What should the MLRO report contain?

Blogs

Published On: 03/03/2022

Table of Contents

Protect your business with reliable and effective AML strategies with AML UAE.

Last Reviewed On: 07/20/2026   |   Last Updated On: 07/20/2026

Business People Meeting Design Ideas professional investor working new start up project. Concept. business planning in office.

What should the MLRO report contain?

The AML compliance officer plays a pivotal role in assisting businesses in being AML compliant. The Money Laundering Reporting Officer (MLRO) has to submit MLRO report semi-annually and is a crucial element in the AML compliance process, ensuring that the companies adhere to the Anti-Money Laundering and Combatting Financing of Terrorism (AML-CFT) requirements. The MLRO report facilitates the desk-based supervision of companies understanding their AML compliance structure and knowing whether they are continuously complying with the AML laws

Mandatory submission of the MLRO report

Cabinet Resolution No. 134 of 2025 states that the MLRO reports should be submitted twice a year to the senior management. A copy of the MLRO report is sent to the concerned supervisory authority. The officer will review all the internal policies and procedures to ensure adherence to the AML rules and regulations. The officer evaluates the efficiency of the companies in AML compliance and the extent to which they are following the procedures. The MLRO also guides the companies to sync with the AML policies and strengthen the AML compliance program.

Contents of the MLRO's Report

The compliance officer should highlight the glaring gap between the current and existing AML laws compliance requirements. The report should focus on the required remedial measures that the company must follow to be AML compliant.

Essential Elements in the MLRO report

Review of the size and the quality of the Suspicious Activity Reports (SAR) submitted by the employees and the number of SARs submitted. The MLRO report should mention the number of clients rejected due to the absence or insufficient information.

The existing AML –CFT training components- the number of courses and the AML training imparted to the employees and any issues concerning the AML training. The evidence of the training imparted and the company’s competence in adhering to the AML/ CFT laws should be part of the MLRO report

  • The report should also mention if the company needs any resources to stay AML/ CFT compliant. 
  • Mention the sample review of the Customer Due Diligence (CDD) file ensuring the information is updated and holds relevance. 
  • Verify the risk ratings and relevance and updation of the risk assessment report.
  • Evaluating the company’s relevance of the AML compliance process- AML/ CFT policies, procedures, and documentation.

Controls to be Highlighted in the MLRO Report

The MLRO will check the following compliances.

Key focus areas in the MLRO's report

The MLRO report should focus on the AML/ CFT process compliance. The report should confirm that the company has utilized and applied the general risk assessment results. The report should include the corrective measures that correspond to the inadequacies of the existing AML/ CFT compliance program.

 

The recommendations should guide the company to improve the AML/ CFT compliance program and help them achieve 100% AML compliance. A deadline has to be provided, and the AML compliance recommendations, as mentioned in the MLRO report, should be followed. The companies should be monitored as to whether they follow the rules and adhere to the deadline. 

Submission of the MLRO Report

Banks, insurance companies, etc., must submit the MLRO report to the Central Bank of UAE (CBUAE). The DNFBPs – Designated Non-Financial Businesses and Professions (DNFBPs must submit the MLRO report to the Ministry of Economy (MoE). 

Regulated entities that have mandatory compliance with the AML/ CT laws need to follow the AML compliance process diligently. Appointment of an MLRO and submission of report is compulsory. The MLRO report should let the authorities know the shortcomings of the AML/ CFT program of the company. It should also highlight the inefficiency in the AML training, which makes the AML compliance program weak and ineffective.

Businesses should hire an AML consultant with their core expertise in AML services. The consultant will provide the correct guidance in preparing robust AML training for your employees, help in selecting the right AML software, and assist in the appointment of an MLRO.

Conclusion

AML UAE has a vast team of professionals with core expertise in In-house AML compliance and allied services. Get access to various services such as AML/ CFT Policy Controls and Procedures Documentation, in-house AML compliance department set up, AML software selection, Annual AML/ CFT Risk Assessment Report. It also provides AML training services and AML/ CFT Health checks. Mitigate risks and stay AML compliant by following the process carefully. 

FAQs - Essential Elements in the MLRO report

What is the role of the MLRO? 

The responsibilities of MLRO are: 

  • Ensure compliance of daily operations with the company’s AML policies 
  • Be the point of communication between the company and its employees as well as the company and federal authority 
  • Make suspicious transaction reports 
  • Acting in compliance with UAE’s guidelines, notifications, rules, and regulations 
  • Respond if the concerned authority requests any document  

MLRO means Money Laundering Reporting Officer in AML.  

The MLRO must submit the MLRO report to the senior management of the company. They must forward a copy to the Central Bank of UAE (CBUAE) in the case of financial institutions and the Ministry of Economy (MOE) in the case of DNFBPs. 

Add a comment

Share via :

About the Author

Pathik Shah

FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)

Pathik is an ACAMS-certified AML consultant specialising in governance, risk, and compliance for regulated entities in the UAE. He brings over 28 years of experience, with 1,000+ hours of AML training and 200+ advisory engagements across DNFBPs, VASPs, and FIs. He supports businesses in aligning with AML/CFT requirements from the CBUAE, DFSA, MoET, MoJ, VARA, CMA, FSRA, and FATF. Known for translating complex regulations into audit-ready procedures, Pathik enables operational clarity and compliance readiness.

Reach Out to Pathik

A comprehensive AML Guide for ADGM companies 

A comprehensive AML Guide for ADGM companies 

Blogs

Published On: 04/19/2023

Table of Contents

Protect your business with reliable and effective AML strategies with AML UAE.

Last Reviewed On: 07/20/2026   |   Last Updated On: 07/20/2026

A comprehensive AML Guide for ADGM companies 

The Financial Services Regulatory Authority (FSRA) supervises Abu Dhabi Global Market (ADGM) entities. 

FSRA has issued rules and guidelines for implementing AML and Sanctions by ADGM entities to mitigate financial crimes. Though the ADGM’s AML Rulebook considers the Federal AML rules, the regulated entities in ADGM must follow the Rulebook and the Federal AML Law requirements 

This article focuses on the critical AML compliance requirements of entities in ADGM.  

Business Risk Assessment and AML Policies, Procedures and Controls

The FSRA-issued AML rulebook mandates the ADGM entities to assess the ML/FT risks their business is exposed to.  

While conducting AML business risk assessment, the ADGM entities must identify and analyze the ML/FT risk associated with the below-mentioned risks parameters: 

  • Customers  
  • Products, services, and transactions  
  • Geographic risk  
  • Distribution channels 
  • Other risk factors such as technology 
How to conduct AML Business Risk Assessment Priv

Basis the results of the AML Business Risk Assessment, adopting the risk-based approach, the entities must establish AML controls, procedures, policies, and systems aligned with the AML regulations to help entities identify, manage, and mitigate the ML/FT risks.  

To ensure the effectiveness of the ML/FT mitigation measures, it is important to review ML/FT risk factors impacting the business and update the assessment to identify any new risk scenarios and design relevant controls to manage the increased level of risks.  

Customer Risk Assessment and Customer Due Diligence

The entities must assess the customers’ profile, transactions, and business relationships to identify the ML/FT risk such customers pose to the business. Considering various risk parameters, a risk rating should be assigned to the customer, and appropriate Customer Due Diligence measures should be applied before establishing a business relationship. 

For performing Customer Risk Assessment, the entities must consider various factors associated with the customer, a few of them illustrated hereunder: 

  • Ownership, control structure, and nature of customer 
  • Nature of the customer’s business 
  • Nature and purpose of the business relationship  
  • Nationality and residence of the customer 
  • Place of incorporation of the customer who is a legal person. 
Key factors for Customer Risk Assessment under AML regulations

Based on these factors, the risk rating is allocated to each customer – high, medium, or low. For low-risk customers, entities may conduct Simplified or Standard Due Diligence. While for customers identified as high-risk, Enhanced Due Diligence measures must be applied.  

Enhanced Due Diligence measures under UAE AML Regulations

Depending on the risk profiling or risk classification of the customer, the ADGM entities must carry out Customer Due Diligence under the following circumstances: 

  • Before onboarding a customer or establishing a business relationship 
  • Before executing a transaction with an occasional customer for an amount equal to or more than US$15,000 
  • When the customer or transaction is suspected to be related to money laundering or financing of terrorism. 
  • When there is doubt about the authenticity of documents provided by the customers 

As part of the Customer Due Diligence process, the ADGM entities must undertake the following: 

  • Identify the customers, their representatives, and beneficial owners and verify their identities, 
  • Screen the customer, beneficial owners, and senior managerial persons to check if any of these persons are sanctioned under the UAE local list, UNSC Consolidated List or any other relevant international sanctions list, 
Sanctions Screening - Actionable and Reporting under AML UAE
  • Understand the nature and purpose of the business relationship, 
  • Have systems and controls in place to determine whether the customer, beneficial owners, or senior managerial person is a Politically Exposed Person (PEP), 
  • Conduct ongoing monitoring of the business relationships and transactions conducted with the customer to check their consistency with the customer’s business and risk rating 
PEP and PEP Screening under UAE AML Regulations pre

However, when a customer is assigned a high-risk rating, Enhanced Due Diligence (EDD) measures must be applied before establishing a business relationship or executing a transaction with such a customer. Here, the EDD measures would include the following: 

  • Get more information to identify the customer and its beneficial owners,  
  • Identify and verify the source of wealth and funds of the customer and its beneficial owners, 
  • Establishing reasonableness of the purpose of the business relationship, 
  • Seek senior management’s approval to start a business relationship with a high-risk customer, 
  • Insist on getting the first payment through the customer’s account with the bank subject to similar AML standards,  
  • More frequent monitoring of the customer’s profile and transactions. 
A comprehensive AML Guide for ADGM companies 

Money Laundering Reporting Officer (MLRO)

Every ADGM entity must appoint an MLRO to ensure compliance with AML requirements as prescribed under the FSRA-issued AML Rulebook and the AML Federal laws. Such MLROs must be residents of the UAE. 

Further, the FSRA must approve the appointment of the MLRO. 

If an MLRO leaves the company immediately, a new MLRO must be appointed, or at least a Deputy MLRO must be appointed to manage the AML compliance function temporarily until the appointment of an MLRO. FSRA Rulebook allows the ADGM entities to outsource the MLRO position to a third party.  

AML Training and Awareness 

FSRA mandates entities to conduct regular training for its employees responsible for AML compliance. Such training and AML awareness sessions must customize be customized basis the entities’ business operations, products/services, transaction complexities, distribution channels, and customers.  

ADGM entities must conduct such AML training at least once a year and keep it up-to-date. Further, it is mandatory to record details of such training programs, including their dates, duration, nature, and list of participants.  

Designing a comprehensive AML Training Program

Reporting Suspicious Activities  

Every ADGM entity must have procedures, controls, policies, and systems to detect suspicious activities and report them immediately to the Financial Intelligence Unit (FIU) by filing SAR/STR on the goAML portal 

Frontline employees observing the suspicion must report it to the entity’s MLRO and submit all the details about the activity, customer or transaction involving money laundering or terrorist financing activity. When the MLRO receives an internal STR/SAR from an employee, they must investigate the activity. MLRO must submit an external STR/SAR with the FIU based on the evidence collected. 

ADGM entities must maintain a list of ML/FT risk indicators and keep reviewing and updating this list to identify and mitigate the risks effectively. 

AML Record Keeping  

ADGM entities must maintain AML-related records for a minimum period of six (6) years in electronic format. The records to be maintained include the following: 

  • Entities’ AML Business Risk Assessment and the AML framework implemented 
  • Documents and information received from customers during KYC and CDD 
  • Copies of business correspondence with customers, including transactional details 
  • Suspicious activity/transactions reports – internal and external, related investigation records, documents, etc. 
  • Records of communication and correspondence with the FIU 
AML Record Keeping

AML Annual Return

ADGM entities must fill in all the details in the AML Return Form and submit such AML Annual Return with the FSRA for the year starting from 1st January to 31st December every year. Such AML Annual Return is to be furnished with the authorities before the end of April of the following year. 

The key differences between Federal AML Law and the FSRA-issued ADGM AML Rules and Guidance

(a) FSRA AML Rulebook includes the following under the definition of the “Designated Non-Financial Businesses and Professions (DNFBPs), which is not the case under Federal AML Laws:  

  • Dealer engaged in trading of any saleable item where the transaction amount equals to or exceeds US$ 15,000 in cash through a single transaction or series of connected transactions.
  • Tax Consulting Firm

(b) FSRA-regulated entities must appoint a Compliance Officer or Money Laundering Reporting Officer who is a resident of the UAE. No such specific condition around residency is mentioned in the Federal AML Law.  

(c) The minimum period prescribed for maintaining the AML record is six (6) years for ADGM entities, as compared to five (5) years prescribed under the Federal AML Laws.  

(d) AML Annual Return is to be filed by the ADGM entities every year for the period 1st January to 31st December by the end of April of the following year. The AML Annual Return requirement is in addition to the semi-annual report requirement mentioned under Cabinet Resolution No. 134 of 2025.

Need expert assistance to comply with ADGM’s AML Rulebook? 

The companies in ADGM must follow all these requirements as per the ADGM AML Rulebook. Any non-compliance with these requirements calls for heavy administrative fines. The best way to avoid these fines and penalties is to take the help of a professional AML consultant.  

AML UAE is a leading AML consultant in the UAE. Our comprehensive services help you comply with the relevant AML/CFT requirements and mitigate the threats of money laundering and terrorism financing. 

We understand Federal AML laws and ADGM-specific rules to help clients identify and assess their business risk and develop solid and comprehensive AML/CFT policies, procedures, and controls. We can help you set up your in-house AML compliance department and impart AML training to your team, to manage ML/FT compliance competently. 

Our strength lies in our solid team of ADGM compliance specialists and experienced and knowledgeable AML professionals. So, leave your AML compliance worries to us, and focus on your core business operations.  

Avail comprehensive, expert, and efficient services for AML compliance matters

Contact our team at AML UAE.

Share via :

About the Author

Dipali Vora

CAMS, ACS

Dipali is an Associate member of ICSI and a Certified Anti-Money Laundering Specialist (CAMS). She has an overall experience of 8 years in the compliance domain, including Anti-Money Laundering, due diligence, secretarial audit, and managing scrutiniser functions. She currently assists clients by advising and helping them navigate through all the legal and regulatory challenges of Anti-Money Laundering Law. She helps companies to develop, implement, and maintain effective AML/CFT and sanctions programs.

Reach Out to Dipali

TFS Implementation Criteria: Ownership, Control, and Acting on behalf of a Designated Person

TFS Implementation Criteria Ownership, Control, and Acting on behalf of a Designated Person

Blogs

Published On: 02/27/2023

Table of Contents

Protect your business with reliable and effective AML strategies with AML UAE.

Last Reviewed On: 07/20/2026   |   Last Updated On: 07/20/2026

TFS Implementation Criteria

Targeted Financial Sanctions are restrictions imposed on Designated Persons from the financing of terrorism and proliferation perspective, mandating the business organizations not to make any funds or assets available to such Designated Persons.

Targeted Financial Sanctions Legal Framework in UAE:

Article 19(e) of Federal Decree Law 10 of 2025 requires the prompt application of the directives issued by the UAE’s executive officer or other competent authorities for implementing the decisions of the UN Security Council under Chapter (7) of UN Convention for the Prevention and Suppression of the Financing of Terrorism and Proliferation of Weapons of Mass Destruction, and other related directives.

UAE Cabinet Decision No. 74 of 2020 establishes the framework regarding Targeted Financial Sanctions (TFS), including the Local Terrorist List and the UN Consolidated List and the procedures to implement TFS.

Any non-compliance with the obligations of Cabinet Decision No. 74 of 2020 or failure to implement procedures to ensure compliance may result in imprisonment for a minimum period of 1 year, up to 7 years, and/or a fine ranging between AED 50,000 and AED 5,000,000. Further, the Supervisory Authorities may impose any other appropriate administrative sanctions, such as issuing a warning letter or canceling the business license for any violation or shortcoming in implementing TFS obligations.

TFS Implementation Criteria 1: Ownership or Majority Interest

While implementing TFS with respect to designated individuals and entities listed on the UAE Local Terrorist List issued by the UAE Cabinet (in line with UNSC 1373) and on the UNSC Consolidated List issued by the United Nations Security Council, it is essential to take into account the following criteria viz., ownership, control and acting on behalf of a Designated Person.

TFS must be implemented on a legal entity if a Designated Person (natural or legal) owns the entity. Suppose the designated individual or entity owns more than 50% of the proprietary rights or has a controlling interest in the entity. In that case, such an entity is considered owned by the Designated Person and is subject to a freezing mechanism.

TFS Implementation Criteria

Since the Designated Individual/Entity owns more than 51% of the non-designated Company A, the funds or other assets of Company A must be frozen immediately.

Since Entity 1 and Person 1 own 24% and 25% shares of Company A, they will not be treated as designated persons, and the freezing mechanism will not be applied to them.

If the Designated Person holds 50% or less of the proprietary rights of a non-designated entity, such an entity is not subjected to the freezing mechanism.

Any funds or other assets due to the designated person’s 31% ownership of proprietary rights in Company A must be subject to a freezing mechanism.

The reporting entities must remain vigilant on the changes in the ownership structures of non-designated entities where the designated person holds 50% or less of the proprietary rights.

TFS implementation Criteria 2: Control

Suppose the Designated Person has control over the non-designated entity despite having a minority interest in such entity. In that case, Financial Institutions (FIs), Virtual Asset Service Providers (VASPs), and Designated Non-Financial Businesses and Professions (DNFBPs) are required to apply freezing measures.

To determine whether the designated person exerts control over the non-designated entity, the following criteria need to be taken into account:

  1. Check if the Designated Person has the right to appoint or remove a majority of the members of the legal entity’s management,
  2. Check if the Designated Person is appointed solely as a result of the exercise of his voting rights as a majority of the members of the management body of a legal person who has held office during the present and previous financial year,
  3. Check if the Designated Person is, alone, controlling the majority of shareholders’ or members’ voting rights in the legal person, pursuant to an agreement with other shareholders in or members of a legal person,
  4. Check if the Designated Person has the right to exercise a dominant influence over a legal person, pursuant to an agreement entered into with that legal person or to a provision in its Memorandum or Articles of Association, where the law governing that legal person permits its being subject to such agreement or provision,
  5. Check if the Designated Person has the power to exert the right to exercise a dominant influence referred to in point (d) without being the holder of that right,
  6. Check if the Designated Person has the right to use all or part of the assets of that legal person, e.g., managing the business of that legal person on a unified basis while publishing consolidated accounts,
  7. Check if the Designated Person shares jointly and severally the financial liabilities of a legal person or guarantees them,
  8. Check if the Designated Person has a power of attorney or authorized signatory arrangement over a legal person.

In the above scenario, despite holding the minority interest in the non-designated Company A, the freezing measures must be applied without delay as the Designated Individual/Entity exerts control over Company A by holding the majority of the voting rights.

TFS implementation Criteria 3: Acting on behalf or at the Direction of the Designated Person

FIs, DNFBPs, and VASPs must apply TFS measures on individuals and entities holding power of attorney or acting as authorized signatories for designated persons.

In the above scenario, the Designated Person exerts control over Company A through a Power of Attorney issued in favor of a Non-Designated Person. Hence the funds and other assets of Company A must be frozen without any delay as it would be treated as being controlled by the Designated Person via Power of Attorney.

About AML UAE

AML UAE is an AML consulting firm assisting FIs, VASPs, and DNFBPs in complying with the AML Laws in UAE. Be it goAML registration, AML/CFT Program design and implementation, AML training, or TFS implementation, AML UAE is your one-stop solution for all your compliance worries. With AML UAE, ensure a robust TFS framework and fight the financing of terrorism and proliferation.

Avail comprehensive, expert, and efficient services
for AML compliance matters

Contact our team at AML UAE.

Share via :

About the Author

Jyoti Maheshwari

CAMS, ACA

Jyoti has over 11 years of hands-on experience in regulatory compliance, policymaking, risk management, technology consultancy, and implementation. She holds vast experience with Anti-Money Laundering rules and regulations and helps companies deploy adequate mitigation measures and comply with legal requirements. Jyoti has been instrumental in optimizing business processes, documenting business requirements, preparing FRD, BRD, and SRS, and implementing IT solutions.

Reach Out to Jyoti

Role of an Auditor Under UAE AML Compliance

Blogs

Published On: 03/15/2022

Table of Contents

Protect your business with reliable and effective AML strategies with AML UAE.

Last Reviewed On: 07/17/2026   |   Last Updated On: 07/17/2026

Auditor or internal revenue service staff, Business women checking annual financial statements of company. Audit Concept.

Role of an Auditor Under UAE AML Compliance

The UAE has implemented anti-money laundering laws and ensures strict compliance to help fight this rampant financial crime. The objective of the AML laws is to get rid of money laundering and prevent large-scale funding of criminal and terrorist financing. Banks, financial institutions, DNFBPs – Designated Non- Financial Businesses & Professions, and other regulated entities must follow the AML rules. The role of an auditor under UAE AML Compliance is massive. The auditors act as guardians who ensure that the organizations adhere to the compliance rules and do not leave any scope of non-compliance.

DNFBPs subject to AML Compliance in the UAE

The AML law was implemented by Cabinet Resolution No. 134 of 2025, Federal Decree-Law No. 10 of 2025. It strengthens the AML compliance network and has strengthened UAE’s AML/CFT legal and institutional framework per the FATF recommendations

The auditors analyse the nature of the business and their obligations in the context of the UAE Anti-Money Laundering Laws. Every business is unique, so they examine the accounts, documents, control policies to identify suspicious transactions and doubtful accounts with great vigilance. 

What is the role of an auditor under UAE AML Compliance?

There are several duties of an auditor that are performed to prevent money laundering, which has serious financial repercussions on the country’s economic structure and the world economy at large. The duties of an auditor can be defined as follows:

  • Examination of annual records and accounts.
  • Analyse the internal control procedures.
  • Identifying any suspicious transaction and taking the appropriate action to prevent money laundering. 
  • Assessment of money laundering risk and evaluating transactions to detect financial terrorism.
  • Compliance- to check whether the institution complies with rules and regulations laid down by the authorities. 
  • Prevent the clients from AML violation risks by evaluating risks on two parameters-
Difference between suspicious activity and suspicious transaction

(a) Assessment of own risk regarding the nature and type of the business.
(b) Obligation of risk assessment when appointed to carry out the auditing duties.

Auditors perform various duties such as conducting the valuation of the assets and liabilities, approving bad debts, etc. They receive compensation for their duties, and they need to consider other risks that involve service risks, customer risks, location risks, etc.

