DFSA and FSRA Compliance Documentation for Financial Services in the UAE
The DFSA and FSRA regulate financial services in the UAE's free zones. Here's how to review your compliance documentation for these regulators systematically.
The UAE has a unique financial regulatory structure. Two international financial free zones — the Dubai International Financial Centre (DIFC) and the Abu Dhabi Global Market (ADGM) — each have their own independent regulators: the Dubai Financial Services Authority (DFSA) and the Financial Services Regulatory Authority (FSRA) respectively. Outside the free zones, the Central Bank of the UAE (CBUAE) and the Securities and Commodities Authority (SCA) regulate financial services.
For firms operating in the DIFC or ADGM, the DFSA and FSRA impose comprehensive documentation requirements modelled on international best practices — drawing heavily from UK FCA, Singapore MAS, and IOSCO standards. The documentation burden covers governance, risk management, AML/CFT, conduct of business, systems and controls, and increasingly, technology governance and sustainable finance.
What the DFSA Requires (DIFC)
Key DFSA Regulatory Modules
| Module | What It Covers | Key Documentation |
|---|---|---|
| General (GEN) | Licensing, authorisation, fitness and propriety | Licence application, F&P assessments, organisational structure |
| Conduct of Business (COB) | Client-facing conduct, suitability, disclosure | Client classification, suitability assessments, risk warnings |
| Systems and Controls (SYS) | Internal governance, risk management, compliance | Governance framework, risk management, compliance monitoring |
| Anti-Money Laundering (AML) | AML/CFT compliance | AML policy, risk assessment, CDD procedures, STR filing |
| Prudential — Investment, Insurance, Banking (PIB/PIN/PBR) | Capital adequacy, prudential requirements | Capital calculations, stress testing, liquidity management |
| Collective Investment (CIR) | Fund management | Fund documentation, prospectus, reporting |
| Markets (MKT) | Market conduct, disclosure | Listing documents, ongoing disclosure |
Governance and Systems Documentation
| Requirement | Documentation |
|---|---|
| Governing body | Board charter, committee terms of reference, skills matrix |
| Senior management | Organisational structure, reporting lines, job descriptions for licensed functions |
| Compliance | Compliance manual, compliance monitoring programme, compliance reports |
| Risk management | Risk management framework, risk appetite statement, risk register |
| Internal audit | Internal audit charter, risk-based audit plan, audit reports |
| Outsourcing | Outsourcing policy, register, risk assessments, contracts, DFSA notifications |
| Business continuity | BCP, DR plan, testing records |
| Technology governance | IT risk management, cyber security, data protection |
Conduct of Business
| Requirement | Documentation |
|---|---|
| Client classification | Retail Client, Professional Client, Market Counterparty — classification records |
| Suitability | Suitability assessment for each recommendation to Retail Clients |
| Key Information | Client agreements, risk warnings, fee disclosures |
| Best execution | Best execution policy, execution records, annual review |
| Conflicts of interest | Conflicts policy, register, management procedures |
| Complaints | Complaints handling procedures, register, resolution records |
| Financial promotions | Approval process for marketing materials, records of approved promotions |
AML/CFT
The DFSA's AML module requires:
| Requirement | Documentation |
|---|---|
| AML/CFT policy | Board-approved comprehensive policy |
| Business risk assessment | Firm-wide ML/TF risk assessment |
| Customer Due Diligence | Risk-based CDD, simplified CDD, enhanced CDD procedures |
| Ongoing monitoring | Transaction monitoring, sanctions screening |
| Suspicious Activity Reports | SAR procedures, filing with UAE Financial Intelligence Unit (FIU) |
| Record keeping | All CDD and transaction records — minimum 6 years |
| Money Laundering Reporting Officer | MLRO appointment, reporting lines, resources |
| Training | AML/CFT training for all relevant staff |
What the FSRA Requires (ADGM)
Key FSRA Frameworks
| Framework | Key Documentation |
|---|---|
| Financial Services and Markets Regulations (FSMR) | Licence application, authorised activities, conditions |
| General Rulebook (GEN) | Governance, systems and controls, compliance, outsourcing |
| Conduct of Business Rulebook (COBS) | Client dealings, suitability, disclosure, complaints |
| AML Rulebook | AML/CFT policy, CDD, monitoring, reporting |
| Prudential Rules | Capital requirements, liquidity, stress testing |
| Funds Rules | Fund documentation, investor disclosure, reporting |
| Sustainable Finance Regulatory Framework | ESG disclosure, climate risk management |
ADGM-Specific Requirements
ADGM has positioned itself at the forefront of several regulatory areas:
| Area | Documentation |
|---|---|
| Digital assets | Framework for Virtual Asset Service Providers (VASPs) — licensing, custody, AML |
| Sustainable finance | ESG disclosure requirements, climate risk integration |
| RegTech/FinTech | Regulatory sandbox participation, innovation licence documentation |
| Data protection | ADGM Data Protection Regulations 2021 — comprehensive data protection framework |
Common Compliance Failures
1. Governance Documentation Gaps
Both DFSA and FSRA commonly cite:
