Anti Money Laundering Laws in UAE: A Complete Guide to the AML/CFT Framework

Quick Summary:

  • Federal Decree-Law No. (10) of 2025 is the principal AML/CFT/CPF statute in the UAE. It repealed Federal Decree-Law No. (20) of 2018 (FDL 10/2025, Art. 41) and entered into force two weeks after publication in the Official Gazette (Art. 42) — reported as 14 October 2025.
  • Cabinet Resolution No. (134) of 2025 is the Executive Regulations. It repealed Cabinet Resolution No. (10) of 2019 (CR 134/2025, Art. 70) and entered into force thirty days after publication (Art. 71) — reported as 14 December 2025.
  • Proliferation financing is now a standalone criminal offence (FDL 10/2025, Art. 3(3)), covering weapons of mass destruction, delivery systems, and dual-use goods and technologies.
  • Scope is wider than most businesses assume: financial institutions, six categories of DNFBPs (now including commercial gaming operators), virtual asset service providers, non-profit organisations, and legal arrangements.
  • Administrative fines run from AED 10,000 to AED 5,000,000 for each violation, escalating to suspension of activity and licence revocation (Art. 17). Legal persons convicted of ML, FT or PF face fines of AED 5,000,000 to AED 100,000,000 (Art. 27(1)).
  • Criminal proceedings for money laundering, terrorist financing and proliferation financing do not lapse by prescription (Art. 37(2)). A compliance failure today remains actionable indefinitely.
  • Free zone registration is not an exemption. The federal framework applies across the UAE. What changes is your supervisor, not your obligation.
  • Records must be retained for not less than five years (CR 134/2025, Art. 25).

If your AML policy still cites the 2018 law or the 2019 Executive Regulations, it is out of date and will not survive an inspection.

What are Anti Money Laundering Laws in the UAE?

Anti money laundering laws in the UAE are the body of federal legislation, executive regulations, cabinet decisions and supervisory guidance that require regulated businesses to detect, prevent and report financial crime. The framework covers three connected offences: money laundering, the financing of terrorism, and the financing of the proliferation of weapons of mass destruction.

The current regime rests on two instruments. Federal Decree-Law No. (10) of 2025 sets out the offences, the powers of the authorities, and the duties of regulated entities. Cabinet Resolution No. (134) of 2025 sets out how those duties are performed in practice. Everything else sector rulebooks, circulars, guidance notes sits on top of those two.

AML, CFT and CPF: what the three acronyms cover

Term What it addresses Governing provision
AML – Anti Money Laundering Concealing or disguising the illicit origin of criminal proceeds FDL 10/2025, Art. 2
CFT – Combating the Financing of Terrorism Providing or collecting funds for terrorist acts, terrorists, or terrorist organisations FDL 10/2025, Art. 3(1)
CPF – Countering Proliferation Financing Funding the manufacture, acquisition, transport, or use of weapons of mass destruction, their delivery systems, and related dual-use goods FDL 10/2025, Art. 3(3)

The third limb is the newest. Under the previous regime, the statutory title referred to the financing of illegal organisations. The 2025 law replaced that framing with proliferation financing, which now stands as an offence.

Is money laundering a criminal offence in the UAE?

Yes. Under Article 2 of Federal Decree-Law No. (10) of 2025, a person commits money laundering where they know, or where there are sufficient indications or evidence to believe, that funds are the proceeds of a predicate offence, and they intentionally convert or transfer those proceeds to disguise their origin, conceal their true nature or source, acquire or use them, or assist the perpetrator in evading punishment.

Two features of the offence matter commercially. First, money laundering is treated as an independent crime the punishment or non-punishment of the person who committed the predicate offence does not prevent conviction for laundering (Art. 2(2)). Second, conviction for the predicate offence is not required to establish that the proceeds were illegitimate, and knowledge may be inferred from the factual and objective circumstances surrounding the act (Art. 2(3)).

That last point is the one boards should absorb. Knowledge can be inferred. Deliberate incuriosity is not a defence.

UAE AML Law 2025: Federal Decree-Law No. (10) of 2025 Explained

Federal Decree-Law No. (10) of 2025 was issued on 30 September 2025 and, under Article 42, entered into force two weeks after its publication in the Official Gazette. It runs to thirteen chapters and forty-two articles.

Article 41 repeals Federal Decree-Law No. (20) of 2018 outright. It also provides a transitional rule that is easy to miss: executive regulations, resolutions and circulars issued under the 2018 law remain effective only insofar as they do not conflict with the new decree-law, and only until superseding instruments are issued (Art. 41(3)). In other words, some of the guidance on your shelf still applies but only where it does not contradict the current statute.

What the AML law 2025 covers

ChapterSubjectWhy it matters to you
OneDefinitions (Art. 1)Defines regulated entity terms, beneficial owner, virtual assets
TwoThe offences (Arts. 2–4)Including criminal liability of the legal person
ThreeProvisional measures and investigation (Arts. 5–9)FIU suspension and freezing powers
FourCross-border disclosure (Art. 10)Currency, bearer instruments, precious metals and stones
FiveThe Financial Intelligence Unit (Art. 11)Your reporting counterparty
SixNational coordination (Arts. 12–15)Supreme Committee, National Committee
SevenSupervisory authorities and administrative penalties (Arts. 16–17)The fine schedule
EightPreventive measures, transparency, beneficial owners (Arts. 18–20)Your core duties
NineInternational cooperation and asset recovery (Arts. 21–22)Cross-border exposure
Ten–ElevenStatistics and confidentiality (Arts. 23–24)Handling of STR information
TwelvePenalties (Arts. 25–37)Criminal exposure
ThirteenFinal provisions (Arts. 38–42)Repeals, entry into force

Chapters Seven, Eight and Twelve are where a compliance officer should start.

