Skip to content

Insights AML

Corporate Service Provider UAE AML Programme and goAML Registration

Corporate service provider AML in the UAE — goAML registration, MLRO appointment, CDD and STR filing support for formation agents, 2026.

UAE corporate service provider compliance team mapping beneficial owners and reviewing AML policy ahead of goAML registration with the Financial Intelligence Unit
UAE corporate service provider compliance team mapping beneficial owners and reviewing AML policy ahead of goAML registration with the Financial Intelligence Unit Photo: Velmont Crest Editorial

Key takeaways

  1. CSPs are scoped DNFBPs under FDL 10/2025 and CR 134/2025 — which repealed FDL 20/2018 and CD 10/2019 — regardless of mainland or free zone licence type
  2. Registered agents handling Beneficial Ownership filings must register on goAML through MoE SACM
  3. CDD applies to the incorporating client AND every UBO above the 25 percent threshold
  4. EDD triggers for PEP exposure, opaque ownership chains and FATF high-risk jurisdictions
  5. Sanctions screening against OFAC, UN consolidated, UK HMT and UAE Local Terrorist lists
  6. Five-year retention of CDD files, MLRO assessments and STR filings under Art. 25 of CR 134/2025

A UAE corporate service provider AML programme is where most of the ownership questions regulators care about get answered: who the beneficial owner really is, whether anyone in the chain is sanctioned or politically exposed, and where the formation money came from. Every UAE company formation agent, registered agent, PRO services firm, nominee directorship provider and registered office provider is a Designated Non-Financial Business and Profession (DNFBP) under Federal Decree-Law No. 10 of 2025 on anti-money laundering, countering the financing of terrorism and proliferation financing, and its Executive Regulations in Cabinet Resolution No. 134 of 2025.

Check which instrument your programme manual names before you read any further. The framework changed in late 2025. Federal Decree-Law No. 20 of 2018 was repealed outright by Article 41 of Federal Decree-Law No. 10 of 2025, issued 30 September 2025, and Cabinet Decision No. 10 of 2019 was repealed by Article 70 of Cabinet Resolution No. 134 of 2025, issued 29 October 2025. A CSP whose policy still cites the 2018 and 2019 instruments as the governing law is describing a framework that no longer exists, and that is precisely the kind of finding an inspector writes up. Both instruments were read from the UAE Legislation portal on 5 August 2026.

In practice that means a Business Risk Assessment, an appointed MLRO, goAML registration through the UAE Financial Intelligence Unit, CDD on every incorporation, and monitoring that continues for the lifetime of the registered-agent relationship.

This guide covers the scope, the AML programme template a Dubai, DMCC, JAFZA, ADGM or RAKEZ corporate service provider needs in 2026, the CDD layers, sanctions screening, common STR triggers, and what your external AML compliance adviser is expected to prepare behind the scenes. It is written for company formation agents UAE AML rules treat as front-line DNFBPs — the firms that incorporate, administer and register the country’s legal entities. If you would rather hand the build to a partner, our AML compliance support in the UAE covers the CSP programme end to end.

Because the acronyms do real work in this area, it helps to fix them once. AML is the full form of anti-money laundering, and the UAE framework is almost always written as AML/CFT — anti-money laundering and countering the financing of terrorism — because the two obligations travel together in the same law and the same portal. Money laundering itself means moving the proceeds of crime through legitimate-looking transactions until the origin is obscured, and a company formation is an attractive step in that chain precisely because a new legal entity carries no history.

That is the whole reason a CSP is regulated at all. KYC, or know your customer, is the identity layer most people have met at a bank; in the UAE AML rules the wider obligation is called customer due diligence, and CDD includes KYC but goes further into source of funds, ownership structure and purpose of the relationship. AML compliance in the UAE, for a CSP, is the documented system that ties all of that together and can be shown to an inspector.

