Last updated: June 2026.

AML compliance for gaming operators in the UAE became a legal reality in late 2025. Commercial gaming operators are now Designated Non-Financial Businesses and Professions (DNFBPs) under Federal Decree-Law No. 10 of 2025 and Cabinet Decision No. 134 of 2025, supervised for anti-money laundering purposes by the General Commercial Gaming Regulatory Authority (GCGRA). This guide is written for operators, finance teams, and prospective licensees who need a practical, regulator-aware view of what the rules require and how to put a working programme in place.

Quick Answer: Do UAE gaming operators have AML obligations?

Yes. Since Cabinet Decision No. 134 of 2025 came into effect on 14 December 2025, licensed commercial gaming operators in the UAE are DNFBPs. They must apply customer due diligence at or above AED 11,000, screen for sanctions and politically exposed persons, appoint a Money Laundering Reporting Officer, file suspicious transaction reports through goAML, and keep records for at least five years.

Key Takeaways

  • New DNFBP category: Commercial gaming operators were added to the DNFBP list under Article 3 of Cabinet Decision No. 134 of 2025.
  • Single supervisor: The GCGRA is the sole AML/CFT supervisor for the gaming sector, established in Abu Dhabi in September 2023.
  • The trigger figure: AML duties bite at a single or linked transaction of AED 11,000 or more. Gaming chips on their own are not a financial transaction.
  • Reporting route: Suspicious transaction reports go to the UAE Financial Intelligence Unit through the goAML portal, and tipping off the customer is a criminal offence.
  • Penalty exposure: Administrative fines under Article 17 of Federal Decree-Law No. 10 of 2025 run from AED 10,000 to AED 5,000,000 per violation, alongside suspension and licence revocation.
  • Records: Customer files, transaction data, and internal analysis must be kept for a minimum of five years.
  • Day-1 readiness matters: The GCGRA can inspect from the moment a licence is granted, so the compliance programme needs to be live before the doors open.

Who counts as a commercial gaming operator under UAE AML law?

A commercial gaming operator is any business licensed by the GCGRA to run gaming activity in the UAE, whether at a physical venue, online, or on board vessels and marine craft. Once licensed, the operator sits inside the AML perimeter as a DNFBP and carries the same core duties as other reporting entities, scaled to the gaming risk profile.

The AED 11,000 transaction trigger

Customer due diligence becomes mandatory when a customer carries out a single financial transaction, or several linked transactions, worth AED 11,000 or more. Linked transactions matter here: a customer who structures activity into smaller amounts to stay under the line is exactly the behaviour the rule is built to catch. Operators should monitor for patterns across a gaming day, not just single tickets.

What falls outside the AML perimeter

Pure gaming chips or gaming instruments, on their own, are not treated as a financial transaction. The obligation attaches to the money movement around the play: buy-ins, cash-outs, credits, transfers, and payouts. Drawing this line correctly in your policies prevents two common errors, over-reporting harmless chip handling and under-reporting genuine value transfers.

Who regulates gaming AML in the UAE? The GCGRA

The General Commercial Gaming Regulatory Authority is the single AML/CFT supervisor for commercial gaming in the UAE. It licenses operators, sets sector guidance, runs risk assessments, carries out inspections, and imposes penalties for breaches. For a gaming operator, the GCGRA is the body that will examine your programme, so its expectations should shape how you build it.

Function Body What it means for operators
Sector AML supervisor GCGRA Licensing, guidance, inspections, and penalties for gaming operators
Suspicious transaction reports UAE Financial Intelligence Unit (FIU) Receives STRs through the goAML portal
Targeted financial sanctions Executive Office for Control and Non-Proliferation (EOCN) Maintains listings and the freezing regime operators must apply
National framework National AML/CFT and Sanctions Committee Sets policy, including the Commercial Gaming Policy Paper

How the GCGRA works with the FIU and the EOCN

The GCGRA supervises, but it does not receive your suspicious transaction reports. Those go to the FIU through goAML. Sanctions listings and freezing obligations come from the EOCN. A working gaming programme therefore plugs into three channels at once: GCGRA for supervision and guidance, the FIU for reporting, and the EOCN for sanctions alerts. Register with each before you need them.

