The UAE has moved from Financial Action Task Force grey list scrutiny to renewed international confidence, and that shift has raised the compliance bar for every regulated business in the country. Following the country’s removal from the FATF grey list in February 2024, supervisors have moved from framework building to enforcement effectiveness, with the Ministry of Economy and the Central Bank issuing record numbers of penalties against non-compliant entities. For auditors, accountants, real estate brokers, dealers in precious metals, corporate service providers, and financial institutions, robust AML/CFT compliance is no longer a documentation exercise. It is a licence to operate. This guide sets out the practical challenges UAE businesses face in 2026 and the best practices needed to close common gaps.

The UAE AML/CFT Regulatory Landscape in 2026

The core framework rests on Federal Decree-Law No. 20 of 2018 on Anti-Money Laundering and Combating the Financing of Terrorism, later amended by Federal Decree-Law No. 26 of 2021, together with Cabinet Decision No. 10 of 2019 setting out the implementing regulations. Oversight is layered. The Central Bank of the UAE supervises licensed financial institutions, while the Ministry of Economy regulates Designated Non-Financial Businesses and Professions, known as DNFBPs, including auditors, real estate brokers, precious metals and stones dealers, and corporate service providers. The Executive Office for Anti-Money Laundering and Counter Terrorism Financing coordinates national strategy, and suspicious transaction reports are filed through the goAML platform operated by the UAE Financial Intelligence Unit.

Common AML/CFT Compliance Challenges Facing UAE Businesses

Customer due diligence gaps

Many entities still treat customer due diligence as an onboarding checklist rather than an ongoing obligation. Weak identity verification, poor understanding of the purpose of the business relationship, and inconsistent enhanced due diligence on politically exposed persons remain the most cited findings in Ministry of Economy inspections carried out during 2024 and 2025.

Beneficial ownership obligations

Identifying the natural persons who ultimately own or control a legal entity remains one of the hardest areas in practice, particularly where ownership sits through multi-layered offshore holding structures. Failure to maintain accurate registers or file changes on time triggers administrative penalties, and many firms struggle to align internal records with the requirements set out under Cabinet Decision No. 109 of 2023 on beneficial ownership. A structured approach to ubo compliance is now expected at both onboarding and periodic review stages.

goAML reporting obligations

DNFBPs must register on the goAML portal and submit Suspicious Transaction Reports, Suspicious Activity Reports, High Risk Country reports, Partial Name Match Reports, and, where applicable, Dealers in Precious Metals and Stones Reports. Under-reporting and delayed filing continue to be leading causes of enforcement action.

Sanctions screening

Firms must screen customers and counterparties against the UAE Local Terrorist List and the United Nations Security Council Consolidated List, and freeze funds without delay where a positive match is confirmed. Manual screening across large customer books almost always produces gaps.

Training and record-keeping

Records must be retained for a minimum of five years, and staff training must be documented, role-specific, and refreshed regularly. Generic annual training is no longer accepted as adequate by supervisors.

Best Practices to Strengthen Your AML/CFT Programme

Adopt a documented risk-based approach

Every regulated entity should complete an enterprise-wide risk assessment covering customer, geography, product, delivery channel, and transaction risks. The assessment should be reviewed at least annually and after any material change in the business, and it should feed directly into policies, monitoring rules, and training priorities.

Strengthen customer and beneficial ownership diligence

Effective controls start at onboarding. Enhanced procedures should apply to politically exposed persons, customers in high-risk jurisdictions, and complex ownership structures, supported by reliable independent data sources and clear escalation triggers. Well designed ubo due diligence workflows help teams identify hidden control chains and reduce reliance on self-declaration.

Appoint a qualified Money Laundering Reporting Officer

The MLRO or Compliance Officer should have sufficient seniority, independence, and direct access to senior management and the board. Their responsibilities cover policy oversight, goAML reporting, sanctions screening, staff training, and management information reporting on control effectiveness.

Commission independent AML audits

An independent review of the AML/CFT programme provides assurance that policies operate as designed. It is expected by supervisors and often reduces the severity of enforcement outcomes where issues are self-identified and remediated early. Firms benefit from engaging an experienced audit and assurance partner familiar with UAE regulatory expectations across mainland and free zones.

Use technology to reduce manual error

Automated name screening, transaction monitoring, and case management tools improve consistency, reduce false negatives, and produce the audit trail that supervisors expect during inspections.

Integrate AML with wider finance controls

AML compliance rarely stands alone. Aligning it with corporate tax, VAT, and bookkeeping controls ensures consistent customer records, faster responses to regulator information requests, and a stronger overall control environment.

