01
Document overview
Practical AML/CFT/CPF rules for banks, exchange houses, payment services, VASPs, DNFBPs, non-profits, companies and trusts.
- KYC, risk assessment, PEPs and beneficial ownership.
- Rules for exchange houses, payment transfers and virtual assets.
- STRs, freezing, financial intelligence and international cooperation.
02
Scope and exclusions
Applies to
Executive regulation of the federal AML/CFT/CPF regime. It sets practical duties for financial institutions, exchange houses and other money or value transfer service providers, virtual-asset service providers, designated non-financial businesses and professions, non-profit organisations, registrars, companies, trustees and other participants in legal arrangements. It covers risk assessment, KYC and beneficial ownership, PEPs, suspicious transaction reports, wire and virtual-asset transfers, record keeping, financial intelligence, freezing and international cooperation.
Limitations and exclusions
The Regulation is not a banking, payment, exchange-house or VASP licence and does not replace sector-specific Central Bank rules, free-zone regulator rules, targeted-financial-sanctions directions, sector requirements or other special regimes. Professional privilege limits reporting only in the express Article 18 case and is not a general exemption. Article 70 repeals Cabinet Resolution No. 10 of 2019.
03
Document text
This view displays an English translation published by the FTA and expressly labelled unofficial; the Decision's Arabic text controls in the event of divergence.
Preamble
Official English translation — Arabic text controlsPermanent link →Cabinet Resolution
The Cabinet: − Having reviewed the Constitution; − Federal Law No. (1) of 1972 Regarding the Competences of the Ministries and the Powers of Ministers, as amended; − Federal Decree by Law No. (10) of 2025 Regarding Anti-Money Laundering, and Combating the Financing of Terrorism and Proliferation Financing; − Cabinet Resolution No. (10) of 2019 Regarding the Executive Regulations of Federal Decree by Law No. (20) of 2018 Regarding Anti-Money Laundering, and Combating the Financing of Terrorism and Illegal Organizations, as amended; − Upon the proposal of the Minister of Finance, and the approval of the Cabinet; Hereby resolves as follows:
Article (1)
Official English translation — Arabic text controlsPermanent link →Chapter One: Definitions
The definitions set forth in Federal Decree by Law No. (10) of 2025, referred to hereinabove, shall apply to this Resolution. In addition, the following terms and expressions shall have the meanings assigned to each of them, unless the context requires otherwise: Companies: Companies, regardless of their type or activity, that are subject to the provisions of the legislation in force in the State. Senior Management: The person or persons vested with authority to take strategic and executive decisions materially affecting risk management, compliance policies, and operational governance, including chief executive officers, general managers, members of the board of directors, or any person occupying a position that enables them to directly influence the conduct of business and internal policies, including compliance policies. Intermediary Financial Institution: A Financial Institution that, in the payment chain, receives and transmits a funds transfer between the originating Financial Institution and the Beneficiary Financial Institution, or another Intermediary Financial Institution. Beneficiary Financial Institution: The Financial Institution that receives the transfer from the originating Financial Institution, either directly or through an Intermediary Financial Institution, for the benefit of the Beneficiary, and which constitutes the end point in the payment chain. Financial Institutions: Any person engaging in one or more financial activities or operations for the benefit of, or on behalf of, a Customer, as stipulated in Article (2) of this Resolution. Designated Non-Financial Businesses and Professions (DNFBPs): Any person engaging in one or more commercial or professional activities or businesses for the benefit of, or on behalf of, a Customer, as stipulated in Article (3) of this Resolution. Commercial Gaming: Any game of chance, or any form of chance-based or skill-based practice, involving the placement of a monetary stake for the purpose of winning money or any other item of value, including agreements whereby the loser must compensate the winner with money or any other agreed consideration. This includes, without limitation, lottery operations, Commercial Gaming halls, internet gaming, sports wagering, and any other licensed games of chance or opportunity regulated by the General Commercial Gaming Regulatory Authority, whether conducted within gaming premises or elsewhere. Commercial Gaming Operators: Any person who carries out the operation of Commercial Gaming halls, internet Commercial Gaming, sports betting, or lottery gaming. Virtual Asset Service Providers: Any person who, as a commercial activity, conducts one or more Virtual Asset activities or related operations for the benefit of, or on behalf of, another natural or legal person, as stipulated in Article (4) of this Resolution. Trust Protector: A natural or legal person appointed pursuant to a Trust deed and granted powers and authorities for the purpose of protecting the Trust, ensuring its proper administration, and achieving its objectives, without such powers prejudicing its legal independence or resulting in the transfer of assets to the benefit of the settlor, or the settlor’s effective control over them. Nominator: One or more natural or legal persons who issue instructions, directly or indirectly, to a nominee acting on their behalf as a Nominee Director or Nominee Shareholder of a legal person. Nominee Shareholder: A natural or legal person who exercises voting rights in accordance with the instructions of the Nominator, or receives dividends on their behalf, and shall not be deemed the Beneficial Owner of a legal person by virtue of holding shares in a nominee capacity. Nominee Director: A natural or legal person who customarily performs management functions in a company on behalf of the Nominator and in accordance with their instructions, and shall not be deemed the Beneficial Owner of a legal person. Beneficial Owner: The natural person who owns or exercises ultimate effective control over the Customer, or the natural person on whose behalf Transactions are conducted, including any natural person exercising ultimate effective control over a legal person or Legal Arrangement, whether directly or through a chain of ownership or control or by any other indirect means, and who is identified, whether one or more persons, in accordance with Article (10) of this Resolution. Reasonable Measures: Measures taken within the framework of Customer Due Diligence and Beneficial Owner