Skip to content

Financial crime

AML and counter-terrorist financing

Federal Decree-Law No. 20 of 2018, DFSA AML Module, DIFC AML Regulations

In short

Two supervisory regimes operate side by side. DFSA Authorised Firms follow the DFSA AML Module. Designated Non-Financial Businesses and Professions are supervised by the DIFC Registrar. Both routes require a named MLRO, a documented business risk assessment, customer due diligence proportionate to risk, registration on the federal goAML platform and prompt suspicious activity reporting.

Instrument
Federal Decree-Law No. 20 of 2018, DFSA AML Module, DIFC AML Regulations
In force
Federal law from 2018, with subsequent amendments
Regulator
DFSA for Authorised Firms, DIFC Registrar for DNFBPs
Applies to
All DFSA Authorised Firms and Registered Auditors, plus DIFC entities falling within the DNFBP categories such as company service providers, real estate brokers, dealers in precious metals and stones, and lawyers and accountants carrying out specified transactions.

What it requires

ObligationWhat it means in practice
Appoint an MLROA named individual, resident in the UAE, with authority and direct access to senior management and the board.
Carry out a business risk assessmentDocumented, covering customers, products, delivery channels, geographies and updated at least annually.
Apply customer due diligenceIdentify and verify the customer and beneficial owner, understand the purpose of the relationship and apply enhanced measures for higher risk.
Register on goAMLThe federal reporting platform operated by the Financial Intelligence Unit.
File suspicious activity reportsThrough goAML as soon as suspicion arises, without tipping off the customer.
Screen against sanctions listsIncluding the UAE Local Terrorist List and United Nations consolidated lists, with ongoing monitoring.
Train staff and keep recordsAnnual AML training for all relevant staff and records retained for at least six years.

Deadlines

ItemWhen
Business risk assessment reviewAt least annually, and on any material change
AML annual return to the DFSAAs notified by the regulator each year
Suspicious activity reportAs soon as suspicion arises
Record retentionMinimum 6 years from the end of the relationship

If you get it wrong

Federal penalties under Decree-Law No. 20 of 2018 include substantial fines and, for serious cases, imprisonment. The DFSA can fine, restrict or withdraw a Licence and take action against individuals. The Registrar can fine DNFBPs and publish the outcome. Failure to register on goAML has itself produced penalties across the UAE.

Which regime applies to you

If you hold a DFSA Licence, the DFSA AML Module applies and your supervision comes from the DFSA. If you are a non-regulated DIFC entity that falls within a DNFBP category, the DIFC Registrar supervises you under the DIFC AML Regulations. Both sit under the federal framework, and both require goAML registration.

Entities that are neither an Authorised Firm nor a DNFBP still have to comply with sanctions obligations and the federal prohibitions. They do not need an MLRO or a full programme, which is the main practical difference.

The business risk assessment is the foundation

Supervisors read the risk assessment first. It should explain, with evidence, what money laundering and terrorist financing risks the business actually faces given its customers, products, channels and geographies, and how the controls respond to each. A generic template with the firm's name inserted is obvious and it invites scrutiny of everything else.

The assessment then drives the rest. Customer risk ratings, enhanced due diligence triggers, transaction monitoring thresholds and training content should all trace back to it. When they do not, supervisors notice the disconnect quickly.

Politically exposed persons and source of wealth

The Gulf client base means PEP exposure is higher than many firms are used to. A PEP relationship requires senior management approval, enhanced due diligence and ongoing monitoring, and the source of wealth analysis has to be documented rather than assumed.

Source of wealth is where files most often fall short. Recording that a client is a businessman is not an analysis. Recording which businesses, over what period, generating what returns, supported by what evidence, is.

Common questions

Who needs an MLRO in the DIFC?

Every DFSA Authorised Firm and every DIFC entity that is a DNFBP. The MLRO must be a named individual resident in the UAE with direct access to senior management. For Authorised Firms the role is an Authorised Individual function requiring DFSA approval.

Can the MLRO role be outsourced?

Smaller firms can use an outsourced MLRO arrangement, and the DFSA accepts it where the individual has genuine capacity and access. Responsibility remains with the firm and its governing body, and a written outsourcing agreement is expected.

What is goAML?

It is the reporting platform operated by the UAE Financial Intelligence Unit. Registration is mandatory for Authorised Firms and DNFBPs, and it is the channel through which suspicious activity reports and sanctions-related reports are filed.

Check the source

This page summarises the position as at September 2026. Laws and regulations change. The authoritative text is published by the regulator: DFSA rulebook. Nothing here is legal advice.

Compliance is a calendar, not a project

Six recurring obligations across four different bodies, and nobody sends a reminder. We track them for DIFC entities so renewal is never the moment you discover a gap.