AML Business Risk Assessment
An AML business risk assessment is the documented study of the money laundering, terrorism financing, and proliferation financing risks your business carries, scored across your customers, products, geographies, and delivery channels, and set against the controls you rely on. UAE law requires every financial institution, DNFBP, and VASP to identify, assess, understand, and document those risks and keep the assessment current [Cabinet Resolution No. 134 of 2025, Article 5(1)]. We build it, score it, and hand you the methodology so your team can maintain it.
A note on the name before anything else, because it causes real confusion. Business risk assessment has two meanings. In general management, it means assessing strategic, operational, and financial risk, which this page is not about. In UAE AML practice, it is the statutory enterprise-wide assessment of financial crime risk, the same document your supervisor may call a business-wide, firm-wide, or enterprise-wide risk assessment, practice-wide, company-wide, institution-wide, or simply the EWRA, or ML/FT/PF risk assessment, or internal risk assessment (IRA).
Scored on your data, not a template.
Get an AML business risk assessment built from your own customer, product, and transaction profile, with the methodology handed over.
What Is a Business Risk Assessment Under UAE AML Law?
It is the analytical foundation of your entire AML programme, and every control you operate flows from it. Your policies must be proportionate to the risks it identifies [Cabinet Resolution No. 134 of 2025, Article 5(2)(b)]. EWRA helps you determine the risks and controls you need to consider when performing customer risk assessments. Simplified due diligence is defensible only where it supports that [Article 5(3)]. Enhanced due diligence triggers come from the risks it names [Article 5(2)(c)]. Your customer rating model, monitoring thresholds, screening configuration, and training content all inherit from enterprise-wide ML/FT/PF risk assessment.
The assessment answers three questions in sequence, and skipping any of them is the most common structural failure we see. What risk does this business face before any controls are applied, which is inherent risk. Control effectiveness is how well the controls we operate reduce it. What is left, which is residual risk, is the risk the business is willing to carry.
The EWRA must be documented. An enterprise-wide risk assessment that lives in the compliance officer’s head, however sophisticated, does not satisfy Article 5(1), and it cannot be tested by the independent audit function required under Article 21.
Business Risk Assessment vs Customer Risk Assessment
Two different exercises that get conflated constantly. The business risk assessment covers the risk your whole firm carries and drives your policies and controls. A customer risk assessment rates an individual customer at onboarding and during periodic reviews, and it operates within those controls. You need both, and the customer risk methodology is one of the outputs the business assessment justifies. If your customer rating model cannot be traced back to a finding in your business assessment, an inspector will ask where the ratings came from.
What Is EWRA? Enterprise-Wide Risk Assessment Explained
EWRA stands for enterprise-wide risk assessment. In AML, it means the same document as the business risk assessment: a single assessment covering the whole entity rather than one business line, product, or branch. The term comes from international practice and has become common in UAE compliance conversations, particularly in the financial free zones and among firms with group reporting lines.
Enterprise-wide is the important half of the phrase. An assessment covering only your largest business line, or only the customers your compliance team happens to see, is not enterprise-wide, and the gaps it leaves tend to sit exactly where risk concentrates: a small side business, an introducer channel, a legacy customer book nobody has reviewed. We scope the assessment to the whole legal entity and, where relevant, to the group structure around it.
Firm-Wide AML Risk Assessment: The Same Document, Four Names
Business risk assessment, business-wide risk assessment, firm-wide risk assessment, and enterprise-wide risk assessment all describe the same obligation. The variation comes from which rulebook or which group a firm grew up with, not from any difference in what the law requires. Article 5(1) of Cabinet Resolution No. 134 of 2025 sets one requirement, and the DFSA AML Module uses the term business risk assessment for DIFC Relevant Persons, which is why firms operating across the mainland and the financial free zones often hold documents with two different titles and identical purposes.
Practical consequence: if a bank, an auditor, or a supervisor asks for your firm-wide risk assessment and you hand over something called an EWRA, you have answered the question. What matters is scope and method, not the label on the cover page. Version control matters, because a group that maintains a firm-wide assessment centrally and a local one separately usually ends up with two documents that disagree, and the disagreement is the finding.
Is a Business Risk Assessment Mandatory in the UAE?
Yes, for every entity in scope, and it is not a light obligation. Article 5(1) of Cabinet Resolution No. 134 of 2025 requires identifying, assessing, understanding, and documenting risks; considering the results of the National Risk Assessment; retaining the study; and keeping the assessment updated. It sits inside the risk-based approach mandated by Article 19 of Federal Decree-Law No. 10 of 2025, and its absence is punishable in itself, with no money laundering required.