identification procedures, proportionate to the risks of Money Laundering, Financing of Terrorism, or Proliferation Financing. Business Relationship: Any ongoing commercial or financial relationship established between Financial Institutions, DNFBPs, or Virtual Asset Service Providers and their Customer, in connection with the activities or services they provide to the Customer. Correspondent Banking Relationship: A relationship between a correspondent Financial Institution and a respondent institution through a current account, or any other type of account or related service, including correspondent relationships established for securities transactions or funds transfers. Payable-Through Accounts: Correspondent accounts used directly by third parties to conduct transactions on their behalf. Financial Group: A group of Financial Institutions consisting of a holding company or another Legal Person that exercises control over the rest of the group, and coordinates functions for the purpose of applying supervision at the group level, across its branches and subsidiaries, in accordance with International Core Principles for Financial Supervision and the anti-money laundering and combating terrorism financing policies and procedures. International Core Principles for Financial Supervision: The Basel Committee’s Core Principles for Effective Banking Supervision (Principles 1–3, 5–9, 11–15, 26, and 29); The International Association of Insurance Supervisors Core Principles (Principles 1, 3–10, 18, 21–23, and 25); The International Organization of Securities Commissions Principles (Principles 24, 28, 29, and 31) and Responsibilities (A, B, C, and D). Wire Transfer: Any operation for the electronic funds transfer conducted by a Financial Institution or a Virtual Asset Service Provider on behalf of an originator, whereby funds are transmitted to a specified Beneficiary at another Financial Institution, Virtual Asset Service Provider, or virtual wallet, whether the originator and beneficiary are the same person or different persons. Shell Bank: A bank incorporated or licensed in a jurisdiction in which it has no physical presence, and is not affiliated with a regulated Financial Group. Population Register: The State Population Register, which includes individual data and civil events, as regulated by Federal Law No. (9) of 2006 Regarding the Population Register and Identity Card System, as amended. High-Risk Customers: Customers who present heightened risk due to their personal profile, activities, the nature of the Business Relationship, or geographic location, including customers from high-risk countries, non-residents not holding a State-issued identity card, customers with complex ownership structures, customers conducting complex or economically or legally unjustified Transactions, customers engaging in large cash Transactions, Transactions with unknown third parties, or any other high-risk Transactions as determined by Financial Institutions, DNFBPs, Virtual Asset Service Providers, or the Supervisory Authority. Politically Exposed Persons (PEPs): Natural persons entrusted with, or have been previously entrusted with, prominent public functions in the State or in any other country, such as Heads of State or Government, senior politicians, senior government officials including judicial or military officials, senior executive managers of state-owned enterprises, senior political party officials, and persons entrusted with, or have previously been entrusted with, the management of international organizations or any prominent function therein, including members of Senior Management such as directors, deputy directors, members of the board of directors, or persons of equivalent positions. This definition includes: 1. Immediate family members of the politically exposed person, such as spouses, children and their spouses, and parents; 2. Persons known to be close associates of the politically exposed person, including: a. Persons having joint beneficial ownership of a legal person or Legal Arrangement, or any other close professional or social relationships with a PEP; b. Persons having sole beneficial ownership of a legal person or Legal Arrangement that has been established for the benefit of a PEP. Adequate Information: In the context of legal persons; information that is available or can be obtained to identify the Beneficial Owner and the means by which ownership or control is exercised, including full name, nationality, date and place of birth, residential address, identity number and type, tax registration number, if any, and any other information required for this purpose. In the context of Legal Arrangements; information used to identify the natural persons who are the Beneficial Owners thereof and their roles, including information on the Trustee, Settlor, Protector, if any, Beneficiary, or, as the case may be, class of Beneficiaries and the authorities and powers granted thereto, and any other person exercising ultimate effective control over the Legal Arrangement or occupying a similar or equivalent position. Accurate Information: Information that has been verified for accuracy. In the context of legal persons; information that has been verified to confirm its accuracy through the verification of the identity and status of the Beneficial Owner using original documents, data, or information obtained from a reliable and independent source. The extent of the verification measures may vary according to the identified level of risk. Where there is a discrepancy in the information, necessary supplementary measures shall be taken to confirm the accuracy of the Beneficial Owner’s information. In the context of Legal Arrangements, information that has been verified to confirm its accuracy through the verification of the identity and status of the Beneficial Owner, using reliable documents, data, or information. The extent of verification measures may vary according to the identified level of risk. Where there is a discrepancy in the information, necessary supplementary measures shall be taken to confirm the accuracy of the Beneficial Owner’s information. Up-to-Date Information: In the context of legal persons, information that is as current as possible and updated within a reasonable, specified timeframe following any change. In the context of Legal Arrangements, information that is as current as possible and updated within a reasonable timeframe. However, where Beneficiaries are designated by characteristics or class, Trustees or persons in equivalent or similar positions are not required to obtain complete Adequate and Accurate Information until a Beneficiary becomes entitled at the time of payment or seeks to exercise vested rights, in accordance with the risk-based approach. Decree by Law: Federal Decree by Law No. (10) of 2025 Regarding Anti-Money Laundering, and Combating the Financing of Terrorism and Proliferation Financing.
