logo
CREDORA CONSULTANCY LLC
Trust | Transform | Thrive
Credora Consultancy LLC

goAML Registration UAE & DNFBP AML Compliance Services

Credora assists UAE businesses with goAML registration, DNFBP compliance, SACM access, Compliance Officer and MLRO documentation, AML policies, business risk assessments, customer due diligence and ongoing AML compliance.

If your bank, licensing authority or compliance team has asked for DNFBP registration, a goAML Organisation ID, AML policy or proof of AML compliance, we can first review what applies to your licensed activity and then help organise the required registration and compliance records.

Has Your Bank Asked for a DNFBP Certificate or goAML Registration?

A bank may ask a business operating in a DNFBP sector for additional AML information during account opening, periodic KYC review or a compliance update. The request may refer to a “DNFBP certificate”, goAML registration, Organisation ID, AML policy, MLRO details or other compliance evidence. These are not all the same document. Credora can review the bank’s request and identify what your business should provide.

What Is a DNFBP in the UAE?

DNFBP stands for Designated Non-Financial Businesses and Professions. It is a regulatory classification used under the UAE Anti-Money Laundering, Counter-Terrorism Financing and Counter-Proliferation Financing framework for businesses and professions whose activities can carry increased financial-crime risk.

A company does not become a DNFBP simply because it is a non-financial business. Its licensed activities and the transactions or professional services it performs must fall within the categories specified under the UAE AML regulations.

DNFBP activities include real estate brokerage, dealing in precious metals and precious stones, specified activities carried out by independent accountants and legal professionals, trust and company service activities and other activities covered by the applicable regulations.

DNFBP Sector Examples Why AML Requirements Apply
Real Estate Real estate agents and brokers involved in property purchase and sale transactions Property transactions can involve substantial funds, complex ownership structures and third-party payments
Precious Metals & Stones Gold, jewellery, diamonds and other precious metal or stone dealers where the applicable transaction conditions are met High-value and cash-intensive transactions require appropriate AML controls and reporting
Accountants & Auditors Independent accounting and auditing businesses carrying out activities covered by the DNFBP framework Professional advisers may have access to financial records, corporate structures and transactions
Trust & Company Services Businesses providing specified company formation, corporate administration or related services Corporate structures may be used to hold assets, transfer ownership or conduct transactions

Who Regulates DNFBPs in the UAE?

For DNFBPs licensed by UAE mainland licensing authorities and commercial free zones, the Ministry of Economy & Tourism is the relevant AML supervisory authority for the sectors under its remit.

Businesses in the UAE’s financial free zones require separate consideration. Entities supervised within DIFC and ADGM follow their respective regulatory frameworks. A business should therefore confirm both its licensed activity and supervisory authority before beginning the registration process.

Is a DNFBP Registration a Certificate?

No. DNFBP is not a certificate that a company applies for and receives as a printed document. It describes the regulatory category into which certain businesses or professional activities fall.

For a DNFBP required to report through the UAE Financial Intelligence Unit, the relevant practical requirement is registration on the goAML system. Once the entity registration is approved, the registered entity receives an approval notification containing its unique Organisation ID.

Do not confuse goAML registration with AML training certification. A professional training certificate relating to AML/CFT for DNFBPs is separate from a company’s goAML entity registration and Organisation ID.

What Is goAML?

goAML is the reporting platform used by the UAE Financial Intelligence Unit (UAEFIU). Registered reporting entities use the system to submit Suspicious Transaction Reports, Suspicious Activity Reports and other applicable financial-intelligence reports.

goAML registration should therefore not be treated as a one-time licence form. The account gives the appointed Compliance Officer or Money Laundering Reporting Officer access to the reporting system when a statutory report is required.

Why Is a UAE Bank Asking for DNFBP or goAML Registration?

UAE banks carry out customer due diligence when opening and reviewing business bank accounts. If a company carries out an activity associated with a DNFBP sector, the bank may ask for additional AML compliance information to understand whether the business has completed the registrations and controls applicable to its activity.

A request described as a “DNFBP certificate” may therefore be a request for evidence of goAML registration or other AML compliance records. The exact evidence should be confirmed with the bank because onboarding and KYC document requirements can differ between financial institutions.

