- Front
- AML Compliance
- goAML Registration for UAE DNFBPs: Step-by-Step Guide
goAML Registration for UAE DNFBPs: Step-by-Step Guide
A practical UAE guide to goAML registration for DNFBPs, covering eligibility, documents, SACM access, application steps, common errors, and ongoing AML duties.
Key takeaways
- goAML registration is mandatory for UAE businesses that fall within an applicable DNFBP category.
- Businesses should confirm their supervisory authority before starting the registration process.
- Consistent company, licence, ownership, and compliance officer information can reduce avoidable delays.
- Registration normally begins with SACM access before the reporting entity is registered in goAML.
- An approved account does not replace customer due diligence, risk assessment, screening, reporting, training, and record-keeping controls.
What Is goAML in the UAE?
goAML is an electronic reporting platform used by the UAE Financial Intelligence Unit to receive and analyse reports relating to suspected money laundering, terrorism financing, and connected financial crime. It gives regulated entities a secure channel for submitting suspicious transaction and suspicious activity reports to the competent authority.
The system was developed by the United Nations Office on Drugs and Crime and is used by financial intelligence units in multiple jurisdictions. In the UAE, the FIU receives information from financial institutions and DNFBPs and uses it to support the detection and analysis of suspicious activity.
goAML does not replace the company’s internal AML framework. A business still needs documented risk assessments, customer due diligence procedures, beneficial ownership checks, sanctions screening, transaction monitoring, internal escalation, staff training, and record retention.
A clean goAML application starts with consistent records, but effective compliance begins only after the account is operational. — Consultant observation, KPM Global Services UAE
Which UAE Businesses May Need to Register?
A business may need to register when its licensed or actual activities place it within a regulated DNFBP category. Classification should be based on the services performed, customer transactions, supervisory authority, and applicable UAE AML requirements rather than the company name alone.
The Ministry of Economy and Tourism identifies four principal categories under its supervision:
- Real estate brokers and agents involved in property purchase or sale transactions
- Auditors and accounting firms providing professional or assurance services
- Dealers in precious metals and precious stones
- Trust and company service providers involved in company formation, administration, or registered-office services
The Ministry’s current classification guidance describes these sectors and confirms that DNFBPs under its remit must register in goAML.
Lawyers, legal consultants, and other professional firms may also have AML and reporting obligations depending on the services they provide and the authority supervising them. A 2026 UAE government forum on DNFBP compliance included real estate firms, precious metals and stones dealers, independent accountants and auditors, corporate service providers, lawyers, and legal consultants.
Businesses in the Abu Dhabi Global Market, Dubai International Financial Centre, or another regulated free zone should confirm the correct registration and supervisory route. The UAE FIU’s SACM portal recognises that reporting entities may operate under bodies such as the ADGM and the Dubai Financial Services Authority.
Example 1: A Dubai mainland consultancy provides business setup assistance, arranges company incorporation, and supplies registered-office services. Although its licence uses the word “consultancy,” its actual services may place it within the trust or company service provider category. The owners should confirm classification before assuming goAML registration does not apply.
Why Does goAML Registration Matter?
Registration gives an authorised reporting entity access to the channel used for submitting suspicious transaction and activity reports. Without approved access and trained users, a DNFBP may be unable to make a required submission promptly or demonstrate that it has established a workable reporting process.
The regulatory focus extends beyond registration. The Ministry reported 1,063 AML compliance violations and more than AED 42 million in fines during inspections conducted in the first half of 2025. The issues covered regulated real estate businesses, precious metals and stones dealers, corporate service providers, and auditors.
For business owners, the practical lesson is that a goAML approval email is not evidence of a complete AML programme. Regulators may also examine:
- Whether the business has completed a documented risk assessment
- Whether customer and beneficial-owner information is verified
- Whether higher-risk relationships receive enhanced review
- Whether sanctions and politically exposed person screening is performed
- Whether unusual activity is identified and escalated
- Whether reporting decisions are documented
- Whether staff receive role-relevant training
- Whether supporting records can be produced during an inspection
What Should a Business Prepare Before Registration?
A DNFBP should prepare its company and authorised-user records before opening the application. The names, licence numbers, addresses, identity details, and contact information entered into SACM and goAML should agree with the supporting documents and internal corporate records.
The Ministry currently lists an authorisation letter, passport, residence visa, Emirates ID, commercial trade licence, and an authenticator application among the main registration requirements.
