UAE Third National Risk Assessment: Why Businesses Should Revisit Their Financial-Crime Risk Assessments
The UAE has launched its third National Risk Assessment, beginning a new review of the country's exposure to money laundering, terrorist financing and proliferation financing risks.
Announced by the General Secretariat of the National Committee for Anti-Money Laundering, Combating the Financing of Terrorism and Financing of Proliferation on 28 September 2026, the assessment will bring together 84 competent authorities alongside contributions from the private sector.
Its purpose extends beyond identifying individual offences or enforcement cases. The assessment is intended to develop a broader understanding of how financial-crime risks are changing, where the most significant vulnerabilities exist and how national resources and controls should respond.
For businesses operating in the UAE, that matters because the findings are also expected to help the private sector update its own institutional risk assessments and internal controls.
The announcement therefore provides a useful prompt for organisations to consider whether their existing understanding of financial-crime risk still reflects the environment in which they operate.
What Is the UAE National Risk Assessment?
A National Risk Assessment looks across sectors, activities and financial-crime typologies to establish where threats and vulnerabilities exist and how significant they are.
The UAE's third assessment builds on two previous cycles. The first was completed in 2018, while the findings from the second were approved in 2024 and contributed to the development of the UAE's 2024–2027 National Strategy.
The latest exercise will use operational data, supervisory expertise and sectoral analysis, with findings validated against multiple sources.
According to the UAE authorities, the assessment will move through five stages:
- Defining scope and initial priorities.
- Collecting data and evidence.
- Analysing risks.
- Validating findings using multiple sources.
- Translating identified risks and data gaps into future national strategy and action planning.
The exercise is therefore not simply a review of historical cases. It is intended to identify how the risk landscape is developing and where future attention should be directed.
What Risks Is the UAE Examining?
The scope of the third assessment is broad.
Authorities have said it will consider licensed, unlicensed and emerging activities, together with exposure to illicit financial flows and cross-border movements of funds.
Specific areas include:
- Beneficial ownership transparency.
- Misuse of companies and other legal arrangements.
- Complex ownership chains.
- Cross-border financial flows.
- Virtual assets.
- New financing channels.
- Fraud involving modern technologies.
- Asset recovery.
- Proliferation financing.
- Attempts to evade targeted financial sanctions.
The money laundering assessment will also cover 21 predicate offences and more than 20 criminal typologies. Authorities intend to consider not only the number of identified cases but also the scale of criminal proceeds, links with organised crime, international connections and the complexity of the activity involved.
For businesses, the significance is not that every organisation will be exposed to every one of these risks.
It is that national priorities can change as threats, technologies, business structures and methods of moving money develop.
Why Institutional Risk Assessments Matter
An organisation's risk assessment should reflect its actual activities and exposures rather than operate as a static compliance document.
Different businesses will face different risks depending on factors such as:
- The sectors in which they operate.
- The jurisdictions in which they do business.
- Their customer and counterparty base.
- The use of agents or intermediaries.
- Their ownership and corporate structure.
- The nature and value of transactions.
- Exposure to virtual assets or emerging payment methods.
- International supply chains.
- Regulatory requirements applicable to their activities.
The UAE announcement specifically states that the National Risk Assessment's findings are intended to enable the private sector to update institutional risk assessments and internal controls.
That is an important distinction.
An effective risk framework should not simply identify that financial crime exists. It should help an organisation determine which risks are relevant to its particular operations, how significant those exposures are and whether existing controls remain proportionate.
This principle sits naturally within a broader Risk Management approach: understanding the organisation, identifying material threats and vulnerabilities, assessing existing controls and reviewing the risk profile when circumstances change.
National Risk Priorities Can Affect Business-Level Decisions
Changes identified at national level can ultimately influence decisions taken within individual organisations.
For example, if emerging typologies indicate greater use of complex corporate structures or intermediaries to obscure parties to transactions, an organisation may need to consider whether its existing counterparty review processes remain appropriate.
If sanctions-evasion techniques become more sophisticated, businesses exposed to international transactions may need to reconsider how effectively their controls identify indirect relationships and unusual transactional patterns.
