Check your DPDP Readiness now | Click Here
GRC · Finance & GRC

Regulatory Reporting for GRC Teams in Middle East Banking

A GRC function at a Middle East bank manages several parallel reporting obligations that don't share a single deadline, format, or recipient: suspicious transaction reports to the Financial Intelligence Unit via goAML, large exposure reporting, operational incident notification on a 4-hour/24-hour/72-hour clock, and periodic disclosure and provisioning reports.

⏱ 10 MIN READ ◆ GRC ✎ ASCENT EDITORIAL
GRC
Assessment
Implementation
Governance & Compliance
Continuous Improvement

Key Takeaways

  • There is no single "regulatory reporting" obligation in UAE banking, it is a portfolio of distinct reporting regimes, each with its own trigger, timeline, and recipient, and a GRC function needs to track them as separate disciplines that happen to share infrastructure.
  • Suspicious Transaction Reports have no minimum monetary threshold and must be filed "without delay" through the goAML platform, this is the UAE's most unforgiving reporting obligation, with fines from AED 100,000 to AED 1,000,000 for failure to report.
  • The UAE's AML/CFT framework was substantially updated with Federal Decree-Law No. (10) of 2025, replacing the earlier 2018/2021 legislation — GRC teams should confirm internal references to "AML-CFT Law" point to the current instrument.
  • Operational incident notification under the Operational Risk Management Regulation runs on an explicit tiered clock: 4 hours, 24 hours, and 72 hours for high-risk incidents, distinct from AML/CFT reporting timelines.
  • Regional consistency should not be assumed: Saudi Arabia's SAMA runs a separately governed, increasingly granular reporting regime, and a GRC function operating across multiple Gulf jurisdictions needs jurisdiction-specific verification rather than a single regional playbook.

Quick Answer

A GRC function at a Middle East bank manages several parallel reporting obligations that don't share a single deadline, format, or recipient: suspicious transaction reports to the Financial Intelligence Unit via goAML with no minimum threshold and no delay permitted, large exposure and concentration reporting to the Central Bank, operational incident notification on a strict 4-hour/24-hour/72-hour clock, and periodic disclosure and provisioning reports. This page maps what's actually required in the UAE, where the deepest and most current regulatory detail sits, with a lighter, appropriately hedged view of how the pattern extends across the wider Gulf region.

Why "Regulatory Reporting" Isn't One Thing

Ask a GRC leader at a Middle East bank to describe their regulatory reporting obligations, and the honest answer is a list, not a single process: suspicious transactions to the Financial Intelligence Unit, large exposures and concentration data to the Central Bank, operational incidents on a strict notification clock, provisioning and credit risk data, and periodic public disclosures. Each of these lives under a different law, has a different trigger, and often reports to a different recipient system entirely.

Treating "regulatory reporting" as one function to be staffed and resourced uniformly is a common structural mistake. The obligations genuinely don't behave the same way, an AML suspicious transaction report has no minimum threshold and no tolerance for delay, while a large exposure report is a scheduled, threshold-triggered submission. A GRC team's reporting architecture needs to reflect that difference, not flatten it.

The UAE Reporting Landscape, by Regime

Suspicious Transaction and Activity Reporting (AML/CFT). Governed currently by Federal Decree-Law No. (10) of 2025 and its implementing Cabinet Resolution No. (134) of 2025, which updated the earlier AML-CFT framework. Licensed Financial Institutions must report a Suspicious Transaction Report (STR) or Suspicious Activity Report (SAR) to the UAE Financial Intelligence Unit (FIU) via the goAML platform whenever there are reasonable grounds to suspect a transaction, attempted transaction, or funds are connected to a crime — with no minimum reporting threshold and no permitted delay. Failure to report, whether intentional or through gross negligence, is a federal crime carrying a fine of AED 100,000 to AED 1,000,000 and/or imprisonment.

Large Exposures and Concentration Reporting. Under the Large Exposures Regulation (Circular C 1/2023), banks must report to the Central Bank all exposures at or above 10% of Tier 1 capital, both with and without credit risk mitigation applied, all exempted exposures above that threshold, the largest 20 exposures regardless of size, and exposures by sector, country, and currency (Article 5). This reporting is scheduled and threshold-triggered, not event-driven.

