AML Record-Keeping Requirements: What Documents to Retain and for How Long

Record keeping is a fundamental but often overlooked aspect of AML compliance. When regulators — including the CBUAE, Ministry of Economy, DFSA, FSRA, and FIU — inspect your business, the quality and completeness of your records will be one of the first things they assess. Inadequate record keeping is one of the most common audit findings across all regulated sectors in the UAE under Federal Decree-Law No. 10 of 2025 on Anti-Money Laundering, Combating Financing of Terrorism and Proliferation Financing (which replaced Federal Decree-Law No. 20 of 2018).

UAE businesses must retain all CDD records, transaction data, internal reports, and compliance documentation for a minimum of five years after the business relationship ends or the transaction is completed under Federal Decree-Law No. 10 of 2025 and its implementing Cabinet Decision No. 134 of 2025. Records must be readily retrievable. ADZ’s First Compliance platform provides automated, secure record management with instant retrieval for inspection readiness.

Key Takeaways

  • The mandatory minimum retention period is five years from the end of the business relationship or the date of the transaction — whichever is later — under Federal Decree-Law No. 10 of 2025
  • All CDD records, screening results (including negative results), STR filings, DPMSR/REAR filings, training records, and policy documents must be retained and be readily retrievable within hours
  • Failure to produce required records during a CBUAE, Ministry of Economy, DFSA, or FSRA inspection is itself a compliance violation attracting administrative fines of up to AED 5,000,000 per violation
  • Electronic records are fully acceptable provided they are secure, complete, tamper-evident, and reproducible in readable form
  • Records must be retained beyond five years if subject to an active investigation, legal proceedings, or a hold request from a competent authority such as the FIU

What Records Must Be Maintained

     a) Customer Due Diligence Records

  • Copies of identification documents (passport, Emirates ID, trade license, commercial registration)
  • Beneficial ownership documentation — including UBO declarations, shareholder registers, and corporate structure charts
  • Risk assessment records for each customer, including PEP (Politically Exposed Person) screening results and adverse media screening outcomes
  • Source of funds and source of wealth documentation for high-risk customers requiring Enhanced Due Diligence
  • Enhanced due diligence documentation for high-risk customers, PEPs, and customers from high-risk jurisdictions
  • Records of all ongoing monitoring activities, including periodic risk profile reviews and trigger-event reviews

     b) Transaction Records

  • Full details of all transactions: date, amount, currency, parties, payment method
  • Wire transfer information including originator and beneficiary details (essential for Travel Rule compliance for VASPs)
  • Cash transaction records above and below CDD thresholds, with particular attention to patterns suggesting structuring (smurfing)
  • Records of any transactions that were declined on compliance grounds, including the reason for refusal

High Angle View Of Businessperson Calculating Invoice

First Compliance by ADZ automatically captures and stores all CDD and transaction records in a secure, searchable digital repository — eliminating the risk of lost or incomplete documentation and providing instant retrieval during inspections.

     c) Compliance Program Records

  • AML/CFT policies and procedures, including all historical versions with effective dates
  • Business risk assessment documentation under Federal Decree-Law No. 10 of 2025 and its implementing Cabinet Decision No. 134 of 2025, updated at least annually
  • Compliance Officer appointment records and MLRO designation documentation
  • Board or senior management approvals for compliance program elements
  • Internal audit reports and findings, including remedial action plans
  • Regulatory correspondence with CBUAE, Ministry of Economy, DFSA, FSRA, FIU, or other authorities

     d) Reporting Records

  • STR/SAR filing records and all supporting documentation and investigation notes
  • Internal suspicious activity reports, including cases where an STR was considered but not filed (with documented reasoning)
  • goAML correspondence and FIU acknowledgements
  • TFS screening results, match dispositions, CNMR (confirmed match reports), and PNMR (potential match reports) filed with the CBUAE
  • REAR filings (real estate agents) and DPMSR filings (DPMS businesses) with supporting documentation

     e) Training Records

  • Training dates and topics covered, referencing applicable typologies and regulatory updates
  • Attendee lists and sign-in sheets
  • Assessment results and pass/fail records
  • Training materials used, updated for new typologies including structuring, predicate offences, and sector-specific red flags

Retention Periods

      a) The Five-Year Rule

All records must be retained for a minimum of five years after:

  • The business relationship has ended, OR
  • The date of the transaction, OR
  • The date the report was filed

Some regulators — particularly the DFSA and FSRA — may require longer retention periods for specific record categories. Always verify requirements with your specific supervisory authority.

      b) Beyond Five Years

Records must be retained longer if:

  • Requested by a competent authority (FIU, CBUAE, Ministry of Economy, public prosecutor) during an investigation
  • Subject to ongoing legal proceedings
  • Required by other regulatory obligations specific to your sector or licensing jurisdiction

ADZ’s compliance team helps businesses establish record-keeping policies and systems that meet all regulatory requirements, with our First Compliance platform providing automated retention management and legal hold functionality.

Record Management Best Practices

  • Store records in a secure, organized system with appropriate access controls to protect sensitive CDD information
  • Ensure records are readily retrievable — regulators expect access within hours, not days, during inspections
  • Maintain both digital and physical records where required by your supervisory authority
  • Implement access controls that limit sensitive information to those with a genuine compliance need
  • Back up records regularly to a secure off-site or cloud location
  • Establish clear retention and disposal procedures, with documented sign-off for each disposal event
  • Test retrieval processes before inspections through internal mock-audit exercises
  • Maintain a record inventory or index so inspectors can efficiently navigate your documentation

Frequently Asked Questions

What happens if records are lost or destroyed?

Inability to produce required records during a CBUAE, Ministry of Economy, DFSA, or FSRA inspection is a compliance failure that can result in administrative fines of up to AED 5,000,000 per violation and adverse inspection findings.

Can I keep records electronically?

Yes. Electronic records are fully acceptable provided they are secure, complete, tamper-evident, accessible, and can be reproduced in readable form when required by inspectors or the FIU.

Do I need to keep records of negative screening results?

Yes. Documentation that a customer was screened against sanctions lists, PEP databases, and adverse media sources — and that no match was found — is important evidence of your compliance with a risk-based approach.

When can I destroy AML records?

Only after the mandatory five-year minimum retention period has passed and no regulatory or legal hold applies. Document the destruction event, including the date, the records destroyed, and the authorizing officer.

Are training records really that important?

Yes. Training records are inspected routinely by all UAE supervisory authorities. Missing training records are among the most common minor findings — but repeated failures can escalate into more serious enforcement action.

Related Reading

AML Record Keeping Requirements UAE

AML Compliance Checklist UAE

Fail AML Audit UAE Consequences

Secure, Compliant Record Management

First Compliance by ADZ provides comprehensive digital record management — automatically capturing every CDD record, transaction detail, screening result, STR filing, and training completion in a secure, searchable repository with a complete audit trail. Every record is instantly retrievable for CBUAE, Ministry of Economy, DFSA, FSRA, or FIU inspections.

ADZ’s advisory team helps businesses establish record-keeping policies, test retrieval readiness, and implement retention management that meets all UAE regulatory requirements.

Contact ADZ today — visit adilzone.com or reach out to our compliance team.

Scroll to Top