Home Blog AML Compliance UAE 2026: DNFBP, KYC, goAML & Reporting

AML/KYC Compliance in the UAE in 2026: DNFBP Requirements, goAML, CDD and Reporting

Aug 25, 2026
40 min
5
Aug 25, 2026 08:02
AML/KYC Compliance in the UAE in 2026: DNFBP Requirements, goAML, CDD and Reporting

AML/KYC compliance in the UAE in 2026: DNFBP requirements, goAML, CDD and reporting

AML/KYC compliance in the UAE is not limited to banks. Real estate brokers and agents, dealers in precious metals and stones, independent accountants and auditors, trust and company service providers and other regulated sectors can fall within the UAE anti-money-laundering framework. In 2026, businesses should work from the new Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025, together with the current guidance of their supervisory authority. This guide explains who is in scope, what an effective AML/CFT/CPF programme must contain, how goAML and suspicious reporting work, what the Compliance Officer is responsible for, and which records and controls regulators expect to see.

Last reviewed: 25 August 2026. The article was checked against Federal Decree-Law No. 10 of 2025, Cabinet Resolution No. 134 of 2025, the Ministry of Economy and Tourism’s March 2026 AML/CFT/CPF Guidelines for DNFBPs, current goAML guidance, UAE targeted-financial-sanctions requirements and the active administrative-penalty framework.


Key points

  • The core UAE AML framework changed for 2026. Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025 are now the central AML/CFT/CPF legislation, replacing the old 2018/2019 framework as the main reference point.
  • AML obligations depend on the regulated activity and supervisory framework, not simply on the company’s size or turnover.
  • For DNFBPs under Ministry of Economy and Tourism supervision, the principal sectors are real estate agents and brokers, dealers in precious metals and stones, independent accountants and auditors, and trust and corporate service providers.
  • Legal professionals are supervised separately by the Ministry of Justice. DNFBPs in DIFC and ADGM are supervised by the DFSA and FSRA respectively, so they must follow the rules of the relevant financial free zone.
  • An effective programme is broader than a written AML policy. It should include a documented Business Risk Assessment, risk-based CDD, beneficial-owner verification, ongoing monitoring, sanctions and PEP controls, reporting procedures, training, record keeping and governance.
  • DNFBPs must appoint a qualified Compliance Officer, also commonly referred to as the MLRO. Current MoET guidance states that the appointment requires prior written approval from the relevant Supervisory Authority.
  • Registration on goAML is mandatory for DNFBPs that report to the UAE FIU. The Compliance Officer is the central user for suspicious transaction and activity reporting.
  • STRs and SARs must be filed without delay once suspicion is established. Tipping off the customer about a report or investigation is prohibited.
  • Targeted Financial Sanctions are not merely a screening exercise. A confirmed match can require freezing funds or assets without delay and reporting under the applicable UAE TFS rules.
  • The minimum statutory record-retention period is generally five years, but the start point depends on the relevant event and a competent authority can require longer retention.

In this guide

  • What changed in the UAE AML framework for 2026?
  • Which UAE businesses are DNFBPs?
  • Which authority supervises your AML compliance?
  • What an effective AML/KYC programme contains
  • Business Risk Assessment and the risk-based approach
  • Compliance Officer / MLRO requirements
  • KYC and Customer Due Diligence
  • Beneficial owners and corporate customers
  • Enhanced Due Diligence, PEPs and source of funds
  • Sanctions and Targeted Financial Sanctions
  • goAML registration and suspicious reporting
  • STR, SAR and the tipping-off rule
  • AML record retention
  • Staff training and independent testing
  • AML compliance checklist
  • Penalties and enforcement risk
  • Common compliance mistakes
  • How MIRAD can support AML/KYC compliance
  • Frequently asked questions
  • Official sources

What changed in the UAE AML framework for 2026?

A major change is the legal basis itself. The UAE issued Federal Decree-Law No. 10 of 2025 regarding Anti-Money Laundering and Combating the Financing of Terrorism and Proliferation Financing. Its Executive Regulations were issued through Cabinet Resolution No. 134 of 2025 and became effective in December 2025.

