AML personal liability UAE 2026

AML Personal Liability UAE 2026 Is No Longer a Theoretical Risk: Here Is the Proof

AML personal liability UAE 2026 became a documented reality on 24 June 2026 when the Central Bank of the UAE separately fined the Head of Compliance and MLRO of a foreign bank branch AED 300,000 personally for failure to fulfil his responsibilities independently of the AED 20 million institutional fine issued to the bank itself.

Table of Contents

This is not a legal warning from a law firm. This is an enforcement action published and reported across Arabian Business, Gulf News, The National, and Khaleej Times in which an individual compliance officer was personally fined by a UAE regulator for failing to do his job. The corporate entity was fined. The individual was also fined. Separately. Simultaneously. Publicly.

For every CEO, CFO, general manager, board member, and MLRO at a UAE-regulated business, whether a bank, exchange house, real estate agency, gold trading firm, accounting firm, or corporate service provider, this is the moment that changes the compliance conversation from “what does our company need to do?” to “what am I personally responsible for?”

This guide explains AML personal liability UAE 2026 in plain language: what Article 27(5) of Federal Decree-Law No. 10 of 2025 actually says, who is captured under the definition of senior management, what triggers individual liability, what the penalties are, and exactly how directors, managers, and MLROs can protect themselves.

For the full details of the June 2026 CBUAE enforcement action, see our CBUAE AML Fine 2026 analysis. For the complete explanation of Federal Decree-Law No. 10 of 2025, see our UAE AML Law 2025 Guide.

What Is AML Personal Liability in UAE 2026?

AML personal liability UAE 2026 is the legal exposure of individual managers, directors, board members, and compliance officers to personal criminal prosecution, fines, and imprisonment for AML/CFT/CPF failures, independently of whether the company itself is also penalised.

Under Federal Decree-Law No. 10 of 2025, AML personal liability in UAE operates at two levels simultaneously:

Corporate liability under Article 27(1):

Legal persons, companies and other entities whose representatives, directors, or agents commit offences such as money laundering, terrorism financing, or proliferation financing face fines ranging from AED 5 million to AED 100 million, or an amount equivalent to the criminal property involved.

Individual personal liability under Article 27(5):

Any individual responsible for the actual management of a legal person may be punished by imprisonment, a fine, or both, if it is proven that they were aware of the offence and that its commission resulted from their breach of duty.

These two forms of liability are independent. Article 27(1) and Article 27(5) operate the corporate fine simultaneously, and the individual fines are not alternatives. The June 2026 CBUAE enforcement action demonstrates this in practice: AED 20 million to the company and AED 300,000 to the MLRO personally on the same day.

This is the fundamental shift that senior management AML liability UAE 2026 represents. Previously, corporate liability shielded individuals; in most cases, fines went to the company, not the person. Under Federal Decree-Law No. 10 of 2025, that shield has been removed.

Who Is “Senior Management” Under UAE AML Law 2026?

Senior management under UAE AML Law 2026 is defined broadly in Cabinet Resolution 134 of 2025 as those with authority to take strategic or executive decisions affecting risk management, compliance policies, and operational governance, including CEOs, general managers, and board members.

This is a deliberately wide definition. It captures:

Chief Executive Officers (CEOs) and General Managers

The person ultimately responsible for the institution’s operations bears AML personal liability UAE 2026 for failures in the AML/CFT/CPF framework under their leadership. A CEO who fails to ensure adequate AML controls are in place, funded, and operational carries individual exposure under Article 27(5).

Chief Financial Officers (CFOs)

AML liability CEO CFO UAE 2026 applies where a CFO’s decisions over budgets, resource allocation, or financial controls contribute to AML compliance failures. A CFO who defunds the compliance function or overrides compliance recommendations carries individual exposure.

Board Members and Directors

Director AML liability UAE 2026 applies to any board member who approves AML policies, oversees compliance programmes, or receives AML risk reports. The regulations require that AML policies, controls, and procedures be approved by senior management, making board approval a specific, documented obligation that creates traceable individual accountability.

