Skip to content

Insights Compliance

AML Compliance in Abu Dhabi 2026 — What DNFBPs and ADGM Firms Actually Have to Do

AML compliance in Abu Dhabi for DNFBPs and FSRA-regulated ADGM firms: goAML registration, MLRO, sanctions screening, UBO checks and SAR reporting.

AML compliance in Abu Dhabi advisor reviewing DNFBP risk assessment and goAML registration for real estate brokerage and ADGM-registered entity
AML compliance in Abu Dhabi advisor reviewing DNFBP risk assessment and goAML registration for real estate brokerage and ADGM-registered entity Photo: Velmont Crest Editorial

Key takeaways

  1. DNFBP registration with the Ministry of Economy is mandatory for real estate brokers, dealers in precious metals/stones, auditors, accountants, tax consultants and corporate service providers
  2. goAML portal registration with the UAE Financial Intelligence Unit is required for all reporting entities — SARs and STRs file through goAML
  3. FSRA-regulated ADGM entities sit under the FSRA AML/CFT rulebook with risk-based KYC, ongoing monitoring and quarterly returns
  4. ADGM non-regulated entities carry their own AML obligations under the ADGM AML Rulebook administered by the Registration Authority
  5. Sanctions screening against UN, OFAC, UK HMT, EU and UAE Local Terrorist List is required at onboarding and on an ongoing basis
  6. Penalties for non-compliance reach up to AED 5,000,000 per breach under the federal AML/CFT framework, plus FSRA enforcement powers for ADGM-regulated firms

AML compliance in Abu Dhabi runs under three regimes that overlap. The federal AML/CFT framework — Federal Decree-Law No. 10 of 2025 and its executive regulations under Cabinet Decision No. 134 of 2025, which replaced the earlier Federal Decree-Law No. 20 of 2018 and Cabinet Decision No. 10 of 2019 in late 2025 — covers every reporting entity in the UAE. The Ministry of Economy and Tourism (MoET) and the Executive Office for Anti-Money Laundering and Countering the Financing of Terrorism run it for non-financial professions.

FSRA-regulated ADGM firms sit under the FSRA AML Rulebook with quarterly returns and on-site supervision. Non-regulated ADGM entities sit under the ADGM AML Rulebook, administered by the Registration Authority.

This guide is for MLROs, compliance officers, owners and operations leads at Abu Dhabi DNFBPs, ADGM-registered entities and small-to-mid financial firms who are building, reviewing or rebuilding an AML programme in 2026. It covers what the rules actually require, what supervisors actually inspect, what penalties have actually been imposed, and how we scope engagements for clients in the capital.

Why AML in Abu Dhabi reads differently

The federal framework is the same nationwide — anti-money laundering in the UAE runs on one law — so the differences below are about supervisors and sectors, not the underlying rules.

The first is ADGM. Abu Dhabi hosts it, which means FSRA-regulated banks, fund managers, broker-dealers, payment service providers, custodians and virtual asset service providers, all covered by the FSRA AML Rulebook with quarterly returns, on-site inspections and AML wrapped into capital-adequacy supervision. DIFC’s DFSA does the same thing in Dubai under different rule numbering.

Real estate looks different too. Abu Dhabi sees fewer property transactions than Dubai overall, but a much higher share are large commercial and institutional deals. Brokers and developers carry DNFBP AML obligations under federal rules and licensing duties from the Department of Municipalities and Transport.

The thresholds are worth being precise about, because they are widely misquoted. Article 3(2) of Cabinet Decision No. 134 of 2025 brings real-estate brokers and agents into scope “when concluding transactions or settlements on behalf of their customers in relation to the purchase or sale of real estate” — with no value threshold at all. The AED 55,000 figure is a different trigger, and it now does two separate jobs. In Article 3(3) it is the scope trigger for dealers in valuable metals and precious stones, on a single cash transaction or linked transactions.

In Article 7(2)(a) it is the customer due diligence threshold for occasional transactions — but that article now names Financial Institutions only, where the repealed Article 6(2) of Cabinet Decision No. 10 of 2019 applied it to Financial Institutions and DNFBPs alike. An Abu Dhabi DNFBP that reads its CDD duty off the AED 55,000 line is reading an article that no longer covers it. Its duty sits in Article 7(1): on commencing a business relationship, on suspicion of a crime, and where there are doubts about identification data already held.

