Blog Image

How to Submit an AIF Report in goAML UAE: Step-by-Step Guide

When a business submits an STR or SAR through goAML in the UAE, the reporting process may not necessarily end with the original report. The UAE Financial Intelligence Unit (UAEFIU) may require additional information while reviewing the case.

For an entity that originally submitted the STR or SAR, this may involve an AIF — Additional Information File without Transactions.

Knowing how to submit an AIF correctly is important for UAE businesses, particularly DNFBPs that are required to maintain effective AML/CFT controls and respond appropriately to FIU requests.

In this guide, we explain how to submit an AIF report in goAML UAE, when an AIF should be used, what information should be prepared, how to reference the original STR or SAR, and the common mistakes businesses should avoid.

What Is an AIF Report in goAML?

AIF stands for Additional Information File without Transactions.

An AIF is a supplementary report used to provide additional information relating to an already submitted STR or SAR.

The UAE Ministry of Economy & Tourism's current DNFBP guidance explains that when the FIU requests further information while reviewing an STR or SAR, the DNFBP that submitted the original report may receive an AIF request through the goAML Message Board. The AIF should contain non-transactional supplemental details.

The UAEFIU's goAML reporting guide also defines AIF as an Additional Information File without Transactions.

In simple terms:

STR/SAR = original suspicious report

AIF = additional non-transactional information about that existing report

If the FIU requires additional information including transactions, the relevant report is AIFT rather than AIF.

When Should You Submit an AIF?

An AIF is generally used when the FIU requests further information concerning an STR or SAR that your business has already submitted.

For example, the FIU may require additional clarification about:

  • Customer identification
  • Beneficial ownership
  • Customer activity
  • Business relationship
  • Source of funds or wealth
  • Customer risk profile
  • Supporting documentation
  • Background information
  • The circumstances surrounding the original suspicion

The exact information required depends on the FIU's request.

It is therefore important not to treat an AIF as a standard form that contains the same information for every case.

Important distinction

An AIF is not a new STR.

The UAE Ministry of Economy & Tourism specifically distinguishes between primary suspicious reports and supplementary reports. STRs and SARs are used for new suspicions, while AIF and AIFT are supplementary reports relating to an already submitted STR or SAR.

AIF vs AIFT: Which One Should You Use?

Before starting the submission, make sure you have identified the correct report type.

ReportPurposeTransactions
STRReport a suspicious transactionYes/transaction-related
SARReport suspicious activityMay concern attempted or other suspicious activity
AIFProvide additional information about an existing STR/SARNo
AIFTProvide additional information about an existing STR/SARYes
RFIRespond to an FIU request for informationDepends on the RFI type

The UAEFIU identifies AIF as an additional information file without transactions and AIFT as an additional information file with transactions.

If the FIU specifically asks for transaction details, do not simply submit an AIF because it appears similar. Review the request and determine whether an AIFT is required.

What Information Should You Prepare Before Submitting an AIF?

Before logging into goAML, gather the information requested by the FIU.

Depending on the case, this may include:

1. Original STR or SAR details

Locate the report that the FIU's request relates to.

You should have the original report's web reference number available.

2. Customer information

Depending on the request, this may include:

  • Customer identification information
  • Nationality
  • Address
  • Occupation or business activity
  • Customer relationship information
  • Beneficial ownership details

Only provide information relevant to the request and consistent with your records.

3. Supporting documents

The FIU may require supporting information or documentation depending on the case.

Possible records can include:

  • KYC documents
  • Company documents
  • Contracts
  • Invoices
  • Correspondence
  • Source-of-funds documentation
  • Internal customer records

The specific requirements should be determined from the FIU request.

4. Internal compliance records

The MLRO or Compliance Officer should review the relevant internal records before submitting the response.

This helps ensure that the information provided is accurate and consistent with the original report.

Step-by-Step: How to Submit an AIF Report in goAML UAE

Step 1: Check the goAML Message Board

If the FIU requires additional information, the request may appear through the goAML Message Board.

The current Ministry of Economy & Tourism guidance specifically states that an AIF request may be sent through the Message Board when the FIU requires further information while reviewing an STR or SAR.

Start by reading the request carefully.

Identify:

  • What information is being requested
  • Which STR or SAR the request relates to
  • Whether the request specifies an AIF
  • Any supporting information required
  • Any instructions or deadlines provided

Do not begin preparing a generic response before understanding the request.

Step 2: Locate the Original STR or SAR

Find the original suspicious report in your goAML records.

Confirm that you have identified the correct report.

This is particularly important when your organisation has submitted multiple STRs or SARs.

The UAEFIU requires the original report reference to be used when submitting additional information.

