DIFC: what the DFSA’s 2 March 2026 amendments changed in the AML module

On 26 February 2026 the DFSA issued a Notice of Amendments to Legislation. Its Board had made the AML Rule-Making Instrument (No. 435) 2026 and the Glossary Module Rule-Making Instrument (No. 436) 2026, both to come into force on 2 March 2026. The DFSA's…

Illustration for “DIFC: what the DFSA's 2 March 2026 amendments changed in the AML module”

On 26 February 2026 the DFSA issued a Notice of Amendments to Legislation. Its Board had made the AML Rule-Making Instrument (No. 435) 2026 and the Glossary Module Rule-Making Instrument (No. 436) 2026, both to come into force on 2 March 2026. The DFSA’s stated purpose was short: “to make various amendments to align with Federal AML legislation”.

A notice like that is easy to file as a find-and-replace on statute names. Part of it is exactly that. But the appendix to the notice, which shows new text underlined and deleted text struck through, also changes what must sit in a customer file, who approves the firm’s AML policies, what the MLRO is responsible for, and one phrase in the suspicious activity reporting Rule. This briefing separates the two.

Which text this is

The version read here is the consolidated module stamped AML/VER30/04-26, which the DFSA’s rulebook site lists as the current AML module. It carries the 2 March amendments and one later change, covered below. For the wording before the amendments, this briefing uses the consolidated version stamped AML/VER28/12-25.

One caution from the document itself. The consolidated version states on its cover that it is meant purely as a documentation tool and has no legal effect, and that the authentic versions of the rulemaking instruments are those published on the DFSA website.

The module applies to Relevant Persons: an Authorised Firm other than a Credit Rating Agency, an Authorised Market Institution, a DNFBP, or a Registered Auditor.

The federal references now point at the 2025 instruments

Before 2 March, the module’s glossary defined “Federal AML legislation” by naming Federal Law No. 20 of 2018 and Cabinet Decision No. 10 of 2019. It now names Federal Law No. 10 of 2025, Federal Law No. 7 of 2014, Cabinet Resolution No. 134 of 2025 and Cabinet Decision No. 74 of 2020. “Federal Law No. 10 of 2025” is the module’s own label; the Central Bank of the UAE’s rulebook publishes the instrument of that number and subject as Federal Decree by Law No. (10) of 2025, effective from 14 October 2025 and shown as in force.

Several consequential edits follow from that:

  • “Money laundering” in lower case. Rule 3.1.1 used to say the term includes terrorist financing, the financing of illegal organisations and proliferation financing. It now says terrorist financing and proliferation financing.
  • The National Committee. Rule 10.3.1 lists the bodies whose findings a firm must stay informed of and take reasonable steps to comply with. Item (d) was the body the module abbreviated to NAMLCFTC; it is now “the National Committee”, which the glossary defines as the National Committee for Anti-Money Laundering, Combating the Financing of Terrorism, and Proliferation Financing.
  • Who can freeze. The overview Guidance used to say the U.A.E Central Bank has the power under Federal AML legislation to freeze funds or other assets. It now says the FIU has that power.
  • Administrative penalties. Rules 14.8.1 and 14.8.2 now refer to a DFSA decision to impose an administrative penalty under Article 17(1) of Federal Law No. 10 of 2025. The procedures in Schedule 3 to the Regulatory Law apply to that decision, and the person concerned may refer the matter to the FMT for review.

What changed in the customer file

This is the part that needs an onboarding form change. Rule 7.3.2 sets out what a firm must obtain and verify to identify a customer, and the amendments added to its lists for natural persons and for bodies corporate.

Natural persons — Rule 7.3.2(2). Item (b) was “date of birth”. It is now “date and place of birth”. A new item (f) is added: where applicable, the name and address of the person’s employer.

Bodies corporate — Rule 7.3.2(3). The list used to end at (f), the full names of senior management. It now continues:

> “(g) the legal form; (h) the tax registration number (if any); (i) the > unique reference number (if any); and (j) if the body corporate is > constituted under the law of any country or territory outside the U.A.E., > the name and address of its legal representative in the U.A.E. (if any).”

Keep the qualifiers when you write this into procedure. Employer details are “where applicable”; the tax registration number, the unique reference number and the U.A.E. legal representative are each “(if any)”. The Rule’s verb for all of them is the same as for the name: obtain and verify.

Beneficial owners — Guidance, not a Rule. The Guidance on identifying beneficial owners gained a new opening. A firm should be aware of its obligations under Federal AML legislation to have or obtain adequate information to identify the beneficial owners, and that information includes each beneficial owner’s full name, nationality, date and place of birth, residential address, identity number and type, tax registration number (where applicable), and any other relevant information. The DFSA’s existing position on thresholds sits unchanged in the same paragraph: it does not set explicit ownership or control thresholds in defining the Beneficial Owner.

For customers already on the books, look to the ongoing CDD Rule. Rule 7.6.1(1)(d) requires a firm to review the adequacy of the CDD information it holds on customers and beneficial owners to ensure that it is kept up to date, particularly for customers with a high risk rating, and Rule 7.6.1(2) requires that review periodically and at other appropriate times when a material change or event occurs.

