The United Arab Emirates (UAE) has consistently demonstrated its commitment to safeguarding the integrity of its financial system. As a global hub for trade, real estate, and financial services, the nation continuously refines its regulatory frameworks to counter financial crimes effectively. The introduction of Federal Decree-Law No. 10 of 2025 UAE represents the latest milestone in this ongoing regulatory evolution, building upon the foundations laid by Federal Decree-Law No. 20 of 2018 and its subsequent amendments.
This new decree-law introduces sophisticated compliance standards designed to address emerging risks in the modern financial landscape. For compliance officers, corporate risk managers, and business leadersโparticularly within Designated Non-Financial Businesses and Professions (DNFBPs) and financial institutionsโunderstanding these updates is not merely a matter of regulatory adherence; it is a strategic necessity to ensure operational continuity and mitigate substantial legal risks.
The Strategic Context of Federal Decree-Law No. 10 of 2025 UAE
The UAE’s regulatory journey is characterized by proactive alignment with international standards, particularly those set by the Financial Action Task Force (FATF). Over the past several years, the Ministry of Economy, the Central Bank of the UAE (CBUAE), and the Executive Office for Control and Non-Proliferation (EOCN) have intensified their oversight. Federal Decree-Law No. 10 of 2025 is designed to consolidate these efforts, addressing complex financial crime typologies that have emerged with the rise of digital assets, cross-border transactions, and sophisticated corporate structures.
By enacting this decree-law, the UAE government aims to achieve several key objectives:
- Strengthen National Security: By cutting off illicit financial flows that support terrorism and proliferation financing.
- Enhance Market Transparency: Ensuring that ultimate beneficial ownership (UBO) information is accurate, accessible, and verified.
- Foster International Trust: Demonstrating to global partners and investors that the UAE maintains a secure, transparent, and compliant investment environment.
- Modernize Enforcement Mechanisms: Equipping regulatory bodies with advanced tools and broader mandates to detect, investigate, and penalize non-compliance.
The timing of this decree aligns with the UAE’s broader economic vision, which emphasizes digital transformation and the growth of non-oil sectors. As the country attracts unprecedented volumes of foreign direct investment (FDI), maintaining a clean financial ecosystem is paramount. The 2025 decree serves as a clear signal to international markets that the UAE will not tolerate financial misconduct within its borders.
Key Structural Changes and Regulatory Shifts
Federal Decree-Law No. 10 of 2025 UAE introduces several pivotal shifts in how anti-money laundering (AML) and countering the financing of terrorism (CFT) programs must be structured and executed. Below is an overview of the primary areas of transformation.
1. Enhanced Focus on Technology and Digital Assets
The integration of technology in financial services has created new avenues for illicit actors. The 2025 decree-law places a heavy emphasis on the regulation of Virtual Asset Service Providers (VASPs) and the use of decentralized technologies. Compliance frameworks must now explicitly account for the risks associated with virtual assets, peer-to-peer transactions, and privacy-enhancing technologies.
Organizations are now required to conduct specialized risk assessments before deploying any new technology or offering virtual asset-related services. This proactive approach ensures that technological innovation does not outpace regulatory oversight.
2. Stricter Ultimate Beneficial Ownership (UBO) Requirements
Transparency remains a cornerstone of the UAE’s AML strategy. Under the new decree, the requirements for identifying, verifying, and reporting UBOs have been tightened. Corporate Service Providers (CSPs) and legal entities must maintain real-time, accurate registers of beneficial ownership and report any changes to the relevant licensing authorities without delay. The law introduces stricter penalties for failing to maintain accurate UBO records or providing misleading information.
The definition of a beneficial owner has been refined to prevent the use of complex, multi-layered corporate structures to hide the identity of the true controlling individuals. Compliance officers must look beyond nominal shareholders to identify any individual who exercises ultimate effective control over the legal entity.
3. Expanded Scope for DNFBPs
Designated Non-Financial Businesses and Professions, including real estate brokers, lawyers, auditors, and trust and company service providers, face heightened scrutiny. The 2025 standards demand that DNFBPs implement risk-based compliance programs that are as robust as those found in traditional banking sectors. This includes mandatory registration on regulatory portals like goAML and the implementation of comprehensive Customer Due Diligence (CDD) procedures.
DNFBPs can no longer rely on simplified due diligence as a default option. Instead, they must demonstrate a deep understanding of their clients’ business profiles and source of wealth, particularly when dealing with high-value transactions or clients from high-risk jurisdictions.
