Log in
Home / Publications / No. 023
The first question is not what to do. It is whether the rules reach you at all. Many UAE businesses assume AML is a banking matter and find out otherwise during an inspection.
Position as at August 2026
Financial institutions, and a second category usually called DNFBPs. Designated non-financial businesses and professions.
That second category is where the surprises are. It reaches real estate brokers and agents, dealers in precious metals and stones, auditors and accountants, and company service providers.
If you are an accountant, an auditor, a corporate service provider or a property broker, you are almost certainly in scope. Many firms in these categories still believe they are not.
Once in scope, four things follow.
1. Register on the goAML system. This is the reporting platform, and registration is itself a requirement, separate from having anything to report.
2. Know your customer. Identify and verify who you are dealing with, understand the ownership behind a corporate client, and identify the beneficial owner. Screen against sanctions and the relevant lists.
3. Assess and monitor. A documented risk assessment of your business, and ongoing monitoring proportionate to the risk of each relationship.
4. Report suspicion. Suspicious transaction reports go through goAML. This is not optional and it is not conditional on being certain.
You must not tell the customer.
Reporting a suspicion and then mentioning it to the subject defeats the purpose and is itself an offence in most AML frameworks. If you report, you report and you say nothing.
Documents, not intentions.
Your risk assessment, and whether it was written for your business rather than downloaded.
Your customer files, and whether verification documents are actually on them. Evidence that screening happened, with dates.
Your appointed compliance officer.
Your training records.
Your policies, and whether staff can describe them.
The most common finding is not wrongdoing. It is that the policy exists and the file does not evidence it being followed.
A written risk assessment specific to your business.
A named compliance officer.
A customer file for every client containing identification, verification, beneficial ownership and screening evidence, with dates.
Screening repeated periodically rather than only at onboarding.
Training that happened and was recorded. goAML registration.
Sanctions lists change. A client who was clear at onboarding may not be clear now.
Periodic rescreening of your existing client base is what catches this, and it is one of the more common gaps found in inspections.
The specific decrees, penalty amounts, and the exact scope of each DNFBP category. These are set in law and have been amended.
If you are in scope, work from your supervisory authority's own guidance rather than from a summary.
This is general information, not advice on your position.
We run AML compliance for our own practice and advise clients in scope. If you are unsure whether you are caught, tell us your licensed activity.
Have a question on this?
AskCALX searches the official corpus and answers with the article quoted, word for word.
Newsletter
Latest in UAE business, tax and technology, once a month.
Thank you, you are on the list.
Office 1316, Aspin Commercial Tower
Sheikh Zayed Road, P.O. Box 10415, Dubai
Open in Google Maps →