In-house AML Compliance Department Setup
An in-house AML compliance department is the internal function that operates your AML/CFT/CPF programme every working day. It brings together the compliance officer or MLRO, senior management oversight, reporting lines, goAML access, policies, registers, systems and operating procedures required to manage financial crime risk.
UAE law requires financial institutions, DNFBPs and VASPs to maintain proportionate AML/CFT/CPF arrangements and appoint a competent compliance officer at management level. It does not require every regulated entity to maintain a separately staffed department. Depending on the organisation’s size, activities, risk profile and supervisory framework, the compliance function may be operated by a single internal officer, a larger internal team or, where permitted, an approved third-party or hybrid arrangement.
Common inspection weaknesses include an undocumented appointment, insufficient independence, unclear reporting lines, missing supervisory approval, incomplete goAML registration and inadequate access to customer or transaction information. These failures can result in regulatory action even where no underlying money-laundering offence has been established. Article 17 of Federal Decree-Law No. 10 of 2025 permits supervisory authorities to impose measures including warnings, restrictions and administrative fines ranging from AED 10,000 to AED 5 million for each violation, depending on the circumstances and applicable supervisory framework.
We help you build an operational compliance function that is properly structured, appointed, approved where required, registered, documented and ready to operate.
A function, not a file.
Build an AML compliance function that is properly appointed, approved where required, registered, documented and operational.
What Is an In-House AML Compliance Department?
In legal terms, it is the governance layer of your AML programme, the appointed compliance officer or MLRO, the senior management oversight above them, and the operating machinery beneath them. When an inspection or review begins, three things are requested before almost anything else: your AML policy and procedures, your business risk assessment, and your compliance officer’s appointment. This service exists for the third, and for everything the third person needs to actually do the job.
A working AML department in the UAE stands on four legs.
The appointment:
A named, qualified individual at management level, independent in decision-making, approved by your supervisor where the law requires it.
The authority:
Documented reporting lines that let the officer escalate to senior management and block or file without being overridden.
The access:
goAML registration, screening tools, and the customer and transaction data the role needs.
The evidence:
Registers, decision logs, training records, and periodic reports to senior management that prove the function operates.
An informal allocation of responsibility is not sufficient. The appointment should be formally documented and supported by a role description, defined reporting lines, evidence of competence, appropriate authority, access to information and safeguards against conflicts of interest or commercial interference.
The approval process depends on the applicable supervisory framework. MoET-supervised DNFBPs must obtain the relevant Supervisory Authority’s prior written approval. Where a suitably qualified and independent person cannot be appointed internally, the March 2026 MoET Guidelines provide that a third-party compliance officer may be permitted, subject to supervisory approval, fitness and propriety, independence, unrestricted access, contractual safeguards and continuing accountability by senior management.
Is an AML Compliance Officer Mandatory in the UAE?
Yes. Article 22 of Cabinet Resolution No. 134 of 2025 requires financial institutions, DNFBPs and VASPs within its scope to appoint a compliance officer at management level. The officer must possess appropriate competence and experience, exercise independent judgement and perform the responsibilities assigned under the Executive Regulations.
Appointment formalities are also governed by the relevant supervisory framework. Article 49 of Cabinet Resolution No. 134 of 2025 empowers supervisory authorities to maintain records of compliance officers and require regulated entities to obtain approval before appointment. MoET’s March 2026 Guidelines specifically require prior written supervisory approval for the compliance officer of a MoET-supervised DNFBP.
The officer’s responsibilities include reviewing internal reports and relevant records, deciding whether a matter should be reported to the UAE Financial Intelligence Unit, maintaining the confidentiality of reporting decisions, overseeing the AML/CFT/CPF framework and reporting periodically to senior management.
Senior management remains responsible for approving and overseeing the entity’s policies, controls and procedures. The intended governance structure is therefore an accountable governing body or senior management above an appropriately empowered and independent compliance officer.
Is a Separate AML Compliance Department Mandatory in the UAE?
UAE-regulated financial institutions, DNFBPs and VASPs must maintain proportionate AML/CFT/CPF arrangements and appoint an appropriately empowered compliance officer. However, the law does not require every entity to establish a separately staffed department.
The appropriate model may involve:
- one internal compliance officer;
- an internal compliance team;
- an approved third-party compliance officer, where permitted; or
- an internal officer supported through a hybrid arrangement.
The correct structure depends on the entity’s size, activities, risk profile, licence and supervisory authority.
Federal Baseline and Supervisor-specific Requirements
Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025 establish the UAE-wide AML/CFT/CPF baseline. The detailed requirements concerning the compliance officer or MLRO, including approval, employment, residency, reporting, returns and outsourcing, may differ according to the entity’s supervisor and licence.
