AML Compliance in the UAE: Obligations and Risk Assessment
Scope first, then risk: the two answers that set the size of the programme
UAE AML duties reach past the banks to designated non-financial businesses and professions. This article covers how to decide whether you are in scope, what a risk-based assessment has to cover, the obligations that follow for businesses in scope, and what regulators do about weak controls or missed reporting.
Reviewed by Mohamed Noureldin, Founder, Managing Partner & Senior Legal Consultant
Two questions settle what an anti-money-laundering (AML) programme in the UAE must do: is the business in scope, and what is its risk? A yes to the first brings duties that are mandatory. The answer to the second is what turns those duties into a proportionate set of controls.
The first task is an honest scope decision
AML obligations extend beyond banks to designated non-financial businesses and professions — real-estate brokers, dealers in precious metals and stones, corporate service providers and others. Any business has to determine, honestly, whether it falls within scope, because the duties that follow are mandatory.
What a risk assessment has to cover
UAE AML law is built on a risk-based approach. Businesses must assess the money-laundering and terrorist-financing risks presented by their customers, products, delivery channels and geographies, then calibrate controls to that risk. A documented risk assessment is both a legal expectation and the foundation for every other control.
From the assessment to the controls the law names
In-scope businesses must conduct customer due diligence, enhanced for higher-risk relationships. They must screen against sanctions lists, monitor transactions, keep records, appoint a compliance officer, and file suspicious-transaction reports through the national system. These are legal duties, not optional best practice.
What weak controls cost
Regulators actively supervise and penalise AML failings, with significant administrative fines and business restrictions for weak controls or missed reporting. The cost of non-compliance typically far exceeds the cost of a sound programme. The risk assessment is also the first thing a regulator will ask to see.