Tipping Off in the UAE: The 2026 AML Compliance Guide

Tipping off is the fastest way for a compliant UAE business to turn a routine suspicious transaction report into a criminal matter. The team does the hard part correctly: it spots the pattern, escalates it, files on goAML. Then someone at the front desk says the wrong sentence to the customer, and under UAE law that sentence is an offence in its own right. This guide covers what the penalty is, who your staff may lawfully speak to, and how to slow a transaction down without giving the game away.

Last updated: 16 August 2026. Written by the AML/CFT compliance team at ADZ, Dubai.

Quick Answer: What Is Tipping Off in the UAE?

Tipping off is telling a customer or any third party that a suspicious transaction report has been filed or is being considered, or that an investigation is underway. UAE law prohibits it. The Ministry of Economy and Tourism sets the sanction at imprisonment of at least six months and a fine of AED 100,000 to AED 500,000.

Key Takeaways

  • Tipping off is a standalone offence. Article 29 of Federal Decree-Law No. 10 of 2025 penalises the disclosure separately from any underlying money laundering offence.
  • The sanction is personal. The Ministry of Economy and Tourism sanctions table sets imprisonment of no less than six months and a fine of AED 100,000 to AED 500,000, or either penalty. Legal persons face criminal fines reaching AED 100,000,000, and natural persons stay individually liable alongside the company.
  • It covers more than the report itself. The prohibition extends to any related information given to the UAE Financial Intelligence Unit and to any information the FIU requests from you.
  • Your group is carved out. Sharing with foreign branches, subsidiaries or a parent company for the purpose of identifying, preventing or reporting a crime is not a breach of confidentiality.
  • You do not have to exit the customer. After filing, the relationship must be reclassified as high risk with enhanced due diligence applied. Termination is not required.
  • The supervisor tells you how to stall without tipping off. The March 2026 DNFBP Guidelines list permitted delay measures, including citing an unspecified operational problem or requesting further documentation.
  • Good faith protects you. Reporting staff carry statutory protection from administrative, civil and criminal liability, even if no crime turns out to have occurred.

What Does UAE Law Say About Tipping Off?

Two instruments govern the duty. Federal Decree-Law No. 10 of 2025 on anti-money laundering, combating the financing of terrorism and the financing of proliferation came into force on 14 October 2025, replacing Federal Decree-Law No. 20 of 2018. Its Cabinet Decision No. 134 of 2025 executive regulations followed on 14 December 2025, replacing Cabinet Decision No. 10 of 2019.

Article 29 of the decree-law creates the tipping off offence. Article 15 carries the internal control, risk assessment and reporting obligations that a tipping off failure usually breaches at the same time. For businesses supervised by the Ministry of Economy and Tourism, the operating detail sits in the AML/CFT/CPF Guidelines for DNFBPs, March 2026 edition. Section 10.10 is the passage your policy should quote.

The wording the supervisor actually uses

Under no circumstances, the guidelines say, may a business or its managers or employees inform a customer, their representative, or any third party, directly or indirectly, that a report is intended or has been made. The same bar covers disclosing information contained in the report, or revealing that an investigation is underway.

The phrase “directly or indirectly” is the part that catches people. A raised eyebrow, a change in how a relationship manager returns calls, or a hint that a client should “maybe use a different bank for this one” can all count as indirect disclosure.

What counts as a disclosure

The prohibition applies to more than the moment of filing. Per section 10.10, it covers the act of reporting a suspicious transaction, any related information provided to the UAE Financial Intelligence Unit, and any information the FIU requests from you. That pulls the following inside the confidentiality perimeter:

  • The internal escalation from a staff member to the compliance officer, before any decision to file has been taken
  • The suspicious transaction report or suspicious activity report itself, and its goAML submission number
  • Additional Information File requests, with or without transactions, that the FIU sends through the goAML message board
  • Requests for Information the FIU issues to you or to other reporting entities
  • Any directive the FIU gives you about the transaction or the relationship, including the timing of that directive

Still setting up your reporting channel? Our goAML portal registration guide and our walkthrough on how to file an STR in the UAE cover the mechanics either side of this duty.

Your policy is only as good as the people applying it. Compliance 360, the ADZ training arm, runs 32 specialised AML/CFT courses approved by KHDA, including front-line staff modules on reporting conduct. Explore ADZ AML training programmes.

What Is the Penalty for Tipping Off in the UAE?

The Ministry of Economy and Tourism publishes a sanctions table in section 5 of the March 2026 DNFBP Guidelines. Item 9 covers tipping off directly. The table below reproduces the entries a compliance officer needs when briefing a board, because a tipping off incident rarely arrives on its own.

