Insights AML
AML Programme for Law Firms UAE — a DNFBP Template That Survives Inspection
AML programme for law firms UAE — DNFBP risk matrix, STR triggers, MLRO appointment and goAML enrolment for UAE lawyers and notaries in 2026.

Key takeaways
- Lawyers, notaries and independent legal professionals are scoped DNFBPs under FDL 10/2025 and CR 134/2025, supervised by the Ministry of Justice
- Triggering activities: real estate transfers, company formation, beneficial ownership work, asset structuring
- Every UAE law firm must register on goAML and answer to the Ministry of Justice as its AML supervisor
- An MLRO must be appointed in writing — usually the managing partner in small firms
- Client risk matrix scores PEP exposure, geography, structure complexity and payment patterns
- STR filing is owed when reasonable grounds for suspicion exist — not when guilt is proven
An AML programme for a law firm in the UAE isn’t a single template you file and forget. It’s a recurring operational discipline that wraps client onboarding, matter intake, sanctions screening, transaction review and STR filing into one defensible system. Every UAE lawyer, notary and independent legal professional who prepares or executes the transactional matters listed in Federal Decree-Law No. 10 of 2025 is a Designated Non-Financial Business and Profession (DNFBP). That means full AML/CFT obligations under the UAE Ministry of Justice and the UAE Financial Intelligence Unit.
This guide covers the scope, the AML programme template a Dubai or Abu Dhabi law firm needs in 2026, the client risk matrix structure, the common STR triggers in a legal practice, and what your external adviser should be preparing behind the scenes. If you would rather have the DNFBP programme built and inspection-tested for you, Velmont Crest offers AML compliance support in the UAE for legal and professional-services firms, and our AML compliance guide for UAE DNFBPs sets out the wider rulebook.
Who actually has to file
Two terms do a lot of work in this guide, so it helps to set them down plainly before the detail starts. DNFBP means Designated Non-Financial Business or Profession — the FATF-derived label the UAE applies to lawyers, auditors, corporate service providers, real estate brokers and dealers in precious metals and stones. These are businesses that sit inside the anti money laundering perimeter without being banks, and that is the whole point of the category. KYC, meanwhile, means know your customer: the identification and verification work you do at the front end of a relationship. AML compliance in the UAE runs considerably wider than KYC. It takes in ongoing monitoring, source-of-funds testing, record keeping, staff training and reporting, so a firm that has done its KYC and stopped there has finished perhaps the first sixth of the job.
The DNFBP scoping language in Cabinet Resolution No. 134 of 2025 captures lawyers, notaries and other independent legal professionals when they prepare for, or carry out, transactions for clients involving any of the following five categories:
- Buying or selling real estate — sale and purchase agreements, lease assignments, off-plan transfers
- Managing client money, securities or other assets — including escrow arrangements and trust structures
- Managing bank, savings or securities accounts — for clients or related vehicles
- Organising contributions for the creation, operation or management of companies
- Creation, operation or management of legal persons or arrangements — incorporations, foundations, trusts
Pure courtroom advocacy, family law, personal status, criminal defence and litigation work don’t by themselves trigger DNFBP scope. The trap is assuming that’s where it ends. Most UAE commercial firms — including the small two-to-five-partner setups that dominate the market — handle enough transactional advisory, free zone incorporation, real estate conveyancing and beneficial ownership work that the entire firm ends up in scope and has to register on goAML. We’ve yet to meet a commercial practice that wasn’t.
Velmont Crest is a DED-licensed accounting firm and an authorised channel partner of Meydan Free Zone and RAKEZ, supporting AML compliance for legal and professional services DNFBPs across mainland and free zone structures.
The instruments, and which one governs what
Three documents do the work, and mixing them up is the source of most of the wrong numbers in circulation about UAE law firm AML.
| Instrument | What it governs | Status |
|---|---|---|
| Federal Decree-Law No. 10 of 2025 | The AML/CFT/CPF law itself — offences, supervisory powers, court penalties, the reporting duty | Issued 30 September 2025; Article 42 brings it into force two weeks after publication in the Official Gazette. Article 41(1) repeals Federal Decree-Law No. 20 of 2018 |
| Cabinet Resolution No. 134 of 2025 | The Executive Regulations — DNFBP scope, CDD, beneficial ownership, STRs, internal controls, the compliance officer, record-keeping | The operative rulebook for what a firm must actually do |
| Cabinet Resolution No. 71 of 2024 | The schedule of administrative violations and fines for DNFBPs supervised by the Ministry of Justice and the Ministry of Economy | Kept alive by Article 41(3) of FDL 10/2025, which preserves regulations, resolutions and circulars issued under the 2018 law “insofar as they do not conflict” until superseded |
That last row is the one worth understanding rather than skimming. The 2018 law was repealed, but the fine schedule made under it was not swept away with it — Article 41(3) preserves it until something replaces it. So a UAE law firm assessing its exposure in 2026 is reading a 2025 law, a 2025 executive regulation and a 2024 penalty schedule side by side. Any adviser working from a single document is working from a third of the picture.

