...

AML Compliance in the UAE: Linking SDG 16 to Financial Integrity 

AML Compliance in the UAE: Linking SDG 16 to Financial Integrity

AML Compliance in the UAE: Linking SDG 16 to Financial Integrity 

AML and financial integrity compliance under SDG 16: what UAE businesses need to know

The UAE spent two years on the Financial Action Task Force’s grey list, from March 2022 to February 2024, watching correspondent banks treat every wire transfer with a UAE counterparty as a red flag. That period changed how the country treats anti-money laundering compliance. It is no longer a banking-sector technicality. It sits inside a national strategy now. And it connects directly to a global framework most business owners have never linked to their own compliance obligations: Sustainable Development Goal 16, on peace, justice, and strong institutions.

This guide explains what AML and financial integrity compliance actually require in the UAE today, why regulators frame it as more than a banking issue, and what the SDG 16 connection means in practice for a private business.

Why AML compliance became a national priority

The UAE’s grey-listing in March 2022 was a wake-up call with real commercial cost. Banks abroad de-risked UAE clients by default. Deals slowed or fell through simply because a wire transfer mentioned a UAE entity. The government responded with a multi-year reform programme:

  • A new Executive Office to Combat Money Laundering and Terrorist Financing
  • A specialist court for money laundering and financial crime
  • Updated AML guidance for financial institutions and non-financial businesses
  • A revised Penal Code with stronger bribery and corruption provisions

FATF removed the UAE from the grey list in February 2024. The EU followed in August 2025, taking the UAE off its own list of high-risk third countries. Rather than easing off, the UAE has kept building. On September 30, 2025, it issued Federal Decree-Law No. 10 of 2025, a full overhaul of the AML framework that replaced the 2018 law and significantly raised the stakes for businesses and their managers.

What changed under the new AML law

Federal Decree-Law No. 10 of 2025 rewrote several core parts of the UAE’s AML regime.

Proliferation financing, meaning the financing of weapons of mass destruction, is now an offence in its own right, alongside money laundering and terrorist financing. Virtual asset service providers are explicitly brought into scope. The threshold for establishing an offence has dropped. A person can now be liable not only if they had actual knowledge of wrongdoing, but if a reasonable person in their position would have known. That is an objective test, not a subjective one.

Penalties increased sharply. Fines for legal entities now range from AED 5 million to AED 100 million, up from a prior range of AED 500,000 to AED 50 million. Regulated entities face fines up to AED 10 million. Courts can order the dissolution of a company or the closure of its headquarters following a money laundering conviction, and no limitation period applies, so liability exposure does not expire with time.

Senior management carries direct personal risk under the new law. Managers can face personal criminal liability if they had actual knowledge of an offence, or if the offence occurred because they breached their own duties. The law defines senior management broadly, covering anyone with the authority to materially influence risk management, compliance policy, or operational governance, not just formal executives.

Who has to comply

Who has to comply

AML obligations in the UAE extend well beyond banks. Three categories of entity fall under the regime:

  • Financial institutions, including banks, exchange houses, finance companies, and payment service providers, supervised primarily by the Central Bank of the UAE, with the DFSA covering DIFC firms and the FSRA covering ADGM firms.
  • Designated non-financial businesses and professions (DNFBPs), a category that includes real estate brokers, lawyers, accountants, auditors, precious metals and stones dealers, and corporate service providers.
  • Virtual asset service providers (VASPs), newly and explicitly captured under the 2025 law.

DNFBPs are the category most private businesses overlook. If your business is an accounting firm, a real estate brokerage, or a corporate services provider, you are likely a DNFBP regardless of size. That means the same customer due diligence, record-keeping, and suspicious transaction reporting obligations a bank faces, scaled to your risk profile.

The SDG 16 connection

Sustainable Development Goal 16 commits countries to peace, justice, and strong institutions. Two of its targets map directly onto AML and financial integrity work. Target 16.4 calls for significantly reducing illicit financial and arms flows and strengthening the recovery of stolen assets by 2030. Target 16.5 calls for substantially reducing corruption and bribery in all forms.

These targets are not abstract policy language. Every AML control a business puts in place, customer due diligence, beneficial ownership checks, suspicious transaction reporting, sanctions screening, is a practical contribution to Target 16.4 and 16.5. A country’s illicit financial flows and corruption levels are largely a function of how well its regulated businesses screen the money moving through them.

This is also where AML compliance and Majra’s Companies for Good 2031 strategy start to overlap. Companies for Good 2031, covered in detail here, asks businesses to report governance and social contribution data through an Impact Declaration. A business with a documented, functioning AML programme already has much of the governance evidence that declaration asks for. Financial integrity and CSR reporting draw on the same underlying discipline: clean records, clear ownership, and traceable transactions.

