Key Takeaways
4 insights · 11 min readFederal Decree-Law No. 20 of 2018 is the UAE’s principal AML/CFT law; Cabinet Decision No. 10 of 2019 is its implementing regulation. [VERIFY current amendments]
It applies to every DNFBP — auditors, real estate agents, dealers in precious metals and stones, and corporate service providers — regardless of size.
Article 16 sets 8 minimum obligations: risk assessment, CDD, an approved MLRO, written policies, red-flag indicators, STR reporting via goAML, UN sanctions screening, and 5-year record-keeping.
Breaches are criminal. Tipping off, no-CDD dealings and shell-bank links carry fines up to AED 10,000,000 and imprisonment. [VERIFY figures]
The UAE AML law is Federal Decree-Law No. 20 of 2018 on Anti-Money Laundering and Combating the Financing of Terrorism, implemented through Cabinet Decision No. 10 of 2019. It applies to all DNFBPs and sets out 8 minimum obligations — from customer due diligence and appointing an MLRO to filing Suspicious Transaction Reports on goAML and keeping records for 5 years. It has been amended, most recently in 2024. [VERIFY] AML compliance setup from AED 349.
In this guide
What the law is How it evolved Who it applies to 8 minimum obligations What it prohibits CDD levels Confidentiality & protection Senior management liability PenaltiesWhat is the UAE AML law (Federal Decree-Law No. 20 of 2018)?
The UAE AML law is built on two instruments — Federal Decree-Law No. 20 of 2018 and its implementing Cabinet Decision No. 10 of 2019. The Law sets the criminal framework and the high-level obligations; the Cabinet Decision provides the detailed operational rules your business follows day to day — customer due diligence, risk assessment, compliance-officer qualifications, record-keeping and the powers of supervisory authorities.
Together they define what every regulated business must do to prevent money laundering and the financing of terrorism. Meeting them is not optional and does not scale with size — a sole practitioner faces the same core duties as a large firm. If you need help interpreting the law for your specific activity, our team handles AML compliance obligations under UAE law end to end.
⚠ Current legal status
Federal Decree-Law No. 20 of 2018 has been amended twice — by Federal Decree-Law No. 26 of 2021 and Federal Decree-Law No. 7 of 2024. Cabinet Decision No. 10 of 2019 was amended by Cabinet Resolution No. 24 of 2022. Your AML programme must reflect all current amendments, not the original 2018 text. [VERIFY]
How has UAE AML law evolved?
Requirements have tightened steadily since 2018, in line with FATF standards and the UAE’s National AML/CFT Strategy. Understanding the history explains why inspections have become more rigorous.
| Year | Instrument | What it introduced |
|---|---|---|
| 2018 | Federal Decree-Law No. 20 of 2018 | Foundational AML/CFT law — DNFBP obligations, STR requirements, criminal framework |
| 2019 | Cabinet Decision No. 10 of 2019 | Implementing regulation — CDD, risk assessment, MLRO qualifications, record-keeping, supervisory powers |
| 2021 | Federal Decree-Law No. 26 of 2021 [VERIFY] | First amendment — strengthened enforcement, expanded definitions after FATF feedback |
| 2022 | Cabinet Resolution No. 24 of 2022 [VERIFY] | Updated CDD thresholds, enhanced beneficial-ownership rules, refined supervisory powers |
| 2023 | Cabinet Decision No. 109 of 2023 [VERIFY] | Real Beneficiary registers (partners, shareholders, nominee directors) for mainland & non-financial free zones |
| 2024 | Federal Decree-Law No. 7 of 2024 [VERIFY] | Second amendment — latest tightening, aligned with FATF and the 2024–2027 National Strategy |
Who does UAE AML law apply to?
