AML/CFT UAE 2026: Compliance, Requirements & goAML Guide
Anti-Money Laundering and Combating the Financing of Terrorism (AML/CFT) compliance is a major responsibility for businesses operating in the UAE. In 2026, companies are working under an updated federal legal framework, with Federal Decree by Law No. (10) of 2025 and Cabinet Resolution No. (134) of 2025 forming the current foundation of the UAE’s AML/CFT regime. The executive regulations came into force on 14 December 2025 and replaced the previous Cabinet Resolution No. (10) of 2019.
For businesses, AML/CFT compliance is not simply about registering on goAML. It involves understanding the risks associated with customers and transactions, conducting appropriate due diligence, identifying beneficial owners, maintaining records, monitoring business relationships, and reporting suspicious activity when required.
This guide explains the key AML/CFT requirements in the UAE for 2026, who needs to comply, how goAML works, and what businesses should have in place to remain prepared for regulatory inspections.
What Is AML/CFT in the UAE?
AML/CFT refers to the measures businesses and financial institutions take to prevent money laundering, terrorist financing, and related financial crimes.
The UAE has developed a risk-based AML/CFT framework that covers financial institutions, Designated Non-Financial Businesses and Professions (DNFBPs), Virtual Asset Service Providers (VASPs), and other relevant entities.
The UAE’s current framework also incorporates measures addressing proliferation financing, reflecting the broader AML/CFT/CPF approach.
The objective is to prevent criminals from using legitimate businesses and financial systems to move, conceal, or use proceeds connected to criminal activity.
What Changed for AML/CFT Compliance in 2026?
One of the most important developments businesses need to understand is that the UAE’s previous AML/CFT framework has been replaced by the newer legislation introduced in 2025.
Federal Decree by Law No. (10) of 2025 establishes the current federal framework, while Cabinet Resolution No. (134) of 2025 provides its executive regulations. Cabinet Resolution No. (134) became effective on 14 December 2025, and it expressly repealed Cabinet Resolution No. (10) of 2019.
This means businesses should not rely on old AML policies simply because they were previously compliant. Internal policies, risk assessments, customer due diligence procedures, and reporting processes should be reviewed against the current requirements.
Who Needs to Comply With AML/CFT Requirements in the UAE?
AML/CFT obligations apply to different categories of businesses and regulated entities.
These include:
- Financial Institutions
- Designated Non-Financial Businesses and Professions (DNFBPs)
- Virtual Asset Service Providers
- Other entities covered by the applicable AML/CFT legislation
DNFBPs include businesses and professions that can face money laundering risks through their services and customer relationships.
Depending on the activity and applicable regulations, this can include sectors such as:
- Real estate
- Auditing and accounting
- Corporate and business services
- Dealers in precious metals and stones
- Legal and professional services
Businesses should determine their regulatory classification and applicable supervisory authority before deciding what compliance measures are required.
What Are the Main AML/CFT Requirements?
A compliant AML/CFT framework should be based on the risks faced by the business rather than relying on a generic checklist.
Some of the most important areas include the following.
1. Business-Wide Risk Assessment
Businesses should identify and assess their exposure to money laundering, terrorist financing, and proliferation financing risks.
The assessment should consider factors such as:
- Customer types
- Geographic exposure
- Products and services
- Delivery channels
- Transaction patterns
- Ownership structures
A risk assessment should be meaningful and connected to the actual activities of the business.
2. Customer Due Diligence
Customer Due Diligence (CDD) is one of the central components of AML compliance.
Under the current executive regulations, Financial Institutions, DNFBPs, and VASPs must verify the identity of customers and beneficial owners before or during the establishment of a business relationship or, where applicable, before conducting an occasional transaction.
CDD generally involves:
- Identifying the customer
- Verifying customer information
- Understanding the purpose and intended nature of the relationship
- Understanding the customer’s business
- Identifying beneficial owners
- Assessing customer risk
The level of due diligence should reflect the level of risk.
