United Arab Emirates KYC, KYB & AML compliance checklist
A practical, source-linked checklist for implementing KYC, KYB and AML requirements in United Arab Emirates.
- Last reviewed
- Last reviewed:
- Version
- Version 1.1

Direct answer
What does the United Arab Emirates compliance checklist cover?
The United Arab Emirates checklist translates primary KYC, KYB and AML rules into 11 control areas and 41 implementation checks. It identifies the relevant authorities, customer and beneficial-owner controls, reporting duties, recordkeeping expectations and evidence teams should retain.
Key regulatory facts
- FIU
- UAE Financial Intelligence Unit; suspicious reports use the FIU's approved forms and goAML service
- Primary AML rules
- Federal Decree-Law 10/2025 and Cabinet Resolution 134/2025
- FI occasional CDD
- AED 55,000, single or linked transactions
- Wire and VASP CDD
- AED 3,500 under Cabinet Resolution 134/2025
- AML ownership test
- 25% or more, then other control, then senior management
- National KYC platform
- Federal Decree-Law 30/2024 and Cabinet Resolution 55/2026 are active
- Suspicion reporting
- Without delay, including attempts and regardless of value
- Core retention
- At least 5 years, using the latest applicable trigger
- FATF public lists
- Not listed at 19 June 2026; removed from increased monitoring in February 2024
Implementation detail
United Arab Emirates compliance requirements and actions
Open each control area to review the requirement, recommended implementation action, evidence to retain and the primary-source citation used by the research team.
01Scope, authorities, and licensingResolve the regulated activity, location and supervisor before onboarding or launch.3 items+
Map each entity and activity to the federal reporting perimeter.
- Implementation action
- Classify financial activities, designated non-financial businesses and professions, virtual-asset services and nonprofit activity under the 2025 law and executive regulation; record the applicable supervisor.
- Evidence to retain
- Entity map, activity analysis, licence inventory, supervisor confirmation and legal opinion.
- Primary citation
- Federal Decree-Law 10/2025; Cabinet Resolution 134/2025, Articles 2-5
Separate federal, emirate and financial-free-zone regimes.
- Implementation action
- Determine whether CBUAE, SCA, Ministry of Economy and Tourism, Ministry of Justice, VARA, DFSA or FSRA rules govern each service; do not extend a mainland or free-zone rule beyond its perimeter.
- Evidence to retain
- Jurisdiction decision tree, establishment documents, customer-location rules and regulator correspondence.
- Primary citation
- Federal Decree-Law 10/2025; joint UAE supervisory guidance; applicable regulator rulebook
Obtain every required financial, payment or virtual-asset permission.
- Implementation action
- Before promotion or operation, classify retail payment, stored-value, payment-token, remittance, exchange, securities and virtual-asset activity and secure the licence, registration or non-objection required by the competent regulator.
- Evidence to retain
- Product analysis, application, licence, conditions, approved agents and renewal calendar.
- Primary citation
- Federal Decree-Law 6/2025; CBUAE Retail Payment Services Regulation; CBUAE Payment Token Services Regulation; applicable SCA, VARA, DFSA or FSRA rules
02Governance and risk assessmentControls must be risk-based, senior-approved, independently tested and updated.3 items+
Maintain a documented enterprise crime-risk assessment.
- Implementation action
- Assess money-laundering, terrorist-financing and proliferation-financing exposure by customer, country, product, service, transaction, delivery channel and technology and update it when risks change.
- Evidence to retain
- Methodology, risk assessment, source inputs, approvals, residual-risk decision and remediation plan.
- Primary citation
- Cabinet Resolution 134/2025, Articles 4-5 and 24
Maintain senior-approved policies and a management-level compliance officer.
- Implementation action
- Document CDD, reporting, sanctions, records, employee screening, training and governance procedures proportionate to risk and obtain senior-management approval.
- Evidence to retain
- Policy suite, approval minutes, compliance appointment, authority matrix and reporting packs.
- Primary citation
- Cabinet Resolution 134/2025, Articles 21-22
Independently test the AML/CFT/CPF programme.