Article (2)
Official English translation — Arabic text controlsPermanent link →Chapter Two: Financial Institutions, Designated Non-Financial Businesses and Professions, Virtual Asset Service Providers, and Non-Profit Organizations · Part One: Financial Institutions and Designated Non-Financial Businesses and Professions · Division One: Nature of Financial Institutions and Designated Non-Financial Businesses and Professions
Financial Institutions shall include any person who, as a commercial activity, carries out one or more of the following financial activities or operations for the benefit of, or on behalf of, a Customer: 1. Acceptance of deposits and other repayable funds from the public. 2. Lending, including consumer loans and mortgage loans, with or without recourse, and the financing of commercial transactions, including the purchase of export documents and the purchase of debts, whether with or without recourse. 3. Financial leasing, excluding financial leasing related to consumer products. 4. Money or value transfer services, excluding any natural or legal person who solely provides Financial Institutions with messaging or other support systems for the transfer of funds. 5. Issuance and management of means of payment, including debit cards, credit cards, cheques, payment orders, banker drafts, and electronic money. 6. Guarantees and financial commitments. 7. Trading in financial market instruments such as cheques, bills of exchange, certificates of deposit, derivatives, and others; or foreign exchange, currency exchange instruments, interest rates, indices, other financial derivatives, or tradable financial instruments; and trading in commodity futures contracts. 8. Participation in the issuance of securities and the provision of financial services related to such issuances. 9. Management of funds and portfolios of all types. 10. Safekeeping and administration of cash or liquid securities on behalf of others. 11. Other operations for investing, managing, or operating funds or monies on behalf of others. 12. Subscription to, or savings in, life insurance policies and other types of investment-related insurance, including those provided by insurance agents and brokers. 13. Money or currency exchange. 14. Any other financial activities or operations as may be determined by a resolution issued by the Supervisory Authority, in coordination with the National Committee.
Article (3)
Official English translation — Arabic text controlsPermanent link →Chapter Two: Financial Institutions, Designated Non-Financial Businesses and Professions, Virtual Asset Service Providers, and Non-Profit Organizations · Part One: Financial Institutions and Designated Non-Financial Businesses and Professions · Division One: Nature of Financial Institutions and Designated Non-Financial Businesses and Professions
Designated Non-Financial Businesses and Professions (DNFBPs) shall include any person who carries out one or more of the following commercial or professional activities or businesses: 1. Commercial Gaming Operators, including Commercial Gaming conducted on board vessels or marine craft, when conducting a single financial transaction or several transactions that appear to be linked and whose value equals or exceeds eleven thousand dirhams (AED 11,000). A financial transaction shall not include a transaction that solely involves gaming chips or gaming instruments. 2. Real estate brokers and agents, when concluding transactions or settlements on behalf of their customers in relation to the purchase or sale of real estate. 3. Dealers in valuable metals and precious stones, when carrying out any single cash transaction or several transactions that appear to be linked and whose value equals or exceeds fifty-five thousand dirhams (AED 55,000). 4. Lawyers, notaries, other independent legal professionals, and independent accountants, whether practicing individually, as partners, or as professionals within a firm practicing such profession, when they prepare, conduct, or execute financial transactions on behalf of their customers in relation to the following activities: a. Buying and selling real estate; b. Managing funds owned by the customer ; c. Managing bank accounts, savings accounts, or securities accounts; d. Organizing contributions for the establishment, operation, or management of Companies; e. Establishing, operating, managing legal persons or Legal Arrangements, or selling, or purchasing commercial entities. 5. Company and Trust Service Providers, when carrying out or executing any transaction for the benefit of, or on behalf of, their customers in relation to the following activities: a. Acting as an agent in the incorporation or establishment of Legal Persons; b. Acting, or arranging for another person to act, as a director or secretary of a company, or as a partner or in a similar position in another Legal Person; c. Providing a registered office, business address, place of residence, correspondence address, or administrative address for a company, any legal person, or a Legal Arrangement; d. Acting, or arranging for another person to act, as a Trustee of an express Trust or performing an equivalent function for another form of Legal Arrangement; e. Acting, or arranging for another person to act, as a Nominee Shareholder for another person. 6. Any other businesses or professions may be determined by a resolution issued by the Supervisory Authority, in coordination with the National Committee.
Article (4)
Official English translation — Arabic text controlsPermanent link →Chapter Two: Financial Institutions, Designated Non-Financial Businesses and Professions, Virtual Asset Service Providers, and Non-Profit Organizations · Part One: Financial Institutions and Designated Non-Financial Businesses and Professions · Division One: Nature of Financial Institutions and Designated Non-Financial Businesses and Professions
Virtual Asset Activities shall include the following activities or operations: 1. Exchange between Virtual Assets and fiat currencies. 2. Exchange between one or more types of Virtual Assets. 3. Transfer of Virtual Assets. 4. Safekeeping or administration of Virtual Assets or instruments enabling control over Virtual Assets. 5. Provision of financial services or activities related to an issuer’s offer or sale of Virtual Assets, or participation therein. 6. Any other activities or operations as may be determined by a resolution issued by the Supervisory Authority, in coordination with the National Committee.
