📌 Introduction
The UAE continues to strengthen its framework for combating money laundering, terrorist financing and proliferation financing as part of its commitment to protecting the integrity of its financial system and business environment.
For businesses operating in regulated sectors, Anti-Money Laundering (AML) compliance is much more than maintaining a policy document. It requires a structured, risk-based compliance framework covering customer due diligence, risk assessment, sanctions screening, ongoing monitoring, suspicious transaction reporting, employee training, record keeping and effective management oversight.
The UAE’s current AML/CFT/CPF framework is principally governed by Federal Decree-Law No. 10 of 2025 and its Executive Regulations under Cabinet Resolution No. 134 of 2025, which replaced the previous legislative framework.
For Financial Institutions (FIs), Designated Non-Financial Businesses and Professions (DNFBPs), and other entities subject to AML/CFT requirements, understanding these obligations and implementing them effectively is essential to maintaining regulatory compliance in 2026.
🧾 What Is AML Compliance?
AML compliance refers to the policies, procedures, systems and controls established by regulated businesses to identify, assess, manage and mitigate risks associated with:
- Money Laundering (ML)
- Terrorist Financing (TF)
- Proliferation Financing (PF)
- Sanctions exposure
- Other relevant financial crime risks
An effective AML/CFT framework should be proportionate to the nature, size, complexity and risk exposure of the organization.
The objective is not simply to satisfy regulatory requirements, but to prevent businesses, financial institutions and professional services from being misused for illicit financial activities.
🏢 Which Businesses Are Subject to AML Requirements in the UAE?
The UAE AML/CFT framework applies to a broad range of regulated entities, including Financial Institutions (FIs) and Designated Non-Financial Businesses and Professions (DNFBPs). The specific obligations and supervisory authority may vary depending on the nature of the business, its activities and the regulatory framework under which it operates.
Financial Institutions may include:
- Banks
- Exchange houses
- Finance companies
- Insurance companies and other regulated insurance-sector entities
- Payment service providers and other regulated financial service businesses
- Securities and investment-related businesses
- Other financial institutions falling within the applicable UAE AML/CFT regulatory framework
Designated Non-Financial Businesses and Professions (DNFBPs) include relevant activities carried out by:
- Real estate brokers and agents
- Dealers in Precious Metals and Stones (DPMS)
- Auditors and accountants
- Trust and company service providers
- Lawyers, notaries and other independent legal professionals when carrying out specified activities
Financial Institutions and DNFBPs are subject to AML/CFT obligations appropriate to their activities and risk exposure, including requirements relating to risk assessment, Customer Due Diligence (CDD), Enhanced Due Diligence (EDD), beneficial ownership identification, sanctions screening, ongoing monitoring, suspicious transaction reporting, record keeping, internal controls and employee training.
The applicable requirements may also differ according to the entity’s supervisory authority. Businesses should therefore understand both the UAE’s overarching AML/CFT legislation and the specific rules, guidance and expectations issued by their respective regulator.
📊 Key AML Compliance Requirements for UAE Businesses
1. Establish an AML/CFT Compliance Framework
A regulated business should have an AML/CFT framework appropriate to its activities and risks.
The framework should clearly establish:
- AML/CFT policies and procedures
- Roles and responsibilities
- Customer acceptance procedures
- Customer risk assessment
- CDD and EDD requirements
- Screening procedures
- Ongoing monitoring
- Internal escalation procedures
- Suspicious transaction reporting
- Record-keeping requirements
- Training requirements
Importantly, the framework should reflect how the business actually operates rather than functioning merely as a standard policy document.
🔍 2. Conduct an Enterprise-Wide Risk Assessment (EWRA)
A fundamental part of the risk-based approach is understanding the organization’s exposure to ML/TF/PF risks.
An Enterprise-Wide Risk Assessment (EWRA) generally considers risk factors such as:
- Customer risk
- Geographic risk
- Product and service risk
- Transaction risk
- Delivery channel risk
- Other risks relevant to the business
The organization can then establish appropriate controls based on the risks identified.
A higher-risk business relationship should generally receive stronger scrutiny than a lower-risk relationship.
👤 3. Perform Customer Due Diligence (CDD)
Businesses subject to AML requirements must understand who they are dealing with.
Customer Due Diligence may involve:
- Identifying the customer
- Verifying customer identity
- Understanding the nature of the business relationship
- Identifying beneficial owners
- Establishing ownership and control structures
- Understanding the purpose of the relationship
- Assessing the customer’s risk profile
CDD should not be viewed simply as collecting identification documents. Businesses need to understand the customer and the associated risk.
⚠️ 4. Apply Enhanced Due Diligence for Higher-Risk Relationships
Where higher risks are identified, additional measures may be necessary.
