Compliance

Can AML Checks Be Built Into a UAE Real Estate Deal Process?

SBShaffay Bajwa, Founder··7 min read
A brass-rimmed magnifying glass over a cream property folder with five tabs and a key.

Yes — AML checks can sit inside a UAE real estate CRM's deal workflow. A CRM can hold fields, documents and approval steps; it cannot do the legal judgement for you.

What AML checks should a UAE property broker consider?

In the UAE, real estate agents and brokers are expected to perform anti-money laundering checks as part of their client due diligence. These checks typically include identifying the client and beneficial owner, monitoring the business relationship, keeping records and escalating suspicious activity.

Where do AML checks sit in a deal?

AML checks should sit at the points where money moves or ownership changes: first contact, offer, reservation, SPA signing, payment and transfer. The check itself is a record: who the client is, who really owns or controls the buying entity, where the money comes from, and whether anything about the transaction is unusual.

Deal stageCheckWhat you record
First contactIdentificationPassport or Emirates ID copy, name as per ID, nationality, DOB
Offer or EOIBeneficial ownershipName and details of any person ultimately owning 25% or more of a buying company; for individuals, confirmation they are acting for themselves
Reservation / SPASource of fundsBank statement, salary certificate, sale proceeds letter, loan approval
Payment scheduleSource of wealthHow the client accumulated funds: business income, inheritance, investment
Transfer / handoverSuspicious activity reviewNotes on any unusual patterns, third-party payers, rapid resale intentions

Secondary market sale example

  1. Agent meets buyer at a viewing and records Emirates ID, passport and contact details in the CRM.
  2. Buyer makes an offer; before the broker forwards it, the CRM requires the agent to upload ID copies and a signed declaration.
  3. The brokerage's compliance officer reviews the file: name matches ID, no sanctions flags, plausible source of funds.
  4. The SPA is prepared; the CRM records the purchase price, payment method and bank details.
  5. Any payment from a third party triggers a query: why is a family member or company paying?
  6. At transfer, the file is locked and exported for the brokerage's records.

Off-plan purchase example

Off-plan deals are a known high-risk channel, so the same checks apply, but source-of-funds evidence is more important. For an off-plan reservation, the broker should verify the buyer before accepting the booking fee, record the developer and project details, and check whether the buyer has made multiple reservations across projects — a pattern that may need a look. WIYO's off-plan CRM can hold project, buyer and payment-plan data in one record; the AML fields sit alongside, not in a separate sheet.

What fields and documents should a CRM hold for AML?

A CRM used in a UAE brokerage should hold more than a name and phone number. The table below separates what you collect and what you upload.

FieldDocument
Full legal name as per Emirates ID/passportPassport copy, Emirates ID (front and back)
Nationality and date of birthVisa page or residency permit for non-GCC buyers
Residential addressRecent utility bill or tenancy contract
Source of funds for this transactionBank statement, salary certificate, sale-of-property letter
Source of wealth (overall)Company ownership documents, investment portfolio statement
Beneficial owner for corporate buyersMemorandum of association, share register, UBO declaration
Payment detailsTransfer receipt, cheque image, mortgage approval

The minimum set for a secondary market deal

  1. Client identification (Emirates ID or passport)
  2. Proof of address
  3. Source of funds for the specific purchase
  4. For a corporate buyer: ownership structure and UBO details
  5. A signed declaration that the client is acting on their own behalf or on behalf of a named third party

Building AML checkpoints into CRM workflows

The operational challenge is not collecting documents once; it is making sure every deal passes the same checks without relying on memory. A CRM can enforce checkpoints:

  1. Add mandatory fields to each deal stage (e.g., cannot move from "Offer" to "Reserved" without ID copy).
  2. Attach document tags so the reviewer sees "AML: verified" at a glance.
  3. Assign a check to a named role, not just the agent — the agent collects, the office manager or compliance officer approves.
  4. Use stage gates that block the next step until the earlier check is done. This mirrors the logic in Where Dubai Property Deals Die: a deal should not move to the next stage with missing mandatory information.
  5. Keep an audit log: who uploaded what, when, and who approved it. This log is your evidence for supervisors.
  6. Set reminders for periodic reviews on long-running off-plan deals, where a buyer's situation can change between reservation and handover.

