Pricing
Language
Published 19-07-2026 · Updated 19-07-2026

UAE AML Rules for Commercial Gaming Operators

Understand UAE gaming AML rules, the AED 11,000 threshold, GCGRA oversight, player due diligence, sanctions screening and reporting.

Share

UAE AML Rules for Commercial Gaming Operators

Commercial gaming operators in the United Arab Emirates sit within a developing but already substantive regulatory framework. The General Commercial Gaming Regulatory Authority (GCGRA) licenses and supervises commercial gaming, while UAE federal legislation establishes the core anti-money laundering, counter-terrorist financing, and counter-proliferation financing obligations.

The central gaming-specific rule is found in Cabinet Resolution No. 134 of 2025. It brings commercial gaming operators within the designated non-financial businesses and professions (DNFBP) perimeter when they conduct a single financial transaction—or several transactions that appear to be linked—of AED 11,000 or more.

That threshold is important, but it is not a complete AML program. A licensed operator must also consider customer due diligence, ongoing monitoring, higher-risk relationships, targeted financial sanctions, suspicious transaction reporting, governance, and recordkeeping.

In brief: UAE commercial gaming operators should map financial transactions and linked activity, identify players and relevant related parties, screen for sanctions and PEP exposure, monitor relationships and transactions, escalate unusual activity, and preserve an auditable decision record.

Who Regulates Commercial Gaming in the UAE?

The GCGRA is the UAE authority responsible for licensing, regulating, and supervising commercial gaming. Its published scope includes lottery operations, internet gaming, sports wagering, and land-based gaming facilities or resorts.

The executive regulation also expressly includes commercial gaming conducted on board vessels or marine craft. Operators should determine territorial and licensing scope with UAE counsel rather than assuming that an offshore or onboard format falls outside the framework.

For financial crime prevention, the GCGRA says it expects licensees to demonstrate adequate controls, including:

  • periodic risk assessments;
  • suitable policies, procedures, and governance;
  • player due diligence;
  • transaction monitoring; and
  • internal and external reporting of suspicious transactions and activities.

The wider AML architecture remains shared. GCGRA supervises the gaming sector, the UAE Financial Intelligence Unit (FIU) receives suspicious transaction reports through its designated electronic system, and the UAE targeted-financial-sanctions framework governs list screening, freezing, and reporting.

Which UAE AML Rules Apply?

The most relevant official sources are:

SourceWhat it establishes
Federal Decree-Law No. 10 of 2025The federal AML/CFT/CPF framework, including preventive obligations, the FIU, supervision, reporting, and penalties.
Cabinet Resolution No. 134 of 2025The executive regulation, including the gaming perimeter, CDD, ongoing monitoring, internal controls, compliance oversight, and recordkeeping.
Cabinet Decision No. 74 of 2020Targeted financial sanctions, including implementation of UN Security Council measures and the UAE Local Terrorist List.
GCGRA Financial Crime PreventionThe regulator's description of financial-crime controls and supervisory expectations for licensees.
Commercial Gaming Policy Paper (2025)Official policy recommendations and sector-risk considerations. It should not be presented as if every recommendation were a stand-alone binding rule.

This distinction matters. Federal legislation and applicable GCGRA regulations or licence conditions create binding requirements. The policy paper is highly relevant to control design and supervisory expectations, but it describes recommendations and best practices rather than replacing the law.

UAE Gaming AML Timeline

The commercial gaming framework builds on an older federal AML and targeted-financial-sanctions foundation. The most relevant milestones for operators are:

UAE gaming regulation

UAE AML and Commercial Gaming Milestones

  1. 2014

    Terrorism offences law

    Federal Law No. 7 of 2014 established a key part of the federal counter-terrorism framework.

  2. 2020

    Targeted financial sanctions

    Cabinet Decision No. 74 of 2020 set the framework for terrorist lists and relevant UN sanctions implementation.

  3. 2022

    GCGRA founding law

    GCGRA references Federal Law by Decree No. 30 of 2022 as its founding legislation.

  4. 2023

    Beneficial ownership procedures

    Cabinet Resolution No. 109 of 2023 addressed real-beneficiary procedures for legal persons.

  5. 2023

    Gaming regulator launched

    GCGRA was established and publicly launched as the federal commercial gaming regulator.

