In-house AML Compliance Department Setup

An in-house AML compliance department is the internal function that operates your AML/CFT/CPF programme every working day. It brings together the compliance officer or MLRO, senior management oversight, reporting lines, goAML access, policies, registers, systems and operating procedures required to manage financial crime risk.

UAE law requires financial institutions, DNFBPs and VASPs to maintain proportionate AML/CFT/CPF arrangements and appoint a competent compliance officer at management level. It does not require every regulated entity to maintain a separately staffed department. Depending on the organisation’s size, activities, risk profile and supervisory framework, the compliance function may be operated by a single internal officer, a larger internal team or, where permitted, an approved third-party or hybrid arrangement.

Common inspection weaknesses include an undocumented appointment, insufficient independence, unclear reporting lines, missing supervisory approval, incomplete goAML registration and inadequate access to customer or transaction information. These failures can result in regulatory action even where no underlying money-laundering offence has been established. Article 17 of Federal Decree-Law No. 10 of 2025 permits supervisory authorities to impose measures including warnings, restrictions and administrative fines ranging from AED 10,000 to AED 5 million for each violation, depending on the circumstances and applicable supervisory framework.

We help you build an operational compliance function that is properly structured, appointed, approved where required, registered, documented and ready to operate.

A function, not a file.

Build an AML compliance function that is properly appointed, approved where required, registered, documented and operational.

What Is an In-House AML Compliance Department?

In legal terms, it is the governance layer of your AML programme, the appointed compliance officer or MLRO, the senior management oversight above them, and the operating machinery beneath them. When an inspection or review begins, three things are requested before almost anything else: your AML policy and procedures, your business risk assessment, and your compliance officer’s appointment. This service exists for the third, and for everything the third person needs to actually do the job.

A working AML department in the UAE stands on four legs.

The appointment:

A named, qualified individual at management level, independent in decision-making, approved by your supervisor where the law requires it.

The authority:

Documented reporting lines that let the officer escalate to senior management and block or file without being overridden.

The access:

goAML registration, screening tools, and the customer and transaction data the role needs.

The evidence:

Registers, decision logs, training records, and periodic reports to senior management that prove the function operates.

An informal allocation of responsibility is not sufficient. The appointment should be formally documented and supported by a role description, defined reporting lines, evidence of competence, appropriate authority, access to information and safeguards against conflicts of interest or commercial interference.

The approval process depends on the applicable supervisory framework. MoET-supervised DNFBPs must obtain the relevant Supervisory Authority’s prior written approval. Where a suitably qualified and independent person cannot be appointed internally, the March 2026 MoET Guidelines provide that a third-party compliance officer may be permitted, subject to supervisory approval, fitness and propriety, independence, unrestricted access, contractual safeguards and continuing accountability by senior management.

Is an AML Compliance Officer Mandatory in the UAE?

Yes. Article 22 of Cabinet Resolution No. 134 of 2025 requires financial institutions, DNFBPs and VASPs within its scope to appoint a compliance officer at management level. The officer must possess appropriate competence and experience, exercise independent judgement and perform the responsibilities assigned under the Executive Regulations.

Appointment formalities are also governed by the relevant supervisory framework. Article 49 of Cabinet Resolution No. 134 of 2025 empowers supervisory authorities to maintain records of compliance officers and require regulated entities to obtain approval before appointment. MoET’s March 2026 Guidelines specifically require prior written supervisory approval for the compliance officer of a MoET-supervised DNFBP.

The officer’s responsibilities include reviewing internal reports and relevant records, deciding whether a matter should be reported to the UAE Financial Intelligence Unit, maintaining the confidentiality of reporting decisions, overseeing the AML/CFT/CPF framework and reporting periodically to senior management.

Senior management remains responsible for approving and overseeing the entity’s policies, controls and procedures. The intended governance structure is therefore an accountable governing body or senior management above an appropriately empowered and independent compliance officer.

What Is an In-House AML Compliance Department?

