AML Regulatory Reporting Services

AML regulatory reporting is the set of filings a reporting entity must submit to the UAE Financial Intelligence Unit through the goAML portal, and to other authorities as required by law. It covers suspicious transaction and activity reports, sector reports such as the Real Estate Activity Report (REAR) and the Dealers in Precious Metals and Stones Report (DPMSR), high-risk country reports, and confirmed and partial name match reports. Reporting a suspicion is a legal duty, not a discretion [Federal Decree-Law No. 10 of 2025, Article 18], and the duty falls on your compliance officer personally as much as on the business. 

Reporting is where AML compliance becomes irreversible. Every other control can be improved quietly over time. A report is filed or it is not, on a date that is recorded, in a format that is either correct or rejected, with a narrative that either explains the suspicion or does not. It is also the one obligation where doing it late, using the wrong report type, or telling the customer you have done it each creates a separate problem.

Key takeaways

  • Reporting to the UAE FIU runs through the goAML portal, and you must complete registration before filing any report. 
  • There are three families of reports, not one. Suspicion-based: the Suspicious Transaction Report (STR) and Suspicious Activity Report (SAR). Threshold and activity-based: DPMSR, REAR, and the High-Risk Country Transaction Report (HRC) and High-Risk Country Activity Report (HRCA). Sanctions-driven: the Partial Name Match Report (PNMR) and Confirmed Name Match Report (CNMR). Firms that only file the first family are under-reporting. 
  • The duty to report a suspicion is a legal obligation, not a discretion, and it sits with a named compliance officer who cannot delegate the decision. 
  • A high-risk country transaction reported to the FIU may be held for three working days, which is a business timing constraint as much as a compliance one. 
  • Reporting in good faith carries statutory immunity, and secrecy or confidentiality cannot be invoked as a reason not to report. 
  • Tipping off is absolute and is most often breached by front-line staff explaining a delay. 

Filed correctly, on time, first time

Get goAML registration, report drafting, and filing support from specialists who submit these every week.

What Is AML Regulatory Reporting?

In the UAE it means reporting to the FIU through goAML, an application developed by the United Nations Office on Drugs and Crime and used as the communication channel between reporting entities and the FIU. The reports fall into three broad families, and firms that understand only the first are usually under-reporting:

STR and SAR, filed when you suspect proceeds of crime, money laundering, terrorism financing, or related activity. Judgement-driven, narrative-heavy, and the family everyone knows about.

[Cabinet Decision No. 74 of 2020]

 DPMSR, REAR, HRC, and HRCA, filed because a transaction or activity meets defined criteria, whether or not you are suspicious of anything. A dealer in precious metals filing a DPMSR is not accusing the customer of anything.

[Cabinet Resolution No. 134 of 2025, Article 16]

PNMR and CNMR, filed in connection with name matches against the UN Consolidated List and the UAE Local Terrorist List and any freezing measures applied.

The distinction matters commercially as well as legally. Firms that treat reporting as an occasional emergency, triggered only when something looks wrong, miss the entire second family, and the second family is where inspectors find omissions because those reports are mandatory and countable.

AML Reporting vs Financial and Statutory Reporting

Worth separating early, because regulatory reporting means two unrelated things in the UAE market. Prudential and statistical reporting is submitting financial and risk returns to the Central Bank or another supervisor, and it is largely a data and systems exercise with a substantial software market attached. Statutory reporting means annual accounts and filings. Management information reporting is internal. This page offers none of those.

AML regulatory reporting is a compliance obligation about specific customers, transactions, and suspicions, filed with the FIU, triggered by AML law. If you are looking for a prudential returns platform or a statutory audit filing service, an accounting firm or a reporting software vendor is the right destination and we will say so on the call rather than after the engagement letter.

goAML Registration for Reporting Entities

Registration comes before any report, and it is the point where firms most often stall. The entity creates an account on the goAML portal and submits its trade licence, supervisory authority, and compliance officer details. The FIU validates the registration against the relevant regulator’s records, which is why a mismatch between your licence data and your regulator’s record stops the process. Once approved, the compliance officer becomes the primary user and can add delegate users to draft and submit reports. 

