Skip to content

Insights AML

Gold Trader UAE AML: the DPMS Programme and the AED 55K Trigger

Gold trader AML compliance UAE: the DPMS AED 55,000 cash threshold, DPMSR filing via goAML, MLRO setup and CDD for dealers in precious metals and stones.

UAE gold and jewellery trader compliance officer documenting cash transaction above AED 55,000 threshold and preparing DPMSR submission through goAML to the FIU
UAE gold and jewellery trader compliance officer documenting cash transaction above AED 55,000 threshold and preparing DPMSR submission through goAML to the FIU Photo: Velmont Crest Editorial

Key takeaways

  1. DPMS scope under FDL 10/2025, CD 134/2025 — gold, silver, platinum, palladium and precious stones
  2. AED 55,000 single or aggregated cash threshold triggers a DPMSR filing
  3. DPMSR is filed through goAML — take the filing deadline from the FIU's current DPMSR guidance, not from a template
  4. CDD required for every cash counterparty regardless of repeat-customer status
  5. Sanctions screening against OFAC, UN consolidated and UAE Local Terrorist lists
  6. Five-year retention under CD 134/2025, with the MLRO as the named filer

A UAE gold trader AML programme is one of the highest-risk corners of the DNFBP framework, and it’s not hard to see why. The business runs on cash, the commodity moves across borders easily, and a slice of the customer base would rather not be asked too many questions. On top of that, the reporting obligations are unusually specific — they fire at the AED 55,000 cash threshold and nowhere lower. Building a gold trader AML UAE programme therefore means engineering the whole compliance system around that single number.

Every UAE Dealer in Precious Metals and Stones (DPMS) — gold wholesaler in the Dubai Gold Souk, jewellery retailer, diamond trader in the DMCC Diamond Exchange, bullion house, precious-metals refiner — is a scoped DNFBP under Federal Decree-Law No. 10 of 2025 and Cabinet Decision No. 134 of 2025. That means a Business Risk Assessment, an appointed MLRO, goAML registration through the UAE Financial Intelligence Unit, CDD on cash counterparties, threshold reporting through DPMSR and ongoing monitoring.

This guide walks through the scope, the AML programme template a UAE gold or jewellery trader needs in 2026, the AED 55,000 trigger mechanics, DPMSR drafting, STR red flags and what your external adviser is expected to prepare behind the scenes. If you would rather have the whole DPMS programme built and reviewed for you, Velmont Crest offers AML compliance support in the UAE for dealers in precious metals and stones. For the wider rulebook, see our AML compliance guide for UAE DNFBPs.

Why gold keeps drawing FIU attention

The UAE precious-metals sector handles a large share of global gold flow. The DMCC coordinates the Dubai Good Delivery refinery standard and the responsible-sourcing audits. The Dubai Gold and Commodities Exchange trades futures contracts that interact with physical flows. The FATF mutual evaluation of the UAE flagged DPMS supervision as a strategic priority, and the Ministry of Economy and Tourism (MoET) — the federal supervisor for DPMS — has stepped up on-site inspections since 2022.

The DPMS scoping language captures:

  • UAE gold wholesalers in the Dubai Gold Souk, Sharjah Souk and other emirate gold districts
  • Jewellery retailers in malls, souks and standalone stores selling pieces containing precious metals or stones
  • Diamond traders in the DMCC Diamond Exchange and other diamond markets
  • Bullion dealers and houses selling investment-grade gold, silver, platinum and palladium
  • Precious-metals refiners processing scrap, bar and coin
  • Wholesalers supplying retail jewellery outlets across the UAE and the wider region

The trade licence category — commercial, industrial or specialist — does not change the obligation. Free zone DMCC operators face identical AML obligations to mainland Department of Economic Development licensees. Nor does a gold trading license in Dubai buy any softer treatment than one issued in Sharjah or Ajman, because AML compliance in the UAE is federal law rather than a licensing condition attached to one authority.

Velmont Crest is a DED-licensed accounting firm supporting AML compliance and gold and jewellery sector accounting for DPMS operators across mainland and free zone setups.

