers, brokers, and agents in scope must register on the UAE Financial Intelligence Unit’s goAML platform and file suspicious transaction and activity reports, along with related filings, through it.

The Central Bank issues insurance-specific material including the CBUAE Insurance Brokers’ Regulation, the CBUAE Guidance for the Insurance Sector of October 2022, and insurance STR outreach, in addition to its general guidance for all licensed financial institutions. This CBUAE insurance AML guidance sits on top of the federal AML rules for insurers.

Insurers and brokers must identify and verify the customer and any beneficial owner, screen against sanctions and politically exposed person lists, and risk-rate the relationship before cover incepts. For investment-linked and higher-value life business they should establish the source of funds and, where risk is higher, apply enhanced due diligence. Onboarding checks then feed ongoing monitoring across the life of the policy.

Typical indicators include premiums settled in cash or by an unrelated third party, early surrender or cancellation with the refund directed elsewhere, frequent unexplained top-ups, cover that does not fit the customer’s profile or means, and reluctance to provide beneficial owner or source of funds information. These signs, drawn from the sector typologies and red flag guidance, should trigger escalation and, where suspicion remains, a report through goAML.

No. General insurance usually carries lower money laundering risk than life or investment-linked cover, but a CBUAE-licensed insurer, agent or broker should still assess its own position under the Central Bank’s rules and guidance, its licence, its sanctions duties and the risk profile of its products and customers.

The ones where value can move or change hands: single large premiums, third-party premium payments, frequent top-ups, early surrender or cancellation with a refund sent elsewhere, beneficiary or assignee changes, and any claim or payout involving sanctioned, high-risk or opaque parties.

Need help building or reviewing your insurance AML programme?

Strengthen your AML framework with practical solutions designed to help insurance providers meet regulatory requirements and reduce compliance risks.

Share via :

About the Author

Pathik Shah

FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)

Pathik is an ACAMS-certified AML consultant specialising in governance, risk, and compliance for regulated entities in the UAE. He brings over 28 years of experience, with 1,000+ hours of AML training and 200+ advisory engagements across DNFBPs, VASPs, and FIs. He supports businesses in aligning with AML/CFT requirements from the CBUAE, DFSA, MoET, MoJ, VARA, CMA, FSRA, and FATF. Known for translating complex regulations into audit-ready procedures, Pathik enables operational clarity and compliance readiness.

Reach Out to Pathik

AML Regulations for Banks and Financial Institutions in UAE

AML Regulations for Banks and Financial Institutions in UAE

Blogs

Published On: 07/09/2026

Table of Contents

Protect your business with reliable and effective AML strategies with AML UAE.

Last Reviewed On: 07/09/2026   |   Last Updated On: 07/09/2026

Key Highlights

  • The principal statute is Federal Decree-Law No. 10 of 2025 on anti-money laundering, combating the financing of terrorism, and proliferation financing, read together with its Executive Regulations in Cabinet Resolution No. 134 of 2025.
  • Financial institutions are a defined class under UAE AML law. Banks, insurance firms, exchange houses and money service businesses, registered hawala providers, capital market firms, finance companies, and other licensed financial institutions all fall inside it.
  • Supervision is shared. The Central Bank of the UAE oversees most mainland financial institutions, the Capital Market Authority oversees the capital market, and the DFSA and FSRA supervise firms in the DIFC and ADGM financial free zones.
  • Every regulated institution reports suspicious activity to the UAE Financial Intelligence Unit through the goAML platform.
  • The national risk assessments rate residual money-laundering risk as highest for registered hawala providers and medium-high for banks and exchange houses, with proliferation-financing risk concentrated in trade finance (UAE ML and TF National Risk Assessment 2024; UAE PF National Risk Assessment 2026).
  • Core obligations span the sector: risk assessment, customer due diligence, sanctions screening, transaction monitoring, recordkeeping, and suspicious transaction reporting.
  • This page is the overview. Each sector has its own dedicated guide for the finer details.

Banks and financial institutions sit at the centre of the UAE’s fight against money laundering. They move most of the money, so they carry most of the responsibility to spot and stop it. This guide sets out the AML regulations for banks and financial institutions in the UAE. It discusses which institutions are covered, who supervises them, the full legal framework they answer to, and how the national risk assessments rate the money laundering, terrorist financing, and proliferation financing risk of each sub-sector. It is a map of the whole regime, with links out to detailed sector guides where you need to go deeper.

Banks and financial institutions in the UAE are subject to Federal Decree-Law No. 10 of 2025, Cabinet Resolution No. 134 of 2025, targeted financial sanctions rules, and the guidance or rulebook issued by their relevant AML supervisor. Mainland banks, exchange houses, finance companies, insurers and registered hawala providers are generally supervised by the Central Bank of the UAE. Mainland capital market firms are supervised by the Capital Market Authority, formerly SCA. DIFC firms are supervised by the DFSA, and ADGM firms by the FSRA. Suspicious reports are filed with the UAE FIU through goAML.

Which banks and financial institutions are covered by UAE AML Law?

Under Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025, a “financial institution” is any entity that carries on one or more defined financial activities, whether licensed onshore by the Central Bank or in one of the financial free zones. If your business takes deposits, moves money, underwrites insurance, deals in securities, or lends, you are almost certainly inside the AML regulations for banks and financial institutions in the UAE. The categories below each have their own dedicated guide.

Banks

Banks are the widest and most heavily supervised group. The category covers commercial banks, wholesale banks, and the branches of foreign banks licensed by the Central Bank of the UAE. They take deposits, lend, run payment and correspondent banking relationships, and provide trade finance, so almost every money laundering, terrorist financing, and sanctions typology touches a bank at some point. Their scale, openness, and extensive cross-border networks are exactly what make them attractive to criminals, which is why they sit at the front line of the UAE regime and carry the deepest set of obligations. Read the dedicated guide: AML regulations for banks in the UAE.

Insurance

Life insurance and investment-linked products can be used to place and layer illicit funds, particularly where premiums can be settled in cash or policies surrendered early. The category captures insurers, brokers, agents, and other intermediaries carrying on relevant life and investment-related business. General insurance and pure protection products normally present lower ML and TF risk, but licensed insurers, brokers and agents supervised by the Central Bank should still assess their AML obligations and apply controls proportionate to their products and customers. Firms in this sector are treated as financial institutions and must run customer due diligence, screening, and reporting on the relevant lines. Read the dedicated guide: AML regulations for insurance companies and brokers in UAE.

Exchange houses and MSBs

Exchange houses and money service businesses handle currency exchange, remittance, wage payments, and banknote trading, which makes them a classic conduit for structuring and the cross-border movement of value. Because they deal in cash and often route payments through foreign correspondents, they carry a heightened risk of layering and third-party laundering. They are licensed and supervised by the Central Bank and must apply the same core AML controls as other licensed institutions. Read the dedicated guide: AML regulations for exchange houses in UAE.

Registered hawala providers

Hawala and other informal value transfer systems are legal in the UAE only when the provider holds a registration certificate from the Central Bank. Registered hawala providers carry AML duties in their own right, including customer identification, record-keeping, and suspicious transaction reporting through goAML. Their cash-based, relationship-driven model is inherently harder to monitor, so supervision of the sector is close. Read the dedicated guide: AML regulations for registered hawala providers in UAE.

Capital Market

The capital market covers brokerages, custodians, fund managers, investment managers, and other firms dealing in or advising on securities and commodities. These firms are financial institutions for AML purposes and are supervised for the capital market under the framework of the Capital Market Authority. Although securities firms do not take cash deposits, they must still identify their clients, screen against sanctions lists, and monitor for market-based laundering. Read the dedicated guide: AML regulations for capital market firms in UAE.

Finance Companies

Finance companies provide credit, consumer and commercial financing, and related lending services, and are licensed and supervised by the Central Bank of the UAE. They are captured as financial institutions and carry the full set of core AML obligations, scaled to their products and customer base. Their exposure tends to be lower than that of deposit-taking banks, but lending can still be used to integrate illicit funds. Read the dedicated guide: AML regulations for finance companies in the UAE.

Other LFIs

The financial institution definition is deliberately broad, so other licensed financial institutions carrying on defined activities are captured even where they do not fit the labels above. This includes certain payment and stored value activities and other specialist licensed models. Where a firm carries on a regulated financial activity, it should assume the AML framework applies and confirm its status with its supervisor. Read the dedicated guide: AML regulations for other LFIs in the UAE.

AML Supervisory Authority for Banks and Financial Institutions in UAE

Supervision in the UAE is shared between the federal financial regulators and the two financial free zone authorities. Knowing your supervisor matters because it determines which rulebook, guidance, and enforcement powers apply to you.

Central Bank of the UAE (CBUAE)

The Central Bank is the AML supervisor for most mainland financial institutions, including banks, exchange houses, finance companies, registered hawala providers, insurers, and money service businesses. It issues sector guidance, inspects licensed institutions, and can impose administrative and financial penalties for breaches. Institutions should expect their AML programme to be tested by thematic inspections.

Capital Market Authority

The capital market is supervised by the Capital Market Authority, formerly the Securities and Commodities Authority, under Federal Decree-Law No. 32 of 2025. It sets AML expectations for brokerages, custodians, fund managers, and other securities and commodities firms, and monitors their compliance.

Dubai Financial Services Authority (DFSA)

The DFSA is the independent regulator for firms established in the Dubai International Financial Centre. It runs its own AML rulebook that applies alongside the federal law, so a DIFC firm answers to the DFSA for day-to-day supervision while still meeting the UAE’s overarching AML obligations.

Financial Services Regulatory Authority (FSRA)

The FSRA is the independent regulator for firms established in the Abu Dhabi Global Market. Like the DFSA, it maintains its own AML rulebook and supervises and enforces against firms in its free zone, within the wider federal framework.

UAE FIU and goAML

Whoever supervises you, every regulated financial institution reports to a single national body. The UAE Financial Intelligence Unit receives and analyses suspicious transaction reports, suspicious activity reports, and related filings, all submitted through the goAML platform.

Registration on goAML is a baseline obligation, and timely, good-quality reporting is one of the clearest signals of an effective AML programme.

See our goAML registration guide and the difference between a suspicious activity and a suspicious transaction for the practical steps.

Firms in the DIFC and ADGM file suspicious reports with the UAE FIU through goAML in the same way, and may also carry parallel notification duties to the DFSA or FSRA under their own rulebooks.

The table below shows which authority supervises each type of financial institution.

Financial institution 

Primary AML supervisor 

Mainland banks 

Central Bank of the UAE (CBUAE) 

Exchange houses and MSBs 

CBUAE 

Registered hawala providers 

CBUAE 

Finance companies 

CBUAE 

Insurers, brokers and agents 

CBUAE 

Mainland capital market firms 

Capital Market Authority 

DIFC firms 

DFSA 

ADGM firms 

FSRA 

AML Legal Framework Applicable to Banks and Financial Institutions in UAE

The framework has four layers: the core federal laws and regulations, the guidance that applies to all reporting entities, the Central Bank’s own guidance for licensed financial institutions, and the national and sector risk assessments that tell you where the threats actually are. This section catalogues each layer. It stays at overview depth on purpose, because the detailed obligations live in the sector guides.

Federal AML Laws and Executive Regulations Applicable to Banks and Financial Institutions

These four instruments are the legal foundation for every financial institution in the UAE.

Federal Decree-Law No. 10 of 2025 on AML, CFT and CPF

Federal Decree-Law No. 10 of 2025 is the principal UAE statute governing anti-money laundering, terrorism financing, and proliferation financing. It sets the core definitions, recognises offences through virtual assets, and establishes the Financial Intelligence Unit within the Central Bank as the independent body that receives and analyses suspicious transaction reports. Powers to suspend or freeze suspicious transactions and funds sit with the FIU and the competent authorities under the law, Cabinet Resolution No. 74 of 2020 and UAE FIU Regulation No. 1 of 2026. For banks and insurers, it is the source of core reporting and oversight duties.

Cabinet Resolution No. 134 of 2025, the Executive Regulations

Cabinet Resolution No. 134 of 2025 issues the Executive Regulations of Federal Decree-Law No. 10 of 2025, translating the statute into detailed rules. It defines scope, including banking, securities, and life insurance, and requires a risk-based approach, customer due diligence, beneficial owner verification, ongoing monitoring, and approved internal policies. For banks and insurers, it is the practical rulebook of procedures and controls that supervisors test.

Cabinet Resolution No. 74 of 2020 on terrorist lists and UNSC resolutions

Cabinet Resolution No. 74 of 2020 regulates the terrorist lists and how the UAE implements United Nations Security Council resolutions on terrorism, its financing, and weapons proliferation. Freezing must be applied within twenty-four hours. Financial institutions must register with the Executive Office, continuously screen customers and beneficial owners against the lists, freeze matches without prior notice, and report promptly, establishing core sanctions screening duties.

Federal Law No. 7 of 2014 on combating terrorism crimes

Federal Law No. 7 of 2014 on Combating Terrorism Crimes defines terrorist offences in the UAE and fixes their penalties, up to life imprisonment or death. It penalises providing, collecting, or maintaining funds for terrorist purposes and addresses freezing suspected funds held in financial institutions. Banks and insurers rely on it to understand the predicate conduct their controls detect, deter, and report.

AML Guidance Applicable to All Reporting Entities

Beyond the core laws, the Central Bank and the FIU issue a large body of guidance, guidelines, and typologies that shape day-to-day compliance. The instruments below sit in the overarching guidance set for licensed financial institutions.

UAE FIU Regulation No. 1 of 2026 on Suspension and Freezing Powers, April 2026

UAE FIU Regulation No. 1 of 2026, dated April 2026, governs the postponement or suspension of suspicious transactions and the freezing of funds. Applying to financial institutions, designated non-financial businesses and virtual asset service providers, it introduces the urgent Postponement Suspicious Transaction Report, plus a Suspension Order of up to ten working days and a Freezing Order of up to thirty days. For firms, it preserves funds at risk.

UAE FIU Strategic Analysis Report on Human Trafficking, April 2026

The UAE FIU Strategic Analysis Report on Human Trafficking, dated April 2026, analyses money laundering flows linked to human trafficking using suspicious reports filed with the Financial Intelligence Unit. It covers sexual exploitation, forced labour and organ removal, profiles traffickers, organised crime and money mules, assesses vulnerable sectors, and develops risk indicators. For financial institutions, it is a detection resource that improves reporting quality.

Guidance on Targeted Financial Sanctions for Financial Institutions, DNFBPs and VASPs, March 2026

The Guidance on Targeted Financial Sanctions for Financial Institutions, DNFBPs and VASPs, from the Executive Office for Control and Non-Proliferation, was first published in January 2021 and last amended in March 2026. It sets four obligations: registering in the Notification Alert System, screening against the Local and UN lists, freezing assets without delay, and reporting. The 2026 update renames the confirmed-match report, previously the Funds Freeze Report or FFR, as the Confirmed Name Match Report, and reports of partial matches as the Partial Name Match Report.

Joint Guidance on the Compliance Officer and MLRO, 2026

The Joint Guidance on the Compliance Officer and Money Laundering Reporting Officer, issued in 2026 by the UAE Supervisory Sub-Committee, establishes a unified framework for the officer’s appointment, authority, and responsibilities across regulated sectors. Recognising the role as a cornerstone of effective AML defences, it sets expectations on seniority, experience, independence, board access, and resources, clarifying how institutions appoint and empower a fit and proper officer.

FIU Strategic Analysis Report on Terrorist Financing, May 2025

The FIU Strategic Analysis Report on Terrorist Financing, published in May 2025, is produced by the UAE Financial Intelligence Unit using data from 2021 to 2024. It sets out typologies such as unlicensed hawala, corporate networks, trade-based financing, real estate, and virtual assets, and examines facilitators, concluding with risk indicators that help institutions detect, trace, and report suspicious terrorist financing activity.

goAML FAQs, April 2024

The goAML FAQs, version 2.1 dated 18 April 2024, are a question-and-answer guide from the UAE Financial Intelligence Unit helping reporting entities use the goAML system and its access services. It gives step-by-step remedies for registration and login problems, including expired one-time passwords, Google Authenticator passcodes and password resets. For financial institutions, it supports reliable access, underpinning timely reporting.

PF Institutional Risk Assessment Guidance for FIs, DNFBPs and VASPs, December 2023

The Proliferation Financing Institutional Risk Assessment Guidance, published in December 2023, sets out how financial institutions should assess and manage exposure to proliferation financing. It explains a methodology built around inherent risks, control effectiveness, and residual risks, describes mitigating measures and a customer risk scoring questionnaire with worked case studies, helping firms recognise elevated risk customers, calibrate controls, and document risk decisions for supervisors.

Terrorist and Proliferation Financing Red Flags Guidance, December 2023

The Terrorist and Proliferation Financing Red Flags Guidance, updated December 2023, consolidates indicators helping financial institutions detect suspicious terrorist and proliferation financing, including evasion of targeted sanctions under United Nations Resolutions or local designations. It explains tactics such as front companies, sets out the legal basis for reporting, and groups proliferation indicators by customer profile, transaction, maritime and trade finance. It is a working reference for detection.

Suspicious Activity and Transaction Reporting Thematic Review, January 2023

The Suspicious Activity and Transaction Reporting Thematic Review, issued in January 2023, sets out findings and expectations from the 2022 AML/CFT examination of financial institutions and designated non-financial businesses. It contrasts acceptable and deficient practices across governance, policies, risk-based monitoring, data, alert review, investigation and reporting. For financial institutions, it is a practical benchmark to test monitoring and reporting arrangements and close gaps before inspection.

Cabinet Resolution No. 109 of 2023 Regulating the Real Beneficiary Procedures

Cabinet Resolution No. 109 of 2023 regulates beneficial owner procedures for legal persons in the UAE, requiring accurate, up-to-date ownership information and registers updated within short deadlines. Banks and insurers rely on this data for customer due diligence on corporate customers. These procedures apply to legal persons licensed or registered in the State, including commercial free zones, but exclude the financial free zones, the DIFC and ADGM, which operate their own beneficial ownership regimes.

Cabinet Resolution No. 132 of 2023 on Administrative Penalties for Real Beneficiary Violations

Cabinet Resolution No. 132 of 2023 sets the administrative penalties for violations of the beneficial owner procedures under Cabinet Resolution No. 109 of 2023, empowering the registrar to fine and, on a third violation, suspend licences. It reinforces why corporate customers must keep ownership data current. These penalties apply to legal persons licensed or registered in the State, including commercial free zones, but not to the financial free zones, the DIFC and ADGM, which follow their own regime.

Counter Proliferation Financing Guideline, November 2022

The Counter Proliferation Financing Guideline, published in November 2022 by the Executive Office for Control and Non-Proliferation, supplements the Guidance on Targeted Financial Sanctions. It helps financial institutions identify, assess, and mitigate Proliferation Financing risks in line with Financial Action Task Force standards, covering the UAE framework, risk assessment, preventive measures such as enhanced due diligence and trade finance controls, and red flags for sanctions evasion.

goAML Web Submission Guide, July 2022

The goAML Web Submission Guide, issued by the UAE Financial Intelligence Unit in July 2022, sets out how the Compliance Officer or Money Laundering Reporting Officer submits reports through goAML. It covers report types, including Suspicious Transaction and Suspicious Activity Reports, accessing the system, completing the cover and submitting. For financial institutions, it standardises reporting and helps officers file complete reports promptly.

IEMS User Guide for Reporting Entities, March 2022

The IEMS User Guide for Reporting Entities, dated March 2022, is a manual from the UAE Financial Intelligence Unit for its Integrated Enquiry Management System, which handles information requests, prosecution decisions, and freeze orders between the Unit, authorities, and reporting entities. It explains login, the dashboard, the reply workflow, and Admin, Maker, and Checker roles, showing institutions how to action enquiries and freeze instructions compliantly.

Joint Guidance on Combating the Use of Unlicensed Virtual Asset Providers, March 2022

The Joint Guidance on Combating the Use of Unlicensed Virtual Asset Providers, issued in March 2022 by the UAE Supervisory Authorities, including the Central Bank and the Virtual Assets Regulatory Authority, educates the public and regulated entities on the risks of unlicensed providers. It reminds institutions of their AML obligations, sets expectations on due diligence and reporting, and provides red flags such as missing licences and unrealistic promises.

goAML Pre-Registration Guide, March 2022

The goAML Pre-Registration Guide, issued by the UAE Financial Intelligence Unit in March 2022, explains how reporting entities secure access to the Services Access Control Manager, or SACM, before reaching goAML to register and file suspicious reports. It covers the gateway, a Google Authenticator one-time password, and safeguarding a personal Secret Key. For financial institutions, correct pre-registration is a prerequisite for secure reporting.

goAML Registration Guide, March 2022

The goAML Registration Guide, issued by the UAE Financial Intelligence Unit in March 2022, sets out how an organisation registers with the FIU on the goAML platform as a reporting entity, stakeholder or supervisory body. All accountable and reporting entities must register to submit suspicious reports. It covers portal access, selecting registration type, entering data, access rights and password resets. For financial institutions, it underpins compliant reporting.

Strategic Review on Targeted Financial Sanctions Case Studies, November 2021

The Strategic Review on Targeted Financial Sanctions Case Studies, dated November 2021, examines how sanctions-related reports arise in the UAE under Cabinet Resolution No. 74 of 2020, which implements United Nations freezing measures on terrorism and proliferation financing. It classifies reports by source, suspicion and instrument, distinguishes terrorist from proliferation patterns, and presents red flags, statistics and recommendations. For financial institutions, it strengthens detection, screening and reporting.

Typologies on the Circumvention of Targeted Sanctions, November 2021

This typologies report, amended in November 2021 and issued by the Executive Office, compiles cases showing how sanctioned parties circumvent targeted sanctions on terrorism and proliferation, evading United Nations Resolutions and the national terrorist list. It groups methods by channel, covering banking, remitters, exchange houses, hawala, smuggling, dual-use trade, legal entities and virtual assets, with red flags. For financial institutions, it strengthens screening, due diligence and reporting.

Update to the List of High Risk Jurisdictions, November 2021

This November 2021 decision of the National AML/CFT Committee updates the lists of high-risk jurisdictions subject to a call for action and under increased monitoring, and the counter-measures to apply, updating an earlier March 2021 decision. For financial institutions, country risk is a core input: it signals which jurisdictions warrant enhanced due diligence and keeps risk assessments aligned with the latest listings.

Joint Guidance on Satisfactory and Unsatisfactory Practice, June 2021

The Joint Guidance on Satisfactory and Unsatisfactory Practice, issued in June 2021 by the UAE Supervisory Authorities, draws on inspections between January 2020 and May 2021. It contrasts satisfactory and unsatisfactory practices across governance, risk assessment, policies, training, customer due diligence, monitoring, sanctions screening, and reporting. It translates real inspection findings into concrete examples of supervisory expectations, helping firms benchmark their controls and remediate weaknesses before examination.

Typologies on the Circumvention of TFS, PF and WMD, May 2021

This typologies report, amended in May 2021 and issued by the Executive Office, examines how sanctioned parties receive financing in evasion of United Nations Resolutions on terrorism and proliferation of weapons of mass destruction. Organised by method, it covers banking, money remitters, hawala, online payments, non-profits, cash smuggling, cyberactivity, trade and legal entities, with red flags. For financial institutions, it supports stronger screening, monitoring and reporting.

goAML FAQs, September 2020

The goAML FAQs Guide, issued by the UAE Financial Intelligence Unit in September 2020, is a question-and-answer reference for reporting entities using the goAML platform. It gives step-by-step help on resetting passwords, updating organisation and personal details, and delegating reporting subject to Supervisory Body approval. For financial institutions, accurate registration data and managed access underpin timely, compliant reporting to the FIU.

goAML Registration Guide Stage 2, September 2020

The goAML Registration Guide Stage 2, issued by the UAE Financial Intelligence Unit in September 2020, outlines how an organisation registers with the FIU on the goAML platform as a reporting entity, stakeholder or supervisory body. All accountable and reporting entities must register, with electronic submission required since 27 June 2019. It covers portal access, registration type, access rights and password resets.

Emerging ML, TF and PF Risks and Trends in the Financial Sector

Emerging ML, TF, and PF Risks and Trends in the Financial Sector is a Supervisory Subcommittee report giving financial institutions an overview of current threats. Issued under Article 16 of Federal Decree-Law No. 10 of 2025, it examines artificial intelligence exploitation, ESG fraud, trade finance abuse, virtual assets, and sanctions evasion, with banking case studies, highlighting typologies and red flags for risk assessments and controls.

Guideline on Grievance Procedures

The Guideline on Grievance Procedures is issued by the Executive Office for Control and Non-Proliferation, which receives grievance requests related to the UAE Local Terrorist List and the UN Consolidated List. Under Cabinet Resolution No. 74 of 2020, it processes three types: de-listing, cancellation of freezing measures, and permission to use frozen assets. It explains the lawful routes affected customers may use, informing how institutions respond.

Online Grievance System User Guide

The Online Grievance System User Guide is issued by the Executive Office for Control and Non-Proliferation, which receives grievance requests related to the UAE Local Terrorist List and the UN Consolidated List. It walks users through the application form for three request types: de-listing, cancellation of freezing measures, and permission to use frozen funds, explaining the route affected customers use to challenge designations or access frozen assets.

Simple Guide to Subscribe to the EOCN Notification Alert System (NAS)

This short guide explains how to subscribe to the Notification Alert System operated through the Executive Office’s website, so users receive timely updates to the UAE sanctions lists: the Local Terrorist List and the UN Consolidated List. It gives step-by-step subscription instructions. For financial institutions, it supports a core control, since sanctions screening is only effective when firms work from current lists.

Typologies in the Financial Sector

Typologies in the Financial Sector, produced jointly by the Supervisory Authorities Sub-Committee and the Financial Intelligence Unit with the Executive Office, shares money laundering, terrorist financing, sanctions, fraud and corruption typologies observed in the market, several arising during COVID-19. It covers risks beyond the National Risk Assessment, including unlicensed money service operators and links to human trafficking. For financial institutions, it is an early warning tool.