  6. 2025

    New federal AML law

    Federal Decree-Law No. 10 of 2025 introduced the current federal AML/CFT/CPF framework.

  7. 2025

    Gaming enters DNFBP perimeter

    Cabinet Resolution No. 134 of 2025 expressly addressed commercial gaming operators and the AED 11,000 threshold.

  8. 2025

    Commercial Gaming Policy Paper

    GCGRA and the national AML/CFT policy structure published sector risks and recommended controls.

  9. 2026

    Operational implementation

    Official regulator materials continue to develop financial-crime-prevention expectations for the licensed sector.

The AED 11,000 Gaming Threshold

Cabinet Resolution No. 134 of 2025 places a commercial gaming operator in the DNFBP category when it carries out:

  • one financial transaction of AED 11,000 or more; or
  • several financial transactions that appear to be linked and together reach that level.

Operators should therefore avoid controls that look only at individual payments. A player could fund an account in several smaller amounts, use different payment methods, or deposit and withdraw across a short period. The operating model needs aggregation logic capable of detecting apparently linked transactions.

Is Every Movement of Gaming Chips a Financial Transaction?

No. The executive regulation says that a transaction solely involving gaming chips or gaming instruments is not a financial transaction for this specific perimeter rule.

The word solely is important. An internal chip-only movement is different from a cash buy-in, account funding, wallet load, payout, redemption, bank transfer, or withdrawal. Operators should document their transaction taxonomy and obtain legal advice for ambiguous product flows rather than treating the chip exception as a broad exemption.

Does the Threshold Replace Onboarding CDD?

No. The AED 11,000 provision defines when a commercial gaming operator falls within the DNFBP perimeter. It should not be read as permission to ignore other CDD triggers below that amount.

Under the wider executive regulation, CDD is relevant when a business relationship begins, when money-laundering or terrorist-financing suspicion arises, and when the operator doubts the accuracy or adequacy of previously obtained customer information. The operator must apply the framework across the relationship, not only when a single payment crosses the gaming threshold.

Player Due Diligence for UAE Gaming Operators

A practical player-due-diligence workflow should answer four questions:

  1. Who is the player? Verify identity using reliable, independent information and retain the evidence used.
  2. Who else is involved? Identify representatives, beneficial owners, payment parties, or other connected persons where the relationship or transaction requires it.
  3. What is the risk? Assess geography, occupation, products, payment methods, expected activity, PEP exposure, sanctions risk, and other relevant factors.
  4. Does actual activity make sense? Compare deposits, gaming behaviour, transfers, and withdrawals with the expected purpose and risk profile of the relationship.

CDD should not become a one-time identity check. Information must remain adequate and current, and higher-risk players require deeper review.

Enhanced Due Diligence and High-Risk Players

Enhanced due diligence (EDD) should be proportionate to the risk identified. Depending on the circumstances, it may include:

  • obtaining more information about the player and the intended relationship;
  • establishing source of funds or source of wealth;
  • identifying third-party funding or unusual payment arrangements;
  • reviewing the purpose and background of complex or unusually large activity;
  • applying senior-management approval where required;
  • increasing the frequency or depth of ongoing review; and
  • documenting why the operator accepted, restricted, or ended the relationship.

Politically exposed persons require particular attention. A PEP match is not automatically evidence of wrongdoing, but it changes the risk analysis. Operators should distinguish the player from false positives, identify the nature of the public function, consider family members and close associates where applicable, and apply the measures required by the UAE framework.

Enterprise Risk Assessment and Gaming Red Flags

Article 5 of the executive regulation requires a documented assessment of money-laundering, terrorist-financing, and proliferation-financing risk. For a commercial gaming operator, that assessment should cover customers, countries, products, services, transactions, delivery channels, and new technologies. It should be approved through the operator's governance process, kept current, and translated into controls rather than left as a descriptive report.

The 2025 Commercial Gaming Policy Paper identifies sector concerns that can inform—but do not replace—the operator's own assessment. Relevant scenarios include:

  • anonymous or insufficiently identified activity;
  • player accounts being used to store or move value rather than for genuine play;
  • third-party deposits, payouts, or funding arrangements;
  • customers or transactions connected to foreign or higher-risk jurisdictions;
  • multiple payment methods used without a clear explanation;
  • misuse of chips, tickets, wallets, or other gaming value instruments;
  • high-value players and VIP arrangements;
  • employee collusion or control circumvention; and
  • cash-intensive activity that obscures source or ownership of funds.

