21 July 2026 · How To

How to Register & Report on goAML

Registering on goAML runs in five practical steps: appoint your AML compliance officer, often called an MLRO, first, since the registration is built around a named natural person with a valid Emirates ID; pre-register on your supervisory authority's portal to obtain goAML access credentials; complete the goAML portal registration itself using your trade licence, the compliance officer's Emirates ID and passport, and an authorisation letter; wait for approval and then verify your entity profile, reporting categories and activities once you can log in; and finally build the internal side that registration alone does not cover — your written AML/CFT programme, business risk assessment, customer due diligence files and sanctions screening process. Registration itself is free and is typically approved within days, so there is little excuse for delay. From there, day-to-day compliance means running CDD and enhanced due diligence on higher-risk clients, keeping records of every check and decision, and filing a Suspicious Transaction Report through goAML whenever you have reasonable grounds to suspect a transaction relates to crime or money laundering.

Exiloz Management & Tax Consultant · Dubai-based FTA-focused advisory · VAT, corporate tax & accounting

RegisterCompliance officerCDDFile STRs
goAMLRegister
CDDOn clients
STRWhen suspicious
Set up

Register and build the programme

Registration and the compliance programme are two different jobs, and treating goAML registration as the finish line is one of the most common mistakes DNFBPs make. The registration opens your reporting channel with the UAE Financial Intelligence Unit; the programme is the set of internal controls — a named compliance officer, a written risk assessment, and documented procedures — that actually keeps you compliant between filings.

  • Appoint your compliance officer (MLRO) before starting the goAML registration itself.
  • Pre-register on your supervisory authority portal to obtain goAML access credentials.
  • Complete goAML registration with your trade licence, compliance officer ID and an authorisation letter.
  • Adopt a written AML/CFT programme once you have portal access.
  • Complete a documented business risk assessment covering customers, geography and delivery channels.
Operate

CDD and reporting day to day

Once registered, AML compliance becomes an ongoing operational habit rather than a one-off project. Every new client relationship needs identity verification reaching through to beneficial owners, a sanctions-list check, and a risk rating that decides how closely you monitor the relationship afterward — and every one of those steps needs to leave a paper trail, because an inspector will ask to see the file, not just be told the process exists.

  • Identify clients and verify beneficial owners behind corporate structures.
  • Screen every client against targeted financial sanctions lists before onboarding.
  • Risk-rate each relationship and apply enhanced due diligence where warranted.
  • Keep documented records of every check, decision and periodic review.
  • File a Suspicious Transaction Report through goAML whenever grounds to suspect arise.
The registration steps

How the goAML portal registration actually works

The portal process trips up more businesses on sequencing than on complexity. Skipping the pre-registration step, or trying to register before a compliance officer is formally appointed, is the most common reason a submission bounces back — and every bounce restarts the clock while your business continues operating unregistered in the meantime.

  • Appoint the compliance officer first — the whole registration is built around this named person.
  • The supervisory-portal pre-registration step must happen before goAML access is issued.
  • Have the trade licence, compliance officer's Emirates ID, passport and authorisation letter ready together.
  • After approval, verify entity details, reporting categories and activities before your first filing.
Common mistakes

Where DNFBPs go wrong after registering

The businesses that get fined are rarely the ones that struggled with the goAML portal itself — registration is free and usually approved within days. They are almost always the ones that registered and then stopped, treating the portal login as proof of compliance rather than the starting point for a programme that still needs a risk assessment, CDD files, staff training and a working STR process behind it.

  • Registering on goAML without a written risk assessment or AML programme.
  • Skipping beneficial-owner checks on corporate clients, rather than looking through to natural persons.
  • Treating sanctions screening as optional rather than a mandatory, inspected control.
  • Filing an STR late instead of filing a defensive report as soon as suspicion arises.

Frequently Asked Questions

For DNFBPs standing up AML compliance from a blank slate, not just logging into goAML.

Do I need a compliance officer?

Yes. Every DNFBP must appoint a compliance officer — often called an MLRO — and adopt a written AML/CFT programme, even if that officer is the business owner in a sole practice. The goAML registration itself is built around this named individual's Emirates ID, so the appointment needs to happen before you start the portal registration, not after.

What is CDD?

Customer due diligence is the process of identifying and verifying your clients and the beneficial owners standing behind them, then assessing how much risk that relationship carries. Higher-risk clients — larger transactions, complex ownership structures, or higher-risk geographies — need enhanced due diligence, which means deeper checks and closer ongoing monitoring.

When do I file an STR?

File a Suspicious Transaction Report through goAML whenever you have reasonable grounds to suspect a transaction, or the funds behind it, relate to crime or money laundering — you do not need proof, only a reasonable basis for suspicion. Filing early and defensively is always the safer choice; a late STR filed only after the fact is treated far more seriously than a report that turns out not to lead anywhere.

What documents do I need to register on goAML?

You will need your trade licence, the compliance officer's Emirates ID and passport, and an authorisation letter confirming their appointment, plus your supervisory-portal pre-registration credentials before the goAML portal registration itself can be completed. Having all of this ready in one sitting avoids the resubmission delays that are the most common cause of a slow approval.

How long does goAML registration take?

Registration itself is generally free and is usually approved within days once a complete submission is made, so there is little practical excuse for delay. Most of the time DNFBPs lose is spent gathering documents or fixing an incomplete first submission, not waiting on the regulator.

Does registering on goAML mean I am fully compliant?

No. Registration only opens your reporting channel — it does not replace the risk assessment, CDD files, sanctions screening and staff training that make up the actual AML programme behind it. An inspector reviewing a registered-but-otherwise-empty file will still record multiple violations.

Can Exiloz build our programme?

Yes. We handle the goAML and Ministry of Economy registrations, appoint and document your compliance officer role, write your risk assessment, and set up working CDD and STR processes so the registration is backed by a programme that actually holds up at inspection.

Stand up your AML programme

Exiloz registers you on goAML and the Ministry of Economy system, appoints and documents your compliance officer role, and builds working CDD and STR processes behind it.

Book a Consultation Call Us