Operational Incident Notification. Under the Operational Risk Management Regulation (Circular C 1/2026, effective 14 September 2026), institutions must notify the Central Bank within 4 hours of an event significantly affecting Critical Operations, provide a summary report within 24 hours, confirm return to normal operations, and separately notify within 72 hours of any incident classified as high-risk (Article 15.2–15.3).

Credit Risk and Provisioning Reporting. Under the Credit Risk Management Regulation (Circular C 3/2024, effective 30 November 2024), institutions must maintain and report provisioning calculations consistent with the regulation's minimum acceptable practices, reviewed and revised as credit profiles change.

Public Disclosure. Under Article 16 of the Operational Risk Management Regulation, institutions must publicly disclose key information about their Operational Risk and Resilience approach, commensurate with size, complexity, and systemic importance — a standing, not incident-driven, obligation.

Comparison: Reporting Obligations Side by Side

ObligationGoverning InstrumentTriggerTimelineRecipient
Suspicious Transaction/Activity ReportFederal Decree-Law No. 10/2025, Cabinet Resolution 134/2025Reasonable grounds for suspicion, any amountWithout delay, no minimum thresholdUAE FIU via goAML
Large exposure reportLarge Exposures Regulation, C 1/2023, Art. 5Exposure at/above 10% of Tier 1 capitalPer Central Bank reporting scheduleCBUAE
Operational incident notificationOperational Risk Management Regulation, C 1/2026, Art. 15Event significantly affecting a Critical Operation4hr initial, 24hr summary, 72hr for high-riskCBUAE
Credit risk/provisioning reportCredit Risk Management Regulation, C 3/2024Standing obligation, reviewed on trigger eventsPer reporting cycleCBUAE
Public disclosureOperational Risk Management Regulation, Art. 16Standing obligationPeriodic, per institution's disclosure policyPublic / stakeholders

Who Owns What

  • AML/CFT Compliance Officer (MLRO) — owns STR/SAR filing decisions and goAML platform management; this role carries personal accountability under the AML-CFT framework.
  • Credit Risk / Group Risk — owns large exposure aggregation and reporting, and credit risk provisioning reporting.
  • Operational Risk Function — owns incident classification and the notification clock under the Operational Risk Management Regulation.
  • Compliance / GRC Leadership — owns the disclosure policy and typically coordinates across the other functions to ensure the Board has a consolidated view of reporting performance.
  • Board and Senior Management — receive regular reporting on breaches or expected breaches of risk appetite thresholds, and bear ultimate responsibility for the frameworks that produce these reports.
  • Central Bank of the UAE / UAE FIU — the two primary regulatory recipients, though a given institution's Central Bank reporting requirements may extend further via case-by-case requests.

Expert Insight: The Deadline That Doesn't Forgive

Most regulatory reporting obligations in UAE banking have some flexibility built in — reporting cycles, materiality thresholds, or reasonable-efforts standards. Suspicious transaction reporting has none of that. There is no minimum reporting threshold — a suspicious transaction of any size must be reported — and the requirement is to report "without delay," which UAE FIU guidance interprets as as soon as reasonably possible after the transaction takes place or the suspicion develops, not at the next scheduled reporting interval.

This creates a structural tension GRC leaders need to manage deliberately: an institution can have excellent large exposure reporting, sound operational incident notification discipline, and still carry serious regulatory risk if suspicious transaction detection and escalation is slow, because this is the one reporting obligation where "we were going to report it next cycle" is not a defense — failure to report, even through gross negligence rather than intent, is itself a federal crime. A GRC function's resourcing and escalation design should reflect that this obligation, more than any other on this page, cannot be batched or scheduled around.

Practical Example: One Transaction, Two Reporting Clocks

A bank's transaction monitoring system flags an unusual pattern of transfers linked to a corporate customer at 2:00 PM. The compliance analyst investigating the alert determines by 4:30 PM that there are reasonable grounds to suspect the transactions may be connected to a predicate offense. Under the AML-CFT framework, the clock to file an STR via goAML starts now — "without delay" means the filing should happen as soon as reasonably possible, not at the end of the business day or the next compliance committee meeting.

