Commercial gaming stopped being a policy debate in the UAE and became a licensed, supervised industry. For any operator, technology vendor, payment provider or professional services firm touching that industry, GCGRA AML compliance is now the workstream that determines how quickly everything else moves, and AML compliance UAE expectations here are set at bank grade. The General Commercial Gaming Regulatory Authority is not only issuing licences. It is the sole anti-money laundering and counter-terrorist financing supervisor for the entire sector, and it supervises against a federal statute that was rewritten twice inside twelve months.
That combination — a genuinely new industry sitting on top of a freshly overhauled AML framework — makes GCGRA AML compliance unlike anything else in the UAE compliance landscape. There is no domestic operating history to draw on, no sector rulebook to copy, and no settled market practice to benchmark against. What there is, instead, is a very clear set of federal obligations that bite from day one, and a regulator that has made no secret of its intention to hold GCGRA AML compliance to Tier 1 standards.
This guide sets out what GCGRA AML compliance requires in practice, where operator and supplier duties diverge under the UAE commercial gaming AML regime, why financial-services templates fail in a gaming environment, and — a question almost nobody is addressing properly — what gaming AML Dubai exposure looks like for businesses based in the emirate.
GCGRA AML compliance: the ten things that matter
- Federal Decree-Law No. 10 of 2025 replaced the 2018 AML law in full, with effect from 14 October 2025.
- Cabinet Decision No. 134 of 2025, in force from 14 December 2025, added licensed commercial gaming operators to the DNFBP list at Article 3.
- The GCGRA, established in Abu Dhabi in September 2023, is the sole AML/CFT supervisor for the sector.
- Customer due diligence triggers at AED 11,000, in a single transaction or cumulatively across linked transactions.
- Suspicious transaction reports go to the UAE Financial Intelligence Unit through goAML — not to the GCGRA.
- Sector-specific GCGRA AML/CFT guidelines have not yet been issued, so licensees must build from federal law, general reporting-entity guidance and international standards.
- The B2B supply chain is where the market activity actually is — more than fifteen gaming-related vendor licences have been granted, against a very small number of operator licences.
- Suppliers are not on the DNFBP list, but acquire financial crime obligations through licence conditions, suitability assessment and contractual flow-down from operators.
- Dubai holds no land-based or online gaming operator licence, yet carries substantial indirect exposure through vendors, payments, hospitality, professional services and property.
- Financial-services AML policies cannot be lifted into a gaming programme. The risk typologies, customer profile and value instruments are structurally different.
Part 1: The legal foundation behind GCGRA AML compliance
Two instruments changed the ground beneath every UAE reporting entity, gaming included. Both are recent enough that a large number of AML compliance UAE manuals still in circulation cite the repealed regime, which is the first thing to check before any GCGRA AML compliance work begins.

Federal Decree-Law No. 10 of 2025
Published in the Official Gazette on 30 September 2025 and in force from 14 October 2025, the 2025 AML Law repeals and replaces Federal Decree-Law No. 20 of 2018 in its entirety. This was not a refresh. The new law:
- Introduces proliferation financing as a distinct criminal offence, a category that did not exist in the 2018 framework
- Brings virtual asset service providers directly and explicitly within the AML/CFT perimeter
- Lowers the evidentiary threshold for predicate offences to a “knew or should have known” standard
- Expands freezing powers and prosecutorial access to accounts, systems and communications
- Tightens beneficial ownership requirements and restructures the supervisory framework
- Raises penalties materially compared with the 2018 regime
Cabinet Decision No. 134 of 2025
The executive regulations for the 2025 law took effect on 14 December 2025, replacing Cabinet Decision No. 10 of 2019. Article 3 is the provision that matters for this sector: it formally added licensed commercial gaming operators — including casinos, online gaming platforms and e-sports operators — to the list of Designated Non-Financial Businesses and Professions.
That single amendment is the hinge on which GCGRA AML compliance turns. Commercial gaming DNFBP status is not a label — it is the trigger for the entire obligation set. From 14 December 2025, a licensed gaming operator in the UAE is not a business that ought to have AML controls as a matter of prudent governance. It is a regulated reporting entity with statutory duties, a named supervisor, a reporting obligation and a defined penalty exposure.
