AML Policy

How to Write an AML Policy & Procedures Manual for UAE

August 2026  ·  8 min read  ·  By AML Expert UAE

Your AML/CFT Policy and Procedures Manual is the foundation of your entire compliance programme. It's the document that tells regulators — and your own staff — how your business identifies, assesses, and manages money laundering and terrorist financing risk.

Without a written policy, you cannot demonstrate compliance, even if you're doing the right things in practice. And a policy that was downloaded from the internet or recycled from another business — without being tailored to your specific operations — will likely fail a supervisory inspection.

Under UAE Federal Decree-Law No. 10 of 2025, all designated entities must have written AML/CFT policies and procedures that are approved by senior management and reviewed annually. This guide explains what must be included, section by section.

Warning: Generic "template" AML policies found online or purchased cheaply do not meet UAE supervisory requirements. Inspectors review policies for business-specific content and reject cookie-cutter documents.

What Must an AML Policy Manual Contain?

A compliant UAE AML/CFT Policy and Procedures Manual typically contains the following core sections:

Section 1

Introduction and Scope

Defines the purpose of the policy, the applicable UAE law (Federal Decree-Law No. 10 of 2025, Cabinet Decision No. 10 of 2019, relevant ministerial decisions), and which parts of the business and which staff the policy covers. Also identifies the supervisory authority under which the entity operates.

Section 2

Governance and Roles

Describes the AML compliance structure: the role of the Board/Senior Management, the appointment and authority of the MLRO/Compliance Officer, compliance reporting lines, and staff responsibilities. This section must clearly show who is accountable for AML compliance and what authority they have to enforce it.

Section 3

Business Risk Assessment

Summarises how the Business Risk Assessment (BRA) is conducted — the methodology, the inherent risk factors assessed (customer types, products/services, geographies, delivery channels), and how residual risk is scored. The BRA itself is usually a separate document referenced here.

Section 4

Customer Acceptance Policy

Defines which customers the business will and will not accept. Specifies prohibited customer types (e.g. anonymous customers, shell banks, customers from prohibited jurisdictions), conditions for accepting higher-risk customers, and the escalation process for borderline cases.

Section 5

KYC and Customer Due Diligence Procedures

The most detailed section. Covers:

  • CDD requirements for individual and corporate customers
  • Beneficial ownership identification procedures
  • PEP screening and EDD requirements
  • Simplified Due Diligence conditions (if applicable)
  • Non-face-to-face onboarding controls
  • Ongoing monitoring and periodic review frequencies by risk tier
  • What to do when CDD cannot be completed
Section 6

Transaction Monitoring

Describes how the business monitors customer transactions for unusual or suspicious patterns. Includes the monitoring methodology (automated systems, manual review, or both), red flags and typologies relevant to the business sector, and escalation procedures when suspicious activity is identified.

Section 7

Suspicious Transaction and Activity Reporting (STR/SAR)

Sets out the full process from identification of suspicion to submission of a report to the UAE FIU via the goAML portal. Includes internal escalation procedures, tipping-off prohibition, protection of staff who file reports in good faith, and record-keeping requirements for filed reports.

Section 8

Sanctions Screening and TFS Compliance

Details how the business screens customers and transactions against UN consolidated sanctions lists, UAE Local Terrorist Lists, and other applicable sanctions lists. Covers the frequency of screening, what to do when a match is found, and how Partial Name Match Reports (PNMRs) and Complete Name Match Reports (CNMRs) are filed via goAML.

Section 9

Record Keeping

Specifies what records must be retained (customer identification documents, transaction records, CDD files, STR records), the 5-year retention period required by UAE law, the format and storage method for records, and how records are made available to supervisory authorities on request.

Section 10

AML Training and Awareness

Describes the training programme: who must be trained (all staff, with tailored depth by role), frequency (at minimum annually), topics covered, and how training completion is documented. New staff training requirements before they commence customer-facing work should also be addressed here.

Section 11

Independent Audit and Review

Explains how the AML compliance programme is independently reviewed — whether through an internal audit function or external AML audit — the frequency of review, how findings are reported to senior management, and how the remediation of identified gaps is tracked.

Section 12

Regulatory Reporting and FIU Liaison

Covers all mandatory regulatory reporting obligations beyond STRs — including any sector-specific reports (e.g. DPMSR for precious metals dealers, HRC reports for high-risk country transactions), interaction with supervisory authority examinations, and co-operation obligations with the UAE FIU.

Common Mistakes in UAE AML Policies

These are the most frequent reasons an AML policy fails a UAE supervisory inspection:

How Often Must the Policy Be Reviewed?

UAE law requires the AML/CFT policy to be reviewed at least annually, and additionally whenever there are significant changes to:

Best practice: Build the annual policy review into your compliance calendar and document it with a version log showing the date of review, changes made, and senior management sign-off. Inspectors look for this evidence.

Get Professional AML Policy Drafting Support

AML Expert UAE drafts custom AML/CFT Policy and Procedures Manuals tailored to each client's specific business, sector, and risk profile. We don't use generic templates — every policy is built from your Business Risk Assessment, and cross-referenced with the latest UAE regulatory guidance.

We serve financial institutions, DNFBPs, VASPs, and all other designated entities across all UAE emirates and free zones.

Need a Compliant AML Policy?

We draft AML/CFT Policy and Procedures Manuals that are tailored to your business and ready for supervisory inspection. Request a free consultation today.

Free Consultation