Blog Image

goAML UAE 2026: New AML Requirements & Reporting Guide

UAE goAML 2026: New AML Requirements, Reporting Changes & Compliance Guide The UAE’s AML compliance landscape has become more demanding in 2026. For businesses operating as Designated Non-Financial Businesses and Professions (DNFBPs), having a goAML account is no longer something to treat as a one-time registration task. Businesses need to understand their reporting obligations, maintain appropriate AML/CFT controls, identify suspicious activity and ensure that their compliance officer or MLRO can respond appropriately when concerns arise. There is also an important regulatory development to be aware of: the UAE Ministry of Economy & Tourism now lists Federal Decree-Law No. (10) of 2025 on combating money laundering, terrorist financing and proliferation financing, together with Cabinet Decision No. (134) of 2025 implementing the law. This makes goAML UAE 2026 a strong topic for businesses that want to understand what they need to do now rather than relying on older AML guidance.

What Is goAML in the UAE?

goAML is the electronic reporting platform used by the UAE Financial Intelligence Unit (FIU) to receive applicable suspicious transaction and suspicious activity reports. The UAE FIU’s current portal allows reporting entities to obtain access to goAML and use the system for filing Suspicious Transaction Reports (STRs) and Suspicious Activity Reports (SARs). For DNFBPs, goAML forms part of a broader AML/CFT compliance framework that includes customer due diligence, beneficial-owner identification, risk assessment, transaction monitoring and suspicious activity reporting.

What Has Changed for AML Compliance in the UAE in 2026?

One of the most important developments is the UAE’s updated AML/CFT/CPF legislative framework. The Ministry of Economy & Tourism currently lists: Federal Decree-Law No. (10) of 2025 Cabinet Decision No. (134) of 2025 concerning its Executive Regulations Cabinet Decision No. (109) of 2023 concerning beneficial owners Cabinet Decision No. (132) of 2023 concerning administrative sanctions as part of the UAE’s financial-crime legislation framework. For businesses, this means AML compliance should be reviewed against the current 2026 framework, rather than relying solely on older checklists or procedures.

Who Needs to Register for goAML?

Businesses that fall within the applicable reporting-entity framework need to understand whether they must register and report through goAML. DNFBP categories include sectors such as: Real estate brokers and agents Dealers in precious metals and precious stones Independent accountants and auditors Corporate and trust service providers Other applicable regulated professional activities The Ministry provides sector-specific AML resources and goAML guidance for DNFBPs. The FIU portal also states that reporting entities under various supervisory bodies, as well as certain commercial entities not directly regulated by a specific authority, are expected to follow the goAML access and registration process where applicable.

Is goAML Registration Mandatory?

For DNFBPs that fall within the applicable reporting requirements, registration is mandatory. The Ministry’s goAML information states that DNFBPs must register on the goAML platform so they can submit applicable STRs and SARs. Businesses should not assume that having a trade licence automatically means they need goAML registration. The first step is determining whether the company’s activities fall within a DNFBP or other reporting-entity category.

Is goAML Registration Free?

Yes. The Ministry’s technical instructions state that goAML registration is free. However, businesses may incur separate costs if they engage an external AML consultant, Compliance Officer, MLRO or service provider to assist with registration and ongoing compliance.

What Are the Current goAML Registration Steps?

The current Ministry instructions outline the registration process. Generally, the process involves:

1. Complete Pre-Registration

The reporting entity begins the applicable pre-registration process.

2. Access the Portal

The Ministry’s current instructions direct applicants to access the relevant portal and select the appropriate production environment.

3. Log In

Applicants use the credentials and authentication method provided during the pre-registration stage.

4. Register the Organisation

Select “Register a New Organisation” and enter the required company information.

5. Upload Supporting Documents

The required supporting documents should be uploaded accurately.

6. Submit the Application

Review the information before submitting the registration request.

7. Track the Application

The Ministry states that applicants receive a reference number and are notified by email whether the application has been approved or rejected. If rejected, the Ministry advises applicants to repeat the process from the pre-registration stage.

What Documents Are Required for goAML Registration?

The exact requirements can vary according to the reporting entity and registration process. The Ministry’s goAML information identifies documents such as: Authorisation letter Passport copy UAE residence visa Emirates ID Trade licence for companies Required authentication setup The Ministry also advises applicants to carefully check the supporting documents before submitting the application. Incorrect company information or incomplete documentation can lead to delays or rejection.

