What This Blog Covers
This guide explains what is tipping off in AML, and what it looks like when it happens inside a business. You will find the simple meaning of tipping off, the two things you must keep quiet after a suspicious transaction report, when the duty starts, and who it applies to.
We cover real tipping off examples, including the accidental ones most teams never think about, what is not tipping off, and the penalties in the UAE.
We then get practical: how to hold a transaction without alerting the customer, how to exit a customer safely, who inside your business is allowed to know, what small firms should do when one person handles both sales and compliance, and what to do if someone has already slipped. There is also a short self-check and a ready-to-use checklist at the end.
What Is Tipping Off in AML?
Tipping off in AML means letting a customer, or anyone else outside a small need-to-know group, find out that a suspicious transaction report has been filed about them, is being prepared, or that their activity is being reviewed. It counts whether you say it directly, hint at it, or let them work it out. It is a criminal offence, not an internal policy matter.
Most people assume tipping off is something a corrupt employee does on purpose. In practice, it is usually an accident. A relationship manager who suddenly stops returning calls. A message that says a little too much. A sentence spoken to be helpful. That is the part worth paying attention to.
Tipping Off Meaning in Simple Words
Outside compliance, the tipping off meaning is simple: you warn someone that something is coming so they can get ready for it. A friend tells you the boss is in a bad mood before your meeting. That is a tip off.
Now apply the same idea to financial crime. If a customer is warned that they are being reported or looked at, they can move their money, close their accounts, shred documents, or disappear. Same behaviour, very different consequences. You will see the term written as tipping off, tipping-off, tipped off, or in policy documents as the “no tipping off” rule. They all mean the same thing.
What Tipping Off Means in AML and Banking
When a business spots something that does not add up, it must file a suspicious transaction report with the UAE Financial Intelligence Unit. That duty comes with a second duty attached: keep it confidential.
The tipping off meaning in banking is that breaking that confidentiality, in any direction and by any method, is an offence. It is not limited to telling the customer. Telling their business partner, their spouse, their lawyer, a friend at another bank, or posting something that lets people join the dots all count. It also does not matter whether you meant to do it.
The Two Things You Have to Keep Quiet
This is the part most teams get half right. There are two separate secrets, not one:
- What is in the report — what was suspected, what data was shared, what the concern was.
- That a report exists at all — that anything was filed, is being drafted, or is under internal review.
Staff are usually careful with the first and careless with the second. “I can’t discuss the details, but you should probably speak to a lawyer” protects the contents and gives away the existence. That is still tipping off.
Why the No Tipping Off Rule Exists
The whole point of reporting is to let the authorities look at something quietly. A customer who knows they are being watched will act. Money moves offshore, companies get dissolved, records vanish, and by the time anyone can act, there is nothing left to recover.
That is why the rule is written so broadly, and why it applies to everyone in the business rather than just the compliance officer.
When Does Tipping Off Actually Happen?
Here is the misunderstanding that causes most real breaches: people think the duty starts when they click submit. It does not. It starts much earlier and it never really ends.
Before anything is filed. Suspicion has formed. Someone is reviewing a transaction. Nothing has gone anywhere yet, and the duty is already live. Talking loosely at this stage is the most common failure of all, because staff genuinely believe there is nothing to keep quiet yet.
While the report is being prepared. Colleagues are asking questions, files are being pulled, and the customer starts noticing that something has changed.
After the report has gone in. The obligation continues. There is no expiry date, no thirty-day rule, and it does not lapse when the customer leaves.
When the authorities come back with questions. Follow-up requests are a sharper risk, because the customer is often still active, still calling, and still expecting normal service.
Whenever a transaction is being held. The delay itself is the leak. How you explain that delay is the single most important conversation in this entire topic, and we come back to it below.
Know What a Tipping Off Mistake Could Cost You?
Who Has to Follow the No Tipping Off Rule?
If your business has AML/CFT compliance obligations in the UAE, this rule applies to you. Size makes no difference.
Banks, Exchange Houses, Payment Firms and Fintechs
The obvious group. Large teams, many customer touchpoints, and usually the most mature controls, which is exactly why breaches here tend to come from the front line rather than compliance.
Real Estate, Gold, Corporate Services, Accountants and Lawyers
DNFBPs carry the same duty with far fewer resources. A real estate agent explaining why a transfer is stuck, or a dealer in precious metals and stones suddenly asking a walk-in buyer for paperwork, is in the samen as a bank teller. So is a company service provider putting an incorporation on hold.
