Skip to content

Insights AML

MoE AML Inspection UAE 2026 — a 30-Day Prep Playbook for DNFBPs

A practical MoE AML inspection playbook for UAE DNFBPs — 30-day checklist, the questions inspectors ask, remediation scope and penalty exposure.

Ministry of Economy AML inspection preparation, sample auditor questions, gap-fix budget for DNFBPs
Ministry of Economy AML inspection preparation, sample auditor questions, gap-fix budget for DNFBPs Photo: Velmont Crest Editorial

Key takeaways

  1. MoET supervises the DNFBP sector under Federal Decree-Law 10 of 2025; lawyers and notaries fall under the Ministry of Justice
  2. Neither the Decree-Law nor Cabinet Decision 134 of 2025 sets a minimum inspection notice period — plan for a short one
  3. Article 17(1)(b) allows AED 10,000 to AED 5,000,000 per documented violation; Cabinet Resolution 71 of 2024 sets the DNFBP amounts
  4. Article 49(10) ties inspection frequency to the National Risk Assessment and to each firm's own risk profile
  5. A 30-day pre-inspection checklist covers MLRO, BRA, CDD, screening and training
  6. Grievance runs to the Minister within 30 working days; silence for 40 working days is a deemed rejection

The Ministry of Economy and Tourism (MoET) — the former Ministry of Economy, renamed in 2025 — is the federal supervisor for anti-money laundering and counter-terrorism financing across most Designated Non-Financial Businesses and Professions categories: real estate brokers and agents, dealers in precious metals and stones, auditors, accountants, tax consultants, and corporate service providers. Lawyers and notaries are supervised separately by the Ministry of Justice.

The UAE rewrote the whole framework in 2025 — a new Decree-Law in October, a new executive regulation in December — and anti money laundering UAE supervision now reaches firms that never expected a regulator to knock. If your AML compliance in Dubai, Sharjah or Abu Dhabi has been running on a goAML login and good intentions, a supervisor working from Article 49 of Cabinet Decision 134 of 2025 will find that out quickly.

Here is the part people get wrong before they start. No UAE instrument gives you a guaranteed notice period. Article 16 of the Decree-Law puts desk-based and field-based supervision on the same footing, and Article 49(9) lets the supervisor request whatever information it considers necessary. Firms that treated AML compliance as a binder collecting dust find out, too late, that the binder is the audit. What follows is the thirty-day preparation cadence we use when a MoET inspection notice lands on a client’s desk — our own working framework, not a statutory timetable.

Who gets picked, and why it probably isn’t random

Selection is risk-based because the executive regulation says it must be. Article 49(9) of Cabinet Decision 134 of 2025 requires supervisory authorities to conduct off-site and on-site supervision and inspections “on a risk-based basis”, and to request and obtain any information they consider necessary to do it. Article 49(10) then names the three inputs that set the frequency.

The three statutory inputs to inspection frequency

Article 49(10) inputWhat it means for a DNFBPCan the firm influence it?
(a) The National Risk AssessmentSector-level risk decided nationally — cash-intensive and high-value asset sectors score higherNo
(b) Characteristics of the supervised firm, including diversity, size and the degree of discretion the risk-based approach permitsYour scale, product mix and how much latitude your risk approach claimsPartly — an unjustified claim to low-risk latitude invites testing
(c) Crime risks, the level of understanding of them, and the internal policies, controls and procedures applied, as determined in the supervisor’s own risk assessment of the firmYour Business Risk Assessment, policy manual and control evidence, as the supervisor scores themYes — this is the input you own

Source: Cabinet Decision 134 of 2025, Article 49(9) and 49(10). Checked 5 August 2026.

That third input is the practical lever. A dealer in precious metals and stones and a real estate brokerage both sit in higher-risk sectors under input (a) and cannot change that. What they can change is the quality of the written programme the supervisor scores under input (c). A firm whose Business Risk Assessment is a live document, whose customer files carry a recorded risk rating with reasoning, and whose training register is current, presents a lower residual risk than an identical firm working from a template — and the regulation makes that difference count towards how often it is visited.

Note what Article 16 of Federal Decree-Law 10 of 2025 also says: supervisory and inspection operations may be “desk-based or field-based”. A document request that arrives by email is supervision, not a warm-up for it. Firms that treat off-site requests as administrative correspondence and answer them late are being observed while they do it.

