AML and KYC in the UAE: requirements for international companies

AML and KYC in the UAE: requirements for international companies
A Practical Guide for International Business
Mainstream
Compliance with AML (anti-money laundering) and KYC (customer identification) requirements in the United Arab Emirates is not a one-time registration formality. It is a strategic regulatory risk management system.
The main question is not whether the company is registered with go AML or whether copies of passports have been collected. The main question is whether the company can prove in practice that it is not used for money laundering, terrorist financing or evading sanctions.
Effective compliance begins with three checks:
- Does the company understand its regulatory status under UAE law?
- How deep and documented is its internal control system.
- How transparent is the ownership structure, customer base and financial flows.
If these three issues are not resolved in advance, the company may face not just a fine, but also account locks, personal detention of management, loss of license and reputational damage that will close access to the market.
When an international company needs to comply with AML and KYC requirements
The obligation to comply with the UAE anti-money laundering legislation arises if:
- the company is registered in the mainland of the UAE or in the free zone;
- The company conducts business that is regulated by the UAE Central Bank, the Securities and Commodities Authority (SCA), the Dubai Financial Services Authority (DFSA) or the Abu Dhabi Financial Services Regulatory Authority (FSRA);
- The company is classified as a certain non-financial enterprise and profession (DNFBP) – for example, corporate administration service providers, real estate agents, dealers of precious metals, lawyers, accountants;
- The company opens a bank account in the UAE or conducts significant transactions through Emirati banks.
- The company acts as a trade intermediary, logistics hub or re-invoicing center with the participation of high-risk jurisdictions;
- a direct request from a correspondent bank, regulator or local partner for AML documents;
- M&A transaction, investment attraction or entry into the UAE stock market is planned;
- The company interacts with government agencies or participates in tenders in the UAE.
The question is not whether to comply with AML/KYC. The question is how quickly and systematically you do it.
The mistake most international companies make
Many companies start with the question:
What forms do you fill out for the bank?
That's the wrong first question.
The right question is:
Does our overall business model and structure fit the risk profile we are showing to regulators and banks?
The bank or regulator looks not only at the completed questionnaires, but at the set of factors: Beneficial structure, geography of payments, frequency and volume of transactions, category of counterparties, country of origin of capital, public profile of founders. If a formal KYC package looks flawless but real flows signal risk, a lock or denial of service will follow without explanation.
AML compliance in the UAE requires not just documentation, but a well-calibrated regulatory risk management strategy.
Step 1. Determine the applicable law and its regulatory status
The first thing to look at is not the list of documents from the bank, but the legislative landscape that defines your responsibilities.
Key regulations of the UAE:
- Federal Decree-Law No. 20 of 2018 on Countering Money Laundering and Combating the Financing of Terrorism and Illegal Organizations (as amended);
- Resolution of the Cabinet of Ministers No. 10 of 2019 on the procedure for applying the law;
- Cabinet Resolution No. 58 of 2020 on Beneficial Ownership Requirements
- Decisions and circulars of the UAE Central Bank, including the AML/CFT Guidelines for Financial Institutions and the DNFBP;
- Rules of Supervisory Authorities of Free Financial Zones (DFSA, FSRA)
- FATF International Standards and UN Sanctions Regimes, Mandatory for Local Implementation.
Misdefining regulatory status can lead to either excessive costs or, worse, to the omission of critical requirements.
Step 2. Assessing business risks
The Business Risk Assessment is the foundation. Without it, it is impossible to build a secure AML system.
We need to analyze:
- geography of customers, contractors and beneficiaries;
- supply and payment channels;
- products and services (increased risk – private banking, complex corporate structures, real estate transactions for cash);
- Type of clients (PEPs, persons from high-risk jurisdictions, companies with nominee shareholders);
- communication channels (personal presence, remote identification);
- The volume and frequency of transactions, the presence of unusually large or fractional payments.
Risk should not be assessed in general, but in relation to a particular company. Two seemingly identical businesses may have fundamentally different risk profiles due to ownership structure and geography of operations.