Two practical points that cause more delay than anything technical. The named compliance officer must be the person actually appointed, so registration often exposes an appointment that was never formalised [Cabinet Resolution No. 134 of 2025, Article 22]. The goAML Message Board is the FIU’s channel for acceptance and rejection notices and requests for additional information, which means an unmonitored Message Board is an unanswered regulator. If you are registering yourself and want the screen-by-screen detail, our goAML registration guide walks through it; this page is about what happens once you are registered and have a report to file. 

Registration stalled, or never completed?

Send us your licence details and current registration status and we will tell you what is blocking it, with no obligation.

UAE goAML Report Types Explained

The full set of report types, what each is for, and when it applies. Selecting the wrong type is treated as a filing deficiency, so this table is worth keeping. If you would rather watch than read, we have the goAML report types explained on video, which is the version to send a team that is being trained on this for the first time:

Report Full Name When It Applies
STR Suspicious Transaction Report A transaction or attempted transaction is suspected of involving proceeds of crime, money laundering, or terrorism financing. The trigger is a transaction.
SAR Suspicious Activity Report Suspicious behaviour, conduct, or a pattern not tied to a specific transaction. The trigger is activity without a transaction, which is why refusing to onboard a customer can still require a report.
DPMSR Dealers in Precious Metals and Stones Report A dealer conducts a transaction at or above AED 55,000 in cash with individuals or corporates, or by wire transfer with corporates. Mandatory on threshold, regardless of suspicion.
REAR Real Estate Activity Report Purchase or sale of freehold property where payment for any part of the value is physical cash of AED 55,000 or more, a virtual asset, or funds converted from or to a virtual asset. Driven by the transaction rather than by suspicion, which is why brokerages often under-report.
HRC High-Risk Country Transaction Report A transaction connected to a jurisdiction on the high-risk list maintained by the National Committee. Carries a waiting period, covered below.
HRCA High-Risk Country Activity Report Activity, rather than a specific transaction, connected to a high-risk jurisdiction.
PNMR Partial Name Match Report A partial match against a designated name, where identity is not confirmed. Filed by FIs, DNFBPs, and VASPs.
CNMR Confirmed Name Match Report A confirmed match against a designated name, alongside the freezing action taken.
AIF and AIFT Additional Information File, without and with transactions Filed in response to an FIU request for further information through the Message Board, with AIFT used where transactions are included.
RFI and RFIT Request for Information, without and with transactions The response format where the FIU requests information, again distinguished by whether transactions are attached.

The distinction most often got wrong : STR and SAR are used interchangeably in conversation, and goAML treats them as different report types with different triggers. A transaction points to an STR. Activity without a transaction points to a SAR.

When Must You File an STR or SAR?

As soon as practicable once suspicion arises, and the word suspicion carries a lower threshold than firms assume. You do not need evidence, certainty, or a completed internal investigation. You need a suspicion you cannot dispel, and the duty to report it is imposed by law [Federal Decree-Law No. 10 of 2025, Article 18].

Three situations that generate reports and are frequently missed:

Attempted transactions

A transaction you declined is still reportable. The customer who withdrew when asked for source of funds is often the strongest report you will file that year.

Refused onboarding

Declining a customer for AML reasons does not end the obligation. If suspicion arose, activity was suspicious even though no transaction occurred, which is what a SAR is for.

Exiting a relationship

Offboarding an existing customer on AML grounds carries the same logic, and the file should show the report as well as the exit.

The decision not to file is also reviewable. The FIU and external auditors examine decisions not to report as well as reports made, so a documented rationale for concluding that suspicion was dispelled belongs in the record rather than in an optional note.

