logo
CREDORA CONSULTANCY LLC
Trust | Transform | Thrive
Credora Consultancy LLC · UAE Compliance Advisory

AML/CFT Compliance Services in Dubai, UAE

AML Business Risk Assessment, AML Policies, KYC/CDD, Sanctions Screening, goAML , Training and Compliance Reviews

Credora provides AML compliance services in Dubai and across the UAE for DNFBPs and other regulated businesses that need to establish, update or review their anti-money laundering controls.

Our work can cover AML Business Risk Assessments, AML/CFT/CPF policies and procedures, KYC and customer due diligence, beneficial-owner checks, customer risk classification, Enhanced Due Diligence, PEP and sanctions controls, goAML procedures, staff training, independent compliance reviews and inspection preparation.

Not every UAE business has the same AML obligations. Your licensed activity, customer profile and regulatory authority determine which requirements apply.

AML Compliance Services for UAE Businesses

Credora provides AML compliance services for UAE businesses that need to meet AML/CFT/CPF requirements, prepare required compliance documents, improve existing AML controls or get ready for regulatory inspection.

A newly regulated business may need its risk assessment, AML policy, customer-risk methodology and compliance procedures developed from the beginning.

An established business may instead need an AML gap analysis, customer file review, policy update, independent AML review or compliance remediation before a regulatory inspection.

AML Compliance Setup and Documentation

  • AML/CFT/CPF policies and procedures
  • Business Risk Assessment (BRA)
  • KYC and KYB procedures
  • Customer Due Diligence (CDD) procedures
  • Enhanced Due Diligence (EDD) procedures
  • Customer risk assessment and classification

AML Screening and goAML Reporting

  • UBO and ownership verification procedures
  • PEP screening procedures
  • Sanctions and Targeted Financial Sanctions controls
  • goAML registration and reporting services
  • STR and SAR reporting procedures
  • Internal suspicious transaction escalation procedures

AML Compliance Review and Remediation

  • AML compliance review and gap analysis
  • Customer file and KYC review
  • Compliance Officer governance review
  • AML training for employees
  • Independent AML compliance reviews
  • AML inspection preparation and remediation services

The AML compliance scope should reflect the regulations, business activities and risk profile that apply to your company rather than a standard package used for every business.

Who Needs AML Compliance in the UAE?

UAE AML requirements apply to regulated categories including financial institutions, Designated Non-Financial Businesses and Professions (DNFBPs) and Virtual Asset Service Providers.

For businesses supervised by the Ministry of Economy and Tourism, the main DNFBP sectors include real estate brokers and agents, dealers in precious metals and stones, independent accountants and auditors, and company or trust service providers.

Legal professionals can also have AML obligations when carrying out activities covered by the applicable requirements for the legal profession.

Not every UAE company is automatically a DNFBP.

Whether DNFBP requirements apply depends on the activities and services the business actually performs.

Credora can review the trade licence, business activities and regulatory jurisdiction to identify the AML requirements that apply to the company.

Which AML Regulator Applies to Your Business?

UAE federal AML legislation applies across the country, while the supervisory authority depends on the company’s activity, licence and jurisdiction.

Business or Activity Typical Supervisory Authority
CBUAE-regulated financial institutions Central Bank of the UAE
Mainland and commercial Free Zone DNFBPs under MoET Ministry of Economy and Tourism
Lawyers and covered legal activities Ministry of Justice
DIFC Relevant Persons Dubai Financial Services Authority
Dubai VASPs outside the DIFC Virtual Assets Regulatory Authority

For DIFC firms, the DFSA’s updated AML and Glossary Modules came into force on 2 March 2026 following the introduction of the new UAE federal AML legislation.

VARA-licensed VASPs in Dubai are subject to VARA’s rules together with the applicable federal AML requirements.

Your licensed activity, jurisdiction and supervisory authority determine the AML requirements your business must follow.

UAE AML Law and Compliance Requirements

Federal Decree-Law No. 10 of 2025 replaced the previous federal AML legislation and is now the principal federal law addressing money laundering, terrorist financing and proliferation financing.

Cabinet Resolution No. 134 of 2025 contains the current Executive Regulations and sets out the AML requirements that regulated businesses must put into practice.

