UAE reporting entities should treat goAML as a controlled reporting workflow, not a website login. Under Federal Decree-Law No. 10 of 2025, financial institutions and designated non-financial businesses and professions (DNFBPs) must report suspicious funds or transactions to the UAE Financial Intelligence Unit (FIU) directly and without delay when reasonable grounds for suspicion exist.
A sound process has three parts. Register the right entity and users under the right supervisor, build an internal escalation path that reaches the money laundering reporting officer (MLRO), then submit a complete suspicious transaction report (STR) without warning the customer. The UAE FIU receives the report. The reporting entity's authorised human remains responsible for the filing decision, accuracy and follow-up.
Connect portal access, case evidence, human authority and the post-filing record.
UAE reporting entities should register under the correct supervisor, investigate the available evidence, let the MLRO decide whether the reporting threshold is met and submit through a named authorised user.
A practical goAML operating model has four connected stages.
This is an editorial operating model. It is not legal advice and it does not replace the UAE FIU's portal instructions, your supervisor's directions or counsel's interpretation of the current law.
Federal Decree-Law No. 10 of 2025 is the current federal law on anti-money laundering, counter-terrorist financing and proliferation financing. It took effect on October 14, 2025 and replaced the earlier Federal Decree-Law No. 20 of 2018.
Cabinet Resolution No. 134 of 2025 is the current executive regulation. It took effect on December 14, 2025 and replaced Cabinet Decision No. 10 of 2019.
That matters because some operational pages still cite the previous 2018 and 2019 instruments. The Ministry of Economy and Tourism's goAML page was updated on October 3, 2026, but its alert text still names the old framework. Use the page for current registration mechanics and DNFBP scope cues, then confirm legal duties against the 2025 law, the 2025 executive regulation and your supervisor's current directions.
The law sets the reporting trigger. When a financial institution or DNFBP has reasonable grounds to suspect that funds are criminal proceeds, linked to a crime or intended for a crime, it must report directly and without delay to the FIU and provide the available transaction and party information.
The executive regulation requires financial institutions and DNFBPs to appoint a competent compliance officer with enough authority and independence to perform the role. Your governance should make clear who receives internal alerts, who investigates, who can submit, who acts as backup and who answers FIU follow-up.
No. Registration follows the entity's regulated status and supervisory route. The UAE FIU's SACM launch page says supervisory bodies and reporting entities under those bodies use the registration process to secure goAML access for STR and suspicious activity report submissions.
The current SACM form asks the applicant to choose either Reporting Entity or Supervisory Body. It also asks the reporting entity to select its supervisor. The listed choices include the Central Bank of the UAE, Dubai Financial Services Authority, Abu Dhabi Global Market, Securities and Commodities Authority, Ministry of Economy and Tourism, Ministry of Justice and the Virtual Assets Regulatory Authority.
For DNFBPs under the Ministry of Economy and Tourism, the Ministry page identifies four main categories covered by its registration guidance: real estate businesses, auditors and accountants, dealers in precious metals and stones, and trust or company service providers.
Do not copy another firm's registration route. A bank, an ADGM firm, a mainland real estate broker and a law firm may reach goAML through different supervisory relationships. Start with the licence and supervisor, not the trade name.
Build a one-page registration record before anyone opens the form. Record the entity's exact licensed name, licence or registration number, legal form, regulated activity, supervisor and the reason the entity is a reporting entity.
Then resolve these questions.
A duplicate or misrouted application can slow access and create a weak audit trail. Keep the supervisor's answer with the registration file.
The registered user should be authorised to act for the entity. The SACM terms require the person completing pre-registration to confirm that they are authorised and that the submitted identity information is correct.
The practical owner is usually the MLRO or another compliance officer operating under the entity's approved authority matrix. Name a backup as well. Absence, leave or staff turnover should not stop a required report.
Set out four separate permissions.
| Permission | What the user can do | Control boundary |
|---|---|---|
| Prepare | Build the case, populate fields and attach evidence. | Cannot submit unless separately authorised. |
| Review | Test the legal trigger, facts and narrative. | Cannot change evidence without a recorded reason. |
| Submit | Send the approved report through goAML. | Must use a named account and approved authority. |
| Administer | Add or remove users and maintain access. | Should not inherit filing authority by default. |
Avoid shared credentials. The SACM terms make each entity responsible for activity under its user accounts and for maintaining password confidentiality.
The Ministry's current DNFBP page lists an authorisation letter, passport, residence visa, Emirates ID and the commercial trade licence among the documents needed for registration. It also directs applicants to install an authenticator application used for the SACM access code.
The current SACM form asks for the entity name, supervisor, registration number, registering person's identity, nationality, ID type and number, email, mobile number, remarks and a PDF attachment.
Prepare clean, legible files with consistent names. Check that the entity name is identical across the licence, authorisation letter and form. Confirm that the email is controlled by the institution, the mobile number is usable for the authorised person and the attachment contains no unrelated personal information.
