Blog Image

How Long Should AML Records Be Kept in the UAE?

How Long Should AML Records Be Kept in the UAE?

If your business operates in the UAE, keeping proper AML records is not something you should treat as a simple paperwork exercise. These records help demonstrate that your business has carried out the right customer checks, monitored transactions and taken action when something looks suspicious.

So, how long should AML records be kept in the UAE?

The general requirement is at least five years. However, the date from which those five years are counted can vary depending on the type of record and the circumstances. UAE AML requirements cover financial institutions, Designated Non-Financial Businesses and Professions (DNFBPs), and other regulated businesses within the AML framework.

In this guide, we explain the UAE AML record retention period, what records need to be kept and some common mistakes businesses should avoid.

What Is the AML Record Retention Period in the UAE?

Under UAE AML requirements, relevant businesses generally need to retain AML-related records for a minimum of five years.

This includes records relating to transactions, customer due diligence (CDD), ongoing monitoring, account information, business correspondence and suspicious transaction reports (STRs/SARs), together with the results of relevant analysis.

Importantly, the five-year period does not always simply mean five years from the date a document was created.

Depending on the circumstances, the retention period may run from events such as:

  • Completion of a transaction
  • Termination of a business relationship
  • Closure of a customer’s account
  • Completion of an occasional transaction
  • Completion of a regulatory inspection
  • Issuance of a final judicial judgment
  • Liquidation or dissolution of a legal entity or arrangement

The UAE Central Bank’s current guidance explains that the applicable five-year period is generally calculated from the most recent relevant trigger event.

What AML Records Should Businesses Keep?

AML record keeping covers much more than copies of passports or Emirates IDs.

Depending on your business and regulatory obligations, your AML records may include the following.

1. Customer Due Diligence Records

Businesses should maintain information collected during the customer identification and verification process.

This can include:

  • Customer identification documents
  • Beneficial ownership information
  • Customer risk assessments
  • Source of funds or source of wealth information, where applicable
  • Information about the customer’s business activities
  • CDD reviews and updates
  • Enhanced due diligence records for higher-risk customers

These records help show who the customer is, who ultimately owns or controls the business and how the relationship was assessed from an AML perspective.

2. Transaction Records

Transaction records are another major part of AML record keeping.

Businesses should retain sufficient information to understand and reconstruct transactions. This can include transaction details, supporting documentation and relevant records relating to domestic or international transactions.

The records should be organised in a way that allows transactions to be tracked and reconstructed when necessary.

3. Ongoing Monitoring Records

AML compliance does not end once a customer has passed initial KYC checks.

Businesses should also maintain records showing how customers and transactions were monitored over time.

For example, records may include:

  • Transaction monitoring results
  • Alerts generated by monitoring systems
  • Reviews of unusual activity
  • Customer risk-rating changes
  • Decisions made following an alert
  • Supporting documents used during an investigation

Keeping these records can be particularly important if a regulator later asks why a particular transaction or customer was considered low, medium or high risk.

4. STR and SAR Records

Suspicious Transaction Reports (STRs) and suspicious activity-related records should also be retained.

This can include the report itself, supporting information and the results of any analysis carried out before or after reporting.

The UAE AML framework specifically includes suspicious transaction reports and the results of related analysis among the records that must be maintained.

Businesses should also make sure these records are handled securely and confidentially.

5. AML Policies, Risk Assessments and Supporting Documents

A strong AML recordkeeping system should not only contain customer and transaction information.

Businesses should also maintain appropriate records relating to their AML/CFT risk assessment and mitigation measures. For regulated financial institutions, the UAE Central Bank specifically refers to maintaining records associated with ML/TF/PF risk assessments and mitigation measures.

This can help demonstrate that your AML programme is not just a written policy sitting in a folder but is actually being implemented.

Why Is Five-Year AML Record Keeping Important?

At first glance, keeping five years of records can feel like an administrative burden. In reality, good record keeping is one of the foundations of an effective AML compliance programme.

There are several reasons for this.

It Helps During Regulatory Inspections

Regulators may need to review customer files, transactions, risk assessments or AML controls.

If your records are incomplete or difficult to retrieve, even a business with otherwise reasonable AML procedures could face compliance problems.

UAE requirements state that relevant records should be available to competent authorities when requested.

It Creates an Audit Trail

Good records allow a business to answer straightforward questions such as:

  • Who was the customer?
  • Who was the beneficial owner?
  • What due diligence was completed?
  • What was the customer’s risk rating?
  • What transactions took place?
  • Was unusual activity identified?
  • What action did the business take?

Without an adequate audit trail, it becomes much harder to demonstrate that AML controls were actually followed.

It Supports Suspicious Activity Investigations

Historical records can become important when a transaction appears suspicious months or years after the original customer relationship began.

