Must a UAE gaming operator keep a record of decisions not to file a suspicious activity report?
Yes. Gaming operators must have defined protocols covering internal reporting to the Money Laundering Reporting Officer, protection for the person making the notification, investigation of reported activity, external reporting to the Financial Intelligence Unit, and a record of decisions not to submit reports.
The last item is the one operators most often miss. When an internal escalation is reviewed and the Money Laundering Reporting Officer concludes that the activity is explainable and no filing is warranted, that conclusion and its reasoning must be documented. The Compliance Officer function more generally requires that where a decision is taken to retain a matter rather than notify the Financial Intelligence Unit, the reasons are stated and kept in full confidentiality.
These records fall within the five-year retention requirement that applies to due diligence documentation, transaction records, internal and external suspicious activity reports, correspondence with the Financial Intelligence Unit and risk assessment documentation. During supervisory review, the no-file decisions are often the most informative population, because they show whether the operator’s suspicion threshold is calibrated correctly or set too high.
Legal Reference (UAE):
· Commercial Gaming Policy Paper, Section 2.1.2 — suspicious activity protocols must include a record of decisions not to submit reports, and five-year record retention
· Cabinet Resolution No. 134 of 2025, Article 22(2) — Compliance Officer must state reasons where a matter is retained rather than notified
For more details, consult the full text of the Commercial Gaming Policy Paper or seek guidance from your AML compliance officer.