Three situations that generate reports and are frequently missed:

UAE AML Laws Behind Regulatory Reporting

The full set of report types, what each is for, and when it applies. Selecting the wrong type is treated as a filing deficiency, so this table is worth keeping. If you would rather watch than read, we have the goAML report types explained on video, which is the version to send a team that is being trained on this for the first time:

Legal Instrument Legal Instrument How It Shapes the Filing
Federal Decree-Law No. 10 of 2025, Article 18 The obligation to report suspicious transactions to the Financial Intelligence Unit, read together with Articles 17 to 19 of Cabinet Resolution No. 134 of 2025, which carry the reporting obligation, the report content and process, and the tipping-off prohibition. The statute, issued 30 September 2025 and in force two weeks after publication in the Official Gazette, repealing FDL No. 20 of 2018 (Article 41), with administrative penalties of AED 10,000 to AED 5,000,000 per violation (Article 17) and criminal penalties in Chapter Twelve (Articles 25 to 36), of which two bear directly on reporting: Article 28, the penalty for breaching the Article 18 reporting duty, and Article 29, tipping off. The core duty. Also the reason legacy internal reporting procedures need review: escalation frameworks written under the 2018 law do not automatically reflect the current one, including the standalone proliferation financing offence.
Cabinet Resolution No. 134 of 2025, Article 19 Reporting procedures and the prohibition on tipping off, meaning the customer must not be informed that a report has been or will be made. Filing is only half the obligation. Confidentiality of the report, and the handling of the relationship afterwards, is the half that creates personal exposure for staff.
Cabinet Resolution No. 134 of 2025, Article 22 The compliance officer at management level with independence in decision-making and appropriate competence, subject to supervisory approval for DNFBPs. The reporting decision belongs to a named person, not to a committee, a system, or a consultant. We prepare the analysis; your officer decides and files.
Cabinet Resolution No. 134 of 2025, Articles 6 to 10 and 16 CDD and verification, the AED 55,000 and AED 3,500 thresholds, beneficial ownership to the 25% standard, and PEP identification. The content of the report. Incomplete beneficial ownership data is one of the most common reasons a report is rejected, which makes CDD quality a reporting problem as well as an onboarding one.
Cabinet Resolution No. 134 of 2025, Article 23 Countermeasures and enhanced measures for high-risk countries, with the list maintained by the National Committee. Drives HRC and HRCA reporting, including the waiting period before a reported transaction may be executed.
Cabinet Resolution No. 74 of 2020 Targeted financial sanctions: screening against the UN Consolidated List and the UAE Local Terrorist List, and freezing without delay on a confirmed match. Drives PNMR and CNMR filings. Screening and freezing sit upstream of the report, so a firm whose screening is weak will not generate the reports in the first place, whatever its filing process looks like.
Cabinet Resolution No. 134 of 2025, Article 25 Record keeping with prompt retrieval on request. Reports, internal escalation notes, the decision rationale, and the underlying CDD file are all part of the record, and they must be producible together.
Cabinet Resolution No. 71 of 2024 and sectoral guidance The DNFBP penalty schedule (41 listed violations, AED 50,000 to AED 1,000,000, doubling on recurrence within a year), MoET Guidelines for DNFBPs (September 2025), and the DFSA and FSRA rulebooks, with the DFSA additionally requiring an annual AML return for DIFC firms. The consequences of failure, and the additional periodic filings that free zone entities owe on top of the federal obligations.

High-Risk Country Reporting: HRC, HRCA and the Waiting Period

High-risk country reporting carries an operational constraint that surprises firms and has real commercial consequences. When a transaction connected to a listed high-risk jurisdiction is reported to the FIU, the FIU’s published guidance indicates the transaction may be executed only after three working days from reporting, and only if the FIU does not object. 

Read that as a business constraint rather than a compliance footnote. It means a payment your customer expects to clear today may not clear for three working days. Firms that discover this rule at the moment they need it handle it badly. Firms that have planned for it build the delay into their process and their customer communications in advance. 

