What an AML/CFT Policy Must Contain (and What Templates Miss)
A UAE AML/CFT policy that a bank, PSP, VARA, DFSA, FSRA or CBUAE desk will accept is a pack mapped to your products, clients, geographies and payment rails. Cabinet Resolution No. 134 of 2025 Article 21 lists the minimum contents. A downloaded PDF copies those headings and leaves the risk assessment, CDD stop, sanctions logic, STR path, compliance-officer duties, record clocks and independent test unconnected to the business. A recycled file of that kind fails a compliance committee in a minute.
AML/CFT policy work starts from the model, not from a blank Word outline. UAE company formation and licensing produces the entity. The pack is a separate artefact.
Who must keep a written AML/CFT pack in the UAE?
Federal Decree by Law No. (10) of 2025 binds financial institutions, designated non-financial businesses and professions, and virtual asset service providers. It entered into force on 14 October 2025, two weeks after publication in Official Gazette No. 808 on 30 September 2025, and repealed Federal Decree-Law No. 20 of 2018. Cabinet Resolution No. 134 of 2025 entered into force on 14 December 2025 and repealed Cabinet Resolution No. 10 of 2019.
Article 19 of the Decree-Law requires those persons to assess crime risks, apply customer due diligence, refuse anonymous or fictitious accounts, keep senior-management-approved internal policies that also cover majority-owned branches and subsidiaries, implement targeted financial sanctions instructions, and retain records. Article 20 forbids the activity without a licence, registration or enrolment from the competent or supervisory authority.
Your supervisor then adds a second layer. CBUAE licensed financial institutions sit under CBUAE guidance and, for exchange-style licensed persons, Rulebook Chapter 16.3. DIFC firms remain “Relevant Persons” under federal AML legislation and the DFSA AML module. ADGM firms sit under the FSRA. Dubai VASPs sit under VARA’s Compliance and Risk Management Rulebook on top of the same federal floor. Ministry of Economy supervision covers many DNFBPs.
FATF Recommendations 1 and 18 describe a risk-based internal programme: policies, a management-level officer, employee screening, training and independent audit. UAE statutes encode that benchmark. Write the pack to Decree-Law 10 and Cabinet 134, not to a US Bank Secrecy Act manual.
Which instruments bind the pack in 2026?
Read the pack against four documents.
The Decree-Law is the statute. Article 18 requires a suspicious transaction report to the Financial Intelligence Unit without delay where you suspect or have reasonable grounds to suspect that a transaction or funds are proceeds or are intended for the crime, regardless of value. Article 19 is the preventive-measures list above. Article 17 gives the supervisor a warning and an administrative fine of AED 10,000 to AED 5,000,000 for each violation. Article 27 is a different regime: a legal person whose representatives, directors or agents commit money laundering, terrorist financing or proliferation financing on its behalf faces AED 5 million to AED 100 million, or the value of the criminal property, whichever is greater.
Cabinet 134 is the operating manual: risk assessment (Art. 5), CDD including the Article 14 stop (Arts. 6-15), PEPs (Art. 16), STRs and tipping-off (Arts. 17-19), the six-item programme minimum (Art. 21), the compliance officer (Art. 22), high-risk countries (Art. 23), new technology (Art. 24), and records (Art. 25).
CBUAE’s Guidance for Licensed Financial Institutions on Customer Due Diligence / Know Your Customer and Recordkeeping, dated 6 November 2025, does not create new legal duties. It states how CBUAE expects LFIs to fulfil existing ones. Records must show why the customer was onboarded, how the customer was risk-rated, and how activity was monitored against that profile. Confirm the live text on the CBUAE AML/CFT portal before you freeze a version number in a board pack.
VARA, DFSA and FSRA rulebooks apply where you hold that licence. A Dubai VASP still sits on the federal floor; VARA adds officer fit-and-proper tests, an eight-year record clock, and Travel Rule evidence at licensing.
What does a real AML/CFT policy pack contain?
A pack is a set of approved documents that a reviewer can test against your business model. The policy states obligations and risk appetite. Procedures tell staff what to do. The risk assessment, STR indicators, training log, independent-test report and board minutes prove the pack runs.
A template sold as “AML policy UAE” or “AML policy template” supplies headings. A committee, a bank or a supervisor opens the missing facts first.
August 2026, against Cabinet 134 and Decree-Law 10. Confirm live supervisor manuals for your licence.