Businessperson refusing bribe given money by partner with anti bribery corruption concept.

Critical factors for consideration include:

  • Nature and the type of business.
  • Nature and volume of the financial transactions. Country’s origin of the interested or associated parties and determine whether they belong to a high-risk country
  • Communication channels with which clients are introduced. 

Auditors provide their valuable opinion on the transactions that might be associated with money laundering. They will provide their expert opinion on the valuation of the assets and liabilities, approval of mergers and acquisitions or approval of writing off bad debts, etc. The auditors review the internal policies, procedures, and controls. They provide their expertise in appointment compliance officers and ensure that the company adheres to rules and regulations and prevents violation of AML laws. They check the background verification system of CDD using different methods based on the business type, nature, and size. 

Carry out the CDD process

Auditors conduct the Customer Diligence process and follow a strict risk assessment process to evaluate the risk of the company’s AML compliance and those of its clients. The auditors use various resources and ensure that the company they associate with has a clean record. They need to be unbiased in their observation and documentation process to have a clear picture of customer due diligence.

Identifying suspicious transactions and reporting the same to the respective authorities.

Auditors need to keep a vigilant eye on the transactions of the clients. If they find any transaction suspicious and have a reasonable ground for doing so, they have to report the case to the Financial Intelligence Unit using the goAML Portal.

How can AML UAE assist you?

AML UAE is one of the most reputed AML consultants serving thousands of businesses in the UAE and offering robust support in AML compliance. Our panel consists of AML compliance consultants with in-depth knowledge of the UAE AML rules and regulations. Get a risk-based approach for annual AML report filing services. We assist DNFBPs in complying with the AML requirements. To obtain further detailed information about this reputed consultant, feel free to visit AML UAE.

FAQs on Role of an Auditor

What are the duties and responsibilities of an auditor? 

The auditor must perform the following duties under AML Law: 

  • Examine and evaluate AML policy, controls, and procedures to ensure compliance with the law. 
  • Make necessary recommendations in relation to AML policy, controls, and procedures. 
  • Check if those recommendations have been taken into consideration by the management and complied with. 

Add a comment

Share via :

About the Author

Pathik Shah

FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)

Pathik is an ACAMS-certified AML consultant specialising in governance, risk, and compliance for regulated entities in the UAE. He brings over 28 years of experience, with 1,000+ hours of AML training and 200+ advisory engagements across DNFBPs, VASPs, and FIs. He supports businesses in aligning with AML/CFT requirements from the CBUAE, DFSA, MoET, MoJ, VARA, CMA, FSRA, and FATF. Known for translating complex regulations into audit-ready procedures, Pathik enables operational clarity and compliance readiness.

Reach Out to Pathik

How can UAE businesses be AML Compliant?

Blogs

Published On: 02/22/2022

Table of Contents

Last Reviewed On: 07/17/2026   |   Last Updated On: 07/17/2026

MicrosoftTeams-image (5)

How can UAE businesses be AML Compliant?

It is obligatory for banks, financial institutions, and other regulated entities to follow the AML rules and regulations or face penalties. UAE has imposed hefty fines for violation of AML rules and regulations. Administrative fines range from AED 10,000 to AED 5,000,000 per violation (Article 17, Federal Decree-Law No. 10 of 2025; schedule Article 39).  By not being AML compliant, businesses put their reputation at stake and face the government’s ire. So, they need to ensure that they diligently follow the AML rules and make their business AML compliant.

The UAE Ministry of Economy has defined 26 categories of fines for non-compliance with the AML rules and regulations. It’s essential to mitigate the risks involved in non-compliance. AML consultants prove to be of great assistance to be AML compliant.  

With the aid of technology, businesses in UAE and worldwide can harness its power and streamline the AML compliance process. The AML software is a great tool to facilitate the AML process.

Designing a comprehensive AML Training Program

AML software plays a crucial role in being AML compliant

Optimizing the AML compliance program is of paramount importance to ensure that it is efficient, cost-effective, and scalable. It is critical to keep pace with the changing AML rules and leave no scope of non-compliance. The risk profile may also change over a period. So the business needs to ensure that their system is updated and equipped with the knowledge of the latest amendments to comply with the AML rules effectively

There are various aspects to look for following the AML rules and regulations. A business has to create a robust AML/ CFT program, provide AML training to its employees, follow the proper procedure for AML policy, rules and documentation. It also includes the selection of the right AML software.

The AML software will help the business incorporate all these elements into the AML compliance program and avoid any risk of non-compliance. The AML software will enable companies to immediately identify suspicious transactions and strengthen the AML compliance strategy.

The software collects and stores customers’ KYC data and verifies it. It also verifies the customers’ risk and screens against a sanction list. It will provide information about PEPs and enable businesses to be sure about whom they’re entering into a business relationship. The software alerts them on any suspicious transaction or account and provides real-time updates to take the necessary action to prevent money laundering. 

Role of AML Consultants

Businesses are occupied with running their businesses efficiently, providing high customer satisfaction, enhanced customer experience, promoting growth, and maximising profitability. Dealing with the complex AML compliance process can take a back seat in a competitive marketplace.

Businesses are at risk of non-compliance, so following the AML/ CFT Policy, Controls, and Documentation procedure is necessary. With the help of reliable AML consultants, companies can get the proper rules, policies, and systems in place and create a strong AML compliance framework that will help them fight money laundering successfully.

Consequences for Non-compliance with UAE AML Regulations

It is an elaborate process that involves risk identification by analysing the business process and identifying the risk which money launderers will take advantage of and be successful in their criminal intentions. Companies can immediately identify the illegal movement of money. The consultants will also examine the existing AML policies, letting the business know if their current AML compliance procedure is competent enough to keep money launderers at bay.

The gap analysis will clarify the appropriate actions that need to be taken to achieve AML compliance for the business.

The gap analysis report is shared with the AML compliance officer and the stakeholders. After the discussion, the consultants create the best AML/ CFT program.

A customized AML program is required to combat the challenges of the non-compliance risk and fight money laundering. The AML policy, controls, and procedures are created, eliminating or minimising the risk of non-compliance, and businesses can focus on improving customer growth. 

Building an effective AML compliance process

The FATF –Financial Task Force has provided several recommendations for AML rules and regulations that define the AML compliance process. The FATF was founded in 1989 to fight money laundering and terrorist financing. It also aims to prevent the funding of accumulation and expanding weapons of mass destruction. FATF has provided some standard recommendations on the global level which countries can follow to fight the menace of money laundering

In 2020 the Minister of Justice had issued ministerial resolutions for setting up specialised courts for dealing with money laundering cases.

AML Compliance Requirements

This resolution was meant for the judiciary in the courts of Sharjah, Umm AI Quwain and Ajman, and Fujairah. It is noteworthy that each country has particular AML compliance requirements that businesses must follow.

It is crucial to have a robust AML compliance program that will meet all the needs and prevent the risk of non-compliance. Organisations can efficiently fulfil the requirements of AML compliance, avoid penalties, guard their reputation by not associating with suspicious activities or entities, and help the government achieve the goal of preventing money laundering.

UAE has issued the Federal Decree-Law No. 10 of 2025 on the Anti-Money Laundering and Countering the Financing of Terrorism which defines the legal structure to ensure AML compliance with the international standards.

The law aims to prevent money-laundering practices and create a legal framework that assists authorities in ensuring AML compliance and arresting the criminals involved in money laundering. The law aims to counter the financing of terrorist activities and suspicious entities

AML Software

Standardising the AML program is necessary. An AML software will help to fulfil this objective. A reliable AML service provider will assist in selecting the proper AML software. 

It is vital to empower the AML compliance team with the right resources and transparent policies to adhere to without any confusion. 

How to get an effective AML compliance program?

The intricacies involved in the AML compliance program might prove overwhelming for businesses already occupied with keeping the company afloat, providing high customer satisfaction. The complex legislation might prove daunting for companies, so it would be best to hire an AML consultant to create an effective AML compliance program.

So how an AML compliance service provider will help in this arena? They will assist in setting up an AML compliance department and help businesses always stay AML compliant with their services. 

As business owners in the UAE, people need to invest time and energy in the research to follow the AML / CFT policy,  rules,  and documentation process or set up an  In-house AML compliance department. It is compulsory for banks, financial institutions, and other regulated entities to integrate an AML compliance framework into the company. It is best to create an in-house AML compliance department.

In addition to this, an AML compliance officer has to be appointed who will manage the AML compliance process. The AML consultants play a huge role in helping businesses be AML compliant. 

Conclusion

AML UAE is one of the most reliable AML compliance in the UAE, providing services to thousands of businesses and helping in AML risk assessment and mitigation. AML compliance is an absolute necessity. Organisations need to follow the AML rules and regulations to protect their business against financial crime and assist the government in preventing money laundering and funding criminal and terrorist activities. With our array of AML compliance services such as AML/ CFT Policy, Controls, Procedures & Documentation, and in-house AML compliance Department set up, AML trainingAnnual AML/ CFT Risk Assessment reportand AML/ CFT health checkup ; businesses can get complete peace of mind as they can stay AML compliant at all times.

FAQs

Who is responsible for compliance with AML? 

The following businesses must comply with AML: 

  • Banks 
  • Financial institutions 
  • Real estate agents 
  • Dealers in precious metals and gems 
  • Trust and company service providers 
  • Lawyers, notaries, and other legal professionals 
  • Accountants and auditors 

If the employee is compliant with AML regulations, identifying suspicious transactions and carrying out risk assessments would be easier. Also, employees would carry out activities in alignment with internal AML policies, procedures, and controls, and conduct due diligence of customers before onboarding them.  

For everyday AML compliance, an employee’s responsibilities are: 

  • To check daily activities for any suspicion of money laundering or any other financial crime 
  • To ensure KYC and CDD of customers are conducted 
  • To raise complaints if any doubt is raised 
  • To comply with the AML policies, processes, and internal controls implemented in the company 

A company can be tested for AML compliance in the following ways: 

  • Implementation of risk-based AML measures 
  • Identity verification of customers through CDD and EDD measures 
  • Checking customers against Sanctions screening and PEP status 
  • Identifying suspicious transactions and submitting reports 
  • Forming AML team, appointing AML Compliance Officer, and conducting AML training 

Share via :

About the Author

Pathik Shah

FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)

Pathik is an ACAMS-certified AML consultant specialising in governance, risk, and compliance for regulated entities in the UAE. He brings over 28 years of experience, with 1,000+ hours of AML training and 200+ advisory engagements across DNFBPs, VASPs, and FIs. He supports businesses in aligning with AML/CFT requirements from the CBUAE, DFSA, MoET, MoJ, VARA, CMA, FSRA, and FATF. Known for translating complex regulations into audit-ready procedures, Pathik enables operational clarity and compliance readiness.

Reach Out to Pathik

A guide To establishing an Effective AML/CFT Framework in your business

Regulatory Obligations and AML-CFT Framework

A Guide to Establishing an Effective AML/CFT Framework in Your Business

Published On: 05/02/2024

Table of Contents

Protect your business with reliable and effective AML strategies with AML UAE.

Last Reviewed On: 07/17/2026   |   Last Updated On: 07/17/2026

A Guide to Establishing an Effective AML/CFT Framework in Your Business

Financial Institutions and Designated Non-Financial Businesses and Professions that do not abide by the Money-Laundering laws or regulations have to pay heavy penalties and face severe reputational losses. Therefore, every business has to establish an effective AML/CFT framework to operate as per the legal requirements of the country.

So, the question arises: what should you consider when managing AML/CFT compliance in your business? This article provides the best practices for establishing an effective AML/CFT framework in your business.

Compliance. Trust. Transparency

Customized and cost-effective AML compliance services to support your business always

What is an Anti-Money Laundering Framework?

Implementing elements of the Anti-money laundering (AML) framework using a risk-based approach is crucial for preventing money laundering, financing terrorism, and proliferation financing (ML/FT and PF). The AML framework is a set of policies, procedures and controls that are formed to detect, deter, and report ML/FT and PF activities.

The AML framework lays down a structured strategy that aims to fulfil regulatory obligations and achieve mitigation of ML/FT and PF risks.

Importance of an Anti-Money Laundering Framework

The following is a list of factors stating why the AML framework is essential:

Ensure regulatory compliance:

DNFBPs are required to comply with different AML regulations, including regulations imposed by national and international regulators. In case it fails to comply with such regulatory requirements, penalties and fees are imposed on DNFBPs. Therefore, with the implementation of an effective AML framework, they can ensure compliance with these regulations and stay away from associated penalties and fines.

Risk mitigation:

The major threat to DNFBPs is using their platforms to facilitate financial risks. Criminals often use them to indulge in criminal activities because of inherent vulnerabilities. The AML framework employs measures that help DNFBPs in detecting ML/FT and PF activities and further aid in combating ML/FT and PF risks.

Protect business’s reputation:

As DNFBPs work in a highly competitive market, it is essential for them to maintain a good reputation to attract and retain clients and customers. Commitment to AML compliance can act as a deciding factor for clients to enter into a business relationship with the DNFBP. Any linkage to ML/FT and PF activities can damage its reputation, which results in client and business loss. The AML framework helps DNFBPs avoid risk and maintain their reputation by laying down the best strategy within its framework.

Maintain the integrity of the financial system:

By promoting stability, preventing illicit activities, risk management, and regulatory compliance, the AML framework helps maintain the integrity of the financial system. With such measures, the AML framework enables a safe, secure and strong global economy.

Regulatory requirements around AML/CFT framework

AML regulatory framework in the UAE includes national regulations, international regulatory framework and national AML strategy.

National Regulatory Framework

The national regulatory structure in the UAE contains federal civil, commercial and criminal regulations. Because criminal legislation comes under federal jurisdiction throughout the country, the ML/FT and PF criminal activities are covered under it. The following are such regulations within the country:

  • Federal Decree-Law No. 10 of 2025 on Anti-Money Laundering and Combating the Financing of Terrorism and Illegal Organisations.
  • Cabinet Resolution No. 134 of 2025 Concerning the Implementing Regulation of Federal Law No. 10 of 2025.
  • Cabinet UBO Resolution No. 58 of 2020 on the Regulation of the Procedures of the Real Beneficiary (UBO Resolution)

International regulatory framework

The AML framework in the UAE is aligned with the international bodies network, which implements international treaties and conventions for combating illicit crimes. These integrated laws are supervised by the regional regulatory authorities.

For such an integrated framework, the government and competent authorities in the UAE collaborated with various international bodies such as:

  • United Nations
  • Financial Action Task Force (FATF)
  • Middle East and North Africa Financial Action Task Force (MENAFATF)
  • Egmont Group of Financial Intelligence Units

National AML Strategy

The UAE government has implemented strategic decisions in the form of the National Strategy on Anti-Money Laundering and Countering the Financing of Terrorism. The strategy shapes the key initiative of the country’s national action plan. This strategy is based on four pillars that include:

  • Legislative & Regulatory Measures
  • Transparent Analysis of Intelligence
  • Domestic and International Cooperation & Coordination
  • Compliance and Law Enforcement

Furthermore, the National Committee for Combating Money Laundering and the Financing of Terrorism and Illegal Organisations looks into the implementation of strategy, emphasising effective coordination between different authorities, compliance with regulations and awareness of ML/FT risks among DNFBPs.

Compliance. Trust. Transparency

Customized and cost-effective AML compliance services to support your business always

Regulatory Obligations and AML/CFT Framework

The AML framework needs to be aligned with the statutory obligations of DNFBPs as follows:

ML/FT Enterprise-Wide Risk Assessment

ML/FT Enterprise-Wide Risk Assessment, also known as Business Risk Assessment, is an assessment that lays down an extensive plan that needs to be carried out to manage ML/FT and PF risks at an enterprise level. EWRA is a key pillar of a risk-based approach that addresses business-specific AML risks, threats, and vulnerabilities and further takes action to mitigate them.

EWRA is a continuous process to identify and assess ML/FT and PF risks that DNFBPs face in business lines, their products, and services and associated with different customers. While conducting the assessment, it considers various internal and external factors such as geographical risks, customer behavior, distribution channels and adequacy of the current AML policies.

DNFBPs with EWRA can effectively detect money laundering risks, identify mitigating measures, point out gaps and take cautious decisions relating to risk appetite and allocation of resources.

Customer Due Diligence

Customer Due Diligence (CDD) is an extensive process to identify and verify customer identity with the help of verified documents. CDD process also includes assessing customer risk profile, understanding the nature of transactions and monitoring customer activities. Additionally, it also focuses on assessing risk associated with customer’s business relationships and transactions.

Further, the CDD process differs depending on the ML/FT and PF risks that customers are associated with. CDD comes in three types: Simplified Due Diligence, Standard Due Diligence and Enhanced Due Diligence. Different CDD types are employed for each customer to mitigate ML/FT and PF risks, depending on the circumstance.

Ongoing Monitoring

Only after CDD measures are employed for customers can DNFBPSs establish business relationships with them. Once they enter into these relationships, DNFBPS must undertake ongoing monitoring measures. This measure is crucial as it continuously detects and reports suspicious activities.

Further, as part of ongoing monitoring, DNFBPs monitor business relationships with each customer on an ongoing basis to prevent any probable ML/FT and PF activities which an existing customer can pose.

DNFBPs also need to undertake ongoing monitoring of transactions. In order to undertake such a measure, they need to implement a robust transaction monitoring system that can detect suspicious activity effectively by pointing out unusual patterns and frequent transactions and alerting the involvement of high-risk jurisdictions.

Regulatory Reporting

It is a regulatory obligation under the UAE’s AML regulatory framework to swiftly report suspicious transactions or any reasonable situation where any suspicion relating to proceeds is in question. DNFBPs in the UAE must put in place and update indicators that could be used to identify possible suspicious transactions.

Regulatory reporting means submitting various reports provided under the AML/CFT regulatory framework to the relevant authorities. In the UAE, Suspicious Activity Report (SAR) or Suspicious Transactions Report (STR) are standard reports filed by DNFBPs to report any suspicious activity they come across.

Furthermore, in addition to SAR/STR, they must also file reports depending on the circumstances and nature of their business. These include filing of Partial Name Match Report (PNMR), Confirmed Name Match Report (CNMR), Real Estate Activity Report (REAR), Dealers in Precious Metals and Stones Report (DPMSR), High-Risk Country (HRC), and High-Risk Customer Activity (HRCA) reports.

AML/CFT Governance

For an effective AML framework, DNFBPs must include AML/CFT governance within their AML framework. This governance measure acts as a foundational structure. DNFBPs must include the following measures within AML/CFT governance:

  • AML governance must include compliance staffing and training to ensure that compliance officers and employees understand their responsibilities surrounding AML and further effectively undertake them.
  • It is mandated by the UAE’s regulatory framework that senior management is involved in the institution of the AML framework. Further, the law imposes various responsibilities on it, such as implementing governance and operating systems, approval of internal policies, procedures, and controls, application of the directives of Competent Authorities, and oversight of the AML/CFT compliance programme.
  • The AML framework must include an AML/CFT health check mechanism within DNFBPs that evaluates the business’s performance against all applicable AML/CFT obligations. This measure establishes ways to oversee vulnerabilities across DNFBPs, thereby strengthening the effectiveness of AML policies.
  • AML governance must include AML Independent Audit measures to evaluate efficacy and adherence to AML measures. It is an essential factor of the AML framework to engage auditors for conducting thorough reviews of current policies, procedures, and controls.

Record Keeping

Having a record-keeping system is essential within the AML framework. Records are an important source of information not only for DNFBPs but also for regulators. With record keeping, it is easier to undertake investigations and ensure transparency. As per the UAE’s AML regulatory framework, it is mandated that DNFBPs keep comprehensive information related to transactions, CDD, and any SAR/STR for five years.

Maintaining such records helps in identifying potential ML/FT and PF activities and underscores regulatory oversight. By keeping such records, DNFBPs can effectively counter ML/FT crimes and further safeguard themselves. Furthermore, having robust record-keeping practices, DNFBPs can effectively respond to regulators and commit to having a transparent and answerable culture.  

Targeted Financial Sanctions

Targeted Financial Sanctions (TFS) include measures that the regulatory authority imposes to restrict financial transactions with specific individuals, entities, or countries. DNFBPs must undertake such measures to prevent transactions with sanctioned individuals or entities and freeze their assets when identified.

To avoid indulgence with ML/FT and PF risk, DNFBPs, as part of this measure, undertake screening procedures for customers against relevant sanctions lists released by national and international bodies and further report any matches to the appropriate authorities.

How to frame effective AML Controls framework?

Here are a few ways in which you can effectively build AML Controls Framework:

1 - Having Qualified Compliance Professionals

The first and foremost step to building an effective AML and CFT framework is to have an effective and efficient AML expert who wouldn’t shy away from taking the help of creativity and innovation.

A practical AML/CFT framework requires a structure of corporate governance that incorporates compliance professionals or officers who are fluent in terms of legal regulations requirements.

A guide To establishing an Effective AMLCFT Framework in your business

Anti-money laundering professionals are basically responsible for making sure that the reported issues within the organization are addressed or looked after within the organization and within a time frame that will restrict you from further damage.

In addition to that, it is your moral duty to make all the employees of your organization and not just AML professionals know about the legal and ethical responsibilities that need to be effectively managed at an individual level as well in order to comply with the legal AML regulations.

Furthermore, all the employees must understand the fundamental idea of AML/CFT. In order to effectively comply with AML or CFT regulations, all the employees must undergo interdisciplinary training or certification programs in order to identify potential risks.

2 - Training of Anti-Money Laundering Experts

Anti-money laundering is a pretty dynamic subject. There is always some sort of updates, changes in regulations, proposals, or laws happening. In addition to that, various methods continue to find channels in criminals with every passing day.

Improving the overall skill set of your employees is essential in order to ensure that AML/CFT measures are actually implemented in the best possible way.

Professionals from the finance department must clearly understand the AML and CFT legislation and regulations for identifying and reporting any suspicious transactions.

Likewise, management employees who have direct contact with customers or the ones who process documents and money must understand the requirements of the Anti-Money Laundering Laws in the UAE.

Your entire staff must be well aware of the AML/CFT Framework and various roles of the consultants, compliance officers, officers, senior management, and the board of directors.

In addition to that, all of your staff members must be aware of ways in which they are supposed to react if at all they encounter suspicious activity.

3 - Risk Assessment And Risk-Based Approach

The foundation of a practical counter-terrorism financing framework (CFT) and anti-money laundering (AML) is actually based on a risk-based approach.

Business enterprises should determine the risk level of the clients by conducting an accurate risk assessment during the process of client
recruitment.

Post this, enterprises should aim to implement an efficient and effective AML compliance program in accordance with the AML/CFT Framework. By developing a tailor-made control program in accordance with the risk levels of your respective clients.

