The UAE Travel Rule is the obligation to send identifying information about the sender and the receiver alongside the money itself. It applies to wire transfers and to virtual asset transfers, it bites at AED 3,500, and since 14 December 2025 it has sat in binding domestic law rather than in guidance. Most UAE firms already screen names and monitor transactions. Far fewer can prove that a complete originator and beneficiary data set travelled with every qualifying payment they sent, received or passed on last quarter.
That gap matters because the UAE Travel Rule is one of the few AML controls a supervisor can test from the outside. An inspector does not need to read your policy. They can pull a sample of transfers and check whether the fields were there.
Quick Answer: What Is the UAE Travel Rule?
The UAE Travel Rule requires full originator and beneficiary information to accompany any wire transfer or virtual asset transfer at or above AED 3,500. It comes from Cabinet Decision No. 134 of 2025, the Executive Regulations to Federal Decree-Law No. 10 of 2025, and it has been in force since 14 December 2025.
Key Takeaways
- One threshold, two asset classes. AED 3,500 is the trigger for fiat wire transfers and for virtual asset transfers alike.
- The instrument is Cabinet Decision No. 134 of 2025. It is the Executive Regulations to Federal Decree-Law No. 10 of 2025, published on 15 November 2025 and in force from 14 December 2025.
- Unhosted wallets are not carved out. A transfer to or from a self-hosted wallet still carries the data collection obligation.
- Every seat in the chain owes something different. Ordering, intermediary and beneficiary institutions each have their own duty, and passing a payment on unchanged is itself a controlled act.
- Missing data is a decision point, not an error log. You need a written rule for when an incomplete transfer is executed, held, returned or reported.
- Five supervisors can ask. CBUAE, VARA, DFSA, FSRA and the CMA each police the rule inside their own perimeter.
- Records run five years. The retention clock under the 2025 regime applies to the transfer data as much as to the customer file.
- The UAE Travel Rule is inspectable from the outside. A supervisor can sample your transfers and check the fields without reading a single policy document.
What Is the Travel Rule and Why Does It Apply in the UAE?
The definition
The Travel Rule is the requirement that identifying information about the originator and the beneficiary of a transfer must move with that transfer along the whole payment chain. Every institution that handles the payment, and every supervisor who examines it afterwards, should be able to see who sent the value and who received it. It exists because a payment stripped of its parties is the single most useful object in money laundering.
Internationally the rule is FATF Recommendation 16. The FATF adopted a revised version in June 2025 that widened the scope from wire transfers to payments and value transfers generally. That change pulls instant payments, card-based cross-border transactions, digital wallets and virtual asset transfers into the same standard. You can read the current recommendations on the FATF website.
How the obligation reached UAE law
The UAE route from international standard to enforceable duty runs through two instruments:
| Instrument | What it does | In force |
|---|---|---|
| Federal Decree-Law No. 10 of 2025 | The primary AML/CFT law. Replaced Federal Decree-Law No. 20 of 2018 and set the offence, supervisory and penalty framework. | 14 October 2025 |
| Cabinet Decision No. 134 of 2025 | The Executive Regulations. Sets the operational detail, including the AED 3,500 transfer information threshold and the required data fields. | 14 December 2025 |
The practical consequence is that transfer information is no longer a supervisory expectation you argue about. It is a regulation with a number attached. If you have not yet mapped your obligations against the current primary law, start with our guide to Federal Decree-Law No. 10 of 2025.
Why this is a 2026 priority and not a 2025 one
Two things changed the temperature. First, the FATF is assessing the UAE under its fifth-round methodology, which grades effectiveness rather than the existence of rules. Transfer data completeness is exactly the kind of control that produces a file-level evidence trail, so it is easy to sample and hard to talk your way past.
Second, the CBUAE issued an updated AML/CFT/CPF guidance package on 16 April 2026 for licensed financial institutions. One of its supervisory guidelines deals with correspondent banking relationships, where transfer information quality is the whole subject.
Who Must Comply With the UAE Travel Rule?
The duty attaches to whoever handles the transfer, not to whoever owns the customer. That catches more firms than people expect.
Licensed financial institutions
Banks, finance companies, payment service providers and money service businesses carry the full obligation on every qualifying transfer they originate, route or receive. Exchange houses sit squarely inside it, and remittance corridors out of the UAE are among the most heavily sampled flows in the country. Our guide to AML compliance for UAE exchange houses works through the sector controls in detail.
