Chat with us, powered by LiveChat

AML Compliance in the UAE: What the Regulator Expects

September 10, 2026

A UAE supervisor asks whether Federal Decree by Law No. (10) of 2025 and Cabinet Resolution No. (134) of 2025 can be shown to run in your products, through a named officer who can decide a suspicious-transaction file without a sales veto. The Decree-Law has been in force since 14 October 2025.

Nataly Medici
Nataly Medici
Managing Partner and CEO

Cabinet 134 has been in force since 14 December 2025. Together they set the federal floor for financial institutions, designated non-financial businesses and professions, and virtual asset service providers. Your licence then adds a second layer from CBUAE, VARA, DFSA, FSRA or the Ministry of Economy and Tourism.

AML/CFT policy work is the pack and the operating controls that make that floor inspectable. UAE company formation and licensing is the entity and the permission. The regulator samples both.

Who must run an AML programme in the UAE?

Cabinet 134 draws three commercial perimeters. Article 2 lists financial activities carried out as a business for a customer. Article 3 lists designated non-financial businesses and professions. Article 4 lists virtual-asset activities. Decree-Law 10 Article 20 forbids those activities without a licence, registration or enrolment from the competent or supervisory authority. Sit in any of the three lists and you take Article 19 preventive measures, Cabinet 134 operating rules, and a management-level compliance officer under Articles 21(3) and 22. Confirm the live activity list on the CBUAE Rulebook. Supervisors may add activities by resolution with the National Committee. Write first to the UAE instruments, then to the supervisor who will examine you.

Financial institutions under Cabinet Article 2

Article 2 captures, as a commercial activity for a customer, the heads from deposit-taking, lending and trade finance through payment instruments, portfolio management, specified investment-linked insurance and currency exchange, plus residual activities the supervisor adds. CBUAE is the usual supervisor for banks, exchange houses, finance companies and many payment firms. DIFC and ADGM financial institutions still sit on the federal floor and on DFSA or FSRA modules.

This perimeter fits a firm whose revenue comes from holding, moving or intermediating other people’s money under a financial licence. It fails when founders treat a CBUAE or free-zone permission as a substitute for Cabinet 134: the licence is the entry ticket, not the programme.

DNFBPs under Cabinet Article 3

Article 3 names commercial gaming operators at AED 11,000 in a single financial transaction or linked transactions; real-estate brokers and agents on purchase, sale or settlement for customers; dealers in precious metals and stones on cash or linked cash at AED 55,000; independent legal professionals and accountants on the listed financial acts; and company and trust service providers on the listed agency, director, address, trustee and nominee-shareholder acts. A residual limb lets the supervisor add professions.

This perimeter fits a professional firm that handles client money, formation or property deals in the listed ways. It fails when a corporate-services shop assumes that “we only file with the registrar” sits outside AML: acting as director, providing a registered office, or arranging a nominee shareholder is inside Article 3(5). Ministry of Economy and Tourism supervision is common onshore; free-zone DNFBPs still read the federal text.

VASPs under Cabinet Article 4

Article 4 lists exchange between virtual assets and fiat, exchange between virtual assets, transfer, safekeeping or administration of virtual assets or of instruments that confer control, financial services related to an issuer’s offer or sale, and a residual. Article 36(1) requires a licence, registration or listing from the competent supervisor for anyone conducting those activities, offering related products or services, or performing the transactions from within the State. Article 36(4) extends the transfer-information duties to financial institutions that send or receive virtual-asset transfers for a customer.

This perimeter fits an exchange, broker, custodian, transfer desk or issuance-adjacent service operating from the UAE. It fails when a team books the entity in a free zone, serves UAE users from a foreign VASP, and treats federal AML as optional. VARA, ADGM FSRA and DIFC DFSA add the sector overlay; they do not repeal Article 4. Digital asset legal support is the structuring conversation that should happen before the AML officer is asked to bless a product the licence does not cover.

What Decree-Law 10 of 2025 expects of the obligated person

The statute replaced Federal Decree-Law No. 20 of 2018. Official Gazette No. 808 published it on 30 September 2025. It entered into force on 14 October 2025. Dual source the in-force date, proliferation financing, digital systems and virtual assets as methods, and the lower knowledge threshold to the CBUAE Rulebook host and to White & Case’s 6 November 2025 alert: knowledge that funds are illicit may be inferred from factual and objective circumstances.

