What is AML/CFT?
If you work in a UAE bank, the terms AML and CFT are part of your daily professional vocabulary. These arenโt just acronyms to be remembered โ they represent real risks, and how theyโre understood makes all the difference in how compliance performs.
AML stands for Anti-Money Laundering. CFT stands for Combating the Financing of Terrorism. Together, they form the foundation of your bank's legal and regulatory obligations to the Central Bank of the UAE (CBUAE) and to the broader financial system.
What is Money Laundering?
Money laundering is the process by which individuals or organisations disguise the origins of money obtained through criminal activity, making illegally obtained funds appear legitimate.
The goal is always the same: to make dirty money look clean so it can be used freely without attracting suspicion. Money laundering typically occurs in three stages:
Placement is the first and most vulnerable stage for criminals. This is when illegally obtained cash or assets are introduced into the financial system โ through cash deposits, currency exchange, purchasing assets, or using money service businesses. This is the stage at which banks are most directly exposed.
Layering involves moving money through a series of complex transactions to distance it from its criminal source โ wire transfers between multiple accounts and jurisdictions, converting between asset classes, using shell companies, or conducting multiple transactions just below reporting thresholds (a technique called structuring or smurfing).
Integration is the final stage, where the laundered money re-enters the legitimate economy โ through property purchases, luxury goods, business investments, or loans repaid with criminal proceeds. At this point, the money appears entirely legitimate and is extremely difficult to trace.
What is Terrorist Financing?
Terrorist financing is the provision, collection, or movement of funds with the knowledge that they will be used โ in whole or in part โ to carry out a terrorist act or to support a terrorist organisation or individual terrorist.
Critically, terrorist financing does not always involve large sums of money, and it does not always originate from illegal sources. Small transactions, transfers from seemingly clean sources, and legitimate business revenues can all be used to fund terrorism. This makes it significantly harder to detect than money laundering and requires a different set of analytical skills and monitoring approaches.
Under UAE law, financing of illegal organisations โ including organisations that are not classified specifically as terrorist groups โ is also covered within the CFT framework.
Why AML/CFT Compliance Matters for Banking Professionals
You may be thinking that AML/CFT compliance is primarily a concern for your bank's compliance department or financial crime team. It is not. As a banking professional, your responsibilities under UAEโs Federal Decree-Law No. (10) of 2025 are personal and direct.
Every employee in a UAE bank has legal obligations. You are required to know your customers, recognise suspicious behaviour, and report it through the correct internal channels. If you fail to do so โ whether through negligence or deliberate inaction โ you are personally exposed to regulatory consequences. Your bank is also exposed to regulatory sanctions, financial penalties, and reputational damage that can take years to repair.
The financial system exists on trust. When banks are used to launder criminal proceeds or finance terrorism, that trust is damaged, and the consequences extend well beyond the bank itself. They affect the broader economy, public safety, and the UAE's standing in the international financial community.
The Global Context โ FATF and International Standards
The Financial Action Task Force (FATF) is the global standard-setting body for AML/CFT. Founded in 1989, FATF has developed 40 Recommendations that represent the international benchmark for effective AML/CFT systems. Countries are assessed against these recommendations through a mutual evaluation process, and their ratings determine how they are perceived by international financial institutions, correspondent banks, and foreign regulators.
The UAE is a member of MENAFATF โ the Middle East and North Africa Financial Action Task Force โ a FATF-style regional body that applies FATF standards across the region and conducts mutual evaluations of its members.
FATF standards are not suggestions. They directly influence your bank's correspondent banking relationships, your customers' access to international transactions, and the regulatory scrutiny your institution faces from foreign supervisors. Understanding FATF is understanding the context in which every AML/CFT rule your bank follows was written.
What is the CBUAE and What is Its Role in AML/CFT?
The Central Bank of the UAE (CBUAE) is the primary financial regulator and supervisor for the UAE's banking and financial services sector. Established under Federal Law No. 10 of 1980 and restructured under Federal Decree-Law No. 14 of 2018, the CBUAE is responsible for monetary policy, financial stability, licensing financial institutions, and supervising AML/CFT compliance across the sector it regulates.
The CBUAE's AML/CFT Mandate
The CBUAE's AML/CFT supervisory role is derived from the UAE's primary AML/CFT legislation and from its own governing law. Its mandate includes:
- Issuing AML/CFT regulations, standards, and guidance applicable to all Licensed Financial Institutions (LFIs) it supervises
- Conducting on-site examinations and off-site assessments of LFIs' AML/CFT frameworks
- Issuing administrative sanctions โ including financial penalties, restrictions on activities, and licence suspension or revocation โ when LFIs fail to meet their obligations
- Coordinating with other domestic regulators and law enforcement authorities on AML/CFT matters
- Engaging with international bodies including FATF, MENAFATF, and the Egmont Group on behalf of the UAE's financial sector
The CBUAE does not operate in isolation. It works within a national framework that includes the UAE Financial Intelligence Unit, the National AML/CFT Committee, the Executive Office for Control and Non-Proliferation, and law enforcement agencies including the Public Prosecution and the Ministry of Interior.
What the CBUAE Expects from You and Your Bank
The CBUAE expects every LFI it supervises to have a robust, risk-based AML/CFT compliance programme that is genuinely embedded in the institution's operations.
In practice, this means the CBUAE expects your bank to know who its customers are, understand what they do and why they are using your services, monitor transactions for suspicious activity, screen against applicable sanctions lists, report suspicions promptly, keep records for the required period, and demonstrate that your board and senior management are actively accountable for AML/CFT outcomes.
