KYC and CDD Services

KYC and CDD managed services means we run your customer due diligence operation, onboarding checks, identity verification, beneficial ownership, sanctions and PEP screening, enhanced due diligence, periodic review, and remediation, performed by trained analysts under your policies and in accordance with UAE law. Cabinet Resolution No. 134 of 2025 sets out what due diligence must achieve [Articles 6 to 10].

One principle needs to be clear before anything else, because it’s what firms most often get wrong when they outsource. You can outsource the work. You cannot outsource the obligation. When an inspector asks why a customer was onboarded, the answer cannot be that a service provider handled it. The file has to be yours, the decision has to be traceable, and you have to be able to retrieve the records. Every part of how we run this service is built around that constraint rather than around ways to work past it.

Your obligation. Our capacity.

Get trained KYC and CDD analysts running your files to UAE law, with the evidence trail staying yours.

What Are KYC Managed Services?

A managed service is an operating arrangement, not software or a consulting report. We take a defined part of your customer due diligence workload and run it continuously: receiving cases, performing checks to your standards, escalating what needs a decision, and leaving behind a file that would satisfy your supervisor. You keep the policy, the risk appetite, the compliance officer, and the final say on any relationship.

Firms come to this for three reasons.

Capacity

Where volume exceeds what the internal team can process, and files are ageing.

Capability

Where the business has grown into obligations nobody in-house has done before, such as layered beneficial ownership or enhanced due diligence on high-risk customers.

Remediation

Where a backlog or an inspection finding means a defined population of existing files has to be brought up to standard against a deadline.

What a managed service is not: a way to make the obligation someone else’s problem. If a provider offers that, they are describing something the law doesn’t permit, and the arrangement will fail at the first inspection.

KYC vs CDD: What Is the Difference?

Used interchangeably in conversation, but they are not the same thing, which matters when a supervisor or a bank asks you a precise question.

KYC, know your customer

is the identification and verification step: establishing who the customer is and confirming it with reliable, independent documents or data. It is a component, and it is the one most people picture.

CDD, customer due diligence

is the whole obligation. It includes identification and verification, but also understanding the purpose and intended nature of the relationship, identifying and verifying beneficial owners, screening, assessing customer risk, and monitoring the relationship on an ongoing basis. Where the law imposes duties, it imposes them as CDD. [Cabinet Resolution No. 134 of 2025, Articles 6 to 10]

[Cabinet Resolution No. 134 of 2025, Articles 6 to 10]

EDD, enhanced due diligence

is the intensified version applied where risk is higher: source of funds and wealth, closer scrutiny, more frequent review, and senior management approval to begin or continue the relationship.

[Cabinet Resolution No. 134 of 2025, Article 5(2)(c)]

SDD, simplified due diligence

is the reduced version, permitted only where your risk assessment genuinely supports it, it is documented as such, and it is applied in coordination with your Supervisory Authority. It is not a shortcut for busy periods, and it never reduces your targeted financial sanctions obligations.

[Cabinet Resolution No. 134 of 2025, Article 5(3)]

KYB and KYS

know your business and know your supplier, extend the same discipline to corporate counterparties and to your supply chain. Neither is a separate legal obligation in the AML framework, yet banks and counterparties increasingly expect both.

The practical consequence: a firm that has done KYC and believes it has done CDD is usually missing the purpose of the relationship, the beneficial owner verification, or the ongoing monitoring, and those are exactly the three gaps a file review finds.

Customer Due Diligence vs Commercial or Financial Due Diligence

Worth separating, because the phrase due diligence services covers two unrelated markets in the UAE. Commercial, financial, vendor, and transaction due diligence are M&A and investment exercises: examining a target company’s accounts, contracts, and commercial position before a deal. That is transaction advisory work and not what this page offers. Customer due diligence is an AML compliance obligation performed on the people and entities you do business with, continuously, under Cabinet Resolution No. 134 of 2025. If you need the first, an audit or corporate finance firm is the right call.

What Is Customer Due Diligence Under UAE Law?

CDD is the set of measures a reporting entity must apply to identify and understand its customers and the risk they present, before or during the establishment of the relationship and continuously thereafter. Under the Executive Regulations it requires you to identify the customer and verify identity using reliable independent source documents, data, or information; understand the purpose and intended nature of the business relationship; identify beneficial owners and take reasonable measures to verify them; and conduct ongoing due diligence across the life of the relationship, keeping documents and information current [Cabinet Resolution No. 134 of 2025, Articles 6 to 10].

Two features of the obligation catch firms out. It is continuous rather than a gate at onboarding, so a file that was compliant on day one and untouched for four years is no longer compliant. It is also risk-based, so the depth of due diligence must reflect the risk the customer presents as assessed in your business risk assessment, which means an identical process applied to every customer suggests no risk assessment is driving it.

Can You Outsource KYC and CDD in the UAE?

