top of page
Logo
  • Whatsapp
  • Facebook
  • Instagram

How Can a Real Estate Brokerage Prepare for an AML Inspection?

2 days ago
9 min read

How Can a Real Estate Brokerage Prepare for an AML Inspection?


How Can a Real Estate Brokerage Prepare for an AML Inspection?

An Anti-Money Laundering inspection can place significant pressure on a UAE real estate brokerage—particularly when the company is registered on goAML but has not maintained a complete, working compliance system.

During an inspection, having an AML policy document is not enough. The brokerage should be able to demonstrate that it identifies customers and beneficial owners, assesses risks, screens relevant parties, monitors transactions, reports suspicious activity and keeps evidence that these controls are operating effectively.

The financial and reputational consequences of non-compliance can be substantial. In the first half of 2025, the UAE Ministry of Economy and Tourism reported 495 violations involving real estate brokerages, resulting in penalties totalling AED 18.5 million. The Ministry highlighted weaknesses involving due diligence, risk assessments and suspicious-transaction reporting. View the Ministry’s inspection announcement.

The most effective preparation is therefore not to create documents immediately before an inspection. It is to establish an inspection-ready system that connects written policies to actual customers, transactions and compliance decisions.


Why Are Real Estate Brokers Subject to AML Requirements?

Real estate can be attractive to criminals because property may be used to store or transfer significant value. Transactions may also involve companies, nominees, overseas investors, intermediaries, complex ownership arrangements, cash or virtual assets.

Real estate agents and brokers handling the purchase or sale of property fall within the UAE’s Designated Non-Financial Businesses and Professions—or DNFBP—framework.

The current principal legislative framework includes:

  • Federal Decree-Law No. 10 of 2025 concerning Anti-Money Laundering, Terrorism Financing and Proliferation Financing

  • Cabinet Resolution No. 134 of 2025 containing the Executive Regulations

  • Targeted Financial Sanctions requirements

  • Ministry of Economy and Tourism circulars and sector guidance

  • UAE Financial Intelligence Unit reporting requirements

Brokerages should ensure their policies no longer rely exclusively on the repealed 2018 AML law and 2019 Executive Regulations. The current legislation is available through the UAE legislation portal and the Ministry’s financial-crime legislation page.


What Will an AML Inspector Look For?

An inspector may assess whether the brokerage’s controls are appropriate for its size, customers, geographical exposure, services and transaction patterns.

The review may include:

  • Company-wide AML risk assessment

  • AML policies and procedures

  • Appointment and authority of the Compliance Officer or MLRO

  • goAML registration and access

  • Customer and beneficial-owner identification

  • Customer risk classifications

  • Sanctions, PEP and adverse-media screening

  • Source-of-funds and source-of-wealth checks

  • Enhanced Due Diligence

  • Ongoing transaction monitoring

  • Suspicious-transaction escalation

  • goAML reports

  • Employee training

  • Record retention

  • Management oversight

  • Independent compliance reviews

  • Remediation of previous findings

Inspectors may select customer files and ask the brokerage to explain how each customer’s risk rating was calculated, who approved the relationship and why particular documents were obtained.


1. Review the Business-Wide Risk Assessment

The business-wide risk assessment is the foundation of the brokerage’s AML compliance system.

It should identify and evaluate the money-laundering, terrorism-financing and proliferation-financing risks arising from:

  • Customer types

  • Customer nationalities and residences

  • Countries connected to transactions

  • Legal entities and ownership structures

  • Services provided

  • Property types and values

  • Payment methods

  • Cash exposure

  • Virtual-asset exposure

  • Use of third parties or representatives

  • Non-face-to-face relationships

  • High-risk jurisdictions

  • Politically Exposed Persons

  • Unusual or complex transactions

A generic risk assessment copied from another company is unlikely to explain the brokerage’s actual risks.

The assessment should describe the inherent risks, controls applied and remaining or residual risk. It should also show how the results influence customer onboarding, Enhanced Due Diligence, transaction monitoring, training and management oversight.

The assessment should be reviewed periodically and whenever there is a material change in customers, services, ownership, geographical exposure or legislation.


2. Update the AML Policies and Procedures

The AML policy should reflect the company’s real operations and the current legal framework.

It should address:

  • Customer acceptance

  • Customer Due Diligence

  • Identification of beneficial owners

  • Customer risk classification

  • Simplified and Enhanced Due Diligence

  • PEP handling

  • Sanctions screening

  • High-risk countries

  • Source of funds and source of wealth

  • Ongoing monitoring

  • Suspicious-activity escalation

  • goAML reporting

  • Prohibition against tipping off

  • Record retention

  • Employee training

  • Compliance testing

  • Responsibilities of senior management and the MLRO

The policy should be approved by senior management, communicated to relevant employees and supported by operating forms and checklists.

A policy that exists only as a signed PDF—but is not followed in customer files—will not demonstrate effective compliance.


3. Confirm the MLRO’s Appointment and Authority

The brokerage should have a formally appointed Compliance Officer or Money Laundering Reporting Officer with sufficient authority, knowledge and access to information.