Money Laundering Reporting Officers (MLROs) and Heads of Compliance

MLRO personal liability UAE 2026 is the most directly demonstrated category following the June 2026 CBUAE enforcement action. The MLRO is the individual with the specific day-to-day responsibility for the AML/CFT compliance programme and is therefore the individual most directly in the line of fire when controls fail.

See also  AML Compliance for Law Firms and Legal Consultants in UAE 2026: The Complete Guide

Anyone With Real Influence Over How the Business Is Run

The Greenberg Traurig analysis of the UAE AML framework is explicit: the senior management definition captures not only formal directors but anyone who has real influence over how the business is run. A de facto manager, someone who exercises executive authority without a formal title, is within the personal liability perimeter.

The critical implication: AML individual accountability UAE does not require a formal board resolution or a specific title. If you exercise real decision-making authority over the AML compliance framework, you are within the scope of Article 27(5).

What Triggers AML Personal Liability in UAE 2026?

AML personal liability UAE 2026 is triggered by a specific combination of factors under Article 27(5) of Federal Decree-Law No. 10 of 2025. Understanding exactly what triggers individual liability and what does not is essential for every director and manager assessing their personal exposure.

Trigger 1: Awareness of the Offence

The primary trigger for AML personal criminal liability UAE 2026 under Article 27(5) is that the individual was aware of the AML offence, meaning they knew or should have known that the company’s AML controls were failing or that financial crime was occurring.

This is where the lower knowledge threshold in AML UAE 2025 changes becomes directly relevant to individual liability. Under the 2018 law, knowledge required proof of actual, subjective awareness. Under Federal Decree-Law No. 10 of 2025, knowledge of illicit intent can now be inferred from objective circumstances, a “should have known” standard of proof.

In practice, this means:

  • A CEO who receives board reports showing repeated AML inspection findings and takes no action has constructive knowledge of compliance failures
  • An MLRO who is aware that transaction monitoring alerts are not being investigated has knowledge of a control failure
  • A board member who approves a compliance budget insufficient to maintain required controls has knowledge of the resulting risk
  • A CFO who ignores documented compliance resource requests has knowledge of the consequence

The “should have known” AML standard UAE 2026 means that wilful blindness, choosing not to know, is no longer a defence. Circumstantial evidence AML UAE 2025 can establish knowledge where direct evidence does not exist.

Trigger 2: Breach of Duty

AML breach of duty UAE manager 2026 is the second required element under Article 27(5). The offence must have resulted from the individual’s breach of their duties and responsibilities.

A breach of duty in the AML context is the failure to fulfil the specific obligations that the individual’s role carries, as established by Federal Decree-Law No. 10 of 2025, Cabinet Resolution 134 of 2025, the CBUAE Rulebook, and the individual’s own job description and appointment terms.

For an MLRO, breach of duty includes: failure to maintain an effective AML/CFT programme, failure to investigate suspicious activity reports adequately, failure to file STRs when required, and failure to keep the AML framework current and operational.

For a CEO or general manager, breach of duty includes: failure to approve and fund adequate AML policies and procedures, failure to ensure the MLRO has the authority and resources to fulfil their role, and failure to act on reported compliance failures.

For a board member, breach of duty includes: failure to provide adequate oversight of the AML programme, failure to challenge management on AML risk reports, and approval of inadequate AML policies without sufficient scrutiny.

Trigger 3: AML Gross Negligence Liability UAE Directors

AML gross negligence liability UAE directors is an additional pathway to personal liability. The Kayrouz & Associates analysis notes that the standard is not negligence; it requires awareness and breach of duty, but the combination of lower evidentiary thresholds and circumstantial evidence means the practical risk is real.

This means that even where deliberate misconduct cannot be proven, a pattern of gross negligence or systemic failure to exercise the oversight and control that the role requires can establish the awareness and breach of duty elements necessary for Article 27(5) liability.

What Are the Penalties for AML Personal Liability in UAE 2026?

