Skip to main content
KreupAI Logo
RESOURCE GUIDEApplies to: GCC-wideDaftar
KB-062

Client Data Residency for Gulf Accounting Firms: What PDPL Means for Your Cloud Choice

A practical evergreen guide to GCC accounting client data residency, including requirements, data, workflows, evidence, controls, implementation risks and system configuration.

Author:Bosco Sabu John
10 min read

Client Data Residency for Gulf Accounting Firms: What PDPL Means for Your Cloud Choice

This guide explains GCC accounting client data residency, the operational records organisations should maintain, the controls a business system should enforce, and the evidence needed for review. Requirements can change by entity, activity, jurisdiction and effective date. Use the current authoritative material from PDPL, map each obligation to an owner and source, and obtain specialist advice before treating the guide as a legal, regulatory, tax, certification or contractual determination.

This is for the partner or compliance officer in a firm that books and files for dozens of UAE client entities. The obligation you carry is your own, not your clients'. What an inspector asks for first is not a policy but the due diligence pack on a named engagement.

One structural point first. Federal Decree-Law No. (10) of 2025 came into force on 14 October 2025, and Article 41(1) repeals Federal Decree-Law No. (20) of 2018 outright. Instruments made under the old law survive under Article 41(3) only where they do not conflict, and only until superseded. Cabinet Resolution No. (134) of 2025 is the new executive regulation.

What actually makes an accounting practice a DNFBP

Two answers exist, and the gap between them is where firms get confused. The supervisory answer is categorical. The Ministry of Economy and Tourism supervises four DNFBP sectors: real estate agents and brokers, dealers in precious metals and stones, independent accountants and auditors, and trust and corporate service providers. It describes the accounting category as firms that "provide professional services and assurance to third parties regarding financial and/or business matters".

The statutory answer is transactional. Article 3(4) of Cabinet Resolution No. (134) of 2025 catches lawyers, notaries and independent accountants when they prepare or execute financial transactions concerning: buying and selling real estate; managing customer funds; managing bank or securities accounts; organising contributions for the establishment of companies; and establishing or operating legal persons or legal arrangements.

Firms read the second list, conclude that bookkeeping and audit sit outside it, and stop. That fails twice. The Ministry supervises and registers the sector as a category, so a scope argument does not remove you from its inspection population. And a bureau usually touches the list without naming it: paying a client's suppliers from a client account is managing customer funds. Put the scoping note on file, dated.

Two registrations, not one

Per the Ministry's registration guidance, a DNFBP first registers on the Ministry's supervisory system (the SACM environment) to obtain a username, then registers separately on goAML, the FIU's reporting platform. Access uses a one-time code from Google Authenticator. Required documents are an authorisation letter, passport, residence visa and Emirates ID copies for the registering individual, and a copy of the trade licence.

Three consequences follow. The authenticator binds to one device held by one person, so a departure or an un-migrated handset stops the firm filing, and the duty to report without delay does not pause while re-enrolment runs. Registration on the Ministry's system alone does not let you file. And both records must carry the same entity name and licence number as the trade licence; a mismatch is a rejection cause.

[NEEDS SOURCE: the deadline or grace period for a newly licensed accounting or audit firm to complete Ministry system and goAML registration; and the goAML production portal URL and registration field set. The FIU's goAML web report submission guide returned HTTP 403 to automated retrieval.]

The compliance officer and the business risk assessment

Article 21(3) of Cabinet Resolution No. (134) of 2025 requires a compliance officer at management level, and Article 22 sets the duties: monitoring transactions, reviewing suspicious data, assessing internal systems, developing training, and cooperating with the authorities. The Ministry's DNFBP guidelines go further: at section 7.1.1 the appointment "must receive the prior written approval of the relevant Supervisory Authority", and section 7.1.3 requires familiarity with typologies and red flags, experience in compliance, audit, legal or risk roles, and independence.

The failure point is the interim. A firm whose officer resigns appoints internally and carries on, but prior written approval means the replacement is not yet the approved officer, and the file shows a gap.

Article 5(1) requires the firm to assess its crime risks proportionately to the nature and size of its business, across customer, geographic, product and service, transaction and delivery channel risk. Article 19(1)(a) frames it as continuing: identify, understand, manage, assess, document and continuously update. The Ministry's guidelines require the assessment to incorporate the National Risk Assessment and the relevant sectoral risk assessment, and to document how the firm's controls address each risk.

An assessment that lists risks without mapping each to a control is the half that fails inspection. For a bureau, the factors that genuinely differentiate a portfolio are: beneficial owners not resident in the UAE; entities with no employees and no premises; bank accounts outside the UAE; a declared activity that does not match the transactions in the ledger you maintain; and clients arriving through a single intermediary. Forty clients from one formation agent is a concentration risk, and the agent's due diligence is not yours.