When CBUAE examiners arrive at your institution, they are testing whether your compliance programme actually works โ not just whether you have one.
The UAE AML/CFT Legal Framework
Understanding the legal framework is not optional for banking professionals in the UAE. You need to know what laws govern your obligations, where they come from, and how they interact with each other.
Federal Decree-Law No. (10) of 2025 Regarding Anti-Money Laundering, and Combating the Financing of Terrorism and Proliferation Financing
This is thecornerstone of the UAE's AML/CFT legal framework โ commonly referred to as the AML-CFT Law. Federal Decree-Law No. (10) of 2025, which replaces the earlier Federal Decree-Law No. (20) of 2018, defines money laundering, terrorist financing, and financing of illegal organisations as criminal offences under UAE law. It establishes the obligations of financial institutions and designated non-financial businesses to implement AML/CFT measures. It sets out the requirements for suspicious transaction reporting. And it defines the criminal and administrative penalties that apply when these obligations are not met.
Every UAE banking professional needs to be familiar with this law. It is the legal foundation on which all CBUAE regulations and standards are built.
Cabinet Resolution No. (134) of 2025
Cabinet Decision No. (134) of 2025 is the Implementing Regulation of the AML-CFT Law. It translates the law's broad requirements into specific, operational obligations โ covering customer due diligence requirements, enhanced due diligence triggers, record-keeping periods, the basis for risk assessment, and the responsibilities of compliance officers.
If Federal Decree-Law No. (10) of 2025 tells you what you must achieve, Cabinet Decision No. (134) of 2025 tells you how to achieve it.
CBUAE Standards and Guidance
The CBUAE has issued a suite of standards and guidance documents that translate the legal framework into institution-specific requirements for banks and other LFIs. These include:
- CBUAE AML/CFT Standards for Licensed Financial Institutions โ comprehensive standards covering governance, risk assessment, CDD, transaction monitoring, sanctions screening, reporting, record-keeping, and training
- Guidance on AML/CFT for specific sectors โ including exchange houses, finance companies, and payment service providers
- Thematic guidance on specific risk areas โ including trade finance, correspondent banking, and virtual assets
These standards carry regulatory force. Non-compliance with CBUAE standards is not a technical breach of a guideline โ it is a regulatory failure that the CBUAE can and does sanction.
The UAE's FATF Journey โ Grey List to Removal
In March 2022, the UAE was placed on the FATF grey list โ formally known as the list of "Jurisdictions under Increased Monitoring." This was a significant moment for the UAE's financial sector. Being grey-listed signalled to the international community that the UAE's AML/CFT system had identified deficiencies, and it triggered heightened scrutiny from correspondent banks, foreign regulators, and international financial institutions.
The consequences were tangible. Some international banks increased their due diligence on UAE-related transactions. Others restricted or exited certain correspondent banking relationships. The reputational and commercial pressure on the UAE's financial sector was real.
The UAE responded with an accelerated programme of legislative reform, regulatory strengthening, increased enforcement, and institutional capacity building. New laws were enacted, regulations were tightened, enforcement actions increased significantly, and coordination between government agencies improved substantially.
In February 2024, FATF removed the UAE from the grey list โ recognising that the country had made significant and sustainable progress in addressing the identified deficiencies. This was a major milestone, but it did not signal the end of the reform agenda. The CBUAE and other UAE authorities have been explicit that the standards introduced during the grey-listing period are permanent fixtures of the regulatory environment โ not temporary measures that lapse with grey-list removal.
For you as a banking professional, the grey-list period and its aftermath are important context. The regulatory intensity you experience today is a direct product of that period โ and it is not going away.
Key Regulatory Bodies You Need to Know
UAE Financial Intelligence Unit (UAEFIU) โ The national financial intelligence unit, operating under the Ministry of Economy. The UAEFIU receives and analyses suspicious transaction reports (STRs) from financial institutions and DNFBPs through the goAML platform, and disseminates financial intelligence to law enforcement and other competent authorities. When your bank files an STR, it goes to the UAEFIU.
National AML/CFT Committee (NAMLCFTC) โ The inter-agency body responsible for coordinating the UAE's national AML/CFT strategy across all government entities. It brings together the CBUAE, Ministry of Economy, Ministry of Justice, Ministry of Foreign Affairs, and other relevant authorities to ensure a unified national approach.
Executive Office for Control and Non-Proliferation (EOCN) โ Responsible for administering the UAE's targeted financial sanctions regime, including implementing UN Security Council sanctions and managing the local terrorist designation lists. When you are screening customers and transactions against UAE sanctions lists, the EOCN's lists are central to that process.
Ministry of Economy โ Responsible for supervising AML/CFT compliance among Designated Non-Financial Businesses and Professions (DNFBPs), including real estate agents, auditors, legal professionals, and dealers in precious metals and stones.
Who Should Comply with CBUAE AML/CFT Requirements?
The CBUAE's AML/CFT requirements apply to all entities it licenses and supervises โ collectively referred to as Licensed Financial Institutions (LFIs). If you work in any of the following types of institution in the UAE, you are working within the CBUAE's AML/CFT supervisory perimeter.
