anti-money-laundering-compliance

By July 25th, 2026ISO Audit And Certificate12 min read

Anti-Money Laundering Compliance in the GCC: Regulations and Requirements

Anti-money laundering (AML) compliance in the Gulf Cooperation Council (GCC) region is governed by a combination of national laws, central bank regulations and sector-specific guidelines. Each member state has established a legal framework aligned with the Financial Action Task Force (FATF) recommendations, covering customer due diligence (CDD), beneficial ownership registers, suspicious transaction reporting and the appointment of AML compliance officers. This guide provides a comprehensive overview of AML regulations and requirements across Bahrain, Saudi Arabia and the UAE.

Published: 25 July 2026 | Last updated: 25 July 2026 | Author: Mustafa Hasan, Lead Auditor | Reviewed by: Bitrixme Compliance Team

Key Takeaways

  • Bahrain’s AML regime is governed by the Central Bank of Bahrain (CBB) Rulebook and Law No. 4 of 2001, with the CBB and the Financial Intelligence Directorate as the key supervisory authorities.
  • Saudi Arabia’s AML framework is enforced by the Capital Market Authority (CMA) and the Saudi Central Bank (SAMA), supported by the Financial Intelligence Unit (FIU).
  • The UAE Central Bank regulates AML compliance for financial institutions, while the Financial Intelligence Unit (FIU) handles suspicious transaction reporting.
  • All three jurisdictions require comprehensive Know Your Customer (KYC) procedures, risk-based customer due diligence and the appointment of a designated AML compliance officer.
  • Penalties for non-compliance include substantial fines, imprisonment and revocation of operating licences.

Overview of AML Regulation in the GCC

The GCC states have progressively strengthened their AML frameworks in response to FATF evaluations and evolving international standards. All member states are members of the Middle East and North Africa Financial Action Task Force (MENAFATF), a FATF-style regional body. The legal framework in each country typically consists of:

  • A primary AML/CFT law that criminalises money laundering and terrorist financing.
  • Central bank or capital market authority regulations specifying compliance requirements for regulated entities.
  • Sector-specific guidelines for financial institutions, designated non-financial businesses and professions (DNFBPs) and virtual asset service providers (VASPs).
  • An FIU responsible for receiving, analysing and disseminating suspicious transaction reports (STRs).

Bahrain AML Regulations

Bahrain’s AML framework is primarily governed by the Central Bank of Bahrain (CBB) Rulebook (Volume 1 for conventional banks, Volume 2 for Islamic financial institutions), the Anti-Money Laundering Law (Law No. 4 of 2001, as amended) and the Penal Code. The CBB and the Financial Intelligence Directorate (FID) share supervisory responsibility.

Key Requirements under Bahrain AML Law

  • Customer Due Diligence (CDD): Financial institutions must conduct CDD when establishing a business relationship, when carrying out occasional transactions exceeding BHD 6,000, when there is a suspicion of money laundering or when there are doubts about previously obtained customer identification data.
  • Enhanced Due Diligence (EDD): EDD is required for high-risk customers, including politically exposed persons (PEPs), customers from high-risk jurisdictions and complex or unusually large transactions.
  • Beneficial Ownership Register: The Bahrain Ministry of Industry, Commerce and Tourism (MOICT) maintains a central Beneficial Ownership Register as required under Law No. 27 of 2015.
  • Suspicious Transaction Reporting: STRs must be submitted to the FID immediately and in any case within 14 days of forming a suspicion. Tipping-off is prohibited.
  • AML Compliance Officer: All regulated entities must appoint a senior-level AML compliance officer with direct access to the board of directors.

Saudi Arabia AML Regulations

Saudi Arabia’s AML framework is governed by the Anti-Money Laundering Law (promulgated by Royal Decree No. M/20 of 2018) and the implementing regulations issued by the Capital Market Authority (CMA) for capital market institutions and the Saudi Central Bank (SAMA) for banks and insurance companies. The Financial Intelligence Unit (FIU) operates under the Presidency of State Security.

Key Requirements under Saudi AML Law

  • Customer Due Diligence: CDD must be conducted for all customers, including identifying and verifying the customer’s identity, understanding the purpose and nature of the business relationship and conducting ongoing monitoring. Simplified CDD is permitted for low-risk customers.
  • Beneficial Ownership: Entities must identify and verify the identity of any natural person who ultimately owns or controls 25 per cent or more of the entity. SAMA and CMA regulations require maintaining current beneficial ownership information.
  • Suspicious Transaction Reporting: STRs must be filed with the FIU immediately upon suspicion. The FIU operates the SARA (Suspicious Activity Reporting Application) portal for electronic submissions.
  • Record Keeping: All records related to CDD, transactions and STRs must be retained for at least 10 years after the business relationship ends or the transaction is completed.
  • AML Compliance Officer: A qualified AML compliance officer must be appointed at the senior management level. The officer must have a direct reporting line to the board and access to all necessary information.

