A UAE company opening a bank account, a UK property investor buying through an overseas structure, a Dubai real estate broker onboarding a foreign buyer, a company formation provider setting up an entity for an international client- all face the same question: how much do we really know about the person, business, and money involved?
That question is the practical heart of AML compliance, and it is not just a problem for banks. In both the UK and the UAE, a wide range of businesses are expected to identify their customers, understand ownership, assess risk, run AML checks, keep records, and report suspicious activity where the rules require it.
For businesses working across the UK and the UAE, the stakes are higher. Cross-border ownership, overseas payments, property purchases and high-value transactions all raise financial crime risk. The problem is rarely deliberate wrongdoing; more often it is weak checks, thin records, or an AML policy that exists on paper but is never used in practice.
This guide sets out what AML compliance means, how the rules apply in each jurisdiction, what DNFBPs and regulated entities should consider, and how to build a framework that actually works.
Why AML Compliance Matters Now
Regulators now have better data, stronger reporting systems, and higher expectations. The UK Financial Intelligence Unit receives more than 850,000 Suspicious Activity Reports a year, and its central database holds over 4.5 million reports.
The UAE has also strengthened its AML and counter-terrorist financing framework. In February 2024, it was removed from the FATF list of jurisdictions under increased monitoring, the so-called grey list. That was a positive step, but it does not lower the bar for businesses; if anything, continued supervision, reporting, and enforcement should be expected.
Internationally, the FATF continues to review and publicly list jurisdictions with weak AML controls through its ongoing monitoring process, and it updates those lists three times a year. The direction of travel is clear: AML compliance is now part of responsible business management, not a background legal detail.
What Is AML Compliance?
AML compliance means the policies, procedures, and controls a business uses to prevent money laundering, terrorist financing, and related financial crime. In practice, it means the business can:
- Identify who the individual or business customer is
- Understand who ultimately owns or controls a company
- Classify customers, transactions, and jurisdictions by risk
- Screen customers and review relevant documents
- Monitor for unusual behaviour or transactions
- Keep evidence of what was checked and why decisions were made
- Escalate and report suspicion where required, and train staff to spot red flags
Compliance is not a one-time registration exercise. A policy, a registration number or access to a reporting portal does not make a business compliant. The framework has to work day to day.
What Does an AML Check Actually Involve?
An AML check is a review carried out to identify financial crime risk in a customer, company, transaction or business relationship. What it involves depends on the business and the level of risk. A straightforward customer may need standard identity verification and sanctions screening; a higher-risk one may need a deeper look at ownership, source of funds, source of wealth, political exposure, and adverse media.
For an individual, a check may cover proof of identity and address, sanctions and politically exposed person screening, and, where the risk requires it, source of funds and source of wealth. For a company, it may cover registration documents, the trade licence or Companies House records, directors and shareholders, ultimate beneficial owners, the ownership and control structure, the nature of the business, and source of funds evidence where relevant.
The point is not simply to collect documents. The business should understand who it is dealing with, why the transaction is happening, and whether the explanation is commercially reasonable.
Anti-Money Laundering in the UK
UK AML obligations apply to a range of businesses depending on the sector, activity, and supervisory authority, not only to large financial institutions. They commonly apply to:
- Financial services firms
- Estate agency businesses and letting agents in certain circumstances
- Accountancy service providers
- Trust or company service providers
- Money service businesses
- High-value dealers
- Cryptoasset businesses
- Certain legal professionals carrying out regulated work
Different businesses may be supervised by different authorities, including the Financial Conduct Authority, HMRC or professional body supervisors. Where the rules apply, firms are generally expected to carry out customer due diligence, assess risk, maintain an AML policy, train staff, keep records, and submit Suspicious Activity Reports where the reporting threshold is met.
