Insights AML
Auditor AML UAE 2026: The DNFBP Programme Inspectors Expect
Auditor AML programme UAE — DNFBP scope under Federal Decree-Law 10/2025, MLRO appointment, goAML registration and the STR triggers for auditors.
Key takeaways
- Independent accountants and auditors are DNFBPs under Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025
- Audit firm AML obligation is separate from the ISA-based engagement and the ICV or financial-statement scope
- Independence rules under the IESBA Code interact with, but do not override, DNFBP obligations
- Engagement-level risk assessment runs alongside the firm-level Business Risk Assessment
- Suspicions arising during audit work are escalated to the MLRO under the no-tipping-off rule
- MoET Auditors Register status does not exempt the firm from goAML registration
A UAE auditor AML programme is the discipline sitting underneath every engagement acceptance, every fieldwork team and every audit opinion an external audit firm issues. Every UAE-registered external auditor, whether listed on the UAE Ministry of Economy and Tourism Auditors Register for mainland practice or operating under a free zone audit licence, is a Designated Non-Financial Business and Profession under UAE law.
The UAE Ministry’s own Supplemental Guidance for Independent Accountants and Auditors states the position without qualification: pursuant to Federal Decree-Law No. 10 of 2025 and its Executive Regulations, Cabinet Resolution No. 134 of 2025, independent accountants fall under the DNFBP category. That triggers the full AML/CFT/CPF programme: a documented Business Risk Assessment, engagement-level risk assessments, an appointed MLRO, goAML registration through the UAE Financial Intelligence Unit, CDD on every audit client, ongoing screening, and STR filing without tipping off.
This guide walks through the scope, the AML programme template a mainland or free zone audit firm needs in 2026, the engagement-acceptance risk discipline, the red-flag indicators the UAE Ministry actually publishes, and what your external AML compliance adviser is expected to prepare behind the scenes.
Why the Ministry watches audit firms so closely
UAE external auditors have line-of-sight to client transactions, related-party arrangements, ownership structures and source-of-funds explanations that no other DNFBP sees. The Ministry of Economy and Tourism puts it in its own words: independent accountants and auditors are uniquely placed at the core of an establishment’s financial reporting and governance processes, which lets them identify AML/CFT/CPF weaknesses and detect potentially suspicious activity, while the nature of the services they provide exposes the UAE sector to potential misuse by criminals seeking to obscure ownership and control of assets.
That is not an abstract concern. The UAE Ministry publishes its enforcement numbers in AED.
Table 1 — MoET DNFBP inspection results, first half of 2025. Every figure below was read from the Ministry of Economy and Tourism announcement dated 24 July 2025, on 4 August 2026.
| Sector | Violations | Penalties |
|---|---|---|
| Precious metals and gemstones traders | 473 | AED 20 million |
| Real estate brokerages | 495 | AED 18.5 million |
| Corporate service providers and auditors | 95 | Over AED 4 million |
| All DNFBP categories combined | 1,063 | Over AED 42 million |
Ninety-five UAE violations against corporate service providers and auditors in a single half-year is the number that ought to reset a UAE audit firm’s sense of how theoretical this obligation is.
The DNFBP scoping language captures:
- Mainland audit firms registered on the MoET Auditors Register
- Free zone audit firms licensed by DMCC, ADGM, DIFC, RAKEZ or other free zone authorities
- Sole-practitioner auditors with even a single registered engagement
- Tax consultants and tax agents registered with the FTA — see our Velmont Crest UAE accountant guide for related-profession context
- Accounting consultancies providing assurance-equivalent work
The firm size, the number of partners and the engagement count do not change the obligation. A sole practitioner with two audit clients faces the same registration requirement as a mid-tier firm with two hundred engagements. That feels unfair to the small practices, and we hear that complaint often — but the FATF logic is that a single bad engagement at a two-client shop is exactly as much of a laundering channel as one at a big firm.