The law applies to Financial Institutions and to Designated Non-Financial Businesses and Professions (DNFBPs). If your activity falls in a DNFBP category, you must register with your supervisory authority and on the goAML portal and build a full AML programme.
| DNFBP category | Who it covers |
|---|---|
| Auditors & accountants | Independent accounting and audit firms providing professional services |
| Real estate agents & brokers | Firms that buy or sell real property for clients |
| Dealers in precious metals & stones | Gold, diamond and jewellery traders above the cash threshold |
| Corporate service providers | Company formation agents and company formation / registered-agent businesses |
| Lawyers & notaries | Independent legal professionals in specified transactions (e.g. managing client money, forming companies) |
Expert Tip
Being licensed in a free zone does not exempt you. Non-financial free-zone entities in these categories are supervised for AML purposes and are expected to register on goAML and maintain a compliant programme just like mainland businesses.
What are the 8 minimum obligations under UAE AML law?
Article 16 sets 8 non-negotiable obligations for all regulated entities, including every DNFBP. They apply regardless of business size, revenue or headcount.
| # | Obligation | What it requires |
|---|---|---|
| 1 | Identify & assess risks | A documented Business-Wide Risk Assessment across customers, geographies, products and channels — kept updated |
| 2 | Customer Due Diligence | Verify identity, understand the relationship, apply enhanced checks for high-risk clients, monitor ongoing |
| 3 | Appoint an MLRO | A qualified, management-level Compliance Officer, MoE-approved, with full independence and authority |
| 4 | Internal policies & controls | Written AML policies (CDD, monitoring, STRs, screening, records) approved by senior management |
| 5 | Suspicious-transaction indicators | Internal red flags to identify suspicious activity across all business lines |
| 6 | Report suspicious activity | File STRs via goAML on reasonable suspicion and cooperate fully with authorities |
| 7 | Implement UN sanctions | Apply UNSC resolution directives immediately (targeted financial sanctions screening) |
| 8 | Maintain records (5 years) | Keep CDD files, transactions, risk assessments and STRs for at least 5 years; produce on request |
The specific article cross-references in the Law and the AML Decision are detailed and are periodically renumbered by amendment, so [VERIFY] them against the current consolidated text. In practice, meeting all eight comes down to a clear sequence:
- Register — enrol with your supervisory authority and on the goAML portal.
- Appoint your MLRO — a qualified, independent Compliance Officer with board backing.
- Assess your risk — complete and document a Business-Wide Risk Assessment.
- Write & approve policies — CDD, monitoring, sanctions screening and record-keeping, signed off by senior management.
- Operate & report — monitor transactions, file STRs when needed, and retain records for five years.
✅ A compliant DNFBP
- Registered with its supervisor and on goAML
- MLRO appointed, empowered and independent
- Business-Wide Risk Assessment documented and current
- Written AML policies approved by senior management
- STRs filed in good faith; records kept for 5 years
❌ A DNFBP at risk
- Not registered on goAML
- No MLRO, or one with no authority
- Onboarding clients without completing CDD
- Ignoring sanctions screening and freeze orders
- Failing to file STRs — or tipping off clients
Need help implementing these obligations?
Fastlane handles everything — MLRO appointment, goAML registration, Business-Wide Risk Assessment, policies and monthly monitoring.
What does UAE AML law prohibit?
Alongside its positive duties, the law imposes absolute prohibitions — breaching any of them is a criminal offence.
Absolute prohibitions for DNFBPs
• Anonymous or fictitious accounts — no relationship or transaction under an anonymous, fictitious or pseudonymous name or number.
• No dealing without CDD — no business relationship or transaction without completing risk-based CDD, for any reason, no exceptions.
• Shell banks — no dealings with shell banks, including opening accounts or facilitating transactions through them.
• Secrecy as a shield — banking, professional or contractual secrecy cannot be used to refuse statutory reporting.
• Bearer shares — no facilitating the issue of bearer shares or bearer share warrants.
• Tipping off — never inform a client or third party that an STR has been or will be filed, or that an investigation is underway.
