Quick Answer
A GRC function at a Middle East bank manages several parallel reporting obligations that don't share a single deadline, format, or recipient: suspicious transaction reports to the Financial Intelligence Unit via goAML with no minimum threshold and no delay permitted, large exposure and concentration reporting to the Central Bank, operational incident notification on a strict 4-hour/24-hour/72-hour clock, and periodic disclosure and provisioning reports. This page maps what's actually required in the UAE, where the deepest and most current regulatory detail sits, with a lighter, appropriately hedged view of how the pattern extends across the wider Gulf region.
Key Takeaways
- There is no single "regulatory reporting" obligation in UAE banking, it is a portfolio of distinct reporting regimes, each with its own trigger, timeline, and recipient, and a GRC function needs to track them as separate disciplines that happen to share infrastructure.
- Suspicious Transaction Reports have no minimum monetary threshold and must be filed "without delay" through the goAML platform, this is the UAE's most unforgiving reporting obligation, with fines from AED 100,000 to AED 1,000,000 for failure to report.
- The UAE's AML/CFT framework was substantially updated with Federal Decree-Law No. (10) of 2025, replacing the earlier 2018/2021 legislation. GRC teams should confirm internal references to "AML-CFT Law" point to the current instrument.
- Operational incident notification under the Operational Risk Management Regulation runs on an explicit tiered clock: 4 hours, 24 hours, and 72 hours for high-risk incidents, distinct from AML/CFT reporting timelines.
- Regional consistency should not be assumed: Saudi Arabia's SAMA runs a separately governed, increasingly granular reporting regime, and a GRC function operating across multiple Gulf jurisdictions needs jurisdiction-specific verification rather than a single regional playbook.
Why "Regulatory Reporting" Isn't One Thing
Ask a GRC leader at a Middle East bank to describe their regulatory reporting obligations, and the honest answer is a list, not a single process.
Suspicious transactions to the Financial Intelligence Unit, large exposures and concentration data to the Central Bank, operational incidents on a strict notification clock, provisioning and credit risk data, and periodic public disclosures. Each of these lives under a different law, has a different trigger, and often reports to a different recipient system entirely.
Treating "regulatory reporting" as one function to be staffed and resourced uniformly is a common structural mistake. The obligations genuinely don't behave the same way, an AML suspicious transaction report has no minimum threshold and no tolerance for delay, while a large exposure report is a scheduled, threshold-triggered submission. A GRC team's reporting architecture needs to reflect that difference, not flatten it.
The UAE Reporting Landscape, by Regime
-
Suspicious Transaction and Activity Reporting (AML/CFT)
Governed currently by Federal Decree-Law No. (10) of 2025 and its implementing Cabinet Resolution No. (134) of 2025, which updated the earlier AML-CFT framework. Licensed Financial Institutions must report a Suspicious Transaction Report (STR) or Suspicious Activity Report (SAR) to the UAE Financial Intelligence Unit (FIU) via the goAML platform whenever there are reasonable grounds to suspect a transaction, attempted transaction, or funds are connected to a crime, with no minimum reporting threshold and no permitted delay. Failure to report, whether intentional or through gross negligence, is a federal crime carrying a fine of AED 100,000 to AED 1,000,000 and/or imprisonment.
-
Large Exposures and Concentration Reporting
Under the Large Exposures Regulation (Circular C 1/2023), banks must report to the Central Bank all exposures at or above 10% of Tier 1 capital, both with and without credit risk mitigation applied, all exempted exposures above that threshold, the largest 20 exposures regardless of size, and exposures by sector, country, and currency (Article 5). This reporting is scheduled and threshold-triggered, not event-driven.
-
Operational Incident Notification
Under the Operational Risk Management Regulation (Circular C 1/2026, effective 14 September 2026), institutions must notify the Central Bank within 4 hours of an event significantly affecting Critical Operations, provide a summary report within 24 hours, confirm return to normal operations, and separately notify within 72 hours of any incident classified as high-risk (Article 15.2-15.3).
