Trackers
Trackers

AML & KYC in UAE: 2026 Update

AML & KYC in UAE is one of the most actively evolving compliance areas in the region. The UAE has built a comprehensive anti-money laundering and know-your-customer framework that applies to banks, financial institutions, designated non-financial businesses and professions, and virtual asset service providers. Businesses operating in the UAE face real legal and reputational risk if they fall short of these requirements. This guide covers the current legal framework, the competent authorities, customer due diligence obligations, recent regulatory updates, sector-specific rules, penalties, and practical steps for compliance.

The legal framework governing AML & KYC in UAE

The UAE';s anti-money laundering regime rests on several interlocking pieces of legislation. The primary statute is Federal Decree-Law No. 20 of 2018 on Anti-Money Laundering and Combating the Financing of Terrorism and Illegal Organisations, commonly referred to as the AML-CFT Law. This law defines money laundering offences, sets out the obligations of reporting entities, and establishes the criminal penalties for violations.

Cabinet Decision No. 10 of 2019 issued the implementing regulations to the AML-CFT Law. These regulations specify the detailed customer due diligence procedures, beneficial ownership requirements, record-keeping standards, and the categories of designated non-financial businesses and professions (DNFBPs) that must comply. Cabinet Decision No. 58 of 2020 further extended and clarified the scope of obligations for DNFBPs, including real estate agents, dealers in precious metals and stones, lawyers, accountants, and company service providers.

The UAE';s AML framework is also shaped by its membership in the Financial Action Task Force (FATF). Following a mutual evaluation and a period on the FATF grey list, the UAE undertook significant legislative and institutional reforms. The country was removed from the FATF grey list in recent years, reflecting the scale of those reforms. Compliance with FATF Recommendations remains the benchmark against which the UAE';s framework is measured, and regulators continue to update rules to maintain that standard.

Federal Law No. 7 of 2014 on Combating Terrorism Offences and its amendments complement the AML-CFT Law by addressing terrorist financing. Together, these statutes form the backbone of the UAE';s financial crime prevention architecture.

Competent authorities and their roles

Several authorities share responsibility for AML & KYC supervision in the UAE, and understanding their respective mandates is essential for any business operating in the country.

The Financial Intelligence Unit (FIU), known as the UAE FIU or "Ain", is the national centre for receiving, analysing, and disseminating suspicious transaction reports (STRs) and suspicious activity reports (SARs). All reporting entities are legally required to file STRs with the FIU through the goAML platform. The FIU operates under the Central Bank of the UAE and coordinates with international counterparts.

The Central Bank of the UAE (CBUAE) supervises banks, exchange houses, finance companies, insurance companies, and other licensed financial institutions. The CBUAE issues its own AML/CFT guidelines and conducts on-site and off-site examinations. Its Supervisory Guidance on AML/CFT sets detailed expectations for risk-based compliance programmes.

The Securities and Commodities Authority (SCA) oversees investment firms, brokers, and capital market participants. The Dubai Financial Services Authority (DFSA) regulates entities in the Dubai International Financial Centre (DIFC), while the Financial Services Regulatory Authority (FSRA) covers the Abu Dhabi Global Market (ADGM). Both free zone regulators have their own AML rulebooks that largely mirror FATF standards but contain jurisdiction-specific requirements.

The Ministry of Economy supervises DNFBPs at the federal level and has been particularly active in recent enforcement cycles. The Virtual Assets Regulatory Authority (VARA) in Dubai and the relevant ADGM and DIFC frameworks govern virtual asset service providers (VASPs), a sector subject to increasingly detailed AML/KYC rules.

Customer due diligence: what KYC requires in practice

Know-your-customer (KYC) obligations in the UAE follow a risk-based approach. Reporting entities must identify and verify the identity of customers, understand the nature and purpose of the business relationship, and conduct ongoing monitoring of transactions. The level of scrutiny applied depends on the assessed risk level of the customer and the transaction.

Standard customer due diligence (CDD) applies to most business relationships. It requires collecting and verifying the customer';s full legal name, date of birth or registration number, nationality or place of incorporation, address, and the identity of any beneficial owners holding 25% or more of a legal entity. For corporate customers, this means obtaining constitutional documents, shareholder registers, and proof of the authority of representatives.

Enhanced due diligence (EDD) is mandatory for higher-risk relationships. These include politically exposed persons (PEPs) and their family members or close associates, customers from high-risk jurisdictions identified by the FATF, complex or unusual transactions without apparent economic purpose, and correspondent banking relationships. EDD requires senior management approval, additional source-of-funds documentation, and more frequent transaction monitoring.

