UAE Financial Intelligence Unit (FIU): Role, Powers and Responsibilities Under UAE AML Law

What Is the Financial Intelligence Unit (FIU)?

A Financial Intelligence Unit (FIU) is the national authority that receives reports of suspicious financial activity from regulated businesses, analyses those reports, and passes the resulting intelligence to law enforcement. It sits between the private sector and the criminal justice system. It does not investigate, arrest, or prosecute.

FIU Full Form and Meaning

FIU stands for Financial Intelligence Unit. The term is sometimes written incorrectly as “financial investigation unit,” which describes a different kind of body. An FIU produces intelligence; it does not conduct criminal investigations.

What an FIU does in the AML/CFT Chain

Every FIU performs three sequential functions:

  • Receive: Regulated entities file suspicious transaction reports and related information into a central channel.
  • Analyse: The unit examines each report, enriches it with data it can lawfully obtain, and establishes whether there are grounds to suspect a link to criminal activity.
  • Disseminate: Where those grounds exist, the unit passes intelligence to the authorities empowered to act on it.

This is why an FIU is described as the bridge between compliance functions and law enforcement. Without it, thousands of individual reports would sit in isolation, with no mechanism to connect a transaction flagged by a bank in one emirate to a property purchase flagged by a broker in another.

FIU, Regulator, and Law Enforcement: Three Different Bodies

Reporting entities routinely confuse these roles, and the confusion has practical consequences.

BodyWhat it doesWhat it cannot do
Financial Intelligence UnitReceives and analyses suspicious transaction reports, disseminates financial intelligenceProsecute, arrest, or impose administrative fines on a reporting entity
Supervisory AuthoritySupervises your AML/CFT compliance, inspects, imposes administrative penaltiesReceive suspicious transaction reports in place of the FIU
Law Enforcement Authorities and Public ProsecutionInvestigate, seize, charge, prosecuteReceive suspicious transaction reports directly from reporting entities

Under UAE law, administrative penalties for AML/CFT failures sit with Supervisory Authorities under Federal Decree-Law No. 10 of 2025, Article 17, not with the FIU. The FIU is not your regulator.

Is every country required to have an FIU?

Yes. FATF Recommendation 29 requires each jurisdiction to establish a national FIU that serves as the central agency for receiving and analysing suspicious transaction reports and disseminating the results. The FATF also assesses how effectively that unit performs, which is why FIU capability is a recurring theme in mutual evaluation reports.

Role and Responsibilities of the UAE FIU

The UAE FIU has six core responsibilities: receiving suspicious transaction reports as the national centre, analysing them operationally and strategically, requesting further information from reporting entities, disseminating intelligence to law enforcement, providing feedback on report quality, and maintaining the national financial intelligence database. Each is set out in Cabinet Resolution No. 134 of 2025, Articles 44 to 46.

1. National centre for receiving suspicious transaction reports

Cabinet Resolution No. 134 of 2025, Article 46(1) provides that the Unit receives reports from financial institutions, DNFBPs, and virtual asset service providers in accordance with the forms approved by the Unit, and examines, analyses, and retains those reports in its database.

Two points follow for reporting entities. The form is prescribed by the Unit, so filing outside the approved format is not compliant filing. And the Unit retains reports, which means a poorly constructed report does not disappear; it remains on record.

2. Analysing financial intelligence

Article 46(3) requires the Unit to analyse reports and available information in two distinct ways.

Operational analysis uses available and obtainable information to identify specific targets such as persons, funds, or criminal networks, to trace the course of specific activities or transactions, and to identify links between those targets, activities, or transactions and potential criminal property.

Strategic analysis uses available and obtainable information, including data provided by Concerned Authorities, to identify crime trends and patterns.

The distinction matters more to your compliance function than it first appears. Operational analysis is what happens to the individual report you filed. Strategic analysis is what eventually produces the typologies, red flag indicators, and sector risk observations that feed back into national risk assessment and, in turn, into the inputs your own ML/TF/PF risk assessment is expected to reflect. Your reports are raw material for the risk picture you will later be assessed against.