Yes, and the legal detail matters more here than anywhere else on this page, because two different arrangements get called outsourcing and they carry different obligations.

Outsourcing, which is what a managed service is

A third party performs due diligence work on your behalf, under your policies, to your standards, using your risk criteria. The obligation remains entirely yours, the records are yours, and you supervise the arrangement. Nothing in UAE law prevents this, and it is how most compliance operations at scale actually run. What the law will examine is whether you retained control: your policy governed the work, your compliance officer made the decisions that needed judgement, and your records are complete and retrievable [Cabinet Resolution No. 134 of 2025, Article 20 (3)].

Reliance on a third party, which is something else

Relying on due diligence already performed by another regulated party, for example, accepting the onboarding a bank or fellow institution has done rather than repeating it. This is permitted subject to conditions set out in Article 20 of Cabinet Resolution No. 134 of 2025, and those conditions are the point: you must be able to obtain the information immediately, be able to get the underlying documentation without delay on request, and satisfy yourself that the third party is regulated and supervised. Ultimate responsibility stays with you regardless.

Firms conflate the two, and it causes real problems, because reliance carries conditions that outsourcing does not, and outsourcing carries supervision duties that reliance does not. Our service is outsourcing. We do not ask you to rely on due diligence we performed for somebody else, and your file will contain the underlying evidence rather than an assurance that it exists elsewhere.

Not sure which arrangement you actually have?

Send us your current provider's contract and we will tell you whether it is outsourcing or reliance, and what that means for your files.

UAE AML Laws Behind KYC and CDD

Every check we perform traces to a provision, and every file we build is designed to be read by someone holding these instruments:

Legal Instrument What It Requires How It Shapes the Service
Cabinet Resolution No. 134 of 2025, Articles 6 to 9 Identification and verification before or during the relationship, understanding its purpose and intended nature, CDD for occasional transactions at or above AED 55,000 and wire transfers at or above AED 3,500 for financial institutions, and ongoing due diligence across the relationship. The core workflow, including the thresholds that determine when an occasional customer becomes a due diligence case. Getting the trigger points wrong is the most common structural error we correct.
Cabinet Resolution No. 134 of 2025, Article 10 Identification of every natural person owning or controlling 25% or more, with the fallback cascade to persons exercising control and then to senior management, and reasonable measures to verify them. Beneficial ownership work, which is where files most often thin out. Verifying a UBO through two layers of corporate structure is slow, and slow is exactly why it gets skipped.
Cabinet Resolution No. 134 of 2025, Articles 5(2)(c) and 5(3) Enhanced due diligence for high-risk situations including source of funds and wealth and senior management approval, and simplified due diligence only where the risk assessment supports it and in coordination with the Supervisory Authority. EDD triggers and depth, and the discipline that simplified due diligence is a documented decision rather than a busy-period shortcut.
Cabinet Resolution No. 134 of 2025, Article 20 Conditions for relying on customer due diligence performed by a third party, including immediate access to the information, ability to obtain underlying documentation without delay, and continuing ultimate responsibility. The line between outsourcing and reliance. Our arrangement is outsourcing, so your file holds the evidence rather than a promise that someone else holds it.
Cabinet Resolution No. 134 of 2025, Articles 16 and 23 PEP identification covering family members and close associates, and countermeasures for high-risk countries. Screening scope and the country risk rules applied at onboarding and on review.
Cabinet Resolution No. 74 of 2020 Targeted financial sanctions: screening against UN and UAE Local Terrorist Lists, freezing without delay, and reporting to the Executive Office for Control and Non-Proliferation. Screening at onboarding and on an ongoing basis, with a defined escalation path that reaches your compliance officer rather than stopping with an analyst.
Cabinet Resolution No. 134 of 2025, Articles 19, 22 and 25 Tipping-off prohibition and reporting procedures, the compliance officer at management level, and record keeping with prompt retrieval. Confidentiality rules for analysts, escalation into your officer's decision, and file construction designed so records can be produced promptly on request.
Federal Decree-Law No. 10 of 2025 The primary AML/CFT/CPF statute in force 14 October 2025, repealing FDL No. 20 of 2018 (Article 41). Risk-based preventive measures (Article 19), STR duties (Article 18), and administrative penalties of AED 10,000 to AED 5,000,000 per violation (Article 17). The framework the whole operation answers to, and the reason files built under the 2018 law need review rather than assumption.
CBUAE Outsourcing Regulation for Banks, Circular No. 14/2021 Bank outsourcing governance: a notice of no objection from the Central Bank before outsourcing, the board remaining responsible for outsourced activities, and Article 6 requiring the Master System of Record including confidential data to be maintained within the UAE. For bank clients this determines the approval step, the supervision arrangement, and where data may sit. We build the no-objection process into the mobilisation timeline rather than discovering it later.
Federal Decree-Law No. 45 of 2021 (Personal Data Protection Law) Restrictions on cross-border transfer of personal data (Article 23), breach notification (Article 9), and controller duties when appointing processors offering sufficient guarantees. We process your customers' personal data on your instructions, which makes you controller and us processor, with the contract, location, and security terms that follow from it.
Cabinet Resolution No. 71 of 2024 and sectoral guidance The DNFBP penalty schedule (41 listed violations, AED 50,000 to AED 1,000,000, doubling on recurrence within a year), MoET Guidelines for DNFBPs (September 2025), and the DFSA and FSRA rulebooks. The standard files are built to withstand, expressed in the terms your own supervisor uses.

