What training and competence rules does the DFSA apply?
The Dubai Financial Services Authority (DFSA) requires firms in the Dubai International Financial Centre to ensure relevant employees are fit and proper, competent, and trained in DIFC legislation, with records to prove it. Senior Executive Officers, Compliance Officers and Money Laundering Reporting Officers need 15 hours of structured CPD a year. Separate rules require regular AML training and annual cybersecurity training, and firms must review Authorized Individuals' competence at least annually.
By the Knowledge Foundry editorial team. How we write and check these pages
- Published
- Updated
- Reading time
- 10 min
- Jurisdiction
- United Arab Emirates: Dubai International Financial Centre (DIFC)
- Regulator
- Dubai Financial Services Authority (DFSA)
Key takeaways
- There is no standalone training and competence module in the DFSA Rulebook as at September 2026. The obligations sit mainly in the General Module (GEN) and the Anti-Money Laundering, Counter-Terrorist Financing and Sanctions Module (AML).
- GEN Rule 5.3.19 requires Authorized Firms to ensure, as far as reasonably practical, that Relevant Employees are fit and proper, competent, and trained in DIFC legislation, and to keep records that demonstrate it.
- GEN Rule 5.3.19A sets a minimum of 15 hours of structured CPD each calendar year for the Senior Executive Officer, Compliance Officer and Money Laundering Reporting Officer.
- From July 1, 2026, firms must assess an individual's fitness and propriety, including competence, before applying for Authorized Individual status, and must review it at least annually, keeping records for six years.
- AML Rule 12.1.1 and GEN Rule 5.5.14 add specific AML training content and at least annual cybersecurity training for relevant Employees.
Why does the DIFC have its own training rules?
The DIFC is a financial free zone with its own regulator, so firms licensed there follow the DFSA Rulebook rather than the rules of onshore UAE financial regulators. The DFSA describes itself as the independent regulator of financial services conducted in or from the DIFC, "a purpose-built financial free zone in Dubai, UAE".
For international readers, the UAE has two broad layers. Onshore, federal laws and federal regulators apply across the seven emirates. Financial free zones, chiefly the DIFC in Dubai and Abu Dhabi Global Market (ADGM), have their own financial services regulators and rulebooks. Federal criminal law still reaches into the free zones: the DFSA states that Federal Anti-Money Laundering Legislation applies directly in the DIFC under Articles 70 and 71 of the Regulatory Law, and that the DFSA is the competent authority administering it for DIFC firms.
In practice a DIFC firm maps three sources into its training program: the DFSA Rulebook, federal AML legislation (see UAE AML/CFT training requirements), and DIFC laws administered by other DIFC bodies, such as the data protection regime covered in DIFC Data Protection Law training.
Where are the DFSA's training and competence rules?
The rules are spread across the General Module and the AML module; the current list of Rulebook modules contains no separate training and competence module. The table sets out the provisions that matter most for training design, as at September 2026.
| Provision | Who it covers | What it requires |
|---|---|---|
| GEN 5.3.19 | Relevant Employees of an Authorized Firm | Fit and proper, competent and capable for assigned functions, and trained in DIFC legislation; systems and controls plus records to demonstrate compliance |
| GEN 5.3.19A | Senior Executive Officer, Compliance Officer, Money Laundering Reporting Officer | At least 15 hours of CPD each calendar year, relevant to role and skills, made up of structured activities, with adequate records |
| GEN 7.6.1 and GEN App7 | Individuals proposed for Authorized Individual status | Firm must be satisfied the individual is fit and proper, including competence and capability, before applying to the DFSA |
| GEN 7.7.1 to 7.7.3 | Authorized Individuals | Ongoing competence and currency of knowledge, reviewed at least annually, with records kept for six years |
| GEN 5.5.14 | All relevant Employees of an Authorized Person | Cybersecurity training at least annually and awareness of how to detect and report Cyber Incidents |
| AML 12.1.1 and AML 14.4.5 | All relevant Employees of a Relevant Person | AML training at appropriate and regular intervals, with defined content, tailored to the business, evidenced by training records |
What does GEN 5.3.19 require for employee competence?