Running alongside this is the commercial gaming legislative architecture itself, including Federal Decree-Law No. 25 of 2025, which took effect on 1 June 2026 and provides the legal foundation empowering the GCGRA to license and supervise gaming activity nationally. Operators should treat licensing and AML as two parallel obligations to be evidenced together, not sequentially.
On primary sources: legislation in this area is moving quickly and secondary commentary is not always current. Every reference in this guide should be verified against the official published text before being relied on for a licence submission, a board paper or a legal opinion.
Part 2: Commercial gaming DNFBP status and what GCGRA AML compliance demands
Commercial gaming DNFBP designation is not a classification exercise. It is a package of enforceable duties, and the full GCGRA AML compliance suite applies immediately. There is no transitional relief for a sector with no operating history — the obligations arrived complete.
A GCGRA-supervised licensee must have the following GCGRA AML compliance elements in place, operating, and capable of being evidenced:
| Obligation | What it means in practice |
|---|---|
| Institutional risk assessment | A documented, board-approved assessment of the licensee’s own ML/TF/PF risk across products, delivery channels, patron base and geographies. Not a template. |
| Customer due diligence | Identification and verification applied at or above the prescribed threshold, in single or linked transactions, completed before play where required. |
| Enhanced due diligence | Heightened scrutiny for politically exposed persons, high-risk patrons, VIP and junket relationships, and exposure to higher-risk jurisdictions. |
| Patron risk classification | A documented tiering methodology that drives the intensity of due diligence and monitoring, rather than a single flat standard. |
| Sanctions and PEP screening | Live screening capability with a working process for handling Executive Office listings, matches, escalation and freezing. |
| MLRO appointment | A named officer with genuine authority, adequate resourcing and direct access to senior management and the board. |
| Suspicious transaction reporting | Filed with the UAE Financial Intelligence Unit through the goAML portal, with a supporting narrative, acknowledgment retained, and no tipping-off. |
| Record retention | A minimum of five years, covering customer files, transaction records and internal reports. |
| Senior management accountability | Personal approval of internal policies and oversight of high-risk relationships, particularly where proliferation financing risk arises. |
| Training | Annual as a minimum, role-specific, with attendance and assessment records maintained. |
| Independent testing | A defined programme of independent review of the AML framework, with findings tracked to closure. |
The GCGRA compliance advisory work we do begins by mapping which of these a business already holds in some usable form and which must be built from nothing. For a first-time UAE gaming licensee, the answer sits much closer to the second category than management usually expects.
Part 3: The UAE commercial gaming AML market as it actually stands
GCGRA AML compliance planning improves considerably when it is anchored to the real shape of the UAE commercial gaming AML market rather than to press speculation. As at the first half of 2026, the picture is as follows.
Operator licences are scarce and deliberately so
- The Game LLC holds the UAE lottery licence, granted in July 2024. The GCGRA has indicated it intends to maintain a single licensed lottery nationally.
- Wynn Resorts holds the first — and so far only — land-based gaming facility licence, for the Wynn Al Marjan Island integrated resort in Ras Al Khaimah, a multi-billion-dollar development expected to open in 2027.
- Coin Technology Projects LLC is the first and, at the time of writing, only licensed online gaming operator, running the Play971 and TrueWin platforms following a December 2025 launch, initially available in Abu Dhabi and Ras Al Khaimah.
- MGM Resorts has publicly indicated an intention to pursue a licence in Abu Dhabi.
The working model appears to be one land-based licence per emirate and one online licence per emirate, with each emirate deciding independently whether to participate at all. Sharjah has indicated it will not. GCGRA chairman Jim Murren, formerly chief executive of MGM Resorts International, has publicly stressed that the regulator is moving deliberately rather than quickly.
The B2B supply chain is where the volume is
The gaming-related vendor regime is significantly more active than the operator regime. More than fifteen vendor licences have been granted to internationally recognised suppliers, including Aristocrat — the first major international technology provider to receive one, in October 2024 — alongside IGT, Konami, Sportradar, SmartPlay International, Hub88 and Live88 (Yolo Group), EQL Games, Arena Racing Company, and Endorphina, which secured a Tier II gaming-related vendor licence in 2026. PayBy, a Dubai-based payments business acquired by Astra Tech, became the first licensed payment provider in the sector.
