The Grey List Is Gone. The Compliance Pressure Has Intensified.
On 23 February 2024, the UAE achieved what many considered its most important regulatory milestone in a decade: removal from the Financial Action Task Force’s grey list — the “Jurisdictions under Increased Monitoring” list — where it had been placed in March 2022 due to strategic deficiencies in its Anti-Money Laundering and Counter-Terrorism Financing (AML/CFT) framework.
The relief was real. The UAE’s removal from the grey list improved its global reputation, eased correspondent banking relationships, and signalled to international investors that the country’s financial system had been fundamentally strengthened.
But here is what many UAE business owners misunderstood about this milestone: removal from the grey list did not mean the end of AML pressure. It marked the beginning of a permanent, elevated compliance standard.
In 2026, the UAE faces its next FATF mutual evaluation — scheduled to begin in June 2026. In preparation, the UAE Central Bank has ramped up its enforcement efforts against non-compliant financial institutions, issuing nearly AED 350 million in fines in recent months for breaches of AML and CTF regulations. The UAE has enacted a new AML law. Inspections of Designated Non-Financial Businesses and Professions (DNFBPs) have intensified across all sectors. And enforcement activity — not just legislation — is what the FATF evaluators will examine in June.
If your UAE business falls within the scope of AML regulations and you have not reviewed your compliance framework since 2022 or 2023, you are operating at significant risk in 2026. This guide from HAS Business Bureau gives you everything you need to understand what has changed, what is required, and how to build a compliance framework that is genuinely fit for purpose.
The UAE’s AML Journey: From Grey List to Global Standard (2022–2026)
To understand what is required in 2026, it helps to understand how the UAE got here.
The Grey List (March 2022)
The FATF placed the UAE on its grey list in March 2022, citing strategic deficiencies in its AML/CFT system. Key criticism included: insufficient enforcement of existing laws, inadequate oversight of DNFBPs, weak beneficial ownership transparency, and limited financial intelligence unit capacity.
The Reform Programme (2022–2024)
The UAE’s response was comprehensive and fast-moving. Major reforms included:
- Establishment of the Executive Office to Combat Money Laundering and Terrorist Financing — a new coordinating body with direct accountability to the highest levels of government
- New specialist court to prosecute financial crimes
- Strengthened DNFBP supervision by the Ministry of Economy, with dedicated AML inspections and penalty enforcement
- Intensified enforcement activity — including the suspension of licences of 32 local gold refineries between July and October 2024 for 256 violations
- New AML and CTF guidelines for financial institutions and DNFBPs
- Enhanced FIU (Financial Intelligence Unit) resources and the expansion of goAML reporting
- New and amended legislation to strengthen the legal framework
Removal from the Grey List (February 2024)
On 23 February 2024, the UAE was removed from the Financial Action Task Force’s list of “Jurisdictions under Increased Monitoring”. This decision highlights the country’s commitment to strengthening its global financial reputation, having worked closely with both public and private sectors, particularly in banking and non-financial businesses, to strengthen regulations and combat financial crimes.
EU High-Risk List Removal (July 2025)
In a further milestone, on 9 July 2025, the European Parliament voted not to oppose the European Commission’s decision to remove the UAE from its high-risk AML list. This was a significant step for UAE businesses with EU trading relationships, as EU financial institutions are required to apply enhanced due diligence to transactions from high-risk jurisdictions.
The New AML Law (2025) and 2026 FATF Evaluation
The UAE enacted a new AML law in late 2025, incorporating new offences for proliferation financing and digital/virtual asset activities. The UAE’s next mutual evaluation by the FATF is scheduled for June 2026. It is anticipated that the UAE will continue to prioritise AML/CFT governance in 2025 and 2026, particularly in light of the upcoming FATF assessment, including regulatory agencies continuing to take a strong posture toward enforcement activities.
This is the regulatory environment your UAE business is operating in right now.
