AML compliance in the UAE is not a policy binder on a shelf — it is a supervised, inspected obligation with its own penalty grid. Every business classified as a DNFBP — real estate agents, precious metals and stones dealers, auditors, corporate service providers and law firms — must build a documented programme, register on goAML, and be able to show it all to the supervisor on demand. This guide is the setup sequence, in the order the FTA-supervised businesses actually need it.
TL;DR
- The legal base is Federal Decree-Law No. 20 of 2018 on AML, its Executive Regulations (Cabinet Resolution No. 10 of 2019), and the 2025 overhaul in Federal Decree-Law No. 10 of 2025 — confirm which obligations sit with your supervisory authority before filing anything.
- Six components are mandatory: risk assessment, CDD with beneficial-owner identification, sanctions screening, transaction monitoring, STR filing via goAML, and 5-year record keeping with annual training.
- Administrative fines under Cabinet Decision No. 71 of 2024 (as applied to Ministry of Economy and Ministry of Justice supervised DNFBPs) run from AED 50,000 to AED 1,000,000 per violation category, doubled on repetition.
- A missing compliance officer or no goAML registration is the fastest route to the lowest fine band — and the easiest items for an inspector to prove.
Step 1 — confirm you are a DNFBP, and who supervises you
The classification decides everything: which authority inspects you, which penalty grid applies, and what deadlines you answer to. The main DNFBP categories in the UAE are real estate brokers and agents, dealers in precious metals and stones, auditors, and corporate service providers, supervised by the Ministry of Economy, and legal professionals supervised by the Ministry of Justice. If your activity is on this list — even as a side activity — the full AML regime applies to you, not just to banks.
Step 2 — the enterprise-wide risk assessment
Before any policy, document your exposure: which services carry money-laundering risk (large cash property transactions, company formation for third parties, precious metal exports), which customer types (high-risk jurisdictions, PEPs), and which channels (agents, intermediaries). The risk assessment drives every later decision — the depth of due diligence, the monitoring frequency, the escalation thresholds. Supervisors ask for it first, and a risk assessment that was copy-pasted from a template is itself a documented violation.
Step 3 — customer due diligence and beneficial ownership
| Obligation | What it means in practice | Legal base |
|---|---|---|
| Customer Due Diligence (CDD) | Identify and verify the customer before establishing the relationship; re-verify on trigger events | Federal Decree-Law No. 20 of 2018; Executive Regulations |
| Beneficial owner identification | Look through corporate customers to the natural persons who own or control them | Cabinet Resolution No. 109 of 2023 |
| Enhanced due diligence | Deeper checks for high-risk customers, PEPs and high-risk jurisdictions | Executive Regulations, Cabinet Resolution No. 10 of 2019 |
| Sanctions screening | Screen customers and transactions against UN and local sanctions lists before and during the relationship | Federal Decree-Law No. 20 of 2018 |
| Record keeping | Retain CDD files and transaction records for five years | Federal Decree-Law No. 20 of 2018 |
Step 4 — goAML registration and reporting
Every DNFBP registers as a reporting entity on the goAML portal run by the UAE Financial Intelligence Unit, and files Suspicious Transaction Reports there when monitoring flags a transaction. Two setup facts matter: the registration is entity-level (one account per licence), and the reporting obligation is independent of the supervisory authority's inspections — an STR filed on time does not excuse a missing policy, and vice versa. Legal professionals benefit from a specific carve-out: information protected by legal privilege — defence, representation, arbitration, mediation and legal opinion work — is outside the STR duty, which is why the scope of your reporting workflow must be defined precisely.
Step 5 — governance, training and the compliance officer
- Appoint a compliance officer (MLRO) with the authority and independence to escalate to senior management and file STRs.
- Write the internal policies — risk-based CDD, screening, monitoring, escalation and record retention — approved at board or partner level.
- Train the team annually and keep attendance records; training gaps are among the lowest-value but most-cited violations.
- Test the programme — an annual independent review of whether the policies match the actual transaction flow.
Penalty exposure
The administrative grid for DNFBPs supervised by the Ministry of Justice and the Ministry of Economy, Cabinet Decision No. 71 of 2024, sets out dozens of violation categories with fines from AED 50,000 to AED 1,000,000 per violation, doubled on repetition. The lower end covers governance and documentation gaps — no compliance officer, incomplete records, no training; the top end covers dealings with sanctioned or fake-name counterparties. Criminal exposure sits above the administrative grid: money-laundering offences under Federal Decree-Law No. 20 of 2018 carry imprisonment and fines up to AED 5,000,000, which is why the compliance programme is treated as a licence condition, not an option.
Law firms carry the AML obligation alongside the audit and tax obligations — the audit side is covered in our guide on audit services for law firms in the UAE, and the FTA-facing compliance calendar in our guide on corporate tax compliance in the UAE.
How Finanshels handles this
We classify the entity, run the risk assessment, build the policy set, register the goAML account and keep the file inspection-ready with annual training and reviews. Talk to our AML team before the supervisor's letter arrives, not after.
FAQs
Which businesses count as DNFBPs in the UAE?
Real estate brokers and agents, dealers in precious metals and stones, auditors, corporate service providers and law firms — supervised by the Ministry of Economy or the Ministry of Justice depending on the activity.
Do I have to register on goAML?
Yes — every DNFBP registers as a reporting entity on the goAML portal and files suspicious transaction reports there when monitoring flags a transaction.
What are the fines for AML non-compliance?
Administrative fines under Cabinet Decision No. 71 of 2024 range from AED 50,000 to AED 1,000,000 per violation and are doubled on repetition; criminal money-laundering offences carry higher penalties under Federal Decree-Law No. 20 of 2018.
How long must AML records be kept?
Five years from the end of the relationship or the occasional transaction, covering CDD files and transaction records.
Last reviewed: September 2026 by Krishna Subash Nair, AML Compliance Specialist, Finanshels. Rules as of Federal Decree-Law No. 20 of 2018 (as amended by Federal Decree-Law No. 10 of 2025) and Cabinet Decision No. 71 of 2024; verify current obligations against your supervising authority before acting.