These indicators do not prove criminal activity. They should influence customer-risk scoring, transaction-monitoring scenarios, EDD triggers, investigation priorities, and training.

High-Risk Countries, Third Parties, and New Technology

Three cross-sector rules are especially relevant to online and technology-intensive gaming models.

High-Risk Countries

Article 23 of Cabinet Resolution No. 134 of 2025 requires proportionate EDD for relationships or transactions involving countries identified as high risk or as having deficient AML/CFT/CPF systems. Operators must also apply countermeasures or other measures required by the supervisory authority or National Committee.

Country risk should therefore influence player acceptance, source-of-funds review, payment corridors, withdrawal controls, monitoring intensity, and senior escalation. A country flag should not be used as a substitute for evaluating the customer and transaction facts.

Reliance on Third Parties

An operator may be able to rely on a qualifying third party for specified CDD measures under Article 20, subject to its conditions. The operator nevertheless remains responsible for the accuracy and adequacy of those measures and must be able to obtain the underlying CDD information and documents without delay.

Outsourcing software, verification, or review work is not the same as transferring regulatory accountability. Contracts, oversight, data access, service continuity, audit rights, and exit planning should reflect that distinction.

New Products and Technologies

Article 24 requires risk assessment before launching or using new products, business practices, delivery mechanisms, or new and developing technologies. For gaming operators, this may include mobile onboarding, remote play, digital wallets, cashless gaming, new payment methods, automated decisions, and material changes to player-account functionality.

The assessment should happen before launch, identify ML/TF/PF exposure, define mitigating controls, and leave evidence of approval and testing. Technical measures discussed in the policy paper—such as security standards or vulnerability testing—should be treated as policy recommendations unless made binding through legislation, GCGRA rules, technical standards, or licence conditions.

Sanctions Screening and Freezing Without Delay

Commercial gaming operators must integrate targeted financial sanctions into player and payment workflows. The UAE framework covers the UAE Local Terrorist List and relevant UN Security Council sanctions lists.

The UAE Ministry of Economy and Tourism's targeted-financial-sanctions guidance describes core operational expectations, including:

  • screening customers and relevant related parties;
  • taking freezing measures without delay and without prior notice following a confirmed match;
  • reporting matches and the action taken through the applicable channel;
  • maintaining effective internal controls; and
  • preventing tipping off.

A screening alert is not always a confirmed sanctions match. The review should compare available identifiers such as full name, aliases, date of birth, nationality, address, identification documents, and entity-registration data. The evidence should show how the operator reached its conclusion.

Screening outcomeOperational response
False positiveRecord the identifiers compared, the reason for clearance, the reviewer, and the source evidence.
Possible matchEscalate promptly, obtain further identifying information where lawful, and apply the operator's hold or restriction procedure.
Confirmed matchFollow the applicable freeze-without-delay and reporting process without notifying the player in advance.
Suspicious activity without a list matchAssess whether an STR/SAR must be submitted to the UAE FIU. A sanctions hit is not required for suspicion to exist.

Ongoing Monitoring After Onboarding

Initial screening captures one moment. Risk can change when a player becomes a PEP, appears on a sanctions list, is linked to credible adverse information, changes payment behaviour, or begins using new counterparties.

An effective monitoring model combines two distinct controls:

  • ongoing customer monitoring, which rechecks the player and relevant related parties for new sanctions, PEP, wanted-person, or other risk information; and
  • transaction monitoring, which evaluates activity and behaviour for unusual patterns.

These controls complement each other but are not interchangeable. Name screening alone will not detect every suspicious deposit or withdrawal pattern. Behavioural transaction monitoring alone will not identify a newly designated person unless it is connected to current list data.

Suspicious Transaction Reporting

Suspicion may arise from the player profile, the source or destination of funds, linked transactions, rapid movement of value, third-party payments, inconsistent explanations, sanctions-evasion indicators, or activity without an apparent lawful or economic purpose.