What Does goAML Reporting Actually Mean?

goAML registration and goAML reporting are not the same thing. Registration gives the reporting entity access to the system. Reporting is the process of submitting applicable information to the FIU when a suspicious transaction, suspicious activity or other reportable circumstance arises. The current March 2026 DNFBP guidance states that DNFBPs are required to promptly report suspicious transactions or attempted transactions where the applicable suspicion or reasonable grounds to suspect exist.

STR vs SAR: Which Report Should You File?

Suspicious Transaction Report — STR

An STR is used to report a suspicious transaction where the applicable reporting threshold is met.

Suspicious Activity Report — SAR

A SAR is used for applicable suspicious activity or attempted transactions. The appropriate report type depends on the circumstances and the reporting requirements applicable to the entity. The UAE FIU’s goAML system supports the filing of STRs and SARs.

How Quickly Must Suspicious Activity Be Reported?

This is one of the areas businesses should take seriously. The March 2026 DNFBP guidance states that DNFBPs are required to report STRs/SARs to the FIU without delay. It explains that once the Compliance Officer confirms that a transaction is suspicious, the report should be submitted immediately. Businesses should therefore have an internal escalation process that allows employees to raise potential suspicious activity quickly.

What Happens If a Business Fails to Report Suspicious Activity?

The consequences can be serious. The March 2026 DNFBP guidance states that failure to report a suspicious transaction without delay, whether intentionally or through gross negligence, is a federal crime under the UAE AML/CFT/CPF framework and may result in applicable sanctions. This is why goAML should not be treated simply as an administrative registration requirement. The business needs an operational AML framework behind the account.

What Is the Role of the MLRO?

The Money Laundering Reporting Officer (MLRO) or designated Compliance Officer plays an important role in the suspicious reporting process. Responsibilities can include: Reviewing suspicious activity Investigating internal alerts Assessing customer risk Reviewing KYC and CDD information Assessing suspicious transactions Deciding whether reporting is required Filing applicable reports Maintaining confidentiality Responding to FIU requests Maintaining appropriate records The March 2026 guidance specifically states that the designated Compliance Officer reviews and scrutinises records and suspicious transaction information before deciding whether to notify the FIU or maintain the transaction with reasons documented. New 2026 Focus: Proliferation Financing One area businesses should not overlook is countering the financing of proliferation (CPF). The updated UAE framework addresses money laundering, terrorist financing and proliferation financing. The March 2026 DNFBP guidance also highlights targeted financial sanctions related to proliferation financing, including screening, freezing without delay and reporting obligations that apply alongside the AML/CFT framework. This means AML compliance programmes should not focus exclusively on traditional money-laundering risks.

High-Risk Countries: What Businesses Need to Watch

Geographic risk remains an important part of AML compliance. The Ministry’s current AML resources include Circular No. (1) of 2026 updating the lists of high-risk countries, countries subject to increased monitoring and related measures. Businesses should therefore make sure that their AML procedures do not rely on an outdated high-risk-country list. This is particularly important for businesses dealing with: International customers Cross-border payments Overseas beneficial owners International property transactions High-value transactions Customers with links to higher-risk jurisdictions

Beneficial Ownership Is Still Critical

Identifying the Ultimate Beneficial Owner (UBO) remains an important component of UAE AML compliance. A company should understand who ultimately owns or controls its customer and whether the ownership structure makes commercial sense. Complex ownership structures should not automatically be considered suspicious, but they can require enhanced scrutiny depending on the circumstances and customer risk. Businesses should ensure that their UBO records and procedures are aligned with the applicable UAE requirements.

Common goAML Mistakes Businesses Make

Treating Registration as the Entire AML Requirement

Having a goAML account does not mean the company has completed its AML obligations.

Using an Outdated AML Policy

The UAE’s legal and regulatory framework has evolved. Businesses should review policies against the current requirements.

Not Updating High-Risk Country Lists

High-risk and increased-monitoring lists can change.

Weak Customer Due Diligence

Collecting an Emirates ID or passport alone does not necessarily constitute an effective risk-based CDD process.

No Internal Reporting Procedure

Employees should know how to escalate suspicious activity to the Compliance Officer or MLRO.

