AML/CFT and goAML: Reporting Duties for UAE Financial Institutions
goAML is the UAE Financial Intelligence Unit's reporting platform, and AML/CFT rules require every licensed financial institution to register on it and file suspicious transaction reports. Federal Decree-Law 20/2018 and CBUAE supervision make this reporting a core obligation, not an optional control, across the UAE's banking sector.
- Governing law: Federal Decree-Law 20/2018 on Anti-Money Laundering and Combating the Financing of Terrorism.
- Reporting channel: goAML, the web platform operated by the UAE Financial Intelligence Unit (FIU).
- Who must register: all financial institutions and designated non-financial businesses and professions supervised in the UAE.
- Supervisor for banks: the Central Bank of the UAE (CBUAE).
- Core filing: a Suspicious Transaction Report (STR) or Suspicious Activity Report (SAR) whenever grounds for suspicion exist.
The UAE context for AML/CFT reporting
The UAE's position as a regional trade, remittance and wealth hub — with an expatriate-majority population, extensive free-zone activity and high volumes of cross-border salary transfers and cash-intensive sectors — makes AML/CFT supervision unusually demanding. Institutions such as Emirates NBD, FAB and Dubai Islamic Bank, along with firms licensed in the DIFC and ADGM, operate under a federal framework that channels all suspicion-based reporting through a single national system: goAML. That single-channel design lets the FIU aggregate intelligence across banks, exchange houses, insurers and DNFBPs into one national picture.
What is goAML and who operates it in the UAE?
goAML is a reporting and analysis platform, originally developed by the United Nations Office on Drugs and Crime, adopted by the UAE FIU as the mandatory channel for AML/CFT disclosures. In the UAE, the FIU sits under the Central Bank of the UAE and receives, analyses and disseminates reports filed by supervised entities.
Any institution that comes under the AML/CFT framework must register its entity on goAML, nominate a compliance officer, and file reports electronically. Registration is a prerequisite for lawful operation — a bank, exchange house or insurer cannot discharge its reporting duty by any other means.
What are the reporting duties under Federal Decree-Law 20/2018?
Federal Decree-Law 20/2018, together with its implementing Cabinet Decision, sets out the substantive obligations. For a financial institution these break down into a linked set of duties:
- Customer due diligence (CDD): identify and verify the customer and, where relevant, the beneficial owner, before and during the business relationship.
- Ongoing monitoring: scrutinise transactions against the customer's known profile and risk rating.
- Record-keeping: retain CDD documents and transaction records for the statutory retention period.
- Reporting: file the relevant report on goAML when suspicion arises.
- Internal controls: appoint a compliance officer, train staff, and maintain independent audit of the AML/CFT programme.
The reporting duty is triggered by suspicion, not by proof. If a transaction or attempted transaction gives reasonable grounds to suspect money laundering, terrorist financing or a predicate offence, the institution must report — and must do so without tipping off the customer.
What are the main goAML report types?
Institutions file different report types depending on the trigger. The most common are set out below.
Report type | Full name | Typical trigger |
|---|---|---|
STR | Suspicious Transaction Report | Suspicion attached to an executed or attempted transaction |
SAR | Suspicious Activity Report | Suspicion based on activity or conduct, not a single transaction |
FFR | Funds Freeze Report | Action taken on funds linked to a designated person or sanctions list |
PNMR | Partial Name Match Report | A possible match against a UN or local sanctions list requiring notification |
HRC / HRCA | High-Risk Country reports | Dealings connected to jurisdictions flagged as higher risk |
The correct report type matters: filing an STR where a SAR is required, or vice versa, can leave a genuine risk mis-categorised in the FIU's analysis. Institutions should map their internal alerts to goAML report types as part of their AML/CFT procedures.
How quickly must a report be filed?
The law and FIU guidance require reporting without delay once suspicion is formed. There is no grace period for "watching the account a little longer" before a genuine suspicion is escalated — once the compliance officer concludes that grounds exist, the report is due. Delay, non-reporting and tipping-off each carry penalties under the AML framework, and CBUAE can take supervisory action against banks that under-report or file late.
Because the trigger is qualitative, the practical challenge is consistency: ensuring that similar red flags produce similar outcomes across branches, relationship managers and product lines, rather than depending on who happens to review the alert.
What happens if an institution gets it wrong?
Weak AML/CFT reporting exposes an institution on several fronts. Supervisors can impose administrative and financial penalties; a poor filing record damages correspondent-banking relationships; and individual officers can face personal liability for failures such as tipping-off. Conversely, over-reporting — filing defensive STRs on everything to avoid blame — floods the FIU with noise and can itself attract supervisory criticism. The goal is accurate, well-reasoned reporting supported by sound customer due diligence.
How AI helps
Reporting quality depends almost entirely on the quality of the underlying KYC and due-diligence file — and in the UAE that means reading Emirates ID cards, passports, residence visas, trade licences and Ejari documents accurately and consistently. YuAccess applies document AI to extract and verify these identity and entity documents at onboarding, so customer profiles are complete and structured before any monitoring rule runs. Cleaner onboarding data means fewer false alerts to triage and more reliable inputs when a compliance officer has to decide whether a transaction genuinely warrants a goAML filing — turning suspicion into a defensible, well-documented report.
FAQ
Is goAML registration mandatory for all financial institutions in the UAE? Yes. Any entity supervised under the UAE's AML/CFT framework, including banks, exchange houses and insurers, must register on goAML and file reports electronically. Registration is a precondition for lawful operation.
What is the difference between an STR and a SAR on goAML? An STR (Suspicious Transaction Report) attaches suspicion to a specific executed or attempted transaction, while a SAR (Suspicious Activity Report) covers suspicious conduct or behaviour that is not tied to a single transaction. Both are filed through goAML.
Who supervises AML/CFT compliance for banks in the UAE? The Central Bank of the UAE (CBUAE) supervises banks and other licensed financial institutions, while the FIU operates the goAML platform and analyses the reports it receives.
Can we tell a customer that we have filed a report about them? No. Tipping-off is prohibited under Federal Decree-Law 20/2018. Informing a customer, directly or indirectly, that a report has been or may be filed is a distinct offence.
How long must we keep AML records? Institutions must retain customer due diligence and transaction records for the statutory retention period set out in the AML framework, and make them available to the CBUAE and the FIU on request.
What triggers a goAML report — do we need proof of a crime? No. The trigger is reasonable grounds for suspicion, not proof. If a transaction or activity gives cause to suspect money laundering, terrorist financing or a predicate offence, the institution must report without delay.
Explore more UAE compliance and onboarding guidance on the YuVerse UAE hub.
This is a general explainer, not legal advice.
References
- Federal Decree-Law No. 20 of 2018 on Anti-Money Laundering and Combating the Financing of Terrorism and Financing of Illegal Organisations — United Arab Emirates. https://u.ae/
- Central Bank of the UAE — AML/CFT Rulebook and supervisory guidance. https://rulebook.centralbank.ae/
- UAE Financial Intelligence Unit (goAML reporting platform). https://www.uaefiu.gov.ae/