The legal framework underpinning all of this is Federal Decree-Law 10 of 2025 on Anti-Money Laundering, Combating the Financing of Terrorism and Proliferation Financing — a Federal Decree-Law, not a Federal Law, issued 30 September 2025 — and its executive regulation Cabinet Resolution 134 of 2025, issued 29 October 2025. Article 41(1) of the decree-law repealed Federal Decree-Law 20 of 2018 and Article 70 of the resolution repealed Cabinet Decision 10 of 2019.

Both commence by formula rather than on a stated date: two weeks after Official Gazette publication under Article 42 of the decree-law, thirty days after publication under Article 71 of the resolution. We could not confirm the Official Gazette issue or publication date from a primary source on 5 August 2026, so we quote the issuance dates printed on the instruments themselves and leave the commencement date out rather than repeat a figure from commentary.

Article 41(3) of the new Decree-Law keeps regulations, resolutions and circulars made under the 2018 law alive until superseded, which is why Cabinet Resolution 71 of 2024 still governs DNFBP administrative fines even though its own cross-references point at the repealed 2019 regulation.

The current AML instrument stack for a UAE DNFBP

InstrumentWhat it doesIn forceStatus as at 5 Aug 2026
Federal Decree-Law 10 of 2025Primary AML/CFT/PF statute; supervisory and criminal penaltiesIssued 30 Sep 2025; in force two weeks after gazette publication (Art. 42)Current; repealed FDL 20/2018
Cabinet Resolution 134 of 2025Executive regulation; CDD, compliance officer, records, supervisory competencesIssued 29 Oct 2025; in force thirty days after gazette publication (Art. 71)Current; repealed Cabinet Decision 10/2019
Cabinet Resolution 71 of 202441-item schedule of DNFBP violations and administrative fines9 July 2024Still in force via Art 41(3); repealed CR 16/2021
Cabinet Resolution 74 of 2020Targeted financial sanctions obligations; items 33–41 of the CR 71/2024 schedule cite it2020Still in force
Cabinet Resolution 109 of 2023Beneficial owner procedures; the UBO register an inspector asks for2023Current; repealed CR 58/2020
Cabinet Decision 132 of 2023Administrative penalties for beneficial owner breaches16 December 2023Current; repealed CD 53/2021
Article 39 schedule under FDL 10/2025The replacement per-violation fine schedule the new law envisagesNot published. CR 71/2024 continues to apply

Sources: uaelegislation.gov.ae and the CBUAE Rulebook. Checked 5 August 2026. We have not found a published Article 39 schedule; where a source quotes per-violation fines “under the 2025 law”, check whether it is actually quoting Cabinet Resolution 71 of 2024.

What the notice actually says (and asks for)

Be clear about one thing before the planning starts: neither Federal Decree-Law 10 of 2025 nor Cabinet Decision 134 of 2025 prescribes a minimum notice period, and the Ministry of Economy and Tourism does not publish one. Anyone quoting you a guaranteed number of days is quoting practice, not law. The thirty-day framework in this playbook is our own preparation cadence, chosen because it is long enough to rebuild an evidence set and short enough to be realistic — not because a regulation grants it.

What the law does fix is the substance. Article 49(9) gives the supervisor the right to request and obtain any information it deems necessary. Article 22(5) of the executive regulation puts a matching duty on the compliance officer: cooperate with the supervisory authority and the Unit, provide the data they request, and enable their assigned personnel to access the records and documents needed for their work. There is no negotiating position built into either provision.

A document request list is the practical centre of the exercise, and every item on the list below traces to a specific obligation you can point at. Build the binder against the obligations rather than against a rumoured template.

The evidence set, and the article that requires it

Document the inspector asks forWhere the obligation comes from
Compliance officer appointment, at management level, with independence in decision-makingCD 134/2025, Art 22
Internal AML policies, controls and procedures approved by senior managementCD 134/2025, Art 21
Business Risk Assessment — identify, understand, manage, assess, document and continuously updateFDL 10/2025, Art 19(1)(a)
CDD files with beneficial ownership traced to a natural personFDL 10/2025, Art 19(1)(b); CD 134/2025, Arts 7–8
Evidence of enhanced due diligence for high-risk countriesCD 134/2025, Art 23
Sanctions screening and freezing evidenceCabinet Resolution 74 of 2020, Art 21, as cited in CR 71/2024 items 33–41
Suspicious transaction reports, and the reasons for cases held rather than filedFDL 10/2025, Art 18(1); CD 134/2025, Art 22(2)
Training programme, plan, attendance and assessment recordsCD 134/2025, Art 22(4)
Independent audit function testing the AML programmeCD 134/2025, Art 21(6)
Record retention across the five-year set, organised for reconstruction of transactionsCD 134/2025, Art 25(1)–(3)
Beneficial owner register, partners or shareholders register, nominee directors registerCabinet Resolution 109 of 2023, Arts 8–10
Employee fitness and propriety screening proceduresCD 134/2025, Art 21(4)

