AML/CFT Health Check

An AML/CFT health check is an independent review that tests whether your AML compliance programme actually works, as opposed to whether it exists on paper. It examines your risk assessment, policies, customer due diligence files, screening, monitoring, reporting, training, and records against UAE law and your supervisor’s expectations, then hands you a prioritised list of what to fix and in what order. Article 21 of Cabinet Resolution No. 134 of 2025 requires an independent audit function to test the effectiveness and adequacy of the AML/CFT framework. A properly scoped independent health check may help an entity evidence compliance with this requirement, provided that the review is sufficiently independent, risk-based, documented and supported by control and sample testing.

The logic is simple. An inspection is coming, whether this year or next. Every finding it produces will cost you something: a penalty, a remediation deadline, a licence condition, or a bank asking questions it did not ask before. A finding you discover yourself costs you a fix. That is the entire proposition, and it is why the useful health check is the uncomfortable one. A review that tells you everything is fine has told you nothing you can act on.

Find it before they do.

Get an independent AML/CFT health check with findings ranked by regulatory exposure, not by ease of fixing.

What Is an AML/CFT Health Check?

It is a diagnostic. We take your programme apart control by control and test each one against three questions: does the law require it, does your documentation claim it, and does the evidence show it happening. Findings arise wherever those three answers diverge, and in our experience the most common divergence is not a missing control but a documented control nobody performs.

You will see the same exercise called an AML health check, an anti-money laundering health check, a compliance health check, an AML gap analysis, an AML compliance check, or an independent AML review. The scope varies with the label, and what matters is the depth. A checklist review confirms that documents exist. A health check tests whether controls operate. Only the second one predicts what an inspector will find.

It is also distinct from your risk assessment, and the two are frequently confused. Your enterprise-wide risk assessment asks how much ML, TF, and PF risk your business carries. A health check asks how well your programme is managing it. You need both, and the health check tests whether the risk assessment itself is current and defensible.

AML Gap Analysis: The Core of Every Health Check

An AML gap analysis compares what your business does against what the law, your supervisor, and your own documented framework require, then records every difference as a finding with a fix. It is not a separate product from a health check. It is what a health check produces.

We run the gap analysis across four reference points rather than one, because a single benchmark misses too much:

The law.

Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025, article by article, including the provisions most legacy programmes miss: proliferation financing controls, the objective knowledge standard, and the current CDD thresholds.

Your supervisor's expectations.

MoET, MoJ, CBUAE, CMA, GCGRA, VARA, DFSA, ADGM RA, or FSRA guidance, because two firms with identical federal obligations can face different supervisory emphasis.

Your own framework.

Your policies, procedures, and risk assessment, since a control you promised in writing and do not perform is a worse finding than one you never claimed.

The penalty schedule.

For MoET and MoJ supervised DNFBPs, the 41 listed violations under Cabinet Resolution No. 71 of 2024 make a useful and uncomfortably practical test list, because they are what you will actually be fined for.

Each gap is then rated by regulatory exposure rather than by how easy it is to close, which is the difference between a report that reduces risk and a report that produces activity. Firms that fix the quick items first and leave the exposed ones for later usually discover the ordering was the real finding.

Is an Independent AML Audit Mandatory in the UAE?

An independent audit function to test the AML/CFT programme is required [Cabinet Resolution No. 134 of 2025, Article 21], and this obligation surprises firms more than any other on this page. Many businesses have a policy, an appointed compliance officer, and training records, and have never commissioned an independent test of whether any of it works.

The word independent is doing real work in that sentence. Your compliance officer cannot audit their own programme, for the same reason an accountant does not audit their own accounts. The officer built the controls, made the judgement calls, and has every incentive, entirely honestly, to read the evidence in their own favour. Independence can come from an internal audit function where you have one, a group function, or an external reviewer where you do not.

The requirement also connects to a broader duty that runs through the whole framework: your internal policies, controls, and procedures must have their implementation monitored and their effectiveness assessed [Cabinet Resolution No. 134 of 2025, Article 5(2)]. Assessed is not a synonym for described. Something has to be tested, and someone has to be able to show the testing happened.

Not sure whether you owe an independent audit?

Tell us your licence and supervisor and we will confirm what applies to you, with no obligation.