It is also the first document requested during a supervisory visit. When an inspection or review begins, examiners usually request three things before anything else: your AML policy and procedures, your risk assessment, and your compliance officer’s appointment. Two of those three depend on this one, which is why a weak assessment rarely produces a single finding. It can produce findings across CDD, monitoring, training, and reporting at the same time, because they all depend on it.
Not sure whether your current assessment would hold up?
Send us your latest version and we will tell you where the methodology would be challenged, with no obligation.
UAE AML Laws Behind Your Business Risk Assessment
Every assessment we prepare is mapped to the provisions that create the duty and shape its content:
| Legal Instrument | What It Requires | What It Means for Your Business Risk Assessment |
|---|---|---|
| Federal Decree-Law No. 10 of 2025 | The primary AML/CFT/CPF statute, in force 14 October 2025, repealing FDL No. 20 of 2018 (Article 41). Preventive measures on a risk-based approach (Article 19), STR duties (Article 18), supervisory powers (Article 16), and administrative penalties of AED 10,000 to AED 5,000,000 per violation (Article 17). Proliferation financing becomes a standalone offence. | The risk-based approach starts here, and PF must be assessed alongside ML and TF. Assessments written before October 2025 almost never cover proliferation financing, which makes legacy alignment the first thing we check. |
| Cabinet Resolution No. 134 of 2025, Article 5(1) | Identify, assess, understand, and document ML/TF/PF risks, take the National Risk Assessment results into account, retain the study, and keep it updated on an ongoing basis. | Your scope and your standard of proof in one article. Every rating in the assessment should be traceable to it, including the NRA integration that assessments most often omit. |
| Cabinet Resolution No. 134 of 2025, Articles 5(2) and 5(3) | Senior-management-approved policies, controls, and procedures proportionate to the nature and size of the business, with implementation monitored and effectiveness assessed; aligned with National Risk Assessment and Sectoral Risk Assessment, EDD for high-risk situations; simplified due diligence only where risk allows. | Why the assessment cannot be cosmetic. Proportionate means proportionate to something measured, and simplified due diligence applied without an assessment behind it is indefensible. |
| Cabinet Resolution No. 134 of 2025, Articles 6 to 10 and 16 | CDD and verification, thresholds including AED 55,000 for occasional transaction and AED 3,500 for wire transfer for Financial Institutions, ongoing monitoring, beneficial ownership to the 25% standard with the fallback cascade, and PEP identification. | The specific exposures the assessment has to score: customer type, ownership opacity, transaction size against your thresholds, and PEP presence in your book. |
| Cabinet Resolution No. 134 of 2025, Articles 20, 21, 22, 23 and 25 | Third-party reliance conditions, training and an independent audit function, the compliance officer at management level, countermeasures for high-risk countries, and record keeping with prompt retrieval. | Delivery channel risk where you rely on introducers, geographic risk where high-risk countries are involved, and the requirement that the assessment be retained, testable, and owned by a named officer. |
| Cabinet Decision No. 74 of 2020 | Targeted financial sanctions: screening against UN and UAE Local Terrorist Lists, freezing without delay, and reporting to the Executive Office for Control and Non-Proliferation. | Sanctions exposure is a risk factor in its own right, and the effectiveness of your screening control is among the harder ratings to justify honestly. |
| Cabinet Resolution No. 109 of 2023 | Real Beneficiary Procedures: the beneficial ownership register, the 25% threshold, and update deadlines. | Ownership opacity is scored against this standard, which matters most for corporate service providers and layered structures. |
| Cabinet Resolution No. 71 of 2024 | The administrative penalty schedule for DNFBPs supervised by the MoET and MoJ: 41 listed violations with fines of AED 50,000 to AED 1,000,000, doubling where the same violation recurs within one year. | Quantifies the cost of a missing or inadequate assessment, and useful to read alongside the gap list your assessment produces. |
| Sectoral guidance and free zone rulebooks | MoET Guidelines for DNFBPs (September 2025), CBUAE, CMA, MoJ, GCGRA and VARA expectations, the DFSA AML Module, which requires a documented business risk assessment for DIFC Relevant Persons, and the FSRA AML Rulebook in the ADGM. Plus the National and Sectoral Risk Assessments. | Determines the terminology, the scope, and the supervisory emphasis that applies to you. Free zone entities carry the federal obligation and the rulebook obligation together, not one instead of the other. |
The gap we find most often: no traceable link between the National Risk Assessment and the firm’s own ratings. The NRA gets a paragraph of acknowledgement and then never changes a score. Article 5(1) requires its results to be taken into account, and taken into account means visible consequences somewhere in the document.
AML Risk Assessment Methodology: How We Build Yours
The methodology is the part supervisors actually read, and it is the part most assessments cannot survive. A rating without a documented basis is an opinion, and an opinion cannot be re-run, tested, or defended by anyone other than the person who formed it.
