UAE · Regulatory risks

Why the Board of Directors Should Manage Regulatory Risks in the UAE

Erich Rath10 min read

Mainstream

Regulatory risk management in the United Arab Emirates is not a function of the compliance department. This is the responsibility of the Board of Directors.

The regulatory field of the UAE is one of the most dynamic and strict in the region. Mistakes are not limited to reputational losses. They lead to personal, including criminal, liability of directors, business lockdown, asset seizure and immediate suspension of activities.

The question is not whether management knows the risks. The key question is whether the board has real oversight to ensure that these risks are identified, assessed and managed.

Effective management of regulatory risks at the board level begins with three fundamental audits:

  • Does the Board understand what regulatory regime applies to the company – the mainland (on-shore), free zone (free zone) or financial zone (DIFC / ADGM).
  • Does the company have a compliance system that is controlled by the board, and not only on paper?
  • Whether the directors themselves are protected from personal liability for violations that occurred without their knowledge but during their term of office.

If these three issues are not resolved, the board of directors bears risks that can materialize at any time – when checking the regulator, a deal with a new counterparty or changing sanctions lists.

When the Board of Directors must actively manage regulatory risks

Regulatory risk management becomes a critical function of the board if:

  • The company enters the UAE market for the first time or changes its structure of presence (transition from free zone to the mainland or vice versa);
  • The business is subject to Economic Substance Regulations (ESR) or Beneficial Owner Disclosure (UBO) requirements.
  • The Central Bank of the UAE, Securities and Commodities Authority (SCA), Dubai Financial Services Authority (DFSA) or Financial Services Regulatory Authority (FSRA) has initiated an audit or inquiry.
  • activities are related to high-risk sectors: financial services, precious metals trade, logistics, transit supplies through the UAE;
  • The company is involved in international transactions where the UN, OFAC, EU or local terrorist lists apply;
  • There has been a change in legislation that could affect the legal status of a business (for example, the introduction of corporate tax in 2023 and transfer pricing rules);
  • M&A transactions, restructurings or financing are undertaken, where regulatory risks may become an obstacle or a source of liability for directors.

The mistake most boards of directors make

All problems start with the same mistake: The Board of Directors considers regulatory risks as a responsibility of management and compliance services.

This misconception is dangerous for two reasons. First, under UAE law, directors are personally liable for damages caused to a company, shareholders or creditors as a result of unfair conduct, gross negligence or violation of the law (Article 24 of Federal Decree-Law No. 32 of 2021 “On Commercial Companies”). The delegation of risk management does not remove this responsibility.

Second, in the case of a regulatory investigation or allegations of anti-money laundering violations (Federal Decree-Law No. On 20 of 2018 on AML/CFT, with subsequent amendments), the investigative authorities assess the tone from above – whether there was real control by the board. Lack of control is considered as acceptance of violations.

The right approach: The Council does not replace management, but sets standards, approves policy makers, regularly hears reports, and has an independent channel of information on the state of regulatory compliance.

Step 1. Identify the applicable regulatory regime

The first thing the board must do is to clearly state which regulatory jurisdiction the company is under.

The regime in the UAE depends on the place of registration:

  • On-shore (mainland) – federal legislation applies, supervision is carried out by the Central Bank, SCA, the Ministry of Economy and other federal agencies. Here is the widest range of requirements for AML, licensing, corporate governance.
  • Free Zone – each zone has its own regulator (for example, DMCC, JAFZA, DAFZA), its own legislation applies, but the requirements for AML/CFT and international sanctions are fully in force.
  • Financial Zones (DIFC, ADGM) are their own legal systems based on English common law, independent regulators (DFSA, FSRA) with high standards of compliance and supervision.

Mistakes at this stage, such as the simplified free zone approach to business that is actually being pursued on the mainland, can lead to serious claims, including the elimination of the license.

Step 2. Evaluate the personal responsibility of directors

In the UAE, the personal responsibility of a director is not a hypothetical risk, but a legal reality.

The director may be involved:

  • j civil liability for losses of the company, shareholders or third parties due to negligence, breach of duties or excess of authority;
  • criminal liability under AML legislation (fines of up to 5 million dirhams and imprisonment);
  • to liability for violation of the sanctions regime (up to criminal prosecution for financing terrorism);
  • to subsidiary liability in case of bankruptcy of the company, if it is proved that it occurred due to the actions or omissions of the board.