The penalties for AML personal liability UAE 2026 under Federal Decree-Law No. 10 of 2025 are severe and operate across multiple dimensions simultaneously.

Criminal Penalties Article 27(5)

Imprisonment: Individual managers and directors found liable under Article 27(5) face imprisonment; the duration depends on the nature and severity of the underlying offence, ranging from imprisonment terms applicable to the principal money laundering offence itself.

Personal fines: Individual fines are imposed separately from and in addition to corporate fines. The June 2026 AED 300,000 MLRO personal fine demonstrates the scale, and this was an administrative, not criminal, fine. Criminal fines under Article 27(5) can be significantly higher.

Both imprisonment and fine: Article 27(5) specifies that individuals may face “imprisonment, a fine, or both.” The combination of criminal prosecution and financial penalty is explicitly available.

Administrative Penalties Article 17

Under Article 17 of Federal Decree-Law No. 10 of 2025, regulators, including the CBUAE, Ministry of Economy, DFSA, and FSRA, can impose administrative penalties on individuals, including:

  • Administrative fines of up to AED 5 million on individuals
  • AML removal of board members: UAE directors can be formally removed from their positions
  • AML licence revocation UAE directors, the individual can be barred from holding management positions in regulated entities
  • Suspension or restriction of specific business activities
  • Requirement for independent monitor appointments at the expense of the institution

Reputational Consequences

The CBUAE publishes enforcement actions, including individual fines, on its website and through official statements. The June 2026 AED 300,000 MLRO fine was reported across multiple major UAE business publications. The reputational consequence of a named individual enforcement action in the UAE financial sector is severe and lasting.

AML Fines Scale: Corporate vs Individual

Liability Type

Legal Basis

Maximum Penalty

Corporate fine

Article 27(1)

AED 100 million or the value of the criminal property

Individual criminal fine

Article 27(5)

Significantly linked to the principal offence

Individual administrative fine

Article 17

AED 5 million

Board removal

Article 17

Permanent

Licence revocation

Article 17

Permanent

AML imprisonment of UAE managers

Article 27(5)

Varies by offence severity

What Is the Difference Between Corporate and Individual AML Liability in UAE?

The difference between corporate and individual AML liability in UAE is the most important distinction for senior managers to understand because it determines whether a compliance failure stays at the company level or crosses to personal exposure.

Corporate AML liability under Article 27(1) applies to the legal entity, the company, bank branch, or regulated business, for offences committed by its representatives, directors, or agents. Corporate fines range from AED 5 million to AED 100 million. The company pays. Shareholders bear the economic consequences.

Individual AML personal liability UAE 2026 under Article 27(5) applies to the specific person responsible for the actual management of the legal entity where that person was aware of the offence and where the offence resulted from their breach of duty. The individual pays personally. Imprisonment is possible. The personal consequence cannot be absorbed by the company.

Independent corporate criminal liability UAE means these two forms of liability are not mutually exclusive; they are triggered simultaneously and pursued in parallel. The June 2026 CBUAE enforcement action is the clearest available evidence: AED 20 million to the institution and AED 300,000 to the MLRO personally on the same day.

The practical consequence for senior management: a company’s AML compliance failure is not just a corporate risk to be managed by the legal or compliance team. It is a personal risk to career, finances, freedom, and reputation for every individual within the definition of senior management.

See also  The Future of goAML UAE: What to Expect in 2026

Concerned about your personal AML liability exposure as a director, manager, or MLRO?

AMLUAE provides specialist AML advisory support for senior management, including personal liability assessments, MLRO role formalisation, board briefings on AML obligations, and documentation of oversight activities to protect individual exposure.

Does AML Personal Liability Apply to Free Zone Directors in UAE?

AML personal liability for free zone directors UAE applies to all regulated entities regardless of free zone registration. Federal Decree-Law No. 10 of 2025 covers the entire UAE mainland, all free zones including DIFC, ADGM, JAFZA, DMCC, and Meydan.

