We help businesses and regulated entities understand their obligations, assess risks, review policies and procedures, and develop a compliance framework aligned with their activity, supervisory authority, customers and transaction profile.
The applicable obligations may vary according to the company's activity, licence, supervisory authority, operating model and risk exposure.
The applicable obligations and supervisory authority may vary according to the licensed activity, activities actually performed, business location, customer profile, products, services and transaction structure.
A standardised compliance framework should not be applied mechanically to businesses with different activities, structures and risks.
What activities is the company licensed to perform, and what does it actually do?
Which authority supervises the business and sets its registration, reporting and compliance expectations?
Who are the customers, what services are provided, and through which channels?
What risks arise from customers, jurisdictions, services, transactions, delivery channels and technologies?
Needs to determine the applicable obligations and build an initial governance, risk and due-diligence structure.
Needs to update policies and procedures to reflect current operations, risks and regulatory requirements.
Needs clarity regarding authority, escalation routes, reporting, documentation and senior-management interaction.
Needs to organise records, review practical implementation and identify gaps before supervisory review.
Needs to analyse regulatory observations and prepare a structured, documented remediation plan.
Needs to assess the AML risks associated with new products, technologies, customers or jurisdictions.
An effective framework should connect risk assessment, governance, customer onboarding, monitoring, escalation, reporting, training, record keeping and periodic review.
The scope of work should be determined after reviewing the company's activity, licence, supervisory authority, operating structure and risk profile.
Review the company's licensed and actual activities, jurisdiction and supervisory authority to identify the relevant AML compliance framework.
Review existing policies, procedures, customer files, records and practices to identify gaps between written requirements and actual implementation.
Support the preparation or update of a documented risk assessment covering customers, jurisdictions, services, transactions and delivery channels.
Develop or review internal policies and procedures that reflect the company's operations, size and risk exposure.
Review customer onboarding, identity verification, beneficial ownership, risk classification and enhanced due-diligence requirements.
Review authority, reporting lines, escalation procedures and senior-management involvement within the applicable framework.
Review screening, potential-match handling, escalation and documentation procedures.
Develop or review internal suspicion indicators, escalation routes, assessment documentation and reporting procedures.
Reporting decisions remain with the company's Compliance Officer and management, unless specifically authorised and legally appropriate.
Provide legal and procedural guidance concerning relevant registration, reporting or process requirements where this falls within the firm's verified scope.
The firm does not represent the Financial Intelligence Unit and does not guarantee registration or report acceptance.
Support the development of role-based legal and practical training content for management and employees.
Review the organisation of policies, records, files and implementation evidence, and identify issues requiring remediation.
The service does not guarantee the outcome of an inspection.
Support the analysis of regulatory observations, prioritisation of corrective actions, allocation of responsibilities and documentation of implementation.
Review the framework when the company's business, customers, products, markets, technology or regulatory obligations change.
A generic policy that does not reflect the business activity
An outdated enterprise risk assessment
No clear customer-risk methodology
Incomplete customer files
Beneficial ownership not adequately documented
Unclear procedures for politically exposed persons
No documented internal escalation path
Weak documentation of Compliance Officer decisions
Generic training unrelated to employee roles
Sanctions screening without a potential-match process
No regular reporting to senior management
No testing of control effectiveness
Poorly organised regulatory records
Inconsistent implementation across staff or branches
Full reliance on a third-party system without internal oversight
Launching new services or technologies without prior risk assessment
Regulatory findings being addressed without a documented plan
The existence of policies does not by itself demonstrate an effective framework. The company should be able to explain how decisions are made, controls are applied and evidence is retained.
The inclusion of a sector does not mean that every business within it is subject to identical obligations. The activity, licence and supervisory authority must be reviewed.
Review the activity, licence, supervisory authority and company structure.
Review available policies, procedures, templates, customer files, reports and records.
Identify key risks, weaknesses and priorities.
Develop the required policies, procedures, responsibilities, models and escalation paths.
Support management, the Compliance Officer and operational teams in applying the framework.
Test implementation and update the framework when risks, operations or regulatory expectations change.
A supervisory authority may review policies, risk assessments, customer files, management reports, training records, monitoring procedures, escalation decisions and supporting documentation. The framework should be explainable and evidenced, not merely documented.
A review does not guarantee the absence of violations or a particular regulatory outcome.
This depends on the company's actual activity, licence, supervisory authority, services and transaction profile. The regulatory scope should be determined before building or updating the framework.
A general policy is not sufficient if it does not reflect the company's risks, procedures, staff responsibilities, monitoring, escalation and documentation practices.
It is a documented assessment of risks arising from customers, jurisdictions, products, services, transactions and delivery channels. It should inform the level of controls applied by the business.
Customer due diligence includes the core procedures for identifying and verifying the customer and beneficial owner and understanding the relationship. Enhanced due diligence applies where risk is higher and additional information, approval or monitoring is required.
The detailed requirements depend on the applicable framework and supervisory authority. The current executive framework includes requirements concerning a Compliance Officer with appropriate authority, independence and competence.
Senior management, the company and the individuals assigned compliance responsibilities remain accountable for implementation. An external adviser may provide support but does not remove internal responsibility.
Certain forms of reliance or outsourcing may be permitted under the applicable rules, but the company may remain responsible for the effectiveness of the process, the accuracy of information and oversight of the service provider.
This depends on the company's classification, regulatory status and applicable reporting obligations. The business's activity and supervisory framework should be reviewed.
Reporting decisions depend on the relevant facts, indicators and legal requirements. The organisation should maintain a clear internal assessment, escalation and reporting procedure.
The applicable framework includes restrictions on disclosing to a customer or another party that a suspicious transaction report has been submitted or that a related investigation may exist.
The executive framework includes minimum retention requirements for relevant records and documents, commonly for at least five years, with the starting point depending on the type of record or relationship.
The service may include reviewing the existing framework, records and implementation evidence and identifying remediation priorities. It does not guarantee the outcome of an inspection.
The appropriate scope can be determined after reviewing the company's activity, licence, supervisory authority, operations and risk exposure.
This page concerns preventive and corporate AML compliance. Where a company or its management faces a criminal investigation, allegation or asset-freezing measure, the enquiry should be directed to the separate Money Laundering Defence service.
Money Laundering Defence Lawyers in Dubai and the UAEShare basic information about the company's activity, licence and current compliance framework so the legal team can understand the potential scope of review and the appropriate next step.
Do not submit customer data, suspicious transaction reports, identity documents or confidential regulatory correspondence through this initial form.