Crypto and Virtual Asset Businesses
Virtual asset firms face a specific version of the problem: support tickets. A frozen withdrawal generates an angry message within minutes, and whoever answers that ticket is one careless sentence away from an offence. VASPs in the UAE need scripted responses more than most.
It Is Not Just the Compliance Officer’s Job
The rule reaches directors, managers and employees alike. The receptionist who mentions that “the compliance team have been asking about your file” has committed the same offence as anyone else. This is why the no tipping off rule belongs in induction training, not only in the compliance manual.
Tipping Off Examples: What It Looks Like in Real Life
Abstract rules do not change behaviour. Specific examples do. Here is what tipping off in AML looks like across the range, from obvious to almost invisible.
The Obvious Ones
- Telling the customer directly that a report has been filed about them.
- Telling their spouse, partner, accountant or broker.
- Mentioning it to a friend who works at another firm.
- Showing the customer the internal case notes or the report itself.
The Hints
- “If I were you, I would move that money this week.”
- “Maybe use a different bank for this one.”
- “I can’t explain but be careful about the next few months.”
- Encouraging a customer to withdraw an application, restructure a payment, or take their business somewhere else.
None of these mention a report. All of them are tipping off, because the customer walks away knowing exactly what they needed to know.
The Accidents
This is where most breaches live.
A sudden change in behaviour. A relationship that was warm for three years goes cold overnight. Calls stop being returned. Emails become oddly formal. A customer who deals with people for a living reads that instantly.
A burst of questions out of nowhere. Asking for six new documents after two years of silence tells the customer something changed, even if every question is legitimate. Routine ongoing monitoring is fine. Routine monitoring that arrives the week after a report is filed looks like exactly what it is.
Digital leaks. A case notes visible on a shared screen at the counter. An internal email forwarded without checking the thread below. A customer portal that shows a status the customer was never meant to see. A chat reply typed quickly at the end of a long day.
Third parties and outsourced staff. The outsourced bookkeeper, the IT vendor with database access, the consultant who mentions it in a meeting with the client in the room.
Talking shop in the wrong place. Lifts, open-plan offices, coffee shops, taxis, family WhatsApp groups. Dubai and Abu Dhabi are small business communities. Assume you are overheard.
What It Looks Like in Different Businesses
| Business | Moment of risk | What usually goes wrong |
|---|---|---|
| Bank or exchange house | A held wire or blocked card | Branch staff explain the “real” reason to calm the customer down. |
| Real estate | A stalled transfer or delayed registration | The agent tells the buyer that compliance is holding it. |
| Gold and jewellery | A walk-in cash purchase suddenly needs documents | The salesperson apologises and explains too much. |
| Corporate services | An incorporation or renewal is put on hold | The client is told the file was “flagged.” |
| Crypto and virtual assets | A frozen withdrawal | A support agent copies internal notes into the ticket reply. |
What Is Not Tipping Off
Just as damaging as saying too much is a team so frightened of the rule that it freezes. Over-correcting is itself a red flag to an observant customer. So here is what you are still allowed to do.
Escalating internally. Telling your compliance officer, your MLRO or your line manager is the process working correctly. It is not a breach, and staff should never hesitate over it.
Sharing within your group. Where a business is part of a wider financial group, information can be shared with branches and subsidiaries for AML purposes. Cabinet Resolution No. 134 of 2025 requires group programmes to include confidentiality and non-tipping-off safeguards around that sharing, so the sharing must be controlled, but it is permitted.
Answering your regulator or supervisor. Responding to your supervisory authority is not a disclosure problem.
Asking normal due diligence questions. Standard KYC refreshes, document renewals and customer due diligence checks are part of the job. The nuance is in delivery, not in the question itself. A refresh that follows your usual cycle looks routine. The same refresh, delivered urgently and out of sequence, does not.
Talking a client out of something unlawful. Where a lawyer, notary, other independent legal professional or independent statutory auditor tries to dissuade a client from committing an unlawful act, that is expressly not treated as disclosure under Article 19 of Cabinet Resolution No. 134 of 2025.
Is Your Policy Clear Enough to Actually Help Staff?
What Happens If You Tip Someone Off?
Tipping off in the UAE is a criminal offence under Federal Decree-Law No. 10 of 2025, not an administrative slip. Under Article 29, warning someone, or revealing information about transactions under review or about inquiries being made, is punishable by imprisonment and a fine of not less than AED 50,000, or by either of those penalties.
Two details are worth noticing, because most articles miss them.
The Fine Has a Floor, not a Ceiling
The law sets a minimum of AED 50,000. It does not state a maximum for this offence. Anyone assuming AED 50,000 is the worst case is reading it backwards.