UAE gold wholesale compliance officer reviewing daily cash transaction aggregation report flagging counterparties approaching the AED 55,000 DPMSR threshold

Six things inspectors check, in this order

A defensible UAE DPMS programme has six pieces. Inspectors look for all six on a Ministry of Economy on-site visit.

Start with the Business Risk Assessment

The DPMS BRA scores firm-level exposure across five dimensions: customer risk (walk-in retail buyers, repeat wholesale buyers, business-to-business counterparties, non-resident visitors paying in cash), product risk (high-value bullion versus retail jewellery, scrap-gold buy-back), geographic risk (sourcing jurisdictions, customer origin countries, FATF high-risk markets), delivery channel risk (in-store sales versus off-counter wholesale transactions) and transaction risk (cash exposure, payment-method mix, deal-size distribution). The BRA is refreshed annually and whenever the trader enters a new product line or sourcing corridor.

The threshold monitoring procedure that actually catches things

This is the operational heart of a DPMS programme. The procedure defines:

  • How cash transactions are recorded at the point of sale or wholesale counter
  • How transactions are aggregated by counterparty across the calendar day and the calendar week
  • The flagging rule that surfaces every counterparty reaching or exceeding the AED 55,000 cash threshold
  • The daily MLRO review of flagged-transactions report
  • The DPMSR drafting workflow and the filing deadline through goAML, taken from the FIU’s current DPMSR guidance rather than from a template

A POS that records transactions but never aggregates by counterparty leaves the MLRO blind. A back-office reconciliation that groups by date but not by buyer ID fails for the same reason. The Ministry of Economy expects the aggregations to surface on their own — not for someone to go hunting for them after the fact.

CDD before the sale completes, not after

CDD on cash counterparties at or above the threshold collects: passport or Emirates ID copy, residential address, source of funds narrative, intended use of the gold or stones purchased, and screening clearance. For repeat buyers a file is opened on first qualifying transaction and refreshed periodically. For walk-in customers paying in cash at threshold, CDD is collected before the transaction completes — not after.

For wholesale customers and business counterparties, CDD extends to the legal entity (trade licence, MoA, registered office) and every Real Beneficiary under the Real Beneficiary Procedures in Cabinet Resolution No. 109 of 2023. Get the instrument right: Article 22 of Cabinet Resolution 109 of 2023 cancelled Cabinet Resolution No. 58 of 2020, which is still cited on a great many UAE compliance manuals. Article 5(1) of the 2023 Resolution sets the test at direct or indirect ownership of 25% or more of the capital, or 25% or more of the voting rights, including control exercised by other means such as the right to appoint or remove a majority of the board.

Sanctions and PEP screening every time

Every CDD’d counterparty is screened against the UAE Local Terrorist List, the UN Security Council Consolidated Sanctions List, the OFAC Specially Designated Nationals list and adverse-media databases. Screening is captured in writing with source, date, reference and clearance decision. Re-screening runs whenever a list is materially updated and at periodic refresh cycles for repeat counterparties.

Appointing the MLRO and getting on goAML

The MLRO is appointed in writing before the goAML registration is submitted. The MLRO has direct authority to file DPMSRs and STRs without obtaining permission for each filing and reports straight to senior management. The trader then completes the Ministry of Economy SACM registration, the goAML enrolment and the linked EmaraTax records. See our goAML registration guide for the step-by-step portal walkthrough.

Training, records and the annual self-assessment

Counter staff, wholesale staff and management complete annual AML training documented with attendance logs. Counter-staff training specifically covers cash structuring identification, refusal of CDD documentation by a buyer, and the internal escalation route. All CDD files, DPMSRs, STR filings and MLRO assessments are retained for five years from the transaction date under CD 134/2025. The trader files an annual self-assessment report with the Ministry of Economy through SACM.

AED 55,000

Cash transaction threshold per Cabinet Decision 134 of 2025 — aggregated across linked transactions with the same counterparty, not per individual invoice

Counter staff at UAE jewellery store collecting passport and source of funds narrative from cash customer above AED 55,000 reporting threshold before transaction completion

What the executive regulation actually says, clause by clause

Most DPMS programme templates paraphrase the rules. It is worth reading the exact wording once, because two of the most common design errors — treating AED 55,000 as a per-invoice figure, and treating the CDD threshold as a DPMS-only rule — disappear the moment you see the text.