Similarly, developments involving virtual assets, new financing channels or technology-enabled fraud may affect organisations whose risk assessments were designed before those exposures became material.
This does not mean every change in the national assessment requires every business to introduce additional procedures.
A risk-based approach requires the opposite: understanding which developments actually matter to the organisation and responding proportionately.
Risk Assessment Should Come Before Additional Due Diligence
This is also where the distinction between organisational risk assessment and individual due diligence becomes important.
The National Risk Assessment operates at a broad level. It identifies threats, vulnerabilities and priorities across the UAE economy and relevant sectors.
An organisation's own risk assessment should then consider how those issues relate to its specific activities.
Only after that does the question arise of whether a particular customer, investment, supplier, transaction or commercial relationship requires greater scrutiny.
For example, a business may determine that certain jurisdictions, ownership structures, transactional patterns or intermediary relationships present a higher level of exposure. That assessment can then influence when standard checks are sufficient and when enhanced due diligence may be appropriate.
Keeping those stages separate helps prevent due diligence from becoming a generic checklist applied identically to every relationship.
The purpose of a risk-based approach is to direct greater scrutiny towards the areas where it is justified.
Beneficial Ownership Remains an Important Theme
Beneficial ownership transparency is specifically included within the scope of the new National Risk Assessment.
This reflects the wider importance of understanding who ultimately owns or controls legal entities and arrangements.
Complex ownership is not inherently problematic. International businesses, investment structures and family-owned groups can legitimately involve several companies and jurisdictions.
The risk arises where complexity obscures the identity of the parties involved, makes control difficult to establish or prevents an organisation from understanding who ultimately benefits from a transaction.
The UAE assessment will examine both beneficial ownership transparency and the misuse of legal persons and legal arrangements, alongside complex ownership chains and the use of intermediaries.
For businesses, these are areas where the quality of information matters as much as simply obtaining documentation.
Sanctions Evasion and Proliferation Financing
The new assessment also places specific attention on proliferation financing and attempts to evade targeted financial sanctions.
UAE authorities have highlighted potential risks arising through commercial transactions, dual-use goods, corporate structures and intermediaries, including situations where parties to transactions may be concealed.
This again demonstrates why risk assessment needs to consider relationships and transaction structures rather than relying solely on a straightforward name-screening exercise.
An organisation may need to understand not only who it is dealing with directly but, where proportionate, the ownership, control and intermediaries involved in the wider relationship.
Risk Profiles Do Not Remain Static
Perhaps the most useful lesson for businesses is that risk assessments should be capable of changing.
The UAE's own national process illustrates this.
Its third assessment builds on earlier exercises but incorporates new data, emerging activities, changing criminal typologies, technological developments and current cross-border risks. The findings will ultimately feed into the country's 2028 National Strategy and National Action Plan.
Organisations can apply the same underlying principle at business level.
A risk assessment completed several years ago may no longer fully reflect:
- Changes in geographic exposure.
- New products or services.
- Different payment methods.
- New suppliers or intermediaries.
- Changes in ownership.
- Emerging technologies.
- Developing sanctions risks.
- New fraud methodologies.
- Changes in the wider regulatory environment.
Risk management therefore works best as an ongoing process rather than a one-off exercise.
Preparing for a Changing Risk Environment
The third UAE National Risk Assessment does not simply catalogue financial-crime threats. It is intended to influence future priorities, supervision, preventive measures and the development of the national response.
For the private sector, its importance lies in understanding where that changing risk picture intersects with individual business operations.
Organisations do not need to react to every emerging threat in the same way.
They do need a clear understanding of their own exposure, the controls already in place and the circumstances that would justify reviewing them.
As the findings from the UAE's latest assessment develop, businesses with significant financial-crime, cross-border, counterparty or sanctions exposure should be able to assess whether their existing risk frameworks remain aligned with the environment in which they operate.
The objective is not to eliminate every possible risk.
It is to ensure that material risks are understood, prioritised and managed on the basis of current information rather than assumptions that may no longer reflect the market.