UAE AML Laws Your Health Check Tests Against

Every finding we raise cites the provision it comes from, so your compliance officer can defend the fix internally and your supervisor can see the basis for it:

Legal InstrumentWhat It RequiresWhat We Test
Federal Decree-Law No. 10 of 2025 The primary AML/CFT/CPF statute, in force 14 October 2025, repealing FDL No. 20 of 2018 (Article 41). Preventive measures on a risk-based approach (Article 19), STR duties (Article 18), supervisory powers (Article 16), administrative penalties of AED 10,000 to AED 5,000,000 per violation (Article 17). Whether your framework has been realigned since October 2025 at all. Legacy alignment is the single most common finding we raise, because a programme built on the repealed 2018 law fails before any individual control is examined.
Cabinet Resolution No. 134 of 2025, Article 21 An independent audit function to test the AML/CFT programme, and ongoing employee training and development. Whether an independent test has ever been performed, and whether training is role-based, current, and evidenced with attendance and assessment records rather than asserted.
Cabinet Resolution No. 134 of 2025, Article 5 Documented ML/TF/PF risk assessment taking the National Risk Assessment into account (5(1)); senior-management-approved policies proportionate to nature and size with implementation monitored and effectiveness assessed (5(2)); simplified due diligence only where risk allows (5(3)); enhanced due diligence for high-risk situations (5(2)(c)). Whether the risk assessment is current, whether the policies trace to it, whether senior management approval is dated and evidenced, and whether SDD and EDD are applied on a documented basis rather than by habit.
Cabinet Resolution No. 134 of 2025, Articles 6 to 10 and 16 CDD and verification, for financial institutions, Article 7 addresses an occasional transaction threshold of AED 55,000 and wire transfers of AED 3,500. For VASPs, the occasional transaction threshold is AED 3,500. For DPMS, the AED 55,000 cash threshold arises from the DNFBP scope provisions.

Commercial gaming has its own threshold under Article 3. Ongoing monitoring, beneficial ownership to the 25% standard with the fallback cascade, and PEP identification.
Live file testing on a risk-weighted sample. This is where health checks earn their fee, because the gap between a documented onboarding procedure and the files actually on the system is usually wider than management expects.
Cabinet Resolution No. 134 of 2025, Articles 19, 20, 22, 23 and 25 Tipping-off prohibition and reporting procedures, third-party reliance conditions, the compliance officer at management level with competence and independence, countermeasures for high-risk countries, and record keeping with prompt retrieval. Escalation and decision logs, goAML registration and filing readiness, the officer's actual independence and authority, and a retrieval test: we ask for specific records and time how long they take to produce.
Cabinet Decision No. 74 of 2020 Targeted financial sanctions: screening against UN and UAE Local Terrorist Lists, freezing without delay, and reporting to the Executive Office for Control and Non-Proliferation. Screening coverage and list currency, match handling and disposition quality, the freeze protocol, and whether anyone has tested that the screening engine is still matching.
Cabinet Resolution No. 71 of 2024 The administrative penalty schedule for DNFBPs supervised by the MoET and MoJ: 41 listed violations with fines of AED 50,000 to AED 1,000,000, doubling where the same violation recurs within one year. Used as a direct test list where it applies to you, so findings are expressed in the same terms your supervisor would use.
Sectoral guidance and free zone rulebooks MoET Guidelines for DNFBPs (September 2025), CBUAE, CMA, MoJ, GCGRA and VARA expectations, plus the DFSA AML Module and FSRA AML Rulebook. The DFSA additionally requires an annual AML return. Supervisor-specific obligations, including free zone requirements that sit on top of the federal framework and are easy to overlook when a group applies one standard everywhere.

The finding behind most other findings: a programme that was never realigned after 14 October 2025. If your policy still cites Federal Decree-Law No. 20 of 2018, the health check will produce findings across CDD, monitoring, reporting, and training simultaneously, because they all inherit from a repealed framework.

What an AML Compliance Check Covers, Control by Control

The scope is calibrated to your licence and size, and a full check covers:

Governance and the compliance function.

Appointment, competence, independence, authority to escalate, reporting cadence to senior management, and whether the officer can actually block a transaction.

Risk assessment.

Currency, methodology, whether NRA and SRA findings changed anything, and whether the ratings are defensible.

[Cabinet Resolution No. 134 of 2025, Article 5(1)]

Policies, controls, and procedures.

Legal alignment, internal consistency, senior management approval, version control, and whether the procedures describe what the business does.

Customer due diligence files.

Risk-weighted sampling across onboarding and periodic review, verification quality, beneficial ownership to the 25% standard, and EDD where triggered.

Screening.

Sanctions, PEP, and adverse media coverage, list currency, match disposition, and the freeze workflow.

