Bank, Fintech, Crypto, DNFBP or Consulting: How the AML Job Actually Differs 

07.09.26 05:16 AM By NIYEAHMA

In short. Anti-money laundering (AML) work differs most by control maturity and ownership. In a bank, you operate a mature programme and own a narrow part of it. In fintech compliance jobs, you may be the programme. Virtual asset businesses add licence and supervisory uncertainty. Consultancies and managed service providers give breadth without living with the decision. At a DNFBP, a real estate brokerage, a corporate service provider or an audit firm, you are usually the whole compliance function, with the widest blast radius and the thinnest support. The supervision section below is grounded in Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025. 

AML jobs are advertised in almost identical language, no matter where they sit. Conduct customer due diligence. Review alerts. Escalate suspicious activity. Support the compliance officer. 


Those four lines describe six completely different jobs depending on who prints them. 


What follows compares the work, not the industry. What you do on a Tuesday. What breaks if you are wrong. What the environment quietly writes onto your CV. And because the supervision rules here are UAE-specific, if you are weighing AML jobs in Dubai or elsewhere in the UAE, the section on who supervises you does that licence by licence. 


How to use this article. If you are comparing offers, start with Table 1 and the interview questions; if you are checking UAE regulatory fit, go directly to the supervision section. 

The nine things that actually differ between AML employers

Key point: employer type changes the work through nine variables, and pay is not the most important one. 

  1. Control maturity. Operating a framework someone else built, or writing one. 

  1. Tooling and data quality. A configured monitoring platform with clean data, or a spreadsheet and a vendor trial. 

  1. Ownership. How much of the programme is yours. One control, or all of them. 

  1. Regulatory intensity and who supervises you. How often a supervisor is in the building, and whether you ever speak to one. 

  1. Blast radius. How far the damage travels when you are wrong. 

  1. Pace and change frequency. How often the product, the customers and the rules move underneath you. 

  1. What your day looks like. Queue work, project work, client work, or all three in a week. 

  1. What it does to your CV. Which doors it opens, and which it quietly closes. 

  1. Career risk. Restructuring, funding, licence withdrawal and offshoring exposure sit in different places. 

What blast radius means, and why it matters more than seniority

Blast radius is the distance between your mistake and its consequence.


In a large bank, quality assurance (QA), the next reviewer, or a lookback catches a wrongly closed alert. 


In a small fintech with no second reviewer, the same wrongly closed alert leaves the building. It reaches a regulator, or a correspondent bank, or nobody at all, which is worse. 


A small blast radius is comfortable and teaches you slowly. Large blast radius teaches you fast and punishes you hard. Neither is better. Know which one you are choosing. 

The six environments compared

Key point: the same job title carries different trade-offs in each of these six places. 

Most articles on this compare four. I have added two more. A fifth, because many people in financial crime compliance work at outsourced and managed service providers and almost nobody writes about that job. And a sixth, because DNFBP roles at real estate brokerages, corporate service providers, audit firms, dealers in precious metals and stones, and gaming operators are where a large share of UAE AML hiring actually happens, and they behave nothing like the other five. 


Table 1 runs the nine variables down the left and the six employer types across the top. Read it as a row rather than as a column. A single dimension, such as control maturity or blast radius, tells you more about what your week will actually feel like than any whole-column summary of an employer type can. 


The mistake people make with a grid like this is treating a column as a ranking. Each buys you something and charges you for it in another row, usually in the row you skipped. If you are weighing two offers, pick the three dimensions that matter most to you and compare only those. 

