AML Compliance Audit in Dubai (UAE): Process, Documents and Costs

The UAE has not relaxed AML and UBO supervision since leaving the FATF grey list on 23 February 2024. In the first half of 2025 the Ministry of Economy and Tourism alone recorded 1,063 violations and issued more than AED 42 million in fines. Here is how a Dubai company prepares for a compliance audit, which documents are requested, how the six phases run and what the work costs under the current legal framework.
Let Us Call You

For detailed information +90 542 381 3868'Call.

AML compliance audit in Dubai UAE: process steps, required documents and costs

Table of Contents

1. What Is an AML Compliance Audit and Why Does the UAE Require It?

2. Who Must Comply With AML Rules in the UAE?

3. The AML Compliance Audit Process Step by Step

4. AML Audit Document Checklist

5. How goAML Registration and STR Filing Are Tested

6. UBO Declaration and the 25% Threshold

7. The Most Common Audit Findings

8. How Recent Legal Changes Affect Audits

9. A 30-Day Audit Preparation Plan

10. AML Compliance Audit Cost and Duration

What Is an AML Compliance Audit and Why Does the UAE Require It?

An AML compliance audit is an independent review that tests whether a company actually meets its anti-money laundering and counter-terrorist financing obligations. The reviewer works through written policies, customer due diligence files, transaction monitoring records and reporting logs, then documents where practice diverges from the rulebook. Depending on the licence, oversight sits with the Ministry of Economy and Tourism, the Central Bank of the UAE, the DFSA in DIFC or the FSRA in ADGM.

The UAE was removed from the FATF list of jurisdictions under increased monitoring on 23 February 2024 and, as of the FATF update of 19 June 2026, remains off that list. Keeping that status depends on how individual businesses behave, which is why inspection activity has increased rather than eased. In the first half of 2025 alone, the Ministry of Economy and Tourism recorded 1,063 violations and issued more than AED 42 million in administrative fines.

The audit produces three practical outputs: a documented risk profile, a classified list of gaps, and a dated remediation plan. Banks reviewing account applications, free zone authorities processing licence renewals and corporate counterparties running vendor checks increasingly ask to see these reports.

Internal Review, Independent Audit and Regulatory Inspection

Three different exercises are often confused. Knowing which one you face determines how much preparation is needed.

Type of reviewWho performs itPurpose
Internal self-assessmentThe company compliance officer (MLRO)Find gaps before a regulator does
Independent AML auditExternal auditor or compliance consultantTest policy against practice on a file sample
Regulatory inspectionMinistry, Central Bank, DFSA or FSRAFormal determination of compliance and enforcement
The UAE AML Compliance Stack: Four Layers an Auditor Tests

Layer 1 – Legal framework

Federal Decree-Law No. 10 of 2025, Cabinet Resolution No. 134 of 2025 and Cabinet Decision No. 109 of 2023 on beneficial ownership. Auditor question: which rules apply to this entity?

Layer 2 – Corporate policy

Written AML/CFT policy, business-wide risk assessment, appointment of a compliance officer. Auditor question: is the rule written down and current?

Layer 3 – Operational controls

Customer due diligence, enhanced due diligence, sanctions and PEP screening, transaction monitoring. Auditor question: is the rule applied in daily work?

Layer 4 – Reporting and records

goAML registration, suspicious transaction reports, staff training and a five-year archive. Auditor question: can the work be evidenced?

Who Must Comply With AML Rules in the UAE?

AML obligations reach well beyond banks. UAE law places designated non-financial businesses and professions (DNFBPs) alongside financial institutions. Many entrepreneurs setting up a company in Dubai discover only at the first inspection letter that their activity code brings them into scope.

Financial Institutions

Banks, exchange houses, payment service providers, insurers, brokerages and virtual asset service providers fall here. Supervision sits mainly with the Central Bank of the UAE, while DIFC firms answer to the DFSA and ADGM firms to the FSRA under their own rulebooks.

DNFBPs: Designated Non-Financial Businesses and Professions

Four categories sit under Ministry of Economy and Tourism supervision:

Every business in these four groups must register on goAML, appoint a compliance officer and maintain a business-wide risk assessment from the moment it starts trading.

Mainland, Free Zone, DIFC and ADGM

Which authority audits you depends on where the entity is registered. Mainland companies answer to the Ministry of Economy and Tourism and the Department of Economy and Tourism. In commercial free zones the zone authority is the first point of contact, while DIFC and ADGM operate independent financial free zone regimes with their own beneficial ownership rules.

The AML Compliance Audit Process Step by Step

For a company with organised records, an independent AML audit typically runs two to four weeks. Missing files, an outdated risk assessment or scattered customer documentation can double that. The table below sets out the six phases in the order they occur.

