UAE AML/CFT Compliance for DNFBPs: Current Regulatory Framework
Vassilev & Chisuse Law Firm ยท 2026-09-20
The United Arab Emirates (UAE) anti-money laundering, counter-terrorist financing and counter-proliferation financing framework (AML/CFT/CPF) applies not only to the financial sector but also to specified Designated Non-Financial Businesses and Professions (DNFBPs).
As of the present moment, the principal federal framework is set out in Federal Decree by Law No. (10) of 2025 Regarding Anti-Money Laundering, and Combating the Financing of Terrorism and Proliferation Financing and Cabinet Resolution No. (134) of 2025 Regarding the Executive Regulations of Federal Decree by Law No. (10) of 2025. The 2025 Federal Decree by Law repealed Federal Decree-Law No. (20) of 2018, while Cabinet Resolution No. (134) of 2025 has been the operative executive regulation since 14 December 2025.
The Targeted Financial Sanctions (TFS) framework continues to be governed in part by Cabinet Resolution No. (74) of 2020. The competent supervisory authority and any additional regulatory requirements depend on the relevant activity and place of licensing. Entities in the Dubai International Financial Centre (DIFC) and Abu Dhabi Global Market (ADGM) are also subject to the relevant AML rules of the Dubai Financial Services Authority (DFSA) or Financial Services Regulatory Authority (FSRA), alongside the applicable federal framework.
Which Activities Fall Within the UAE DNFBP Regime?
The current federal executive regulations identify specific categories of activities as DNFBPs and, in certain cases, make the application of the regime dependent on the nature or value of the relevant transaction.
Real estate brokers and agents fall within the regime when concluding transactions or arranging transactions for customers concerning the purchase or sale of real estate. Dealers in precious metals and precious stones are covered where they carry out a single cash transaction, or several linked cash transactions, with a value of at least AED 55,000.
Lawyers, notaries, other independent legal professionals and independent accountants are covered when they prepare, conduct or execute specified financial transactions on behalf of clients. These include the purchase and sale of real estate, management of client funds, management of bank, savings or securities accounts, organisation of contributions for the creation, operation or management of companies, and the creation, operation or management of legal persons or legal arrangements and the purchase or sale of business entities.
The regime also applies to Company and Trust Service Providers where they provide the services specified in the regulations, including company formation, providing or arranging directors, secretaries or partners, providing a registered, business, correspondence or administrative address, acting or arranging for another person to act as a trustee or equivalent, and providing nominee shareholder services.
Since 2025, the federal DNFBP definition also covers Commercial Gaming Operators in relation to a single financial transaction or several linked financial transactions with a value of at least AED 11,000, subject to the conditions set out in the applicable executive regulations.
Entities established in the financial free zones must also consider the sector-specific rules of the relevant regulator. DNFBP status should therefore not be determined solely by the general title of a profession or service without analysing the activities performed, the transactions involved and the applicable supervisory regime.
What Internal AML/CFT/CPF Policies Must DNFBPs Maintain?
DNFBPs must maintain internal policies, controls and procedures proportionate to the nature, size and risk profile of their business. The internal framework must be approved by senior management, continuously monitored and updated when the business, its risks or the applicable regulatory environment changes.
The control framework must address risk management, Customer Due Diligence, monitoring of business relationships and transactions, suspicious transaction and activity reporting, sanctions controls, record keeping and the allocation of responsibilities. The current framework also requires a compliance officer at management level, appropriate employee screening, periodic training and an independent audit function, proportionate to the nature and size of the business.
How Must DNFBPs Assess Their Business Risk?
The risk-based approach requires a DNFBP to identify, assess, understand and manage the financial crime risks to which it is exposed. The assessment must be documented, kept current and made available to the competent supervisory authority upon request.
The assessment must consider at least customer risks, countries and geographic areas, products, services, transactions and delivery channels. It must also take account of the findings of the UAE National Risk Assessment and other relevant risk factors. The intensity of subsequent controls should be proportionate to the level of risk identified.
Higher-risk situations require enhanced measures. Depending on the circumstances, these may include obtaining additional information about the customer and beneficial owner, more frequent updating of CDD information, establishing the reasons for particular transactions, determining the source of funds and source of wealth, enhanced ongoing monitoring and, where applicable, senior management approval.
Customer Due Diligence and Enhanced Due Diligence
Customer Due Diligence (CDD) includes identifying and verifying the customer and beneficial owner, establishing the purpose and intended nature of the business relationship, and conducting ongoing monitoring of the relationship and transactions. CDD documents, data and information must be kept current.
Identity verification must take place before or during the establishment of a business relationship or, where there is no business relationship, before the relevant transaction is conducted. In low-risk circumstances, verification may be completed after the relationship has commenced only where the applicable conditions are satisfied, including where this is necessary not to interrupt the normal conduct of business, verification is completed promptly and appropriate risk controls are in place.