3. Requesting additional information from reporting entities

Article 46(2) empowers the Unit to require financial institutions, DNFBPs, virtual asset service providers, and Concerned Authorities to provide any additional information or documents relating to reports and information it has received, as well as any other information it deems necessary for the performance of its functions, within the timeframes and in the manner the Unit determines.

The range of information the Unit can draw on is deliberately wide, and the same Article names disclosure system data, customs information, tax information, and Population Register information among the sources available to it.

Article 42 of the same Resolution removes the obvious objection: bank secrecy, professional secrecy, and contractual liability cannot be invoked to withhold information. Federal Decree-Law No. 10 of 2025, Article 11(1) mirrors the information-request power at statutory level.

Practical implications of an FIU information request:

  • The timeframe is set by the Unit, not negotiated by you.
  • Partial responses generate further requests and extend the Unit’s file on your entity’s responsiveness.
  • Supporting documents matter. Where customer due diligence work or an internal investigation informed your suspicion, that documentation belongs with the response.
  • Contact details registered on the reporting platform must be current, or requests reach nobody.

4. Disseminating intelligence to law enforcement and prosecution

Articles 46(6) and 46(7) require the Unit to use dedicated, secure, and protected channels to disseminate report-related data, analysis results, and other relevant information to Law Enforcement Authorities where sufficient grounds exist to suspect a link to the Crime, and to provide the Public Prosecution and Law Enforcement Authorities with information relating to the Crime, including information obtained from Financial Intelligence Units in other countries, whether spontaneously or on request.

Dissemination is not prosecution. It is the point at which financial intelligence becomes available to bodies that can act on it. What happens next is outside the Unit’s hands and outside yours.

5. Providing feedback to reporting entities, and the risk attached to it

Article 46(4) requires the Unit to provide financial institutions, DNFBPs, and virtual asset service providers with feedback on reports received, to improve the effectiveness of crime combating measures and the detection and reporting of suspicious transactions.

Article 46(5) is the clause that deserves far more attention than it receives. It requires the Unit to cooperate and coordinate with the Supervisory Authority by referring the results of its analyses relating to the quality of reports received, to ensure compliance by financial institutions, DNFBPs, and virtual asset service providers with crime combating procedures.

Read that carefully. The quality of your suspicious transaction reports is a compliance matter that can reach your supervisor through the FIU. Defensive over-reporting, narrative-free filings, and reports with no articulated grounds for suspicion are not a neutral choice. They are visible, they are assessed, and the assessment travels.

6. Maintaining the national financial intelligence database

Federal Decree-Law No. 10 of 2025, Article 11(4) and Cabinet Resolution No. 134 of 2025, Article 45(2) require the Unit to establish and maintain a database of the information in its possession and to protect it through information security and confidentiality controls, including cybersecurity measures and procedures for processing, storing, and disseminating information, and procedures ensuring restricted access to its premises, information, and technological systems.

Article 45(3) adds that staff must obtain the necessary security clearances and be aware of their responsibilities in handling and disseminating sensitive and confidential information.

7. Training, research, and published outputs

Cabinet Resolution No. 134 of 2025, Article 45 gives the Unit a further set of institutional competences:

  • Establishing its organisational structure and internal regulations, including staff integrity procedures and controls preventing unauthorised access or disclosure (Article 45(1)).
  • Providing training courses and programmes for its own staff and for any other entity, whether within or outside the State (Article 45(4)).
  • Preparing studies, research, and statistics relating to the Crime, and following up on national and international work in the field (Article 45(5)).
  • Preparing annual reports on its anti-crime activities, including a general analysis of notifications and suspicious transaction reports received, crime activities and trends, and a summary prepared for publication (Article 45(6)).

Those published outputs are worth reading rather than skimming. The trend and typology content in them is among the few pieces of official evidence available when you need to justify why your risk assessment weights a particular threat the way it does.

Powers of the UAE FIU: Suspending Transactions and Freezing Funds

The Chief of the UAE FIU can order the suspension of a suspect transaction for up to 10 working days and the freezing of suspect funds for up to 30 days, in both cases without prior notice. These powers sit in Federal Decree-Law No. 10 of 2025, Article 5, and they are the point at which financial intelligence becomes an immediate instruction to a reporting entity.