CBUAE Guidance for Licensed Financial Institutions

Alongside the guidance that reaches every reporting entity, the Central Bank issues a dedicated body of guidance, rules and thematic reviews for the licensed financial institutions it supervises. These set the CBUAE’s specific expectations for banks and other financial institutions across risk assessment, due diligence, sanctions, reporting and sector-specific exposure.

CBUAE Thematic Review on Sanctions List Screening in the Banking Sector, May 2026

Conducted by the CBUAE’s AML/CFT Supervision Department and published in May 2026 under Cabinet Resolution No. 74 of 2020, this thematic review assessed how banks screen customers and transactions against the UAE Local Terrorist List and the UNSC Sanctions List. It examined whether banks screen at onboarding, periodically and on list updates, freeze without delay and notify the authorities of matches. For banks, it flags where sanctions screening programmes fall short.

CBUAE Best Practices on Implementing a Risk-Based Approach, October 2025

Published by the CBUAE in October 2025, this best-practice paper explains how licensed FIs should design a risk-based approach and run an institutional ML, TF and PF risk assessment. It covers assessing inherent risk across customers, products, delivery channels and geographies, testing the control environment, and determining residual risk. For banks, it clarifies expected methodology, granularity, governance and review frequency, so their programme is genuinely risk-driven rather than tick-box.

CBUAE Best Practices on Role-Based AML/CFT/CPF Training, October 2025

Released by the CBUAE in October 2025, this paper sets expectations for tailoring AML/CFT/CPF training to staff roles. It separates training for the board, owners and senior management from the three lines of defence, and covers new-hire, annual enterprise-wide, group and localised training. Banks are expected to match content, frequency and intensity to each function’s risk exposure, document a training plan, and keep records evidencing delivery and effectiveness.

CBUAE Guidance on Customer Due Diligence, KYC and Record-Keeping, October 2025

Published by the CBUAE in October 2025, this guidance treats CDD, KYC and record-keeping as the cornerstone of AML, sanctions and anti-fraud compliance. It covers identifying and verifying customers and beneficial owners, building a risk profile from source of funds, wealth and expected activity, ongoing monitoring, simplified and enhanced due diligence, name screening, non-face-to-face relationships, third-party reliance and customer exit. Banks must evidence robust CDD and retain supporting records.

CBUAE Guidance on Correspondent Banking, October 2025

Released by the CBUAE in October 2025, this guidance addresses how licensed FIs should manage correspondent banking relationships and cross-border payments. It examines risk factors such as nested relationships, payable-through accounts, geography, ownership and customer base, and sets out standard, specific and enhanced due diligence, ongoing monitoring, sanctions obligations and reporting. Annexes cover the SWIFT to ISO 20022 transition and RMA relationships, helping banks scrutinise respondent institutions proportionately.

CBUAE Guidance on Risks Related to Trade-Based Money Laundering and Transshipment, October 2025

Issued by the CBUAE in October 2025, this guidance helps licensed FIs understand and mitigate trade-based money laundering and illicit transhipment risks. It explains documentary and open-account trade finance, typologies such as over-invoicing and under-invoicing, multiple invoicing, shell companies and free-trade-zone misuse, and vulnerable sectors like gold and vehicles. For banks, it prescribes enterprise-wide risk assessment, customer and enhanced due diligence, sanctions screening, transaction monitoring and reporting.

CBUAE Guidance on Risks Related to Proliferation Finance, October 2025

Issued by the CBUAE in October 2025, this guidance helps licensed FIs counter the financing of weapons of mass destruction proliferation. It maps threats and vulnerabilities across trade finance, correspondent banking, hawala, free trade zones, shell companies and precious metals, then sets out risk assessment, customer and enhanced due diligence, transaction monitoring and targeted financial sanctions duties. In practice, banks must build proliferation finance risk into their controls and export-control screening.

Federal Decree-Law No. 6 of 2025 on the Central Bank and the regulation of financial institutions

Federal Decree-Law No. 6 of 2025 is not the AML law, but it is the licensing and supervisory foundation for the Central Bank-regulated institutions covered here, including banks, exchange houses, finance companies, insurers and hawala providers. Issued on 8 September 2025, it governs the Central Bank and the regulation of licensed financial institutions and activities and insurance business. It repealed Federal Decree-Law No. 14 of 2018, the previous Central Bank law, and Federal Decree-Law No. 48 of 2023 on insurance activities, and regulations and circulars issued under those laws remain in force until they are replaced.

CBUAE AML/CFT Guidelines for Financial Institutions, July 2023

Issued by the CBUAE in July 2023, these are the flagship AML/CFT guidelines for financial institutions. They walk banks and other FIs through the UAE legal framework, the risk-based approach, business-wide risk assessment, customer due diligence and enhanced due diligence, wire transfers, ongoing monitoring, suspicious transaction reporting and record-keeping. In practice, they set the baseline compliance expectations against which supervised institutions must show they meet their statutory obligations.

CBUAE Guidance on Risks Related to Virtual Assets and VASPs, February 2023

Issued by the CBUAE on 20 February 2023, this guidance sets out how licensed FIs should identify and mitigate money laundering and terrorist financing risks from virtual assets and virtual asset service providers. It covers the UAE regulatory framework, the non-objection process for opening VASP accounts, customer due diligence, enhanced measures for higher-risk customers, transaction monitoring, sanctions obligations and proprietary virtual asset investments, giving banks concrete red flags and expectations.

CBUAE Guidance on Digital Identification for Customer Due Diligence, October 2022

Dated 31 October 2022, this CBUAE guidance explains how licensed FIs may use digital identity systems for customer due diligence. It describes identity proofing, enrolment, authentication and lifecycle management, and the risks these systems present. Crucially, it helps banks assess a system’s reliability and independence through assurance levels and decide on appropriate use in the context of risk, including customer verification, ongoing due diligence and third-party reliance.

CBUAE Guidance on Suspicious Transaction Reporting, August 2022

Published by the CBUAE on 3 August 2022, this document guides licensed FIs on identifying and reporting suspicious transactions across the three lines of defence. It addresses the compliance officer and MLRO role, manual and automated monitoring, how to draft and submit STRs and SARs through goAML, review and filing timelines, tipping-off prohibitions and record retention. For banks, it clarifies disclosure duties, legal protections and the consequences of failing to report.

CBUAE Guidance on the Risks Relating to Politically Exposed Persons, August 2022

The CBUAE issued this guidance on 1 August 2022 to help licensed FIs manage risks from politically exposed persons. It sets out the requirements for classifying customers as PEPs and related customers, time limits on PEP status, screening, risk rating and enhanced due diligence. It also covers transaction monitoring, suspicious transaction reporting, governance and training, and gives red flag indicators so banks can apply proportionate scrutiny to higher-risk relationships.

CBUAE Guidance on the Risks Relating to Payments, August 2022

Dated 1 August 2022, this CBUAE guidance addresses money laundering and terrorist financing risks in the payments sector. It examines peer-to-peer and cross-border payments, intermediation, nesting, use of agents and merchant risks, alongside obligations for stored value facilities, retail payment services and card schemes. Banks are directed to conduct risk assessment, apply customer and enhanced due diligence, wire transfer controls, correspondent due diligence, sanctions screening and reporting.

CBUAE Guidance on Transaction Monitoring and Sanctions Screening, September 2021

The CBUAE issued this guidance on 8 September 2021, requiring licensed FIs to show compliance within one month. It explains how to build risk-based transaction monitoring and sanctions screening programmes, covering risk assessment, data management, rule definition and testing, alert scoring, name and transaction screening, list management, and post-implementation tuning. In practice, banks must govern, audit and staff these systems, manage third-party vendors and keep supporting records.

CBUAE Guidance for Cash-Intensive Businesses, September 2021

Dated 27 September 2021, this CBUAE guidance addresses the money laundering vulnerabilities of cash, bearer instruments, prepaid cards, cash couriers and currency exchanges. It expects licensed FIs to run enterprise risk assessments, apply customer and enhanced due diligence, monitor transactions and file suspicious transaction reports. For banks, that means tighter scrutiny of customers who handle large volumes of cash and clearer expectations on documenting the source of those funds.

CBUAE Guidance for Registered Hawala Providers and LFIs, August 2021

Issued by the CBUAE on 15 August 2021, this guidance covers both registered hawala providers and the banks that serve them. It sets registration, sanctions freezing, AML/CFT programme, customer due diligence, record-keeping and goAML reporting duties for hawala providers, and a risk-based approach for licensed FIs banking them. In practice, banks must understand and manage the money laundering and terrorist financing risks these money remitters bring into the system.

CBUAE Guidance on the Implementation of Targeted Financial Sanctions, July 2021

Issued by the CBUAE on 4 July 2021, this guidance directs licensed FIs on implementing targeted financial sanctions. It requires a sanctions compliance programme with senior management commitment, risk assessment, internal controls, training, independent audit and record-keeping, plus screening against the UN Consolidated List and Local Terrorist List, handling of false positives, and payment screening. Banks must freeze without delay on a confirmed match and notify the CBUAE and Executive Office.

CBUAE Guidance on Services to Legal Persons and Arrangements, June 2021

Published by the CBUAE on 7 June 2021, this guidance tackles how companies, trusts and similar structures can obscure beneficial ownership, purpose and source of funds. It explains formation, beneficial owner identification and UAE economic substance rules, and requires licensed FIs to risk-rate such customers, verify ownership and control, monitor them and file suspicious transaction reports. For banks, it sharpens expectations on unwrapping who really owns and controls corporate clients.

CBUAE Guidance for the Real Estate and Precious Metals and Stones Sectors, June 2021

Issued by the CBUAE on 16 June 2021, this guidance helps licensed FIs manage ML and TF risk when serving real estate businesses and dealers in precious metals and stones. It explains sector-specific risks, typologies and red flags, then sets out mitigating measures covering the risk-based approach, customer and enhanced due diligence, suspicious transaction reporting, governance and training. For banks, it means calibrating controls to these high-value, cash-exposed sectors.

CBUAE STR Outreach for Banks and Finance Companies, March 2021

Delivered on 10 March 2021, this CBUAE outreach session brought together the Financial Intelligence Unit, AML/CFT Supervision and the Ministry of Interior to brief banks and finance companies on suspicious transaction reporting. Drawing on the AML law, it explains when and what to report, goAML as the sole reporting channel, the different report types and the compliance officer’s duties. It reinforces prompt, well-grounded STR filing as a core supervisory expectation.

CBUAE Board of Directors Decision No. 59/4/2019 on AML/CFT Procedures, 2019

Issued by the CBUAE Board of Directors on 13 June 2019, Decision No. 59/4/2019 sets the procedures for anti-money laundering and combating the financing of terrorism and illicit organisations. It requires every financial institution and its concerned persons to comply with the federal AML law, its Executive Regulation and Central Bank instructions, guidelines and notices, and empowers the Central Bank to impose administrative sanctions, subject to a right of appeal. It replaced Circular No. 24/2000.

CBUAE Guidance Note on the Responsible Use of AI and Machine Learning by LFIs

This CBUAE guidance note sets principles for the responsible, consumer-focused use of artificial intelligence and machine learning by licensed FIs. It addresses governance and board accountability, fairness and non-discrimination, transparency and explainability, data quality and privacy, continuous monitoring, human oversight and third-party risk. It flags high-impact decisions such as loan or insurance outcomes and expects banks to build these principles into their AI and machine learning policies and existing risk frameworks.

CBUAE List of Administrative and Financial Sanctions

This CBUAE document explains the Central Bank’s enforcement powers over financial institutions with weak AML and sanctions frameworks. Penalties range from a warning through mandatory remediation to restrictions, senior-management removal and licence revocation, alongside financial fines set per violation. The scale can reach very substantial sums under the Central Bank Law. For banks, it signals that supervisory consequences are dissuasive, proportionate and consistently applied across the sector.

NRA, SRA, and Other Important Guidelines Applicable to Banks and Financial Institutions in UAE

The UAE assesses its money laundering, terrorist financing, and proliferation financing risk at the national level, and the law expects every financial institution to align its own business and enterprise-wide risk assessment with those findings. The two assessments below are the anchor documents, and the sector ratings that follow show where banks and financial institutions actually sit, in the mainland and in the financial free zones.

UAE PF National Risk Assessment 2026

The UAE Proliferation Financing National Risk Assessment 2026 examines exposure to the financing of weapons of mass destruction and evasion of targeted sanctions on the DPRK and Iran. Overall country risk is medium-high. Virtual asset service providers are high in the mainland, banks, exchange houses and hawala providers medium-high, free zone banks and money service businesses medium, stored value facilities medium-low. For financial institutions, it guides screening and controls.

The table below summarises the residual risk ratings that banks and financial institutions should reflect in their own risk assessments.

UAE ML and TF National Risk Assessment 2024

The UAE Money Laundering and Terrorist Financing National Risk Assessment 2024, the country’s second, rates threats and residual risks across mainland and free zone financial sectors using 2019 to 2023 data. Overall, the national money laundering risk is medium-high. Banking, exchange houses and securities are medium-high; hawala providers are high; finance companies and insurance are medium. For financial institutions, it sets the national baseline for their risk-based controls.

Sub-sector 

ML and TF residual risk 

PF residual risk 

Banking 

Medium-high (mainland); medium to medium-high (free zones) 

Medium-high (mainland); medium (free zones) 

Exchange houses and MSBs 

Medium-high 

Medium-high (mainland); medium for free zone MSBs 

Registered hawala providers 

High 

Medium-high (mainland); not permitted in free zones 

Finance companies 

Medium 

Not separately rated 

Insurance 

Medium 

Medium for maritime (mainland); medium-low (free zones) 

Capital market and securities 

Medium range, effective controls 

Low (mainland and free zones) 

Alongside the national assessments, sector risk assessments, red flag guidance, and typologies reports give financial institutions the detail they need to keep their enterprise-wide risk assessment current and defensible.

Core AML Obligations at a Glance

Whatever the sector, the AML regulations for banks and financial institutions in the UAE turn on a common set of duties. This is the overview; each is covered in depth in its own guide.

Expert Tip:

Supervisors usually look beyond a single alert in isolation. They test whether the institution has a risk assessment aligned to the national risk assessment, documented alert handling and escalation, and a compliance officer who can show independence and authority. Systemic weaknesses and high-risk or sanctions-related failures that are poorly documented are what draw findings. Get the risk assessment and the compliance function right, and the rest becomes defensible.

Sub-Sector Guides for Financial Institutions in UAE

Use this page as the map, then go to the sector guide that fits your licence for the detailed rules, checklists, and templates.

  • AML regulations for banks in UAE: the deposit-taking, lending, payments, and trade finance obligations that carry the deepest AML duties.
  • AML regulations for insurance companies and brokers in UAE: how life and investment business is brought inside the AML perimeter, and what insurers and intermediaries must do.
  • AML regulations for exchange houses in UAE: currency exchange, remittance, and banknote controls for a cash-intensive, cross-border sector.
  • AML regulations for registered hawala providers in the UAE: registration, record-keeping, and reporting duties for the highest residual-risk financial sub-sector.
  • AML regulations for capital market firms in UAE: client onboarding, screening, and monitoring for brokerages, custodians, and fund managers under the Capital Market Authority.
  • AML regulations for finance companies in UAE: how credit and financing providers apply the core AML controls, scaled to their products.
  • AML regulations for other LFIs in UAE: the catch-all for payment, stored value, and other licensed financial activities captured by the definition.

Conclusion

AML regulations for banks and financial institutions in the UAE come down to three questions: are you a financial institution, who supervises you, and which parts of the framework apply? For the great majority of licensed firms, the answer is that you are covered, the Central Bank or your free zone regulator supervises you, and the full stack of Federal Decree-Law No. 10 of 2025, its Executive Regulations, the sanctions rules, and the supporting guidance all apply. Use the national risk assessments to calibrate your programme to the real threats in your sub-sector, treat this page as your starting point, and use the sector guides to turn the framework into day-to-day controls. This is a fast-moving area, so review your obligations against the latest guidance regularly. For a wider view, see our guide to anti-money laundering laws in the UAE.

Frequently Asked Questions

What is the AML risk rating for banks in the UAE?

The UAE ML and TF National Risk Assessment 2024 rates the banking sector at medium-high residual risk, with an inherent risk of high because of the sector’s size, cross-border reach, and exposure to high-risk customers. For proliferation financing, mainland banks are rated medium-high, largely through trade finance, while banks in the financial free zones are rated medium.

Yes. Hawala is legal only when the provider is registered with the Central Bank, and registered hawala providers must run customer identification, record-keeping, and suspicious transaction reporting. The sector carries the highest residual money laundering rating of any financial sub-sector, and hawala is not permitted to operate in the financial free zones.

Among the core financial institutions, registered hawala providers carry the highest residual money laundering risk. For proliferation financing, virtual asset service providers carry the highest exposure, which is relevant to any bank or institution that services them.

Exchange houses are rated medium-high for money laundering and terrorist financing, driven by cash handling, banknote shipments, reliance on foreign remittance partners, and third-party transactions. They are supervised by the Central Bank and must apply full customer due diligence and screening.

Firms in the DIFC are supervised by the DFSA and firms in the ADGM by the FSRA, each under its own AML rulebook that sits alongside the federal law. In practice, financial free zone banks and money service businesses tend to carry lower proliferation financing risk than their mainland counterparts because they are account-based, cash is not permitted, and many are branches of global banks.

The insurance sector is rated medium for money laundering, reflecting the limited ways life and investment products can be abused, and maritime insurance is rated medium for proliferation financing in the mainland. Insurers and intermediaries carrying out relevant business are financial institutions and must apply customer due diligence, screening, and reporting.

No. Securities firms are rated low for proliferation financing in both the mainland and the free zones, and their money laundering risk sits in the medium range, with controls assessed as effective. They do not take cash deposits, but they must still identify clients, screen against sanctions lists, and monitor for market-based laundering under the Capital Market Authority framework.

Yes. Finance companies are licensed by the Central Bank, are rated medium residual risk for money laundering, and must run the full set of core AML controls scaled to their credit and financing products.

Need help mapping these obligations to your licence?

Understand your AML obligations with expert guidance tailored to your banking licence and regulatory requirements.

Share via :

About the Author

Pathik Shah

FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)

Pathik is an ACAMS-certified AML consultant specialising in governance, risk, and compliance for regulated entities in the UAE. He brings over 28 years of experience, with 1,000+ hours of AML training and 200+ advisory engagements across DNFBPs, VASPs, and FIs. He supports businesses in aligning with AML/CFT requirements from the CBUAE, DFSA, MoET, MoJ, VARA, CMA, FSRA, and FATF. Known for translating complex regulations into audit-ready procedures, Pathik enables operational clarity and compliance readiness.

Reach Out to Pathik

AML Regulations for Banks in UAE

AML Regulations for Banks in UAE

Blogs

Published On: 07/07/2026

Table of Contents

Protect your business with reliable and effective AML strategies with AML UAE.

Last Reviewed On: 07/07/2026   |   Last Updated On: 07/07/2026

Key Highlights

  • Banks are Licensed Financial Institutions under Federal Decree-Law No. 10 of 2025 and its Executive Regulations in Cabinet Resolution No. 134 of 2025, so CBUAE AML/CFT/CPF guidance for LFIs applies to them where relevant to their activities, products, customers, delivery channels and geographic exposure.
  • The Central Bank of the UAE is the primary AML supervisor for banks in mainland UAE and the commercial free zones. Banks in the DIFC and ADGM answer to the DFSA and FSRA and sit outside this guide.
  • The banking sector’s residual money laundering risk is rated medium-high in the national risk assessment, with an inherent risk of high, and its proliferation financing risk is medium-high, mainly through trade finance.
  • Core obligations run across every bank: risk assessment, customer due diligence, sanctions screening, transaction monitoring, record-keeping, and suspicious transaction reporting through goAML.
  • On top of the federal laws, the Central Bank issues a deep body of guidance for licensed financial institutions that shapes day-to-day banking compliance.
  • This article catalogues the whole framework and links up to the banks and financial institutions pillar for the wider view.

Banks are among the most important and closely supervised parts of the UAE financial system for anti-money laundering. They take deposits, lend, move money across borders, and finance trade, so many major money laundering, terrorist financing and sanctions typologies involve banks directly or indirectly. This guide sets out the AML regulations for banks in the UAE: who is in scope, who supervises them, the full legal framework that applies, and how the national risk assessments rate the banking sector’s money laundering, terrorist financing, and proliferation financing risk. It covers banks licensed by the Central Bank of the UAE in mainland UAE and the commercial free zones.

Question Direct answer 
Who supervises UAE banks for AML? The CBUAE, for banks it licenses outside the DIFC and ADGM. 
What is the main AML law? Federal Decree-Law No. 10 of 2025. 
What is the executive regulation? Cabinet Resolution No. 134 of 2025. 
Where are suspicious reports filed? With the UAE FIU through goAML. 
What are the main bank AML controls? AML Programme consisting of ML/FT risk assessment, policy, controls, and procedures, customer due diligence, beneficial ownership checks, sanctions screening, transaction monitoring, STR and SAR reporting, record-keeping, governance and training. 

What counts as a bank for AML purposes in the UAE?

A bank, for AML purposes, is any institution licensed by the Central Bank of the UAE to carry on banking business, whether it operates in mainland UAE or in a commercial free zone. The categories below all sit inside the AML regulations for banks in the UAE. Banks established in the financial free zones of the DIFC and ADGM are supervised by the DFSA and FSRA under their own rulebooks and are not covered here.

Commercial banks

Commercial banks take retail and corporate deposits, lend, and provide payment, card, and everyday banking services. Their scale, their reach across the customer base, and their exposure to cash, wire transfers, and high-risk customers put them at the front line of AML risk and give them the deepest set of obligations.

Wholesale banks

Wholesale banks focus on corporate, institutional, and high-value business rather than retail customers. Their exposure runs through corporate structures, trade finance, and cross-border flows, which is where much of the sector’s proliferation financing and trade-based laundering risk concentrates.

Branches of foreign banks

Branches of foreign banks licensed by the Central Bank must run a full local AML programme, even where their head office operates its own global controls. They remain answerable to the Central Bank for their UAE activities and must meet the same core local AML/CFT/CPF obligations for their UAE activities, subject to the terms of their CBUAE licence.

AML Supervisory Authority for Banks in the UAE

Supervision of banks in mainland UAE and the commercial free zones rests with a single authority.

Central Bank of the UAE (CBUAE)

The Central Bank of the UAE licenses banks, supervises their AML programmes, issues the guidance that shapes their controls, and inspects them. It runs thematic reviews and skilled persons’ reviews of bank AML programmes and can impose administrative and financial penalties, restrict activities, or withdraw a licence for breaches. Banks in the DIFC and ADGM are supervised instead by the DFSA and FSRA and fall outside this guide.

UAE FIU and goAML

Banks in scope of this guide submit suspicious transaction and activity reports and related filings to the UAE Financial Intelligence Unit through goAML. Registration on goAML is a baseline obligation, and suspicious transaction reports, suspicious activity reports, and related filings are submitted through it. See our goAML registration guide for the practical steps.

AML Legal Framework Applicable to Banks in the UAE

The framework has four layers: the core federal laws, the guidance that applies to all reporting entities, the national risk assessments, and the Central Bank’s guidance for licensed financial institutions. This section catalogues each layer, grounded in the Banks CBUAE library. Because banks are Licensed Financial Institutions, every instrument addressed to LFIs applies to them.

Federal AML Laws and Executive Regulations Applicable to Banks in the UAE

These instruments are the legal foundation for every bank in scope.

Federal Decree-Law No. 10 of 2025 on AML, CFT and CPF

Federal Decree-Law No. 10 of 2025 is the principal statute governing anti-money laundering, counter-terrorist financing, and proliferation financing in the United Arab Emirates. It sets the core definitions, including money laundering, predicate offences, targeted financial sanctions, and suspicious transactions, and it recognises offences committed through digital systems, virtual assets, and cryptographic technologies. It establishes the Financial Intelligence Unit within the Central Bank as the independent body to which banks must submit all suspicious transaction reports exclusively, empowering the Unit to request information and freeze suspect funds. For banks, the Decree-Law is the source of their core duties, supervisory oversight, and administrative penalties, functioning as the layer beneath every subordinate regulation.

Cabinet Resolution No. 134 of 2025, the Executive Regulations

Cabinet Resolution No. 134 of 2025 issues the Executive Regulations of Federal Decree-Law No. 10 of 2025, translating the statute into the operating rules that financial institutions must follow. It carries over the Decree-Law definitions and adds concepts such as senior management, beneficial owner, reasonable measures, correspondent and payable-through accounts and wire transfers. It identifies in-scope activities, expressly including banking, securities, funds transfers, and money and currency exchange. The Regulations set the substantive obligations: a risk-based approach, customer due diligence, beneficial owner identification and verification, ongoing monitoring, and internal policies approved by senior management. For banks, this is the practical rulebook that supervisors test in examinations and enforcement.

Cabinet Resolution No. 109 of 2023 on beneficial owner procedures

Cabinet Resolution No. 109 of 2023 regulates the beneficial owner procedures for legal persons licensed or registered in the United Arab Emirates. It defines the real beneficiary as the natural person who ultimately owns or controls a legal person, whether directly or through a chain of ownership or other indirect means. It requires legal persons to maintain accurate information on their beneficial owners, identify board nominee members, and keep beneficial owner and shareholder registers updated, generally within fifteen days of changes. This matters to banks, which rely on ownership data to verify beneficial owners behind corporate customers. These procedures apply to legal persons licensed or registered in the State, including commercial free zones, but exclude the financial free zones, the DIFC and ADGM, which operate their own beneficial ownership regimes.

