Table of Contents

Ready to Defeat Your AML Compliance Obstacles?

Citadel Brings Revolution with Secure Solutions to AML Compliance Problems

Key Takeaways: goAML Registration UAE

  • goAML is the official online platform for reporting suspicious financial activities to the Financial Intelligence Unit (FIU).
  • UAE regulated entities, including Financial Institutions, DNFBPs and VASPs, are required to register on the goAML platform to meet AML reporting obligations.
  • goAML registration is free for all regulated entities subject to UAE AML laws.
  • Failure to register on the goAML platform and non-compliance with reporting obligations may result in fines, penalties, or imprisonment.

What is goAML?

goAML is the official reporting platform developed by the United Nations Office on Drugs and Crime (UNODC). It is used by the UAE Financial Intelligence Unit (FIU) to receive, analyse, and distribute suspicious activity and transaction reports (SAR/STR) from regulated entities to combat money laundering and terrorist financing (ML/TF).

 

goAML is the single platform to report suspicious transactions, activities, sanctions matches and other required information. It allows the FIU to review reports quickly and take required actions. FIU obtains the information and shares relevant data with law enforcement and other competent authorities to support investigations.

 

AML compliance involves KYC, risk assessments, screening, employee training, ongoing monitoring, record-keeping, and regulatory reporting. When a regulated entity detects suspicious activity or transactions, it reports the case to the FIU through the goAML system.

Who Must Register for goAML in UAE?

In the UAE, regulated entities subject to AML/CFT laws are required to register on the goAML portal to report suspicious activities and transactions. This includes:

  • Financial Institutions
    • Banks and Investment Firms
    • Insurance Companies
    • Exchange Houses
    • Fintech Firms
  • Designated Non-Financial Businesses and Professions (DNFBPs)
    • Real Estate Agents and Brokers (REAB)
    • Trust and Company Service Providers (TCSPs)
    • Dealers in Precious Metals and Stones (DPMS)
    • Lawyers, notaries, and independent legal professionals
    • Independent accountants and auditors
    • Commercial gaming Operators
  • Virtual Asset Service Providers (VASPs)

Is goAML Registration Mandatory in UAE?

goAML registration is mandatory and essential for timely reporting by UAE entities subject to AML/CFT obligations. goAML platform makes reporting convenient for UAE FIs, DNFBPs, and VASPs. Regulated entities can file the following reports through the goAML portal:

  • Suspicious Activity Report (SAR)
  • Suspicious Transaction Report (STR)
  • Dealers in Precious Metals and Stones Report (DPMSR)
  • Real Estate Activity Report (REAR)
  • Confirmed Name Match Report (CNMR)
  • Partial Name Match Report (PNMR)
  • High-Risk Country Transaction Report (HRC)
  • High-Risk Country Activity Report (HRCA)

Failure to register on the goAML portal is a compliance failure to detect and report suspicious activities or transactions related to money laundering and terrorist financing.

Documents Required for goAML Registration

Regulated entities in the UAE are required to provide specific documents to register on the goAML system. This includes:

  • The valid Trade License of the entity.
  • A copy of the passport, Emirates ID, and resident visa of the Compliance Officer.
  • An authorisation letter from the organisation confirming the appointment of the Compliance Officer or Money Laundering Reporting Officer (MLRO).
  • Install the Google Authenticator application on the mobile number associated with the registered contact number for two-factor authentication.

How to Register on goAML UAE (Step-by-Step)

The goAML registration for UAE regulated entities is a two-step process comprising Services Access Control Manager (SACM) and Authenticator Registration and Entity Registration on goAML. The points below explain the process in simple steps:

Step 1: SACM and Authenticator Registration

The first step of registration involves getting the username and SECRET CODE for accessing the Google Authenticator app on the mobile.

A. Register on SACM

Access https://services.uaefiu.gov.ae/sacm/ and complete the form by filling in all the mandatory fields, marked with (*).

Registration for goAML web Access

Guide to fill in the details:

  • Registration Type should be Reporting Entity.
  • Entity Name should be the same as on the trade license
  • Mention the appropriate supervisory authority.
  • Under “ID Number/Reg. No.” mention the trade license number.
  • Enter the name of the Compliance Officer (CO) or MLRO under the “Individual Name” section.
  • Enter the nationality of the CO or the MLRO.
  • Enter the ID type and ID number of the selected document.
  • Enter the e-mail and mobile number of the CO/MLRO. The mobile number should be a UAE-registered number and entered in 009715xxxxxxxx format.
  • Add remarks, if any.
  • File to be attached as a PDF. A single file containing all mentioned documents.
  • Read and acknowledge the terms and conditions.
  • Submit the application to get a reference number.
  • Also, ensure you have whitelisted email IDs: no-reply.sacm@uaefiu.gov.ae and no-reply.goaml@uaefiu.gov.ae

B. Verify Email

On clicking submit, you’ll receive an email at your registered email ID, requesting you to verify the email ID. Once submitted, the supervisory authority reviews the request and informs you of approval or rejection. Upon approval, an email shall be sent to the registered email ID with the email OTP and link to generate the Secret Key. You can access the OTP on the registered mobile number as well. Enter the email ID, email OTP, and SMS OTP to get the Secret Key. The OTP is valid for 24 hours only.

If the request is rejected, review the reason, fulfil the requirement and resubmit the request.

 

C. Configure Google Authenticator

Install the Google Authenticator app on the mobile and set it up by entering the username and Secret Key. The app will generate a 6-digit verification code after activation, which you must enter every time you log in to goAML.