The legal framework: Federal Decree-Law No. 10 of 2025 and Cabinet Decision No. 134 of 2025

The UAE rebuilt its AML architecture in 2025. Federal Decree-Law No. 10 of 2025 replaced the earlier Federal Decree-Law No. 20 of 2018 and took effect on 14 October 2025. Cabinet Decision No. 134 of 2025, the executive regulations, followed on 14 December 2025 and is where gaming operators were formally added to the DNFBP list. For background on the parent statute, see our guide to Federal Decree-Law No. 10 of 2025.

Instrument Role in gaming AML
Federal Decree-Law No. 10 of 2025 Primary AML/CFT framework: FIU powers, supervisory competencies, STR duty, penalty regime
Cabinet Decision No. 134 of 2025 Executive regulations: DNFBP list (adds gaming), CDD rules, beneficial owner rules, five-year record-keeping
Cabinet Decision No. 109 of 2023 Beneficial ownership regime, including the 25% ownership or control test
Cabinet Decision No. 74 of 2020 Targeted financial sanctions and the obligation to freeze without delay

Core AML obligations for gaming operators

The duties below apply to every licensed operator. They mirror the obligations placed on other DNFBPs, such as dealers in precious metals and stones, but they need to be adapted to the speed, anonymity risk, and cash intensity of gaming.

1. Appoint a compliance officer and an MLRO

Every operator must appoint a Money Laundering Reporting Officer with the seniority and independence to act. The MLRO owns suspicious transaction reporting, sanctions decisions, and the relationship with the GCGRA and the FIU. In smaller operations one person may hold the compliance officer and MLRO roles, but the responsibilities and reporting lines must be documented.

2. Build an enterprise-wide risk assessment

Before you write a single policy, assess the money laundering and terrorist financing risk across your customers, products, channels, and geographies. The risk assessment is the document the GCGRA will ask for first, because everything else, your CDD thresholds, monitoring rules, and training, should flow from it. Update it when you launch a new product or payment channel.

3. Customer due diligence, beneficial ownership, and PEP screening

Identify and verify customers at the AED 11,000 trigger, and earlier where risk warrants. Where a customer is a legal person, identify the beneficial owner using the 25% ownership or control test. Screen every customer against politically exposed person data, and apply enhanced due diligence to higher-risk relationships. For the mechanics of identifying who really controls a customer, see our note on beneficial ownership.

4. Sanctions screening and freezing without delay

Screen customers and counterparties against the UAE Local Terrorist List and the United Nations Consolidated List, and register for the EOCN alert system so you receive updates as listings change. A confirmed match triggers a freeze without delay and a report to the EOCN. Our guide to targeted financial sanctions sets out the freezing steps in detail.

5. Record-keeping for at least five years

Keep customer identification records, transaction data, internal analysis, and correspondence for a minimum of five years from the end of the relationship or the date of the transaction. Records must be retrievable quickly when the GCGRA or the FIU asks, so storage and indexing are a compliance issue, not just an IT one.

6. Ongoing monitoring and reporting

Monitoring is continuous, not a one-off check at sign-up. Watch for unusual patterns across sessions and accounts, and file a suspicious transaction report when grounds for suspicion arise. The monitoring rules you build should reflect your risk assessment. For a practical view of rule design and false-positive control, see our AML transaction monitoring guide.

7. Staff training

Frontline staff handle the first signs of suspicious activity, so training is a control, not a formality. Cashiers, hosts, floor staff, and managers all need role-specific training on red flags, escalation, and the tipping-off rule. Untrained staff are one of the most common gaps inspectors find.

Need help mapping your gaming AML obligations? ADZ’s advisory team builds AML programmes for UAE-regulated entities, not just policy documents. Talk to our compliance advisory team.

A risk-based CDD and EDD escalation matrix for gaming

Regulatory commentary tends to stop at “apply a risk-based approach”. The harder question is what that looks like in practice. The matrix below is a starting model you can adapt to your own risk assessment and customer base. It is illustrative, not a substitute for your own documented thresholds.

