Regulation and standard

What AML/CFT training does UAE law require?

Short answer

UAE law requires financial institutions, designated non-financial businesses and professions, and virtual asset service providers to run periodic anti-money laundering programs and workshops that build the capability of compliance staff and other relevant employees. The requirement sits in Article 21 of Cabinet Resolution No. 134 of 2025, which implements Federal Decree-Law No. 10 of 2025. The compliance officer must develop, implement, and document ongoing training plans for employees.

By the Knowledge Foundry editorial team. How we write and check these pages

Published
Updated
Reading time
10 min
Jurisdiction
United Arab Emirates (federal)
Regulator
Supervisory Authorities under Federal Decree-Law No. 10 of 2025, including the Central Bank of the UAE (CBUAE); the UAE Financial Intelligence Unit (UAEFIU) receives suspicious transaction reports

Key takeaways

  • Federal Decree-Law No. 10 of 2025 repealed Federal Decree-Law No. 20 of 2018, and Cabinet Resolution No. 134 of 2025 repealed Cabinet Decision No. 10 of 2019. Training obligations should now be mapped to the 2025 texts.
  • Article 21(5) of Cabinet Resolution No. 134 of 2025 requires periodic anti-crime programs and workshops for those in the compliance function and other relevant employees.
  • Article 22(4) makes the compliance officer responsible for developing, implementing, and documenting ongoing programs and training plans for employees.
  • For banks, insurers, exchange houses and other Central Bank licensees, the Central Bank of the UAE (CBUAE) expects role-based training, an annual training needs assessment, an annual training plan approved by the board or senior management, attendance records, and post-training assessments.
  • Supervisory Authorities can impose administrative fines of AED 10,000 to AED 5,000,000 per violation, and can suspend or replace responsible directors and managers.

What does UAE law require for AML/CFT training?

UAE law requires regulated entities to include staff training in their internal anti-money laundering policies, and makes the compliance officer responsible for planning and documenting it. The obligation is set out in the executive regulations rather than the decree-law itself.

Article 19(1)(d) of Federal Decree-Law No. 10 of 2025 requires financial institutions, DNFBPs and virtual asset service providers to establish internal policies, controls and procedures approved by senior management, and leaves the minimum content of those policies to the executive regulations. Cabinet Resolution No. 134 of 2025 supplies that content in Article 21, which lists six required elements. Element five reads: "Preparation of anti-crime periodic programs and workshops to build the capacities and qualify those assuming the compliance function and other relevant employees."

Article 22 then requires each entity to appoint a compliance officer at management level with "appropriate competence and experience". One of the officer's five listed duties is "Developing, implementing, and documenting ongoing programs and training plans for employees of the establishment regarding all matters related to the Crime and methods of combating it." "The Crime" is defined in the decree-law, whose definitions apply to the resolution, and covers money laundering and its predicate offenses, terrorist financing, and proliferation financing.

Three words that shape the program

The text says periodic, ongoing, and documented. A one-time induction module does not meet that standard, and training that happened but was not recorded is hard to evidence. A training matrix that ties each role to its required modules and refresh dates is the simplest way to show all three.

Which UAE AML/CFT laws are current as at September 2026?

As at September 2026, the governing texts are Federal Decree-Law No. 10 of 2025 and its executive regulations, Cabinet Resolution No. 134 of 2025. The UAE Financial Intelligence Unit (UAEFIU) lists both, after the earlier texts, on its Understanding the Law page. The repeals themselves are in Article 41(1) of the decree-law and Article 70 of the resolution.

UAE federal AML/CFT texts and their status (sources: UAEFIU and the texts themselves)
TextIssuedStatus as at September 2026
Federal Decree-Law No. 20 of 20182018, amended in 2021 and 2024Repealed by Article 41(1) of Federal Decree-Law No. 10 of 2025
Cabinet Decision No. 10 of 20192019, amended in 2022Repealed by Article 70 of Cabinet Resolution No. 134 of 2025
Federal Decree-Law No. 10 of 2025September 30, 2025In force two weeks after publication in the Official Gazette (Article 42)
Cabinet Resolution No. 134 of 2025October 29, 2025In force 30 days after publication in the Official Gazette (Article 71)

Article 41(3) of the 2025 decree-law keeps regulations, resolutions and circulars issued under the 2018 law in effect, so far as they do not conflict, until replacements are issued. This matters for training content: some supervisory guidance still cites the 2018 law. For example, the CBUAE's role-based training best practices document names Federal Decree-Law No. 20 of 2018 as its legal basis. Training materials should cite the current law while still following guidance that has not yet been reissued.

Who must provide AML/CFT training in the UAE?

