Insights AML
AML Consulting Services UAE — What Providers Actually Do and What Drives the Cost
Who needs AML consulting services in the UAE, what a DNFBP programme covers — goAML, EWRA, MLRO, training — and how to spot a weak AML consultant.
Key takeaways
- Who must comply — financial institutions under CBUAE, and DNFBPs (real estate, precious metals/stones dealers, auditors, corporate service providers) supervised largely by the Ministry of Economy.
- Core obligations — goAML registration, appointed compliance officer, risk-based CDD/EDD, sanctions and PEP screening, STR/SAR reporting, record-keeping and training.
- What consultants deliver — gap assessments, EWRA, tailored policies and procedures, screening-tool selection, training programmes, goAML support and mock inspections.
- Penalty reality — Article 17(1)(b) of Federal Decree-Law 10/2025 allows AED 10,000 to AED 5,000,000 per violation, with sector bans and licence revocation behind it.
- Cost drivers — sector risk, customer volumes and geography, group complexity, existing programme maturity, and whether ongoing support (outsourced compliance function) is included.
- Provider red flags — template-only policies, guaranteed outcomes, no sector experience, and silence about who actually staffs the ongoing obligations.
For years, UAE SMEs treated anti-money-laundering rules as a banking problem. Then the Ministry of Economy began inspecting real estate brokerages, gold traders and corporate service providers — the DNFBP categories — applying a published fine schedule that climbs into the millions of dirhams, and the market for AML consulting services — anti-money laundering consulting, in full — grew up almost overnight. The demand is rational: the obligations are genuinely technical, the supervisors are genuinely checking, and most in-scope businesses have no compliance department. This guide, updated July 2026, maps what the law requires, what a competent AML/CFT consultant actually delivers, how engagements are priced, and the red flags that separate programme-builders from binder-sellers.
Who is in scope — the DNFBP surprise
The framework — Federal Decree-Law No. 10 of 2025 on AML/CFT, issued 30 September 2025, which repealed Federal Decree-Law No. 20 of 2018 at its Article 41; its Executive Regulations in Cabinet Resolution No. 134 of 2025, issued 29 October 2025, which repealed Cabinet Decision No. 10 of 2019 at its Article 70; and the decisions built on them — covers financial institutions under the Central Bank, and Designated Non-Financial Businesses and Professions supervised largely by the Ministry of Economy (with financial free zone regulators covering their own patches):
- Real estate agents and brokers — for transactions in property purchase and sale.
- Dealers in precious metals and precious stones — the gold souk economy, above cash thresholds.
- Auditors and accountants — including firms like ours, which is partly why we know the regime from the inside.
- Trust and corporate service providers — company formation and administration businesses.
Lawyers and notaries face equivalent obligations in defined activities. If your licence puts you in these lanes, the full programme applies regardless of size: a two-person brokerage carries the same categories of obligation as a bank, scaled by risk. The sector-by-sector obligations are mapped in our AML compliance UAE overview. Owners meeting these obligations for the first time usually need the groundwork before the programme makes sense, which is where our explainer on AML meaning and the three stages of money laundering starts.
The obligations a programme must cover
- goAML registration — the UAE FIU’s reporting platform; registration is mandatory and its absence is independently finable. Portal mechanics are in the goAML registration guide, and the profile needs annual renewal.
- A named compliance officer / MLRO — appointed, competent, senior enough to refuse business; the role, reporting lines and the MLRO job description and appointment letter are set out in their own guide.
- Enterprise-wide risk assessment (EWRA) — the documented map of where ML/TF risk enters your UAE business, refreshed as it changes.
- Risk-based CDD/EDD — identify customers and beneficial owners, screen against sanctions lists and PEP status, escalate the high-risk cases; the tiering logic is unpacked in EDD vs CDD vs SDD.
- Ongoing monitoring and STR reporting — spot the unusual, document the decision, file through goAML where suspicion holds.
- Targeted financial sanctions — screening against the UN and local lists, with Article 19(1)(e) requiring instructions from the UAE Executive Office or other competent authorities to be implemented forthwith.
