Skip to content

Insights AML

goAML Registration UAE 2026: The DNFBP Login and STR Guide

goAML registration in the UAE — DNFBP enrolment, login, MLRO appointment and STR/SAR workflow with penalties for non-registration explained in 2026.

Compliance officer reviewing AML monitoring dashboard on screen — goAML portal login, DNFBP registration, MLRO appointment and STR/SAR filing workflow at the UAE FIU
Compliance officer reviewing AML monitoring dashboard on screen — goAML portal login, DNFBP registration, MLRO appointment and STR/SAR filing workflow at the UAE FIU Photo: Velmont Crest Editorial

Key takeaways

  1. goAML is the UAE FIU's portal under Federal Decree-Law 10/2025 and Cabinet Resolution 134/2025
  2. DNFBPs and financial institutions must register, regardless of trade licence category
  3. Registration runs through SACM → goAML — pre-register on the FIU's SACM before the goAML form
  4. An MLRO must be appointed before submission — name, ID and contact go on the registration form
  5. Login failures usually trace to unapproved accounts, MFA issues or expired passwords — not the portal
  6. STRs / SARs must be filed without tipping off the customer; records retained for five years

goAML registration in the UAE is the mandatory step every DNFBP and financial institution must complete before it can file suspicious transaction reports. A goAML login failure is rarely a portal problem. Nine times out of ten it is a sequencing problem: a registration submitted before the supporting paperwork was ready, an MLRO that was never formally appointed, or a SACM or licence record that fell out of sync during a free zone renewal and nobody noticed.

This guide covers what goAML is, who must register, how goAML registration actually flows in 2026, the most common login errors, the STR and SAR reporting workflow, and what your accounting and compliance advisor (see our AML compliance UAE guide) prepares behind the scenes. If you would rather not navigate the SACM and goAML enrolment alone, our AML compliance support in the UAE handles the registration build for DNFBPs.

What Is goAML?

goAML is the UAE Financial Intelligence Unit’s anti-money-laundering reporting platform, hosted at goaml.uaefiu.gov.ae. The software was developed by the UN Office on Drugs and Crime (UNODC) and is used by FIUs in more than 50 countries. In the UAE it sits inside the Central Bank’s FIU, so goAML registration with the UAE Central Bank’s Financial Intelligence Unit is the single mandatory channel for:

  • Suspicious Transaction Reports (STRs) — when a specific transaction looks suspicious
  • Suspicious Activity Reports (SARs) — when broader customer behaviour looks suspicious even without a single triggering transaction
  • Dealer in Precious Metals and Stones Reports (DPMSR) — for cash transactions above the AED 55,000 threshold
  • Real Estate Activity Reports (REAR) — for high-value property transactions paid wholly or partly in cash, virtual assets or other non-bank instruments
  • Request for Information (RFI) responses — when the FIU asks a registered entity for further detail

Suspicion is not the only trigger, either. Where a customer or counterparty matches a sanctions designation, freezing measures have to be in place within 24 hours and a confirmed or partial name-match report goes through the same platform — we set out the five-business-day name-match report and the rest of the CFT timetable in our AML and CFT guide.

Use of goAML is required under Federal Decree-Law No. 10 of 2025 on Anti-Money Laundering and Combating the Financing of Terrorism and the Financing of Illegal Organisations — which replaced the earlier 2018 law from October 2025 — as implemented by Cabinet Resolution No. 134 of 2025 and the supplementary guidance issued by the UAE Ministry of Economy and Tourism for non-financial sectors.

Velmont Crest is a DED-licensed accounting firm supporting AML compliance for DNFBPs across mainland and free zone setups.

UAE compliance officer mapping Designated Non-Financial Business activities to goAML registration scope ahead of FIU enrolment

Who Must Register on goAML?

The UAE FIU splits registrants into two broad groups: financial institutions and designated non-financial businesses and professions (DNFBPs). Both must register. DNFBPs were the later addition — brought firmly into scope by the UAE’s AML/CFT regulations — and they’ve been actively enforced against since 2021, so the “we’re not a bank” excuse stopped working years ago.

