How to Become an MLRO in the UAE: Requirements, Experience and Approval 

22.09.26 09:05 AM By NIYEAHMA

In short. To become an MLRO in the UAE you need three things: seniority, independence, and demonstrated competence. Federal law requires the appointment and names none of those as a certificate or a number of years. Your supervisor adds their own expectations on top, and those differ by regulator. The route runs through governance work, not through more casework. 

Most pages on this subject tell you to get a certification and wait. That is not how the appointment works, and it is not what a board or supervisor assesses. 


This article sets out what UAE law actually requires, what supervisors add, what employers look for, and what disqualifies a candidate. I have marked each of those four categories explicitly, because conflating them is the single most common error in AML career advice. 


One vocabulary point first, because it affects how you read every job advert in the market. 

What is an MLRO? MLRO meaning, and why UAE job adverts often say Compliance Officer

Key point: in most UAE firms the Compliance Officer and the MLRO are the same person doing the same job. The Executive Regulations use Compliance Officer. The market says MLRO. 

An MLRO is a Money Laundering Reporting Officer. The role is the individual inside a regulated business who is accountable for the anti-money laundering programme and who decides whether a suspicion becomes a report to the authorities. 


UAE federal law does not use the term. Cabinet Resolution No. 134 of 2025, the Executive Regulations of the AML law, uses Compliance Officer. Financial free zone rulebooks and international firms use MLRO. Some larger institutions split the two, giving the Compliance Officer the broader regulatory remit and the MLRO the reporting decision specifically. 


The practical consequence for your job search is simple. Search both terms. Read the duties rather than the title, and if a description gives one person the reporting decision and another person the wider compliance function, ask in the interview which one you would be. 

MLRO requirements in the UAE at a glance

Key point: the commonest mistake is treating a supervisor's expectation as a federal legal requirement. They are different things with different consequences. 

The table below separates the four sources of MLRO requirements in the UAE. Read it top to bottom, because they are cumulative: federal law applies to everyone, your supervisor adds to it, your employer adds to that, and the market adds preferences that are not requirements at all. When somebody tells you that a particular credential is mandatory, the first question is always which row of this table they are quoting from. 

Source What it sets Where it is written Can it compel you? 
Federal law The obligation to appoint, at management level, with independence and appropriate competence and experience Federal Decree-Law No. 10 of 2025; Article 22 of the Executive Regulations Yes, on every regulated business in the UAE 
Your supervisor Approval or notification process, fitness and propriety, sometimes a stated experience period or named credentials The relevant supervisor's rulebook or guidance Yes, but only for firms it supervises 
Your employer Sector experience, language, seniority, systems knowledge, reporting line The job description and the internal governance framework Only as a condition of that job 
The market Preferred certifications, preferred backgrounds, typical tenure Job adverts and recruiter briefs No. This is preference, not requirement 

What UAE law actually requires of an MLRO

Key point: the law requires the appointment and three qualities. It names no certificate and no minimum period of service. 

The governing provision is Article 22 of the Executive Regulations. It requires financial institutions, designated non-financial businesses and professions, and virtual asset service providers to appoint a Compliance Officer at management level and under their responsibility, who shall have independence in decision-making and possess appropriate competence and experience. 


Three requirements sit in that sentence, and each one is testable in an interview. 

  1. Management level. The appointment has to carry enough seniority to be heard. A reporting officer buried three levels below the decision-makers cannot do the job, and a supervisor will see that in the organisation chart before it sees anything in your CV. 

  1. Independence in decision-making. You must be able to reach a reporting decision without the business overruling you. This is the requirement most often compromised in practice, usually by a reporting line that runs into the revenue side of the business. 

  1. Appropriate competence and experience. Note the word appropriate. It scales with the firm. What is appropriate for a single-branch corporate services provider is not what is appropriate for a bank, and the law leaves that judgement to the appointment rather than fixing a number. 

