DIFC AML compliance changed shape in 2026. The Dubai Financial Services Authority amended the Anti-Money Laundering, Counter-Terrorist Financing and Sanctions Module of its Rulebook, and the amended version has been in force since April. If your firm operates in or from the Dubai International Financial Centre, the rules you were audited against last year are not the rules you will be audited against this year.
This guide sets out what the DFSA now requires, how UAE federal law sits alongside the Rulebook, and what a compliance team should have in place before the next inspection.
Quick Answer: What is DIFC AML compliance?
DIFC AML compliance means meeting the DFSA Anti-Money Laundering, Counter-Terrorist Financing and Sanctions Rulebook alongside UAE federal AML law. The DFSA administers both inside the DIFC, so one regulator supervises two layers of obligation. The current AML Module, version VER30/04-26, took effect on 1 April 2026. Registered DNFBPs owe a separate registration and annual return under AML 15.
Key Takeaways
- Two layers, one supervisor. The DFSA states that it is the competent authority for administering federal AML, CTF and CPF legislation as it applies to Relevant Persons in the DIFC, with sole administrative oversight and direct supervision.
- The Rulebook was amended twice in 2026. The AML and Glossary Module amendments came into force on 2 March 2026, and Rule-Making Instrument No. 432 of 2026 followed on 1 April 2026.
- The driver was federal. The DFSA aligned the Rulebook with Federal Decree-Law No. 10 of 2025 and Cabinet Decision No. 134 of 2025.
- DNFBPs have their own chapter. AML 15 covers registration, the annual information return, notification of changes, disclosure of regulatory status and whistleblowing procedures.
- Virtual assets are written into the transfer rules. AML 9.3A covers Crypto Token transfers and AML 9.3B covers NFT and Utility Token transfers.
- Federal penalties bite regardless of jurisdiction. Administrative fines for legal entities run from AED 5,000,000 to AED 100,000,000 under the 2025 regime.
- The timing matters. The FATF fifth round onsite evaluation of the UAE is expected in mid 2026, and it assesses effectiveness rather than paperwork.
Who has to comply with the DFSA AML Rulebook?
The Rulebook uses the term Relevant Person. It is broader than most firms assume, and it is the first thing to get right, because the whole module hangs off it.
A Relevant Person in the DIFC covers Authorised Firms, Authorised Market Institutions, Registered Auditors, and Designated Non-Financial Businesses and Professions registered with the DFSA. Branches of foreign firms operating in or from the DIFC are captured on the same basis as locally incorporated entities.
Authorised Firms and Authorised Market Institutions
If you hold a DFSA licence to carry on Financial Services, the full AML Module applies. That includes the business risk assessment obligation in AML 5, the customer due diligence chain in AML 7, the sanctions obligations in AML 10, and the reporting obligations in AML 13. There is no light-touch tier for smaller firms. The risk-based approach in AML 4 lets you scale the intensity of a control, not skip the control.
Registered DNFBPs in the DIFC
DNFBP status inside the DIFC catches the following:
- Law firms, notary firms and other independent legal businesses
- Accounting, audit and insolvency firms
- Real estate developers and agencies handling property transactions
- Dealers in precious metals and precious stones above the cash threshold
- Persons who issue or provide services relating to NFTs or Utility Tokens
Exclusions apply in several of those categories. Check the Rulebook definition against what your firm actually does, not against how the licence is worded.
A DNFBP in the DIFC has to register with the DFSA before carrying on the activity. Registration is not a formality. It brings the firm into the DFSA supervisory population, with the reporting and notification obligations that follow.
What about firms outside the DIFC?
If your entity sits on the mainland or in a non-financial free zone, the DFSA Rulebook does not apply to you. Your supervisor is the Ministry of Economy and Tourism, the Central Bank, the Securities and Commodities Authority or another sectoral authority. We compare the three regimes side by side in our guide to AML requirements across mainland, DIFC and ADGM.
What changed in the DFSA AML Module in 2026?
Two separate instruments landed within a month of each other, which is why some firms have tracked one and missed the other.
The 2 March 2026 amendments
The DFSA confirmed that the updated AML and Glossary Modules came into force on 2 March 2026. The stated purpose was to clarify the AML regime that applies in the DIFC and to align it with the federal legislation introduced in late 2025. That means Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025.
Alongside the amendments, the DFSA published a set of Frequently Asked Questions. Those FAQs address governance, risk assessments, digital onboarding, outsourcing and internal audit expectations. They are supporting material and sit beside the Rules rather than replacing them, but they are the clearest available signal of where the DFSA expects firms to be weak.