Why the Ministry watches CSPs first

The Ministry of Economy treats corporate service providers as one of the highest-risk DNFBP categories, and the logic is hard to argue with: every UAE legal entity passes through a CSP at incorporation. That makes CSPs the gatekeepers for beneficial ownership transparency and the first line of defence against shell-company misuse. The FATF mutual evaluation of the UAE flagged CSP supervision as a priority, and on-site inspection activity has stepped up noticeably since 2023.

The DNFBP scoping language, now in Article 3 of CR 134/2025, captures by way of business:

  • Acting as a formation agent for legal persons (mainland LLCs, free zone companies, foundations, partnerships)
  • Acting as or arranging for another person to act as a director or secretary of a company or partner of a partnership
  • Providing a registered office, business address or accommodation for a company or other legal person
  • Acting as or arranging for another person to act as a trustee of an express trust
  • Acting as or arranging for another person to act as a nominee shareholder for another person

The scope catches the full UAE company-formation ecosystem — DMCC company set-up consultants, JAFZA registered agents, ADGM and DIFC corporate service providers, mainland incorporation specialists working with the Department of Economic Development, PRO services firms handling licence renewal and beneficial ownership filings, and registered office providers offering virtual or shared address services.

Velmont Crest is a DED-licensed accounting firm and an authorised channel partner with Meydan Free Zone and RAKEZ, supporting AML compliance for corporate service providers and other DNFBPs.

UAE corporate service provider compliance officer reviewing incorporation file beneficial ownership chain and source of funds evidence before client onboarding

Six pieces inspectors expect to find

A defensible UAE CSP programme has six interlocking components. Inspectors look for all six on a Ministry of Economy on-site visit.

1. Business Risk Assessment (BRA)

The CSP BRA scores firm-level exposure across five dimensions: customer risk (categories of incorporating clients, PEP exposure, complex ownership structures), product or service risk (formation work, registered agent services, nominee arrangements, trustee services), geographic risk (jurisdictions of incorporating clients and ultimate beneficial owners, FATF high-risk countries, sanctioned territories), delivery channel risk (face-to-face client meetings versus remote onboarding via intermediaries) and transaction risk (capital deployment patterns, source of funds, payment methods used at incorporation). The BRA is refreshed annually and whenever the CSP enters a new service line or jurisdiction.

2. Client and Entity Risk Matrix

A CSP matrix typically scores incorporation engagements across four bands:

  • Low risk — UAE-resident individual incorporator forming a single-shareholder operating company in a stable jurisdiction
  • Standard risk — established UAE entrepreneur forming a new operating subsidiary or holding company with documented capital
  • High risk — non-resident client from a medium-risk jurisdiction, multi-tier corporate ownership, registered office service without operational presence
  • Enhanced risk — PEP exposure in the ownership chain, FATF high-risk jurisdiction connection, nominee arrangements requested, opaque source of capital, refusal to disclose UBO

Each band determines whether standard CDD, enhanced due diligence (EDD), or refusal applies — our EDD vs CDD vs SDD guide breaks down which diligence tier attaches to each risk band. The matrix is reviewed at engagement opening and refreshed periodically across the lifetime of the registered-agent relationship.

3. CDD Across Three Layers

A CSP collects CDD across three layers that build on one another.

The first is the incorporating client: passport, Emirates ID for UAE residents, proof of residential address, occupation, source of funds for the formation, and evidence that identity has actually been verified.

The second is the legal entity being formed. Here you capture intended business activities, expected operating jurisdictions and counterparties, expected sources and uses of funds, expected payment methods, and the planned ownership and management structure.

The third is every ultimate beneficial owner — every natural person controlling 25 percent or more of the entity directly or indirectly, with identification, residency, PEP screening, a source-of-wealth narrative and supporting documentation. Where the ownership chain runs through multiple corporate layers, you trace upward until a natural person is identified. Where no natural person controls 25 percent under the ownership test, the senior managing official is recorded as the UBO under the alternative control test set out in Cabinet Decision No. 58 of 2020 on the Beneficial Owner Procedures.

