Proud of UAE  [email protected]       [email protected]        +97142500251 97142500251+       +971507869887 971507869887+      WhatsApp

The Role of a Compliance Officer under the UAE AML Law

Who Must Appoint an AML Compliance Officer in the UAE

Under Federal Decree-Law No. 10 of 2025 on Anti-Money Laundering and Combating the Financing of Terrorism and Illegal Organisations (effective 14 October 2025), all financial institutions and Designated Non-Financial Businesses and Professions (DNFBPs) operating in the UAE are required to appoint a Compliance Officer. This obligation applies to banks, exchange houses, insurance companies, securities firms, payment service providers, as well as DNFBPs including accountants, auditors, lawyers, real estate agents, precious metals and stones dealers, and company service providers.

The Compliance Officer is the individual within the organisation who holds personal accountability for AML/CFT compliance. They are not simply an administrator of a compliance programme , they are a regulatory contact point between the organisation and its supervisory authority, a gatekeeper for suspicious activity reporting, and under the 2025 law, a personally liable party where compliance failures occur on their watch.

The Definition of an AML Compliance Officer Under UAE Law

A Compliance Officer, under the UAE AML framework, is a person employed or appointed by a legal entity with appropriate competence and experience in AML/CFT matters, tasked with ensuring that the entity meets all its obligations under the applicable AML legislation on the entity’s behalf. The Compliance Officer must have sufficient seniority, resources, and access to information to perform their duties effectively. A Compliance Officer who is placed in a position without the authority or access needed to fulfil their role cannot legally discharge their obligations.

The implementing regulation under Cabinet Resolution No. 134 of 2025 (effective 14 December 2025) sets out the specific qualifications and operational requirements for Compliance Officers, including minimum competency standards and the requirement that the appointment be notified to the relevant supervisory authority , the CBUAE for financial institutions, and the Ministry of Economy for DNFBPs.

Explore: AML Compliance Services UAE

Need Expert Advice?

Contact the team at Farahat & Co. for professional support and expert insights for businesses operating in the UAE.

Core Duties of the AML Compliance Officer

The duties of the Compliance Officer under the UAE AML framework fall into two connected areas: obligations to the organisation that employs them, and obligations to the government through the supervisory authority and the Financial Intelligence Unit (FIU).

Duties to the Organisation

  • Developing and maintaining the AML/CFT policy: drafting, implementing, and regularly updating the organisation’s AML/CFT policies and procedures to reflect current law and regulatory guidance. Following the transition to FDL No. 10 of 2025 and Cabinet Resolution No. 134 of 2025, any policy still referencing the 2018/2019 instruments must be updated immediately
  • Customer Due Diligence oversight: ensuring that CDD processes are applied consistently at onboarding and on an ongoing basis, that Enhanced Due Diligence is applied to high-risk customers, Politically Exposed Persons, and high-risk jurisdictions, and that CDD records are maintained and retained as required
  • Transaction monitoring: overseeing the organisation’s transaction monitoring system or processes, reviewing alerts escalated by the compliance team, and determining whether escalated matters require filing a Suspicious Transaction Report with the FIU
  • STR decision-making: reviewing all internal suspicion reports, assessing whether there are reasonable grounds to suspect that a transaction or attempted transaction relates to the proceeds of crime or the financing of terrorism, and filing STRs with the UAE FIU through the goAML platform without delay where such grounds exist
  • Staff training: developing and delivering AML/CFT training for all relevant employees, ensuring that staff can identify the indicators of suspicious activity, understand their obligations to escalate internal suspicions, and are aware of the tipping-off prohibition
  • Internal audit and testing: working with internal audit or an independent testing function to assess the effectiveness of the AML/CFT programme, identify gaps, and implement remediation
  • MLRO report preparation: preparing the semi-annual MLRO report and submitting it to senior management and the relevant supervisory authority as required under Cabinet Resolution No. 134 of 2025

Duties to the Government and Supervisory Authority

  • Filing Suspicious Transaction Reports: submitting STRs to the UAE FIU through the goAML platform when there are reasonable grounds to suspect money laundering or terrorism financing activity. The report must be filed without delay , not after internal investigation is complete, but as soon as suspicion arises
  • Cooperating with supervisory inspections: providing the supervisory authority (CBUAE or Ministry of Economy) with all requested information, records, and access during compliance inspections and examinations
  • Notifying the supervisory authority of significant compliance failures: where a material compliance failure is identified, the Compliance Officer has an obligation to notify the relevant supervisory authority as required under the regulatory framework
  • Keeping the supervisory authority updated on appointment changes: where the Compliance Officer changes, the new appointment must be notified to the supervisory authority and the FIU

Personal Liability of the AML Compliance Officer Under FDL No. 10 of 2025

The most significant change introduced by Federal Decree-Law No. 10 of 2025 for Compliance Officers is the explicit extension of personal enforcement liability. Under the previous framework, enforcement action for AML non-compliance was directed primarily at the institutional level. Under FDL No. 10 of 2025, the Compliance Officer can be held personally liable for compliance failures that fall within their responsibility.

