Insights AML
goAML Renewal UAE 2026: Annual Data Refresh Process
How UAE DNFBPs maintain goaml registration through annual data refresh, MLRO updates and FIU notifications to avoid AED 50,000 penalty exposure.

Key takeaways
- goAML registration does not expire, but the data within must stay current under FIU supervision.
- Seven DNFBP categories plus financial institutions must complete the annual refresh cycle.
- Material changes (MLRO, UBO, address, activity) trigger immediate updates outside the annual window.
- Cabinet Resolution 71 of 2024 sets DNFBP fines from AED 50,000 to AED 1,000,000 per violation.
- Common failures: stale MLRO email, missed share transfers, undocumented sanctions tool changes.
- A specialist accountant prepares the data pack, drafts the BRA and reconciles UBO to ledger.
goAML renewal in the UAE is an annual data refresh, not a re-registration: the portal account never expires, but the MLRO details, beneficial ownership records, business risk assessment and sanctions-screening attestations inside it must be reconfirmed every year and after any material change. Designated Non-Financial Businesses and Professions commonly assume goAML registration is a one-time exercise — portal account created, MLRO appointed, welcome email filed, done. That assumption is where avoidable exposure begins, because a Ministry of Economy and Tourism supervisory visit or a Financial Intelligence Unit follow-up tests the current state of the record, not the date it was first created.
Under Federal Decree-Law 10 of 2025 — issued 30 September 2025, which repealed Federal Decree-Law 20 of 2018 at its Article 41 — and its executive regulation, Cabinet Resolution 134 of 2025, issued 29 October 2025, goAML registration is a living record. The portal profile, the business risk assessment, the MLRO appointment and the sanctions screening attestations all need refreshing annually, and again whenever a material change happens in the licensee. For firms juggling trade licence renewals, corporate tax registration and VAT reporting, that continuous control is exactly the thing that falls through the cracks. Our AML compliance advisory practice exists to close that gap with a structured annual refresh discipline.
What “renewal” actually means here
The word “renewal” is doing a lot of damage here, so let’s clear it up first. The goAML account has no fixed expiry the way a trade licence does. No annual fee, no automatic suspension, no portal lockout on some anniversary. What you do have is an AML/CFT obligation to keep every data point inside the portal profile accurate at all times — which is a quieter, easier-to-miss duty than a hard deadline would be. The Ministry of Economy and Tourism, as AML/CFT supervisor for the DNFBP sector, has been explicit in its inspection circulars: stale data is treated as no data. The Financial Intelligence Unit, which operates the goAML portal at goaml.uaefiu.gov.ae, expects licensees to run an internal annual refresh discipline that re-attests every field, refreshes every supporting document and re-signs the MLRO appointment.
In practice, that means scheduling a fixed annual review window, walking the portal screen by screen, validating each field against the current UAE trade licence and shareholder records, and producing a dated refresh certificate that sits in the AML file next to the original registration evidence. The certificate matters as much as the update: it is the artefact that proves the review happened on a date, which is precisely what a UAE supervisor asks for and what a corrected field on its own cannot demonstrate. Skip the discipline and the portal account still works. The compliance posture does not. The appointment being re-signed here — the role itself and the letter that evidences it — is set out in our guide to the MLRO job description and appointment letter.
The legal stack the refresh sits on
Before the mechanics, it is worth knowing which instruments are actually live, because the UAE AML framework was rebuilt in late 2025 and a great many manuals still cite the repealed statute.
