UAE: two financial centres, two rulebooks, one federal law
Ask where a UAE firm's AML obligations come from and you will get three correct answers, depending on who you ask. That is not confusion — it is the structure.
Ask where a UAE firm’s AML obligations come from and you will get three correct answers, depending on who you ask. That is not confusion — it is the structure.
The DFSA supervises firms in the Dubai International Financial Centre. The FSRA supervises firms in Abu Dhabi Global Market. Above both sits the federal regime: the Central Bank of the UAE, the Ministry of Economy for DNFBPs and the beneficial-ownership registry, and the AMLSCU as the federal FIU. A firm in either centre lives under a dual regime — the centre’s rulebook and the federal law, at the same time.
The New AML Law was enacted in October 2025, and the UAE underwent its FATF mutual evaluation in June 2026. Both supervisors were visibly preparing for that evaluation, and the posture has not relaxed since.
What each supervisor has actually been doing
DFSA (DIFC). Its Q1 2026 update introduced a firm-led crypto token suitability model and aligned the AML Module with UAE federal law. Enforcement actions have totalled over USD 984,000. The suitability model matters more than the number: responsibility for deciding which tokens a firm will touch has been pushed onto the firm, with the regulator reviewing the decision rather than publishing the list.
FSRA (ADGM). Sixteen enforcement actions to date, including an USD 8.85 million penalty against the HAYVN group and four penalties specifically for AML contraventions. A USD 504,000 settlement in December 2024 covered AML failures spanning nearly six years. Total penalties levied in 2024 were USD 782,666. The FSRA’s 2025–2026 business plan focuses on AI-assisted enforcement and digital forensics — meaning the examiner arrives with tooling, not just a questionnaire.
Two more federal changes worth carrying into your scoping:
- ADGM Whistleblower Protection Regulations came into force on 31 May 2025.
- Cabinet Resolution 134/2025 added gaming operators to the DNFBP definition.
Who supervises what
| Body | Scope |
|---|---|
| DFSA | DIFC firms — banks, DNFBPs, VASPs; digital-asset inspections a stated 2025–26 priority |
| FSRA | ADGM firms — AML/CFT, governance, disclosure; AI-assisted enforcement programme |
| CBUAE | All UAE-licensed institutions; issues federal AML regulations — applies alongside the centres’ rules |
| Ministry of Economy | DNFBPs and designated sectors; beneficial ownership registry |
| AMLSCU | Federal FIU and MENAFATF co-chair; national AML/CFT strategy |
The failure mode
The common failure is not ignorance of either rulebook. It is a programme written against one of them and quietly assumed to satisfy the other. A DIFC firm builds to the DFSA AML Module and treats the federal law as background; an ADGM firm builds to the FSRA rules and discovers at inspection that the CBUAE expectation was the binding one for a particular product.
Six years of undetected failures — the span in that FSRA settlement — is not usually a firm that had no controls. It is a firm whose controls answered a different question than the one being asked.
Three things worth doing this week
- Write down which rulebook governs each obligation. One column per obligation: centre rule, federal rule, or both. The rows where you hesitate are the work.
- If you touch tokens, document the suitability decision — the DFSA model puts the reasoning on you, and an undocumented decision is an unmade one.
- Check whether Cabinet Resolution 134/2025 caught a client of yours. Gaming operators became DNFBPs; some correspondent and payment relationships changed risk tier overnight without anyone re-rating them.
Sources
This article draws on the following sources. Follow the links for the original text.
AML beginner compliance financial-crime jurisdiction-briefing know-your-regulator united-arab-emirates