An informal allocation of responsibility is not sufficient. The appointment should be formally documented and supported by a role description, defined reporting lines, evidence of competence, appropriate authority, access to information and safeguards against conflicts of interest or commercial interference.

The approval process depends on the applicable supervisory framework. MoET-supervised DNFBPs must obtain the relevant Supervisory Authority’s prior written approval. Where a suitably qualified and independent person cannot be appointed internally, the March 2026 MoET Guidelines provide that a third-party compliance officer may be permitted, subject to supervisory approval, fitness and propriety, independence, unrestricted access, contractual safeguards and continuing accountability by senior management.

The appropriate model may involve:

The correct structure depends on the entity’s size, activities, risk profile, licence and supervisory authority.

Federal Baseline and Supervisor-specific Requirements

Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025 establish the UAE-wide AML/CFT/CPF baseline. The detailed requirements concerning the compliance officer or MLRO, including approval, employment, residency, reporting, returns and outsourcing, may differ according to the entity’s supervisor and licence.

This page therefore distinguishes between:

1. Federal legal requirements applying across the relevant regulated categories;
2. supervisor-specific requirements imposed by the CBUAE, CMA, MoET, MoJ, DFSA, FSRA, VARA, GCGRA or another competent authority; and
3. AML UAE implementation recommendations intended to make the function operational and inspection-ready.

Legal InstrumentWhat It DoesWhat It Means for Your Department
Federal Decree-Law No. 10 of 2025 The primary AML/CFT/CPF statute, in force 14 October 2025, repealing FDL No. 20 of 2018 (Article 41). Sets the preventive obligations (Article 19), STR reporting duties (Article 18), supervisory powers (Article 16), administrative penalties of AED 10,000 to AED 5,000,000 per violation (Article 17), and criminal penalties (Articles 26 to 35). The department's mandate originates here: senior management accountability, the reporting duty the officer executes, and the penalty exposure a working function protects you from.
Cabinet Resolution No. 134 of 2025 The Executive Regulations, effective 14 December 2025. They define the entities within scope under Articles 2 to 4; require risk-based, senior-management-approved policies, controls and procedures under Article 5; prescribe training and an independent audit function under Article 21; establish the compliance officer's appointment and responsibilities under Article 22; regulate third-party reliance under Article 20; prescribe high-risk-country measures under Article 23; establish record-keeping requirements under Article 25; and address supervisory approval and oversight of compliance officers under Article 49. This is the principal operating framework for the compliance function. It determines how the function must be governed, resourced, appointed, monitored, trained, independently tested and evidenced. The detailed appointment and approval process must then be aligned with the applicable supervisory authority's rulebook or guidance.
Cabinet Decision No. 74 of 2020 The targeted financial sanctions framework: screening against UN and UAE Local Terrorist Lists, freezing without delay, and reporting to the Executive Office for Control and Non-Proliferation (EOCN). Your department's screening desk, freeze protocol, and EOCN reporting workflow are built to this instrument.
Cabinet Resolution No. 71 of 2024 The administrative penalty schedule for DNFBPs supervised by the MoET and MoJ: 41 listed violations with fines of AED 50,000 to AED 1,000,000, which the ministry may double where the same violation recurs within one year. Failure to appoint a compliance officer, register on goAML, or maintain the required records each appears in this schedule. The department exists to keep you off it.
Cabinet Resolution No. 109 of 2023 Real Beneficiary Procedures governing identification and maintenance of beneficial ownership information. Identification is not limited to the percentage threshold and may also arise through voting rights, direct or indirect control, control through other means and the applicable senior-management fallback where no natural person can otherwise be identified. The compliance function should establish responsibility for collecting, verifying, maintaining and updating beneficial ownership information and for ensuring that ownership and control are assessed beyond the percentage test alone.
Sectoral guidance issued by supervisory authorities Supervisory rulebooks, guidance, circulars and notices issued by the CBUAE, CMA, DFSA, FSRA, ADGM RA, MoET, MoJ, GCGRA, VARA and other competent authorities, including the MoET Guidelines for DNFBPs dated March 2026 and the April 2026 Joint Guidance on the Compliance Officer and MLRO Function in the UAE. The federal framework establishes the baseline, but appointment conditions, approval procedures, role titles, residency requirements, regulatory returns and reporting expectations may differ by supervisor. The department must therefore be mapped to the entity's actual licence and supervisory perimeter.

