Insights AML
MLRO UAE 2026 — What the Role Needs and How the Appointment Letter Reads
Money laundering reporting officer UAE — appointment letter clauses, compliance-officer duties under Cabinet Decision 134/2025, and deputy MLRO rules.

Key takeaways
- MLRO appointment is mandatory under Federal Decree-Law 10 of 2025 and Cabinet Decision 134 of 2025 and must be evidenced in writing
- The MLRO files STRs and SARs through goAML and acts as the FIU point of contact
- Typical disqualifiers: junior rank, front-line client ownership, no Emirates ID, contractor without written authority
- External MLRO support is priced by scope, transaction volume and named-officer seniority — request a quote
- Larger firms should appoint a deputy MLRO for absence cover and segregation of duties
- AML fines for DNFBPs run AED 50,000 to AED 1,000,000 per violation under Cabinet Resolution 71/2024
Every UAE Designated Non-Financial Business or Profession (DNFBP) and every licensed financial institution must appoint a Money Laundering Reporting Officer (MLRO) under Federal Decree-Law 10 of 2025 and its executive regulations, Cabinet Decision 134 of 2025 (which in 2025 replaced the earlier Federal Decree-Law 20 of 2018 and Cabinet Decision 10 of 2019). The appointment has to be in writing and signed by senior management. It has to be recorded in goAML against a named individual with a valid Emirates ID, and refreshed without delay the moment the holder changes.
One step now sits in front of all of that, and it is the change most appointment letters have not caught up with. Article 49(18) of Cabinet Resolution No. 134 of 2025 lists among the competences of supervisory authorities “maintaining an updated list of Compliance Officers of supervised entities, notifying the Unit thereof, and requiring such entities to obtain its prior approval before appointing their Compliance Officers”. The equivalent provision in the repealed Cabinet Decision No. 10 of 2019 was permissive. Do not treat the appointment as a purely internal act: check your own supervisory authority’s current procedure for clearing a compliance officer before the letter is signed, because an appointment made without an approval your supervisor expects is a defect in the file rather than a formality.
A verbal nomination counts for nothing. Nor does a draft letter sitting unsigned in a folder, or a goAML profile still pointing at someone who left the firm a year ago. Any of those is a finding waiting to happen at the next Ministry of Economy inspection, and the exposure is personal as well as corporate.
This guide walks through who qualifies, what the role actually involves, how the appointment letter should read, what the external MLRO market currently charges, and where the AML compliance support we provide stops and your own appointed officer’s accountability begins.
What an MLRO actually does
The MLRO is the named person inside the firm who carries operational responsibility for the AML/CFT programme. One human, identifiable to the regulator, reachable by the Financial Intelligence Unit, accountable to the board. In practice that means assessing internal escalations from colleagues, filing Suspicious Transaction Reports (STRs) and Suspicious Activity Reports (SARs) through goAML, dealing with the FIU and the Ministry of Economy, keeping the programme documentation current, making sure training is delivered and recorded, and presenting to senior management on the state of the programme at least once a year.
The point worth holding onto: the MLRO isn’t the whole compliance department. They’re the named individual sitting on top of whatever compliance resources the firm decides to put behind them — and that distinction is exactly where under-resourced appointments come apart.
Where the obligation sits in UAE law
The MLRO obligation sits across three layers of UAE law and guidance. Federal Decree-Law 10 of 2025 on combating money laundering, the financing of terrorism and the financing of the proliferation of weapons is the primary statute — it was issued on 30 September 2025 and repealed the earlier Federal Decree-Law 20 of 2018 outright at its Article 41, carrying the core obligations relevant to internal compliance officers and reporting duties. Article 42 brings it into force two weeks after publication in the Official Gazette; we could not confirm the gazette publication date from a primary source, so we quote the issuance date rather than a commencement date.
