- DNFBP status is activity-based, not size-based: real estate brokers, precious metals dealers, auditors, accountants and corporate service providers all fall under AML rules from the day their licence is issued.
- Core obligations include registering on goAML, registering for sanctions screening, appointing a compliance officer, documenting an AML policy, and running customer due diligence.
- The MLRO role does not require a full-time hire for a small DNFBP; a founder can hold it directly if they genuinely exercise the authority, or the function can be outsourced.
- AML/DNFBP obligations are separate from UBO declaration, which every UAE company files regardless of activity; DNFBPs carry both obligations simultaneously.
- Administrative fines for AML violations range from AED 10,000 to AED 5,000,000 per violation, scaled to severity.
- There is no small-business carve-out: a business is a DNFBP because of its licensed activity, not because of its revenue or employee count.
A two-person corporate service provider and a fifty-person accounting firm carry exactly the same AML compliance obligation under UAE law. Size does not exempt a business, only its activity does. Real estate brokers, precious metals dealers, auditors, accountants, and corporate service providers, the category the UAE calls Designated Non-Financial Businesses and Professions, all fall inside AML rules the moment they’re licensed for that activity, regardless of headcount or revenue.
This guide explains who actually counts as a DNFBP, what the compliance officer role really requires, and what the registration and reporting obligations look like in practice for a small business that has never dealt with financial crime compliance before.
What actually makes a business a DNFBP
See e.zone’s piece on why AML is a critical control point for regulated small businesses, or the AML policy drafting service if you still need one in place.
The UAE’s AML framework, built around Cabinet Decision No. 10 of 2019 and its amendments, doesn’t apply AML obligations to every company. It applies them to specific activities considered higher-risk for money laundering: real estate brokers and agents, dealers in precious metals and stones above certain transaction thresholds, auditors, independent legal professionals and accountants providing certain services, and corporate service providers, meaning businesses that form or manage companies on behalf of clients.
If your licensed activity falls into one of these categories, AML obligations apply from the day your licence is issued, not from the day you cross a revenue threshold or hire your first employee. This is the detail most founders in these sectors miss: there’s no small-business carve-out based on size.
| DNFBP category | What triggers the obligation |
|---|---|
| Real estate brokers and agents | Facilitating property sale or purchase transactions |
| Precious metals and stones dealers | Cash transactions above the regulatory threshold |
| Auditors and accountants | Providing specified accounting or audit services to clients |
| Independent legal professionals | Preparing or executing transactions for clients on specified matters |
| Corporate service providers | Forming, registering, or managing companies for clients |
“AML compliance doesn’t scale with your headcount. It scales with what your licence says you do.”
The core obligations, at minimum
- Register on the goAML system, the UAE’s Financial Intelligence Unit platform, which is the channel through which suspicious transaction reports are filed.
- Register on the Automatic Reporting System for sanctions screening against UN and local sanctions lists.
- Appoint a Compliance Officer or MLRO (Money Laundering Reporting Officer), someone with sufficient experience, authority, and independence to oversee AML controls.
- Put a documented AML/CFT policy in place that reflects your specific business’s risk profile, not a generic template.
- Carry out customer due diligence and sanctions screening on clients before and during the business relationship.
- File suspicious transaction reports through goAML when a transaction raises red flags, regardless of whether it’s ultimately proven to be illicit.

What the Compliance Officer role actually requires
The MLRO doesn’t need to be a full-time hire for a small DNFBP. What matters is that the person has genuine authority to act, independence from transaction-approval decisions, and enough experience to recognize red flags specific to the business’s activity. For a two or three-person corporate service provider, this often means the owner takes on the role directly, provided they can demonstrate they’re actually exercising it, not just holding the title on paper.
For businesses that don’t want to build this function in-house, outsourcing the MLRO role to a specialist compliance firm is a fully accepted and increasingly common solution, particularly for smaller DNFBPs where hiring a dedicated compliance hire doesn’t make financial sense yet.
Consider a two-person corporate service provider helping international clients incorporate UAE companies. The founders assumed AML rules applied only to larger firms handling higher transaction volumes. A routine audit revealed they had never registered on goAML or appointed a compliance officer, despite being a textbook DNFBP from day one. The fix itself was straightforward, registration and appointing one of the founders as MLRO, but the gap had existed, unnoticed, for over a year.
How this differs from UBO declaration obligations
AML/DNFBP compliance and UBO declaration are separate obligations that sometimes get conflated. Every UAE company must file a UBO declaration regardless of activity; see our guide on who counts as a beneficial owner and what filing actually requires. AML/DNFBP obligations are activity-specific and layer additional requirements, goAML registration, a compliance officer, ongoing due diligence, on top of the UBO filing every company already handles.

What non-compliance actually costs
Administrative fines for AML violations range from AED 10,000 to AED 5,000,000 per violation, with the amount scaled to the severity and nature of the breach. Beyond the direct fine, a documented AML violation can affect a corporate service provider’s or auditor’s ability to maintain professional registrations and client relationships, since AML compliance history increasingly factors into how banks and larger clients assess a DNFBP as a counterparty.
Common mistakes DNFBPs make
- Assuming AML obligations apply only once the business reaches a certain size or transaction volume, when the trigger is the licensed activity itself.
- Appointing a compliance officer on paper without giving them genuine authority or involving them in actual due diligence decisions.
- Using a generic AML policy template without adapting it to the business’s specific client base and transaction patterns.
- Treating goAML registration as optional until a transaction actually looks suspicious, rather than a standing requirement from licensing.
- Not distinguishing AML/DNFBP obligations from the separate general compliance checklist every UAE company already follows.
When professional help is worth it
A DNFBP with a straightforward client base and low transaction complexity can often handle goAML registration and policy documentation directly, particularly with guidance from their industry association. Where outsourcing genuinely earns its cost is the ongoing MLRO function itself, since maintaining real due diligence discipline day to day is harder to sustain internally for a very small team than the one-time registration steps. Recurring compliance costs like this sit inside the wider annual cost picture; see our guide on what a UAE company actually costs to run each year. e.zone’s AML compliance advisors can assess whether your specific licensed activity triggers DNFBP status before your next audit finds the gap for you.
Frequently asked questions
What is a DNFBP in the UAE?
A Designated Non-Financial Business or Profession: real estate brokers, precious metals and stones dealers, auditors, accountants, independent legal professionals, and corporate service providers. AML obligations apply to these activities regardless of company size.
Does a small business need a full-time compliance officer?
Not necessarily. A founder or existing staff member can hold the MLRO role directly if they have genuine authority and independence, or the function can be outsourced to a specialist compliance firm.
What is goAML and do I need to register?
goAML is the UAE Financial Intelligence Unit's reporting platform. Any DNFBP must register on it as part of their core AML obligations, since it is the channel for filing suspicious transaction reports.
Is AML compliance the same as UBO declaration?
No. Every UAE company files a UBO declaration regardless of activity. AML/DNFBP obligations are activity-specific and add further requirements on top, including goAML registration and a compliance officer.
What happens if a DNFBP does not comply with AML rules?
Administrative fines range from AED 10,000 to AED 5,000,000 per violation. Non-compliance can also affect a business's standing with banks and larger clients who factor AML compliance into due diligence.
When do AML obligations start for a new DNFBP?
From the day the licence covering a DNFBP activity is issued, not from a revenue threshold or employee count. There is no grace period based on business size.
Talk to a setup advisor
Free 20-minute call to confirm the right structure for your business.