3. Beneficial Ownership Identification
Businesses need to understand who ultimately owns or controls their customers, particularly when dealing with legal entities.
Beneficial ownership checks are important because complex corporate structures can sometimes be used to conceal the individuals who ultimately control or benefit from assets or transactions.
Businesses should maintain accurate and appropriately verified beneficial ownership information and update it when relevant changes occur. The current executive regulations specifically address the identification and verification of beneficial owners.
4. Ongoing Customer Monitoring
AML compliance does not end once a customer has completed onboarding.
The current UAE executive regulations require ongoing monitoring of business relationships. This includes reviewing transactions to determine whether they are consistent with information held about the customer, the nature of the customer’s activities, and the risks associated with the relationship.
Businesses should also ensure that customer information and CDD records remain relevant and up to date, with particular attention to high-risk customers.
5. Enhanced Due Diligence for Higher-Risk Customers
Not every customer presents the same level of risk.
Where a customer or relationship presents higher risks, businesses may need to apply Enhanced Due Diligence (EDD).
This can involve obtaining additional information about:
- Source of funds
- Source of wealth
- Business activities
- Ownership structures
- Expected transaction activity
The purpose is to understand the relationship more deeply and apply controls proportionate to the identified risk.
6. Politically Exposed Person (PEP) Screening
Businesses should have processes for identifying customers and beneficial owners who may qualify as Politically Exposed Persons (PEPs).
The current executive regulations include specific requirements for PEPs. For example, appropriate risk-management systems must be used to determine whether customers or beneficial owners are PEPs, and additional approval requirements apply to relationships involving foreign PEPs.
PEP status does not automatically mean that a customer is involved in financial crime. It means the relationship may require enhanced risk management and monitoring.
7. Targeted Financial Sanctions Compliance
AML/CFT compliance also involves measures related to Targeted Financial Sanctions (TFS).
Businesses should have appropriate controls to identify potential matches and prevent prohibited dealings where required.
The current executive regulations require enhanced internal controls for detecting and preventing violations or circumvention of relevant TFS instructions, together with ongoing enhanced scrutiny and documented records of measures taken.
8. AML/CFT Policies and Internal Controls
Businesses should maintain written AML/CFT policies and procedures that reflect their actual operations.
A practical compliance framework should clearly explain:
- Who is responsible for AML compliance
- How customers are classified by risk
- How CDD is performed
- How transactions are monitored
- How suspicious activity is escalated
- How reports are submitted
- How records are maintained
- How employees receive AML training
A policy document alone is not enough. Businesses need to demonstrate that their procedures are actually implemented.
9. Compliance Officer Responsibilities
An effective AML framework needs clear accountability.
The current executive regulations require relevant Financial Institutions, DNFBPs, and VASPs to appoint a compliance officer at management level with appropriate competence and experience and independence in decision-making. The regulations also set out responsibilities including transaction monitoring, reviewing suspicious transaction information, assessing internal AML/CFT systems, and reporting to senior management.
For smaller businesses, the exact compliance structure should reflect the nature, size, and complexity of the business while still meeting applicable legal requirements.
10. AML Training for Employees
Employees should understand how AML/CFT requirements apply to their daily responsibilities.
Training may cover:
- KYC procedures
- Customer risk assessment
- CDD and EDD
- Beneficial ownership
- PEP identification
- Suspicious transaction indicators
- Internal escalation procedures
- goAML reporting responsibilities
Training should be appropriate to employees’ roles rather than simply being a generic annual presentation.
11. Record Keeping
Good documentation is essential for demonstrating compliance.
Businesses should maintain appropriate records relating to:
- Customer identification
- Beneficial ownership
- Risk assessments
- CDD and EDD
- Transaction monitoring
- Suspicious activity reviews
- AML training
- Internal compliance reviews
The current framework also emphasizes maintaining documented records of measures taken in areas such as targeted financial sanctions compliance.
What Is goAML in the UAE?
goAML is the electronic reporting system used by the UAE Financial Intelligence Unit (FIU) to receive and process suspicious reports.