This matters because many older AML articles, policies and templates still refer primarily to Federal Decree-Law No. 20 of 2018 and Cabinet Decision No. 10 of 2019. Those references should not be copied into a 2026 compliance framework without checking the current legislation and supervisory guidance.

The current framework also gives greater practical prominence to proliferation-financing risk (PF), targeted financial sanctions, governance, business-wide risk assessment and the effectiveness of controls. A document titled simply “AML/KYC Policy” may therefore be too narrow if the actual programme does not address AML/CFT/CPF requirements.


Which UAE businesses are DNFBPs?

The Ministry of Economy and Tourism’s March 2026 DNFBP Guidelines expressly cover four principal sectors under its supervisory remit.

DNFBP sectorExamples / scope
Real Estate Agents and Brokers (REAB)Businesses acting in real estate agency and brokerage activities that fall within the regulated DNFBP framework.
Dealers in Precious Metals and Precious Stones (DPMS)Businesses dealing in gold, silver, platinum, diamonds, jewellery and other precious metals or stones within the regulated activity.
Independent Accountants and Auditors (IAA)Independent accounting and audit professionals and firms within the relevant regulated scope.
Trust and Corporate Service Providers (TCSP)Businesses providing company formation, registered-address, administration, nominee, trust or related corporate services where the activity falls within the DNFBP definition.

Important: the AED 55,000 figure should not be used as a universal test for whether a company “becomes a DNFBP”. DNFBP status is driven by the regulated activity. Under the current MoET guidance, AED 55,000 is relevant to CDD for certain occasional transactions: CDD is required where an occasional transaction equals or exceeds AED 55,000, as well as where there is suspicion regardless of value or doubt about previously obtained identification data.


Which authority supervises your AML compliance?

Business / locationMain AML supervisor
MoET-supervised DNFBPs in mainland UAE and Commercial Free ZonesMinistry of Economy and Tourism (MoET)
Law firms and legal professionals within the relevant federal/local frameworkMinistry of Justice (MoJ)
DNFBPs operating in DIFCDubai Financial Services Authority (DFSA)
DNFBPs operating in ADGMFinancial Services Regulatory Authority (FSRA)
Financial institutionsRelevant financial regulator, including the Central Bank of the UAE where applicable
Virtual Asset Service ProvidersThe applicable virtual-asset regulator and AML supervisory framework, depending on activity and jurisdiction

Do not use a Ministry of Economy checklist automatically for every entity in the UAE. The national law applies within its scope, but supervisory rules, portals, approvals and inspection expectations can differ between MoET, MoJ, DFSA, FSRA and other competent authorities.


What an effective AML/KYC programme contains

A regulator-ready AML programme is a system of governance, risk assessment, client controls, monitoring, reporting and evidence. It should be capable of demonstrating what the company actually does, not only what its policy says.

  • Documented AML/CFT/CPF governance framework approved by senior management.
  • Business Risk Assessment (BRA) covering ML, TF and PF exposure.
  • Documented risk appetite and customer-risk methodology.
  • KYC and Customer Due Diligence (CDD), including identification and verification.
  • Identification and verification of Ultimate Beneficial Owners, beneficiaries and controlling persons.
  • Simplified Due Diligence where legally appropriate and Enhanced Due Diligence for higher-risk cases.
  • PEP identification and risk controls.
  • Source of Funds and Source of Wealth procedures where relevant to risk.
  • Sanctions and adverse-media screening, including Targeted Financial Sanctions procedures.
  • Ongoing monitoring and periodic/event-driven KYC review.
  • Internal escalation of suspicious transactions and STR/SAR reporting through goAML.
  • Compliance Officer / MLRO governance and access to senior management.
  • Record retention, data accessibility and confidentiality controls.
  • Role-specific AML/CFT/CPF staff training.
  • Independent testing or audit appropriate to the size, nature and risk of the business.
  • Documented remediation and follow-up after regulatory findings or internal control failures.