| Instrument | Status | What it governs |
|---|---|---|
| Federal Decree-Law No. 10 of 2025 | Issued 30 September 2025; Article 41(1) repealed FDL 20 of 2018; Article 42 brings it into force two weeks after Official Gazette publication | The operative UAE AML/CFT statute |
| Cabinet Decision No. 134 of 2025 | In force since December 2025 | Executive regulation — DNFBP categories, CDD, reporting |
| Cabinet Resolution No. 71 of 2024 | Issued 8 July 2024 under the 2018 law; preserved by Art 41(3) of FDL 10 of 2025 | DNFBP administrative penalties — 41 items, AED 50,000 to AED 1,000,000 |
| Cabinet Resolution No. 16 of 2021 | Repealed by Art 8 of Cabinet Resolution No. 71 of 2024 | The earlier penalty schedule |
| Federal Decree-Law No. 20 of 2018 | Repealed | The former UAE AML statute |
Article 41(3) of the 2025 Decree-Law is the provision that keeps the penalty schedule alive: resolutions issued under the 2018 law remain effective until superseding instruments are made, and the Ministry of Economy and Tourism continues to publish Cabinet Resolution No. 71 of 2024 in its AML legal framework. So the statute changed while the fines did not.
The practical consequence for a UAE DNFBP is a documentation task rather than a new obligation. AML manuals, MLRO appointment letters, business risk assessments and CDD procedures that cite Federal Decree-Law No. 20 of 2018 as the governing law are now citing a repealed statute — a defect a supervisor will note, and one the annual refresh is the natural moment to correct.
Who has to do this every year
The obligation falls on every entity that was required to register on goAML in the first place. For DNFBPs, UAE goAML registration is the entry point into this regime, and the annual refresh keeps it alive. Under the UAE framework that means two broad populations. The first is financial institutions, which sit under Central Bank supervision and have their own parallel reporting expectations. The second, and the one that this article focuses on, is the seven DNFBP categories defined under the UAE AML framework and its executive regulation, Cabinet Decision 134 of 2025.
Those seven categories are: real estate brokers and agents involved in transactions for clients; dealers in precious metals and precious stones (DPMS) handling single transactions or linked transactions at or above the AED 55,000 threshold; auditors; accountants and tax consultants providing specified services; lawyers, notaries and other independent legal professionals when carrying out specified financial transactions; and corporate service providers and trust service providers involved in company formation, nominee director services or registered office provision.
| DNFBP category | When the obligation bites |
|---|---|
| Real estate brokers and agents | Acting in transactions for clients |
| Dealers in precious metals and stones (DPMS) | Single or linked transactions at or above AED 55,000 |
| Auditors | On the licensed activity |
| Accountants and tax consultants | When providing the specified services |
| Lawyers, notaries and independent legal professionals | When carrying out specified financial transactions |
| Corporate service providers | Company formation, nominee director services |
| Trust service providers | Trust arrangements, registered office provision |
Every entity holding a UAE trade licence that activates any of these regulated activities must hold a live goAML registration and must operate the annual refresh discipline against that registration. The test is the activity on the licence, not the emirate — a Dubai mainland brokerage, a Sharjah free zone corporate service provider and an Abu Dhabi jewellery dealer sit under the same obligation. For sector-specific context on how this interacts with day-to-day operations, our notes on gold and jewellery accounting in the UAE cover the DPMS angle in depth, while our real estate accounting guide addresses the broker AML overlay.

Pin the refresh to the same month your trade licence renews
If there is one habit worth building here, it is this: fix the refresh to a predictable point in the calendar. The cleanest anchor is your trade licence renewal month, because the underlying corporate records — shareholder register, registered address, business activities — are already being pulled and refreshed then for the Department of Economic Development or your free zone authority. Align the goAML refresh to that same window and the data pack gets assembled once, the directors sign once, and the MLRO gets pulled in once. Less rework, fewer gaps.
Within the refresh window, these are the items that must be reviewed and re-attested:
- MLRO contact details — full name, Emirates ID, mobile, professional email and appointment letter date.
- The deputy MLRO, where one has been appointed.
- The registered office address and licence number.
- The full list of beneficial owners holding twenty-five per cent or more, with passport and address evidence retained.
- A refreshed business risk assessment that reflects the current customer mix, geographic exposure and product or service risk.
- The customer due diligence procedure document, with version control.
- The sanctions screening tools currently in use — typically a combination of the OFAC SDN list, the UN 1267 consolidated list and the UAE local sanctions list maintained by the Executive Office for Control and Non-Proliferation.
