AML & Compliance

AML compliance for UAE businesses

Anti-money-laundering frameworks that meet regulatory expectations and fit how your business actually works.

UAE anti-money-laundering rules reach well beyond banks. Real estate brokers, dealers in precious metals and stones, auditors and accountants, corporate service providers and several other business types are designated non-financial businesses and professions (DNFBPs), with legal duties to identify customers, assess risk, screen against sanctions lists and report suspicious activity.

Supervisors have increased inspections in recent years, and the consequences of weak compliance are serious: significant administrative penalties, restrictions on the business, and reputational damage that can affect banking relationships. A policy document on file is not enough. Supervisors expect to see a framework that is operating in practice.

We help you build that framework and keep it working, from goAML registration and risk assessment to customer due diligence, screening, reporting and staff training. Everything is sized to your business rather than copied from a bank’s manual.

What we cover

AML & Compliance services

  • 01

    goAML registration and ongoing reporting

    goAML is the UAE Financial Intelligence Unit’s platform for suspicious transaction reports and other regulatory reports. Businesses in regulated sectors must register on it and keep their registration current, and some sectors must also file routine reports on specified cash or property transactions. We handle the registration and help you file the reports your sector requires, correctly and on time.

    • goAML registration for the business and its compliance officer
    • Dealers in precious metals and stones reports (DPMSR)
    • Real estate activity reports (REAR)
    • Ongoing filing support and record retention
  • 02

    AML/CFT policy and procedure drafting

    Every regulated business needs written AML/CFT policies and procedures that reflect current UAE law and its own risks. Generic templates rarely satisfy a supervisor because they do not match how the business actually operates. We draft a policy and procedures manual covering governance, risk assessment, due diligence, screening, reporting, record-keeping and training, tailored to your activities and team.

    • Policy and procedures manual written for your business
    • Roles and responsibilities, including the compliance officer
    • Due diligence, screening and reporting procedures
    • Updates when the law or your business changes
  • 03

    Enterprise-wide risk assessment

    A business-wide risk assessment identifies how your customers, products, geographies, delivery channels and transactions could be exposed to money laundering, terrorist financing or proliferation financing. It is the foundation the rest of your compliance programme should be built on, and supervisors routinely ask to see it. We carry out the assessment, document the method and results, and translate them into proportionate controls.

    • Inherent risk analysis across customers, products and geographies
    • Assessment of existing controls and residual risk
    • Documented methodology and risk ratings
    • Annual review and update
  • 04

    KYC and customer due diligence framework

    Customer due diligence means knowing who you are dealing with, who ultimately owns and controls them, and whether their activity makes sense. We design KYC forms, risk-scoring models and procedures for simplified, standard and enhanced due diligence, so staff know exactly what to collect, verify and escalate. The framework also covers ongoing monitoring and periodic review of existing customers.

    • KYC forms for individuals and companies
    • Customer risk-scoring methodology
    • Enhanced due diligence for higher-risk customers
    • Ongoing monitoring and periodic review procedures
  • 05

    Sanctions and PEP screening setup

    UAE businesses must screen customers and counterparties against the UAE Local Terrorist List and the UN Consolidated List, and act without delay if there is a match. Identifying politically exposed persons is also a core part of due diligence. We help you choose or configure a screening approach, define how potential matches are investigated and recorded, and set out the steps to follow when a match is confirmed.

    • Screening against UAE and UN sanctions lists
    • PEP and adverse media screening
    • Match investigation and escalation procedures
    • Freezing and reporting steps for confirmed matches
  • 06

    Suspicious transaction reporting (STR/SAR) support

    When something looks unusual, staff need to know how to raise it, and the compliance officer needs to decide whether it should be reported. Filing a suspicious transaction or activity report is a legal obligation, and alerting the customer to it is prohibited. We help you set up internal escalation procedures and support your compliance officer in assessing cases and preparing clear, complete reports on goAML.

    • Red flag indicators relevant to your sector
    • Internal escalation and decision records
    • Support assessing and drafting STRs and SARs
    • Guidance on tipping-off and confidentiality
  • 07

    AML staff training

    Policies only work if the people applying them understand them. Our AML training explains the legal obligations in plain language and uses examples from your sector so staff can recognise red flags in their own work. Sessions can be run for new joiners, as annual refreshers or as focused briefings for management and the compliance officer, with attendance records kept for inspections.

