DNFBP AML/CFT/CPF compliance support

AML Services in Dubai

Build a practical AML framework around business-wide risk assessment, customer due diligence, beneficial ownership, screening, goAML, internal escalation and recordkeeping.

Current frameworkFederal Decree-Law 10/2025
Executive regulationCabinet Resolution 134/2025
DNFBP guidanceMinistry guidance • March 2026
goAMLReporting platform for STR/SAR
Current UAE framework

AML controls need to reflect the 2025 law and 2026 guidance

The UAE AML framework was updated substantially. Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025 now form the core federal framework for anti-money laundering, counter-terrorism financing and counter-proliferation financing requirements.

The Ministry of Economy & Tourism also issued updated DNFBP Guidelines in March 2026. Those guidelines emphasise a risk-based approach, documented policies and procedures, customer due diligence, beneficial-owner identification, ongoing monitoring, reporting and recordkeeping.

For existing AML files

If a policy manual still cites the older 2018/2019 framework as the current legal basis, the references and procedures need to be reviewed against the legislation now in force.

Who may be in DNFBP scope?

Start by confirming whether the licensed activity is supervised as a DNFBP

The Ministry of Economy & Tourism's goAML information identifies several Designated Non-Financial Business and Profession categories.

Real estateBrokers and agents involved in relevant buying or selling transactions.
Independent accountants & auditorsProfessional accounting or assurance services falling within the supervised category.
Precious metals & stonesRelevant dealers, manufacturers, brokers and other covered businesses.
Trust & company servicesCompany formation, registered address or other covered corporate-service activities.

The licence and actual activity need to be reviewed together. A company is not classified merely because a similar business name appears in a broad industry category.

AML compliance framework

Core areas we can help organise

BRA

Business-wide risk assessment

Document exposure across customers, services, delivery channels, geography and transaction patterns.

CRA

Customer risk assessment

Use documented risk factors to determine the level of due diligence and approval required.

CDD

Customer due diligence

Build onboarding files that identify and verify customers and understand the purpose of the relationship.

BO

Beneficial ownership

Trace ownership and control until the relevant natural persons are identified and documented.

MON

Ongoing monitoring

Refresh customer files and review transactions against the expected customer profile.

REP

Reporting & escalation

Create a clear internal route for unusual activity to reach the responsible compliance function.

Business-wide risk assessment

Design controls around the risks the business actually faces

The 2026 DNFBP Guidelines require internal policies, procedures and controls to be based on the results of the business-wide ML/TF/PF risk assessment and to reflect the nature, size and complexity of the business.

That makes the risk assessment more than a compliance form. It is the document that explains why the organisation applies particular controls, customer risk categories, enhanced review triggers and monitoring intensity.

Customers

Ownership structure, occupation or business activity, expected behaviour and other risk indicators.

Geography

Customer, ownership, transaction and service exposure to relevant jurisdictions.

Products & services

How the service could be used, complexity, value and ability to move or disguise funds.

Delivery channels

Face-to-face, intermediated, remote or technology-enabled onboarding and transaction risks.

CDD & beneficial ownership

Know who the customer is, who controls them and why the relationship exists

CDD needs to establish and verify the customer's identity, understand beneficial ownership and capture the purpose and intended nature of the relationship. For layered legal-person structures, the Ministry's 2026 guidance describes tracing ownership and control through the layers until the relevant natural persons are identified.

The guidance also refers to identifying natural persons who ultimately own or control through direct or indirect ownership of 25% or more, while also considering other means of control and cumulative ownership.

  • Customer identity and verification
  • Trade licence / legal-person details
  • Ownership and control structure
  • Beneficial-owner identification
  • Purpose of the relationship
  • Expected transaction/activity profile
  • Customer risk rating
  • Periodic refresh trigger
Enhanced due diligence

Higher-risk relationships need deeper evidence and approval

Enhanced due diligence is not a separate onboarding system; it is a deeper level of review triggered by risk. Depending on the facts, that can involve additional information on the customer or beneficial owner, source of funds or source of wealth, senior approval, more frequent review or closer transaction monitoring.

Trigger areaPossible response
Complex ownershipObtain additional ownership evidence and trace control through each relevant layer.
Higher-risk geographyApply the enhanced measures required for the relevant risk and current regulatory position.
Unusual business modelUnderstand the commercial purpose, source of funds and expected transaction pattern in more depth.
PEP or other elevated riskApply the additional review, approval and monitoring required by the applicable framework.
Inconsistent activityInvestigate the difference between expected and actual customer behaviour.
goAML

Prepare the organisation for suspicious transaction and activity reporting

The Ministry of Economy & Tourism states that DNFBPs must register on goAML. The system is used by the UAE Financial Intelligence Unit to receive and analyse suspicious transaction and suspicious activity reports.

Our support can focus on registration readiness, responsible-user information, internal escalation and maintaining the records that support reporting decisions.

Registration readiness

Organise the trade licence, authorised-user information and other required records for the registration process.

Internal escalation

Give employees a defined route for escalating unusual activity before any external reporting decision.

Decision evidence

Keep a controlled file of the facts, analysis and approval associated with the reporting decision.

Access governance

Control who is authorised to access the platform and submit reports on behalf of the organisation.

Compliance officer / MLRO governance

Give the responsible compliance function authority and a workable escalation process

AML controls fail when employees do not know who owns a decision or when the compliance function cannot obtain the records it needs. The governance structure needs to identify the responsible officer, escalation route, senior-management involvement and how unresolved risks are reported.

  • Clear compliance responsibility
  • Access to customer and transaction records
  • Escalation from front-line staff
  • Senior-management reporting
  • Conflict and independence considerations
  • Training responsibilities
  • Periodic control review
Policies, procedures & controls

Documents need to match the risk assessment and day-to-day process

The Ministry's March 2026 DNFBP Guidelines state that internal policies, procedures and controls need to be documented, approved by senior management, communicated through the organisation and integrated into day-to-day operations. They also need periodic review and effectiveness testing as risks or regulatory expectations change.

PolicyRisk appetite, governance, responsibilities and mandatory requirements.
ProcedureHow staff perform onboarding, screening, review, escalation and recordkeeping.
ControlApproval, checking or monitoring that reduces the identified risk.
EvidenceForms, system records and approvals showing the procedure occurred.
Recordkeeping

Keep AML evidence retrievable for at least the required period

Cabinet Resolution No. 134 of 2025 requires relevant transaction and due-diligence records to be retained for at least five years, with the retention start point depending on the nature of the record and event. The 2026 DNFBP Guidelines also emphasise that records need to be organised so transactions and decisions can be reconstructed.

  • CDD / EDD forms
  • Identification documents
  • Beneficial-owner evidence
  • Risk assessments
  • Screening results
  • Transaction records
  • Internal escalation records
  • Training records
  • Policy approvals
  • Monitoring evidence
AML remediation

Fix the control environment, not only the missing documents

1

Assess

Review current policies, risk assessment, customer files, screening and reporting controls.

2

Prioritise

Separate urgent legal/control gaps from lower-risk documentation improvements.

3

Remediate

Repair CDD files, policy gaps, risk ratings and escalation processes.

4

Train

Target staff training to the weaknesses identified during the review.

5

Monitor

Track unresolved actions and test whether revised controls are operating.

Typical deliverables

Build an AML file that management can maintain

Deliverables depend on the business, supervisor and risk profile.

  • Business-wide risk assessment
  • Customer risk methodology
  • CDD / EDD checklists
  • Beneficial-owner workflow
  • Screening procedure
  • AML policy & procedures
  • Escalation / reporting workflow
  • Compliance action register
  • Training material
  • Recordkeeping framework
DNFBP-specific AML priorities

The risk framework should reflect the type of business

Different DNFBP sectors face different customer, transaction and delivery-channel risks. The underlying AML framework is shared, but the practical controls should be tailored to the activity being supervised.

Accountants & auditors

Client acceptance, beneficial ownership, unusual business structures, source information and the risk created by services involving company, financial or transaction information.

Real-estate brokers & agents

Buyer and seller identification, beneficial ownership, payment patterns, property value, geography and unusual transaction structures.

Dealers in precious metals & stones

Customer identity, cash or high-value transactions, source information, product movement and other sector-specific red flags.

Trust & company service providers

Company formation, nominee or administrative services, ownership complexity, registered-address services and the purpose of the structure.

Screening & ongoing review

Onboarding checks need a process for later changes

Customer risk can change after onboarding. Ownership may change, new jurisdictions may appear, transaction patterns can shift or new sanctions and risk information can become relevant.

A practical AML workflow therefore includes initial screening, periodic refresh and event-driven review rather than treating the customer file as complete after the first approval.

  • Sanctions screening
  • PEP / relevant risk screening
  • Adverse-information review where appropriate
  • Ownership change triggers
  • Licence / activity change triggers
  • Periodic CDD refresh
  • Transaction-profile review
  • Document expiry tracking
AML training & control testing

Employees need to recognise when a normal transaction becomes an AML concern

Role-based trainingFront-line, finance, compliance and management training based on their responsibilities.
Red flagsExamples relevant to the company's actual customers, products and services.
Escalation practiceEmployees know how to raise a concern without alerting the customer.
Effectiveness reviewPeriodic testing checks whether procedures are operating as documented.
FAQs

AML Services FAQs

Which Dubai businesses can fall within DNFBP AML requirements?

The Ministry of Economy & Tourism identifies relevant DNFBP categories that include real-estate brokers and agents, independent accountants and auditors, dealers in precious metals and stones, and trust or company service providers. The exact supervisory position depends on the licensed activity and circumstances.

What is the current UAE AML legal framework?

The current federal framework includes Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025. The Ministry of Economy & Tourism also published updated DNFBP Guidelines in March 2026.

Is goAML registration required for DNFBPs?

The Ministry of Economy & Tourism states that DNFBPs must register on goAML, the platform used for suspicious transaction and suspicious activity reporting to the UAE Financial Intelligence Unit.

What does customer due diligence include?

CDD normally includes identifying and verifying the customer, identifying beneficial ownership and control, understanding the purpose of the relationship and applying a risk rating that drives the level of due diligence.

How long are AML records retained?

Cabinet Resolution No. 134 of 2025 and the 2026 DNFBP Guidelines require relevant transaction and due-diligence records to be retained for at least five years, with the exact starting point depending on the type of record and event.

Can ZeroSync prepare an AML policy only?

Yes, but an AML policy is most useful when it is connected to risk assessment, CDD forms, screening, escalation, training, recordkeeping and management oversight.

Does AML support replace legal advice or the regulator's decision?

No. We can help organise the compliance framework and evidence. Regulatory interpretation, enforcement decisions and formal legal representation remain with the competent authorities and appropriately qualified legal advisers where required.

Speak with ZeroSync

Strengthen your AML framework with current UAE requirements

Tell us your licensed activity, supervisory position and the current state of your AML files. We can scope a risk assessment, policy review, goAML readiness or remediation project.