Proud of UAE  [email protected]       [email protected]        +97142500251 97142500251+       +971507869887 971507869887+      WhatsApp

UAE Anti-Money Laundering Law 2025: What Changed Under FDL 10

What Changed Under the UAE’s Anti-Money Laundering Law in 2025

The UAE replaced its primary anti-money laundering statute in 2025. Federal Decree-Law No. 10 of 2025 came into effect on 14 October 2025 and formally supersedes Federal Decree-Law No. 20 of 2018, which had governed AML/CFT compliance for seven years. Two months later, the implementing regulation followed: Cabinet Resolution No. 134 of 2025 took effect on 14 December 2025, replacing Cabinet Decision No. 10 of 2019. Together, these two instruments set out the current UAE anti-money laundering law, and businesses still relying on guidance written against the 2018/2019 framework are working from rules that no longer apply.

This article focuses on what actually changed between the old regime and the new one: the expanded scope of regulated entities, the new offenses added to the law, the wider criminal exposure for companies and their compliance officers, and the revised penalty structure. It is not a general introduction to AML in the UAE; it is a comparison of the two regimes for businesses that need to know what is different now.

FDL No. 20 of 2018 vs Federal Decree-Law No. 10 of 2025: What Actually Changed

The table below sets out the practical differences between the repealed law and the law currently in force.

AreaFederal Decree-Law No. 20 of 2018 (repealed)Federal Decree-Law No. 10 of 2025 (current)
Implementing regulationCabinet Decision No. 10 of 2019Cabinet Resolution No. 134 of 2025, effective 14 December 2025
Proliferation financingNot treated as a standalone criminal offenseExplicit standalone offense covering financing of weapons and dual-use goods
Virtual asset service providers (VASPs)Addressed indirectly, without a dedicated licensing and conduct regimeExplicitly regulated; anonymity-enhancing virtual assets that obscure the origin or ownership of funds are prohibited outright
Corporate criminal liabilityEnforcement centered mainly on individual officersCorporate entities can be held criminally liable in their own right, in addition to individual officers
MLRO personal liabilityCompliance duties framed as an internal governance functionPersonal liability for the Money Laundering Reporting Officer is expanded; reporting failures can attract individual penalties, not only a corporate fine
Maximum corporate fineLower statutory ceilingFines of up to AED 100 million for serious violations
Free zone coverageApplication to financial free zones was often argued on a case-by-case basisScope is stated to extend to entities in free zones, including DIFC and ADGM, dealing in cross-border value, cash, virtual assets, or high-value goods

The pattern across every row is the same: the 2025 law closes gaps the 2018 law left open, particularly around virtual assets, corporate accountability, and the personal exposure of the person actually filing the reports.

Need Expert Advice?

Contact the team at Farahat & Co. for professional support and expert insights for businesses operating in the UAE.

MLRO Personal Liability Under the 2025 AML Law

Every regulated entity, whether a financial institution or a DNFBP, must appoint a Money Laundering Reporting Officer responsible for suspicious transaction monitoring, filing Suspicious Transaction Reports (STRs) through the goAML platform, and keeping the compliance program current. Under Federal Decree-Law No. 10 of 2025, the MLRO’s exposure is no longer limited to an internal disciplinary matter. Personal liability is extended: an MLRO who fails to escalate a genuinely suspicious transaction, or who signs off on inadequate due diligence records, can face individual penalties alongside any fine levied on the company itself.

The MLRO is also required to submit a compliance report on a semi-annual basis. That report goes to the entity’s senior management, and separately to the Central Bank of the UAE (CBUAE) for financial institutions, or to the Ministry of Economy for DNFBPs. Missing this reporting cycle, or filing an incomplete report, is now treated as a compliance failure attributable to the MLRO individually, not just to the business.

For a worked illustration: if a real estate brokerage’s MLRO receives an internal alert on a cash-heavy property purchase and does not file an STR within a reasonable window, both the brokerage and the MLRO named on file can be investigated. Under the 2018 regime, the practical consequence usually stopped at the corporate level. Under the 2025 law, it does not.

Who Must Comply With the UAE’s 2025 AML Law

Federal Decree-Law No. 10 of 2025 widens the list of entities that fall within scope. Regulated categories now include:

  • Financial institutions: banks, insurers, securities firms, money-exchange houses, and payment or remittance services.
  • Designated Non-Financial Businesses and Professions (DNFBPs): real estate agents and brokers, auditors and accountants, corporate and trust service providers, dealers in precious metals and stones, and independent legal professionals.
  • Virtual Asset Service Providers (VASPs): exchanges, custodial wallet providers, and other crypto-asset businesses, which VARA requires to run quarterly AML/CFT risk assessments in addition to the federal obligations.
  • Entities handling cross-border value movement, cash transactions, virtual assets, or high-value goods, including those operating from financial free zones such as DIFC or ADGM.

A business that assumed it sat outside AML scope because it is not a bank should re-check that assumption against the current law. Several categories, particularly real estate brokerages, precious metals dealers, and corporate service providers, are now explicitly captured where they may not have been under the 2018 framework.

Also check: AML Compliance Services in UAE

Core AML Compliance Obligations Under Federal Decree-Law No. 10 of 2025

The obligations themselves are not new in concept, but the 2025 framework tightens how they must be carried out.

Customer Due Diligence (CDD) and KYC. Entities must verify client identity using a passport, Emirates ID, or trade license, and must establish beneficial ownership before onboarding. A risk-based approach applies: standard due diligence for ordinary clients, and enhanced due diligence for higher-risk profiles such as politically exposed persons, complex ownership chains, or virtual-asset counterparties.

Continuous monitoring. Transactions must be screened on an ongoing basis, not only at onboarding, against domestic and international sanctions lists and PEP registers.

