Cabinet Resolution No. 134 of 2025: Strengthening the UAE’s AML/CFT/PF Regulatory Framework
The regulatory environment surrounding financial compliance in the United Arab Emirates has undergone a significant transformation with the introduction of Cabinet Resolution No. 134 of 2025. Enacted to operationalise Federal Decree Law No. 10 of 2025, this resolution officially took effect on December 14, 2025, effectively repealing and replacing Cabinet Resolution No. 10 of 2019. This milestone resolution establishes updated executive regulations designed to reinforce the national anti-money laundering framework, expanding the scope of regulatory oversight, introducing refined definitions, and mandating enhanced compliance requirements across multiple regulated sectors.
A central element of this legislative progression is the explicit integration of Proliferation Financing risk management alongside traditional anti-money laundering and counter-terrorism financing mandates. The updated framework redefines standard legal terminology, expanding the framework to expressly address the financing of the proliferation of weapons of mass destruction. This shift requires all covered entities to systematically evaluate and address proliferation risks across their operational frameworks.
Sectoral Scope and Regulatory Expansion
The framework applies across Financial Institutions, Designated Non-Financial Businesses and Professions, and Virtual Asset Service Providers, while also establishing specific obligations for Non-Profit Organizations, companies, legal arrangements and other relevant stakeholders. The framework expands the scope of regulated activities, including the formal inclusion of Commercial Gaming Operators as DNFBPs, while establishing specific AML/CFT/PF obligations for Virtual Asset Service Providers.
The Commercial Gaming Sector represents a major addition to the Designated Non-Financial Businesses and Professions category. Commercial games and gaming operators are now formally integrated under these regulatory obligations. Compliance requirements for gaming operators are triggered when a single financial transaction, or several transactions that appear to be linked, equals or exceeds AED 11,000. A transaction solely involving gaming chips or gaming instruments is excluded from the definition of a financial transaction for this purpose.
Virtual Asset Service Providers face an elevated operational standard that aligns their obligations more closely with traditional financial institutions. The framework also establishes specific information requirements for international wire transfers of AED 3,500 or more, including the verification and transmission of accurate originator and beneficiary information. VASPs are separately required to apply Customer Due Diligence to occasional virtual asset transactions of AED 3,500 or more, whether conducted as a single transaction or through linked transactions. Additionally, virtual asset service providers must uphold rigorous record-keeping practices and strictly adhere to targeted financial sanctions protocols.
Governance and Institutional Risk Oversight
Governance structures within regulated organizations must adapt to reflect the broader obligations mandated by the 2025 resolution. Senior management oversight and internal compliance leadership roles require immediate adjustment to incorporate proliferation financing risk mitigation.
Entities must maintain an appropriate, documented risk assessment framework covering exposure to money laundering, terrorism financing and proliferation financing. This risk evaluation process must consider various parameters, including customer profiles, geographic operations, specific products, transaction types, and delivery channels. The internal assessments are required to align with the findings of the National Risk Assessment and must be updated regularly or whenever significant operational changes occur.
Compliance Officers appointed within regulated organisations bear expanded responsibilities. Operating at a managerial level with documented independence, the Compliance Officer is responsible for overseeing the implementation of internal controls, reviewing suspicious transaction information and determining whether notification to the Financial Intelligence Unit is required, and assessing risks associated with new products, services, business practices, and technologies.
Due Diligence and Ultimate Beneficial Ownership Standards
Customer onboarding and continuous verification protocols have been refined to ensure greater transparency and risk mitigation. Regulated entities must complete baseline customer due diligence prior to or during the establishment of a formal business relationship. Verification requires the use of official, independent documentation for natural persons, legal persons, and legal arrangements alike.
The process of identifying Ultimate Beneficial Owners has been sharpened through clarified legal definitions. For legal persons, the framework requires identification of the natural person who ultimately owns or controls, directly or indirectly, the statutory ownership threshold specified under applicable UAE beneficial ownership regulatory standards. Where no such person can be identified, or where there is doubt as to the Beneficial Owner, the framework provides for identification based on legal or actual control and, where necessary, the relevant Senior Management position. Modern regulatory standards explicitly differentiate standard beneficial owners from Nominee Directors and Nominee Shareholders, stipulating that individuals serving in nominal management or shareholder capacities cannot be categorized as ultimate beneficial owners. Regulated institutions are obligated to maintain accurate beneficial ownership records and must update any changes to this data within fifteen working days.
High-risk relationships, including those involving high-risk jurisdictions or elevated proliferation-financing exposure, require enhanced risk mitigation measures and, where applicable, Enhanced Customer Due Diligence. Conversely, Simplified Due Diligence may only be applied when low risk is clearly demonstrated and no suspicion of illicit activity exists.
Operational Controls, Reporting, and Data Retention
Continuous transaction monitoring remains a foundational requirement for all regulated entities. Operational systems must be configured to identify unusual or suspicious activity regardless of the underlying monetary value.
When a suspicion of money laundering, terrorism financing, or proliferation financing arises, institutions are required to submit Suspicious Transaction Reports or Suspicious Activity Reports to the Financial Intelligence Unit without delay. STRs are submitted through the Financial Intelligence Unit's electronic reporting system, including the UAE's goAML platform. Strict statutory prohibitions against tipping-off remain enforced to prevent the compromise of ongoing regulatory reviews.
The 2025 framework also introduces specific criminal liability where a person unlawfully enables another person to benefit from an account held with a Financial Institution or Virtual Asset Service Provider, while knowing, or having sufficient grounds to believe, that such use is intended for the misuse of the account. This provision strengthens the legal framework against the use of bank and virtual asset accounts as mule accounts.
Relevant customer, transaction, CDD, monitoring, analysis and reporting records must generally be retained for at least five years, with the applicable retention period calculated from the relevant statutory trigger. Retained records must be structured to allow for the complete reconstruction of individual transactions and must be made readily accessible to competent supervisory authorities and the Financial Intelligence Unit upon request.
Strategic Action Plan for Regulated Entities
To achieve full alignment with Cabinet Resolution No. 134 of 2025 and Federal Decree Law No. 10 of 2025, organizations operating within the United Arab Emirates should undertake a structured review of their existing frameworks against the updated legislative requirements.
First, internal risk assessment frameworks should be reviewed and, where necessary, revised to incorporate proliferation financing indicators, relevant red flags, and appropriate control measures. Second, compliance manuals, customer onboarding forms, and screening workflows should be updated to reflect the 2025 legal framework and the refined definitions regarding nominee director and nominee shareholder positions. Third, customer risk profiling methodologies must account for specialized sector risks, including virtual asset transfers and commercial gaming thresholds.
Entities should review and, where necessary, strengthen their independent audit arrangements to test the effectiveness and adequacy of their AML/CFT/PF controls. Through these structured measures, regulated entities can ensure robust regulatory compliance while contributing to the overall integrity of the national financial system.
Updated On: 14 Aug, 2026