A KYC form pack is useful, but forms alone are not a compliance programme. The forms must connect to a risk methodology, escalation rules, monitoring, evidence retention and a Compliance Officer who has authority to act.


Business Risk Assessment and the risk-based approach

The Business Risk Assessment is one of the central components of the 2026 DNFBP framework. The business must identify and assess its exposure to money laundering, terrorism financing and proliferation financing and use that assessment to determine the level of controls and resources required.

Current MoET guidance states that the risk assessment must be documented, supported by methodology and data, kept up to date and made available to the Supervisory Authority on request. Senior management must formally certify that the BRA accurately reflects the entity’s risk exposure and is supported by appropriate mitigation measures.

What should the BRA consider?

  • Customer and beneficial-owner risk.
  • Countries and geographic exposure, including high-risk jurisdictions.
  • Products and services offered.
  • Transaction types and payment methods.
  • Delivery channels, including remote onboarding.
  • Complex or opaque ownership structures.
  • Cash-intensive activity.
  • New technologies and digital or virtual-asset exposure where relevant.
  • Sector-specific typologies and red flags.
  • Findings from the UAE National Risk Assessment, Sectoral Risk Assessments and current supervisory circulars.
  • Proliferation-financing risk, including exposure to dual-use goods, sanctioned jurisdictions and opaque corporate structures.

The BRA should not be treated as an annual document that is automatically valid for twelve months. It should be reviewed periodically and updated when material changes occur — for example, a new customer segment, new country, new service, new technology, regulatory change or newly identified ML/TF/PF threat.


Compliance Officer / MLRO requirements

Current MoET guidance uses the term Compliance Officer (CO) and notes that the role is also referred to as the Money Laundering Reporting Officer (MLRO). The CO is responsible for the effectiveness of the DNFBP’s AML/CFT/CPF programme and acts as the principal liaison with the FIU and Supervisory Authority.

The company must appoint a qualified person with appropriate seniority, authority, independence and resources. The March 2026 Guidelines state that the appointment must receive the prior written approval of the relevant Supervisory Authority.

  • Oversee and update the AML/CFT/CPF framework.
  • Own or oversee the Business Risk Assessment.
  • Review customer-risk methodology, CDD, monitoring and sanctions controls.
  • Receive and assess internal suspicious-activity escalations.
  • Decide whether an STR or SAR should be submitted and file it with the FIU.
  • Maintain direct and unrestricted access to relevant records and systems.
  • Have access to senior management and the board where applicable.
  • Oversee staff training and awareness.
  • Cooperate with supervisory inspections, FIU requests and remediation actions.
  • Ensure AML records are retained and accessible.

A third-party Compliance Officer can be possible in certain circumstances, subject to the applicable rules and supervisory approval. Outsourcing the role does not transfer the DNFBP’s ultimate responsibility for compliance.


KYC and Customer Due Diligence (CDD)

KYC is one component of the wider CDD process. The purpose is not only to collect a passport or trade licence, but to understand who the customer is, who ultimately owns or controls a legal person, why the relationship exists and whether actual activity is consistent with the declared profile.

  • Identify and verify the customer from reliable and independent information.
  • Identify and verify the beneficial owner, beneficiaries and controlling persons where relevant.
  • Understand the purpose and intended nature of the business relationship.
  • For corporate customers, understand the business activity, ownership structure and control structure.
  • Screen relevant persons against sanctions and appropriate adverse-media sources.
  • Establish an appropriate customer-risk rating.
  • Obtain clarity on source of funds and, where required by risk, source of wealth.
  • Monitor the relationship and transactions on an ongoing basis.
  • Refresh KYC and CDD information periodically and when a triggering event occurs.

For an occasional transaction without an existing business relationship, current MoET guidance requires CDD when the transaction is AED 55,000 or more, including linked transactions. CDD is also required where there is suspicion of ML/TF/PF regardless of value, or doubts about the accuracy or completeness of existing identification information.