Suspension or cessation of a transaction: up to 10 working days

Article 5(1) provides that the Chief of the Unit may, without prior notice, order the cessation or temporary suspension of any transaction suspected of being related to the Crime, for a period not exceeding ten working days, based on the Unit’s analysis of suspicious transaction reports, or on information or requests received from domestic or international sources, including a counterpart Unit or any authority competent to take such measures.

Note the trigger sources. An order can originate from a foreign counterpart FIU’s request, not only from a report you filed.

Freezing of funds: up to 30 days, extendable

Article 5(2) provides that the Chief of the Unit may also, without prior notice, order the freezing of funds suspected of being related to the Crime and held with financial institutions, DNFBPs, or virtual asset service providers, for a period not exceeding thirty days, based on the Unit’s analysis of suspicious transaction reports and other information received. The order is subject to extension by the Attorney General or their delegate.

Lifting a freeze

Article 5(4) places the obligation on you. Financial institutions, DNFBPs, and virtual asset service providers must lift the freezing order on its cancellation by the Chief of the Unit, or on expiry of the thirty-day period, unless it has been extended.

Articles 5(3) and 5(5) provide that the Unit establishes the system specifying the controls and procedures governing suspension and cessation and the conditions for lifting them, with implementing detail in the Executive Regulations. Cabinet Resolution No. 134 of 2025, Article 51 carries those provisions.

What your procedures need to cover

An order arriving without prior notice is not the moment to design a response. A defensible procedure covers:

  • Who is authorised to receive and acknowledge an order, and their backup.
  • How the instruction is executed within the core systems, and how execution is evidenced.
  • How the customer relationship is handled without tipping off.
  • How the expiry or cancellation date is diarised, so the freeze is lifted when the law requires it and not left running.
  • Where the decision trail is stored for later inspection.

The failure mode is rarely the freeze itself. It is the absence of a record showing when the order arrived, who acted, and when it was lifted. This belongs in your AML policies and procedures rather than in an individual’s memory.

Challenging an extension

Federal Decree-Law No. 10 of 2025, Article 6 provides a grievance route against an extension decision issued by the Attorney General or their delegate under Article 5(2). The grievance is filed by written report to the competent Criminal Court, the Public Prosecution submits a memorandum stating its opinion, and the Court decides within a period not exceeding fourteen working days from submission. The decision is final and not subject to appeal, and if the grievance is rejected no new grievance may be submitted until three months have passed, unless a serious and substantial reason arises earlier.

This is a matter for legal counsel acting for the account holder, not for a reporting entity’s compliance function.

What the FIU cannot do

The Unit does not prosecute, does not arrest, and does not impose administrative penalties on reporting entities. Administrative penalties, ranging from a warning through fines of AED 10,000 to AED 5,000,000 per violation and up to licence revocation, are imposed by Supervisory Authorities under Federal Decree-Law No. 10 of 2025, Article 17.

How the UAE FIU Handles a Suspicious Transaction Report

A suspicious transaction report filed in the UAE moves through eight stages, from internal detection to FIU feedback. Understanding the full path explains why reporting entities rarely receive an outcome, and where their own exposure sits.

Who must report

Federal Decree-Law No. 10 of 2025, Article 11 names financial institutions, designated non-financial businesses and professions, and virtual asset service providers as the entities that submit reports, and the FIU as the exclusive recipient. Article 18 imposes the reporting obligation itself.

DNFBP categories in scope include real estate brokers and agents, dealers in precious metals and stones, lawyers and independent legal professionals, auditors and accountants, and corporate service providers. Virtual asset service providers are within scope by name, which is a material change from the pre-2025 material still circulating online.

When the obligation is triggered

The trigger is suspicion, not value. There is no minimum monetary threshold below which a suspicious transaction need not be reported, and the obligation attaches to attempted transactions as well as completed ones. Reports must be made without delay.