Licensed Financial Institutions (LFIs)
LFIs supervised by the CBUAE for AML/CFT purposes include:
- National and foreign banks operating in the UAE โ including branches and subsidiaries
- Finance companies โ providing personal finance, auto finance, mortgage finance, and other lending products
- Exchange houses โ engaged in currency exchange and money transfer services
- Payment service providers โ including licensed fintech companies offering payment processing, digital wallets, and money transmission services
- Insurance companies and intermediaries โ for life insurance and investment-linked products with a financial crime exposure
- Registered hawala providers โ informal value transfer operators registered with the CBUAE
If you work in a bank, you are an LFI. Your institution is subject to the full scope of CBUAE AML/CFT standards.
Designated Non-Financial Businesses and Professions (DNFBPs)
DNFBPs are non-financial sector businesses that are exposed to money laundering risk by virtue of the services they provide. In the UAE, they are supervised for AML/CFT purposes primarily by the Ministry of Economy and relevant emirate-level authorities. DNFBPs include:
- Real estate agents and brokers
- Dealers in precious metals and precious stones
- Auditors, accountants, and tax advisers
- Legal professionals providing certain services
- Company and trust service providers
As a banking professional, you need to understand DNFBPs not because you are one, but because your bank's customers may be. Understanding the AML/CFT vulnerabilities of your DNFBP customers is an essential part of conducting proper due diligence on them.
Virtual Asset Service Providers (VASPs)
VASPs โ entities that exchange, transfer, or provide custody of virtual assets (cryptocurrencies and similar instruments) โ are subject to AML/CFT regulation in the UAE under a framework that has developed significantly since 2022. VASPs operating in mainland UAE require CBUAE approval, while those operating in financial free zones (DIFC and ADGM) are regulated by their respective financial regulators.
The VASP sector represents an area of growing regulatory focus. As a banking professional dealing with fintech companies, crypto exchanges, or businesses with virtual asset exposure, you need to understand and apply heightened due diligence.
Common Misconceptions About Who Is Covered
A misconception sometimes encountered in banking is that AML/CFT obligations apply only to "high-risk" departments โ trade finance, correspondent banking, or private banking. This is incorrect. Every employee who has customer contact, processes transactions, or makes decisions that could affect the bank's AML/CFT posture has obligations. AML/CFT is not a specialist function โ it is a whole-institution responsibility.
Core AML/CFT Compliance Requirements
Your bank's AML/CFT compliance programme must cover a defined set of requirements mandated by CBUAE standards. These are not optional โ each is a regulatory expectation that CBUAE examiners will specifically assess.
Risk-Based Approach
The risk-based approach is the foundation of everything else. Rather than applying identical AML/CFT measures to every customer and every transaction, you are required to calibrate the intensity of your controls to the level of risk involved. Higher-risk customers, products, and geographies get more scrutiny. Lower-risk situations get proportionate but less intensive treatment.
In practice, a risk-based approach requires your bank to complete a Business Risk Assessment (BRA) โ a documented analysis of the money laundering and terrorist financing risks inherent in your institution's business model, customer base, products and services, delivery channels, and geographic exposure. The BRA is the starting point for your entire AML/CFT programme. If your BRA is weak or out of date, everything that flows from it will be inadequate.
AML/CFT Governance and Accountability
The CBUAE requires AML/CFT to be governed at the highest levels of your institution. Your board of directors is ultimately accountable for ensuring that your bank has an effective AML/CFT programme. Senior management is responsible for implementing it. This is not a delegatable responsibility โ it sits at the top.
In practice, this means your board must approve the AML/CFT policy, must receive regular reporting on AML/CFT risks and compliance performance, and must demonstrate active engagement with financial crime risk. CBUAE examiners will look at board minutes, committee reports, and management information to assess whether governance is substantive or cosmetic.
Appointing a Compliance Officer and MLRO
Your bank must appoint a dedicated Compliance Officer โ senior enough to have genuine authority and direct access to board and senior management โ who is responsible for overseeing the AML/CFT programme. The CBUAE must be notified of this appointment.
Your bank must also designate a Money Laundering Reporting Officer (MLRO) โ the person responsible for receiving internal suspicious activity reports from staff, evaluating them, and deciding whether to file a Suspicious Transaction Report (STR) with the UAEFIU. The MLRO must have the skills, experience, and authority to fulfil this role independently.
In smaller institutions, the Compliance Officer and MLRO may be the same person. In larger banks, these are typically separate roles. Regardless of structure, the MLRO must have direct access to all information they need to assess suspicious activity โ including customer records, transaction histories, and AML/CFT alerts.
AML/CFT Policies and Procedures
Your bank must have documented, board-approved AML/CFT policies and procedures that cover every aspect of your compliance programme. These must be:
- Written in clear, operational language that the staff who use them can actually follow
- Approved by the appropriate governance level โ typically board or senior management committee
- Kept current โ reviewed and updated whenever the business, the risk environment, or the regulatory framework changes
- Communicated to all relevant staff and accessible when needed
Policies that exist but are never updated, never read, and never followed do not constitute an AML/CFT programme. CBUAE examiners will test whether your procedures match your actual practices โ not just whether the documents exist.
Know Your Customer (KYC)
KYC is the process of identifying and verifying who your customers are โ and understanding enough about them to assess the risk they represent and detect when their behaviour is unusual. It is not a one-time exercise conducted at account opening. It is an ongoing process that continues throughout the customer relationship.
KYC covers:
- Identity โ who is the customer? Verify identity documents, corporate registrations, licensing, and ownership structures
- Purpose โ why does this customer want to use your bank's services? What products do they need and why?
- Source of funds โ where does the money in this relationship come from?
- Source of wealth โ for higher-risk customers, where did the customer's overall wealth originate?
- Expected activity โ what transactions do you expect this customer to conduct, and in what volumes?