Then there’s the gold trade, run through Madinat Zayed Souk and the Abu Dhabi Gold Souk. Dealers in precious metals and stones are federal DNFBPs with cash-transaction thresholds, SAR obligations and Ministry of Economy supervision.

And the government-related counterparties are a category of their own. SMEs supplying ADNOC, ADNEC, EGA, EDGE Group, Aldar, Mubadala portfolio companies or the Abu Dhabi government screen these as standard. They’re almost always low-risk, but “obviously fine” isn’t a defence on inspection day, so the screening still has to be documented.

AED 5,000,000

Upper-end federal AML penalty per breach for serious failures including dealing with sanctioned parties, failure to file SARs or systemic AML programme breakdown

Are you in scope? Two groups, one test

The federal AML regime defines reporting entities in two broad groups.

Financial Institutions

Banks, finance companies, exchange houses, insurance companies, securities firms and other financial institutions regulated by the UAE Central Bank, the Securities and Commodities Authority, the FSRA (in ADGM) or the DFSA (in DIFC). These entities sit under their primary regulator’s AML rulebook with the most intensive supervisory regime.

Designated Non-Financial Businesses and Professions (DNFBPs)

Per the federal AML/CFT executive regulations (Cabinet Decision No. 134 of 2025, which replaced Cabinet Decision No. 10 of 2019):

  • Real estate brokers and agents — any party involved in real estate transactions including brokerage, agency, valuation and developer sales activity
  • Dealers in precious metals and stones — gold, silver, platinum, diamonds, jewellery, gemstones; cash transactions above AED 55,000 trigger SAR consideration
  • Auditors and audit firms — including Ministry of Economy-accredited audit firms and ADGM Recognised Auditors
  • Accountants and accounting firms — including Velmont Crest and similar firms providing bookkeeping, financial reporting and accounting services
  • Tax consultants and tax agents — including FTA-registered tax agents
  • Corporate service providers — including company formation agents, registered agents and trust and company service providers
  • Lawyers and legal consultants — in specific activities including real estate transactions, management of client money, formation of companies, asset transfers and certain other activities
  • Trust and company service providers — including ADGM and DIFC TCSPs

Each DNFBP must register with the Ministry of Economy through the AML/CFT supervisory portal, appoint an MLRO, prepare a written AML risk assessment, implement KYC and CDD procedures, conduct ongoing sanctions screening, train staff annually, file SARs through goAML when warranted, and complete the annual AML/CFT supervisory return.

AML compliance in Abu Dhabi for real estate brokers and developers

For agents, brokers and developers, AML compliance in Abu Dhabi carries a layer most other DNFBPs do not. Alongside the Ministry of Economy DNFBP registration, brokerage licensing sits with the Abu Dhabi Department of Municipalities and Transport, and the federal real estate reporting regime bites whenever a buyer settles in cash, virtual assets or precious metals at or above AED 55,000 for all or part of a property. That cash leg has to be reported through goAML with the buyer’s identity, the source of funds and the transaction detail, separately from any suspicion-based SAR.

In practice the work is source-of-funds discipline. Where a purchaser pays cash for a villa or a floor of offices, you evidence where the money came from before completion, not after. Off-plan sales add developer-side duties, since the developer is itself a reporting party. Foreign buyers, layered holding structures and politically exposed persons push a file into enhanced due diligence.

If you are building a broker or developer programme, our real estate agency AML programme template sets out the policy, and the escrow account rules for UAE real estate sit alongside it. Both feed one goal: a file that holds up on inspection day.

AML compliance in Abu Dhabi for gold and precious metals dealers

Dealers in precious metals and stones face some of the most closely watched AML compliance in Abu Dhabi, because cash still moves through the trade at Madinat Zayed Souk, the Gold Souk and the wholesale bullion market. A dealer becomes a federal DNFBP the moment it deals in gold, silver, platinum, diamonds or finished jewellery, and the reporting duty is triggered by a cash transaction — single or linked — at or above AED 55,000, filed through goAML as a dealers in precious metals and stones report, on top of any suspicion-based SAR.

Bullion and refinery-facing businesses carry a heavier version again. The responsible-sourcing expectations that sit around the UAE gold supply chain, drawn from OECD due-diligence guidance and the local Good Delivery standard, push know-your-counterparty checks up the chain to refiners, exporters and mine-side suppliers. Source-of-gold and source-of-funds both need documenting.