AML Compliance in the UAE
In the UAE, AML requirements apply to financial institutions, DNFBPs, virtual asset service providers and other regulated entities, depending on the business activity and the relevant regulator. They are particularly relevant for:
- Real estate brokers and agents
- Dealers in precious metals and precious stones
- Auditors and accountants
- Trust and company service providers
- Financial institutions
- Virtual asset service providers
Where the regulations require it, relevant reporting entities, including many DNFBPs, must register on goAML, the platform used to submit suspicious transaction and suspicious activity reports to the UAE Financial Intelligence Unit. Not every UAE business carries the same obligation, so the first step is to confirm whether, and how, the rules apply to a given activity.
Importantly, goAML registration is not the same as full AML compliance. It gives a business access to the reporting system. The business still needs an AML policy, a risk assessment, a customer due diligence process, sanctions screening, an internal reporting route, staff training and proper records.
UK vs UAE AML Compliance: Key Differences
The two regimes share many principles, but businesses should not assume the requirements are identical.
|
Area |
UK Position |
UAE Position |
| Supervisory structure | Depends on sector; may involve the FCA, HMRC or professional body supervisors | Depends on the sector and licensing authority; DNFBPs are supervised by the relevant UAE authorities |
| Suspicious reporting | SARs are generally submitted to the National Crime Agency | STRs and SARs are submitted through goAML to the UAE FIU |
| DNFBP focus | Estate agents, accountants, TCSPs, and high-value dealers, among others | Real estate, precious metals and stones, auditors, accountants, and TCSPs |
| Cross-border risk | Firms must consider overseas customers, ownership, and funds | Firms must consider overseas customers, sanctions, ownership, and the source of funds |
The common thread is that both regimes expect businesses to understand risk and evidence their decisions. A policy that is never used is unlikely to be enough in either country.
Who Are DNFBPs?
DNFBP stands for Designated Non-Financial Business or Profession, non-financial businesses and professional service providers that can be exposed to money laundering risk because of the services they offer. They commonly include:
- Real estate brokers and agents, because property can be used to move or store large amounts of value
- Dealers in precious metals and stones, because high-value goods can be bought, sold, or moved across borders
- Accountants and auditors, who see ownership, accounts, and transaction information
- Trust and company service providers, because structures can be used to obscure ownership
- Certain legal professionals, whose services involve property, companies, trusts, or client money
Being a DNFBP does not make a business suspicious. It means the business operates where AML risk can arise and needs a clear process to manage it.
What Should an AML Policy Include?
An AML policy is the written framework explaining how a business identifies, assesses, and manages money laundering risk. It should be practical and specific to the business, not a generic template filed away and forgotten. A strong policy usually covers:
- A business-wide risk assessment of the main AML risks the business faces
- Customer due diligence: how customers are identified and verified
- Enhanced due diligence: what happens when a customer or transaction is higher risk
- Sanctions screening: when it is done and how possible matches are handled
- Source of funds and source of wealth: when evidence is required and what is acceptable
- Suspicious activity reporting: how staff escalate concerns internally
- Record-keeping: what is retained and for how long
- Staff training and a regular review process
The policy should answer real questions. Who reviews a high-risk customer? Who approves enhanced due diligence? What happens if a customer refuses to provide documents? When should a transaction be paused? Those are the questions that matter in practice.
Business-Wide Risk Assessment
A business-wide risk assessment is the foundation of AML compliance; it identifies where the business is most exposed. It should consider customer types, the countries involved, products and services, delivery channels, payment methods, transaction values, ownership structures, use of intermediaries, and sector-specific risks.
A UK company formation provider serving mainly overseas clients has a very different risk profile from a local bookkeeping practice, just as a UAE real estate broker handling high-value international buyers differs from a small business dealing only in local, low-value transactions. The assessment should reflect how the business actually operates and be reviewed when it changes, enters a new market, serves a new type of customer, or handles new transaction types.
Customer Due Diligence
Customer due diligence (CDD) is the process of identifying and verifying a customer before starting a relationship or carrying out a relevant transaction. It usually involves identifying the customer, verifying identity using reliable documents or data, understanding the nature and purpose of the relationship, identifying beneficial owners where a company or structure is involved, assessing risk, and keeping evidence of the checks completed.
