MLRO Responsibilities in the UAE: 2026 Guide

The MLRO responsibilities UAE regulators now expect go far beyond filing the occasional suspicious transaction report. Under Federal Decree-Law No. 10 of 2025 and Cabinet Decision No. 134 of 2025, every UAE financial institution and DNFBP must appoint a qualified, supervisor-approved Money Laundering Reporting Officer who owns the AML/CFT programme end to end. A June 2026 enforcement action, in which the Central Bank of the UAE personally fined a Head of Compliance AED 300,000, made one point unavoidable: the MLRO carries personal, not just institutional, accountability.

This guide sets out who can hold the role, how to secure supervisory approval, the full duty set, what the MLRO report must contain, and how to reduce personal liability. It is written for compliance teams and business owners who need the operating model, not a definition.

Quick Answer: What are the MLRO’s responsibilities in the UAE?

A UAE MLRO owns the AML/CFT programme: they oversee customer due diligence and ongoing monitoring, receive internal suspicion reports, decide and file Suspicious Transaction Reports to the UAE FIU through the goAML portal, keep records for five years, train staff, and report to senior management and the board. The role needs prior supervisory approval.

Key Takeaways

  • The MLRO is a mandatory, approved appointment. Financial institutions and DNFBPs must appoint a compliance officer or MLRO with prior approval from their supervisory authority, applied for through the goAML portal.
  • The role is programme ownership, not paperwork. The MLRO owns policy, CDD and EDD oversight, screening, ongoing monitoring, reporting, record-keeping, training, and regulator liaison.
  • Reporting runs to the top. The MLRO reports to senior management and the board, commonly through a semi-annual MLRO report, and files STRs to the UAE FIU independently.
  • Personal liability is real. In June 2026 the Central Bank of the UAE fined an MLRO AED 300,000 personally, alongside an AED 20 million penalty on the institution.
  • Penalties stack. Administrative fines commonly run from AED 50,000 to AED 1,000,000 per violation, and legal-person court fines can reach AED 100 million.
  • Outsourcing is allowed, accountability is not transferable. You can outsource the MLRO function to a qualified provider, but the regulated entity keeps ultimate responsibility.

What is an MLRO in the UAE?

An MLRO, or Money Laundering Reporting Officer, is the senior individual a regulated entity appoints to run its anti-money laundering and counter-terrorist-financing programme and to act as the single reporting point to the UAE Financial Intelligence Unit. The role is the operational centre of the AML/CFT framework: every suspicion inside the business flows to the MLRO, and the MLRO decides what reaches the regulator.

The MLRO is defined by function, not job title. In a bank the role may sit with a Head of Compliance; in a real estate brokerage or a precious-metals dealer it may sit with a director who also carries the compliance-officer designation. What matters to a supervisor is that a named, approved, competent person holds the duties set out in law.

MLRO versus compliance officer: is there a difference?

In practice the two titles overlap in the UAE, and smaller DNFBPs often combine them in one person. The compliance officer designation covers the design and running of the AML/CFT programme, while the MLRO designation covers the reporting function, receiving internal reports and filing to the FIU. Larger institutions may split them; most DNFBPs do not. The obligations described in this guide attach to whoever holds the reporting responsibility.

The legal basis for the MLRO role

The MLRO role sits on two pillars of current UAE law. Federal Decree-Law No. 10 of 2025, in force from 14 October 2025, is the primary AML/CFT/CPF statute and replaced the older Federal Decree-Law No. 20 of 2018. Cabinet Decision No. 134 of 2025, the executive regulations, was published in Official Gazette No. 811 on 15 November 2025 and took effect on 14 December 2025. Together they require regulated entities to appoint a qualified compliance officer, run ongoing due diligence, report suspicion, and keep records.

Sitting above the statute is the Central Bank of the UAE guidance refreshed on 16 April 2026, which pushed supervision toward effectiveness. Supervisors now test whether controls work in practice, not whether a policy exists on paper. The 2026 FATF mutual evaluation, expected mid-year under the fifth-round methodology, applies the same outcome-based lens. Both raise the bar for what an MLRO must demonstrate. Our explainer on the CBUAE April 2026 AML update covers that shift in detail, and the Federal Decree-Law No. 10 of 2025 guide breaks down the statute itself.

