Proud of UAE  [email protected]       [email protected]        +97142500251 97142500251+       +971507869887 971507869887+      WhatsApp

The Role of Audit Firms in UAE Anti-Money Laundering Compliance

Understanding Anti-Money Laundering and the Role of Audit Firms in the UAE

Anti-money laundering (AML) compliance is not a document filed once and forgotten. It is a program that has to be tested, and testing that program is where an audit firm’s role becomes essential. Under Federal Decree-Law No. 10 of 2025 on Combating Money Laundering, the Financing of Terrorism, and the Financing of Illegal Organisations (effective 14 October 2025), and its implementing regulation, Cabinet Resolution No. 134 of 2025 (effective 14 December 2025), UAE businesses that fall within the AML/CFT framework must maintain risk-based policies, procedures, and internal controls, and must be able to show that those controls actually work. An independent review, whether performed by an internal audit function or an external audit firm, is how a business demonstrates that its AML program is more than paperwork.

This requirement exists because a written policy and a functioning control are not the same thing. UAE financial institutions and designated non-financial businesses and professions (DNFBPs) have, in past years, maintained detailed AML policies and trained compliance staff while still missing red flags, because the function reviewing those controls was not independent enough to challenge management or escalate weaknesses. An audit firm brought in specifically to test the AML program, separate from the team that built it, closes that gap.

How Money Laundering Works: Placement, Layering, and Integration

Money laundering is the process of disguising the proceeds of criminal activity, such as fraud, drug trafficking, corruption, or theft, so the funds appear to come from a legitimate source. It is a serious financial crime under UAE law, and a business that knowingly or negligently facilitates it, even without direct involvement in the underlying crime, can face liability of its own.

The process typically runs through three stages. Placement is the point at which illicit funds first enter the formal financial system, often through a bank deposit, a cash-intensive business, or a real estate transaction. Layering follows, using a series of transactions, transfers, or conversions into other assets, designed specifically to break the audit trail and make the original source of funds difficult to trace. Integration is the final stage, where the now-laundered funds are reintroduced into the economy as apparently legitimate income, investment returns, or business proceeds.

Shell companies are a common tool at the layering stage. A shell company holds no real operations, produces no goods, and delivers no services; it exists only to move money through a legal-looking corporate structure and to obscure who ultimately controls the funds. Identifying shell-company patterns, along with other structuring behavior, is one of the core tasks of an AML audit.

Need Expert Advice?

Contact the team at Farahat & Co. for professional support and expert insights for businesses operating in the UAE.

What an Independent AML Audit in the UAE Examines

An independent AML audit is a distinct engagement from a financial statement audit. It does not test whether the numbers in the accounts are accurate; it tests whether the business has an effective AML/CFT program and is actually following it. A typical AML audit in the UAE covers the following areas.

  • The AML/CFT compliance program document and the underlying business risk assessment
  • Customer Due Diligence (CDD) and Enhanced Due Diligence (EDD) procedures, including how higher-risk customers are identified
  • Verification of Ultimate Beneficial Ownership (UBO) records against the business’s actual customer files
  • Sanctions and watch-list screening against the UN Consolidated List and the UAE Local Terrorist List
  • The quality and timeliness of Suspicious Transaction Reports (STRs) filed with the UAE Financial Intelligence Unit (FIU) through the goAML platform
  • Staff AML training records and record-keeping practices for customer files and transaction history

Also check: AML Compliance Services in UAE

Current UAE AML Legal Framework Governing Audit Firms

Audit firms sit on both sides of UAE AML regulation. They test other businesses’ AML controls as part of an audit engagement, and they are themselves classified as DNFBPs under UAE law, which means they carry their own compliance obligations. The table below sets out the current instruments that govern this area.