This page therefore distinguishes between:
1. Federal legal requirements applying across the relevant regulated categories;
2. supervisor-specific requirements imposed by the CBUAE, CMA, MoET, MoJ, DFSA, FSRA, VARA, GCGRA or another competent authority; and
3. AML UAE implementation recommendations intended to make the function operational and inspection-ready.
| Legal Instrument | What It Does | What It Means for Your Department |
|---|---|---|
| Federal Decree-Law No. 10 of 2025 | The primary AML/CFT/CPF statute, in force 14 October 2025, repealing FDL No. 20 of 2018 (Article 41). Sets the preventive obligations (Article 19), STR reporting duties (Article 18), supervisory powers (Article 16), administrative penalties of AED 10,000 to AED 5,000,000 per violation (Article 17), and criminal penalties (Articles 26 to 35). | The department's mandate originates here: senior management accountability, the reporting duty the officer executes, and the penalty exposure a working function protects you from. |
| Cabinet Resolution No. 134 of 2025 | The Executive Regulations, effective 14 December 2025. They define the entities within scope under Articles 2 to 4; require risk-based, senior-management-approved policies, controls and procedures under Article 5; prescribe training and an independent audit function under Article 21; establish the compliance officer's appointment and responsibilities under Article 22; regulate third-party reliance under Article 20; prescribe high-risk-country measures under Article 23; establish record-keeping requirements under Article 25; and address supervisory approval and oversight of compliance officers under Article 49. | This is the principal operating framework for the compliance function. It determines how the function must be governed, resourced, appointed, monitored, trained, independently tested and evidenced. The detailed appointment and approval process must then be aligned with the applicable supervisory authority's rulebook or guidance. |
| Cabinet Decision No. 74 of 2020 | The targeted financial sanctions framework: screening against UN and UAE Local Terrorist Lists, freezing without delay, and reporting to the Executive Office for Control and Non-Proliferation (EOCN). | Your department's screening desk, freeze protocol, and EOCN reporting workflow are built to this instrument. |
| Cabinet Resolution No. 71 of 2024 | The administrative penalty schedule for DNFBPs supervised by the MoET and MoJ: 41 listed violations with fines of AED 50,000 to AED 1,000,000, which the ministry may double where the same violation recurs within one year. | Failure to appoint a compliance officer, register on goAML, or maintain the required records each appears in this schedule. The department exists to keep you off it. |
| Cabinet Resolution No. 109 of 2023 | Real Beneficiary Procedures governing identification and maintenance of beneficial ownership information. Identification is not limited to the percentage threshold and may also arise through voting rights, direct or indirect control, control through other means and the applicable senior-management fallback where no natural person can otherwise be identified. | The compliance function should establish responsibility for collecting, verifying, maintaining and updating beneficial ownership information and for ensuring that ownership and control are assessed beyond the percentage test alone. |
| Sectoral guidance issued by supervisory authorities | Supervisory rulebooks, guidance, circulars and notices issued by the CBUAE, CMA, DFSA, FSRA, ADGM RA, MoET, MoJ, GCGRA, VARA and other competent authorities, including the MoET Guidelines for DNFBPs dated March 2026 and the April 2026 Joint Guidance on the Compliance Officer and MLRO Function in the UAE. | The federal framework establishes the baseline, but appointment conditions, approval procedures, role titles, residency requirements, regulatory returns and reporting expectations may differ by supervisor. The department must therefore be mapped to the entity's actual licence and supervisory perimeter. |
Entities operating in the DIFC and ADGM must also comply with the applicable DFSA AML Module or FSRA AML Rulebook. Both frameworks contain their own requirements concerning the MLRO, governance, independence, regulatory reporting and annual AML returns for relevant entities. The precise obligations depend on the entity’s regulatory status, permissions and applicable rulebook provisions. We design the function to the specific framework governing the client’s licence.
Who Must Set Up an AML Compliance Function in the UAE?
The same three categories the Executive Regulations bring into scope:
Banks and financial institutions.
Banks, finance companies, exchange houses, insurers, payment service providers, capital market firms, and other licensed financial institutions carrying out any of the fourteen financial activities listed in the law.
[Cabinet Resolution No. 134 of 2025, Article 2]
DNFBPs.
Real estate brokers and agents; dealers in precious metals and stones; lawyers, notaries, and independent accountants when executing financial transactions for clients; company and trust service providers; and commercial gaming operators.
[Cabinet Resolution No. 134 of 2025, Article 3]
VASPs.
Virtual asset service providers conducting exchange, transfer, safekeeping, or issuance-related activities.
[Cabinet Resolution No. 134 of 2025, Article 4]
Your supervisor follows your activity: the CBUAE for financial institutions, the MoET for most DNFBPs, the MoJ for legal professionals, the CMA for capital market companies, the GCGRA for commercial gaming operators, VARA for Dubai VASPs, and the DFSA or FSRA in the financial free zones. Suspicious transaction reports from all of them flow to the UAE Financial Intelligence Unit through goAML, and targeted financial sanctions matters go to the EOCN. Your department must be registered, named, and known to each of these before the first report is ever due.
What a Complete AML Compliance Department Includes
A department that survives an inspection is a set of appointments, registrations, and operating routines in which every element answers to a legal provision:
Compliance officer appointment.
A formally documented appointment at management level, supported by a role description, competence and fit-and-proper evidence, reporting lines, authority, independence safeguards and supervisory approval where applicable. For MoET-supervised DNFBPs, the appointment requires prior written approval and may, where an appropriate internal officer cannot be appointed, involve an approved third-party compliance officer.
[Cabinet Resolution No. 134 of 2025, Articles 22 and 49]
Senior management governance.
Board or owner-level approval of the framework, defined oversight duties, and a periodic reporting cadence from the officer to senior management with minutes to prove it happened.
[Cabinet Resolution No. 134 of 2025, Article 5(2)]
goAML registration and reporting workflow.
Registration with the UAE FIU, internal escalation routes, the officer’s decision log, and filing readiness for STRs and SARs under Article 18 of Federal Decree-Law No. 10 of 2025, with confidentiality rules that prohibit tipping off the customer.
[Cabinet Resolution No. 134 of 2025, Article 19]
Enterprise-Wide Risk Assessment ownership.
