Every UAE Regulated Business Needs an AML/CFT Policy Document. Here Is What It Must Contain in 2026
AML CFT policy documentation UAE is the single most fundamental compliance deliverable any regulated business must have, and it is consistently the most common gap identified during Ministry of Economy inspections, CBUAE supervisory examinations, and DFSA and FSRA reviews in 2026.
Table of Contents
ToggleAn AML/CFT policy and procedures manual is a formal written document laying down the policies, controls, and procedures implementing UAE AML/CFT law requirements and related regulations. Under Federal Decree-Law No. 10 of 2025 and Cabinet Resolution 134 of 2025, this document must be approved by senior management, made accessible to compliance and relevant staff, independent AML auditors, and supervisory authorities, and kept up-to-date with the latest legal requirements at all times.
The enforcement environment makes this urgent. In H1 2025, the Ministry of Economy found 1,063 AML violations, a large proportion involving businesses with generic or outdated AML policy documents that did not reflect their actual operations. The CBUAE issued over AED 370 million in fines in 2025, including the June 2026 AED 20 million fine specifically citing “significant and repeated” failures in an institution’s AML compliance framework. Dubai’s VARA issued a formal warning to VASPs in 2026 citing “major weaknesses” in AML/CFT frameworks and mandating quarterly reviews. The Ministry of Justice issued Circular No. 1 of 2026 requiring law firms to update their AML policies dynamically whenever risk factors change, not just annually.
This guide explains exactly what AML CFT policy documentation UAE must include in 2026, who needs it, how to update it for Federal Decree-Law No. 10 of 2025, what happens if your policy is outdated during an inspection, and how AMLUAE produces customised, regulator-ready AML policy documents for every regulated business type in the UAE.
What Is an AML/CFT Policy and Procedures Document in UAE?
An AML/CFT policy and procedures document in UAE is a formal written compliance framework that translates the requirements of Federal Decree-Law No. 10 of 2025, Cabinet Resolution 134 of 2025, and applicable sector-specific guidance into the specific policies, controls, and procedures that govern how your business detects, prevents, and reports money laundering, terrorist financing, and proliferation financing.
It is the foundational document of your entire AML compliance programme. Every other compliance activity CDD, EDD, STR filing, training, sanctions screening must be governed by and consistent with what your AML policy document says. A business whose actual operations differ from what its AML policy describes is in breach of UAE AML law because the policy is not just a document; it is a binding internal framework that must reflect operational reality.
AML CFT policy documentation UAE is not optional for any regulated entity; it is a legal requirement under Cabinet Resolution 134 of 2025. Every financial institution, DNFBP, VASP, and NPO regulated for AML in the UAE must maintain a current, tailored, senior-management-approved AML policy document as a prerequisite for compliance, not as an end product of it.
What Is the Difference Between an AML Policy and AML Procedures in UAE?
The difference between an AML policy and AML procedures in UAE defines how the two documents work together and why both are required.
AML Policy sets out the principles, governance framework, and strategic approach your business takes to managing money laundering, terrorist financing, and proliferation financing risk. It defines what your business will and will not do, who is responsible for what, and what standards govern every aspect of the AML compliance programme. The AML policy is approved by senior management or the board.
AML Procedures set out the operational step-by-step instructions that implement the policy: exactly how CDD is conducted for different client types, exactly how STRs are escalated and filed, exactly how sanctions screening alerts are investigated, exactly how training is recorded. Procedures are more granular and operational than the policy.
AML Controls are the specific systems, tools, and mechanisms that enforce the procedures: transaction monitoring rules, screening systems, CDD checklists, escalation workflows.
Under Cabinet Resolution 134 of 2025, all three elements policy, procedures, and controls must be documented in your AML/CFT policy and procedures manual. The combined document is what regulators review during inspections, what the CBUAE assesses during supervisory examinations, and what the Ministry of Economy uses to evaluate DNFBP compliance readiness.
What Are the AML Policy Requirements Under Federal Decree-Law No. 10 of 2025?
