AML/KYC compliance in the UAE is not limited to banks. Real estate brokers and agents, dealers in precious metals and stones, independent accountants and auditors, trust and company service providers and other regulated sectors can fall within the UAE anti-money-laundering framework. In 2026, businesses should work from the new Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025, together with the current guidance of their supervisory authority. This guide explains who is in scope, what an effective AML/CFT/CPF programme must contain, how goAML and suspicious reporting work, what the Compliance Officer is responsible for, and which records and controls regulators expect to see.
Last reviewed: 25 August 2026. The article was checked against Federal Decree-Law No. 10 of 2025, Cabinet Resolution No. 134 of 2025, the Ministry of Economy and Tourism’s March 2026 AML/CFT/CPF Guidelines for DNFBPs, current goAML guidance, UAE targeted-financial-sanctions requirements and the active administrative-penalty framework.
A major change is the legal basis itself. The UAE issued Federal Decree-Law No. 10 of 2025 regarding Anti-Money Laundering and Combating the Financing of Terrorism and Proliferation Financing. Its Executive Regulations were issued through Cabinet Resolution No. 134 of 2025 and became effective in December 2025.
This matters because many older AML articles, policies and templates still refer primarily to Federal Decree-Law No. 20 of 2018 and Cabinet Decision No. 10 of 2019. Those references should not be copied into a 2026 compliance framework without checking the current legislation and supervisory guidance.
The current framework also gives greater practical prominence to proliferation-financing risk (PF), targeted financial sanctions, governance, business-wide risk assessment and the effectiveness of controls. A document titled simply “AML/KYC Policy” may therefore be too narrow if the actual programme does not address AML/CFT/CPF requirements.
The Ministry of Economy and Tourism’s March 2026 DNFBP Guidelines expressly cover four principal sectors under its supervisory remit.
| DNFBP sector | Examples / scope |
| Real Estate Agents and Brokers (REAB) | Businesses acting in real estate agency and brokerage activities that fall within the regulated DNFBP framework. |
| Dealers in Precious Metals and Precious Stones (DPMS) | Businesses dealing in gold, silver, platinum, diamonds, jewellery and other precious metals or stones within the regulated activity. |
| Independent Accountants and Auditors (IAA) | Independent accounting and audit professionals and firms within the relevant regulated scope. |
| Trust and Corporate Service Providers (TCSP) | Businesses providing company formation, registered-address, administration, nominee, trust or related corporate services where the activity falls within the DNFBP definition. |
Important: the AED 55,000 figure should not be used as a universal test for whether a company “becomes a DNFBP”. DNFBP status is driven by the regulated activity. Under the current MoET guidance, AED 55,000 is relevant to CDD for certain occasional transactions: CDD is required where an occasional transaction equals or exceeds AED 55,000, as well as where there is suspicion regardless of value or doubt about previously obtained identification data.
| Business / location | Main AML supervisor |
| MoET-supervised DNFBPs in mainland UAE and Commercial Free Zones | Ministry of Economy and Tourism (MoET) |
| Law firms and legal professionals within the relevant federal/local framework | Ministry of Justice (MoJ) |
| DNFBPs operating in DIFC | Dubai Financial Services Authority (DFSA) |
| DNFBPs operating in ADGM | Financial Services Regulatory Authority (FSRA) |
| Financial institutions | Relevant financial regulator, including the Central Bank of the UAE where applicable |
| Virtual Asset Service Providers | The applicable virtual-asset regulator and AML supervisory framework, depending on activity and jurisdiction |
Do not use a Ministry of Economy checklist automatically for every entity in the UAE. The national law applies within its scope, but supervisory rules, portals, approvals and inspection expectations can differ between MoET, MoJ, DFSA, FSRA and other competent authorities.
A regulator-ready AML programme is a system of governance, risk assessment, client controls, monitoring, reporting and evidence. It should be capable of demonstrating what the company actually does, not only what its policy says.
A KYC form pack is useful, but forms alone are not a compliance programme. The forms must connect to a risk methodology, escalation rules, monitoring, evidence retention and a Compliance Officer who has authority to act.
