Guide

goAML registration in the UAE: preparation and handover checklist

What to prepare before applying, what to check after approval and why portal access is only one part of AML compliance.

Updated 7 October 2026 · Last verified 7 October 2026

The short answer

First establish whether your activities are in scope and which supervisor is responsible. For DNFBPs required to register, goAML provides access to the Financial Intelligence Unit’s reporting system. Registration is not a compliance certificate and does not replace a working AML programme.

Prepare the official registration documents

The Ministry’s registration page lists an institutional authorisation letter, the representative’s passport, residence visa and Emirates ID, and a commercial trade licence for companies. It describes protection-system registration and authenticator-based access. Follow the current official registration guide for the exact application route and any case-specific requests.

Do not send authentication codes to an adviser. The authorised person should control their access and follow the portal’s current instructions.

Use an application readiness sheet

This is Meraki’s suggested organisational checklist. It is not an additional list of legal documents or a promise that the supervisor will approve an application.

CheckRecord internally
ScopeActivity, jurisdiction, responsible supervisor and unresolved applicability questions.
AuthorityWho may act for the entity and the current authorisation record.
Document qualityValidity, spelling and legal-name consistency; identify missing pages before submitting.
Application ownershipNamed owner, secure contact channel, submission date and reference.
QueriesEach official request, response owner and completion status.
OutcomeApproval or outstanding requirements; do not treat a submitted application as approved.

After approval: make the handover usable

A useful handover is something the business can operate without relying on one person’s memory. Confirm who is responsible for the next action and where the evidence is stored.

  • Record who owns administration and who monitors official communications.
  • Confirm authorised access works without circulating passwords in email or messaging groups.
  • Keep the official acknowledgement and current guidance in a controlled location.
  • Document how staff raise concerns internally and who reviews them.
  • Track staff changes so access and responsibilities can be reviewed through the proper process.
  • Agree a follow-up review of open actions; a registration receipt alone is not the end of the engagement.

Keep operational compliance separate from portal administration

The March 2026 DNFBP guidance covers governance, risk assessment, customer due diligence, reporting and record keeping. It addresses confidentiality and tipping-off. If a concern arises, escalate through the authorised compliance process; do not discuss a possible suspicious-activity report with the customer.

To understand the wider programme and supervisory distinctions, use the companion AML guide. Detailed report classifications, sanctions decisions and individual cases need the relevant official instructions and qualified review.

AML duties beyond registration

Agree the scope before appointing support

Ask whether the proposed work is application assistance, programme preparation, training or ongoing support, and which items are excluded. Request clear ownership of submissions and a list of deliverables. Do not assume an external consultant takes over management’s responsibilities.

Meraki’s AML/goAML page sets out its support route. Do not send customer identity records or suspicious-activity details through the general enquiry form.

AML and goAML support Explore related compliance services Ask about the preparation scope

Sources

Tell us about your business

A complimentary introductory discussion, then an agreed proposal.

What do you need?

Enter a phone number or email so we can reply. Do not send passwords, ID documents or financial account details. Privacy notice.

WhatsApp instead
WhatsApp