Customer due diligence on a client entity

The subject is the entity, the natural persons behind it, and the person acting for it. Article 10(1)(a) requires identification of the natural person who ultimately owns a controlling interest or shares of 25 per cent or more, falling back to the person with ultimate effective control where nobody meets the threshold.

Enhanced due diligence under Article 5(2)(c) means additional information on customer and beneficial owner, more regular CDD updates, source of funds, increased monitoring, and senior management approval. Article 16(1)(a) adds, for foreign politically exposed persons, systems to determine PEP status and approval before the relationship begins. Article 8 covers ongoing monitoring.

Monitoring in a bureau is unlike a bank's. You are not screening payments in real time; you are posting them in arrears, so your signal is the ledger: round-sum transfers to related entities, a supplier with no contract, revenue with no matching operational cost, director loans that never settle. Write the policy in those terms, because "we monitor on an ongoing basis" evidences nothing.

[NEEDS SOURCE: whether the AED 55,000 occasional-transaction and AED 3,500 wire transfer CDD thresholds in Article 7 of Cabinet Resolution No. (134) of 2025 apply to DNFBPs as well as financial institutions]

The report types, and which one you actually file

Reports go to the UAE Financial Intelligence Unit through goAML. Article 18(1) requires notification "without delay and directly", by detailed report, through the system designated by the Unit, without invoking confidentiality.

ReportTriggerWhenWho files
STR, Suspicious Transaction ReportSuspicion that an executed transaction relates to money laundering, fraud or terrorist financingWithout delayAll reporting entities
SAR, Suspicious Activity ReportSuspicion about an activity or attempted transaction, nothing completedWithout delayAll reporting entities
AIF / AIFT, Additional Information File without / with transactionsFIU asks for more on an STR or SAR you filedPer FIU requestThe entity that filed
RFI / RFIT, Request for Information without / with transactionsFIU seeks information on someone else's reportPer FIU requestAny entity asked
HRC / HRCA, High Risk Country transaction / activity reportTransaction or activity involving a country on the NAMLCFTC high-risk listThree working days before executionAll reporting entities
FFR, Funds Freeze ReportConfirmed match to a terrorist list, freezing appliedFive daysFIs, DNFBPs, VASPs
PNMR, Partial Name Match ReportSuspension applied on a partial match to a terrorist listFive daysFIs, DNFBPs, VASPs
DPMSRCash of AED 55,000 or more with an individual, any amount with an entity[NEEDS SOURCE]Precious metals and stones dealers
REAR, Real Estate Activity ReportFreehold purchase or sale with cash of AED 55,000 or more, or virtual assets[NEEDS SOURCE]Real estate brokers and agents

Source: UAE FIU, goAML Report Types v1.2, 29 April 2024.

Two distinctions matter most. The STR and SAR split turns on whether a transaction happened, not on severity: a prospect who withdraws after being asked about source of funds has transacted nothing, so that is a SAR, and declining to onboard does not discharge the duty. And HRC and HRCA carry the only forward-looking deadline, which a bureau posting in arrears structurally cannot meet.

Separately, the Ministry's targeted financial sanctions obligations require screening customers and beneficial owners against the UN Security Council and local terrorist lists, freezing "without delay and without prior notice", and registration in the automatic sanctions reporting system.

Tipping off, and how it constrains the client conversation

The Ministry's guidelines state that under no circumstances may a DNFBP, its managers or its employees inform a customer, a business relationship representative, or any third party, directly or indirectly, of the intention to report or that a report has been made, nor disclose anything contained in it. Article 29(1) of the decree-law makes it criminal: imprisonment and a fine of not less than AED 50,000, or either penalty.

In a firm where the same people keep the books and speak to the client daily, that means three things. You cannot explain a delay by reference to the report, because "we are waiting on a compliance matter" is closer to disclosure than it sounds. You cannot resign in terms that signal the reason: disengagement is permitted, a letter reciting the suspicious transactions is not. And you cannot put pointed questions about the transaction after filing, because the sequence signals the report as clearly as saying so. Ask before you conclude.

Handover to a successor accountant is the sharpest edge, because courtesy expects an explanation and the prohibition covers third parties. Article 18(2)'s narrow exemption is drawn around legal privilege, not ordinary accounting work.

A client onboarding AML procedure

Run this per client entity, before the first posting, keeping every artefact in the engagement file rather than a mailbox.

