Blog Image

How to Respond to an FIU Information Request in UAE

Receiving an FIU information request in the UAE can be a stressful experience for a business, especially if the request relates to a previously submitted Suspicious Transaction Report (STR) or Suspicious Activity Report (SAR).

An information request does not necessarily mean that your business has done something wrong. The UAE Financial Intelligence Unit (FIU) may require additional information to better understand a transaction, customer, activity or relationship while reviewing a report.

For reporting entities using goAML, the request may be communicated through the goAML Message Board. Depending on the circumstances, the FIU may request additional information through an Additional Information File (AIF), an Additional Information File with Transactions (AIFT), or a Request for Information (RFI).

Responding accurately, completely and within the required timeframe is an important part of your AML compliance responsibilities.

This guide explains what an FIU information request means, what businesses should do when they receive one, what information may be required and common mistakes to avoid.

What Is an FIU Information Request?

An FIU information request is a request from the Financial Intelligence Unit for additional information that may help it assess suspicious activity, transactions, customers or other relevant matters.

The request can arise after an STR or SAR has been submitted, or it may involve information requested from multiple reporting entities.

The UAEFIU's goAML reporting guide explains that when the FIU requires further details while reviewing an STR or SAR, the reporting entity that originally submitted the report may receive an AIF request through the goAML Message Board. If additional transactions are required, an AIFT may be used.

An RFI is different. The guide explains that an RFI without transactions can be sent to multiple reporting entities rather than only the entity that originally submitted the STR/SAR.

Why Does the FIU Request Additional Information?

There can be several reasons for an information request.

The FIU may need to:

  • Clarify information included in an STR or SAR
  • Understand a customer's activity
  • Obtain additional transaction details
  • Identify related individuals or entities
  • Understand the relationship between parties
  • Review the source or movement of funds
  • Clarify dates, amounts or transaction patterns
  • Obtain information held by another reporting entity
  • Assess whether additional transactions are relevant

A request should therefore be treated as a compliance matter requiring careful attention, rather than automatically assuming that enforcement action is being taken against the business.

What Types of FIU Requests Can You Receive Through goAML?

Understanding the report type is important because the response process can differ.

Additional Information File (AIF)

An AIF is used when the FIU requires further information relating to an existing STR or SAR but does not require additional transactions to be reported through that submission.

The UAEFIU goAML guide states that an AIF request can be sent through the Message Board when the FIU requires further details while reviewing an STR/SAR.

Additional Information File With Transactions (AIFT)

An AIFT is similar to an AIF but supports the submission of additional transaction information.

If the FIU requests further information including transactions, the reporting entity may receive an AIFT request through goAML.

Request for Information (RFI)

An RFI can be used when the FIU needs information from multiple reporting entities rather than only the reporting entity that originally submitted an STR or SAR.

The goAML guide identifies both:

  • RFI without transactions
  • RFI with transactions

as available report types.

Where Will You Receive the FIU Request?

For goAML users, requests can be communicated through the goAML Message Board.

The UAEFIU's reporting guide specifically explains that AIF, AIFT and RFI requests can be received through the Message Board.

This is why the MLRO or authorised compliance personnel should regularly monitor the organisation's goAML account.

Don't assume that completing an STR submission means the reporting process is finished.

There may be further communication after the original report.

What Should You Do When You Receive an FIU Request?

The first step is to read the request carefully.

Don't immediately send documents without understanding what the FIU has asked for.

A practical response process is:

  1. Review the request
  2. Identify the relevant customer or case
  3. Identify the original STR/SAR or FIU reference
  4. Determine exactly what information is requested
  5. Gather the relevant records
  6. Verify the information
  7. Prepare the response in the appropriate goAML report type
  8. Review the response internally
  9. Submit it through goAML
  10. Retain evidence of the response

Step 1: Review the Request Carefully

Start by identifying exactly what the FIU wants.

For example, the request may concern:

  • A particular transaction
  • A customer
  • A company
  • A bank account
  • A series of transactions
  • A beneficiary
  • A source of funds
  • A relationship between two parties
  • Supporting documents

Don't respond to a broader question than what was actually asked.

At the same time, don't omit information that is clearly relevant to the request.

Step 2: Identify the Original Report

If the request relates to an existing STR or SAR, identify the original report and its reference information.

The UAEFIU's goAML FAQ states that when submitting additional information relating to an existing report, the MLRO or Compliance Officer should reference the original report's web reference number in the FIU Reference field.

This helps connect the additional information with the original report.

Step 3: Assign the Request to the MLRO

The response should normally be coordinated through the person responsible for AML compliance and suspicious transaction reporting within the business.

The MLRO should:

  • Review the request
  • Coordinate information gathering
  • Assess the available records
  • Verify the response
  • Maintain confidentiality
  • Submit the appropriate response

Avoid allowing multiple employees to independently respond to an FIU request without central coordination.

That can lead to inconsistent information.

Step 4: Gather the Relevant Records

The information required will depend on the request.