The AED thresholds in UAE AML, and what each one is actually for
Numbers get borrowed across categories constantly, and the AED 55,000 figure is the worst offender. Here is where each threshold in Cabinet Resolution 134 of 2025 actually sits.
| Amount | Applies to | Provision |
|---|---|---|
| AED 11,000 | Commercial gaming operators, on a single financial transaction or several that appear linked | Article 3(1) |
| AED 55,000 | Dealers in valuable metals and precious stones, on any single cash transaction or several that appear linked | Article 3(3) |
| AED 55,000 | Financial Institutions, on occasional transactions, single or several linked — triggering CDD | Article 7(2)(a) |
| AED 3,500 | Financial Institutions, on occasional transactions in the form of wire transfers | Article 7(2)(b) |
| AED 3,500 | Virtual Asset Service Providers, on occasional transactions, single or several linked | Article 7(3) |
| No threshold | Lawyers, notaries, other independent legal professionals and independent accountants — scope turns on the activity in Article 3(4), not on a value | Article 3(4) |
That last row is the one that matters for a law firm and it is easy to miss. There is no monetary floor on legal DNFBP scope. A firm becomes a DNFBP because it prepares, conducts or executes a transaction in one of the Article 3(4) categories — buying and selling real estate, managing customer funds, managing bank, savings or securities accounts, organising contributions for the establishment, operation or management of companies, or establishing, operating or managing legal persons and legal arrangements, or selling or purchasing commercial entities. A small conveyance is as much a triggering activity as a large one.
Note the drafting of Article 3(4) too: it reaches lawyers “whether practicing individually, as partners, or as professionals within a firm practicing such profession”. Structure offers no exit.
So when the AED 55,000 figure appears later in this guide as a cash red flag, treat it as a borrowed benchmark rather than a rule that binds your firm. It is the level at which the UAE decided cash becomes interesting enough to require identification in the dealer sector. That makes it a sensible internal escalation trigger for a legal practice handling client money. It is not a statutory threshold for lawyers, and a firm that treats it as one will under-report below it.
A six-stage programme that survives inspection
A defensible UAE law firm AML programme has six interlocking pieces. Skip one and a Ministry of Justice inspection can put you in the annexed list of Cabinet Resolution No. 71 of 2024, where fines run from AED 50,000 to AED 1,000,000 depending on which obligation you missed.
1. Business Risk Assessment (BRA)
The BRA is the document the regulator asks for first. It scores the firm’s exposure across five dimensions: customer risk (PEPs, HNW individuals, corporate clients with opaque structures), product or service risk (which matter types create AML exposure), geographic risk (sanctioned jurisdictions, FATF grey-list countries, conflict zones), delivery channel risk (face-to-face client meetings vs remote onboarding through agents) and transaction risk (cash exposure, payment-method patterns, deal sizes). Refresh it at least annually and whenever the firm enters a new practice area.
2. Client Risk Matrix
The risk matrix translates the BRA into a per-client score that drives the level of due diligence applied. A typical UAE law firm matrix uses four bands:
- Low risk — UAE-resident individuals with stable income, listed companies, regulated financial institutions
- Standard risk — established SMEs, owner-managed UAE companies, real estate buyers with documented financing
- High risk — non-resident clients from medium-risk jurisdictions, complex multi-tier ownership, high-cash businesses
- Enhanced risk — PEPs and their relatives or close associates, clients from FATF high-risk jurisdictions, beneficial owners refusing documentation
Each band determines whether standard CDD, enhanced due diligence (EDD), or refusal of the engagement applies. The matrix is reviewed at engagement opening and refreshed whenever a matter materially changes.