Article (5)
Official English translation — Arabic text controlsPermanent link →Chapter Two: Financial Institutions, Designated Non-Financial Businesses and Professions, Virtual Asset Service Providers, and Non-Profit Organizations · Part One: Financial Institutions and Designated Non-Financial Businesses and Professions · Division Two: Risk Identification and Risk Mitigation
1. Financial Institutions, DNFBPs, and Virtual Asset Service Providers shall identify, understand, manage, and assess their crime risks in a manner proportionate to the nature and size of their business, taking into account the risk-based approach and the results of the National Risk Assessment, and shall comply with the following: a. Consider all relevant risk factors, such as Customer risks, countries and geographic risk, product, service, transaction, and delivery channel risks, prior to determining the overall level of risk and the appropriate level of risk mitigation measures to be applied. b. Document the processes for identifying and assessing risks and the information related thereto, retain the relevant study, update it on an ongoing basis, and provide it to the concerned authorities upon request. 2. Financial Institutions, DNFBPs, and Virtual Asset Service Providers shall mitigate the crime risks identified pursuant to Clause (1) of this Article, taking into account the risk-based approach, the results of the National Risk Assessment, and sectoral assessments, and shall comply with the following: a. Establish internal policies, controls, and procedures approved by Senior Management, enabling them to manage and mitigate the identified risks, and review and update them on an ongoing basis. b. Ensure that such internal policies, controls, and procedures are proportionate to the nature and size of their business, and monitor their implementation, assess their effectiveness, and enhance them where necessary, in accordance with Article (21) of this Resolution. c. Apply Enhanced Due Diligence measures for the management and mitigation of identified risks, including, by way of example: 1) Obtaining and verifying additional information, such as information on the Customer’s identity and occupation, the Beneficial Owner, the amount of funds, and information available through public databases and open sources; 2) Obtaining additional information on the purpose of the Business Relationship or the reasons for expected Transactions or Transactions that have actually been carried out; 3) Updating Customer Due Diligence information on the Customer and the Beneficial Owner more regularly; 4) Taking Reasonable Measures to identify the source of funds and wealth of the Customer and the Beneficial Owner; 5) Increasing the degree and level of ongoing monitoring of the Business Relationship to determine whether it appears unusual or suspicious, and selecting Transaction patterns requiring further scrutiny and review; 6) Carrying out the first payment through an account in the Customer’s name held with a Financial Institution subject to equivalent Due Diligence standards; 7) Obtaining approval from Senior Management to commence or continue the Business Relationship with the Customer. 3. Financial Institutions, DNFBPs, and Virtual Asset Service Providers may, upon fulfilling the requirements set out in Clauses (1) and (2) of this Article, and in coordination with the Supervisory Authority, apply Simplified Due Diligence measures to manage crime risks where low risks are identified, unless there is a suspicion that a crime has been committed. Such Simplified Due Diligence measures shall be proportionate to the elements of low risk and shall ensure full implementation of the instructions issued by the Executive Office or other Competent Authorities in relation to Targeted Financial Sanctions, and may include, by way of example, the following: a. Verifying the identity of the Customer and the Beneficial Owner after the commencement of the Business Relationship; b. Updating Customer data at longer intervals; c. Reducing the frequency of ongoing monitoring and Transaction scrutiny; d. Inferring the purpose and nature of the Business Relationship from the type of Transaction or the Business Relationship established, without the need to collect information or undertake specific procedures. 4. Where high risks related to Proliferation Financing are identified, Financial Institutions, DNFBPs, and Virtual Asset Service Providers shall take proportionate measures to manage and mitigate such risks. This includes, by way of example, the following: a. Adopting enhanced internal controls aimed at detecting and preventing potential violations of, non-implementation of, or circumvention of instructions of the Executive Office or other relevant Competent Authorities relating to Targeted Financial Sanctions, and conducting ongoing enhanced scrutiny of the Business Relationship to ensure full compliance; b. Maintaining documented records of the measures taken and making them available to the competent authorities upon request; c. Conducting periodic reviews of internal controls in line with changes in the level of risk.
Article (6)
Official English translation — Arabic text controlsPermanent link →Chapter Two: Financial Institutions, Designated Non-Financial Businesses and Professions, Virtual Asset Service Providers, and Non-Profit Organizations · Part One: Financial Institutions and Designated Non-Financial Businesses and Professions · Division Three: Customer Due Diligence and Beneficial Owner Identification Procedures
1. Financial Institutions, DNFBPs, and Virtual Asset Service Providers shall verify the identity of the Customer and the Beneficial Owner before or during the establishment of a Business Relationship or the opening of an account, or prior to carrying out a Transaction for a Customer with whom no such relationship exists. 2. In cases of low crime risk, Financial Institutions, DNFBPs, and Virtual Asset Service Providers may defer the completion of Customer identity verification until after the establishment of the Business Relationship, subject to the following conditions: a. Verification shall be completed as soon as possible after the commencement of the Business Relationship or execution of the Transaction; b. The deferral shall be necessary so as not to disrupt the normal course of business; c. Appropriate and effective measures shall be applied to control the risks of the Crime. 3. Financial Institutions, DNFBPs, and Virtual Asset Service Providers shall take measures to manage risks in circumstances where the Customer is able to benefit from the Business Relationship prior to the completion of the verification process.
Article (7)
Official English translation — Arabic text controlsPermanent link →Chapter Two: Financial Institutions, Designated Non-Financial Businesses and Professions, Virtual Asset Service Providers, and Non-Profit Organizations · Part One: Financial Institutions and Designated Non-Financial Businesses and Professions · Division Three: Customer Due Diligence and Beneficial Owner Identification Procedures
1. Financial Institutions, Designated Non-Financial Businesses and Professions, and Virtual Asset Service Providers, as applicable, shall apply Customer Due Diligence measures in the following cases: a. Upon the commencement of a Business Relationship; b. Where there is suspicion of a Crime; c. Where there are doubts as to the accuracy or adequacy of Customer identification data previously obtained. 2. Financial Institutions shall apply Customer Due Diligence measures in the following cases: a. When conducting occasional Transactions for a Customer amounting to or exceeding fifty-five thousand dirhams (AED 55,000), whether carried out as a single Transaction or several Transactions that appear to be linked; b. When conducting occasional Transactions in the form of Wire Transfers amounting to or exceeding three thousand five hundred dirhams (AED 3,500). 3. Virtual Asset Service Providers shall apply Customer Due Diligence measures when conducting occasional Transactions amounting to or exceeding three thousand five hundred dirhams (AED 3,500), whether carried out as a single Transaction or several Transactions that appear to be linked.
