Quick Summary
A comprehensive practical guide to navigating UAE anti-money laundering regulations, regulatory frameworks, risk assessments, UBO registration, and goAML compliance for businesses.
Navigating the United Arab Emirates’ anti-money laundering (AML) and counter-terrorism financing (CFT) regulatory landscape requires a clear understanding of federal decrees, cabinet resolutions, and sectoral supervisory guidelines. Whether operating as a Financial Institution (FI) or a Designated Non-Financial Business or Profession (DNFBP), maintaining full regulatory compliance is essential for mitigating financial crime risks, maintaining international banking relationships, and avoiding severe administrative penalties. This comprehensive UAE AML regulations compliance guide details the foundational pillars of the UAE AML framework, outlining step-by-step compliance requirements, risk assessment methodologies, Ultimate Beneficial Ownership (UBO) obligations, and best practices for leveraging the goAML portal effectively.
Understanding the UAE AML Legal and Regulatory Framework
The UAE’s anti-money laundering regime is designed to meet international standards set by the Financial Action Task Force (FATF). The primary legislative framework governs all commercial, financial, and professional entities operating across both mainland UAE and commercial free zones, including international financial centers like the Dubai International Financial Centre (DIFC) and Abu Dhabi Global Market (ADGM).
Key Statutory Laws and Cabinet Resolutions
The legal backbone of the UAE’s anti-financial crime regime consists of interlocking legislative acts that define criminal offenses, mandate preventive measures, and empower supervisory authorities to enforce compliance across all commercial sectors:
- Federal Decree-Law No. (20) of 2018: The foundational law on anti-money laundering and combating the financing of terrorism and illegal organizations. It establishes the legal definition of money laundering, penalizes money laundering predicate offenses, and sets out the fundamental obligations for financial and non-financial entities.
- Cabinet Decision No. (10) of 2019: The executive regulations accompanying Federal Decree-Law No. (20) of 2018, detailing operational requirements for customer due diligence (CDD), suspicious transaction reporting, record-keeping, and compliance officer duties.
- Federal Decree-Law No. (10) of 2025: The updated legislation modernizing anti-financial crime enforcement, expanding supervisory oversight, introducing stricter measures for virtual asset operations, and strengthening cross-border cooperation mechanisms.
- Cabinet Decision No. (109) of 2023: Regulates Ultimate Beneficial Ownership (UBO) procedures across all mainland and non-financial free zone entities, replacing Cabinet Decision No. (58) of 2020 to standardize beneficial ownership registers.
- Cabinet Decision No. (74) of 2020: Establishes procedures for Targeted Financial Sanctions (TFS) and the implementation of UN Security Council sanctions lists alongside the UAE Local Terrorist List.
Primary UAE Regulatory and Supervisory Authorities
Compliance oversight in the UAE is divided among specific federal and local bodies based on business activities and license types. Each authority issues detailed guidelines, conducts regular on-site and off-site inspections, and enforces administrative penalties for non-compliance within its domain.
| Supervisory Body | Regulated Sector / Entities Covered | Primary Focus & Guidance Scope |
|---|---|---|
| Central Bank of the UAE (CBUAE) | Banks, exchange houses, finance companies, payment service providers, stored value facilities, and insurance entities. | Prudential oversight, transaction monitoring, institutional AML risk management, and goAML integration. |
| Securities and Commodities Authority (SCA) | Capital markets, brokers, investment funds, asset managers, and financial advisory firms. | Market integrity, securities trading oversight, investment fund CDD, and insider trading prevention. |
| Ministry of Economy (MoE) | Mainland DNFBPs including real estate agents, precious metal dealers, auditors, accountants, and corporate service providers. | DNFBP registration, goAML portal compliance, UBO register oversight, and sector-specific inspections. |
| DFSA / FSRA (DIFC & ADGM) | Financial entities and DNFBPs registered in DIFC and ADGM respectively. | International financial center regulatory standards, independent regulatory rulebooks, and specialized licensing. |
| Ministry of Justice (MoJ) | Lawyers, legal consultants, law firms, and independent legal practitioners. | Legal profession regulatory oversight, client trust account monitoring, and legal services AML guidelines. |
| Virtual Assets Regulatory Authority (VARA) | Virtual Asset Service Providers (VASPs) operating in or from the Emirate of Dubai (excluding DIFC). | Crypto-asset transfers, virtual wallet screening, VASP licensing, and Travel Rule compliance. |
Classification of Obligated Entities: FIs vs. DNFBPs
Under UAE AML regulations, compliance requirements apply strictly based on the nature of a business’s operations. The regulatory framework categorizes obligated businesses into two primary buckets: Financial Institutions (FIs) and Designated Non-Financial Businesses and Professions (DNFBPs).