The board should be clear about this. Even if a specific violation was committed by an employee, the director may be held responsible for the lack of a system that could prevent the violation.

Step 3. Implement a compliance system controlled by the Board

The compliance system should not be a formal set of documents. The Council shall ensure that:

  • Appoint an independent Compliance Officer or Money Laundering Reporting Officer (MLRO) with direct access to the board.
  • Regular (at least quarterly) reporting to the Board on regulatory risks, incidents and changes in legislation;
  • Approval and annual review of AML/CFT policies, sanctions compliance, due diligence procedures of counterparties;
  • mandatory independent audit of the compliance program;
  • Recording all of the board’s decisions regarding risk management is a key safeguard in subsequent review.

Step 4. Proactive monitoring of regulatory changes

The regulatory environment of the UAE is changing rapidly. The board should ensure that the company monitors not only the laws that have come into force, but also projects that may affect the business.

Key monitoring areas today:

  • Economic Substance Regulations (ESR) requirements – especially for holding, financial and logistics companies
  • Ultimate Beneficial Owners (UBO) disclosure regime and administrative penalties for non-performance
  • Corporate tax rules (9% from 2023) and transfer pricing documentation
  • Changes in the regulation of virtual assets and fintech;
  • Update the sanctions lists and FATF requirements.

Proactivity means that it is not the management that initiates these changes, but the board itself.

Step 5. Managing Sanctions and International Risks

The UAE is a global trading hub and the council has an obligation to consider the intersection of local regulation with extraterritorial sanctions regimes. Violation of secondary US sanctions or EU restrictions can cut off a company from the banking system even if the UAE’s laws are formally enforced.

The Board must ensure that the company:

  • - applies automatic sanction screening of all counterparties, beneficiaries and supply chains;
  • has a procedure for actions in case of “red flags” – requests for payment through third countries, non-standard logistics, participation of persons from sanction jurisdictions;
  • It does not rely solely on the assurances of a local partner – its own verification is mandatory.

Step 6. Be prepared for regulatory investigations

Even with a perfect compliance system, an investigation can begin. The Board of Directors shall approve in advance a protocol of response, which shall include:

  • immediate notification of legal advisers;
  • Ensuring the safety of documents and electronic data;
  • Identification of a speaker to interact with the regulator;
  • parallel internal review of an incident under the supervision of a board (or audit committee).

The mistake here is to try to resolve the problem with informal contacts without the participation of qualified lawyers. In the UAE, this can be seen as an attempt to obstruct justice.

Distribution of responsibility for regulatory risks: Management vs. Board of Directors

CriteriaManagement (CEO, CFO, CCO)Board of Directors
Approval of compliance policyDevelops and offersAcknowledges and is responsible for their presence
Monitoring of enforcementPerforms operational controlProvides strategic oversight
Accountability to the regulatorResponsible for current reportingResponsible for reliability and completeness
Personal responsibilityApplied for specific violationsApplied for lack of system and supervision
Crisis responseParticipate promptlyMake strategic decisions and control communication

How to strengthen the position of the board of directors before problems arise

Proactive protection does not begin at the moment of crisis, but at the moment of formation of the council. The most effective measures are:

  • Legal audit of the compliance system with the involvement of external consultants specializing in the UAE – at least once a year.
  • Regular training of directors on specifics of responsibility and changes in UAE regulation.
  • Directors and Officers Liability Insurance (D&O) with coverage in the UAE and, preferably, with coverage for legal defence costs in criminal investigations.
  • Documentation of good faith: Detailed protocols for discussing compliance issues, fixing management questions and the answers received.
  • The presence of independent non-executive directors with UAE regulatory experience or DIFC/ADGM on the board.

Typical mistakes of the boards of directors in the UAE

  1. Ignoring the differences between the mainland, free zone and financial zones. Compliance standards in one jurisdiction are not always sufficient in another.
  2. Lack of written AML/CFT policies and sanctions compliance. Management's oral assurances will not protect the director during the investigation.
  3. Blind trust in a local partner or sponsor. Even if there is a local member, the responsibility of the council is not delegated.
  4. Ignoring ESR and UBO requirements. Fines and suspensions are increasingly being applied.
  5. Prolonging the notification of the regulator about violations. In the UAE, voluntary disclosure and cooperation often mitigate the impact.
  6. The hope that connections will solve the problem. In the UAE today, regulators are tough and predictable, especially in terms of financial transparency and sanctions.

