The UAE Has Passed One Test. This Is the Next One.
The UAE’s removal from the FATF grey list in February 2024 was a genuine achievement. It followed two years of intensive legislative and institutional reform, during which the country completed all 15 action plan items FATF had required, rebuilt enforcement capacity across multiple regulators, and demonstrated material improvements in financial intelligence outputs. The question worth asking now is a harder one: what does the 5th Round Mutual Evaluation, with its onsite assessment scheduled for June 2026, actually require of regulated entities operating in the UAE?
The honest answer is that the evaluation will test something most compliance programmes in this market have not been designed to demonstrate: not that rules exist on paper, but that those rules produce measurable outcomes in practice. For compliance officers, legal counsel, investment managers and family office principals operating across ADGM, DIFC, DMCC and the onshore UAE market, the distinction matters. A programme built around policy documents and database screenings will satisfy a box-checking examiner. It will not satisfy a FATF assessor operating under the 2022 fifth-round methodology.
What the Fifth Round Methodology Actually Measures
The FATF’s 2022 methodology assesses two distinct dimensions: technical compliance, which asks whether the required laws and rules exist, and effectiveness, which asks whether they produce the intended outcomes. For the UAE, technical compliance is largely demonstrated. The country was rated Compliant for 15 of the 40 Recommendations and Largely Compliant for a further 24 following its third follow-up report in 2023. It received no Non-Compliant ratings.
Effectiveness is the more difficult terrain. The UAE’s 2020 Mutual Evaluation Report identified weaknesses across multiple Immediate Outcomes (IOs), and the follow-up cycle since then has addressed technical compliance improvements far more visibly than it has documented operational effectiveness at the entity level. Under the fifth-round methodology, assessors evaluate performance against all 11 IOs using four ratings: High, Substantial, Moderate and Low. For a major international financial centre, anything below Substantial on the core financial sector IOs will be noticed.
The IOs that FATF assessors are most likely to scrutinise in the UAE context include IO3 (adequate supervision and monitoring of financial institutions and DNFBPs), IO4 (financial institutions and DNFBPs applying effective AML/CFT preventive measures), IO5 (beneficial ownership transparency), IO6 (effective use of financial intelligence) and IO11 (prevention and suppression of proliferation financing). The 2022 methodology also formally separates financial institution supervision from DNFBP supervision into different IOs, which means weaknesses in the professional services, real estate, precious metals and corporate services sectors will be visible rather than obscured within aggregate findings.
On-site visits under the fifth round last two to three weeks. Assessors look back across four to five years of data. They will interview private sector representatives directly, and those interviews will probe not whether a firm has a risk assessment, but whether the risk assessment is current, whether it is aligned to the UAE’s 2024 National Risk Assessment findings, and whether it has actually changed the firm’s due diligence behaviour.
The Legislative Reset and Its Compliance Consequences
The UAE’s regulatory landscape has been significantly restructured in the eighteen months preceding this evaluation. Federal Decree-Law No. 10 of 2025, which came into force on 14 October 2025 and repeals Federal Decree-Law No. 20 of 2018, is not an incremental amendment. It is a comprehensive new framework that criminalises proliferation financing as a standalone offence, lowers the threshold required to establish a money laundering offence, expands the FIU’s powers to freeze assets for up to 30 days without prior notice, and introduces personal criminal liability for senior managers and directors who breach their oversight obligations.
Cabinet Decision No. 134 of 2025, which came into force on 14 December 2025 and serves as the executive regulations for the new law, codifies 71 articles and close to 300 enforceable requirements. The document governs governance frameworks, customer due diligence standards, transaction monitoring obligations, STR filing requirements and record-keeping across all Licensed Financial Institutions, Designated Non-Financial Businesses and Professions (DNFBPs) and Virtual Asset Service Providers (VASPs). It formally brings commercial gaming operators into the DNFBP category for transactions above AED 11,000.
The CBUAE followed this with four updated guidance documents published in April 2026, covering counter-proliferation financing, trade-based money laundering, correspondent banking and customer due diligence. The counter-proliferation financing guidance is particularly significant: it treats CPF not as an extension of AML/CFT but as a separate compliance pillar, requiring a distinct PF risk assessment that addresses customer, product, jurisdictional and delivery channel risk through the specific lens of weapons of mass destruction proliferation.
For entities operating in ADGM and DIFC, the FSRA and DFSA maintain their own supervisory frameworks aligned with but not identical to the federal regime. ADGM-regulated entities are exempt from Cabinet Resolution No. 109 of 2023 on beneficial ownership, being governed instead by the FSRA’s own rulebook. This does not reduce the substantive obligation; it means the evidentiary standard for UBO verification is applied through a different instrument. VARA-regulated entities in Dubai must comply with both the federal framework and VARA’s Compliance and Risk Management Rulebook, including Travel Rule obligations for virtual asset transfers above USD 1,000.