Cabinet Resolution No. 134 of 2025, the executive regulation of Federal Decree-Law No. 10 of 2025, brings dealers into DNFBP scope in these terms: “Dealers in valuable metals and precious stones, when carrying out any single cash transaction or several transactions that appear to be linked and whose value equals or exceeds fifty-five thousand dirhams (AED 55,000).” Two words in that sentence do the heavy lifting — cash, and linked.

RuleWhat Cabinet Resolution 134 of 2025 providesWhere it sits
DPMS scope triggerAny single cash transaction, or several transactions that appear to be linked, equal to or above AED 55,000Article 3, item 3 (DNFBP scope)
Financial institution occasional-transaction CDDAED 55,000, single or several linked transactionsArticle 7(2)(a)
Wire transfer CDD threshold for financial institutionsAED 3,500Article 7(2)(b)
Virtual asset service provider occasional-transaction CDDAED 3,500, single or several linkedArticle 7(3)
Record retention — transactions and commercial dealingsNot less than five years from completion of the transaction or termination of the business relationshipRecord-keeping provisions
Record retention — CDD records, STR analysis, CCTV and ATM recordingsNot less than five years from the later of relationship termination, account closure, completion of an occasional transaction, completion of a supervisory inspection, completion of an investigation, or a final court judgmentRecord-keeping provisions
Refusing or unable to complete CDDConsider submitting a Suspicious Transaction Report to the UnitArticle 14(1)
Suspicion of a crime where CDD would tip off the customerMay refrain from CDD, and must submit an STR stating the reasonsArticle 14(2)
Duty to build and update suspicion indicatorsEstablish indicators to identify suspicion of a crime and update them on an ongoing basisArticle 17

Read from the English text of Cabinet Resolution No. 134 of 2025 on 5 August 2026. Federal Decree-Law No. 10 of 2025 was issued on 30 September 2025 and repealed Federal Decree-Law No. 20 of 2018 at its Article 41; Cabinet Resolution No. 134 of 2025 was issued on 29 October 2025 and repealed Cabinet Decision No. 10 of 2019 at its Article 70.

Two honest gaps are worth stating rather than papering over. The AED 55,000 figure in Cabinet Resolution 134 of 2025 is expressly a cash figure for dealers. The UAE Financial Intelligence Unit’s own goAML material describes the DPMSR as also covering transactions with companies and entities at or above AED 55,000, which is where the international-transfer point below comes from — but that operational scope sits in the FIU’s reporting guidance, not in the executive regulation, so read it from the FIU’s current DPMSR submission guide rather than from this page. And the executive regulation does not set the DPMSR filing deadline. The two-week window is an FIU reporting-guidance figure, not a Cabinet Resolution one; confirm the current deadline inside goAML before you build it into a procedure.

How aggregation works

The threshold mechanics matter because most DPMSR omissions trace back to misunderstanding what counts as a single transaction. The Ministry of Economy applies four operational rules:

  1. Single transaction. A single cash invoice at or above AED 55,000 triggers DPMSR — straightforward.
  2. Linked transactions within the same visit. Multiple cash invoices to the same buyer in the same visit are aggregated. AED 30,000 + AED 25,000 = one AED 55,000 transaction.
  3. Linked transactions within the same calendar day. Multiple cash transactions with the same buyer on the same day are aggregated even across separate visits or counters.
  4. Structuring suspicion. Multiple cash transactions with the same buyer across days that appear designed to stay below the threshold trigger an STR regardless of whether any individual day reaches AED 55,000.

The filing clock runs from the date of the qualifying transaction, not from the date the MLRO completes the assessment. A DPMSR filed after the window closes is a late filing — an inspection finding even where the substantive content is correct. Take the length of that window from the FIU’s current DPMSR submission guidance on uaefiu.gov.ae: it is a reporting-guidance figure rather than one set in Cabinet Resolution 134 of 2025, and it is not something to inherit from an old procedure manual.

When a sale should stop and the MLRO should hear about it

Beyond the threshold mechanics, certain customer behaviours trigger an STR regardless of value.