- Board and senior management not demonstrating effective oversight of the firm's operations in the UAE
- Compliance monitoring programme documented but not implemented — or implemented without documented results
- Risk appetite statement too generic — not setting specific limits relevant to the firm
- Internal audit function not independent or not risk-based
- Governance arrangements that suggest the UAE entity lacks substance (decisions made offshore)
- Fitness and propriety assessments not conducted for all licensed functions
2. Conduct of Business Failures
- Client classification not documented or incorrect (treating Retail Clients as Professional)
- Suitability assessments not conducted for every recommendation to Retail Clients
- Risk warnings not provided before transactions in complex products
- Best execution policy exists but annual review not conducted
- Financial promotions distributed without compliance approval
- Complaints not recorded or not resolved within prescribed timelines
3. AML/CFT Deficiencies
- Business risk assessment not covering all products, services, delivery channels, and customer types
- Enhanced due diligence triggered but not documented in customer files
- Sanctions screening not covering all required lists (UN, OFAC, UAE local lists)
- SARs not filed promptly — analysis and filing rationale not documented
- MLRO reports to the governing body insufficient
- Training not role-specific — same generic training for all staff
4. Outsourcing Documentation
Both regulators have increased scrutiny of outsourcing:
- Outsourcing register incomplete — not covering all outsourced activities
- Material outsourcing without regulator notification
- Contracts missing required provisions (audit rights, sub-outsourcing controls, exit provisions)
- No documented oversight of outsourced activities
- Intra-group outsourcing treated less rigorously than third-party outsourcing
5. Substance Concerns
For firms operating in the DIFC or ADGM:
- Insufficient locally based staff with appropriate expertise
- Key decisions made outside the UAE without documented governance
- Board meetings held outside the UAE without justification
- Risk management and compliance functions not adequately resourced locally
- Delegation to group entities without proper oversight documentation
Building a Compliance Documentation Review Process
Step 1: Regulatory Mapping
| Requirement | Document | Owner | Last Reviewed | Status |
|---|---|---|---|---|
| Governance — Board charter | Board Charter | Company Secretary | January 2026 | ✅ Current |
| Governance — Compliance | Compliance Manual | Compliance Officer | November 2025 | ✅ Current |
| Governance — Risk management | Risk Framework | CRO | October 2025 | ✅ Current |
| COB — Client classification | Classification Policy | Compliance | September 2025 | ✅ Current |
| COB — Best execution | Best Execution Policy | COO | March 2025 | ⚠️ Annual review overdue |
| COB — Financial promotions | Promotions Register | Compliance | Ongoing | ✅ Current |
| AML — Policy | AML/CFT Policy | MLRO | August 2025 | ✅ Current |
| AML — Risk assessment | Business Risk Assessment | MLRO | June 2025 | ⚠️ Annual update due |
| Outsourcing — Register | Outsourcing Register | COO | Ongoing | ⚠️ 2 new arrangements not documented |
| Prudential — Capital | Capital Adequacy Report | CFO | Monthly | ✅ Current |
| Technology — Cyber security | Cyber Security Framework | IT/CISO | July 2025 | ⚠️ Needs update |
Step 2: Implement Review Cycles
| Document Type | Review Frequency | Triggered Review |
|---|---|---|
| Governance documents | Annually | Regulatory change, board change, regulator feedback |
| Conduct of business policies | Annually | Regulatory change, product change, complaint trend |
| Best execution policy | Annually | Execution venue change, market structure change |
| AML/CFT framework | Annually | Regulatory change, risk assessment update, audit finding |
| Outsourcing register | Quarterly | New arrangement, provider change |
| Capital adequacy | Monthly | Material business change, stress event |
| Compliance monitoring | Ongoing (per programme) | Regulatory change, risk assessment |
| Technology governance | Annually | Incident, technology change, regulatory guidance |
Step 3: Pre-Supervision Readiness
Both DFSA and FSRA conduct supervisory visits. Be prepared:
- All governance documents current and board-approved
- Compliance monitoring programme implemented with documented results
- AML/CFT risk assessment current, MLRO reports up to date
- Client classification records complete for all active clients
- Suitability assessments documented for all Retail Client recommendations
- Outsourcing register complete and regulator notifications filed
- Capital adequacy reports current
- Technology risk and cyber security documentation current
- Complaints register up to date with resolution records
- Financial promotions register showing compliance approval for all materials
Step 4: Cross-Document Consistency
- Risk appetite vs. business strategy — are they aligned?
- AML risk assessment vs. monitoring parameters — does monitoring address identified risks?
- Compliance manual vs. compliance monitoring programme — does monitoring cover all manual commitments?
- Outsourcing register vs. actual outsourced activities — is the register complete?
- Client classification vs. suitability requirements — are suitability assessments conducted for all Retail Clients?
