Independent AML Audit in the UAE: What It Is, Who Needs One, and What Auditors Test

At Ontrax Risk and Compliance Ltd., we deliver tailored Anti-Money Laundering (AML) compliance solutions that protect your business, ensure regulatory alignment, and foster long-term credibility. Whether you’re a financial institution, a crypto business, or part of a DNFBP sector, our specialized services are built to meet your unique compliance challenges.

Independent AML audit UAE requirements and process for FIs, DNFBPs and VASPs

If you run a regulated business in the UAE, someone has probably told you that you need an independent AML audit. They were right. What they may not have told you is that the legal basis for it changed at the end of 2025, and that a large share of the guidance still circulating online — including from firms selling the service — points at a law that no longer exists.

So let us do this properly. This is a plain-English walk through what an independent AML audit UAE regulators actually expect, who has to have one, what an auditor will look at, what the findings mean, and how to come out of it in better shape than you went in.

Short answer:  An independent AML audit is a review of your anti-money laundering programme by someone who did not build or run it, testing whether the controls you have written down actually operate in practice. In the UAE it is required under Article 21 of Cabinet Resolution No. 134 of 2025, and it applies to financial institutions, DNFBPs and virtual asset service providers alike. Most firms do it annually.

What is an independent AML audit?

Start with what an independent AML audit is not. An independent AML audit is not a financial audit. Your statutory auditor signing off the accounts has not done this, and cannot do it as part of that engagement. It is also not a policy review — reading your manual and confirming it says sensible things is a much smaller exercise.

An independent AML audit tests the gap between what you say you do and what you actually do. That gap is where nearly every enforcement action lives.

In an independent AML audit UAE supervisors would recognise, the auditor pulls a sample of your customer files and check whether the due diligence you promised in your policy was genuinely performed, and performed before the relationship went live. They will look at screening alerts and ask what happened to them. They will find out whether the training your policy mandates was actually delivered, to whom, and whether anyone failed. They will check whether last year’s findings were closed or quietly forgotten.

It is, in other words, an evidence exercise. The question is never “do you have a policy on this” — it is “show me where you did it.”

Is an independent AML audit mandatory in the UAE?

Direct answer:  Yes. An independent audit function is a mandatory element of the AML/CFT programme for every reporting entity in the UAE under Article 21 of Cabinet Resolution No. 134 of 2025, read with Article 19 of Federal Decree-Law No. 10 of 2025. There is no revenue threshold and no small-business exemption, though supervisors apply proportionality to scope.

Here is where it gets interesting, and where you should be careful about what you read elsewhere.

For years, the go-to citation for this obligation was Article 20 of Cabinet Decision No. 10 of 2019. That was correct — until it wasn’t. Federal Decree-Law No. 10 of 2025 came into force on 14 October 2025 and repealed the 2018 AML law in full. Cabinet Resolution No. 134 of 2025 followed on 14 December 2025, replacing the 2019 executive regulations entirely.

independent AML audit UAE

If you search for “independent AML audit UAE requirement” today, a good number of the top results still cite the repealed 2019 provision as their authority. Some of those pages belong to firms offering the service. That is not a small detail. If a provider’s own marketing is built on a repealed law, it is fair to ask how current their audit methodology is.

The current legal stack behind the independent AML audit UAE requirement is straightforward:

  • Federal Decree-Law No. 10 of 2025, Article 19 — makes the risk-based approach and its supporting internal controls mandatory, with policies approved by senior management, applied across branches and majority-owned subsidiaries, and reviewed continuously.
  • Cabinet Resolution No. 134 of 2025, Article 21 — requires ongoing training and development programmes together with an independent audit function to test whether the programme works.
  • MoET AML/CFT Guidelines for DNFBPs, September 2025, Section 7 — prescribes a designated compliance officer, staff training and screening, group oversight, an independent audit function and senior-management responsibility, with proportionality for resource-limited DNFBPs.

On proportionality: proportionality changes the depth and cost of the audit. It does not remove the obligation. A four-person brokerage still needs an independent review; it just needs a smaller one than a bank.

Who needs an independent AML audit in the UAE?

The independent AML audit UAE obligation reaches three groups, and the third is newer than people realise.

independent AML audit UAE

Financial institutions

Banks, exchange houses, insurance companies and brokers, payment service providers and finance companies. If you are supervised by the Central Bank, the DFSA or the ADGM FSRA, your rulebook also imposes its own independent-review requirements on top of the federal ones. Those obligations stack rather than substitute.