Cabinet Resolution No. 132 of 2023 on penalties for beneficial owner violations

Cabinet Resolution No. 132 of 2023 sets out the administrative penalties for violations of the beneficial owner procedures established under Cabinet Resolution No. 109 of 2023. It empowers the registrar to impose fines, under an annexed schedule of violations and penalties, on legal persons that fail to maintain accurate registers or provide required information. Consequences escalate: on a third violation, the registrar may suspend the commercial licence and close the premises until the fine is paid and the breach corrected. For banks, this reinforces why corporate customers must keep beneficial ownership data current. These penalties apply to legal persons licensed or registered in the State, including commercial free zones, but not to the financial free zones, the DIFC and ADGM, which follow their own regime.

Cabinet Resolution No. 74 of 2020 on terrorist lists and UNSC resolutions

Cabinet Resolution No. 74 of 2020 regulates the terrorist lists and governs how the United Arab Emirates implements United Nations Security Council resolutions on terrorism, its financing, and the proliferation of weapons of mass destruction. It provides for a local list issued by the Cabinet, gives effect to the Security Council sanctions lists, and defines designation, listing, and de-listing. Freezing measures must be applied without delay, within twenty-four hours. For banks, it establishes the core sanctions duties: registering on the Executive Office website for notifications, continuously screening customers, beneficial owners, and transaction parties against the lists, freezing any match without prior notice, and reporting promptly to the supervisory authority.

Federal Law No. 7 of 2014 on combating terrorism crimes

Federal Law No. 7 of 2014 on Combating Terrorism Crimes is the criminal statute that defines terrorist offences in the United Arab Emirates and fixes the penalties attached to them. It sets out concepts such as terrorist crime, terrorist purpose, terrorist organisation, and terrorist person, and it distinguishes conventional from nonconventional weapons, including toxins, pathogenic agents, and radioactive materials. Penalties reach life imprisonment and, in specified circumstances, the death penalty. Of direct relevance to banks is its treatment of terrorism financing: it penalises providing, collecting, preparing, or maintaining funds for a terrorist purpose, and addresses freezing suspect funds, including those deposited in financial institutions.

AML Guidance Applicable to All Reporting Entities

Beyond the core laws, the Central Bank, the UAE FIU and the Executive Office issue guidance, typologies and reporting materials that banks should consider where relevant to their AML/CFT/CPF obligations and risk exposure.

UAE FIU Regulation No. 1 of 2026 on Suspension and Freezing Powers, April 2026

UAE FIU Regulation No. 1 of 2026, dated April 2026, governs the postponement or suspension of suspicious transactions and the freezing of funds. Issued under the AML/CFT Decree-Law and its Executive Regulation, it applies to reporting entities, including financial institutions. It introduces the Postponement Suspicious Transaction Report, an urgent filing where funds suspected of crime risk imminent transfer, withdrawal or dissipation, with a monetary threshold that does not apply to higher threat offences, third party laundering, organised crime or terrorist financing. It defines a Suspension Order of ten working days and a Freezing Order of thirty days. For banks, it is a fast-track mechanism preserving funds at risk.

UAE FIU Strategic Analysis Report on Human Trafficking, April 2026

The UAE FIU Strategic Analysis Report on Human Trafficking, dated April 2026, analyses money laundering and related financial flows connected to human trafficking, drawing on suspicious transaction and activity reports filed with the Financial Intelligence Unit. It sets out objectives, methodology and scope, covering sexual exploitation, forced labour and organ removal. It identifies patterns, including child sexual abuse material, laundering of trafficking proceeds and convergence with other crime, and profiles subjects such as organised crime groups, foreign politically exposed persons and money mules. It assesses the vulnerability of sectors, including financial institutions, and develops indicators around customer profile, behaviour, transactions and due diligence. For banks, it links trafficking to behaviour.

Guidance on Targeted Financial Sanctions for Financial Institutions, DNFBPs and VASPs, March 2026

The Guidance on Targeted Financial Sanctions for Financial Institutions, DNFBPs and VASPs, issued by the Executive Office for Control and Non-Proliferation, was first published in January 2021 and last amended in March 2026. It clarifies reporting entities’ obligations under the UAE’s targeted financial sanctions framework, which prevents misuse of the financial system for terrorism financing, proliferation financing and sanctions evasion. It sets out four obligations: registering in the Notification Alert System, screening against the Local Terrorist List and United Nations Consolidated List, freezing assets without delay, and reporting measures taken. The March 2026 update renames the Funds Freeze Report as the Confirmed Name Match Report, defining compliant screening for banks.

Joint Guidance on the Compliance Officer and MLRO, 2026

The Joint Guidance on the Compliance Officer and Money Laundering Reporting Officer, issued in 2026 by the UAE Supervisory Sub-Committee, establishes a unified framework for the appointment, authority and responsibilities of the officer across regulated sectors. It applies to institutions supervised by the Central Bank of the UAE, the Securities and Commodities Authority, the Ministry of Justice and the Ministry of Economy and Tourism, building on Federal Decree-Law No. 10 of 2025, Cabinet Resolution No. 134 of 2025 and the 2025 framework. Recognising the role as a cornerstone of compliance, it sets expectations on seniority, experience, independence and board access. For banks, it clarifies how to appoint a fit officer.

FIU Strategic Analysis Report on Terrorist Financing, May 2025

The FIU Strategic Analysis Report on Terrorist Financing, published in May 2025 and subtitled Terrorist Financing Typologies and Facilitators, is produced by the UAE Financial Intelligence Unit. It draws on data from January 2021 to December 2024, including suspicious transaction and activity reports, cases disseminated to authorities, counterpart requests and open source material. It explains how terrorist financing works and reviews global typologies. It sets out transactional patterns such as moving funds through banks, unlicensed hawala, corporate networks, trade-based financing, high-value goods, real estate, virtual assets and crowdfunding. It examines facilitators and concludes with risk indicators that help banks detect, trace and report suspicious terrorist financing activity.

goAML FAQs, April 2024

The goAML FAQs, version 2.1 dated 18 April 2024, are a practical question-and-answer guide published by the UAE Financial Intelligence Unit to help reporting entities use the goAML reporting system and its registration and access services. It addresses common problems users encounter when registering and logging in, providing step-by-step remedies. It walks through expired one-time passwords during the first login, pop-up authentication requiring the system-issued username with a Google Authenticator passcode, the correct login sequence, and resetting a forgotten password. It sets out whom to contact when errors persist. For banks, the FAQs reduce friction in reporting, helping compliance teams meet obligations without avoidable delays.

PF Institutional Risk Assessment Guidance for FIs, DNFBPs and VASPs, December 2023

The Proliferation Financing Institutional Risk Assessment Guidance, published in December 2023, sets out how banks and other financial institutions should assess and manage exposure to proliferation financing. It explains a methodology built around inherent risks, control effectiveness and residual risks, and identifies the risk categories and factors institutions should consider when scoring their business. It describes mitigating measures covering client onboarding, customer due diligence, enhanced due diligence, sanctions and adverse media screening, ongoing and transaction monitoring, suspicious activity reporting, and employee training. It provides a customer risk scoring questionnaire, elevated risk factors and worked case studies. For banks, it translates proliferation financing obligations into a practical framework for calibrating controls.

Terrorist and Proliferation Financing Red Flags Guidance, December 2023

The Terrorist and Proliferation Financing Red Flags Guidance, updated in December 2023, gives banks a consolidated list of indicators to identify suspicious terrorist financing and proliferation financing activity, including evasion of targeted financial sanctions imposed under United Nations Security Council Resolutions or local designations. It explains how sanctioned parties evade controls through renaming, intermediaries, front companies and alternative networks. After setting out the legal basis for reporting, it presents terrorist financing red flags, then proliferation indicators grouped into customer profile, account and transaction activity, maritime and trade finance categories. For banks, it is a working reference for front-line and compliance teams, sharpening detection and informing reporting decisions.

Suspicious Activity and Transaction Reporting Thematic Review, January 2023

The Suspicious Activity and Transaction Reporting Thematic Review, issued in January 2023, sets out the key findings and regulatory expectations from the 2022 AML/CFT examination of licensed financial institutions and designated non-financial businesses and professions. It focuses on the suspicious transaction and activity reporting framework and the transaction monitoring systems feeding it, and is read alongside existing reporting and monitoring guidance. Organised around regulatory expectations with acceptable and deficient practices, it covers governance, policies, risk-based deployment of monitoring controls, data management, alert review, case investigation and reporting decisions. It applies across banks, exchange houses, finance companies and payment service providers, giving banks a practical benchmark before inspection.

Counter Proliferation Financing Guideline, November 2022

The Counter Proliferation Financing Guideline, published in November 2022 by the Executive Office for Control and Non-Proliferation, supplements the wider Guidance on Targeted Financial Sanctions. It raises awareness among banks and other regulated entities of proliferation financing threats, risks and vulnerabilities, helping them identify, assess and mitigate those risks in line with Financial Action Task Force standards. It explains what proliferation financing means, its stages and the UAE framework, including the interagency mechanism and federal laws. It covers building this risk into a bank’s assessment, preventive measures such as enhanced due diligence, correspondent banking, trade finance and dual-use goods, staff training, and red flags, clarifying obligations under Security Council Resolutions.

goAML Web Submission Guide, July 2022

The goAML Web Submission Guide, issued by the UAE Financial Intelligence Unit in July 2022, sets out the steps to follow when submitting a report to the FIU through the goAML platform. It is addressed to the designated Compliance Officer or Money Laundering Reporting Officer of a registered reporting entity, or the deputy where the lead officer is unavailable. It provides an overview of report types, including the Suspicious Transaction Report and the Suspicious Activity Report covering attempted, non-executed transactions, plus Additional Information Files, Request for Information and High Risk Country reports. It explains accessing goAML and completing the report cover. For banks, it standardises reporting.

Joint Guidance on Combating the Use of Unlicensed Virtual Asset Providers, March 2022

The Joint Guidance on Combating the Use of Unlicensed Virtual Asset Providers in the UAE, issued in March 2022, is a joint publication of the UAE Supervisory Authorities, including the Central Bank of the UAE, the Securities and Commodities Authority and the Virtual Assets Regulatory Authority. Aligned with Financial Action Task Force guidance on a risk-based approach, it educates the public and regulated entities on the risks of unlicensed virtual asset service providers. It reminds banks of their anti-money laundering obligations, setting expectations on vigilance, due diligence, transaction analysis, controls and reporting. It provides red flags such as absent licences, no physical presence, unrealistic promises and pressure to invest quickly.

IEMS User Guide for Reporting Entities, March 2022

The IEMS User Guide for Reporting Entities, dated March 2022, is a practical manual from the UAE Financial Intelligence Unit for its Integrated Enquiry Management System. The system automates requesting information, implementing public prosecutions’ decisions and handling other anti-money laundering and counter-terrorist financing requests from domestic authorities, providing an end-to-end flow between the Unit, authorities and reporting entities. It explains how banks register and log in, reuse goAML credentials, and reach the system through the Services or eServices portals. It describes the dashboard, request management and the reply and attachments workflow, and the Admin, Maker and Checker roles. For banks, it shows how to action enquiries and freeze instructions.

goAML Pre-Registration Guide, March 2022

The goAML Pre-Registration Guide, issued by the UAE Financial Intelligence Unit in March 2022, explains how reporting entities secure access to the Services Access Control Manager, known as SACM, before reaching the goAML application to register and file suspicious reports. The application is available through a public portal for reporting entities not regulated by the Central Bank of the UAE, except hawaladars, while entities under various Supervisory Bodies follow the steps set out. It describes SACM as the gateway to the goAML environments, with access controlled by a time-based one-time password through Google Authenticator, and explains how to secure a personal Secret Key. For banks, correct pre-registration enables secure access.

goAML Registration Guide, March 2022

The goAML Registration Guide, issued by the UAE Financial Intelligence Unit in March 2022, sets out the steps an organisation follows when registering with the FIU on its reporting platform, goAML. It applies to registration as a reporting entity, stakeholder or supervisory body, and explains that all accountable and reporting entities in the United Arab Emirates, regardless of their regulator, must register to submit suspicious reports. It describes reaching the portal through the Services Access Control Manager, noting that Central Bank-regulated institutions require a dedicated MPLS link while others use the internet, then covers registration type, organisation and person data and access rights. For banks, correct registration underpins timely reporting.

Strategic Review on Targeted Financial Sanctions Case Studies, November 2021

The Strategic Review on Targeted Financial Sanctions Case Studies, dated November 2021, examines targeted financial sanctions reporting in the United Arab Emirates over the review period. It sits within the framework under which the UAE, through Cabinet Resolution No. 74 of 2020, implements United Nations Security Council Resolutions on terrorism, terrorist financing and the financing of the proliferation of weapons of mass destruction, including freezing measures and prohibitions on providing funds and services. It sets out its methodology, then classifies reports by source, suspicion and instruments involved, distinguishing terrorist financing from proliferation financing, with red flags and recommendations. For banks, it shows how sanctions-related suspicions arise and are reported.

Typologies on the Circumvention of Targeted Sanctions, November 2021

This typologies report, last amended in November 2021 and issued by the Executive Office, compiles cases showing how sanctioned persons, groups and entities attempt to circumvent targeted sanctions relating to terrorism and the proliferation of weapons of mass destruction. Drawing on public sources from the UAE and abroad, it presents methods used to evade United Nations Security Council Resolutions and the UAE’s national terrorist list. It groups typologies by channel and sector, covering banking services, money remitters, exchange houses, hawala, online payments, non-profit misuse, cash and gold smuggling, dual-use goods, virtual assets and legal entities. For banks, it turns evasion tactics into learning that strengthens screening, monitoring and reporting.

Update to the List of High Risk Jurisdictions, November 2021

This November 2021 decision of the National Anti-Money Laundering and Combatting the Financing of Terrorism and Financing of Illegal Organisations Committee updates the list of high-risk jurisdictions subject to a call for action, the list under increased monitoring, and the counter-measures to apply, replacing an earlier March 2021 decision. Addressed to the supervisory authorities and the Financial Intelligence Unit, it reflects the Committee’s mandate to identify high-risk countries and instruct supervisors to ensure due diligence is applied by financial institutions. For banks it matters because country risk is a core input to risk based controls, signalling which jurisdictions warrant enhanced due diligence and keeping risk assessments current.

Joint Guidance on Satisfactory and Unsatisfactory Practice, June 2021

The Joint Guidance on Satisfactory and Unsatisfactory Practice, issued in June 2021, is a joint publication of the UAE Supervisory Authorities, including the Central Bank of the UAE, the Dubai Financial Services Authority, the Financial Services Regulatory Authority, the Securities and Commodities Authority and the Ministries of Justice and Economy. Drawing on supervisory inspections between January 2020 and May 2021, it contrasts satisfactory and unsatisfactory practices in the anti-money laundering framework, targeted financial sanctions and counter proliferation financing. For banks it covers governance, risk assessment, three lines of defence, policies, training, the compliance officer role, onboarding, monitoring, due diligence, sanctions screening and suspicious transaction reporting, helping firms benchmark controls.

Typologies on the Circumvention of TFS, PF and WMD, May 2021

This typologies report, last amended in May 2021 and issued by the Executive Office, examines how sanctioned persons, groups and entities receive financing in violation or evasion of United Nations Security Council Resolutions on terrorism and the proliferation of weapons of mass destruction. It explains that targeted financial sanctions cover asset freezing and prohibitions on making funds available to designated parties. Organised by financing method, it addresses the misuse of banking services, money remitters, hawala, online payments, non-profit organisations and cash smuggling, and, for proliferation, banking sector abuse, cyberactivity, economic resources, trade and legal entities. For banks it details concrete evasion techniques, supporting stronger screening, monitoring and reporting.

goAML FAQs, September 2020

The goAML FAQs Guide, issued by the UAE Financial Intelligence Unit in September 2020, is a practical question and answer reference for reporting entities that use the goAML platform, through which suspicious reports are filed in the United Arab Emirates. It compiles the queries most commonly raised by users and gives step by step responses for tasks arising once an organisation is registered. It explains how to reset a forgotten password, update organisation details through the My Org Details menu, and change personal details, and describes delegation of reporting to a third party by the Money Laundering Reporting Officer, subject to Supervisory Body approval. For banks it resolves routine issues.

goAML Registration Guide Stage 2, September 2020

The goAML Registration Guide Stage 2, issued by the UAE Financial Intelligence Unit in September 2020, outlines the steps an organisation follows when registering with the FIU on its reporting platform, goAML. It applies to registration as a reporting entity, stakeholder or supervisory body, and confirms that all accountable and reporting entities in the United Arab Emirates, whatever their regulator, must register to submit suspicious reports, noting that since 27 June 2019, reports must be submitted electronically. It explains reaching the portal through the Services Access Control Manager, noting that Central Bank-regulated institutions need a dedicated MPLS link while others use the internet. For banks, registration enables lawful reporting.

Guideline on Grievance Procedures

The Guideline on Grievance Procedures is issued by the Executive Office for Control and Non-Proliferation, the authority receiving grievance requests related to the UAE Local Terrorist List and the United Nations Security Council Consolidated List, together the Sanctions Lists. It clarifies how requests are submitted, the types available and how they are reviewed. Under Cabinet Resolution No. 74 of 2020, it processes three types of requests: to remove or de-list a designation, to cancel or lift freezing measures, and to permit use of frozen assets. Procedures apply only to freezes based on Sanctions List designations. For banks, it explains the lawful routes customers use to challenge designations or access frozen assets.

Online Grievance System User Guide

The Online Grievance System User Guide is issued by the Executive Office for Control and Non-Proliferation, the authority receiving grievance requests related to the UAE Local Terrorist List and the United Nations Security Council Consolidated List, together the Sanctions Lists. The Executive Office launched the system to streamline submissions, and this manual walks users through the application form. It explains the steps for the three request types: de-listing, cancellation of freezing measures, and permission to use frozen funds. It covers identifying the aggrieved party, selecting the relevant lists and grievance type, and attaching documents. For banks, it explains the route through which affected customers challenge designations or access frozen assets.

Simple Guide to Subscribe to the EOCN Notification Alert System (NAS)

This short guide explains how to subscribe to the Notification Alert System operated through the Executive Office’s website, so that users receive timely updates to the sanctions lists applied in the United Arab Emirates. It notes that targeted financial sanctions rest on two lists, together the Sanctions Lists: the UAE Local Terrorist List issued by the UAE Cabinet, and the United Nations Consolidated List issued by the Security Council. The guide sets out where the lists can be accessed and gives step-by-step subscription instructions. For banks, it supports a core control: screening only works from current lists, and prompt notification helps them freeze without delay.

Emerging ML, TF and PF Risks and Trends in the Financial Sector

Emerging ML, TF and PF Risks and Trends in the Financial Sector, issued by the Supervisory Subcommittee, gives banks a current overview of the money laundering, terrorist financing and proliferation financing threats reshaping the sector. Responding to technological innovation, geopolitical shifts and evolving criminal methods, it is issued under Article 16 of Federal Decree-Law No. 10 of 2025. It examines emerging risks, including exploitation of artificial intelligence, greenwashing and ESG-related fraud, trade finance abused for proliferation financing, illicit virtual asset transactions in banking, and sanctions evasion. Banking case studies cover money mule networks, trade-based laundering and virtual asset conversion, highlighting typologies and red flags for risk assessments and controls.

Typologies in the Financial Sector

Typologies in the Financial Sector is a report produced jointly by the Supervisory Authorities Sub-Committee and the Financial Intelligence Unit, with the Executive Office and a pilot group of financial institutions. It shares money laundering, terrorist financing, sanctions, fraud, and bribery and corruption typologies observed in the market, several emerging during the COVID-19 pandemic, to help firms anticipate and mitigate risks beyond those in the National Risk Assessment. It examines proactive analysis, the increased use of unlicensed money service operators that balance books over time, and combinations of risk indicators, noting links to modern slavery. For banks, it is an early warning tool to refine monitoring and engage authorities.

NRA, SRA, and Other Important Guidelines for Banks

The UAE assesses its money laundering, terrorist financing, and proliferation financing risk at the national level, and banks must align their own business and enterprise-wide risk assessments with those findings.

UAE PF National Risk Assessment 2026

The UAE Proliferation Financing National Risk Assessment 2026 examines the country’s exposure to proliferation financing, meaning financing of weapons of mass destruction and evasion of targeted financial sanctions under United Nations Security Council resolutions on the Democratic People’s Republic of Korea and Iran. Prepared under the Financial Action Task Force’s revised Recommendation 1, it rates threats across mainland and free zone sectors; overall risk is medium-high. Banks are rated medium-high in the mainland, exposed through trade finance and open account transactions, while virtual asset service providers are high, and exchange houses and hawala are medium-high. Free zone banks are medium, maritime insurance medium, stored value medium-low. It shows where risk sits.

The table below summarises the residual risk ratings that the banking sector should reflect in its own risk assessment (from the UAE ML and TF National Risk Assessment 2024 and the UAE PF National Risk Assessment 2026).

UAE ML and TF National Risk Assessment 2024

The UAE Money Laundering and Terrorist Financing National Risk Assessment 2024 is the country’s second national assessment, prepared using the World Bank methodology by the National Committee. Drawing on data from 2019 to 2023, it rates threats, vulnerabilities and residual risks, including a sectoral assessment of financial institutions across the mainland and financial free zones. Overall money laundering residual risk is medium-high, with drug trafficking and fraud among the highest threats. The banking sector is rated medium-high, reflecting its attractiveness and exposure to fraud and third-party laundering. Exchange houses are medium-high, registered hawala high, finance companies and insurance medium, and securities medium to medium-high. It sets the baseline for banks.

Assessment  Banking sector residual risk 
Money laundering and terrorist financing (NRA 2024)  Medium-high, on an inherent risk of high, with controls assessed as largely effective 
Proliferation financing (PF NRA 2026)  Medium-high in the mainland, mainly through trade finance and open account transactions 

Alongside the national assessments, sector risk assessments, red flag guidance, and typologies reports give banks the detail they need to keep their enterprise-wide risk assessment current and defensible.

CBUAE Guidance Applicable to Banks in the UAE

The Central Bank’s guidance for licensed financial institutions applies to banks as Licensed Financial Institutions. The documents below make up that guidance set.

CBUAE Thematic Review on Sanctions List Screening in the Banking Sector, May 2026

Issued in May 2026, this CBUAE thematic review examines how banks screen against the UAE Local Terrorist List and the United Nations Security Council Consolidated List. It sets out findings and supervisory expectations on the quality of sanctions screening, name matching, and the timeliness of freezing and reporting, and it is read alongside the Central Bank’s guidance on the implementation of targeted financial sanctions.

CBUAE Best Practices for Licensed FIs on Implementing Role-Based AML/CFT/CPF Training, October 2025

The CBUAE Best Practices for Licensed Financial Institutions on Implementing Role-Based AML/CFT/CPF Training, published in October 2025, sets out how banks and other institutions should design and deliver training tailored to the specific responsibilities and risk exposure of each role. It treats a comprehensive programme as critical to compliance, helping staff identify money laundering, terrorist financing and proliferation financing red flags within their own functions. Content, frequency and intensity follow a risk-based approach. The document addresses scope, guidance for the Board, senior management and the three lines of defence, and how to document, update and record training. For banks, well-targeted training equips staff with the judgement their duties demand.

CBUAE Best Practices for Licensed FIs on a Risk-Based Approach and Institutional Risk Assessments, October 2025

The CBUAE Best Practices for Licensed Financial Institutions on Implementing a Risk-Based Approach and Conducting Institutional Risk Assessments, dated October 2025, assists banks and other licensed institutions in developing a methodology, conducting an institutional risk assessment, and applying a risk-based approach across money laundering, terrorist financing and proliferation financing risk. Issued under Article 44.11 of Cabinet Decision No. 10 of 2019 (now repealed and replaced by Cabinet Decision No. 134 of 2025, under which supervisory guidance is issued pursuant to Article 49.4), it sets expectations without replacing binding requirements. It describes an effective methodology, granularity, accountability and frequency, then best practices for assessing inherent risk across customers, products, channels and geographies, evaluating controls, and determining residual risk. It applies to banks and other institutions. Sound assessment underpins proportionate, compliant controls.

CBUAE Guidance for Licensed FIs on Correspondent Banking, October 2025

The CBUAE Guidance for Licensed Financial Institutions on Correspondent Banking and Managing Correspondent Banking Relationships, published in October 2025, explains how banks should understand and control the money laundering, terrorist financing and proliferation financing risks arising from correspondent banking and cross-border payments. It describes what correspondent banking involves and the requirements for processing cross-border transfers. It sets out respondent risk factors, including nested relationships, payable-through accounts, geography, ownership and customer base. On mitigation, it covers risk assessment, standard, specific and enhanced due diligence, ongoing monitoring, suspicious activity reporting, sanctions obligations, governance, audit, training and record-keeping. For banks, correspondent relationships can expose them to parties they do not themselves know.

CBUAE Guidance for Licensed FIs on Customer Due Diligence and Record-Keeping, October 2025

The CBUAE Guidance for Licensed Financial Institutions on Customer Due Diligence and Record-Keeping, published in October 2025, addresses controls foundational to anti-money laundering, counter-terrorist financing, counter-proliferation financing, sanctions, counter-fraud and anti-bribery compliance. It treats due diligence and know your customer processes as the cornerstone for banks seeking to understand customers, including occupation, source of funds, wealth and expected activity, so suspicious activity can be detected. It covers identification and verification of customers, beneficial owners and those acting on a customer’s behalf, risk profiling, ongoing monitoring, simplified and enhanced due diligence, non-face-to-face relationships, name screening, exit, third-party reliance and record-keeping. Reliable records underpin the ability to report financial crime.

CBUAE Guidance for Licensed FIs on Risks Related to Proliferation Finance, October 2025

The Guidance for Licensed Financial Institutions on Risks Related to Proliferation Finance, issued by the CBUAE in October 2025, helps banks understand and counter the financing of the proliferation of weapons of mass destruction. Read alongside the CBUAE’s Procedures and Guidelines, it sets expectations rather than new legislation. It explains what proliferation financing is, then the threats and vulnerable channels, including trade finance, correspondent banking, hawala, offshore accounts, free trade zones, shell and front companies, and dealers in precious metals. It addresses United Nations and FATF obligations, local requirements, a risk-based approach, and mitigating controls covering due diligence, monitoring, reporting, sanctions, governance, audit, training and record-keeping. It exploits legitimate structures.