Rule-Making Instrument No. 432 of 2026
On 5 March 2026 the DFSA issued its Notice of Amendments to Legislation. Following the close of consultation on Consultation Paper No. 169, the DFSA Board made Rule-Making Instrument (No. 432) 2026, amending the AML Module with effect from 1 April 2026. The Fees Module instrument, No. 433 of 2026, took effect on the same date.
The practical consequence is that the current version of the module is VER30/04-26. If your policy manual cross-references VER28/12-25 or anything earlier, your rule citations are out of date, and an inspector will notice.
Reading the two changes together
| Instrument | In force | What it did |
|---|---|---|
| AML and Glossary Module amendments | 2 March 2026 | Clarified the DIFC AML regime and aligned defined terms with the federal framework |
| Rule-Making Instrument No. 432 of 2026 | 1 April 2026 | Amended the AML Module following Consultation Paper No. 169 |
| Fees Module Instrument No. 433 of 2026 | 1 April 2026 | Amended the fees payable, relevant to DNFBP registration |
| DFSA AML FAQs | Published March 2026 | Set expectations on governance, risk assessment, digital onboarding, outsourcing and internal audit |
Rulebook version drift is one of the most common findings we see. ADZ conducts independent AML/CFT audits for CBUAE, DFSA and VARA regulated entities, and a version check is the first thing we run. Book an independent AML/CFT audit with ADZ.
Does UAE federal AML law apply inside the DIFC?
Yes, and this is the point most DIFC firms get wrong. The DIFC is a financial free zone with its own civil and commercial law, which leads people to assume the federal AML regime stops at the boundary. It does not.
The DFSA states plainly that it is the competent authority for the administration of federal AML, CTF and CPF legislation as it applies to Relevant Persons in the DIFC. In its own words, it has sole administrative oversight and direct supervision of Relevant Persons for compliance with that legislation, including the DFSA AML, CTF and Sanctions Rules.
So a DIFC firm is not choosing between two regimes. It carries both, and one regulator inspects against both.
What the federal layer adds
Federal Decree-Law No. 10 of 2025 replaced Federal Decree-Law No. 20 of 2018 and came into force on 14 October 2025. Cabinet Decision No. 134 of 2025, the executive regulation, followed on 14 December 2025. Together they widened the scope of the regime, raised administrative penalties, lowered the knowledge threshold for offences and brought virtual asset service providers squarely inside the perimeter.
The federal layer also owns the reporting channel. Suspicious transaction and suspicious activity reports go to the UAE Financial Intelligence Unit through the goAML platform, not to the DFSA. Our goAML STR filing guide walks through the submission mechanics.
What the DIFC layer adds
The DFSA Rulebook is more prescriptive than the federal instruments in several places. It sets out an explicit business risk assessment obligation, defined MLRO qualities and responsibilities, an internal reporting chain, record keeping periods, notification triggers and, for DNFBPs, a registration and reporting cycle. Where the federal law states a principle, the Rulebook usually states a rule.
What does the DFSA AML Rulebook actually require?
The module runs to sixteen chapters. The operative ones carry the obligations that inspections turn on, and each has a failure mode we see repeatedly.
AML 4 and AML 5: risk-based approach and business risk assessment
AML 4 requires you to apply a risk-based approach. AML 5 requires you to assess your business AML risks and to maintain AML systems and controls that answer that assessment.
The failure mode is a business risk assessment that reads like a template. It names generic typologies, scores everything medium, and never connects to a control. A defensible assessment names your actual customer types, delivery channels, geographies and products, then explains what each control does about them. We set out the method in our guide to the AML business risk assessment.
AML 6 and AML 7: customer risk assessment and due diligence
AML 6 requires a documented assessment of customer AML risk. AML 7 then sets the due diligence chain. It covers when CDD must be undertaken, the timing, and the standard requirements. It also covers enhanced, simplified and ongoing due diligence, and what to do when you cannot complete CDD at all.
Two points cause most of the trouble. First, the trigger for enhanced due diligence has to be written down and applied consistently, not decided case by case by whoever is onboarding. Second, AML 7.7 means an incomplete file is a decision point, not a pending task that sits open for six months.
AML 8: reliance and outsourcing
You may rely on a third party for elements of CDD, and you may outsource. In both cases the regulatory responsibility stays with you. AML 8.3 adds specific treatment for Money Service Providers.
If your group operates a shared onboarding hub outside the DIFC, this is the chapter that decides whether that arrangement is defensible. See our guide to third-party reliance and outsourced CDD.
AML 9: correspondent banking, transfers and virtual assets
AML 9 covers correspondent banking relationships, electronic fund transfers and audit. Two subsections deserve attention in 2026: AML 9.3A sets additional requirements for Crypto Token transfers, and AML 9.3B sets additional requirements for NFT and Utility Token transfers.
