Anti-Money Laundering (AML) Compliance for UAE Businesses: Navigating the 2025 Legislative Overhaul
Knowledge can now be inferred from the circumstances, and managers can face personal criminal liability
How Federal Decree Law No. 10 of 2025 changes AML compliance in the UAE: proliferation financing, the objective test for knowledge, entity fines, manager liability and virtual assets. It then covers Cabinet Resolution No. 134 of 2025, DNFBP sector duties, governance and training, enforcement scenarios and a phased programme.
Reviewed by Mohamed Noureldin, Founder, Managing Partner & Senior Legal Consultant
Under the UAE's new anti-money laundering law, failing to detect suspicious activity through negligence or inadequate systems is no longer a defence. Liability can arise where a person knew or should have reasonably known that funds were illicit. That change arrived with a legislative overhaul the UAE enacted in late 2025 to align with the standards of the Financial Action Task Force (FATF). It demands immediate attention from all regulated entities, including financial institutions and Designated Non-Financial Businesses and Professions (DNFBPs).
Related: Our AML compliance advisory and real estate law advisory services.
The law in force since 14 October 2025
The cornerstone of the updated AML/CTF framework is Federal Decree Law No. 10 of 2025 Concerning Combating Money Laundering, Terrorism Financing, and the Financing of Proliferation (the "New AML Law"). It came into effect on 14 October 2025. It repeals and replaces the previous Federal Decree Law No. 20 of 2018, and introduces stricter enforcement powers, higher penalties and a broader scope of application.
Sanctions lists and dual-use goods enter the risk assessment
The most significant change is the explicit inclusion of a framework for combating Proliferation Financing (CPF). It brings the UAE's legal structure into full alignment with the latest FATF recommendations. Those recommendations require countries to criminalise and take action against the financing of the proliferation of weapons of mass destruction.
For businesses, compliance programmes must now extend their risk assessments and monitoring systems to identify and mitigate risks associated with CPF. That requires a deeper understanding of international sanctions lists and of the nature of transactions involving dual-use goods or high-risk jurisdictions.
From actual knowledge to what a person should have known
The New AML Law fundamentally alters the burden of proof for establishing money laundering and other principal offences by introducing an objective test. Knowledge that funds were illicit can now be inferred from the factual and objective circumstances. Liability can arise where a person knew or should have reasonably known about the illicit nature of the funds.
The shift is from a subjective test of actual knowledge to an objective test of competence and diligence. It is the most critical change for compliance officers and senior management. It places a much higher onus on businesses to maintain documented and effective internal controls. A failure to detect suspicious activity due to negligence or inadequate systems, such as a failure of due diligence, ignoring clear red flags or inadequate training, is no longer a defence. It is now a potential basis for criminal liability. The new standard requires businesses to demonstrate that their policies are effective, regularly tested and rigorously enforced.
Higher fines for entities and personal liability for managers
- Corporate fines: Penalties for legal entities have been significantly increased. Fines range from AED 5 million to AED 100 million or a sum equivalent to the value of the criminal property, whichever is greater. Courts also have the power to order the dissolution of a legal entity or the closure of its headquarters.
- Manager liability: The New AML Law introduces personal criminal liability for managers of legal entities. Managers can face fines or imprisonment if they have actual knowledge of a principal offence, or if the offence occurred as a result of a breach of their employment duties.
Virtual assets and VASPs
The New AML Law and its Executive Regulations explicitly address the use of digital systems, virtual assets and encryption technologies. Virtual Asset Service Providers (VASPs) are now directly regulated, with strict licensing, reporting and anti-anonymity requirements. Businesses dealing with cryptocurrencies or other virtual assets must ensure their AML/CTF programmes are specifically tailored to the unique risks of this sector, including transaction monitoring and wallet screening.
Beneficial owners, FIU orders and foreign requests under the Executive Regulations
The practical implementation of the New AML Law is detailed in its Executive Regulations, Cabinet Resolution No. 134 of 2025, which came into force on 14 December 2025. The resolution provides the operational framework for regulated entities.