CBUAE Guidance for Licensed FIs on Risks Related to Trade-Based ML and Transshipment, October 2025

The CBUAE Guidance for Licensed Financial Institutions on Risks Related to Trade-Based Money Laundering and Transhipment, published in October 2025, helps banks understand and manage the risks criminals exploit through international trade and the movement of goods. It provides background on the trade system and trade finance, distinguishing documentary finance from open account trade. It sets out typologies, including over- and under-invoicing, over- and under-shipment, multiple invoicing, falsely described goods, shell and front companies, free trade zones, back-to-back letters of credit and registered hawala providers. It addresses services-based money laundering, vulnerable sectors such as gold, and transhipment risks, then mitigation through risk assessment and enhanced due diligence.

Federal Decree-Law No. 6 of 2025 on the Central Bank and the regulation of financial institutions

Federal Decree-Law No. 6 of 2025 is not the AML law, but it sits directly behind a bank’s licence. Issued on 8 September 2025, it governs the Central Bank and the regulation of licensed financial institutions and activities and insurance business, and it confirms that no person may carry on a licensed financial activity in the State without Central Bank authorisation. It repealed Federal Decree-Law No. 14 of 2018, the previous Central Bank law, and regulations, decisions and circulars issued under the old law remain in force until they are replaced.

CBUAE AML and CFT Guidelines for Financial Institutions, July 2023

The CBUAE Anti-Money Laundering and Combating the Financing of Terrorism Guidelines for Financial Institutions, dated July 2023, help supervised institutions, banks among them, understand and perform their statutory obligations under the framework in force in the United Arab Emirates. Prepared jointly by the Supervisory Authorities, they set out minimum expectations for identifying, assessing and mitigating money laundering and terrorist financing risks. They apply to all financial institutions and their boards, management and employees. They summarise the legal frameworks, statutory obligations and typologies, and devote substantial attention to the risk-based approach across customers, products, channels and geography. For banks, they consolidate supervisory expectations into a reference that shapes compliance and due diligence.

CBUAE Guidance for Licensed FIs on Risks Related to Virtual Assets and VASPs, February 2023

The CBUAE Guidance for Licensed Financial Institutions on Risks Related to Virtual Assets and Virtual Asset Service Providers, issued on 20 February 2023, helps banks understand and manage the money laundering and terrorist financing risks arising from exposure to virtual assets and the businesses that deal in them. It explains the associated threats and vulnerabilities and how institutions may become exposed. It describes the UAE legal framework, including the roles of the SCA, CBUAE, VARA and FSRA, and the requirement for CBUAE non-objection before opening accounts for such providers. On mitigation, it addresses the risk-based approach, general, specific and enhanced due diligence. Virtual assets can move value rapidly and pseudonymously.

CBUAE Guidance for Licensed FIs on Digital Identification for Customer Due Diligence, October 2022

The CBUAE Guidance for Licensed Financial Institutions on Digital Identification for Customer Due Diligence, issued on 31 October 2022, helps banks understand how digital identity systems can be used to identify and verify customers and to conduct ongoing due diligence. It reflects the CBUAE’s expectations and should be read with the wider legal framework. It provides an overview of digital identity systems and their participants, explaining identity proofing and enrolment, authentication and lifecycle management. It sets out how such systems may support customer identification, ongoing due diligence and third-party reliance, and examines their risks. It explains how banks should assess a system’s reliability through its assurance levels.

CBUAE Guidance for Licensed FIs on Suspicious Transaction Reporting, August 2022

The CBUAE Guidance for Licensed Financial Institutions on Suspicious Transaction Reporting, issued on 3 August 2022, explains how banks and other institutions should identify, investigate and report suspicious transactions and activity. It sets out the legal basis for reporting, the consequences of failing to disclose, the protection afforded to those who report, and the meaning of a suspicious transaction. It describes the roles of the three lines of defence and the money laundering reporting officer, transaction monitoring methods, and the procedures for filing, structuring, submitting and amending reports. Further sections address confidentiality and the prohibition on tipping off. For banks, timely, well-drafted reporting is central to disrupting financial crime.

CBUAE Guidance for Licensed FIs on Risks Relating to Payments, August 2022

The Guidance for Licensed Financial Institutions on the Risks Relating to Payments, issued by the CBUAE in August 2022, addresses the money laundering and terrorist financing risks that arise across the payments sector and for the institutions, banks included, that serve it. Issued under Article 44.11 of Cabinet Decision No. 10 of 2019 (now repealed and replaced by Cabinet Decision No. 134 of 2025, under which supervisory guidance is issued pursuant to Article 49.4), and read with the CBUAE’s Procedures and Guidelines, it sets out expectations rather than creating new law. It explains what makes payments vulnerable, including the speed of funds movement, peer-to-peer and cross-border payments, intermediation, nesting, agents and merchant risks. On mitigation, it covers risk assessment, customer and enhanced due diligence, ongoing monitoring, wire transfer and correspondent requirements.

CBUAE Guidance for Licensed FIs on Risks Relating to Politically Exposed Persons, August 2022

The Guidance for Licensed Financial Institutions on the Risks Relating to Politically Exposed Persons, issued by the CBUAE in August 2022, sets out how banks should identify, understand and manage the heightened money laundering and terrorist financing risks associated with politically exposed persons. Issued under Article 44.11 of Cabinet Decision No. 10 of 2019 (now repealed and replaced by Cabinet Decision No. 134 of 2025, under which supervisory guidance is issued pursuant to Article 49.4), and read with the CBUAE’s Procedures and Guidelines, it explains that such customers warrant special attention not because banks should avoid them, but because thorough due diligence is needed before accepting a relationship. It distinguishes domestic and foreign politically exposed persons and heads of international organisations, reaching family and close associates, and covers screening.

CBUAE Guidance for Licensed FIs on Transaction Monitoring and Sanctions Screening, September 2021

The CBUAE Guidance for Licensed Financial Institutions on Transaction Monitoring and Sanctions Screening, issued on 8 September 2021, sets out how banks should design, operate and maintain the systems that detect suspicious activity and identify sanctioned parties. It reflects the CBUAE’s expectations for compliance and should be read alongside the wider legal framework. On transaction monitoring, it addresses risk assessment, risk-based deployment, data management, rule definition and testing, alert scoring, outcomes analysis and validation. On sanctions screening, it covers programme design and testing for name and transaction screening, and list management. A further section deals with governance, vendors, training and record-keeping. For banks, validated monitoring and screening are essential.

CBUAE Guidance for Licensed FIs to Cash-Intensive Businesses, September 2021

The Guidance for Licensed Financial Institutions Providing Services to Cash-Intensive Businesses, issued by the CBUAE in September 2021, helps banks manage the money laundering and terrorist financing risks that arise when customers handle large volumes of cash. Issued under Article 44.11 of Cabinet Decision No. 10 of 2019 (now repealed and replaced by Cabinet Decision No. 134 of 2025, under which supervisory guidance is issued pursuant to Article 49.4), and read with the CBUAE’s Procedures and Guidelines, it sets out expectations rather than new legal requirements. It explains why cash is vulnerable, the risks of alternatives such as bearer negotiable instruments and prepaid cards, and concerns including cross-border movement, couriers and currency exchanges. On mitigation, it sets out a risk-based approach, enhanced due diligence, beneficial owner identification and monitoring.

CBUAE Guidance for Registered Hawala Providers and LFIs, August 2021

The Guidance for Registered Hawala Providers and Licensed Financial Institutions Providing Services to Registered Hawala Providers, issued by the CBUAE in August 2021, addresses the money laundering and terrorist financing risks of hawala activity. Because banks are licensed financial institutions, this combined guidance reaches banks through the LFI side, addressing those that serve registered hawala providers as well as the providers themselves. Drawing on the FATF description of hawaladars, it explains what hawala is, its global risks, and UAE regulation, including permitted and non-permitted services. It addresses sanctions and freezing without delay, registration and operating requirements, the need for a bank account, and an AML/CFT programme covering due diligence.

CBUAE Guidance for Licensed FIs on Implementation of Targeted Financial Sanctions, July 2021

The CBUAE Guidance for Licensed Financial Institutions on the Implementation of Targeted Financial Sanctions, issued on 4 July 2021, helps banks meet their obligations to identify, freeze and report assets and transactions connected to designated persons and entities. Read alongside the CBUAE’s procedures and the Executive Office’s guidance, it sets out expectations for demonstrating compliance. It describes a sanctions compliance programme: senior management commitment, risk assessment and appetite, internal controls, training, independent audit and record-keeping. It then covers screening operations, evasion, the United Nations Consolidated List and Local Terrorist List, false positives, payments screening, confirmed matches and notification duties. Effective sanctions implementation is essential to avoid facilitating prohibited activity.

CBUAE Guidance for Licensed FIs to Legal Persons and Arrangements, June 2021

The Guidance for Licensed Financial Institutions Providing Services to Legal Persons and Arrangements, issued by the CBUAE in June 2021, helps banks manage the money laundering and terrorist financing risks that arise when customers are companies, other legal persons or legal arrangements. Read with the CBUAE’s Procedures and Guidelines, it sets out expectations rather than creating new law. It explains how such structures can be misused to obscure beneficial ownership, hide the purpose of an account, and conceal the source of funds. It covers formation requirements, beneficial owner identification, economic substance, and mitigation through the risk-based approach, customer risk rating and enhanced due diligence. Understanding ownership and control is central.

CBUAE Guidance for Licensed FIs to the Real Estate and Precious Metals and Stones Sectors, June 2021

The CBUAE Guidance for Licensed Financial Institutions Providing Services to the Real Estate and Precious Metals and Stones Sectors, issued on 16 June 2021, helps banks understand and manage the money laundering and terrorist financing risks that arise when they serve customers active in these two higher-risk sectors. Read alongside the CBUAE’s AML/CFT procedures, it does not replace any legal obligation; where a discrepancy arises, the legal framework prevails. It examines the risks presented by dealers in precious metals and stones and by real estate, the features that increase risk, and how each sector is supervised. On mitigation, it explains the risk-based approach, customer and enhanced due diligence, and reporting.

CBUAE STR Outreach for Banks and Finance Companies, March 2021

The CBUAE STR Outreach for Banks and Finance Companies, delivered in March 2021, is an awareness session prepared by the Financial Intelligence Unit and the CBUAE to strengthen suspicious transaction reporting across banks and finance companies. Prepared with input from the FIU, the AML/CFT supervision function and the Ministry of Interior, it explains reporting obligations and practical steps. It covers when to report, grounding the duty in Article 15 of Federal Decree-Law No. 10 of 2025 and Article 17 of Cabinet Resolution No. 134 of 2025, and what to report regardless of value. It confirms goAML as the only channel and addresses compliance officer tasks and common deficiencies.

CBUAE Board of Directors Decision No. 59/4/2019 on AML and CFT procedures

Central Bank Board of Directors Decision No. 59/4/2019, issued on 13 June 2019, sets out anti-money laundering and combating the financing of terrorism procedures for financial institutions supervised by the Central Bank of the United Arab Emirates, including banks. Made under Decree Federal Law No. 14 of 2018, repealed and replaced with Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025, it cancels the earlier Circular No. 24/2000. It requires banks and their concerned persons to comply with the law, the implementing regulation and related Central Bank instructions. It empowers the Central Bank to supervise, examine, request information and impose administrative sanctions, establishing the supervisory basis underpinning bank compliance.

CBUAE Guidance Note on Responsible Use of AI and ML by LFIs

The CBUAE Guidance Note on the Responsible Use of Artificial Intelligence and Machine Learning by Licensed Financial Institutions sets out principles for the consumer-focused, ethical adoption of AI and machine learning, including generative AI, by banks. It is non-binding, intended to help institutions formulate internal policies focused on areas bearing on consumers, promoting consumer protection and good market conduct, with principles that can evolve as the technology develops. It covers governance and accountability, placing responsibility with senior management and the Board, a documented framework, reporting and a model inventory. It addresses fairness, transparency, data quality, privacy, monitoring, human oversight, outsourcing and ethical innovation.

CBUAE List of Administrative and Financial Sanctions

The CBUAE List of Administrative and Financial Sanctions records the penalties the Central Bank can impose under the Central Bank Law and the Anti-Money Laundering and Combating the Financing of Terrorism Law. It applies to all licensed institutions and persons, including banks. It explains that the CBUAE is the supervisory authority responsible for addressing shortcomings in compliance frameworks. Under Article 14 of Decretal Federal Law No. 20 of 2018, as amended, it can impose penalties from a warning to licence revocation, and fines of fifty thousand to five million dirhams per violation. Under Article 137, fines reach two hundred million dirhams. It shows a methodical, dissuasive approach to enforcement.

Core AML Obligations for Banks at a Glance

Whatever the licence, the AML regulations for banks in the UAE turn on a common set of duties.

Expert Tip:

For a bank, the two areas that draw the most supervisory attention are correspondent banking and trade finance, because both move value across borders through third parties. Build your enhanced due diligence and transaction monitoring around those flows and document the rationale, and the rest of the programme becomes far easier to defend.

Conclusion

AML regulations for banks in the UAE come down to a simple chain: banks are Licensed Financial Institutions, the Central Bank supervises them, and Federal Decree-Law No. 10 of 2025, its Executive Regulations, targeted financial sanctions rules, and relevant CBUAE LFI guidance form the core framework for banks licensed by the Central Bank. The banking sector carries the deepest obligations in the financial system because it carries the highest inherent risk. Use the national risk assessments to calibrate your programme, treat this guide as the map, and read across to the wider view in our guide to anti-money laundering laws in the UAE and the pillar on AML regulations for banks and financial institutions in the UAE.

Frequently Asked Questions

Are banks subject to AML regulations in the UAE?

Yes. Banks are Licensed Financial Institutions under Federal Decree-Law No. 10 of 2025, supervised by the Central Bank of the UAE, and must run customer due diligence, sanctions screening, transaction monitoring, record-keeping, and suspicious transaction reporting through goAML.

The Central Bank of the UAE supervises banks in mainland UAE and the commercial free zones. Banks established in the DIFC and ADGM are supervised by the DFSA and FSRA under their own AML rulebooks.

The UAE ML and TF National Risk Assessment 2024 rates the banking sector at medium-high residual risk, with an inherent risk of high. For proliferation financing, mainland banks are rated medium-high, mainly through trade finance and open account transactions.

A bank must maintain a risk assessment aligned with the national risk assessments, perform customer due diligence and enhanced due diligence, screen against sanctions and PEP lists, monitor transactions, report suspicious activity through goAML, keep records, and appoint a qualified compliance officer and MLRO.

A bank must identify and verify the customer and any beneficial owner, screen against sanctions and politically exposed person lists, risk-rate the relationship, and establish the source of funds where relevant, applying enhanced due diligence to higher-risk customers before the relationship proceeds.

Common indicators include structuring of cash deposits, unexplained or rapid cross-border wire transfers, trade finance documents that do not match the underlying goods, money mule activity, and transactions that do not fit the customer’s known profile. The red flags and typologies guidance sets these out for detection and reporting.

Yes. A branch of a foreign bank licensed by the Central Bank must run a full local AML programme and remain answerable to the Central Bank for its UAE activities, even where the head office operates its own global controls.

This guide focuses on banks licensed and supervised by the Central Bank of the UAE outside the financial free zones. Banks in the DIFC and ADGM are supervised by the DFSA and FSRA, respectively, under their own AML rulebooks, while UAE federal AML legislation also forms part of the applicable framework in those financial free zones.

Need help building or reviewing your bank's AML programme?

Ensure your bank's AML programme is effective, compliant, and aligned with regulatory expectations. Get expert advice tailored to your business.

Share via :

About the Author

Pathik Shah

FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)

Pathik is an ACAMS-certified AML consultant specialising in governance, risk, and compliance for regulated entities in the UAE. He brings over 28 years of experience, with 1,000+ hours of AML training and 200+ advisory engagements across DNFBPs, VASPs, and FIs. He supports businesses in aligning with AML/CFT requirements from the CBUAE, DFSA, MoET, MoJ, VARA, CMA, FSRA, and FATF. Known for translating complex regulations into audit-ready procedures, Pathik enables operational clarity and compliance readiness.

Reach Out to Pathik

Supplemental Guidance for Dealers in Precious Metals and Stones (DPMS)

Supplemental Guidance for Dealers in Precious Metals and Stones (DPMS)

Blogs

Last Updated: 06/03/2026

Table of Contents

Protect your business with reliable and effective AML strategies with AML UAE.

MoET's DPMS Guidance in Nutshell

  • Applies to all UAE dealers in precious metals and stones (DPMS), covering metals above set purity thresholds, diamonds, coloured gemstones and pearls above defined weights.
  • The AED 55,000 threshold is the minimum legal trigger for treating a transaction as a covered transaction requiring full AML/CFT/CPF measures, not an exemption below it. DPMSR filing is a separate threshold-based reporting obligation with its own specific triggering circumstances. Related transactions, instalments, and cash equivalents must all be aggregated toward the threshold.
  • CDD and EDD must be applied on a risk-driven basis and are not limited to transactions at or above AED 55,000. Sanctions screening is a threshold-independent obligation; its depth and frequency must be proportionate to the risk profile. Ongoing monitoring applies to business relationships, with proportionate steps taken for occasional transactions. A five-year record retention rule applies across four specific triggering events.
  • Sub-sector risk varies: refineries and bullion traders face the highest ML risk, wholesalers are most exposed to TBML, and retail jewellers face placement and structuring risk.
  • Common gaps include mistreating the AED 55,000 threshold, missing DPMSR filings, and weak supply chain CDD, particularly in higher-risk subsectors.
  • MoET expects a documented, proportionate risk-based programme: strong governance, supply chain due diligence, TBML detection, red-flag training and an empowered MLRO.

What UAE Dealers in Precious Metals and Stones Need to Know About AML/CFT/CPF Compliance

Where a person or entity is regularly engaged in dealing in precious metals and stones in the UAE and carries out transactions meeting or exceeding the AED 55,000 covered transaction threshold, it falls within the DNFBP category under Federal Decree-Law No. (10) of 2025 and Cabinet Resolution No. 134 of 2025, and must comply with the applicable AML/CFT/CPF obligations.

Entities whose business involves only incidental or infrequent dealings in PMS, where such transactions are not a regular component of the business, should assess carefully whether they qualify as a DPMS for these purposes.

MoET published sector-specific Supplemental Guidance for Dealers in Precious Metals and Stones in March 2026 to set out sector-specific expectations, risk factors, and practical considerations. It should be read alongside the UAE AML/CFT/CPF legal framework, MoET’s broader DNFBP guidelines, and applicable EOCN guidance.

The 2024 UAE National Risk Assessment (NRA) identifies the DPMS sector as one with high inherent exposure to money laundering risks, yielding a residual risk rating of medium-high. The key drivers include high cash intensity, the portability of high-value goods, extensive cross-border trade, involvement of legal persons, and reliance on intermediaries.

The 2024 MoET Sectoral Risk Assessment (SRA) specifically flags bullion trading, refinery, and wholesale activities as higher-risk subsectors.

Need a BRA or AML Programme Tailored to Your DPMS Sub-Sector?

Develop a risk-based compliance framework aligned with your business model, supply chain exposure, and MoET expectations.

Legal Status and Applicability of the MoET DPMS Supplemental Guidance

Who Does the Guidance Apply To?

  • Scope of Applicability
  • How to Read Mandatory vs Recommended Requirements
  • Relationship with EOCN Guidelines on TFS and CPF

Scope of Applicability


Unless otherwise stated, this guidance applies to all Dealers in Precious Metals and Stones, including their boards of directors, management, and employees, established and operating in the territory of the UAE and in Commercial Free Zones.

It applies whether they establish or maintain a business relationship with a customer or engage in the financial activities and transactions outlined in Articles 2 and 3 of Cabinet Resolution No. 134 of 2025. The guidance applies equally to entities in the mainland UAE and in Commercial Free Zones without distinction.

How to Read Mandatory vs Recommended Requirements

The guidance draws a clear distinction between mandatory and recommended obligations. Requirements indicated by ‘shall’ or ‘must’ are compulsory. Requirements indicated by ‘should’ signify recommended practice, unless a recorded, risk-based justification supports an alternative approach that provides equal or greater control. In cases of any discrepancy between this guidance and the Federal Decree Law, Cabinet Resolutions, and directives from the Competent Authority, the legislation and directives take precedence.

Relationship with EOCN Guidelines on TFS and CPF

While this guidance provides high-level direction on Targeted Financial Sanctions (TFS) and Counter-Proliferation Financing (CPF), all operational, procedural, and implementation requirements in these areas remain governed by the applicable EOCN guidelines.

DPMS entities must refer separately to the full TFS guidelines issued by the Executive Office for Control and Non-Proliferation (EOCN) under Cabinet Decision No. 74 of 2020, which detail their obligations for screening, freezing, and reporting in relation to designated persons or entities.

The primary legislative basis for TFS and CPF obligations also sits in Federal Decree-Law No. (10) of 2025, Part 5, and Cabinet Resolution No. 134 of 2025, Chapter 6; Cabinet Decision No. 74 of 2020 provides the operative procedural framework for implementation.

DPMS should additionally refer to the EOCN Guidance on Counter Proliferation Financing and the Guidance on Proliferation Financing Institutional Risk Assessment to incorporate PF risk into their Business Risk Assessment.

Legal Status of This Guidance

What This Guidance Is and Is Not

The MoET Supplemental Guidance for DPMS is a practical compliance tool. It does not constitute additional legislation or regulation and is not intended to set legal, regulatory, or judicial precedent. It does not replace or supersede any legal or regulatory requirements or statutory obligations. Regulated entities should perform their own assessments of how to meet statutory obligations and should seek legal or other professional advice if they are unsure of the application of the legal or regulatory frameworks to their specific circumstances.

Nothing in this Supplemental Guidance should be interpreted as providing any explicit or implicit guarantee or assurance that supervisory or other Competent Authorities would defer, waive, or refrain from exercising their enforcement, judicial, or punitive powers in the event of a breach of the prevailing laws, regulations, or regulatory rulings. The guidance also notes that the lists and examples it provides are not exhaustive and do not set limitations on the measures regulated entities may need to take.

Unsure Whether Your Business Qualifies as a DPMS?

Get a free initial assessment to test whether your activity falls within DPMS scope and how the AED 55,000 threshold applies.

Regulatory Definition of Precious Metals and Stones Under UAE AML Law

One of the most practically important sections of the MoET DPMS Guidance is the precise regulatory definition of what counts as a precious metal or stone for AML/CFT/CPF purposes. This definition determines whether and when your compliance obligations are triggered. These classifications align with UAE federal legislation governing the control, stamping, and identification of PMS, as well as with the Kimberley Process Certification Scheme for raw diamonds.

Precious Metals: Minimum Purity Thresholds

Which Metals Are Covered and at What Purity

The guidance sets out four precious metals and their minimum purity levels for the purposes of applying AML/CFT/CPF measures. Gold must have a minimum purity of 500 parts per 1,000. Silver must have a minimum purity of 800 parts per 1,000. Platinum must have a minimum purity of 850 parts per 1,000. Palladium must have a minimum purity of 500 parts per 1,000. These purity thresholds define the point at which the metals carry sufficient value and liquidity to pose material ML/TF/PF risks. Metal falling below these thresholds may fall outside the specific PMS definition for this purpose. However, DPMS should still consider whether the product’s value, the customer’s risk profile, or the transaction pattern calls for proportionate AML/CFT/CPF measures. See Other High-Value Materials That Carry Similar Risk below.

The 50% Rule for Composite Objects

Any object where at least 50% of its monetary value is derived from precious metals or precious stones must be treated as PMS for AML/CFT/CPF purposes, irrespective of its form or intended use.

Other High-Value Materials That Carry Similar Risk

The guidance further notes that DPMS may engage in transactions involving other types of metals and gemstones, which, while technically not classified as PMS, may nevertheless carry ML/TF/PF risks similar in nature to PMS. These include other high-value metals such as platinum-group or platinoid metals like rhodium, semi-precious gemstones such as amethysts, opals, and jade, and synthetic, treated, or artificial gemstones, including lab-grown diamonds, emeralds, rubies, sapphires, and pearls. DPMS should apply a risk-based approach to these materials, considering the nature, value, and risk indicators of each transaction.

Precious Stones and Pearls: Weight Thresholds

Diamonds: Rough and Polished

The guidance establishes separate weight thresholds for rough and polished diamonds. Rough diamonds of any weight in carats fall within the definition. Polished diamonds that are loose require a minimum weight of 0.3 carats per stone to fall within the definition. Polished diamonds that are mounted in a setting require a minimum weight of 0.5 carats per single stone, whether the setting contains one or more stones. The weight thresholds define the point at which polished diamonds typically acquire sufficient value and liquidity to pose material ML/TF/PF risks. The trade in rough diamonds is also specifically subject to the Kimberley Process Certification Scheme requirements, which DPMS must verify and document.

Coloured Gemstones and Pearls

Coloured gemstones, specifically polished emeralds, rubies, and sapphires, must meet a minimum weight of 1 carat per stone if loose, or a minimum weight of 2 carats per single stone when mounted in a setting, to fall within the definition. Loose pearls require a minimum diameter of 3 millimetres per bead. Pearls that are strung or mounted in a setting require a minimum diameter of 10 millimetres per single bead. While pearls are not technically gemstones, they are included in the definition for the purpose of the DPMS guidance because they carry comparable value and liquidity characteristics.

Understanding the AED 55,000 Covered Transaction Threshold

The AED 55,000 threshold is the most commonly misunderstood aspect of UAE DPMS compliance. The MoET DPMS Guidance devotes significant space to clarifying exactly how it works and, critically, what it does not mean. Understanding this correctly is essential to passing a MoET supervisory inspection.