- Implementation action
- Operate risk-based monitoring, staff training and an independent audit function; track findings to verified closure.
- Evidence to retain
- Training records, audit plan, test samples, findings, owners and closure evidence.
- Primary citation
- Cabinet Resolution 134/2025, Article 21
03Natural-person identificationIdentify and verify customers and representatives from reliable independent evidence.4 items+
Apply CDD at every applicable trigger.
- Implementation action
- Perform CDD at relationship start, on suspicion or doubtful prior data; for financial institutions also at AED 55,000 occasional transactions and AED 3,500 occasional wires; for VASPs at AED 3,500 occasional transactions, aggregating linked activity where specified.
- Evidence to retain
- Trigger matrix, aggregation tests, timestamps, customer file and exception log.
- Primary citation
- Cabinet Resolution 134/2025, Article 7
Verify natural-person identity using current reliable evidence.
- Implementation action
- Obtain the official name, nationality, address, date and place of birth and applicable employment information, plus a true copy of a valid identity card or travel document, and corroborate authenticity.
- Evidence to retain
- Identity copy, verification results, liveness or presence evidence, discrepancy log and approval.
- Primary citation
- Cabinet Resolution 134/2025, Article 9(1)(a)
Verify each representative and their authority.
- Implementation action
- Identify and verify the person acting for a customer and confirm the authenticity and scope of the authorisation before permitting access or instructions.
- Evidence to retain
- Representative KYC, power or mandate, authority check, limits and activity log.
- Primary citation
- Cabinet Resolution 134/2025, Articles 9 and 12
Do not proceed when CDD cannot be completed.
- Implementation action
- Do not establish or continue the relationship or execute the transaction; consider an STR. If further CDD would alert the customer, stop that step and report the reason to the FIU.
- Evidence to retain
- Restriction, exit decision, suspicion assessment, approval and submission receipt.
- Primary citation
- Cabinet Resolution 134/2025, Article 14
04KYB, registries, and beneficial ownershipVerify legal existence, authority, ownership and actual control, keeping AML and registry tests distinct.5 items+
Verify legal-person identity, purpose and authority.
- Implementation action
- Obtain name, legal form, constitutional documents, tax and unique reference numbers where applicable, registered and principal address, directors and binding authority from reliable independent sources.
- Evidence to retain
- Current registrar extract, constitutional pack, licence, officer list, mandates and discrepancy log.
- Primary citation
- Cabinet Resolution 134/2025, Article 9(1)(b)
Identify AML beneficial owners at 25% or more.
- Implementation action
- Trace natural persons ultimately owning, alone or jointly, an actual controlling ownership interest or shares of 25% or more; if unresolved, identify control by other means, then the relevant senior-management person or persons.
- Evidence to retain
- Layered ownership chart, percentage calculations, control analysis, fallback rationale and verified identities.
- Primary citation
- Cabinet Resolution 134/2025, Article 10(1)
Identify all controlling parties to legal arrangements.
- Implementation action
- Identify and verify trustees, settlors, protectors, beneficiaries or classes and every other natural person exercising ultimate effective control, including legal persons within the arrangement.
- Evidence to retain
- Trust or arrangement instrument, party register, powers, ownership analysis and verified identities.
- Primary citation
- Cabinet Resolution 134/2025, Article 10(2)
Maintain the entity-level beneficial-owner record where Decision 109/2023 applies.
- Implementation action
- Create the record within 60 days of formation, keep adequate and current owner data, record changes within 15 days of knowledge and provide required information to the registrar; apply the decision's 25% or control and senior-manager cascade.
- Evidence to retain
- Beneficial-owner, shareholder and nominee registers, notices, filing receipts and change log.
- Primary citation
- Cabinet Decision 109/2023, Articles 5-10
Apply financial-free-zone ownership rules separately.
- Implementation action
- For DIFC or ADGM entities use the relevant registrar and free-zone beneficial-ownership rules rather than Cabinet Decision 109/2023; document any government or listed-company exemption before relying on it.