Entities operating in the DIFC and ADGM must also comply with the applicable DFSA AML Module or FSRA AML Rulebook. Both frameworks contain their own requirements concerning the MLRO, governance, independence, regulatory reporting and annual AML returns for relevant entities. The precise obligations depend on the entity’s regulatory status, permissions and applicable rulebook provisions. We design the function to the specific framework governing the client’s licence.

Who Must Set Up an AML Compliance Function in the UAE?

The same three categories the Executive Regulations bring into scope:

Banks and financial institutions.

Banks, finance companies, exchange houses, insurers, payment service providers, capital market firms, and other licensed financial institutions carrying out any of the fourteen financial activities listed in the law.

[Cabinet Resolution No. 134 of 2025, Article 2]

DNFBPs.

Real estate brokers and agents; dealers in precious metals and stones; lawyers, notaries, and independent accountants when executing financial transactions for clients; company and trust service providers; and commercial gaming operators.

[Cabinet Resolution No. 134 of 2025, Article 3]

VASPs.

Virtual asset service providers conducting exchange, transfer, safekeeping, or issuance-related activities.

[Cabinet Resolution No. 134 of 2025, Article 4]

Your supervisor follows your activity: the CBUAE for financial institutions, the MoET for most DNFBPs, the MoJ for legal professionals, the CMA for capital market companies, the GCGRA for commercial gaming operators, VARA for Dubai VASPs, and the DFSA or FSRA in the financial free zones. Suspicious transaction reports from all of them flow to the UAE Financial Intelligence Unit through goAML, and targeted financial sanctions matters go to the EOCN. Your department must be registered, named, and known to each of these before the first report is ever due.

What a Complete AML Compliance Department Includes

A department that survives an inspection is a set of appointments, registrations, and operating routines in which every element answers to a legal provision:

Compliance officer appointment.

A formally documented appointment at management level, supported by a role description, competence and fit-and-proper evidence, reporting lines, authority, independence safeguards and supervisory approval where applicable. For MoET-supervised DNFBPs, the appointment requires prior written approval and may, where an appropriate internal officer cannot be appointed, involve an approved third-party compliance officer.

[Cabinet Resolution No. 134 of 2025, Articles 22 and 49]

Senior management governance.

Board or owner-level approval of the framework, defined oversight duties, and a periodic reporting cadence from the officer to senior management with minutes to prove it happened.

[Cabinet Resolution No. 134 of 2025, Article 5(2)]

goAML registration and reporting workflow.

Registration with the UAE FIU, internal escalation routes, the officer’s decision log, and filing readiness for STRs and SARs under Article 18 of Federal Decree-Law No. 10 of 2025, with confidentiality rules that prohibit tipping off the customer.

[Cabinet Resolution No. 134 of 2025, Article 19]

Enterprise-Wide Risk Assessment ownership.

The documented ML/TF/PF risk study the department maintains, mapped to the National Risk Assessment and Sectoral Risk Assessment, updated on an ongoing basis.

[Cabinet Resolution No. 134 of 2025, Article 5(1)]
 

Policy, controls, and procedures.

The AML/CFT/CPF manual the department operates, drafted or realigned to the current law. If yours predates October 2025, see our AML/CFT Policy, Controls, and Procedures Documentation service, the natural companion to this one.

CDD, screening, and monitoring operations.

Risk-based onboarding and due diligence procedures covering the establishment of business relationships, applicable occasional-transaction or transfer thresholds, situations involving suspicion and cases where the accuracy or adequacy of existing identification information is doubtful. The function also includes sanctions, PEP and adverse-media screening, match disposition, enhanced due diligence and documented ongoing monitoring.

[Cabinet Resolution No. 134 of 2025, Articles 6 to 9 and 16]

Sector reporting.

