AML Compliance

At Eighty20, we combine expertise with integrity to deliver reliable business and financial solutions. Our team ensures every service and report adds real value to your business growth.

Table of Contents

Anti-money laundering compliance in the UAE is not completed by preparing a policy and filing it away.

Businesses subject to AML requirements must maintain an active, risk-based framework that reflects their customers, services, transactions, ownership structures, geographic exposure, payment methods, and actual business activities.

Eighty20 provides AML compliance services in the UAE for eligible Designated Non-Financial Businesses and Professions, or DNFBPs.

We help businesses assess financial crime risks, build practical AML/CFT/CPF controls, improve Customer Due Diligence, review beneficial ownership, strengthen screening processes, prepare compliance documentation, support goAML procedures, and identify gaps before they become regulatory problems.

What Is AML Compliance?

AML stands for Anti-Money Laundering.

It refers to the policies, controls, systems, and procedures businesses use to identify and reduce the risk of criminals using legitimate companies to move, disguise, or benefit from illicit funds.

The UAE framework also addresses:

  • Terrorism Financing
  • Proliferation Financing

These areas are commonly addressed together as AML/CFT/CPF compliance.

An effective AML framework may include:

  • Business-Wide Risk Assessment
  • Customer Due Diligence
  • Beneficial Owner identification
  • Customer risk classification
  • Enhanced Due Diligence
  • PEP screening
  • Sanctions screening
  • Ongoing monitoring
  • Suspicious activity escalation
  • goAML reporting procedures
  • Employee training
  • Record keeping
  • Internal controls
  • Periodic compliance reviews

The controls should reflect the actual risks faced by the business.

A generic AML policy copied from another company may not adequately address the risks arising from your own customers, products, services, countries, or transaction patterns.

What Are the Current UAE AML Laws in 2026?

The UAE strengthened its anti-money laundering framework through Federal Decree-Law No. 10 of 2025 regarding Anti-Money Laundering and Combating the Financing of Terrorism and Proliferation Financing.

The framework is supported by Cabinet Resolution No. 134 of 2025, which provides the Executive Regulations of the Decree-Law, alongside other relevant legislation, decisions, regulatory guidance, and sector-specific requirements.

The modern UAE framework places significant emphasis on areas including:

  • Risk-based compliance
  • Customer identification
  • Beneficial ownership
  • Internal AML controls
  • Suspicious activity reporting
  • Sanctions compliance
  • Ongoing monitoring
  • Record keeping
  • Financial crime risk management
  • Terrorism financing
  • Proliferation financing

The applicable obligations depend on the business activity and the relevant supervisory authority.

Which UAE Businesses Are Subject to AML Requirements?

AML obligations do not apply to every UAE business in exactly the same way.

Financial institutions and certain Designated Non-Financial Businesses and Professions are subject to specific AML requirements when carrying out covered activities.

DNFBP sectors overseen by the UAE Ministry of Economy and Tourism include:

  • Real estate brokers and agents
  • Dealers in precious metals and precious stones
  • Independent accountants and auditors
  • Trust and company service providers

Legal professionals and certain other regulated businesses may fall under another competent supervisory authority.

A company should therefore not rely only on the wording of its trade licence.

Its actual services, customer relationships, transactions, business model, and regulator should also be considered when determining AML obligations.

AML Compliance for Real Estate Businesses

Real estate transactions can involve:

  • High transaction values
  • Overseas buyers and sellers
  • Corporate ownership structures
  • Third-party payments
  • Multiple jurisdictions
  • Complex beneficial ownership
  • Unusual funding arrangements

Real estate brokers and agents carrying out covered transactions should understand who their customers are, identify relevant beneficial owners, assess customer and transaction risks, maintain suitable records, and establish procedures for escalating unusual or suspicious activity.

Risk assessments may consider:

  • Buyer and seller profiles
  • Beneficial ownership
  • Geographic risk
  • Payment methods
  • Source of funds
  • Property values
  • Transaction behaviour
  • Third-party involvement

Higher-risk situations may require Enhanced Due Diligence and closer monitoring.