DNFBPs — all six categories

Article 3 of Cabinet Resolution 134 of 2025 lists the designated non-financial businesses and professions: real estate brokers and agents, dealers in precious metals and stones, lawyers and notaries and other independent legal professionals, independent accountants and auditors, company and trust service providers, and — as of December 2025 — commercial gaming operators.

That last addition is why gaming licensees now need the same DNFBP AML audit everyone else does. If that applies to you, our GCGRA compliance advisory work covers how the audit obligation interacts with sector licensing.

Virtual asset service providers

The 2025 AML Law brought VASPs directly and explicitly into the perimeter rather than addressing them by implication. A VASP AML audit is therefore mandatory: exchanges, custody and wallet providers, and transfer services are squarely in scope, and in Dubai a VARA authorisation sits alongside the federal obligation rather than replacing it. If that is your business, crypto AML compliance needs designing against both regimes at once.

How often do you need an AML audit?

Direct answer:  UAE law does not specify a frequency. Established practice is annually, plus a triggered review after any significant regulatory change, a material change to your business model, an acquisition, or a serious compliance incident.

The absence of a stated AML audit frequency confuses people, and it occasionally gets used as an argument for not doing one. That argument does not survive contact with a supervisor.

The reasoning is risk-based. Frequency should match your risk profile: a high-risk business with cash-intensive customers, cross-border flows and a large retail base needs testing more often than a small professional firm with twenty long-standing corporate clients. What supervisors look for is a documented rationale for the interval you chose, and evidence you stuck to it.

Annual is the safe default, and it is what most UAE reporting entities land on. Beyond that, treat these as automatic triggers for a fresh review:

  • A change in the law — and 2025 was a year with two of them
  • Entering a new market, product line or customer segment
  • An acquisition, or bringing a new entity into the group
  • A supervisory inspection, a finding, or a near miss
  • A change of MLRO, or a material change to the compliance team
  • Implementing or replacing a screening or monitoring system

What does “independent” actually mean?

Independence is the part of an independent AML audit that firms most often get wrong, usually in good faith. They commission a review, it gets done thoroughly, and it fails the independence test on a technicality that was obvious from the start.

independent AML audit UAE

The principle is that the reviewer must have no stake in the outcome and no hand in what is being reviewed. Your MLRO cannot audit the programme they run. The consultant who wrote your AML policy cannot audit that policy. A compliance analyst reporting to the compliance officer cannot audit the compliance officer’s work — the reporting line alone defeats it.

What does work: an external compliance firm with no prior involvement in designing your controls; an internal audit function that reports to the board or audit committee rather than to management; or a group compliance function sitting outside the audited entity.

One practical wrinkle worth planning for. If you use an outsourced AML function or a provisioned MLRO, that provider cannot then audit the programme they operate. You need a second, separate firm. Some providers will tell you otherwise. They are wrong, and it is exactly the kind of thing a supervisor notices immediately.

What does an AML audit actually cover?

Scope varies with size and risk, but a competent independent AML audit works through ten domains. Treat the list below as your AML audit checklist, with what the auditor is really testing in each domain.

independent AML audit UAE
DomainWhat the auditor is testing
Enterprise risk assessmentWhether it exists, is board-approved, is specific to your actual products and customers, and has been refreshed since the law changed
Policies and proceduresWhether they reflect the 2025 law, and whether staff can find and follow them
CDD and EDD filesSample testing: was due diligence done, done before onboarding, and does the evidence support the risk rating applied
Sanctions and PEP screeningWhether screening runs at onboarding and continuously, how alerts are adjudicated, and whether there is an audit trail
Transaction monitoringWhether rules are tuned to your risk, whether alerts are cleared with reasoning, and whether backlogs exist
STR filing and goAMLRegistration status, the escalation path from alert to filing, timeliness, and whether decisions not to file were documented
TrainingDelivery records, role-specific content, assessment results, and whether the board and senior management were included
Governance and MLROAppointment, authority, resourcing, reporting line, and evidence of senior management engagement
Record keepingFive-year retention across customer files, transactions and internal reports, and whether records can actually be retrieved
Prior audit findingsWhether last cycle’s findings were closed, and closed with evidence rather than assertion

Notice how much of this is testing rather than reading. A weak audit reviews documents. A useful one pulls twenty customer files and checks them against what the policy promised. If your AML risk assessment and your KYC procedures have never been sample-tested against real files, the first proper audit is going to be uncomfortable — and valuable.

What does the audit process look like?