CDD must also be applied where there is suspicion of money laundering or another relevant offence, or where doubts arise regarding the accuracy or adequacy of previously obtained identification data. Where a DNFBP cannot apply the required CDD measures, it must not establish or continue the business relationship or execute the relevant transaction and must consider whether a suspicious transaction report is required.
The rules for Politically Exposed Persons (PEPs) depend on the category concerned. For foreign PEPs, the framework requires systems to determine PEP status, senior management approval before establishing or continuing the business relationship, reasonable measures to establish the source of funds and source of wealth, and enhanced ongoing monitoring. For domestic PEPs and persons entrusted with prominent functions by international organisations, these enhanced measures apply where the business relationship presents a higher risk.
Targeted Financial Sanctions and Sanctions Screening
Targeted Financial Sanctions obligations form a distinct part of the UAE AML/CFT/CPF framework. DNFBPs must screen against the United Nations Security Council sanctions lists and the UAE Local Terrorist List and maintain a process capable of promptly identifying persons and entities subject to asset-freezing measures and prohibitions on making funds or economic resources available.
Current guidance issued by the Executive Office for Control and Non-Proliferation (EOCN) requires daily sanctions screening. Screening must consider not only customer names but also beneficial ownership and control. The application of TFS is not determined by a generic mechanical 50% ownership threshold. Direct and indirect ownership and control must be assessed, and where a listed person holds an ownership interest, the freezing measures may affect that person's interest regardless of the specific percentage held.
Where a confirmed match is identified, the relevant funds or economic resources must be frozen without delay and without prior notice to the affected person. A Funds Freeze Report (FFR) must be submitted through goAML within the applicable period, with current EOCN guidance requiring reporting within two business days. A potential or partial match must be handled under the corresponding procedure and a Partial Name Match Report (PNMR) submitted through goAML.
How Long Must AML Records Be Retained?
DNFBPs must retain the required records, documents and data relating to financial and commercial transactions for at least five years following completion of the transaction or termination of the business relationship, as applicable. The same minimum period applies to CDD and ongoing monitoring records, customer files, correspondence and identification documents.
Records must be organised so that they can be provided promptly to the competent authorities. In practical terms, this requires a traceable record-keeping system capable of reconstructing the relevant customer relationship, due diligence measures and transactions.
Compliance Officer, MLRO, Internal Controls and Training
A DNFBP must appoint a compliance officer at management level who has the necessary competence and experience and sufficient independence to perform the role. The compliance officer oversees implementation of the internal AML/CFT/CPF framework, the handling of potentially suspicious matters and compliance with reporting and regulatory cooperation requirements.
Businesses must also maintain ongoing and documented staff training programmes proportionate to employees' functions and risk exposure. Training must enable relevant employees to recognise applicable risks and indicators of suspicion and to understand internal escalation and reporting procedures.
Reporting Suspicious Transactions and Activities Through goAML
Where a DNFBP suspects or has reasonable grounds to suspect that funds, a transaction or an attempted transaction represent proceeds of crime or are connected with criminal activity, it must notify the Financial Intelligence Unit (FIU) electronically without delay. The reporting obligation applies irrespective of the value of the transaction.
goAML is the electronic reporting platform operated by the UAE Financial Intelligence Unit. The platform provides different reporting types, including a Suspicious Transaction Report (STR) for suspicious transactions and a Suspicious Activity Report (SAR) for suspicious activity or attempted transactions where the relevant facts fall within the applicable reporting category.
A DNFBP and its directors, officers and employees must not inform a customer or third party that an STR has been or is intended to be filed, or disclose related information concerning an investigation. The current framework provides specific reporting exceptions for certain information obtained by lawyers, notaries, other independent legal professionals and independent statutory auditors in protected professional circumstances. An attempt by a legal professional to dissuade a client from engaging in unlawful conduct does not constitute prohibited disclosure.
What Does AML/CFT/CPF Compliance Mean in Practice?
Effective compliance requires more than maintaining a standard AML policy. A DNFBP must be able to demonstrate that its risks have been assessed, its internal policies reflect its actual business, CDD and EDD are applied according to risk, sanctions screening operates continuously, records are traceable, staff receive appropriate training, and identified suspicions are escalated and reported in accordance with the applicable requirements.
For businesses operating across different Emirates or free zones, a fundamental compliance step is identifying the applicable regulatory framework and competent supervisory authority. Businesses operating in the DIFC or ADGM must also consider the relevant local regulatory framework alongside the applicable federal AML/CFT/CPF requirements.
Legal Assistance with AML/CFT/CPF Compliance
Vassilev & Chisuse Law Firm assists non-financial businesses operating internationally and in the Middle East with matters concerning the applicable AML/CFT regulatory framework, internal policies and control systems, and registration and reporting through goAML.
This material reflects the legal and regulatory framework reviewed as at 21 September 2026 and is provided for general information purposes only. It does not constitute individual legal, financial, tax or other professional advice and should not be used as a substitute for legal advice concerning a specific matter.
Related legal services
Related articles