Dimension 
Bank or large financial institution Fintech or payments firm Virtual asset business Consultancy or advisory Outsourced or managed service provider DNFBP or other sector-specific business 
Control maturity Mature, documented, already exists. You operate a part of it 
Ranges from strong to almost nothing. You may be the programme 
Young. Often built from scratch in the last few years 
Not yours. You assess and design other people's The client's programme, run to the client's procedure under a contract Usually the newest. Often you are writing the first version 
Tooling and data quality Configured platform, governed data, slow to change anything 
Spreadsheets, a vendor trial, or a well built in-house rules engine. Huge variation 
Chain analytics plus conventional screening. Data is public, attribution is hard Whatever the client has. You see many and configure none Client tooling or the provider's case platform, often read-only Minimal. A screening subscription, a spreadsheet register, manual files 
Ownership of the programme One control, deeply. Narrow remit, clear boundaries 
Potentially all of it: policy, tooling, filings, training, board reporting 
Most of it, plus the licensing conversation 
None of it. You advise and leave A defined process at volume, to a service level. Decision rights stay with the client All of it, usually alongside another job you already do 
Regulatory intensity and supervisor 
Highest contact. Prudential and conduct supervision, examinations, remediation 
Real supervision, lighter contact until something goes wrong 
High attention. The supervisor depends on where you are licensed 
Indirect, unless the firm is itself a subject person Indirect. The client is supervised. You inherit their findings Direct. Supervised by the MoET or the relevant free zone authority as a DNFBP 
Blast radius 
Small per person. Contained by QA, audit and layered review 
Large. Often no second reviewer, and one failure can matter to the firm 
Largest. Errors can be public, on-chain and permanent. Licence risk is live 
Small operationally, large reputationally for the firm Small per case, systemic across the book. One process defect repeats everywhere Widest relative to support. No second reviewer, no QA, no escalation layer 
Pace and change frequency 
Slow. Change runs through committees and release cycles 
Fast. Product ships weekly and the risk profile moves with it 
Fastest. Products, chains and rules all move 
Project paced. Weeks or months, then a new client Steady and high volume. Change arrives as a client instruction Deal paced. Quiet, then a transaction that has to close this week 
What your day looks like A queue, a workflow, a QA sample, a monthly pack A queue, plus policy drafting, a product meeting and a vendor call Alerts, wallet tracing, travel rule exceptions, licensing questions Interviews, gap analysis, workshops, deliverables, travel High-volume case work against a script, to handling-time and quality targets UBO unpicking, source of funds on a deal, screening hits, the register, board memos 
What it does to your CV Depth in one control, recognised everywhere. Reads as narrow after long service Breadth, and visible gaps. Reads as capable and slightly unproven Specialist. Opens virtual asset roles, narrows some conventional ones Breadth plus network. Reads as advisory rather than operational Strong on process discipline and volume, weaker on judgement and ownership Deep on beneficial ownership and sector risk, thin on tooling and scale 
Career risk Restructuring, offshoring of process roles, slow internal mobility Funding risk. The firm can disappear before your programme is finished Licence risk, market cycles, withdrawal from a jurisdiction Utilisation pressure and up-or-out. Easy to reverse into industry Contract loss, client insourcing, highest exposure to task automation Small firm dependency, budget pressure, isolation from compliance peers 
The table is the quickest way to read the article; the sections below explain the trade-offs behind each row. 

AML in a bank or large financial institution

Key point: the programme already exists, and your job is to operate a small part of it well. 

AML jobs in banks all start from the same condition. Somebody wrote the policy years ago. Somebody else configured the transaction monitoring rules, and a separate team validates them. A third team owns the data. Your remit is a slice of that AML programme, and the slice is well defined. 


You get depth. High volumes, unusual typologies, correspondent relationships, and enough repetition to build real pattern recognition. You also see what a supervisory inspection looks like from the inside, which almost nothing else teaches. Banks have the strongest QA culture in the field, so if your written work is weak, you will find out. Our guide to what an AML analyst actually does all day sets out that queue in detail. 


What it costs you is scope. After five years you may know alert triage extremely well and have never written a policy, chosen a vendor, or presented to a board. That is not a failure of effort. It is the structure. 


Who it suits. People who want to learn one control properly, and who are early enough in an AML career path to trade breadth for grounding. 

AML in a fintech or payments firm

Key point: the variance between fintechs is wider than the gap between fintechs and banks. 

The spread in programme quality between one fintech and the next is the single most useful thing I can tell you about fintech compliance jobs. 


Some fintechs have a genuinely good programme, built by someone who came from a bank and knew what they were doing. Two years there can teach you more than several in a narrow bank seat. Others have a policy nobody has read, a rule set that has never been tuned, and one overwhelmed person. Two years there teaches you how to survive and very little else. 


Same sector. Opposite outcome. The interview questions further down exist to tell these two apart. 


