goAML Reporting UAE: Complete Guide for Businesses in 2026
Businesses operating in regulated sectors in the UAE need to understand their responsibilities for identifying and reporting suspicious transactions and activities. For relevant Designated Non-Financial Businesses and Professions (DNFBPs), the UAE’s goAML system is the electronic platform used to submit applicable reports to the Financial Intelligence Unit (FIU). GoAML reporting is not simply about completing an online form. A business needs appropriate procedures to identify suspicious activity, investigate potential red flags, document its findings, and determine whether a report should be submitted. The UAE Ministry of Economy & Tourism’s current DNFBP guidance identifies Suspicious Transaction Reports (STRs) and Suspicious Activity Reports (SARs) as the primary report types for new suspicions, with additional report types available when further information is requested by the FIU.
What Is goAML Reporting in the UAE?
‘goAML reporting’ refers to the electronic submission of applicable AML/CFT reports through the UAE Financial Intelligence Unit’s goAML platform. The platform allows relevant reporting entities to submit the following: Suspicious Transaction Reports (STRs) Suspicious Activity Reports (SARs) Additional Information Files (AIF) Additional Information Files with Transactions (AIFT) Requests for Information (RFI) High-Risk Country Transaction Reports (HRC), where applicable The UAE FIU states that the goAML portal enables reporting entities to access the system and file STRs and/or SARs. For DNFBPs, goAML reporting forms part of the wider UAE AML/CFT compliance framework.
Who Needs to Use goAML Reporting?
The requirement depends on the nature of the business and its regulatory classification. Relevant DNFBPs can include: Real estate brokers and agents Dealers in precious metals and precious stones Independent accountants and auditors Trust and company service providers The Ministry of Economy & Tourism provides sector-specific AML/CFT guidance and goAML resources for these businesses. Not every UAE company is automatically subject to identical reporting obligations. Businesses should first determine whether their activity falls within the applicable reporting-entity or DNFBP framework.
What Is an STR in goAML?
STR stands for Suspicious Transaction Report. An STR is used when a DNFBP suspects that a transaction may be connected with money laundering, a predicate offence, terrorist financing or illegal organisations. The current UAE DNFBP guidance states that an STR is applicable where the relevant suspicion arises during the establishment or course of a business relationship or while carrying out a transaction for or on behalf of a customer or occasional customer. An STR should explain the basis for the suspicion using the information available to the reporting entity.
What is a SAR in goAML?
SAR stands for Suspicious Activity Report. A SAR applies to suspicious activity or an attempted transaction that has not been completed where the relevant circumstances indicate a possible connection with money laundering, predicate offences, terrorist financing or illegal financing. The UAE’s current DNFBP guidance distinguishes SARs from STRs based on the nature of the suspicious conduct being reported. Understanding the distinction is important because selecting the correct report type is part of effective goAML reporting.
STR vs SAR: What Is the Difference?
The distinction can be simplified as follows: Report Generally used for STR Suspicious transaction SAR Suspicious activity or attempted transaction AIF Additional non-transactional information requested by the FIU AIFT Additional information involving transaction details RFI Response to a request for information HRC Applicable transactions involving high-risk countries
The UAE’s current guidance specifically advises compliance officers, MLROs and relevant employees to understand the different report types and select the appropriate type when submitting information through goAML.
When Should a Business File an STR or SAR?
A business should have procedures for identifying suspicious activity and escalating it to the compliance officer or MLRO. Potential indicators can include: Transactions inconsistent with the customer’s profile Unexplained third-party payments Unusual cash activity Complex ownership structures Unexplained changes in business activity High-risk jurisdiction exposure Unclear source of funds Difficulty identifying the beneficial owner False, misleading or questionable documents Transactions without a clear economic purpose A red flag does not automatically mean that an STR or SAR must be filed. The circumstances should be investigated and assessed against the customer’s risk profile. The UAE guidance explains that some suspicious indicators may require internal investigation before reasonable grounds for suspicion are established, but the investigation should begin immediately and continue without unnecessary delay.
Is There a Minimum Amount for an STR in the UAE?
Businesses should not rely on a minimum transaction value when deciding whether suspicious activity needs to be reported. The current UAE DNFBP guidance states that suspicious transactions and attempted transactions can fall within the reporting requirement regardless of the monetary amount when the applicable suspicion or reasonable-grounds standard is met. Therefore, a relatively small transaction should not automatically be ignored simply because its value is low.
How Does goAML Reporting Work?
A typical internal reporting process involves several stages.
Identify the Red Flag
Employees or monitoring systems identify activity that appears unusual or inconsistent with the customer’s profile.
Review the Customer
The Compliance Officer or MLRO reviews relevant KYC, CDD, UBO and risk information.
Investigate the Activity
The business considers the purpose of the transaction, parties involved, source and destination of funds and other relevant circumstances.
