Real estate brokers, gold and jewellery traders, corporate service providers and accountants in the UAE carry anti-money laundering duties that go well beyond a one-off registration. Since Federal Decree-Law No. 10 of 2025 came into force on 14 October 2025, supervisors expect those duties to be documented, risk-based and working in practice.
DirhamWise helps you register your business on goAML, writes the AML policy and risk assessment your supervisor will ask to see, sets up KYC and sanctions screening procedures your staff can follow, and trains your team to recognise and escalate suspicious activity. The framework is built around how your business actually operates, not copied from a template.

A designated non-financial business or profession (DNFBP) is a business outside banking and insurance that the AML law treats as a gatekeeper, because its services can be misused to move or disguise illicit money. Article 3 of Cabinet Resolution No. 134 of 2025, the Executive Regulations of the new AML law, lists the DNFBP activities. The obligations are triggered by the activity you carry out, not by the name on your licence, so a company can fall inside the regime for only part of its business.
| DNFBP category | When the AML rules apply | Supervisor (mainland and commercial free zones) |
|---|---|---|
| Real estate brokers and agents | When concluding transactions or settlements for customers buying or selling real estate | Ministry of Economy and Tourism (MoET) |
| Dealers in precious metals and precious stones | When carrying out a single cash transaction, or several transactions that appear linked, of AED 55,000 or more | MoET |
| Independent accountants | When preparing or carrying out transactions for clients involving buying and selling real estate, managing client funds, managing bank, savings or securities accounts, organising contributions to companies, or forming, running, buying or selling legal persons | MoET |
| Company and trust service providers | When acting as formation agent, acting or arranging for others to act as director, secretary, partner, nominee shareholder or trustee, or providing a registered office or business address | MoET |
| Lawyers, notaries and other independent legal professionals | For the same client transaction activities listed for independent accountants | Ministry of Justice |
The list also covers commercial gaming operators, and supervisors can add further businesses or professions. MoET is the supervisory body for DNFBPs licensed by mainland registrars and commercial free zones. Businesses licensed in a financial free zone fall under their own regulator, such as the DFSA in DIFC or the FSRA in ADGM, and the supervisory body selected on goAML must reflect that.
If you are not sure whether your activity is caught, that is the first question we answer, in writing, before any registration work starts.
Guides that still quote Federal Decree-Law No. 20 of 2018 and Cabinet Decision No. 10 of 2019 are out of date. Both have been repealed and replaced.
| Current instrument | What it replaced | In force from |
|---|---|---|
| Federal Decree-Law No. 10 of 2025 on Anti-Money Laundering, and Combating the Financing of Terrorism and Proliferation Financing | Federal Decree-Law No. 20 of 2018 | 14 October 2025 |
| Cabinet Resolution No. 134 of 2025 (Executive Regulations) | Cabinet Decision No. 10 of 2019 | 14 December 2025 |
The changes that matter most to DNFBPs:
MoET has also previously suspended the operations of DNFBP establishments that failed to register on goAML, so not registering is an enforcement risk in itself.
goAML is the UAE Financial Intelligence Unit’s (UAEFIU) electronic reporting platform. Since 27 June 2019, reporting entities have been required to file suspicious transaction reports and other reports through it, and a business must be registered before it can file. Access runs in two stages: a secure gateway called SACM, then the goAML organisation registration itself. The steps below follow the UAEFIU’s published registration guides.
Neither the UAEFIU nor MoET publishes a fixed approval time, so we do not promise one. What we control is helping you submit a complete, consistent application the first time.
For entities supervised by MoET or the Ministry of Justice, the UAEFIU’s SACM and goAML guide lists these attachments:
| Document | What to check |
|---|---|
| Valid trade licence | Not expired, and its activities match the organisation type and business activity you select |
| Compliance officer’s passport copy | Clear, in date and consistent with the details typed into the form |
| Compliance officer’s Emirates ID copy | The Emirates ID number is entered without spaces or hyphens |
| Approval email from MoET | Received at the SACM stage |
| Authorisation letter | Issued by the entity, naming the registering person and their position |
Entities supervised by the DFSA, the FSRA or the Central Bank have different attachment lists.
