The regulatory landscape of the United Arab Emirates (UAE) is undergoing a rapid and sophisticated transformation. As a global financial hub bridging East and West, the UAE continues to fortify its defenses against illicit financial flows, money laundering, and terrorism financing. The introduction of Federal Decree Law No 10 of 2025 UAE marks a monumental milestone in this ongoing evolution, updating and refining the nation’s anti-money laundering and counter-terrorism financing (AML/CFT) framework to meet the highest international standards.
For compliance officers, risk managers, Designated Non-Financial Businesses and Professions (DNFBPs), and financial institutions, understanding this new decree is not merely a matter of legal conformity—it is a strategic necessity. This practical guide provides an in-depth analysis of Federal Decree Law No 10 of 2025 UAE, highlighting key regulatory shifts, operational impacts, and actionable steps to ensure your organization remains fully compliant and resilient.
The Strategic Context of Federal Decree Law No 10 of 2025 UAE
To appreciate the significance of the new decree, one must view it through the lens of the UAE's broader commitment to financial integrity. Following the country's successful exit from the Financial Action Task Force (FATF) grey list, regulatory bodies have doubled down on maintaining a robust, proactive, and highly effective AML/CFT regime. Federal Decree Law No 10 of 2025 UAE builds upon the foundation laid by previous legislations, such as Federal Decree-Law No. 20 of 2018, by introducing more precise definitions, enhanced supervisory powers, and stricter enforcement mechanisms.
The primary objective of this decree is to close existing regulatory gaps, address emerging financial crime typologies (such as virtual asset exploitation and complex corporate structures), and foster seamless coordination among domestic and international supervisory authorities. By aligning local practices with modern global standards, the UAE ensures its financial ecosystem remains secure, transparent, and attractive to legitimate global capital.
Key Regulatory Shifts and Amendments
Federal Decree Law No 10 of 2025 UAE introduces several critical amendments that redefine how businesses must approach compliance. Below is an analysis of the most significant changes:
1. Expanded Scope of Obligated Entities
The decree broadens and clarifies the definitions of entities subject to AML/CFT obligations. While traditional financial institutions and DNFBPs remain under strict scrutiny, the law places a renewed emphasis on digital assets, virtual asset service providers (VASPs), and complex corporate vehicles. Any entity facilitating the transfer, exchange, or custody of digital value must now operate under the same rigorous compliance standards as traditional banking institutions.
2. Enhanced Ultimate Beneficial Ownership (UBO) Transparency
Identifying the natural persons who ultimately own or control a legal entity has always been a cornerstone of effective AML compliance. The 2025 decree mandates stricter verification protocols for UBOs. Businesses can no longer rely solely on self-declarations; they must conduct independent verification using reliable, independent source documents and maintain real-time, updated registers accessible to regulatory authorities upon request.
3. Stricter Penalties for Non-Compliance
To deter non-compliance, the decree significantly escalates the administrative and criminal penalties for violations. Financial penalties have been scaled, and personal liability for compliance officers and senior management has been clarified. Under the new framework, negligence in establishing a robust compliance program can lead to severe personal and corporate repercussions, including license revocation and criminal prosecution.
4. Focus on Proliferation Financing and Targeted Financial Sanctions (TFS)
The 2025 decree integrates targeted financial sanctions and proliferation financing counter-measures directly into the core compliance workflow. Screening against local and international sanctions lists (such as the UAE Local Terrorist List and the UN Security Council Consolidated List) must be automated, real-time, and continuous.
Impact on Designated Non-Financial Businesses and Professions (DNFBPs)
DNFBPs—including real estate brokers, corporate service providers (CSPs), legal professionals, auditors, and dealers in precious metals and stones—face some of the most substantial operational shifts under Federal Decree Law No 10 of 2025 UAE. Historically viewed as high-risk sectors for money laundering, these industries must now elevate their compliance maturity.
Real Estate Sector Implications
The UAE real estate market, particularly in Dubai, remains a key driver of economic growth. Under the new decree, real estate developers and brokers must apply stringent Customer Due Diligence (CDD) and Enhanced Due Diligence (EDD) to all transactions, especially those involving cash, virtual assets, or complex corporate buyers. Compliance officers must ensure that any transaction matching specific risk indicators is flagged and analyzed immediately.