Checklist for board member

Before the approval of the annual report or in the run-up to the transaction, you must answer 12 questions:

  1. Do I understand the regulatory regime applicable to our company and do we have a valid license?
  2. Is a qualified MLRO/Compliance Officer appointed with direct access to the board?
  3. Have the AML/CFT, sanctions compliance and due diligence policies been approved and implemented?
  4. Has there been an external audit of the compliance program this year?
  5. Is there a procedure for escalating red flags to council level?
  6. Have the beneficial owners of all key counterparties been verified and have the UBO registry records updated?
  7. Are we in compliance with ESR requirements and are the documentation ready?
  8. Have we received regulatory requests or notifications and how have they been handled?
  9. Is the liability of directors (D&O) insured and does the insurance cover investigations in the UAE?
  10. Have you been trained in regulatory risk management in the past 12 months?
  11. Are the discussions on compliance risks reflected in the board's minutes?
  12. Does the council have an approved plan of action in case of a search, a call to law enforcement or a lockdown of accounts?

What a strong regulatory risk management system looks like

An effective system is built on three levels:

  1. Tone from above and strategic oversight of the council. Policies are approved, risks are regularly reviewed, and the board sets expectations for zero tolerance for perceived violations.
  2. Operational compliance management. A qualified team performs screening, monitoring, staff training and reporting for the regulator. The council does not receive a “no problem report” but a substantive analysis of risks and incidents.
  3. Independent check. Internal audits or external consultants test the system for vulnerabilities. The results are presented directly to the audit committee or board.

Without a third level, the board gets the picture that management wants to show, not the reality.

FAQ

What is the director’s personal responsibility for violating AML legislation in the UAE?

Criminal liability is foreseen, including imprisonment and fines of up to 5 million dirhams. The director may be involved if he has not provided proper supervision, even if he has not performed the operation himself.

Can the Board delegate responsibility for compliance to management?

Operational functions can be delegated. Delegating responsibility is not. By law, it is the board that bears fiduciary duties and ultimate responsibility.

What are the consequences for a company if the board does not manage regulatory risks?

From fines (up to tens of millions of dirhams), suspension or revocation of licenses to criminal prosecution of officials and blocking of transactions by banks.

What if the company is checked by the Central Bank or DFSA?

Get specialized lawyers immediately. Secure the documents. Appoint an interaction coordinator. Not to hide or destroy information is a serious crime. The council must be informed within a few hours.

Is D&O Insurance Required in the UAE?

Not for everyone, but for companies in DIFC and ADGM, it's almost standard. For mainland companies and free zone, having D&O insurance is the best practice to ensure that directors’ personal assets are protected in investigations and lawsuits.

How often should the board review the compliance program?

Minimum, every year. An extraordinary review is necessary when changing legislation, entering new markets or detecting a significant incident.

Related services

  • Corporate Governance and Regulatory Compliance in the UAE
  • AML/CFT and Sanctions Compliance
  • Protection of Directors and Officers: investigation and D&O liability
  • Business structuring in the UAE (mainland, free zone, DIFC, ADGM)
  • Internal investigations and interaction with regulators
  • Audit of compliance systems and ESG risks

Related material

  • AML/CFT Compliance in the UAE: What every director should know
  • Personal responsibility of the UAE Legislation Director
  • How to Choose Between Mainland, Free Zone and DIFC/ADGM in Terms of Regulatory Risks
  • Sanctions risks in the UAE in international trade: practical guide
  • Economic Substance Regulations (ESR) in the UAE: Mistakes that can be avoided

Conclusion

The board of directors working with business in the UAE cannot afford to be a passive observer of regulatory risks. The regulatory field of the Emirates requires direct involvement, strategic oversight and proactive posture.

Management of regulatory risk at the board level is not just about protecting against fines and investigations. This is the key to business sustainability, access to funding, the foundation of the relationship with the regulator and, crucially, the personal protection of each director.

In the UAE, the winners are not the companies that take risks hoping to go unnoticed. The winners are those whose boards build a system where compliance becomes an organic part of the business, rather than a set of documents to be verified. This approach transforms regulatory risks from a threat to a manageable strategic factor.

Have a question about the topic of this article?

Write to us and we will respond within one business day.