FATF · CBUAE · UAE AML / CFT · CPF Framework

Redefining Risk Intelligence
for the Modern Compliance World

Unlock enterprise-wide visibility across AML, CFT, CPF, Sanctions and Regulatory risk domains with a Risk-Based Approach — and generate regulator-ready reports in one click.

No setup required
11 risk domains
PDF board reports
Case management
Built on the frameworks your regulator reads
FATF 40 Recommendations
CBUAE AML/CFT Guidance
UAE Federal Decree-Law No. (20) of 2018
Cabinet Decision No. (10) of 2019
Wolfsberg Principles
goAML Reporting
UN & OFAC Sanctions Lists
Basel AML Index
EU 6AMLD
Overall Residual Trend
This Year
Jan: 3 residualFeb: 5 residualMar: 4.2 residualApr: 6.5 residualMay: 5.8 residualJun: 8 residualJul: 7.2 residualAug: 9 residualSep: 8.4 residualOct: 9.8 residualNov: 9.2 residual
Top Domains
Sanctions82%
PEP71%
Geographic63%
Customer48%
Interactive preview — pick a metric to re-plot the trend, hover a point for its reading.
11
Risk domains scored
200++
Jurisdictions rated
1-click
Board-ready PDF packs
100%%
Auditable score trail
About EWRA

Smart Compliance Assessments
for Smarter Boards.

Elevate your compliance program with intelligent workflows designed to score, visualize and defend your risk posture — automating routine tasks and improving Board oversight across every risk domain.

Start Assessment
AML / CFT / CPF Scoring
11-domain assessment aligned to FATF and CBUAE guidance.
Live Risk Radar
Inherent vs residual visualisation across every domain.
Board-Ready PDFs
A4 executive packs with heatmaps, findings and sign-off.
Case Management
Track investigations from alert to closure with audit trails.
Services

Everything a compliance function needs

Six modules that cover the full lifecycle — from onboarding a customer to signing off the annual risk assessment at Board level.

How it works

From blank page to Board pack in an afternoon

No implementation project, no consultants on site, no data migration. Four steps.

01
Profile your business
Tell us your sector, footprint, products and delivery channels. EWRA pre-loads the domains that actually apply to you.
02
Score inherent risk
Work through guided questions across all 11 domains. Every answer carries a documented weight — no black-box scoring.
03
Rate your controls
Assess control design and effectiveness. Residual risk and the gap to your appetite are calculated as you go.
04
Export and sign off
Generate the Board pack, the AML policy and the regulator submission. Version it, timestamp it, hand it to the auditor.
Use cases

Built for every regulated entity

Whoever your supervisor is, the expectation is the same — show a documented, risk-based view of your exposure.

Exchange Houses & Money Services
Evidence a Risk-Based Approach for CBUAE inspections with domain-level scoring and documented mitigation.
Banks & Financial Institutions
Run the annual EWRA cycle, compare year-on-year residual movement and brief the Board with defensible numbers.
DNFBPs — Real Estate, Gold, Legal
Meet goAML and supervisory expectations without building a compliance function from scratch.
Virtual Asset Service Providers
Assess exposure across counterparty, jurisdiction and product risk with travel-rule aware controls.
MLROs & Compliance Officers
Replace spreadsheet risk registers with a versioned, timestamped assessment you can hand to an auditor.
Consultants & Audit Firms
Deliver client EWRAs faster — reuse methodology, swap inputs, export a branded report the same day.
Why EWRA

Retire the risk assessment spreadsheet

Today, without EWRA
  • Risk registers scattered across spreadsheet tabs
  • Scoring logic nobody can explain to an inspector
  • Board packs rebuilt by hand every quarter
  • No history when the regulator asks what changed
  • Onboarding decisions buried in email threads
With EWRA
  • One versioned assessment across all 11 domains
  • Transparent, documented scoring methodology
  • Board-ready PDF in one click, every time
  • Timestamped trail on every score and rationale
  • CRA scoring and KYC evidence in one repository
Pricing

Pay per client, not per seat

The rate drops as your book grows. Same platform on every band — only the per-client price changes.

No. of clientsType of clientPrice
Rechargeable (per client)Startups & smaller enterpriseAED 200/ client
Up to 20 clientsMedium level enterpriseAED 180/ client
Up to 50 clientsMedium level enterpriseAED 160/ client
Up to 100 clientsLarge level enterpriseAED 120/ client
Up to 200 clientsLarge level enterpriseAED 100/ client
Enterprise (customised)Bank levelAED 90/ client
Every band includes
  • All 11 risk domains, scored with the documented methodology
  • Customer onboarding with CRA scoring
  • Case management with a full audit trail
  • Board-ready and full assessment PDFs
  • AML policy generator
Get Started
Assessment download and report access unlock after payment. Prices are per client and exclude VAT.
FAQ

Questions your MLRO will ask

Is the methodology aligned to FATF and CBUAE expectations?

Yes. The 11 domains, the inherent-versus-residual model and the control-effectiveness scale follow the FATF Risk-Based Approach guidance and CBUAE AML/CFT expectations for licensed financial institutions and DNFBPs. The full methodology is documented in-app so an inspector can follow every number.

How long does a first assessment take?

Most teams complete a first pass in two to three hours. There is no implementation project, no data migration and nothing to install — you answer guided questions and the scoring happens as you go.

Can we run assessments for more than one entity?

Yes. Each entity keeps its own assessment, dashboard and report pack, and group-level consolidation rolls them into a single Board view. Multi-entity groups and bank-level books are priced on the customised band.

Are the reports good enough for a regulator submission?

The Board pack exports as an A4 PDF with the risk heatmap, domain-by-domain breakdown, findings, mitigation actions and a sign-off block for the MLRO and the Board. Export it, sign it, submit it.

What happens to our data?

Your assessment stays inside your own workspace and leaves it only when you export a report. Nothing is shared with other tenants and nothing is used to train anything.

Can our external auditor review the assessment?

Yes. Every score carries its rationale, owner and timestamp, so an auditor can trace a residual rating back to the answer that produced it without a single follow-up email.

Your next inspection is already scheduled.

Start the assessment free — no card, no setup, no consultant. Have a defensible risk picture before the end of the day.