Insights AML
AML and CFT Meaning — What the Two Halves of the UAE Regime Actually Do
AML and CFT meaning for UAE businesses — AML stops criminal money looking clean, CFT stops money reaching terrorism, and both bind DNFBPs.
Key takeaways
- AML is anti-money laundering and CFT is countering the financing of terrorism — related duties, opposite money flows.
- AML looks backwards at where funds came from. CFT looks forwards at where funds are going, which is why small sums matter in CFT.
- The UAE statute is Federal Decree by Law No. 10 of 2025, covering money laundering, terrorist financing and proliferation financing together.
- Cabinet Decision No. 74 of 2020 sets the targeted financial sanctions framework: screen against the UN Consolidated List and the UAE Local Terrorist List.
- A confirmed match must be frozen without delay, within 24 hours, with a name-match report filed through goAML within five business days.
- Value thresholds do not switch CFT off. A pattern of small, ordinary-looking payments is the classic terrorist-financing signal.
Anyone who has renewed a UAE trade licence in the last two years has seen the phrase AML/CFT on a form, in a supervisor’s circular, or in the training slide deck a compliance consultant sent over. The AML half gets explained often enough. The CFT half almost never does, and it quietly gets treated as a subset of the same thing — which is where the trouble starts, because the two halves detect completely different behaviour and a programme tuned only for one will miss the other entirely.
AML and CFT meaning, in plain terms
AML stands for anti-money laundering and CFT for countering the financing of terrorism. AML targets money that came from a crime and is being made to look clean. CFT targets money — often lawfully earned — heading toward terrorism. UAE law regulates both under Federal Decree by Law No. 10 of 2025.
That is the definition. The rest of this page is about why the distinction changes what you actually have to build, and where UAE law puts the specific deadlines.
The one difference that changes everything
Think of the two regimes as following money in opposite directions.
Money laundering runs backwards. The funds already exist, they came from something illegal, and the whole exercise is disguising that origin. The UAE Government portal sets out the offence in Article 2 terms: a person commits money laundering where they know, or should reasonably suspect, that money comes from illegal activities and they intentionally convert or transfer it to hide its source, conceal details such as its origin or ownership, use or keep it, or help someone involved in the crime avoid detection or punishment. Every one of those verbs is about the past.
Terrorist financing runs forwards. The money may be perfectly clean at the point you see it. Somebody’s salary, a trading profit, a genuine-looking charitable donation. What makes it criminal is the destination. Nothing about the funds themselves is anomalous, and no amount of source-of-funds questioning will surface it, because the honest answer to “where did this come from” is boring and true.
This produces a detection problem that most compliance programmes are not designed for. Anti-money-laundering controls are built around size and anomaly — the transaction that does not fit the customer profile, the sudden wealth, the cash that arrives split into instalments to sit under a reporting threshold. Terrorist financing frequently involves sums small enough that none of those rules fire. A monitoring engine tuned entirely to large-value laundering will run clean for years while sitting on exactly the pattern CFT exists to catch.
The UAE AML/CFT framework as it stands in August 2026
The UAE rewrote its AML/CFT statute in 2025. If your policy document, your consultant’s deck or a template you downloaded still cites the 2018 framework, it is citing law that has been replaced. Worth knowing: not every government page has caught up either, and you will still find official pages citing the older instruments.
Everything in the table below was checked against the cited primary source on 3 August 2026.