A defensible methodology answers six questions in writing before a single score is assigned:
1. What are we scoring?
The risk factors and the sub-factors under each, chosen for your business rather than lifted from a generic model.
2. On what scale?
The rating bands and what each one means in concrete terms, so that medium means the same thing on page two and page forty.
3. With what weightings?
Which factors carry more influence, and why, since equal weighting across all factors is itself an assertion about your business that usually isn’t true.
4. From what data?
Provide the source for each input so an auditor can trace a score back to a customer file, a transaction report, or a documented judgement.
5. How is control effectiveness rated?
The criteria distinguishing an effective control from a documented one, and the evidence required to claim the former.
6. How is residual risk derived?
The arithmetic or logic connecting inherent risk and control effectiveness, stated explicitly rather than left implied.
We document all six, hand over the working model, and structure the engagement so your compliance officer can model the assessment next year without us. Firms that intend to keep this in-house should say so at the outset, because it changes how we build the build.
AML Risk Scoring: Inherent Risk, Controls, Residual Risk
Scoring is where ML/FT assessments quietly become useless. Two failure patterns account for most of what we see. The first is compression: every factor lands on medium, which tells the reader nothing and usually means the scale was never defined. The second is generosity: controls are rated effective because they exist in a policy, which produces a residual risk figure that cannot be defended the moment anyone tests a file.
On the quantitative assessment of ML/TF/PF risks, since it comes up in most kick-off meetings: numbers are useful, and they are not the point. A weighted numeric model brings consistency and makes year-on-year comparison possible, which matters. It also creates a temptation to treat the output as objective when every weighting inside it was a judgement. We build numeric models where the data supports them, and we document the reasoning behind each weighting so the score remains explainable. A score you cannot explain is worse than a qualitative rating you can.
Risk appetite belongs in this section too, and it is frequently missing. Residual risk tells you what is left. Appetite tells you whether that is acceptable, and it is a decision for senior management, stated explicitly, not inferred from whatever the business is currently doing.
The Five AML Risk Factors: Customer, Product/Service/Transaction, Geography, Delivery Channel, Technology
These five are the standard basis of a risk-based assessment:
Risk Factor
What Gets Assessed
Customer risk
Customer types and segments, ownership opacity and layered structures, PEP exposure, cash-intensive businesses, non-resident and non-face-to-face customers, and concentration in a single relationship
Product/service/transaction risk
Which offerings can move or store value, transaction sizes relative to the AED 55,000 and AED 3,500 thresholds wherever applicable, third-party payment exposure, and anonymity or speed features
Geographic risk
Customer, counterparty, and transaction jurisdictions against high-risk country lists, sanctions exposure, and the countermeasures required under Article 23
Delivery channel risk
Face-to-face against remote or digital onboarding, use of intermediaries, agents, and introducers, and reliance on third-party due diligence under Article 20. This is the factor most often scored too generously, because the firm never sees the customer the introducer met
Technology risk
Risks arising from emerging technologies like artificial intelligence, machine learning, and introduction of new products which use blockchain and other cutting-edge technologies.
How to Do an AML Risk Assessment, Step by Step
If you are preparing your own Business Risk Assessment (BRA), follow this sequence to produce a defensible document. It is also, in outline, what we do:
1. Define the scope.
Which legal entity, which business lines, which branches, and whether group exposures are in or out. Keep it in writing so you can prove you not only implemented it but also have evidence.
2. Gather the data.
Customer, product, geography, channel, and transaction data, plus your existing policies, registers, and any inspection findings, findings of NRA and SRA, supervisory guidance, if any.
3. Design the methodology.
Define risk categories, risk factors, sub-factors, scales, and weightings. Document the rationale behind your assumptions and describe your methodology in full.
4. Score inherent risk.
Score factor by factor, recording the reasoning next to each rating rather than in a separate note.
5. Test control effectiveness.
Interviews plus sample testing. A control described in a policy and a control operating on a Tuesday are different findings, and only testing distinguishes them.
6. Derive residual risk and set appetite.
Residual position calculated, appetite decided by senior management explicitly.
7. Integrate the NRA and SRA.
Map national and sectoral findings to your exposure, and record the resulting changes. [Cabinet Resolution No. 134 of 2025, Article 5(1)]
8. Produce the gap list and action plan.
Include findings with owners and deadlines, as evidence that you acted on your analysis.
9. Obtain senior management approval.
Dated, named, and minuted, then diarise the review cycle and the trigger events. [Cabinet Resolution No. 134 of 2025, Article 5(2)(a)]
Who Performs an AML Risk Assessment?
