What internal AML controls must UAE gaming operators put in place?

What internal AML controls must UAE gaming operators put in place?

UAE gaming operators must put in place internal policies, controls, and procedures proportionate to the size and nature of their business to manage and mitigate money laundering and terrorist financing risks. These must be documented, approved by senior management, kept up to date, and tested through an independent audit function.

Core elements include a business risk assessment, customer due diligence and enhanced due diligence procedures, ongoing transaction monitoring, sanctions and PEP screening, record-keeping, a suspicious transaction reporting process, and staff training. The operator must appoint an independent compliance officer at management level to run the programme. The sector policy paper also encourages technology-driven monitoring given the volume and speed of gaming transactions. Controls should be reviewed whenever new products, payment methods, or technologies are introduced, because these can create fresh vulnerabilities.

Legal Reference (UAE):

· Cabinet Resolution No. 134 of 2025 (Executive Regulations), Article 21 — requires internal policies, controls, procedures, and an independent audit function.

· Cabinet Resolution No. 134 of 2025 (Executive Regulations), Article 24 — requires assessment of risks arising from new products and technologies.

For more details, consult the full text of Cabinet Resolution No. 134 of 2025 or seek guidance from your AML compliance officer.

AML Regulations for Commercial Gaming Operators in UAE