Potential records can include:

  • Customer identification documents
  • Corporate documents
  • Beneficial ownership information
  • Account information
  • Transaction records
  • Invoices
  • Contracts
  • Payment records
  • Source of funds information
  • Source of wealth information
  • Customer communications
  • Internal review records
  • Previous due diligence information
  • Relevant screening results

Only provide information that is relevant and appropriately requested.

Step 5: Verify the Information Before Submission

Accuracy is extremely important.

Before submitting your response, check:

  • Names
  • Dates
  • Amounts
  • Currencies
  • Transaction references
  • Account numbers
  • Company information
  • Beneficial ownership information
  • Customer information
  • Supporting documents

A simple mistake in a date or transaction amount can create confusion when the FIU compares your response with other information.

Step 6: Prepare the Appropriate goAML Report

Use the report type specified or required by the FIU request.

For example:

AIF → additional information without transactions.

AIFT → additional information including transactions.

RFI → information requested from relevant reporting entities, with or without transactions depending on the request.

Don't submit a completely new STR simply because you received a request for additional information unless the circumstances separately require a new report.

The response should be linked to the relevant request and original report where applicable.

What Information Should You Include in the Response?

The information depends on what the FIU has requested.

However, a useful response can include:

Customer Information

Provide relevant identifying information about the customer or subject.

This may include:

  • Full legal name
  • Identification details
  • Nationality
  • Date of birth
  • Address
  • Business details
  • Beneficial ownership information

Transaction Information

Where requested, provide:

  • Transaction date
  • Amount
  • Currency
  • Sender
  • Recipient
  • Account information
  • Transaction reference
  • Payment method
  • Relevant transaction history

Business Relationship Information

Explain:

  • When the customer relationship started
  • Purpose of the relationship
  • Customer's stated business activity
  • Expected activity
  • Relevant services provided

Source of Funds Information

Where relevant, provide information about the source of funds and the evidence available to the business.

Source of Wealth Information

Where relevant, provide information about the customer's source of wealth and the documentation or information supporting it.

Suspicious Activity Context

If the request relates to an existing STR or SAR, explain the relevant facts and circumstances clearly.

How Should You Write the Response?

The response should be factual, concise and organised.

Avoid unnecessary speculation.

A useful structure can be:

Background

Briefly identify the customer and relationship.

Information Requested

Address each question or information point raised by the FIU.

Relevant Transactions

Provide the requested transaction details in a clear format.

Supporting Information

Explain the documents or records being provided.

Additional Context

Include any other information directly relevant to understanding the matter.

The objective is to make it easy for the FIU to understand the information without having to search through unrelated material.

Should You Provide More Information Than Requested?

Don't deliberately withhold relevant information.

At the same time, avoid sending large amounts of irrelevant material simply because you have it available.

For example, if the FIU asks for information about three specific transactions, provide those transactions and any directly relevant context.

If additional transactions are clearly connected and relevant, follow the applicable reporting process and instructions.

The key is relevance and completeness.

What If You Don't Have the Requested Information?

Sometimes a business may not have all the information requested.

Don't invent information.

Instead:

  1. Confirm what information is available.
  2. Identify what is missing.
  3. Explain why it is unavailable, where appropriate.
  4. Provide alternative records if they are relevant.
  5. Continue reasonable efforts to obtain information where required.

For example, if a historical document is no longer available, state that clearly rather than creating an assumption about what it contained.

What If the Information Has Changed Since the Original STR?

This can happen.

For example, the customer may have:

  • Provided new documentation
  • Changed ownership
  • Completed additional transactions
  • Changed business activity
  • Provided information about the source of funds

If the new information is relevant to the FIU request, explain the change clearly and distinguish between:

Information available when the original STR was filed

and

Information obtained afterward

This creates a clearer audit trail.

What If the FIU Requests Additional Transactions?

If the request specifically asks for additional transactions, the appropriate goAML report type may be AIFT or RFI with transactions, depending on the request.

The UAEFIU's goAML guide states that AIFT supports additional transaction information when the FIU requires further details including transactions while processing an STR/SAR.

Make sure the transaction information is complete and consistent with your internal records.

What If the FIU Requests Information About Multiple Customers?

Don't assume that every customer is automatically suspicious.

An RFI can be used to request information from multiple reporting entities.

Follow the scope of the request and provide the relevant information according to the instructions received.

The fact that information has been requested does not, by itself, establish that a customer has committed an offence.

Should You Tell the Customer About the FIU Request?

This is an area where businesses need to exercise particular caution.

Do not casually tell a customer:

"The FIU has asked us about you."

AML/CFT rules can restrict disclosure of suspicious transaction reporting information and related investigations.

The UAE's current targeted financial sanctions guidance also highlights the need for policies and procedures that prohibit employees from notifying customers in specified circumstances.

If you're unsure whether a particular communication is permitted, obtain appropriate compliance or legal advice before contacting the customer about the request.

What Records Should You Keep?

Keep a clear internal record of the response process.