The build is the same as any DNFBP — registration, MLRO, written risk assessment, screening, record-keeping — but weighted towards cash-handling controls and counterparty verification. Our gold trader DPMS AML programme template shows the structure, and AML consulting for the wider UAE market gives the surrounding context.

What supervisors actually inspect on the MLRO

The Money Laundering Reporting Officer is the senior individual responsible for the firm’s AML/CFT compliance, and supervisors inspect the function as a central indicator of programme quality. In smaller DNFBPs the same person is often simply called the AML officer or compliance officer — the title matters less than the authority behind it.

Seniority is the first thing they check. The MLRO has to be senior enough to act independently of operational management, with a direct reporting line to the board or governance body — in smaller DNFBPs that’s often the managing partner or compliance director. The role can be outsourced to a third-party compliance firm for smaller DNFBPs, but the firm keeps ultimate responsibility, and the outsourced MLRO must be named, registered with the supervisor and accessible for inspection.

Then there’s the paper trail. The MLRO maintains documented evidence of risk assessment decisions, KYC and CDD reviews, SAR/STR filings (including decisions not to file where suspicion was considered and rejected), training delivery, sanctions screening output and supervisory liaison, all of which supervisors inspect on-site. On top of that the MLRO delivers or arranges annual AML/CFT training for relevant staff and keeps the training records, and acts as the primary contact for the Ministry of Economy, the Executive Office for AMLCTF, the FIU and the activity-specific regulator (FSRA for ADGM-regulated firms). Good training covers the three stages of money laundering — placement, layering and integration — and connects each stage to the firm’s own transaction patterns rather than staying theoretical.

Risk assessment and policy — written, not templated

The foundation of any AML programme is the written risk assessment and the AML/CFT policy that follows from it.

The risk assessment identifies and documents the AML and CFT risks the firm faces by customer type, jurisdiction, product or service, delivery channel and transaction profile, with higher-risk segments getting higher controls. For a real estate brokerage those dimensions are cash-buyer profile, source-of-funds verification thresholds, foreign investor jurisdictions and beneficial ownership complexity; for an accounting firm they’re client industry sectors, beneficial ownership structures, jurisdictions served and transaction patterns. You review it annually and update it for material changes.

The AML/CFT policy then translates that assessment into operational procedures — customer onboarding, KYC and CDD, sanctions screening, transaction monitoring, SAR/STR escalation and filing, record-keeping, staff training, governance and reporting lines — and it’s board-approved and reviewed annually. Supervisors are quick to spot a generic template that doesn’t reflect the firm’s actual business, so the assessment has to show real analysis of your customer base, transaction patterns and jurisdictional exposure.

KYC, CDD and the UBO question

Customer due diligence is the operational core of any AML programme. Standard CDD means verified KYC documents — identification documents (passport for individuals, trade licence plus MoA plus UBO declaration for entities), proof of address, verified contact details — and an understanding of the customer’s business and source of funds. Part of that is establishing the ultimate beneficial owner — the natural person who ultimately owns or controls 25% or more of the customer, or otherwise exercises effective control. UBO identification is mandatory under federal AML rules and also feeds the ADGM, DIFC and mainland UBO disclosure requirements that apply at company-formation level.

Higher-risk customers get enhanced due diligence: PEPs, customers from higher-risk jurisdictions per FATF and UAE assessments, complex multi-jurisdictional ownership chains, high-value transactions and unusual patterns. EDD usually means senior management approval, extra source-of-funds verification and closer ongoing monitoring. At the other end, simplified due diligence can apply to lower-risk types — large listed companies, certain government entities, regulated financial institutions from FATF-equivalent jurisdictions — but only with documented justification. It isn’t a default; you justify it case by case.

None of this stops at onboarding. Transactions are monitored throughout the relationship against the customer’s stated profile, material deviations trigger review, and the CDD record is refreshed periodically. The Executive Regulations do not set a refresh interval by risk band — they require the data to be kept current, and leave the cadence to your documented risk-based policy, so the interval you will be tested against is the one you wrote down.