Cabinet Resolution 134 of 2025, the executive regulation for the new law, issued 29 October 2025 and repealing the former Cabinet Decision 10 of 2019 at its Article 70, sets out the operational detail. Article 21(3) puts “appropriate anti-crime compliance management arrangements, including the appointment of a Compliance Officer at management level” inside the internal policies every firm must have approved by senior management. Article 22 then names the officer’s duties directly. The Ministry of Economy and Tourism describes itself as the supervisory authority “entrusted with the supervision of the Designated Non-financial Businesses and Professions (DNFBPs) sector at the state level and commercial free zones”, which is where the inspection, guidance and administrative-penalty powers sit for most UAE DNFBPs.
Article 3 of Cabinet Decision 134 of 2025 lists five DNFBP categories plus a catch-all. Commercial gaming operators, at a transaction threshold of AED 11,000. Real estate brokers and agents concluding purchase or sale transactions for customers. Dealers in valuable metals and precious stones, at AED 55,000 in cash. Lawyers, notaries, other independent legal professionals and independent accountants, but only when they prepare, conduct or execute the five listed transaction types on a customer’s behalf. Company and trust service providers, across five listed activities. Item 6 lets a supervisory authority add further businesses by resolution, in coordination with the National Committee.
Which supervisor you answer to follows the category rather than the licence. Legal professionals sit with the Ministry of Justice; commercial gaming operators with the General Commercial Gaming Regulatory Authority; the rest of the DNFBP population with the Ministry of Economy and Tourism. Financial institutions answer to the Central Bank. The appointment obligation itself does not scale with headcount — Article 22 applies to a two-person brokerage and a hundred-person audit firm in the same terms.
The DNFBP categories and their Article 3 thresholds
| Article 3 category | Trigger in the text | Threshold | Usual supervisor |
|---|---|---|---|
| Commercial gaming operators | Single or linked financial transaction | AED 11,000 | GCGRA |
| Real estate brokers and agents | Concluding a purchase or sale for a customer | No monetary threshold | Ministry of Economy and Tourism |
| Dealers in valuable metals and precious stones | Single or linked cash transaction | AED 55,000 | Ministry of Economy and Tourism |
| Lawyers, notaries, independent legal professionals, independent accountants | Only for the five listed activities, e.g. buying and selling real estate, managing customer funds, forming or selling companies | No monetary threshold | Ministry of Justice (legal professionals) |
| Company and trust service providers | Acting as formation agent, director, secretary, registered office, trustee or nominee shareholder | No monetary threshold | Ministry of Economy and Tourism |
| Any other business added by resolution | Article 3(6) catch-all | Set in the adding resolution | The adding supervisory authority |
Source: Cabinet Decision 134 of 2025, Article 3, as published on uaelegislation.gov.ae. Checked 5 August 2026.

Who actually qualifies
Supervisor expectations around MLRO suitability are clear even where the law leaves room. The appointee needs enough seniority to credibly challenge other senior managers and the board, ideally with board-level access directly or through a documented escalation route. They should be independent of revenue-generating front-line client work wherever the firm’s size lets you segregate. In smaller DNFBPs full independence is rarely achievable, so the supervisor will look for compensating controls: a deputy MLRO and an independent annual audit.
The MLRO must be a UAE resident with a valid Emirates ID, reachable by the FIU on a working phone and email, with no adverse regulatory, criminal or insolvency history, and with real AML literacy. That means familiarity with Federal Decree-Law 10/2025, Cabinet Decision 134/2025, the goAML portal and sanctions screening practice, not a one-day certificate from 2019.
A job description that holds up at inspection
Start from the statute rather than from a template. Article 22 of Cabinet Decision 134 of 2025 sets five duties, and a job description that does not visibly cover all five is a description the supervisor can pick apart in a single reading. Everything else in your letter is elaboration on these.
