The Strategic Guide to AML Compliance Advisory in the UAE
AML compliance in the UAE is assessed on the evidence a business can retrieve on request, not on the quality of the policy sitting behind it.
A UAE supervisor inspecting a business asks for the risk assessment behind the policy, the customer files showing it was applied, the screening records, the training log and the reports filed. This guide identifies which authority holds your AML file, what the programme has to document from beneficial ownership to independent testing, and the failings inspections keep producing.
Reviewed by Mohamed Noureldin, Founder, Managing Partner & Senior Legal Consultant
Anti-money laundering compliance in the UAE is assessed on evidence, not on intention. A supervisor examining a business does not ask whether it has a policy; it asks to see the risk assessment behind the policy, the customer files that show the assessment was applied, the screening records, the training log, and the reports filed. Federal Decree-Law No. 20 of 2018 on anti-money laundering sets the framework, and it reaches well beyond banks: designated non-financial businesses and professions, including real estate brokers and agents, dealers in precious metals and stones, auditors and corporate service providers, carry the same core obligations.
Related: See our AML compliance advisory services in the UAE.
This guide sets out who supervises whom, what a compliance programme has to contain to survive an inspection, and the failures that supervisors find most often.
Who Supervises You
The first question for any UAE business is which authority holds its AML file, because the rulebook, the reporting channel and the inspection method follow from that answer.
- Licensed financial institutions on the mainland are supervised by the Central Bank of the UAE, with the Securities and Commodities Authority supervising its own licensees.
- Designated non-financial businesses and professions licensed on the mainland and in most free zones are supervised by the Ministry of Economy.
- Firms in the DIFC are supervised by the Dubai Financial Services Authority under its own AML module. This is a point that is frequently reported incorrectly: the DIFC's regulator is the DFSA, not the FSRA.
- Firms in ADGM are supervised by the Financial Services Regulatory Authority, with the ADGM Registration Authority supervising non-financial businesses inside the zone. The DIFC Registrar of Companies performs the equivalent role in Dubai's financial centre.
- Virtual asset businesses are supervised according to where they are licensed, including by the Virtual Assets Regulatory Authority in Dubai and by the DFSA and FSRA within the financial centres.
Reports of suspicion go to the Financial Intelligence Unit through the goAML portal in every case, and targeted financial sanctions obligations are administered through the Executive Office for Control and Non-Proliferation. Registration on goAML and on the sanctions notification system is itself a compliance requirement, and being registered without ever having filed anything is a pattern supervisors look for.
Related: Our VAT compliance advisers work alongside the AML team on record-keeping obligations.
What the Programme Has to Contain
The building blocks are consistent across supervisors, and each one has to be documented.
A business risk assessment. Written, specific to the business, and covering customer types, products and services, delivery channels, geographies and new technologies. It is the document that justifies every other decision, including where simplified measures are applied. A template downloaded and left unedited fails at the first question.
Policies, controls and procedures approved by senior management, proportionate to the risks identified, with a record of the approval.
A compliance officer with the seniority, independence and access to information the role requires, and the authority to file a report without needing commercial sign-off. Where the same person carries revenue targets and the reporting function, the conflict is obvious and gets recorded as a finding.
Customer due diligence. Identify the customer and verify identity from reliable, independent sources; identify the beneficial owner and take reasonable measures to verify who that is, tracing through the ownership chain rather than stopping at the first corporate shareholder; understand the purpose and intended nature of the relationship; and monitor the relationship on an ongoing basis so that the file reflects the customer as it is now, not as it was at onboarding.
Enhanced due diligence for higher-risk relationships, including politically exposed persons and their family members and close associates, complex or opaque ownership structures, customers connected to high-risk jurisdictions, and transactions with no apparent economic purpose. Enhanced measures mean more evidence, including on source of funds and source of wealth, and senior management approval to open or continue the relationship.
Related: See our tax advisory services for VAT and corporate tax record-keeping alongside AML files.
Sanctions screening. Screen customers and beneficial owners against the UAE local terrorist list and the United Nations consolidated list, both at onboarding and whenever the lists are updated, not only at the start of the relationship. Where there is a match, funds must be frozen without delay and the position reported through the prescribed channel.
Reporting. A suspicious transaction or activity report is filed on suspicion, not on proof, and it is filed through goAML. Once a report is made, the customer must not be tipped off, which needs to be reflected in what front-line staff are trained to say.
Record keeping. Customer files, transaction records, screening results and the reports themselves must be retained for the period the legislation prescribes and be retrievable on request. Records held only in a departed employee's mailbox are not retained records.
Training and independent testing. Training should differ by role, because what a relationship manager needs to recognise is not what a finance officer needs. The AML function itself should be independently reviewed, and the review's findings tracked to closure.
Sector-specific duties sit on top of this. Real estate brokers and agents, for example, must report defined categories of transaction, including certain cash and virtual asset payments, through the channel the Ministry of Economy prescribes, irrespective of whether anything appears suspicious.
Related: Explore our corporate governance advisory services for board-level compliance oversight.
Where Programmes Fail Inspection
The recurring findings are unglamorous. A risk assessment that does not mention the business's actual customer base. Beneficial ownership identified from a customer declaration but never verified against corporate documents. Screening performed at onboarding and never repeated. Ongoing monitoring described in the policy but with no record of any review having taken place. A compliance officer appointed on paper who cannot show a single internal escalation. Training delivered once, to everyone, with the same slides. And files that cannot be produced within the time the inspector allows, which is treated as though they do not exist.
Two interactions are worth planning for. First, AML records are personal data, and their collection, retention and transfer engage Federal Decree-Law No. 45 of 2021 on personal data protection, or the DIFC and ADGM data protection regimes for entities in those zones. The lawful basis and the retention period should be documented rather than assumed. Second, the same underlying documents support tax obligations, including corporate tax registration and filing under Federal Decree-Law No. 47 of 2022 and VAT at 5%. Building one retrievable record set, rather than parallel ones, reduces both cost and the risk of inconsistent answers to two regulators.
Strategic Considerations for UAE Businesses
- Confirm which authority supervises you and work from that authority's rulebook, not a generic checklist.
- Write the business risk assessment first; everything else has to be traceable to it.
- Verify beneficial ownership through the chain and record what you relied on.
- Re-screen on list updates, not only at onboarding.
- Give the compliance officer independence from revenue and a documented escalation route.
- File through goAML on suspicion and keep the decision trail for reports you considered but did not make.
- Test the programme independently and close out the findings; an unactioned internal report is worse than none.
Related Services: Explore our AML compliance advisory and AML programme reviews in the UAE services for practical legal support in this area.
Disclaimer: The information provided in this article is for general informational purposes only and does not constitute legal advice. Readers should seek professional legal advice tailored to their specific circumstances before making any decisions or taking any action based on the content of this article.
Nour Attorneys Team
Additional Resources
Explore more of our insights on related topics:
- AML Compliance for Crypto Businesses in UAE
- Resolving Aml Compliance Advisory Disputes Effectively
- Common Aml Compliance Advisory Mistakes to Avoid in Dubai
- How to Build an Effective AML Compliance Program in the UAE