Article (8)
Official English translation — Arabic text controlsPermanent link →Chapter Two: Financial Institutions, Designated Non-Financial Businesses and Professions, Virtual Asset Service Providers, and Non-Profit Organizations · Part One: Financial Institutions and Designated Non-Financial Businesses and Professions · Division Three: Customer Due Diligence and Beneficial Owner Identification Procedures
Financial Institutions, Designated Non-Financial Businesses and Professions, and Virtual Asset Service Providers shall apply Customer Due Diligence measures and conduct ongoing monitoring in respect of the Business Relationship, which shall include the following: 1. Scrutinizing Transactions carried out throughout the duration of the Business Relationship to ensure that such Transactions are consistent with the information available thereto regarding the Customer, the nature of their activities, and the risks they represent, including, where necessary, the source of funds. 2. Ensuring that documents, data, or information obtained as part of Customer Due Diligence measures are up to date and relevant, through reviewing records, with particular emphasis on records relating to categories of High-Risk Customers.
Article (9)
Official English translation — Arabic text controlsPermanent link →Chapter Two: Financial Institutions, Designated Non-Financial Businesses and Professions, Virtual Asset Service Providers, and Non-Profit Organizations · Part One: Financial Institutions and Designated Non-Financial Businesses and Professions · Division Three: Customer Due Diligence and Beneficial Owner Identification Procedures
1. Financial Institutions, Designated Non-Financial Businesses and Professions, and Virtual Asset Service Providers shall identify the Customer, whether permanent or occasional, and determine whether the Customer is a natural person, Legal Person, or Legal Arrangement, and shall verify such identity using original documents, data, or information obtained from a reliable and independent source, as follows: a. In respect of Customers who are natural person, obtaining the name as stated in the identity card or travel document, nationality, address, date and place of birth, and, where applicable, the name and address of the employer, together with a true copy of a valid identity card or travel document; b. In respect of Customers who are Legal Persons or Legal Arrangements, obtaining the following basic information: 1) Name, legal form, memorandum of association, tax registration number of the Legal Persons subject to corporate tax, and the unique reference number, if any; 2) Address of the registered office or principal place of business, and where the Person is foreign, the name and address of its legal representative in the State, if any, together with supporting evidence; 3) Articles of association or any other equivalent approved documents; 4) Names of relevant persons holding Senior Management positions within the Legal Person or Legal Arrangement. 2. Financial Institutions, Designated Non-Financial Businesses and Professions, and Virtual Asset Service Providers shall verify that any person acting on behalf of the Customer is duly authorized to do so, and shall identify such person in accordance with Clause (1) of this Article. 3. Financial Institutions, Designated Non-Financial Businesses and Professions, and Virtual Asset Service Providers shall understand the purpose and the intended nature of the Business Relationship and obtain information relating thereto where necessary. 4. Financial Institutions, Designated Non-Financial Businesses and Professions, and Virtual Asset Service Providers shall understand the nature of the Customer’s business and the ownership and control structure thereof.
Article (10)
Official English translation — Arabic text controlsPermanent link →Chapter Two: Financial Institutions, Designated Non-Financial Businesses and Professions, Virtual Asset Service Providers, and Non-Profit Organizations · Part One: Financial Institutions and Designated Non-Financial Businesses and Professions · Division Three: Customer Due Diligence and Beneficial Owner Identification Procedures
Financial Institutions, Designated Non-Financial Businesses and Professions, and Virtual Asset Service Providers shall take into account the risks of the Crime arising from the Customer and the Business Relationship, identify the Beneficial Owner of Legal Persons and Legal Arrangements, and take Reasonable Measures to verify such identity using documents, data, or information obtained from a reliable and independent source, in a manner that enables them to be satisfied that the Beneficial Owner’s identity has been determined, as follows: 1. Customers that are Legal Person: a. Obtaining the identity of the natural person who ultimately owns, whether individually or jointly with another person, an actual controlling ownership interest or shares in the Legal Person of 25% (twenty-five percent) or more; b. Where there is doubt as to the identification of the natural person under paragraph (a) of this Clause, or doubt that the natural person who owns an ownership interest or controlling shares is the Beneficial Owner, or where no natural person exercises control through ownership interest, the identity of the natural person who exercises legal or actual control over the Legal Person , or through any other means, whether directly or indirectly, shall be identified; c. Where no natural person is identified pursuant to paragraphs (a) and (b) of this Clause, identifying the relevant natural person holding a Senior Management position shall be identified, whether one or more persons. 2. Customers that are Legal Arrangement: a. Identifying the identity of the Trustee, Settlor, Trust Protector, Beneficiaries, or classes of Beneficiaries, and the powers and authorities granted thereto where no Beneficiaries are identifiable at the time of establishment of the Trust; b. Identifying the identity of any other natural person exercising ultimate effective control, including through a chain of ownership or control over the trust, whether directly or indirectly; c. Obtaining adequate information regarding the Beneficial Owner to enable the identification thereof at the time of payment or when the Beneficial Owner intends to exercise legally acquired rights; d. Identifying the natural persons holding equivalent or similar positions in other Legal Arrangements; e. Identifying the Beneficial Owner of a Legal Person where such Legal Person is a party to the Legal Arrangement, in accordance with the provisions of this Article.
Article (11)
Official English translation — Arabic text controlsPermanent link →Chapter Two: Financial Institutions, Designated Non-Financial Businesses and Professions, Virtual Asset Service Providers, and Non-Profit Organizations · Part One: Financial Institutions and Designated Non-Financial Businesses and Professions · Division Three: Customer Due Diligence and Beneficial Owner Identification Procedures
Where the Customer, or the controlling owner, is a company listed on a securities market that is subject to disclosure requirements ensuring sufficient transparency with respect to the identification of the Beneficial Owner, or a subsidiary thereof holding a controlling interest, it shall be permissible not to identify or verify the identity of any shareholder or Beneficial Owner of such Companies. In such cases, identity information may be obtained from publicly available registers, from the Customer, or from any other reliable sources.