A registration checklist should include:
The UAE FIU's launch page uses SACM, the Services Access Control Manager, as the access gate for the goAML launch portal. The Ministry's DNFBP instructions describe the first operational step as registering in SACM and obtaining a username.
On the live form, select Reporting Entity, enter the exact entity details, choose the supervisor and complete the authorised user's identity fields. Upload the requested PDF. Read the portal terms before accepting them.
The form also tells applicants to allow messages from the FIU's no-reply SACM and goAML addresses. Add those addresses to the institution's email controls before submission. A registration process can appear stalled when approval or activation mail is trapped by the spam gateway.
Save the submitted data, attachment hash, submission time and confirmation. Do not store credentials in the case file.
Once SACM access is approved, activate the secure login according to the current portal instructions. The Ministry page says the access sequence uses an authenticator-generated password after SACM registration.
The organisation profile in goAML should match the licensed entity. Add the MLRO and other users only within the approved role design. Confirm who can prepare, review, submit and manage users.
Run these checks before treating registration as complete.
The internal process should turn an alert into an evidence-based human decision. It should not create an extra approval chain that delays a report after the legal trigger is met.
A useful sequence is:
The system can collect evidence and draft the report. It should not turn a risk score into an automatic legal conclusion.
Key Insight: A goAML filing is defensible only when portal access, case evidence, MLRO authority, authorised submission and the post-filing record remain connected. Automation can prepare the case, but the MLRO retains the filing decision.The legal duty calls for a detailed report with available data about the transaction and parties. The exact fields depend on the report type and current goAML form, but the underlying case should normally contain:
Do not dump every available document into the report. Include what supports the suspicion and keep the full case record available for follow-up.
A useful STR narrative lets an FIU analyst understand the subject, conduct, timeline, money flow and reason for suspicion without reverse engineering the case.
Use a clear order.
Use facts rather than labels. "High risk" is not an explanation. State which transactions occurred, how they connected and why the known information did not explain them.
Separate observation from inference. For example, a newly opened company received transfers from several unrelated senders, then sent most of the funds to one overseas beneficiary within hours. That is an observation. The inference may be that the account is acting as a pass-through. Record both, and say what evidence supports the inference.
Do not alert the customer or another unauthorised person that an STR has been or may be filed. Federal Decree-Law No. 10 of 2025 prohibits direct or indirect disclosure that a report was submitted, an investigation is underway or information has been or will be provided to the FIU.
The SACM terms also require confidentiality around reports and information transmitted through the service.
Build the control into daily work.
The same rule applies to automation. A customer-facing message must never reveal that an internal review or FIU report caused an action.
The authorised user should select the current FIU report type, complete all mandatory fields, check the parties and transactions, attach the permitted evidence and submit through goAML. The UAE FIU portal is designed for reporting entities to register and file STRs or suspicious activity reports.
Before the final click, compare the report with the approved case record.
After submission, save the receipt or reference number, date, time, report type, submitter and exact filed version. Monitor the portal and institutional mailbox for requests or status messages. A successful upload is not the end of the reporting process.
Illustrative scenario, not a customer result.
A UAE trading company receives transfers from unrelated overseas individuals and moves most of the funds to one overseas beneficiary within hours.
Illustrative example, not a customer result. A UAE trading company opens an account for domestic wholesale activity. During the next month, it receives transfers from several unrelated overseas individuals. Most incoming funds leave within hours to one company in another jurisdiction. The payment descriptions do not match the invoices provided, and the customer gives different explanations to relationship management and compliance.
The monitoring system creates an alert. An investigator gathers account history, onboarding records, beneficial-owner information, counterparties, transfer details and the customer's explanations. The case shows the observed flows separately from the investigator's inference.
An AI agent may organise the transactions, identify linked parties, draft a chronology and prepare a proposed narrative. The MLRO reviews the evidence and decides whether reasonable grounds for suspicion exist. If the MLRO approves the filing, the authorised user submits through goAML. The system records the final text, receipt and later FIU requests. No agent makes or files the regulated decision independently.
| Component | Responsibility | Boundary |
|---|---|---|
| Monitoring and referrals | Identify activity that needs investigation. | An alert is not an STR decision. |
| Case workspace | Join customer, transaction, ownership and review evidence. | The workspace cannot decide legal suspicion. |
| Investigation support | Build chronology, links and unresolved questions. | Recommendations remain reviewable. |
| MLRO or delegate | Decide whether the reporting threshold is met. | The decision must follow the authority matrix. |
| goAML preparer | Populate the approved report accurately. | Cannot change the MLRO's rationale without review. |
| Authorised submitter | Submit and preserve the official receipt. | Must not use shared credentials. |
| Access administrator | Maintain users and roles. | Access management is separate from filing authority. |
Human control should be explicit. The MLRO can approve, reject or return a draft. Authorised staff can override an automated suggestion. The institution can pause the workflow or use a kill switch if an agent behaves outside its configured scope.