Enterprise-wide risk assessment
A reviewer wants named products, customer types, corridors, delivery channels, NRA and sector inputs, residual risk after controls, plus a date and owner. A template that says “We adopt a risk-based approach” with no product map fails the test.
Risk appetite and governance
Board or owner approval, version control, who may accept high risk, and escalation to senior management. A purpose clause and a logo do not substitute.
CDD: natural persons
Documents, verification timing, deferred-verification conditions (Art. 6), and when CDD repeats (Art. 7-8). A generic ID list copied from another country is the usual omission.
CDD: legal persons and beneficial owners
The 25% ownership test, control fallback, senior-manager fallback (Art. 10), and listed-company treatment (Art. 11). “Identify the UBO” with no cascade is not a procedure.
EDD, PEPs, high-risk countries
Article 5(2) EDD toolkit, foreign versus domestic PEP (Art. 16), and the National Committee high-risk list (Art. 23). A PEP definition plus a screenshot of a screening vendor is the template version.
Incomplete CDD / Article 14 stop
No relationship, no continuation, no transaction. Consider an STR. Tipping-off exception sits in Article 14(2). Silence, or “try to collect more documents,” is the miss.
Ongoing monitoring
Scrutiny against expected activity, refresh of high-risk files (Art. 8), and a named owner of alerts. “Transactions will be monitored” is a slogan.
Sanctions / TFS
UAE local lists and UN lists, freeze-on-match, who decides a hit, and records of freezes. “We screen against sanctions lists” does not name the lists or the freeze owner.
STR / goAML / tipping-off
Indicators (Art. 17). Notify the Unit without delay (Decree-Law Art. 18; Cabinet Art. 18). No disclosure (Art. 19). A “SAR form” with a US FinCEN address belongs in a different country.
Compliance officer / MLRO
Management-level appointment, independence, Article 22 duties, and VARA extra tests if you are a VASP. A job title in the footer is not an appointment.
Employee screening
Fitness and propriety at hiring (Art. 21(4)). Missing entirely, or an HR policy pasted in.
Training
Periodic programmes for the compliance function and relevant staff (Art. 21(5)), with role-based content. An annual slide deck with no attendance log fails.
Record-keeping
Five-year federal clock from the latest listed event (Art. 25). Eight years if VARA. Reconstruct a transaction. “Keep records for five years” with no event trigger is incomplete.
Independent audit
A function that tests adequacy and effectiveness (Art. 21(6)), not the same people who wrote the pack. “We may audit from time to time” is not a programme.
New products and technology
Pre-launch ML/TF/PF assessment (Art. 24). Templates often omit this section.
Group, branches, third-party reliance
Majority subsidiaries (Decree-Law Art. 19). Third-party CDD conditions (Art. 20). You remain responsible. A group logo page is not reliance language.
Corporate onboarding, beneficial-ownership evidence and the points where a KYB file breaks belong in a separate operating procedure. Sanctions screening as a daily process, wallet analytics, and the MLRO’s personal liability and outsourcing limits belong in their own documents. The policy points to those procedures and states the decision rights.
How must the risk assessment map to products and flows?
The enterprise-wide risk assessment is the document a reviewer opens first. Cabinet Resolution No. 134 of 2025 Article 5 requires you to identify, understand, manage and assess crime risks in line with the nature and size of the business, the National Risk Assessment, and a risk-based approach. You weigh customer, country, product, transaction and delivery-channel risk before you set control intensity. You document the method, keep the study, update it, and produce it on request. The assessment has to drive CDD intensity, EDD triggers, monitoring scenarios and the independent test plan. A template that states a risk-based approach without naming your products and rails leaves Article 5 unmet.
Products, customers, geographies and channels
Name the business in the assessment the way a banker will describe it. A AED-denominated invoice PSP and an OTC desk that pre-funds USDT do not share a residual-risk score. Write the customer types you accept and refuse, the countries you serve, and whether funds arrive by local bank transfer, correspondent rails, card, or virtual-asset wallet.
Article 5(2) then requires you to mitigate those risks with senior-management-approved policies, to monitor whether those policies work, and to apply enhanced due diligence where risk is high. The Resolution’s EDD examples include extra identity data, more frequent CDD refresh, source of funds and wealth, heavier ongoing monitoring, and senior-management approval to start or continue. Your procedure has to say which tools you use for which score. A template that prints the full EDD list as one block for “high risk” without tying it to a product will not survive a walkthrough.