4. Sanctions and PEP Screening

Every incorporating client and every UBO is screened against the UAE Local Terrorist List, the UN Security Council Consolidated Sanctions List, the OFAC Specially Designated Nationals list, the UK HM Treasury Consolidated List and adverse-media databases. Screening is captured in writing with source, date, reference and clearance decision. Re-screening runs whenever a list is materially updated and at least quarterly across the active client base.

5. MLRO Appointment and goAML Registration

The MLRO is appointed in writing before the goAML registration is submitted, and the sequence now has an extra step in front of it. Article 49(18) of Cabinet Resolution No. 134 of 2025 lists among the competences of supervisory authorities “maintaining an updated list of Compliance Officers of supervised entities, notifying the Unit thereof, and requiring such entities to obtain its prior approval before appointing their Compliance Officers”. Under the repealed Cabinet Decision No. 10 of 2019 this was permissive; the current text is framed as a supervisory competence to be exercised. Treat prior approval from your supervisory authority as a step to plan for rather than an afterthought, and confirm the current procedure with your own supervisor before you issue the appointment letter.

Article 22 sets the standard for the person appointed: a Compliance Officer “at management level and under their responsibility, who shall have independence in decision-making and possess appropriate competence and experience”. Neither Federal Decree-Law No. 10 of 2025 nor Cabinet Resolution No. 134 of 2025 names any specific qualification or certification, so a job specification that makes one mandatory is adding a requirement the law does not impose. The MLRO has direct authority to file STRs and reports straight to senior management.

The CSP then completes the SACM registration, the goAML enrolment through the UAE Financial Intelligence Unit and registration on the linked Automatic Reporting System for Sanctions Lists. See our goAML registration guide for the UAE for the step-by-step portal walkthrough, and our goAML annual renewal guide for keeping that registration current once it is live.

6. Training, Record Retention and Annual Reporting

All client-facing staff and management complete annual AML training documented with attendance logs. All CDD files, UBO records, MLRO assessments and STR filings are retained for not less than five years from the end of the registered-agent relationship, under Article 25 of CR 134/2025 (the successor to Article 24 of the repealed CD 10/2019). The CSP files an annual self-assessment report with the Ministry of Economy through SACM.

AED 50,000–200,000

Administrative fine for a UAE CSP failing to register on the FIU's electronic system — item 23 of the list annexed to Cabinet Resolution No. 71 of 2024, which repealed Cabinet Resolution No. 16 of 2021

Compliance team mapping ultimate beneficial owner chain across multiple jurisdictions and screening senior managing officials against OFAC and UN sanctions lists

What the fines actually are

That KeyStat is one row of a much longer list. The live schedule is the list annexed to Cabinet Resolution No. 71 of 2024, published in English by the Ministry of Economy and Tourism. Article 8 repealed the previous schedule in Cabinet Resolution No. 16 of 2021 — so a UAE programme manual still quoting fines from 16/2021 is quoting a repealed instrument.

Two definitions run through every row, and they need a caveat that did not exist when the schedule was drafted. Cabinet Resolution No. 71 of 2024 defines “the Decree-Law” as Federal Decree-Law No. 20 of 2018 and “the Executive Regulation” as Cabinet Resolution No. 10 of 2019 — both of which have since been repealed, by Article 41 of Federal Decree-Law No. 10 of 2025 and Article 70 of Cabinet Resolution No. 134 of 2025 respectively.

Cabinet Resolution No. 71 of 2024 itself remains published on the Ministry of Economy and Tourism’s financial-crimes legislation page, checked 5 August 2026. What the Ministry has not published, as far as we could establish on that date, is a re-based schedule renumbered to the 2025 articles. We are not going to guess at one. Read the article numbers in the table below as the schedule’s own cross-references to the repealed text, and use the mapping that follows to find the equivalent obligation in the instrument that now governs you.

