Émirats arabes unis KYC, KYB & AML compliance checklist
Une checklist pratique et sourcée pour mettre en œuvre les exigences KYC, KYB et AML en Émirats arabes unis.
- Dernière revue
- Dernière revue:
- Version
- Version 1.1

Réponse directe
Que couvre la checklist de conformité pour Émirats arabes unis ?
La checklist pour Émirats arabes unis traduit les principales règles KYC, KYB et AML en 11 domaines de contrôle et 41 contrôles d’implémentation, avec les autorités, obligations de déclaration et preuves à conserver.
Faits réglementaires clés
- FIU
- UAE Financial Intelligence Unit; suspicious reports use the FIU's approved forms and goAML service
- Primary AML rules
- Federal Decree-Law 10/2025 and Cabinet Resolution 134/2025
- FI occasional CDD
- AED 55,000, single or linked transactions
- Wire and VASP CDD
- AED 3,500 under Cabinet Resolution 134/2025
- AML ownership test
- 25% or more, then other control, then senior management
- National KYC platform
- Federal Decree-Law 30/2024 and Cabinet Resolution 55/2026 are active
- Suspicion reporting
- Without delay, including attempts and regardless of value
- Core retention
- At least 5 years, using the latest applicable trigger
- FATF public lists
- Not listed at 19 June 2026; removed from increased monitoring in February 2024
Détail d’implémentation
Exigences et actions de conformité pour Émirats arabes unis
Ouvrez chaque domaine pour consulter l’exigence, l’action recommandée, les preuves à conserver et la source primaire utilisée.
01Scope, authorities, and licensingResolve the regulated activity, location and supervisor before onboarding or launch.3 éléments+
Map each entity and activity to the federal reporting perimeter.
- Action d’implémentation
- Classify financial activities, designated non-financial businesses and professions, virtual-asset services and nonprofit activity under the 2025 law and executive regulation; record the applicable supervisor.
- Preuves à conserver
- Entity map, activity analysis, licence inventory, supervisor confirmation and legal opinion.
- Source primaire
- Federal Decree-Law 10/2025; Cabinet Resolution 134/2025, Articles 2-5
Separate federal, emirate and financial-free-zone regimes.
- Action d’implémentation
- Determine whether CBUAE, SCA, Ministry of Economy and Tourism, Ministry of Justice, VARA, DFSA or FSRA rules govern each service; do not extend a mainland or free-zone rule beyond its perimeter.
- Preuves à conserver
- Jurisdiction decision tree, establishment documents, customer-location rules and regulator correspondence.
- Source primaire
- Federal Decree-Law 10/2025; joint UAE supervisory guidance; applicable regulator rulebook
Obtain every required financial, payment or virtual-asset permission.
- Action d’implémentation
- Before promotion or operation, classify retail payment, stored-value, payment-token, remittance, exchange, securities and virtual-asset activity and secure the licence, registration or non-objection required by the competent regulator.
- Preuves à conserver
- Product analysis, application, licence, conditions, approved agents and renewal calendar.
- Source primaire
- Federal Decree-Law 6/2025; CBUAE Retail Payment Services Regulation; CBUAE Payment Token Services Regulation; applicable SCA, VARA, DFSA or FSRA rules
02Governance and risk assessmentControls must be risk-based, senior-approved, independently tested and updated.3 éléments+
Maintain a documented enterprise crime-risk assessment.
- Action d’implémentation
- Assess money-laundering, terrorist-financing and proliferation-financing exposure by customer, country, product, service, transaction, delivery channel and technology and update it when risks change.
- Preuves à conserver
- Methodology, risk assessment, source inputs, approvals, residual-risk decision and remediation plan.
- Source primaire
- Cabinet Resolution 134/2025, Articles 4-5 and 24
Maintain senior-approved policies and a management-level compliance officer.
- Action d’implémentation
- Document CDD, reporting, sanctions, records, employee screening, training and governance procedures proportionate to risk and obtain senior-management approval.
- Preuves à conserver
- Policy suite, approval minutes, compliance appointment, authority matrix and reporting packs.
