Back to Glossary

Entry · Business

goAML

GoAML is the UAE Financial Intelligence Unit's electronic platform for reports from entities with anti-money-laundering reporting duties. Financial institutions and covered designated non-financial businesses and professions use it to file suspicious transaction or activity reports and other required reports. Registration and reporting obligations depend on the entity's regulated activity.

From the Money Master HQ dictionary, founded by Shihan Sheriff (FCMA, VP of Finance at Nomod, CFO at Esanjo Ventures). How these definitions are written.

What it means

A jewellery dealer notices a transaction pattern that raises a money-laundering concern; if the dealer is a reporting entity under UAE rules, staff escalate the concern to the responsible compliance function, and the business may then need to file a report with the UAE Financial Intelligence Unit through goAML. goAML is a secure reporting channel, not a public complaints website, and the UAE FIU says reporting entities connect to the platform to submit suspicious transaction reports. The Ministry of Economy and Tourism says registration for designated non-financial businesses and professions, or DNFBPs, is mandatory, and its guidance describes categories and steps, including an initial SACM access stage.

Businesses should check the current regulator guidance for their exact activity rather than assume a neighbouring firm's classification applies. Potentially covered activities include parts of real estate, precious metals and stones, accounting, legal work and company services, and the exact regulatory definition and any thresholds matter.

An ordinary shop selling unrelated goods should not be told it is covered solely because it handles cash. Registration is not the whole compliance programme, because a covered business needs customer due diligence, risk assessment, controls, record keeping and trained staff appropriate to its obligations.

An appointed compliance officer or money laundering reporting officer typically coordinates reporting, and employees need a clear internal escalation route, including what facts to record and whom to contact. Suspicion is not the same as certainty, so a reporting entity should assess available facts and follow legal and regulator guidance on when and how to report, since delay while seeking impossible proof can defeat the purpose of a suspicious report.

The FIU's reporting process distinguishes report types, as a suspicious transaction report and suspicious activity report may reflect different underlying circumstances, and other report categories can apply to specific sectors or transactions, so choose the form directed by current official guidance. A useful internal timeline measure is reports submitted within the applicable deadline divided by all reports due in that period, so nine of ten equals 90%.

Deadlines can vary with the type of reporting duty and current rules, so do not copy a timer from another jurisdiction or from an old training slide, and the compliance officer should verify the relevant rule and retain evidence of the filing. The report should be complete enough to support analysis, identifying the parties, transactions, reasons for concern and supporting information requested by the system.

Confidentiality is important, as staff should not tell a customer that a suspicious report has been or will be made if the law prohibits disclosure, and training should explain what staff can say while ordinary service questions are handled. A business with several branches must know which legal entity is registered and which people have access, since shared passwords and a departed employee's active account pose operational risks, and the official access-management process should be followed when authorised staff change.

A rejected or incomplete submission needs follow-up, so do not assume that clicking 'submit' once means the report was accepted. A firm may use an adviser, but responsibility does not disappear when drafting help is outsourced, so the business should understand its own suspicion and review any filing made on its behalf under the applicable process, with sensitive customer information kept only in permitted secure channels.

Regulators can update classifications, guides and portals, so the Ministry's page and the FIU's instructions are better references for a current workflow than a dated blog, and owners should assign someone to check for changes and maintain access before an urgent case arises; for a covered owner, the practical sequence is to establish whether the activity triggers duties, register correctly, train staff, assess and escalate concerns, and file securely when required, because goAML is the route for reporting, not a substitute for judgment or the wider anti-money-laundering framework.

In practice

Real-world examples.

1

Example

A covered precious-metals dealer completes the applicable goAML registration steps.

2

Example

An employee escalates a suspicious transaction pattern to the firm's compliance officer.

3

Example

The officer files the appropriate report and keeps the submission acknowledgement.

Formula

Calculation

Illustrative internal timeliness = reports filed by their applicable deadline / reports due x 100. Nine of ten is 90%; verify the deadline separately for each duty.

Case study

Seen in the real world.

This entirely fictional example follows Falcon Jewels, an invented UAE dealer. Staff knew a portal existed but had no clear escalation procedure and an old employee still held access. The firm checked its regulatory classification, updated authorized access and trained staff on internal reporting. In a later concerning case, the compliance officer used the official process and kept the acknowledgement. The case does not claim an inspection outcome or assume that a report proves wrongdoing.

Watch out

Common mistakes.

  • Assuming a portal login is the whole AML compliance program.
  • Using another sector's report type or deadline without checking current guidance.
  • Alerting a customer to a protected suspicious report.

Questions

People also ask.

What is goAML?

The UAE FIU's electronic system for reporting entities to submit specified AML reports.

Who must register?

Covered financial institutions and DNFBPs, subject to the applicable regulated-activity rules.

How do DNFBPs register?

Follow the current FIU and relevant supervisor instructions, including any required SACM access step.

Was this explanation helpful?

From the founder's library

Accounting Fundamentals: A Non-Finance Manager's Guide to Finance and Accounting, by Shihan Sheriff

Take it further with the book.

Build your financial confidence beyond this definition. Shihan's full-length guide, Accounting Fundamentals, takes the same plain-English approach and turns it into a complete, practical playbook for non-finance managers, business owners and students - with chapter-end quiz answers and presentation slides included.

US$2.24US$2.99

25% off with code MMHQ25, applied at checkout. Priced in USD - checkout may show the equivalent in your local currency.

View the book and save 25%
Last updated · October 8, 2026
Browse all terms →

Disclaimer

The information provided in this finance dictionary is for educational and informational purposes only. It should not be construed as financial, investment, legal, or tax advice. Always consult with a qualified professional before making any financial decisions. Money Master HQ makes no representations or warranties about the accuracy, completeness, or suitability of this information. Use of this content is at your own risk.