How to Write an Enterprise-Wide AML Risk Assessment in the UAE

Published 18 September 2026 · Last reviewed against the primary sources 18 September 2026

Every designated business in the UAE has to assess its own exposure to money laundering, terrorist financing and proliferation financing, write it down, keep it current and hand it to its supervisor when asked. That document, which MoET calls the business-wide risk assessment and which is widely known as the EWRA, is the foundation every other control is measured against. This guide sets out what the law requires and how to build one that holds up.

The legal duty

Article 19(1)(a) of Federal Decree-Law No. 10 of 2025 requires every DNFBP to identify, understand, manage, assess, document and continuously update the risks of the Crime within its business, to retain the risk assessment study, and to provide it to the Supervisory Authority on request.

The Crime is defined in Article 1 as money laundering and its predicate offences, the financing of terrorism, and proliferation financing. A risk assessment that covers only money laundering and terrorist financing therefore does not meet the duty.

Source: FDL 10/2025, Article 1 (definition of Crime) and Article 19(1)(a)

What the Executive Regulations add

Article 5(1) of Cabinet Resolution No. 134 of 2025 makes the assessment proportionate to the nature and size of the business, and requires it to take account of the National Risk Assessment. Before deciding the overall level of risk, the business must consider all relevant risk factors, including:

  • customer risks
  • country and geographic risks
  • product and service risks
  • transaction risks
  • delivery channel risks

Source: CR 134/2025, Article 5(1)(a)

Documented, retained, updated

Article 5(1)(b) requires the business to document its process for identifying and assessing risk, retain the study, update it on an ongoing basis, and provide it to the authorities on request. MoET's guidelines say the documentation should include the methodology, the analysis and the supporting data, and that senior management must formally certify that the assessment accurately reflects the firm's risk exposure, is supported by appropriate mitigation, and is available for the supervisor to review.

The same guidelines expect the assessment to be refreshed whenever something could affect its accuracy: a change of strategy, new products or services, new technology, or new laws and regulations. For most firms they suggest reviewing it at least annually.

Source: CR 134/2025, Article 5(1)(b); MoET DNFBP Guidelines 2026, sections 8.3 and 8.3.1.2

Inherent risk, controls, residual risk

MoET describes the purpose of the assessment in three steps: identify the inherent risk the business faces as a whole, determine how well its policies, procedures and controls mitigate that risk, and establish the residual risk and any gaps that must be closed. The result is usually a rating of each risk as high, medium or low, which tells management where to spend its compliance effort.

According to the guidelines, a sound methodology:

  • uses both quantitative and qualitative information, including interviews, internal questionnaires and audit reports
  • reflects the risk appetite approved by management
  • includes the compliance officer's input
  • draws on external sources such as the National Risk Assessment, sectoral risk assessments and FATF material
  • explains how risk factors are weighted, classified and prioritised
  • assesses the likelihood, timing and impact of each risk
  • tests whether the controls actually work, using audit and compliance reports
  • derives residual risk and decides whether further controls are needed
  • is documented, communicated to management, and itself tested and audited

Source: MoET DNFBP Guidelines 2026, sections 8.3 and 8.3.1.1

Business-wide versus customer risk assessment

The guidelines draw a clear line between the two. A customer risk assessment rates individual customers so that due diligence and monitoring match each one. The business-wide assessment rates the firm as a whole, taking into account internal and external factors. A register of customer ratings is not a business-wide risk assessment, and an inspector will expect both.

Source: MoET DNFBP Guidelines 2026, section 8.3

From assessment to controls

The assessment exists to drive mitigation. Article 5(2) of the Executive Regulations requires internal policies, controls and procedures approved by senior management and proportionate to the risks identified, monitored for effectiveness, and enhanced where needed. Where risk is high, it lists enhanced due diligence measures, such as verifying more information, obtaining the source of funds and wealth, monitoring more closely and requiring senior management approval. Where risk is low, Article 5(3) allows simplified measures in coordination with the supervisor, but never where a crime is suspected.

New products, practices and technologies need their own assessment before launch, under Article 24 of the Executive Regulations.

Source: CR 134/2025, Articles 5(2), 5(3) and 24

If a consultant writes it for you

Outsourcing is allowed, but MoET warns against treating a vendor's assessment as a black box. The firm must understand the methodology, data and assumptions used, check that every relevant risk factor was considered and weighted, and have senior management critically review the result. Responsibility for its adequacy stays with the firm.

Source: MoET DNFBP Guidelines 2026, section 8.3

See where your firm stands

The AML Compass assessment checks your firm against these duties for its own sector and jurisdiction. The assessment and your scores are free.

Common questions

Is an enterprise-wide risk assessment mandatory for a small UAE business?
Yes, for any business designated as a DNFBP. Federal Decree-Law 10 of 2025, Article 19(1)(a), applies to every DNFBP. Cabinet Resolution 134 of 2025, Article 5(1), makes the depth proportionate to the nature and size of the business, so a small firm may have a simpler assessment, but it must still have one.
How often does the risk assessment need updating?
Continuously under the law, which in practice means at least annually for most firms according to MoET's 2026 guidelines, plus an update whenever a change in strategy, products, technology or regulation could affect it.
Does it have to cover proliferation financing?
Yes. The duty is to assess the risks of the Crime, which Article 1 of the Decree-Law defines to include proliferation financing, alongside money laundering and terrorist financing.
Who has to approve it?
MoET's guidelines require senior management to formally certify that the business-wide risk assessment is an accurate reflection of the firm's risk exposure and is supported by appropriate mitigation measures.

Primary sources

Related

A plain reading of the provisions cited, not legal advice. Your firm remains responsible for assessing its own obligations.