All topicsAML and CFT obligations
AML training in the UAE: who needs to learn what?
An employee recognising a warning sign and a compliance officer assessing it need different skills. Here is how a useful AML training programme connects them.

A salesperson notices that a customer’s payment will come from an unrelated company. The compliance officer sees the same information and asks different questions: who controls that company, what explains the payment and whether the transaction needs further examination. Both people need AML training, but not the same depth of training.
That distinction is the starting point for a useful programme. Anti-money-laundering awareness gives people a common language. Role-specific training teaches them what to do with the situations they actually encounter. Specialist development equips those responsible for the more difficult decisions.
What does the UAE requirement ask of a business?
Articles 21 and 22 of Cabinet Resolution 134 of 2025 place training within the regulated entity’s wider controls. They address periodic programmes for compliance and relevant staff, and the compliance officer’s role in developing, implementing and documenting ongoing training.
The practical point is that training belongs to the business’s risk-management arrangements. A certificate is evidence of an activity; it does not, by itself, show that the right people learned the right procedure or that the company’s controls work.
The scope matters too. Requirements for a regulated financial institution or DNFBP should not be casually presented as an identical obligation for every UAE employer. Establishing the organisation’s regulated activities comes before choosing its training plan.
A shared foundation, then different responsibilities
Most relevant staff need to understand why criminals use legitimate businesses, what an unusual transaction can look like and how concerns move through the company. They also need to understand confidentiality: telling a customer that a suspicious report may be filed can create a serious problem.
From there, learning should follow responsibility.
Role | The capability training should develop |
|---|---|
Customer-facing employee | Recognise relevant warning signs, gather required information and use the internal escalation route |
Operations or onboarding employee | Apply customer and beneficial-owner checks, document gaps and follow review procedures |
Compliance officer | Assess concerns, manage reporting and controls, and keep knowledge current |
Management | Understand the business’s risks, approve suitable controls and provide the resources to operate them |
These are examples of training needs, not four universally prescribed job titles. In a small business, one person may perform several functions. That makes the coverage broader, not unnecessary.
Why examples need to resemble the work
Return to the unrelated payer. An introductory lesson can explain why a payment inconsistent with the customer profile deserves attention. Company instruction must then show where the employee records it, whether the transaction is held, and who makes the decision.
Without that second layer, the employee may understand the warning sign yet still send a vague message to the wrong colleague. Conversely, a procedure memorised without understanding can become a mechanical form-filling exercise.
A general AML and CFT awareness course can support the foundation. It should be accompanied by the firm’s actual escalation contacts, customer-check procedures and sector examples. Neither a broad awareness course nor a specialist qualification automatically supplies those internal details.
How often should training happen?
A calendar is helpful, but it is not the whole programme. Joining the business, moving to a higher-risk role, changing a procedure or identifying a recurring mistake can all create a learning need before the next scheduled session.
The cited provisions call for periodic and ongoing training; they should not be turned into a made-up universal rule that every employee must complete the same number of hours once a year. Specific supervisory directions and the entity’s own approved arrangements may add requirements.
The sensible question at review is whether the current plan still fits the people, activities and risks. Repeating unchanged slides while the business starts a new service is less useful than teaching the decisions that service introduces.
What demonstrates that the programme is working?
Attendance establishes participation. Assessment can show understanding of selected points. A reviewed case or supervisor discussion can reveal whether the learning carries into work. These forms of evidence answer different questions and are strongest together.
An AML training register connects those records to people and roles over time. It makes a new joiner’s missing induction or a transferred employee’s additional training need visible. The aim is a programme the business can explain and improve, not merely a folder containing the largest possible number of certificates.
Questions we are asked
Short answers on the points readers raise most about this topic.
- Can an employee use a certificate from a previous employer?
- It may demonstrate relevant prior learning, subject to its content, date and any applicable requirements. The new employer still needs to assess gaps and teach its own procedures, responsibilities and escalation routes.
- Does AML training have to be delivered in English?
- The important learning question is whether staff understand and can apply it. Choose a language and materials appropriate to the audience, while checking any specific supervisory or reporting requirements. An English attendance record alone does not demonstrate understanding.
Related articles
Train your people, and keep records an inspector can read.
