Author: First Compliance

What Is FATF? A Complete Guide for Businesses in the UAE and Kuwait

What Is FATF? A Complete Guide for Businesses in the UAE and Kuwait

AML Compliance Services

What Is FATF? A Complete Guide for Businesses in the UAE and Kuwait

What Does FATF Stand For?

FATF stands for the Financial Action Task Force. In French it is called Groupe d’action financière (GAFI), which is why you will occasionally see that acronym in international regulatory documents alongside FATF.

It is an intergovernmental body, meaning it is composed of member countries and jurisdictions working together under a shared framework rather than being controlled by any single government or private organization.

When and Why Was FATF Created?

FATF was established in 1989 at the G7 Summit in Paris. The original concern was specific: drug trafficking profits were flooding into the global banking system, and no coordinated international mechanism existed to stop it.

The founding logic was simple but powerful. Criminal networks only survive because they can move, hide, and spend the money they make. Disrupt their access to the financial system and you disrupt the enterprise itself.

The mandate has grown significantly since 1989:

Year Development
1989 FATF founded, focused exclusively on money laundering
1990 First 40 Recommendations published
2001 Mandate expanded to include counter-terrorist financing (CFT) after 9/11
2003 40 Recommendations revised and strengthened
2012 Third pillar added: counter-proliferation financing (CPF)
2019 Guidance on virtual assets and VASPs published
2022 UAE added to the Grey List
2024 UAE exits Grey List
2026 Kuwait added to the Grey List

What Are the Three Pillars FATF Works On?

Pillar What It Means Real-World Example
Anti-Money Laundering (AML) Preventing criminals from disguising illegal funds as legitimate money A drug trafficker buying real estate to clean cash
Counter-Terrorist Financing (CFT) Stopping funds from reaching terrorist individuals or groups Small transfers routed through shell accounts to fund an attack
Counter-Proliferation Financing (CPF) Blocking financing for weapons of mass destruction programmes Front companies procuring materials for a nuclear programme

Where Is FATF Based and Who Are Its Members?

FATF is headquartered in Paris, France, and operates within the OECD building. It is led by a rotating Presidency held by a member country for a two-year term.

As of 2026, FATF has:

  • 40 member jurisdictions including the USA, UK, EU, China, India, Saudi Arabia, and the UAE
  • 2 regional organisations as members (the Gulf Co-operation Council and the European Commission)
  • Over 200 jurisdictions committed to FATF standards through a global network of FATF-Style Regional Bodies (FSRBs)

Kuwait and the UAE are both members of MENAFATF, the Middle East and North Africa Financial Action Task Force, which is the FATF-Style Regional Body covering the Gulf region.

What Does FATF Actually Do?

FATF does four core things:

  1. Sets the Global Standards: FATF publishes the 40 Recommendations, which are the internationally accepted standards for AML, CFT, and CPF. These are not legally binding treaties, but virtually every country in the world has adopted them into national law because failing to do so results in isolation from the global financial system.
  2. Evaluates Countries FATF: and its regional bodies conduct Mutual Evaluation Reviews (MERs) of member countries. These are deep, independent assessments of how well a country has implemented the 40 Recommendations in both law and practice.
  3. Maintains the Grey List and Black List: Based on MER findings and follow-up monitoring, FATF identifies countries with strategic deficiencies and places them under increased monitoring. More on this below.
  4. Produces Guidance and Typologies: FATF regularly publishes guidance documents on specific risks, such as virtual assets, real estate, professional money laundering, and trade-based money laundering, to help countries and businesses understand emerging threats.

What Are the FATF 40 Recommendations?

The 40 Recommendations are the rulebook of global financial crime prevention. They cover every major area of AML/CFT/CPF compliance:

Category Recommendations Cover
AML/CFT Policies and Coordination National risk assessments, inter-agency cooperation
Money Laundering and Confiscation Criminalisation of ML, asset seizure powers
Terrorist and Proliferation Financing CFT laws, targeted financial sanctions
Preventive Measures CDD, EDD, PEPs, correspondent banking, wire transfers
Transparency and Beneficial Ownership Company registers, trust ownership disclosure
Powers and Responsibilities of Authorities FIU functions, law enforcement powers
International Cooperation Mutual legal assistance, extradition

Every regulated business in the UAE and Kuwait, whether a bank, exchange house, law firm, real estate broker, or crypto platform, operates under national laws built directly on these 40 Recommendations. For businesses seeking compliance monitoring software in Dubai, understanding these foundations is essential to choosing a platform that genuinely maps to regulatory obligations rather than just ticking boxes.

What Is a Mutual Evaluation Report (MER)?

A Mutual Evaluation Report is FATF’s formal assessment of a country’s AML/CFT/CPF system. It evaluates two dimensions:

Technical Compliance: Has the country passed the right laws and regulations? Do the rules on paper match the 40 Recommendations?

Effectiveness: Are those laws actually working? Are criminals being prosecuted? Are suspicious transactions being reported? Is the financial system genuinely protected?

A country can have technically sound laws and still fail on effectiveness if those laws are not being applied in practice. This distinction is critical, and it is exactly why Kuwait was greylisted in February 2026 despite having made significant technical progress following its 2024 MER.

What Is the FATF Grey List?

The Grey List, formally called “Jurisdictions Under Increased Monitoring,” is a public list of countries that have agreed to work with FATF to fix identified weaknesses in their AML/CFT/CPF systems within an agreed timeframe.

Being on the Grey List means:

  • The country has strategic deficiencies that pose a risk to the global financial system
  • The country has committed to an agreed action plan with specific milestones
  • FATF will monitor and report on progress at every Plenary (three times per year)
  • International financial institutions are expected to apply Enhanced Due Diligence to transactions and customers connected to that country

Being removed from the Grey List requires on-site verification by FATF that the action plan has been fully and effectively implemented.

Grey List vs Black List

List Formal Name What It Means Current Members (2026)
Grey List Jurisdictions Under Increased Monitoring Strategic deficiencies exist; country is cooperating with FATF 22 jurisdictions including Kuwait
Black List High-Risk Jurisdictions Subject to a Call for Action Serious deficiencies; FATF calls on all countries to apply countermeasures North Korea, Iran, Myanmar

Kuwait and the FATF Grey List: The Full Story

Kuwait's First Greylisting (2012 to 2015)

Kuwait was first placed on the FATF Grey List in 2012. At that time the deficiencies related to gaps in its AML/CFT legal framework, weak suspicious transaction reporting, and limited international cooperation. Kuwait addressed the required action items and was removed from the list in February 2015.

The 2024 Mutual Evaluation Report

In June 2024, FATF adopted Kuwait’s latest Mutual Evaluation Report. The findings were mixed. Kuwait had made meaningful technical progress, including adopting a new national AML/CFT/CPF strategy and updating key legislation. However, the effectiveness of the system was found to be significantly lacking.

Kuwait Added to the Grey List: February 2026

At the February 2026 Plenary in Mexico City, FATF formally placed Kuwait back on the Grey List. The specific deficiencies identified were:

  • A consistently low understanding of terrorist financing risks among relevant authorities
  • Prosecution focused on simple money laundering cases with a significant lack of complex case investigations
  • Insufficient outreach to real estate agents and Dealers in Precious Metals and Stones on suspicious transaction reporting
  • Beneficial ownership registry data that is not consistently accurate, complete, or updated
  • Low volume of investigations tied to cross-border currency movements and bearer negotiable instruments

Kuwait's Agreed Action Plan

To exit the Grey List, Kuwait must demonstrate verified progress on:

Action Item What Is Required
STR reporting in DNFBPs Sector-specific outreach to real estate and precious metals dealers including distribution of ML/TF indicators
Beneficial ownership accuracy Registry data must be accurate, complete, and current; sanctions applied for non-compliance
Complex ML prosecutions Increase investigations and prosecutions involving cross-border currency movements and complex predicate offences
TF risk understanding Demonstrate that relevant authorities have an adequate and calibrated understanding of terrorist financing risks

Kuwait will remain on the Grey List until FATF conducts an on-site visit and verifies that each item has been fully and effectively addressed.

The UAE and FATF: From Grey List to Global Standard

The UAE's Greylisting in 2022

The UAE was placed on the FATF Grey List in March 2022. The listing reflected concerns about gaps in its AML/CFT/CPF framework across several sectors including real estate, gold trading, corporate service providers, and virtual assets.

