AML Compliance in the UAE Under the New Law: What DNFBPs Must Do Now

Home AML AML Compliance in the UAE Under the New Law: What DNFBPs Must Do Now
Vikash Bhuwania
Written by Vikash Bhuwania
Contributors
Senior Tax Associate
Reviewed by Muhammad Aaliyan Ibrahim Founder & Managing Partner
Home AML AML Compliance in the UAE Under the New Law: What DNFBPs Must Do Now

For a Designated Non-Financial Business or Profession (DNFBP), having an AML framework on paper is no longer enough. The question today is whether your controls would stand up if regulators asked why a decision was made, what checks were performed, and what evidence supports those decisions. AML compliance UAE requirements have moved towards a more evidence-driven approach, where gaps in oversight can create consequences beyond the organisation itself.

 

The change is particularly important for owners, directors and senior managers. Responsibility is no longer limited to whether the company had policies in place; the effectiveness of those policies, the decisions taken, and the supervision exercised may also come under scrutiny.

 

The UAE strengthened its anti-money laundering framework through Federal Decree-Law No. 10 of 2025, effective from 14 October 2025. The new framework introduced a lower knowledge threshold, made proliferation financing a standalone offence, and increased focus on personal accountability alongside corporate compliance obligations.

 

The UAE introduced Federal Decree-Law No. 10 of 2025, effective from 14 October 2025, replacing the previous AML framework under Federal Law No. 20 of 2018. The knowledge standard has shifted from actual knowledge towards an objective assessment of what a person reasonably should have known. Proliferation financing is now treated as a standalone criminal offence under the updated AML/CFT/CPF framework. Directors, managers and responsible compliance personnel may face increased personal exposure where obligations are breached or oversight failures occur. DNFBPs must reassess whether their existing AML controls, risk assessments, customer due diligence and reporting processes remain effective under the new requirements.

What Changed, and When It Took Effect

The anti money laundering UAE framework entered a new phase with the introduction of Federal Decree-Law No. 10 of 2025 on Anti-Money Laundering, Combating the Financing of Terrorism and Countering Proliferation Financing. The new legislation replaced the previous framework under Federal Law No. 20 of 2018 and introduced changes that directly affect DNFBPs, management responsibility, proliferation financing controls and regulatory expectations.

 

The UAE’s updated AML regime forms part of its broader commitment to strengthening financial crime prevention measures. The revised framework should be read alongside the wider guidance issued through the UAE’s official AML channels, including the UAE Government Portal’s AML/CFT framework overview.

 

The new law was issued in October 2025 and became effective on 14 October 2025. For DNFBPs, the key question is not whether an AML policy exists, but whether the organisation’s risk assessment, customer due diligence procedures, reporting controls and governance arrangements remain effective under the updated requirements.

 

Businesses that need a refresher on existing obligations, including DNFBP requirements, goAML processes and AML/CFT fundamentals, can refer to ADEPTS’ detailed guide on UAE AML/CFT regulatory compliance requirements.

Area Under Federal Law No. 20 of 2018 Under Federal Decree-Law No. 10 of 2025
Knowledge threshold Liability generally focused on actual knowledge of criminal conduct Introduces a broader assessment where liability may arise where a person reasonably should have known
Proliferation financing Addressed primarily through sanctions-related obligations Recognised as a standalone offence within the AML/CFT/CPF framework
Corporate liability Corporate entities could face penalties for AML/CFT violations Corporate exposure continues with increased focus on accountability and enforcement
Manager and senior officer responsibility Liability depended on applicable circumstances and involvement Greater emphasis on personal responsibility of managers and responsible officers where breaches occur
Virtual asset activities Subject to evolving regulatory treatment Virtual asset-related risks are expressly considered within the strengthened framework
Limitation periods Governed under the previous legal framework Requires assessment under the updated decree-law provisions

The criminal provisions under Federal Decree-Law No. 10 of 2025 should be distinguished from administrative penalties introduced through Cabinet Decision No. 134 of 2025. These operate as separate enforcement mechanisms: criminal sanctions arise under the decree-law, while administrative penalties apply to regulatory breaches identified by supervisory authorities.

