top of page
Logo
  • Whatsapp
  • Facebook
  • Instagram

Never Completed an AML Risk Assessment? What UAE Businesses Must Do

Aug 29
8 min read
Never Completed an AML Risk Assessment? What UAE Businesses Must Do

Our Company Has Never Completed an AML Risk Assessment—What Should We Do?

Many UAE businesses register on goAML, appoint a Compliance Officer and collect identification documents from customers. They may believe these steps are enough to demonstrate Anti-Money Laundering compliance.

Then the company receives an inspection notice or compliance questionnaire asking for its Business-Wide Risk Assessment or Institutional Risk Assessment.

Management discovers that the company has never prepared one.

This is a significant compliance gap, particularly for businesses classified as Designated Non-Financial Businesses and Professions. However, the correct response is not to create a backdated document merely to complete the file.

The company should conduct a genuine current assessment, identify how the gap affected its customer due diligence and monitoring, and implement a documented remediation plan.


Which Businesses Need an AML Risk Assessment?

The obligation applies to regulated entities, including Financial Institutions, Virtual Asset Service Providers and Designated Non-Financial Businesses and Professions, subject to their respective supervisory frameworks.

DNFBP sectors commonly include:

  • Real estate brokers and agents

  • Dealers in precious metals and stones

  • Independent accountants and auditors

  • Corporate and trust service providers

  • Legal professionals when conducting specified transactions

  • Other businesses brought within the regulated categories by applicable legislation

The Ministry of Economy and Tourism supervises several DNFBP sectors operating in the UAE, including those established in commercial Free Zones. Review the Ministry’s AML/CFT information and guidance.

If your company is unsure whether it is a DNFBP, it should review its actual activities—not only the general wording on its trade licence—and confirm its correct supervisory authority.


What Is a Business-Wide AML Risk Assessment?

A Business-Wide Risk Assessment, also called an Institutional Risk Assessment, evaluates the company’s overall exposure to:

  • Money laundering

  • Terrorism financing

  • Proliferation financing

It should answer questions such as:

  • What types of customers does the company serve?

  • In which countries are customers, owners and transactions connected?

  • Which products and services are most vulnerable to misuse?

  • Are transactions cash-intensive, complex or unusually large?

  • Does the company work with intermediaries or nominees?

  • Are customers onboarded remotely?

  • How effective are the company’s AML controls?

  • What risks remain after those controls are applied?

Federal Decree-Law No. 10 of 2025 requires regulated entities to identify, understand, manage, assess, document and continuously update financial-crime risks within their business scope. Review the current UAE AML law.

The assessment should be proportionate to the nature and size of the business. A small real estate brokerage and a large international precious-metals dealer do not require identical documents, but both must demonstrate that their assessment is appropriate to their actual exposure.


Business-Wide Risk Assessment Versus Customer Risk Assessment

These two assessments are connected but serve different purposes.

Business-Wide Risk Assessment

The Business-Wide Risk Assessment examines the company as a whole. It considers the company’s customer base, geographic exposure, products, services, transactions, delivery channels and control environment.

Customer Risk Assessment

The Customer Risk Assessment evaluates the risk presented by an individual customer or corporate client.

It considers factors such as:

  • Customer type

  • Business activity

  • Ownership structure

  • Ultimate beneficial owners

  • Politically Exposed Person status

  • Country connections

  • Source of funds

  • Expected transactions

  • Delivery channel

  • Adverse information

  • Sanctions exposure

The customer’s risk rating determines the appropriate level of due diligence and monitoring. Higher-risk customers generally require Enhanced Due Diligence.

The Ministry’s Customer Risk Assessment guidance confirms that customer and institutional assessments are separate but essential parts of the overall AML framework. Read the DNFBP Customer Risk Assessment guide.

A company cannot replace its Business-Wide Risk Assessment by simply marking each customer as “low,” “medium” or “high.”


What Risks Should the Assessment Cover?

A proper assessment normally examines at least the following categories.

Risk category

Matters to assess

Customer risk

Customer type, ownership structure, PEP status, cash intensity, business activity and use of intermediaries

Geographic risk

Customer nationality, residence, business locations, source of funds and connections to higher-risk or sanctioned jurisdictions

Product and service risk

Services that may conceal ownership, transfer value, hold assets or facilitate complex transactions

Transaction risk

Size, frequency, complexity, cash use, third-party payments and transactions without a clear economic purpose

Delivery-channel risk

Face-to-face or remote onboarding, agents, introducers, digital communications and reliance on third parties

Proliferation-financing risk

Exposure to dual-use goods, complex trade structures, sanctioned parties, shipping routes and controlled products

Operational risk

Staff experience, record quality, system limitations, compliance resources and effectiveness of internal controls

The company should also consider the UAE National Risk Assessment, relevant Sectoral Risk Assessment, supervisory guidance, current typologies and its own experience with customers and transactions.