The sentence to remember : outsourcing the work does not outsource the obligation, and for banks the board remains responsible for outsourced activities [CBUAE Outsourcing Regulation for Banks, Circular No. 14/2021]. Any provider who tells you otherwise is selling you a finding.

CDD Thresholds in the UAE: When Due Diligence Triggers

Due diligence is not only an onboarding event. It is triggered by circumstances, and the trigger points are specific:

Establishing a business relationship

dentification and verification before or during establishment, with the relationship’s purpose and intended nature understood and recorded.

Whether carried out in a single operation or in several that appear linked (applicable to financial institutions), which is why structuring detection matters at the counter as well as in monitoring.

Wire transfers at or above AED 3,500

With the originator and beneficiary information the transfer rules require (applicable to financial institutions).

Suspicion of ML, TF, or PF

Regardless of any threshold or exemption, and regardless of whether the customer is established.

Doubts about previously obtained data

Where the identification information you hold is no longer reliable or adequate, verification must be repeated.

Thresholds differ by sector and activity, and VASPs in particular operate to different occasional transaction limits. We configure the trigger rules to your licence rather than applying a single set across every client.

Enhanced Due Diligence: When It Applies and What It Requires

EDD applies where risk is higher, and the situations are not a matter of preference: politically exposed persons and their family members and close associates, customers or transactions connected to high-risk jurisdictions, complex or unusually large transactions without an apparent economic purpose, opaque ownership structures, and any situation your own risk assessment classifies as high risk.

What EDD looks like done properly. Article 5(2)(c) introduces these measures as examples rather than a closed checklist, and expects you to apply the ones proportionate to the risk you have identified:

Source of funds and source of wealth

Two different questions. Source of funds is where this money came from; source of wealth is how the customer accumulated their assets overall. Files that answer only the first are the most common EDD weakness we find.

Payment from customer’s own bank account

Where it fits the risk, take the first payment through an account in the customer’s own name held with a financial institution that is itself subject to equivalent due diligence standards.

Senior management approval

To establish or continue the relationship, evidenced with a name and a date rather than implied by the account being open. [Cabinet Resolution No. 134 of 2025, Article 5(2)(c)]

Deeper verification

Additional independent corroboration of identity, ownership, and the rationale for the structure or transaction.

Closer ongoing scrutiny

More frequent review and tighter monitoring parameters, set at onboarding rather than promised.

We perform the analytical work and prepare the file to the point of decision. The approval itself is yours, because it is a judgement the law assigns to your senior management.

Beneficial Ownership Verification to the 25% Standard

Identifying every natural person who owns or controls 25% or more of a legal person, and where no such person exists or doubt remains, applying the cascade to those exercising control by other means and then to the natural persons holding senior management positions [Cabinet Resolution No. 134 of 2025, Article 10]. Your beneficial ownership register duties sit alongside this [Cabinet Resolution No. 109 of 2023].

This is the slowest part of onboarding and the part most often abandoned halfway. A UAE holding company owned by an offshore entity owned by a trust is three registries, two jurisdictions, and often a document in another language. The temptation is to record the first layer and move on, and the resulting file names an owner who is not the beneficial owner. We work the structure to the natural person, document each layer with its evidence, and flag where the chain genuinely cannot be completed so your compliance officer can make an informed decision rather than an assumed one.

KYC Periodic Review, KYC Update and CDD Remediation

Three related activities that firms treat as one and should not.

Periodic review

Scheduled re-examination of a file at a frequency set by customer risk rating, typically annual for high risk and longer for lower ratings. Driven by the calendar and your risk model.

KYC update, or refresh

Refreshing expired documents and changed data: a lapsed passport, a new address, a change of authorised signatory, an ownership change. Driven by events and expiries rather than the calendar.

CDD remediation

A project to bring a defined population of existing files up to current standard, usually after an inspection finding, a change in the law, an acquisition, or the discovery that historic onboarding was inconsistent. Finite, scoped, and deadline-driven.

Remediation is where managed services earn their reputation, because the work is high-volume, time-boxed, and painful to absorb into a team that also has to onboard new business. It is also where the realignment to Federal Decree-Law No. 10 of 2025 is currently generating demand, since files built under the repealed 2018 framework do not automatically satisfy the current one.