Velmont Crest is a Dubai-based, DED-licensed accounting firm supporting AML compliance and audit-readiness work for DNFBPs across mainland and free zone setups. We are not ourselves a licensed audit firm; we work alongside licensed external auditors to prepare AML programmes and inspection-readiness files.
How the UAE rates the risk of the audit sector
Before designing a UAE programme it helps to know what the supervisor already thinks of your sector, because the Ministry has written it down.
Drawing on the 2024 UAE National Risk Assessment and its own 2024 Sectoral Risk Assessment, the Ministry categorises the independent accountant and auditor sector as presenting a medium level of inherent money laundering risk, with a medium-low residual risk. The residual rating reflects the sector’s gatekeeping role and what the Ministry calls the generally strong regulatory and professional standards governing it.
The UAE vulnerabilities it names are specific. Potential misuse of professional services to facilitate money laundering through the layering of illicit funds. Concealment of beneficial ownership. Use of complex cross-border corporate structures. The Ministry also notes that the sector has not been widely associated with systemic abuse for terrorist financing, which is a useful piece of proportionality when a small UAE practice is deciding how much programme it actually needs.
Table 2 — The Ministry’s own risk framing. Every row below was read from the MoET Supplemental Guidance for Independent Accountants and Auditors, April 2026, on 4 August 2026.
| Dimension | Ministry position |
|---|---|
| Inherent ML risk | Medium at aggregate sector level |
| Residual ML risk | Medium-low |
| TF association | Not widely associated with systemic abuse for terrorist financing |
| Named vulnerabilities | Layering of illicit funds; concealment of beneficial ownership; complex cross-border corporate structures |
| Elevating factors | Corporate customers with complex ownership, cross-border transactions, diverse geographic exposure |
| Sources | 2024 UAE National Risk Assessment and MoET 2024 Sectoral Risk Assessment |
5 years
Minimum AML record retention for a UAE audit firm, measured from the latest of four trigger events set out in the MoET Supplemental Guidance for Independent Accountants and Auditors
The seven obligation heads, straight from the Ministry
Most AML checklists circulating among UAE audit firms are somebody’s paraphrase. The UAE Ministry’s own summary of obligations is short enough to reproduce, and building a programme against it means every element traces to a published expectation rather than a consultant’s opinion.
Table 3 — AML/CFT/CPF obligation heads for an audit firm. Every row below was read from the MoET Supplemental Guidance for Independent Accountants and Auditors, section 1.4, on 4 August 2026.
| Obligation head | What the Ministry requires |
|---|---|
| Compliance administration | An adequate governance framework: a qualified Compliance Officer or MLRO, staff training and screening mandates, independent audit of the AML framework, and senior management oversight. Group entities implement group-wide programmes |
| Risk identification and assessment | Identify, assess and document ML, TF and PF exposure through a Business Risk Assessment proportionate to the nature, size and complexity of the firm |
| Policies, procedures and internal controls | Establish, document, implement and regularly update policies tailored to the business model, with explicit measures to mitigate identified risks |
| Customer due diligence and ongoing monitoring | Risk-based CDD covering identification and verification of customers and beneficial owners, purpose of the relationship, customer risk profiles and EDD where higher risks arise |
| Sanctions compliance | Comply with UAE competent-authority directives on UN Security Council Resolutions, terrorism lists, targeted financial sanctions and proliferation financing controls |
| Suspicious activity or transaction reporting | Identify and promptly report suspicion; timeliness and quality of reports are named supervisory focus areas for this sector |
| Record-keeping | Comprehensive records of transactions, CDD, correspondence and analysis outcomes, retained per the Executive Regulations |
One sentence in that section deserves lifting out on its own, because it corrects the most common design error in UAE audit firm programmes. The Ministry says entities must apply a risk-driven CDD and EDD measure as opposed to a threshold-driven measure, so that reliance on transaction value alone does not result in the overlooking of material risk indicators. A small-fee engagement is not automatically a low-risk engagement.
Six pieces inspectors actually check
A defensible UAE audit firm programme has six interlocking components. Inspectors look for all six on a UAE Ministry on-site visit. Together they form the baseline standard of AML compliance UAE inspectors now expect from every registered audit practice, and they anchor the firm’s written AML policies and procedures, from the policy manual down to the engagement checklists.