 

For DNFBPs, this distinction matters because compliance failures may create exposure at multiple levels. A documented AML programme, supported by evidence of implementation and ongoing monitoring, is increasingly important under the updated framework.

Are You a DNFBP? The Named Categories

Before reviewing your AML controls, the first question is whether your business falls within the scope of a Designated Non-Financial Business and Profession (DNFBP). Understanding the dnfbp meaning is important because DNFBPs carry specific obligations relating to customer due diligence, risk assessment, record keeping and suspicious transaction reporting.

 

The UAE AML framework applies to several non-financial sectors that can be exposed to money laundering and terrorist financing risks. The UAE Ministry of Economy’s AML/CFT guidance for DNFBPs sets out the supervisory approach for sectors including professional service providers, real estate businesses and dealers in precious metals and stones.

 

For a detailed overview of the wider AML framework, including DNFBP obligations, goAML requirements and compliance expectations, refer to ADEPTS’ UAE AML/CFT regulatory compliance guide.

 

The practical obligations differ depending on the nature of the business. A real estate brokerage does not face the same risk indicators as an audit firm or a corporate service provider. The following matrix highlights common areas where DNFBPs should pay closer attention.

DNFBP category Typical trigger activity Supervisory authority Obligation most often missed
Accountants and auditors Providing accounting, audit, assurance or professional services involving client funds, structures or transactions Relevant professional supervisory authorities Documenting customer risk assessments, beneficial ownership checks and rationale for accepting higher-risk clients
Real estate brokers and agents Buying, selling or facilitating transactions involving real estate assets Ministry of Economy and relevant local regulators Maintaining evidence of source of funds checks and enhanced due diligence for higher-risk transactions
Corporate service providers and company formation agents Establishing legal entities, managing structures or assisting with ownership arrangements Ministry of Economy and applicable licensing authorities Identifying beneficial owners and understanding the purpose and ownership structure of entities
Dealers in precious metals and stones Transactions involving high-value commodities Ministry of Economy and relevant supervisors Applying appropriate customer identification and transaction monitoring controls
Lawyers and notaries Certain legal activities involving transactions, structures or client assets Relevant legal supervisory authorities Ensuring AML procedures apply when performing activities within DNFBP scope

Accounting and audit firms are themselves included within the DNFBP framework. ADEPTS operates within this environment as a regulated professional services firm and applies AML controls internally as part of its own compliance responsibilities. This practical perspective allows AML recommendations to be assessed from the position of a regulated DNFBP, not only from an advisory standpoint.

 

Businesses involved in crypto-related activities should also consider whether they fall within the scope of virtual asset activities regulated under the UAE AML/CFT framework. The UAE Government Portal’s AML/CFT overview provides the broader regulatory context.

 

If you operate within any of these categories, the next question is not only whether you are covered by the law, but whether your existing AML programme would withstand regulatory scrutiny under the updated requirements.

The Lower Knowledge Threshold: “Should Have Known”

The Lower Knowledge Threshold: “Should Have Known”

One of the most significant changes under the updated AML compliance UAE framework is the shift from focusing only on what a person actually knew to assessing what they reasonably should have identified from the circumstances available to them. Under Federal Decree-Law No. 10 of 2025, knowledge may be inferred from factual and objective circumstances rather than requiring direct evidence of awareness in every case.

 

For DNFBPs, this changes the compliance question. It is no longer enough to say that a firm was unaware of a risk. Regulators may examine whether warning indicators existed, whether appropriate checks were performed, and whether the business acted reasonably based on the information available.