The AML policy requirements under Federal Decree-Law No. 10 of 2025 and Cabinet Resolution 134 of 2025 set a materially higher standard than the previous 2018 framework. Here is exactly what the law requires of your AML CFT policy documentation UAE:
Senior management approval
The AML policy must be formally approved by senior management or the board. This approval must be documented in board minutes, resolutions, or formal sign-off registers. Verbal approval is insufficient.
Tailored to your specific business
The policy must reflect your actual business type, practice areas, client base, transaction types, geographic exposure, and risk profile. A generic downloaded template that does not reflect your operations is not compliant, and inspectors can identify a generic policy within minutes.
Current with the latest legal requirements
The policy must be kept up to date with Federal Decree-Law No. 10 of 2025, Cabinet Resolution 134 of 2025, and all applicable sector-specific guidance. A policy that predates October 2025 or December 2025, when the new law and implementing regulations came into force, requires immediate updating.
Accessible to relevant parties
The policy must be accessible to compliance and relevant staff, independent AML auditors, and supervisory authorities. A policy stored in a drawer that front-line staff has never seen does not satisfy the accessibility requirement.
Covering all mandatory elements
Cabinet Resolution 134 of 2025 specifies the minimum elements that every AML policy must cover. These are set out in full in the next section.
Including proliferation financing
Federal Decree-Law No. 10 of 2025 elevates proliferation financing to a standalone criminal offence. Every AML policy must now include a dedicated proliferation financing section covering risk assessment, controls, and reporting, not just AML and CFT.
Dynamically updated
Ministry of Justice Circular No. 1 of 2026 requires law firms to update their policies whenever relevant risk factors change. The CBUAE’s April 2026 guidance requires financial institutions to ensure their frameworks reflect current operational reality. The principle of dynamic updating now applies across all regulated sectors, not just legal professionals.
What Must an AML Policy Include in UAE 2026?
An AML policy must include fifteen mandatory elements in UAE 2026 under Cabinet Resolution 134 of 2025. Every AML CFT policy documentation UAE produced by AMLUAE covers all fifteen:
1. Governance Framework and Senior Management Responsibilities
The policy must define the governance structure for AML compliance, identifying the board’s oversight responsibilities, senior management’s implementation responsibilities, and the MLRO’s day-to-day operational responsibilities. It must establish clear lines of accountability and escalation who is responsible for what, and what happens when a compliance issue is identified.
2. Business-Wide Risk Assessment Methodology
The policy must describe the methodology your business uses to identify, assess, and rate money laundering, terrorist financing, and proliferation financing risks across your business activities, client types, transaction types, products, services, and geographic exposure. The risk assessment methodology section connects the policy to your formal AML/CFT risk assessment document.
3. Customer Due Diligence (CDD) Procedures
The policy must contain detailed CDD procedures covering the identification and verification of customer identity for different client types (individuals, companies, trusts, PEPs), the documentation required at different risk levels, the circumstances in which CDD must be updated or refreshed, and the procedures for ongoing monitoring of customer relationships.
4. Enhanced Due Diligence (EDD) Procedures
The policy must define the circumstances that trigger EDD, including clients from high-risk jurisdictions (covering the FATF grey list as of June 2026, including Iraq and Kuwait), PEPs and their associates, correspondent banking relationships, complex or unusual transactions, and high-value relationships. It must describe the additional documentation, approval requirements, and monitoring intensity that EDD relationships require.
5. Simplified CDD Procedures
Where simplified CDD is applied for lower-risk clients, the policy must document the eligibility criteria, the simplified verification process, and the rationale for treating those clients as lower risk. Simplified CDD cannot be applied by default; it requires documented justification.
6. Ultimate Beneficial Owner (UBO) Identification
The policy must include procedures for identifying and verifying the UBO of corporate clients the natural person or persons who ultimately own or control the entity. UBO identification failures are among the most common inspection findings; the policy must specify exactly how UBOs are identified, what documentation is required, and how UBO information is kept current.