The offences in detail

Money laundering (Art. 2). As set out above.

Financing of terrorism (Art. 3(1) – (2)). Intentionally providing, collecting or making available funds by any means, directly or indirectly expressly including through digital systems, virtual assets or cryptographic technologies knowing they will be used for terrorist acts, by a terrorist or terrorist organisation, or to finance travel for terrorist purposes. Funds count whether their source was legitimate or illegitimate, and whether they were used.

Proliferation financing (Art. 3(3)). Providing, collecting or making available funds knowing they will be used for the manufacture, possession, acquisition, development, production, sale, supply, export, trans-shipment, brokerage, transport, transfer, storage or use of weapons of mass destruction, their means of delivery, or related materials including dual-use technologies and goods when employed for those purposes.

That dual-use language is the sleeper clause for the UAE’s trading and re-export economy. A shipment can be entirely lawful in one context and captured in another. Trading companies, freight forwarders, and the banks financing them now need proliferation financing built into risk assessment, screening and monitoring not treated as a theoretical concern for defence contractors.

Criminal liability of the legal person (Art. 4). A legal person is criminally liable where any offence under the decree-law is intentionally committed in its name or for its account, without prejudice to the personal criminal liability of the individual perpetrator and to administrative penalties.

Cabinet Resolution No. (134) of 2025: The Executive Regulations

If the decree-law states the duty, Cabinet Resolution No. (134) of 2025 states the method. Issued on 29 October 2025, it entered into force thirty days after publication in the Official Gazette (Art. 71) and repealed Cabinet Resolution No. (10) of 2019 (Art. 70). It comprises nine chapters and seventy-one articles.

This is the document most UAE businesses have never opened, and it is the one supervisor inspect against.

Article-to-obligation lookup

ObligationArticle in CR 134/2025
Scope of financial institutionsArt. 2
Scope of DNFBPsArt. 3
Virtual asset activitiesArt. 4
Risk assessment, risk-based approach, EDD and SDDArt. 5
Timing of identity verificationArt. 6
When CDD applies (including thresholds)Art. 7
Ongoing monitoring of the relationshipArt. 8
Customer identification requirementsArt. 9
Beneficial owner identificationArt. 10
Listed-company customersArt. 11
Life insurance beneficiariesArt. 12
Existing customersArt. 13
Inability to complete CDDArt. 14
Shell banks and anonymous accountsArt. 15
Politically exposed personsArt. 16
STR indicatorsArt. 17
STR submissionArt. 18
Tipping-off prohibitionArt. 19
Third-party relianceArt. 20
Internal policies, controls and proceduresArt. 21
Compliance Officer dutiesArt. 22
High-risk countries and countermeasuresArt. 23
New technologiesArt. 24
Record-keepingArt. 25
Correspondent bankingArt. 26
Money or value transfer servicesArt. 27
Wire transfersArts. 28–31
Financial groups, branches and subsidiariesArts. 32–33
Non-profit organisationsArt. 34
VASP supervision and obligationsArts. 35–36
Beneficial ownership, registrars, companies, nomineesArts. 37–41
No secrecy defenceArt. 42

From FDL 20/2018 to FDL 10/2025: What Actually Changed

If you searched for “Federal Decree-Law No. 20 of 2018” and landed here, this section is for you. That law is repealed. So is Cabinet Resolution No. (10) of 2019. Any policy, training deck or client-facing document still citing them is citing a framework that no longer exists.

TopicPrevious frameworkCurrent framework
Principal statuteFederal Decree-Law No. (20) of 2018 (repealed)Federal Decree-Law No. (10) of 2025
Executive RegulationsCabinet Resolution No. (10) of 2019 (repealed)Cabinet Resolution No. (134) of 2025
Third offence limbFinancing of illegal organisationsProliferation financing (Art. 3(3))
Virtual assetsAddressed indirectlyExpress offences and a standalone regulated category (Arts. 19–20, 30)
Non-profit organisationsPeripheralExpress obligations (CR 134/2025, Art. 34)
Legal arrangements and nomineesLimitedDetailed duties (CR 134/2025, Arts. 39–41)
Freeze powersGovernor-levelChief of the FIU: 10 working days suspension, 30 days freezing (Art. 5)
Reporting authority nameFinancial Information UnitFinancial Intelligence Unit
PrescriptionGeneral rulesNo lapse by prescription for ML, FT and PF (Art. 37(2))
Commercial gamingOutside the perimeterDNFBP category (CR 134/2025, Art. 3(1))

What your existing AML documentation needs

If your framework was written before October 2025, expect to update at least the following:

  • Every legal reference and citation throughout the policy suite
  • The offences section, to add proliferation financing as a standalone offence
  • Risk assessment methodology, to include PF risk factors and dual-use goods exposure
  • Virtual asset provisions, where relevant to your customer base or products
  • Beneficial ownership procedures, including nominee disclosure and the fifteen-working-day update rule
  • The penalty schedule used in training material and staff awareness content
  • Sanctions and TFS procedures, and the escalation path attached to them

This is not a find-and-replace exercise. Several figures and timelines changed, and carrying a 2018-era number into a 2026 document is worse than having no number at all.

