goAML registration is the process of enrolling with the UAE Financial Intelligence Unit’s (FIU) electronic reporting platform, which financial institutions, Designated Non-Financial Businesses and Professions (DNFBPs), and Virtual Asset Service Providers (VASPs) use to file Suspicious Transaction Reports (STRs), Suspicious Activity Reports (SARs), and other anti-money laundering (AML) filings. Built by the United Nations Office on Drugs and Crime (UNODC) and adopted by the UAE FIU, goAML is the single official channel through which regulated entities report suspicious activity, and registering on it is a legal obligation, not an optional compliance step.
This guide covers who must register, the step-by-step registration process, required documents, the reports filed through the system, and the penalties for failing to register or comply.
The Legal Framework Behind goAML Registration
UAE AML obligations, including goAML registration, are currently governed by Federal Decree-Law No. 10 of 2025, effective 14 October 2025, and its implementing regulation, Cabinet Resolution No. 134 of 2025, effective 14 December 2025. These replaced the earlier Federal Decree-Law No. 20 of 2018 and Cabinet Decision No. 10 of 2019, which many older compliance guides still reference. The current framework also extends personal liability for Money Laundering Reporting Officers (MLROs), making accurate, timely goAML registration and reporting a direct compliance responsibility rather than a purely administrative one.
Who Must Register on goAML in the UAE
Registration is mandatory for:
- Financial institutions. Banks, exchange houses, insurance companies, and investment and finance companies.
- DNFBPs. Real estate brokers and agents, dealers in precious metals and stones, auditors and accountants, lawyers and notaries, trust and company service providers, and free zone entities carrying out DNFBP-type activities.
- Virtual Asset Service Providers (VASPs). Entities providing cryptocurrency services or handling virtual assets.
Any entity falling under UAE AML supervision needs both a designated AML compliance officer and an active goAML registration. Failing to register is treated as a standalone violation of UAE AML law, separate from any penalty for a specific unreported transaction.
Also check: AML Compliance Services
Need Expert Advice?
Contact the team at Farahat & Co. for professional support and expert insights for businesses operating in the UAE.
goAML Obligations for Virtual Asset Service Providers
VASPs face an additional layer of AML supervision on top of standard goAML registration. Under VARA Version 2.0, Virtual Asset Service Providers operating in or from Dubai must conduct AML/CFT risk assessments on a quarterly basis, not the annual or ad hoc review cycle that suffices for many other DNFBPs. This means a VASP’s goAML registration is only the entry point, ongoing compliance requires a standing quarterly review process feeding into whatever suspicious activity gets reported through the portal. A VASP that registers on goAML but treats its risk assessment as a one-time onboarding task, rather than a recurring quarterly obligation, is not meeting its actual AML compliance burden even though its registration status shows as active.
Step-by-Step goAML Registration Process
- Register in the SACM system. Access the Service Access Control Manager (SACM) system operated by the UAE FIU and obtain a username and a secret key for the Google Authenticator app.
- Set up Google Authenticator. Use the secret key to link the app, which generates a time-based code used as your password for the goAML portal.
- Complete goAML portal registration. Log in using your username and the Authenticator code, then provide details about the organization and its designated Compliance Officer.
- Submit required documents. Provide identification and proof of address for the Compliance Officer along with the other documents listed below.
- Wait for verification and approval. The FIU reviews the submission and approves the registration.
Once approved, the organization can file STRs, SARs, and other required reports through the platform.
goAML Registration Is Not the Same as Full AML Compliance
Registering on goAML satisfies one specific obligation: having a channel to file reports. It does not, by itself, satisfy the broader AML compliance program a regulated entity is required to maintain. Separate from goAML access, entities must conduct and document customer due diligence (CDD) on new and existing clients, maintain a risk-based AML policy tailored to their business, and, for many financial institutions and DNFBPs, submit semi-annual MLRO reports covering the entity’s AML activity and findings over the preceding period. These MLRO reports go to the entity’s senior management and, depending on the sector, to the Central Bank of the UAE for financial institutions or the Ministry of Economy for DNFBPs, a separate submission from anything filed through goAML itself. A business that treats goAML registration as the finish line, rather than the access point to an ongoing compliance program, is likely to find gaps in exactly the areas a supervisory review checks first.
Confidentiality After Filing: The Tipping-Off Prohibition
Filing an STR or SAR through goAML triggers a confidentiality obligation that catches some compliance officers off guard. Once a report is filed, the entity, its staff, and its Compliance Officer are prohibited from disclosing to the customer, the transaction counterparty, or any third party that a report has been made or that an investigation may be underway. This is commonly referred to as the “tipping-off” prohibition, and it applies regardless of how the information might otherwise be handled internally. Practically, this means a Compliance Officer cannot casually mention to a relationship manager that “the client’s transaction got flagged,” where that information could plausibly make its way back to the client, since doing so risks the tipping-off violation independently of whatever the underlying STR was about.