- Source primaire
- Cabinet Resolution 134/2025, Articles 21-22
Independently test the AML/CFT/CPF programme.
- Action d’implémentation
- Operate risk-based monitoring, staff training and an independent audit function; track findings to verified closure.
- Preuves à conserver
- Training records, audit plan, test samples, findings, owners and closure evidence.
- Source primaire
- Cabinet Resolution 134/2025, Article 21
03Natural-person identificationIdentify and verify customers and representatives from reliable independent evidence.4 éléments+
Apply CDD at every applicable trigger.
- Action d’implémentation
- Perform CDD at relationship start, on suspicion or doubtful prior data; for financial institutions also at AED 55,000 occasional transactions and AED 3,500 occasional wires; for VASPs at AED 3,500 occasional transactions, aggregating linked activity where specified.
- Preuves à conserver
- Trigger matrix, aggregation tests, timestamps, customer file and exception log.
- Source primaire
- Cabinet Resolution 134/2025, Article 7
Verify natural-person identity using current reliable evidence.
- Action d’implémentation
- Obtain the official name, nationality, address, date and place of birth and applicable employment information, plus a true copy of a valid identity card or travel document, and corroborate authenticity.
- Preuves à conserver
- Identity copy, verification results, liveness or presence evidence, discrepancy log and approval.
- Source primaire
- Cabinet Resolution 134/2025, Article 9(1)(a)
Verify each representative and their authority.
- Action d’implémentation
- Identify and verify the person acting for a customer and confirm the authenticity and scope of the authorisation before permitting access or instructions.
- Preuves à conserver
- Representative KYC, power or mandate, authority check, limits and activity log.
- Source primaire
- Cabinet Resolution 134/2025, Articles 9 and 12
Do not proceed when CDD cannot be completed.
- Action d’implémentation
- Do not establish or continue the relationship or execute the transaction; consider an STR. If further CDD would alert the customer, stop that step and report the reason to the FIU.
- Preuves à conserver
- Restriction, exit decision, suspicion assessment, approval and submission receipt.
- Source primaire
- Cabinet Resolution 134/2025, Article 14
04KYB, registries, and beneficial ownershipVerify legal existence, authority, ownership and actual control, keeping AML and registry tests distinct.5 éléments+
Verify legal-person identity, purpose and authority.
- Action d’implémentation
- Obtain name, legal form, constitutional documents, tax and unique reference numbers where applicable, registered and principal address, directors and binding authority from reliable independent sources.
- Preuves à conserver
- Current registrar extract, constitutional pack, licence, officer list, mandates and discrepancy log.
- Source primaire
- Cabinet Resolution 134/2025, Article 9(1)(b)
Identify AML beneficial owners at 25% or more.
- Action d’implémentation
- Trace natural persons ultimately owning, alone or jointly, an actual controlling ownership interest or shares of 25% or more; if unresolved, identify control by other means, then the relevant senior-management person or persons.
- Preuves à conserver
- Layered ownership chart, percentage calculations, control analysis, fallback rationale and verified identities.
- Source primaire
- Cabinet Resolution 134/2025, Article 10(1)
Identify all controlling parties to legal arrangements.
- Action d’implémentation
- Identify and verify trustees, settlors, protectors, beneficiaries or classes and every other natural person exercising ultimate effective control, including legal persons within the arrangement.
- Preuves à conserver
- Trust or arrangement instrument, party register, powers, ownership analysis and verified identities.
- Source primaire
- Cabinet Resolution 134/2025, Article 10(2)
Maintain the entity-level beneficial-owner record where Decision 109/2023 applies.
- Action d’implémentation
- Create the record within 60 days of formation, keep adequate and current owner data, record changes within 15 days of knowledge and provide required information to the registrar; apply the decision's 25% or control and senior-manager cascade.
- Preuves à conserver
- Beneficial-owner, shareholder and nominee registers, notices, filing receipts and change log.
- Source primaire
- Cabinet Decision 109/2023, Articles 5-10
Apply financial-free-zone ownership rules separately.
- Action d’implémentation
- For DIFC or ADGM entities use the relevant registrar and free-zone beneficial-ownership rules rather than Cabinet Decision 109/2023; document any government or listed-company exemption before relying on it.