Transaction monitoring.

Rules and thresholds against your assessed risk, alert handling quality, backlogs, and closure rationale.

Reporting

Internal escalation, the officer’s decision log, goAML registration and filing readiness, and the sector reports your supervisor expects, including REAR and DPMSR where applicable.

Training.

Coverage by role, currency, assessment, and whether attendance records would survive an inspector interviewing a front-line employee.

[Cabinet Resolution No. 134 of 2025, Article 21]

Record keeping.

Retention, accessibility, and a live retrieval test against the prompt production standard.

[Cabinet Resolution No. 134 of 2025, Article 25]

AML/CFT Compliance Service or Independent AML Health Check?

These are two different engagements and firms often ask for one when they need the other. A compliance service builds or runs part of your programme: drafting the policy, preparing the risk assessment, delivering training, or supporting reporting. An independent audit tests what has been built. The same firm can do both, but not on the same work at the same time, because reviewing your own output is not independence in any sense a supervisor would accept.

How we handle it in practice: where we have built your framework, we can run the health check on the parts we did not build, or bring in a reviewer who was not involved, and we will tell you plainly when the honest answer is that someone else should review it. Where you need remediation after a health check, we can support the fixes, and a subsequent re-test should then be run by someone who did not perform them. Saying this out loud costs us occasional work and is the only defensible way to sell both services.

CFT Check and Sanctions Screening: What We Test

Counter-terrorism financing controls fail differently from AML controls, which is why we test them separately. An AML failure usually shows up as a weak file. A CFT or sanctions failure shows up as a name that was never matched, and it carries a freeze obligation with no time to spare.

List coverage and currency.

Which lists you screen against, where the data comes from, how often it updates, and the elapsed time between a designation and your screening reflecting it.

Match logic.

Behaviour on Arabic and transliterated names, threshold settings, and whether anyone has tuned them without documenting why.

Disposition quality.

Sample review of cleared matches, because a screening engine that alerts correctly and is cleared carelessly produces exactly the same outcome as one that never alerted.

Freeze protocol.

Who can freeze, how fast, what happens outside business hours, and whether reporting to the Executive Office is documented. [Cabinet Decision No. 74 of 2020]

Silent failure testing.

Whether the screening is still running as configured. Feeds lapse, integrations break, and nothing visibly changes until a designation is missed. Our AML screening software testing and validation service covers this in depth.

AML Check vs AML Health Check: Which Do You Need?

Worth separating, because the same two words mean two very different things and the wrong one wastes your time.

An AML check

is a lookup on a single person or company: a sanctions, PEP, and adverse media screen against databases, sometimes with a report attached. It answers whether this counterparty is a problem. It takes minutes, and it is a transaction-level control.

An AML health check

is a review of your whole compliance programme against the law. It answers whether your business would withstand an inspection. It takes weeks, and it is a governance-level exercise.

AML Health Check Services: What You Receive

Deliverable

What It Does

Health check report with rated findings

Every finding with its legal citation, evidence, risk rating, and the fix, ordered by regulatory exposure

AML gap analysis matrix

Requirement by requirement: compliant, partial, or gap, so nothing is left to interpretation

Prioritised remediation plan

Owners, deadlines, and sequencing, written so it can be handed straight to the compliance officer

File testing working papers

The sample tested, what was found, and the basis for each conclusion, which is what a supervisor or auditor will ask to see

Senior management summary

A short, honest board-level briefing on exposure, so approval of the remediation budget is an informed decision

Inspection readiness pack

The documents and evidence a supervisor typically requests first, assembled and gap-checked

Re-test on closure

Verification that the fixes were implemented, which is the part most firms skip and inspectors check

Our AML/CFT Health Check Process, Step by Step

1. Scoping

Licence, supervisor, business model, volumes, and any inspection history or open findings, so the review is aimed at your actual exposure.

2. Document review.

Risk assessment, policies, procedures, registers, training records, and reports, tested against the current law rather than the version they were written under.

3. Control walkthroughs.

Interviews with the compliance officer, front-line staff, and operations, because the person performing a control describes it differently from the person who wrote it.

4. File and sample testing.

Risk-weighted CDD file sampling, screening disposition review, alert handling review, and a record retrieval test. [Cabinet Resolution No. 134 of 2025, Articles 6 to 10, 25]

5. Gap analysis and rating.

Findings mapped to the provision each one breaches, then rated by regulatory exposure.