| Item | Position | Primary source checked |
|---|---|---|
| Governing statute | Federal Decree by Law No. 10 of 2025, “Regarding Anti-Money Laundering, and Combating the Financing of Terrorism and Proliferation Financing” | u.ae; uaeiec.gov.ae |
| Money laundering offence | Article 2 — knowing, or having reason to reasonably suspect, that money comes from illegal activities, and intentionally converting, transferring, concealing, using, keeping, or assisting a perpetrator to avoid detection | u.ae |
| Implementing regulation | Cabinet Decision No. 134 of 2025 | uaeiec.gov.ae |
| Targeted financial sanctions framework | Cabinet Decision No. 74 of 2020, described as the primary framework for implementing targeted financial sanctions in the UAE | uaeiec.gov.ae |
| Lists that must be screened | The UN Consolidated List, maintained by the UN Security Council, and the UAE Local Terrorist List, maintained by the UAE Cabinet | uaeiec.gov.ae |
| Freezing deadline on a match | ”Without delay (within 24 hours)” of identifying a match | uaeiec.gov.ae |
| Name-match reporting deadline | Confirmed or partial name match report submitted through goAML “within five (5) business days from taking such measures” | uaeiec.gov.ae |
| Duration of a freeze | No time limit; remains valid until delisting or official cancellation by the Executive Office | uaeiec.gov.ae |
| National policy body | National Anti-Money Laundering and Combating Financing of Terrorism and Financing of Illegal Organizations Committee (NAMLCFTC) | u.ae |
| Reporting platform | goAML, developed by UNODC, used by the UAE Financial Intelligence Unit to receive, analyse and distribute suspicious transaction reports | u.ae; uaefiu.gov.ae |
| DNFBP categories supervised by the Ministry of Economy | Real estate brokers and agents; chartered accountants, accountants and auditors; dealers in precious metals and stones including jewellery stores; providers of company establishment or business administration services | moet.gov.ae |
| goAML registration | ”Registration of Designated Non-Financial Companies on goAML Portal is Mandatory”; failure to register “may result in severe penalties” | moet.gov.ae |
What the 2025 law penalises, and who imposes it
This is the section most AML pages get wrong, and the error is always the same shape: a criminal fine imposed by a court gets reprinted as though a supervisor could hand it to you at an inspection. The Decree by Law separates the two completely, and the difference is roughly twentyfold.
Administrative penalties sit in Chapter Seven. Article 16 gives the Supervisory Authority — the Central Bank for financial institutions, the Ministry of Economy and Tourism for the DNFBP categories — the power to run risk assessments and desk or field inspections. Article 17 sets out what it may then do. Criminal penalties sit in Chapter Twelve and belong to the Public Prosecution and the courts.
Every figure below is quoted from the official English text of Federal Decree by Law No. 10 of 2025 as published in the Central Bank of the UAE Rulebook, read on 4 August 2026.
| Article | Who imposes it | What it covers | The figure as written |
|---|---|---|---|
| Art 17(1)(b) | Supervisory Authority (administrative) | Any violation of the Decree by Law, its Executive Regulations or decisions issued under them | ”not less than ten thousand dirhams (AED 10,000) and not exceeding five million dirhams (AED 5,000,000) for each violation” |
| Art 17(1)(a) and (c)–(g) | Supervisory Authority | Non-financial sanctions available alongside or instead of a fine | Warning; prohibition from the sector; restriction of board and management powers; suspension or replacement of directors; suspension of the activity; revocation of the licence |
| Art 17(3) | Supervisory Authority | The same violation recurring within one year of the previous fine | An incremental administrative fine |
| Art 17(4) | Supervisory Authority | Publication of penalties | The authority “may publish the administrative penalties imposed by it through various media outlets” |
| Art 26(1) | Court (criminal) | Committing the money laundering offence | AED 100,000 to AED 5,000,000, or the value of the criminal property, whichever is greater, plus imprisonment of 1 to 10 years |
| Art 26(3) | Court (criminal) | Committing the terrorist financing offence | AED 1,000,000 to AED 10,000,000, or twice the value of the criminal property, whichever is greater, plus life or temporary imprisonment of at least 10 years |
| Art 26(4) | Court (criminal) | Committing the proliferation financing offence | AED 1,000,000 to AED 10,000,000, or twice the value, whichever is greater, plus temporary imprisonment |
| Art 27(1) | Court (criminal) | A legal person whose representatives, directors or agents commit the ML, TF or PF offence in its name | AED 5,000,000 to AED 100,000,000, or the value of the criminal property, whichever is greater |
| Art 28 | Court (criminal) | Deliberate or grossly negligent failure of the Article 18 duty to report a suspicious transaction to the Financial Intelligence Unit | AED 100,000 to AED 1,000,000, plus imprisonment |
| Art 29(1) | Court (criminal) | Tipping off — warning a customer that a report has been filed or an investigation is running, contrary to Article 24 | Not less than AED 50,000, plus imprisonment, or either penalty |
| Art 32 | Court (criminal) | Carrying on a financial activity, a DNFBP activity or a virtual asset activity without the licence or registration Article 20 requires | AED 200,000 to AED 10,000,000, plus imprisonment, or either penalty |
| Art 33 | Court (criminal) | Violating instructions issued by the Executive Office or another competent authority on targeted financial sanctions | Not less than AED 20,000, plus imprisonment, or either penalty |
Article 33 is the one to sit with, because it is the CFT half of the regime carrying a criminal charge rather than an administrative one. Ignoring a freezing instruction is not a filing failure that attracts a fine from your supervisor. It is an offence, and Article 37(4) goes further: where the Article 33 crime jeopardises the security or interests of the State, it is treated as an offence affecting the internal and external security of the State.