Offence Sanction
Tipping off (notifying or warning a person of an STR, SAR or investigation) Imprisonment of no less than 6 months and a fine of AED 100,000 to AED 500,000, or either penalty
Violation of Article 15 obligations (internal controls, risk assessment, reporting) if intentional or by gross negligence Imprisonment and a fine of AED 100,000 to AED 1,000,000, or either penalty
General violation of other provisions where no specific penalty is prescribed Imprisonment or a fine of AED 10,000 to AED 100,000
Corporate (legal person) liability Criminal fine reaching AED 100,000,000 depending on the offence, plus possible confiscation, suspension of activity, closure of premises, dissolution, and publication of the judgment

Who does the tipping-off penalty fall on?

This is the point that changes staff behaviour in a training room. Tipping off is charged against the person who made the disclosure. A relationship manager who warns a client is personally exposed to imprisonment and a six-figure dirham fine. The guidelines are explicit that natural persons remain individually liable even where the company is also penalised, and no corporate indemnity cures that.

The company exposure runs alongside it

A tipping off incident is almost never a single-line finding. It normally arrives with an Article 15 failure attached, because if a staff member could disclose freely then the internal controls, the escalation procedure and the training were all inadequate. Supervisors read the disclosure as evidence of the control gap. That is how one conversation becomes a programme-wide finding, and how a finding becomes the kind of correspondence covered in our guide on responding to an AML regulatory notice.

The enforcement backdrop supports taking this seriously. The Ministry of Economy fined 29 DNFBP companies AED 22.6 million across 225 violations in one announced action. The Central Bank of the UAE issued more than AED 370 million in AML/CFT penalties during 2025, including a case where a head of compliance was personally fined AED 300,000.

When Does the Tipping-Off Duty Start and End?

Most teams assume the tipping-off clock starts at submission. It starts earlier and it runs longer.

Before you file: the internal suspicion window

The duty attaches from the moment a suspicion or reasonable grounds for suspicion form, not from the moment the report goes to the FIU. The DNFBP Guidelines require internal reporting to the compliance officer directly once suspicion is established. Any internal investigation before that point must be shown to have started immediately and continued without interruption. Everything in that window is confidential, so a staff member cannot warn a colleague outside the escalation chain, and cannot flag it to the customer while “checking a few things”.

After you file

Filing does not release the tipping-off duty. It extends it, because you now hold a goAML submission number and a live relationship that must be handled without revealing either. This is the window where most tipping off happens, and the delay measures below address it directly.

While the FIU is asking questions

The FIU may come back with instructions, an Additional Information File request, or a Request for Information. The guidelines require strict confidentiality over all FIU directives.

One instruction catches people out. Depending on the case, the FIU may require the compliance officer to keep information privileged even inside the organisation, restricting it to named senior management or the board. Staff then follow the compliance officer’s instructions without being told why.

Every one of those interactions needs a record. Log the exact date and time the FIU directive was received, the timing and manner of executing it, and who was told what. Retention follows the obligations set out in our guide to AML record-keeping requirements in the UAE.

Who Can You Tell Without Tipping Off?

There is a lawful channel, and compliance officers routinely under-use it because they assume total silence is the only way to avoid tipping off. Total silence can itself breach group oversight obligations.

Inside your own organisation

The confidentiality requirement does not apply to communication within the business for the purpose of identifying, preventing or reporting a crime. It does require that the circle stays defined. Information should reach only those who need it to do their job, and should not travel further because a manager was curious. Name the roles inside that circle in the policy rather than leaving it to judgement in the moment.

Foreign branches, subsidiaries and the parent company

The March 2026 guidelines state that the confidentiality requirement does not pertain to communication within the business or its affiliated group members, meaning foreign branches, subsidiaries or the parent company. The permitted purpose is identifying, preventing or reporting a crime. Group escalation is expected. Routing that information onward to a customer-facing team elsewhere in the group, with no role in the reporting, is not.

The professional secrecy exemption, and its limits

Lawyers, notaries public, other legal stakeholders and independent legal auditors have a narrow exemption where information was obtained while advising or defending a client in legal or judicial proceedings. Two limits matter. It exempts from the reporting obligation only, and it is not permission to tell the client they were nearly reported. It also does not stretch to the commercial work those same firms do, such as forming companies, holding client money, or acting on a property transaction.

Our guide on customer due diligence in the UAE sets out where those obligations bite.

How Do You Delay a Transaction Without Tipping Off?

This is the practical bind. Where a report concerns a pending transaction, the guidelines expect best efforts to delay execution so the FIU has a reasonable window to respond, without arousing the customer’s suspicion. The supervisor does not leave you to improvise. Section 10.12 of the DNFBP Guidelines lists measures you may consider, singly or in combination.