The high-risk jurisdictions list is maintained by the National Anti-Money Laundering and Combating the Financing of Terrorism and Financing of Illegal Organisations Committee, and it changes. A control that checks it periodically is worth more than a list copied into a procedure two years ago. 

Name Match Reporting: PNMR and CNMR

Sanctions-driven reporting runs on a different clock from suspicion-based reporting. A name match is not something you investigate at your convenience, because the underlying obligation is to freeze without delay [Cabinet Resolution No. 74 of 2020].

Filed where a match against a designated name is partial, and identity is not confirmed. Prompt filing allows the FIU to help resolve it. 

Confirmed Name Match Report (CNMR)

 Filed where the match is confirmed, alongside the action taken. 

One operational point that catches firms out. Freezing decisions often arise outside business hours, so a process that depends on one person being reachable will fail. 

A prior question sits underneath all of this. These reports only get raised if your screening produces the match in the first place, and a screening tool that has never been tested against known designated names is an assumption rather than a control. That is screening testing and validation work rather than reporting work, and it is worth settling before you judge your filing volumes. 

Sector Reports: REAR for Real Estate and DPMSR for Precious Metals

The recurring failure is architectural rather than deliberate: head office understands the obligation, branches generate the transactions, and nothing connects the two. 

For both, the compliance question is rarely whether the team knows the rule. It is whether the reporting trigger is wired into the transaction process, so a qualifying deal cannot complete without raising the report. We build that workflow into the engagement rather than relying on staff to remember.

DPMSR

Dealers in precious metals and stones report transactions at or above AED 55,000 in cash with individuals or corporates, or by wire transfer with corporates, with identification documents, whether or not anything about the transaction is suspicious. A dealer with regular high-value trade owes a stream of these, and a dealer filing none is making a statement about either their business or their compliance. 

REAR

Real estate brokers and agents report a purchase or sale of freehold property where payment for a portion or the entire property value is made in any of three ways: physical cash of AED 55,000 or more, whether in a single transaction or several; a virtual asset; or funds converted from or to a virtual asset. The last two carry no threshold, so a part-payment in crypto is reportable at any value. Identification documents for the buyer and seller must be obtained and retained with the filing. Note the contrast with the DPMSR: the same AED 55,000 figure, but the DPMSR trigger covers both cash and wire transfer while the REAR cash trigger is physical cash only. 

Tipping Off: What You Cannot Do After Filing

Once a report is made or is being contemplated, you must not disclose that fact to the customer or to any third party [Cabinet Resolution No. 134 of 2025, Article 19]. This is absolute, and it is the obligation most likely to be breached by someone acting in good faith. 

What tipping off looks like in practice, and none of these is hypothetical: 

Which is why reporting training has to reach front-line staff rather than stopping with the compliance team. The person most likely to tip off is not the officer who filed the report. It is the colleague who wants to help a customer they like. 

The protections that make filing safe are protections firms hesitating over a report rarely know they have. Reporting in good faith carries statutory immunity, so a report made honestly does not expose the reporter or the entity to liability even if the suspicion turns out to be unfounded [Federal Decree-Law No. 10 of 2025, Article 37]. And bank secrecy, professional secrecy, and contractual confidentiality cannot be invoked as a reason to withhold information or to decline to report [Cabinet Resolution No. 134 of 2025, Article 42]. 

Those two provisions address the objection we hear most often: a partner or relationship owner arguing that filing breaches a duty to the client. It does not, and the law says so directly.

Why goAML Reports Get Rejected

A rejected report is not a filed report, and the clock does not stop while you correct it. The recurring rejection reasons are consistent enough to be treated as a checklist:

Missing identifiers

Incomplete identification data on the subject, which usually reflects a CDD gap rather than a data entry error.

The natural persons behind an entity are absent or unverified, which is the same weakness that shows up in file reviews. 

