The point of all the identification, monitoring, and record-keeping in an anti-money-laundering programme is to reach a moment of action: recognising something suspicious and reporting it. In the UAE, suspicious transactions and activity are reported to the Financial Intelligence Unit through the goAML system, and the obligation to report is not discretionary. A business that spots something concerning and stays silent has failed at the one task the whole framework is designed to enable. Here is how reporting works and what triggers it.
What has to be reported
The obligation is to report suspicious transactions or activity: dealings that give reasonable grounds to suspect they involve the proceeds of crime, or terrorist financing, or that make no economic sense in the customer's context. It is not limited to completed transactions; a suspicious attempt or approach can also be reportable. Crucially, the standard is suspicion, not proof. You are not required to be certain, or to investigate like a prosecutor; you are required to report when the circumstances reasonably raise suspicion.
Signs that should prompt a closer look
Suspicion usually builds from indicators rather than a single obvious signal.
| Indicator | Why it draws attention |
|---|---|
| Transactions with no clear purpose | Activity that does not fit the customer |
| Reluctance to provide information | Avoiding normal due diligence |
| Unusual sources or structuring of funds | Possible attempt to disguise origin |
| Links to high-risk parties or places | Elevated inherent risk |
| Activity inconsistent with the profile | Behaviour that does not match the picture |
Report through goAML, and do not tip off
Reports are made through the goAML portal to the Financial Intelligence Unit, which is why in-scope businesses must register on it before the need to report ever arises. Two rules matter alongside the duty to report. First, timeliness: a suspicious matter should be reported promptly, not sat on. Second, and just as important, you must not tip off the customer that a report has been made or is being considered, because doing so can defeat the investigation and is itself an offence. Reporting is a confidential act.
The standard is suspicion, not proof, and the report goes to the FIU through goAML. You must act promptly and you must not tip off the customer. Silence when you had grounds to report is the failure the whole framework exists to prevent.
Build the decision into a process
Because the judgement can be difficult, in-scope businesses route suspicions through their compliance officer, who assesses whether the threshold is met and makes the report. Staff should know how to escalate a concern internally, and the compliance officer should decide and document. This turns a hard, high-stakes judgement into a defined process rather than leaving individual employees to freeze or guess. A clear internal path is what ensures suspicions actually reach the point of decision.
What to do about it
Register on goAML if you are in scope, before you need it. Train staff to recognise and escalate the indicators of suspicion, and route decisions through your compliance officer. Report promptly when the threshold of suspicion is met, remembering that suspicion, not proof, is the standard, and never tip off the customer. The entire AML apparatus exists to produce good reports at the right moments, and a business that has built a clear path to that decision is one that can actually meet its central obligation.
This article is general information and is not legal advice. Reporting obligations and thresholds are set by law. We would be glad to help you set up reporting and train your team.