A Period of Intensive Reform

Between 2022 and 2024, the UAE undertook one of the most comprehensive and rapid compliance reform programmes in FATF history:

  • New AML/CFT federal legislation and Cabinet Resolutions
  • Establishment of VARA as a dedicated virtual asset regulator
  • Strengthening of the UAE Financial Intelligence Unit and go AML platform
  • Significant increase in STR filings, ML investigations, and prosecutions
  • Crackdown on unlicensed money service businesses
  • Enhanced supervision of DNFBPs across real estate, gold, and legal services

During this period, the demand for reliable compliance monitoring software in Dubai grew sharply, as regulated entities raced to demonstrate that their internal controls were not just documented but genuinely operational and auditable.

The UAE Exits the Grey List: February 2024

In February 2024, FATF removed the UAE from the Grey List following a successful on-site assessment confirming that the agreed action plan had been fully implemented and was producing results. This was a landmark moment for the UAE’s positioning as a global financial and business hub.

The Ongoing Obligation

Exiting the Grey List does not mean compliance work is finished. UAE-regulated entities are legally required to continuously update their AML/CFT/CPF programmes in line with FATF updates. Kuwait’s greylisting in February 2026 is a direct trigger for UAE businesses to apply Enhanced Due Diligence to all Kuwait-linked customers and transactions.

What Does FATF Mean for Businesses in the UAE and Kuwait?

Whether you run a bank, a real estate firm, a law practice, an exchange house, or a crypto platform, FATF’s standards translate into real day-to-day compliance obligations:

FATF Requirement What Your Business Must Do
Customer Due Diligence (CDD) Verify every customer's identity and understand the nature of the relationship
Enhanced Due Diligence (EDD) Apply deeper scrutiny to high-risk customers, PEPs, and customers from greylisted countries like Kuwait
Beneficial Ownership Identify and verify the real human beings who ultimately own or control a legal entity
Suspicious Transaction Reporting File STRs with the national FIU (goAML in UAE) when transactions cannot be explained
Record Keeping Maintain customer and transaction records for a minimum period (five years in UAE, eight years for VASPs)
Risk Assessment Conduct and regularly update a documented assessment of the ML/TF/PF risks your business faces
Screening Screen customers, counterparties, and transactions against sanctions lists, PEP databases, and adverse media
Training Ensure all relevant staff understand their AML/CFT obligations

Meeting these obligations manually across hundreds or thousands of customers is neither practical nor defensible to a regulator. This is why investing in purpose-built compliance monitoring software in Dubai is no longer a luxury for growing businesses. It is a baseline operational requirement.

How First Compliance Solution Helps Businesses in the UAE and Kuwait

Understanding FATF is step one. Building a compliance programme that actually meets every obligation, day after day, across hundreds or thousands of customers and transactions, is a different challenge entirely. That is where First Compliance Solution comes in.

First Compliance Solution is a full-spectrum AML/CFT compliance platform built by experts in law, compliance, and financial crime. It is designed specifically for the regulatory environment in the UAE and the broader Gulf region, and it maps directly to every FATF-driven obligation that regulated businesses face.

What the Platform Covers

For UAE Businesses

Following Kuwait’s greylisting in February 2026, UAE entities must immediately apply Enhanced Due Diligence to Kuwait-linked customers. First Compliance automates this process. When a customer’s risk profile changes because of a Grey List update, the system flags the account, triggers an EDD workflow, and documents every step for regulatory audit purposes. As the most trusted compliance monitoring software in Dubai, First Compliance Solution ensures that no Grey List update ever catches your business unprepared.

For Kuwait Businesses

Kuwait’s greylisting means local financial institutions and DNFBPs face intensified supervisory scrutiny. Building a defensible, documented, and effective AML/CFT programme is now an urgent priority. First Compliance Solution provides the infrastructure to do exactly that, whether your organisation is a bank, exchange house, real estate firm, or legal practice.

Compliance Need First Compliance Solution Module
Customer identity verification E-KYC with real-time face verification
Beneficial ownership capture and verification Onboarding and Due Diligence
Risk-based customer scoring Risk Management
Sanctions, PEP, and watchlist screening Sanction Screening across hundreds of global lists
Ongoing transaction monitoring Transaction Monitoring with real-time alerts
STR preparation and goAML filing Regulatory Reporting
Case investigation and documentation Compliance Case Management
Policy and record management Document Management
Management oversight and reporting Dashboard and Analytics
Regulatory deadline and review alerts Alerts and Notifications

Why It Matters

AML Compliance Services

FATF assessors evaluate both technical compliance and effectiveness. Having a policy document is not enough. You need to demonstrate that your controls actually work, that suspicious transactions are identified, that EDD is applied correctly, and that your risk assessments reflect your real exposure. First Compliance Solution creates a full audit trail across every function so that when a regulator or assessor asks for evidence, you have it.

For businesses in Kuwait now entering a period of heightened regulatory scrutiny, and for UAE businesses managing the knock-on obligations that come with every FATF Grey List update, deploying the right compliance monitoring software in Dubai is the single most impactful step a compliance team can take.

Visit firstcompliancesolution.com to request a demo and see how the platform can be configured for your sector, whether you are a bank, VASP, real estate firm, or any other regulated entity in the UAE or Kuwait.

Quick Reference: FATF Key Terms Glossary

Term Plain English Meaning
AML Anti-Money Laundering
CFT Counter-Terrorist Financing
CPF Counter-Proliferation Financing
MER Mutual Evaluation Report: FATF's country assessment
Grey List Countries under increased FATF monitoring
Black List Countries subject to FATF countermeasures
CDD Customer Due Diligence: verifying who your customer is
EDD Enhanced Due Diligence: deeper checks for higher-risk customers
PEP Politically Exposed Person: officials at higher risk of corruption
UBO Ultimate Beneficial Owner: the real human behind a company
STR Suspicious Transaction Report: a report filed with the FIU
FIU Financial Intelligence Unit: the national body that receives STRs
goAML UAE's FIU platform for submitting STRs
DNFBP Designated Non-Financial Business or Profession (e.g. lawyers, real estate agents, accountants)
VASP Virtual Asset Service Provider (e.g. crypto exchanges)
MENAFATF The regional FATF body covering the Middle East and North Africa
Travel Rule Requirement to pass sender and recipient data with virtual asset transfers

Summary

FATF is the global organization that sets the rules for fighting money laundering, terrorist financing, and proliferation financing. Its 40 Recommendations form the foundation of AML/CFT law in the UAE, Kuwait, and over 200 jurisdictions worldwide. Countries that fail to implement those rules effectively get placed on the Grey List, which triggers real consequences for their financial sectors and for businesses that deal with them.

Kuwait is on the Grey List as of February 2026. The UAE exited in February 2024 and must maintain the standards that got it off. For businesses operating in both countries, the compliance obligations are concrete, legally binding, and actively supervised.

First Compliance Solution gives you the technology to meet every one of those obligations, from customer onboarding and sanctions screening to transaction monitoring and regulatory reporting, all in one platform built for the Gulf’s regulatory reality.

Every Country on the FATF Grey List Right Now: Why They Are Listed and What It Means for Your Business

Every Country on the FATF Grey List Right Now: Why They Are Listed and What It Means for Your Business

fatf-grey-list-countries-2026

Introduction

As of 13 February 2026, the FATF Grey List includes 22 jurisdictions: Algeria, Angola, Bolivia, Bulgaria, Cameroon, Côte d’Ivoire, Democratic Republic of the Congo, Haiti, Kenya, Kuwait, Lao PDR, Lebanon, Monaco, Namibia, Nepal, Papua New Guinea, South Sudan, Syria, Venezuela, Vietnam, Virgin Islands (UK), and Yemen.

For every compliance officer, risk manager, and business operating in or from the UAE and Kuwait, this list is not background information. It is an active operational input that must be woven into customer risk scoring, transaction monitoring, EDD procedures, and enterprise-wide risk assessments. Every entity linked to any of these 22 jurisdictions requires heightened scrutiny.

The right governance risk and compliance software in Dubai makes this process systematic, documented, and defensible. This blog breaks down every greylisted country, why it was listed, what is required to fix it, and how First Compliance Solution equips your organization to manage the exposure.

What Greylisting Means in Practice

Grey-listed jurisdictions are not subject to FATF calls for enhanced due diligence or countermeasures. Instead, they are placed under increased monitoring, meaning they must demonstrate measurable progress in implementing FATF recommendations.