Weak suspicion narratives

The reason-for-reporting section describes what happened without explaining why it is suspicious. A narrative that could apply to a thousand ordinary customers tells the FIU nothing.

Incorrect report type

STR selected where SAR applies, or a sector report filed as a suspicion report, which the FIU must reclassify.

Schema errors

Technical validation failures on format, mandatory fields, or structure, particularly on XML submissions. 

The narrative is where we spend most of our drafting time, because it is the part a person reads. A good narrative states what was expected of this customer, what actually happened, why the difference matters, and what you did about it, in that order, in language an analyst who has never met your business can follow. Before you submit, our STR and SAR filing checklist covers the field-level checks, and our goAML readiness checklist tests whether your wider setup will hold up across a year of filings rather than a single report.

AML Assurance Reporting Services in the UAE

Distinct from filing reports to the FIU, and often confused with it. Assurance reporting means reporting on the state of your AML programme: periodic reporting from the compliance officer to senior management, independent audit outputs, and the reporting packs a supervisor, an auditor, a bank, or a group parent asks for. 

The compliance officer’s periodic report to senior management has a legal dimension, since senior management cannot exercise the oversight the framework requires without it, and its absence is visible in minutes. We prepare these in a structure that shows what changed, what was reported, what was found, and what remains open, rather than a volume count that tells the board nothing it can act on.

Our AML Regulatory Reporting Services

VASP Regulatory Reporting in the UAE

Virtual asset service providers carry the same core reporting obligations as other reporting entities, filed through goAML, with additional considerations that change how the process runs rather than what is owed.

  • Speed. Transactions settle faster than an escalation chain designed for banking timelines, so the internal route from analyst to reporting decision has to be short and rehearsed. 
  • Counterparty and chain data. Report narratives increasingly need to explain on-chain context in terms an analyst can follow, which is as much a drafting skill as an analytical one. 
  • Travel Rule information. Originator and beneficiary data quality affects both your screening and the completeness of any report you file. 
  • Supervisor. VARA in Dubai or the relevant federal authority elsewhere, which affects registration validation and the guidance that applies to you. [Cabinet Resolution No. 134 of 2025, Article 4] 

goAML registration and user administration

Registration, validation issues resolved with your supervisor, primary and delegate user setup, and Message Board monitoring. 

Reporting workflow design

 Internal escalation routes, decision trees for report type selection, decision logs, and the registers that evidence the process. 

Report drafting and quality review

STR and SAR narratives drafted or reviewed before submission, with the identification and beneficial ownership data checked against the rejection reasons above. 

Threshold and sector report support

 DPMSR, REAR, HRC, and HRCA workflows wired into the transaction process so qualifying activity cannot pass unreported. 

Sanctions reporting

PNMR and CNMR handling and the freeze protocol. [Cabinet Resolution No. 74 of 2020] 

FIU correspondence

AIF, AIFT, RFI, and RFIT responses, prepared to the same standard as the original report.

Assurance reporting

Compliance officer reporting to senior management and the packs supervisors, auditors, and banks request. 

Training

Reporting and tipping-off training for the front line, not only the compliance team. [Cabinet Resolution No. 134 of 2025, Article 21] 

How We Support a goAML Filing, Step by Step

Escalation received

An internal alert or a query from your team reaches us with the underlying file. 

Analysis

We review the transaction and customer, confirm beneficial ownership, check screening results, and test the suspicion against what we would normally expect of this customer. 

Report type selection

STR, SAR, or a threshold or sanctions report, with the reasoning recorded so you can defend the choice.

Narrative drafting

Written to be read by an analyst with no knowledge of your business, stating expectation, deviation, significance, and action.

Data completeness check

Identifiers, beneficial ownership, and mandatory fields verified against the common rejection reasons before submission. 

Officer review and decision

Your compliance officer makes the reporting decision and submits it, because the law assigns it to them. [Cabinet Resolution No. 134 of 2025, Article 22] 

Submission and Message Board monitoring

Track acceptance or rejection, make corrections, and resubmit promptly where needed. 

