Proliferation and Proliferation Financing Explained: A UAE Compliance Guide (2026)
What Proliferation Actually Means
Under Federal Decree-Law No. 10 of 2025, proliferation is defined as the illicit and unauthorised trade in materials, systems, equipment, components, programs, or technology that contributes to the production or development of Weapons of Mass Destruction (WMD), related technology, or their delivery means. Weapons of Mass Destruction, in turn, include nuclear, biological, chemical, and radiological weapons.
In practical terms, proliferation is not only about warheads. It also captures the industrial and commercial ecosystem that supports WMD programmes:
- Specialised raw materials such as uranium, plutonium, and certain isotopes
- Precursor chemicals used in chemical weapons production
- Biological agents and dual-use laboratory equipment
- Delivery systems, including missiles and unmanned aerial vehicles
- Dual-use goods and technology, such as centrifuges, precision machining tools, valves, and specific software
Any of these items can move through legitimate supply chains before being diverted. That is precisely why proliferation is treated as a financial-crime risk and not only a national security issue.
What Proliferation Financing Means
Proliferation Financing (PF) is the funding side of that ecosystem. It is the act of providing, collecting, or making funds available, by any means and directly or indirectly, with knowledge that the funds will be used, in whole or in part, for the manufacture, possession, acquisition, development, production, sale, supply, export, trans-shipment, brokerage, transport, transfer, storage, or use of Weapons of Mass Destruction, their delivery means, or related materials, including dual-use technologies and goods.
Federal Decree-Law No. 10 of 2025 also captures any act carried out contrary to the UN Security Council resolutions issued under Chapter VII of the UN Charter concerning the prevention, suppression, and cessation of proliferation and its financing.
Two features of the offence are worth flagging for compliance teams:
- Source of funds is irrelevant. PF can be committed using clean money. Unlike money laundering, the funds do not have to originate from a predicate offence.
- Knowledge can be inferred. The law expressly allows knowledge to be inferred from factual and objective circumstances. Wilful blindness is not a defence.
How PF Differs From Money Laundering and Terrorism Financing
Regulated entities often treat ML, TF, and PF as a single block. In control design, they behave very differently.
Dimension | Money Laundering | Terrorism Financing | Proliferation Financing |
Source of funds | Always illicit | May be licit or illicit | Often licit; typically commercial trade flows |
Primary risk signal | Layering and integration of funds | Small values, high-risk beneficiaries | Sanctioned parties, diversion, dual-use goods |
Core control | Transaction monitoring on behaviour | Watchlist screening and behavioural monitoring | Sanctions screening, trade-based due diligence, end-use analysis |
Typical actor | Individuals, organised crime | Individuals, cells, NPOs | State actors, front companies, procurement networks |
The implication is that a control framework built only for laundering typologies will not reliably detect PF. Sanctions integrity, jurisdictional risk, and trade-based analysis carry disproportionate weight in the PF context.
The UAE Legal Framework for PF
Three instruments define the CPF (Counter-Proliferation Financing) regime in the UAE:
- Federal Decree-Law No. 10 of 2025 criminalises Proliferation Financing (Article 3), defines the underlying terms (Article 1), and sets the penalty structure (Articles 26 and 27).
- Cabinet Resolution No. 134 of 2025 (the Executive Regulations) sets the operational obligations: risk assessment, CDD, ongoing monitoring, record-keeping, and reporting.
- Cabinet Resolution No. 74 of 2020 governs Targeted Financial Sanctions (TFS), including UNSC resolutions 1540, 1718, 1737, and their successors dealing with proliferation. The Executive Office for Control and Non-Proliferation (EOCN) is the competent authority.
The suspicious transaction reporting obligation in Article 18 of Federal Decree-Law No. 10 of 2025 expressly covers transactions suspected of being linked to Proliferation Financing. PF is not an optional add-on to STR narratives; it is a mandatory reporting trigger in its own right.
