Your AML/CFT Policy and Procedures Manual is the foundation of your entire compliance programme. It's the document that tells regulators — and your own staff — how your business identifies, assesses, and manages money laundering and terrorist financing risk.
Without a written policy, you cannot demonstrate compliance, even if you're doing the right things in practice. And a policy that was downloaded from the internet or recycled from another business — without being tailored to your specific operations — will likely fail a supervisory inspection.
Under UAE Federal Decree-Law No. 10 of 2025, all designated entities must have written AML/CFT policies and procedures that are approved by senior management and reviewed annually. This guide explains what must be included, section by section.
What Must an AML Policy Manual Contain?
A compliant UAE AML/CFT Policy and Procedures Manual typically contains the following core sections:
Introduction and Scope
Defines the purpose of the policy, the applicable UAE law (Federal Decree-Law No. 10 of 2025, Cabinet Decision No. 10 of 2019, relevant ministerial decisions), and which parts of the business and which staff the policy covers. Also identifies the supervisory authority under which the entity operates.
Governance and Roles
Describes the AML compliance structure: the role of the Board/Senior Management, the appointment and authority of the MLRO/Compliance Officer, compliance reporting lines, and staff responsibilities. This section must clearly show who is accountable for AML compliance and what authority they have to enforce it.
Business Risk Assessment
Summarises how the Business Risk Assessment (BRA) is conducted — the methodology, the inherent risk factors assessed (customer types, products/services, geographies, delivery channels), and how residual risk is scored. The BRA itself is usually a separate document referenced here.
Customer Acceptance Policy
Defines which customers the business will and will not accept. Specifies prohibited customer types (e.g. anonymous customers, shell banks, customers from prohibited jurisdictions), conditions for accepting higher-risk customers, and the escalation process for borderline cases.
KYC and Customer Due Diligence Procedures
The most detailed section. Covers:
- CDD requirements for individual and corporate customers
- Beneficial ownership identification procedures
- PEP screening and EDD requirements
- Simplified Due Diligence conditions (if applicable)
- Non-face-to-face onboarding controls
- Ongoing monitoring and periodic review frequencies by risk tier
- What to do when CDD cannot be completed
Transaction Monitoring
Describes how the business monitors customer transactions for unusual or suspicious patterns. Includes the monitoring methodology (automated systems, manual review, or both), red flags and typologies relevant to the business sector, and escalation procedures when suspicious activity is identified.
Suspicious Transaction and Activity Reporting (STR/SAR)
Sets out the full process from identification of suspicion to submission of a report to the UAE FIU via the goAML portal. Includes internal escalation procedures, tipping-off prohibition, protection of staff who file reports in good faith, and record-keeping requirements for filed reports.
Sanctions Screening and TFS Compliance
Details how the business screens customers and transactions against UN consolidated sanctions lists, UAE Local Terrorist Lists, and other applicable sanctions lists. Covers the frequency of screening, what to do when a match is found, and how Partial Name Match Reports (PNMRs) and Complete Name Match Reports (CNMRs) are filed via goAML.
Record Keeping
Specifies what records must be retained (customer identification documents, transaction records, CDD files, STR records), the 5-year retention period required by UAE law, the format and storage method for records, and how records are made available to supervisory authorities on request.
AML Training and Awareness
Describes the training programme: who must be trained (all staff, with tailored depth by role), frequency (at minimum annually), topics covered, and how training completion is documented. New staff training requirements before they commence customer-facing work should also be addressed here.
Independent Audit and Review
Explains how the AML compliance programme is independently reviewed — whether through an internal audit function or external AML audit — the frequency of review, how findings are reported to senior management, and how the remediation of identified gaps is tracked.
Regulatory Reporting and FIU Liaison
Covers all mandatory regulatory reporting obligations beyond STRs — including any sector-specific reports (e.g. DPMSR for precious metals dealers, HRC reports for high-risk country transactions), interaction with supervisory authority examinations, and co-operation obligations with the UAE FIU.
Common Mistakes in UAE AML Policies
These are the most frequent reasons an AML policy fails a UAE supervisory inspection:
- The policy is a generic template with no reference to the entity's actual business, products, or customers
- Roles and responsibilities are vague — no named MLRO with documented authority
- CDD procedures don't address beneficial ownership in any meaningful way
- The sanctions screening section doesn't reference the UAE Local Terrorist List or the automatic reporting obligation for matches
- The policy has not been reviewed or updated since the introduction of Federal Decree-Law No. 10 of 2025
- Senior management approval is not documented — no sign-off date, no version history
- The policy exists but staff have never read it — no training records to demonstrate dissemination
How Often Must the Policy Be Reviewed?
UAE law requires the AML/CFT policy to be reviewed at least annually, and additionally whenever there are significant changes to:
- The applicable law or regulatory guidance
- The business's products, services, or customer base
- The business's risk profile (e.g. expansion into new markets)
- The MLRO or senior compliance personnel
Get Professional AML Policy Drafting Support
AML Expert UAE drafts custom AML/CFT Policy and Procedures Manuals tailored to each client's specific business, sector, and risk profile. We don't use generic templates — every policy is built from your Business Risk Assessment, and cross-referenced with the latest UAE regulatory guidance.
We serve financial institutions, DNFBPs, VASPs, and all other designated entities across all UAE emirates and free zones.
Need a Compliant AML Policy?
We draft AML/CFT Policy and Procedures Manuals that are tailored to your business and ready for supervisory inspection. Request a free consultation today.
Free Consultation