  1. Scope the engagement in writing. Record which Article 3(4) activities it touches.
  2. Identify the legal person. Trade licence, memorandum and articles, register extract, registered address, licensed activity. Check it matches what the client says it does.
  3. Identify the beneficial owners. Work the chain to natural persons at 25 per cent or more. Where nobody meets the threshold, identify the person with ultimate effective control and record why.
  4. Identify the person acting. Passport or Emirates ID, plus the authority relied on: board resolution, power of attorney or signatory listing. A signatory who is neither owner nor director is a question, not a formality.
  5. Screen. Entity, owners, directors and signatories against the UN Consolidated List and the UAE Local Terrorist List, and for PEP status. Retain the output with its date, not just the conclusion.
  6. Rate the risk and apply enhanced due diligence where triggered. Record the reasoning and the review cycle, and date the senior management approval before the relationship begins.
  7. Resolve or decline. Do not onboard on the basis that ownership documents will follow. If the prospect withdraws when asked, consider a SAR.
  8. Set the monitoring condition and file the pack. Record what an unusual pattern would look like here, then file documents, screening evidence, rating, approvals, and who did what and when.

Records, and what an inspection looks for

Article 25 requires records for not less than five years from completion of the transaction or termination of the business relationship, covering identification documents, CDD records, account files, correspondence and reports. Article 19(1)(f) requires them immediately available on request, and "immediately" is doing real work: a firm that can produce a CDD pack in a week has records, but not available ones. The period runs from termination, so a client disengaged last year is in scope for four more.

The Ministry publishes its enforcement outcomes, and the recurring findings beat any checklist. An announcement dated 10 July 2022, covering fines exceeding AED 3 million on eight DNFBP companies totalling AED 3,550,000 across 69 violations in a population including auditors, identified: no internal policies and controls; suspicious business relationships without safeguards; inadequate customer due diligence; no ongoing monitoring; no documented reporting procedures; and insufficient enhanced due diligence for PEPs.

Read that as a list of missing documents: inspections test whether the artefact exists, is dated and is signed.

Article 17(1) lets a supervisory authority impose a warning, an administrative fine of not less than AED 10,000 and not more than AED 5,000,000 for each violation, prohibition from the sector, suspension of directors, and revocation of the licence. Article 28 makes failure to report criminal, carrying imprisonment and a fine of AED 100,000 to AED 1,000,000, or either. The per-violation basis is what turns housekeeping into a material number: violations count per client file.

[NEEDS SOURCE: the fine amounts per violation in the schedule to Cabinet Resolution No. (71) of 2024, and whether it repeals Cabinet Decision No. (16) of 2021. The schedule tables did not render on the UAE Legislation portal and the Ministry PDF timed out.]

Where teams get this wrong

Treating registration as the programme. It is the smallest obligation and the only one with a confirmation email. Registering and stopping produces supervised status with no controls, which is worse than not registering, because it makes you visible.

Running CDD once. Ownership changes, licences lapse, an owner becomes a PEP. A file accurate on the day it opened fails ongoing monitoring on its own terms.

Confusing the client's obligations with the firm's. Helping clients register on goAML evidences nothing in your own file.

Letting the compliance officer be the engagement partner. It defeats independence. Where you cannot separate them, document the conflict and the mitigation.

What to automate, and what not to

Automate the register and the evidence trail. Which entities you act for, when CDD was last refreshed, when screening last ran and what it returned, which approvals exist and who gave them, and which files are missing a document: all structured, dated, and exactly what an inspector asks for. A system that raises a CDD refresh at month nine of a twelve-month cycle, and refuses to let an engagement go live without a complete pack, removes most of the Ministry's own enforcement findings.

Do not automate the suspicion decision. Whether a ledger pattern is commercial or concerning is a judgement made with context, and a rules engine flagging every round-sum related-party transfer produces a queue nobody reads, which is worse than no queue because it looks like monitoring. Nor the client communication: tipping off makes the wording of any message about a delayed engagement a legal decision, not a template.

Where a system helps

The work that scales badly is holding a current, evidenced AML position on every client entity at once: beneficial ownership as it stands today, screening run this quarter rather than at onboarding, and a pack that can be produced on request. That is the workflow Daftar is built around: entity-level records, per-engagement checklists with owners and dates, and evidence held against the engagement rather than in an inbox. Daftar is not connected to goAML and does not file on your behalf.

FAQ

Does a bookkeeping-only practice have to register on goAML? The Ministry supervises independent accountants and auditors as one of four DNFBP sectors and requires registration. The narrower statutory trigger in Article 3(4) turns on activities such as managing customer funds, and most bureaux touch at least one.

We registered on the Ministry's system. Are we registered on goAML? No. Two systems, two registrations. Only the goAML registration lets you file a report.

A client asked why we are slow to release accounts after we filed an STR. What can we say? Nothing that lets them infer a report was made or intended. Article 29(1) covers indirect disclosure and carries imprisonment and a fine of not less than AED 50,000, or either.

Related reading: [ASSIGN: title of KB-057] (KB-057).

Sources