Article 19 is the preventive list the examiner will ask you to map: crime-risk assessment, customer due diligence, no anonymous or fictitious accounts, senior-management-approved policies covering majority-owned branches and subsidiaries, targeted financial sanctions instructions, and records. Article 18 requires a report to the Financial Intelligence Unit without delay where you suspect, or have reasonable grounds to suspect, that a transaction or funds are proceeds or are intended for the crime, regardless of amount.

Enforcement sits in two regimes. Article 17 is administrative: a warning; a fine of AED 10,000 to AED 5,000,000 for each violation; restriction or suspension of persons proven responsible; suspension of activity; revocation of the licence. Article 27 is criminal liability of the legal person when representatives, directors or agents commit money laundering, terrorist financing or proliferation financing on its behalf: AED 5 million to AED 100 million, or the value of the criminal property, whichever is greater. A separate band of AED 200,000 to AED 10 million covers listed lesser offences, including operating without the required licence. Managers can face imprisonment and/or a fine where they knew of the offence or the offence followed a breach of the duties of the position. Do not collapse Article 17 into Article 27. The Unit may suspend suspected transactions for up to ten working days and freeze funds for thirty days, extendable.

What Cabinet Resolution 134 of 2025 tells you to operate

Cabinet 134 is the executive regulation of Decree-Law 10. VARA’s 4 March 2026 circular to Dubai VASPs states that Official Gazette Issue No. 811 dated 15 November 2025 published it, and that it entered into force thirty days later, on 14 December 2025. The MOJ English text and the CBUAE Rulebook host the same instrument and record the repeal of Cabinet Resolution No. 10 of 2019.

The Resolution sets customer identification, the due-diligence stop, politically exposed persons, suspicious-transaction decisions, the internal programme, the compliance officer, high-risk countries, new technology, and record clocks. A supervisor who asks to see Cabinet 134 in your files wants those facts tied to your products. Confirm the live text before you freeze a board pack.

Enterprise-wide risk, including proliferation financing

Article 5 requires financial institutions, DNFBPs and VASPs to identify, assess, understand and mitigate crime risks, including proliferation financing, and to keep that assessment current. Simplified due diligence, where allowed, still requires full targeted financial sanctions controls. The examiner wants named products, customer types, geographies, delivery channels, residual risk after controls, an owner and a date. A sentence that “we adopt a risk-based approach” with no product map does not satisfy Article 5. Ksenia Babochkina’s line on the compliance service page applies: regulators move faster than founders expect, and what looked low-risk eighteen months ago can be a licensing requirement today.

CBUAE has published dedicated LFI guidance on proliferation-finance risks on the same AML/CFT hub.

The six programme items in Article 21

Article 21 requires senior-management-approved internal policies, controls and procedures, proportionate to identified crime risks and to the nature and size of the business, reviewed on an ongoing basis. The six contents are customer due diligence measures, including risk management for relationships opened before verification is complete; suspicious-transaction reporting procedures; compliance-management arrangements including a compliance officer at management level; employee fitness-and-propriety screening; periodic anti-crime training; and an independent audit function that tests adequacy and effectiveness.

The six items must exist, carry senior-management approval, and admit an independent test. A six-heading download with no product facts does not meet Article 21.

High-risk countries and new technology

Article 23 requires enhanced due diligence proportionate to risk on relationships and transactions with persons from countries the National Committee identifies as high-risk, or from countries with AML/CFT/CPF deficiencies, plus any countermeasures the supervisor or the Committee require. Article 24 requires an assessment of crime risks from new products, practices and technologies before you launch them. A product committee that ships a new wallet flow or a new corridor without that assessment is already off the Resolution, even if the marketing site looks finished.

Which CDD facts the examiner samples first

Cabinet Articles 6 to 15 set customer due diligence. Article 9 requires identification of the customer as a natural person, legal person or legal arrangement, verified from original documents or data from a reliable independent source. Article 10 requires beneficial-owner identification for legal persons and arrangements, with a 25 percent ownership interest as the first cascade, then control, then a senior-manager fallback. Article 14 is the stop: no business relationship, no continuation, no transaction, if due diligence cannot be applied; consider a report to the Unit; the tipping-off exception for that stop sits in Article 14(2).