Reporting Proliferation Financing Through goAML in the UAE
In the UAE, Suspicious Transaction Reports and Suspicious Activity Reports (STRs/SARs) linked to Proliferation Financing must be filed through the goAML platform, the electronic reporting system operated by the UAE Financial Intelligence Unit. Article 18(1)(a) of Cabinet Resolution No. 134 of 2025 requires Financial Institutions, DNFBPs, and Virtual Asset Service Providers to notify the Unit “immediately and without delay” through the Unit’s electronic system or any other means approved thereby. In practice, that system is goAML.
For Proliferation Financing specifically, three goAML report types matter most. The Confirmed Name Match Report (CNMR) and Partial Name Match Report (PNMR) are defined in the EOCN Guidance on Targeted Financial Sanctions (March 2026), which also confirms that CNMR replaces the previously used Funds Freeze Report (FFR) terminology:
- Suspicious Transaction Report or Suspicious Activity Report (STR/SAR): filed under Article 18 of Federal Decree-Law No. 10 of 2025 when a transaction, attempted transaction, or funds are suspected of being linked to Proliferation Financing, regardless of value.
- Confirmed Name Match Report (CNMR): filed immediately after freezing funds or assets belonging to a party designated under UNSC proliferation-related resolutions or the UAE Local Terrorist List. Formerly called the Funds Freeze Report (FFR); the terminology was updated in the March 2026 EOCN Guidance.
- Partial Name Match Report (PNMR): filed when a screening hit is a probable but not confirmed match to a designated party linked to Proliferation Financing.
Practical goAML expectations for CPF reporting in the UAE:
- Register with goAML before onboarding customers, not after a match. The registration process for DNFBPs and VASPs requires SACM pre-registration and organisation-level enrolment, and cannot be rushed on the day a freeze becomes necessary.
- Keep goAML user roles up to date. The Compliance Officer appointed under Article 22 of Cabinet Resolution No. 134 of 2025 must have active access to submit PF-related reports without operational delay.
- Respect the tipping-off prohibition. Article 19 of Cabinet Resolution No. 134 of 2025 prohibits disclosing, directly or indirectly, that a goAML report has been or will be submitted, including to the customer concerned.
- Draft PF report narratives with clarity. A goAML report on Proliferation Financing should identify the trigger, the parties, the goods or transactions involved, the sanctions reference where applicable, and the reason PF was suspected as opposed to ML or TF.
- File without delay. Delayed filing on a PF matter can attract administrative penalties under Article 17 of Federal Decree-Law No. 10 of 2025, which range from AED 10,000 to AED 5,000,000 per violation, independent of any criminal outcome.
For firms already registered on goAML for ML and TF reporting, no separate registration is required for Proliferation Financing. The same account is used, but internal workflows, escalation paths, and quality-assurance reviews should explicitly recognise PF as a distinct report category.
Penalties for Proliferation Financing
The penalty regime under UAE AML law reflects how seriously PF is treated:
- Natural persons: temporary imprisonment plus a fine of AED 1,000,000 to AED 10,000,000, or an amount equivalent to twice the value of the criminal property, whichever is greater (Article 26).
- Legal persons: a fine of AED 5,000,000 to AED 100,000,000, or the value of the criminal property involved, whichever is greater. On conviction, the court must order dissolution and closure of the premises where the activity is conducted (Article 27).
- Attempt is punished on the same footing as the completed offence.
- Administrative fines under Article 17 range from AED 10,000 to AED 5,000,000 per violation, and may be applied for control failures even where no criminal PF conduct is proven.
For most regulated firms, the administrative track is the more immediate exposure. Weak PF controls, missed TFS matches, or delayed reporting can trigger enforcement even without a link to an actual proliferation event.
