Regulation and standard

What training and competence rules does the DFSA apply?

Short answer

The Dubai Financial Services Authority (DFSA) requires firms in the Dubai International Financial Centre to ensure relevant employees are fit and proper, competent, and trained in DIFC legislation, with records to prove it. Senior Executive Officers, Compliance Officers and Money Laundering Reporting Officers need 15 hours of structured CPD a year. Separate rules require regular AML training and annual cybersecurity training, and firms must review Authorized Individuals' competence at least annually.

By the Knowledge Foundry editorial team. How we write and check these pages

Published
Updated
Reading time
10 min
Jurisdiction
United Arab Emirates: Dubai International Financial Centre (DIFC)
Regulator
Dubai Financial Services Authority (DFSA)

Key takeaways

  • There is no standalone training and competence module in the DFSA Rulebook as at September 2026. The obligations sit mainly in the General Module (GEN) and the Anti-Money Laundering, Counter-Terrorist Financing and Sanctions Module (AML).
  • GEN Rule 5.3.19 requires Authorized Firms to ensure, as far as reasonably practical, that Relevant Employees are fit and proper, competent, and trained in DIFC legislation, and to keep records that demonstrate it.
  • GEN Rule 5.3.19A sets a minimum of 15 hours of structured CPD each calendar year for the Senior Executive Officer, Compliance Officer and Money Laundering Reporting Officer.
  • From July 1, 2026, firms must assess an individual's fitness and propriety, including competence, before applying for Authorized Individual status, and must review it at least annually, keeping records for six years.
  • AML Rule 12.1.1 and GEN Rule 5.5.14 add specific AML training content and at least annual cybersecurity training for relevant Employees.

Why does the DIFC have its own training rules?

The DIFC is a financial free zone with its own regulator, so firms licensed there follow the DFSA Rulebook rather than the rules of onshore UAE financial regulators. The DFSA describes itself as the independent regulator of financial services conducted in or from the DIFC, "a purpose-built financial free zone in Dubai, UAE".

For international readers, the UAE has two broad layers. Onshore, federal laws and federal regulators apply across the seven emirates. Financial free zones, chiefly the DIFC in Dubai and Abu Dhabi Global Market (ADGM), have their own financial services regulators and rulebooks. Federal criminal law still reaches into the free zones: the DFSA states that Federal Anti-Money Laundering Legislation applies directly in the DIFC under Articles 70 and 71 of the Regulatory Law, and that the DFSA is the competent authority administering it for DIFC firms.

In practice a DIFC firm maps three sources into its training program: the DFSA Rulebook, federal AML legislation (see UAE AML/CFT training requirements), and DIFC laws administered by other DIFC bodies, such as the data protection regime covered in DIFC Data Protection Law training.

Where are the DFSA's training and competence rules?

The rules are spread across the General Module and the AML module; the current list of Rulebook modules contains no separate training and competence module. The table sets out the provisions that matter most for training design, as at September 2026.

DFSA Rulebook provisions that drive training and competence (as at September 2026)
ProvisionWho it coversWhat it requires
GEN 5.3.19Relevant Employees of an Authorized FirmFit and proper, competent and capable for assigned functions, and trained in DIFC legislation; systems and controls plus records to demonstrate compliance
GEN 5.3.19ASenior Executive Officer, Compliance Officer, Money Laundering Reporting OfficerAt least 15 hours of CPD each calendar year, relevant to role and skills, made up of structured activities, with adequate records
GEN 7.6.1 and GEN App7Individuals proposed for Authorized Individual statusFirm must be satisfied the individual is fit and proper, including competence and capability, before applying to the DFSA
GEN 7.7.1 to 7.7.3Authorized IndividualsOngoing competence and currency of knowledge, reviewed at least annually, with records kept for six years
GEN 5.5.14All relevant Employees of an Authorized PersonCybersecurity training at least annually and awareness of how to detect and report Cyber Incidents
AML 12.1.1 and AML 14.4.5All relevant Employees of a Relevant PersonAML training at appropriate and regular intervals, with defined content, tailored to the business, evidenced by training records

What does GEN 5.3.19 require for employee competence?

GEN Rule 5.3.19 requires an Authorized Firm to ensure, as far as reasonably practical, that its Relevant Employees are fit and proper, competent and capable of performing their assigned functions, and "trained in the requirements of the legislation applicable in the DIFC". The firm must maintain systems and controls to achieve this and "must be able to demonstrate that it has complied with these requirements through appropriate measures, including the maintenance of relevant records" (GEN 5.3.19).

The version in force from July 1, 2026 refers to Relevant Employees; the earlier version referred to all Employees. A Relevant Employee is an Employee other than an Authorized Individual who meets the criteria in GEN Rule 4.3.1(2): involvement in Financial Services business, activities connected with it, or managing the firm. DFSA guidance on GEN 4.3.1 gives front office sales and trading and back office compliance and accounting as examples, and says drivers, personal assistants and similar roles would not ordinarily be covered.