-
Credit Risk and Provisioning Reporting
Under the Credit Risk Management Regulation (Circular C 3/2024, effective 30 November 2024), institutions must maintain and report provisioning calculations consistent with the regulation's minimum acceptable practices, reviewed and revised as credit profiles change.
-
Public Disclosure
Under Article 16 of the Operational Risk Management Regulation, institutions must publicly disclose key information about their Operational Risk and Resilience approach, commensurate with size, complexity, and systemic importance, a standing, not incident-driven, obligation.
Comparison: Reporting Obligations Side by Side
| Obligation |
Governing Instrument |
Trigger |
Timeline |
Recipient |
| Suspicious Transaction/Activity Report |
Federal Decree-Law No. 10/2025, Cabinet Resolution 134/2025 |
Reasonable grounds for suspicion, any amount |
Without delay, no minimum threshold |
UAE FIU via goAML |
| Large exposure report |
Large Exposures Regulation, C 1/2023, Art. 5 |
Exposure at/above 10% of Tier 1 capital |
Per Central Bank reporting schedule |
CBUAE |
| Operational incident notification |
Operational Risk Management Regulation, C 1/2026, Art. 15 |
Event significantly affecting a Critical Operation |
4hr initial, 24hr summary, 72hr for high-risk |
CBUAE |
| Credit risk/provisioning report |
Credit Risk Management Regulation, C 3/2024 |
Standing obligation, reviewed on trigger events |
Per reporting cycle |
CBUAE |
| Public disclosure |
Operational Risk Management Regulation, Art. 16 |
Standing obligation |
Periodic, per institution's disclosure policy |
Public / stakeholders |
Who Owns What
Owner
AML/CFT Compliance Officer (MLRO)
Owns STR/SAR filing decisions and goAML platform management; this role carries personal accountability under the AML-CFT framework.
Owner
Credit Risk / Group Risk
Owns large exposure aggregation and reporting, and credit risk provisioning reporting.
Owner
Operational Risk Function
Owns incident classification and the notification clock under the Operational Risk Management Regulation.
Owner
Compliance / GRC Leadership
Owns the disclosure policy and typically coordinates across the other functions to ensure the Board has a consolidated view of reporting performance.
Oversight
Board and Senior Management
Receive regular reporting on breaches or expected breaches of risk appetite thresholds, and bear ultimate responsibility for the frameworks that produce these reports.
Recipient
Central Bank of the UAE / UAE FIU
The two primary regulatory recipients, though a given institution's Central Bank reporting requirements may extend further via case-by-case requests.
Expert Insight: The Deadline That Doesn't Forgive
Expert Insight
Most regulatory reporting obligations in UAE banking have some flexibility built in, reporting cycles, materiality thresholds, or reasonable-efforts standards. Suspicious transaction reporting has none of that. There is no minimum reporting threshold, a suspicious transaction of any size must be reported, and the requirement is to report "without delay," which UAE FIU guidance interprets as as soon as reasonably possible after the transaction takes place or the suspicion develops, not at the next scheduled reporting interval.
This creates a structural tension GRC leaders need to manage deliberately: an institution can have excellent large exposure reporting, sound operational incident notification discipline, and still carry serious regulatory risk if suspicious transaction detection and escalation is slow, because this is the one reporting obligation where "we were going to report it next cycle" is not a defense. Failure to report, even through gross negligence rather than intent, is itself a federal crime. A GRC function's resourcing and escalation design should reflect that this obligation, more than any other on this page, cannot be batched or scheduled around.
Practical Example: One Transaction, Two Reporting Clocks
Example
A bank's transaction monitoring system flags an unusual pattern of transfers linked to a corporate customer at 2:00 PM. The compliance analyst investigating the alert determines by 4:30 PM that there are reasonable grounds to suspect the transactions may be connected to a predicate offense. Under the AML-CFT framework, the clock to file an STR via goAML starts now, "without delay" means the filing should happen as soon as reasonably possible, not at the end of the business day or the next compliance committee meeting.