It Gets Considerably Worse If Money Is Lost
Where the disclosure means the proceeds cannot be seized, or they are destroyed or lose value, the penalty rises to imprisonment of not less than one year plus a fine equal to the value of the proceeds, with a minimum of AED 100,000. In other words, the more effective your warning was, the heavier the consequence.
The Business Is Exposed Separately
An employee being prosecuted does not discharge the company. Under Article 27, a legal person whose representatives, directors or agents commit this offence on its behalf faces a fine of not less than AED 200,000 and up to AED 10,000,000.
The Costs That Are Not Fines
| Who is exposed | What it looks like |
|---|---|
| The individual | Criminal record, imprisonment, dismissal, career damage |
| The business | Criminal fine, supervisory findings, forced remediation |
| The licence | Conditions, restrictions, or worse, depending on the supervisor |
| The relationship with your regulator | A failed inspection and years of closer attention |
| Reputation | Counterparties and banks quietly reassessing you |
For most firms, the fine is not the expensive part.
How to Delay a Transaction Without Tipping Off
This is the question every practical person came for. A transaction needs to be held while a report is with the FIU. The customer is on the phone. What do you say?
Why Delay Is Usually Safer Than Refusing
An abrupt rejection, or terminating the relationship on the spot, is itself a signal. Holding is quieter and buys time for the FIU to respond or ask for more. Slowing something down attracts far less attention than stopping it dead.
Reasons You Can Safely Give
The rule of thumb is straightforward: say something that is true, boring, and internal. All of these are genuinely true while a review is underway.
- Internal review and approval. The transaction is going through the standard internal approval process. Honest, unremarkable, and true.
- Verification or documents outstanding. Additional verification is being completed, or a document needs to be resubmitted or updated.
- Processing or system delays. Operational turnaround times, system processing, batch cycles.
- Commercial or contractual reasons. Terms need review, limits need reconfirming, pricing needs re-approval.
Two cautions. First, whatever reason you give must be genuinely true, not a story invented to mislead. Second, it has to be consistent. If three colleagues give three different reasons, the customer stops believing all of them and starts asking why.
Things You Should Never Say
- “Compliance flagged your account.”
- “We had to report this.”
- “There’s an investigation.”
- “I’m not allowed to tell you why.”
- “This is a regulatory matter.”
- “I’d rather not put this in writing.”
The last two feel safe. They are not. Both tell the customer there is something worth hiding.
When the Customer Keeps Pushing
Move the conversation to someone trained for it. Agree the wording internally before anyone has the conversation, so every person the customer might reach says the same thing. Never improvise under pressure and never let a frustrated staff member “explain properly” to keep a client happy.
How Long Can You Hold?
Long enough to hear back, and no longer than you can justify. Follow your own procedures and your supervisor’s expectations. If the hold becomes impossible to sustain, escalate it rather than letting a frontline employee decide alone.
How to Exit a Customer Without Tipping Off
Closing a relationship is where a surprising number of breaches happen, because someone always has to be told something.
Timing matters more than wording. Closing an account the week after filing draws a straight line the customer can follow. Where you can, let time pass and let the exit follow a natural point, such as a renewal date or contract expiry.
Use commercial grounds properly. Non-renewal at expiry, contractual notice, a change in risk appetite, or a portfolio review are all legitimate and unremarkable.
Watch what goes in writing. Closure letters and termination emails are documents the customer keeps and may show to others. Keep them short, factual and free of anything that hints at a reason beyond commercial.
Document the real reasoning internally. Your file should show exactly why the decision was made, who approved it, and when. The external communication should not. That split is the whole discipline.
Let's Put Your Compliance Framework to the Test
Who Is Allowed to Know?
The principle is simple: only people who need the information to do their job. The hard part is applying it to real roles, including the awkward ones nobody puts in a policy.
| Role | Should they know a report exists? | Should they know the contents? | What they can be told instead |
|---|---|---|---|
| Front desk / reception | No | No | Nothing; route queries to a named person |
| Relationship manager / sales | Usually not | No | The agreed holding line only |
| Operations / processing | Only if they must action a hold | No | Process instructions without reasons |
| Compliance officer / MLRO | Yes | Yes | — |
| Senior management | Where necessary for oversight | Summary only | — |
| Board | Aggregated reporting only | No | Volumes and trends, not names |
| Internal audit | For control testing | Where in scope | — |
| IT / system administrators | Usually not, but they often can see it | No | Access must be controlled and logged |
| Outsourced or offshore teams | Only where contractually bound and necessary | No | Task-level instructions |
| External auditor | Where in scope | Where in scope | — |
| Group parent or head office | Yes, within group programme safeguards | Yes, within safeguards | — |
| Customer’s own lawyer, agent or broker | Never | Never | Nothing |
The Awkward Cases
Your IT administrator can read everything. Access controls, permission tiers and audit logs are the answer, not trust.
