KYC and CDD Services
KYC and CDD managed services means we run your customer due diligence operation, onboarding checks, identity verification, beneficial ownership, sanctions and PEP screening, enhanced due diligence, periodic review, and remediation, performed by trained analysts under your policies and in accordance with UAE law. Cabinet Resolution No. 134 of 2025 sets out what due diligence must achieve [Articles 6 to 10].
One principle needs to be clear before anything else, because it’s what firms most often get wrong when they outsource. You can outsource the work. You cannot outsource the obligation. When an inspector asks why a customer was onboarded, the answer cannot be that a service provider handled it. The file has to be yours, the decision has to be traceable, and you have to be able to retrieve the records. Every part of how we run this service is built around that constraint rather than around ways to work past it.
Your obligation. Our capacity.
Get trained KYC and CDD analysts running your files to UAE law, with the evidence trail staying yours.
What Are KYC Managed Services?
A managed service is an operating arrangement, not software or a consulting report. We take a defined part of your customer due diligence workload and run it continuously: receiving cases, performing checks to your standards, escalating what needs a decision, and leaving behind a file that would satisfy your supervisor. You keep the policy, the risk appetite, the compliance officer, and the final say on any relationship.
Firms come to this for three reasons.
Capacity
Where volume exceeds what the internal team can process, and files are ageing.
Capability
Where the business has grown into obligations nobody in-house has done before, such as layered beneficial ownership or enhanced due diligence on high-risk customers.
Remediation
Where a backlog or an inspection finding means a defined population of existing files has to be brought up to standard against a deadline.
What a managed service is not: a way to make the obligation someone else’s problem. If a provider offers that, they are describing something the law doesn’t permit, and the arrangement will fail at the first inspection.
KYC vs CDD: What Is the Difference?
Used interchangeably in conversation, but they are not the same thing, which matters when a supervisor or a bank asks you a precise question.
KYC, know your customer
is the identification and verification step: establishing who the customer is and confirming it with reliable, independent documents or data. It is a component, and it is the one most people picture.
CDD, customer due diligence
is the whole obligation. It includes identification and verification, but also understanding the purpose and intended nature of the relationship, identifying and verifying beneficial owners, screening, assessing customer risk, and monitoring the relationship on an ongoing basis. Where the law imposes duties, it imposes them as CDD. [Cabinet Resolution No. 134 of 2025, Articles 6 to 10]
[Cabinet Resolution No. 134 of 2025, Articles 6 to 10]
EDD, enhanced due diligence
is the intensified version applied where risk is higher: source of funds and wealth, closer scrutiny, more frequent review, and senior management approval to begin or continue the relationship.
[Cabinet Resolution No. 134 of 2025, Article 5(2)(c)]
SDD, simplified due diligence
is the reduced version, permitted only where your risk assessment genuinely supports it, it is documented as such, and it is applied in coordination with your Supervisory Authority. It is not a shortcut for busy periods, and it never reduces your targeted financial sanctions obligations.
[Cabinet Resolution No. 134 of 2025, Article 5(3)]
KYB and KYS
know your business and know your supplier, extend the same discipline to corporate counterparties and to your supply chain. Neither is a separate legal obligation in the AML framework, yet banks and counterparties increasingly expect both.
The practical consequence: a firm that has done KYC and believes it has done CDD is usually missing the purpose of the relationship, the beneficial owner verification, or the ongoing monitoring, and those are exactly the three gaps a file review finds.
Customer Due Diligence vs Commercial or Financial Due Diligence
Worth separating, because the phrase due diligence services covers two unrelated markets in the UAE. Commercial, financial, vendor, and transaction due diligence are M&A and investment exercises: examining a target company’s accounts, contracts, and commercial position before a deal. That is transaction advisory work and not what this page offers. Customer due diligence is an AML compliance obligation performed on the people and entities you do business with, continuously, under Cabinet Resolution No. 134 of 2025. If you need the first, an audit or corporate finance firm is the right call.
