Regulatory Framework Overview
DIFC operates under the DIFC AML Regulations 2020 , supervised by the Dubai Financial Services Authority (DFSA). The DIFC is a dedicated financial free zone with its own independent legal jurisdiction. The DFSA has enacted comprehensive AML rules that apply to all authorised firms operating within the Centre.
ADGM operates under the ADGM AML Regulations 2018 (as amended), supervised by the Financial Services Regulatory Authority (FSRA). ADGM is Abu Dhabi’s financial free zone and similarly has its own legal jurisdiction with comprehensive AML obligations.
Mainland UAE AML obligations arise from Federal Decree-Law No. 20/2018 on Anti-Money Laundering and Combating the Financing of Terrorism , together with Cabinet Decisions and guidance from the Securities and Commodities Authority (SCA) and the UAE Financial Intelligence Unit (UAEFIP). The Central Bank of the UAE supervises banks and exchange houses, while the SCA oversees capital markets participants.
The FATF Recommendations provide the international framework within which all three jurisdictions operate, but the specific implementation varies significantly across each.
Supervisory Architecture
The supervisory structure differs materially across the three environments.
In DIFC , the DFSA is the sole AML supervisor for all firms registered in the Centre. The DFSA conducts ongoing supervision through a combination of off-site monitoring and on-site examinations. Firms must register with the DFSA and maintain AML compliance programmes approved by the Authority.
In ADGM , the FSRA performs a similar function, supervising all financial services firms operating within the Abu Dhabi Global Market. The FSRA has powers to issue rules, conduct inspections and take enforcement action.
In mainland UAE , the supervisory structure is more fragmented. The Central Bank of the UAE supervises banks, exchange houses and finance companies. The SCA supervises capital markets participants including broker-dealers and investment funds. Commercial licences issued by Department of Economic Development offices in each emirate do not themselves confer AML regulatory status, but entities with SCA licences fall under SCA AML oversight.
This fragmented structure means that a firm with activities spanning DIFC, ADGM and mainland UAE may need to manage three separate supervisory relationships simultaneously.
DNFBP Obligations Across Jurisdictions
Designated Non-Financial Businesses and Professions (DNFBPs) face different AML obligations depending on which jurisdiction applies to their activities.
In DIFC , DNFBPs are subject to AML obligations under the DIFC AML Regulations where they carry on relevant activities. Real estate agents and developers, dealers in precious metals and stones, and lawyers and accountants providing certain services fall within scope.
In ADGM , the AML Regulations similarly capture DNFBP activities including real estate transactions, precious metals and stones dealings, and designated professional services.
The SCA issues specific guidance for DNFBPs operating in the securities and commodities space, while the Central Bank oversees DNFBP compliance in the banking sector context.
Beneficial Ownership Requirements
All three jurisdictions have strengthened beneficial ownership requirements, though with some procedural differences.
DIFC requires firms to identify and verify the beneficial owners of their customers. The DFSA expects firms to understand the ownership and control structure of legal entities and to take reasonable measures to identify persons who exercise significant control.
ADGM similarly requires identification of beneficial owners, with the FSRA expecting firms to understand ultimate beneficial ownership and control structures.
Mainland UAE introduced enhanced beneficial ownership requirements under the AML legislative framework. Cabinet Decision on beneficial ownership requires relevant entities to maintain information on ultimate beneficial owners and to make this information available to authorities. The UAE has also established beneficial ownership registers as part of its FATF action plan compliance.
A practical challenge for enterprise organisations is maintaining beneficial ownership information that satisfies each jurisdiction’s specific requirements simultaneously, particularly where group structures are complex.
STR Thresholds and Reporting
Suspicious Transaction Report (STR) obligations apply across all three jurisdictions, but the thresholds and mechanisms differ.
In DIFC , the DFSA AML module requires reporting of transactions that give rise to knowledge or suspicion of money laundering or terrorist financing. There is no specific monetary threshold for STR reporting, reflecting the risk-based approach. Firms must report to the DFSA, which coordinates with the UAE Financial Intelligence Unit.
In ADGM , the FSRA requires STR reporting where a firm knows, suspects or has reasonable grounds to suspect that a transaction involves money laundering or terrorist financing. Again, no specific threshold applies.
For firms operating across multiple jurisdictions, the obligation to file STRs in each jurisdiction where suspicion arises creates operational complexity. Timelines for reporting and the format of reports vary.