Enhanced Due Diligence (EDD) can include:
- Obtaining additional customer information
- Establishing source of funds
- Establishing source of wealth where appropriate
- Understanding complex ownership structures
- Obtaining additional information about transactions
- Applying increased monitoring
- Obtaining appropriate management approval
The extent of EDD should correspond with the risks identified.
🌍 5. Conduct Sanctions and PEP Screening
Screening is another important element of AML compliance.
Businesses should have appropriate procedures for identifying potential exposure involving:
- Sanctioned individuals and entities
- Politically Exposed Persons (PEPs)
- Relevant risk indicators
Screening should not end with customer onboarding. Depending on the applicable requirements and risk profile, businesses should also maintain appropriate ongoing screening and review processes.
Potential matches should be properly investigated, documented and escalated where necessary.
🔄 6. Conduct Ongoing Monitoring and Re-KYC
Customer risk does not remain static.
During a business relationship, there may be changes in:
- Ownership
- Management
- Business activities
- Geographic exposure
- Transaction patterns
- PEP status
- Sanctions exposure
- Overall customer risk
Businesses should therefore maintain appropriate ongoing monitoring and periodically update customer information through Re-KYC, with the frequency and extent of review based on risk and applicable requirements.
🚨 7. Identify and Report Suspicious Activity
Employees should be able to recognize unusual or potentially suspicious behaviour and understand the organization’s internal escalation procedures.
Businesses should establish procedures covering:
- Identification of suspicious activity
- Internal escalation
- MLRO/Compliance Officer review
- Documentation of decisions
- Reporting to the relevant authorities where required
- Confidentiality requirements
A strong reporting framework helps ensure that suspicious activities are identified, assessed, escalated and reported appropriately.
👨💼 8. Establish Effective MLRO and Management Oversight
AML compliance requires appropriate governance.
Depending on the regulatory requirements applicable to the organization, responsibilities may include:
- Oversight of AML/CFT controls
- Review of internal escalations
- Regulatory reporting
- Monitoring compliance deficiencies
- Reporting to senior management
- Maintaining compliance documentation
- Coordinating corrective actions
Senior management also plays an important role in creating an effective compliance culture and ensuring that sufficient resources are allocated to AML/CFT compliance.
🎓 9. Provide Regular AML/CFT Training
Even a well-designed AML framework can fail if employees do not understand their responsibilities.
Training should help relevant employees understand:
- AML/CFT obligations
- Customer due diligence
- Common red flags
- Suspicious activity
- Internal escalation procedures
- Sanctions and PEP risks
- Sector-specific financial crime risks
Training should also be appropriate to the employee’s role and responsibilities.
📁 10. Maintain Proper AML Records
Businesses should maintain appropriate documentation demonstrating how their AML/CFT obligations have been implemented.
Depending on applicable requirements, records may include:
- Customer identification documents
- Beneficial ownership information
- Customer risk assessments
- CDD and EDD documentation
- Screening records
- Transaction-related documentation
- Internal escalation records
- Regulatory reporting records
- Training records
- Risk assessments
- Compliance reviews and audit records
Good record keeping is particularly important during regulatory inspections and independent AML audits.
🛡️ AML Compliance Is About Effectiveness, Not Just Documentation
One of the most important lessons for businesses is that having an AML policy alone does not necessarily demonstrate effective compliance.
Regulators focus on whether AML/CFT controls are actually implemented and operating effectively.
For example, a company may have a policy requiring Enhanced Due Diligence for high-risk customers. But if customer files show that high-risk customers were onboarded without EDD, there is a clear gap between policy and practice.
An effective compliance programme therefore requires businesses to periodically assess whether documented procedures are being followed in day-to-day operations.
🔎 Importance of AML Gap Analysis
An AML Gap Analysis helps businesses compare their existing AML/CFT framework and practices against applicable regulatory requirements.
It can identify areas such as:
- Missing policies
- Outdated procedures
- Weak CDD processes
- Inadequate EDD
- Incorrect risk classifications
- Insufficient screening
- Incomplete customer records
- Weak ongoing monitoring
- Training deficiencies
- Governance weaknesses
Once gaps are identified, businesses can develop corrective action plans to strengthen their compliance framework.
📋 Why Independent AML Audits Matter
An independent AML Audit provides an objective assessment of whether the organization’s AML/CFT controls are appropriately designed and effectively implemented.
An AML Audit may review:
- AML/CFT framework
- EWRA
- Customer risk assessment
- CDD and EDD
- Beneficial ownership
- Screening
- Re-KYC
- Ongoing monitoring
- Suspicious activity escalation
- Record keeping
- Employee training
- MLRO oversight
- Internal controls
Independent reviews can help management identify weaknesses before they become more significant compliance concerns and improve overall regulatory readiness.
🏦 AML Compliance for Financial Institutions
Financial Institutions operate at the centre of the financial system and may face significant exposure to money laundering, terrorist financing, proliferation financing and sanctions-related risks.
