Blog Image

goAML RFI UAE: What Is a Request for Information?

If your business is registered on goAML in the UAE, you may eventually receive an RFI, or Request for Information, through the goAML Message Board.

For businesses and compliance officers, receiving an RFI can be confusing. Does it mean the business has done something wrong? Is it the same as an STR? What information needs to be submitted? How quickly should you respond?

The short answer is that an RFI is a formal request from the UAE Financial Intelligence Unit (FIU) for additional information. Under the Ministry of Economy & Tourism's current guidance, an RFI can be sent when the FIU seeks information from multiple DNFBPs, rather than only the entity that originally submitted an STR or SAR. The receiving DNFBP is expected to submit the requested information through goAML.

This guide explains what a goAML RFI means, how it differs from an STR, AIF and AIFT, what businesses should do after receiving one, and how to avoid common mistakes when responding.

What Is an RFI in goAML?

RFI stands for Request for Information.

It is a request sent through the goAML Message Board when the FIU requires additional information from one or more reporting entities.

The Ministry of Economy & Tourism's current DNFBP guidance specifically distinguishes an RFI from an AIF or AIFT.

An RFI without transactions is used where the FIU seeks further information from multiple DNFBPs, rather than only the entity that submitted the original STR or SAR. The DNFBPs receiving the request are required to submit an RFI report through goAML.

In practical terms, an RFI means:

The FIU needs information from your business to support its analysis or investigation.

Receiving an RFI does not automatically mean that your business is accused of money laundering or another offence.

It means the FIU is requesting information relevant to its work.

Why Would the FIU Send an RFI?

The FIU analyses information received through the UAE's suspicious transaction reporting framework.

An RFI may be used when information held by one reporting entity is not enough, or when the FIU needs information from other businesses that may have dealt with the relevant customer, transaction, company or activity.

For example, an FIU analysis may identify a customer or business that has relationships with several DNFBPs.

The FIU may therefore need information from more than one reporting entity.

Possible information requested could relate to:

  • Customer identity
  • Business relationship
  • Customer activity
  • Beneficial ownership
  • Transactions
  • Source of funds
  • Source of wealth
  • Supporting documents
  • Nature of a business relationship
  • Specific transactions or activities

The exact information depends on the RFI.

Your business should therefore read the request carefully and respond to the information actually requested.

Is an RFI the Same as an STR?

No.

An STR, or Suspicious Transaction Report, is submitted by a reporting entity when it identifies a suspicious transaction or activity that meets the applicable reporting threshold.

An RFI works differently.

An RFI is a request for information from the FIU.

The distinction is important:

Report / RequestPurpose
STRReport suspicious transaction(s) or activity
SARReport suspicious activity, including attempted transactions where applicable
AIFProvide additional non-transactional information requested by the FIU
AIFTProvide additional information including transaction details
RFIProvide information requested from reporting entities, including entities beyond the original reporting entity

The Ministry's current guidance explains that an AIF or AIFT can be requested while the FIU is reviewing an existing STR or SAR, whereas an RFI may be sent to multiple DNFBPs when the FIU seeks further information.

RFI vs AIF vs AIFT: What's the Difference?

These terms are easy to confuse.

RFI — Request for Information

An RFI is used when the FIU seeks information from multiple DNFBPs.

The receiving business submits an RFI report through goAML.

AIF — Additional Information File

An AIF is used when the FIU requests non-transactional supplementary information relating to an existing STR or SAR.

The original reporting entity receives the request through the goAML Message Board and provides the additional information through an AIF report.

AIFT — Additional Information File With Transactions

An AIFT is used when the FIU requests additional information that includes transactional details relating to an existing STR or SAR.

The reporting entity provides the requested transaction information through an AIFT report.

Understanding this distinction helps the Compliance Officer determine what type of response is required.

Where Do You Receive a goAML RFI?

An RFI is sent through the goAML Message Board.

The UAE Ministry of Economy & Tourism explains that goAML is the system used by the FIU to receive and process applicable reports from DNFBPs and other reporting entities.