The training obligation applies to three groups: financial institutions, DNFBPs, and virtual asset service providers. Within each entity, it covers the compliance function and "other relevant employees", which in practice means anyone whose role touches customers, transactions, screening or reporting.

Article 3 of Cabinet Resolution No. 134 of 2025 defines DNFBPs by activity and, in some cases, by threshold. Dealers in precious metals and stones are covered for cash transactions of AED 55,000 or more, and commercial gaming operators for transactions of AED 11,000 or more. Lawyers, notaries, independent legal professionals and accountants are covered when they prepare or carry out listed transactions for clients, such as buying and selling real estate or managing client funds. A firm that falls in scope only for some activities should still train the staff who carry out those activities.

Supervisory Authorities also hold a gatekeeping role over the people who run the program. Article 49(18) of the resolution requires them to keep an updated list of the compliance officers of supervised entities and to require the supervisor's prior approval before a compliance officer is appointed. The competence of that officer is therefore something a supervisor may test before any training plan is reviewed.

Does federal AML/CFT law apply in UAE free zones?

Yes. Unlike data protection, where some free zones have their own laws, federal AML/CFT law applies across the UAE, including the financial free zones. What changes in a free zone is the supervisor and the additional rulebook.

For international readers: the UAE has a federal legal system that applies onshore across the seven emirates, plus many free zones with their own licensing authorities. Two of them, the Dubai International Financial Centre (DIFC) and Abu Dhabi Global Market (ADGM), are financial free zones with their own civil and commercial laws and their own financial regulators. The Dubai Financial Services Authority (DFSA) states that Federal Anti-Money Laundering Legislation applies directly in the DIFC under Articles 70 and 71 of the DIFC Regulatory Law, and that the DFSA administers it for firms in the center.

A DIFC firm therefore trains to both the federal texts and the DFSA's own AML module, which has a detailed training rule; see DFSA training and competence requirements. Onshore, the supervisor depends on the sector: the CBUAE supervises the banks, insurers and other institutions it licenses, while other federal and local authorities supervise DNFBPs and other sectors.

What does the Central Bank of the UAE expect of AML/CFT training?

The CBUAE expects its licensed financial institutions to run a risk-based program in which every employee, from the board to external staff, receives training, and those in higher risk roles receive role-based training. Its expectations are set out in Best Practices for Licensed Financial Institutions on Implementing Role-Based AML/CFT/CPF Training, published in the CBUAE Rulebook.

The document says it does not create new regulation, but that it "sets out the expectations of the CBUAE for LFIs to be able to demonstrate compliance". Its main expectations are:

  • A mix of training types: new hire training (including staff moving into new roles), annual enterprise-wide training, group training where relevant, localized training on UAE risks, board and senior management training, and role-based training.
  • An annual training needs assessment drawing on the enterprise-wide risk assessment, regulatory and audit findings, and senior management feedback, with its methodology and outcomes documented. See how to conduct a training needs analysis.
  • Minimum role groups: the board, owners and senior management; first line staff with heightened exposure; the compliance function; internal audit; and staff who test and tune financial crime systems and models.
  • Board training on a need basis or at least annually, with a record of attendance and the material discussed.
  • An annual training plan approved by the board, owners or senior management, stating participants, topics, delivery methods, objectives, minimum standards by role, frequency, and how employees will be assessed.
  • Records and assessment: attendance for every participant, completion and pass or fail results reported to managers, follow up and escalation of non-completion, and retraining before reassessment when an employee fails.
  • Third-party trainers subject to due diligence, with the compliance function vetting content so it reflects UAE requirements and the institution's own policies.
  • Annual content review, or sooner after significant regulatory change, and refresher training when policies, risks or systems change.

The document also says assessments should ensure "participants do not receive credit for an AML/CFT/CPF training unless they have mastered the respective AML/CFT/CPF-related concepts". That is a competence standard, not a completion standard; the difference is explained in completion tracking vs competency verification.

How do UAE AML/CFT obligations map to learning outcomes and evidence?

Each legal or supervisory expectation can be translated into a measurable learning outcome and a piece of evidence a supervisor can inspect. The table below is an illustrative mapping, not a regulatory template; each entity should adapt it to its own risk assessment and supervisor.