The word "demonstrate" is the practical center of the rule. A completion log alone shows attendance, not competence. Firms should hold a role based competency framework, assessment results, and dated evidence that content reflected the legislation in force at the time.

How much CPD do DFSA key officers need?

The Senior Executive Officer, Compliance Officer and Money Laundering Reporting Officer must each complete at least 15 hours of continuing professional development (CPD) in each calendar year under GEN Rule 5.3.19A. The firm, not only the individual, is responsible for ensuring this happens.

  • Relevance: CPD must relate to the person's current role, any anticipated change in that role, and their professional skill and knowledge.
  • Structure: it must consist of structured activities, defined as courses, seminars, lectures, conferences, workshops, web based seminars or e-learning requiring a commitment of thirty minutes or more.
  • Records: the Employee must keep adequate records of CPD activities to demonstrate that the requirement has been met.

Reading and informal learning under thirty minutes does not count toward the 15 hours. A CPD log should therefore capture the activity, its duration, its provider, and a short note on its relevance to the role.

What changed for Authorized Individuals on July 1, 2026?

From July 1, 2026, the firm carries the first line assessment of competence: it must not apply for Authorized Individual status unless it is satisfied the individual is fit and proper, assessed against GEN App7 (GEN 7.6.1). The changes came through GEN Rule-making Instrument No. 430 of 2025, made after Consultation Paper No. 165 and in force on July 1, 2026, according to the DFSA's December 2025 Notice of Amendments to Legislation.

GEN A7.1.1 requires the firm to consider integrity, competence and capability, financial soundness and proposed role. For competence, the firm must obtain details of the individual's knowledge and skills against those the role requires, verify the information, determine relevant qualifications and experience, and determine the individual's knowledge of the firm's relevant systems and procedures.

The ongoing duty is in GEN 7.7.1: the firm must be satisfied that each Authorized Individual remains fit and proper, continues to be competent, has kept abreast of relevant market, product, technology, legislative and regulatory developments, and is able to apply that knowledge. The assessment must be reviewed at least annually, and GEN 7.7.3 requires records of each assessment to be kept for at least six years and made available to the DFSA on request.

Mandatory appointments

Under GEN Rule 7.5.1, an Authorized Firm must appoint a Senior Executive Officer, Finance Officer, Compliance Officer and Money Laundering Reporting Officer, each held by an Authorized Individual at all times, subject to limited exceptions for credit rating agencies and venture capital fund managers.

What AML and cybersecurity training does the DFSA require?

AML Rule 12.1.1 requires a Relevant Person to provide AML training to all relevant Employees at appropriate and regular intervals, and GEN Rule 5.5.14 requires cybersecurity training for relevant Employees at least annually. Both rules specify content, not just frequency.

Under AML 12.1.1, training must enable Employees to understand relevant money laundering legislation (including Federal AML legislation), the firm's policies and controls and changes to them, how to recognize and deal with suspicious transactions, how to notify the Money Laundering Reporting Officer (MLRO), current money laundering techniques and trends relevant to the business, their own roles including the identity of the MLRO, and relevant sanctions and international findings. Training must be tailored to the firm's products, services, customers, channels and transaction complexity, and indicate different levels of risk. AML 14.4.5 requires the firm to be able to demonstrate compliance, including through training records.

GEN 5.5.14 states that an Authorized Person "must establish and maintain a comprehensive cybersecurity training programme and adequate awareness arrangements". All relevant Employees must receive training on the firm's cybersecurity policies and standards at least annually, develop awareness and competencies for detecting and reporting Cyber Incidents, and understand their individual responsibilities.

How do DFSA obligations map to learning outcomes and evidence?

Each DFSA obligation can be translated into a testable learning outcome and a specific evidence record that a supervisor could inspect. The mapping below is illustrative and should be adapted to the firm's own risk assessment.

Illustrative mapping of DFSA obligations to outcomes and evidence
ObligationExample learning outcomeAssessment evidence
GEN 5.3.19 training in DIFC legislationExplain which Rulebook conduct and client rules apply to the employee's roleRole based scenario assessment, dated content version, pass record
GEN 5.3.19A CPDMaintain current knowledge relevant to SEO, Compliance Officer or MLRO dutiesCPD log with activity, provider, duration of thirty minutes or more, and relevance note; 15 hour annual total
GEN 7.7.1 ongoing competenceApply recent regulatory and product developments to the individual's functionAnnual competence review signed off by the firm, retained for six years
AML 12.1.1(b)(iv) and (v)Identify red flags typical of the firm's business and escalate to the MLRO correctlyCase based test using the firm's own products, escalation walkthrough, completion record
GEN 5.5.14 cybersecurityRecognize and report a suspected Cyber Incident using the firm's procedureAnnual training record, phishing or reporting exercise results

This is the gap between completion tracking and competency verification. The DFSA's rules ask firms to show competence and currency, so records should link each person to the obligation, the outcome, the assessment and the content version. The guide on preparing training records for an audit covers how to structure that evidence, and verification of competency explains how to confirm people can apply what they learned.