6. Report and management debrief.

Findings presented to the compliance officer first for factual accuracy, then to senior management with the exposure stated plainly.

7. Remediation planning.

Owners, deadlines, and sequencing, with support available for the fixes themselves.

8. Re-test and closure.

Verification that each finding is actually closed, documented so it stands as evidence of corrective action.

When to Run an AML Health Check: Six Triggers

Annually, as your independent test.

The default cycle, satisfying the independent audit expectation and keeping findings small. [Cabinet Resolution No. 134 of 2025, Article 21]

After a legal change.

The realignment to Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025 is the current example, and it is not a light-touch update.

Before an expected inspection.

If your supervisor has signalled a visit, the sequence you want is your findings first, theirs second.

After an inspection finding.

To establish whether the finding is isolated or symptomatic, which is the question supervisors ask next.

On a material business change.

New products, markets, channels, licences, or an acquisition, since inherited programmes are rarely equivalent to yours.

When a bank or counterparty starts asking.

Correspondent and account reviews increasingly request AML documentation, and a recent independent review is a strong answer.

Who Needs an AML/CFT Health Check in the UAE?

Banks and financial institutions.

Any of the fourteen listed financial activities, supervised by the CBUAE, with capital market companies under the CMA.

[Cabinet Resolution No. 134 of 2025, Article 2]

DNFBPs.

Real estate brokers and agents, dealers in precious metals and stones, lawyers and notaries, independent accountants, company and trust service providers, and commercial gaming operators.

[Cabinet Resolution No. 134 of 2025, Article 3]

VASPs.

Virtual asset service providers, supervised by VARA in Dubai, DFSA in DIFC, FSRA in ADGM, or the relevant federal authority elsewhere.

[Cabinet Resolution No. 134 of 2025, Article 4]

Free zone entities in the DIFC and ADGM are reviewed against the DFSA AML Module or FSRA AML Rulebook alongside the federal framework, and DIFC firms should time the health check to support the annual AML return. Small firms are not exempt from the independent test; a proportionate review for a single-officer DNFBP is simply shorter than a bank’s.

Penalties an AML Health Check Helps You Avoid

Administrative penalties.

AED 10,000 to AED 5,000,000 per violation, plus warnings, licence suspension or cancellation, restrictions on responsible individuals, and public naming. Note per violation: a single systemic weakness often produces several.

[Federal Decree-Law No. 10 of 2025, Article 17]

The DNFBP penalty schedule.

41 listed violations at AED 50,000 to AED 1,000,000 for MoET and MoJ supervised businesses, doubling where the same violation recurs within one year. The doubling provision is why an unremediated finding is more dangerous than the original one.

[Cabinet Resolution No. 71 of 2024]

The consequential cost.

Remediation under a supervisory deadline costs several times what the same work costs on your own timetable, and it happens while the business is also answering the supervisor.

Who Provides Comprehensive Financial Health Checks in the UAE?

For AML and financial crime compliance specifically: specialist AML consultancies, the risk advisory arms of audit firms, and internal audit functions where a business has one with the relevant expertise. Broader financial health checks covering solvency, tax, or general regulatory matters sit with audit and advisory firms, and they are a different exercise from an AML/CFT review.

Three questions separate providers, and they are worth asking whoever you approach:

  1. Will you test files, or only read documents?Document review alone finds a fraction of what an inspection finds, because inspections look at files.
  2. Will each finding carry its legal citation?Findings without a provision behind them are opinions, and they are hard to defend internally when budget is needed.
  3. Are you independent of the work being reviewed?Where the reviewer or its wider organisation has designed, implemented or operated the controls being tested, the entity should assess whether organisational separation, reporting lines and conflict safeguards are sufficient to preserve independence. In some circumstances, appointing an unrelated reviewer may provide the more defensible assurance arrangement.

AML Health Check by Sector in the UAE

Real estate brokers and agents.

Third-party payments, cash exposure, beneficial ownership on layered buyers, and whether REAR reporting reaches every branch rather than stopping at head office.

Dealers in precious metals and stones.

The AED 55,000 cash threshold in practice, split payments, rapid buy and sell patterns, and DPMSR reporting.

Trust and company service providers.

Beneficial ownership through nominee and trustee arrangements, purpose and rationale evidence, and monitoring for ownership changes.

Lawyers, notaries, and accountants.

Whether DNFBP scope is correctly identified matter by matter, engagement acceptance as a control, and whether escalation survives partner pressure.

Banks, exchange houses, and payment providers.

