Never Completed an AML Risk Assessment? What UAE Businesses Must Do

Our Company Has Never Completed an AML Risk Assessment—What Should We Do?
Many UAE businesses register on goAML, appoint a Compliance Officer and collect identification documents from customers. They may believe these steps are enough to demonstrate Anti-Money Laundering compliance.
Then the company receives an inspection notice or compliance questionnaire asking for its Business-Wide Risk Assessment or Institutional Risk Assessment.
Management discovers that the company has never prepared one.
This is a significant compliance gap, particularly for businesses classified as Designated Non-Financial Businesses and Professions. However, the correct response is not to create a backdated document merely to complete the file.
The company should conduct a genuine current assessment, identify how the gap affected its customer due diligence and monitoring, and implement a documented remediation plan.
Which Businesses Need an AML Risk Assessment?
The obligation applies to regulated entities, including Financial Institutions, Virtual Asset Service Providers and Designated Non-Financial Businesses and Professions, subject to their respective supervisory frameworks.
DNFBP sectors commonly include:
Real estate brokers and agents
Dealers in precious metals and stones
Independent accountants and auditors
Corporate and trust service providers
Legal professionals when conducting specified transactions
Other businesses brought within the regulated categories by applicable legislation
The Ministry of Economy and Tourism supervises several DNFBP sectors operating in the UAE, including those established in commercial Free Zones. Review the Ministry’s AML/CFT information and guidance.
If your company is unsure whether it is a DNFBP, it should review its actual activities—not only the general wording on its trade licence—and confirm its correct supervisory authority.
What Is a Business-Wide AML Risk Assessment?
A Business-Wide Risk Assessment, also called an Institutional Risk Assessment, evaluates the company’s overall exposure to:
Money laundering
Terrorism financing
Proliferation financing
It should answer questions such as:
What types of customers does the company serve?
In which countries are customers, owners and transactions connected?
Which products and services are most vulnerable to misuse?
Are transactions cash-intensive, complex or unusually large?
Does the company work with intermediaries or nominees?
Are customers onboarded remotely?
How effective are the company’s AML controls?
What risks remain after those controls are applied?
Federal Decree-Law No. 10 of 2025 requires regulated entities to identify, understand, manage, assess, document and continuously update financial-crime risks within their business scope. Review the current UAE AML law.
The assessment should be proportionate to the nature and size of the business. A small real estate brokerage and a large international precious-metals dealer do not require identical documents, but both must demonstrate that their assessment is appropriate to their actual exposure.
Business-Wide Risk Assessment Versus Customer Risk Assessment
These two assessments are connected but serve different purposes.
Business-Wide Risk Assessment
The Business-Wide Risk Assessment examines the company as a whole. It considers the company’s customer base, geographic exposure, products, services, transactions, delivery channels and control environment.
Customer Risk Assessment
The Customer Risk Assessment evaluates the risk presented by an individual customer or corporate client.
It considers factors such as:
Customer type
Business activity
Ownership structure
Ultimate beneficial owners
Politically Exposed Person status
Country connections
Source of funds
Expected transactions
Delivery channel
Adverse information
Sanctions exposure
The customer’s risk rating determines the appropriate level of due diligence and monitoring. Higher-risk customers generally require Enhanced Due Diligence.
The Ministry’s Customer Risk Assessment guidance confirms that customer and institutional assessments are separate but essential parts of the overall AML framework. Read the DNFBP Customer Risk Assessment guide.
A company cannot replace its Business-Wide Risk Assessment by simply marking each customer as “low,” “medium” or “high.”
What Risks Should the Assessment Cover?
A proper assessment normally examines at least the following categories.
Risk category | Matters to assess |
Customer risk | Customer type, ownership structure, PEP status, cash intensity, business activity and use of intermediaries |
Geographic risk | Customer nationality, residence, business locations, source of funds and connections to higher-risk or sanctioned jurisdictions |
Product and service risk | Services that may conceal ownership, transfer value, hold assets or facilitate complex transactions |
Transaction risk | Size, frequency, complexity, cash use, third-party payments and transactions without a clear economic purpose |
Delivery-channel risk | Face-to-face or remote onboarding, agents, introducers, digital communications and reliance on third parties |
Proliferation-financing risk | Exposure to dual-use goods, complex trade structures, sanctioned parties, shipping routes and controlled products |
Operational risk | Staff experience, record quality, system limitations, compliance resources and effectiveness of internal controls |
The company should also consider the UAE National Risk Assessment, relevant Sectoral Risk Assessment, supervisory guidance, current typologies and its own experience with customers and transactions.