The Business Risk Assessment is one of the central components of the 2026 DNFBP framework. The business must identify and assess its exposure to money laundering, terrorism financing and proliferation financing and use that assessment to determine the level of controls and resources required.
Current MoET guidance states that the risk assessment must be documented, supported by methodology and data, kept up to date and made available to the Supervisory Authority on request. Senior management must formally certify that the BRA accurately reflects the entity’s risk exposure and is supported by appropriate mitigation measures.
The BRA should not be treated as an annual document that is automatically valid for twelve months. It should be reviewed periodically and updated when material changes occur — for example, a new customer segment, new country, new service, new technology, regulatory change or newly identified ML/TF/PF threat.
Current MoET guidance uses the term Compliance Officer (CO) and notes that the role is also referred to as the Money Laundering Reporting Officer (MLRO). The CO is responsible for the effectiveness of the DNFBP’s AML/CFT/CPF programme and acts as the principal liaison with the FIU and Supervisory Authority.
The company must appoint a qualified person with appropriate seniority, authority, independence and resources. The March 2026 Guidelines state that the appointment must receive the prior written approval of the relevant Supervisory Authority.
A third-party Compliance Officer can be possible in certain circumstances, subject to the applicable rules and supervisory approval. Outsourcing the role does not transfer the DNFBP’s ultimate responsibility for compliance.
KYC is one component of the wider CDD process. The purpose is not only to collect a passport or trade licence, but to understand who the customer is, who ultimately owns or controls a legal person, why the relationship exists and whether actual activity is consistent with the declared profile.
For an occasional transaction without an existing business relationship, current MoET guidance requires CDD when the transaction is AED 55,000 or more, including linked transactions. CDD is also required where there is suspicion of ML/TF/PF regardless of value, or doubts about the accuracy or completeness of existing identification information.
Corporate KYC must go beyond the trade licence. The DNFBP should understand who ultimately owns or controls the customer, how the ownership chain works, who is authorised to act, and whether nominee or layered structures have a legitimate purpose.
Where a structure is unusually complex, opaque or inconsistent with the customer’s stated business purpose, the DNFBP should not simply collect more documents. It should reassess risk and determine whether EDD, escalation or suspicious reporting is required.
Higher-risk customers and relationships require Enhanced Due Diligence. The exact measures depend on the risk, but the company should be able to demonstrate why the case was classified as high risk and what additional controls were applied.
For a PEP relationship, current MoET guidance includes measures such as senior-management approval, establishing Source of Wealth and Source of Funds using reliable evidence, and more frequent monitoring. These controls can also apply where the PEP is a beneficial owner, beneficiary or controlling person.
Sanctions compliance should not be reduced to a one-time name check at onboarding. DNFBPs must maintain controls for Targeted Financial Sanctions (TFS) and follow the instructions and guidance of the Executive Office for Control and Non-Proliferation and other competent authorities.
The March 2026 MoET Guidelines emphasise screening, freezing without delay and reporting obligations. If the business identifies a true match to an applicable UAE or UN terrorism / proliferation designation, funds or assets may need to be frozen immediately without prior notice to the customer and the required report made without delay.
Do not confuse a sanctions alert with a confirmed match. Screening systems can create false positives. The company needs a documented escalation and match-resolution process, but a true match must be handled under the applicable TFS rules without delay.
goAML is the UAE FIU’s reporting platform for suspicious transactions and activities. The Ministry of Economy and Tourism states that registration on goAML is mandatory for DNFBPs within the reporting framework and that DNFBPs must maintain an active registration.
The Compliance Officer is the central user for AML reporting. Registration is therefore not a one-time technical exercise that can be forgotten after setup: access, user details and the identity of the registered Compliance Officer must remain current.
An STR is used where a transaction is suspected to relate to money laundering, a predicate offence or relevant financial-crime activity. A SAR can apply where suspicious activity or an attempted transaction is identified even though the transaction was not completed. The exact report type should follow current FIU/goAML guidance.
