How to Become an AML Analyst in the UAE: The Route In and What to Learn First 

15.09.26 10:51 AM By NIYEAHMA

In short. To become an AML analyst in the UAE you need to be able to form a risk view and defend it in writing. That is the whole job in one sentence. No UAE law requires a qualification for the role. What employers test is whether you can score a customer, decide what enhanced due diligence is proportionate, resolve an alert, and write it up so a reviewer can follow you. 

There are two routes into an AML analyst role in the UAE. You move up from KYC or onboarding, or you come across from another profession. The first is the more common. The second is more common than most career pages admit. 


Both routes fail for the same reason. Candidates arrive able to describe the process and unable to make a call. An AML analyst is paid to reach a conclusion on incomplete information, put a rating on it, and be willing to explain that rating six months later to someone who was not there.

What is an AML analyst? The role at a glance

An AML analyst is the person in a regulated UAE firm who scores customer risk, decides what due diligence that score requires, works the alerts it produces, and writes the record a reviewer or supervisor relies on later. 

Key point: the role is defined by the decisions you own, not by the tasks you perform. 

The table below sets out the role as UAE employers staff it. The column worth studying is the decisions column, because that is what an interview probes and what a promotion depends on. Candidates who prepare from the tasks column give correct answers that sound like a process manual, which is the commonest reason a technically competent applicant is passed over. 
Attribute What it looks like in the UAE market 
Common entry routes Promotion from KYC or onboarding; transfer from audit, accounting, banking operations, fraud, risk, legal or law enforcement 
Tasks you perform Customer risk assessment, enhanced due diligence, screening review, alert handling, investigation, escalation and report drafting 
Decisions you own The risk rating and its rationale, what due diligence is proportionate, whether an alert is closed or escalated, whether an escalation becomes a report recommendation 
What is tested at interview Whether you can defend a rating, handle a case that will not resolve, and write a note somebody else can act on 
Sectors that hire Banks, exchange houses, fintech and payments, virtual asset firms, and every category of designated non-financial business 
Next role Specialist analyst in screening, monitoring, enhanced due diligence or investigations, then senior analyst 

AML analyst requirements and qualifications: what UAE law requires versus what employers ask for

Key point: UAE law sets no qualifications or experience period for an analyst role. Everything you have read to the contrary is employer preference. 

Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025 impose obligations on regulated businesses, not entry requirements on their staff. The only individual the Executive Regulations describe is the Compliance Officer, in Article 22, and even there the requirement is appropriate competence and experience rather than a named credential. 


One indirect requirement is worth knowing, because candidates rarely do. Cabinet Resolution No. 134 of 2025, Article 21 requires firms to have screening procedures that ensure high standards of fitness and propriety when appointing employees, and to run periodic programmes and workshops to build the capacity of those in the compliance function. That is why a background check is part of your hiring process and why your employer must keep training you after you join. 


Everything else on a job advert is preference. Useful preference, often decisive preference, but not a legal requirement, and worth distinguishing when you are deciding where to spend your own money.

AML analyst skills: the six that get people hired in the UAE

Key point: six skills, and five of them are things you decide rather than things you do. 

Read the list below as six decisions rather than six topics. That reframing is the whole point. Most candidates can describe what a customer risk assessment is. Far fewer can say what they would do when two risk factors point in opposite directions, which is the situation that actually arrives. The skills are ordered as they are usually acquired, and the last one carries more weight than its position suggests. 

Customer risk assessment and the risk-based approach

Customer risk assessment is the rating that decides how much due diligence a customer receives and how closely they are monitored, and it is the foundation every other decision in the role sits on. Article 5 of the Executive Regulations requires regulated businesses to identify, understand, manage and assess their crime risks proportionately to the nature and size of their business, considering all relevant risk factors including customer risk, country and geographic risk, product, service, transaction and delivery channel risk, before determining the overall risk level and the mitigation to apply. 


Those five factor categories are the skeleton of every customer risk assessment you will ever complete. An analyst who can name them and explain how they interact is already ahead. An analyst who can explain why two customers with the same score need different treatment is ready for the next rung.

Enhanced due diligence: choosing measures proportionate to the risk you found 

Enhanced due diligence is the set of additional measures a higher risk rating obliges you to apply, chosen to address the specific risk you identified rather than applied as a fixed pack. Article 5(2)(c) of the same Resolution lists what enhanced due diligence looks like: obtaining and verifying additional information such as the customer's identity and occupation, the beneficial owner, the amount of funds and information from public databases and open sources; obtaining additional information on the purpose of the relationship or the reasons for expected or actual transactions; updating due diligence information more regularly; taking reasonable measures to identify source of funds and wealth; and increasing the degree and level of ongoing monitoring. 