Beyond STRs and SARs: REAR for real estate, DPMSR for dealers in precious metals and stones, and CNMR, PNMR, HRC, and HRCA where applicable.

Training programme.

A role-based AML/CFT/CPF training programme supported by training materials, attendance records, assessments and refresher arrangements. The regulated entity must also establish an appropriate independent audit function to test the effectiveness of its AML/CFT/CPF policies, controls and procedures. Internal project quality assurance does not replace the legally required independent audit.

[Cabinet Resolution No. 134 of 2025, Article 21]

Record keeping discipline.

CDD and transaction records retained for at least five years and retrievable promptly on request, with beneficial ownership records updated within fifteen working days of any change.

[Cabinet Resolution No. 134 of 2025, Article 25]

Compliance calendar.

Every registration renewal, report, review, and training deadline the department owes across the year, assigned to a named owner.

What Non-Compliance Costs in the UAE

The penalty framework makes the business case better than any brochure:

Administrative penalties.

Article 17 of Federal Decree-Law No. 10 of 2025 permits supervisory authorities to impose measures for breaches of the AML/CFT/CPF framework, including warnings, restrictions, suspension or cancellation of activities and administrative fines ranging from AED 10,000 to AED 5 million for each violation. Regulatory action may be taken for control failures without the authority first having to establish that the entity itself committed a money-laundering offence. The measure imposed will depend on the nature, seriousness and circumstances of the violation and the applicable supervisory framework.

The DNFBP penalty schedule.

Cabinet Resolution No. 71 of 2024 prescribes administrative violations and sanctions for specified DNFBP failings, including deficiencies relating to compliance appointments, registration, records and reporting. As the Resolution predates the new 2025 AML law and Executive Regulations, the applicable schedule and sanction should be checked against the transitional provisions and any subsequently issued replacement or supervisor-specific measure.

Criminal exposure.

Imprisonment and heavy fines for money laundering, terrorism financing, and proliferation financing offences, with corporate offenders facing fines of up to AED 100,000,000 and possible dissolution.

[Federal Decree-Law No. 10 of 2025, Articles 26 to 35]

Personal liability.

Senior management is responsible for approving the entity’s AML/CFT/CPF policies, controls and procedures and overseeing their effective implementation. Regulatory measures may also extend to responsible individuals where the applicable law, rulebook and facts support such action. The page should not imply that personal liability arises automatically from every control deficiency.

[Cabinet Resolution No. 134 of 2025, Article 5]

In-House, Outsourced, or Hybrid: Which Model Fits?

UAE-regulated entities may operate their AML compliance function through different delivery models. The legally permissible model depends on the entity type, supervisory authority, licence conditions and the individual proposed for appointment. Senior management and the regulated entity remain accountable irrespective of the model selected.

ModelMay Be Suitable ForPrincipal Considerations
Internal compliance officer or team Entities with sufficient internal expertise, resources and organisational scale The officer must have appropriate seniority, competence, independence, authority and access. Conflicts with sales, onboarding or other revenue-generating responsibilities must be prevented or appropriately controlled.
Approved third-party compliance officer MoET-supervised DNFBPs that cannot appoint a suitably qualified and independent person internally, where permitted and approved Prior written supervisory approval is required. The individual must satisfy competence, fit-and-proper, independence and access requirements. Responsibilities, reporting lines, confidentiality and access must be contractually documented. Senior management remains accountable. Other supervisors may restrict or prohibit this arrangement.
Hybrid compliance model Entities retaining an internal officer while obtaining specialist support for EWRA, documentation, screening, training, monitoring, remediation or regulatory readiness The appointed officer must continue to exercise independent judgement and retain responsibility for decisions that cannot be delegated. A written RACI and outsourcing framework should define ownership, escalation, access, confidentiality and quality oversight.

Do not select the delivery model before confirming the supervisory requirements. We first identify whether the regulator permits an internal, third-party or hybrid arrangement and then design the governance, appointment, reporting and support structure around that requirement.

