CBUAE — AML & CFT
AML/CFT training obligations under Federal Decree Law 20/2018 and CBUAE procedures.
What are the CBUAE AML/CFT requirements?
The Central Bank of the UAE (CBUAE) mandates comprehensive anti-money laundering (AML) and counter-terrorism financing (CTF) requirements for all licensed financial institutions in the UAE. These include customer due diligence, transaction monitoring, suspicious activity reporting, sanctions screening, and ongoing employee training.
Who must comply with CBUAE AML/CFT requirements?
All financial institutions licensed by the CBUAE must comply, including banks, exchange houses, finance companies, insurance companies, payment service providers, and other licensed financial entities. The requirements also extend to designated non-financial businesses and professions as specified by the UAE's regulatory framework.
What is Customer Due Diligence (CDD)?
Customer Due Diligence is the process of identifying and verifying the identity of customers before establishing a business relationship. It includes collecting identification documents, verifying beneficial ownership, understanding the purpose and nature of the business relationship, and conducting ongoing monitoring. Enhanced due diligence is required for high-risk customers such as politically exposed persons.
What is a Suspicious Activity Report (SAR)?
A Suspicious Activity Report is a mandatory filing with the UAE Financial Intelligence Unit (FIU) when a financial institution suspects that a transaction involves proceeds of crime, money laundering, or terrorism financing. SARs must be filed promptly, and institutions must not tip off the customer that a report has been made.
What training is required for AML/CFT compliance?
The CBUAE requires all relevant staff to receive regular AML/CFT training covering the UAE's legal framework, the institution's internal policies and procedures, how to identify suspicious transactions, reporting obligations, and the consequences of non-compliance. Training must be documented and records retained for audit purposes.
What are the penalties for AML/CFT non-compliance?
Penalties include significant financial fines imposed by the CBUAE, restrictions on business activities, requirements to implement corrective measures, and potential criminal prosecution of individuals under UAE Federal Law. The CBUAE can also revoke or suspend licenses for serious or repeated violations.
What is Enhanced Due Diligence (EDD)?
Enhanced Due Diligence is a higher level of scrutiny applied to customers or transactions that present elevated money laundering or terrorism financing risks. This includes politically exposed persons, customers from high-risk jurisdictions, complex or unusually large transactions, and correspondent banking relationships. EDD requires more detailed verification, closer ongoing monitoring, and senior management approval
What is transaction monitoring?
Transaction monitoring is the ongoing process of reviewing customer transactions to detect patterns or activities that may indicate money laundering, terrorism financing, or other financial crimes. Financial institutions must implement automated monitoring systems capable of flagging unusual transactions based on customer profiles, transaction patterns, and risk indicators.
What records must be maintained for AML/CFT compliance?
Financial institutions must maintain records of all customer identification and verification documents, transaction records, suspicious activity reports, internal audit findings, training records, and risk assessments. Records must be retained for a minimum of five years after the end of the business relationship or the date of the transaction, whichever is later.
How often should AML/CFT risk assessments be conducted?
The CBUAE expects financial institutions to conduct enterprise-wide AML/CFT risk assessments at least annually, and whenever there are significant changes to the business, products, customers, or regulatory environment. Individual customer risk assessments should be reviewed periodically based on the customer's risk rating and whenever triggered by changes in the customer's profile or transaction patterns.
What does Federal Decree Law 20/2018 require for AML/CFT employee training?
Federal Decree Law No. 20/2018 requires all Licensed Financial Institutions to implement AML/CFT training programmes for their employees.
The law mandates that staff understand their obligations to detect and report suspicious transactions, apply customer due diligence procedures, and comply with sanctions screening requirements.
CBUAE's Role-Based AML/CFT/CPF Training Best Practices (November 2025) further specify that training must be tailored to employee roles and risk exposure, documented, and refreshed regularly.
Visit our CBUAE Course Hub.
Who in a UAE bank needs to complete AML/CFT training?
The CBUAE expects AML/CFT training to cover all employees — from the Board of Directors and senior management to front-line staff, new hires, and external contractors who interact with customers or handle transactions.
Role-based training is required, meaning compliance officers, relationship managers, IT teams, and operations staff each need training tailored to their specific risk exposure and responsibilities.
Visit our CBUAE Course Hub.
How does this course satisfy CBUAE's role-based AML/CFT training requirements?
This course is mapped to Federal Decree Law No. 20/2018, CBUAE AML/CFT Procedures Notice 74/2019, and the Role-Based AML/CFT/CPF Training Best Practices issued in November 2025.
It covers money laundering typologies, terrorist financing red flags, sanctions screening obligations, suspicious transaction reporting, and customer due diligence — the core topics CBUAE examiners expect employees to demonstrate understanding of during inspections.
Visit our CBUAE Course Hub.
What evidence does course completion generate for CBUAE audits?
Every completion generates a timestamped record including the employee name, course title, completion date, assessment score, and a certificate of completion. These records are exportable as compliance reports formatted to satisfy CBUAE examiner requests. Because the course includes knowledge assessments, the evidence demonstrates actual comprehension of AML/CFT obligations — not just course attendance.
Visit our CBUAE Course Hub.
Which employees need specialized TBML training?
While general AML training is for everyone, specialized TBML training is mandatory for Trade Finance operations, Relationship Managers handling corporate trade accounts, and AML Compliance officers. These staff members must be equipped to recognize "red flags" relating to jurisdictions, goods types, and unusual payment arrangements that are unique to the trade sector.