What a fintech gives you that a bank does not is ownership. You write the risk assessment. You sit in product meetings and get asked whether a feature can launch. You pick the tooling. Almost everything happens remotely, so onboarding controls, document authenticity, and liveness checks become your daily problem rather than a branch's. 


What it costs you is gaps. You may never see a mature model validation, a formal lookback, or a working three lines of defence structure. That shows up later, in interviews, as a hesitation you cannot hide. 


Who it suits. People with two to five years of grounded experience who want scope, and who can tolerate being the most senior AML voice in the room.

AML at a virtual asset business

Key point: crypto compliance jobs are conventional AML plus chain analytics, wrapped in a regulatory position that is still settling in most markets. 

Screening, customer due diligence (CDD), enhanced due diligence (EDD) and suspicious transaction reporting all still apply. On top of that, you get wallet attribution, exposure scoring, mixer and bridge tracing, and travel rule exceptions that fail for reasons no bank ever encounters. 


Working at a virtual asset service provider (VASP) builds one thing nowhere else does. Chain analytics, more commonly searched as blockchain analytics, is a genuinely distinct skill. It is portable, scarce, and the strongest single reason to take one of these roles. You can read a blockchain trace, or you cannot, and the market knows the difference. 


The peer group is smaller. There is less institutional memory to borrow from and fewer people to check your reasoning against, so you make judgement calls on thinner precedent. 


Licence risk is career risk that doesn't exist elsewhere. A firm can lose permission to operate in a market, and the compliance team goes with it. That is a reason to ask at interview exactly what the firm is licensed for and by whom, not a reason to avoid the sector. 


Who it suits. People comfortable with ambiguity who want a scarce technical skill, and who accept a narrower set of conventional exits in return. 

AML in consultancy and advisory

Key point: consultancy gives you exposure to many programmes and lets you leave before you live with any decision. 

Inside consultancy, there are three different types of roles. Large firm advisory work is assessments, AML audit and assurance engagements, remediation programmes and regulatory response, at scale, with a strong brand on your CV. Boutique work is closer to the client and more hands-on. Contract or interim work is effectively an in-house role with an end date. All three put the title AML consultant on your CV, and none of them describes the same week. 


The breadth is real. In two years you may see programmes at banks, payments firms, virtual asset businesses and designated non-financial businesses and professions (DNFBPs). That comparative view is hard to get any other way. 


The cost is ownership. You produce a recommendation, the client accepts or ignores it, and you move on. You never find out whether the rule you proposed generated usable alerts eighteen months later. Clients can tell the difference between someone who has run a programme and someone who has reviewed forty of them. 


Consultancy can also put you in scope yourself. Independent accountants and lawyers become subject persons in their own right when they carry out certain activities for clients, as set out in the rule text below. 


Who it suits. People who want breadth, network and structured progression, and who intend to move into industry later. Its value is strongest when you plan the return to industry before the advisory label becomes too settled. 

AML at an outsourced or managed service provider

Key point: this is the largest under-described employer type in financial crime compliance, and it is a real job with real trade-offs. 

A managed service provider runs part of a client's AML compliance programme under contract. Onboarding queues, periodic review backlogs, alert triage, screening disposition, remediation and lookback exercises. 


You get volume and discipline. You will handle far more cases than most in-house analysts, working precisely to procedure, with your output constantly sampled. That discipline transfers. 


What you do not get is decision rights. The client usually keeps the call on escalation and filing. You prepare, they decide. You also rarely see the outcome, which is where most of the learning lives. 


The career risk here is the highest of the six. Contracts end, and clients insource. And high-volume, procedure-driven casework is the task profile most exposed to both automation and further offshoring, which I cover separately in which AML roles are exposed to offshoring


Who it suits. People entering the field who need volume and a track record fast, and who plan to move in-house within a few years.

AML at a DNFBP or other sector-specific business

Key point: DNFBP roles are a sixth environment, with the widest blast radius and the thinnest support. 

Designated non-financial businesses and professions are the sixth environment. Trust and corporate service providers, audit and accountancy firms, real estate brokers, dealers in precious metals and stones, and gaming operators are all in scope in the UAE as DNFBPs under Article 3 of Cabinet Resolution No. 134 of 2025. 