Company information
Prepare:
- Valid commercial or professional trade licence
- Legal company name exactly as shown on the licence
- Trade licence number and licensing authority
- Registered and operating addresses
- Company telephone number and controlled email address
- Incorporation or registration information
- Description of the company’s actual activities
- Relevant supervisory authority and DNFBP category
Ownership and management information
Depending on the application and regulatory requirements, the business should also have current records for:
- Shareholders and partners
- Ultimate beneficial owners
- Directors and managers
- Authorised signatories
- Persons authorised to represent the company
- Existing compliance officer or money laundering reporting officer
Compliance officer information
The authorised user will commonly need:
- Passport copy
- Emirates ID and residence visa, where applicable
- UAE mobile number
- Individual business email address
- Job title and employment details
- Formal appointment or authorisation letter
- Evidence that the person may act for the reporting entity
Avoid using a former employee’s contact details, an uncontrolled personal email address, or a generic inbox that several employees can access. Account ownership and recovery arrangements should remain under company control.
How Do UAE DNFBPs Register for goAML?
The registration process generally involves securing access through SACM and then completing the reporting entity registration within goAML. Portal fields can change, so applicants should follow current instructions rather than relying on screenshots or checklists saved from an earlier registration.
Step 1: Confirm the reporting entity classification
Review both the trade licence and the services delivered in practice.
Confirm:
- The correct DNFBP category
- The applicable supervisory authority
- Whether the business is mainland, non-financial free zone, or financial free zone
- Whether the applicant is registering a company or an authorised individual
- Whether any existing registration or organisation identifier is already in place
Do not submit under a similar-sounding category merely to move the application forward. An incorrect classification can affect approval, account configuration, and available report types.
Step 2: Appoint an authorised compliance officer
The company should formally appoint the person responsible for AML oversight and goAML administration.
Typical responsibilities include:
- Maintaining the AML risk assessment
- Overseeing customer due diligence
- Reviewing unusual customer or transaction activity
- Receiving confidential internal reports
- Deciding whether external reporting is required
- Managing goAML users and permissions
- Retaining supporting records
- Responding to regulatory correspondence
The appointment should be documented through a board resolution, management decision, appointment letter, or another appropriate corporate record.
Step 3: Check the registration documents
Before submission, compare the application data with the trade licence and identity documents.
Check:
- Exact spelling of the legal entity name
- Licence number and expiry date
- Registered address
- Compliance officer name
- Passport or Emirates ID number
- Business email and UAE mobile number
- Supervisory authority
- Reporting entity category
Files should be current, readable, correctly oriented, and saved in the format required by the portal.
Step 4: Register through SACM
SACM is the security access stage used to obtain access to the goAML launch portal. The Ministry’s registration page directs applicants to register in the SACM protection system and use an authenticator-generated password to access goAML.
The applicant should:
- Open the official UAE FIU SACM registration portal.
- Choose the appropriate reporting entity registration route.
- Enter the entity and authorised-user details.
- Upload the required supporting documents.
- Complete email verification and authentication requirements.
- Retain the application reference number and registered contact details.
Company names and identity details should be entered exactly as shown in the supporting records.
Step 5: Complete the goAML entity application
After SACM access is approved, the authorised user proceeds to the goAML registration stage.
The application may request:
- Legal and trading names
- Reporting entity type
- DNFBP category
- Supervisory authority
- Licence and registration information
- Business address and contact details
- Nature of business activities
- Compliance officer or administrator information
- Supporting authorisation documents
Review each field before submission. In practice, small inconsistencies can create more delay than a genuinely missing document because the reviewer may be unable to reconcile the application with the licence or identity evidence.
Step 6: Monitor verification requests
Submitting the application does not guarantee immediate approval. The reviewing authority may request corrected documents, further explanation, or evidence of authority.
Monitor the registered email account and respond through the stated channel. Creating duplicate applications without instructions can produce conflicting organisation records and make the issue harder to resolve.
Step 7: Secure the approved account
After approval:
- Assign access only to employees who need it
- Avoid shared usernames and passwords
- Maintain multifactor authentication
- Record who can prepare, review, approve, and submit reports
- Remove access when an employee leaves or changes role
- Review user permissions periodically
- Update the account when the compliance officer changes
Example 2: A UAE jewellery business obtains goAML approval but leaves the account linked to a manager who later resigns. No replacement user is appointed, and the company cannot access the platform when a suspicious transaction requires review. A basic access register and exit checklist would have identified the issue earlier.
What Must a DNFBP Do After Registration?
An approved goAML account should be supported by procedures that help employees identify concerns, refer them confidentially, and provide the compliance officer with enough information to make a documented reporting decision.