For corporate customers, beneficial ownership matters most. A business should not stop at the company name; it should understand who ultimately owns or controls the entity.
Enhanced Due Diligence
Enhanced due diligence (EDD) applies where the customer, transaction, or relationship presents higher risk, for example, politically exposed persons, high-risk jurisdictions, complex ownership, unusual or third-party payments without clear explanation, high-value transactions, adverse media, unclear source of funds, or reluctance to provide documents.
EDD may involve additional identity or company documents, more detailed source of funds checks, a source of wealth review, senior management approval, closer monitoring, and clearer documentation of the decision. The FCA has noted that stronger firms document each stage, including senior approval and oversight, a useful lesson beyond the FCA-regulated sector: where a decision is higher risk, the reasoning should be visible on the file.
Source of Funds vs Source of Wealth
These two are often confused, but they are not the same.
|
Term |
Meaning |
Examples |
| Source of funds | Where the money for a specific transaction came from | Property sale, salary savings, business profits, a loan, an inheritance |
| Source of wealth | How the customer built their overall wealth | Business ownership, long-term employment, investments, family wealth |
For example, a customer might say the funds for a property purchase came from a company account. That may explain the immediate source of funds, but not the broader source of wealth if the transaction is high risk. Not every customer needs to be treated as suspicious, but where risk is higher, the explanation should be reasonable and supported by evidence.
Sanctions Screening
Sanctions screening is a critical part of AML compliance in both jurisdictions. A business should screen relevant customers, beneficial owners and counterparties against applicable sanctions lists, normally at onboarding and again when risk changes. A customer who was clear at onboarding may be listed later, ownership can change, and counterparties can become restricted.
A clear process should set out who is screened, when, which lists are checked, how possible matches are reviewed, who approves decisions, when a transaction should be paused, and how records are kept.
Suspicious Activity Reporting
If a business knows, suspects, or has reasonable grounds to suspect money laundering or terrorist financing, it may need to make a report. In the UK, SARs are generally submitted to the National Crime Agency; in the UAE, relevant entities submit suspicious transaction and activity reports through goAML to the UAE Financial Intelligence Unit.
The business does not need to prove criminal conduct; that is not its role. The question is whether the facts create suspicion or reasonable grounds for it. Indicators can include a customer refusing basic identity information, funds from an unrelated third party, transactions with no clear commercial purpose, sudden unexplained urgency, inconsistent ownership information, complex structures without reason, payments involving higher-risk jurisdictions, or a customer who becomes defensive when asked routine questions.
Suspicion should be handled carefully: staff should escalate internally, and the business should avoid tipping off the customer that a report has been or may be made.
Practical Examples of AML Risk
These simplified scenarios show how AML issues arise in ordinary business activity. The point is not that they are automatically suspicious; it is that they call for questions, judgment, and records.
| Scenario | AML Concern |
Practical Response |
| A UAE property buyer wants to pay from a company account owned by a third party | Source of funds and third-party payment risk | Ask why the third party is paying, verify the connection, and review the source of funds |
| A UK company formation client uses a layered offshore structure | Beneficial ownership may be unclear | Identify ultimate beneficial owners and document ownership and control |
| A customer pushes to complete a high-value transaction urgently and resists checks | Pressure to bypass normal controls | Pause the process and escalate internally |
| A jewellery customer makes repeated high-value purchases using different payment sources | The pattern may not match the customer profile | Review transaction history and consider enhanced due diligence |
| A client is linked to a higher-risk jurisdiction but gives a reasonable commercial explanation | Higher risk does not automatically mean refusal | Apply proportionate EDD and document the reasoning |
| A customer is a politically exposed person | Increased corruption and bribery risk | Apply EDD, obtain senior approval, and monitor the relationship |
Common AML Issues in UK–UAE Business Activity
Cross-border activity can make ownership, funds, and control harder to assess. Common situations include UAE residents investing in UK property, UK residents investing in UAE businesses, UAE companies with UK directors or shareholders, UK companies serving UAE customers, family businesses with assets in both countries, international structures, overseas payments, and high-value property, jewellery, or investment transactions.