Inherent Risk, Controls and Residual Risk

An effective assessment should distinguish between three concepts.

Inherent risk

This is the risk that exists before applying controls.

For example, a real estate brokerage handling high-value property transactions for overseas corporate buyers may have an elevated inherent risk because of transaction size, cross-border ownership and the possibility of complex legal structures.

Control effectiveness

The company then evaluates its mitigating controls, such as:

  • Customer identification

  • UBO verification

  • Sanctions and PEP screening

  • Source-of-funds checks

  • Customer risk scoring

  • Enhanced Due Diligence

  • Transaction monitoring

  • Compliance approval

  • Staff training

  • Independent testing

  • goAML reporting procedures

A policy that exists only on paper should not automatically be treated as an effective control. The company should have evidence showing that the control operates in practice.

Residual risk

Residual risk is the remaining exposure after applying the controls.

If the residual risk remains high, the company should introduce additional controls, allocate more resources, restrict certain activities or reconsider whether the relationship falls within its risk appetite.


Never Completed an AML Risk Assessment? What UAE Businesses Must Do

1. Do not backdate the document

The assessment should show its genuine preparation and approval date.

A backdated document may create an additional integrity concern because emails, file metadata, staff records and previous compliance reports may show that it did not exist at the stated time.

Instead, document that the gap was identified and that management approved a remediation programme.


2. Define the scope of the business

Prepare an accurate profile covering:

  • Licensed and actual activities

  • Branches and operating locations

  • Customer types

  • Products and services

  • Transaction volumes and values

  • Cash exposure

  • Countries involved

  • Delivery channels

  • Introducers and intermediaries

  • Outsourced compliance activities

  • Higher-risk relationships

The assessment should reflect actual operations rather than generic language copied from another business.


3. Review the existing customer base

Because the company operated without a Business-Wide Risk Assessment, its existing customer ratings may not reflect the correct risks.

The Compliance Officer should review active customers and determine whether:

  • KYC documents are complete

  • UBOs were properly identified

  • Sanctions and PEP screening was performed

  • Risk ratings remain reasonable

  • Source of funds or wealth is required

  • Enhanced Due Diligence should be applied

  • Transaction activity matches the expected profile

  • Suspicious conduct requires internal escalation

Higher-risk and incomplete files should be prioritised.


4. Develop a documented methodology

The methodology should explain:

  • Risk categories used

  • Risk indicators

  • Scoring scale

  • Weight assigned to each factor

  • Definitions of low, medium and high risk

  • How control effectiveness is evaluated

  • How residual risk is calculated

  • Who performs and reviews the assessment

  • Escalation and approval requirements

  • Review frequency

  • Events that trigger an immediate update

A final score without an explainable methodology may be difficult to defend during an inspection.


5. Evaluate the existing controls honestly

The company should assess whether each control is:

  • Properly designed

  • Documented

  • Implemented

  • Used consistently

  • Supported by evidence

  • Reviewed for effectiveness

For example, if the policy requires daily sanctions screening but the company has no screening records, that control should not be rated as fully effective.


6. Prepare a remediation plan

Identified weaknesses should be recorded in a formal action plan showing:

  • The compliance gap

  • Risk created by the gap

  • Corrective action

  • Responsible person

  • Required resources

  • Target completion date

  • Current status

  • Evidence of completion

Examples may include updating KYC files, introducing automated screening, revising customer-risk scoring, training staff or implementing transaction-monitoring procedures.


7. Obtain senior-management approval

Senior management should review and approve:

  • The completed Business-Wide Risk Assessment

  • Risk methodology

  • Residual-risk conclusions

  • Risk appetite

  • Remediation plan

  • Updated policies and controls

The approval should be documented through signed minutes, a resolution or another formal management record.


How Often Should the Assessment Be Updated?

The Ministry’s practical guidance states that DNFBPs should review and update risk assessments at least annually.

An immediate update may also be required when:

  • The company launches a new product or service

  • A new branch or market is opened

  • Customer types materially change

  • Remote onboarding is introduced

  • Transaction volumes increase significantly

  • New sanctions or high-risk-country measures are issued

  • National or sectoral risk assessments change

  • New criminal typologies emerge

  • An inspection identifies weaknesses

  • The company changes its ownership or operating structure

The annual review should not simply change the date on the previous document. Management should reconsider the underlying data, emerging risks, control effectiveness and residual-risk conclusions.


