In this essay
A payment licence is permission to operate. It is not evidence that the operating controls are ready.
The Central Bank of the UAE's May 2026 AML/CFT/CPF thematic review makes that distinction unusually concrete. It covers stored value facilities, retail payment services and card schemes, and payment token service providers. The report says these sectors are growing quickly, crossing borders and relying on non-face-to-face onboarding, intermediaries and digital systems.
The useful product reading is simple: launch readiness now has to be demonstrated through control evidence, not described through policy language.
What the review actually measured
The CBUAE says its review considered licensing outcomes and sector-wide self-assessments. Twenty-six of 35 SVFs and RPSPs submitted responses. Those respondents represented more than 1.12 million customers, activity across 238 jurisdictions, 96 products and more than 92,000 merchants.
Those figures describe the sample, not the entire UAE market. They are also not a market-growth forecast. They show why a control framework has to work across products, merchants, geographies and delivery channels.
The review assessed governance, business-risk assessment, customer due diligence, sanctions compliance, transaction monitoring, suspicious-transaction reporting, training and record retention. That is a product-and-operations map disguised as a compliance list.
The maturity result needs careful reading
Across the SVF and RPSCS entities assessed, 12% demonstrated largely effective AML/CFT/CPF control frameworks, 76% showed partially effective controls, and 12% were assessed as ineffective or not yet fully established.
The last category needs a precise caveat. The report says those entities were newly licensed and still finalising their frameworks before full operations. It does not say that every entity in the category was subject to an enforcement action, nor that the findings represent the whole licensed population.
The practical signal is still strong: a large middle exists between “policy exists” and “control works consistently.” A launch plan that celebrates licence approval while leaving that middle unmeasured is incomplete.
Turn the review into a product gate
For a UAE wallet, PSP, card scheme or payment-token proposition, I would make five evidence packs visible before launch.
First, the risk map. Tie customer segments, products, corridors, merchants, agents and delivery channels to specific ML/TF/PF risks. A generic enterprise risk assessment is too distant from the payment journeys that create exposure.
Second, the onboarding proof. Show how identity, beneficial ownership, customer purpose, geography and risk tier are captured for the actual customer journey. Record which cases are automated, which require review, and what happens when evidence is incomplete.
Third, the sanctions and monitoring proof. A vendor connection is not a control outcome. Show list coverage, screening timing, alert ownership, tuning decisions, escalation, transaction-monitoring scenarios and how false positives are closed.
Fourth, the reporting and record trail. A suspicious-transaction process needs an accountable owner, decision history, submission evidence where required, retention rules and an auditable link back to the customer and transaction states.
Fifth, the governance proof. The CBUAE review highlights risk appetite, compliance independence, training and internal audit. Product leaders should be able to show who can pause a flow, who can approve an exception, who owns remediation and when management receives an honest gap report.
Payment-token teams have extra work
The review separately notes expectations for payment-token service providers, including deeper business-wide risk assessments, more independent compliance functions, stronger governance, blockchain analytics, travel-rule compliance and risk-sensitive agent due diligence.
That does not mean every payment-token product has the same risk profile. It does mean a tokenised payment proposition cannot outsource the operating model to a custody, analytics or travel-rule vendor and call the integration “compliance.” The product must define the control boundary, evidence exchanged, exception owner and recovery path.
The launch decision I would make
Do not ask only: “Has the licence been granted?”
Ask instead:
- Can we show the risk assessment for each live payment journey?
- Can onboarding explain why a customer passed, failed or needs review?
- Can sanctions and monitoring decisions be reconstructed from evidence?
- Can compliance act independently when product targets and risk appetite conflict?
- Can finance, support and risk identify the affected customer or transaction population after an incident?
If the answer is no, the launch is legally possible but operationally immature.
That is the real lesson from the CBUAE review. Payment supervision is increasingly testing whether controls are designed, owned and working in context. The licence opens the door. Evidence determines whether the product is ready to walk through it.
Sources
Closing thought and further reading
The CBUAE's 2026 thematic review shows that UAE payment products need operating evidence, not only a licence application and policy pack.
Building through similar complexity?
Discuss the operating decisions behind the essay, or explore where my experience can help.