 

The updated approach places greater importance on documented decision-making. Customer due diligence, beneficial ownership verification, source of funds or wealth assessment, escalation decisions and internal approvals should all demonstrate why a particular conclusion was reached. The UAE Government’s AML/CFT framework reflects this risk-based approach, where regulated businesses are expected to identify and manage financial crime risks.

 

In practical terms, this may affect situations such as:

Situation What may create exposure under the updated approach
A professional firm accepts a client without properly documenting source of wealth information The absence of supporting evidence may raise questions about whether the risk should have been identified and assessed
A real estate broker proceeds with a transaction despite unusual payment patterns or ownership structures Ignoring visible indicators may suggest insufficient risk assessment or escalation procedures
A corporate service provider establishes a structure without establishing beneficial ownership Failure to understand ownership and control arrangements may indicate inadequate customer due diligence

The practical consequence is simple: the defence is the file.

 

What was requested, what information was obtained, what checks were completed, who reviewed the matter and when those actions occurred should all be supported by evidence.

 

The updated AML regulations require DNFBPs to identify, assess, document and continuously update financial crime risks, while maintaining relevant records for supervisory review. Businesses reviewing whether their current controls meet these expectations can consider an independent AML compliance audit in UAE to identify documentation gaps and control weaknesses.

 

For organisations that need to revisit the wider framework, ADEPTS’ UAE AML/CFT regulatory compliance guide explains the core obligations applicable to DNFBPs, including risk assessment, customer due diligence and reporting requirements.

Proliferation Financing as a Standalone Offence

Proliferation financing refers to providing funds or financial services that support the development, acquisition, possession or transfer of weapons of mass destruction and related materials. Unlike traditional AML risks that focus primarily on proceeds of crime, proliferation financing concerns the misuse of financial channels to support activities prohibited under international sanctions frameworks.

 

Under the updated UAE framework, proliferation financing has received greater focus as part of the country’s strengthened approach to combating money laundering, terrorist financing and proliferation financing. The UAE Government’s AML/CFT framework highlights the UAE’s risk-based approach, including measures designed to prevent misuse of the financial system for illicit purposes.

 

For DNFBPs, the important point is that compliance does not mean identifying weapons-related activity directly. The responsibility is to understand whether a client, transaction or business relationship presents a proliferation financing risk and whether appropriate controls are applied.

 

This means PF considerations should be incorporated into the enterprise-wide risk assessment, customer due diligence procedures and transaction monitoring framework. The UAE Ministry of Economy’s AML/CFT guidance for DNFBPs emphasises the importance of risk-based compliance obligations for designated non-financial businesses and professions.

 

Higher-risk situations may include clients involved in dual-use goods, international trade, logistics, complex ownership structures or transactions connected with higher-risk jurisdictions. These areas are particularly relevant for corporate service providers, accountants and professional firms serving internationally connected businesses.

 

Sanctions screening is also a critical control area. DNFBPs should ensure that their screening processes identify relevant updates, including applicable United Nations Security Council designations, and that potential matches are appropriately reviewed and documented. The UAE Financial Intelligence Unit provides guidance and resources supporting the UAE’s wider AML/CFT/CPF framework.

 

For businesses reviewing whether their existing controls adequately address these expanded requirements, ADEPTS’ UAE AML/CFT regulatory compliance guide explains the broader obligations applicable to DNFBPs. An independent AML compliance audit in UAE can also help assess whether risk assessments, customer due diligence and monitoring procedures are properly documented.

Personal Criminal Liability for Managers and Directors

For many owner-managed DNFBPs, AML responsibility does not sit with a separate compliance department. The same individual may be the owner, senior manager and AML compliance officer. This creates a practical challenge under the updated framework: failures in oversight may not remain only a corporate issue.

 

Under the UAE’s strengthened AML regime, managers and responsible individuals of legal entities may face personal exposure in certain circumstances, separately from the liability of the organisation itself. The focus is not simply whether a company had AML policies in place, but whether those responsible for managing the business took appropriate steps to implement, supervise and maintain those controls.