Without solid KYC, transaction monitoring is meaningless. You cannot identify unusual activity if you do not know what normal looks like for a given customer.
Customer Due Diligence โ Standard, Enhanced, and Simplified
CDD is the operational execution of KYC. CBUAE standards require you to apply different levels of CDD depending on the risk profile of the customer and the relationship.
Standard CDD applies to customers with a normal risk profile. It involves identifying and verifying the customer's identity using reliable, independent documents; identifying the beneficial owner of legal entities; understanding the purpose and intended nature of the business relationship; and conducting ongoing monitoring.
Enhanced Due Diligence (EDD) applies when the risk is higher than normal. You are required to apply EDD automatically in certain situations โ including dealings with Politically Exposed Persons (PEPs), correspondent banking relationships, customers from high-risk jurisdictions identified by FATF, and situations where there is doubt about the accuracy or adequacy of previously obtained CDD information. EDD means doing more โ obtaining additional information, applying greater scrutiny, seeking senior management approval for the relationship, and monitoring more intensively.
Simplified Due Diligence (SDD) may be applied in limited circumstances where the risk is demonstrably low โ for example, certain government entities or publicly listed companies subject to robust disclosure requirements. However, SDD is not a lower standard of compliance โ it is a calibrated approach for situations where the risk genuinely warrants it. You must never apply SDD when there is any suspicion of money laundering or terrorist financing.
Ongoing Monitoring of Customers and Transactions
Customer due diligence does not stop when an account is opened. You are required to conduct ongoing monitoring of every customer relationship โ both of the customer's profile and of the transactions they conduct.
Customer profile monitoring means keeping KYC information current. When a customer's circumstances change โ a change in business activity, a change in beneficial ownership, a change in country of residence โ you must update their records and reassess their risk profile. CBUAE standards require periodic reviews of customer files, with the frequency determined by the customer's risk level โ high-risk customers more frequently, lower-risk customers less so.
Transaction monitoring means scrutinising transactions against the expected profile of the customer. Your bank is required to have systems and processes that flag transactions that appear unusual โ unusual in amount, frequency, destination, or pattern compared to what you know about the customer. Alerts generated by your transaction monitoring system must be reviewed and either cleared with documented rationale or escalated for potential STR filing.
Sanctions Screening
You are required to screen your customers, transactions, and counterparties against applicable sanctions lists โ both before entering a relationship and on an ongoing basis. In the UAE context, this means screening against:
- UAE local lists โ issued by Cabinet Decision, covering individuals and entities designated under UAE counterterrorism and targeted financial sanctions frameworks, administered by the EOCN
- UN Security Council consolidated list โ covering individuals and entities subject to UN sanctions
- Other international lists โ depending on your bank's business model and correspondent relationships, this may include OFAC (US Office of Foreign Assets Control), EU consolidated sanctions list, and UK financial sanctions list
A sanctions hit โ a match between a customer, counterparty, or transaction and a sanctions list โ requires immediate action. You must freeze the relevant funds or assets, refrain from processing the transaction, and report to the appropriate authorities. Your bank's policies must define exactly who is responsible for managing sanctions hits and what the escalation process looks like.
Suspicious Transaction Reporting and the goAML System
If you know, suspect, or have reasonable grounds to suspect that a transaction or a customer is connected to money laundering, terrorist financing, or financing of illegal organisations, you are legally required to report it. This is not discretionary.
The reporting is done by your bank's MLRO, who files a Suspicious Transaction Report (STR) through the goAML platform โ the UAEFIU's secure online reporting system. Internally, your responsibility is to report your suspicion to your MLRO โ not to investigate it yourself, not to discuss it with the customer, and not to delay.
You must never tip off a customer that a report has been filed or is being considered. Tipping off is a criminal offence under UAE law.
Record Keeping
You are required to retain AML/CFT-related records for a minimum of five years from the end of the customer relationship or the date of a transaction, whichever is later. This includes:
- Customer identification and verification documents (KYC records)
- Account files and business correspondence
- Transaction records sufficient to reconstruct individual transactions
- Training records
- STR filing records and internal suspicion reports
- Risk assessment documentation
Records must be maintained in a form that allows them to be retrieved promptly โ a CBUAE examiner or law enforcement authority may request records with very short notice. Disorganised or incomplete records are a compliance failure in their own right, regardless of whether the underlying activity was suspicious.
AML/CFT Training
Every employee in your bank who is relevant to AML/CFT must receive regular, appropriate training. This is a mandatory requirement โ not a nice-to-have. Training must be:
- Role-specific โ a front-line relationship manager needs different training from a back-office payments processor or a senior compliance officer
- Regular โ not a one-time onboarding session. Training must be refreshed and updated as regulations, risks, and typologies evolve
- Documented โ your bank must maintain records of who received what training and when
- Effective โ training must build genuine understanding and practical capability, not just achieve completion metrics
CBUAE examiners will interview staff as part of the examination process. If your employees cannot explain basic AML/CFT concepts โ what a PEP is, how to report a suspicion internally, what triggers EDD โ it reflects directly on your training programme.
Customer Due Diligence โ A Closer Look
CDD is where your bank's AML/CFT obligations become most operational and most visible in day-to-day work. Getting it right is not just a regulatory requirement โ it is the primary mechanism through which you understand and manage the risk your customer base represents.
What CDD Actually Involves
At its most basic, CDD requires you to answer four questions about every customer:
- Who are they? โ Verify identity using reliable, independent, up-to-date documentation
- Who ultimately owns or controls them? โ Identify the Ultimate Beneficial Owner(s)
- What are they using your bank for? โ Understand the nature and purpose of the relationship
- What should their activity look like? โ Establish an expected transaction profile
The answers to these questions form the baseline against which all subsequent monitoring is conducted.