Financial Institutions (FIs)
Financial Institutions are entities that conduct banking, lending, investment, or payment services. Given their position at the core of the financial system, FIs face stringent regulatory requirements. FIs include:
- Commercial, retail, and investment banks.
- Exchange houses and money transfer services.
- Insurance companies and brokerages.
- Investment management firms and broker-dealers.
- Providers of stored-value cards and digital payment instruments.
Designated Non-Financial Businesses and Professions (DNFBPs)
DNFBPs are non-banking businesses whose professional services can be exploited for money laundering or terrorist financing. Under Cabinet Decision No. (10) of 2019, the following sectors are designated as DNFBPs and must maintain a formal AML compliance program:
- Real Estate Brokers and Developers: When involved in transactions concerning the buying and selling of real estate properties for clients.
- Dealers in Precious Metals and Precious Stones (DPMS): When engaging in any cash transaction (or wire transfer equivalent) equal to or exceeding AED 55,000.
- Auditors, External Accountants, and Tax Consultants: When preparing, executing, or managing financial transactions for their clients.
- Lawyers, Notaries, and Other Independent Legal Professionals: When assisting in the planning or execution of transactions involving real estate purchases, managing client funds/securities, opening bank accounts, or organizing contributions for company formation.
- Company Service Providers (Trust and Company Service Providers – TCSPs): When acting as formation agents, directors, partners, or providing registered office facilities and corporate administration services to third parties.
Core AML/CFT Obligations for UAE Entities
To establish a fully compliant anti-money laundering infrastructure, UAE entities must operationalize specific internal controls and governance policies tailored to their operational exposure. Compliance requires a continuous, active operational process integrated into daily workflow.
1. Enterprise-Wide Risk Assessment (EWRA)
Regulated businesses must conduct a formal, documented Enterprise-Wide Risk Assessment (EWRA) to identify, measure, and understand their specific money laundering and terrorism financing risks. The EWRA forms the foundation of the business’s Risk-Based Approach (RBA) and must be reviewed and updated at least annually or whenever significant structural changes occur.
The EWRA must systematically evaluate risks across four core vectors:
- Customer Risk: Assessing risks linked to client profiles, such as high-net-worth individuals, Politically Exposed Persons (PEPs), complex corporate ownership structures, non-resident clients, cash-intensive businesses, or entities operating in high-vulnerability sectors.
- Geographic Risk: Evaluating risk levels associated with countries where clients reside, operate, or transfer funds. High risk attaches to jurisdictions subject to FATF sanctions, non-cooperative countries, tax havens, or conflict zones.
- Products, Services, and Transaction Risk: Analyzing risk inherent in specific offerings, such as trade finance, private banking, cash-intensive services, anonymous pre-paid cards, or virtual asset operations.
- Delivery Channel Risk: Measuring exposure created by non-face-to-face customer onboarding, online trading platforms, mobile banking applications, or heavy reliance on third-party intermediaries and referral agents.
2. Customer Due Diligence (CDD) and Enhanced Due Diligence (EDD)
Verification of customer identity is mandatory before establishing a business relationship or conducting one-off transactions above regulatory thresholds. Entities must apply a calibrated Risk-Based Approach (RBA) to client onboarding:
Standard Customer Due Diligence (CDD)
Standard CDD applies to medium- and standard-risk clients. The process requires:
- Verifying the identity of individual clients through original, valid government identification documents (e.g., Emirates ID, Passport).
- Verifying corporate legal existence through valid trade licenses, certificates of incorporation, Memorandum and Articles of Association (MOA/AOA), and commercial register documentation.
- Identifying all authorized signatories and verifying their authority through board resolutions or power of attorney.
- Understanding the intended nature and purpose of the business relationship.
Enhanced Due Diligence (EDD)
EDD is legally mandatory when dealing with high-risk customers, Politically Exposed Persons (PEPs), or complex, opaque corporate arrangements. EDD protocols require:
- Establishing and documenting the Source of Wealth (SoW) and Source of Funds (SoF) through verified financial statements, tax returns, or asset title deeds.
- Obtaining explicit senior management approval prior to establishing the relationship or processing transactions.
- Conducting intensified, ongoing monitoring of the business relationship and transaction activity.
- Gathering additional background information via adverse media screening and background intelligence checks.
Simplified Due Diligence (SDD)
SDD is permitted only in low-risk scenarios supported by robust risk evidence. Examples include dealing with UAE public sector entities, publicly listed companies on recognized stock exchanges subject to strict disclosure standards, or regulated financial institutions from equivalent AML jurisdictions.
3. Ultimate Beneficial Ownership (UBO) Identification
Under Cabinet Decision No. (109) of 2023, entities must identify and verify the real physical individuals who ultimately own or control the business. The regulation requires looking through layers of corporate ownership to identify natural persons.