Financial Institutions

  • Banks, branches of foreign banks, Islamic banks
  • Exchange houses and money services businesses regulated by the Central Bank
  • Insurance and reinsurance companies, insurance brokers and agents regulated by the Central Bank
  • Finance companies and finance brokers
  • Securities, commodities and investment firms regulated by the Securities and Commodities Authority (SCA)
  • Virtual asset service providers regulated by SCA or VARA

DNFBPs

  • Real estate brokers and agents — and any business involved in buying or selling real estate
  • Dealers in precious metals and stones — gold, diamond, jewellery traders dealing in cash above AED 55,000
  • Auditors and accountants — registered audit firms and accounting consultancies (including ours), whose programme requirements are covered in our auditor AML UAE guide
  • Tax consultants and tax agents registered with the FTA
  • Lawyers, notaries and other independent legal professionals — when preparing or executing transactions for clients
  • Corporate service providers and trust service providers — including company formation specialists, PRO services and registered agents (see our dedicated corporate service provider AML programme guide)

The trade licence category — commercial, professional, industrial or tourism — does not change the obligation. A free zone real estate brokerage and a mainland real estate brokerage have the same goAML duty. Failing to register carries an administrative fine of AED 50,000 to AED 200,000. That is item 23 of the list annexed to Cabinet Resolution No. 71 of 2024, issued 8 July 2024, which describes the violation as failure “to register at the electronic system approved at the Financial Information Unit”.

Article 8 of that Resolution repealed Cabinet Resolution No. 16 of 2021, and the fine is imposed by the Ministry of Justice or the Ministry of Economy and Tourism, whichever supervises the sector — not by the FIU or the Central Bank. Across the whole annexed list of 41 violations the fines run from AED 50,000 to AED 1,000,000, and Article 5(2) lets the Ministry double the fine where a violation is repeated.

Six stages from licence to login

goAML registration in 2026 is built on two UAE FIU systems — SACM (the Services Access Control Manager, where you pre-register for credentials) and the goAML portal itself — sitting on top of the compliance groundwork every reporting entity has to lay first. Skipping a stage will cause the registration to be rejected without explanation.

Stage 1 — SACM Pre-Registration (Services Access Control Manager)

Every reporting entity — financial institution or DNFBP — first pre-registers on SACM, the UAE FIU’s Services Access Control Manager. SACM captures the entity type and its supervisory body — the Ministry of Economy and Tourism for most DNFBPs, the Central Bank for financial institutions — and issues the username and the secret key you use to set up the Google Authenticator app. Those credentials are what open the goAML portal, so SACM pre-registration has to be completed before the full goAML registration form can be reached.

Stage 2 — Business Risk Assessment (BRA)

Before you touch the goAML registration form, the firm should have a documented Business Risk Assessment covering:

  • Customer risk — types of clients, geographic exposure, politically exposed persons
  • Product / service risk — which licensed activities create AML exposure
  • Geographic risk — sanctioned and high-risk jurisdictions
  • Delivery channel risk — face-to-face vs remote onboarding
  • Transaction risk — typical sizes, payment methods, cash exposure

The BRA is the document the regulator will ask for first if you are ever inspected. It also informs every other policy in your AML/CFT framework and is referenced inside the goAML registration form.

Stage 3 — Appoint an MLRO in Writing

The Money Laundering Reporting Officer must be appointed by a board or partner resolution before the goAML form is submitted. The appointment letter records:

  • Full name, Emirates ID, designation
  • Direct line of communication to senior management or the board
  • Independence from front-line client onboarding where the firm is large enough to allow it
  • Acceptance and acknowledgement of obligations under Federal Decree-Law 10/2025

For small firms (sole practitioner accountants, two-partner brokerages), the owner or managing partner usually takes the MLRO role personally. There is no minimum firm size below which the appointment can be skipped.

Stage 4 — Reconcile Your Entity Records

The goAML form uses your trade licence as the anchor record, and the details you enter — legal name, licence number, registered office, authorised signatory — must match your other official records exactly. Mismatches between the goAML form and your licensing-authority or tax-registration records (for example your FTA EmaraTax profile, if you are registered for VAT or corporate tax) are one of the most common rejection reasons, so reconcile the legal name, trade licence number, registered address and authorised signatory details across your records before you submit.

