The Current Legal Foundation of UAE AML Law
The UAE’s Anti-Money Laundering and Counter-Terrorist Financing framework underwent its most significant overhaul since 2018 when two new instruments took effect in late 2025. Federal Decree-Law No. 10 of 2025, effective 14 October 2025, repealed Federal Decree-Law No. 20 of 2018 in its entirety and established the new primary AML/CFT law. Cabinet Resolution No. 134 of 2025, effective 14 December 2025, replaced Cabinet Decision No. 10 of 2019 as the implementing regulation.
These two instruments now constitute the operative legal foundation of UAE AML/CFT compliance. Any reference to the 2018 law as the current governing framework reflects outdated information — including content published in late 2025 that had not yet been updated to reflect the October 2025 repeal.
The 2025 law did not simply consolidate existing rules. It changed the legal framework in four materially significant ways that affect compliance obligations and personal liability across every category of regulated entity.
What Money Laundering Is Under UAE Law
Under Federal Decree-Law No. 10 of 2025, money laundering is defined as any act that involves funds derived from a criminal predicate offence — acquiring, possessing, using, converting, managing, transporting, or transferring such funds, or concealing or disguising their nature, source, location, disposition, movement, ownership, or rights relating to them.
A key feature carried over and strengthened from the 2018 framework is that money laundering is a standalone offence independent of the underlying predicate crime. A person can be prosecuted for money laundering and for the original crime that generated the proceeds simultaneously. The prosecution does not need to first obtain a conviction for the predicate offence before proceeding with a money laundering charge.
The 2025 law adds proliferation financing — the financing of the proliferation of weapons of mass destruction — as a third standalone principal offence alongside money laundering and terrorism financing. This is a structural change from the 2018 framework, where proliferation financing was addressed through targeted sanctions requirements rather than as an independent criminal category.
Need Expert Advice?
Contact the team at Farahat & Co. for professional support and expert insights for businesses operating in the UAE.
The Four Major Changes in the 2025 Law
1. Knowledge Can Now Be Inferred From Circumstances
The 2018 law required proof of actual knowledge that funds were of criminal origin to establish money laundering liability. The 2025 law changes this fundamentally: knowledge can now be inferred from objective circumstances. A business whose AML controls were inadequate — whose processes failed to identify red flags that a properly designed compliance programme would have caught — can face criminal and civil liability under the new standard without direct proof that anyone in the organisation actually knew the funds were connected to crime.
This is the most consequential change for compliance officers and business owners. The legal defence of “we didn’t know” has been materially weakened. The relevant question is now whether the business should have known — a standard that directly tests the quality of CDD procedures, transaction monitoring, and risk assessment.
2. Higher Penalty Ceiling
The maximum administrative penalty for legal persons has increased to AED 100 million under the 2025 law — double the AED 50 million ceiling under the 2018 framework. Article 20, which covers operating financial or DNFBP activities without proper authorisation or licensing, carries fines of between AED 200,000 and AED 10,000,000 alongside potential imprisonment for responsible individuals. Ministry of Economy administrative fines for DNFBP compliance failures range from AED 50,000 to AED 1,000,000 per violation.
3. Expanded Tipping-Off Offence
Under the 2018 law, tipping off required proof of intentional disclosure of a suspicious transaction report or investigation. Article 29 of Federal Decree-Law No. 10 of 2025 expands this significantly. The offence now covers:
- Intentional disclosure — as before
- Grossly negligent disclosures — where communication occurs through reckless disregard for whether it would compromise an investigation
- A broader category of conduct not limited to formal STR filings or official investigations
- Aggravated penalties where the tipping-off results in the loss of criminal proceeds
For law firms, accounting firms, real estate brokers, and other DNFBPs where regular client communication is a core part of business, this expansion requires more careful internal protocols around what can be communicated once a suspicious transaction report has been filed or is being contemplated.
4. Gaming Operators Added as DNFBPs
Cabinet Resolution No. 134 of 2025 added operators of commercial gaming activities to the DNFBP category for the first time, bringing them within the full scope of UAE AML/CFT obligations. Virtual asset service providers’ obligations have also been reinforced and clarified.
Who Must Comply — Financial Institutions and DNFBPs
The UAE AML framework applies to two broad categories of entity:
Financial Institutions
Banks, insurance companies, money exchange houses, investment firms, securities brokers, and other regulated financial services providers carry the fullest AML compliance obligations — including the most rigorous CDD requirements, transaction monitoring systems, and STR reporting obligations.