Retention, by contrast, is fixed. Article 25 of Cabinet Decision No. 134 of 2025 requires records to be kept for not less than five years from completion of the transaction or termination of the relationship, and Article 25(2) restarts that clock from the latest of account closure, completion of a supervisory inspection, completion of an investigation or a final court judgment. ADGM-regulated firms may face longer periods under the FSRA rulebook.

The five lists you cannot skip

Sanctions screening is mandatory at customer onboarding and on an ongoing basis. The lists you screen against are the UN Consolidated Sanctions List, the US OFAC SDN List, the UK HM Treasury Consolidated List, the EU Consolidated Financial Sanctions List, and the UAE Local Terrorist List published by the UAE Executive Office for AMLCTF, with some sectors and risk profiles adding Singapore, Australia or Switzerland on top. A common misconception is that screening runs against a list of sanctioned countries — it doesn’t; the lists name persons, entities and vessels, and country risk enters separately through FATF and UAE jurisdiction-risk assessments.

How you screen depends on volume. A low-volume DNFBP can do manual lookups against the free public lists on supervisor portals; high-volume regulated firms run enterprise platforms with API integration, from providers like Refinitiv World-Check, LexisNexis, Dow Jones Risk & Compliance and Acuris. At that end of the market the choice of AML screening software matters less than the discipline around it — logs, match-review SLAs and re-screening cadence. When a confirmed match comes up you freeze the funds immediately, stop all further transactions and report promptly to the FIU and the relevant supervisor; false positives get documented and dismissed, and the screening log evidences both.

Screening isn’t a one-time event either. You re-screen the customer base periodically and on every customer profile change, and new names added to the lists have to show up in re-screening. No UAE instrument publishes a re-screening frequency by risk band, so the frequency is a decision your policy makes and your screening log has to evidence — the practical constraint is that item 34 of the Cabinet Resolution No. 71 of 2024 annex fines a failure to “constantly verify databases and transactions” against the lists at AED 50,000 to AED 1,000,000, and item 35 sets AED 500,000 to AED 1,000,000 for failing to freeze funds promptly when a match appears.

goAML portal

UAE Financial Intelligence Unit's reporting portal — mandatory registration for all reporting entities, channel for SARs, STRs and supervisor returns

Filing through goAML

The goAML portal is the FIU’s reporting infrastructure for the UAE. All reporting entities register on it with their commercial documents, MLRO appointment details, supervisor information and authorised user credentials. The FIU does not publish a guaranteed processing time, so plan the registration against a compliance calendar rather than a deadline. Keep the goAML login credentials current and accessible to the MLRO — a lapsed or locked-out account delays urgent SAR filing at exactly the wrong moment.

The core reports are the Suspicious Activity Reports, filed when the firm has reasonable grounds to suspect that funds are the proceeds of crime, that a customer is financing terrorism, or that a transaction is otherwise suspicious. You file them through goAML with a supporting narrative, transaction details and customer identification. Filing is event-driven, so there’s no minimum periodic SAR requirement, but failing to file when suspicion arises is a serious breach. Suspicious Transaction Reports are the transaction-level version for dealings that meet the suspicion threshold, and beyond those sit currency transaction reports for high-value cash in regulated sectors, real estate transaction reports for above-threshold deals, and other specialist returns by sector.

One rule sits above all of it: telling the customer, or anyone other than supervisors and law enforcement, that a SAR has been filed is a criminal offence. SAR filings are confidential.

The pattern we run into most often in Abu Dhabi files is a firm with strong onboarding KYC and weak ongoing monitoring. Onboarding is visible — it produces a folder. Ongoing monitoring is invisible until somebody asks to see a year of it. Build the monitoring discipline before the inspection lands.

— Velmont Crest advisory note

The penalty ladder, with the article numbers

“Up to AED 5,000,000” is the headline, and it is right — but it is one rung on a ladder, and the rungs are set by different instruments and imposed by different bodies. Getting them straight matters, because a paperwork gap and a laundering conviction are not the same event and should never be quoted as though they were.