For a mid-sized DNFBP, an independent AML audit takes six to eight weeks end to end. Larger financial institutions run longer; a very small firm can be quicker.

independent AML audit UAE

A few things worth knowing before you start.

Scoping is where you get value or lose it. An audit scoped generically produces generic findings. Tell the auditor where you are worried — the auditor who is told nothing will find the obvious things and miss the ones that matter to you.

Fieldwork is largely about document production, and it is where most delays happen. If nobody can locate the training attendance records from eighteen months ago, that is itself a finding, and you will have burned a week discovering it.

Closure is the phase that gets skipped. Producing a report is not the point. The point is fixing what the report found, with evidence, before the next cycle.

Understanding the audit report

A good AML audit report rates findings by severity and assigns an owner and a deadline to each. A bad one gives you forty undifferentiated observations and leaves you to work out which ones will get you fined.

independent AML audit UAE

The findings we see most often, in rough order of frequency:

  • Risk assessment out of date, or still written against Federal Decree-Law No. 20 of 2018
  • CDD files missing source-of-funds evidence for higher-risk customers
  • Screening performed at onboarding but never repeated
  • Alerts closed with no recorded reasoning — the alert exists, the decision does not
  • Training delivered but not evidenced, or not covering the board
  • An MLRO appointed on paper without authority, resourcing or board access
  • Prior-year findings still open with no remediation plan

That last one deserves emphasis. An open finding carried forward is worse than never having audited at all, because it establishes that you knew about the gap and left it. That is the pattern behind most large international enforcement actions: the audit function existed, it identified the problem, and nobody closed it. If a report lands with findings you cannot resolve internally, that is the moment to bring in help on AML policy development or MLRO provision — not twelve months later.

What happens if you skip it?

Skipping the independent AML audit UAE regulators require has two consequences, and the second is usually more expensive than the first.

The direct consequence is administrative penalties under the AML compliance UAE framework. Article 17 of Federal Decree-Law No. 10 of 2025 provides for fines running from AED 10,000 to AED 5,000,000 per violation. Per violation matters — these are not capped at one penalty per inspection. UAE supervisors have been visibly active: the Central Bank sanctioned a UAE bank AED 3 million in July 2025 following examinations that uncovered AML and sanctions compliance breaches, alongside fines totalling over AED 4.1 million across three exchange houses for similar deficiencies.

The indirect one is everything else. Missing independent testing shows up in bank onboarding questionnaires, in licence renewals, in counterparty due diligence, and in any transaction where a buyer’s advisers review your AML compliance UAE file. It is a small line item that stalls larger things, and it sits at the centre of AML compliance UAE due diligence questionnaires.

The asymmetry: an audit is a planned, budgeted, scoped exercise on your timeline. Remediation under supervisory pressure is none of those things, and typically costs several times more.

How to prepare for an independent AML audit

You will get more out of an independent AML audit, and a shorter findings list, if you do a fortnight of preparation first.

  1. Assemble the core documents. Risk assessment, AML policy manual, CDD and EDD procedures, training plan, MLRO appointment letter and terms of reference, goAML registration confirmation. If any are missing, you already know one finding.
  2. Check your legal references. Open your policy manual and search for “2018” and “2019”. If either appears as the governing law, update before the auditor arrives.
  3. Pull your own sample. Take ten customer files at random and check them against your own policy. Whatever you find, the auditor will find too.
  4. Locate the evidence, not just the process. Training attendance records, screening logs, alert dispositions, board minutes showing AML was discussed. Evidence that cannot be retrieved does not count.
  5. Close last year’s findings first. Or at minimum, have a documented remediation plan with dates. An open finding with a credible plan is a far better position than an open finding with silence.
  6. Brief your people. Inspectors and auditors both test staff awareness by simply asking. Training is the one control that can be tested without reading a single document.

If steps two through four surface more than you expected, a transaction monitoring and screening review or a refresher round of AML training before the audit is usually money well spent.

Independent AML audit UAE: frequently asked questions

What is an independent AML audit?

An independent AML audit is a review of a firm’s anti-money laundering programme by a person or function with no role in designing or operating it. It tests whether documented controls work in practice, covering risk assessment, CDD, screening, monitoring, reporting, training, governance and record keeping.

Is an independent AML audit mandatory in the UAE?

Yes. Article 21 of Cabinet Resolution No. 134 of 2025 requires an independent audit function to test the AML/CFT programme, sitting within the internal-controls duty in Article 19 of Federal Decree-Law No. 10 of 2025. It applies to financial institutions, DNFBPs and VASPs.

How often should an AML audit be done in the UAE?

