WPAA AcademygoAML / AML
goAML / AML

UAE goAML & AML Compliance Guide

A Practical Guide to Anti-Money Laundering Compliance for UAE Businesses

White Paper Accounts Auditing Updated July 2026 7 min read

How to use this guide

This guide is written in plain English for UAE business owners, finance teams and compliance officers. Use the table of contents on the right to jump to a specific section, or read straight through for a full picture. Have a question specific to your business? Book a free consultation with our team using the buttons at the bottom of this page.

A note on this guide

AML and goAML rules are updated periodically by the UAE authorities and the Financial Intelligence Unit (FIU). This guide covers the enduring fundamentals every DNFBP needs to know. For anything specific to your business, or for the latest FIU rules, please book a free consultation with our team.

Introduction

Anti-Money Laundering (AML) compliance is a legal obligation for a wide range of UAE businesses. The goAML platform is the primary channel through which UAE businesses register with the Financial Intelligence Unit and submit Suspicious Transaction Reports. Non-compliance can lead to significant administrative penalties and reputational damage.

What is goAML?

goAML is the UAE reporting platform used to register with the Financial Intelligence Unit and submit Suspicious Transaction Reports (STRs), Suspicious Activity Reports (SARs) and other regulatory notifications. Every Designated Non-Financial Business or Profession (DNFBP) is required to register on goAML.

Who Must Register?

Common DNFBPs (Designated Non-Financial Businesses and Professions) required to register on goAML include:

  • Auditors and accountants
  • Real estate agents and brokers
  • Dealers in precious metals and stones
  • Corporate service providers
  • Legal consultants and law firms
  • Trust and company service providers

Registration is mandatory

Failing to register on goAML is itself an administrative violation. Registration must be completed before you begin providing services to clients falling within scope of the AML regulations.

Customer Due Diligence (CDD)

CDD is the foundation of AML compliance. Businesses must identify and document every client before onboarding, and keep the information up to date.

Standard CDD includes:

  • Verifying customer identity using reliable documents
  • Identifying and verifying the beneficial owner
  • Understanding the purpose and nature of the business relationship
  • Determining the source of funds and source of wealth
  • Assigning a risk rating to the customer

Enhanced Due Diligence (EDD)

EDD is required for higher-risk clients and transactions. It goes beyond standard CDD and typically applies to:

  • Politically Exposed Persons (PEPs) and their close associates
  • Clients from higher-risk jurisdictions
  • Complex ownership structures
  • Unusual or large transactions without a clear economic rationale
  • Clients operating in higher-risk sectors

Suspicious Transaction Reporting

Businesses must report suspicious transactions and suspicious activity through the goAML platform when red flags are identified. Failure to report is itself a regulatory breach.

Common red flags

  • Transactions inconsistent with the customer profile
  • Unusual payment patterns or routing
  • Reluctance to provide required KYC information
  • Use of shell companies or unusually complex structures
  • Requests for anonymity

AML Policies and Procedures

Every DNFBP should maintain:

  • A written AML Policy tailored to the business
  • A documented customer risk assessment framework
  • Staff training records
  • Customer files with CDD and EDD documentation
  • Internal audit and independent review reports

Risk Assessment

UAE regulations require every DNFBP to prepare and maintain a business-level AML risk assessment. The assessment should cover customer risk, geographic risk, product and service risk, and delivery channel risk. It must be reviewed periodically and whenever the business changes materially.

AML Internal Audit

Regular independent reviews help verify that AML controls are working as intended. An internal AML audit typically covers policy adequacy, CDD and EDD sample testing, training coverage, STR filing quality and record-keeping. Findings should be reported to senior management and remediated on a timely basis.

Common AML Mistakes

  • No business-level risk assessment
  • Incomplete or missing customer files
  • Lack of ongoing staff training
  • Failure to screen customers against sanctions and PEP lists
  • Failure to submit STRs or SARs when red flags are identified
  • No documented AML Compliance Officer

How WPAA Can Help

Strong AML controls protect UAE businesses from regulatory penalties and reputational damage, and give clients confidence that the business is run responsibly.

WPAA assists DNFBPs with goAML registration, AML policy drafting, business risk assessments, staff training, AML internal audits and remediation support.

Need help with goAML / AML?

Book a free 30-minute consultation with our team. We'll review your specific situation and flag anything worth acting on.

Disclaimer

This guide is provided for general informational purposes only and should not be considered accounting, tax, legal, or professional advice. Please consult White Paper Accounts Auditing (WPAA) or another qualified professional before acting on any information contained in this guide.