Anti-Money Laundering in UAE: AML/cft Compliance Guide
Due diligence, suspicious transaction reports and compliance programmes for banks and DNFBPs
How the Federal AML Law and the Central Bank's regulations apply to financial institutions and designated non-financial businesses and professions. It covers customer due diligence, enhanced due diligence and record-keeping, and reporting suspicious transactions to the FIU. It then sets out what a compliance programme contains and the penalties for non-compliance.
Reviewed by Mohamed Noureldin, Founder, Managing Partner & Senior Legal Consultant
The Federal AML Law applies to designated non-financial businesses and professions (DNFBPs) as well as to financial institutions, and entities in those categories must understand their compliance obligations even if they operate outside conventional banking or financial services. At the core of those obligations sit customer due diligence, suspicious transaction reporting and continuous monitoring.
Our money laundering defence practice and our AML compliance team provide practical legal support in this area.
A 2025 decree-law replaced the 2018 regime
The UAE's AML/CFT regime is built primarily around Federal Decree by Law No. (10) of 2025 Regarding Anti-Money Laundering, and Combating the Financing of Terrorism and Proliferation Financing (the "Federal AML Law"). It repealed Federal Decree-Law No. (20) of 2018, which had replaced the earlier Federal Law No. 4 of 2002 and introduced a more rigorous and structured legal foundation, designed to meet international standards set by the Financial Action Task Force (FATF).
Beyond the Federal AML Law, the Central Bank of the UAE (CBUAE) has issued extensive regulatory guidelines. These regulations impose compliance obligations on all financial institutions under its supervision, including banks, exchange houses, finance companies and payment service providers. The CBUAE's role extends to monitoring and enforcing AML controls, conducting inspections, and issuing penalties for non-compliance.
The UAE also maintains a multi-agency approach. The Financial Intelligence Unit (FIU) and law enforcement authorities are involved in a coordinated response to money laundering and terrorist financing threats.
FATF, the Egmont Group and the Security Council
The framework is designed with a clear view to compliance with international standards promulgated by FATF, the Egmont Group and United Nations Security Council Resolutions. The UAE seeks to maintain its position as a reputable financial centre and to avoid being blacklisted by international bodies.
FATF's Recommendations serve as a global blueprint for AML/CFT controls, and the UAE has continually adapted its legislative and regulatory tools to correspond with them as they evolve. For example, the Federal AML Law incorporates FATF's risk-based approach, obligating entities to conduct risk assessments and tailor their controls accordingly. The UAE also takes part in mutual evaluation exercises.
Businesses caught outside the banking sector
The Federal AML Law applies not only to traditional financial institutions but also to DNFBPs: persons engaged in the commercial or professional activities specified in its Executive Regulations.
The scope is meant to capture the various channels through which illicit funds could be laundered or terrorist financing conducted.
Customer due diligence is a statutory duty
Under UAE law, financial institutions and DNFBPs are mandated to carry out rigorous customer due diligence (CDD) procedures.
The Federal AML Law requires entities to verify the identity of customers, beneficial owners and any persons acting on behalf of customers. This verification must be ongoing, with enhanced due diligence (EDD) measures applied when dealing with high-risk customers or jurisdictions. CDD also involves ascertaining the purpose and nature of the business relationship. That lets compliance teams build appropriate risk profiles and monitor transactions for suspicious patterns.
Entities must implement systems capable of identifying risks such as politically exposed persons (PEPs) or complex ownership structures designed to obscure the illicit origins of funds. The CBUAE regulations prescribe detailed procedural requirements, including record-keeping obligations and periodic reviews, so that the CDD framework stays responsive to evolving threats.
Documents, and whether they are genuine
In practice, customer identification involves collecting official documents such as passports, national ID cards, or trade licences for companies. Verification processes must confirm that these documents are authentic, often requiring face-to-face verification or the use of certified digital identification tools where permissible.
Finding the natural person behind the customer
Beneficial ownership identification is particularly challenging in the UAE's business environment, where complex corporate structures, including offshore entities and trusts, are frequently used. Entities must build investigative processes to verify the natural persons who ultimately own or control the customer, using source-of-funds checks and beneficial ownership declarations as part of that process.
When enhanced due diligence is mandatory
EDD is mandatory in certain risk scenarios: for example, when dealing with PEPs, customers from jurisdictions with weak AML controls. EDD measures include obtaining senior management approval before establishing the relationship, conducting more frequent reviews, and closely monitoring transactions.
For example, a bank onboarding a PEP from a country with known governance issues must put in place a tailored EDD process. That process scrutinises the source of wealth and funds more rigorously than standard procedures do.
Monitoring is continuous, and records must be kept
CDD is not a one-time event but a continuous process. Entities must monitor transactions against the customer's risk profile and update CDD information periodically or when suspicious activity arises.
The UAE mandates record-keeping of all CDD information, so that the data is available for inspection or investigation when necessary.
