AML Compliance and goAML Registration in the UAE

AML COMPLIANCE SERVICES

Meet your AML duties, from goAML sign-up to staff training

Real estate brokers, gold and jewellery traders, corporate service providers and accountants in the UAE carry anti-money laundering duties that go well beyond a one-off registration. Since Federal Decree-Law No. 10 of 2025 came into force on 14 October 2025, supervisors expect those duties to be documented, risk-based and working in practice.

DirhamWise helps you register your business on goAML, writes the AML policy and risk assessment your supervisor will ask to see, sets up KYC and sanctions screening procedures your staff can follow, and trains your team to recognise and escalate suspicious activity. The framework is built around how your business actually operates, not copied from a template.

Two colleagues in suits reviewing a file on a laptop at a boardroom table
AML COMPLIANCE SERVICES

What's included

goAML registration
We prepare your documents and take your compliance officer through SACM and the goAML forms until your account is active.
Business risk assessment
A documented assessment of customer, country, product, service and channel risks, as Cabinet Resolution No. 134 of 2025 requires.
AML/CFT policy and procedures
A written policy for senior management approval covering CDD, screening, escalation, reporting and record keeping.
KYC and CDD toolkit
Onboarding forms, beneficial ownership checks, PEP questions and a risk-rating sheet your staff can use from day one.
Sanctions screening set-up
A screening routine against UAE and UN Security Council lists, with clear steps for possible matches and freezes.
Training and periodic reviews
Sector-specific training on red flags and STR escalation, plus reviews that keep your programme in line with the law.

Who needs AML compliance and goAML registration in the UAE

A designated non-financial business or profession (DNFBP) is a business outside banking and insurance that the AML law treats as a gatekeeper, because its services can be misused to move or disguise illicit money. Article 3 of Cabinet Resolution No. 134 of 2025, the Executive Regulations of the new AML law, lists the DNFBP activities. The obligations are triggered by the activity you carry out, not by the name on your licence, so a company can fall inside the regime for only part of its business.

DNFBP category When the AML rules apply Supervisor (mainland and commercial free zones)
Real estate brokers and agents When concluding transactions or settlements for customers buying or selling real estate Ministry of Economy and Tourism (MoET)
Dealers in precious metals and precious stones When carrying out a single cash transaction, or several transactions that appear linked, of AED 55,000 or more MoET
Independent accountants When preparing or carrying out transactions for clients involving buying and selling real estate, managing client funds, managing bank, savings or securities accounts, organising contributions to companies, or forming, running, buying or selling legal persons MoET
Company and trust service providers When acting as formation agent, acting or arranging for others to act as director, secretary, partner, nominee shareholder or trustee, or providing a registered office or business address MoET
Lawyers, notaries and other independent legal professionals For the same client transaction activities listed for independent accountants Ministry of Justice

The list also covers commercial gaming operators, and supervisors can add further businesses or professions. MoET is the supervisory body for DNFBPs licensed by mainland registrars and commercial free zones. Businesses licensed in a financial free zone fall under their own regulator, such as the DFSA in DIFC or the FSRA in ADGM, and the supervisory body selected on goAML must reflect that.

If you are not sure whether your activity is caught, that is the first question we answer, in writing, before any registration work starts.

The UAE AML law in 2026: what changed

Guides that still quote Federal Decree-Law No. 20 of 2018 and Cabinet Decision No. 10 of 2019 are out of date. Both have been repealed and replaced.

Current instrument What it replaced In force from
Federal Decree-Law No. 10 of 2025 on Anti-Money Laundering, and Combating the Financing of Terrorism and Proliferation Financing Federal Decree-Law No. 20 of 2018 14 October 2025
Cabinet Resolution No. 134 of 2025 (Executive Regulations) Cabinet Decision No. 10 of 2019 14 December 2025

The changes that matter most to DNFBPs:

  • Tax evasion is a predicate offence. The law’s definition of a predicate offence now expressly includes evasion of direct and indirect taxes. Corporate tax and VAT behaviour therefore belongs in your customer risk thinking, and keeping your own corporate tax compliance in order is part of the same picture.
  • Proliferation financing sits alongside money laundering and terrorist financing throughout the law, including the duty to apply targeted financial sanctions.
  • Administrative penalties (Article 17). A supervisor can issue a warning; impose a fine of AED 10,000 to AED 5,000,000 for each violation; bar the business from the sector; restrict the powers of, suspend or require the replacement of responsible managers; suspend or restrict the activity; or revoke the licence. It can also require periodic reports on how a violation is being fixed. A repeat of the same violation within one year can attract an incremental fine, and penalties can be published.
  • Criminal fines for companies (Article 27). Where a company’s representatives, directors or agents commit money laundering, terrorist financing or proliferation financing on its behalf, the fine is AED 5,000,000 to AED 100,000,000, or the value of the criminal property if that is greater.