Two structural points sit underneath the table. Article 25 says the penalties apply “without prejudice to any more severe penalty provided for in any other law”, so nothing here is a ceiling on total exposure. And Article 39 leaves the detailed violations schedule to a Cabinet resolution, which is why the specific fine attached to a specific failure — a missing goAML registration, an absent risk assessment — is set administratively rather than in the Decree by Law itself. If you need the amount for one named violation, ask your supervisor for the schedule it applies. We are not going to guess it for you.
Targeted financial sanctions are where CFT actually bites
If you strip UAE CFT obligations down to the one thing a supervisor will test hardest, it is sanctions screening — and specifically what happens in the hours after a name matches.
The framework sits in Cabinet Decision No. 74 of 2020, and the Executive Office for Control and Non-Proliferation administers it. Two lists are in play. The UN Consolidated List comes from the UN Security Council. The UAE Local Terrorist List is domestic, and it is genuinely active rather than a historical artefact — the Executive Office has publicly announced designations, including 16 individuals and five entities over connections to Hezbollah.
The duties that follow a match are unusually specific for UAE compliance, which normally speaks in principles rather than clocks.
Freeze without delay, meaning within 24 hours. The Executive Office states that screening must be conducted immediately when the lists are updated, so that freezing measures can be implemented without delay, within 24 hours. That is not 24 working hours after somebody gets round to running the batch. It is why an annual or quarterly manual screening cycle structurally cannot meet the obligation.
File the name-match report within five business days. A confirmed or partial name match report goes through goAML within five business days from taking the measure. Partial matches count. The temptation to quietly dismiss a near-match and move on is exactly what the reporting duty removes.
Expect the freeze to last. Freezes have no time limit and remain valid until the designation is delisted or the Executive Office cancels the measure. You cannot release funds because a client is unhappy, or because a period has elapsed.
24 hours
Maximum time to implement freezing measures after identifying a match to the UN Consolidated List or the UAE Local Terrorist List, per the Executive Office for Control and Non-Proliferation
Screening tooling and process design matter more here than policy wording. Our comparison of PEP screening tools for UAE firms and the OFAC screening checklist for DNFBPs both go into what a workable cycle looks like, including the awkward question of who checks the alerts when the compliance officer is on leave.
A worked example where AML sees nothing and CFT sees plenty
Numbers make the divergence obvious. The following is an illustration constructed to show the mechanics, not a real client matter.
A Sharjah general trading company opened its account with an onboarding profile stating expected turnover of AED 40,000 a month. Over a 90-day review period, the expected activity is therefore AED 120,000. What the account actually shows is:
- 46 outbound transfers averaging AED 3,150 each, totalling AED 144,900, split across individual beneficiaries in four countries
- One payment of AED 18,000 to an organisation described as a charitable association, which does not appear on any register the firm can find
Total outflow is AED 162,900 against an expected AED 120,000 — about 36% above the stated profile.
Now run the two lenses over it.
The AML lens finds very little to grip. There is no cash. No single payment is large. Nothing was broken into instalments just under a threshold, because no individual transfer is anywhere near a threshold to begin with. The 36% variance against profile is the kind of drift a growing trading company produces legitimately every quarter. A monitoring rule set built around large-value laundering typologies would very plausibly produce no alert at all.