7. Suspicious Transaction Reporting (STR) Procedures
The policy must define the complete STR process how suspicious activity is identified and escalated internally, how the MLRO evaluates internal reports, how the decision to file or not file an STR is made and documented, and how STRs are filed through the goAML portal. The policy must address the tipping-off prohibition, confirming that clients must not be informed of STR filings or related investigations.
8. Targeted Financial Sanctions (TFS) Screening Procedures
The policy must specify how TFS screening is conducted, what lists are screened (UAE, UN, OFAC, EU), at what points in the client lifecycle (onboarding, ongoing, transaction-level), and what the response procedure is when a match is identified. The policy must confirm that asset freezing and supervisory notification are the immediate response to a confirmed match.
9. Proliferation Financing (PF) Controls
Federal Decree-Law No. 10 of 2025 requires a dedicated proliferation financing section in every AML policy. This covers how the business identifies and assesses PF risk, including dual-use goods exposure, sanctioned jurisdiction connections, and arms-related counterparty risks, and what controls are applied to mitigate identified PF risks.
10. Record Retention Requirements
The policy must specify record retention periods, confirming the minimum five-year retention requirement under Article 25 of Cabinet Resolution 134 of 2025, the format and security standards for retained records, and the procedure for retrieving records during regulatory inspections. In light of the removal of the statute of limitations for AML crimes under Federal Decree-Law No. 10 of 2025, the policy should address extended retention for higher-risk transactions.
11. MLRO Roles and Responsibilities
The policy must define the MLRO’s specific responsibilities: receiving and evaluating internal suspicious activity reports, making STR filing decisions, overseeing the AML programme, reporting to senior management, and serving as the primary point of contact with regulators. The MLRO’s authority, independence, and resource requirements must be documented.
12. AML Training Obligations
The policy must specify the training requirements for all relevant staff the frequency of training, the content that must be covered for different roles, the documentation standards for training records, and the triggers for additional training (such as significant regulatory changes or the introduction of new products or services).
13. Ongoing Monitoring Procedures
The policy must define how ongoing monitoring of customer relationships and transactions is conducted, what monitoring systems are used, what the alert investigation process is, how monitoring intensity is calibrated to customer risk rating, and how monitoring findings are documented and escalated.
14. Internal Audit and Independent Review
The policy must provide for periodic independent review of the AML compliance programme, confirming that the AML framework is subject to independent audit, the frequency of such reviews, and how findings are reported to senior management and remediated.
15. New Products, Services, and Technology Risk Assessment
The policy must include a process for assessing the AML/CFT/CPF risks of new products, services, technologies, or business relationships before they are introduced, confirming that AML risk assessment is integrated into product and service development, not applied retrospectively.
Can I Use a Free AML Policy Template for My UAE Business?
No, using a free generic AML policy template for a UAE business is not compliant and is one of the most common causes of inspection failures in 2026.
Here is exactly why AML policy templates fail:
They are not tailored to your business type.
A template written for a generic DNFBP does not address the specific risk profile, client base, transaction types, and regulatory obligations of your business, whether you are a real estate agency, a gold trading firm, a law firm, an exchange house, a bank, or a VASP. Inspectors can identify a generic template within minutes of reviewing it.
They are not updated for Federal Decree-Law No. 10 of 2025.
Most free templates available online were written for the 2018 legislation. They do not cover the new proliferation financing standalone obligation, the lower knowledge threshold for prosecution, the personal liability provisions, the dynamic update requirement, or the new sector-specific guidance issued in 2026.
They do not reflect operational reality.
A template describes theoretical procedures, not the actual way your business conducts CDD, escalates suspicious activity, or screens sanctions lists. A policy that does not match your operations is not compliant, regardless of how well-written it is.
They create a dangerous compliance gap.
Staff who rely on a generic template for guidance will apply generic procedures, not the specific, risk-calibrated procedures that your business type and risk profile require. This creates a systemic gap between policy and practice that regulators identify and penalise.
They are a red flag to inspectors.