The 2026 intergovernmental DNFBP forum emphasised effective customer due diligence, customer and beneficial-owner verification, risk assessment, and reporting of suspicious financial activity.
Post-registration controls should typically cover:
- Business-wide AML risk assessment
- Customer identification and verification
- Beneficial ownership checks
- Risk rating and enhanced due diligence
- Politically exposed person screening
- Targeted financial sanctions screening
- Monitoring of customer behaviour and transactions
- Confidential internal escalation
- External report assessment and submission
- Training for client-facing, finance, onboarding, and compliance teams
- Record keeping and regulatory inspection readiness
What Common goAML Registration Mistakes Should Businesses Avoid?
Most avoidable delays arise from inconsistent information, unclear authority, incorrect classifications, or weak account governance. A pre-submission review should therefore focus on whether the application can be matched quickly to the company’s licence, ownership records, and authorised representative.
Common mistakes include:
- Entering a shortened company name instead of the licensed legal name
- Using an expired trade licence or identity document
- Selecting the wrong DNFBP category
- Choosing the wrong supervisory authority
- Uploading cropped, blurred, or password-protected files
- Using personal contact details that the company does not control
- Appointing an applicant without written authority
- Failing to verify the registered email
- Submitting duplicate applications
- Treating registration as the full AML programme
- Failing to update the account after a compliance officer leaves
- Giving too many employees unnecessary access
What Documents and Preparations Should Be Checked?
Before beginning the application, create a controlled registration folder containing:
- Valid trade licence
- Incorporation or commercial registration document, where relevant
- Authorisation letter for the applicant
- Compliance officer appointment document
- Passport copy
- Emirates ID and residence visa, where applicable
- Ownership and beneficial-owner information
- Manager and authorised-signatory details
- Company address and contact details
- Supervisory authority confirmation
- Description of the company’s actual activities
- Existing AML policy and risk assessment
- User-access approval record
- Secure company email and UAE mobile number
- Copies of submissions, references, approval notices, and correspondence
The documents should be checked for consistency before they are uploaded. The company should also decide who will retain the records and monitor future changes.
How Can KPM Global Services UAE Assist?
KPM Global Services UAE can support Dubai and UAE businesses with the practical preparation surrounding goAML registration and ongoing AML compliance.
Depending on the activity and supervisory framework, assistance may include:
- Initial DNFBP classification review
- Registration-readiness assessment
- Document and data consistency checks
- Compliance officer appointment documentation
- SACM and goAML application support
- AML policy and procedure development
- Business risk assessment preparation
- Customer due diligence and screening workflows
- Internal suspicious activity escalation procedures
- Staff training and record-keeping support
- Review of user access and compliance handover arrangements
The reporting entity remains responsible for the accuracy of its submissions, reporting decisions, confidentiality, account governance, and compliance with applicable UAE requirements. No adviser can guarantee registration approval or a particular regulatory outcome.
What Should UAE DNFBPs Do Next?
Businesses should first confirm whether their actual activities fall within a DNFBP category and identify the correct supervisor. They should then appoint an authorised compliance officer, reconcile their company records, complete SACM and goAML registration, and test the internal reporting process before a suspicious case arises.
Owners should also include goAML access in licence-renewal, employee-exit, compliance-handover, and annual AML review procedures. This reduces the risk of discovering expired documents, inaccessible accounts, or outdated contact details during an inspection or urgent reporting event.
This article is for informational purposes and does not constitute legal, tax, accounting, or financial advice.
Questions and answers
Q: Is goAML registration mandatory for UAE DNFBPs?
A: Yes, businesses that fall within an applicable DNFBP category are generally required to register and maintain access to the reporting system. The exact route depends on the company’s activity and supervisory authority.
Q: Which UAE businesses are treated as DNFBPs?
A: Common categories include real estate brokers and agents, dealers in precious metals and stones, auditors, independent accountants, corporate service providers, and certain legal professionals. Classification depends on the services performed and the applicable regulatory framework.
Q: What documents are normally required for goAML registration?
A: Businesses commonly need a valid trade licence, an authorisation letter, and identification documents for the authorised applicant or compliance officer. Additional corporate, ownership, or approval documents may be requested depending on the entity and supervisor.
Q: How long does goAML registration take?
A: There is no standard approval period that applies to every application. Processing time can depend on the accuracy of the information, document quality, correct entity classification, email verification, and whether the authority requests clarification.
Q: Is goAML registration enough to satisfy UAE AML requirements?
A: No. Registration provides access to the reporting channel, but the business should also maintain risk assessments, customer due diligence, beneficial-owner verification, screening, monitoring, internal escalation, training, and record-keeping controls.