UAE: two financial centres, two rulebooks, one set of federal AML laws

Two UAE financial free zones have their own financial regulators: the Dubai International Financial Centre (DIFC), supervised by the Dubai Financial Services Authority (DFSA), and Abu Dhabi Global Market (ADGM), supervised by the Financial Services Regulatory…

Illustration for “UAE: two financial centres, two rulebooks, one federal law”

Two UAE financial free zones have their own financial regulators: the Dubai International Financial Centre (DIFC), supervised by the Dubai Financial Services Authority (DFSA), and Abu Dhabi Global Market (ADGM), supervised by the Financial Services Regulatory Authority (FSRA). A firm in either centre works under two layers at once: its centre’s AML rulebook and the UAE’s federal AML legislation. Both rulebooks say so in their overview chapters.

The two supervisors

DFSA (DIFC). Under Article 70(3) of the DIFC Regulatory Law 2004, the DFSA has jurisdiction for anti-money laundering regulation in the DIFC. Its AML module applies to Authorised Firms (other than Credit Rating Agencies), Authorised Market Institutions, DNFBPs and Registered Auditors. A DNFBP must be registered by the DFSA to conduct its activities in the DIFC.

FSRA (ADGM). Under section 15A of the Financial Services and Markets Regulations 2015 (FSMR), the FSRA has jurisdiction for AML and targeted financial sanctions in ADGM. The same section designates it as the supervisory authority for DNFBPs in ADGM, other than legal professionals; for those, the Ministry of Justice is the supervisory authority and may delegate some of its powers. The FSRA has delegated DNFBP registration and supervision to the ADGM Registrar of Companies, but not its enforcement powers. Any entity acting as a virtual asset service provider in ADGM is expected to be an Authorised Person or Recognised Body.

How the federal layer applies

The DFSA’s rulebook describes the DIFC as governed by “two separate and complementary regimes” for AML, both administered by the DFSA:

  • The federal regime. Under Article 3 of Federal Law No. 8 of 2004, Federal Decree-Law No. 10 of 2025, Federal Law No. 7 of 2014 and their implementing regulations apply in the DIFC. The DFSA, as the DIFC’s supervisory authority for those laws, must supervise firms’ compliance with them and may impose administrative penalties for breaches.
  • The DIFC regime. The Regulatory Law and the DFSA’s AML Rules. The Regulatory Law also requires compliance with the federal regime, so a breach of federal AML law may also be evidence of a breach of the Regulatory Law, and be dealt with under its disciplinary provisions.

ADGM is built the same way. The FSRA’s AML Rulebook states that federal AML legislation applies in ADGM, that firms must comply with it as well as the FSRA’s regulations and rules, and that a federal breach may also be evidence of a breach of FSMR, addressed with the FSRA’s supervisory and enforcement powers.

“Federal AML legislation” is not a single law. The DFSA’s glossary defines it as all federal laws and implementing regulations on money laundering, terrorist financing, proliferation financing and sanctions compliance, including these four:

InstrumentWhat it is
Federal Decree-Law No. 10 of 2025The anti-money laundering, terrorist financing and proliferation financing law; issued 30 September 2025, in force 14 October 2025
Cabinet Resolution No. 134 of 2025Its executive regulations; in force 14 December 2025
Federal Law No. 7 of 2014Combating terrorism offences
Cabinet Decision No. 74 of 2020Terrorism lists and implementation of UN Security Council resolutions

The federal rules can change a firm’s scope directly. Cabinet Resolution 134/2025, for example, lists commercial gaming operators as DNFBPs when they conduct a single financial transaction, or several that appear to be linked, of AED 11,000 or more.

The federal bodies both centres point to

  • The UAE Financial Intelligence Unit (FIU). Decree-Law 10/2025 establishes it within the Central Bank, acting independently. Financial institutions, DNFBPs and virtual asset service providers submit all suspicious transaction reports to it exclusively. In the DIFC, where a report is required, the MLRO makes it to the FIU and notifies the DFSA immediately after submitting it. In ADGM, reports are made to the FIU through goAML.
  • The National Committee for combating money laundering, terrorist financing and proliferation financing, chaired by the Central Bank Governor. It establishes the national strategy, identifies high-risk countries and determines countermeasures, and directs supervisory authorities to verify that firms apply them.
  • The Executive Office for Control and Non-Proliferation (EOCN). It administers Cabinet Decision 74/2020 and is the focal point for implementing targeted financial sanctions; the AML law requires firms to implement its instructions on those sanctions.

One boundary is worth knowing: the Central Bank’s own law, Federal Decree-Law No. 6 of 2025, does not apply to the financial free zones or to the financial institutions regulated by their authorities.

What the supervisors have done recently

  • DFSA. Amendments to its AML module to align with federal AML legislation came into force on 2 March 2026. Since 12 January 2026, firms dealing in crypto tokens have been responsible for deciding, on a reasoned and documented basis, whether each token meets the DFSA’s suitability criteria. For fiat crypto tokens, the DFSA itself must be satisfied that the token is suitable.
  • FSRA. In 2025 it finalised 38 regulatory actions and imposed 37 financial penalties totalling USD 9.24 million. They included penalties totalling USD 8.85 million across four parties involved in unlicensed virtual asset activity, the withdrawal of a legal professional’s DNFBP registration for ongoing AML breaches, action against a further three DNFBPs for AML breaches, and action against an Authorised Person for AML breaches in December 2025.

The FSRA’s 2025 annual report describes the UAE’s mutual evaluation as scheduled for June 2026, and both supervisors’ 2025–2026 business plans set out preparations for the 2026 FATF evaluation.

Three things worth doing this week

  1. Map each AML obligation to its source. One column for the centre rule, one for the federal instrument. Where only one column is filled, check whether the other layer adds a requirement.
  2. Walk through your reporting path end to end. A DIFC firm files with the FIU and then tells the DFSA; an ADGM firm files with the FIU through goAML. Test that each step actually happens.
  3. Read the federal texts themselves. Both rulebooks say their rules should not be relied on to interpret federal AML legislation.

SonarPulse in this jurisdiction: AML/CFT screening software for the UAE, ADGM and DIFC


Sources

This article draws on the following sources. Follow the links for the original text.

Start with a compliance health check.

A working session with your compliance team, then a walkthrough against your own risk appetite: the lifecycle end to end, scoring weights set to your policy, and a review of the audit trail the system produces.

Or write to info@sonarpulse.mu