Standard CDD
For customers assessed as presenting normal risk, Standard CDD requires:
- Obtaining and verifying the customer's identity โ for individuals, this means Emirates ID, passport, or equivalent; for legal entities, this means trade licence, memorandum of association, certificate of incorporation, and similar documents
- Identifying any individual who owns or controls more than 25 percent of a legal entity (the Ultimate Beneficial Owner)
- Understanding the purpose and intended nature of the business relationship
- Collecting information on the customer's expected transaction activity โ types of transactions, volumes, and geographic exposure
- Establishing and maintaining an up-to-date customer file
Enhanced Due Diligence โ When and Why
EDD applies when the standard risk profile is elevated. Under CBUAE standards, you must automatically apply EDD in the following situations โ these are not discretionary:
- Politically Exposed Persons (PEPs) and their family members and close associates
- Correspondent banking relationships with overseas financial institutions
- Customers from or transactions involving high-risk jurisdictions โ countries identified by FATF as having strategic AML/CFT deficiencies
- High-risk business types โ such as money service businesses, cash-intensive businesses, dealers in high-value goods, or shell companies
- Complex or unusual ownership structures โ where beneficial ownership is difficult to establish
- Any situation where you have doubt about the accuracy or completeness of previously obtained CDD information
EDD means going further than standard measures. It typically involves:
- Obtaining additional identity and background information
- Independently verifying the source of funds and source of wealth
- Understanding the customer's business and the rationale for specific transactions in greater depth
- Seeking senior management approval before establishing or continuing the relationship
- Applying more frequent and more intensive ongoing monitoring
Politically Exposed Persons (PEPs)
A PEP is an individual who holds or has held a prominent public function โ including heads of state and government, senior politicians, senior government officials, senior judiciary officials, senior military officers, senior executives of state-owned enterprises, and senior officials of international organisations.
PEPs present a higher risk of corruption and bribery โ they have access to public funds and public decision-making. As a result, you must apply EDD to all PEP relationships, obtain senior management approval before establishing or continuing a relationship with a PEP, and monitor PEP relationships more intensively throughout their duration.
You must also apply EDD to:
- Family members of PEPs โ spouses, children, parents, and siblings
- Close associates of PEPs โ individuals known to have close personal or professional relationships with a PEP
Your bank must have a PEP identification process that reliably flags PEPs at onboarding and during ongoing monitoring. Relying solely on customers to self-declare their PEP status is insufficient.
Ultimate Beneficial Ownership (UBO)
Identifying the Ultimate Beneficial Owner โ the natural person who ultimately owns or controls a legal entity โ is one of the most challenging and most important aspects of CDD for corporate customers.
In the UAE, you are required to identify any individual who directly or indirectly owns or controls 25 percent or more of a legal entity customer, or who otherwise exercises effective control over the entity. If no individual meets the ownership threshold, you must identify the individual(s) who exercise control through other means โ for example, through voting rights, board composition, or contractual arrangements.
You must not only identify the UBO but verify their identity using reliable documents. And you must keep UBO information current โ if ownership changes, your records must reflect it.
Complex ownership structures โ multiple layers of holding companies, trusts, foundations, nominee arrangements โ require particularly careful analysis. If you cannot establish the ultimate beneficial owner after exhausting all reasonable means, that itself may be a reason to file an STR or decline the relationship.
Simplified Due Diligence โ When It Applies
SDD is a reduced level of due diligence that may be applied only where you have assessed the customer to present a genuinely low risk of money laundering or terrorist financing. It is not a shortcut โ it is a risk-calibrated approach.
Customers that may qualify for SDD include certain UAE government entities, publicly listed companies on recognised exchanges subject to disclosure requirements, and regulated financial institutions from low-risk jurisdictions. Your bank's policies must define clearly which customer types qualify for SDD, and the decision must be based on documented risk assessment โ not on operational convenience.
You must never apply SDD when there is any suspicion of money laundering or terrorist financing, regardless of how the customer was previously classified.
Ongoing CDD and Periodic Review
CDD is a continuous process. You must monitor customer relationships throughout their duration โ updating KYC information, reviewing risk classifications, and ensuring that the customer's actual activity matches their expected profile.
Your bank must conduct periodic reviews of customer files, with the frequency driven by risk. High-risk customers must be reviewed more frequently โ typically annually or more often. Standard-risk customers may be reviewed every two to three years. Low-risk customers may be reviewed less frequently.
Triggers for an immediate review include: a change in the customer's business or ownership, unusual or unexpected transactions, adverse media coverage, a sanctions alert, or an internal suspicion report relating to the customer.
Sanctions Compliance in the UAE
Sanctions compliance is a distinct but closely related component of your AML/CFT programme. While AML focuses on detecting criminal proceeds and CFT focuses on terrorist financing, sanctions compliance focuses on ensuring that your bank does not provide financial services to designated individuals, entities, or jurisdictions โ regardless of whether specific criminal activity is suspected.
UAE Local Sanctions Lists
The UAE maintains its own targeted financial sanctions lists, administered by the EOCN. These lists include individuals and entities designated under UAE counterterrorism legislation and those subject to targeted financial sanctions under Cabinet decisions implementing UAE national security priorities.
You are legally required to screen against these lists and to freeze the assets of any designated person or entity immediately upon identification. You must not deal with or provide financial services to a listed individual or entity, and you must report any match to the relevant authority.