  • Building policies and adequate controls to reduce the risk and even the potential of money laundering
  • Understanding the overall levels of risks associated with business transactions and relationships
  • Identifying various sources of risks and evaluating all the potential risk reduction controls
  • Effectively running the successful AML compliance programs
  • Making accurate risk-based decisions about the employees as well as customers.

In addition to that, a risk-based approach is adopted in order to detect and prevent all sorts of money laundering activities.

However, risk-bearing capacity and the risk appetite of all the companies and customers are pretty different from one another. As a result, companies would be failing miserably if they try to implement the same AML controls for every customer.

There are basically two fundamental steps for organizations to move ahead with a risk-based approach. The first one is undoubtedly assessing the risk and the second one is to appropriate control processes to various risk levels.

4 - Advanced Anti-Money Laundering Policies

Highly dynamic anti-money laundering policies are needed to protect a business enterprise from criminal activities like money laundering and fully comply with relevant regulations and laws.

Enterprises need to implement robust risk-based governance to guide systems and processes. Providing a practical anti-money laundering policy framework is the topmost priority when it comes to meeting AML obligations.

Anti-money laundering policies should be easily verifiable by the authorized regulators, reflecting the overall risk appetite.

For instance, your AML policies should incorporate customer risk ranking during the recruitment process and due diligence.

Business enterprises should know their customers in order to comply with local and global legal anti-money laundering requirements and operate within the purview of the established AML/CFT Framework.

5 - Know Your Customer (KYC)

Know your customer processes incorporate the process of accurately and completely defining the information of the respective customers. Generally, KYC is the most critical step in the entire anti-money laundering control process.

Once you are sure of who your customers really are, the risk levels of these customers can be evaluated without any hassle, and post which, you can apply customer due diligence (CDD) processes.

Determining the level of risks of your customers or even potential customers with the help of CDD makes the AML control process much faster and efficient for the company.

During the process of CDD, the potential customer must be screened in politically exposed persons (PEPs) and the sanction list.

If any politically exposed person is found in this list, then the need and importance of enhanced due diligence (EDD) come into the picture.

This is simply because politically exposed persons are usually considered as individuals who hail from a high-risk profile, and thus, merely CDD processes might not be sufficient. As a result, the risks and threats related to the customer’s account opening can be detected, allowing you to take more effective AML controls and establish a highly-effective AML/CFT Framework.

6 - Ongoing Monitoring

Information or risks of institutions or customers may change over a period of time. For example, individuals who are not PEP might become politically exposed person by taking up any new task.

Hence, it is essential to be familiar with the information of the customer that may change over a period, also changing the risk levels of that particular customer.

Therefore, all of this information should be updated in your systems at regular intervals.

In addition to that, the accuracy of this information should also be confirmed so that it does not lose its functions of the risk-based approach.

If you are unable to keep up with the constantly changing customer information, you have to be prepared for some severe consequences.

The AML and CFT framework or policies makes an effective risk management tool. Additionally, an effective AML and CFT regime also reduces the probability of damage to the organization due to fraudulent activities.

7 - Detecting And Reporting Any Suspicious Transactions

The primary purpose of anti-money laundering checks is to detect financial crimes and suspicious transactions. Financial crimes must be detected, and necessary precautions must be taken in order to bring your AML processes to their actual purpose.

Although it is pretty challenging to check suspicious transactions almost instantly, they can be detected with the help of transaction monitoring solutions available to you. All of these transactions are stopped immediately and passed onto some other AML experts.

8 - Upgrade The Anti-Money Laundering System With AI-Powered Solutions

With the constant technological change, crimes are also changing their pace and ways dramatically, resulting in the evolution and development of the regulations. With this given, manual anti-money laundering controls remain insufficient in organizations that are prone to the risk of money laundering activities.

AI-powered anti-money laundering software solutions help you track the unusual transactions for the known patterns, and they reduce the risk of ML to a greater extent and thereby help in implementing an effective AML/CFT Framework.

Conclusion on Effective AML/CFT Framework in Your Business

The anti-money laundering (AML) framework is vital for preventing ML/FT and PF risks. Policies, procedures, and controls established under the AML framework help to detect, mitigate, and report illicit activities, including ML/FT and PF.

Additionally, as a structured strategy, the AML framework aids in a better understanding of the UAE’s AML/CFT regulatory compliance, thus ensuring compliance and avoiding penalties and fines. Therefore, with the implementation of the AML framework, DNFBPs can protect themselves from ML/FT and PF activities.

FAQs on Effective AML/CFT Framework

Why is AML/CFT important?

AML/CFT is essential for the following reasons.

  • In order to protect the financial systems
  • In order to prevent criminals or money launderers from enjoying the proceedings of the money laundering activities
  • In order to restrict the criminals to develop formidable economic powers and challenge the stability.

If you are a financial institution or a designated non-financial business or profession, then the chances are pretty high that you are more prone to encounter pretty risky situations on a daily basis. Hence, each employee should be aware of the AML/CFT policies of your company so that they can also play their part effortlessly.

However, it will be the responsibility of the AML Compliance Officer to ensure that an effective AML/CFT Framework is implemented in the company.

Begin your AML compliance journey with a positive first step.

Contact our team to handle your goAML registration process.

About the Author

Pathik Shah

FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)

Pathik is an ACAMS-certified AML consultant specialising in governance, risk, and compliance for regulated entities in the UAE. He brings over 28 years of experience, with 1,000+ hours of AML training and 200+ advisory engagements across DNFBPs, VASPs, and FIs. He supports businesses in aligning with AML/CFT requirements from the CBUAE, DFSA, MoET, MoJ, VARA, CMA, FSRA, and FATF. Known for translating complex regulations into audit-ready procedures, Pathik enables operational clarity and compliance readiness.

Reach Out to Pathik

A detailed guide of AML compliance requirements for auditors and accountants in the UAE

Blogs

Published On: 10/13/2021

Table of Contents

Protect your business with reliable and effective AML strategies with AML UAE.

Last Reviewed On: 07/17/2026   |   Last Updated On: 07/17/2026

A detailed guide of AML compliance requirements for auditors and accountants in the UAE

The profession of auditors and accountants is not an easy thing. They have access to the financial records and activities of their clients. This accessibility to financial records increases their vulnerability to money laundering. The involvement of their clients in money laundering activities also increases their exposure.

So, they must be extra vigilant to the risks of money laundering and terrorism financing. In this article, we list down the red flags of money laundering that auditors and accountants must be aware of. We also mention the important AML requirements that they must fulfil to remain in compliance with UAE’s AML regulations.

Key aspects that make auditors and accountants vulnerable to money laundering and financial crime

Some of aspects of the profession of auditors and accountants make them vulnerable to financial crimes. They must be aware of these factors to save themselves from becoming a victim of money laundering and terrorism financing. These factors include:

AML regulation for auditors and accountants in UAE

Federal Decree-Law No. 10 of 2025 on Anti-Money Laundering and Combating the Financing of Terrorism and Illegal Organizations is the primary law for AML in UAE. The Cabinet Resolution No. 134 of 2025 concerning the Implementing Regulation of this Decree-Law makes accountants and auditors subject to the AML law. This means that the AML law applies to all auditors and accountants in UAE.

The Cabinet Decision provides a list of Designated Non-Financial Businesses and Professions (DNFBPs). AML regulations apply to these DNFBPs that include auditors and accountants. Given the nature of their profession and the content of their duties, accountants and auditors must comply with AML requirements as stated in the regulations for DNFBPs.
Their exposure to money laundering and financial crime activities is high because of the nature of their profession. They are responsible for financial management, examination of financial records and accounts, and assessment of governance structure and control procedures. These activities are the reason why illicit organizations or individuals exploit or bribe auditors and accountants to launder money.
The Ministry of Economy of UAE provides a Supplemental Guidance for auditors and accountants. It mentions in detail the AML/CFT obligations for both of these professions. These obligations include risk identification, customer due diligence, identification and reporting of suspicious transactions, and internal control and governance frameworks.

Complying with AML and CFT

requirements just got easier

AML/CFT compliance requirements for auditors and accountants in UAE

Auditors and accountants must comply with the following requirements under the AML regulations of UAE:

Understand possible ML/FT risk exposure

You must have a detailed understanding of how your accounting and auditing business can be exposed to ML and FT risks. This requires an assessment at both the enterprise level and customer level. For this:

  • You must adopt a risk-based approach to identify risks in your business transactions. These risks may be of different types based on business nature, type of service, the operational environment, and other factors. Accordingly, you must adopt risk mitigation measures. 
  • You must be aware of the source of ML/FT risks and the phase in which the money laundering risk is high. You must know the client who is exposing you to such money laundering risks. 
  • You must know the transactions of clients that are making you vulnerable to financial crimes – valuation of certain types of assets or liabilities, approval of changes in a company’s capital structure, approval of company restructuring option, use of reserve account, approval of write-off of uncollected debt, payments from clients that are proceeds of financial crimes, or any other. 
  • You must consider different types of risks to your business due to money laundering. These risks include customer risk, geographic risk, transaction risk, channel risk, or any other. You must be able to identify each type and strategize for their elimination. 
  • You must conduct a risk assessment to understand the impact of these risks on your business. You must also analyze it in depth, document it, and update it as and when the changes occur. 
You must conduct a similar assessment of ML/FT risks on your client’s business. You must identify potential risks, adopt a risk-based approach, and document the methodologies adopted. Also, based on the client’s type and nature of business, you must appoint Compliance Officer and relevant team members to facilitate compliance with AML regulations.

Put in place internal policies, controls, and procedures

Auditors and accountants must implement necessary measures to manage and mitigate the ML/FT risks. One of the key measures is the implementation of strong and effective internal policies, controls, and procedures. You must assess these policies for effectiveness and update them accordingly as and when the need arises. 

These policies must relate to customer due diligence and suspicious transaction reporting. It must also include requirements for governance and record-keeping. Overall, such procedures must ensure management and mitigation of risks. 

Auditors and accountants must apply the same for their client’s businesses as well. They must check whether the client has implemented relevant internal policies and control measures related to AML/CFT. They must ensure that these policies and procedures are in alignment with the risk appetite of the client.

Implement customer due diligence measures

Auditors and accountants must apply the necessary customer due diligence (CDD) measures based on the category and profiling of the ML/FT risk. If there is any change in the risk category, they must be ready to update the due diligence measures as well. You must apply these measures during or before the transaction happens or the business relationship starts.

You need to apply similar CDD measures for your clients as well. These due diligence measures include the following:

Seek expert assistance of AML UAE

for your AML compliance requirements and enjoy an AML-compliant business

Report suspicious transactions to Financial Intelligence Unit (FIU)

Auditors and accountants must report any kind of suspicious transactions to the Financial Intelligence Unit as and when they suspect it. You must add all the relevant information for the suspected transaction and keep it updated. You must be extra vigilant to identify any suspicion in any transaction or customer.
Some of the indicators for suspicious transactions in their own business or client’s business include:
  • Unnecessary complex transactions whose purpose or beneficial owner is not known
  • Transactions that are inconsistent with the customer’s risk profiling
  • Large transactions (relatively large to a customer’s income or turnover) that are unusual for that client
  • Large deposits or withdrawals inconsistent with customer’s business nature
  • Unexplained changes in the ownership of entities or unnecessary involvement of a third party
  • Transactions involving high-risk countries or third parties with no relationship with customers
  • Unclear or dubious sourcing of funds for a transaction
  • Refusal of customers to provide relevant information or proofs required for due diligence measures

Ongoing monitoring of their and clients’ activities

Auditors and accountants must be vigilant of their clients’ activities and transactions. They must protect their business transactions and their clients’ from possible misuse by terrorists or criminals. So, you must check the client’s business and transactions often to be sure of no involvement of financial crime.
You must do continuous monitoring of the following activities of your client’s business:
  • You must check for any unexpected changes, amendments, or transfers that are unusual to your client’s routine transactions. 
  • You must keep a check on any changes in ownership, capital contributions, dividend payments, powers of attorney, or any other transaction that changes the control of the client’s business.
  • You must monitor any unusual transaction, which does not align with the client’s expected business activity. This may include funds transfers or financial transactions, or any other transaction that does not give the correct source of financing. 
  • An important consideration for auditors and accountants must be to check the source of the payments received from clients. You must ensure that the payments come from known sources and not from any unknown foreign accounts or third parties. The mode of payment must be such that it does not hide the origin of funds and must be the usual mode used by the client. 

Access the best AML advisory services

for making your business AML-compliant

Conclusion

Auditors must understand the vulnerability of their professional activities to money laundering risks. With that understanding, they must implement the above measures to comply with UAE’s AML/CFT regulations. These measures ensure that they themselves and their clients are not exposed to money laundering or terrorism financing activities.

To plan and implement any of these measures, you can also take the support of AML consultants in the UAE. A professional, AML consultant will be better equipped to help accountants and auditors with the right, relevant measures against money laundering. The consultant will ensure that industry-specific steps are taken in the fight against money laundering and terrorism financing.

Role of AML UAE

AML UAE is a leading AML compliance services provider in UAE. We help you with fulfilling all the requirements for AML and CFT in UAE. Our spectrum of AML compliance services is not restricted to national boundaries, but we also make sure that you comply with the global regulations of AML.

We can help you with:

Frequently Asked Questions (FAQs)

Here are a few frequently asked questions when it comes to the need and importance of sanction and PEP screening in the customer onboarding process.

Are the means of payment used by a client, possible red flags of ML/FT risks?

Yes, the means of payment used by the client to pay to the auditor or accountant can be an indicator of ML/FT risks. Some of the possible red flags are:

  • If the payment is divided into several, small parts
  • If the relevant documents submitted for the transaction are not trustworthy
  • If the payment is done via an unrelated third party with no connection to the client or no legal explanation for the same
  • If the mode of payment used is such that it hides the true payer of the money. 

The auditor and accountant must have the following information about the beneficial owner of the company:

  • Identification details
  • Source of wealth
  • Corporate history and business activities
  • Business relationships
  • Business transactions with third parties in foreign jurisdictions
  • Any connections with criminals or past allegations of criminal activities

Share via :

Add a comment

About the Author

Pathik Shah

FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)

Pathik is an ACAMS-certified AML consultant specialising in governance, risk, and compliance for regulated entities in the UAE. He brings over 28 years of experience, with 1,000+ hours of AML training and 200+ advisory engagements across DNFBPs, VASPs, and FIs. He supports businesses in aligning with AML/CFT requirements from the CBUAE, DFSA, MoET, MoJ, VARA, CMA, FSRA, and FATF. Known for translating complex regulations into audit-ready procedures, Pathik enables operational clarity and compliance readiness.

Reach Out to Pathik

A deep dive into the AML compliance requirements for the real estate sector in the UAE

Blogs

Published On: 04/18/2023

Table of Contents

Protect your business with reliable and effective AML strategies with AML UAE.

Last Reviewed On: 07/17/2026   |   Last Updated On: 07/17/2026

AML compliance requirements for the real estate sector in the UAE

The real estate sector is one of the main non-financial sectors that is highly vulnerable to money laundering activities. Large sums of money are involved in real estate transactions with limited regulatory scrutiny, so money laundering activities and terrorist financing transactions are quite common in the real estate sector.

As per the Central Bank of the UAE’s ‘Financial Stability Report, 2022’, the real estate sector (real estate and construction) contributed 18.5% of the UAE’s 2021 real non-oil GDP and 22% of UAE banking sector loans.

It becomes essential for the regulators to make the sector more regulated and controlled. It is also important to identify the possible suspicious transactions and conduct regular monitoring of real estate transactions. UAE has made special provisions for AML requirements in the real estate sector.

In the blog, we list down the situations that real estate businesses must be aware of to identify money laundering. We also cover the UAE regulations that govern AML/CFT provisions in the country. Lastly, we include the AML requirements that real estate agents and brokers must fulfill.
AML Compliance Requirements in UAE

Untangle the Web of AML Compliance with AMLUAE

Establish clear, relevant, and comprehensive AML Program with our expert assistance

Suspicious transactions in the real estate sector that raise a concern for money laundering

Following are the possible situations that raise suspicion regarding involvement of money laundering or any financial crime in the real estate sector:

In regards to these possibilities, the UAE government introduced AML/CFT regulations. Let us look at the key regulations and directives that control the real estate sector’s compliance with AML/CFT.

AML regulation for real estate sector in UAE

Do AML regulations apply to real estate brokers in the UAE?

Federal Decree-Law No. 10 of 2025 on Anti-Money Laundering and Combating the Financing of Terrorism and Illegal Organizations is the primary law for AML in UAE. The Cabinet Decision No. 134 of 2025 concerning the Implementing Regulation of this Decree-Law makes real estate agents and brokers subject to the AML law. This means that the AML law applies to real estate agents and brokers in the UAE.

These regulations are necessary since the real estate sector has a lower level of awareness of possible suspicious ML/FT transactions. Also, the real estate sector is big with not many rules to invest or do business in it. This makes the sector highly exposed to ML/FT activities that disturb the economy and income distribution of the country.

The Cabinet Decision provides a list of Designated Non-Financial Businesses and Professions (DNFBPs) that includes real estate brokers and agents. These define the various CDD obligations of the real estate industry and ways to identify risk factors. Let us look at the AML/CFT compliance requirements for the real estate sector in the UAE.

AML/CFT compliance requirements for real estate brokers and agents in UAE

Real estate agents and brokers must comply with the following requirements under the AML regulations of UAE:

Understand possible ML/FT risk exposure

You must have a detailed understanding of how your real estate business can be exposed to ML and FT risks. For this:

  • You must adopt a risk-based approach to identify risks in your business transactions. These risks may be of different types based on business nature, type of service, the operational environment, and other factors. Accordingly, you must adopt risk mitigation measures. 
  • You must be aware of the source of ML/FT risks and the phase in which the money laundering risk is high. 
  • You must know the latest ML/FT trends and understand the various customer risks, channel risks, and geographic risks to the real estate industry.  You must be able to identify each type and strategize for their elimination. 
  • You must be aware of the type, size, complexity, transparency, geographic origins, or any unusual nature of financial arrangements or instruments related to the buying and selling of property.
  • Brokers and agents must have full information on a customer’s residence status, type of real estate transaction, and speed and frequency of transactions to gauge the risk. 
  • You must keep all this information related to risk profiling documented and saved. The information must include methods of risk identification used, models used, and overall risk score. 

Understand the Money Laundering Risk Exposure to Your Business

AML UAE provides expert assistance in conducting AML Enterprise-Wide Risk Assessment

Implement Customer Due Diligence measures

Real estate brokers and agents must apply the necessary customer due diligence (CDD) measures based on the category and profiling of the ML/FT risk. If there is any change in the risk category, they must update the due diligence measures as well. You must apply these measures during or before the transaction happens or the business relationship starts.

These due diligence measures include the following:

Sanctions Screening - Actionable and Reporting under AML UAE
  • You must have in place a defined process for screening customers and prospects against Sanctions Lists. You must conduct background checks on your customers and prospects to identify any association with financial crimes.
  • You must be vigilant of the identity of the beneficial owner of your client. You must obtain all relevant proofs for establishing their identity and the source of funding. 
  • You must check for the compatibility of the customer’s profile with the relevant real estate transaction to see if it suits their financial stature and professional circumstances.
  • You must track the legal arrangement or structure used in the transaction, as it may result in hiding the identity of the owner or source of funds. 
  • You must also keep an eye on any association with Political Exposed Persons (PEPs), specifically in the case of foreign buyers or sellers. 
PEP and PEP Screening under UAE AML Regulations pre
  • You must check for any previous business transaction or relationship between buyer and seller. 

Ongoing monitoring of transactions

Whenever you identify high-risk customers, you must conduct a regular check of their transactions. You must monitor the frequency and type of real estate transactions they have been involved in. You must check the status of the financial instrument during the lifecycle of the transaction or you must check the land registry details.

Put in place internal policies, controls, and procedures

What are the basic elements of AML Policy in UAE Pre

The real estate brokers and agents must implement necessary measures to manage and mitigate the ML/FT risks. One of the key measures is the implementation of strong and effective internal policies, controls, and procedures. You must assess these policies for effectiveness and update them accordingly as and when the need arises. 

These policies must relate to customer due diligence and suspicious transaction reporting. It must also include requirements for governance and record-keeping. Overall, such procedures must ensure management and mitigation of risks.

Report suspicious transactions to Financial Intelligence Unit (FIU)

You must report any kind of suspicious transactions to the Financial Intelligence Unit as and when you suspect it. You must add all the relevant information for the suspected transaction and keep it updated. You must be extra vigilant to identify any suspicion in any transaction or customer.

Some of the indicators for suspicious transactions include:

  • Unnecessary complex transactions whose purpose or beneficial owner is not known
  • Transactions that are inconsistent with the customer’s risk profiling
  • Large transactions (relatively large to a customer’s income or turnover)
  • Unexplained changes in the ownership of entities or unnecessary involvement of a third party
  • Transactions involving high-risk countries or third parties with no relationship with customers
  • Unclear or dubious sourcing of funds for a transaction
  • Refusal of customers to provide relevant information or proofs required for due diligence measures

Real Estate Activity Report Submission

Ministry of Economy has recently issued a Circular (No. 05/2022 dated 24th June 2022), requiring the real estate brokers to report the specified transactions pertaining to real estate in the new report named as – Real Estate Activity Report (‘REAR’). The reporting entities have to submit REAR with the FIU UAE.

Read more about REAR here.

Filing of Real Estate Activity Report (REAR) on goAML under UAE AML Law

Devise and implement a sound governance structure

You must formulate a governance structure to ensure your business complies with AML/CFT requirements. For this, you must appoint a fit and capable compliance officer. He/she must be capable of handling Ml/FT reporting, AML/CFT program management, and training and development of the team.

You must keep your employee up-to-date on AML/CFT laws, policies, and norms. You must design a training manual and impart it to relevant team members. You must also assess the effectiveness of these training programs to ensure the right knowledge development.

A well-functioning governance structure is tested by an independent audit frequently. This auditing procedure will check the risk profile of products and services, customers, and target markets. If it is not possible for you to keep an internal audit team, then you can hire a third-party auditing team.

Free Download AML Policy Template for Real Estate Agents and Brokers in UAE

Responsibilities of Senior Management around AML program under UAE AML Laws

Reliable and Robust AML Services for Real Estate Agents and Brokers

From EWRA to filing REAR, get end-to-end AML compliance services with AML UAE

Anti-money laundering regulations for real estate transactions

The real estate sector brings a huge difference to UAE’s economy. So, it is immensely critical to keep money laundering and terrorism financing in check in this sector. You must implement all the above-mentioned measures to comply with national and global AML regulations.