The defining feature is that you are almost never a compliance department. You are a person who also does compliance, or the single hire who is the entire function. No queue is built for you, no QA sample, no second reviewer, and usually no monitoring platform. The register is a spreadsheet, and the screening is a subscription. 


The work is deal-shaped rather than queue-shaped. Nothing happens for a fortnight, then a transaction has to close this week, and the source of funds does not reconcile. That is when the job is actually tested, and it is tested on judgement rather than on throughput. 


These roles are smaller, closer to the client, and often the only compliance seat in the firm. Blast radius is very large, and support is thin. They also teach beneficial ownership work, identifying the ultimate beneficial owner (UBO) behind a structure, better than most bank roles do. If you are heading into that space, our course on AML obligations for TCSPs in the UAE is built for it. 


Who it suits. People who want ownership early and can tolerate working without a safety net. It is a poor fit if you need peers to check your reasoning, and a strong fit if you want beneficial ownership and source of funds work on your CV faster than any bank will give it to you.

Who supervises you, and why it changes by employer type

Key point: UAE federal law applies to all six employer types, but who inspects you depends on what your firm is licensed as and where. For a DNFBP, it is normally the Ministry of Economy and Tourism (MoET) or the relevant free zone authority, not the Central Bank. 

Supervision is where the employer question stops being about culture and becomes a legal matter. 


The current UAE anti-money laundering and countering the financing of terrorism (CFT) framework is Federal Decree-Law No. 10 of 2025 and its Executive Regulations, Cabinet Resolution No. 134 of 2025. They replaced Federal Decree-Law No. 20 of 2018 and Cabinet Decision No. 10 of 2019, so you should carefully check any current reliance on the earlier framework. 


The law does not name one supervisor. It defines the term by function. Article 1 of Federal Decree-Law No. 10 of 2025 defines the Supervisory Authority as:

"The federal and local authorities entrusted under the legislation with the supervision of the financial institutions, designated non-financial businesses and professions, virtual asset service providers, and non-profit organizations (NPOs); or the competent authorities responsible for granting approval to engage in an activity or profession, where no specific supervisory authority is designated by the legislation." 

Read that carefully. Your supervisor depends on what your firm does and how it is licensed, not on what your team is called. 


In practice, a bank or exchange house is supervised by the Central Bank of the UAE. A virtual asset business may sit under the Virtual Assets Regulatory Authority in Dubai, the Dubai Financial Services Authority in the Dubai International Financial Centre, or the Financial Services Regulatory Authority in the Abu Dhabi Global Market, depending on where it is licensed and what it does. Confirm the position with the supervisor itself. I have reproduced no free zone rule text here, and the verification section explains why. 


Article 36(1) of Cabinet Resolution No. 134 of 2025 makes the licensing point for virtual assets: 

"Any natural or legal person conducting any Virtual Asset Service Provider activity, offering related products or services, or performing its transactions from within the State shall be licensed, registered, or listed, as applicable, by the competent Supervisory Authority." 

Article 4 of the same Resolution defines the activities that put your employer in scope. They include: 

"1. Exchange between Virtual Assets and fiat currencies. 2. Exchange between one or more types of Virtual Assets. 3. Transfer of Virtual Assets. 4. Safekeeping or administration of Virtual Assets or instruments enabling control over Virtual Assets." 

Regulatory intensity is set by risk, not by employer type

People assume banks get inspected more because they are banks. That is not what the rule says. 


Article 49(10) of Cabinet Resolution No. 134 of 2025 requires the Supervisory Authority to determine inspection frequency based on:

"a. The National Risk Assessment; b. The characteristics of Financial Institutions, Financial Groups, DNFBPs, and Virtual Asset Service Providers, including their diversity, size, and degree of discretion permitted under the risk-based approach; c. Crime risks, the level of understanding thereof, and the internal policies, controls, and procedures applied" 

So a small firm in a high-risk activity can attract more supervisory attention than a large firm in a low-risk one. Size is one input, not the answer. 

The Compliance Officer or MLRO duty is the same in all of them

The role sits on the same statutory footing at a bank, a fintech and a virtual asset business. Article 22 of Cabinet Resolution No. 134 of 2025 requires that firms:

"appoint a Compliance Officer at management level and under their responsibility, who shall have independence in decision-making and possess appropriate competence and experience" 

and sets five duties, including: 

"Reviewing records and receiving, examining, and assessing Suspicious Transaction data, and deciding whether to notify the Unit or to retain the matter stating the reasons therefor, in full confidentiality." 