A UBO is defined using a three-tier cascade analysis:
| Tier Level | UBO Identification Criteria | Operational Action Required |
|---|---|---|
| Tier 1: Direct/Indirect Ownership | Any natural person who ultimately owns or controls, directly or indirectly, 25% or more of the entity’s capital or voting rights. | Obtain passport copy, Emirates ID, address proof, and verify percentage of shareholding through share certificates. |
| Tier 2: Ultimate Control | If no individual meets the 25% threshold or if there is doubt, the natural person exercising control through other means (e.g., voting agreements, dominant influence, right to appoint board members). | Review board composition, voting structures, shareholder agreements, and corporate governance documents. |
| Tier 3: Senior Management | If no natural person is identified under Tier 1 or Tier 2, the natural person holding executive management position (e.g., CEO, Managing Director). | Document the operational structure and verify the identity of the highest-ranking executive official. |
Entities must maintain an updated Register of Beneficial Owners and a Register of Partners/Shareholders at their business premises. Any change to UBO details must be updated in the internal register within 15 days and reported to the relevant licensing authority within 15 days of the amendment.
Targeted Financial Sanctions (TFS) and Sanctions Screening
UAE businesses must establish automated or manual sanctions screening procedures aligned with Cabinet Decision No. (74) of 2020. Screening must occur during initial onboarding and continuously whenever updates are published to national or international lists.
Sanctions Screening Checklist
To ensure total compliance with UAE sanctions obligations, entities must implement the following operational checks:
- Local List Screening: Continuous, automated cross-referencing of client databases against the UAE Local Terrorist List published by the Executive Office for Control and Non-Proliferation (EOCN).
- UN Consolidated List Screening: Real-time screening against the United Nations Security Council Resolutions (UNSCR) consolidated lists.
- Commercial / Third-Party Lists: Screening against international databases such as OFAC, EU, UK HMT, and Interpol lists.
- Freeze Requirements: In the event of a confirmed match (positive hit), entities must immediately freeze funds or assets without delay and within 24 hours, without prior notice to the customer.
- Reporting Obligations: Mandatory reporting of partial or confirmed matches via the goAML platform using Funds Freeze Reports (FFR) or Partial Name Match Reports (PNMR) within 24 hours of identification.
goAML Reporting and System Compliance
The goAML portal, developed by the United Nations Office on Drugs and Crime (UNODC) and administered by the UAE Financial Intelligence Unit (FIU), is the central digital platform for financial crime reporting across the United Arab Emirates. Registration on goAML is mandatory for all FIs and DNFBPs.
Key goAML Report Types
Obligated entities must understand the distinct operational triggers for filing specific reports on the goAML system:
| Report Type | Acronym | Regulatory Trigger & Purpose |
|---|---|---|
| Suspicious Transaction Report | STR | Filed when a transaction has taken place and there are reasonable grounds to suspect funds are proceeds of crime or linked to illicit activities. |
| Suspicious Activity Report | SAR | Filed when an attempted transaction or client behavior appears suspicious, even if no financial transaction actually occurred. |
| Funds Freeze Report | FFR | Filed immediately upon freezing funds or assets belonging to individuals or entities listed on UN or UAE Local Sanctions lists. |
| Partial Name Match Report | PNMR | Filed when a potential match occurs on a sanctions list that requires FIU clarification to confirm or rule out identity. |
| High-Risk Country Transaction Report | HCTR | Mandatory filing for transactions involving accounts, individuals, or institutions based in high-risk, non-cooperative jurisdictions. |
| Real Estate Activity Report | REAR | Mandatory for real estate agents and developers for cash transactions, virtual asset payments, or trade-equity arrangements exceeding AED 55,000. |
| Dealers in Precious Metals/Stones Report | DPMSR | Mandatory for precious metals and gems dealers engaging in physical cash transactions or wire transfers equal to or exceeding AED 55,000. |
Role and Qualifications of the AML Compliance Officer
Every regulated entity in the UAE must appoint a dedicated, competent AML Compliance Officer (also referred to as the Money Laundering Reporting Officer – MLRO). The appointed individual must possess deep regulatory knowledge, sufficient operational independence, and direct access to senior management and the board of directors.
Core Responsibilities of the MLRO
The AML Compliance Officer is legally responsible for executing the organization’s compliance duties:
- Maintaining and updating internal AML/CFT policies, procedures, and enterprise risk assessment frameworks.
- Monitoring daily customer transactions and reviewing internal red-flag escalations raised by operational staff.
- Filing STRs, SARs, FFRs, and statutory reports through the goAML portal without notifying the customer (avoiding
Operational Independent Audit and Internal AML Controls Architecture
Establishing an Enterprise-Wide Risk Assessment and onboarding framework fulfills initial legal parameters, but maintaining long-term compliance under UAE AML regulations requires robust internal control mechanisms and ongoing verification. Regulated entities, including Financial Institutions (FIs) and Designated Non-Financial Businesses and Professions (DNFBPs), must construct a three-lines-of-defense model to prevent control drift and operational exposure. A critical requirement within this framework is the independent AML audit, which objectively evaluates whether policies are executed accurately across daily operations.