MoET has also previously suspended the operations of DNFBP establishments that failed to register on goAML, so not registering is an enforcement risk in itself.

How goAML registration works, step by step

goAML is the UAE Financial Intelligence Unit’s (UAEFIU) electronic reporting platform. Since 27 June 2019, reporting entities have been required to file suspicious transaction reports and other reports through it, and a business must be registered before it can file. Access runs in two stages: a secure gateway called SACM, then the goAML organisation registration itself. The steps below follow the UAEFIU’s published registration guides.

  1. SACM pre-registration. The person who will register, normally your compliance officer, submits an expression of intent through the registration link on the UAEFIU’s SACM portal. The form asks for the entity name as licensed, the supervisory body, the trade licence number, the person’s Emirates ID, an operational email address and a UAE mobile number, with the licence, Emirates ID and any documents your supervisor asks for attached as a PDF. The request is confirmed through a verification email.
  2. Supervisor review. Your supervisory body, MoET for most mainland and commercial free zone DNFBPs, approves or rejects the request.
  3. Secret key and authenticator. Once approved, the officer secures a personal secret key using a link and one-time password sent by email and SMS, and links it to the Google Authenticator app, which then generates the codes used to log in. Each user secures their own key; keys cannot be shared within an organisation.
  4. Register a new organisation. On goAML, select Reporting Entity as the registration type and the organisation type that matches your licensed activity and supervisor. Enter the licence number, business activity, addresses, phone numbers and a group email address that authorised staff can access.
  5. Registering person. Add the compliance officer’s details, including Emirates ID and passport numbers, entered without spaces or hyphens, and an official business email. The UAEFIU guide rules out Gmail, Hotmail and Yahoo accounts for this field.
  6. Attachments and submission. Upload the supporting documents, complete the captcha and submit. The system issues a registration reference number for any follow-up with the supervisor or the goAML support team.
  7. Approval. The supervisory body or the FIU reviews the request and approves or rejects it, and the outcome is notified by email. The registering person becomes the organisation’s admin user and can then approve colleagues’ user requests.

Neither the UAEFIU nor MoET publishes a fixed approval time, so we do not promise one. What we control is helping you submit a complete, consistent application the first time.

Documents required for goAML registration

For entities supervised by MoET or the Ministry of Justice, the UAEFIU’s SACM and goAML guide lists these attachments:

Document What to check
Valid trade licence Not expired, and its activities match the organisation type and business activity you select
Compliance officer’s passport copy Clear, in date and consistent with the details typed into the form
Compliance officer’s Emirates ID copy The Emirates ID number is entered without spaces or hyphens
Approval email from MoET Received at the SACM stage
Authorisation letter Issued by the entity, naming the registering person and their position

Entities supervised by the DFSA, the FSRA or the Central Bank have different attachment lists.

Where registrations usually stall

  • A personal webmail address used for the registering person.
  • An organisation type or business activity that does not match the trade licence.
  • An expired licence, or unclear scans of identity documents.
  • A registering person who is not the appointed compliance officer, or has no authorisation letter.

Your ongoing AML obligations after registration

Registration gives you a channel to report. Inspections test whether the programme behind it works. Article 19 of Federal Decree-Law No. 10 of 2025 and the Executive Regulations set out the core duties every DNFBP must meet.

Obligation What the law requires What we deliver
Business risk assessment Identify, assess and document risks from customers, countries, products, services, transactions and delivery channels, taking account of the National Risk Assessment; keep it updated and provide it on request (CR 134/2025, Art. 5) A written enterprise-wide risk assessment with a scoring method and mitigation plan
Policies, controls and procedures Approved by senior management, proportionate to your risks and size, reviewed and updated on an ongoing basis (Art. 21) An AML/CFT policy and procedure manual written for your sector
Customer due diligence (KYC) Verify customers and beneficial owners before or during onboarding, and apply CDD again on suspicion or doubt about earlier data; monitor the relationship (Arts. 6 to 9) Onboarding forms, document checklists and a customer risk-rating sheet
Beneficial ownership Identify the natural persons owning 25% or more of a corporate customer, or otherwise controlling it (Art. 10) Ownership-chain mapping for corporate and trust customers
Enhanced due diligence Extra measures for politically exposed persons, including senior management approval and source of funds and wealth checks, and for customers from high-risk countries (Arts. 16 and 23) An EDD checklist with a senior management approval step
Targeted financial sanctions Apply the Executive Office’s instructions forthwith (Decree-Law, Art. 19) A screening procedure with escalation and freezing steps
Compliance officer Appointed at management level, independent in decision-making, with appropriate competence and experience (Art. 22) A role description, reporting lines and hands-on support for your appointed officer
Training Ongoing programmes for the compliance function and other relevant staff (Arts. 21 and 22) Sector-specific sessions with attendance records
Record keeping Keep transaction and CDD records for at least five years (Art. 25) A retention schedule and file structure
Independent testing An independent audit function tests the effectiveness of the AML policies and controls (Art. 21) A periodic AML health check against current rules