Designated Non-Financial Businesses and Professions (DNFBPs)
The following categories are classified as DNFBPs under the current framework and must apply AML/CFT compliance standards comparable to those of financial institutions:
- Real estate agents and brokers involved in the buying and selling of real estate
- Dealers in precious metals and gemstones
- Auditors, accountants, and tax advisers
- Company service providers and corporate formation agents
- Lawyers and independent legal professionals in defined circumstances
- Operators of commercial gaming activities (newly added under CR No. 134 of 2025)
Each category is classified as a DNFBP because its activities create specific channels that money launderers can exploit — real estate through high-value cash transactions, precious metals through portable high-value assets, and professional services through the legal structures and financial products they create or manage on behalf of clients.
The Core Compliance Obligations for DNFBPs
Know Your Customer (KYC) and Customer Due Diligence (CDD)
CDD must be completed before any business relationship is established or any transaction is executed above applicable thresholds. Requirements vary by customer risk level:
- Standard CDD — identity verification, proof of address, understanding of the business relationship’s purpose, and source of funds for individuals; corporate structure and Ultimate Beneficial Owner identification for entities
- Enhanced Due Diligence (EDD) — required for higher-risk situations: Politically Exposed Persons, customers from high-risk jurisdictions identified by FATF, complex corporate structures, large cash transactions, and any relationship where the standard risk assessment identifies elevated exposure. EDD requires deeper verification, senior management approval before proceeding, and ongoing monitoring rather than periodic review
- Simplified Due Diligence (SDD) — available in limited, specifically defined lower-risk circumstances only; not a general permission to reduce CDD effort
CDD records must be retained for a minimum of 5 years following the end of the business relationship or the last transaction.
Suspicious Transaction Reporting
Every DNFBP must be registered on the UAE Financial Intelligence Unit’s goAML platform and must file Suspicious Transaction Reports (STRs) or Suspicious Activity Reports (SARs) promptly when the obligation is triggered — which is on reasonable suspicion, not on proof or certainty. The obligation arises when a transaction, attempted transaction, or pattern of activity gives the business reasonable grounds to suspect a connection to money laundering, terrorism financing, or proliferation financing.
Failure to file a required report carries fines of AED 300,000 to AED 5,000,000 per violation. The good faith protection under the 2025 law expressly protects DNFBPs, their employees, and their representatives from liability for reports filed in good faith — even where the underlying suspicion later proves unfounded.
Internal Controls and AML Policy
A written AML/CFT policy is a legal requirement, not a best practice aspiration. It must cover internal CDD procedures, transaction monitoring processes, escalation steps, the STR filing procedure, staff training requirements, and the role and authority of the designated AML Compliance Officer. The Compliance Officer carries personal accountability for the firm’s compliance posture under the 2025 framework.
Targeted Financial Sanctions Screening
Cabinet Decision No. 74 of 2020 on Targeted Financial Sanctions remains in force alongside the 2025 AML law. Every DNFBP must screen clients and their beneficial owners against the UAE Local Terrorist List and applicable international sanctions lists — both before establishing a business relationship and on an ongoing basis throughout it. A business that proceeds with a sanctioned individual or entity faces severe consequences regardless of whether it was unaware of the sanctions listing at the time.
Ultimate Beneficial Ownership Records
Cabinet Decision No. 58 of 2020 requires all UAE companies to identify, maintain, and report their Ultimate Beneficial Owners — any person who owns or controls 25% or more of the company’s capital directly or indirectly. DNFBPs must verify UBO information for all corporate clients as part of their CDD process.
The Supervisory Structure
AML supervision in the UAE is divided by sector:
- The Central Bank of the UAE supervises banks, exchange houses, and financial institutions
- The Securities and Commodities Authority (SCA) supervises investment firms and securities markets
- The Insurance Authority supervises insurance companies
- The Ministry of Economy supervises most DNFBPs — real estate brokers, dealers in precious metals and stones, auditors and accountants, company service providers, and now gaming operators
- The UAE Financial Intelligence Unit (FIU) receives all STRs and SARs through goAML, analyses financial intelligence, and coordinates with law enforcement and foreign FIUs
The FATF’s 2026 mutual evaluation of the UAE’s AML/CFT framework is driving heightened supervisory activity across all these bodies. The Ministry of Economy imposed AED 42 million in DNFBP fines in the first half of 2025 alone — nearly double its total for 2024 — reflecting a deliberate pre-evaluation enforcement intensification.