Who Must Comply with UAE AML Regulations in 2026?
AML compliance obligations in the UAE apply to two broad categories:
Financial Institutions (FIs)
Banks, exchange houses, insurance companies, investment firms, and other regulated financial services entities supervised by the Central Bank of the UAE, the SCA, or the Insurance Authority.
Designated Non-Financial Businesses and Professions (DNFBPs)
This category captures many businesses that do not think of themselves as part of the financial system:
Real estate agents and brokers — When involved in transactions for the purchase or sale of real property (not pure rental management).
Dealers in precious metals and stones — Gold dealers, jewellery retailers, diamond traders, and similar businesses. This category has faced the most visible enforcement, with 32 gold refineries having their licences suspended in 2024.
Lawyers, notaries, and legal professionals — When conducting designated activities including: managing client funds, creating or managing companies, buying or selling property, managing bank accounts, or providing general advice to facilitate financial transactions.
Accountants and auditors — When preparing, executing, or advising on financial transactions, managing client funds, or providing company formation services.
Corporate Service Providers (CSPs) — Businesses that form companies, provide registered office addresses, act as nominee directors, or manage corporate structures for clients.
Trust and company service providers — Businesses providing trustee, director, or shareholder services.
Virtual Asset Service Providers (VASPs) — Crypto exchanges, NFT platforms, virtual asset wallet providers, and related businesses. This is a rapidly growing category with intensified regulatory oversight in 2026.
Real Estate Developers — Developers selling real property directly to purchasers have been brought under AML supervision, reflecting the UAE’s position as a major property investment market.
Does this apply to free zone companies? Yes. UAE AML obligations apply regardless of whether a business is incorporated on the mainland or in a commercial free zone. If your business activity falls within a DNFBP category, you must comply. This applies to Meydan Free Zone, IFZA, JAFZA, SPC, and all other commercial free zones (DIFC and ADGM have their own parallel frameworks).
The Core AML Compliance Obligations: 2026 Update
1. goAML Portal Registration
All DNFBPs must register on the goAML portal operated by the UAE Financial Intelligence Unit (FIU). This portal is the mechanism for filing Suspicious Transaction Reports (STRs) and Suspicious Activity Reports (SARs).
Registration is mandatory. Failure to register is a regulatory violation in its own right, regardless of whether you have any suspicious transactions to report.
How to register: goaml.uae.gov.ae
2. Appoint a Money Laundering Reporting Officer (MLRO)
Every covered business must designate a Money Laundering Reporting Officer — a senior individual with specific AML responsibilities including:
- Receiving internal suspicious activity reports from staff
- Evaluating those reports and deciding whether to file an STR
- Filing STRs on goAML when required
- Maintaining AML records and documentation
- Serving as the AML point of contact for regulatory authorities
For small businesses, the MLRO is typically the owner or a senior director. For larger businesses, it should be a qualified individual with AML training and authority to make reporting decisions.
3. Enterprise-Wide Risk Assessment (EWRA)
The Enterprise-Wide Risk Assessment — also called the Business-Wide Risk Assessment (BWRA) — is a documented analysis of the money laundering and terrorist financing risks your business faces. It must assess:
- Customer risk — Who are your clients? Are any high-risk (PEPs, high-risk jurisdictions, unusual structures)?
- Product/service risk — Which of your products or services are most vulnerable to AML abuse?
- Geographic risk — Do you transact with clients from high-risk countries?
- Transaction risk — What is the volume, frequency, and nature of your transactions?
- Delivery channel risk — Are transactions conducted face-to-face or through remote/digital channels?
The EWRA must be reviewed and updated at minimum annually, and whenever there is a material change to the business.
2026 update: Under Cabinet Resolution No. 134 of 2025, DNFBPs must specifically implement Enhanced Due Diligence (EDD) measures for customers from countries appearing on the FATF grey list and black list, and update their EDD procedures whenever FATF updates its lists. As of early 2026, FATF updates its lists three times per year.