- The suspicious transaction report retention log, confirming the five-year archive obligation.
Each of these items should produce a dated artefact that the MLRO signs off, and the full pack should live in a single AML folder that any future supervisor can review in a single sitting.
When you can’t wait for the annual window
The annual cycle is the floor, not the ceiling. There is a parallel obligation to update the portal promptly whenever a material change occurs in the underlying licensee. Waiting until the next annual window in these cases is not acceptable and creates penalty exposure independent of the annual cycle.
The triggering events to watch for are these:
- MLRO resignation, replacement, prolonged absence or change of contact details, where the new appointment letter must be uploaded and the portal profile updated within fifteen working days.
- Any beneficial ownership change above twenty-five per cent, whether through share transfer, inheritance, corporate restructuring or the addition of a new shareholder.
- Change of the registered office address, including moves within the same emirate.
- Any addition or deletion of business activities on the trade licence, particularly where a new activity brings the licensee within a new DNFBP category.
- Opening of a branch in another emirate or free zone, where the branch may need its own profile linkage.
- Any change to the EmaraTax registration, including VAT or corporate tax linkage.
- Any change to the sanctions screening tool or vendor, which requires a fresh attestation.
The discipline we recommend is a single internal trigger log, owned by the company secretary or the engaged accountant, where every corporate change is flagged with a goAML implication column. That column either confirms no update is needed or generates a workflow ticket to update the portal.
AED 50K
Starting fine for non-registration or stale data per FIU notice
What stale data actually costs
Cabinet Resolution No. 71 of 2024 is the operative penalty framework for DNFBP AML breaches, and it is worth reading in full at least once because the bracketing is wider than most directors assume. It was issued on 8 July 2024 under the 2018 AML law and its 2019 Executive Regulations, and Article 8 repealed the earlier schedule in Cabinet Resolution No. 16 of 2021.
Both parent instruments have since been replaced, but Article 41(3) of Federal Decree-Law No. 10 of 2025 keeps resolutions issued under the 2018 law effective until superseding ones are issued, and the Ministry of Economy and Tourism still publishes this Resolution in its AML legal framework. Failure to register on the electronic system approved by the FIU is item 23 of the annexed list, at AED 50,000 to AED 200,000.
Registration data that has gone stale is not a separate item; it falls under item 32, failure to comply with the instructions, regulations and forms set by supervisory authorities, from AED 50,000. Across the 41 items the fines reach AED 1,000,000, and Article 5(2) allows the Ministry to double a fine where the same violation is repeated. In practice, the Ministry of Economy and Tourism and the Financial Intelligence Unit do issue grace warnings to first-time offenders where the breach is technical and quickly remediated.
However, those warnings are recorded against the licensee file, and a second finding within the same supervisory cycle typically triggers the full administrative penalty without further warning. The structural risk is that fines are charged per violation, so a single inspection can produce several linked findings at once — a stale MLRO record, a missing UBO refresh and an outdated business risk assessment are three findings, not one, and each carries its own bracket from AED 50,000 upwards. In serious cases the framework also permits suspension of the trade licence, which for an operating UAE business effectively stops trade until it is resolved.
The arithmetic of “per violation” is worth setting out plainly, because it is what makes a stale profile disproportionately expensive.
| Scenario | Findings | Minimum bracket exposure |
|---|---|---|
| Never registered on the FIU’s electronic system | 1 (item 23) | AED 50,000 to AED 200,000 |
| Registered, but the MLRO record is out of date | 1 (item 32) | From AED 50,000 |
| MLRO, UBO and BRA all stale at one inspection | 3 | From AED 150,000 combined |
| Same violation repeated in a later cycle | — | Article 5(2) permits the Ministry to double the fine |
| Across the full annexed list of 41 items | — | Fines run to AED 1,000,000 |
Those brackets are the Resolution’s own figures, imposed by the Ministry of Economy and Tourism or the Ministry of Justice, and they sit alongside the criminal provisions of the AML law rather than replacing them. The point of the table is not the headline number but the multiplier: the difference between one finding and three is a single afternoon of record-keeping done once a year.