Two things follow from that for GCGRA vendor licence compliance. First, for an international gaming business without an existing UAE footprint, a vendor licence is the realistic near-term entry route. Second — and this is the point most commentary misses — the population of businesses that already carry GCGRA-linked compliance exposure is dominated by suppliers, not operators.
The GCGRA’s own published licence categories span gaming operators, gaming-related vendors, key persons at corporate level, and key persons as individuals. Personal licensing of directors, executive officers and senior compliance staff means individual accountability is designed into the framework, not added later.
Part 4: Gaming AML Dubai — exposure without a licence
Dubai occupies an unusual and widely misunderstood position in this framework. Gaming AML Dubai exposure is worth setting out carefully, because the received wisdom is wrong in both directions.
4.1 Dubai holds no gaming operator licence
As at early 2026, no land-based casino licence has been issued for Dubai, and no online gaming operator licence has been granted for the emirate either. The licensed online platform is available in Abu Dhabi and Ras Al Khaimah but not in Dubai. Unlicensed gaming and unlicensed offshore platforms remain unlawful, and the regulator has explicitly warned that this extends to facilitators of unlicensed activity — not only to the operators themselves.
This is the point at which many Dubai businesses stop reading, on the reasonable-sounding assumption that a sector without a local licence cannot be a local compliance problem. That assumption is where gaming AML Dubai risk actually sits.
4.2 The federal perimeter does not stop at the emirate border
The GCGRA is a federal authority with exclusive jurisdiction across all seven emirates. There is no separate Dubai gaming regulator, no Dubai carve-out, and no exemption for foreign operators, technology vendors or digital-only platforms. A Dubai-registered company supplying, financing, marketing or servicing licensed gaming activity anywhere in the UAE falls within a federal regulatory perimeter regardless of where its trade licence was issued.
The commercial consequence is that Dubai currently functions as the sector’s commercial and service hub without holding its licensed operations. Gaming AML Dubai exposure is therefore real today — the opposite of the arrangement most people assume.
4.3 Where Dubai’s real exposure actually sits
Five channels account for most gaming AML Dubai exposure, and each one carries AML compliance UAE obligations of its own.

| Channel | Nature of exposure |
|---|---|
| Technology and payment vendors | Dubai hosts a dense concentration of payment institutions, platform businesses, geolocation and identity providers, and gaming technology firms. The first licensed payment provider in the sector is a Dubai-based business. These entities hold GCGRA vendor licences with attached conditions. |
| Feeder market and hospitality | Al Marjan Island sits roughly forty-five minutes by road from Dubai. Dubai hotels, concierge operations, limousine and charter services, VIP hosting and travel intermediaries will service patrons of a licensed venue in a neighbouring emirate. |
| Professional and corporate services | Dubai and DIFC-based law firms, corporate service providers, auditors and consultancies advising gaming licensees take on clients whose source of funds and sector risk profile differ materially from their existing book. |
| Banking and payments intermediation | Dubai and DIFC financial institutions will process gaming-derived flows, whether as operator banking, vendor settlement, patron transfers or winnings. Correspondent and de-risking decisions follow. |
| Property and high-value goods | Dubai real estate, precious metals and stones dealers, and luxury asset businesses are established DNFBPs. Gaming-derived wealth entering those channels is a classic placement and layering pattern flagged in international typology work. |
4.4 The Dubai regulatory stack is genuinely crowded
A single Dubai-based arrangement touching gaming can engage several regimes at once, and they apply cumulatively rather than in the alternative:
- GCGRA — for the gaming activity itself, and for AML/CFT supervision of licensed operators
- Central Bank of the UAE — where the money leg involves payment services, stored value or fiat settlement
- VARA — for virtual asset activity carried on in or from Dubai outside the DIFC, under Dubai Law No. 4 of 2022 and the Virtual Assets and Related Activities Regulations 2023
- DFSA — for firms inside the DIFC, which sits outside VARA’s perimeter and operates its own crypto token and AML modules
- Ministry of Economy — for DNFBP supervision of the property, DPMS and corporate services sectors that gaming wealth flows into
This matters most for Web3, tokenised rewards, NFT-based loyalty and digital wallet models, where a gaming platform can require GCGRA authorisation and a VARA assessment and Central Bank payment approvals simultaneously. Firms in that position need a crypto AML compliance framework designed against all applicable regimes at once, not sequenced one regulator at a time. Sequencing is how firms end up rebuilding controls three times.