What happens if a firm or individual falls short?

Weak training and competence controls expose both the firm and its individuals to DFSA supervisory and disciplinary action. DFSA guidance on GEN 4.3.1 states that breaching a Conduct Principle makes an individual liable to disciplinary action and may indicate the individual is no longer fit and proper, in which case the DFSA may consider suspending or withdrawing Authorized Individual status or imposing restrictions under Articles 58 and 59 of the Regulatory Law.

For the firm, GEN 5.3.19, GEN 7.7.3 and AML 14.4.5 all turn on demonstrable records. Missing CPD logs, undated content, or annual reviews that were never documented are the gaps a supervisory visit is most likely to find.

How does Knowledge Foundry approach this?

Knowledge Foundry models DFSA obligations, the roles they apply to, and the learning outcomes and assessment points that evidence them before any content is written. Each record then links a person to the rule version, content version and assessment result, so annual reviews and CPD evidence can be produced for a supervisor from one governed source.

Frequently asked questions

Does the DFSA still have a Training and Competence module?

No. As at September 2026 the DFSA Rulebook module list has no separate training and competence module. Training and competence obligations sit in the General Module, mainly GEN 5.3.19, GEN 5.3.19A, GEN 5.5.14, GEN 7.6, GEN 7.7 and GEN App7, and in chapters 12 and 14 of the AML module.

Do DFSA rules set a fixed frequency for AML training?

AML Rule 12.1.1 requires AML training at appropriate and regular intervals rather than a fixed frequency. Many firms train annually, with extra sessions when policies, typologies or sanctions change, but the rule leaves the interval to the firm's risk based judgment. The guide on setting refresh cycles covers how to justify an interval.

Can e-learning count toward the 15 hours of CPD?

Yes. GEN Rule 5.3.19A lists e-learning, alongside courses, seminars, lectures, conferences, workshops and web based seminars, as a structured activity, provided each activity requires a commitment of thirty minutes or more and is relevant to the person's role and professional skill and knowledge.

Do these DFSA rules apply to firms in ADGM or onshore UAE?

No. The DFSA Rulebook applies to firms regulated by the DFSA in or from the DIFC. ADGM has its own financial services regulator and rules, and onshore financial institutions are supervised by federal authorities. Federal AML legislation, however, applies across the UAE, including the DIFC.

Sources

  1. GEN 5.3.19 (systems and controls: staff and agents), Dubai Financial Services Authority (DFSA)
  2. GEN 5.3.19A (Continuing Professional Development), Dubai Financial Services Authority (DFSA)
  3. GEN 7.6.1 (Application for Authorised Individual status), Dubai Financial Services Authority (DFSA)
  4. GEN A7.1.1 (Assessing the fitness and propriety of Authorised Individuals), Dubai Financial Services Authority (DFSA)
  5. GEN 7.5.1 (Mandatory appointments), Dubai Financial Services Authority (DFSA)
  6. GEN 7.7.1 (Ongoing requirements in relation to Authorised Individuals), Dubai Financial Services Authority (DFSA)
  7. GEN 7.7.3 (records of assessment), Dubai Financial Services Authority (DFSA)
  8. GEN 5.5.14 (cyber risk management: training and awareness), Dubai Financial Services Authority (DFSA)
  9. AML 12.1.1 (AML training and awareness), Dubai Financial Services Authority (DFSA)
  10. AML 14.4.5 (record keeping: training records), Dubai Financial Services Authority (DFSA)
  11. GEN 4.3.1 and Guidance (Conduct Principles for individuals: application), Dubai Financial Services Authority (DFSA)
  12. Glossary: Relevant Employee, Dubai Financial Services Authority (DFSA)
  13. Notice of Amendments to Legislation December 2025, Dubai Financial Services Authority (DFSA)
  14. DFSA Rulebook modules, Dubai Financial Services Authority (DFSA)
  15. About the DFSA, Dubai Financial Services Authority (DFSA)
  16. Overview of DFSA AML/CTF and Sanctions Obligations, Dubai Financial Services Authority (DFSA)

This page is general information, not legal or compliance advice. Check the primary sources above and obtain advice for your circumstances. See our editorial standards.

Ready to see it?

Bring a subject. Leave with a framework.

A 45-minute working session with our team on a real subject or program you own. You see the system operate on your material, and you keep the framework it produces.

We reply within one business day.