The compliance with the anti-money laundering regulations for real estate transactions will enable you to save yourself and your business from any fraudulent transaction or business relationship. This, in turn, helps you to minimize your exposure to money laundering and terrorism financing risks. These measures also help you to be in congruence with international AML/CFT regulations and best practices.

To plan and implement any of these measures, you can also take the support of AML consultants in the UAE. A professional, AML consultant will be better equipped to help real estate brokers and agents with the right, relevant measures against money laundering. The consultant will ensure that industry-specific steps are taken in the fight against money laundering and terrorism financing.

Role of AML UAE

AML UAE is a leading AML compliance services provider in UAE. We help you with fulfilling all the requirements for AML and CFT in UAE. Our spectrum of AML compliance services is not restricted to national boundaries, but we also make sure that you comply with the global regulations of AML.

We can help you with:

FAQs - AML Compliance Requirements for Real Estate

Here are a few frequently asked questions About AML For Real Estate Sector.

What is AML in real estate? 

There are AML regulations for estate agents in the UAE, including implementation of necessary CDD measures, identification of ML/TF risks and reporting, internal policies, and sound governance structure.  

Yes. The primary reasons for the high risks of money laundering in the real estate sector are transactions involving large sums of money and limited regulations and laws. Also, more cash transactions, undervaluation or overvaluation of property, and involvement of PEPs or unknown third parties as investors expose the industry to higher risks.  

It is essential to conduct customer due diligence in the real estate sector to comply with know your customer, know your business, and ultimate beneficial owner regulations. For this, collect clients’ information, verify them with identity documents, verify UBO, check against PEPs or Sanction lists, and prepare risk profiles.  

Anti-money laundering in the real estate sector is essential. So, estate agents must do AML checks to identify customers, transactions, and their links with any financial crimes.  

Estate agents must do AML checks to avoid the possibility of engaging in business transactions with financial criminals, drug traffickers, money launderers, or terrorism sponsors.  

The factors that contribute to the vulnerability of the real estate sector to money laundering and other financial criminal activities are:

  • It is possible to launder big amounts of money in buying, selling, and leasing property. 
  • The prices are subjective like some prime locations have high property prices, leading to no suspicion based on prices.
  • It is seen as one of the best investment options.
  • There is a lesser degree of regulatory oversight and regulations for the real estate sector.

In the case of undervaluation of a property, the seller agrees to sell the property to the buyer at a lesser price than the market value. The buyer pays the difference between the two amounts with illicit funds to the seller. 

In the case of overvaluation of a property, the buyer buys the property at a higher price than the market value. This allows the buyer to obtain a large loan from the bank. Then the buyer uses illicit money to repay debts, thereby laundering illicit money into the legal financial system. 

– Federal Decree-Law No. (20) of 2018 On Anti-Money Laundering and Combating the Financing of Terrorism and Financing of Illegal Organizations,
– Implementing regulation, Cabinet Decision No. (10) of 2019 Concerning the Implementing Regulation of Decree-Law No. (20) of 2018 On Anti-Money Laundering and Combating the Financing of Terrorism and Illegal Organizations,
– Cabinet Decision No. (20) of 2019 Regarding Terrorism Lists Regulation and Implementation of UN Security Council Resolutions On the Suppression and Combating of Terrorism, Terrorists Financing & Proliferation of Weapons of Mass Destruction, and Related Resolutions,
– AML/CFT Guidelines for Financial Institutions and Designated Non-Financial Businesses and Professions issued by supervisory authority (such as FSRA or DFSA),
– UAE Ministry of Economy’s Guidelines for Designated Non-Financial Businesses and Professions,
– UAE Ministry of Economy’s Supplemental Guidance for specific sector (such as Real Estate Sector, Dealers in Precious Metals and Stones, etc.)

Share via :

Add a comment

About the Author

Pathik Shah

FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)

Pathik is an ACAMS-certified AML consultant specialising in governance, risk, and compliance for regulated entities in the UAE. He brings over 28 years of experience, with 1,000+ hours of AML training and 200+ advisory engagements across DNFBPs, VASPs, and FIs. He supports businesses in aligning with AML/CFT requirements from the CBUAE, DFSA, MoET, MoJ, VARA, CMA, FSRA, and FATF. Known for translating complex regulations into audit-ready procedures, Pathik enables operational clarity and compliance readiness.

Reach Out to Pathik

AML Regulations for Capital Market Firms in UAE

AML Regulations for Capital Market Firms in UAE

Blogs

Published On: 07/13/2026

Table of Contents

Protect your business with reliable and effective AML strategies with AML UAE.

Last Reviewed On: 07/13/2026   |   Last Updated On: 07/13/2026

Key Highlights

  • Capital market firms, including broker-dealers, fund and asset managers, investment advisers, and custodians, are financial institutions under Federal Decree-Law No. 10 of 2025 and its Executive Regulations in Cabinet Resolution No. 134 of 2025.
  • They are supervised for AML by the Capital Market Authority, established under Federal Decree-Law No. 32 of 2025 as the successor to the Securities and Commodities Authority, not by the Central Bank.
  • The national risk assessment rates the securities sector’s money laundering risk in the medium to medium-high range with controls assessed as effective, and its proliferation financing risk as low.
  • On top of the federal laws, the Capital Market Authority issues its own AML rulebook chapter, sector guidance, notices, thematic reviews, and reporting standards.
  • Virtual asset service providers fall under a separate framework rather than this securities regime: the federal CMA regime applies outside the financial free zones and works alongside local licensing authorities such as Dubai’s Virtual Assets Regulatory Authority. We cover it on a dedicated page rather than here.
  • Firms in the DIFC and ADGM answer to the DFSA and FSRA and sit outside this guide.

Capital market firms sit at a different point in the UAE financial system from banks, payment institutions and remittance houses. They deal, manage, advise, and hold securities rather than take deposits or send remittances. They also answer to a different regulator, the Capital Market Authority, rather than the Central Bank. This guide sets out the AML regulations for capital market firms in the UAE: which activities are in scope, who supervises them, the full legal framework that applies, and how the national risk assessments rate the sector’s money laundering, terrorist financing, and proliferation financing risk. It covers securities and commodities firms supervised by the Capital Market Authority, outside the DIFC and ADGM.

In short: CMA-regulated capital market firms in the UAE, including broker-dealers, fund and asset managers, investment advisers and custodians outside the DIFC and ADGM, must comply with Federal Decree-Law No. 10 of 2025, its Executive Regulations in Cabinet Resolution No. 134 of 2025, the targeted financial sanctions framework under Cabinet Resolution No. 74 of 2020, UAE FIU reporting through goAML, and the Capital Market Authority’s own rulebook and reporting standards. Firms in the DIFC and ADGM follow the separate DFSA and FSRA AML regimes.

What activities are covered in the capital market sector?

The capital market sector, for AML purposes, covers firms licensed by the Capital Market Authority to carry on securities and commodities activities. The categories below all sit inside the AML regulations for capital market firms in the UAE. Firms established in the DIFC and ADGM are supervised by the DFSA and FSRA and are not covered here.

Brokerage and dealing in securities

Broker-dealers execute and arrange trades in securities and commodities for clients. Their exposure runs through client onboarding, the source of investment funds, and the risk that trading and settlement are used to move or layer value.

Fund and asset management

 Fund and asset managers invest and manage money on behalf of clients and funds. Their controls centre on the investor behind the money, the beneficial owners of corporate and pooled investors, and the source of subscriptions.

Investment advisory

Investment advisers arrange and advise on securities business. Even where they do not hold client assets, they are inside the AML perimeter for the relevant business they introduce and service.

Custody and other market intermediaries

Custodians hold securities, and other market intermediaries support trading and settlement. Their duty is to know the client whose assets they hold and to monitor for activity that does not fit the account.

AML Supervisory Authority for the Capital Market Firms in UAE

For capital market firms outside the Financial Free Zones, the Capital Market Authority is the primary sector supervisor for AML, CFT and CPF compliance. The UAE Financial Intelligence Unit and the Executive Office for Control and Non-Proliferation also play roles in reporting and targeted financial sanctions.

Capital Market Authority (CMA)

The Capital Market Authority, established under Federal Decree-Law No. 32 of 2025 as the successor to the Securities and Commodities Authority, licenses and supervises capital market firms, issues the AML rulebook and guidance they follow, and inspects them through thematic reviews and examinations. It can require reporting, direct remediation, and the imposition of penalties for breaches. Virtual asset activity sits under a separate framework rather than this securities regime: the federal CMA regime applies outside the financial free zones and works alongside local licensing authorities, including Dubai’s Virtual Assets Regulatory Authority. Our dedicated guide to AML for VASPs outside Dubai covers it in full. Firms established in the DIFC and ADGM are supervised instead by the DFSA and FSRA and fall outside this guide.

UAE FIU and goAML

In-scope capital market firms register with the UAE Financial Intelligence Unit on the goAML platform and report through it. Registration on goAML is a baseline obligation, and suspicious transaction reports, suspicious activity reports, and related filings are submitted through it where required. See our goAML registration guide for the practical steps.

AML Legal Framework Applicable to Capital Market Firms in UAE

The framework has four layers: the core federal laws, the guidance that applies to all reporting entities, the national risk assessments, and the Capital Market Authority’s sector-specific material. This section catalogues each layer, grounded in the Capital Market CMA library. Some older SCA, FIU and supervisory materials were issued under the 2018 AML framework; they should be read subject to Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025, and only to the extent they remain in force and are not inconsistent with the current framework.

Layer Instrument Why it matters 
AML statute Federal Decree-Law No. 10 of 2025 Core AML, CFT and CPF offences, FIU powers, reporting duties and penalties 
Executive Regulations Cabinet Resolution No. 134 of 2025 Practical obligations: risk-based approach, CDD and EDD, beneficial ownership, monitoring, reporting and record keeping 
TFS framework Cabinet Decision No. 74 of 2020 and EOCN guidance Screening, freezing without delay and reporting of confirmed and partial name matches 
Capital market laws Federal Decree-Law No. 32 and No. 33 of 2025 Establish the Capital Market Authority and govern licensing and supervision of capital market activities 
CMA and SCA materials Rulebook Chapter Five, notices, thematic reviews and returns Sector-specific AML expectations and reporting standards 
NRA and PF NRA UAE ML and TF NRA 2024 and UAE PF NRA 2026 Baseline for the business-wide and enterprise-wide risk assessment and risk calibration 

Federal AML Laws and Executive Regulations Applicable to Capital Market Firms in UAE

These instruments are the legal foundation for every capital market firm in scope.

Federal Decree-Law No. 10 of 2025 on AML, CFT and CPF

For a securities or commodities firm, Federal Decree-Law No. 10 of 2025 is the foundational statute behind every anti-money laundering control a broker-dealer, asset manager, adviser or custodian must run. It defines money laundering, predicate offences, targeted financial sanctions and suspicious transactions, and confirms that offences may be committed through digital systems. It creates the Financial Intelligence Unit within the Central Bank as the national central agency for receiving suspicious transaction reports, empowered to demand further information and, through the Head of the Unit, to issue suspension and freezing measures within the limits and procedures set by the Decree-Law and the UAE FIU regulation on suspension and freezing powers. The Decree-Law places market intermediaries under supervisory oversight, exposes them to administrative penalties, and imposes the duty to detect, report and support enforcement.

Cabinet Resolution No. 134 of 2025, the Executive Regulations

Cabinet Resolution No. 134 of 2025 issues the Executive Regulations of Federal Decree-Law No. 10 of 2025, converting the statute into the operating rulebook that market intermediaries follow day to day. It expands the definitions, adding senior management, beneficial owner, reasonable measures and wire transfers, and confirms that securities activities and funds transfers fall squarely within the scope. For a broker-dealer, fund manager, adviser or custodian, it prescribes the substantive obligations: a risk-based approach, customer due diligence, identification and verification of beneficial owners behind corporate clients, ongoing monitoring of trading and settlement activity, and internal policies approved by senior management. These are the concrete procedures supervisors will test in examinations.

Cabinet Resolution No. 109 of 2023 on beneficial owner procedures

Cabinet Decision No. 109 of 2023 regulates beneficial owner procedures for legal persons in the United Arab Emirates. It defines the real beneficiary as the natural person who ultimately owns or controls a legal person, directly or through a chain of ownership, and requires legal persons to obtain, maintain and disclose accurate beneficial owner information, identify nominee board members, and keep a real beneficiary register updated within fifteen days of any change. For a securities firm, this underpins due diligence, since brokers and custodians rely on trustworthy ownership data to verify corporate clients. These procedures apply to legal persons licensed or registered in the State, including commercial free zones, but exclude the financial free zones, the DIFC and ADGM, which operate their own beneficial ownership regimes.

Cabinet Resolution No. 132 of 2023 on penalties for beneficial owner violations

Cabinet Resolution No. 132 of 2023 sets the administrative penalties for breaches of the beneficial owner procedures under Cabinet Decision No. 109 of 2023. It empowers the registrar to fine legal persons that fail to keep accurate registers or supply required information, following an annexed schedule, without prejudice to other sanctions under the primary anti-money laundering legislation. Consequences escalate: on a third violation, the registrar may suspend the commercial licence and close the premises until the fine is paid and the breach corrected. For a securities or commodities firm, this explains why corporate clients must keep ownership data current. These penalties apply to legal persons licensed or registered in the State, including commercial free zones, but not to the financial free zones, the DIFC and ADGM, which follow their own regime.

Cabinet Resolution No. 74 of 2020 on terrorist lists and UNSC resolutions

Cabinet Resolution No. 74 of 2020 governs how the United Arab Emirates applies the terrorist lists and gives effect to United Nations Security Council sanctions on terrorism, its financing and proliferation. It provides for a local Cabinet list, defines designation, listing and de-listing, and requires freezing measures to be applied without delay, meaning within twenty-four hours. For a securities or commodities firm, this is the backbone of transaction monitoring. Brokers, dealers, managers and custodians must register on the Executive Office website, continuously screen clients, prospective investors, beneficial owners and counterparties against the lists, freeze any matched funds or securities without prior notice, and report promptly to the supervisor.

Federal Law No. 7 of 2014 on combating terrorism crimes

Federal Law No. 7 of 2014 on Combating Terrorism Crimes is the criminal statute defining terrorist offences and their penalties in the United Arab Emirates. It sets out concepts such as terrorist crime, terrorist purpose, terrorist organisation and terrorist person, and prescribes severe penalties up to life imprisonment and, in specified cases, death. Of direct interest to a securities or commodities firm is its treatment of terrorism financing: it penalises providing, collecting or maintaining funds for terrorist ends and addresses freezing suspect funds held in financial institutions. Because the wider framework defines terrorist acts by reference to this law, market intermediaries use it to understand the conduct their controls target.

AML Guidance Applicable to All Reporting Entities

Beyond the core laws, the FIU and the Executive Office issue guidance and typologies that apply to all reporting entities, capital market firms included.

UAE FIU Regulation No. 1 of 2026 on Suspension and Freezing Powers, April 2026

UAE FIU Regulation No. 1 of 2026, dated April 2026, governs the postponement or suspension of suspicious transactions and the freezing of funds. Issued under the AML/CFT Decree-Law and its Executive Regulation, it applies to reporting entities and complements existing reporting duties. It introduces the Postponement Suspicious Transaction Report, an urgent filing where there is a risk of imminent transfer, withdrawal or dissipation of funds suspected of being linked to crime. The Head of the Unit may issue a Suspension Order of up to ten working days and a Freezing Order of up to thirty days. For dealers, managers and custodians, it creates a fast-track mechanism to preserve investor funds.

UAE FIU Strategic Analysis Report on Human Trafficking, April 2026

The UAE FIU Strategic Analysis Report on Human Trafficking, dated April 2026, analyses money laundering and financial flows connected to trafficking, drawing on suspicious transaction and activity reports filed with the Financial Intelligence Unit. It sets out its objectives, methodology and scope and covers the main forms of exploitation. Findings span the laundering of trafficking proceeds and convergence with other criminal enterprises, profiling subjects including organised crime groups, foreign politically exposed persons and money mules. It develops risk indicators around customer profile, behavioural activity, account and transactional activity, and due diligence. For dealers, managers, advisers and custodians, it is a detection resource for refining monitoring and improving report quality.

Guidance on Targeted Financial Sanctions for Financial Institutions, DNFBPs and VASPs, March 2026

Issued by the Executive Office for Control and Non-Proliferation, first published in January 2021 and last amended in March 2026, this guidance clarifies the obligations of reporting entities under the UAE’s targeted financial sanctions framework. It sets out four duties: registering in the Executive Office’s Notification Alert System; screening clients against the UAE Local Terrorist List and the United Nations Consolidated List; freezing assets without delay and not making them available to designated persons; and reporting the measures taken. The March 2026 update renames the Funds Freeze Report as the Confirmed Name Match Report and addresses weekend screening. For a securities firm, it defines how screening, freezing and reporting operate.

Joint Guidance on the Compliance Officer and MLRO, 2026

Issued in 2026 by the UAE Supervisory Sub-Committee, this joint guidance sets a unified framework for the appointment, authority and responsibilities of the Compliance Officer or Money Laundering Reporting Officer across regulated sectors. It applies to firms supervised by authorities, including the Securities and Commodities Authority, the Central Bank and the Ministries of Justice, Economy and Tourism, building on Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025. It treats the role as a cornerstone of an effective programme, requiring appropriate seniority, experience, operational independence, board access and adequate resources. For a securities firm, it clarifies how to appoint a fit and proper officer.

FIU Strategic Analysis Report on Terrorist Financing, May 2025

Published in May 2025 by the UAE Financial Intelligence Unit, this strategic analysis on terrorist financing typologies and facilitators draws on data held from 1 January 2021 to 31 December 2024, including suspicious transaction and activity reports and cases disseminated to authorities. It explains how terrorist financing works and sets out typologies such as moving and obscuring funds through financial institutions, corporate networks, trade-based methods, high-value goods and real estate. It also examines facilitators, including designated persons, family members, money mules, corporate nominees and professional service providers, closing with practical indicators. For an investment firm or custodian, these indicators sharpen the detection, tracing and reporting of suspicious securities-account activity.

Federal Decree-Law No. 6 of 2025 on the Central Bank (regulatory background)

Federal Decree-Law No. 6 of 2025 is the Central Bank law governing the licensing and supervision of financial institutions. It is not the AML statute, but it sits in the overarching framework because it underpins the wider UAE financial system that capital market firms interact with, from settlement banks to custodians. For a CMA-regulated brokerage or fund manager, it matters mainly at the perimeter: knowing which counterparties are Central Bank-licensed, and how the two supervisory regimes, the CMA under Federal Decree-Law No. 32 of 2025 and the Central Bank, fit together across the sector.

goAML FAQs, April 2024

The goAML FAQs, version 2.1 dated 18 April 2024, are a practical question-and-answer guide from the UAE Financial Intelligence Unit helping reporting entities use the goAML reporting system and its registration and access services. It addresses common registration and login problems with step-by-step remedies, including expired one-time passwords at first login, pop-up authentication requiring the system-issued username with a Google Authenticator passcode, the correct login sequence, and resetting a forgotten password. It sets out where to enter credentials and who to contact when errors persist. For dealers, managers, advisers and custodians, reliable goAML access underpins timely suspicious reporting, so this guidance keeps compliance teams connected without avoidable delays.

PF Institutional Risk Assessment Guidance for FIs, DNFBPs and VASPs, December 2023

Published in December 2023, this guidance sets out how firms should assess and manage their exposure to proliferation financing. It explains a methodology built around inherent risks, control effectiveness and residual risks, and identifies the risk categories and factors institutions consider when scoring their business. It describes supporting measures, covering client onboarding, know your customer and due diligence, enhanced due diligence, screening for sanctions and adverse media, ongoing and transaction monitoring, and suspicious activity reporting. A customer risk scoring questionnaire, elevated risk factors and worked case studies show how scores are applied. For a brokerage or fund manager, it turns proliferation financing obligations into a repeatable framework that supervisors can review.

Terrorist and Proliferation Financing Red Flags Guidance, December 2023

Updated in December 2023, the Terrorist and Proliferation Financing Red Flags Guidance gives a consolidated set of indicators to help firms detect suspicious financing and evasion of targeted financial sanctions imposed under United Nations resolutions or local designations. It explains how sanctioned parties disguise involvement through renaming, intermediaries and front companies, useful when screening the beneficial owners behind corporate brokerage and fund clients. Indicators are grouped by customer profile, account, transaction activity, maritime and trade finance. For dealers, managers, advisers and custodians, it sharpens front-line and compliance awareness, supporting decisions on when securities dealing or account activity should trigger a report to competent authorities.

Suspicious Activity and Transaction Reporting Thematic Review, January 2023

Issued in January 2023, this Suspicious Activity and Transaction Reporting Thematic Review sets out key findings and regulatory expectations from the 2022 AML/CFT examination of licensed financial institutions and designated non-financial businesses and professions. It focuses on the suspicious transaction and activity reporting framework and the transaction monitoring systems that feed it, read alongside existing guidance on reporting and on monitoring and screening. It is organised around expectations with acceptable and deficient practices across governance, policies, risk-based monitoring controls, data management, alert review, case investigation, reporting decisions and the post-reporting process. For a brokerage or fund manager, it is a practical benchmark for testing, monitoring and reporting before inspection.

Counter Proliferation Financing Guideline, November 2022

Published in November 2022 by the Executive Office for Control and Non-Proliferation, this guideline supplements the wider Guidance on Targeted Financial Sanctions and raises awareness of proliferation financing threats among regulated firms. It explains what proliferation financing means, sets out its stages, and describes the UAE counter-proliferation framework, the interagency mechanism and the relevant federal laws. For a securities house, fund manager or custodian, it shows how to fold proliferation financing risk into the firm’s own risk assessment and apply mitigating measures, including enhanced due diligence on clients and transactions, scrutiny of shell and front companies, dual-use trade exposure and staff training. Red flags help detect sanctions evasion.

goAML Web Submission Guide, July 2022

The goAML Web Submission Guide, issued by the UAE Financial Intelligence Unit in July 2022, sets out how to submit a report to the FIU through the goAML platform. It is addressed to the designated Compliance Officer or Money Laundering Reporting Officer of a registered reporting entity, or the deputy where the lead officer is unavailable. It gives an overview of report types, including the Suspicious Transaction Report and the Suspicious Activity Report, the latter covering suspected activity or an attempted, non-executed transaction, alongside the Additional Information File, Request for Information and High Risk Country reports. For dealers, managers, advisers and custodians, it standardises how suspicions are reported promptly.