Article 22 duties, and what each one means in the file
| Article 22 duty (verbatim summary) | What the supervisor asks to see |
|---|---|
| 1. Monitoring transactions related to the crime | Transaction-monitoring rules, alert log, disposition notes |
| 2. Reviewing records, receiving, examining and assessing suspicious transaction data, deciding whether to notify the Unit or retain the matter stating the reasons, in full confidentiality | Internal escalation register with a written rationale for every filed and unfiled case |
| 3. Reviewing internal AML/CFT/CPF systems against the Decree-Law and the Resolution, assessing compliance, proposing updates, and reporting directly to senior management (copy to the supervisor on request, with management’s observations and decisions) | Dated periodic report, board minute recording receipt, management response |
| 4. Developing, implementing and documenting ongoing training programmes and plans | Training plan, materials, attendance and assessment records |
| 5. Cooperating with the supervisory authority and the Unit, providing requested data and enabling access to records | Inspection correspondence file, RFI response log |
Source: Cabinet Decision 134 of 2025, Article 22 (Division Eight, Duties of the Compliance Officer). Checked 5 August 2026.
Two details in Article 22 are easy to skim past and expensive to miss. The reasons for not filing must be recorded, so a decision to hold a matter internally is itself a document. And the periodic report goes directly to senior management, with a copy to the supervisor if it asks, including management’s own observations and decisions — meaning the board’s reaction is part of the evidence, not just the officer’s report.
The list below expands those five statutory duties into the operational responsibilities a UAE appointment letter usually needs to spell out.
- Receive and assess all internal STRs and SARs escalated by staff, with documented rationale for filing or not filing.
- File STRs and SARs through the goAML portal in the prescribed format, without tipping-off the customer or third parties.
- Maintain the firm-wide Business Risk Assessment (BRA), refreshed at least annually and on material change.
- Approve onboarding of clients flagged for Enhanced Due Diligence, high-risk jurisdictions or PEP status.
- Maintain and periodically update the AML/CFT policy and procedures manual.
- Deliver or commission annual AML/CFT training for all staff, with attendance and assessment records retained.
- Oversee sanctions screening against the OFAC Specially Designated Nationals (SDN) list, the United Nations 1267 consolidated list and the UAE local terrorist designation list.
- Maintain the Ultimate Beneficial Owner (UBO) register in line with Cabinet Resolution 109 of 2023, which repealed Cabinet Resolution 58 of 2020.
- Respond to FIU Requests for Information (RFIs) within the prescribed deadline.
- Present a written annual compliance report to senior management or the board.
- Liaise with the Ministry of Economy supervisor on inspections, returns and remediation plans.
- Maintain AML/CFT record retention for the five-year minimum in Article 25 of Cabinet Decision 134 of 2025, counted from the latest of relationship end, account closure, occasional transaction, completion of a supervisory inspection, completion of an investigation, or a final court judgment.
- Ensure goAML registration data is current and refreshed whenever the MLRO or deputy changes.
- Coordinate the independent AML audit and oversee remediation of findings.
- Escalate to the board where the AML programme is under-resourced or where senior management is impeding compliance work.
Inside the appointment letter, clause by clause
The appointment letter is the document a supervisor will ask for first. Below is a structured outline of the clauses that should appear; it is not a fillable form and every firm should have its own letter drafted to reflect its specific governance, but the headings hold across the DNFBP sectors.
Header. Firm letterhead with trade licence number, registered address, the date of the appointment letter and a unique reference number for the file.
Recipient details. Full legal name of the appointee as it appears on the Emirates ID, the Emirates ID number itself, current designation within the firm, employee number where applicable, and direct contact details.
Appointment statement. Plain language confirming the appointment as Money Laundering Reporting Officer, the effective date, and whether the appointment is indefinite (recommended) or for a fixed term. Example wording: “The Board hereby appoints [Name], Emirates ID [Number], as the firm’s Money Laundering Reporting Officer with effect from [Date], on an indefinite basis subject to the termination provisions below.”
Role and responsibilities. Reference to Federal Decree-Law 10 of 2025 and Cabinet Decision 134 of 2025, with the job description annexed in full or summarised in a list of core duties.