Source: the articles cited, from the texts published on uaelegislation.gov.ae and the CBUAE Rulebook. Checked 5 August 2026.

The six things Article 21 says your policy manual must contain

Article 21 componentCommon gap
1. CDD measures, including risk management for relationships begun before verification completesThe deferred-verification path is undocumented
2. Procedures for reporting suspicious transactionsThe escalation route exists verbally, not in the manual
3. Compliance management arrangements, including appointment of a compliance officer at management levelThe officer sits below management level
4. Screening procedures for fitness and propriety in appointing employeesNo pre-hire screening documented at all
5. Periodic anti-crime programmes and workshops for compliance staff and other relevant employeesTraining exists for front line only, not for the compliance function
6. An independent audit function to test the effectiveness and adequacy of the policies, controls and proceduresNever commissioned, or commissioned with no management response on file

Source: Cabinet Decision 134 of 2025, Article 21 (Division Seven). The whole set must be approved by senior management, proportionate to identified risks and to the nature and size of the business, and reviewed and updated on an ongoing basis. Checked 5 August 2026.

DNFBPs in higher-risk segments should expect deeper sampling. A dealer in precious metals operating in gold and jewellery will face questions on cash-equivalent inventory controls and walk-in customer thresholds. A real estate broker will be asked to demonstrate source-of-funds verification for the most recent ten transactions above the AED 55,000 cash-payment threshold.

MoE inspection preparation desk with policy manuals and screening logs

The 30-Day Pre-Inspection Checklist

The window between notice and visit is short. The following sequence treats the thirty days as four working weeks, each with a defined objective. The MLRO owns the timeline; the senior management signatory must be available to sign refreshed documents; the operations lead pulls files on request.

Days 1 to 7 — Foundations. Confirm the MLRO appointment letter is current, signed by the licensed manager, and on file. Retrieve the goAML registration certificate and verify that the registered MLRO matches the appointment letter (a frequent mismatch when MLROs change without updating goAML, which our goAML registration guide covers in detail). Confirm the Business Risk Assessment carries a date within the previous twelve months and that it actually reflects the firm’s current client book — not a template inherited from a consultant in 2022. Pull the AML/CFT policy manual and confirm senior management approval is documented by signature and date on the cover page or in an approval minute.

Days 8 to 14 — Customer files. Pull a stratified sample of customer due diligence, enhanced due diligence and simplified due diligence files. Aim for at least twenty files across the spectrum, with deliberate inclusion of higher-risk profiles (PEPs, offshore beneficial owners, cash-intensive sectors). For each file confirm: identification documents within validity, beneficial ownership chain documented to the natural person, risk classification recorded with reasoning, sanctions screening evidence dated at on-boarding and at the most recent annual review.

Verify sanctions-screening logs. The obligations cited in items 33 to 41 of the Cabinet Resolution 71 of 2024 schedule are those in Article 21 of Cabinet Resolution 74 of 2020: registering on the Executive Office for Control and Non-Proliferation website to receive designation notifications, constantly verifying databases and transactions against the Security Council, Sanctions Committee and local lists, freezing promptly and without prior warning on a match, and reporting to the Executive Office.

OFAC SDN screening is commercial practice where there is a US-dollar or US nexus, not a UAE legal requirement — say so plainly when the inspector asks, because claiming a legal basis you do not have is worse than describing a control you chose. Confirm the beneficial owner register required by Cabinet Resolution 109 of 2023 is current and reconciles to customer files.

Days 15 to 21 — Reporting and training. Pull the suspicious transaction report log. Inspectors will not penalise a firm for filing zero STRs if the rationale is documented; they will penalise a firm that filed zero STRs without any documented monitoring activity, because that indicates the monitoring did not occur. Retrieve training attendance records for every staff member who interacts with customers, covering at least one session in the past twelve months with content tailored to the firm’s sector. Article 21(6) of Cabinet Decision 134 of 2025 requires an independent audit function to test the effectiveness and adequacy of the internal policies, controls and procedures. Where that audit has been completed, confirm the report is on file with management’s response to each finding.