Ministry of Economy and CBUAE inspectors routinely identify generic templates. A generic policy signals to the inspector that your AML compliance culture is superficial, which immediately raises the intensity of scrutiny applied to every other element of your framework.
s your current AML policy a generic template that does not reflect your actual business?
AMLUAE produces fully customised AML CFT policy documentation UAE tailored to your specific business type, risk profile, client base, and regulatory obligations under Federal Decree-Law No. 10 of 2025.
What Happens if My AML Policy Is Outdated During a UAE Inspection?
An outdated AML policy during a UAE inspection is treated as a significant compliance failure, one of the most common findings identified by Ministry of Economy inspectors, CBUAE examiners, and DFSA and FSRA supervisors in 2026.
The consequences are specific and documented:
Immediate violation finding.
An AML policy that predates Federal Decree-Law No. 10 of 2025 (October 2025) or Cabinet Resolution 134 of 2025 (December 2025) is an immediate compliance violation; the policy does not reflect the current legal requirements, which are mandatory. The violation is recorded in your inspection report.
Administrative fine.
Under Article 17 of Federal Decree-Law No. 10 of 2025, an outdated or non-compliant AML policy attracts an administrative fine ranging from AED 50,000 to AED 5,000,000 depending on the severity and whether previous findings on the same issue have been identified.
Repeated failure designation.
If the same policy deficiency was identified in a previous inspection and has not been remediated, it is classified as a “repeated” failure, attracting significantly higher penalties. The CBUAE’s June 2026 AED 20 million fine was specifically for “significant and repeated” failures, demonstrating the direct consequence of not remediating documented compliance gaps.
Heightened scrutiny of the entire framework.
An outdated policy signals to inspectors that the business’s compliance culture is reactive rather than proactive, triggering deeper scrutiny of every other element of the AML framework. An inspection that might have been limited in scope can expand significantly when the policy is found to be outdated.
Supervisory risk profile escalation.
A policy finding is recorded in your permanent supervisory risk profile, meaning future inspections will be more frequent and more intense. For the full picture of what happens during an AML inspection, see our AML Inspection UAE 2026 guide.
How Often Should an AML Policy Be Updated in UAE?
An AML policy should be updated in UAE whenever material changes occur to the regulatory environment, the business’s operations, or its risk profile, and at a minimum annually. Under Federal Decree-Law No. 10 of 2025 and Cabinet Resolution 134 of 2025, the AML policy is a living document, not a static annual exercise.
Specific triggers that require immediate AML policy updates include:
Regulatory changes: New legislation, implementing regulations, supervisory guidance, or circulars that change your AML obligations. In 2026 alone, this includes Federal Decree-Law No. 10 of 2025, Cabinet Resolution 134 of 2025, the CBUAE’s April 2026 guidance package, Ministry of Justice Circulars No. 1–4 of 2026, VARA’s 2026 quarterly review mandate, and the June 2026 FATF grey list update.
FATF grey list changes: The FATF updates its grey list three times per year. Each update, including the addition of Kuwait in February 2026 and Iraq in June 2026, requires review of the country risk section of your AML policy.
Business changes: New products, services, client categories, geographic markets, or ownership structures change your risk profile and require policy updates to reflect the new risk landscape.
National Risk Assessment updates: The UAE’s National Risk Assessment is periodically updated. AML policies must reflect the current NRA findings as specifically required by VARA’s 2026 circular for VASPs and by Ministry of Justice Circular No. 1 of 2026 for law firms.
Inspection findings: When a regulator identifies a policy gap, the policy must be updated to address the finding before the next inspection.
At minimum annually: Regardless of whether any of the above triggers have occurred, the AML policy should be formally reviewed annually and the review outcome documented.
AML Policy Requirements by Sector What Your Business Specifically Needs
AML Policy for Banks and Financial Institutions UAE 2026
An AML policy for banks UAE 2026 must specifically address the CBUAE’s April 2026 guidance requirements covering real-time transaction monitoring with automated anomaly detection, dynamic CDD with ongoing reassessment, correspondent banking EDD, trade-based money laundering controls, and proliferation financing risk assessment. Banks that updated their policies for the 2018 framework but have not integrated the April 2026 CBUAE guidance are operating with a material compliance gap.