RungInstrument and articleAmountImposed by
Fixed violation fines (41 listed items)Cabinet Resolution No. 71 of 2024, annexAED 50,000 – 1,000,000 per violationMinistry of Economy and Tourism
General supervisory fineFDL No. 10 of 2025, Art. 17(1)(b)AED 10,000 – 5,000,000 per violationSupervisory Authority
Other supervisory measuresFDL No. 10 of 2025, Art. 17(1)(a), (c)–(g)Warning; sector ban; restriction or suspension of officers; suspension of activity; licence revocationSupervisory Authority
Failure to report a suspicious transactionFDL No. 10 of 2025, Art. 28 (breach of Art. 18)Imprisonment and AED 100,000 – 1,000,000, or eitherCriminal court
Tipping offFDL No. 10 of 2025, Art. 29(1) (breach of Art. 24)Imprisonment and a fine of not less than AED 50,000, or eitherCriminal court
Money laundering by a natural personFDL No. 10 of 2025, Art. 26(1)1–10 years and AED 100,000 – 5,000,000, or the value of the criminal property if greaterCriminal court
Money laundering by a legal personFDL No. 10 of 2025, Art. 27(1)AED 5,000,000 – 100,000,000, or the value of the criminal property if greaterCriminal court

Quoted from Federal Decree-Law No. 10 of 2025 and the annex to Cabinet Resolution No. 71 of 2024, checked 5 August 2026.

Two things follow from that table for an Abu Dhabi MLRO. First, the criminal exposure on a missed report is personal as well as corporate — Article 28 attaches to whoever “deliberately or through gross negligence” breaches the Article 18 reporting duty, and the sentence includes imprisonment. Second, Article 17(3) allows a supervisor to impose an incremental fine where the same violation recurs within a year of the previous one, so the second finding on the same point is not priced like the first.

What the 2025 rulebook moved

Cabinet Resolution No. 134 of 2025, issued 29 October 2025, repealed Cabinet Decision No. 10 of 2019 in its Article 70 and, under Article 71, takes effect thirty days after publication in the Official Gazette. The substance largely carried over; the article numbers did not. If your Abu Dhabi policy manual cites the 2019 regulation, these are the provisions it now needs to point at.

ObligationArticle in CD 134/2025Note
DNFBP categories and triggersArticle 3Commercial gaming operators from AED 11,000; DPMS from AED 55,000 cash; real-estate brokers with no threshold
CDD on occasional transactionsArticle 7(2)(a)AED 55,000, single or linked — Financial Institutions only under this article; the repealed Art. 6(2) also named DNFBPs
CDD triggers for DNFBPsArticle 7(1)Commencing a business relationship; suspicion of a crime; doubts about identification data — no monetary threshold
CDD on wire transfersArticle 7(2)(b)AED 3,500
Virtual asset service providersArticle 7(3)AED 3,500 on occasional transactions
Internal policies and controlsArticle 21Senior-management approved, proportionate to risk and size
Independent audit functionArticle 21(6)Listed alongside the policy itself, applied to the same population — no size carve-out in the text
Compliance officer appointment and dutiesArticle 22Management level, independent in decision-making, five listed duties
Record retentionArticle 25Not less than five years

The independent audit point is the one that surprises Abu Dhabi SMEs. Article 21(6) sits in the same list as the written policy and the training programme, and Article 21 addresses financial institutions, DNFBPs and virtual asset service providers without distinguishing by headcount or turnover. A consultant who tells you the independent audit only applies to larger firms is describing a carve-out that is not in the article.

If you’re an ADGM-regulated firm, FSRA adds a layer

ADGM-regulated firms sit under the FSRA AML Rulebook on top of federal AML/CFT law, and the added weight shows up in a few places. There are quarterly Prudential and AML returns through the FSRA’s e-services portal covering AML/CFT controls, transaction monitoring exceptions, sanctions screening output, SAR filing statistics and material AML events. On-site supervisory inspections run annually for higher-risk firms and biennially for lower-risk ones, with focused thematic reviews when supervisor priorities shift.

Responsibility lands on named people. The Senior Executive Officer and the MLRO carry direct responsibility for AML controls, and the FSRA can impose individual disqualifications and fines on senior management for systemic failures. For prudentially-regulated firms the AML controls also form part of the operational risk capital assessment, so weak AML can translate into higher capital requirements. And FSRA-licensed virtual asset service providers face enhanced obligations reflecting the FATF Travel Rule, blockchain analytics requirements and crypto-specific risk typologies.