Despite the absence of mandatory countermeasures, greylisting has real consequences for businesses dealing with these countries:

Business Impact What It Requires From You
Country risk ratings must be elevated Update your Enterprise-Wide Risk Assessment immediately
Customer risk scoring recalibrated Flag customers and counterparties from greylisted jurisdictions as higher risk
Enhanced Due Diligence required Obtain source of funds, source of wealth, transaction purpose, and senior approval
Transaction monitoring intensified Increase scrutiny of frequency, size, and patterns of transactions
STR obligations heightened Any unexplained transactions involving greylisted countries must be reported via goAML
Correspondent banking reviews International banks may apply restrictions on payments to/from these jurisdictions

The Five Most Significant Changes Explained

1. Proliferation Financing as a Standalone Offence

Perhaps the most consequential change in the new law is the introduction of proliferation financing (PF) as a distinct criminal offence, separate from broader counter-terrorism financing obligations. Under the 2018 framework, PF controls were embedded within general CTF provisions and were often treated as an extension of sanctions screening. The 2025 law demands a fundamentally different approach.
Businesses must now:

  • ● Conduct a specific Proliferation Financing Risk Assessment (PFRA) that is separate from their general Business Risk Assessment
    ● Implement targeted financial sanctions (TFS) controls specifically designed to detect and prevent PF activity
    ● Document their PF risk exposure and the controls applied to mitigate it
    ● Train staff on PF typologies, red flags, and reporting obligations

This change alone will require most regulated entities to revisit their existing risk assessment frameworks from the ground up.

2. Tax Evasion as a Predicate Offence

Key Stats to Know

The explicit inclusion of tax evasion as a predicate offence to money laundering carries significant practical implications, particularly for businesses that serve high-net-worth individuals, corporate clients with complex cross-border structures, or customers operating in multiple jurisdictions.

Where previously tax matters were largely treated as a separate regulatory concern, compliance teams must now consider tax risk as part of their AML customer due diligence process. Enhanced due diligence for clients with opaque tax structures, offshore holdings, or exposure to high-risk jurisdictions is now an expectation, not a discretionary measure.

3. Virtual Assets and VASPs

The UAE has become one of the most active virtual asset markets in the world, and the 2025 law reflects that reality. Virtual Asset Service Providers are now explicitly brought within the scope of the AML framework, with obligations that mirror those applied to traditional financial institutions.
Key requirements for VASPs and entities transacting in virtual assets include:

  • ● Full compliance with the Travel Rule for virtual asset transfers above threshold values
    ● Risk-based CDD on virtual asset customers, including source of funds verification
    ● Real-time sanctions screening against all relevant lists including OFAC, UN, and UAE local lists
    ● Suspicious Transaction Reporting for anomalous virtual asset activity
    ● Licensing verification of counterparty VASPs before processing transactions

4. Strengthened Beneficial Ownership Requirements

Beneficial ownership transparency has been a persistent weakness in the UAE’s AML framework, and the 2025 law addresses it directly. Regulated entities are now required to verify beneficial ownership information more rigorously at onboarding, review it more frequently throughout the relationship, and maintain records in a format that is accessible and auditable.

The practical implications are significant:

  • Ownership structures with multiple layers or complex corporate chains require deeper investigation
  • Passive reliance on customer-provided documentation is no longer sufficient
  • Ongoing monitoring must flag changes in ownership structure that could indicate emerging risk
  • Records must be maintained in a format that can be produced quickly to supervisory authorities

5. Enhanced Penalties and Supervisory Powers

5. Enhanced Penalties and Supervisory Powers

The 2025 law grants supervisory authorities, including the Central Bank, CBUAE, SCA, VARA, and DFSA within their respective jurisdictions, significantly broader powers to investigate, sanction, and prosecute non-compliance. Penalties have been enhanced across the board, with fines reaching into the tens of millions of dirhams for serious or repeated breaches.

The Central Bank has already signaled the direction of travel, issuing approximately AED 350 million in AML-related fines in recent months. Under the new law, that enforcement posture is backed by an even stronger legal foundation.

Who Is Affected: Regulated Entities Under the New Law

The following categories of business fall within the scope of Federal Decree-Law No. 10 of 2025:

● Banks, exchange houses, and financial institutions
● Insurance companies and brokers
● Investment firms and asset managers
● Real estate agents and brokers
● Lawyers, notaries, and independent legal professionals
● Accountants and auditors
● Company formation agents and corporate service providers
● Dealers in precious metals and stones
● Virtual Asset Service Providers (VASPs)
● Free zone entities engaged in financial or designated non-financial activities

If your business falls into any of the above categories and you have not yet conducted a gap analysis against the new law, that process should begin immediately.

What Businesses Must Do Now: A Compliance Action Plan

Business Impact What It Requires From You
Country risk ratings must be elevated Update your Enterprise-Wide Risk Assessment immediately
Customer risk scoring recalibrated Flag customers and counterparties from greylisted jurisdictions as higher risk
Enhanced Due Diligence required Obtain the source of funds, the source of wealth, the transaction purpose, and senior approval
Transaction monitoring intensified Increase scrutiny of frequency, size, and patterns of transactions
STR obligations heightened Any unexplained transactions involving greylisted countries must be reported via goAML
Correspondent banking reviews International banks may apply restrictions on payments to/from these jurisdictions

Grey-listing often triggers internal compliance changes, including EDD thresholds, transaction monitoring calibration, periodic review frequency, and approvals for higher-risk relationships.

The Complete FATF Grey List: All 22 Countries Explained

1. Algeria

Listed: October 2024

Regional Body: MENAFATF

Algeria was added to the grey list with an action plan specifying improvements around implementing risk-based supervision, establishing a framework for basic and beneficial ownership information, enhancing its suspicious transaction reporting procedures, applying financial sanctions for terrorism financing, and conducting oversight of the country’s non-profit sector.

Progress note: At the February 2026 Plenary, FATF made the initial determination that Algeria has substantially completed its action plan and warrants an on-site assessment to verify that the implementation of AML/CFT reforms has begun and is being sustained. Algeria is one of the closest countries to exiting the list.

2. Angola

Listed: October 2024

 Regional Body: ESAAMLG

After the June 2023 adoption of its mutual evaluation report, Angola made progress on some of its recommended actions. However, the FATF identified deficiencies in the country’s AML/CFT regime, including its understanding of ML/TF risks, supervision of non-financial entities, low prosecution rates for criminal offences, and delays in implementing sanctions.

Remaining action plan items:

  • Enhance understanding of ML/TF risks
  • Improve risk-based supervision of non-banking entities and DNFBPs
  • Ensure competent authorities have accurate, timely access to beneficial ownership information
  • Demonstrate increased ML investigations and prosecutions
  • Demonstrate ability to identify, investigate, and prosecute terrorist financing
  • Implement targeted financial sanctions without delay

3. Bolivia

Listed: June 2025

Regional Body: GAFILAT

Since its last mutual evaluation report in 2023, Bolivia has made some progress on its recommended actions, including improving its understanding of ML/TF risks, strengthening its financial intelligence networks, and increasing its ability to investigate terrorist financing. However, this was not enough to prevent greylisting in June 2025.

Remaining action plan items:

  • Implement risk-based supervision of DNFBPs
  • Ensure beneficial ownership information is accurate and current
  • Increase ML investigations and prosecutions

4. Bulgaria

Listed: October 2023

Regional Body: MONEYVAL

Bulgaria’s greylisting was notable as it became the first EU member state placed on the FATF Grey List in over a decade. The deficiencies identified relate to the effectiveness of AML/CFT measures, including gaps in supervising higher-risk sectors, the quality of suspicious transaction reporting, and the effectiveness of prosecutions for complex money laundering cases.

Compliance note for UAE businesses: Bulgaria is an EU member state, and its greylisting has triggered specific EDD obligations for Bulgarian-connected transactions under UAE AML/CFT regulations.

5. Cameroon

Listed: October 2023

Regional Body: GABAC / FATF

Cameroon was identified as having strategic deficiencies across multiple dimensions of its AML/CFT/CPF framework, including gaps in financial sector supervision, limited effectiveness of suspicious transaction reporting, and weaknesses in beneficial ownership transparency across corporate structures. The country has been working through an action plan, but progress has been slower than the timeframe requires.

6. Côte d'Ivoire (Ivory Coast)

Listed: October 2024

 Regional Body: GIABA

Despite making progress on some of its June 2023 MER’s recommendations, such as strengthening its legal AML/CFT framework, Côte d’Ivoire was added to the grey list in October 2024. The country will continue to work with FATF to implement its action plan, including by demonstrating a sustained increase in ML/TF prosecutions, strengthening its sanctions framework, and improving its measures to verify beneficial ownership information.

