How Can a Real Estate Brokerage Prepare for an AML Inspection?

How Can a Real Estate Brokerage Prepare for an AML Inspection?
An Anti-Money Laundering inspection can place significant pressure on a UAE real estate brokerage—particularly when the company is registered on goAML but has not maintained a complete, working compliance system.
During an inspection, having an AML policy document is not enough. The brokerage should be able to demonstrate that it identifies customers and beneficial owners, assesses risks, screens relevant parties, monitors transactions, reports suspicious activity and keeps evidence that these controls are operating effectively.
The financial and reputational consequences of non-compliance can be substantial. In the first half of 2025, the UAE Ministry of Economy and Tourism reported 495 violations involving real estate brokerages, resulting in penalties totalling AED 18.5 million. The Ministry highlighted weaknesses involving due diligence, risk assessments and suspicious-transaction reporting. View the Ministry’s inspection announcement.
The most effective preparation is therefore not to create documents immediately before an inspection. It is to establish an inspection-ready system that connects written policies to actual customers, transactions and compliance decisions.
Why Are Real Estate Brokers Subject to AML Requirements?
Real estate can be attractive to criminals because property may be used to store or transfer significant value. Transactions may also involve companies, nominees, overseas investors, intermediaries, complex ownership arrangements, cash or virtual assets.
Real estate agents and brokers handling the purchase or sale of property fall within the UAE’s Designated Non-Financial Businesses and Professions—or DNFBP—framework.
The current principal legislative framework includes:
Federal Decree-Law No. 10 of 2025 concerning Anti-Money Laundering, Terrorism Financing and Proliferation Financing
Cabinet Resolution No. 134 of 2025 containing the Executive Regulations
Targeted Financial Sanctions requirements
Ministry of Economy and Tourism circulars and sector guidance
UAE Financial Intelligence Unit reporting requirements
Brokerages should ensure their policies no longer rely exclusively on the repealed 2018 AML law and 2019 Executive Regulations. The current legislation is available through the UAE legislation portal and the Ministry’s financial-crime legislation page.
What Will an AML Inspector Look For?
An inspector may assess whether the brokerage’s controls are appropriate for its size, customers, geographical exposure, services and transaction patterns.
The review may include:
Company-wide AML risk assessment
AML policies and procedures
Appointment and authority of the Compliance Officer or MLRO
goAML registration and access
Customer and beneficial-owner identification
Customer risk classifications
Sanctions, PEP and adverse-media screening
Source-of-funds and source-of-wealth checks
Enhanced Due Diligence
Ongoing transaction monitoring
Suspicious-transaction escalation
goAML reports
Employee training
Record retention
Management oversight
Independent compliance reviews
Remediation of previous findings
Inspectors may select customer files and ask the brokerage to explain how each customer’s risk rating was calculated, who approved the relationship and why particular documents were obtained.
1. Review the Business-Wide Risk Assessment
The business-wide risk assessment is the foundation of the brokerage’s AML compliance system.
It should identify and evaluate the money-laundering, terrorism-financing and proliferation-financing risks arising from:
Customer types
Customer nationalities and residences
Countries connected to transactions
Legal entities and ownership structures
Services provided
Property types and values
Payment methods
Cash exposure
Virtual-asset exposure
Use of third parties or representatives
Non-face-to-face relationships
High-risk jurisdictions
Politically Exposed Persons
Unusual or complex transactions
A generic risk assessment copied from another company is unlikely to explain the brokerage’s actual risks.
The assessment should describe the inherent risks, controls applied and remaining or residual risk. It should also show how the results influence customer onboarding, Enhanced Due Diligence, transaction monitoring, training and management oversight.
The assessment should be reviewed periodically and whenever there is a material change in customers, services, ownership, geographical exposure or legislation.
2. Update the AML Policies and Procedures
The AML policy should reflect the company’s real operations and the current legal framework.
It should address:
Customer acceptance
Customer Due Diligence
Identification of beneficial owners
Customer risk classification
Simplified and Enhanced Due Diligence
PEP handling
Sanctions screening
High-risk countries
Source of funds and source of wealth
Ongoing monitoring
Suspicious-activity escalation
goAML reporting
Prohibition against tipping off
Record retention
Employee training
Compliance testing
Responsibilities of senior management and the MLRO
The policy should be approved by senior management, communicated to relevant employees and supported by operating forms and checklists.
A policy that exists only as a signed PDF—but is not followed in customer files—will not demonstrate effective compliance.
3. Confirm the MLRO’s Appointment and Authority
The brokerage should have a formally appointed Compliance Officer or Money Laundering Reporting Officer with sufficient authority, knowledge and access to information.
