AML Compliance for Corporate Service Providers in the UAE (2026)
Corporate service providers — company formation agents, registered agents and businesses that set up or administer companies for clients — are Designated Non-Financial Businesses and Professions (DNFBPs) under UAE law, and the obligations tightened sharply on 14 October 2025 when Federal Decree-Law No. 10 of 2025 replaced the 2018 AML law. The decisions that matter in 2026 are whether your firm is registered on goAML, whether your customer due diligence meets the new law's evidentiary bar, and whether your internal risk assessment reflects the expanded scope. Every material claim below carries an official source.
The law that governs CSPs in 2026
Federal Decree-Law No. 10 of 2025, in force since 14 October 2025, repeals and replaces Federal Decree-Law No. 20 of 2018 and aligns the UAE with the latest FATF standards. Its Executive Regulations were issued under Cabinet Resolution No. 134 of 2025. (Mondaq — Federal Decree-Law No. 10 of 2025; UAE Legislation Portal) Company service providers sit squarely in the DNFBP perimeter, which the new law broadened — including explicit coverage of virtual-asset related services. UAE FIU
What a CSP must actually do
AML/CFT risk assessment
- What it means for a CSP: Document the firm's exposure: nominee arrangements, layered ownership, high-risk jurisdictions, shells formed for unclear purposes
- Source: FD-L 10/2025 risk-based approach
Customer due diligence (CDD)
- What it means for a CSP: Identify the client and beneficial owners, verify identity documents, understand the corporate structure being formed or administered
- Source: FD-L 10/2025; Cabinet Resolution No. 134 of 2025
Enhanced due diligence (EDD)
- What it means for a CSP: Higher-risk clients — politically exposed persons, complex offshore structures, cash-heavy introducers — need senior-management approval and deeper source-of-funds checks
- Source: FD-L 10/2025
goAML registration and reporting
- What it means for a CSP: Register with the UAE Financial Intelligence Unit and file suspicious transaction reports through goAML
- Source: UAE FIU — goAML
Record keeping
- What it means for a CSP: Retain CDD and transaction records per the law's retention periods, accessible to supervisors on request
- Source: FD-L 10/2025
Compliance officer and training
- What it means for a CSP: Appoint an AML compliance officer, screen staff, train on red flags annually
- Source: FD-L 10/2025; Executive Regulations
What changed under the 2025 law
The new regime raises the bar in ways CSPs feel directly. Evidentiary thresholds for enforcement are lower and clearer; penalties are elevated; senior management carries explicit liability for failures; and the scope now expressly captures virtual assets and proliferation financing. (Greenberg Traurig — UAE's new AML law) The core money-laundering offence carries 1–10 years' imprisonment and a fine of AED 100,000 up to AED 5,000,000 or the value of the criminal property, whichever is higher. (Mondaq — FD-L 10/2025 penalties table) Administrative penalties for DNFBP breaches sit on top of the criminal exposure — superyacht-level fines are not the ceiling for systemic failures.
The compliance calendar for 2026
A CSP that has not yet re-baselined its programme to the 2025 law should treat the following as this quarter's work:
- Re-issue the firm-wide risk assessment against the new law's scope (including virtual-asset-adjacent introductions).
- Refresh CDD on every active client structure, prioritising older entities and those with opaque ownership.
- Confirm the goAML registration is live and the reporting workflow reaches the FIU within required timelines. UAE FIU
- Retrain staff on the new law's evidentiary standards and senior-management liability.
Our AML team handles the full programme build — see AML compliance services and our setup guide, how to set up AML compliance for a UAE business. Auditors carry their own DNFBP duties, covered in AML compliance for auditors in the UAE.
Related AML concepts CSPs should know
A CSP's programme sits alongside several linked AML concepts: know-your-customer (KYC) onboarding is the first line of CDD, distinct from ongoing transaction monitoring which flags unusual fund movements after incorporation; beneficial ownership transparency — identifying the natural person who ultimately owns or controls a structure, not just the named shareholder — is the single most-cited enforcement gap for formation agents; and sanctions screening against UN and local designated-persons lists must run at onboarding and periodically thereafter, separate from money-laundering risk scoring. A firm that treats these as one undifferentiated "compliance check" typically fails at least one of them.
Frequently asked questions
Are company formation agents really DNFBPs? Yes — businesses that create, register or administer legal persons for clients fall in the DNFBP perimeter, so the full obligations (CDD, goAML, record keeping) apply.
Which law applies now — the 2018 or 2025 law? Federal Decree-Law No. 10 of 2025, effective 14 October 2025, replaced the 2018 law; the 2018 law survives only for historical conduct.
What is the first reportable red flag for a CSP? A client forming an entity with no discernible business purpose, nominee ownership the client cannot explain, or funds moving immediately after incorporation — file a suspicious transaction report through goAML.
Reviewed by Krishna Subash Nair, Anti-Money Laundering Consultant at Finanshels, September 2026. Rules are date-scoped to 2026 and should be re-checked against the UAE FIU and current legislation before compliance decisions.