Accountability sits with the entity and, specifically, with senior management who approve the framework and the compliance officer who owns it [Cabinet Resolution No. 134 of 2025, Articles 5(2)(a) and 22]. Who does the work is a separate question with three common answers.
The compliance officer, internally.
Workable where the officer has a methodology, the data access, and the time. The usual constraint is not competence but independence of judgement: rating your own controls is uncomfortable, and most people rate them kindly.
An external specialist.
Common for a first assessment, for firms without a methodology, or where an independent challenge to internal control ratings is wanted. The risk to watch is dependency, which is why the methodology handover matters.
A hybrid, which is what most of our clients run.
We build the first assessment and the model, then support the annual refresh while the compliance officer owns and signs it.
One thing worth knowing : whoever performs the assessment, the independent audit function required under Article 21 should not be the same person or team. If your compliance officer prepares the assessment and also tests it, the testing is not independent in any sense a supervisor accepts.
Business Risk Assessment Services: What You Receive
Deliverable
What it does
AML business risk assessment report
The full documented assessment: scope, inherent risk, control effectiveness, residual risk, appetite, and conclusions
Documented methodology
Factors, scales, weightings, and the basis for each, so the assessment is reproducible by you, your auditor, and your supervisor
Working risk model
The scoring model itself, handed over so next year’s refresh does not start from a blank page
Control effectiveness working papers
The evidence behind each rating, which is exactly what an independent audit under Article 21 will ask to see
NRA and SRA integration record
National and sectoral findings mapped to your business, with the resulting changes to ratings and controls recorded
Gap list and action plan
Findings with owners, deadlines, and a tracker your compliance officer can run
Senior management approval pack
Board or owner-level summary and the sign-off documentation supervisors expect
EWRA data collection and reconciliation
EWRA data collection and reconciliation
An enterprise-wide risk assessment needs reliable information about the business it measures. AML UAE helps you collect and reconcile the customer, transaction, product, country and delivery-channel data used in your EWRA, so the assessment has a clear and traceable basis.
Resolve gaps before scoring risk
We define the assessment period and population, agree how each data field will be used and compare extracts from your CRM, onboarding records, accounting system and transaction platform. We investigate duplicate customers, inconsistent country labels, missing risk ratings and differences between reported totals. Unavailable data is recorded as a limitation rather than silently treated as zero.
Your assessment dataset
You receive a reconciled dataset, data dictionary and exception log showing the source, owner and treatment of material differences. We also document any justified estimates and the effect they may have on the assessment.
Your team provides the agreed extracts and confirms their completeness. We establish a repeatable collection process so future risk assessments can be updated without rebuilding the dataset from the beginning.
EWRA methodology recalibration
Recalibrate your EWRA methodology
A scoring model should explain why your business carries a particular level of money laundering, terrorist financing or proliferation financing risk. We review the factors, scales, weightings and control assessments behind your EWRA when ratings appear inconsistent or no longer reflect the business.
Test the logic behind the result
We examine whether material exposures can be diluted by averaging, whether control scores rely on evidence and how missing information affects the outcome. Sensitivity testing shows which assumptions materially change the final rating. A low residual score should be supported by working controls.
The revised methodology
You receive revised scoring guidance, the rationale for material changes and worked examples using your business data. We explain the effect on the previous assessment and identify decisions requiring management approval. Provide your current model, calculations and supporting control evidence so the review can test how the methodology operates in practice.
NRA and SRA mapping to EWRA
Connect national and sectoral risks to your EWRA
National and sectoral risk assessments help a business understand the threats relevant to its activities. We translate applicable UAE NRA and SRA findings into specific EWRA factors, supporting analysis and control actions.
Make the connection visible
We identify relevant findings, record the source and publication date, and assess how each issue could arise through your customers, products, countries or delivery channels. A sector rating provides context; your own exposure and control evidence determine the conclusions for your business.
What changes in your assessment
You receive a source-to-risk mapping schedule and proposed updates to the assessment narrative, scoring rationale and mitigation plan. We identify findings that do not apply and explain why. Your current EWRA, service profile and customer data help us distinguish meaningful exposure from a generic list of national risks.
Separate ML, TF and PF risk analysis
Assess money laundering terrorist financing and proliferation financing risks separately
Different financial crime risks can arise through the same customer or transaction. We help your EWRA explain money laundering, terrorist financing and proliferation financing exposure separately, while keeping the assessment usable as one business document.
Use scenarios relevant to your activities
The review considers how criminal proceeds could enter the business, how legitimate or illicit funds could support terrorism and how products, counterparties or payment routes could support proliferation-related sanctions evasion. We assess each scenario against the information and controls available.
A clearer risk rationale
You receive distinct risk narratives, relevant indicators and control mappings, with a consolidated action plan. We record uncertainty where data is limited and identify where one control addresses several risks. The service uses your business model, customer profile and existing EWRA to avoid treating all three risks as interchangeable.