4. AML Policy, Procedures, and Controls Manual
Every covered business must maintain a written AML Policy and Procedures Manual that documents:
- Customer Due Diligence (CDD) procedures — who, when, what
- Enhanced Due Diligence (EDD) triggers and procedures
- Simplified Due Diligence (SDD) criteria (where applicable)
- Sanctions screening procedures and tools
- Internal suspicious activity reporting procedures
- STR/SAR filing procedures
- Staff training requirements and schedule
- Record-keeping policy
- The MLRO’s role and escalation process
The Ministry of Economy’s AML inspection process examines this document first. A generic template that does not reflect your actual business activities, customer types, and risk profile is treated as non-compliant.
5. Customer Due Diligence (CDD)
Standard CDD must be applied to all new clients and at appropriate intervals for existing clients:
- Verify the client’s identity (passport, Emirates ID, trade licence)
- Verify the identity of the UBO (see our UBO Registration Dubai guide)
- Understand the nature and purpose of the business relationship
- Assess whether the client’s transaction profile is consistent with their stated business
Enhanced Due Diligence (EDD) is mandatory for:
- Politically Exposed Persons (PEPs) — including family members and close associates
- Clients from FATF grey list or black list jurisdictions
- Clients with complex or opaque ownership structures
- High-value transactions that seem inconsistent with the client’s stated profile
- Clients where the source of funds cannot be readily explained
Ongoing monitoring is required for all clients — not just at onboarding. Transaction patterns that change significantly, or that become inconsistent with the established profile, must trigger a CDD review.
6. Sanctions Screening
Every covered UAE business must screen clients, transactions, and counterparties against:
- UAE Local Terrorist Designation List (published by the UAE Cabinet — check moec.gov.ae)
- UN Security Council Sanctions Lists (updated via un.org/securitycouncil/sanctions)
- OFAC (US Treasury) — for businesses with USD transactions or US-connected relationships
- EU and UK Sanctions Lists — for businesses with European relationships
- FATF High-Risk Jurisdictions Lists — updated three times per year
Screening must be conducted at client onboarding and on an ongoing basis as lists are updated. Manual screening of a large client base against regularly updated lists is challenging — most businesses use software-based screening tools. HAS Business Bureau can advise on cost-appropriate screening solutions for your business size.
7. Suspicious Transaction Reporting (STR/SAR)
When your business identifies a transaction or activity that raises a suspicion of money laundering, terrorist financing, or sanctions violation, you must file a report on goAML within 35 business days of forming the suspicion (or immediately if you believe a transaction is imminent).
The “tipping off” prohibition: It is a criminal offence under UAE AML law to alert the client that a report has been or may be filed. This means that once you decide to file an STR, you must not discuss your suspicion with the client, delay a transaction in a way that alerts them, or take any action that would signal your concern.
What triggers an STR? Common red flags include:
- Unusual payment patterns (overpayment then refund requests, round-number transactions)
- Inconsistency between stated business activity and actual transactions
- Client using multiple entities or accounts to move funds
- Client reluctant to provide standard identification documents
- Transactions involving jurisdictions on FATF high-risk lists
- Requests for unusual payment methods (cash, cryptocurrency in non-VASP context)
- UBO structures that cannot be verified
8. Staff Training
All relevant employees must receive AML training covering:
- How to recognise suspicious activity
- The internal reporting process (to the MLRO)
- Legal consequences of non-compliance (personal liability risk)
- Current red flags in your specific sector
Training must be documented (date, attendees, content covered) and delivered at minimum annually. New hires must receive AML training before handling client-facing activities.
9. Record-Keeping
AML records — CDD documents, transaction records, internal reports, STR decisions (including decisions not to file) — must be maintained for a minimum of 5 years from the end of the business relationship or the date of the transaction.