The supervisory authority differs by free zone: DFSA for DIFC, FSRA for ADGM, Ministry of Economy for mainland DNFBPs, but the individual liability framework under Article 27(5) applies universally. A DIFC-based bank’s Head of Compliance carries the same personal liability exposure as a mainland bank’s MLRO under the federal framework.

For DIFC entities, the DFSA updated its AML Module in March 2026, explicitly aligning with Federal Decree-Law No. 10 of 2025, including its individual accountability provisions. The FSRA’s recent significant enforcement action against HAYVN group demonstrates that ADGM regulators are equally active in enforcing individual accountability.

What Must the Board of Directors Approve for AML Compliance in UAE?

The board of directors must approve specific AML compliance elements in UAE under Cabinet Resolution 134 of 2025, making board approval a documented obligation that creates direct individual accountability for every board member who signs off.

Under the regulations, the board must specifically:

Approve the AML/CFT/CPF policy and procedures

The board is required to formally approve the written AML policy. A board that approves an inadequate policy has documented its own breach of duty.

Approve the AML/CFT risk assessment

The business-wide risk assessment must be reported to and acknowledged by senior management. A board that receives a risk assessment without genuinely challenging or acting on it has accepted accountability for the identified risks.

Approve the MLRO appointment and mandate

The board must ensure the MLRO has the formal authority, independence, seniority, and resources to fulfil the role. Appointing an MLRO without adequate mandate is itself a breach of a board’s duty.

Oversee AML programme implementation

The regulations require ongoing oversight of business relationships in higher-risk scenarios. Senior management cannot delegate oversight responsibility and then claim ignorance when controls fail.

Ensure adequate resource allocation

The CBUAE’s April 2026 guidance is explicit that AML compliance must be genuinely operationally effective. A board that approves compliance budgets insufficient to maintain required controls has knowledge of the resulting risk.

How Can Directors Protect Themselves from AML Personal Liability in UAE?

Directors can protect themselves from AML personal liability in UAE by demonstrating active, documented, evidenced fulfilment of their AML oversight responsibilities, not passive receipt of compliance reports.

Here is the complete 10-step protection guide:

Step 1: Understand exactly what your role requires

Know which specific AML obligations are attached to your position under Federal Decree-Law No. 10 of 2025 and Cabinet Resolution 134 of 2025. If you are a CEO, your obligations differ from a board member’s or an MLRO’s. Document your understanding and have it reviewed by a qualified AML compliance consultant Dubai.

Step 2: Ensure your MLRO has formal authority and a documented mandate

The most common pathway to MLRO personal liability UAE 2026 is being appointed without adequate authority, independence, or resources. Ensure your MLRO has a formal appointment letter, a documented role description, a reporting line to senior management, and a budget sufficient to run an effective programme. Document all of this.

Step 3: Actively challenge AML risk reports, do not just receive them

AML personal liability UAE 2026 can be established where a senior manager receives reports of compliance failures and takes no action. Board members and CEOs must actively engage with AML risk reports, asking questions, demanding explanations, and requiring documented remediation plans. Evidence of active challenge is evidence of fulfilment of duty.

Step 4: Ensure previous inspection findings are genuinely remediated

AML breach of duty UAE manager 2026 is most easily established where a regulatory finding from the CBUAE, Ministry of Economy, or other authority was not adequately remediated before the next inspection. Treat every regulatory finding as a personal liability trigger and ensure remediation is genuine and evidenced, not cosmetic.

Step 5: Receive formal AML training appropriate to your role

AML training senior management UAE 2026 is not optional under Cabinet Resolution 134 of 2025 it is a documented obligation. Board members and senior executives must receive training appropriate to their oversight responsibilities. Document the date, content, and attendance. Untrained board members cannot credibly claim to have exercised adequate oversight.

Step 6: Approve AML policy and risk assessment formally and on record

Board AML policy approval UAE must be formally documented in board minutes, resolutions, or sign-off registers. A policy that was approved verbally without documentation is a policy that cannot be evidenced. Every approval must be in writing, with a date and the name of the approving individual.