This matters beyond crypto native firms. A DIFC law firm or corporate service provider that issues or services Utility Tokens can find itself inside the DNFBP perimeter and inside these transfer rules at the same time. Firms regulated on the Dubai virtual asset side should also read our VARA compliance guide for the parallel regime.
AML 10: sanctions and international obligations
AML 10.2 covers relevant United Nations resolutions and sanctions. AML 10.3 covers government, regulatory and international findings. In practice this means screening against the UAE Local Terrorist List and the UN Consolidated List, acting on the freeze obligation without delay, and evidencing that your screening ran when you say it ran.
AML 11 and AML 12: the MLRO and training
AML 11 sets the appointment of an MLRO, the qualities the DFSA expects of that person, and the responsibilities of the role. AML 12 requires training and awareness.
Generic annual AML awareness training no longer satisfies a supervisor. The expectation across UAE regulators has moved to role-based training, so a relationship manager, an onboarding analyst and a board member should each receive different content. Our guide to MLRO responsibilities in the UAE sets out the scope of the role.
Role-based training, mapped to the Rulebook. Compliance 360 by ADZ offers 32 specialised AML/CFT training courses, KHDA approved. See the Compliance 360 course list.
AML 13: suspicious activity reports and tipping off
AML 13 sets the internal reporting requirement, the suspicious activity report itself, the tipping off prohibition and the asset freezing obligation. The internal chain matters as much as the external filing: staff report to the MLRO, the MLRO decides, and the decision is recorded either way. A decision not to file is still a decision that has to be documented.
Tipping off is where well-meaning client relationship teams create criminal exposure. Our guide to tipping off in the UAE covers what your team may and may not say after a report is filed.
AML 14: record keeping, notifications and group policies
AML 14 pulls together group, branch and subsidiary treatment, group policies, notifications to the DFSA, record keeping, the annual AML return, communication with the DFSA, employee disclosures and decision making procedures.
Notification obligations are the quiet risk. Firms remember to file the annual return and forget that a change in MLRO, a change in business model or a material control failure can each carry its own notification trigger. Our guide to AML record keeping requirements covers retention periods across UAE regimes.
What do DIFC DNFBPs owe under AML 15?
AML 15 is the chapter that generalist advisers usually miss, because it applies only to DNFBPs and only in the DIFC.
Registration and the annual information return
AML 15.1 covers registration and notifications. Within it, the Rulebook sets out an annual information return and a notification of changes obligation. Withdrawal of registration is handled separately under AML 15.2, and AML 15.3 governs how a registered DNFBP may describe its regulatory status.
That last point catches firms out. A DNFBP registration is not a Financial Services licence, and describing it as one is itself a breach.
Whistleblowing under AML 15.3A
AML 15.3A requires DNFBPs to have whistleblowing arrangements: an interpretation section, policies and procedures, and a record of whistleblowing reports. A small DIFC law firm or audit practice with no formal internal channel has a gap here, and it is a gap that is cheap to close and expensive to be found with.
Transitional relief
AML 16 carries the transitional rules, including specific relief at AML 16.3 for Ancillary Service Providers and DNFBPs. If your firm registered close to the amendment dates, check whether transitional treatment applies to you before assuming the full obligation bit immediately.
What are the penalties for getting DIFC AML compliance wrong?
Exposure comes from both layers, and from the criminal courts on top of them.
| Layer | Who acts | What it looks like |
|---|---|---|
| Federal | Administrative penalty under the 2025 regime | Fines for legal entities running from AED 5,000,000 to AED 100,000,000, with personal exposure for managers |
| DIFC | DFSA disciplinary and remedial powers | Fines, restrictions on the licence or registration, withdrawal of registration, public censure |
| Criminal | UAE courts | Prosecution for money laundering offences, tipping off and failure to report |
The reputational layer is the one firms underestimate. DFSA enforcement outcomes are published, and a DIFC entity trades on the credibility of the centre it sits in.
How should a DIFC firm prepare for the next inspection?
A workable sequence for bringing DIFC AML compliance up to the current Rulebook, assuming you are starting from an existing programme rather than from nothing.
| Window | Action | Output |
|---|---|---|
| Days 1 to 15 | Version audit of every policy against AML Module VER30/04-26 | Corrected rule citations and a gap list |
| Days 16 to 30 | Rebuild the business risk assessment against AML 5, tied to real customer and product data | Board approved risk assessment |
| Days 31 to 45 | Test the CDD chain end to end against AML 7, including EDD triggers and incomplete files | Remediation list with owners and dates |
| Days 46 to 60 | Review reliance and outsourcing arrangements against AML 8, including group hubs | Updated agreements and evidence of oversight |
| Days 61 to 75 | Screening and freeze testing under AML 10, plus alert handling evidence | Screening test results with timestamps |
| Days 76 to 90 | Role-based training refresh under AML 12 and, for DNFBPs, the AML 15 pack | Training records and a completed registration file |
Run ongoing monitoring alongside this rather than after it. Our guide to ongoing monitoring covers the review cycle in detail.