Days 22 to 30 — Rehearsal. Conduct a dry-run inspection with the MLRO playing the inspectee role and a senior team member or external advisor playing the inspector. Walk through the document request list end to end. Prepare physical and digital evidence binders organised in the exact sequence of the inspector’s checklist so files can be produced within minutes, not hours. Brief reception staff on inspector arrival protocol, brief operations staff that questions outside their remit must be referred to the MLRO, and confirm meeting room availability with screen-share capability for digital evidence.

The penalty ladder, and where the numbers actually come from

Three different instruments impose three different ranges, and they are routinely blended in circulation. They are not interchangeable, and a supervisor cannot impose a court’s fine.

Which range applies to what

LayerImposed byRangeSource
Supervisory envelopeSupervisory authorityAED 10,000 – AED 5,000,000 per violationFDL 10/2025, Art 17(1)(b)
DNFBP scheduleMinistry of Economy and Tourism / Ministry of JusticeAED 50,000 – AED 1,000,000 by item, across 41 itemsCabinet Resolution 71/2024, annexed list
Repeat multiplierMinistryFine may be doubled on repetitionCabinet Resolution 71/2024, Art 5(2)
Recurrence within a yearSupervisory authorityIncremental fine permittedFDL 10/2025, Art 17(3)
Criminal — natural personCriminal court1–10 years and AED 100,000 – AED 5,000,000, or the value of the criminal property if greaterFDL 10/2025, Art 26(1)
Criminal — legal personCriminal courtAED 5,000,000 – AED 100,000,000, or the value of the criminal property if greaterFDL 10/2025, Art 27(1)
Criminal — reporting failureCriminal courtImprisonment and/or AED 100,000 – AED 1,000,000FDL 10/2025, Art 28

Sources: Federal Decree-Law No. 10 of 2025 (CBUAE Rulebook) and Cabinet Resolution No. 71 of 2024 (uaelegislation.gov.ae). Checked 5 August 2026. An inspection produces a supervisory penalty. The Article 26 and 27 figures belong to a criminal prosecution and are reproduced here only so they are not mistaken for what an inspector can impose.

If the Ministry decides to fine you — the Cabinet Resolution 71/2024 clock

StepDeadlineArticle
Ministry notifies the DNFBP of the decision to impose the fineWithin 20 working days of issuing the noticeArt 4(1)
Grievance to the Minister or delegate, substantiated and with supporting documentsWithin 30 working days of the notice, or of the grievant becoming awareArt 4(2)
Minister may deny and endorse, amend to another penalty proportionate to the activity and transaction volume, or cancel where the reasons are removed or invalidOn considerationArt 4(3)
No reply to the grievance40 working days = deemed rejectionArt 4(4)
Court appealNot accepted until the grievance has been made and decided, or the reply deadline has lapsedArt 4(5)

Source: Cabinet Resolution No. 71 of 2024, Article 4, as published on uaelegislation.gov.ae. Checked 5 August 2026. Article 4(3)(b) is the sentence worth reading twice: the Minister may substitute a different penalty, but the grievance may not leave the aggrieved party worse off.

The practical point in that table is Article 4(5). You cannot go to court first. A firm that lets the 30-working-day grievance window pass while it takes legal advice has closed its own route of challenge, whatever the merits.

The thresholds an inspector will test against your files

Most inspection findings are not exotic. They are a customer file that should have triggered due diligence at a numeric threshold and did not. Article 3 and Article 7 of Cabinet Decision 134 of 2025 set those numbers, and Article 28 adds the wire-transfer data rules. Every UAE DNFBP should be able to point at the trigger that applies to its own licensed activity without looking it up.