Step 3. Develop and implement AML/KYC policies and procedures
Based on risk assessment, internal documents are created:
- AML/CFT policy (approved by senior management)
- Customer identification and verification (CDD) procedure;
- Enhanced Verification Procedure (EDD)
- Procedure for detection and reporting of suspicious transactions (STR/SAR);
- the procedure of verification of sanctions lists;
- the procedure for storing records;
- the procedure for informing the management and interaction with the Financial Intelligence Unit of the UAE (FIU);
- Beneficial Ownership Policy (UBO)
All documents should not be templates, but reflect the real business model and operational processes of the company.
Step 4. Identify and verify the customer and beneficial owner
KYC in the UAE requires the identification of not only the direct customer, but also the ultimate beneficial owner – an individual who owns or controls at least 25% of the client company or otherwise exercises control.
Mandatory elements of CDD:
- the full name and legal form of the client;
- registration documents;
- the address, nature and purpose of the business relationship;
- ownership and management structure;
- data of the identity document of the beneficiaries and persons authorized to act on behalf of the client;
- Source of funds and source of wealth (for high-risk customers).
If the ultimate beneficiary cannot be identified, the client’s senior management personnel should be considered as UBO. Lack of transparency is not a reason to miss identification.
Step 5. Check customers and counterparties on sanctions and compliance lists
The Company is obliged to screen clients, beneficiaries, contractors and beneficiaries:
- on the sanctions lists of the UN Security Council;
- The local list of terrorists of the UAE (Local Terrorist List);
- according to the lists recognized by the UAE regulator;
- Adverse media (PEP lists) are used.
Screening should be done prior to establishing a business relationship, when updating data and at each transaction, depending on the level of automation. Identifying a match requires an immediate escalation procedure and, if necessary, blocking the operation and notifying the FIU.
Step 6. Monitor transactions and report suspicious activity
The most sensitive block for the regulator is the inability to identify and report suspicious transactions in time.
The company is obliged to:
- Continuous monitoring of business relationships and individual transactions;
- - to record indicators of suspicious activity (unusually large amounts, splitting payments, discrepancy to the client profile, communication with high-risk jurisdictions, complex unexplained money chains);
- Immediately report a suspicious transaction (STR) through the go AML platform to the UAE Financial Intelligence Unit (FIU).
Important: In the UAE, it is forbidden to inform the client about the fact of filing an STR (“tipping off”). Violation of this prohibition entails serious responsibility.
Step 7. Appoint an AML Responsible (MLRO) and provide training to staff
Every company that is subject to AML legislation is required to appoint a Compliance Officer/MLRO (Money Laundering Reporting Officer).
MLRO requirements:
- sufficient level of qualification and experience;
- direct access to senior management and the board of directors;
- independence from business units;
- Availability of resources to perform functions.
In addition, the company is required to provide regular, documented training to AML/KYC employees, tailored to their functions and level of risk. Training once a year is the minimum.
Step 8. Provide independent audit of the AML program
The UAE law requires regular independent audits of the effectiveness of the AML/CFT system.
The audit should:
- Check whether policies and procedures comply with regulatory requirements
- Test the actual functioning of the control (for example, how fully the beneficiaries are identified, how the allerts are practiced);
- identify gaps and make recommendations for their elimination;
- be conducted by an external qualified auditor or an internal service independent of the function being audited.
The absence of an independent audit or a formal approach to it is considered by the regulator as an aggravating factor.
Step 9. Be prepared for inspections and requests from the regulator
The UAE Central Bank and other supervisory authorities conduct scheduled and unscheduled on-site and remote checks.
The inspectors assess:
- availability and quality of policies and procedures;
- Documentary evidence of CDD/EDDs;
- records on monitoring and investigation of alerts;
- Timeliness and completeness of STR submission;
- training and audit protocols;
- Beneficial transparency of the company.
The company must be able to provide the requested documents in a short time. The worst thing about the lack of policies is the existence of policies that are not implemented.
Step 10. Respond to incidents and minimize consequences
When a violation is detected, a regulator request is received or a suspicious transaction is detected, the speed and quality of the reaction is critical.