Cross-border activity is not inherently suspicious; most arrangements are entirely legitimate. But the business should be able to explain the commercial purpose, identify the people involved, and provide evidence of the movement of funds where required.
AML Compliance Checklist for Businesses
This checklist helps a business review whether its AML framework is practical and complete.
| Question | Yes / No |
| Have we confirmed whether AML rules apply to our business? | |
| Do we have a current business-wide risk assessment? | |
| Is our AML policy tailored to our actual business activity? | |
| Do staff know how to carry out AML checks? | |
| Do we identify beneficial owners for company customers? | |
| Do we screen customers and beneficial owners for sanctions? | |
| Do we have a process for politically exposed persons? | |
| Do we check the source of funds where the risk requires it? | |
| Do we know when enhanced due diligence is needed? | |
| Do staff know how to escalate suspicious activity? | |
| Are AML records organised and easy to retrieve? | |
| Has staff training been completed and recorded? | |
| Do we review customer risk when circumstances change? | |
| Do we review the AML policy periodically? |
Common AML Compliance Mistakes
Most AML failures begin with weak systems rather than deliberate misconduct. The recurring ones are: treating compliance as a one-off task once a policy is written and registration is complete; relying on a generic policy that does not reflect the business; failing to identify beneficial owners behind company customers; ignoring source of funds on higher-risk, high-value transactions; over-relying on another adviser or intermediary to have done the checks; failing to update customer files as ownership, activity or payment behaviour changes; and weak internal escalation, where staff notice something unusual but do not know who to tell.
What Happens If a Business Does Not Comply?
Failure to meet AML obligations can lead to regulatory action, with the outcome depending on the jurisdiction, regulator, sector, seriousness of the breach, and whether the business cooperated. Possible consequences include administrative penalties, remediation requirements, increased supervisory attention, restrictions on activity, licence or registration issues, reputational damage and, in serious cases, further investigation.
This should not be overstated; not every mistake leads to severe enforcement. But repeated failures, weak systems, poor records, or a failure to report suspicious activity increase risk significantly. A business that spots gaps early and acts is usually in a far better position than one that waits for a regulator to raise concerns.
How to Strengthen AML Compliance
A practical framework should be clear, proportionate, and usable. In short:
- Confirm scope, check whether UK or UAE AML rules apply to the business
- Update the risk assessment across customers, jurisdictions, services, and transactions
- Review the AML policy so it reflects real activity
- Strengthen onboarding, including beneficial ownership checks, and define clear EDD triggers
- Confirm when and how sanctions screening is completed
- Train staff using sector-specific examples, not generic theory
- Keep organised evidence of checks, decisions, and approvals, and review the framework regularly
The aim is not paperwork for its own sake; it is a system that helps the business make sound decisions and evidence them if questioned.
When Should You Speak to an AML Specialist?
It is worth speaking to an anti-money laundering specialist where it is unclear whether AML rules apply; the business operates across the UK and the UAE; it deals with higher-risk customers or jurisdictions; it handles high-value transactions; it provides company formation or professional services; it is a DNFBP or regulated entity; it has received a regulator query; its AML policy has not been reviewed recently; staff are unclear about checks or reporting; or it needs help with remediation or file reviews.
A specialist’s role is not to make the business unnecessarily cautious. It is to help it understand its obligations, apply proportionate controls, and document decisions properly.
How Nexus Tax Can Help
For businesses with UK–UAE exposure, AML risk rarely sits on its own. It usually overlaps with tax, structuring, residency, and reporting, which is exactly where a generic compliance provider stops and a cross-border adviser adds value. Nexus Tax works across both jurisdictions, so you get one team that understands how your ownership structure, customer base, source of funds, and overseas interests are viewed on both sides.
