How to Create an Internal Approval Process for goAML Reports
Submitting a report through goAML is an important compliance activity for businesses with applicable reporting obligations in the UAE. However, preparing a report should not necessarily be treated as a simple data-entry task.
Before a report is submitted, businesses can establish an internal approval process to review the information, supporting records, risk indicators, and reporting decision. A structured review can help identify incomplete information, inconsistencies, calculation errors, or documentation gaps before the report reaches the submission stage.
An internal approval process also helps establish clear responsibilities between employees who prepare, review, approve, and submit reports.
What Is an Internal Approval Process for goAML Reports?
An internal approval process is a set of procedures that a business uses to review a goAML report before final submission.
Instead of allowing one person to prepare and immediately submit a report, the business can introduce defined review stages.
A typical process may involve:
- Identifying the matter requiring reporting.
- Collecting relevant information.
- Preparing the report.
- Conducting an initial quality check.
- Performing an independent review.
- Resolving identified issues.
- Obtaining appropriate approval.
- Submitting the report.
- Retaining relevant records.
The exact structure should depend on the organisation's size, reporting responsibilities, risk profile, and internal compliance framework.
1. Define Who Is Responsible for Each Stage
The first step is to assign clear responsibilities.
Employees should understand who is responsible for preparing the report, who reviews it, who provides approval, and who performs the final submission.
For example, a business may establish separate responsibilities for:
- Report preparation
- Data verification
- Compliance review
- Management approval where applicable
- Final submission
- Record keeping
Smaller businesses may have fewer employees and therefore combine some responsibilities. However, the business should still clearly document who performs each activity.
2. Establish a Standard Reporting Workflow
A written workflow can make the approval process easier to follow.
The workflow should explain what happens from the initial identification of a reportable matter through to final submission.
A simple workflow could be:
Issue identified → Information collected → Report prepared → Quality review → Compliance review → Approval → Submission → Record retention
Having a consistent process reduces the possibility of employees skipping important review stages.
3. Create a Pre-Submission Checklist
A pre-submission checklist can help reviewers verify important information before a report is submitted.
Depending on the type of report, the checklist may cover:
- Customer identification information
- Beneficial ownership information where relevant
- Transaction details
- Dates and amounts
- Parties involved
- Relevant account information
- Reason for reporting
- Supporting documentation
- Narrative accuracy
- Internal review notes
- Required fields
The checklist should be tailored to the business's reporting procedures rather than treated as a generic form.
4. Verify Customer and Transaction Information
One of the most important stages is checking whether the information entered into the report is consistent with the business's records.
The reviewer can compare relevant information against internal systems and supporting documentation.
For example, the review may check:
- Customer name
- Identification details
- Company information
- Beneficial ownership information
- Transaction dates
- Transaction amounts
- Account information
- Counterparty information
Inconsistent information should be investigated and corrected before submission where appropriate.
5. Review the Reporting Narrative
The narrative is an important part of explaining why a report is being submitted.
A reviewer should check whether the narrative is clear, factual, and consistent with the information contained elsewhere in the report.
The review can consider whether the narrative:
- Clearly explains the relevant activity
- Identifies important dates
- Identifies relevant parties
- Describes relevant transactions
- Explains the reason for the reporting concern
- Avoids unsupported assumptions
- Matches the underlying records
A clear narrative can make the report easier to understand and review.
6. Check Supporting Documentation
Supporting records should be reviewed before final approval.
Depending on the circumstances, relevant records may include transaction information, customer documents, correspondence, account records, internal review notes, or other evidence supporting the reporting decision.
The business should establish a process for identifying which documents are relevant and ensuring that required records are retained according to its applicable procedures.
The approval process should also make clear whether documents need to be attached, referenced, or retained separately.
7. Introduce a Maker-Checker Approach
A maker-checker process can provide an additional layer of control.
The maker prepares the report, while the checker independently reviews the information before submission.
This separation can help identify errors that the original preparer may have overlooked.
The checker should not simply confirm that the report exists. The review should involve meaningful verification of the relevant information and reporting rationale.
For larger organisations, additional approval levels may be appropriate depending on the complexity or risk of the report.
8. Define Approval Criteria
Businesses should establish clear criteria for approving a report.
The approval process can require the reviewer to confirm that:
- Required information has been completed.
- Relevant information has been verified.
- Supporting records have been reviewed.
- The reporting rationale is documented.
- Identified errors have been resolved.
