Blog

UAE FATF Grey List Exit & AML Law (2025)

The UAE was placed on the FATF grey list in March 2022 and exited in February 2024 after an unprecedented regulatory overhaul. Federal Decree-Law No. 10 of 2025 is the capstone of that effort — a completely rewritten AML/CFT framework with expanded scope, stronger enforcement, and mandatory goAML integration. Here's what changed, why the grey list mattered, and what DNFBPs must do now.

StartupOS TeamStartupOS TeamAug 12, 2026
How the UAE Escaped the FATF Grey List — and What the New AML Law Means for Your Business
The UAE is off the grey list — but the laws that got it there are permanent

The FATF removed the UAE from its "increased monitoring" list in February 2024. The reforms that enabled that exit — including an entirely new AML law (DL 10/2025), expanded goAML reporting, and mandatory KYC digital infrastructure (DL 30/2024) — are now permanent features of the UAE business landscape. The compliance burden that was built for FATF is the compliance burden you inherit as a UAE business owner.

In March 2022, the Financial Action Task Force (FATF) placed the UAE on its "grey list" — officially, jurisdictions under increased monitoring for deficiencies in their anti-money laundering and counter-terrorist financing (AML/CFT) frameworks. For the next 23 months, the UAE undertook one of the most aggressive regulatory overhauls in its history to get off that list.

The UAE exited the grey list on February 23, 2024. But the laws, regulations, enforcement mechanisms, and compliance expectations that enabled that exit remain — and in some cases, have been strengthened further. If your understanding of UAE AML compliance predates the grey list, it is dangerously outdated.


The Grey List, Explained

What FATF Grey Listing Means

The FATF grey list is not sanctions. It is a public statement that a jurisdiction has "strategic deficiencies" in its AML/CFT framework and has committed to resolving them under an agreed action plan. The practical consequences include:

  • Enhanced due diligence by foreign financial institutions on transactions involving the listed jurisdiction
  • Higher compliance costs for businesses in the jurisdiction (banks abroad require additional documentation)
  • Reputational impact — some international counterparties refuse or limit business with grey-listed jurisdictions
  • Reduced correspondent banking access — foreign banks reduce or terminate relationships with banks in the listed country
  • Slower transaction processing — cross-border payments face additional screening and delays

For UAE businesses, the grey list meant more questions from international banks, more documentation requests for cross-border transactions, and in some cases, outright refusal of business by offshore counterparties who had a policy of not dealing with grey-listed jurisdictions.

The UAE's Action Plan

The FATF's action plan for the UAE required:

  1. Demonstrating effective prosecution of money laundering — not just laws on the books, but convictions in court
  2. Strengthening international cooperation — mutual legal assistance, extradition, and asset recovery
  3. Improving beneficial ownership transparency — identifying the real people behind UAE companies
  4. Enhancing suspicious transaction reporting — and demonstrating that reports lead to investigations
  5. Targeting high-risk sectors — particularly gold, real estate, and corporate service providers

Between March 2022 and February 2024, the UAE:

  • Increased money laundering convictions by 250%+ year over year
  • Confiscated AED 4+ billion in assets linked to financial crime
  • Established the Executive Office for AML/CFT to coordinate national strategy
  • Expanded the goAML reporting platform to cover more sectors
  • Issued Cabinet Decision No. 109/2023 (UBO procedures) and CD 132/2023 (UBO penalties)

The Exit

On February 23, 2024, FATF announced the UAE's removal from the grey list, citing "significant progress" on all action plan items. The UAE became one of the fastest jurisdictions to exit the grey list — completing a process that typically takes 3-5 years in under 2 years.


The New AML Law (DL 10/2025)

The capstone of the UAE's AML reform is Federal Decree-Law No. 10 of 2025, Concerning Combating Money Laundering, Terrorism Financing, and the Financing of Proliferation. Published September 30, 2025 and effective October 14, 2025, it repealed and replaced the previous AML law (Federal Decree-Law No. 20 of 2018 and its amendment DL 26 of 2021).