3. CDD and EDD Procedures
Standard Customer Due Diligence collects passport, Emirates ID, proof of address, beneficial ownership disclosure to the 25% threshold, and a source-of-funds narrative. Enhanced Due Diligence layers on documentary source-of-wealth evidence, senior-partner approval before opening, ongoing transaction monitoring and refreshed screening. Write the procedures down, version-control them, and apply them identically across the practice. Don’t leave it to individual partner discretion.
The 25% figure has a specific home. Cabinet Resolution 134 of 2025 Article 10(1)(a) requires the identity of the natural person who “ultimately owns, whether individually or jointly with another person, an actual controlling ownership interest or shares in the Legal Person of 25% (twenty-five percent) or more”. If that produces nobody, or produces someone you doubt is the real controller, Article 10(1)(b) sends you to whoever exercises legal or actual control by any other means; and if that still produces nobody, Article 10(1)(c) makes you name the relevant senior manager. It is a three-step cascade, not a single percentage test, and a CDD file that stops at step one when step one produced no answer is an incomplete file rather than a completed one.
One narrow relief is worth knowing: under Article 11, where the customer or the controlling owner is a company listed on a securities market subject to disclosure requirements that ensure sufficient transparency on beneficial ownership — or a controlled subsidiary of one — you may decline to identify and verify its shareholders or beneficial owners, taking identity information from public registers instead.
The EDD list in Article 5(2)(c) is the one to build your enhanced procedure from, because it is written out: additional identity and occupation information, additional information on the purpose of the relationship or the reasons for the transactions, more regular updating of CDD information, reasonable measures to identify source of funds and wealth, increased ongoing monitoring, routing the first payment through an account in the customer’s own name at an institution subject to equivalent standards, and senior management approval to start or continue the relationship.
4. Sanctions and PEP Screening
Every new client and beneficial owner is screened against the UAE Local Terrorist List, the UN Security Council Consolidated Sanctions List, the OFAC Specially Designated Nationals list and adverse-media databases. Screening is captured in writing with the screening source, date, screening reference and clearance decision. Re-screening runs whenever a relevant list is updated and at periodic refresh cycles.
5. MLRO Appointment and goAML Registration
The Money Laundering Reporting Officer is appointed in writing through a partner or board resolution before the goAML registration is submitted. The MLRO has direct authority to file STRs without obtaining permission for each filing and reports straight to senior management. The firm then completes its Ministry of Justice supervisory registration, the goAML enrolment and the linked EmaraTax records. See our goAML registration guide for the step-by-step portal walkthrough.
6. Training, Record Retention and Annual Reporting
All client-facing lawyers and support staff complete annual AML training documented with attendance logs and acknowledgements. Cabinet Resolution 134 of 2025 sets the retention rule in Article 25, and it is more demanding than the familiar “five years from the end of the relationship” shorthand suggests. The firm files an annual self-assessment report with the Ministry of Justice.
| What Article 25 requires | Period | Runs from |
|---|---|---|
| Records, documents, instruments and data on all domestic and international financial and cash transactions and commercial dealings (Article 25(1)) | Not less than five years | Completion of the transaction, or termination of the business relationship |
| CDD records, ongoing monitoring records, account files, business correspondence, copies of identification documents, STRs, results of any analysis, CCTV and related recordings (Article 25(2)) | Not less than five years | The most recent of: termination of the relationship, account closure, completion of an occasional transaction, completion of a supervisory inspection, completion of an investigation, or issuance of a final court judgment |
| Organisation of those records (Article 25(3)) | — | Sufficient to permit reconstruction of individual transactions, data analysis and tracing of financial transactions, capable of providing evidence for prosecution |
| Availability (Article 25(4)) | — | Promptly to the concerned authorities on request |
Read Article 25(2) carefully, because the “most recent of” construction is what catches firms out. A matter that closed in 2021 but was inspected in 2025 has a retention clock that started in 2025, not 2021. Any destruction policy that keys purely off the file closing date will eventually destroy something it should have kept.