1. The firm-wide Business Risk Assessment
The UAE audit firm BRA scores firm-level exposure across five dimensions: client risk (sectors audited, ownership profiles, PEP exposure across the client base), service risk (statutory audit, voluntary audit, IFRS reviews, agreed-upon procedures), geographic risk (jurisdictions of audit clients and their counterparties, FATF high-risk corridors), delivery channel risk (in-person fieldwork versus remote engagements onboarded through intermediaries) and transaction risk (deal-size patterns in the audited population, cash exposure of audit clients). The BRA is refreshed at least annually and whenever the firm adds a new practice area or industry specialism.
2. Where most audit firms slip — engagement scoring
This is what distinguishes a defensible UAE audit firm AML programme. Every new engagement acceptance and every continuance decision triggers a documented AML risk assessment that scores:
- Client type, whether a listed entity, private company, state-related entity or family office
- Sector, where the high-risk ones include cash-intensive retail, gold and jewellery, real estate, virtual asset providers and money services
- Ownership, from single-tier through to multi-tier corporate structures, PEP exposure and nominee arrangements
- Geography, from UAE-only operations to cross-border counterparties and FATF high-risk jurisdictions
- Reputational signals such as adverse media, regulatory enforcement history and prior auditor resignations
- Source of capital, with a documented evidence trail for the share capital, recent injections and related-party loans
The scoring assigns each UAE engagement to a low, standard, high or enhanced-risk band, and that band drives the level of CDD, the audit team seniority and the audit-firm risk-committee review.
3. CDD that actually traces UBOs
Standard CDD for a UAE audit client collects: trade licence, MoA, registered office address, list of directors and authorised signatories, identification for senior management contacts and every Ultimate Beneficial Owner above the 25 percent threshold under Cabinet Decision No. 58 of 2020. Enhanced Due Diligence layers on documentary source-of-wealth evidence for UBOs, partner-level sign-off on engagement acceptance, ongoing transaction monitoring during fieldwork and periodic re-screening.
4. Sanctions and PEP screening, on a calendar
Every UAE audit client, every UBO, every authorised signatory and every key management contact is screened against the UAE Local Terrorist List, the UN Security Council Consolidated Sanctions List, the OFAC Specially Designated Nationals list and adverse-media databases. Screening is captured in writing with source, date, reference and clearance decision. Re-screening runs at engagement acceptance, before opinion sign-off and whenever a relevant list is materially updated.
The Ministry routes the operational detail elsewhere, and it is worth following the pointer. Its guidance directs independent accountants and auditors to the full targeted financial sanctions guidelines issued by the Executive Office for Control and Non-Proliferation, which detail obligations under Cabinet Decision No. 74 of 2020, including screening, freezing and reporting in relation to designated persons or entities.
5. Appointing the MLRO and getting on goAML
The UAE MLRO is appointed in writing before the goAML registration is submitted. The MLRO has direct authority to file STRs without obtaining permission for each filing and reports straight to senior management or the audit-firm risk committee. The firm then completes the Ministry’s AML supervisory registration, the goAML enrolment and the linked EmaraTax records. See our goAML registration guide for the step-by-step portal walkthrough.
6. Training, five-year retention, annual filing
All audit staff and management complete annual AML training documented with attendance logs. Training is role-specific — engagement partners on acceptance risk, audit managers on fieldwork red flags, junior staff on escalation.
Retention is where UAE firms most often guess, so it is worth being exact.
Table 4 — When the five-year retention clock starts. Every row below was read from the MoET Supplemental Guidance for Independent Accountants and Auditors, section 1.4, on 4 August 2026. Records are retained for at least five years from the latest of these events.
| Trigger event |
|---|
| The termination of a business relationship or closure of a customer account |
| Completion of an occasional transaction where no business relationship exists |
| The issuance of a final judgment by a competent judicial authority |
| Dissolution, liquidation, or termination of a legal person or arrangement |
The UAE Ministry adds a quality standard alongside the period. Records must be retained in an orderly manner that allows effective analysis and tracing of financial activities, must be sufficient to reconstruct transactions in a way that can support investigations or serve as evidence in legal proceedings, and must be readily available to competent authorities on request without undue delay.