Where a bank specifically asks for proof of goAML registration, this may include the goAML approval notification, Organisation ID or another record from the registered account.

goAML Registration and Reporting Support Services in the UAE

Credora supports UAE businesses with the practical work required before and after goAML registration. Our services cover SACM and goAML setup, STR and SAR preparation support, internal AML reporting procedures, UAEFIU follow-up and ongoing DNFBP reporting compliance.

goAML Registration & SACM Setup in the UAE

Credora helps businesses complete the practical steps required for goAML registration in the UAE. We first review the trade licence, business activity and supervisory jurisdiction so the company follows the correct registration route.

For Ministry-supervised DNFBPs, we can assist with the SACM access stage, Compliance Officer or MLRO documentation and the subsequent goAML entity registration.

  • Review of the company’s DNFBP activity and supervisory authority
  • SACM registration and authenticator setup support
  • Compliance Officer or MLRO authorisation documentation
  • Preparation and review of the required registration documents
  • goAML organisation and administrator profile setup
  • Support through registration until the Organisation ID is issued

Already registered? We can also review an existing goAML account where the company has changed its Compliance Officer, MLRO, contact information or other registration details.

STR & SAR Reporting Support

A Suspicious Transaction Report (STR) relates to a suspicious transaction or attempted transaction, while a Suspicious Activity Report (SAR) can address suspicious conduct or activity that may not centre on a specific transaction.

Credora can support the company’s Compliance Officer or MLRO with the review and preparation process so the report contains clear facts, relevant parties, transaction information, supporting records and a structured explanation of the reasons for reporting.

  • Review of internal alerts and supporting transaction records
  • Assistance in organising information required for an STR or SAR
  • Review of customer, UBO and transaction details used in the report
  • Support in preparing a clear and factual reporting narrative
  • Quality checks for completeness and consistency before filing
  • Technical guidance on entering the information into goAML

Important: The reporting entity and its authorised Compliance Officer or MLRO remain responsible for determining whether a matter is suspicious and for meeting the applicable reporting obligation.

AML Reporting Workflow & Internal Escalation Procedures

A business needs more than access to goAML. Employees must know how to identify an unusual matter, who to notify internally, what information to preserve and when the matter must reach the Compliance Officer or MLRO.

Credora helps DNFBPs build a practical internal AML reporting process that fits the company’s size, activities and risk profile instead of relying on a generic procedure that staff do not use.

  • Internal suspicious activity escalation procedures
  • Defined responsibilities for employees, management and the MLRO
  • Internal alert and case-review forms
  • Procedures for collecting supporting documents and transaction records
  • Internal review and decision-making workflow
  • Record-keeping procedures for alerts, investigations and reporting decisions

A documented workflow also helps the business show how its DNFBP AML compliance framework operates in practice during a bank review, internal compliance assessment or regulatory inspection.

UAEFIU Follow-Up & goAML Report Corrections

Filing a report does not always end the process. A reporting entity may need to correct information, address a report validation issue, provide additional records or respond to a further information request through the appropriate channel.

Credora can support the Compliance Officer or MLRO in organising the requested information and maintaining a complete internal record of the company’s response.

  • Review of goAML report validation or rejection issues
  • Correction of incomplete or inconsistent report information
  • Preparation of supporting records requested after submission
  • Organisation of responses to requests for additional information
  • Internal tracking of follow-up actions and deadlines
  • Maintenance of report files, supporting evidence and response records

Our role is to help the company prepare an accurate and organised response while the authorised reporting entity manages its formal communication and statutory obligations with the UAEFIU or relevant supervisory authority.

Ongoing DNFBP goAML Reporting & AML Compliance Support

goAML registration is not a one-time compliance task. DNFBPs must keep their registration information current and maintain the controls needed to identify, investigate, document and report suspicious matters when required.

Credora provides ongoing DNFBP AML compliance and goAML reporting support for businesses that need regular assistance with their reporting framework, documentation and compliance processes.

  • Periodic review of goAML registration and authorised-user details
  • Support when the Compliance Officer or MLRO changes
  • Review of internal AML alerts and case documentation
  • STR and SAR preparation support when a reportable matter arises
  • Review of reporting procedures against current business activities
  • Support for sector-specific goAML reporting requirements where applicable
  • Improvement of AML records before bank or regulatory compliance reviews

Businesses in real estate, precious metals and stones, accounting, audit and company services can have different AML risks and reporting requirements. We tailor the compliance scope to the company’s actual licensed activities and transactions.