Who Must Comply with AML Law in the UAE?

The obligations in Article 19 of the decree-law apply to financial institutions, designated non-financial businesses and professions, and virtual asset service providers. The Executive Regulations define each population and add duties for non-profit organisations and legal arrangements.

Financial institutions

Under Article 2 of CR 134/2025, a financial institution is any person carrying out one or more of fourteen listed financial activities as a commercial activity, including: accepting deposits; lending and trade finance; financial leasing (excluding consumer-product leasing); money or value transfer services; issuing and managing means of payment; financial guarantees and commitments; trading in financial market instruments, foreign exchange and commodity futures; participating in securities issuance; fund and portfolio management; safekeeping and administration of cash or liquid securities; investing or managing funds for others; life and investment-linked insurance including through agents and brokers; and currency exchange.

Designated Non-Financial Businesses and Professions (DNFBPs)

Article 3 of CR 134/2025 sets out six DNFBP categories, several with express monetary thresholds:

  1. Commercial gaming operators, including gaming conducted on board vessels or marine craft, where a single financial transaction or several linked transactions equal or exceed AED 11,000. Transactions solely involving gaming chips or instruments are excluded.
  2. Real estate brokers and agents, when concluding transactions or settlements on behalf of customers relating to the purchase or sale of real estate.
  3. Dealers in valuable metals and precious stones, on any single cash transaction or several linked transactions equal to or exceeding AED 55,000.
  4. Lawyers, notaries, other independent legal professionals and independent accountants, when preparing, conducting or executing financial transactions for clients relating to buying and selling real estate; managing client funds; managing bank, savings or securities accounts; organising contributions for the establishment, operation or management of companies; and establishing, operating or managing legal persons or legal arrangements, or selling or purchasing commercial entities.
  5. Company and trust service providers, when acting as incorporation agent, director, secretary or partner; providing a registered office or correspondence address; acting as trustee of an express trust; or acting as a nominee shareholder.
  6. Any other business or profession determined by resolution of the supervisory authority in coordination with the National Committee.

Virtual Asset Service Providers

Article 4 of CR 134/2025 lists five virtual asset activities: exchange between virtual assets and fiat currencies; exchange between types of virtual assets; transfer of virtual assets; safekeeping or administration of virtual assets or instruments enabling control over them; and provision of financial services related to an issuer’s offer or sale of virtual assets.

VASPs sit as their own category rather than as a DNFBP subset, and they carry the lowest CDD threshold in the regime — AED 3,500 for occasional transactions (Art. 7(3)).

Non-profit organisations

Article 34 of CR 134/2025 requires NPOs, in coordination with their supervisory authority, to apply focused, proportionate and risk-based measures; adopt approved best practices to protect against misuse for terrorist financing; establish clear policies on accountability, transparency and integrity; and conduct transactions through regulated financial channels wherever possible. These obligations extend to persons acting on behalf of, or for the benefit of, the NPO.

Do AML laws apply to free zone companies in the UAE?

Yes. The federal framework applies across the UAE. Free zone registration determines which authority supervises you and which rulebook applies in addition to federal law — it does not remove you from the regime. Entities in DIFC and ADGM are subject to their financial services regulator’s AML rulebook and to the federal decree-law and its Executive Regulations.

AML/CFT Supervisory Authorities in the UAE

Article 16 of FDL 10/2025 gives supervisory authorities the duties of supervision, monitoring and follow-up, including conducting sectoral risk assessments, performing desk-based and field-based inspections, and maintaining statistics on measures taken and penalties imposed.

The current allocation of supervisory responsibility is broadly as follows. Confirm your own position with your licensing authority, as allocations are periodically adjusted.

Supervised populationSupervisory authorityJurisdiction
Financial institutionsCentral Bank of the UAE (CBUAE)UAE excluding financial free zones
TCSPs, DPMS, auditors and accountants, real estate brokers and agentsMinistry of Economy and Tourism (MoET)UAE excluding financial free zones
Lawyers, notaries, legal consultantsMinistry of Justice (MoJ)UAE excluding financial free zones
Capital markets participantsSecurities and Commodities Authority / Capital Market AuthorityUAE excluding DIFC and ADGM
Virtual asset service providersCapital Market Authority (outside Dubai); VARA (Dubai, excluding DIFC)As indicated
Commercial gaming operatorsGeneral Commercial Gaming Regulatory Authority (GCGRA)UAE excluding financial free zones
All regulated entities in DIFCDubai Financial Services Authority (DFSA)DIFC
All regulated entities in ADGMFinancial Services Regulatory Authority (FSRA)ADGM

The Financial Intelligence Unit

Article 11 establishes an independent Financial Intelligence Unit within the Central Bank. All suspicious transaction reports go to the Unit, regardless of your sector or where in the UAE you operate.

The Unit’s powers are worth understanding before you encounter them. Under Article 5, the Chief of the Unit may, without prior notice, order the cessation or temporary suspension of any transaction suspected of being related to the crime for a period not exceeding ten working days, and may order the freezing of suspect funds held with financial institutions, DNFBPs or VASPs for a period not exceeding thirty days, extendable by the Attorney General or their delegate. Regulated entities must lift a freeze when the order is cancelled or the period expires, unless extended.