Risk and Customer Controls

  • Identification and assessment of financial-crime risk
  • Customer identification and verification
  • Beneficial-owner identification
  • Customer-risk classification
  • Enhanced Due Diligence for higher-risk relationships

AML Controls and Reporting

  • Suspicious transaction and activity reporting
  • Internal AML controls and procedures
  • Compliance Officer responsibilities
  • AML training for relevant employees
  • Record keeping and independent review of AML controls

An AML policy is only one part of compliance. The business also needs procedures, customer records, risk assessments and other evidence showing that its AML controls are being applied in practice.

AML Business Risk Assessment UAE

An AML Business Risk Assessment (BRA) identifies and evaluates the money laundering, terrorist financing and proliferation financing risks faced by a UAE business as a whole.

The assessment should reflect the company’s actual customers, services, transactions, geographic exposure and delivery methods. It should first identify the inherent risk the business faces before controls are applied, then consider the effectiveness of its AML controls to determine the remaining residual risk.

A Business Risk Assessment is different from a Customer Risk Assessment. The BRA considers financial-crime risk across the whole business, while customer risk assessment determines the level of risk presented by an individual customer or business relationship.

Customer Risk
Customer types, ownership structures, business activities, PEP exposure and other characteristics that can increase ML/TF/PF risk.

Geographic Risk
Countries connected with customers, beneficial owners, counterparties, transactions and the source or destination of funds.

Product and Service Risk
The extent to which the company’s products or services could be exposed to or misused for money laundering, terrorism financing or proliferation financing.

Transaction Risk
Cash transactions, third-party payments, unusual payment patterns, transaction complexity, value, frequency and other relevant financial activity.

Delivery-Channel Risk
Face-to-face and remote onboarding, online services, intermediaries, agents and other ways in which the company delivers its services.

The BRA should also consider relevant external information, including the UAE National Risk Assessment, applicable sector risk assessments, regulatory guidance and emerging financial-crime risks.

The final assessment should document the risk methodology, risk ratings, effectiveness of existing controls, residual risk and any additional controls required. The results should then feed into customer risk classification, due diligence, transaction monitoring and other AML procedures.

Management approval is part of the process. For Ministry-supervised DNFBPs, senior management must formally certify that the BRA reflects the company’s risk exposure, is supported by appropriate risk controls and is available for review by the supervisory authority.

How Often Should a DNFBP Update Its AML Business Risk Assessment?

For DNFBPs supervised by the Ministry of Economy and Tourism, the current guidance states that in most cases the Business Risk Assessment should be considered at least annually. The appropriate frequency can be higher or lower depending on the size, activities and risk exposure of the business.

The BRA must also be kept up to date when changes inside or outside the business could affect its financial-crime risk. A company should not wait for the next scheduled review when a significant change has already occurred.

When Should the BRA Be Reviewed?

  • changes to the company’s products or services;
  • entry into new countries or markets;
  • significant changes in customer types or transaction patterns;
  • new delivery channels, technologies or business practices;
  • changes in ownership, operations or business strategy;
  • new AML/CFT/CPF laws, regulatory requirements or supervisory guidance;
  • new money laundering, terrorism financing or proliferation financing risks relevant to the business; and
  • new findings from compliance reviews, audits or regulatory inspections.

The review should not simply change the date on the existing assessment. The company should check whether its risk factors, scoring, controls and residual risk still reflect how the business currently operates.

Credora can prepare a new AML Business Risk Assessment in the UAE or review an existing BRA against the company’s current activities, risk exposure and applicable DNFBP requirements.

AML/CFT/CPF Policy and Procedures UAE

An AML/CFT/CPF policy sets out how a UAE business identifies, assesses and manages its money laundering, terrorist financing and proliferation financing risks.

The policy should reflect the company’s licensed activities, customer types, transaction profile, geographic exposure and supervisory requirements. A policy written for a real estate brokerage, for example, should not simply be reused by a jewellery business, accounting firm or company service provider.

What Should an AML Policy Cover?

