There are two kinds of AML programme. One is built to work. The other is built to look complete in a folder. Both survive quite happily until a supervisor asks to see twelve specific documents and then picks ten customer files at random.
An AML inspection UAE regulators conduct is not really an audit of your paperwork. It is a test of whether the things your paperwork claims are actually happening. This guide sets out what gets requested, what inspectors judge good and bad, what the penalties look like, and what you can realistically fix in thirty days.
Short answer: A UAE AML inspection is a supervisory examination of your anti-money laundering framework, conducted by the Ministry of Economy and Tourism for most DNFBPs, the Central Bank for financial institutions, or the DFSA, FSRA, VARA or GCGRA depending on your licence. It may be off-site, on-site, or unannounced. Inspectors test eight areas: risk assessment, policies, the Compliance Officer appointment, CDD files, sanctions screening, training, goAML reporting and independent audit.
What an AML inspection actually tests

Every AML inspection falls into one of eight areas. The useful thing about that list is that it doubles as a work plan — each row is a gap you can close before anyone asks.
Taking them in turn, and being specific about what “good” looks like.
1. Business-wide risk assessment
The first document requested and the most common failure. It must be current, board-approved and specific to your sector. An assessment dated before December 2025 predates the current executive regulations and almost certainly omits proliferation financing, which is now a mandatory component. A generic template with your company name inserted is worse than none, because it demonstrates the risk-based approach is not operating. This is what an AML risk assessment engagement exists to produce.
2. Policies and procedures
Inspectors check two things: whether the manual reflects Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025, and whether staff can actually find and follow it. A manual citing the repealed 2018 law is an immediate finding, and there are a great many still in circulation. AML policy development that maps to your actual operations, rather than to a sector average, is the fix.
3. Compliance Officer or MLRO
The appointment is tested for substance, not existence. Is the person senior enough, do they have a direct line to the board, are they independent of commercial targets, and are they resourced. An officer who cannot describe the customer base fails all four. Where a firm cannot justify a full-time senior hire, MLRO provision is the standard answer, and for DIFC and ADGM entities the role is a regulated function requiring personal approval — see MLRO services for DIFC and ADGM.
4. CDD and EDD files
The inspector chooses the sample. That is the whole point — you cannot curate it. They check whether due diligence was performed, performed before the relationship went live, and whether the evidence on file supports the risk rating applied. Thin files on high-risk customers are the classic finding, and they are usually a symptom of KYC and CDD procedures that were written but never tested against real cases.
5. Sanctions screening
Supervisory guidance re-emphasises the duty to screen all customers and counterparties against UN, UAE and other applicable lists in real time, with documented evidence at onboarding and on an ongoing basis. Two words there defeat most firms: real time, and ongoing. Batch screening once a week, or screening at onboarding and never again, does not meet it. Country-risk matrices also need updating when the high-risk country lists change, which they did again in March 2026. This is transaction monitoring and screening territory.
6. Training
Training is the one control an inspector can test without reading a document — by asking your staff a question. Records must show delivery, role-specific content, assessment, and coverage of senior management. Generic annual awareness slides delivered to everyone identically is a finding, because a receptionist and a relationship manager face different risks. AML training and awareness tailored by role solves it cheaply.
7. STR filing and goAML
Registration on goAML must be complete, not merely started, and the MLRO must have working access. Inspectors look at the escalation path from internal alert to filed report, and — importantly — at decisions not to file. An undocumented decision not to report is indistinguishable from an oversight. Firms without the internal capacity to run this reliably use an outsourced AML function.
8. Independent audit
An independent audit function is required, and inspectors ask for the last report and evidence that its findings were closed. An open finding carried forward from last year is treated more seriously than a new one, because it establishes that you knew. An independent AML audit run on your own timeline converts unknowns into managed findings.
Three ways an AML inspection reaches you

Direct answer: UAE supervisors conduct both remote off-site document reviews and on-site inspections, and they are legally able to attend unannounced. Because advance notice is not guaranteed, the compliance framework has to be permanently inspection-ready rather than prepared in response to a notification.
An off-site AML inspection arrives as a document request by email, usually with a deadline measured in days. They are less intrusive but no less consequential, because what you send becomes the record.
An on-site AML inspection adds interviews. Inspectors speak to front-line staff, not just the MLRO, and the gap between what the policy says and what the counter staff describe is where findings come from.
An unannounced AML inspection is the reason “we will sort it out when we get the letter” is not a strategy. Whatever state the framework is in on the day is the state that gets recorded.
A related point firms get wrong: there is no grace period after licensing. AML obligations begin on the day the trade licence is issued, before the first customer is onboarded. A new business is not given time to settle in before the requirements apply.
The twelve documents they ask for first