Comparative Analysis: Previous Framework vs. Federal Decree-Law No. 10 of 2025
To help compliance professionals understand the practical differences, the following table highlights the key transitions from the previous regulatory framework to the standards established under Federal Decree-Law No. 10 of 2025.
| Regulatory Area | Previous Framework (Decree-Law No. 20 of 2018 & Amendments) | New Standards (Federal Decree-Law No. 10 of 2025) |
|---|---|---|
| Technology Integration | Basic guidelines on digital onboarding and virtual asset risks. | Mandatory risk assessments for virtual assets; integration of AI-driven transaction monitoring. |
| UBO Verification | Self-declaration by clients with periodic verification by the business. | Strict independent verification of UBO data; real-time reporting of ownership changes. |
| DNFBP Supervision | Focus on registration and basic policy implementation. | Intensified, audit-ready compliance programs; strict enforcement of goAML reporting. |
| Penalties & Enforcement | Standard administrative fines and potential license suspensions. | Substantially increased financial penalties; personal liability for compliance officers in cases of gross negligence. |
| Suspicious Transaction Reporting | Reporting based on general suspicion with standard timelines. | Accelerated reporting windows; enhanced data quality requirements for goAML submissions. |
Impact on Key Sectors in the UAE
The implications of Federal Decree-Law No. 10 of 2025 UAE vary across industries. Understanding sector-specific impacts is crucial for developing targeted compliance strategies.
Real Estate Sector
Dubai’s real estate market is a vital component of the UAE economy. Because real estate transactions often involve high-value transfers, the sector is naturally exposed to money laundering risks. Under the 2025 decree-law, real estate developers, brokers, and agents must strictly adhere to CDD and Enhanced Due Diligence (EDD) protocols. This includes verifying the source of funds for high-value cash transactions, virtual asset payments, and transactions involving politically exposed persons (PEPs).
Furthermore, real estate professionals must ensure that all transactions involving cash or virtual assets above the designated regulatory thresholds are reported promptly through the goAML portal. Failure to do so can result in severe administrative fines and the suspension of professional licenses.
Corporate Service Providers (CSPs)
As gatekeepers to the UAE’s corporate ecosystem, CSPs bear a significant responsibility. The new law requires CSPs to conduct rigorous background checks on foreign entities seeking to establish a presence in the UAE. CSPs must ensure that the corporate structures they help create are transparent and do not serve as shell companies designed to obscure illicit wealth.
CSPs must also maintain ongoing monitoring of their clients’ business activities. If a client’s business model changes significantly or if they engage in transactions that do not align with their declared business profile, the CSP must update their risk assessment and, if necessary, file a suspicious activity report.
Financial Institutions
Banks, exchange houses, and insurance companies must upgrade their transaction monitoring systems to detect complex, multi-layered transaction patterns. The 2025 standards emphasize the need for real-time sanctions screening and the rapid reporting of Suspicious Transaction Reports (STRs) and Suspicious Activity Reports (SARs) via the goAML portal.
Financial institutions are also expected to foster closer collaboration with regulatory authorities and law enforcement agencies. This includes participating in public-private partnerships and sharing information on emerging financial crime typologies to strengthen the national defense against illicit finance.
Practical Steps for Compliance Officers to Align with the 2025 Standards
Transitioning to the new regulatory standards requires a structured, proactive approach. Compliance officers should consider the following steps to ensure their organizations remain fully compliant:
Step 1: Conduct an Enterprise-Wide Risk Assessment (EWRA)
An EWRA is the foundation of any effective AML program. Under the new decree, businesses must update their risk assessments to reflect the specific risk factors identified in Federal Decree-Law No. 10 of 2025. This involves analyzing customer risk, geographic risk, product/service risk, and delivery channel risk.
The EWRA should be a dynamic document, updated at least annually or whenever there are significant changes in the business environment or regulatory landscape. It must clearly document how the organization identifies, assesses, and mitigates its specific AML/CFT risks.
Step 2: Update AML/CFT Policies and Procedures
Existing compliance manuals must be revised to incorporate the updated definitions, reporting timelines, and UBO verification procedures mandated by the new law. Ensure that these policies are approved by senior management and communicated clearly to all relevant staff members.
Policies should include clear guidelines on the use of technology, the handling of virtual assets, and the procedures for identifying and reporting suspicious transactions. They should also outline the roles and responsibilities of the compliance officer and other key personnel.
Step 3: Enhance Customer Due Diligence (CDD) and KYC Protocols
Implement robust Know Your Customer (KYC) procedures that leverage reliable, independent source documents. For high-risk clients, apply Enhanced Due Diligence (EDD) measures, which may include obtaining additional information on the source of wealth and the purpose of the business relationship.
Verification processes should be automated where possible to reduce human error and ensure consistency. However, compliance teams must retain the capability to conduct manual reviews and exercise professional judgment in complex cases.