KYC Outsourcing Models: Full, Overflow, Remediation and Targeted Support

Model Best For How It Works
Full managed service Firms without an internal KYC team, or with one that is fully occupied elsewhere We run the whole CDD operation to your policy: onboarding, screening, EDD preparation, periodic review, and refresh, with escalation into your compliance officer
Overflow capacity Seasonal peaks, campaign onboarding, or growth outpacing hiring Your team handles business as usual and routes surplus volume to us, on the same standards and templates, so files are indistinguishable
Remediation project Inspection findings, backlogs, acquisitions, or realignment to the 2025 framework A defined population, a defined standard, a deadline, and a tracker your compliance officer and your supervisor can both follow
EDD only Firms comfortable with standard onboarding but stretched by high-risk cases We take the complex files: layered ownership, PEPs, source of wealth, high-risk jurisdictions, prepared to the point of your approval decision
Quality assurance only Firms with an internal team wanting independent file testing rather than production Sample-based file review against your policy and the law, with findings, patterns, and analyst-level feedback

How Our Managed KYC Service Works, Step by Step

Your licence, supervisor, policy, risk model, and customer types, so our analysts apply your standards rather than generic ones.

Outsourcing agreement, data protection terms, systems access, software integration, and provisioning of screening and watchlist access.

Documented procedures, checklists, escalation rules, and quality standards specific to you, so decisions are consistent and reviewable.

A pilot batch worked and reviewed with your compliance officer before volume starts, which is where standards get calibrated.

Cases received, checks performed, screening run, structures worked, files built, and anything requiring judgement escalated to your officer with the analysis complete.

Internal sampling of our own output against your playbook, with results reported to you rather than kept in-house.

Volumes, turnaround, escalations, and quality metrics on a regular cycle, so your officer can supervise the arrangement and evidence that supervision.

 Files and evidence delivered into your systems in a form you can retrieve promptly, with retention aligned to your obligations.

KYC and CDD Services: What You Receive

Deliverable

What It Does

Completed CDD files

Built to your policy and the Executive Regulations, structured so an inspector can follow the reasoning

Documented KYC playbook

Your procedures, checklists, and escalation rules, which stay yours if the arrangement ends

Beneficial ownership analysis

Structures worked to the natural person with each layer evidenced, and unresolvable chains flagged rather than assumed

Screening records

Sanctions, PEP, and adverse media results with disposition reasoning, not just a cleared status

EDD packs

Source of funds and source of wealth analysis prepared to the point of your senior management decision

Customer risk ratings

Applied using your model, with the rationale recorded so ratings can be defended and re-tested

Periodic review and refresh schedule

Driven by risk rating and document expiry, with a tracker your officer runs

Quality assurance reporting

Our own sampling results, error patterns, and corrective actions, reported to you

Management information

Volumes, turnaround, escalation rates, and ageing, which is also the evidence that you supervised the arrangement

Individual KYC file completion

Complete individual customer KYC files

Missing identity details or inconsistent customer information can leave onboarding decisions unsupported. We help your team complete individual KYC files against the requirements applicable to your business and the customer’s risk profile.

 

Review the file as a whole

We check identification evidence, the purpose of the relationship, expected activity and required screening records. We record missing information and contradictions, prepare focused follow-up requests and identify cases requiring enhanced due diligence or compliance officer review.

A file ready for a decision

You receive a completed checklist, an indexed evidence record and an exception summary. Unresolved items remain visible for the authorised decision-maker. Your organisation retains responsibility for accepting the customer and approving exceptions; we provide the review and follow-up support agreed for the file population.

Corporate KYB and authority verification

Verify corporate customers and authorised representatives

Corporate onboarding requires a clear view of the legal entity and the people entitled to act for it. We review company records, licensing information and signing authority so your KYB file supports an informed onboarding decision.

Check existence and authority

Our review compares incorporation and licence documents with available registry information, identifies relevant directors and representatives, and checks the evidence supporting their authority. We examine inconsistencies between the application, ownership information and proposed business relationship.

Evidence your team can use

You receive a corporate verification record, document index and escalation list. Ownership or control questions requiring further investigation are identified for the beneficial ownership review. Share the company documents, ownership chart and proposed mandates; the depth of verification is agreed according to risk and the applicable supervisory framework.

Event-driven KYC refresh

CDD quality assurance sampling

Check the quality of completed CDD files

A completed checklist does not always mean that a customer file supports its risk and onboarding decisions. Our CDD quality assurance review tests a defined sample for completeness, consistency and the quality of the underlying judgement.

Look beyond missing documents

We assess verification evidence, ownership analysis, expected activity, screening outcomes and escalation decisions. Sampling can target high-risk cases, recently onboarded customers, particular reviewers or recurring exceptions. The sample basis and limitations are recorded.

Turn findings into improvements

You receive graded findings, examples of recurring weaknesses and a corrective action schedule. We separate individual file errors from process or training issues and can retest an agreed sample after correction. This is a targeted quality review; it does not replace an independent AML audit where one is required.

