Financial crime regulations in the UAE continue to evolve, with Federal Decree-Law No. 10 of 2025 (effective October 14, 2025) and Cabinet Resolution No. 134 of 2025 (effective December 14, 2025) introducing the most significant overhaul of the AML/CFT framework to date.
Many businesses have AML policies in place. However, having documents on file is only one part of compliance. Regulators also expect businesses to demonstrate that their controls work in practice.
As a result, many AML reviews uncover the same recurring weaknesses. These gaps often lead to corrective actions, regulatory findings, and in some cases, financial penalties.
In this article, we look at four common AML compliance gaps for DNFBPs in the UAE and the practical steps businesses can take to address them.
The Growing Compliance Expectations Facing UAE DNFBPs
Under the UAE’s anti-money laundering framework, DNFBPs must implement risk-based controls to identify, assess, and manage money laundering and terrorist financing risks.
This includes conducting Customer Due Diligence (CDD), maintaining records, reporting suspicious transactions, and monitoring client activities. These obligations arise from the UAE’s AML legislation and related guidance issued by competent authorities.
Consequently, businesses that treat compliance as a simple documentation exercise often face challenges during inspections and audits.
If you have not already reviewed your AML framework, our previous post, “AML Audit and Compliance Review in the UAE: What Businesses Often Miss Until It’s Too Late,” provides additional insight into common compliance weaknesses and review findings.
Gap #1: Ineffective Implementation of AML Policies
Many DNFBPs have AML policies in place. However, regulators often find a gap between written procedures and day-to-day operations.
In some cases, businesses rely on generic policy templates. In others, employees are unaware of their responsibilities or do not consistently follow internal procedures.
Furthermore, internal controls may not fully reflect the latest regulatory requirements under the UAE’s AML framework, including updates introduced through Federal Decree-Law No. 10 of 2025 (effective October 14, 2025) and Cabinet Resolution No. 134 of 2025 (effective December 14, 2025), which also mandate Proliferation Financing risk assessments.
Common Signs of This Gap
- Staff cannot explain AML procedures during inspections
- Policies are copied from generic templates
- Controls do not reflect business activities
- Compliance responsibilities are unclear
- Employee training records are incomplete
How to Fix It
- Start by reviewing all AML policies against your business model.
- Next, map each policy requirement to a practical internal process.
- Then, conduct regular staff training sessions and maintain training records.
- Finally, test your controls through periodic AML compliance reviews and internal assessments.
Gap #2: Inconsistent Customer Due Diligence (CDD)
Customer Due Diligence is one of the most important AML requirements for DNFBPs.
However, many businesses apply the same onboarding process to every client. This approach creates significant compliance risks.
For example, some organisations fail to identify the Ultimate Beneficial Owner (UBO). Others overlook Politically Exposed Persons (PEPs) or perform only basic checks on high-risk clients.
Under UAE AML regulations, businesses must apply a risk-based approach to customer due diligence. Enhanced Due Diligence (EDD) is required when higher-risk situations are identified.
Common Signs of This Gap
- Missing UBO documentation
- No PEP screening process
- Limited client risk assessment records
- High-risk clients treated the same as low-risk clients
- Incomplete source of funds verification
How to Fix It
- First, establish clear onboarding procedures.
- Next, verify beneficial ownership information before onboarding clients.
- In addition, implement screening procedures for PEPs and sanctions lists.
- Most importantly, apply Enhanced Due Diligence for higher-risk clients and document the reasons behind every decision.
Gap #3: Generic and Unrealistic Risk Scoring
Risk assessments form the foundation of an effective AML compliance programme.
However, many DNFBPs assign low-risk ratings to all clients. In many cases, there is little or no documentation to support these classifications.
As a result, regulators may conclude that the business has not properly assessed its exposure to financial crime risks.
According to UAE guidance, businesses must identify and assess risks based on factors such as customers, services, geographic exposure, delivery channels, and other relevant risk indicators.
Common Signs of This Gap
- Every client receives the same risk score
- Risk assessments are completed only once
- Geographic risks are ignored
- Service-specific risks are not considered
- Risk ratings lack supporting evidence
How to Fix It
Begin by reviewing your enterprise-wide risk assessment.