UAE law does not fix a frequency. Annual is established practice, plus a triggered review after a legal change, a business model change, an acquisition, a system replacement or a compliance incident. Supervisors expect a documented rationale for whatever interval you choose.

Who can perform an independent AML audit?

An external compliance firm with no involvement in building your controls, an internal audit function reporting to the board rather than management, or a group function outside the audited entity. Your MLRO, your policy author and anyone reporting to the compliance function cannot.

Can our statutory auditor do the AML audit?

Not as part of the financial audit, which has a different scope and objective. An audit firm may perform an independent AML audit as a separate engagement, provided the team has genuine AML expertise and no conflict.

Do DNFBPs need an independent AML audit?

Yes. All six DNFBP categories are in scope: real estate brokers, dealers in precious metals and stones, lawyers and notaries, independent accountants and auditors, corporate service providers, and commercial gaming operators added in December 2025.

Do VASPs and crypto businesses need one?

Yes. Federal Decree-Law No. 10 of 2025 brought virtual asset service providers directly into the AML perimeter. In Dubai, VARA obligations apply alongside the federal requirement rather than instead of it.

What does an independent AML audit cost in the UAE?

It scales with entity size, risk profile and sample volume rather than being a fixed fee. A small DNFBP sits at the lower end; a bank or multi-entity group at the upper. Scope is the main cost driver, which is why scoping deserves attention.

How long does an AML audit take?

Six to eight weeks end to end is realistic for a mid-sized DNFBP: roughly a week of scoping, two to three weeks of fieldwork, one to two weeks of testing, and a week of reporting, followed by remediation.

What are the penalties for not having one?

Article 17 of Federal Decree-Law No. 10 of 2025 provides for administrative fines from AED 10,000 to AED 5,000,000 per violation. Indirect consequences — banking access, licence renewals, counterparty due diligence — are often more damaging.

What is the difference between an AML audit and an AML risk assessment?

The risk assessment identifies the money laundering and terrorist financing risks your business faces and drives the design of your controls. The audit tests whether those controls actually work. You need both. An AML risk assessment drives design; the audit tests operation, and it will examine the AML risk assessment as one of its ten domains.

Our AML policy cites the 2018 law — is that a problem?

Yes, and it is one of the most common findings right now. Federal Decree-Law No. 20 of 2018 was repealed in October 2025 and Cabinet Decision No. 10 of 2019 in December 2025. A manual citing repealed law suggests the framework has not been reviewed since the reform.

What happens after the audit report?

AML audit report findings are assigned owners and deadlines, remediation is carried out, and closure is evidenced. The next cycle picks up anything left open. An unclosed prior-year finding is treated more seriously than a new one.

Can an independent AML audit be done remotely?

Largely yes. Document review, file sampling and system walkthroughs can be conducted remotely, though on-site work adds value for cash-intensive businesses and for testing whether front-line staff apply procedures in practice.

Where this leaves you

An independent AML audit in the UAE is the one control that tests all the others. That is why regulators require it, and why it is the fastest way to find out whether the compliance framework you have been paying for actually works.

The 2025 reforms make this independent AML audit cycle more consequential than usual. Every reporting entity in the UAE is now operating under a statute and a set of executive regulations that did not exist eighteen months ago, and a great many AML compliance UAE frameworks have not been touched since. The audit is where that gap surfaces — ideally on your timeline rather than a supervisor’s.

Ontrax provides independent AML audit services from DIFC, Dubai, for financial institutions, DNFBPs and virtual asset businesses across the UAE. We test against the current legal framework, rate findings by severity with owners and deadlines, and support remediation through to evidenced closure.

Because independence matters, we will tell you plainly where we cannot act: if we built your policy or provide your MLRO in DIFC or ADGM, we cannot audit that same programme, and we will say so before you engage us rather than after.

To scope an audit, or to talk through whether your framework would survive one, get in touch.

Primary sources and further reading

Leave a Reply

Your email address will not be published. Required fields are marked *

At Ontrax Risk and Compliance Ltd., we deliver tailored Anti-Money Laundering (AML) compliance solutions that protect your business, ensure regulatory alignment, and foster long-term credibility. we ensure your business stays compliant with evolving AML regulations. Our expert-driven AML solutions help you mitigate risks, prevent financial crime, and meet global compliance standards.

NEWSLETTER

    Quick Links
    LOCATION
    Contact Us
    © 2026 Ontrax Risk and Compliance Ltd. | All Rights Reserved. Designed & Developed by Inspia Technologies