Separately, if the same pattern also involves a disruption to the bank's payment processing — for instance, the monitoring system itself experiencing degraded performance while investigating the volume of flagged activity — a second, entirely independent clock may start under the Operational Risk Management Regulation: 4 hours to notify the Central Bank if the disruption significantly affects a Critical Operation. These two obligations, triggered by related but distinct facts, report to two different recipients, on two different bases, and a GRC function needs a structure that can run both without either one being delayed by attention paid to the other.

Reporting Readiness Checklist

  • Institution registered and active on the goAML platform, with current authorized users
  • Internal escalation path for suspicious activity detection to STR/SAR filing decision documented, with no reliance on scheduled batch reporting
  • Large exposure aggregation methodology current and tested against the 10% Tier 1 capital threshold and Group of Connected Counterparties rules
  • Operational incident severity classification criteria defined and Board-approved, ahead of any live incident
  • Incident notification workflow built to meet the 4-hour/24-hour/72-hour timelines under the Operational Risk Management Regulation
  • Credit risk provisioning reporting aligned with the Credit Risk Management Regulation's current minimum practices
  • Public disclosure policy current and covering the required Operational Risk and Resilience information
  • Internal references to "the AML-CFT Law" confirmed as pointing to Federal Decree-Law No. 10/2025, not the superseded 2018/2021 instrument
  • Reporting ownership clearly assigned across MLRO, credit risk, operational risk, and compliance functions, with a coordination mechanism for overlapping incidents

Controls and Evidence Mapping

Reporting AreaGoverning RequirementEvidence to MaintainTypical Owner
STR/SAR filingFederal Decree-Law 10/2025goAML submission records, internal escalation logsMLRO / Compliance
Large exposure reportingLarge Exposures Regulation, Art. 5Exposure aggregation records, submission historyCredit Risk / Group Risk
Incident notificationOperational Risk Management Regulation, Art. 15Notification logs against 4hr/24hr/72hr timelinesOperational Risk
Credit provisioning reportingCredit Risk Management Regulation, C 3/2024Provisioning calculations and rationaleCredit Risk
Public disclosureOperational Risk Management Regulation, Art. 16Published disclosure records, review historyCompliance / GRC

Consolidate your regulatory reporting view

See how Ascent helps risk and compliance teams track obligations, deadlines, and evidence in one place.

Request a Demo →

Regulatory Reporting Maturity Model

DimensionLevel 1: Ad HocLevel 2: DevelopingLevel 3: ManagedLevel 4: Optimized
STR/SAR escalation speedReviewed at scheduled intervalsEscalation path exists but inconsistently followedConsistent same-day escalation and filingReal-time monitoring-to-filing integration
Large exposure aggregationManual, facility-by-facilityAggregated periodically, error-proneSystematic aggregation per Group of Connected CounterpartiesReal-time aggregation integrated into origination
Incident notificationNo defined severity criteriaCriteria exist but timelines inconsistently met4hr/24hr/72hr timelines consistently metNotification triggers built into monitoring systems
Cross-functional coordinationEach reporting obligation managed in isolationSome informal coordinationDefined coordination protocol for overlapping incidentsUnified reporting dashboard across obligations
Regulatory currencyReferences to superseded laws/circulars persistPeriodic manual review of regulatory currencyScheduled review cycle for all cited instrumentsAutomated tracking of regulatory updates

A candid self-assessment against these dimensions, rather than an assumption about industry norms, is the appropriate starting point for any GRC function reviewing its reporting architecture.

Best Practices

  • Resource suspicious transaction escalation separately from scheduled reporting functions — it cannot be batched, and treating it like a periodic report understates its urgency.
  • Maintain a single internal register of every distinct reporting obligation, its governing instrument, trigger, timeline, and recipient — the fragmentation described in this guide is the norm, not the exception, and needs to be made visible internally.
  • Build a coordination protocol for incidents that trigger more than one reporting obligation simultaneously, so attention to one doesn't delay the other.
  • Review all internal policy references to governing laws and regulations on a fixed cycle, given how frequently UAE financial regulation has been updated in recent years.
  • Give the Board a consolidated reporting-performance view spanning all obligations, not separate updates from each function in isolation.