The CFT lens finds four problems at once. Forty-six transfers to individuals is not what a general trading company’s payment pattern looks like — suppliers are companies and there are rarely 46 of them. The beneficiaries have no evident commercial relationship to the licensed activity. The geographic spread has no stated business reason behind it. And a payment to an unregistered non-profit is the single most conventional terrorist-financing indicator there is, because non-profit channels are the classic route for moving small sums to a destination while giving the payment an innocent explanation.
The obligations that follow are concrete. Screen all 46 beneficiary names, the charitable association and its known officers against the UN Consolidated List and the UAE Local Terrorist List. If any name is a confirmed match, freeze within 24 hours and file the name-match report through goAML within five business days. Independently of any match, escalate the file to enhanced due diligence: establish the commercial rationale for individual beneficiaries, evidence the charitable payment, and get senior approval on record before the relationship continues. The tiering logic behind that decision is covered in our guide to SDD, CDD and EDD.
Note what is not required. Nobody has to close the account or refuse the payments. The duty is to understand the activity, document what you concluded and why, and report it if you cannot explain it. Plenty of files that open exactly like this one close normally, with a perfectly ordinary explanation on the record. What is not acceptable is not looking.
Where the two control sets diverge
Most of an AML/CFT programme is shared plumbing. Customer identification, beneficial ownership, record-keeping and reporting serve both halves. But four controls behave differently depending on which risk you are chasing.
Transaction monitoring thresholds. AML rules reward size and deviation. CFT rules need to catch fragmentation, velocity and destination concentration — patterns that are invisible to a value threshold. If every rule in your monitoring set has an amount in it, you have no CFT monitoring.
Source of funds versus destination of funds. AML asks where money came from and will accept a documented, lawful origin as reassurance. In CFT a lawful origin is not reassurance at all, because the funds usually are lawful. The equivalent CFT question is who ultimately receives this and what for.
Screening frequency. For AML purposes, screening at onboarding plus periodic review is defensible. For CFT it is not, because the lists change and the 24-hour freezing obligation attaches to the moment you could have identified the match. Screening has to run against list updates.
Sector risk weighting. Precious metals, real estate and complex corporate structures carry heavy AML risk. Money or value transfer services, charitable and non-profit flows, and cross-border remittance corridors carry heavy CFT risk. A firm can be low-risk on one axis and high on the other, and a single blended risk rating hides that.
What a working AML/CFT programme looks like
Strip out the acronyms and the obligations resolve into a short list of things that either happen or do not.
You register on goAML and keep the registration current. It is the Financial Intelligence Unit’s platform, built by the UN Office on Drugs and Crime, and you cannot file anything without it. The mechanics are in our goAML registration and login guide, and the annual renewal catches people out more often than the initial signup does.
You appoint a compliance officer with the seniority to stop a deal. The role carries personal accountability at inspection, and it is not a title you hand to whoever has capacity. What the role actually involves is set out in our MLRO job description and appointment letter guidance.
You write an enterprise-wide risk assessment that describes your business rather than a generic one, and it has to address terrorist financing as its own risk category rather than a footnote under laundering.
You run customer due diligence proportionate to risk, and you find the real human owner behind corporate customers. Beneficial ownership is a standalone filing duty as well — see UBO declaration and renewal.
You screen continuously and you keep the evidence of having screened, including the negative results.
You retain records and, more importantly, retain the reasoning. Inspectors are not looking for a passport photocopy. They are looking for what you concluded when you saw it.
Sector-specific builds differ in emphasis. We have separate walkthroughs for real estate agencies, gold and precious-metals dealers, auditors and accounting firms, corporate service providers and law firms.
The mistakes that show up at inspection
Almost nobody we review is knowingly moving criminal or terrorist money. The failures are administrative, and they repeat.
The CFT section is one paragraph. It says the firm screens against sanctions lists, and nothing else in the document is designed for terrorist-financing risk. An inspector reading it can tell in thirty seconds.
Screening was run at onboarding and never again. This is the single most common finding, and it is the one that directly conflicts with a 24-hour freezing obligation attached to list updates.
Partial matches are dismissed without a record. Somebody decided the name was probably a different person and moved on. There is nothing in the file showing the decision, the basis for it, or that anyone senior saw it.