AML Compliance for Dealers in Precious Metals and Precious Stones

Gold, diamonds, jewellery, and other valuable commodities can create heightened financial crime risks because they are portable, valuable, and transferable.

Covered dealers should assess risks associated with:

  • Customer profile
  • Transaction value
  • Cash payments
  • Products
  • Delivery method
  • Source of funds
  • Geographic exposure
  • Beneficial ownership
  • Third-party payments
  • Sanctions exposure

AML controls should reflect the dealer’s actual sales and transaction process rather than operating separately from the commercial workflow.

AML Compliance for Accountants and Auditors

Independent accountants and auditors may gain access to sensitive information concerning:

  • Ownership structures
  • Financial transactions
  • Company accounts
  • Tax records
  • Assets
  • Banking arrangements
  • Corporate structures

Certain professional services can expose accounting and audit firms to money laundering, terrorism financing, or proliferation financing risks.

Firms should determine when their activities fall within applicable DNFBP requirements and maintain processes for identifying customers, beneficial owners, risk factors, suspicious behavior, and relevant reporting obligations.

AML Compliance for Trust and Company Service Providers

Trust and company service providers may assist with:

  • Company formation
  • Corporate administration
  • Registered office services
  • Legal-person structuring
  • Ownership arrangements
  • Management-related services

These activities can involve overseas owners, corporate shareholders, nominee arrangements, multiple legal entities, and complex ownership chains.

This makes clear beneficial ownership identification and risk assessment particularly important.

What Do Our AML Compliance Services Cover?

Eighty20 helps businesses develop or improve AML frameworks based on their actual risks.

We begin by understanding:

  • Business activities
  • Trade licence
  • Services
  • Customer types
  • Payment methods
  • Countries involved
  • Ownership structures
  • Transaction patterns
  • Applicable supervisory authority
  • Existing AML controls

We then identify compliance gaps and help strengthen the framework.

Our services may include:

  • AML compliance gap assessment
  • Business-Wide Risk Assessment
  • AML/CFT/CPF policy preparation
  • Customer acceptance procedures
  • CDD and KYC processes
  • Beneficial Owner review
  • Customer risk-rating frameworks
  • Enhanced Due Diligence procedures
  • PEP screening processes
  • Sanctions screening procedures
  • Ongoing monitoring frameworks
  • goAML registration support
  • Suspicious reporting procedures
  • AML training
  • Record-keeping frameworks
  • Compliance file reviews
  • Remediation plans
  • Periodic AML framework reviews

Management and the appointed compliance function remain responsible for ensuring that required controls are actually implemented.

What Is a Business-Wide Risk Assessment?

A Business-Wide Risk Assessment, or BWRA, identifies where money laundering, terrorism financing, and proliferation financing risks may arise across the organisation.

A BWRA may assess:

  • Customer types
  • Products and services
  • Payment methods
  • Transaction channels
  • Countries and jurisdictions
  • Ownership structures
  • Delivery channels
  • Agents and intermediaries
  • New technologies
  • High-risk activities
  • Transaction values
  • Business relationships

A strong risk assessment should explain why each area has been classified as low, medium, or high risk.

The assessment should then be connected to actual controls.

For example, a higher-risk customer category may require more extensive due diligence, senior management approval, additional source-of-funds evidence, or more frequent monitoring.

AML Policies and Procedures

An AML policy should explain how compliance works inside the business.

It may cover:

  • Governance and responsibilities
  • Customer acceptance criteria
  • CDD requirements
  • Beneficial Owner checks
  • Customer risk classification
  • Enhanced Due Diligence
  • PEP management
  • Sanctions screening
  • Ongoing monitoring
  • Internal escalation
  • Suspicious activity reporting
  • goAML procedures
  • Employee training
  • Record keeping
  • Independent review
  • Policy updates

The document should reflect the organisation’s actual operations.

A policy that describes controls employees do not understand or perform may provide little practical protection.

What Is Customer Due Diligence?

Customer Due Diligence, or CDD, is the process of identifying the customer, verifying relevant information, and understanding the purpose and expected nature of the business relationship.

