Do DNFBPs need an independent AML audit in the UAE?

Do DNFBPs need an independent AML audit in the UAE?

Yes. A DNFBP is expected to subject its AML programme to an independent audit that periodically tests whether the policies, procedures, and controls are adequate and are working in practice. The audit is a distinct assurance function, separate from the day-to-day compliance role, and it should report gaps and weaknesses so senior management can act on them.

The reviewer should be suitably qualified, aware of current regulatory requirements, and familiar with the specific obligations of the DNFBP sector concerned. The scope should cover the risk assessment, customer due diligence, sanctions screening, transaction monitoring, reporting, record keeping, and training. Findings and the remediation of them should be documented and retained.

Legal Reference (UAE):

· Federal Decree-Law No. 10 of 2025, Article 19 - requires internal policies, controls, and procedures that are reviewed and updated on an ongoing basis.

· Cabinet Resolution No. 134 of 2025 (Executive Regulations), Article 5 - requires monitoring and assessment of the effectiveness of AML controls.

For more details, consult the full text of Federal Decree-Law No. 10 of 2025 or seek guidance from your AML compliance officer.

Conducting independent AML audits in DNFBPs