Our goAML Registration & DNFBP Compliance Services

Credora can assist from the initial DNFBP assessment through goAML registration and the wider AML compliance framework required for the business.

DNFBP Status Assessment

Review of the trade licence, business activity and regulatory jurisdiction to determine whether the entity falls within the relevant DNFBP requirements.

SACM Registration Support

Preparation of SACM registration details, supporting documents and Compliance Officer or MLRO information required for the first registration stage.

goAML Entity Registration

Assistance with the entity profile, registration information, supporting documents and submission required to obtain the Organisation ID.

AML Policy & Procedures

Preparation or review of AML procedures covering customer acceptance, due diligence, escalation, monitoring, reporting, record keeping and governance.

Business Risk Assessment

Assessment of the company’s exposure by customer type, geography, products, services, delivery channels and transaction profile.

CDD, EDD & KYC Framework

Customer onboarding procedures covering identification, beneficial ownership, risk classification, source information and Enhanced Due Diligence where required.

Sanctions & PEP Controls

Review of screening procedures for customers, beneficial owners and relevant parties against applicable sanctions and politically exposed person controls.

Bank Compliance Support

Review of bank requests relating to goAML, AML policies, business activities, UBO information, Compliance Officer details and DNFBP status.

How goAML Registration Works in the UAE

For Ministry-supervised DNFBPs, goAML registration involves SACM and authenticator access followed by goAML entity registration. In practice, the process can be organised into the following stages.

  • 1. Confirm the DNFBP Activity and Supervisor: The trade licence, business activity and jurisdiction are checked before registration so that the entity follows the appropriate supervisory route.
  • 2. Prepare the Registration Documents: The trade licence, Compliance Officer or MLRO authorisation and identification documents are prepared in the required format.
  • 3. Complete SACM Registration: The nominated Compliance Officer or MLRO completes the required SACM registration and authentication setup.
  • 4. Submit the goAML Entity Registration: The entity profile, address, administrator details and supporting documents are completed through the goAML registration area.
  • 5. Receive the Organisation ID: Once approved, the entity receives a system notification containing its unique goAML Organisation ID.

What Documents Are Required for goAML Registration?

The main documents required for a Ministry-supervised DNFBP registration include:

  • Valid Trade Licence: A current trade licence for the UAE entity being registered.
  • Authorisation Letter: A formal authorisation appointing the Compliance Officer or Money Laundering Reporting Officer.
  • Identification Documents: Emirates ID and/or passport copy of the appointed Compliance Officer or MLRO.

For the applicable Ministry registration route, the supporting documents should be prepared in the required submission format. Company names, licence details and Compliance Officer information should also be entered consistently with the supporting records.

What Do You Receive After goAML Registration?

After the goAML entity registration is reviewed and approved, the business receives an approval notification containing its unique Organisation ID. The Compliance Officer or MLRO can then access the registered entity through the goAML system.

This is why a business looking for a downloadable “DNFBP certificate UAE” may not find one. The relevant records are the approved goAML registration, Organisation ID and the company’s ongoing AML compliance documentation.

Is goAML Registration Enough for DNFBP Compliance?

No. goAML registration is only one part of DNFBP compliance. A regulated business must also maintain AML controls appropriate to its activities and risk profile.

Depending on the business, this can include appointing a Compliance Officer, business and customer risk assessments, customer due diligence, beneficial-owner identification, Enhanced Due Diligence, PEP controls, sanctions screening, transaction monitoring, record keeping and reporting suspicious activities or transactions where required.

The company’s AML policy should reflect how these controls operate in the actual business rather than functioning only as a generic document prepared for a bank or regulatory request.

Sector-Specific DNFBP Requirements

Real Estate Brokers and Agents

Real estate businesses should maintain customer and beneficial-owner due diligence, transaction records, screening and the reporting procedures applicable to property transactions. Certain transactions can also trigger specific reporting through goAML in addition to the general obligation to report suspicious activity.