Depending on your policies and applicable requirements, this can include:

  • Original FIU request
  • Date received
  • Person responsible
  • Internal investigation notes
  • Information collected
  • Documents reviewed
  • Final response
  • Submission date
  • goAML reference
  • Internal approval
  • Follow-up correspondence

Good documentation can demonstrate how the business responded and how the MLRO reached its decisions.

Common Mistakes When Responding to an FIU Request

1. Ignoring the Request

An FIU request should not sit unread in the goAML Message Board.

2. Responding Without Reviewing the Original STR

If the request relates to a previous report, review the original submission before preparing the response.

3. Providing Inconsistent Information

Make sure the response matches your internal records and the original report.

4. Guessing Missing Information

Never create facts simply to complete a response.

5. Sending Irrelevant Documents

More documents do not necessarily mean a better response.

6. Failing to Reference the Original Report

Where the request concerns an existing STR/SAR, use the appropriate reference information. The UAEFIU FAQ specifically instructs MLROs/Compliance Officers to reference the original report when submitting additional information.

7. Treating the Request as a New STR Automatically

An information request and a new suspicious transaction report are different processes.

8. Informing the Customer Without Checking

Disclosure can create serious compliance issues.

9. Allowing Multiple Uncoordinated Responses

Centralise the response through the MLRO or designated compliance function.

10. Failing to Keep an Internal Record

Document how the request was handled and what was submitted.

FIU Information Request Response Checklist

Before submitting your response, check:

  •  Request has been reviewed carefully
  •  Original STR/SAR identified, where applicable
  •  FIU reference confirmed
  •  Relevant customer identified
  •  Requested transactions identified
  •  Information verified
  •  Supporting documents reviewed
  •  Missing information identified
  •  Response addresses each requested point
  •  Correct goAML report type selected
  •  Confidentiality maintained
  •  MLRO/compliance review completed
  •  Response submitted through goAML
  •  Submission reference recorded
  •  Internal records retained

What If You Need Help Responding to an FIU Request?

An FIU information request can require more than simply uploading documents.

The business may need to:

  • Review historical transactions
  • Reconstruct a transaction pattern
  • Check customer due diligence
  • Review beneficial ownership
  • Verify source of funds
  • Examine internal records
  • Compare information against the original STR
  • Prepare a structured response
  • Submit an AIF, AIFT or RFI through goAML

If your team is unsure about the appropriate response, professional AML support can help review the request and organise the available information.

Frequently Asked Questions

What is an FIU information request in the UAE?

It is a request from the UAE Financial Intelligence Unit for additional information that may assist in reviewing a suspicious transaction, suspicious activity or other relevant matter.

Where do I receive an FIU request?

For goAML reporting entities, relevant requests such as AIF, AIFT and RFI requests can be received through the goAML Message Board.

What is an AIF in goAML?

An Additional Information File (AIF) is used to provide additional information relating to an existing STR or SAR when the FIU requests further details without additional transactions.

What is an AIFT in goAML?

An Additional Information File with Transactions (AIFT) is used when the FIU requests additional information that includes transactions.

What is an RFI in goAML?

An RFI, or Request for Information, can be used when the FIU requires information from reporting entities, including situations involving multiple reporting entities. goAML supports RFI reports with and without transactions.

Do I need to reference the original STR?

When submitting additional information relating to an existing STR/SAR, the UAEFIU FAQ instructs the MLRO/Compliance Officer to reference the original report's web reference number in the FIU Reference field.

Does an FIU request mean my business is being penalised?

Not necessarily. An information request may simply mean that the FIU needs additional information to understand or assess a matter.

What if I don't have all the requested documents?

Do not invent information. Provide what is available and explain relevant gaps where appropriate.

Can I tell the customer about the FIU request?

You should not disclose information about an FIU request or suspicious reporting without first considering the applicable confidentiality and tipping-off restrictions. Obtain appropriate professional advice if you are unsure.

Who should respond to an FIU information request?

The response should normally be coordinated by the MLRO or the person responsible for the reporting entity's AML compliance and goAML reporting.

How quickly should I respond?

Follow the deadline and instructions contained in the request. Do not assume that the timeframe is the same for every request.

Final Thoughts

Receiving an FIU information request in the UAE should be treated as an important compliance matter, but it does not automatically mean that your business has violated AML requirements.

The right approach is to remain organised and factual.

Start by reviewing the request, identify the relevant customer and original report, gather the requested information, verify your records and submit the response through the appropriate goAML reporting mechanism.

If the request relates to an existing STR or SAR, pay particular attention to the distinction between AIF, AIFT and RFI and make sure the original report is properly referenced where required.

Most importantly, maintain confidentiality and avoid making assumptions about what the FIU's request means.

The UAE's AML framework is continuing to evolve. The Ministry of Economy & Tourism currently lists Federal Decree by Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025 among the current AML/CFT/CPF legislation.

If your business receives an FIU request and you're unsure how to respond, an AML professional can assist with goAML reporting, AIF/AIFT preparation, transaction analysis, AML documentation and MLRO support.

This article is for general informational purposes and is not legal advice. Always follow the specific instructions and deadlines contained in the FIU request and the current UAE AML/CFT/CPF framework.