Simplified due diligence (SDD) is permitted in limited circumstances where the risk is demonstrably low, such as certain regulated financial institutions or listed companies subject to equivalent disclosure requirements. However, SDD does not mean no due diligence - it means a reduced but still documented process.

Beneficial ownership is a particular focus of UAE regulators. Cabinet Decision No. 58 of 2020 requires companies to maintain accurate and up-to-date beneficial ownership registers and to file this information with the relevant licensing authority. A common mistake among foreign-owned businesses is treating the registered shareholder as the beneficial owner without looking through to the ultimate natural person in control. Regulators expect entities to identify the natural person who ultimately owns or controls the customer, regardless of how many layers of corporate structure exist.

Ongoing monitoring is a continuous obligation. Reporting entities must review customer files periodically, update KYC records when material changes occur, and screen customers and transactions against sanctions lists maintained by the UAE Cabinet and international bodies. The frequency of review should reflect the risk rating of the customer - high-risk customers typically require annual review.

Recent regulatory updates and enforcement trends

The UAE';s AML & KYC landscape has changed substantially in recent years, and staying current is not optional. Several significant developments have reshaped compliance expectations.

The CBUAE has issued updated guidance on the risk-based approach, placing greater emphasis on the quality of risk assessments rather than mere procedural compliance. Supervisors now expect institutions to demonstrate that their risk ratings are calibrated to actual exposure, not simply assigned by default. Institutions that apply a one-size-fits-all approach to customer risk are increasingly cited in examination findings.

The Ministry of Economy has intensified its supervision of DNFBPs. Enforcement actions against real estate brokers, lawyers, and accountants have increased, with administrative penalties imposed for failures to register on the goAML platform, failure to conduct CDD, and failure to file STRs. Many smaller professional firms underestimate the scope of their obligations, treating AML compliance as a concern only for banks.

Virtual asset regulation has expanded significantly. VARA in Dubai has issued detailed AML/CFT compliance requirements for VASPs, including travel rule obligations that require VASPs to transmit originator and beneficiary information alongside virtual asset transfers above specified thresholds. The ADGM and DIFC frameworks contain equivalent requirements. VASPs that fail to implement travel rule compliance face licence suspension.

The UAE has also strengthened its sanctions compliance architecture. The UAE Cabinet regularly updates its local terrorist designation list, and all reporting entities are required to screen against this list in addition to UN Security Council lists. Failure to screen or to freeze assets of designated persons is a criminal offence under the AML-CFT Law.

If your business is navigating these recent changes and needs a structured compliance review, contact info@vlolawfirm.com. We can help structure the setup correctly the first time.

Sector-specific AML & KYC obligations

Different sectors face tailored requirements under the UAE framework, and the practical implications vary considerably.

Banks and financial institutions operate under the most detailed regime. The CBUAE';s AML/CFT guidelines require a dedicated compliance officer, a written AML/CFT policy approved by the board, independent audit of the compliance function, and regular staff training. Correspondent banking relationships require specific EDD, including assessment of the respondent bank';s AML controls and prohibition on relationships with shell banks.

Real estate is a high-priority sector for UAE regulators, given the sector';s historical vulnerability to money laundering. Real estate brokers and developers must conduct CDD on buyers and sellers, identify beneficial owners of purchasing entities, and file STRs for suspicious transactions. Cash transactions above specified thresholds trigger mandatory reporting obligations. A non-obvious requirement is that obligations attach at the point of establishing a business relationship, not only at the point of transaction completion.

Lawyers, accountants, and company service providers must conduct CDD when they assist clients with company formation, management of client funds, real estate transactions, or other specified activities. The obligation does not apply to litigation or legal advice in the traditional sense, but the boundary is not always clear in practice. Many professional firms fail to implement adequate CDD procedures because they assume their sector is not covered.

Virtual asset service providers face a rapidly evolving set of requirements. In addition to standard CDD and EDD, VASPs must implement transaction monitoring systems capable of detecting unusual patterns in blockchain transactions, apply the travel rule for transfers above applicable thresholds, and maintain records of wallet addresses and transaction data. The technical complexity of these requirements means that many VASPs require specialist compliance infrastructure.

Dealers in precious metals and stones must conduct CDD for cash transactions above the applicable threshold and file STRs for suspicious activity. This sector has historically had lower compliance awareness, and the Ministry of Economy has targeted it in recent enforcement rounds.