The internal-controls requirements, in the Resolution’s own order
Article 21 lists what a firm’s internal anti-crime policies, controls and procedures must include, and Article 22 lists what the compliance officer must do. The two are frequently merged in commentary; they are separate provisions with separate duties.
| Provision | Requirement |
|---|---|
| Article 21, opening words | Internal anti-crime policies, controls and procedures approved by senior management, proportionate to the identified risks and the nature and size of the activity, reviewed and updated on an ongoing basis |
| Article 21(1) | CDD measures, including risk management procedures for relationships begun before verification is complete |
| Article 21(2) | Procedures for reporting suspicious transactions |
| Article 21(3) | Appropriate compliance management arrangements, including appointment of a compliance officer at management level |
| Article 21(4) | Screening procedures for fitness and propriety in the appointment of employees |
| Article 21(5) | Periodic anti-crime programmes and workshops for the compliance function and other relevant staff |
| Article 21(6) | An independent audit function to test the effectiveness and adequacy of the internal policies, controls and procedures |
| Article 22 | Appoint a compliance officer at management level, with independence in decision-making and appropriate competence and experience, who monitors transactions, reviews and assesses suspicious transaction data and decides whether to notify the Unit, reviews and reports on internal systems to senior management, develops and documents training, and cooperates with the Supervisory Authority and the Unit |
Article 21(6) is the requirement small firms most often assume is meant for banks. It is not qualified by size in the text — it applies to Financial Institutions, DNFBPs and Virtual Asset Service Providers alike. For a two-partner practice, “independent” does not have to mean an internal audit department; it does have to mean somebody who did not write the procedures testing whether they work, and a written record of what was tested and what was found.
Note also the vocabulary. The Resolution says Compliance Officer; the market, the goAML portal and most UAE firms say MLRO. In a small legal practice they are usually the same person, but if your appointment letter names an MLRO and your policy manual cites Article 22 duties, make sure the document says plainly that the two labels describe one role.
AED 50,000–200,000
Administrative fine for a law firm failing to register on the FIU's electronic system — item 23 of the list annexed to Cabinet Resolution No. 71 of 2024

The two penalty regimes, and why blending them is a serious error
A UAE law firm faces administrative penalties from its supervisor and, quite separately, criminal penalties from a court. These are different instruments, different decision-makers and different orders of magnitude, and quoting one as though it were the other is how AML advice ends up frightening or reassuring a firm for no good reason.
| Route | Who imposes it | Amount | Provision |
|---|---|---|---|
| Supervisory administrative penalties, generally | The Supervisory Authority — for a law firm, the Ministry of Justice | Warning, or an administrative fine of not less than AED 10,000 and not exceeding AED 5,000,000 for each violation, plus prohibition from the sector, restriction or suspension of personnel, suspension of the activity, or revocation of the licence | FDL 10/2025 Article 17(1) |
| Repeat violations | Supervisory Authority | An incremental fine where the same violation recurs within one year of the previous fine | FDL 10/2025 Article 17(3) |
| Publication | Supervisory Authority | The authority may publish the penalties it imposes through media outlets | FDL 10/2025 Article 17(4) |
| Court penalty on a legal person for the ML/TF/PF offence itself | A criminal court | Not less than AED 5,000,000 and not exceeding AED 100,000,000, or the value of the criminal property, whichever is greater | FDL 10/2025 Article 27(1) |
| Court penalty on a legal person for the ancillary offences (Articles 28, 29, 30, 32, 33, 34, 35) | A criminal court | AED 200,000 to AED 10,000,000 | FDL 10/2025 Article 27(2) |
| Tipping off | A criminal court | Imprisonment and a fine of not less than AED 50,000, or either penalty | FDL 10/2025 Article 29(1), for a breach of Article 24 |
| Specific DNFBP administrative violations | Ministry of Justice / Ministry of Economy | The itemised schedule in Cabinet Resolution 71 of 2024, from AED 50,000 to AED 1,000,000 | CR 71/2024, annexed list |
The distinction is not academic. Article 17(1)(b) is what a Ministry of Justice inspector can impose for a programme failure — a missing risk assessment, a thin CDD file, an unregistered firm. Article 27(1) is what a court imposes when the firm itself is convicted of money laundering. A firm that has never laundered anything but has a weak programme is looking at the first column, not the second.
The Cabinet Resolution 71 of 2024 items a law firm hits most
Each row below is an item in the list annexed to Cabinet Resolution 71 of 2024, read from the Resolution itself.