Record and follow-up

Retain the report, escalation notes, decision rationale, and CDD file together and make them retrievable, and handle any FIU follow-up. [Cabinet Resolution No. 134 of 2025, Article 25] 

Regulatory Reporting Services: What You Receive

Deliverable

What It Does

goAML registration completed

Entity registered, validation issues resolved, primary and delegate users configured 

Reporting procedure and decision tree

Which report type applies to which trigger, documented so the choice is consistent and reviewable 

Internal escalation workflow

The route from front-line concern to compliance officer decision, with the decision log that evidences it 

Drafted or reviewed reports

Narratives written to survive FIU review, with data completeness checked before submission 

Sector reporting workflow

DPMSR, REAR, HRC and HRCA triggers wired into the transaction process rather than left to memory 

Reporting registers

STR, SAR, and sector report logs, plus the record of decisions not to report and the reasoning

Senior management reporting pack

Periodic assurance reporting that supports the oversight the framework expects 

Reporting and tipping-off training

Delivered to the people who will be asked the awkward question by a customer 

Have a filing decision in front of you now?

Tell us the situation and we will help you work out what needs to be filed and by when

Regulatory Reporting Software or Reporting Support?

A large share of regulatory reporting searches are for software: platforms that generate returns, validate schemas, and submit files. It is worth being clear about what software solves here and what it does not.

Software helps with format and volume

Schema validation, XML generation, submission, and record retention, all of which matter if you file at scale.

It does not decide whether to report

That is a judgement the law assigns to your compliance officer, and it carries consequences.

It does not write the narrative

The reason-for-reporting section is where reports succeed or fail, and no system can explain why a customer’s behaviour departed from what you expected.

If you want to understand what reporting software does and where it fits, our regulatory reporting software page covers the category. If you are evaluating reporting or AML platforms, our AML software selection service runs it as a structured process. If you have a system and want to know whether it is working, our testing and validation service covers that. If you need reports filed correctly, this is the page for you.

Who Must Report in the UAE?

Financial institutions

Banks, exchange houses, finance companies, insurers, and payment providers, supervised by the CBUAE, with capital market firms under the CMA, and companies supervised by FSRA and DFSA. 

[Cabinet Resolution No. 134 of 2025, Article 2]

DNFBPs

Dealers in precious metals and stones, real estate brokers and agents, auditors and accountants, lawyers and notaries, corporate service providers, and commercial gaming operators.

[Cabinet Resolution No. 134 of 2025, Article 3] 

VASPs

Virtual asset service providers, supervised by VARA in Dubai or the relevant federal authority elsewhere.

[Cabinet Resolution No. 134 of 2025, Article 4]

All three categories register on goAML and file according to their licence and activities. Insurers and insurance intermediaries sit within the financial institution category and are frequently under-registered relative to their obligations, which is a common finding in that sector.

Penalties for Failure to Report in the UAE

Failure to report attracts consequences on four separate tracks, and they run in parallel rather than as alternatives. An entity can face an administrative fine, a criminal charge against a named individual, a sectoral penalty from its own supervisor, and a quality finding on the reports it did file.

Administrative penalties

AED 10,000 to AED 5,000,000 per violation, plus warnings, licence restrictions, and public naming. Failure to register on goAML is punishable independently of whether any report was ever due.

[Federal Decree-Law No. 10 of 2025, Article 17]

Criminal exposure

The statute includes criminal provisions, and failure to report a suspicion or tipping off is among the areas where personal liability is most real for the individuals involved; each has its own provision.

[Federal Decree-Law No. 10 of 2025, Article 28 (failure to report) and Article 29 (tipping off), within Chapter Twelve, Articles 25 to 36]

The DNFBP penalty schedule.

41 listed violations at AED 50,000 to AED 1,000,000 for MoET- and MoJ-supervised businesses, doubling if the same violation recurs within one year. 