- High-risk country measures — Article 23 of Cabinet Resolution 134/2025 requires enhanced due diligence proportionate to risk for customers from countries the UAE National Committee identifies as high risk, plus any countermeasures the Supervisory Authority directs.
- Records and training — five-year retention and a staff training cycle inspectors ask to see evidence of.
Item three is the one with the sharpest statutory wording behind it. Article 19(1)(a) of Federal Decree-Law No. 10 of 2025 requires an in-scope UAE business to identify, understand, manage, assess, document and continuously update its exposure, applying the risk-based approach, to retain the risk assessment study and the related information, and to provide it to the Supervisory Authority on request. “Continuously update” and “retain” are both obligations in their own right, which is why an EWRA dated two years ago is a finding even where one exists.
Article 24 adds a forward-looking limb most UAE SMEs miss entirely. New products, new business practices, new delivery mechanisms and new or developing technologies must be risk-assessed before launch or use, with measures taken to manage what the assessment finds. A Dubai brokerage adding a crypto payment route, or an Abu Dhabi dealer opening an online channel, owes that assessment in advance rather than at the next inspection.
AED 10k – 5m
Administrative fine a UAE Supervisory Authority may impose per violation under Article 17(1)(b) of Federal Decree-Law No. 10 of 2025
The law that applies today, and what changed in October 2025
Anyone buying AML consulting services in the UAE in 2026 should be able to name the four instruments the engagement is built on. If a proposal still cites Federal Decree-Law No. 20 of 2018 as live law, that is the first thing to query — it was repealed outright by Article 41(1) of the 2025 decree-law.
| Instrument | What it does | Status checked 4 August 2026 |
|---|---|---|
| Federal Decree-Law No. 10 of 2025 on AML/CFT and proliferation financing | The primary law: obligations, supervisory penalties, criminal penalties | Issued 30 September 2025; Article 42 brings it into force two weeks after publication in the Official Gazette |
| Cabinet Resolution No. 134 of 2025 | The Executive Regulations: DNFBP scope, CDD, EWRA, compliance officer duties, record-keeping | In force; issued 29 October 2025 |
| Federal Decree-Law No. 20 of 2018 | The previous AML law | Repealed by Article 41(1) of Federal Decree-Law No. 10 of 2025 |
| Prior executive regulations, resolutions and circulars issued under the 2018 law | Detailed rules and penalty schedules | Article 41(3) keeps them effective insofar as they do not conflict with the 2025 decree-law, until superseded |
That last row is the one that catches consultants out. The 2025 decree-law did not sweep the desk clean. Article 41(3) expressly preserves the regulations, resolutions and circulars issued under the 2018 law that were in force at the date of issuance, to the extent they do not conflict, until replacements are issued. So a live obligation can sit in a 2020 or 2024 instrument and still bind you — which is why “we work to the new law” is not, by itself, a complete answer from a provider.
Article 39 then does something worth knowing before anyone quotes you a fine figure. It hands the job of prescribing the specific violations and their matching administrative penalties to a future Cabinet resolution, proposed by the Minister and coordinated with the Supervisory Authority, which will also name the bodies that impose them, the grievance mechanism and the collector of the fines. Until that resolution is published, the per-violation schedule under the 2025 framework is not a settled published number.
Which activities make you a DNFBP — and at what threshold
The DNFBP list is not in the decree-law at all. It sits in Article 3 of Cabinet Resolution No. 134 of 2025, and it is activity-based rather than licence-based: you are a DNFBP when you carry out one of these activities, whatever your trade licence says. The thresholds below are quoted from that Article.
| DNFBP category | The trigger in Article 3 of Cabinet Resolution 134/2025 | Threshold |
|---|---|---|
| Commercial gaming operators, including on board vessels | A single transaction, or linked transactions, at or above the stated value | AED 11,000 |
| Real estate brokers and agents | Concluding transactions or settlements for a customer on the purchase or sale of real estate | No value threshold |
| Dealers in valuable metals and precious stones | A single cash transaction, or linked cash transactions, at or above the stated value | AED 55,000 |
| Lawyers, notaries, other independent legal professionals and independent accountants | Preparing, conducting or executing financial transactions for a customer in the five listed activities | No value threshold |
| Company and trust service providers | Carrying out the five listed corporate services for or on behalf of a customer | No value threshold |
| Any other business or profession | Determined by a resolution of the Supervisory Authority in coordination with the National Committee | Set by that resolution |
Two details in that table change how the scope question should be asked. The AED 55,000 figure for dealers in valuable metals and precious stones applies to a cash transaction or linked cash transactions — the wording in Article 3(3) is specific about cash, where the gaming trigger at AED 11,000 covers a financial transaction and excludes one involving only gaming chips or instruments. And the professional categories carry no monetary threshold at all; the trigger is the nature of the activity performed for the customer.