Depending on the customer and risk level, information may include:

  • Full legal name
  • Nationality
  • Date of birth
  • Emirates ID or passport
  • Residential address
  • Company trade licence
  • Incorporation documents
  • Ownership records
  • Authorised signatories
  • Business activities
  • Purpose of the relationship
  • Expected transactions
  • Source of funds
  • Other relevant supporting documents

CDD requirements should be proportionate to risk.

Higher-risk situations generally require more extensive checks.

How Should Beneficial Owners Be Identified?

The direct shareholder of a company may not always be the person who ultimately owns or controls it.

Businesses should understand the ownership chain and identify the relevant natural person or persons exercising ultimate ownership or control.

This may require reviewing:

  • Corporate registers
  • Shareholding records
  • Incorporation documents
  • Parent-company information
  • Overseas company records
  • Ownership diagrams
  • Control arrangements

Complex ownership structures should have a reasonable commercial explanation.

Where ownership or control cannot be understood clearly, additional investigation may be necessary.

Customer Risk Assessment

Not every customer presents the same financial crime risk.

A customer risk assessment may consider:

  • Nationality
  • Residence
  • Customer type
  • Business activity
  • Countries involved
  • Ownership complexity
  • Source of funds
  • Transaction value
  • Payment behaviour
  • Delivery channel
  • Political exposure
  • Sanctions risk
  • Adverse information
  • Expected activity

The reasons behind the risk rating should be documented rather than relying only on a numerical score.

What Is Enhanced Due Diligence?

Enhanced Due Diligence, or EDD, involves additional checks where higher money laundering, terrorism financing, or proliferation financing risk has been identified.

EDD may involve:

  • Additional identification documents
  • Further ownership verification
  • Source-of-funds evidence
  • Source-of-wealth information
  • Senior management approval
  • Independent verification
  • Additional transaction analysis
  • More frequent monitoring
  • Stronger internal controls

The level of EDD should be proportionate to the identified risk.

Politically Exposed Person Screening

A Politically Exposed Person, or PEP, is an individual who holds or has held a prominent public function.

Relevant family members and known close associates may also require additional consideration.

A PEP relationship does not automatically mean criminal activity is present.

However, the relationship may require additional risk management measures such as:

  • Senior management approval
  • Source-of-funds checks
  • Source-of-wealth assessment
  • Enhanced ongoing monitoring
  • Documented risk decisions

The business should record how the relationship was assessed and approved.

Sanctions Screening

Sanctions screening helps identify whether customers or connected parties may be subject to applicable targeted financial sanctions or other relevant restrictions.

Screening may include:

  • Customers
  • Beneficial owners
  • Directors
  • Authorised signatories
  • Business partners
  • Payors
  • Payees
  • Other connected parties

A potential name match should be investigated rather than automatically treated as either a confirmed match or a false positive.

Screening should also continue throughout the relationship because customer information and sanctions lists may change.

Ongoing Customer Monitoring

AML compliance does not stop once a customer passes onboarding.

Businesses should continue monitoring the relationship and determine whether actual activity remains consistent with what was originally expected.

Ongoing monitoring may include:

  • Reviewing transaction values
  • Checking payment methods
  • Comparing activity with customer history
  • Updating expired documents
  • Re-screening relevant parties
  • Reviewing high-risk relationships
  • Monitoring changes in ownership
  • Investigating unusual activity

Higher-risk customers may require more frequent review.

goAML Registration and Reporting Support

The goAML system is used by the UAE Financial Intelligence Unit to receive and process suspicious activity and suspicious transaction reports.

The Ministry of Economy and Tourism confirms that DNFBPs subject to these obligations must register on goAML and use the platform for relevant reporting.

goAML may be used for reports including Suspicious Transaction Reports and Suspicious Activity Reports.

Registration itself, however, is not equivalent to complete AML compliance.

A business must also maintain appropriate risk assessments, CDD processes, monitoring, internal reporting procedures, records, and other applicable controls.

Eighty20 can support businesses with goAML registration and reporting procedures.

Final reporting decisions and the accuracy of information submitted remain the responsibility of the reporting entity and relevant authorised personnel.

Suspicious Transaction and Activity Reporting

Suspicion can arise before or after a transaction is completed.