7. Democratic Republic of the Congo (DRC)

Listed: June 2024

Regional Body: GABAC / ESAAMLG

The DRC was greylisted due to systemic weaknesses in its AML/CFT framework. The key deficiencies identified include inadequate risk-based supervision of financial institutions and DNFBPs, very low volumes of suspicious transaction reporting, weak beneficial ownership transparency, and limited capacity to investigate and prosecute money laundering related to the country’s significant extractive industries and informal economy.

8. Haiti

Listed: June 2020

Regional Body: CFATF

Haiti has been on the grey list since 2020, making it one of the longest-running greylisted jurisdictions. Haiti chose to defer reporting at the February 2026 Plenary, meaning the statement issued previously for that jurisdiction is included in FATF’s publication but may not necessarily reflect the most recent status of its AML/CFT regime.  Ongoing political instability, governance challenges, and gang-related criminal economies have made sustained AML/CFT reform deeply difficult.

9. Kenya

Listed: February 2024

 Regional Body: ESAAMLG

Kenya was greylisted in February 2024 following its mutual evaluation, which identified persistent gaps in risk-based supervision of financial institutions and DNFBPs, weaknesses in beneficial ownership data quality, and insufficient prosecution of complex money laundering cases. Kenya is a significant regional financial hub, making its greylisting particularly impactful for businesses with East Africa exposure.

Progress note: At its February 2026 Plenary, FATF made the initial determination that Namibia has substantially completed its action plan and warrants an on-site assessment. Kenya is also progressing toward completion of its action plan, but has not yet reached the on-site assessment stage.

10. Kuwait

Listed: February 2026

Regional Body: MENAFATF

Kuwait is the most recently added jurisdiction of direct relevance to UAE-based businesses. After its initial 2015 removal, Kuwait was re-listed in February 2026 following the country’s 2024 MER. Critical shortcomings were highlighted with its AML/CFT framework, including an inadequate understanding of TF risks and a lack of investigations into complex ML cases. The country is also tasked with improving the implementation of targeted financial sanctions to ensure assets linked to terrorism can be promptly frozen.

Remaining action plan items:

  • Enhance outreach to real estate agents and Dealers in Precious Metals and Stones on STR reporting
  • Ensure beneficial ownership registry information is accurate, complete, and current
  • Increase ML investigations and prosecutions tied to cross-border currency movements
  • Improve understanding of terrorist financing risks across relevant authorities

For UAE-regulated entities, Kuwait’s greylisting is an immediate compliance trigger requiring EDD for all Kuwait-linked customers and counterparties.

11. Lao PDR (Laos)

Listed: February 2025

Regional Body: APG

Despite Laos’ steps to address recommendations from its 2023 MER, such as bolstering financial intelligence unit resources and eliminating bearer shares, the FATF found significant challenges remained regarding the country’s risk assessment process, regulatory oversight, and law enforcement effectiveness.

Remaining action plan items:

  • Improve national risk assessment processes
  • Strengthen regulatory oversight of financial institutions and DNFBPs
  • Improve law enforcement’s capacity to investigate and prosecute ML cases

12. Lebanon

Listed: October 2024

 Regional Body: MENAFATF

The FATF placed Lebanon on the grey list in October 2024, citing the country’s AML/CFT risk assessments, its approach to asset recovery, and its lack of up-to-date beneficial ownership information as areas for improvement. The FATF has acknowledged the social, economic, and security-related difficulties Lebanon has faced since its invasion by Israel in October 2024, and has not recommended that enhanced due diligence or countermeasures be applied to the country.

Lebanon’s position is particularly sensitive given its deep integration with regional banking networks and the significant Lebanese diaspora with business connections across the Gulf.

13. Monaco

Listed: June 2024

Regional Body: MONEYVAL

Monaco, which has the highest concentration of millionaires and billionaires in the world, was added to the grey list in June 2024 due to insufficient progress in combating illicit financial flows. This decision follows a January 2023 review by MONEYVAL, which found that while Monaco had made some progress in identifying ML/TF threats, significant gaps remained in its investigative and prosecutorial capabilities.

Monaco’s greylisting is particularly significant for wealth management firms, private banking operations, and luxury real estate professionals in Dubai who manage clients with Monaco-connected assets or residency.

14. Namibia

Listed: February 2025

Regional Body: ESAAMLG

Namibia was added to the grey list in February 2025 following identified weaknesses in its AML/CFT framework, including gaps in risk-based supervision, low beneficial ownership transparency, and insufficient prosecution activity. At the February 2026 Plenary, FATF made the initial determination that Namibia has substantially completed its action plan and warrants an on-site assessment. Namibia is among the most advanced countries in working toward removal.

15. Nepal

Listed: February 2025

Regional Body: APG

While Nepal made legislative amendments in 2024 to align with FATF standards, the country has struggled with implementation and enforcement, particularly in financial sector oversight, prosecutorial effectiveness, and regulatory compliance. The Asia/Pacific Group on Money Laundering had previously flagged Nepal’s slow response to key recommendations from its 2022 MER, which highlighted persistent gaps in monitoring high-risk sectors and financial crime enforcement.

Nepal’s large remittance economy and close financial ties with Gulf countries, including the UAE, make its greylisting relevant to exchange houses and payment service providers operating across the Gulf.

16. Papua New Guinea (PNG)

Listed: February 2026

Regional Body: APG

Papua New Guinea was added to the grey list in February 2026, a decade after its 2016 removal. Although the country made technical improvements following its first listing in 2014, its 2024 mutual evaluation revealed significant systemic AML/CFT failures. The FATF identified significant deficiencies in criminal prosecutions for ML and in the supervision of high-risk sectors, including DNFBPs.

PNG will work with FATF to implement its action plan by improving its understanding of ML risks and endorsing the National AML/CFT/CPF Strategic Plan, proactively seeking outbound international cooperation to identify and trace criminal property abroad, improving risk-based supervision of banks, MVTS and FX dealers, and higher-risk DNFBPs, and demonstrating an increase in ML investigations, prosecutions, and confiscation of criminal proceeds.

17. South Sudan

Listed: October 2021

Regional Body: ESAAMLG

South Sudan has been on the grey list since October 2021, with deficiencies spanning nearly every dimension of AML/CFT compliance, including national risk assessment, financial sector supervision, beneficial ownership transparency, STR reporting, and international cooperation. Ongoing conflict, political instability, and weak institutional infrastructure have made reform progress slow.

18. Syria

Listed: October 2010

Regional Body: MENAFATF

Syria has been on the FATF Grey List since 2010, making it one of the longest-standing entries in the list’s history. Syria chose to defer reporting at the February 2026 Plenary, and the statement issued previously for that jurisdiction may not necessarily reflect the most recent status of its AML/CFT regime. The country’s prolonged conflict, near-total institutional collapse, and severe sanctions exposure make it effectively a no-go zone for regulated businesses.

19. Venezuela

Listed: June 2024

Regional Body: GAFILAT

In early 2022, an assessment team visited Venezuela to prepare the country’s MER. The team raised concerns about ML risks associated with the nation’s large informal economy, including illegal mining. They also highlighted terrorist financing threats linked to the close economic alliance between Caracas and Tehran. Consequently, Venezuela was added to the grey list in June 2024.

Venezuela also remains subject to significant international sanctions from the US, EU, and UK, which compound the compliance obligations associated with Venezuelan-linked transactions.

20. Vietnam

Listed: June 2023

Regional Body: APG

Vietnam was greylisted in June 2023 following a mutual evaluation that identified deficiencies in risk-based supervision, beneficial ownership transparency, and effectiveness of AML/CFT controls across its rapidly growing financial services and real estate sectors. Vietnam’s integration into global trade and manufacturing supply chains makes it an active area of compliance concern for UAE trade finance and corporate service businesses.

21. Virgin Islands (UK)

Listed: June 2025

Regional Body: CFATF

In June 2025, the FATF tasked the British Virgin Islands with enhancing risk-based supervision of investment firms, virtual asset service providers, and trust or company service providers, ensuring beneficial ownership information is available to the authorities, and systematically pursuing ML investigations. The jurisdiction has made some progress since its most recent MER, such as increasing requests for international cooperation and risk-assessing its non-profit sector.

The BVI’s greylisting is of direct relevance to UAE corporate service providers, law firms, and wealth management businesses that frequently incorporate structures using BVI entities.