That is the whole federal requirement for the person. Everything else you have read about mandatory years and mandatory credentials comes from a supervisor, an employer or a recruiter, and should be checked against whichever of those it actually is. 

MLRO responsibilities in the UAE: what the job is once you have it

Key point: four of the five statutory duties are governance duties. Only one is casework. Your preparation should follow the same ratio. 

Article 22 of the Executive Regulations lists five duties. I have set them out below with what each one means on a Tuesday morning, because the statutory language is compact and the daily reality is not. 


The ratio is worth pausing on before you read them. One duty is about cases. Four are about systems, reporting, training and dealing with authorities. Most people preparing for this role spend their time getting better at cases, because that is what they already do and it is the part that gets measured. That is the wrong emphasis, and it is why capable senior analysts fail reporting appointment interviews. 

MLRO duty 1: monitoring transactions related to the crime

This is the casework duty. In practice it means owning the transaction monitoring arrangement rather than clearing alerts personally. You are accountable for whether the monitoring is capable of finding what it is supposed to find, which is a different question from whether today's queue is clear. Article 17 of the same Resolution requires regulated businesses to establish indicators through which they can identify suspicion, and to update those indicators on an ongoing basis as laundering methods change. 

MLRO duty 2: reviewing suspicious transaction data and deciding whether to report

This is the duty that defines the role. Article 22 requires the Compliance Officer to review records, receive, examine and assess suspicious transaction data, and decide whether to notify the Financial Intelligence Unit or to retain the matter stating the reasons therefor, in full confidentiality. 


Read the second half of that clause carefully, because it is the part candidates miss. Deciding not to report is a permitted decision, but only if you state your reasons. An undocumented decision not to report is the single most common finding against a reporting officer, and it is entirely avoidable. 

MLRO duty 3: reviewing the internal systems and reporting to senior management

Article 22 requires you to review the internal anti-money laundering, counter-terrorist financing and counter-proliferation-financing systems and procedures, assess whether they are consistent with the law and the Executive Regulations, evaluate the firm's level of compliance, propose updates, and prepare periodic reports submitted directly to senior management, with a copy to the supervisory authority on request, including senior management's observations and decisions. 


Directly to senior management is a deliberate phrase. It establishes a reporting line that the business cannot filter. If you are interviewing for the role, ask how that reporting line works in practice, because a firm that routes your report through the chief executive's office for editing has already compromised the appointment.

MLRO duty 4: developing and documenting AML training 

The duty covers developing, implementing and documenting ongoing programmes and training plans for employees on the crime and how to combat it. Documented is the operative word. Training that happened but was not recorded, tested and tracked will be treated as training that did not happen. 


In practice this is a bigger job than it sounds, because the training has to differ by role. A relationship manager needs to recognise a red flag and know who to tell. An onboarding analyst needs the due diligence detail. A board member needs enough to ask a useful question. One deck delivered to everybody satisfies nobody, and it is the commonest weakness in a training programme. 


Keep the evidence as you go rather than assembling it when somebody asks. Who attended, what material was used, on what date, and some test of whether anything was retained. That file is one of the first things an inspection will want to see.

MLRO duty 5: cooperating with the supervisory authority and the Financial Intelligence Unit

You are the point of contact. That means providing data on request and enabling assigned personnel to access the records and documents they need. Candidates who have never handled a regulator request underestimate how much of the job this becomes during an inspection cycle. 


The skill here is not technical. It is judgement about scope and tone. Answer what was asked, completely and on time, without volunteering material that invites three more questions and without appearing to hold anything back. Getting that balance wrong in either direction is how a routine information request becomes a long engagement. 


The other half of it is internal. You will need documents from people who do not report to you and who have their own deadlines. A reporting officer who has not built those relationships before the request arrives will spend the deadline chasing rather than reviewing.

What experience does a UAE MLRO need?