Where independence and AML pull against each other
The IESBA Code of Ethics for Professional Accountants prohibits external auditors from providing certain non-assurance services to their audit clients where the independence threats cannot be reduced to an acceptable level. The Ministry’s guidance points the same way, noting that professional accountants should also consider their ethical obligations under the Code of Ethics issued by IFAC, referencing the 2022 handbook. AML obligations sit alongside independence — they do not override it and are not overridden by it.
Table 5 — What an audit firm can and cannot do for its own audit clients. This table sets out our reading of how the IESBA independence framework interacts with the DNFBP obligations. It is our analysis, not quoted text from either instrument.
| Activity | Position |
|---|---|
| Perform CDD on its own audit clients | Permitted — CDD is part of engagement acceptance |
| Run sanctions and PEP screening on its own audit clients | Permitted |
| File STRs through goAML on its own audit clients | Permitted, and required where reasonable grounds for suspicion arise |
| Provide outsourced MLRO services to its own audit clients | Not appropriate under independence rules |
| Draft an audit client’s own AML policy manual | Not appropriate where threats cannot be safeguarded |
| Deliver AML advisory to non-audit clients | Permitted, typically through a separate advisory arm |
A UAE audit firm typically separates AML services for non-audit clients, delivered through a dedicated advisory arm or a separate consultancy, from AML services for audit clients, which are limited to the firm’s own DNFBP compliance rather than the client’s.
Red flags the Ministry actually publishes
Most red-flag lists in circulation are invented. The UAE Ministry publishes its own, and it is far more specific about audit work than the generic DNFBP versions.
Table 6 — Red-flag indicators for independent accountants and auditors. Every row below was read from the MoET Supplemental Guidance for Independent Accountants and Auditors, section 6, on 4 August 2026. The Ministry notes the list is not exhaustive and that one indicator does not automatically imply a crime.
| Category | Indicator |
|---|---|
| Concealing the UBO | Use of companies, trusts or bearer shares to obscure beneficial ownership |
| Concealing the UBO | Use of professional intermediaries, trustees or nominee shareholders to provide the appearance of legitimacy |
| Concealing the UBO | Multi-jurisdictional structures created to disguise beneficial ownership |
| Concealing the UBO | Changing the ownership without notifying the accountant of the changes made |
| Lack of transparency | Refusal to co-operate or provide information, data and documents usually required to facilitate an audit |
| Lack of transparency | Inability or refusal to explain the business activity, the identity of beneficial owners, or the source of wealth and funds |
| Lack of transparency | Requesting the auditor to accept management representations without evidence, or to exclude accounts, transactions or jurisdictions from scope |
| Lack of transparency | Unusual requests, including those relating to secrecy, made of the accountant or its employees |
| High-risk associations | The entity or any UBO appears on a sanctions list or international list |
| High-risk associations | Funds originating from or transiting jurisdictions with high tax secrecy or weak enforcement |
| Entity behaviour | Cannot demonstrate a history or provide evidence of real activity |
| Entity behaviour | Suddenly becomes active after a long period of dormancy without a logical explanation |
| Entity behaviour | Registered at an address listed against numerous other companies, indicating a mailbox service |
| Entity behaviour | Directors or controlling shareholders who cannot be located or contacted |
| Transaction patterns | Unusual number or frequency of transactions in a relatively short period |
| Transaction patterns | Disposal of assets under unusual conditions involving unnecessary expense or losses without explanation |
Several of these map onto the classic three stages of money laundering — placement, layering and integration. Unexplained cash deposits sit at the placement stage, round-tripping through related entities is textbook layering, and capital injections that cannot be evidenced often mark integration back into the legitimate books.
