What We Cover
We first determine which requirements apply specifically to your company. We review its license, actual activities, jurisdiction, supervisory authority, and role in the AML/CFT/CPF framework. We separately assess the regimes applicable to financial institutions, DNFBPs, VASPs, and other regulated categories. The company receives a precise scope of obligations rather than a generic “just in case” checklist.
We create a compliance map covering responsible persons, required registrations, risk assessment, policies, CDD/KYC/KYB, sanctions controls, monitoring, reporting, training, record retention, and internal controls. We consider not only federal regulation but also the requirements of the relevant regulator or free zone and applicable industry guidance and circulars.
Following the assessment, we provide a management plan with priorities, documents, deadlines, and accountable persons. We work directly with the client and applicable official systems without an unnecessary chain of intermediaries. Where a requirement does not apply, we document the basis; where it does, we translate it into a specific implementation plan.
We conduct a risk-based assessment of activities, customers, countries, products, and transactions. We assess sales channels, payment methods, ownership structure, counterparties, geography, sanctions exposure, and proliferation financing risks. We distinguish inherent risk from the effectiveness of existing controls and determine the residual risk the company actually accepts after mitigation.
We build a clear assessment model with factors, weightings, risk levels, and documented reasoning. We establish customer risk ratings for individuals and entities, high-risk criteria, EDD triggers, approval procedures, and review frequency. The outcome must allow the reasoning for each customer decision to be reconstructed rather than depend on one employee’s memory.
We convert the risk assessment into workable onboarding, ongoing monitoring, escalation, and management reporting rules. We update the model when activities, products, geographies, customer composition, or regulatory requirements change. Management sees a risk map and the actions used to manage those risks, not a formal report with no operational value.
We develop and update AML/CFT/CPF policies for the company’s actual activities. We incorporate governance, allocation of authority, CDD, EDD and applicable SDD, UBO identification, source of funds and source of wealth, ongoing monitoring, TFS, suspicious activity escalation, record keeping, training, and quality control. The policy reflects the real business process rather than another company’s template with the name replaced.
At the same time, we create a practical toolkit: questionnaires, risk-scoring tools, checklists, approval forms, screening logs, case notes, escalation records, registers, and management reports. For each action, we define the initiator, reviewer, approver, evidence, and storage location. Compliance becomes a sequence of controlled decisions rather than a collection of documents.
We arrange management approval, implementation, version control, and periodic review. We align the policies with corporate documents, onboarding, accounting, payments, and the company’s banking profile. When changes occur, we update the entire connected framework and promptly communicate the new rules to employees.
We take control of onboarding before the relationship with a customer or counterparty begins. We identify and verify the individual or entity, representatives, beneficial owners, and controlling persons; establish the purpose and nature of the relationship, ownership structure, expected activity, and applicable sources of funds or wealth. Discrepancies are resolved before they become unexplained risk.
We assign a risk profile and determine the scope of due diligence. For higher-risk cases, we conduct EDD covering the ownership structure, business purpose, geography, transactions, adverse media, PEP and sanctions exposure, and supporting corporate and financial documents. The decision is based on a body of verifiable information, and its rationale is documented in the customer file.
After onboarding, we conduct periodic and event-driven reviews. We update documents when an owner, director, activity, country, payment behavior, or other material circumstance changes and compare the profile with actual transactions. The company receives an up-to-date KYC/KYB register, a controlled request queue, and an evidentiary history for each decision.
We establish sanctions and PEP screening before onboarding, throughout the relationship, and whenever applicable lists are updated. We screen customers, prospects, UBOs, directors, representatives, related persons, and transaction participants against the UAE Local Terrorist List, UN Consolidated List, and other lists applicable to the geography, banks, and structure of the specific business.
We do not rely solely on a search result. We analyze matches using identifiers, distinguish false positives from potential or confirmed matches, assess ownership and control, document the conclusion, and initiate the correct escalation route. For PEPs, family members, and close associates, we determine the risk level, required approvals, EDD, and enhanced monitoring.
Where there is an applicable match, we arrange the required actions, internal escalation, and appropriate report through goAML or another designated channel. We retain screening evidence, timestamps, decisions, and filing confirmations. Management can see the status of each case, and the company can demonstrate not only that screening occurred but also the quality of the decision.
We design role-based training rather than delivering the same presentation to the entire company. Management receives the control framework and key decision points; sales and onboarding teams learn red flags and stop procedures; finance learns indicators of unusual payments; and the compliance team covers CDD/EDD, monitoring, investigations, reporting, and confidentiality. We test understanding and document the results.
Within the agreed scope, we provide an operationally managed outsourced compliance function for DNFBPs. We maintain the calendar and registers, review customer files, conduct risk assessments and screening, manage internal escalations and management reporting, update policies, and prepare for engagement with the supervisory authority. Management retains full visibility and approves decisions, while day-to-day work always has a responsible owner.
If the company needs an internal function, we build it: defining the roles of Compliance Officer and MLRO, authority, deputies, reporting lines, data access, KPIs, and independent oversight. We prepare the team for inspections and remediation, assemble requested documents, and close identified gaps under one plan.
We register the relevant company and authorized user in goAML, configure access, and verify filing readiness. We work directly with the official portal without intermediaries. Within the company, we create a confidential workflow: red flag identification, initial analysis, escalation to the Compliance Officer or MLRO, documentation of the decision, and retention of evidence.
We prepare materials for STRs, SARs, and other applicable reports, select the correct form, develop a clear factual narrative, and assemble attachments. We support the authorized person during filing and monitor subsequent communications in goAML. We separately establish a process for FIU requests and submission of additional information regarding previously filed materials.
We keep registration, authority, and contact details current and maintain a log of internal decisions and submitted reports. Access, content, and the fact of reporting are protected under an established confidentiality process. As a result, goAML operates as part of the overall compliance function rather than a standalone registration revisited only after a request.
We determine the company’s status and obligations under CRS and FATCA where these regimes apply. We determine whether the structure is a Reporting Financial Institution or falls within another category and review registration, GIIN and sponsoring arrangements, onboarding forms, self-certifications, tax residence, controlling persons, due diligence, and reportable data.
We establish an operational CRS/FATCA framework: collection and verification of self-certifications, classification of accounts and holders, monitoring of changes in circumstances, data review, and preparation of annual reporting. We connect it with KYC/KYB and corporate data without conflating tax transparency with AML. All actions are included in one compliance calendar with accountable persons and evidence of completion.
We will combine the right services and create one clear workflow.
Describe Your Project ↗