Home  /  Publications  /  No. 023

COMPLIANCE·10 NOV 2021·3 min read

UAE AML Obligations, and Whether They Apply to You

The first question is not what to do. It is whether the rules reach you at all. Many UAE businesses assume AML is a banking matter and find out otherwise during an inspection.

Position as at August 2026

Who is caught

Financial institutions, and a second category usually called DNFBPs. Designated non-financial businesses and professions.

That second category is where the surprises are. It reaches real estate brokers and agents, dealers in precious metals and stones, auditors and accountants, and company service providers.

If you are an accountant, an auditor, a corporate service provider or a property broker, you are almost certainly in scope. Many firms in these categories still believe they are not.

The four obligations

Once in scope, four things follow.

1. Register on the goAML system. This is the reporting platform, and registration is itself a requirement, separate from having anything to report.

2. Know your customer. Identify and verify who you are dealing with, understand the ownership behind a corporate client, and identify the beneficial owner. Screen against sanctions and the relevant lists.

3. Assess and monitor. A documented risk assessment of your business, and ongoing monitoring proportionate to the risk of each relationship.

4. Report suspicion. Suspicious transaction reports go through goAML. This is not optional and it is not conditional on being certain.

The part people get wrong

You must not tell the customer.

Reporting a suspicion and then mentioning it to the subject defeats the purpose and is itself an offence in most AML frameworks. If you report, you report and you say nothing.

What an inspection actually looks at

Documents, not intentions.

Your risk assessment, and whether it was written for your business rather than downloaded.
Your customer files, and whether verification documents are actually on them. Evidence that screening happened, with dates.
Your appointed compliance officer.
Your training records.
Your policies, and whether staff can describe them.

The most common finding is not wrongdoing. It is that the policy exists and the file does not evidence it being followed.

The practical minimum

A written risk assessment specific to your business.
A named compliance officer.
A customer file for every client containing identification, verification, beneficial ownership and screening evidence, with dates.
Screening repeated periodically rather than only at onboarding.
Training that happened and was recorded. goAML registration.

Why screening at onboarding alone is not enough

Sanctions lists change. A client who was clear at onboarding may not be clear now.

Periodic rescreening of your existing client base is what catches this, and it is one of the more common gaps found in inspections.

What this article does not cover

The specific decrees, penalty amounts, and the exact scope of each DNFBP category. These are set in law and have been amended.

If you are in scope, work from your supervisory authority's own guidance rather than from a summary.

This is general information, not advice on your position.

Where we fit

We run AML compliance for our own practice and advise clients in scope. If you are unsure whether you are caught, tell us your licensed activity.

Have a question on this?

Ask a tax question. The law answers.

AskCALX searches the official corpus and answers with the article quoted, word for word.

Ask a tax question →

Let’s get startedYour engagement

One engagement letter. One file. Every deadline met.


Let’s talk!

Newsletter

Stay up to date with our newsletter.

Latest in UAE business, tax and technology, once a month.

Thank you, you are on the list.

Visit us

Office 1316, Aspin Commercial Tower
Sheikh Zayed Road, P.O. Box 10415, Dubai
Open in Google Maps →

© 2026 CALX International Auditing of Accounts L.L.C. · All rights reserved · Privacy