Key point: federal law sets no number of years. Some supervisors do. Do not quote one as if it applied to everyone. 

This is the question I am asked most, and the honest answer is uncomfortable. UAE federal law does not state a period. Article 22 of the Executive Regulations calls for appropriate competence and experience and leaves the assessment to the appointer and the supervisor. 


Some individual supervisors do publish thresholds, and where they do, those thresholds bind the firms they supervise and nobody else. A period stated in one supervisor's rulebook is not a UAE-wide requirement, and treating it as one has sent more than one candidate down a route that did not apply to them. The regulator comparison page sets out who publishes what, checked against the live rulebooks. 


What holds regardless of supervisor is the composition of the experience rather than its length. An appointment panel is looking for four things, and a candidate with three years covering all four is stronger than a candidate with eight years covering one. 

  1. Reporting decisions you personally made, including at least one where the outcome was not to report and you documented why. 

  1. Framework work: the risk assessment, a policy you wrote or materially revised, a control you tested. 

  1. An external interaction: an audit, an inspection, a supervisor request, or a correspondent bank's due diligence questionnaire. 

  1. Governance exposure: a paper you took to senior management or the board, and what happened when they pushed back. 

Does an MLRO need regulatory approval in the UAE? 

Key point: it depends entirely on who supervises your firm. There is no single answer. 

Whether your appointment needs prior regulatory approval depends on the supervisor, not on the role. Financial free zone regimes generally operate an approved person or authorised individual process, in which the individual is assessed before taking up the position. Mainland supervision of designated non-financial businesses and professions generally does not work that way, though notification and registration obligations still apply. 


The practical career consequence is one most people learn too late. An approval granted under one regime does not transfer to another. If you hold an approved position in a financial free zone and move to a mainland firm, or the reverse, you go through the receiving supervisor's process from the beginning. Plan employer moves with that in mind. 


The regulator comparison page sets out the position for each UAE supervisor side by side, with the date each rulebook was checked. 

Is a certification such as CAMS mandatory to become an MLRO in the UAE?

Key point: not under federal law. Some supervisors and many employers ask for one. That is a different sentence, and it matters. 

Federal Decree-Law No. 10 of 2025 and the Executive Regulations describe the compliance function without naming any credential. Article 22 asks for competence and experience, not for a certificate. 


Individual supervisors take different approaches. Some name credentials in their rulebooks as one route to demonstrating competence, often alongside an alternative experience route. Employers frequently ask for a certification in job descriptions, which reflects hiring preference and the difficulty of assessing competence from a CV, not a legal obligation. 


My own position, and I hold CAMS, is that a certification is worth having and worth nothing on its own. It gets your application read. It does not answer the questions the panel will ask you. If you are choosing between credentials, the certification comparison guide is the right place to start, and it covers the honest question of whether to certify at all

What disqualifies an MLRO candidate in the UAE

Key point: most failed appointments stem from independence or seniority, not knowledge. 

The reasons a candidate does not get appointed, or does not survive the appointment, fall into five categories. None of them is about how much AML you know. 

  1. A reporting line that compromises independence. If the person who can veto your reporting decision also owns the revenue relationship, the appointment does not satisfy the independence requirement in substance, no matter how the chart is drawn. 

  1. Insufficient seniority. Management level is a stated requirement. An officer who cannot get on the senior management agenda cannot perform the reporting duty in Article 22. 

  1. A conflicting second role. Holding the reporting appointment alongside a commercial or revenue-generating role creates a conflict over the very decisions the role exists to make. Some combinations are workable in a small firm, and some are not, and the test is whether the conflict bites on the reporting decision. 

  1. Insufficient availability. An officer covering several entities, or holding the role as a fraction of a wider job, may not be able to discharge the duties. Supervisors probe this. 

  1. Fitness and propriety concerns. They assess honesty, integrity, and reputation. So is a history of regulatory findings. 