Inherent Risk, Controls and Residual Risk
An effective assessment should distinguish between three concepts.
Inherent risk
This is the risk that exists before applying controls.
For example, a real estate brokerage handling high-value property transactions for overseas corporate buyers may have an elevated inherent risk because of transaction size, cross-border ownership and the possibility of complex legal structures.
Control effectiveness
The company then evaluates its mitigating controls, such as:
Customer identification
UBO verification
Sanctions and PEP screening
Source-of-funds checks
Customer risk scoring
Enhanced Due Diligence
Transaction monitoring
Compliance approval
Staff training
Independent testing
goAML reporting procedures
A policy that exists only on paper should not automatically be treated as an effective control. The company should have evidence showing that the control operates in practice.
Residual risk
Residual risk is the remaining exposure after applying the controls.
If the residual risk remains high, the company should introduce additional controls, allocate more resources, restrict certain activities or reconsider whether the relationship falls within its risk appetite.
Never Completed an AML Risk Assessment? What UAE Businesses Must Do
1. Do not backdate the document
The assessment should show its genuine preparation and approval date.
A backdated document may create an additional integrity concern because emails, file metadata, staff records and previous compliance reports may show that it did not exist at the stated time.
Instead, document that the gap was identified and that management approved a remediation programme.
2. Define the scope of the business
Prepare an accurate profile covering:
Licensed and actual activities
Branches and operating locations
Customer types
Products and services
Transaction volumes and values
Cash exposure
Countries involved
Delivery channels
Introducers and intermediaries
Outsourced compliance activities
Higher-risk relationships
The assessment should reflect actual operations rather than generic language copied from another business.
3. Review the existing customer base
Because the company operated without a Business-Wide Risk Assessment, its existing customer ratings may not reflect the correct risks.
The Compliance Officer should review active customers and determine whether:
KYC documents are complete
UBOs were properly identified
Sanctions and PEP screening was performed
Risk ratings remain reasonable
Source of funds or wealth is required
Enhanced Due Diligence should be applied
Transaction activity matches the expected profile
Suspicious conduct requires internal escalation
Higher-risk and incomplete files should be prioritised.
4. Develop a documented methodology
The methodology should explain:
Risk categories used
Risk indicators
Scoring scale
Weight assigned to each factor
Definitions of low, medium and high risk
How control effectiveness is evaluated
How residual risk is calculated
Who performs and reviews the assessment
Escalation and approval requirements
Review frequency
Events that trigger an immediate update
A final score without an explainable methodology may be difficult to defend during an inspection.
5. Evaluate the existing controls honestly
The company should assess whether each control is:
Properly designed
Documented
Implemented
Used consistently
Supported by evidence
Reviewed for effectiveness
For example, if the policy requires daily sanctions screening but the company has no screening records, that control should not be rated as fully effective.
6. Prepare a remediation plan
Identified weaknesses should be recorded in a formal action plan showing:
The compliance gap
Risk created by the gap
Corrective action
Responsible person
Required resources
Target completion date
Current status
Evidence of completion
Examples may include updating KYC files, introducing automated screening, revising customer-risk scoring, training staff or implementing transaction-monitoring procedures.
7. Obtain senior-management approval
Senior management should review and approve:
The completed Business-Wide Risk Assessment
Risk methodology
Residual-risk conclusions
Risk appetite
Remediation plan
Updated policies and controls
The approval should be documented through signed minutes, a resolution or another formal management record.
How Often Should the Assessment Be Updated?
The Ministry’s practical guidance states that DNFBPs should review and update risk assessments at least annually.
An immediate update may also be required when:
The company launches a new product or service
A new branch or market is opened
Customer types materially change
Remote onboarding is introduced
Transaction volumes increase significantly
New sanctions or high-risk-country measures are issued
National or sectoral risk assessments change
New criminal typologies emerge
An inspection identifies weaknesses
The company changes its ownership or operating structure
The annual review should not simply change the date on the previous document. Management should reconsider the underlying data, emerging risks, control effectiveness and residual-risk conclusions.