- Preuves à conserver
- Perimeter decision, free-zone extract, exemption analysis and filing evidence.
- Source primaire
- Cabinet Decision 109/2023, Articles 2 and 6; applicable DIFC or ADGM regulations
05PEPs, EDD, and remote onboardingDetect public-function exposure and strengthen controls where risk requires.4 éléments+
Identify PEPs, family members and close associates.
- Action d’implémentation
- Use appropriate risk systems, declarations and reliable sources to determine whether a customer or beneficial owner is a foreign or domestic PEP or holds a prominent international-organisation function.
- Preuves à conserver
- Declaration, screening result, relationship map, match rationale and refresh history.
- Source primaire
- Cabinet Resolution 134/2025, Article 16
Apply approval, wealth, funds and enhanced-monitoring measures.
- Action d’implémentation
- For foreign PEPs obtain senior approval, establish source of wealth and funds and enhance ongoing monitoring; apply the same measures to higher-risk domestic and international-organisation PEPs.
- Preuves à conserver
- Risk assessment, senior approval, source corroboration, monitoring plan and reviews.
- Source primaire
- Cabinet Resolution 134/2025, Article 16
Control remote onboarding as a technology risk.
- Action d’implémentation
- Before use, assess impersonation, synthetic-identity, document and deepfake risks; validate the method, protect evidence and add controls proportionate to residual risk.
- Preuves à conserver
- Technology risk assessment, validation, liveness results, fraud tests, restrictions and monitoring.
- Source primaire
- Cabinet Resolution 134/2025, Articles 8, 9 and 24
Map duties under the national KYC Digital Platform.
- Action d’implémentation
- Determine whether the entity collects, retains, analyses, classifies, uses, exchanges, protects or manages KYC data or issues a KYC report; if in scope, classify its platform role, supply the prescribed natural- or legal-person data and implement the current access, consent, security and update requirements.
- Preuves à conserver
- Platform-scope analysis, role registration, data-field map, customer authority, transmission logs, security controls and update evidence.
- Source primaire
- Federal Decree-Law 30/2024; Cabinet Resolution 55/2026, Articles 2-3 and applicable platform provisions
06Monitoring and suspicious reportingSuspicious transactions and attempts are reported without delay and regardless of value.4 éléments+
Monitor relationships and keep indicators current.
- Action d’implémentation
- Scrutinise activity against customer information, business purpose, risk and source of funds where necessary; update crime indicators with changing methods and supervisory instructions.
- Preuves à conserver
- Monitoring scenarios, indicator register, alerts, investigations, source data and dispositions.
- Source primaire
- Cabinet Resolution 134/2025, Articles 8 and 17
Report suspicion and attempted transactions without delay.
- Action d’implémentation
- When suspicion or reasonable grounds arise, regardless of value, submit the FIU-approved suspicious report with available data and documents through the authorised service; do not wait for proof or a threshold.
- Preuves à conserver
- Suspicion chronology, analysis, approved report, goAML delivery record and acknowledgement.
- Source primaire
- Federal Decree-Law 10/2025; Cabinet Resolution 134/2025, Article 18
Register and govern goAML access before operations.
- Action d’implémentation
- Complete FIU pre-registration under the correct supervisor, establish controlled organisation and user administration and test the current report and supplemental-information process.
- Preuves à conserver
- Registration, user approvals, role matrix, test evidence and current FIU guidance.
- Source primaire
- UAE FIU goAML services registration
Prevent tipping off and preserve report confidentiality.
- Action d’implémentation
- Restrict report and investigation data and do not disclose that a report has been or will be filed or that an investigation is underway, except as lawfully permitted.
- Preuves à conserver
- Need-to-know matrix, access logs, communication controls, training and incident review.
- Source primaire
- Cabinet Resolution 134/2025, Article 19
07Payments, wires, thresholds, and agentsPayment permissions, wire data and agent oversight are product- and regulator-specific.4 éléments+
Carry complete originator and beneficiary information.
- Action d’implémentation
- For international wires of AED 3,500 or more verify originator information and transmit the required names, accounts or unique reference and identifying field; transmit required data below the threshold and verify where suspicion exists.