Documents an AML Inspector May Request

During an inspection, the supervisory authority may request:

  • Current and previous Business-Wide Risk Assessments

  • Risk-assessment methodology and scoring model

  • Senior-management approvals

  • Customer Risk Assessments

  • KYC and UBO records

  • PEP and sanctions-screening evidence

  • Enhanced Due Diligence files

  • Source-of-funds and source-of-wealth records

  • Transaction-monitoring records

  • AML policies and procedures

  • Compliance Officer appointment documents

  • Training materials and attendance records

  • Internal compliance reports

  • Independent review or audit reports

  • goAML registration evidence

  • Copies of regulatory reports where permitted

  • Remediation plans and status updates

  • Evidence that national and sectoral risks were considered

The company should be able to demonstrate both what it decided and how the decision was implemented.


Is the Risk Assessment the Same as a goAML Report?

No.

The Business-Wide Risk Assessment is a documented internal assessment of the company’s overall financial-crime exposure.

goAML is used for regulatory reporting, including suspicious transaction or activity reports and other applicable report types.

Preparing a risk assessment does not replace the obligation to report suspicious activity. Similarly, being registered on goAML does not prove that the company has completed its risk assessment.

The business must also comply with any separate risk-assessment return, questionnaire or submission required by its supervisory authority.


What Are the Risks of Continuing Without an Assessment?

A company that cannot produce a current and supportable assessment may be unable to demonstrate that its AML controls are risk-based.

This can affect:

  • Customer-risk classifications

  • Enhanced Due Diligence decisions

  • Transaction monitoring

  • Sanctions controls

  • Staff training

  • Suspicious-activity escalation

  • Management oversight

  • Resource allocation

The Ministry of Economy and Tourism has confirmed that its inspection framework examines areas including due diligence, risk-assessment methodologies and suspicious-transaction reporting. Identified violations may lead to corrective measures and administrative penalties. Review the Ministry’s DNFBP inspection update.


How Ahmad Al Araidi Auditing Can Help

Ahmad Al Araidi Auditing of Accounts assists UAE DNFBPs in establishing and strengthening their AML/CFT/CPF compliance frameworks.

Our support may include:

  • Confirming the company’s DNFBP obligations

  • Preparing the Business-Wide Risk Assessment

  • Designing the risk-scoring methodology

  • Reviewing the UAE National and sectoral risks

  • Preparing customer-risk assessment tools

  • Reviewing existing customer files

  • Identifying high-risk and incomplete relationships

  • Updating AML policies and procedures

  • Developing a remediation action plan

  • Preparing KYC, CDD and EDD forms

  • Reviewing sanctions and PEP screening procedures

  • Training employees and senior management

  • Organising an inspection-ready AML compliance file

  • Conducting an independent AML compliance review


Frequently Asked Questions


Can we use a standard risk-assessment template?

A template may provide structure, but the final assessment must reflect the company’s actual customers, services, countries, transactions, controls and regulatory exposure.


Should a small company prepare a risk assessment?

Yes, if it falls within a regulated category. The assessment may be proportionate to the business’s nature and size, but small size does not automatically remove the obligation.


Can the Compliance Officer approve the assessment alone?

The Compliance Officer may prepare or coordinate it, but senior management should understand, review and approve the company’s risk exposure and remediation measures.


Should we review old customer files?

Yes. If earlier risk ratings were created without an appropriate business-wide methodology, active customers should be reassessed using the corrected approach.


Do we need to report the past compliance gap?

That depends on the company’s supervisory requirements and circumstances. The company should maintain a transparent remediation record and obtain professional advice if an inspection, information request or formal breach-reporting obligation applies.


Is completing the assessment enough to become compliant?

No. Its findings must be reflected in customer due diligence, monitoring, sanctions controls, training, policies and management oversight.


Has Your Company Never Completed an AML Risk Assessment?

Do not wait for a supervisory inspection to reveal the gap.

Prepare a current, evidence-based assessment, review existing customers and create a documented remediation plan that management can monitor.

Never Completed an AML Risk Assessment? What UAE Businesses Must Do

If you never Completed an AML Risk Assessment? Contact Ahmad Al Araidi Auditing of Accounts for an AML risk-assessment and compliance-readiness review.


Website: auditors.ae

Phone: +971 56 626 6391


This article provides general information and does not constitute legal or regulatory advice. AML obligations depend on the company’s activities, supervisory authority, customer profile and specific circumstances.

Contact Us

Service Inquiry

Fill in the form below to let us know which service you're interested in

and how we can help - we'll get back to you as soon as possible.

Which service are you interested in?

 Address. Deira, Port Saeed, Office 405, Dubai, UAE

© 2026 by Al Araidi Auditing. Powered and secured by Wix

bottom of page