Authority and reporting line. Direct access to senior management and the board, authority to require information from any function, authority to freeze onboarding where AML concerns warrant it, and a stated reporting line that bypasses any conflicted intermediate manager.
Resources and budget allocation. Confirmation that the firm will provide adequate staff, training budget, screening tool licences and external advisory access to enable the MLRO to discharge the role.
Acknowledgement of independence. Statement that AML decisions, including STR filings, cannot be overridden on commercial grounds and that no detriment will follow from good-faith reporting.
Termination and handover provisions. Notice period, handover obligations, goAML re-registration on departure, and continued obligations around confidentiality and good-faith reporting.
Signature blocks. Senior management signatory (chair, managing director or CEO depending on governance) and the appointee’s countersignature accepting the role and its responsibilities.
Schedule. Reference to the AML/CFT policy manual version in force at the date of appointment, ensuring the appointee accepts a defined baseline.

Five years’ experience, ICA or CAMS preferred
Cabinet Decision 134 of 2025 does not prescribe a qualification. Article 22 sets a standard instead — management level, independence in decision-making, appropriate competence and experience — and leaves the firm to evidence it. That is harder, not easier, because the burden falls on you to show why this person clears the bar. Several years of relevant compliance, audit, legal or senior finance experience is the usual way UAE firms discharge it. Working familiarity with Federal Decree-Law 10 of 2025, Cabinet Decision 134 of 2025, the goAML portal workflows and at least one commercial sanctions screening tool is essential. English is non-negotiable: supervisory correspondence, training material and most screening interfaces run in it.
Qualifications help evidence competence rather than confer it. Two internationally recognised options are the ICA International Diploma in Anti Money Laundering and the ACAMS CAMS designation. Neither is required by UAE law, and it is worth being blunt about that because job adverts routinely imply otherwise. Article 22 of Cabinet Resolution No. 134 of 2025 requires a Compliance Officer “at management level and under their responsibility, who shall have independence in decision-making and possess appropriate competence and experience”, and names no certificate at all. Neither does Federal Decree-Law No. 10 of 2025.
We checked both texts on 5 August 2026, along with the Ministry of Economy and Tourism’s DNFBP guidelines, and found no named qualification anywhere in them. The Central Bank’s role-based training material mentions ACAMS as an example of a certification staff may seek, which is an illustration and not a mandate. Treat a qualification as evidence in the appointment file rather than as a licence to hold the role, and expect a documented professional track record to carry more weight than the letters. Sector-specific knowledge matters at least as much.
An MLRO at a Dubai real estate brokerage needs to understand the cash-equivalent transactions and beneficial ownership traps that an MLRO at an audit firm would never encounter, and the DPMS threshold of AED 55,000 in Article 3(3) means a gold trader’s officer is testing single transactions an accountant never sees. Article 22(4) makes continuing training an express duty of the officer towards staff; extend the same discipline to the officer’s own file and the competence question answers itself.
Evidencing competence — what goes in the personnel file
| Evidence item | Why the supervisor wants it | Refresh cadence |
|---|---|---|
| CV with dated AML, audit, legal or senior finance roles | Supports “appropriate competence and experience”, Art 22 | On appointment, then on change of role |
| Valid Emirates ID and residence visa | Reachability by the Financial Intelligence Unit | Before each expiry |
| goAML user record naming the individual | Ties the named human to the reporting channel | On every change of holder |
| Signed appointment letter and countersignature | Proves the appointment exists in writing | On appointment and on renewal |
| Organisation chart showing the reporting line | Supports “management level” and independence, Art 22 | Annually and on restructure |
| Conflict declaration covering front-line client ownership | Supports independence in decision-making, Art 22 | Annually |
| AML and sanctions CPD records | Supports continuing competence | Annually |
| Deputy MLRO appointment and parallel goAML access | Cover for absence and for conflicted files | On appointment and on change |
This table is Velmont Crest’s own file-construction checklist, built around the requirements of Article 22 of Cabinet Decision 134 of 2025. The cadences are our recommendation, not a statutory schedule — Article 22 sets the standard and leaves the evidencing to the firm.