Simplified due diligence exists. Article 5(3) allows it only after you have done the assessment, in coordination with the supervisor, where low risk is identified and there is no suspicion of a crime. Targeted financial sanctions still apply in full. A template that offers SDD as a default for “SMEs” is unsafe.
Proliferation financing and new technology
Article 5(4) requires proportionate measures where proliferation-financing risk is high: enhanced internal controls against breach or circumvention of targeted financial sanctions instructions; documented records of those measures; periodic review as risk changes. Decree-Law 10 put CPF into the federal statute. A 2018-era template that never mentions proliferation financing is stale.
Article 24 requires you to identify and assess ML, TF and PF risk from new products, new business practices, new delivery mechanisms, and new or developing technologies, before launch or use. A policy that lets product, sales or engineering ship a new rail and “update AML later” conflicts with Article 24. The independent test should sample whether any product launched since the last assessment has a dated risk memo.
For digital-asset businesses, the 2026 stack around this pack is wider than the policy document. Crypto compliance in 2026 sets that context. Wallet screening and KYT scenarios belong in a monitoring procedure.
What must CDD and EDD say, including the Article 14 stop?
Customer due diligence is the operational spine of the pack. Federal Decree-Law No. 10 of 2025 Article 19 requires CDD and continuous monitoring, scoped to risk and to the National Risk Assessment. Cabinet Resolution 134 Articles 6 to 15 set when you identify the customer and beneficial owner, which documents you take, and what you do if you cannot finish. CBUAE’s 6 November 2025 guidance for licensed financial institutions treats CDD as an ongoing process: onboarding, occasional transactions, suspicion, unreliable identification, periodic review and trigger events. The policy has to state those moments in your product language. A US template that copies a CIP checklist and a five-pillar BSA programme does not encode Article 14.
Standard CDD, EDD triggers and beneficial owners
Article 6 requires verification of the customer and the beneficial owner before or during establishment of a business relationship or account opening, or before an occasional transaction. Low-risk deferral is allowed only if verification follows as soon as possible, the deferral is needed so business is not disrupted, and you apply effective risk controls. You must still manage the risk if the customer can use the relationship before verification is complete. Article 21(1) requires the written programme to include those pre-verification risk procedures.
Article 7 states when CDD applies: start of a relationship; suspicion of a crime; doubts about previously obtained data. Financial institutions also apply CDD to occasional transactions of AED 55,000 or more, including linked transactions, and to occasional wire transfers of AED 3,500 or more. VASPs apply CDD to occasional transactions of AED 3,500 or more, including linked transactions. Put those thresholds in the procedure with the product codes they attach to. A template that uses USD 10,000 or a BSA wire figure cites the wrong statute.
Article 9 lists identity content for natural persons and for legal persons and arrangements. You must understand purpose and intended nature of the relationship, and the customer’s business and ownership structure.
Article 10 is the beneficial-owner cascade for legal persons: the natural person who owns 25% or more, alone or with another; if that is in doubt or if no one controls through ownership, the natural person who exercises legal or actual control; if none, the senior manager. Legal arrangements have their own list. Article 11 relieves you from identifying shareholders of a listed company that is subject to sufficient disclosure, or a qualifying subsidiary. The policy should state that cascade. File-level evidence of how a given corporate onboarding breaks is a KYB procedure.
Article 16 splits foreign PEPs (detect, senior-management approval, source of funds and wealth, enhanced monitoring) from domestic PEPs and persons with a prominent function in an international organisation. Article 23 requires EDD, and any supervisor or National Committee countermeasures, for persons from listed high-risk countries. Write the lists you use and the refresh cycle.
Article 14: no relationship without CDD
Article 14(1) prohibits establishing or continuing a business relationship, and prohibits executing a transaction, where you cannot apply CDD. You must consider a suspicious transaction report to the Unit. CBUAE’s November 2025 guidance says the same in supervisory language: do not establish or maintain a relationship with a customer who cannot or will not provide required CDD, including at periodic or event-driven review.
Article 14(2) is the narrow exception. If you suspect a crime and have reasonable grounds to believe that applying CDD would alert the customer, you may refrain from those measures, and you must submit an STR stating why you withheld them. Incomplete files stay blocked under Article 14(1). The policy has to give the compliance officer a documented path for both limbs: stop the relationship, or file and hold CDD because of a tipping-off risk.