The judgement is in the word proportionate. Enhanced due diligence is not a fixed pack applied to everyone above a threshold. It is a set of options, and choosing the two that address the specific risk you identified is what separates an analyst from a form-filler.

Sanctions screening, PEP and adverse media screening judgement

Sanctions, PEP and adverse media screening produce far more noise than signal, and the analyst's value is in discriminating between them fast and defensibly. The skill has three parts: knowing when a name match is genuinely the same person, knowing what secondary identifiers actually prove, and knowing when an adverse media item is material rather than merely embarrassing. 


A fairness rule applies here and it is not optional. No risk conclusion attaches to a customer's nationality, ethnicity, name origin or the country that issued their document, on its own. Country risk is a factor about jurisdictions and exposure, not a judgement about people, and treating it otherwise produces both bad compliance and unlawful discrimination. 

Transaction monitoring alert triage 

Transaction monitoring alert triage is deciding, quickly and defensibly, whether activity fits what you expected the customer to do. Most analysts inherit an alert queue. The skill is reading an alert as a question about expected behaviour rather than as an accusation. What did we expect this customer to do, based on what they told us at onboarding, and does this activity fit that picture? 


This is where the customer file you built in a KYC role pays off. An analyst who never reads the onboarding file before working the alert is guessing, and it shows in the write-up. 

AML investigation and evidence assembly 

When an alert does not resolve, it becomes an investigation. That means gathering what is available internally, checking public sources, building a chronology, and separating what you observed from what you inferred. 


The discipline that matters is keeping those two categories apart on the page. A chronology that mixes established facts with your working theory reads as compelling and falls apart under review, which is the worst combination available. 


The practical habit is to write the chronology before you form a view. Dates, amounts, counterparties and what the customer told you, in order, with nothing interpretive in it. Only then write what you think it means. Doing it the other way round means you assemble evidence that supports a conclusion you already reached, which is how investigations go wrong.

Writing an escalation note and a suspicious transaction report narrative 

An escalation note is the analyst's written recommendation to the Compliance Officer, and it is the output every other skill on this list feeds into. The reporting obligation behind it is absolute: Federal Decree-Law No. 10 of 2025, Article 18(1) requires notification of the Financial Intelligence Unit without delay and directly where a firm suspects or has reasonable grounds to suspect that a transaction or funds represent proceeds or relate to the crime, regardless of value. 


As an analyst you rarely file the report. You write the note that the Compliance Officer relies on to decide. Get into the habit of writing that note as if the decision maker has never seen the customer, because that is usually true. 

From KYC analyst to AML analyst: the two gates 

Key point: you can arrange both gates within your current job. 

If you are already in KYC or onboarding, you have the customer picture. What changes when you cross into AML work is covered on the KYC analyst page. This section is narrower and more useful: the two specific pieces of evidence a hiring manager looks for, and how to get both without changing employers. 

  1. You have justified a risk rating in writing to someone who disagreed, and the rating survived. Ask to draft the rationale on files your senior currently rates, then have them mark it. 

  1. You have handled a case that did not resolve cleanly. Volunteer for the files everyone else avoids, because those are the only ones that teach you anything about ambiguity. 

Both are ordinary requests most managers will grant because they reduce their own workload. The reason people do not make the move is almost never that permission was refused. It is that they never asked. 

AML analyst career path from outside compliance: six routes in 

Key point: name what transfers, then close the one gap that does not. 

Six backgrounds convert well, and each carries a different strength and a different gap. Auditors bring evidence standards and lack customer risk framing. Accountants bring the ability to read structures and financials and lack the reporting framework. Fraud analysts bring pattern recognition and lack the regulatory context. Banking operations staff bring system fluency and lack the judgement layer. Lawyers bring documentary rigour and lack operational pace. Law enforcement backgrounds bring investigation skills and lack the commercial and proportionality dimension. 


The application mistake is common to all six. Candidates describe their previous job and hope the reader makes the connection. Do the connecting yourself. State the transferable skill, name the gap, and say what you have done about the gap. A candidate who says openly that they have never scored a customer risk assessment but has built three on public companies is far more credible than one who talks around it. 

What a first AML analyst interview tests 

Key point: expect a scenario. Prepare a method, not an answer. 