Step 7: Commission an independent AML health check

The Kayrouz & Associates analysis recommends an independent compliance health check before the FATF evaluation period: “External validation of your AML framework is valuable evidence of effective oversight.” An independent review that identifies gaps and demonstrates they were addressed is powerful protection against an Article 27(5) breach of duty finding. For a related guide on what inspectors check, see our AML Inspection UAE 2026 guide.

Step 8: Ensure the MLRO has a clear escalation pathway to the board level

AML oversight responsibility UAE requires that suspicious activity, compliance failures, and regulatory findings have a documented escalation pathway from the MLRO to senior management and the board. If the MLRO identifies a problem and cannot get it heard at board level, both the MLRO and the board members who failed to provide that channel carry exposure.

Step 9: Document every significant AML decision you make or approve

AML wilful misconduct by UAE directors and AML gross negligence liability by UAE directors are both established through patterns of behaviour over time, not single incidents. Every significant AML decision approving a policy, authorising a budget, or receiving a risk report should be documented with the date, what was reviewed, and what decision was made. This documentation is your defence.

Step 10: Review your personal exposure with a specialist AML consultant regularly

AML personal liability UAE 2026 is not a fixed, static risk it evolves with regulatory changes, new enforcement actions, and changes in your institution’s risk profile. Akin Gump recommends senior management briefings on personal liability exposure as a specific action in response to the new UAE AML framework. Schedule an annual personal liability review with a specialist AML compliance consultant Dubai who understands the current enforcement environment.

The FATF Connection: Why Personal AML Liability Is Being Enforced Now

AML personal liability UAE 2026 is being actively enforced now for a specific reason: the FATF Fifth Round Mutual Evaluation. As Akin Gump noted: “As the next FATF Mutual Evaluation approaches in June 2026, it is evident that the UAE is focusing on a zero-tolerance approach across its regulators towards money laundering.”

FATF evaluates not just whether a country has adequate legislation, but also whether that legislation produces real deterrence. Individual accountability and personal criminal liability are specifically assessed by FATF as measures of whether a country’s AML framework deters financial crime at the level of individual decision-makers, not just institutions.

The UAE’s enforcement of AML individual accountability through the June 2026 CBUAE MLRO fine, the AED 350 million in institutional fines in 2025, and the accelerating pace of CBUAE AML enforcement 2026 collectively demonstrate to FATF assessors that UAE’s personal liability framework produces real outcomes. This enforcement trajectory is not temporary it reflects a fundamental shift in how UAE AML compliance is supervised and enforced.

See also  AML Compliance for Lawyers in UAE: A Complete Guide for Legal Professionals and Law Firms

As Norton Rose Fulbright observed, the “should have known” standard of proof reflects a change that aligns with FATF’s expectations around effective implementation of preventive measures and the role of senior management in setting and overseeing a risk-based compliance culture. Senior management AML liability UAE 2026 is the mechanism through which the UAE demonstrates to FATF that individual decision-makers bear real, personal consequences for AML failures.

What Senior Management Must Do Right Now: An Urgent Action List

Based on the June 2026 CBUAE enforcement action and the AML personal liability framework under Article 27(5), here is the urgent action list for every CEO, CFO, board member, and MLRO at a UAE-regulated entity:

MLROs: Formally document your role mandate, authority, reporting lines, and resource requirements. Ensure you have written evidence of every significant AML decision you have made. If you have identified control failures and escalated them without adequate response, document the escalation and the response or lack of it.

CEOs and General Managers: Commission an independent AML health check of your institution’s compliance framework. Ensure previous regulatory findings are genuinely remediated. Ensure your MLRO has the authority, resources, and independence required. Ensure AML policies are formally approved and documented at board level.

CFOs: Review AML compliance budget allocations against what the CBUAE’s April 2026 guidance and Cabinet Resolution 134 of 2025 require. If resource constraints are creating control gaps, document the issue and escalate it formally, and document the response.