Registration and reporting. Regulated entities must register on the goAML platform and file an STR whenever a transaction raises a genuine suspicion. Customer identification records, transaction records, beneficial ownership information, and compliance documentation must be retained.

Governance. A documented AML policy, regular risk assessments, internal audits of the compliance function, and staff training are required, overseen by the appointed MLRO and reported to senior management.

Must check: Declaration of Ultimate Beneficial Ownership (UBO) in UAE

A Worked Example: Applying the New AML Obligations

Consider a mid-sized precious metals trading firm in the UAE that deals in gold bars and jewellery, with several clients paying in cash for transactions above AED 55,000. Under the 2018 framework, this firm’s AML obligations were often treated as a lower priority since enforcement against DNFBPs in this category was inconsistent.

Under Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025, the same firm now has clearly defined duties: it must register as a regulated DNFBP on goAML, appoint an MLRO, run enhanced due diligence on any client paying in cash above the firm’s risk threshold, document the source of funds where the transaction pattern looks unusual, and file an STR if a client structures multiple purchases to avoid a reporting threshold. If the firm’s MLRO does not act on an internal red flag, the firm faces exposure to a corporate fine that can reach AED 100 million for serious violations, and the MLRO personally faces investigation under the expanded liability provisions described above. That is the practical difference the 2025 law makes for a business that, under the old regime, might reasonably have assumed it was a lower enforcement priority.

Penalties and Enforcement Under the 2025 AML Law

Federal Decree-Law No. 10 of 2025 restructures both the scale and the reach of AML penalties.

  • Corporate fines of up to AED 100 million for serious money laundering, terrorist financing, or proliferation financing violations.
  • Criminal penalties, including imprisonment, for individuals and senior officers found to be personally involved in violations.
  • Administrative sanctions, including license suspension, deregistration, and business bans, layered on top of financial penalties.
  • Expanded powers for the Financial Intelligence Unit (FIU) to freeze assets, suspend transactions, request further information, and coordinate with foreign counterpart authorities.

The combination of a higher fine ceiling, standalone corporate criminal liability, and personal MLRO exposure is what distinguishes enforcement under the 2025 law from enforcement under the 2018 law. A violation that previously resulted in a fine against the company alone can now also result in individual consequences for the officer who should have caught it.

Related: Forensic Audit Services | Certified Fraud Examiner

Practical Steps for Businesses Adapting to the UAE AML Law 2025

Businesses newly captured by the expanded scope, or already regulated but working from outdated procedures, should work through the following before an inspection or audit exposes the gap:

  1. Re-confirm regulated status against the current definitions in Federal Decree-Law No. 10 of 2025, particularly for real estate, precious metals, legal services, and corporate service providers that may not have been captured under the 2018 law.
  2. Update CDD and KYC procedures to reflect the risk-based standard versus enhanced due diligence distinction, and document beneficial ownership for every client relationship.
  3. Confirm the entity is registered on goAML and that STR filing responsibility sits clearly with a named MLRO.
  4. Review whether the MLRO’s semi-annual reporting line to senior management, and to CBUAE or the Ministry of Economy as applicable, is documented and current.
  5. Run an internal gap analysis comparing existing AML policies against Cabinet Resolution No. 134 of 2025, since procedures written against the 2019 Cabinet Decision may no longer satisfy the current implementing regulation.

Businesses operating across the UAE, including those in financial free zones, should treat this as a compliance priority rather than an administrative formality, given the scale of the penalties now attached to non-compliance.

Frequently Asked Questions

What is Federal Decree-Law No. 10 of 2025 and when did it take effect?

Federal Decree-Law No. 10 of 2025 is the UAE’s current anti-money laundering and counter-terrorism financing law. It came into effect on 14 October 2025 and replaced Federal Decree-Law No. 20 of 2018, which had been in force since 2018.

What is Cabinet Resolution No. 134 of 2025 and how is it different from the primary law?

Cabinet Resolution No. 134 of 2025 is the implementing regulation issued under Federal Decree-Law No. 10 of 2025. It took effect on 14 December 2025 and replaced Cabinet Decision No. 10 of 2019. The federal law sets out the offenses and obligations; the Cabinet Resolution sets out the operational detail, such as due diligence procedures and reporting mechanics.

Which businesses became newly regulated under the 2025 AML law?

Real estate agents and brokers, dealers in precious metals and stones, corporate and trust service providers, and virtual asset service providers are all explicitly captured under Federal Decree-Law No. 10 of 2025. Several of these categories faced inconsistent enforcement under the 2018 law and should not assume they remain a lower priority.

How often must an MLRO report, and to whom?

An MLRO must submit a compliance report on a semi-annual basis. The report goes to the entity’s senior management, and separately to the Central Bank of the UAE for financial institutions, or to the Ministry of Economy for DNFBPs.

What are the maximum penalties for non-compliance under the current AML law?

Corporate fines can reach AED 100 million for serious violations. Individuals, including senior officers and the MLRO personally, can face criminal penalties including imprisonment. Regulators can also suspend a license, deregister the entity, or impose a business ban.

How can Farahat & Co. help my business comply with the 2025 AML regulations?

Farahat & Co. reviews existing AML policies against Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025, identifies gaps in CDD, KYC, and MLRO reporting procedures, and helps structure a compliance program suited to the entity’s regulated category.

Need Expert Advice?

Contact the team at Farahat & Co. for professional support and expert insights for businesses operating in the UAE.

How Farahat & Co. Can Help

Farahat & Co. reviews AML policies, MLRO reporting structures, and customer due diligence procedures against Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025, and helps regulated entities close the gaps left over from the 2018/2019 framework.

Contact Farahat & Co. today to discuss your AML compliance requirements.

×

Hold On!

Business decisions are easier with the right guidance.