The eight stages

StageWhat happensWho acts
1Detection through monitoring, screening, or staff escalationReporting entity
2Internal assessment and decision by the compliance officer or MLROReporting entity
3Filing on the Unit’s approved form through the national reporting platformReporting entity
4Receipt, examination, and retention in the Unit’s databaseFIU
5Prioritisation, then operational and strategic analysisFIU
6Requests for additional information or documentsFIU to reporting entity
7Dissemination to Law Enforcement Authorities or Public Prosecution where grounds existFIU
8Feedback on the report, and possible referral of quality findings to your supervisorFIU

A suspension or freezing order under Article 5 can enter at any point after stage 5.

Why you rarely hear back

The Unit’s analysis is confidential, the information it holds is subject to use restrictions, and the tipping-off prohibition constrains what can be communicated. Silence after filing is the normal condition, not a sign the report was ignored or that no action followed.

What a high-quality report contains

Article 46 gives the Unit both the power to demand more and the duty to report back on quality. A report that reduces the likelihood of both contains:

  • Complete identification of all parties, including beneficial owners where identified.
  • A narrative that states the grounds for suspicion in plain terms, rather than describing the transaction and leaving the reader to infer the concern.
  • The specific red flags observed, named as such.
  • The customer due diligence file and any internal investigation record attached rather than referenced.
  • Current contact details for the compliance officer or MLRO on the reporting platform.

Support with report construction and platform mechanics sits within our STR and goAML reporting service.

goAML and IEMS: The UAE FIU’s Reporting Systems

The UAE FIU operates two principal systems. goAML is the mandatory channel through which reporting entities file suspicious transaction reports. IEMS is the channel through which the Unit and domestic stakeholders exchange enquiries.

goAML

goAML is the reporting platform of the UAE FIU, launched in June 2019 and developed by the United Nations Office on Drugs and Crime. Registration is mandatory for reporting entities, not optional, and it is the channel for suspicious transaction reports, suspicious activity reports, and the other prescribed report types.

IEMS

The Integrated Enquiry Management System facilitates communication between domestic stakeholders, financial institutions, and the UAE FIU, and is used to exchange specific requests and the correspondence relating to them.

Which system applies to you

SystemPrimary usersPurposeRegistration
goAMLFinancial institutions, DNFBPs, VASPsFiling STRs, SARs, and other prescribed report typesMandatory for reporting entities
IEMSDomestic authorities and financial institutionsExchanging enquiries and related correspondence with the FIUBy arrangement with the FIU

Where registration and filing usually go wrong

In our experience reviewing client reporting arrangements, the recurring problems are administrative rather than analytical: compliance officer contact details left unchanged after a staff departure, registration allowed to lapse into an inactive status, the wrong report type selected, and supporting documents omitted from the submission. None of these are difficult to fix. All of them delay analysis and are visible to the Unit.

Who Does What in the UAE AML/CFT Framework

The UAE AML/CFT framework separates intelligence, supervision, policy, and enforcement across distinct bodies. Confusing them is the source of several common compliance errors. 

BodyLegal basisRoleWhat it receives from you
Financial Intelligence UnitFDL 10/2025, Art. 11; CR 134/2025, Arts. 44 to 47National centre for receiving, analysing, and disseminating financial intelligence; can suspend transactions and freeze fundsSuspicious transaction reports and responses to information requests
Supervisory AuthoritiesFDL 10/2025, Arts. 16 and 17; CR 134/2025, Art. 49Supervise AML/CFT compliance, inspect, impose administrative penaltiesRegistrations, returns, inspection evidence
Law Enforcement Authorities and Public ProsecutionFDL 10/2025, Arts. 6, 8, 9Investigate, seize, freeze by court order, prosecuteNothing directly; they receive intelligence from the FIU
National CommitteeFDL 10/2025, Arts. 13 and 14; CR 134/2025, Art. 48National AML/CFT policy, coordination, national risk assessmentNothing directly
Supreme CommitteeFDL 10/2025, Art. 12Oversight of the national strategy and the mutual evaluation processNothing directly

The FIU and your supervisor are connected. Cabinet Resolution No. 134 of 2025, Article 46(5) provides for referral of report-quality findings, and Article 56 provides for national cooperation and information exchange between authorities more broadly. Treating the FIU relationship as separate from your supervisory relationship is a mistake.

