Must UAE businesses consider National Risk Assessment findings in their own risk assessment?
Yes. UAE financial institutions, DNFBPs and virtual asset service providers must take account of the National Risk Assessment when building and calibrating their own risk assessment and customer due diligence. The law expressly requires customer due diligence scope to be set with due regard to the outcomes of the national risk assessment, which means the NRA is not optional background reading but a direct input into a firm’s controls.
In practice, this means aligning your inherent-risk scoring with the sectors and typologies the NRA flags as high risk, and being able to show a supervisor how NRA findings shaped your policies, monitoring rules and enhanced due diligence triggers.
Legal Reference (UAE):
· Federal Decree-Law No. 10 of 2025, Article 19(1)(b) — CDD measures must have due regard to the outcomes of the national risk assessment.
· Federal Decree-Law No. 10 of 2025, Article 19(1)(d) — internal policies must manage and mitigate identified risks and be reviewed and updated continuously.
For more details, consult the full text of Federal Decree-Law No. 10 of 2025 or seek guidance from your AML compliance officer.