What an external MLRO arrangement involves
This section is informational context only. Velmont Crest does not act as MLRO on behalf of clients and does not provide outsourced MLRO services — the role must be held by an individual appointed by your firm with appropriate authority and independence. Where firms do choose to engage external MLRO support from licensed compliance consultancies, pricing is not a fixed rate card. It is driven by scope and moves with several factors, so ask any provider for a written quote against your own profile rather than assuming a headline figure. The main cost drivers are:
- Transaction volume and escalation frequency — a small DNFBP with infrequent escalations sits at the light end; a high-volume dealer in precious metals and stones or a busy real estate brokerage carries a heavier ongoing load.
- Jurisdictional and cross-border complexity — a licensed financial institution or DNFBP with significant cross-border exposure needs a fuller arrangement than a single-emirate practice.
- Per-STR filing work, where some providers price each suspicious transaction report submitted through goAML on top of the retainer.
- Initial mobilisation — the one-off Business Risk Assessment, policy drafting, training and goAML registration set-up, priced by the size and sector of the firm.
- Seniority of the named officer — a more experienced, better-credentialled MLRO commands a higher rate.
Whatever the number, any outsourced arrangement must preserve the firm’s own ultimate accountability for AML/CFT compliance and requires careful contractual scoping — including information access, decision rights, escalation routes, conflict management, professional indemnity cover and termination handover. Ask for a scoped, fixed quote in writing before you commit. For DPMS-specific context see our note on gold and jewellery accounting in the UAE and for brokers see our guidance on real estate accounting in the UAE.
AED 50K-1M
Administrative fine per violation across the 41 items listed in Cabinet Resolution No. 71 of 2024; failing to appoint a competent compliance officer is item 24, at AED 50,000–200,000
What it costs when the appointment fails
Penalty figures for UAE AML get quoted wrongly more often than any other number in this area, because three separate instruments impose three very different ranges and people blend them. Keep them apart.
The supervisor’s power. Article 17(1) of Federal Decree-Law 10 of 2025 lists what a supervisory authority may impose: a warning; an administrative fine of not less than AED 10,000 and not exceeding AED 5,000,000 for each violation; a ban from the sector for a period the supervisor sets; restrictions on board members, executives or owners proven responsible, including appointment of a temporary supervisor; suspension or replacement of directors; suspension or restriction of the activity; and revocation of the licence. Article 17(3) allows an incremental fine where the same violation recurs within a year of the previous one, and Article 17(4) lets the supervisor publish the penalty.
The specific amounts. Article 39 leaves the per-violation schedule to a Cabinet resolution. No replacement schedule under the 2025 law had been published as at 5 August 2026, and Article 41(3) keeps resolutions made under the repealed 2018 law in force until superseded — which is why Cabinet Resolution 71 of 2024 still governs administrative penalties for DNFBPs supervised by the Ministry of Economy and the Ministry of Justice. Its annexed list runs to 41 numbered violations. The items that land on the MLRO’s own desk:
Cabinet Resolution 71/2024 — the items an MLRO owns
| Item | Violation | Minimum | Maximum |
|---|---|---|---|
| 1 | No internal policies, measures and controls approved by top management | AED 100,000 | AED 200,000 |
| 5 | Failure to identify, assess, document and continuously update the firm’s crime risks, or to provide them on request | AED 50,000 | AED 500,000 |
| 9 | Failure to apply CDD before a business relationship or an occasional transaction at or above AED 55,000, or a wire transfer at or above AED 3,500 | AED 50,000 | AED 200,000 |
