Key Takeaways
4 insights · 11 min readUAE AML law requires every DNFBP — including RAK ICC registered agents — to appoint a compliance officer whose tasks are set by Article 21 of Cabinet Decision No. 10 of 2019.
The officer has five statutory tasks: detect crime-linked transactions; report suspicious transactions to the FIU; maintain AML rules and file semi-annual reports; run ongoing training; and cooperate with the authorities.
A RAK ICC agent must file a signed Declaration and Confirmation to the Registrar attesting its appointed compliance officer complies with Article 21.
Reports to senior management (copied to the Supervisory Authority) are semi-annual; suspicious transactions go to the FIU without delay; AML records are kept for at least 5 years.
An AML compliance officer is the person a UAE financial institution or DNFBP must appoint to run its anti-money-laundering programme. Under Article 21 of Cabinet Decision No. 10 of 2019, the officer must detect crime-linked transactions, report suspicious ones to the FIU, maintain AML rules and file semi-annual reports, train staff, and cooperate with the Supervisory Authority and FIU.
In this guide
What a compliance officer is Why a RAK ICC agent needs one The five Article 21 tasks Detecting and reporting AML rules and semi-annual reports Training staff Cooperating with authorities The Registrar declaration Penalties for failure Can you outsource it How to set it upIf you run a RAK ICC registered agent, a corporate service provider or any other designated business, appointing an AML compliance officer is not optional — it is a legal requirement. The role, and the exact duties that come with it, are defined by Article 21 of Cabinet Decision No. 10 of 2019, the implementing regulation of Federal Decree-Law No. 20 of 2018 on Anti-Money Laundering and Combating the Financing of Terrorism. This guide sets out the five statutory AML compliance officer duties in full, explains the Declaration and Confirmation a RAK ICC agent files with the Registrar, and shows how our AML compliance team builds a function that stands up to a Ministry of Economy inspection.
What is an AML compliance officer under UAE law?
An AML compliance officer (sometimes called the AMLCO or, where the reporting role is emphasised, the MLRO) is the individual a regulated business appoints to own its anti-money-laundering and counter-terrorist-financing programme. The requirement flows from Federal Decree-Law No. 20 of 2018 and is given detail by Cabinet Decision No. 10 of 2019. Article 20 of that Decision deals with the appointment; Article 21 sets out the tasks the officer must actually perform.
The officer is expected to be independent, sufficiently senior, and resourced to do the job properly. In practice they sit at the centre of the firm's controls: they decide whether a transaction is suspicious, whether to file a report, how policies are kept current, and how staff are trained. Because the role carries real legal weight, the UAE framework treats a weak or absentee compliance officer as a compliance failure in its own right — not a mere internal HR matter.
| Term | What it means |
|---|---|
| Compliance Officer / AMLCO | The designated officer responsible for the firm's AML/CFT programme under Article 21 |
| MLRO | Money Laundering Reporting Officer — the reporting role, often the same person |
| FIU | The UAE Financial Intelligence Unit, which receives suspicious transaction reports |
| goAML | The FIU's online portal for registration and report filing |
| STR / SAR | Suspicious Transaction / Activity Report submitted to the FIU |
| DNFBP | Designated Non-Financial Business or Profession — e.g. registered agents, auditors, real estate, precious-metal dealers |
| Supervisory Authority | The sector regulator (the Ministry of Economy for many DNFBPs) |
| CDD | Customer Due Diligence — verifying client and beneficial-owner identity and risk |
Why does a RAK ICC registered agent need a compliance officer?
RAK ICC registered agents form and administer companies, which places them squarely within the population of DNFBPs that the UAE AML framework regulates. Corporate service providers, auditors, real estate brokers, dealers in precious metals and stones, and certain legal professionals all fall in the same bracket. Every one of them must appoint a compliance officer and operate an AML/CFT programme — the same discipline that underpins compliant UAE company incorporation.
RAK ICC reinforces this with a specific document: a Declaration and Confirmation addressed to the Registrar, in which the registered agent confirms that its appointed compliance officer complies with the tasks in Section 8 Article 21 of Cabinet Decision No. 10 of 2019. In other words, RAK ICC does not just assume agents are compliant — it asks them to put it in writing, signed by an authorised signatory. That makes the five Article 21 tasks the exact benchmark every agent is measured against.
⚠️ A named officer on paper is not enough
Appointing a compliance officer in name only — with no goAML registration, no policies and no training — leaves a registered agent exposed. Supervisors assess whether the five Article 21 tasks are actually being performed, not just whether a name is on file. Build the function properly — speak to our AML team →
What are the five key tasks of the compliance officer (Article 21)?