Risk tier Example indicators Due diligence response
Standard Resident customer, modest play, transparent funding, no PEP or sanctions hit Standard CDD at the AED 11,000 trigger, baseline monitoring
Medium-high Higher buy-ins, frequent cash-outs, customer from a higher-risk jurisdiction Additional identity and source-of-funds checks, tighter monitoring thresholds, periodic review
High PEP, complex ownership, structuring signals, adverse media, large cash use Enhanced due diligence, senior sign-off, source-of-wealth evidence, ongoing senior review
Prohibited Sanctions match, refusal to provide identification, suspected proceeds of crime Decline or exit, freeze where required, file an STR, report a sanctions match to the EOCN

Gaming-specific red flags and STR scenarios

The UAE Commercial Gaming Policy Paper sets out the typologies that make gaming attractive to money launderers. Turning those typologies into floor-level red flags is what separates a paper policy from a working one.

Typology Floor-level red flag
Minimal-play conversion Customer buys in heavily, plays little, then cashes out asking for a cheque or transfer
Structuring Repeated buy-ins or cash-outs just under the AED 11,000 line, often across multiple visits
Third-party funding One person funds another’s play, or chips are passed between unrelated customers
Multiple payment methods A single customer splits funding across cards, cash, and e-wallets without clear reason
VIP or junket abuse High-value play routed through intermediaries with opaque source of funds
Employee complicity Staff overriding controls, suppressing alerts, or assisting a customer to avoid checks

When a red flag cannot be explained, the MLRO assesses whether grounds for suspicion exist and, if they do, files a suspicious transaction report. The test is suspicion, not proof. You do not need to be certain a crime occurred to be required to report.

How to file a suspicious transaction report through goAML

Reporting is the point where many programmes fail, not because operators refuse to report, but because the process is not set up in advance. The steps below outline the route. For a deeper walkthrough, see our UAE STR filing guide.

  1. Register on goAML early. Registration with the UAE FIU portal takes time, so complete it before you open, not when you have a report to file.
  2. Capture the grounds for suspicion. Record what triggered the concern, in clear and specific terms, while the detail is fresh.
  3. Assemble the subject and transaction data. Identify the customer, the amounts, the dates, the channels, and any linked activity.
  4. Write a clear narrative. The quality of the report depends on the narrative. State the facts, the pattern, and why it is suspicious.
  5. Attach supporting evidence. Identification documents, transaction logs, and any internal analysis.
  6. Submit and retain the acknowledgment. Keep the goAML reference as part of your five-year records.
  7. Do not tip off the customer. Disclosing that a report has been filed is a criminal offence under the AML law.

VIP programmes, junkets, and cash handling

Gaming risk concentrates in two places: high-value play and cash. VIP programmes and junket arrangements move large sums through intermediaries, which can obscure the true source of funds. Controls here should include documented source-of-funds and source-of-wealth checks for VIP customers, due diligence on any intermediary, and senior sign-off for high-value relationships.

Cash deserves its own controls. Set thresholds for cash acceptance, require additional checks above defined limits, and reconcile cash movements against play. A customer who consistently converts large cash buy-ins into clean payouts with little genuine play is showing one of the clearest laundering patterns in the sector.

Product and payment-channel controls

Payment innovation outpaces policy. E-wallets, pre-paid cards, and virtual assets each create distance between a customer and the original source of funds. Before you accept a new payment channel, run it through your risk assessment and decide what additional checks apply.

  • E-wallets and pre-paid cards: verify the funding source, not just the wallet, and watch for rapid load-and-withdraw behaviour.
  • Virtual assets: apply heightened scrutiny, given the cross-border and pseudonymous nature of the funds.
  • Account-to-account transfers: confirm the account holder matches the customer, and flag third-party transfers.

Penalties for non-compliance

The cost of getting this wrong is set out in the law. Administrative penalties under Article 17 of Federal Decree-Law No. 10 of 2025 apply per violation, and they sit alongside the GCGRA’s power to suspend or revoke a licence. For a gaming operator, a licence is the business, which makes AML failure an existential risk, not a line item.

Consequence Detail
Administrative fine AED 10,000 to AED 5,000,000 per violation under Article 17
Supervisory action Warning, suspension, prohibition from activity, or licence revocation
Criminal exposure Where money laundering offences are prosecuted, courts can impose higher fines on legal persons and custodial sentences on individuals
Reputational and banking impact Loss of banking relationships and counterparty trust following enforcement

A Day-1 AML setup checklist for new GCGRA licensees

The GCGRA can inspect from the day your licence is granted, so the programme must be operational before you open. Use this checklist as a build sequence.