Then evaluate client risks based on:
- Client profile
- Business activity
- Geographic location
- Transaction patterns
- Products and services used
For example, real estate activities, high-value transactions, and cross-border dealings may present different levels of risk.
As a result, risk ratings should reflect genuine business realities and not simply follow a standard template.
Gap #4: Weak Escalation Documentation and goAML Reporting
- Many compliance failures arise from poor record-keeping.
- A business may identify a potential concern. However, if the decision-making process is not documented, regulators may view the control as ineffective.
- This issue often appears during compliance reviews.
- For example, businesses may fail to record why a sanctions match was dismissed. Similarly, they may not document why a Suspicious Activity Report (SAR) was not submitted.
- In addition, reporting procedures are sometimes unclear or inconsistently followed.
- The UAE requires reporting entities to submit suspicious transaction reports and related filings through the goAML platform where reporting obligations apply.
- DNFBPs must retain all CDD records, beneficial ownership information, and transaction records for at least 10 years (per the September 2025 MoET Guidelines).
Common Signs of This Gap
- No documented escalation process
- Missing compliance decision records
- Incomplete investigation notes
- Lack of SAR review procedures
- Poor goAML reporting records
Note: Non-compliance carries significant penalties: administrative fines ranging from AED 50,000 to AED 5 million per violation, and criminal penalties up to AED 10 million plus imprisonment for ML/TF offences. Serious or repeated non-compliance may result in fines up to AED 100 million, license suspension, or deregistration
How to Fix It
- Create a formal escalation framework.
- Next, document every compliance review and decision.
- Maintain records that explain why alerts were cleared, escalated, or reported.
- In addition, train employees on internal reporting procedures and goAML requirements.
- Most importantly, maintain a clear audit trail that demonstrates how compliance decisions were reached.
Strengthen Your AML Compliance Framework with Elevate Accounting & Auditing
AML compliance is not just about meeting regulatory requirements. It is also about protecting your business from financial, legal, and reputational risks.
At Elevate Accounting & Auditing, we provide comprehensive AML/CFT Compliance Services in the UAE, including:
- AML compliance reviews
- AML gap assessments
- Enterprise-wide risk assessments
- AML policy and procedure development
- Customer Due Diligence framework reviews
- AML training and awareness programmes
- Regulatory compliance support
- Enterprise-wide Risk Assessments covering ML/TF/PF risks per National AML/CFT/CPF Strategy 2024–2027
Our team helps DNFBPs identify weaknesses, strengthen internal controls, and build practical compliance frameworks that align with current UAE AML regulations.
Need Support with AML/CFT Compliance?
Speak with the specialists at Elevate Accounting & Auditing for an independent review of your AML framework and discover how our AML/CFT compliance services can help your business stay prepared for regulatory inspections and ongoing compliance obligations.
FAQS
1.) What are the most common AML compliance gaps for DNFBPs in the UAE?
Common AML compliance gaps include weak implementation of AML policies, inconsistent Customer Due Diligence (CDD), unrealistic risk assessments, and poor documentation of compliance decisions. These issues can lead to regulatory findings and penalties during AML inspections.
2.) Why is Customer Due Diligence (CDD) important for UAE DNFBPs?
CDD helps businesses verify customer identities, identify Ultimate Beneficial Owners (UBOs), assess risk levels, and detect suspicious activities. It is a core requirement under UAE AML regulations and supports effective AML/CFT compliance.
3.) When is Enhanced Due Diligence (EDD) required?
EDD is required for higher-risk customers or transactions, such as Politically Exposed Persons (PEPs), complex ownership structures, or high-risk jurisdictions. Businesses must apply a risk-based approach and document their findings.
4.) What is an Enterprise-Wide Risk Assessment (EWRA)?
An EWRA evaluates a business’s money laundering, terrorist financing, and proliferation financing risks based on factors such as customers, services, transactions, and geographic exposure. It forms the foundation of an effective AML compliance programme.
Elevate Accounting & Auditing helps UAE businesses conduct EWRAs that support stronger AML/CFT compliance frameworks and risk management processes.
5.) What AML records must DNFBPs retain in the UAE?
DNFBPs must retain CDD records, beneficial ownership information, transaction records, and compliance documentation. Current UAE guidelines require many of these records to be maintained for at least 10 years.