Beneficial owners and corporate customers

Corporate KYC must go beyond the trade licence. The DNFBP should understand who ultimately owns or controls the customer, how the ownership chain works, who is authorised to act, and whether nominee or layered structures have a legitimate purpose.

  • Legal name, registration details and legal form.
  • Registered and principal business address.
  • Nature of the customer’s business.
  • Ownership and control structure.
  • Ultimate Beneficial Owner(s).
  • Directors, managers and authorised representatives as relevant.
  • Authority of the representative acting for the customer.
  • Nominee shareholders or directors and the underlying arrangement where identified.
  • Source and purpose of funds used in the transaction or relationship, based on risk.
  • Expected transaction pattern and geographic exposure.

Where a structure is unusually complex, opaque or inconsistent with the customer’s stated business purpose, the DNFBP should not simply collect more documents. It should reassess risk and determine whether EDD, escalation or suspicious reporting is required.


Enhanced Due Diligence, PEPs and source of funds

Higher-risk customers and relationships require Enhanced Due Diligence. The exact measures depend on the risk, but the company should be able to demonstrate why the case was classified as high risk and what additional controls were applied.

Politically Exposed Persons (PEPs)

For a PEP relationship, current MoET guidance includes measures such as senior-management approval, establishing Source of Wealth and Source of Funds using reliable evidence, and more frequent monitoring. These controls can also apply where the PEP is a beneficial owner, beneficiary or controlling person.

Examples of EDD triggers

  • Customer or beneficial owner is a foreign PEP or presents elevated PEP risk.
  • Customer is connected to a high-risk jurisdiction.
  • Complex ownership structure without a clear commercial rationale.
  • Unusual use of nominees, shell entities or intermediaries.
  • Large or unusual transactions inconsistent with the known customer profile.
  • Source of funds or source of wealth cannot be reasonably explained or evidenced.
  • High cash intensity or unusual third-party payments.
  • Adverse media indicating financial-crime or predicate-offence risk.
  • Sanctions alerts or links to sanctioned jurisdictions that require investigation.
  • Transaction patterns associated with known sector-specific ML/TF/PF typologies.

Sanctions and Targeted Financial Sanctions

Sanctions compliance should not be reduced to a one-time name check at onboarding. DNFBPs must maintain controls for Targeted Financial Sanctions (TFS) and follow the instructions and guidance of the Executive Office for Control and Non-Proliferation and other competent authorities.

The March 2026 MoET Guidelines emphasise screening, freezing without delay and reporting obligations. If the business identifies a true match to an applicable UAE or UN terrorism / proliferation designation, funds or assets may need to be frozen immediately without prior notice to the customer and the required report made without delay.

Do not confuse a sanctions alert with a confirmed match. Screening systems can create false positives. The company needs a documented escalation and match-resolution process, but a true match must be handled under the applicable TFS rules without delay.


goAML registration and suspicious reporting

goAML is the UAE FIU’s reporting platform for suspicious transactions and activities. The Ministry of Economy and Tourism states that registration on goAML is mandatory for DNFBPs within the reporting framework and that DNFBPs must maintain an active registration.

The Compliance Officer is the central user for AML reporting. Registration is therefore not a one-time technical exercise that can be forgotten after setup: access, user details and the identity of the registered Compliance Officer must remain current.


STR, SAR and the tipping-off rule

An STR is used where a transaction is suspected to relate to money laundering, a predicate offence or relevant financial-crime activity. A SAR can apply where suspicious activity or an attempted transaction is identified even though the transaction was not completed. The exact report type should follow current FIU/goAML guidance.

Current MoET guidance requires STRs/SARs to be reported to the FIU without delay. Internal review can be necessary to establish whether reasonable grounds for suspicion exist, but the company should be able to show that the review started promptly and continued without unnecessary delay.

There is no minimum transaction value for suspicion. A suspicious case can require reporting regardless of the amount involved.