The Executive Office and targeted financial sanctions

Article 19(1)(e) requires regulated entities to implement forthwith the instructions issued by the Executive Office or other competent authorities concerning targeted financial sanctions. Article 33 attaches a criminal penalty to breaching those instructions.

Core AML Compliance Obligations Under UAE AML Regulations

Article 19(1) of FDL 10/2025 sets out the core duties. CR 134/2025 turns them into operational requirements. Together they produce the following programme.

1. Enterprise-wide risk assessment

Identify, understand, manage and assess your crime risks proportionately to the nature and size of your business, taking account of the risk-based approach and the results of the National Risk Assessment (CR 134/2025, Art. 5(1)). Consider customer risk, country and geographic risk, product, service, transaction and delivery-channel risk before determining overall risk. Document the process, retain the study, keep it updated, and produce it to the authorities on request.

Where high proliferation financing risks are identified, Article 5(4) requires proportionate measures including enhanced internal controls, documented records of measures taken, and periodic review of controls as risk levels change.

2. Customer due diligence

Verify the identity of the customer and the beneficial owner before or during the establishment of a business relationship or the opening of an account, or before carrying out a transaction for a customer with whom no relationship exists (Art. 6(1)). In low-risk cases, verification may be deferred, subject to completion as soon as possible, necessity so as not to disrupt normal business, and appropriate risk controls (Art. 6(2)).

CDD applies on commencement of a business relationship, where there is suspicion of a crime, and where there are doubts about the accuracy or adequacy of previously obtained identification data (Art. 7(1)). Financial institutions must additionally apply CDD to occasional transactions of AED 55,000 or more, and to occasional wire transfers of AED 3,500 or more (Art. 7(2)). VASPs apply CDD to occasional transactions of AED 3,500 or more (Art. 7(3)).

For natural persons, obtain the name as stated on the identity card or travel document, nationality, address, date and place of birth, employer details where applicable, and a true copy of a valid ID or travel document. For legal persons and legal arrangements, obtain name, legal form, memorandum of association, corporate tax registration number where subject to corporate tax, unique reference number if any, registered address, articles of association, and the names of senior management (Art. 9(1)).

3. Beneficial ownership identification

For legal persons, identify the natural person who ultimately owns, individually or jointly, an actual controlling ownership interest or shares of 25% or more. Where that person cannot be identified, or where doubt exists, identify the natural person exercising legal or actual control by any other means. Where no such person is identified, identify the relevant natural person holding a senior management position (Art. 10(1)).

For legal arrangements, identify the trustee, settlor, trust protector, and beneficiaries or classes of beneficiaries, along with any other natural person exercising ultimate effective control (Art. 10(2)).

4. Enhanced and simplified due diligence

Enhanced due diligence measures under Article 5(2)(c) include obtaining and verifying additional identity, occupation and beneficial owner information; obtaining additional information on the purpose of the relationship; updating CDD information more regularly; taking reasonable measures to identify source of funds and wealth; increasing the degree of ongoing monitoring; routing the first payment through an account in the customer’s name at an institution subject to equivalent standards; and obtaining senior management approval to commence or continue the relationship.

Simplified due diligence is available where low risks are identified, in coordination with the supervisory authority, and unless there is suspicion of a crime (Art. 5(3)). It must remain proportionate to the low-risk elements and must not compromise full implementation of targeted financial sanctions instructions.

5. Politically exposed persons

For foreign PEPs: establish appropriate risk management systems to determine PEP status; obtain senior management approval before establishing or continuing the relationship; take reasonable measures to identify source of funds and wealth; and conduct enhanced ongoing monitoring (Art. 16(1)(a)). For domestic PEPs and persons entrusted with a prominent function in an international organisation, take adequate measures to determine status, and apply the same enhanced measures where a high-risk relationship exists (Art. 16(1)(b)).

6. Ongoing monitoring

Scrutinise transactions throughout the relationship to ensure consistency with what you know about the customer, their activities and their risk profile, including source of funds where necessary; and keep CDD documents, data and information current through record review, with particular emphasis on high-risk customer categories (Art. 8).

Where CDD cannot be applied, you are prohibited from establishing or continuing the relationship or executing the transaction and must consider filing a suspicious transaction report (Art. 14(1)).

7. Screening against sanctions and high-risk jurisdictions

Apply enhanced due diligence proportionate to risk for relationships and transactions involving persons from countries identified by the National Committee as high-risk, or from countries with AML/CFT/CPF deficiencies, and apply any countermeasures required (Art. 23).

8. Internal policies, controls and procedures

Article 21 requires internal policies, controls and procedures approved by senior management, proportionate to identified risks and to the nature and size of activities, reviewed and updated on an ongoing basis, and covering: CDD measures including risk management before verification is complete; STR reporting procedures; compliance management arrangements including appointment of a Compliance Officer at management level; employee fitness and propriety screening; periodic training programmes and workshops; and an independent audit function to test the effectiveness and adequacy of the controls.

That last requirement is the one most often missing. Designing a control is not evidence that it works.