This means that a Compliance Officer who:

  • fails to file an STR where reasonable grounds for suspicion existed
  • submits a superficial or incomplete MLRO report that does not surface material compliance deficiencies
  • fails to update the organisation’s AML/CFT policies to reflect current law
  • allows CDD processes to lapse without remediation

…is not just creating institutional enforcement risk. They are creating personal regulatory risk that can result in fines, disqualification from acting as a Compliance Officer, and in cases of deliberate concealment or fraud, criminal prosecution.

The practical consequence is that the Compliance Officer role is no longer a compliance function that can be assigned to a junior employee as an administrative add-on. It requires a qualified, experienced professional with the seniority and authority to implement their decisions, and it requires that person to maintain genuinely current knowledge of UAE AML law.

The Compliance Officer for Virtual Asset Service Providers

For businesses licensed by the Virtual Assets Regulatory Authority (VARA) in Dubai, the Compliance Officer obligations are additionally governed by VARA Version 2.0 (effective 19 June 2025). Under VARA’s AML/CFT framework, VASPs are required to conduct quarterly AML/CFT risk assessments (replacing the previous annual requirement), implement the Travel Rule for virtual asset transfers, and maintain an MLRO Certification Renewal process. The personal liability provisions under FDL No. 10 of 2025 apply to VASP Compliance Officers in the same way they apply to financial institutions and DNFBPs.

What Qualifies Someone to Act as an AML Compliance Officer

The UAE AML framework requires that the Compliance Officer have appropriate competence and experience. In practice, this means:

  • Substantive knowledge of UAE AML/CFT legislation, including FDL No. 10 of 2025 and Cabinet Resolution No. 134 of 2025
  • Understanding of the organisation’s business model and the specific ML/FT risks it faces
  • Experience in CDD, transaction monitoring, and STR filing processes
  • Seniority sufficient to implement decisions and communicate directly with the board and supervisory authority
  • Active maintenance of current knowledge through ongoing professional development

A Compliance Officer who qualified under the 2018/2019 legislative framework but has not updated their knowledge to reflect FDL No. 10 of 2025 does not meet the current competency standard, regardless of how long they have held the role.

Frequently Asked Questions (FAQs)

Who is required to appoint an AML Compliance Officer in the UAE?

All financial institutions and DNFBPs operating in the UAE must appoint a Compliance Officer under Federal Decree-Law No. 10 of 2025. This includes banks, exchange houses, insurance companies, securities firms, payment service providers, accountants, auditors, lawyers, real estate agents, precious metals dealers, and company service providers.

What law currently governs the AML Compliance Officer role in the UAE?

Federal Decree-Law No. 10 of 2025 (effective 14 October 2025) is the primary law. Cabinet Resolution No. 134 of 2025 (effective 14 December 2025) is the implementing regulation. These replaced Federal Decree-Law No. 20 of 2018 and Cabinet Decision No. 10 of 2019. Any compliance programme or policy still referencing the 2018/2019 instruments is operating under superseded legislation.

Can an AML Compliance Officer be personally liable for compliance failures?

Yes. Federal Decree-Law No. 10 of 2025 explicitly extended personal enforcement liability to Compliance Officers for failures within their remit. A Compliance Officer who fails to file an STR, submits a deficient MLRO report, or fails to maintain current AML/CFT policies faces personal regulatory action independently of any institutional penalties imposed on the organisation.

What is the difference between a Compliance Officer and an MLRO?

In UAE AML practice, these terms are often used interchangeably. The Compliance Officer is the person appointed under the AML legislation to oversee the organisation’s AML/CFT programme. The MLRO (Money Laundering Reporting Officer) is the specific individual responsible for receiving internal suspicion reports and deciding whether to file STRs with the FIU. In most UAE organisations, one person holds both roles.

How often must an AML Compliance Officer submit an MLRO report?

Semi-annually, under Cabinet Resolution No. 134 of 2025. Two reports are required each year, submitted to both senior management and the relevant supervisory authority , the CBUAE for financial institutions and the Ministry of Economy for DNFBPs. For VASPs under VARA, additional quarterly AML/CFT risk assessments are required under VARA Version 2.0 (effective June 2025).

Need Expert Advice?

Contact the team at Farahat & Co. for professional support and expert insights for businesses operating in the UAE.

How Farahat & Co. Can Help

Farahat & Co. provides AML compliance advisory services to financial institutions and DNFBPs across the UAE, supporting Compliance Officers with AML/CFT policy development and updates to reflect FDL No. 10 of 2025, MLRO report preparation, CDD framework design, STR filing guidance, staff training, and regulatory inspection preparation.

Contact Farahat & Co. today to discuss your AML Compliance Officer support requirements.

M. Al Khairy

M. Al Khairy, LL.B., has extensive experience in providing legal advice to the firm’s business clientele. His primary area of practice is corporate law, covering a variety of aspects such as commercial transactions, property, trade, administrative, and litigation.
He is a high-calibre expert with technical knowledge and industry experience, which is why the firm is able to provide incisive advice corporate clients need. Al Khairy is also highly experienced in undertaking procedural formalities and providing counsel pertaining to company liquidation.
×

Hold On!

Business decisions are easier with the right guidance.

For audit, accounting, tax, or VAT, our team is here to help.