Article (12)
Official English translation — Arabic text controlsPermanent link →Chapter Two: Financial Institutions, Designated Non-Financial Businesses and Professions, Virtual Asset Service Providers, and Non-Profit Organizations · Part One: Financial Institutions and Designated Non-Financial Businesses and Professions · Division Three: Customer Due Diligence and Beneficial Owner Identification Procedures
1. In addition to the Due Diligence measures required in respect of the Customer and the Beneficial Owner, Financial Institutions shall apply Due Diligence and ongoing monitoring measures with respect to the beneficiary of life insurance policies and other types of investment-related insurance classes, as soon as the beneficiary is identified or designated, as follows: a. Where the beneficiary is designated by name, name of the person shall be obtained, whether the person is a natural person, a Legal Person, or a Legal Arrangement. b. Where the beneficiary is designated by category or description, such as by family relationship (including spouse or children) or by other means such as a will or estate, sufficient information about the beneficiary shall be obtained to ensure that the Financial Institution will be able to identify the beneficiary at the time of payment of compensation or entitlements. c. In all cases, the identity of the beneficiary shall be verified at the time of payment of compensation or entitlements, or upon the exercise of any rights related to such policies. 2. In all cases, Financial Institutions shall consider the beneficiary of life insurance policies as a risk factor when determining the applicability of Enhanced Customer Due Diligence measures. Where it is determined that such beneficiary is a Legal Person or Legal Arrangement that presents high risk, Financial Institutions shall apply Enhanced Customer Due Diligence measures, which shall include reasonable procedures to identify and verify the Beneficial Owner of the beneficiary of the insurance policy at the time of payment of compensation or entitlements, or upon the exercise of any rights related to such policies.
Article (13)
Official English translation — Arabic text controlsPermanent link →Chapter Two: Financial Institutions, Designated Non-Financial Businesses and Professions, Virtual Asset Service Providers, and Non-Profit Organizations · Part One: Financial Institutions and Designated Non-Financial Businesses and Professions · Division Three: Customer Due Diligence and Beneficial Owner Identification Procedures
Financial Institutions, Designated Non-Financial Businesses and Professions, and Virtual Asset Service Providers shall apply Customer Due Diligence measures to Customers and existing Business Relationships at the time this Resolution enters into force, at such times as they deem appropriate based on materiality and risk, and shall ensure the adequacy of data previously obtained where Due Diligence measures were applied prior to the entry into force of this Resolution.
Article (14)
Official English translation — Arabic text controlsPermanent link →Chapter Two: Financial Institutions, Designated Non-Financial Businesses and Professions, Virtual Asset Service Providers, and Non-Profit Organizations · Part One: Financial Institutions and Designated Non-Financial Businesses and Professions · Division Three: Customer Due Diligence and Beneficial Owner Identification Procedures
1. Financial Institutions, Designated Non-Financial Businesses and Professions, and Virtual Asset Service Providers shall be prohibited from establishing or continuing a Business Relationship or executing a Transaction where they are unable to apply Customer Due Diligence measures, and shall consider submitting a Suspicious Transaction Report to the Unit whenever necessary. 2. Where Financial Institutions, Designated Non-Financial Businesses and Professions, and Virtual Asset Service Providers suspect the commission of a Crime, they may refrain from applying Customer Due Diligence measures if they have reasonable grounds to believe that such measures may result in alerting the Customer, and shall submit a Suspicious Transaction Report to the Unit, stating the reasons for not applying such measures.
Article (15)
Official English translation — Arabic text controlsPermanent link →Chapter Two: Financial Institutions, Designated Non-Financial Businesses and Professions, Virtual Asset Service Providers, and Non-Profit Organizations · Part One: Financial Institutions and Designated Non-Financial Businesses and Professions · Division Three: Customer Due Diligence and Beneficial Owner Identification Procedures
Financial Institutions, Designated Non-Financial Businesses and Professions, and Virtual Asset Service Providers shall comply with the following: 1. Refraining from dealing with Shell Banks in any manner whatsoever, including opening bank accounts therefor or accepting funds or deposits therefrom. 2. Refraining from opening or maintaining anonymous accounts or accounts held under obviously fictitious names.
Article (16)
Official English translation — Arabic text controlsPermanent link →Chapter Two: Financial Institutions, Designated Non-Financial Businesses and Professions, Virtual Asset Service Providers, and Non-Profit Organizations · Part One: Financial Institutions and Designated Non-Financial Businesses and Professions · Division Four: Politically Exposed Persons
1. In addition to applying Customer Due Diligence measures, Financial Institutions, Designated Non-Financial Businesses and Professions, and Virtual Asset Service Providers shall comply with the following: a. In respect of foreign Politically Exposed Persons: 1) Establishing appropriate risk management systems to determine whether the Customer or the Beneficial Owner is a Politically Exposed Person; 2) Obtaining approval from Senior Management prior to establishing or continuing a Business Relationship with existing Customers who are Politically Exposed Persons. 3) Taking Reasonable Measures to identify the source of funds and wealth of Customers and Beneficial Owners identified as Politically Exposed Persons. 4) Conducting enhanced ongoing monitoring of the Business Relationship. b. In respect of domestic Politically Exposed Persons and persons entrusted with a prominent function in an international organization: 1) Taking adequate measures to determine whether the Customer or the Beneficial Owner falls within these categories. 2) Applying the measures set out in subparagraphs (2), (3), and (4) of paragraph (a) of this Clause where a high-risk Business Relationship exists with such persons. 2. Subject to Clause (1) of this Article, Financial Institutions concerned with life insurance policies shall take Reasonable Measures to determine whether the beneficiary or the Beneficial Owner thereof is a Politically Exposed Person prior to the payment of compensation or entitlements or the exercise of any related rights. Where higher risks are identified, they shall inform Senior Management prior to the payment of compensation or entitlements or the exercise of any related rights, conduct enhanced scrutiny of the entire Business Relationship, and consider submitting a Suspicious Transaction Report to the Unit whenever necessary.