The documented ML/TF/PF risk study the department maintains, mapped to the National Risk Assessment and Sectoral Risk Assessment, updated on an ongoing basis.
Policy, controls, and procedures.
The AML/CFT/CPF manual the department operates, drafted or realigned to the current law. If yours predates October 2025, see our AML/CFT Policy, Controls, and Procedures Documentation service, the natural companion to this one.
CDD, screening, and monitoring operations.
Risk-based onboarding and due diligence procedures covering the establishment of business relationships, applicable occasional-transaction or transfer thresholds, situations involving suspicion and cases where the accuracy or adequacy of existing identification information is doubtful. The function also includes sanctions, PEP and adverse-media screening, match disposition, enhanced due diligence and documented ongoing monitoring.
[Cabinet Resolution No. 134 of 2025, Articles 6 to 9 and 16]
Sector reporting.
Beyond STRs and SARs: REAR for real estate, DPMSR for dealers in precious metals and stones, and CNMR, PNMR, HRC, and HRCA where applicable.
Training programme.
A role-based AML/CFT/CPF training programme supported by training materials, attendance records, assessments and refresher arrangements. The regulated entity must also establish an appropriate independent audit function to test the effectiveness of its AML/CFT/CPF policies, controls and procedures. Internal project quality assurance does not replace the legally required independent audit.
[Cabinet Resolution No. 134 of 2025, Article 21]
Record keeping discipline.
CDD and transaction records retained for at least five years and retrievable promptly on request, with beneficial ownership records updated within fifteen working days of any change.
[Cabinet Resolution No. 134 of 2025, Article 25]
Compliance calendar.
Every registration renewal, report, review, and training deadline the department owes across the year, assigned to a named owner.
What Non-Compliance Costs in the UAE
The penalty framework makes the business case better than any brochure:
Administrative penalties.
Article 17 of Federal Decree-Law No. 10 of 2025 permits supervisory authorities to impose measures for breaches of the AML/CFT/CPF framework, including warnings, restrictions, suspension or cancellation of activities and administrative fines ranging from AED 10,000 to AED 5 million for each violation. Regulatory action may be taken for control failures without the authority first having to establish that the entity itself committed a money-laundering offence. The measure imposed will depend on the nature, seriousness and circumstances of the violation and the applicable supervisory framework.
The DNFBP penalty schedule.
Cabinet Resolution No. 71 of 2024 prescribes administrative violations and sanctions for specified DNFBP failings, including deficiencies relating to compliance appointments, registration, records and reporting. As the Resolution predates the new 2025 AML law and Executive Regulations, the applicable schedule and sanction should be checked against the transitional provisions and any subsequently issued replacement or supervisor-specific measure.
Criminal exposure.
Imprisonment and heavy fines for money laundering, terrorism financing, and proliferation financing offences, with corporate offenders facing fines of up to AED 100,000,000 and possible dissolution.
[Federal Decree-Law No. 10 of 2025, Articles 26 to 35]
Personal liability.
Senior management is responsible for approving the entity’s AML/CFT/CPF policies, controls and procedures and overseeing their effective implementation. Regulatory measures may also extend to responsible individuals where the applicable law, rulebook and facts support such action. The page should not imply that personal liability arises automatically from every control deficiency.
[Cabinet Resolution No. 134 of 2025, Article 5]
In-House, Outsourced, or Hybrid: Which Model Fits?
UAE-regulated entities may operate their AML compliance function through different delivery models. The legally permissible model depends on the entity type, supervisory authority, licence conditions and the individual proposed for appointment. Senior management and the regulated entity remain accountable irrespective of the model selected.
| Model | May Be Suitable For | Principal Considerations |
|---|---|---|
| Internal compliance officer or team | Entities with sufficient internal expertise, resources and organisational scale | The officer must have appropriate seniority, competence, independence, authority and access. Conflicts with sales, onboarding or other revenue-generating responsibilities must be prevented or appropriately controlled. |
| Approved third-party compliance officer | MoET-supervised DNFBPs that cannot appoint a suitably qualified and independent person internally, where permitted and approved | Prior written supervisory approval is required. The individual must satisfy competence, fit-and-proper, independence and access requirements. Responsibilities, reporting lines, confidentiality and access must be contractually documented. Senior management remains accountable. Other supervisors may restrict or prohibit this arrangement. |
| Hybrid compliance model | Entities retaining an internal officer while obtaining specialist support for EWRA, documentation, screening, training, monitoring, remediation or regulatory readiness | The appointed officer must continue to exercise independent judgement and retain responsibility for decisions that cannot be delegated. A written RACI and outsourcing framework should define ownership, escalation, access, confidentiality and quality oversight. |
Do not select the delivery model before confirming the supervisory requirements. We first identify whether the regulator permits an internal, third-party or hybrid arrangement and then design the governance, appointment, reporting and support structure around that requirement.
Our AML Compliance Department Setup Process
The same disciplined sequence for every engagement, whether you are appointing your first compliance officer or rebuilding a function a previous inspection found wanting. Most clients reach an operational baseline within 2 to 6 weeks.
1. Discovery and scoping.
We confirm your licence type, supervisory authority, business model, products, customer types, and delivery channels, and agree the priority risks and outcomes.
