Business Setup in Dubai | Company Formation UAE & KSA | Noble Core Ventures

DNFBP UAE 2026: AML Duties for Your Business

DNFBP UAE 2026: the five categories, AML duties, goAML registration, record-keeping and fines from AED 50,000. Clear compliance guide for founders.
dnfbp uae β€” official document, Noble Core Ventures

dnfbp uae β€” official document, Noble Core Ventures
By Ishita Roy · Business Consultant, Noble Core Ventures
Hands-on UAE company-formation specialists since 2020 · Reviewed for accuracy · Updated July 2026

Quick AnswerDNFBP UAE 2026: the five categories, AML duties, goAML registration, record-keeping and fines from AED 50,000. Clear compliance guide for founders.

DNFBP status is one of the most misunderstood parts of running a business in the UAE, and in 2026 it carries real financial risk. If your company is a real estate broker, a dealer in precious metals or stones, a corporate service provider, an auditor or an independent legal professional, you are almost certainly a DNFBP and you carry the full weight of the UAE's anti-money-laundering duties. Breach them and administrative fines run from AED 50,000 to AED 5,000,000 per violation under the national penalty framework.

This guide explains, in plain language for founders, what a DNFBP is, which five categories are captured, exactly what AML duties you must perform, who supervises you, and what happens if you do not comply. The aim is simple: help you see whether you are in scope and give you a clear route to meeting your obligations before a supervisor or a bank asks the question for you.

What Is a DNFBP in the UAE?

A DNFBP in the UAE is a Designated Non-Financial Business or Profession: one of five categories, including real estate brokers, dealers in precious metals and stones handling cash at or above AED 55,000, corporate service providers, auditors and lawyers. Each carries full anti-money-laundering duties under Federal Decree-Law No. 20 of 2018, with administrative fines from AED 50,000 to AED 5,000,000 for breaches, and record-keeping of at least 5 years.

The concept comes from international standards set by the Financial Action Task Force, which the UAE implements through its national AML law. The logic is that money laundering does not only pass through banks. It passes through property purchases, gold and jewellery deals, company structures and professional advice. So the law extends bank-style controls, know your customer, monitoring, reporting, to the non-financial businesses that sit on these routes. Because these firms are not financial institutions, they are grouped separately as DNFBPs, but their core obligations are strikingly similar to those of a bank.

DNFBP essentials Detail
Governing law Federal Decree-Law No. 20 of 2018
Implementing regulation Cabinet Decision No. 10 of 2019
Penalties Cabinet Decision No. 16 of 2021
Number of categories 5
Precious-metals cash trigger AED 55,000
Fine range AED 50,000 – AED 5,000,000
Record retention 5 years minimum
Primary supervisor Ministry of Economy

The Ministry of Finance leads the UAE's national AML committee and its engagement with the Financial Action Task Force, while the Federal Tax Authority handles the separate but related worlds of corporate tax and VAT. A founder who understands where DNFBP duties fit within this wider architecture is far better placed to build a business that banks and regulators trust.

The Five DNFBP Categories Explained

Understanding whether you are captured starts with the five categories, each defined by activity rather than label. Real estate agents and brokers are in scope when they carry out transactions for a customer concerning the buying and selling of real property. It is the act of brokering a purchase or sale for a client that triggers the duty, which is why property is a core focus of UAE AML supervision given the size of the market.

Dealers in precious metals and precious stones, often shortened to DPMS, are captured when they conduct a single cash transaction, or several linked cash transactions, equal to or above AED 55,000. This sweeps in gold traders, jewellers, diamond dealers and bullion merchants who take cash. Corporate service providers are captured because forming companies, providing registered offices, and acting as or arranging nominee directors and shareholders can be used to disguise beneficial ownership, the exact vulnerability money launderers exploit.

Auditors and accountants fall in scope when they prepare or carry out transactions for clients relating to buying and selling real estate, managing client money, or creating and managing companies. Independent legal professionals, including lawyers and notaries, are captured when they handle the same kinds of specified financial transactions on a client's behalf. The common thread across all five is clear: each sits at a point where value moves or ownership is created, and each therefore becomes a gatekeeper the law expects to check who is really behind the money. If your business fits any category, even partly, treat yourself as a DNFBP until a qualified adviser confirms otherwise.