What the audit team should escalate
- Audit evidence contradicts the management explanation for a material transaction
- Unexplained material misstatement that does not appear to be error
- Related-party transactions without apparent commercial purpose
- Source of significant capital injections cannot be evidenced
- Apparent round-tripping of funds through related entities
- Pressure on the audit team to overlook documentary anomalies
- Sudden changes to year-end balances after audit fieldwork begins
- Repeated changes of CFO, finance director or in-house auditor over short periods
When any of these triggers appear, the audit team escalates to the MLRO without tipping off the audit client. The MLRO assesses the case, requests further information through the engagement partner where appropriate, and files the STR through goAML if the reasonable-grounds threshold is met. The Ministry flags timeliness and quality of STRs as continuing supervisory focus areas for this sector specifically.
The single most defensible record a UAE audit firm can keep is the engagement-acceptance risk memo refreshed at each continuance decision. A client accepted at standard risk three years ago may now sit in an enhanced-risk band because a new UBO has emerged or sanctions exposure has changed. The continuance memo is what proves the firm reassessed — not just renewed.
Which services put an audit firm in scope
UAE audit firms sometimes assume only the statutory audit engagement carries the AML load. The Ministry’s guidance quotes the FATF Risk-Based Approach Guidance for the Accounting Profession and lists a much wider set of services as potential exposure points.
Table 7 — Services identified as ML/TF/PF exposure points. Every row below was read from the MoET Supplemental Guidance for Independent Accountants and Auditors, section 2.1, on 4 August 2026, which reproduces the FATF 2019 list. The Ministry notes that inclusion of a service does not imply every such service falls within the IAA sector.
| Service |
|---|
| Audit and assurance services, including reporting accountant work in initial public offerings |
| Book-keeping and the preparation of annual and periodic accounts |
| Tax compliance work and tax advice |
| Trust and company services |
| Internal audit as a professional service, and advice on internal control and risk management |
| Regulatory and compliance services, including outsourced examinations and remediation |
| Company liquidation, insolvency, receiver-manager and bankruptcy related services |
| Advice on structuring transactions, corporate structuring, cross-border arrangements and ownership structures |
| Due diligence in relation to mergers and acquisitions |
| Advice on investments and custody of customer money |
| Forensic accounting |
The Ministry also names three audit-specific functions that carry the obligation: financial audits of a customer’s books, records and periodic accounts; operational audits of internal controls, governance and risk management; and compliance audits of a customer’s adherence to legal and regulatory requirements.
There is a point buried in that section that few UAE firms have absorbed. The UAE Ministry observes that independent accountants and auditors receive professional fees from their customers, which could themselves represent the proceeds of crime. Your own fee income is inside the risk perimeter.
Where audit firm programmes keep failing
After enough inspection-readiness reviews you start seeing the same handful of gaps, almost in the same order. None of them is exotic. They are the bits that get skipped because they feel like paperwork rather than risk.
The most common one is engagement acceptance without documented risk scoring. Plenty of UAE firms run a strong opening CDD process but leave the scoring implicit, and inspectors expect a written risk memo for every new engagement and every continuance decision.
Close behind it is over-reliance on management representation letters. A representation letter is audit evidence, not AML CDD evidence, and the DNFBP obligation requires documentary verification of beneficial ownership rather than a client’s confirmation. The Ministry’s own red-flag list treats a customer who asks the auditor to accept management representations without evidence as an indicator in its own right.
Then there is the UAE MLRO without operational authority. An MLRO who needs partner approval to file an STR is not an MLRO in the statutory sense, because the role requires direct authority to file without permission.
Sanctions screening only at acceptance is another. The lists update continuously, so a firm that screens once at acceptance and never refreshes is one list update away from an active audit relationship with a sanctioned UBO. Training collapsed into a single annual session fails the same way, since audit fieldwork red flags need role-specific training for junior, senior and manager staff.
Last is the missing separation between firm AML and client AML services, where advising an audit client on their own AML programme without satisfying independence safeguards becomes an enforcement risk on both sides.