| 13 | Failure to identify and validate the beneficial owner of legal persons and arrangements | AED 50,000 | AED 200,000 |
| 19 | Failure to conduct ongoing monitoring of the continuing business relationship | AED 50,000 | AED 500,000 |
| 22 | Failure to submit suspicious transaction reports to the Financial Intelligence Unit promptly, or to provide requested additional information | AED 100,000 | AED 500,000 |
| 23 | Failure to register on the electronic system approved by the Financial Intelligence Unit | AED 50,000 | AED 200,000 |
| 24 | Failure to appoint a compliance officer with appropriate competence and expertise | AED 50,000 | AED 200,000 |
| 25 | Failure to enable the compliance officer to perform the duties stipulated in the executive regulation | AED 50,000 | AED 500,000 |
| 26 | Failure to keep required records, organise them for reconstruction of transactions, or make them promptly available | AED 50,000 | AED 200,000 |
| 28 | Tipping off — disclosing to the customer or anyone else that a report has been or will be made | AED 100,000 | AED 500,000 |
| 34 | Failure to constantly screen databases and transactions against the UN, Sanctions Committee and local lists | AED 50,000 | AED 1,000,000 |
| 35 | Failure to freeze funds promptly and without prior warning when a match appears on a local list | AED 500,000 | AED 1,000,000 |
Source: the list annexed to Cabinet Resolution No. 71 of 2024, as published on uaelegislation.gov.ae. Checked 5 August 2026. Item 25 is the reason an under-resourced appointment is a separate violation from no appointment at all.
The court’s power is a different order of magnitude, and a different trigger. Chapter Twelve of Federal Decree-Law 10 of 2025 is criminal, not administrative. It is not what a Ministry of Economy inspection produces.
Supervisory fine versus criminal fine — do not blend these
| Instrument | Who imposes it | Trigger | Range |
|---|---|---|---|
| FDL 10/2025, Art 17(1)(b) | Supervisory authority | Any breach of the Decree-Law, its executive regulation or decisions issued under them | AED 10,000 – AED 5,000,000 per violation |
| Cabinet Resolution 71/2024 annex | Ministry of Economy / Ministry of Justice, as registrar-supervisor | The 41 specified DNFBP violations | AED 50,000 – AED 1,000,000 by item |
| FDL 10/2025, Art 26(1) | Criminal court, natural person | Committing money laundering | 1–10 years’ imprisonment and AED 100,000 – AED 5,000,000, or the value of the criminal property if greater |
| FDL 10/2025, Art 27(1) | Criminal court, legal person | Representatives, directors or agents committed ML, TF or PF on its behalf | AED 5,000,000 – AED 100,000,000, or the value of the criminal property if greater |
| FDL 10/2025, Art 27(2) | Criminal court, legal person | Offences under Arts 28, 29, 30, 32, 33, 34 or 35 committed on its behalf | AED 200,000 – AED 10,000,000 |
| FDL 10/2025, Art 28 | Criminal court | Deliberate or grossly negligent breach of the Article 18 reporting duty | Imprisonment and/or AED 100,000 – AED 1,000,000 |
| FDL 10/2025, Art 29(1) | Criminal court | Tipping off in breach of Article 24 | Imprisonment and/or not less than AED 50,000 |
Source: Federal Decree-Law No. 10 of 2025, Chapters Seven and Twelve, as reproduced in the CBUAE Rulebook. Checked 5 August 2026. Article 27(3) additionally requires the court to dissolve a legal person convicted of terrorist or proliferation financing and close its premises.
Article 28 is the one that makes the MLRO role personal. A deliberate or grossly negligent failure to report under Article 18 is a criminal offence carrying imprisonment and a fine, and the duty in Article 18 is to notify the Unit “without delay and directly”, by detailed report, through the electronic system designated by the Unit — regardless of the value of the transaction, and without invoking confidentiality. There is no de minimis and no professional-secrecy defence outside the narrow carve-out in Article 18(2) for lawyers, notaries and independent legal auditors acting in circumstances subject to professional secrecy.
