Skip to main content
AML Compliance Audit in Dubai (UAE): Process, Documents and Costs

Blog

AML Compliance Audit in Dubai (UAE): Process, Documents and Costs

The UAE has not relaxed AML and UBO supervision since leaving the FATF grey list on 23 February 2024. In the first half of 2025 the Ministry of Economy and Tourism alone recorded 1,063 violations and issued more than AED 42 million in fines. Here is how a Dubai company prepares for a compliance audit, which documents are requested, how the six phases run and what the work costs under the current legal framework.

World Company Setup

For Tailored Solutions Free Consultation

World Company Setup consultant on a phone call with a client during a free consultation

Schedule an Online Meeting or Contact Us

Our experts will contact you within 12 hours.

WhatsApp

The UAE has not relaxed AML and UBO supervision since leaving the FATF grey list on 23 February 2024. In the first half of 2025 the Ministry of Economy and Tourism alone recorded 1,063 violations and issued more than AED 42 million in fines. Here is how a Dubai company prepares for a compliance audit, which documents are requested, how the six phases run and what the work costs under the current legal framework.

AML compliance audit in Dubai UAE: process steps, required documents and costs

What Is an AML Compliance Audit and Why Does the UAE Require It?

An AML compliance audit is an independent review that tests whether a company actually meets its anti-money laundering and counter-terrorist financing obligations. The reviewer works through written policies, customer due diligence files, transaction monitoring records and reporting logs, then documents where practice diverges from the rulebook. Depending on the licence, oversight sits with the Ministry of Economy and Tourism, the Central Bank of the UAE, the DFSA in DIFC or the FSRA in ADGM.

The UAE was removed from the FATF list of jurisdictions under increased monitoring on 23 February 2024 and, as of the FATF update of 19 June 2026, remains off that list. Keeping that status depends on how individual businesses behave, which is why inspection activity has increased rather than eased. In the first half of 2025 alone, the Ministry of Economy and Tourism recorded 1,063 violations and issued more than AED 42 million in administrative fines.

The audit produces three practical outputs: a documented risk profile, a classified list of gaps, and a dated remediation plan. Banks reviewing account applications, free zone authorities processing licence renewals and corporate counterparties running vendor checks increasingly ask to see these reports.

Internal Review, Independent Audit and Regulatory Inspection

Three different exercises are often confused. Knowing which one you face determines how much preparation is needed.

Type of reviewWho performs itPurpose
Internal self-assessmentThe company compliance officer (MLRO)Find gaps before a regulator does
Independent AML auditExternal auditor or compliance consultantTest policy against practice on a file sample
Regulatory inspectionMinistry, Central Bank, DFSA or FSRAFormal determination of compliance and enforcement
The UAE AML Compliance Stack: Four Layers an Auditor Tests

Layer 1 – Legal framework

Federal Decree-Law No. 10 of 2025, Cabinet Resolution No. 134 of 2025 and Cabinet Decision No. 109 of 2023 on beneficial ownership. Auditor question: which rules apply to this entity?

Layer 2 – Corporate policy

Written AML/CFT policy, business-wide risk assessment, appointment of a compliance officer. Auditor question: is the rule written down and current?

Layer 3 – Operational controls

Customer due diligence, enhanced due diligence, sanctions and PEP screening, transaction monitoring. Auditor question: is the rule applied in daily work?

Layer 4 – Reporting and records

goAML registration, suspicious transaction reports, staff training and a five-year archive. Auditor question: can the work be evidenced?

Who Must Comply With AML Rules in the UAE?

AML obligations reach well beyond banks. UAE law places designated non-financial businesses and professions (DNFBPs) alongside financial institutions. Many entrepreneurs setting up a company in Dubai discover only at the first inspection letter that their activity code brings them into scope.

Financial Institutions

Banks, exchange houses, payment service providers, insurers, brokerages and virtual asset service providers fall here. Supervision sits mainly with the Central Bank of the UAE, while DIFC firms answer to the DFSA and ADGM firms to the FSRA under their own rulebooks.