The opening AML inspection request is fairly standard across supervisors. If you can produce all twelve within a day, you are in better shape than most.
Note item nine. The customer file sample is selected by the inspector, from your full customer list. Firms that keep three immaculate files for demonstration purposes and two hundred thin ones discover the flaw in that plan quickly.
Note also that several items are about being able to retrieve, not about having. Training attendance records from eighteen months ago exist in most firms; being able to produce them in an afternoon is a different matter, and the inability to find something is recorded the same way as not having it.
What supervisors call satisfactory

This is not guesswork: AML inspection expectations are published. UAE supervisory authorities have published joint guidance setting out common themes of satisfactory and unsatisfactory practice observed during inspections, drawn from what they found across the sector. The expectations are documented and public.
What runs through the satisfactory column is evidence. Not the existence of a control, but the ability to demonstrate it operated: screening that is logged, decisions that are reasoned in writing, findings closed with proof rather than assertion, training matched to the role it was given to.
What runs through the unsatisfactory column is the opposite pattern — controls that exist on paper and leave no trace in practice. An alert closed with no recorded rationale looks identical, from the outside, to an alert nobody looked at.
What happens if the AML inspection goes badly

The sanctions available after an AML inspection escalate from written warnings through administrative fines to licence suspension and revocation. Article 17 of Federal Decree-Law No. 10 of 2025 provides for administrative penalties from AED 10,000 to AED 5,000,000 per violation.
Per violation is the phrase that matters. A single systemic control failure — say, screening that never ran after onboarding — generates a finding against every affected relationship, not one finding for the firm. That is how modest-sounding per-item penalties become large aggregate numbers.
Late filing is also treated as a standalone violation in its own right, separate from whatever other gap prompted it. And enforcement is visibly active: between July and October 2024 the licences of 32 local gold refineries were suspended, with the businesses charged with 256 violations relating to money laundering control failures including failure to notify the FIU of suspicious transactions.
The part that is not on the ladder: banking relationships, licence renewals and counterparty due diligence all ask about supervisory findings. For many firms the commercial consequence outlasts the fine by years.
Thirty days to AML inspection ready