9. The Compliance Officer

Article 22 requires appointment of a Compliance Officer at management level, with independence in decision-making and appropriate competence and experience. Duties include monitoring transactions related to the crime; reviewing records and assessing suspicious transaction data and deciding whether to notify the Unit or retain the matter with reasons stated, in full confidentiality; reviewing internal systems and procedures against the decree-law and the Resolution and reporting periodically to senior management; developing and documenting training programmes; and cooperating with the supervisory authority and the Unit.

10. Record-keeping

Retain all records, documents, instruments and data relating to domestic and international financial and cash transactions and commercial dealings for not less than five years from completion of the transaction or termination of the business relationship (Art. 25(1)).

Separately, retain CDD and ongoing monitoring records, account files, business correspondence, copies of identification documents, suspicious transaction reports, analysis results, and CCTV and ATM recordings for not less than five years calculated from the most recent of: termination of the relationship, account closure, completion of an occasional transaction, completion of a supervisory inspection, completion of an investigation, or issuance of a final court judgment (Art. 25(2)).

Records must be organised so that individual transactions can be reconstructed and financial flows traced, sufficient to provide evidence for prosecution where necessary (Art. 25(3)).

11. Training

Article 21(5) requires periodic anti-crime programmes and workshops to build capacity among those in the compliance function and other relevant employees. Article 22(4) makes developing, implementing and documenting those programmes a Compliance Officer duty. Undocumented training is, for inspection purposes, training that did not happen.

12. New technologies

Identify and assess ML, FT and PF risks arising from new products, new business practices, new delivery mechanisms and new or developing technologies for both new and pre-existing products before launch or use and take appropriate measures to manage and mitigate them (Art. 24).

Targeted Financial Sanctions Obligations

Targeted financial sanctions form a distinct legal stream, and supervisors inspect them as such.

The statutory duty sits in Article 19(1)(e) of FDL 10/2025: regulated entities must implement forthwith the instructions issued by the Executive Office or other competent authorities concerning targeted financial sanctions. The operational framework sits in Cabinet Resolution No. (74) of 2020, which regulates terrorist lists and the implementation of UN Security Council resolutions on terrorism, terrorist financing and the proliferation of weapons of mass destruction. Guidance issued by the Executive Office for Control and Non-Proliferation supplements this and should always be described as guidance rather than as law.

In practice, a functioning TFS programme requires:

  • Subscription to the Executive Office’s notification alert system, so designations reach you promptly
  • Screening customers, beneficial owners and counterparties against the Local Terrorist List and the UNSC consolidated list, at onboarding and on an ongoing basis
  • Re-screening the customer base whenever lists are updated, not only at onboarding
  • Freezing without delay upon a confirmed match, with a documented escalation path
  • Reporting the match through goAML
  • Retaining screening logs, match assessments and false-positive dispositions as evidence

Article 33 provides that any person who violates targeted financial sanctions instructions shall be punished with imprisonment and a fine of not less than AED 20,000, or by either penalty.

Suspicious Transaction Reporting and goAML

The obligation

Article 18(1) of FDL 10/2025 requires financial institutions, DNFBPs and VASPs that suspect, or have reasonable grounds to suspect, that a transaction or funds represent proceeds or are related to or intended for use in the crime regardless of their value to notify the Unit without delay and directly, providing a detailed report through the electronic system designated by the Unit, and to furnish any additional information requested, without invoking confidentiality provisions.

There is no minimum reporting threshold. Suspicion is the trigger, not the amount.

Article 18 of CR 134/2025 restates the duty and adds that banking secrecy, professional secrecy and contractual liability cannot be invoked, and that entities must promptly respond to any request from the Unit for additional information. Article 17 requires entities to establish and continuously update indicators enabling them to identify suspicion, in line with instructions issued by the supervisory authority.

The legal professional exemption

Lawyers, notaries, other independent legal professionals and independent statutory auditors are exempt where the information was obtained in the course of assessing a client’s legal position, defending or representing the client before courts or in arbitration or mediation, or providing a legal opinion relating to judicial proceedings whether before, during or after those proceedings or in other circumstances subject to professional secrecy (CR 134/2025, Art. 18(2); FDL 10/2025, Art. 18(2)).

The exemption is narrower than it is often assumed to be. It attaches to the circumstances in which information was obtained, not to the profession.

Tipping-off

Article 19(1) of CR 134/2025 prohibits regulated entities and their directors, officers and employees from disclosing, directly or indirectly, to the customer or any other person, that a suspicious transaction report has been or is about to be submitted, or any related information, or that an investigation is being conducted subject to permitted information sharing within a financial group under Article 32.

Attempts by lawyers, notaries, other independent legal professionals or independent statutory auditors to dissuade a client from committing an unlawful act do not constitute disclosure (Art. 19(2)).

Protection for those who report

Article 37(1) of FDL 10/2025 provides that no criminal, civil or administrative liability is incurred by supervisory authorities, the Unit, law enforcement authorities, financial institutions, DNFBPs, VASPs, or their board members, employees and authorised representatives, as a result of furnishing required information or breaching a confidentiality restriction even where they were not fully aware of the nature or actual occurrence of the crime unless the reporting was made in bad faith with intent to harm others.

Beneficial Ownership and Transparency Requirements

Beneficial ownership is a standing weakness in most compliance frameworks and a specific focus of international assessment.