Cabinet Decision 134 of 2025 — the numeric triggers

TriggerWho it applies toAmountArticle
Single or linked financial transaction bringing a commercial gaming operator inside the DNFBP definitionCommercial gaming operatorsAED 11,000Art 3(1)
Single or linked cash transaction bringing a dealer inside the DNFBP definitionDealers in valuable metals and precious stonesAED 55,000Art 3(3)
Occasional transaction requiring CDDFinancial institutionsAED 55,000Art 7(2)(a)
Occasional transaction in the form of a wire transfer requiring CDDFinancial institutionsAED 3,500Art 7(2)(b)
Occasional transaction requiring CDDVirtual asset service providersAED 3,500Art 7(3)
International wire transfer where originator information must be verified and full data accompany the transferFinancial institutionsAED 3,500 and aboveArt 28(1)
International wire transfer below the threshold — data must accompany it but need not be verified absent suspicionFinancial institutionsBelow AED 3,500Art 28(3)
Beneficiary institution must verify the beneficiary’s identity where not previously verifiedBeneficiary financial institutionsAED 3,500 and aboveArt 30(2)
Beneficial ownership — the percentage that makes a natural person a real beneficiaryAll in-scope UAE legal persons25% of capital or 25% of voting rightsCabinet Resolution 109 of 2023, Art 5(1)

Sources: Cabinet Decision 134 of 2025 and Cabinet Resolution 109 of 2023, as published on uaelegislation.gov.ae. Checked 5 August 2026. Note that a threshold is a floor, not a licence: Article 7(1) requires CDD on commencing any business relationship, where a crime is suspected, or where there are doubts about previously obtained identification data, regardless of amount.

The AED 55,000 line is the one that most often produces a finding for a Dubai or Sharjah dealer in precious metals, because Article 3(3) counts “several transactions that appear to be linked” and a file structured as three payments of AED 20,000 is exactly what the drafting is aimed at. The same logic applies to the AED 11,000 gaming threshold and the AED 3,500 wire threshold. A monitoring rule that only tests single transactions will pass its own test and fail the inspector’s.

What changed when the 2025 framework landed

A firm still working from a 2019-vintage policy manual will fail on citations before an inspector reaches the substance. The table below is the mapping we use when we rebuild a UAE policy manual against the current texts.

Old framework to new — the mapping that has to be in your manual

TopicRepealed positionCurrent position
Primary statuteFederal Decree-Law 20 of 2018 (repealed)Federal Decree-Law 10 of 2025, issued 30 September 2025
Executive regulationCabinet Decision 10 of 2019 (repealed)Cabinet Resolution 134 of 2025, issued 29 October 2025
Compliance officer dutiesArticle 21 of the 2019 regulationArticle 22 of Cabinet Decision 134 of 2025
Internal policies contentArticle 20 of the 2019 regulationArticle 21 of Cabinet Decision 134 of 2025
Supervisory penaltiesArticle 14 of FDL 20/2018Article 17 of FDL 10/2025, AED 10,000 – AED 5,000,000 per violation
DNFBP administrative fine scheduleCabinet Resolution 16 of 2021Cabinet Resolution 71 of 2024, AED 50,000 – AED 1,000,000 across 41 items
Beneficial owner proceduresCabinet Resolution 58 of 2020Cabinet Resolution 109 of 2023
Beneficial owner penaltiesCabinet Decision 53 of 2021Cabinet Decision 132 of 2023, to AED 100,000 on a third violation
Scope of the regimeMoney laundering and terrorist financingAdds proliferation financing as a named limb throughout
Record retentionFive yearsFive years, but Article 25(2) counts from the most recent of six trigger events

Sources: FDL 10/2025 Art 41; CR 71/2024 Art 8; CR 109/2023 Art 22; CD 132/2023 Art 8. Checked 5 August 2026.

Two of those rows cause most of the trouble. Cross-references to “Article 21” for the compliance officer are now wrong — that Article governs internal policies, and the officer’s duties moved to Article 22. And Cabinet Resolution 71 of 2024 still cites the repealed 2019 regulation in its own legal-reference column, which is correct as drafting and confusing as reading: the fine schedule survives under Article 41(3) of the new Decree-Law even though the articles it points at have been replaced.

Fifteen questions we’d put to your MLRO before the inspectors do

These are our own rehearsal questions, each written back from a specific obligation in Federal Decree-Law 10 of 2025, Cabinet Decision 134 of 2025 or Cabinet Resolution 109 of 2023 rather than from any published inspection script. They are neither exhaustive nor predictive. But if an MLRO has one afternoon left before the visit, rehearsing crisp, evidence-backed answers to each of these is the highest-leverage thing they can do with it.