What the AED 55,000 Threshold Means

How Related Transactions Are Aggregated

The guidance makes clear that the threshold applies to single transactions or to a series of transactions that appear to be related. This includes one or more transactions involving the same business relationship or customer, whether related to a single item or set of items.

It also includes one or more transactions which, in the judgment of the dealer, appear to be structured so as to avoid the established threshold. The nature of the transaction, customer behaviour, and other relevant risk indicators should be considered when determining whether transactions are related or structured.

DPMS cannot treat separate invoices for the same visit as unrelated transactions simply because each individual invoice is below the threshold.

Cash Equivalents Count Toward the Threshold

A significant and frequently overlooked element of the threshold rules is that cash equivalents count toward the AED 55,000 limit in exactly the same way as cash. Cash equivalents are bearer negotiable instruments, including cashier’s cheques, money orders, postal orders, treasury bills, bearer bonds, and promissory notes. They are instruments that can be transferred without identifying the underlying owner, and they function as cash for the purposes of the AML/CFT/CPF framework. Trade-in items accepted as part payment are also treated as cash equivalents.

The guidance provides a specific worked example: a retail dealer who accepts a diamond ring valued at AED 10,000 as a trade-in toward an AED 60,000 pendant, resulting in a net cash transfer of only AED 50,000, is still conducting a covered transaction because the payment in kind is a cash equivalent.

Worked Examples from the Guidance

Separate Invoices Do Not Defeat the Threshold

The guidance provides a worked example of a customer who makes cash purchases of several different PMS items at the same time and requests separate invoices for each piece. No individual invoice meets the threshold of AED 55,000, but the total purchase price exceeds this amount. The guidance is explicit that these are covered transactions. This worked example directly addresses one of the most common structuring techniques observed in the DPMS sector and makes clear that separating a single visit or transaction into multiple invoices does not defeat the obligation.

Instalment Payments Are One Transaction

The guidance provides a worked example of a customer who wishes to purchase items with a total value meeting or exceeding AED 55,000 and places a 25% deposit in cash below the threshold, then pays further cash instalments over subsequent weeks. The guidance confirms that all of these transactions are related and are therefore covered transactions, even though each individual payment is below AED 55,000. The practical implication is that DPMS must assess the total transaction value when a customer agrees to purchase items, not merely the value of each individual cash payment.

The Refinery Services Example

The guidance provides a worked example specifically relevant to gold refineries: a retail jeweller brings 9 karat diamond-studded jewellery for refining to a gold refinery, requesting diamond separation and gold refining. The value of the lot of jewellery is AED 90,000, and the charges from the refinery paid in cash by the retailer are AED 2,500. This is a covered transaction even though the cash involved in the service fee is well below the threshold. The exchange of the material in the form of jewellery is above the threshold, and hence the transaction is a covered transaction. This clarifies that refineries must assess the value of the material they are processing, not merely the cash fee they charge for the service.

The DPMSR Reporting Obligation

The Three DPMSR Triggering Circumstances

Covered transaction classification and DPMSR filing are connected but legally distinct obligations. A transaction may trigger the full AML/CFT/CPF framework as a covered transaction under Section 2.2 of the guidance, while DPMSR filing must be assessed separately under the specific reporting circumstances in Section 1.4.1. Not every covered transaction automatically generates a DPMSR obligation, and the DPMSR triggering circumstances differ depending on whether the counterparty is an individual, a company or an entity.

Separate from the SAR/STR obligation, DPMS must file a Dealers in Precious Metals and Stones Report (DPMSR) in three specific circumstances.

  • First, when conducting a transaction with resident individuals for cash equal to or more than AED 55,000 or its equivalent in foreign currency.
  • Second, when conducting a transaction with non-resident individuals for cash equal to or more than AED 55,000 or its equivalent in foreign currency.
  • Third, when conducting transactions with companies or entities equal to or more than AED 55,000 or its equivalent in foreign currency, whether in cash or through wire transfer. Note that for company and entity transactions, the wire transfer trigger makes the obligation significantly broader than for individual transactions.

The DPMSR Is Not Risk-Dependent

The obligation to file a DPMSR is not risk-dependent and must be fulfilled even when CDD measures have been satisfactorily completed, and no red flags have been identified. This is a critical point that many DPMS entities get wrong. Entities cannot decide not to file a DPMSR on the basis that a customer is low risk or that the transaction appeared clean. The filing obligation exists independently of the risk assessment outcome. Failure to submit a DPMSR within the predefined parameters and timelines may undermine the effectiveness of the entity’s compliance framework and expose it to enforcement action.

When Both DPMSR and SAR/STR Must Be Filed Simultaneously

Where a transaction both exceeds the DPMSR threshold and raises reasonable grounds for suspicion, both the threshold-based reporting and suspicion-based reporting obligations must be met in accordance with their respective requirements. The two reporting obligations are entirely independent of each other. Filing a DPMSR does not discharge the obligation to file a SAR/STR, and filing a SAR/STR does not discharge the DPMSR obligation. Effective reporting relies on well-defined internal escalation mechanisms, clear allocation of responsibilities between business functions and the Compliance Officer, and ongoing staff training.

Need Help with DPMSR Filing and STR Quality?

Get support for threshold reporting, suspicious activity escalation, and filing quality across qualifying transactions.

Core AML/CFT/CPF Obligations for UAE Dealers in Precious Metals and Stones

Section 1.4 of the MoET DPMS Guidance sets out eight core compliance obligations under Federal Decree-Law No. (10) of 2025 and Cabinet Resolution No. 134 of 2025. Together they form the basis of an effective risk-based AML/CFT/CPF programme designed to prevent sector misuse for ML, TF, or PF purposes.

Obligation 

What It Requires 

Compliance Administration 

Appoint a qualified CO/MLRO; staff training and screening mandates; subject the AML/CFT/CPF framework to independent audit; overall oversight by senior management; group-wide programmes where applicable. 

Risk Identification and Assessment 

Undertake a Business Risk Assessment proportionate to the nature, size, and complexity of activities, incorporating the 2024 NRA and MoET SRA findings. 

Policies, Procedures, and Internal Controls 

Establish, document, implement, and regularly update AML/CFT/CPF policies and procedures tailored to the entity’s specific business model and risk exposure. 

Customer Due Diligence and Ongoing Monitoring 

Identify and verify customers and beneficial owners; create and maintain customer risk profiles; apply EDD where higher risks are identified; risk-driven approach, not threshold-driven. 

Sanctions and PEP Compliance 

Screen against UNSCR lists; comply with TFS; apply EDD for PEPs; foreign corruption is a key ML threat per the 2024 NRA. 

SAR/STR Reporting 

Promptly report suspicious activities and transactions. Timeliness and quality of SAR/STR reporting are explicitly named as key supervisory focus areas for the DPMS sector. 

Record Keeping 

Retain all CDD, transactional, and correspondence records for at least five years from the triggering event. Records must support reconstruction of transactions and be available to competent authorities without undue delay. 

DPMSR Threshold Reporting 

File a DPMSR for cash transactions with resident and non-resident individuals of AED 55,000 or more, and for all transactions with companies or entities of AED 55,000 or more whether in cash or by cross-border wire transfer. The obligation is not risk-dependent. 

Key Points Across the Eight Obligations

Five-Year Record Retention and the Four Triggering Events

Records must be retained for at least five years from the latest of: the termination of a business relationship or closure of a customer account; the completion of an occasional transaction where no business relationship exists; the issuance of a final judgment by a competent judicial authority; or the dissolution, liquidation, or termination of a legal person or arrangement. All CDD and transactional records must be readily available to Competent Authorities upon request and without undue delay.

SAR/STR Quality as a Supervisory Focus Area

The guidance explicitly names the timeliness and quality of SAR/STR reporting as key supervisory focus areas for the DPMS sector, signalling that these are among the specific areas MoET examines during supervisory inspections. A SAR/STR that is filed late, filed without sufficient supporting detail, or not filed at all for a clearly suspicious transaction represents a distinct compliance weakness that can arise independently of other weaknesses in the entity’s programme.

PEP Exposure and Foreign Corruption as a Key ML Threat

The guidance specifically notes that entities must adopt an approach for dealing with Politically Exposed Persons (PEPs) and must be cognisant that foreign corruption is identified as one of the key ML threats in the 2024 NRA. PEP exposure in the DPMS sector is therefore directly linked to an identified ML threat vector, not merely a generic DNFBP obligation.

“The weight and purity thresholds in the guidance are not arbitrary numbers. They define the point at which PMS acquire sufficient value and liquidity to pose material ML/TF/PF risks. The most common misunderstanding we see is entities treating these thresholds as an exemption below which no AML measures apply. They are not. They define the product scope. The AED 55,000 threshold governs the transaction trigger. The two are entirely separate concepts, and conflating them is one of the most common inspection failure points.”

Jyoti Maheshwari

Jyoti Maheshwari - Partner, NIYEAHMA Consultants LLP

DPMS Compliance Gap Analysis: Where UAE Entities Most Commonly Fall Short

This section provides a practitioner-level gap analysis, mapping each of the eight core obligations to the most common implementation failures observed across UAE DPMS entities during compliance reviews. These observations are drawn from practitioner experience and are consistent with the expectations set out in the MoET DPMS Guidance, but are not themselves derived from the guidance. Every gap listed represents a real inspection risk.

Obligation 

Most Common Gap Observed in Practice 

Supervisory Consequence 

Business Risk Assessment 

BRA was completed once at entity setup and never updated. Does not reference the 2024 NRA or MoET SRA findings. Senior management is not formally involved in the approval. 

MoET expects BRA to be updated periodically and whenever significant changes occur in business, risk, or regulatory environments. An outdated BRA is a core inspection failure point. 

AED 55,000 Threshold 

Treated as a hard on/off switch. CDD is applied only when the threshold is met. No risk-based measures applied to sub-threshold transactions regardless of risk indicators present. 

The guidance is explicit: the threshold is a minimum legal trigger, not an exemption. Sub-threshold transactions showing elevated risk indicators must still be assessed. This is a primary inspection finding for the DPMS sector. 

DPMSR Filing 

Not filed when CDD is clean. Not filed for cash equivalent transactions such as cashier’s cheques or trade-ins. Not recognised as applicable to wire transfers for company or entity transactions. 

The obligation is not risk-dependent. Failure to file within predefined parameters exposes the entity to enforcement action regardless of whether the transaction was otherwise clean. 

SAR/STR Quality 

Filed too late, filed with insufficient detail, or not filed at all for sub-threshold suspicious transactions. Internal escalation not connected to the STR process. 

Timeliness and quality of SAR/STR reporting are explicitly named as key supervisory focus areas for the DPMS sector. Poor quality reports and delayed filing are treated as independent compliance failures. 

Beneficial Ownership 

UBO verification relies entirely on customer self-declaration without corroboration from independent sources. Complex legal structures are not traced beyond the immediate counterparty. 

Sole reliance on customer representations where the overall risk profile warrants enhanced scrutiny is specifically identified as insufficient. Entities must refuse or exit relationships where UBO cannot be verified. 

Supply Chain CDD 

The origin of gold or diamonds is accepted on trust from the counterparty. KPCS documentation has not been checked for rough diamonds. Scrap gold claims are accepted without assessing plausibility relative to quantity. 

Where documentation is incomplete, inconsistent, or unverifiable, shipments are to be rejected. Bullion and refinery operations are specifically identified as higher-risk subsectors requiring demonstrably effective controls. 

Staff Training 

Generic AML training with no DPMS-specific content on typologies, red flags, or TBML. Front-line sales staff are not trained. No scenario-based exercises. 

MoET expects training programmes to address sector-specific risks, emerging typologies, and reporting obligations. Front-line staff who cannot identify DPMS-sector red flags represent a direct compliance gap. 

Record Keeping 

Records are fragmented across emails, physical files, and informal channels. No structured retrieval system. Five-year retention is not tracked or enforced. 

Records must be sufficient to reconstruct transactions, must be readily available to Competent Authorities upon request without undue delay, and must support investigations or be used as evidence in legal proceedings. 

Most Critical Gaps and Why They Matter

Threshold Treatment: The Most Pervasive Gap

Treating the AED 55,000 threshold as a hard on/off switch is the single most common gap observed across UAE DPMS entities. The guidance is explicit: the threshold is a minimum legal trigger, not an exemption. Entities that cannot demonstrate risk-based measures applied below the threshold are exposed during inspection, regardless of how clean their above-threshold records are.

Supply Chain CDD: The Gap Specific to Higher-Risk Subsectors

For bullion traders, refiners, and wholesale entities, supply chain CDD is the most consequential gap. The specific supervisory expectations, including origin plausibility assessment, weight/purity reconciliation, and the mandatory rejection of shipments with incomplete or unverifiable documentation, are set out in the Sub-Sector Specific Compliance Controls table under Gold Refinery / Bullion Trader.

Concerned About Gaps in Your DPMS Programme?

Review your BRA, CDD, monitoring, training, and record-keeping against MoET expectations before the next inspection.

Sub-Sector Specific Compliance Controls for UAE Dealers in Precious Metals and Stones

Each sub-sector within the DPMS space has a distinct risk profile and correspondingly different control requirements. The table below maps each sub-sector to its primary risks and the specific controls required, derived entirely from the source document.

Sub-Sector 

Primary ML/TF/PF Risk 

Key Controls Required 

Gold Refinery / Bullion Trader 

Highest risk: refining and re-melting eliminates all origin identifiers, enabling commingling. Exposure to PF/sanctions evasion via incoming materials from high-risk regions. UAEFIU highlights ongoing responsible sourcing weaknesses. 

(1) Reject shipments with incomplete, inconsistent, or unverifiable documentation. (2) Compare the declared origin against the known production capability of the jurisdiction. (3) Reconcile weight, purity, and value against documentation. (4) Apply EDD to all scrap gold purchases. (5) Treat unverifiable scrap claims as high-risk by default. 

Wholesale PMS Trader 

TBML via over/under-invoicing, circular trading patterns, and use of intermediaries to obscure buyer/seller identity. Complex transactional structures and third-party payments without economic rationale. 

(1) Scrutinise price deviations from global benchmarks. (2) Check for mismatched weights, purity discrepancies, or document inconsistencies. (3) Detect circular trading patterns. (4) Validate third-party payments with documented economic rationale. (5) Identify trade routes for unusual detours or low-oversight jurisdictions. 

Retail Jeweller (Buy/Sell) 

Classic placement, layering, and integration risks. Structuring transactions across invoices. Use as a substitute currency. Resale through secondary channels. PEP and criminal association exposure. 

(1) Monitor transaction patterns and cumulative totals against the AED 55,000 threshold. (2) Apply risk-based CDD at all transaction values, not only at the threshold. (3) Verify source of funds for high-value cash purchases. (4) Record denomination and serial numbers when accepting cash and cash equivalents. (5) Reassess customer risk profile when patterns change suddenly. 

Diamond Dealer (Rough/Polished) 

Falsification of KPCS certificates. Conflict diamond commingling. Multi-jurisdictional obscuring of origin. Use as an alternative currency in drug trafficking and arms dealing. 

(1) Verify the KPCS certificate for all rough diamond shipments. (2) Reject shipments without valid KPCS documentation or where the certificate appears forged or has an unusually long validity period. (3) Verify the country of origin is a KPCS participant. (4) Apply the weight thresholds in Section 2.1 to determine AML/CFT/CPF applicability. 

Gold/Silver Scrap Dealer 

Stolen jewellery and conflict gold are entering formal supply chains via recycling. Inability to trace origin once re-melted. Deliberate use of scrap channel to introduce illicit gold into legitimate supply chains. 

(1) Evaluate the plausibility of scrap claims relative to the quantity supplied. (2) Where volumes indicate commercial-scale supply chains, apply enhanced scrutiny. (3) Identify and verify all suppliers, including small-scale collectors. (4) Document rationale for accepting each scrap consignment. (5) An individual or small-scale collector presenting volumes exceeding the stated operational capacity is a red flag. 

Free Zone PMS Entity 

Cross-border trade opacity, multiple jurisdictions, and use of general trading licences to conduct PMS activities without specific authorisation. Invoice-only gold trading as a layering mechanism. 

(1) Verify that the licensed activity is consistent with actual trading activity. (2) Escalate where material discrepancies exist between licensed activities and actual trade behaviour. (3) Flag frequent pro forma invoice requests with no corresponding physical delivery. (4) Scrutinise payment flows through multiple intermediaries across jurisdictions. 

Understanding the Risk Differences Across Sub-Sectors

Risk differs significantly by business model. Refineries and bullion traders carry the highest origin and responsible-sourcing risk because the beneficiation process eliminates traceability: once PMS is refined or re-melted, its origin cannot be recovered. Wholesale traders are most exposed to TBML through over/under-invoicing, false documentation, and multi-intermediary layering. Retail jewellers are primarily exposed to placement and structuring through repeated sub-threshold transactions. The table below maps each sub-sector to its specific risk profile and the controls MoET expects.

Need Sub-Sector-Specific AML Policies?

Build procedures tailored to your DPMS model, whether you operate in retail, wholesale, refining, or scrap.

DPMS AML/CFT/CPF Self-Assessment Diagnostic: Where Does Your Business Stand?

Use this diagnostic to assess your entity’s current compliance posture against the eight core obligations in the MoET DPMS Guidance. For each obligation, identify which description most accurately reflects your current position: GREEN (compliant), AMBER (partially compliant), or RED (non-compliant or not yet implemented). Every RED or AMBER finding represents a regulatory risk that should be addressed before your next MoET supervisory examination.

Obligation 

Diagnostic Question 

GREEN (Compliant) 

AMBER (Partial) 

RED (Non-Compliant) 

Business Risk Assessment 

Do you have a documented BRA updated within the last 12 months that references the 2024 NRA medium-high residual risk rating and MoET SRA subsector findings? 

✅ Documented, board-approved BRA updated within 12 months referencing NRA and SRA 

⚠ BRA exists but does not reference NRA/SRA or is over 12 months old 

❌ No BRA documented, or BRA covers generic risks only 

AED 55,000 Threshold 

Are CDD and risk-based measures applied to ALL transactions regardless of value, treating the threshold as a minimum trigger only? 

✅ Risk-based measures applied at all transaction values; threshold treated as minimum legal trigger 

⚠ CDD applied below threshold for flagged cases only; no systematic approach 

❌ CDD and measures are applied only when the threshold is met 

DPMSR Filing 

Is DPMSR filing integrated into operational workflows and filed for all three triggering circumstances regardless of risk outcome? 

✅ DPMSR filed for all qualifying transactions; process integrated into operations 

⚠ DPMSR filed inconsistently or only when red flags are present 

❌ DPMSR not filed, partially understood, or omitted when CDD is clean 

Beneficial Ownership 

Can you identify and verify the UBO of every legal person counterparty before executing a covered transaction using independent sources? 

✅ UBO verified through reliable independent sources for all legal persons 

⚠ UBO sought but relies mainly on customer self-declaration without corroboration 

❌ UBO not systematically verified; documentary ownership chain not established 

SAR/STR Quality 

Are suspicious transaction and activity reports filed promptly and with sufficient quality and completeness to satisfy supervisory expectations? 

✅ STRs filed promptly with full supporting detail; timeliness and quality reviewed internally 

⚠ STRs filed, but quality is inconsistent, or timing is frequently delayed 

❌ No STR programme in place or significant under-reporting observed 

Supply Chain CDD 

Do you verify the origin of gold, rough diamonds, and other PMS using export certificates, KPCS documentation, customs declarations, and shipment documents? 

✅ Full supply chain CDD applied; KPCS checked; origin compared against known production capability 

⚠ Origin documentation reviewed but not systematically verified against production capability 

❌ No supply chain CDD; origin taken on trust from counterparty 

Staff Training 

Have all staff, including front-line sales and senior management, received AML/CFT/CPF training covering DPMS-specific typologies and red flags? 

✅ Regular, documented, sector-specific training including TBML, structuring, PF red flags 

⚠ Basic generic training in place; no DPMS-specific content on typologies or red flags 

❌ No training programme or last training over 24 months ago 

Record Keeping 

Are all CDD, transactional, and correspondence records maintained in a format that allows reconstruction and is accessible to MoET on request without delay? 

✅ Structured record management system; records retrievable quickly; five-year retention met 

⚠ Records exist but are fragmented across emails, files, and systems 

❌ Records incomplete, inaccessible, or retention period not met 

How to Use Your Results

Interpreting RED Findings

Any RED finding requires immediate remediation. Red findings on BRA currency, threshold treatment, and DPMSR filing are the three most commonly identified in MoET DPMS supervisory examinations and are the first areas an inspector will test. A RED finding on beneficial ownership verification is particularly serious because the guidance specifies that entities must refuse or exit relationships where beneficial ownership cannot be reasonably verified. An entity that cannot demonstrate a systematic UBO verification process has a structural programme failure, not merely a documentation gap.

Interpreting AMBER Findings

AMBER findings indicate partial compliance. They typically indicate that a process exists but is inconsistently applied, insufficiently documented, or not yet embedded into operational workflows. AMBER findings on supply chain CDD, staff training, and SAR/STR quality are the most common. These must be strengthened with documented procedures, staff training records, and evidence of operational implementation before a supervisory examination. An AMBER finding that cannot be explained and evidenced during an inspection is likely to be treated as RED by the inspector.

Using the Diagnostic as a Pre-Inspection Tool

This diagnostic is designed to reflect the actual areas a MoET inspector evaluates during a DPMS supervisory examination. The most effective use is to run it at least six weeks before any anticipated inspection, identify all RED and AMBER findings, assign ownership and deadlines for remediation, and document the remediation steps taken. Entities that can demonstrate awareness of their own gaps and a structured remediation plan are better positioned during an inspection than entities that appear unaware of weaknesses that the inspector identifies.

“What MoET is saying in this guidance is something we see confirmed in client engagements regularly. The risk for IAA firms is not primarily that they will be caught in an obvious fraud. The risk is that a client with a complex ownership structure, a plausible business story, and a well-presented set of financials will slowly draw the firm into legitimising something that should have triggered a closer look three engagements ago. By the time the pattern becomes visible, the audit trail showing how the firm responded to each early warning sign becomes the story. Risk-based controls are not just a regulatory obligation; they are the firm’s own protection.”

Pathik Shah - CAMS, FCA, CISA | Founder and Principal Consultant, NIYEAHMA Consultants LLP

Sector and Risk Context: Why the DPMS Sector Is High Risk

Section 2 of the MoET DPMS Guidance explains the specific risk landscape of the DPMS sector. Understanding this context is essential for building a credible Business Risk Assessment and for demonstrating to a supervisor that your compliance programme is proportionate to the risks your entity actually faces

Why Precious Metals and Stones Are Attractive to Criminals

Intrinsic Value, Portability, and Anonymity

The guidance identifies several specific characteristics of PMS that make them attractive to criminals. PMS represent high intrinsic value in a relatively compact form, tends to maintain or even increase in value over time, and can be easily transported physically in many forms. PMS can be used both as a means to generate criminal proceeds through various predicate offences and as a vehicle to launder them. PMS can be used for illicit purposes, including ML/TF/PF, in a variety of ways, either directly through physical exchange as a form of currency or indirectly through exchange of value via various formal and informal financial systems, as well as via international trade.

Decentralised Markets and Cultural Factors

There are large, well-established, decentralised, and often cash-based markets for certain types of precious metals and stones, particularly for gold and diamonds, which often allow them to be traded or exchanged with relative anonymity. The difficulty in tracing specific items, combined with the global nature of PMS markets, makes it easier for criminals to exploit cross-border, multi-jurisdictional situations to obscure paper and money trails while rendering it more difficult for national law enforcement authorities to detect and investigate cases. The guidance also notes that in certain geographic regions, the buying and selling of PMS is a common cultural practice, making it difficult to distinguish between legitimate transactions and their illicit counterparts.

The ML Threats Identified for the DPMS Sector

The guidance identifies the key money laundering threats for the DPMS sector as trade-based money laundering (TBML), smuggling, laundering of proceeds from drug trafficking and foreign corruption, and activities of professional money laundering networks. While the 2024 NRA did not identify misuse of the sector for terrorism financing, the sector’s characteristics make it vulnerable to misuse for illicit value transfer, sanctions evasion, and proliferation financing, especially through trade-based activities that include degrees of opacity.

The PMS Supply Chain: Risk at Every Stage

Upstream vs Downstream Risk: A Critical Distinction

Upstream activities (extraction, raw minerals trading) carry heightened origin, traceability, and commingling risk. Downstream activities (wholesale and retail) are more exposed to placement, layering, and integration. MoET expects entities to understand their specific position in the chain and calibrate controls accordingly.

The Five Supply Chain Stages and Their Specific Risks

The guidance maps five supply chain stages, each with distinct risk profiles. The table below sets out the key risks and MoET’s control expectations at each stage.

Supply Chain Stage 

Key ML/TF/PF Risks 

MoET Control Expectation 

Extraction / Production 

Infiltration by criminal or terrorist groups, commingling, over/under invoicing, accounting fraud, theft, smuggling, bribery. 

Stronger emphasis on source of origin information, counterparty assessment, and any indicators of commingling or illicit sourcing. 

Trading in Raw Minerals 

Falsification of KPCS certificates, commingling of conflict minerals, cash transactions, smuggling, multi-jurisdictional opacity with multiple traders. 

Enhanced scrutiny of counterparties, payment methods, and trade documentation especially where multiple intermediaries or cross-border movements are involved. 

Beneficiation (Refining / Cutting) 

Loss of traceability through refining or smelting, TBML, cash transactions, commingling. Origin is very difficult to trace once PMS goes through the beneficiation process. 

Deploy adequate controls relating to source of origin information and consistency of purity, volumes, and valuation. 

Wholesale Trade 

TBML, commingling, placement/layering/integration typologies, complex transactional structures, third-party payments. Bullion and scrap: unverifiable scrap claims are high-risk. 

Sufficient awareness and capability to spot TBML typologies. Evidence origin plausibility, reconcile weight/purity vs documentation, treat unverifiable scrap claims as high-risk. 