Separately, if the same pattern also involves a disruption to the bank's payment processing, for instance, the monitoring system itself experiencing degraded performance while investigating the volume of flagged activity, a second, entirely independent clock may start under the Operational Risk Management Regulation: 4 hours to notify the Central Bank if the disruption significantly affects a Critical Operation. These two obligations, triggered by related but distinct facts, report to two different recipients, on two different bases, and a GRC function needs a structure that can run both without either one being delayed by attention paid to the other.
Reporting Readiness Checklist
Institution registered and active on the goAML platform, with current authorized users
Internal escalation path for suspicious activity detection to STR/SAR filing decision documented, with no reliance on scheduled batch reporting
Large exposure aggregation methodology current and tested against the 10% Tier 1 capital threshold and Group of Connected Counterparties rules
Operational incident severity classification criteria defined and Board-approved, ahead of any live incident
Incident notification workflow built to meet the 4-hour/24-hour/72-hour timelines under the Operational Risk Management Regulation
Credit risk provisioning reporting aligned with the Credit Risk Management Regulation's current minimum practices
Public disclosure policy current and covering the required Operational Risk and Resilience information
Internal references to "the AML-CFT Law" confirmed as pointing to Federal Decree-Law No. 10/2025, not the superseded 2018/2021 instrument
Reporting ownership clearly assigned across MLRO, credit risk, operational risk, and compliance functions, with a coordination mechanism for overlapping incidents
Controls and Evidence Mapping
| Reporting Area |
Governing Requirement |
Evidence to Maintain |
Typical Owner |
| STR/SAR filing |
Federal Decree-Law 10/2025 |
goAML submission records, internal escalation logs |
MLRO / Compliance |
| Large exposure reporting |
Large Exposures Regulation, Art. 5 |
Exposure aggregation records, submission history |
Credit Risk / Group Risk |
| Incident notification |
Operational Risk Management Regulation, Art. 15 |
Notification logs against 4hr/24hr/72hr timelines |
Operational Risk |
| Credit provisioning reporting |
Credit Risk Management Regulation, C 3/2024 |
Provisioning calculations and rationale |
Credit Risk |
| Public disclosure |
Operational Risk Management Regulation, Art. 16 |
Published disclosure records, review history |
Compliance / GRC |
Regulatory Reporting Maturity Model
| Dimension |
Level 1: Ad Hoc |
Level 2: Developing |
Level 3: Managed |
Level 4: Optimized |
| STR/SAR escalation speed |
Reviewed at scheduled intervals |
Escalation path exists but inconsistently followed |
Consistent same-day escalation and filing |
Real-time monitoring-to-filing integration |
| Large exposure aggregation |
Manual, facility-by-facility |
Aggregated periodically, error-prone |
Systematic aggregation per Group of Connected Counterparties |
Real-time aggregation integrated into origination |
| Incident notification |
No defined severity criteria |
Criteria exist but timelines inconsistently met |
4hr/24hr/72hr timelines consistently met |
Notification triggers built into monitoring systems |
| Cross-functional coordination |
Each reporting obligation managed in isolation |
Some informal coordination |
Defined coordination protocol for overlapping incidents |
Unified reporting dashboard across obligations |
| Regulatory currency |
References to superseded laws/circulars persist |
Periodic manual review of regulatory currency |
Scheduled review cycle for all cited instruments |
Automated tracking of regulatory updates |
A candid self-assessment against these dimensions, rather than an assumption about industry norms, is the appropriate starting point for any GRC function reviewing its reporting architecture.
Best Practices
Resource suspicious transaction escalation separately from scheduled reporting functionsIt cannot be batched, and treating it like a periodic report understates its urgency.
