UAE DNFBPs in 2026: Is Your Customer Risk Assessment Meeting MoE’s Expectations?

1. Why Customer Risk Assessment Matters More in 2026

For UAE Designated Non-Financial Businesses and Professions (DNFBPs), the Customer Risk Assessment (CRA) is where the risk-based approach becomes operational. It influences the level of due diligence required, whether Enhanced Due Diligence (EDD) is necessary, the level of approval and how closely the relationship should be monitored.

 This matters more than ever in 2026. The UAE’s AML/CFT/CPF framework has been updated, and the Ministry of Economy and Tourism (MoE) continues to actively supervise and enforce it. In the first half of 2025 alone, MoE inspections identified 1,063 AML compliance violations across supervised DNFBPs and resulted in fines exceeding AED 42 million.

If MoE reviewed one of your customer files today, could you clearly demonstrate why that customer was rated Low, Medium or High Risk?

2. The Regulatory Framework Has Changed

Federal Decree-Law No. 10 of 2025 regarding Anti-Money Laundering and Combating the Financing of Terrorism and Proliferation Financing came into force on 14 October 2025, replacing Federal Decree-Law No. 20 of 2018. Its Executive Regulations, Cabinet Resolution No. 134 of 2025, became effective on 14 December 2025.

MoE’s March 2026 AML/CFT/CPF Guidelines reinforce the expectation that DNFBPs identify, assess, understand and mitigate their ML/TF/PF risk exposure. Businesses should therefore ensure that their risk assessments, policies and onboarding frameworks reflect the current regulatory environment.

3. What Should a Strong CRA Demonstrate?

A CRA should not simply contain a box marked Low, Medium or High. The rating should result from a documented assessment of the risks presented by the particular customer and business relationship.

  • Customer and business risk: the customer’s identity, legal form, business activity and purpose of the relationship.
  • Geographic risk: jurisdictions connected to the customer, beneficial owners, activities and flow of funds.
  • Ownership and control: the UBOs, ownership structure and any complexity requiring further understanding.
  • Product, service and delivery risk: the service being provided, how it is delivered and whether intermediaries or third parties are involved.
  • Transaction and payment risk: expected activity, payment methods, third-party payments and whether activity is consistent with the relationship.
  • PEP, sanctions and adverse information: relevant screening results and how they affect the overall assessment.
  • Proliferation financing risk: relevant exposure to jurisdictions, activities, goods, counterparties or other PF risk indicators.

The key is not simply identifying these factors, but demonstrating how they influenced the final customer risk rating.

4. The CRA Should Drive Due Diligence

The customer’s risk rating should have a practical consequence. Where higher risks are identified, additional measures may be required.

  • Further information on the customer or UBO
  • Establishing — and where appropriate corroborating — Source of Funds or Source of Wealth
  • Understanding complex ownership arrangements
  • Obtaining the required approvals
  • Applying enhanced ongoing monitoring

The CRA should also reflect the risks identified in the firm’s own business wide risk assessment. A corporate service provider, for example, will not necessarily face the same risks as a real estate broker or dealer in precious metals and stones. A generic template should therefore not replace a methodology tailored to the firm’s business.

One risk factor should not automatically determine the overall rating. A connection to a higher-risk jurisdiction or a complex structure may increase risk and require further scrutiny, but the assessment should consider the relationship as a whole and document the rationale for the final classification.

5. SOF, SOW and Ownership Must Make Sense

For corporate customers, identifying the immediate shareholder may only be the starting point. DNFBPs should understand the ownership and control structure and identify the natural person or persons who ultimately own or control the customer in accordance with applicable requirements.

Source of Funds (SOF) and Source of Wealth (SOW) matter too. SOF concerns the origin of the particular funds involved in the relationship or transaction, while SOW concerns how an individual’s overall wealth was accumulated. Generic descriptions such as “business income”, “employment income” or “savings” may be a starting point, but higher-risk circumstances may require further explanation or supporting evidence.

6. Customer Risk Does Not Remain Static

A customer rated Low or Medium Risk at onboarding may not remain at that level. A risk profile can change with:

  • Changes in ownership, directors or UBOs
  • New jurisdictions or activities
  • Unusual transactions
  • New PEP exposure
  • Sanctions developments
  • Credible adverse information

DNFBP should consider whether the CRA remains appropriate and whether additional due diligence or a revised rating is required.

7. Where CRAs Commonly Fall Short
  • CRA completed only after the business relationship has been established.
  • Generic scoring templates that do not reflect the firm’s own risks.
  • Risk ratings with little or no documented rationale.
  • Manual overrides that are not justified or appropriately approved.
  • Screening, geographic or PF risks identified but not reflected in the final rating.
  • High-Risk customers that do not receive the appropriate EDD and approvals.
  • Customer files that are not reassessed following material changes.
  • Policies or forms that continue to reference superseded legislation.
8. Quick Self-Check: Is Your CRA Inspection-Ready?
  • Our framework reflects Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025.
  • Customer risk assessments consider ML, TF and PF risk and are completed at the appropriate stage.
  • Our CRA methodology reflects our own business-wide risk assessment.
  • Relevant screening, ownership, geographic, service and transaction risks feed into the final rating.
  • Higher-risk relationships receive appropriate EDD, approvals and enhanced monitoring.
  • Risk-rating overrides are documented and appropriately approved.
  • We have periodic review frequencies and defined trigger events for reassessing customer risk.
  • We can explain from the file why each customer received its risk rating.
9. The Bottom Line

In 2026, a CRA needs to do more than simply exist. It should reflect the current UAE AML/CFT/CPF framework, appropriately consider ML, TF and PF risks and visibly influence the controls applied to each customer.

What risks were identified → How were they assessed → Why did the customer receive that rating → What controls were applied?

If MoE reviewed one of your customer files tomorrow, could you demonstrate not only the risk rating assigned, but why it was assigned and what you did about it?

How Banks Group Can Help

We help businesses move beyond the tick-box approach to compliance. From customer risk assessment methodologies and KYC/CDD frameworks to compliance health checks and customer file reviews, our focus is on building controls that are practical, proportionate and defensible.

Is your Customer Risk Assessment inspection-ready? Contact us to discuss how we can support your business in reviewing and strengthening its AML/CFT/CPF framework.

    Contact Details

    Email: admin@bankslegal.com

    WhatsApp: +971 55 655 2447

    Share

    Recent insights
    The UAE’s Evolving Anti-Counterfeiting Enforcement Landscape
    Fund Structuring in DIFC and ADGM
    Proliferation Financing: The Risk DNFBPs Cannot Afford to Overlook

    We deliver our services with a focus on quality and achieving impressive resultsOur legal expertise protects your interests and achieves meaningful outcomes. Whether handling litigation, transactions, or asset protection, we are committed to excellence.