New-product and technology ML/TF/PF risk assessment
- Assess AML risk before launching a product or technology
A new product, delivery channel or technology can change how customers enter your business and how money moves through it. We help you assess the AML implications before implementation, including changes to existing services.
- Review the proposed customer journey
We examine eligibility, onboarding, payment flows, intermediaries, geographical reach and system dependencies. The assessment identifies where existing CDD, screening and monitoring controls need to change and where testing is required before launch.
- A documented launch decision
You receive a risk assessment, proposed controls and a list of unresolved conditions for management to consider. We distinguish control design from evidence that the control works. Provide the product specification, process maps and planned launch date so risk review and testing can be built into the delivery schedule.
Exchange-house remittance corridor assessment
Assess AML risk across remittance corridors
Remittance corridor risk reflects who sends money, who receives it and how funds move between them. We help exchange houses assess corridor exposure using their own customer and transaction data.
Look beyond a country label
The review considers purpose, payment methods, counterparties, delivery arrangements and patterns such as unusual velocity or repeated beneficiaries. We connect relevant country measures and risk information to the actual corridor without treating every customer from a country as carrying identical risk.
Translate findings into controls
You receive a corridor assessment, data limitations and recommended due diligence or monitoring changes. Provide corridor volumes, customer profiles and payout arrangements so conclusions can be supported by the business’s activity.
Insurance AML scope and product-risk assessment
Assess insurance AML scope and product risk
Insurance products and distribution arrangements create different financial crime exposures. We help insurers and intermediaries identify the relevant AML scope and assess the risks associated with the products they offer.
Assess features that move value
The review considers investment or savings features, premium patterns, early surrender, assignment and payments to beneficiaries. We distinguish the roles of insurer, intermediary and other parties, and assess the information each can obtain.
A product-based assessment
You receive a scope and risk map with recommended controls and escalation triggers. We use the relevant CBUAE framework and product documents, rather than assuming every insurance line or distribution role has the same obligations.
Virtual-asset exposure review for banks
Assess a bank's exposure to virtual asset activity
A bank can encounter virtual asset exposure through customers, counterparties and payment activity without providing a virtual asset service itself. We help identify those connections and assess their implications for the bank’s AML framework.
Understand the exposure
The review considers customer business models, relevant VASP permissions, transaction routes and available information on funding and counterparties. We examine the limits of bank data and identify when further due diligence or monitoring is needed.
A documented response
You receive an exposure assessment, proposed controls and escalation criteria. We distinguish the bank’s obligations from those of the VASP and avoid assuming that a customer’s licence resolves all underlying risk. Share the relevant customer segments and payment data to define the review.
ADGM RA thematic-review BRA remediation
Address business risk assessment findings from ADGM RA reviews
A response to a business risk assessment finding should correct the underlying weakness and show what changed. We help ADGM DNFBPs address RA findings relevant to their own assessment and operations.
Link the finding to the correction
We review the regulator’s observations, methodology, data and risk narratives. The work can address weak links to business activity, insufficient separation of ML, TF and PF exposure, or unsupported control assessments where these are identified.
Evidence the improvement
You receive an updated assessment, a finding-to-action map and supporting approval records. We distinguish the firm’s specific findings from wider thematic observations. Provide the review correspondence and current BRA so the work addresses the actual issue rather than adding generic wording.
FSRA new-business AML risk assessment
Assess AML risk before expanding an FSRA business
A new service, customer segment or jurisdiction can change an FSRA firm’s risk exposure and control needs. We support a documented AML assessment before the change is implemented.
Examine the proposed change
The review follows customer and transaction flows, identifies new parties and data dependencies, and tests whether existing due diligence, screening and monitoring remain suitable. We separate AML control readiness from any additional regulatory permission required.
A decision record for management
You receive a risk assessment, proposed mitigations and unresolved launch conditions with owners. Provide the business proposal and implementation plan so assessment and testing can be incorporated before the change takes effect.
VASP activity-specific EWRA
Build a VASP EWRA around the activities you perform
Virtual asset risks vary between exchange, brokerage, transfer, custody and other permitted activities. We help VASPs assess their own exposure using the services, customers and transaction routes they actually support.
Analyse the operating model
The assessment considers assets, networks, wallet interactions, counterparties and the availability of customer and transaction information. We examine relevant cross-border exposure and dependencies on analytics, custody or other providers. Each activity is assessed within its applicable supervisory framework.
A business-specific risk assessment
You receive distinct risk scenarios, control assessments and prioritised actions supported by available data. Limitations in attribution or system coverage are recorded explicitly. Share the licence, product catalogue and transaction profile to define the assessment.
