AML/CFT Compliance Program in the UAE: Dubai & Sharjah Guide (2026)
Business Solutions

AML/CFT Compliance Program in the UAE: Dubai & Sharjah Guide (2026)

By ModsolutionsAugust 20, 2026

For businesses such as a real estate company, a corporate service provider, a law firm, an accounting firm, or a precious metals dealer in Dubai or Sharjah, AML/CFT compliance is not just a piece of paper; it is a condition of obtaining a license. Since October 2025, the UAE has had a completely restructured anti-money laundering framework in place, and businesses that continue to have anti-money laundering policies that were drafted under the previous law are the ones appearing in the anti-money laundering enforcement statistics. This guide takes you through the process of who should be registered, what a compliant program should include, and how ModSolutions takes you from risk assessment to your first suspicious transaction report.

The information contained in this article is general in nature and should not be relied upon for legal advice. It's important to always verify your exact responsibilities with a licensed AML advisor or legal counsel. 

What Is an AML/CFT Compliance Program?

An AML CFT Compliance Program is a written framework comprising policies, responsibilities, and reporting mechanisms that an entity uses for identifying, preventing, and reporting money laundering and terrorist financing. In the UAE, the requirement to implement such a program is statutory, rather than best practice, for all financial institutions and the prescribed categories of non-financial businesses referred to as DNFBPs.

A working program typically includes a documented risk assessment, written AML/CFT policies, a named compliance officer (MLRO), customer due diligence procedures, sanctions screening, staff training, and registration on the government's reporting platforms. Having a "policy" sitting unused in a drawer does not satisfy the law—regulators expect the program to be actively applied and evidenced.

The Legal Framework Behind It (What Changed in 2025)

However, as of now, the Anti-Money Laundering/Countering the Financing of Terrorism regime of the UAE has been provided under Federal Decree-Law No. 10 of 2025 on Anti-Money Laundering, Combating the Financing of Terrorism and Countering the Financing of Proliferation, effective from 14 October 2025, along with its executive regulations, namely, Cabinet Resolution No. 134 of 2025, effective from 14 December 2025.

These two pieces of legislation have superseded the earlier Federal Decree-Law No. 20 of 2018 and Cabinet Decision No. 10 of 2019, and both these pieces of legislation are no longer applicable. However, if your risk assessment or any other document references the older piece of legislation, then you are referring to a repealed law.

Key regulators and bodies you'll encounter:

  • UAE Central Bank (CBUAE) — primary AML/CFT supervisor for banks, exchange houses, and other licensed financial institutions.
  • Ministry of Economy — supervisory authority for most DNFBPs, including real estate, legal, accounting, and corporate service providers.
  • UAE Financial Intelligence Unit (FIU)receives and analyzes suspicious transaction reports filed via goAML.
  • Dubai Economy and the Sharjah Economic Development Department (SEDD)—issue and renew trade licenses and coordinate with the Ministry of Economy on DNFBP compliance checks in their respective emirates.
  • Executive Office for AML/CTF (EO AML/CTF) — coordinates national policy and the UAE's relationship with FATF.

The UAE was removed from the FATF grey list in February 2024, and the 2025 legislative overhaul reflects the country's continued push—under its Vision 2031 financial transparency agenda—to keep pace with FATF standards rather than fall back into heightened scrutiny.

Who Needs AML Registration in the UAE? (DNFBP Checklist)

You are almost certainly a DNFBP—and therefore subject to full AML/CFT obligations—if your business falls into one of these categories under Article 3 of Cabinet Resolution No. 134 of 2025:

  • Real estate brokers and agents who conclude sales, purchases, or settlements on behalf of clients (pure leasing/letting agencies that never handle a sale generally fall outside this definition, though a supervisory authority can still bring them in).
  • Dealers in precious metals and stones (gold, jewelry, and diamonds) for cash transactions at or above AED 55,000.
  • Lawyers, notaries, and independent legal professionals performing specified transactional work — company formation, managing client funds, buying/selling real estate or businesses on a client's behalf.
  • Independent accountants and auditors carrying out the same categories of transactional work.
  • Corporate and trust service providers (CSPs) — company formation agents, registered agents, nominee directors/shareholders, and firms providing a registered office or correspondence address.
  • Commercial gaming operators, including casinos, online gaming platforms, and e-sports operators, for transactions of AED 11,000 or more (added as a formally recognized DNFBP category under the 2025 framework).

Not sure which category you fall into? A company secretarial firm that also offers nominee directorship is a CSP. An accounting firm that also provides tax agency services can carry dual obligations. When in doubt, get your activity confirmed against your trade license—this is one of the most common gaps ModSolutions finds during onboarding.

Why AML Compliance Matters for Dubai & Sharjah Businesses

Dubai and Sharjah host a dense concentration of the exact sectors the UAE's AML law targets: real estate brokerages, jewelry and gold trading, and corporate service providers supporting free zone and mainland company formation. That concentration means Dubai Economy, SEDD, and the Ministry of Economy inspection teams are actively working through these sectors—not occasionally, but as a routine part of license renewal and spot audits.