Table 8 — The eight gaps we see most, and the evidence that closes each. This table is Velmont Crest practice rather than a published Ministry checklist.
| Gap | Evidence that closes it |
|---|---|
| Engagement acceptance without documented scoring | A signed risk memo per acceptance and per continuance |
| Continuance treated as renewal | A dated reassessment showing what changed since last year |
| Representation letter used as CDD | Documentary UBO verification held on file |
| MLRO without filing authority | Written appointment granting direct authority to file |
| Screening only at acceptance | A screening log with source, date, reference and clearance |
| One-size training session | Role-specific attendance logs for partners, managers and juniors |
| No independent review of the AML framework | An independent audit of the programme, per the compliance administration head |
| Firm AML and client AML services blurred | A written service-line separation with independence sign-off |
How the penalty regime works
Administrative penalties for UAE DNFBPs supervised by the Ministry of Economy and Tourism and the Ministry of Justice sit in Cabinet Resolution No. 71 of 2024, issued 8 July 2024 and published in English by the Ministry itself. Article 8 repealed the previous schedule in Cabinet Resolution No. 16 of 2021. Article 2 applies it to DNFBPs under Ministry oversight, and Article 3 gives the Ministry — Justice or Economy, as the case may be — the power to impose the fine. It is not the FIU or the Central Bank that fines an audit firm.
The list annexed to the Resolution sets 41 violations with fines from AED 50,000 to AED 1,000,000, each charged per violation. The ones an audit firm meets most often: failing to register on the electronic system approved by the FIU, meaning goAML, is item 23 at AED 50,000 to AED 200,000; failing to appoint a competent compliance officer is item 24 at AED 50,000 to AED 200,000; failing to run customer due diligence before accepting an engagement is item 9 at AED 50,000 to AED 200,000; and failing to submit a suspicious transaction report to the FIU promptly is item 22 at AED 100,000 to AED 500,000. Article 5(2) allows the Ministry to double the fine where a violation is repeated, and Article 5(3) preserves the non-financial sanctions in Article 17 of the Decree-Law alongside it.
One point of law is worth stating plainly, because it is easy to get wrong. Cabinet Resolution No. 71 of 2024 was issued under the 2018 AML law and its 2019 Executive Regulations, and its legal-reference column still cites those articles. Both have since been replaced. It nonetheless remains in force: Article 41(3) of Federal Decree-Law No. 10 of 2025 keeps the regulations and resolutions issued under the 2018 law effective, so far as they do not conflict with the new Decree-Law, until superseding instruments are issued.
No replacement schedule had been issued at the time of writing, and the Ministry of Economy and Tourism still publishes Cabinet Resolution No. 71 of 2024 in its AML legal framework. The fines also sit inside the statutory band in Article 17(1)(b) of the new Decree-Law, which runs from AED 10,000 to AED 5,000,000 per violation.
Alongside the schedule, the Ministry’s published enforcement outcome gives the practical measure: 1,063 violations and more than AED 42 million in penalties across the DNFBP sector in the first half of 2025 alone, of which 95 violations and over AED 4 million fell on corporate service providers and auditors. Penalty schedules do get amended — Article 6 reserves that power to the Cabinet — so confirm the current bands with the Ministry of Economy and Tourism before relying on a figure for a specific case.
Where this leaves your audit firm
If your firm has not yet finished a firm-level Business Risk Assessment, drafted engagement-acceptance risk templates, or registered an MLRO on goAML, you are operating outside the federal AML/CFT framework, whether you sit on the MoET Auditors Register or on a free zone audit licence.
If you have a manual but it has not been refreshed against current Ministry expectations, the gap usually sits in three places: engagement-level risk scoring is implicit rather than documented, continuance decisions do not generate a refreshed risk memo, and sanctions re-screening is not running between acceptance and opinion sign-off. A fourth is now worth adding — few UAE firms have re-papered their manual against Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025, and a manual still citing the 2018 law reads as stale on an inspection day.