Determine Whether Suspicion Exists
The MLRO assesses whether the available information creates reasonable grounds for suspicion.
Select the Appropriate Report
If reporting is required, the business selects the applicable report type, such as an STR or SAR.
Submit Through goAML
The report is submitted electronically through the UAE FIU’s goAML system.
Maintain Records
The business should retain appropriate records relating to the investigation and reporting process.
What Information Should an STR or SAR Contain?
A good report should provide enough information for the FIU to understand why the activity is considered suspicious. The UAE’s guidance on STR/SAR narrative reporting recommends presenting relevant information in a clear and chronological structure. Areas can include: Summary of findings Parties involved Identification information Purpose of the report Description of the suspected violation Suspicious transactions Dates and amounts Source and destination of funds Reasons for suspicion Relevant red flags Actions taken Previous STR/SAR references Sanctions or watchlist links, if applicable Additional information available to authorities The guidance emphasises that the narrative should clearly communicate the basis for the report.
How to Write a Good goAML Narrative
The narrative is one of the most important parts of an STR or SAR. Instead of simply writing: “The transaction appears suspicious.” the report should explain the circumstances that led to the suspicion. A useful narrative can answer: Who? Who are the parties involved? What? What transaction or activity occurred? When? When did the activity take place? Where? Where did the funds or activity originate, and where were they directed? Why? Why does the activity appear unusual or suspicious? How? How was the activity conducted? What action was taken? What did the business do after identifying the red flags? The information should be factual, concise, and supported by the records available to the business.
What Is the Role of the MLRO in goAML Reporting?
The Money Laundering Reporting Officer (MLRO) or Compliance Officer plays a central role in the reporting process. The compliance officer’s responsibilities can include the following: Reviewing suspicious transaction information Investigating potential red flags Assessing customer risk Deciding whether an STR or SAR is required Submitting reports through goAML Responding to FIU requests Maintaining confidentiality Keeping appropriate records The UAE’s DNFBP guidance specifically states that the compliance officer is responsible for reviewing, scrutinising and studying records and receiving data concerning suspicious transactions before deciding whether to notify the FIU.
What Are AIF and AIFT Reports?
Sometimes the FIU may require additional information after an STR or SAR has been submitted. AIF An Additional Information File (AIF) is used to provide additional information that does not contain transaction details. AIFT An Additional Information File with Transactions (AIFT) is used where additional information includes transaction details. The current DNFBP guidance states that AIF and AIFT submissions should reference the original STR or SAR submission number.
What is an RFI in goAML?
RFI means Request for Information. The FIU may request information from one or more reporting entities through the goAML Message Board. Depending on the request, the reporting entity may need to submit: RFI without transactions RFI with transactions Businesses should monitor their goAML communications and respond to applicable requests within the required timeframe.
What Is an HRC Report?
‘HRC’ refers to a High-Risk Country Transaction Report. Where applicable, a DNFBP may have additional reporting obligations relating to transactions involving high-risk countries or jurisdictions. The UAE’s current guidance explains that the applicable HRC reporting process applies where the relevant high-risk-country criteria are met. Businesses should monitor the UAE’s current high-risk-country lists and applicable regulatory instructions because these can change.
goAML Reporting and High-Risk Countries
Geographic risk is an important consideration in AML compliance. A transaction involving a high-risk jurisdiction is not automatically suspicious. The business should consider: Customer’s connection to the jurisdiction Purpose of the transaction Source and destination of funds Nature of the business Ownership structure Expected transaction activity Where additional reporting requirements apply, the business should follow the relevant FIU and supervisory-authority procedures.
goAML Reporting for Real Estate Businesses
Real estate businesses can face particular AML risks because transactions may involve high-value properties, international customers and complex ownership arrangements. Potential red flags include: Property purchases inconsistent with customer wealth Unexplained third-party payments Unusual cash involvement Complex ownership structures Rapid property transactions without an obvious commercial purpose Unexplained sources of funds The Ministry provides specific AML/CFT red-flag resources and reporting guidance for real estate brokers and agents.
goAML Reporting for Precious Metals Businesses
Dealers in precious metals and precious stones may encounter risks associated with high-value and easily transferable assets. Businesses should pay attention to the following: Unusually large transactions Unexplained cash payments Third-party payments Transactions inconsistent with the customer’s profile Unusual geographic exposure Customers refusing required information The Ministry provides sector-specific red flags and case studies for this category of DNFBP.
goAML Reporting for Accountants and Auditors
Accountants and auditors can encounter complex financial arrangements, corporate structures and transactions. Potential reporting concerns can include: Unclear beneficial ownership Unexplained financial structures Transactions without a clear purpose Unusual third-party arrangements Inconsistent customer information Unexpected changes in business activity The Ministry provides dedicated AML/CFT resources for independent accountants and auditors.
goAML Reporting for Company Service Providers
Trust and company service providers can face risks related to company formation and corporate structures. Potential concerns include: Complex ownership structures Difficulty identifying the UBO Unexplained nominee arrangements Companies with no apparent commercial purpose Frequent ownership changes Multiple high-risk jurisdictions The business should assess these risks as part of its wider customer due diligence and AML framework.