If you are being offered a reporting appointment, test all five before you accept. The personal exposure sits with you, and a firm that will not fix a reporting line before you start will not fix it afterwards. 

MLRO interview questions: what I would ask a candidate

Key point: every one of these questions is about judgement under pressure, not recall. 

If I were on the panel, these are the three questions I would put to an MLRO candidate. All three are situations rather than topics, and in each case I already know what the rulebook says. What I am trying to find out is what the person would actually do at four o'clock on a Thursday, when the answer is not obvious and somebody senior wants a different one. 


These are the three questions I would ask. I have set out what a weak answer sounds like and what a strong one contains, because the difference is rarely about knowledge. 

Tell me about a time you decided not to report

A weak answer describes a case where the suspicion evaporated. A strong answer describes a case where it did not fully evaporate, explains the residual concern, states what was documented, and says what monitoring was put in place afterwards. The panel is testing whether you understand that not reporting is a decision requiring reasons, not an absence of a decision. 


Candidates who have genuinely held the role tend to answer this one slowly, because they choose which case to describe and strip the identifying detail out as they go. That hesitation is a good sign. An immediate, fluent, richly detailed answer usually means the person is about to tell you something they should not.

The chief executive tells you the client is important and the report will lose the account. What happens next?

A weak answer is defiant and abstract. A strong answer is procedural and calm. It explains what you would say in the room, what you would record, who else you would inform, and what you would do if the pressure continued. It also acknowledges that the reporting decision is yours and is not negotiable, without turning the conversation into a confrontation. The tipping-off prohibition is relevant here, and a strong candidate raises it unprompted. 

Your monitoring system has produced almost no alerts for a quarter. What do you do?

A weak answer treats this as good news. A strong answer treats it as a control failure until proven otherwise, and describes the checks: whether data feeds are complete, whether rules are still active after a system change, whether thresholds were altered, and whether the customer base has genuinely changed. Article 17 of the Executive Regulations requires indicators to be updated on an ongoing basis, and a silent system is the classic sign that they have not been. 

Would you report? An MLRO decision case

Key point: this is a labelled hypothetical. It describes no real person, customer, case or institution. 

A corporate customer of two years, in a legitimate trading business, begins receiving payments from three new counterparties in a jurisdiction it has never traded with. The amounts match its normal invoice sizes. The customer credibly explains that it has won a new distribution agreement. It provides the agreement. The agreement appears genuine. Your relationship manager is pleased. Your analyst has cleared the alerts. 


Then one of the three counterparties appears in an adverse media item that is four years old, unproven, and concerns a different corporate entity with a similar name. 


The instinct is to close it. The name is different, the item is old, the explanation is documented. That instinct is defensible and it may well be right. 


What makes it a reporting officer's decision rather than an analyst's is what you do about the residual uncertainty. Has anyone verified that the similar name is in fact a different entity, or has it been assumed? Does the distribution agreement explain the payment pattern, or merely coexist with it? If you clear it, what triggers a fresh look, and who owns that trigger? 


There is no single correct answer here, and anyone who tells you otherwise has not held the role. What is not defensible is a decision file that records the conclusion without the reasoning. Article 22 asks for reasons stated. That clause is your protection as much as it is your obligation. 

The realistic route from AML analyst to MLRO in the UAE

Key point: the gap is governance exposure, and analysts are rarely given it by default. 

Almost every UAE MLRO came up through analyst work. What separates the ones who made the jump is not more casework. It is four shifts: from executing tasks to owning outcomes, from applying rules to exercising judgement, from doing the work to assuring the work, and from operations into governance. 


A deputy appointment is the most reliable bridge, because it gives you delegated reporting decisions with a more experienced officer still accountable. If your firm has one, ask for it. If it does not, ask to draft a section of the enterprise-wide risk assessment, to run a control test, or to take one item to the management meeting yourself. 


The detailed roadmap, including realistic timing and the five things that stall people, is covered on the analyst to MLRO page.

