Proud of UAE  [email protected]       [email protected]        +97142500251 97142500251+       +971507869887 971507869887+      WhatsApp

What Must an MLRO Report Contain Under UAE AML Law?

What an MLRO Report Is

An MLRO report is a formal periodic submission prepared by the Money Laundering Reporting Officer of a financial institution or Designated Non-Financial Business and Profession (DNFBP), reviewing the organisation’s AML/CFT compliance position over a defined period. It is addressed to senior management and, separately, to the relevant supervisory authority. Its purpose is not to confirm that everything is working correctly. Its purpose is to give senior management and the regulator an honest, evidence-based assessment of where the compliance programme stands, what gaps exist, and what actions are being taken to address them.

The MLRO is personally accountable for the quality and accuracy of this report. Under Federal Decree-Law No. 10 of 2025, the personal liability of MLROs for AML compliance failures has been explicitly extended beyond institutional liability. An MLRO who submits a superficial or incomplete report, or who fails to surface material compliance deficiencies, is not simply producing a poor document. They are creating personal regulatory exposure.

The Legal Basis for MLRO Reporting in the UAE

The mandatory submission of MLRO reports is governed by Cabinet Resolution No. 134 of 2025, effective 14 December 2025, which replaced Cabinet Decision No. 10 of 2019 as the implementing regulation under the UAE AML/CFT framework. The submission obligation applies to all financial institutions and DNFBPs operating in the UAE.

Reports are submitted to two separate recipients:

  • Senior management of the reporting entity, giving the board and executive team the information they need to discharge their own oversight responsibilities
  • The relevant supervisory authority: financial institutions submit to the Central Bank of the UAE (CBUAE); DNFBPs submit to the Ministry of Economy (MoE)

The frequency of submission is semi-annual. Two reports are required each year, covering the first and second halves of the calendar year respectively. A report that arrives late, covers only part of the required content, or is submitted to only one of the two required recipients is a non-compliant submission regardless of its substantive quality.

Need Expert Advice?

Contact the team at Farahat & Co. for professional support and expert insights for businesses operating in the UAE.

The Core Contents of an MLRO Report

The report must cover the organisation’s full AML/CFT compliance position for the reporting period. 10 elements are required in a complete report:

1. Entity and MLRO Identification

Full details of the reporting entity: legal name, licence number, registration details, and the supervisory authority to which the report is addressed. Full details of the MLRO: name, qualifications, contact information, and date of appointment. Where the MLRO has changed during the reporting period, both the outgoing and incoming officers should be identified.

2. Suspicious Activity Report Summary

A full account of all Suspicious Transaction Reports (STRs) and Suspicious Activity Reports (SARs) filed through the FIU’s goAML platform during the reporting period. For each report: the date of submission, the nature of the suspicious activity, whether it was filed on the basis of a confirmed or suspected transaction, and any subsequent action taken by the FIU or law enforcement. Where no STRs were filed during the period, this must be explicitly stated and the basis for the nil position explained.

3. Customer Due Diligence and Risk Assessment

An assessment of how CDD and risk assessment procedures operated during the period. This covers the volume of new customers onboarded, the risk distribution across the customer base (high, medium, low), instances where Enhanced Due Diligence was applied, the triggers for those EDD decisions, and any cases where onboarding was declined on AML grounds. Under VARA Version 2.0 (May 2025), licensed VASPs must now conduct quarterly AML/CFT client risk assessments; this should be reflected in the MLRO report for entities in scope.

4. Transaction Monitoring

A summary of how the transaction monitoring system operated during the period: the number of alerts generated, how many were investigated, how many were escalated to STR stage, and how many were cleared after review. Where the monitoring system produced a significant number of false positives, or where material gaps in coverage were identified, these should be disclosed with the steps being taken to address them.

5. Sanctions Screening

Confirmation that screening against the UAE Local Terrorist List, UNSC consolidated list, and other applicable sanctions frameworks was conducted for all customers and beneficial owners throughout the period. Any matches, near-matches, or screening system failures identified should be reported with the resolution outcome for each.