  • business and customer risk assessment procedures;
  • customer acceptance, KYC, CDD and Enhanced Due Diligence;
  • beneficial-owner, PEP and sanctions screening controls;
  • transaction monitoring and internal escalation procedures;
  • STR, SAR and goAML reporting responsibilities;
  • Compliance Officer responsibilities, staff training and record keeping; and
  • review, approval and updating of AML controls when the business or regulatory requirements change.

Credora can prepare an AML/CFT/CPF policy for a UAE business or review and update an existing AML manual where the company’s activities, risks or regulatory requirements have changed.

KYC, CDD and Enhanced Due Diligence (EDD) in the UAE

Customer Due Diligence (CDD) is the process of identifying the customer, verifying the information provided and assessing the money laundering, terrorist financing and proliferation financing risk of the relationship.

KYC should not stop once a passport, Emirates ID or trade licence has been collected. The business should understand who the customer is, who ultimately owns or controls the customer, why the relationship is being established and what type of activity is expected.

What Should Customer Due Diligence Cover?

  • identification and verification of the customer;
  • identification and verification of beneficial owners and controlling persons;
  • verification of anyone authorised to act on behalf of the customer;
  • the nature and purpose of the business relationship;
  • the customer’s business activities and ownership structure;
  • source of funds and, where relevant, source of wealth;
  • expected transaction type, value, frequency and geographic exposure;
  • customer risk classification and appropriate level of due diligence;
  • sanctions, PEP and adverse-media screening where applicable; and
  • ongoing monitoring and periodic updating of customer information.

For a corporate customer, the review can include the legal name, registration details, registered address, principal place of business, ownership structure, authorised signatories, directors or senior management, business activities and the countries in which the company operates or transacts.

The information collected should be used to build a customer risk profile. This allows the business to compare the customer’s actual transactions and behaviour with what was expected when the relationship began.

Customer information should also be reviewed during the relationship. A change in ownership, business activity, transaction pattern, geographic exposure, adverse media or other significant information can require the KYC file and customer risk rating to be reviewed before the next scheduled update.

Enhanced Due Diligence (EDD): Higher-risk customers require deeper checks. Depending on the risk, this can include additional customer and UBO verification, source-of-funds and source-of-wealth evidence, more information about counterparties and international exposure, senior management approval and more frequent monitoring.

Credora can prepare KYC and customer onboarding forms, CDD and EDD checklists, customer risk-rating procedures, review workflows and documentation requirements that reflect the AML rules applicable to the business.

Ultimate Beneficial Owner (UBO) Checks

Identifying the Ultimate Beneficial Owner is an important part of Customer Due Diligence when the customer is a company, partnership, trust or other legal arrangement.

For a legal-person customer, the review should identify the natural person who ultimately owns or controls 25% or more of the entity, directly or indirectly, or who exercises ultimate control through other means.

Where ownership passes through holding companies, overseas entities, nominee shareholders or other layers, the review should continue through the ownership chain until the individuals who ultimately own or control the customer are identified.

A UBO Review Can Include

  • shareholding and voting rights;
  • direct and indirect ownership;
  • intermediate holding companies and ownership layers;
  • persons exercising control through agreements or other arrangements;
  • nominee shareholders or nominee directors;
  • directors, authorised signatories and other controlling persons;
  • corporate structure charts and supporting ownership documents;
  • sanctions, PEP and adverse-media checks on relevant individuals; and
  • changes in ownership or control during the business relationship.

If no natural person meets the applicable ownership or control threshold, the AML review should follow the required control test and identify the relevant natural person holding the senior managing position where required.

The 25% threshold should not be treated as a reason to stop reviewing the structure. Where a customer presents higher risk, common control exists across several holdings, or the ownership structure is unusually complex, additional individuals below the standard threshold may need to be identified and reviewed.

A signed UBO declaration by itself may not be sufficient where the declaration conflicts with company records, public information or the actual ownership and control structure. The information should be supported by reliable documents or other independent sources appropriate to the level of risk.

Credora can establish procedures for identifying, verifying, documenting and periodically reviewing beneficial ownership as part of the company’s KYC and AML compliance requirements.

AML Compliance Officer and MLRO Requirements

DNFBPs are required to appoint a qualified Compliance Officer or Money Laundering Reporting Officer (MLRO) with sufficient authority, independence and resources to carry out the role.