Our AML Compliance Department Setup Process

The same disciplined sequence for every engagement, whether you are appointing your first compliance officer or rebuilding a function a previous inspection found wanting. Most clients reach an operational baseline within 2 to 6 weeks.

1. Discovery and scoping.

We confirm your licence type, supervisory authority, business model, products, customer types, and delivery channels, and agree the priority risks and outcomes.

2. Governance design.

We design the department’s structure: the officer’s position and reporting line, senior management oversight duties, escalation routes no commercial role can override, and the RACI matrix that documents who is responsible, accountable, consulted, and informed for every obligation. [Cabinet Resolution No. 134 of 2025, Article 5(2)]

3. Compliance officer or MLRO appointment.

We identify the appointment conditions applicable to your regulator, including internal-employment, residency, competence, fit-and-proper, independence and prior-approval requirements. We then prepare the role description, appointment documentation, competence file, reporting-line evidence and supervisory submission. Where the applicable framework permits a third-party compliance officer, we also document the appointment, access, confidentiality, accountability and contractual safeguards. [Cabinet Resolution No. 134 of 2025, Articles 22 and 49; applicable supervisory rulebook]

4. goAML registration.

We complete the FIU registration, build the internal escalation workflow that feeds it, and set up the reporting decision tree and the officer’s decision log.

5. Framework build.

The Enterprise-Wide Risk Assessment, the AML/CFT/CPF policy manual, and the registers, forms, and templates the department will run, each obligation carrying its legal citation. [Cabinet Resolution No. 134 of 2025, Articles 5, 21, 25]

6. Screening and systems enablement.

Where tools are needed, we support selection, configuration guidance, disposition rules, and the audit trail expectations that make screening defensible.

7. Training and go-live.

Role-based training for the officer, front-line staff, and senior management, with attendance records your inspector can test. [Cabinet Resolution No. 134 of 2025, Article 21]

8. Quality Assurance, handover and ongoing support.

A qualified second reviewer performs an internal quality assurance review of the agreed deliverables before handover. Your team receives the compliance calendar, governance and reporting arrangements, operational templates and implementation guidance. This internal quality review is separate from, and does not replace, an independent AML audit required under the applicable legal or supervisory framework.

What Is Included in Our Department Setup Service?

You receive a working function, not a folder. Every item is tailored to your licence and supervisor:

You receive

What it does

Compliance officer appointment pack

Role description, appointment letter, competence file, independence statement, and the supervisory approval submission where required

Governance charter and RACI matrix

Reporting lines, senior management oversight duties, and documented ownership for every obligation, ready for an inspector’s first question

goAML registration and reporting workflow

FIU registration, escalation routes, reporting decision tree, MLRO decision log, and the STR/SAR register

Enterprise-Wide Risk Assessment

A documented, defensible ML/TF/PF risk study the department owns and updates

AML/CFT/CPF policy and procedures manual

The framework the department operates, drafted or realigned to FDL 10/2025 and CR 134/2025 (see our dedicated documentation service)

Registers, forms, and templates

Customer, screening, and transaction registers; CDD, EDD, PEP, and source-of-funds forms; SAR and STR logs; sector-report registers for REAR and DPMSR; CNMR, PNMR, HRC, and HRCA

Training plan and register

Role-based training delivered and evidenced, so the department’s people are as defensible as its documents

Compliance calendar

Every AML/CFT/CPF obligation and deadline across the year, assigned to a named owner

Senior management reporting templates

The periodic report format that proves oversight is happening, with a minutes trail

Independent quality review

A qualified reviewer who was not the primary drafter checks the agreed deliverables for legal mapping, internal consistency, completeness and implementation readiness before handover. This is a delivery quality-control measure and does not replace the regulated entity’s independent AML audit

See what your licence actually requires.

A 15-minute call is usually enough. Tell us what you are licensed for and we will confirm which parts of the department apply to you, and which you can leave out.

What Information Do We Need From You?