2. Governance design.
We design the department’s structure: the officer’s position and reporting line, senior management oversight duties, escalation routes no commercial role can override, and the RACI matrix that documents who is responsible, accountable, consulted, and informed for every obligation. [Cabinet Resolution No. 134 of 2025, Article 5(2)]
3. Compliance officer or MLRO appointment.
We identify the appointment conditions applicable to your regulator, including internal-employment, residency, competence, fit-and-proper, independence and prior-approval requirements. We then prepare the role description, appointment documentation, competence file, reporting-line evidence and supervisory submission. Where the applicable framework permits a third-party compliance officer, we also document the appointment, access, confidentiality, accountability and contractual safeguards. [Cabinet Resolution No. 134 of 2025, Articles 22 and 49; applicable supervisory rulebook]
4. goAML registration.
We complete the FIU registration, build the internal escalation workflow that feeds it, and set up the reporting decision tree and the officer’s decision log.
5. Framework build.
The Enterprise-Wide Risk Assessment, the AML/CFT/CPF policy manual, and the registers, forms, and templates the department will run, each obligation carrying its legal citation. [Cabinet Resolution No. 134 of 2025, Articles 5, 21, 25]
6. Screening and systems enablement.
Where tools are needed, we support selection, configuration guidance, disposition rules, and the audit trail expectations that make screening defensible.
7. Training and go-live.
Role-based training for the officer, front-line staff, and senior management, with attendance records your inspector can test. [Cabinet Resolution No. 134 of 2025, Article 21]
8. Quality Assurance, handover and ongoing support.
A qualified second reviewer performs an internal quality assurance review of the agreed deliverables before handover. Your team receives the compliance calendar, governance and reporting arrangements, operational templates and implementation guidance. This internal quality review is separate from, and does not replace, an independent AML audit required under the applicable legal or supervisory framework.
What Is Included in Our Department Setup Service?
You receive a working function, not a folder. Every item is tailored to your licence and supervisor:
You receive
What it does
Compliance officer appointment pack
Role description, appointment letter, competence file, independence statement, and the supervisory approval submission where required
Governance charter and RACI matrix
Reporting lines, senior management oversight duties, and documented ownership for every obligation, ready for an inspector’s first question
goAML registration and reporting workflow
FIU registration, escalation routes, reporting decision tree, MLRO decision log, and the STR/SAR register
Enterprise-Wide Risk Assessment
A documented, defensible ML/TF/PF risk study the department owns and updates
AML/CFT/CPF policy and procedures manual
The framework the department operates, drafted or realigned to FDL 10/2025 and CR 134/2025 (see our dedicated documentation service)
Registers, forms, and templates
Customer, screening, and transaction registers; CDD, EDD, PEP, and source-of-funds forms; SAR and STR logs; sector-report registers for REAR and DPMSR; CNMR, PNMR, HRC, and HRCA
Training plan and register
Role-based training delivered and evidenced, so the department’s people are as defensible as its documents
Compliance calendar
Every AML/CFT/CPF obligation and deadline across the year, assigned to a named owner
Senior management reporting templates
The periodic report format that proves oversight is happening, with a minutes trail
Independent quality review
A qualified reviewer who was not the primary drafter checks the agreed deliverables for legal mapping, internal consistency, completeness and implementation readiness before handover. This is a delivery quality-control measure and does not replace the regulated entity’s independent AML audit
MLRO appointment and approval pack
Prepare the compliance officer or MLRO appointment pack
Appointing a compliance officer involves documenting the role, the person’s suitability and the authority needed to perform it. We prepare the appointment evidence against your entity’s supervisory framework and proposed operating model.
Build the appointment evidence
The pack can include a role description, appointment letter, competence record, reporting lines, independence assessment and relevant application forms. We identify approval or notification requirements and any employment, residency or role-combination issues requiring attention.
Make the role operational
You receive a submission checklist and a record of outstanding conditions, together with access and handover actions. Your organisation approves the appointment and the relevant authority determines any regulatory approval. Share the candidate’s experience, qualifications and proposed responsibilities so the pack reflects the actual role.
Employee AML screening and competence controls
Document employee screening and AML competence controls
People performing AML work need appropriate competence, integrity and clearly defined responsibilities. We help you design proportionate employee screening and competence checks for recruitment, appointment and changes of role.
Match checks to the role
We review the information needed, permitted checks, verification methods and escalation of concerns. The procedure distinguishes qualifications from practical capability and considers conflicts of interest and access to sensitive information. Privacy and lawful data handling form part of the design.
Keep appointment evidence current
You receive a role-based checklist, competence record and review triggers. Management retains hiring and appointment decisions. Provide role descriptions and current HR procedures so the controls fit your organisation and the applicable supervisory expectations.
Accounting-service AML scope assessment
- Determine the AML scope of accounting services
An accounting firm’s AML position depends on the services it performs and its jurisdiction. We review your engagement types and actual work to determine which activities fall within the applicable regulated scope.
- Assess the work behind the service label
The review examines activities such as managing client money, supporting business or asset transactions and creating or administering legal entities. We distinguish work performed by the firm from functions carried out internally by a client’s employees and record relevant scope questions.
- A service-level scope map
You receive an activity assessment, supervisory mapping and proposed intake questions for new engagements. Provide your licence, service list and representative engagement letters so the analysis is based on the work your firm undertakes.
Law-firm matter-level AML scope assessment
Assess AML scope at law firm matter level
A law firm’s AML obligations must be applied to the work undertaken on a matter. We help you build an intake assessment that identifies relevant activities, the applicable supervisory framework and circumstances requiring specialist review.
Start with the proposed work
The assessment considers the transaction or arrangement, the firm’s role and whether client funds or assets are involved. We distinguish the scope analysis from separate questions of professional secrecy, privilege and suspicious reporting.
