Whether you are a DNFBP
The designated categories are specific, and businesses inside them frequently do not realise it because they think of AML as a banking matter.
Real estate brokers and agents. Dealers in precious metals and precious stones, which includes a substantial part of the Dubai gold and jewellery trade. Corporate service providers, including company formation agents. Auditors and accountants. Lawyers and notaries in defined circumstances.
If you sit in one of those categories, the obligations apply in full regardless of your size. A two-person brokerage has the same substantive requirements as a large agency, scaled to its risk but not waived. And because the categories are activity-based rather than size-based, growing into the obligation is not possible — you were either in it from the start or you were not.
Who this is for
DNFBPs across both emirates, mainland and free zone. In our experience the businesses most often unaware are smaller real estate brokerages, jewellery and precious metals traders, and corporate service providers formed to support a single group.
Also businesses that registered on goAML during the initial push, did nothing further, and have since been asked for their risk assessment. And businesses acquiring or being acquired, where AML compliance is now a standard diligence item and its absence is a finding.
What the work involves
How we run it:
- Confirm DNFBP status against the activity, since it determines whether any of the rest applies.
- Register on goAML, or check that an existing registration is complete and correctly configured.
- Appoint a compliance officer with the authority and independence to do the job, and document the appointment.
- Build the business risk assessment — customers, countries, products, delivery channels — which is the foundation everything else is measured against.
- Write the policies and procedures, sized to the business and specific to it, not a template with the name changed.
- Design the customer due diligence process: identification, verification, beneficial ownership, purpose of the relationship, and enhanced measures where risk requires them.
- Set up ongoing monitoring and the process for identifying and escalating suspicious activity.
- Train the staff who actually deal with customers, with the training recorded.
- Establish the reporting capability for suspicious transaction reports, before one is needed rather than during it.
What an inspection looks at
The pattern is consistent, and it is worth knowing before rather than after:
- goAML registration — present and correctly configured, which is the threshold rather than the test
- The compliance officer — appointed, documented, and able to explain the programme when asked
- The business risk assessment — current, specific to this business, and actually informing the procedures
- Customer files — sampled, to see whether the documented CDD process was actually applied
- Beneficial ownership — identified for corporate customers rather than stopping at the entity
- Enhanced due diligence — applied where the risk assessment says it should be
- Training records — who was trained, when, on what
- Reporting — the capability exists and staff know how to escalate
The customer file sample is where most programmes fail. A well-written procedure that was never applied to an actual customer is worse than no procedure, because it demonstrates awareness of an obligation that was not met.
Proportionate, but not optional
A two-person brokerage does not need the AML programme of a bank, and any adviser selling one is selling volume rather than compliance. The obligations are risk-based, which means the depth of your procedures should reflect the risk your business actually carries.
What is not proportionate is the existence of the elements. You need a risk assessment even if it is short. You need a compliance officer even if they do other things. You need CDD applied to every customer, training for everyone who deals with customers, and the ability to report.
The practical objective is a programme small enough that it is actually followed. An elaborate policy nobody reads fails an inspection more comprehensively than a simple one everybody applies, because the gap between the document and the practice is itself the finding.
What goes wrong
These are the failures we are brought in to correct, in rough order of frequency:
- Registering on goAML and stopping, which completes the visible step and none of the substantive ones.
- A template risk assessment with the business name changed, which does not describe this business’s risk.
- CDD documented but not applied, which the customer file sample will show immediately.
- Stopping at the corporate customer without identifying its beneficial owners.
- A compliance officer in name only, unable to explain the programme.
- No training records, so training that happened cannot be evidenced.
- Assuming small businesses are exempt. The categories are activity-based, not size-based.
- An elaborate programme nobody follows, which fails more comprehensively than a simple one that is applied.
When this needs to happen
Before you take on customers, if you are starting. Immediately, if you are a DNFBP without a programme — the obligation is live now and the absence of a programme is not cured by the absence of an inspection.
The risk assessment should be reviewed at least annually and whenever the business changes materially: a new customer segment, a new geography, a new product or service. Training should be periodic and recorded, and CDD refreshed on a risk-based cycle rather than only at onboarding.
What you end up with
- DNFBP status confirmed in writing
- goAML registration completed or verified
- A business risk assessment specific to your business
- AML/CFT policies and procedures, proportionate and usable
- A CDD process including beneficial ownership and enhanced measures
- Compliance officer appointment documented, with a defined role
- Staff training delivered and recorded
- Suspicious transaction reporting capability established
What to have ready
To start, we need:
- Trade licence and activity description, to confirm DNFBP status
- A description of your customer base and typical transactions
- Geographic exposure — where customers and counterparties are based
- Existing goAML registration details, if any
- Any existing policies, procedures or risk assessment
- Organisation chart and details of customer-facing staff
- A sample of customer files as currently maintained
- Details of any prior inspection or correspondence
How this is priced
The programme build is a fixed fee, scoped on the size of the business and the complexity of its customer base. A small brokerage is a contained engagement; a corporate service provider with international clients is larger.
Ongoing support — annual risk assessment review, refresher training, and availability when a difficult customer question arises — is an annual fee. Where you need an outsourced compliance officer function, that is quoted separately.
Related
Frequently Asked Questions
Are we a DNFBP?
If you are a real estate broker or agent, a dealer in precious metals or stones, a corporate service provider, an auditor or accountant, or a lawyer or notary in defined circumstances — almost certainly yes. The categories are activity-based rather than size-based, so a two-person business is as much in scope as a large one.
Is registering on goAML enough?
No, and this is the most common misunderstanding. Registration is the visible step. You also need a compliance officer, a business risk assessment, documented CDD procedures actually applied to customers, staff training with records, and a reporting capability. In an inspection the registration is checked first and helps least.
What does an inspection look at?
goAML registration, the compliance officer and whether they can explain the programme, the business risk assessment, a sample of customer files to see whether CDD was actually applied, beneficial ownership for corporate customers, enhanced due diligence where required, training records, and reporting capability.
We are very small. Does all of this really apply?
The obligations are risk-based, so the depth of your procedures should reflect your actual risk — a small brokerage does not need a bank’s programme. What is not proportionate is whether the elements exist. You need a risk assessment, a compliance officer, CDD, training and reporting capability, however short each may be.
What is customer due diligence?
Identifying and verifying your customer, identifying beneficial owners where the customer is a company, understanding the purpose of the relationship, and applying enhanced measures where your risk assessment indicates higher risk. It has to be applied and evidenced, not just documented as a procedure.
Who can be the compliance officer?
Someone with sufficient seniority, authority and independence, who understands the business and the obligations. In a small business they will have other responsibilities, which is fine — what is not fine is an appointment in name only, because they will be asked to explain the programme.
What happens if we have registered but done nothing else?
It is a common position and it is fixable. Build the risk assessment first, because everything else is measured against it, then procedures, then apply CDD to the existing customer base, then train. Doing it now is considerably better than doing it during an inspection.
It is a common position and it is fixable. The risk assessment comes first, because everything else is measured against it.
Check my compliance status 058 101 9570
Last reviewed 27 July 2026. Rates, thresholds and deadlines change — the e-invoicing provider deadline has already moved once. Confirm current requirements with the Federal Tax Authority before acting, or ask us to check your position.