Therefore, your Compliance Officer or authorised goAML user should regularly check the system for:

  • New messages
  • RFI requests
  • AIF requests
  • AIFT requests
  • FIU communications
  • Reporting updates

Businesses should not rely only on informal internal communication to identify an FIU request.

What Should You Do When You Receive an RFI?

Don't ignore it.

The first step is to read the RFI carefully and identify exactly what information the FIU is requesting.

A practical response process can look like this:

Step 1: Review the RFI

Read the request carefully.

Identify:

  • Customer name
  • Relevant entity
  • Transaction or activity
  • Period covered
  • Documents requested
  • Information requested
  • Any specific questions
  • Submission instructions
  • Applicable deadline

Do not assume that every RFI requires the same information.

Step 2: Assign Responsibility

The Compliance Officer or MLRO should coordinate the response.

Depending on the request, information may need to be obtained from:

  • Compliance
  • Finance
  • Accounts
  • Sales
  • Customer service
  • Management
  • Legal
  • Operations

The response should be centrally controlled rather than allowing different departments to provide inconsistent information.

Step 3: Gather the Relevant Records

Collect the documents and information requested.

Depending on the nature of the RFI, this could include:

  • Customer identification records
  • KYC documents
  • Beneficial ownership information
  • Transaction records
  • Contracts
  • Invoices
  • Payment information
  • Correspondence
  • Customer risk assessment
  • Source-of-funds information
  • Source-of-wealth information

Only provide information that is relevant and requested, unless additional information is necessary to accurately answer the request.

Step 4: Verify the Information

Before submission, check the information carefully.

Look for:

  • Incorrect dates
  • Name mismatches
  • Missing transactions
  • Duplicate documents
  • Inconsistent customer information
  • Incorrect amounts
  • Missing supporting records

An inaccurate response can create additional questions and unnecessary compliance risk.

Step 5: Submit Through goAML

The requested information should be submitted through the appropriate goAML reporting process.

The Ministry's guidance states that DNFBPs receiving an RFI are required to submit an RFI report through goAML.

Step 6: Keep an Internal Record

Maintain an internal record of:

  • RFI received
  • Date received
  • Person responsible
  • Information requested
  • Documents collected
  • Review performed
  • Date submitted
  • Submission reference
  • Any follow-up communication

This creates an audit trail for the business.

What Information Can Be Requested in an RFI?

There is no single universal checklist because an RFI is tailored to the FIU's information requirements.

Depending on the circumstances, a request could potentially concern:

Customer Information

  • Full name
  • Identification documents
  • Nationality
  • Address
  • Contact information
  • Customer profile

Beneficial Ownership

  • Ultimate beneficial owner
  • Ownership structure
  • Control structure
  • Corporate documents

Business Relationship

  • Purpose of the relationship
  • Services provided
  • Date of onboarding
  • Nature of the customer's business
  • Expected activity

Transactions

Where transaction information is requested, the business may need to provide:

  • Date
  • Amount
  • Currency
  • Sender
  • Recipient
  • Payment method
  • Account details
  • Transaction purpose
  • Supporting documents

Source of Funds or Wealth

The FIU may seek information relevant to understanding the source of funds or wealth associated with the activity.

The exact scope depends on the request.

What If You Don't Have the Requested Information?

Don't simply ignore the request.

If your business genuinely does not hold the requested information, the response should accurately explain the situation and provide whatever relevant information is available.

For example, there may be circumstances where:

  • The person was never a customer
  • The transaction did not occur through your business
  • Records are no longer held
  • The requested information does not apply
  • The business cannot identify the referenced transaction

The important principle is accuracy and transparency.

Never manufacture information simply because the FIU has requested it.

What If the Information Is Held by Another Department?

This is a common practical issue.

For example, the Compliance Officer may receive an RFI requesting invoices, while the invoices are held by the finance department.

The Compliance Officer should coordinate internally and ensure that the final response is reviewed before submission.

A good internal process is:

RFI received → Compliance review → Information gathering → Verification → Management/internal review where appropriate → goAML submission → Record retention

This reduces the risk of contradictory or incomplete responses.

Does Receiving an RFI Mean You Have to File an STR?

Not necessarily.

An RFI and an STR serve different purposes.