The inspection file should contain:
Appointment resolution or letter
Job description
Management approval
MLRO authorisation
Evidence of goAML access
Reporting line to senior management
Training and qualification records
Periodic compliance reports
Records of issues escalated to management
The MLRO must be able to make reporting decisions without inappropriate commercial interference.
Sales pressure should never prevent a customer from being rejected, delay Enhanced Due Diligence or stop a suspicious matter from being reported.
4. Check the goAML Registration
All applicable DNFBPs must register on goAML. The platform is used to submit Suspicious Transaction Reports and Suspicious Activity Reports to the UAE Financial Intelligence Unit. The Ministry confirms that goAML registration is mandatory.
Before an inspection, verify that:
The registration is active
The company information is correct
The current MLRO has access
Email addresses and mobile numbers are current
The Google Authenticator access works
Former employees no longer control the account
Reporting procedures have been tested
Submitted reports and acknowledgements are securely retained
Registration alone does not prove compliance. The company must know when and how to submit the required reports.
5. Review Every Customer File
The brokerage should conduct a sample review—or, where necessary, a full review—of existing customer and transaction files.
For an individual customer, the file may include:
Emirates ID or passport
UAE visa, where applicable
Residential address
Contact details
Occupation or business activity
Purpose of the transaction
Customer risk assessment
Sanctions and PEP screening
Source-of-funds evidence
Source-of-wealth evidence for higher-risk cases
Transaction documents
Payment records
Ongoing monitoring notes
For a corporate customer, the file may also require:
Trade licence or registration certificate
Memorandum and Articles of Association
Ownership structure
Register of shareholders
Identification of directors and authorised signatories
Ultimate Beneficial Owner information
Identification documents for beneficial owners
Board resolution or authorisation
Nature of business
Source of company funds
Customer and UBO screening results
The brokerage must look beyond the company named in the sale agreement and identify the natural person who ultimately owns or controls it.
6. Document Customer Risk Ratings
Every customer should be assigned an appropriate risk classification based on defined factors.
These may include:
Nationality and residence
Business activity
Property value
Payment method
Corporate structure
PEP status
Sanctions exposure
High-risk country connections
Use of intermediaries
Unusual transaction behaviour
Source of funds
Whether the relationship is remote or face-to-face
A rating such as “low,” “medium” or “high” should be supported by a calculation and written reasoning.
A high-risk customer is not automatically prohibited. However, the brokerage may need Enhanced Due Diligence, additional evidence, senior-management approval and closer monitoring before proceeding.
7. Maintain Screening Evidence
The brokerage should screen customers, potential customers, beneficial owners, authorised representatives and other relevant parties against applicable sanctions lists.
It should also assess PEP status and, depending on the risk, adverse-media information.
The screening file should show:
Name searched
Date and time of the search
Lists or screening system used
Search results
Potential matches identified
How false positives were resolved
Reviewer’s name
Approval or escalation decision
Evidence of ongoing rescreening
The UAE’s targeted financial sanctions guidance requires relevant parties to be screened against the UN Consolidated List and UAE Local Terrorist List. Where a potential or confirmed match arises, the company must follow the applicable freezing and reporting procedures without delay. Review the official targeted financial sanctions guidance.
A screenshot stating “no match” without identifying the searched person, date and database may not provide sufficient evidence.
8. Review Source of Funds and Payment Methods
The brokerage should understand how the property is being financed and whether the payment method is consistent with the customer’s profile.
Evidence may include:
Bank statements
Salary certificates
Business financial statements
Sale agreements for other assets
Loan or mortgage approvals
Inheritance documents
Dividend records
Investment statements
Company resolutions
Evidence of accumulated savings
The brokerage should investigate warning signs such as:
Payments made by unrelated third parties
Large cash payments
Funds arriving from multiple accounts
Sudden changes in the buyer or seller
Complex corporate ownership without a commercial explanation
Transactions inconsistent with the customer’s known income
Overpayment followed by a refund request
Rapid resale without a clear economic reason
Customer resistance to providing UBO or source-of-funds information
Virtual-asset payments with unclear origin
The objective is not simply to collect documents. The MLRO must assess whether those documents provide a reasonable and consistent explanation.
9. Confirm Whether a Real Estate Activity Report Is Required
A Real Estate Activity Report, or REAR, may be required for certain freehold property purchase and sale transactions.
The Ministry’s real estate circular identifies the following reporting situations:
A single or multiple cash payment of AED 55,000 or more
Payment of all or part of the property value using virtual assets
Conversion of virtual assets into cash used for all or part of the property transaction
The brokerage must retain the required identification and transaction documents and submit the REAR through goAML. A REAR is a threshold or activity-based report; it does not replace an STR or SAR when the transaction is suspicious. Review the Ministry’s real estate reporting announcement.