ADGM SPVs: the obligation founders forget

ADGM non-regulated entities — SPVs, holding companies, foundations, trading companies, Tech Startup-licensed firms — carry AML obligations under the ADGM AML Rulebook administered by the Registration Authority, scaled to what the entity actually does. A passive SPV or holding company gets the lighter version: UBO disclosure, sanctions screening of counterparties and incoming funds, record-keeping, and an annual AML/CFT statement to the Registration Authority confirming ongoing compliance. A trading entity or Tech Startup with live customer relationships gets the full set — CDD, ongoing monitoring and SAR reporting. And a registered agent or corporate service provider serving ADGM clients picks up its own DNFBP obligations under federal law on top of the ADGM rules.

The common error is for ADGM SPV and holding-company directors to read “non-regulated” as “no AML obligations.” It isn’t. The Registration Authority can fine you, restrict your activity and ultimately pull the licence. So file UBO updates promptly, screen incoming funds, keep your records — even if the company never does anything more exciting than hold a few assets.

How to start AML compliance in Abu Dhabi: the first 90 days

If you are standing up AML compliance in Abu Dhabi from scratch — a new brokerage, a fresh accounting practice, an ADGM entity that has just worked out it is in scope — the order of the work matters more than the speed. Doing it in sequence stops you registering for goAML before you have an MLRO to name, or drafting policy before you have assessed your own risk.

A workable order looks like this. First, confirm which regime you fall under: federal DNFBP, FSRA-regulated or ADGM non-regulated. Second, appoint and empower the MLRO, since almost everything downstream is filed in their name. Third, prepare the written risk assessment, because the policy has to flow from it. Fourth, register on goAML and, for ADGM entities, complete the UBO and Registration Authority filings. Fifth, put onboarding, screening and record-keeping into live use, then train the team.

Give it a quarter, and treat the first annual return and any inspection as the real test. Our goAML registration and login guide covers the portal step, the UBO declaration and renewal rules cover the ownership filing, and the Ministry of Economy inspection playbook sets out what supervisors ask for.

What drives the cost of an Abu Dhabi AML programme

There is no single price for AML compliance in Abu Dhabi, and any provider quoting a flat per-tier grid before seeing your licence is guessing. What actually moves the number is the scope of the work, not a headline rate.

What drives the costLighter endHeavier end
DNFBP categorySolo accountant, small CSP, single-office brokerageMulti-branch brokerage, mid-size audit firm, active DPMS
Regulatory regimeFederal DNFBP onlyFSRA-regulated ADGM firm with quarterly returns
MLRO modelOutsourced or back-up MLRO supportFull in-house MLRO function
Screening volumeLow-volume manual lookupsHigh-volume automated screening with adverse-media
Reporting cadenceAnnual supervisory returnQuarterly Prudential and AML returns, on-site inspection prep
First-year buildProgramme already passing inspectionFull rebuild before steady-state support

Because these dimensions combine differently for every firm, we scope the AML engagement against your written risk assessment, customer base and reporting cadence, then quote a single fixed annual figure. A first-year engagement that needs a full rebuild before steady-state support carries more setup work than a programme already passing supervisor inspection. The accounting and audit-support side is quoted the same way, against scope rather than a rate card — request a quote. For the AML engagement itself, book a free discovery call and you get a fixed figure scoped to your licence.

How Velmont Crest scopes Abu Dhabi AML work

Velmont Crest, a Dubai accounting firm is a DED-licensed accounting and advisory firm based in Dubai and provides AML compliance support to Abu Dhabi DNFBPs — real estate brokers, dealers in precious metals, accountants, tax consultants, corporate service providers — and to ADGM-registered non-regulated entities.

A standard engagement covers AML/CFT policy and procedure drafting, written risk assessment preparation and annual update, MLRO outsourcing or support to in-house MLROs, goAML registration support, sanctions screening implementation (process design and tool selection support), KYC and CDD procedure design and review, annual staff training delivery, supervisory return preparation, and SAR/STR drafting and filing support.

We are not a licensed AML auditor and do not perform independent AML audits — we provide first-line implementation and second-line monitoring support. We are not a Ministry of Economy-accredited audit firm and do not sign audit opinions. We are not an FSRA-authorised compliance advisor for FSRA-regulated firms — those firms must work with FSRA-authorised compliance advisors for FSRA-specific work. We are not a Federal Tax Authority registered tax agent.

For service detail see our AML compliance service page. For sibling-market context see AML compliance in Sharjah, AML compliance UAE and accounting companies in Abu Dhabi.