Concerns may relate to:

  • Customer identity
  • Ownership structure
  • Source of funds
  • Payment method
  • Transaction behaviour
  • Attempted transactions
  • Unusual activity
  • Inconsistent explanations
  • Sanctions concerns

Employees should understand how to escalate concerns internally.

The appropriate compliance officer or authorised person should assess the available information and determine whether regulatory reporting is required.

Businesses must also avoid inappropriate disclosure to the customer where doing so would constitute prohibited tipping off.

AML Record Keeping Requirements in the UAE

Record keeping is a core AML obligation.

The UAE Ministry of Economy and Tourism’s 2026 DNFBP guidance states that DNFBPs must maintain comprehensive records relating to transactions, Customer Due Diligence, business correspondence, AML risk assessments, monitoring, and related analysis.

The minimum statutory retention period is generally five years, calculated from the most recent applicable event, which may include:

  • Termination of the business relationship
  • Completion of an occasional transaction
  • Completion of a supervisory inspection
  • A final judicial judgment
  • Dissolution or termination of a legal person or arrangement

Competent authorities may require records to be retained for longer in particular circumstances.

AML records may include:

  • Customer identification
  • Beneficial ownership documents
  • Customer risk assessments
  • Screening evidence
  • Transaction records
  • Source-of-funds evidence
  • Monitoring records
  • Internal concern reports
  • goAML-related records
  • Training records
  • Senior management approvals
  • Compliance reports
  • Policy reviews

Records should be organised, secure, and capable of being retrieved when required by the competent authority.

AML Training for Employees

Employees should understand the financial crime risks connected with their actual responsibilities.

Training may cover:

  • AML/CFT/CPF fundamentals
  • Customer warning signs
  • Required customer documents
  • Internal escalation procedures
  • PEP risks
  • Sanctions concerns
  • Suspicious activity
  • Tipping-off restrictions
  • Record keeping
  • Changes to internal procedures

Training should be relevant to the employee’s role.

For example, sales staff, onboarding teams, finance employees, and compliance personnel may require different levels of detail.

Training records should also be maintained.

Common AML Compliance Problems We Help Identify

Common AML Compliance Problem What It Means How We Help
Missing Business-Wide Risk Assessment The business has AML policies but no properly documented assessment of the actual financial crime risks it faces. We help identify key business risks and connect them with practical AML controls.
Generic AML Policies Template-based policies may not reflect the company’s customers, transactions, products, services, or workflows. We help align AML procedures with the business’s actual operations.
Incomplete Customer Files CDD files may be missing identification documents, ownership records, source-of-funds evidence, or required approvals. We review file gaps and help improve the customer documentation process.
Weak Beneficial Owner Checks The business may stop at the direct shareholder without identifying the individual who ultimately owns or controls the customer. We help develop a more structured beneficial ownership review process.
Missing Customer Risk Ratings Customers may be onboarded without a documented assessment of their financial crime risk. We help establish a clear and repeatable customer risk-rating methodology.
One-Time Sanctions Screening Screening is completed only during onboarding and may not capture later changes in sanctions status or customer information. We help develop periodic and event-driven screening procedures.
Unclear Suspicious Activity Escalation Employees may identify unusual activity but may not know who to report it to or what information should be recorded. We help create a clear internal escalation and reporting process.
Missing Training Evidence AML training may take place without proper attendance records or supporting documentation. We help organise training records and evidence of employee participation.
Weak Compliance Records AML checks may be performed correctly but not properly documented. We help improve record-keeping so the business can demonstrate its compliance activities more clearly during reviews or inspections.

Our AML Compliance Services Include

Depending on the engagement, our support may include:

  • AML compliance gap assessment
  • Business-Wide Risk Assessment
  • AML/CFT/CPF policy preparation
  • Customer acceptance procedures
  • Customer Due Diligence forms
  • Customer risk-rating tools
  • Beneficial Owner procedures
  • Enhanced Due Diligence checklists
  • PEP procedures
  • Sanctions screening procedures
  • Ongoing monitoring guidance
  • goAML registration support
  • Suspicious reporting procedures
  • AML training support
  • Record-keeping framework
  • Compliance file review
  • Remedial action planning
  • Periodic AML framework review

The final scope depends on the business activity, supervisory authority, size, complexity, and risk profile.