Maintaining a clear history allows compliance teams and competent authorities to understand the wider context instead of looking at one transaction in isolation.

Can Businesses Delete AML Records After Five Years?

This is where businesses need to be careful.

Five years is generally the minimum retention period, not necessarily a universal deadline after which every record should automatically be deleted.

The applicable retention period can depend on the circumstances, and competent authorities may require certain records to be retained for longer. UAE Central Bank guidance expressly notes that competent authorities can require longer retention for records they consider relevant.

Businesses should therefore have a documented record-retention policy rather than automatically deleting files as soon as five years have passed.

It is also important to consider other legal, regulatory and sector-specific retention requirements that may apply to the business.

What About AML Records for DNFBPs in the UAE?

The five-year principle also applies to Designated Non-Financial Businesses and Professions (DNFBPs) covered by the UAE AML framework.

DNFBPs can include sectors such as:

  • Real estate brokers and agents
  • Dealers in precious metals and stones
  • Auditors and accountants
  • Corporate service providers
  • Certain legal and professional service providers

The exact AML obligations depend on the nature of the business and the applicable regulatory framework.

For example, the UAE Ministry of Economy has stated that real estate brokers and agents registered and licensed in the UAE, including those in free zones, are required to maintain records and transaction data for at least five years.

How Should AML Records Be Stored?

Keeping records for five years is only useful if you can actually find them when needed.

A practical AML recordkeeping system should be:

Organised: Records should be categorised so that customer files, transaction information, CDD documents and investigation records can be retrieved efficiently.

Secure: AML records contain sensitive customer and business information. Access should be restricted to authorised personnel.

Accurate: Information should be kept up to date and discrepancies should be addressed rather than ignored.

Retrievable: Your compliance team should be able to locate relevant records without searching through thousands of unrelated files.

Protected against loss: Electronic records should be appropriately backed up, while businesses relying on physical documentation should have suitable controls against damage or loss.

UAE guidance also stresses that records should be organised sufficiently to allow the reconstruction and tracking of individual transactions.

Common AML Record-Keeping Mistakes

Businesses often make avoidable mistakes when managing AML records.

Deleting records too early

Some companies treat five years as a rough target and delete documents without checking when the applicable retention period actually began.

Keeping only KYC documents

AML compliance involves more than identity documents. Transaction records, monitoring results, risk assessments and suspicious activity records may also need to be retained.

Poor document organisation

Having the documents somewhere in an email inbox or shared drive is not the same as having a structured recordkeeping system.

Failing to document decisions

If an AML alert was reviewed and closed, the reasoning behind that decision should be appropriately documented. A regulator may want to understand not just what decision was made but why.

Ignoring older customer files

Long-standing customers should not automatically be treated as low risk. Their records and risk profiles may need to be reviewed and updated according to the business’s AML procedures.

How Can Businesses Improve AML Record Keeping?

A simple approach can make AML record management much easier.

Start by creating a clear retention policy that explains:

  1. Which AML records must be retained
  2. How long each category should be retained
  3. When the retention period starts
  4. Who is responsible for maintaining the records
  5. Who can access them
  6. How records are securely archived
  7. How records are disposed of when they can legally be deleted

It is also useful to periodically test whether your team can retrieve an old customer file or transaction record quickly.

If you cannot find a five-year-old customer record when conducting an internal review, there is a good chance you will struggle when a regulator asks for it.

Frequently Asked Questions

How many years should AML records be kept in the UAE?

The general minimum AML record retention period in the UAE is five years. The exact starting point depends on the type of record and the relevant circumstances.

Do STR records need to be retained?

Yes. Suspicious transaction reports and the results of related analysis are included within the AML records that relevant businesses are required to maintain.

Do KYC documents need to be kept for five years?

Yes, relevant customer due diligence records, including identification documents and other CDD information, are generally subject to the applicable minimum five-year retention requirement.

Can AML records be stored electronically?

AML records can be maintained electronically provided the business has appropriate controls to protect their integrity, security and accessibility and can produce them when required.

Is five years always the maximum retention period?

No. Five years is generally the minimum statutory period. Depending on the circumstances, authorities may require certain records to be retained for longer.

Final Thoughts

AML record keeping in the UAE is about more than satisfying a five-year requirement. It is about creating a reliable history of your business’s AML decisions, customer checks and transaction monitoring.

For most businesses covered by the UAE AML framework, keeping relevant AML records for at least five years is the starting point. But businesses should also pay attention to the event that starts the retention period, maintain records in an organised and secure manner, and check whether a longer retention period applies.

A good rule to follow is simple: if your business cannot quickly explain what it knew about a customer, what transactions took place and what AML action it took, its recordkeeping system probably needs improvement.