InstrumentEffective DateWhat It Covers
Federal Decree-Law No. 10 of 202514 October 2025Primary AML/CFT law; replaced Federal Decree-Law No. 20 of 2018
Cabinet Resolution No. 134 of 202514 December 2025Implementing regulation; sets out CDD, record-keeping, reporting, and internal control/audit requirements; replaced Cabinet Decision No. 10 of 2019

Because audit firms are themselves DNFBPs, they must register on the goAML platform, appoint their own Money Laundering Reporting Officer (MLRO), apply CDD to their own clients, and file an STR if they encounter suspicious activity while performing any engagement, including a routine financial statement audit. This dual role, tester and tested, is part of what makes an audit firm’s independence so important.

Who Can Conduct an AML Audit in the UAE

An AML audit can be performed internally, by staff who were not involved in building or running the AML program being tested, or externally, by an independent audit firm. The MLRO or a member of the compliance team who sits outside day-to-day AML operations can carry out the review for larger organizations with sufficient staff. Smaller businesses, which often lack the headcount or in-house expertise to run an independent internal review, typically engage a qualified external audit firm instead.

Which authority supervises the business also matters. The Central Bank of the UAE (CBUAE) supervises AML compliance for banks, insurers, and other financial institutions. The Ministry of Economy supervises DNFBPs, a category that includes auditors, accountants, real estate agents and brokers, dealers in precious metals and stones, and company service providers. The Virtual Assets Regulatory Authority (VARA) supervises virtual asset service providers, which must complete quarterly AML/CFT risk assessments. An audit firm needs to know which regulator applies to a client before scoping the engagement, since reporting lines and expectations differ by sector.

Also check: Internal Audit Services

How Often a UAE Business Should Conduct an AML Audit

The MLRO is required to submit reports on the AML program’s effectiveness on a semi-annual basis, to senior management and to the relevant supervisory authority, CBUAE for financial institutions or the Ministry of Economy for DNFBPs. That reporting obligation is separate from the independent AML audit itself, which most UAE businesses schedule annually, with higher-risk entities such as those handling large cash volumes, cross-border transfers, or virtual assets reviewing more frequently.

A useful benchmark is a 12-to-18-month audit cycle, similar to standard internal audit planning, adjusted upward in frequency wherever the business’s risk assessment flags elevated exposure. Businesses that skip AML audits or run them irregularly are the ones most often flagged during a regulatory inspection for having a policy on paper that was never actually tested.

AML Internal Audit vs. Financial Statement Audit

These two audit types are frequently confused, but they test different things. A financial statement audit, performed by a licensed audit firm, examines a company’s financial statements on a sampling basis to confirm they are free of material misstatement and fairly presented. An AML audit confirms that a company has an effective AML/CFT program and is carrying out what that program says it does. A business can pass a financial statement audit cleanly while still having weak AML controls, which is exactly why the two engagements are kept separate.

Three areas tend to draw the closest regulatory scrutiny when an AML audit function itself is reviewed.

Planning and Scoping

Regulators look closely at the audit plan and scope document, particularly where a business has skipped or delayed scheduled reviews. UAE businesses are generally expected to follow at least a 12-to-18-month audit cycle, with the scope adjusted to reflect the business’s own risk assessment rather than a generic checklist.

Reporting and Execution

Incomplete testing is one of the most common weaknesses regulators cite. To meet the standard expected under the current framework, an AML audit needs to include sufficient transaction sampling, documented testing steps, and re-testing where initial results raise questions, rather than a high-level summary with no supporting workpapers.

Validation and Follow-up

Finding a weakness is only half the job. Regulators expect audit findings to be validated and followed through to a permanent fix, not a short-term patch that leaves the same control gap open at the next review. An audit report that lists the same finding two cycles in a row is a signal that follow-up was not enforced.

Also check: Forensic Audit Services | Certified Fraud Examiner

Red Flags a UAE Audit Firm Screens For During an AML Review

Certain patterns recur often enough in AML audits that they function as a starting checklist. None of these automatically prove wrongdoing, but each one is a trigger for closer review.