Article 15 bans dealing with shell banks and bans anonymous or fictitious-name accounts. Decree-Law Article 19(1)(c) repeats the anonymous-account ban and adds numbered names. A template that still allows “numbered accounts for privacy clients” is instructing a breach.
What sanctions and STR language must the policy carry?
The policy needs a sanctions section that names the UAE local terrorist lists and the United Nations lists, states that a true match freezes assets, names who reviews a potential match, and states how you record the freeze. Screening software, alert handling and list-management operations live in a sanctions procedure. Decree-Law Article 19(1)(e) requires you to implement forthwith the instructions of the Executive Office or other competent authorities on targeted financial sanctions. Cabinet 74 of 2020 (as amended) remains the list-implementation architecture those instructions sit on.
Suspicious transaction reporting is a legal duty with a clock. Decree-Law Article 18 and Cabinet 134 Article 18 require you, if you suspect or have reasonable grounds to suspect, to notify the Unit without delay, with all available data, through the Unit’s electronic system, and to answer follow-up requests. Banking secrecy is no defence, subject to the legal-professional exception in Article 18(2) of the Resolution. Cabinet Article 17 requires you to build and update indicators of suspicion. The policy should name goAML as the UAE FIU channel, name who may file, and name the backup if that person is absent.
Cabinet Article 19 prohibits directors, officers and employees from disclosing to the customer or any other person that an STR has been or will be submitted, or that an investigation is underway, without prejudice to group information-sharing under Article 32. A template that tells relationship managers to “discuss the SAR with the client to clarify” is a tipping-off script. Attempts by lawyers, notaries, independent legal professionals or independent statutory auditors to dissuade a customer from an unlawful act do not count as disclosure.
For VASPs, VARA Part III adds Travel Rule compliance through federal law, including unhosted wallets and counterparties in places that have not implemented the Rule. State in the policy that Travel Rule controls exist and where the procedure sits. Wallet screening does not discharge the Travel Rule.
How should governance, records and independent testing be written?
Cabinet Resolution 134 Article 21 lists six minimum contents of internal anti-crime policies: CDD, including risk management before verification is complete; STR procedures; compliance management with a compliance officer at management level; employee fitness screening; periodic training; and an independent audit function that tests adequacy and effectiveness. Article 22 then assigns the compliance officer concrete duties: monitor, assess suspicion, decide whether to notify the FIU, review internal systems, train staff, and cooperate with the supervisor and the Unit. FATF Recommendation 18 uses a similar stack as an international benchmark. UAE law is the binding source. The policy has to name who holds which duty inside your entity, with backups.
Compliance officer duties, without a job-description article
Article 22 requires a management-level compliance officer, under the entity’s responsibility, with independence in decision-making and appropriate competence and experience. The policy names the appointed person, the deputy, reporting lines, and maps each Article 22 duty to a named owner: monitoring, STR decision, systems review, reports to senior management, training, and cooperation with the supervisor and the Unit.
VARA splits a Compliance Officer from an MLRO for licensed VASPs. The CO needs five years in a compliance function, UAE residence or a UAE passport, full-time employment, and a direct Board report. The MLRO needs two years handling AML/CFT matters. Both remain fit and proper, reviewed once a year. Other supervisors use MLRO language in their manuals. Personal liability, outsourcing of the role, and whether one human can hold both seats are a separate staffing analysis.
CBUAE 16.3 also wants the policy to define the manager in charge, any compliance committee, and employee duties, and to provide regular reporting to the board on ML/FT risk. 16.3.6 requires approval by the manager in charge, the compliance officer, and the board or owner.
Record clocks and independent test
Cabinet Article 25(1) requires you to keep records of domestic and international financial and cash transactions and commercial dealings for at least five years from completion of the transaction or termination of the business relationship, and to produce them on request. Article 25(2) extends a five-year clock to CDD files, monitoring, correspondence, STRs and analysis, measured from the most recent of the events listed in that article (end of relationship, account closure, occasional transaction, inspection, investigation, or final judgment). CBUAE’s November 2025 guidance adds quality: storage that supports internal work and lawful access, plus documentation of onboarding rationale, risk rating, and monitoring.
VARA-licensed VASPs keep books and AML records for no less than eight years (Rules I.F.2 and III.I.2), and without a fixed end date where records may relate to UAE national security. If you hold that licence, the policy states the eight-year clock. If you do not, leave the extra years out.