| Item | Violation | Fine range |
|---|---|---|
| 9 | Failure to undertake customer due diligence before establishing the business relationship, or on a casual transaction at or above AED 55,000, whether single or several linked transactions | AED 50,000 – 200,000 |
| 12 | Failure to understand the purpose and nature of the business relationship, or the ownership and control structure of the customer | AED 50,000 – 200,000 |
| 19 | Failure to conduct ongoing auditing and monitoring so that CDD documents, data and information stay current, especially for high-risk customer categories | AED 50,000 – 500,000 |
| 22 | Failure to promptly submit suspicious transaction reports to the Financial Intelligence Unit on reasonable grounds of suspicion, or to provide additional information the Unit requests | AED 100,000 – 500,000 |
| 23 | Failure to register at the electronic system approved at the Financial Intelligence Unit | AED 50,000 – 200,000 |
| 24 | Failure to appoint a compliance officer with the appropriate competence and expertise | AED 50,000 – 200,000 |
| 26 | Failure to keep records, documents and data, or to organise them so individual transactions can be reconstructed and traced, or to make them promptly available on request | AED 50,000 – 200,000 |
Article 5(2) of the same Resolution lets the Ministry double the fine where the violation is repeated, and Article 5(3) makes clear that an administrative fine does not stop the Ministry imposing the other sanctions available to it.
Red flags the FIU expects you to spot
Every UAE law firm AML programme has to list the red flags that trigger an internal escalation to the MLRO. The triggers below aren’t exhaustive. They’re the patterns the Ministry of Justice and the FIU expect a competent legal practice to recognise.
Cash and Payment-Method Red Flags
- Client offers to pay legal fees or settlement amounts in cash at or above the AED 55,000 dealer benchmark in Article 3(3) without economic explanation — a borrowed escalation trigger, since no monetary floor applies to legal DNFBP scope
- Funds arrive from a third party not previously disclosed in the engagement
- Multiple small transfers structured to remain below screening thresholds
- Payment instructions involve a virtual asset wallet without prior CDD on the source
- Request to receive funds into the firm’s client account and forward them with no underlying transaction
Client Behaviour Red Flags
- Refusal to provide beneficial ownership documentation
- Source-of-funds story that does not reconcile with the client profile, income, age or business background
- Insistence on completing the matter at unusual speed or in unusual secrecy
- Repeated changes to the identity of the principal counterparty during a transaction
- Requests for legal opinions on structures that appear primarily designed to obscure beneficial ownership rather than achieve a commercial purpose
Structural Red Flags
- Beneficial owner is a foreign PEP, family member or close associate not previously disclosed
- Ownership chain runs through three or more jurisdictions including known opacity centres
- A bearer-share component or nominee shareholding without documentary economic substance
- The legal entity has been dormant for an extended period and is suddenly reactivated for a large transaction
- The matter involves a counterparty appearing on a sanctions list — UAE, UN, OFAC or relevant national equivalent
Real Estate Specific Red Flags
- Property purchase price materially out of line with the documented market value
- Cash component above the FIU Real Estate Activity Report threshold
- Multiple back-to-back transfers of the same property between related parties
- A client refusing to disclose the ultimate buyer behind a nominee purchase
- Source of the deposit funds traced to a jurisdiction the firm cannot evidence due diligence on
When any of these triggers appear, the lawyer escalates internally to the MLRO without tipping off the client. Article 29 of Federal Decree-Law 10/2025 makes tipping off — including oblique hints such as “we are reviewing your file” — a criminal offence carrying personal penalties.
The single most defensible record a UAE law firm can keep is the MLRO assessment memo — a one-page note showing what was escalated, what the MLRO reviewed, what additional information was sought, and the documented reasoned decision to file or not file an STR. Even matters that do not result in a filing should generate a written assessment.
When the local bar adds its own layer
The federal AML/CFT framework runs through the Ministry of Justice and the FIU regardless of which licensing authority issues the firm’s legal practice licence. On top of that, the emirate-level legal regulators layer their own professional-conduct expectations. In Dubai the Dubai Legal Affairs Department (DLAD) regulates licensed legal consultants and registered law firms, and AML compliance evidence is a recurring item in DLAD inspections and licence renewals — ADGM and DIFC sit outside this, operating under their own financial services regimes.
In Abu Dhabi the Abu Dhabi Judicial Department licenses Emirati lawyers and registered consultants, and AML compliance folds into the ADJD professional conduct rules. Sharjah, Ras Al Khaimah and Ajman run similar oversight through their own emirate-level departments for locally licensed firms.
Whichever of these jurisdictions a firm is registered in, it still files STRs through the federal goAML portal — there’s no local STR channel. What the local regulator may want is evidence of AML registration and training as part of practising-licence renewal.

The independent audit nobody budgets for
Article 21(6) of Cabinet Resolution 134 of 2025 requires an independent audit function to test the effectiveness and adequacy of the internal anti-crime policies, controls and procedures. It sits in a list that applies to Financial Institutions, DNFBPs and Virtual Asset Service Providers alike, and nothing in the text carves out small practices. This is the requirement UAE law firms are least likely to have addressed, because it is the one that reads like a banking obligation.