Electronic records are acceptable provided they are secure, retrievable, and accessible to authorities within a reasonable timeframe.
What the Ministry of Economy AML Inspection Examines
The UAE Ministry of Economy conducts AML compliance inspections of DNFBPs. Based on reported inspection findings, inspectors typically examine:
Documentation: Does the AML Policy manual exist? Is it current? Does it reflect the actual business?
EWRA: Is there a current, documented risk assessment? Is it specific to the business, not generic?
CDD files: For a sample of clients, are identity documents on file? Is UBO information verified? Are EDD records available for high-risk clients?
Sanctions screening: Is there evidence that sanctions screening is being conducted? Against which lists? How frequently?
STR records: Is the MLRO appointed? Are there records of internal reports received and decisions made? Has the business filed any STRs on goAML?
Training records: Is there evidence of AML training for relevant staff?
Businesses that fail an inspection face penalties, remediation requirements, and enhanced ongoing monitoring. The most serious cases have resulted in licence suspension. A voluntary compliance review before inspection is always preferable to a forced remediation after one.
The New AML Law (2025): What Changed
The UAE’s new AML legislation enacted in late 2025 introduced several key changes:
Proliferation financing offences — New criminal offences specifically targeting the financing of the proliferation of weapons of mass destruction (WMDs), aligning with FATF’s expanded mandate.
Virtual assets and digital systems — Expanded provisions specifically targeting illicit activities involving digital systems and virtual assets, particularly in terrorist financing.
Updated DNFBP obligations — Refined requirements for CDD, EDD, and record-keeping, with specific provisions for higher-risk client categories.
Stronger enforcement tools — New powers for the Executive Office to Combat Money Laundering and for the Ministry of Economy to conduct investigations and issue penalties.
For businesses operating in virtual assets, digital commerce, or real estate, the practical impact of these changes is significant. HAS Business Bureau’s compliance specialists can advise on how the new law affects your specific business.
AML Compliance Costs: What It Actually Takes
Many UAE SMEs delay AML compliance because they are unsure what it costs. Here is a realistic guide:
| AML Compliance Component | Approximate Cost (AED, one-time) | Annual Maintenance (AED) |
|---|---|---|
| goAML registration | Free | Free |
| EWRA preparation | 3,000 – 8,000 | 2,000 – 4,000 (annual review) |
| AML Policy Manual drafting | 5,000 – 15,000 | 2,000 – 5,000 (updates) |
| CDD framework and templates | 2,000 – 5,000 | Minimal |
| Sanctions screening software | 0 – 5,000 | 3,000 – 15,000/year |
| Staff AML training | 1,000 – 3,000 | 1,000 – 3,000/year |
| Total (small DNFBP) | 11,000 – 36,000 | 8,000 – 27,000/year |
Compare this to the cost of non-compliance: AED 100,000 in fines, licence suspension, and banking disruption. The compliance investment is the obvious choice.
HAS Business Bureau provides bundled AML compliance packages for UAE DNFBPs at predictable monthly retainer rates — covering the full compliance framework, annual reviews, and ongoing advisory support.
Your 2026 AML Compliance Action Plan
If you are a UAE DNFBP that has not comprehensively reviewed its AML compliance since before the 2024–2025 reforms, here is your priority action plan:
Immediate (this month):
- Confirm your goAML registration is active and credentials are accessible
- Verify your MLRO is still employed and appropriately briefed
- Check whether your AML Policy Manual references the current legislation (including 2025 amendments)
Short-term (next 30 days):
- Conduct an updated EWRA reflecting your current client base and transaction profile
- Review CDD files for your top 20 clients — are they complete and current?