Article 2 applies the list to Designated Non-Financial Businesses and Professions — where a UAE corporate service provider sits.

The rows below are the ones a CSP is most likely to be measured against.

#Legal referenceViolation (abridged)Minimum (AED)Maximum (AED)
1Art 20, Executive RegulationNo AML policies, measures and internal controls approved by top management100,000200,000
2Art 20, Executive RegulationPolicies not consistent with the firm’s crime risks, nature and size, or not updated continuously50,000100,000
3Art 20, Executive RegulationPolicies not applied to a branch or a majority-owned subsidiary50,000100,000
8Art 23, Executive RegulationRisks not identified and assessed when developing a new service or professional practice50,000500,000
9Art 6(1–5), Executive RegulationNo customer due diligence before the business relationship, or on a casual transaction at or above AED 55,00050,000200,000
12Art 8(3, 4), Executive RegulationPurpose and nature of the relationship, and the ownership and control structure, not understood50,000200,000
13Art 9, Executive RegulationBeneficial owner of a legal person or legal arrangement not identified and validated50,000200,000
14Art 16, Decree-LawInformation obtained through due diligence not kept50,000200,000
15Art 4(2/B), Executive RegulationNo enhanced due diligence once high risk is identified100,000500,000
22Arts 15 and 17, Decree-LawSuspicious transaction report not promptly submitted to the FIU, or additional information it requests not provided100,000500,000
23Art 17(1) and Art 20(2), Executive RegulationNot registered on the electronic system approved at the Financial Information Unit — the goAML registration50,000200,000
24Art 21, Executive RegulationNo compliance officer appointed with the competence and expertise to perform the duties50,000200,000
25Art 21, Executive RegulationCompliance officer not enabled to perform the Article 21 duties50,000500,000
26Art 24(1, 3, 4), Executive RegulationRecords not kept, or not organised to allow re-analysis and reconstruction, or not produced promptly on request50,000200,000

Source: the list annexed to Cabinet Resolution No. 71 of 2024, read from the Ministry’s own English publication. Checked 4 August 2026. Row numbers are the list’s own, and the “Executive Regulation” article numbers in the second column are the schedule’s references to the repealed Cabinet Decision No. 10 of 2019.

Here is where those obligations now live, read from Cabinet Resolution No. 134 of 2025 on 5 August 2026.

ObligationOld article (repealed CD 10/2019)Current article (CR 134/2025)
DNFBP scoping listArt. 3Art. 3
CDD triggers for DNFBPsArt. 6(1)Art. 7(1)
Occasional-transaction CDD at AED 55,000Art. 6(2), Financial Institutions and DNFBPsArt. 7(2), Financial Institutions only
Compliance Officer appointment and dutiesArt. 21Art. 22
Prior approval before appointing the Compliance OfficerArt. 44(14), permissiveArt. 49(18), a supervisory competence
Record-keeping, five yearsArt. 24Art. 25

Row 9 is the one to read twice. The schedule penalises a DNFBP for failing to run CDD “on a casual transaction at or above AED 55,000”, tracking Article 6(2) of the repealed regulation, which applied that trigger to Financial Institutions and DNFBPs alike. Article 7(2) of Cabinet Resolution No. 134 of 2025 applies the AED 55,000 occasional-transaction trigger to Financial Institutions only, and adds a separate AED 3,500 trigger for occasional wire transfers. A corporate service provider is not a Financial Institution, so that particular article no longer names you.

What has not changed is that a CSP owes full CDD under Article 7(1) on commencing a business relationship, where there is suspicion of a crime, and where there are doubts about the accuracy or adequacy of identification data previously obtained — which, for a formation agent, is every engagement. The threshold was never the thing that put you in scope; the relationship was.

Read both columns, not the first number. Every row is a band, and the minimum is the floor of that band rather than a standard charge — item 23 is the one people quote as “AED 50,000 for missing goAML”, when the same row reaches AED 200,000. Article 3(1) also lets the Ministry impose one of the administrative penalties in Article 14 of the Decree-Law instead of the fine, or alongside it, so the money is not necessarily the whole of the consequence.