⚠ Tipping off is a criminal offence
Even a casual remark to a client that “we had to report something” constitutes tipping off. The penalty is imprisonment of no less than 6 months plus a fine of AED 100,000 to AED 500,000, and it applies to all staff — not just the Compliance Officer. [VERIFY]
How does CDD work — Standard, Enhanced and Simplified?
The law requires a risk-based approach: the level of scrutiny must match the risk of the client and the transaction.
| CDD level | When applied | Key measures |
|---|---|---|
| Standard CDD | Default for all new relationships and transactions | Identity verification, beneficial-owner identification, understanding business purpose, ongoing monitoring |
| Enhanced (EDD) | High-risk — PEPs, high-risk jurisdictions, complex structures, unusual transactions | Extra information on client and beneficial owner, source-of-funds verification, senior-management approval, increased monitoring |
| Simplified (SDD) | Low-risk clients only, where no suspicion exists | Less frequent updates and reduced monitoring — but never where any suspicion of crime exists |
Can secrecy block reporting? Confidentiality and whistleblower protection
No — secrecy cannot override the duty to report, and good-faith reporters are legally protected. The law balances confidentiality against reporting duties in three ways.
Reporting cannot be blocked by secrecy. DNFBPs cannot use banking, professional or contractual secrecy to refuse a statutory report. UAE data-protection rules specifically permit reporting to authorities — you cannot invoke privacy rights to avoid filing an STR.
Internal sharing is permitted. The confidentiality requirement does not prevent sharing suspicious-activity information within the same DNFBP or across affiliated group members — foreign branches, subsidiaries or the parent — to identify, prevent or report financial crime.
Good-faith reporters are protected. Under Article 27 of the AML/CFT Law, DNFBPs and their people are protected from administrative, civil or criminal liability when they report in good faith — even if they did not know the exact underlying crime, and even if no illegal activity ultimately occurred. [VERIFY]
Key Point
Good-faith STR filing gives you legal protection. Not filing when you should gives you criminal exposure. When in doubt — report.
Who is accountable? Senior management and personal liability
Accountability sits at the top of the organisation — not just with the Compliance Officer. Senior management and board members are personally responsible for the programme.
Senior management must:
• Ensure the AML programme is adequately resourced and effective.
• Approve the entity’s AML policy framework and risk appetite.
• Approve business relationships with high-risk customers, including PEPs.
• Review periodic compliance reports from the MLRO.
• Implement directives on sanctions and freeze orders.
• Guarantee the MLRO’s independence — the MLRO cannot be pressured or overruled on STR decisions.
⚠ Personal liability
Penalties apply to the business entity, its managers and individual employees. Being the owner or director does not shield you — it increases your exposure. Where management abuses its position to facilitate financial crime, the law carries aggravated penalties of up to AED 10,000,000 plus imprisonment. [VERIFY]
What are the penalties for violating UAE AML law?
Penalties scale from administrative fines to serious criminal sanctions, depending on the breach.
| Violation | Penalty |
|---|---|
| General AML violations | Fines from AED 10,000 up to AED 10,000,000, depending on the breach [VERIFY] |
| Tipping off | Imprisonment ≥ 6 months + AED 100,000–500,000 [VERIFY] |
| Aggravated (management facilitating crime) | Up to AED 10,000,000 + imprisonment [VERIFY] |
| Using funds for terrorism financing | Up to life imprisonment [VERIFY] |
Administrative fine amounts are set by Cabinet Decision and updated periodically, so treat the figures above as indicative and [VERIFY] them against the current law and schedule of fines. The cheapest way to manage this exposure is a working programme that is kept current — which is exactly what our AML compliance services deliver, from registration through to monthly monitoring. DNFBPs also have parallel corporate tax and accounting duties that should be handled together.
Fastlane Compliance Team
Ministry of Economy-registered audit firm and FTA-registered tax agents supporting DNFBPs across the UAE with goAML registration, MLRO support, risk assessments and monthly AML monitoring. Every guide is reviewed against current regulations before publishing.
Ask the team a question