← All guides

Jurisdiction guide · UAE

UAE: the new AML law, CBUAE guidance and your enterprise-wide risk assessment

Federal Decree-Law No. 10 of 2025, its executive regulations and the CBUAE’s risk assessment expectations, with what they mean for a payments business’s EWRA.

Published

What changed in the UAE

Federal Decree-Law No. (10) of 2025 Regarding Anti-Money Laundering, and Combating the Financing of Terrorism and Proliferation Financing took effect on 14 October 2025. It repeals the 2018 law (Federal Decree-Law No. (20) of 2018) and, as its title signals, puts proliferation financing alongside money laundering and terrorist financing. The definition of the offence expressly covers commission through digital systems, virtual assets and cryptographic technologies. Read the Decree-Law on the CBUAE Rulebook

Article 19 is the one that matters for the assessment. Financial institutions, designated non-financial businesses and professions, and virtual asset service providers must “identify, understand, manage, assess, document, and continuously update the risks of the Crime within their business scope”, retain “the risk assessment study and related information” and provide it to the supervisory authority on request.

The executive regulations followed: Cabinet Resolution No. (134) of 2025, in force from 14 December 2025, replacing Cabinet Decision No. (10) of 2019. They require firms to assess their crime risks “in a manner proportionate to the nature and size of their business”, taking into account the risk-based approach and the National Risk Assessment, and to consider customer, country and geographic, product, service, transaction and delivery channel risks before deciding the overall level of risk. Policies and controls must be approved by senior management and reviewed on an ongoing basis. Read Cabinet Resolution No. (134) of 2025

What the CBUAE expects of the risk assessment

In November 2025 the Central Bank of the UAE published a best-practice paper on implementing a risk-based approach and conducting institutional risk assessments, effective from 7 November 2025 and applying to banks, exchange houses, finance companies, stored value facilities, retail payment service providers, card schemes, virtual asset service providers, registered hawala providers and insurers. Licensed financial institutions are expected to demonstrate compliance within one month of it coming into effect. Read the CBUAE best-practice paper

The paper describes the shape of the assessment the CBUAE wants to see:

  • Inherent risk across customers, products and services, delivery channels, geography and operating structure, then the design and operating effectiveness of controls, then the residual risk that remains.
  • Ownership by the board and senior management, with the MLRO or compliance officer conducting the work and the board giving final approval.
  • An update at least annually, and sooner after trigger events such as a change in business model, structure or a major new line of business.
  • Where a group assesses by business line or country, the results aggregated into an enterprise-level report of inherent risks, controls and residual risks.

Separate guidance on proliferation finance, also effective from 7 November 2025, states that an institution’s “enterprise-wide ML/TF/PF risk assessment or standalone product risk assessment should evaluate the PF risk associated with a new product before the product is launched” and should periodically assess the ML/TF/PF risk of all products and services. The CBUAE has also published guidance on trade-based money laundering and correspondent banking for firms with that exposure. Read the proliferation finance guidance

What this means for a payments business’s EWRA

For a payment service provider, exchange house or stored value facility operating in the UAE, the practical changes to the enterprise-wide risk assessment are these:

  1. Proliferation financing becomes its own line. Assess PF exposure and PF controls explicitly rather than folding them into sanctions or terrorist financing.
  2. Virtual assets and digital channels need a view. If you serve VASPs, settle in virtual assets or onboard through digital channels, describe the exposure and the controls around it.
  3. Control effectiveness needs evidence. The CBUAE distinguishes design from operating effectiveness. A policy’s existence is not evidence that it works.
  4. The record must be retrievable. Article 19 expects the “risk assessment study” and its supporting information to be available on request, so keep evidence, rationale and approval together.
  5. Show what changed. With an annual update expected, a reviewer will want to see the movement from the prior assessment and why.

How to reflect it in EWRA

EWRA is built around the same sequence the CBUAE describes: inherent risk by domain, control design and operating effectiveness, then residual risk, with the rationale kept next to each answer.

  • Adjust the framework to add proliferation financing factors, controls and questions, and record why the change was made.
  • Assess sanctions on its own terms, with a separate scoring and governance record.
  • Grade each control’s design and operating effectiveness and let the residual risk follow from the evidence.
  • Route the assessment through preparation, review, challenge and approval so the sign-off record is there when the supervisor asks.
  • Use year-on-year comparison to show what moved since the last assessment, and export the report and audit trail.

The demonstration environment uses a fictional payments group whose entities include a UAE branch, so you can see how a multi-country assessment sits together. Try the payments demo Sample data only; no sign-up.

Check the current position

The Decree-Law, the executive regulations and the CBUAE guidance are the sources to rely on; summaries, including this one, are not. Confirm the requirements that apply to your licence category, and whether a supervisor other than the CBUAE has issued its own expectations for your business. Decree-Law No. (10) of 2025

How to do an EWRA

This guide provides general information, not legal advice. Check the current source material and requirements applicable to your firm. Software does not confer regulatory approval.