Quick-Reference AML/CFT Compliance Checklist

Confirm registration on the goAML portal. Complete and document an enterprise-wide AML/CFT risk assessment. Maintain up-to-date customer due diligence files and beneficial ownership records. Screen all customers and counterparties against the UAE Local Terrorist List and the UN Consolidated List. File suspicious transaction and activity reports without delay. Deliver documented, role-specific AML training at least annually. Retain records for a minimum of five years. Commission an independent AML audit and remediate findings on a defined timeline.

Partner With Experienced UAE Compliance Specialists

Asad Abbas & Co. Chartered Accountants LLC brings more than 10 years of UAE experience across audit, tax, and regulatory compliance. As an FTA Approved Tax Agent, RERA Registered Auditor, Freezone Listed Auditor, and firm registered with the UAE Ministry of Justice, we support DNFBPs and financial institutions across Dubai, Abu Dhabi, and the wider UAE. Our team of 40+ qualified professionals holding CPA, CGMA, CMA, CFM, and MBA credentials has served more than 5,000 clients and delivered over 1,000 audits across 14+ industries. From risk assessments and policy design to independent AML testing and beneficial ownership reviews, our specialists help you meet supervisory expectations with confidence. Speak with our compliance team today for a confidential assessment of your current AML/CFT framework, and take the next step toward a defensible, well documented programme aligned with UAE federal requirements.

Frequently Asked Questions

Q: What is AML/CFT compliance in the UAE?

A: AML/CFT compliance refers to the legal and regulatory obligations placed on financial institutions and Designated Non-Financial Businesses and Professions to prevent money laundering, terrorism financing, and the financing of illegal organisations. In the UAE, these obligations flow from Federal Decree-Law No. 20 of 2018 and its implementing Cabinet Decision No. 10 of 2019. Regulated entities must implement customer due diligence, sanctions screening, suspicious transaction reporting through the goAML portal, ongoing transaction monitoring, staff training, and record-keeping for a minimum of five years to remain compliant with UAE law.

Q: Who supervises AML/CFT compliance in the UAE?

A: Supervision is shared across several authorities. The Central Bank of the UAE regulates licensed financial institutions including banks, exchange houses, insurance companies, and finance companies. The Ministry of Economy supervises Designated Non-Financial Businesses and Professions such as auditors, real estate brokers, dealers in precious metals and stones, and corporate service providers. Securities and commodities activities fall under the Securities and Commodities Authority, while free zone regulators such as the DFSA in DIFC and the FSRA in ADGM supervise their licensed entities. The Executive Office for Anti-Money Laundering and Counter Terrorism Financing coordinates national policy across all supervisors.

Q: What are the penalties for AML/CFT non-compliance in the UAE?

A: Penalties are significant and rising. Administrative fines under Cabinet Decision No. 10 of 2019 and its amendments can reach several million dirhams per violation, and repeat breaches may trigger licence suspension or revocation. The Ministry of Economy has publicly announced record penalties against DNFBPs since 2022, and criminal liability applies to money laundering offences under Federal Decree-Law No. 20 of 2018, including imprisonment. Beyond financial penalties, non-compliance can lead to reputational damage, loss of banking relationships, restricted cross-border business, and inclusion on supervisory watch lists shared with other authorities.

Q: How often should an AML risk assessment be updated?

A: An enterprise-wide AML/CFT risk assessment should be reviewed at least once every 12 months and refreshed whenever there is a material change in the business, such as a new product line, entry into a new market or jurisdiction, a change in customer base, or a shift in regulatory expectations. The assessment must be documented, approved by senior management, and used to shape customer due diligence procedures, transaction monitoring rules, sanctions screening thresholds, and staff training priorities. UAE supervisors expect the risk assessment to be a living document supported by clear evidence of periodic review.

Q: Do free zone companies in Dubai and Abu Dhabi need AML compliance?

A: Yes. Free zone companies engaged in regulated activities are subject to the same federal AML/CFT obligations as mainland entities. Financial free zone regulators such as the Dubai Financial Services Authority in the DIFC and the Financial Services Regulatory Authority in the ADGM operate their own rulebooks aligned with UAE federal law. DNFBPs licensed in commercial free zones fall under Ministry of Economy supervision and must register on the goAML portal, complete customer due diligence, screen against sanctions lists, deliver documented training, and file suspicious activity reports in line with the same national framework applied across the country.

insights

Related Blogs

blog
5th Aug | 2026

Essentials of VAT Compliance for Businesses in the UAE

Value Added Tax has been part of the UAE business landscape since January 2018, yet compliance remains one…

Read more orange-arrow-right
blog
12th Aug | 2026

Comprehensive Guide: Preparing Your Business for a Successful Audit in the UAE

Audits in the UAE have shifted from a periodic formality to a year round compliance discipline. With Corporate…

Read more orange-arrow-right
blog
24th Jul | 2026

Are You Ready for a VAT Audit in the UAE? Key Considerations

The Federal Tax Authority has intensified its scrutiny of taxable businesses across the Emirates, and companies that once…

Read more orange-arrow-right