What are the core AML obligations of financial institutions and DNFBPs in the UAE?

What are the core AML obligations of financial institutions and DNFBPs in the UAE?

Financial institutions, DNFBPs and virtual asset service providers share a set of core obligations under the UAE AML law. They must identify, understand, assess, document and continuously update their financial crime risks using a risk-based approach, and retain the risk assessment for the supervisory authority.

They must implement customer due diligence and ongoing monitoring; refrain from opening or maintaining anonymous, fictitious or numbered accounts; establish internal policies, controls and procedures approved by senior management and applied across branches and majority-owned subsidiaries; implement targeted financial sanctions instructions without delay; and retain all transaction records for prompt availability to the authorities. They must also report suspicious transactions to the Financial Intelligence Unit. These duties apply proportionately to the nature and size of the business, but none of them are optional. The Executive Regulations set the minimum content for each requirement.

Legal Reference (UAE):

ยท Federal Decree-Law No. 10 of 2025, Article 19 - core preventive obligations of regulated entities.

For more details, consult the full text of Federal Decree-Law No. 10 of 2025 or seek guidance from your AML compliance officer.

AML regulations for DNFBPs in the UAE