UAE AML Compliance for Businesses: A Practical 2026 Guide
Understand UAE AML compliance under the 2025 framework, including risk assessment, CDD, beneficial ownership, sanctions screening, goAML reporting and records.

Anti-money-laundering compliance is not only a concern for banks. In the UAE, regulated financial institutions, designated non-financial businesses and professions, virtual asset service providers and certain non-profit organisations all operate within a risk-based framework designed to prevent money laundering, terrorist financing and proliferation financing.
The framework was materially refreshed by Federal Decree-Law No. 10 of 2025, which took effect on 14 October 2025, and Cabinet Resolution No. 134 of 2025, effective from 14 December 2025. For businesses in scope, compliance requires more than registering on a portal. It involves understanding risk, identifying customers and beneficial owners, monitoring relationships, screening relevant parties, reporting suspicion and keeping evidence that the controls actually operate.
UAE AML compliance at a glance
| Control area | Practical purpose |
|---|---|
| Enterprise risk assessment | Identifies how customers, services, countries and delivery channels expose the business to risk. |
| Customer due diligence | Establishes and verifies who the customer is and why the relationship or transaction makes sense. |
| Beneficial ownership | Identifies the natural person who ultimately owns or controls a legal person or arrangement. |
| Enhanced due diligence | Applies stronger checks where the assessed risk is higher. |
| Ongoing monitoring | Checks that activity remains consistent with the known customer profile and expected purpose. |
| Sanctions screening | Helps identify parties subject to targeted financial sanctions and supports required action. |
| goAML reporting | Provides the UAE Financial Intelligence Unit's channel for relevant reports, including suspicious activity or transactions. |
| Records and governance | Demonstrates what was checked, decided, reported, approved and reviewed. |
What changed in the 2025 AML framework?
Federal Decree-Law No. 10 of 2025 replaced the previous 2018 federal AML law. It expressly covers money laundering, terrorist financing and proliferation financing and recognises supervisory authorities for financial institutions, DNFBPs, virtual asset service providers and non-profit organisations. The law also reinforces the Financial Intelligence Unit, national coordination and a framework for administrative penalties.
Cabinet Resolution No. 134 of 2025 supplies the executive rules. It contains detailed provisions concerning the nature of covered activities, risk identification, customer due diligence, beneficial owners, politically exposed persons, correspondent relationships, reporting, internal policies, record keeping and supervisory expectations.
A company should therefore avoid relying on an old compliance manual that simply cites the repealed legislation. Existing procedures should be reviewed against the current law, executive regulations, supervisory guidance and any sector-specific instructions.
Which non-financial businesses may be DNFBPs?
The UAE framework applies to specified non-financial activities when the relevant legal conditions are met. Common examples include:
- Real estate brokers and agents when concluding transactions for customers involving the purchase or sale of real estate.
- Dealers in precious metals and precious stones when conducting qualifying cash transactions at or above the applicable threshold.
- Independent accountants, auditors and certain professional service providers when carrying out covered activities.
- Lawyers, notaries and other independent legal professionals when preparing, conducting or executing specified transactions for clients.
- Company and trust service providers when forming legal persons, providing registered-office or related services, arranging nominee functions or performing other covered services.
The trade licence name alone does not always settle the question. A business should review the activities it actually performs, the capacity in which it acts and the relevant legal definitions. The Ministry of Economy and Tourism provides AML information and a DNFBP questionnaire to assist businesses under its supervision.
Step 1: appoint clear AML responsibility
AML compliance needs an accountable owner. Depending on the organisation and regulatory requirements, this may be a compliance officer or money-laundering reporting officer with sufficient competence, independence, information access and authority.
Senior management remains important. Assigning day-to-day work to one employee does not remove the need for leadership to approve policies, understand material risks, provide resources and respond to significant findings. A very small business may use proportionate arrangements, but it should still document who performs each control and who makes escalation decisions.
Step 2: complete a business-wide risk assessment
A useful enterprise risk assessment is specific to the business. It should consider inherent exposure and the strength of existing controls across areas such as:
- Customer type, ownership complexity and expected activity.
- Countries connected to customers, beneficial owners, payments and transactions.
- Products and services offered.
- Transaction values, frequency and payment methods.
- Face-to-face, remote and intermediary-led relationships.
- Use of cash, virtual assets or opaque ownership vehicles.
- Exposure to politically exposed persons or higher-risk sectors.
- Sanctions, adverse information and suspicious behavioural indicators.
The output should classify risk using a rational methodology, identify control gaps and produce an action plan. Copying a generic low-risk conclusion without evidence is unlikely to help during an inspection. The assessment should be reviewed periodically and when a significant change occurs, such as entering a new market, launching a new product or changing delivery channels.
Step 3: perform customer due diligence
Customer due diligence is the foundation of the control environment. The business should identify the customer, verify identity using reliable and independent documents or information, understand the purpose and intended nature of the relationship, and identify the person acting on the customer's behalf.
For a legal person, the process normally involves understanding its legal form, registration, ownership and control structure. The business should identify and take reasonable measures to verify the beneficial owner rather than stopping at the first corporate shareholder.
Documents are only part of the process. The information should make commercial sense when considered together. For example, the proposed service, ownership structure, source of funds and payment route should be consistent with the customer's profile and stated purpose.
Step 4: identify and verify beneficial owners
A beneficial owner is a natural person who ultimately owns or controls the customer or on whose behalf a transaction is conducted. Where ownership is layered across companies or jurisdictions, the analysis should trace the chain until the relevant natural person or persons are identified under the applicable test.