6. Record Keeping Compliance

Confirmation that CDD records, transaction records, and STR filings are being retained for the required minimum period of 5 years following the end of the business relationship or transaction. Where record-keeping gaps were identified, the corrective actions taken should be summarised.

7. Staff Training

A summary of AML/CFT training delivered during the period: who was trained, what training was provided, whether all relevant staff have completed the required training within the applicable deadlines, and the results of any testing or assessment. Where training gaps exist, they should be identified alongside the remediation plan.

8. AML Policy and Procedure Review

Confirmation of whether the AML/CFT policy was reviewed during the period and whether any updates were made. Where updates were required by regulatory changes, including the transition to Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025, the report should confirm that the policy now references current legislation rather than the repealed 2018/2019 instruments.

9. Identified Deficiencies and Recommendations

A clear, honest account of any AML/CFT compliance deficiencies identified during the period, their root causes, the risk they present, and the specific remediation actions being taken. Each deficiency should have a named owner and a deadline for resolution. This section is the most important in the report from a regulatory perspective. A report that identifies no deficiencies across a full six-month period in a complex business environment will attract supervisory scepticism rather than approval.

10. Emerging Risks

An assessment of AML/CFT risks the organisation expects to face in the upcoming period, including changes in the customer base, new products or services, regulatory developments, and sector-specific risk trends. For businesses operating in the virtual asset space, this section should reference the current VARA enforcement environment and any evolving typologies relevant to the business’s activities.

What Distinguishes a Strong MLRO Report From a Weak One

A weak MLRO report lists activities: training was conducted, monitoring was performed, no STRs were filed. A strong MLRO report analyses outcomes: what the training achieved, what the monitoring found, why no STRs were filed and whether that reflects a genuinely low-risk period or an underperforming detection capability.

Supervisory authorities in the UAE have become increasingly sophisticated in how they read these reports, particularly in the lead-up to the FATF 2026 mutual evaluation of the UAE’s AML/CFT framework. A report that reads as a compliance checklist rather than a genuine management tool will be treated accordingly.

Frequently Asked Questions (FAQs)

How often must an MLRO report be submitted in the UAE?

Semi-annually, under Cabinet Resolution No. 134 of 2025. Two reports are required per year, submitted to both senior management and the relevant supervisory authority (CBUAE for financial institutions, Ministry of Economy for DNFBPs).

What law governs MLRO reporting in the UAE?

Federal Decree-Law No. 10 of 2025 (effective 14 October 2025) is the primary AML/CFT law. Cabinet Resolution No. 134 of 2025 (effective 14 December 2025) is the implementing regulation that replaced Cabinet Decision No. 10 of 2019. Any MLRO report still citing the 2019 decision as the governing instrument is referencing repealed legislation.

Can an MLRO be personally liable for a deficient report?

Yes. Federal Decree-Law No. 10 of 2025 explicitly extended personal enforcement liability to MLROs for AML compliance failures. Submitting a report that fails to surface material deficiencies, or that covers only the required content superficially, creates personal regulatory exposure for the MLRO in addition to institutional liability for the entity.

What happens if an MLRO report is submitted late or incompletely?

Late or incomplete submission is a compliance failure subject to administrative penalties under the UAE AML framework. The Ministry of Economy imposed AED 42 million in DNFBP fines in the first half of 2025 alone, reflecting an enforcement posture that treats procedural failures as seriously as substantive ones.

Need Expert Advice?

Contact the team at Farahat & Co. for professional support and expert insights for businesses operating in the UAE.

How Farahat & Co. Can Help

Farahat & Co. supports financial institutions and DNFBPs across the UAE in preparing MLRO reports that meet the requirements of Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025, covering all required content areas, identifying genuine compliance deficiencies, and providing the remediation guidance that makes the report a management tool rather than a regulatory formality.

Contact Farahat & Co. today to discuss your AML compliance and MLRO reporting requirements.

Shahnaz Kaushar is a senior Trademark and Intellectual Property (IP) Expert. She has handled some of the firm’s complex, high-profile cases – many involving the protection of trademark and IP rights.
×

Hold On!

Business decisions are easier with the right guidance.