Example checkpoint for an off-plan reservation

Before an off-plan reservation can be marked "Reserved", the CRM requires: buyer ID uploaded, source-of-funds document attached, project and unit selected, payment plan noted and broker declaration signed. Only after a designated reviewer approves the AML check can the status change. This kind of gate works in any configurable CRM, and the same logic applies to WIYO's deal pipeline.

Why a CRM is the right place — and where it is not enough

A CRM helps because AML evidence lives next to the deal, not in a filing cabinet or an agent's personal email. It makes checks consistent across 5 or 50 agents, and it produces an exportable record when regulators ask. What a CRM cannot do is make the legal judgement: it will not decide whether a source of funds is suspicious, and it will not file a suspicious transaction report for you. People do that. Your RERA-awareness should come from policy and training, supported by the CRM's records. See our RERA-aware CRM guide for the broader workflow.

This guide is published by WIYO, a UAE real estate CRM. We recommend a CRM as the system of record for AML evidence, but we do not claim that using any software, including WIYO, makes a brokerage compliant. Compliance is your responsibility under UAE law.

Questions to ask your CRM vendor

When you evaluate a CRM for a UAE brokerage, ask these questions before you sign:

  1. Can I add mandatory fields to each deal stage?
  2. Can I attach documents with tags like "ID", "source of funds", "UBO"?
  3. Can I restrict AML fields to compliance or management roles?
  4. Does the audit log show who edited what and when, and can it be exported?
  5. Can I record third-party payers and link them to the file?
  6. Does the system support retention periods so records are not accidentally deleted?
  7. Can I build stage gates that block progress until a check is approved?
  8. For open API buyers: can I connect identity verification or sanctions screening later? See our Open API buyer's guide.

A vendor that says "we are fully AML compliant" should be able to show exactly which of these capabilities exist and how they map to your procedures. If they cannot, you are buying a database, not a control.

Who this is for

This is for brokerage owners, operations managers and compliance officers at UAE brokerages handling secondary and off-plan transactions. If you are a solo agent doing a handful of deals a year, a well-organised spreadsheet can work, but a CRM makes your files auditable. If you run a team of five or more, the CRM checkpoint approach is the only practical way to be consistent.

Frequently asked questions

Is AML compliance the broker's responsibility or the CRM's?

The broker's. The CRM is a tool to record, remind and enforce the process. The obligation rests with the brokerage and the individuals involved, not with software. A CRM can help you evidence what you did, but the responsibility remains with your team.

Do I need to check every buyer and tenant?

Yes, for any transaction where you act as a broker, you should perform at least basic identity checks. The level of checks may vary with risk: a straightforward cash purchase by a UAE national with a clear salary history is different from an offshore company buying multiple off-plan units. But identifying the client and beneficial owner early is good practice.

What is the threshold for suspicious transaction reporting?

There is no fixed monetary threshold. The test is suspicion: if a transaction appears unusual, involves third parties without clear reason, or the client is unwilling to provide information, you should escalate it internally and consider filing a report through official channels.

Can a CRM automatically file a suspicious transaction report?

No. Filing is done through official reporting channels, not inside a CRM. A CRM can hold the evidence, generate a summary and remind you to escalate, but the report itself must be made by an authorised person in your brokerage. Do not buy a CRM on a claim of automatic STR filing.

What is the difference between source of funds and source of wealth?

Source of funds answers "where did the money for this specific purchase come from?" — a bank statement, a salary, a loan, a sale of another property. Source of wealth answers "how did the client accumulate their overall assets?" — a business, inheritance, investments. Both are required under CDD, and they are not interchangeable.

How long do I need to keep AML records?

Record-keeping periods are set by regulation. Check the current requirement for your jurisdiction and transaction type. Your CRM should allow you to configure retention periods and prevent accidental deletion.

Relevant WIYO solution:Real Estate CRM in Dubai
SB

Written by

Shaffay Bajwa

Founder & CTO at WIYO · Software engineer, 5 years building in the UAE real estate market.

Want to see WIYO live?

30-minute personalised demo with live data from your existing portals.

Book a Live Demo