Token and product AML launch review
Assess AML risk before listing a token or launching a virtual asset product
A token or product launch can introduce risks that the existing VASP framework does not address. We assess the proposed asset, service and customer journey before the business makes its launch decision.
Review the asset and its use
The assessment considers transferability, relevant privacy features, control arrangements, counterparties and available monitoring information. We examine whether the product creates gaps in customer understanding, sanctions controls or transaction analysis.
Document conditions for launch
You receive a risk assessment, proposed restrictions or controls and a list of issues requiring resolution. AML assessment is one part of the launch process and does not replace separate legal, technical or regulatory approval work. Provide the product specification, network details and proposed operating arrangements.
Country-risk list and countermeasure update
Keep country risk lists and countermeasures current
Country risk information changes, but different lists have different purposes. We help maintain a documented process for reviewing updates and translating them into customer, transaction and control actions.
Distinguish the source and its effect
The review separates UAE requirements, FATF statements, sanctions designations and the firm’s own geographical risk methodology. We identify affected customers or corridors and assess whether enhanced measures, reporting changes or other specific actions are required.
Track the update through the business
You receive a source register, change log and implementation actions for relevant systems and procedures. Each change records its effective date and approval. A FATF listing is not automatically treated as a comprehensive sanctions prohibition or an identical HRC reporting trigger.
Proliferation-financing institutional risk assessment
- Assess institutional proliferation financing exposure Proliferation financing risk assessment examines how a business could be used to support prohibited proliferation-related activity or evade relevant sanctions. We help develop the institutional analysis using the firm's products, customers and operating footprint.
- Identify plausible exposure The assessment considers counterparties, ownership structures, trade connections, payment routes and relevant goods or services where these arise in the business. We examine control coverage and information limitations, including exposure that a simple name screen may not resolve.
- A documented risk and control assessment You receive PF-specific scenarios, supporting rationale and recommended actions within the EWRA. For firms already separating ML, TF and PF analysis, this work deepens the PF component rather than creating a duplicate assessment. Provide the existing EWRA and relevant business data to define the scope.
Want the model, not just the report?
Tell us whether you intend to maintain this in-house and we will build the handover into the engagement.
AML Risk Management: What Happens After the Assessment
An assessment measures risk. AML risk management is what you do about it, and the two are not the same deliverable. The assessment tells you where exposure sits and how well controls contain it. Risk management is the ongoing business of closing the gaps it found, adjusting controls as the business changes, and keeping the picture current between formal assessments.
In practice this means four things running continuously. Remediation of the gap list, on the deadlines it set. Control adjustment when the assessment says a control is ineffective, which is a policy and procedure change rather than a note in a file. Monitoring of the risk drivers that would change your ratings, meaning new products, new markets, new channels, and shifts in your customer mix. And re-assessment when any of those move materially, rather than waiting for the annual cycle to come round.
This is also where the business risk assessment earns its cost. A firm that treats it as an annual document files it and changes nothing. A firm that treats it as a management tool usually discovers that some controls were over-applied while others were missing, which is why clients that move to a genuine risk-based approach often reduce compliance costs rather than increase them.
Who Needs an AML Business Risk Assessment in the UAE?
Banks and financial institutions.
Any of the fourteen listed financial activities, supervised by the CBUAE, with capital market companies under the CMA.
[Cabinet Resolution No. 134 of 2025, Article 2]
DNFBPs.
Real estate brokers and agents, dealers in precious metals and stones, lawyers and notaries, independent accountants, company and trust service providers, and commercial gaming operators.
[Cabinet Resolution No. 134 of 2025, Article 3]
VASPs
Virtual asset service providers, supervised by VARA in Dubai or the relevant federal authority elsewhere.
[Cabinet Resolution No. 134 of 2025, Article 4]
DIFC Relevant Persons prepare a business risk assessment under the DFSA AML Module alongside the federal obligation, and ADGM entities under the FSRA AML Rulebook. Size does not exempt anyone. A proportionate assessment for a single-officer DNFBP is a great deal shorter than a bank’s, and proportionate is not a synonym for absent.
Penalties for a Missing Business Risk Assessment
Administrative penalties.
AED 10,000 to AED 5,000,000 per violation, plus warnings, licence suspension or cancellation, restrictions on responsible individuals, and public naming. Note per violation, because a missing assessment rarely produces one finding.
[Federal Decree-Law No. 10 of 2025, Article 17]
The DNFBP penalty schedule.
41 listed violations at AED 50,000 to AED 1,000,000 for MoET- and MoJ-supervised businesses, doubling if the same violation recurs within one year.
[Cabinet Resolution No. 71 of 2024]
The consequential exposure.