22. Yemen

Listed: February 2010

Regional Body: MENAFATF

Yemen has been on the grey list since 2010. In June 2014, the FATF determined that Yemen had substantially addressed its action plan at a technical level, but due to the security situation, FATF has been unable to conduct an on-site visit to confirm whether the process of implementing the required reforms has begun and is being sustained. The FATF will conduct an on-site visit at the earliest possible date. Over a decade later, Yemen’s security situation has not permitted that visit, making it effectively a permanent entry on the list under current conditions.

Summary Table: All 22 Grey List Countries at a Glance

Country Region Date Listed Primary Deficiencies Status
Algeria MENA Oct 2024 Supervision, beneficial ownership, STR, TF sanctions Near on-site assessment
Angola Africa Oct 2024 ML/TF risk understanding, supervision, prosecutions Active action plan
Bolivia Latin America Jun 2025 DNFBP supervision, beneficial ownership, ML prosecutions Active action plan
Bulgaria Europe (EU) Oct 2023 Supervision, STR quality, complex ML prosecutions Active action plan
Cameroon Africa Oct 2023 Financial sector supervision, STR, beneficial ownership Active action plan
Côte d'Ivoire Africa Oct 2024 ML/TF prosecutions, sanctions, beneficial ownership Active action plan
DR Congo Africa Jun 2024 Supervision, STR, beneficial ownership, extractive sector Active action plan
Haiti Caribbean Jun 2020 Governance, supervision, all areas Deferred reporting
Kenya Africa Feb 2024 DNFBP supervision, beneficial ownership, complex ML Active action plan
Kuwait MENA Feb 2026 TF risk understanding, complex ML, DNFBP STR, beneficial ownership New listing
Lao PDR Asia Feb 2025 Risk assessment, regulatory oversight, law enforcement Active action plan
Lebanon MENA Oct 2024 Risk assessments, asset recovery, beneficial ownership Active action plan
Monaco Europe Jun 2024 Investigations, prosecutions, illicit financial flows Active action plan
Namibia Africa Feb 2025 Supervision, beneficial ownership, prosecutions Near on-site assessment
Nepal Asia Feb 2025 Supervision, enforcement, sector monitoring Active action plan
Papua New Guinea Pacific Feb 2026 ML risk understanding, supervision, prosecutions, confiscation New listing
South Sudan Africa Oct 2021 National risk assessment, supervision, STR, all areas Active action plan
Syria MENA Oct 2010 All areas; conflict-affected Deferred reporting
Venezuela Latin America Jun 2024 Informal economy ML, TF, illegal mining Active action plan
Vietnam Asia Jun 2023 Supervision, beneficial ownership, real estate sector Active action plan
Virgin Islands (UK) Caribbean Jun 2025 VASP supervision, beneficial ownership, ML investigations Active action plan
Yemen MENA Feb 2010 All areas; conflict-affected; on-site not possible Awaiting on-site visit

Recent Removals: Countries That Exited the Grey List

Understanding which countries successfully exited the Grey List is just as important for risk management. These removals demonstrate what full action plan implementation looks like in practice:

Country Removed Key Reforms That Secured Removal
South Africa Oct 2025 Improved STR quality, increased ML prosecutions, stronger DNFBP supervision
Nigeria Oct 2025 Completed ML/TF risk assessment, enhanced high-risk sector controls, improved beneficial ownership
Mozambique Oct 2025 Inter-agency coordination, TF risk assessment, AML/CFT strategy implementation
Burkina Faso Oct 2025 Risk-based supervision, beneficial ownership maintenance, TF law enforcement
Philippines Feb 2025 Casino sector reform, TF prosecution capacity, international cooperation
Croatia Jun 2025 TF detection, non-profit sector oversight, UN financial sanctions implementation
Tanzania Jun 2025 Risk-based supervision, prosecutorial effectiveness, FIU capability
UAE Feb 2024 Comprehensive legislative overhaul, VARA establishment, STR surge, DNFBP crackdown

The Common Threads: Why Countries Keep Getting Listed

Across all 22 greylisted jurisdictions, several deficiency types appear repeatedly. These are the areas where global AML/CFT frameworks most commonly break down:

Beneficial Ownership Transparency: Appearing in the action plans of Algeria, Angola, Bolivia, Côte d’Ivoire, Kenya, Kuwait, Lebanon, Namibia, the Virgin Islands, and others. The ability to identify who ultimately owns and controls a company is foundational to AML/CFT, and it remains the most widespread weakness globally.

Risk-Based Supervision: Effective supervision requires regulators to allocate their resources to the highest-risk entities and sectors. Most greylisted countries apply a rule-based approach that treats all entities the same, leaving high-risk areas under-supervised.

STR Reporting Quality and Volume: Suspicious Transaction Reports are the primary intelligence tool of financial intelligence units. In most greylisted countries, STR volumes are too low, the quality of analysis is insufficient, or DNFBPs are largely not filing at all.

ML/TF Prosecutorial Effectiveness: Having criminalisation laws on paper is not enough. FATF requires demonstrated prosecutions, particularly for complex cases. Most greylisted countries prosecute only simple, low-value ML cases while complex predicate offences go uninvestigated.

Targeted Financial Sanctions Implementation: The ability to freeze assets linked to designated terrorist individuals and entities without delay is a core FATF requirement. Many greylisted countries have the legal framework but fail to act swiftly in practice.

What UAE and Kuwait Businesses Must Do Right Now

Given that two MENA-region countries are now on the Grey List and multiple others maintain links to Gulf financial flows, regulated entities in the UAE and Kuwait face a specific and immediate compliance obligation:

  • Review your customer base and identify any clients with connections to all 22 greylisted jurisdictions, not just Kuwait
  • Update Enterprise-Wide Risk Assessments to reflect the February 2026 Grey List
  • Apply or intensify EDD for customers from Monaco (wealth management), BVI (corporate structures), Lebanon (banking), and Bulgaria (EU-based entities) as well as Kuwait and PNG
  • Recalibrate transaction monitoring thresholds and typology libraries for greylisted country exposure
  • Review beneficial ownership information for any corporate clients incorporated in or connected to greylisted jurisdictions
  • File STRs for any transactions that cannot be risk-justified post-EDD review
  • Update internal policies, procedure manuals, and staff training materials

How First Compliance Solution Helps You Manage Grey List Exposure

Managing 22 greylisted jurisdictions, each with different risk profiles, regional contexts, and compliance triggers, is a task that cannot be done manually at scale. This is where purpose-built governance risk and compliance software in Dubai becomes the critical infrastructure of your compliance programme.

First Compliance Solution is a comprehensive, AI-powered platform that brings together every module your team needs to manage grey list exposure across your entire customer base.

How the Platform Addresses Each Grey List Challenge

Sanctions and Jurisdiction Screening: First Compliance integrates with hundreds of global sanctions lists, PEP databases, and watchlists. When FATF updates the Grey List in February, June, or October, your screening configuration reflects the change. Every customer and counterparty linked to a greylisted jurisdiction is flagged automatically. No manual list management. No gaps.

Risk-Based Customer Scoring: The platform’s Risk Management module allows you to configure country-level risk weighting into your customer risk scoring model. A customer from Kuwait or Lebanon automatically scores higher and triggers an EDD workflow, regardless of which compliance officer is handling the case.

Automated EDD Workflows: EDD for greylisted country customers requires collecting additional information, including source of funds, source of wealth, transaction purpose, and senior management approval. First Compliance’s Compliance Case Management module structures this workflow, ensures it is completed, and creates a full, documented audit trail for every case.

Transaction Monitoring With Grey List Calibration: The Transaction Monitoring module screens transactions in real time, with configurable rules and thresholds that can be set differently for customers from greylisted jurisdictions. A transaction that is unremarkable for a low-risk customer becomes a priority alert when the counterparty is based in a greylisted country.

Regulatory Reporting: When a transaction cannot be risk-justified and must be reported as an STR to the UAE FIU via go AML, First Compliance’s Regulatory Reporting module supports the full preparation, review, and submission workflow.

As the most comprehensive governance risk and compliance software in Dubai for regulated entities managing multi-jurisdictional exposure, First Compliance Solution turns the February 2026 FATF update from a reactive scramble into a systematic, automated response.