For licensees who also hold corporate tax obligations, these AML findings interact with broader FTA-supervised compliance, and our corporate tax services team coordinates the cross-references so that one supervisory event does not cascade into another.

Five ways a goAML profile goes stale
Five failure patterns account for most of what turns a live registration into a stale one. Each is individually easy to fix; in combination they produce the kind of supervisory finding that puts a UAE licensee squarely inside the annexed list of Cabinet Resolution No. 71 of 2024.
- A stale MLRO email. The appointed officer has changed roles internally or left the firm, and the portal still routes notifications to a dormant inbox. The consequence is a notification failure — the licensee misses any subsequent supervisory correspondence and only discovers it when something has already escalated.
- A forgotten ownership change during a share transfer. The corporate records have been updated with the Department of Economic Development or the free zone authority, but the goAML beneficial ownership declaration has been left untouched, so two UAE government records now disagree about who owns the business.
- A new free zone branch. A branch is added to the licensee group and the head office goAML registration is assumed to cover it, with no separate evaluation of whether the branch’s activity brings it inside a DNFBP category in its own right.
- A sanctions screening tool change. The licensee has switched vendors or upgraded software, but the portal attestation still references the previous tool — so the evidence log and the declared control describe different systems.
- A suspicious transaction report retention gap. The five-year retention obligation has not been documented in the AML manual, and the supervisor cannot evidence that the archive exists at all.
The annual refresh discipline catches all five in a single workflow.
What “material change” means in practice
The event-driven obligation is the one that generates exposure between annual windows, so it is worth being precise about what triggers it and what evidence has to follow.
| Trigger event | What has to change in the profile | Supporting evidence to file |
|---|---|---|
| MLRO resignation, replacement or prolonged absence | Name, Emirates ID, mobile, professional email, appointment date | Signed appointment letter, board minute |
| Deputy MLRO appointed or removed | Deputy record | Appointment or revocation letter |
| Beneficial ownership crossing 25% | Full UBO list re-declared | Share transfer instrument, updated register, passport and address evidence |
| Change of registered office | Address and licence data | New tenancy, updated trade licence |
| New or deleted licensed activity | Activity list, and DNFBP category assessment | Amended trade licence |
| New branch in another emirate or free zone | Branch linkage assessment | Branch licence, group structure note |
| EmaraTax registration change | VAT or corporate tax linkage | FTA registration certificate |
| Sanctions screening tool or vendor change | Screening attestation | Vendor contract, dated screenshots of the new tool |
Two of those rows carry a UAE-specific trap. The registered address must match the trade licence character for character, because a supervisor comparing the two reads a discrepancy as a stale record rather than a typo. And the DNFBP category assessment on a new activity is a judgement, not a lookup — adding a company-formation or registered-office activity to a Dubai licence can pull a business inside the corporate service provider category for the first time, which changes the whole obligation set rather than merely a field.
The discipline that holds all of this together is a single internal trigger log, owned by the company secretary or the engaged accountant, in which every corporate change carries a goAML implication column. That column either confirms no update is needed or raises a workflow ticket — and either way it leaves a dated record that the question was asked.
The biggest myth in UAE AML is that the hard work ends at registration. In supervisory practice, the opposite is true: the registration is the easy part, and the annual refresh is where the regulated discipline is actually tested.
Where the accountant sits in the renewal
A specialist accounting firm sits behind the annual refresh as infrastructure, not as the regulated representative. The MLRO is the appointed officer of the licensee. The directors carry ultimate responsibility under the AML regime. What we provide on the advisory side is the data pack, the workflow and the documentation discipline that turns the MLRO’s sign-off into a two-hour exercise rather than a two-week scramble.