Registration gives you a channel to report. Inspections test whether the programme behind it works. Article 19 of Federal Decree-Law No. 10 of 2025 and the Executive Regulations set out the core duties every DNFBP must meet.
| Obligation | What the law requires | What we deliver |
|---|---|---|
| Business risk assessment | Identify, assess and document risks from customers, countries, products, services, transactions and delivery channels, taking account of the National Risk Assessment; keep it updated and provide it on request (CR 134/2025, Art. 5) | A written enterprise-wide risk assessment with a scoring method and mitigation plan |
| Policies, controls and procedures | Approved by senior management, proportionate to your risks and size, reviewed and updated on an ongoing basis (Art. 21) | An AML/CFT policy and procedure manual written for your sector |
| Customer due diligence (KYC) | Verify customers and beneficial owners before or during onboarding, and apply CDD again on suspicion or doubt about earlier data; monitor the relationship (Arts. 6 to 9) | Onboarding forms, document checklists and a customer risk-rating sheet |
| Beneficial ownership | Identify the natural persons owning 25% or more of a corporate customer, or otherwise controlling it (Art. 10) | Ownership-chain mapping for corporate and trust customers |
| Enhanced due diligence | Extra measures for politically exposed persons, including senior management approval and source of funds and wealth checks, and for customers from high-risk countries (Arts. 16 and 23) | An EDD checklist with a senior management approval step |
| Targeted financial sanctions | Apply the Executive Office’s instructions forthwith (Decree-Law, Art. 19) | A screening procedure with escalation and freezing steps |
| Compliance officer | Appointed at management level, independent in decision-making, with appropriate competence and experience (Art. 22) | A role description, reporting lines and hands-on support for your appointed officer |
| Training | Ongoing programmes for the compliance function and other relevant staff (Arts. 21 and 22) | Sector-specific sessions with attendance records |
| Record keeping | Keep transaction and CDD records for at least five years (Art. 25) | A retention schedule and file structure |
| Independent testing | An independent audit function tests the effectiveness of the AML policies and controls (Art. 21) | A periodic AML health check against current rules |
The business-wide risk assessment is the document everything else hangs from. It describes who your customers are, where they and their money come from, which services and payment methods you offer, and how customers reach you, then rates each factor and records the controls that bring the risk down. A gold trader taking cash from walk-in customers and a broker selling off-plan units to overseas companies will reach very different conclusions, and the inspector will expect yours to read as specific to you.
Separately from customer checks, Article 38 of Cabinet Resolution No. 134 of 2025 requires companies to hold their own beneficial owner information and shareholder register data, update it within 15 working days of any change, and cooperate when a bank or DNFBP asks for it. Those records must be kept for at least five years after the company is dissolved. We check this as part of every engagement.
Under Article 18 of the Decree-Law, when a DNFBP suspects, or has reasonable grounds to suspect, that a transaction or funds are linked to a crime, it must report to the UAEFIU without delay through goAML, regardless of the amount, and answer any follow-up request. Staff must not tell the customer, or anyone else, that a report has been or will be filed. Lawyers, notaries, other independent legal professionals and independent statutory auditors have a limited exception for information obtained under professional secrecy.
A useful report sets out the background, the parties involved, the reasons for the report and the red flags observed. The FIU may come back with questions, so the internal file behind each report matters as much as the report itself. We give your team an internal escalation form, a decision log for the compliance officer and drafting support for the report narrative.

goAML also carries other report types that DNFBPs use, each with its own UAEFIU submission guide:
Targeted financial sanctions mean freezing funds, and not making funds available, to persons designated by UAE Cabinet resolutions on terrorist lists or by the United Nations Security Council under Chapter VII of the UN Charter. The Executive Office for Control and Non-Proliferation issues the instructions that DNFBPs must apply forthwith. We set up a screening routine that covers onboarding, list updates and payments, and write down exactly what staff do when a name matches in part or in full.