Notice what the list is weighted toward. Of the rows above, the heaviest maximums attach to failures of judgement rather than failures of paperwork: no enhanced due diligence once you have already spotted high risk, no risk assessment before launching a service, a suspicious transaction you did not report. The AED 500,000 rows are the ones where the firm saw something and did nothing.

If the Ministry fines a CSP: notice, grievance and the 30-day clock

Article 3(2) says the Minister designates a competent authority inside the Ministry to impose fines on DNFBPs and to set the procedures for doing so. In practice that means the fine reaches a UAE corporate service provider from the Ministry of Economy or the Ministry of Justice, as the case may be — not from the FIU and not from the Central Bank, which supervises a different population.

One scope limit is worth reading off the cover page. The resolution’s own title covers violators subject to the control of the Ministry of Justice and Ministry of Economy. The federal AML law — now Federal Decree-Law No. 10 of 2025, which repealed Federal Decree-Law No. 20 of 2018 — applies across the UAE, including inside the financial free zones. But supervision and the applicable penalty schedule do not all sit in one place.

So a corporate service provider licensed in the Dubai International Financial Centre or the Abu Dhabi Global Market answers to that centre’s own AML supervisor, and should confirm which schedule it is measured against before quoting the figures above in an engagement letter. For a mainland or non-financial free zone CSP in Dubai, Sharjah or Abu Dhabi, the list annexed to Cabinet Resolution No. 71 of 2024 is the one that bites.

Article 4 then sets the process, and it is short. The Ministry notifies the business of the decision to impose the fine within 20 working days. Any person with a capacity or any stakeholder may grieve to the Minister or a delegate within 30 working days of the notice, or of becoming aware of it, provided the grievance is substantiated and the supporting documents are attached.

That 30-working-day window is the practical reason a CSP keeps its AML file in order. On considering a grievance the Minister may deny it and endorse the penalty, or amend it to another penalty from Article 14 of the Decree-Law or from the annexed list. A grievance argued from a dated risk assessment, a signed MLRO appointment and a complete CDD file is a different document from one written after the notice arrives.

Tracing the UBO until you hit a person

A UBO is the ultimate beneficial owner: the natural person who ultimately owns or controls a legal entity, whether through direct shareholding, an indirect chain of holding companies, voting rights, or control exercised by other means. The point of the concept is that it does not stop at the first company on the share register. It keeps going until it reaches a human being, which is why the work is called tracing rather than checking.

UBO tracing is where most CSP inspection findings concentrate. A defensible UBO trace meets four tests:

  1. Documentary evidence at every layer — share registers, MoA, share certificates or equivalent corporate records for every entity in the chain, not just the client’s statement of ownership
  2. Natural person identification — the trace terminates at one or more natural persons, with full CDD on each
  3. Alternative test where no 25 percent owner exists — the senior managing official is named and CDD’d, not left blank
  4. Periodic refresh — the UBO file is refreshed at least annually and whenever the registered agent files an updated UBO declaration

CSPs that file UBO declarations with the UAE Ministry of Economy on behalf of clients have to hold supporting evidence for what they file. A declaration filed on the client’s word alone, with no share registers and no ID behind it, is an inspection finding waiting to happen — and in our experience it’s the single most common one.