GEN Rule 5.3.19 requires an Authorized Firm to ensure, as far as reasonably practical, that its Relevant Employees are fit and proper, competent and capable of performing their assigned functions, and "trained in the requirements of the legislation applicable in the DIFC". The firm must maintain systems and controls to achieve this and "must be able to demonstrate that it has complied with these requirements through appropriate measures, including the maintenance of relevant records" (GEN 5.3.19).
The version in force from July 1, 2026 refers to Relevant Employees; the earlier version referred to all Employees. A Relevant Employee is an Employee other than an Authorized Individual who meets the criteria in GEN Rule 4.3.1(2): involvement in Financial Services business, activities connected with it, or managing the firm. DFSA guidance on GEN 4.3.1 gives front office sales and trading and back office compliance and accounting as examples, and says drivers, personal assistants and similar roles would not ordinarily be covered.
The word "demonstrate" is the practical center of the rule. A completion log alone shows attendance, not competence. Firms should hold a role based competency framework, assessment results, and dated evidence that content reflected the legislation in force at the time.
How much CPD do DFSA key officers need?
The Senior Executive Officer, Compliance Officer and Money Laundering Reporting Officer must each complete at least 15 hours of continuing professional development (CPD) in each calendar year under GEN Rule 5.3.19A. The firm, not only the individual, is responsible for ensuring this happens.
- Relevance: CPD must relate to the person's current role, any anticipated change in that role, and their professional skill and knowledge.
- Structure: it must consist of structured activities, defined as courses, seminars, lectures, conferences, workshops, web based seminars or e-learning requiring a commitment of thirty minutes or more.
- Records: the Employee must keep adequate records of CPD activities to demonstrate that the requirement has been met.
Reading and informal learning under thirty minutes does not count toward the 15 hours. A CPD log should therefore capture the activity, its duration, its provider, and a short note on its relevance to the role.
What AML and cybersecurity training does the DFSA require?
AML Rule 12.1.1 requires a Relevant Person to provide AML training to all relevant Employees at appropriate and regular intervals, and GEN Rule 5.5.14 requires cybersecurity training for relevant Employees at least annually. Both rules specify content, not just frequency.
Under AML 12.1.1, training must enable Employees to understand relevant money laundering legislation (including Federal AML legislation), the firm's policies and controls and changes to them, how to recognize and deal with suspicious transactions, how to notify the Money Laundering Reporting Officer (MLRO), current money laundering techniques and trends relevant to the business, their own roles including the identity of the MLRO, and relevant sanctions and international findings. Training must be tailored to the firm's products, services, customers, channels and transaction complexity, and indicate different levels of risk. AML 14.4.5 requires the firm to be able to demonstrate compliance, including through training records.
GEN 5.5.14 states that an Authorized Person "must establish and maintain a comprehensive cybersecurity training programme and adequate awareness arrangements". All relevant Employees must receive training on the firm's cybersecurity policies and standards at least annually, develop awareness and competencies for detecting and reporting Cyber Incidents, and understand their individual responsibilities.
How do DFSA obligations map to learning outcomes and evidence?
Each DFSA obligation can be translated into a testable learning outcome and a specific evidence record that a supervisor could inspect. The mapping below is illustrative and should be adapted to the firm's own risk assessment.
| Obligation | Example learning outcome | Assessment evidence |
|---|---|---|
| GEN 5.3.19 training in DIFC legislation | Explain which Rulebook conduct and client rules apply to the employee's role | Role based scenario assessment, dated content version, pass record |
| GEN 5.3.19A CPD | Maintain current knowledge relevant to SEO, Compliance Officer or MLRO duties | CPD log with activity, provider, duration of thirty minutes or more, and relevance note; 15 hour annual total |
| GEN 7.7.1 ongoing competence | Apply recent regulatory and product developments to the individual's function | Annual competence review signed off by the firm, retained for six years |
| AML 12.1.1(b)(iv) and (v) | Identify red flags typical of the firm's business and escalate to the MLRO correctly | Case based test using the firm's own products, escalation walkthrough, completion record |
| GEN 5.5.14 cybersecurity | Recognize and report a suspected Cyber Incident using the firm's procedure | Annual training record, phishing or reporting exercise results |
This is the gap between completion tracking and competency verification. The DFSA's rules ask firms to show competence and currency, so records should link each person to the obligation, the outcome, the assessment and the content version. The guide on preparing training records for an audit covers how to structure that evidence, and verification of competency explains how to confirm people can apply what they learned.