Records of ultimate beneficial owners
The Executive Regulations place significantly higher scrutiny on establishing and verifying beneficial ownership. Regulated entities must maintain accurate and up-to-date records of their ultimate beneficial owners. They must apply Enhanced Due Diligence (EDD) when the beneficial owner is a high-risk individual or entity. This requirement is crucial for preventing the misuse of corporate structures for money laundering.
For businesses, this means a thorough review of their company formation and corporate governance records is essential. See our pages on free zone company formation and corporate governance advisory.
Seizure and freezing orders
The enforcement toolkit of the Financial Intelligence Unit (FIU) has been significantly expanded, granting it powers to act swiftly against suspected illicit activities.
| FIU power | Description | Implication for businesses |
|---|---|---|
| Seizure order | Suspend transactions suspected to be linked to financial crime for up to 10 working days, without prior notice. | Transactions can be halted instantly, requiring immediate response and clear documentation of compliance procedures. |
| Freezing order | Freeze funds suspected to be linked to financial crime for a period of 30 days (extendable). | Assets can be immobilised for extended periods, severely impacting operations and liquidity. |
These expanded powers underscore the need for real-time transaction monitoring and a rapid, well-defined internal process for handling FIU inquiries and orders.
Foreign orders and confiscation
The New AML Law broadens the UAE courts' powers to implement foreign orders for "provisional measures" or confiscate criminal property without the need for a local, UAE-based money laundering investigation. For professional legal guidance on these obligations, see our AML compliance advisory service page.
Real estate, precious metals and professional firms under the risk-based approach
DNFBPs remain a critical focus area for the UAE's regulatory bodies, particularly the Ministry of Economy and Tourism (MoET). DNFBPs include real estate agents, dealers in precious metals and stones, auditors and legal consultants. In August 2025 the MoET released Circular No. 6 of 2025, which re-emphasised the importance of a risk-based approach (RBA) to AML compliance. The RBA requires businesses to tailor their controls to their specific risks.
- Real estate: Due to the sector's vulnerability to money laundering, agents must conduct CDD on both the buyer and the seller, verify the source of funds and wealth, and prioritise the identification of the beneficial owner for all high-value transactions. See our real estate law advisory services.
- Precious metals and stones (DPMS): DPMS must apply CDD to all cash transactions exceeding the set threshold (typically AED 55,000). They must also implement systems for identifying and reporting suspicious transactions, especially those involving unusual payment methods.
- Legal and accounting professionals: When involved in specific financial transactions for a client, such as managing client money or forming companies, they must apply CDD and EDD. They must be acutely aware of the risk of tipping off a client when filing a Suspicious Transaction Report (STR). That balance requires specialised legal advice and training.
The MoET's focus on the RBA is a direct call for DNFBPs to move beyond a tick-box approach and embed risk management into their core operations.
Governance, monitoring systems and staff training
The legislative changes of 2025 make a thorough review and upgrade of existing AML/CTF compliance programmes necessary.
The increased personal liability for managers makes strong governance non-negotiable. This includes appointing a dedicated, senior Compliance Officer. It includes immediately updating all internal policies and procedures to reflect the New AML Law and Executive Regulations, especially concerning CPF, virtual assets and the objective test. It also includes a regular, independent audit of the AML/CTF programme to confirm its effectiveness.
The scale and complexity of transactions demand a modern, technology-driven approach:
- Automated KYC/CDD: Implement automated systems for real-time sanctions screening, PEP screening and adverse media checks to reduce human error and provide an auditable trail.
- AI-driven transaction monitoring: Move beyond simple rule-based systems and use AI and machine learning to detect subtle, non-obvious patterns of suspicious activity, such as deviations from a customer's normal behaviour.
- Case management and reporting: Use integrated case management systems that centralise all data and give a consistent, documented and timely process for filing STRs with the FIU. The new law's expanded FIU powers mean that delays in reporting are more likely to result in severe penalties.