Under Article 38 of CR 134/2025, companies must obtain and retain basic information and up-to-date information on nominee directors and nominee shareholders, and update it within fifteen working days of any amendment or change, verifying accuracy on an ongoing basis. They must maintain a partners’ or shareholders’ register including share numbers, classes and attached voting rights, held within the State at the company’s office, registered place of business, or another location notified to the Registrar. They must retain beneficial owner information and likewise update it within fifteen working days.

Companies must cooperate with financial institutions, DNFBPs and VASPs in providing adequate, accurate and up-to-date beneficial owner information, and cooperate with the competent authorities without delay (Art. 38(2)–(3)).

Bearer shares are prohibited. No company established and registered in the State may issue bearer shares, bearer share warrants or similar untraceable instruments; those issued before the Resolution entered into force were required to be converted into registered shares within thirty working days from the date of publication (Art. 38(4)).

Nominee directors and nominee shareholders must notify the company of their capacity, disclose information on their status and the identity of the person they represent, and notify any change within fifteen working days (Art. 39).

Providing false or misleading beneficial owner information to a competent authority, or to a financial institution, DNFBP or VASP, is punishable by imprisonment and a fine of not less than AED 20,000, or either penalty (FDL 10/2025, Art. 35(1)).

Penalties for Violating Anti Money Laundering Laws in the UAE

Published figures on this topic vary widely, and several circulating figures are wrong. The following are taken directly from the current statute.

Administrative penalties (FDL 10/2025, Art. 17)

Without prejudice to more severe sanctions under other legislation, a supervisory authority may impose:

Measure TypeDetails
Warning
Administrative FineNot less than AED 10,000 and not exceeding AED 5,000,000 for each violation.
Sector ProhibitionProhibiting the violator from engaging in the relevant sector for a determined period.
Restriction of PowersRestricting the powers of board members, executive, supervisory or managerial personnel, or responsible owners, including the appointment of a temporary supervisor.
Suspension of IndividualsSuspending or requiring replacement of directors, board members, executive or supervisory personnel proven responsible.
Suspension of ActivitySuspending or restricting the activity or profession for a determined period.
Licence Revocation

The supervisory authority may also require periodic reports on remediation (Art. 17(2)), impose an incremental fine where the same violation recurs within one year of a prior fine (Art. 17(3)), and publish the penalties imposed through media outlets (Art. 17(4)).

That publication power is the one that changes the commercial calculus. The financial penalty is finite. The reputational consequence is not.

Criminal penalties

OffenceFull PenaltyArticle
Money launderingImprisonment for 1 to 10 years and a fine of AED 100,000 to AED 5,000,000, or an amount equal to the value of the criminal property, whichever is greater.Art. 26(1)
Aggravated money laundering (abuse of position or professional activity; through a non-profit organisation (NPO); through an organised criminal group; involving specified predicate offences; or recidivism)Temporary imprisonment and a fine of AED 1,000,000 to AED 10,000,000, or twice the value of the criminal property, whichever is greater.Art. 26(2)
Financing of terrorismLife imprisonment or temporary imprisonment of not less than 10 years, and a fine of AED 1,000,000 to AED 10,000,000, or twice the value of the criminal property, whichever is greater.Art. 26(3)
Proliferation financingTemporary imprisonment and a fine of AED 1,000,000 to AED 10,000,000, or twice the value of the criminal property, whichever is greater.Art. 26(4)
Legal person involved in Money Laundering (ML), Financing of Terrorism (FT), or Proliferation Financing (PF)Fine of AED 5,000,000 to AED 100,000,000, or an amount equal to the value of the criminal property, whichever is greater.Art. 27(1)
Legal person committing other offences under Articles 28, 29, 30, 32, 33, and 35Fine of AED 200,000 to AED 10,000,000.Art. 27(2)
Failure to report a suspicious transaction (deliberately or through gross negligence)Imprisonment and a fine of AED 100,000 to AED 1,000,000, or either penalty.Art. 28
Tipping-offImprisonment and a fine of not less than AED 50,000, or either penalty.Art. 29(1)
Breach of asset-management duties or breach of a seizure/freezing orderImprisonment and a fine of not less than AED 50,000, or either penalty.Art. 29(2)
Possessing or concealing funds where there are indications of an illegitimate source or concealed beneficial ownerImprisonment of not less than 3 months and a fine of not less than AED 50,000, or either penalty.Art. 30(1)
Dealing in virtual assets characterised by total anonymity, or using unlicensed accounts or technologies that obstruct tracingImprisonment of not less than 3 months and a fine of not less than AED 50,000, or either penalty.Art. 30(2)
Carrying on a regulated activity without the required licence, registration, or enrolmentImprisonment and a fine of AED 200,000 to AED 10,000,000, or either penalty.Arts. 20 & 32
Violating targeted financial sanctions instructionsImprisonment and a fine of not less than AED 20,000, or either penalty.Art. 33
Breaching the cross-border disclosure duty, concealing information, or providing false informationImprisonment and a fine, or either penalty; confiscation may also be ordered.Arts. 10 & 34
Providing false or misleading beneficial owner informationImprisonment and a fine of not less than AED 20,000, or either penalty.Art. 35(1)
Breaching core obligations under Article 19Imprisonment and a fine of not less than AED 10,000, or either penalty.Art. 35(3)

Additional consequences: on conviction of a legal person for financing of terrorism or proliferation financing, the court shall order dissolution and closure of the premises (Art. 27(3)); on conviction for money laundering, it may do so (Art. 27(4)). The person responsible for actual management may be personally imprisoned and fined where they were aware of the offence and it resulted from breach of their duties (Art. 27(5)). Confiscation follows conviction (Art. 31), and deportation is mandatory for foreigners given a custodial sentence for money laundering or a felony under the decree-law (Art. 36).