Customer exit and offboarding control review

Control AML risks when closing a customer relationship

Customer exit can involve outstanding funds, open investigations and records that must remain accessible. We review your offboarding process so commercial closure and compliance decisions are coordinated.

Review the exit conditions

The assessment covers the reason for exit, pending transactions, repayment destinations and relevant restrictions or authority instructions. We identify how the compliance officer is involved and how customer communications avoid tipping off. An exit does not remove the need to consider suspicious reporting.

A documented closure trail

You receive revised workflow steps, approval points and an exit checklist. The record captures outstanding issues and retention arrangements. Share your current process and representative cases so we can identify where responsibility or evidence is being lost at closure.

TCSP registered-office client review

Review registered office clients throughout the relationship 

A client using only a registered office can still require ongoing attention. We help TCSPs review whether the client’s identity, ownership, contact details and stated activities remain consistent with the relationship. 

Check what has changed 

The review considers returned correspondence, unexplained loss of contact, ownership changes and information inconsistent with the original purpose. We define follow-up and escalation based on the applicable framework and the customer’s risk, rather than treating inactivity as evidence of low risk. 

A documented relationship review 

You receive an updated client review record, unresolved questions and proposed actions for the authorised decision-maker. Share the service agreement, contact history and existing CDD file so the assessment reflects the ongoing service. 

TCSP formation-stage purpose and substance review

Assess purpose and substance at company formation

A formation request should have an understandable commercial purpose and a clear account of who will own and control the entity. We help TCSPs assess those explanations before the formation work proceeds. 

Understand the proposed structure

We review planned activities, jurisdictions, ownership layers, expected counterparties and the reason for using the proposed entity. The assessment records gaps or inconsistencies requiring further enquiry, including structures that add complexity without a credible explanation.

Support a documented acceptance decision

You receive a purpose and substance assessment, evidence requests and escalation points. This AML review considers the plausibility of the business explanation; tax, licensing and economic substance advice are separate matters where required.

TCSP ownership-change monitoring

Changes to shareholders, controllers or authorised representatives can affect a TCSP’s customer understanding. We help you build a process for receiving changes, checking their significance and refreshing affected CDD records.

We compare the revised structure with the previous ownership map, obtain relevant evidence and identify new parties for verification and screening. The review considers whether the change affects risk, the purpose of the structure or previous acceptance decisions.

You receive updated records, an exception list and a change log linking old and new information. We define how corporate administration staff alert compliance so statutory changes and AML updates are coordinated without treating them as the same task.

Merchant and payment-aggregator AML due diligence

Insurance beneficiary and assignment CDD review

Review beneficiary and policy assignment due diligence

A change of beneficiary or assignment can introduce a new party and alter the risk of an insurance relationship. We help review the required identification, verification and escalation steps at the relevant stage of the policy lifecycle.

Connect the parties and the payment

We assess policyholder, beneficiary, assignee and related ownership information where applicable. The review considers the reason for the change, any unexplained third-party involvement and information needed before a payout or other relevant event.

A documented review outcome

You receive a party-and-event checklist, evidence gaps and proposed escalation actions. Timing and depth are aligned with the applicable insurance requirements and risk profile. Share the policy details, change request and existing CDD records for an assessment of the actual case.

Insurance third-party premium payer review

Review insurance premiums paid by third parties

A premium paid by someone other than the policyholder needs a clear explanation of the relationship and funding arrangement. We help your team assess the payer, payment pattern and relevant supporting evidence.

Establish the reason for the payment

The review considers the payer’s connection to the policyholder, consistency with the customer profile and any repeated or unexplained changes. We assess how refunds, surrender proceeds or other payments could return value to a different party.

Support the acceptance decision

You receive a documented review, outstanding evidence requests and escalation recommendations. The insurer or intermediary’s authorised team decides whether the payment can be accepted under its policy and applicable requirements.

Fund investor onboarding and EDD

Review fund investor onboarding and higher-risk cases

Fund subscriptions can involve corporate structures, intermediaries and funding arrangements that require careful review. We support investor onboarding and identify cases needing enhanced due diligence under the fund’s applicable framework. 

Understand the investor and the money

The review covers ownership and control, authority to invest, subscription funding and relevant screening. For higher-risk cases, we help organise additional evidence and explanations, including source of funds or wealth where required by the risk assessment and rules. 

A file for authorised approval

You receive a documented review, evidence gaps and recommended escalation. We distinguish the roles of manager, administrator and distributor. Share the fund structure, onboarding procedures and case records so the service fits the agreed allocation of work. 

Custody and omnibus account AML assessment

Assess custody and omnibus account AML arrangements

An omnibus structure can limit visibility of the investors or transactions behind an account. We help assess the customer relationship, intermediary controls and access to underlying information required by the applicable framework. 