A repeatable intake decision
You receive matter-screening questions, a scope decision record and review triggers for changes in instructions. Your responsible lawyer confirms the nature of the work. Where the position requires legal interpretation or regulatory clarification, that issue is recorded for resolution before assumptions become embedded in the process.
MVTS agent AML oversight review
Review AML oversight of money transfer agents
An agent network needs clear allocation of onboarding, transaction review and escalation responsibilities. We assess how a money or value transfer business oversees its agents and obtains evidence that agreed controls operate.
Check the oversight arrangement
The review covers agent due diligence, agreements, training, reporting, data access and responses to exceptions. We examine whether the principal can identify activity requiring intervention and how agent changes or breaches are handled.
A practical oversight plan
You receive a responsibility map, monitoring recommendations and a record of identified gaps. The scope is aligned to the relevant licence and CBUAE framework. Provide the agent register, contracts and oversight records so the assessment tests the actual network arrangements.
Registered hawala provider AML framework review
Review AML arrangements for registered hawala providers
Registered hawala providers need controls suited to their customer base, settlement methods and operating permissions. We review the framework against the applicable CBUAE requirements and the way the business actually operates.
Follow the transaction and settlement records
The assessment examines customer identification, counterparty information, screening, transaction records and suspicious activity escalation. We consider how funds are settled and how the business reconciles its records across the relevant parties.
An implementation plan
You receive a gap assessment and prioritised actions for procedures, records and staff responsibilities. We review the registration conditions first and identify any activity that needs regulatory clarification. The service does not authorise unregistered or out-of-scope operations.
Bank AML outsourcing approval support
- Prepare AML outsourcing approval evidence for banks
A proposed outsourcing arrangement may require regulatory approval or notification before implementation. We help banks assess the relevant requirements and assemble the evidence needed for the applicable CBUAE process.
- Explain the arrangement and its safeguards
The pack addresses the outsourced activity, provider assessment, accountability, data access, business continuity and exit arrangements. We identify dependencies on subcontractors and the evidence supporting ongoing oversight.
- A submission ready for internal approval
You receive a requirements checklist, draft supporting material and an outstanding-issues register. The bank confirms the proposal and submits through its authorised channel. Regulatory approval remains with the CBUAE, and the service does not imply that every AML role or activity may be outsourced.
Introducer and promoter AML responsibility review
Clarify AML responsibilities for introducers and promoters
An introduction or promotion arrangement can leave uncertainty about who identifies the customer and who assesses the relationship. We review the firm’s actual activities, licence permissions and agreements to define its AML responsibilities.
Examine the customer journey
The assessment follows information from the first contact through referral and acceptance. We identify what your firm knows, which checks it performs and what evidence must reach another regulated party. Responsibility is not assumed to transfer merely because the final service is provided elsewhere.
A clear allocation of work
You receive an activity and responsibility map, proposed procedures and escalation criteria. Provide the relevant agreements and examples of customer interaction so the conclusions reflect how the arrangement operates.
CMA compliance officer AML handover
Manage the AML handover between compliance officers
A change of compliance officer can leave reporting commitments, open cases or authority correspondence without a clear owner. We help CMA-supervised firms organise a controlled handover of the AML function.
Identify what must remain continuous
The review covers open actions, reporting calendars, restricted case records, systems access and relevant supervisory communications. We identify approval or notification steps and ensure access changes are coordinated with the effective appointment arrangements.
A documented handover pack
You receive a handover checklist, responsibility record and outstanding-items tracker. Sensitive information is transferred through authorised access rather than informal files. The outgoing and incoming officers, management and system owners confirm their respective actions.
DFSA DNFBP AML registration support
- Support DFSA DNFBP registration
A business operating in the DIFC should assess whether its activities require DFSA DNFBP registration. We help evaluate the proposed services and prepare the AML-related registration evidence for the relevant process.
- Confirm scope before preparing the pack
The review considers the entity, business activities and applicable DNFBP categories. We identify information required about governance, the MLRO and the compliance arrangements, including points needing clarification.
- Organised application support
You receive a scope record, document checklist and draft supporting material. Your organisation confirms the information and submits through the authorised channel. Registration remains a DFSA decision and is distinct from a commercial licence or other permissions the business may need.
DFSA MLRO suitability and interview preparation
Prepare a DFSA MLRO candidate for the role
An MLRO candidate needs to understand the firm’s risks, controls and responsibilities as well as the applicable requirements. We help assess readiness and organise evidence for the relevant appointment process.
Test practical understanding
Preparation covers the business model, escalation arrangements, reporting judgement and access to management. We use scenarios and discussion to identify knowledge or experience gaps, rather than supplying memorised interview answers.
A focused readiness plan
You receive a suitability evidence checklist, preparation sessions and a development plan. The firm’s appointment decisions and the DFSA’s approval assessment remain separate. Share the role description, candidate background and business risk assessment so preparation is tailored to the role.
ADGM RA DNFBP registration and scope review
Assess ADGM RA DNFBP scope and registration
An ADGM business needs to establish whether its activities fall within the DNFBP framework supervised by the Registration Authority. We review the actual services and prepare the evidence for the relevant registration or supervisory process.
Identify the applicable route
The assessment considers the entity’s activities, licence and customer relationships. We distinguish RA-supervised DNFBP requirements from FSRA financial services authorisation and identify any points requiring clarification.
A documented scope and readiness pack
You receive a scope assessment, requirements checklist and proposed actions for governance, the MLRO and operational controls. Provide your licence and service descriptions so the review is grounded in the business model. Commercial registration alone is not treated as completion of all AML requirements.
