By Amarjeet Singh, 27 July 2026
American compliance officers have spent the past year watching the Trump administration's enforcement priorities with a mixture of relief and anxiety. Relief at reduced regulatory pressure in some areas; anxiety about where the next wave comes from. In the meantime, there is a useful data point sitting in the Gulf that has not received the attention it deserves.
In the first eight months of 2025, the Central Bank of the UAE fined or revoked licences across 31 financial institutions, 13 of them exchange houses, with total penalties exceeding AED 380 million (approximately $104 million). The single largest action was an AED 200 million sanction against one exchange house for what the regulator described as 'pervasive' failures in anti money laundering (AML) controls. The branch manager was personally fined AED 500,000 and permanently banned from the sector.
This happened in a jurisdiction that had been removed from the Financial Action Task Force (FATF) grey list only 18 months earlier, in February 2024. The enforcement surge was not a sign of ongoing failure. It was the opposite: a newly delisted jurisdiction proving to FATF, to correspondent banks, and to international observers that its supervisory regime delivers real consequences.
That dynamic delisting followed by intensified enforcement to demonstrate credibility is not unique to the UAE. It is the standard FATF playbook. And it is worth understanding if you are thinking about where US enforcement is heading as the post-Trump regulatory landscape takes shape, and with the US undergoing its fifth-round mutual evaluation by FATF.
The pattern: credibility through enforcement
The logic is straightforward. FATF mutual evaluations assess not just whether laws exist, but whether they are effectively implemented. A jurisdiction that passes its technical assessment but cannot demonstrate that its supervisory apparatus produces dissuasive sanctions fails the effectiveness test. The UAE, having achieved delisting, had every incentive to generate an enforcement record that would satisfy the mid-2026 FATF mutual assessment that Norton Rose Fulbright identified as an anticipated near-term milestone.
The findings in UAE enforcement actions in 2025 were familiar: weak transaction monitoring, delayed suspicious activity reporting (SAR), inadequate customer due diligence. These are not exotic failure modes. They are the same gaps that the Financial Crimes Enforcement Network (FinCEN), the Office of the Comptroller of the Currency (OCC), and the Federal Reserve have cited in US enforcement actions for decades. The difference is that in the UAE's post-delisting enforcement environment, those gaps resulted in penalties that were not calibrated to institutional size or prior record. They were calibrated to send a message.
US compliance officers should note this is not because the UAE and US regulatory environments are equivalent – they are not – but because the enforcement logic is similar. When a regulatory body needs to demonstrate effectiveness, it enforces. The question is always when, and against whom.
What the UAE experience suggests about monitoring gaps
The UAE enforcement record is notable for what it found, not just what it punished. In almost every significant enforcement action in 2025, the finding was not that the institution lacked a transaction monitoring system. It was that the system existed but did not function effectively: alerts were not acted upon in time, documentation was inadequate, and the gap between policy and practice was demonstrable.
This is a distinction that matters for US chief compliance officers. Most institutions in regulated sectors have transaction monitoring. The regulatory question increasingly is not whether you have monitoring, but whether your monitoring produces documented, timely, individually-authenticated decisions. The new UAE AML law, Federal Decree-Law No. 10 of 2025, makes this explicit by imposing personal liability on senior managers for failures of supervision, including failures to act on information they had access to.
The 'should have known' standard that the new UAE law adopts, as analysed by multiple international law firms including Norton Rose Fulbright and White & Case, aligns the UAE with the UK's Senior Managers regime. It is worth noting that FinCEN's AML/counter financing of terrorism programme overhaul, which has been in development since 2023, moves US AML requirements in a similar direction toward risk-based effectiveness rather than procedural box-checking.
Three questions worth asking
Does your alert-to-decision workflow create an individually authenticated record?
Not just a system log showing the alert was closed. An actual record that a specific, authorised person reviewed specific information and made a documented decision. The UAE enforcement record shows that inspectors look at this question directly.
Can you produce your Suspicious Transaction Report (STR) documentation under time pressure?
The UAE's most cited failure was delayed reporting to the financial intelligence unit. FinCEN's rules on SAR filing timelines are similarly unforgiving. If your team is managing alert volume through a fragmented workflow across multiple applications, time-to-decision is a risk.
Does your board understand that 'adequate controls' now has an individual dimension?
In jurisdictions that have adopted senior manager accountability frameworks, institutional controls are a necessary but not sufficient defence. Boards that still think about AML as a purely institutional risk are behind where regulation is heading.
The UAE's enforcement story is a preview. The specifics will differ by jurisdiction. The direction is consistent.
About the author
Dr Amarjeet Singh is Director of Governance, Risk, and Compliance (GRC) at AJMS Global, a leading consulting firm in the UAE. He previously headed the compliance function at a UAE-based exchange house regulated by the Central Bank of the UAE (CBUAE). He is CAMS, CFE and ICA qualified, with over 15 years of hands-on experience in AML, financial crime compliance, and regulatory governance across the MENA region. He specialises in designing and strengthening robust compliance frameworks within the financial services sector.
Dr Singh is also author of The Money Trail: Mastering Financial Crime Compliance (2024). His peer-reviewed research focuses on the application of AI in financial crime compliance and trade-based money laundering.