 

The UAE Government’s AML/CFT framework reflects the UAE’s risk-based compliance approach, where regulated businesses are expected to establish appropriate governance, monitoring and reporting arrangements.

 

The practical question for a DNFBP owner is:

 

Did you approve the policies, review higher-risk relationships and maintain evidence that your compliance responsibilities were actively performed?

 

The UAE Ministry of Economy’s AML guidance for DNFBPs highlights the importance of effective compliance measures across designated sectors, including professional service providers and other non-financial businesses.

 

For a small audit firm, accounting practice, corporate service provider or advisory business, this distinction matters because the individual responsible for compliance may also be the person making client acceptance decisions, approving risk assessments and overseeing employees.

 

The UAE Financial Intelligence Unit provides the national platform and guidance framework supporting suspicious transaction reporting and AML/CFT compliance obligations.

“The practical change is that compliance cannot remain a document sitting on a shelf. Owners and managers need evidence that they understood the risks, reviewed controls and acted when issues were identified.”
— ADEPTS Compliance Team

Reducing personal exposure requires documented oversight. This includes management approval of AML policies, evidence of high-risk client reviews, documented escalation decisions, employee training records and a clear audit trail showing that responsibilities were actively discharged.

 

Businesses reviewing their current governance structure can refer to ADEPTS’ UAE AML/CFT regulatory compliance guide for the wider compliance framework. Organisations requiring a detailed assessment of their controls can consider an AML compliance audit in UAE or a targeted AML compliance review and advisory service.

What Non-Compliance Now Costs

What Non-Compliance Now Costs

AML enforcement in the UAE is no longer limited to checking whether a business has a written policy. Supervisory authorities increasingly focus on whether DNFBPs can demonstrate that their controls operate effectively, risks are assessed properly and reporting obligations are being followed.

 

The updated AML compliance UAE framework creates two separate layers of exposure: criminal penalties under Federal Decree-Law No. 10 of 2025 and administrative penalties issued under Cabinet Decision No. 134 of 2025. These should not be treated as the same mechanism. Criminal sanctions follow the applicable legal process, while administrative penalties are imposed by competent supervisory authorities for regulatory breaches.

 

The UAE Government Portal’s AML/CFT framework provides the wider regulatory context, while the UAE Ministry of Economy’s AML guidance for DNFBPs explains the compliance expectations applicable to designated non-financial businesses and professions.

 

As of publication, penalty ranges should be confirmed directly against the relevant provisions of Federal Decree-Law No. 10 of 2025 and Cabinet Decision No. 134 of 2025 before relying on specific figures.

Exposure layer Who it applies to Examples of exposure
Criminal penalties under Federal Decree-Law No. 10 of 2025 Legal persons and individuals where criminal offences are established Money laundering, terrorist financing, proliferation financing and related offences subject to prosecution
Administrative penalties under Cabinet Decision No. 134 of 2025 DNFBPs and regulated entities under supervisory frameworks Regulatory breaches, compliance failures and ongoing violations identified by competent authorities

A business may face both types of consequences depending on the nature of the breach. For example, failing to perform or document a proliferation financing risk assessment, ignoring sanctions screening requirements, maintaining inactive goAML registration without proper reporting processes, or failing to document enhanced due diligence may create regulatory concerns.

 

The UAE Financial Intelligence Unit provides the national framework supporting suspicious transaction reporting and AML/CFT compliance processes, including the importance of effective reporting controls.

 

UAE enforcement activity demonstrates that AML obligations are actively monitored. ADEPTS has analysed recent enforcement trends and sector impacts in its article on UAE AML enforcement and AED 380M+ fines.

 

For DNFBPs, the practical response is not only understanding potential penalties but ensuring that controls are documented and operational. A structured AML compliance audit in UAE can help identify weaknesses before they become enforcement issues.