Article 49(18) adds that the Supervisory Authority must require firms to obtain: 

"its prior approval before appointing their Compliance Officers" 

For Licensed Persons supervised by the Central Bank of the UAE, Chapter 16 of the CBUAE Rulebook adds experience thresholds on top. Rule 16.4.4 sets, for a Category B or C licence: 

"A minimum of eight (8) years of experience in AML/CFT compliance, audit or risk management within any financial institution(s); or A minimum of five (5) years of experience in AML/CFT compliance, audit or risk management within any financial institution(s) and possess a specific certification related to AML/CFT compliance." 

Note the career consequence. That rule counts experience "within any financial institution(s)". Whether your fintech, virtual asset or consultancy years count towards a Central Bank appointment is a question for the Central Bank, not a blog. Note also that the same rule allows a specific AML and CFT certification to substitute for three of the eight years, so if you are counting on that route, our account of how much preparation the CAMS exam really takes prices the study time before you commit. Terminology shifts too: UAE federal law says AML compliance officer, while the DIFC and the ADGM say Money Laundering Reporting Officer (MLRO). Our comparison of the MLRO, the compliance officer, and the BSA officer sets out which of the two is accountable, and for what. 

Where consultancies are themselves in scope

Article 3 of Cabinet Resolution No. 134 of 2025 brings certain professional firms into scope as DNFBPs in their own right. It names: 

"Lawyers, notaries, other independent legal professionals, and independent accountants, whether practising individually, as partners, or as professionals within a firm practising such profession, when they prepare, conduct, or execute financial transactions on behalf of their customers" 

Company and Trust Service Providers are named separately in the same article on the same basis. So an advisory firm can be both the adviser and the subject person. If you join one, ask which of the two you are working on. 

Which moves are reversible, and which are not

Key point: reversibility should drive this decision more than pay does, and almost nobody thinks about it. 

Reversibility means how easily you could return to the kind of employer you left, if the new one turns out to be wrong or simply stops existing. Table 2 rates six common moves as easy, moderate or hard, and gives the reason in the third column. Read the reason rather than the rating, because it names what the receiving employer is actually reading on your CV. 


Time is the variable in almost every row. Most of these moves are reversible early and stop being reversible after a few years, because a hiring manager reads you as whatever you did most recently rather than whatever you did first. A bank grounding fades as a selling point at roughly the speed it stops being current. 


The common mistake is to examine the outbound move in detail and never once ask what the return leg would look like.

Move How reversible Why 
Bank to fintech, in the first five years Easy Your bank grounding is still recent and legible 
Bank to fintech, after ten years Harder You are now priced and read as a fintech person 
Fintech or virtual asset business to bank Moderate to hard Banks test for framework exposure you may not have 
Industry to consultancy Easy Consultancies hire practitioners deliberately 
Consultancy to industry Easy, if you move within about three years After that you read as advisory rather than operational 
Managed service provider to in-house Moderate You must show judgement and decisions, not volume 

The asymmetry is the point. Moving out of a bank is easier than moving back in. Plan the return trip before you take the outbound one. 

Eight questions to ask a hiring manager that reveal control maturity

Key point: the advert cannot tell you what you are walking into. These eight questions can, and all eight are ones you can actually say out loud in an interview. 

These are ordinary interview questions, not an audit. Each one is something a candidate can reasonably ask about a job they are considering, and none of them asks for confidential detail. Ask them plainly, as a professional assessing a role. A good employer answers. An evasive answer is itself the answer. If you are early in your career and want only a few, questions two, six, seven and eight are the most natural to ask and still tell you most of what you need. 

  1. "Who owns the enterprise risk assessment, and would I get to work on the next update?" Asked as interest in the work rather than an audit of it, and it returns the same information. A named owner and a live update cycle mean a real programme. Vagueness about who owns it means you may be about to write it. 

  1. "Walk me through an alert from generation to closure. Who reviews it, and what proportion is quality assured?" You are testing whether a second pair of eyes exists. If analysts close their own work, your blast radius is large. 