Almost every AML analyst interview includes a scenario. You will be given a customer, some activity, and an inconsistency, and asked what you would do. Interviewers are not checking whether you arrive at their answer. They are checking whether you have a method. 


A usable method has four steps, and saying them out loud is half the marks. State what you know. State what you would want to know and where you would look. State the range of conclusions the evidence currently supports. State what you would escalate and to whom. 


The single strongest answer available to a candidate is to identify what would change your mind. Very few applicants do it, and it demonstrates exactly the quality the role requires.

What to learn first as an AML analyst, in order 

Key point: sequence matters. Learning monitoring before risk assessment produces an analyst who cannot explain their own alerts. 

The order below is the one I use when training people into the role. Each stage produces something you can talk about in an interview, which is the point of doing it in this sequence rather than picking whichever topic looked interesting. 

Order What to learn Why it comes here Evidence it produces 
Customer due diligence and beneficial ownership Everything else assumes you know who the customer is A complete mock customer file with the ownership traced 
 2Customer risk assessment and the risk factors The rating drives every later decision about that customer A written risk rationale a reviewer could mark 
 3Enhanced due diligence and source of funds and wealth This is what a higher rating actually obliges you to do An EDD memo on a higher-risk scenario 
 4Screening and alert disposition Volume work, and the fastest way to build discrimination Ten dispositions with written reasoning 
 5Transaction monitoring and investigation Only makes sense once you know what behaviour was expected One investigation carried end to end 
 6Reporting and the narrative The output all of the above feeds into One report narrative that survives review 

What I would ask an AML analyst candidate 

Key point: none of these has a right answer. All of them have wrong ones. 

These are the three questions I would put to someone applying for their first AML analyst role. None of them tests recall, and none has a single correct answer, which is deliberate. What I am listening for is whether the candidate has a method they can describe out loud, and whether they can say what would change their mind. Both are rare and both are teachable. 

Talk me through a risk rating you would defend two years from now 

A weak answer describes the scoring model. A strong answer describes a specific customer picture, names which of the five risk factors drove the rating, and says what evidence sits behind each one. What I am listening for is whether the reasoning would still stand up when the person who wrote it is no longer available to explain it, because that is the only test a file note ever really faces. 

You have asked for source of funds evidence three times, and the customer keeps deflecting. What now? 

A weak answer keeps asking. A strong answer recognises that repeated deflection is information in itself, and that Article 14 of the Executive Regulations prohibits establishing or continuing a relationship where due diligence cannot be applied and requires the firm to consider reporting to the Financial Intelligence Unit. Escalating rather than pursuing is the correct instinct. 


The best answers add a point about timing. Three requests over three days and three requests over three months are different situations, and the second one raises a question about why the relationship was allowed to continue that long. A candidate who notices that is thinking about the control environment rather than only about the customer, which is the step from analyst to senior analyst. 

What part of this job do you expect to find hardest? 

This one has no technical content, and it is the most revealing question I ask. A weak answer picks something flattering, usually the volume. A strong answer names the discomfort of deciding on incomplete information, or the pressure that arrives when a commercial relationship is at stake. Analysts who have thought about that in advance handle it when it happens. Analysts who have not tend to drift into clearing everything or escalating everything, which are the same failure in opposite directions. 

AML analyst readiness checklist 

Key point: six of eight is ready to apply. Fewer than five is not. 

  1. I can name the risk factor categories in Article 5 of the Executive Regulations and explain how they interact. 

  2. I can score a customer risk assessment and write a rationale that survives challenge. 

  1. I can explain what enhanced due diligence adds and choose measures proportionate to the specific risk. 

  1. I can clear a screening false positive and escalate a real one, with reasoning in both directions. 

  1. I can read an alert against the onboarding file rather than in isolation. 

  1. I can separate observed facts from inference in a written chronology. 

  1. I know the reporting obligation and can state it from the source instrument. 

  1. I have at least two work products built on public information that I can talk through. 

How this article was researched and verified 

Key point: every legal statement on this page is taken from the primary instrument, and everything else is named as professional judgement. 

Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025 were read directly in their published texts on 1 September 2026. Article 18 of the Decree-Law and Articles 5, 14, 21 and 22 of the Executive Regulations are described from those texts and nothing else.

 

No qualification or experience period is described as required for an analyst role, because no UAE federal instrument sets one for that role. The Executive Regulations describe only one individual: the Compliance Officer. 


No salary figure appears on this page. Pay is covered on the dedicated Dubai and UAE salary guide, where the data carries its own date and methodology. 