Need help mapping your regulatory obligations? Contact ADZ’s compliance advisory team for a gap analysis against Federal Decree-Law No. 10 of 2025 and Cabinet Decision No. 134 of 2025. Speak to ADZ advisory.

Who can be an MLRO in the UAE?

A supervisor will not approve just anyone. The regulations expect an MLRO to demonstrate professional competence, integrity, and relevant AML/CFT experience, and to hold enough seniority to act without interference. The appointment is not effective until the supervisory authority grants prior approval.

Eligibility criteria

  • Competence: demonstrable AML/CFT knowledge, usually evidenced by a recognised certification and relevant experience.
  • Seniority and independence: enough authority to escalate to the board and to file an STR without being overruled by the business.
  • Integrity: a clean record, verified through the fit-and-proper checks the supervisor applies.
  • UAE residency and availability: based in the UAE and reachable by the supervisor and the FIU.
  • No disabling conflicts: the role should not be undermined by a commercial position that rewards onboarding risky clients.

The supervisory approval workflow

Approval is granted by the relevant supervisory authority, which depends on the sector: the Central Bank for licensed financial institutions and exchange houses, the Ministry of Economy for most DNFBPs, and free-zone regulators such as the DFSA, the FSRA, and VARA for entities they license. The application is submitted through the goAML portal maintained by the UAE FIU.

Step What happens
1. Register on goAML The entity registers on the FIU goAML portal if it has not already done so.
2. Nominate the officer Submit the candidate’s passport, residence visa, Emirates ID, and the trade licence.
3. Supervisor review The supervisory authority runs fit-and-proper and competence checks.
4. Approval granted The appointment becomes effective once the supervisor approves.
5. Keep it current Notify the supervisor of any change of MLRO and re-approve the replacement.

Registration itself is a common failure point. Our goAML portal registration guide walks through the account setup that the appointment depends on.

MLRO responsibilities: the full duty set

The role breaks into eight core duties. Each maps to a specific obligation in Federal Decree-Law No. 10 of 2025 and Cabinet Decision No. 134 of 2025, and each is something a supervisor can inspect.

Duty What it involves in practice
1. Own the AML/CFT policy Write, approve, and keep current the policies, procedures, and controls, calibrated to the business risk assessment.
2. Oversee CDD and EDD Make sure customer due diligence, and enhanced due diligence for high-risk relationships, are applied at onboarding and refreshed over time.
3. Run screening Screen customers and beneficial owners against sanctions lists and for PEP and adverse-media exposure, and re-screen on a risk basis.
4. Oversee ongoing monitoring Supervise transaction monitoring and periodic customer reviews so the risk profile stays accurate through the relationship.
5. Receive and assess internal reports Act as the single internal point for staff suspicion reports and decide whether each meets the reporting threshold.
6. File to the FIU Submit STRs, SARs, and other required reports to the UAE FIU through goAML, and guard against tipping-off.
7. Keep records Retain CDD, transaction, and reporting records for a minimum of five years and produce them on request.
8. Train and report upward Deliver AML/CFT training to staff and report programme status to senior management and the board.

Several of these duties have their own build. The screening and review side connects to enhanced due diligence and ongoing monitoring and periodic KYC review, the monitoring side to transaction monitoring setup, and the reporting side to filing an STR through goAML. The MLRO does not run each of these alone, but they answer for all of them.

First Compliance automates the CDD, sanctions and PEP screening, ongoing-monitoring alerts, and goAML reporting that the MLRO signs off, drawing on 1,800-plus sanction lists and 5.5 million-plus PEP records. See how First Compliance supports the MLRO function.

What must the MLRO report to senior management contain?

The MLRO report is the mechanism that puts AML risk in front of the people who own the business. It is a standing obligation, commonly produced at least semi-annually, and supervisors ask to see it during inspections. A weak or missing report is read as a governance failure.

