Compliance
AML for DNFBPs in the UAE: A Guide
· 4 min read · By Aureus Worldwide
The UAE's anti-money-laundering (AML) framework, anchored in Federal Decree-Law No. 20 of 2018, does not only apply to banks. It extends to a group of non-financial businesses known as Designated Non-Financial Businesses and Professions, or DNFBPs. If your business falls into this category, you have specific legal obligations, from registering on the goAML platform to performing customer due diligence and reporting suspicious transactions. This guide explains who is a DNFBP and what compliance involves.
Who counts as a DNFBP
The DNFBP designation captures non-financial businesses considered vulnerable to misuse for money laundering. In the UAE these typically include:
- Real estate brokers and agents
- Dealers in precious metals and precious stones
- Auditors and accountants
- Company service providers and corporate service agents
- Lawyers, notaries and other independent legal professionals (in certain activities)
If your business appears on this list, you should assume the obligations apply and confirm your specific status with the relevant authority. Our guide on AML for UAE real estate looks at one of these sectors in detail.
Why DNFBPs are regulated
DNFBPs often sit at the gateway of large or complex transactions, property sales, high-value goods, company formations, where illicit funds can enter the legitimate economy. By bringing them into the AML regime, the UAE ensures these gatekeepers understand who their clients are, scrutinise unusual activity, and report suspicions to the authorities. This aligns the UAE with international standards set by the Financial Action Task Force.
Core obligations at a glance
Every DNFBP is expected to operate a risk-based AML programme. The main building blocks are:
| Obligation | What it involves |
|---|---|
| goAML registration | Register on the FIU's goAML platform |
| Enterprise risk assessment | Assess money-laundering and terrorist-financing risk |
| Customer due diligence (CDD) | Identify and verify customers and beneficial owners |
| Enhanced due diligence | Apply extra scrutiny to higher-risk clients and PEPs |
| Ongoing monitoring | Monitor activity and keep customer data current |
| Suspicious transaction reporting | Report suspicions to the FIU through goAML |
| Record-keeping | Retain records for the required retention period |
| Compliance officer and training | Appoint a responsible officer and train staff |
The depth of each element should be proportionate to your size and risk, but the framework as a whole is mandatory.
Customer due diligence
CDD is the foundation of AML for DNFBPs. For each client you should verify identity, understand the ownership and control of corporate clients by identifying beneficial owners, and assess the purpose and nature of the relationship. Higher-risk clients, including politically exposed persons (PEPs) and those with opaque structures, require enhanced due diligence. This beneficial-owner analysis ties directly to the UAE's UBO rules, so the two regimes reinforce each other.
Suspicious transaction reporting
A central obligation is to report suspicious activity. If you suspect a transaction may involve the proceeds of crime or terrorist financing, you must file a Suspicious Transaction Report (STR) with the Financial Intelligence Unit via goAML, regardless of the transaction's value. You must not tip off the client. Staff need to recognise red flags and know how to escalate internally to the compliance officer, who decides on reporting.
The duty is to report a genuine suspicion, not to prove a crime. Failing to report what you reasonably suspected is itself a breach.
The role of the compliance officer
DNFBPs are generally expected to appoint a compliance officer responsible for the AML programme, overseeing risk assessment, CDD standards, reporting, training and record-keeping, and acting as the point of contact with the authorities. In smaller firms this may be an existing senior person, but the role and its responsibilities must be clearly defined. For firms without internal capacity, the function can be supported by external specialists.
Penalties for non-compliance
The consequences of ignoring AML obligations are serious. Administrative penalties apply for failures such as not registering on goAML, not conducting due diligence, or not reporting suspicions, and they can escalate substantially for serious or repeated breaches, alongside reputational harm. Because exact amounts are set by the framework and revised periodically, confirm current penalty levels with the relevant authority.
Building a compliant programme
A practical AML programme for a DNFBP involves:
- Confirm your DNFBP status and register on goAML.
- Document an enterprise risk assessment.
- Implement CDD and enhanced due diligence procedures.
- Set up monitoring and reporting workflows.
- Appoint a compliance officer and train staff.
- Keep records for the required period.
- Review and update as your business and the rules change.
Our broader AML compliance guide covers these steps in more depth.
How Aureus Worldwide helps
Aureus Worldwide helps DNFBPs across sectors meet their obligations, confirming scope, registering on goAML, building risk assessments and CDD procedures, designing reporting workflows and training teams, through our AML consulting service. We connect your AML programme to your beneficial ownership obligations so they work as one. We confirm current requirements and penalty levels with the relevant authority. To make your DNFBP AML-compliant, contact us.
Frequently asked questions
What is a DNFBP in the UAE?
A Designated Non-Financial Business or Profession is a non-financial business that the UAE AML framework brings into scope, such as real estate brokers, dealers in precious metals and stones, auditors and accountants, and corporate service providers. Confirm your status with the authority.
Do DNFBPs have to register on goAML?
Yes. DNFBPs are required to register on the UAE Financial Intelligence Unit's goAML platform and use it to submit suspicious transaction and other required reports. Confirm current requirements with the authority.
What happens if a DNFBP ignores AML rules?
Administrative penalties apply for failures such as not registering, not conducting due diligence or not reporting suspicions, and they can escalate for serious or repeated breaches. Confirm current penalty levels with the authority.