What information security standards must support AML controls at UAE gaming operators?
Licensed gaming operators are expected to maintain an Information Security Management System aligned with international best practice, typically ISO/IEC 27001, and to undergo periodic independent vulnerability assessment and penetration testing. This sits within the technical compliance layer of the sector’s supervisory framework and directly supports AML obligations.
The connection is practical rather than theoretical. Player due diligence records, transaction histories, screening results and suspicious activity reports are the evidence base for the entire AML programme. If those records can be altered, deleted or accessed without authorisation, the operator cannot demonstrate that due diligence was performed or that a freeze was applied at the time claimed. Confidentiality controls also underpin the prohibition on tipping off, since uncontrolled access to case files is a realistic route by which a player learns they have been reported.
Supervisory activity in this area covers implementation of the management system, product and platform certification by independent testing laboratories, change management and security reviews, and ongoing monitoring through structured reporting and risk-based audits. Records supporting these controls should be retained on the same five-year basis as other AML documentation.
Legal Reference (UAE):
· Commercial Gaming Policy Paper, Section 2.1.2 — Information Security Management System aligned with ISO/IEC 27001 and periodic VAPT
· Cabinet Resolution No. 134 of 2025, Article 25 — record retention and availability to competent authorities
For more details, consult the full text of the Commercial Gaming Policy Paper or seek guidance from your AML compliance officer.