Monitoring effectiveness, alert backlogs, PEP handling at scale, correspondent exposure, and STR quality.

VASPs

Travel Rule compliance, screening latency against transaction speed, chain analytics use, and the AED 3,500 occasional transaction threshold.

Commercial gaming operators.

Player due diligence, rapid fund movement, and behavioural indicators under GCGRA expectations.

AML Health Check Methodology

Every control is graded on three questions, asked in order: is it designed to work, is it in place, and is it working over time. A control can pass one and fail the next. Separating them turns a health check from an opinion into evidence, which is what an independent auditor under [Cabinet Resolution No. 134 of 2025, Article 21] expects to see in the file.

Step 1

Design adequacy.

We read the control as written and ask whether, followed exactly, it would meet the obligation. Does the CDD procedure cover every trigger, does the EDD standard bite where your EWRA puts risk highest, does escalation give the compliance officer a route independent of the business line. Design gaps are cheapest to fix and costliest to leave.

Step 2

Implementation.

A procedure nobody has been told about was never implemented. We test whether the control reached the systems, forms, and workflows where the work happens: is the screening rule live in the tool, do onboarding staff have the risk-scoring template, is the board-approved version the version in use. Walkthroughs and system inspection carry this step, not interviews.

Step 3

Operating effectiveness.

The step most reviews skip. We sample real files, alerts, and reporting decisions across a defined period. Screening that runs but generates alerts nobody clears, monitoring rules untuned since go-live, STR decisions with no reasoning on file: all pass steps one and two and fail here. Every exception is traced to a root cause.

A control earns a clean rating only when it clears all three. Findings are reported against the step that failed, because the remedy differs: redrafting, deployment and training, or supervision and tuning. That is why your remediation plan is sequenced rather than alphabetical.

What Do We Need to Conduct AML Health Check?

To run the health check, we need your licence and regulatory details, your EWRA, and your AML/CFT policies and procedures, together with the compliance officer’s appointment and reporting records. On the evidence side, we ask for a sample of CDD and EDD files, screening and monitoring output, internal escalation and STR decision logs, and training records. We also review board or senior-management approvals and any findings from a previous inspection or audit, so the review tests against what you have already been told rather than starting from scratch.

Why AML UAE for Your AML/CFT Health Check

Reviewing programmes requires having built them, and building them requires having seen how they fail:

300+

AML compliance projects across FIs, DNFBPs, and VASPs, which is where our finding patterns and sector benchmarks come from

1000+

EWRA and AML/CFT/CPF policy sets delivered, so we know what a good framework looks like from the inside

750+

professionals trained across 3,000+ hours, which is why our control walkthroughs get straight answers from front-line staff

Under 4 hours

typical turnaround on AML/CFT/CPF compliance queries during an engagement, because remediation questions do not keep office hours

Our team combines CAMS certified compliance practitioners with CISA and DISA qualified information systems auditors. That matters on this service more than any other, because testing a screening engine, an audit trail, and a monitoring rule set is systems audit work, not policy review.

The Reviewers Who Run Your Health Check

Pathik Shah

CAMS, FCA, CS, CISA, DISA (ICAI), FAFP (ICAI)

Experience

28+ years

Regulatory Coverage

MoET, MoJ, CBUAE, CMA, FSRA, DFSA, VARA · AML/CFT framework design, RegTech

Jyoti Maheshwari

CAMS, ACA

Experience

11+ years

Regulatory Coverage

MoET, MoJ, CBUAE, CMA, FSRA, DFSA, VARA · AML/CFT/CPF framework, health checks

Dipali Vora

CAMS, ACS

Experience

10+ years

Regulatory Coverage

MoET, MoJ, CBUAE, CMA, FSRA, DFSA, VARA · Consulting, training, implementation

Monika Shah

CAMS

Experience

3+ years

Regulatory Coverage

MoET, MoJ, CBUAE, CMA, FSRA, DFSA, VARA · managed KYC, consulting, goAML reporting

AML Health Check Examples From Our Engagements

An audit firm testing its own control effectiveness

The firm had policies, an appointed officer, and training records, and had never had any of it independently tested. The review found the framework sound in design and inconsistently applied in practice: client risk ratings assigned at onboarding and never revisited, and engagement acceptance treated as a commercial step rather than a control. Neither would have been visible from documents alone.

A DNFBP whose screening had quietly stopped

Screening appeared to be running and alerts had simply become rare, which management had read as a clean customer book. A data feed had lapsed months earlier without any notification. The finding was not the lapse itself but the absence of any control that would have detected it, which is why the remediation was a monitoring routine rather than a new tool.

