Build a practical AML framework around business-wide risk assessment, customer due diligence, beneficial ownership, screening, goAML, internal escalation and recordkeeping.
The UAE AML framework was updated substantially. Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025 now form the core federal framework for anti-money laundering, counter-terrorism financing and counter-proliferation financing requirements.
The Ministry of Economy & Tourism also issued updated DNFBP Guidelines in March 2026. Those guidelines emphasise a risk-based approach, documented policies and procedures, customer due diligence, beneficial-owner identification, ongoing monitoring, reporting and recordkeeping.
If a policy manual still cites the older 2018/2019 framework as the current legal basis, the references and procedures need to be reviewed against the legislation now in force.
The Ministry of Economy & Tourism's goAML information identifies several Designated Non-Financial Business and Profession categories.
The licence and actual activity need to be reviewed together. A company is not classified merely because a similar business name appears in a broad industry category.
Document exposure across customers, services, delivery channels, geography and transaction patterns.
Use documented risk factors to determine the level of due diligence and approval required.
Build onboarding files that identify and verify customers and understand the purpose of the relationship.
Trace ownership and control until the relevant natural persons are identified and documented.
Refresh customer files and review transactions against the expected customer profile.
Create a clear internal route for unusual activity to reach the responsible compliance function.
The 2026 DNFBP Guidelines require internal policies, procedures and controls to be based on the results of the business-wide ML/TF/PF risk assessment and to reflect the nature, size and complexity of the business.
That makes the risk assessment more than a compliance form. It is the document that explains why the organisation applies particular controls, customer risk categories, enhanced review triggers and monitoring intensity.
Ownership structure, occupation or business activity, expected behaviour and other risk indicators.
Customer, ownership, transaction and service exposure to relevant jurisdictions.
How the service could be used, complexity, value and ability to move or disguise funds.
Face-to-face, intermediated, remote or technology-enabled onboarding and transaction risks.
CDD needs to establish and verify the customer's identity, understand beneficial ownership and capture the purpose and intended nature of the relationship. For layered legal-person structures, the Ministry's 2026 guidance describes tracing ownership and control through the layers until the relevant natural persons are identified.
The guidance also refers to identifying natural persons who ultimately own or control through direct or indirect ownership of 25% or more, while also considering other means of control and cumulative ownership.
Enhanced due diligence is not a separate onboarding system; it is a deeper level of review triggered by risk. Depending on the facts, that can involve additional information on the customer or beneficial owner, source of funds or source of wealth, senior approval, more frequent review or closer transaction monitoring.
| Trigger area | Possible response |
|---|---|
| Complex ownership | Obtain additional ownership evidence and trace control through each relevant layer. |
| Higher-risk geography | Apply the enhanced measures required for the relevant risk and current regulatory position. |
| Unusual business model | Understand the commercial purpose, source of funds and expected transaction pattern in more depth. |
| PEP or other elevated risk | Apply the additional review, approval and monitoring required by the applicable framework. |
| Inconsistent activity | Investigate the difference between expected and actual customer behaviour. |
The Ministry of Economy & Tourism states that DNFBPs must register on goAML. The system is used by the UAE Financial Intelligence Unit to receive and analyse suspicious transaction and suspicious activity reports.
Our support can focus on registration readiness, responsible-user information, internal escalation and maintaining the records that support reporting decisions.
Organise the trade licence, authorised-user information and other required records for the registration process.
Give employees a defined route for escalating unusual activity before any external reporting decision.
Keep a controlled file of the facts, analysis and approval associated with the reporting decision.
Control who is authorised to access the platform and submit reports on behalf of the organisation.
AML controls fail when employees do not know who owns a decision or when the compliance function cannot obtain the records it needs. The governance structure needs to identify the responsible officer, escalation route, senior-management involvement and how unresolved risks are reported.
The Ministry's March 2026 DNFBP Guidelines state that internal policies, procedures and controls need to be documented, approved by senior management, communicated through the organisation and integrated into day-to-day operations. They also need periodic review and effectiveness testing as risks or regulatory expectations change.
Cabinet Resolution No. 134 of 2025 requires relevant transaction and due-diligence records to be retained for at least five years, with the retention start point depending on the nature of the record and event. The 2026 DNFBP Guidelines also emphasise that records need to be organised so transactions and decisions can be reconstructed.
Review current policies, risk assessment, customer files, screening and reporting controls.
Separate urgent legal/control gaps from lower-risk documentation improvements.
Repair CDD files, policy gaps, risk ratings and escalation processes.
Target staff training to the weaknesses identified during the review.
Track unresolved actions and test whether revised controls are operating.
Deliverables depend on the business, supervisor and risk profile.
Different DNFBP sectors face different customer, transaction and delivery-channel risks. The underlying AML framework is shared, but the practical controls should be tailored to the activity being supervised.
Client acceptance, beneficial ownership, unusual business structures, source information and the risk created by services involving company, financial or transaction information.
Buyer and seller identification, beneficial ownership, payment patterns, property value, geography and unusual transaction structures.
Customer identity, cash or high-value transactions, source information, product movement and other sector-specific red flags.
Company formation, nominee or administrative services, ownership complexity, registered-address services and the purpose of the structure.
Customer risk can change after onboarding. Ownership may change, new jurisdictions may appear, transaction patterns can shift or new sanctions and risk information can become relevant.
A practical AML workflow therefore includes initial screening, periodic refresh and event-driven review rather than treating the customer file as complete after the first approval.
The Ministry of Economy & Tourism identifies relevant DNFBP categories that include real-estate brokers and agents, independent accountants and auditors, dealers in precious metals and stones, and trust or company service providers. The exact supervisory position depends on the licensed activity and circumstances.
The current federal framework includes Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025. The Ministry of Economy & Tourism also published updated DNFBP Guidelines in March 2026.
The Ministry of Economy & Tourism states that DNFBPs must register on goAML, the platform used for suspicious transaction and suspicious activity reporting to the UAE Financial Intelligence Unit.
CDD normally includes identifying and verifying the customer, identifying beneficial ownership and control, understanding the purpose of the relationship and applying a risk rating that drives the level of due diligence.
Cabinet Resolution No. 134 of 2025 and the 2026 DNFBP Guidelines require relevant transaction and due-diligence records to be retained for at least five years, with the exact starting point depending on the type of record and event.
Yes, but an AML policy is most useful when it is connected to risk assessment, CDD forms, screening, escalation, training, recordkeeping and management oversight.
No. We can help organise the compliance framework and evidence. Regulatory interpretation, enforcement decisions and formal legal representation remain with the competent authorities and appropriately qualified legal advisers where required.
Tell us your licensed activity, supervisory position and the current state of your AML files. We can scope a risk assessment, policy review, goAML readiness or remediation project.