This is a different question from "how do I pass my own bank's KYC checks" - that's covered in our bank KYC and AML compliance guide. This guide answers a question a lot of UAE business owners haven't asked themselves at all: does your business have its own legal obligation to run AML/KYC checks on your customers? For real estate agents, jewellers, company formation agents, accountants, and lawyers handling certain transactions, the answer is yes - and the law governing that obligation was fully rewritten in late 2025, which a meaningful amount of AML guidance online hasn't caught up on yet.
The Law Just Changed: Federal Decree-Law No. 10 of 2025
This is worth knowing before anything else in this guide, because it affects which citations to trust. Federal Decree-Law No. 10 of 2025 came into force on 14 October 2025, replacing the original Federal Decree-Law No. 20 of 2018 as the UAE's core anti-money laundering law. Its executive regulation, Cabinet Resolution No. 134 of 2025, took effect on 14 December 2025, replacing Cabinet Decision No. 10 of 2019. The new framework expanded scope to explicitly cover proliferation financing - unauthorized financing connected to weapons of mass destruction and dual-use goods - gave the Financial Intelligence Unit power to freeze funds for 30 days instead of the previous 7, and doubled the maximum corporate fine for actual money laundering or terrorism financing offences to AED 100 million. Managers who knew about a violation or failed in their oversight duties can now face personal liability. The core DNFBP obligations - registration, due diligence, reporting - carried over in substance, but the citations, penalty figures, and FIU powers referenced anywhere still pointing to the 2018 law and 2019 regulation are out of date.
Are You a DNFBP? The Five Categories
"DNFBP" stands for Designated Non-Financial Business or Profession - a business that isn't a bank or financial institution but is still legally required to run its own AML program because of what it does. Five categories cover most UAE SMEs that fall into this:
- Real estate agents and brokers — involved in buying, selling, or leasing property on behalf of clients.
- Dealers in precious metals and stones (DPMS) — gold, diamond, and jewelry businesses engaging in cash transactions above the threshold covered below.
- Auditors and accountants — independent professionals providing audit, accounting, or tax-related services.
- Company service providers — corporate formation and administration agents - business setup consultancies, registered agents, and firms managing company incorporation or administration on a client's behalf.
- Independent legal professionals — lawyers and notaries, specifically when handling certain client transactions such as buying/selling property, managing client funds, or forming and managing companies.
If your business falls into one of these categories, the obligations below apply to you directly - not just to the bank you hold an account with.
The Core Obligations Every DNFBP Must Meet
- 1. Register on goAML — the Financial Intelligence Unit's platform for suspicious transaction and activity reporting, registered through the Ministry of Economy.
- 2. Appoint a compliance officer (MLRO) — a designated Money Laundering Reporting Officer responsible for the AML program and regulator liaison.
- 3. Complete a business-wide risk assessment — identifying, documenting, and continuously updating money laundering, terrorism financing, and proliferation financing risks specific to your business, aligned with the UAE's National Risk Assessment.
- 4. Apply customer due diligence (CDD) — identifying and verifying customers and beneficial owners, with enhanced due diligence mandatory for high-risk customers, politically exposed persons, and customers connected to high-risk jurisdictions.
- 5. Screen for targeted financial sanctions — subscribing to the Executive Office for Control and Non-Proliferation's Notification Alert System, screening customers and counterparties both before a transaction and on an ongoing basis, and freezing and reporting any match without delay.
- 6. Keep records for a minimum of five years — transaction records, CDD documentation, and supporting data, available immediately on request from the relevant authorities.
- 7. Train and screen staff — proportional to business size, with documented completion records and continuous review.
- 8. Maintain an independent audit function — reviewing the AML program's effectiveness as a distinct governance component from the compliance officer role itself.
Real Estate-Specific: The REAR Requirement
Real estate agents carry an additional, transaction-level obligation on top of the core list above: the Real Estate Activity Report (REAR), filed through goAML since 1 July 2022. A REAR is mandatory whenever a freehold property transaction involves AED 55,000 or more in a single or linked physical cash payment, any payment made wholly or partly in virtual assets, or cash funded by converting a virtual asset. Filing a REAR doesn't replace any separate suspicious transaction or activity reporting obligation that might also apply to the same deal - it's filed in addition, not instead.
Precious Metals and Stones: The Same AED 55,000 Threshold
Dealers in precious metals and stones face the same AED 55,000 single-or-linked cash transaction threshold as real estate, triggering the same reporting obligation through goAML. Businesses in this category should treat any cash-heavy sale approaching that figure as a compliance checkpoint, not just a sales milestone.
Penalties for Non-Compliance
| Violation Type | Penalty |
|---|---|
| Administrative/regulatory violation (per violation) | AED 10,000 - 5,000,000 |
| Unlicensed AML-regulated activity (criminal) | AED 200,000 - 10,000,000 |
| Corporate fine for money laundering/terrorism financing offence | Up to AED 100,000,000 |
| "Tipping off" a customer under investigation | Unlimited fine |
| Manager personal liability | Applies where the manager knew of the violation or failed in oversight duties |
The administrative range applies to regulatory shortfalls - a missed goAML registration, weak CDD documentation, an outdated risk assessment - while the far larger criminal fines apply to actual money laundering or terrorism financing offences, not paperwork gaps. Both tracks are real exposure, and the administrative one is the far more common way DNFBPs actually get penalized.
Common Mistakes DNFBPs Make
- Treating this as a banking-only issue — conflating your own bank account's KYC checks with your business's separate, independent AML obligations toward your own customers - these are two different compliance relationships.
- Assuming goAML registration alone is enough — registration is the entry point, not the whole program - risk assessment, CDD, screening, and record-keeping all have to actually run on an ongoing basis.
- Running CDD once at onboarding and never again — ongoing monitoring is a stated requirement, not a one-time checkbox at the start of a client relationship.
- Skipping the independent audit function — a common gap in smaller DNFBPs, where the compliance officer's own work never gets independently reviewed.
- Working from pre-October 2025 guidance — citations, penalty figures, and FIU powers based on the old 2018 law and 2019 regulation are now out of date.
Why Get Expert Help on AML/KYC Compliance
Whether your business is a DNFBP, and what your specific risk assessment and CDD program should look like, depends on your exact activity and client base - not a generic checklist. Takween Advisory helps businesses assess their DNFBP status and build the compliance program the current law actually requires. Book a free consultation to get your AML/KYC obligations reviewed properly.
AML/KYC Compliance for UAE Businesses: Quick Reference Table
Here's a quick-reference summary of every figure covered in this guide.
| Item | Detail |
|---|---|
| Current AML law | Federal Decree-Law No. 10 of 2025 (in force since 14 October 2025) |
| Current executive regulation | Cabinet Resolution No. 134 of 2025 (effective 14 December 2025) |
| Superseded law | Federal Decree-Law No. 20 of 2018 |
| DNFBP categories | Real estate agents/brokers, DPMS, auditors/accountants, company service providers, independent legal professionals |
| REAR/DPMS cash reporting threshold | AED 55,000, single or linked transactions |
| Record retention period | Minimum 5 years |
| FIU fund-freeze power | 30 days (up from 7 days under the old law) |
| Administrative penalty range | AED 10,000 - 5,000,000 per violation |
| Maximum corporate fine (ML/TF offence) | AED 100,000,000 |
| REAR filing platform | goAML, since 1 July 2022 |