For lawyers, notaries, independent legal professionals and independent accountants, Article 3(4) lists exactly which activities pull them in: buying and selling real estate, managing customer funds, managing bank, savings or securities accounts, organising contributions for the establishment, operation or management of companies, and establishing, operating or managing legal persons or arrangements, or buying and selling commercial entities. Routine bookkeeping or a tax filing is not on that list. Handling a client’s company incorporation is.
Company and trust service providers are caught by Article 3(5) when they act as agent in incorporating a legal person, act or arrange for another to act as director, secretary or partner, provide a registered office, business address, residence, correspondence or administrative address, act or arrange for another to act as trustee of an express trust, or act or arrange for a nominee shareholder. A Dubai or Sharjah business-centre operator selling registered addresses is squarely inside that definition, and frequently has no idea.
What a competent AML consultant actually delivers
Whether you engage AML consultants in Dubai, an anti-money laundering consultant attached to your audit firm, or remote AML experts covering the northern emirates, the deliverable list should look the same.
Build-phase deliverables: a gap assessment against the regulations; the EWRA, built from your real customer and transaction data rather than a generic matrix; policies and procedures written to your operations (the document an inspector reads against what your staff actually do); goAML registration and profile setup; screening-tool selection and configuration — the vendor landscape is compared in our PEP screening tools review; CDD file templates and workflows; and role-based training with attendance evidence.
Run-phase support: periodic file testing and programme reviews, refresher training, EWRA updates, regulatory-change monitoring, and mock inspections — the single highest-value exercise for a DNFBP expecting the Ministry’s questionnaire, rehearsed in full in the MoE inspection preparation playbook.
What no consultant can deliver: the accountability. The law places the programme on the business and its named officer; outsourcing the routine work is legitimate and common, outsourcing the responsibility is neither. Any provider promising “full compliance guaranteed” or “inspection-proof” outcomes is selling something the framework does not permit anyone to sell.
What the penalties actually say — and where the published figure stops
This is where the UAE AML market’s marketing is least reliable, so it is worth separating two completely different things that are routinely quoted as one number.
| Who imposes it | Provision | What it can be |
|---|---|---|
| A Supervisory Authority, administratively | Federal Decree-Law 10/2025, Article 17(1)(a) | Warning |
| A Supervisory Authority, administratively | Article 17(1)(b) | Not less than AED 10,000 and not more than AED 5,000,000 for each violation |
| A Supervisory Authority, administratively | Article 17(1)(c) to (f) | Prohibition from the sector, restriction of the powers of board members and executives including a temporary supervisor, suspension or replacement of directors, suspension or restriction of the activity or profession |
| A Supervisory Authority, administratively | Article 17(1)(g) | Revocation of the licence |
| A court, on conviction of a legal person for money laundering, terrorist financing or proliferation financing | Article 27(1) | Not less than AED 5,000,000 and not more than AED 100,000,000, or the value of the criminal property, whichever is greater |
| A court, on conviction of a legal person for the offences in Articles 28 to 35 | Article 27(2) | Not less than AED 200,000 and not more than AED 10,000,000 |
The AED 100,000,000 ceiling belongs to a criminal court convicting a legal person of the underlying crime. It is not what a supervisor can impose for a compliance failure, and a consultant who quotes it while selling a programme build is either careless or frightening you on purpose. The administrative exposure a DNFBP faces for a defective programme is the Article 17 ladder, topped by AED 5,000,000 per violation.