Where this leaves you

AML compliance in Abu Dhabi is a programme, not a project. The federal framework, the FSRA Rulebook (for ADGM-regulated firms) and the ADGM AML Rulebook (for non-regulated ADGM entities) all expect ongoing, documented, board-overseen AML disciplines — not a one-off policy drafted at incorporation and never updated.

The Abu Dhabi DNFBP or ADGM entity that passes supervisor inspection cleanly is the one whose MLRO can produce, on the day, the current written risk assessment, the latest sanctions screening logs, the year-to-date training records, the goAML registration confirmation, the SAR filing log (including documented decisions not to file), the CDD files for any sample customer requested, and the board-approved annual AML report.

Build that discipline before the inspection lands. The penalty schedule is real, the supervisors are active, and the cost of a clean programme is a fraction of the cost of a serious breach. And administrative fines are only one side of it — money laundering punishment in the UAE under the criminal provisions of the same law includes imprisonment, entirely separate from the supervisory penalties covered here.


Disclaimer: Velmont Crest is a DED-licensed accounting and advisory firm. We provide advisory, preparation and compliance support services for UAE businesses, including AML policy drafting, risk assessment preparation, MLRO outsourcing support, KYC and CDD procedure design, sanctions screening implementation support, training delivery and supervisory return preparation. We are not a licensed AML auditor and do not perform independent AML audits. We are not a Ministry of Economy-accredited audit firm and do not sign statutory audit opinions.

We are not an FSRA-authorised compliance advisor for FSRA-regulated firms; FSRA-regulated firms must work with FSRA-authorised compliance advisors for FSRA-specific work. We are not a Federal Tax Authority registered tax agent. Fees, regulatory requirements, AML/CFT rules, sanctions lists and supervisory priorities change frequently — verify the current position with the relevant authority and take advice from a licensed AML professional for matters specific to your circumstances.