#PhaseWhat happensTypical durationOutput
1ScopingReview of licence, activity codes and customer base1–3 daysAudit scope note
2Risk assessmentScoring of customer, product, geography and channel risk3–5 daysBusiness-wide risk report
3Document collectionCorporate records, KYC files and the policy set are gathered3–7 daysIndexed digital file
4Sample testingCDD, EDD and screening checks on selected customer files3–7 daysTest working papers
5Findings reportGaps classified by severity with owners and deadlines2–4 daysCompliance report and action plan
6Follow-upVerification that findings have been closed30–90 days laterClosure memo

1. Scoping and Preparation

The audit starts by reading the activity codes on the trade licence, because those codes decide whether the business is a DNFBP and which sectoral guidance applies. The compliance officer appointment letter, job description and independence are checked at the same time; the role is expected to sit apart from sales and customer onboarding.

2. Business-Wide Risk Assessment

The business-wide risk assessment is the backbone of the audit. Customer types, products and services, countries served and delivery channels are scored separately, and the resulting risk level determines how strict the acceptance policy must be. An assessment that has never been updated, or that ignores the national and sectoral risk assessments, is the single most frequently flagged weakness.

3. Documents and Records

Records are collected in searchable digital form, preferably PDF. Inconsistency between corporate records and customer files is the first thing an auditor looks for: if the shareholding percentage in the ownership document does not match the UBO declaration, the file goes into deeper review.

4. Sample Testing and Fieldwork

The auditor selects a sample that represents each risk tier and tests whether identity verification, source of funds enquiry, sanctions screening and politically exposed person checks were carried out and recorded. Where enhanced due diligence is missing on a high-risk customer, a finding is raised.

5. Findings Report and Remediation Plan

Findings are graded critical, high, medium and low, each with an owner and a closing date. Critical items are usually scheduled to close within 30 days and medium items within 90.

6. Follow-Up and Ongoing Monitoring

As action items close, a follow-up review confirms them. Ongoing monitoring means refreshing sanctions lists, repeating staff training and revisiting the risk assessment whenever the business model changes.

AML Audit Document Checklist

Preparation falls into four document groups. Submitting all of them at once is the fastest way to shorten an audit.

Corporate and Structural Documents

Policies, Procedures and Appointments

Customer Files and Transaction Records

Reporting and Retention Records

How goAML Registration and STR Filing Are Tested

goAML is the reporting platform of the UAE Financial Intelligence Unit, and registration is mandatory for every entity in scope. An auditor first confirms the registration is active, then checks that the person named in the system still holds the role. The Ministry of Economy and Tourism suspended the activity of 50 DNFBP establishments for three months over missing goAML registration, which is why the gap is treated as a critical finding.

Suspicious transaction reports must be filed without delay and directly with the Financial Intelligence Unit. Two things are tested: whether reported cases are logged, and whether there is written reasoning for transactions that raised suspicion but were not reported. An undocumented decision counts, for audit purposes, as a decision never made. The registration route itself is covered in our guide to AML application and goAML registration.

UBO Declaration and the 25% Threshold

An ultimate beneficial owner is a natural person who holds, directly or indirectly, 25% or more of the shares or voting rights in a company. Control rights such as the power to appoint or remove the majority of directors also create UBO status. The governing instrument is Cabinet Decision No. 109 of 2023, which repealed Cabinet Decision No. 58 of 2020; DIFC and ADGM apply their own beneficial ownership regimes.

An audit looks for three registers and checks that each is current: the register of partners, the register of ultimate beneficial owners and the nominee director record. The statutory timelines are set out below.

ObligationDeadline
Create the UBO register for a newly incorporated entity60 days
Update the register after becoming aware of a change15 days
Notify the registrar of the change15 days
Respond to a registrar request for information14 days
Retain registers on liquidation5 years

Cabinet Resolution No. 132 of 2023 applies an escalating penalty scale to UBO breaches: a time-limited warning first, then administrative fines that start at AED 15,000 and reach AED 100,000 depending on the violation. On a third breach the registrar may suspend the trade licence and close the establishment.

The Most Common Audit Findings

Inspection results published by the Ministry of Economy and Tourism for the first half of 2025 show where weaknesses cluster by sector. Most violations concentrate on customer due diligence, risk assessment and suspicious transaction reporting.

SectorViolations recordedFines imposed
Dealers in precious metals and stones473AED 20 million
Real estate brokerages495AED 18.5 million
Corporate service providers and auditors95Over AED 4 million
Total (H1 2025)1,063Over AED 42 million

Recurring weaknesses in the field are consistent: a risk assessment that was never refreshed, no enhanced due diligence on a high-risk customer, sanctions screening carried out but never recorded, a compliance officer embedded in the sales function, and an inability to evidence genuine trading activity. The last of these directly raises the risk of being treated as a shell company.

The UAE AML/CFT framework has been rebuilt over the past two years. Federal Decree-Law No. 10 of 2025, in force since 14 October 2025, replaced the 2018 decree-law and now covers proliferation financing alongside money laundering and terrorist financing. Cabinet Resolution No. 134 of 2025, the implementing regulation, took effect on 14 December 2025.

Three changes matter in practice:

Offence definitions and the full penalty structure are covered in our article on money laundering laws in Dubai.

A 30-Day Audit Preparation Plan

A company with a known audit date can complete most of the groundwork in four weeks.