What are the CBUAE expectations for TBML risk mitigation?
The CBUAE "Guidance for LFIs on Risks Related to TBML and Transshipment" requires institutions to implement robust controls to detect the manipulation of trade transactions. This includes identifying "Red Flags" such as over-invoicing, under-invoicing, and "Phantom Shipping." LFIs must have specialized procedures to scrutinize trade documents (Bills of Lading, Invoices) for inconsistencies that suggest value movement for illicit purposes.
How does this course align with FATF and CBUAE TBML Guidance?
This course is mapped to the CBUAE TBML Guidance (effective 2025) and FATF best practices. It covers the end-to-end trade lifecycle, from Letter of Credit (LC) issuance to payment. Modules include dual-use goods screening, vessel tracking, and the analysis of complex corporate structures often used in illicit transshipment to bypass sanctions or launder funds.
What are the common TBML "Red Flags" staff must be able to identify?
Staff must be trained to spot anomalies such as: (1) Significant discrepancies between the description of the goods on the bill of lading and the invoice; (2) Payments made by third parties with no apparent connection to the trade transaction; and (3) Transactions involving "High-Risk" goods like electronics or precious metals destined for transshipment hubs without a clear economic rationale.
What is the "Dual-Use Goods" requirement under UAE Law?
UAE regulators place heavy emphasis on preventing the financing of proliferation. Staff must be trained to identify "Dual-Use Goods"—items that have both commercial and military applications (e.g., specific chemicals or specialized valves). LFIs are required to screen trade transactions against prohibited lists and ensure that Export Control licenses are in place where required by the UAE Executive Office for Control and Non-Proliferation (EOCN).
What are the foundational CDD requirements under UAE AML Law?
As per Federal Decretal-Law No. (20) of 2018 and its Executive Regulations, LFIs must perform CDD for all customers before or during the establishment of a business relationship. This includes identifying and verifying the customer’s identity, identifying the Beneficial Owner (any individual owning 25% or more), and understanding the intended nature and purpose of the business relationship.
How does this course align with the CBUAE AML/CFT Rulebook?
This course is mapped to the CBUAE Guidance on CDD/KYC and Record-Keeping. It covers the "Risk-Based Approach," distinguishing between Simplified Due Diligence (SDD) for low-risk customers and Enhanced Due Diligence (EDD) for high-risk customers, such as Politically Exposed Persons (PEPs) or customers from high-risk jurisdictions as identified by the FATF.
What are the "Ongoing Monitoring" obligations for LFI staff?
CDD is not a one-time event. CBUAE regulations require "Ongoing Due Diligence" to ensure that the information held on file remains accurate and up-to-date. Staff must be trained to conduct periodic reviews and trigger "Event-Driven" reviews when a customer’s profile changes, such as a change in ownership, a sudden increase in transaction volume, or the discovery of adverse media.
How should staff handle the identification of "Beneficial Owners"?
Staff must be trained to "look through" corporate layers to identify the natural person(s) who ultimately own or control the legal entity. CBUAE standards require obtaining a clear understanding of the ownership and control structure. If a customer fails to provide information on the Beneficial Owner, staff must be trained on the mandatory "Non-Onboarding" and "STR/SAR filing" protocols.
What is the mandatory record-keeping period for CDD documents in the UAE?
Under UAE Law, LFIs must maintain all records, documents, and data for at least five (5) years following the completion of a transaction or the termination of the business relationship. These records must be sufficient to allow for the reconstruction of individual transactions and must be made available to the CBUAE or the UAE Financial Intelligence Unit (FIU) upon request.
What is "Specific Due Diligence" for Correspondent Banking?
As per Article 25 of the AML-CFT Decision, LFIs must perform "Enhanced Due Diligence" on any "Respondent" institution before establishing a correspondent relationship. This includes evaluating the respondent's AML/CFT controls, verifying its reputation, and ensuring it is subject to effective supervision in its home jurisdiction.
How does this course align with CBUAE Guidance on Correspondent Banking?
This course is mapped to the CBUAE "Guidance for LFIs on Correspondent Banking Relationships." It covers the "Wolfsberg Group" standards, the use of the AML Questionnaire, and the mandatory requirement for Senior Management approval before any new correspondent relationship is activated.
What is a "Shell Bank" and why are they prohibited?
A "Shell Bank" is a bank that has no physical presence in the country where it is incorporated and is not affiliated with a regulated financial group. CBUAE regulations strictly prohibit LFIs from entering into or continuing a correspondent relationship with a shell bank, or with a respondent bank that is known to permit its accounts to be used by shell banks.
What are "Nested" or "Downstream" correspondent relationships?
"Nested" relationships occur when a respondent bank provides correspondent services to other financial institutions through its account with the UAE LFI. Staff must be trained to understand the risks of "limited visibility" in these chains and the requirement to assess whether the respondent bank effectively monitors its own downstream customers.
How must staff manage the "Annual Review" of correspondent relationships?
Correspondent relationships must be reviewed at least annually (or more frequently for high-risk respondents). Training covers the "Recertification" process, where staff must verify that the respondent’s license remains valid, its ownership hasn't changed to include PEPs, and its AML controls have not deteriorated. Any significant adverse news must be escalated to the Board or Senior Management.