No monitoring threshold, rule parameter, alert volume or false positive rate appears anywhere in this article. Those are firm-specific, and publishing them would be both unreliable and unhelpful to detection. 


No system, vendor or screening provider is named or endorsed. 


The six skills, the learning sequence, the conversion backgrounds, the three interview questions and the readiness checklist are mine. They come from hiring, training, and reviewing analysts, and they reflect professional judgement rather than regulatory requirements.

Build the risk judgement an AML analyst is hired for 

Key point: the risk rating and the enhanced due diligence decision are the two things you will be tested on. 

Mastering Customer Risk Assessment and EDD covers the two capabilities at the centre of this role: scoring a customer against the risk factors and choosing due diligence proportionate to what you found. If you are coming from outside compliance, take Decoding KYC Requirements first so you have a solid customer picture before building risk judgement on top of it. When you are ready to specialise, Unlocking Essential Insights on Screening and Advanced Transaction Monitoring are the next two. Explore Courses to see the full path.

The asymmetry is the point. Moving out of a bank is easier than moving back in. Plan the return trip before you take the outbound one. 

Frequently asked questions about becoming an AML analyst in the UAE 

None are set by UAE law. The AML law and its Executive Regulations impose obligations on firms rather than entry requirements on their staff. Employers typically want a degree and treat a certification as a bonus. What decides the hire is evidence that you have made a judgement call and can defend it. 
Two routes. Move up from a KYC or onboarding role, which is the most common. Or come across from audit, accounting, banking operations, fraud, risk, legal or law enforcement, naming what transfers and closing the gap that does not with work products built on public information. 

The five risk factor categories in Cabinet Resolution No. 134 of 2025, Article 5, and how they interact. Everything else in the role, the due diligence scope, the monitoring intensity and the escalation threshold, follows from the rating those factors produce. 

It is the rating that determines how much due diligence a customer receives and how closely they are monitored. Cabinet Resolution No. 134 of 2025, Article 5 sets the factors that feed it. Sign-off varies by firm: analysts typically propose, a senior analyst or the Compliance Officer approves higher ratings, and the Executive Regulations require senior management approval before a relationship with a foreign politically exposed person is established or continued. 

No UAE instrument requires CAMS for an analyst role. Employers frequently list it as preferred, and it is a useful tie-breaker on an application, particularly for candidates without direct experience. It does not substitute for being able to make and defend a decision. 

More than most candidates expect. Every rating, every alert disposition and every escalation ends in a written record, and the quality of that record is what your work is judged on months later. Analysts who treat the write-up as an afterthought are the ones whose files come back from quality review. 

Banks, exchange houses, fintech and payments firms, and virtual asset service providers, plus every category of designated non-financial business: real estate, precious metals and stones, corporate service providers, law firms and accountancy practices. 

The shape of the day varies by firm and by specialisation, and it is covered in detail on the separate page describing what an AML analyst does all day. In summary: a queue of alerts or reviews, one or two cases that need real digging, and the writing that records both. 

It has two specific pressures: volume, and the discomfort of making a judgement on incomplete information. The volume is manageable with method. The judgement discomfort never entirely goes away, and the analysts who last are the ones who learned to document their reasoning rather than to seek certainty. 

A specialisation, in screening, transaction monitoring, enhanced due diligence or investigations, and then senior analyst where you begin reviewing other people's work. The specialisation guide compares the five and what each one leads to. 

Some operations roles offer hybrid arrangements. Fully remote is less common in compliance than in adjacent functions, because access to customer data is tightly controlled and because supervisors expect the compliance function to be present and reachable. 

Use public information only. A listed company, a public registry and open sources are enough to build a customer file, an ownership trace, a risk rationale and a set of screening dispositions. Never use a current employer's cases, and label everything as a training exercise. 

No. The analyst investigates and recommends. Cabinet Resolution No. 134 of 2025, Article 22 places the decision to notify the Financial Intelligence Unit, or to retain the matter with reasons stated, with the appointed Compliance Officer. What the analyst owns is the quality of the note that decision is made from. 

About the author

Pathik Shah is the founder of ProAML Training. He holds CAMS and is a Fellow Chartered Accountant (FCA) and a Certified Information Systems Auditor (CISA), and he holds the DISA and FAFD qualifications from the Institute of Chartered 
Accountants of India. He has spent more than 28 years in governance, risk and compliance, and advises regulated 
firms across the UAE and the GCC on AML and CFT programmes. He writes about the difference between knowing the 
rules and doing the work.

NIYEAHMA