Criminal Penalties Under the 2025 Law
| Offence | Imprisonment | Maximum Fine |
|---|---|---|
| Money laundering | Up to 10 years | AED 5,000,000 |
| Terrorism financing | Up to life imprisonment | AED 10,000,000 |
| Proliferation financing | Up to life imprisonment | AED 10,000,000 |
| Operating without AML authorisation | Determined by court | AED 10,000,000 |
| Failure to report (STR) | Imprisonment possible | AED 5,000,000 |
| Tipping off (intentional) | Minimum 6 months | AED 500,000 |
| Tipping off (gross negligence) | Determined by court | AED 500,000 |
| Legal persons (companies) | N/A (dissolution possible) | AED 100,000,000 |
Practical Compliance Steps for 2026
- Update all internal AML policies to reference Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025 as the governing instruments — any policy still citing the 2018 law is referencing repealed legislation
- Review CDD procedures against the new evidentiary standard — confirm that risk assessment processes are robust enough to meet the “should have known” threshold, not just the old “actually knew” bar
- Register on goAML and file all outstanding reports — unregistered DNFBPs are in automatic non-compliance regardless of whether they have suspicious transactions to report
- Screen for proliferation financing as a standalone category, not as a subset of terrorism financing
- Brief the AML Compliance Officer on the expanded personal liability implications under the 2025 framework
- Commission an independent AML audit before the FATF 2026 mutual evaluation drives further regulatory scrutiny
Frequently Asked Questions (FAQs)
What is the current UAE AML law?
Federal Decree-Law No. 10 of 2025, effective 14 October 2025, is the current primary UAE AML/CFT law. It replaced Federal Decree-Law No. 20 of 2018, which has been fully repealed. The implementing regulation is Cabinet Resolution No. 134 of 2025, effective 14 December 2025.
Who must comply with UAE AML law?
Financial institutions (banks, insurance companies, exchange houses, investment firms) and Designated Non-Financial Businesses and Professions (DNFBPs) — real estate agents, dealers in precious metals and stones, auditors and accountants, company service providers, lawyers in defined circumstances, and now operators of commercial gaming activities under the 2025 regulation.
What is the most significant change in the 2025 AML law?
The lowering of the evidentiary threshold for liability: knowledge that funds are of criminal origin can now be inferred from objective circumstances rather than requiring direct proof of actual knowledge. This materially weakens the “we didn’t know” defence and directly tests the adequacy of a business’s AML controls and risk assessment processes.
What are the maximum penalties for AML violations in the UAE?
Legal persons face fines up to AED 100 million and potential dissolution. Natural persons face up to 10 years imprisonment and AED 5 million for money laundering, up to life imprisonment for terrorism or proliferation financing, and AED 300,000–5,000,000 for failure to file a required STR.
What is the FIU and what is goAML?
The UAE Financial Intelligence Unit (FIU) is the body that receives, analyses, and acts on suspicious transaction reports. goAML is the FIU’s platform through which all STRs and SARs must be submitted. Every DNFBP must be registered on goAML before it can meet its STR filing obligations.
Do cryptocurrencies and digital assets fall under UAE AML law?
Yes. The definition of “funds” under the UAE AML framework expressly includes electronic and digital assets, closing potential loopholes that criminals might otherwise exploit through crypto-based transactions.
What is tipping off and what are its consequences under the 2025 law?
Tipping off is disclosing to a client or third party that a suspicious transaction report has been filed or that an investigation is underway. Under Article 29 of Federal Decree-Law No. 10 of 2025, this now covers both intentional disclosures and grossly negligent ones, with aggravated penalties where the disclosure results in the loss of criminal proceeds.
Need Expert Advice?
Contact the team at Farahat & Co. for professional support and expert insights for businesses operating in the UAE.
How Farahat & Co. Can Help
Farahat & Co. supports DNFBPs and other regulated entities across the UAE in building and maintaining AML compliance frameworks that meet the current requirements under Federal Decree-Law No. 10 of 2025 — including AML policy development, risk assessment, CDD procedures, goAML registration and STR filing support, staff training, and independent AML audits ahead of the FATF 2026 mutual evaluation.
Contact Farahat & Co. today to discuss your AML compliance requirements under the current UAE framework.
