← Insights

Resolving AML Compliance Advisory Disputes Effectively

An adviser can build the framework. The supervisor still writes to the licensee.

Why AML advisory engagements end in dispute: the obligation the licensed business cannot outsource, the scope questions an engagement letter should settle, the recurring flashpoints, and what a liability cap really covers.

Reviewed by Mohamed Noureldin, Founder, Managing Partner & Senior Legal Consultant

Two documents usually explain an AML advisory dispute, and they rarely describe the same service. The first is the engagement letter, which tends to promise a policy suite, a risk assessment and some training. The second is the supervisor's findings letter, which lists what the business was actually required to do and did not.

The client reads the second document and concludes that it paid for compliance and did not get it. The adviser reads the first and points out that it was asked for a set of documents, not for the running of a compliance function. Both are describing the same engagement. The gap between them is where the dispute lives.

The obligation stays with the business

The starting point is unwelcome to a good many clients: the legal duty to comply with anti-money-laundering obligations rests on the licensed business, and it cannot be handed to a consultant. An adviser can write the risk assessment, configure the screening, sit as an outsourced officer and train the staff. The business remains the party the supervisor writes to, the party that answers for a failure, and the party that pays a penalty.

That does not leave a client without recourse. If an adviser gave wrong advice, missed something within its scope, or delivered work that fell below the standard a competent adviser would meet, there is a claim. But it is a claim in contract and in professional negligence against the adviser, and it runs in parallel with the regulatory exposure rather than removing it. The two proceed on different timetables and different evidence, and a business that treats the second as an answer to the first tends to handle both badly.

This has a governance consequence. Responsibility for AML oversight sits with the board or the senior management of the licensee, and delegating the work does not delegate the accountability. Our corporate governance practice advises on how that oversight is documented, which is one of the first things an examiner asks to see.

What the engagement letter should have settled

Most of these disputes are drafting failures rather than performance failures. An engagement letter that answers the following questions rarely produces litigation.

What is being delivered, and in what form. A policy document, a business risk assessment, a customer risk methodology, screening configuration, file remediation and ongoing monitoring are six different things. Name the ones in scope and say plainly that the rest are not.

Whether the engagement is a project or an ongoing service. A framework written once and never revisited ages badly as the business changes and the rules move. If nobody is retained to update it, say so in writing, because "we assumed you were keeping it current" is the single most common complaint in this area.

What the adviser depends on the client to provide. Advisory work is built on client data: customer files, ownership information, transaction records, product descriptions. Where that data is incomplete or wrong, the output is wrong. Record the dependency and record what was actually supplied and when.

Who makes the decisions. Whether a particular relationship is accepted, whether an activity is reported to the Financial Intelligence Unit, whether a customer is exited — these are decisions of the business, informed by advice. An engagement that blurs advice into decision-making creates exactly the ambiguity that is later argued about.

Who holds the officer role. Where a compliance or reporting officer function is outsourced, the arrangement needs to say what that person is responsible for, what access and information they get, what happens when they are ignored, and how the role ends. Outsourced officer engagements generate a disproportionate share of the disputes we see.

The recurring flashpoints

The risk assessment that was never tailored. A generic document with the client's name inserted is easy to identify and difficult to defend. Supervisors look for evidence that the business considered its own customers, products, delivery channels and geographies, and the file should show that thinking.

Screening and monitoring that was delivered but never tuned. A tool switched on with default settings produces either an unreadable volume of alerts or almost none. Both are findings. Whose job it was to calibrate the thresholds, and to review them, should be in the contract.

Reports made or not made. Disagreements about whether a suspicious activity report should have been filed are among the sharpest, because the consequences of getting it wrong run in both directions. What protects everyone is a written record of what the adviser recommended, when, and what the business decided.

Remediation that stopped halfway. A file review that identifies gaps and is then paused for cost reasons leaves the business worse off than before: it now has a document listing its own deficiencies and no evidence of having fixed them. If work is stopping, record why and what remains outstanding.

Inconsistency with the rest of the filing record. The customers, counterparties and transactions described in an AML file should be recognisable in the business's other regulatory filings. Where they are not, both come under scrutiny; our tax advisory team is often involved for that reason.

None of this is confined to banks. The regime reaches designated non-financial businesses and professions as well, and a large share of the disputes we handle involve firms in that group — real estate, corporate services, dealers in high-value goods — who did not think of themselves as regulated until the first inspection. Our AML compliance advisory practice works with businesses on both sides of these engagements.

Liability, caps and what they actually cover

Advisory contracts routinely cap liability at the fees paid. Where the loss complained of is a regulatory penalty, that cap can be an order of magnitude below the sum in dispute, which is a conversation worth having at signature rather than afterwards.

Do not assume a penalty imposed on the business can simply be passed to the adviser through an indemnity. Whether a clause of that kind is effective depends on how it is drafted, the law governing the contract, and the limits a court or tribunal will place on shifting the consequences of a party's own regulatory failure. Where a claim is contemplated, the realistic recoverable loss is usually the cost of putting the work right, the cost of the remediation exercise, and the professional costs of responding to the supervisor.

Check the adviser's professional indemnity cover as well. A capped liability against an uninsured consultancy is a theoretical remedy.

Where the dispute is resolved

A mainland engagement will normally be heard by the courts of the emirate unless the contract sends it elsewhere. Where either party is established in the DIFC or the ADGM, the dispute may fall to those courts, which are common-law jurisdictions with their own procedure and their own regulators.

Arbitration is common in these contracts and is worth choosing deliberately. Arbitration seated onshore is governed by Federal Law No. 6 of 2018, as amended, and the DIFC remains available as a seat. Two points of housekeeping catch older agreements: the DIFC-LCIA was abolished by Dubai Decree No. 34 of 2021 and its caseload passed to the Dubai International Arbitration Centre, and the Abu Dhabi centre formerly known as ADCCAC was restructured as arbitrateAD in 2024. Clauses naming the old institutions should be updated at the next amendment rather than tested in a dispute.

Whichever forum applies, confidentiality deserves attention. These disputes put the business's compliance weaknesses on the record, and the choice of forum affects who can see them.

What keeps these engagements out of court

Almost everything that decides one of these disputes exists before it starts, in the file each side kept while the work was still going well. Keep the version history of every deliverable, with dates. Keep the instructions and the data transfers in writing. Record the recommendations that were not followed, and the reasons given for not following them. Diarise a review of the framework rather than assuming somebody owns it. And settle the liability provisions at signature, while they are still open to negotiation: once a supervisor's letter has arrived, they are simply the terms both parties are left with.

Disclaimer: The information provided in this article is for general informational purposes only and does not constitute legal advice. Readers should seek professional legal advice tailored to their specific circumstances before making any decisions or taking any action based on the content of this article.

Nour Attorneys Team

Further reading

Call Us NowChat With Our Team On WhatsApp