Why AML UAE: Setup Experience You Can Verify

We are an AML consulting firm working only on AML/CFT compliance in the UAE, and building working compliance functions is where our delivery numbers come from:

300+

successful AML compliance projects across FIs, DNFBPs, and VASPs

1,000+

EWRA and AML/CFT/CPF policies and procedures delivered to UAE reporting entities

750+

professionals trained, across 3,000+ hours of AML/CFT/CPF training

500+

published articles, guides, and educational resources, including our widely read analyses of FDL No. 10 of 2025 and Cabinet Resolution No. 134 of 2025

The results show in delivery: Our delivery experience includes establishing governance and AML/CFT/CPF frameworks for financial institutions, DNFBPs and VASPs; supporting goAML and sector-reporting readiness; and delivering role-based training across operational and management teams.

In one VASP engagement, the agreed governance, risk-assessment, policy, screening and audit-readiness deliverables were implemented within four weeks. In a real estate engagement, we established the REAR reporting workflow and trained more than 650 agents to identify and escalate relevant transactions and suspicions.

Engagement outcomes depend on the client’s starting position, responsiveness, business complexity, regulator and scope. AML UAE does not guarantee regulatory approval or certify that an entity is fully compliant merely because the implementation deliverables have been completed.

The AML Compliance Specialists Who Build Your Department

Pathik Shah

CAMS, FCA, CS, CISA, DISA (ICAI), FAFP (ICAI)

Experience

28+ years

Regulatory Coverage

MoET, MoJ, CBUAE, CMA, FSRA, DFSA, VARA · AML/CFT framework design, RegTech

Jyoti Maheshwari

CAMS, ACA

Experience

11+ years

Regulatory Coverage

MoET, MoJ, CBUAE, CMA, FSRA, DFSA, VARA · AML/CFT/CPF framework, health checks

Dipali Vora

CAMS, ACS

Experience

10+ years

Regulatory Coverage

MoET, MoJ, CBUAE, CMA, FSRA, DFSA, VARA · Consulting, training, implementation

Monika Shah

CAMS

Experience

3+ years

Regulatory Coverage

MoET, MoJ, CBUAE, CMA, FSRA, DFSA, VARA · managed KYC, consulting, goAML reporting

Every framework carries a named reviewer and a review date, and passes an independent quality review before it reaches you. We are also straight about scope: what your department must contain depends on your licence, your activities, and your risk profile, and we will tell you plainly what you need and what you do not. And we stay engaged after handover: training refreshers, health checks, annual reviews, and realignment when the law or your business changes.

Setup Engagements Across UAE Frameworks

Three snapshots of what the service looks like in practice:

A virtual asset service provider preparing for supervision

The business needed a compliance function that could stand in front of its regulator before launch. We designed the governance structure, supported the compliance officer appointment, completed goAML registration, and delivered the EWRA, policy framework, and screening workflows. Within four weeks, the client had implemented the agreed governance, EWRA, policy, screening and reporting-readiness deliverables and was prepared for the next stage of its regulatory and independent-review process.

A real estate group scaling its reporting obligations

With REAR reporting arriving for the sector, the group needed the obligation to reach every branch, not just head office. We built the reporting workflow, set up the registers, and trained more than 650 agents so front-line staff knew when and how to raise internal alerts, giving the compliance officer a pipeline instead of a blind spot.

A small MoET-supervised DNFBP appointing its first officer

A single-officer function, sized honestly for a small business: one approved compliance officer with a written appointment, an escalation route the owners cannot override, a proportionate framework under Article 5(2)(b), and a compliance calendar that tells one person exactly what is due and when. Proportionate is not the same as informal, and the paper trail proves it.

FAQs on AML Compliance Department Setup in the UAE

An in-house AML compliance department is the internal function responsible for operating an organisation’s AML/CFT/CPF programme. It ordinarily includes an appointed compliance officer or MLRO, senior management oversight, defined reporting lines, goAML access, policies, risk assessments, registers, screening, monitoring and reporting procedures. UAE law requires an effective and proportionate compliance function, but it does not require every regulated entity to maintain a separately staffed department.