Stage 5 — Complete the goAML Registration Form

The form asks for organisation type, legal form, trade licence details, registered office, MLRO name and Emirates ID, authorised signatory details, plus supporting documents: trade licence, MoA, authorisation letter, MLRO appointment letter, signatory passport and Emirates ID, and BRA attestation. You receive an automated acknowledgement on submission — approval is not instant, the FIU reviews each registration manually.

Stage 6 — Approval and First Login

Once approved, the FIU emails the organisation ID and user ID. Only then will the login screen accept your credentials. The FIU publishes no turnaround commitment for this review, so build the registration into a compliance calendar rather than running it against a deadline.

AED 50,000–200,000

Administrative fine for failure to register on the FIU's electronic system — item 23 of the list annexed to Cabinet Resolution No. 71 of 2024

goAML registration UAE: fees, timeline and who submits the form

goAML registration in the UAE carries no government portal fee. The FIU does not charge a DNFBP or a financial institution to enrol, so any cost you meet is advisory work or the underlying compliance build — the Business Risk Assessment, the AML policy manual, the MLRO appointment — rather than a registration levy. Be wary of anyone quoting a fixed “goAML registration fee” as though it were a government charge. It is not.

Who submits also matters. The registration is filed by the entity’s authorised signatory, and the form ties back to the trade licence and your official entity records. In a small firm the authorised signatory and the MLRO are often the same person, which is fine; the form simply needs both roles recorded accurately. The FIU then reviews each submission before activating the account, and publishes no service-level turnaround for that review — treat any specific number of days you are quoted as an estimate rather than a commitment, whoever it comes from.

One point firms miss: once approved, the registration is not set-and-forget. Details change — a new MLRO, a renewed licence, a moved office — and the goAML profile has to be updated to match. Our goAML annual renewal guide covers the yearly refresh that keeps an approved account in good standing after go-live.

goAML registration UAE for free zone and offshore companies

A frequent question is whether goAML registration in the UAE applies to free zone and offshore companies, or only to mainland firms. It applies to both. The obligation follows the licensed activity, not the address, so a DMCC precious-metals trader, a DIFC or ADGM corporate service provider, and a JAFZA or RAKEZ real estate broker all register with the same federal Financial Intelligence Unit through the same goAML portal.

The financial free zones add a wrinkle. DIFC and ADGM run their own regulators — the DFSA and the FSRA — for prudential and conduct matters. That supervision does not replace the federal AML reporting duty. A DNFBP inside DIFC or ADGM still files STRs and SARs to the UAE FIU on goAML; the local regulator sits alongside the federal channel, not instead of it.

The emirate makes no difference either. Whether you are handling goAML registration in Abu Dhabi, goAML registration in Sharjah or goAML registration in Fujairah, the account is opened with the same federal Financial Intelligence Unit, because there is no emirate-level regulator to register with instead. What changes from one emirate to the next is only the licensing authority whose trade licence and ownership documents you attach to the form.

Offshore vehicles are not a loophole either. Where an offshore company carries out a DNFBP activity — dealing in real estate, trading precious metals, or acting as a corporate service provider — the registration duty is the same. What changes between setups is the paperwork you attach to the form, because the licence, ownership records and SACM route differ by authority. If you are still choosing a structure, our business setup advisory work factors the AML obligation in from the outset rather than leaving it as a surprise after the licence issues.

Screen view of a goAML portal login session with two-factor authentication and active session monitoring for a UAE reporting entity

Logging in, once you’re approved

Once the registration is approved, login itself is short:

  1. Navigate to goaml.uaefiu.gov.ae
  2. Click Login and choose your user type (Organisation or Individual)
  3. Enter your username and password
  4. Complete the multi-factor authentication challenge — usually a one-time password sent to the registered MLRO mobile number
  5. Acknowledge the system notices and proceed to the dashboard

The dashboard shows pending RFIs, recent submissions, draft reports and any system messages from the FIU.

goAML login UAE: organisation, individual and multi-user access

People write the name several ways. You will see goAML login, go AML login and even AML log in typed into a search bar, and they all lead to the same single portal — there is no second system and no separate emirate-level site. A goAML login in the UAE is not one-size-fits-all, though, and the first screen makes you choose. When you click Login you pick a user type — Organisation or Individual — and the two behave differently. Most DNFBPs and financial institutions log in as an Organisation, tied to the entity’s registration and trade licence. The Individual route is for a person acting in their own name, which is the exception rather than the rule for a licensed business.