Article (17)
Official English translation — Arabic text controlsPermanent link →Chapter Two: Financial Institutions, Designated Non-Financial Businesses and Professions, Virtual Asset Service Providers, and Non-Profit Organizations · Part One: Financial Institutions and Designated Non-Financial Businesses and Professions · Division Five: Suspicious Transaction Reports
Financial Institutions, Designated Non-Financial Businesses and Professions, and Virtual Asset Service Providers shall establish indicators through which they are able to identify suspicion of a Crime for the purpose of submitting Suspicious Transaction Reports, and shall update such indicators on an ongoing basis in line with the development and diversification of methods used in the commission of a Crime, in compliance with instructions issued by the Supervisory Authority in this regard.
Article (18)
Official English translation — Arabic text controlsPermanent link →Chapter Two: Financial Institutions, Designated Non-Financial Businesses and Professions, Virtual Asset Service Providers, and Non-Profit Organizations · Part One: Financial Institutions and Designated Non-Financial Businesses and Professions · Division Five: Suspicious Transaction Reports
1. Where Financial Institutions, Designated Non-Financial Businesses and Professions, and Virtual Asset Service Providers suspect, or have reasonable grounds to suspect, that a Transaction or attempted Transaction, or funds, in whole or in part, constitute proceeds, are related to the Crime, or are intended to be used therein, regardless of their value, they shall, without invoking banking secrecy, professional secrecy, or contractual liability, comply with the following: a. Immediately and without delay notify the Unit by submitting Suspicious Transaction Reports, containing all available data and information relating to such Transaction or funds, and related parties, through the Unit’s electronic system or any other means approved thereby. b. Promptly respond to any request from the Unit for additional information. 2. Lawyers, notaries, other independent legal professionals, and independent statutory auditors shall be exempt from the provisions of Clause (1) of this Article where the information relating to such transactions was obtained in the course of assessing a Customer’s legal position, defending, or representing the Customer before courts, or in arbitration or mediation proceedings, or providing a legal opinion relating to judicial proceedings, including providing advice on initiating or avoiding such proceedings, whether the information was obtained before, during, or after such proceedings, or in other circumstances subject to professional secrecy.
Article (19)
Official English translation — Arabic text controlsPermanent link →Chapter Two: Financial Institutions, Designated Non-Financial Businesses and Professions, Virtual Asset Service Providers, and Non-Profit Organizations · Part One: Financial Institutions and Designated Non-Financial Businesses and Professions · Division Five: Suspicious Transaction Reports
1. Financial Institutions, Designated Non-Financial Businesses and Professions, and Virtual Asset Service Providers, as well as their directors, officers, and employees shall be prohibited from disclosing, whether directly or indirectly, to the Customer or any other person that they have submitted or are about to submit a Suspicious Transaction Report, or any information or data related thereto, or that an investigation is being conducted in respect thereof, without prejudice to information sharing with branches and subsidiaries at the level of the Financial Group, in accordance with the provisions of Article (32) of this Resolution. 2. Attempts by lawyers, notaries, other independent legal professionals, or independent statutory auditors to dissuade a Customer from committing an unlawful act shall not constitute disclosure.
Article (20)
Official English translation — Arabic text controlsPermanent link →Chapter Two: Financial Institutions, Designated Non-Financial Businesses and Professions, Virtual Asset Service Providers, and Non-Profit Organizations · Part One: Financial Institutions and Designated Non-Financial Businesses and Professions · Division Six: Reliance on a Third Party
1. Taking into account the countries identified by the National Committee as high-risk and countries with deficiencies in their anti-money laundering, combating terrorist financing, and proliferation financing systems, and to the maximum extent possible the available information on country risks, Financial Institutions, Designated Non-Financial Businesses and Professions, and Virtual Asset Service Providers may rely on a third party to apply Customer Due Diligence measures for the purposes of identifying the Customer and Beneficial Owner and understanding the nature of the Customer’s business or for the purposes of a Business Relationship, provided that they remain responsible for the accuracy of such measures and comply with the following: a. Ensuring that the third party is regulated and supervised and complies with Customer Due Diligence and record-keeping requirements pursuant to this Resolution. b. Immediately obtaining from the third party the necessary identification data and information collected during Customer Due Diligence measures, and taking the necessary steps to ensure the ability to obtain copies of the necessary documents without delay upon request. 2. Financial Institutions, Designated Non-Financial Businesses and Professions, and Virtual Asset Service Providers that rely on a third party that forms part of the same Financial Group, shall ensure the following: a. That the Group applies Due Diligence requirements in respect of customers and Politically Exposed Persons, maintains records, and implements anti-crime programs in accordance with Divisions Three, Four, and Eleven of Part One of this Chapter and Article (32) of this Resolution, and that the group is subject, in this regard, to supervision by the competent authority. b. That any high risks related to countries are adequately mitigated through the Group’s anti-crime policies and controls. 3. Reliance on a third party shall not include the use by Financial Institutions, Designated Non-Financial Businesses and Professions, and Virtual Asset Service Providers of external sources, such as outsourcing or agency services to perform Customer Due Diligence measures on their behalf, where such services are carried out in accordance with their internal policies and procedures, and the external sources are subject to their supervision and control in the effective implementation of those policies and procedures, and apply fitness and propriety standards and effective audit procedures to their staff.