Platform Modules Mapped to Grey List Management Obligations

Compliance Obligation First Compliance Solution Module
Grey list jurisdiction screening at onboarding Sanction Screening
Customer risk scoring with country risk weighting Risk Management
EDD workflows for greylisted country customers Onboarding and Due Diligence
Beneficial ownership capture and verification E-KYC with real-time face verification
Transaction monitoring for greylisted country exposure Transaction Monitoring
Case management and EDD documentation Compliance Case Management
STR preparation and goAML submission Regulatory Reporting
Policy and procedure document management Document Management
MLRO dashboards and risk reporting Dashboard and Analytics
Regulatory deadline alerts Alerts and Notifications

For UAE businesses managing exposure to all 22 greylisted jurisdictions simultaneously, and for Kuwait-based entities now building their AML/CFT infrastructure under increased FATF scrutiny, the platform provides the end-to-end operational backbone that manual compliance simply cannot replicate.

Investing in robust governance risk and compliance software in Dubai is no longer a choice reserved for large financial institutions. Every regulated DNFBP, exchange house, law firm, real estate broker, and VASP faces the same Grey List obligations, and every one of them needs a system that keeps pace with every FATF update.

Contact us to request a demo and see how the platform can be configured to your sector’s specific obligations under the UAE and Kuwait AML/CFT law.

Conclusion

The FATF Grey List is a living, changing document. In the past twelve months alone, eight countries were removed, and four were added. The February 2026 update brought Kuwait and Papua New Guinea onto the list, leaving 22 jurisdictions under increased monitoring. At the June 2026 Plenary, the list will change again.

For businesses in the UAE and Kuwait, keeping pace with every Grey List update is a legal obligation, not an optional best practice. The countries on this list represent real exposure in your customer base, your transaction flows, and your correspondent relationships.

With governance risk and compliance software in Dubai from First Compliance Solution, every Grey List update becomes an automated system trigger rather than a manual compliance crisis. Your risk scores update, your EDD workflows activate, and your audit trail documents every decision, all without your team having to start from scratch each time the FATF meets.

Contact us to find out how the platform can be configured for your specific sector, customer base, and regulatory obligations.

UAE’s New AML Law 2025/2026: Key Changes Under Federal Decree-Law No. 10 and What Businesses Must Do Now

UAE's New AML Law 2025/2026: Key Changes Under Federal Decree-Law No. 10 and What Businesses Must Do Now

AML compliance in the UAE

On 14 October 2025, the UAE took one of its most significant legislative steps in the fight against financial crime. Federal Decree-Law No. 10 of 2025 came into force, repealing and replacing the previous AML law that had governed the country’s anti-money laundering framework since 2018. This is not a minor update. It is a comprehensive overhaul, and every regulated business operating in the UAE needs to understand exactly what has changed, what is now required, and what the cost of non-compliance looks like in 2026.

With the FATF Mutual Evaluation scheduled for June 2026, the timing of this legislation is deliberate. The UAE is signaling to international assessors that its legal framework is not just reformed on paper but is being actively enforced. For compliance officers, legal teams, and business owners across the Emirates, the window to align with the new law is already narrowing.

Why This Law Was Introduced

The UAE’s removal from the FATF grey list in February 2024 marked a turning point, but it also came with an implicit expectation: that the country would continue strengthening its AML/CFT architecture rather than ease off once the immediate pressure had passed. Federal Decree-Law No. 10 of 2025 is the legislative centerpiece of that continued commitment.

The new law addresses gaps that the 2020 Mutual Evaluation identified, incorporates the findings of the UAE’s third National Risk Assessment published in April 2025, and aligns domestic legislation more closely with the FATF’s evolving global standards. It also reflects the realities of a financial landscape that looks very different from 2018, including the rapid growth of virtual assets, the increasing sophistication of financial crime, and the UAE’s expanded role as a global trading and investment hub.

Key Changes Under Federal Decree-Law No. 10 of 2025

Area of Change Previous Position (2018 Law) New Position (2025 Law)
Proliferation Financing Addressed within broader CTF provisions Now a standalone criminal offence with specific obligations
Predicate Offences Limited list of underlying crimes Expanded to explicitly include tax evasion
Virtual Assets Limited coverage Explicit inclusion of VASPs and digital asset transactions
Beneficial Ownership General obligations Strengthened verification and record-keeping requirements
Penalties Existing penalty framework Significantly enhanced fines and criminal sanctions
Digital Systems Not explicitly addressed Explicitly covered, including digital onboarding and e-KYC
Risk-Based Approach Encouraged Mandated with documented evidence of application
STR Obligations Existing framework Expanded scope of reporting triggers and timelines
Supervisory Powers Existing framework Broader powers granted to supervisory authorities
Cross-Border Cooperation General provisions Strengthened mutual legal assistance and information sharing

The Five Most Significant Changes Explained

1. Proliferation Financing as a Standalone Offence

Perhaps the most consequential change in the new law is the introduction of proliferation financing (PF) as a distinct criminal offence, separate from broader counter-terrorism financing obligations. Under the 2018 framework, PF controls were embedded within general CTF provisions and were often treated as an extension of sanctions screening. The 2025 law demands a fundamentally different approach.
Businesses must now:

  • ● Conduct a specific Proliferation Financing Risk Assessment (PFRA) that is separate from their general Business Risk Assessment
    ● Implement targeted financial sanctions (TFS) controls specifically designed to detect and prevent PF activity
    ● Document their PF risk exposure and the controls applied to mitigate it
    ● Train staff on PF typologies, red flags, and reporting obligations

This change alone will require most regulated entities to revisit their existing risk assessment frameworks from the ground up.

2. Tax Evasion as a Predicate Offence

Key Stats to Know

Key Stats to Know

Key Stats to Know

The explicit inclusion of tax evasion as a predicate offence to money laundering carries significant practical implications, particularly for businesses that serve high-net-worth individuals, corporate clients with complex cross-border structures, or customers operating in multiple jurisdictions.

Where previously tax matters were largely treated as a separate regulatory concern, compliance teams must now consider tax risk as part of their AML customer due diligence process. Enhanced due diligence for clients with opaque tax structures, offshore holdings, or exposure to high-risk jurisdictions is now an expectation, not a discretionary measure.

3. Virtual Assets and VASPs

The UAE has become one of the most active virtual asset markets in the world, and the 2025 law reflects that reality. Virtual Asset Service Providers are now explicitly brought within the scope of the AML framework, with obligations that mirror those applied to traditional financial institutions.
Key requirements for VASPs and entities transacting in virtual assets include:

  • ● Full compliance with the Travel Rule for virtual asset transfers above threshold values
    ● Risk-based CDD on virtual asset customers, including source of funds verification
    ● Real-time sanctions screening against all relevant lists including OFAC, UN, and UAE local lists
    ● Suspicious Transaction Reporting for anomalous virtual asset activity
    ● Licensing verification of counterparty VASPs before processing transactions

4. Strengthened Beneficial Ownership Requirements

Beneficial ownership transparency has been a persistent weakness in the UAE’s AML framework, and the 2025 law addresses it directly. Regulated entities are now required to verify beneficial ownership information more rigorously at onboarding, review it more frequently throughout the relationship, and maintain records in a format that is accessible and auditable.

The practical implications are significant:

  • Ownership structures with multiple layers or complex corporate chains require deeper investigation
  • Passive reliance on customer-provided documentation is no longer sufficient
  • Ongoing monitoring must flag changes in ownership structure that could indicate emerging risk
  • Records must be maintained in a format that can be produced quickly to supervisory authorities

5. Enhanced Penalties and Supervisory Powers

5. Enhanced Penalties and Supervisory Powers

The 2025 law grants supervisory authorities, including the Central Bank, CBUAE, SCA, VARA, and DFSA within their respective jurisdictions, significantly broader powers to investigate, sanction, and prosecute non-compliance. Penalties have been enhanced across the board, with fines reaching into the tens of millions of dirhams for serious or repeated breaches.

The Central Bank has already signaled the direction of travel, issuing approximately AED 350 million in AML-related fines in recent months. Under the new law, that enforcement posture is backed by an even stronger legal foundation.

Who Is Affected: Regulated Entities Under the New Law

The following categories of business fall within the scope of Federal Decree-Law No. 10 of 2025:

● Banks, exchange houses, and financial institutions
● Insurance companies and brokers
● Investment firms and asset managers
● Real estate agents and brokers
● Lawyers, notaries, and independent legal professionals
● Accountants and auditors
● Company formation agents and corporate service providers
● Dealers in precious metals and stones
● Virtual Asset Service Providers (VASPs)
● Free zone entities engaged in financial or designated non-financial activities

If your business falls into any of the above categories and you have not yet conducted a gap analysis against the new law, that process should begin immediately.