Three further features of Article 17 matter commercially. Clause 2 lets the authority order periodic reports on the remedial measures taken, so a penalty can come with an ongoing reporting burden attached. Clause 3 permits an incremental fine where the same violation recurs within one year of the previous fine for it. Clause 4 permits the authority to publish the penalties it imposes through the media — reputational exposure is part of the design, not an accident of it.
And here is the gap, stated rather than filled. Article 39 of Federal Decree-Law 10/2025 leaves the schedule of specific violations and their matching administrative penalties to a Cabinet resolution that had not been published as at 4 August 2026. That means there is no published per-violation figure under the 2025 framework for a discrete failure such as not being registered on goAML. Article 41(3) keeps earlier instruments alive where they do not conflict, so an older schedule may still be applied — but anyone stating a precise dirham figure for a specific AML violation today should be asked which instrument they are reading it from. We are not going to invent one.
Who your supervisor is, and where the penalty schedule currently lives
Supervision in the UAE is split, and the split decides which door an inspection comes through. Financial institutions sit with the Central Bank of the UAE. DNFBPs across the mainland and the commercial free zones sit with the Ministry of Economy and Tourism, which publishes its AML material at moet.gov.ae. The financial free zones — DIFC in Dubai and ADGM in Abu Dhabi — are supervised by their own regulators rather than by the federal ministry.
The Ministry’s own AML page names the two instruments it works from on penalties: Cabinet Decision No. 132 of 2023 on administrative penalties imposed on violators, and Cabinet Resolution No. 71 of 2024 regulating violations and the administrative penalties imposed on violators. Those sit alongside the Article 17 ladder in the decree-law rather than replacing it, and they are exactly the kind of instrument Article 41(3) preserves until superseded. If a provider quotes you a figure for a specific violation, that is where to ask them to point.
None of this changes the practical shape of an inspection for a small business in Dubai, Sharjah, Ajman or Fujairah. The Ministry’s questionnaire opens on the enterprise-wide risk assessment, moves to whether a compliance officer is appointed and trained, and then pulls customer files to test whether the written procedure was actually followed. A DPMS dealer in the Dubai gold souk and a two-person brokerage in Ajman face the same sequence, scaled to their risk.
The compliance officer is a statutory role with five defined duties
Article 22 of Cabinet Resolution 134/2025 does not merely require an appointment. It specifies the standard the person must meet and the five things they must do, which is the most useful checklist a UAE business can hold a provider’s proposal against.
The standard first: the officer must be appointed at management level, under the responsibility of the business, with independence in decision-making and appropriate competence and experience. Independence is a structural test, not a job title — an officer who reports to the person whose deals they are meant to challenge does not have it.
| Duty under Article 22 | What an inspector will look for |
|---|---|
| Monitoring transactions related to the crime | Evidence that monitoring actually ran, not a policy saying it should |
| Reviewing records, receiving, examining and assessing suspicious transaction data, and deciding whether to notify the UAE FIU or retain the matter with reasons, in full confidentiality | A documented decision on each alert, including the ones not reported |
| Reviewing internal systems and procedures against the decree-law and the Executive Regulations, assessing compliance, proposing updates, and reporting directly to senior management | Dated periodic reports to senior management, with management’s observations and decisions recorded |
| Developing, implementing and documenting ongoing training programmes and plans for employees | Attendance records and content, not a certificate for one person |
| Cooperating with the Supervisory Authority and the FIU, providing requested data and enabling access to records | A named contact and a records index that can be produced quickly |
Article 21(3) of the same Resolution puts the appointment inside a wider internal-control obligation: policies, controls and procedures approved by senior management, covering CDD, suspicious-transaction reporting, the compliance officer appointment, fit-and-proper screening of employees, periodic training programmes and workshops, and an independent audit function to test whether the controls actually work. That last item — an independent test of your own programme — is the one most small UAE businesses have never done, and it is written into the regulations.
Record-keeping: five years, counted from the latest of several dates
Article 25 of Cabinet Resolution 134/2025 sets the retention rule, and the counting convention is the part that gets missed. Transaction records, documents, instruments and data for all domestic and international financial, cash and commercial dealings must be kept for not less than five years from the date the transaction completed or the business relationship with the customer ended.