    • Training content specific to your sector
    • Induction and annual refresher sessions
    • Board and senior management briefings
    • Attendance and assessment records for inspections
  • 08

    Compliance officer support and ongoing monitoring

    Your appointed compliance officer carries significant responsibility, and in smaller businesses the role is often combined with other duties. We provide ongoing support by reviewing higher-risk cases, keeping procedures current with regulatory changes, preparing for supervisory inspections and helping with reports to senior management. This keeps the programme running between annual reviews rather than only when an inspection is announced.

    • Regular compliance reviews and case support
    • Monitoring of regulatory changes
    • Inspection preparation and supervisor questionnaires
    • Compliance reports for senior management
  • 09

    AML audit and gap assessment

    An independent AML review tests whether your framework meets current requirements and whether it is actually being followed. We review policies, risk assessments, customer files, screening records and reports, then set out the gaps in order of priority with clear remediation steps. Many businesses use this before a supervisory inspection, or afterwards to address its findings.

    • Independent review of the full AML framework
    • Sample testing of customer files and screening
    • Prioritised gap report with remediation plan
    • Follow-up review once remediation is complete

Process

How we work

  1. Confirm your obligations

    We establish whether your business is regulated, which supervisor applies, and which registrations and reports are required.

  2. Assess your risk

    We carry out or review your business-wide risk assessment, because everything else is built on it.

  3. Build the framework

    Policies, due diligence, screening and reporting procedures are put in place, and goAML registration is completed.

  4. Train and embed

    Staff and management are trained so the procedures are understood and applied in daily work.

  5. Monitor and review

    Ongoing support, periodic reviews and independent testing keep the programme current and ready for inspection.

AML & Compliance

Why clients choose Shastra

  • 01

    Proportionate to your size

    We build frameworks a small or mid-sized business can actually run, not a bank’s procedures cut down.

  • 02

    Grounded in your operations

    Policies reflect how you really onboard customers and handle transactions, which is what supervisors test.

  • 03

    Connected to your finances

    Our accounting and tax work gives us a practical view of where financial risk shows up in real transactions.

  • 04

    Partner-led

    A partner of the firm oversees AML engagements and is available when difficult judgement calls arise.

FAQs

Frequently asked questions

Have a question that is not answered here? Ask us directly, and we will give you a straight answer.

Ask a question
Does my business need to comply with UAE AML regulations?

If you operate in a sector designated as a non-financial business or profession, such as real estate brokerage, dealing in precious metals or stones, auditing and accounting, or corporate services, you have direct AML obligations. Financial institutions and virtual asset service providers are covered under their own regulators. If you are unsure, we can review your activities and confirm.

What is goAML and who needs to register?

goAML is the reporting platform of the UAE Financial Intelligence Unit. Businesses with AML obligations must register so they can file suspicious transaction reports and any other reports their sector requires, even if they never expect to file one.

What happens if we do not comply?

Supervisors can impose administrative penalties, which can be substantial, as well as measures such as restricting or suspending business activities. Serious violations can also lead to criminal liability. Weak controls can affect your banking relationships too, since banks review their customers’ AML arrangements.

How often should we update our risk assessment and policies?

At least once a year, and sooner if your business changes, for example when you add products, enter new markets or take on different types of customer, or when laws and regulatory guidance change.

Who should be our compliance officer?

The compliance officer should be someone within your business with enough seniority, independence and access to information to do the job properly, and their details are recorded with your goAML registration. In smaller firms the role is often combined with other duties, which is where external support is most useful.

How long does it take to put an AML framework in place?

For most small and mid-sized businesses, the core framework of risk assessment, policies, KYC procedures, screening and goAML registration can be in place within weeks rather than months, depending on how quickly information is available. Training and embedding the procedures continues after that.

Insights

Latest on AML & Compliance

All articles

Consultation

Talk to us about AML & Compliance

Tell us a little about your business and what you need. We will come back to you to arrange a conversation, usually by phone or WhatsApp.