Banking Regulations in UAE Federal: Complete Guide
A control that exists in a policy but leaves no trace in the file is treated, on inspection, as a control that never existed.
The UAE runs parallel financial regimes, so this guide starts with the question most compliance problems come down to: whether the Central Bank, the Securities and Commodities Authority, the DFSA or the FSRA supervises the activity, and how the activity, the customer and the place of solicitation decide it. It then covers what licensing assesses, the governance, outsourcing and record-keeping duties that follow, how anti-money laundering is examined as part of supervision, consumer disclosure and complaints, and where data protection differs between onshore and the financial centres.
Start by identifying your regulator
Most banking compliance problems in the UAE begin with a single unanswered question: which regulator actually supervises this activity? The answer is not obvious, because the country runs parallel financial regimes. Onshore — that is, mainland and most free zones — banks, finance companies, exchange houses, payment and stored-value providers and insurance-linked financing sit under the Central Bank of the UAE. Securities and investment activity onshore is supervised by the Securities and Commodities Authority. Inside the Dubai International Financial Centre, the Dubai Financial Services Authority regulates financial services under DIFC law, and in Abu Dhabi Global Market the same role belongs to the Financial Services Regulatory Authority. DIFC and ADGM are common-law jurisdictions with their own courts.
Those regimes are not interchangeable. A licence issued in one does not authorise business in another, and marketing a product from a financial centre to customers onshore is itself a regulated question. Before drafting a single policy document, write down the activity, the customer, and the place where the customer is solicited. That triangle decides which rulebook governs you.
What a licence actually requires
Authorisation and fitness
Licensing is not a form-filling exercise. Regulators assess the applicant's shareholders and ultimate beneficial owners, the fitness and propriety of proposed directors and senior managers, the business plan and its funding, the capital the regulator requires for that category of activity, and whether the applicant has the systems to run it. Controllers and senior appointments generally need approval before they take effect, not after, and later changes in ownership or control usually require the regulator's consent as well.
Corporate form matters alongside the licence. An onshore company is constituted under the Commercial Companies Law, Federal Decree-Law No. 32 of 2021, which replaced Federal Law No. 2 of 2015. Restrictions on foreign ownership of mainland companies were lifted by Federal Decree-Law No. 26 of 2020, so most mainland activities can now be wholly foreign-owned, subject to the strategic-impact list. Financial activity carries its own approval requirements on top of that, so a general company licence never substitutes for a financial services authorisation.
Governance, outsourcing and records
Once licensed, the recurring obligations are governance obligations: a board that can evidence oversight, a compliance function with authority and access, a risk function, internal audit, and documented policies that are actually followed. Outsourcing — including intra-group outsourcing and cloud hosting — does not transfer responsibility. The licensed entity remains answerable for the outsourced function, and material arrangements usually require notification or approval.
Records are the part most institutions underestimate. Supervisors test compliance by asking for evidence: account opening files, board and committee minutes, transaction records, approval trails for exceptions. A control that exists in a policy but leaves no trace in the file is treated, in an inspection, as a control that did not exist.
Anti-money laundering sits inside banking supervision
AML and counter-terrorist financing obligations are not a separate compliance silo; supervisors examine them as part of prudential and conduct supervision. Expect to show a documented business risk assessment, customer due diligence proportionate to that risk, identification and verification of beneficial owners, enhanced measures for higher-risk relationships and politically exposed persons, screening against the applicable sanctions lists, ongoing transaction monitoring, and a named compliance officer with the standing to escalate.
Suspicious transactions must be reported to the UAE Financial Intelligence Unit through the reporting system it operates, and the client must not be told that a report has been made. Records must be kept for the period the legislation specifies. Failures here attract administrative penalties and, at the extreme, licence action.
Customers, documents and complaints
Consumer protection rules shape the paperwork. Terms must be disclosed before the customer commits, fees and charges must be set out, and key documents are expected in Arabic as well as English for onshore customers. In litigation before the onshore courts, the Arabic text is what the judge reads, so a translation prepared as an afterthought becomes the operative contract.
Institutions must operate an internal complaints process with recorded outcomes and timeframes, and customers who are not satisfied can escalate beyond the institution to the complaint machinery the Central Bank oversees. Treating complaints as an operational nuisance is expensive: patterns of unresolved complaints are exactly what supervisors look for.
Client data and confidentiality
Banking confidentiality and data protection overlap but are not the same duty. Personal data processed onshore falls under the UAE Personal Data Protection Law, Federal Decree-Law No. 45 of 2021, while DIFC and ADGM each apply their own data protection regime. Group structures that move customer files between an onshore branch and a financial centre entity, or offshore to a service centre, need a lawful basis for each transfer and a written record of it.
Disclosure to authorities is the common pressure point. Your policy should distinguish routine regulatory reporting from ad-hoc requests, name who may authorise a disclosure, and require the request to be recorded. A confidentiality clause that simply says "as permitted by law" tells no one what to do at eight o'clock on a Thursday evening.
Tax and reporting
Financial institutions are within the corporate tax regime introduced by Federal Decree-Law No. 47 of 2022, which applies to financial years starting on or after 1 June 2023, with no tax on taxable income up to AED 375,000 and 9% above that. VAT applies at 5% under Federal Decree-Law No. 8 of 2017, as amended by Federal Decree-Law No. 18 of 2022, with the treatment of individual financial services depending on how the product is priced. The Economic Substance Regulations were cancelled for financial years ending after 31 December 2022 by Cabinet Decision No. 98 of 2024, so obligations remain only for the FY2019 to FY2022 periods — but those older years can still be examined.
Disputes
Financing and account disputes onshore are heard by the local courts in Arabic. Where the parties prefer arbitration, the Federal Arbitration Law, Federal Law No. 6 of 2018, as amended in 2023, governs arbitrations seated onshore. The DIFC-LCIA was abolished by Dubai Decree No. 34 of 2021 and its caseload moved to the Dubai International Arbitration Centre, while DIFC remains available as a seat; in Abu Dhabi, ADCCAC was restructured as arbitrateAD. Legacy clauses naming an institution that no longer exists should be reviewed and replaced, and the choice of seat should be a considered decision rather than inherited boilerplate. Where a facility or account relationship has already broken down, early advice on financial dispute resolution usually costs less than the enforcement that follows.
A working checklist
- Confirm which regulator supervises each activity, and whether any of it touches customers in another regime.
- Check that every controller, director and approved individual holds the approval the regulator requires.
- Keep the business risk assessment current and make sure due diligence files match it.
- Map where customer data is stored and transferred, and record the basis for each transfer.
- Review arbitration and jurisdiction clauses in standard terms for institutions that no longer exist.
- Retain the evidence, not just the policy.
Where advice helps
The federal framework rewards institutions that can show their work. Licensing, governance, AML, data and dispute clauses are separate obligations that a supervisor will test together, and the cost of correcting them after an inspection is far higher than the cost of getting the file in order beforehand. For help reviewing a licence application, a compliance programme or a set of customer terms, contact the Nour Attorneys team.
Disclaimer: The information provided in this article is for general informational purposes only and does not constitute legal advice. Readers should seek professional legal advice tailored to their specific circumstances before making any decisions or taking any action based on the content of this article.
Nour Attorneys Team
Related Resources
More of our writing on related subjects:
- Banking Regulations Compliance in the UAE
- Fintech Legal Frameworks for Dubai Businesses
- Anti-Money Laundering Compliance for UAE Investors
- Investment Advisory Strategies for Multinational Entities