[Cabinet Resolution No. 71 of 2024]

Quality as well as quantity

Reports filed late, in the wrong type, or with narratives that cannot be assessed are recorded against your entity, so a firm that files diligently but poorly is not in the clear. If you are not sure which of these you are exposed to, an AML/CFT health check is a cheaper way to find out than an inspection. 

Choosing Regulatory Reporting Services in the UAE

Since the phrase covers everything from software resale to genuine filing support, these are the questions worth asking any provider:

  • Who makes the reporting decision? If a provider offers to decide for you, they are offering something the law assigns to your compliance officer. [Cabinet Resolution No. 134 of 2025, Article 22] 
  • Do you draft narratives, or only submit forms? Submission is mechanical. Narrative drafting is where reports are accepted or rejected. 
  • How do you handle report type selection? A provider without a documented decision tree is guessing, and incorrect type selection is a recorded quality issue. 
  • What happens when a report is rejected? Correction and resubmission speed matters, since the obligation is not discharged until the report is accepted. 
  • Who monitors the Message Board? An unanswered FIU request is worse than a late report. 

Why AML UAE for AML Regulatory Reporting

Reporting rewards repetition, because the difference between an accepted report and a rejected one is largely craft:

300+

AML compliance projects across FIs, DNFBPs, and VASPs, which is where our narrative drafting and rejection-avoidance patterns come from

1000+

EWRA and AML/CFT/CPF policy sets delivered, so the escalation procedures we design connect to a framework rather than sitting beside one

750+

professionals trained across 3,000+ hours, including the front-line reporting and tipping-off training that prevents the most damaging mistakes

Under 4 hours

typical turnaround on compliance queries during an engagement, which matters more here than on any other service, because reporting decisions do not wait

We also publish extensively on goAML, including registration guidance and reporting explainers, which is a reasonable proxy for whether a provider actually does this work or merely offers it.

The Reviewers Who Run Your Health Check

Pathik Shah

CAMS, FCA, CS, CISA, DISA (ICAI), FAFP (ICAI)

Experience

28+ years

Regulatory Coverage

MoET, MoJ, CBUAE, CMA, FSRA, DFSA, VARA · AML/CFT framework design, RegTech

Jyoti Maheshwari

CAMS, ACA

Experience

11+ years

Regulatory Coverage

MoET, MoJ, CBUAE, CMA, FSRA, DFSA, VARA · AML/CFT/CPF framework, health checks

Dipali Vora

CAMS, ACS

Experience

10+ years

Regulatory Coverage

MoET, MoJ, CBUAE, CMA, FSRA, DFSA, VARA · Consulting, training, implementation

Monika Shah

CAMS

Experience

3+ years

Regulatory Coverage

MoET, MoJ, CBUAE, CMA, FSRA, DFSA, VARA · managed KYC, consulting, goAML reporting

FAQs on AML Regulatory Reporting in the UAE

It is the set of filings a reporting entity must submit to the UAE Financial Intelligence Unit through the goAML portal, and to other authorities as required by law. It covers suspicion-based reports (STR and SAR), threshold and activity reports (DPMSR, REAR, HRC, HRCA), and sanctions-driven reports (PNMR, CNMR). The duty to report a suspicion is imposed by law [Federal Decree-Law No. 10 of 2025, Article 18]. 

goAML is the reporting platform used by the UAE Financial Intelligence Unit, originally developed by the United Nations Office on Drugs and Crime. It is the channel through which reporting entities register, submit reports, and communicate with the FIU, including through the Message Board where acceptances, rejections, and requests for further information appear. 

Financial institutions, DNFBPs, and virtual asset service providers, as defined in the Executive Regulations [Cabinet Resolution No. 134 of 2025, Articles 2 to 4]. Registration requires trade licence and supervisory authority details plus the compliance officer’s information, and the FIU validates it against your regulator’s records, which is why licence data mismatches are the most common cause of delay. 