Retail Trade 

Commingling, placement/layering/integration, fraud, theft, robbery, embezzlement. High-value and repeated transactions particularly vulnerable. 

Greater emphasis on monitoring customer behaviour, transaction patterns, and payment methods, especially where high-value or repeated transactions occur. 

Why MoET Expects You to Know Where You Fit

Supply chain stages do not necessarily proceed in sequence, and entities may operate across multiple stages simultaneously. A Business Risk Assessment must identify the entity’s specific supply chain position and calibrate controls to the cumulative risk exposure across every stage in which it participates.

Risk Factors to Consider When Building Your BRA

Customer and Counterparty Risk Factors

The guidance sets out a range of customer and counterparty risk factors that DPMS must consider. These include whether the counterparty is a physical person, legal person, or legal arrangement; if a legal person or arrangement, whether it is part of a larger or more complex group; and whether there is any association with a PEP. A particular focus is placed on whether the party appears to be acting on their own behalf or at the behest of a third party, and whether the party’s knowledge and experience in relation to the product or service type is appropriate for the transaction being proposed.

Geographic Risk Factors

Geographic risk is pivotal, particularly at upstream supply chain stages in relation to mining and initial sourcing operations. The guidance notes that gold mining can be vulnerable to terrorist financing if it occurs in remote locations with minimal governmental presence or infrastructure, and that in some areas gold mining can be dominated by armed non-governmental groups. Mining for jewels is largely small and informal, often carried on in areas of significant turmoil and conflict. The guidance encourages entities to develop their own country-risk model, drawing on publications issued by the NAMLCFTC, analytical reports and advisories issued by the UAE FIU, and the FATF lists of High-Risk Jurisdictions subject to a Call for Action and Jurisdictions under Increased Monitoring.

Product and Transaction Risk Factors

Product and transaction risk factors include the type, nature, quantity, quality, purity, price, form, rarity, portability, and potential for anonymity of the products or services involved. The type, size, complexity, cost, and transparency of the transaction, including whether a physical or virtual exchange of merchandise is involved, and the means of payment or financing, are also relevant factors, particularly in relation to whether they appear consistent with the counterparty or customer’s socio-economic profile and the degree of expertise required. Novelty or unusual nature of the transaction, such as requirements to expedite beyond what is customary, unusual delivery requirements, or unusual requests for secrecy, are specific risk indicators that the guidance flags.

Does Your BRA Reflect Supply Chain Risk?

Update your risk assessment to reflect origin, counterparty, and transaction risks across your PMS supply chain.

Customer Due Diligence and Ongoing Monitoring for UAE Dealers in Precious Metals and Stones

MoET DPMS Guidance highlights additional CDD and monitoring points that are specific to DPMS and must be applied on top of the general DNFBP requirements. These points highlight typologies and risk indicators specific to the DPMS sector and are intended to support entities in implementing measures that are risk-based, proportionate, and effective.

Sanctions Screening: A Threshold-Independent Obligation

Maintain Threshold-Independent Sanctions Screening

Irrespective of the size of the transaction or the method of payment, DPMS must maintain a process for screening all existing and prospective business relationships and customers against Sanctions Lists. This applies even to transactions that fall well below the AED 55,000 threshold, and does not depend on the risk classification of the customer.

Depth and Frequency of Screening Must Match the Risk

The guidance notes that DPMS are expected to ensure that the depth and frequency of screening are commensurate with the associated risks. Screening should include adverse media checks to identify any potentially adverse information, including associations with PEPs or financial or other crimes. The guidance also requires background checks in addition to sanctions list screening.

Beneficial Ownership: The Core CDD Challenge

Third-Party Intermediaries as a Concealment Technique

The guidance identifies the attempt to conceal beneficial ownership through third-party intermediaries, proxies, or legal structures as a characteristic technique used in a variety of ML/TF/PF typologies. Such intermediaries may include family members, friends, business associates, other legal representatives, or other third persons. These arrangements can help to create distance between the source of the illicit funds and the transaction or activity in question. In the DPMS context, DPMS should be particularly attentive to establishing and verifying the identity of the true beneficial owner and corroborating the legitimacy of their source of funds through reliable independent sources, wherever ongoing business relationships are concerned or when high-risk situations are identified.

The Verification and Corroboration Process

The starting point in determining beneficial ownership of a legal entity or legal arrangement is to ask pertinent questions and obtain information directly from the business relationship or customer. The information thus obtained should be analysed for reasonableness and consistency and should be appropriately confirmed or corroborated with reference to reliable independent sources whenever possible. The guidance specifies that sole reliance on representations provided by customers where the overall risk profile warrants enhanced scrutiny is not sufficient. Reliable independent sources include (but are not limited to) bank references or bank account information provided by financial institutions or commercial credit reporting agencies, public registries, and federal or national tax identification numbers.

CDD Alerting Factors Specific to DPMS

The guidance identifies three specific CDD alerting factors for DPMS entities. First, compatibility of the customer’s profile, including their economic or financial resources, with the specifics, including nature, size, and frequency of the transaction or activities involved. Second, use of complex or opaque legal structures or arrangements such as trusts, foundations, personal investment companies, investment funds, or offshore companies, which may tend to conceal the identity of the true beneficial owner or source of funds. Third, possible association with politically exposed persons, especially in regard to foreign customers. These factors must be taken into account both at the time of establishing a business relationship and on an ongoing basis.

When to Refuse or Exit a Relationship

The guidance is explicit that DPMS must refuse or exit relationships where beneficial ownership or source of funds and origin cannot be reasonably verified, or where sanctions and PF risks cannot be mitigated. This is a mandatory obligation, not a discretionary one. An entity that continues a relationship with a customer or counterparty where beneficial ownership has not been verified is operating in breach of the guidance, regardless of how long the relationship has existed or how commercially important the customer may be.

Ongoing Monitoring: Practical Steps for DPMS

What Ongoing Monitoring Looks Like in the DPMS Context

The guidance acknowledges that ongoing monitoring in the DPMS sector is more complex than in sectors with continuous customer relationships. In retail and occasional transaction contexts, it may not always be possible to perform detailed ongoing monitoring of the entirety of business partners’ or customers’ activity. Nevertheless, DPMS must take reasonable steps to protect itself from misuse, particularly where high-risk customers have been identified. The guidance provides three specific monitoring examples: in covered transactions, maintaining careful records of certificate numbers and identifying characteristics of PMS including weight, purity, colour, shape, cut, inclusions, and other markings; in warehousing or safekeeping arrangements, monitoring the status of the merchandise throughout the transaction lifecycle to detect unusual changes or substitutions; and in contracted services such as refining, cutting, or polishing, ensuring that funds received come from known sources on which CDD has been performed.

Payment Method Consistency as a Monitoring Signal

The guidance emphasises that payment methods should be consistent with the customer’s profile and should not be methods that could disguise the origin of funds. Methods that raise monitoring concerns include cash, cashier’s cheques, traveller’s cheques, postal money orders, prepaid cards, third-party endorsed cheques, cryptocurrencies, IOUs, and promissory notes or other difficult-to-trace payment methods. Where it is necessary to accept such forms of payment, particularly cash, DPMS should record as much information as possible, such as the denomination and serial numbers of the banknotes or complete details regarding negotiable instruments. Anomalies identified through monitoring should be assessed and subjected to enhanced scrutiny and reporting where applicable.

Need a DPMS CDD and Ongoing Monitoring Framework?

Put beneficial ownership, source-of-funds checks, and risk-based monitoring into a practical workflow.

Practical Document Checklist for DPMS CDD by Customer and Supplier Type

MoET DPMS Guidance establishes the general principles for beneficial ownership verification and source of funds corroboration. The guidance identifies acceptable evidence, including bank statements, loan or financing agreements, proof of savings, income records, and documents relating to prior property sales. The table below translates these principles into a practical, role-specific checklist for front-line use. This checklist is derived from the obligations set out in the guidance and from practitioner experience of what MoET supervisors expect to see in a customer file during inspection.

Customer / Supplier Type 

Minimum CDD Documents 

EDD Trigger and Additional Documents Required 

Individual (UAE National) 

Emirates ID (verified); source of funds declaration; nature and purpose of transaction; sanctions screening record. 

Risk-Based EDD depending on the facts of the case. Add: PEP status check, adverse media review, enhanced source of funds documentation. 

Individual (Non-Resident / Foreign National) 

Passport (verified); country of residence confirmation; source of funds documentation; nature and purpose of transaction; sanctions screening. 

EDD is triggered by any high-risk jurisdiction link. Add: source of wealth documentation, independent corroboration of source of funds (bank reference, income records), adverse media review, and jurisdictional risk assessment. 

Corporate Entity (UAE) 

Trade licence; memorandum and articles of association; UBO declaration tracing to natural person owning or controlling 25%+; authorised signatory ID; source of funds; sanctions screening of entity and UBO. 

EDD triggered by offshore involvement, PEP shareholders, or a complex structure. Add: full ownership chain documentation, audited financial statements, and independent corroboration of UBO identity. 

Corporate Entity (Foreign / Offshore) 

Certificate of incorporation; constitutional documents; UBO declaration tracing to a natural person; authorised signatory ID; source of funds; sanctions screening. 

Foreign and offshore structures present elevated ML/TF risk and the guidance identifies them as requiring enhanced scrutiny in Section 2.3. Whether full EDD is applied depends on the entity’s risk assessment of the specific structure. At minimum, additional steps should include: full legal structure documentation across all jurisdictions; independent verification of UBO through public registries or commercial databases; source of wealth documentation; and, where nominee arrangements are involved, a legal opinion on the structure. Where the risk assessment identifies heightened opacity, layering indicators, or high-risk jurisdiction exposure, EDD measures should be applied. 

Politically Exposed Person (PEP) 

All documents applicable to individual or corporate types above, plus documented PEP identification and classification. 

EDD measures are required where the risk profile of the PEP relationship warrants them, which in practice will apply to most PEP relationships. The guidance requires entities to adopt a documented approach for dealing with PEPs. As a minimum, that approach should address: senior management approval before establishing or continuing the relationship; enhanced source of wealth verification; documented assessment of transaction purpose against the PEP profile; adverse media review; and ongoing enhanced monitoring throughout the relationship. The degree of EDD applied should be proportionate to the specific risk presented by the PEP’s role, jurisdiction, and business relationship. 

Supplier (Gold / Rough Diamonds) 

Business licence; UBO documentation; supply chain documentation; KPCS certificate for rough diamonds; customs declarations; export certificates. 

EDD triggered by high-risk jurisdiction origin, unverifiable documentation, or CAHRA exposure. Add: mine-of-origin verification compared against known production capability, independent assay or certification from an internationally recognised body, full chain of custody documentation. 

Supplier (Scrap / Recycled PMS) 

Business or individual identification; description and weight of material; stated source of the material. 

EDD triggered where quantity supplied exceeds plausible retail or personal source volumes. Add: documentary evidence supporting the plausibility of the scrap claim, independent assessment of origin where volumes exceed expected capacity. 

Intermediary / Third-Party Payer 

Identification of intermediary; documented commercial rationale for the involvement of the intermediary; CDD on the party on whose behalf the intermediary acts. 

EDD triggered where intermediary involvement has no clear economic rationale. Add: full CDD on the underlying principal, documented assessment of whether the intermediary arrangement indicates UBO concealment, confirmation that the intermediary is not being used to distance the beneficial owner. 

“The eight obligations in Section 1.4 form an interconnected system, not a checklist. The BRA informs the policies. The policies drive CDD. CDD drives monitoring. Monitoring drives SAR/STR quality. If any link is weak, the entire programme is exposed during a supervisory inspection. The most common failure pattern we observe is strong documentation at the policy level but poor operationalisation at the front-line level. MoET inspectors test the front line, not the policy document.”

Dipali Vora - Partner, NIYEAHMA Consultants LLP

Common Sectoral Challenges and Best Practices for UAE DPMS Entities

Section 4 of the MoET DPMS Guidance identifies the specific challenges that make DPMS compliance difficult in practice and sets out the best practices that MoET expects entities to adopt. Understanding these challenges and responses is essential for designing a compliance programme that is both effective and proportionate.

Challenges and MoET Expected Responses

Sectoral Challenge 

Why It Matters 

Best Practice / MoET Expected Response 

Fragmented supply chains and commingling 

Re-melting or re-cutting PMS removes origin identifiers, allowing illicit material to enter legitimate supply chains undetected. 

Identify all counterparties in the supply chain; verify PMS origin against production capabilities; reject incomplete or inconsistent documentation.  

High value in small quantities 

PMS can be moved or stored discreetly, enabling proceeds storage and transport outside formal financial channels. 

Apply risk-based CDD at all transaction values; treat PMS acquisition disproportionate to customer profile as a red flag.  

Cash dominance and structuring 

Cash and cash equivalents create traceability gaps; structuring enables criminals to stay below reporting thresholds. 

Maintain denomination recording; apply source-of-funds enquiries; monitor cumulative transaction totals; aggregate related transactions.  

Responsible sourcing weaknesses 

Smaller entities often accept documentation at face value, enabling conflict gold and sanctioned-network material to enter formal supply chains. 

Verify origin using KPCS certificates, customs declarations, and export documentation; compare against known jurisdiction production capacity; reject unverifiable shipments.  

TBML techniques 

Minor purity or weight manipulations justify large price variations; market volatility masks artificially inflated or deflated pricing. 

Scrutinise price deviations from global benchmarks; check document consistency across invoices, weights, and purity; detect circular trading and identify unusual trans-shipment routes.  

Low AML/CFT/CPF awareness among smaller DPMS 

Limited compliance capacity leads to inconsistent red flag identification and under-reporting, providing easy access points for criminals. 

Appoint a qualified CO/MLRO; ensure regular front-line training; implement independent audit; apply technology-assisted monitoring proportionate to business size and risk.  

Governance and risk-based framework 

Absence of documented, proportionate risk policies leaves entities unable to demonstrate compliance during supervisory examinations. 

Establish written policies and procedures aligned to the entity’s specific risk profile; subject to routine updates when business, risk, or regulatory environment changes significantly.  

Is Your Programme Inspection-Ready?

Run a self-assessment to spot RED and AMBER gaps before MoET does.

ML/TF/PF Typologies Used to Exploit UAE Dealers in Precious Metals and Stones

Section 5 of the MoET DPMS Guidance sets out the common typologies used to exploit the DPMS sector, drawing on FATF research and case analysis. Multiple typologies are often used in combination in a single transaction or series of transactions. Entities should incorporate the regular review of ML/TF/PF trends and typologies into their employment screening and compliance training programmes, as well as into their risk identification and assessment procedures.

Six Typologies Identified in the Guidance

Typology 

How PMS Is Exploited 

Key Detection Signals 

PMS as Alternative Currency 

Gold and diamonds used as payment for illicit goods and services (drugs, arms, trafficking), bypassing the formal financial system. 

PMS accepted or tendered in lieu of cash; no commercial rationale; correlation with known criminal networks. 

PMS as Stored Value 

PMS purchased to hold illicit value over time, transferred across borders, and later converted. Also used in PF/sanctions evasion to shift value into insurable, portable instruments. 

Purchase scale inconsistent with customer profile; weak commercial purpose; warehousing or insurance arrangements disproportionate to declared business. 

Trade-Based Money Laundering (TBML) 

Over/under-invoicing, false documentation, VAT/customs fraud, and virtual trading used to move value. Proforma-only trades and settlement without physical movement are specific indicators. 

Repeated proforma requests without completion; frequent document revisions; price deviations from market benchmarks; settlement without physical delivery. 

Physical Smuggling 

High value-to-weight ratio makes PMS easy to conceal. Techniques include disguising gold or diamonds as ordinary low-value objects. UAE is identified as a primary wholesale supply market in FATF typologies. 

PMS sourced for subsequent export to high-risk jurisdictions; inconsistencies between declared weight/value and physical goods; routing through CAHRA countries. 

Intermediaries and Front / Shell Entities 

Layered ownership, nominee directors, unlicensed brokers, and shell companies used to separate sanctioned or criminal principals from visible transactions. 

Ambiguous or frequently changing ownership; authorised signatories inconsistent with declared profile; non-transparent trade documentation. 

Exploitation of High-Risk Subsectors 

Refining and re-melting eliminates origin identifiers, enabling commingling of illicit gold. Inadequate responsible sourcing controls at refineries and bullion traders create entry points for PF and sanctions evasion. 

Reluctance to provide origin documentation; supply chain custody gaps; economic justification absent or implausible; links to CAHRA or sanctioned counterparties. 

Does Your Team Know the Latest DPMS Typologies?

Train staff to recognise TBML, smuggling, sanctions evasion, and other sector red flags.

Red Flag Indicators for UAE Dealers in Precious Metals and Stones

Section 6 of the MoET DPMS Guidance provides an extensive catalogue of red flag indicators across five categories. The presence of one or more red flags does not automatically imply criminal activity. It indicates that enhanced due diligence or further investigation is warranted. The appointed Compliance Officer must carefully assess all circumstances to determine whether the activity or transaction is indeed suspicious.

Red Flag Summary Table

The table below consolidates the red flags from all five categories in Section 6 of the guidance for operational reference.

Category 

Red Flag Indicator 

Customer: Structuring 

Numerous small transactions over a short period below the CDD threshold, with a substantial cumulative total, are also known as smurfing 

Customer: Structuring 

Customer approaches different branches of the same DPMS in a short period to conduct sub-threshold transactions 

Customer: Structuring 

Payments restructured or split shortly after being informed of reporting or identification requirements 

Customer: Unusual Requests 

Sudden and unusual inquiries about refund policies, followed by requests for large refunds 

Customer: Unusual Requests 

Requests to alter or cancel a transaction after being asked for identity or supporting documents 

Customer: Unusual Requests 

Abnormal requests for precious metal conversions into ordinary objects to disguise PMS identification 

Customer: High-Risk Association 

Customer appears related to a high-risk country or entity associated with CAHRA origin gold trading or to a designated terrorist 

Customer: Transparency 

Customer fails to provide sufficient explanation or documentation for the source of funds 

Customer: Secrecy 

Requests that normal business records not be kept 

Customer: Secrecy 

Unusually concerned about reporting thresholds or the entity’s AML/CFT/CPF policies 

Transaction: Payment 

Unusual or complex payment arrangements without an apparent legitimate business or economic purpose 

Transaction: Third Parties 

Payments received from a third party who is not the owner of the funds, without a legitimate business purpose 

Transaction: Third Parties 

Introduction of third parties late in the transaction lifecycle without a documented commercial rationale 

Transaction: Profile 

Transactions beyond the customer’s means based on stated occupation, income, or industry experience 

Transaction: Refunds 

Overpayment and requests for refunds to a third party or in cash; payment in one form, refund requested in another 

Supplier: Documentation 

Contracts, invoices, or trade documents with vague or missing descriptions, appearing counterfeit, or frequently modified 

Supplier: Origin 

PMS originating directly or indirectly from CAHRA, including routing through intermediary countries to disguise the true origin 

Supplier: KPCS 

Rough diamonds not accompanied by a valid Kimberley Process certificate, or a certificate that appears forged or has unusually long validity 

Supplier: Origin 

Repeated changes in the declared country of origin across invoices, certificates, or shipping documents 

PF: Evasion 

PMS trade structures with unclear end-use, end-user, or ultimate destination of value 

PF: Evasion 

Inconsistencies in trade documents, financial flows, destinations, ports, or addresses 

Real-World Case Studies with UAE Control Mapping d

Section 7 of the MoET DPMS Guidance contains seven UAE-contextualised case studies and eight additional international case studies drawn from FATF research. The tables below summarise each case study, the key ML method used, and the primary UAE DPMS control it tests.

UAE-Contextualised Case Studies (CS 1–7)

Case Study 

Synopsis 

Key Red Flags 

Primary Control 

CS 1: PMS as Substitute Currency and Store of Value 

Drug trafficking network purchased gold and jewellery via split invoices to stay below the threshold; resold through wholesale channels. 

Sub-threshold structuring; repeated purchase-and-resale; no personal rationale. 

Aggregate related transactions; apply risk-based CDD regardless of individual invoice value. 

CS 2: Gold Smuggling / TBML 

Gold smuggled across borders; proceeds laundered through trade documentation misrepresentation and informal value transfer. 

Mismatched trade documents; informal payment channels; CAHRA origin gold. 

Verify customs documentation; screen against CAHRA; apply supply chain CDD. 

CS 3: Retail-Level Misuse for Drug Trafficking 

Criminal group accepted diamonds and jewellery as drug payment; converted incrementally to cash through retail outlets. 

Continual resale of personal jewellery; no interest in design or value; incremental cash conversion. 

Identify unusual resale patterns; apply CDD to walk-in customers showing repeated sub-threshold resale. 

CS 4: Gold as Substitute Currency and Laundering Vehicle 

Criminal syndicate used gold purchases from informal prospectors as remuneration and value storage; resold through unrelated dealers. 

Cash purchases from unregistered suppliers; rapid resale; gold used as remuneration; no business infrastructure. 

Apply EDD for cash-sourced gold from informal suppliers; assess plausibility of acquisition and resale trajectory. 

CS 5: Illicit Gold Trade through Wholesale Trading 

Wholesaler used large cash withdrawals to buy gold from undocumented ‘private individuals’; structured transactions below thresholds; used front company. 

Cash-only procurement at wholesale scale; generic supplier identification; structured tranches; implausible scrap volumes. 

Identify and verify all suppliers including beneficial ownership; assess plausibility of claimed scrap origins; escalate structuring patterns. 

CS 6: Jewellery Merchant as Narcotics Proceeds Conduit 

Diamond merchant received cash, money orders, and cashier’s cheques (structured across instruments) to purchase high-value diamonds for a criminal network. 

Payment via multiple instruments; incomplete records; third-party purchaser; no interest in jewellery characteristics. 

Identify true purchaser and payer; apply EDD for payments via multiple instruments; retain complete records. 

CS 7: Trade Documentation Used to Facilitate Cross-Border Laundering 

UAE free zone entity issued invoices for gold that never moved; illicit funds entered as payment for supposed bullion supply. 

Invoice-only trading; no physical gold movement; proforma requests without completion; mismatched licensed activity. 

Scrutinise invoice-only trades; verify physical delivery; escalate where trade pattern serves purely documentary purpose. 

International Case Studies (CS 8–15): FATF Research Mapped to UAE Controls

The following international case studies from Section 7.1 of the guidance are drawn from FATF research and mapped to the UAE DPMS controls they test.

Case Study 

Country 

Synopsis 

Primary Control 

CS 8: Scrap Gold Smuggling 

United States (HSI) 

Scrap gold declared at USD 6.4m on import; actual payments USD 24m. TBML via customs undervaluation. 

Scrutinise price deviations from global benchmarks; verify declared values, weights, and purity against customs documentation. 

CS 9: Fraudulent Gold Refinery 

Switzerland (MROS) 

STR filed by major refinery after adverse media linked customer to fraud, forgery, and ML. Turnover grew from EUR 150m to EUR 1,000m in three years. 

Evaluate commercial plausibility of supplier growth trajectories; sudden unexplained volume increases are a red flag. 

CS 11: Bangladesh Gold Smuggling 

Bangladesh 

Gold physically smuggled in soft drink bottles and soap bars. UAE, Oman, and Saudi Arabia identified as primary wholesale supply markets for the network. 

Assess whether gold is purchased for export to high-risk jurisdictions; physical smuggling can involve disguising PMS as ordinary objects. 

CS 12: SEZ Jewellery Substitution 

India (DRI) 

Gold jewellery imported into a Special Economic Zone then substituted with brass before export. USD 100–120m in fraudulent imports. 

Free zone entities face analogous risks; trade documentation must be scrutinised for substitution and false certification indicators. 

CS 15: Gold as Funds Justification 

Costa Rica 

Company offered above-market gold purchase prices to justify large cross-border fund transfers; funds withdrawn as cash immediately on arrival. 

Validate third-party payments and ensure plausible economic rationale; above-market purchase offers are a documented red flag. 

Frequently Asked Questions: MoET Supplemental Guidance for Dealers in Precious Metals and Stones

What is the MoET DPMS Supplemental Guidance and is it legally binding?

It is not legislation and does not constitute legal advice, but it sets out the minimum expectations MoET uses as its benchmark during supervisory examinations. Where it conflicts with Federal Decree by Law No. (10) of 2025 or Cabinet Resolution No. 134 of 2025, the legislation prevails.

No. The threshold is a minimum legal trigger for mandatory full AML/CFT/CPF measures, not an exemption below it. Where a transaction below AED 55,000 presents elevated ML/TF/PF risk indicators, proportionate risk-based measures must still be applied.

The DPMSR must be filed for cash transactions with individuals of AED 55,000 or more, and for all transactions with companies or entities of AED 55,000 or more (cash or wire). The obligation is not risk-dependent; where a transaction also gives rise to suspicion, both the DPMSR and the SAR/STR must be filed independently.

Cash equivalents are bearer negotiable instruments (cashier’s cheques, money orders, postal orders, treasury bills, bearer bonds, promissory notes) that can be transferred without identifying the owner. Trade-in items accepted as part payment are also treated as cash equivalents and count toward the AED 55,000 threshold.

The 2024 MoET SRA identifies bullion trading, refinery, and wholesale activities as higher-risk because of supply chain opacity, reliance on intermediaries, and non-standard payment mechanisms. The UAEFIU report additionally highlights ongoing responsible sourcing weaknesses across the sector.

The KPCS is an international certification regime requiring that rough diamond shipments be conflict-free and accompanied by a valid certificate; DPMS must verify this documentation as part of CDD and supply chain controls. Absent, forged, or unusually long-validity KPCS certificates are red flags requiring escalation.

TBML involves disguising criminal proceeds through trade transactions, using techniques such as over/under-invoicing, false documentation, and layering through intermediaries. In DPMS, gold and diamonds are particularly susceptible because minor purity or weight manipulations can justify large price deviations; repeated proforma requests, document revisions, or settlement without physical delivery are specific high-risk indicators.