The inspection file should contain:

  • Appointment resolution or letter

  • Job description

  • Management approval

  • MLRO authorisation

  • Evidence of goAML access

  • Reporting line to senior management

  • Training and qualification records

  • Periodic compliance reports

  • Records of issues escalated to management

The MLRO must be able to make reporting decisions without inappropriate commercial interference.

Sales pressure should never prevent a customer from being rejected, delay Enhanced Due Diligence or stop a suspicious matter from being reported.


4. Check the goAML Registration

All applicable DNFBPs must register on goAML. The platform is used to submit Suspicious Transaction Reports and Suspicious Activity Reports to the UAE Financial Intelligence Unit. The Ministry confirms that goAML registration is mandatory.

Before an inspection, verify that:

  • The registration is active

  • The company information is correct

  • The current MLRO has access

  • Email addresses and mobile numbers are current

  • The Google Authenticator access works

  • Former employees no longer control the account

  • Reporting procedures have been tested

  • Submitted reports and acknowledgements are securely retained

Registration alone does not prove compliance. The company must know when and how to submit the required reports.


5. Review Every Customer File

The brokerage should conduct a sample review—or, where necessary, a full review—of existing customer and transaction files.

For an individual customer, the file may include:

  • Emirates ID or passport

  • UAE visa, where applicable

  • Residential address

  • Contact details

  • Occupation or business activity

  • Purpose of the transaction

  • Customer risk assessment

  • Sanctions and PEP screening

  • Source-of-funds evidence

  • Source-of-wealth evidence for higher-risk cases

  • Transaction documents

  • Payment records

  • Ongoing monitoring notes

For a corporate customer, the file may also require:

  • Trade licence or registration certificate

  • Memorandum and Articles of Association

  • Ownership structure

  • Register of shareholders

  • Identification of directors and authorised signatories

  • Ultimate Beneficial Owner information

  • Identification documents for beneficial owners

  • Board resolution or authorisation

  • Nature of business

  • Source of company funds

  • Customer and UBO screening results

The brokerage must look beyond the company named in the sale agreement and identify the natural person who ultimately owns or controls it.


6. Document Customer Risk Ratings

Every customer should be assigned an appropriate risk classification based on defined factors.

These may include:

  • Nationality and residence

  • Business activity

  • Property value

  • Payment method

  • Corporate structure

  • PEP status

  • Sanctions exposure

  • High-risk country connections

  • Use of intermediaries

  • Unusual transaction behaviour

  • Source of funds

  • Whether the relationship is remote or face-to-face

A rating such as “low,” “medium” or “high” should be supported by a calculation and written reasoning.

A high-risk customer is not automatically prohibited. However, the brokerage may need Enhanced Due Diligence, additional evidence, senior-management approval and closer monitoring before proceeding.


7. Maintain Screening Evidence

The brokerage should screen customers, potential customers, beneficial owners, authorised representatives and other relevant parties against applicable sanctions lists.

It should also assess PEP status and, depending on the risk, adverse-media information.

The screening file should show:

  • Name searched

  • Date and time of the search

  • Lists or screening system used

  • Search results

  • Potential matches identified

  • How false positives were resolved

  • Reviewer’s name

  • Approval or escalation decision

  • Evidence of ongoing rescreening

The UAE’s targeted financial sanctions guidance requires relevant parties to be screened against the UN Consolidated List and UAE Local Terrorist List. Where a potential or confirmed match arises, the company must follow the applicable freezing and reporting procedures without delay. Review the official targeted financial sanctions guidance.

A screenshot stating “no match” without identifying the searched person, date and database may not provide sufficient evidence.


8. Review Source of Funds and Payment Methods

The brokerage should understand how the property is being financed and whether the payment method is consistent with the customer’s profile.

Evidence may include:

  • Bank statements

  • Salary certificates

  • Business financial statements

  • Sale agreements for other assets

  • Loan or mortgage approvals

  • Inheritance documents

  • Dividend records

  • Investment statements

  • Company resolutions

  • Evidence of accumulated savings

The brokerage should investigate warning signs such as:

  • Payments made by unrelated third parties

  • Large cash payments

  • Funds arriving from multiple accounts

  • Sudden changes in the buyer or seller

  • Complex corporate ownership without a commercial explanation

  • Transactions inconsistent with the customer’s known income

  • Overpayment followed by a refund request

  • Rapid resale without a clear economic reason

  • Customer resistance to providing UBO or source-of-funds information

  • Virtual-asset payments with unclear origin

The objective is not simply to collect documents. The MLRO must assess whether those documents provide a reasonable and consistent explanation.


9. Confirm Whether a Real Estate Activity Report Is Required

A Real Estate Activity Report, or REAR, may be required for certain freehold property purchase and sale transactions.

The Ministry’s real estate circular identifies the following reporting situations:

  • A single or multiple cash payment of AED 55,000 or more

  • Payment of all or part of the property value using virtual assets

  • Conversion of virtual assets into cash used for all or part of the property transaction

The brokerage must retain the required identification and transaction documents and submit the REAR through goAML. A REAR is a threshold or activity-based report; it does not replace an STR or SAR when the transaction is suspicious. Review the Ministry’s real estate reporting announcement.