  1. "When were the transaction monitoring rules last tuned, and who approved the thresholds?" A programme that has never tuned its rules is running the vendor's defaults. Our piece on reading a transaction monitoring rule like an examiner explains what a good answer sounds like. 

  1. "How does compliance get involved when the business wants to launch something new?" The most revealing question in the list, and easier to ask than it looks. You are listening for whether compliance is consulted before the decision or told after it. If examples of compliance changing a plan come easily, it has standing. If the question lands as a blank, it does not. 

  1. "Is there a remediation or improvement programme running at the moment, and would this role touch it?" You are not asking what an inspection found, and you should not: much of it will be confidential and the question puts an honest manager in an awkward position. You are testing whether they know what is being fixed, and whether they will describe its shape to you. 

  1. "What does the workload look like day to day, and is the team on top of it at the moment or catching up?" A backlog is normal, and putting it this way lets the manager say so without it sounding like an admission. A team that cannot describe its own position is the warning sign. We cover what an alert backlog actually signals separately. 

  1. "How many people do this job today, and how many did it a year ago?" Direction of travel matters more than the number. Ask why anyone left. 

  1. "What would I own outright in month one, and what would need someone else's approval?" The ownership question in plain form. It tells you where you sit between operating a programme and being one. 

Two rules for reading the answers. Ask the same question of two interviewers and compare. And ask to speak to whoever holds the Compliance Officer or MLRO appointment, because question four is usually only answered honestly by them.

If you are moving towards fintech or virtual assets

Key point: remote onboarding is the control set that changes most, and it is where bank-trained people are most often caught out. 

The control set that changes most when you leave a branch-based institution is onboarding. No counter, no original document in hand, no colleague to eyeball the customer. Everything is remote, and the failure modes are different. 


Three things break in ways a branch never sees them break. Document authenticity, because you are assessing an image of a passport rather than the passport. Liveness, because the face on the video call can be synthetic or replayed. And source of funds, because there is no relationship manager who has met the customer and can vouch for the story. 


The second change is speed. A branch account opens over days. A fintech account opens in minutes, which means the control has to be decisive in real time or the customer is already transacting. That constraint is what makes remote onboarding a different discipline rather than the same discipline online. 


That is the concrete skills gap for anyone making this move, and our course on AML Compliance in Remote Customer Onboarding covers it directly. Enrol Now, or Explore Courses across the catalogue if a different sector fits you better. 

We sell AML training, so here is our interest in this

ProAML Training, part of NIYEAHMA, sells applied AML and CFT training. Some of what I have described as a gap in one environment is a gap our courses address. You should factor that in. 


I have tried to keep the article honest about it. I have not said any employer type is better. I have not named a single firm, praised or otherwise. I have not put a salary figure anywhere on this page, because pay claims are the easiest way to make a career article persuasive and wrong. If you want pay, we treat it separately and with sourcing discipline in AML salary bands by role, region and employer type and in our guide to AML analyst salary in Dubai.

How this article was researched and verified

Read at source and quoted verbatim on 30 August 2026. Federal Decree-Law No. 10 of 2025, Article 1 definition of the Supervisory Authority. Cabinet Resolution No. 134 of 2025, Articles 3, 4, 22, 36(1), 49(10) and 49(18). CBUAE Rulebook Chapter 16, within Notice N 35/2018 STA, Rule 16.4.4, read at rulebook.centralbank.ae. Every blockquote above is reproduced word for word, not paraphrased from a secondary summary. 


Deliberately left out. No salary, pay ratio or bonus figure, because none could be sourced to a survey with a stated sample, geography and date. No headcount, growth rate, hiring trend or failure rate, because every figure I found for those sat two or three citations away from its origin. No vendor is named, including chain analytics providers, because naming one in a career article implies a requirement that does not exist. No employer is named or characterised.

 

Left unverified, and marked as such in the text. The current rulebooks of the Virtual Assets Regulatory Authority, the Dubai Financial Services Authority and the Abu Dhabi Global Market Financial Services are named in general terms and given no rule reference for any of them. Verify with the relevant authority before relying on it. Virtual asset regulation moves faster than any other part of this framework. 