  • Complete an enterprise-wide money laundering and terrorist financing risk assessment.
  • Appoint an MLRO and document the compliance reporting lines.
  • Write AML/CFT policies and procedures mapped to your risk assessment.
  • Stand up CDD, beneficial ownership, PEP, and sanctions screening, with the EOCN alert system connected.
  • Register with the goAML portal and test the reporting workflow.
  • Set monitoring rules and cash-handling thresholds for the gaming floor and online channels.
  • Train all staff on red flags, escalation, and the tipping-off rule.
  • Build a five-year record-keeping and retrieval system.
  • Run an independent gap review before opening, and again on a regular cycle.

Preparing for a GCGRA inspection? ADZ conducts independent AML/CFT audits and gap analyses for UAE-regulated entities. Book an independent AML audit and find the gaps before an inspector does.

How ADZ supports gaming operators

ADZ is a UAE-based practitioner firm. We implement and run compliance programmes, rather than only writing about them. For gaming operators, that means three things working together. Our advisory team designs and builds the AML programme around your risk assessment. First Compliance, our screening and reporting software, supports CDD, sanctions and PEP screening, and goAML reporting, drawing on 1,800+ sanction lists and 5.5M+ PEP records. Compliance 360, our KHDA-approved training arm, delivers the staff training the law requires.

Train your floor and back office to the standard inspectors expect. Compliance 360 runs KHDA-approved AML/CFT courses tailored to UAE obligations. Explore Compliance 360 training.

Frequently Asked Questions

Are gaming operators DNFBPs in the UAE?

Yes. Licensed commercial gaming operators were added to the DNFBP list under Article 3 of Cabinet Decision No. 134 of 2025, which took effect on 14 December 2025. As DNFBPs, they carry full AML/CFT obligations supervised by the GCGRA.

Who is the AML supervisor for gaming in the UAE?

The General Commercial Gaming Regulatory Authority (GCGRA), established in Abu Dhabi in September 2023, is the sole AML/CFT supervisor for commercial gaming. It handles licensing, guidance, inspections, and penalties for the sector.

What is the AED 11,000 threshold?

AED 11,000 is the value, in a single or linked transaction, at which customer due diligence becomes mandatory for gaming operators. Operators should also watch for customers who split activity into smaller amounts to stay below the line.

How do gaming operators report suspicious transactions?

Through the goAML portal of the UAE Financial Intelligence Unit. The MLRO assesses whether grounds for suspicion exist, files the report with a clear narrative and supporting evidence, retains the acknowledgment, and must not tip off the customer.

What are the penalties for AML breaches by gaming operators?

Administrative fines under Article 17 of Federal Decree-Law No. 10 of 2025 run from AED 10,000 to AED 5,000,000 per violation, alongside warnings, suspension, prohibition, and licence revocation. Money laundering offences can also carry criminal penalties.

How long must gaming operators keep AML records?

At least five years from the end of the customer relationship or the date of the transaction. Records include identification documents, transaction data, internal analysis, and correspondence, and must be retrievable on request.

When do the gaming AML rules apply from?

Federal Decree-Law No. 10 of 2025 took effect on 14 October 2025, and Cabinet Decision No. 134 of 2025, which adds gaming operators to the DNFBP list, took effect on 14 December 2025. The GCGRA can inspect from the date a licence is granted.

Related Reading

Commercial gaming is the newest sector to come inside the UAE’s AML perimeter, and the supervisory expectations are set from day one. Operators that treat AML as part of building the business, rather than a task to handle after opening, will face inspections with confidence. If you are licensing now, the right move is to design the programme alongside the rest of your launch, with a documented risk assessment, working reporting, and trained staff in place before you take the first bet.

Disclaimer: This article is general regulatory information, not legal advice. Always check the primary texts on uaelegislation.gov.ae and the official guidance of the GCGRA, the EOCN, and the UAE FIU, and take tailored advice before acting.

Official sources: General Commercial Gaming Regulatory Authority, the UAE Commercial Gaming Policy Paper, the Financial Action Task Force, and the UAE Legislation portal.

Scroll to Top