The file should show the reasoning, not merely contain a percentage copied from a form. Where no natural person is identified through ownership, the applicable control and senior-management tests must be considered in accordance with current rules. Any discrepancy, uncertainty or unusual complexity should trigger further checks.
This customer-level AML exercise is related to, but not identical with, the company's separate obligation to maintain and update its own beneficial-owner records with the competent licensing authority.
Step 5: apply enhanced measures when risk is higher
A risk-based approach does not mean refusing every higher-risk customer. It means applying controls proportionate to risk and declining or exiting relationships when the risk cannot be understood or managed.
Enhanced due diligence may include obtaining more information about ownership, business activities, source of funds or wealth, reasons for transactions, expected activity and connected parties. It can also require senior-management approval, closer monitoring and more frequent refreshes.
Politically exposed persons require specific attention under the regulations. Screening should consider the customer, beneficial owner and relevant close connections, followed by the measures required for the applicable category and risk.
Step 6: screen for targeted financial sanctions
Sanctions compliance should be built into onboarding and ongoing monitoring rather than treated as an occasional internet search. A business should have a process to screen relevant customers, beneficial owners and connected parties against applicable lists and to identify potential matches promptly.
A possible match should be escalated using a documented procedure. Staff should not inform a customer in a way that could compromise required action or reporting. Because targeted financial sanctions can involve immediate legal consequences, businesses should follow current UAE Executive Office, supervisory-authority and reporting instructions.
Step 7: monitor the relationship and transactions
Due diligence is not complete once a file is opened. Ongoing monitoring compares actual behaviour with what the business understands about the customer, expected activity and risk profile.
Warning signs depend on the sector. Examples can include unexplained third-party payments, unusual cash use, rapid changes in ownership, transactions inconsistent with the stated business, reluctance to provide beneficial-owner information, artificial complexity, repeated changes in instructions or activity involving locations without a clear commercial connection.
A warning sign does not automatically prove criminal activity. It is a reason to examine the facts, obtain appropriate information and decide whether suspicion exists. The review and decision should be recorded.
Step 8: register for and use goAML where required
goAML is the UAE Financial Intelligence Unit's reporting platform. The Ministry of Economy and Tourism states that all DNFBPs must register. The registration process begins through the Services Access Control Manager, followed by registration within goAML.
Registration is not the final objective. An in-scope business must ensure that authorised users can access the system, reporting details remain current and relevant personnel understand the types of reports and filing process.
Suspicious Transaction Reports and Suspicious Activity Reports are used to communicate relevant suspicion to the FIU. The reporting decision should not be delayed merely because every fact is not proven; the legal test concerns suspicion and the applicable reporting obligation. Businesses must also protect confidentiality and avoid tipping off.
Step 9: maintain complete records
A regulator or inspector should be able to reconstruct what happened. The file should contain the customer information, verification evidence, beneficial-owner analysis, risk rating, screening results, transaction review, approvals, escalations, reports and the basis for important decisions.
Records must be retained for the period and in the manner required by current law and regulatory instructions. They should be retrievable, secure and protected from unauthorised alteration or disclosure. Digital systems can help, but a software subscription does not replace governance or human judgment.
Step 10: train staff and test the controls
Training should be relevant to the employee's role. Frontline employees need to recognise warning signs and know how to escalate them. Compliance personnel need deeper knowledge of risk, reporting and investigation. Senior management should understand its oversight responsibilities.
Testing should ask whether the controls work in practice. A sample review might examine whether identification documents were valid, beneficial owners were traced correctly, risk ratings were supported, screening was completed, high-risk approvals were obtained and periodic reviews occurred on time.
Common AML compliance mistakes
- Assuming AML rules apply only to banks.
- Registering on goAML but having no internal reporting procedure.
- Accepting a corporate shareholder without tracing the natural beneficial owner.
- Using one risk rating for every customer.
- Collecting documents without checking whether the transaction makes sense.
- Screening only at onboarding and never again.
- Failing to document why an alert was closed.
- Allowing an old compliance policy to cite repealed legislation.
- Treating staff training as a one-time attendance certificate.
- Disclosing an internal suspicion or report to the customer.
A practical 2026 implementation checklist
- Confirm whether the business and its actual activities fall within a regulated category.
- Identify the competent supervisory authority and current sector guidance.
- Appoint responsible personnel and document governance.
- Update policies for Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025.
- Complete and approve a business-wide risk assessment.
- Design risk-based onboarding, CDD and beneficial-owner procedures.
- Implement PEP, sanctions and adverse-information screening.
- Define higher-risk approval and enhanced-due-diligence steps.
- Register and maintain authorised access to goAML where required.
- Create confidential internal escalation and external reporting procedures.
- Set record-retention, security and retrieval controls.
- Train personnel according to their roles.
- Test samples, track deficiencies and record remediation.
- Review the framework after material business or regulatory changes.
Official references
- UAE Legislation: Federal Decree-Law No. 10 of 2025
- UAE Legislation: Cabinet Resolution No. 134 of 2025
- Ministry of Economy and Tourism: Anti-money-laundering information for DNFBPs
- Ministry of Economy and Tourism: AML and goAML questions
- UAE Financial Intelligence Unit: goAML web-access registration
- UAE FIU: goAML registration guide
Need help organising your UAE business compliance records and next steps? Call Al Shamil Zone on 800 2794, contact us through WhatsApp, or email info@shamilservices.ae.
This article provides general information and is not legal or regulatory advice. AML obligations depend on the business, activity, supervisory authority, customer and transaction. Refer to the Arabic legislation where interpretation matters and obtain appropriate professional guidance.
Ready to get started? Contact Al Shamil Zone by phone at 800 2794, via WhatsApp at +971 54 586 6222, or email info@shamilservices.ae.


