For detailed information +90 542 381 3868'Call.

Table of Contents
1. What Is an AML Compliance Audit and Why Does the UAE Require It?
2. Who Must Comply With AML Rules in the UAE?
3. The AML Compliance Audit Process Step by Step
4. AML Audit Document Checklist
5. How goAML Registration and STR Filing Are Tested
6. UBO Declaration and the 25% Threshold
7. The Most Common Audit Findings
8. How Recent Legal Changes Affect Audits
An AML compliance audit is an independent review that tests whether a company actually meets its anti-money laundering and counter-terrorist financing obligations. The reviewer works through written policies, customer due diligence files, transaction monitoring records and reporting logs, then documents where practice diverges from the rulebook. Depending on the licence, oversight sits with the Ministry of Economy and Tourism, the Central Bank of the UAE, the DFSA in DIFC or the FSRA in ADGM.
The UAE was removed from the FATF list of jurisdictions under increased monitoring on 23 February 2024 and, as of the FATF update of 19 June 2026, remains off that list. Keeping that status depends on how individual businesses behave, which is why inspection activity has increased rather than eased. In the first half of 2025 alone, the Ministry of Economy and Tourism recorded 1,063 violations and issued more than AED 42 million in administrative fines.
The audit produces three practical outputs: a documented risk profile, a classified list of gaps, and a dated remediation plan. Banks reviewing account applications, free zone authorities processing licence renewals and corporate counterparties running vendor checks increasingly ask to see these reports.
Three different exercises are often confused. Knowing which one you face determines how much preparation is needed.
| Type of review | Who performs it | Purpose |
| Internal self-assessment | The company compliance officer (MLRO) | Find gaps before a regulator does |
| Independent AML audit | External auditor or compliance consultant | Test policy against practice on a file sample |
| Regulatory inspection | Ministry, Central Bank, DFSA or FSRA | Formal determination of compliance and enforcement |
AML obligations reach well beyond banks. UAE law places designated non-financial businesses and professions (DNFBPs) alongside financial institutions. Many entrepreneurs setting up a company in Dubai discover only at the first inspection letter that their activity code brings them into scope.
Banks, exchange houses, payment service providers, insurers, brokerages and virtual asset service providers fall here. Supervision sits mainly with the Central Bank of the UAE, while DIFC firms answer to the DFSA and ADGM firms to the FSRA under their own rulebooks.
Four categories sit under Ministry of Economy and Tourism supervision:
Every business in these four groups must register on goAML, appoint a compliance officer and maintain a business-wide risk assessment from the moment it starts trading.
Which authority audits you depends on where the entity is registered. Mainland companies answer to the Ministry of Economy and Tourism and the Department of Economy and Tourism. In commercial free zones the zone authority is the first point of contact, while DIFC and ADGM operate independent financial free zone regimes with their own beneficial ownership rules.
For a company with organised records, an independent AML audit typically runs two to four weeks. Missing files, an outdated risk assessment or scattered customer documentation can double that. The table below sets out the six phases in the order they occur.
| # | Phase | What happens | Typical duration | Output |
| 1 | Scoping | Review of licence, activity codes and customer base | 1–3 days | Audit scope note |
| 2 | Risk assessment | Scoring of customer, product, geography and channel risk | 3–5 days | Business-wide risk report |
| 3 | Document collection | Corporate records, KYC files and the policy set are gathered | 3–7 days | Indexed digital file |
| 4 | Sample testing | CDD, EDD and screening checks on selected customer files | 3–7 days | Test working papers |
| 5 | Findings report | Gaps classified by severity with owners and deadlines | 2–4 days | Compliance report and action plan |
| 6 | Follow-up | Verification that findings have been closed | 30–90 days later | Closure memo |
The audit starts by reading the activity codes on the trade licence, because those codes decide whether the business is a DNFBP and which sectoral guidance applies. The compliance officer appointment letter, job description and independence are checked at the same time; the role is expected to sit apart from sales and customer onboarding.
