What is an Enterprise-Wide Risk Assessment for a DNFBP in the UAE?

What is an Enterprise-Wide Risk Assessment for a DNFBP in the UAE?

An enterprise-wide risk assessment is the firm-level exercise of identifying, understanding, assessing and documenting the money laundering, terrorist financing and proliferation financing risks within the business scope, applying a risk-based approach. It is not a per-customer assessment. It looks at the firm as a whole: the customer types it serves, the products and services it offers, the delivery channels it uses, the countries it is exposed to, and the transactions it handles.

Three features are easy to miss. It must be documented, so an unwritten understanding of risk does not satisfy the obligation. It must be continuously updated rather than produced once and filed. And it must be retained and provided to the supervisory authority on request, which makes it one of the first documents an inspection will ask for. Its practical purpose is to set the calibration for everything else the firm does, because the depth of customer due diligence, the intensity of monitoring and the content of training are all meant to follow from it.

Legal Reference (UAE):

· Federal Decree-Law No. 10 of 2025, Article 19(1)(a), which requires the risks of the crime within the business scope to be identified, understood, managed, assessed, documented and continuously updated using a risk-based approach, with the assessment retained and provided to the supervisory authority on request.

· Cabinet Resolution No. 134 of 2025, Article 23, which requires enhanced measures where exposure arises to high-risk countries or countries with deficiencies in their AML, CFT and CPF systems.

Where the position is finely balanced, document your reasoning and raise it with your compliance officer.

Enterprise-wide risk assessment for DNFBPs in the UAE