By Alia Noor, FCMA, CGMA, MBA
UAE Registered Tax Agent | Associate Partner – Taxation & Compliance Advisory
Ahmad Alagbari Chartered Accountants
A customer provides a passport, trade licence and shareholder details. The KYC checklist is complete. But do you really know who you are doing business with?
Money laundering rarely arrives labelled as suspicious. It can hide behind legitimate businesses, complex ownership structures and transactions that appear ordinary until the pieces are viewed together.
This is why an effective Anti-Money Laundering (AML) programme cannot depend on a single control.
The UAE has strengthened its AML framework through Federal Decree-Law No. 10 of 2025 Regarding Anti-Money Laundering, and Combating the Financing of Terrorism and Proliferation Financing, together with Cabinet Resolution No. 134 of 2025, which issued its Executive Regulations.
For businesses within the scope of the UAE AML framework, the question is no longer simply “Do we have an AML policy?”
The better question is: “Do our AML controls actually work?”
Five Pillars of an Effective AML Programme
An effective AML programme can be viewed through five fundamental components:
- AML Compliance Management — Clear responsibility for overseeing AML compliance, supported by appropriate authority, access to information and effective escalation channels.
- Internal Policies, Procedures and Controls — Written controls covering customer risk assessment, CDD, Beneficial Ownership, Politically Exposed Persons (PEPs), sanctions, monitoring, suspicious transaction reporting and record keeping. Controls should reflect the nature, size and risk profile of the business.
- Continuous Employee Training — Employees should understand the AML risks relevant to their roles, recognise warning signs and know when and how concerns should be escalated.
- Independent Review — Periodic independent testing helps determine whether AML policies and controls are operating as intended and identifies weaknesses before they become regulatory problems.
- Customer Due Diligence (CDD) — Understanding who the customer is, who ultimately owns or controls them, why the Business Relationship exists and whether their activity makes sense.
All five pillars matter. But CDD is where many of these controls come together.
CDD: More Than Collecting Documents
CDD is sometimes reduced to obtaining identification documents and completing a KYC checklist. That misses its real purpose.
Effective CDD should answer four fundamental questions:
- Who is the customer?
- Who ultimately owns or controls them?
- Why does the Business Relationship make sense?
- Do their transactions make sense?
A company may have a valid trade licence and complete documentation. But what if its shareholder is another company, owned through several entities across different jurisdictions? What if payments begin arriving from unrelated third parties? What if transactions bear little resemblance to the customer's stated business activity?
None of these factors alone proves money laundering. But they may mean more questions need to be asked.
When Is CDD Required?
Under the UAE Executive Regulations, CDD is required in specified circumstances, including:
- When commencing a Business Relationship;
- Where there is a suspicion of a Crime; and
- Where doubts arise regarding the accuracy or adequacy of previously obtained customer identification information.
Specific thresholds also apply to certain occasional transactions.
For Financial Institutions, CDD applies to occasional transactions of AED 55,000 or more, whether undertaken as a single transaction or several transactions that appear to be linked. For occasional Wire Transfers, the threshold is AED 3,500 or more.
For Virtual Asset Service Providers, CDD applies to occasional transactions of AED 3,500 or more, including apparently linked transactions.
Suspicion does not wait for a monetary threshold.
SDD or EDD? Let Risk Decide
Not every customer presents the same level of risk.
Where lower risks are identified, Simplified Due Diligence (SDD) may be permitted under the applicable regulatory framework. This may include less frequent updating of customer information or reduced monitoring.
Where higher risks exist, Enhanced Due Diligence (EDD) requires deeper scrutiny. Depending on the circumstances, enhanced measures may include:
- Additional information about the Customer and Beneficial Owner;
- Greater understanding of the purpose of the relationship;
- Establishing source of funds or source of wealth, where required;
- Increased and more frequent ongoing monitoring; and
- Appropriate Senior Management approval.
The principle is straightforward:
The higher the risk, the deeper the due diligence.
Who Is Really Behind the Customer?
One of the most important parts of CDD is identifying the Beneficial Owner.
The shareholder appearing on a corporate document may not necessarily be the natural person who ultimately owns or controls the business. Businesses may therefore need to look through corporate layers and legal arrangements to understand where ultimate ownership and control actually rest.
Complexity itself is not suspicious. Many legitimate international businesses operate through multi-layered structures.
The real question is whether that complexity makes commercial sense.
Warning indicators may include:
- Unnecessarily opaque ownership structures;
- Difficulty identifying the natural person exercising ultimate control;
- Unexplained changes in ownership or control;
- Unusual payments involving unrelated third parties; and
- Transactions inconsistent with the customer's stated business activities.
These indicators do not automatically establish wrongdoing. They indicate that further enquiry may be necessary.
A red flag is not proof of money laundering. It is a reason to ask another question.
CDD Does Not End at Onboarding
Perhaps one of the biggest mistakes is believing CDD is finished once a customer has been accepted.
Customers change.
Ownership changes. Businesses enter new markets. Transaction volumes increase. New jurisdictions become involved. A Customer or Beneficial Owner may become a Politically Exposed Person (PEP).
CDD must therefore be ongoing.
Businesses should consider whether customer information remains current and whether transactions continue to correspond with what they know about the customer and their risk profile.
Instead of asking “Is the KYC file complete?”, ask:
“Does what we are seeing still make sense?”
The Bottom Line
The five pillars are not five separate boxes to tick.
Compliance management creates accountability. Policies establish the framework. Training enables people to recognise risk. Independent review tests whether the controls work. CDD helps businesses understand who they are dealing with.
Weakness in one can undermine the others.
When it comes to CDD, three questions remain fundamental:
- Who are we doing business with?
- Who is really behind them?
- Does what they are doing make sense?
When businesses can answer those questions — and demonstrate how they reached those answers — AML compliance moves beyond paperwork.
It becomes a genuine line of defence against financial crime.
Compliance Begins Where the Checklist Ends..
Be Compliant.
Disclaimer
This article is intended for general information and educational purposes only and does not constitute legal, tax, regulatory or professional advice. The application of UAE AML/CFT and proliferation financing requirements may vary depending on the nature of the business, regulated activity, applicable Supervisory Authority and specific facts and circumstances. Readers should refer to applicable UAE legislation, regulations and guidance issued by the relevant Competent and Supervisory Authorities and seek appropriate professional advice where required.
Tags
UAE AML, Anti-Money Laundering, AML Compliance, AML Programme, Five Pillars of AML, Customer Due Diligence, CDD, KYC, Enhanced Due Diligence, EDD, Simplified Due Diligence, SDD, Beneficial Owner, UBO, DNFBP, AML Training, Financial Crime, PEP, Suspicious Transaction Reporting, UAE Compliance, Proliferation Financing