What AML Duties Does a DNFBP Have?

Once you accept you are a DNFBP, the duties are specific and testable. First, register on the goAML platform of the UAE Financial Intelligence Unit and on the Automatic Reporting System for Sanctions Lists. Second, appoint a competent, senior compliance officer, the Money Laundering Reporting Officer, who owns the AML function. Third, carry out a business-wide risk assessment that identifies where your particular firm is exposed to laundering and terrorist financing, and keep it current.

Fourth, perform customer due diligence on every customer: identify them, verify that identity, understand the purpose of the relationship, and identify the beneficial owner behind corporate customers. Fifth, apply enhanced due diligence to higher-risk customers and situations, including politically exposed persons and higher-risk jurisdictions. Sixth, screen customers and counterparties against the United Nations and UAE sanctions lists and act immediately on a match, including freezing and reporting.

Seventh, monitor transactions and behaviour on an ongoing basis, and file a Suspicious Transaction Report or Suspicious Activity Report on goAML whenever you have reasonable grounds to suspect illicit funds, without tipping off the customer. Eighth, keep full records for at least five years. Ninth, train relevant staff so they can recognise red flags. Tenth, respond to supervisory inspections and complete the annual AML questionnaires that the Ministry of Economy and other supervisors issue. These duties are not optional extras; each maps to a specific violation and fine if neglected, and supervisors test them directly during inspection.

DNFBP Registration on goAML and Sanctions Systems

Registration is the visible proof that a DNFBP takes its duties seriously, and it is usually the first thing a supervisor or bank checks. You register your organisation through the route your supervisor specifies, which for most DNFBP categories is the Ministry of Economy's compliance system feeding into goAML. You provide your trade licence details, registered address and authorised signatory, then nominate your compliance officer with their Emirates ID, passport and a signed authorisation.

Crucially, there are two systems, not one. goAML is where you file suspicious transaction and activity reports and, for dealers, the high-value cash report. The Automatic Reporting System for Sanctions Lists is where you meet screening and freezing obligations against the UN Consolidated List and the UAE Local Terrorist List. A DNFBP must be live on both. Being registered on one while ignoring the other is a common and finable gap.

There is no government charge to enrol, but expect to spend two to four weeks reaching an approved, active status, most of that time waiting for the supervisor to approve your nominated officer. The practical mistake founders make is treating registration as the finish line. It is the starting line: an active account with no due diligence, no screening and no records behind it is treated by supervisors as evidence of non-compliance, not compliance. Register early, register on both systems, and immediately begin building the operational file that shows the registration is real.

Customer Due Diligence for DNFBPs

Customer due diligence is the heart of DNFBP compliance because it is what actually stops your business from being used to launder money. At a minimum you identify the customer and verify that identity using reliable, independent documents: a passport and Emirates ID for individuals, a trade licence and ownership records for companies. You establish the purpose and intended nature of the relationship, and for corporate customers you identify and verify the ultimate beneficial owner, the real person who owns or controls the entity.

For higher-risk relationships you escalate to enhanced due diligence. Triggers include a politically exposed person, an unusually complex or opaque ownership structure, a transaction with no clear economic rationale, a customer insisting on unusual secrecy, or a link to a higher-risk country. Enhanced measures mean establishing source of funds and source of wealth, obtaining senior management approval to proceed, and monitoring the relationship more closely. Where you cannot complete due diligence, you must not act, and you must consider filing a report.

For a precious-metals dealer, this means verifying the identity of a customer paying AED 90,000 in cash before completing the sale and filing the dealers report. For a real estate broker, it means confirming who is really buying a property and where the money originates. For a corporate service provider, it means knowing who ultimately owns every company formed. Documented, dated due diligence files are the single most powerful defence in an inspection, and their absence is the single most common reason for a fine.

