← Insights

How Proper AML Compliance Advisory Structuring Saves Millions

Anti-money laundering compliance in the UAE is assessed on the file a firm can produce, not on the work it says it does.

A UAE supervisor asks for six things by name: a risk assessment, approved policies, customer due diligence records, screening against the Local Terrorist List and UN lists, reports filed through goAML, and a compliance officer who cannot be overruled. The article covers each, along with the failures that recur — ownership traced only to the first layer, alerts cleared without a dated note.

Reviewed by Mohamed Noureldin, Founder, Managing Partner & Senior Legal Consultant

Anti-money laundering compliance in the UAE is assessed on evidence, not intention. When a supervisor inspects, it asks for the business risk assessment, the customer files, the screening records, the reports filed with the Financial Intelligence Unit, the training log, and the minutes showing that senior management reviewed all of it. A firm that has done the work but cannot produce the file is treated much like a firm that has not done the work at all.

That matters because the obligations reach well beyond banks. Financial institutions are supervised by the Central Bank of the UAE; firms operating in the DIFC and ADGM are supervised by the DFSA and the FSRA respectively; and a wide category of designated non-financial businesses and professions — real estate brokers and agents, dealers in precious metals and stones, auditors, and corporate service providers — falls under the Ministry of Economy. Many businesses in that last group are captured without realising it.

Related: Our AML compliance UAE practice builds and reviews programmes for regulated firms and for designated non-financial businesses.

What a compliant programme actually contains

The UAE's federal anti-money laundering and counter-terrorist financing legislation, together with its implementing regulation and the supervisors' rulebooks, requires a risk-based programme. In practice that programme has six components, and a supervisor will look for each of them by name.

  • An enterprise-wide risk assessment. A written assessment of the firm's exposure by customer type, product, delivery channel, geography and transaction pattern, reviewed and updated when the business changes. Everything else in the programme should trace back to it.
  • Written policies, controls and procedures approved by senior management and matched to that risk assessment, rather than adopted from a template.
  • Customer due diligence. Identify and verify the customer and any beneficial owner, understand the purpose of the relationship, and establish source of funds and, where risk requires, source of wealth. Enhanced due diligence applies to higher-risk relationships, including politically exposed persons and customers connected to high-risk jurisdictions. Simplified measures are available only where risk is demonstrably low and the reasoning is recorded.
  • Sanctions and list screening. Screen customers and, where relevant, counterparties against the UAE Local Terrorist List and the United Nations Security Council consolidated lists, at onboarding and on an ongoing basis, and act on the freezing obligations a match triggers.
  • Reporting. Suspicious transaction and suspicious activity reports are filed with the Financial Intelligence Unit through the goAML portal. Registration on goAML is itself a supervisory requirement for firms in scope, and failure to register is one of the easiest breaches for a supervisor to identify.
  • A compliance officer. An appointed money laundering reporting officer with the seniority, independence and access to information needed to decide whether a report is filed, without that decision being overruled by the business.

Related: See our VAT compliance support and our business compliance advisory practice.

Where programmes fail

The failures are consistent, and most are documentary rather than conceptual.

The risk assessment is generic. A document that could describe any firm in the sector shows that the assessment was not performed. It should name the firm's own customer segments, its own corridors and its own products.

Files are incomplete for legacy customers. Onboarding standards improve, but existing relationships are rarely brought up to the new standard. Periodic review, triggered by risk rating, is what closes that gap.

Beneficial ownership stops at the first layer. Where a corporate customer sits behind two or three holding entities, identifying the immediate shareholder is not identifying the beneficial owner. The chain must be documented through to the natural persons who ultimately own or control the customer.

Screening alerts are cleared without a record. An analyst's conclusion that a hit is a false positive is a compliance decision and needs a dated note explaining the basis for it. Cleared alerts with no rationale are indistinguishable from unreviewed alerts.

Reports are delayed while the business considers the commercial position. Suspicion triggers the reporting obligation. What happens to the relationship is a separate question, and the prohibition on tipping off means the customer cannot be consulted about it.

Training is an annual slide deck. Supervisors expect role-specific training with an attendance record, refreshed when the rules or the business change.

Related: Explore our AML compliance advisory solutions for firms operating onshore and in the financial free zones.

Third parties and correspondent relationships

Exposure is frequently introduced by someone else. Agents, introducers, distributors and outsourced onboarding providers act in the firm's name, and the firm remains responsible for the standard of due diligence they perform. Where customer due diligence is placed with a third party, the arrangement should be documented, the underlying records must be obtainable on request, and the firm should test a sample of files rather than rely on assurances. The same applies to correspondent and payment relationships, where the counterparty's own controls need to be assessed before the relationship opens.

Practical steps for UAE businesses

Confirm which supervisor you answer to before anything else. Scope determines which rulebook applies, which registration is required and where reports go. Groups operating both onshore and in the DIFC or ADGM will be answering to more than one supervisor, under overlapping but not identical rules.

Give the compliance officer a reporting line to the board and a written mandate. Independence is one of the first things an inspection tests, and a reporting officer who reports to the head of sales does not have it.

Put the programme on a documented review cycle, so that the risk assessment, the policies and the customer risk ratings are refreshed on a stated frequency and the review itself is minuted.

Commission an independent audit. An external review that tests customer files, samples screening decisions and traces reports from identification through to filing will find the gaps before a supervisor does — and the audit report, with a tracked remediation plan, is itself evidence of a functioning programme.

Keep the record. Penalties for AML failures in the UAE are substantial and can extend to restrictions on the licence, and the difference between a firm that is fined and one that is not is usually whether the file supports what management says the firm does.

Finally, treat the programme as a live obligation rather than a project. Customer bases change, products change, and supervisory expectations have risen steadily. A programme that was adequate when it was written and has not been revisited since is, on inspection, indistinguishable from one that was never written at all.

Related Services: Explore our AML compliance advisory and AML compliance for startups services for practical legal support in this area.

Disclaimer: The information provided in this article is for general informational purposes only and does not constitute legal advice. Readers should seek professional legal advice tailored to their specific circumstances before making any decisions or taking any action based on the content of this article.

Nour Attorneys Team

Additional Resources

Explore more of our insights on related topics:

Call Us NowChat With Our Team On WhatsApp