What “independent” means in a two-partner Dubai practice is a practical question rather than a doctrinal one. The test is separation between the person who designed and operates the programme and the person testing whether it works. Options that satisfy that in a small firm include an external adviser running a documented review, a partner who is not the compliance officer testing a sample of files against the written procedure, or a peer-review arrangement with another practice. What does not satisfy it is the compliance officer signing off on the compliance officer’s own work.
| Element | What a defensible independent review produces |
|---|---|
| Scope statement | Which period, which matter types, which controls were tested |
| Sample | How many CDD files were pulled, how they were selected, and from which practice areas |
| Findings | What was missing or inconsistent, matter by matter, without naming a conclusion the evidence does not support |
| Root cause | Whether a gap is a procedure problem, a training problem or a supervision problem |
| Remediation | Who owns each fix, by when, and how completion will be evidenced |
| Sign-off | Who performed the review, their independence from the programme, and the date |
The cost of doing this once a year is small. The cost of an inspection finding that Article 21(6) was never addressed is an administrative fine under Article 17(1)(b) of Federal Decree-Law 10 of 2025 sitting somewhere in a range that starts at AED 10,000 and runs to AED 5,000,000 per violation, plus the harder-to-price consequence that the Supervisory Authority may publish the penalty.
What an inspection looks for, and in what order
Ministry of Justice AML supervision of a legal practice tends to work outward from the documents that prove the programme exists to the files that prove it operates. A firm that can produce this sequence in order has answered most of the visit before it starts.
| Stage | What the inspector is testing | The document that answers it |
|---|---|---|
| Registration | That the firm registered on the FIU’s electronic system | goAML enrolment record — item 23 of Cabinet Resolution 71 of 2024 fines non-registration at AED 50,000 to AED 200,000 |
| Governance | That a compliance officer at management level was appointed with independence in decision-making | Partner or board resolution, plus the goAML officer record matching the person actually in post |
| Risk | That the firm identified and documented its own risks rather than adopting a template | Business Risk Assessment under Article 5(1)(b), retained and updated |
| Design | That policies, controls and procedures were approved by senior management and cover the Article 21 list | The policy manual, version-controlled, with an approval date |
| Operation | That the design is actually followed on real matters | A sample of CDD files with source-of-funds narratives proportionate to matter size |
| Detection | That the firm has indicators for spotting suspicion and keeps them current | The red-flag schedule required by Article 17, plus evidence it has been updated |
| Escalation | That escalations reach the compliance officer and get a reasoned decision | MLRO assessment memos — including on matters where no STR was filed |
| Testing | That an independent audit function tested the programme | The Article 21(6) review file described above |
| Retention | That records are kept and organised to the Article 25 standard | The retention policy, and the ability to retrieve a closed matter promptly |
The ordering matters because inspections fail at the joins. Firms usually have the manual and usually have some CDD. What they lack is the connective evidence — the Business Risk Assessment the manual is supposed to answer, and the assessment memos that show escalations were considered rather than never raised.
Where we see firms slip up
The template-only manual is the single most common inspection finding — a policy manual copied from another firm with no Business Risk Assessment underneath it. Inspectors ask which client risks the manual is designed to address, and an off-the-shelf manual can’t answer that.
Privilege trips people up too, in both directions. Some firms assume legal professional privilege exempts them from STR filing across the board; others assume it never applies. Neither is right. Article 18(2) of Cabinet Resolution 134 of 2025 writes the exemption down, and it is drawn around advisory and litigation work — assessing a client’s legal position, representing them before courts or in arbitration or mediation, opinions relating to judicial proceedings. Transactional matters of the kind listed in Article 3(4) sit outside it. Firms that misjudge that boundary risk an STR omission penalty on one side and a professional conduct problem on the other, which is why the reasoning belongs in writing on the file.
Then there’s MLRO drift: the MLRO leaves the firm, the goAML record isn’t updated, and the inspector finds a former employee still listed as the active reporting officer. The fix is immediate written re-appointment and a goAML record update within days.
Thin CDD files are another recurring one. Passport and Emirates ID alone are not CDD for a real estate matter or a corporate formation involving high-value transfers — the file needs a documented source-of-funds narrative supported by bank statements, sale agreements or salary evidence proportionate to the matter size.