Where the UAE stands right now

The next FATF Mutual Evaluation of the UAE is scheduled for June 2026, and regulators have been explicit that they are treating this as a high priority. The Central Bank issued over AED 370 million in fines during 2025 alone. That included an AED 18.1 million penalty on two foreign bank branches and an AED 200 million penalty on an exchange house for AML control failures. The FSRA in ADGM has pursued smaller but frequent enforcement actions against DNFBPs. Its $8.85 million fine against a virtual asset firm in 2025 signalled that digital asset businesses are now squarely in scope.

The CBUAE issued an updated package of AML, counter-terrorism financing, and counter-proliferation financing guidance in April 2026, covering proliferation financing risk assessment, trade-based money laundering, correspondent banking due diligence, and customer due diligence standards. It also moved away from generic AML training toward role-specific training requirements for compliance staff.

Compliance obligations at a glance

RequirementApplies toWhat it involvesWhere it sits
Registration and reportingFinancial institutions and DNFBPsRegister on goAML; file Suspicious Transaction and Activity ReportsMinistry of Economy / Financial Intelligence Unit
Customer due diligenceAll regulated entitiesIdentify clients, verify beneficial ownership, apply enhanced due diligence for PEPsCentral Bank, DFSA, FSRA
Risk assessmentAll regulated entitiesBusiness-wide risk assessment, now including proliferation financing as a standalone categoryCBUAE / sector regulators
Record-keepingAll regulated entitiesRetain AML records for at least five years after a transaction or relationship endsFederal AML Law
Compliance officer / MLROAll regulated entitiesAppoint a senior, independent officer with board access and adequate resourcesJoint Guidance on Compliance Officers, 2026
Senior management accountabilityDirectors and managersPersonal criminal liability for actual knowledge or breach of dutyFederal Decree-Law No. 10 of 2025

What DNFBPs and SMEs should do now

What DNFBPs and SMEs should do now

Most AML guidance is written for banks with dedicated compliance departments. A smaller DNFBP or private business needs a shorter, practical starting point:

  • Confirm whether your business falls under the DNFBP definition. If you provide accounting, real estate, legal, or corporate services, assume you do until proven otherwise.
  • Register on goAML if you have not already. This is the platform the Ministry of Economy and the Financial Intelligence Unit use for suspicious transaction and activity reports.
  • Appoint a compliance officer or MLRO with real authority and board access, not a title added to someone’s existing job description.
  • Review your risk assessment against the objective knowledge standard. Under the new law, “we didn’t know” is a weaker defence than it used to be if a reasonable person in your position would have known.
  • Brief senior management directly on personal liability exposure. This is no longer only a company-level risk.

Frequently Asked Questions

Is AML compliance only for banks in the UAE? 

No. AML obligations apply to financial institutions and to designated non-financial businesses and professions, a category that includes real estate brokers, lawyers, accountants, auditors, and corporate service providers. Many private businesses fall under DNFBP rules without realizing it.

What is Federal Decree-Law No. 10 of 2025? 

It is the UAE’s current federal AML law, issued September 30, 2025, replacing the 2018 AML framework. It adds proliferation financing as a standalone offence, brings virtual asset service providers into scope, lowers the knowledge threshold for offences to an objective test, and significantly raises penalties, including personal criminal liability for senior managers.

How does SDG 16 relate to AML compliance? 

SDG 16 targets 16.4 and 16.5 call for reducing illicit financial flows and reducing corruption and bribery. Every AML control a business applies, customer due diligence, beneficial ownership verification, suspicious transaction reporting, contributes directly to those targets. It is the same underlying discipline the UAE’s national AML strategy is built around.

What happens if my business misses its AML obligations? 

Penalties for legal entities now range from AED 5 million to AED 100 million under the 2025 law, with regulated entities facing fines up to AED 10 million. Administrative penalties can include business suspension, license revocation, and removal of senior management. Courts can order a company’s dissolution following a conviction, and no limitation period applies.

Is my company automatically compliant if it isn’t a bank? 

No. If your business is a DNFBP, meaning it operates in real estate, legal services, accounting, auditing, or corporate services, you carry the same core obligations as a financial institution. That means customer due diligence, record-keeping, risk assessment, and suspicious transaction reporting, scaled to your size and risk profile.

How Oak Business Consultant can help

Working out whether your business counts as a DNFBP, and what that means in practice, is the first place most companies get stuck. Our AML consulting services assess your exposure under Federal Decree-Law No. 10 of 2025, build the risk assessment and due diligence procedures your business actually needs, and help you register correctly on goAML.

Because AML compliance depends on clean underlying records, our regulatory compliance services make sure your licensing and structure hold up before a regulator looks at them, and our accounting and bookkeeping team keeps the financial records your AML programme depends on accurate and audit-ready. Where your compliance work needs coordination with government entities, our PRO services team handles that liaison directly.

Not sure whether your business is a DNFBP, or whether your current AML programme would hold up under the CBUAE’s 2026 guidance? Get in touch and we will walk through your structure and flag exactly what is required.

Share this post