Record-Keeping, Reporting and Supervision

Two ongoing duties, record-keeping and reporting, define day-to-day DNFBP life. On records, you must retain customer identification data, the supporting verification documents, account files, business correspondence and the results of any analysis for at least five years after the relationship ends or the transaction is completed. Supervisors can and do ask to see these files, and the inability to produce them is itself a violation, regardless of whether any laundering occurred.

On reporting, you file through goAML whenever suspicion arises. Timeliness matters: a report filed late, or not at all, is treated as a failure even where your underlying judgement was sound. You must never tip off the customer that a report has been made, because disclosure is a serious offence in its own right. Dealers additionally file the dedicated cash report for qualifying transactions at or above AED 55,000.

Supervision closes the loop. The Ministry of Economy is the national supervisor for most DNFBP categories and conducts risk-based inspections, themed campaigns and annual questionnaires. Financial free zones such as ADGM run their own equivalent regimes for firms licensed there. Supervisors assess your registration, your officer, your risk assessment, your due diligence files, your screening and your training, then rate your compliance and act where it is weak. A business that keeps clean records and files properly turns supervision into a routine event; one that does not turns it into a penalty.

DNFBP Compliance Costs and Penalties

DNFBP compliance costs money, but non-compliance costs far more. The table below sets out realistic budget items alongside the penalty exposure, so you can weigh them honestly.

Item Indicative amount (AED)
goAML and sanctions-system registration 0 (government)
Outsourced compliance officer (annual) 12,000 – 60,000
AML risk assessment and policies 5,000 – 25,000
Sanctions-screening tool (annual) 3,000 – 30,000
Staff training (annual) 1,000 – 8,000
Failure to register (fine) From 50,000
Failure to conduct due diligence (fine) From 50,000
Serious or repeated breaches (fine) Up to 5,000,000

Penalties flow from Cabinet Decision No. 16 of 2021. Beyond the fine itself, supervisors can suspend or withdraw a licence, publish the offender's name, and refer serious cases to prosecutors. Under Article 26 of the AML law, the criminal offence of money laundering carries one to ten years' imprisonment and fines of AED 100,000 to AED 5,000,000, and a business whose failures enable an offence is exposed. The UAE has publicly announced tens of millions of dirhams in AML fines on private-sector firms, a clear signal that enforcement is active. Set against annual compliance costs measured in the low tens of thousands, the case for getting it right is overwhelming.

Real DNFBP Scenarios Founders Face

Consider how these rules land in practice. A property brokerage closes a AED 2 million villa sale where the buyer wants to pay a large deposit in cash. The broker, as a DNFBP, must verify the buyer's identity, understand the source of the funds, and consider whether the cash element and any reluctance to explain it amount to a suspicious transaction worth reporting. Ignoring the question is not neutral; it is a compliance failure.

A jewellery retailer sells a bullion piece for AED 120,000 in cash. Because the amount exceeds AED 55,000, the dealer must have verified the customer, must file the dealers report, and must watch for structuring, such as a customer splitting the purchase into sub-threshold amounts across days. A corporate service provider is asked to form a company with a complex offshore ownership chain and a reluctant beneficial owner. The provider must establish who truly controls the entity before proceeding, and decline or report if it cannot.

In each case the DNFBP is acting as a gatekeeper exactly as the law intends. The businesses that struggle are those that see AML as paperwork bolted on after the deal. The businesses that thrive build the check into the deal itself, so that verifying a customer is as natural as issuing an invoice. That mindset, more than any single document, is what keeps a DNFBP on the right side of supervision.

A further scenario is worth flagging because it catches many founders off guard: the customer who declines to explain the source of a large payment or who becomes evasive when asked for identification. Under DNFBP rules, that reluctance is itself a red flag. You are not obliged to complete a deal you cannot verify, and walking away from a transaction you cannot satisfy yourself about is often the correct, protective decision. Supervisors expect to see that judgement exercised and documented, not overridden by the commercial pull of a sale. A DNFBP that can point to deals it declined on AML grounds demonstrates a genuinely functioning programme far more convincingly than one that has never turned business away.

