What is a Customer Risk Assessment (CRA) for DNFBPs in the UAE?
A Customer Risk Assessment (CRA) is the process a DNFBP uses to rate the money laundering and terrorist financing risk posed by each customer, so that due diligence can be applied in proportion to that risk. It sits within the wider risk-based approach that every regulated firm must adopt, and it usually scores factors such as customer type, ownership structure, geography, product or service, and delivery channel.
Under UAE law a DNFBP must identify, understand, assess, document and continuously update its crime risks, taking account of the national risk assessment and retaining the study for the supervisor. The customer-level assessment flows from this: higher-risk customers, such as politically exposed persons or those connected to high-risk countries, attract enhanced due diligence and senior management approval, while genuinely low-risk customers may be eligible for simplified measures. The assessment should be refreshed when circumstances change.
Legal Reference (UAE):
· Cabinet Resolution No. 134 of 2025 (Executive Regulations), Article 41 requires firms to identify, assess and document crime risks and keep the assessment updated.
· Federal Decree-Law No. 10 of 2025, Article 19(1)(a) sets out the risk-based approach obligation.
For more details, consult the full text of Cabinet Resolution 134 of 2025 or seek guidance from your AML compliance officer.