Without a defensible assessment, you cannot justify a single control decision, so one gap becomes findings across CDD, EDD, monitoring, screening, and training simultaneously.
AML Risk Assessment Tools and Software: Where They Fit
An ML/FT risk assessment tool can hold your model, do the arithmetic, keep a version history, and produce a presentable output. All of that is genuinely useful once you have a methodology. What no tool can do is choose your risk categories, risk factors, weightings, judge whether a control is effective, or take a national risk finding into account on your behalf. Those are judgements, and they are precisely what a supervisor examines.
So the sequencing matters more than the selection. Firms that license a tool before they have a methodology end up with a well-formatted assessment whose numbers nobody in the room can explain, which is a worse position than a plain spreadsheet with documented reasoning. Build the business risk assessment, then decide whether an EWRA tool is worth paying to maintain it. If you are already evaluating platforms, our AML software selection service covers requirements, vendor scoring, and contract terms.
AML Business Risk Assessment by Sector in the UAE
Real estate brokers and agents.
Non-resident buyers, third-party payments, cash exposure, and beneficial ownership through layered purchasers. Geographic and customer risk usually dominate, and delivery channel risk is understated wherever agents onboard independently.
Dealers in precious metals and stones.
Cash intensity against the AED 55,000 threshold, rapid buy and sell patterns, split payments, and supply chain provenance.
Trust and company service providers.
Ownership opacity as the dominant factor, nominee and trustee arrangements, and cross-border structures that make the 25% test genuinely difficult rather than merely administrative.
Lawyers, notaries, and accountants.
Which matters fall inside DNFBP scope, client money exposure, and engagement acceptance treated as a control rather than a commercial step.
Banks, exchange houses, and payment providers.
Corridor and volume analysis, correspondent exposure, PEP concentration, and monitoring effectiveness measured rather than assumed.
VASPs.
Transaction speed, counterparty and chain exposure, Travel Rule obligations, and the AED 3,500 occasional transaction threshold.
Commercial gaming operators.
Player due diligence, rapid fund movement, and behavioural indicators under GCGRA expectations.
Why AML UAE for Your Business Risk Assessment
Methodology improves with repetition, and this is the deliverable we have produced more than any other:
1,000+
EWRA and AML/CFT/CPF policy sets delivered to UAE reporting entities, which is where our sector benchmarks come from
300+
AML compliance projects across FIs, DNFBPs, and VASPs
45%+
cost saving achieved by clients moving to a genuine risk-based approach, because a real assessment usually shows controls over-applied in one place and missing in another
750+
professionals trained across 3,000+ hours, so the assessment is understood by the people operating the controls it justifies
Our team combines CAMS-certified compliance practitioners with CISA and DISAqualified information systems auditors, which is why control effectiveness testing here means testing rather than interviewing, and why our models are built to be audited.
The Specialists Who Build Your Assessment

Pathik Shah
CAMS, FCA, CS, CISA, DISA (ICAI), FAFP (ICAI)
Experience
28+ years
Regulatory Coverage
MoET, MoJ, CBUAE, CMA, FSRA, DFSA, VARA · AML/CFT framework design, RegTech

Jyoti Maheshwari
CAMS, ACA
Experience
11+ years
Regulatory Coverage
MoET, MoJ, CBUAE, CMA, FSRA, DFSA, VARA · AML/CFT/CPF framework, health checks

Dipali Vora
CAMS, ACS
Experience
10+ years
Regulatory Coverage
MoET, MoJ, CBUAE, CMA, FSRA, DFSA, VARA · Consulting, training, implementation

Monika Shah
CAMS
Experience
3+ years
Regulatory Coverage
MoET, MoJ, CBUAE, CMA, FSRA, DFSA, VARA · managed KYC, consulting, goAML reporting
AML Risk Assessment Examples From Our Engagements
A brokerage where every factor scored medium
The existing assessment rated all factors medium and every control adequate. Analysis of the actual customer data showed heavy concentration in non-resident buyers from two jurisdictions and a material proportion of third-party payments, neither of which appeared anywhere in the document. Raising geographic and customer risk produced a shorter, far more defensible assessment, and it changed the EDD triggers, which was the point.
A firm that discovered it was over-controlled
Enhanced due diligence was being applied to nearly every customer, which reads as caution and was in fact a finding waiting to happen: nobody could explain the basis, and applying EDD everywhere meant applying it properly nowhere. The assessment identified where risk genuinely sat, documented simplified due diligence where Article 5(3) allowed it, and reduced onboarding time without weakening a control that mattered.