When to escalate to the MLRO

Ownership and Structure Red Flags

  • Client refuses to disclose the ultimate beneficial owner or insists on bearer-share equivalents
  • Ownership chain runs through three or more jurisdictions including known opacity centres for no commercial reason
  • Sudden change of beneficial owner shortly after incorporation
  • Request for nominee shareholders or directors without documented economic justification
  • Beneficial owner appears on a sanctions list — OFAC, UN, UK HMT, UAE Local Terrorist List

Source of Funds Red Flags

  • Incorporation capital materially out of proportion with the disclosed business activity
  • Capital arriving from a third party not previously disclosed in the engagement
  • Source of funds story that does not reconcile with the UBO’s age, occupation or financial profile
  • Cash injection of capital above reportable thresholds
  • Capital wired from a jurisdiction the CSP cannot evidence due diligence on

Behavioural Red Flags

  • Insistence on completing incorporation at unusual speed or in unusual secrecy
  • Repeated changes to the identity of the apparent principal during onboarding
  • Reluctance to attend in person for identity verification where the client claims UAE residency
  • Vague or shifting explanations for the choice of UAE jurisdiction
  • Request for a shelf company or pre-incorporated entity without economic rationale

Post-Incorporation Red Flags

  • Entity becomes inactive immediately after incorporation
  • UBO refresh declaration cannot be verified against new evidence
  • Bank account opening fails on AML grounds and the client requests a different jurisdiction
  • Sanctions screening hit develops mid-relationship on a previously cleared UBO
  • Adverse media linking the entity or UBO to investigations

When any of these triggers appear, the staff member escalates to the MLRO without tipping off the client. Tipping off remains a criminal offence. Article 24 of Federal Decree-Law No. 10 of 2025 makes information obtained in relation to suspicious transactions confidential, and Article 29(1) punishes anyone who notifies or warns another person, discloses information about transactions under review, or reveals that the competent authorities are making inquiries, with imprisonment and a fine of not less than AED 50,000, or either penalty. That replaces the equivalent offence in the repealed Federal Decree-Law No. 20 of 2018.

A CSP’s strongest defence in an inspection is the continuous-monitoring record — a dated log showing every quarterly screening refresh, every annual UBO confirmation and every MLRO sign-off on continuing exposure across the active book. Most CSPs have a strong onboarding file and a weak monitoring trail. Inspectors notice the gap.

— Velmont Crest advisory note
UAE Ministry of Economy AML inspector reviewing corporate service provider client risk matrix and ongoing beneficial owner refresh declarations

STR filing services in the UAE for corporate service providers

Search for “STR filing services in the UAE” and what most corporate service providers actually want is help getting a suspicious transaction report onto goAML correctly. Here is the honest boundary. A suspicious transaction report — and its sibling the suspicious activity report — is submitted through the UAE Financial Intelligence Unit’s goAML portal, and only the appointed MLRO can file it. No external adviser, and no piece of software, can press that button on the MLRO’s behalf without breaking the reporting obligation under Federal Decree-Law 10/2025.

So what does an STR filing service really cover? The drafting and the plumbing around the report, not the submission itself. That means an internal suspicion-report template staff can complete in minutes, a clear escalation route from front-line onboarder to MLRO, the ongoing screening that surfaces the hit in the first place, and a walkthrough of the goAML report fields so the MLRO is not learning the portal under pressure. When a red flag appears, the staff member escalates internally without tipping off the client; the MLRO weighs it and files where there are reasonable grounds for suspicion, and without delay. If you have not enrolled yet, our goAML registration guide for the UAE covers the enrolment step first.

How STR filing fits a corporate service provider AML programme in the UAE

STR filing is the reporting layer, and a corporate service provider AML programme in the UAE only holds together when that layer is real rather than theoretical. The suspicious transaction report is not the only submission a CSP may make on goAML, and knowing the difference keeps the MLRO from freezing at the wrong moment.

A suspicious transaction report (STR) covers a transaction — an incorporation capital movement, for instance — that raises suspicion. A suspicious activity report (SAR) covers a suspicious activity, or an attempted transaction that was never executed, which is common in formation work where no single completed transaction stands out. A partial name match report (PNMR) is filed when an incorporating client or UBO throws a possible, unconfirmed hit against a sanctions list. A funds freeze report (FFR) follows a confirmed match, once the assets have been frozen and the required notifications made.