PEP Screening Across Jurisdictions
Politically Exposed Person (PEP) screening obligations are broadly consistent in principle across the three jurisdictions, reflecting FATF Recommendations, but practical implementation differs.
DIFC requires enhanced due diligence for PEPs, including senior foreign figures, their family members and close associates. The DFSA expects firms to have systems to identify PEPs and to apply enhanced monitoring.
ADGM similarly requires enhanced due diligence for PEPs with FSRA expectations on screening and ongoing monitoring.
Mainland UAE requires PEP screening and enhanced due diligence under the AML framework. The definition of PEP encompasses foreign PEPs, domestic PEPs and international organisation PEPs. Enhanced measures include senior management approval for the business relationship and enhanced ongoing monitoring.
For enterprise organisations, a global PEP screening programme must be calibrated to meet the most stringent applicable standard while remaining operationally viable.
Sanctions Obligations
Sanctions compliance is an area where the three jurisdictions intersect with federal and international obligations.
DIFC and ADGM both operate under United Nations Security Council sanctions obligations implemented through UAE federal law. Additionally, the UAE has implemented autonomous sanctions regimes. Both the DFSA and FSRA expect firms to maintain robust sanctions screening programmes.
Mainland UAE implements sanctions through the Central Bank and relevant federal authorities. Executive Office of the Committee for Drug Control and Money Laundering offences coordinates sanctions policy.
The UAE’s removal from the FATF Increased Monitoring list in February 2024 reflected significant progress in AML/CFT effectiveness, but sanctions compliance remains a high-priority supervisory area across all three jurisdictions.
Cross-Border Operational Challenges
For enterprise organisations operating across DIFC, ADGM and mainland UAE, several practical challenges emerge.
Regulatory multiplicity means that a single group compliance function must manage three distinct regulatory relationships, three sets of reporting obligations and three supervisory examination cycles.
Inconsistency in definitions and thresholds creates tension. Where DIFC and ADGM may have their own specific requirements on certain matters, mainland UAE applies Cabinet Decisions with different thresholds or definitions.
Information sharing between regulators has improved, with memoranda of understanding between the DFSA, FSRA and mainland UAE supervisory authorities. However, firms remain responsible for managing their own obligations across jurisdictions.
Staff training and competency standards must address the specific requirements of each jurisdiction where the firm operates.
Practical Implications for Compliance Programmes
Senior decision-makers responsible for financial crime programmes in the UAE should consider several practical steps.
First, map the regulatory exposure of each entity within the group to its applicable AML jurisdiction. Many groups assume that a single group AML policy applies universally without checking against each applicable regulatory framework.
Second, design multi-jurisdiction AML programmes that satisfy the most stringent common standard while documenting where specific jurisdictional calibrations are required. A risk-based approach should underpin this, with enhanced controls for higher-risk activities.
Third, maintain clear documentation of compliance with each applicable regulatory framework. Supervisory authorities across all three jurisdictions expect to see evidence of understanding and compliance with their specific requirements.
Fourth, invest in compliance infrastructure that can support multiple regulatory requirements without creating unsustainable operational overhead. Technology solutions that can apply different rule sets based on entity and jurisdiction offer significant advantages.
Conclusion
The UAE’s three AML environments present genuine complexity for enterprise organisations. The DIFC, ADGM and mainland UAE each have distinct supervisory authorities, legislative frameworks and operational requirements that must be navigated simultaneously.
For Chief Compliance Officers and Heads of Financial Crime, the key is to understand that a single group AML programme, while necessary, is not sufficient. Specific jurisdictional requirements must be identified, documented and implemented.
The investment in building a comprehensive multi-jurisdiction AML programme is substantial, but it is an investment that reduces regulatory risk and positions the organisation for sustainable operations across the UAE’s financial ecosystem.
DIFC vs ADGM vs Mainland UAE AML: A Compliance Comparison for 2026
A practical comparison of AML/CFT obligations across DIFC, ADGM and mainland UAE. Understand supervisory frameworks, DNFBP rules, STR thresholds and PEP screening differences.
Speak to our teamThis article was accurate at the time of publication in August 2026 and is intended for general informational purposes only. It does not constitute legal, regulatory or compliance advice. Organisations should seek qualified professional guidance in relation to their specific obligations.