Common Mistakes

Treating suspicious transaction reporting like a scheduled compliance task. The "without delay" standard and absence of a minimum threshold mean this obligation needs continuous, not periodic, attention.

Letting internal documentation cite superseded legislation. References to the 2018/2021 AML-CFT framework that haven't been updated to Federal Decree-Law No. 10/2025 create both a compliance risk and a credibility problem with regulators and auditors.

Managing each reporting obligation in a silo. Large exposure reporting, incident notification, and STR filing are often owned by entirely separate teams with no shared incident view — missing the fact that a single underlying event can trigger more than one.

Confusing large exposure reporting thresholds with STR reporting thresholds. These are entirely different regimes — one has a specific percentage trigger, the other has none — and conflating them in internal training materials creates real confusion for staff.

Common Challenges at Scale

Coordinating reporting across multiple business lines and legal entities. A banking group with several licensed entities in the UAE needs consistent reporting discipline across all of them, not just the parent.

Keeping pace with a genuinely fast-moving regulatory environment. UAE financial regulation has seen substantial updates in recent years — the AML-CFT law, the Credit Risk Management Regulation, the Large Exposures Regulation, and the Operational Risk Management Regulation have all been issued or substantially revised within a few years of each other.

Balancing speed and accuracy under the "without delay" STR standard. Fast escalation must not come at the cost of the quality of the suspicion assessment — building both speed and rigor into the same process is a genuine operational challenge.

Maintaining goAML platform proficiency across a large compliance team. Staff turnover and platform updates both create a recurring, not one-time, training need.

Expert Tip

Expert tip

When auditing a GRC function's reporting readiness, don't start by asking "are we compliant?" Start by asking "can we name, right now, every distinct reporting obligation we carry, its trigger, its timeline, and its owner?" A function that can answer that cleanly is almost always the one that's actually meeting its deadlines — the ones that struggle are consistently the ones where reporting obligations have never been mapped as a complete, distinct list.

Use Cases

A bank consolidating its regulatory reporting register. Building the single internal list of every distinct obligation, its governing instrument, and its owner, as a foundation for audit readiness.

A compliance team updating policy references after a legal framework change. Systematically reviewing all internal documentation citing AML-CFT, credit risk, or operational risk regulations to confirm current instrument references.

A GRC leader building a Board reporting pack. Structuring a consolidated view across STR filing performance, large exposure status, incident notification timeliness, and disclosure currency.

An institution expanding into a new Gulf jurisdiction. Confirming that reporting obligations do not transfer automatically from the UAE and require jurisdiction-specific verification.

The Wider Region: What Extends and What Doesn't

The pattern seen in the UAE — a central bank or monetary authority setting increasingly granular, increasingly time-sensitive reporting requirements — is broadly consistent across the Gulf, but the specific rules, deadlines, and platforms are not interchangeable.

In Saudi Arabia, the Saudi Central Bank (SAMA) regulates banks, finance companies, and insurers under its own framework, including the Banking Control Law and Finance Companies Control Law, with AML/CFT reporting governed by Saudi Arabia's Anti-Money Laundering Law and SAMA's own implementing AML/CTF guidance. SAMA has been moving toward greater reporting granularity — reportedly issuing a substantial number of regulatory reporting updates for credit institutions in recent years — and conducts examinations with frequency tied to institutional size and complexity.

For a GRC function operating across both the UAE and Saudi Arabia, or elsewhere in the Gulf, the safe assumption is that no reporting obligation transfers automatically between jurisdictions. Each central bank or monetary authority maintains its own reporting platform, its own thresholds, and its own enforcement regime. This page's UAE detail is verified against primary CBUAE and UAE FIU source text; any SAMA-specific compliance program should be built on SAMA's own current rulebook and specialist local advice, not extrapolated from the UAE picture.

Building or Strengthening the Reporting Function

  1. Build the complete reporting obligation register — every distinct requirement, its governing law, trigger, timeline, and current owner.
  2. Audit internal policy documents for outdated legal references, particularly around the AML-CFT framework given the 2025 legislative update.
  3. Separate suspicious transaction escalation from scheduled reporting workflows in both process design and resourcing.
  4. Build a cross-functional coordination protocol for incidents that trigger more than one reporting obligation.
  5. Establish a fixed review cycle for regulatory currency across all cited instruments.
  6. Confirm jurisdiction-specific requirements separately for any operations outside the UAE, rather than assuming regional consistency.