An STR, suspicious transaction report, is filed when a transaction or attempted transaction triggers it. A SAR, suspicious activity report, is filed when suspicious behaviour or a pattern triggers it and no specific transaction is involved. Practitioners use the terms interchangeably in conversation, and goAML treats them as distinct report types. Selecting the wrong one forces the FIU to reclassify it and is recorded as a quality issue against your entity. If you need to settle this for a team, our side-by-side on the difference between an STR and a SAR sets out the triggers and the borderline cases.

As soon as practicable once suspicion arises. You do not need proof or a completed investigation, only a suspicion you cannot dispel [Federal Decree-Law No. 10 of 2025, Article 18]. Attempted transactions, refused onboarding, and AML-driven exits are all reportable even though no completed transaction exists. Decisions not to report are also reviewable, so the rationale belongs in the record. 

A Dealers in Precious Metals and Stones Report, filed by a dealer for transactions at or above AED 55,000 in cash with individuals or corporates, or by wire transfer with corporates, together with identification documents. It is a threshold report rather than a suspicion report, so it is filed regardless of whether anything about the transaction appears suspicious. 

Real Estate Activity Report, filed by real estate brokers and agents on a purchase or sale of freehold property where payment for a portion or the entire value is made in physical cash of AED 55,000 or more, in a single transaction or several, or in a virtual asset, or with funds converted from or to a virtual asset. The two virtual asset triggers carry no threshold. Like the DPMSR, it is transaction-driven rather than suspicion-driven. The common failure is architectural: head office understands the obligation while branches generate the transactions, with nothing connecting the two. 

High-Risk Country Transaction and High-Risk Country Activity reports, filed in connection with jurisdictions on the high-risk list maintained by the National Committee. The FIU’s guidance indicates a reported high-risk country transaction may be executed only after three working days from reporting and if the FIU does not object, making this a business timing constraint as well as a compliance obligation. 

Partial Name Match Report and Confirmed Name Match Report. They arise from screening against the UN Consolidated List and the UAE Local Terrorist List: a partial match that cannot be confirmed, and a confirmed match together with the freezing measures applied. Financial institutions, DNFBPs, and VASPs must file them [Cabinet Resolution No. 74 of 2020]. 

Disclosing to the customer or any third party that a report has been made or is being contemplated [Cabinet Resolution No. 134 of 2025, Article 19]. It is absolute, and well-meaning staff often breach it by explaining a delay, warning a client that questions are being asked, or giving an AML reason for closing an account. That is why reporting training has to reach the front line, not stop with compliance. 

Common reasons include missing subject identifiers, incomplete beneficial ownership data, weak suspicion narratives that describe events without explaining why they are suspicious, selecting the wrong report type, and technical schema errors. You must correcand resubmit a rejected report, and the obligation is not discharged until it is accepted. 

We can support preparation, drafting, and workflow externally. The reporting decision cannot be transferred, because it is assigned to your appointed compliance officer at management level [Cabinet Resolution No. 134 of 2025, Article 22]. We prepare the analysis and the narrative to the point of decision; your officer decides and submits, and the record stays with you. 

Records must be retained and retrievable promptly on request [Cabinet Resolution No. 134 of 2025, Article 25], and in practice that means keeping the report itself together with the internal escalation notes, the decision rationale, and the underlying CDD file, since a report produced without its supporting file answers only half the question an inspector is asking. 

Yes. Free zone entities file to the FIU through goAML like everyone else and also follow their own rulebook. DIFC Relevant Persons under the DFSA AML Module have periodic obligations, including an annual AML return, and ADGM entities follow the FSRA AML Rulebook. Confirm the current filing calendar for your licence, since these are periodic rather than event-driven. 

Get the filing right the first time.

One short form, one focused conversation, and reporting support scoped to your licence. A CAMS-certified specialist will come back with the arrangement and price.