Dealers in Precious Metals and Stones

Dealers in precious metals and stones require particular attention to high-value and cash transactions. Under the current UAE framework, applicable cash transactions of AED 55,000 or more, including linked transactions where the relevant conditions are met, can trigger additional DNFBP requirements.

Accountants, Auditors and Company Service Providers

Professional service firms should pay particular attention to the nature of the client, beneficial ownership, complex company structures, source information and the purpose of transactions or corporate arrangements. The AML framework should match the services actually performed by the firm.

What If the Bank Has Asked for AML or DNFBP Documents?

A bank compliance request should be answered according to exactly what the bank has requested. Depending on the company’s activity and the bank’s KYC review, this may involve the goAML Organisation ID, registration approval, AML policy, business risk assessment, MLRO or Compliance Officer details, ownership information or other supporting records.

Credora can review the bank’s email or compliance checklist, identify the missing AML records and help prepare the relevant response instead of submitting unrelated documents under the assumption that there is a single “DNFBP certificate”.

DNFBP AML Penalties and Inspections in the UAE

DNFBP compliance is actively supervised in the UAE. The applicable administrative penalty framework provides penalties for specified AML/CFT compliance failures, with the amount depending on the particular violation.

Regulatory inspections can examine customer due diligence, business risk assessment, internal AML controls, Compliance Officer responsibilities, suspicious transaction reporting and other preventive measures.

A DNFBP should therefore not wait for a bank query or regulatory inspection before checking whether its goAML registration and AML compliance records are complete.

Why Work With Credora for DNFBP & goAML Compliance?

DNFBP compliance sits across company documentation, accounting records, customer onboarding, beneficial ownership, transaction monitoring and regulatory reporting. Our approach is to review the business activity first and build the compliance scope around the company’s actual operations rather than treating goAML as an isolated registration exercise.

Credora Consultancy is led by Mr. Chirag Gupta, FCA, CMA, UAECA and FTA Registered Tax Agent, with more than 15 years of professional experience across accounting, audit, taxation, financial reporting and advisory work.

How Our DNFBP Compliance Service Works

  • 1. Send Us Your Trade Licence and Requirement: Tell us whether the request came from your bank, regulator, licensing authority or internal compliance review.
  • 2. We Assess Your DNFBP Position: We review the licensed activity, regulatory jurisdiction and current registration or compliance status.
  • 3. We Identify the Missing Requirements: This may include SACM or goAML registration, Compliance Officer documentation, AML policies, risk assessments, due diligence procedures or bank evidence.
  • 4. We Complete the Agreed Compliance Scope: The registration and compliance documents are prepared around the applicable requirements and information supplied by the company.

Frequently Asked Questions About DNFBP and goAML

What does DNFBP mean?

DNFBP means Designated Non-Financial Businesses and Professions. It covers specified non-financial sectors that are subject to UAE AML/CFT/CPF requirements.

Is goAML registration mandatory for DNFBPs?

DNFBPs subject to the applicable UAE reporting framework are required to register on goAML and maintain the registration required for their activities. The correct registration route depends on the entity’s supervisor and jurisdiction.

Do I receive a DNFBP certificate?

There is no standard company certificate called a DNFBP Certificate. An approved goAML entity receives an Organisation ID. Professional AML training certificates are separate from the company’s entity registration.

What if my bank asks for a DNFBP certificate?

Confirm whether the bank requires goAML approval, an Organisation ID, AML policy, Compliance Officer details or another compliance record. Credora can review the request before the supporting documents are prepared.

Does a Free Zone company need goAML registration?

A commercial Free Zone company can fall within the DNFBP framework if its activities meet the applicable criteria. DIFC and ADGM entities follow their respective supervisory frameworks and should not automatically use the Ministry registration route.

Is goAML registration enough to make a company AML compliant?

No. Registration provides access to the reporting system. The business must also implement the AML controls applicable to its activities, including risk assessment, customer due diligence, screening, record keeping, monitoring and reporting procedures.

Can Credora help if our MLRO or Compliance Officer has changed?

Yes. Credora can review the existing entity registration, current Organisation ID and the documentation required to update the Compliance Officer or MLRO information under the applicable process.

Need Help With goAML or a Bank DNFBP Request?

Send us your UAE trade licence and the request you received. We can review whether DNFBP requirements apply, check your current goAML position and identify the registration or AML compliance documents that need attention.