No limitation period

Article 37(2) provides that criminal proceedings for money laundering, financing of terrorism and proliferation financing do not lapse by prescription, that imposed penalties do not extinguish by lapse of time, and that connected civil actions likewise do not prescribe.

The practical consequence deserves stating plainly. A control failure in 2026 is still actionable in 2036 or later — particularly where new evidence surfaces through cross-border cooperation or whistleblowing. Remediation is not something that becomes unnecessary with time.

AML Laws in Dubai, Abu Dhabi and the Free Zones

Is there a separate AML law for Dubai?

No. There is no distinct Dubai anti money laundering law. Federal Decree-Law No. (10) of 2025 and Cabinet Resolution No. (134) of 2025 apply across the United Arab Emirates. What varies by emirate and by zone is which authority supervises you and which additional rulebook applies.

Mainland and commercial free zones

Federal law applies in full. Supervision is exercised by the CBUAE, MoET, MoJ, the Capital Market Authority or the GCGRA depending on your activity.

DIFC

The Dubai Financial Services Authority is the licensing and AML supervisory authority for entities operating in or from DIFC, whether they conduct financial activities, DNFBP activities or virtual asset activities. The DFSA’s AML, CTF and Sanctions Module applies in addition to federal law, and its DNFBP definition is broader than the federal one capturing, among others, real estate developers, dealers in precious metals or stones at a USD 15,000 threshold, and persons issuing or providing services relating to certain tokens.

ADGM

The Financial Services Regulatory Authority supervises entities in or from ADGM. The ADGM Anti Money Laundering and Sanctions Rulebook applies alongside federal law, and the ADGM DNFBP definition is likewise wider than the federal one extending, for example, to dealers in any saleable item priced at USD 15,000 or more.

Dubai virtual assets

The Virtual Assets Regulatory Authority supervises VASPs licensed and operating in or from Dubai, excluding DIFC. VARA’s Compliance and Risk Management Rulebook applies in addition to the federal framework.

The point to take away

Additional rulebooks add obligations. They do not replace federal law. A firm regulated in DIFC or ADGM must satisfy both, and the more demanding requirement governs.

How to Comply with UAE AML Laws: A Practical Sequence

  1. Confirm scope. Determine whether your activity falls within Article 2, 3 or 4 of CR 134/2025, and identify your supervisory authority. Document the conclusion, including where you conclude you are out of scope.
  2. Register on goAML. Registration with the Financial Intelligence Unit’s platform is the gateway to reporting. Carrying on a regulated activity without required licence, registration or enrolment carries criminal exposure under Articles 20 and 32.
  3. Appoint a Compliance Officer. At management level, with independence in decision-making and appropriate competence and experience (Art. 22).
  4. Conduct the enterprise-wide risk assessment. Aligned to the National Risk Assessment and sectoral assessments, covering customer, geographic, product, service, transaction and delivery-channel risk, with proliferation financing addressed explicitly (Art. 5).
  5. Document the policy suite. Approved by senior management, proportionate to your risks and size, covering every element of Article 21.
  6. Build the operating controls. CDD and EDD workflows, beneficial ownership capture, PEP identification, sanctions and name screening, transaction monitoring, and escalation paths.
  7. Select tooling that matches your risk profile. Screening and monitoring systems should be tested and validated, not merely purchased. See: AML Software Selection
  8. Train the team, and record it. Role-based, periodic, documented.
  9. Report. STRs without delay and regardless of value; sanctions matches through goAML; sector-specific reports where applicable.
  10. Test and remediate. Independent audit of effectiveness and adequacy, with findings tracked to closure (Art. 21(6)).

Common AML Compliance Mistakes UAE Businesses Make

Assuming free zone registration is an exemption. It is not. It determines your supervisor.

Treating goAML registration as the whole of compliance. Registration is step two of ten, not the destination.

Running a policy that cites repealed law. If your document references Federal Decree-Law No. 20 of 2018 or Cabinet Resolution No. 10 of 2019, it is describing a framework that no longer exists.

A risk assessment disconnected from the National Risk Assessment. Article 5(1) requires the NRA results to be taken into account. An assessment that does not reference them is incomplete on its face.

No proliferation financing coverage. PF is a standalone offence with its own risk-mitigation requirements under Article 5(4). Most pre-2025 frameworks do not address it at all.

Screening once, at onboarding. Lists change. Article 8 requires ongoing monitoring, and TFS obligations require action on designation, not on next review.

Under-reporting suspicion. There is not de minimis threshold. Article 37(1) protects good-faith reporting; Article 28 penalises failure to report.

Untested transaction monitoring. Article 21(6) requires an independent audit function that tests effectiveness and adequacy. Rules that have never been tuned or validated are a finding waiting to happen.

Controls that exist but cannot be evidenced. If the decision was not recorded, the escalation was not logged, and the training was not documented, none of it exists for inspection purposes.