Larger firms rarely want a single shared login, and they do not have to. goAML lets an organisation add more than one user under its registration, so the MLRO, a deputy and a finance contact can each hold their own credentials instead of passing one password around. Each added user is still subject to FIU approval, and each stays tied to the organisation’s record. Sharing one login across a team is the habit that later produces the locked-account and expired-password headaches covered below.

The safest setup pairs the primary login with a role-based mailbox and, where the firm is large enough, a named deputy MLRO who can file if the primary is travelling or unwell. That way a goAML login never depends on one individual being at their desk on the day a report is due. The underlying programme that supports all of this is set out in our AML compliance UAE guide.

When the login keeps rejecting you and it isn’t the password

The portal itself is reasonably reliable — more reliable than its reputation, honestly. Most login failures trace back to one of a handful of root causes, and only one of them is an actual technical fault.

”Invalid Username or Password” Despite Correct Credentials

The most common failure by a long margin. The usual cause is that the registration has not yet been approved. The login screen does not distinguish between “wrong password” and “account not yet active”; both produce the same generic error. Check the approval email before assuming the password is wrong.

Account Locked After Failed Attempts

Repeated failed attempts lock the account. The FIU does not publish the exact attempt count, so do not gamble on it — once the error repeats, stop and request an unlock through the FIU help desk rather than retrying into a lockout.

MFA / OTP Not Received

If the OTP does not arrive, check that the mobile number registered with goAML is current — UAE numbers that change carrier are a frequent cause. The MFA can be reset, but only after the FIU verifies the MLRO’s identity through the help desk.

”Account Pending Approval”

The registration is still in review. There is no way to accelerate it. Keep the acknowledgement reference number to hand for follow-up.

Browser or Cache Issues

goAML is sensitive to browser cache. Use the latest Chrome or Edge, clear cookies for the goaml.uaefiu.gov.ae domain, and disable extensions that interfere with form submission.

Password Expired

Passwords expire periodically and the system forces a reset. If the reset email goes to a former employee’s mailbox, the login is effectively dead until the FIU revives the account — another reason to register the MLRO with a role-based mailbox.

The single change that prevents the most goAML lockouts is registering the MLRO using a role-based email address — mlro@yourdomain — rather than a personal mailbox. When staff change, the inbox stays, the reset emails stay reachable, and the FIU never finds itself emailing a former employee.

— Velmont Crest advisory note

Filing an STR or SAR, end to end

Once logged in, the core operational use of goAML is filing suspicious reports, and the process runs through four hands before anything is submitted.

It starts with front-line staff, who flag a transaction or pattern — unusual cash structuring, a mismatched economic rationale, a customer who goes quiet on CDD, structuring just below a reporting threshold, or any indicator written into the firm’s policy manual. Whoever spots it escalates to the MLRO through the firm’s internal SAR mechanism, and they must not tip off the customer while doing so.

Under Federal Decree-Law 10/2025 tipping off is a criminal offence, not just an administrative one. Article 24 makes the information confidential, and Article 29(1) punishes anyone who notifies or warns another person, or discloses information about transactions under review, with imprisonment and a fine of not less than AED 50,000, or either of those. Separately, item 28 of the annex to Cabinet Resolution No. 71 of 2024 carries an administrative fine of AED 100,000 to AED 500,000 for the same disclosure.

From there the MLRO takes over. They review the case, request supporting documentation, and decide whether reasonable grounds exist to suspect money laundering, terrorist financing or proliferation financing, recording the assessment and the decision in writing either way. If the conclusion is that a report is required, the MLRO files an STR for a specific transaction or a SAR for a pattern through goAML, and the platform logs the time, the filer and the reference number. The original transaction may proceed or be blocked depending on the case, but the customer is never told a report went in.

