
RAKEZ Appreciation Certificate
Recognised for Excellence in Partner Performance
Bestax helps Dubai businesses build and maintain a practical AML framework.
We review what applies to your activity, identify gaps, support goAML access and reporting, and prepare your business for Ministry of Economy and Tourism compliance checks.
Tell us your licence activity, your regulator and where your customers and payments come from, and we will confirm what actually applies to you.
The approvals and registrations behind the work.
Good AML support should tell you what you actually need, not hand you a generic policy file.
We start by checking your licence activity, regulator, customer types, payment methods, countries involved and the level of money laundering, terrorism financing and proliferation financing risk in your business.

Our support can include:
Under the current UAE framework, financial institutions, Virtual Asset Service Providers and Designated Non-Financial Businesses and Professions can have AML obligations. For DNFBPs supervised by the Ministry of Economy and Tourism, the main categories include the businesses below.
Businesses involved in buying or selling real estate for customers
Gold, jewellery, diamonds, precious metals and precious-stone businesses
Accounting, audit and assurance professionals within the regulated scope
Company formation, registered office and selected corporate administration services
DNFBPs in mainland UAE and commercial free zones can fall under Ministry supervision. Businesses in the DIFC and ADGM may instead be supervised by the DFSA or FSRA, so the regulator must be confirmed before applying a compliance checklist.
Administrative penalties can apply for weak policies, missing risk assessments, poor CDD, failure to report suspicions, missing records and other compliance failures.
The Ministry actively supervises DNFBPs and continued inspections remain part of the UAE compliance framework.
Banks often ask businesses to explain ownership, source of funds, customers and transaction patterns. A weak compliance file can create avoidable questions.
A clear risk-based process helps staff know when normal CDD is enough, when EDD is needed and when a matter should be escalated to the MLRO.
AML failures can lead to more than a financial cost. Serious cases can involve further regulatory action and separate criminal consequences.
High-risk country lists, sanctions requirements and sector guidance are updated. Your AML programme should change when the risks change.

For reporting entities, access to the UAE Financial Intelligence Unit’s goAML system is a core part of the reporting process. The Ministry currently states that registration is mandatory for DNFBPs and that the registration itself is free.
The process includes pre-registration through the protection system, use of Google Authenticator and registration of the organisation in goAML. Typical documents include the trade licence, an authorisation letter and identification documents for the authorised compliance person.
Our AML registration support focuses on getting the organisation details, compliance contact and supporting documents aligned before submission. Once access is approved, the system is used for the reports that apply to the business, including suspicious transaction or activity reporting.
Document the risks linked to customers, countries, products, services, transaction channels and the way your business operates. The assessment must be reviewed and updated as risks change.
Policies should match the real size and risk of the business. A copied manual that staff do not use is not enough.
Identify and verify customers and beneficial owners, understand the purpose of the relationship and obtain enough information to assess risk.
Apply stronger checks where risk is higher, including appropriate source-of-funds or source-of-wealth work and closer monitoring.
Have a process to identify politically exposed persons and apply the additional controls required by the risk.
Review transactions and customer information so unusual activity, changed ownership or a changed risk profile is not missed.
Screen customers and relevant parties against applicable UAE and UN sanctions requirements and act promptly on confirmed or potential matches.
Staff need a clear internal escalation process. The Compliance Officer or MLRO must be able to assess the concern and file the required report without inappropriate interference.
Training should match the employee’s role and show real red flags for the company’s sector, not only definitions from the law.
Keep CDD, transaction, monitoring, risk-assessment and reporting records in a form that can be provided to the authorities without undue delay.
The UAE’s current principal AML law is Federal Decree-Law No. 10 of 2025, supported by Cabinet Resolution No. 134 of 2025. The new executive framework became effective in December 2025 and the Ministry issued updated DNFBP guidance in March 2026.