- Evidence to retain
- Perimeter decision, free-zone extract, exemption analysis and filing evidence.
- Primary citation
- Cabinet Decision 109/2023, Articles 2 and 6; applicable DIFC or ADGM regulations
05PEPs, EDD, and remote onboardingDetect public-function exposure and strengthen controls where risk requires.4 items+
Identify PEPs, family members and close associates.
- Implementation action
- Use appropriate risk systems, declarations and reliable sources to determine whether a customer or beneficial owner is a foreign or domestic PEP or holds a prominent international-organisation function.
- Evidence to retain
- Declaration, screening result, relationship map, match rationale and refresh history.
- Primary citation
- Cabinet Resolution 134/2025, Article 16
Apply approval, wealth, funds and enhanced-monitoring measures.
- Implementation action
- For foreign PEPs obtain senior approval, establish source of wealth and funds and enhance ongoing monitoring; apply the same measures to higher-risk domestic and international-organisation PEPs.
- Evidence to retain
- Risk assessment, senior approval, source corroboration, monitoring plan and reviews.
- Primary citation
- Cabinet Resolution 134/2025, Article 16
Control remote onboarding as a technology risk.
- Implementation action
- Before use, assess impersonation, synthetic-identity, document and deepfake risks; validate the method, protect evidence and add controls proportionate to residual risk.
- Evidence to retain
- Technology risk assessment, validation, liveness results, fraud tests, restrictions and monitoring.
- Primary citation
- Cabinet Resolution 134/2025, Articles 8, 9 and 24
Map duties under the national KYC Digital Platform.
- Implementation action
- Determine whether the entity collects, retains, analyses, classifies, uses, exchanges, protects or manages KYC data or issues a KYC report; if in scope, classify its platform role, supply the prescribed natural- or legal-person data and implement the current access, consent, security and update requirements.
- Evidence to retain
- Platform-scope analysis, role registration, data-field map, customer authority, transmission logs, security controls and update evidence.
- Primary citation
- Federal Decree-Law 30/2024; Cabinet Resolution 55/2026, Articles 2-3 and applicable platform provisions
06Monitoring and suspicious reportingSuspicious transactions and attempts are reported without delay and regardless of value.4 items+
Monitor relationships and keep indicators current.
- Implementation action
- Scrutinise activity against customer information, business purpose, risk and source of funds where necessary; update crime indicators with changing methods and supervisory instructions.
- Evidence to retain
- Monitoring scenarios, indicator register, alerts, investigations, source data and dispositions.
- Primary citation
- Cabinet Resolution 134/2025, Articles 8 and 17
Report suspicion and attempted transactions without delay.
- Implementation action
- When suspicion or reasonable grounds arise, regardless of value, submit the FIU-approved suspicious report with available data and documents through the authorised service; do not wait for proof or a threshold.
- Evidence to retain
- Suspicion chronology, analysis, approved report, goAML delivery record and acknowledgement.
- Primary citation
- Federal Decree-Law 10/2025; Cabinet Resolution 134/2025, Article 18
Register and govern goAML access before operations.
- Implementation action
- Complete FIU pre-registration under the correct supervisor, establish controlled organisation and user administration and test the current report and supplemental-information process.
- Evidence to retain
- Registration, user approvals, role matrix, test evidence and current FIU guidance.
- Primary citation
- UAE FIU goAML services registration
Prevent tipping off and preserve report confidentiality.
- Implementation action
- Restrict report and investigation data and do not disclose that a report has been or will be filed or that an investigation is underway, except as lawfully permitted.
- Evidence to retain
- Need-to-know matrix, access logs, communication controls, training and incident review.
- Primary citation
- Cabinet Resolution 134/2025, Article 19
07Payments, wires, thresholds, and agentsPayment permissions, wire data and agent oversight are product- and regulator-specific.4 items+
Carry complete originator and beneficiary information.
- Implementation action
- For international wires of AED 3,500 or more verify originator information and transmit the required names, accounts or unique reference and identifying field; transmit required data below the threshold and verify where suspicion exists.