The business-wide risk assessment is the backbone of the audit. Customer types, products and services, countries served and delivery channels are scored separately, and the resulting risk level determines how strict the acceptance policy must be. An assessment that has never been updated, or that ignores the national and sectoral risk assessments, is the single most frequently flagged weakness.
Records are collected in searchable digital form, preferably PDF. Inconsistency between corporate records and customer files is the first thing an auditor looks for: if the shareholding percentage in the ownership document does not match the UBO declaration, the file goes into deeper review.
The auditor selects a sample that represents each risk tier and tests whether identity verification, source of funds enquiry, sanctions screening and politically exposed person checks were carried out and recorded. Where enhanced due diligence is missing on a high-risk customer, a finding is raised.
Findings are graded critical, high, medium and low, each with an owner and a closing date. Critical items are usually scheduled to close within 30 days and medium items within 90.
As action items close, a follow-up review confirms them. Ongoing monitoring means refreshing sanctions lists, repeating staff training and revisiting the risk assessment whenever the business model changes.
Preparation falls into four document groups. Submitting all of them at once is the fastest way to shorten an audit.
goAML is the reporting platform of the UAE Financial Intelligence Unit, and registration is mandatory for every entity in scope. An auditor first confirms the registration is active, then checks that the person named in the system still holds the role. The Ministry of Economy and Tourism suspended the activity of 50 DNFBP establishments for three months over missing goAML registration, which is why the gap is treated as a critical finding.
Suspicious transaction reports must be filed without delay and directly with the Financial Intelligence Unit. Two things are tested: whether reported cases are logged, and whether there is written reasoning for transactions that raised suspicion but were not reported. An undocumented decision counts, for audit purposes, as a decision never made. The registration route itself is covered in our guide to AML application and goAML registration.
An ultimate beneficial owner is a natural person who holds, directly or indirectly, 25% or more of the shares or voting rights in a company. Control rights such as the power to appoint or remove the majority of directors also create UBO status. The governing instrument is Cabinet Decision No. 109 of 2023, which repealed Cabinet Decision No. 58 of 2020; DIFC and ADGM apply their own beneficial ownership regimes.
An audit looks for three registers and checks that each is current: the register of partners, the register of ultimate beneficial owners and the nominee director record. The statutory timelines are set out below.
| Obligation | Deadline |
| Create the UBO register for a newly incorporated entity | 60 days |
| Update the register after becoming aware of a change | 15 days |
| Notify the registrar of the change | 15 days |
| Respond to a registrar request for information | 14 days |
| Retain registers on liquidation | 5 years |
Cabinet Resolution No. 132 of 2023 applies an escalating penalty scale to UBO breaches: a time-limited warning first, then administrative fines that start at AED 15,000 and reach AED 100,000 depending on the violation. On a third breach the registrar may suspend the trade licence and close the establishment.
Inspection results published by the Ministry of Economy and Tourism for the first half of 2025 show where weaknesses cluster by sector. Most violations concentrate on customer due diligence, risk assessment and suspicious transaction reporting.
| Sector | Violations recorded | Fines imposed |
| Dealers in precious metals and stones | 473 | AED 20 million |
| Real estate brokerages | 495 | AED 18.5 million |
| Corporate service providers and auditors | 95 | Over AED 4 million |
| Total (H1 2025) | 1,063 | Over AED 42 million |
Recurring weaknesses in the field are consistent: a risk assessment that was never refreshed, no enhanced due diligence on a high-risk customer, sanctions screening carried out but never recorded, a compliance officer embedded in the sales function, and an inability to evidence genuine trading activity. The last of these directly raises the risk of being treated as a shell company.
The UAE AML/CFT framework has been rebuilt over the past two years. Federal Decree-Law No. 10 of 2025, in force since 14 October 2025, replaced the 2018 decree-law and now covers proliferation financing alongside money laundering and terrorist financing. Cabinet Resolution No. 134 of 2025, the implementing regulation, took effect on 14 December 2025.