Current MoET guidance requires STRs/SARs to be reported to the FIU without delay. Internal review can be necessary to establish whether reasonable grounds for suspicion exist, but the company should be able to show that the review started promptly and continued without unnecessary delay.
There is no minimum transaction value for suspicion. A suspicious case can require reporting regardless of the amount involved.
The business must also protect the confidentiality of the reporting process. Telling a customer or another unauthorised person that an STR/SAR has been or will be filed, or that an investigation is taking place, can constitute prohibited tipping off.
The current MoET DNFBP Guidelines state that the minimum statutory retention period for relevant AML records is generally five years. The period is calculated from the latest applicable event rather than from one universal date.
Depending on the case, the five-year period can run from events such as termination of the customer relationship, completion of an occasional transaction, completion of a supervisory inspection, final judgment or dissolution / liquidation of the legal person. Competent authorities can require longer retention.
AML training should be role-specific rather than a generic annual slide deck. Current guidance expects relevant personnel — including customer-facing staff, compliance teams, senior management and board members where applicable — to understand the legal framework, internal procedures, red flags, escalation process and tipping-off restrictions.
The control environment should also be tested. Depending on the size, complexity and risk profile of the DNFBP, this can include internal or outsourced independent testing of CDD files, risk scoring, STR procedures, sanctions screening, training and remediation.
AML non-compliance can create administrative, regulatory and criminal exposure. The consequence depends on the violation, the responsible person, intent or gross negligence, the supervisory framework and whether the issue involves a failure of controls, reporting, targeted sanctions or an underlying financial crime.
The March 2026 MoET Guidelines summarise criminal consequences under the new law. For example, intentional or grossly negligent violation of specified internal-control, risk-assessment and reporting obligations can carry imprisonment and/or a fine within the statutory range. Tipping off and failure to comply with UN sanctions implementation requirements also have separate criminal consequences.
For legal persons, the new law can also result in substantial corporate fines depending on the offence, and courts can have powers including confiscation, suspension of activities, closure, dissolution and publication of judgment. Separately, the Ministry continues to operate an administrative-fines framework for DNFBP compliance violations.
Do not market AML compliance only around a single “fine up to AED 5 million”. Different violations can attract different administrative and criminal consequences under the current framework. The safer approach is to identify the actual breach and applicable provision.
MIRAD can help structure the compliance framework around the company’s actual DNFBP activity, customer profile, geography and supervisory authority rather than using a generic template. The starting point should be a gap review against the current 2025 law, 2025 Executive Regulations and applicable 2026 supervisory guidance.
Related MIRAD services: AML Compliance in the UAE, KYC in the UAE, Compliance Request Responses, and KYC and UBO filing support.
MIRAD can review your DNFBP obligations, update the risk assessment and AML/CFT/CPF framework, prepare KYC and EDD procedures and support the operational compliance process.
Request AML compliance supportDoes AML apply to every UAE company?
Which businesses are DNFBPs under Ministry of Economy and Tourism supervision?
Is AED 55,000 the threshold for becoming subject to AML?
Is goAML registration mandatory for DNFBPs?
What is the difference between an MLRO and a Compliance Officer?
Does the Compliance Officer require regulatory approval?
Is a generic AML policy template enough?
When is Enhanced Due Diligence required?
Do PEPs have to be rejected as customers?
When must an STR be filed?
What is the difference between an STR and a SAR?
How long must AML records be retained?
Do sanctions checks only need to be done when onboarding a client?
Can an AML consultant file an STR for the company?
Disclaimer: This article is for general information only and does not constitute legal, regulatory or compliance advice for a specific entity. AML/CFT/CPF obligations depend on the company’s licensed activity, jurisdiction, supervisor, customer profile, transactions and risk exposure. The UAE regulatory framework, high-risk-country lists, sanctions requirements, circulars and supervisory expectations change over time. Verify the current requirements with the relevant Supervisory Authority and obtain qualified professional advice before implementing or changing a compliance programme.
Leave your details and get a guide as a gift to avoid mistakes