Velmont Crest’s UAE compliance team provides advisory support across the audit firm DNFBP programme lifecycle — from Business Risk Assessment through engagement-acceptance methodology, MLRO appointment support, goAML registration assistance, policy drafting and inspection-readiness reviews. It is the same AML compliance service we run for other DNFBP categories, tuned to the independence constraints an audit firm works under. That distinction matters when comparing AML consulting services, because an audit firm’s programme has to respect IESBA independence limits that a generic template ignores.
We pair this with bookkeeping and audit assistance work for non-audit clients so the AML evidence trail aligns with the underlying financial records. We are a DED-licensed UAE accounting firm and authorised channel partner with Meydan Free Zone and RAKEZ.
For a clean review of where your audit firm AML programme stands today, book a free consultation.
Disclaimer: Velmont Crest is a DED-licensed accounting firm. We provide advisory, preparation and compliance support services. We are not a licensed external audit firm, MLRO of record or FTA tax agent. AML/CFT rules and DNFBP obligations change frequently — verify all requirements with the UAE Financial Intelligence Unit, the Ministry of Economy and Tourism and your sector regulator, and engage a licensed legal or AML professional for advice specific to your circumstances.
References
- UAE Ministry of Economy and Tourism — Supplemental Guidance for Independent Accountants and Auditors (April 2026)
- UAE Ministry of Economy and Tourism — H1 2025 DNFBP inspection results (24 July 2025)
- UAE Ministry of Economy and Tourism — register in goAML
- UAE Ministry of Economy and Tourism — does your company fall under the DNFBP definition
- UAE Financial Intelligence Unit — goAML portal
- Federal Decree-Law No. 41 of 2023 on the Regulation of the Accounting and Auditing Profession — UAE Ministry of Economy and Tourism
Frequently asked questions
- Is every UAE auditor a DNFBP under the AML rules?
- Yes, and there is no size cutoff. The MoET Supplemental Guidance for Independent Accountants and Auditors states that pursuant to Federal Decree-Law No. 10 of 2025 and its Executive Regulations, Cabinet Resolution No. 134 of 2025, independent accountants fall under the DNFBP category. The guidance applies to sole practitioners as well as members and employees of firms engaged primarily in audit and accounting-related services, established or operating in the UAE and Commercial Free Zones.
- Do auditor independence rules affect the AML obligation?
- They sit side by side rather than cancelling each other out. Independence rules under the IESBA Code stop an audit firm from providing certain non-assurance services to an audit client where threats cannot be safeguarded. AML rules pull the other way: run CDD, screen for sanctions, score engagement-level risk, and file STRs through goAML where reasonable grounds for suspicion exist. Neither overrides the other, so an auditor cannot dodge the AML work by pointing at independence.
- What client matters trigger an STR filing in an audit firm?
- The MoET red-flag list includes a customer who refuses to co-operate or provide information usually required to facilitate an audit, who is unable or refuses to explain the business activity, the identity of beneficial owners or the source of wealth and funds, and who requests the auditor to accept management representations without evidence or to exclude certain accounts, transactions or jurisdictions from scope. The compliance officer assesses whether the activity is genuinely suspicious before filing.
- Does an MoET-registered auditor still need separate goAML registration?
- Yes, they are two different things. The Ministry of Economy and Tourism Auditors Register is a professional licensing record and has nothing to do with AML status. The DNFBP obligation needs its own goAML registration through the UAE Financial Intelligence Unit, alongside the Ministry's own AML supervisory record. Holding one does not satisfy the other, and inspectors check for both.
- What does an external AML adviser actually do for a UAE audit firm?
- Mostly the build-out and the upkeep. A specialist adviser drafts the Business Risk Assessment, prepares engagement-acceptance and continuance risk templates, builds the CDD procedure including UBO tracing, supports MLRO appointment and goAML registration, and keeps it running with annual training and inspection-readiness reviews. What the adviser does not do matters just as much: they are not your MLRO, they do not file STRs for you, and they do not perform the audit work.
- What does AML/CFT mean?