AML Policy for Real Estate Agents UAE 2026
An AML policy for real estate agents UAE 2026 must cover the specific DNFBP obligations of the property sector, including CDD on all transaction parties (not just the client), UBO verification for corporate buyers, Real Estate Activity Report (REAR) filing obligations through the goAML portal, and the enhanced scrutiny required for transactions involving clients connected to FATF grey-listed jurisdictions, including Kuwait and Iraq, following the 2026 updates.
AML Policy for Gold Traders UAE 2026
An AML policy for gold traders UAE 2026 must address the specific risk profile of Dealers in Precious Metals and Stones (DPMS), including cash transaction monitoring, cross-border supply chain counterparty due diligence, the proliferation financing risk assessment required for dual-use goods exposure, and the enhanced monitoring required for Iraq-connected counterparties following the June 2026 FATF grey list addition.
AML Policy for Law Firms UAE 2026
An AML policy for law firms UAE 2026 must comply with all four Ministry of Justice 2026 circulars covering the dynamic update obligation of Circular No. 1, the high-risk country update requirement of Circular No. 2, the institutional risk assessment obligation of Circular No. 3, and the targeted financial sanctions procedures required by Circular No. 4. For a comprehensive guide to law firm AML obligations, see our AML Compliance Law Firms UAE 2026 guide.
AML Policy for VASPs UAE 2026
An AML policy for VASPs UAE 2026 must reflect the full AML/CFT/CPF obligations of Federal Decree-Law No. 10 of 2025 for virtual asset service providers, including Travel Rule compliance, real-time sanctions screening, dynamic CDD for crypto wallet customers, and the VARA quarterly review mandate for business risk assessments. Following VARA’s 2026 warning citing “major weaknesses” in VASP AML frameworks, specifically around proliferation financing, targeted financial sanctions, and AI-related risks, every VASP operating in the UAE must ensure its AML policy is current and comprehensive.
AML Policy for Gaming Operators UAE 2026
An AML policy for gaming operators UAE 2026 must address the specific DNFBP obligations of GCGRA-licensed operators, including the AED 11,000 transaction threshold, the gaming-chip exemption nuance, player due diligence procedures, and the nine sector risks identified in the 2025 Commercial Gaming Policy Paper.
AML Policy for Corporate Service Providers UAE 2026
An AML policy for corporate service providers (CSPs) and company formation agents UAE 2026 must address the UBO identification obligations that are most commonly violated in Ministry of Economy inspections, specifically covering multi-layered ownership structures, nominee arrangements, and the verification procedures required for complex corporate clients.
AML Policy for Free Zone Companies UAE
An AML policy for free zone companies UAE must comply with the applicable supervisory framework: DFSA for DIFC, FSRA for ADGM, and the Ministry of Economy or CBUAE for other commercial free zones. DIFC-regulated entities must ensure their policies reflect the DFSA’s updated AML Module effective March 2026. ADGM-regulated entities must reflect the FSRA’s AML Rulebook. All other free zone businesses follow the federal framework under Federal Decree-Law No. 10 of 2025.
How Do I Write an AML Policy for My UAE Business?
Writing an AML policy for a UAE business in 2026 requires eight sequential steps, each building on the previous one. Here is the complete process:
Step 1: Confirm your regulatory category
Determine whether your business is a financial institution, DNFBP, VASP, or NPO under Federal Decree-Law No. 10 of 2025 and which supervisory authority governs your sector. The policy structure and content requirements differ by regulatory category.
Step 2: Conduct your business-wide risk assessment first
The AML policy must reflect your actual risk profile, which means your risk assessment must be completed before the policy is drafted, not after. The risk assessment identifies which risks are most relevant to your business, which client categories require enhanced scrutiny, and which transaction types need specific controls. The policy then translates these findings into operational procedures. For risk assessment support, see our AML/CFT Risk Assessment service.
