UAE AML/CFT rules expect regulated firms and DNFBPs to have their frameworks independently tested. We carry out independent AML/CFT and CPF audits and targeted health checks that show you exactly where you stand, before the regulator does.
Our methodology combines file reviews, data testing and stakeholder interviews to give you a clear, heat-mapped view of your exposure and a prioritised remediation roadmap you can take to your regulator.
A full, independent assessment of your AML/CFT and CPF framework against your regulator’s requirements, covering governance, risk assessment, CDD, screening, monitoring, reporting, training and record-keeping. Suited to annual audit requirements and pre-inspection readiness.
Targeted health check
A faster, focused review of the areas that matter most right now, such as a single control, a business line or the findings from a recent inspection. Suited to firms that need a quick, reliable read on their position.
What we test
What we test
Enterprise-Wide Risk Assessment review
Inherent risk across customers, products, channels and geographies, and whether your controls genuinely bring it down to the residual position the board has approved.
Sanctions Screening Testing
Synthetic and known-match testing of detection rates, fuzzy-matching thresholds, list coverage and refresh cycles, plus a review of alert-handling quality.
Transaction Monitoring Calibration
Above- and below-the-line testing of rules and thresholds against live data to close detection gaps and cut false positives.
KYC/CDD File Review & Remediation
Risk-based sampling of onboarding files, gap scoring against your own standard, and a structured back-book remediation programme.
Anti-Bribery & Corruption Review
ABC policy, gifts and hospitality registers, third-party and intermediary due diligence, and conduct risk in commercial incentives.
Verification that the customer and transaction data feeding your screening and monitoring systems is complete, current and correctly mapped.
Remediation Roadmap
Findings ranked by severity and effort, with owners, milestones and evidence requirements the regulator can follow.
Risk domains
The risk domains we cover
A single view across every financial crime and conduct risk your supervisor will ask about.
Money laundering
Placement, layering and integration typologies mapped to your actual customer and product mix.
Terrorist financing
Low-value, high-risk patterns and typologies aligned to UAE national risk assessment findings.
Sanctions
UN, UAE Local Terrorist List, OFAC, EU and UK regime exposure, ownership aggregation and evasion typologies.
Proliferation financing
Dual-use goods, trade finance corridors and opaque ownership structures under targeted financial sanctions.
Bribery & corruption
Third-party intermediaries, facilitation payments, public official exposure and incentive-driven conduct risk.
Conduct & market abuse
Mis-selling, suitability, conflicts of interest and market manipulation controls, where relevant to your licence.
Our audit methodology
01
Scope & data capture
Entity perimeter, risk taxonomy and data extraction agreed, with interviews scheduled across the first and second lines.
02
Testing & analysis
Data analytics, file sampling, screening and monitoring testing, and stakeholder interviews run in parallel.
03
Heat map & findings
Residual risk plotted by domain and business line, with each finding evidenced and rated for severity.
04
Roadmap & readout
A prioritised remediation plan with owners and milestones, presented to the board or audit committee.
Our independence
Independence is the point of an audit. Where RegLex also acts as your MLRO or designed your framework, we will say so up front and agree how independence is maintained, or recommend a separate reviewer.
Who this is for
Commissioned by exchange houses, payment and virtual asset firms, brokers, insurers and DNFBPs: as an annual independent audit, ahead of an inspection, or after a finding.
What you get
An independent audit report that meets supervisory expectations
Evidenced testing results for screening and monitoring effectiveness
A heat-mapped view of exposure by business line and risk domain
A prioritised remediation roadmap with owners and deadlines
Weaknesses identified before the regulator finds them
Faq
Common questions
Is an independent AML audit mandatory in the UAE?
UAE AML/CFT rules require regulated firms and DNFBPs to have their policies, procedures and controls independently tested. Many firms, especially smaller ones, meet this by appointing an external auditor. How often and how extensive the review must be depends on your size, risk profile and regulator.
What is the difference between an audit and a health check?
An audit is a full, independent assessment of your whole framework, suitable for annual requirements and for sharing with your regulator. A health check is a faster, targeted review of specific areas, useful when you need a quick read on your position.
How often should an EWRA be refreshed?
At least annually, and whenever there is a material change: a new product, market, delivery channel, acquisition or significant regulatory development.
What does sanctions screening testing involve?
Controlled testing using synthetic and known-match data to measure detection rates, fuzzy-matching thresholds, list coverage and refresh frequency, alongside a review of alert handling and escalation quality.
How long does an audit take?
An independent audit typically takes two to six weeks, depending on entity size, data availability and sample size. A targeted health check is usually faster.
Will the findings be usable with our regulator?
Yes. Every finding is evidenced, severity-rated and traceable to source data or file references, in the format supervisors expect to see during an inspection.