Automated transaction monitoring systems enable entities to flag unusual patterns, such as rapid fund movements inconsistent with the customer's known business profile.
Reporting suspicion to the FIU
Financial institutions and DNFBPs have an obligation to identify and report suspicious transactions to the FIU. They must put internal controls in place and train personnel to detect red flags, such as unusual transaction volumes, inconsistent client profiles, or transactions involving high-risk jurisdictions. On detection, entities submit Suspicious Transaction Reports (STRs) promptly and confidentially.
What makes a transaction suspicious
Under UAE law, a transaction is suspicious if there are reasonable grounds to suspect that the funds involved are proceeds of any felony or misdemeanour, or are related to money laundering, terrorist financing or proliferation financing, whether the transaction was executed or merely attempted. Examples include sudden large cash deposits, transactions inconsistent with the customer's known business, or transfers to or from countries designated as high-risk by international bodies.
Financial institutions must set internal policies that clearly define suspicious indicators tailored to their business models. For instance, a money exchange house may flag frequent small-value transactions just below reporting thresholds, which can indicate structuring or smurfing.
Timing, confidentiality and tipping off
Once a suspicion arises, entities must report to the FIU without delay and directly. The reporting process is confidential, to protect the integrity of investigations and to prevent tipping off the subject of the report.
The Federal AML Law imposes strict confidentiality requirements, and entities are legally protected from liability arising from good faith reporting. Failure to report, or tipping off, can lead to severe penalties, including fines and criminal prosecution. The CBUAE's supervisory role includes auditing the effectiveness of suspicious transaction reporting and enforcing penalties for non-compliance or failure to report.
Alerts that feed the report
Many UAE-regulated entities use automated alert systems that integrate with transaction monitoring platforms. These systems generate alerts based on predefined rules. Compliance officers then review the alerts to decide whether an STR should be filed, which improves the timeliness and accuracy of reporting.
What a compliance programme has to contain
An effective AML/CFT compliance programme requires more than adherence to statutory obligations. It necessitates policies, procedures and governance structures tailored to the entity's specific risks. Legal advisers and compliance specialists must work together to design programmes that integrate efficiently with business operations.
Key elements include the appointment of a qualified compliance officer, staff training, independent audits, and a risk-based approach to monitoring. That approach lets entities prioritise resources on high-risk areas. Our AML compliance advisers advise organisations on defences against money laundering risks and on alignment with evolving regulatory standards.
Governance starts with the board
Boards of directors and senior management must set clear AML/CFT policies and demonstrate a commitment to enforcement. The appointment of a dedicated compliance officer with sufficient authority, resources and independence is essential.
Regular staff training must be designed to raise awareness of AML/CFT risks, the identification of red flags, and reporting obligations. Practical training scenarios tailored to the entity's sector improve vigilance across departments.
Mapping the risks of the business model
A fundamental component of a compliance programme is an enterprise-wide risk assessment to identify the vulnerabilities unique to the business model. For example, a real estate developer in Dubai may face risks linked to opaque ownership structures or cash-intensive transactions.
Once risks are mapped, entities can put targeted controls in place, such as transaction limits, enhanced due diligence procedures and periodic independent audits. This risk-based approach avoids a one-size-fits-all model and uses resources efficiently.
Independent audit
Auditors assess the adequacy of policies, the accuracy of record-keeping, the strength of transaction monitoring, and the responsiveness of suspicious activity reporting. Findings from audits should be used to improve the compliance framework continuously, as tactics and regulatory expectations change.
Technology alongside human judgment
Technology should not replace human judgment, but it is critical in managing the volume and complexity of financial transactions. Transaction monitoring platforms can be designed to detect patterns indicative of layering or structuring. Data analytics tools can analyse large data sets for anomalies that human reviewers might miss.
Entities must ensure these systems are regularly updated to reflect changes in the typologies of money laundering and terrorist financing, and are properly integrated into their compliance governance.
Inspections, fines and prosecution
The CBUAE and other supervisory bodies conduct regular inspections and audits to assess adherence to AML obligations. Non-compliance can trigger penalties ranging from administrative fines to suspension or revocation of licences. The Federal AML Law gives authorities power to impose financial sanctions proportionate to the severity of breaches, and to prosecute individuals or entities involved in money laundering offences.
In recent years, the UAE has intensified its enforcement efforts. Regulatory bodies have imposed substantial fines against banks and DNFBPs for failures in CDD, delayed STR submissions and inadequate risk assessments.
Money laundering offences under UAE law attract severe penalties, including imprisonment and heavy fines. Entities found complicit may face dissolution and closure of their premises, asset freezes, and criminal prosecution of the person responsible for their actual management.
Legal counsel can advise on remediation measures, defend clients against regulatory sanctions, and pursue mitigation strategies during enforcement proceedings, including negotiating settlements or coordinating remediation plans with regulators. Our financial crime team handles money laundering defence.
This article is for informational purposes only and does not constitute legal advice.