My firm is classified as a DNFBP — what does the AML risk assessment actually need to cover?
My firm is classified as a DNFBP — what does the AML risk assessment actually need to cover?
If your business falls under the DNFBP category — accounting and audit firms, real estate brokers, dealers in precious metals and stones — Federal Decree-Law No. 10 of 2025 (Article 19) requires you to carry out a risk assessment at the level of the business itself, not only customer-by-customer. Cabinet Resolution No. 134 of 2025 spells out that this assessment must be documented, approved by senior management, and made available to the supervisory authority on request.
In practice, the assessment needs to cover four dimensions: customer risk (client types, ownership structures, the nature of what they transact), geographic risk (which countries the business deals with, especially those flagged as high-risk on the official updated lists), product or service risk (real estate transactions, for instance, carry inherently higher risk under the national risk assessment than routine bookkeeping work), and delivery-channel risk (a client onboarded in person versus one handled entirely remotely). The key point is that this is not a static document — the law speaks of "continuous" updating, meaning the assessment should be revisited whenever your activities, client base, or new sector-risk information change. RASEEKH helps DNFBP clients build a documented, coherent risk assessment that can stand up to a supervisory review.