Article 21 of Cabinet Decision No. 10 of 2019 lists five key tasks. These are the duties a RAK ICC registered agent confirms its compliance officer performs, and the checklist any Supervisory Authority will test against. The table summarises each task and how often it applies.
| # | Article 21 task | Frequency / trigger |
|---|---|---|
| 1 | Detect transactions relating to any crime | Ongoing / real time |
| 2 | Review suspicious transactions and decide to notify the FIU or retain (with reasons), keeping confidentiality | Report to FIU without delay |
| 3 | Review internal AML rules, assess compliance, propose updates and report to senior management and the Supervisory Authority | Semi-annual reports |
| 4 | Prepare, execute and document ongoing AML/CFT training for employees | Continuous programme |
| 5 | Cooperate with the Supervisory Authority and FIU and provide requested data and records | On request / ongoing |
The rest of this guide takes each task in turn, because the difference between a compliant agent and a penalised one is almost always in the detail of how these five duties are actually carried out.
Need a compliance officer function built from scratch?
We set up goAML, AML policies, CDD, training and semi-annual reporting for RAK ICC agents and DNFBPs.
Tasks 1 and 2: detecting and reporting suspicious transactions
The first two tasks are the heart of the role. Task 1 requires the officer to detect transactions relating to any crime — which in practice means monitoring client activity for red flags. Task 2 goes further: the officer must review, scrutinise and study records, receive data on suspicious transactions, and then decide either to notify the UAE Financial Intelligence Unit (FIU) or to retain the transaction with documented reasons — all while maintaining complete confidentiality.
Two points matter for compliance. First, suspicious transaction reports (STRs) are filed to the FIU through its goAML portal, so the business must be goAML-registered before any suspicion arises — not after. Second, confidentiality is a legal duty: a compliance officer must not "tip off" a client that a report has been, or may be, made. Getting either wrong — a missed report, or an unlawful disclosure — is exactly the kind of failing that draws enforcement.
Expert Tip
Document the decisions you don't report, not just the ones you do. Task 2 explicitly allows the officer to retain a transaction "with the reasons for maintaining". A clear, dated rationale for why a flagged transaction was not escalated is often the single most useful record in an inspection.
Task 3: reviewing AML rules and semi-annual reporting
Task 3 is about keeping the programme alive. The compliance officer must review the internal rules and procedures for combating money laundering and terrorist financing, check that they remain consistent with the Decree-Law and the Decision, assess how well the firm actually applies them, and propose updates where needed. Crucially, the officer must then prepare and submit semi-annual reports on these points to senior management — and send a copy to the relevant Supervisory Authority, enclosed with senior management's remarks and decisions.
This creates a fixed governance rhythm: every six months, the AML programme is reviewed, reported up to leadership, and shared with the regulator. For a RAK ICC registered agent, that semi-annual report is also the evidence trail that backs up the Declaration and Confirmation filed with the Registrar. Skipping it does not just weaken controls — it undermines the very statement the agent has signed.
Task 4: ongoing AML training for employees
Task 4 requires the compliance officer to prepare, execute and document ongoing training and development programmes for the firm's employees on money laundering, terrorist financing, the financing of illegal organisations, and the means to combat them. The emphasis on "ongoing" and "document" is deliberate: a single induction session is not enough, and training that cannot be evidenced counts for little in a review.
Effective programmes are role-specific — front-office staff who onboard clients need CDD and red-flag training, while senior managers need to understand their reporting and governance obligations. Keeping an attendance and content record for each session turns training from a box-tick into defensible evidence that the firm takes its obligations seriously. It is the same standard we apply across our company formation and compliance engagements.
Task 5: cooperating with the Supervisory Authority and FIU
The final task is cooperation. The compliance officer must collaborate with the Supervisory Authority and the FIU, provide them with all requested data, and allow their authorised employees to view the records and documents needed to perform their duties. In practice, this means keeping records organised and retrievable so that a request for information can be answered promptly and completely.
For DNFBPs, the Supervisory Authority is typically the Ministry of Economy, which conducts risk-based inspections. An agent that can produce its CDD files, STR decisions, semi-annual reports and training logs on request demonstrates a functioning programme. One that cannot — even if it technically "has" a compliance officer — signals a control gap. Retaining AML records for at least five years is the baseline expectation that makes this cooperation possible.
How does a registered agent confirm compliance to the RAK ICC Registrar?
