The AML Documents a UAE Supervisor Can Ask Your Firm to Produce

Published 18 September 2026 · Last reviewed against the primary sources 18 September 2026

When a supervisor inspects a designated business, the question is rarely whether the firm has good intentions. It is whether the firm can produce the evidence the law requires it to keep. This guide lists those documents, each tied to the provision that requires it, so a firm can check what it would be able to hand over tomorrow.

1. The business-wide risk assessment

The written assessment of the firm's money laundering, terrorist financing and proliferation financing risks, with its methodology and supporting data, retained and provided to the supervisor on request. MoET expects senior management to have formally certified it.

Source: FDL 10/2025, Article 19(1)(a); CR 134/2025, Article 5(1)(b); MoET DNFBP Guidelines 2026, section 8.3.1.2

2. Policies, controls and procedures approved by senior management

Article 21 of the Executive Regulations lists what the internal policies must cover at a minimum:

  • customer due diligence, including how relationships are handled before verification is complete
  • procedures for reporting suspicious transactions
  • compliance arrangements, including a compliance officer at management level
  • screening of employees for fitness and propriety
  • training programmes for the compliance function and relevant staff
  • an independent audit function that tests the controls

Source: FDL 10/2025, Article 19(1)(d); CR 134/2025, Article 21

3. The compliance officer's appointment and reports

The firm must appoint a compliance officer at management level, with independence in decision-making and appropriate competence. The officer reviews the firm's AML, CFT and proliferation financing systems and prepares periodic reports to senior management, including management's observations and decisions, with a copy to the supervisor on request. The officer must also give the supervisor and the Financial Intelligence Unit the data they request and access to records.

Source: CR 134/2025, Article 22

4. Customer due diligence and transaction records

All records, documents and data relating to domestic and international transactions and commercial dealings must be kept for at least five years from the completion of the transaction or the end of the business relationship, and made available promptly on request. The Decree-Law requires them to be immediately available to competent authorities.

Source: FDL 10/2025, Article 19(1)(f); CR 134/2025, Article 25(1)

5. Suspicious transaction decisions

The compliance officer receives and assesses suspicious transaction information and decides whether to notify the Financial Intelligence Unit or to retain the matter, stating the reasons, in confidence. A decision not to report is itself a record the firm should be able to show.

Source: CR 134/2025, Article 22(2)

6. goAML registration

MoET's guidelines state that DNFBPs must register on the Financial Intelligence Unit's goAML system and keep that registration active. Without it the firm cannot file a report.

Source: MoET DNFBP Guidelines 2026, section 10.1

7. Training records

The compliance officer must develop, implement and document ongoing training programmes and plans for employees. Attendance and content records are the evidence that the programme exists.

Source: CR 134/2025, Articles 21(5) and 22(4)

8. Independent audit

The policies must include an independent audit function that tests the effectiveness and adequacy of the firm's controls. The audit report, and what was done about its findings, is what shows it happened.

Source: CR 134/2025, Article 21(6)

9. Sanctions screening records

The firm must implement the Executive Office's targeted financial sanctions instructions without delay, register to receive list notifications, and screen customers, beneficial owners and transaction parties. The Executive Office's guidance asks firms to keep records of all screening results, including false positives, for at least five years.

Source: FDL 10/2025, Article 19(1)(e); Cabinet Decision 74/2020, Article 21; EOCN TFS Guidance, March 2026 edition, paragraph 46

10. Proliferation financing measures, where the risk is high

Where the risk assessment identifies high proliferation financing risk, the firm must keep documented records of the measures it took and make them available on request.

Source: CR 134/2025, Article 5(4)(b)

See where your firm stands

The AML Compass assessment checks your firm against these duties for its own sector and jurisdiction. The assessment and your scores are free.

Common questions

How long must a UAE DNFBP keep AML records?
At least five years from the completion of the transaction or the end of the business relationship, under Cabinet Resolution 134 of 2025, Article 25(1). The Executive Office's guidance applies the same five-year minimum to sanctions screening records.
Does the AML policy need to be signed?
The law requires internal policies, controls and procedures approved by senior management (Federal Decree-Law 10 of 2025, Article 19(1)(d), and Cabinet Resolution 134 of 2025, Article 21). A signed and dated approval is the practical way to show that.
Who can the supervisor ask for these documents?
The firm. The compliance officer is responsible for cooperating with the supervisor and the Financial Intelligence Unit and giving access to the records they need, under Cabinet Resolution 134 of 2025, Article 22(5).

Primary sources

Related

A plain reading of the provisions cited, not legal advice. Your firm remains responsible for assessing its own obligations.