Virtual asset service providers
Exchanges, brokers, custodians and transfer providers dealing in virtual assets carry the same obligation on virtual asset transfers. The point that catches firms out is unhosted wallets. Cabinet Decision No. 134 of 2025 does not exempt transfers to or from a self-hosted address from the data collection obligation.
You may not be able to transmit data to a self-hosted address. You are still expected to collect it, assess the counterparty risk and record what you did. Our VASP AML compliance guide covers the wider VARA regime.
Where DNFBPs actually sit
Real estate brokers, dealers in precious metals and stones, accountants, auditors, lawyers and corporate service providers do not usually originate wire transfers as a service. That does not put them outside the subject.
A DNFBP receiving client funds needs to know where those funds came from. An incoming transfer that arrives with a blank or nonsensical originator field is a red flag the firm is expected to act on rather than file. In practice the DNFBP question is not “do I transmit data” but “what do I do when the data that arrives is wrong”.
Not sure which side of the perimeter you sit on? ADZ conducts independent AML/CFT audits for CBUAE, DFSA and VARA regulated entities, and scopes the review to the transfers you actually handle. Explore ADZ AML/CFT audit services.
What Information Must Travel With a Transfer?
This is the part worth printing and pinning above a payments desk. The data set splits into what you need about the sender and what you need about the receiver, and the two are not symmetrical.
Originator data fields
| Field | Requirement | Note |
|---|---|---|
| Full legal name | Required | As held on the verified customer record, not as typed by the customer |
| Account number or wallet identifier | Required | Where no account exists, a unique transaction reference that permits traceability |
| Verified identifying detail | Required, at least one | Address, national identity number, or date and place of birth |
Beneficiary data fields
| Field | Requirement | Note |
|---|---|---|
| Full legal name | Required | Matched against sanctions and PEP lists before release |
| Account number or wallet identifier | Required | The destination identifier the value actually lands in |
Two operational points follow from that asymmetry. The originator side carries the verification burden, because it is your own customer and you hold the file. The beneficiary side carries the screening burden, because the name is the only thing you can test. Firms that treat both sides as a single validation step usually end up with a screening queue full of unverifiable beneficiary noise and an origination process that lets thin customer records through.
What “verified” means here
Verified means the detail was checked against reliable, independent source documents or data, and the check is evidenced in the customer file. A field copied from a customer instruction and never tested is unverified data occupying a verified field, which is worse than a blank because it makes a weak file look complete. If your onboarding is not producing that evidence, the fix belongs upstream in customer due diligence rather than in the payments system.
The AED 3,500 Threshold Explained
AED 3,500 is the figure set by Cabinet Decision No. 134 of 2025 at which the full information set becomes mandatory for a wire transfer or a virtual asset transfer. It is a low bar by design. It is not a reporting threshold, it is a data threshold, and it applies whether the transfer is domestic or cross-border.
Set the system rule at the conservative bound
Firms sometimes argue over whether the trigger reads as “AED 3,500 and above” or “more than AED 3,500”. The difference is one dirham and no supervisor has ever congratulated a firm for winning that argument. Configure the rule to capture transfers at AED 3,500, document why you chose the lower bound, and spend the effort saved on data quality instead.
Below the threshold is not a blank cheque
Smaller transfers still require the name and the account or wallet identifier of both parties so the payment remains traceable. What relaxes is the verification obligation, not the record. And the relaxation disappears the moment there is a suspicion of money laundering or terrorist financing, at which point you verify regardless of value.
Structuring around the figure
A published threshold is an invitation to sit just under it. Your transaction monitoring rules should look for the pattern rather than the single payment. Watch for repeated transfers just below AED 3,500 to the same beneficiary, a set of related senders funding one destination, or a customer whose average ticket collapses to AED 3,400 shortly after onboarding.
Threshold-adjacent structuring is a monitoring scenario, and if it is not in your rule set, it is a gap an inspector will find quickly. Our AML transaction monitoring setup guide covers scenario design.
Screening the beneficiary name is the hard half. First Compliance runs sanctions and PEP screening against 1,800 plus sanction lists and 5.5 million plus PEP records, and automates goAML reporting. See how First Compliance works.
Who Owes What: Duties Along the Payment Chain
A transfer usually touches three types of institution, and each one has a distinct duty. Compliance programmes that describe only the sending duty tend to fail on the middle and receiving seats.
| Seat in the chain | Primary duty | The control that proves it |
|---|---|---|
| Ordering institution (sends) | Obtain, verify and transmit the full originator set plus the required beneficiary detail | Pre-release validation that blocks a payment with an incomplete mandatory field |
| Intermediary institution (routes) | Pass on all information received, unchanged, and keep a record where a message format truncates it | Straight-through processing controls plus a truncation exception log |
| Beneficiary institution (receives) | Detect missing or meaningless information and apply a risk-based response before crediting | Inbound completeness checks with a documented hold, return and report path |
The intermediary seat is the one firms forget. Stripping or losing information in transit is not a neutral technical event. If your message format drops a field, that is a control failure you need to see, record and remediate, not a formatting quirk to be absorbed silently.