- Verify that your sanctions screening is being conducted against all required lists
- Schedule AML training for all relevant staff
Medium-term (next 90 days):
- Update your AML Policy Manual to reflect 2025 legislative changes
- Implement (or upgrade) your sanctions screening process
- Conduct a full review of all client CDD files
- Document your STR decision-making records for the past 12 months
How HAS Business Bureau Supports Your AML Compliance
HAS Business Bureau’s compliance team provides end-to-end AML support for UAE DNFBPs:
- goAML registration and MLRO designation support
- EWRA preparation — business-specific, not generic templates
- AML Policy Manual drafting — tailored to your activities and risk profile
- CDD framework design — templates, checklists, and procedures
- Sanctions screening setup — tool selection and process design
- Staff AML training — delivered in-house or remotely, with documentation
- Annual AML compliance reviews — updating policies, re-assessing risks
- STR filing support — when suspicious activity is identified
- Ministry of Economy inspection readiness — pre-inspection gap analysis and remediation
- Integration with UBO, ESR, VAT, and Corporate Tax compliance
Our Business Taxation & Compliance service manages AML compliance as part of an integrated regulatory framework — so it connects properly with your UBO register, your CT reporting, and your ongoing bookkeeping.
Frequently Asked Questions
Does the UAE’s removal from the FATF grey list mean AML rules have relaxed? No. The removal reflects that the UAE has met FATF standards, but those standards are now the permanent baseline. The upcoming June 2026 FATF evaluation means enforcement is intensifying, not relaxing. Businesses that were non-compliant before grey list removal and have not updated their frameworks are at higher risk now, not lower.
What is the difference between an STR and an SAR? A Suspicious Transaction Report (STR) is filed when a specific transaction triggers suspicion of money laundering or terrorist financing. A Suspicious Activity Report (SAR) is filed when a pattern of behaviour or activity — even without a specific transaction — raises concern. Both are filed via the goAML portal.
My business is small — do I still need a full AML programme? If your business falls within a DNFBP category, size does not exempt you. A sole-practitioner accountant, a small gold jewellery retailer, or a one-person corporate services provider must comply with the full AML framework. The depth and complexity of the framework should be proportionate to your risk profile, but the core obligations are non-negotiable.
How often must I update my AML policy? At minimum annually, and whenever there is a material change to your business or the regulatory framework. The 2025 AML law amendments, the updated FATF lists, and new Cabinet Resolutions issued in 2024–2025 all require policy reviews for most UAE DNFBPs.
Can HAS Business Bureau file STRs on my behalf? We can advise on whether an STR should be filed and assist with the drafting and submission process via goAML. The decision to file must be made by your MLRO — this is a legal decision that cannot be fully delegated to a third party, but we provide expert guidance throughout.
Conclusion: The Post-Grey List Environment Demands Real Compliance
The UAE’s exit from the FATF grey list in February 2024 was a landmark achievement — but it transformed compliance from a “catch-up” exercise into a permanent, performance standard that will be evaluated again in June 2026. The UAE Central Bank has issued hundreds of millions of dirhams in AML fines. The Ministry of Economy is actively inspecting DNFBPs. Banks are more rigorous in their KYC than at any previous point.
For UAE businesses that fall within the DNFBP framework — accountants, lawyers, real estate agents, corporate service providers, precious metals dealers, and virtual asset businesses — the question is not whether to comply, but whether your compliance is actually fit for the 2026 standard.
Contact HAS Business Bureau today for an AML compliance health check. We will review your current framework, identify the gaps, and build a remediation plan that gets you to full compliance before a regulator finds the gaps first.
📞 +971 58 526 4004 | 📧 info@hasbusiness.ai 📍 Meydan Grandstand, 6th Floor, Nad Al Sheba, Dubai, UAE
Related Reading:
- UBO Registration Dubai: Is Your Company Non-Compliant? (2026 Checklist)
- UAE Corporate Tax 2026: What Every Business Owner Must Know Before Filing
- VAT Registration in UAE: Complete 2026 Guide
- BPO Services UAE: How Business Process Outsourcing Is Transforming Dubai Companies
- Management Audit Dubai: What It Is, Why It Matters & How to Get One