References

Frequently asked questions

Who has to comply with AML rules in Abu Dhabi?
Three groups. Federal DNFBPs under [Federal Decree-Law No. 10 of 2025](https://u.ae/en/information-and-services/justice-safety-and-the-law) and its executive regulations, [Cabinet Decision No. 134 of 2025](https://u.ae/en/information-and-services/justice-safety-and-the-law) — that's real estate brokers and agents, dealers in precious metals and stones, auditors, accountants, tax consultants and agents, corporate service providers, some lawyers and legal consultants, and trust and company service providers. Financial institutions regulated by the UAE Central Bank — commercial banks, finance companies, exchange houses, insurers. And FSRA-regulated firms inside ADGM, which carry their own rulebook on top.
How does AML compliance in Abu Dhabi differ from Dubai?
At the federal level it doesn't — same law, same Ministry of Economy supervision for DNFBPs, same goAML portal, same sanctions lists, same penalties. What's different is the local cast. Abu Dhabi has ADGM, which runs its own AML Rulebook through the Registration Authority for non-regulated entities and the FSRA AML Rulebook for regulated firms; Dubai's equivalents are the DIFC and DFSA rulebooks. And real estate AML in the capital sits under the Abu Dhabi Department of Municipalities and Transport for brokerage licensing, layered on top of the federal DNFBP rules.
What is goAML and who must register?
[goAML](https://www.uaefiu.gov.ae/) is the UAE Financial Intelligence Unit's reporting portal — where suspicious activity reports (SARs) and suspicious transaction reports (STRs) get filed. Every federal DNFBP, every Central Bank-regulated financial institution, plus FSRA-regulated ADGM firms and DFSA-regulated DIFC firms has to register and report through it. To register you supply commercial documents, MLRO appointment details, supervisor information and authorised user credentials. SAR and STR filing is event-driven, so you file when suspicion arises — there's no minimum. The calendar-driven part is the broader supervisory work, like the annual AML/CFT risk return and keeping your risk assessment current.
What does an MLRO actually do in an Abu Dhabi DNFBP?
The Money Laundering Reporting Officer is the senior person who owns the firm's AML/CFT compliance — risk decisions, SAR filings, training, dealing with the supervisor. The role is mandatory for DNFBPs under federal rules and for ADGM-regulated firms under FSRA rules. It can't be a name on a letter; it has to be someone with real authority and a direct line to the board.
What is the difference between FSRA AML and federal DNFBP AML?
Mostly intensity, not substance. Both trace back to the same FATF Recommendations and federal AML/CFT law, so the underlying obligations line up closely. What changes is the supervisor, the reporting cadence and how hard you get watched. FSRA AML for ADGM-regulated firms runs under the FSRA AML Rulebook administered by the [Financial Services Regulatory Authority](https://www.adgm.com/), covering banks, fund managers, broker-dealers, payment service providers, custodians and virtual asset firms. That world is heavier — quarterly Prudential and AML returns, ongoing supervisory engagement, on-site inspections, capital adequacy with an AML overlay, and a board AML committee once the firm is large enough.
What KYC and customer due diligence does Abu Dhabi AML require?
You identify and verify the customer, identify the beneficial owner (the natural person who ultimately controls 25%+ or otherwise calls the shots), work out what the relationship is actually for, and then keep monitoring transactions against that picture over time. Higher-risk customers get enhanced due diligence — PEPs, customers from higher-risk jurisdictions, tangled ownership chains, large transactions. Lower-risk types can get simplified due diligence, but only where you've written down why. Whatever you do, document it and hold the records for the prescribed period, usually 5 years from the end of the relationship.
How does AML apply to ADGM-registered entities that are not FSRA-regulated?
They're still in scope — that's the part founders miss. ADGM non-regulated entities like SPVs, holding companies, foundations, trading companies and Tech Startup-licensed firms sit under the [ADGM AML Rulebook](https://www.adgm.com/), administered by the Registration Authority, which scales the obligations to what you actually do. A passive SPV or holding company gets the lighter version — UBO disclosure, sanctions screening of counterparties and incoming funds, record-keeping. An active trading entity or Tech Startup with real customers gets the full set — CDD, ongoing monitoring, SAR reporting. And a corporate service provider or registered agent serving ADGM clients picks up its own federal DNFBP obligations on top of all that.
What does AML compliance cost for an Abu Dhabi DNFBP?
It scales with your DNFBP category, transaction volume, whether you sit under the federal DNFBP regime or the FSRA AML Rulebook, and whether the MLRO is outsourced or in-house. A small brokerage or solo accounting practice carries a lighter programme than a busy multi-branch brokerage or an FSRA-regulated ADGM firm running quarterly returns. Rather than publish a per-tier price grid that rarely fits a real AML scope, we price the engagement to your actual risk assessment, screening volume and reporting cadence, then quote a fixed annual figure against your licence and customer base. See our /contact/ page for published Velmont figures.
What are the three stages of money laundering?
Placement (getting illicit cash into the financial system), layering (moving it through transactions and structures to obscure the source) and integration (bringing it back as apparently legitimate funds). UAE supervisors expect DNFBP training and risk assessments to connect these stages to the firm's own products — cash property purchases map to placement, layered holding structures to layering, and clean-looking outbound transfers to integration.
What are the penalties for AML breaches in Abu Dhabi?
Up to AED 5,000,000 per breach under the federal AML/CFT framework — [Federal Decree-Law No. 10 of 2025](https://u.ae/en/information-and-services/justice-safety-and-the-law) and its executive regulations. The top of that range is reserved for the serious stuff — failing to file SARs, skipping CDD, dealing with sanctioned parties, or a programme that's broken throughout. It doesn't stop at fines, either. Repeat or serious failures can pull in criminal liability for the MLRO and senior management, licence revocation, and publication — Article 17(4) lets the Supervisory Authority publish the penalties it imposes through media outlets. ADGM firms also sit under the FSRA's own schedule of fines, restrictions, censures and disqualifications.
Does Velmont Crest provide AML compliance support in Abu Dhabi?
Yes. We're a DED-licensed accounting and advisory firm based in Dubai, and we support Abu Dhabi DNFBPs — real estate brokers, dealers in precious metals, accountants, tax consultants, corporate service providers — as well as ADGM-registered non-regulated entities. The work spans AML/CFT policy and procedure drafting, the written risk assessment and its annual refresh, MLRO outsourcing or back-up for an in-house MLRO, goAML registration, sanctions screening setup, KYC and CDD procedure design, annual staff training, supervisory returns, and drafting and filing SARs and STRs.

Filed under: aml compliance abu dhabi, DNFBP abu dhabi, goAML registration, FSRA AML, ADGM anti money laundering, sanctions screening UAE, MLRO appointment

Published · Updated