Handling Incomplete or Missing Transfer Information
The UAE Travel Rule turns incomplete data into a decision you have to make rather than an error you can log. Every UAE firm that receives transfers needs a written, approved policy for it. Not a preference. A policy, with named decision rights and time limits.
The four possible responses
- Execute and record. Where the missing element is minor, the counterparty is well understood and the risk assessment supports it. Record the decision and the reason.
- Hold and request. Suspend the transfer, ask the sending institution for the missing detail, and set an internal deadline for a response.
- Reject or return. Where the information is absent, plainly false, or the counterparty will not supply it.
- Report. Where the pattern or the omission itself gives grounds for suspicion, file through goAML.
Where the line sits
A single truncated address on a low-value payment from a known correspondent is a data quality issue. A pattern of incoming transfers from one institution where the originator name is a single letter, a company abbreviation nobody can resolve, or the same generic string every time is not a data quality issue. It is a typology. The trigger for escalation should be the pattern across a counterparty, measured monthly, rather than the individual payment.
When it becomes a report
If the missing or false information gives you grounds for suspicion, the obligation to report is immediate and it does not wait for the transfer to be resolved. Reports go through the Financial Intelligence Unit platform at goAML. Two related duties often get missed at the same moment: you must not tell the customer, and you must keep the reasoning on file. Our guides to filing an STR in the UAE and tipping off cover both sides.
Penalties under the federal AML regime are not nominal. Fines for legal persons run from AED 5,000,000 to AED 100,000,000, and failures connected to suspicious transaction reporting carry a ceiling of AED 5,000,000 under Federal Decree-Law No. 10 of 2025.
Which Regulator Supervises Your Travel Rule Compliance?
The UAE runs a split perimeter, and the supervisor that examines your transfer data depends on where you are licensed and what you move. Firms that pick the wrong rulebook usually build a good programme against the wrong standard.
| Supervisor | Perimeter |
|---|---|
| CBUAE | Licensed financial institutions, and payment tokens including dirham stablecoins. Guidance package updated 16 April 2026. |
| VARA | The sole authority for virtual assets across Dubai mainland and Dubai free zones, with the DIFC carved out. |
| DFSA | The DIFC, under the DFSA Rulebook AML Module. |
| FSRA | ADGM. |
| CMA | Federal onshore securities and commodities activity, excluding the DIFC and ADGM. Replaced the SCA on 1 January 2026. |
Sitting in a financial free zone does not release you from the federal law. It adds a rulebook on top of it. If you operate inside one, read our jurisdiction guides on DIFC AML compliance under the DFSA Rulebook and ADGM AML compliance. The relevant rulebooks are published by the Central Bank of the UAE, the DFSA and VARA.
How Do You Build Travel Rule Controls That Survive an Inspection?
An inspector will not ask whether you comply. They will ask for a sample and check it. Build backwards from that.
- Write the threshold rule down. AED 3,500, stated in the policy, configured in the system, with the two matching.
- Make mandatory fields blocking. If a required field can be left empty and the payment still releases, the control does not exist.
- Separate collection from transmission. Unhosted wallet transfers still require collection even where transmission is not possible.
- Log truncation. Any message format that drops data should raise an exception someone reads.
- Run inbound completeness checks. Received transfers need the same scrutiny as sent ones.
- Screen the beneficiary before release, not after settlement.
- Define the four responses to incomplete data, with owners and time limits.
- Measure counterparty data quality monthly, so patterns surface as patterns.
- Retain for five years. Transfer data falls inside the record-keeping regime.
- Update beneficial ownership within 15 working days of any identified change, so the originator record stays accurate.
- Train the payments team as well as compliance. The people who release payments make the decisions.
- Test it yourself before someone else does. Pull 25 transfers at random each quarter and check every field.
Point nine is where firms lose marks that should be free. Retention rules built for customer files often exclude payment message data. Our guide to AML record-keeping requirements in the UAE sets out what has to be kept and for how long.
Five UAE Travel Rule Failures We See Most Often
- The policy says AED 3,500 and the system says something else. Usually a legacy figure nobody revisited after December 2025.
- Beneficiary screening runs after release. Fast, and useless as a preventive control.