Documents an AML Inspector May Request
During an inspection, the supervisory authority may request:
Current and previous Business-Wide Risk Assessments
Risk-assessment methodology and scoring model
Senior-management approvals
Customer Risk Assessments
KYC and UBO records
PEP and sanctions-screening evidence
Enhanced Due Diligence files
Source-of-funds and source-of-wealth records
Transaction-monitoring records
AML policies and procedures
Compliance Officer appointment documents
Training materials and attendance records
Internal compliance reports
Independent review or audit reports
goAML registration evidence
Copies of regulatory reports where permitted
Remediation plans and status updates
Evidence that national and sectoral risks were considered
The company should be able to demonstrate both what it decided and how the decision was implemented.
Is the Risk Assessment the Same as a goAML Report?
No.
The Business-Wide Risk Assessment is a documented internal assessment of the company’s overall financial-crime exposure.
goAML is used for regulatory reporting, including suspicious transaction or activity reports and other applicable report types.
Preparing a risk assessment does not replace the obligation to report suspicious activity. Similarly, being registered on goAML does not prove that the company has completed its risk assessment.
The business must also comply with any separate risk-assessment return, questionnaire or submission required by its supervisory authority.
What Are the Risks of Continuing Without an Assessment?
A company that cannot produce a current and supportable assessment may be unable to demonstrate that its AML controls are risk-based.
This can affect:
Customer-risk classifications
Enhanced Due Diligence decisions
Transaction monitoring
Sanctions controls
Staff training
Suspicious-activity escalation
Management oversight
Resource allocation
The Ministry of Economy and Tourism has confirmed that its inspection framework examines areas including due diligence, risk-assessment methodologies and suspicious-transaction reporting. Identified violations may lead to corrective measures and administrative penalties. Review the Ministry’s DNFBP inspection update.
How Ahmad Al Araidi Auditing Can Help
Ahmad Al Araidi Auditing of Accounts assists UAE DNFBPs in establishing and strengthening their AML/CFT/CPF compliance frameworks.
Our support may include:
Confirming the company’s DNFBP obligations
Preparing the Business-Wide Risk Assessment
Designing the risk-scoring methodology
Reviewing the UAE National and sectoral risks
Preparing customer-risk assessment tools
Reviewing existing customer files
Identifying high-risk and incomplete relationships
Updating AML policies and procedures
Developing a remediation action plan
Preparing KYC, CDD and EDD forms
Reviewing sanctions and PEP screening procedures
Training employees and senior management
Organising an inspection-ready AML compliance file
Conducting an independent AML compliance review
Frequently Asked Questions
Can we use a standard risk-assessment template?
A template may provide structure, but the final assessment must reflect the company’s actual customers, services, countries, transactions, controls and regulatory exposure.
Should a small company prepare a risk assessment?
Yes, if it falls within a regulated category. The assessment may be proportionate to the business’s nature and size, but small size does not automatically remove the obligation.
Can the Compliance Officer approve the assessment alone?
The Compliance Officer may prepare or coordinate it, but senior management should understand, review and approve the company’s risk exposure and remediation measures.
Should we review old customer files?
Yes. If earlier risk ratings were created without an appropriate business-wide methodology, active customers should be reassessed using the corrected approach.
Do we need to report the past compliance gap?
That depends on the company’s supervisory requirements and circumstances. The company should maintain a transparent remediation record and obtain professional advice if an inspection, information request or formal breach-reporting obligation applies.
Is completing the assessment enough to become compliant?
No. Its findings must be reflected in customer due diligence, monitoring, sanctions controls, training, policies and management oversight.
Has Your Company Never Completed an AML Risk Assessment?
Do not wait for a supervisory inspection to reveal the gap.
Prepare a current, evidence-based assessment, review existing customers and create a documented remediation plan that management can monitor.
Never Completed an AML Risk Assessment? What UAE Businesses Must Do
If you never Completed an AML Risk Assessment? Contact Ahmad Al Araidi Auditing of Accounts for an AML risk-assessment and compliance-readiness review.
Website: auditors.ae
Email: info@auditors.ae
Phone: +971 56 626 6391
This article provides general information and does not constitute legal or regulatory advice. AML obligations depend on the company’s activities, supervisory authority, customer profile and specific circumstances.



