Regulatory & Compliance · UAE

Initial AML-CFT-CPF Policy & Procedure Development in the UAE

Every regulated UAE business needs board-approved AML, CFT and CPF policies and procedures matched to its actual risks, and under the framework in force since late 2025, a template citing the repealed law is a liability, not a shortcut. Cressford Chartered Accountants drafts the initial policy set from the ground up: risk assessment first, then the policies, procedures, registers and forms the team will genuinely use, aligned to Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025.

✓ Built on the 2025 framework
✓ Drafted for daily use, not the shelf
✓ Fixed fee, agreed in advance
Prefer to speak with us? Call +971 54 389 0111
Chartered Accountants · Dubai · UAE

Get your policy set drafted

Describe the business and a scoped quotation for the full policy set follows within one working day. Your details remain confidential.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

No obligation. Your details remain confidential.

Why it matters

Why the initial policy set decides everything after it

The policies and procedures are the constitution of the AML programme: every customer file, screening decision, report and training session that follows is measured against them. Done properly at the start, they make the rest of compliance routine. Done as a purchased template, they fail in three predictable ways: they cite the repealed 2018 law, they describe risks the business does not have while missing the ones it does, and the team ignores them because they were never written to be used. All three are read by supervisors as evidence of non-compliance, and template-only documentation is a recurring feature of published penalties.

The CPF element matters too. The 2025 framework expressly extends to Countering Proliferation Financing, alongside money laundering and terrorist financing, so a policy set that stops at AML-CFT is incomplete on its face.

Deliverables

What the initial policy set includes

Enterprise-wide risk assessment (EWRA) documenting the business's real ML, TF and PF exposure, the foundation the policies are built on
The AML-CFT-CPF policy, board-approved and aligned clause by clause to the 2025 framework
Operating procedures: customer onboarding, CDD and EDD, UBO identification, PEP handling and ongoing monitoring
Targeted Financial Sanctions procedure: screening, freeze-without-delay mechanics and reporting on a match
Internal STR escalation and goAML reporting workflow, with the no-tipping-off rule built in
Registers, checklists and client-facing forms the team uses daily, not annexes for the shelf
Governance matrix: the compliance officer's mandate, management responsibilities and reporting lines
Record-keeping and retention schedule meeting the five-year statutory minimum
The process

How the policy set is built

1
Understand the business
Clients, products, channels and geography are mapped; the policies must describe this business, not a generic one.
2
Assess the risk
The EWRA is written and calibrated, the document every later control traces back to.
3
Draft the set
Policy, procedures, registers and forms are drafted in plain, usable language, aligned to the 2025 framework.
4
Approve and embed
Management reviews and the board approves; the team is walked through what changes in their daily work, with training available as the natural next step.
5
Keep it current
An annual review cycle is set so the documents track the law and the business as both evolve.
Why Cressford Chartered Accountants

Why businesses have Cressford Chartered Accountants draft the set

Written to survive inspection

As registered auditors, the firm knows exactly how documents are examined, and drafts them to hold up under that examination.

Current on the 2025 framework

Every reference is to FDL 10/2025 and Cabinet Resolution 134/2025, including the CPF obligations older templates omit entirely.

Usable by real teams

Procedures are written for the people who follow them daily, because a policy nobody uses is a finding waiting to be made.

Fixed fee, Dubai-based

The full set at a fixed fee agreed in advance. Office 2514, DAMAC Smart Heights, Barsha Heights (Tecom), Dubai.

FAQ

Policy development questions, answered

What does CPF stand for?

Countering Proliferation Financing: preventing funds from supporting the proliferation of weapons of mass destruction. The 2025 UAE framework expressly covers it alongside money laundering and terrorist financing, so complete policy sets are AML-CFT-CPF, not AML-CFT alone.

Is a written AML policy legally required?

Yes. Regulated businesses must maintain internal policies, controls and procedures proportionate to their risks, approved by senior management, and produce them to the supervisor on request.

Why not use a template?

Because supervisors read them instantly: wrong law cited, risks that do not match the business, procedures nobody follows. Template-only documentation appears repeatedly in published enforcement, and the fine dwarfs the drafting fee saved.

Does the work start with the risk assessment?

Yes, deliberately. The law requires controls proportionate to the business's risks, so the EWRA is written first and every policy clause traces back to it, which is also the logic an inspector applies.

How long does the initial set take?

Typically two to four weeks depending on the complexity of the business and how quickly information flows, with the timeline fixed at scoping.

What happens after the documents are delivered?

Board approval, a team walkthrough, and an annual review cycle. Training and inspection-readiness support follow naturally where wanted, from the same team that drafted the set.

A policy set that actually protects you

Risk-based, board-ready and written for daily use, at a fixed fee agreed in advance.