The buyer who insists on cash, broken into pieces

  • Customer offers to pay in cash for a transaction below the AED 55,000 threshold but breaks the payment into multiple instalments designed to stay below it
  • Customer arrives with cash bundled in unusual denominations or sealed wrappers consistent with bulk transport
  • Customer requests an invoice value that does not match the cash tendered
  • Payment instructions involve a third party not previously disclosed
  • Wholesale customer requests cash payment for product invoiced electronically

The customer who can’t explain why they’re here

  • Customer refuses to provide identification at or above the threshold and asks to walk away from the transaction
  • Customer cannot articulate the source of cash or provides inconsistent stories
  • Repeat customer pattern of just-below-threshold purchases over compressed periods
  • Customer is uninterested in the product specification, design or quality and focuses entirely on weight or bullion content
  • Customer requests delivery to an address materially distant from the place of purchase without explanation

The wholesale request that doesn’t fit a retail story

  • Wholesale request for high volumes of a single bullion specification without retail destination
  • Buyback request for newly purchased product within a short period at the same outlet
  • Customer offers to sell scrap gold of inconsistent origin without documentation
  • Request to melt down identifiable jewellery for bullion without provenance evidence

The name that doesn’t pass screening

  • Beneficial owner or named counterparty appears on a sanctions list — OFAC, UN, UK HMT, UAE Local Terrorist List
  • Adverse media linking the buyer to investigations or proceedings
  • Counterparty is a Politically Exposed Person not previously disclosed
  • Counterparty is registered in a FATF high-risk jurisdiction without commercial rationale

When any of these triggers appear, the staff member escalates to the MLRO without tipping off the customer. Tipping off is a criminal offence under the UAE AML law.

The single change that prevents most DPMSR omissions is configuring the POS or back-office system to flag any counterparty reaching seventy percent of the threshold during a calendar day. That gives the MLRO time to confirm CDD is complete and to authorise the transaction before it exceeds AED 55,000 — instead of discovering the breach the next morning when the daily report runs.

— Velmont Crest advisory note
UAE Ministry of Economy inspector reviewing DPMS dealer training records aggregated cash transaction log and MLRO assessment memos during scheduled inspection

Where we see programmes slip

Per-invoice thinking is the one that catches most firms. Treat each invoice in isolation and you miss the aggregation rule for same-counterparty same-day transactions, and that single misreading is behind more late or missed DPMSRs than anything else on this list.

The next slip is timing on CDD. When the sale is allowed to complete and the passport gets asked for at handover, the transaction has already gone through and can no longer be evaluated. The procedure wants CDD collected before completion at the threshold, not after.

Walk-in repeat customers without a file are a quieter problem. A buyer who keeps coming back for cash purchases at AED 30,000 to 50,000 is a structuring red flag even where no single visit reaches the threshold, and the MLRO needs a file showing the pattern was actually looked at.

Then there is the counter itself. An assistant who doesn’t recognise a structuring pattern or doesn’t know the escalation route disables the whole programme at the exact moment it’s supposed to work.

Sanctions screening pegged to transaction size is another one. Exposure doesn’t scale with deal value. A AED 10,000 cash sale to a sanctioned individual is still a sanctions violation, so screening has to run for every CDD’d counterparty, not just the big ones.

And late filings. The clock runs from the transaction date, not from the date the MLRO finishes the assessment, so the internal workflow needs to leave the MLRO enough time to assess and submit well before the deadline — whatever deadline the FIU’s current DPMSR guidance sets.

What a gold trader AML UAE DPMS programme template includes

A gold trader AML UAE DPMS programme template is a binder of documents, not a single policy. When the Ministry of Economy asks to see your programme, these are the files it wants on the desk. A workable set covers:

  • The Business Risk Assessment, dated and signed, scoring customer, product, geographic, channel and transaction risk
  • An AML policy manual covering AML/CFT that states the AED 55,000 cash threshold and the aggregation method in plain terms
  • A threshold-monitoring procedure describing how cash is grouped by counterparty across the day
  • A customer due diligence procedure for walk-in and wholesale buyers, with the UBO verification steps for corporate customers
  • The written MLRO appointment letter and the goAML registration confirmation
  • Blank DPMSR and STR working templates, plus a sanctions-screening register
  • Training records with attendance logs and a five-year retention schedule

Keep the template as living documents. A binder printed once and never revisited is treated as no programme at all — the Ministry expects each file to carry a recent review date. Refresh the Business Risk Assessment yearly, and re-date the policy manual whenever the rules or your product lines shift.