There are three levels of sanctions for non-compliance with AML/ATF guidelines: financial penalties; suspension or failure to renew the business license; and criminal proceedings and imprisonment in case of very serious or repeated breaches. In addition, there is an indirect consequence as well, in that banks refuse to open accounts for businesses which do not have their AML program functioning properly.

The ModSolutions 4-Pillar AML Readiness Framework

Rather than treating AML as a one-time form to file, ModSolutions builds your programme around four pillars that mirror how regulators actually assess compliance:

  1. Assess—Enterprise-wide risk assessment covering your customer base, geography, products/services, and delivery channels, benchmarked against Ministry of Economy and FIU guidance.
  2. Appoint—Selection and formal appointment of a qualified MLRO (Money Laundering Reporting Officer), with the appointment documented and reflected in your goAML record.
  3. Register—Registration on goAML, the Ministry of Economy's supervisory self-assessment platform, and, where applicable, sanctions-screening system enrolment.
  4. Report—Ongoing customer due diligence, transaction monitoring, suspicious transaction reporting (STR/SAR), staff training, and scheduled program reviews.

Each pillar produces a concrete deliverable—a signed risk assessment, an MLRO appointment letter, a goAML registration confirmation, or a reporting log—so you have evidence of compliance, not just a policy binder.

Your AML Compliance Roadmap: Day 1 to Ongoing Audits

Stage

Timeframe

What Happens

Day 1–3

Initial assessment

Confirm DNFBP status against your trade license activities; scope the engagement

Day 4–10

Risk assessment

Conduct enterprise-wide ML/TF risk assessment; identify high-risk clients, geographies, and services

Day 11–15

Policy drafting

Draft AML/CFT policy manual, CDD procedures, and record-keeping protocols aligned to Federal Decree-Law No. 10 of 2025

Day 16–18

MLRO appointment

Identify and formally appoint a senior, UAE-resident MLRO with direct board access; document the appointment

Day 19–25

UBO & goAML registration

Confirm/update Ultimate Beneficial Owner (UBO) register; complete two-stage goAML registration with the Ministry of Economy

Day 26–30

Staff training

Train front-line and sales staff on red flags, CDD, and the tipping-off prohibition

Month 2 onward

Live operation

Apply CDD to new and existing clients, screen against sanctions lists, and file STRs as suspicion arises

Ongoing

Quarterly-Annual

Re-screen client portfolio, refresh the risk assessment at least annually, review and update policies, submit UBO updates within 15 days of any change

Timelines vary by business size and how far behind an existing program already is, but this sequence—assess, then appoint, then register, then report—is the order regulators expect to see, and skipping steps is one of the fastest ways to fail an inspection.

Who's Involved: Board, MLRO, and Front-Line Staff

  • Board and senior management are ultimately accountable for the AML/CFT programme's adequacy, even if they delegate day-to-day operation to the MLRO.
  • The MLRO (compliance officer) must be senior enough to have direct board access, UAE-resident, and empowered to file STRs independently—for smaller firms, this is often the owner or a partner rather than a junior hire. If your MLRO leaves the business, a replacement must be appointed in writing and your goAML record updated promptly; an inspector finding a former employee still listed as MLRO will treat the entire framework as defective.
  • Front-line and sales staff are your first line of detection—they need practical training on red flags (unusual cash structuring, reluctance to provide ID, third-party payments) and a clear understanding that "tipping off" a client about a report is itself a criminal offense.

DIY AML Compliance vs. Hiring a Consultant

Factor

DIY In-House

Hiring a Consultant (ModSolutions)

Regulatory accuracy

Risk of relying on outdated guidance (many templates online still cite the repealed 2018 law)

Programme built and updated against current Federal Decree-Law No. 10 of 2025

Time to compliance

Weeks to months, often longer, while staff learn the requirements alongside their existing role

Typically 4–6 weeks for a full programme, run in parallel with your operations

MLRO expertise

You must train or hire an MLRO from scratch

Guided MLRO selection, appointment documentation, and ongoing advisory support

Cost

Lower upfront cost, but higher exposure to fines if gaps are missed

Predictable engagement fee, offset against the cost of a single administrative penalty

Inspection readiness

Depends entirely on internal knowledge of what inspectors check

Documentation built to withstand a Ministry of Economy or Dubai Economy/ SEDD inspection

Ongoing maintenance

Easy to let risk assessments and training lapse once the initial push is over

Structured annual review cycle built into the engagement

DIY is workable for very small, low-risk operations with real internal AML knowledge. For most DNFBPs in Dubai and Sharjah, the risk of an outdated policy or a missed goAML update outweighs the cost of getting it built the first time correctly.

AML/CFT Penalties in the UAE (2026)

Administrative fines under Federal Decree-Law No. 10 of 2025 are set out primarily under Article 17, with a separate, harsher penalty track under Article 20/32 for operating without registration at all.