UAE AML Regulations

The UAE’s AML framework is based on Federal Decree-Law No. 20 of 2018 on Anti-Money Laundering and Combating the Financing of Terrorism, as amended by Federal Decree-Law No. 26 of 2021. The UAE Central Bank supervises financial institutions, while the Securities and Commodities Authority (SCA) supervises capital market entities. The FIU handles STR analysis and dissemination.

Key Requirements under UAE AML Law

  • Customer Due Diligence: CDD is mandatory for all customers at the outset of a business relationship. The UAE Central Bank’s AML/CFT guidelines specify detailed CDD procedures, including identification of the customer, beneficial owner and the purpose of the relationship.
  • Beneficial Ownership Register: The UAE maintains a central register of beneficial owners under Cabinet Resolution No. 58 of 2020. All legal persons must register their ultimate beneficial owners (UBOs) with the relevant licensing authority.
  • Suspicious Transaction Reporting: STRs must be submitted to the FIU within 30 working days of forming a suspicion. The UAE FIU operates the goAML portal for electronic reporting.
  • Targeted Financial Sanctions: All regulated entities must implement procedures to implement UN Security Council sanctions and UAE-proscribed lists without delay.
  • AML Compliance Officer: A senior AML compliance officer must be appointed, approved by the board and registered with the relevant supervisory authority.

Comparison of AML Requirements across Bahrain, Saudi Arabia and the UAE

The table below compares the core AML compliance requirements across the three jurisdictions:

RequirementBahrainSaudi ArabiaUAE
Primary regulatorCBBSAMA / CMACentral Bank / SCA
AML LawLaw No. 4 of 2001Royal Decree M/20 of 2018Federal Decree-Law 20/2018
CDD thresholdBHD 6,000SAR 10,000AED 55,000
Beneficial ownership threshold25%25%25%
STR deadline14 daysImmediate30 working days
Record retention period10 years10 years5 years
AML Compliance OfficerRequiredRequiredRequired
PEP screeningMandatoryMandatoryMandatory

Know Your Customer (KYC) Requirements

KYC procedures are the foundation of any AML compliance programme. Across all three jurisdictions, the following elements are required:

KYC ElementIndividual CustomersLegal Entity Customers
Full nameVerified via passport or national IDVerified via commercial registration
Date of birthConfirmed with official documentN/A
NationalityVerified via passportCountry of incorporation verified
AddressUtility bill or bank statementRegistered office address
Contact detailsPhone and email collectedAuthorised signatory contact details
Source of funds/wealthRequired for high-risk customersRequired for all customers
Beneficial ownershipN/AUBO identification (25% threshold)
Purpose of relationshipCollected at onboardingCollected at onboarding

Beneficial Ownership Registers

All three jurisdictions require the maintenance of beneficial ownership registers. The requirements differ in scope and administration:

  • Bahrain: The Beneficial Ownership Register is maintained by MOICT. Companies must identify any individual who directly or indirectly owns or controls 25 per cent or more of the company’s shares or voting rights. The register is accessible to law enforcement and the CBB.
  • Saudi Arabia: The Ministry of Commerce maintains the beneficial ownership register for all companies registered in the Kingdom. Disclosure extends to any natural person who ultimately owns or controls 25 per cent or more of the entity or exercises control through other means.
  • UAE: Cabinet Resolution No. 58 of 2020 mandates that all legal persons maintain a Register of Ultimate Beneficial Owners with the relevant licensing authority. The register must include details of any individual who directly or indirectly owns or controls 25 per cent or more of the entity.

Suspicious Transaction Reporting (STR)

The obligation to report suspicious transactions is a cornerstone of AML compliance. The reporting requirements differ across jurisdictions:

JurisdictionReporting DeadlineReporting PortalDuty to Report
Bahrain14 days from suspicionFID electronic systemMandatory for all regulated entities
Saudi ArabiaImmediateSARA (SAMA FIU portal)Mandatory for all regulated entities
UAE30 working daysgoAML (UAE FIU portal)Mandatory for all regulated entities

Tipping-off the customer or any third party about an STR submission is a criminal offence in all three jurisdictions. Regulated entities must also report attempted transactions, regardless of whether the transaction was completed.