Red Flags and Typologies for PF
PF risk indicators are behavioural and contextual. Common typologies to build into monitoring and CDD include:
Customer-level indicators
- Ownership structures that route through multiple jurisdictions with no economic rationale
- Front companies, shell companies, or trading entities with limited digital or physical footprint
- Nominee directors, obscured beneficial ownership, or reluctance to provide UBO information
- Connections, direct or indirect, to jurisdictions subject to UNSC proliferation-related resolutions
Transaction and trade indicators
- Goods described in vague or generic terms on shipping and payment documentation
- Third-party payments from unrelated jurisdictions or via non-obvious intermediaries
- Trade in dual-use items where the stated end-use does not fit the buyer’s business profile
- Repeated use of trans-shipment hubs, freight-forwarders, or free zones to obscure end destination
- Payment routing designed to avoid direct exposure to a high-risk jurisdiction
Behavioural indicators
- Requests to alter payment beneficiaries, remove references, or split transactions below reporting thresholds
- Documentation that appears templated, inconsistent, or reused across unrelated shipments
New customers immediately transacting at volumes inconsistent with their stated size or history
PF Control Blueprint for FIs, DNFBPs, and VASPs
An effective CPF framework should not sit in isolation. It plugs into the existing AML/CFT operating model at defined points.
1. Risk assessment
Address PF explicitly in the enterprise-wide risk assessment. Consider product, customer, delivery channel, and geography, and score exposure to sanctioned jurisdictions and dual-use trade flows.
2. Sanctions and screening
Screen customers, related parties, beneficial owners, counterparties, vessels, and, where relevant, goods against the UAE Local Terrorist List, the UNSC Consolidated List, and PF-specific designations administered through the EOCN. Screening must run at onboarding, at material change, and on ongoing basis.
3. Customer due diligence and EDD
For higher-risk relationships, apply Enhanced Due Diligence with a proliferation lens: obtain end-use and end-user information, verify counterparty legitimacy, and understand the trade rationale. Document the analysis.
4. Trade and transaction monitoring
Configure scenarios that specifically test for PF typologies, including dual-use goods flows, trans-shipment risk, and payment routing through sensitive corridors. Investigate meaningful alerts and close them with defensible rationale.
5. Freezing and reporting
On a positive TFS match, freeze without delay and without prior notice. Notify the EOCN and the Financial Intelligence Unit through goAML within the required timelines. File a Suspicious Transaction Report where PF is suspected, whether the transaction was executed or merely attempted.
6. Governance and training
Provide role-based CPF training and ensure senior management receives regular reporting on PF risk exposure, TFS screening performance, and STR outcomes.
Common CPF Gaps and Practical Fixes
Gap: PF is mentioned in policy but not built into monitoring scenarios.
Fix: Add dedicated PF typology rules and calibrate thresholds against actual customer and product data.
Gap: Sanctions screening runs only at onboarding.
Fix: Implement continuous screening triggered by list updates, material changes, and defined transaction events.
Gap: STRs mention ML and TF but rarely PF.
Fix: Train investigators to test PF hypotheses explicitly and record why PF was ruled in or out.
Gap: Trade documentation is accepted at face value.
Fix: Introduce dual-use screening and end-use verification for defined trade corridors and product categories.
Gap: PF risk is not visible at board level.
Fix: Include PF exposure, screening performance, and TFS reporting in the AML/CFT MI pack.
Board and Senior Management Questions
Senior leadership should periodically test whether the CPF framework is working as intended:
- Does our enterprise-wide risk assessment identify concrete PF exposure, not a generic reference?
- Are we screening against the UAE Local Terrorist List and UNSC lists on a continuous basis?
- Do we have PF-specific typologies in transaction and trade monitoring?
- Are TFS matches actioned with freezing and reporting inside required timelines?
- Do our STRs distinguish PF suspicion from ML and TF where relevant?
- Is CPF training delivered to the right roles at the right frequency?