A useful MLRO report to senior management covers:

  • Reporting activity: the number of internal suspicion reports received, how many were escalated to STRs, and how many were filed to the FIU.
  • Risk picture: changes in the customer, product, and geographic risk profile since the last report.
  • Screening and monitoring output: sanctions and PEP hits, alert volumes, and how the backlog was cleared.
  • Control gaps and remediation: weaknesses found, actions taken, and target dates for open items.
  • Training coverage: who was trained, on what, and completion rates.
  • Regulatory engagement: inspections, findings, and correspondence with supervisors.
  • Resourcing: whether the compliance function has the people and tools to meet the obligations.

The point of the report is not volume. It is to give the board a decision-ready view of where money-laundering risk is rising and what the business must fund to control it.

MLRO personal liability in the UAE

The single biggest change in the UAE compliance climate is personal accountability. On 24 June 2026 the Central Bank of the UAE announced an AED 20 million penalty against the UAE branch of a foreign bank for repeated AML/CFT and sanctions-framework failures, and separately imposed an AED 300,000 penalty on the Head of Compliance and MLRO for failing to fulfil the responsibilities of the position. The message to the market was direct: the individual answers for control failures, alongside the entity.

That action sits inside a wider enforcement pattern. The Central Bank issued more than AED 370 million in AML/CFT fines during 2025. Under the executive regulations, administrative penalties commonly run from AED 50,000 to AED 1,000,000 per violation, and violations stack across findings in a single inspection. Court-imposed fines on legal persons for money-laundering offences can reach AED 100 million.

Exposure Scale
Personal penalty on an MLRO (June 2026 case) AED 300,000
Institutional penalty in the same case AED 20,000,000
Administrative fines per violation AED 50,000 to AED 1,000,000
Court fines on legal persons up to AED 100,000,000
CBUAE AML/CFT fines issued in 2025 more than AED 370,000,000

What most often triggers a finding

Supervisory penalties rarely come from a single dramatic event. They come from repeated, documented gaps that an inspection surfaces. The recurring ones for the MLRO function are worth naming:

  • Late or missing appointment. Operating without an approved compliance officer, or failing to re-approve a replacement when the previous officer leaves.
  • Stale customer risk profiles. Risk ratings that were set at onboarding and never refreshed, so enhanced due diligence never triggered when it should have.
  • Screening that was never actioned. Sanctions or PEP alerts generated but left undispositioned, with no dated record of the decision.
  • Late, incomplete, or absent STRs. Suspicion identified internally but not escalated or filed to the FIU, the failure that most directly attaches to the reporting officer.
  • No MLRO report. Senior management with no documented view of AML risk, which a supervisor reads as absent governance.

Each of these is preventable, and each is easier to defend when the work is logged as it happens rather than reconstructed after a notice arrives.

How to reduce MLRO personal exposure

Personal liability follows failure to perform the role, so the defence is evidence that the role was performed. Practical steps:

  • Document decisions. Keep a dated record of every reporting decision, including the reasoned calls not to file, so a supervisor can see the judgement applied.
  • Escalate in writing. When the business resists a control, record the escalation to senior management. Silence looks like consent.
  • Insist on resourcing. Put resourcing gaps in the MLRO report. An officer who flagged an under-funded function is in a very different position from one who did not.
  • Keep training current. Maintain your own AML/CFT certification and refresh staff training on schedule.
  • Automate the evidence trail. Systems that log screening, alerts, and filings turn “we did our job” into an auditable record.

In-house or outsourced MLRO: which fits your business?

Not every UAE business can justify a full-time, approved MLRO. Smaller DNFBPs often outsource the function to a licensed provider, while larger or higher-risk entities keep it in-house. The regulations permit outsourcing, but the regulated entity keeps ultimate accountability, so the decision is about capacity and risk, not about transferring responsibility away.

Factor In-house MLRO Outsourced MLRO
Best for Banks, higher-risk or larger entities Smaller DNFBPs, new registrants
Cost Full salary plus tooling Fixed service fee
Expertise Depends on the hire Specialist team on tap
Accountability Retained by the entity Retained by the entity

We compare the two models in depth in our guide to in-house versus outsourced AML compliance in the UAE. Whichever route you take, the appointed officer still needs supervisory approval and the skills to match, which is where structured AML training comes in.

