Is an independent AML audit mandatory for DNFBPs in the UAE?
Yes. A DNFBP must maintain an independent audit function to test the effectiveness and adequacy of its internal AML policies, controls and procedures. This is a required element of the internal compliance arrangements that every regulated firm must put in place, and it forms the third line of defence in a sound AML framework.
An independent audit must be carried out by a party that is not involved in the day-to-day running of the compliance programme, so that it can objectively assess whether risk assessments, customer due diligence, sanctions screening, reporting and record-keeping are working as intended. Larger firms may use an internal audit team, while smaller DNFBPs often engage an external specialist. The scope, frequency and depth of the audit should be proportionate to the size and risk profile of the business, and findings should be reported to senior management for action.
Legal Reference (UAE):
ยท Cabinet Resolution No. 134 of 2025 (Executive Regulations), Article 21(6) requires an independent audit function to test internal AML controls.
For more details, consult the full text of Cabinet Resolution 134 of 2025 or seek guidance from your AML compliance officer.