DMCC gold and diamond traders carry an extra responsible-sourcing layer

If you hold a DMCC licence, the federal DPMS obligations are only half the picture. DMCC members trading precious metals and stones sit under the free zone’s own responsible-sourcing regime, which runs alongside the AED 55,000 reporting rules rather than replacing them. In practice that means a second body of due diligence aligned to the OECD Due Diligence Guidance for Responsible Supply Chains of Minerals from Conflict-Affected and High-Risk Areas — supply-chain policies, counterparty checks on where the metal came from, and a responsible-sourcing report or audit for firms in scope. Refiners on the Dubai Good Delivery list carry the heaviest version of this.

None of it displaces the goAML and DPMSR work. A DMCC gold or diamond trader runs both tracks at once: the FIU-facing threshold reporting and the DMCC-facing sourcing programme. The overlap is the counterparty file, so build one due diligence record that satisfies both. Our DMCC free zone guide covers the licensing side, and the OFAC sanctions screening checklist covers the screening both regimes expect.

Does the AED 55,000 rule apply to card and bank transfers?

This trips up a lot of gold and jewellery desks. For an individual customer, the DPMSR trigger is specifically a cash threshold. A AED 200,000 sale to a private buyer paid by domestic bank transfer, cheque or card runs through the regulated banking system, which already carries its own monitoring, so on its own it does not generate a DPMSR. The reportable cash event is AED 55,000 or more.

The picture shifts for corporate customers. Where the buyer is a legal person, an international wire transfer at or above AED 55,000 is also a reportable DPMSR event — not only cash — so a company settling a large purchase by cross-border transfer can trigger the report with no cash changing hands at all.

That does not put electronic payments outside the programme. Customer due diligence still applies to the counterparty whatever the payment method, sanctions screening still runs, and a bank-transfer deal can still need an STR if the source of funds looks wrong or the pattern is odd. Mixed settlements are the trap. A buyer who pays AED 40,000 in cash and the rest by card has still tendered AED 40,000 in cash, and if a second cash payment that day tips the cash total to AED 55,000, the cash portion is what counts. Track the cash leg separately from the card and transfer legs so the aggregation still works.

Where this leaves your gold trading desk

If your UAE gold or jewellery trading firm has not completed a Business Risk Assessment, configured a threshold-aggregation routine or registered an MLRO on goAML, you are outside the federal AML/CFT framework. Failing to register alone carries an administrative fine of AED 50,000 to AED 200,000 — item 23 of the list annexed to Cabinet Resolution No. 71 of 2024. Across the annexed list of 41 violations the fines run from AED 50,000 to AED 1,000,000, charged per violation, so missing CDD files (AED 50,000 to AED 200,000 a case) climb fast from there.

If you have a manual but it has not been refreshed against current Ministry of Economy expectations, the gap is usually in three places: the threshold-aggregation procedure is per-invoice rather than per-counterparty, counter-staff training has not been refreshed in twelve months, and sanctions re-screening is not running on repeat customers. Two companion reads help here — our MLRO appointment guide for the UAE covers who to name and how, and the Ministry of Economy AML inspection playbook walks through exactly what the on-site visit looks like.

Velmont Crest’s UAE compliance team provides advisory support across the DPMS programme lifecycle — from Business Risk Assessment through MLRO appointment support, goAML registration assistance, policy drafting, threshold-monitoring methodology and inspection-readiness reviews. We pair this with bookkeeping and audit assistance work so the AML evidence trail aligns with the underlying financial records. We are a DED-licensed UAE accounting firm and authorised channel partner with Meydan Free Zone and RAKEZ.

For a clean review of where your gold trader AML programme stands today, book a free consultation.


Disclaimer: Velmont Crest is a DED-licensed accounting firm. We provide advisory, preparation and compliance support services. We are not a licensed MLRO of record, regulated DPMS counterparty or FTA tax agent. AML/CFT rules and DPMS obligations change frequently — verify all requirements with the UAE Financial Intelligence Unit, the Ministry of Economy and your sector regulator, and engage a licensed legal or AML professional for advice specific to your circumstances.