Step 3: Map all regulatory requirements to your business
Review Federal Decree-Law No. 10 of 2025, Cabinet Resolution 134 of 2025, and the applicable sector-specific guidance for your industry the CBUAE’s April 2026 guidance for financial institutions, Ministry of Justice Circulars No. 1–4 for law firms, VARA’s quarterly review mandate for VASPs, and Ministry of Economy requirements for DNFBPs. Every regulatory requirement must be addressed explicitly in the policy.
Step 4: Draft the governance framework section
Define the board and senior management oversight responsibilities, the MLRO’s mandate and authority, and the escalation structure for compliance issues. This section establishes accountability, making clear who is responsible for what element of the AML programme.
Step 5: Draft all fifteen mandatory policy elements
Work through each of the fifteen mandatory elements listed in the previous section, tailoring each one to your specific business type, client base, and operational reality. Every procedure described in the policy must match how your business actually operates.
Step 6: Include sector-specific elements
Add the sector-specific sections relevant to your business: REAR reporting for real estate agents, Travel Rule procedures for VASPs, gaming chip threshold procedures for GCGRA operators, or trade-based money laundering controls for commodity traders.
Step 7: Obtain formal senior management approval
Present the completed policy to senior management or the board for formal approval. Document the approval in writing board minutes, resolution, or sign-off register with the date, the approving individuals, and a confirmation that the policy was reviewed before approval.
Step 8: Distribute and implement
Make the approved policy accessible to all relevant staff, the MLRO, independent auditors, and supervisory authorities. Train staff on the policy’s requirements. Establish the review schedule and trigger criteria to ensure the policy remains current.
What Company Can Help Me Write an AML Policy in Dubai UAE?
AMLUAE is the specialist AML compliance consultancy that writes AML policies for UAE businesses for every regulated sector, every business size, and every supervisory framework in the UAE.
AMLUAE’s AML CFT policy documentation UAE service is different from competitor offerings in five specific ways:
Updated for Federal Decree-Law No. 10 of 2025, not the 2018 framework
Every policy document AMLUAE produces is drafted against the current legal framework, Federal Decree-Law No. 10 of 2025 and Cabinet Resolution 134 of 2025, including the new proliferation financing standalone obligation, the dynamic update requirement, and the personal liability provisions. Competitors offering policies built for the 2018 framework are giving clients false assurance.
Tailored to your specific sector and risk profile
AMLUAE drafts different policies for different business types not a single template with name changes. A real estate agency policy differs from a gold trader policy, a bank policy differs from a VASP policy, and a law firm policy differs from a CSP policy. Every AMLUAE policy reflects the specific risk profile, client base, transaction types, and regulatory obligations of the client business.
Covers all mandatory elements plus sector-specific requirements
AMLUAE’s policies cover all fifteen mandatory elements under Cabinet Resolution 134 of 2025 plus any sector-specific requirements: REAR reporting for real estate, Travel Rule for VASPs, VARA quarterly review mandate, MoJ four circulars for law firms, CBUAE April 2026 guidance for banks.
Includes the dynamic update framework
Following Ministry of Justice Circular No. 1 of 2026 and the CBUAE’s April 2026 guidance, every AMLUAE policy includes a documented review schedule and trigger criteria, ensuring the policy is updated whenever material changes occur, not just on a fixed annual cycle.
Inspection-ready format
AMLUAE policies are structured in the format that Ministry of Economy, CBUAE, DFSA, and FSRA inspectors expect to find, with clear section headings, documented approval records, version control, and a review log that demonstrates active management of the compliance framework.
How Much Does AML Policy Documentation Cost in UAE?
The cost of AML CFT policy documentation UAE at AMLUAE depends on three factors: the regulatory category and complexity of your business, the number of entities and jurisdictions covered, and whether the policy is a standalone document or part of a broader compliance framework build.