Receiving an RFI does not automatically mean that your business must submit an STR.

However, while responding to an RFI, your Compliance Officer may identify information that creates or strengthens a suspicion of money laundering, terrorist financing or other relevant financial crime.

In that situation, the business should assess its reporting obligations independently.

The decision to file an STR/SAR should be based on the applicable AML/CFT/CPF framework and the facts of the case—not simply because an RFI was received.

Can You Tell the Customer About the RFI?

This is an area where businesses need to be particularly careful.

AML/CFT rules contain confidentiality and tipping-off requirements.

A business should not casually disclose an FIU request to the customer or another unauthorised person.

The Compliance Officer should determine what information can be shared internally and externally based on applicable UAE requirements and the circumstances of the case.

Staff should not discuss an RFI with the customer unless there is a clear legal and compliance basis for doing so.

Common Mistakes When Responding to an RFI

1. Ignoring the Message Board

A business may miss the request because nobody checks goAML regularly.

Better approach: Establish a formal process for monitoring the system.

2. Providing Incomplete Information

Submitting only part of the requested information can lead to further enquiries.

Better approach: Create a checklist from the RFI before gathering documents.

3. Providing Incorrect Information

Incorrect transaction dates or amounts can undermine the response.

Better approach: Reconcile information against the underlying records.

4. Sending Unverified Documents

Documents should be reviewed before submission.

Better approach: Ensure that the information is authentic, relevant and internally consistent.

5. Treating the RFI Like an STR

An RFI is not simply another STR.

Better approach: Identify the report type requested by the FIU and follow the appropriate goAML process.

6. Discussing the RFI With the Customer

Unnecessary disclosure can create confidentiality and tipping-off concerns.

Better approach: Limit access to the matter to authorised personnel.

7. Failing to Keep an Internal Audit Trail

A business may respond successfully but have no record of what was submitted.

Better approach: Keep an internal RFI response file.

How Should an MLRO Manage an RFI?

The MLRO or Compliance Officer should treat an RFI as a controlled compliance matter.

A good internal procedure should cover:

  1. Monitoring the goAML Message Board
  2. Logging the RFI
  3. Identifying the responsible person
  4. Reviewing the scope
  5. Gathering records
  6. Verifying information
  7. Reviewing the response
  8. Submitting through goAML
  9. Recording the submission
  10. Handling any follow-up request

The response should be factual and evidence-based.

Avoid speculation.

If the FIU asks a specific question and your records do not support a definitive answer, explain what the records show rather than making assumptions.

RFI Response Checklist

When your business receives an RFI, use this checklist:

  •  RFI reviewed
  •  Request logged internally
  •  Relevant customer identified
  •  Relevant transactions identified
  •  Responsible Compliance Officer/MLRO assigned
  •  KYC documents collected
  •  Beneficial ownership information checked
  •  Relevant contracts/invoices collected
  •  Transaction records reconciled
  •  Source-of-funds information reviewed where relevant
  •  Requested documents verified
  •  Response reviewed internally
  •  Confidentiality considerations addressed
  •  RFI submitted through goAML
  •  Submission reference recorded
  •  Internal response file maintained
  •  Follow-up actions recorded

How Can Businesses Prepare for an RFI?

The easiest way to respond efficiently to an RFI is to maintain good AML records before an FIU request arrives.

Your business should maintain organised records relating to:

  • Customer identification
  • Customer due diligence
  • Beneficial ownership
  • Risk assessments
  • Transaction records
  • Source of funds
  • Source of wealth where applicable
  • Customer communications
  • Supporting documents
  • Previous compliance reviews

The Ministry of Economy & Tourism's current AML guidance emphasises effective AML/CFT/CPF compliance programmes and reporting processes for supervised DNFBPs.

Good record keeping means the Compliance Officer can retrieve relevant information quickly instead of trying to reconstruct a customer relationship months or years later.

Is an RFI a Sign of an AML Investigation?

Not necessarily.

An RFI means the FIU is requesting information.

The request may form part of the FIU's analysis of financial intelligence, but receiving an RFI alone does not establish that the business has committed an AML violation.

