Businesses sometimes treat anti-money-laundering compliance as a report filed only after a suspicious payment appears. The current UAE framework is broader. Regulated entities need a standing, risk-based system for governance, customer due diligence, beneficial ownership, ongoing monitoring, reporting, records, training, and review before a specific red flag arises.
The legal framework also changed recently. Federal Decree-Law No. 10 of 2025 replaced the prior 2018 core law, and Cabinet Resolution No. 134 of 2025 provides the current executive regulations. A policy copied from an old template may therefore cite repealed rules, omit proliferation-financing obligations, or fail to address virtual assets and the current operational requirements.
What Are the Current Anti-Money Laundering Regulations in the UAE?
The current anti-money laundering regulations UAE businesses must assess are led by Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025. They apply to financial institutions, designated non-financial businesses and professions, and virtual asset service providers within their scope.
A compliant program is risk-based and documented: it identifies enterprise and customer risk, verifies customers and beneficial owners, applies enhanced measures where required, monitors relationships and transactions, reports suspicious activity through the competent channel without tipping off, retains records, trains staff, and tests controls.
Compliance is not activated only after a suspicious transaction appears. Responsibility and penalties depend on the specific provision and facts; serious criminal offenses under the current law can carry imprisonment and very substantial fines, including fines that may reach AED 100 million under applicable provisions.
Each entity should map its regulator, activities, customers, products, geography, and current controls.
Update the legal register, identify whether the business is a regulated reporting entity, and convert the statutory duties into assigned, tested, and documented controls that operate throughout the customer relationship.
The Current UAE AML Framework
Federal Decree-Law No. 10 of 2025 is the current core federal statute on anti-money laundering, terrorism financing, and proliferation financing. Cabinet Resolution No. 134 of 2025 supplies the implementing detail. The framework should be read together with the rules, guidance, and supervisory expectations issued by the regulator responsible for the entity and sector.
A business should not describe a policy as current merely because it includes the words KYC or suspicious transaction report. The legal register should identify the operative law, executive regulation, sector guidance, sanctions obligations, internal owners, review dates, and evidence that the controls are actually performed. DIFC or ADGM entities may also have free-zone regulatory requirements that need separate mapping.
Is Your UAE AML Program Up to Date?
Leaders Advocates can help businesses review their AML framework, risk assessments, customer due diligence, beneficial ownership procedures, monitoring, and reporting controls.
Who Must Build a Standing Compliance Program
The framework covers financial institutions, designated non-financial businesses and professions, and virtual asset service providers within the defined scope. Depending on the activity, this can include banks, exchange houses, real estate brokers, dealers in precious metals and stones, and other designated sectors. Licensing and supervisory lines should be confirmed rather than inferred from a broad industry label.
The first implementation step is a scope memorandum listing every legal entity, branch, license, product, channel, and regulator. A group policy may provide common standards, but each entity still needs controls fitted to its actual risks and reporting duties. Outsourcing onboarding or screening does not automatically outsource legal accountability or management oversight.
Enterprise and Customer Risk Assessments Drive the Controls
A risk-based program begins by assessing customers, products, services, delivery channels, geography, transaction patterns, ownership structures, and emerging threats. The result should explain why a risk level was assigned and which controls respond to it. A color on a spreadsheet without supporting methodology is not a complete assessment.
Customer risk should be reviewed when material information changes, not frozen at onboarding. Higher-risk relationships may require enhanced due diligence, senior approval, source-of-funds or source-of-wealth analysis, closer monitoring, or other measures required by the applicable framework. Low risk does not mean no identification, no records, or no review.
Customer Due Diligence and Beneficial Ownership
Customer due diligence should identify and verify the customer, understand the purpose and intended nature of the relationship, identify the beneficial owner, and assess whether the structure and activity make sense. Legal-entity files need more than a trade license: ownership, control, authorized persons, business purpose, and changes should be understood and recorded.
Complex structures are not automatically unlawful, but unexplained layers, nominees, inconsistent activity, or unclear control require attention. Staff should know when to stop onboarding, seek more information, escalate for enhanced review, or decline the relationship under approved procedures. Decisions and exceptions should be documented so they can be explained to management and a supervisor later.
- Verify identity using reliable and current information appropriate to the customer type.
- Identify beneficial ownership and control rather than relying only on the immediate shareholder.
- Record the purpose, expected activity, products, geography, and payment profile.
- Apply enhanced measures and senior approval where the risk requires them.
- Refresh the file and reassess risk when material facts or behavior change.
Ongoing Monitoring, Red Flags, and Escalation
Monitoring should compare actual behavior with the expected profile and identify unusual patterns for review. A red flag is a prompt for analysis, not automatic proof of money laundering. The review should gather the relevant facts, document the rationale, and escalate through the approved internal channel without alerting the customer improperly.