UN Security Council Sanctions
The UAE is a UN member state and implements UN Security Council sanctions resolutions. The UN consolidated list โ maintained by the UN Sanctions Committee โ covers individuals and entities subject to asset freezes, travel bans, and arms embargoes under various UN sanctions regimes. Your bank must screen against the UN consolidated list as part of your ongoing screening obligations.
International Lists
Depending on your bank's business model, correspondent relationships, and the currencies and jurisdictions in which you operate, you may also need to screen against:
- OFAC Specially Designated Nationals (SDN) list and other OFAC sanctions programmes โ particularly relevant if your bank processes US dollar transactions
- EU consolidated sanctions list โ relevant for Euro transactions and European counterparty relationships
- UK financial sanctions list โ relevant for Sterling transactions and UK counterparty relationships
The currency of a transaction matters. USD transactions that route through US correspondent banks bring OFAC exposure. EUR transactions bring EU sanctions exposure. Your bank must understand its exposure and screen accordingly.
How Screening Works in Practice
Your bank should have automated screening tools that screen customers at onboarding and on an ongoing basis as lists are updated, and that screen transactions โ including beneficiary names, counterparty banks, and countries โ against applicable sanctions lists in real time or near real time.
Automated screening generates alerts โ potential matches between a name or entity in a transaction and a sanctions list entry. These alerts must be reviewed by trained staff who can distinguish a genuine hit from a false positive (a coincidental name similarity with no actual sanctions connection). Genuine hits require immediate action: freeze the funds, do not process the transaction, and report to the appropriate authority in accordance with your bank's policies and UAE legal requirements.
The Tipping-Off Prohibition
You must never inform a customer โ directly or indirectly โ that they have been the subject of a sanctions screening alert, a suspicious transaction report, or an internal AML/CFT investigation. Tipping off is a criminal offence under UAE law and can result in personal criminal liability. This applies even in response to what may seem like an innocent enquiry from the customer about why their transaction has been delayed.
Suspicious Transaction Reporting
Reporting suspicious activity is one of your most important legal obligations. It is also one where the consequences of failure โ for your bank and potentially for you personally โ are most direct.
What Triggers an STR
You must file an STR when you know, suspect, or have reasonable grounds to suspect that a transaction or customer activity is connected to money laundering, terrorist financing, or financing of illegal organisations. The threshold is suspicion โ not certainty, not proof. If you have a reasonable basis to be suspicious, you must report.
Common triggers for suspicion include:
- A customer who is reluctant to provide CDD information or provides inconsistent or implausible explanations for their business or transactions
- Transactions that are inconsistent with the customer's known profile โ unexpected volumes, unusual counterparties, or geographies that do not fit the expected pattern
- Cash transactions that are structured in amounts just below reporting thresholds โ a known technique called smurfing
- Transactions that appear to have no obvious legitimate economic purpose
- A customer who seems unusually interested in secrecy, asks about your bank's reporting thresholds, or attempts to discourage routine due diligence
- Transactions involving jurisdictions associated with high money laundering or terrorist financing risk
- Rapid movement of funds through multiple accounts with no clear business rationale
You do not need to be certain that criminal activity is occurring. If something does not feel right, report it internally to your MLRO. The MLRO's job is to evaluate the suspicion โ not yours.
Filing via goAML
STRs are filed by your bank's MLRO through the goAML platform, operated by the UAEFIU. goAML is the UAE's secure online portal for financial intelligence reporting. Every LFI must be registered on goAML.
When you raise a suspicion internally, your MLRO assesses it. If the MLRO determines that a report is warranted, they file the STR through goAML โ providing details of the customer, the transaction or activity of concern, the basis for suspicion, and any other relevant information.
Reports must be filed promptly โ without tipping off the customer and without undue delay after the suspicion arises. Failing to file an STR when one is required is a criminal offence under UAE law.
Consequences of Failing to Report
If you become aware of suspicious activity and fail to report it internally, you are potentially personally liable under UAE law. The obligation to report is not limited to compliance or financial crime staff โ it applies to every employee who has knowledge of or reasonable grounds for suspicion.
Your bank must have a clear, accessible internal reporting process that makes it straightforward for any employee to raise a suspicion with the MLRO without fear of retaliation. If your bank does not have such a process, that is itself a compliance gap.
How the CBUAE Supervises and Examines Compliance
Understanding how the CBUAE supervises your bank is essential โ not to prepare for examination theatre, but to understand what genuine compliance looks like from a regulator's perspective.
The CBUAE Examination Process
The CBUAE uses a combination of on-site examinations and off-site supervision to assess the AML/CFT compliance of LFIs.
On-site examinations involve CBUAE examiners visiting your institution โ physically or remotely โ to conduct a detailed assessment of your AML/CFT programme. Examinations may be comprehensive (covering all aspects of the AML/CFT framework) or thematic (focusing on a specific area of risk or control, such as transaction monitoring effectiveness or CDD quality).
During an on-site examination, examiners will typically:
- Review your AML/CFT policies, procedures, and governance documentation
- Assess the quality of your Business Risk Assessment
- Test the quality of your CDD files โ sampling customer records to assess completeness, accuracy, and proportionality to risk
- Evaluate your transaction monitoring system โ reviewing alert volumes, closure rationale, and escalation quality
- Assess your sanctions screening coverage and hit management process
- Review your STR filing history and the quality of internal suspicion assessments
- Interview staff โ including compliance staff, relationship managers, and senior management โ to assess knowledge and awareness
- Review your training programme and training records
- Examine management information provided to the board and senior management on AML/CFT matters
Off-site supervision involves the CBUAE monitoring your institution's AML/CFT performance through regular reporting requirements, analysis of STR filing patterns, and review of management information submitted to the regulator.