What Businesses Must Do Now: A Compliance Action Plan

Action Priority Timeline
Conduct gap analysis against Federal Decree-Law No. 10 Critical Immediately
Update Business Risk Assessment to include PF risk Critical Within 30 days
Review and update CDD and EDD procedures High Within 30 days
Update sanctions screening to cover all required lists Critical Immediately
Implement or review Travel Rule compliance (VASPs) High Within 30–60 days
Retrain staff on new typologies, PF, and tax evasion High Within 60 days
Review beneficial ownership verification procedures High Within 30 days
Update AML policies and procedures manual High Within 45 days
Conduct board-level briefing on new obligations Medium Within 30 days
Stress-test transaction monitoring rule sets Medium Within 60 days
Prepare evidence pack for regulatory inspection Medium Within 90 days

The Role of Technology in Meeting the New Standard

The obligations introduced under Federal Decree-Law No. 10 are not achievable through manual processes alone. The volume, complexity, and speed of data required to meet the new law’s expectations demand a technology-led approach. This is where investing in robust AML compliance software becomes not just useful but essential. A capable platform enables regulated entities to:

  • ● Screen customers and transactions against hundreds of global and local sanctions lists in real time
    ● Apply dynamic, risk-based scoring to customer profiles that updates automatically as new information emerges
    ● Monitor transactions continuously for patterns consistent with money laundering, proliferation financing, or tax evasion
    ● Generate and file Suspicious Transaction Reports within the required timeframes
    ● Maintain auditable records of every compliance decision for regulatory inspection
    ● Produce management information and board-level reporting on compliance performance
    ● Document the application of a risk-based approach in a format assessor can verify

Without the right technology embedded in your operations, the gap between what the law now requires and what your organization can demonstrate is likely to be significant.

Common Gaps Regulators Will Identify in 2026

Based on the new law’s provisions and the FATF’s 5th Round Methodology, the following weaknesses are most likely to be identified during supervisory inspections and the June 2026 Mutual Evaluation:

  • ● Proliferation financing risk assessments that are absent, generic, or not tailored to the specific business model
    ● Transaction monitoring systems that generate high volumes of false positives but miss genuine suspicious activity
    ● CDD files that are incomplete, outdated, or do not reflect the current risk rating of the customer
    ● STR filings that are low in volume, poor in quality, or submitted outside required timeframes
    ● Beneficial ownership records that cannot be verified independently or accessed quickly
    ● Staff training that is annual and tick-box rather than ongoing and risk-informed
    ● Governance structures where the compliance function lacks sufficient seniority, resource, or board access

Each of these gaps is both a regulatory risk and an operational vulnerability. Addressing them before an inspection is infinitely preferable to explaining them during one.

How First Compliance Supports Full Alignment with the New Law

At First Compliance, we have developed our platform specifically for regulated entities operating within the UAE’s legal and regulatory environment. Every module is built to address the obligations that matter most under Federal Decree-Law No. 10 of 2025 and the broader FATF framework. For any regulated business searching for dependable AML compliance software, our solution is purpose-built for exactly this environment.

Our platform covers:

  • Sanctions and PEP Screening – real-time screening against hundreds of global lists including OFAC, UN, EU, HM Treasury, and UAE local lists
    ● eKYC and Customer Due Diligence – automated, risk-scored onboarding with full document management and beneficial ownership mapping
    Transaction Monitoring – AI-powered detection of suspicious patterns with customizable rule sets aligned to current UAE typologies
    Proliferation Financing Controls – dedicated modules supporting PFRA and TFS compliance
    ● Regulatory Reporting – structured STR and CTR workflows that ensure accurate, timely filing
    ● Case Management – complete audit trails for every alert, investigation, and compliance decision
    ● Risk Management – dynamic customer risk scoring that reflects a genuine risk-based approach
    ● Dashboard and Analytics – real-time management information for compliance officers and board-level reporting

Whether you are a bank, a VASP, a DNFBP, or a free zone entity, our platform scales to your size, your risk profile, and your regulatory obligations.

The Bottom Line

Federal Decree-Law No. 10 of 2025 has raised the bar for AML compliance in the UAE in a way that cannot be addressed through policy updates alone. It demands operational change, technological investment, and a genuine culture of compliance that runs from the front line to the boardroom.

With the FATF Mutual Evaluation arriving in June 2026, the question is not whether your organization will face scrutiny. It is whether you will be ready when it arrives.

The businesses that act now, closing gaps, upgrading systems, and embedding the new law’s requirements into daily operations, will not only survive the evaluation. They will demonstrate the kind of institutional commitment that regulators and international partners are looking for.

Take the Next Step with First Compliance

Do not wait for a regulatory inspection to discover where your gaps are. First Compliance gives you the tools, the data, and the audit trail to face the new AML landscape with confidence. Our AML compliance software is trusted by regulated entities across the UAE to deliver exactly the kind of operational readiness that the new law demands.

Schedule your free demo today at First Compliance and let our team show you exactly how our platform aligns with Federal Decree-Law No. 10 of 2025, the FATF’s 5th Round requirements, and the supervisory expectations of 2026.

Your compliance framework should be an asset, not a vulnerability. Let us help you make it one.

Preparing for FATF Mutual Evaluation UAE 2026: What Regulators Will Scrutinize and How to Stay Compliant

Preparing for FATF Mutual Evaluation UAE 2026: What Regulators Will Scrutinize and How to Stay Compliant

Compliance monitoring software Dubai

The UAE has come a long way. Removed from the FATF grey list on 23 February 2024 after being placed under increased monitoring in March 2022, the country has demonstrated a serious commitment to strengthening its AML/CFT framework. But with the UAE’s next mutual evaluation by the FATF scheduled for June 2026, the work is far from over. In fact, for regulated entities across the UAE, the real pressure is only just beginning.

This evaluation will be conducted under the FATF’s 5th Round Methodology, which applies tighter scrutiny, a faster cycle, and a sharper focus on effectiveness rather than mere technical compliance. For financial institutions, DNFBPs, and compliance officers operating in the UAE, understanding what assessors will scrutinise is not optional. It is urgent.

Why This Evaluation Matters More Than the Last

The 2020 Mutual Evaluation exposed significant weaknesses in the UAE’s AML/CFT system, ultimately leading to grey listing. Since then, the UAE has enacted sweeping reforms. Federal Decree-Law No. 10/2025, which came into effect on 14 October 2025, repealed and replaced the 2018 AML law, introducing standalone offences for proliferation financing, expanding predicate offences to include tax evasion, and explicitly covering digital systems and virtual assets.

The UAE has also launched a national strategy for AML, CTF and proliferation financing for 2024 to 2027, developed on the basis of its third National Risk Assessment, published in April 2025.

Despite this progress, regulators will expect to see that reforms are not just enacted on paper but embedded in day-to-day institutional practice. That distinction, between formal compliance and operational effectiveness, is precisely where the 2026 evaluation will probe hardest.

Why This Evaluation Matters More Than the Last

Focus Area What Assessors Will Look For
Beneficial Ownership Accurate, up-to-date records; effective verification at onboarding
Transaction Monitoring Real-time detection of suspicious patterns; STR filing quality and volume
Sanctions Screening Coverage of all relevant lists; speed and accuracy of screening
Virtual Assets Compliance with Travel Rule; VASP licensing and oversight
Customer Due Diligence Risk-based approach; enhanced DD for high-risk customers
Regulatory Reporting Timeliness, completeness and accuracy of STRs and CTRs
Proliferation Financing Controls aligned with new Federal Decree-Law No. 10/2025
Cross-Border Cooperation Mutual Legal Assistance requests; information sharing evidence

The 11 Immediate Outcomes: Where Gaps Are Most Likely

The FATF’s 5th Round assesses effectiveness against 11 Immediate Outcomes (IOs). Based on the UAE’s 2020 MER and subsequent reforms, the following IOs are likely to attract the greatest scrutiny in 2026:

  • ● IO.4 – Financial institutions apply adequate AML/CFT preventive measures
    ● IO.3 – Supervisors appropriately supervise, monitor and regulate financial institutions and DNFBPs
    ● IO.6 – Financial intelligence is effectively used by competent authorities
    ● IO.7 – ML offences and activities are investigated and offenders prosecuted
    ● IO.11 – Proliferation financing is prevented and suppressed

For each IO, assessors will seek evidence of actual outcomes, not policies alone. Documentation, case examples, audit trails, and data will all be requested.