Screening only at onboarding is a quieter failure that bites later. Sanctions and PEP lists update continuously, so a firm that never re-screens is one list update away from a client becoming a sanctioned entity without anyone at the firm knowing. Periodic re-screening isn’t optional.
And training gets treated as an event rather than a programme. A single induction session is not annual training. Inspectors look for refreshed training every twelve months, documented attendance, role-specific content for partners and front-line staff, and written confirmation that the trainee actually understood the obligations.
Where this leaves your firm
If your firm hasn’t completed a Business Risk Assessment, drafted a client risk matrix or registered an MLRO on goAML, you’re operating outside the federal AML/CFT framework. Doesn’t matter how small the practice is or how little transactional work you do.
Under Cabinet Resolution No. 71 of 2024 the fine for failing to register alone is AED 50,000 to AED 200,000, and the bands escalate from there: missing CDD files sit at AED 50,000 to AED 200,000 a case, and failing to file a suspicious transaction report promptly runs AED 100,000 to AED 500,000. For a law firm the Ministry of Justice is the authority that imposes them, and Article 5(2) lets it double any fine where the violation is repeated.
If you have a manual but it hasn’t been refreshed against current Ministry of Justice expectations, the gap is usually in three places: the client risk matrix isn’t mapped to actual matter types, source-of-funds documentation is thin in the CDD files, and there’s no MLRO assessment record for matters that warranted internal review. Two companion guides go deeper on the pieces most firms get wrong — our MLRO appointment guide for the UAE covers who to name and the appointment letter, and the AML inspection playbook walks through what the on-site visit actually looks like.
Velmont Crest’s UAE compliance team provides advisory support across the DNFBP programme lifecycle — from Business Risk Assessment through MLRO appointment support, goAML registration assistance, policy drafting and inspection-readiness reviews. We pair this with bookkeeping and business setup advisory work so the AML evidence trail aligns with the underlying financial records. We are a DED-licensed UAE accounting firm and authorised channel partner with Meydan Free Zone and RAKEZ.
For a clean review of where your law firm AML programme stands today, book a free consultation.
Disclaimer: Velmont Crest is a DED-licensed accounting firm. We provide advisory, preparation and compliance support services. We are not a licensed law firm, MLRO of record, or registered legal consultant. AML/CFT rules and DNFBP obligations change frequently — verify all requirements with the UAE Financial Intelligence Unit, the Ministry of Justice and your emirate legal regulator, and engage a licensed legal or AML professional for advice specific to your circumstances.
References
- UAE Financial Intelligence Unit — goAML portal
- Federal Decree-Law No. 10 of 2025 on AML/CFT
- Cabinet Resolution No. 134 of 2025 — Executive Regulations
- Cabinet Resolution No. 71 of 2024 — AML violations and administrative fines for DNFBPs supervised by the Ministry of Justice and the Ministry of Economy and Tourism
- UAE Ministry of Justice — AML/CFT supervision for legal professionals
- Dubai Legal Affairs Department
- UAE Legislation portal — Cabinet Resolution No. 134 of 2025, Executive Regulations of Federal Decree-Law No. 10 of 2025
- Federal Decree-Law No. 10 of 2025 — Articles 17, 24, 27, 29, 41 and 42, read in full on 5 August 2026
- Cabinet Resolution No. 134 of 2025 — Articles 3, 5, 7, 9, 10, 11, 17, 18, 21, 22 and 25, read in full on 5 August 2026
- Cabinet Resolution No. 71 of 2024 — Article 5 and annexed list items 9, 12, 19, 22, 23, 24 and 26, read in full on 5 August 2026
Frequently asked questions
- Is every UAE law firm a DNFBP under the AML rules?
- Not automatically, but most end up there. A firm becomes a Designated Non-Financial Business and Profession the moment it prepares or carries out a client transaction touching real estate, client money or assets, bank/savings/securities accounts, contributions for setting up or running a company, or the creation and management of legal persons and arrangements. Pure litigation and personal status work don't trigger scope on their own. The thing is, almost every commercial firm in Dubai and Abu Dhabi does enough transactional advisory and corporate structuring that the whole firm lands in scope and has to register on goAML.
- Who must be the MLRO in a UAE law firm?