10. Test the Suspicious-Activity Reporting Process
Employees should know how to escalate concerns internally without informing the customer.
The internal process should establish:
How employees identify a warning sign.
How they submit an internal report to the MLRO.
How the MLRO investigates the matter.
How the decision to report or not report is documented.
How an STR or SAR is submitted through goAML.
How confidentiality is protected.
How the customer relationship is monitored afterwards.
The MLRO should retain appropriate decision records, including cases where an internal concern was reviewed but a goAML report was not submitted.
There is no minimum transaction value that must be reached before suspicious activity can be reported.
11. Organise the AML Inspection File
A practical inspection file should contain:
Inspection area | Evidence to prepare |
Governance | Management approvals, MLRO appointment and reporting structure |
Risk assessment | Current business-risk assessment and review history |
Policies | Approved AML/CFT/CPF policies and operating procedures |
goAML | Registration, active access and submitted-report records |
Customer files | KYC, UBO, customer-risk ratings and approvals |
Screening | Sanctions, PEP and adverse-media search evidence |
Transactions | Contracts, payment records and monitoring notes |
Reporting | Internal reports, STR/SAR decisions and REAR submissions |
Training | Materials, attendance records and employee assessments |
Record keeping | Retention procedure and accessible customer files |
Oversight | Management reports, compliance reviews and remediation tracker |
Relevant AML and transaction records should generally be retained for at least five years and remain retrievable when requested by a competent authority.
12. Conduct a Mock Inspection
Before responding to an inspector, conduct a structured compliance health check.
Select several customer files covering different risk levels and ask:
Can we identify the customer and beneficial owner?
Is the risk rating supported?
Was screening completed at the correct time?
Is the payment method understood?
Is source-of-funds evidence sufficient?
Was Enhanced Due Diligence performed where necessary?
Were relevant goAML reports submitted?
Can the MLRO explain the decision?
Are all records accessible?
Was management informed of significant risks?
Record every weakness in a remediation tracker showing the problem, responsible person, required action, deadline and completion evidence.
Documents should never be backdated or fabricated. If a historical gap cannot be corrected, record it honestly and implement a properly approved remediation plan.
How Ahmad Al Araidi Auditing Can Help
Ahmad Al Araidi Auditing of Accounts assists UAE real estate brokerages in preparing for AML inspections and strengthening their compliance systems.
Our support may include:
AML compliance gap assessment
Business-wide risk assessment
AML/CFT/CPF policies and procedures
Customer and corporate KYC forms
UBO verification procedures
Customer risk-classification methodology
Sanctions and PEP screening procedures
Enhanced Due Diligence checklists
Source-of-funds and source-of-wealth reviews
goAML reporting procedures
REAR, STR, SAR, FFR and PNMR guidance
Employee and management training
Inspection-file preparation
Sample customer-file testing
Remediation plans and compliance trackers
Ongoing AML compliance support
Frequently Asked Questions
Is goAML registration enough for an inspection?
No. Registration provides access to the reporting platform. The brokerage must also maintain risk assessments, policies, customer files, screening evidence, monitoring procedures, training records and reporting controls.
Does every property customer require Enhanced Due Diligence?
Not automatically. The level of due diligence should reflect the assessed risk. Higher-risk relationships require additional investigation, evidence, approval and monitoring.
Should both the buyer and seller be checked?
The brokerage should identify and assess the parties relevant to its role in the transaction, including customers, beneficial owners, representatives and other parties required under the applicable procedures.
What if a customer refuses to provide UBO or source-of-funds information?
The brokerage should not proceed merely because the transaction is commercially valuable. The matter should be escalated to the MLRO, and the need for a suspicious-activity report should be assessed without tipping off the customer.
Can an external consultant take responsibility for AML compliance?
A consultant can support the company, but the brokerage and its management remain responsible for implementing and maintaining an effective compliance system.
Is Your Real Estate Brokerage Ready for an AML Inspection?
An inspection should not be the first time the company tests its AML controls.
A professional pre-inspection review can identify missing documents, outdated policies, weak customer files and unreported transactions before they become regulatory findings.
Contact Ahmad Al Araidi Auditing of Accounts for an AML inspection-readiness assessment.
Website: auditors.ae
Email: info@auditors.ae
Phone: +971 56 626 6391
Recommended CTA button: Check My AML Inspection Readiness
This article provides general information and does not constitute legal advice. AML requirements and reporting decisions depend on the brokerage’s activities, customers, jurisdiction, supervisory authority and the legislation and official guidance applicable at the relevant time.