What Examiners Look For
CBUAE examiners are looking for evidence that your AML/CFT programme is genuinely effective โ not just that it exists on paper. The most important questions they are trying to answer are:
- Does your bank understand its own AML/CFT risks?
- Are your controls proportionate to those risks?
- Are your controls actually operating?
- Does your board and senior management genuinely oversee the programme?
- Do your staff understand their obligations?
- When you identify suspicious activity, do you act on it?
A bank that has comprehensive policies but poor quality CDD files, low STR volumes relative to its risk profile, or staff who cannot explain basic AML/CFT concepts will be viewed very differently from a bank whose documentation, practice, and culture are consistently aligned.
Thematic Reviews
In addition to institution-specific examinations, the CBUAE periodically conducts thematic reviews across the sector โ assessing how all or a subset of LFIs manage a specific risk or control area. Past thematic areas have included correspondent banking due diligence, trade finance AML controls, and the effectiveness of transaction monitoring systems.
If your bank is selected for a thematic review, you will be asked to provide data, documentation, and potentially participate in interviews on the specific theme being assessed.
Penalties for AML/CFT Non-Compliance
The consequences of AML/CFT non-compliance in the UAE are significant โ for your bank and potentially for you personally. The UAE's legal and regulatory framework provides for a range of sanctions that are actively applied.
Administrative Sanctions
The CBUAE has broad powers to impose administrative sanctions on LFIs that fail to meet their AML/CFT obligations. These include:
- Written warnings โ formal notification of identified deficiencies with required remediation
- Directives โ binding instructions requiring specific actions within defined timeframes
- Financial penalties โ monetary sanctions imposed on the institution for regulatory failures
- Restrictions on activities โ limiting or prohibiting specific products, services, or customer categories
- Suspension or revocation of licence โ in serious cases, the CBUAE can suspend or revoke an institution's operating licence
The CBUAE has used these powers actively since the grey-list period โ the number and severity of enforcement actions increased significantly from 2022 onwards, and that enforcement posture has been maintained following grey-list removal.
Financial Penalties
Under the UAE AML-CFT Law and the CBUAE's own regulatory powers, financial penalties for AML/CFT failures can be substantial. Financial penalties are calculated based on the nature and severity of the violation, the size of the institution, and the degree of cooperation provided during the examination process.
Penalties for individual violations and for systemic programme failures are distinct. A bank with multiple identified deficiencies โ weak CDD, inadequate transaction monitoring, poor STR filing โ can face penalties that compound across each identified failing.
Criminal Liability
Individual criminal liability is a real consequence of AML/CFT failures in the UAE. Under Federal Decree-Law No. 20 of 2018:
- Deliberately committing a money laundering offence carries imprisonment and significant financial penalties
- Failing to report a known or suspected money laundering or terrorist financing offence is itself a criminal offence
- Tipping off a customer about a suspicion or a report is a criminal offence
Criminal liability attaches to individuals โ not just to institutions. Senior managers, compliance officers, MLROs, and front-line staff have all faced personal consequences for AML/CFT failures in the UAE.
Reputational Consequences
Beyond formal sanctions, the reputational consequences of AML/CFT failures are significant. Correspondent banks conduct their own due diligence on their UAE banking counterparts. A bank with a history of regulatory failures โ even if not publicly announced โ may find its correspondent relationships restricted, its access to international clearing systems affected, and its ability to attract and retain institutional clients diminished. In the UAE's concentrated banking market, reputational damage is particularly consequential.
Building an Effective AML/CFT Compliance Programme
Your bank's AML/CFT programme is not a set of documents โ it is a living system of governance, processes, people, and technology that must function reliably every day. The following five pillars, drawn from established international standards and CBUAE expectations, provide the framework for what an effective programme looks like.
Pillar 1 โ Governance and Tone from the Top
An effective AML/CFT programme starts with genuine commitment from the board and senior management. The board must understand the AML/CFT risks your bank faces, approve the framework for managing them, receive regular and meaningful reporting on compliance performance, and hold management accountable for outcomes.
Governance is not about creating committees and approval hierarchies on paper. It is about ensuring that the right people are making the right decisions with the right information โ and that financial crime risk is treated with the same seriousness as credit risk, market risk, and operational risk.
Pillar 2 โ Policies and Procedures
Your AML/CFT policies and procedures must be comprehensive, current, and operational. They must cover every aspect of your compliance programme โ from customer onboarding to transaction monitoring to STR filing to record keeping. They must be written in language that the people who use them can understand and follow. And they must be updated whenever the regulatory framework, the risk environment, or the bank's business model changes.
A policy manual that was last reviewed two years ago, that describes processes the bank no longer follows, or that staff have never read, is not a compliant AML/CFT programme.
Pillar 3 โ Training and Awareness
Every employee with AML/CFT responsibilities โ which in a bank means virtually every customer-facing and operations employee โ must receive regular, role-specific training. Training must build genuine understanding and practical competence. It must be updated as typologies, regulations, and the bank's risk profile evolve. And it must be documented so that you can demonstrate to a CBUAE examiner that specific individuals received specific training at specific times.
Training is not just an annual compliance module. The most effective programmes integrate AML/CFT awareness into day-to-day working culture โ through briefings, case studies, typology alerts, and managers who model the right behaviours.