The UAE FIU’s International Role

Cabinet Resolution No. 134 of 2025, Article 47 sets out the Unit’s international competences: exchanging information with counterpart units, concluding memoranda of understanding, notifying counterparts of outcomes, following international developments, and participating in the Egmont Group.

Exchanging information with counterpart FIUs

Article 47(1) allows the Unit to exchange information, both spontaneously and on request, with counterpart units regardless of differences in their nature, and with other foreign competent authorities responsible for the suspension or cessation of transactions suspected of being related to the Crime, and to exchange information with Concerned Authorities in the State to facilitate that cooperation.

Article 47(3) attaches the conditions. The Unit notifies counterpart units of the results of the use of information provided and of the analyses conducted on it, and that information may be used solely for the purposes of combating the Crime and may not be disclosed to any third party without the consent of the Unit. Federal Decree-Law No. 10 of 2025, Article 11(2) states the same restriction at statutory level.

Memoranda of understanding

Article 47(2) allows the Unit to conclude memoranda of understanding regulating cooperation and information exchange with counterpart units and Concerned Authorities, in accordance with legislation in force in the State. Federal Decree-Law No. 10 of 2025, Article 11(3) provides the statutory power.

Egmont Group participation

Article 47(5) requires the Unit to follow the requirements of the Egmont Group and to attend and participate in its meetings as a member. Article 47(4) requires it to follow developments relating to the Crime through relevant regional and international organisations and to participate in related meetings.

Why this matters commercially

Two consequences follow for firms with cross-border exposure. First, a transaction that raises no domestic flag can still attract a suspension order originating from a foreign counterpart’s request under Article 5(1). Second, the effectiveness of the UAE FIU’s international cooperation is directly assessed in FATF mutual evaluations, which is why intelligence capability features so heavily in the UAE’s engagement with the FATF process.

What the UAE FIU Expects from Reporting Entities

The FIU does not supervise you, but its expectations are testable. Everything it receives depends on controls you build and evidence you retain.

The controls that feed the FIU

Federal Decree-Law No. 10 of 2025, Article 19 and Cabinet Resolution No. 134 of 2025, Articles 6 to 15 and 25 set the obligations that generate reportable intelligence in the first place:

  • A documented enterprise-wide risk assessment covering money laundering, terrorist financing, and proliferation financing
  • Customer due diligence, with enhanced measures for higher-risk relationships under Articles 12 and 13, and specific treatment of politically exposed persons under Article 16
  • Ongoing transaction monitoring capable of producing a defensible suspicion
  • Sanctions and name screening
  • Record-keeping under Article 25
  • Beneficial ownership identification under Federal Decree-Law No. 10 of 2025, Article 19(3) and Cabinet Resolution No. 134 of 2025, Articles 37 to 41
  • The relevant framework support sits across our KYC and CDD framework, customer risk assessment, PEP and high-risk customer management, and sanctions screening services.

Readiness checklist

Systems

  • Reporting platform registration active, with current authorised users
  • Monitoring and screening configured to your actual risk profile, not to a vendor default
  • A tested route from alert to escalation to filing

Documentation

  • Customer due diligence files complete and retrievable within an inspection timeframe
  • Internal investigation records showing how a suspicion was formed or discounted
  • A decision trail for reports filed and, importantly, for alerts closed without filing

People

  • A compliance officer or MLRO with the authority to file without commercial sign-off
  • AML training that covers the tipping-off prohibition explicitly
  • A documented escalation path with named alternates

Response readiness

  • A procedure for FIU information requests, with an owner and a timeframe
  • A procedure for suspension and freezing orders, including the diarised expiry date
  • Periodic independent testing through AML internal audit or a broader regulatory inspection readiness review

Mistakes that draw attention

  • Filing late, on the view that internal certainty must precede reporting. The threshold is suspicion, and the requirement is without delay.
  • Defensive over-reporting to create a paper trail. Report quality is assessed and can be referred to your supervisor.
  • Narratives that describe a transaction without stating the grounds for suspicion.
  • Ignoring or partially answering information requests.
  • Stale platforms contact details.
  • No procedure for a freeze order, discovered now one arrives.