For CDD material the clock is more generous to the regulator. Records obtained through customer due diligence and ongoing monitoring, account files, business correspondence, copies of identification documents, suspicious transaction reports, the results of any analysis, and CCTV and ATM recordings must be kept for not less than five years — but counted from the latest of: termination of the business relationship, account closure, completion of an occasional transaction, completion of a Supervisory Authority inspection, completion of an investigation, or issuance of a final court judgment.
That means an inspection restarts the clock. A UAE business that was inspected in 2026 on a relationship that ended in 2023 is holding those files until at least 2031, not 2028. Article 25(3) adds a quality standard on top: records must be organised so that individual transactions can be reconstructed and financial flows traced, to a standard capable of supporting a prosecution.
How engagements are priced — the drivers
No honest flat rate exists, so compare quotes on drivers:
- Sector risk — a gold trader’s programme carries more screening and cash-control weight than a services CSP’s.
- Volumes and geography — customer counts, transaction values and exposure to higher-risk jurisdictions set the monitoring load.
- Entity count and structure — group programmes with shared functions price differently from single-licence builds.
- Existing maturity — a refresh of a real programme costs a fraction of a first build from nothing.
- Build vs run — one-off programme construction versus ongoing support (file reviews, training cycles, screening operation) are separate lines; get both quoted so year-two costs are not a surprise.
The buying discipline mirrors any professional service: written scope, named deliverables, the CVs of who does the work, and references from your own sector.
One scoping question is worth asking before any quote: which supervisor are we building for. A DNFBP in Dubai mainland or a Sharjah commercial free zone is building for the Ministry of Economy and Tourism’s questionnaire. A firm inside DIFC or ADGM is building for a different regulator with its own rulebook, and a programme written for one is not portable to the other. Providers who do not ask which UAE authority supervises you before pricing the work have not scoped it.
An inspection does not stop at the policy — it pulls customer files and checks whether the policy actually happened. The gap between the binder and the files is where the exposure lives.
Red flags in the UAE’s AML consulting market
The market spans big-four advisory arms, regulatory compliance consulting firms, specialist AML consulting companies and solo practitioners. Most AML consulting firms in Dubai and the wider UAE are competent at the build phase; the differences show in the run phase — and in these red flags:
- Template mills — policies with another firm’s name in the metadata, EWRAs that never mention your actual customers.
- Guaranteed outcomes — nobody can guarantee an inspection result; the claim itself signals unseriousness.
- No sector footprint — DPMS, real estate and CSP programmes differ materially; ask what the provider has built in your category.
- Registration-only offers — goAML registration without the programme behind it satisfies one obligation of ten.
- No answer to “who runs it in month four?” — the programme is a routine, and routines need named owners; a consultant with no ongoing model is handing you a binder and a wave.
Where Velmont Crest fits in
We approach AML from an unusual seat: as accountants, we are DNFBPs under the same regime we advise on, inspected against the same standards — our own programme is not theoretical. Our AML compliance services cover the build (EWRA, tailored policies, goAML registration, CDD workflows, training) and the run (file reviews, screening routines, renewal cycles, mock inspections) — the full span of AML advisory services — for real estate, precious metals, CSP and professional-services businesses across the UAE.
Because the same team often keeps the client’s books, the AML programme sits on transaction data we already reconcile monthly — which is exactly where unusual patterns actually surface. If an inspection notice has arrived, or you would rather build before one does, start through the contact page — scoped quote within one UAE business day.
Disclaimer: Velmont Crest is a DED-licensed UAE accounting firm providing advisory, preparation and compliance support services. We are not a law firm and we do not represent clients before the Ministry of Economy and Tourism, the UAE Central Bank, the Financial Intelligence Unit or any court. AML obligations, supervisory practice and penalty schedules change — verify every figure against the current official text before acting, and take licensed legal advice on any enforcement matter.