Why we push clients to name a deputy
A deputy MLRO is recommended for any firm that can’t tolerate a single point of failure when the primary MLRO is on leave, sick, travelling or gone. Larger firms, multi-branch operations and any DNFBP with regular cross-border transactions should treat the deputy appointment as effectively mandatory in practice, even where the regulation doesn’t spell it out. The deputy needs to be appointed in writing to the same standard as the primary MLRO, hold parallel goAML access, be trained to the same depth, and be ready to step in when the primary holder is conflicted on a specific client or transaction. Documenting the trigger points (annual leave, sickness, conflict of interest, departure) in the AML policy manual closes a gap inspectors find often.
An MLRO appointment that exists only in the minutes of a board meeting is not an appointment the supervisor will recognise. Get it in writing, get the Emirates ID into goAML, refresh it the day the holder changes.
How Velmont Crest supports the MLRO programme
Velmont Crest sits alongside your appointed MLRO as an advisory and operational support, not as a substitute for the role itself. We do not act as your MLRO and do not hold ourselves out as the named compliance officer on your goAML profile.
What we do is draft the appointment letter to a structure that has held up under inspection, build and refresh the Business Risk Assessment against your client base and transaction profile, design the Customer Due Diligence and Enhanced Due Diligence policy to fit your sector, prepare training materials and attendance records, and support the MLRO with the ledger extracts, transaction analysis and beneficial ownership mapping that turn raw bookkeeping into AML-usable intelligence.
We maintain the audit trail so that when the supervisor asks for evidence of training delivery in Q2 of last year, the answer arrives within minutes rather than weeks. The accountability for filing decisions, for goAML submissions and for the senior management report remains with your appointed MLRO — that is the boundary, and it is a boundary the law draws rather than a boundary of our choosing.
For the bookkeeping discipline that underpins reliable AML work see our accounting and bookkeeping services, and for the tax overlay that frequently shares the same underlying data see our corporate tax services. For the practical mechanics of getting registered on the FIU’s reporting platform itself, our goAML registration and login guide walks through the workflow.
If you are appointing an MLRO inside a specific sector, our sector templates go deeper — the gold trader DPMS AML programme and the AML programme for UAE law firms — and the Ministry of Economy AML inspection playbook shows what the officer will be tested on when the supervisor visits.
The ten-step appointment checklist
- Identify a UAE-resident individual with the required seniority, independence and AML literacy.
- Confirm a valid Emirates ID and clean adverse-history record before nomination.
- Draft a written appointment letter with the clauses set out above.
- Obtain board or senior-management signature and countersignature by the appointee.
- Register or update the MLRO record in goAML against the appointee’s Emirates ID.
- Annex the job description and reference the AML/CFT policy manual version in force.
- Document the reporting line, authority and resource allocation.
- Appoint a deputy MLRO with parallel access and training.
- Schedule the first annual compliance report and the first independent AML audit.
- Calendar a review of the appointment letter, goAML registration and deputy arrangement at least annually and on every change of holder.
If you are reviewing an existing MLRO arrangement against this checklist or need help drafting the letter, policy manual and Business Risk Assessment from scratch, our AML compliance advisory team supports DNFBPs across the categories listed in Article 3 of Cabinet Decision 134 of 2025 — without ever holding ourselves out as your MLRO. The role is yours; the structure around it is where we add value.
Frequently asked questions
- Who can be appointed as MLRO in the UAE?
- A UAE-resident natural person with a valid Emirates ID, enough seniority to push back on senior management and the board, real AML/CFT literacy, and — where the firm is big enough to segregate — independence from front-line client work. In smaller DNFBPs that's usually a partner or director; in larger ones, someone in a dedicated compliance, risk or finance function. They also have to be reachable by the Financial Intelligence Unit, carry no adverse regulatory or criminal history, and be appointed in writing by senior management, with the appointment logged in goAML. The writing and the goAML record aren't optional extras.
- Can the business owner be the MLRO?
- Yes — and in a small DNFBP without the headcount for a dedicated compliance hire, it's often the only realistic option. The problem to manage is independence. The owner is usually the main revenue generator and the key client relationship too, and the supervisor will poke at exactly that. You soften it with documented escalation routes, a deputy who can step in when the owner is conflicted, an independent annual AML audit, and a written acknowledgement that STR decisions outrank commercial ones. The letter still has to exist on paper, and goAML still has to name the real holder.
