
AML Laws UAE: What Every DNFBP Must Know Before Hiring a Consultant
If your business touches real estate, precious metals, legal services, accounting, or corporate structuring in the UAE, you are almost certainly bound by AML Laws UAE—whether or not anyone at your firm has read it. Non-compliance isn't a paperwork risk anymore. It's a licensing risk, a banking risk, and, in serious cases, a personal liability risk for your money laundering reporting officer.
"For a complete breakdown of the 2025 regulatory framework, DNFBP categories, and full penalty structure, see our Complete UAE AML Regulations Guide."
This guide outlines who should register, the process, what it's worth doing wrong, and how ModSolutions constructs AML programs that will withstand a Ministry of Economy inspection.
This article is intended for general informational purposes only and should not be relied upon as legal advice. Talk to a licensed AML advisor about your particular responsibilities.
What Changed: The UAE Replaced Its Entire AML Framework in 2025
The majority of online compliance guides are still for Federal Decree-Law No. 20 of 2018 and Cabinet Decision No. 10 of 2019. That has been replaced by a different structure.
The UAE has now adopted Federal Decree-Law No. 10 of 2025 on Anti-Money Laundering, Combating the Financing of Terrorism and Countering Proliferation Financing and its Executive Regulations, dated 14 October 2025 and 14 November 2025, respectively. This is a replacement, not an amendment, and it is more stringent than the previous.
Practical differences that matter to your business:
- The evidentiary threshold for proving money laundering has been lowered, making prosecutions easier to bring.
- False or incomplete UBO (Ultimate Beneficial Owner) reporting is now a standalone criminalized offense.
- Administrative penalty ceilings for legal persons have increased substantially.
- MLRO accountability is now personal as well as institutional — a compliance officer can face consequences independently of the company.
- Commercial gaming and e-sports operators are now formally recognized as DNFBPs.
- Individual DNFBP category definitions (particularly real estate) have been widened.
If your AML policy was drafted before October 2025, it is very likely already out of date — regardless of how thorough it was at the time.
Who Needs AML Registration in the UAE? (DNFBP Checklist)
Under the new framework, a Designated Non-Financial Business or Profession (DNFBP) carries the same core AML obligations as a bank. You are almost certainly a DNFBP if your business falls into any of these categories:
- Real estate brokers and agents — including anyone concluding transactions or settlements on a client's behalf involving the purchase or sale of property (pure leasing is generally excluded)
- Dealers in precious metals and precious stones (DPMS)—jewelers, bullion dealers, gemstone traders
- Auditors and accountants — including tax consultants providing regulated services
- Lawyers, legal consultants, and notaries public — when preparing or executing transactions for clients involving real estate, company formation, or asset management
- Corporate service providers (CSPs) and trust/company formation agents — including registered agents forming companies or acting as nominee directors/shareholders
- Commercial gaming operators — casinos, online gaming platforms, and e-sports operators (newly designated)
Quick self-check: If you handle client money, structure ownership on someone's behalf, or facilitate high-value asset transfers, assume you're in scope until confirmed otherwise.
The 4-Pillar AML Readiness Framework
ModSolutions' Compliance Team built this framework specifically because most DIY attempts fail at the sequencing, not the individual tasks. Doing these out of order is the single most common inspection failure we see.
| Pillar | What It Covers | Why Order Matters |
| 1. Assess | Institutional Risk Assessment (IRA) covering your customer base, geography, products, and delivery channels | Everything downstream — your policy, your MLRO's workload, your screening rules — is built on this document. Skip it, and your policy won't match your actual risk |
| 2. Appoint | Board or partner resolution appointing a UAE-resident MLRO with genuine seniority and direct access to management | Must happen before goAML registration—the form requires named MLRO details |
| 3. Register | goAML enrolment via the Ministry of Economy, plus sanctions list screening system registration | Cannot be completed without a finalised MLRO appointment on file |
| 4. Report | Ongoing STR/SAR filing, transaction monitoring, annual IRA refresh, and independent audit | This is where "compliance" becomes a living function rather than a folder of PDFs |
Expert Insight — ModSolutions Compliance Team
"The DNFBPs we see get fined rarely fail because they didn't try. They fail because they built a policy first, appointed an MLRO second, and never went back to check whether the policy actually matched their risk profile. An inspector doesn't just want to see a document — they want to see that your MLRO can explain, on the spot, why your screening frequency matches your client base. That's the gap between paper compliance and audit-ready compliance."
Your AML Compliance Roadmap: Day 1 to Ongoing
| Timeframe | Action | Owner |
| Day 1–7 | Confirm DNFBP status and license activity scope | You / Advisor |
| Week 1–2 | Conduct Institutional Risk Assessment | Compliance Advisor |
| Week 2–3 | Draft AML/CFT policy, CDD, and record-retention procedures | Compliance Advisor |
| Week 3 | Board/partner resolution appointing MLRO | You + MLRO |
| Week 3–4 | goAML registration and sanctions screening system enrolment | MLRO |
| Week 4–5 | Staff AML training (role-based) | Compliance Advisor |
| Month 2 onward | Ongoing CDD, transaction monitoring, STR/SAR filing as needed | MLRO |
| Annually | IRA refresh, UBO filing confirmation, policy review, independent audit | MLRO + Advisor |
Most firms working with a dedicated advisor complete Pillars 1–3 within 3 to 5 weeks. Firms attempting this without support commonly take two to three times longer—and often have to redo the Institutional Risk Assessment once they realize the policy doesn't reflect it.