MLRO readiness checklist: ten things to evidence before you apply

Key point: if you cannot evidence eight of these ten, you are preparing rather than ready. 

  1. I have made at least one reporting decision and documented the reasons, including a decision not to report. 

  1. I have written or materially revised an AML policy or procedure. 

  1. I have contributed to an enterprise-wide risk assessment. 

  1. I have designed or tested a control and acted on the result. 

  1. I have handled a request from a supervisor, an auditor, an inspector or a correspondent bank. 

  1. I have delivered AML training and can evidence that it was recorded and tested. 

  1. I have presented to senior management or a board and been challenged. 

  1. I have refused a business request on compliance grounds and kept the working relationship. 

  1. I can explain the reporting obligation and the tipping-off prohibition from the source instruments. 

  1. I can name my prospective firm's supervisor and describe its appointment process. 

How this article was researched and verified

Key point: every legal statement in this article is traced to a named article of a named instrument, read in its published text rather than summarised from secondary sources. 


Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025 were read directly in their published texts on 1 September 2026. Article 18 and Article 19 of the Decree-Law, and Articles 17, 19, 21 and 22 of the Executive Regulations, are described from those texts and nothing else. 


This article states no minimum number of years as a UAE-wide requirement, because the federal framework does not set one. Where individual supervisors publish thresholds, those are set out on the regulator comparison page with the date each rulebook was checked, rather than being generalised here. 


No certification is described as mandatory, because no federal instrument names one. Where supervisors reference credentials, that is a supervisor position and is treated as such. 


No approval timescale is quoted, because individual supervisors set approval processes and their duration, and they change. Confirm the current process with the supervisor for your firm before relying on any figure. 


The decision case, the three interview questions, the five disqualifiers and the readiness checklist are mine. They come from practice and assessing candidates, and they reflect professional judgement rather than regulatory requirements.

Build the framework skills a reporting appointment needs

Key point: the gap between senior analyst and reporting officer is framework work. 

If you are working toward a reporting appointment, the two capabilities tested hardest are the reporting decision and the framework behind it. Mastering Regulatory Reporting covers the suspicious activity and transaction report end to end, including the narrative that survives review. Setting the Right Compliance Framework covers the policies, procedures and controls that Article 21 of the Executive Regulations requires. Take them in that order, and Explore Courses for the full path. 

MLRO in the UAE: frequently asked questions

Key point: the recurring confusion in every question below is the same one. Federal law sets the appointment and three qualities; supervisors, employers and recruiters add everything else. 

An MLRO owns a regulated firm's anti-money laundering programme and holds the reporting decision. Cabinet Resolution No. 134 of 2025, Article 22 sets five duties: monitoring transactions related to the crime, reviewing and assessing suspicious transaction data and deciding whether to notify the Financial Intelligence Unit, reviewing the internal systems and reporting periodically to senior management, developing and documenting employee training, and cooperating with the supervisory authority and the Unit. Four of the five are governance duties rather than casework. 
Money Laundering Reporting Officer. It is the individual accountable for a regulated firm's anti-money laundering programme and for deciding whether a suspicion is reported to the authorities. UAE federal law uses the title Compliance Officer for the same function. 

Both, and expect the same roles under either label. Cabinet Resolution No. 134 of 2025 uses the title Compliance Officer, while financial free zone rulebooks and international firms tend to say MLRO. Filter on the duties in the advert rather than the title. Where a firm genuinely splits the two functions between two people, the page comparing the Compliance Officer, MLRO and BSA Officer roles sets out how the accountability divides. 

Federal law sets no number. Cabinet Resolution No. 134 of 2025, Article 22 requires appropriate competence and experience. Individual supervisors may publish their own thresholds, and where they do, those bind only the firms they supervise. Check the supervisor that applies to your firm rather than assuming a UAE-wide figure. 