Work is outsourced. Contractual confidentiality clauses are the minimum. Before relying on any third party, check their controls, not just their contract.
A director is also connected to the customer. More common in smaller firms than anyone admits. Recuse them, document the recusal, and route the case elsewhere.
Tipping Off Risk in Small Businesses and One-Person Compliance Teams
Most advice on this topic assumes a compliance department separated from a customer-facing team. In a five-person brokerage or a two-person gold trading business, the compliance officer is the person at the counter. Telling that person to “keep the teams apart” is useless.
Here is what actually works.
Do not change your pattern. If you normally call a client every Thursday, keep calling every Thursday. Consistency of behaviour is the entire defence when you cannot separate roles. A sudden change in your own manner is the leak.
Prepare your line in advance. Decide what you will say about a delay before you need to say it and write it down. Under pressure, unprepared people over-explain.
Protect files physically. Password-protected folders, a locked drawer, a screen that locks when you walk away. In a small office, a visible screen is a genuine risk.
Keep one channel. All case discussion in one controlled place. Not personal WhatsApp, not a shared inbox everyone can read.
Know when to bring in help. If you are carrying the whole function alone, an outside review of your controls is often cheaper than the consequences of a slip. That is a legitimate option, not a failure.
Lawyers, Auditors and Accountants: Where It Works a Bit Differently
Lawyers, notaries, other legal professionals and independent legal auditors have a narrow exemption from reporting where information was obtained in circumstances covered by professional secrecy, such as assessing a client’s legal position or representing them in proceedings.
The danger is assuming the exemption covers everything the firm does. It does not. Work such as handling client money, buying or selling property, managing accounts, or forming and managing companies sits outside it, and carries the full reporting duty and the full confidentiality duty with it.
The practical fix is two clean workflows, so exempt and non-exempt work never get confused. Lawyers and legal professionals and accountants and auditors in the UAE should be able to point at a documented process showing which is which.
Building the No Tipping Off Rule into Your Policies and Systems
Training alone will not hold. Controls will.
Say it in the policy, specifically. Not “staff must not tip off”, but the situations in your business where it could happen, who may be told, through which channel, the approved holding language, and the consequences for staff. Generic wording gives inspectors nothing to test.
Restrict who can see case files. Permission tiers and audit trails on your case management system. If everyone can read every file, you do not have a need-to-know rule, you have a hope. Good AML software handles this natively; poor software makes it manual.
Keep flags off customer-facing screens. Check what your customer portal, statements and automated emails display. This catches more firms than any human error does.
Control the channels. Name the approved place for case discussion and ban the rest. Personal messaging apps are the usual culprit.
Sort out storage and retention. Where reports and supporting files live, who can retrieve them, and for how long. This should already sit inside your internal control framework, and you AML internal audit should be testing it rather than assuming it.
Not Sure Where Your Compliance Stands?
Training Your Team So Nobody Slips
Most firms train compliance staff thoroughly and everyone else briefly. That is backwards. Compliance staff rarely tip off. The people who do are the ones holding the customer relationship, and they usually get the shortest session.
Cover four things and cover them properly:
- The two things that stay quiet — the report and the fact of it.
- The approved holding language, practised out loud rather than read from a slide.
- What to do when a customer pushes back — escalate, do not improvise.
- Who to escalate to, immediately, by name.
Role-play beats slide every time. Run three or four realistic scenarios from your own business: the angry caller, the friendly long-standing client who asks casually, the colleague who asks what is going on with an account. Then keep the evidence. Attendance records, assessment results and refresh dates are exactly what a supervisor asks to see and structured AML training gives you both the coverage and the proof.
What to Do If Tipping Off Has Already Happened
If you are reading this because something has already been said, work through it calmly and in order. Do not try to bury it.
Stop. No further discussion with the customer by anyone. Escalate immediately.
Write down what happened. Who said what, to whom, when, and through which channel. Write it now, while memories are fresh, and write it honestly.
Tell the right people internally. Your compliance officer and senior management, through whatever route your policy specifies.
Get proper advice on what must be reported onward. Whether and how to inform your supervisor or the FIU is a judgement call that should be made with advice, not decided alone by the person who made the mistake.
Fix the control that failed. A breach is a symptom. Find whether it was a policy gap, a system permission, an untrained staff member or an unclear escalation path, and close it.
