What is an Enterprise-Wide Risk Assessment for a DNFBP in the UAE?

What is an Enterprise-Wide Risk Assessment for a DNFBP in the UAE?

An Enterprise-Wide Risk Assessment (EWRA) is a documented exercise in which a DNFBP identifies, understands, and assesses the money laundering, terrorist financing, and proliferation financing risks across its whole business. It looks at customer types, geographies, products and services, delivery channels, and transaction patterns, and it takes account of the findings of the UAE National Risk Assessment.

The EWRA is the foundation of the risk-based approach. The risk rating it produces should drive the calibration of due diligence, monitoring, and controls, so that higher-risk areas receive more attention. The assessment must be documented, kept up to date on an ongoing basis, retained for at least five years, and made available to the supervisory authority on request.

Legal Reference (UAE):

· Federal Decree-Law No. 10 of 2025, Article 19 - requires entities to identify, assess, document, and update their risks and retain the risk assessment.

· Cabinet Resolution No. 134 of 2025 (Executive Regulations), Article 5 - internal policies must be proportionate to the assessed risks.

For more details, consult the full text of Federal Decree-Law No. 10 of 2025 or seek guidance from your AML compliance officer.

AML compliance self-assessment tool for DNFBPs