Proliferation Financing: The Risk DNFBPs Cannot Afford to Overlook

When most businesses think about financial crime, they think about money laundering and, to a lesser extent, terrorist financing. But there is a third risk that sits firmly alongside them in the UAE’s regulatory framework and may be less familiar to many businesses: proliferation financing (PF).

On 23 September 2026, the Central Bank of the UAE announced enforcement measures against the UAE branches of Bank Melli Iran following violations relating to anti-money laundering, combating the financing of terrorism and proliferation financing requirements. The measures included restrictions on certain financial transactions involving Iran.

While the enforcement action concerned a bank, the wider message is relevant to DNFBPs: proliferation financing is an integral part of the UAE’s financial crime framework and must be addressed through appropriate risk-based controls.

What is proliferation financing?

Proliferation financing generally involves the provision or use of funds or financial services connected with the proliferation of nuclear, chemical or biological weapons and their means of delivery.

The risk can also arise through transactions involving dual-use goods — items that have legitimate commercial applications but may also be diverted for proliferation purposes.

Importantly, PF does not necessarily involve proceeds of crime. Funds may originate from legitimate sources. The risk may instead lie in who ultimately benefits, the parties involved, the destination of funds or goods, and their ultimate purpose.

This makes effective sanctions controls, customer understanding and transaction scrutiny particularly important.

Why should DNFBPs be concerned?

Under Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025, proliferation financing forms part of the UAE’s broader AML/CFT/CPF framework.

DNFBPs can be exposed to PF risk in different ways:

  • Corporate service providers may establish or administer corporate structures that could potentially be misused to obscure ownership, control or the parties behind transactions.
  • Dealers in precious metals and stones operate in a sector involving high-value and portable assets that can facilitate the movement of value across borders.
  • Real estate brokers and agents may encounter transactions involving complex ownership arrangements, third-party funding or persons connected to sanctioned networks.
  • Lawyers and accountants may be involved in establishing companies, structuring transactions or arrangements, or handling matters involving complex ownership chains.
Red flags to watch for

PF risk does not always present itself as an obvious sanctions match.  UAE sanctions guidance specifically flags complex commercial arrangements and legal structures used to obscure beneficial ownership as sanctions-evasion indicators. Depending on the nature of the business and transaction, that can also include:

  • Clients whose stated business activities are vague or inconsistent with their ownership, geographic exposure or transaction patterns;
  • Links to jurisdictions subject to relevant UN sanctions regimes or other higher-risk geographic exposure;
  • Trading companies dealing in industrial, electronic, chemical or other potentially dual-use goods;
  • Complex or layered ownership structures with no apparent commercial rationale, including nominee arrangements;
  • Frequent or unexplained changes to company names, shareholders, directors or business activities;
  • Payments routed through unrelated third parties or multiple jurisdictions without a clear commercial rationale; and
  • Reluctance to provide information regarding end-users, the ultimate destination of goods, beneficial ownership or the source of funds.

A red flag does not automatically establish proliferation financing. It should, however, prompt the business to investigate further, apply appropriate due diligence and document its assessment.

What should DNFBPs have in place?
1. PF incorporated into the Business Risk Assessment

A DNFBP’s Business Risk Assessment should specifically consider its exposure to proliferation financing, taking into account its customer base, products and services, geographic exposure, transaction profile and delivery channels.

The assessment should be supported by documented analysis rather than simply assigning PF a low-risk rating. Current MoET guidance requires DNFBPs to identify, assess, understand and mitigate their ML/TF/PF risks using a risk-based approach.

2. Targeted Financial Sanctions screening that works in practice

Businesses should have effective processes for screening relevant parties against the UN Consolidated List and UAE Local Terrorist List in accordance with applicable Targeted Financial Sanctions requirements.

Potential or confirmed matches should be escalated immediately, with applicable freezing and reporting requirements followed without delay. Suspicious activity relating to PF that does not involve a sanctions-list match may separately give rise to STR/SAR reporting obligations.

The effectiveness of a sanctions control is therefore not determined simply by whether a screening system exists. Businesses should also have clear procedures for reviewing alerts, resolving false positives, escalating potential matches and documenting decisions.

3. CDD that goes beyond collecting documents

Effective CDD means understanding the customer’s business, ownership and control structure, purpose of the relationship and expected activity — and considering whether the information provided makes commercial sense.

This can be particularly important where customers are involved in cross-border trading, logistics, industrial goods or complex corporate structures.

4. Clear responsibility for PF

The responsibilities of the Compliance Officer and other relevant personnel should clearly address PF and sanctions compliance alongside AML and CFT.

Staff should understand who is responsible for reviewing alerts, escalating concerns and making reporting decisions.

5. Training that addresses PF-specific risks

Employees involved in onboarding, transaction review and compliance should be able to recognise relevant PF and sanctions-evasion indicators rather than relying solely on conventional money-laundering red flags.

6. Evidence that controls are operating

Risk assessments, screening results, match resolutions, due diligence, escalations and decisions should be appropriately documented.

Having a policy is important. Being able to demonstrate that the controls described in that policy operate effectively in practice is equally important.

 Proliferation financing can feel remote from everyday dealings, until a transaction shows one of the patterns above. With PF firmly embedded in the UAE’s AML/CFT/CPF framework, businesses should consider a simple question:

Does your compliance framework treat proliferation financing as a genuine risk — or merely as a heading in your AML policy?

Contact Details

Email: admin@bankslegal.com

WhatsApp: +971 55 655 2447

Share

Recent insights
Fund Structuring in DIFC and ADGM
Employee Incentives: An Overlooked Driver of M&A Success in the UAE
ADGM Simplifies SPV Applications and Shifts Focus from Nexus to Purpose and Assets

We deliver our services with a focus on quality and achieving impressive resultsOur legal expertise protects your interests and achieves meaningful outcomes. Whether handling litigation, transactions, or asset protection, we are committed to excellence.