The UAE government describes goAML as an integrated platform used by the FIU to receive, analyse, and distribute suspicious transaction reports. DNFBPs and other relevant reporting entities are required to register so they can submit suspicious reports through the system.
The UAEFIU’s current goAML registration guide states that accountable and reporting entities in the UAE are required to register on goAML in order to submit suspicious reports.
What Reports Can Be Submitted Through goAML?
The goAML system supports reporting to the UAE FIU, including:
- Suspicious Transaction Reports (STRs)
- Suspicious Activity Reports (SARs)
- Additional Information Files (AIFs)
- Requests for Information (RFIs), where applicable
The UAEFIU’s registration guide identifies STR, SAR, AIF, and RFI as report types within the goAML framework.
How Does goAML Registration Work?
The registration process begins through the UAEFIU’s Services Access Control Manager (SACM).
The current registration portal asks for information including:
- Reporting entity name
- Supervisory body
- Registration or identification number
- User details
- Nationality
- Identification information
- Email address
- Mobile number
- Supporting attachment where required
The UAEFIU provides the registration service through its official portal.
After registration and access are established, authorized users can access the goAML application for applicable reporting activities.
Is goAML Registration the Same as AML Compliance?
No.
This is one of the most important points for UAE businesses to understand.
goAML registration is only one part of an AML/CFT compliance framework.
A business can be registered on goAML and still have serious compliance weaknesses if it does not properly:
- Conduct customer due diligence
- Assess customer risks
- Identify beneficial owners
- Monitor relationships
- Maintain records
- Train employees
- Identify suspicious activity
- Follow applicable reporting requirements
The UAE government specifically describes goAML as a reporting platform, while the wider AML/CFT framework imposes broader compliance obligations on regulated and accountable entities.
What Should Businesses Do Before an AML Inspection?
Being registered on goAML does not mean a business is automatically inspection-ready.
Businesses should periodically review:
Customer Files
Check whether customer identification, beneficial ownership information, and risk classifications are complete and current.
AML Risk Assessment
Make sure the risk assessment reflects the actual business model and current risk exposure.
AML Policies
Review policies and procedures against the current UAE legal framework.
Transaction Monitoring
Check whether unusual transactions are identified, investigated, and appropriately escalated.
Employee Training
Maintain evidence of AML training and ensure employees understand their responsibilities.
Reporting Procedures
Make sure the business has a documented process for reviewing and reporting suspicious activity.
Compliance Records
Keep supporting documentation organized and accessible.
Common AML/CFT Mistakes Businesses Should Avoid
Many compliance problems come from relatively basic weaknesses.
Common examples include:
- Treating AML as a one-time registration exercise
- Using generic AML policies that do not reflect the business
- Failing to update customer information
- Not identifying beneficial owners correctly
- Weak customer risk assessments
- Insufficient transaction monitoring
- Poor documentation
- Inadequate employee training
- Ignoring sanctions screening
- Delaying escalation of suspicious activity
A strong AML program should operate continuously rather than only when a regulator announces an inspection.
How to Strengthen Your AML/CFT Framework in 2026
Businesses can take a practical approach by following these steps:
1. Review your regulatory classification. Confirm whether your business is a Financial Institution, DNFBP, VASP, or another relevant entity.
2. Update your AML/CFT policies. Make sure they reflect the current legislation and your actual business activities.
3. Reassess your risks. Review customer, geographic, product, service, and transaction risks.
4. Strengthen CDD and beneficial ownership checks. Make sure customer information is verified and kept current.
5. Improve ongoing monitoring. Look for transactions and behaviors that do not match the customer’s expected profile.
6. Review your goAML access and reporting process. Ensure authorized users can access the system and understand the reporting workflow.