Joint Guidance on Combating the Use of Unlicensed Virtual Asset Providers, March 2022

Issued in March 2022, this joint guidance from the UAE Supervisory Authorities, including the Securities and Commodities Authority and the Central Bank, addresses the risks posed by providers operating outside the licensing regime. It reminds regulated firms of their anti-money laundering obligations and urges the public to deal only with licensed entities. It sets expectations to stay vigilant, factor emerging risks into risk assessments, conduct adequate due diligence, identify clients who seek out unlicensed providers, and report suspicions. Red flags include the absence of a regulatory licence, no physical presence, unrealistic promises or Ponzi schemes, and pressure to invest quickly. For a brokerage, it sharpens the screening of exposed client flows.

IEMS User Guide for Reporting Entities, March 2022

Dated March 2022, the IEMS User Guide for Reporting Entities is a practical manual from the UAE Financial Intelligence Unit for its Integrated Enquiry Management System, which automates information requests, the implementation of public prosecutions’ decisions and other requests from domestic authorities. It explains how firms register and log in, noting that entities already on the goAML system reuse the same credentials. It walks through the dashboard, request management and the reply and attachments workflow, covering account, account holder and signatory details, sets out the Admin, Maker and Checker roles, and stresses meeting due dates and implementing freeze orders immediately. For a securities firm, it shows how enquiries are handled.

goAML Pre-Registration Guide, March 2022

The goAML Pre-Registration Guide, issued by the UAE Financial Intelligence Unit in March 2022, explains how reporting entities secure access to the Services Access Control Manager, or SACM, before reaching the goAML application to register and file suspicious reports. The application is available through a public portal for entities not regulated by the Central Bank, with others following their Supervisory Body’s steps. SACM hosts links to the production and testing environments, controlled by a time-based one-time password from Google Authenticator. It covers pre-registration, confirmation of intent and safeguarding a personal Secret Key. For dealers, managers, advisers and custodians, correct pre-registration is a prerequisite for secure reporting access.

goAML Registration Guide, March 2022

The goAML Registration Guide, issued by the UAE Financial Intelligence Unit in March 2022, sets out the steps an organisation follows when registering with the FIU on its reporting platform. It applies to registration as a reporting entity, stakeholder or supervisory body, confirming that every accountable and reporting entity in the United Arab Emirates, whatever its regulator, must register to submit suspicious reports. It explains reaching the portal through the Services Access Control Manager, then selecting the registration type, entering the organisation and addresses, adding the registering person and setting user access rights. For dealers, managers, advisers and custodians, correct registration is the foundation of compliant, timely reporting.

Strategic Review on Targeted Financial Sanctions Case Studies, November 2021

Dated November 2021, this Strategic Review on Targeted Financial Sanctions Case Studies examines sanctions reporting in the UAE over the period reviewed. It sits within the framework under which the country, through Cabinet Resolution No. 74 of 2020, implements United Nations Security Council Resolutions on terrorism, terrorist financing and the financing of proliferation, including freezing measures and prohibitions on providing funds and services. The review explains its methodology, then classifies sanctions reports by source, by suspicion and by the instruments involved, drawing out patterns that distinguish terrorist financing from proliferation financing and presenting red flags and recommendations. For a brokerage, it shows how sanctions suspicions arise and are reported.

Typologies on the Circumvention of Targeted Sanctions, November 2021

Last amended in November 2021 and issued by the Executive Office, this typologies report compiles cases showing how sanctioned persons and entities attempt to circumvent targeted sanctions relating to terrorism and the proliferation of weapons of mass destruction. Drawing on public sources from the UAE and abroad, it presents methods used to evade United Nations resolutions and the national terrorist list. Typologies are grouped by channel and sector, covering online payment facilities, trade in dual-use goods, elaborate legal entity structures, cyberactivity and economic resources, illustrated with named networks and red flags. For dealers, managers, advisers and custodians, it turns evasion tactics into practical learning for screening, due diligence and monitoring.

Update to the List of High Risk Jurisdictions, November 2021

This November 2021 decision of the National Anti-Money Laundering Committee updates the list of high-risk jurisdictions subject to a call for action, the list of jurisdictions under increased monitoring and the counter-measures to apply, superseding an earlier March 2021 decision. Addressed to the supervisory authorities and the Financial Intelligence Unit, it reflects the Committee’s mandate to identify countries with weak controls, set proportionate counter-measures and direct supervisors to ensure the required due diligence is applied. For dealers, managers, advisers and custodians, country risk is a core input to controls, signalling which jurisdictions warrant enhanced due diligence on investors and securities flows and requiring risk assessments to track the latest listings.

Joint Guidance on Satisfactory and Unsatisfactory Practice, June 2021

Issued in June 2021, this joint guidance from the UAE Supervisory Authorities, including the Securities and Commodities Authority, the Central Bank and the Ministries of Justice and Economy, draws on themes seen during supervisory inspections between January 2020 and May 2021. It contrasts satisfactory and unsatisfactory practices across the anti-money laundering framework, targeted financial sanctions and counter-proliferation financing. For a brokerage or fund manager, it addresses governance and management oversight, risk assessment, three lines of defence, policies, training and the compliance officer role, alongside client onboarding, monitoring, risk rating, due diligence, transaction monitoring, sanctions screening and reporting. It turns inspection findings into concrete examples, helping firms benchmark controls beforehand.

Typologies on the Circumvention of TFS, PF and WMD, May 2021

Last amended in May 2021 and issued by the Executive Office, this typologies report examines how sanctioned persons and entities obtain financing in violation of or evasion of United Nations resolutions on terrorism and the proliferation of weapons of mass destruction. It explains that targeted financial sanctions cover both asset freezing and prohibitions on making funds or assets available, directly or indirectly, to designated parties. Organised by financing method, it addresses trade in goods, economic resources, online payment facilities, cyberactivity against financial institutions and the misuse of legal entities or arrangements, closing with red flags. For dealers, managers, advisers and custodians, it strengthens the screening, monitoring and reporting of attempted circumvention.

goAML FAQs, September 2020

The goAML FAQs Guide, issued by the UAE Financial Intelligence Unit in September 2020, is a practical question-and-answer reference for reporting entities using the goAML platform, through which suspicious reports are filed in the United Arab Emirates. It compiles the queries most commonly raised once an organisation is registered and active, with step-by-step responses. It explains resetting a forgotten password, updating organisation details such as name, licensed activity, address and contacts, and how the Money Laundering Reporting Officer, as admin, delegates reporting to a third party subject to Supervisory Body approval. For dealers, managers, advisers and custodians, accurate registration data and managed access underpin compliant, uninterrupted reporting to the FIU.

goAML Registration Guide Stage 2, September 2020

The goAML Registration Guide Stage 2, issued by the UAE Financial Intelligence Unit in September 2020, outlines the steps an organisation follows when registering with the FIU on its reporting platform. It applies to registration as a reporting entity, stakeholder or supervisory body, confirming that every accountable and reporting entity in the United Arab Emirates must register to submit suspicious reports, and noting that since 27 June 2019 such reports must be filed electronically through goAML. It covers reaching the portal through the Services Access Control Manager, selecting the registration type and registering an organisation. For dealers, managers, advisers and custodians, proper registration is the gateway to lawful electronic reporting.

Guideline on Grievance Procedures

The Guideline on Grievance Procedures comes from the Executive Office for Control and Non-Proliferation, the authority that receives grievance requests linked to the UAE Local Terrorist List and the United Nations Consolidated List, together the Sanctions Lists. Under Cabinet Resolution No. 74 of 2020, three types are handled: de-listing of a designation, cancellation of freezing measures, and permission to use frozen assets, each distinguished by whether the designation sits on the Local or United Nations List. For a brokerage, fund manager or custodian, it maps the lawful routes an affected client may use to challenge a designation or seek access to frozen securities and funds.

Online Grievance System User Guide

The Online Grievance System User Guide comes from the Executive Office for Control and Non-Proliferation, which receives grievance requests tied to the UAE Local Terrorist List and the United Nations Consolidated List, together the Sanctions Lists. Launched to streamline submissions, the system is explained step by step in this manual. It covers three online request types: de-listing, cancellation of freezing measures, and permission to use frozen funds. It walks the user through identifying the aggrieved individual or legal entity, selecting the grievance type, declaring earlier requests and appeals, and attaching documents. For a custodian, it explains how an affected client may challenge a designation or seek access to frozen assets.

Simple Guide to Subscribe to the EOCN Notification Alert System (NAS)

This short guide explains how to subscribe to the Notification Alert System operated through the Executive Office’s website, so users receive timely updates to the sanctions lists applied in the UAE. Targeted financial sanctions rest on designations across two lists, together the Sanctions Lists: the UAE Local Terrorist List issued by the Cabinet and the United Nations Consolidated List issued by the Security Council, each updated periodically. It shows where the lists can be accessed and gives step-by-step subscription instructions, from the webpage to entering details and confirming. For a securities firm, this supports a core control: screening works only against current lists.

Emerging ML, TF and PF Risks and Trends in the Financial Sector

Issued by the Supervisory Subcommittee under Article 16 of Federal Decree-Law No. 10 of 2025, this report gives regulated firms a current view of the money laundering, terrorist financing and proliferation financing threats reshaping the financial sector amid technological change, geopolitical shifts and evolving criminal methods. After setting out the scope and methodology, it examines emerging risks such as artificial intelligence exploitation, greenwashing and ESG-related fraud, trade finance abuse, and sanctions evasion linked to the Commonwealth of Independent States. Case studies cover money mule networks, trade-based laundering, free-zone corporate structures and fraudulent green schemes. Brokers and asset managers should feed these typologies and red flags into risk assessments and detection systems.

Typologies in the Financial Sector

Typologies in the Financial Sector is a joint report by the Supervisory Authorities Sub-Committee and the Financial Intelligence Unit, prepared with the Executive Office and a pilot group of institutions. It shares money laundering, terrorist financing, sanctions, fraud and corruption typologies observed in the market, several arising during the COVID-19 period, to help firms anticipate emerging risks. Sitting above the National Risk Assessment, it describes risk indicators that combine to obscure the true nature of transactions and flags links to modern slavery and human trafficking. For dealers, asset managers, advisers and custodians, it works as an early-warning tool for updating risk assessments, refining monitoring scenarios and engaging authorities.

NRA, SRA, and Other Important Guidelines for the Capital Market Sector in the UAE

The UAE assesses its money laundering, terrorist financing, and proliferation financing risk at the national level, and capital market firms must align their own business and enterprise-wide risk assessments with those findings.

UAE PF National Risk Assessment 2026

The UAE Proliferation Financing National Risk Assessment 2026 examines exposure to the financing of weapons of mass destruction and the evasion of targeted financial sanctions under United Nations resolutions on North Korea and Iran. Prepared in response to the Financial Action Task Force’s revised Recommendation 1, it rates the securities sector low for proliferation financing in both the mainland and the financial free zones. It sets an overall country risk of medium-high. Banks, exchange houses and registered hawala providers are rated medium-high in the mainland, and maritime insurance is rated medium. For dealers, managers, advisers and custodians, it clarifies where risk concentrates and should inform screening and due diligence.

The table below summarises the residual risk ratings that the capital market sector should reflect in its own risk assessment.

UAE ML and TF National Risk Assessment 2024

The UAE Money Laundering and Terrorist Financing National Risk Assessment 2024 is the country’s second such assessment, prepared using the World Bank methodology and drawing on data from 2019 to 2023. It rates the securities sector’s residual money laundering risk in the medium to medium-high range, reflecting its diverse activities, while noting effective AML controls across the sector, and it covers both the mainland and financial free zones. Among other sub-sectors, banking and exchange houses are rated medium-high, registered hawala providers high, and finance companies and insurance medium. Overall, the national money laundering residual risk is medium-high. For dealers, managers, advisers and custodians, it sets the baseline informing their risk-based approach.

Assessment  Capital market (securities) sector residual risk 
Money laundering and terrorist financing (NRA 2024)  Medium to medium-high, with the sector’s AML controls assessed as effective 
Proliferation financing (PF NRA 2026)  Low in both the mainland and the financial free zones 
Sr Sub-Sector Residual ML Risk as per NRA 2024 
1 

Market Institutions and 

Brokers 

Medium-High 
2 

Investment Management  

 

Medium 
3 

Forex Companies  

 

Medium-High 
4 

Advisors and Promoters 

 

Medium 

Alongside the national assessments, sector risk assessments, red flag guidance, and typologies reports give capital market firms the detail they need to keep their enterprise-wide risk assessment current and defensible.

CMA-Regulated Capital Market Sector-Specific Guidance

Beyond the federal framework, the Capital Market Authority issues the rulebook, guidance, notices, and reporting standards that govern AML in the sector. The documents below make up that set.

A note on transition: the Capital Market Authority is the legal successor to the Securities and Commodities Authority under Federal Decree-Law No. 32 of 2025, so references to older SCA decisions, notices and guidance below should be read as references to the CMA where they remain in force, and subject to Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025.

Federal Decree-Law No. 32 of 2025 on the Capital Market Authority

Federal Decree-Law No. 32 of 2025 on the Capital Market Authority establishes the Capital Market Authority, successor to the Securities and Commodities Authority, as the federal regulator of securities, markets, central clearing and central depository institutions across the mainland and free zones, excluding the Financial Free Zones. It defines Licensed Persons, Approved Persons and Self-Regulatory Organisations, and gives the Authority objectives including market integrity and efficiency, investor protection and mitigation of systemic risk. Article 5 grants powers to license, supervise and inspect firms conducting financial activities, issue rules, impose sanctions and cooperate with relevant authorities. For broker-dealers, fund managers, advisers and custodians, it is the constitutional foundation of supervision.

Federal Decree-Law No. 33 of 2025 on the Regulation of the Capital Market

Federal Decree-Law No. 33 of 2025 on the Regulation of the Capital Market is the substantive rulebook governing securities activities under the Capital Market Authority. Article 3 lists the financial activities requiring a licence, spanning market operation, central clearing, central depository and custody services, dealing, asset management, investment funds and advisory work. It prohibits conducting these activities or performing approved functions without authorisation, and defines securities, issuers, foreign issuers, investment funds, insiders and inside information. The law restricts insider dealing and imposes prohibited dealing periods on those listed on the Market, protecting investors from market abuse. It also frames the settlement, restructuring and liquidation of Licensed Persons.

CMA Key AML/CFT/CPF Obligations, Risks and Supervisory Observations, 2025

This 2025 Capital Market Authority letter to Chief Executive Officers sets out Key AML/CFT/CPF Obligations, Emerging Risks and Supervisory Observations for securities firms. During the 2025 supervision cycle, the CMA ran its annual risk assessment across the sector, gauging inherent money-laundering, terrorist-financing and proliferation-financing risk against each firm’s nature, scale, customer base, products, delivery channels and geographic exposure, informed by the FATF Recommendations and the UAE National Risk Assessment. Through onsite inspections, desk-based reviews, MLRO report reviews and thematic work, it identified recurring deficiencies requiring remediation under board governance. It reminds broker-dealers and asset managers to track suspicious-reporting trends, sanctions-screening outcomes and beneficial-ownership data, warning of Article 17 enforcement.

CMA Instructions for the 2024 Annual Return AML/CFT and TFS Risk Assessment

The CMA Instructions for the 2024 Annual Return set out how licensed securities firms complete their AML, CFT and targeted financial sanctions risk assessment return. Broker-dealers, fund and asset managers, custodians and investment advisers report across five tabs: customer risk, products and services risk, distribution channel risk, controls and the quality of risk mitigation, and signatories. The Capital Market Authority requires full completion, monetary values in dirhams, and country breakdowns using standard country names or codes. The return captures inherent risk from investors, securities business, correspondent relationships, payment forms and onboarding channels, alongside controls covering the compliance officer, enhanced due diligence, transaction monitoring, sanctions screening and internal audit.

CBUAE AML and CFT Guidelines for Financial Institutions, July 2023

These CBUAE Anti-Money Laundering and Combating the Financing of Terrorism Guidelines for Financial Institutions, dated July 2023, are general financial-institution guidance that the Capital Market Authority points its firms toward for detailed expectations. Grounded in Federal Decree-Law No. 10 of 2025 and its implementing regulation, they explain the risk-based approach, business-wide risk assessment across customer, geographic, product and delivery-channel factors, and mitigation through internal controls and customer due diligence, including beneficial-owner identification, wire transfers and ongoing monitoring. For broker-dealers, fund managers, custodians and advisers, they translate statutory obligations, typologies and reporting duties into practical benchmarks that reinforce sound onboarding, screening and monitoring of investors and securities accounts.

CMA Minimum Standards for the Semi-Annual AML and CTF Report, 2023

These CMA Minimum Standards, dated 2023, guide the semi-annual Compliance Officer and Money Laundering Reporting Officer reports for securities firms, framed under Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025. Broker-dealers, fund managers and custodians must prepare bi-annual reports for the periods ending 30 June and 31 December, review them at board level, and submit a copy with the Board’s comments to the Capital Market Authority within two months of each period end. The prescribed structure runs from an executive summary through governance, the enterprise-wide risk assessment, policies, customer risk rating and due diligence, a gap analysis, action plan, findings and board approval.

CMA Implementation of Targeted Financial Sanctions, May 2022

CMA Notice 1/2022, dated 19 May 2022, directs all licensed financial institutions to implement Targeted Financial Sanctions under UN Security Council Resolutions 1718 (2006) and 2231 (2015), pursuant to Cabinet Resolution No. 74 of 2020. Broker-dealers, asset managers and custodians must screen every party to a financial transaction, apply enhanced due diligence to dealings linked to relevant countries, and verify cross-border flows suspected of unauthorised trade in dual-use goods. Confirmed matches require a Funds Freeze Report through goAML within five business days, potential matches a Partial Name Match Report, and suspicious activity an STR to the Financial Intelligence Unit. Firms should consult Executive Office guidance and prevent sanctions evasion.

CMA Awareness of Cabinet Resolution No. 111 of 2022 on Virtual Assets and their Service Providers

Cabinet Resolution No. 111 of 2022 regulates virtual assets and virtual asset service providers in the UAE, setting the federal framework that sits alongside the securities regime. For capital market firms, it matters wherever a product, custodian or client touches virtual assets: it defines VASP activities, licensing and the supervisory perimeter, and feeds the enhanced due diligence and reporting a securities or fund business must apply to virtual-asset exposure. It anchors the CMA’s own virtual-asset expectations and the UAE travel rule that follows.

CMA Thematic Review on Reliance on Third Parties, December 2021

This second CMA thematic review, dated December 2021, examined the five firms licensed for custody of securities, all banks or local branches of foreign banks holding Central Bank licences, testing compliance with FATF Recommendation 17 on reliance on third parties. Because custodians safeguard investors’ securities and cash and serve largely institutional and offshore clients, they frequently outsource customer due diligence. A twenty-one-question survey drew a hundred per cent response: four of five engaged third parties, two within their financial group and two external, all regulated or listed entities governed by service level agreements. Reasons cited were cost, specialist skills and technology; ultimate due diligence responsibility remains with the custodian.

CMA Thematic Review of Targeted Financial Sanctions in the Capital Market Sector, November 2021

This CMA thematic review, dated November 2021, assessed how securities brokerage firms understand and comply with Targeted Financial Sanctions, international and domestic, under Cabinet Resolution No. 74 of 2020. Brokers, the gateway for capital market investors and rated medium-high vulnerability in the National Risk Assessment, answered a twenty-nine-question survey with a ninety-six per cent response rate. Findings show sixty-five per cent ran separate sanctions risk assessments, seventy per cent used third-party screening systems, and eighty-one per cent screened daily; one firm found, reported and froze a match in 2021. Good practices cover senior-management approval, verifying vendor coverage of domestic lists, clear reporting responsibilities and Executive Office monitoring.

CMA AML and CFT Guidance for the Capital Market Sector, September 2021

The Capital Market Authority AML/CFT Guidance for the Capital Market Sector, dated September 2021, supplements the main Financial Institutions Guidelines and sets out the Securities and Commodities Authority’s expectations for firms it licenses. It applies to boards, management and employees of institutions carrying out securities activities in the UAE, read with those wider guidelines. Part 1 surveys sector typologies, including trade-based money laundering through mis-invoicing and misrepresentation of price, quantity or quality, and cash-based laundering, with red-flag indicators. Parts 2 and 3 explain the risk-based approach, business-wide risk assessment and the customer, product, delivery-channel and geographical risk factors that brokers, asset managers and advisers must identify, assess and mitigate.

CMA Notice 3/2021 on the Immediate Reporting Mechanism

Notice 3/2021, dated 26 July 2021, addressed all licensed entities and licensed securities and commodities exchanges on the immediate reporting mechanism for financial institutions implementing Cabinet Resolution No. 74 of 2020 on Terrorism Lists Regulation and the implementation of UN Security Council Resolutions on suppression of terrorism, terrorist financing and proliferation of weapons of mass destruction. Referring to Article 21, clause 5, it advised that the goAML system had been upgraded with a new feature so that reports on matched names and actions taken pass directly to the Executive Office for goods subject to import and export control. Broker-dealers, fund managers and custodians must update policies and implement the process.

CMA Notice 4/2021 on Targeted Financial Sanctions Reporting

Notice 4/2021, dated 4 August 2021, addressed all licensed entities and licensed securities and commodities exchanges on Targeted Financial Sanctions reporting, following the earlier 26 July notice. Under Cabinet Resolution No. 74 of 2020, the Central Bank of the UAE, coordinating with the Executive Office of the Committee for goods subject to import and export control, established a unified mechanism using the Financial Intelligence Unit’s goAML platform. It introduced two reports: the Funds Freeze Report for a confirmed match, requiring freezing within two business days, and the Partial Name Match Report for a potential match, requiring suspension. Broker-dealers, fund managers and custodians report simultaneously to the Executive Office and Authority. These notices predate the March 2026 sanctions guidance, so current goAML filings use the renamed Confirmed Name Match Report and the Partial Name Match Report; older notices should be read with that change in mind.

CMA Notice 6/2021 on the Update to High Risk Jurisdictions

CMA Notice 6/2021, dated 22 November 2021, updates the National Committee’s lists of High Risk Jurisdictions subject to a Call for Action and Jurisdictions under Increased Monitoring for all licensed entities and securities and commodities exchanges, superseding Notice 1/2021. Broker-dealers, fund managers, custodians and advisers must apply enhanced due diligence to relationships and transactions touching listed countries, adopt the Recommendation 19 countermeasures for the Black List, and refresh geographic risk scoring for investors. Firms are prohibited from relying on third parties based in Black List jurisdictions, must file High Risk Jurisdiction reports through goAML, and re-evaluate measures where countries are delisted, proportionate to securities-account risk.