- Appropriate personnel have completed the review.
The business can document the approval using an internal workflow, electronic record, review log, or another suitable method.
9. Establish an Escalation Process
Not every report will be straightforward.
Employees may encounter incomplete information, conflicting records, unusual circumstances, or questions about the reporting decision.
The internal process should explain when an issue must be escalated to the appropriate compliance personnel or management.
For example, escalation may be required when:
- Important information cannot be verified.
- Records contain significant inconsistencies.
- The reporting rationale is unclear.
- Additional investigation is required.
- A high-risk issue is identified.
- The reviewer disagrees with the initial assessment.
Clear escalation procedures help prevent unresolved questions from being overlooked before submission.
10. Document Review Comments and Corrections
An effective approval process should create an audit trail.
If a reviewer identifies an error, the business can document:
- What was identified
- Who identified it
- What correction was required
- Who made the correction
- When the correction was completed
- Who completed the final review
This documentation can help demonstrate that the business has an established quality-control process.
11. Control Access to Reporting Systems
Access to goAML and related systems should be managed according to employees' responsibilities.
Businesses should regularly review who has access and whether those permissions remain appropriate.
When employees change roles or leave the organisation, their access should be reviewed and updated where necessary.
Clear access controls can reduce the risk of unauthorised activity and support better accountability.
12. Maintain Records of Submitted Reports
Businesses should establish procedures for retaining appropriate records relating to reports and their internal approval process.
Records may include:
- Internal review checklists
- Approval records
- Supporting documentation
- Review comments
- Corrections
- Relevant correspondence
- Submission records
The retention approach should follow the business's applicable legal, regulatory, and internal requirements.
13. Review the Process Periodically
An internal approval process should not remain unchanged indefinitely.
Businesses can periodically review whether the process is working effectively.
The review may identify:
- Repeated reporting errors
- Delays in approval
- Unclear responsibilities
- Missing documentation
- Training gaps
- Access-control issues
- Communication problems
Lessons from previous reports can be used to improve future reporting procedures.
Common Mistakes in goAML Report Approval
Businesses can weaken their reporting controls by:
- Allowing the same person to prepare and approve every report without appropriate controls
- Submitting reports without an independent quality check
- Failing to verify customer information
- Ignoring inconsistencies between records
- Using unclear reporting narratives
- Not documenting review decisions
- Failing to retain supporting records
- Giving excessive system access
- Having no escalation procedure
- Not reviewing the approval process periodically
A structured process can help reduce these weaknesses.
Internal goAML Report Approval Checklist
A business can use the following checklist as a starting point:
- Identify the reporting matter.
- Assign a report preparer.
- Collect relevant information.
- Prepare the goAML report.
- Verify customer and transaction information.
- Review the reporting narrative.
- Check relevant supporting records.
- Conduct an independent quality review.
- Resolve identified errors.
- Escalate unresolved issues where necessary.
- Obtain appropriate approval.
- Complete the submission.
- Retain relevant records.
- Review the process periodically.
Frequently Asked Questions
1. Why should businesses have an internal approval process for goAML reports?
An internal approval process can help identify incomplete information, inconsistencies, documentation gaps, and other issues before a report is submitted.
2. Should the person preparing a goAML report also approve it?
Where practical, separating preparation and review can provide an additional control. A maker-checker approach allows another person to independently review the report before submission.
3. What should be checked before submitting a goAML report?
The business should establish its own checklist based on the applicable reporting requirements. Checks may include customer information, transaction details, relevant parties, reporting rationale, narrative quality, and supporting records.
4. Why is the reporting narrative important?
The narrative provides an explanation of the relevant activity and reporting concern. It should be clear, factual, consistent with the available records, and sufficiently informative for the intended review.
5. Should businesses keep records of internal goAML reviews?
Businesses should establish appropriate record-keeping procedures covering their reporting and internal review activities. The records should be retained in accordance with applicable requirements.
6. What should happen if a reviewer finds an error?
The error should be assessed and corrected through the business's internal procedure before submission where appropriate. Significant or unresolved issues should be escalated to the appropriate compliance personnel.
7. Should goAML system access be reviewed?
Yes. Businesses should periodically review user access and ensure that permissions correspond with employees' current responsibilities.
8. How often should a goAML report approval process be reviewed?
There is no single frequency suitable for every business. Organisations should review their process periodically and whenever significant changes occur in reporting requirements, systems, responsibilities, or internal controls.