Screening and reporting, automated. First Compliance by ADZ covers CDD, sanctions screening against more than 1,800 sanction lists and over 5.5 million PEP records, and goAML reporting. See how First Compliance works.
Frequently Asked Questions
Does UAE federal AML law apply inside the DIFC?
Yes. The DFSA states that it is the competent authority for administering federal AML, CTF and CPF legislation as it applies to Relevant Persons in the DIFC, with sole administrative oversight and direct supervision. A DIFC firm carries the federal obligations and the DFSA Rulebook at the same time.
What version of the DFSA AML Module is current in 2026?
Version VER30/04-26, which took effect on 1 April 2026 following Rule-Making Instrument No. 432 of 2026. It superseded VER28/12-25. The AML and Glossary Module amendments that preceded it came into force on 2 March 2026.
Who is a DNFBP in the DIFC?
DIFC DNFBP status covers law firms, notary firms and other independent legal businesses, plus accounting, audit and insolvency firms. It also covers real estate developers and agencies, dealers in precious metals and precious stones above the cash threshold, and persons issuing or providing services relating to NFTs or Utility Tokens. Exclusions are set out in the Rulebook.
Do DIFC firms report suspicious activity to the DFSA or to goAML?
Suspicious transaction and suspicious activity reports go to the UAE Financial Intelligence Unit through the goAML platform. The DFSA supervises whether your reporting systems work, but it is not the recipient of the report itself. Separate notification obligations to the DFSA sit under AML 14.
Does a DIFC DNFBP need a whistleblowing policy?
Yes. AML 15.3A requires DNFBPs to maintain whistleblowing policies and procedures and to keep a record of whistleblowing reports. This applies regardless of headcount, so small practices are not exempt.
How often should a DIFC firm refresh its business risk assessment?
At least annually, and immediately on any material change: a new product, a new customer segment, a new jurisdiction, a new delivery channel or a significant control failure. A risk assessment dated more than twelve months back is an inspection finding waiting to happen.
What penalties apply for AML breaches in the DIFC?
Federal administrative fines for legal entities run from AED 5,000,000 to AED 100,000,000 under the 2025 regime, with personal exposure for managers. The DFSA can separately impose fines, restrict or withdraw a licence or registration and issue public censure. Criminal prosecution remains available for money laundering, tipping off and failure to report.
Is the FATF evaluation relevant to a DIFC firm?
Yes. The FATF fifth round onsite evaluation of the UAE is expected in mid 2026 and assesses effectiveness across the eleven immediate outcomes rather than technical compliance alone. Supervisors under evaluation inspect harder, and DIFC firms sit inside the sample.
Related Reading
- AML Requirements: Mainland vs DIFC vs ADGM
- ADGM AML Compliance 2026: Nominee, UBO and Cash Rules
- Federal Decree-Law No. 10 of 2025: UAE AML Compliance Guide
- MLRO Responsibilities in the UAE: 2026 Guide
- AML Business Risk Assessment in the UAE: 2026 Guide
- Third-Party Reliance and Outsourced CDD in the UAE
- How to File an STR in the UAE: 2026 goAML Reporting Guide
- AML Record-Keeping Requirements in the UAE
Official sources
- DFSA: AML and Glossary Modules amendments come into force, FAQs published
- DFSA: Notice of Amendments to Legislation, March 2026
- FATF: United Arab Emirates country page
- Central Bank of the UAE
- UAE Financial Intelligence Unit: goAML
Where ADZ fits
ADZ is an approved channel partner for the DIFC, ADGM, DMCC and eight other free zones, and an ISO 27001 and ISO 9001:2015 certified compliance practice based in Dubai. We conduct four types of independent AML audit, covering the federal and CBUAE scope, the DFSA scope, the VARA scope and supply chain reviews. We also handle goAML registration and DPMSR automation, and we are an affiliate of Anjarwalla Collins and Haidermota, the regional office of Africa Legal Network.
If your DIFC AML compliance programme has not been reviewed against AML Module VER30/04-26, that is the work to do before the next inspection cycle. Speak to the ADZ compliance advisory team about a gap analysis.
Disclaimer: this article is general information on UAE and DIFC AML regulation as at 25 August 2026. It is not legal advice. Rules change, and your obligations depend on your licence, activity and risk profile. Confirm your position against the DFSA Rulebook and take advice before acting.