Financial Intelligence Units in Other Countries

FIUs exist in every FATF-assessed jurisdiction, but they follow different institutional models. The UAE operates an administrative model FIU hosted by the central bank.

The four models

  • Administrative. Housed within a central bank, ministry, or independent agency, separate from law enforcement. The UAE follows this model.
  • Law enforcement. Located within a police or enforcement body.
  • Judicial or prosecutorial. Attached to the prosecution service.
  • Hybrid. Combining features of the above.

Examples

JurisdictionFIUModel
United Arab EmiratesUAE Financial Intelligence UnitAdministrative, within the Central Bank
United KingdomUK Financial Intelligence UnitLaw enforcement, within the National Crime Agency
United StatesFinancial Crimes Enforcement Network (FinCEN)Administrative, within the Treasury
AustraliaAUSTRACAdministrative, also the AML/CTF regulator
IndiaFIU-INDAdministrative, under the Ministry of Finance

Australia is a useful contrast: AUSTRAC is both the FIU and the supervisor. In the UAE those functions are deliberately separate, which is why the FIU cannot fine you and your supervisor cannot receive your reports.

One clarification on the acronym

Outside financial crime, “FIU” most commonly refers to Florida International University. In an AML context in the UAE, FIU means the Financial Intelligence Unit established under Federal Decree-Law No. 10 of 2025.

Conclusion: Why the FIU Matters to Every Regulated Firm in the UAE

The UAE Financial Intelligence Unit is the destination for every suspicious transaction report filed in the country, and the source of orders that can stop a transaction within your systems the same day, without notice. It cannot fine you. It can, however, tell your supervisor what the quality of your reporting looks like.

That combination is the reason the FIU relationship deserves designed procedures rather than assumed ones. Firms that handle it well share three characteristics: their reports state grounds for suspicion clearly, their information requests are answered inside the Unit’s timeframe, and their freeze procedure existed before they needed it.

FAQs About the UAE FIU 

What is the full form of FIU?

FIU stands for Financial Intelligence Unit. In the UAE it refers to the national body established within the Central Bank under Federal Decree-Law No. 10 of 2025, Article 11, which receives and analyses suspicious transaction reports and disseminates financial intelligence to law enforcement.

In anti-money laundering terms, an FIU is the central national agency that receives suspicious transaction reports from regulated entities, analyses them, and passes intelligence to authorities empowered to investigate. It does not investigate or prosecute, and it does not supervise the entities that report to it.

Federal Decree-Law No. 10 of 2025 (Articles 5, 6, and 11) and Cabinet Resolution No. 134 of 2025 (Articles 44 to 47 and 51). These replaced Federal Decree-Law No. 20 of 2018 and Cabinet Decision No. 10 of 2019, which are repealed.

It is established within the Central Bank but operates independently. Cabinet Resolution No. 134 of 2025, Article 44(2) grants operational independence, including authority over analysis, requests, re-dissemination, and referral of information. The Central Bank provides its resources; it does not direct its analysis.

Financial institutions designated non-financial businesses and professions, and virtual asset service providers. Federal Decree-Law No. 10 of 2025, Article 11 makes the FIU the exclusive recipient of those reports.

No. The trigger is suspicion, regardless of amount, and the obligation extends to attempted transactions. Reports must be filed without delay.

The Chief of the Unit can order the freezing of funds suspected of being related to the Crime for up to thirty days under Federal Decree-Law No. 10 of 2025, Article 5(2), without prior notice, and that period can be extended by the Attorney General or their delegate.

Up to ten working days, under Federal Decree-Law No. 10 of 2025, Article 5(1).

Operational analysis identifies specific persons, funds, or criminal networks and traces links to potential criminal property. Strategic analysis identifies crime trends and patterns across the wider data set. Both are required by Cabinet Resolution No. 134 of 2025, Article 46(3).

The Unit examines and retains the report, prioritises it, analyses it, may request further information, and disseminates intelligence to Law Enforcement Authorities where sufficient grounds exist. You may receive an information request or feedback, but you will generally not be told the outcome.

Insights & Success Stories

Related Industry Trends & Real Results