Delayed Reporting

The March 2026 guidance specifically requires applicable STR/SAR reporting without delay.

Ignoring Tipping-Off Restrictions

The March 2026 guidance makes clear that protections for good-faith reporting do not extend to unlawful disclosure to customers or other persons that a report has been or will be filed.

2026 goAML Compliance Checklist

Use this as a starting point for reviewing your AML framework: Confirm whether your business is a DNFBP Complete applicable goAML registration Appoint a Compliance Officer/MLRO Maintain an AML/CFT/CPF risk assessment Maintain KYC procedures Identify and verify UBOs Apply customer risk classification Maintain transaction-monitoring procedures Maintain suspicious activity escalation procedures Keep STR/SAR reporting procedures Monitor high-risk jurisdictions Implement applicable targeted financial sanctions screening Maintain staff AML training Protect STR/SAR information Maintain appropriate AML records Review AML policies when regulations change

What Should Businesses Do in 2026?

If your business already has goAML registration, this is a good time to conduct a full AML compliance review rather than assuming the existing setup is sufficient. Review:

Your business classification

Are your current activities correctly classified?

Your AML risk assessment

Does it reflect your actual customers, services, jurisdictions and transaction patterns?

Your KYC process

Are you collecting and verifying the information you actually need?

Your UBO records

Can you identify who ultimately owns or controls your customers?

Your sanctions screening

Are your screening processes updated?

Your high-risk-country controls

Are you using current lists and measures?

Your STR/SAR procedures

Can suspicious activity be escalated and reported without delay?

Your MLRO function

Is the responsible person actually able to perform the required compliance duties?

Final Thoughts

goAML UAE 2026 is more than a registration requirement. It is part of a broader AML/CFT/CPF compliance framework that businesses need to manage continuously. The UAE’s current framework includes updated 2025 legislation and 2026 guidance, while the ministry continues to publish updates relating to high-risk jurisdictions, sanctions, reporting and DNFBP compliance. For DNFBPs, the priority should be to make sure that registration, AML risk assessment, KYC, UBO verification, sanctions screening, transaction monitoring, internal escalation and FIU reporting all work together. If your company has never registered for goAML, or if your existing AML framework has not been reviewed recently, 2026 is a good time to conduct a compliance review. Need help with goAML registration or UAE AML compliance? Speak with an AML consultant before submitting your application.

Frequently Asked Questions

Is goAML registration mandatory in the UAE?

For businesses that fall within the applicable reporting-entity and DNFBP requirements, registration is mandatory. The Ministry states that DNFBPs must register on goAML to submit applicable STRs and SARs.

Is goAML registration free?

Yes. The Ministry’s technical instructions state that goAML registration is free.

What is goAML used for?

goAML is used by applicable reporting entities to submit suspicious transaction and suspicious activity reports to the UAE FIU.

What is an STR?

An STR is a Suspicious Transaction Report submitted when the applicable requirements for reporting a suspicious transaction are met.

What is a SAR?

An SAR is a Suspicious Activity Report, used for applicable suspicious activity or attempted transactions.

How quickly must an STR or SAR be submitted?

The March 2026 DNFBP guidance states that applicable STRs/SARs must be reported to the FIU without delay.

Does every UAE company need goAML registration?

Not necessarily. The requirement depends on the company’s activities and regulatory classification. Businesses should first determine whether they fall within a DNFBP or another applicable reporting-entity category.

What are the consequences of not reporting suspicious transactions?

The March 2026 DNFBP guidance states that failure to report a suspicious transaction without delay, intentionally or through gross negligence, is a federal crime and may result in sanctions.

Does goAML registration mean my company is AML compliant?

No. Registration is only one component of AML compliance. Businesses may also need risk assessments, KYC/CDD, UBO identification, sanctions screening, transaction monitoring, staff training, internal reporting procedures and appropriate record keeping.

What changed in UAE AML compliance in 2026?

The UAE’s current legislative framework includes Federal Decree-Law No. (10) of 2025 and Cabinet Decision No. (134) of 2025, while the Ministry has also issued updated 2026 guidance and circulars relevant to DNFBPs.

Can an external consultant help with goAML registration?

Yes. A business can obtain professional assistance with registration and AML compliance, but the company remains responsible for meeting its applicable legal and regulatory obligations.