  1. “Show me your Business Risk Assessment dated within the last twelve months. Walk me through the methodology.”
  2. “Pick this customer file at random. Walk me through how you on-boarded this client and what triggered the risk rating you assigned.”
  3. “Show me the sanctions screening evidence for this specific transaction on this specific date.”
  4. “Who is your MLRO? Where is the signed appointment letter? Has the MLRO completed mandatory training in the past twelve months?”
  5. “How many suspicious transaction reports have you filed in the past twelve months? For zero filings, where is the documented monitoring rationale?”
  6. “How often do you train staff on AML obligations? Where are the attendance records, the content of the training, and evidence of comprehension testing?”
  7. “What is your customer risk classification methodology? Walk me through the scoring matrix.”
  8. “Demonstrate ongoing monitoring of an enhanced due diligence client. Show me the trigger events and the review cadence.”
  9. “How do you identify and handle politically exposed persons? What additional approvals are required before on-boarding a PEP?”
  10. “Where is your ultimate beneficial owner register? When was it last updated and what was the trigger for the update?”
  11. “What is your record retention policy? Where are the files held? Article 25(2) of Cabinet Decision 134 of 2025 counts five years from the most recent of relationship end, account closure, an occasional transaction, completion of a supervisory inspection, completion of an investigation, or a final court judgment — show me how your schedule handles that.”
  12. “Show me an example of a customer you offboarded for AML concerns. What was the trigger, what was the rationale and what was the STR position?”
  13. “How do you handle the risk of tipping off a customer who is the subject of a suspicious transaction report?”
  14. “What was the trigger for your last internal compliance review and what corrective actions were implemented?”
  15. “Demonstrate that senior management has formally approved your AML programme. Show me the minutes or the signed approval.”

Every question has a documentary answer. If the answer is verbal, it does not count. Inspectors record answers verbatim and reconcile them to the file.

MLRO reviewing customer due diligence binder during MoE inspection rehearsal

Scoping the remediation work

When the gap assessment is complete the firm faces a remediation workload. There is no fixed price for it — the cost is driven by how many gaps the assessment surfaces, the sector, the size of the client book and how deep the file-level rework has to go, so any provider should quote against your specific position rather than a headline range. The main workstreams to scope are:

  • Policy manual refresh with documented senior management approval — an advisory-supported job that aligns the manual to how the firm actually operates rather than a generic template.
  • Business Risk Assessment refresh — priced by sector complexity, geographic spread and how deep the underlying client analysis needs to go.
  • Sanctions-screening tooling — a subscription that scales with transaction volume, real-time screening and how much adverse-media coverage is included.
  • Staff training — a sector-specific external session with case studies and a comprehension test at the end.
  • Independent AML audit — Article 21(6) of Cabinet Decision 134 of 2025 requires an independent audit function to test the effectiveness and adequacy of the internal policies, controls and procedures. It covers programme adequacy, sample testing and a written report with findings.
  • Customer file remediation — priced by how much each file is missing: an identification refresh, an undocumented UBO chain, absent screening evidence, or a risk rating that was never put on file.

A firm with a clean operating culture but lapsed documentation is a lighter job than one with structural gaps — no current BRA, screening done ad hoc, training non-existent. Rather than guess at either duration, prioritise by exposure: put the workstreams that close the largest published fine first.

Remediation workstreams, ranked by the exposure each one closes

WorkstreamCabinet Resolution 71/2024 item it addressesPublished fine range
Sanctions freezing procedure — freeze promptly and without prior warning on a local-list matchItem 35AED 500,000 – AED 1,000,000
Continuous screening of databases and transactions against UN, Sanctions Committee and local listsItem 34AED 50,000 – AED 1,000,000
Registration with the Executive Office for Control and Non-Proliferation to receive designation noticesItem 33AED 50,000 – AED 1,000,000
Internal policies and procedures under Cabinet Resolution 74 of 2020Item 41AED 100,000 – AED 1,000,000
STR filing discipline and FIU response handlingItem 22AED 100,000 – AED 500,000
Tipping-off controls and staff briefingItem 28AED 100,000 – AED 500,000
Business Risk Assessment refresh, documented and kept currentItem 5AED 50,000 – AED 500,000
Ongoing monitoring of continuing business relationshipsItem 19AED 50,000 – AED 500,000
Enabling the compliance officer to actually perform the role — access, authority, resourcesItem 25AED 50,000 – AED 500,000
Board-approved policy manualItem 1AED 100,000 – AED 200,000
Customer file remediation against the AED 55,000 and AED 3,500 CDD triggersItem 9AED 50,000 – AED 200,000
Beneficial ownership traced and validated to a natural personItem 13AED 50,000 – AED 200,000
Record organisation permitting reconstruction of individual transactionsItem 26AED 50,000 – AED 200,000
Compliance officer appointment with appropriate competenceItem 24AED 50,000 – AED 200,000

Source: the list annexed to Cabinet Resolution No. 71 of 2024, uaelegislation.gov.ae. Checked 5 August 2026. Ranking is by the published fine, not by how long the work takes — a screening procedure can be written in a week and closes a bigger number than a file remediation that takes a month.