AMLUAE offers flexible pricing structures for different business sizes and needs:
- SME DNFBPs: real estate agencies, gold traders, accounting firms, and legal consultancies benefit from streamlined policy documentation designed for businesses with straightforward risk profiles
- Larger institutions: banks, exchange houses, and fintech businesses require more comprehensive policy documentation covering the full CBUAE April 2026 guidance requirements
- Multi-entity groups: requiring policies for multiple regulated entities across different categories benefit from coordinated documentation with shared governance frameworks and entity-specific operational procedures
Contact AMLUAE for a tailored quote. The initial consultation is free with no obligation, and AMLUAE will confirm the scope, timeline, and cost before any engagement begins.
How Long Does It Take to Get an AML Policy Document in UAE?
How long it takes to get an AML policy document in UAE depends on the complexity of your business and the urgency of your requirement:
Business Type | Standard Timeline | Urgent Timeline |
Small DNFBP (real estate, gold trader, accountant) | 7–10 working days | 3–5 working days |
Mid-size DNFBP (law firm, CSP, larger real estate) | 10–15 working days | 5–7 working days |
Financial institution (exchange house, finance company) | 15–20 working days | 7–10 working days |
Bank or large financial institution | 20–30 working days | 10–15 working days |
VASP or gaming operator | 10–15 working days | 5–7 working days |
For businesses facing an imminent Ministry of Economy or CBUAE inspection, AMLUAE offers an accelerated policy documentation service, delivering a compliant, customised AML policy within 3 to 5 working days depending on the business type.
How AMLUAE Produces AML CFT Policy Documentation UAE for Every Regulated Business
AMLUAE is a specialist AML compliance consultancy dedicated exclusively to UAE AML/CFT/CPF compliance. Our AML CFT policy documentation UAE service is the most comprehensive available in the UAE market, covering every regulated sector, every supervisory framework, and every 2026 regulatory update.
What AMLUAE’s AML Policy Documentation Service Delivers:
A fully customised AML/CFT/CPF policy and procedures manual covering all fifteen mandatory elements under Cabinet Resolution 134 of 2025, tailored to your specific business type, regulatory category, risk profile, client base, and geographic exposure.
Sector-specific content for your industry, whether you need an AML policy for banks UAE updated for the CBUAE April 2026 guidance, an AML policy for real estate agents UAE covering REAR reporting, an AML policy for VASPs UAE reflecting VARA’s quarterly review mandate, an AML policy for law firms UAE compliant with all four MoJ 2026 circulars, or an AML policy for gold traders UAE covering DPMS-specific obligations.
A dynamic review framework including a documented review schedule, trigger criteria for immediate updates, and a version control log ensuring your policy remains current between formal review cycles.
Formal senior management approval documentation including a board-ready policy summary, a sign-off register, and documentation guidance to support the evidenced approval process required by Cabinet Resolution 134 of 2025.
Inspection-ready format structured in the format that Ministry of Economy, CBUAE, DFSA, and FSRA inspectors expect, with clear section headings, cross-references to relevant regulatory provisions, and a presentation that demonstrates genuine compliance engagement.
AML/CFT Policy & Documentation: The foundational service that every UAE regulated business needs as the starting point for AML compliance.
Connected services:
- AML/CFT Health Check: Assess your current policy before commissioning a new one
- AML/CFT Risk Assessment Report: The risk assessment your policy must be built on
- In-House AML Compliance Setup: Full framework build including policy, risk assessment, and all operational controls
- AML Training Program: Staff training on the policy your business has adopted
- Regulatory Reporting Services: goAML reporting aligned with your policy’s STR procedures
We serve financial institutions, DNFBPs, VASPs, NPOs, gaming operators, and corporate service providers across Dubai, Abu Dhabi, Sharjah, Ras Al Khaimah, Fujairah, and all UAE free zones including DIFC, ADGM, JAFZA, DMCC, and Meydan.
Whether your AML policy has never been written, was last updated for the 2018 law, does not reflect your current operations, or failed a recent regulatory inspection, AMLUAE produces the customised, current, inspection-ready AML CFT policy documentation UAE your business needs.
