
AML in the UAE: The New Test Is Not Compliance, It Is Credibility
In the UAE, anti-money laundering compliance has moved from the back office to the boardroom. The recent focus on UAE AML compliance, CBUAE supervision and regulatory (DIFC and ADGM) compliance in the UAE is not simply about whether a policy exists. It is about whether a business can prove, in real time, that its controls understand the customer, the transaction, the ownership structure and the financial crime risk behind the money.
The direction of travel is clear. The Central Bank of the UAE has intensified AML/CFT/CPF supervision across licensed financial institutions, exchange houses, payment service providers, insurance firms and other financial services providers. Its 2026 guidance places sharper emphasis on risk-based compliance, proliferation financing, trade-based money laundering, correspondent banking, customer due diligence, targeted financial sanctions and meaningful suspicious transaction reporting.
For senior management, the message is uncomfortable but important. Regulators are no longer impressed by binders, templates or annual training slides. They want evidence of judgement. They want to see whether the compliance function has authority, whether internal audit challenges management, whether alerts are investigated properly and whether the board understands the financial crime risks attached to growth.
The rise of the skilled persons review
A key feature of this environment is the CBUAE skilled persons review. Under the regulator’s supervisory approach, licensed financial institutions may be required to appoint an independent professional services firm to review their financial crime compliance programme. The scope can include AML/CFT frameworks, proliferation financing controls, targeted financial sanctions, governance, internal audit effectiveness, transaction monitoring, customer due diligence, reporting quality and remediation discipline.
The reviewer must be credible, independent, suitably experienced and capable of giving the regulator a clear view of whether controls work in practice. This is not a cosmetic exercise. A weak review can expose deeper governance problems. A strong review can help management turn regulatory anxiety into a disciplined improvement plan.
Two short stories from the front line
A UAE-regulated business reached out to us after a supervisory concern around customer due diligence. The policy looked acceptable, but files told a different story. Beneficial ownership was not always refreshed. Risk ratings were static. Enhanced due diligence was treated as a checklist, not a decision. We helped redesign the risk assessment model, rebuild the KYC file review process and create board-level reporting that focused on risk trends rather than administrative completion rates. The result was a more confident compliance function and a clearer remediation trail.
In another case, a fast-growing financial services client was struggling with alert backlogs. The system generated noise, while genuine red flags risked being buried. We worked with management to recalibrate scenarios, strengthen escalation protocols, align suspicious transaction reporting with goAML expectations and train front-office teams to identify behavioural risk. The breakthrough was cultural. Compliance stopped being viewed as a blocker and became a commercial safeguard.
What should boards ask now?
- Do we understand our true AML, CFT and proliferation financing risk exposure?
- Is customer due diligence updated when behaviour changes, not only at onboarding?
- Can our internal audit function independently challenge AML controls?
- Are sanctions screening and transaction monitoring calibrated to our business model?
- Would our documentation withstand a skilled persons review or regulatory inspection?
The UAE’s ambition is to be a trusted global financial centre. That ambition requires institutions to show not only growth, but control. In today’s market, AML weakness is not a compliance gap. It is a strategic risk, a banking risk, a reputational risk and, increasingly, a leadership risk.
How Baker Tilly can help
Baker Tilly can support regulated entities and DNFBPs with AML/CFT/CPF advisory, regulatory gap assessments, CBUAE skilled persons review readiness, independent AML audit, internal audit services, governance reviews, customer due diligence testing, sanctions and transaction monitoring reviews, goAML reporting support, remediation, related preparation and board reporting. Our approach combines regulatory insight with practical business judgement, helping clients move from policy compliance to demonstrable control effectiveness. In a market where trust is capital, strong compliance is no longer defensive. It is a competitive advantage.