The short answer
First establish whether your activities are in scope and which supervisor is responsible. For DNFBPs required to register, goAML provides access to the Financial Intelligence Unit’s reporting system. Registration is not a compliance certificate and does not replace a working AML programme.
Prepare the official registration documents
The Ministry’s registration page lists an institutional authorisation letter, the representative’s passport, residence visa and Emirates ID, and a commercial trade licence for companies. It describes protection-system registration and authenticator-based access. Follow the current official registration guide for the exact application route and any case-specific requests.
Do not send authentication codes to an adviser. The authorised person should control their access and follow the portal’s current instructions.
Use an application readiness sheet
This is Meraki’s suggested organisational checklist. It is not an additional list of legal documents or a promise that the supervisor will approve an application.
| Check | Record internally |
|---|---|
| Scope | Activity, jurisdiction, responsible supervisor and unresolved applicability questions. |
| Authority | Who may act for the entity and the current authorisation record. |
| Document quality | Validity, spelling and legal-name consistency; identify missing pages before submitting. |
| Application ownership | Named owner, secure contact channel, submission date and reference. |
| Queries | Each official request, response owner and completion status. |
| Outcome | Approval or outstanding requirements; do not treat a submitted application as approved. |
After approval: make the handover usable
A useful handover is something the business can operate without relying on one person’s memory. Confirm who is responsible for the next action and where the evidence is stored.
- Record who owns administration and who monitors official communications.
- Confirm authorised access works without circulating passwords in email or messaging groups.
- Keep the official acknowledgement and current guidance in a controlled location.
- Document how staff raise concerns internally and who reviews them.
- Track staff changes so access and responsibilities can be reviewed through the proper process.
- Agree a follow-up review of open actions; a registration receipt alone is not the end of the engagement.
Keep operational compliance separate from portal administration
The March 2026 DNFBP guidance covers governance, risk assessment, customer due diligence, reporting and record keeping. It addresses confidentiality and tipping-off. If a concern arises, escalate through the authorised compliance process; do not discuss a possible suspicious-activity report with the customer.
To understand the wider programme and supervisory distinctions, use the companion AML guide. Detailed report classifications, sanctions decisions and individual cases need the relevant official instructions and qualified review.
Agree the scope before appointing support
Ask whether the proposed work is application assistance, programme preparation, training or ongoing support, and which items are excluded. Request clear ownership of submissions and a list of deliverables. Do not assume an external consultant takes over management’s responsibilities.
Meraki’s AML/goAML page sets out its support route. Do not send customer identity records or suspicious-activity details through the general enquiry form.
AML and goAML support Explore related compliance services Ask about the preparation scope