A group with two assessments that disagreed
A regional group maintained a firm-wide assessment centrally and a UAE assessment locally, prepared on different methodologies in different years. They rated the same customer segment differently, which is the kind of inconsistency a supervisor finds immediately, and a compliance team never notices. We reconciled them onto one methodology with a documented local overlay, so the group view and the UAE view could differ where the risk genuinely differed, and only there.
FAQs on Business Risk Assessment in the UAE
It is the documented assessment of the money laundering, terrorism financing, and proliferation financing risks your business carries, scored across customers, products, geographies, technological, and delivery channels, and set against the effectiveness of your controls. UAE law requires it under Article 5(1) of Cabinet Resolution No. 134 of 2025. In general management, the same phrase means strategic and operational risk, which is a different exercise entirely.
Enterprise-wide risk assessment. In AML, it means the same document as a business risk assessment, business-wide risk assessment, or firm-wide risk assessment: one assessment covering the whole entity rather than a single business line, product, or branch.
Yes. Every financial institution, DNFBP, and VASP in the scope of Articles 2 to 4 of Cabinet Resolution No. 134 of 2025 must identify, assess, understand, and document its ML/TF/PF risks under Article 5(1), taking the National Risk Assessment into account and keeping the assessment updated. Failure to do so is independently punishable under Article 17 of Federal Decree-Law No. 10 of 2025.
The business risk assessment covers the risk your whole firm carries and drives your policies and controls. A customer risk assessment rates one customer at onboarding and on review, and operates within those controls. You need both, and your customer rating methodology should be traceable back to a finding in the business assessment.
Yes, and it’s the same as an enterprise-wide risk assessment (EWRA). The variation in naming comes from which rulebook or group a firm grew up with rather than any difference in the obligation. The DFSA AML Module uses business risk assessment for DIFC Relevant Persons, which is why firms operating across the mainland and the free zones often hold two documents with different titles and the same purpose.
Define the scope, gather and analyse your customer, product, geography, channel, and transaction data, design and document the methodology before scoring, score inherent risk factor by factor, test control effectiveness rather than accepting descriptions, derive residual risk and set appetite with senior management, integrate the National and Sectoral Risk Assessment findings, produce a gap list with owners and deadlines, and obtain dated senior management approval.
Accountability sits with senior management and the compliance officer [Cabinet Resolution No. 134 of 2025, Articles 5(2)(a) and 22]. The work itself can be done internally, by an external specialist, or in a hybrid arrangement where a consultant builds the first assessment and methodology, and the officer owns the annual refresh. Whoever prepares it, the independent audit function under Article 21 should be someone else.
The documented basis for your scores, which risk factors and sub-factors are assessed, on what rating scale, with what weightings and why, from what data sources, how control effectiveness is judged, and how residual risk is derived from inherent risk and control effectiveness. Supervisors read the methodology, not just the conclusion, because a rating without a documented basis cannot be tested or re-run.
Inherent risk is scored per factor before controls, control effectiveness is rated against each, and residual risk is derived from the two. Scoring can be quantitative with weighted numeric models or qualitative with defined rating bands, and both are acceptable as long as the reasoning is documented. The two most common failures are compressing everything to medium, which signals an undefined scale, and rating controls as effective because they exist on paper.
The law requires it to be kept updated on an ongoing basis rather than naming a fixed interval, and an annual cycle is the working standard in practice. Update sooner on a material change: a new product, market, delivery channel, or licence; a new National or Sectoral Risk Assessment; a change in the law; a shift in your customer mix; or an audit or inspection finding.
A template can organise the structure, and it cannot produce the assessment. Article 5(1) requires the risks of your business to be identified and understood, and Article 5(2)(b) requires the resulting controls to be proportionate to your nature and size. A downloaded template carries someone else’s risk universe and, more damagingly, someone else’s weightings, which is visible on a first read. We build from your data and hand over the model so you can maintain it.
The assessment measures risk at a point in time. AML risk management is the continuous work that follows: remediating the gaps it found, adjusting controls rated ineffective, monitoring the drivers that would change your ratings, and re-assessing when they move materially. An assessment that is filed and never acted on is a document; risk management is what makes it a control.
Yes. DIFC Relevant Persons prepare one under the DFSA AML Module, which also applies the MLRO regime and an annual AML return. ADGM entities follow the FSRA AML Rulebook, with the ADGM Registration Authority supervising DNFBPs. Both obligations sit on top of the federal framework rather than replacing it, and groups applying a single standard across mainland and free zone entities usually have gaps in at least one.
Typically two to four weeks for a mid-sized entity from data request to approved report. The analysis is rarely the constraint. The timeline depends on how quickly you can provide customer, transaction, and geography data, and how quickly stakeholders are available for control effectiveness interviews.
Build an assessment you can defend.
One short form, one focused conversation, and a clear scope. A CAMS-certified specialist will come back with timeline and price.