Permitted delay measure How it works in practice
Delay processing without explanation Simply do not progress the file. Works for short windows and low-contact relationships.
Cite an unspecified operational or technical problem Tell the customer a system or process issue is being resolved. Keep it vague and consistent across everyone who speaks to them.
Request further information or supporting documents Ask for licences, shipping or customs paperwork, further identification, or bank references. This buys time and improves the file at once.
State that paperwork has been lost and must be resubmitted A recognised measure in the guidelines. Use sparingly, because it is the least credible on repeat.
State that the transaction is pending internal approval Effective where your published process already includes approval gates, so nothing looks unusual.

Three rules govern all of them. Keep the story consistent, since the fastest way to tip off a customer is to have two employees give two different reasons. Document the measure you chose and why, since the file is what an inspector reads later.

And if you run out of runway before the FIU responds, do not simply push the transaction through. The guidelines direct you back to the FIU for specific instructions on whether to execute or reject.

Not sure your escalation procedure holds up? ADZ maps reporting obligations, drafts the policy language, and builds the escalation chain around your actual operating model. Speak to the ADZ compliance advisory team.

What Happens to the Customer After You File?

Two consequences follow immediately, and only one of them is widely understood.

Reclassify as high risk. Do not automatically exit

The relationship must be reclassified as high risk straight away, with risk-based enhanced due diligence and enhanced ongoing monitoring applied. The guidelines are explicit that terminating it is not required. Reflexive exit is a mistake twice over. It removes your visibility over an account the FIU may be interested in, and an abrupt unexplained termination signals to an attentive customer that something happened.

Our guides on enhanced due diligence and ongoing monitoring set out that step-up.

Follow FIU instructions if they arrive, and act anyway if they do not

The FIU may issue directives or may say nothing at all. Silence is not clearance. Where no feedback arrives within a reasonable period, you still hold the relationship at high risk and continue monitoring it. The absence of a response is not a finding in your favour and should never be recorded as one.

Watch for signs you may already have tipped off the customer

The guidelines list behaviours that should trigger a follow-up report to the FIU as a supplement to the original. Treat each as a fresh suspicion, not as an inconvenience:

  • Sudden material amendments to the details or circumstances of the transaction
  • Excessive pressure, intimidation, anger beyond what the situation warrants, or threats aimed at forcing completion
  • Abrupt cancellation of the transaction, termination of the relationship, or a sudden attempt to close the account and withdraw the balance
  • New adverse information about the transaction, the relationship or the counterparty
  • Any other reasonable grounds to suspect the customer has become aware the matter is being reported

If one of these appears shortly after an internal conversation, treat it as a possible tipping off incident inside your own business and investigate accordingly.

Where Tipping Off Actually Happens

Tipping off rarely comes from a deliberate warning. It comes from five recurring gaps, and each maps to a control you can test.

  1. The apologetic relationship manager. A long-standing client asks why a payment is stuck, and the manager says more than the approved line to preserve goodwill. Control: one rehearsed holding response that every customer-facing role uses.
  2. The unrestricted case file. The report and its supporting documents sit in a shared folder any team member can open. Control: access-restricted case records with an audit trail.
  3. The corridor conversation. The suspicion gets discussed at a desk, in a lift, or on a group chat that includes people outside the circle. Control: a named escalation channel, and a rule that suspicion is never discussed outside it.
  4. The inconsistent story. One employee blames the system, another mentions a compliance check. Control: one owner of the customer narrative, usually the compliance officer.
  5. The exit letter that says too much. A termination notice cites regulatory concerns. Control: legal review of standard offboarding wording before it is ever used.

The failure is operational, not legal. Policies rarely permit tipping off. People do it because nobody told them what to say instead. That is a training problem, which is why staff competency sits at the centre of our guide to AML training requirements for UAE employees.

What Your Tipping-Off Controls Should Look Like

Use the table below at your next programme review, or hand it to an independent reviewer. The right-hand column is what an inspector asks to see, so build the evidence as you go rather than assembling it under deadline.

Control What good looks like Evidence to retain
Written tipping-off policy Quotes the section 10.10 prohibition, names the permitted internal circle, and covers the group carve-out Approved policy with senior management sign-off and version history
Escalation channel One defined route from staff member to compliance officer, with no informal alternatives Procedure document plus a log of internal escalations
Scripted holding responses Approved wording for delayed transactions, tested in training Script library and dated acknowledgements from customer-facing staff
Access controls on report files Named users only, with logging on the case record Access list and system audit trail
Role-based training Front-line, management and compliance modules, refreshed at least annually Attendance records, assessment results, training calendar
FIU directive handling Time-stamped receipt, defined executor, restricted distribution Directive log with dates, times and actions taken
Offboarding review Standard exit wording that never cites a compliance reason Reviewed template and a sample of issued notices
Independent testing Tipping-off controls tested as a discrete line item in the AML audit Audit report, findings and remediation tracker

The compliance officer owns most of this. Where that role is still loosely defined, our guide to MLRO responsibilities in the UAE sets out the full remit. Our AML inspection preparation guide covers how these records get examined.