SCA Board Chairman's Decision No. 21 of 2019 on AML and CFT Procedures

The SCA Board Chairman’s Decision No. 21/Chairman of 2019, issued on 8 May 2019 and active from 7 May 2019, applied anti-money laundering, counter-terrorism financing and illegal-organisations financing procedures to the capital market. Signed by Sultan bin Saeed Al Mansouri, it required every financial entity licensed or approved by the Securities and Commodities Authority, and its stakeholders, to comply with Federal Decree-Law No. 10 of 2025, its executive regulation under Cabinet Resolution No. 134 of 2025, and the Authority’s instructions, guidelines and circulars. It empowered the Authority to supervise and inspect firms without notice, demand information, and impose administrative sanctions on brokers, fund managers and other market participants.

CMA Guidelines for Combating Money Laundering and Terrorist Financing (Chapter Five)

Chapter Five of the Capital Market Authority rulebook sets out the Guidelines for Combating Money Laundering, Counter-Terrorism Financing and Funding of Illegal Organisations. It provides mandatory standards requiring each supervised firm to build a compliance programme tailored to its activities, risk profiles and controls, read with Federal Decree-Law No. 10 of 2025. The chapter defines suspicious transactions, ultimate beneficial owners and targeted financial sanctions, and directs firms to apply a proportionate risk-based approach to customer due diligence, focusing resources on higher-risk clients. It fixes board and senior-management responsibility, mandates suspicious-activity reporting as a legal duty, and covers screening, record-keeping and training that broker-dealers, fund managers and custodians must embed operationally. To the extent Chapter Five still refers to the 2025 framework, those references should now be read in light of Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025.

CMA AML and Financial Crimes Framework and Controls: Good and Weak Practices

Prepared by Mendy Ghaleb of the Capital Market Authority’s AML and Financial Crimes Department, this presentation contrasts good practices and common weaknesses in AML and financial-crime frameworks and controls. It anchors expectations in Federal Decree-Law No. 10 of 2025, Cabinet Resolution No. 134 of 2025, and the beneficial-owner, terrorism-list and sanctions decisions, alongside Chapter 5 of the CMA Rulebook. Through field inspections and desk-based analysis it flags recurring failings for securities firms, including generic business-wide risk assessments misaligned with activities, template risk-appetite statements without thresholds, and copied policies with limited board oversight. Under Article 17, the CMA may issue warnings, fines to AED 5,000,000, sector bans and licence revocation.

CMA Obligations to Implement the Business-Wide Risk Assessment (BWRA)

This Capital Market Authority material explains a securities firm’s obligation to implement a Business-Wide Risk Assessment, described as a fundamental, strategic discipline for an effective AML and CFT compliance framework. The BWRA requires firms to identify, understand and assess the full spectrum of money-laundering, terrorist-financing, targeted-financial-sanctions and proliferation-financing risks, examining client types, products, delivery channels, geographic locations and new technologies. It runs in three phases: planning and scoping across business units, legal entities, divisions and regions; implementation, assessing inherent risk with empirical data and designing controls; and results, defining residual risk against a risk-appetite statement with action plans. Broker-dealers, fund managers and custodians must keep it dynamic and updated.

CMA Thematic Review of Screening Systems

This CMA Thematic Review of Screening Systems, a market-wide horizontal assessment, examined name and transaction screening across the UAE capital market sector under Federal Decree-Law No. (10) of 2025 and FATF standards. The Capital Market Authority tested forty-six screening systems at twenty-six Licensed Financial Institutions using control, variation and clean datasets covering United Nations and UAE sanctions lists. Systems were widely embedded across broker-dealer, fund and custody onboarding and monitoring and identified clear matches well, but performance varied under complex scenarios such as spelling differences and Arabic-Latin transliteration. Elevated alert volumes signalled tuning opportunities. Supervisory expectations stress calibration, governance, management information, defined metrics like false positive rates, and ongoing optimisation.

CMA Questions and Answers on the National Risk Assessment

These CMA Questions and Answers explain how securities firms should align their Enterprise-Wide Risk Assessment with the 2024 National Risk Assessment. Broker-dealers, fund managers, custodians and advisers must map NRA typologies to their business, such as onboarding offshore special purpose vehicles, layering through securities trading, weak beneficial-owner documentation and misuse of layering and shell companies. Even low-risk firms must review the NRA, document relevance and reassess annually. The Capital Market Authority expects an audit trail: a date-stamped updated assessment, revised onboarding, screening and third-party reliance policies, staff training logs, board minutes and a gap analysis. Firms must reflect changes in the annual AML Return and evidence real implementation.

CMA Circular on the Examination Observations Report

This CMA circular reports examination observations drawn from securities firms’ annual AML/CFT and sanctions risk assessment returns, assessed under a risk-based approach against Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025. The Capital Market Authority found common shortcomings: outdated governance policies, weak testing of sanctions controls, incomprehensive risk assessments, gaps in customer due diligence and beneficial-ownership understanding of investors, incomplete sanctions compliance programmes lacking the eight essential components, and poor suspicious-transaction procedures. Firms should remediate, involve the board and auditors, and maintain adequate oversight. Non-compliance may trigger enforcement, including administrative penalties from AED 50,000 to AED 5,000,000 per violation and licence cancellation.

UAE Virtual Assets Travel Rule

The UAE Virtual Assets Travel Rule applies to virtual asset service providers across the federal, emirate and free-zone space, requiring originator and beneficiary information to travel with virtual-asset transfers. Capital market firms dealing in or advising on virtual-asset products, or holding them in custody, use it to understand the information that must accompany transfers and the risk-based and enhanced due diligence expected. It aligns the UAE with the FATF travel-rule standard and shapes how a securities business documents and screens virtual-asset movements.

CMA Chapter Five Outreach

Chapter Five Outreach explains the CMA’s Chapter Five Regulations for combating money laundering, terrorism financing and the financing of illicit organisations in plain, presentation form. It walks capital market firms through the mandatory standards, their grounding in federal AML law, and how the CMA expects brokerages, custodians and fund managers to apply them day to day. As an outreach companion to the binding Chapter Five guidelines, it is a practical reference for onboarding, monitoring and reporting across the securities sector.

CMA and FIU Joint Awareness Session on Suspicious Reporting Effectiveness

Delivered by the Capital Market Authority’s AML and Financial Crimes Department with the Financial Intelligence Unit, this joint session focuses on the effectiveness of suspicious reporting by capital market firms. It restates the key legislation, the obligations of financial institutions and the internal controls and governance the CMA expects, then presses on report quality: filing complete, timely and well-reasoned suspicious transaction and activity reports through goAML rather than defensive or low-value submissions. For a securities or fund business it sharpens what good reporting looks like.

CMA Examination Observations, Appendix of Detailed Findings

This appendix accompanies the CMA and Securities and Commodities Authority examination observations, collecting the detailed findings behind the headline review. It sets out, area by area, the weak and better practices inspectors saw across capital market firms, from governance and risk assessment to screening and reporting. For a brokerage or fund manager it doubles as a self-assessment checklist: read against your own programme, it flags the specific control gaps the regulator has already penalised in the sector.

Core AML Obligations for Capital Market Firms at a Glance

Whatever the licence, the AML regulations for capital market firms in the UAE turn on a common set of duties.

  • A business and enterprise-wide risk assessment aligned to the national risk assessments, submitted through the Capital Market Authority’s annual return.
  • Customer due diligence on investors and clients, and, for higher-risk relationships, enhanced due diligence, including source of funds for subscriptions and trades.
  • Ongoing monitoring of trading and settlement, and sanctions screening of clients and beneficial owners.
  • Suspicious transaction and activity reporting through goAML, an MLRO, and the Authority’s semi-annual and annual AML reporting.
  • Identifying the ultimate beneficial owner of corporate and pooled investors.
Control area  What CMA-regulated firms should evidence 
Business and enterprise-wide risk assessment  Risk assessed by customer, product, geography, delivery channel and new technology, aligned to the national risk assessments 
Investor onboarding  Customer identity, beneficial ownership, and source of funds and wealth for subscriptions and trades where relevant 
Sanctions screening  Screening of clients, prospective investors, beneficial owners and counterparties against the UAE Local Terrorist List and the UN Consolidated List 
Transaction monitoring  Monitoring of trading, settlement, subscriptions, redemptions and unusual investor activity 
Third-party reliance  A written reliance framework and audit trail, with final responsibility retained by the firm 
MLRO and reporting  Semi-annual AML and CTF report, annual AML, CFT and TFS return, and suspicious reporting through goAML 
Record keeping and governance  Records retained and retrievable for inspection, with board approval, risk appetite and compliance independence 

Practical Compliance Note:

Capital Market Authority supervisory materials and thematic reviews show recurring attention to sanctions-screening effectiveness and reliance on third parties for customer due diligence. Capital market firms should document how their screening system is calibrated and tested, how potential matches are handled, and the point at which reliance on an introducer ends and the firm’s own due diligence resumes.

Conclusion

AML regulations for capital market firms in the UAE run on two tracks: the federal AML law that applies to every financial institution, and the Capital Market Authority’s own rulebook, guidance, and reporting regime on top. Broker-dealers, fund and asset managers, investment advisers, and custodians all sit inside that framework, supervised by the Authority rather than the Central Bank. The sector’s money laundering risk is rated in the medium range with effective controls, and its proliferation financing risk is low, but the reporting and examination expectations are demanding. Use the national risk assessments to calibrate, and read across to our guide to anti-money laundering laws in the UAE and the pillar on AML regulations for banks and financial institutions in the UAE.

Frequently Asked Questions

Which capital market firms are subject to AML rules in the UAE?

Broker-dealers, fund and asset managers, investment advisers, custodians, and other market intermediaries licensed by the Capital Market Authority are financial institutions under Federal Decree-Law No. 10 of 2025 and must run a full AML programme. Firms in the DIFC and ADGM are supervised separately by the DFSA and FSRA.

The Capital Market Authority, established under Federal Decree-Law No. 32 of 2025 as the successor to the Securities and Commodities Authority, supervises AML compliance for capital market firms outside the financial free zones. It issues the sector rulebook and guidance and runs examinations and thematic reviews.

Firms must maintain a business-wide risk assessment, perform customer due diligence and enhanced due diligence on investors and beneficial owners, screen against sanctions lists, monitor trading and settlement, keep records, and report suspicious activity through goAML. The Authority pays particular attention to screening systems and reliance on third parties.

Yes. Firms must appoint a money laundering reporting officer, file suspicious transaction and activity reports through goAML, and submit the Capital Market Authority’s semi-annual AML and CTF report and annual AML/CFT and TFS risk assessment return.

Virtual asset service providers sit under a separate framework, distinct from the securities regime covered here: the federal CMA regime applies outside the financial free zones and works alongside local licensing authorities, including Dubai’s Virtual Assets Regulatory Authority. Firms with that exposure should refer to our dedicated guide to AML for VASPs outside Dubai, which addresses that demand in full.

Yes, where they remain in force and are not inconsistent with the 2025 framework. The Capital Market Authority is the legal successor to the Securities and Commodities Authority under Federal Decree-Law No. 32 of 2025, so older SCA decisions, notices and guidance are read as CMA materials, subject to Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025.

Yes. The Capital Market Authority requires a business-wide or enterprise-wide risk assessment covering customer, product, delivery-channel, geographic, targeted financial sanctions, proliferation financing and new-technology risks, aligned to the UAE national risk assessments and reflected in the Authority’s annual AML return.

Need help building or reviewing your capital market firm AML programme?

Get expert support to develop a robust AML programme that protects your business, manages risk, and meets regulatory expectations.

Share via :

About the Author

Pathik Shah

FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)

Pathik is an ACAMS-certified AML consultant specialising in governance, risk, and compliance for regulated entities in the UAE. He brings over 28 years of experience, with 1,000+ hours of AML training and 200+ advisory engagements across DNFBPs, VASPs, and FIs. He supports businesses in aligning with AML/CFT requirements from the CBUAE, DFSA, MoET, MoJ, VARA, CMA, FSRA, and FATF. Known for translating complex regulations into audit-ready procedures, Pathik enables operational clarity and compliance readiness.

Reach Out to Pathik

AML Regulations for Exchange Houses in UAE

AML Regulations for Exchange Houses in UAE

Blogs

Published On: 07/13/2026

Table of Contents

Protect your business with reliable and effective AML strategies with AML UAE.

Last Reviewed On: 07/13/2026   |   Last Updated On: 07/13/2026

Key Highlights

  • Exchange houses are Licensed Financial Institutions under Federal Decree-Law No. 10 of 2025 and its Executive Regulations in Cabinet Resolution No. 134 of 2025, so CBUAE guidance for LFIs is relevant to them, some of it applying generally and some depending on the firm’s products, customers, corridors and delivery channels.
  • The Central Bank of the UAE is the primary AML/CFT/CPF supervisor for exchange houses, while the UAE FIU, the Executive Office and other competent authorities carry reporting, sanctions and enforcement roles. Money service businesses in the DIFC and ADGM answer to the DFSA and FSRA and sit outside this guide.
  • The sector’s residual money laundering risk is rated medium-high in the national risk assessment, driven by banknote shipments, reliance on foreign remittance partners, and third-party transactions.
  • The risks that matter most are structured cash at the counter, high-risk remittance corridors, and third-party senders and beneficiaries, so transaction monitoring and sanctions screening are central.
  • On top of the general LFI framework, the Central Bank issues guidance written specifically for exchange houses, including a dedicated typologies report on money and value transfer services.
  • Registered hawala providers are covered under their own framework, which we treat separately, and this article links across to it.

Exchange houses move money for millions of people in the UAE, sending remittances home for workers, exchanging currency, and trading banknotes at scale. That same speed, cash intensity, and cross-border reach are exactly what make the sector attractive to money launderers and sanctions evaders, which is why the Central Bank supervises it closely. This guide sets out the AML regulations for exchange houses in the UAE: who is in scope, who supervises them, the full legal framework that applies, and how the national risk assessments rate the sector’s money laundering, terrorist financing, and proliferation financing risk. It covers exchange houses and money transfer businesses licensed by the Central Bank of the UAE.

Exchange houses licensed by the Central Bank of the UAE must comply with the applicable UAE AML/CFT/CPF framework, including Federal Decree-Law No. 10 of 2025, Cabinet Resolution No. 134 of 2025, Cabinet Resolution No. 74 of 2020, the CBUAE exchange business standards, relevant CBUAE AML/CFT guidance, and UAE FIU goAML reporting requirements. The sector’s key AML risks are cash-intensive transactions, cross-border remittances, high-risk corridors, banknote shipments, third-party senders, and sanctions exposure.

Who counts as operating in the Exchange House Sector for AML purposes in the UAE?

An exchange house, for AML purposes, is a business licensed by the Central Bank of the UAE to carry on exchange business, whether that is currency exchange, remittance, or the wholesale movement of banknotes. The categories below all sit inside the AML regulations for exchange houses in the UAE. Registered hawala providers operate under a separate registration framework and are dealt with on their own page, and money service businesses in the DIFC and ADGM are supervised by the DFSA and FSRA and are not covered here.

Currency exchange and money changing

Firms that buy and sell foreign currency for retail and corporate customers, often on a walk-in, one-off basis, sit at the front of the sector. Their exposure runs through cash, rapid conversion between currencies, and customers the firm may deal with only once.

Remittance and money transfer

Outbound and inbound remittance is the sector’s highest-volume activity, moving value across borders through corridors that vary widely in risk. Reliance on foreign remittance partners, third-party senders and beneficiaries, and the Wage Protection System all shape the money laundering and sanctions risk here.

Wholesale banknote trading

Exchange houses that import and export physical banknotes in bulk carry a distinct risk, since large cross-border banknote shipments can be used to move value outside the transparent payment system.

AML Supervisory Authority for Exchange Houses in the UAE

The Central Bank is the primary supervisor for exchange houses, while other competent authorities carry reporting, sanctions and enforcement roles.

Central Bank of the UAE (CBUAE)

The Central Bank of the UAE licenses exchange houses, sets the exchange business standards they operate under, supervises their AML programmes, issues sector guidance, and inspects them. It can impose administrative and financial penalties, restrict activities, or withdraw a licence for breaches. It is the primary AML/CFT/CPF supervisor for the sector, working alongside the UAE FIU, the Executive Office for Control and Non-Proliferation and other competent authorities that carry reporting, sanctions and enforcement roles. Money service businesses established in the DIFC and ADGM are supervised instead by the DFSA and FSRA under their own AML rulebooks, while still operating within the wider UAE AML/CFT framework, and fall outside this guide.

UAE FIU and goAML

In-scope exchange houses must register on the UAE Financial Intelligence Unit’s goAML platform and use it to submit suspicious transaction reports, suspicious activity reports, targeted financial sanctions filings and other required reports where applicable. See our goAML registration guide for the practical steps.

AML Legal Framework Applicable to Exchange Houses in the UAE

The framework has five layers: the core federal laws, the guidance that applies to all reporting entities, the national risk assessments, the Central Bank’s general guidance for licensed financial institutions, and the Central Bank’s exchange-house-specific guidance. This section catalogues each layer, grounded in the official CBUAE AML/CFT and exchange business materials. Because exchange houses are Licensed Financial Institutions, CBUAE guidance for LFIs is relevant to them, some of it applying generally and some depending on the firm’s products, customers, corridors and delivery channels. Older guidance, standards and outreach material should be read together with, and subject to, Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025, to the extent they remain in force and are not inconsistent with the current framework.

The table below shows how these layers fit together, from the core statute down to the risk assessments that calibrate day-to-day controls.

Layer Instrument Why it matters 
AML statute Federal Decree-Law No. 10 of 2025 Core AML/CFT/CPF offences, FIU powers, reporting and penalties 
Executive regulation Cabinet Resolution No. 134 of 2025 Practical duties: risk-based approach, CDD, EDD, monitoring, beneficial owner, STR and records 
Central Bank regulatory law Federal Decree-Law No. 6 of 2025 Central Bank and licensed financial activity framework (regulatory background) 
Sanctions framework Cabinet Resolution No. 74 of 2020 and EOCN guidance Screening, freezing, confirmed and partial name match reporting, and sanctions reporting 
Exchange-house standards CBUAE Standards for Exchange Business, Chapter 16 Sector-specific AML/CFT compliance programme 
CBUAE LFI guidance STR, CDD, transaction monitoring, TFS, payments, PEPs, VASPs, PF and TBML Supervisory expectations for licensed financial institutions 
NRA and PF NRA UAE ML/TF NRA 2024 and UAE PF NRA 2026 Baseline for the exchange house risk assessment 

Federal AML Laws and Executive Regulations Applicable to Exchange Houses in the UAE

These instruments are the legal foundation for every exchange house in scope.

Federal Decree-Law No. 10 of 2025 on AML, CFT and CPF

For an exchange house moving outbound and inbound remittances and dealing in currency, Federal Decree-Law No. 10 of 2025 is the source of the whole obligation to fight money laundering, terrorist financing and proliferation financing. It fixes the definitions that shape how the firm screens walk-in and one-off customers, third-party senders and beneficiaries, and recognises that the crime can travel through digital systems, virtual assets and cryptographic technologies. It establishes the Financial Intelligence Unit as the destination for the exchange house’s suspicious transaction reports, empowers that Unit to demand further information, and provides for temporary suspension and freezing measures within the limits and procedures set by the law and the related FIU regulation. Supervision and penalties flow from here.

Cabinet Resolution No. 134 of 2025, the Executive Regulations

Cabinet Resolution No. 134 of 2025 issues the Executive Regulations of Decree-Law No. 10 of 2025, turning the statute into the working rulebook a money transfer business runs on. It confirms that funds transfers and money and currency exchange fall within scope, including services offered through agents and brokers, and defines wire transfers, intermediary and beneficiary institutions, and beneficial owners. From here come the substantive duties: a risk-based approach, customer due diligence and beneficial owner verification on customers and originators, screening of beneficiary information, and ongoing monitoring with refreshed records. The exchange house must adopt internal policies approved by senior management and proportionate to its remittance and cash-intensity risks, and meet the wire transfer requirements that supervisors test.

Cabinet Resolution No. 109 of 2023 on beneficial owner procedures

When a corporate customer walks in to send a wholesale remittance or trade banknotes, the exchange house must know who really stands behind it, and Cabinet Resolution No. 109 of 2023 supplies that transparency. It defines the real beneficiary as the natural person who ultimately owns or controls a legal person, or on whose behalf transactions are conducted. It obliges legal persons to obtain accurate, up-to-date beneficial owner information, identify nominee board members, and maintain a real beneficiary register and a shareholders register, updated generally within fifteen days of any change. These records feed the firm’s due diligence. They apply to legal persons licensed or registered in the State, including commercial free zones, but exclude the financial free zones, the DIFC and ADGM, which operate their own beneficial ownership regimes.

Cabinet Resolution No. 132 of 2023 on penalties for beneficial owner violations

Cabinet Resolution No. 132 of 2023 puts teeth behind the beneficial ownership rules by setting the penalties for breaching Cabinet Resolution No. 109 of 2023. It empowers the registrar to fine legal persons that fail their obligations, such as keeping accurate registers, per a schedule annexed to the Resolution and without prejudice to other sanctions. Consequences escalate: on a third violation, the registrar may suspend the licence and close the premises until the fine is paid and the breach is corrected. For an exchange house, this shows why the corporate remitters it onboards must keep ownership data current. These penalties apply to legal persons licensed or registered in the State, including commercial free zones, but not to the financial free zones, the DIFC and ADGM, which follow their own regime.

Cabinet Resolution No. 74 of 2020 on terrorist lists and UNSC resolutions

Sanctions screening sits at the core of an exchange house, and Cabinet Resolution No. 74 of 2020 defines it. It regulates the UAE terrorist lists, gives effect to the local Cabinet list and the United Nations Security Council lists, and requires that freezing measures be applied without delay, meaning within twenty-four hours. Practically, the firm must register on the Executive Office website to receive designation and de-listing notices, then continuously screen its customer database, potential clients, beneficial owners and the parties to every remittance, including third-party senders and beneficiaries, both routinely and whenever the lists change. On any match, the exchange house freezes without delay, enforces unfreezing decisions and reports to its supervisor.

Federal Law No. 7 of 2014 on combating terrorism crimes

Federal Law No. 7 of 2014 on Combating Terrorism Crimes is the criminal statute that these controls serve. It defines terrorist crime, terrorist purpose, terrorist organisation and terrorist person, distinguishes conventional from nonconventional weapons, and prescribes penalties up to life imprisonment and, in cases, death. For a money transfer business, the sharpest edge is terrorism financing: it penalises anyone who provides, collects, prepares or maintains funds, or helps obtain them, for a terrorist organisation, person or crime, and addresses freezing funds suspected of such a purpose held with financial institutions. Because the wider framework defines terrorist acts by reference to this law, it explains what an exchange house’s remittance screening must detect.