Review visibility and reliance

The assessment covers the account holder, beneficial ownership where relevant, underlying-party access and the purpose of the arrangement. We examine contractual rights, jurisdictional risk and how unusual activity can be investigated without assuming all underlying customers are directly onboarded by the custodian. 

A documented control assessment

You receive identified information gaps, due diligence recommendations and escalation conditions. Share the account structure, agreements and available transaction records so the review addresses the actual level of transparency.

DFSA fund administrator AML oversight

Review AML oversight of fund administrators

Delegating investor administration requires a clear view of what the administrator does and how the responsible firm checks it. We assess the arrangement within the applicable DFSA framework and agreed allocation of responsibilities. 

Test oversight and information access

The review covers the agreement, customer checks, exceptions, management information and access to underlying files. We examine how higher-risk cases and suspicious activity concerns reach the responsible officer and how deficiencies are followed up. 

An oversight improvement plan

You receive findings, proposed reporting requirements and targeted file-review recommendations. The service distinguishes administrative delegation from a permitted reliance arrangement. Share the agreements and oversight records so the assessment reflects how the administrator is actually supervised. 

FSRA fund investor AML oversight

A fund manager needs sufficient evidence to oversee investor AML work performed by administrators or other parties. We review the allocation of work and the information available for higher-risk and exceptional cases.

The assessment covers onboarding, ownership changes, subscriptions, redemptions and escalation of concerns. We examine access to underlying records and whether management information reveals unresolved exceptions rather than reporting only completed volumes.

You receive a responsibility assessment, sample-review findings where agreed and proposed oversight actions. We align the review with the relevant FSRA requirements and actual delegation arrangements. The responsible firm retains the obligations assigned to it by the applicable framework. 

See which model fits your volumes

A 15-minute call is usually enough. Tell us your customer types and monthly volume and we will map the arrangement.

Data Protection in Outsourced KYC

Outsourced KYC means someone else handling your customers’ identity documents, addresses, ownership details, and, in EDD cases, their financial histories. That is among the most sensitive data your business holds, and how it is handled deserves a straight answer, not reassurance.

Under the Personal Data Protection Law, you are the controller, and we are the processor, which means we act on your documented instructions. You retain the accountability [Federal Decree-Law No. 45 of 2021].

KYC Software or KYC Managed Services?

A question worth answering plainly, because they solve different problems and firms often buy the wrong one.

Software solves a throughput and consistency problem

It verifies identities, runs screening, stores files, and enforces a workflow. It does not decide whether a beneficial ownership chain is credible, judge whether a source-of-wealth explanation holds together, or work a structure through three registries in two languages.

A managed service solves a capacity and judgement problem

Trained analysts perform the work that requires reading, reasoning, and chasing, which is most of what a difficult file consists of.

Most firms at scale need both, and the sequencing usually runs software first for the mechanical checks and people for the exceptions. If you are choosing between platforms, our AML software selection service runs that as a structured process, and if you already have a screening system, our testing and validation service establishes whether it is doing what you think it is.

Choosing a KYC Service Provider in the UAE

Since the market has widened considerably, here are the questions that separate providers, and we would rather you ask them of everyone, including us.

Whose policy governs the work?

If the provider applies its own standard rather than yours, your files will align with someone else’s risk appetite.

Where do the records live, and can you retrieve them promptly?

Prompt retrieval is the legal standard [Cabinet Resolution No. 134 of 2025, Article 25]. A provider holding your evidence in their system is a retrieval problem waiting for an inspection.

Is this outsourcing or reliance?

Different legal tests, different conditions, and providers aren’t always clear about what they are offering.

Who makes the decisions that require judgement?

Define escalation to your compliance officer; don’t improvise it.

What are the data protection terms?

Location, access, sub-processors, breach notification, and exit.

How do you measure quality, and do you see the results?

A provider that samples its own work and reports the errors to you is telling you something a testimonial cannot.

Who Needs KYC and CDD Services in the UAE?

Banks, exchange houses, and payment providers

High onboarding volumes, complex structures, and the strictest supervisory expectations, with the Circular No. 14/2021 approval path applying to banks.

[Cabinet Resolution No. 134 of 2025, Article 2]

DNFBPs

Real estate brokers, dealers in precious metals and stones, corporate service providers, lawyers, notaries, and accountants, where CDD arrives in bursts around transactions rather than steadily

[Cabinet Resolution No. 134 of 2025, Article 3]

VASPs and fintechs

Fast onboarding, digital-first customers, and different occasional transaction thresholds, where the pressure is to keep due diligence rigorous at speed.

[Cabinet Resolution No. 134 of 2025, Articles 4, 7(3) and 36]

Insurers and insurance intermediaries.

Policyholder and beneficiary due diligence, where the beneficiary may not appear until a claim.

Firms under a remediation deadline.

Where a supervisor, a bank, or an acquisition has created a defined population of files that must be brought to standard by a date.