Corporate Service Providers (CSPs)
CSPs are on the front lines of corporate formation. The decree requires CSPs to conduct exhaustive background checks on company founders, directors, and UBOs. If a client structure involves multiple layers of offshore entities or trusts, the CSP must map out the entire ownership chain and document the legitimate commercial purpose of such a structure before onboarding.
| Sector | Key Focus Areas Under 2025 Decree | Required Action |
|---|---|---|
| Real Estate | High-value cash transactions, virtual asset payments, foreign buyers. | Implement robust CDD/EDD; report cash transactions exceeding thresholds via goAML. |
| CSPs | Complex corporate structures, offshore entities, nominee arrangements. | Map full UBO chains; verify source of wealth (SoW) and source of funds (SoF). |
| Precious Metals & Stones | Physical cash transactions, high-value asset transfers. | Enforce strict cash transaction limits; conduct real-time sanctions screening. |
The Risk-Based Approach (RBA): The Core of the 2025 Framework
A central theme of Federal Decree Law No 10 of 2025 UAE is the transition from a rules-based compliance checklist to a dynamic, Risk-Based Approach (RBA). Regulators do not expect a one-size-fits-all compliance program; instead, they demand that businesses allocate their resources where the risks are highest.
Conducting an Enterprise-Wide Risk Assessment (EWRA)
To comply with the new standards, every obligated entity must conduct and document an Enterprise-Wide Risk Assessment (EWRA). This assessment must evaluate risks across four primary pillars:
- Customer Risk: Assessing the risk profile of clients (e.g., Politically Exposed Persons (PEPs), high-net-worth individuals, clients from high-risk jurisdictions).
- Geographic Risk: Evaluating the risks associated with the countries where the business operates, where clients are based, or where transactions originate/terminate.
- Product/Service Risk: Identifying inherent risks in the specific products or services offered (e.g., cash-intensive services, anonymous digital transactions, complex corporate structuring).
- Delivery Channel Risk: Analyzing how services are delivered (e.g., non-face-to-face onboarding, third-party intermediaries).
The EWRA must be updated at least annually, or immediately upon significant changes to the business model, regulatory environment, or operational footprint. It must be approved by senior management and serve as the foundation for all compliance policies, controls, and procedures.
Technology, goAML, and Transaction Monitoring
In the modern regulatory environment, manual compliance processes are no longer sufficient. Federal Decree Law No 10 of 2025 UAE emphasizes the integration of technology to detect and prevent financial crime in real time.
Optimizing the goAML Portal
The goAML portal, developed by the United Nations Office on Drugs and Crime (UNODC) and utilized by the UAE Financial Intelligence Unit (FIU), remains the primary channel for reporting suspicious activities. Under the 2025 decree, the quality, speed, and accuracy of Suspicious Activity Reports (SARs) and Suspicious Transaction Reports (STRs) are under intense scrutiny. Defensive filing—submitting low-quality reports simply to avoid regulatory ire—is highly discouraged. Reports must contain detailed, structured intelligence, clear narratives, and supporting documentation.
Automated Transaction Monitoring and Sanctions Screening
Businesses must implement automated transaction monitoring systems capable of identifying unusual patterns, structuring (smurfing), and rapid movement of funds. Sanctions screening must be integrated into the onboarding and transaction lifecycle, ensuring that no funds are transferred to or received from designated individuals or entities. Automated alerts must be investigated promptly, and any true matches must be frozen immediately in accordance with Targeted Financial Sanctions guidelines.
A Step-by-Step Implementation Roadmap for Compliance Officers
Transitioning your organization's compliance framework to align with Federal Decree Law No 10 of 2025 UAE requires a structured, methodical approach. Compliance officers should follow this roadmap:
Step 1: Gap Analysis
Compare your current AML/CFT policies, procedures, and controls against the requirements of the 2025 decree. Identify gaps in UBO verification, transaction monitoring thresholds, sanctions screening frequency, and staff training.
Step 2: Update the Enterprise-Wide Risk Assessment (EWRA)
Revise your EWRA to reflect the new risk factors introduced by the decree. Ensure that emerging risks, such as virtual asset exposure or complex corporate clients, are thoroughly evaluated and mitigated.
Step 3: Revise Policies, Controls, and Procedures (PCPs)
Update your written compliance manual to reflect the new regulatory standards. Ensure that clear protocols are established for CDD, EDD, simplified due diligence (SDD), PEP screening, and goAML reporting.