The response plan should include:
- immediate involvement of MLRO and external legal advisers;
- internal investigation;
- If necessary, proactive disclosure to the regulator.
- Suspension of relationships with a risky client;
- Adjust procedures to prevent recurrence;
- Communication with a partner bank (without tipping off).
Practice shows that: The attempt to hide the problem or delay the response greatly increases regulatory and reputational risks.
Financial Institutions and DNFBP: Key differences in requirements
| Criteria | Financial institutions | Certain Non-Financial Enterprises and Professions (DNFBP) |
|---|---|---|
| Regulator | UAE Central Bank, DFSA, FSRA | Central Bank of the UAE (through specialized supervisory departments) |
| Obligation to register with go AML | Yes. | Yes. |
| Mandatory MLRO | Yes. | Yes. |
| Volume of CDD/EDD | Full, including ongoing monitoring | Depends on the sector: in real estate transactions, corporate services, trading in precious metals |
| Expectations for automation | High (transactional monitoring) | Depends on the scale and risk profile |
| Independent audit | Mandatory. | Mandatory. |
| Penalties for violation | Up to 50 million dirhams and above, revocation of license | Up to 1 million dirhams and above, suspension of activities |
It is particularly important for international holdings and trading houses to correctly identify whether they are DNFBPs and are not regulated as an informal financial intermediary.
How to strengthen your position before problems arise
The best AML strategy is laid at the stage of business registration in the UAE.
Preferably:
- From the outset, ensure a transparent and understandable ownership structure – without nominee shareholders and tangled chains.
- Prepare a full KYC package for beneficiaries with confirmation of the source of wealth;
- Choose the right registration area (mainland or free zone) taking into account the requirements for the disclosure of UBO and the specifics of the licensed activity;
- Before opening a bank account, work out the AML profile: transaction structure, expected counterparties, geography;
- develop and implement compliance policies not for a tick, but as a working mechanism;
- Regular independent audits at least once a year;
- appoint an experienced MLRO with real credentials.
The more transparent and predictable the business is for the regulator and banks, the lower the risk of sudden blocking of operations.
Typical mistakes of international companies in AML / KYC in the UAE
- Many DNFBPs are unaware of their obligation to register with the FIU system and fall into the area of violations from day one.
- Banks and the UAE regulator are extremely sensitive to discrepancies between the declared and the actual ownership structure.
- The regulator checks not the presence of a document, but its application in real business processes.
- According to UAE law, the customer identification must be updated periodically, especially when the risk profile changes.
- Not to report suspicious transactions for fear of losing a customer The liability for not submitting an STR is much more serious than commercial losses.
- The AML standards of free financial zones and onshore zones (DFSA) and FSRA have their own rules, but the general vector is set by federal legislation and FATF standards.
- Without training, staff will not be able to recognize a suspicious transaction in time.
- If a company is licensed in the UAE, its international operations are also subject to the UAE AML requirements, especially if they pass through Emirati banks.
Compliance Manager Checklist of an International Company
Before you declare full AML compliance in the UAE, you need to answer 15 questions:
- Is our activity subject to AML/CFT legislation in the UAE?
- Is the company registered in the go AML system (if required)?
- Is a qualified MLRO assigned with direct access to the manual?
- Is a written business risk assessment based on customers, products and geography?
- Is the AML/CFT policy and related procedures approved?
- Is the customer identified and the beneficial owners verified before the business relationship begins?
- Do we check all contractors and beneficiaries for sanctions lists and unfavorable information?
- Are enhanced measures (EDDs) applied to PEPs, high-risk jurisdictions, and complex structures?
- Is there a constant monitoring of transactions for suspicious activity?
- Is there a documented procedure for submitting STR to the FIU?
- Is the fact of filing STR (no tipping off) completely confidential?
- Is there regular and documented training for staff?
- Has the AML program been independently audited in the past 12 months?
- Do KYC/CDD records and transactions remain for at least five years after the relationship ends?
- Is the company ready to submit a full package of documents for any client to the regulator or bank within 24-48 hours?
What a strong compliance strategy looks like in the UAE
A strong strategy usually includes five levels:
1. Governance (Management)
Transparent ownership structure, senior management involvement, documented compliance assignment, allocated resources for the AML function.
