Regulatory Framework
The DIFC’s AML/CFT regime is primarily governed by the DIFC AML Regulations 2020, which came into force in 2020 and have been subject to subsequent amendments. These regulations establish the legal foundation for AML/CFT obligations in the DIFC, drawing from the FATF Recommendations as the international standard while reflecting the specific context of the DIFC’s role as an international financial centre.
The DFSA has issued the AML Module (AMI) within its Rulebook, which provides detailed guidance on how regulated firms must implement their AML/CFT obligations. The AMI module covers the full spectrum of requirements, from initial risk assessment through to ongoing monitoring and reporting.
The DIFC’s approach reflects a commitment to international standards while recognising the specific risk profile of a jurisdiction that attracts significant cross-border financial flows.
Supervisory Approach
The DFSA adopts a risk-based supervisory approach, with the intensity and focus of supervision calibrated to the risk profile of each firm. The DFSA conducts both off-site and on-site supervision, including thematic reviews of specific AML/CFT areas.
Key aspects of the DFSA’s supervisory approach include:
Assessment of the adequacy and effectiveness of a firm’s AML/CFT programme
Review of governance arrangements, including board and senior management oversight
Evaluation of the firm’s risk assessment and its alignment with the DFSA’s understanding of market risks
Testing of specific controls, including CDD processes, transaction monitoring, and STR filing
The DFSA has shown willingness to take enforcement action where firms fail to meet expectations, with public decisions demonstrating the consequences of inadequate AML/CFT frameworks.
Customer Due Diligence
The DFSA requires firms to apply risk-based customer due diligence measures. This encompasses:
Identification and verification: Obtaining sufficient information to establish the identity of the customer and, where relevant, beneficial owners. Verification must be conducted using reliable and independent documents, data, or information.
Purpose and nature: Understanding the intended nature and purpose of the business relationship or occasional transaction.
Ongoing monitoring: Maintaining adequate systems and processes to monitor the customer’s activities and transactions on an ongoing basis.
Risk classification: Assigning an appropriate risk rating to each customer and applying controls commensurate with that risk.
For beneficial ownership, firms must identify the individuals who ultimately own or control 25 percent or more of a legal entity, or who exercise significant control over the entity.
Enhanced Due Diligence
Enhanced due diligence measures apply to higher-risk customers, including:
Politically exposed persons (PEPs)
Customers from jurisdictions identified as high-risk
Complex ownership structures
Unusual or suspicious transactions
For PEPs, the DFSA requires senior management approval before establishing or continuing the business relationship, enhanced source of wealth and source of funds investigation, and enhanced ongoing monitoring.
DNFBP Obligations
The DIFC’s DNFBP regime applies to relevant entities operating within the free zone. While the DIFC’s primary focus is financial services, certain activities may bring entities within the DNFBP scope, particularly trust and company service providers and dealers in precious metals and stones operating within the DIFC.
DNFBPs operating in the DIFC must apply CDD measures for transactions above the applicable threshold and maintain appropriate records.
STR Filing and Reporting Obligations
The DFSA requires regulated firms to file suspicious activity reports (SARs), known as suspicious transaction reports (STRs) in many jurisdictions, when they have reasonable grounds to suspect that a transaction or activity may involve money laundering, terrorist financing, or another criminal offence.
Key reporting requirements include:
Prompt reporting to the DFSA
Maintenance of confidentiality to avoid tipping off
Retention of records related to suspicious activity
The DFSA coordinates with the UAE Financial Intelligence Unit (UAEFIP) on financial intelligence matters.
Sanctions Obligations
Firms operating in the DIFC must comply with applicable sanctions regimes, including United Nations Security Council sanctions as implemented in the UAE, and any specific DFSA sanctions requirements. This involves screening customers and counterparties against sanctions lists and implementing procedures to freeze assets or funds where required.
Training Requirements
The DFSA requires firms to ensure that relevant staff receive adequate training on AML/CFT obligations. Training must be appropriate to the roles and responsibilities of staff, with ongoing updates as the regulatory environment evolves. Records of training must be maintained.
AML/CFT Programme Requirements
The DFSA expects firms to maintain a comprehensive AML/CFT programme that includes:
A documented risk assessment
Policies and procedures approved by senior management
Appropriate systems and controls
Adequate training for staff
Independent audit or compliance review
Clear escalation procedures for suspicious activity
The programme must be proportionate to the nature, scale, and complexity of the firm’s activities.
Enforcement Trends
The DFSA has taken action against firms for AML/CFT failures, including cases involving inadequate CDD, failure to file STRs, and governance deficiencies. These enforcement actions serve as reminders that the DFSA expects firms to maintain robust frameworks throughout the lifecycle of their authorisation.
Recent DFSA decisions have addressed failures in transaction monitoring systems, insufficient documentation of risk assessments, and inadequate senior management oversight.
DIFC and Mainland UAE Key Differences
Organisations should note that the DIFC operates as a separate jurisdiction from the mainland UAE. While there are areas of alignment with UAE federal requirements, the DIFC has its own legal framework, regulatory authority, and enforcement regime.
The DIFC’s AML/CFT framework draws directly from international standards, and its supervisory approach reflects its positioning as an international financial centre. Firms operating in both the DIFC and mainland UAE must understand and comply with the requirements applicable in each jurisdiction.
Implications for Compliance Leaders
The DIFC’s AML/CFT framework demands robust programme design and sustained operational attention. Compliance functions must maintain the capability to identify and respond to financial crime risk, support the business objectives of the firm while managing risk, and demonstrate to the DFSA that the programme is effective.
For firms entering the DIFC or expanding their activities there, early planning for AML/CFT obligations is advisable. The authorisation process involves assessment of compliance capabilities, and ongoing supervisory expectations are significant.
Nexiant supports financial services firms in the DIFC with AI-assisted screening, transaction monitoring, and compliance solutions designed to meet DFSA requirements. Contact our team to discuss your needs.
DIFC AML Requirements: DFSA Compliance Guide for Financial Services Firms
Understand AML/CFT obligations in the Dubai International Financial Centre under the DFSA. Covers DIFC AML Regulations 2020, DNFBP requirements, CDD, PEP screening, and STR filing.
Speak to our teamThis article was accurate at the time of publication in August 2026 and is intended for general informational purposes only. It does not constitute legal, regulatory or compliance advice. Organisations should seek qualified professional guidance in relation to their specific obligations.