- Preuves à conserver
- Field matrix, validation logic, sampled transfers, repair queue and verification results.
- Source primaire
- Cabinet Resolution 134/2025, Article 28
Control incomplete intermediary and incoming wires.
- Action d’implémentation
- Detect missing information and apply documented risk rules to execute, suspend or reject; beneficiary institutions verify an unverified beneficiary at AED 3,500 or more.
- Preuves à conserver
- Detection rules, repair requests, risk decisions, beneficiary checks and escalation records.
- Source primaire
- Cabinet Resolution 134/2025, Articles 29-30
Govern money-transfer agents within the AML programme.
- Action d’implémentation
- Maintain the current agent list, make it available to authorities, include agents in the AML/CFT/CPF programme and monitor their compliance.
- Preuves à conserver
- Agent due diligence, contracts, register, training, monitoring and remediation.
- Source primaire
- Cabinet Resolution 134/2025, Article 27
Use the correct payment or payment-token licence.
- Action d’implémentation
- Map the service to retail payment, stored-value or payment-token categories; obtain the CBUAE licence, registration or non-objection and comply with restrictions on promotions, agents and outsourcing.
- Preuves à conserver
- Regulatory classification, licence, product terms, agent approvals, outsourcing register and launch sign-off.
- Source primaire
- CBUAE Retail Payment Services and Card Schemes Regulation; Payment Token Services Regulation, Articles 2, 5, 19 and 20
08Targeted financial sanctionsUAE and UN list matches require immediate controls under Cabinet Decision 74/2020 and current Executive Office instructions.4 éléments+
Subscribe to updates and screen UAE and UN sanctions lists.
- Action d’implémentation
- Screen customers, beneficial owners, controllers, representatives, related parties and transactions against the current Local Terrorist List and UN Consolidated List at onboarding, daily and when lists change.
- Preuves à conserver
- Subscription, list inventory, update logs, screening configuration, tests and dispositions.
- Source primaire
- Cabinet Decision 74/2020; Executive Office TFS guidance
Freeze confirmed matches without delay and prior notice.
- Action d’implémentation
- Freeze covered funds and assets immediately, in any event within the official without-delay standard, prevent funds or services being made available and keep restrictions until lawful release.
- Preuves à conserver
- Match analysis, freeze timestamp, ownership/control analysis, asset inventory and system blocks.
- Source primaire
- Cabinet Decision 74/2020; Executive Office TFS guidance
Report freezes and attempted transactions through the current route.
- Action d’implémentation
- For financial institutions and DNFBPs submit the Fund Freeze Report with supporting material through goAML within two business days and notify the relevant supervisor as required.
- Preuves à conserver
- FFR, attachments, submission receipt, supervisor notice and chronology.
- Source primaire
- Executive Office TFS guidance and confirmed-match workflow
Govern partial matches, exemptions and release.
- Action d’implémentation
- Suspend or restrict a possible match according to current guidance, seek Executive Office direction and release or permit access only under verified competent-authority or UN procedure.
- Preuves à conserver
- Identifier analysis, correspondence, licence or exemption, approval and release log.
- Source primaire
- Cabinet Decision 74/2020; Executive Office TFS guidance
09Records and regulator accessRecords must reconstruct transactions and decisions and follow the latest applicable retention trigger.3 éléments+
Retain transaction and relationship records for at least five years.
- Action d’implémentation
- Keep domestic and international transaction, cash and commercial-dealing records for at least five years after transaction completion or relationship termination, applying the later applicable trigger.
- Preuves à conserver
- Retention schedule, trigger calculations, archive sample, legal holds and deletion controls.
- Source primaire
- Cabinet Resolution 134/2025, Article 25(1)
Apply the latest-trigger rule to CDD and investigation records.
- Action d’implémentation
- Keep CDD, monitoring, account, correspondence, identification, STR, analysis and specified recording evidence for at least five years from the most recent applicable closure, transaction, inspection, investigation or final-judgment event.
- Preuves à conserver
- Record-class map, linked case files, trigger engine, archive and retrieval test.