The business must also protect the confidentiality of the reporting process. Telling a customer or another unauthorised person that an STR/SAR has been or will be filed, or that an investigation is taking place, can constitute prohibited tipping off.


AML record retention in the UAE

The current MoET DNFBP Guidelines state that the minimum statutory retention period for relevant AML records is generally five years. The period is calculated from the latest applicable event rather than from one universal date.

  • Customer identification and CDD files.
  • Beneficial-owner and control information.
  • Transaction records.
  • Business correspondence.
  • Customer and business-risk assessments.
  • EDD reviews and supporting evidence.
  • Internal suspicious-activity reports and analysis.
  • STR/SAR records and relevant FIU correspondence.
  • Sanctions-screening and match-resolution evidence.
  • Training and governance records where relevant.
  • Documentation showing reliance on third parties for CDD where applicable.
  • Ongoing-monitoring and periodic-review records.

Depending on the case, the five-year period can run from events such as termination of the customer relationship, completion of an occasional transaction, completion of a supervisory inspection, final judgment or dissolution / liquidation of the legal person. Competent authorities can require longer retention.


Staff training and independent testing

AML training should be role-specific rather than a generic annual slide deck. Current guidance expects relevant personnel — including customer-facing staff, compliance teams, senior management and board members where applicable — to understand the legal framework, internal procedures, red flags, escalation process and tipping-off restrictions.

  • Current AML/CFT/CPF laws and supervisory expectations.
  • Company policies and controls.
  • Sector-specific ML/TF/PF red flags and typologies.
  • CDD, EDD and customer-risk methodology.
  • PEP and sanctions escalation.
  • Internal suspicious-activity escalation.
  • goAML reporting responsibilities.
  • Tipping-off restrictions.
  • Proliferation-financing risks relevant to the business.
  • Practical case studies and role-specific examples.

The control environment should also be tested. Depending on the size, complexity and risk profile of the DNFBP, this can include internal or outsourced independent testing of CDD files, risk scoring, STR procedures, sanctions screening, training and remediation.


AML compliance checklist for a UAE DNFBP


Penalties and enforcement risk

AML non-compliance can create administrative, regulatory and criminal exposure. The consequence depends on the violation, the responsible person, intent or gross negligence, the supervisory framework and whether the issue involves a failure of controls, reporting, targeted sanctions or an underlying financial crime.

The March 2026 MoET Guidelines summarise criminal consequences under the new law. For example, intentional or grossly negligent violation of specified internal-control, risk-assessment and reporting obligations can carry imprisonment and/or a fine within the statutory range. Tipping off and failure to comply with UN sanctions implementation requirements also have separate criminal consequences.

For legal persons, the new law can also result in substantial corporate fines depending on the offence, and courts can have powers including confiscation, suspension of activities, closure, dissolution and publication of judgment. Separately, the Ministry continues to operate an administrative-fines framework for DNFBP compliance violations.

Do not market AML compliance only around a single “fine up to AED 5 million”. Different violations can attract different administrative and criminal consequences under the current framework. The safer approach is to identify the actual breach and applicable provision.


Common AML/KYC compliance mistakes

  • Using an AML policy written for the old 2018/2019 framework without updating it for the 2025 law and Executive Regulations.
  • Treating AML as only AML/CFT and ignoring proliferation-financing risk and CPF controls.
  • Assuming every UAE company must register on goAML without first identifying whether it is a regulated reporting entity.
  • Conversely, operating a DNFBP and failing to register or maintain active access to goAML.
  • Using AED 55,000 as a universal threshold for whether a business is subject to AML regulation.
  • Appointing an MLRO in an internal memo without checking the current supervisory-approval requirement.
  • Having a generic policy but no documented Business Risk Assessment.
  • Collecting passports and licences without identifying and verifying beneficial owners.
  • Using a risk-rating spreadsheet that does not connect to actual EDD or monitoring controls.
  • Checking sanctions only at onboarding and never rescreening customers or beneficial owners.
  • Treating Source of Funds and Source of Wealth as the same concept in every case.
  • Failing to escalate attempted or rejected suspicious transactions.
  • Waiting for a transaction to exceed a monetary threshold before considering an STR.
  • Discussing a filed or contemplated STR with the customer and creating a tipping-off risk.
  • Retaining documents but being unable to retrieve the complete audit trail during inspection.
  • Training only junior staff while excluding management and decision makers from AML awareness.

