UAE Anti-Money Laundering Framework Under Federal Decree-Law No. 10 of 2025
Introduction: What Is the UAE's New AML Law?
The United Arab Emirates has significantly strengthened its financial crime prevention framework through Federal Decree-Law No. 10 of 2025 on Anti-Money Laundering, Combating the Financing of Terrorism, and Countering the Financing of Proliferation. The legislation establishes the principal federal legal framework governing anti-money laundering (AML), counter-terrorist financing (CFT), and counter-proliferation financing (CPF) obligations across financial institutions, Designated Non-Financial Businesses and Professions (DNFBPs), and other entities falling within its scope.
The new law reflects the UAE's continuing commitment to strengthening financial integrity, improving transparency, and aligning its regulatory framework with international standards. It places greater emphasis on risk-based compliance, customer transparency, beneficial ownership, suspicious transaction reporting, targeted financial sanctions, and effective internal controls.
Who Does Federal Decree-Law No. 10 of 2025 Apply To?
Federal Decree-Law No. 10 of 2025 establishes obligations applicable to a broad range of regulated sectors. These include financial institutions and DNFBPs operating in areas such as corporate services, real estate, precious metals and stones, legal and accounting services, and other activities covered by the legislation.
The framework requires covered entities to establish appropriate systems and controls to prevent their businesses and services from being misused for money laundering, terrorism financing, or proliferation financing.
The legislation also reinforces the principle that regulated activities must be conducted in accordance with applicable licensing and authorization requirements. Businesses operating within regulated sectors must therefore ensure that their activities, governance structures, and compliance arrangements remain consistent with the requirements of the relevant competent authorities.
Why Is a Risk-Based Approach Central to UAE AML Compliance?
A central principle under the UAE's AML framework is the adoption of a risk-based approach.
Covered entities are expected to identify, assess, understand, and mitigate the risks associated with money laundering, terrorism financing, and proliferation financing. Risk assessments should take into account factors such as customer profiles, geographic exposure, products and services, delivery channels, and the nature and complexity of business relationships.
This approach requires businesses to move beyond a purely documentary compliance model. Policies and procedures should be proportionate to the risks identified and supported by appropriate internal controls, monitoring mechanisms, escalation procedures, and management oversight.
What Are the Customer Due Diligence and Beneficial Ownership Requirements?
Customer Due Diligence (CDD) remains one of the fundamental obligations under the federal AML framework.
Covered entities must identify and verify their customers using reliable and independent information and understand the purpose and intended nature of the business relationship. Where customers are legal persons or legal arrangements, businesses must also establish the relevant ownership and control structures and identify the Ultimate Beneficial Owner (UBO).
Beneficial ownership transparency is particularly important where corporate structures involve multiple jurisdictions, layered ownership arrangements, nominee relationships, or complex control structures.
Entities must also maintain appropriate customer information and conduct ongoing due diligence where required, particularly where changes in ownership, control, business activity, or customer risk profile may affect the relationship's risk assessment.
When Is Enhanced Due Diligence Required for Higher-Risk Relationships?
The legislation adopts a risk-sensitive approach to customer relationships. Where a customer, jurisdiction, product, service, transaction, or delivery channel presents heightened financial crime risks, covered entities are expected to apply enhanced risk mitigation measures.
Enhanced Customer Due Diligence may therefore be required for higher-risk relationships, while simplified measures should only be applied where the relevant conditions for lower-risk treatment are satisfied and there are no circumstances giving rise to suspicion.
This risk-based structure allows regulated entities to allocate compliance resources according to the level and nature of identified financial crime exposure.
How Should Businesses Monitor Transactions and Report Suspicious Activity?
AML compliance does not end when a customer is onboarded. Covered entities must maintain appropriate ongoing monitoring arrangements to identify unusual or suspicious transactions and activities.
Monitoring should be capable of identifying activity that is inconsistent with the customer's known profile, business activities, source of funds, or expected transaction behaviour. Where appropriate, transactions should be escalated for further review and investigation.
Where there is suspicion of money laundering, terrorism financing, proliferation financing, or another relevant financial crime, applicable reporting obligations must be followed. Suspicious Transaction Reports and other applicable suspicious reports are submitted to the UAE Financial Intelligence Unit (FIU) through the official goAML reporting system.
Entities must also maintain appropriate internal procedures for identifying, escalating, documenting, and reporting suspicious activity while observing applicable restrictions against tipping-off.
What Are the Targeted Financial Sanctions and Proliferation Financing Requirements?
The federal framework places significant importance on targeted financial sanctions and the prevention of proliferation financing.
Covered entities must establish appropriate screening and control mechanisms to identify persons and entities subject to applicable targeted financial sanctions requirements. Screening should form part of the entity's broader customer onboarding, transaction monitoring, and ongoing compliance processes.
The express incorporation of proliferation financing into the federal AML framework further expands the risk areas that regulated entities must consider when designing their financial crime compliance programmes.
What Record-Keeping and Internal Control Obligations Apply?