The UAE FIU is the recipient of suspicious transaction reports. Operators should establish an internal escalation route that allows the compliance officer to:

  1. receive and review internal alerts;
  2. obtain the relevant player, payment, and gaming evidence;
  3. decide whether external reporting is required;
  4. file through the FIU's designated electronic system without delay where the legal test is met;
  5. prevent tipping off; and
  6. preserve the analysis and reporting record.

Submitting a report does not replace any separate obligation to freeze or report a confirmed targeted-financial-sanctions match.

Compliance Officer, Controls, and Governance

Cabinet Resolution No. 134 of 2025 requires a management-level Compliance Officer with suitable independence, competence, and experience. The role includes monitoring compliance, reviewing unusual or suspicious activity, considering reports to the FIU, assessing internal systems, and reporting to senior management.

An operator's governance framework should clearly allocate responsibility for:

  • enterprise and product risk assessments;
  • player acceptance and higher-risk approvals;
  • sanctions and PEP alert review;
  • transaction-monitoring investigations;
  • STR/SAR and sanctions reporting;
  • staff training;
  • independent testing or audit; and
  • remediation of control failures.

Using the title MLRO may be appropriate in an operator's structure or licence documentation, but the executive regulation's binding terminology is Compliance Officer. Internal documentation should align with the exact rules and licence conditions that apply to the operator.

Beneficial Ownership of the Operator

Player CDD is only one side of beneficial-ownership control. A UAE legal person operating a gaming business must also consider Cabinet Resolution No. 109 of 2023, including the obligation to maintain accurate real-beneficiary and partner or shareholder information and update the relevant registrar when required.

Cabinet Resolution No. 132 of 2023 establishes administrative consequences for violations of those real-beneficiary procedures. Corporate ownership records should therefore be managed as a substantive transparency control, not merely a licensing formality.

UAE Commercial Gaming AML Workflow

The following model connects licensing scope, transaction classification, player due diligence, screening, escalation, and evidence retention. Operators should adapt the decision points to their products, risk assessment, GCGRA requirements, and licence conditions.

Rendering diagram...
A practical UAE commercial gaming AML flow from licensing and transaction classification through CDD, sanctions decisions, FIU escalation, and record retention.

Five-Year Recordkeeping

The executive regulation establishes a recordkeeping period of at least five years for relevant records. Depending on the event and legal provision, the retention period may run from the transaction, the end of the business relationship, the completion of an inspection, or the final judgment in a case.

The evidence set should include:

  • identity and CDD documents;
  • beneficial-ownership or connected-party information where relevant;
  • transactions and linked-transaction analysis;
  • screening inputs, sources, timestamps, candidate results, and decisions;
  • enhanced-due-diligence and source-of-funds evidence;
  • internal alerts and investigation notes;
  • reporting decisions and submitted reports; and
  • approvals, restrictions, freezes, and relationship-exit decisions.

Administrative Penalties

Article 17 of Federal Decree-Law No. 10 of 2025 allows the supervisory authority to impose administrative measures for breaches of the law, its executive regulation, or related decisions. These include:

  • a warning;
  • a fine from AED 10,000 to AED 5,000,000 for each violation;
  • restricting or suspending responsible managers or board members;
  • prohibiting, suspending, or restricting the relevant activity;
  • requiring remediation reporting; and
  • revoking the licence.

The authority may increase an administrative fine for a repeated violation within the specified period and may publish imposed penalties. Separate criminal penalties may apply to criminal conduct such as money laundering, terrorist financing, proliferation financing, tipping off, or other offences. Operators should avoid presenting the AED 5 million administrative maximum as the maximum exposure for every possible case.