As of the MOJ English text in August 2026: occasional-transaction due diligence for financial institutions at AED 55,000; for financial-institution wires and for VASP occasional transactions at AED 3,500, including linked transactions; dealers in precious metals and stones at AED 55,000 cash or linked cash. Confirm Article 7 live for your activity. Do not import a US or EU dollar threshold and hope it maps.

CBUAE’s Guidance for Licensed Financial Institutions on Customer Due Diligence / Know Your Customer and Record-Keeping, dated 6 November 2025, does not create a new statute. It states how CBUAE expects licensed financial institutions to show why the customer was onboarded, how the customer was risk-rated, and how activity was monitored. A bank that onboards you will run a similar test on your file. Crypto compliance in 2026 is the operating map for virtual-asset businesses inside that overlay.

Politically exposed persons sit in Article 16. Enhanced measures, source of funds and source of wealth, and senior-management approval appear in the EDD toolkit under Article 5(2). The examiner wants to see who you classified, why, and who signed the high-risk acceptance.

What the named officer must be able to do on a surprise afternoon

Cabinet Article 22 requires a compliance officer at management level, independent in decision-making, with appropriate competence and experience. The officer monitors crime-related transactions, decides whether to notify the Unit or retain the file with reasons, reviews internal systems, trains staff, reports to senior management, and opens records to the supervisor and the Unit. Federal texts say “compliance officer.” CBUAE, DFSA and FSRA also say “money laundering reporting officer.” Treat them as the same federal function unless the licence splits the seats. A surprise examination tests whether that person can walk the last retain-or-file decision without calling sales first. That is the federal seat.

The federal seat under Article 22

Independence is a decision right. The officer files or retains. Sales cannot override that decision. Credentials for the Unit’s electronic system sit with that person. A vendor who “helps with AML” while the founder holds the password fails Article 22(2) and Article 22(5) on the first request for records. Periodic reports go to senior management; the supervisor can demand a copy. Training is documented, role-based, and current. Nataly Medici’s line on sloppy filings applies: a licence rejected for sloppy documentation is harder to recover from than one that was never filed. An officer who cannot walk the last retain-or-file decision is sloppy documentation with a name on the org chart.

What the licence adds on top of Article 22

CBUAE Licensed Persons (exchange-style Chapter 16) expect a full-time UAE-resident compliance officer, board or owner approval of the programme, at least annual review, quarterly AML reporting in the Licensed Person rule, and a ban on outsourcing the role or the entire function (specific tasks only, with No Objection). DFSA and FSRA expect a UAE-resident MLRO of seniority and independence, with stated exceptions for some auditor and representative-office cases, and their own report clocks to the governing body. VARA splits a compliance officer (five years in a compliance function, UAE resident or UAE passport, full-time, reports to the Board) from an MLRO (two years handling AML/CFT); one person may hold both non-client-facing seats if VARA accepts Fit and Proper. VARA also requires at least eight years of books and AML records. Confirm the live rulebook page for your permission.

How CBUAE, VARA, DFSA and FSRA add a second layer

The federal instruments apply in every emirate. The second layer is who examines you and which extra clocks they print. Read the federal text first, then the sector rulebook, then any circular issued after Cabinet 134. A conflict is resolved in favour of the stricter operating duty that still sits on a live instrument. CBUAE, VARA, DFSA and FSRA each sample that duty in a different file. Building real rules for crypto is the argument that the operating file has to match the rulebook. Confirm live pages before you rely on a 2019 PDF. The three gates below are those perimeters.

CBUAE licensed financial institutions

CBUAE hosts the Decree-Law, Cabinet 134, and LFI guidance covering suspicious-transaction reporting, targeted financial sanctions, transaction monitoring, CDD and record-keeping, correspondent banking, proliferation finance, and related topics. Examiners sample whether your risk assessment names those topics where they apply. The VA Travel Rule page remains in force for unhosted-wallet and privacy-token operating rules even where the HTML still cites old Cabinet numbering; follow Cabinet 134 article numbers in your manuals and confirm the live CBUAE node.

This overlay fits a bank, exchange house, finance company or payment firm under CBUAE. It fails when a group runs UAE accounts from a regional office that cannot produce local STR ownership, which is a recurring finding in the Joint Guidance.