Metrics to Track

  • Time from suspicious activity detection to STR/SAR filing, tracked as a distribution, not just an average
  • Large exposure reporting submissions completed on schedule vs. total due
  • Operational incident notifications meeting the 4-hour/24-hour/72-hour timelines vs. total qualifying incidents
  • Number of internal policy documents with confirmed-current regulatory citations vs. total reviewed
  • Number of reporting obligations with a named, current owner in the reporting register

How autoResilience Supports Regulatory Reporting

autoResilience is an integrated Governance, Risk, Compliance and Resilience platform. The core difficulty most GRC functions face with regulatory reporting isn't any single obligation in isolation — it's the fragmentation described throughout this page: distinct reporting regimes, owned by different teams, tracked in different systems, with no consolidated view of overall reporting health.

Within autoResilience, a GRC function can maintain a centralized reporting obligation register mapped to each governing instrument, track submission and notification timelines against their regulatory deadlines, and give the Board a consolidated view across AML/CFT, large exposure, operational incident, and disclosure reporting rather than separate updates from each function. Dashboards can surface overdue submissions, approaching deadlines, and outdated regulatory references before they become audit findings.

This does not replace the judgment of the MLRO in assessing suspicion, or the specific expertise required to interpret any individual regulation. What it can do is help the institution maintain the shared visibility and evidence trail that a genuinely fragmented reporting landscape requires.

Explore how autoResilience can support your institution's regulatory reporting program.

Related Resources

  • UAE Financial Intelligence Unit — Compliance & Guidance, goAML platform access
  • Central Bank of the UAE Rulebook — Large Exposures Regulation, Credit Risk Management Regulation, Operational Risk Management Regulation
  • Internal: Operational resilience obligations for BFSI institutions in the UAE
  • Internal: Developer risk management for real estate lending banks
  • autoResilience GRC platform — reporting obligation and evidence management

Frequently Asked Questions

Is there a minimum transaction amount before a suspicious transaction must be reported?

No. There is no minimum reporting threshold under the UAE's AML-CFT framework — all suspicious transactions, including attempted transactions, must be reported regardless of amount.

What law currently governs AML/CFT reporting in the UAE?

Federal Decree-Law No. (10) of 2025 is the current principal AML/CFT/CPF legislation, with Cabinet Resolution No. (134) of 2025 as its implementing regulation, replacing the earlier Federal Decree-Law No. 20 of 2018 as amended by No. 26 of 2021.

What happens if an institution fails to file a required suspicious transaction report?

It is a federal crime, whether the failure was intentional or through gross negligence, carrying a fine of no less than AED 100,000 and no more than AED 1,000,000, and/or imprisonment.

How fast must an operational incident be reported to the Central Bank?

Within 4 hours for initial notification of an event significantly affecting a Critical Operation, with a 24-hour summary report, and within 72 hours for any incident classified as high-risk.

Do the UAE's reporting rules apply the same way in Saudi Arabia or other Gulf countries?

No. Each jurisdiction's central bank or monetary authority — SAMA in Saudi Arabia, for example — maintains its own reporting framework, thresholds, and platforms. Reporting obligations should be verified separately for each jurisdiction an institution operates in.

About the Author

Shambhavi Singh

Shambhavi Singh

Marketing Executive, Ascent Risk & Resilience

Shambhavi Singh is a Marketing Executive at Ascent Risk & Resilience, where she contributes to brand communication, content strategy, and digital storytelling across the organization's risk and resilience solutions. With a background spanning content writing, voice-over artistry, anchoring, public speaking, and social impact, she brings both creativity and clarity to every message she crafts.

Shambhavi's passion for communication started early in her hometown of Varanasi, where her curiosity for culture and heritage shaped her worldview. A natural storyteller and confident speaker, she has built a strong presence as a social media writer and continues to use her voice to inform, inspire, and engage audiences.

Driven by a blend of will and skill, she is committed to building meaningful connections, leading with empathy, and contributing to initiatives that create positive change. A social worker at heart and a marketer by profession, Shambhavi combines creativity, purpose, and leadership in everything she does.

We're here to help