Maintain a single internal register of every distinct reporting obligation, its governing instrument, trigger, timeline, and recipientThe fragmentation described in this guide is the norm, not the exception, and needs to be made visible internally.
Build a coordination protocol for incidents that trigger more than one reporting obligation simultaneouslySo attention to one doesn't delay the other.
Review all internal policy references to governing laws and regulations on a fixed cycleGiven how frequently UAE financial regulation has been updated in recent years.
Give the Board a consolidated reporting-performance view spanning all obligationsNot separate updates from each function in isolation.
Common Mistakes
Treating suspicious transaction reporting like a scheduled compliance task
The "without delay" standard and absence of a minimum threshold mean this obligation needs continuous, not periodic, attention.
Letting internal documentation cite superseded legislation
References to the 2018/2021 AML-CFT framework that haven't been updated to Federal Decree-Law No. 10/2025 create both a compliance risk and a credibility problem with regulators and auditors.
Managing each reporting obligation in a silo
Large exposure reporting, incident notification, and STR filing are often owned by entirely separate teams with no shared incident view, missing the fact that a single underlying event can trigger more than one.
Confusing large exposure reporting thresholds with STR reporting thresholds
These are entirely different regimes, one has a specific percentage trigger, the other has none, and conflating them in internal training materials creates real confusion for staff.
Common Challenges at Scale
Coordinating reporting across multiple business lines and legal entities
A banking group with several licensed entities in the UAE needs consistent reporting discipline across all of them, not just the parent.
Keeping pace with a genuinely fast-moving regulatory environment
UAE financial regulation has seen substantial updates in recent years, the AML-CFT law, the Credit Risk Management Regulation, the Large Exposures Regulation, and the Operational Risk Management Regulation have all been issued or substantially revised within a few years of each other.
Balancing speed and accuracy under the "without delay" STR standard
Fast escalation must not come at the cost of the quality of the suspicion assessment, building both speed and rigor into the same process is a genuine operational challenge.
Maintaining goAML platform proficiency across a large compliance team
Staff turnover and platform updates both create a recurring, not one-time, training need.
Expert Tip
Best Practice
When auditing a GRC function's reporting readiness, don't start by asking "are we compliant?" Start by asking "can we name, right now, every distinct reporting obligation we carry, its trigger, its timeline, and its owner?" A function that can answer that cleanly is almost always the one that's actually meeting its deadlines, the ones that struggle are consistently the ones where reporting obligations have never been mapped as a complete, distinct list.
Use Cases
A bank consolidating its regulatory reporting register
Building the single internal list of every distinct obligation, its governing instrument, and its owner, as a foundation for audit readiness.
A compliance team updating policy references after a legal framework change
Systematically reviewing all internal documentation citing AML-CFT, credit risk, or operational risk regulations to confirm current instrument references.
A GRC leader building a Board reporting pack
Structuring a consolidated view across STR filing performance, large exposure status, incident notification timeliness, and disclosure currency.
An institution expanding into a new Gulf jurisdiction
Confirming that reporting obligations do not transfer automatically from the UAE and require jurisdiction-specific verification.
The Wider Region: What Extends and What Doesn't
The pattern seen in the UAE, a central bank or monetary authority setting increasingly granular, increasingly time-sensitive reporting requirements, is broadly consistent across the Gulf, but the specific rules, deadlines, and platforms are not interchangeable.
In Saudi Arabia, the Saudi Central Bank (SAMA) regulates banks, finance companies, and insurers under its own framework, including the Banking Control Law and Finance Companies Control Law, with AML/CFT reporting governed by Saudi Arabia's Anti-Money Laundering Law and SAMA's own implementing AML/CTF guidance. SAMA has been moving toward greater reporting granularity, reportedly issuing a substantial number of regulatory reporting updates for credit institutions in recent years, and conducts examinations with frequency tied to institutional size and complexity.