The core duties are the same for every DNFBP, but inspectors look for controls that fit the sector’s specific risks.
The focus is on who is really paying: source of funds, payments from third parties or from abroad, buyers acting through companies, and cash. On top of STRs, the UAEFIU’s REAR guide requires brokers and agents to obtain identity documents and file a Real Estate Activity Report for sales or purchases of freehold property where:
Records for these transactions must be kept for at least five years.
The AED 55,000 cash trigger applies to single transactions and to transactions that appear linked, so staff need to recognise split payments. The UAEFIU’s DPMSR guide requires identity documents and a DPMSR for cash transactions of AED 55,000 or more with resident and non-resident individuals, and, for companies, a copy of the trade licence and the representative’s ID where the transaction reaches AED 55,000 in cash or by wire transfer. Supplier due diligence and the origin of stock matter as much as customer checks. We often support these clients alongside their accounting and bookkeeping, which keeps cash records and AML records consistent.
Formation agents, registered-office providers and nominee arrangements sit close to beneficial ownership risk. Expect questions on how you identify the natural person behind each structure you create or administer, and how you record nominee directors and shareholders.
The rules apply when an independent accountant prepares or carries out transactions for a client, such as managing client money or accounts, or forming, running, buying or selling companies. Many firms first find they are in scope through payment-handling or company formation work.
Each engagement is scoped and quoted in writing before work starts. A typical sequence:
We work alongside the compliance officer you appoint; the decision to report and the accountability stay with your business, as the law intends. To discuss scope, contact our team.
A DNFBP is a designated non-financial business or profession: a business outside the financial sector that must meet AML duties because of the services it provides. In the UAE this covers real estate brokers and agents, dealers in precious metals and stones, independent accountants, company and trust service providers, lawyers, notaries and other independent legal professionals, and commercial gaming operators, each when carrying out the activities listed in Article 3 of Cabinet Resolution No. 134 of 2025.
Every reporting entity must register on goAML to file suspicious transaction reports. For DNFBPs, that means any business whose activities fall under the DNFBP definition, whether licensed on the mainland or in a free zone. Businesses in DIFC or ADGM register with their own regulator, the DFSA or the FSRA, as the supervisory body.
Independent accountants are DNFBPs when they prepare or carry out transactions for clients involving real estate, client funds, bank or securities accounts, company contributions, or the formation, management, purchase or sale of companies. Real estate brokers and agents are in scope when concluding purchase or sale transactions for customers. If you are in scope, you need to register.
For entities supervised by MoET or the Ministry of Justice, the UAEFIU guide lists a valid trade licence, the compliance officer’s passport and Emirates ID copies, the approval email from MoET and an authorisation letter. The licence and Emirates ID are also attached as a PDF at the SACM pre-registration stage.
Federal Decree-Law No. 10 of 2025, in force from 14 October 2025, and its Executive Regulations, Cabinet Resolution No. 134 of 2025, in force from 14 December 2025. They replaced Federal Decree-Law No. 20 of 2018 and Cabinet Decision No. 10 of 2019.
goAML registration gives your business access to the UAEFIU’s reporting system. AML compliance is the full programme behind it: risk assessment, policy, customer due diligence, sanctions screening, training, record keeping and reporting. A business can be registered and still fail an inspection if the programme is missing.
Yes. DNFBPs must appoint a compliance officer at management level who has independence in decision-making and appropriate competence and experience. The officer reviews suspicious activity, decides whether to report, oversees training and reports to senior management. The same person normally registers the business on goAML and becomes its admin user.
Neither the UAEFIU nor MoET publishes a fixed timeframe, because each application depends on the supervisor’s review. Most delays come from incomplete or inconsistent submissions, which is what our preparation work is designed to prevent.
Tell us your activity, licence and emirate, and we will send a written quote covering goAML registration, risk assessment, AML policy and staff training.
+971 56 500 6694 · info@dirhamwise.com · Contact form
ParkLane Tower, Park Regis, Business Bay, Dubai · Monday to Saturday, 9:00am to 6:00pm