References

Frequently asked questions

Which UAE businesses count as DPMS?
Pretty much anyone trading in precious metals, precious stones, or jewellery made from them, once a transaction hits the cash threshold. Cabinet Decision 134 of 2025 puts it in those terms, and in practice it sweeps up a wide net: gold wholesalers in the Dubai Gold Souk, jewellery retailers in malls and souks, diamond traders in the DMCC Diamond Exchange, bullion dealers, refiners, and the wholesalers feeding retail outlets. Your trade licence category doesn't matter here. Commercial, industrial, specialist — same obligations either way. Free zone or mainland, also identical.
What is the AED 55,000 threshold, and how does aggregation work?
It's the cash figure that turns an ordinary sale into a reportable one. Under Cabinet Decision 134 of 2025 it applies to a single cash transaction, or a run of linked cash transactions with the same customer, once the total reaches AED 55,000. And the Ministry of Economy reads 'linked' broadly — invoices to the same buyer on the same day, or close together, get added up. So a customer who pays AED 30,000 cash for a chain and AED 25,000 cash for matching earrings in one visit has made one AED 55,000 transaction, and it needs a DPMSR. Slicing payments to stay just under? That's a red flag in its own right, and it triggers an STR.
What's the difference between a DPMSR and an STR?
A DPMSR is purely about the number. Any cash transaction at or above AED 55,000 gets one filed, suspicious or not. An STR is about your judgement — the MLRO files it whenever there are reasonable grounds for suspicion, at any value. One deal can need both. A AED 80,000 cash payment with a hand-wavy source-of-funds story, for instance: the threshold pulls in a DPMSR, the vagueness pulls in an STR. Same goAML portal, different templates.
Who can be the MLRO in a small gold trading firm?
A senior person, appointed in writing, with the authority to file through goAML without asking permission each time. In a sole-trader shop that's usually the owner himself. A family operation with a few outlets tends to give it to the senior family member or the GM, and a bigger wholesale setup running shifts will often hand it to a dedicated compliance officer. Their name, Emirates ID and contact details go on the goAML registration, so when the person changes you update the portal within days.
What does an external AML adviser actually do for a gold trader?
The build-out, not the filing. A specialist drafts the Business Risk Assessment, builds the threshold-monitoring procedure that aggregates daily cash per counterparty, writes the CDD procedure for cash buyers, supports the MLRO appointment and goAML registration, and trains counter staff on ID checks, structuring red flags and DPMSR drafting. Filing the DPMSRs and STRs isn't part of that. That's the appointed MLRO's job, personally, through goAML, and it can't be handed off to your adviser.
What does DNFBP mean, and is a gold trader one?
DNFBP stands for Designated Non-Financial Business or Profession — the FATF category the UAE applies to non-bank sectors with high money-laundering exposure. Dealers in precious metals and stones sit squarely inside it, alongside real estate brokers, corporate service providers, auditors and accountants. So yes, a gold trader is a DNFBP, which is what pulls it into goAML registration, MLRO appointment, customer due diligence and record-keeping duties that most people associate with banks.
What does DPMS stand for in UAE AML rules?
DPMS means Dealers in Precious Metals and Stones. It is the supervised sub-category of DNFBP that covers gold wholesalers, jewellery retailers, diamond traders, bullion houses and refiners, and its federal supervisor is the Ministry of Economy. The related acronym DPMSR is the Dealer in Precious Metals and Stones Report — the cash-threshold report filed through goAML, which is a different filing from a suspicious transaction report.
How do I start AML compliance in the UAE from scratch?
Work in this order, because each step depends on the one before it. Write the Business Risk Assessment first, since it decides how strict everything else needs to be. Appoint an MLRO in writing. Register the entity on goAML. Then write the AML policy manual, the CDD procedure and the threshold-monitoring method so they reflect the risks you actually identified. Train the counter staff last, on the procedures as written. Starting with goAML registration and back-filling the paperwork is the common shortcut, and inspectors spot it immediately.

Filed under: AML compliance, DNFBP, DPMS, gold trader, MLRO, goAML

Published · Updated