UAE Anti-Money Laundering (AML) Rules for Businesses
UAE businesses in defined categories, including real estate brokers, dealers in precious metals and stones, corporate service providers, auditors and independent accountants, are classed as Designated Non-Financial Businesses and Professions (DNFBPs) and must comply with the UAE AML/CFT framework under Federal Decree-Law No. 20 of 2018 and its Cabinet Decision. That means registering on the goAML platform, appointing a compliance officer, running customer due diligence, monitoring transactions, keeping records, and filing suspicious transaction reports.
Financial institutions face a parallel, more detailed regime through the Central Bank. Fines for non-compliance can be substantial and are set by Cabinet Decision.
Money laundering rules used to feel like something only banks worried about. That changed once the UAE brought a wide range of ordinary businesses, real estate brokers, gold and jewellery dealers, company formation agents, auditors, into the same AML framework as a Designated Non-Financial Business and Profession, or DNFBP.
If your business sits in one of these categories, AML compliance is not optional paperwork, it is a licence condition, and it is actively checked.
The Legal Framework in One Paragraph
The core law is Federal Decree-Law No. 20 of 2018 on Anti-Money Laundering and Combating the Financing of Terrorism, amended by Decree-Law No. 26 of 2021, with detailed obligations set out in Cabinet Decision No. 10 of 2019 and its amendments.
The regime is overseen at a national level by the Executive Office of Anti-Money Laundering and Counter Terrorism Financing, with day-to-day supervision split between the Central Bank for financial institutions and the Ministry of Economy, along with the relevant free zone authorities, for DNFBPs.
The framework, the DNFBP guidance and the registration route are published by the Ministry of Economy, and financial institutions are supervised separately by the Central Bank of the UAE.

What Is a DNFBP, and Are You One
A DNFBP is a non-financial business that regulators consider vulnerable to being used, knowingly or not, to move or hide illicit money. If your business falls into one of the categories below, you carry AML obligations even though you are not a bank.

- Real estate agents and brokers. When involved in buying or selling property on behalf of clients.
- Dealers in precious metals and stones. When a transaction, or linked transactions, reach or exceed a defined cash threshold.
- Corporate service providers. Company formation agents, registered agents, and providers of company secretary, director, or trustee services.
- Auditors and independent accountants. When preparing for or carrying out transactions for a client related to specified activities.
- Lawyers and notaries. When acting for a client in specified financial or property transactions, such as buying or selling a business or managing client funds.
For dealers in precious metals and stones, the AML obligation is generally triggered by cash transactions at or above a defined threshold. Confirm the current threshold with your regulator, since these figures are set by Cabinet Decision and can be updated.
It is also worth noting that a business can move in and out of DNFBP status as its activities evolve: a general trading company that starts occasionally brokering property deals for clients, for example, may find itself picking up real estate DNFBP obligations it did not have when it was licensed purely for trading.
Financial institutions, banks, exchange houses, insurance companies, and licensed finance companies sit under a parallel and generally more detailed AML regime supervised directly by the Central Bank, with additional sector-specific rules on top of the general framework described here.
If your business is itself a regulated financial institution rather than a DNFBP, treat this guide as background context and work from your Central Bank-issued regulations directly, since the detailed requirements differ in several respects.
It is worth stressing that being outside the DNFBP list does not mean AML risk disappears entirely for a business.
Any UAE company can be used, unknowingly, as a vehicle for laundering money through inflated invoices, unusual payment routing, or a customer paying far more than a service is worth.
Businesses outside the formal DNFBP categories are not required to run the full compliance programme described here, but basic vigilance, knowing your customer and questioning transactions that do not make commercial sense, remains good practice regardless of sector.
The Core Obligations, in Order
Once a business is a DNFBP, or a financial institution, the obligations follow broadly the same sequence, whatever the sector.
- Register on goAML. The Financial Intelligence Unit's platform for suspicious transaction reporting and regulatory communication.
- Appoint a compliance officer. A named person responsible for AML compliance, often called the MLRO, with the authority and access to do the job.
- Run a business-wide risk assessment. Understand where your specific business is exposed to money laundering or terrorist financing risk.
- Conduct customer due diligence (CDD). Verify who you are dealing with before the relationship or transaction proceeds.
- Apply enhanced due diligence (EDD) for higher-risk customers, including politically exposed persons and complex ownership structures.
- Monitor transactions on an ongoing basis, not only at onboarding.
- File a Suspicious Transaction Report (STR) through goAML whenever something does not add up, whether or not the transaction goes ahead.
- Keep records of due diligence, transactions and reports for the required retention period.
- Train staff so they recognise red flags relevant to your sector.
Customer Due Diligence, What It Actually Means
CDD is not a form you fill in once. At a minimum it means identifying and verifying the customer using reliable documents, understanding the purpose and intended nature of the business relationship, and identifying the beneficial owner behind any corporate customer, which is exactly where UBO rules and AML obligations meet.
For higher-risk situations, such as a politically exposed person, a customer from a higher-risk jurisdiction, or an unusually complex ownership structure, enhanced due diligence applies: more documentation, senior management sign-off, and closer ongoing monitoring.
Where a business cannot complete due diligence, because a customer will not provide the requested documents or the ownership structure cannot be clarified, the correct response is to decline or end the relationship rather than proceed on an incomplete file.
This can feel commercially uncomfortable in the moment, particularly with a customer offering a large transaction, but an incomplete CDD file is exactly the pattern regulators look for when reviewing a business after the fact.
goAML and Suspicious Transaction Reporting
goAML is the UAE Financial Intelligence Unit's reporting platform, and registration on it is mandatory for financial institutions and DNFBPs alike. Suspicious transaction reports, and related reports for suspicious activity, attempted transactions, and cases involving cash above a threshold, are filed through this system.
Filing an STR is not an accusation you have to be certain about; it is a professional judgement call based on your risk assessment and red flags, and the law protects businesses that file in good faith even if the transaction turns out to be legitimate.