Violation

Penalty Range

General administrative violations (per Article 17)

AED 10,000 – AED 5,000,000 per violation

Operating a DNFBP activity without a license/registration (Article 20 & 32)

AED 200,000 – AED 10,000,000, and possible imprisonment

No goAML registration

Fines starting from approximately AED 50,000

Failure to maintain/implement AML policy

Fines commonly cited around AED 200,000

Failure to file a required STR

Fines commonly cited at AED 500,000 and above, plus possible criminal liability

UBO register non-compliance or late update

From AED 15,000 per violation

Serious/repeated violations by legal persons

Can escalate substantially higher, alongside license suspension or revocation

Penalty figures reflect publicly available regulatory guidance current as of August 2026. Actual fines are determined case-by-case by the competent supervisory authority—treat this table as a planning reference, not a guarantee of any specific amount.

goAML Registration: What It Actually Involves

goAML is the FIU's reporting platform, accessed via the Ministry of Economy for DNFBP enrollment. Registration is a two-stage process—organization registration followed by individual user (MLRO) registration—and it is a standing legal requirement, not something you only need once you have a suspicious transaction to report.

Two systems are commonly confused:

  • goAML — the operational platform for filing STRs and SARs.
  • The Ministry of Economy's self-assessment platform — a separate supervisory system used for risk-assessment data submissions and DNFBP compliance monitoring.

Both are mandatory where applicable, and treating them as interchangeable is a common source of compliance gaps ModSolutions sees during onboarding.

Expert Insight — ModSolutions Compliance Team

"The businesses that get caught out aren't usually the ones ignoring AML altogether — they're the ones with a policy document from three years ago that still cites the 2018 law, an MLRO who left the company eight months ago, or a goAML account nobody has logged into since registration. Compliance isn't a document; it's a live process. Our job is to make sure your risk assessment, your MLRO, and your reporting habits are all still accurate on the day an inspector actually walks in."

ModSolutions Compliance Advisory Team

What's Included in a ModSolutions AML/CFT Engagement

  • DNFBP status confirmation against your trade license
  • Enterprise-wide ML/TF risk assessment
  • AML/CFT policy manual drafted against current UAE legislation
  • MLRO identification, appointment support, and documentation
  • UBO register review and goAML registration (organisation + MLRO)
  • CDD and sanctions-screening process setup
  • Staff training session for front-line and sales teams
  • Ongoing annual review and audit-support retainer options

We don't publish client counts or "success rate" claims—our methodology is the 4-pillar framework above, and we're happy to walk you through exactly what each deliverable looks like before you commit to an engagement.

Frequently Asked Questions

Do I need AML compliance if I'm a small real estate brokerage in Sharjah? 

Yes, if you conclude sales or purchase transactions on behalf of clients, you fall under the DNFBP definition regardless of company size. Pure leasing/letting-only agencies are generally outside scope, but your supervisory authority can still bring specific activities into scope.

How often do I need to renew or update my AML registration? 

There is no single "renewal" date—instead, your risk assessment should be refreshed at least annually, your UBO register updated within 15 days of any ownership change, and your goAML MLRO details kept current at all times, including immediately after any change of compliance officer.

What happens if I don't appoint an MLRO? 

Operating without a properly appointed and documented MLRO is treated as a core compliance failure. It can trigger administrative fines and, combined with a lack of goAML registration, exposes you to the higher penalty band for unlicensed DNFBP activity under Article 20/32.

Is AML compliance only for banks and financial institutions? 

No. While CBUAE supervises financial institutions, the Ministry of Economy supervises a wide range of DNFBPs — real estate, legal, accounting, corporate services, and precious metals dealers — all of which carry the same core obligations: risk assessment, MLRO appointment, CDD, and reporting.

How long does it take to set up a full AML/CFT compliance program? 

A complete program—risk assessment through goAML registration and initial staff training—typically takes 4 to 6 weeks when run as a structured engagement, though this varies with business size and how much existing documentation (if any) needs to be corrected.

What's the difference between goAML and UBO registration? 

goAML is the platform for filing suspicious transaction/activity reports with the FIU. UBO (Ultimate Beneficial Owner) registration is a separate requirement to identify and file details of anyone who owns 25% or more of your company with the relevant registrar. Most businesses need both.

Can I be fined even if I've never had a suspicious transaction to report? 

Yes. Registration and having a functioning program are standing obligations—the absence of a report doesn't excuse the absence of a risk assessment, an MLRO, or a goAML registration.

What records do I need to keep, and for how long? 

UAE guidance generally requires customer due diligence records, transaction records, and STR-related documentation to be retained for a minimum of five years

Related Articles

Related articles will be displayed here

Get a call within 55 seconds

Click here to get started

Stay Updated

Learn about the latest trends and updates from ModSolutions.

By clicking Subscribe, you agree to our Terms & Conditions and Privacy Policy.