- Can a UAE firm use an external MLRO?
- You can — licensed compliance consultancies offer it, mostly to smaller DNFBPs. What you can't outsource is the accountability. Senior management still owns the programme, the policies, the training and the supervisory relationship, full stop. So the arrangement needs tight scoping in the contract. The external MLRO must get genuine authority and information access, the supervisor has to be told where the rules require it, and a real individual still has to be named in goAML. Honestly, most firms land on a hybrid — an internal appointee with external advisory behind them — rather than full delegation.
- What skills and qualifications does an MLRO need?
- No qualification is mandated. Article 22 of Cabinet Decision 134 of 2025 requires the officer to sit at management level, have independence in decision-making, and possess appropriate competence and experience — and leaves the firm to evidence that. In practice UAE firms discharge it with several years in compliance, audit, legal or senior finance, plus working knowledge of Federal Decree-Law 10 of 2025, the executive regulation, the goAML portal, sanctions screening tools and the firm's own client base. Certifications such as the ICA AML diploma or the ACAMS CAMS designation help evidence competence rather than confer it. English is essential — the correspondence and the screening tools all run in it. CPD should be evidenced every year, not just claimed.
- Is a deputy MLRO required in the UAE?
- Not for every DNFBP as a hard rule, but strongly recommended — and in practice close to mandatory for larger firms, multi-branch operations, or anyone who can't afford a single point of failure when the MLRO is on leave, off sick or gone. The deputy should meet the same bar: same qualifications, a written appointment, parallel goAML access, and enough training to take over cleanly. There's a second use too — the deputy can step in for segregation where the primary MLRO has a lingering front-line conflict on a particular client or transaction.
- What exactly does Cabinet Decision 134 of 2025 require the compliance officer to do?
- Article 22 of Cabinet Decision 134 of 2025 sets five duties, and they read as the job description. Monitor transactions related to the crime. Review records, assess suspicious transaction data, and decide whether to notify the Financial Intelligence Unit or hold the matter — recording the reasons either way, in full confidentiality. Review internal AML systems against the Decree-Law and the Resolution, assess compliance, propose updates, and report periodically straight to senior management. Develop, run and document staff training. Cooperate with the supervisor and the Unit. The same Article requires the officer to sit at management level, with independence in decision-making and appropriate competence and experience.
- How big can an AML penalty in the UAE actually get?
- It depends on which body imposes it. A supervisory authority acting under Article 17(1)(b) of Federal Decree-Law 10 of 2025 may impose an administrative fine of AED 10,000 to AED 5,000,000 per violation. Cabinet Resolution 71 of 2024 fixes the specific DNFBP amounts, in a schedule running from AED 50,000 to AED 1,000,000 across 41 numbered items. A criminal court is a different order entirely: under Article 27(1), a legal person whose representatives, directors or agents committed money laundering, terrorist financing or proliferation financing faces AED 5,000,000 to AED 100,000,000, or the value of the criminal property if greater. Blending the supervisory range with the criminal one is the most common error in circulation.
- How long must the MLRO keep AML records in the UAE?
- Five years — but the clock is not where most firms assume. Article 25 of Cabinet Decision 134 of 2025 requires records of all domestic and international financial and cash transactions to be kept for at least five years from completion of the transaction or the end of the business relationship. Clause 2 is the one that bites: due diligence records, account files, correspondence, ID copies, suspicious transaction reports, analysis results and CCTV or ATM recordings run five years from the most recent of the relationship ending, account closure, an occasional transaction, completion of a supervisory inspection, completion of an investigation, or a final court judgment. An inspection restarts the clock rather than running alongside it.
Filed under: MLRO, AML compliance, appointment letter, DNFBP, Money Laundering Reporting Officer
Published · Updated