Keeping accounting records audit-ready is part of the same exercise: the match between financial statements and bank movements is the first data point in any source of funds enquiry. Planning tax and accounting support alongside bank account processes shortens preparation considerably.

AML Compliance Audit Cost and Duration

The cost of an AML compliance audit depends on company size, customer numbers, transaction volume and how much of the work is outsourced. The ranges below reflect what small and medium-sized businesses in Dubai typically encounter.

Service itemEstimated cost (AED)Typical duration
Document preparation and file indexing1,000 – 5,0003 – 7 days
Policy set and risk assessment preparation2,500 – 8,0005 – 10 days
Independent AML audit and financial review3,000 – 15,0002 – 4 weeks
Legal advice where required2,000 – 10,000Case dependent
Administrative fine exposure if non-compliant15,000 – 100,000 (UBO breaches)–

What Drives the Cost

The main variables are the number of customer files and their risk mix, the jurisdiction (mainland, commercial free zone, DIFC or ADGM), the number of layers in the group structure, how current the existing policy set is, and whether records are already organised digitally. Companies that handle preparation in-house pay noticeably less for external work.

Currency note: the figures above are market estimates as at September 2026 and are not an official tariff. Administrative fine amounts are based on Cabinet Resolution No. 132 of 2023. Confirm current figures with the relevant authority before making decisions.

Sources and Official References

The sources below support the legal references and figures used above. Legislation is updated periodically, so check the current version on the official page before acting.

  • FATF – High-risk and monitored jurisdictions: fatf-gafi.org
  • Central Bank of the UAE Rulebook – Federal Decree-Law No. 10 of 2025: rulebook.centralbank.ae
  • UAE Legislation – Cabinet Resolution No. 134 of 2025 (implementing regulation): uaelegislation.gov.ae
  • UAE Legislation – Cabinet Decision No. 109 of 2023 (beneficial ownership): uaelegislation.gov.ae
  • UAE Legislation – Cabinet Resolution No. 132 of 2023 (UBO penalties): uaelegislation.gov.ae
  • Ministry of Economy and Tourism – goAML registration: moet.gov.ae
  • Ministry of Economy and Tourism – AML resources and inspection results: moet.gov.ae/en/aml
  • UAE Financial Intelligence Unit – AML/CFT laws and decisions: uaefiu.gov.ae
  • UAE Government Portal – Combatting money laundering: u.ae

Frequently Asked Questions and Answers

An AML compliance audit is an independent review that tests whether a company meets its anti-money laundering and counter-terrorist financing obligations, working through written policies, customer due diligence files and reporting records. It produces a risk profile, a graded list of findings and a dated remediation plan.

Financial institutions such as banks, exchange houses, payment providers and virtual asset service providers, plus four DNFBP groups supervised by the Ministry of Economy and Tourism: real estate agents and brokers, dealers in precious metals and stones, independent accountants and auditors, and trust and corporate service providers. Scope is determined by the activity codes on the trade licence.

With organised records, an independent audit usually takes two to four weeks. An outdated business-wide risk assessment, missing identity documents or a multi-layered ownership structure can extend it to about six weeks.

Memorandum and articles of association, trade licence, proof of address, registers of partners and ultimate beneficial owners, UBO declaration, passports and Emirates IDs of partners and managers, the written AML policy, the business-wide risk assessment, the compliance officer appointment letter, customer due diligence files, training records, audited financial statements, six months of bank statements, and invoices or contracts evidencing genuine activity.

A natural person holding 25% or more of the shares or voting rights, directly or indirectly, is an ultimate beneficial owner. Control rights such as the power to appoint or remove the majority of directors also create UBO status. The threshold is set by Cabinet Decision No. 109 of 2023.

Registration is mandatory for every entity in scope. The Ministry of Economy and Tourism suspended the activity of 50 DNFBP establishments for three months for failing to register on goAML. Missing registration is classified as a critical audit finding and leads to administrative sanctions.

No. The UAE was removed from the FATF list of jurisdictions under increased monitoring on 23 February 2024 and remains off the list as of the update of 19 June 2026. Maintaining that status depends on individual companies keeping up their compliance obligations.

Under Federal Decree-Law No. 10 of 2025, in force since 14 October 2025, legal persons face fines of AED 5 million to AED 100 million for money laundering, terrorist financing and proliferation financing offences, and AED 200,000 to AED 10 million for other violations. UBO breaches follow the escalating scale in Cabinet Resolution No. 132 of 2023, from AED 15,000 up to AED 100,000, with licence suspension possible on a third breach.

The business-wide risk assessment must be kept current, and in practice most companies run a comprehensive internal review once a year. It should be refreshed immediately whenever the business model, ownership structure, product range or country exposure changes. Records must be retained for at least five years.

Written by Int. Finance & Tax Consultant · ·
Legal ReviewRARabia KahramanLawyer · Aydın Barosu Reg. No: 3136International Trade and Tax Law Specialist Attorney

Submit Request Form

Fill out the form to submit your service requests.Submit Request Form

Call Now

Call us now for information and price.Call Now

© 2026 World Company Setup & Corporate Services