Internal AML Team vs Outsourced AML Support

Area Internal AML Team Outsourced AML Support
Business knowledge Strong direct knowledge of internal operations Business knowledge developed through assessment and ongoing engagement
Policy development Requires internal AML expertise Specialist policy and framework support can be provided
Risk assessment Prepared internally Independent support can help structure or review the assessment
Compliance reviews Requires internal resources Periodic reviews can form part of the engagement
CDD framework Built and maintained internally Templates, processes, and controls can be supported
Training Organised internally Role-based training support can be provided
Monitoring Day-to-day responsibility remains internal Procedures and review support can be provided
Final compliance decisions Company responsibility Company responsibility
Regulatory obligations Remain with the company Remain with the company
Cost structure Internal staff, systems, training, and administration Based on the agreed scope of outsourced support

Our AML Compliance Process

Initial Business Assessment

We review the business activity, licence, customer profile, transactions, geographic exposure, and relevant supervisory authority.

Compliance Gap Assessment

Existing documents, risk assessments, customer files, procedures, screening records, and training evidence are reviewed where included in the engagement.

Framework Development

Required AML policies, risk assessments, forms, controls, and procedures are prepared or improved according to the agreed scope.

Implementation Support

We explain how the relevant CDD, screening, escalation, monitoring, and record-keeping procedures should operate.

Periodic Review and Improvement

AML risks and regulatory requirements can change.

Periodic reviews help determine whether policies, risk assessments, customer files, and controls remain appropriate.

FAQs:

No. AML obligations do not apply to every company in the same way. Financial institutions and covered DNFBPs are subject to specific AML requirements. A company should consider its actual business activities, transactions, and supervisory authority when determining whether the AML framework applies.

A Business-Wide Risk Assessment identifies the money laundering, terrorism financing, and proliferation financing risks faced by the organisation. It normally considers areas such as customers, services, transactions, countries, payment methods, ownership structures, and delivery channels.

The findings help determine which AML controls should be applied.

KYC, or Know Your Customer, focuses primarily on identifying and understanding customers. AML is the wider compliance framework and can include:

  • Risk assessment
  • KYC and CDD
  • Beneficial ownership
  • Sanctions
  • PEP controls
  • Monitoring
  • Suspicious activity reporting
  • Training
  • Record keeping

KYC is therefore one component of AML compliance.

Covered DNFBPs are required to register on the goAML platform and use it for applicable suspicious activity and suspicious transaction reporting requirements. Registration alone does not constitute complete AML compliance.

Enhanced Due Diligence involves additional checks where a customer, relationship, or transaction presents higher financial crime risk. It may include additional ownership evidence, source-of-funds information, source-of-wealth checks, senior management approval, and increased monitoring.

The Ministry of Economy and Tourism’s current DNFBP guidance provides a minimum statutory retention period of generally five years, calculated according to the relevant triggering event. Competent authorities may require records to be retained for longer in particular cases.

No. Being a Politically Exposed Person does not automatically mean the individual is involved in financial crime. However, the relationship may require additional risk assessment, appropriate approval, source-of-funds or source-of-wealth checks, and enhanced ongoing monitoring.

No. Screening should form part of an ongoing risk management process because customer information, ownership structures, and sanctions lists may change after onboarding.

The concern should be escalated internally according to the company’s AML procedures.

The relevant compliance officer or authorised person should review the facts and determine whether further due diligence, monitoring, internal action, or reporting through goAML is required.

This depends on the business, regulator, legal requirements, required independence, responsibilities of the role, and agreed service scope. The position should be reviewed before confirming whether any compliance officer function can be provided.

Build a Practical AML Compliance Framework

Eighty20 can help you review existing gaps, improve AML controls, prepare practical compliance documents, and build a framework aligned with the risks faced by your UAE business.

Contact Eighty20 to discuss your AML compliance requirements in the UAE.

Get In Touch
Start and Manage your Business in the Gulf with Eighty20

Need to talk

+971 55 435 1884