How often must a UAE regulated entity update its enterprise-wide risk assessment?
A UAE regulated entity must review and update its enterprise-wide risk assessment at least once a year, and promptly whenever a significant risk factor changes. Material triggers include launching a new product or service, entering a new market or delivery channel, onboarding higher-risk customer types, or a shift in the national threat picture such as an updated National Risk Assessment or new sanctions exposure.
The underlying law requires risks to be identified, assessed, documented and continuously updated, so a one-off assessment left unchanged will not satisfy supervisors. The methodology and its results should be documented and retained so the Supervisory Authority can review them on request.
Legal Reference (UAE):
· Federal Decree-Law No. 10 of 2025, Article 19(1)(a) — obligation to continuously update the risk assessment and retain the study for the Supervisory Authority.
· Cabinet Resolution No. 134 of 2025 — Executive Regulations specifying the risk-based approach and review requirements.
For more details, consult the full text of Federal Decree-Law No. 10 of 2025 or seek guidance from your AML compliance officer.