How MIRAD can support AML/KYC compliance in the UAE

MIRAD can help structure the compliance framework around the company’s actual DNFBP activity, customer profile, geography and supervisory authority rather than using a generic template. The starting point should be a gap review against the current 2025 law, 2025 Executive Regulations and applicable 2026 supervisory guidance.

  • Assessment of DNFBP status and applicable supervisory framework.
  • AML/CFT/CPF gap analysis against current UAE requirements.
  • Business Risk Assessment methodology and documentation.
  • Development or update of AML/CFT/CPF policies, procedures and controls.
  • KYC/CDD forms for individuals and legal entities.
  • UBO identification and ownership-structure documentation.
  • Customer-risk scoring and EDD procedures.
  • PEP, sanctions, adverse-media, Source of Funds and Source of Wealth workflows.
  • Compliance Officer / MLRO role and governance support.
  • goAML registration and maintenance support where within the service scope.
  • Internal STR/SAR escalation procedures and reporting workflow design.
  • Record-retention and compliance-file structure.
  • Role-based staff AML training.
  • Preparation for regulatory requests, remediation and inspection readiness.
Build an AML programme that works in an inspection

MIRAD can review your DNFBP obligations, update the risk assessment and AML/CFT/CPF framework, prepare KYC and EDD procedures and support the operational compliance process.

Request AML compliance support

AML/KYC compliance in the UAE: FAQ

Does AML apply to every UAE company?

Which businesses are DNFBPs under Ministry of Economy and Tourism supervision?

Is AED 55,000 the threshold for becoming subject to AML?

Is goAML registration mandatory for DNFBPs?

What is the difference between an MLRO and a Compliance Officer?

Does the Compliance Officer require regulatory approval?

Is a generic AML policy template enough?

When is Enhanced Due Diligence required?

Do PEPs have to be rejected as customers?

When must an STR be filed?

What is the difference between an STR and a SAR?

How long must AML records be retained?

Do sanctions checks only need to be done when onboarding a client?

Can an AML consultant file an STR for the company?


Official sources

  • UAE Legislation — Federal Decree-Law No. 10 of 2025 regarding Anti-Money Laundering and Combating the Financing of Terrorism and Proliferation Financing.
  • UAE Legislation — Cabinet Resolution No. 134 of 2025 regarding the Executive Regulations of Federal Decree-Law No. 10 of 2025.
  • Ministry of Economy and Tourism — AML/CFT/CPF Guidelines for Designated Non-Financial Businesses and Professions, March 2026.
  • Ministry of Economy and Tourism — Register in goAML / goAML Suspicious Transaction Reporting System.
  • UAE Financial Intelligence Unit — goAML reporting guidance.
  • Executive Office for Control and Non-Proliferation — Targeted Financial Sanctions and CPF guidance.
  • UAE Legislation — Cabinet Resolution No. 71 of 2024 regulating administrative penalties for DNFBP AML violations.
  • Current MoET circulars on high-risk jurisdictions, increased monitoring and sector-specific AML/CFT/CPF requirements.

Disclaimer: This article is for general information only and does not constitute legal, regulatory or compliance advice for a specific entity. AML/CFT/CPF obligations depend on the company’s licensed activity, jurisdiction, supervisor, customer profile, transactions and risk exposure. The UAE regulatory framework, high-risk-country lists, sanctions requirements, circulars and supervisory expectations change over time. Verify the current requirements with the relevant Supervisory Authority and obtain qualified professional advice before implementing or changing a compliance programme.

What you need to know to get Emirates ID?

Leave your details and get a guide as a gift to avoid mistakes

Guide illustration
Article contents

    Related articles