A note on the 2026 mutual evaluation

The UAE’s fifth-round FATF mutual evaluation, with the onsite visit expected in June 2026, is weighted toward effectiveness rather than rules on paper. Assessors look at whether suspicious transaction reporting genuinely works, and that includes whether reporting entities protect the integrity of the process. A documented, tested tipping-off control set is one of the clearer ways to show that your reporting is real.

Have your controls tested before someone else does. ADZ conducts four types of independent AML/CFT audit covering federal, DFSA, VARA and supply-chain requirements. Book an independent AML/CFT audit with ADZ.

Frequently Asked Questions

What is tipping off under UAE AML law?

Tipping off means informing a customer, their representative or any third party, directly or indirectly, that a suspicious transaction report has been made or is intended. It also covers disclosing information contained in that report, or revealing that an investigation is underway. Article 29 of Federal Decree-Law No. 10 of 2025 makes it a criminal offence, and the Ministry of Economy and Tourism DNFBP Guidelines set out the prohibition in section 10.10.

What is the penalty for tipping off in the UAE?

The Ministry of Economy and Tourism sanctions table sets imprisonment of no less than six months and a fine of AED 100,000 to AED 500,000, or either of those two penalties. Legal persons face criminal fines reaching AED 100,000,000 depending on the offence. A court may also order confiscation, suspension of activity, closure of premises, dissolution and publication of the judgment.

Can I tell a customer their transaction was reported?

No. That is the core prohibited disclosure, and it applies whether the report has already been filed or is still being considered. It also applies to indirect signals such as hinting that the customer should route the payment elsewhere. Use an approved holding response instead, and route all questions about the delay to a single owner.

Can I exit a customer after filing an STR?

You are not required to. The DNFBP Guidelines direct you to reclassify the relationship as high risk and apply enhanced due diligence and enhanced ongoing monitoring. They state that termination is not required. If you do exit for commercial reasons, the notice must never cite a compliance concern, a regulatory issue or a report, since an abrupt or explained termination can itself amount to an indirect disclosure.

Does the tipping-off rule apply inside my own group?

No. The confidentiality requirement does not apply to communication within the business or with affiliated group members, meaning foreign branches, subsidiaries or a parent company, where the purpose is identifying, preventing or reporting a crime. It does still apply to anyone outside that purpose, including customer-facing teams elsewhere in the group who have no reporting role.

Is it tipping off to ask a customer for more documents?

No, and the DNFBP Guidelines list it as a permitted way to delay a transaction while the FIU considers a report. Requesting licences, shipping or customs documents, further identification or bank references is a normal due diligence step. Keep the request proportionate and consistent with how you treat comparable customers so it does not stand out.

Am I protected if I report in good faith and no crime occurred?

Yes. The AML law and executive regulations protect the business, its board members, employees and authorised representatives from administrative, civil and criminal liability arising from good-faith reporting to the FIU. That protection applies even if you did not know precisely what the underlying criminal activity was, and regardless of whether illegal activity in fact occurred.

Who inside my business should know about a filed report?

Only those who need the information to perform their role in identifying, preventing or reporting the crime. The compliance officer defines that circle in advance and names the roles in the policy. In some cases the FIU may require information to be restricted even further, to named senior management or board members, and staff must then follow the compliance officer’s instructions without receiving an explanation.

Related Reading

Getting the Tipping-Off Rules Right

Tipping off is one of the few AML failures where a single sentence from an untrained employee creates personal criminal exposure and hands a supervisor evidence of a control gap at the same time. The controls that prevent it are unglamorous: a defined escalation route, a restricted case file, one approved holding line, and staff who have practised using it. ADZ builds and tests exactly those controls for UAE businesses, from policy drafting through to independent audit. Contact ADZ for a consultation and gap analysis.

Official sources referenced in this tipping-off guide: the Ministry of Economy and Tourism AML/CFT/CPF Guidelines for DNFBPs (March 2026), the Ministry of Economy and Tourism, and the UAE Financial Intelligence Unit.

Disclaimer: this guide is general information on UAE AML/CFT obligations as at 16 August 2026 and is not legal advice. Requirements differ by sector, supervisor and licensing jurisdiction. Confirm your specific obligations with your supervisory authority or a qualified adviser before acting.

Scroll to Top