Financial Crime

AML / CFT Compliance

Riskweise builds, tests and runs anti-money laundering and counter-terrorist financing frameworks for financial institutions and designated businesses in the UAE and the wider GCC, from the business risk assessment and the policy set through screening system validation, training and regulatory reporting, aligned with Federal Decree-Law No. 10 of 2025 and its Executive Regulations.

The UAE replaced its anti-money laundering law in 2025. Federal Decree-Law No. 10 of 2025 took effect on 14 October 2025 and its Executive Regulations, Cabinet Resolution No. 134 of 2025, on 14 December 2025. A framework written against the 2018 law now cites repealed provisions. Ten services are listed below and can be taken singly or together. The accountable compliance officer remains yours throughout: we build, test and support, and we do not take over a statutory role.

Methodology

How we approach it.

01, Component

Assess: business risk assessment, annual risk assessment report, health check

The business risk assessment is the document every other control is supposed to follow from: customers, products, channels, geographies and delivery, scored for inherent risk, set against the controls in place, with a residual rating the Board has approved. We build it as an editable model with the scoring method visible, refresh it as the annual AML/CFT risk assessment report, and run the health check as an independent read of the whole framework against the current law, the supervisor's guidance and what the institution actually does. The health check is the usual starting point where a framework predates the 2025 law.

02, Component

Build: policies and procedures, compliance department setup, software selection

A policy set written to the 2025 Decree-Law and its Executive Regulations and to the institution's own risk assessment, covering customer due diligence, enhanced and simplified measures, politically exposed persons, targeted financial sanctions, suspicious transaction reporting, record keeping and governance, with procedures a first-line team can follow. For an institution building the function, the department design: roles, reporting lines to the Board, committee terms of reference, the compliance officer's mandate, monitoring plan and management information. For system selection, a requirements specification and a scored evaluation of screening, transaction monitoring and case management vendors. We hold no vendor relationships and take no commission.

03, Component

Test: screening software testing and validation

Sanctions and name screening engines and transaction monitoring systems are models, and they fail in the ways models fail: thresholds set once and never revisited, fuzzy matching that misses transliterated Arabic names, list updates that do not load, scenarios that fire on noise and stay silent on the typology they were built for. We test them the way we validate a credit model. Controlled test data with known true matches and deliberate variations, measured detection and false positive rates, threshold sensitivity, above-the-line and below-the-line sampling, list completeness and timeliness, data lineage from core system to screening input, and a documented validation report. This is the part of the service that draws most directly on the practice's model validation work.

04, Component

Run: training, regulatory reporting, managed KYC and customer due diligence

Training by audience: Board and senior management, the compliance function, and front-line staff, built on the institution's own risk assessment and typologies, with attendance and assessment records a supervisor can inspect. Regulatory reporting support covering the returns and questionnaires the supervisor requires and the preparation and quality review of suspicious transaction and activity reports filed through the goAML platform; the decision to file, and the filing, stay with your compliance officer. Managed KYC and customer due diligence: onboarding files, periodic reviews, remediation backlogs and enhanced due diligence research prepared to your procedures and your risk ratings. This is outsourced work carried out under your procedures and your control, not the regulated third-party reliance the Executive Regulations describe, and responsibility for the accuracy of the due diligence stays with the institution, so every file comes back for your sign-off.

What we deliver

Concrete outputs.

  • AML/CFT policy, controls and procedures documentation
  • In-house AML compliance department setup
  • AML training
  • AML software selection
  • Annual AML/CFT risk assessment report
  • AML/CFT health check
  • Business risk assessment
  • AML screening software testing and validation services
  • Regulatory reporting
  • Managed KYC and customer due diligence services
Who this is for

The fit.

  • Banks, finance companies and exchange houses licensed by the CBUAE
  • Insurers, brokers and takaful operators
  • Payment service providers, stored value facilities and fintechs
  • Virtual asset service providers, including firms licensed by VARA
  • Firms in the DIFC and ADGM, under DFSA and FSRA rulebooks
  • Designated non-financial businesses and professions: real estate brokers, dealers in precious metals and stones, corporate service providers, auditors and law firms
  • Institutions preparing for a supervisory examination or responding to findings
Common questions

Questions we get asked.