2. Risk Assessment (Risk Assessment)
Individual, updated risk assessment of the company, which forms the basis of all policies and procedures, and does not lie in a dead document.
3. Controls (Control procedures)
Working mechanisms of CDD, EDD, sanction screening, transaction monitoring and STR filing, built into operational processes.
4. Monitoring and Testing (Monitoring and Testing)
Independent audit, selective testing of transactions, analysis of allerts and timely elimination of gaps.
5. Independent Assurance (Independent Quality Assurance)
Regular external or internal independent confirmation that the system is working and meets the expectations of the UAE regulator.
Without tier five, the first four may not stand up to scrutiny by either the bank or the supervisory authority.
FAQ
All financial institutions and DNFBP supervised by the Central Bank of the UAE, as well as companies in the jurisdiction of DFSA and FSRA. Registration is required to report suspicious transactions.
Fines for violations of AML/KYC in the UAE range from tens of thousands to 50 million dirhams and above. In addition, the suspension of the license, the ban on holding positions, personal administrative and criminal liability of managers, as well as blocking of accounts are possible.
Are the requirements applicable to free-zone companies? Companies registered in UAE free zones are also required to comply with federal AML legislation. In addition, financial free zones (DIFCs, ADGMs) have their own detailed rules, often even more stringent.
How often should I update my client’s KYC?The law requires updating the data at a frequency depending on the level of risk. For low-risk clients, usually once every 1-3 years, for high-risk clients, much more often. In addition, KYC is updated in the event of any significant changes in the structure or activities of the client.
Is it necessary to identify the beneficial owner if the client is a public company?If the company is listed on a recognized exchange and discloses information, a simplified approach can be used. However, there is no complete exemption from the identification of beneficiaries: The basis for simplified measures should be documented at least.
In accordance with the legislation of the UAE, the company is obliged to refuse to establish or continue business relations, and in case of suspicion, to consider filing an STR.
The law allows the use of measures taken by a trusted third party, but the ultimate liability remains with the company that relies on this information. The company is obliged to immediately obtain all the necessary data and verify their reliability.
What transactions are considered suspicious?The law does not provide a closed list. Indicators may be: unusually large amounts without an explicit economic purpose, splitting payments, transactions with high-risk jurisdictions without a reasonable commercial justification, complex illogical money chains, evasion of information.
A suspicious transaction report must be filed with the FIU immediately after detection. Procrastination should be a minimal and reasonable internal analysis procedure.
The federal law is unified, but financial regulators (DFSA, FSRA) impose increased requirements comparable to the leading international financial centers. Mainland companies are supervised by the Central Bank and must follow its guidelines.
Related services
Corporate Compliance & Regulatory Advisory AML/KYC Compliance in the UAEInternational Sanctions & Export Controls Corporate Investigations, Regulatory Investigations & Business Integrity Corporate Structuring & Licensing in the UAE (Mainland and Free Zones)Opening Bank Accounts & Financial Regulatory Support in the UAEUBO Disclosure & Ownership Structuring
Related material
How to register a company in the UAE: Selection between mainland and free zone Requirements for disclosure of beneficial owners in the UAESanctions risks when doing business through the UAESanctions check of a foreign counterparty before concluding a contract How to open a bank account in the UAE without refusal Independent AML audit in the UAE: What the regulator checks Personal liability of directors and MLRO for violation of AML How to build compliance for a trading house in Dubai
Conclusion
Compliance with AML and KYC requirements in the United Arab Emirates does not require isolated actions under pressure from the bank, but a holistic strategy for managing regulatory risk.
A strong position is based on the correct definition of regulatory status, transparent ownership structure, real-world identification and monitoring procedures, continuous staff training and independent audit.
A jurisdiction that consistently strengthens oversight of financial flows and brings its standards closer to global best practices does not win the one who fills out the forms faster. The winner is the one who builds a business from day one that can withstand any compliance screening – and remains efficient and competitive.
Have a question about the topic of this article?
Write to us and we will respond within one business day.