Red FlagWhy It Matters
Shell company with no real operationsNo goods produced, no services delivered, revenue with no clear business source
Complex or opaque ownership structureLayers of holding entities can be used to obscure the true UBO
Structuring transactions below reporting thresholdsSplitting a transaction into smaller amounts is a classic method to avoid triggering a report
Unusual third-party paymentsFunds moving to or from parties unrelated to the declared business relationship
Cash volume inconsistent with the business typeCash intensity that does not match the stated business model warrants explanation
Transactions linked to high-risk jurisdictionsCounterparties or fund flows tied to jurisdictions with weak AML enforcement

An audit firm that finds one or more of these patterns is expected to escalate the finding to the MLRO and, where the threshold for suspicion is met, ensure an STR is filed with the UAE FIU through goAML rather than resolving the matter internally and moving on.

Penalties for AML Non-Compliance in the UAE

Federal Decree-Law No. 10 of 2025 extended personal liability for MLROs and compliance officers who fail to meet their reporting and control obligations, alongside liability at the business level. A business found to have an inadequate or non-functioning AML program can face administrative penalties ranging from formal warnings to significant fines, and in more serious or repeated cases, suspension or revocation of its professional license by the relevant supervisory authority, whether CBUAE, the Ministry of Economy, or VARA depending on sector. Where an audit or investigation uncovers active facilitation of money laundering rather than a control weakness, the matter can be referred for criminal prosecution under the same law.

Because the consequences apply at both the business and the individual level, an AML audit that is treated as a compliance formality rather than a genuine independent test leaves both the company and its MLRO exposed. Farahat & Co. is an audit and advisory firm, not a law firm, and does not provide legal representation; a business facing an active AML investigation should seek independent legal counsel alongside its audit and compliance advisors.

Frequently Asked Questions (FAQs)

What is an independent AML audit, and how is it different from a financial statement audit?


An independent AML audit tests whether a business has an effective anti-money laundering program and is actually following it, covering areas such as customer due diligence, UBO verification, sanctions screening, and STR filing. A financial statement audit tests whether the company’s financial statements are free of material misstatement. The two engagements serve different purposes and are performed separately, even when carried out by the same audit firm.

Which UAE businesses need their AML program tested by an audit function?


Any business classified as a financial institution or a DNFBP under Federal Decree-Law No. 10 of 2025 needs an AML/CFT compliance program tested through an internal or independent audit. This includes banks and other financial institutions supervised by CBUAE, and DNFBPs such as auditors, accountants, real estate agents and brokers, dealers in precious metals and stones, and company service providers, supervised by the Ministry of Economy.

How often should a UAE business conduct an AML audit?


Most UAE businesses schedule an independent AML audit annually, following a 12-to-18-month cycle similar to standard internal audit planning, with higher-risk businesses reviewing more frequently. This is separate from the MLRO’s semi-annual reporting obligation to senior management and the relevant supervisory authority.

What happens if a UAE business fails an AML compliance review?


A business with an inadequate or non-functioning AML program can face administrative penalties ranging from formal warnings to significant fines, and in serious or repeated cases, suspension or revocation of its professional license. Federal Decree-Law No. 10 of 2025 also extends personal liability to MLROs and compliance officers who fail to meet their obligations, and cases involving active facilitation of money laundering can be referred for criminal prosecution.

Who is qualified to carry out an AML audit for a UAE business?


An AML audit can be performed internally by staff who were not involved in building or running the AML program under review, typically the MLRO or a member of the compliance team, provided the business has sufficient headcount for genuine independence. Smaller businesses without that internal capacity generally engage a qualified external audit firm instead.

What should a UAE business do to prepare for an AML audit?


A business should keep its AML/CFT compliance program, risk assessment, and CDD/EDD files current rather than updating them only before a review, retain complete customer and transaction records, document staff AML training, and confirm which supervisory authority, CBUAE, the Ministry of Economy, or VARA, applies to its sector before the audit is scoped. Businesses that treat the AML program as a living control rather than a static document consistently perform better under review.

Need Expert Advice?

Contact the team at Farahat & Co. for professional support and expert insights for businesses operating in the UAE.

How Farahat & Co. Can Help

Farahat & Co. provides independent AML audits, internal audit services, and AML compliance program reviews that help UAE businesses meet their obligations under Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025.

Contact Farahat & Co. today to discuss your AML audit and compliance requirements.

×

Hold On!

Business decisions are easier with the right guidance.