- AML stands for anti-money laundering and CFT for combating the financing of terrorism. UAE material increasingly uses AML/CFT/CPF, adding countering proliferation financing. The framework sits in Federal Decree-Law No. 10 of 2025 and its Executive Regulations under Cabinet Resolution No. 134 of 2025, supervised for auditors by the Ministry of Economy and Tourism. In practice it means a Business Risk Assessment, engagement-level risk scoring, CDD and sanctions screening, an appointed MLRO, goAML registration and STR filing without tipping off.
- What are the three stages of money laundering?
- Placement, layering and integration. Placement is when illicit cash first enters the financial system, such as unexplained cash deposits in a customer account. Layering moves funds through transactions designed to obscure their origin, and round-tripping through related entities is a textbook example. Integration is when the money re-enters the legitimate economy looking clean. The MoET guidance identifies layering of illicit funds, concealment of beneficial ownership and complex cross-border structures as the sector's main vulnerabilities.
- Who must register on goAML in the UAE?
- Every entity the UAE AML framework supervises: licensed financial institutions and all Designated Non-Financial Businesses and Professions. On the DNFBP side that includes external auditors and audit firms, accounting and tax practices, real estate agents and brokers, dealers in precious metals and stones, and corporate service providers, whether mainland or free zone licensed. Registration runs through the UAE Financial Intelligence Unit's goAML portal and is expected before the firm starts delivering in-scope services.
- How long must an audit firm keep its AML records?
- The MoET Supplemental Guidance says records are to be retained for at least five years from the latest of four events: the termination of a business relationship or closure of a customer account; completion of an occasional transaction where no business relationship exists; the issuance of a final judgment by a competent judicial authority; or the dissolution, liquidation or termination of a legal person or arrangement. Records must be sufficient to reconstruct transactions.
- How risky does the UAE consider the audit sector?
- The MoET Supplemental Guidance, drawing on the 2024 UAE National Risk Assessment and the Ministry's own 2024 Sectoral Risk Assessment, categorises the independent accountant and auditor sector as presenting a medium level of inherent money laundering risk with a medium-low residual risk. It notes the sector has not been widely associated with systemic abuse for terrorist financing, but flags corporate customers with complex ownership, cross-border transactions and diverse geographic exposure as live risk factors.
- What are the seven AML obligation heads for an audit firm?
- The MoET Supplemental Guidance lists compliance administration, risk identification and assessment, policies, procedures and internal controls, customer due diligence and ongoing monitoring, sanctions compliance, suspicious activity or transaction reporting, and record-keeping. Each maps to a numbered section of the Ministry's Guidelines for Designated Non-Financial Businesses and Professions, so an audit firm can trace every element of its programme back to a published expectation.
- Are CDD requirements triggered by transaction value?
- No, and the MoET guidance is explicit about it. It states that entities must apply a risk-driven CDD and EDD measure as opposed to a threshold-driven measure, so that reliance on transaction value alone does not result in the overlooking of material risk indicators. An audit engagement with a modest fee can still sit in an enhanced-risk band because of ownership, geography or sector.
- What are the targeted financial sanctions obligations?
- The MoET Supplemental Guidance directs independent accountants and auditors to the full targeted financial sanctions guidelines issued by the Executive Office for Control and Non-Proliferation, which detail obligations under Cabinet Decision No. 74 of 2020, including requirements for screening, freezing and reporting in relation to designated persons or entities. All operational and procedural TFS requirements remain governed by the EOCN guidelines rather than by the Ministry's own guidance.
- Is the MoET guidance itself legally binding?
- It is guidance rather than legislation. The Ministry states that the document does not constitute additional legislation or regulation and does not replace or supersede any legal or regulatory requirements, and that where there is a discrepancy between the guidance and the frameworks in force, the frameworks prevail. It also explains its own drafting convention: requirements marked shall or must are compulsory, while should signifies recommended practice unless a recorded, risk-based justification supports an alternative.
Filed under: AML compliance, DNFBP, auditor, MLRO, goAML, audit firm
Published · Updated