The Three Lines of Defense Model in UAE Compliance
To ensure systemic accountability, UAE supervisory authorities emphasize structural separation between operational execution, compliance oversight, and independent evaluation. A compliant organization structures its controls across three distinct tiers:
- First Line (Frontline Operations): Business units, relationship managers, and customer service staff responsible for gathering CDD documents, applying initial onboarding controls, identifying red flags, and conducting day-to-day transaction monitoring.
- Second Line (Compliance & MLRO): The designated Money Laundering Reporting Officer (MLRO) and compliance team responsible for setting policy, approving high-risk onboarding, performing EDD, analyzing internal red-flag escalations, and filing reports on the goAML portal.
- Third Line (Independent Audit): An internal or external audit function completely independent of the MLRO and frontline operations, tasked with testing the actual effectiveness of both First and Second Line controls.
Execution Framework for the Independent AML Audit
Under UAE AML statutory rules, an independent audit must be conducted periodically—typically on an annual basis or following major regulatory changes and system migrations. The audit must look beyond written policies to evaluate real-world operational testing. Auditors must sample files, test technical tools, and review administrative logs across several core operational streams.
Audit Scope Vector Operational Sampling Focus Key Testing Criteria Onboarding & CDD Files High-risk, medium-risk, PEP, and UBO onboarding files across all operating units. Verification that UBO declarations match official registers, EDD source-of-wealth proof is uploaded, and senior management approvals exist in file logs prior to account opening. Sanctions Engine Calibration Automated fuzzy-matching engines and transaction screening tools. Testing screening engine thresholds against the local EOCN list and UNSC updates; checking whether rule changes create false-negative gaps during batch screening. goAML Filing Integrity Internal escalation logs vs. goAML portal filings. Verifying that internal alerts raised by frontline staff were properly evaluated by the MLRO and that STR/SAR filings were submitted within mandated timeframes without client tipping-off. Training Program Verification Attendance records, training content, and staff knowledge assessments. Confirming all permanent, temporary, and contractor staff completed role-specific AML training upon joining and during mandatory annual refreshers. Common Operational Audit Findings and Corrective Action Protocols
During supervisory inspections, regulatory bodies often focus on recurring execution failures within compliance workflows. Identifying and rectifying these gaps internally prevents administrative enforcement actions and remediation notices from licensing authorities.
Frequent Internal Control Deficiencies
Audits frequently uncover technical and human breakdowns within active operations, such as:
- Stale UBO Registers: Failing to update the internal UBO register or notify licensing authorities within the 15-day window following structural ownership changes.
- Static Risk Scoring: Leaving client risk profiles unchanged at standard risk despite subsequent involvement in high-risk geographic transfers or significant shifts in transaction volume.
- Incomplete EDD Documentation: Accepting unverified self-declarations for Source of Wealth (SoW) rather than requiring independent corroborative documents such as bank statements, audited accounts, or asset sale agreements.
- Legacy System Screening Gaps: Running manual sanctions screening instead of automated continuous batch screening, leading to delays when EOCN or UN lists undergo sudden revisions.
Documenting Audit Remediation
When an audit identifies deficiencies, the business must formulate a formal Corrective Action Plan (CAP). The MLRO and senior management must assign clear operational owners, set strict completion deadlines, and re-test rectified processes. All audit findings, board review minutes, and CAP execution logs must be retained for at least five years to demonstrate proactive governance during supervisory reviews by relevant UAE regulatory bodies.
Frequently Asked Questions
What businesses are classified as DNFBPs in the UAE?
Designated Non-Financial Businesses and Professions (DNFBPs) include real estate agents and developers, dealers in precious metals and stones, auditors and accountants, legal professionals, and Corporate Service Providers (CSPs) operating in mainland UAE or free zones.
What is the threshold for UBO identification under Cabinet Decision No. 109 of 2023?
Entities must identify any natural person who ultimately owns or controls 25% or more of the company's share capital or voting rights, directly or indirectly.
How quickly must a firm freeze assets upon matching a Targeted Financial Sanctions list?
Under Cabinet Decision No. (74) of 2020, entities must execute a funds freeze within 24 hours of a confirmed match against local or UN sanctions lists without prior notification to the affected customer.
What is the primary function of the goAML portal in the UAE?
The goAML portal is the centralized reporting system operated by the UAE Financial Intelligence Unit (FIU) used by regulated entities to submit Suspicious Transaction Reports (STRs), Suspicious Activity Reports (SARs), and regulatory transaction notifications.