VARA-licensed VASPs in Dubai outside DIFC

VARA’s Compliance and Risk Management Rulebook sits on the federal floor. The 4 March 2026 circular tells licensed VASPs to implement Cabinet 134: risk-based controls including proliferation financing, CDD at the AED 3,500 occasional threshold, enhanced due diligence for higher risk, originator and beneficiary information on virtual-asset transfers, targeted financial sanctions, suspicious-transaction reporting without delay through the Unit’s electronic system, and records that meet both federal and VARA clocks. VARA may require a full-time employee in a specified officer seat even where the Company Rulebook contemplates MLRO outsourcing.

This overlay fits a Dubai VASP whose VA activities match both Schedule 1 of the VARA regulations and Cabinet Article 4. It fails when the website promotes an activity the licence does not name.

DFSA in the DIFC and FSRA in ADGM

DIFC Relevant Persons remain bound by federal AML legislation and the DFSA AML module. ADGM Relevant Persons remain bound by federal legislation and the FSRA AML Rulebook. Both expect a UAE-resident MLRO of seniority and independence, with deputy and outsourcing tests that differ from CBUAE’s Licensed Person ban. FSRA prints a semi-annual MLRO report to the governing body. Confirm the live module.

This overlay fits a firm that chose a financial free zone because counterparties or the product need that perimeter. It fails when the federal officer is appointed and the module’s residency, deputy or report clock is left blank.

How the FIU expects reports to arrive

Decree-Law Article 18 is the duty: notify the Unit without delay, regardless of value, on suspicion or reasonable grounds. Cabinet Articles 17 to 19 add indicators, the notify-or-retain decision, and the prohibition on tipping-off. The Unit receives those reports through goAML, the electronic system named in CBUAE suspicious-transaction guidance (Annex 4 on the AML/CFT Rulebook hub). The officer learns registration and report types from the live Unit materials and from the supervisor’s STR guidance.

The examiner wants evidence that the officer can decide, that the decision is recorded, that the report went through the Unit’s system, and that staff did not tell the customer a report was filed. VARA’s circular reminds VASPs that the Unit may order a suspend of up to ten working days. After you file, you handle the relationship the way the Unit and the supervisor instruct.

What targeted financial sanctions and transfer data add to the same file

Decree-Law Article 19 includes targeted financial sanctions instructions. Cabinet 134 keeps full TFS even where simplified due diligence is otherwise available, and Article 36(3) tells VASPs to meet financial-institution TFS duties. Cabinet Decision No. 74 of 2020, as amended, supplies freeze-without-delay and notice clocks: screen the universe, freeze on a confirmed local or UN match without prior notice, notify through the prescribed channels. CBUAE’s live TFS page, last updated 4 February 2026, and EOCN guidance are the operating texts for licensed financial institutions. Older CBUAE PDFs that print a two-business-day notice clock conflict with the five-business-day language on the live page and in Cabinet 74 Article 15. Confirm the live page for your licence type.

Wire and virtual-asset transfer transparency sits in Cabinet 134 Articles 28 to 30 and Article 36. The originating VASP must obtain, retain and transmit, immediately and securely, at least the originator’s name, account or wallet, and residential or business address, and the beneficiary’s name and account or wallet. Financial institutions that send or receive those transfers for a customer inherit the same duties. UAE operating law in 2026 is Cabinet 134 plus, for CBUAE persons, the Virtual Assets Travel Rule node. On-chain screening does not discharge name-list TFS or that data set.

How records and independent testing prove the programme runs

Cabinet Article 25 requires records that reconstruct CDD, transactions and the officer’s decisions, kept for at least five years from the latest listed event. Decree-Law Article 19(f) is the statutory hook. VARA requires books and AML records for no less than eight years, indefinite if national security so requires. Keep both clocks if you are a Dubai VASP. CBUAE CDD guidance wants the file to show why you onboarded, how you rated, and how you monitored. Independent testing under Article 21(6) cannot sit with the first line that wrote the procedure last week.

Examiners and correspondent banks ask for the dated risk assessment, board or owner approval, officer appointment, a sample of CDD files including a stopped case under Article 14, a retain-or-file log, training attendance, sanctions dispositions, and the last independent-test report with management responses. Missing artefacts are findings. Recycled artefacts from another group entity, with the UAE products edited in the header, are also findings.

FATF’s 23 February 2024 statement that removed the UAE from increased monitoring named private-sector effectiveness, including STR filing in DNFBP sectors, TFS implementation, and sanctions for non-compliance. The FATF assessments calendar lists a possible June 2026 onsite and a possible February 2027 plenary. Those dates are indicative. They explain why supervisors sample operating evidence in 2026.