- Evidence to retain
- Field matrix, validation logic, sampled transfers, repair queue and verification results.
- Primary citation
- Cabinet Resolution 134/2025, Article 28
Control incomplete intermediary and incoming wires.
- Implementation action
- Detect missing information and apply documented risk rules to execute, suspend or reject; beneficiary institutions verify an unverified beneficiary at AED 3,500 or more.
- Evidence to retain
- Detection rules, repair requests, risk decisions, beneficiary checks and escalation records.
- Primary citation
- Cabinet Resolution 134/2025, Articles 29-30
Govern money-transfer agents within the AML programme.
- Implementation action
- Maintain the current agent list, make it available to authorities, include agents in the AML/CFT/CPF programme and monitor their compliance.
- Evidence to retain
- Agent due diligence, contracts, register, training, monitoring and remediation.
- Primary citation
- Cabinet Resolution 134/2025, Article 27
Use the correct payment or payment-token licence.
- Implementation action
- Map the service to retail payment, stored-value or payment-token categories; obtain the CBUAE licence, registration or non-objection and comply with restrictions on promotions, agents and outsourcing.
- Evidence to retain
- Regulatory classification, licence, product terms, agent approvals, outsourcing register and launch sign-off.
- Primary citation
- CBUAE Retail Payment Services and Card Schemes Regulation; Payment Token Services Regulation, Articles 2, 5, 19 and 20
08Targeted financial sanctionsUAE and UN list matches require immediate controls under Cabinet Decision 74/2020 and current Executive Office instructions.4 items+
Subscribe to updates and screen UAE and UN sanctions lists.
- Implementation action
- Screen customers, beneficial owners, controllers, representatives, related parties and transactions against the current Local Terrorist List and UN Consolidated List at onboarding, daily and when lists change.
- Evidence to retain
- Subscription, list inventory, update logs, screening configuration, tests and dispositions.
- Primary citation
- Cabinet Decision 74/2020; Executive Office TFS guidance
Freeze confirmed matches without delay and prior notice.
- Implementation action
- Freeze covered funds and assets immediately, in any event within the official without-delay standard, prevent funds or services being made available and keep restrictions until lawful release.
- Evidence to retain
- Match analysis, freeze timestamp, ownership/control analysis, asset inventory and system blocks.
- Primary citation
- Cabinet Decision 74/2020; Executive Office TFS guidance
Report freezes and attempted transactions through the current route.
- Implementation action
- For financial institutions and DNFBPs submit the Fund Freeze Report with supporting material through goAML within two business days and notify the relevant supervisor as required.
- Evidence to retain
- FFR, attachments, submission receipt, supervisor notice and chronology.
- Primary citation
- Executive Office TFS guidance and confirmed-match workflow
Govern partial matches, exemptions and release.
- Implementation action
- Suspend or restrict a possible match according to current guidance, seek Executive Office direction and release or permit access only under verified competent-authority or UN procedure.
- Evidence to retain
- Identifier analysis, correspondence, licence or exemption, approval and release log.
- Primary citation
- Cabinet Decision 74/2020; Executive Office TFS guidance
09Records and regulator accessRecords must reconstruct transactions and decisions and follow the latest applicable retention trigger.3 items+
Retain transaction and relationship records for at least five years.
- Implementation action
- Keep domestic and international transaction, cash and commercial-dealing records for at least five years after transaction completion or relationship termination, applying the later applicable trigger.
- Evidence to retain
- Retention schedule, trigger calculations, archive sample, legal holds and deletion controls.
- Primary citation
- Cabinet Resolution 134/2025, Article 25(1)
Apply the latest-trigger rule to CDD and investigation records.
- Implementation action
- Keep CDD, monitoring, account, correspondence, identification, STR, analysis and specified recording evidence for at least five years from the most recent applicable closure, transaction, inspection, investigation or final-judgment event.
- Evidence to retain
- Record-class map, linked case files, trigger engine, archive and retrieval test.
