DFSA AML Rulebook amendments 2026:

what DIFC firms need to know

DFSA AML Rulebook amendments 2026: what DIFC firms need to know
The Dubai Financial Services Authority (DFSA) has introduced significant amendments to its Anti-Money Laundering, Counter-Terrorist Financing and Sanctions (AML) Module and Glossary Module, aligning its framework with the UAE's updated federal AML legislation. The DFSA AML amendments were issued on 26 February 2026 and came into force on 2 March 2026.

The amendments incorporate references to Federal Decree Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025, establishing a stronger and more comprehensive framework for tackling money laundering, terrorist financing and proliferation financing. While many of the revisions update legal references, a number of substantive changes introduce enhancements to customer due diligence (CDD) requirements, beneficial ownership obligations and governance expectations.

 

Key developments organisations should be aware of:

  • Introduction of proliferation financing
One of the most notable developments in the revised DFSA AML Rulebook is the increased emphasis on proliferation financing. Organisations are expected to incorporate proliferation financing risks into their enterprise-wide risk assessments, AML/CFT/CPF programmes, staff training and governance arrangements.

This reflects growing international focus on preventing the financing of weapons proliferation and aligns the UAE framework more closely with evolving FATF expectations. As a result, DFSA-regulated firms should consider whether their existing financial crime risk management frameworks adequately address proliferation financing risks.
  • Customer due diligence expectations
The amendments expand the information Authorised Firms are expected to obtain and verify as part of their customer due diligence processes.

For individual customers, firms are now expected to obtain additional information such as the customer's place of birth and, where applicable, name and address of the employer (where applicable). For corporate customers, firms must collect further information such as the legal form, tax registration information, unique reference numbers and local legal representative details where the entity is incorporated outside the UAE.

These changes may require DIFC firms to revisit onboarding procedures, customer information forms and KYC data collection processes to ensure all required information is captured consistently and in line with the revised DFSA AML requirements.
  • Increased focus on beneficial ownership transparency
The amendments introduce greater clarity regarding beneficial ownership information that firms are expected to obtain and maintain. Authorised Firms are required to collect more comprehensive information regarding beneficial owners, including full name, nationality, date and place of birth, residential address, identification details, tax registration information and other relevant identifying information.

This development reflects the continued regulatory focus on ownership transparency and the ability of firms to identify and verify the individuals who ultimately own or control customers. For organisations operating in the DIFC, reviewing existing beneficial ownership procedures should therefore form an important part of their broader DIFC AML compliance assessment.
  • Greater accountability for senior management
A notable enhancement within the revised DFSA AML Module is the explicit expectation that an Authorised Firm's AML policies, procedures, systems and controls are approved by senior management.

Although governance and oversight have long formed part of regulatory expectations, the amendment reinforces the role of senior management in overseeing AML compliance and demonstrating effective governance over financial crime risks.

 

What should DIFC firms do next?

The DFSA AML Rulebook amendments 2026 present an opportunity for firms to assess whether their existing AML/CFT/CPF frameworks remain aligned with evolving regulatory expectations.

Key areas for consideration include:
  • Conducting gap assessments against the revised DFSA AML requirements to identify areas requiring remediation or enhancement.
  • Reviewing and updating AML/CFT/CPF policies and procedures to align with revised DFSA requirements.
  • Updating of the Enterprise-Wide Risk Assessment.
  • Assessing whether onboarding processes capture all additional customer and beneficial ownership information requirements.
  • Evaluating governance arrangements and MLRO oversight responsibilities.
  • Reviewing customer due diligence and KYC frameworks.
  • Updating internal training and awareness programmes.


Key implications for DIFC firms

The latest DFSA AML amendments demonstrate the DFSA's continued focus on strengthening AML/CFT/CPF controls and maintaining consistency with the UAE's evolving financial crime framework. While many firms may already have mature AML/CFT/CPF compliance programmes, the inclusion of proliferation financing, expanded due diligence requirements, enhanced beneficial ownership standards and reinforced governance expectations highlight the importance of regularly reviewing and updating AML/CFT/CPF frameworks.

As regulatory scrutiny continues to increase, firms should ensure that their AML/CFT/CPF programmes are not only compliant on paper but also supported by effective governance, robust customer due diligence processes and demonstrable control effectiveness.

CONNECT WITH AML EXPERTS