Step 3: Record the Original Web Reference Number

The web reference number of the original STR or SAR is an important part of linking the additional information to the original report.

The UAEFIU's goAML FAQ states that the MLRO or Compliance Officer should quote the original report reference number by entering the report's web reference number in the FIU Reference field.

Before submitting, double-check the reference number.

An incorrect reference can make it harder to associate the additional information with the correct case.

Step 4: Select the AIF Report Type

Within the goAML reporting interface, select the appropriate additional-information report type.

For an AIF, the report type is:

Additional Information File without Transactions

The UAEFIU's reporting guide lists AIF as one of the report types available through goAML.

Do not select AIFT if the FIU has requested non-transactional supplemental information only.

Step 5: Enter the Required Internal Information

Complete the relevant report information requested by the goAML form.

This may include internal reference information and other report details.

Make sure your entries are:

  • Accurate
  • Consistent with your internal records
  • Consistent with the original STR/SAR
  • Relevant to the FIU request

Avoid adding speculative information.

If you do not have a requested piece of information, investigate internally and address the issue appropriately rather than guessing.

Step 6: Enter the FIU Reference

Enter the original STR/SAR web reference number in the FIU Reference field as required.

This step is specifically addressed in the UAEFIU's FAQ on submitting additional information.

This reference helps connect the AIF with the original suspicious report.

Step 7: Provide the Additional Information

Now provide the non-transactional information requested by the FIU.

A good response should directly address the questions or information requirements in the request.

For example, if the FIU asks for clarification about the beneficial owner, provide the relevant beneficial ownership information rather than submitting unrelated customer information.

If clarification is required regarding the customer's source of funds, provide the relevant information and supporting records available to the business.

Step 8: Review the AIF Before Submission

Do not immediately submit the report after completing the fields.

Review it carefully.

Check:

  • Original STR/SAR reference
  • Customer details
  • Internal reference
  • Requested information
  • Supporting information
  • Spelling of names
  • Dates
  • Consistency with the original report
  • Whether any transaction details have accidentally been included when the request is specifically for an AIF

The UAEFIU's goAML FAQ confirms that reports can be previewed and printed before submission, allowing users to review the report before finalising it.

Step 9: Submit the AIF

Once the MLRO or authorised Compliance Officer has completed the review, submit the AIF through goAML.

Keep the submission information and relevant reference details as part of your internal AML records.

Step 10: Maintain an Internal Record

After submission, retain an internal record of the process.

Your compliance file should, as appropriate, document:

  • Original STR/SAR
  • Original report reference
  • FIU request
  • Information gathered
  • Supporting documents
  • Internal review
  • AIF submission
  • Submission/reference details
  • Relevant correspondence

This creates an audit trail showing how the business responded to the FIU request.

Who Should Submit an AIF?

AIF submissions should be handled by the organisation's appropriately authorised AML reporting personnel.

The UAEFIU's reporting guide is applicable to the designated Compliance Officer/MLRO or deputy CO/MLRO of the reporting entity registered on goAML.

For many businesses, this means the MLRO or Compliance Officer should coordinate the response and ensure that the information submitted is accurate and appropriately linked to the original STR/SAR.

Other employees may assist with gathering information, but the organisation should follow its approved AML governance and authorisation procedures.

Common AIF Submission Mistakes

Mistake 1: Treating an AIF as a new STR

An AIF supplements an existing STR or SAR.

It should not be used as a substitute for submitting a new suspicious report where a new reporting obligation exists.

Mistake 2: Forgetting the original report reference

The UAEFIU specifically requires the original report's web reference number to be referenced when submitting additional information.

Always verify the reference before submission.

Mistake 3: Selecting AIF when transaction information is required

AIF is defined as an additional information file without transactions.

Where additional transaction information is required, the relevant report may be AIFT.

Mistake 4: Providing information that does not answer the request

More information is not necessarily better.

The objective should be to provide accurate and relevant information that addresses the FIU's request.

Mistake 5: Creating inconsistencies with the original STR/SAR

An AIF should be reviewed against the original report.

If new information appears to conflict with what was previously reported, the issue should be investigated internally before submission.

Mistake 6: Guessing when information is unavailable

AML reporting should be based on reliable information and appropriate records.

If the business cannot locate or verify requested information, the matter should be escalated through the organisation's compliance process rather than filling gaps with assumptions.

AIF Submission Checklist

Before submitting an AIF through goAML, use this checklist:

  •  FIU request reviewed
  •  Correct report type confirmed
  •  Original STR/SAR identified
  •  Original web reference number confirmed
  •  FIU Reference field checked
  •  Requested information collected
  •  Information verified against internal records
  •  Response is non-transactional where AIF is required
  •  Supporting information reviewed
  •  Original STR/SAR checked for consistency
  •  MLRO/Compliance Officer review completed
  •  Report previewed before submission
  •  AIF submitted through goAML
  •  Internal audit trail retained

What If the FIU Requests Transaction Information?