FluxForce's relevant solution is Regulatory Reporting (STR / SAR / CTR). The product fit is an AI-agent workflow that investigates the underlying alert, gathers the available evidence, prepares a filing-ready case and drafts reporting content for human review.
The company-level position is: AI agents that investigate AML, sanctions, fraud and KYC alerts and prepare the case. Your analyst makes the call, with evidence an examiner can replay. You decide how much each agent does on its own, and every one has a kill switch.
For goAML, Zara Trustwell can support the regulatory workflow and Arin Narrate can support the evidence trail. The customer configures what each agent may collect or draft and where it must stop for approval. The MLRO decides whether to file. An authorised human submits the report.
FluxForce does not provide legal advice, decide that suspicion exists, guarantee acceptance by the FIU or replace goAML. It must fit the institution's data, supervisor, policies, authority matrix and portal controls. The goAML template glossary, UAE jurisdiction guide and SAR filing deadline calculator are useful review points.
| Metric | Definition | Guardrail |
|---|---|---|
| Registration completion time | Time from approved application pack to working access. | Separate supervisor delay from internal delay. |
| Access exceptions | Failed logins, orphaned users and excess permissions. | Do not trade access security for speed. |
| Alert-to-MLRO time | Time from internal escalation to a decision-ready case. | Fast routing cannot replace investigation. |
| Narrative rework rate | Reports returned internally for factual or structural correction. | A low rate matters only if review is real. |
| Filing data accuracy | Share of checked fields matching the case evidence. | Filled fields are not proof of correct fields. |
| Post-filing response time | Time to answer a valid FIU request. | Restrict responses to authorised channels. |
| Evidence completeness | Required case items present at closure. | Measure usefulness, not document count. |
| Human overrides | Agent drafts changed, rejected or stopped by authorised users. | Review the reasons instead of treating every override as failure. |
Monitoring, investigation support and goAML preparation support the filing. They do not replace the MLRO or authorised submitter.
| Component | Responsibility | Boundary |
|---|---|---|
| Monitoring and referrals | Identify activity that needs investigation. | An alert is not an STR decision. |
| Case workspace | Join customer, transaction, ownership and review evidence. | The workspace cannot decide legal suspicion. |
| MLRO or delegate | Decide whether the reporting threshold is met. | The decision follows the approved authority matrix. |
| Authorised submitter | Submit and preserve the official receipt. | Shared credentials are prohibited. |
| Access administrator | Maintain users and roles. | Access administration does not grant filing authority. |
The MLRO can approve, reject or return a draft. Authorised staff can override an agent suggestion, pause the workflow or use the kill switch.
Current federal reporting trigger, direct reporting and confidentiality boundary.
Federal law; entity-specific applicability requires UAE legal review.
2026-10-04
Current executive regulation and compliance-officer governance.
Federal executive regulation; supervisor-specific requirements may add detail.
2026-10-04
Current secure launch and registration route for reporting entities.
Operational portal guidance, not legal interpretation.
2026-10-04
DNFBP categories, documents and registration sequence.
Operational guidance; older legal citations require current-law caution.
2026-10-04
| Metric | Definition | Decision guardrail |
|---|---|---|
| Registration completion time | Time from approved application pack to working access. | Separate supervisor delay from internal delay. |
| Alert-to-MLRO time | Time from escalation to a decision-ready case. | Fast routing cannot replace investigation. |
| Filing data accuracy | Share of checked fields matching case evidence. | Filled fields are not proof of correct fields. |
| Evidence completeness | Required case items present at closure. | Measure usefulness, not document count. |
Pick a recent internal investigation and replay it from alert to filing decision. Check whether the entity can identify who knew what, when they knew it, why the MLRO decided and which version was filed. Fix the breaks before the next urgent case arrives.
goAML is the system used by the UAE FIU for reporting entities to register and submit STRs and suspicious activity reports. Access begins through the FIU's SACM launch portal.
Financial institutions and DNFBPs that are reporting entities should follow the route set by their supervisor. The live SACM form includes several UAE supervisors, so the correct choice depends on the entity's licence and regulated activity.
The Ministry's DNFBP page lists an authorisation letter, the applicant's passport, residence visa and Emirates ID, plus the company's trade licence. Other supervisors may require different or extra evidence, so confirm the current pack before submission.
A financial institution or DNFBP must report directly and without delay when it has reasonable grounds to suspect that funds are proceeds, linked to crime or intended for criminal use. The MLRO should apply that legal test to the available facts.
No. The federal law prohibits direct or indirect disclosure that a report was submitted, an investigation is underway or information has been or will be given to the FIU.
No. An AI agent can collect evidence, build a chronology and draft reporting content within customer-configured limits. The MLRO decides whether to file, and an authorised person submits through goAML.
Save the receipt or reference, submission time, report type, submitter, exact filed version, supporting case evidence and later FIU correspondence. Keep access restricted and preserve the decision trail.
Sahil Kataria is the Founder and CEO of FluxForce. His FluxForce author profile is the controlled source for public attribution. Final author and biography approval remain pending for this draft.