4.5 What Dubai and DIFC firms should be doing now
- Run a perimeter test. Establish whether any current or prospective revenue line is connected to licensed gaming activity anywhere in the UAE — as supplier, intermediary, financier, marketer or adviser. Document the conclusion either way.
- Update the enterprise risk assessment. If gaming-sector exposure exists and the risk assessment does not mention it, the risk assessment is out of date. This is one of the first things a supervisor will test.
- Refresh source-of-wealth methodology. Gaming winnings, VIP credit and junket-linked wealth require a different evidentiary approach from salaried or business income. Existing CDD standards are unlikely to cover it.
- Check contractual flow-down. Operator contracts will impose AML, sanctions, data and integrity obligations on suppliers. Those obligations need an owner internally before the contract is signed.
- Brief the board. Sector entry decisions carry reputational and licensing consequences that sit above the compliance function. This is a board-level risk appetite question, not a compliance-team one.
A note on timing: Dubai’s position is widely expected to develop, and the one-licence-per-emirate model leaves the emirate as the largest unallocated opportunity in the market. Firms that build a defensible framework now will be positioned when that happens. Firms that wait will be competing for advisers and evidence at exactly the moment everyone else is.
Part 5: Why DFSA and FSRA templates fail GCGRA AML compliance
This is the most expensive assumption in GCGRA AML compliance right now, and it deserves to be stated bluntly.
The underlying principles are genuinely shared. A risk-based approach, customer due diligence, ongoing monitoring, suspicious activity reporting, record-keeping and independent testing appear in the DFSA rulebook, the ADGM FSRA framework and the federal AML compliance UAE regime alike. That shared vocabulary is precisely the problem: it makes a financial-services AML policy look transferable when it is not.
Three structural differences break the analogy and make UAE commercial gaming AML its own discipline.
Patron risk is not customer risk
A DIFC asset manager onboards a defined, relatively stable client base with documented wealth and an evident commercial rationale for the relationship. A gaming operator onboards high volumes of retail patrons, many transacting for the first time, many non-resident, with no business rationale to interrogate. Risk classification logic that produces meaningful output in the first environment produces noise in the second. If you are running MLRO services in DIFC or ADGM and assume the same methodology transfers, the alert volumes will tell you otherwise within a month.
Value instruments do not behave like money
Chips, plaques, tickets, promotional credit, player wallet balances, bonus value and loyalty points all create movement that does not map cleanly onto a bank-style transaction monitoring rule set. Casino value instruments are specifically identified in UAE sector policy work as a money laundering risk. Monitoring calibrated for wire transfers and card payments will miss most of what matters on a gaming floor or platform.
The typologies are sector-specific
The joint policy work issued by the UAE National Committee and the GCGRA identifies the risks that define this sector: anonymous transactions, exploitation of player accounts, third-party payments, foreign-jurisdiction patronage, use of multiple payment methods, casino value instruments, VIP programmes, employee complicity and cash usage. The FATF typology report on casino and gaming sector vulnerabilities covers much of the same ground. Almost none of these appear in a financial-services risk register, because almost none of them exist there.
An AML risk assessment built on the wrong typologies will pass an internal review and fail a supervisory one, and every downstream GCGRA AML compliance control inherits the defect. The document will look complete. It will simply be assessing the wrong risks — and AML policy development built on top of it inherits the same defect.