Role of the AML Compliance Officer

The AML compliance officer plays a central role in an organisation’s AML compliance programme. Key responsibilities across all three jurisdictions include:

  1. Policy development: Drafting and maintaining the organisation’s AML/CFT policies, procedures and controls.
  2. Risk assessment: Conducting and documenting enterprise-wide money laundering and terrorist financing risk assessments.
  3. CDD oversight: Monitoring the effectiveness of CDD and EDD procedures across the organisation.
  4. STR review: Reviewing all internal suspicious activity reports and making STR submission decisions.
  5. Training: Delivering AML training to all relevant staff and ensuring ongoing professional development.
  6. Regulatory liaison: Acting as the primary point of contact for the supervisory authority and the FIU.
  7. Reporting: Submitting periodic AML compliance reports to the board of directors.

The AML compliance officer must be a senior-level employee with sufficient authority, independence and resources to fulfil their responsibilities. In all three jurisdictions, the officer must be registered with the relevant supervisory authority.

Penalties for Non-Compliance

Penalties for AML non-compliance are severe across the GCC. The table below summarises the maximum penalties under each jurisdiction:

JurisdictionMaximum FineMaximum ImprisonmentOther Sanctions
BahrainBHD 100,000 (CBB) / BHD 500,000 (Court)10 yearsRevocation of licence, disqualification of directors
Saudi ArabiaSAR 5 million per violation15 yearsBan from practicing, licence suspension
UAEAED 5 million (Central Bank) / AED 50 million (Court)10 yearsBlacklisting, licence revocation, debarment from government contracts

In addition to financial and criminal penalties, non-compliant entities face significant reputational damage, loss of banking relationships and removal from correspondent banking networks. Regulatory settlements and remediation orders are also common.

Frequently Asked Questions

What is the difference between CDD and EDD in AML compliance?

Customer Due Diligence (CDD) is the standard process of identifying and verifying a customer’s identity, understanding the purpose of the business relationship and conducting ongoing monitoring. Enhanced Due Diligence (EDD) is an elevated level of scrutiny applied to high-risk customers, such as PEPs, customers from high-risk jurisdictions or those with complex or unusually large transactions.

Who must appoint an AML compliance officer in the GCC?

All regulated entities must appoint an AML compliance officer. Regulated entities include banks, insurance companies, exchange houses, capital market institutions, finance companies and designated non-financial businesses and professions such as real estate agents, lawyers, accountants and auditors.

What is the beneficial ownership threshold in GCC countries?

All three jurisdictions (Bahrain, Saudi Arabia and the UAE) use a 25 per cent threshold for beneficial ownership identification. Any natural person who directly or indirectly owns or controls 25 per cent or more of the shares, voting rights or capital of a legal entity must be identified as a beneficial owner.

What should a business do if it suspects a transaction involves money laundering?

The business must submit a Suspicious Transaction Report (STR) to the relevant FIU or FID through the designated reporting portal. The report must be filed within the prescribed timeframe (immediate in Saudi Arabia, 14 days in Bahrain, 30 working days in the UAE). The business must not tip off the customer.

Are virtual asset service providers (VASPs) regulated under GCC AML laws?

Yes. Bahrain was the first GCC country to regulate VASPs under the CBB’s Crypto-Asset Module. Saudi Arabia regulates VASPs under SAMA’s framework for virtual assets. The UAE’s Virtual Assets Regulatory Authority (VARA) and the Central Bank regulate VASP activities under the AML law.

What record-keeping requirements apply under GCC AML laws?

Bahrain and Saudi Arabia require records to be retained for 10 years after the business relationship ends or the transaction is completed. The UAE requires a minimum of five years. Records include CDD documentation, transaction records, STR submissions and AML compliance reports.

How Bitrixme Can Help

Bitrixme provides end-to-end AML compliance services across the GCC, including AML programme design, risk assessment facilitation, CDD and EDD procedure development, STR reporting frameworks, AML compliance officer support and regulatory liaison. Our team holds recognised AML certifications and has direct experience with CBB, SAMA, CMA and UAE Central Bank compliance requirements. Contact Bitrixme today to schedule a compliance assessment or reach out on WhatsApp for an immediate consultation.


Disclaimer: This article provides general guidance on AML compliance across the GCC and does not constitute legal advice. Organisations should consult qualified legal professionals for advice specific to their circumstances and jurisdictions of operation.