What a Defensible AML Programme Looks Like Under the New Law

The question for DNFBPs is no longer whether an AML policy exists. The real question is whether the programme can withstand regulatory review when tested against the updated requirements. Under the strengthened AML compliance UAE framework, a compliance programme that is documented but not implemented, reviewed or evidenced may create significant weaknesses.

 

The UAE Government’s AML/CFT framework follows a risk-based approach, requiring businesses to identify, assess and manage financial crime risks according to the nature of their activities. For DNFBPs, this means reviewing whether existing controls remain effective under the updated requirements.

 

A defensible AML programme should be tested through the following gap checks:

  1. Update the enterprise-wide risk assessment (EWRA)
    Confirm that proliferation financing risks, sector-specific threats and relevant customer risk factors have been assessed and documented. The UAE Ministry of Economy’s AML guidance for DNFBPs emphasises the importance of maintaining risk-based compliance procedures.

  2. Review customer due diligence (CDD) and enhanced due diligence (EDD) files
    Ensure source of wealth, source of funds, beneficial ownership and risk-rating decisions are properly documented. The file should demonstrate why a client was accepted and how risks were addressed.

  3. Confirm goAML registration and reporting processes
    Registration alone is not sufficient. DNFBPs should confirm that suspicious transaction reporting procedures are active and employees understand when escalation is required. The UAE Financial Intelligence Unit provides the national framework supporting suspicious transaction reporting and AML/CFT obligations.

  4. Refresh AML training programmes
    Employees should understand changes affecting risk assessment, reporting obligations, sanctions screening and personal responsibilities. Training records should demonstrate who attended, when training occurred and what topics were covered.

  5. Evidence management oversight
    Senior management approval of AML policies, high-risk client reviews and remediation actions should be documented. Compliance responsibility should be supported by evidence, not only assigned through job titles.

  6. Perform an independent AML audit
    A periodic review should test whether policies operate effectively in practice. ADEPTS’ guide on AML compliance audits in UAE explains how independent testing can identify weaknesses in AML frameworks.

  7. Validate sanctions and proliferation financing screening controls
    Screening processes should operate against updated designation lists, with evidence of reviews, alerts and escalation decisions where required.

ADEPTS’ experience with DNFBP compliance reviews shows that common weaknesses are often not the absence of policies, but missing evidence — incomplete risk assessments, undocumented enhanced due diligence, outdated training records and insufficient approval trails.

 

Our UAE AML/CFT regulatory compliance guide provides further guidance on DNFBP obligations, while our analysis of UAE AML enforcement trends and AED 380M+ fines highlights why regulators are focusing increasingly on implementation rather than documentation alone.

 

Under an objective assessment approach, the strongest protection for a DNFBP is simple: the compliance decision must be supported by evidence.

How ADEPTS Handles AML Compliance

If your DNFBP’s AML programme was built under the previous framework, the question now is whether it remains effective under the updated law and whether your governance structure can demonstrate active oversight.

 

ADEPTS supports DNFBPs in strengthening their AML frameworks through practical, evidence-based compliance reviews, including:

  • AML programme gap analysis against Federal Decree-Law No. 10 of 2025 requirements.

  • Enterprise-wide risk assessment updates, including proliferation financing risk considerations.

  • AML policy and procedure drafting, review and remediation support.

  • goAML registration review and suspicious transaction reporting process assessment.

  • Customer due diligence (CDD) and enhanced due diligence (EDD) framework design.

  • AML compliance training for employees and responsible officers.

  • Independent AML audit and effectiveness testing.

  • Inspection readiness reviews from a supervisory perspective.

Our approach is focused on whether controls work in practice, not only whether documents exist. ADEPTS is itself a regulated DNFBP and applies AML governance processes internally, giving our team practical understanding of the responsibilities faced by professional service firms.

 

You can learn more about our AML compliance services in the UAE, or review our UAE AML/CFT regulatory compliance guide for an overview of DNFBP obligations and regulatory expectations.