- The unhosted wallet gap. Firms read a transmission limit as a collection exemption.
- Incomplete inbound data is logged, not decided. A report nobody owns is not a response.
- Free zone firms build to one rulebook. The federal law applies alongside the DFSA or FSRA rules, not instead of them.
Frequently Asked Questions
What is the Travel Rule in the UAE?
The UAE Travel Rule requires that identifying information about the originator and the beneficiary accompanies a wire transfer or a virtual asset transfer along the payment chain. It applies at or above AED 3,500 and sits in Cabinet Decision No. 134 of 2025, the Executive Regulations to Federal Decree-Law No. 10 of 2025, in force since 14 December 2025.
What is the AED 3,500 Travel Rule threshold?
AED 3,500 is the value at which the full originator and beneficiary information set becomes mandatory. Below it, the name and the account or wallet identifier of both parties are still needed so the transfer stays traceable, but the verification obligation relaxes. That relaxation ends the moment there are grounds to suspect money laundering or terrorist financing.
Does the UAE Travel Rule apply to unhosted wallets?
Yes. Cabinet Decision No. 134 of 2025 does not exempt transfers to or from unhosted or self-hosted wallets from the data collection obligation. A virtual asset service provider may be unable to transmit data to a self-hosted address, but it is still expected to collect the information, assess the counterparty risk and record the assessment.
What should we do when an incoming transfer has missing originator information?
Apply a written, risk-based policy with four defined outcomes: execute and record, hold and request the missing detail, reject or return, or report through goAML. Decide by counterparty pattern rather than by single payment. Where the omission gives grounds for suspicion, file a suspicious transaction report and do not tell the customer.
Who supervises Travel Rule compliance in the UAE?
It depends on the licence. The CBUAE supervises licensed financial institutions and payment tokens. VARA is the sole authority for virtual assets across Dubai mainland and Dubai free zones, with the DIFC carved out. The DFSA covers the DIFC, the FSRA covers ADGM, and the CMA covers federal onshore securities and commodities activity outside those two financial free zones.
Does the Travel Rule apply to DNFBPs?
DNFBPs such as real estate brokers, dealers in precious metals and stones, accountants and corporate service providers rarely originate wire transfers as a service, so the transmission duty seldom applies to them directly. The receiving side does matter. An incoming client payment with a blank or meaningless originator field is a red flag the firm has to act on.
How long do Travel Rule records have to be kept in the UAE?
Five years under the record-keeping regime introduced by Federal Decree-Law No. 10 of 2025 and Cabinet Decision No. 134 of 2025. The retention duty covers the transfer information itself rather than just the underlying customer file, and many retention schedules still miss that distinction.
Is the UAE Travel Rule the same as FATF Recommendation 16?
Cabinet Decision No. 134 of 2025 gives FATF Recommendation 16 binding domestic force in the UAE with a local threshold and local supervisors. The FATF adopted a revised Recommendation 16 in June 2025 that widened the standard from wire transfers to payments and value transfers generally, including instant payments, digital wallets and virtual asset transfers.
Related Reading
- Federal Decree-Law No. 10 of 2025: UAE AML Compliance Guide
- AML Compliance for VASPs in the UAE: 2026 VARA Guide
- AML Compliance for UAE Exchange Houses: 2026 Guide
- AML Transaction Monitoring in the UAE: 2026 Setup Guide
- How to File an STR in the UAE: 2026 goAML Reporting Guide
- AML Record-Keeping Requirements in the UAE
- CNMR and PNMR Filing on goAML: UAE Sanctions Guide
- DIFC AML Compliance 2026: The DFSA Rulebook Guide
Getting Your Transfer Data Right
The UAE Travel Rule rewards firms that treat transfer information as a control rather than as metadata. The threshold is fixed, the fields are listed, and the evidence either exists in your records or it does not. Most remediation work we see is small: a threshold corrected, a validation made blocking, an inbound check built, a retention schedule extended to payment messages. The cost of finding those gaps yourself is a fraction of the cost of a supervisor finding them for you.
Map your obligations before your next inspection. ADZ is a UAE-based practitioner firm, ISO 27001 and ISO 9001:2015 certified, and an approved channel partner for ADGM, DIFC, DMCC and eight further free zones. Contact the ADZ compliance advisory team for a gap analysis of your transfer controls: AML compliance advisory or speak to ADZ.
Disclaimer: this article is general information on UAE AML/CFT requirements as at 29 August 2026 and is not legal advice. Regulatory instruments and supervisory expectations change. Confirm your obligations with your supervisor or a qualified adviser before acting.