- A senior person inside the firm, appointed in writing, who can file Suspicious Transaction Reports through goAML without asking anyone's permission first. Where the firm is big enough, the Ministry of Justice wants that person kept independent of front-line client onboarding. In two- and three-partner firms the managing partner usually just takes it on personally; once you're past twenty lawyers it tends to sit with a senior counsel or a dedicated compliance director. One practical point — the MLRO's name, Emirates ID and contact details live on the goAML registration, so if the person changes you have to update the portal within days, not whenever you get round to it.
- What client matters trigger an STR filing in a law firm?
- It's usually one of the familiar red flags. A client who wants to settle a property price in cash at or above the AED 55,000 dealer benchmark in Cabinet Resolution 134 of 2025 Article 3(3) with no economic explanation — borrowed as a trigger, since legal DNFBP scope has no monetary floor of its own. A corporate formation where the apparent beneficial owner won't produce ID, or the ownership chain runs through high-risk jurisdictions. A source-of-funds story that doesn't fit the client's profile, foot-dragging on CDD documents, any structure built mainly to hide who really owns it. None of these is an automatic filing. The MLRO weighs whether there are reasonable grounds for suspicion and, if there are, files the STR on goAML.
- Does a law firm need separate AML registration with the Bar?
- The federal AML supervision of lawyers sits with the Ministry of Justice, and reporting runs through the FIU goAML portal, whoever issues your practice licence. Emirate-level regulators — the Dubai Legal Affairs Department, the Abu Dhabi Judicial Department and the rest — can pile on their own professional-conduct duties, things like periodic AML training and reporting to the local bar. But those sit on top of the federal AML/CFT registration; they don't replace it. A DLAD-registered firm in Dubai still files its STRs through goAML, not through the DLAD.
- What does an external AML adviser actually do for a UAE law firm?
- Mostly the heavy lifting that sits behind the programme. That means drafting or refreshing the Business Risk Assessment that scores client types, geographic exposure and matter risk; building the client risk matrix the firm runs at onboarding; writing the policy manual covering CDD, EDD, sanctions screening, STR escalation and record retention; and backing up the MLRO on internal training, mock-inspection prep and the annual self-assessment to the Ministry of Justice. One line we don't cross: the adviser never files STRs for you. That stays with the appointed MLRO, personally, through goAML.
- What is KYC?
- KYC stands for know your customer — the identification and verification step you complete before you act for a client. For a UAE law firm that means collecting and checking identity documents for the client and, where the client is a company, for its beneficial owners and controllers; establishing the purpose of the retainer; screening against sanctions and PEP lists; and recording what you found and when. KYC is the entry point to a wider AML obligation rather than the whole of it. Ongoing monitoring, source-of-funds enquiry, record retention and suspicious transaction reporting all sit on top, and it is those later stages that inspectors most often find missing.
- What is the difference between an AML administrative fine and a court penalty in the UAE?
- Different decision-makers, different scales, and they should never be quoted as one range. An administrative fine comes from your supervisor — for a law firm, the Ministry of Justice — under Article 17(1)(b) of Federal Decree-Law 10 of 2025, and runs from AED 10,000 to AED 5,000,000 for each violation, alongside non-financial sanctions up to revocation of the licence. A court penalty on a legal person convicted of money laundering, terrorism financing or proliferation financing sits in Article 27(1) at AED 5,000,000 to AED 100,000,000, or the value of the criminal property if that is greater. The first is what a programme failure attracts. The second is what a conviction attracts.
- Does a small UAE law firm really need an independent AML audit?
- On the text, yes. Article 21(6) of Cabinet Resolution 134 of 2025 requires an independent audit function to test the effectiveness and adequacy of internal anti-crime policies, controls and procedures, and it is not qualified by the size of the firm — it applies to financial institutions, DNFBPs and virtual asset service providers alike. What varies is how you satisfy it. In a two- or three-partner practice, independence means the person testing the programme is not the person who wrote and runs it: an external adviser, or a partner who is not the compliance officer, working through a documented sample of files. What will not pass is the compliance officer reviewing their own work.
- What is money laundering?
- Money laundering is the process of moving the proceeds of crime through legitimate-looking transactions so the money can be used without attracting suspicion. It is usually described in three stages: placement, where illicit funds enter the financial system; layering, where transfers, purchases and corporate structures obscure the trail; and integration, where the money re-emerges as apparently clean wealth. Law firms matter to this because the layering stage often needs exactly what a lawyer provides — a property transfer, a company formation, a client account. That is why legal professionals are scoped as DNFBPs rather than left outside the regime.
Filed under: AML compliance, DNFBP, law firm, MLRO, STR, goAML
Published · Updated