10. Test the Suspicious-Activity Reporting Process

Employees should know how to escalate concerns internally without informing the customer.

The internal process should establish:

  1. How employees identify a warning sign.

  2. How they submit an internal report to the MLRO.

  3. How the MLRO investigates the matter.

  4. How the decision to report or not report is documented.

  5. How an STR or SAR is submitted through goAML.

  6. How confidentiality is protected.

  7. How the customer relationship is monitored afterwards.

The MLRO should retain appropriate decision records, including cases where an internal concern was reviewed but a goAML report was not submitted.

There is no minimum transaction value that must be reached before suspicious activity can be reported.


11. Organise the AML Inspection File

A practical inspection file should contain:

Inspection area

Evidence to prepare

Governance

Management approvals, MLRO appointment and reporting structure

Risk assessment

Current business-risk assessment and review history

Policies

Approved AML/CFT/CPF policies and operating procedures

goAML

Registration, active access and submitted-report records

Customer files

KYC, UBO, customer-risk ratings and approvals

Screening

Sanctions, PEP and adverse-media search evidence

Transactions

Contracts, payment records and monitoring notes

Reporting

Internal reports, STR/SAR decisions and REAR submissions

Training

Materials, attendance records and employee assessments

Record keeping

Retention procedure and accessible customer files

Oversight

Management reports, compliance reviews and remediation tracker

Relevant AML and transaction records should generally be retained for at least five years and remain retrievable when requested by a competent authority.


12. Conduct a Mock Inspection

Before responding to an inspector, conduct a structured compliance health check.

Select several customer files covering different risk levels and ask:

  • Can we identify the customer and beneficial owner?

  • Is the risk rating supported?

  • Was screening completed at the correct time?

  • Is the payment method understood?

  • Is source-of-funds evidence sufficient?

  • Was Enhanced Due Diligence performed where necessary?

  • Were relevant goAML reports submitted?

  • Can the MLRO explain the decision?

  • Are all records accessible?

  • Was management informed of significant risks?

Record every weakness in a remediation tracker showing the problem, responsible person, required action, deadline and completion evidence.

Documents should never be backdated or fabricated. If a historical gap cannot be corrected, record it honestly and implement a properly approved remediation plan.


How Ahmad Al Araidi Auditing Can Help

Ahmad Al Araidi Auditing of Accounts assists UAE real estate brokerages in preparing for AML inspections and strengthening their compliance systems.

Our support may include:

  • AML compliance gap assessment

  • Business-wide risk assessment

  • AML/CFT/CPF policies and procedures

  • Customer and corporate KYC forms

  • UBO verification procedures

  • Customer risk-classification methodology

  • Sanctions and PEP screening procedures

  • Enhanced Due Diligence checklists

  • Source-of-funds and source-of-wealth reviews

  • goAML reporting procedures

  • REAR, STR, SAR, FFR and PNMR guidance

  • Employee and management training

  • Inspection-file preparation

  • Sample customer-file testing

  • Remediation plans and compliance trackers

  • Ongoing AML compliance support


Frequently Asked Questions


Is goAML registration enough for an inspection?

No. Registration provides access to the reporting platform. The brokerage must also maintain risk assessments, policies, customer files, screening evidence, monitoring procedures, training records and reporting controls.


Does every property customer require Enhanced Due Diligence?

Not automatically. The level of due diligence should reflect the assessed risk. Higher-risk relationships require additional investigation, evidence, approval and monitoring.


Should both the buyer and seller be checked?

The brokerage should identify and assess the parties relevant to its role in the transaction, including customers, beneficial owners, representatives and other parties required under the applicable procedures.


What if a customer refuses to provide UBO or source-of-funds information?

The brokerage should not proceed merely because the transaction is commercially valuable. The matter should be escalated to the MLRO, and the need for a suspicious-activity report should be assessed without tipping off the customer.


Can an external consultant take responsibility for AML compliance?

A consultant can support the company, but the brokerage and its management remain responsible for implementing and maintaining an effective compliance system.


Is Your Real Estate Brokerage Ready for an AML Inspection?

An inspection should not be the first time the company tests its AML controls.

A professional pre-inspection review can identify missing documents, outdated policies, weak customer files and unreported transactions before they become regulatory findings.

Contact Ahmad Al Araidi Auditing of Accounts for an AML inspection-readiness assessment.

Website: auditors.ae

Phone: +971 56 626 6391

Recommended CTA button: Check My AML Inspection Readiness

This article provides general information and does not constitute legal advice. AML requirements and reporting decisions depend on the brokerage’s activities, customers, jurisdiction, supervisory authority and the legislation and official guidance applicable at the relevant time.

Contact Us

Service Inquiry

Fill in the form below to let us know which service you're interested in

and how we can help - we'll get back to you as soon as possible.

Which service are you interested in?

 Address. Deira, Port Saeed, Office 405, Dubai, UAE

© 2026 by Al Araidi Auditing. Powered and secured by Wix

bottom of page