What the New Law Changes

1. Expanded scope of obligated entities. The definition of Designated Non-Financial Businesses and Professions (DNFBPs) has been reviewed and in some cases expanded. The categories of DNFBPs now include:

DNFBP categories under the new AML law
DNFBP CategoryExamples
Real estate agents and brokersAny person involved in buying/selling real estate on behalf of clients
Dealers in precious metals and stonesGold, diamond, and jewellery dealers conducting cash transactions above AED 55,000
Corporate service providersCompany formation agents, PRO services, trust and company service providers
Auditors and accountantsExternal auditors, accounting firms, tax advisors
Lawyers and notariesWhen conducting specified transactions (buying/selling real estate, managing client money, creating/operating legal persons)
Virtual Asset Service Providers (VASPs)Now explicitly included; regulated by VARA in Dubai, SCA at federal level

2. Stronger enforcement powers. The new law grants supervisory authorities expanded powers to:

  • Conduct inspections without prior notice
  • Demand documents and records without specifying a suspected violation
  • Impose administrative fines directly (not necessarily through a court process)
  • Refer cases for criminal prosecution with streamlined evidence requirements

3. Enhanced goAML integration. The goAML platform, operated by the UAE Financial Intelligence Unit (FIU), is now explicitly mandated for a broader range of DNFBPs. Registration is mandatory — not optional, not "when you have a suspicious transaction to report." Failure to register is itself a violation.

4. Alignment with FATF standards. The new law directly addresses FATF Recommendation 22 (DNFBP customer due diligence), Recommendation 23 (DNFBP reporting), and Recommendation 28 (regulation and supervision of DNFBPs). This alignment was a condition of the grey list exit and is now codified in UAE federal law.

5. Cabinet Resolution No. 134 of 2025 — detailed implementing regulations issued alongside the new law, specifying operational requirements for CDD, record-keeping, internal controls, and reporting.

If you are a DNFBP and haven't updated your AML program for DL 10/2025, you are non-compliant

The new law has been in effect since October 2025. If your AML compliance program references Federal Decree-Law No. 20 of 2018, it is referencing a repealed law. Update your policies, procedures, and training materials to reflect the new framework.


What DNFBPs Must Do

If your business falls within any DNFBP category, you have specific obligations under the AML law and its implementing regulations. These are not suggestions — they are legal requirements with administrative and criminal consequences.

1. Customer Due Diligence

Before establishing a business relationship or conducting a transaction, you must:

  • Identify the customer and verify their identity using reliable, independent source documents
  • Identify the beneficial owner and take reasonable measures to verify their identity
  • Understand the purpose and intended nature of the business relationship
  • Conduct ongoing monitoring of the business relationship

Enhanced Due Diligence (EDD) is required for:

  • Customers from high-risk countries (as identified by FATF)
  • Politically Exposed Persons (PEPs) — both domestic and foreign
  • Complex or unusually large transactions
  • Transactions with no apparent economic or lawful purpose

2. STR Reporting

If you suspect — or have reasonable grounds to suspect — that funds are the proceeds of criminal activity or related to terrorism financing, you must:

  • File a Suspicious Transaction Report (STR) through the goAML portal
  • Do so promptly — typically within 24–72 hours of forming the suspicion
  • Not tip off the customer that a report has been filed (tipping off is a criminal offense)

The reporting obligation is proactive. You cannot wait for certainty. "Reasonable grounds to suspect" triggers the obligation.

3. Record-Keeping

Maintain records of:

  • CDD documents — for at least 5 years after the business relationship ends
  • Transaction records — for at least 5 years after the transaction
  • STR filings and related correspondence — indefinitely
  • Internal compliance reviews and training records — for at least 5 years

All records must be available to supervisors and the FIU upon request.

4. Internal Controls

DNFBPs must:

  • Appoint a Compliance Officer (at management level)
  • Establish AML/CFT policies and procedures appropriate to the business's size and risk profile
  • Conduct annual AML training for all relevant employees
  • Implement an independent audit function to test AML controls (for larger DNFBPs)
  • Screen employees against sanctions lists

5. goAML Registration

Register your business on the goAML platform even if you have no suspicious transactions to report. Registration is a prerequisite for STR filing, and failure to register is itself a violation. The FIU actively monitors registration status and cross-references with licensing databases.


The KYC Digital Platform

One of the most operationally significant AML developments is Federal Decree-Law No. 30 of 2024, establishing the "Know Your Customer" (KYC) Digital Platform.

The platform is designed to address a fundamental inefficiency in UAE compliance: every financial institution and many DNFBPs independently verify the identity of the same customers, duplicating effort and cost while creating inconsistent data.

What the KYC Platform does:

  • Creates a centralized, secure repository of verified customer identity information
  • Allows financial institutions and authorized DNFBPs to access verified KYC data (with customer consent)
  • Reduces duplication of KYC effort — verify once, use across institutions
  • Standardizes KYC data format and quality
  • Managed by the UAE Central Bank

What this means for businesses: When opening a bank account, the bank may access your verified KYC data from the platform rather than requesting physical documents. This has the potential to significantly speed up the corporate bank account opening process — but only once the platform is fully operational and populated with data.