What happens if a firm or individual falls short?
Weak training and competence controls expose both the firm and its individuals to DFSA supervisory and disciplinary action. DFSA guidance on GEN 4.3.1 states that breaching a Conduct Principle makes an individual liable to disciplinary action and may indicate the individual is no longer fit and proper, in which case the DFSA may consider suspending or withdrawing Authorized Individual status or imposing restrictions under Articles 58 and 59 of the Regulatory Law.
For the firm, GEN 5.3.19, GEN 7.7.3 and AML 14.4.5 all turn on demonstrable records. Missing CPD logs, undated content, or annual reviews that were never documented are the gaps a supervisory visit is most likely to find.
How does Knowledge Foundry approach this?
Knowledge Foundry models DFSA obligations, the roles they apply to, and the learning outcomes and assessment points that evidence them before any content is written. Each record then links a person to the rule version, content version and assessment result, so annual reviews and CPD evidence can be produced for a supervisor from one governed source.
Frequently asked questions
Does the DFSA still have a Training and Competence module?
No. As at September 2026 the DFSA Rulebook module list has no separate training and competence module. Training and competence obligations sit in the General Module, mainly GEN 5.3.19, GEN 5.3.19A, GEN 5.5.14, GEN 7.6, GEN 7.7 and GEN App7, and in chapters 12 and 14 of the AML module.
Do DFSA rules set a fixed frequency for AML training?
AML Rule 12.1.1 requires AML training at appropriate and regular intervals rather than a fixed frequency. Many firms train annually, with extra sessions when policies, typologies or sanctions change, but the rule leaves the interval to the firm's risk based judgment. The guide on setting refresh cycles covers how to justify an interval.
Can e-learning count toward the 15 hours of CPD?
Yes. GEN Rule 5.3.19A lists e-learning, alongside courses, seminars, lectures, conferences, workshops and web based seminars, as a structured activity, provided each activity requires a commitment of thirty minutes or more and is relevant to the person's role and professional skill and knowledge.
Do these DFSA rules apply to firms in ADGM or onshore UAE?
No. The DFSA Rulebook applies to firms regulated by the DFSA in or from the DIFC. ADGM has its own financial services regulator and rules, and onshore financial institutions are supervised by federal authorities. Federal AML legislation, however, applies across the UAE, including the DIFC.
Sources
- GEN 5.3.19 (systems and controls: staff and agents), Dubai Financial Services Authority (DFSA)
- GEN 5.3.19A (Continuing Professional Development), Dubai Financial Services Authority (DFSA)
- GEN 7.6.1 (Application for Authorised Individual status), Dubai Financial Services Authority (DFSA)
- GEN A7.1.1 (Assessing the fitness and propriety of Authorised Individuals), Dubai Financial Services Authority (DFSA)
- GEN 7.5.1 (Mandatory appointments), Dubai Financial Services Authority (DFSA)
- GEN 7.7.1 (Ongoing requirements in relation to Authorised Individuals), Dubai Financial Services Authority (DFSA)
- GEN 7.7.3 (records of assessment), Dubai Financial Services Authority (DFSA)
- GEN 5.5.14 (cyber risk management: training and awareness), Dubai Financial Services Authority (DFSA)
- AML 12.1.1 (AML training and awareness), Dubai Financial Services Authority (DFSA)
- AML 14.4.5 (record keeping: training records), Dubai Financial Services Authority (DFSA)
- GEN 4.3.1 and Guidance (Conduct Principles for individuals: application), Dubai Financial Services Authority (DFSA)
- Glossary: Relevant Employee, Dubai Financial Services Authority (DFSA)
- Notice of Amendments to Legislation December 2025, Dubai Financial Services Authority (DFSA)
- DFSA Rulebook modules, Dubai Financial Services Authority (DFSA)
- About the DFSA, Dubai Financial Services Authority (DFSA)
- Overview of DFSA AML/CTF and Sanctions Obligations, Dubai Financial Services Authority (DFSA)
This page is general information, not legal or compliance advice. Check the primary sources above and obtain advice for your circumstances. See our editorial standards.