Step 4: Invest in Compliance Training
A compliance program is only as strong as the people executing it. Regular training programs are essential to ensure that employees can identify red flags, understand their reporting obligations, and navigate the goAML platform effectively.
Training should be tailored to the specific roles of employees. For example, front-line staff should focus on identifying suspicious customer behavior, while compliance analysts should receive advanced training on transaction monitoring and investigation techniques.
Step 5: Implement Independent AML Audits
Regular, independent audits of your AML/CFT framework are critical to identifying gaps and ensuring operational effectiveness. These audits provide senior management and regulatory authorities with assurance that the compliance program is functioning as intended.
The audit should cover all aspects of the compliance program, including policies and procedures, risk assessments, CDD/KYC processes, transaction monitoring, and training. The findings of the audit should be documented, and any identified deficiencies should be addressed promptly through a corrective action plan.
Risk Considerations and Enforcement Trends
The introduction of Federal Decree-Law No. 10 of 2025 UAE signals a shift toward a more aggressive enforcement posture by UAE regulatory bodies. Compliance officers must be aware of the key risk considerations and enforcement trends to protect their organizations from severe penalties.
Increased Personal Liability
One of the most significant changes under the new decree is the potential for increased personal liability for compliance officers and senior management. In cases of gross negligence or willful blindness, individuals can be held personally liable for compliance failures, facing substantial fines and potential criminal charges. This highlights the importance of maintaining a culture of compliance and ensuring that compliance officers have the authority and resources they need to perform their duties effectively.
Focus on Data Quality and Reporting
Regulatory authorities are placing a greater emphasis on the quality of data submitted through the goAML portal. Incomplete or inaccurate reports can lead to delays in investigations and may be viewed as a compliance failure. Organizations must ensure that their transaction monitoring systems generate high-quality alerts and that compliance analysts conduct thorough investigations before submitting reports.
Collaborative Enforcement
The UAE is increasingly working with international partners and law enforcement agencies to combat cross-border financial crime. This collaborative approach means that compliance failures in the UAE can have global repercussions, affecting an organization’s reputation and ability to operate in international markets. Businesses must ensure that their compliance programs are designed to meet both local and international standards.
How Tareq Badarin and Farahat & Co. Can Assist
Navigating the complexities of Federal Decree-Law No. 10 of 2025 UAE requires specialized expertise and a deep understanding of the local regulatory landscape. Operating within the framework of Farahat & Co., Tareq Badarin provides comprehensive AML, CTF, and risk management advisory services tailored to the unique needs of businesses in Dubai and the wider UAE.
Our services include:
- Regulatory Advisory & Consultation: Helping you interpret and apply the latest legal updates to your business operations.
- KYC & CDD Optimization: Streamlining your onboarding processes while ensuring full compliance with verification standards.
- Enterprise-Wide Risk Assessments (EWRA): Designing and executing risk assessments that identify and mitigate potential vulnerabilities.
- AML Compliance Audits: Conducting independent reviews of your compliance framework to ensure audit readiness.
- Certification and Training Programs: Equipping your compliance team with the knowledge and skills required to manage regulatory risks effectively.
Protect your business from regulatory penalties and reputational damage. Contact Tareq Badarin today to schedule a consultation and ensure your compliance framework is fully aligned with the standards of Federal Decree-Law No. 10 of 2025.
Frequently Asked Questions
What is the primary focus of Federal Decree-Law No. 10 of 2025 UAE?
The primary focus of Federal Decree-Law No. 10 of 2025 is to modernize the UAE's AML/CFT framework by introducing stricter ultimate beneficial ownership (UBO) verification, enhancing oversight of virtual assets and VASPs, expanding compliance requirements for DNFBPs, and increasing penalties for non-compliance.
How does the new decree-law affect real estate firms in Dubai?
Real estate firms must implement more rigorous Customer Due Diligence (CDD) and Enhanced Due Diligence (EDD) procedures. This includes verifying the source of funds for high-value cash transactions, virtual asset payments, and transactions involving politically exposed persons (PEPs), as well as reporting suspicious activities via the goAML portal.
What are the consequences of non-compliance under the 2025 standards?
Non-compliance can result in substantially increased financial penalties, administrative sanctions, suspension of business licenses, and potential personal liability or criminal prosecution for compliance officers and senior management in cases of gross negligence.
What steps should businesses take to align with Federal Decree-Law No. 10 of 2025?
Businesses should conduct an Enterprise-Wide Risk Assessment (EWRA), update their AML/CFT policies and procedures, enhance their KYC and UBO verification protocols, invest in regular staff training, and schedule independent AML compliance audits.