ADGM RA MLRO appointment pack
Prepare an ADGM RA MLRO appointment pack
An ADGM DNFBP needs appointment evidence that reflects the MLRO’s responsibilities and the applicable RA expectations. We help organise candidate information, role arrangements and supporting documents.
Check suitability and practical access
The review considers competence, independence, reporting lines, availability and access to customer and transaction records. We use the relevant appointment checklist and identify issues requiring confirmation before submission or commencement.
A complete appointment record
You receive a document checklist, draft role materials and a record of outstanding conditions. The entity confirms the appointment arrangements and the authority determines any required approval. Share the proposed role and candidate background so the pack describes the function accurately.
ADGM high-value dealer AML scope and controls
Assess AML scope for high value dealers in ADGM
ADGM’s DNFBP framework includes activities that require a specific assessment of high–value dealing. We help businesses examine their goods, transaction methods and role against the applicable ADGM definition and requirements.
Review the actual trading model
The assessment considers the items sold, transaction values, linked activity, payment arrangements and the entity carrying out the sale. We avoid importing a mainland DPMS scope test into an ADGM business without checking the relevant rule.
A practical control plan
You receive a scope record, supervisory mapping and proposed customer, transaction and record-keeping controls. Share the licence and sales profile so the assessment is based on the business’s activity. Any unresolved interpretation is identified for appropriate clarification.
FSRA AML authorisation readiness
Prepare the AML framework for FSRA authorisation
An FSRA application needs an AML framework that fits the proposed financial services and can be put into operation. We help applicants connect their business model to risk assessment, governance and control evidence.
Build around the proposed permissions
The work examines customers, products, jurisdictions, outsourcing and transaction flows. We prepare or review the AML-related documents and identify dependencies such as the MLRO appointment, systems and data access.
A readiness pack with open conditions
You receive a requirements map, supporting materials and a register of actions to complete before the relevant stage of authorisation or launch. The applicant remains responsible for its submission and the FSRA determines approval. We do not present a draft policy as evidence that an operational control has already been implemented.
FSRA MLRO appointment and continuity support
Maintain continuity in an FSRA MLRO appointment
An FSRA-regulated firm’s AML function needs continuity during an appointment, absence or a change of MLRO. We help prepare the role evidence and transition arrangements under the applicable framework.
Identify responsibilities that cannot lapse
The review covers suitability, reporting lines, access, pending cases and regulatory commitments. We assess approval or notification requirements and the proposed arrangements for absence or departure, without assuming one substitute model fits every firm.
A controlled appointment and handover
You receive the appointment checklist, continuity actions and a record of unresolved conditions. Management and authorised officers confirm implementation. Share the role description, planned change and current obligations so coverage is considered before access or responsibilities are transferred.
VARA AML licence-readiness pack
Prepare AML evidence for a VARA licence application
A VASP’s AML arrangements should explain how its permitted activities will be controlled in practice. We help applicants prepare the AML-related components of their VARA readiness pack.
Connect the operating model to the controls
The work considers customer and wallet onboarding, counterparty exposure, transaction monitoring, sanctions response and reporting responsibilities. We map documents and operational evidence to the relevant requirements and identify dependencies on technology or service providers.
A clear readiness position
You receive a requirements matrix, supporting materials and an open-actions register. We distinguish planned controls from implemented and tested arrangements. VARA determines the licensing outcome, and our support does not authorise trading before the relevant permissions are in place.
VARA MLRO appointment and readiness support
- Prepare a VARA MLRO for appointment and operation
A VASP’s MLRO needs to understand both the regulatory role and the risks created by the firm’s virtual asset activities. We help organise appointment evidence and assess practical readiness for the function.
- Review competence and operating arrangements
The assessment covers experience, responsibilities, independence, escalation and access to relevant customer, wallet and transaction information. We identify approval conditions, knowledge gaps and dependencies on other teams or providers.
- A readiness and development record
You receive an appointment checklist, proposed role materials and a focused action plan. Scenario discussions test understanding of the firm’s actual business model. The appointment and any required approval remain with the firm and VARA respectively.
Sponsored VASP AML responsibility review
Define AML responsibilities in a sponsored VASP arrangement
A sponsored VASP arrangement needs a clear account of who performs AML work and who remains responsible for oversight. We review the proposed structure against the applicable VARA sponsored VASP provisions and approvals.
Map the operating responsibilities
The assessment covers onboarding, due diligence, monitoring, sanctions response, reporting and access to records. We examine escalation between the sponsor and sponsored entity, including the role of the responsible officer and dependencies on shared systems.
A documented allocation and oversight plan
You receive a responsibility matrix, agreement recommendations and an evidence-access checklist. The arrangement must reflect the relevant regulatory conditions; a commercial contract does not itself transfer or remove obligations. Share the proposed agreements, approvals and operating model for review.
Country-risk list and countermeasure update
Define AML responsibilities in insurance intermediary arrangements
Insurance distribution can involve several organisations collecting customer information. We help you establish whether the arrangement is a referral, outsourced activity or permitted reliance, and what each party must do.
Check the evidence handover
The review covers the agreement, regulatory status, required information, access to documents and escalation of concerns. We identify gaps between the promised service and the records actually received by the insurer or intermediary.
A workable responsibility framework
You receive an assessment, proposed contractual provisions and oversight checks. The relevant entity retains the responsibilities assigned to it by law and supervisory rules. Provide the distribution agreement and sample customer files so the review can test the arrangement in practice.