CAHRA (Conflict-Affected and High-Risk Areas) refers to regions affected by conflict, weak governance, sanctions exposure, or illegal mining. PMS originating from or routed through CAHRA requires enhanced scrutiny; DPMS must compare declared origin against known production capabilities and reject shipments with incomplete, inconsistent, or unverifiable documentation.

BRAs must be updated periodically and whenever significant changes occur in business, risk, or regulatory environments. The 2025 legislative changes (Federal Decree by Law No. (10) of 2025 and Cabinet Resolution No. 134 of 2025) and the 2024 NRA and SRA findings are all qualifying trigger events; a BRA not updated to reflect these is unlikely to meet MoET’s minimum benchmark.

No fixed list is prescribed, but entities must assess the plausibility of scrap claims against the volume supplied. At minimum, collect supplier identification, a description and weight of material, and a stated source; where volumes suggest a commercial rather than personal origin, enhanced scrutiny and documented justification are required.

Conclusion: What Every UAE DPMS Entity Must Do Next

Step 1: Run the Self-Assessment Diagnostic

Use the RAG diagnostic table in Section 8 of this article to assess your current compliance posture across all eight obligations. Any RED finding requires immediate remediation. Document your results and assign ownership and timelines for remediation before your next supervisory examination.

Step 2: Confirm Your Sub-Sector Risk Classification

Identify which of the six sub-sectors in the sub-sector table applies to your operations and implement the corresponding controls. Bullion traders, refiners, and wholesale entities face the highest expectations and must apply origin verification, responsible sourcing documentation, and enhanced counterparty assessment as standard practice

Step 3: Update Your Business Risk Assessment

Incorporate the 2024 NRA medium-high residual risk rating and the MoET SRA findings on bullion, refinery, and wholesale subsectors into your BRA. Obtain formal senior management approval. Document the methodology used, the weights applied to risk factors, and the rationale for the risk ratings assigned to your customer and supplier base.

Step 4: Fix Your Threshold Treatment

If your entity currently applies CDD only at or above AED 55,000, revise your procedures immediately. Your policy must explicitly state that risk-based measures apply at all transaction values wherever risk indicators are present. Document the specific risk factors that trigger sub-threshold CDD in your sector context.

Step 5: Integrate DPMSR Filing into Operations

Confirm that your DPMSR filing process covers all three triggering circumstances, including the wire transfer trigger for company and entity transactions. Build the DPMSR trigger into your transaction processing workflow as an automatic step, not a compliance judgment call. Ensure filing is not conditional on the absence of red flags.

Step 6: Strengthen Supply Chain CDD

Map your position in the PMS supply chain and implement origin verification, KPCS checks, and counterparty due diligence proportionate to your stage and risk exposure. Specifically, compare declared origin against known production capabilities of the declared jurisdiction for every significant supply transaction. Document the comparison and retain the supporting documents.

Step 7: Embed Red Flags in Front-Line Training

Train all front-line staff on the Section 6 red flag indicators, specifically including TBML indicators, supplier behaviour flags, and proliferation financing red flags. Use scenario-based exercises that reflect the case studies in Section 7 of the guidance. Document all training delivered and record attendance.

Step 8: Appoint or Review Your MLRO

Ensure your Compliance Officer or MLRO has sector-specific DPMS knowledge, including familiarity with TBML typologies, KPCS requirements, responsible sourcing standards, and the UAE-specific reporting obligations for DPMSR, SAR, and STR. The guidance requires a qualified CO/MLRO with sector-specific knowledge and a sound understanding of regulatory obligations.

Ready to Build a MoET-Compliant AML Programme?

Get sector-specific support to align governance, controls, reporting, and training with the guidance.

Share via :

About the Author

Pathik Shah

FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)

Pathik is an ACAMS-certified AML consultant specialising in governance, risk, and compliance for regulated entities in the UAE. He brings over 28 years of experience, with 1,000+ hours of AML training and 200+ advisory engagements across DNFBPs, VASPs, and FIs. He supports businesses in aligning with AML/CFT requirements from the CBUAE, DFSA, MoET, MoJ, VARA, CMA, FSRA, and FATF. Known for translating complex regulations into audit-ready procedures, Pathik enables operational clarity and compliance readiness.

Reach Out to Pathik

Supplemental Guidance for Trust and Company Service Providers (TCSPs)

Supplemental Guidance for Trust and Company Service Providers (TCSPs)

Blogs

Last Updated: 06/03/2026

Table of Contents

Protect your business with reliable and effective AML strategies with AML UAE.

MoET's Supplemental Guidance for TCSPs in a Nutshell

  • Issued by the UAE Ministry of Economy and Tourism in April 2026, anchored in Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025, supplementing the broader DNFBP Guidelines.
  • Applies equally to mainland and commercial free zone TCSPs, covering company formation, nominee services, trusts and foundations, registered office services, and cross-border structuring.
  • Sets out core obligations: Business Risk Assessments, risk-based CDD and EDD, beneficial ownership verification across every layer, source of funds and wealth checks, ongoing monitoring, STR reporting, and MLRO governance.
  • Maps five sector-specific risk areas with 21 case studies covering BO opacity, nominee abuse, shell entities, cross-border flows, governance failures, and trust or foundation misuse, alongside detailed red flags and a practical interpretation of the NRA’s Medium Risk rating.
  • Supervisors will test whether controls work in practice rather than on paper, exposing weaknesses to supervisory findings and required remedial actions within specified timeframes.

The UAE Ministry of Economy and Tourism (MoET) released its Supplemental Guidance for Trust and Company Service Providers in April 2026. It is sector-specific and detailed. While it does not create new legal obligations, it is a strong supervisory reference for how MoET expects TCSPs to implement their AML/CFT/CPF obligations in practice. If you operate as a TCSP in the UAE, whether as a formation agent, registered office provider, nominee service provider, trust administrator, or company secretarial firm, this guidance gives a clear indication of the areas supervisors are likely to assess during inspections and supervisory engagements.

This article unpacks the MoET Supplemental Guidance for TCSPs in plain language, adds professional context, and tells you what it actually means for your day-to-day operations. For ease of reference, we use ‘MLRO’ throughout to refer to the designated AML/CFT Compliance Officer or reporting officer responsible for internal escalation and FIU reporting under Article 22 of Cabinet Resolution No. 134 of 2025.

What Is the MoET Supplemental Guidance for TCSPs and Why Does It Matter?

Key Points Under This Section

  • Issued by the UAE Ministry of Economy and Tourism in April 2026
  • Supplements the main DNFBP Guidelines with sector-specific depth
  • Anchored in Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025
  • Does not create new law but shapes what supervisors will test
  • Applies to mainland and commercial free zone TCSPs equally

The MoET Supplemental Guidance for Trust and Company Service Providers provides detailed guidance to TCSPs on exactly how the Ministry expects them to identify, assess, and mitigate money laundering, terrorist financing, and proliferation financing risks within their specific sector.

It sits alongside the broader DNFBP Guidelines rather than replacing them. It does not constitute additional legislation or regulation, does not set legal precedent, and does not replace or supersede statutory obligations under Federal Decree-Law No. 10 of 2025, Cabinet Resolution No. 134 of 2025, or any other binding instrument. Where any discrepancy arises between this guidance and prevailing law, the law prevails.

Think of the DNFBP Guidelines as the framework, and this guidance as the instruction manual for TCSPs within that framework. Where the two overlap, TCSPs should treat this supplemental guidance as the sector-specific reference point, while ensuring continued compliance with the broader DNFBP Guidelines and prevailing legal requirements.

Why This TCSP Guidance Needs Immediate Attention

During supervisory inspections, MoET will assess whether your AML/CFT/CPF controls are operating effectively in practice, not just whether policies exist on paper. The guidance explicitly states that deficiencies in risk assessment, beneficial ownership transparency, or ongoing monitoring may result in supervisory findings and required remedial actions within specified timeframes. The emphasis is on substance over form.

The legal anchor for this guidance is Federal Decree-Law No. 10 of 2025, which came into effect on 14 October 2025, and its implementing regulations under Cabinet Resolution No. 134 of 2025, which followed on 14 December 2025. These are the operative instruments for all UAE AML/CFT/CPF compliance work. References to the older 2018 or 2019 legislation are no longer sufficient.

Who Does the MoET Supplemental Guidance for TCSPs Apply To? Scope and Covered Activities

Key Points Under This Section

  • Five specific activities trigger DNFBP obligations for TCSPs
  • Applies to mainland and free zone TCSPs
  • Covers all boards, management, and employees of covered entities
  • Trust formation and administration carry distinct additional obligations

The MoET Supplemental Guidance for TCSPs applies to any entity conducting the following activities on behalf of a client in the UAE:

Covered Activity  What It Means in Practice 
Acting as an agent in the creation or establishment of legal persons  Company formation agents, business setup advisors, incorporation service providers 
Providing directors, secretaries, partners, or similar roles  Nominee director services, company secretary services, registered manager arrangements 
Providing a registered office, work address, or administrative address  Virtual office providers, registered address services, correspondence handling 
Acting as or equipping another person to act as trustee  Trust administration, fiduciary services, trust operators  
Acting as or equipping another person to act as a nominee shareholder  Nominee shareholding services, share custody arrangements 

The guidance applies to all such entities operating in the UAE, whether on the mainland or within commercial free zones, and covers board members, senior management, and employees. Section 1.3 of the guidance grounds this scope in Articles (2) and (3) of Cabinet Resolution No. 134 of 2025 (the Executive Regulations of Federal Decree-Law No. 10 of 2025).

Not sure whether your firm qualifies as a TCSP under UAE law?

Our team at AML UAE has helped several formation agents, registered office providers, and company secretarial firms determine their regulatory scope and build compliant frameworks from the ground up.

Core AML/CFT/CPF Obligations: What the MoET Supplemental Guidance for TCSPs Requires

Key Points Under This Section

  • Risk identification and assessment must be documented and updated regularly
  • Policies and procedures must cover all compliance dimensions, not just CDD
  • CDD and ongoing monitoring are core functions, not checkbox exercises
  • STR and SAR reporting obligations apply regardless of transaction value
  • Governance includes a qualified MLRO, senior oversight, and staff training
  • Record keeping must allow full reconstruction of decisions by authorities
  • Targeted financial sanctions compliance must include screening freezing action without delay, and reporting under Cabinet Decision No. 74 of 2020

The MoET Supplemental Guidance for TCSPs requires every TCSP to maintain a comprehensive, risk-based compliance framework. The seven core components are not aspirational. They are the minimum standard against which your firm will be assessed.

Each of these components carries a specific weight in supervisory assessments. However, the guidance places particular emphasis on the gap between policy and practice. Having a well-written CDD policy is not enough. Your MLRO needs to be able to demonstrate that it was actually applied, documented, and reviewed in individual client relationships.

On record keeping, the guidance sets a standard that many TCSPs currently fall short of. Records must be detailed enough that a competent authority can reconstruct the rationale and context of every relationship decision without needing oral explanations from your staff. That means documenting not just what you collected, but why you made the risk decisions you did and what alternative courses of action you considered. Under Article 25 of Cabinet Resolution No. 134 of 2025, all CDD records, transaction records, and supporting documentation must be retained for a minimum of five years from the termination of the business relationship or the completion of the occasional transaction, and must be organised so that individual transactions can be reconstructed and made immediately available to competent authorities.

“The governance component is where many TCSPs struggle most. The guidance requires the MLRO to do more than sign off on onboarding forms. They need to be actively reviewing high-risk relationships, providing guidance on ambiguous cases, assessing escalations, and deciding whether reporting thresholds are triggered. That is a substantive role, and it needs to be properly resourced. Appointing an MLRO as a title without giving them the time, access, and authority to do the job is a control weakness that supervisors will identify quickly.”

Jyoti Maheshwari

Jyoti Maheshwari - Partner, NIYEAHMA Consultants LLP

Five Sector-Specific Risk Areas Every TCSP Must Understand

Key Points Under This Section

  • TCSPs should apply enhanced scrutiny during company formation to ensure transparency and to avoid the misuse of this structure to obscure ownership and facilitate illicit activity.
  • Nominee arrangements require enhanced governance regardless of perceived legitimacy
  • Trust and foundation services carry distinct risks from the separation of ownership and control
  • Registered office services carry low inherent risk but are frequently misused in practice
  • Cross-border structures demand a higher standard of scrutiny across all dimensions

The guidance does not treat all TCSP activities as equally risky. It identifies five service types that carry elevated ML/TF/PF exposure and sets out specific control expectations for each.

Company Formation and Legal Structuring

Company formation is the point of entry into the financial and corporate system. The guidance notes that risks are elevated where structures are established with multiple layers of ownership, incorporated across different jurisdictions, or created without a clear commercial purpose aligned to the customer’s economic profile.

The practical expectation is that TCSPs apply enhanced scrutiny at the point of formation itself. This means documenting the purpose of the structure, the rationale for the chosen legal form and jurisdictions, the roles of all parties, and how ownership and control actually work in practice. Higher-risk or more complex structures should go through internal review and approval, including MLRO escalation.

Nominee Shareholders and Directors

The guidance acknowledges that nominee arrangements serve legitimate purposes in some contexts. However, it is equally clear that they carry inherent ML/TF/PF risk because they can obscure the identity of the true beneficial owner and reduce transparency over control.

TCSPs providing nominee services must ensure full transparency over the underlying beneficial ownership structure. This means identifying and verifying the beneficial owners behind the arrangement, documenting the legal relationship between the nominee and the beneficial owner clearly, and understanding the precise scope of the nominee’s authority. Arrangements where the TCSP cannot obtain sufficient information about the beneficial owner must not be accepted.

Trust and Foundation Services

Trusts and foundations present distinct risks because they deliberately separate legal ownership from beneficial interest. The multiple parties involved, including settlors, trustees, beneficiaries, and protectors, make it harder to identify who actually controls and benefits from the arrangement.

The guidance requires TCSPs to identify and verify all relevant parties to the arrangement. Trust deeds must be reviewed in detail. Discretionary arrangements deserve particular attention, because control in these structures is not always immediately apparent. Ongoing monitoring needs to cover distributions, changes in beneficiaries, and amendments to the structure.

Provision of Registered Office and Administrative Services

Registered office services are often treated as low-risk administrative functions. The guidance pushes back on this assumption. When multiple entities are registered at the same address, or when a registered office is used to establish a presence without any substantive business operations, risk exposure increases significantly.

TCSPs providing these services must understand the nature and purpose of each registered entity, verify beneficial ownership and key controlling parties, and monitor for unusual patterns. Even where the TCSP has no broader relationship with the entity beyond address provision, minimum CDD requirements still apply.

Cross-Border Structures and Multi-Jurisdictional Arrangements

The guidance identifies cross-border structures as carrying elevated risk across all TCSP activities. The core concern is that multi-jurisdictional arrangements can fragment ownership, complicate beneficial ownership identification, and obscure the flow of funds in ways that no single service provider can fully see.

The expected approach includes understanding the role and purpose of each jurisdiction, assessing the regulatory environment in those jurisdictions, tracing the flow of funds and assets across borders, and verifying that the geographic footprint of the structure is consistent with the customer’s stated business activities. Cross-border structures should attract enhanced oversight and internal escalation procedures.

Key Risk Factors: Customers, Transactions, and Geographic Exposure

Key Points Under This Section

  • Customer risk is not static: it includes behavioural indicators throughout the relationship
  • Non-resident, offshore, and PEP-linked customers carry elevated inherent risk
  • Transactional risk must be assessed across the full lifecycle of the service
  • Frequent changes in ownership or control are a risk signal, not just an administrative matter
  • Geographic risk extends beyond the customer’s location to the full jurisdictional footprint of the structure

The MoET Supplemental Guidance for TCSPs breaks down risk factors across three dimensions: the nature and type of customers, the nature and type of transactions or services, and geographic exposure. Understanding these three dimensions is the foundation of any credible risk-based approach.

Customer Risk Factors

The guidance expects TCSPs to go beyond static customer characteristics when assessing risk. A customer who presents well at onboarding can still raise red flags during the relationship through inconsistent information, unexplained urgency, or evasiveness about the purpose of a structure.

Specific higher-risk customer types identified in the guidance include non-resident or offshore customers with no clear economic link to the UAE, customers introduced through intermediaries without a face-to-face component, and individuals with PEP connections or links to high-risk jurisdictions. In all these cases, the TCSP’s ability to independently verify information is reduced, and enhanced scrutiny is required.

Transactional and Service Risk Factors

The guidance explicitly frames transactional risk assessment as covering the full lifecycle of the service, not just individual transactions in isolation. A structure that looks low risk at formation can become high risk following changes in ownership, the introduction of new jurisdictions, or shifts in the nature of the underlying activity.

Higher-risk scenarios in this dimension include the establishment of multiple entities within a short timeframe with similar ownership profiles, frequent changes to directors or signatories without commercial justification, rapid transfer or restructuring of ownership across jurisdictions, and the provision of registered office or administrative services to entities without substantive operations.

Geographic Risk Factors

Geographic risk in the TCSP sector is multi-dimensional. The guidance requires TCSPs to assess geographic risk not only based on the customer’s location, but also in relation to the jurisdictions of incorporation of legal entities, the origin and destination of funds, and the location of underlying business activities.

Higher-risk scenarios arise where structures involve jurisdictions with weaker AML/CFT frameworks, limited beneficial ownership disclosure requirements, or known exposure to corruption or sanctions risks. The guidance states that using such jurisdictions is not inherently indicative of wrongdoing. However, it does require a higher level of scrutiny and a clear understanding of the commercial rationale.

Does your TCSP compliance framework cover all five risk areas?

Many UAE TCSPs have strong onboarding processes but significant gaps in nominee governance, cross-border scrutiny, and registered office CDD. Our AML consulting team can help you identify and close those gaps.

Customer Due Diligence, Beneficial Ownership, and Ongoing Monitoring: The TCSP Standard

Key Points Under This Section

  • CDD must go beyond identity verification to encompass purpose, structure, and economic rationale
  • Beneficial ownership identification must cover all layers of complex structures
  • Source of funds and source of wealth verification are distinct requirements
  • Ongoing monitoring must include trigger-based reassessments, not just periodic reviews
  • Record keeping must enable full reconstruction of relationship decisions
  • The MLRO plays a pivotal role beyond receiving and filing escalations

Customer Due Diligence in the TCSP sector carries a higher standard than in most other DNFBP categories. This is because TCSPs are directly involved in creating and administering legal structures, meaning they act as a critical control point before a structure becomes operational.

Establishing a Business Relationship

When a TCSP agrees to create, manage, or support a legal person or arrangement on behalf of a client, it establishes a business relationship that triggers full CDD obligations. At this point, the guidance expects the TCSP to develop a holistic understanding covering the purpose behind the structure, the roles and relationships of all involved parties, the jurisdictions and their risk levels, and the anticipated nature and scale of activities.

The guidance gives particular weight to situations where the structure appears unnecessarily complex, where there is reliance on intermediaries without a clear commercial role, or where the customer is reluctant to provide complete or consistent information. In these cases, the TCSP must not rely solely on formal compliance with documentation requirements. It must critically assess whether the overall arrangement is coherent, transparent, and credible.

TCSPs often receive customers through introducers, law firms, business setup agents, and overseas advisors. Article 20 of Cabinet Resolution No. 134 of 2025 permits reliance on CDD performed by a third party only where the third party is itself subject to AML/CFT regulation and supervision, applies CDD measures consistent with the UAE framework, and provides immediate access to the underlying CDD information and documentation on request. Ultimate responsibility for CDD remains with the TCSP regardless of any reliance arrangement, and the guidance expects the TCSP to satisfy itself, on a documented basis, that these conditions are met before placing weight on a third party’s work.

Beneficial Ownership Identification and Verification

The guidance states that beneficial ownership identification is one of the most critical and complex aspects of CDD for TCSPs. The ability of legal persons and arrangements to separate legal ownership from actual control creates inherent vulnerabilities that can be exploited to conceal illicit activity.

The expected approach requires TCSPs to identify the natural persons who ultimately own or control the structure, whether through direct ownership interests, voting rights, or other forms of control. This includes indirect holdings and layered structures across multiple jurisdictions. The process must not stop at collecting declarations from the customer. The information must be corroborated using independent and reliable sources wherever feasible.

Enhanced scrutiny is required where ownership structures involve jurisdictions with limited transparency, where shares are held on behalf of others without clear documentation, where there are frequent or unexplained changes in ownership, or where the customer seeks to limit access to ownership information.

Source of Funds and Source of Wealth

The guidance distinguishes between the source of funds (the specific origin of the funds used in a transaction) and the source of wealth (the origin of the customer’s overall accumulated wealth). Both are relevant for TCSPs, particularly where structures are used to hold, manage, or transfer assets, or where there is exposure to higher-risk customers or jurisdictions.

The practical expectation is that TCSPs assess whether the customer’s financial profile is consistent with the nature and scale of the structure being established or managed. Particular care is required where the origin of funds links to high-risk activities or jurisdictions, where there is a mismatch between the customer’s known profile and the scale of the transaction, where funds pass through multiple intermediaries without a clear rationale, or where payment methods obscure traceability.

Ongoing Monitoring

The guidance is explicit that ongoing monitoring in the TCSP sector must be dynamic, not periodic. Risks in this sector often materialise through gradual changes rather than discrete suspicious transactions. A risk-calibrated approach to monitoring must include reviewing changes in ownership, control, or governance arrangements, tracking amendments to legal structures, assessing whether the structure continues to be used consistently with its stated purpose, and reassessing risk levels following trigger events.

The guidance identifies specific trigger events that should prompt an immediate reassessment: changes in shareholders, directors, or authorised signatories; introduction of new entities or jurisdictions; significant changes in the nature or scale of activities; and requests for services outside the originally stated purpose.

Where CDD cannot be completed, or where beneficial ownership transparency cannot be achieved to the standard required, Article 14 of Cabinet Resolution No. 134 of 2025 prohibits the TCSP from establishing or continuing the business relationship and from carrying out the requested transaction. The TCSP must also consider whether the underlying facts give rise to a suspicion that warrants an STR or SAR filing through goAML under Article 18 of Cabinet Resolution No. 134 of 2025. Exit and refusal decisions, and the reasoning supporting them, must be documented to the same standard as onboarding decisions.

What This Means in Practice

If you are running annual CDD reviews as your only monitoring mechanism, you are not meeting the standard set by this guidance. The guidance requires trigger-based reassessment as the primary monitoring mechanism, supported by periodic reviews. Your compliance framework needs to define what constitutes a trigger event for each service type and ensure that frontline staff can identify and escalate these promptly.

Is your CDD framework aligned with the 2025 UAE law and this guidance?

Outdated CDD templates, missing source of wealth processes, and weak trigger-based monitoring are among the most common findings in UAE TCSP supervisory reviews. Our team can conduct a targeted AML health check on your CDD framework.

Common Sectoral Challenges and Best Practices: What Good Looks Like

Key Points Under This Section

  • Beneficial ownership transparency across multi-layered structures is the most persistent challenge
  • Over-reliance on customer-provided information without independent corroboration is a recurring weakness
  • Limited visibility in administrative-only relationships creates monitoring blind spots
  • Inconsistent application of the risk-based approach leads to uneven control quality
  • Best practice includes systematic ownership mapping and trigger-based monitoring
  • Integration of CDD, monitoring, and governance functions distinguishes strong frameworks

The guidance dedicates a full section to common challenges and best practices within the TCSP sector. This is unusual in regulatory guidance and reflects MoET’s recognition that the sector faces structural challenges that go beyond a failure to follow rules.

Challenges the Guidance Identifies

The most persistent challenge is beneficial ownership transparency in multi-layered structures. TCSPs encounter ownership chains that include foreign holding companies, trusts, or foundations in jurisdictions with limited public disclosure requirements. Verification beyond the first or second layer is genuinely difficult, particularly where documentation is incomplete or inconsistent across sources.

A second challenge is over-reliance on customer-provided information at onboarding. The guidance notes that information declared by a client may contradict publicly available data or adverse media. Without independent corroboration, these discrepancies remain undetected.

A third challenge is limited visibility in administrative-only relationships. Where a TCSP only provides a registered office or administrative support without involvement in financial transactions, detecting unusual activity becomes significantly harder.

What Best Practice Looks Like

The guidance describes best practices for TCSPs, which include systematically mapping and documenting ownership and control structures using visual or diagrammatic representations rather than narrative descriptions alone. They cross-check customer-provided information against official registries, regulatory filings, and third-party intelligence tools. They implement trigger-based monitoring mechanisms rather than relying solely on fixed review cycles. And they maintain strong documentation and audit trail practices that clearly record not just what information was collected, but why key decisions were made.

The guidance also describes mature TCSPs as forward-looking: using internal data, typologies, and supervisory feedback to continuously refine controls, updating risk indicators, and incorporating lessons from past cases into staff training and internal guidance.

How TCSPs Are Misused: Typologies from the MoET Guidance

Key Points Under This Section

  • Layered corporate structures are the most common vehicle for ML via TCSPs
  • Nominee arrangements are used to create a formal separation between legal and beneficial ownership
  • Company formation services are misused to create entities with no substantive activity
  • Multi-jurisdictional structures exploit regulatory gaps and fragment oversight
  • Trusts and foundations can be used to distance beneficial ownership from assets
  • Registered office and administrative services can create a veneer of legitimacy
  • Fiduciary roles are misused to enhance the perceived legitimacy of illicit structures

The guidance describes eight distinct typologies through which TCSP services may be misused for ML/TF/PF. Understanding these is not an academic exercise. Each one maps directly to a control expectation in your compliance framework.