References
- UAE Legislation Portal — Federal Decree-Law No. 10 of 2025 on Anti-Money Laundering, Combating the Financing of Terrorism and Proliferation Financing
- UAE Legislation Portal — Cabinet Resolution No. 134 of 2025, Executive Regulations of Federal Decree-Law No. 10 of 2025
- UAE Ministry of Economy and Tourism — combatting money laundering and terrorism financing, DNFBP supervision
- UAE Financial Intelligence Unit — AML/CFT laws and related decisions
- Central Bank of the UAE Rulebook — Federal Decree-Law No. 10 of 2025
Frequently asked questions
- What are AML consulting services?
- Professional support to build and run the anti-money-laundering programme UAE law requires of your business: assessing your exposure (enterprise-wide risk assessment), writing policies and procedures that fit your actual operations, setting up goAML registration and reporting, designing customer due diligence and sanctions-screening workflows, training staff and the compliance officer, and preparing for supervisory inspections. Good engagements transfer capability; weak ones deliver templates.
- Who needs AML compliance in the UAE?
- Beyond banks and financial institutions: the DNFBP categories — real estate agents and brokers, dealers in precious metals and precious stones, auditors and accountants, and trust and corporate service providers — carry full obligations under Federal Decree-Law No. 10 of 2025 (which replaced Federal Decree-Law No. 20 of 2018), supervised largely by the Ministry of Economy and Tourism (financial free zones have their own supervisors). Registration in goAML, a compliance officer, risk assessment, CDD and reporting apply to a two-person brokerage as much as a bank.
- What is goAML and do I need to register?
- goAML is the UAE Financial Intelligence Unit's platform through which regulated entities file suspicious transaction and activity reports and receive notices. Every in-scope financial institution and DNFBP must register and maintain its profile — operating without registration is itself a violation with published fines. Registration involves documentation of the entity and its compliance officer; our goAML registration guide walks the portal steps.
- What does an AML compliance officer / MLRO do?
- The named individual accountable for the programme: approving high-risk relationships, reviewing alerts and deciding whether to file STRs through goAML, maintaining the risk assessment and policies, delivering training and facing the supervisor at inspection. UAE rules require the appointment; the person needs seniority, competence and independence. Smaller DNFBPs often struggle to staff it internally — which is where structured external support for the function's routine work earns its keep, with accountability staying in-house.
- What are the penalties for AML non-compliance in the UAE?
- Article 17(1)(b) of Federal Decree-Law No. 10 of 2025 lets a Supervisory Authority impose an administrative fine of not less than AED 10,000 and not more than AED 5,000,000 for each violation, alongside warnings, sector bans, restrictions on directors, suspension of the activity and licence revocation. A criminal court convicting a legal person of money laundering faces a different range under Article 27(1) — AED 5,000,000 to AED 100,000,000, or the value of the criminal property if greater. The two get conflated in marketing. Article 39 leaves the schedule of specific violations and matching fines to a Cabinet resolution, so no per-violation figure is published under the 2025 framework yet.
- How much do AML consulting services cost in the UAE?
- Scope decides it. A gap assessment for a single-office brokerage is a different engagement from a group-wide programme build with screening-tool implementation and year-round support. The drivers: your sector's inherent risk, customer volume and geography, entity count, how much programme already exists, and whether you want one-off build or ongoing operation. Ask any provider to quote against a written scope with deliverables named — and be suspicious of flat-fee 'full compliance' packages.
- How do I choose between AML consulting firms in the UAE?
- Compare on four things: sector footprint (ask what the firm has built in your DNFBP category — a DPMS programme is not a brokerage programme), the CVs of who actually does the work, a written scope with named deliverables, and a clear answer to who runs the programme in month four. Treat guaranteed-outcome claims and flat-fee 'full compliance' packages as disqualifying — no consultant can guarantee an inspection result, and the framework does not permit anyone to carry your accountability.
- What is an EWRA and why do inspectors ask for it first?
- The enterprise-wide risk assessment — your documented analysis of how money-laundering and terrorist-financing risk actually enters your business: customer types, products, delivery channels, geographies — and the controls you apply against each. It is the foundation the risk-based approach stands on, which is why supervisors open with it: a business that cannot show its EWRA has, by definition, no basis for any of its other controls. It must be refreshed as the business changes.
Filed under: AML, CFT, goAML, DNFBP, Compliance Officer, EWRA, Consulting, UAE
Published · Updated