For AML compliance Dubai businesses should now make sure their programme also addresses proliferation financing risk, current high-risk country measures, senior-management responsibility and the effectiveness of the Compliance Officer role. The Ministry’s 2026 DNFBP guidance also stresses practical risk assessment, CDD, ongoing monitoring, suspicious reporting, training and record keeping.
DNFBPs are required to appoint a qualified Compliance Officer. Current Ministry guidance says the role should sit at management level, have appropriate authority and independence, and have access to the information needed to perform the job.
The Compliance Officer, also commonly called the MLRO for reporting responsibilities, should oversee the risk assessment, policies, CDD, monitoring, sanctions screening, training, records and reporting process. Senior management remains accountable for compliance even when a permitted third-party compliance arrangement is used.
KYC is only one part of CDD. A compliant process should identify the customer, verify identity from reliable sources, identify and verify the beneficial owner where required, understand why the customer is using your service and assign a risk level.
Higher-risk relationships need stronger checks. That can include more information about the ownership chain, source of funds, source of wealth, expected transactions, countries involved and the reason for unusual payment methods.
Ownership records used for AML should also stay consistent with your UBO compliance records. Keeping the two processes aligned reduces avoidable gaps when regulators or banks review the company.
A business should not wait for proof of a crime before escalating a genuine suspicion. DNFBPs must have procedures to identify unusual activity, assess the concern and report to the UAE Financial Intelligence Unit when the legal reporting test is met.
The report and the fact that a report may be filed must remain confidential. Telling the customer or another unauthorised person about a suspicious report or related investigation can create separate legal exposure.
The Ministry’s March 2026 DNFBP guidance states that the minimum statutory retention period for relevant CDD and transaction records is five years, calculated from the latest applicable event listed in the guidance. Authorities can require a longer period in specific cases.
Your files should allow a reviewer to understand who the customer was, what checks were completed, why the risk rating was chosen, what transactions were reviewed, what concerns were escalated and what action was taken.
Strong bookkeeping also makes transaction review easier. If your financial records are incomplete, consider linking this work with Accounting and Bookkeeping Services in Dubai.
The current administrative penalty schedule used for DNFBPs under Ministry of Justice and Ministry of Economy and Tourism supervision is Cabinet Resolution No. 71 of 2024. The resolution remains listed as active and replaced the older Cabinet Resolution No. 16 of 2021.
| Example Compliance Failure | Published Administrative Fine Range |
|---|---|
| No top-management-approved AML policies and controls | AED 100,000 to AED 200,000 |
| Failure to identify, assess and update business AML risks | AED 50,000 to AED 500,000 |
| Failure to carry out required customer due diligence | AED 50,000 to AED 200,000 |
| Failure to apply Enhanced Due Diligence for identified high risk | AED 100,000 to AED 500,000 |
| Failure to promptly report suspicious transactions to the FIU | AED 100,000 to AED 500,000 |
| Failure to register on the FIU-approved electronic reporting system | AED 50,000 to AED 200,000 |
| Failure to appoint a suitably competent compliance officer | AED 50,000 to AED 200,000 |
| Failure to keep required AML records and data | AED 50,000 to AED 200,000 |
| Failure to register for applicable sanctions-list notifications | AED 50,000 to AED 1,000,000 |
| Dealing with shell banks | AED 200,000 to AED 1,000,000 |
This AML fines UAE penalty table is a practical summary, not a substitute for reviewing the exact violation and regulator. The same resolution allows the Ministry to double the administrative fine for a repeated violation, and other administrative measures may also apply.
AML penalties UAE businesses face are not limited to one fixed fine. The amount depends on the breach, and repeated administrative violations can be treated more severely.
The 2025 federal AML law also contains separate criminal offences and penalties for matters such as money laundering, terrorism financing, tipping off and certain intentional or grossly negligent compliance failures. That is why a business should fix a compliance gap when it is found rather than wait for an inspection.
A risk assessment is the starting point for a useful AML programme. Bestax reviews your customers, services, payment methods, transaction values, delivery channels, geographic exposure, ownership risks and any sector-specific red flags.