Step 4: Upgrade Compliance Technology
Assess your current compliance software. Ensure your transaction monitoring and sanctions screening tools are calibrated correctly, with minimal false positives and maximum accuracy. Verify that your system integrates seamlessly with the latest UAE regulatory databases.
Step 5: Conduct Specialized Training
A compliance program is only as strong as the people executing it. Conduct comprehensive, role-specific training for all employees, from front-line sales staff to senior management and board members. Ensure everyone understands their obligations under Federal Decree Law No 10 of 2025 UAE.
Step 6: Independent AML Audit
Schedule an independent, third-party AML audit to validate the effectiveness of your updated compliance framework. An external audit provides an unbiased assessment of your controls and demonstrates to regulators your commitment to compliance.
How Tareq Badarin & Farahat & Co. Can Assist Your Business
Navigating the complexities of Federal Decree Law No 10 of 2025 UAE requires specialized expertise and deep local regulatory knowledge. Operating in collaboration with Farahat & Co., a leading professional services firm in the UAE, Tareq Badarin provides comprehensive, end-to-end AML compliance and financial crime advisory services tailored to your specific industry.
Our specialized solutions include:
- Regulatory Advisory & Consultation: Interpreting the nuances of the 2025 decree and aligning your business model with UAE regulatory expectations.
- Enterprise-Wide Risk Assessments (EWRA): Designing and executing robust risk assessment frameworks that identify, measure, and mitigate your specific risk exposures.
- KYC & CDD Optimization: Streamlining your client onboarding processes, enhancing UBO verification protocols, and implementing efficient EDD workflows.
- AML Compliance Audits: Conducting independent, rigorous audits to test the effectiveness of your controls and ensure readiness for regulatory inspections.
- Compliance Training: Delivering practical, engaging training programs to equip your team with the knowledge and skills needed to maintain a culture of compliance.
Do not wait for a regulatory inspection to discover gaps in your compliance framework. Contact us today to secure your business, protect your reputation, and ensure full alignment with Federal Decree Law No 10 of 2025 UAE.
Operationalizing the Three Lines of Defense Under the 2025 Framework
To successfully absorb the structural changes mandated by Federal Decree Law No 10 of 2025 UAE, organizations must move beyond theoretical compliance and establish clear operational boundaries. Relying solely on a compliance officer to detect and prevent financial crime is no longer viable under the updated legal regime. Instead, businesses must implement a modernized “Three Lines of Defense” governance model that distributes accountability across the entire organizational structure.
First Line of Defense: Frontline Operations and Business Units
The first line of defense consists of relationship managers, sales agents, customer onboarding specialists, and front-office staff. Under Federal Decree Law No 10 of 2025 UAE, these individuals are the primary gatekeepers. They are responsible for executing initial Customer Due Diligence (CDD), identifying red flags during face-to-face or digital interactions, and gathering accurate Ultimate Beneficial Ownership (UBO) information at the point of sale. First-line staff must be trained to recognize transaction structuring, inconsistent client profiles, and suspicious wealth sources before transactions are initiated.
Second Line of Defense: The Compliance Function and Risk Management
The second line of defense is led by the designated Compliance Officer and the risk management team. This function operates independently of the revenue-generating business units. Under the 2025 decree, the responsibilities of the second line have expanded to include:
- Continuous monitoring and calibration of automated transaction screening systems.
- Conducting deep-dive Enhanced Due Diligence (EDD) on high-risk clients, politically exposed persons (PEPs), and complex corporate entities.
- Managing the goAML portal workflow, including the objective analysis and timely filing of Suspicious Activity Reports (SARs) and Suspicious Transaction Reports (STRs).
- Providing regulatory advisory support to the frontline business units and maintaining the Enterprise-Wide Risk Assessment (EWRA).
Third Line of Defense: Independent Internal and External Audit
The third line of defense provides independent assurance to the board of directors and senior management regarding the overall effectiveness of the compliance framework. This line is executed by internal audit teams or specialized external consultants. The third-line audit must evaluate whether the first and second lines are functioning in harmony, test the integrity of the automated compliance software, and verify that the policies updated in response to Federal Decree Law No 10 of 2025 UAE are actively practiced rather than existing merely as paper policies.
Governance and Board-Level Oversight
A critical shift introduced by the 2025 framework is the explicit assignment of personal liability to senior management and board members for systemic compliance failures. Governing bodies can no longer treat anti-money laundering protocols as a secondary operational issue. Boards must establish formal reporting lines, review quarterly compliance performance reports, allocate adequate financial and technological resources to the compliance department, and actively foster an organizational culture that prioritizes financial integrity over short-term commercial gains.