For a scoped, fixed quote against your own gap assessment, book a free consultation rather than working to a guessed number.

AED 10K-5M

Administrative penalty range per AML breach under Federal Decree-Law 10 of 2025

After the inspectors leave: the three ways this ends

Inspections close in one of three broad positions. The one you want is the clean outcome: the file closes with no action required and the firm returns to the ordinary risk-based cycle described in Article 49(10). The second is a remediation instruction. Article 17(2) of Federal Decree-Law 10 of 2025 gives the supervisor an express power to order the submission of periodic reports on the measures taken to remedy a violation — so remediation is not an informal understanding, it is a reporting obligation with the supervisor still watching.

The third outcome is an administrative penalty. Cabinet Resolution 71 of 2024 sets the notification and grievance timetable above, and Article 3(1) confirms the Ministry can impose a supervisory penalty from Article 17(1), a fine from the annexed list, or both. Grievances succeed on a documentary basis, not on a view that the penalty is harsh: Article 4(3) lets the Minister amend a penalty by reference to the violation, the nature of the activity and the volume of transactions of the facility — all of which are evidenced from your own records.

One consequence sits outside the fine. Article 17(4) of Federal Decree-Law 10 of 2025 provides that “in all cases, the Supervisory Authority may publish the administrative penalties imposed by it through various media outlets.” That is a discretionary publication power over individual penalties, not a standing public register — but it is a real one, and it is the exposure a firm cannot pay off.

The fine is not the whole exposure. Article 17(4) lets the supervisor publish the penalty through media outlets, and Article 17(1) puts a sector ban, director suspension and licence revocation on the same menu as the money.

— Velmont Crest advisory note

Where Velmont Crest fits on inspection prep

Velmont Crest supports DNFBPs through inspection preparation in an advisory capacity. The MLRO remains the firm’s appointed officer of record and the senior management signatory remains accountable for programme approval. Our role is to compress the preparation timeline, raise the quality of the evidence and reduce the operational burden on a team that still has a business to run.

The engagement typically covers: a gap assessment scored against the MoE inspection template, evidence binder assembly indexed to the inspector’s likely document request list, customer file remediation with documented rationale for each rating decision, a Business Risk Assessment refresh anchored to the firm’s actual client book, sanctions-screening methodology documentation, the senior management approval trail, and mock-interview support for the MLRO and operations team. We do not attend inspections in the role of the firm’s MLRO and we do not represent the firm to the Ministry as its appointed officer. We prepare the firm so its own MLRO walks into the inspection room ready.

For firms whose bookkeeping is also under our care, the inspection preparation benefits from financial records that already tie to customer files and transaction monitoring. For firms preparing simultaneously for corporate tax registration and AML inspection, sequencing the two workstreams against a single calendar avoids the documentation overlap that frequently overwhelms in-house teams. Whichever route applies, the destination is the same: an inspection-ready posture maintained year-round rather than rebuilt in panic every cycle.

Before the notice arrives is also the moment to get the underlying programme right. Our MLRO appointment guide for the UAE covers the officer inspectors will question first, while the sector templates — the gold trader DPMS AML programme and the AML programme for UAE law firms — show what a defensible file looks like in the two most heavily inspected DNFBP categories.

Talk to our AML compliance advisory team before the inspection notice arrives, not after. The thirty-day window is workable. The seven-day window — when the notice has been sitting unopened in an MLRO’s inbox — is not.