Compliance 360 offers 32 KHDA-approved AML/CFT training courses, including MLRO-level programmes that prepare an officer for the role and the approval process. Explore ADZ training.

MLRO audit-readiness checklist

Whether the review is an internal audit, a supervisory inspection, or preparation for the 2026 FATF evaluation, an MLRO should be able to answer yes to each of these. Grounding the checklist in a current business risk assessment keeps everything below proportionate to actual risk.

  • Is the MLRO appointment approved by the correct supervisory authority, with the approval on file?
  • Are AML/CFT policies current, board-approved, and mapped to Federal Decree-Law No. 10 of 2025 and Cabinet Decision No. 134 of 2025?
  • Is the customer risk profile refreshed on a risk-based schedule, with trigger events forcing a review?
  • Are sanctions and PEP screening logs complete, with hits dispositioned and dated?
  • Is every reporting decision documented, including reasoned decisions not to file?
  • Are records retained for at least five years and retrievable on request?
  • Has the MLRO report gone to senior management within the reporting cycle?
  • Is staff training logged with completion rates, and is the MLRO’s own certification current?

An independent audit tests these answers before a regulator does. ADZ conducts four types of independent AML/CFT audit, covering federal and Central Bank, DFSA, VARA, and supply-chain requirements.

ADZ conducts independent AML/CFT audits for entities regulated by the Central Bank of the UAE, the DFSA, and VARA. Test your MLRO function before an inspection does. Book an ADZ audit.

Frequently Asked Questions

Who can be an MLRO in the UAE?

An MLRO must be a competent, senior individual with demonstrable AML/CFT experience and integrity, based in the UAE, and free of conflicts that would undermine the role. The appointment is not valid until the relevant supervisory authority, applied to through the goAML portal, grants prior approval.

Can an MLRO be held personally liable in the UAE?

Yes. In June 2026 the Central Bank of the UAE personally fined an MLRO AED 300,000 for failing to fulfil the responsibilities of the position, separately from a AED 20 million penalty on the institution. Personal liability follows a failure to perform the role, which is why documented decisions and escalations matter.

Can you outsource the MLRO function in the UAE?

Yes. UAE regulations allow a regulated entity to outsource the MLRO function to a qualified, licensed provider, and this is common among smaller DNFBPs. The outsourced officer still needs supervisory approval, and the regulated entity keeps ultimate accountability for compliance.

What must the MLRO report to senior management contain?

It should cover reporting activity, the current risk picture, screening and monitoring output, control gaps and remediation, training coverage, regulatory engagement, and resourcing. The aim is to give the board a decision-ready view of money-laundering risk, not a raw activity count.

How often must an MLRO report be produced?

The MLRO report is a standing obligation, commonly produced at least semi-annually and available for supervisors to inspect. Higher-risk entities may report more frequently, and any significant event, such as a major sanctions hit, should be escalated to senior management as it arises rather than held for the cycle.

What is the difference between an MLRO and a compliance officer in the UAE?

The compliance officer designation covers designing and running the AML/CFT programme, while the MLRO designation covers the reporting function, receiving internal reports and filing to the FIU. In most UAE DNFBPs one approved person holds both, and the statutory duties attach to whoever carries the reporting responsibility.

Does a DNFBP need an MLRO, or only financial institutions?

Both. Designated non-financial businesses and professions, including real estate brokers, dealers in precious metals and stones, accountants, law firms, and corporate service providers, must appoint an approved compliance officer or MLRO under Federal Decree-Law No. 10 of 2025, supervised by the Ministry of Economy or the relevant free-zone regulator.

Related Reading

The MLRO role is now the pivot point of UAE AML/CFT compliance, and after the June 2026 enforcement action it carries personal stakes. ADZ helps UAE businesses appoint, train, support, and audit the MLRO function, from advisory and outsourced MLRO cover to First Compliance software and Compliance 360 training. Contact ADZ for a free consultation and gap analysis.

Disclaimer: This article is general information on UAE AML/CFT compliance and is not legal advice. Regulations and enforcement practice change. Confirm your obligations with your supervisory authority or a qualified adviser before acting. Verify current requirements with official sources including the Central Bank of the UAE, the UAE Ministry of Economy, and the FATF.

Scroll to Top