DNFBPs: Designated Non-Financial Businesses and Professions

Four categories sit under Ministry of Economy and Tourism supervision:

  • Real estate agents and brokers (REAB) – any business intermediating sales or leases
  • Dealers in precious metals and stones (DPMS) – gold, diamond and jewellery trading
  • Independent accountants and auditors (IAA)
  • Trust and corporate service providers (TCSP) – company formation and management services

Every business in these four groups must register on goAML, appoint a compliance officer and maintain a business-wide risk assessment from the moment it starts trading.

Mainland, Free Zone, DIFC and ADGM

Which authority audits you depends on where the entity is registered. Mainland companies answer to the Ministry of Economy and Tourism and the Department of Economy and Tourism. In commercial free zones the zone authority is the first point of contact, while DIFC and ADGM operate independent financial free zone regimes with their own beneficial ownership rules.

The AML Compliance Audit Process Step by Step

For a company with organised records, an independent AML audit typically runs two to four weeks. Missing files, an outdated risk assessment or scattered customer documentation can double that. The table below sets out the six phases in the order they occur.

#PhaseWhat happensTypical durationOutput
1ScopingReview of licence, activity codes and customer base1–3 daysAudit scope note
2Risk assessmentScoring of customer, product, geography and channel risk3–5 daysBusiness-wide risk report
3Document collectionCorporate records, KYC files and the policy set are gathered3–7 daysIndexed digital file
4Sample testingCDD, EDD and screening checks on selected customer files3–7 daysTest working papers
5Findings reportGaps classified by severity with owners and deadlines2–4 daysCompliance report and action plan
6Follow-upVerification that findings have been closed30–90 days laterClosure memo

1. Scoping and Preparation

The audit starts by reading the activity codes on the trade licence, because those codes decide whether the business is a DNFBP and which sectoral guidance applies. The compliance officer appointment letter, job description and independence are checked at the same time; the role is expected to sit apart from sales and customer onboarding.

2. Business-Wide Risk Assessment

The business-wide risk assessment is the backbone of the audit. Customer types, products and services, countries served and delivery channels are scored separately, and the resulting risk level determines how strict the acceptance policy must be. An assessment that has never been updated, or that ignores the national and sectoral risk assessments, is the single most frequently flagged weakness.

3. Documents and Records

Records are collected in searchable digital form, preferably PDF. Inconsistency between corporate records and customer files is the first thing an auditor looks for: if the shareholding percentage in the ownership document does not match the UBO declaration, the file goes into deeper review.

4. Sample Testing and Fieldwork

The auditor selects a sample that represents each risk tier and tests whether identity verification, source of funds enquiry, sanctions screening and politically exposed person checks were carried out and recorded. Where enhanced due diligence is missing on a high-risk customer, a finding is raised.

5. Findings Report and Remediation Plan

Findings are graded critical, high, medium and low, each with an owner and a closing date. Critical items are usually scheduled to close within 30 days and medium items within 90.

6. Follow-Up and Ongoing Monitoring

As action items close, a follow-up review confirms them. Ongoing monitoring means refreshing sanctions lists, repeating staff training and revisiting the risk assessment whenever the business model changes.

AML Audit Document Checklist

Preparation falls into four document groups. Submitting all of them at once is the fastest way to shorten an audit.

Corporate and Structural Documents

  • Memorandum and articles of association with all amendments
  • Valid trade licence and a printout of activity codes
  • Proof of registered address (Ejari or tenancy contract)
  • Register of partners and shareholders
  • Ultimate beneficial owner register and UBO declaration
  • Nominee director or shareholder agreements
  • Ownership structure chart covering every layer of the group
  • Passport, visa and Emirates ID copies for all partners and managers

Policies, Procedures and Appointments

  • Written AML/CFT policy and procedure manual
  • Business-wide risk assessment report
  • Compliance officer (MLRO) appointment letter and terms of reference
  • Customer acceptance and rejection policy
  • Sanctions screening procedure and screening logs
  • Staff training plan, attendance records and training material

Customer Files and Transaction Records

  • Customer due diligence files and identity verification evidence
  • Enhanced due diligence records for high-risk relationships
  • Source of funds and source of wealth declarations
  • Audited financial statements and the last six months of bank statements
  • Invoices, purchase orders and contracts evidencing real activity

Reporting and Retention Records

  • goAML registration confirmation and system access details
  • Suspicious transaction report log, with written rationale for cases not reported
  • Evidence that records are retained for at least five years

How goAML Registration and STR Filing Are Tested

goAML is the reporting platform of the UAE Financial Intelligence Unit, and registration is mandatory for every entity in scope. An auditor first confirms the registration is active, then checks that the person named in the system still holds the role. The Ministry of Economy and Tourism suspended the activity of 50 DNFBP establishments for three months over missing goAML registration, which is why the gap is treated as a critical finding.