For most corporate service providers the day-to-day reality is SARs and partial-name-match reports rather than dramatic STRs — a shifting principal, a name that half-matches a listed person, a UBO who will not be pinned down. Mapping each red flag to the right goAML report type, and each risk band to the right diligence tier, is where external support genuinely earns its keep.

Where CSP programmes break down

The most common failure is a strong onboarding file and nothing after it. A robust CDD pack is assembled at incorporation and then the relationship is never looked at again, when the Ministry of Economy expects monitoring to continue for the lifetime of the registered-agent relationship. On the schedule above that is item 26 territory — records that cannot reconstruct what the UAE firm knew, and when it knew it.

Close behind sits the UBO declaration filed without evidence. A client says they own 100 percent, the CSP files the declaration on that basis, and the supporting share register is never collected. An inspection finds the declaration unsupported, and there is nothing to fall back on.

Nominee work is its own trap. Acting as a nominee shareholder or director without a documented economic reason, and without enhanced due diligence on the ultimate principal, is one of the highest-risk things a CSP can do. The Ministry expects EDD, MLRO sign-off and quarterly review on every nominee engagement.

Training tends to be too generic. Annual sessions that skip the risks specific to formation work — UBO tracing, source of funds for capital, nominee arrangements, shelf companies — are exactly what inspectors mean when they say training is generic. They want role-specific content, not a slide deck downloaded off the internet.

Then there is sanctions screening that runs only at onboarding. Lists update continuously, so a CSP that screens once at incorporation is one list update away from holding an active relationship with a sanctioned UBO and having no idea. In firms of more than ten staff, we also see the MLRO doubling as a front-line onboarder, which the Ministry doesn’t accept — it expects the MLRO to be independent of client onboarding, because conflating the two roles undermines the integrity of the whole assessment.

If you’re running a CSP without a programme

If your UAE corporate service provider has not yet completed a Business Risk Assessment, drafted a client and entity risk matrix or registered an MLRO on goAML, you are operating outside the federal AML/CFT framework — irrespective of whether your operating base is mainland, DMCC, JAFZA, ADGM, DIFC or RAKEZ. Failing to register alone carries an administrative fine of AED 50,000 to AED 200,000 — item 23 of the list annexed to Cabinet Resolution No. 71 of 2024 — and the bands are charged per violation, so missing CDD and UBO evidence (AED 50,000 to AED 200,000 a case) escalates quickly across a client book.

If you have a manual but it has not been refreshed against current Ministry of Economy expectations, the gap is usually in three places: the UBO tracing files are thin on documentary evidence, the post-incorporation monitoring log is missing or sparse, and sanctions re-screening has not run since onboarding.

Velmont Crest’s UAE compliance team provides advisory support across the CSP DNFBP programme lifecycle — from Business Risk Assessment through MLRO appointment support, goAML registration assistance, policy drafting, UBO tracing methodology and inspection-readiness reviews. We pair this with bookkeeping and business setup advisory work so the AML evidence trail aligns with the underlying financial records.

For a clean review of where your CSP AML programme stands today, book a free consultation.


Disclaimer: Velmont Crest is a DED-licensed accounting firm. We provide advisory, preparation and compliance support services. We are not a licensed MLRO of record, registered legal consultant or FTA tax agent. AML/CFT rules and DNFBP obligations change frequently — verify all requirements with the UAE Financial Intelligence Unit, the Ministry of Economy and your sector regulator, and engage a licensed legal or AML professional for advice specific to your circumstances.

