UAE: Cabinet Resolution 134/2025 repealed the 2019 executive regulations

If your UAE AML policy still cites Cabinet Decision No. (10) of 2019 — the implementing regulation of Decree-Law No. (20) of 2018 — it cites an instrument that no longer exists. The CBUAE Rulebook records its status as Repealed.

Illustration for “UAE: Cabinet Resolution 134/2025 repealed the 2019 executive regulations”

If your UAE AML policy still cites Cabinet Decision No. (10) of 2019 — the implementing regulation of Decree-Law No. (20) of 2018 — it cites an instrument that no longer exists. The CBUAE Rulebook records its status as Repealed.

What replaced it is Cabinet Resolution No. (134) of 2025, the Executive Regulations of Federal Decree by Law No. (10) of 2025. The Rulebook gives it the reference CAB RES 134/2025, shows it effective from 14 December 2025, and lists its status as In-Force.

This is a replacement, not an amendment

Article (70) is one sentence and leaves nothing standing:

> “Cabinet Resolution No. (10) of 2019, referred to herein, is hereby repealed, > and any provision that contradicts or conflicts with the provisions of this > Resolution is also repealed.”

Article (71) sets the mechanism: the Resolution is published in the Official Gazette and enters into force thirty days after the date of publication.

The shape of the instrument changed with it. The 2019 regulation ended at Article (62), in a Chapter 8 headed Final Provisions. Resolution 134/2025 ends at Article (71), in a Chapter Nine. Where 2019 had a single Chapter 7 on International Cooperation, the 2025 text splits the ground into a Chapter Seven on National Cooperation and Coordination and a Chapter Eight on International Cooperation and Asset Recovery. Chapter Three is now headed Transparency and Beneficial Ownership, where 2019 read Transparency and Beneficial Owner.

So a gap-check cannot be a search-and-replace on the citation line. The numbers have moved with the text: the beneficial ownership chapter opened at Article (34) in 2019 and opens at Article (37) now.

What did not move: the headline money thresholds

Worth saying plainly, because it is the half of the exercise that produces the least work.

Under Article (7), financial institutions apply customer due diligence to occasional transactions at or above AED 55,000, whether in a single transaction or several that appear to be linked, and to occasional transactions in the form of wire transfers at or above AED 3,500. Virtual asset service providers apply CDD to occasional transactions at or above AED 3,500, single or linked. The 2019 text carried the same AED 55,000 and AED 3,500 figures for financial institutions.

The wire-transfer mechanics in Article (28) also hold their shape. An originating institution verifies originator information for international wire transfers at or above AED 3,500. Transfers below that figure must still be accompanied by the same data, without the need to verify its accuracy, unless there are suspicions of the commission of the Crime, which is the Resolution’s collective term for the offences it covers. Under Article (30), a beneficiary institution verifies the beneficiary’s identity for international wire transfers at or above AED 3,500 where that identity has not already been verified.

A thresholds table built on the 2019 figures still holds for these tests. That is the easy half of the exercise.

What did move: scope, definitions and powers

Scope. Article (3) opens the DNFBP list with Commercial Gaming Operators, including commercial gaming conducted on board vessels or marine craft, when they conduct a single financial transaction, or several that appear to be linked, of AED 11,000 or more. The article then carves out a category of activity in a sentence of its own: a financial transaction does not include a transaction that solely involves gaming chips or gaming instruments. Both halves matter — the threshold and the carve-out — and a policy that reproduces only the first overstates the obligation. The 2019 DNFBP list as published on the Rulebook has no gaming category at all; it begins with real estate brokers and agents.

Dealers in valuable metals and precious stones are DNFBPs when carrying out any single cash transaction, or several linked transactions, of AED 55,000 or more. The cash qualifier is in the article and belongs in the policy.

Definitions. Article (1) defines five terms a gap-check should search for by name: Senior Management, Nominee Director, Nominee Shareholder, Nominator and Trust Protector. Senior Management turns on decision-making authority — the person or persons who take strategic and executive decisions materially affecting risk management, compliance policies and operational governance — with chief executive officers, general managers and board members given as examples. A nominee director or nominee shareholder is expressly not the beneficial owner by virtue of that capacity, which removes a shortcut in ownership analysis.

Beneficial ownership. Under Article (38), companies must update both their basic information and their beneficial owner information within fifteen (15) working days of any amendment or change, and verify accuracy on an ongoing basis. Article (39) puts the mirror-image duty on the nominee: disclose the capacity and the Nominator’s identity to the company, and report any change within fifteen working days. Article (38) also prohibits the issue of bearer shares, bearer share warrants and similar untraceable instruments, and requires those issued before the Resolution entered into force to be converted into registered shares within thirty working days of publication. Article (40) sets a retention floor of not less than five years after dissolution.

FIU powers. This is the change most likely to reach your front line. Under Article (51), the Chief of the Unit may order the suspension or cessation of a transaction suspected of being related to the Crime, immediately and without prior notice, for a period not exceeding ten working days. Separately, the Chief may order the freezing of suspected funds held by financial institutions, DNFBPs or virtual asset service providers, without prior notice, for a period of thirty days, with extension by the Attorney General or their delegate. The 2019 equivalent sat elsewhere: the Governor ordered freezing, for no more than seven working days, and only at financial institutions licensed by the Central Bank.

The compliance officer. Article (22) requires the compliance officer to be appointed at management level, with independence in decision-making, and extends the duty to virtual asset service providers alongside financial institutions and DNFBPs. Periodic reports go directly to Senior Management — now a defined term.

Four things a gap-check has to cover

  1. Re-cite, then re-read. Replace every reference to Cabinet Decision 10/2019 and Decree-Law 20/2018, then open the new article and check the wording. The numbering has shifted.
  2. Re-test the DNFBP perimeter. If you bank, insure or serve gaming operators or precious-metals dealers, the trigger tests are AED 11,000 (with the chips and gaming-instruments carve-out) and AED 55,000 in cash.
  3. Name your Senior Management. The term is now defined, and the compliance officer reports to it. Write down who that is, and record the management-level appointment and the officer’s decision-making independence.
  4. Rehearse an Article (51) order. Ten working days to suspend, thirty days to freeze, no prior notice, and the freeze can land on a VASP. Check who in your firm receives such an order out of hours, who notifies the owner of the frozen funds as Article (51) requires, and who lifts it when it expires unextended.

Sources

This article draws on the following sources. Follow the links for the original text.

Start with a compliance health check.

A working session with your compliance team, then a walkthrough against your own risk appetite: the lifecycle end to end, scoring weights set to your policy, and a review of the audit trail the system produces.

Or write to info@sonarpulse.mu