Penalties, enforcement, and practical compliance steps

Non-compliance with AML & KYC obligations in the UAE carries serious consequences. The AML-CFT Law provides for criminal penalties including imprisonment and fines for money laundering offences. Administrative penalties for compliance failures - such as failure to conduct CDD, failure to file STRs, or failure to maintain records - can reach significant amounts per violation and may be imposed on both the entity and responsible individuals.

The CBUAE has the power to impose administrative sanctions on licensed financial institutions, including fines, restrictions on business activities, and licence revocation. The Ministry of Economy can impose administrative penalties on DNFBPs and refer serious cases to the Public Prosecution. The DFSA and FSRA have equivalent powers within their jurisdictions.

In practice, enforcement has become more systematic. Regulators now use data analytics to identify outliers in STR filing rates, and institutions that file very few reports relative to their business volume attract supervisory attention. A common mistake is treating STR filing as a last resort rather than a routine compliance tool. The legal standard for filing is reasonable suspicion, not certainty.

Record-keeping is a frequently overlooked obligation. The AML-CFT Law requires reporting entities to retain customer identification documents, transaction records, and CDD files for at least five years after the end of the business relationship. Failure to maintain adequate records is itself a violation, independent of whether any underlying suspicious activity occurred.

Practical steps for businesses seeking to strengthen their AML & KYC compliance in the UAE include the following:

  • Conduct a documented risk assessment covering customer types, products, delivery channels, and geographies.
  • Appoint a qualified compliance officer with clear authority and direct board access.
  • Implement written AML/CFT policies and procedures reviewed at least annually.
  • Register on the goAML platform and ensure STR filing procedures are operational.
  • Screen all customers and transactions against UAE Cabinet and UN sanctions lists.

For businesses entering the UAE market or restructuring their compliance programmes, professional legal advice at the outset avoids costly remediation later. Contact info@vlolawfirm.com to discuss your specific situation. We can assist with documents and filings.

Frequently asked questions

What triggers an obligation to file a suspicious transaction report in the UAE?

The legal threshold for filing an STR with the UAE FIU is reasonable suspicion that a transaction or attempted transaction involves the proceeds of crime, is connected to money laundering or terrorist financing, or involves a sanctioned person or entity. Suspicion does not require certainty or proof. Reporting entities must file promptly after forming a suspicion, and tipping off the customer about the report is a criminal offence. Failure to file when suspicion exists exposes both the institution and responsible individuals to criminal and administrative liability. The goAML platform is the mandatory channel for all STR submissions.

How long does it take to build a compliant AML/KYC programme, and what does it cost?

The timeline and cost depend heavily on the size and complexity of the business. A small DNFBP such as a law firm or real estate broker can implement a basic compliant programme - covering risk assessment, written policies, CDD procedures, and goAML registration - within several weeks, with professional fees typically in the low to mid thousands of USD range. A bank or VASP with complex products and a large customer base will require months of work and substantially higher investment in technology, staffing, and external review. Ongoing costs include annual policy reviews, staff training, and periodic independent audits. Many businesses underestimate the technology component, particularly for transaction monitoring and sanctions screening.

Does AML & KYC compliance in the UAE apply differently in free zones such as DIFC and ADGM?

Entities licensed in the DIFC are regulated by the DFSA, which has its own AML rulebook - the Anti-Money Laundering, Counter-Terrorist Financing and Sanctions Module (AML Module) - that applies in place of the CBUAE';s guidelines for financial services activities within the DIFC. Similarly, ADGM entities are subject to FSRA rules. However, the underlying criminal law - the federal AML-CFT Law - applies across the UAE including in free zones. This means that while the supervisory rulebook differs, the criminal offences and the obligation to file STRs with the UAE FIU apply equally. Businesses operating across both onshore and free zone environments must map their obligations carefully, as they may face dual supervisory scrutiny.

Conclusion

AML & KYC compliance in the UAE is a substantive legal obligation that applies across a wide range of businesses, not only banks. The framework is detailed, actively enforced, and continues to evolve in line with FATF standards and domestic regulatory priorities. Businesses that treat compliance as a procedural formality rather than a genuine risk management function face growing enforcement risk.

VLO Law Firms advises international clients on AML & KYC matters in the UAE. We can assist with compliance programme design, risk assessments, STR procedures, beneficial ownership analysis, and regulatory engagement. To request a consultation, contact: info@vlolawfirm.com