Article (21)
Official English translation — Arabic text controlsPermanent link →Chapter Two: Financial Institutions, Designated Non-Financial Businesses and Professions, Virtual Asset Service Providers, and Non-Profit Organizations · Part One: Financial Institutions and Designated Non-Financial Businesses and Professions · Division Seven: Internal Supervision and Foreign Branches and Subsidiaries
Financial Institutions, Designated Non-Financial Businesses and Professions, and Virtual Asset Service Providers shall have internal anti-crime policies, controls, and procedures approved by Senior Management, proportionate to the identified Crime risks and to the nature and size of their activities, and the mitigation thereof. Such policies, controls, and procedures shall be reviewed and updated thereby on an ongoing basis, and shall include the following: 1. Customer Due Diligence measures as required pursuant to this Resolution, including risk management procedures for Business Relationships prior to the completion of the verification process. 2. Procedures for reporting Suspicious Transactions. 3. Appropriate anti-crime compliance management arrangements, including the appointment of a Compliance Officer at management level. 4. Screening procedures to ensure the application of high standards of fitness and propriety in the appointment of employees; 5. Preparation of anti-crime periodic programs and workshops to build the capacities and qualify those assuming the compliance function and other relevant employees. 6. An independent audit function to test the effectiveness and adequacy of internal anti-crime policies, controls, and procedures.
Article (22)
Official English translation — Arabic text controlsPermanent link →Chapter Two: Financial Institutions, Designated Non-Financial Businesses and Professions, Virtual Asset Service Providers, and Non-Profit Organizations · Part One: Financial Institutions and Designated Non-Financial Businesses and Professions · Division Eight: Duties of the Compliance Officer
Financial Institutions, Designated Non-Financial Businesses and Professions, and Virtual Asset Service Providers shall appoint a Compliance Officer at management level and under their responsibility, who shall have independence in decision-making and possess appropriate competence and experience, and who shall undertake the following duties: 1. Monitoring Transactions related to the Crime. 2. Reviewing records and receiving, examining, and assessing Suspicious Transaction data, and deciding whether to notify the Unit or to retain the matter stating the reasons therefor, in full confidentiality. 3. Reviewing Anti-Money Laundering, and combating Financing of Terrorism, and Proliferation Financing internal systems and procedures, assessing their consistency with the provisions of the Decree by Law and this Resolution, evaluating the establishment’s level of compliance with their implementation, proposing what is necessary to update and develop them; and preparing periodic reports thereon to be submitted directly to Senior Management, and sending a copy thereof to the concerned Supervisory Authority upon its request, including Senior Management observations and decisions. 4. Developing, implementing, and documenting ongoing programs and training plans for employees of the establishment regarding all matters related to the Crime and methods of combating it. 5. Cooperating with the Supervisory Authority and the Unit, providing them with any data they may request, and enabling their assigned personnel to access the records and documents necessary for the exercise of their competencies.
Article (23)
Official English translation — Arabic text controlsPermanent link →Chapter Two: Financial Institutions, Designated Non-Financial Businesses and Professions, Virtual Asset Service Providers, and Non-Profit Organizations · Part One: Financial Institutions and Designated Non-Financial Businesses and Professions · Division Nine: High-Risk Countries
1. Financial Institutions, Designated Non-Financial Businesses and Professions, and Virtual Asset Service Providers shall apply Enhanced Customer Due Diligence measures proportionate to the level of risk arising from a Business Relationship or Transactions with a natural or legal person from countries identified by the National Committee as high-risk, or from countries with deficiencies in Anti-Money Laundering, and combating Financing of Terrorism, and Proliferation Financing systems. 2. Financial Institutions, Designated Non-Financial Businesses and Professions, and Virtual Asset Service Providers shall apply countermeasures and any other measures required by the Supervisory Authority, whether on its own initiative or as determined by the National Committee, in relation to high-risk countries and countries with deficiencies in Anti-Money Laundering, combating the Financing of Terrorism, Proliferation Financing systems.
04
Publication status
Source and translation status
The official Arabic text controls and the government English version is auxiliary. Article headings embedded by the government portal in division headings have been normalised without changing hierarchy. A non-operative translator footer following English Article 71 has been excluded from the provision text.
Legal review
On 3 September 2026, metadata, nine chapters, the preamble and the continuous sequence of Articles 1–71 were reconciled against the official Arabic and English texts. Russian and Chinese remain drafts pending external legal review, particularly for licensed financial services, sanctions procedures and international judicial cooperation. · September 3, 2026
Republication status
Official document: publication relies on the official-documents exclusion in Article 3 of Federal Decree-Law No. 38/2021. Source-site access terms remain separately applicable.
Change history
- 29 October 2025 — issued; 14 November 2025 — published in Official Gazette No. 811; 14 December 2025 — entered into force.
- Article 70 repealed Cabinet Resolution No. 10 of 2019 and all conflicting provisions.
- 3 September 2026 — the preamble and all 71 articles were added to the addressable four-language corpus and Russian and Chinese editorial versions prepared.
06
Official primary source
Cabinet Resolution No. 134 of 2025
Official document: publication relies on the official-documents exclusion in Article 3 of Federal Decree-Law No. 38/2021. Source-site access terms remain separately applicable.
Verify official text ↗
+7 (495) 221 31 46