Blog Image

goAML Compliance for Virtual Asset Service Providers in the UAE

Why goAML matters to UAE VASPs

Virtual Asset Service Providers (VASPs) handle customers, wallets, counterparties, and transfers that may cross borders quickly. They need controls to understand customers, assess service risks, monitor activity, and escalate concerns. goAML is the UAE FIU reporting system for suspicious reports and other report types.

The current UAE AML law includes VASPs among entities required to notify the FIU without delay when they suspect, or have reasonable grounds to suspect, a transaction or funds relate to crime. The duty applies regardless of value and calls for a detailed report based on available information. goAML readiness is therefore an ongoing compliance responsibility, not just portal registration.

goAML registration and VASP licensing are separate

First identify the competent and supervisory authority for the VASP’s activities and location; licensing routes depend on business model and jurisdiction. The AML law requires the relevant licence, registration, or enrolment before covered activity is conducted.

goAML access is a separate FIU reporting channel. It is not a VASP licence, and a commercial licence does not automatically complete FIU onboarding. Verify both regulatory status and reporting access, then follow current FIU/SACM instructions for users and authorisations.

Build the reporting workflow before the first alert

Define how an alert moves from detection to assessment and, where required, FIU reporting. The procedure should identify who can escalate concerns, who approves the assessment, how customer and wallet information is gathered, how decisions are documented, who submits reports and monitors FIU messages, and how sensitive information is restricted. Train operations, customer support, monitoring staff, and decision-makers so reporting does not rely on one person or an informal process.

What information helps support a report?

Required information depends on the report and facts. Preserve customer and beneficial-owner records, wallet addresses, transaction identifiers, dates, asset and amount, counterparties, available source/destination data, and investigation notes. A clear narrative explains who was involved, what happened, when, which assets were involved, and why the activity raised concern. Separate verified facts from assumptions; an analytics alert alone does not prove crime. The law calls for a detailed report based on available information, not invented details. Document missing information and follow current FIU instructions.

A practical VASP goAML reporting process

1. Identify and triage the concern

Possible indicators may arise from customer onboarding, wallet screening, transaction monitoring, sanctions screening, law-enforcement enquiries, or internal reviews. Route concerns to the designated compliance team and preserve the underlying data before it is lost or overwritten.

2. Assess the customer and activity together

Review the transaction in context: the customer’s expected activity, purpose of the relationship, source of funds, counterparties, jurisdictional exposure, and prior activity. A single indicator may have a legitimate explanation; a combination of unexplained features may require escalation. Use a risk-based process and record the reasoning.

3. Decide whether the suspicion threshold is met

Apply the current UAE legal standard and the organisation’s reporting procedure. The current law refers to suspicion or reasonable grounds to suspect and states that reporting is not limited by transaction value. Do not set an internal minimum amount below which staff are told never to report.

4. Select the appropriate report type

Use the report type that matches the case and the current FIU guidance. An STR or SAR is not interchangeable with other report types such as an AIF, AIFT, RFI, or sanctions-related report. If another report type or response is required, follow the specific instructions attached to it.

5. Submit promptly and manage follow-up

The law requires reporting without delay. Submit through the approved FIU channel, retain the submission reference, restrict access to the report, and monitor the goAML Message Board for requests or feedback. Assign an owner and deadline to each FIU request so that it is answered accurately and on time.

Common VASP reporting weaknesses

Avoid unsupported conclusions from analytics, generic report narratives, missing transaction references, unlinked wallet/customer records, and unmonitored FIU messages. Keep goAML reporting distinct from licensing obligations. Test the process through file reviews and training; ensure the risk assessment and monitoring scenarios reflect the products and customer types actually served.

Connect goAML to broader AML controls

A reliable report depends on the controls that produce the information. Customer onboarding should establish the customer’s identity, beneficial ownership where relevant, expected activity, and purpose of the relationship. Monitoring should reflect the services offered, customer types, assets, transaction channels, and geographic exposure. Escalation instructions should tell staff how to preserve records and when to involve the MLRO.

Senior management should receive regular information about the quality and timeliness of the reporting process, recurring data gaps, overdue FIU requests, and training needs. This oversight should protect confidential report details and provide access only to authorised people. Review current AML law, executive regulations, supervisor rulebooks, UAEFIU report guides, portal instructions, and circulars. A VASP must also follow its own supervisor’s requirements. Seek qualified advice for a specific business model or reporting decision. The MLRO should also review a sample of closed alerts and filed reports to confirm that narratives are clear, decisions are supported, and portal requests are answered on time.

FAQs

Are VASPs included in UAE FIU reporting obligations?

The current AML law includes VASPs among entities required to report suspicion to the FIU through the designated electronic system or another approved means.

Does goAML registration replace a VASP licence?

No. FIU reporting access and the licence, registration, or enrolment needed to conduct virtual-asset activities are separate requirements.

Must a VASP report suspicious activity below a particular transaction value?

The current AML law states that the reporting duty applies regardless of transaction value when the relevant suspicion standard is met.

What if the VASP does not have every transaction detail?

Preserve and submit available relevant information, document what is missing and what was done to obtain it, and follow the current FIU instructions. Do not fabricate details.

Does a wallet analytics alert automatically require an STR?

Not by itself. Review the alert alongside customer and transaction context, document the assessment, and apply the legal reporting standard.