Part 6: Gaming AML KYC, player due diligence and the AED 11,000 trigger
Under the current executive regulations, the due diligence and reporting threshold for gaming transactions is AED 11,000, applied to a single transaction or cumulatively across linked transactions. The figure is not arbitrary: it sits deliberately close to the USD/EUR 3,000 casino threshold in the international standards, signalling that the UAE is aligning to global practice rather than inventing its own bar.
The threshold is the easy part of gaming AML KYC. What a supervisor examines under GCGRA AML compliance is everything built around it.

- Linked-transaction logic. Can the system actually identify structuring — a patron splitting activity into amounts that individually sit below the line? A threshold rule without aggregation logic is a control in name only, and it is the first thing an examiner will test.
- Source of funds, not merely identity. Verifying who a patron is answers a different question from where the stake came from. For high-value and VIP play, the second question carries almost all of the risk.
- Timing. Due diligence completed after play has commenced is a finding, regardless of whether it was eventually completed correctly.
- Third-party payment handling. Where the payment instrument does not belong to the patron, the standard escalates rather than relaxes. This is one of the sector’s named risk typologies.
- Ongoing monitoring. Onboarding CDD is a snapshot. Patron risk changes with behaviour, and the file has to change with it.
- Age and geolocation controls. Participation is restricted to those aged 21 and over, and geo-restriction is a licensing expectation for online platforms. These sit alongside AML controls rather than inside them, but they are examined together.
Effective gaming AML KYC and transaction monitoring and screening in a gaming environment means tuning to patron behaviour patterns rather than importing a banking rule library and adjusting thresholds. The two approaches produce very different alert profiles, and only one of them produces alerts an MLRO can act on. Equally, KYC processes have to be built for volume and speed without sacrificing evidentiary quality — a tension that does not arise in the same form in wholesale financial services.
Part 7: GCGRA vendor licence compliance — the supplier gap
GCGRA vendor licence compliance is the issue almost nobody in the market is addressing clearly, and it is the single most consequential misreading we encounter.
Cabinet Decision No. 134 of 2025 designates commercial gaming operators as DNFBPs. It does not, by that route, place the same statutory DNFBP obligations on every gaming-related vendor. A significant number of B2B licensees have read that and concluded — reasonably enough on a plain reading — that AML is the operator’s problem.
That conclusion is wrong in practice, and GCGRA vendor licence compliance obligations arrive by four separate routes.

- The GCGRA’s jurisdiction is not limited to operators. The regime reaches technology vendors, platform providers, payment solution providers, equipment suppliers, content aggregators, live dealer platforms, sports data firms, geolocation providers and marketing affiliates. Vendor licences are being issued now, with conditions attached, and those conditions are enforceable.
- Obligations arrive contractually even where they do not arrive statutorily. Licensed operators carrying full DNFBP liability will push AML, sanctions, data protection and integrity requirements down their supply chain, because their own supervisory exposure depends on it. A vendor without a defensible framework becomes a procurement failure long before it becomes a regulatory one.
- Suitability assessment applies at the vendor stage. The GCGRA assesses the integrity and suitability of entities and individuals involved in ownership, management and operational control. Weak financial crime governance is a suitability issue in a sector where a licence is treated as a privilege rather than an entitlement.
- Key person licensing attaches to individuals. Directors, executive officers and senior compliance personnel are licensed in their own right. Personal regulatory history follows people across applications and across jurisdictions.
The practical GCGRA vendor licence compliance failure we see is sequencing. Suppliers treat compliance as a post-licence workstream, then discover mid-application that the evidence required — a documented risk assessment, a named compliance function, a working screening capability, trained staff, an independent review plan — takes months to build and cannot be retrofitted into a submission already under assessment.
The asymmetry: these gaps are inexpensive to close at design stage and expensive to close under supervisory pressure or mid-application. That asymmetry is the entire commercial argument for building the framework before the licence is live rather than after.
Part 8: GCGRA AML compliance reporting — three channels, not one
A working GCGRA AML compliance programme plugs into three separate channels simultaneously. Confusing them is a common and highly visible early error.

