Financial crime
AML and counter-terrorist financing
Federal Decree-Law No. 20 of 2018, DFSA AML Module, DIFC AML Regulations
In short
Two supervisory regimes operate side by side. DFSA Authorised Firms follow the DFSA AML Module. Designated Non-Financial Businesses and Professions are supervised by the DIFC Registrar. Both routes require a named MLRO, a documented business risk assessment, customer due diligence proportionate to risk, registration on the federal goAML platform and prompt suspicious activity reporting.
- Instrument
- Federal Decree-Law No. 20 of 2018, DFSA AML Module, DIFC AML Regulations
- In force
- Federal law from 2018, with subsequent amendments
- Regulator
- DFSA for Authorised Firms, DIFC Registrar for DNFBPs
- Applies to
- All DFSA Authorised Firms and Registered Auditors, plus DIFC entities falling within the DNFBP categories such as company service providers, real estate brokers, dealers in precious metals and stones, and lawyers and accountants carrying out specified transactions.
What it requires
| Obligation | What it means in practice |
|---|---|
| Appoint an MLRO | A named individual, resident in the UAE, with authority and direct access to senior management and the board. |
| Carry out a business risk assessment | Documented, covering customers, products, delivery channels, geographies and updated at least annually. |
| Apply customer due diligence | Identify and verify the customer and beneficial owner, understand the purpose of the relationship and apply enhanced measures for higher risk. |
| Register on goAML | The federal reporting platform operated by the Financial Intelligence Unit. |
| File suspicious activity reports | Through goAML as soon as suspicion arises, without tipping off the customer. |
| Screen against sanctions lists | Including the UAE Local Terrorist List and United Nations consolidated lists, with ongoing monitoring. |
| Train staff and keep records | Annual AML training for all relevant staff and records retained for at least six years. |
Deadlines
| Item | When |
|---|---|
| Business risk assessment review | At least annually, and on any material change |
| AML annual return to the DFSA | As notified by the regulator each year |
| Suspicious activity report | As soon as suspicion arises |
| Record retention | Minimum 6 years from the end of the relationship |
If you get it wrong
Which regime applies to you
If you hold a DFSA Licence, the DFSA AML Module applies and your supervision comes from the DFSA. If you are a non-regulated DIFC entity that falls within a DNFBP category, the DIFC Registrar supervises you under the DIFC AML Regulations. Both sit under the federal framework, and both require goAML registration.
Entities that are neither an Authorised Firm nor a DNFBP still have to comply with sanctions obligations and the federal prohibitions. They do not need an MLRO or a full programme, which is the main practical difference.
The business risk assessment is the foundation
Supervisors read the risk assessment first. It should explain, with evidence, what money laundering and terrorist financing risks the business actually faces given its customers, products, channels and geographies, and how the controls respond to each. A generic template with the firm's name inserted is obvious and it invites scrutiny of everything else.
The assessment then drives the rest. Customer risk ratings, enhanced due diligence triggers, transaction monitoring thresholds and training content should all trace back to it. When they do not, supervisors notice the disconnect quickly.
Politically exposed persons and source of wealth
The Gulf client base means PEP exposure is higher than many firms are used to. A PEP relationship requires senior management approval, enhanced due diligence and ongoing monitoring, and the source of wealth analysis has to be documented rather than assumed.
Source of wealth is where files most often fall short. Recording that a client is a businessman is not an analysis. Recording which businesses, over what period, generating what returns, supported by what evidence, is.
Common questions
Who needs an MLRO in the DIFC?
Every DFSA Authorised Firm and every DIFC entity that is a DNFBP. The MLRO must be a named individual resident in the UAE with direct access to senior management. For Authorised Firms the role is an Authorised Individual function requiring DFSA approval.
Can the MLRO role be outsourced?
Smaller firms can use an outsourced MLRO arrangement, and the DFSA accepts it where the individual has genuine capacity and access. Responsibility remains with the firm and its governing body, and a written outsourcing agreement is expected.
What is goAML?
It is the reporting platform operated by the UAE Financial Intelligence Unit. Registration is mandatory for Authorised Firms and DNFBPs, and it is the channel through which suspicious activity reports and sanctions-related reports are filed.
Check the source
This page summarises the position as at September 2026. Laws and regulations change. The authoritative text is published by the regulator: DFSA rulebook. Nothing here is legal advice.Compliance is a calendar, not a project
Six recurring obligations across four different bodies, and nobody sends a reminder. We track them for DIFC entities so renewal is never the moment you discover a gap.