The DNFBP Risk Assessment: Your Foundation

Every DNFBP obligation rests on one document that founders often skip: the enterprise-wide risk assessment. This is a written analysis of where your specific business is exposed to money laundering and terrorist financing, and it is the lens through which supervisors judge everything else you do. A generic template downloaded from the internet is worse than useless, because inspectors can tell instantly that it does not reflect your actual customers, products and geographies.

A proper assessment examines four risk dimensions. Customer risk asks who you deal with: cash-heavy buyers, offshore companies, politically exposed persons or clients from higher-risk jurisdictions all raise the score. Product and service risk asks what you offer: nominee arrangements, bearer instruments and large cash acceptance carry more risk than transparent, traceable services. Geographic risk asks where your customers and funds come from, weighting jurisdictions with weak AML controls more heavily. Delivery-channel risk asks how you onboard: non-face-to-face and intermediated relationships are riskier than in-person ones.

From this you set a risk rating for each customer and calibrate your controls accordingly, applying standard due diligence to low-risk relationships and enhanced measures to high-risk ones. The assessment must be reviewed and updated at least annually and whenever your business changes materially. Crucially, it drives your resourcing: a firm that identifies high cash exposure but never strengthens its cash controls has failed on its own analysis, and supervisors treat that gap harshly. Build the risk assessment first, and every other DNFBP duty becomes easier to justify and evidence.

How DNFBP Duties Compare to Bank Obligations

Founders sometimes assume that because they are not a bank, their AML burden is light. The comparison is instructive because the duties are far closer than expected. Both banks and DNFBPs must register with the FIU, appoint a compliance officer, perform customer due diligence, identify beneficial owners, screen against sanctions lists, monitor for suspicious activity, report through goAML, keep records for five years, and train staff. The Financial Action Task Force standards deliberately mirror the two regimes so that launderers cannot simply route around banks by using property, gold or company structures.

Where they differ is mainly in supervisor and intensity. Banks are supervised by the Central Bank of the UAE (CBUAE) with continuous, resource-heavy oversight, while most DNFBPs answer to the Ministry of Economy through risk-based, periodic inspection. Banks typically deploy automated transaction-monitoring systems, whereas a smaller DNFBP may run proportionate manual processes suited to its size and risk. That proportionality is genuine, but it is not an exemption: a small brokerage still owes the same core duties as a bank, just scaled to its risk profile.

The practical takeaway for a DNFBP is to borrow the bank mindset without the bank overhead. Treat every customer relationship as something you must be able to explain and evidence later. If you can show a supervisor who your customer is, why the relationship makes sense, and that you watched it for red flags, you have met the spirit and the letter of the regime, whatever your size.

Building a DNFBP AML Programme Step by Step

A compliant DNFBP programme can be built in a clear sequence, and following it prevents the scramble that happens when a bank or supervisor asks for evidence. Begin by confirming your category and supervisor, then register on goAML and the sanctions system. Next, appoint your compliance officer and give them genuine authority and time to do the role. With the officer in place, complete your enterprise risk assessment so every later control is grounded in evidence.

Then write your AML policies and procedures: how you onboard customers, when you escalate to enhanced due diligence, how you screen sanctions lists, how you monitor and report, and how you retain records. Choose a screening solution proportionate to your size, whether a dedicated tool or a rigorous manual process against the official lists. Roll out staff training so that everyone who meets customers can recognise the red flags relevant to your business, and record that training.

Finally, operate the programme and prove it. Keep dated due diligence files, screening results, internal escalations and any filed reports. Complete supervisory questionnaires on time and prepare for inspection by keeping a single, well-organised compliance file. Review the whole programme annually, updating the risk assessment and policies as your business evolves. This sequence turns a set of abstract legal duties into a running system, and it is exactly the system Noble Core builds and maintains for DNFBP clients so that compliance supports the business rather than surprising it.

