What is a risk-based approach (RBA) under UAE AML law?

What is a risk-based approach (RBA) under UAE AML law?

A risk-based approach (RBA) means allocating AML resources and controls in proportion to the money laundering, terrorist financing and proliferation financing risk a business faces. Rather than treating every customer and transaction identically, a firm identifies where its risk is highest and applies stronger measures there, while using simplified measures for genuinely low-risk relationships.

Under UAE law the RBA is mandatory. Regulated entities must identify, understand, assess, document and continuously update their risks, then design customer due diligence, monitoring and internal policies that match those risks and the outcomes of the national risk assessment. The approach must be evidenced: supervisors expect a documented methodology showing why particular customers, products or geographies were rated as they were.

Legal Reference (UAE):

· Federal Decree-Law No. 10 of 2025, Article 19(1)(a) — risks must be managed using the risk-based approach and the multiple aspects of risk defined by the Executive Regulations.

· Cabinet Resolution No. 134 of 2025 — Executive Regulations detailing the risk-based approach and risk factors.

For more details, consult the full text of Federal Decree-Law No. 10 of 2025 or seek guidance from your AML compliance officer.

UAE AML/CFT laws guide