Effective AML compliance requires regulated entities to maintain appropriate records relating to customers, beneficial ownership, transactions, risk assessments, due diligence, monitoring, and suspicious activity reviews.
Records and supporting documentation should be maintained in a manner that allows the relevant information to be retrieved and provided to competent authorities when lawfully required.
Businesses should also establish clear internal responsibilities for AML compliance, maintain appropriate policies and procedures, provide relevant employee training, and periodically assess whether their controls remain effective against their identified risks.
What Are the Penalties for Non-Compliance With UAE AML Law?
Failure to comply with applicable AML requirements may expose businesses and responsible persons to significant regulatory and legal consequences.
Depending on the nature and seriousness of the violation, enforcement measures may include administrative penalties and other regulatory measures available under the applicable legal and supervisory framework. Serious financial crime conduct may also give rise to criminal liability.
Accordingly, AML compliance should be treated as an integral part of corporate governance and operational risk management rather than as a periodic administrative requirement.
How Can Businesses Build an Effective AML Compliance Framework?
For businesses operating in the UAE, Federal Decree-Law No. 10 of 2025 provides the core legal foundation for establishing an effective financial crime compliance framework.
Businesses should ensure that their AML policies are supported by documented risk assessments, appropriate customer due diligence, accurate UBO records, effective sanctions screening, ongoing transaction monitoring, employee training, internal escalation procedures, and appropriate reporting mechanisms.
Regular reviews of AML controls are also important to ensure that compliance arrangements remain aligned with changes in the business, customer base, geographic exposure, products and services, and applicable regulatory requirements.
A proactive and risk-based approach enables UAE businesses to strengthen their governance structures, reduce exposure to financial crime risks, and maintain confidence among customers, regulators, financial institutions, and other stakeholders.
Key Takeaways
- Federal Decree-Law No. 10 of 2025 is the UAE's core federal AML, CFT, and CPF legislation.
- It applies to financial institutions and DNFBPs, including corporate services, real estate, and legal and accounting professions.
- A risk-based approach, robust CDD, UBO identification, and sanctions screening are central obligations.
- Suspicious activity must be reported to the FIU through goAML, with tipping-off restrictions observed.
- Non-compliance can trigger administrative penalties and, in serious cases, criminal liability.
Conclusion: A Modern Pillar of the UAE's Financial Crime Prevention Framework
Federal Decree-Law No. 10 of 2025 therefore represents a significant pillar of the UAE's modern financial crime prevention framework, providing a comprehensive legal foundation for AML, CFT, and counter-proliferation financing controls across the UAE's financial and commercial environment.
Can simplified due diligence be used instead?
Simplified measures may only be applied where the relevant conditions for lower-risk treatment are met and there are no circumstances giving rise to suspicion. They are not a default option and must be justified by the entity's own risk assessment.
What is goAML and why does it matter?
goAML is the official reporting system of the UAE Financial Intelligence Unit. Covered entities submit Suspicious Transaction Reports and other suspicious activity reports through goAML when they identify activity that may relate to money laundering, terrorism financing, or proliferation financing.
What are targeted financial sanctions?
Targeted financial sanctions require covered entities to screen customers and transactions against applicable sanctions lists to identify persons and entities that are restricted from receiving funds or services, as part of onboarding and ongoing monitoring.
What records must be kept under the AML law?
Entities must keep records relating to customer identification, beneficial ownership, transactions, risk assessments, due diligence, monitoring activity, and suspicious activity reviews, in a format that can be retrieved and produced to competent authorities when required.
What happens if a business fails to comply?
Non-compliance can lead to administrative penalties and other regulatory measures, and serious financial crime conduct may also result in criminal liability, depending on the nature and severity of the violation.
Is proliferation financing a new addition?
Federal Decree-Law No. 10 of 2025 expressly incorporates proliferation financing alongside money laundering and terrorism financing, expanding the risk areas that regulated entities must build into their compliance programmes.
How often should AML controls be reviewed?
AML controls should be reviewed regularly and whenever there are changes in the business, customer base, geographic exposure, products, services, or applicable regulatory requirements, to ensure they remain aligned with current risk.
Does this law replace earlier UAE AML legislation?
Federal Decree-Law No. 10 of 2025 is the current federal legal framework governing AML, CFT, and CPF obligations in the UAE. Businesses should confirm the applicable implementing regulations and guidance issued by their supervisory authority for their specific sector.
How can a business start building an AML compliance framework?
A business should begin with a documented risk assessment, followed by customer due diligence procedures, UBO identification, sanctions screening, transaction monitoring, staff training, and internal escalation and reporting procedures aligned to the law's requirements.
Stay Ahead of UAE's AML Compliance Requirements
With over 15 years of regional experience across the UAE, GCC, India, and UK, Legacy Partners is an authorised representative supporting businesses in building, reviewing, and strengthening AML, CFT, and CPF compliance frameworks under Federal Decree-Law No. 10 of 2025.
Contact Legacy Partners today to schedule a compliance consultation and safeguard your business against regulatory and financial crime risk.
Frequently Asked Questions
Updated On: 18 Aug, 2026