If the FIU asks for additional information including transactions, an AIF may not be the appropriate report type.

The current Ministry of Economy & Tourism guidance distinguishes AIF from AIFT:

  • AIF: additional non-transactional information
  • AIFT: additional information including transactional details

The FIU may send an AIFT request through the goAML Message Board where transaction information is required while assessing an STR or SAR.

This is why businesses should always read the FIU request carefully before selecting the report type.

AIF vs RFI: Don't Confuse the Two

AIF and RFI can also be confused because both involve additional information.

However, they serve different purposes.

An AIF is supplementary information relating to an existing STR or SAR submitted by the reporting entity.

An RFI, or Request for Information, may be used when the FIU seeks information from multiple DNFBPs rather than only the entity that originally submitted the STR/SAR.

The appropriate response therefore depends on the nature of the FIU request.

Does Submitting an AIF Mean the AML Case Is Closed?

Not necessarily.

An AIF is a response to an information requirement connected with an existing suspicious report. It does not automatically mean that all AML monitoring or internal compliance activity relating to the customer should stop.

Depending on the circumstances, the business may need to continue:

  • Customer monitoring
  • KYC review
  • Risk assessment
  • Enhanced due diligence
  • Internal investigation
  • Review of related activity
  • Record keeping
  • Further reporting where legally required

The appropriate action depends on the facts of the case and the organisation's AML procedures.

Confidentiality and AIF Reporting

Businesses should handle FIU requests and suspicious reporting information confidentially.

Employees should not improperly disclose information about suspicious reporting or FIU communications to customers or unauthorised persons.

The organisation should therefore limit access to relevant compliance personnel and follow its internal confidentiality and information-security procedures.

Frequently Asked Questions

What does AIF mean in goAML UAE?

AIF means Additional Information File without Transactions. It is used to provide additional non-transactional information relating to an existing STR or SAR.

How do I submit an AIF in goAML?

An AIF is submitted through the goAML platform when the FIU requests additional non-transactional information relating to an existing STR or SAR. The reporting entity should review the FIU request, identify the original report, reference its web reference number and provide the requested information through the appropriate AIF report.

Where do I find the AIF request?

An AIF request may be received through the goAML Message Board.

Do I need the original STR reference number for an AIF?

Yes. The UAEFIU states that the original report's web reference number should be entered in the FIU Reference field when submitting additional information.

What is the difference between AIF and AIFT?

AIF is an Additional Information File without Transactions. AIFT is an Additional Information File with Transactions.

Is AIF a new suspicious transaction report?

No. AIF is a supplementary report connected to an already submitted STR or SAR. STR and SAR are the primary report types used for new suspicions.

Who should submit an AIF?

The reporting entity's designated Compliance Officer/MLRO or appropriately authorised personnel should manage and submit the report according to the organisation's AML governance procedures. The UAEFIU's goAML submission guide is specifically directed to designated CO/MLROs or their deputies.

Can I review an AIF before submitting it?

Yes. The UAEFIU's FAQ states that goAML reports can be previewed and printed before submission.

Final Takeaway

Submitting an AIF through goAML is essentially a supplementary reporting process: the FIU needs more information about an STR or SAR that has already been submitted, and the reporting entity provides the requested information without transaction details.

The key steps are to:

  1. Check the goAML Message Board.
  2. Read the FIU request carefully.
  3. Identify the relevant STR or SAR.
  4. Confirm the original web reference number.
  5. Select the AIF report type.
  6. Provide the requested non-transactional information.
  7. Review the submission for accuracy and consistency.
  8. Submit through goAML.
  9. Keep a complete internal audit trail.

The most important point is to follow the FIU's specific request. If transaction information is required, the appropriate report may be AIFT rather than AIF.

For UAE DNFBPs, a well-managed AIF process forms part of a broader AML/CFT compliance framework. The MLRO or Compliance Officer should ensure that responses are accurate, properly documented and consistent with the organisation's AML policies and the information previously submitted to the FIU.

Need Help With goAML and UAE AML Compliance?

Managing STRs, SARs, AIFs, AIFTs and FIU requests can be time-consuming, particularly for businesses that do not have an experienced in-house compliance team.

Professional AML compliance support can assist with goAML registration, STR/SAR reporting, AIF and AIFT submissions, AML risk assessments, MLRO services, KYC procedures, and ongoing UAE AML compliance.