What Assessors Will Find When They Interview Private Sector Firms
There is a specific failure mode that recurs in FATF mutual evaluations of financial centres that have prioritised technical compliance: the regulated entity can produce its policies but cannot explain how those policies have changed its operational decisions. Assessors under the fifth-round methodology are trained to identify this gap. They look for evidence of a closed loop: the national risk assessment informs the business-wide risk assessment, which drives CDD standards, which are reflected in enhanced due diligence procedures for identified high-risk customers, which produce STRs of sufficient quality to generate actual intelligence value.
The UAE’s 2024 National Risk Assessment rated drug trafficking and fraud as the highest ML threats, followed by goods piracy, cash and gold smuggling, foreign corruption and tax evasion. A compliance programme that does not specifically reference these risk categories and cannot demonstrate that they have influenced due diligence decisions for relevant customers is not, in FATF’s terms, risk-based. It is risk-labelled.
Several structural characteristics of the UAE market make effectiveness harder to demonstrate than in more transparent jurisdictions. Beneficial ownership verification in free zones remains an area of documented complexity: while Cabinet Resolution No. 109 of 2023 requires identification of natural persons with 25% or more ownership or control, and changes to ownership must be reported within 15 working days, the practical verification of layered structures through nominee arrangements or multi-jurisdictional holding chains requires active investigation rather than form completion. Assessors will ask how firms handle structures where the declared UBO does not appear to have the economic profile consistent with the transaction. They will ask what steps are taken when a database check returns a clean result but source-of-funds documentation is thin.
STR quality is a second area of scrutiny. The volume of STRs filed is insufficient evidence of effectiveness; assessors examine whether reports are typology-driven, whether they connect identified red flags to specific predicate offences, and whether they have generated law enforcement referrals or contributed to asset recovery actions. A firm that files defensively, to create a record of having filed, rather than because its analysis has identified a specific typology match, will communicate the wrong thing during an examiner interview.
What This Means in Operational Terms
The evaluation creates direct consequences for regulated entities, not only for national regulators. The following obligations are not aspirational; they flow from Federal Decree-Law No. 10 of 2025, Cabinet Decision No. 134 of 2025 and the applicable ADGM, DFSA or VARA supervisory frameworks.
Business-wide risk assessments must be aligned to the UAE’s 2024 National Risk Assessment findings. If the NRA rates foreign corruption and tax evasion as elevated ML threats, and your business serves corporates with significant cross-border activity, your BWRA must reflect this and your CDD procedures must respond to it with proportionate enhanced scrutiny.
Beneficial ownership verification must go beyond registry checks. Cabinet Resolution No. 109 of 2023 and the equivalent FSRA and DFSA frameworks require identification and verification of natural person UBOs. Verification requires corroboration from independent sources; accepting a self-declared structure without adverse media screening, corporate registry cross-checks or, for high-risk relationships, direct source enquiry does not meet the standard.
Proliferation financing must be treated as a standalone compliance obligation. The CBUAE’s April 2026 guidance requires a documented PF risk assessment separate from the AML/CFT risk assessment. Real-time sanctions screening against UN Security Council Resolutions 1718 (DPRK) and 2231 (Iran), as well as the UAE Local Terrorist List, must cover not only customers but beneficial owners, related parties and, for trade finance, counterparties and shippers.
STR quality must be measurable. Firms should be able to demonstrate the ratio of STRs filed to suspicious activity alerts generated, the typologies reflected in reports, and outcomes where available. Assessors will read a sample of STRs. Reports that are vague, do not identify a predicate offence, or use boilerplate language will be identified as indicators of form-filling compliance rather than effective financial intelligence.
Personal liability for senior managers is now statutory. Article provisions under Federal Decree-Law No. 10 of 2025 allow criminal liability to attach to directors and senior managers who breach oversight obligations, not only to the institution. The evaluation will examine whether boards and senior management demonstrate genuine ownership of the AML/CFT/CPF programme, not whether they have signed off on a policy.
The Question That Due Diligence Firms Must Answer
The FATF evaluation assesses the UAE’s national system, but the data points the assessors collect come from individual firms. When an assessor interviews a compliance officer at a DIFC asset manager, or a MLRO at an ADGM-regulated family office, or a risk manager at a DMCC precious metals trader, they are building a picture of whether the regulatory framework is producing real-world outcomes. The absence of documented, evidence-based due diligence processes in a high-risk relationship file is not just a compliance gap; it is a data point in a national assessment that determines the UAE’s international standing.
The practical question for due diligence practitioners is not whether their firm has a policy. It is whether that policy, when examined by someone trained in investigative methodology, produces a defensible account of how the firm identified, assessed and managed the specific risks presented by each counterparty, investor or customer. That is a different standard from what most technology-led compliance programmes in this market currently deliver. Database screening identifies disclosed risk; it does not investigate undisclosed risk. STR filing creates a record; it does not replace the analytical judgment that should precede it.
The gap between demonstrated compliance and actual effectiveness has been the defining challenge of UAE financial crime regulation since the 2020 MER. The 2026 evaluation will determine whether that gap has closed. The answer will come not from the regulators alone, but from the quality of the evidence that regulated entities can produce when asked to defend their decisions in a room with a FATF assessor.