Conclusion: Treat PF as a First-Class Compliance Risk
Proliferation and proliferation financing are no longer secondary considerations in the UAE AML framework. Federal Decree-Law No. 10 of 2025, Cabinet Resolution No. 134 of 2025, and the TFS regime under Cabinet Resolution No. 74 of 2020 collectively place PF on the same footing as money laundering and terrorism financing.
For Financial Institutions, DNFBPs, and VASPs across DIFC, ADGM, VARA, CMA, MOET, and MOJ contexts, the practical test is simple: can the firm demonstrate that it identifies, screens, monitors, freezes, and reports PF risk with the same discipline it applies to ML? Where the answer is not yet a clear yes, the CPF framework is the natural place to invest.
Put an AML Policy in Place That Meets UAE Standards
Custom AML policies and procedures aligned with UAE AML law and supervisory expectations for Real Estate Agent.
Independent AML Review for Real Estate Agents
Obtain an objective assessment of your AML, CFT, and CPF compliance against federal law and supervisory guidance.
Build a Risk-Based AML Program
Implement practical CDD, EDD, and monitoring systems tailored to high-value property transactions and cross-border exposure.
Yes. Real estate agents are formally classified as Designated Non-Financial Businesses and Professions (DNFBPs) under UAE federal AML legislation. This means they are legally required to comply with anti-money laundering (AML), counter-terrorist financing (CFT), and counter-proliferation financing (CPF) obligations comparable in structure to regulated financial institutions, calibrated to sector-specific risk exposure.
A business falls within scope where it conducts real estate activities on behalf of clients. This includes:
Real estate brokerage firms
Property consultants and transaction intermediaries
Leasing and rental agents
Off-plan sales representatives
Firms facilitating high-value or complex property transfers
Classification is determined by the nature of the activity performed, not merely the company title.
Real estate agents operating in mainland UAE and relevant commercial free zones are supervised by the Ministry of Economy and Tourism.
The Ministry conducts inspections, reviews reporting through goAML, issues sector-specific circulars, and applies administrative penalties where non-compliance is identified.
The principal legislation is Federal Decree Law No. 10 of 2025, which establishes enforceable AML, CFT, and CPF obligations for reporting entities, including DNFBPs.
It is supported by Cabinet Resolution No. 134 of 2025 (Executive Regulations), which operationalises compliance requirements such as:
Risk-based approach implementation
Enhanced Due Diligence (EDD) triggers
Transaction monitoring expectations
Supervisory inspection powers
Real estate agents must implement a structured compliance framework including:
A documented Business Risk Assessment (BRA) aligned with national risk findings
Customer Due Diligence (CDD) and beneficial ownership verification
Enhanced Due Diligence for higher-risk customers (e.g., PEPs, high-risk jurisdictions)
Ongoing transaction monitoring
Suspicious Transaction Reporting (STR) through goAML
Targeted Financial Sanctions (TFS) screening
Record retention mechanisms
Appointment of an empowered AML Compliance Officer
Supervisory reviews assess operational effectiveness, not just policy documentation.
Yes. Under Ministry Circular No. 05/2022, firms must submit a Real Estate Activity Report through goAML when qualifying freehold property transactions are settled in cash or virtual assets above prescribed thresholds.
The UAE’s Money Laundering and Terrorist Financing National Risk Assessment (ML/FT NRA) and Proliferation Financing National Risk Assessment (PF NRA) establish the national risk baseline.
Real estate agents must embed these findings into their Business Risk Assessment, sanctions screening controls, and escalation procedures.
Regulators evaluate whether firms demonstrate alignment with national risk exposure — particularly in areas such as:
High-value property transactions
Offshore and layered ownership structures
Foreign investor involvement
Sanctions and proliferation financing exposure
Administrative penalties are governed by Cabinet Resolution No. 71 of 2024, which applies to entities supervised by the Ministry of Economy and the Ministry of Justice.
Sanctions may include financial penalties, regulatory measures, and enhanced supervisory scrutiny depending on the severity and nature of the breach.