Some of the CBUAE, FIU and supervisory materials below were first issued under the earlier 2018 and 2019 AML frameworks. They should be read subject to Federal Decree-Law No. 10 of 2025, Cabinet Resolution No. 134 of 2025 and later rulebook updates, and only so far as they remain in force and are not inconsistent with the current framework.

AML Guidance Applicable to All Reporting Entities

Beyond the core laws, the Central Bank, the FIU, and the Executive Office issue guidance and typologies that apply to all reporting entities, exchange houses included.

UAE FIU Regulation No. 1 of 2026 on Suspension and Freezing Powers, April 2026

UAE FIU Regulation No. 1 of 2026, dated April 2026, governs the postponement or suspension of suspicious transactions and the freezing of funds. Issued under the AML/CFT Decree-Law, it applies to reporting entities, including exchange houses, and complements existing suspicious transaction reporting duties. It introduces the Postponement Suspicious Transaction Report, an urgent filing where a remittance or withdrawal suspected of criminal links is about to be transferred, drawn down or dissipated. It sets a monetary threshold that falls away for higher-threat predicate offences, third-party laundering, organised crime or terrorist financing, and defines a Suspension Order of up to ten working days and a Freezing Order of up to thirty days.

UAE FIU Strategic Analysis Report on Human Trafficking, April 2026

The UAE FIU Strategic Analysis Report on Human Trafficking, dated April 2026, analyses money laundering flows tied to trafficking, drawing on suspicious transaction and activity reports filed with the Financial Intelligence Unit. It covers objectives, methodology and scope, and the main forms of trafficking, including sexual exploitation, forced labour and organ removal. It sets out patterns across themes such as adult and child exploitation, forced labour and proceeds laundering, profiles the subjects involved, including designated traffickers, organised crime groups, foreign politically exposed persons and money mules, and assesses vulnerable sectors. It then develops risk indicators around customer profile, behaviour and transactional activity, helping exchange houses spot mules moving trafficking money.

Guidance on Targeted Financial Sanctions for Financial Institutions, DNFBPs and VASPs, March 2026

First published in January 2021 and last amended in March 2026, this Executive Office guidance clarifies targeted financial sanctions obligations for financial institutions, DNFBPs and VASPs. It sets out four duties central to any exchange house: registering in the Notification Alert System; screening customers, senders and beneficiaries against the UAE Local Terrorist List and the United Nations Consolidated List; freezing funds without delay and never releasing them to designated persons; and reporting the measures taken. It explains ownership, control and acting-on-behalf concepts that matter for third-party remittances. The March 2026 update renames the Funds Freeze Report as the Confirmed Name Match Report and addresses screening during weekends and public holidays.

Joint Guidance on the Compliance Officer and MLRO, 2026

Issued in 2026 by the UAE Supervisory Sub-Committee, this joint guidance sets a unified framework for appointing, empowering and defining the Compliance Officer or Money Laundering Reporting Officer across regulated sectors, including firms supervised by the Central Bank that licenses exchange houses. Building on Federal Decree-Law No. 10 of 2025, Cabinet Resolution No. 134 of 2025 and the 2025 legal framework, it treats the role as a cornerstone of effective AML, CFT and counter-proliferation work. It sets expectations on appointment and resignation, requiring seniority, experience, operational independence, freedom from conflicts, direct board access and adequate resources, and covers the compliance function, its outsourcing and the officer’s duties.

FIU Strategic Analysis Report on Terrorist Financing, May 2025

Published in May 2025 by the UAE Financial Intelligence Unit, this strategic analysis on terrorist financing typologies and facilitators draws on Unit data from 2021 to 2024, including suspicious transaction and activity reports, disseminated cases and open source material. For exchange houses it is especially pointed, identifying how terrorist funds move through financial institutions, unlicensed hawala, corporate networks, trade-based schemes, high-value goods, real estate, virtual assets and crowdfunding. It profiles facilitators such as designated individuals, family members, money mules, corporate nominees and professional intermediaries who sit behind third-party senders and beneficiaries. The developed risk indicators help remittance staff detect, trace and report attempts to obscure funds through one-off and layered transfers.

goAML FAQs, April 2024

The goAML FAQs, version 2.1 dated 18 April 2024, is a practical question and answer guide from the UAE Financial Intelligence Unit to help reporting entities use the goAML system and its registration and access services. It walks through common snags such as expired one-time passwords at first login, pop-up authentication screens requiring the system-issued username with a Google Authenticator passcode, the correct login sequence through the services portal, and resetting a forgotten password. It sets out where to enter credentials, which emails issue usernames and codes, and who to contact when errors persist. For an exchange house, reliable goAML access underpins timely reporting.

PF Institutional Risk Assessment Guidance for FIs, DNFBPs and VASPs, December 2023

Published in December 2023, this guidance sets out how financial institutions should assess and manage exposure to proliferation financing, built around inherent risks, control effectiveness and residual risks. It names the risk categories and factors an exchange house should weigh when scoring its remittance and currency exchange business. Mitigating measures span client onboarding, know your customer and due diligence, enhanced due diligence, screening customers for sanctions and adverse media, ongoing and transaction monitoring, suspicious activity reporting, and employee training. A customer risk scoring questionnaire, elevated risk factors and worked case studies, including sanctions and adverse media matches, show how to calibrate controls and document risk decisions supervisors can review.

Terrorist and Proliferation Financing Red Flags Guidance, December 2023

Updated in December 2023, this Red Flags Guidance gives exchange houses a consolidated set of indicators for spotting terrorist and proliferation financing, including attempts to evade targeted financial sanctions imposed under UN Security Council Resolutions or local designations. It flags evasion tactics such as renaming, front companies, intermediaries and alternative financial networks that a walk-in remitter or third-party sender might exploit. The document first sets out the legal basis for reporting, then lists terrorist financing indicators followed by proliferation ones grouped by customer profile, account and transaction activity, maritime and trade finance, with sanctions appendices. For counter staff and compliance teams it sharpens detection and guides reporting decisions.

Suspicious Activity and Transaction Reporting Thematic Review, January 2023

Issued in January 2023, this thematic review sets out findings and regulatory expectations from the 2022 AML and CFT examination of licensed financial institutions and DNFBPs, focusing on the suspicious transaction and activity reporting framework and the transaction monitoring systems that feed it. It is meant to be read alongside existing guidance on reporting and on monitoring and sanctions screening. It contrasts acceptable and deficient practice across governance, policies, risk-based deployment of monitoring, data management, alert review, case investigation, reporting decisions and the post-reporting process. It applies expressly to exchange houses alongside banks, finance companies and payment providers, offering a benchmark to test remittance monitoring and close gaps before inspection.

Counter Proliferation Financing Guideline, November 2022

Published in November 2022 by the Executive Office for Control and Non-Proliferation, this guideline supplements the wider Guidance on Targeted Financial Sanctions and raises awareness of proliferation financing threats among regulated entities. For an exchange house, it explains how weapons-related funds can be raised or moved through remittances and currency exchange, and how to fold proliferation risk into the firm’s own risk assessment. It sets out preventive measures including enhanced due diligence on customers and transactions, alertness to shell and front companies, dual-use goods and trade routes, and staff training. The red flag list helps counter staff spot sanctions evasion attempts by walk-in and corporate senders.

goAML Web Submission Guide, July 2022

The goAML Web Submission Guide, issued by the UAE Financial Intelligence Unit in July 2022, sets out how to submit a report to the FIU through the goAML platform. It is addressed to the designated Compliance Officer or Money Laundering Reporting Officer of a registered reporting entity, or the deputy where the lead officer is unavailable. It reviews the report types, including the Suspicious Transaction Report and the Suspicious Activity Report, the latter covering suspected activity or an attempted, non-executed transaction, plus Additional Information Files and High Risk Country reports. It explains access for Central Bank-regulated and other entities, then covers selecting a report, completing the cover, and submitting.

Joint Guidance on Combating the Use of Unlicensed Virtual Asset Providers, March 2022

Issued in March 2022, this joint guidance from the UAE Supervisory Authorities, including the Central Bank, the Securities and Commodities Authority and the Virtual Assets Regulatory Authority, aligns with FATF’s risk-based approach and warns the public and regulated firms about unlicensed virtual asset providers. It urges confining virtual asset dealings to licensed entities and reminds exchange houses of their AML obligations. Expectations include vigilance to fraud, factoring emerging risks into assessments, adequate due diligence, spotting customers who seek unlicensed providers, and reporting suspicions. Red flags include no licence, no physical presence, unrealistic promises or Ponzi schemes, poor websites and pressure to invest quickly, helping counter staff intercept suspect remittances.

IEMS User Guide for Reporting Entities, March 2022

Dated March 2022, this practical manual from the UAE Financial Intelligence Unit explains its Integrated Enquiry Management System, which automates information requests, prosecution decisions and other AML and CFT instructions from domestic authorities. It provides an end-to-end flow between the Unit, the authorities and reporting entities such as exchange houses. Firms already registered on goAML reuse those credentials, reaching the system through the Services Portal or eServices Portal. The guide walks through the dashboard, request management and the reply workflow covering account holder and signatory details, and sets out Admin, Maker and Checker roles. It stresses meeting due dates and implementing freeze orders immediately on the amount or whole balance.

goAML Pre-Registration Guide, March 2022

The goAML Pre-Registration Guide, issued by the UAE Financial Intelligence Unit in March 2022, explains how reporting entities gain access to the Services Access Control Manager, or SACM, before reaching goAML to register and file suspicious reports. The application is reached through a public portal for entities not regulated by the Central Bank of the UAE, except hawaladars, with entities under various Supervisory Bodies following the stated steps. SACM hosts the links to the production and testing environments, secured by a time-based one-time password from Google Authenticator. The guide covers pre-registration, confirming intent, and safeguarding a personal Secret Key issued after FIU due diligence, which cannot be shared.

goAML Registration Guide, March 2022

The goAML Registration Guide, issued by the UAE Financial Intelligence Unit in March 2022, sets out how an organisation registers with the FIU on its reporting platform, goAML. It applies to registration as a reporting entity, a stakeholder or a supervisory body, and confirms that every accountable and reporting entity in the UAE, whoever its regulator, must register to submit suspicious reports. Access runs through the Services Access Control Manager, with Central Bank-regulated institutions needing a dedicated MPLS link and others over the internet. It walks through selecting the registration type, entering organisation and address details, adding the registering person, uploading attachments, setting access rights and resetting passwords.

Strategic Review on Targeted Financial Sanctions Case Studies, November 2021

Dated November 2021, this strategic review examines targeted financial sanctions reporting in the United Arab Emirates, sitting within the framework by which the UAE, through Cabinet Resolution No. 74 of 2020, implements United Nations Security Council Resolutions on terrorism, terrorist financing and proliferation, including freezing measures and prohibitions on providing funds. It sets out its methodology, then classifies sanctions reports by source, by suspicion and by instrument. It distinguishes terrorist financing patterns from proliferation patterns and presents red flags, statistics and recommendations, plus the Executive Office’s role in circulating list updates. For an exchange house, it shows how sanctions suspicions arise and are reported, sharpening screening across remittance flows.

Typologies on the Circumvention of Targeted Sanctions, November 2021

Last amended in November 2021 and issued by the Executive Office, this typologies report compiles cases showing how sanctioned persons, groups and entities try to circumvent targeted sanctions relating to terrorism and the proliferation of weapons of mass destruction. Drawing on public UAE and foreign sources, it groups methods by channel, expressly covering exchange houses alongside banking services, money remitters, hawala and similar providers, online payment facilities, misused non-profits, cash and gold smuggling, trade in dual-use goods, misused legal entities and virtual assets, plus proliferation-side banking and cyberactivity. Illustrated with named case networks and red flags, it turns evasion tactics into learning that sharpens screening, due diligence, monitoring and reporting.

Update to the List of High Risk Jurisdictions, November 2021

This November 2021 decision of the National Anti-Money Laundering and Combating the Financing of Terrorism and Financing of Illegal Organizations Committee updates the list of high-risk jurisdictions subject to a call for action, the list under increased monitoring, and the counter-measures to apply. It is addressed to bodies including the supervisory authorities and the Financial Intelligence Unit, and revises an earlier March 2021 decision. Reflecting the Committee’s mandate to identify high-risk countries and set proportionate counter-measures, it instructs supervisors to ensure due diligence is applied. For exchange houses, it signals which remittance corridors warrant enhanced due diligence and keeps customer and transaction risk ratings aligned with the latest listings.

Joint Guidance on Satisfactory and Unsatisfactory Practice, June 2021

Issued in June 2021 by the UAE Supervisory Authorities, including the Central Bank, the DFSA, the FSRA, the Securities and Commodities Authority and the Ministries of Justice and Economy, this joint guidance draws on inspections between January 2020 and May 2021. It contrasts satisfactory and unsatisfactory practice across the AML framework, targeted financial sanctions and counter proliferation financing. For an exchange house it covers governance and management oversight, the risk assessment, three lines of defence, policies, training and the compliance officer or MLRO role, plus customer onboarding, monitoring, risk rating, due diligence, transaction monitoring, sanctions screening and record keeping, letting firms benchmark controls before an examination exposes weaknesses.

Typologies on the Circumvention of TFS, PF and WMD, May 2021

Last amended in May 2021 and issued by the Executive Office, this typologies report examines how sanctioned persons and entities receive financing in violation or evasion of UN Security Council Resolutions on terrorism and the proliferation of weapons of mass destruction. It explains that targeted financial sanctions cover both asset freezing and bans on making funds available, directly or indirectly, to designated parties. Organised by method, it addresses the misuse of banking services, money remitters, hawala and similar providers, online payment facilities, non-profits and cash smuggling on the terrorist side, and banking, cyberactivity, trade and legal entities on the proliferation side, closing with red flags drawn from real cases.

goAML FAQs, September 2020

The goAML FAQs Guide, version 1.5 dated 8 September 2020 from the UAE Financial Intelligence Unit, answers the practical questions reporting entities raise while using the goAML portal, from resetting a forgotten password to fixing a rejected submission. For an exchange house filing frequent remittance-related suspicious transaction reports, it is a quick reference for the operational snags that would otherwise stall a filing, covering login and access, report status and common submission errors. It sits alongside the newer April 2024 FAQs and keeps the compliance team moving when the portal behaves unexpectedly.

goAML Registration Guide Stage 2, September 2020

The goAML Registration Guide, version 3.3 dated 16 September 2020, sets out how an organisation registers with the UAE Financial Intelligence Unit as a reporting entity, stakeholder or supervisory body. It applies to every accountable and reporting entity whatever its regulator, so a newly licensed exchange house follows it to secure goAML access before filing its first suspicious transaction or activity report. It works through organisation and user details, document uploads and approval, giving the exchange house its onboarding path onto the single national reporting channel.

Guideline on Grievance Procedures

Issued by the Executive Office for Control and Non-Proliferation, this guideline explains how grievance requests tied to the UAE Local Terrorist List and the United Nations Consolidated List, collectively the Sanctions Lists, are submitted and reviewed. Under Cabinet Resolution No. 74 of 2020 it covers three request types: de-listing a designation, lifting freezing measures, and seeking permission to use frozen funds. For each it distinguishes Local List designations by the UAE Cabinet from United Nations designations by the Security Council. It clarifies the procedures apply only to Sanctions List freezes, not court orders. For an exchange house, it maps the lawful routes a frozen remittance customer can take.

Online Grievance System User Guide

This user guide from the Executive Office for Control and Non-Proliferation walks applicants through its Online Grievance System, launched to streamline requests relating to the UAE Local Terrorist List and the United Nations Consolidated List, collectively the Sanctions Lists. It explains how to submit the three online request types: de-listing, cancellation of freezing measures, and permission to use frozen funds. Users identify the aggrieved individual or entity, select the relevant list and grievance type, declare previous requests, attach documents and give contact details. It notes the form is in Arabic while the manual is in English. For exchange houses, it shows the route a frozen remittance customer can follow.

Simple Guide to Subscribe to the EOCN Notification Alert System (NAS)

This short guide explains how to subscribe to the Notification Alert System on the Executive Office’s website so users receive timely updates to the sanctions lists applied in the United Arab Emirates. Targeted financial sanctions rest on two lists, collectively the Sanctions Lists: the UAE Local Terrorist List issued by the Cabinet, and the United Nations Consolidated List issued by the Security Council, both updated periodically. It shows where the lists sit and gives step by step subscription instructions through to confirmation. For an exchange house, this supports a core control: screening senders and beneficiaries only works against current lists, and prompt alerts let counter staff apply freezes without delay.

Emerging ML, TF and PF Risks and Trends in the Financial Sector

Issued by the Supervisory Subcommittee under Article 16 of Federal Decree-Law No. 10 of 2025, this report gives regulated firms a current picture of the money laundering, terrorist financing and proliferation financing threats reshaping the sector. Its typologies and red flags can be factored into exchange house risk assessments and monitoring. It examines abuse of artificial intelligence, greenwashing and ESG-related fraud, trade finance misused for proliferation, growth in illicit virtual asset transactions, and sanctions evasion linked to the Commonwealth of Independent States. Case studies on money mule networks, trade-based laundering and virtual asset conversion, plus typologies in stored value and retail payment services, sharpen detection of layered remittance flows.

Typologies in the Financial Sector

Typologies in the Financial Sector is a joint report from the Supervisory Authorities Sub-Committee and the Financial Intelligence Unit, developed with the Executive Office and a pilot group of firms. It shares money laundering, terrorist financing, sanctions, fraud, and bribery and corruption typologies seen in the market, several surfacing during the COVID-19 pandemic, to help the private sector anticipate emerging risks. Sitting above the National Risk Assessment, it flags the growing use of unlicensed money service operators that settle books over time rather than moving each transfer individually, lists indicators that combine to obscure a transaction, and notes links to modern slavery and human trafficking.

NRA, SRA, and Other Important Guidelines for Exchange Houses in UAE

The UAE assesses its money laundering, terrorist financing, and proliferation financing risk at national level, and exchange houses must align their own business and enterprise-wide risk assessments to those findings.

UAE PF National Risk Assessment 2026

The UAE Proliferation Financing National Risk Assessment 2026 rates exchange houses medium-high in the mainland, exposed mainly through currency exchange and cross-border transfers that sanctioned networks may exploit to evade targeted financial sanctions relating to the Democratic People’s Republic of Korea and Iran. Prepared in response to FATF revised Recommendation 1, it examines threats and vulnerabilities across mainland and free zone sectors on a low-to-high scale, with overall country risk medium-high. Virtual asset service providers rate highest at high; banks and hawala providers medium-high; free zone banks and money service businesses medium; maritime insurance medium to medium-low; and stored value facilities medium-low. It should shape sanctions screening and due diligence.

The table below summarises the residual risk ratings the exchange house sector should reflect in its own risk assessment.

UAE ML and TF National Risk Assessment 2024

The UAE Money Laundering and Terrorist Financing National Risk Assessment 2024, the country’s second, rates the exchange house sub-sector residual medium-high, driven by cash intensity, banknote shipments, reliance on foreign remittance partners and third-party transactions. Prepared using the World Bank methodology on data from 2019 to 2023, it identifies threats, vulnerabilities and residual risks across the mainland and financial free zones, with overall national money laundering risk medium-high and drug trafficking and fraud among the highest threats. Registered hawala providers are rated high, banks medium-high, finance companies and insurance medium, and securities medium to medium-high. For exchange houses, it sets the baseline that should shape customer risk ratings and controls.

Assessment Exchange house sector residual risk 
Money laundering and terrorist financing (NRA 2024) Medium-high, driven by banknote shipments, reliance on foreign remittance partners, and third-party transactions 
Proliferation financing (PF NRA 2026) Medium-high in the mainland, through currency exchange and cross-border transfers 

Alongside the national assessments, sector risk assessments, red flag guidance, and typologies reports give exchange houses the detail they need to keep their enterprise-wide risk assessment current and defensible.

CBUAE Guidance Applicable to Exchange Houses in UAE

The Central Bank’s guidance for licensed financial institutions applies to exchange houses as Licensed Financial Institutions. The documents below make up that guidance set.

CBUAE Best Practices for Licensed FIs on Implementing Role-Based AML/CFT/CPF Training, October 2025

Published in October 2025, the CBUAE Best Practices on Implementing Role-Based AML/CFT/CPF Training shows exchange houses how to tailor learning to each job rather than issuing one generic course. Counter and teller staff handling walk-in remittances, and compliance teams overseeing corridors, receive content matched to their own exposure and to the red flags of money laundering, terrorist financing and proliferation financing they realistically meet. The guidance applies a risk-based approach so frequency and intensity track each role’s risk, spanning regulatory requirements, global standards, internal policies, products, customers and geographies. It covers the Board, senior management, the three lines of defence, delivery methods, documentation and records.

CBUAE Best Practices for Licensed FIs on a Risk-Based Approach and Institutional Risk Assessments, October 2025

Dated October 2025 and issued under article 44.11 of Cabinet Decision No. 10 of 2019 (now repealed and replaced by Cabinet Decision No. 134 of 2025, under which supervisory guidance is issued pursuant to Article 49.4), this CBUAE Best Practices document guides exchange houses in building a risk assessment methodology, running an institutional risk assessment and embedding a risk-based approach across money laundering, terrorist financing and proliferation financing. It explains the framework, appropriate granularity, accountability and assessment frequency, then how to score inherent risk across customers, products, delivery channels, geographies and operating structure before weighing controls to reach residual risk. For a remittance and currency-exchange business, this means scaling scrutiny to the corridors served and the exposure each carries. It expressly applies to exchange houses alongside banks and other institutions.

CBUAE Guidance for Licensed FIs on Correspondent Banking, October 2025

Exchange houses depend on foreign remittance partners and correspondent relationships to settle cross-border transfers, and this October 2025 CBUAE Guidance explains how to control the money laundering, terrorist financing and proliferation financing risks that dependence brings. It describes correspondent banking, the requirements for processing cross-border funds transfers, and the risk factors attaching to respondent institutions, including third-party transaction risk from nested relationships and payable-through accounts, geography, ownership, products and customer base. On mitigation it covers enterprise-wide and relationship-specific risk assessment, standard, specific and enhanced due diligence, ongoing monitoring, suspicious activity reporting, targeted financial sanctions, governance, independent audit, training and record-keeping. Robust due diligence guards against exposure to unknown parties.