Using AI to Review Compliance Documentation
What AI Can Check
- Completeness — verify policies cover all DFSA/FSRA-required elements
- Consistency — cross-reference policies, procedures, and registers for contradictions
- Currency — flag references to superseded DFSA/FSRA rules or guidance
- COB compliance — check client-facing documents against conduct of business requirements
- Substance indicators — flag documentation that suggests offshore decision-making without local governance
- Terminology — verify correct use of DFSA/FSRA regulatory terminology
What AI Cannot Replace
- Regulatory interpretation for firm-specific situations
- Assessment of governance effectiveness (substance vs. form)
- Client suitability assessment
- AML/CFT transaction monitoring effectiveness
- Capital adequacy calculations
- Supervisory relationship management
Practical Example
In TeamBench, you could configure a reviewer:
Reviewer name: UAE Financial Services Compliance Reviewer
System prompt:
You are a compliance documentation reviewer for UAE financial services firms regulated by the DFSA (DIFC) or FSRA (ADGM). Review governance documents, conduct of business policies, AML/CFT frameworks, and outsourcing documentation against DFSA rulebook modules (GEN, COB, SYS, AML) or FSRA rulebooks (GEN, COBS, AML). Check for: completeness (all regulatory requirements addressed), substance (documentation demonstrates genuine UAE-based governance and oversight), consistency (no contradictions across documents), currency (current rulebook references), and conduct compliance (client classification, suitability, disclosure properly documented). Flag specific gaps with the DFSA/FSRA rule reference. Use British English (standard in UAE financial free zones).
Evaluation criteria:
- Regulatory Completeness (weight: 3) — All applicable DFSA/FSRA requirements addressed
- Substance (weight: 3) — Documentation demonstrates genuine UAE-based governance
- Consistency (weight: 2) — No contradictions across documents
- Currency (weight: 1) — Current rulebook and guidance references
- Structure (weight: 1) — Professional presentation, clear organisation
Quality gate: Minimum score: 85.
Upload relevant DFSA/FSRA rulebook modules and your firm's regulatory framework into a Knowledge Base.
Frequently Asked Questions
What's the difference between DFSA and FSRA?
DFSA regulates financial services in the DIFC (Dubai). FSRA regulates financial services in the ADGM (Abu Dhabi). Both are independent regulators with their own rulebooks, modelled on international standards. A firm operating in both free zones needs separate licences and must comply with both sets of rules. Outside the free zones, the CBUAE and SCA regulate financial services.
What are the penalties for non-compliance?
Both DFSA and FSRA can impose substantial fines (up to $100 million for DFSA), restrict business activities, withdraw licences, publicly censure firms and individuals, and refer matters for criminal prosecution. Both regulators have active enforcement programmes.
How important is "substance" in the UAE?
Extremely important. Both DFSA and FSRA expect firms to have genuine operational substance in the UAE — appropriate local staffing, board presence, decision-making authority, and risk management capability. "Brass plate" operations face enhanced scrutiny and potential enforcement action.
Do DFSA and FSRA requirements differ significantly?
The core requirements are similar (both based on international standards), but there are differences in specific rules, thresholds, and reporting requirements. ADGM has been more proactive in areas like digital assets and sustainable finance. Always check the specific rulebook for your regulator.
How do we handle dual regulation (onshore and free zone)?
If your group operates both within a free zone and onshore UAE, you need to comply with both regulatory regimes. Documentation must address each regulator's requirements separately. Shared group policies may be used but must be supplemented with jurisdiction-specific elements.
What's the regulatory approach to digital assets?
ADGM has a comprehensive framework for Virtual Asset Service Providers (VASPs) and digital assets. DFSA has introduced its own crypto token regime. Both require specific licensing, AML/CFT compliance, custody requirements, and technology risk management documentation for firms dealing in digital assets.
Key Takeaways
- The UAE's financial free zones (DIFC and ADGM) have independent regulators (DFSA and FSRA) with comprehensive documentation requirements modelled on international standards.
- Substance is a top regulatory priority — documentation must demonstrate genuine UAE-based governance, decision-making, and operational capability.
- Conduct of business documentation is critical — client classification, suitability assessments, risk warnings, best execution, and financial promotions all require documented compliance.
- AML/CFT compliance requires business risk assessments, risk-based CDD, transaction monitoring, sanctions screening, and regular MLRO reporting.
- Common failures include governance gaps, conduct of business deficiencies, AML/CFT documentation weaknesses, incomplete outsourcing registers, and substance concerns.
- Both regulators actively enforce — fines can be substantial, and enforcement actions are published.
- AI-assisted review can check completeness, consistency, currency, and substance indicators across your documentation portfolio, but cannot replace regulatory judgement or supervisory relationship management.
- Implement annual review cycles aligned with regulatory expectations and triggered reviews for rulebook changes and supervisory feedback.
This article provides general information about DFSA and FSRA compliance documentation requirements and is not regulatory or legal advice. Always consult the DFSA or FSRA for current rules and seek qualified compliance advice for your specific situation.