We then compare your existing controls with the current UAE requirements and create a clear remediation list. This helps management see what is missing, what needs updating and which gaps create the highest regulatory risk.
Your policy should reflect how your company actually works. We can help structure customer acceptance rules, CDD and EDD steps, PEP handling, source-of-funds checks, sanctions screening, transaction monitoring, internal escalation, suspicious reporting, training and record keeping.
The aim is to create a process employees can follow and management can evidence during an inspection.
Staff who speak to customers, review documents, handle payments or approve transactions need to understand the red flags relevant to their role. Training should explain what to look for, when to stop and ask for more information, and when to escalate the matter to the Compliance Officer.
Management training is also important because senior management approves the framework, provides resources and remains responsible for making sure the compliance programme works.
A regulator may ask for more than a policy document. Your business should be able to show risk assessments, customer files, beneficial-owner checks, risk ratings, screening evidence, training records, MLRO reports, monitoring results and proof that identified gaps were fixed.
Bestax can review a sample of your files, test whether the policy is being followed and create an action plan before a supervisory inspection.
Where broader internal-control weaknesses are found, the review can be coordinated with Internal Audit Services in Dubai so the remediation covers both AML and wider control issues.
Confirm your activity, licensing authority and whether the DNFBP rules apply to your business.
Review existing registration, policies, risk assessment, CDD files, MLRO arrangements and reporting procedures.
Document the risks specific to your business and customer base.
Prioritise missing or weak controls based on regulatory risk.
Prepare or update policies, forms, risk ratings, screening steps and reporting processes.
Train relevant employees using practical examples and escalation steps.
Test selected files and evidence before a regulator requests them.
Update the framework when the business, customer risk, sanctions environment or regulatory guidance changes.
10+Years
UAE accounting and compliance experience
35+Professionals
Accounting, audit, tax and compliance team
1,000+Clients
Businesses supported across the UAE and beyond
If your question is not here, ask it directly.
No. goAML registration applies to reporting entities within the regulated categories, including financial institutions, VASPs and DNFBPs. For Ministry-supervised DNFBPs, this includes real estate agents and brokers, dealers in precious metals and stones, independent accountants and auditors, and trust or company service providers within scope.
Yes. The Ministry of Economy and Tourism currently states that registration on the goAML platform is free. Professional fees can still apply if you hire an adviser to review documents, complete the process or build the wider compliance framework.
The Ministry lists an authorisation letter, identification documents for the authorised person and the commercial trade licence among the core documents. The system also uses the SACM protection process and Google Authenticator.
For businesses required to register, failure to register on the FIU-approved electronic system is listed under Cabinet Resolution No. 71 of 2024 with an administrative fine range of AED 50,000 to AED 200,000. Other compliance failures may create separate penalties.
A common mistake is treating compliance as a one-time registration or policy purchase. Regulators expect the framework to work in practice, including risk assessment, CDD, monitoring, reporting, training, records and management oversight.
DNFBPs are required to appoint a qualified Compliance Officer. The officer must have suitable competence, authority and independence to oversee the programme and reporting process. Senior management remains accountable for the effectiveness of the framework.
There is no useful one-size-fits-all calendar answer. The assessment should be kept current and updated when risk changes, such as new products, new customer types, new countries, ownership changes, new payment methods or regulatory updates.
The Ministry’s March 2026 DNFBP guidance states a minimum statutory period of five years for relevant CDD and transaction records, calculated from the latest applicable event identified in the guidance. Authorities can require a longer period in specific cases.
No. Current Ministry guidance states that senior management and the board retain ultimate accountability. A third-party Compliance Officer may be permitted in certain circumstances, but the business must still oversee the arrangement and meet its legal duties.
We can review your scope, goAML status, risk assessment, policies, customer files, CDD and EDD evidence, sanctions screening, MLRO records, training and record keeping. We then provide a prioritised remediation plan so gaps can be fixed before they become inspection findings.