7. Train employees. Make AML awareness part of normal business operations.
8. Test your controls. Internal reviews can identify weaknesses before they become regulatory problems.
AML/CFT Compliance Checklist for UAE Businesses
Before considering your AML framework ready, review whether you have:
- [ ] Identified your applicable AML/CFT obligations
- [ ] Completed a business risk assessment
- [ ] Established AML/CFT policies and procedures
- [ ] Implemented KYC and CDD procedures
- [ ] Identified and verified beneficial owners
- [ ] Established customer risk-rating procedures
- [ ] Implemented enhanced due diligence where appropriate
- [ ] Established PEP screening procedures
- [ ] Implemented sanctions and TFS controls
- [ ] Established ongoing customer monitoring
- [ ] Maintained appropriate compliance records
- [ ] Provided AML/CFT training to relevant employees
- [ ] Appointed the appropriate compliance function or officer
- [ ] Registered on goAML where required
- [ ] Established a process for reviewing suspicious activity
- [ ] Maintained evidence of compliance activities
Final Thoughts
AML/CFT compliance in the UAE has become more structured and risk-focused, and 2026 is an important year for businesses to review their existing compliance arrangements. The introduction of Federal Decree by Law No. (10) of 2025 and Cabinet Resolution No. (134) of 2025 means businesses should ensure that their AML/CFT policies and controls reflect the current legal framework.
For businesses required to use goAML, registration is an essential step, but it should not be treated as the entire compliance program. Effective AML/CFT compliance requires a combination of risk assessment, customer due diligence, beneficial ownership verification, ongoing monitoring, sanctions controls, employee training, record keeping, and appropriate suspicious activity reporting.
The most effective approach is to treat AML/CFT as an ongoing business responsibility rather than a one-time regulatory requirement.
Frequently Asked Questions About AML/CFT UAE
What is AML/CFT compliance in the UAE?
AML/CFT compliance refers to the systems, policies, procedures, and controls businesses use to prevent and detect money laundering, terrorist financing, and related financial crimes.
What is the main AML law in the UAE in 2026?
The current federal framework is based on Federal Decree by Law No. (10) of 2025 concerning Anti-Money Laundering, Combating the Financing of Terrorism and Proliferation Financing, together with its executive regulations under Cabinet Resolution No. (134) of 2025.
Is Cabinet Resolution No. 10 of 2019 still applicable?
No. Cabinet Resolution No. (134) of 2025 repealed Cabinet Resolution No. (10) of 2019 and replaced its executive framework.
Who needs to register on goAML?
Accountable and reporting entities subject to the UAE AML/CFT framework are required to register on goAML for applicable suspicious reporting. The UAEFIU’s current registration guide states that reporting entities are required to register to submit suspicious reports.
Is goAML registration enough to meet AML requirements?
No, goAML is a reporting platform. Businesses must also implement the broader AML/CFT controls applicable to their activities, including CDD, risk assessment, beneficial ownership identification, ongoing monitoring, record-keeping, and reporting procedures.
What is Customer Due Diligence (CDD)?
CDD involves identifying and verifying customers and beneficial owners, understanding the purpose and nature of a business relationship, and assessing the associated risks. The current UAE executive regulations set out CDD requirements for financial institutions, DNFBPs, and VASPs.
What is the role of a compliance officer?
A compliance officer is responsible for important AML/CFT functions such as monitoring relevant transactions, reviewing suspicious transaction information, assessing internal AML/CFT controls, and reporting to senior management as required under the applicable framework.
What should a UAE business do if it identifies suspicious activity?
The business should follow its internal escalation and investigation procedures and, where the applicable legal requirements are met, submit the appropriate suspicious report through goAML to the UAE Financial Intelligence Unit.
Should AML policies be updated in 2026?
Yes. Businesses should review their AML/CFT framework against the current legislation and applicable supervisory guidance, particularly following the replacement of the previous 2019 executive regulation with the 2025 framework.
Note: AML/CFT requirements can vary according to the business’s regulatory classification, activities, supervisory authority, and risk profile. Businesses should refer to the current UAE legislation and applicable regulator guidance when determining their specific obligations. The official UAE legislation platform notes that the Arabic text prevails where there is a conflict with the English translation.