Then it all has to be kept. Under Cabinet Resolution 134 of 2025, every record — the transaction, the CDD file, the SAR escalation, the MLRO assessment and the goAML filing reference — is retained for five years from the end of the business relationship or the transaction date, whichever is later.

What we actually do behind the MLRO

The MLRO is the person who files on goAML. The accounting and compliance advisor sits behind the MLRO and prepares much of the underlying material:

  • Business Risk Assessment support — pulling client lists, geographic exposure data, activity volumes and payment-method analysis for the BRA
  • Transaction monitoring data — extracting customer ledgers, payment patterns and CDD-relevant balances from the bookkeeping system so the MLRO can assess whether a transaction is genuinely anomalous
  • Evidence preservation — ensuring the underlying invoices, contracts, bank statements and CDD files are stored to the five-year retention standard
  • Policy and procedure manuals — drafting or reviewing the AML/CFT policy, CDD procedures and STR / SAR escalation workflow
  • Internal training records — documenting AML training sessions and staff acknowledgements
  • Annual AML report — preparing the data and narrative that feeds the firm’s annual self-assessment submission to the Ministry of Economy and Tourism

What the accountant does not do: file STRs or SARs, act as the MLRO, or represent the firm before the FIU. Those are the MLRO’s personal statutory duties. Our role is to make sure the MLRO has clean, defensible material to work from.

AML team reviewing suspicious transaction report drafting workflow and red flag documentation before submission to the UAE FIU

Where DNFBPs slip up

The most common mistake is treating goAML registration as the whole job. Registration is only the start. Running an AML programme means quarterly transaction monitoring, ongoing CDD refreshes, annual training, the BRA refresh and the annual Ministry of Economy and Tourism report, and none of that happens on its own just because you can log in. The portal profile itself also has to be kept current — our goAML annual renewal guide covers the yearly data refresh that keeps the registration compliant after go-live.

Almost as common is letting an MLRO move on without re-appointing one. If your MLRO leaves, a replacement has to be appointed in writing and the goAML record updated within days, not months. An inspector who opens the file and finds the MLRO field still showing a former employee will treat the whole AML framework as defective.

A lot of firms also confuse the two portals in play. SACM is only the FIU’s access gateway that issues your goAML credentials; goAML is the operational reporting platform where STRs and SARs are filed. They do different jobs, and a DNFBP has to keep both current.

Late filing is another one. An STR has to go in promptly, which supervisors generally read as within a few business days of the MLRO forming reasonable suspicion, and a delayed filing is itself an offence. Closely related is tipping off: even an oblique hint like “we’re reviewing your file with the bank” can cross the line, so the internal team needs training on exactly where that boundary sits.

The last recurring gap is evidence. A goAML filing without the underlying CDD file, transaction record and MLRO assessment behind it won’t hold up if the FIU comes back later with an RFI, and the five-year retention obligation is there precisely so it does.

What goAML failures actually cost

Registration is one line in a longer list. Once you hold a goAML account, the portal becomes the evidence trail for most of the obligations a supervisor can fine you for, and each of those has a published figure in the annex to Cabinet Resolution No. 71 of 2024. These are the rows that a goAML-registered DNFBP is realistically measured against.

Annex itemWhat it penalisesMinimumMaximum
22Failure to promptly submit a suspicious transaction report to the FIU, or to provide additional information the Unit requestsAED 100,000AED 500,000
23Failure to register on the FIU’s approved electronic systemAED 50,000AED 200,000
24Failure to appoint a compliance officer with the competence and experience for the roleAED 50,000AED 200,000
25Failure to enable the compliance officer to perform the duties the regulations assignAED 50,000AED 500,000
26Failure to keep records and data, or to organise them so transactions can be reconstructedAED 50,000AED 200,000
28Tipping off — disclosing to the customer that a report has been or will be filedAED 100,000AED 500,000
32Failure to comply with supervisors’ instructions, regulations and forms, or to answer a request for informationAED 50,000
34Failure to screen databases and transactions against the sanctions listsAED 50,000AED 1,000,000
35Failure to freeze funds promptly and without prior warning when a local-list match appearsAED 500,000AED 1,000,000

Source: list annexed to Cabinet Resolution No. 71 of 2024, from the Ministry of Economy and Tourism’s own published copy, checked 5 August 2026. Item 32’s maximum carries a typesetting error in the published English translation, so only its floor is shown.