Typology  How It Works  Key Control Response 
Layered corporate structures  Multiple entities across jurisdictions create distance between beneficial owner and assets  Full ownership chain mapping; verify UBO across all layers 
Nominee arrangements  Nominees provide formal separation from beneficial owner; act on instructions without independent judgement  Document legal relationship; verify UBO behind nominee; ongoing monitoring of use 
Shell entity formation  Legal entities with no substantive activity used to hold funds, conduct transactions, or create legitimacy  Verify actual business activity; assess economic substance at formation and ongoing 
Multi-jurisdictional structures  Jurisdictional diversity fragments oversight and exploits regulatory gaps  Assess each jurisdiction’s risk; verify commercial rationale for jurisdictional choices 
Trust and foundation misuse  Discretionary beneficiaries, broad classes, and cross-border elements obscure beneficial interests  Identify all parties; review trust deeds; monitor distributions and amendments 
Fiduciary role exploitation  Regulated professional involvement used to enhance legitimacy of illicit structure  Exercise independent judgement; maintain oversight of entity activities 
Administrative service misuse  Registered office used to create presence without substantive operations  Assess economic substance; verify business activities; monitor financial flows 
Client account structuring  Client accounts used to move funds between entities or jurisdictions with reduced transparency  Understand purpose of client account use; monitor for structuring patterns 

All 21 MoET Case Studies: Grouped, Interpreted, and Rated

Customer Behaviour: Individual Clients

  • The guidance contains 21 case studies covering the full spectrum of TCSP risk scenarios
  • Most involve a pattern of individually reasonable changes that become suspicious in aggregate
  • Supervisory expectations consistently focus on holistic assessment, not transaction-by-transaction review
  • Several case studies test the MLRO’s obligation to escalate even where each step appears procedurally compliant
  • Our ratings reflect the complexity of detection, not the severity of the underlying risk

The 21 case studies in the MoET Supplemental Guidance are one of its most valuable features. They show you exactly how MoET expects TCSPs to apply professional judgement in real scenarios. Here we group them by typology, add an AML UAE interpretation, and rate each one by detection difficulty.

How to Read Our Case Study Ratings

Detection Difficulty: Low = clear red flags from the outset | Medium = patterns emerge over time | High = individually reasonable, suspicious only in aggregate

The ratings reflect how challenging detection is in practice, not the severity of the underlying risk. These scenarios should prompt risk reassessment and appropriate escalation. Depending on the facts, the response may include enhanced due diligence, enhanced monitoring, MLRO review, refusal or exit, and, where suspicion is formed, an STR or SAR filing.

Group A: Beneficial Ownership Opacity Through Structural Complexity

Case Study  Core Scenario  AML UAE Interpretation  Detection Difficulty 
CS1: Layered Corporate Structure with Frequent Ownership Changes  UAE holding company with offshore shareholders undergoes repeated incremental ownership changes over nine months, each framed as capital restructuring  The nine-month horizon is the point. No single change triggers suspicion. The obligation is to assess the pattern. Most TCSPs process change requests individually and never see the aggregate picture. You need a relationship-level view of structural changes over time.  Medium 
CS6: Gradual Obscuring Through Corporate Restructuring  Long-standing client repeatedly amends company structure, ownership progressively diluted across multiple jurisdictions, each change individually documented  This is the boiling-frog scenario. Each change comes with documentation. Each change has an explanation. But commercial activity does not grow in proportion to structural complexity. The mismatch between operational reality and structural elaboration is the signal.  High 
CS13: Parallel Structures with Similar Ownership Patterns  Multiple companies under different client names share identical nominee arrangements, overlapping addresses, and similar governance frameworks  This requires cross-client visibility that most TCSPs do not build into their monitoring systems. The guidance expects you to identify patterns across your portfolio, not just within individual relationships.  High 
CS19: Client Seeking Limited Transparency in Corporate Records  Client repeatedly asks to minimise ownership information in corporate records and questions documentation requirements  The client’s consistent focus on reducing transparency, even where the structure remains technically legal, is the red flag. Legitimate clients generally accept documentation requirements. Clients who resist them repeatedly warrant enhanced scrutiny.  Medium 

Group B: Nominee and Intermediary Abuse

Case Study Core Scenario AML UAE Interpretation Detection Difficulty 
CS2: Nominee Director with Operational Disconnect TCSP provides nominee director for a company engaged in high-value consultancy; financial control rests with informal parties not in the corporate structure The nominee director arrangement is legitimate on paper. The red flag is the disconnect between formal governance and actual control. Where instructions consistently come from parties outside the corporate structure, the TCSP must investigate the actual control arrangement and escalate to the MLRO. Medium 
CS7: Use of Professional Intermediaries to Distance Control Foreign client routes all communications through a legal advisor who acts for multiple entities with near-identical structures, all linked to different clients The use of a well-documented professional intermediary is precisely the kind of scenario where TCSPs lower their guard. But the guidance expects independent verification of beneficial ownership and purpose, regardless of how credible the intermediary appears. Pattern recognition across multiple engagements is key here. High 
CS9: Repeated Nominee Arrangements Across Unrelated Entities CSP provides nominee director services to multiple companies with similar ownership patterns, later finding the same individuals indirectly linked across structures This demands portfolio-level analysis. Individual onboarding files look clean. The risk only becomes visible when you map connections across your client base. The guidance explicitly expects this cross-client analysis. High 
CS21: Unusual Reliance on Powers of Attorney for Corporate Control Company formally owned and managed by identifiable individuals; operational control exercised via powers of attorney to third parties not in the ownership structure Powers of attorney used as the primary mechanism for operational control are a significant red flag. The guidance requires TCSPs to identify who actually exercises control, not just who appears on the corporate register. Medium 

Group C: Shell Entity and Economic Substance Issues

Case Study Core Scenario AML UAE Interpretation Detection Difficulty 
CS4: Misuse of Registered Office and Administrative Services (Portfolio) TCSP provides registered office to multiple entities with overlapping management, all engaging in cross-border consultancy, licensing, and procurement flows This tests the portfolio-level risk assessment requirement. Individually, each entity may look acceptable. The shared characteristics, the overlapping management, and the transaction patterns across the portfolio are what warrant investigation. Medium 
CS8: Inconsistent Business Activity vs Declared Purpose Company incorporated for general trading shows no identifiable trading activity but repeatedly amends its licensed activities to unrelated sectors The mismatch between declared purpose and actual activity is the clearest red flag in this group. Periodic reviews should include a check on whether the entity has actually conducted the business it claims to conduct. Low 
CS15: Shelf Company for Perceived Credibility Client acquires older shelf company to present as an established business to counterparties, then remains operationally inactive This is a misrepresentation risk as much as an ML risk. The TCSP is being used to facilitate a false impression of legitimacy. The guidance requires the compliance officer to assess the intended use and whether the structure creates a misleading impression. Low 
CS18: Registered Office Without Genuine Presence Client uses registered office without any physical presence or operations, periodically requesting official letters confirming UAE presence for use with overseas counterparties The combination of no operational substance and repeated requests for presence confirmation letters is the key pattern here. TCSPs providing administrative services must assess whether their services are being used to manufacture a perceived footprint. Low 

Group D: Cross-Border Complexity and Financial Flows

Case Study  Core Scenario  AML UAE Interpretation  Detection Difficulty 
CS3: Cross-Border Structuring with Circular Investment Flows  UAE holding company with multi-jurisdictional subsidiaries executes intercompany loans, equity injections, and service agreements that circulate the same pool of funds  Circular fund flows are the defining characteristic of layering. The internal agreements may be formally documented, but economic substance is absent. TCSPs need to assess the economic purpose of transactions, not just their procedural compliance.  Medium 
CS5: Misuse of Registered Office and Administrative Services  Low-risk general trading client over time introduces offshore ownership, new counterparties, and complex payment arrangements explained as tax efficiency measures  This is the long-term relationship risk. TCSPs often apply less scrutiny to clients they have known for years. The guidance is clear: initial risk assessments do not hold indefinitely. Cumulative changes must trigger reassessment.  High 
CS12: High-Risk Jurisdiction Entity Post Incorporation  UAE company with local shareholders later introduces a foreign corporate shareholder from a limited-transparency jurisdiction, framed as strategic investment, with no commercial follow-through  The post-incorporation introduction of a high-risk jurisdiction entity without any corresponding commercial activity is a classic escalation trigger. The risk rating of the entire relationship must be reassessed, not just the new shareholder.  Low 
CS16: Multi-Jurisdictional Structure with Unclear Decision-Making Authority  UAE company administered by TCSP receives instructions from multiple individuals in different jurisdictions with no single authority identified; client claims decisions are made collectively at group level  The absence of a clear decision-making authority in a multi-jurisdictional structure is itself a control concern. TCSPs must be able to identify who exercises ultimate control and document it. Vague governance arrangements warrant escalation.  Medium 

Group E: Governance and Process Failures

Case Study  Core Scenario  AML UAE Interpretation  Detection Difficulty 
CS10: Frequent Changes in Authorised Signatories  UAE company undergoes repeated changes in authorised signatories within a short timeframe; each change is procedurally documented but individuals have limited connection to the business  Procedural compliance and risk compliance are different things. Each signatory change passes the formal test. But the pattern of frequent rotation without operational justification suggests an attempt to manage accountability rather than run a business.  Medium 
CS14: Delayed Disclosure of Beneficial Ownership Changes  Client discloses beneficial ownership changes after regulatory deadlines; subsequent review shows changes occurred significantly earlier than declared  Intentional delay in ownership disclosure is the clearest form of transparency failure. The guidance expects TCSPs to enforce timely disclosure requirements actively and to treat repeated delays as an escalation trigger.  Low 
CS17: Frequent Changes in Business Activities Without Clear Direction  Company with consultancy licence repeatedly amends activities to unrelated sectors while showing no commercial development in any of them  Activity amendments without commercial development in any direction indicate the entity is being positioned for a purpose other than its stated one. The TCSP’s compliance officer should assess the cumulative picture.  Low 
CS20: Use of Multiple CSPs for Fragmented Service Provision  Client distributes services across multiple CSPs, each receiving limited visibility; client coordinates between them, providing only partial information to each  This is a deliberate fragmentation strategy designed to prevent any single TCSP from having full visibility. The guidance makes clear that the TCSP’s obligation to understand the full structure does not diminish because other providers are involved.  High 

Group F: Foundation and Trust Misuse

Case Study  Core Scenario  AML UAE Interpretation  Detection Difficulty 
CS11: Foundation Without Clear Purpose  Client requests establishment of a foundation citing wealth preservation, with complex multi-jurisdictional governance but no identifiable assets, activities, or defined purpose  Wealth preservation is a legitimate purpose for a foundation. But the inability to identify any assets, activities, or defined mechanism for that preservation means the stated purpose cannot be verified. The guidance expects TCSPs to decline where clarity is not achieved.  Low 

Do your staff know how to respond to these 21 scenarios in practice?

Understanding what a risk looks like on paper is very different from identifying and escalating it in the middle of a client relationship. Our AML consulting team provides TCSP-specific training and scenario-based assessments.

How TCSPs Should Interpret the NRA's Medium Risk Classification in Practice

Key Points Under This Section

  • The 2024 UAE NRA classifies the TCSP sector as Medium Risk for ML
  • Medium Risk at the national level does not mean Medium Risk at the entity or customer level

The 2024 UAE National Risk Assessment categorises the TCSP sector as Medium Risk for money laundering. This rating has a direct influence on how TCSPs calibrate their internal risk appetite and how they justify the level of resources they allocate to compliance.

The MoET guidance describes a sector characterised by elevated inherent risks from company formation and nominee services, a gatekeeper role that directly influences access to the financial system, consistent identification in national risk assessments as a key vulnerability linked to the misuse of legal persons and arrangements, 21 detailed case studies illustrating complex and hard-to-detect risk patterns, and a red flag framework covering individual behaviour, entity behaviour, transaction behaviour, and additional indicators.

Rather than treating the NRA’s Medium Risk rating as a reason for standardised controls across all TCSP relationships, firms should use it as a sector-level reference point. The guidance makes clear that certain TCSP activities, including nominee arrangements, complex ownership chains, cross-border structuring, and trust or foundation services, may require enhanced scrutiny.

The AML UAE Perspective on the Medium Risk Classification

The Medium Risk classification reflects the NRA’s assessment of the sector as a whole relative to other sectors in the UAE economy. It does not mean that individual TCSPs, client relationships, or transaction types within the sector are medium risk. The guidance itself is explicit that certain activities within the TCSP sector, including nominee arrangements, cross-border structuring, and trust services, carry elevated risk that requires enhanced controls.

The practical implication is this: if your internal risk framework defaults to medium-risk treatment across your TCSP business simply because the NRA says the sector is Medium Risk, you are almost certainly miscalibrating your controls. The guidance expects TCSPs to apply the NRA findings in a nuanced and operationalised way, not as a sector-wide risk floor.

We recommend that TCSPs treat the Medium Risk NRA classification as the baseline for their lowest-risk, highest-transparency clients with no elevated customer, transaction, or geographic risk factors. For every scenario involving nominee arrangements, cross-border elements, or complex ownership structures, the internal risk assessment should reflect elevated risk regardless of the sector-level NRA classification.

Red Flag Indicators from the MoET Supplemental Guidance for TCSPs: A Practical Reference

Key Points Under This Section

  • Red flags are grouped across individual customer behaviour, entity and arrangement behaviour, and transaction behaviour
  • The presence of one red flag does not automatically confirm suspicious activity
  • Multiple concurrent red flags warrant escalation to the MLRO regardless of transaction value
  • The MLRO must assess, document, and determine whether circumstances give rise to suspicion
  • Declining to report because no transaction occurred does not extinguish the reporting obligation

The guidance contains an extensive and well-structured set of red flag indicators. These are not a checklist to be completed at onboarding and filed away. They are a living reference that should inform monitoring, trigger reassessment when observed during the relationship, and feed into the MLRO’s STR and SAR decision-making process. Some of these red flags are as follows:

Individual Customer Behaviour Red Flags

  • Refuses to provide personal, business, or financial information
  • Provides inconsistent or incomplete information across different interactions
  • Avoids personal contact or in-person meetings without justification
  • Does not maintain contact after the initial establishment of a legal entity
  • Refuses to disclose the identity of the beneficial owner, source of wealth, or nature of business dealings
  • Withdraws, becomes unresponsive, or terminates the relationship following EDD requests
  • Applies pressure to expedite incorporation or documentation while discouraging due diligence
  • Is under investigation, has criminal connections, or appears in adverse media
  • Is a PEP or has associations with a PEP inconsistent with their official duties
  • Appears unfamiliar with the details of the transaction they are requesting

Legal Entity and Arrangement Red Flags

  • Cannot demonstrate actual business activity or provide evidence of operations
  • Uses an address linked to multiple unrelated companies
  • Has dormant status that suddenly becomes active without explanation
  • Uses overly complicated ownership or management structures without justification
  • Uses nominee agreements, shelf companies, or offshore trusts to obscure beneficial ownership
  • Requests use of foreign private foundations in secrecy jurisdictions
  • Engages in rapid changes to company ownership, management, or structure shortly after establishment
  • Is registered in a tax haven or jurisdiction with weak AML regulations
  • Has directors or shareholders who are difficult to contact or appear uninvolved
  • Uses the same individuals as directors or shareholders across multiple companies
  • Requests to backdate incorporation documents, share transfers, or directorship appointments

Transaction Behaviour Red Flags

  • Conducts high-value transactions inconsistent with their profile or financial history
  • Uses multiple accounts or funding sources without a clear rationale
  • Requests transactions with excessive secrecy or through anonymous instruments
  • Engages in frequent or high-value intercompany loans with no clear economic purpose
  • Sends or receives funds to and from high-risk jurisdictions without justification
  • Uses cash as collateral for loans from foreign institutions
  • Makes significant capital contributions inconsistent with company size or industry norms
  • Breaks down transactions into smaller parts to avoid reporting requirements
  • Receives payments from unrelated third parties with no apparent connection
  • Prefers unusual payment methods such as virtual assets or precious metals

“In our experience reviewing TCSP compliance programmes, the registered office risk area is consistently underestimated. Firms set up good onboarding processes for company formation clients but apply almost no CDD to entities that only use their address. The guidance is clear: even if your only service to an entity is providing its registered address, you still have minimum CDD obligations. And if you have fifty entities at the same address with overlapping management and no discernible business activity, that portfolio-level pattern is itself a red flag that requires investigation at the group level, not just entity by entity.”

Dipali Vora - Partner, NIYEAHMA Consultants LLP

Common Challenges in the IAA Sector: What the SRA Found

TCSP Compliance Gap Scorecard: Where Does Your Firm Stand?

  • Use this scorecard to identify gaps between your current controls and the MoET Supplemental Guidance for TCSPs expectations
  • Score each item honestly: Yes (2 points), Partial (1 point), No (0 points)
  • A score below 70% indicates significant remediation priorities
  • Share this assessment with your MLRO and senior management

The following scorecard is an AML UAE practical self-assessment tool derived from the guidance. It is not an MoET scoring methodology and does not represent an official supervisory assessment framework.

Rate each item: Yes (2 points) | Partial (1 point) | No (0 points). Total possible score: 60 points.

Control Area Assessment Question Your Score (0/1/2) 
Risk Framework Is your Business Risk Assessment aligned with the UAE NRA and the TCSP Sectoral Risk Assessment, and updated at least annually?  
Risk Framework Does your risk assessment specifically address the five sector-specific risk areas in the MoET Supplemental Guidance for TCSPs?  
Policies and Procedures Do your policies cover all seven core obligations including sanctions compliance and reporting?  
Policies and Procedures Were your policies updated following the UAE Federal Decree-Law No. 10 of 2025 and its implementing regulation under Cabinet Resolution No. 134 of 2025?   
Customer Due Diligence Does your CDD process go beyond identity verification to assess purpose, structure, and economic rationale?  
Customer Due Diligence Do you have a documented source of wealth process for higher-risk customers, distinct from source of funds?  
Beneficial Ownership Can you demonstrate that beneficial ownership has been identified and verified across all layers, not just the first?  
Beneficial Ownership Do you independently corroborate beneficial ownership information using sources beyond the customer’s own declarations?  
Nominee Services Do you have a specific policy and enhanced oversight process for nominee director and shareholder arrangements?  
Ongoing Monitoring Does your monitoring framework include trigger-based reassessments, not just annual reviews?  
Ongoing Monitoring Do you have a process to identify and escalate the trigger events listed in the guidance?  
STR and SAR Reporting Does your internal escalation process ensure that suspicions reach the MLRO without delay?  
MLRO and Governance Does your MLRO have the time, authority, and access to actively review high-risk relationships?  
Record Keeping Can your records allow a competent authority to reconstruct the rationale for every risk decision without oral explanation?  
Cross-Border Structures Do you apply a higher standard of scrutiny and enhanced internal review to cross-border and multi-jurisdictional structures?  
Staff Training Have your frontline staff been trained on the TCSP-specific risk scenarios and red flags in this guidance?  
Registered Office Do you apply CDD requirements to entities using your registered office address even if they use no other services?  
Portfolio Monitoring Do you have a process to identify risk patterns across your client portfolio, not just within individual relationships?  
Sanctions Compliance Do you screen all beneficial owners and related parties, not just primary customers, against sanctions lists?  
Cross-Client Analysis Do you have a process to identify when the same individuals appear across multiple client structures?  

Interpreting Your Score

50 to 60 points (83% to 100%): Your framework is broadly aligned with the guidance. Focus on documentation quality and continuous improvement.

35 to 49 points (58% to 82%): Material gaps exist. Prioritise beneficial ownership, ongoing monitoring, and governance.

Below 35 points (under 58%): Significant remediation required. Consider an external AML health check before your next supervisory engagement.

Scored below 70% on the compliance gap scorecard?

Do not wait for a supervisory inspection to surface the gaps. Our team at AML UAE provides targeted remediation support for UAE TCSPs across all compliance dimensions covered by this guidance.

TCSP Compliance Obligations Timeline: What Triggers What

Key Points Under This Section

  • Compliance obligations in the TCSP sector are event-driven as well as time-driven
  • Formation or onboarding triggers the full CDD cycle before the relationship commences
  • Ongoing triggers include structural changes, ownership changes, and behavioural shifts
  • Suspicious activity triggers an STR or SAR obligation regardless of transaction value or completion
  • Periodic reviews serve as a backstop but do not replace trigger-based monitoring

The guidance does not present TCSP compliance obligations in a linear way. In practice, obligations are activated by specific events across the lifecycle of a client relationship.

Frequently Asked Questions About the MoET Supplemental Guidance for TCSPs

Is this guidance legally binding on UAE TCSPs?

The guidance itself clarifies that it does not constitute additional legislation or regulation. However, it sets out how MoET will assess compliance with Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025, which are legally binding. In a supervisory inspection, failure to meet the standards set out in the guidance will likely be treated as evidence of non-compliance with those binding instruments. Treat the guidance as an important supervisory reference for demonstrating compliance with the binding AML/CFT/CPF framework.

Yes. The guidance explicitly states that providing a registered office, work address, correspondence address, or administrative address for a legal person or legal arrangement is one of the five activities that trigger TCSP obligations under the UAE AML/CFT framework. You are required to apply minimum CDD requirements to all entities using your address, even if you have no other relationship with them.

It means identifying the natural person who ultimately owns or controls the legal structure, whether directly or through a chain of companies, trusts, or other arrangements. You cannot stop at the first company layer and record that company as the beneficial owner. You must follow the ownership chain until you reach a natural person. For complex multi-jurisdictional structures, this may require reviewing corporate registries in multiple jurisdictions, obtaining certified documentation, and using third-party intelligence tools.

An STR (Suspicious Transaction Report) is filed where a specific transaction is the basis of suspicion. A SAR (Suspicious Activity Report) is filed where the suspicion arises from activity, behaviour, or circumstances rather than a specific transaction. Both apply to TCSPs. The guidance explicitly notes that suspicion may arise from the formation, administration, or restructuring of legal persons, from customer behaviour, from inconsistencies in information, or from the absence of a clear economic rationale. None of these requires a specific transaction to have occurred.

The guidance is cautious on this point. While reliance on third-party CDD is permitted under the UAE framework in certain circumstances, the TCSP retains ultimate responsibility for the adequacy of the information obtained. Where an intermediary is used, the TCSP must ensure it can independently verify the accuracy and completeness of the information, particularly for beneficial ownership. The guidance specifically flags heavy reliance on intermediaries without direct engagement with the beneficial owner as a red flag in Case Study 7.

No. The guidance states that TCSPs must integrate NRA findings into their internal risk assessment frameworks. The Medium Risk classification is a sector-level average, not a floor for individual customer or transaction risk. The guidance explicitly expects TCSPs to apply enhanced scrutiny to nominee arrangements, cross-border structures, and complex ownership chains regardless of the sector-level NRA rating. Your internal risk appetite must reflect the actual risk of each client relationship and each service type, not a sector average.

TCSPs are strictly prohibited from disclosing to a customer or any third party that an STR or SAR has been filed, that one is intended to be filed, or that an investigation is underway. This prohibition extends to any information that could reasonably lead the customer to become aware of such reporting. Importantly, the guidance clarifies that taking steps to delay a transaction, decline a service, or request additional information for legitimate compliance purposes does not constitute tipping-off, provided these actions are conducted without revealing the existence of a report or suspicion.

The guidance requires the Business Risk Assessment to be documented, regularly updated, and aligned with national and sectoral risk findings, including the NRA and relevant Sectoral Risk Assessments. It does not specify a fixed frequency. In practice, an annual review is a prudent minimum, with earlier updates triggered by changes in the NRA, SRA, supervisory guidance, business model, client base, or emerging typologies.

Not on its own. The guidance requires TCSPs to clearly document the legal and contractual relationship between the nominee and the beneficial owner, understand the scope and limitations of the nominee’s authority, and maintain ongoing awareness of how the entity is being used. A standard form agreement may cover the contractual dimension, but it does not satisfy the ongoing monitoring, beneficial ownership verification, and governance oversight requirements. Nominee services require enhanced procedures, not just standard documentation.

The guidance is clear: where material uncertainties remain unresolved, the TCSP should decline to establish the relationship or exit an existing one, and should consider whether the circumstances warrant internal escalation or external reporting. A client’s withdrawal, unresponsiveness, or termination of the relationship following EDD requests is itself listed as a red flag indicator. Document everything. Escalate to the MLRO. If the circumstances meet the reporting threshold, file an STR or SAR with the FIU.

Conclusion: From Guidance to Action

The MoET Supplemental Guidance for Trust and Company Service Providers is one of the most detailed sector-specific AML/CFT/CPF documents the UAE has produced. As AML UAE’s analysis demonstrates, it reflects a regulatory environment that has moved decisively beyond tick-box compliance and toward genuine, evidence-based supervision.

The message running through every section is consistent: the quality of your professional judgement matters as much as the completeness of your documentation. Supervisors will assess whether your controls work in practice, not just whether they exist on paper.

For TCSP operators, the practical priorities are clear. Revisit your scope and ensure you have correctly identified all the activities that trigger your obligations. Stress-test your beneficial ownership processes against complex, multi-layered structures. Build trigger-based monitoring into your operational workflows. Invest in your MLRO’s capacity to do the role properly. And use the 21 case studies in the guidance as a training resource for your frontline teams.

If the compliance gap scorecard in this article surfaced significant gaps, the time to address them is now, before a supervisory engagement does it for you.

AML UAE: Your Specialist Partner for TCSP Compliance in the UAE

Our team of qualified AML professionals, led by CAMS-certified consultants with deep UAE DNFBP experience, helps TCSPs build, test, and remediate their AML/CFT/CPF compliance frameworks. From Business Risk Assessments to MLRO support to staff training, we cover the full spectrum of TCSP compliance needs.

Share via :

About the Author

Pathik Shah

FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)

Pathik is an ACAMS-certified AML consultant specialising in governance, risk, and compliance for regulated entities in the UAE. He brings over 28 years of experience, with 1,000+ hours of AML training and 200+ advisory engagements across DNFBPs, VASPs, and FIs. He supports businesses in aligning with AML/CFT requirements from the CBUAE, DFSA, MoET, MoJ, VARA, CMA, FSRA, and FATF. Known for translating complex regulations into audit-ready procedures, Pathik enables operational clarity and compliance readiness.

Reach Out to Pathik