The compliance officer cannot explain the firm’s own risk assessment. Inspectors do not read the manual and leave. They interview staff and pull files at random, which our Ministry of Economy inspection preparation playbook covers in detail.
Everything cites superseded law. Policies referencing only the 2018 framework signal that the document has not been touched since it was bought.
Which UAE authority actually supervises you
Firms often build an AML/CFT programme without knowing who will inspect it, which means they read the wrong circulars. The Decree by Law does not name one national regulator. Article 16 gives supervision to “the Supervisory Authority” for each sector, and in the UAE that resolves to several bodies with different guidance libraries.
Financial institutions — banks, exchange houses, finance companies, insurers and registered hawala providers — sit under the Central Bank of the UAE, whose Rulebook publishes sector guidance on transaction monitoring, sanctions screening, correspondent banking and politically exposed persons. The four DNFBP categories sit under the Ministry of Economy and Tourism. Firms licensed in the two common-law financial free zones answer to their own regulators instead: the Dubai Financial Services Authority in the DIFC, and the Financial Services Regulatory Authority in Abu Dhabi Global Market.
That split matters for a very ordinary reason. A Dubai property brokerage, a Sharjah gold trader and an Ajman corporate service provider all report suspicious transactions through the same goAML platform to the same Financial Intelligence Unit — but they are inspected by the Ministry of Economy and Tourism, against its guidance, on its cycle. A DIFC advisory firm doing similar work is inspected by the DFSA against a different rulebook. Neither the UAE Central Bank’s guidance nor the DFSA’s rulebook is the right primary reference for a mainland Dubai or Fujairah DNFBP, and using the wrong one is a common reason a manual reads impressively and still fails inspection.
The Executive Office for Control and Non-Proliferation sits across all of them on the CFT side. Its targeted financial sanctions instructions bind every regulated business in the UAE regardless of which authority licenses it, which is why the 24-hour freezing duty is the one obligation that reads identically in Abu Dhabi, Dubai and every northern emirate.
Where to start if this is new to you
Establish first whether your licensed activity puts you in a DNFBP category or under a financial-services regulator, because that determines who supervises you and which circulars bind you. Then check whether your goAML registration exists and is current. Then read your own risk assessment and ask whether a stranger could tell which company it describes.
Velmont Crest works as an accounting and compliance advisory practice supporting UAE businesses through exactly this work — AML compliance advisory, enterprise-wide risk assessments, policy and procedure drafting, screening process design, goAML support and inspection readiness. Our broader guides cover AML compliance in the UAE end to end, the plain-English meaning of AML on its own, and what an AML consulting engagement actually includes.
Accountability for the programme stays with the licensed business and its named officer, and that cannot be contracted out. What outside support does is build the thing properly, fit it to how the business really operates, and keep it current as the lists and the law move.
If you want your position reviewed, get a quote and tell us your licensed activity and which authority supervises you. That is usually enough to work out where you stand and what is missing.
Frequently asked questions
- What does AML CFT stand for?
- AML stands for anti-money laundering. CFT stands for countering the financing of terrorism, sometimes written as combating the financing of terrorism. They are usually written together as AML/CFT because supervisors regulate them as one compliance regime with shared controls. Increasingly you will see AML/CFT/CPF, where CPF is counter-proliferation financing — the funding of weapons of mass destruction programmes. The UAE's governing statute covers all three strands: Federal Decree by Law No. 10 of 2025 is titled Regarding Anti-Money Laundering, and Combating the Financing of Terrorism and Proliferation Financing.
- What is the difference between AML and CFT?
- They follow money in opposite directions. AML deals with funds that already came from a crime and are being disguised as legitimate income, so the question is where did this money come from. CFT deals with funds heading toward terrorism, and those funds are frequently lawful in origin — a salary, a business profit, a genuine donation — so the question is where is this money going and who ultimately receives it. That difference has a practical consequence. Large amounts and unexplained wealth drive AML detection. In CFT the amounts are often small and unremarkable, and the signal comes from the destination, the beneficiary and the shape of the payments rather than their size.
- What is CFT in banking?