Step 2: Entity Registration on goAML

Use https://services.uaefiu.gov.ae/goaml/ and log in with the user ID provided in the SACM registration as the username, and enter the authenticator code (6-digit) as the Password.

SCAM sign-in

Upon logging in, it will direct you to the goAML Registration Page; select Register. Click on Reporting Entity to select it as the registration type.

Fill in the mandatory details, including the reporting entity, address & phone number of the entity, administrator details, address and phone number of the MLRO/CO, and upload the required documents. Click Preview and Submit.

The system will generate a reference code and send an email with it. Further, once the request is reviewed and approved, the entity will receive an email containing the unique Organisation ID, which is your entity’s unique goAML identity number.

SACM Registration Explained

SACM means Service Access Control Manager. It is the mandatory first step in the UAE goAML registration process. It acts as a secure gateway before accessing the main goAML reporting platform. It manages the multi-factor authentication setup and captures the necessary details such as trade license, compliance officer information and others.

 

Common SACM mistakes include incorrect entity or CO/MLRO details, an invalid email ID or mobile number, incorrect document uploads, and not completing the Google Authenticator setup, which delays the registration process.

 

Regulated entities receive a username and OTP by email and SMS during SACM registration. These credentials are necessary to log in for the first time, set up the account and activate Google Authenticator.

Common Reasons goAML Registration Gets Rejected

goAML registration may get rejected due to the following common reasons:

Why goAML Registration Applications Get Rejected

Wrong Supervisory Authority

Not knowing the right authority that supervises the business or selecting the wrong authority is a mistake. Ensure choosing the right authority that regulates the business.

Incorrect Organisation Type

Selecting the wrong organisation type can result in registration issues, as it must match the business activities.

Document Upload Issues

Uploading unclear, expired or inconsistent documents may result in rejected applications. Also, upload all documents in a single PDF file.

Incorrect Email

Using an incorrect or inaccessible email ID restricts the entity from receiving emails, login details and important registration updates.

Mobile Verification Failure

Entering the wrong mobile number or failing to complete the verification successfully makes it difficult to continue the process.

Multiple Registrations

Only one active goAML registration is required for a business. Creating multiple accounts or submitting multiple requests for the same entity may result in rejection.

How Long Does goAML Registration Take?

The duration for goAML registration depends on factors such as pre-registration timeline, approval timeline, delays and the resubmission process. The regulated entity should gather required documents, appoint a CO or MLRO and complete the SACM account setup to begin with goAML registration.

 

Further, the supervisory authority reviews the application, which takes time. If no issues are found, approval is generally within a few business days. Further, there can be delays due to missing or incorrect document uploads, or wrong information entered. Sometimes the registration may get rejected, requiring resubmission, which again requires time.

How to Login to goAML UAE?

After the registration on goAML is complete, regulated entities may log in through https://services.uaefiu.gov.ae/goaml/.

For the first login, enter the SACM username and the 6-digit code generated by the Google Authenticator app.

For the second login, enter the goAML username and password created during goAML registration.

goAML Registration Fees

Registration on the official UAE goAML system is free for regulated entities, involving no charges for all DNFBPs, VASPs, and Financial Institutions.

After Registration: What Happens Next?

goAML registration is just the first step to compliance. Regulated entities should also cover the following steps to meet AML/CFT compliance requirements:

  • Entities must identify suspicious transactions that appear unusual and file a Suspicious Transaction Report (STR) through the goAML platform without delay.
  • When noticing any suspicious behaviour or activity, entities must submit a Suspicious Activity Report (SAR) through the goAML portal.
  • Entities should maintain all records, including customer identification, transaction documents, due diligence records and copies of reports submitted through goAML, for a specific period as required by law.
  • Train employees on AML obligations, how to detect suspicious activities or transactions, which reports to file, when to file reports, and how to submit reports through the goAML portal.
  • Continue carrying out compliance procedures and keep goAML details updated. Ensure required reports are submitted without delay. Update changes to MLRO, contact details, and business details whenever required to avoid non-compliance penalties.

Common goAML Errors & Solutions

goAML Issues

How to Avoid Them

The 24-hour OTP expires before you enter it.

Ensure you complete the steps the same day you receive it. Or, request a new OTP and enter it as soon as you receive it.

Unable to upload files during registration.

Ensure you merge the files in a single PDF.

Organisation does not appear during registration.

Confirm selected the correct supervisory authority and entered the right business details.

The verification email is not received.

Make sure to white-list emails no-reply.sacm@uaefiu.gov.ae and no-reply.goaml@uaefiu.gov.ae

How We Help with goAML Registration?

We provide end-to-end support to help regulated entities meet AML/CFT obligations. Our support includes guiding entities throughout the goAML registration process, from preparing necessary documents to submitting the application and resolving registration issues. Further, we help entities appoint a qualified MLRO or Compliance Officer to meet regulatory requirements.

 

Our team helps DNFBPs, VASPs, and FIs prepare customised AML/CFT policies and procedures that align with business operations and UAE compliance requirements. We also conduct enterprise-wide risk assessments to identify business exposure to ML/TF risks and develop mitigation strategies.

 

Additionally, we guide on detecting suspicious activities and transactions and preparing SAR/STR reports to be submitted through the goAML portal.

Frequently Asked Questions

Picture of Sridhar Rajam
Sridhar Rajam

Sridhar is a Certified Anti-Money Laundering Investigator (CAMI) with over 30 years of experience in compliance, risk, and audit, including more than 20 years in AML and financial crime prevention. He has contributed to the development of UAE regulatory standards through the FERG sub-committee and has maintained active engagement with the Central Bank of the UAE on supervisory and compliance matters.