What an AML risk assessment covers

The business-wide risk assessment is the document everything else hangs from. It describes who your customers are, where they and their money come from, which services and payment methods you offer, and how customers reach you, then rates each factor and records the controls that bring the risk down. A gold trader taking cash from walk-in customers and a broker selling off-plan units to overseas companies will reach very different conclusions, and the inspector will expect yours to read as specific to you.

What an AML policy should include

  • Governance: who owns AML, the compliance officer’s role and how senior management approves the policy.
  • Customer due diligence, including simplified and enhanced measures and when each applies.
  • Sanctions screening and what staff do on a possible match.
  • Internal escalation and suspicious transaction reporting.
  • Staff screening, training and record keeping.
  • Review frequency and independent testing.

Your own beneficial ownership information

Separately from customer checks, Article 38 of Cabinet Resolution No. 134 of 2025 requires companies to hold their own beneficial owner information and shareholder register data, update it within 15 working days of any change, and cooperate when a bank or DNFBP asks for it. Those records must be kept for at least five years after the company is dissolved. We check this as part of every engagement.

Suspicious transaction reporting and sanctions screening

Under Article 18 of the Decree-Law, when a DNFBP suspects, or has reasonable grounds to suspect, that a transaction or funds are linked to a crime, it must report to the UAEFIU without delay through goAML, regardless of the amount, and answer any follow-up request. Staff must not tell the customer, or anyone else, that a report has been or will be filed. Lawyers, notaries, other independent legal professionals and independent statutory auditors have a limited exception for information obtained under professional secrecy.

A useful report sets out the background, the parties involved, the reasons for the report and the red flags observed. The FIU may come back with questions, so the internal file behind each report matters as much as the report itself. We give your team an internal escalation form, a decision log for the compliance officer and drafting support for the report narrative.

Adviser leading a team session at a flipchart while colleagues take notes around a meeting table

goAML also carries other report types that DNFBPs use, each with its own UAEFIU submission guide:

  • STR and SAR for suspicious transactions and suspicious activity.
  • REAR, the Real Estate Activity Report.
  • DPMSR, the Dealers in Precious Metals and Stones Report.
  • PNMR, the Partial Name Match Report, for a potential sanctions match, and FFR, the Funds Freeze Report, for freezing measures and attempted transactions involving a confirmed match.

Sanctions screening

Targeted financial sanctions mean freezing funds, and not making funds available, to persons designated by UAE Cabinet resolutions on terrorist lists or by the United Nations Security Council under Chapter VII of the UN Charter. The Executive Office for Control and Non-Proliferation issues the instructions that DNFBPs must apply forthwith. We set up a screening routine that covers onboarding, list updates and payments, and write down exactly what staff do when a name matches in part or in full.

Aerial view of Dubai's high-rise towers and city grid under a hazy sky

Sector notes: real estate, gold, corporate services and accountants

The core duties are the same for every DNFBP, but inspectors look for controls that fit the sector’s specific risks.

Real estate brokers and agents

The focus is on who is really paying: source of funds, payments from third parties or from abroad, buyers acting through companies, and cash. On top of STRs, the UAEFIU’s REAR guide requires brokers and agents to obtain identity documents and file a Real Estate Activity Report for sales or purchases of freehold property where:

  • the payment includes cash of AED 55,000 or more, in a single payment or several;
  • any part of the price is paid in virtual assets; or
  • the funds used were converted from or to virtual assets.

Records for these transactions must be kept for at least five years.

