Compliance
Conducting an AML Risk Assessment in the UAE
· 4 min read · By Aureus Worldwide
UAE anti-money-laundering law is built on a single idea: the risk-based approach. Instead of treating every customer and transaction the same, businesses must focus their effort where the risk is highest, and that requires knowing where the risk actually is. The AML risk assessment is how you find out. For financial institutions and the many designated non-financial businesses now in scope, a sound risk assessment is both a legal requirement and the foundation of an effective compliance programme. This guide explains how to conduct one.
Why the risk assessment comes first
Under the UAE AML framework (Federal Decree-Law No. 20 of 2018 and its implementing regulations), regulated businesses must apply a risk-based approach. You cannot apply that approach until you have assessed your risks, so the risk assessment is the starting point of the entire programme. It determines how much due diligence each customer needs, how closely you monitor, and where you concentrate resources. Our broader AML compliance guide sets the wider context.
Who must do it
The obligation falls on financial institutions and designated non-financial businesses and professions (DNFBPs), which include:
- Real estate agents and brokers
- Dealers in precious metals and stones
- Auditors and accountants
- Corporate service providers (company formation, registered agents)
If you are a DNFBP, the risk-based approach, and therefore a risk assessment, applies to you. Our AML for DNFBPs guide explains the sector obligations.
The four risk dimensions
A robust AML risk assessment examines risk across four standard dimensions:
| Dimension | What you assess | Higher-risk examples |
|---|---|---|
| Customer | Who your clients are | PEPs, complex ownership, cash-intensive |
| Product / service | What you offer | High-value, easily transferable items |
| Geography | Where clients/funds come from | High-risk or sanctioned jurisdictions |
| Channel | How you deal with clients | Non-face-to-face, intermediated onboarding |
Rating each dimension, then combining them, produces an overall risk profile for the business and for individual customer relationships.
Customer risk
Consider the nature of your customers, are they politically exposed persons (PEPs), do they have complex or opaque ownership structures, are they cash-intensive, or based in higher-risk sectors? Accurate beneficial-ownership information is essential here, which is why your UBO register feeds directly into customer risk.
Product and service risk
Some products carry more risk, high-value goods, items that are easily transferable or resold, or services that can move value across borders. Assess how your offering could be misused.
Geographic risk
Funds or customers connected to high-risk or sanctioned jurisdictions, or countries with weak AML controls, raise risk. Keep your view of high-risk geographies current.
Channel risk
Non-face-to-face onboarding and reliance on intermediaries increase the risk of impersonation or hidden ownership, requiring stronger verification.
Scoring and rating risk
Translate the assessment into a usable rating:
- Assess each dimension as low, medium or high (or a numeric score)
- Combine them into an overall risk rating for the business
- Apply the same logic to each customer at onboarding
- Set the level of due diligence to match, simplified, standard or enhanced
- Document the rationale for each rating
The output is not a one-off score but a framework that drives day-to-day decisions about how much scrutiny each relationship gets.
From assessment to controls
The risk assessment is only valuable if it shapes your controls. A higher-risk customer should trigger enhanced due diligence, deeper verification, source-of-funds checks and closer monitoring, while lower-risk relationships can take a proportionate approach. Crucially, the assessment improves your ability to spot suspicious transactions, which must be reported through the goAML portal. A weak risk assessment means genuine red flags slip through; a strong one focuses attention where it counts.
The risk-based approach is not about doing less, it is about doing more where it matters. A good risk assessment tells you exactly where to look.
Keeping it current
Money-laundering risk is not static. Review the assessment at least annually, and whenever your business changes, new products, new markets, new customer types, or when national risk assessments and regulatory guidance are updated. An out-of-date risk assessment is almost as weak as none at all.
Governance and documentation
Regulators expect the risk assessment to be documented, approved and embedded in the business, with a designated compliance officer overseeing it. Keep the methodology, the ratings and the supporting reasoning on file so you can demonstrate a considered, risk-based approach if examined. Specific requirements and high-risk lists change, so confirm current expectations with the relevant authority.
How Aureus Worldwide helps
Aureus Worldwide helps UAE financial institutions and DNFBPs design and document AML risk assessments across customer, product, geographic and channel risk, and translate them into proportionate controls. Our AML consulting service builds your risk-based framework, supports goAML registration and reporting, and aligns it with your UBO obligations. To put a sound AML risk assessment in place, contact us.
Frequently asked questions
What is an AML risk assessment?
An AML risk assessment is a structured analysis of how exposed a business is to money laundering and terrorist financing. It examines customers, products and services, geographies and delivery channels, rates the risk in each area, and produces an overall risk profile that shapes the firm's AML controls under a risk-based approach.
Who must conduct an AML risk assessment in the UAE?
Financial institutions and designated non-financial businesses and professions (DNFBPs), including real estate agents, dealers in precious metals and stones, auditors, and corporate service providers, are required to apply a risk-based approach, which begins with assessing their money-laundering and terrorist-financing risks.
How does the risk assessment connect to goAML?
The risk assessment underpins the whole AML programme. It informs customer due diligence levels, ongoing monitoring, and the identification of suspicious transactions, which must be reported through the goAML portal. A sound risk assessment makes it more likely genuine suspicious activity is detected and correctly reported.