If you have a month before an AML inspection, this sequence gets you materially further than reading rulebooks does.
- Days 1 to 7 — locate and date everything. Assemble the twelve documents in one folder. Check the version date on each. Search your policy manual for “2018” and “2019” and for “five years” if you are a VASP. Anything you cannot find in week one is a finding waiting to happen.
- Days 8 to 21 — sample yourself. Pull ten customer files at random, not ten good ones, and test them against what your policy promises. Check whether screening ran after onboarding. Check whether any alert was closed without a written reason. Whatever you find, the inspector will find.
- Days 22 to 30 — close and evidence. Fix what you found and record the fix with dates and owners. You will not close everything, and that is fine. A gap you identified and are actively remediating reads completely differently from a gap the inspector discovered.
If step two surfaces more than you expected, that is the normal outcome and it is the reason to do it. Firms that have never sample-tested their own files against their own policy almost always find something. Bringing in an independent AML audit to do it properly is faster than doing it yourself, and it produces a document you can show the inspector.
Does size or sector change the AML inspection?
Direct answer: Not the obligation. A two-person corporate service provider and a fifty-person accounting firm carry identical AML duties, and the supervisory checklist does not scale down for headcount. What proportionality changes is the depth and cost of what is proportionate — a smaller firm needs a smaller framework, not a partial one.
Sector changes the AML inspection typologies rather than the structure. A real estate broker, a precious metals dealer, a corporate service provider and a virtual asset business all need the same eight areas covered, but the risks they assess within them are entirely different — which is exactly why generic templates fail.
Newly regulated sectors carry an additional burden, because there is no local operating history to draw on. A virtual asset business faces supervisory expectations that did not exist two years ago, and building against a bank template produces controls aimed at the wrong risks.
What to do on the day
Assuming an on-site AML inspection, a few practical things make the day go better and none of them are about compliance knowledge.
- Give the inspectors a room, a desk and reliable connectivity. Making them work in a corridor does not help you
- Nominate one point of contact, normally the MLRO, and route every request through them so nothing is answered twice with different answers
- Answer what is asked. Volunteering adjacent information opens areas that were not on the agenda
- If you do not know, say you will find out and come back within the hour. Guessing creates a record that is wrong
- Keep a log of every document handed over and every question asked. You will need it when the findings report arrives
- Brief front-line staff beforehand that they may be asked questions, and that the honest answer is always the right one
The instinct to present the firm at its best is understandable, but an AML inspection is not a pitch. Inspectors have seen every version of an unprepared business, and a candid account of a known gap with a remediation plan lands far better than a confident claim that unravels when they open a file.
This is also where having an outsourced AML function or provisioned MLRO helps in a way that is hard to quantify in advance. Someone who has sat through several of these knows which questions are routine and which signal that the inspector has found a thread worth pulling.
AML inspection UAE: frequently asked questions
What is an AML inspection in the UAE?
An AML inspection is a supervisory examination of a firm’s anti-money laundering framework. The supervisor tests whether documented controls actually operate, covering risk assessment, policies, the Compliance Officer appointment, CDD files, sanctions screening, training, goAML reporting and independent audit.
Who conducts AML inspections in the UAE?
It depends on your licence. The Ministry of Economy and Tourism supervises most DNFBPs, the Ministry of Justice covers lawyers and notaries, the Central Bank covers financial institutions, and the DFSA, FSRA, VARA and GCGRA supervise the DIFC, ADGM, Dubai virtual assets and commercial gaming respectively.
Can a UAE AML inspection be unannounced?
Yes. Supervisors conduct remote off-site document reviews and on-site inspections, and are able to attend without advance notice. Compliance readiness therefore needs to be permanent rather than assembled in response to a notification.
What documents do AML inspectors ask for?
Typically the trade licence and constitutional documents, beneficial owner register, organisation chart, group structure, business-wide risk assessment, AML policy manual, Compliance Officer appointment, goAML registration, a customer file sample of their choosing, screening logs, training records, and prior audit findings with closure evidence.
How are customer files selected for review?
By the inspector, from your full customer list. You do not choose the sample, which is why maintaining a few well-prepared demonstration files is not a workable strategy.
What are the most common AML inspection findings?
A risk assessment that is out of date or cites repealed legislation, screening performed at onboarding only, alerts closed without recorded reasoning, generic training not tailored to role, an MLRO without real authority, and prior-year findings still open.
What are the penalties after a failed AML inspection?
Sanctions escalate from written warnings to administrative fines, licence suspension and licence revocation. Article 17 of Federal Decree-Law No. 10 of 2025 provides for penalties from AED 10,000 to AED 5,000,000 per violation, applied per breach rather than per inspection.
Is there a grace period for new businesses?
No. AML obligations begin on the day the trade licence is issued and apply before the first customer is onboarded. A new business is not given a settling-in period.
Do small firms face the same AML inspection requirements?
Yes. The supervisory checklist does not adjust for headcount, and a two-person firm carries the same legal obligations as a large one. Proportionality affects the depth and cost of the framework, not whether each element is required.
How long does an AML inspection take?
An off-site review is usually a document request with a deadline of days. An on-site inspection typically runs one to several days depending on firm size, followed by a findings report and a remediation period.
What should we do when we receive an inspection notice?
Assemble the standard document set, check version dates, sample your own customer files against your policy, and document any gaps you find along with a remediation plan. A gap you identified and are fixing is treated differently from one the inspector discovers.
Can we prepare for an AML inspection in 30 days?
You can materially improve the outcome in thirty days: one week locating and dating documents, two weeks sample-testing your own files, and one week closing gaps with evidence. You will not fix everything, but demonstrating an active, documented remediation programme changes how findings are received.
Does an independent AML audit help with inspections?
Considerably. It surfaces the same gaps an inspector would, on your timeline, and produces a report plus closure evidence you can present. Note that the firm operating your AML function cannot also audit it — independence rules out reviewing your own work.
What happens after the inspection report?
Findings are issued with a remediation period. Closing them with documented evidence before the follow-up review is the objective. Unclosed findings carried into a subsequent inspection are treated more seriously than new ones.
AML inspection UAE: where this leaves you
An AML inspection is unusual among regulatory events in that you know almost exactly what will be asked of you. The document list is standard, the eight areas are published, and the supervisors have set out in writing what they consider satisfactory practice and what they do not.
What separates firms that come through cleanly from firms that do not is rarely knowledge of the rules. It is whether anyone has sat down with ten real customer files and checked them against the policy. That exercise takes an afternoon and predicts the inspection result better than anything else you can do.
Ontrax works with financial institutions, DNFBPs and virtual asset businesses across the UAE on exactly these eight areas — risk assessment, policies, MLRO provision, KYC and CDD, screening, training, the outsourced AML function and independent audit. We are based in DIFC, Dubai.
If you have an inspection scheduled, or you simply want to know what one would find, get in touch. A gap analysis takes weeks, not months.
Primary sources and further reading
- UAE Ministry of Economy and Tourism — DNFBP guidelines, circulars and supervisory guidance
- UAE National Committee for AML/CFT — joint guidance and national framework publications
- Central Bank of the UAE — AML/CFT regulations, guidance and enforcement notices
- Financial Action Task Force — the international standards underpinning UAE supervisory expectations

