UAE compliance
A failed AML hit is a decision point, not a rejection notice
The rules around anti-money laundering in the UAE have tightened sharply since the country’s exit from the FATF grey list in 2024. Banks, DNFBPs, real estate agents, gold dealers, and virtual asset providers are all expected to react to a failed screening with a documented, defensible process. What used to be a quick internal note is now a regulated workflow, and the Central Bank of the UAE and the Ministry of Economy are actively auditing how firms handle these moments.
This guide walks through why a customer fails a check, the immediate steps to take, how communication should be handled, and where the compliance landscape is heading next.
Why it happens
Common reasons a customer fails an AML screening
A failed screening rarely means the person is a criminal. Most alerts are triggered by name matches, incomplete data, or sanctions overlaps that need human review. Understanding the source of the alert shapes every step that follows.
- Sanctions list hit. The customer appears on the UAE Local Terrorist List, the UN Consolidated List, or an OFAC list.
- PEP exposure. The customer is a politically exposed person, or a close associate of one, and needs enhanced due diligence.
- Adverse media. Credible news links the customer to fraud, corruption, or financial crime.
- Document mismatches. Emirates ID, passport, or trade licence details do not align with the information provided.
- High-risk geography. The source of funds routes through a jurisdiction flagged by the Financial Action Task Force.
- Behavioural red flags. Transaction patterns do not match the stated business activity.

Trend one
Immediate response is being timed and audited
Regulators in the UAE now look at how quickly a compliance team reacts once an alert fires. Waiting a week to open a case file is treated as a control weakness. The current expectation is that a Level 1 analyst opens the case the same business day and escalates to the MLRO within 24 to 48 hours if the hit is not a clear false positive.
- Freeze or pause the transaction pending review, do not proceed on assumption.
- Re-verify the customer file: Emirates ID, passport, trade licence, UBO declaration.
- Run a second-source check to rule out a name collision.
- Log every action with timestamp, reviewer, and rationale.
Rigorous AML and KYC checks at this stage do two things: they narrow down whether the alert is real, and they build the audit trail your regulator will ask for later.
Trend two
Suspicious Transaction Reports are rising, and so is scrutiny
The UAE Financial Intelligence Unit received a record volume of Suspicious Transaction Reports and Suspicious Activity Reports through the goAML portal over the past two years. Filing rates are up across banks, exchange houses, and DNFBPs, according to figures published by the UAE FIU. The direction of travel is clear: when in doubt, file.
- Confirm the concern is genuine. A true match, not a false positive.
- Draft the STR internally. The MLRO reviews facts, evidence, and reasoning.
- Submit through goAML. Filing is expected without tipping off the customer.
- Preserve the record. Keep supporting documents for at least five years, as required under Federal Decree-Law No. 20 of 2018.
Do not tip off the customer
Article 25 of the UAE AML law prohibits disclosing that an STR has been filed. Keep communication neutral and factual.
Trend three
Customer communication is a legal minefield
One of the fastest ways a UAE firm gets fined is by handling the customer conversation poorly after a failed check. Staff sometimes explain why the account has been paused, which can constitute tipping off. Others refuse to communicate at all, which invites complaints and reputational risk.
A safer script is short and neutral: the application is under internal review, additional information may be requested, and no timeline can be guaranteed. Front-line staff should be trained not to speculate.
The next wave of enforcement in the UAE will not be about who filed an STR. It will be about who could show, on paper, that they made a considered decision when the alert came in.
Trend four
Technology is closing the gap, but human judgement still decides
Automated screening platforms are now standard even at small firms in Dubai and Abu Dhabi. The next shift is toward continuous monitoring rather than one-off checks at onboarding. Sanctions lists update weekly, PEP status changes overnight, and adverse media surfaces without warning. A customer who passed a screening in January can fail one in June without doing anything themselves.
- Perpetual KYC. Customer files are re-scored automatically as source data changes.
- AI-assisted triage. Machine learning suppresses obvious false positives so analysts see fewer, better alerts.
- Beneficial ownership registries. The UAE’s UBO regulations mean firms can cross-check declared owners against official records.
