Skip to Content
mkACE Management Consultancy logo reveal. Click once to finish the animation, click again or press Escape to close. MKACE management consultancy AdvisoryComplianceExcellence
AML & CFT Compliance

Build an AML framework that works in daily files.Not only in the policy document.

Practical AML/CFT support for applicable DNFBPs—from business risk assessment and customer due diligence to goAML readiness, staff training and remediation tracking.

Risk-basedControls linked to customers, products and countries
File-levelCDD, EDD and approvals made usable
goAML-readyRegistration and reporting workflow mapped
When this service fits

Choose it for a defined operating need.

Use this service where AML obligations apply but policies, customer files, screening, training or reporting readiness do not match the actual risk profile.

01

Newly regulated or registered DNFBP

The business needs an AML framework and goAML readiness aligned to its licensed activities.

02

Weak customer files

CDD, beneficial ownership, source information or risk ratings are incomplete or inconsistent.

03

Regulatory remediation

Inspection findings, notices or internal reviews require a controlled correction plan.

04

Growth or higher-risk exposure

New countries, customer types, delivery channels or transaction patterns change the business risk.

How the engagement moves

Four stages. A visible output at every stage.

The framework is built from the business risk downward, then tested against actual customer files and escalation responsibilities.

01Stage 01

Confirm applicability and exposure

Review licensed activities, customers, products, delivery channels, countries and transaction profile.

Stage outputAML applicability and risk map
02Stage 02

Assess the existing framework

Test governance, policies, screening, customer files, training, monitoring and goAML readiness.

Stage outputGap assessment
03Stage 03

Build or remediate controls

Prepare proportionate policies, templates, workflows, responsibilities and escalation points.

Stage outputAML operating framework
04Stage 04

Test and maintain

Review sample files, train relevant staff and track remediation and periodic-review actions.

Stage outputCompliance action tracker
Defined deliverables

What management receives.

Deliverables are adapted to the DNFBP’s sector, size, customer base and risk profile.

DELIVERABLE / 01

Business Risk Assessment

A structured assessment of customer, product, channel, geography and transaction exposure.

DELIVERABLE / 02

AML/CFT policies and procedures

Governance, CDD/EDD, screening, monitoring, escalation, reporting, record and training controls.

DELIVERABLE / 03

Customer-due-diligence toolkit

Risk rating, beneficial-owner, PEP, sanctions, source information and approval templates.

DELIVERABLE / 04

goAML and remediation tracker

Registration/readiness actions, reporting workflow and compliance gaps assigned to owners and dates.

DNFBP enforcement environment

Registration and operational compliance both matter.

The UAE Ministry of Economy has taken enforcement action against DNFBP establishments that failed to register in goAML. Registration alone is not the full framework: the business must operate appropriate risk-based controls and reporting processes.

UAE Ministry of Economy — DNFBP goAML enforcement ↗
Governance

Named responsibility

Senior management and the compliance function need defined authority and escalation.

CDD

Know the customer and UBO

Identity, ownership, purpose and risk must be supported and periodically reviewed.

Screening

PEP and sanctions controls

Screening results, potential matches and approvals need a documented workflow.

Reporting

Suspicion escalation

Internal escalation and goAML reporting should protect confidentiality and avoid tipping off.

Records to begin

Start with the information that creates the position.

We tailor the final request list after an initial discussion. These records normally provide the starting point.

  • Trade licence and regulated activities
  • Customer and transaction profiles
  • Countries and delivery channels
  • Current AML policy and risk assessment
  • Sample customer and UBO files
  • Screening system and match records
  • goAML registration and reporting status
  • Inspection findings, training and compliance records
Questions before you engage

Clear answers about this scope.

The final scope depends on the entity, operating model, records, authority requirements and the facts confirmed during onboarding.

Who is typically treated as a DNFBP?

Relevant UAE categories include real estate brokers/agents, dealers in precious metals and stones, auditors/accountants, company service providers and legal professionals, subject to the applicable rules and activities.

Is goAML registration enough?

No. The business also needs a proportionate risk assessment, CDD/EDD, screening, monitoring, training, governance and reporting process.

Can you review sample customer files?

Yes. File testing is useful for comparing written policies with the controls actually performed.

Do you act as MLRO?

Any compliance appointment requires a separate role-specific assessment and engagement. It is not assumed within a general AML review.

Can you assist after an inspection?

Yes. Findings can be converted into a prioritised remediation plan with evidence and ownership tracked.

Related services

Move to the service that matches the next requirement.

Each page has a defined scope. Select the current service or move to another service when the business need changes.

Contact Us

Test whether the written framework works in real customer files.

Share the licensed activity, customer profile and current AML/goAML position. We will begin with applicability and risk.

Request an AML compliance review