Board Members: Ensure board minutes reflect active engagement with AML risk reports, questions asked, answers received, and remediation demanded. Ensure your formal approval of the AML policy and risk assessment is documented. Receive formal AML training appropriate to board-level oversight responsibility and document it.

How AMLUAE Helps Directors, Managers, and MLROs Manage AML Personal Liability UAE 2026

AML personal liability UAE 2026 is a personal risk that requires personal action, not just a corporate compliance exercise. At AMLUAE, we help the individuals within the senior management definition CEOs, CFOs, board members, and MLROs, document their AML oversight, formalise their authority and mandate, and build evidence of effective fulfilment of duty that protects against Article 27(5) exposure.

AML/CFT Health Check: An independent assessment of your AML framework against the CBUAE’s current enforcement standard. The output is documented evidence that you have actively commissioned and acted on an independent review of your compliance programme, powerful protection against a breach of duty finding.

AML/CFT Policy & Documentation: Produces formally documented, board-ready AML policies updated for Federal Decree-Law No. 10 of 2025 and Cabinet Resolution 134 of 2025 with board approval registers, MLRO mandate documentation, and escalation procedure records.

AML/CFT Risk Assessment Report: A formal, regulator-ready risk assessment that documents your institution’s AML risk profile, its controls, and the rationale for your risk-based decisions, the foundational document that evidences senior management’s understanding and oversight of AML risk.

In-House AML Compliance Setup: Builds your complete AML compliance function, including MLRO role formalisation, authority documentation, board approval workflows, and escalation procedures designed to evidence active, documented fulfilment of the obligations that Article 27(5) requires.

AML Training Program: Role-based AML training for CEOs, CFOs, board members, and MLROs covering AML personal liability UAE 2026, Article 27(5) obligations, the “should have known” standard, board approval requirements, and what the CBUAE’s current enforcement approach means for individual exposure. All training is formally documented with attendance records.

Regulatory Reporting Services: Manages all STR, SAR, and goAML portal filings, ensuring your MLRO’s reporting track record demonstrates active, quality engagement with the FIU. The MLRO’s STR filing history is one of the first things CBUAE examiners assess when evaluating whether the role has been effectively fulfilled.

AML Software: Real-time transaction monitoring, automated sanctions screening, and dynamic KYC tools that produce documented evidence of operational compliance effectiveness, the evidence that protects senior management from a “controls were inadequate in practice” finding.

We serve financial institutions, DNFBPs, VASPs, NPOs, and corporate service providers across Dubai, Abu Dhabi, Sharjah, Ras Al Khaimah, Fujairah, and all UAE free zones, including DIFC, ADGM, JAFZA, DMCC, and Meydan.

Whether you are a CEO assessing your exposure following the June 2026 CBUAE enforcement action, an MLRO formalising your role mandate and protection, a board member ensuring your AML approvals are documented, or a CFO reviewing compliance resource adequacy, AMLUAE provides the specialist advisory support to manage AML personal liability UAE 2026 in practice.

Frequently Asked Questions About AML Personal Liability UAE 2026

Can a director be personally liable for AML failures in UAE?

Yes, a director can be personally liable for AML failures in UAE under Article 27(5) of Federal Decree-Law No. 10 of 2025. Any individual responsible for the actual management of a legal entity may face imprisonment, a personal fine, or both, if they were aware of the AML offence and its commission resulted from their breach of duty. The June 2026 CBUAE enforcement action, in which an MLRO was personally fined AED 300,000, confirms this is actively enforced.

What is the AML personal liability standard for managers in UAE 2026?

The AML personal liability standard for managers in UAE 2026 under Article 27(5) requires two elements: the individual was aware of the AML offence, and the offence resulted from their breach of duty. Under Federal Decree-Law No. 10 of 2025, awareness can be established through objective circumstances, a "should have known" standard, meaning wilful blindness and gross negligence can satisfy the knowledge requirement alongside actual knowledge.