- goAML integration. Filing systems increasingly connect directly to the FIU portal to reduce manual errors.
Mistakes that cost UAE businesses the most
Proceeding anyway
Closing the deal because the customer is important, then filing paperwork later, is the single biggest source of regulatory fines.
Verbal decisions
An MLRO who clears an alert by phone with no written rationale leaves the firm exposed at the next audit.
One-and-done checks
Screening only at onboarding, and never again, misses customers whose risk profile changes after the relationship starts.
A worked example
A Dubai-based real estate brokerage screened a buyer paying cash for an apartment in Business Bay. The screening flagged adverse media linking the buyer’s declared employer to a foreign corruption investigation. The MLRO paused the transaction, requested proof of source of funds, and asked for a signed declaration on the origin of the money. The buyer produced bank statements that did not match the declared salary. The brokerage filed an STR through goAML, kept the customer informed only that the file was under review, and preserved all correspondence. Six months later, when the Ministry of Economy audited the firm’s DNFBP compliance, the case file was cited as an example of correct process.
Looking ahead
Where UAE AML compliance is going next
Expect three shifts over the next 18 months: mandatory perpetual KYC for higher-risk sectors, tighter coordination between the Central Bank, SCA, and free zone regulators, and heavier penalties for firms that cannot evidence their decision-making. The businesses that will do well are the ones treating a failed screening not as a problem to bury, but as a process to document.
Frequently asked questions
Can we still onboard a customer who failed an AML screening?
Sometimes, yes. A failed screening is often a false positive or a data mismatch. If enhanced due diligence clears the concern and the MLRO signs off in writing, onboarding can proceed. If the concern is genuine, or a Suspicious Transaction Report has been filed, the customer should not be onboarded.
Do we have to tell the customer they failed the screening?
No. Under Article 25 of Federal Decree-Law No. 20 of 2018, disclosing that a suspicion or an STR filing exists is a criminal offence in the UAE. Communication should be limited to general statements about internal review.
Front-line staff should be trained to avoid speculation and refer questions to the compliance function.
How long should we keep records of a failed screening?
UAE AML law requires firms to keep customer due diligence records, transaction records, and supporting documents for at least five years from the end of the business relationship or the date of the transaction, whichever is later. Many firms keep records for longer as a matter of policy.
When should we file a Suspicious Transaction Report?
File an STR whenever there is a reasonable suspicion that funds are linked to money laundering, terrorism financing, or a predicate offence. You do not need proof. The reasonable-suspicion threshold is deliberately low, and filing is done through the goAML portal operated by the UAE Financial Intelligence Unit.
What happens if we ignore an AML alert?
Ignoring alerts exposes the business to administrative fines that can reach millions of dirhams, licence suspension, and personal liability for the MLRO and senior management. The Central Bank of the UAE and the Ministry of Economy publish enforcement actions regularly, and reputational damage is often more costly than the fine itself.
Do small businesses in the UAE have to run AML checks?
Yes, if they fall within the Designated Non-Financial Businesses and Professions category. This includes real estate agents, dealers in precious metals and stones, corporate service providers, auditors, and lawyers. The size of the firm does not exempt it from the obligation to screen customers and file STRs where required.
How often should we re-screen existing customers?
Risk-based frequency is the standard. Low-risk customers are typically re-screened annually, medium-risk every six months, and high-risk customers on a continuous or quarterly basis. Many UAE firms are moving to perpetual KYC, where the file is monitored against list changes in near real time.
Written by Ralf McDowell
Cyclist, hustler, fender owner, hand letterer and growthhacker. Acting at the sweet spot between beauty and sustainability to express ideas through design. I'm fueled by craft beer, hip-hop and tortilla chips.
Recent Posts
- What UAE Businesses Should Do If a Customer Fails an AML Screening
- Can Psychometric Tests Reduce Bad Hires in the UAE?
- How the Use of ID Scanning Helps to Control Access to Gyms, Lounge Areas, and SPA Hotels
- The Best Cars to Rent for Music Festivals in Western Australia
- Essential Equine Supplies – Comprehensive Guide for Horse Owners
Blog Author Ralf McDowell