Above the fixed list sits the supervisor’s general power in Article 17(1)(b) of Federal Decree-Law No. 10 of 2025 — an administrative fine of AED 10,000 to AED 5,000,000 for each violation, alongside warnings, restrictions on responsible officers, suspension of the activity and revocation of the licence. And Article 28 of the same Decree-Law makes a deliberate or grossly negligent failure to report under Article 18 a criminal matter, punishable by imprisonment and a fine of AED 100,000 to AED 1,000,000, or either.

What triggers the duty in the first place

The single most common reason a firm has no goAML account is that it never worked out it was in scope. Cabinet Decision No. 134 of 2025 sets the scope in Article 3, and the thresholds are specific rather than general.

CategoryTrigger in Article 3Threshold
Commercial gaming operatorsA single financial transaction, or linked transactionsAED 11,000
Real-estate brokers and agentsConcluding transactions or settlements for a customer on a purchase or sale of real estateNo value threshold
Dealers in valuable metals and precious stonesAny single cash transaction, or linked cash transactionsAED 55,000
Lawyers, notaries, independent legal professionals and independent accountantsListed activities including real-estate dealings, managing client funds or accounts, arranging company formation, and buying or selling commercial entitiesActivity-based, no value threshold
Company and trust service providersActing as incorporation agent, arranging directors or partners, providing a registered office, arranging a trustee or nominee shareholderActivity-based, no value threshold

Two more thresholds sit one article later and are frequently confused with the ones above. Article 7(2)(a) requires customer due diligence on occasional transactions at or above AED 55,000, single or linked; Article 7(2)(b) sets AED 3,500 for occasional transactions in the form of wire transfers; and Article 7(3) applies the same AED 3,500 to virtual asset service providers.

Note who Article 7(2) names, because the 2025 rewrite narrowed it. Both of its limbs apply to Financial Institutions only. The repealed Article 6(2) of Cabinet Decision No. 10 of 2019 applied the AED 55,000 occasional-transaction trigger to Financial Institutions and DNFBPs; Article 7(2) of Cabinet Resolution No. 134 of 2025 does not. So the AED 55,000 in Article 3(3) is a scope test for precious-metals dealers, on cash only, and the AED 55,000 in Article 7(2)(a) is a due-diligence test for financial institutions.

They are the same number doing two different jobs for two different populations. What binds every DNFBP regardless of value is Article 7(1): customer due diligence on commencing a business relationship, on suspicion of a crime, and where there are doubts about the accuracy or adequacy of identification data already obtained. Read from Cabinet Resolution No. 134 of 2025 on 5 August 2026.

How Velmont Crest helps

If you are a DNFBP or financial institution and you cannot log in to goAML today, an upstream stage is almost certainly incomplete. The fix is rarely a password reset. It is usually a documentation refresh, an MLRO re-appointment, or a missing SACM linkage.

If you can log in but have never filed a report, that is not by itself a problem — many small DNFBPs go years without genuinely suspicious activity. What matters is whether your BRA, CDD files, SAR records and training logs would survive an inspection.

Velmont Crest’s UAE compliance team provides advisory support across the goAML lifecycle — from Business Risk Assessment through MLRO appointment, registration support, policy drafting and ongoing transaction-monitoring preparation. We pair this with bookkeeping and business setup advisory work so the AML evidence trail aligns with the underlying financial records. We are a DED-licensed UAE accounting firm and authorised channel partner with Meydan Free Zone and RAKEZ.

For a clean review of where your goAML setup stands today, book a free consultation.


Disclaimer: Velmont Crest is a DED-licensed accounting firm. We provide advisory, preparation and compliance support services. AML/CFT rules and goAML procedures change frequently — verify all requirements with the UAE Financial Intelligence Unit, the Central Bank of the UAE, the Ministry of Economy and Tourism and your sector regulator before acting, and engage a licensed legal or AML professional for advice specific to your circumstances.