What is Article 27(5) of Federal Decree-Law No. 10 of 2025?

Article 27(5) of Federal Decree-Law No. 10 of 2025 is the provision that establishes personal criminal liability for individuals responsible for the actual management of a legal entity in UAE. It states that any such individual may be punished by imprisonment, a fine, or both if it is proven that they were aware of an AML/CFT/CPF offence and that its commission resulted from their breach of duty. It operates independently of Article 27(1) corporate liability; both can be applied simultaneously.

Can UAE regulators fine an individual MLRO or compliance officer?

Yes, UAE regulators can and do fine individual MLROs and compliance officers. On 24 June 2026, the CBUAE imposed a personal administrative fine of AED 300,000 on the Head of Compliance and MLRO of a foreign bank branch for failure to fulfil his responsibilities and position functions separately from the AED 20 million institutional fine. Under Article 17 of Federal Decree-Law No. 10 of 2025, individual administrative fines can reach AED 5 million, and individuals can be removed from their positions or barred from regulated roles.

What does "should have known" mean for AML liability in UAE?

The "should have known" standard for AML liability in UAE means that knowledge of an AML offence can be established through objective circumstances, not just proven through direct evidence of actual awareness. Under Federal Decree-Law No. 10 of 2025, a manager who receives reports of compliance failures, who oversees a function with documented control gaps, or who approves inadequate compliance budgets may be found to have known of the resulting risk even if they claim not to have been directly informed of the specific offence.

What are the penalties for senior management AML failures in UAE?

Penalties for senior management AML failures in UAE include criminal penalties under Article 27(5), imprisonment, personal fines, or both, and administrative penalties under Article 17 including individual fines of up to AED 5 million, removal from board or management positions, and prohibition from holding regulated roles. These are in addition to, not instead of, corporate fines of AED 5 million to AED 100 million under Article 27(1). The June 2026 CBUAE enforcement action imposed both a corporate fine and a personal MLRO fine simultaneously.

How can directors protect themselves from AML personal liability in UAE?

Directors can protect themselves from AML personal liability in UAE by actively and documentably fulfilling their AML oversight obligations, formally approving AML policies and risk assessments in writing, challenging and acting on AML risk reports, ensuring the MLRO has documented authority and adequate resources, commissioning independent AML health checks, receiving formal role-appropriate AML training, and documenting every significant AML decision they make or approve. Passive receipt of compliance reports without active engagement is insufficient protection under Article 27(5).

Does AML personal liability apply to free zone directors in UAE?

Yes, AML personal liability applies to free zone directors in UAE. Federal Decree-Law No. 10 of 2025 and its Article 27(5) personal liability provisions apply to all regulated entities in the UAE, regardless of free zone registration. DIFC directors are subject to the DFSA's updated AML Module (March 2026), which aligns with the federal personal liability framework. ADGM directors face equivalent obligations under the FSRA. All free zone business leaders carry the same individual AML liability exposure as mainland directors.

What must the board approve for AML compliance in UAE?

The board must formally approve the written AML/CFT/CPF policy and procedures, acknowledge the business-wide risk assessment, approve the MLRO's appointment and mandate, oversee the adequacy of AML resource allocation, and ensure ongoing active oversight of the compliance programme. Under Cabinet Resolution 134 of 2025, each of these approvals must be documented in board minutes, resolutions, or formal sign-off registers. Undocumented approvals cannot be evidenced during regulatory inspections or enforcement proceedings.

What is the difference between corporate and individual AML liability in UAE?

Corporate AML liability under Article 27(1) applies to the legal entity fines of AED 5 million to AED 100 million. Individual AML personal liability UAE 2026, under Article 27(5) applies to the specific person responsible for actual management: imprisonment, personal fines, or both. These are not alternatives; they are simultaneous. Independent corporate criminal liability UAE means that both the company fine and the individual fine are both imposed. The June 2026 CBUAE enforcement action is the clearest evidence: AED 20 million to the bank and AED 300,000 to the MLRO on the same day.