DIY AML Compliance vs. Hiring a Consultant
| Factor | DIY Approach | ModSolutions Advisory |
| Setup time | 8–14 weeks (with rework common) | 3–5 weeks |
| Regulatory currency | High risk of using outdated templates referencing repealed 2018 law | Current under Federal Decree-Law 10/2025 & Cabinet Resolution 134/2025 |
| MLRO training/support | Internal staff learning on the job | MLRO-as-a-service or guided appointment, with ongoing support |
| Inspection readiness | Policy often untested until an actual inspection | Framework built to withstand Ministry of Economy review |
| Ongoing obligations (STR filing, IRA refresh) | Frequently missed once the initial setup is "done" | Tracked and managed as a continuous programme |
| Cost exposure if it goes wrong | A single missed STR or lapsed goAML registration can trigger fines starting at AED 50,000 | Structured to minimise the risk of triggering a violation in the first place |
DIY is not reckless by definition—some smaller, simple-structure businesses manage it. But the businesses that get fined are rarely the ones that never tried. They're the ones whose "finished" policy was never pressure-tested against how they actually operate.
AML Non-Compliance Penalties in the UAE (2026)
Administrative fines are issued per violation, not per inspection — meaning multiple lapses compound quickly.
| Violation | Typical Fine Range (AED) |
| Failure to register on goAML | From 50,000 |
| No UBO register or late UBO filing (beyond 15-day update window) | From 15,000 |
| Failure to implement a written AML/CFT policy | Up to 200,000 |
| Failure to file a required STR/SAR | 500,000+ |
| No MLRO appointed | 50,000 – 1,000,000 |
| Serious or repeated violations (legal persons) | Up to 5,000,000, with the new law's overall ceiling for legal persons raised considerably higher for the most severe cases |
Beyond the fine itself, non-compliance can trigger license suspension, banking relationship termination (UAE banks now de-risk non-compliant DNFBP clients quickly), and referral for criminal investigation in cases involving suspected actual laundering activity.
Why Hire an AML Expert Instead of Going Alone
Three reasons come up in almost every client conversation ModSolutions has:
- The law changed underneath most existing policies. If your framework predates October 2025, it needs a review—not just an update, a review against current DNFBP definitions and reporting rules.
- goAML and the MoE's SACM portal are two different systems. Confusing the operational reporting platform (goAML) with the supervisory self-assessment platform (SACM) is one of the most common — and most avoidable — inspection failures.
- An MLRO's appointment must be defensible, not just filed. Inspectors who find a stale MLRO name on file treat the entire AML framework as compromised, even if every other document is in order.
What's Included in ModSolutions' AML Compliance Service
Transparency matters here, so here's exactly what our engagement covers:
- Institutional Risk Assessment tailored to your sector and client base
- AML/CFT policy drafting aligned to Federal Decree-Law 10/2025 and Cabinet Resolution 134/2025
- MLRO appointment support (guided appointment or MLRO-as-a-service)
- goAML and sanctions screening system registration
- Staff AML/CFT training, role-based
- Ongoing STR/SAR filing support and annual IRA refresh
- Audit-readiness review ahead of Ministry of Economy inspections
Realistic timeline: 3–5 weeks for initial setup, followed by ongoing quarterly-to-annual maintenance depending on your risk profile.
FAQ
Q1: Who needs AML registration in the UAE?
Any Designated Non-Financial Business or Profession—real estate brokers, precious metals/stone dealers, auditors and accountants, lawyers and notaries, corporate service providers, and (newly) commercial gaming operators—must register for AML compliance alongside all licensed financial institutions.
Q2: What is the current UAE AML law?
The UAE operates under Federal Decree-Law No. 10 of 2025 on Anti-Money Laundering, Combating the Financing of Terrorism and Countering Proliferation Financing, with executive regulations under Cabinet Resolution No. 134 of 2025. This replaced the previous Federal Decree-Law No. 20 of 2018 and Cabinet Decision No. 10 of 2019 in late 2025.
Q3: How much are AML fines in the UAE?
Administrative fines are issued per violation and commonly range from AED 15,000 for minor UBO filing lapses up to AED 5,000,000 or more for serious violations like failing to file a required Suspicious Transaction Report, with higher ceilings available for the most severe cases involving legal persons.
Q4: How long does AML compliance setup take?
With a dedicated advisor, most DNFBPs complete risk assessment, policy drafting, MLRO appointment, and goAML registration within 3 to 5 weeks. DIY attempts commonly take significantly longer due to rework.
Q5: What is goAML, and who has to register?
goAML is the UAE Financial Intelligence Unit's mandatory platform for filing Suspicious Transaction Reports, Suspicious Activity Reports, and sector-specific reports such as high-value real estate or precious metals transaction reports. Both financial institutions and all DNFBPs must register via the Ministry of Economy.
Q6: How often does an AML risk assessment need updating?
The institutional risk assessment must be refreshed at least annually or immediately whenever there's a material change in business structure, customer profile, or services offered.
Q7: What does an MLRO need to do?
A money laundering reporting officer must be a sufficiently senior UAE resident with direct access to management, responsible for overseeing the AML program, reviewing suspicious activity, filing STRs/SARs, and—under the 2025 law—carrying personal accountability alongside the firm's institutional liability.
Q8: What happens if I register late?
Late or missing goAML registration alone can trigger fines starting at AED 50,000, and inspectors treat a missing or outdated registration as a red flag that prompts closer scrutiny of the rest of your compliance file.