The DFSA AML rulebook is the module of the Dubai Financial Services Authority’s rulebook that sets the anti-money-laundering obligations for firms licensed in the Dubai International Financial Centre. Its full name is the Anti-Money Laundering, Counter-Terrorist Financing and Sanctions Module, and it is the working rulebook a DIFC compliance team lives by.
It doesn’t stand alone. A DIFC firm runs a dual framework: the DFSA module on top of the UAE’s federal AML law, both pointing at the same national reporting channel. That layering, and the fact that the federal law underneath was rewritten in late 2025, is the part firms most often get wrong.
What the DFSA AML module is
The module sits inside the DFSA rulebook as the AML chapter, kept current through numbered versions as the rules change. It translates the international standards set by the Financial Action Task Force, and the UAE’s federal law, into the specific obligations a DIFC-licensed firm has to meet and the DFSA can inspect.
In practice it is the document that tells a firm how to run its financial-crime programme: how to assess risk, what checks to run on customers, when to file a report, how long to keep records, and what the DFSA will hold it to on examination. The DFSA supervises against it directly, so for a DIFC firm the module is the operative standard the firm is measured against.
The module is versioned, so it changes as the rules change. That matters more than it sounds. A firm working from a superseded version of the DFSA rulebook can be following instructions that no longer match what the regulator inspects against, which is exactly the trap the 2025-26 refresh created for firms that didn’t keep up.
Who the rulebook binds
The module applies to what the DFSA calls Relevant Persons: the firms it authorises and registers in the DIFC. That is a wider group than banks alone.
It covers financial firms such as banks, asset managers, brokers and payment providers. It covers virtual-asset firms, so a crypto exchange or custodian operating in the DIFC falls under the same module. And it covers designated non-financial businesses, including law and accountancy firms and corporate service providers, which can be used to move or hide illicit money. If the DFSA licenses a firm, that firm almost certainly carries obligations under the AML module.
The core obligations
Strip the module down and it asks a DIFC firm to run the same programme any serious AML regime expects, documented to the standard the DFSA inspects against.
A firm has to take a risk-based approach, assessing the money-laundering risk of its customers, products and markets rather than treating everyone the same. It has to carry out customer due diligence, with enhanced due diligence for higher-risk relationships such as politically exposed persons. It has to appoint a Money Laundering Reporting Officer with the authority and independence to do the job. And it has to screen customers and transactions against sanctions lists.
Two obligations catch firms out because they are specific and testable. The DFSA requires firms to file a Suspicious Activity Report with the UAE Financial Intelligence Unit through the goAML portal, the same national channel every UAE firm uses, whenever they form a suspicion. And it requires records to be kept for six years and an annual AML Return to be submitted, which gives the regulator a scheduled window into how the programme is running.
Underneath all of it sits the business risk assessment. Before a firm can run a risk-based programme, it has to document its own money-laundering risk across its customers, products, delivery channels and the countries it deals with, and keep that assessment current. The DFSA treats a weak or out-of-date business risk assessment as a root-cause failing, because every other control is calibrated from it.
How the DFSA supervises the DIFC AML regime
The DFSA doesn’t publish the module and step back. It supervises DIFC AML compliance actively, using the annual AML Return, thematic reviews and on-site inspections to test whether a firm’s programme works in practice rather than only on paper.
The Return is the scheduled pressure point. Every Relevant Person submits it each year, giving the DFSA a structured view of the firm’s customer base, its risk exposure, the reports it has filed, and how its controls are performing.
A programme that looks complete in a policy document but thin in the Return is what draws supervisory attention. The practical lesson is that the DFSA measures the anti money laundering programme by what it produces, the risk assessments, the reports and the records, not by the length of the manual behind it.