Real estate, precious metals, or corporate services all carry AML obligations from day one. Price your setup and we will flag exactly what compliance you need in place before you open.
Record Keeping and Audits
| Record type | Examples | Why it matters |
|---|---|---|
| Due diligence files | ID documents, UBO information, source of funds | Proves who you dealt with and why you accepted them |
| Transaction records | Invoices, transfers, contracts tied to the transaction | Supports monitoring and any later investigation |
| Risk assessments | Business-wide and customer-level risk ratings | Shows your compliance programme is active, not theoretical |
| STR filings and internal escalations | goAML submissions, internal review notes | Evidences that red flags were actually acted on |
Regulators and, separately, your own bank, may ask to see these records during a compliance review or a periodic audit of your AML programme. A business that can produce a clean, organised file moves through these reviews quickly.
One that has to reconstruct records after the fact usually ends up under closer, longer scrutiny.
Many DNFBPs are also required to undergo an independent audit of their AML compliance function periodically, checking that the programme on paper matches what actually happens in practice.
This is separate from a financial statement audit, and it specifically tests whether due diligence files are complete, whether the risk assessment is current, and whether staff can demonstrate they understand the red flags relevant to the business.
Building good habits into daily operations makes this kind of review straightforward rather than a scramble.
Penalties for Non-Compliance
Administrative penalties under Cabinet Decision No. 10 of 2019 apply for failing to register on goAML, failing to appoint a compliance officer, failing to conduct due diligence, or failing to report.
These fines can be significant, and they sit separately from any criminal liability that arises if the business is found to have actually facilitated money laundering, which is prosecuted under the Decree-Law itself and carries far more serious consequences.
Because the administrative fine schedule is set by Cabinet Decision and can be revised, confirm the current amounts that apply to your DNFBP category with your compliance adviser rather than relying on a figure you saw elsewhere.

Building a Proportionate AML Programme
A small real estate brokerage and a large corporate services provider do not need the same AML programme, but both need a real one.
Start with the risk assessment, since it shapes everything downstream: it tells you how much due diligence is enough, which customers need enhanced checks, and what your compliance officer should actually be watching for.
Resist the temptation to copy a template built for a bank; a proportionate programme that your team actually follows beats an elaborate one that sits in a folder.
Sanctions screening is a related obligation worth calling out separately. Businesses in scope of AML rules are also expected to check counterparties against relevant sanctions lists before onboarding and periodically afterward, since a customer or transaction can be perfectly legitimate from a money laundering perspective and still be prohibited because a party to it appears on a sanctions list.
This screening is usually run alongside, not instead of, standard customer due diligence.
Where AML Meets Everyday Business Decisions
AML compliance shows up in ordinary moments: turning away a cash payment above your threshold without documentation, asking a new corporate client for their beneficial owner information, or pausing a transaction that does not match what the customer told you about their business.
Building these checks into your standard onboarding process, rather than treating them as exceptions, is what keeps a DNFBP compliant without slowing down the business it is meant to protect.
New businesses setting up in a DNFBP sector often underestimate how early AML obligations start. Registration on goAML and appointment of a compliance officer are expected from the point the business begins operating in scope, not after the first flagged transaction.
Building the compliance programme alongside the company formation itself, rather than retrofitting it once the business is already trading, is the difference between AML being a smooth part of onboarding customers and a stressful catch-up exercise months in.
If you are unsure whether your planned activities fall into a DNFBP category, treat that uncertainty as a question to resolve before you open your doors, not after a bank or regulator raises it.
A short conversation at setup, confirming whether real estate brokerage, precious metals dealing, or corporate services work will bring specific AML obligations, is far cheaper than discovering the answer during a compliance review a year into trading.
Frequently asked questions
A Designated Non-Financial Business and Profession is a non-financial business type that UAE law brings into the AML/CFT regime because of its money laundering risk. It includes real estate agents and brokers, dealers in precious metals and stones above a cash threshold, corporate service providers, auditors, independent accountants, and certain lawyers and notaries.
No. goAML registration is mandatory for financial institutions and for businesses classed as DNFBPs. A business outside these categories generally does not have this specific obligation, though good customer due diligence practice is sensible for any business handling significant payments.
A suspicious transaction report, or STR, is a filing made through the goAML platform when a business identifies a transaction, attempted transaction, or pattern of activity that raises money laundering or terrorist financing concerns. It is a professional judgement, not a formal accusation, and businesses filing in good faith are protected under the law.
Failing to appoint a compliance officer, along with other core obligations such as registering on goAML or conducting due diligence, carries an administrative penalty under Cabinet Decision No. 10 of 2019. Penalties can be significant and increase for repeat or serious non-compliance, separate from any criminal liability.
Yes. Standard customer due diligence verifies who you are dealing with and the purpose of the relationship. Enhanced due diligence applies to higher-risk customers, such as politically exposed persons or complex ownership structures, and requires more documentation, senior sign-off, and closer ongoing monitoring.
See the number for your setup
The cost calculator runs on Dubai Business Corporation’s real price book. Answer a few questions and get your total, fully itemised, in under a minute.