The appropriate response is therefore not to panic or speculate.

Instead:

Read → Verify → Gather → Review → Submit → Record

Treat the request seriously, but respond based on facts and documented evidence.

goAML RFI vs AIF vs AIFT: Quick Comparison

FeatureRFIAIFAIFT
Full nameRequest for InformationAdditional Information FileAdditional Information File With Transactions
Main purposeRequest information from reporting entitiesAdditional non-transactional informationAdditional information including transactions
Usually connected toFIU information gatheringExisting STR/SAR reviewExisting STR/SAR review
TransactionsDepends on request; RFI described by MoET as without transactions in the cited guidanceNo transaction detailsTransaction details included
Submitted throughgoAMLgoAMLgoAML
Who may receive it?Multiple DNFBPs may receive an RFIOriginal reporting entityOriginal reporting entity

The Ministry's current guidance specifically describes RFI without transactions as a request to multiple DNFBPs, while AIF and AIFT are used to obtain further information from the entity that submitted the original STR/SAR.

Frequently Asked Questions

What does RFI mean in goAML UAE?

RFI means Request for Information. It is a request sent through the goAML Message Board when the FIU requires additional information from reporting entities. Under the Ministry's current guidance, an RFI can be sent to multiple DNFBPs.

Is an RFI the same as an STR?

No. An STR is a suspicious transaction report submitted by a reporting entity. An RFI is a request from the FIU for information.

Why would the FIU send an RFI?

The FIU may need additional information from one or more reporting entities to support its analysis of financial intelligence or activity.

Where do I receive an RFI?

An RFI is communicated through the goAML Message Board.

How do I respond to an RFI in goAML?

Review the request, gather and verify the requested information, and submit the appropriate RFI report through the goAML platform.

What is the difference between RFI and AIF?

An RFI is used when the FIU seeks information from multiple DNFBPs. An AIF is used to provide additional non-transactional information requested in connection with an existing STR or SAR.

What is the difference between RFI and AIFT?

An AIFT is used when the FIU requests additional information that includes transaction details relating to an existing STR or SAR.

Does receiving an RFI mean my company is suspected of money laundering?

Not automatically. An RFI is a request for information. It should be handled seriously and confidentially, but receiving one does not by itself establish wrongdoing.

Do I need to file an STR after receiving an RFI?

Not automatically. An RFI and an STR have different purposes. However, if information obtained during the review gives rise to a reporting obligation, the business should assess the applicable STR/SAR requirements separately.

Can I tell my customer that the FIU requested information?

Businesses should be careful because AML/CFT confidentiality and tipping-off requirements may apply. The matter should be handled by the MLRO or Compliance Officer in accordance with applicable UAE requirements.

What if my business doesn't have the information requested?

Do not invent information. Explain accurately what records your business does or does not hold and provide relevant information that is available.

How should an MLRO manage an RFI?

The MLRO should log the request, identify the scope, coordinate information gathering, verify the response, submit it through goAML and retain an internal record of the response.

Final Thoughts

goAML RFI in the UAE is a formal Request for Information from the FIU. It is an important part of the UAE's financial intelligence and AML reporting framework.

For DNFBPs, the right response is not to ignore the request or immediately assume that the business is under investigation.

Instead, treat the RFI as a controlled compliance task.

Review the request carefully, gather the relevant records, verify the information, submit the response through goAML and maintain a clear internal audit trail.

The distinction between an RFI, AIF, AIFT, STR and SAR is also important. Each serves a different purpose within the reporting framework.

Most importantly, businesses should maintain accurate KYC, customer due diligence, beneficial ownership and transaction records on an ongoing basis. Good AML record keeping makes it significantly easier to respond when the FIU requests additional information.

If your business has received a goAML RFI and you are unsure what information should be provided or how to structure the response, obtaining professional AML compliance support can help ensure that the request is handled accurately, confidentially and within the applicable requirements.

This article is for general informational purposes and does not constitute legal or regulatory advice. UAE AML/CFT/CPF requirements and FIU/goAML procedures may change. Businesses should refer to the latest UAE legislation, supervisory guidance and official goAML instructions applicable to their sector.