Penalties for Inadequate Customer Due Diligence

  • Administrative penalties. AED 10,000 to AED 5,000,000 per violation, plus warnings, licence restrictions, and public naming. CDD failures are counted per breach so that a systemic file weakness can trigger multiple penalties rather than a single one. [Federal Decree-Law No. 10 of 2025, Article 17]
  • The DNFBP penalty schedule. 41 listed violations at AED 50,000 to AED 1,000,000 for MoET- and MoJ-supervised businesses, doubling if the same violation recurs within one year. [Cabinet Resolution No. 71 of 2024]
  • The commercial cost that arrives first. Banks review correspondent and account relationships based on CDD quality, and a file population that cannot withstand review affects banking access long before a supervisor is involved.
  • Accountability does not transfer. Outsourcing the work leaves the obligation with you, and for banks, the board remains responsible for outsourced activities. [CBUAE Outsourcing Regulation for Banks, Circular No. 14/2021]

KYC and CDD by Sector in the UAE

Non-resident buyers, third-party payers, and beneficial ownership through layered purchase vehicles, with transaction-driven volume spikes.

The AED 55,000 occasional transaction threshold applied at the counter, walk-in customers, and linked-transaction detection.

The heaviest beneficial ownership work in the market: nominees, trusts, and multi-jurisdiction structures where the 25% test genuinely requires investigation.

Determining which engagements fall within DNFBP scope, then applying client- and matter-level due diligence without obstructing fee earners.

Volume, remittance corridors, and periodic review cycles that generate more work than onboarding does.

Digital onboarding at speed, wallet and counterparty considerations, and the AED 3,500 occasional transaction threshold.

Know your business and know your supplier checks, which sit outside the strict AML obligation and are increasingly demanded by banks and counterparties.

Why AML UAE for KYC and CDD Managed Services

Running files is a different discipline from advising on them, and we do both, which is the point:

300+

AML compliance projects across FIs, DNFBPs, and VASPs, so our analysts have seen the structures and the red flags rather than only the procedures

1000+

EWRA and AML/CFT/CPF policy sets delivered, which is why our analysts can apply your policy accurately: we write these documents for a living

750+

professionals trained across 3,000+ hours, and the same training standard is applied internally to the people working your files

Under 4 hours

typical turnaround on compliance queries during an engagement, because a stalled file is a commercial problem as well as a compliance one

One commitment that shapes the arrangement: your files, your playbook, and your records remain yours, delivered into your systems and retrievable by you. If you end the arrangement, you keep everything needed to carry on, including the procedures we built. A managed service that leaves you unable to operate without it has created a dependency, not a control.

The Team Behind Your Files

Pathik Shah

CAMS, FCA, CS, CISA, DISA (ICAI), FAFP (ICAI)

Experience

28+ years

Regulatory Coverage

MoET, MoJ, CBUAE, CMA, FSRA, DFSA, VARA · AML/CFT framework design, RegTech

Jyoti Maheshwari

CAMS, ACA

Experience

11+ years

Regulatory Coverage

MoET, MoJ, CBUAE, CMA, FSRA, DFSA, VARA · AML/CFT/CPF framework, health checks

Dipali Vora

CAMS, ACS

Experience

10+ years

Regulatory Coverage

MoET, MoJ, CBUAE, CMA, FSRA, DFSA, VARA · Consulting, training, implementation

Monika Shah

CAMS

Experience

3+ years

Regulatory Coverage

MoET, MoJ, CBUAE, CMA, FSRA, DFSA, VARA · managed KYC, consulting, goAML reporting

What Our KYC File Reviews Have Found

The onboarding that stopped at layer one

A corporate service provider had complete files on every entity it onboarded and had recorded the immediate shareholder in each case. In roughly a third of files, the immediate shareholder was itself a company, and the natural person behind it had never been identified. Every file looked finished. The remediation was not complicated; it was simply a matter of volume, and it required a defined project rather than an instruction to the team to catch up.

Source of funds without source of wealth

An EDD population where every file answered where the money for this transaction came from and none addressed how the customer had accumulated their wealth overall. The distinction sounds academic until an inspector asks the second question, at which point a file that answers only the first shows that the EDD was procedural rather than analytical.

Periodic review that had quietly stopped

Reviews were scheduled by risk rating, and the schedule was being followed for the customers who had a rating. A batch onboarded during a system migration had never been rated, so it never entered the review cycle and went untouched for four years. Nobody had done anything wrong on any given day, which is how the most durable gaps form.

FAQs on KYC and CDD Services in the UAE

KYC, or know your customer, is the identification and verification of a customer’s identity using reliable, independent source documents, data, or information. In UAE law, it forms part of the wider customer due diligence obligation set out in Articles 6 to 10 of Cabinet Resolution No. 134 of 2025.