Documents Required for goAML Registration
- Authorization letter from the institution being represented
- Passport copy, residence visa, and Emirates ID of the Compliance Officer
- Copy of the commercial trade license, for companies
- The Google Authenticator app installed and linked, since it generates the time-based password used for SACM access
Registration Deadlines
| Registration type | Deadline |
|---|---|
| Existing companies as of the original rollout | 30 April 2021 |
| New companies | Within a reasonable time after formation or after becoming subject to AML supervision |
A business formed today that falls under AML supervision should register as part of its initial compliance setup, not treat it as a later step once operations are already underway.
Must check: Ultimate Beneficial Ownership (UBO) Declaration
Reports Filed Through the goAML Portal
| Report type | Purpose | When to file |
|---|---|---|
| Suspicious Transaction Report (STR) | Reports suspicious transactions linked to money laundering or terrorism financing | Upon noticing suspicious financial behavior |
| Suspicious Activity Report (SAR) | Reports suspicious activity or attempted transactions | As soon as suspicious activity is detected |
| Dealers in Precious Metals & Stones Report (DPMSR) | Covers transactions in precious metals or stones at or above AED 55,000 in cash or wire transfer | Within 2 weeks of the transaction |
| High-Risk Country Transaction Report (HRC) | Reports transactions involving high-risk countries | When conducting a transaction with a designated high-risk country |
| Real Estate Activity Report (REAR) | Reports cash or virtual asset real estate transactions | When agents, brokers, or lawyers are involved in such a transaction |
| Fund Freeze Report (FFR) | Reports freezing of funds tied to sanctioned individuals or entities | When funds are frozen following a confirmed sanctions match |
| Partial Name Match Report (PNMR) | Reports a partial match against the UAE sanctions list | When identified during customer due diligence |
As a worked example: a real estate brokerage completes a AED 2,000,000 property sale where the buyer pays a significant portion in cash with no clear source of funds explanation. This triggers a Real Estate Activity Report, filed through the same goAML credentials used for standard STR filings, not a separate registration or system.
What to Do About a Late or Missed Registration
A late or missing goAML registration is treated as non-compliance and should be corrected proactively rather than left unresolved:
- Notify the supervising authority. Report the gap to the relevant supervisory authority or the Ministry of Economy.
- Complete both registration stages. DNFBPs under Ministry of Economy supervision register through the SACM portal; entities also need the UAEFIU eServices Portal for the full registration.
- Submit the pre-registration form. This covers trade license details, ownership structure, Compliance Officer contact information, and business activities.
Earlier remedial action generally results in a lighter enforcement response than waiting until the gap is identified during a supervisory review.
Common Compliance Issues
- Inaccurate or outdated Compliance Officer information on file
- An inactive or abandoned goAML login
- Delayed STR or SAR filings once suspicious activity is identified
- Failing to update business information after a change in ownership or activity
- General lack of AML awareness among staff who should be escalating suspicious activity internally
Penalties for Non-Compliance
| Penalty type | Details |
|---|---|
| Standard fine range | AED 50,000 to AED 1,000,000 |
| Escalated fine, severe cases | Can be doubled up to AED 5,000,000 |
| Assessment authority | Supreme Committee for Combating Money Laundering, Financing of Terrorism and Illegal Organisations |
These figures reflect the penalty structure introduced under Cabinet Resolution No. 16 of 2021, and businesses should confirm current amounts against the FIU or Ministry of Economy at the time of any enforcement action, since the broader AML penalty and supervisory framework has since been updated under Cabinet Resolution No. 134 of 2025. Beyond the fine itself, failing to report suspicious transactions can expose the entity, and in some cases the individual Compliance Officer, to further legal liability given the extended MLRO accountability under current law.
See also: Corporate Secretarial Services
Frequently Asked Questions (FAQs)
Who approves goAML registration applications in the UAE?
Is goAML registration mandatory for all businesses in the UAE?
What is the penalty for not registering on goAML in the UAE?
How do I change the Compliance Officer or MLRO on the goAML portal?
How do I submit a Suspicious Transaction Report through goAML?
What happens if I miss the goAML registration deadline?
Do Virtual Asset Service Providers have extra AML obligations beyond goAML registration?
Can a Compliance Officer tell a client that an STR was filed against them?
What law currently governs goAML and AML compliance in the UAE?
Need Expert Advice?
Contact the team at Farahat & Co. for professional support and expert insights for businesses operating in the UAE.
How Farahat & Co. Can Help
Farahat & Co. assists financial institutions, DNFBPs, and VASPs with goAML registration, Compliance Officer documentation, and ongoing STR and SAR filing support.
Contact Farahat & Co. today to discuss your goAML registration and AML compliance requirements.