The UAE's AML Architecture

The UAE's AML/CFT framework involves multiple agencies. Understanding who does what helps you navigate compliance:

Who does what in the UAE's AML architecture
AgencyRole
Central Bank of the UAE (CBUAE)Primary AML/CFT supervisor for financial institutions. Issues regulations, conducts inspections, imposes sanctions.
Financial Intelligence Unit (FIU)Receives and analyzes STRs via goAML. Disseminates intelligence to law enforcement.
Ministry of EconomySupervises DNFBPs (corporate service providers, auditors, real estate agents). Maintains UBO registers.
Ministry of JusticeProsecutes money laundering and terrorism financing cases.
Executive Office for AML/CFTCoordinates national AML/CFT strategy. Reports to the Higher Committee Overseeing the National Strategy.
VARA (Dubai Virtual Assets Regulatory Authority)Regulates virtual asset service providers in Dubai (outside DIFC).
SCA (Securities and Commodities Authority)Regulates VASPs at federal level and capital market participants.
DFSA / FSRARegulate AML/CFT compliance within DIFC and ADGM respectively.

Penalties for AML Non-Compliance

The new AML law strengthens penalties significantly:

AML Violation Penalties Under DL 10/2025
ViolationAdministrative PenaltyCriminal Consequences
Failure to conduct CDDFines (amount determined by supervisor)Possible criminal referral for systematic failure
Failure to report STRSignificant finesCriminal prosecution for willful blindness
Failure to register on goAMLFinesLicense suspension risk
Tipping off (informing customer of STR)Not applicable — automatic criminalImprisonment and/or fines
Failure to maintain recordsFinesAggravated if records destroyed to obstruct investigation
Failure to appoint compliance officerFinesRegulatory sanctions
Failure to provide AML trainingFinesEscalating penalties for repeat offenses

Frequently Asked Questions


The Bottom Line

The UAE's FATF grey list exit was a regulatory achievement. The laws that enabled it — the new AML law (DL 10/2025), the UBO regime (CD 109 and 132/2023), the KYC Digital Platform (DL 30/2024), and the goAML expansion — are now permanent infrastructure.

For UAE businesses, particularly DNFBPs, the practical message is:

  1. Know your category. Determine whether your business is a DNFBP. If you are unsure, get a legal opinion — the consequences of misclassification are worse than the cost of the advice.

  2. Register on goAML. If required, register now — not when you have a suspicious transaction to report. The FIU is checking.

  3. Update your AML program. If your policies reference Federal Decree-Law No. 20 of 2018, they are referencing a repealed law. Update to DL 10/2025 and CD 134/2025.

  4. Train your team. Annual AML training is mandatory for DNFBPs. Your employees need to know what triggers an STR, how to conduct CDD, and that tipping off is a criminal offense.

The FATF grey list is gone. The compliance burden it created is not.


Sources

  • Federal Decree-Law No. 10 of 2025 — Concerning Combating Money Laundering, Terrorism Financing, and Financing of Proliferation
  • Federal Decree-Law No. 20 of 2018 — Previous AML Law (repealed)
  • Cabinet Resolution No. 134 of 2025 — Implementing Regulations for the New AML Law
  • Cabinet Decision No. 109 of 2023 — Beneficial Owner Procedures
  • Cabinet Decision No. 132 of 2023 — UBO Administrative Penalties
  • Federal Decree-Law No. 30 of 2024 — KYC Digital Platform
  • FATF — UAE Mutual Evaluation Report and Follow-Up Reports (2020–2024)
  • FATF — Statement on UAE Removal from Increased Monitoring (February 2024)
  • UAE Financial Intelligence Unit — goAML Portal
  • UAE Central Bank — AML/CFT Supervision
  • UAE Ministry of Economy — DNFBP Supervision

This article is for informational purposes only and does not constitute legal advice. AML obligations vary by business activity, size, and risk profile. Consult a licensed UAE compliance advisor for guidance specific to your business. Verify current requirements with the relevant supervisory authority.

Emirates Identity Authority
Federal Tax Authority
Government of Dubai
Emirates
FOIZ
DMCC
Dubai Knowledge Park
DIFC

Ready to launch your
UAE business?

Start for Free
MeshMyBiz

UAE Business Setup & Services Platform

Product news and behind-the-scenes updates.

Company

Resources

Legal