We help business owners, investors, property clients, company formation providers, accountants, and real estate businesses put practical AML frameworks in place and keep them working, including:
- Business-wide AML risk assessments tailored to your sector and client base
- AML policy drafting and review, built for your actual activity rather than a template
- Customer and enhanced due diligence procedures, and source of funds and wealth guidance
- Sanctions screening processes and goAML support for UAE reporting entities
- File reviews, remediation, and support responding to regulator questions
- Cross-border UK–UAE compliance reviews for groups and structures spanning both
Where the facts are complex, early advice helps you avoid weak documentation, unclear responsibilities, and rushed responses under pressure, and lets you onboard good clients faster, not slower.
Talk to Nexus Tax
If you are unsure whether AML rules apply to your business, operate across the UK and the UAE, or want your current framework reviewed before a regulator does, get in touch with Nexus Tax for a confidential, no-obligation conversation. We will help you confirm your obligations, close the gaps, and put a proportionate framework in place. Contact us today to book a consultation.

Conclusion
AML compliance is now a core responsibility for many UK and UAE businesses, DNFBPs and regulated entities. The detail varies by sector and regulator, but the principles are consistent: understand your customer, assess risk, keep records, monitor activity and report suspicion where required.
For cross-border businesses, the need for clear documentation is stronger still, because UK–UAE structures, overseas payments and high-value transactions raise questions if you cannot explain who is involved and where the funds came from. Confirm your obligations, prepare a risk assessment, maintain a usable policy, train staff, document decisions, and review regularly; that is what turns AML compliance from a paper exercise into a working control system.
Frequently Asked Questions
Q: What is AML compliance?
AML compliance is the process of preventing and detecting money laundering, terrorist financing, and related financial crime. It usually includes customer due diligence, AML checks, risk assessment, sanctions screening, staff training, record-keeping, and suspicious activity reporting.
Q: What is the meaning of an AML check?
An AML check is a review carried out to identify financial crime risk in a customer, business relationship, or transaction. It may include identity verification, beneficial ownership checks, sanctions screening, politically exposed person checks, and a source of funds review.
Q: What is an AML policy?
An AML policy is a written framework explaining how a business identifies, assesses, and manages money laundering risk. It should cover customer due diligence, enhanced due diligence, reporting, record-keeping, training, and internal responsibilities.
Q: Who needs AML compliance in the UK?
UK AML obligations may apply to financial services firms, estate agents, accountancy service providers, trust or company service providers, money service businesses, high-value dealers, cryptoasset businesses and certain legal professionals, depending on the services provided.
Q: Who needs AML compliance in the UAE?
UAE AML obligations may apply to financial institutions, DNFBPs, virtual asset service providers and other regulated entities. DNFBPs commonly include real estate businesses, dealers in precious metals and stones, auditors, accountants, and company service providers.
Q: Is goAML registration required in the UAE?
Where the regulations require it, relevant UAE reporting entities, including many DNFBPs, must register on goAML. The platform is used to submit suspicious transaction and suspicious activity reports to the UAE Financial Intelligence Unit. Registration alone is not the same as being AML compliant.
Q: Are AML checks required for every customer?
Businesses should apply customer due diligence where the applicable rules require it. The level of checking depends on the customer and risk profile, and higher-risk customers usually require enhanced due diligence.
Q: What is enhanced due diligence?
Enhanced due diligence is a higher level of review applied to customers or transactions that present increased AML risk. It may involve additional documents, a source of funds review, senior approval, and closer monitoring.
Q: When should a business speak to an AML specialist?
Consider speaking to an anti-money laundering specialist if you are unsure whether AML rules apply, operate across the UK and UAE, deal with higher-risk customers, need an AML policy, have received a regulator query, or want your existing framework reviewed.