Handle it fairly with the staff member. Follow a proper process and document the outcome, whether that is retraining or something more serious.
Quick Self-Check: Would You Have Tipped Off?
Work through these before your next team meeting.
- A client asks why his transfer is delayed. You tell him it is going through internal approval. → Not tipping off. True, neutral and unremarkable.
- You tell your manager you have concerns about a customer’s account. → Not tipping off. That is escalation working.
- A customer asks directly, and you say, “I really can’t say anything about it.” → Tipping off. You just confirmed there is something to say.
- You run a scheduled KYC refresh on your normal annual cycle. → Not tipping off. Routine, and it looks routine.
- You call a client and suggest he moves his funds elsewhere for a while. → Tipping off. No report mentioned; message received.
- You discuss the case with your head office compliance team under your group programme. → Not tipping off, within the safeguards that programme requires.
- You forward an internal email to the customer without deleting the thread below. → Tipping off. Accidental, and still an offence.
- You stop taking a long-standing client’s calls after filing. → Probably tipping off. The change in behaviour is the message.
You’re Tipping Off Checklist
Before you file
- Is everyone who touches this customer clear that nothing changes in their behaviour?
- Has the holding line been agreed and written down?
- Is the case file access-restricted?
- Does anyone outside the need-to-know group have visibility they should not have?
After you file
- Has any communication with the customer hinted at a report or a review?
- Have any documents, portal messages or system notes exposed the flag?
- Is the delay being explained consistently by every person who might be asked?
- If an exit is planned, is the timing and stated reason defensible on its own?
Ongoing
- Do frontline staff know who to escalate to, by name, today?
- When was the last time this was covered in training and evidenced?
- Would your access logs show who opened a case file last month?
How GRC Advisors Can Help
At GRC Advisors, we work with UAE-regulated entities on the unglamorous part of this problem: making sure the rule survives contact with a real customer on a real Tuesday afternoon. Most firms we meet already know that tipping off is prohibited. What they do not have is agreed wording for a held transaction, a defined need-to-know list, access controls that restrict anything, or evidence that the frontline has been trained on any of it.
Our AML/CFT compliance practice covers exactly that ground. We draft AML policies and procedures that name the specific situations in your business where a disclosure could happen and set out how each one is handled. We build STR and goAML reporting workflows with confidentiality designed in from the first step rather than added afterwards. We deliver role-based AML training aimed at the people who talk to customers, with the attendance and assessment records your supervisor will ask for.
We also test whether any of it works. Our internal control reviews and AML internal audit work examine who can open a case file, what your customer-facing systems display, and whether your escalation path holds under pressure. Where an inspection is approaching, our regulatory inspection readiness support puts the evidence pack together before the questions start.
Have Questions About AML Compliance?
Frequently Asked Questions
What is tipping off in AML?
It means letting a customer, or anyone outside a need-to-know group, learn that a suspicious transaction report has been filed, is being prepared, or that their activity is under review. Direct statements, hints and accidental disclosures all count.
What does tipping off mean in simple words?
Warning someone that something is coming so they can prepare. In AML, that warning lets a customer move money or destroy records before anyone can act.
Is tipping off a criminal offence in the UAE?
Yes. Under Federal Decree-Law No. 10 of 2025 it carries imprisonment and a fine, or either of those penalties.
What is the penalty for tipping off?
A fine of not less than AED 50,000 and/or imprisonment. Where the disclosure causes proceeds to be lost, destroyed or reduced in value, it rises to imprisonment of at least one year plus a fine equal to the value of the proceeds, with a minimum of AED 100,000.
Can my company be fined if an employee tips off?
Yes. The business faces separate exposure from AED 200,000 up to AED 10,000,000 where the offence is committed on its behalf.
Is telling my manager tipping off?
No. Internal escalation to your manager, compliance officer or MLRO is the process working as intended.
Can I close a customer's account after filing a report?
Yes, but timing and the stated reason matter. Let time pass where possible and exit on genuine commercial or contractual grounds.
Does the rule apply to small businesses and DNFBPs?
Fully. Business size does not reduce the obligation, and small firms carry more risk because the same person often handles both the customer and the compliance function.
What if I tipped someone off by accident?
Stop all further discussion, write down exactly what happened, escalate internally straight away, and take advice on what must be reported onward. Do not attempt to conceal it.
What is the difference between tipping off and a confidentiality breach?
All tipping off is a confidentiality breach, but not every confidentiality breach is tipping off. Tipping off specifically involves revealing, or allowing someone to infer, that a report or review exists.