UAE Gaming AML Compliance Checklist

  • Confirm that every commercial gaming activity, product, channel, and relevant supplier arrangement is within the applicable GCGRA licensing framework.
  • Maintain a documented enterprise risk assessment covering ML, TF, and PF risks across customers, countries, products, transactions, channels, and technologies.
  • Map cash, card, bank-transfer, wallet, chip, payout, redemption, and withdrawal events.
  • Define which events are financial transactions and how apparently linked transactions are aggregated against AED 11,000.
  • Apply CDD at onboarding and whenever suspicion or doubts about existing information arise.
  • Screen players and relevant related parties against the UAE Local Terrorist List and applicable UN lists.
  • Add PEP and adverse-media screening to support the wider risk assessment and EDD workflow.
  • Separate possible matches, confirmed sanctions matches, PEP exposure, and suspicious-activity decisions.
  • Monitor customer risk after onboarding and refresh information on defined or event-driven cycles.
  • Connect player risk, transaction-monitoring alerts, screening results, and case decisions.
  • Assess new products, payment methods, delivery channels, and technologies before launch.
  • Where CDD work involves third parties or outsourced providers, preserve immediate data access, oversight, audit rights, and internal accountability.
  • Test freeze-without-delay, sanctions-reporting, and FIU-reporting procedures before they are needed.
  • Appoint a suitably senior and independent compliance officer.
  • Keep the operator's own real-beneficiary and shareholder information accurate and current where the UAE beneficial-owner regime applies.
  • Retain sufficient evidence for at least the legally required period.

How Checklynx Supports Gaming Compliance Teams

Checklynx supports the screening and decision layer of a gaming operator's AML program. It can help teams:

  • screen players and related parties for sanctions, PEP/RCA, wanted-person, and adverse-media exposure;
  • monitor customers for relevant changes after onboarding;
  • screen transaction parties without confusing this with behavioural transaction monitoring;
  • assess customer risk through configurable CRA workflows;
  • review UBO and related-party structures;
  • run batch screening for existing player populations;
  • manage alerts and cases with source-backed evidence; and
  • preserve a reusable decision and audit trail.

Checklynx does not replace the operator's legal analysis, gaming licence controls, behavioural transaction-monitoring system, or responsibility to decide and submit regulatory reports. It provides native AML screening and workflow capabilities that can connect to the operator's wider compliance architecture.

Frequently Asked Questions

Are UAE commercial gaming operators treated as DNFBPs?

Cabinet Resolution No. 134 of 2025 includes commercial gaming operators in the DNFBP perimeter when they conduct a single financial transaction, or linked financial transactions, of AED 11,000 or more.

What is the UAE gaming AML threshold?

The gaming-specific perimeter threshold is AED 11,000 for one financial transaction or several apparently linked financial transactions. It is not the only reason to perform CDD or investigate suspicious activity.

Do gaming chips count toward AED 11,000?

A transaction solely involving gaming chips or gaming instruments is excluded from the definition of a financial transaction for this perimeter provision. Funding, cashing out, payouts, withdrawals, and other value movements should not automatically be treated as chip-only activity.

Which sanctions lists should UAE gaming operators screen?

The UAE targeted-financial-sanctions baseline includes the UAE Local Terrorist List and relevant UN Security Council sanctions lists. Other lists may be appropriate because of the operator's licences, currencies, counterparties, geographic exposure, contracts, or group policy.

Is the 2025 Commercial Gaming Policy Paper binding law?

The paper is an official and important statement of sector risks, recommended controls, and policy direction. It should not be described as if every recommendation were independently binding unless the same requirement appears in legislation, GCGRA rules, technical standards, or the operator's licence conditions.

Does sanctions screening replace transaction monitoring?

No. Sanctions and PEP screening identifies list or profile exposure. Transaction monitoring looks for unusual activity and behaviour. A defensible AML program needs the relevant controls to exchange information without treating them as the same process.

Final Takeaway

UAE gaming AML compliance is not built around one threshold or one screening event. The AED 11,000 rule defines an important gaming-specific perimeter, while the broader operating model requires player due diligence, linked-transaction controls, sanctions implementation, ongoing monitoring, suspicious transaction reporting, governance, and evidence.

For implementation, start with the binding federal framework and applicable GCGRA rules or licence conditions. Use official policy recommendations to strengthen the control design, but label them accurately. The result should be a joined-up process in which player identity, risk, transactions, screening alerts, investigations, and regulatory decisions can be reconstructed from one defensible evidence trail.

Official Sources

The following primary UAE sources were reviewed for this guide. Legislation, regulatory materials, and licence conditions may change, so operators should confirm the latest applicable version with the relevant authority and qualified UAE counsel.

Continue reading: AML in the gaming industry and AML screening for iGaming and gambling operators.

Share
knowledge base

Footer

UAE AML Rules for Commercial Gaming Operators