Depending on their activities and regulatory requirements, Financial Institutions may need to maintain robust controls covering:
- Institutional and customer risk assessments
- Customer onboarding and KYC
- Beneficial ownership identification
- CDD and EDD
- Source of funds and source of wealth where applicable
- Sanctions and PEP screening
- Ongoing customer monitoring
- Transaction monitoring
- Suspicious transaction identification and reporting
- Correspondent or other higher-risk relationships where applicable
- AML/CFT training
- MLRO and compliance governance
- Independent review and audit
Banks, exchange houses, payment service providers, finance companies and other regulated financial businesses may also be subject to specific AML/CFT requirements, guidance and supervisory expectations issued by their respective regulators.
For Financial Institutions, AML compliance should therefore form an integral part of the organization’s overall risk management, governance and internal control framework.
🏙️ AML Compliance for Real Estate Businesses
Real estate can involve high-value transactions and complex ownership arrangements, making the sector important from an AML/CFT perspective.
UAE real estate brokers and agents subject to AML requirements should pay particular attention to:
- Customer and beneficial owner identification
- Buyer and seller due diligence
- Customer risk assessment
- Source of funds where appropriate
- PEP and sanctions screening
- Suspicious activity
- Record keeping
- Applicable regulatory reporting requirements, including REAR where required
Effective AML controls help real estate businesses identify higher-risk relationships and transactions while maintaining appropriate regulatory compliance.
💎 AML Compliance for Gold, Jewellery and Precious Metals Businesses
Dealers in Precious Metals and Stones (DPMS) operate in another sector with significant AML/CFT exposure.
Businesses should consider risks associated with:
- High-value transactions
- Cash transactions
- International customers
- Complex corporate ownership
- Geographic exposure
- Source of funds
- Unusual transaction patterns
- Sanctions exposure
DPMS businesses should also understand the regulatory reporting requirements applicable to their activities, including DPMSR where required.
A strong risk-based AML framework is particularly important for businesses operating in the gold, jewellery, precious metals and precious stones sectors.
🚩 Common AML Compliance Mistakes Businesses Should Avoid
Some common weaknesses include:
- Treating AML compliance as a one-time exercise
- Using generic policies not tailored to the business
- Incomplete KYC documentation
- Failure to identify beneficial owners
- Incorrect customer risk classification
- Failure to conduct EDD for higher-risk customers
- Inadequate sanctions and PEP screening
- Failure to update customer information
- Insufficient employee training
- Poor documentation of compliance decisions
- Lack of periodic independent review
A strong AML programme should evolve alongside the organization’s business activities and risk profile.
📌 How Businesses Can Prepare for an AML Regulatory Inspection
Regulated businesses should remain inspection-ready rather than waiting until an inspection is announced.
Preparation can include:
- Reviewing the AML/CFT framework
- Updating the EWRA
- Reviewing customer risk assessments
- Checking KYC files
- Verifying EDD documentation
- Reviewing sanctions and PEP screening
- Checking Re-KYC status
- Reviewing training records
- Testing internal controls
- Conducting an AML Gap Analysis
- Conducting an independent AML Audit where appropriate
- Addressing identified deficiencies
This approach helps make compliance part of normal business operations rather than an exercise undertaken only when regulators request information.
💼 How Professional AML Consultants Can Help
AML/CFT requirements can become complex, particularly for Financial Institutions and DNFBPs operating in regulated or higher-risk sectors.
Professional AML consultants can assist organizations with:
- AML/CFT framework implementation
- AML policies and procedures
- Enterprise-Wide Risk Assessment (EWRA)
- Customer Risk Assessment
- AML Gap Analysis
- Independent AML/CFT Audit
- CDD and EDD procedures
- Re-KYC procedures
- AML/CFT training
- MLRO support
- Regulatory inspection readiness
- Ongoing compliance advisory
The exact scope of professional support should be tailored to the organization’s sector, regulatory requirements, business activities and risk profile.
📌 Conclusion
AML compliance in the UAE has entered a strengthened regulatory phase under Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025.
For Financial Institutions, DNFBPs and other regulated entities, effective AML compliance requires much more than preparing policies. It requires a functioning risk-based framework supported by appropriate risk assessments, customer due diligence, screening, ongoing monitoring, reporting procedures, employee training, governance and independent review.
At AVS Lewis & Pecker Auditing, our dedicated AML/CFT compliance professionals provide AML/CFT framework implementation, Enterprise-Wide Risk Assessments, Customer Risk Assessments, independent AML/CFT Audits, AML Gap Analysis, AML/CFT training, compliance advisory, MLRO support and related professional services to businesses across regulated sectors in the UAE.
Our approach is focused not merely on documentation, but on helping organizations establish practical, risk-based AML/CFT controls that support regulatory compliance, strengthen internal governance and protect long-term business integrity.