When a UAE AML programme fits the business and when it fails

The programme fits when the activity list in Cabinet Articles 2, 3 or 4 matches the licence, the website and the payment rails; when Article 5 names those products; when Article 22 is a person who can file; when TFS and transfer-data duties are in the same operating file as CDD; and when records survive a sample without a week of reconstruction. It fits a pre-licence applicant who builds that file before the application, because the supervisor and the bank will both read it.

It fails when the entity is formed first and AML is a PDF bought to unlock a bank appointment. It fails when the officer sits in another time zone with no alert access. It fails when virtual-asset transfers run with empty originator fields. Commercial advisory, implementation and officer support sit outside any government tariff. They are not a Medici quote. Confirm live instruments on the CBUAE Rulebook, VARA rulebooks, DFSA and FSRA modules, and the legislation portal before you lock a version for the board.

FAQ

Is AML compliance mandatory in the UAE?

Yes, if you are a financial institution, a designated non-financial business or profession, or a virtual asset service provider under Cabinet Resolution No. 134 of 2025 Articles 2 to 4. Federal Decree by Law No. 10 of 2025 Article 20 forbids the activity without the required licence, registration or enrolment. Article 19 then requires the preventive programme. Confirm your activity against the live Cabinet text rather than against the marketing name of the company.

What are the AML rules in the UAE in 2026?

The statute is Federal Decree by Law No. 10 of 2025, in force 14 October 2025. The executive regulation is Cabinet Resolution No. 134 of 2025, in force 14 December 2025. Supervisors add rulebooks: CBUAE for many licensed financial institutions, VARA for Dubai VASPs outside DIFC, DFSA in the DIFC, FSRA in ADGM. FATF Recommendations are the international overlay, not a substitute for those texts.

What are the five pillars of AML compliance?

The “five pillars” phrase in search results is a United States Bank Secrecy Act construct: internal controls, a designated officer, training, independent testing, and customer due diligence. Cabinet 134 Article 21 lists six UAE programme items, including employee fitness screening as its own limb. Build the UAE programme to Article 21 and Article 22, not to a US pamphlet.

Is the UAE high risk for AML?

The FATF removed the UAE from its increased-monitoring list on 23 February 2024 after an action plan that included DNFBP supervision, STR filing, beneficial-ownership measures, FIU capacity, money-laundering prosecutions and targeted financial sanctions. The last published mutual evaluation remains the 2020 report. Firm-level risk still depends on your products, customers and corridors.

Who is the MLRO in UAE law?

Cabinet 134 Article 22 requires a management-level compliance officer with independence and listed duties, including the decision to notify the Financial Intelligence Unit. CBUAE, DFSA and FSRA often title the same federal function as MLRO. VARA can split a compliance officer and an MLRO. Residency, experience and outsourcing limits come from the licence, not from a generic job ad.

How do I report a suspicious transaction in the UAE?

Decree-Law Article 18 requires a report to the Financial Intelligence Unit without delay, regardless of value, where you suspect or have reasonable grounds to suspect. The Unit receives reports through goAML. The named officer owns the decision and the credentials. Do not inform the customer that a report was filed. Use the live Unit and supervisor materials for registration and report types.

What changed under Federal Decree-Law 10 of 2025?

The Decree-Law repealed Decree-Law 20/2018, added proliferation financing, treated digital systems and virtual assets as methods, lowered the knowledge test to include inference from objective circumstances, raised legal-person fines to AED 5 million to AED 100 million (or criminal-property value), added manager-level criminal exposure in stated cases, and widened FIU freeze and suspend powers. Confirm the live CBUAE Rulebook text and independent commentary such as White & Case’s 6 November 2025 alert for the in-force date.

Do free-zone companies need UAE AML compliance?

Yes, if they fall inside Cabinet Articles 2, 3 or 4. A free-zone formation does not remove the federal floor. The free-zone authority and, where applicable, VARA, DFSA or FSRA add the second layer. Article 36 still requires a VASP permission for virtual-asset activities conducted from the State.

Sources

Connect with our experts

Get full clarity on licensing, compliance and structuring before you spend time and budget on the wrong move.

Book a Free Call

Ready to build a structure that actually works?

Whether you are launching a fintech company, applying for a license, entering the UAE, issuing a token or preparing for regulatory review — we can help you choose the right path before costly mistakes happen.

Book a Free Call