Concretely, that means we reconcile the ultimate beneficial ownership declaration against the share register, the memorandum of association and the underlying ledger; we draft the updated business risk assessment using the current customer mix, transaction volume and geographic exposure data drawn from the accounting and bookkeeping records we maintain; we compile the sanctions screening evidence log with date-stamped screenshots and tool version references; we prepare the board-level documentation in the format the MLRO needs for sign-off; we coordinate the trade licence and EmaraTax cross-references so that all three registrations tell the same story; and we produce a single dated refresh certificate that lives in the AML file.
The MLRO remains the regulated person, signs the portal submission and retains decision authority over any suspicious transaction reporting. We do not act as the MLRO, we do not represent the licensee before the FIU, and we do not hold the regulated appointment. That separation is deliberate and protects both the licensee and the advisory relationship.
A 30-day checklist before you sign off
The cleanest way to operationalise the annual refresh is a thirty-day pre-renewal checklist that the company secretary or engaged accountant works through in the month before the chosen refresh anchor date. A workable ten-item list is as follows:
- Confirm the MLRO appointment letter is current, signed within the last twelve months and reflects the actual person in role today.
- Validate MLRO and deputy MLRO contact details against current HR records, including professional email, mobile and Emirates ID.
- Pull the latest shareholder register from the trade licence authority and reconcile every UBO holding at or above twenty-five per cent.
- Refresh the business risk assessment using the most recent twelve months of customer mix, transaction volume and geographic exposure data.
- Update the customer due diligence procedure document with version control, change log and MLRO sign-off page.
- Compile the sanctions screening evidence log confirming OFAC SDN, UN 1267 consolidated and UAE local list coverage with dated screenshots.
- Confirm the suspicious transaction report retention archive meets the five-year obligation and is accessible to the MLRO on request.
- Cross-check the trade licence activities against the seven DNFBP categories to confirm no new regulated activity has been added without portal update.
- Verify the EmaraTax linkage and registered office address match the goAML profile exactly, character for character.
- Produce and sign the dated annual refresh certificate and file it in the AML folder alongside the previous year’s certificate.
Sister reading on the initial registration side is available in our goAML registration and login guide for the UAE, which covers the first-time setup workflow that the annual refresh builds on top of. If your firm is a formation agent, our corporate service provider AML programme guide sets out the CSP-specific obligations that the refresh has to keep current, and our EDD vs CDD vs SDD guide explains the diligence tiers the refreshed risk assessment maps to.
Booking your annual goAML refresh
Velmont Crest supports DNFBP licensees across Dubai, Abu Dhabi, Sharjah and the northern emirates with the structured annual data refresh discipline that the UAE Financial Intelligence Unit expects but does not actively remind firms to perform. Our role is advisory and infrastructure-led: we build the data pack, run the reconciliations, draft the documentation and hand the MLRO a clean file to sign off. The regulated appointment, the portal submission and the supervisory liaison remain with the licensee and the appointed officer.
If your goAML profile has not been refreshed in the last twelve months, or if a material change has occurred without portal update, the exposure under Cabinet Resolution No. 71 of 2024 starts at AED 50,000 and compounds quickly across linked findings, because each violation is fined separately. Explore how our AML compliance support plugs into your existing licence renewal calendar to make the annual refresh a predictable, two-hour MLRO sign-off rather than a year-end scramble.
Frequently asked questions
- What does goAML annual renewal actually mean?
- It's not what the name suggests, and that's where most of the market confusion comes from. The goAML registration has no fixed annual expiry. What the Financial Intelligence Unit expects is an annual data refresh — a documented review and re-attestation of every field in your portal profile, plus your business risk assessment, MLRO appointment, beneficial ownership declaration and sanctions screening procedures. If any of that is materially wrong when a supervisor looks, you're exposed under Cabinet Resolution No. 71 of 2024, the DNFBP penalty schedule — item 32 covers failure to comply with the instructions, regulations and forms set by supervisory authorities, and starts at AED 50,000.
- When does the obligation to update goAML data trigger?