- Primary citation
- Cabinet Resolution 134/2025, Article 25(2)
Make records promptly available to competent authorities.
- Implementation action
- Organise information to reconstruct individual transactions, authenticate requests and produce responsive customer and monitoring material promptly while protecting report confidentiality.
- Evidence to retain
- Request register, authority validation, production index, delivery log and receipt.
- Primary citation
- Cabinet Resolution 134/2025, Article 25(3)-(4)
10Privacy, biometrics, and transfersFederal data protection applies subject to statutory exclusions and separate DIFC, ADGM, health and credit-data regimes.4 items+
Map the applicable privacy regime and lawful basis.
- Implementation action
- Determine whether Federal Decree-Law 45/2021, DIFC or ADGM data-protection law or a sector regime applies; document consent or another lawful ground for every identity, screening and monitoring purpose.
- Evidence to retain
- Data inventory, perimeter and lawful-basis analysis, notices, consent records and exception register.
- Primary citation
- Federal Decree-Law 45/2021, Articles 2, 4 and 6; applicable DIFC or ADGM law
Minimise and secure identity and biometric data.
- Implementation action
- Collect only necessary data, apply purpose limitation, accuracy, retention and security controls and treat biometric data used for unique identification as sensitive personal data requiring heightened safeguards.
- Evidence to retain
- Field justification, security design, access reviews, encryption evidence, retention configuration and tests.
- Primary citation
- Federal Decree-Law 45/2021, Articles 1, 5 and 20
Perform impact assessments and appoint a DPO where required.
- Implementation action
- Assess high-risk technology and large-scale sensitive processing before use and appoint an appropriately independent data-protection officer when statutory triggers apply.
- Evidence to retain
- Impact assessment, risk treatment, DPO analysis and appointment, consultation and approval.
- Primary citation
- Federal Decree-Law 45/2021, Articles 10 and 22
Control incidents, rights requests and overseas transfers.
- Implementation action
- Maintain regulator and data-subject notification procedures without inventing an unverified deadline; fulfil applicable rights and transfer data only under an authorised adequacy or safeguard route.
- Evidence to retain
- Incident assessment, notifications, rights log, transfer map, contract and adequacy or derogation analysis.
- Primary citation
- Federal Decree-Law 45/2021, Articles 9, 13-18 and 23-24
11Practical evidence packsEvidence should reproduce onboarding, monitoring and launch decisions across regulator boundaries.3 items+
Maintain a reconstructable onboarding pack.
- Implementation action
- Bundle identity, authority, KYB, beneficial ownership, PEP and sanctions screening, risk, approvals, privacy records and exceptions under stable identifiers.
- Evidence to retain
- Complete sampled onboarding pack and retrieval result.
- Primary citation
- Operational control supporting Cabinet Resolution 134/2025, Articles 7-16 and 25
Maintain a reconstructable reporting and sanctions pack.
- Implementation action
- Link transactions, alerts, analysis, timing, report, acknowledgement, supplements, freeze actions, authority communications and access logs.
- Evidence to retain
- Complete sampled case pack and controlled access log.
- Primary citation
- Operational control supporting Cabinet Resolution 134/2025, Articles 17-19 and Cabinet Decision 74/2020
Maintain a regulator-scoped launch pack.
- Implementation action
- Record activity and location classification, every licence, current legal sources, goAML readiness, ownership filing, sanctions subscription, privacy analysis, vendor controls and validation before launch and on material change.
- Evidence to retain
- Signed launch pack, source register, regulator map, uncertainty log, tests and approvals.
- Primary citation
- Official sources listed below
Primary-source register
15 sources used for this checklist
Use these links to verify the underlying legislation, regulator guidance, reporting procedures and international status statements.