Frequently asked questions

How does the Ministry of Economy select DNFBPs for inspection?
Article 49(10) of Cabinet Decision 134 of 2025 sets out the three inputs a supervisory authority must use to determine how often it inspects. First, the National Risk Assessment. Second, the characteristics of the supervised firms, including their diversity, size and the degree of discretion the risk-based approach permits them. Third, the crime risks each firm faces, how well it understands them, and the internal policies, controls and procedures it applies — as measured in the supervisor's own assessment of that firm's risk structure. So the selection is risk-based by law, not by convention, and the third input is the one you can move: a firm whose written programme is thin scores worse in the supervisor's own risk assessment and earns more attention.
How much notice does a DNFBP get before an MoE inspection?
No minimum is written into the law. Federal Decree-Law 10 of 2025 and Cabinet Decision 134 of 2025 give supervisors the power to conduct off-site and on-site inspections on a risk-based basis and to request any information they consider necessary, but neither text prescribes a notice period, and the Ministry does not publish one. Article 16 of the Decree-Law goes further and puts desk-based supervision on the same footing as a site visit, so the first contact is often a document request rather than a diary entry. Plan on the assumption that the window is short and that the written programme has to stand up on the day it is asked for, not after a month of tidying.
Can a DNFBP postpone or reschedule the inspection?
There is no statutory right to a deferral, and no published procedure for requesting one. Article 49 of Cabinet Decision 134 of 2025 gives the supervisory authority the power to set the frequency of inspections and to request whatever information it considers necessary; nothing in that Article or in Federal Decree-Law 10 of 2025 obliges it to move a date. If a genuine obstacle exists — the compliance officer on medical leave, the authorised signatory abroad — put the request in writing, keep it factual and evidenced, and treat any accommodation as discretionary. Meanwhile keep preparing to the original date, because the schedule you cannot control is the one you have to be ready for.
What happens after the MoE inspection concludes?
Three broad outcomes: no further action, a remediation instruction, or an administrative penalty. Where the Ministry decides to fine a DNFBP, Cabinet Resolution 71 of 2024 sets the mechanics. Article 4(1) requires the Ministry to notify the violating firm of the decision within 20 working days of issuing the notice. Article 3(1) lets it impose a supervisory penalty, a fine from the annexed list, or both. Article 5(2) allows the fine to be doubled where the violation is repeated, and Article 5(3) confirms a fine does not stop the Ministry adding the other supervisory sanctions on top. Grievance rights are in Article 4 and they are strict — see the timetable in the article.
What is a DNFBP and does the definition cover my firm?
DNFBP stands for Designated Non-Financial Business and Profession — the categories the UAE brings inside the AML regime even though they are not banks or licensed financial institutions. The Ministry of Economy and Tourism supervises real estate brokers and agents, dealers in precious metals and stones, auditors, accountants, tax consultants, and corporate service providers including company formation agents and registered-office providers. Lawyers and notaries are supervised by the Ministry of Justice instead. The test is your licensed activity, not your size or turnover, so a two-person brokerage carries the same registration, screening and reporting obligations as a large one.
What do AML and CFT actually mean?
AML is anti-money laundering: stopping criminal proceeds from being washed through legitimate businesses. CFT is combating the financing of terrorism: stopping funds — which may be entirely legitimate in origin — from reaching terrorist organisations. They are treated as one regime in the UAE because the controls overlap almost completely: know your customer, understand the source of funds, screen against sanctions lists, monitor for behaviour that does not fit the customer profile, and report what looks wrong. Federal Decree-Law No. 10 of 2025 added proliferation financing as a standalone offence, so you will increasingly see the regime written as AML/CFT/PF.
What is goAML registration and who has to complete it?
goAML is the reporting platform the UAE Financial Intelligence Unit uses to receive suspicious transaction and suspicious activity reports, and registration on it is mandatory for every DNFBP, not optional. It is also the channel through which sanctions-list notifications reach you. Registration alone is not compliance, and this is where firms get caught: inspectors treat a goAML account with no filing history, no linked MLRO and no evidence of list-monitoring as a warning sign rather than a tick. Register, keep the registered MLRO details current, act on the notifications, and document the reasoning whenever you conclude a case does not warrant a report.
What role does a specialist accountant play in inspection preparation?
Quite a lot of the heavy lifting, but always in a supporting seat. An advisory firm runs the gap assessment against the MoE template, builds the evidence binder and remediates sample customer files. It refreshes the Business Risk Assessment, documents how you screen against sanctions lists, and pulls together the senior-management approval trail. Then it rehearses the MLRO through the questions likely to come up. What it can't do is stand in for the MLRO — that's still the firm's appointed officer of record, and they face the inspectors directly. We just make the inspector's job easy and the MLRO's answers consistent.

Filed under: MoE inspection, AML compliance, DNFBP, Ministry of Economy, inspection prep

Published · Updated