Pillar 4 โ Transaction Monitoring and Controls
Your bank must have systems and processes that enable the ongoing monitoring of customer transactions against their expected profiles. In most banks, this involves a combination of automated transaction monitoring systems โ which generate alerts when transactions trigger defined rules or statistical anomalies โ and human review of those alerts by trained analysts.
The effectiveness of your transaction monitoring is a direct function of the quality of your customer risk profiles. If your KYC and CDD information is poor, your transaction monitoring will generate alerts that are impossible to evaluate meaningfully. Investing in KYC quality is investing in monitoring effectiveness.
Alert volumes, closure rationale quality, and the conversion rate from alerts to internal suspicion reports and STRs are all metrics that CBUAE examiners will examine.
Pillar 5 โ Independent Testing and Audit
Your internal audit function must independently test the effectiveness of your AML/CFT programme on a regular basis. This is not the same as the compliance function reviewing itself โ independent testing must be conducted by people who are separate from the AML/CFT programme they are testing.
Internal audit of your AML/CFT programme should assess whether controls are operating as designed, whether policies are being followed in practice, whether the risk assessment is current and accurate, and whether deficiencies identified in previous audits have been properly remediated. Audit findings must be reported to the board or board audit committee and tracked to closure.
Recent Developments and What to Watch in 2026
The UAE's AML/CFT regulatory environment is not static. The pace of change has been significant since 2022, and several developments in 2024 and 2025 have direct implications for your bank's compliance programme.
The UAE's Removal from the FATF Grey List (February 2024)
The UAE's removal from the FATF grey list in February 2024 was a major milestone, reflecting the substantial legislative, regulatory, and institutional reforms implemented since 2022. However, it would be a mistake to interpret grey-list removal as a signal that regulatory intensity will diminish.
The CBUAE and other UAE authorities have been explicit: the reforms of the grey-list period are permanent. The supervisory capacity built during that period โ more examiners, more frequent examinations, stronger enforcement โ is being maintained. Expectations of the banking sector remain as demanding as they were during the grey-list period, and enforcement activity has continued at an elevated level into 2025.
Grey-list removal has benefited the UAE's banking sector commercially โ some correspondent banking relationships that were restricted or reviewed during the grey-list period have been normalised, and international perceptions of the UAE financial system have improved. But this should be understood as a dividend of improved compliance โ not a signal to reduce it.
Growing Focus on Virtual Assets and VASPs
The regulation of virtual assets and VASPs is an area of significant and continuing development in the UAE. As a banking professional, your exposure to virtual asset risk comes primarily through your corporate customers โ businesses that operate in the virtual asset space, customers who have income or assets connected to virtual asset activities, and transactions that involve VASP counterparties.
Your bank must understand and appropriately manage this exposure. Customers operating as VASPs require enhanced scrutiny, and transactions involving virtual asset-related counterparties require careful evaluation. The CBUAE has issued guidance on managing virtual asset-related risks, and this is an area where examiner attention is increasing.
Beneficial Ownership Transparency Requirements
The UAE has significantly strengthened its beneficial ownership transparency regime โ one of the key reforms undertaken during the grey-list period. The requirement to identify, verify, and maintain current records of Ultimate Beneficial Owners applies to your bank both as a regulated entity (maintaining its own UBO register) and in its CDD processes (identifying UBOs of corporate customers).
In 2025, scrutiny of UBO quality โ whether banks have genuinely identified the natural persons who own and control their corporate customers, rather than accepting nominee structures or stopping at the first layer of ownership โ is a significant examination focus.
Increasing Scrutiny of High-Risk Sectors and Typologies
CBUAE examination focus in 2025 includes heightened scrutiny of banks' management of:
- Real estate-related transactions โ the UAE real estate sector is a historically significant money laundering vulnerability, and banks financing or processing transactions related to property purchases, particularly involving non-resident clients, are expected to apply rigorous CDD and EDD
- Trade finance โ trade-based money laundering remains one of the most complex and significant AML typologies globally, and CBUAE examiners are focusing on whether banks' trade finance operations have adequate AML controls
- High-net-worth and private banking โ the concentration of wealth and the complexity of structures common in private banking create specific AML vulnerabilities that require tailored controls
What Your Bank Should Be Doing Now
Regardless of where your bank sits in its AML/CFT compliance journey, there are several priorities that every UAE bank should be actively addressing in 2026:
- Ensure your Business Risk Assessment is current โ if it has not been updated since the grey-list period reforms or since significant changes in your business, it is overdue for review
- Review CDD file quality โ a systematic sample review of your customer files will identify gaps in KYC information, missing UBO documentation, or risk classifications that are no longer appropriate
- Assess your transaction monitoring effectiveness โ review alert volumes, closure quality, and STR conversion rates honestly. If your STR volumes seem low relative to your customer base and risk profile, understand why
- Invest in training โ ensure that every relevant employee has received current, role-specific AML/CFT training and that records demonstrate this
- Strengthen governance reporting โ ensure that your board and senior management are receiving meaningful, data-driven AML/CFT management information that enables genuine oversight
- Review your sanctions screening coverage โ ensure you are screening against all applicable lists and that your hit management process is robust and well-documented
The expectation in the UAE banking sector in 2026 is not compliance that passes an examination โ it is compliance that genuinely works. The CBUAE's examination approach is designed to test the difference. Building a programme that is substantive, current, and operationally embedded is not just the right approach from a regulatory standpoint โ it is the only approach that holds up over time.