Which law governs AML and CFT in the UAE now?

Federal Decree-Law No. 10 of 2025 Regarding Anti-Money Laundering, and Combating the Financing of Terrorism and Proliferation Financing. It was issued on 30 September 2025, took effect on 14 October 2025, and repealed and replaced Federal Decree-Law No. 20 of 2018. Its Executive Regulations were issued as Cabinet Resolution No. 134 of 2025 and took effect on 14 December 2025. The new law brings proliferation financing into its title, extends the money laundering offence to conduct through digital systems and virtual assets, and defines virtual assets and their service providers. A policy that still cites the 2018 law and Cabinet Decision No. 10 of 2019 is citing repealed instruments, which is the first thing an examiner will notice.

What is a business risk assessment and how is it different from the annual risk assessment report?

The business risk assessment, sometimes called the enterprise-wide risk assessment, is the institution's own documented assessment of its money laundering, terrorist financing and proliferation financing risks across customers, products and services, delivery channels, geographies and transactions. It sets inherent risk against the effectiveness of controls to reach a residual rating, and it has to be approved by senior management, kept up to date and made available to the supervisor. The annual report is that assessment refreshed for the year: what changed in the business and in the national and sectoral risk picture, how the ratings moved, which controls were tested, and what the Board is being asked to approve. One is the method and the baseline. The other is the yearly evidence that the method is being used.

What does testing and validation of AML screening software involve?

Treating the system as a model and testing whether it does what the institution believes it does. We prepare controlled test data containing names and transactions that should alert, with deliberate variations such as transliteration differences, reordered name parts, missing dates of birth and partial identifiers, and measure how many the system catches. We measure the false positive rate and what drives it, test the sensitivity of results to the matching threshold, sample below the threshold to see what is being missed, check that sanctions and watchlist updates load completely and on time, and trace the data from the core system into the screening input to find customers and fields that never reach the engine. The output is a validation report with findings graded by severity, of the kind a supervisor or internal audit can rely on.

Can KYC and customer due diligence be outsourced in the UAE?

The work can, the responsibility cannot, and two different things are often confused. Article 20 of the Executive Regulations (Cabinet Resolution No. 134 of 2025) lets an institution rely on a third party to apply customer due diligence measures only where that third party is itself regulated and supervised and complies with due diligence and record-keeping requirements, and even then the institution remains responsible for the accuracy of the measures. A managed KYC service is not that kind of reliance. It is outsourcing: our analysts prepare onboarding files, periodic reviews and enhanced due diligence research to the institution's own procedures and risk ratings, the institution's compliance function reviews and approves each file, and the records sit where the institution can produce them on request. For CBUAE licensees an outsourcing arrangement that touches a critical operation also falls under the Operational Risk Management Regulation in force from 14 September 2026, which requires an outsourcing register and, where a Critical Operation could be disrupted, the Central Bank's prior no-objection.

Do you act as our Money Laundering Reporting Officer or file suspicious transaction reports for us?

No. The compliance officer role is a statutory appointment that belongs to the institution and is subject to the supervisor's fitness and propriety expectations. We support that person: drafting and quality-reviewing suspicious transaction and activity reports, preparing regulatory returns, building the management information, and coaching a newly appointed officer through the first cycles. The judgement to report and the act of filing through goAML remain with your appointed officer.

Which regulators and sectors do you cover?

In the UAE, institutions supervised by the Central Bank, the Securities and Commodities Authority, the Virtual Assets Regulatory Authority, the DFSA in the DIFC and the FSRA in the ADGM, and designated non-financial businesses and professions supervised by the Ministry of Economy and the Ministry of Justice. Across the GCC the same method applies under each jurisdiction's own law and the standards of the Financial Action Task Force, and we confirm the current instruments at the start of each engagement, since this is an area where they change often.

Do you sell or resell AML software?

No. Software selection is advice on a purchase you make: a requirements specification built from your risk assessment and volumes, a long list, scored demonstrations against your own test cases, reference checks and a recommendation. We have no reseller agreements and receive nothing from any vendor. The same independence is why we can validate a system after it is installed.

Get in touch

Tell us about your financial crime engagement.

We respond within one business day. No agency-style discovery process, straight to scope, fit, and what you actually need.

Start the conversation