AML Scope and Supervisor Determination
Does your business fall within UAE AML requirements, and which authority supervises it? We help you establish the answer before you appoint a compliance officer, arrange registrations, or build your compliance framework.
You may be starting a business, adding an activity to your licence or expanding into another UAE jurisdiction. You may also have received an AML questionnaire from your bank or licensing authority and need to understand what applies to you.
AML UAE reviews your licensed activities alongside the services you actually provide, your operating jurisdiction, and your regulatory permissions. We then prepare a documented assessment of your AML/CFT/CPF obligations and the relevant supervisory framework.
What we assess
Our review covers:
Your business activities
What you do for customers, the transactions you facilitate and whether you handle funds, assets or company arrangements on their behalf.
Your licence and permissions
Your legal entity, branches, licensing jurisdiction and any existing regulatory approvals.
Your regulatory scope
Whether your activities fall within the relevant financial institution, designated non-financial business or profession, or virtual asset service provider categories.
Your supervisory authority
The authority responsible for AML supervision of the activities under review and any matters requiring clarification.
Your initial compliance requirements
Applicable registrations, compliance officer or MLRO arrangements, risk assessments, policies, customer checks, reporting and record-keeping requirements.
We consider the current federal AML framework, including Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025, alongside the relevant supervisory rules and guidance.
What you receive
You receive an activity-to-obligation and supervisor map that explains:
| Deliverable | What it tells you |
|---|---|
| Activity assessment | Which reviewed activities fall within the relevant AML framework, with the supporting reasoning |
| Supervisor mapping | Which supervisory authority and framework apply to each relevant entity or activity |
| Initial obligation register | What your business needs to put in place and the applicable legal or supervisory basis |
| Clarification list | Any unresolved points, missing information or questions requiring confirmation from the relevant authority |
| Prioritised action plan | The next steps, their sequence and the proposed allocation of responsibility |
The assessment records its assumptions and any limitations arising from the information available. Where regulatory confirmation is needed, we identify the question and help you prepare the supporting explanation.
What we need from you
Please provide your trade licence, regulatory permissions where applicable, a description of your services and how transactions work, and any relevant correspondence from your licensing or supervisory authority. For a group or a business with several branches, we also need the entity and branch structure.
Your management team confirms that the information reflects the business’s actual and planned activities. We assess that information against the applicable requirements and explain our conclusions.
This is a fixed-scope engagement covering the entities, jurisdictions and activities agreed at the outset. Registration submissions and implementation support can be included in a subsequent agreed scope.
Unsure which AML requirements apply to your business?
Share your licence and a brief description of your activities with AML UAE. We will help you establish the scope of review and the information needed to get started.
What Information Do We Need From You?
- Trade or commercial licence, activities, and supervisor
- Ownership and control structure and beneficial ownership information
- Customer, product, channel, and geography profile
- Current organisation chart and the person you have in mind for the role, if any
- Existing policies, registers, and systems
- Any inspection findings, letters of concern, or deadlines
Why AML UAE: Setup Experience You Can Verify
We are an AML consulting firm working only on AML/CFT compliance in the UAE, and building working compliance functions is where our delivery numbers come from:
300+
successful AML compliance projects across FIs, DNFBPs, and VASPs
1,000+
EWRA and AML/CFT/CPF policies and procedures delivered to UAE reporting entities
750+
professionals trained, across 3,000+ hours of AML/CFT/CPF training
500+
published articles, guides, and educational resources, including our widely read analyses of FDL No. 10 of 2025 and Cabinet Resolution No. 134 of 2025
The results show in delivery: Our delivery experience includes establishing governance and AML/CFT/CPF frameworks for financial institutions, DNFBPs and VASPs; supporting goAML and sector-reporting readiness; and delivering role-based training across operational and management teams.
In one VASP engagement, the agreed governance, risk-assessment, policy, screening and audit-readiness deliverables were implemented within four weeks. In a real estate engagement, we established the REAR reporting workflow and trained more than 650 agents to identify and escalate relevant transactions and suspicions.
Engagement outcomes depend on the client’s starting position, responsiveness, business complexity, regulator and scope. AML UAE does not guarantee regulatory approval or certify that an entity is fully compliant merely because the implementation deliverables have been completed.
The AML Compliance Specialists Who Build Your Department

Pathik Shah
CAMS, FCA, CS, CISA, DISA (ICAI), FAFP (ICAI)
Experience
28+ years
Regulatory Coverage
MoET, MoJ, CBUAE, CMA, FSRA, DFSA, VARA · AML/CFT framework design, RegTech

Jyoti Maheshwari
CAMS, ACA
Experience
11+ years
Regulatory Coverage
MoET, MoJ, CBUAE, CMA, FSRA, DFSA, VARA · AML/CFT/CPF framework, health checks

Dipali Vora
CAMS, ACS
Experience
10+ years
Regulatory Coverage
MoET, MoJ, CBUAE, CMA, FSRA, DFSA, VARA · Consulting, training, implementation

Monika Shah
CAMS
Experience
3+ years
Regulatory Coverage
MoET, MoJ, CBUAE, CMA, FSRA, DFSA, VARA · managed KYC, consulting, goAML reporting
Every framework carries a named reviewer and a review date, and passes an independent quality review before it reaches you. We are also straight about scope: what your department must contain depends on your licence, your activities, and your risk profile, and we will tell you plainly what you need and what you do not. And we stay engaged after handover: training refreshers, health checks, annual reviews, and realignment when the law or your business changes.