FATF, National Risk Assessment and the Current Supervisory Climate

The UAE was placed under increased monitoring by the Financial Action Task Force in March 2022 and removed from the list on 23 February 2024 following substantial reform. The country’s next mutual evaluation falls under the FATF’s 5th Round methodology, with the assessment cycle running through 2026 and the onsite assessment reported for mid-2026.

The methodological shift matters more than the calendar. The 5th Round places materially greater weight on effectiveness measured against eleven Immediate Outcomes than on technical compliance measured against the 40 Recommendations. A jurisdiction can have excellent legislation and still assess poorly if that legislation is not producing outcomes.

For individual businesses, this translates into a single practical consequence: supervisors must be able to demonstrate that their supervision works, and they do that using the entities they supervise. Any regulated firm can become a sample case. What assessors and supervisors look for is evidence documented risk assessments, complete CDD files with screening records, quality suspicious transaction reports with reasoning, board minutes and policy approvals, training logs, escalation records, and remediation tracked to closure.

Alongside this, the UAE’s National Risk Assessment and sectoral risk assessments are not background reading. Article 5 of CR 134/2025 requires their results to inform your own risk assessment and mitigation measures directly.

Staying Current with UAE AML Updates

Sources worth monitoring directly rather than through secondary commentary:

  • The UAE Legislation portal, for the primary instruments
  • The CBUAE Rulebook and guidance for licensed financial institutions
  • Ministry of Economy and Tourism circulars for DNFBPs
  • Ministry of Justice circulars and resolutions for legal professionals
  • Executive Office for Control and Non-Proliferation notices and TFS guidance
  • National Committee decisions on high-risk jurisdictions
  • Financial Intelligence Unit strategic analysis reports and typology publications
  • VARA, DFSA and FSRA rulebooks and notices for zone-regulated entities

Article 21 requires policies to be reviewed and updated on an ongoing basis. In practice, the triggers are a change to the National Risk Assessment; an update to high-risk country lists; a new circular from your supervisor; a change in your customer base, products or delivery channels; and any material finding from audit or inspection.

How GRC Advisors Supports AML Compliance in the UAE

We work with regulated entities across ADGM, DIFC, VARA, CMA and the UAE Mainland, building AML frameworks that hold up when they are tested rather than when they are described.

Through our AML/CFT Compliance practice we conduct ML/TF/PF Risk Assessments aligned to the National Risk Assessment, draft AML Policies and Procedures that meet Federal Decree-Law No. (10) of 2025 and its Executive Regulations, and design the controls beneath them KYC and CDD Framework, Customer Risk Assessment, PEP and High-Risk Customer Management, Sanctions Screening, and STR and goAML Reporting.

We also deliver role-based AML Training, independent AML Internal Audit, and Regulatory Inspection Readiness support. If your framework predates October 2025, the sensible starting point is a gap review against the current instruments.

Frequently Asked Questions

What is the AML law in the UAE?

The principal statute is Federal Decree-Law No. (10) of 2025 on Anti Money Laundering and Combating the Financing of Terrorism and Proliferation Financing. Its Executive Regulations are Cabinet Resolution No. (134) of 2025, which sets out how the statutory duties are performed in practice.

Federal Decree-Law No. (10) of 2025. Article 41 repeals the 2018 law. Cabinet Resolution No. (134) of 2025 repealed Cabinet Resolution No. (10) of 2019 under its Article 70.

Financial institutions, the six DNFBP categories under Article 3 of CR 134/2025, virtual asset service providers, non-profit organisations, and parties to legal arrangements including trustees and nominees.

Yes. The federal framework applies UAE-wide. Free zone status determines which authority supervises you and which additional rulebook applies; it does not create an exemption.

No. Federal law applies. VARA regulates virtual asset service providers in Dubai outside DIFC, and the DFSA regulates entities in DIFC, each with rulebooks that supplement federal requirements.

No. Criminal proceedings for money laundering, terrorist financing and proliferation financing do not lapse by prescription, and imposed penalties do not extinguish by lapse of time (Art. 37(2)).

Not less than five years, calculated from completion of the transaction or termination of the business relationship, and for CDD-related records from the most recent of relationship termination, account closure, occasional transaction completion, inspection completion, investigation completion, or final judgment (CR 134/2025, Art. 25).

Twenty-five per cent. Identify the natural person who ultimately owns, individually or jointly, a controlling ownership interest or shares of 25% or more; failing that, the person exercising control by other means; failing that, the relevant senior manager (CR 134/2025, Art. 10(1)).

Yes. Virtual asset service providers are a distinct regulated category under Article 4 of CR 134/2025, with a CDD threshold of AED 3,500 for occasional transactions, and Article 30(2) of the decree-law creates a standalone offence for dealing in anonymity-enabling virtual assets or technologies that obstruct tracing.

Both. The zone rulebook supplements federal law rather than replacing it, and where the two differ the more demanding requirement should be applied.

Yes. The Chief of the Unit may order cessation or suspension of a suspect transaction for up to ten working days and freezing of suspect funds for up to thirty days, extendable by the Attorney General or their delegate (FDL 10/2025, Art. 5).

Yes. Article 22 of CR 134/2025 requires a Compliance Officer at management level with independence in decision-making and appropriate competence and experience.

Insights & Success Stories

Related Industry Trends & Real Results