CBUAE Guidance for Licensed FIs on Customer Due Diligence and Record-Keeping, October 2025

For exchange houses serving walk-in and one-off remittance and currency-exchange customers, this October 2025 CBUAE Guidance on Customer Due Diligence and Record-Keeping sets out controls the regulator calls foundational to fighting financial crime. It stresses understanding each customer’s occupation, source of funds, source of wealth and expected activity so suspicious transactions surface. The document details general principles, identification and verification for natural persons, legal persons, arrangements and those acting on a customer’s behalf, then risk profiling through segmentation and geography. It addresses ongoing monitoring, simplified and enhanced due diligence, non-face-to-face relationships, name screening, customer rejection and exit, third-party reliance, record-keeping and red flag indicators. Reliable records underpin reporting.

CBUAE Guidance for Licensed FIs on Risks Related to Proliferation Finance, October 2025

Issued in October 2025, this CBUAE Guidance on Proliferation Finance helps exchange houses counter the financing of weapons of mass destruction as it moves through cross-border payments and banknote flows. Read alongside the CBUAE Procedures and Guidelines, it states regulatory expectations rather than new law, defining proliferation financing before examining the vulnerable channels it exploits, including correspondent banking, hawala and other alternatives to traditional banking, offshore accounts, free trade zones and shell companies. It sets out UNSC and FATF obligations, local requirements, and a risk-based approach across customer, product, geographic and operational risk. Controls span due diligence, transaction monitoring, suspicious reporting, targeted financial sanctions, governance, audit, training and record keeping.

CBUAE Guidance for Licensed FIs on Risks Related to Trade-Based ML and Transshipment, October 2025

Published in October 2025, this CBUAE Guidance on Trade-Based Money Laundering and Transshipment helps exchange houses recognise how criminals abuse international trade, cross-border payments and the movement of goods and banknotes. It explains trade finance, distinguishing documentary from non-documentary and open account trade, then sets out typologies including over- and under-invoicing, over- and under-shipment, multiple invoicing, falsely described goods, shell, front and shelf companies, free trade zones, illicit cash integration, third-party intermediaries and pass-through accounts. It also covers services-based laundering, vulnerable sectors such as gold and precious metals, and illicit transshipment. On mitigation, it addresses enterprise-wide risk assessment and enhanced due diligence. Trade can disguise value or movement.

Federal Decree-Law No. 6 of 2025 on the Central Bank (regulatory background)

Federal Decree-Law No. 6 of 2025 on the Central Bank, Regulation of Financial Institutions and Activities, and Insurance Business, issued on 8 September 2025, is not the AML law, but it matters as regulatory background for a CBUAE-licensed exchange house. It governs the Central Bank’s role and the regulation of licensed financial institutions and financial activities, which is the regime under which the firm holds its licence and answers to its supervisor. An exchange house should read it alongside the AML framework when assessing its licensing, conduct and supervisory position.

CBUAE AML and CFT Guidelines for Financial Institutions, July 2023

Dated July 2023, the CBUAE AML/CFT Guidelines for Financial Institutions name exchange houses, money service businesses and hawaladars expressly among those they bind, so a remittance operator cannot treat them as banking-only material. Prepared jointly by the country’s Supervisory Authorities, they consolidate the minimum expectations for identifying, assessing and mitigating money laundering, terrorist financing and illegal organisation risks into one reference. For a money transfer business, the value lies in the risk-based approach chapters covering business-wide assessment and the customer, product, delivery channel and geographic factors that shape a remittance book. They anchor the firm’s compliance programme, customer due diligence on remitters and beneficiaries, and reporting practices in supervisory expectations.

CBUAE Guidance for Licensed FIs on Risks Related to Virtual Assets and VASPs, February 2023

Issued on 20 February 2023, this CBUAE Guidance helps exchange houses grasp the money laundering and terrorist financing risks where remittances are funded from, or converted into, virtual assets, and where customers deal with virtual asset service providers. It sets out the threats and vulnerabilities, the routes by which an institution becomes exposed, and the UAE framework covering the SCA, CBUAE, VARA and FSRA. It explains the CBUAE non-objection required before opening administrative or transactional accounts for such providers. On mitigation, it addresses the risk-based approach, customer due diligence for provider customers, and enhanced measures for higher-risk customers and transactions. Value can move rapidly and pseudonymously.

CBUAE Guidance for Licensed FIs on Digital Identification for Customer Due Diligence, October 2022

As remittance onboarding moves to apps and remote channels, this CBUAE guidance of 31 October 2022 helps an exchange house understand how digital identity systems can identify and verify customers and support ongoing due diligence. It explains the systems and their participants, key terminology, identity proofing and enrolment, authentication, lifecycle management, and the portability that lets a remitter onboard once. It then covers using such systems for identification and verification, ongoing due diligence and third-party reliance. It examines the risks, from proofing weaknesses to authentication failures, and explains how to assess a system’s assurance and reliability. For app-based money transfer businesses, sound digital identification supports remote onboarding while introducing risks to control.

CBUAE Guidance for Licensed FIs on Suspicious Transaction Reporting, August 2022

Suspicious remittances are the daily bread of an exchange house, and this CBUAE guidance of 3 August 2022 explains how to identify, investigate and report them. It sets out the legal basis for filing, the protection for those who disclose, the meaning of a suspicious transaction, and the consequences of staying silent on structured cash or unusual transfer patterns. The document maps the three lines of defence, the role of the compliance officer or MLRO, transaction monitoring methods from manual to intelligence-led, and how to draft and submit a report. It also covers immediate-attention activity, confidentiality and the strict prohibition on tipping off remittance customers.

CBUAE Guidance for Licensed FIs on Risks Relating to Payments, August 2022

Payments are the very trade of an exchange house, and this CBUAE guidance of August 2022 addresses the money laundering and terrorist financing risks running across the sector. Issued under article 44.11 of Cabinet Decision No. 10 of 2019 (now repealed and replaced by Cabinet Decision No. 134 of 2025, under which supervisory guidance is issued pursuant to Article 49.4), it applies to institutions providing payment products directly and to those serving other payment participants. It explains what makes payments vulnerable: the speed at which funds move, peer-to-peer transfers, cross-border movement, regulatory gaps, intermediation, nesting, and the use of agents. Mitigation covers risk assessment, customer and enhanced due diligence, ongoing monitoring, wire transfer requirements, targeted financial sanctions and suspicious transaction reporting, helping a money transfer business calibrate controls to a fast, intermediated flow.

CBUAE Guidance for Licensed FIs on Risks Relating to Politically Exposed Persons, August 2022

A prominent remittance customer can be a politically exposed person, and this CBUAE guidance of August 2022 sets out how an exchange house identifies and manages the heightened risks they bring. Issued under article 44.11 of Cabinet Decision No. 10 of 2019 (now repealed and replaced by Cabinet Decision No. 134 of 2025, under which supervisory guidance is issued pursuant to Article 49.4), it stresses that the aim is not to refuse such customers but to complete thorough due diligence before accepting or continuing a relationship. It distinguishes domestic and foreign politically exposed persons and heads of international organisations, extending to family and close associates. It covers classification, time limits on status, screening, risk rating, enhanced due diligence, monitoring, reporting, governance and training, with an annex of red flags for high-value transfers.

CBUAE Guidance for Licensed FIs on Transaction Monitoring and Sanctions Screening, September 2021

Issued on 8 September 2021, this CBUAE guidance tells exchange houses how to design, operate and maintain the systems that flag suspicious remittances and identify sanctioned parties on transfers. On transaction monitoring, it covers risk assessment, risk-based deployment, data management, rule definition and pre-implementation testing, alert scoring, outcomes analysis and reporting, plus post-implementation tuning and validation. On sanctions screening, it addresses name and transaction screening design, list management and testing so remitters, beneficiaries and counterparties are caught reliably. A governance section covers oversight, vendor use, role-specific training and record keeping. For a money transfer business, well-calibrated, regularly validated systems are the difference between spotting structured cash and missing it.

CBUAE Guidance for Licensed FIs to Cash-Intensive Businesses, September 2021

No customer type sits closer to an exchange house than the cash-intensive business, and this CBUAE guidance of September 2021 addresses precisely the risks that arise when clients handle large volumes of notes at the counter. Issued under article 44.11 of Cabinet Decision No. 10 of 2019 (now repealed and replaced by Cabinet Decision No. 134 of 2025, under which supervisory guidance is issued pursuant to Article 49.4), it explains why cash is so vulnerable to abuse, the risks of bearer negotiable instruments and prepaid cards, and specific concerns including cross-border cash movement, couriers and currency exchange. On mitigation, it sets a risk-based approach built on enterprise and customer risk assessment, enhanced due diligence, beneficial owner identification, ongoing and transaction monitoring, suspicious transaction reporting, governance and training for high cash flows.

CBUAE Guidance for Registered Hawala Providers and LFIs, August 2021

Issued in August 2021, this CBUAE combined Guidance for Registered Hawala Providers and the Licensed Financial Institutions serving them reaches exchange houses as LFIs providing services and as remittance businesses operating near this space. Read alongside the CBUAE Procedures and Guidelines, it states regulatory expectations rather than new law and is organised in parts covering each audience. It draws on the FATF description of hawaladars as money transmitters who arrange transfers and settle through trade, cash and long-term net settlement, often tied to particular regions. It sets out global risks, UAE regulation, permitted and non-permitted services, sanctions and freezing without delay, registration, a bank account, and a full AML/CFT programme.

CBUAE Guidance for Licensed FIs on Implementation of Targeted Financial Sanctions, July 2021

Exchange houses should screen customers, originators, beneficiaries, beneficial owners and counterparties to a transfer against applicable sanctions lists, and this CBUAE guidance of 4 July 2021 sets out how to identify, freeze and report assets connected to designated persons. Read with the Executive Office guidance, it builds a sanctions programme from senior management commitment, risk assessment and risk appetite through internal controls, training, audit and record keeping. It then addresses screening against the UN Consolidated List and Local Terrorist List, name and payments screening of remitters and beneficiaries, false positive verification and confirmed matches. Red flag indicators for terrorist financing, proliferation financing and evasion help catch counterparties routing funds through the firm’s counters.

CBUAE Guidance for Licensed FIs to Legal Persons and Arrangements, June 2021

When a corporate remitter approaches the counter, this CBUAE guidance of June 2021 governs how an exchange house manages the money laundering and terrorist financing risks that companies, other legal persons and legal arrangements carry. It explains how such structures obscure identity and beneficial ownership, hide the purpose of a transfer, and conceal the source of funds, and it sets out common typologies of abuse. It then covers formation requirements, beneficial owner identification, record keeping, and how legal persons operate under UAE law, including economic substance. Mitigation runs through the risk-based approach, customer risk rating, institutional risk assessment and enhanced due diligence on opaque remitters.

CBUAE Guidance for Licensed FIs to the Real Estate and Precious Metals and Stones Sectors, June 2021

Issued on 16 June 2021, this CBUAE guidance matters to an exchange house whose remittance customers include dealers in precious metals and stones or parties moving funds tied to real estate, both flagged as higher-risk. It is organised around understanding and mitigating the risks each sector presents, describing the features that increase vulnerability, relevant typologies, and how the sectors are regulated in the UAE. On mitigation, it explains applying a risk-based approach, conducting customer and enhanced due diligence, reporting suspicious transactions, and maintaining governance and training. Common requirements sit alongside sector-specific considerations, and annexes provide red flags for spotting illicit value passing through gold traders and property-linked transfers.

CBUAE STR Outreach for Banks and Finance Companies, March 2021

Delivered on 10 March 2021, this Financial Intelligence Unit outreach session briefed banks and finance companies on suspicious transaction reporting, with input from the Ministry of Interior. Although addressed to banks and finance companies, its expectations reach any licensed institution that files through goAML, so an exchange house can read across the same messages: when a report is warranted, the quality the FIU expects, goAML as the sole channel, and the compliance officer’s duties. It reinforces prompt, well-grounded reporting of remittance and currency-exchange suspicions rather than defensive or late filing.

CBUAE Board of Directors Decision No. 59/4/2019 on AML and CFT procedures

Board of Directors Decision No. 59/4/2019, issued on 13 June 2019, is the supervisory bedrock on which every exchange house builds its AML programme. Made under Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025, it cancels the old Circular No. 24/2000 and confirms that a licensed money transfer business, conducting remittance operations for customers, counts as a financial institution bound by the law, its implementing regulation and Central Bank instructions. It empowers the CBUAE to examine the firm’s branches, with or without notice, demand records on cross-border transfers, impose sanctions for breaches, permit appeals and publish penalties against non-compliant houses.

CBUAE Guidance Note on Responsible Use of AI and ML by LFIs

As exchange houses turn to artificial intelligence and machine learning to monitor remittance flows, this CBUAE Guidance Note on the Responsible Use of AI and Machine Learning sets out principles for consumer-focused, ethical adoption, including generative AI. It is non-binding, helping institutions shape internal policies that protect consumers and support good market conduct, and its principles are flexible so they evolve with the technology. The Note covers governance and accountability, placing responsibility for systems and outcomes with senior management and the Board and calling for a documented framework, regular reporting and a model inventory. It addresses fairness, transparency, data quality, privacy, continuous monitoring, human oversight, outsourcing and ethical innovation.

CBUAE List of Administrative and Financial Sanctions

The CBUAE List of Administrative and Financial Sanctions records the penalties the Central Bank can impose, and it applies to all licensed institutions, including exchange houses. It confirms the CBUAE as the supervisory authority for shortcomings in the anti-money laundering and sanctions compliance frameworks of those it licenses. Under Article 17 of Federal Law No. 10 of 2025, it can impose administrative penalties from a warning to licence revocation, and financial penalties from ten thousand to five million dirhams per violation. Under Article 137 of the Central Bank Law, fines reach two hundred million dirhams

Exchange House Sector-Specific CBUAE Guidance

Alongside its general guidance, the Central Bank issues material aimed specifically at exchange houses and money or value transfer services.

Typologies in the Money or Value Transfer Services (MVTS), June 2022

Typologies in the Money or Value Transfer Services of June 2022 is a joint report by the Supervisory Authorities Sub-Committee, the FIU and the Executive Office, built from a pilot of exchange houses and registered hawala providers. It maps emerging ML, TF and sanctions risks across currency exchange and money remittance during 2021 to 2022, drawn from products, processes and transactional data. The report lists nineteen typologies with red flags relevant to exchange houses: structuring, third-party smurfing, unusually high-value transactions, sudden turnover spikes at one branch, trade-based money laundering, fabricated transaction receipts, cash couriers, WPS salary changes, remittances to varied beneficiaries, high-risk-country corridors, frequent currency conversion and cash-against-credit-card advances.

CBUAE Standards for Exchange Business, Chapter 16 (AML/CFT), November 2021

Chapter 16 is the binding AML/CFT rulebook every licensed exchange house must follow, set within the CBUAE Standards for the Regulation of Exchange Business, Version 1.20 of November 2021, amending Version 1.10 of February 2018. It codifies the full compliance programme for money exchange and remittance: an enterprise-wide ML/FT risk assessment, KYC and customer due diligence for walk-in natural persons, enhanced due diligence, PEP checks, and special wire-transfer rules for ordering, intermediary and beneficiary institutions. It also covers agents and correspondent counterparties, third-party transactions, sanctions screening, transaction monitoring, suspicious transaction reporting, tipping-off prohibitions, know-your-employee vetting, record retention, remittance data uploads and bi-annual compliance reporting.

CBUAE Guidance for Licensed Exchange Houses, November 2021

The CBUAE Guidance for Licensed Exchange Houses of November 2021 explains how exchange houses should meet their statutory AML/CFT obligations, read alongside Chapter 16 of the Standards. It flags why the sector rates highly for risk and materiality in the UAE, driven by cash intensity, speed, worldwide reach and the many occasional, walk-in transactions that limit customer understanding. It sets out ten essential programme components and a six-step risk assessment covering customer, product, delivery channel, new technology, jurisdiction and counterparty risk, plus corridor and agent exposure. It details customer due diligence, transaction monitoring with red flags, sanctions freezing without delay, training, audit, record keeping, employee risk, and FIU reporting.

CBUAE STR Outreach for Exchange Houses, March 2021

The CBUAE STR Outreach for Exchange Houses of March 2021 is a joint awareness session by the Financial Intelligence Unit, CBUAE AML/CFT supervision and the Ministry of Interior, aimed at exchange-house compliance officers. It explains when and what to report under Article 15 of the AML law, using goAML as the only channel for STRs, SARs and related report types. It stresses the source of funds and wealth information for remittance customers, monitoring triggers and alerts, tipping-off and confidentiality rules after filing, and securing funds on flagged accounts. It shares FIU-noted deficiencies in timeliness and accuracy, plus Ministry of Interior red flags such as credit turnover inconsistent with the customer profile.

Core AML Obligations for Exchange Houses at a Glance

Whatever the licence, the AML regulations for exchange houses in the UAE turn on a common set of duties.

  • A business and enterprise-wide risk assessment aligned to the national risk assessments, with corridor and product risk built in.
  • Customer due diligence on customers and originators, with collection and screening of beneficiary information, and enhanced due diligence where the transaction, corridor, customer or counterparty risk is higher, including source of funds for large or unusual transfers.
  • Ongoing transaction monitoring for structuring and unusual patterns, and sanctions screening of customers, originators, beneficiaries, beneficial owners, counterparties and relevant transaction parties, including parties to cross-border payments.
  • Suspicious transaction and activity reporting through goAML, full record keeping, and a qualified compliance officer and MLRO.
  • Identifying the ultimate beneficial owner of corporate remitters.

In practice, supervisors expect an exchange house to be able to evidence controls across the areas below.

Control area  What an exchange house should evidence 
Enterprise-wide and business-wide risk assessment  Corridor, product, customer, delivery channel, branch and counterparty risk 
Customer onboarding  Customer identity, purpose, expected activity and source of funds where relevant 
Remittance controls  Originator and beneficiary information, wire-transfer data quality including incomplete or rejected transfers with escalation and record evidence, and third-party transaction handling 
Bulk cash and banknote handling  Supplier and counterparty due diligence, shipment reconciliation, corridor risk, sanctions screening and source-of-cash checks 
Sanctions screening  UAE Local Terrorist List, UN Consolidated List, customers, beneficiaries, counterparties and ownership or control 
Transaction monitoring  Structuring, smurfing, high-risk corridors, repeated beneficiaries and unusual branch activity 
Agent and partner due diligence  Foreign remittance partner assessment, correspondent risk and ongoing review 
goAML reporting  STR and SAR, confirmed and partial name match reports where relevant, and no tipping-off 
Governance  Compliance officer and MLRO independence, board oversight, training, audit and remediation tracking 

Expert Tip:

For an exchange house, most risk sits in three places: structured cash just under thresholds at the counter, remittances to and from high-risk corridors, and third parties who are not the customer being served. Build monitoring rules around corridor risk and one-off customer behaviour rather than long-term relationships, because that is where the sector’s typologies actually appear.

Conclusion

AML regulations for exchange houses in the UAE come down to a clear chain: exchange houses are Licensed Financial Institutions, the Central Bank supervises them, and the applicable framework includes Federal Decree-Law No. 10 of 2025, Cabinet Resolution No. 134 of 2025, the targeted financial sanctions rules, and relevant Central Bank general and exchange-house-specific rules, standards and guidance. The sector’s cash intensity and cross-border reach put it at medium-high risk, so the controls that matter most are screening, monitoring, and knowing who is really sending and receiving the money. Use the national risk assessments to calibrate, use this guide as an overview, and read across to our guide to anti-money laundering laws in the UAE and the pillar on AML regulations for banks and financial institutions in the UAE.

Frequently Asked Questions

Which AML rules apply to exchange houses in the UAE?

Exchange houses are Licensed Financial Institutions under Federal Decree-Law No. 10 of 2025 and its Executive Regulations, supervised by the Central Bank of the UAE. They must apply customer due diligence, sanctions screening, transaction monitoring, record keeping, and suspicious transaction reporting through goAML, and they follow both the general LFI guidance and the Central Bank’s exchange-house-specific guidance.

The national risk assessment rates the sector medium-high, driven by cash intensity, banknote shipments, reliance on foreign remittance partners, and third-party transactions. In practice the biggest risks are structured cash at the counter, remittances through high-risk corridors, and senders or beneficiaries who are not the customer being served.

Monitoring should be built around corridor and product risk rather than long-term relationships, watching for structuring below thresholds, sudden spikes in a branch’s turnover, remittances to many unrelated beneficiaries, and transfers to high-risk countries. The Central Bank’s transaction monitoring and sanctions screening guidance and the money or value transfer typologies report set out what to look for.

Both move value across borders, and the Central Bank studies them together in its money or value transfer typologies. The key difference is the licence: exchange houses hold an exchange business licence, while hawala providers hold a separate registration. Registered hawala providers are covered under their own framework, which we address on a dedicated page.

Yes. Money service businesses established in the Abu Dhabi Global Market and the Dubai International Financial Centre are supervised by the FSRA and DFSA under their own AML rulebooks, while still operating within the wider UAE AML/CFT framework. They fall outside this guide, which covers exchange houses licensed by the Central Bank.

The firm should identify and verify the customer, understand who the beneficiary is, screen both against sanctions and terrorist lists, risk-rate the corridor and the transaction, and establish the source of funds for large or unusual transfers, applying enhanced due diligence where the risk is higher before the transfer proceeds.

Common indicators include structured cash just below reporting thresholds, a customer sending to many unrelated beneficiaries, sudden turnover spikes at one branch, fabricated receipts, cash couriers, unexplained changes to Wage Protection System salaries, and frequent currency conversion, all of which feature in the Central Bank’s money or value transfer typologies.

Are exchange houses required to screen every remittance?

Yes. The exchange house should screen the relevant parties to a remittance, including customers, originators, beneficiaries and counterparties, against the applicable sanctions lists and internal risk controls before processing or releasing funds.

Yes. The exchange house should maintain a business-wide or enterprise-wide risk assessment that reflects its products, branches, customers, delivery channels, foreign remittance partners, corridors, sanctions exposure and the findings of the national ML/TF and PF risk assessments.

Need help building or reviewing your exchange house AML programme?

Whether you're building an AML programme from scratch or enhancing an existing one, our experts provide practical, risk-based solutions to help your exchange house stay compliant and confident.

Share via :

About the Author

Pathik Shah

FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)

Pathik is an ACAMS-certified AML consultant specialising in governance, risk, and compliance for regulated entities in the UAE. He brings over 28 years of experience, with 1,000+ hours of AML training and 200+ advisory engagements across DNFBPs, VASPs, and FIs. He supports businesses in aligning with AML/CFT requirements from the CBUAE, DFSA, MoET, MoJ, VARA, CMA, FSRA, and FATF. Known for translating complex regulations into audit-ready procedures, Pathik enables operational clarity and compliance readiness.

Reach Out to Pathik