UAE DFSA AML Requirements for Firms Operating in the Dubai International Financial Centre

The Dubai International Financial Centre operates as a self-regulating financial free zone with its own independent regulatory framework.

AML Guide  ·  August 2026  ·  GCC

The Dubai International Financial Centre operates as a self-regulating financial free zone with its own independent regulatory framework.

The DIFC AML Regulations 2020

The DIFC AML Regulations 2020, as amended, establish the primary legal framework for AML/CFT obligations within the Centre. These Regulations were substantially updated in 2020 to reflect evolved FATF standards and to strengthen the DIFC’s regulatory framework in response to the FATF mutual evaluation of the United Arab Emirates.

The Regulations impose obligations on Designated Non-Financial Businesses and Professions as well as financial institutions, creating a comprehensive framework that extends AML/CFT obligations beyond traditional financial services. The scope covers lawyers, accountants, trust and company service providers, family foundations, dealers in precious metals and stones and other designated categories.

FATF Recommendations inform the structure and content of the DIFC AML Regulations, but they are not directly applicable law within the DIFC. Firms must look to the Regulations themselves and the DFSA Rulebook for their specific obligations.

The DFSA Rulebook AML Module

The DFSA Rulebook AML Module translates the requirements of the DIFC AML Regulations into detailed operational obligations for authorised firms. The Module covers all aspects of a compliance programme, from customer due diligence through to suspicious transaction reporting and record-keeping.

The AML Module requires firms to implement a comprehensive AML/CFT programme that includes written policies and procedures, appropriate internal controls, risk assessment processes, ongoing employee training and an independent audit function. The DFSA expects these elements to be proportionate to the nature, scale and complexity of the firm’s activities.

Key operational requirements under the AML Module include customer identification and verification procedures, beneficial ownership identification, ongoing customer due diligence, enhanced due diligence for higher-risk relationships, suspicious activity monitoring and reporting, and transaction record-keeping for a minimum of six years.

Customer Due Diligence Standards

The DFSA CDD framework requires firms to identify and verify the identity of customers at the outset of a business relationship and on an ongoing basis throughout the relationship. The framework adopts a risk-based approach, requiring standard CDD for most customers and enhanced due diligence for higher-risk situations.

Standard CDD requires collection and verification of full name, date of birth, nationality, residential address, and for legal entities, evidence of incorporation, ownership structure and identification of beneficial owners. The AML Module defines beneficial owners as individuals who ultimately own or control twenty-five percent or more of a legal entity, or who exercise significant influence or control over its management.

Enhanced due diligence applies to relationships involving politically exposed persons, complex structures where the ownership or control chain is unclear, non-face-to-face relationships, correspondent banking and any other relationship assessed as presenting elevated risk. For PEP relationships, the AML Module requires senior management approval, robust source of wealth and funds investigation, and ongoing enhanced monitoring.

Ongoing monitoring is a continuous obligation. Firms must periodically review customer risk ratings, update customer information when circumstances change and ensure that transaction monitoring is calibrated to customer risk profiles.

Beneficial Ownership Requirements

The DIFC framework places significant emphasis on beneficial ownership identification and verification. Firms must identify the natural persons who ultimately own or control legal entities with which they do business, going beyond the legal ownership structure to understand the true controlling parties.

Where ownership or control is exercised through a chain of entities, firms must trace through to identify the natural persons at the ultimate beneficial ownership level. Where no natural person satisfies the ownership or control test, firms must identify individuals exercising significant control through other means and document the analysis.

The AML Module requires firms to verify beneficial ownership information to the same standard as customer identification. This presents practical challenges for complex corporate structures, and the DFSA expects firms to develop methodologies capable of addressing these challenges effectively.

PEP Screening and Sanctions

DFSA requirements for PEP screening extend throughout the customer lifecycle. Firms must screen customers and beneficial owners against PEP databases at account opening, on an ongoing basis through periodic rescreening and at any point where new information suggests a potential PEP connection.

The AML Module also requires firms to screen against sanctions lists, including United Nations Security Council sanctions as implemented in the UAE and any additional lists required by DFSA. Sanctions compliance requires integration with transaction processing systems to prevent violations.

Firms must establish clear escalation procedures for potential PEP or sanctions matches, including documented investigation procedures and escalation paths to appropriate senior management.

DNFBP Regime

The DIFC AML Regulations 2020 apply AML/CFT obligations to DNFBPs operating within the Centre. This extends the regulatory perimeter beyond financial institutions to capture activities that present elevated money laundering risk.

DNFBPs subject to the Regulations include trust and company service providers, lawyers, accountants, family foundations, dealers in precious metals and stones, and dealers in high-value goods where cash payments exceed prescribed thresholds. Each category faces specific obligations depending on the nature of activities conducted.

The DNFBP regime is designed to ensure that money laundering risks associated with these professions are appropriately mitigated. DNFBPs must implement CDD procedures, maintain records and report suspicious activities to the DFSA.

Reporting Obligations

Firms must report suspicious activities to the DFSA through the designated reporting mechanism. The obligation to report arises when a firm knows, suspects or has reasonable grounds to suspect that a transaction or activity involves money laundering or terrorist financing proceeds.

The DFSA has published guidance on what constitutes suspicious activity and how firms should approach the reporting obligation. Firms are expected to have monitoring systems capable of identifying patterns and anomalies that may give rise to suspicion and procedures for escalating potential concerns through appropriate governance channels.

DFSA Supervisory Approach

The DFSA employs a risk-based supervisory methodology, assessing the risk profile of each firm based on the nature of its activities, its customer base and its controls. Supervisory activities include ongoing monitoring through regulatory returns, themed reviews and on-site examinations.

The DFSA has indicated that it expects firms to take ownership of their AML/CFT obligations, treating compliance as an integral part of business operations rather than a regulatory exercise. This supervisory philosophy means that the DFSA scrutinises not just whether requirements are met in form but whether compliance programmes are effective in practice.

Comparison with Mainland UAE

The DIFC operates under a distinct regulatory framework from mainland UAE. While both frameworks are designed to meet FATF standards, the specific requirements, supervisory arrangements and enforcement mechanisms differ. Firms operating in both environments must understand these differences and implement compliance programmes that satisfy each applicable regime.

The UAE Central Bank supervises financial institutions in mainland UAE under a separate regulatory framework. The SCA serves as the competent authority for DNFBP supervision outside the DIFC. Firms with activities spanning both environments must navigate this jurisdictional complexity.

Implications for Compliance Professionals

Firms authorised by the DFSA face real obligations with real consequences for non-compliance. The enforcement record of the DFSA demonstrates willingness to take action against firms and individuals for AML/CFT failures.

Building an effective compliance programme requires investment in technology, people and processes. Screening systems, transaction monitoring, case management and reporting capabilities must all be fit for purpose under the AML Module requirements.

For enterprise risk leaders, the DIFC framework represents a sophisticated regulatory environment that rewards thoughtful compliance investment and penalises superficial approaches.

DIFC AML Regulations: DFSA Requirements for Financial Firms

A practical guide to DFSA AML/CFT obligations for firms in the DIFC. Understand the AML Module requirements, CDD standards, DNFBP regime and DFSA supervisory approach.

Speak to our team

This article was accurate at the time of publication in August 2026 and is intended for general informational purposes only. It does not constitute legal, regulatory or compliance advice. Organisations should seek qualified professional guidance in relation to their specific obligations.