- In banking, CFT is the set of controls a bank runs to avoid its payment rails being used to move funds to terrorism. In practice it is dominated by screening: every customer, beneficial owner, counterparty and payment beneficiary is checked against the UN Consolidated List and the UAE Local Terrorist List, at onboarding and on an ongoing basis. It also covers transaction monitoring rules tuned for fragmented low-value activity, correspondent banking checks, and scrutiny of non-profit and remittance flows. CFT is why a bank can query a modest transfer that no laundering rule would have flagged.
- Which UAE law covers AML and CFT?
- Federal Decree by Law No. 10 of 2025, titled Regarding Anti-Money Laundering, and Combating the Financing of Terrorism and Proliferation Financing, is the governing statute cited by the UAE Government portal at u.ae and by the Executive Office for Control and Non-Proliferation. Cabinet Decision No. 134 of 2025 is its implementing regulation. Targeted financial sanctions — the terrorist-list and freezing duties that carry most of the CFT weight — sit in Cabinet Decision No. 74 of 2020. Confirm the consolidated text and commencement dates at uaelegislation.gov.ae before relying on any of it in a filing.
- What is AML/CFT compliance in the UAE in practice?
- It is six recurring activities rather than a document. Register on goAML, the reporting platform the Financial Intelligence Unit runs. Appoint a named compliance officer who is senior enough to say no. Write an enterprise-wide risk assessment that describes your actual business. Run customer due diligence proportionate to risk, including finding the real beneficial owner. Screen names against the UN Consolidated List and the UAE Local Terrorist List continuously, not once. Keep the records and the reasoning. Inspections test whether these happen, not whether a manual exists.
- Who has to comply with AML/CFT rules in the UAE?
- Financial institutions supervised by the Central Bank, and a set of non-financial businesses called DNFBPs. The Ministry of Economy names four DNFBP categories it supervises: real estate brokers and agents, chartered accountants, accountants and auditors, dealers in precious metals and stones including jewellery stores, and providers of company establishment or business administration services. The Ministry states that registration of designated non-financial companies on the goAML portal is mandatory and that failure to register may result in severe penalties. Small headcount and low turnover are not exemptions.
- What is the UAE Local Terrorist List?
- It is the domestic designation list maintained under the UAE's targeted financial sanctions framework, published by the Executive Office for Control and Non-Proliferation. It sits alongside the UN Consolidated List maintained by the UN Security Council, and both must be screened. Designations are live rather than historical: the Executive Office has publicly announced additions, including a designation of 16 individuals and 5 entities over links to Hezbollah. Because the list changes, screening has to run on a cycle and on every update, not only when a new customer signs up.
- How quickly must a UAE business freeze funds after a sanctions match?
- Without delay, which the Executive Office for Control and Non-Proliferation states means within 24 hours of identifying a match to the UN Consolidated List or the UAE Local Terrorist List. A confirmed or partial name match report must then be submitted through goAML within five business days of taking that measure. The freeze itself has no expiry — it stays in place until the designation is removed or the Executive Office cancels the measure. This is one of the few genuinely clock-driven duties in UAE compliance, which is why screening that runs monthly by hand tends to fail it.
- Is KYC part of AML and CFT?
- Yes, but it is only one component. KYC — know your customer — is the identification and verification step: collecting the passport, Emirates ID, trade licence or constitutional documents and checking them against reliable independent evidence. Customer due diligence wraps KYC together with beneficial ownership, the purpose of the relationship and ongoing monitoring. AML/CFT is the whole regime that sits above both, adding the risk assessment, sanctions screening, staff training, record retention and suspicious transaction reporting. Firms that treat KYC as the full obligation usually fail on screening and monitoring.
- Does a small transaction size mean CFT rules do not apply?
- No, and assuming otherwise is the most common CFT design error we see. Terrorist financing does not need large sums, so a control set built around high-value transactions will not detect it. What matters instead is the pattern and the destination: many small transfers rather than one large one, beneficiaries with no commercial link to the business, payments to jurisdictions the customer has no stated reason to deal with, and funds routed through non-profit or informal value-transfer channels. Sanctions screening applies to every counterparty regardless of amount.
Filed under: AML, CFT, AML/CFT, Targeted Financial Sanctions, DNFBP, goAML, UAE
Published