Senior management, the MLRO and one phrase in the SAR Rule

Policies approved by senior management. Rule 5.2.1(a) already required effective policies, procedures, systems and controls to prevent opportunities for money laundering. The amendment inserted a condition: they must be approved by the Relevant Person’s senior management. That sits alongside Rule 1.2.1(1), under which responsibility for a firm’s compliance with the module lies with every member of its senior management.

A new MLRO responsibility. Rule 11.4.1 lists the matters the MLRO implements, has oversight of and is responsible for. A new item (i) was added: reviewing and assessing the firm’s AML policies, procedures, systems and controls for consistency with the Rules and Federal AML legislation and, if necessary, recommending updates and enhancements.

“As soon as practicable” is gone. Rule 13.3.1 says what the MLRO must do, “without delay”, on receiving an internal notification: inquire into and document the circumstances, determine whether a Suspicious Activity Report must be made to the FIU and document that determination, make the report if required, and notify the DFSA immediately following its submission to the FIU. Before 2 March, limb (c) read “makes a Suspicious Activity Report to the FIU as soon as practicable”. Those closing words were deleted, which leaves “without delay” at the head of the Rule as the timing for limb (c). A SAR procedure that borrowed the deleted phrase is quoting a Rule that no longer says it.

New signposts to Cabinet Resolution 134 of 2025

The amendments added or re-pointed a set of cross-references to specific federal articles. Every one of these is Guidance:

  • Targeted financial sanctions. The Guidance under Rules 7.6.2 and 10.2.1 now refers to Article 28 of Cabinet Resolution No. 134 of 2025 together with Article 21 of Cabinet Decision No. 74 of 2020, and the obligations it summarises now include applying transaction prohibition measures as well as applying or cancelling freezing orders. The Rule itself, 10.2.1(2), still names only Article 21 of Cabinet Decision No. 74 of 2020.
  • Correspondent relationships. New Guidance under Rule 9.2.2, the Shell Bank Rule, says an Authorised Firm should be aware of Article 26 of Cabinet Resolution No. 134 of 2025, which applies similar requirements to other similar relationships with respondent institutions.

Read these with paragraph 20 of the module’s overview, which the amendments did not touch: Rules or Guidance in the module should not be relied upon to interpret or determine the application of the Federal AML legislation. The signposts tell you which article to open.

DNFBPs: the real estate definition, registration and notifications

The real estate limb of the DNFBP definition changed by a few words. It used to cover a real estate developer or agency which carries out transactions “with a customer” involving the buying or selling of real property. It now covers one which carries out transactions “for or on behalf of a customer”.

For applicants, new Guidance under Rule 15.1.2 says that in assessing whether an applicant has adequate resources and systems and controls, the DFSA will need to be satisfied that the applicant will comply with Article 21 on Internal Supervision of Cabinet Resolution No. 134 of 2025.

And the later change mentioned above belongs here. A separate instrument, the AML Rule-Making Instrument (No. 432) 2026, came into force on 1 April 2026; the DFSA’s notice, issued on 5 March 2026, says it followed Consultation Paper No. 169. It added item (g), “main activities”, to the changes a DNFBP must notify to the DFSA under Rule 15.1.4 — before the change takes effect, or promptly thereafter if it is not possible to notify before then.

One paragraph to check by hand

The first paragraph of the Chapter 2 Guidance in AML/VER30/04-26 still says that a reference to “money laundering” also includes terrorist financing, the financing of illegal organisations and proliferation financing, and it points the reader to Rule 3.1.1. Rule 3.1.1, as amended, no longer mentions the financing of illegal organisations. If your policy’s definitions section was lifted from the overview rather than from the Rule, it carries the older list.

What to do with this

  1. Change the forms, then the files. Add the new Rule 7.3.2 items to onboarding for individuals and bodies corporate, with their qualifiers. Decide how the periodic review under Rule 7.6.1 will pick the same items up for existing customers, and write that decision down.
  2. Evidence the approval. Keep a dated record that senior management approved the current versions of the AML policies and procedures.
  3. Put the review in the MLRO’s calendar. Rule 11.4.1(i) makes the consistency review an MLRO responsibility. Schedule it and keep its output.
  4. Reword the SAR procedure. Where it describes the filing step, replace “as soon as practicable” with “without delay”.
  5. Update the citations. Replace references to Federal Law No. 20 of 2018, Cabinet Decision No. 10 of 2019 and NAMLCFTC in policies, training and templates, and open the federal articles the Guidance now signposts.

SonarPulse in this jurisdiction: AML/CFT screening software for the UAE, ADGM and DIFC


Sources

This article draws on the following sources. Follow the links for the original text.

Start with a compliance health check.

A working session with your compliance team, then a walkthrough against your own risk appetite: the lifecycle end to end, scoring weights set to your policy, and a review of the audit trail the system produces.

Or write to info@sonarpulse.mu