| Channel | Function | What flows through it |
|---|---|---|
| GCGRA | Sector supervisor | Licensing, sector guidance, inspections, risk assessment, enforcement and penalties |
| UAE FIU (goAML) | Financial intelligence | Suspicious transaction and suspicious activity reports, filed by the MLRO |
| Executive Office (EOCN) | Sanctions authority | Targeted financial sanctions listings, freezing obligations and alerts |
The GCGRA supervises your GCGRA AML compliance programme. It does not receive your STRs. Those go to the FIU through goAML, filed by the MLRO with a clear supporting narrative, with the acknowledgment retained on file and no tipping-off of the patron. Sanctions listings and freezing obligations arrive through a different route again and operate on far shorter timeframes — often measured in hours rather than days.
Programmes that route everything through the supervisor, or that treat sanctions screening as a subset of AML transaction monitoring, fail on both counts.
Part 9: Building GCGRA AML compliance before sector guidance exists
The GCGRA is established as the sector’s AML/CFT supervisor, but detailed sector-specific guidelines for GCGRA AML compliance have not yet been issued. Licensees are expected in the meantime to comply with the federal AML law and executive regulations, the guidance applicable to all reporting entities, and the joint commercial gaming policy work — and to exercise judgment where the sector detail is not yet written down.
This is where most in-house teams building GCGRA AML compliance get stuck, and it is a reasonable place to get stuck. There is no template to buy. An over-engineered programme wastes money and slows the business; an under-engineered one creates exposure. Three principles hold up well in that environment.
- Build to the risk, then document the reasoning. Where prescriptive guidance does not exist, a well-evidenced rationale tied to your own institutional risk assessment is the strongest position available. A supervisor examining a new sector is assessing the quality of reasoning as much as the output.
- Build to be revised. Design GCGRA AML compliance policies, monitoring rules and thresholds so they can be re-tuned when guidance lands, rather than rewritten from scratch. Version control and a documented change log matter more here than in a mature regime.
- Appoint the compliance function early. An MLRO engaged during licensing shapes the GCGRA AML compliance programme. An MLRO appointed after approval inherits decisions they would not have made and cannot easily unwind.
For businesses that are not yet at the scale to justify a full-time senior hire, an outsourced or provisioned MLRO gives you the authority and experience the role requires without the fixed cost, and — importantly in this sector — brings pattern recognition from a regulator that is still forming its expectations.
Part 10: Common GCGRA AML compliance failure points
- Reusing DFSA or FSRA policy templates on the assumption that gaming AML is financial-services AML with different customers
- Underinvesting in player KYC and source of funds relative to what a player-facing, high-volume, cash-adjacent business genuinely requires
- Treating supplier compliance as an afterthought to the operator’s licensing process
- Appointing an MLRO in title only — without authority, resourcing or a direct reporting line to senior management
- Screening at onboarding and never again, leaving sanctions and PEP exposure unmonitored for the life of the relationship
- No independent testing plan, which is almost always among the first questions asked in a supervisory review
- Generic training that covers AML in the abstract rather than the specific typologies staff will encounter on a floor or a platform
- Threshold rules implemented without linked-transaction aggregation, leaving structuring undetected by design
- Compliance documentation written for the licence file rather than for the people who have to operate it
- No mapping of which regulator owns which part of a multi-regime arrangement, particularly where payments or virtual assets are involved
Part 11: What defensible GCGRA AML compliance looks like on day one
If you are preparing a submission, or preparing to operate, this is the minimum GCGRA AML compliance evidence file. A programme holding all twelve, documented and demonstrably operating, is defensible. A programme missing three or four is not, regardless of how strong the ones that exist are.

| # | Evidence item | Owner |
|---|---|---|
| 1 | Institutional ML/TF/PF risk assessment, board-approved and sector-specific | Board / MLRO |
| 2 | AML/CFT policy manual reflecting Decree-Law 10/2025 and Cabinet Decision 134/2025 | MLRO |
| 3 | Patron risk classification methodology with documented tiering logic | MLRO / Operations |
| 4 | CDD and EDD procedures with the AED 11,000 trigger and linked-transaction rules built in | MLRO / Operations |
| 5 | Sanctions and PEP screening capability with escalation and freezing procedures | MLRO / IT |
| 6 | MLRO appointment, terms of reference and reporting line | Board |
| 7 | goAML registration and a tested internal escalation-to-STR workflow | MLRO |
| 8 | Record retention schedule meeting the five-year minimum | MLRO / IT |
| 9 | Role-specific training programme with attendance and assessment records | HR / MLRO |
| 10 | Independent testing and review plan with defined frequency | Board / Audit |
| 11 | Third-party and supply chain due diligence framework | Procurement / MLRO |
| 12 | Regulatory perimeter map identifying every applicable authority | Legal / MLRO |
Point ten is the one most often deferred and least often forgiven. An independent AML audit carried out before a supervisor asks for one converts an unknown into a managed finding, on your own timeline.