- Source primaire
- Cabinet Resolution 134/2025, Article 25(2)
Make records promptly available to competent authorities.
- Action d’implémentation
- Organise information to reconstruct individual transactions, authenticate requests and produce responsive customer and monitoring material promptly while protecting report confidentiality.
- Preuves à conserver
- Request register, authority validation, production index, delivery log and receipt.
- Source primaire
- Cabinet Resolution 134/2025, Article 25(3)-(4)
10Privacy, biometrics, and transfersFederal data protection applies subject to statutory exclusions and separate DIFC, ADGM, health and credit-data regimes.4 éléments+
Map the applicable privacy regime and lawful basis.
- Action d’implémentation
- Determine whether Federal Decree-Law 45/2021, DIFC or ADGM data-protection law or a sector regime applies; document consent or another lawful ground for every identity, screening and monitoring purpose.
- Preuves à conserver
- Data inventory, perimeter and lawful-basis analysis, notices, consent records and exception register.
- Source primaire
- Federal Decree-Law 45/2021, Articles 2, 4 and 6; applicable DIFC or ADGM law
Minimise and secure identity and biometric data.
- Action d’implémentation
- Collect only necessary data, apply purpose limitation, accuracy, retention and security controls and treat biometric data used for unique identification as sensitive personal data requiring heightened safeguards.
- Preuves à conserver
- Field justification, security design, access reviews, encryption evidence, retention configuration and tests.
- Source primaire
- Federal Decree-Law 45/2021, Articles 1, 5 and 20
Perform impact assessments and appoint a DPO where required.
- Action d’implémentation
- Assess high-risk technology and large-scale sensitive processing before use and appoint an appropriately independent data-protection officer when statutory triggers apply.
- Preuves à conserver
- Impact assessment, risk treatment, DPO analysis and appointment, consultation and approval.
- Source primaire
- Federal Decree-Law 45/2021, Articles 10 and 22
Control incidents, rights requests and overseas transfers.
- Action d’implémentation
- Maintain regulator and data-subject notification procedures without inventing an unverified deadline; fulfil applicable rights and transfer data only under an authorised adequacy or safeguard route.
- Preuves à conserver
- Incident assessment, notifications, rights log, transfer map, contract and adequacy or derogation analysis.
- Source primaire
- Federal Decree-Law 45/2021, Articles 9, 13-18 and 23-24
11Practical evidence packsEvidence should reproduce onboarding, monitoring and launch decisions across regulator boundaries.3 éléments+
Maintain a reconstructable onboarding pack.
- Action d’implémentation
- Bundle identity, authority, KYB, beneficial ownership, PEP and sanctions screening, risk, approvals, privacy records and exceptions under stable identifiers.
- Preuves à conserver
- Complete sampled onboarding pack and retrieval result.
- Source primaire
- Operational control supporting Cabinet Resolution 134/2025, Articles 7-16 and 25
Maintain a reconstructable reporting and sanctions pack.
- Action d’implémentation
- Link transactions, alerts, analysis, timing, report, acknowledgement, supplements, freeze actions, authority communications and access logs.
- Preuves à conserver
- Complete sampled case pack and controlled access log.
- Source primaire
- Operational control supporting Cabinet Resolution 134/2025, Articles 17-19 and Cabinet Decision 74/2020
Maintain a regulator-scoped launch pack.
- Action d’implémentation
- Record activity and location classification, every licence, current legal sources, goAML readiness, ownership filing, sanctions subscription, privacy analysis, vendor controls and validation before launch and on material change.
- Preuves à conserver
- Signed launch pack, source register, regulator map, uncertainty log, tests and approvals.
- Source primaire
- Official sources listed below
Registre des sources primaires
15 sources utilisées pour cette checklist
Utilisez ces liens pour vérifier la législation, les lignes directrices, les procédures de déclaration et les statuts internationaux.