There is no prescribed qualification. Cabinet Resolution No. 134 of 2025, Article 22 sets three tests instead: the appointment must sit at management level, the officer must have independence in decision-making, and the officer must possess appropriate competence and experience. Competence is assessed on the appointment rather than certified in advance, so what qualifies you is a documented record of reporting decisions, framework work, external interactions and governance exposure. 

Not under federal law. Neither Federal Decree-Law No. 10 of 2025 nor its Executive Regulations name any credential. Some supervisors reference certifications as one route to demonstrating competence, and many employers ask for one as a hiring preference. Those are different from a legal requirement. 

It depends on the supervisor. Financial free zone regimes generally operate an approved person or authorised individual process. Mainland supervision of designated non-financial businesses and professions generally does not, although notification and registration obligations apply. An approval under one regime does not transfer to another. 

The Financial Intelligence Unit. Federal Decree-Law No. 10 of 2025, Article 18(1) requires notification without delay and directly, through the electronic system designated by the Unit or another approved means, with a detailed report containing all available data on the transaction and the relevant parties. 

Yes, and the law contemplates it. Cabinet Resolution No. 134 of 2025, Article 22 requires the officer to decide whether to notify the Unit or to retain the matter stating the reasons therefor. The decision not to report is permitted. The undocumented decision not to report is not. 

No. Cabinet Resolution No. 134 of 2025, Article 19 prohibits disclosing, directly or indirectly, to the customer or any other person that a suspicious transaction report has been or is about to be submitted, or that an investigation is being conducted. Limited information sharing within a financial group is separately provided for. 

Only where the second role bites on the reporting decision. Being responsible for revenue and for reporting on that revenue does not satisfy the independence requirement in substance, however the organisation chart is drawn. Small firms combine roles routinely and the test is always the same: can you reach a reporting decision that damages the other role you hold? 

Residency requirements are set by individual supervisors rather than by the federal framework, and at least one financial free zone regime imposes one with a narrow exception. Check the rulebook of the supervisor that applies to your firm. 

Five things: that the reporting line does not run through the revenue side of the business, that the role carries genuine management-level seniority, that any second role you hold does not conflict on the reporting decision, that you have the time to discharge the duties, and that the firm will resource the function. Personal accountability is covered separately on the page comparing the Compliance Officer, MLRO, and BSA Officer roles. 

Every regulated business does. Cabinet Resolution No. 134 of 2025, Article 22 applies the appointment obligation to financial institutions, to designated non-financial businesses and professions, and to virtual asset service providers alike. Size does not exempt a firm from the appointment; it only changes what appropriate competence and experience look like. 

Yes. Cabinet Resolution No. 134 of 2025, Article 22 requires the Compliance Officer to be appointed at management level and under the firm's responsibility. This is a substance test rather than a title test: an officer who cannot reach senior management directly cannot perform the periodic reporting duty the same Article imposes. 

A deputy MLRO exercises delegated reporting decisions while a more senior appointed officer remains accountable. The federal framework does not require the position, so whether your firm has one is a governance choice and, in some regimes, a supervisory expectation. It is the most reliable bridge out of analyst work, because it gives you real reporting decisions and real governance exposure without the personal accountability of the full appointment. 

Get governance exposure early and take a deputy appointment when one is available. Smaller firms and designated non-financial businesses often give you the whole programme sooner than a large bank will, which is why several strong UAE reporting officers came through those sectors rather than through banking. 

About the author

Pathik Shah is the founder of ProAML Training. He holds CAMS and is a Fellow Chartered Accountant (FCA) and a Certified Information Systems Auditor (CISA), and he holds the DISA and FAFD qualifications from the Institute of Chartered 
Accountants of India. He has spent more than 28 years in governance, risk and compliance, and advises regulated 
firms across the UAE and the GCC on AML and CFT programmes. He writes about the difference between knowing the 
rules and doing the work.

NIYEAHMA