Three changes matter in practice:
Offence definitions and the full penalty structure are covered in our article on money laundering laws in Dubai.
A company with a known audit date can complete most of the groundwork in four weeks.
Keeping accounting records audit-ready is part of the same exercise: the match between financial statements and bank movements is the first data point in any source of funds enquiry. Planning tax and accounting support alongside bank account processes shortens preparation considerably.
The cost of an AML compliance audit depends on company size, customer numbers, transaction volume and how much of the work is outsourced. The ranges below reflect what small and medium-sized businesses in Dubai typically encounter.
| Service item | Estimated cost (AED) | Typical duration |
| Document preparation and file indexing | 1,000 – 5,000 | 3 – 7 days |
| Policy set and risk assessment preparation | 2,500 – 8,000 | 5 – 10 days |
| Independent AML audit and financial review | 3,000 – 15,000 | 2 – 4 weeks |
| Legal advice where required | 2,000 – 10,000 | Case dependent |
| Administrative fine exposure if non-compliant | 15,000 – 100,000 (UBO breaches) | – |
The main variables are the number of customer files and their risk mix, the jurisdiction (mainland, commercial free zone, DIFC or ADGM), the number of layers in the group structure, how current the existing policy set is, and whether records are already organised digitally. Companies that handle preparation in-house pay noticeably less for external work.
Currency note: the figures above are market estimates as at September 2026 and are not an official tariff. Administrative fine amounts are based on Cabinet Resolution No. 132 of 2023. Confirm current figures with the relevant authority before making decisions.
The sources below support the legal references and figures used above. Legislation is updated periodically, so check the current version on the official page before acting.
An AML compliance audit is an independent review that tests whether a company meets its anti-money laundering and counter-terrorist financing obligations, working through written policies, customer due diligence files and reporting records. It produces a risk profile, a graded list of findings and a dated remediation plan.
Financial institutions such as banks, exchange houses, payment providers and virtual asset service providers, plus four DNFBP groups supervised by the Ministry of Economy and Tourism: real estate agents and brokers, dealers in precious metals and stones, independent accountants and auditors, and trust and corporate service providers. Scope is determined by the activity codes on the trade licence.
With organised records, an independent audit usually takes two to four weeks. An outdated business-wide risk assessment, missing identity documents or a multi-layered ownership structure can extend it to about six weeks.
Memorandum and articles of association, trade licence, proof of address, registers of partners and ultimate beneficial owners, UBO declaration, passports and Emirates IDs of partners and managers, the written AML policy, the business-wide risk assessment, the compliance officer appointment letter, customer due diligence files, training records, audited financial statements, six months of bank statements, and invoices or contracts evidencing genuine activity.
A natural person holding 25% or more of the shares or voting rights, directly or indirectly, is an ultimate beneficial owner. Control rights such as the power to appoint or remove the majority of directors also create UBO status. The threshold is set by Cabinet Decision No. 109 of 2023.
Registration is mandatory for every entity in scope. The Ministry of Economy and Tourism suspended the activity of 50 DNFBP establishments for three months for failing to register on goAML. Missing registration is classified as a critical audit finding and leads to administrative sanctions.
No. The UAE was removed from the FATF list of jurisdictions under increased monitoring on 23 February 2024 and remains off the list as of the update of 19 June 2026. Maintaining that status depends on individual companies keeping up their compliance obligations.
Under Federal Decree-Law No. 10 of 2025, in force since 14 October 2025, legal persons face fines of AED 5 million to AED 100 million for money laundering, terrorist financing and proliferation financing offences, and AED 200,000 to AED 10 million for other violations. UBO breaches follow the escalating scale in Cabinet Resolution No. 132 of 2023, from AED 15,000 up to AED 100,000, with licence suspension possible on a third breach.
The business-wide risk assessment must be kept current, and in practice most companies run a comprehensive internal review once a year. It should be refreshed immediately whenever the business model, ownership structure, product range or country exposure changes. Records must be retained for at least five years.