- Federal Decree-Law No. 10 of 2025 on AML/CFT/CPFCentral Bank of the UAE Rulebook · Primary legislation
- Cabinet Resolution No. 134 of 2025 - Executive RegulationsCentral Bank of the UAE Rulebook · Official binding regulation
- UAE FIU goAML services registrationUAE Financial Intelligence Unit · Official reporting service
- Cabinet Decision No. 109 of 2023 on beneficial-owner proceduresMinistry of Economy and Tourism · Official binding decision
- Federal AML and beneficial-ownership legislation repositoryMinistry of Economy and Tourism · Official legislation repository
- Targeted financial sanctions implementationExecutive Office for Control and Non-Proliferation · Official sanctions guidance
- Federal Decree-Law No. 45 of 2021 on personal data protectionUAE Legislation · Primary legislation
- Cabinet Resolution No. 55 of 2026 - KYC Digital Platform RegulationsUAE Legislation · Official binding regulation
- Retail Payment Services and Card Schemes RegulationCentral Bank of the UAE Rulebook · Official regulation
- Payment Token Services RegulationCentral Bank of the UAE Rulebook · Official regulation
- UAE third enhanced follow-up reportMENAFATF · Authoritative regional assessment
- FATF February 2024 plenary outcome and UAE removalFATF · Authoritative status record
- FATF jurisdictions under increased monitoring - 19 June 2026FATF · Authoritative current status
- FATF high-risk jurisdictions subject to a call for action - 19 June 2026FATF · Authoritative current status
- United Nations Security Council consolidated sanctions listUnited Nations · Authoritative sanctions list
Réponses directes
Questions KYC, KYB et AML pour Émirats arabes unis
Who receives suspicious transaction reports?+
The UAE Financial Intelligence Unit. Reporting entities register through the FIU service and submit the approved report type through goAML under the correct supervisory body.
When must suspicion be reported?+
Without delay when suspicion or reasonable grounds concern a transaction, attempted transaction or funds connected with crime, regardless of value. Do not wait for proof or a monetary threshold.
What occasional-transaction CDD thresholds apply?+
For financial institutions, AED 55,000 for a single or linked occasional transaction and AED 3,500 for an occasional wire. For VASPs, AED 3,500 for a single or linked occasional transaction. Relationship, suspicion and doubtful-data triggers apply separately.
How is AML beneficial ownership determined?+
Identify natural persons ultimately owning, alone or jointly, 25% or more; if ownership does not resolve the beneficial owner, identify control by other means, then the relevant senior-management person or persons.
How long are AML records retained?+
At least five years. Cabinet Resolution 134/2025 applies record-specific triggers and, for CDD and investigation material, calculates from the most recent applicable event.
What happens on a sanctions match?+
Screen the UAE Local Terrorist List and UN list, freeze a confirmed match without delay and prior notice, prohibit making funds or services available and make the required report through the current Executive Office and supervisory route.
Which regulator covers payment or virtual-asset activity?+
It depends on the product and location. CBUAE regulates retail payments, stored value and payment-token services; SCA, VARA, DFSA and FSRA may govern other virtual-asset or financial activity. Obtain a written perimeter analysis before launch.
Is the UAE on a FATF public list?+
No. FATF removed the UAE from increased monitoring in February 2024, and it was absent from both FATF public lists dated 19 June 2026. This is not a low-risk classification.
What is the national KYC Digital Platform?+
Federal Decree-Law 30/2024 and Cabinet Resolution 55/2026 establish an active platform framework for persons handling KYC data or issuing KYC reports. Confirm the entity's platform role, required data, access and operational onboarding with the competent authority.
Which privacy law applies?+
Federal Decree-Law 45/2021 applies subject to exclusions. DIFC, ADGM, health and credit data can fall under separate regimes. Confirm the perimeter and current executive rules before biometric or cross-border processing.
Méthode de recherche et de revue
VOVE ID Compliance Research cartographie le périmètre réglementaire, traduit les obligations en contrôles opérationnels, relie les affirmations importantes aux sources et date chaque revue.
General regulatory information, not legal advice or a licence determination. Reviewed as applicable on 14 September 2026. Confirm official Arabic text, later amendments, supervisory circulars, goAML report types, company-registrar procedures, data-protection executive regulations and the exact CBUAE, SCA, VARA, DFSA or FSRA perimeter with the competent authority and qualified UAE counsel before launch.