RAK ICC operationalises all of this through a short Declaration and Confirmation letter to the Registrar. In it, the registered agent confirms and declares that its appointed compliance officer is compliant and adheres to the Compliance Officer Tasks as stated in Section 8 Article 21 of Cabinet Decision No. 10 of 2019. The letter names the registered agent, names the compliance officer, quotes the five key tasks, and is signed by an authorised signatory.
The document is deceptively simple, but it is a formal attestation. By signing it, the agent is representing to the Registrar that the five Article 21 tasks are genuinely being performed — not merely that a compliance officer exists. That is why the declaration should only be signed once the underlying function is real: goAML registration in place, policies written, training delivered, and the semi-annual reporting cycle running.
| Obligation | Basis | Deadline / consequence |
|---|---|---|
| Appoint a competent compliance officer | CD 10/2019 (Art. 20–21) | Before onboarding clients |
| File Declaration & Confirmation to RAK ICC Registrar | RAK ICC requirement | On appointment / as required |
| Report suspicious transactions (goAML) | Article 21(2) | Without delay on suspicion |
| Semi-annual AML report to senior management + Supervisory Authority | Article 21(3) | Every 6 months |
| Ongoing, documented staff training | Article 21(4) | Continuous |
| Retain AML records (CDD, STRs, training) | Decree-Law / Decision | At least 5 years |
What happens if the compliance officer function fails?
UAE AML/CFT obligations are enforced. Administrative penalties for failings — a missing or non-compliant compliance officer, unreported suspicious transactions, inadequate policies or poor record-keeping — are imposed under Federal Decree-Law No. 20 of 2018 and its implementing decisions, and they can be significant [VERIFY current AED range]. For a RAK ICC registered agent, enforcement can also mean regulatory action affecting the agent's ability to operate.
The economics strongly favour getting it right. Setting up a compliant function is a modest, predictable cost; a penalty, remediation exercise and reputational hit are neither.
Worked example — the cost of a paper-only officer
• Scenario — A RAK ICC agent lists a compliance officer on file but has no goAML account, no documented training and no semi-annual reports.
• Trigger — A Ministry of Economy inspection requests STR decisions, training logs and the last two semi-annual reports. None exist.
• Exposure — The agent faces administrative penalties [VERIFY exact fine bracket] plus a remediation deadline, and must rebuild the function under supervision.
• Prevention — An outsourced compliance officer and goAML package from AED 349 would have kept the evidence trail ready before the inspection ever landed.
Who can be a compliance officer, and can you outsource it?
A compliance officer must be competent, independent and senior enough to challenge the business and make reporting decisions without pressure. For larger firms this is an in-house appointment. For many smaller RAK ICC agents and DNFBPs, however, it is more practical to outsource the function to a specialist consultancy that provides the officer, the systems and the reporting as a managed service.
Whichever route you choose, the Article 21 tasks do not change — the standard is the same for in-house and outsourced arrangements. The comparison below shows what a compliant function looks like versus the common shortfalls that attract penalties.
A compliant function
- ✓ Independent, competent officer with real authority
- ✓ goAML registered; STR workflow in place
- ✓ AML policies, CDD and risk assessment documented
- ✓ Ongoing, documented staff training
- ✓ Semi-annual reports filed; 5-year records kept
Common shortfalls
- ✗ Officer named on paper only
- ✗ No goAML account until suspicion arises
- ✗ Generic policies never applied to real clients
- ✗ Training undocumented or one-off
- ✗ No semi-annual reports; records incomplete
How to set up a compliant AML function
Meeting the Article 21 obligations is a repeatable, five-step process. Follow it and the Registrar declaration becomes an accurate statement rather than an aspiration.
- Appoint a qualified compliance officer — independent, senior and resourced, whether in-house or outsourced.
- Register on goAML — set up the FIU account and a workflow for filing suspicious transaction reports.
- Implement AML policies and CDD — write and apply policies, customer due diligence and a risk assessment aligned to Cabinet Decision No. 10 of 2019.
- Train staff and schedule reporting — deliver and document ongoing training, and run the semi-annual reporting cycle to senior management and the Supervisory Authority.
- File the Registrar declaration and retain records — submit the Declaration and Confirmation to RAK ICC and keep AML records for at least five years.
This is the exact workflow our team delivers as a managed AML compliance service, so your controls, evidence and Registrar declaration all line up.
Fastlane Tax Team
FTA-registered tax agents and MoE-approved auditors who set up and run AML/CFT compliance-officer functions for RAK ICC registered agents, corporate service providers and DNFBPs across the UAE. Every guide is reviewed against current UAE regulations before publishing.
Ask the team a question