A firm one week from an inspection

Not enough time to fix everything, so we did not pretend otherwise. We ran a focused review, identified what could be genuinely closed in a week, and prepared honest, evidenced explanations for what could not, with a dated remediation plan attached. Supervisors respond very differently to a firm that knows its own gaps and has a plan than to one that discovers them in the room.

FAQs on AML/CFT Health Checks in the UAE

An AML health check is an independent review that tests whether your AML/CFT compliance programme works in practice, covering your risk assessment, policies, customer due diligence files, screening, monitoring, reporting, training, and records. It produces findings with legal citations and a prioritised remediation plan, and it is how most UAE firms satisfy the independent audit expectation under Article 21 of Cabinet Resolution No. 134 of 2025.

In substance they overlap heavily. An independent AML audit is the formal exercise the law expects; a health check is the same testing, often framed as a diagnostic and sometimes narrower in scope or lighter in reporting. What determines whether your obligation is met is not the label but whether the review was independent of the work being reviewed, tested controls rather than only reading documents, and left evidence behind.

An independent audit function to test the AML/CFT programme is required [Cabinet Resolution No. 134 of 2025, Article 21], alongside the broader duty to monitor implementation and assess the effectiveness of your controls [Article 5(2)]. Many firms are unaware they owe it. Independence can come from internal audit, a group function, or an external reviewer, but not from the compliance officer auditing their own programme.

An AML gap analysis compares what your business does against what the law, your supervisor, and your own documented framework require, recording each difference as a finding with a fix. It is the core output of a health check rather than a separate service. We benchmark against four reference points: the federal law, your supervisor’s guidance, your own policies, and, where it applies to you, the 41 listed violations in Cabinet Resolution No. 71 of 2024.

A risk assessment measures how much ML, TF, and PF risk your business carries. A gap analysis measures how well your programme complies with the law. One is about exposure, the other about compliance, and they answer to different provisions: Article 5(1) for the risk assessment and Articles 5(2) and 21 for the testing. A health check also examines whether your risk assessment itself is current and defensible.

Annually as the default independent test, and sooner on any of these triggers: a change in the law, an expected inspection, an inspection finding, a material business change such as a new product, market, or licence, or a bank or counterparty starting to ask for AML documentation. The realignment to the 2025 framework is a current reason many firms are running one now.

They can and should run internal monitoring, and they cannot provide the independent test. The officer designed the controls and made the judgement calls, so reviewing their own work does not satisfy independence in any form a supervisor accepts. Independence comes from internal audit, a group function, or an external reviewer.

Start with four questions that predict most findings. Does your framework cite Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025 rather than the repealed 2018 law? Is your risk assessment dated within the last twelve months and does it reference the National Risk Assessment? Pull five customer files at random: does each contain what your own procedure requires? Ask for a specific record from three years ago and time how long it takes to produce. Any of those failing means a fuller review is worth running. Our AML compliance self-assessment tool for DNFBPs and our AML checklists give you a structured way to run that first pass in-house.

Typically two to four weeks for a mid-sized entity from scoping to report, and around a week for a focused pre-inspection review. Document review and file testing take time; the report follows quickly once testing is complete. The main variable is how fast you can provide file access and make staff available for control walkthroughs.

Yes, and with one boundary we apply consistently. We can support remediation, drafting, training, and framework rebuilds after a health check. Where we perform the fixes, a subsequent re-test should be run by someone who was not involved in them, and we will say so rather than certify our own work.

Yes, and the framing differs. DIFC firms are Relevant Persons under the DFSA AML Module, which applies the MLRO regime and an annual AML return, so the health check is usually timed to support that return. ADGM entities are reviewed against the FSRA AML Rulebook, with DNFBPs supervised by the ADGM Registration Authority. Both sit on top of the federal framework, and a group applying one standard across mainland and free zone entities usually has findings in at least one of them.

No, and be cautious of anyone who says they do. No UAE authority certifies a business as AML compliant, and no consultancy can issue a certificate that carries regulatory weight. What a health check gives you is evidence: a dated independent review, tested findings, and a documented remediation trail, which is what a supervisor, a bank, or an auditor actually asks to see. Individual professional credentials such as CAMS are a separate matter and are awarded to people, not to companies.

Run the inspection on yourself first.

One short form, one focused conversation, and a scoped health check. A CAMS-certified specialist will come back with timeline and price.

Our latest blogs