Common Mistakes DNFBPs Make

  • Believing you are exempt because you are small, new, or trade mostly by bank transfer, when a single in-scope activity or cash deal brings you into the regime.
  • Registering on goAML but not on the sanctions-list system, leaving a visible gap that supervisors treat as non-compliance.
  • Appointing a compliance officer in name only, with no risk assessment, no reviews and no filed reports to show the role is real.
  • Skipping beneficial-ownership checks on corporate customers, which is precisely the vulnerability the DNFBP rules exist to close.
  • Failing to establish source of funds on large cash deals, especially in real estate and precious metals, where the AED 55,000 trigger applies.
  • Discarding records before five years have passed, then being unable to evidence due diligence during an inspection.
  • Missing the Ministry of Economy's annual questionnaire or inspection requests, each of which is a reportable breach on its own.
  • Confusing AML duties with corporate tax registration and assuming that meeting one covers the other, when they are separate obligations.

Meet Your DNFBP Duties with Noble Core

DNFBP compliance is not a form you file once; it is a system you run alongside your business. Noble Core builds that system for you. We confirm whether your activity makes you a DNFBP, identify your correct supervisor, register you on goAML and the sanctions system, appoint or support your compliance officer, and deliver the risk assessment, policies, screening process and training that supervisors expect to see.

Because these duties are inseparable from how you set up and bank your company, we handle them within your wider business setup in Dubai rather than as an afterthought. We align your DNFBP obligations with the broader AML compliance costs, deadlines and penalties that every small business must plan for, your corporate tax registration and filing with the Federal Tax Authority, and your corporate bank account opening, where banks now inspect a DNFBP's AML posture closely before approving. You can confirm tax duties with the Federal Tax Authority and check DNFBP supervision through the Ministry of Economy.

The difference between a compliant DNFBP and a fined one is rarely intent; it is preparation. Book a free 20-minute consultation and we will tell you exactly where your business stands and what it takes to stay clear of penalties.

Talk to Our Experts

Noble Core tells you whether your business is a DNFBP, registers you on goAML, and builds the AML programme, policies and training that supervisors expect. Free 20-minute consultation.

or use our contact form · info@noblecoreventures.com

Frequently Asked Questions

What does DNFBP stand for in the UAE?

DNFBP stands for Designated Non-Financial Businesses and Professions. It covers non-bank businesses with anti-money-laundering duties, such as real estate agents, precious-metals dealers and corporate service providers.

What are the five DNFBP categories?

Real estate agents and brokers, dealers in precious metals and stones, corporate service providers, auditors and accountants, and independent legal professionals such as lawyers and notaries.

Do DNFBPs have to register on goAML?

Yes. Every DNFBP must register on the UAE Financial Intelligence Unit’s goAML platform and the sanctions-list system, appoint a compliance officer, and be ready to file reports.

Who supervises DNFBPs in the UAE?

The Ministry of Economy supervises most DNFBP categories nationally. Certain free zones and professional bodies supervise their own members, but the AML obligations are set by national law.

What is the cash threshold for precious-metals dealers?

Dealers in precious metals and stones fall under DNFBP reporting duties for single or linked cash transactions equal to or above AED 55,000, and must file the dedicated dealers report.

What AML duties does a DNFBP have?

Registering on goAML, appointing a compliance officer, conducting customer due diligence, screening against sanctions lists, reporting suspicious transactions, keeping records five years and training staff.

What fines do DNFBPs face for AML breaches?

Under Cabinet Decision No. 16 of 2021, administrative fines range from AED 50,000 to AED 5,000,000 per violation, plus possible licence suspension and public naming.

Are free zone companies DNFBPs?

Yes if their activity is in scope. A free zone real estate broker, precious-metals trader or corporate service provider has the same DNFBP duties as a mainland business.

How long must a DNFBP keep records?

A DNFBP must keep customer identification records, transaction records and reports for at least five years after the business relationship ends or the transaction completes.

More Posts

Contact us for Free Consultation

email (1) - Noble Core Ventures
Thank You!
We’ve received your request for business setup services and will contact you soon. Our team is ready to help you start your business smoothly in the UAE!
Free guideMainland vs Free Zone