DFSA, FSRA and the Central Bank: three regulators, one reporting channel
This is the point that causes the most confusion, and getting it straight is half the value of understanding the DFSA rulebook at all. The UAE has three AML supervisors, split by where a firm is licensed, and they aren’t interchangeable.
| Regulator | Free zone or jurisdiction | Supervises |
|---|---|---|
| DFSA | DIFC, the Dubai financial free zone | Firms licensed in the DIFC, under the DFSA AML module |
| FSRA | ADGM, the Abu Dhabi financial free zone | Firms licensed in the ADGM, under the FSRA’s own AML rules |
| CBUAE | Federal / mainland | Mainland banks, exchange houses, insurers and payment firms |
The DFSA and the FSRA are different regulators, in different emirates, with different rulebooks. A firm in the DIFC answers to the DFSA; a firm in the ADGM answers to the FSRA; a mainland firm answers to the Central Bank. What unites them is the reporting rail: all three route suspicious-activity reports to the single UAE Financial Intelligence Unit through goAML. The clean way to hold it: three regulators, three rulebooks, one FIU.
The 2025-26 refresh: why the rulebook changed
The DFSA module didn’t update in a vacuum. The UAE rebuilt its federal AML law underneath it. Federal Decree-Law No. 10 of 2025, effective 14 October 2025, replaced the long-standing 2018 law, and Cabinet Resolution No. 134 of 2025 replaced the 2019 executive regulation. The DFSA then amended its own AML and Glossary Modules to follow, with the updated versions taking effect in 2026.
For a DIFC firm the practical point is the dual framework. It complies with the DFSA module and the federal law at the same time, and both moved. Policies written against the old federal instruments now cite repealed law, so a DIFC compliance team has to re-check its programme against both the refreshed module and the new Decree-Law, not just one of them.
The backdrop to all of this is the UAE’s spell on the Financial Action Task Force grey list, from March 2022 to its removal in February 2024. The tightening of the federal law and the DFSA module is the codified result of that two-year reform, which is why supervision across the UAE, the DIFC included, has become more assertive.
What actually gets firms fined
The DFSA enforces the module, and reporting failures are a live risk rather than a theoretical one. In January 2025 the DFSA issued a provisional fine of around USD 25,000 on Al Ramz Capital for failing to report suspicious transactions, in a case involving alleged wash trades that pushed a share price up sharply. The fine is provisional and subject to appeal, so it isn’t a closed matter, but it shows what the DFSA treats as the breach: the failure to report the suspicion, not the trading itself.
The wider enforcement picture is more substantial. Across 2024 the DFSA finalised several enforcement cases with fines exceeding USD 2.5 million in total. And the pattern is regional: in December 2024 the FSRA in the ADGM fined Aarna Capital around USD 504,000 for failing to detect and report suspicious transactions over several years.
For a DIFC firm the message from both free-zone regulators is the same, that weak reporting is where enforcement lands. Both have signalled through their recent actions that suspicious-activity reporting is the obligation they test hardest, and that a firm which spots a red flag and fails to file it is more exposed than one that genuinely never saw it. The annual Return and the record of reports filed are the two things a DIFC compliance team should expect to be examined on.
FAQs
What is the DFSA AML rulebook?
It is the Anti-Money Laundering, Counter-Terrorist Financing and Sanctions Module of the Dubai Financial Services Authority’s rulebook, which sets the financial-crime obligations for firms licensed in the DIFC. The DFSA supervises firms directly against it.
Who does the DFSA AML module apply to?
Relevant Persons authorised or registered by the DFSA in the DIFC, including banks, asset managers, payment and virtual-asset firms, and designated non-financial businesses such as law and accountancy firms.
How is the DFSA different from the FSRA and the Central Bank?
The DFSA supervises firms in the DIFC (Dubai’s financial free zone), the FSRA supervises firms in the ADGM (Abu Dhabi’s financial free zone), and the Central Bank supervises mainland firms. They are separate regulators with separate rulebooks, but all report suspicious activity to the one UAE Financial Intelligence Unit via goAML.
Does a DIFC firm follow the DFSA rulebook or the federal UAE law?
Both. A DIFC firm runs a dual framework: the DFSA AML module and the federal AML law, which was replaced by Federal Decree-Law No. 10 of 2025. Compliance means meeting both.
What are the main obligations under the DFSA AML module?
A risk-based approach, customer due diligence and enhanced due diligence, a Money Laundering Reporting Officer, sanctions screening, suspicious-activity reporting to the UAE FIU via goAML, an annual AML Return, and six-year record-keeping.
Next read
The DFSA module sits on top of the federal regime. For the wider UAE framework and the rest of our compliance coverage, see the Compliance hub.