 

For organisations seeking independent testing of their existing framework, our AML compliance audit services in UAE focus on identifying control gaps, documentation weaknesses and areas requiring remediation.

 

ADEPTS delivers structured AML reviews, documented remediation plans and practical compliance support designed around the actual risks faced by DNFBPs.

Conclusion

The updated AML framework changes how DNFBPs should think about compliance. The question is no longer only whether a policy exists, but whether the business can demonstrate that appropriate decisions were made, risks were assessed and controls were actively applied.

 

For managers and responsible officers, the compliance responsibility is personal as well as organisational. A programme created under the previous framework may not automatically address the expectations introduced by the new requirements.

 

The UAE’s strengthened AML regime reflects its continued focus on maintaining a transparent and internationally aligned business environment. Well-governed DNFBPs can meet these expectations by reviewing their controls, documenting their decisions and addressing gaps before they become regulatory concerns.

 

A practical first step is an AML programme gap review against the updated requirements. ADEPTS helps DNFBPs assess existing frameworks, identify weaknesses and strengthen compliance arrangements through its AML compliance services in the UAE.

 

Review your AML framework now — before a regulator reviews it for you.

FAQs:

Yes. Accounting and audit firms may fall within the DNFBP framework regardless of whether their clients are small local businesses. The nature of the service provided determines the AML obligations, not only the size of the client base. DNFBPs should assess their activities, risks and customer relationships under the updated requirements.

 

For more information on DNFBP obligations, refer to ADEPTS’ UAE AML/CFT regulatory compliance guide.

Not necessarily. An existing AML policy may remain relevant, but it should be reviewed against the requirements introduced by the updated framework. DNFBPs should reassess risk assessments, proliferation financing controls, customer due diligence procedures, reporting processes and management oversight to identify required updates.

Potentially, depending on the circumstances. Personal exposure does not arise simply because an employee makes a mistake, but managers and responsible officers may face scrutiny where failures involve inadequate supervision, oversight or compliance controls. Evidence of approvals, reviews and escalation procedures becomes important in demonstrating effective management oversight.

Yes. Proliferation financing controls are relevant to DNFBPs, including businesses that may appear unrelated to weapons or trade activities. Real estate firms should consider whether customer profiles, ownership structures, transaction patterns or jurisdictional connections create higher-risk indicators requiring enhanced due diligence and monitoring.

 

The UAE Ministry of Economy’s AML guidance for DNFBPs provides further information on risk-based compliance expectations.

Registration alone does not complete an AML obligation. A DNFBP must have procedures to identify suspicious activity, assess whether reporting is required and maintain evidence of its compliance decisions. Failure to understand reporting obligations or maintain appropriate controls may create regulatory concerns.

 

The UAE Financial Intelligence Unit provides guidance on suspicious transaction reporting processes.

Free zone DNFBPs remain subject to the UAE’s AML/CFT framework, while the relevant supervisory authority may depend on the nature of the activity and licensing arrangement. Businesses should identify their applicable regulator and ensure that internal AML procedures address both federal requirements and any sector-specific guidance.

 

The UAE Government AML/CFT framework provides the broader regulatory context.

No. Outsourcing compliance support does not automatically remove management responsibility. A business may appoint external support for AML activities, but senior management remains responsible for ensuring appropriate governance, oversight and implementation of controls. The arrangement should clearly define responsibilities and maintain evidence of supervision.

 

ADEPTS provides AML compliance services in the UAE including compliance reviews, policy support and remediation assistance.

No. DNFBPs should not disclose that a suspicious transaction report has been filed or that an investigation may be underway. This is commonly known as tipping off and can compromise enforcement activities. Employees should understand confidentiality requirements and receive appropriate AML training on reporting procedures.

References

Related Articles

Vikash Bhuwania
Written by Vikash Bhuwania
Contributors
Senior Tax Associate
Reviewed by Muhammad Aaliyan Ibrahim Founder & Managing Partner