DFSA
DFSA AML/CTF Obligations for DIFC Firms
· 6 min read · By Aureus Worldwide
DFSA AML/CTF obligations require every DIFC firm within scope to run a documented, risk-based programme to prevent money laundering and terrorist financing. The Dubai Financial Services Authority (DFSA) sets these obligations in its Anti-Money Laundering, Counter-Terrorist Financing and Sanctions module, and they sit on top of the UAE's federal AML framework. Meeting your DFSA AML/CTF obligations is not optional or light-touch, it is one of the areas the regulator supervises most closely, and failures carry serious consequences. This guide sets out what the regime requires in practice.
Who is caught: Relevant Persons
The DFSA AML module applies to Relevant Persons in the DIFC. That includes Authorised Firms, Authorised Market Institutions, registered auditors, and Designated Non-Financial Businesses and Professions (DNFBPs) such as certain company-services providers, dealers in precious metals and stones, and real-estate participants. Crucially, DIFC firms must comply with both the DFSA rules and the UAE federal framework, principally Federal Decree-Law No. 20 of 2018 on anti-money laundering and combating the financing of terrorism and its implementing Cabinet Decision, because the DIFC is a financial free zone within the UAE, not outside it. The two regimes are aligned but distinct, and a compliant firm satisfies both.
The building blocks of a DFSA AML programme
A DFSA-compliant AML programme is built on a risk-based approach: you assess where your money-laundering risk is highest and direct your resources accordingly. The core components are:
- A Business Risk Assessment, a firm-wide analysis of the money-laundering and terrorist-financing risks arising from your clients, products, delivery channels and geographies.
- Customer Risk Assessments, a risk rating for each client that drives how much due diligence you apply.
- Customer Due Diligence (CDD), identifying and verifying clients and their beneficial owners.
- Ongoing monitoring, scrutinising transactions and relationships over time.
- Sanctions screening, checking clients and payments against applicable sanctions lists.
- Suspicious-activity reporting, escalating and reporting concerns.
- Governance, training and record-keeping, the framework that holds it all together.
Each layer should be documented, proportionate and periodically reviewed.
The MLRO and senior-management ownership
Every Relevant Person must appoint a Money Laundering Reporting Officer (MLRO), an approved Authorised Individual, resident in the UAE, with the seniority and independence to run the programme and to decide on suspicious-activity reports without interference. The MLRO owns the day-to-day AML function, produces an annual report to senior management on the effectiveness of the programme, and acts as the firm's point of contact with the authorities. But AML is not the MLRO's problem alone: the DFSA expects senior management to own money-laundering risk as part of the firm's wider systems and controls, with a clear tone from the top.
Customer due diligence and EDD
CDD is where policy meets practice. For each client a firm must identify and verify the customer, understand the nature and purpose of the relationship, and identify and take reasonable steps to verify beneficial owners, the natural persons who ultimately own or control the client. Because beneficial-ownership analysis underpins CDD, it connects directly to the UBO work firms do elsewhere; a single, accurate view of ownership supports both.
The intensity of due diligence flexes with risk:
| Risk level | Approach |
|---|---|
| Lower risk | Simplified due diligence, where permitted and justified |
| Standard risk | Full CDD, identify and verify customer and beneficial owner |
| Higher risk | Enhanced Due Diligence (EDD), additional verification, source of funds and wealth, and senior sign-off |
Enhanced Due Diligence is mandatory for higher-risk situations, Politically Exposed Persons (PEPs), clients connected to high-risk jurisdictions, complex or opaque structures, and correspondent relationships. EDD typically means establishing source of funds and source of wealth, obtaining senior management approval to onboard or continue, and monitoring the relationship more closely.
Sanctions and targeted financial sanctions
Sanctions compliance is a distinct, non-negotiable obligation. Firms must screen clients and transactions against United Nations Security Council sanctions and the UAE's targeted financial sanctions regime, and act immediately, freezing and reporting, on a match. The DFSA issues sanctions notices, and firms are expected to have systems that catch both exact and near matches and keep pace with list updates. A missed sanctions hit is among the most serious failures a firm can make.
Reporting: goAML and the FIU
When a firm knows or suspects, or has reasonable grounds to suspect, money laundering or terrorist financing, it must file a suspicious activity/transaction report with the UAE Financial Intelligence Unit (FIU) through the federal goAML portal, and keep the DFSA informed as required. Firms must register on goAML as part of onboarding their compliance function. Two rules deserve emphasis: reporting is mandatory once the threshold of suspicion is met, and tipping off, alerting the subject that a report has been or may be made, is a criminal offence.
Record-keeping, training and independent review
The regime is only credible if it is evidenced. Firms must:
- Retain records, CDD, transactions and AML documentation, commonly for at least six years.
- Train staff regularly, so employees can recognise and escalate red flags.
- Subject the programme to independent review, testing whether policies are actually working.
- File the annual AML return to the DFSA and respond to thematic reviews.
Well-kept records turn a supervisory visit from a scramble into a straightforward demonstration of control.
Reliance on third parties, group programmes and new risks
Two practical points round out the regime. First, a firm may in defined circumstances rely on another regulated party to perform elements of CDD, but reliance never transfers responsibility, the firm remains accountable for the outcome, so it must satisfy itself that the third party's checks are adequate and that it can obtain the underlying records on request. Where a firm is part of a wider group, it is expected to apply group-wide AML policies consistently, subject to local law. Second, the DFSA expects firms to keep pace with emerging risks, new products, delivery channels and technologies, including virtual assets, and to revisit the Business Risk Assessment as the business and the threat landscape change. An AML programme written once and never reviewed is, in the regulator's eyes, no programme at all.
How the AML regime connects to the rest of the Rulebook
AML does not stand apart. It relies on the firm's conduct-of-business onboarding, feeds off the same beneficial-ownership data used for governance, and is overseen through the firm's senior-management arrangements. Treating AML as a genuine operating function, resourced, owned and reviewed, rather than a compliance formality is what the DFSA looks for.
How Aureus Worldwide can help
Aureus Worldwide is a Dubai-based accounting, tax, CFO and compliance-advisory firm. We are not DFSA-authorised and we do not act as your DFSA-approved MLRO, that role must be filled by an approved Authorised Individual within your firm. What we provide is practical AML and compliance support: help designing risk-based policies and CDD frameworks, beneficial-ownership analysis, goAML and documentation support, and staff training, delivered through our AML consulting and compliance officer support services and coordinated with your DIFC and ADGM advisers. To strengthen your AML programme, contact our team.
Frequently asked questions
Who must comply with the DFSA AML rules?
The DFSA AML module applies to Relevant Persons in the DIFC, Authorised Firms, Authorised Market Institutions, registered auditors and Designated Non-Financial Businesses and Professions. They must also comply with the UAE federal AML framework, including Federal Decree-Law No. 20 of 2018 and its implementing regulations.
Does a DIFC firm need an MLRO?
Yes. Every Relevant Person must appoint a Money Laundering Reporting Officer (MLRO), an approved Authorised Individual, resident in the UAE, with sufficient seniority and independence to oversee the AML programme and to make suspicious-activity reports.
Where do DIFC firms file suspicious activity reports?
Suspicious activity and transaction reports are filed with the UAE Financial Intelligence Unit through the federal goAML portal. Firms must register on goAML and also keep the DFSA informed as required. Tipping off the subject of a report is prohibited.
How long must AML records be kept?
Firms must retain customer due diligence records, transaction records and AML documentation for the period set by the DFSA and UAE law, commonly at least six years from the end of the business relationship or the transaction.