Anti-money-laundering rules in the UAE are often thought of as a banking matter. In fact, a wide range of ordinary businesses have direct legal obligations, and one of the first is registering on goAML, the reporting platform of the UAE Financial Intelligence Unit (FIU).
Who needs to register
Businesses classed as designated non-financial businesses and professions (DNFBPs) must register. These include:
- real estate brokers and agents;
- dealers in precious metals and precious stones;
- auditors and accountants;
- corporate service providers; and
- lawyers, notaries and other legal professionals, when carrying out certain transactions for clients.
Financial institutions and virtual asset service providers are also required to register, under their own supervisors.
Registration is required even if you never expect to file a report. Supervisors check it, and not being registered is itself a breach.
What registration involves
The business registers as a reporting entity, and the compliance officer registers as its user. The compliance officer should be someone with enough seniority and access to information to perform the role. Their details must be kept up to date, so if they leave, the registration needs updating promptly.
The reports
Once registered, the business uses goAML to submit reports, including:
- Suspicious Transaction Reports (STR) and Suspicious Activity Reports (SAR), where there are reasonable grounds to suspect that funds or activity are linked to a crime;
- Dealers in Precious Metals and Stones Reports (DPMSR), which dealers must file for cash transactions at or above AED 55,000;
- Real Estate Activity Reports (REAR), which apply to certain real estate transactions, including those involving cash or virtual assets; and
- reports connected to targeted financial sanctions, where a customer or transaction matches a sanctions list.
Reports must be filed promptly, and customers must never be told that a report has been made or is being considered. This “tipping off” is itself an offence.
Registration is only the start
Supervisors do not stop at checking that you are registered on goAML. During inspections they expect to see a working compliance programme, including:
- a documented business-wide risk assessment;
- written AML policies and procedures that reflect how the business actually operates;
- customer due diligence, with enhanced checks for higher-risk customers;
- sanctions screening of customers and counterparties;
- training records for staff; and
- records kept for the required period.
Penalties for failures can be significant, and weaknesses can also affect a business’s relationship with its bank.
Where to start
If your business falls into one of the categories above and is not yet registered, registration should be the first step. After that, the risk assessment is the foundation on which everything else is built.
If you are unsure whether the rules apply to you, or want help putting a proportionate framework in place, please get in touch.
This article is general information based on the rules as we understand them at the date of publication. It is not advice on your circumstances. Laws and practice change, so please speak to us before acting on it.