Common Implementation Pitfalls and Operational Mistakes to Avoid
As organizations transition their compliance frameworks to align with Federal Decree Law No 10 of 2025 UAE, several operational vulnerabilities frequently undermine their efforts. Understanding these common pitfalls allows compliance officers and senior management to proactively address weaknesses before they result in regulatory penalties or operational disruption.
1. Over-Reliance on Automated Out-of-the-Box Software Settings
While Federal Decree Law No 10 of 2025 UAE emphasizes the integration of automated transaction monitoring and sanctions screening, a frequent mistake is treating these systems as “set-and-forget” solutions. Utilizing default vendor rules without customizing thresholds to match the organization’s specific risk profile leads to two major issues:
- False Positive Fatigue: High volumes of irrelevant alerts overwhelm compliance analysts, leading to superficial investigations and a higher likelihood of missing genuine suspicious activity.
- Undetected Red Flags: Failure to calibrate rules against local UAE risk typologies, such as specific regional trade-based money laundering patterns, leaves critical gaps in detection.
Organizations must establish a regular calibration schedule, testing and tuning scenario rules at least semi-annually to ensure alignment with actual transaction behaviors.
2. Inadequate Verification of Complex Corporate Structures
Another prevalent operational failure is relying solely on self-declarations or basic registry extracts for Ultimate Beneficial Ownership (UBO) verification. Under the 2025 decree, superficial checks are insufficient for high-risk corporate clients, offshore entities, or multi-layered trust arrangements. Compliance teams must actively trace ownership chains down to the natural persons holding the ultimate control or economic interest, documenting every step of the verification process. Accepting incomplete corporate charts without independent verification remains a primary target for regulatory scrutiny.
3. Treating the EWRA as a Static Document
The Enterprise-Wide Risk Assessment (EWRA) is frequently treated as a paper-based exercise designed solely to satisfy auditors. However, the 2025 framework demands that the EWRA function as a dynamic operational tool. When businesses launch new digital delivery channels, target new geographic markets, or onboard higher-risk client segments without immediately updating their EWRA, their operational controls quickly become misaligned with their actual risk exposure. The risk assessment must be integrated directly into the product development and strategic planning lifecycles.
4. Insufficient Documentation of Compliance Decisions
In regulatory audits, undocumented actions are considered non-existent. A common pitfall is the failure to maintain a clear, chronological audit trail of compliance decisions, particularly regarding:
- The rationale behind discounting a potential sanctions match or false positive.
- The decision-making process that led to not filing a SAR/STR after an internal alert was raised.
- The justification for applying Simplified Due Diligence (SDD) to specific low-risk clients.
Compliance teams must implement structured case management systems where every decision, along with its supporting evidence and regulatory justification, is permanently recorded and easily retrievable for regulatory inspectors.
Frequently Asked Questions
What is Federal Decree Law No 10 of 2025 UAE?
Federal Decree Law No 10 of 2025 UAE is a major regulatory update to the United Arab Emirates' anti-money laundering and counter-terrorism financing (AML/CFT) framework. It introduces stricter definitions, enhanced supervisory powers, more rigorous UBO verification requirements, and escalated penalties for non-compliance.
Who is affected by Federal Decree Law No 10 of 2025 UAE?
The decree affects all financial institutions, virtual asset service providers (VASPs), and Designated Non-Financial Businesses and Professions (DNFBPs) operating in the UAE, including real estate brokers, corporate service providers (CSPs), auditors, and precious metals dealers.
What are the key changes regarding Ultimate Beneficial Ownership (UBO)?
Under the 2025 decree, businesses must implement stricter verification protocols for UBOs. Relying solely on client self-declarations is no longer sufficient; entities must independently verify UBO identity using reliable, independent sources and maintain real-time registers.
How does the decree impact real estate transactions in Dubai?
Real estate brokers and developers must apply enhanced due diligence (EDD) to high-risk transactions, particularly those involving cash, virtual assets, or complex corporate structures, and report any suspicious activity or cash transactions exceeding regulatory thresholds via the goAML portal.
What steps should compliance officers take immediately?
Compliance officers should conduct a thorough gap analysis, update their Enterprise-Wide Risk Assessment (EWRA), revise internal policies and procedures, upgrade transaction monitoring and screening technology, and conduct specialized training for all staff.