Confidentiality and Tipping Off
Confidentiality is an important part of suspicious transaction reporting. Businesses should not disclose the existence or contents of a suspicious transaction report to the customer or other unauthorised parties where doing so would amount to prohibited tipping-off. The UAE DNFBP guidance specifically addresses confidentiality and the prohibition against tipping off in connection with STR/SAR reporting. Employees should therefore understand who is authorised to access reporting information and how suspicious activity investigations must be handled.
Common goAML Reporting Mistakes
Selecting the Wrong Report Type
Businesses should understand the difference between STR, SAR, AIF, AIFT, RFI and other applicable report types.
Providing a Weak Narrative
A report should clearly explain the reasons for suspicion rather than simply describing a transaction.
Ignoring Customer Context
The transaction should be assessed against the customer’s risk profile and expected activity.
Delaying Internal Escalation
Employees should know how and when to escalate potential suspicious activity to the MLRO.
Failing to Keep Supporting Records
The business should retain appropriate documentation supporting its investigation and reporting decision.
Breaching Confidentiality
Information relating to an STR or SAR should be handled confidentially and shared only with authorised persons.
goAML Reporting Compliance Checklist
Before relying on your goAML reporting process, check that your business has: Completed applicable goAML registration Appointed an appropriate Compliance Officer/MLRO AML/CFT risk assessment Customer risk classification KYC procedures CDD procedures UBO verification procedures Transaction-monitoring procedures Suspicious activity escalation procedures STR/SAR reporting procedures Appropriate goAML access Staff AML training Confidentiality controls Record-keeping procedures Procedures for responding to FIU requests
Final Thoughts
goAML reporting in UAE is an important part of the AML/CFT framework for businesses subject to suspicious transaction and activity reporting requirements. For relevant DNFBPs, the process involves much more than submitting a report through an online portal. Businesses need an effective internal framework for identifying red flags, conducting appropriate investigations, escalating concerns to the MLRO and documenting their decisions. The UAE’s current guidance identifies STRs and SARs as the primary report types for new suspicions, while AIF, AIFT and RFI reports can be used when additional information is required. Businesses should also understand the importance of accurate narratives, confidentiality, timely reporting and appropriate record keeping. If your business is required to use goAML, maintaining an active registration is only the starting point. Effective compliance requires ongoing KYC, customer due diligence, risk assessment, transaction monitoring, sanctions screening and suspicious activity procedures.
Frequently Asked Questions
What is goAML reporting in the UAE?
goAML reporting is the electronic process used by relevant reporting entities to submit applicable suspicious transaction and suspicious activity reports to the UAE Financial Intelligence Unit.
Who needs to submit reports through goAML?
The requirement depends on the business’s regulatory classification and activities. Relevant DNFBPs and other reporting entities subject to UAE AML/CFT requirements use goAML for applicable reporting.
What is an STR?
An STR, or Suspicious Transaction Report, is used when a reporting entity suspects that a transaction may be connected with money laundering, a predicate offence, terrorist financing or illegal organisations.
What is a SAR?
A SAR, or Suspicious Activity Report, is used for applicable suspicious activity or attempted transactions that have not been completed.
Is goAML reporting mandatory in the UAE?
Where a business is subject to the applicable AML/CFT reporting requirements, reporting through the prescribed FIU system is mandatory.
Is there a minimum amount for filing an STR?
Businesses should not rely on a minimum monetary threshold. Where the applicable suspicion or reasonable-grounds standard is met, suspicious transactions and attempted transactions may need to be reported regardless of their value.
Who submits an STR through goAML?
The Compliance Officer or MLRO generally manages the suspicious transaction reporting process for the reporting entity. The UAE guidance specifically identifies the Compliance Officer as responsible for reviewing suspicious transaction information and deciding whether to notify the FIU.
What information should be included in a goAML report?
A report should provide relevant information about the parties, transaction, source and destination of funds, reasons for suspicion, red flags, actions taken and other information that may assist the FIU.
What happens after an STR is submitted?
The FIU may request additional information from the reporting entity. Depending on the request, the business may need to submit an AIF, AIFT or RFI through goAML.
Can a business tell the customer that an STR has been filed?
Businesses need to comply with confidentiality requirements and the prohibition against tipping off. Information relating to suspicious transaction reporting should be handled appropriately and not disclosed to unauthorised persons.
How can a business improve its goAML reporting process?
A business should maintain clear AML procedures covering KYC, customer risk assessment, transaction monitoring, internal escalation, MLRO review, STR/SAR submission, confidentiality and record keeping.