How to Build an Effective AML Compliance Program in the UAE
Sanctions that reach the people running the business, and what a programme must contain
Federal Decree by Law No. (10) of 2025 makes an AML compliance programme a legal necessity, and its sanctions can reach board members and managerial personnel. This article covers the risk assessment the programme is built on, the policies and procedures that follow from it, the compliance officer's authority, employee training, independent auditing, and what keeps the programme current.
Reviewed by Mohamed Noureldin, Founder, Managing Partner & Senior Legal Consultant
Some businesses have treated anti-money laundering compliance as a box-ticking exercise. Federal Decree by Law No. (10) of 2025 Regarding Anti-Money Laundering, and Combating the Financing of Terrorism and Proliferation Financing makes that approach no longer acceptable. It repealed Federal Decree by Law No. (20) of 2018. An effective AML compliance programme is not just a matter of best practice any more; it is a legal necessity. The work is to move past a superficial approach and build something that protects the business from the risks of financial crime and regulatory action.
Sanctions reach the people running the business
The supervisory authority may restrict the powers of board members, executive, supervisory or managerial personnel proven responsible for a violation, and may suspend them or request their replacement. Its consequences reach the people running the business. That gives managers a direct interest in whether the programme is a genuine defence against financial crime or a form-filling routine. Our financial crime service covers that exposure, and our AML compliance advisory service builds and maintains the programme itself.
Compliance is not the compliance department's job alone
An effective programme takes a practical, risk-based and integrated approach. It is not something that can be done in isolation by the compliance department. It requires the buy-in and support of the entire organisation, from the board of directors down. The employees who are involved in customer-facing or transaction-processing roles are the ones who apply it day to day. Our corporate governance service covers the board's part in that.
Start with the risk assessment, and write it down
Financial institutions, designated non-financial businesses and professions, and virtual asset service providers must identify, understand, manage, assess, document and continuously update the risks of the crime within their business scope, and must retain the risk assessment study. Your risk assessment should consider:
- Your products and services. Which of your products and services are most vulnerable to being used for money laundering?
- Your customers. What is the risk profile of your customer base? Do you deal with high-risk customers?
- Your geographic locations. Do you operate in any high-risk jurisdictions?
- Your delivery channels. Are you exposed to any risks from new technologies, such as online or mobile platforms?
Every later step is built on what this analysis finds, which is why our AML compliance advisers work through it with clients before a policy is drafted.
What the written procedures have to cover
Internal policies, controls and procedures must be approved by senior management, must enable the business to manage and mitigate the risks it has identified, and must be reviewed and updated on a continuous basis. They should cover all of the key areas of AML compliance, including:
- customer due diligence (CDD)
- enhanced due diligence (EDD) for high-risk customers
- transaction monitoring
- reporting of suspicious transactions
- record keeping
Our AML compliance service covers each of these areas.
The compliance officer needs authority and resources
Appoint a designated compliance officer who has the necessary skills, experience and authority to oversee your AML compliance programme. The officer should also be given the resources they need to do their job effectively.
Training for the people who meet customers and move money
Training should be tailored to the specific roles and responsibilities of employees in customer-facing or transaction-processing roles. It should be updated regularly to reflect any changes in the law or in your business's risk profile. Our employment law service advises on the employment side of these obligations, and our AML compliance team provides employee training on the policies themselves.
Testing whether the programme works
Your AML compliance programme should be subject to regular independent auditing, to check both that it is effective and that it is being implemented correctly.
Nothing here is finished once it is written
Building an effective AML compliance programme is not a one-off project. The risks of financial crime are constantly evolving, and your programme needs to evolve with them. The law can change, and so can your business's risk profile. Either is a reason to go back over the risk assessment, the policies and procedures, and the employee training, and to update them so that the business remains protected.
Nour Attorneys assists with all aspects of AML compliance, from conducting a risk assessment to providing employee training.
Disclaimer: the information in this article is for general information only and does not constitute legal advice. Readers should seek professional legal advice tailored to their specific circumstances before making any decisions or taking any action based on its content.