- Federal Decree-Law No. 10 of 2025 on AML/CFT/CPFCentral Bank of the UAE Rulebook · Primary legislation
- Cabinet Resolution No. 134 of 2025 - Executive RegulationsCentral Bank of the UAE Rulebook · Official binding regulation
- UAE FIU goAML services registrationUAE Financial Intelligence Unit · Official reporting service
- Cabinet Decision No. 109 of 2023 on beneficial-owner proceduresMinistry of Economy and Tourism · Official binding decision
- Federal AML and beneficial-ownership legislation repositoryMinistry of Economy and Tourism · Official legislation repository
- Targeted financial sanctions implementationExecutive Office for Control and Non-Proliferation · Official sanctions guidance
- Federal Decree-Law No. 45 of 2021 on personal data protectionUAE Legislation · Primary legislation
- Cabinet Resolution No. 55 of 2026 - KYC Digital Platform RegulationsUAE Legislation · Official binding regulation
- Retail Payment Services and Card Schemes RegulationCentral Bank of the UAE Rulebook · Official regulation
- Payment Token Services RegulationCentral Bank of the UAE Rulebook · Official regulation
- UAE third enhanced follow-up reportMENAFATF · Authoritative regional assessment
- FATF February 2024 plenary outcome and UAE removalFATF · Authoritative status record
- FATF jurisdictions under increased monitoring - 19 June 2026FATF · Authoritative current status
- FATF high-risk jurisdictions subject to a call for action - 19 June 2026FATF · Authoritative current status
- United Nations Security Council consolidated sanctions listUnited Nations · Authoritative sanctions list
Direct answers
United Arab Emirates KYC, KYB and AML questions
Who receives suspicious transaction reports?+
The UAE Financial Intelligence Unit. Reporting entities register through the FIU service and submit the approved report type through goAML under the correct supervisory body.
When must suspicion be reported?+
Without delay when suspicion or reasonable grounds concern a transaction, attempted transaction or funds connected with crime, regardless of value. Do not wait for proof or a monetary threshold.
What occasional-transaction CDD thresholds apply?+
For financial institutions, AED 55,000 for a single or linked occasional transaction and AED 3,500 for an occasional wire. For VASPs, AED 3,500 for a single or linked occasional transaction. Relationship, suspicion and doubtful-data triggers apply separately.
How is AML beneficial ownership determined?+
Identify natural persons ultimately owning, alone or jointly, 25% or more; if ownership does not resolve the beneficial owner, identify control by other means, then the relevant senior-management person or persons.
How long are AML records retained?+
At least five years. Cabinet Resolution 134/2025 applies record-specific triggers and, for CDD and investigation material, calculates from the most recent applicable event.
What happens on a sanctions match?+
Screen the UAE Local Terrorist List and UN list, freeze a confirmed match without delay and prior notice, prohibit making funds or services available and make the required report through the current Executive Office and supervisory route.
Which regulator covers payment or virtual-asset activity?+
It depends on the product and location. CBUAE regulates retail payments, stored value and payment-token services; SCA, VARA, DFSA and FSRA may govern other virtual-asset or financial activity. Obtain a written perimeter analysis before launch.
Is the UAE on a FATF public list?+
No. FATF removed the UAE from increased monitoring in February 2024, and it was absent from both FATF public lists dated 19 June 2026. This is not a low-risk classification.
What is the national KYC Digital Platform?+
Federal Decree-Law 30/2024 and Cabinet Resolution 55/2026 establish an active platform framework for persons handling KYC data or issuing KYC reports. Confirm the entity's platform role, required data, access and operational onboarding with the competent authority.
Which privacy law applies?+
Federal Decree-Law 45/2021 applies subject to exclusions. DIFC, ADGM, health and credit data can fall under separate regimes. Confirm the perimeter and current executive rules before biometric or cross-border processing.
Research and review method
VOVE ID Compliance Research maps the regulatory perimeter, translates obligations into operational controls, links each material claim to a source and records the date and version of every review.
General regulatory information, not legal advice or a licence determination. Reviewed as applicable on 14 September 2026. Confirm official Arabic text, later amendments, supervisory circulars, goAML report types, company-registrar procedures, data-protection executive regulations and the exact CBUAE, SCA, VARA, DFSA or FSRA perimeter with the competent authority and qualified UAE counsel before launch.