Aureus Worldwide

Compliance

AML Compliance Checklist for UAE Businesses

· 4 min read · By Aureus Worldwide

AML Compliance Checklist for UAE Businesses

Anti-money-laundering (AML) compliance is a legal obligation for many UAE businesses, not just banks. If you are a Designated Non-Financial Business or Profession (DNFBP), such as a real estate agent, a dealer in precious metals, an auditor or a corporate service provider, you fall within the AML framework and must put real controls in place. The cost of getting this wrong is significant. This checklist sets out the core AML obligations every in-scope UAE business should meet.

A common and dangerous misconception is that AML is something only financial institutions need to worry about. In reality, the framework deliberately extends to a range of non-financial businesses precisely because criminals use them, property purchases, high-value goods and corporate structures are all classic routes for moving illicit funds. Being a DNFBP brings genuine, enforceable obligations, and supervisors do inspect and penalise non-compliance. Whatever your sector, the first step is to take the question seriously and confirm honestly whether you are in scope.

Step 1: confirm whether you are in scope

First, establish whether AML rules apply to you:

  1. Check whether you are a financial institution or DNFBP.
  2. Identify which activities bring you into scope.
  3. Register with the relevant supervisory authority and systems.
  4. Confirm your obligations for your sector.
  5. Confirm scope with the relevant authority.

Our guide to AML for DNFBPs explains who is covered.

Step 2: carry out a business risk assessment

AML is risk-based, so start by understanding your own exposure. Assess risk across:

Factor Consider
Customers Type, location, ownership
Products and services Cash-intensive, high value
Geography Higher-risk jurisdictions
Delivery channels Face-to-face vs remote

Our AML risk assessment guide explains how to document this properly.

Step 3: appoint a compliance officer

In-scope businesses generally need a designated AML/Compliance Officer (MLRO) who:

  • Oversees the AML programme
  • Receives internal suspicion reports
  • Files reports with the authorities
  • Keeps policies up to date

This role carries real responsibility and should be given proper authority. Appointing a compliance officer in name only, without giving them the time, seniority and independence to do the job, is a frequent failing. The person needs to be able to challenge business decisions, decline relationships that present unacceptable risk, and report suspicions without fear of being overruled by commercial pressure. In smaller businesses where no one internally has the capacity or expertise, the role can be outsourced, but the responsibility and the need for genuine authority remain the same.

Step 4: perform customer due diligence

Customer due diligence (CDD) is the heart of AML. For each customer:

  1. Identify the customer.
  2. Verify identity from reliable sources.
  3. Identify the beneficial owner.
  4. Understand the purpose of the relationship.
  5. Apply enhanced due diligence for higher risk.
You cannot manage a risk you have not identified, CDD is how you learn who you are really dealing with.

CDD is also not a one-time event completed at onboarding and then forgotten. The level of due diligence should reflect the risk a customer presents, and it must be kept up to date as that risk changes, for example, if ownership shifts, if the nature of the relationship changes, or if a customer's behaviour starts to look inconsistent with what you know about them. Enhanced due diligence for higher-risk customers means going further: understanding source of funds, obtaining additional verification, and applying closer ongoing scrutiny throughout the relationship.

Step 5: screen against sanctions and PEP lists

Screening is a non-negotiable control:

  • Screen customers and beneficial owners against sanctions lists
  • Identify politically exposed persons (PEPs)
  • Re-screen periodically and on changes
  • Act immediately on a match

Step 6: monitor transactions

AML is ongoing, not a one-off check at onboarding. Monitor for:

  • Transactions inconsistent with the customer profile
  • Unusual patterns or structuring
  • Activity linked to higher-risk jurisdictions
  • Changes in behaviour

Step 7: report suspicions

When suspicion arises, you must file a Suspicious Transaction Report (STR) with the UAE Financial Intelligence Unit:

  1. Document the grounds for suspicion.
  2. File promptly through the required channel.
  3. Never tip off the customer.
  4. Keep a record of the report.

Step 8: keep records and train staff

AML compliance must be evidenced and embedded:

  • Retain CDD and transaction records for the required period
  • Document risk assessments and decisions
  • Train all relevant staff regularly
  • Keep policies and procedures current

Our AML compliance guide covers the full framework.

Keep the rules current

AML obligations, lists and reporting channels change. Always confirm current requirements and penalty amounts with the relevant authority, and keep your programme under review.

How Aureus Worldwide helps

Aureus Worldwide builds and runs AML programmes for UAE businesses and DNFBPs, risk assessments, CDD procedures, screening, monitoring and reporting, and can provide an outsourced compliance officer. Our AML consulting team and compliance officers keep you compliant and audit-ready. To strengthen your AML compliance, contact our advisors.

Frequently asked questions

Who must comply with AML rules in the UAE?

Financial institutions and Designated Non-Financial Businesses and Professions, known as DNFBPs, must comply with UAE anti-money-laundering rules. DNFBPs include real estate agents, dealers in precious metals and stones, auditors and corporate service providers. Confirm your status with the relevant authority.

What is customer due diligence?

Customer due diligence, or CDD, is the process of identifying and verifying your customers, understanding their business and assessing risk before and during the relationship. Enhanced due diligence applies to higher-risk customers. It is a core AML obligation.

What is a suspicious transaction report?

A suspicious transaction report, or STR, is filed with the UAE Financial Intelligence Unit when you suspect funds relate to crime or money laundering. Filing is mandatory when suspicion arises, and tipping off the customer is prohibited. Confirm the process with the relevant authority.

Talk to our chartered accountants →