Part 12: A realistic GCGRA AML compliance implementation sequence
For a licensee or applicant building GCGRA AML compliance from a standing start, this is the order that works. The durations assume management attention is actually available.
| Phase | Focus | Typical duration |
|---|---|---|
| Phase 1 | Licence category determination — operator, vendor or key person — and regulatory perimeter mapping across GCGRA, CBUAE, VARA, DFSA and Ministry of Economy where relevant | 2–3 weeks |
| Phase 2 | Institutional risk assessment against sector-specific typologies, board-approved | 3–4 weeks |
| Phase 3 | AML/CFT policy manual, patron risk methodology, CDD and EDD procedures drafted to the risk assessment | 3–5 weeks |
| Phase 4 | MLRO appointment, governance structure, goAML registration and reporting workflow | 2–4 weeks, run in parallel |
| Phase 5 | Screening and monitoring configuration, tuned to gaming typologies rather than banking rule sets | 4–6 weeks |
| Phase 6 | Training rollout, independent testing plan, and evidence file assembly for submission | 3–4 weeks |
| Ongoing | Advisory as GCGRA sector guidance is issued, with re-tuning of thresholds and rules | Continuous |
GCGRA AML compliance: where this leaves you
The UAE has built a gaming regime that sits far closer to the strictest international jurisdictions than to permissive ones, and it has built UAE commercial gaming AML on top of an AML statute that was substantially strengthened in late 2025. For operators and suppliers, that means GCGRA AML compliance is not a downstream licensing formality. It is a structural GCGRA AML compliance requirement that shapes onboarding, payments, technology architecture, staffing and governance from the first day of operations — and, for a great many Dubai businesses, it is a live exposure that exists today despite the absence of a licensed operator in the emirate.
UAE commercial gaming AML is early enough that there is no established playbook, and that cuts both ways. There is more uncertainty than in a mature market. There is also a real and time-limited advantage in building correctly the first time rather than remediating later under supervisory attention.
Ontrax built its GCGRA AML compliance and GCGRA compliance advisory capability alongside the framework itself, from a base in DIFC, Dubai. Our GCGRA compliance advisory work covers licence category assessment, AML and CFT programme design matched to gaming risk factors, gaming AML KYC and source of funds procedures, operator-versus-supplier obligation mapping, gaming MLRO UAE provision, training and awareness programmes, and ongoing advisory as the GCGRA’s own guidance develops.
If you are preparing a GCGRA application, reviewing an existing GCGRA AML compliance programme, or working out whether operator or GCGRA vendor licence compliance obligations apply to your business, speak to our team for a no-obligation assessment.
GCGRA AML compliance: frequently asked questions
What is GCGRA AML compliance?
GCGRA AML compliance is the set of anti-money laundering and counter-terrorist financing obligations applying to businesses supervised by the General Commercial Gaming Regulatory Authority in the UAE. It covers institutional risk assessment, gaming AML KYC and player due diligence, sanctions screening, MLRO appointment, suspicious transaction reporting, record retention and independent testing.
Are commercial gaming operators regulated for AML in the UAE?
Yes. Licensed operators were given commercial gaming DNFBP status under Article 3 of Cabinet Decision No. 134 of 2025, which took effect on 14 December 2025. They carry the full range of DNFBP obligations under the UAE commercial gaming AML regime, supervised by the GCGRA.
Who supervises GCGRA AML compliance?
