UAE SME Banking Rules Take Effect With AML Due Diligence Override

The Central Bank of the UAE’s new Small to Medium Sized Enterprises (SME) Customer Protection Regulation, C 2/2026, took effect on 13 September 2026, replacing the previous SME Market Conduct Regulation.
The regulation introduces a three-business-day account-opening requirement for SME applicants that a financial institution has assessed as presenting low money laundering and terrorist financing risk, provided the institution is satisfied with standard customer due diligence documentation.
However, the deadline does not override financial crime controls. The regulation expressly waives the three-day requirement where a financial institution is complying with UAE Financial Crime Compliance requirements. Any such waiver must be adequately documented and reported to senior management.
AML risk assessment remains decisive
When considering an SME account application, financial institutions must apply the risk-based approach required under the UAE’s Federal Decree-Law No. 10 of 2025 on anti-money laundering and combating terrorist and proliferation financing.
The regulation also makes clear that opening an account does not automatically mean all transactions must be enabled. Before permitting transactions, institutions must complete the appropriate due diligence required for financial crime compliance, including risk-based controls and sanctions screening.
For low-risk applicants whose account applications have been accepted but where non-financial-crime issues cause additional delay, institutions may provide an account number while temporarily limiting transactions. Such restrictions can include limits on transaction volumes or prohibitions on transfers, remittances or cheques, and the delay generally must not exceed two weeks.
What the change means for compliance teams
The framework creates a clearer distinction between customer-service timelines and AML/CFT obligations. Faster onboarding is expected for genuinely low-risk SMEs with complete documentation, but financial institutions retain the ability—and obligation—to slow or restrict onboarding where financial crime risks require further review.
In practice, this increases the importance of consistent customer risk classification, documented escalation decisions and efficient CDD workflows. Institutions will need to demonstrate why an applicant qualified for the three-day pathway, or why AML/CFT concerns justified an exception.
The regulation is primarily a customer-protection measure rather than a new standalone AML/CFT law. Its significance for financial crime compliance is that it formally embeds AML risk assessment and due diligence safeguards into the account-opening timetable for SME customers.
Sources
Central Bank of the UAE Rulebook, Small to Medium Sized Enterprises (SME) – Customer Protection Regulation, C 2/2026.