Article 21(6) requires an independent audit function to test effectiveness and adequacy of the internal anti-crime policies, controls and procedures. Independent means the testers did not design or run the controls they review, and they can escalate to senior management or the board. The test plan should follow the risk assessment: sample high-risk products, Art. 14 stops, STR quality, sanctions freezes, training attendance, and whether Article 24 memos exist for recent launches.
Article 21(4) and (5) require fitness screening of employees and periodic anti-crime programmes for the compliance function and other relevant staff. CBUAE 16.3 requires the current policy to be held at all licensed premises, accessible to staff, and recirculated after each review.
How do banks, PSPs and supervisors read the pack?
Ksenia Babochkina, Commercial Director at Medici Expert, put the banking point without decoration: “Crypto companies don't get rejected by banks for being crypto companies. They get rejected for not being able to explain themselves clearly.” The AML pack is that explanation. Each reviewer then tests it against a different model.
A bank asks whether your customer types, corridors and expected flows match the CDD and monitoring you described, and whether Art. 14 and sanctions freezes would stop a file the bank does not want. A PSP asks whether STR indicators and goAML registration exist, because your flow becomes their flow. VARA asks whether Board-approved policies match the VA activity, whether the CO and MLRO meet the rulebook tests, and whether Travel Rule and eight-year records are real. DFSA and FSRA ask whether federal obligations plus their module are implemented in the DIFC or ADGM entity you named. CBUAE asks whether the EWRA, CDD lifecycle, record quality and 16.3 governance would survive a thematic review.
Those readers sample files and ask staff to operate the procedure without the consultant in the room. If the PDF describes a bank and you are a VASP, or a UK estate agency and you are a DIFC broker, the sample fails.
Nataly Medici has said a licence rejected for sloppy documentation is harder to recover from than one that was never filed. The same cost attaches to a pack copied to unlock a bank checklist. Build the pack from the model you will still have in twelve months.
When is a template useful, and when does it waste the committee’s time?
A template is a table of contents. Use one to check that Cabinet 134 Article 21 headings exist, that employee screening and independent test are present, and that version control and approval blocks are filled. Then replace every generic paragraph with your products, thresholds, lists, officers, systems and clocks.
A template wastes the committee’s time when it still cites Decree-Law 20 of 2018 or Cabinet 10 of 2019 after 14 December 2025, imports FinCEN or BSA five-pillar language, skips Art. 14, tells staff to call the client about an STR, or leaves the MLRO unnamed. VASP packs that omit Travel Rule or the eight-year clock fail the same test.
US search volume for “aml policy” is larger than UAE volume. The English web is full of FINRA small-firm language and downloadable Word files. Those files can help a US broker-dealer start a BSA programme. A UAE entity writes to Decree-Law 10, Cabinet 134, the supervisor’s manual, and the way its money moves.
FAQ
Who in the UAE is required to have an AML/CFT policy?
Financial institutions, DNFBPs and VASPs must keep senior-management-approved internal policies under Decree-Law 10 Article 19 and Cabinet 134 Article 21. The duty follows the activity and the supervisor, not the free-zone badge.
Are the “five pillars of an AML policy” the UAE test?
The five-pillar formula is a US BSA programme construct (internal controls, independent testing, designated officer, training, CDD). People Also Ask surfaces it on UAE queries because US templates dominate the English web. Cabinet 134 Article 21 lists six minimum contents. Write to Article 21.
What happens if we cannot complete CDD?
Cabinet 134 Article 14 prohibits establishing or continuing the relationship and prohibits executing the transaction. You must consider an STR. If applying CDD would alert a suspected customer, you may withhold those measures and you must file an STR that states why. CBUAE’s November 2025 LFI guidance matches that stop.
How long must we keep AML records in the UAE?
Cabinet 134 Article 25 requires at least five years, with the CDD/STR clock running from the most recent of the listed events (end of relationship, account closure, occasional transaction, inspection, investigation, or final judgment). VARA-licensed VASPs must keep specified books and AML records for at least eight years. State the clock that applies to your licence.
Can we file a licensing or bank application on a downloaded AML PDF?
You can attach anything. The reviewer will sample whether the EWRA names your rails, whether Art. 14 and goAML are operable, and whether the named officer exists. A generic PDF is a table of contents.