The General Commercial Gaming Regulatory Authority, established in Abu Dhabi in September 2023, is the sole AML/CFT supervisor for commercial gaming in the UAE. It handles licensing, sector guidance, inspections and penalties. It does not receive suspicious transaction reports — those go to the UAE Financial Intelligence Unit through the goAML portal.
What is the customer due diligence threshold for gaming transactions?
AED 11,000, applied to a single transaction or cumulatively across linked transactions. Gaming AML KYC processes must also detect activity deliberately structured to sit below that line, which requires aggregation logic rather than a simple threshold check.
Do gaming suppliers and technology vendors need an AML programme?
Yes in practice. The statutory commercial gaming DNFBP designation attaches to operators, but GCGRA vendor licence compliance obligations arrive through licence conditions, suitability assessment, key person licensing and contractual flow-down from operators.
Is there a licensed casino in Dubai?
No. As at early 2026 no land-based casino licence and no online gaming operator licence has been issued for Dubai. The only land-based licence is held by Wynn Resorts for Ras Al Khaimah, and the only licensed online operator serves Abu Dhabi and Ras Al Khaimah.
Does UAE gaming AML law affect Dubai businesses?
Frequently, yes. Gaming AML Dubai exposure follows the activity, not the trade licence. The GCGRA’s jurisdiction is federal, and Dubai hosts a concentration of technology vendors, payment providers, hospitality operators, professional advisers and DNFBPs whose activity connects to licensed gaming elsewhere in the UAE.
Can a DIFC or ADGM AML policy be adapted for a gaming licence?
Not without substantial rework. The risk typologies, customer profile, transaction instruments and monitoring logic in GCGRA AML compliance differ materially from a DFSA or FSRA-regulated financial institution. Shared principles do not make the documents transferable.
Does a gaming licensee need to appoint an MLRO?
Yes. A gaming MLRO UAE appointment is mandatory, and the role must carry genuine authority, adequate resourcing and a direct reporting line to senior management. An MLRO in title only is a finding, and the sector has no domestic hiring pool with directly relevant experience yet.
What happens if a virtual asset or crypto element is involved?
The analysis becomes multi-regime. GCGRA authorisation may sit alongside a VARA assessment for activity in or from Dubai outside the DIFC, and Central Bank engagement where the money leg involves payment services. These regimes apply cumulatively rather than in the alternative.
Has the GCGRA issued sector-specific AML guidelines?
Not at the time of writing. Licensees build GCGRA AML compliance from the federal AML law and executive regulations, guidance applicable to all reporting entities, and the joint NAMLCFTC and GCGRA commercial gaming policy work, applying documented judgment where sector detail is not yet published.
How long does it take to build a compliant programme?
For a business starting from nothing, a realistic range is three to five months to reach a defensible GCGRA AML compliance evidence file, assuming management attention is available. Compressing that materially usually means importing a template, which is the failure mode described throughout this guide.
What does an AML risk assessment cover for a gaming licensee?
An AML risk assessment for a gaming licensee covers products, delivery channels, patron base and geographies against sector-specific typologies — anonymous transactions, player account exploitation, third-party payments, foreign-jurisdiction patronage, casino value instruments, VIP programmes, employee complicity and cash usage. It is the document every other control is built from.
What are the most common GCGRA AML compliance mistakes?
Reusing DFSA or FSRA templates, underinvesting in gaming AML KYC and source of funds, treating GCGRA vendor licence compliance as an afterthought, appointing an MLRO without authority, screening only at onboarding, and implementing the AED 11,000 threshold without linked-transaction aggregation.
Primary sources and further reading
- General Commercial Gaming Regulatory Authority (GCGRA) — the federal regulator: licensing framework, licensee register and regulatory announcements
- GCGRA licence types and categories — official breakdown of operator, gaming-related vendor and key person licences
- Commercial Gaming Policy Paper — UAE National Committee for AML/CFT (NAMLCFTC) — sector ML/TF risk typologies and control expectations, issued jointly with the GCGRA
- FATF Guidance on the Risk-Based Approach for Casinos — the international standard underpinning the UAE approach to the sector
- FATF: Vulnerabilities of Casinos and Gaming Sector — typology report on laundering methods specific to gaming