For a GRC function operating across both the UAE and Saudi Arabia, or elsewhere in the Gulf, the safe assumption is that no reporting obligation transfers automatically between jurisdictions. Each central bank or monetary authority maintains its own reporting platform, its own thresholds, and its own enforcement regime. This page's UAE detail is verified against primary CBUAE and UAE FIU source text; any SAMA-specific compliance program should be built on SAMA's own current rulebook and specialist local advice, not extrapolated from the UAE picture.
Building or Strengthening the Reporting Function
Step 1
Build the complete reporting obligation register
Every distinct requirement, its governing law, trigger, timeline, and current owner.
Step 2
Audit internal policy documents for outdated legal references
Particularly around the AML-CFT framework given the 2025 legislative update.
Step 3
Separate suspicious transaction escalation from scheduled reporting workflows
In both process design and resourcing.
Step 4
Build a cross-functional coordination protocol
For incidents that trigger more than one reporting obligation.
Step 5
Establish a fixed review cycle for regulatory currency
Across all cited instruments.
Step 6
Confirm jurisdiction-specific requirements separately
For any operations outside the UAE, rather than assuming regional consistency.
Metrics to Track
Time from suspicious activity detection to STR/SAR filing, tracked as a distribution, not just an average
Large exposure reporting submissions completed on schedule vs. total due
Operational incident notifications meeting the 4-hour/24-hour/72-hour timelines vs. total qualifying incidents
Number of internal policy documents with confirmed-current regulatory citations vs. total reviewed
Number of reporting obligations with a named, current owner in the reporting register
How autoResilience Supports Regulatory Reporting
autoResilience is an integrated Governance, Risk, Compliance and Resilience platform. The core difficulty most GRC functions face with regulatory reporting isn't any single obligation in isolation, it's the fragmentation described throughout this page: distinct reporting regimes, owned by different teams, tracked in different systems, with no consolidated view of overall reporting health.
Within autoResilience, a GRC function can maintain a centralized reporting obligation register mapped to each governing instrument, track submission and notification timelines against their regulatory deadlines, and give the Board a consolidated view across AML/CFT, large exposure, operational incident, and disclosure reporting rather than separate updates from each function. Dashboards can surface overdue submissions, approaching deadlines, and outdated regulatory references before they become audit findings.
This does not replace the judgment of the MLRO in assessing suspicion, or the specific expertise required to interpret any individual regulation. What it can do is help the institution maintain the shared visibility and evidence trail that a genuinely fragmented reporting landscape requires.
Frequently Asked Questions
Is there a minimum transaction amount before a suspicious transaction must be reported?
No. There is no minimum reporting threshold under the UAE's AML-CFT framework, all suspicious transactions, including attempted transactions, must be reported regardless of amount.
What law currently governs AML/CFT reporting in the UAE?
Federal Decree-Law No. (10) of 2025 is the current principal AML/CFT/CPF legislation, with Cabinet Resolution No. (134) of 2025 as its implementing regulation, replacing the earlier Federal Decree-Law No. 20 of 2018 as amended by No. 26 of 2021.
What happens if an institution fails to file a required suspicious transaction report?
It is a federal crime, whether the failure was intentional or through gross negligence, carrying a fine of no less than AED 100,000 and no more than AED 1,000,000, and/or imprisonment.
How fast must an operational incident be reported to the Central Bank?
Within 4 hours for initial notification of an event significantly affecting a Critical Operation, with a 24-hour summary report, and within 72 hours for any incident classified as high-risk.
Do the UAE's reporting rules apply the same way in Saudi Arabia or other Gulf countries?
No. Each jurisdiction's central bank or monetary authority, SAMA in Saudi Arabia, for example, maintains its own reporting framework, thresholds, and platforms. Reporting obligations should be verified separately for each jurisdiction an institution operates in.
Explore how autoResilience can support your institution's regulatory reporting program.