KYC is the identification and verification step. CDD (customer due diligence) is the full obligation: identification and verification, understanding the purpose and intended nature of the relationship, identifying and verifying beneficial owners, screening, risk rating, and ongoing monitoring. Where the law imposes duties, it imposes them as CDD, so a firm that has done KYC has completed one component rather than the requirement.

The measures required to identify and understand your customers and the risk they present, applied before or during the establishment of a business relationship and continuously thereafter, and calibrated to risk. It requires identity verification from reliable independent sources, understanding the relationship’s purpose, beneficial ownership identification to the 25% standard, and ongoing due diligence keeping information current [Cabinet Resolution No. 134 of 2025, Articles 6 to 10].

Yes. A third party may perform the work on your behalf under your policies and standards. What cannot be outsourced is the obligation: the records remain yours and must be retrievable promptly [Cabinet Resolution No. 134 of 2025, Article 25], your compliance officer retains the decisions requiring judgement, and you must supervise the arrangement. For banks, the board remains responsible for outsourced activities, and a Central Bank notice of no objection applies before outsourcing [CBUAE Outsourcing Regulation for Banks, Circular No. 14/2021].

Outsourcing means someone performs the work for you under your policy, with the obligation and the records staying with you. Reliance means accepting due diligence already performed by another regulated party instead of repeating it, permitted subject to conditions in Article 20 of Cabinet Resolution No. 134 of 2025: immediate access to the information, the ability to obtain underlying documentation without delay, and satisfaction that the third party is regulated and supervised. Ultimate responsibility remains yours either way. Our service is outsourcing, so your file holds the evidence, not a promise that someone else holds it.

Where risk is higher: politically exposed persons and their family members and close associates, connections to high-risk jurisdictions, complex or unusually large transactions without apparent economic purpose, opaque ownership, and anything your risk assessment classifies as high risk. EDD requires source of funds and source of wealth analysis, deeper verification, closer ongoing scrutiny, and senior management approval to establish or continue the relationship [Cabinet Resolution No. 134 of 2025, Article 5(2)(c)].

Three triggers apply to everyone: establishing a business relationship, suspicion of ML, TF, or PF regardless of any threshold, and doubt about the veracity or adequacy of identification data you already hold. The monetary triggers are narrower. Financial institutions apply CDD to occasional transactions at or above AED 55,000, whether in one operation or several that appear linked, and to wire transfers at or above AED 3,500. VASPs apply this to occasional transactions of AED 3,500 or more [Cabinet Resolution No. 134 of 2025, Article 7]. Thresholds vary by sector and activity, so confirm the position for your licence.

Any natural person who ultimately owns or controls 25% or more of a legal person, whether directly or indirectly. Where no such person is identified, or doubt remains, the obligation cascades to any natural person exercising control by other means, and failing that to the natural persons holding senior management positions [Cabinet Resolution No. 134 of 2025, Article 10]. Take reasonable measures to verify their identity, not just record their names.

There is no single interval. Periodic review frequency should follow the customer’s risk rating: high-risk relationships are reviewed more often, typically annually, and lower ratings less frequently. Separately, files must be updated for events such as document expiry, ownership or control changes, changes to the relationship, and any doubt about previously obtained information. The underlying obligation is to keep CDD information current, not to check it on a fixed date.

A scoped project to bring a defined population of existing customer files up to current standards, usually triggered by an inspection finding, a change in the law, an acquisition, or the discovery that historic onboarding was inconsistent. The realignment to Federal Decree-Law No. 10 of 2025 is a current driver, since files built under the repealed 2018 framework do not automatically meet the current requirements. Remediation is finite and deadline-driven, which is why firms usually outsource it first.

Banks must obtain a notice of no objection from the Central Bank before outsourcing an activity. The definition of outsourcing is broad, covering arrangements with any party inside or outside the UAE, including related parties, to perform continuously an activity the bank could undertake itself [CBUAE Outsourcing Regulation for Banks, Circular No. 14/2021]. We build that approval step into the mobilisation timeline rather than discovering it at go-live.

Yes, and this is the single most important operational point. Your records must be complete and retrievable promptly on request [Cabinet Resolution No. 134 of 2025, Article 25]. Files and evidence are delivered into your systems in a form you can produce yourself, and you keep the playbook and procedures if the arrangement ends. A provider holding your evidence in their own system is a retrieval problem waiting for an inspection.

They solve different problems. Software delivers throughput and consistency on mechanical checks: identity verification, screening, workflow, storage. A managed service supplies judgement and capacity for the work that requires reading, reasoning, and chasing, such as working a beneficial ownership chain through multiple jurisdictions or testing whether a source of wealth explanation holds together. Most firms at scale need both. If you are choosing a platform, our AML software selection service covers requirements and vendor evaluation.

Keep the obligation. Lose the backlog.

One short form, one focused conversation, and a scoped arrangement. A CAMS-certified specialist will come back with the model, timeline, and price.