Setup Engagements Across UAE Frameworks
Three snapshots of what the service looks like in practice:
A virtual asset service provider preparing for supervision
The business needed a compliance function that could stand in front of its regulator before launch. We designed the governance structure, supported the compliance officer appointment, completed goAML registration, and delivered the EWRA, policy framework, and screening workflows. Within four weeks, the client had implemented the agreed governance, EWRA, policy, screening and reporting-readiness deliverables and was prepared for the next stage of its regulatory and independent-review process.
A real estate group scaling its reporting obligations
With REAR reporting arriving for the sector, the group needed the obligation to reach every branch, not just head office. We built the reporting workflow, set up the registers, and trained more than 650 agents so front-line staff knew when and how to raise internal alerts, giving the compliance officer a pipeline instead of a blind spot.
A small MoET-supervised DNFBP appointing its first officer
A single-officer function, sized honestly for a small business: one approved compliance officer with a written appointment, an escalation route the owners cannot override, a proportionate framework under Article 5(2)(b), and a compliance calendar that tells one person exactly what is due and when. Proportionate is not the same as informal, and the paper trail proves it.
FAQs on AML Compliance Department Setup in the UAE
An in-house AML compliance department is the internal function responsible for operating an organisation’s AML/CFT/CPF programme. It ordinarily includes an appointed compliance officer or MLRO, senior management oversight, defined reporting lines, goAML access, policies, risk assessments, registers, screening, monitoring and reporting procedures. UAE law requires an effective and proportionate compliance function, but it does not require every regulated entity to maintain a separately staffed department.
Yes. Every financial institution, DNFBP, and VASP in scope of Cabinet Resolution No. 134 of 2025 must appoint a compliance officer at management level with independence in decision-making and appropriate competence [Cabinet Resolution No. 134 of 2025, Article 22]. Operating without one is independently punishable, and for DNFBPs the failure appears in the administrative penalty schedule under Cabinet Resolution No. 71 of 2024.
The individual must satisfy the competence, experience, seniority, independence, authority, access and fit-and-proper requirements imposed by the applicable legal and supervisory framework. MoET-supervised DNFBPs must obtain prior written approval. Where a suitably qualified and independent internal officer cannot be appointed, MoET guidance permits a third-party compliance officer subject to prescribed conditions. Other regulators may impose different requirements, including full-time employment, UAE residency or separate regulatory approval.
Under the federal framework, the compliance officer owns the AML/CFT/CPF programme and the reporting decisions [Cabinet Resolution No. 134 of 2025, Article 22]. In the DIFC, the DFSA AML Module uses a dedicated MLRO regime for Relevant Persons, and in the ADGM the FSRA AML Rulebook sets its own MLRO requirements. In many mainland businesses one person holds both responsibilities; in the financial free zones the MLRO is a defined regulatory role with its own approval process.
The answer depends on the entity’s regulator. MoET guidance permits a DNFBP that cannot appoint a suitably qualified and independent internal compliance officer to appoint a third-party compliance officer, subject to prior written approval and safeguards relating to competence, fitness and propriety, independence, access, contractual responsibilities and continuing senior management accountability. Other regulators may require the officer to be an employee or may restrict outsourcing. Supporting activities may also be outsourced, but responsibilities and decisions that must remain with the appointed officer cannot be transferred without regulatory authority.
Approval requirements depend on the applicable supervisory framework. MoET-supervised DNFBPs must obtain prior written approval for the appointment. DFSA, FSRA, VARA and other regulators apply their own registration, approval, competence, residency or employment requirements. The appointment conditions should therefore be confirmed against the entity’s licence, activities and supervisory authority before the person begins performing the role.
goAML is the UAE Financial Intelligence Unit’s portal for suspicious transaction reporting and related filings. Registration is mandatory for reporting entities, and your compliance department cannot file an STR, SAR, or sector report without it. We handle the registration, build the internal escalation workflow that feeds it, and set up the reporting registers your inspector will ask to see.
Most organisations reach an operational baseline within 2 to 6 weeks, depending on readiness and complexity. Governance design and the compliance officer appointment typically land in the first two weeks, goAML registration and the framework build follow, and training and handover close the engagement.
Suspicious transaction and activity reports (STR, SAR) through goAML, plus the filings your sector requires: REAR for real estate, DPMSR for dealers in precious metals and stones, and funds-related and high-risk-country reports (CNMR, PNMR, HRC, HRCA) where applicable. The department also owes periodic internal reporting to senior management on the programme’s operation.
A single compliance officer may operate the function in a smaller entity where this is proportionate to the nature, size, complexity and ML/TF/PF risk of the business. The appointment must still be formally documented, adequately resourced and independent, and the officer must have sufficient authority and access. Where the individual holds another role, conflicts of interest and segregation-of-duties risks must be identified and appropriately controlled.
Yes. DIFC entities must consider the DFSA AML Module, while ADGM entities must consider the applicable FSRA AML Rulebook or Registration Authority framework. These regimes contain their own requirements concerning the MLRO, approval, reporting lines, independence, regulatory reporting and annual AML returns. The precise requirements depend on the entity’s regulated status, activities and permissions.
CDD records, transaction records, reports, and supporting analysis for at least five years from the completion of a transaction or the end of the business relationship, retrievable promptly on request (Cabinet Resolution No. 134 of 2025, Article 25), with beneficial ownership records updated within fifteen working days of any change.
Get the function right the first time.
One short form, one focused conversation, and a clear plan for the compliance department your business needs. A CAMS-certified specialist will come back with the scope, the timeline, and the price.