Suspicious transaction reports must be filed without delay and directly with the Financial Intelligence Unit. Two things are tested: whether reported cases are logged, and whether there is written reasoning for transactions that raised suspicion but were not reported. An undocumented decision counts, for audit purposes, as a decision never made. The registration route itself is covered in our guide to AML application and goAML registration.

UBO Declaration and the 25% Threshold

An ultimate beneficial owner is a natural person who holds, directly or indirectly, 25% or more of the shares or voting rights in a company. Control rights such as the power to appoint or remove the majority of directors also create UBO status. The governing instrument is Cabinet Decision No. 109 of 2023, which repealed Cabinet Decision No. 58 of 2020; DIFC and ADGM apply their own beneficial ownership regimes.

An audit looks for three registers and checks that each is current: the register of partners, the register of ultimate beneficial owners and the nominee director record. The statutory timelines are set out below.

ObligationDeadline
Create the UBO register for a newly incorporated entity60 days
Update the register after becoming aware of a change15 days
Notify the registrar of the change15 days
Respond to a registrar request for information14 days
Retain registers on liquidation5 years

Cabinet Resolution No. 132 of 2023 applies an escalating penalty scale to UBO breaches: a time-limited warning first, then administrative fines that start at AED 15,000 and reach AED 100,000 depending on the violation. On a third breach the registrar may suspend the trade licence and close the establishment.

The Most Common Audit Findings

Inspection results published by the Ministry of Economy and Tourism for the first half of 2025 show where weaknesses cluster by sector. Most violations concentrate on customer due diligence, risk assessment and suspicious transaction reporting.

SectorViolations recordedFines imposed
Dealers in precious metals and stones473AED 20 million
Real estate brokerages495AED 18.5 million
Corporate service providers and auditors95Over AED 4 million
Total (H1 2025)1,063Over AED 42 million

Recurring weaknesses in the field are consistent: a risk assessment that was never refreshed, no enhanced due diligence on a high-risk customer, sanctions screening carried out but never recorded, a compliance officer embedded in the sales function, and an inability to evidence genuine trading activity. The last of these directly raises the risk of being treated as a shell company.

The UAE AML/CFT framework has been rebuilt over the past two years. Federal Decree-Law No. 10 of 2025, in force since 14 October 2025, replaced the 2018 decree-law and now covers proliferation financing alongside money laundering and terrorist financing. Cabinet Resolution No. 134 of 2025, the implementing regulation, took effect on 14 December 2025.

Three changes matter in practice:

  • Corporate penalty ceilings are higher. For legal persons, money laundering, terrorist financing and proliferation financing offences carry fines from AED 5 million to AED 100 million; other violations range from AED 200,000 to AED 10 million.
  • Proliferation financing is now a separate control point. Screening programmes are expected to cover this risk explicitly.
  • The national committee structure changed. The National Committee, chaired by the Governor of the Central Bank, drives updates to sectoral guidance.

Offence definitions and the full penalty structure are covered in our article on money laundering laws in Dubai.

A 30-Day Audit Preparation Plan

A company with a known audit date can complete most of the groundwork in four weeks.

  • Week 1 – Inventory: verify the licence and activity codes, confirm the compliance officer appointment and goAML registration, collect the existing policy set.
  • Week 2 – Risk: refresh the business-wide risk assessment and reclassify the customer portfolio by risk tier.
  • Week 3 – File clean-up: complete missing identity documents, renew expired passports and visas, reconcile the UBO register against the ownership structure.
  • Week 4 – Dry run: test a sample internally, repeat staff training and draft an action plan for open items.

Keeping accounting records audit-ready is part of the same exercise: the match between financial statements and bank movements is the first data point in any source of funds enquiry. Planning tax and accounting support alongside bank account processes shortens preparation considerably.