References

Frequently asked questions

What is goAML and who runs it?
It's the anti-money-laundering reporting platform built by the UN Office on Drugs and Crime and used by financial intelligence units in more than 50 countries. In the UAE it's run by the Financial Intelligence Unit, which sits inside the Central Bank, at goaml.uaefiu.gov.ae. It's the single mandatory channel for filing suspicious transaction reports, suspicious activity reports, dealer in precious metals and stones reports, and high-value real estate transaction reports. Use of it is required under Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025.
Who has to register on goAML in the UAE?
Two groups. All financial institutions — banks, exchange houses, insurers, finance companies — and all DNFBPs: real estate brokers and agents, dealers in precious metals and stones, auditors, accountants, tax consultants, lawyers, notaries, corporate service providers. Virtual asset service providers regulated by SCA or VARA register too. None of it depends on your trade licence type, free zone versus mainland, or company size. Don't register and the fine runs from AED 50,000 to AED 200,000 — item 23 of the list annexed to Cabinet Resolution No. 71 of 2024, imposed by whichever of the Ministry of Justice or the Ministry of Economy and Tourism supervises you.
Can I log in to goAML before my account is approved?
No, and this trips up almost everyone. After you submit, the FIU reviews the registration before it activates. Until the approval email lands with your organisation ID and user ID, the login screen just rejects your credentials — usually with 'invalid username or password' or 'account pending approval'. The FIU does not publish a service-level turnaround, so there is no official waiting period to measure yourself against; if the wait feels long, contact the FIU help desk with your reference number rather than guessing. Re-submitting only sends you to the back of the queue.
What is an MLRO, and do I need one before registering?
An MLRO is your Money Laundering Reporting Officer — the named person who assesses internal suspicious-activity reports and files STRs and SARs to the FIU through goAML. And yes, you need one appointed in writing before you finish registration, because the form asks for the MLRO's name, Emirates ID, designation and contact details. They should be senior, independent of front-line client work where the firm is big enough to allow it, and reachable by the FIU. In small firms the owner or managing partner usually takes it on personally.
What does an accountant actually do in the goAML workflow?
Four things, mostly behind the scenes. We prepare the Business Risk Assessment that underpins the registration, draft or review the AML/CFT policy manual and CDD procedures, pull together the transaction-monitoring data (ledger extracts, customer ledgers, payment patterns) the MLRO needs to judge whether something is genuinely suspicious, and keep the evidence and audit trails to a five-year standard. What we don't do is file STRs for the firm — the appointed MLRO does that personally, and that line never moves.
What does DNFBP mean?
DNFBP stands for Designated Non-Financial Business or Profession. It is the FATF term the UAE has adopted for the non-bank sectors that money launderers use most: real estate agents and brokers, dealers in precious metals and stones, auditors and accountants, company and trust service providers, and lawyers or notaries when they handle client money or set up structures. If your licence covers one of those activities, you carry the same AML reporting duties as a bank, scaled to your size.
How long does goAML registration take in the UAE?
There is no published turnaround. The FIU reviews each application before activating the account, and it does not commit to a service level, so any firm quoting you a guaranteed number of days is guessing. What you can control is whether the file goes back and forth, and the two usual causes of that are an entity name that does not match the trade licence exactly and an MLRO appointment letter that was never signed. Register early in a licence year rather than against a renewal deadline, because the one timeline you cannot manage is the reviewer's.
What is AML compliance in the UAE, in practical terms?
It is four connected obligations rather than a single filing. You assess your own money-laundering risk in writing, you know who your customers are through documented CDD and screening, you appoint an MLRO with the authority to escalate and report, and you keep records for five years so the work can be inspected later. goAML registration is the visible part, but a supervisor examining your file will spend most of its time on the other three.
What should an AML policy manual actually contain?
At minimum it sets out your risk appetite and the Business Risk Assessment behind it, the CDD and enhanced due diligence steps for each customer category, sanctions and PEP screening procedure, the internal escalation route to the MLRO, the decision record the MLRO must keep, the tipping-off prohibition, staff training frequency, and record retention. It should read like something your team can follow on a busy day, not a document written to be filed and forgotten.

Filed under: goAML, AML compliance, DNFBP, FIU, STR, MLRO

Published · Updated