- Two triggers run side by side. One is the annual cycle, best pinned to your trade licence renewal month so the work is bundled and predictable. The other is event-driven, and it overrides the annual cycle: any material change has to hit the portal promptly, usually within fifteen working days. That covers an MLRO resignation or replacement, a beneficial ownership shift above twenty-five per cent, a change of registered address, a new business activity on the licence, a new free zone branch, or any change to the EmaraTax linkage. Sitting on those until your annual window creates exposure you didn't need to carry.
- What needs updating each year?
- The MLRO contact details and appointment letter, the deputy MLRO if you've appointed one, every beneficial owner at twenty-five per cent or more, the business risk assessment with refreshed sectoral and geographic scoring, the CDD procedure attestation, the sanctions screening tools in use (typically OFAC SDN, UN 1267 consolidated and the UAE local list), the five-year STR retention confirmation, and the registered address and licence details. Put it all in one dated pack the MLRO signs, with the supporting evidence kept on file for inspection.
- What are the penalties for late or missed goAML updates?
- Cabinet Resolution No. 71 of 2024 runs the DNFBP penalty framework. It was issued on 8 July 2024 under the 2018 AML law and stays in force under Article 41(3) of Federal Decree-Law 10 of 2025 until superseded. Failure to register on the FIU's electronic system is item 23 of its annexed list, at AED 50,000 to AED 200,000; across the 41 items the fines run to AED 1,000,000, and Article 5(2) lets the Ministry double a fine on a repeat. First-time offenders sometimes get a grace warning where the breach is technical and fixed quickly — but it's recorded against your file, and a second finding in the same cycle usually brings the full fine. Worse, a single inspection can produce several linked findings at once, so one stale record genuinely does cascade.
- Which AML law is currently in force in the UAE?
- Federal Decree-Law No. 10 of 2025 on Confronting Money Laundering and Combating the Financing of Terrorism and Illegal Organisations. Article 41(1) repealed Federal Decree-Law No. 20 of 2018. It was issued on 30 September 2025 and enters into force two weeks after Official Gazette publication under Article 42. Its executive regulation is Cabinet Resolution No. 134 of 2025, issued 29 October 2025. Resolutions made under the 2018 law survive: Article 41(3) keeps them effective until superseded, which is why Cabinet Resolution No. 71 of 2024 still governs DNFBP penalties. If your AML manual or MLRO appointment letter still cites the 2018 law as operative, that is a documentation defect worth fixing.
- Does goAML registration expire, and is there a renewal fee?
- No on both counts. The goAML account has no fixed expiry the way a UAE trade licence does, no annual renewal fee, and no automatic portal lockout on an anniversary date. What exists instead is a continuing obligation to keep every data point in the profile accurate — the MLRO details, beneficial ownership, registered address, licensed activities, business risk assessment and sanctions screening attestations. The word 'renewal' is industry shorthand for the annual data refresh that discharges that obligation. Because there is no deadline in the system to prompt you, the discipline has to come from your own calendar, which is why anchoring it to the trade licence renewal month works so well.
- Who signs the goAML refresh — the accountant or the MLRO?
- The MLRO. The appointed compliance officer is the regulated person, holds the portal credentials, makes the submission and retains decision authority over any suspicious transaction report. An accounting firm supports the exercise as infrastructure: reconciling the beneficial ownership declaration against the share register and ledger, drafting the refreshed business risk assessment from current customer-mix data, compiling the sanctions screening evidence log, and preparing board-level documentation. That separation is deliberate. An adviser who offers to act as your MLRO or to represent you before the Financial Intelligence Unit is offering something a UAE accounting practice should not be providing.
- How can an accountant support the renewal?
- By building the file, not by becoming the regulated person. We reconcile the UBO declaration against the share register and ledger, draft the updated business risk assessment from current customer-mix data, compile the sanctions screening evidence log, prepare the board-level documentation for the MLRO, and line up the trade licence and EmaraTax cross-references. The MLRO stays the appointed officer and signs the submission. That line never moves, and it's the reason the whole arrangement holds up under inspection.
Filed under: goAML, AML compliance, DNFBP, FIU, renewal, annual refresh
Published · Updated

