Must a UAE accounting firm have an independent audit function to test its own AML programme?
Yes. Internal AML policies, controls and procedures must include an independent audit function whose job is to test whether those controls actually work. This is a distinct requirement from the appointment of a Compliance Officer, and it applies to accounting and audit firms in the same way it applies to any other DNFBP.
The point of independence is that the person or team testing the controls must not be the same person who designed or operates them. In a small practice this is often achieved by engaging an external reviewer or by allocating the testing role to a partner outside the compliance line. The review should cover the adequacy of customer due diligence files, the quality of risk assessments, whether suspicion escalations were handled correctly, sanctions screening coverage, and record retention. Findings need to be documented and reported to senior management with a remediation timetable.
Supervisors commonly ask to see the most recent independent AML review report during an inspection. A firm that has policies on paper but no evidence of testing tends to be treated as having a control gap rather than a documentation gap.
Legal Reference (UAE):
· Cabinet Resolution No. 134 of 2025, Article 21(6) — internal policies must include an independent audit function to test effectiveness and adequacy of AML controls
· Cabinet Resolution No. 134 of 2025, Article 22(3) — Compliance Officer must review internal systems and report periodically to senior management
For more details, consult the full text of Cabinet Resolution No. 134 of 2025 or seek guidance from your AML compliance officer.
AML compliance requirements for auditors and accountants in the UAE