Yes. Every financial institution, DNFBP, and VASP in scope of Cabinet Resolution No. 134 of 2025 must appoint a compliance officer at management level with independence in decision-making and appropriate competence [Cabinet Resolution No. 134 of 2025, Article 22]. Operating without one is independently punishable, and for DNFBPs the failure appears in the administrative penalty schedule under Cabinet Resolution No. 71 of 2024.

The individual must satisfy the competence, experience, seniority, independence, authority, access and fit-and-proper requirements imposed by the applicable legal and supervisory framework. MoET-supervised DNFBPs must obtain prior written approval. Where a suitably qualified and independent internal officer cannot be appointed, MoET guidance permits a third-party compliance officer subject to prescribed conditions. Other regulators may impose different requirements, including full-time employment, UAE residency or separate regulatory approval.

Under the federal framework, the compliance officer owns the AML/CFT/CPF programme and the reporting decisions [Cabinet Resolution No. 134 of 2025, Article 22]. In the DIFC, the DFSA AML Module uses a dedicated MLRO regime for Relevant Persons, and in the ADGM the FSRA AML Rulebook sets its own MLRO requirements. In many mainland businesses one person holds both responsibilities; in the financial free zones the MLRO is a defined regulatory role with its own approval process.

The answer depends on the entity’s regulator. MoET guidance permits a DNFBP that cannot appoint a suitably qualified and independent internal compliance officer to appoint a third-party compliance officer, subject to prior written approval and safeguards relating to competence, fitness and propriety, independence, access, contractual responsibilities and continuing senior management accountability. Other regulators may require the officer to be an employee or may restrict outsourcing. Supporting activities may also be outsourced, but responsibilities and decisions that must remain with the appointed officer cannot be transferred without regulatory authority.

Approval requirements depend on the applicable supervisory framework. MoET-supervised DNFBPs must obtain prior written approval for the appointment. DFSA, FSRA, VARA and other regulators apply their own registration, approval, competence, residency or employment requirements. The appointment conditions should therefore be confirmed against the entity’s licence, activities and supervisory authority before the person begins performing the role.

goAML is the UAE Financial Intelligence Unit’s portal for suspicious transaction reporting and related filings. Registration is mandatory for reporting entities, and your compliance department cannot file an STR, SAR, or sector report without it. We handle the registration, build the internal escalation workflow that feeds it, and set up the reporting registers your inspector will ask to see.

Most organisations reach an operational baseline within 2 to 6 weeks, depending on readiness and complexity. Governance design and the compliance officer appointment typically land in the first two weeks, goAML registration and the framework build follow, and training and handover close the engagement.

Suspicious transaction and activity reports (STR, SAR) through goAML, plus the filings your sector requires: REAR for real estate, DPMSR for dealers in precious metals and stones, and funds-related and high-risk-country reports (CNMR, PNMR, HRC, HRCA) where applicable. The department also owes periodic internal reporting to senior management on the programme’s operation.

A single compliance officer may operate the function in a smaller entity where this is proportionate to the nature, size, complexity and ML/TF/PF risk of the business. The appointment must still be formally documented, adequately resourced and independent, and the officer must have sufficient authority and access. Where the individual holds another role, conflicts of interest and segregation-of-duties risks must be identified and appropriately controlled.

Yes. DIFC entities must consider the DFSA AML Module, while ADGM entities must consider the applicable FSRA AML Rulebook or Registration Authority framework. These regimes contain their own requirements concerning the MLRO, approval, reporting lines, independence, regulatory reporting and annual AML returns. The precise requirements depend on the entity’s regulated status, activities and permissions.

CDD records, transaction records, reports, and supporting analysis for at least five years from the completion of a transaction or the end of the business relationship, retrievable promptly on request (Cabinet Resolution No. 134 of 2025, Article 25), with beneficial ownership records updated within fifteen working days of any change.

Get the function right the first time.

One short form, one focused conversation, and a clear plan for the compliance department your business needs. A CAMS-certified specialist will come back with the scope, the timeline, and the price.

Latest AML/CFT Blogs