Compliance is a culture, not just a department. Because of the new law's focus on manager liability and the objective test, training must be thorough and targeted. Senior management training must focus on their personal responsibilities and the legal implications of the new objective test. All relevant employees must receive regular, role-specific training on identifying red flags, applying CDD/EDD and internal reporting procedures. Training records must be meticulously maintained.
How the objective test could be applied to a missed red flag
The objective test shifts the focus from the defendant's internal state of mind to the adequacy of the firm's compliance infrastructure. Businesses must consider how the "should have reasonably known" standard will be applied in enforcement actions.
An offshore holding structure taken at face value
A DNFBP is engaged to provide services to a company whose ownership involves multiple layers of holding companies registered in various offshore jurisdictions. The firm's compliance officer performs only basic CDD. The officer accepts the documents provided without an independent search for the ultimate beneficial owner. If that owner is later identified as a high-risk individual on a sanctions list, the compliance officer and senior management could face personal liability. The argument would be that a reasonable compliance professional, faced with a complex, multi-jurisdictional structure, should have known that EDD was mandatory and that failing to perform it was a breach of duty.
A flagged transfer dismissed as a false positive
A long-standing client of a financial institution, with a business profile in local retail, suddenly attempts a large, unexplained wire transfer to a company in a jurisdiction known for high money laundering risk. The transaction monitoring system flags the transfer. The compliance analyst, due to heavy workload and lack of training, dismisses the alert as a "false positive" without proper investigation or documentation. When the funds are later traced to a criminal enterprise, the institution and the analyst are exposed. The objective test will focus on the analyst's failure to follow established procedures for investigating a red flag. The argument would be that any reasonable person in that role should have known the transaction was suspicious and required an STR.
Bringing a programme into line, phase by phase
The transition to full compliance with the 2025 legislative framework requires a structured, multi-phase project. Businesses should immediately initiate the following steps.
Gap analysis and risk reassessment
- Conduct a new Business Risk Assessment (BRA). The existing BRA is likely obsolete. A new assessment must explicitly incorporate the risks of CPF, the increased risk from virtual assets and the implications of the objective test.
- Policy and procedure gap analysis. Compare all current AML/CTF policies against the requirements of Federal Decree Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025. Identify all missing or deficient controls, particularly those related to EDD triggers, beneficial ownership verification and STR filing protocols.
- Resource allocation review. Assess the current compliance team's capacity, expertise and technology stack. Determine the necessary budget and personnel increases to meet the new regulatory burden.
Remediation and implementation
- Policy drafting and approval. Draft and formally approve all updated AML/CTF policies and procedures. This includes a new internal manual detailing the firm's response to the objective test and the new personal liability for managers.
- Technology upgrade. Implement or upgrade the AML technology stack. Integrate automated KYC/CDD and AI-driven transaction monitoring systems capable of handling the new complexity, including virtual asset transactions.
- Beneficial ownership register clean-up. Conduct a full remediation of the register. This involves re-verifying the beneficial owner for all high-risk clients and documenting the steps taken to identify the ultimate natural person, especially for complex structures.
Training and culture, on an ongoing basis
- Mandatory, role-specific training. Roll out a mandatory training programme. The training must be customised. For senior management, the focus is personal liability, governance and the objective test. For front-line staff, it is red flag identification, CDD/EDD procedures and internal reporting. For the compliance team, it is new STR filing protocols, the FIU's expanded powers and technology usage.
- Independent audit. Commission an independent, external audit of the newly implemented AML programme. The audit provides an objective assessment of the programme's effectiveness. It also serves as crucial evidence of the firm's commitment to compliance, which is vital under the new objective test.
Given the complexity, the severity of the penalties and the rapid pace of regulatory change, seeking specialised external AML compliance advice is a prudent and often necessary step.
Related services: Our financial crime litigation, AML compliance advisory and real estate law advisory services.
Disclaimer: The information provided in this article is for general informational purposes only and does not constitute legal advice. Readers should seek professional legal advice tailored to their specific circumstances before making any decisions or taking any action based on the content of this article.
Nour Attorneys Team
Additional Resources
More of our insights on related topics: