Turn informal business practices into clear policies, step-by-step procedures, approval rules, control points and evidence your team can use consistently.
Companies often grow through verbal instructions, spreadsheets and individual experience. That can work while the team is small, but it becomes harder to control when staff, locations, transaction volume or regulatory requirements increase.
Policies and SOPs create consistency by defining responsibilities, approvals, evidence and escalation. The work begins with the actual process—not with a generic template.
Where an SOP covers AML, tax, employment, health, safety or another regulated area, the operating document needs to reflect the current legal and supervisory requirements that apply to the business.
Payments, journals, reconciliations, month-end close, financial reporting and record handling.
Vendor onboarding, purchase requests, approvals, invoices, expense claims and payment evidence.
Customer onboarding, credit approval, invoicing, collections, credit notes and bad-debt escalation.
Risk assessment, onboarding, beneficial ownership, screening, escalation, goAML and recordkeeping where applicable.
Employee changes, payroll inputs, approvals, payment records and finance handoffs.
Authority limits, approval matrices, document ownership, escalation and management reporting.
A procedure written without speaking to the people who perform the work often describes an ideal process that nobody follows. We start with process owners, current records, systems and examples of normal and exceptional transactions.
Understand how work starts, who touches it, which system is used and where delays or errors occur.
Identify preparers, reviewers, approvers and escalation points.
Specify what is checked, who checks it and what record proves the step occurred.
Run ordinary and exception scenarios through the draft process before finalising it.
Assign an owner, approval, version, effective date and future review trigger.
| Control question | What the documentation can define |
|---|---|
| Who starts the process? | Initiator, required information and the system or form used. |
| Who reviews it? | Reviewer responsibility and evidence of review. |
| Who approves it? | Authority level, monetary limits and exceptions. |
| Who can change master data? | Supplier, customer, bank, payroll or other sensitive-data controls. |
| What happens when something is wrong? | Escalation route, hold point and corrective action. |
| What is retained? | Documents, system logs, reports, approvals and retention owner. |
The Ministry of Economy & Tourism's March 2026 DNFBP Guidelines state that AML internal policies, procedures and controls need to be based on the business-wide risk assessment, documented, approved by senior management and communicated across the entity.
The guidance also calls for regular review, effectiveness testing and updates as risk or regulatory expectations change.
Instead of telling the accounting team to “close the books,” a month-end SOP can identify the cut-off date, bank reconciliations, receivable and payable reviews, accruals, depreciation, VAT controls, review responsibilities and management report deadline.
Complete transaction entry and gather missing source documents.
Complete banks, receivables, payables and material control accounts.
Post approved accruals, prepayments, depreciation and other close entries.
Investigate unusual balances and approve the management reporting pack.
The final output depends on the number of processes and level of detail agreed.
The procedure still describes screens, approvals or records from the old software.
Named roles have changed and staff no longer know who owns approvals or exceptions.
The policy refers to superseded legal requirements or an old supervisory process.
The same control problem keeps appearing because the procedure does not address the root cause.
Internal or external reviews identify gaps between the documented process and actual practice.
Transaction volume, branches or staff have outgrown informal approvals and manual controls.
| Business area | Examples of documents |
|---|---|
| Finance | Month-end close, journals, bank reconciliation, financial reporting and record retention. |
| Procure-to-pay | Vendor onboarding, purchase approval, invoice processing, payment release and expense claims. |
| Order-to-cash | Customer setup, credit approval, invoicing, collections, credit notes and bad-debt escalation. |
| Payroll-linked finance | Payroll inputs, employee changes, review, payment evidence and accounting handoff. |
| AML / compliance | Risk assessment, CDD, screening, escalation, goAML, training and recordkeeping where applicable. |
| Governance | Delegation of authority, conflicts, approval matrices, document control and incident escalation. |
Employees need to know what changed, which forms or systems they now use, where approvals occur and how exceptions are handled. For important processes, implementation can include workshops, walkthroughs, sample cases and an action register for system or control changes that need to be completed.
A procedure is stronger when the people doing the work can explain it in their own words and demonstrate the evidence they are expected to retain.
“Manager reviews” is not enough for a controlled procedure. The SOP should explain which manager, what is reviewed, how often, what happens when the review identifies an issue and what evidence shows the review occurred.
Stops an unwanted action before it occurs, such as an approval requirement or restricted system access.
Finds an issue after processing, such as bank reconciliation, exception reporting or management review.
Performed by a person and supported by a checklist, approval, signature or other review evidence.
Embedded in the application through access permissions, workflow rules, validation or automated checks.
A policy sets a rule, principle or governance expectation. An SOP describes the practical sequence employees follow to complete a process.
Yes. Common areas include payments, bank reconciliations, month-end close, expense claims, supplier onboarding, customer credit, record retention and financial reporting.
Yes, where relevant to the business. AML-related policies and procedures need to be aligned with the current UAE framework and the supervised entity's risk assessment.
No. Documents need to be implemented, communicated, monitored and updated. A strong SOP includes practical owners, approvals, controls and evidence.
Yes. A policy and SOP gap assessment can identify obsolete, duplicated, inconsistent or missing documents and prioritise what needs revision.
The review frequency depends on risk and the process. A document also needs review when there is a material system, legal, organisational or workflow change.
Depending on scope, it can include policies, step-by-step procedures, responsibility matrices, approval limits, control points, forms or checklists, version history and implementation actions.
Tell us which processes are undocumented or no longer working. We can map the workflow and build practical policies, SOPs and controls around your team.