Sectors Under the Sharpest Scrutiny

Key Stats to Know

Key Stats to Know

Certain sectors will face heightened examination based on the UAE’s risk profile as a major global financial and trading hub:

  • ● Banks and financial institutions – transaction monitoring effectiveness, STR quality
    ● DNFBPs (real estate agents, lawyers, accountants, gold and precious metals dealers) – risk-based CDD, STR filing rates
    ● Virtual Asset Service Providers (VASPs) – Travel Rule compliance, licensing status
    ● Free Zone entities – beneficial ownership transparency, oversight adequacy
    ● Hawala and money service businesses – registration, monitoring, and reporting

The UAE Central Bank has already ramped up enforcement, issuing nearly AED 350 million in fines for AML and CTF breaches in recent months. Regulators are signalling clearly that the supervisory environment has changed.

Key Stats to Know

Metric Figure
UAE grey list inclusion March 2022
UAE grey list removal February 2024
Federal Decree-Law No. 10/2025 effective date 14 October 2025
FATF 5th Round on-site visit (UAE) June 2026
Central Bank AML fines (recent months) ~AED 350 million
UAE National AML/CFT Strategy period 2024–2027

How to Stay Compliant: A Practical Readiness Checklist

Institutions should use the months ahead to close gaps before assessors arrive. The following steps are non-negotiable:

  • ● Conduct an internal gap analysis against FATF’s 40 Recommendations and the 11 IOs
    ● Update your Business Risk Assessment (BRA) to reflect the 2025 National Risk Assessment findings
    ● Review and stress-test your transaction monitoring rules for false negative rates and STR conversion quality
    ● Ensure beneficial ownership records are accurate, verified, and accessible in real time
    ● Document your risk-based approach to CDD with clear escalation procedures for high-risk customers
    ● Align policies with Federal Decree-Law No. 10/2025, particularly on proliferation financing and virtual assets
    ● Train staff across all levels, including front-line teams, on updated typologies and red flags
    ● Prepare an evidence pack for each IO your organisation is relevant to

Effective compliance monitoring software in Dubai is no longer a nice-to-have at this stage. It is the infrastructure that makes all of the above achievable, auditable, and demonstrable to assessors.

How to Stay Compliant: A Practical Readiness Checklist

Institutions should use the months ahead to close gaps before assessors arrive. The following steps are non-negotiable:

  • ● Conduct an internal gap analysis against FATF’s 40 Recommendations and the 11 IOs
    ● Update your Business Risk Assessment (BRA) to reflect the 2025 National Risk Assessment findings
    ● Review and stress-test your transaction monitoring rules for false negative rates and STR conversion quality
    ● Ensure beneficial ownership records are accurate, verified, and accessible in real time
    ● Document your risk-based approach to CDD with clear escalation procedures for high-risk customers
    ● Align policies with Federal Decree-Law No. 10/2025, particularly on proliferation financing and virtual assets
    ● Train staff across all levels, including front-line teams, on updated typologies and red flags
    ● Prepare an evidence pack for each IO your organisation is relevant to

Effective compliance monitoring software in Dubai is no longer a nice-to-have at this stage. It is the infrastructure that makes all of the above achievable, auditable, and demonstrable to assessors.

The Role of Technology in FATF Readiness

Manual compliance processes will not meet the bar that 2026 assessors will set. Regulators want to see systems that generate reliable data, detect anomalies in real time, and produce audit-ready records at a moment’s notice.

This is where purpose-built compliance monitoring software in Dubai delivers a decisive advantage. From automated sanctions screening and risk-scored onboarding to real-time transaction monitoring and regulatory reporting, technology reduces human error, closes coverage gaps, and builds the evidentiary trail that assessors will look for.

How First Compliance Can Help

At First Compliance, we have built an all-in-one platform specifically designed for institutions operating in the UAE’s regulatory environment. Our modules cover every dimension of FATF readiness:

  • ● Sanctions Screening – integrated with hundreds of global lists, updated in real time
    ● eKYC and Onboarding Due Diligence – risk-scored, automated, and fully documented
    ● Transaction Monitoring – AI-powered detection with customisable rule sets
    ● Regulatory Reporting – structured, accurate STR and CTR filing workflows
    ● Case Management – end-to-end audit trails for every compliance decision
    ● Risk Management – dynamic risk scoring aligned with a risk-based approach

As a leading provider of compliance monitoring software in Dubai, First Compliance gives your institution the tools, the data, and the documentation to face the 2026 Mutual Evaluation with confidence.

The Bottom Line

The UAE’s 2026 FATF Mutual Evaluation is not a formality. It is a high-stakes assessment of whether reforms have translated into real-world effectiveness. Institutions that start preparing now, with the right policies, the right training, and the right technology in place, will be far better positioned than those that wait.

The window to act is open. But it will not stay open for long.

Ready to strengthen your compliance framework ahead of the 2026 FATF evaluation?

Schedule a free demo with First Compliance today and see how our platform can close your gaps, automate your reporting, and give you the confidence to face regulatory scrutiny head-on.

Advanced Due Diligence in the Age of AI: A Strategic Workshop for Compliance Leaders

Advanced Due Diligence in the Age of AI: A Strategic Workshop for Compliance Leaders

In response to the ongoing regulatory reporting and supervisory obligations currently impacting the Insurance sector, we are pleased to announce our highly anticipated invitation-only compliance workshop. This strategic adjustment ensures maximum participation and engagement from senior compliance leaders across the UAE’s Insurance and Real Estate sectors.

About the Workshop

Organised by DNY Communications in collaboration with First Compliance by Adil Zone, this exclusive workshop addresses one of the most critical challenges facing compliance professionals today: “Mastering Advanced Due Diligence in the Age of AI.

As artificial intelligence continues to transform the compliance landscape, organizations must adapt their Enhanced Due Diligence (EDD) frameworks to leverage these powerful technologies while maintaining robust governance and risk management practices.

Why This Workshop Matters

The regulatory environment for Insurance and Real Estate sectors in the UAE is evolving rapidly. Compliance leaders face mounting pressure to:

This practitioner-led session has been specifically curated for Insurance and Real Estate Compliance Heads who are at the forefront of these challenges.

Workshop Focus Areas

Participants will gain practical insights into:

AI-Enhanced Due Diligence

Discover how artificial intelligence is reshaping Enhanced Due Diligence frameworks, from initial customer onboarding to ongoing monitoring and risk assessment.

Risk-Based Approaches

Learn advanced techniques for implementing proportionate, risk-based due diligence measures that satisfy regulatory requirements while optimizing operational efficiency.

Governance and Model Risk

Explore frameworks for governing AI systems in compliance operations, including model validation, bias detection, and accountability mechanisms.

Latest Tools and Techniques

Get hands-on exposure to cutting-edge technologies and methodologies that are transforming the compliance function.

Why Attend?

Exclusive Peer Network

Connect with a carefully selected group of no more than 35 senior compliance leaders from Insurance and Real Estate sectors, facilitating meaningful discussions and relationship building.

Practical, Not Theoretical

This is a practitioner-led session focused on real-world applications, case studies, and actionable strategies you can implement immediately.

Stay Ahead of the Curve

In a rapidly evolving regulatory and technological landscape, this workshop provides the knowledge and tools you need to maintain a competitive advantage.

Strategic Insights

Gain perspectives on how AI is not just changing compliance processes, but fundamentally reshaping risk management, customer relationships, and business models.

The First Compliance Advantage

As part of the Adil Zone ecosystem, First Compliance brings deep expertise in regulatory compliance, AML/CFT frameworks, and risk management to organizations across the UAE. Our commitment to “Total Compliance, Total Security” means we understand the unique challenges facing compliance professionals in regulated industries.

This workshop represents our dedication to:

How to Participate

Due to the exclusive nature of this event and limited capacity, attendance is by invitation only. If you are a senior compliance professional in the Insurance or Real Estate sector and would like to be considered for an invitation, please contact:

Email: debbie@dnycommunications.com
Subject: Workshop Invitation Request – January 28, 2026

Please include your name, organization, title, and a brief description of your compliance responsibilities.

Looking Forward

As we approach January 28, 2026, we are excited to bring together some of the most forward-thinking compliance leaders in the UAE for a morning of intensive learning, collaboration, and strategic thinking. The intersection of AI and due diligence represents one of the most significant developments in compliance management in recent years, and this workshop will equip you with the knowledge and tools to navigate this new landscape with confidence.

The regulatory environment will continue to evolve, technologies will advance, and expectations will rise. By investing in your professional development and staying connected with your peers, you position yourself and your organization for success in whatever challenges lie ahead.

Scroll to top