Manual and automated controls should be calibrated to the business. Alerts that are closed with identical generic wording provide weak evidence of review. The compliance function should test why alerts arise, whether thresholds remain appropriate, how long investigations take, and whether related customers or transactions are being connected across systems.
Suspicious Reporting and the Prohibition on Tipping Off
Where suspicion meets the applicable reporting threshold, the entity should use the competent reporting channel, including the UAE Financial Intelligence Unit’s goAML system where applicable. Staff should not wait for proof of the underlying crime before escalating a genuine suspicion, and they should not promise a customer that a payment will be released while secretly describing an internal report.
Access to reporting information should be restricted. Front-line staff need scripts for handling customer questions without revealing that a report has been or may be filed. Internal records should show the information reviewed, the decision-maker, reporting date, follow-up request, and any continuing monitoring or account action required by law or the competent authority.
Concerned About Suspicious Activity or Tipping-Off Risk?
Get legal guidance on internal escalation, suspicious activity reporting, confidentiality, customer communications, and the appropriate response under the UAE AML framework.
Records, Training, Governance, and Independent Testing
The business must retain required customer, transaction, review, alert, report, training, and governance records for the applicable period. Records should be retrievable, protected, and understandable without relying on one employee’s memory. A policy without evidence of execution will not show that due diligence, monitoring, escalation, or management oversight occurred.
Training should be role-specific and tested. A real estate broker, payments analyst, relationship manager, director, and compliance officer face different red flags and decisions. Senior management should receive meaningful risk and control reporting, while periodic independent review should test files, systems, escalation quality, remediation, and whether the written framework matches actual business practice.
Faris Raian’s View: Compliance Must Exist Before the Red Flag
Faris Raian, Founder and Managing Partner at Leaders Advocates, said that businesses sometimes treat AML compliance as a reactive obligation to address only after a transaction looks wrong. He explained that the current law expects a standing, documented process for customer verification, monitoring, and staff training before an obvious red flag appears.
That observation matters operationally. A business cannot recreate months of missing due diligence, monitoring decisions, or management oversight after a regulator asks for the file. The strongest response is a program with assigned responsibility, current risk assessments, consistent records, prompt remediation, and clear evidence that exceptions were identified and handled rather than normalized.
Consequences and a Practical 90-Day Remediation Plan
Failures can lead to supervisory action, license restrictions, administrative measures, and criminal exposure depending on the conduct and provision. The current law includes substantial penalties, with fines reaching AED 100 million under serious applicable provisions alongside imprisonment. The exact consequence must be stated carefully and not assigned to every procedural deficiency automatically.
A remediation plan should first stop any immediate high-risk gap, then update the legal register and risk assessment, triage overdue customer files, test beneficial ownership, review alerts and reporting, deliver targeted training, and report progress to accountable management. Each action needs an owner, deadline, evidence, quality check, and decision on whether historical cases require further review or reporting.
Related Success Story
The firm’s published Corporate Fraud & Embezzlement Case Successfully Resolved in Dubai shows why financial records, authority, transactions, and criminal procedure may need coordinated review. It is not an AML compliance audit and does not guarantee a regulatory or litigation outcome for another business.
Is Your AML Program Current and Defensible?
Leaders Advocates can help map the governing framework, entity scope, risk assessment, due diligence, reporting, records, governance, and remediation priorities.
Common Mistakes
- Using a policy that still cites the replaced 2018 law and old executive regulation.
- Treating CDD as a one-time identity check rather than an ongoing risk process.
- Recording the immediate shareholder without identifying beneficial ownership and control.
- Closing alerts with generic wording that does not show a reasoned review.
- Failing to restrict suspicious-report information and manage tipping-off risk.
- Training staff without testing understanding or preserving attendance and assessment records.
Relevant Legal Services
A Corporate Lawyers in Dubai can align governance, policies, contracts, management accountability, and remediation. A Criminal Defense Lawyers in Dubai can advise where an investigation, statement, reporting issue, or criminal allegation arises. A Litigation Lawyer in Dubai can coordinate regulatory disputes, contested evidence, court proceedings, and related recovery issues.
People Also Ask
The anti money laundering regulations uae businesses apply are a continuous governance and risk system, not a one-time KYC form or a report filed only after misconduct is obvious. Current compliance should reflect Federal Decree-Law No. 10 of 2025, Cabinet Resolution No. 134 of 2025, sector guidance, documented controls, and evidence that the program works in practice.
Need Help Strengthening Your UAE AML Compliance?
Our team can help identify compliance gaps, update policies and controls, assess beneficial ownership and customer-risk procedures, and develop practical remediation priorities.