Repealed instruments. Federal Decree-Law No. 20 of 2018 and Cabinet Decision No. 10 of 2019 are repealed and are not cited here as current. 


Practitioner sentiment. The observations about variance between fintechs, about consultancy and ownership, and about managed service work come from my own experience and from practitioner discussion in open professional forums. Practitioners in those forums repeatedly say the fintech decision is impossible to judge from outside. That is sentiment, not research, and no claim on this page rests on it.

Frequently asked questions

No. It is wider and less supported. Scope goes up and the safety net comes down. The work is not simpler, and you get less help when it is hard. 
That depends far more on the specific fintech than on the sector. Two firms with the same funding stage can offer opposite jobs. Use the eight interview questions above to tell them apart before you decide. 

Write policy, choose or configure tooling, sit in product decisions, and answer the board pack question directly. You are also likely to own remote onboarding controls end to end rather than a slice of them. 

It can narrow some conventional doors and open others. Chain analytics is a scarce, portable skill. The effect is much better if the firm is properly licensed, which is why you should check the licence before you accept. 

In practice, yes. Tracing funds across wallets, bridges and mixers is the core investigative skill in that environment. No specific product is required, and you should not treat any one platform as the standard. 

It is excellent for breadth, comparative judgement and network, and weak for ownership. It is also one of the easiest moves to reverse. Move back into industry within about three years if you want to be read as operational. 

This page intentionally carries no salary figures. Pay varies more by market and by firm than by employer type, and most published figures do not state their sample. We handle it separately in AML salary bands by role, region and employer type

Scale is not the protection people assume. Large institutions restructure and offshore process roles. Small firms fail. The safer position is a role with decision rights, not a role at a large employer. 

A fintech or a small regulated firm, because the scope is wider and titles move faster. The trade is that you may skip formal control disciplines you will be tested on later. 

Yes, and the way to do it is to collect decisions rather than volume. Ask to own escalations, to draft narratives, and to join client calls. Interviewers test judgement, and volume alone doesn’t prove it. 

Most in a supervised financial institution, where inspections and remediation are routine. Least at a consultancy or a managed service provider, where the client holds the relationship. Regulator contact is career-relevant, so ask about it directly. 

It depends on the licence. Federal Decree-Law No. 10 of 2025 defines the Supervisory Authority by function rather than naming one body. A virtual asset business may fall under the Virtual Assets Regulatory Authority in Dubai, or the DFSA in the DIFC, or the FSRA in the ADGM. Confirm with the authority itself. 

Yes, increasingly. They tend to screen for judgement, writing and the ability to work without a procedure, rather than for institutional pedigree. Our guide to exit options from AML and what each one preserves covers the reverse direction. 

Federal Decree-Law No. 10 of 2025 applies to all of them. What differs is who supervises you, and that follows the licence rather than the sector. A bank or exchange house sits with the Central Bank of the UAE. A virtual asset business sits with VARA, the DFSA or the FSRA depending on where it is licensed. A DNFBP sits with the Ministry of Economy and Tourism or its free zone authority. A consultancy may be outside supervision, or may itself be a DNFBP under Article 3 of Cabinet Resolution No. 134 of 2025. Confirm your own firm's position with its supervisor. 

No. In a bank it is a defined step in a documented process. In a fintech it is usually remote, automated and yours to fix. At a managed service provider it is high-volume work against a client script with no decision rights. 

Less than people expect, with one concrete exception. Rule 16.4.4 of the CBUAE Rulebook allows a specified AML and CFT certification to substitute for three of the eight years of experience required to be approved as a Compliance Officer at a Category B or C licensed person. Outside that, a certification signals vocabulary and intent rather than judgement, and no employer type treats it as a substitute for having owned a decision. Our comparison of AML certifications by career stage sets out which one is worth taking when. 

About the author

Pathik Shah is the founder of ProAML Training. He holds CAMS and is a Fellow Chartered Accountant (FCA) and a Certified Information Systems Auditor (CISA), and he holds the DISA and FAFD qualifications from the Institute of Chartered 
Accountants of India. He has spent more than 28 years in governance, risk and compliance, and advises regulated 
firms across the UAE and the GCC on AML and CFT programmes. He writes about the difference between knowing the 
rules and doing the work.

NIYEAHMA