References

Frequently asked questions

Is every UAE corporate service provider in scope as a DNFBP?
Yes. Article 3 of Cabinet Resolution No. 134 of 2025 — the Executive Regulations that repealed and replaced Cabinet Decision 10 of 2019 — catches anyone who, by way of business, acts as a formation agent for legal persons, acts as (or arranges for someone else to act as) a director, secretary or partner, provides a registered office or business address, acts as a trustee of an express trust, or acts as a nominee shareholder. If your firm does any one of those, you are a DNFBP. There is no minimum size or transaction count that lets you out.
What CDD does a CSP collect on every incorporation?
You're really building three files at once. There's the incorporating client — passport, Emirates ID for UAE residents, proof of address, source of funds for the formation. There's the entity being formed, where you record intended activities, the planned ownership and management structure, and the source of capital. And there's every UBO at or above 25 percent, with ID, residency, PEP screening and a source-of-wealth narrative. When ownership runs through layers of companies, keep tracing upward until you reach a real person. If nobody controls 25 percent, the senior managing official goes in as UBO under the alternative test.
Does the CSP file the goAML registration, or does the client?
The CSP registers itself. The formation firm is the DNFBP here — not the companies it sets up. But the new entities have their own question to answer. If a company you incorporate is itself a DNFBP (real estate broker, precious-metals dealer, auditor, lawyer, accountant, tax consultant, another CSP, virtual asset service provider), it registers on goAML in its own name once licensed. You can walk them through it, but they are the registrant of record, not you.
What is a UBO?
UBO stands for ultimate beneficial owner — the natural person who ultimately owns or controls a legal entity. Ownership can be direct, or indirect through a chain of holding companies, and control can also come from voting rights or from influence exercised by other means rather than shares. The defining feature is that the analysis does not stop at the first company on the share register; it continues until it reaches a human being. Where no individual meets the ownership threshold, the UAE rules require the senior managing official to be identified and diligence performed on them instead — that field is never left blank. For a corporate service provider, evidencing the UBO at every layer is the single most inspected part of the file.
What is KYC?
KYC stands for know your customer — verifying who you are dealing with before you act for them. In practice that means collecting and verifying identity documents, confirming the address, and establishing that the person in front of you is the person on the passport. UAE AML rules use a wider term, customer due diligence, and CDD includes KYC but goes beyond it: understanding the ownership and control structure, identifying the ultimate beneficial owner, establishing the purpose of the relationship, and evidencing source of funds and source of wealth where risk requires it. For a corporate service provider, KYC on the individual signing the incorporation papers is the beginning of the file, not the end of it.
What STR triggers should a CSP escalate?
Watch for a client who won't name the ultimate beneficial owner, an ownership chain threading three or more jurisdictions with no commercial logic, incorporation capital that can't be evidenced, a request for nominees with no documented reason, a UBO who turns up on a sanctions or adverse-media list, and a beneficial owner who changes shortly after incorporation. Shelf-company requests sit in the same bucket. The MLRO weighs each escalation and files an STR on goAML where there are reasonable grounds for suspicion.
What does an external AML adviser actually do for a CSP?
The drafting, mostly. They write the Business Risk Assessment that scores your client types, jurisdictions and entity structures, build the client and entity risk matrix, and produce the CDD and EDD manual covering source-of-funds, UBO tracing and nominee work. They support the MLRO appointment and the goAML registration, then run ongoing screening, training and the annual self-assessment to the Ministry of Economy. The one thing they can't do for you is file STRs — that has to be the appointed MLRO, personally, through goAML.
What is the fine if a UAE corporate service provider gets its AML programme wrong?
It depends on the violation, and every entry is a range rather than a single figure. The live schedule is the list annexed to Cabinet Resolution No. 71 of 2024, which repealed Cabinet Resolution No. 16 of 2021. Failing to register on the FIU's electronic system — goAML — is item 23 at AED 50,000 to AED 200,000. Not identifying and validating the beneficial owner is item 13, also AED 50,000 to AED 200,000. The heavier bands attach to judgement failures: no enhanced due diligence after high risk is identified is item 15 at AED 100,000 to AED 500,000, and failing to promptly report a suspicious transaction is item 22 at the same range. Article 3(1) also lets the Ministry impose an Article 14 administrative penalty instead of the fine, or alongside it.

Filed under: AML compliance, DNFBP, corporate service provider, MLRO, goAML, UBO

Published · Updated