Illustrative mapping of UAE AML/CFT training obligations to outcomes and evidence
ObligationLearning outcome (example)Assessment evidence
Periodic programs for compliance staff and relevant employees (Cabinet Resolution No. 134 of 2025, Art. 21(5))Front line staff identify red flags for their product line and escalate them through the internal reporting routeScenario based assessment results by role, dated completion records
Compliance officer documents ongoing training plans (Art. 22(4))Compliance officer maintains a plan linked to the risk assessmentApproved annual training plan with version history
Suspicious transaction reporting without delay to the UAEFIU (Decree-Law No. 10 of 2025, Art. 18)Staff distinguish unusual from suspicious activity and know not to tip off the customerCase study responses, internal escalation log review
Implement targeted financial sanctions instructions forthwith (Art. 19(1)(e))Screening staff disposition alerts and apply freezing instructions correctlySupervised alert reviews, quality assurance sampling
Board oversight of policies (Art. 19(1)(d); CBUAE best practices)Board members explain the institution's risk profile and their oversight dutiesBoard training minutes and attendance, at least annually

Building this mapping once, and keeping it in a compliance obligations register, means a change in the law updates one row rather than every course. The method is described in how to map training to compliance obligations.

What are the consequences of inadequate AML/CFT training?

A training failure is a breach of the executive regulations, so it exposes the entity to the administrative penalties in Article 17 of Federal Decree-Law No. 10 of 2025. Those penalties apply to any violation of the decree-law, its executive regulations, or related decisions.

  • A warning.
  • An administrative fine of not less than AED 10,000 and not more than AED 5,000,000 for each violation, with an escalating fine for the same violation repeated within a year.
  • Restricting the powers of, suspending, or requiring the replacement of board members, executives or managers proven responsible.
  • Suspending or restricting the activity, prohibiting the violator from the sector for a set period, or revoking the license.

Supervisors may also order periodic reports on remediation and may publish the penalties they impose. Separately, Article 25 of Cabinet Resolution No. 134 of 2025 requires transaction and due diligence records to be kept for at least five years. The CBUAE asks that training records be retained for the duration set by UAE record-keeping requirements and made available for audit and examination; guidance on assembling them is in how to prepare training records for an audit.

How does Knowledge Foundry approach this?

Knowledge Foundry models the AML/CFT obligations, the roles they apply to, and the assessment points for each role as a structured framework before any course is written. When a text such as Cabinet Decision No. 10 of 2019 is repealed, the affected concepts and assessments are identified from the framework, so content citing the old law can be found and updated with a record of what changed.

Frequently asked questions

Does UAE law set a fixed number of AML/CFT training hours?

No. Cabinet Resolution No. 134 of 2025 requires periodic programs and ongoing, documented training plans, but sets no hours or frequency. The CBUAE's best practices expect annual enterprise-wide training, board training at least annually or as needed, and role-based training sized to each role's risk exposure. Other supervisors may set their own expectations.

Is the CBUAE role-based training document binding?

The document states that it does not constitute additional legislation or regulation. It does, however, set out the CBUAE's expectations for how licensed financial institutions demonstrate compliance with their legal training obligations, and it asks institutions to provide evidence such as training materials, attendance records, and assessment results. In practice, examiners are likely to test programs against it.

Do outsourced staff and contractors need AML/CFT training?

The CBUAE expects the annual training plan to cover external staff performing AML/CFT/CPF functions on the institution's behalf, including vendors, temporary staff, contractors, and third parties, especially those sourcing new business. It also expects IT and support staff who maintain AML systems to be included.

Should existing training still cite Federal Decree-Law No. 20 of 2018?

No. That law was repealed by Federal Decree-Law No. 10 of 2025, and its executive regulations were repealed by Cabinet Resolution No. 134 of 2025. Training should cite the current texts. Supervisory guidance issued under the old law may remain in effect where it does not conflict, so it can still be followed while it is being reissued.

Do passive shareholders need AML/CFT training?

The CBUAE's best practices say training should be required for owners, partners, and shareholders who carry out an active role in managing the institution, and that it is not mandatory for passive shareholders. Board members and senior management are expected to receive periodic training focused on oversight and compliance culture.

Sources

  1. Federal Decree by Law No. (10) of 2025 Regarding Anti-Money Laundering, and Combating the Financing of Terrorism and Proliferation Financing, UAE Financial Intelligence Unit
  2. Cabinet Resolution No. (134) of 2025 Regarding the Executive Regulations of Federal Decree by Law No. (10) of 2025, UAE Financial Intelligence Unit
  3. Understanding the Law, UAE Financial Intelligence Unit
  4. Best Practices for Licensed Financial Institutions on Implementing Role-Based AML/CFT/CPF Training, Central Bank of the UAE (CBUAE Rulebook)
  5. Anti-Money Laundering and Combating the Financing of Terrorism and Illegal Organisations Laws, Central Bank of the UAE (CBUAE Rulebook)
  6. Overview of DFSA AML, CTF and sanctions obligations, Dubai Financial Services Authority

This page is general information, not legal or compliance advice. Check the primary sources above and obtain advice for your circumstances. See our editorial standards.

Ready to see it?

Bring a subject. Leave with a framework.

A 45-minute working session with our team on a real subject or program you own. You see the system operate on your material, and you keep the framework it produces.

We reply within one business day.