The Compliance Officer should operate at management level, have access to the information needed for AML decisions and be able to escalate matters directly to senior management without interference from commercial or operational functions.

Key Compliance Officer Responsibilities

  • overseeing the Business Risk Assessment and AML procedures;
  • reviewing internal suspicious-activity escalations;
  • deciding whether STRs or SARs should be submitted;
  • acting as a contact point for the FIU and supervisory authority;
  • monitoring KYC, CDD, EDD and sanctions controls;
  • reporting AML matters to senior management;
  • overseeing staff AML training; and
  • following up on audit, inspection and remediation findings.

For Ministry-supervised DNFBPs, the appointment and governance of the Compliance Officer should also meet the approval and qualification requirements of the relevant supervisory authority.

AML Record Keeping Requirements in the UAE

AML compliance depends on being able to show what checks were performed, what decisions were made and why the business accepted, rejected or continued a customer relationship.

Ministry-supervised DNFBPs are expected to retain key AML records, including customer files, risk assessments, internal reports and suspicious-transaction records, for at least five years.

AML Records Can Include

  • customer identification and verification records;
  • beneficial-owner and ownership documents;
  • customer risk assessments and risk-rating decisions;
  • CDD and EDD documents;
  • source-of-funds and source-of-wealth records where required;
  • sanctions and screening results;
  • internal investigations and escalation records;
  • STR and SAR records and supporting analysis;
  • Compliance Officer reports;
  • AML training records; and
  • audit findings and remediation evidence.

Records should be organised so the company can retrieve the relevant customer, transaction and compliance information when requested during an audit, inspection or regulatory enquiry.

AML Training for Employees

AML training should reflect the employee’s responsibilities and the financial-crime risks faced by the business. Front-line staff, compliance personnel and senior management do not necessarily require the same level or type of training.

Training should help employees understand the company’s AML procedures and recognise when a customer, transaction or document requires further review.

  • AML/CFT/CPF obligations relevant to the employee’s role;
  • customer due diligence and beneficial-owner checks;
  • money laundering, terrorism financing and proliferation financing red flags;
  • PEP and sanctions procedures;
  • internal escalation of suspicious activity;
  • confidentiality and tipping-off restrictions; and
  • practical examples relevant to the company’s sector.

Credora can prepare role-specific AML training for employees, management and compliance personnel based on the company’s activities, internal procedures and identified risks.

Independent AML Compliance Review, Inspection Preparation and Remediation

DNFBPs are expected to maintain an independent audit function that tests whether their AML policies, procedures and controls are working effectively.

The scope and frequency of the review should reflect the size of the business, its activities, risk exposure, previous findings and any issues identified during regulatory inspections.

An Independent AML Review Can Examine

  • Business Risk Assessment and risk methodology;
  • AML policies and procedures;
  • sample KYC, CDD and EDD files;
  • customer and beneficial-owner risk ratings;
  • sanctions and screening procedures;
  • internal suspicious-activity escalation;
  • Compliance Officer governance;
  • employee AML training;
  • record keeping and document retrieval; and
  • closure of previous audit or regulatory findings.

Before a regulatory inspection, the same review can be used to identify missing documents, incomplete customer files, outdated risk assessments or procedures that are not being followed in practice.

Where weaknesses are identified, the findings should be converted into clear corrective actions with responsibility, target dates and evidence required to confirm completion.

Credora can carry out an independent AML compliance review, prepare the business for regulatory inspection and develop a remediation plan for identified compliance gaps.

Get AML Compliance Services in Dubai, UAE

Need help with AML compliance in the UAE? Credora provides AML/CFT/CPF compliance services for DNFBPs and regulated businesses, including AML Business Risk Assessments, AML policies and procedures, KYC/CDD and EDD, UBO checks, sanctions controls, employee AML training, compliance reviews and goAML registration.

Send us your trade licence, business activity, licensing authority, current AML documents and details of any regulatory inspection or compliance requirement. We can review what applies to your business and identify the AML documents, controls and corrective actions required.

Credora Consultancy LLC · AML Compliance Services in Dubai and Across the UAE