Gold, jewellery and precious stones dealers

The AED 55,000 cash trigger applies to single transactions and to transactions that appear linked, so staff need to recognise split payments. The UAEFIU’s DPMSR guide requires identity documents and a DPMSR for cash transactions of AED 55,000 or more with resident and non-resident individuals, and, for companies, a copy of the trade licence and the representative’s ID where the transaction reaches AED 55,000 in cash or by wire transfer. Supplier due diligence and the origin of stock matter as much as customer checks. We often support these clients alongside their accounting and bookkeeping, which keeps cash records and AML records consistent.

Corporate service providers

Formation agents, registered-office providers and nominee arrangements sit close to beneficial ownership risk. Expect questions on how you identify the natural person behind each structure you create or administer, and how you record nominee directors and shareholders.

Independent accountants

The rules apply when an independent accountant prepares or carries out transactions for a client, such as managing client money or accounts, or forming, running, buying or selling companies. Many firms first find they are in scope through payment-handling or company formation work.

How we deliver AML compliance for your business

Each engagement is scoped and quoted in writing before work starts. A typical sequence:

  1. Scoping. We confirm whether and where your activities fall under the DNFBP rules, and which supervisor applies.
  2. Gap review. If you already have documents, we test them against Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025 and list what is missing. Policies written under the 2018 law usually need updating.
  3. goAML registration. We prepare the documents and guide your compliance officer through SACM and the goAML forms until the account is active.
  4. Programme build. Risk assessment, policy and procedures, KYC forms, screening routine and STR escalation process.
  5. Training. A session for the compliance officer and front-line staff, using examples from your own sector.
  6. Ongoing support. Periodic reviews, updates when the rules change and help preparing for a supervisory inspection. For a wider controls review, see our internal audit services.

We work alongside the compliance officer you appoint; the decision to report and the accountability stay with your business, as the law intends. To discuss scope, contact our team.

FAQ

Frequently asked questions

What is a DNFBP in the UAE?

A DNFBP is a designated non-financial business or profession: a business outside the financial sector that must meet AML duties because of the services it provides. In the UAE this covers real estate brokers and agents, dealers in precious metals and stones, independent accountants, company and trust service providers, lawyers, notaries and other independent legal professionals, and commercial gaming operators, each when carrying out the activities listed in Article 3 of Cabinet Resolution No. 134 of 2025.

Who needs goAML registration in the UAE?

Every reporting entity must register on goAML to file suspicious transaction reports. For DNFBPs, that means any business whose activities fall under the DNFBP definition, whether licensed on the mainland or in a free zone. Businesses in DIFC or ADGM register with their own regulator, the DFSA or the FSRA, as the supervisory body.

Do accountants and real estate brokers have to register on goAML?

Independent accountants are DNFBPs when they prepare or carry out transactions for clients involving real estate, client funds, bank or securities accounts, company contributions, or the formation, management, purchase or sale of companies. Real estate brokers and agents are in scope when concluding purchase or sale transactions for customers. If you are in scope, you need to register.

What documents are required for goAML registration?

For entities supervised by MoET or the Ministry of Justice, the UAEFIU guide lists a valid trade licence, the compliance officer’s passport and Emirates ID copies, the approval email from MoET and an authorisation letter. The licence and Emirates ID are also attached as a PDF at the SACM pre-registration stage.

Which anti-money laundering law applies in the UAE in 2026?

Federal Decree-Law No. 10 of 2025, in force from 14 October 2025, and its Executive Regulations, Cabinet Resolution No. 134 of 2025, in force from 14 December 2025. They replaced Federal Decree-Law No. 20 of 2018 and Cabinet Decision No. 10 of 2019.

What is the difference between goAML registration and AML compliance?

goAML registration gives your business access to the UAEFIU’s reporting system. AML compliance is the full programme behind it: risk assessment, policy, customer due diligence, sanctions screening, training, record keeping and reporting. A business can be registered and still fail an inspection if the programme is missing.

Do I need to appoint a compliance officer?

Yes. DNFBPs must appoint a compliance officer at management level who has independence in decision-making and appropriate competence and experience. The officer reviews suspicious activity, decides whether to report, oversees training and reports to senior management. The same person normally registers the business on goAML and becomes its admin user.

How long does goAML registration take?

Neither the UAEFIU nor MoET publishes a fixed timeframe, because each application depends on the supervisor’s review. Most delays come from incomplete or inconsistent submissions, which is what our preparation work is designed to prevent.

TALK TO US

Get goAML-registered and AML-ready

Tell us your activity, licence and emirate, and we will send a written quote covering goAML registration, risk assessment, AML policy and staff training.

+971 56 500 6694 · info@dirhamwise.com · Contact form
ParkLane Tower, Park Regis, Business Bay, Dubai · Monday to Saturday, 9:00am to 6:00pm