What Is Customer Due Diligence Under UAE Law?
CDD is the set of measures a reporting entity must apply to identify and understand its customers and the risk they present, before or during the establishment of the relationship and continuously thereafter. Under the Executive Regulations it requires you to identify the customer and verify identity using reliable independent source documents, data, or information; understand the purpose and intended nature of the business relationship; identify beneficial owners and take reasonable measures to verify them; and conduct ongoing due diligence across the life of the relationship, keeping documents and information current [Cabinet Resolution No. 134 of 2025, Articles 6 to 10].
Two features of the obligation catch firms out. It is continuous rather than a gate at onboarding, so a file that was compliant on day one and untouched for four years is no longer compliant. It is also risk-based, so the depth of due diligence must reflect the risk the customer presents as assessed in your business risk assessment, which means an identical process applied to every customer suggests no risk assessment is driving it.
Can You Outsource KYC and CDD in the UAE?
Yes, and the legal detail matters more here than anywhere else on this page, because two different arrangements get called outsourcing and they carry different obligations.
Outsourcing, which is what a managed service is
A third party performs due diligence work on your behalf, under your policies, to your standards, using your risk criteria. The obligation remains entirely yours, the records are yours, and you supervise the arrangement. Nothing in UAE law prevents this, and it is how most compliance operations at scale actually run. What the law will examine is whether you retained control: your policy governed the work, your compliance officer made the decisions that needed judgement, and your records are complete and retrievable [Cabinet Resolution No. 134 of 2025, Article 20 (3)].
Reliance on a third party, which is something else
Relying on due diligence already performed by another regulated party, for example, accepting the onboarding a bank or fellow institution has done rather than repeating it. This is permitted subject to conditions set out in Article 20 of Cabinet Resolution No. 134 of 2025, and those conditions are the point: you must be able to obtain the information immediately, be able to get the underlying documentation without delay on request, and satisfy yourself that the third party is regulated and supervised. Ultimate responsibility stays with you regardless.
Firms conflate the two, and it causes real problems, because reliance carries conditions that outsourcing does not, and outsourcing carries supervision duties that reliance does not. Our service is outsourcing. We do not ask you to rely on due diligence we performed for somebody else, and your file will contain the underlying evidence rather than an assurance that it exists elsewhere.
Not sure which arrangement you actually have?
Send us your current provider's contract and we will tell you whether it is outsourcing or reliance, and what that means for your files.
UAE AML Laws Behind KYC and CDD
Every check we perform traces to a provision, and every file we build is designed to be read by someone holding these instruments:
| Legal Instrument | What It Requires | How It Shapes the Service |
|---|---|---|
| Cabinet Resolution No. 134 of 2025, Articles 6 to 9 | Identification and verification before or during the relationship, understanding its purpose and intended nature, CDD for occasional transactions at or above AED 55,000 and wire transfers at or above AED 3,500 for financial institutions, and ongoing due diligence across the relationship. | The core workflow, including the thresholds that determine when an occasional customer becomes a due diligence case. Getting the trigger points wrong is the most common structural error we correct. |
| Cabinet Resolution No. 134 of 2025, Article 10 | Identification of every natural person owning or controlling 25% or more, with the fallback cascade to persons exercising control and then to senior management, and reasonable measures to verify them. | Beneficial ownership work, which is where files most often thin out. Verifying a UBO through two layers of corporate structure is slow, and slow is exactly why it gets skipped. |
| Cabinet Resolution No. 134 of 2025, Articles 5(2)(c) and 5(3) | Enhanced due diligence for high-risk situations including source of funds and wealth and senior management approval, and simplified due diligence only where the risk assessment supports it and in coordination with the Supervisory Authority. | EDD triggers and depth, and the discipline that simplified due diligence is a documented decision rather than a busy-period shortcut. |
| Cabinet Resolution No. 134 of 2025, Article 20 | Conditions for relying on customer due diligence performed by a third party, including immediate access to the information, ability to obtain underlying documentation without delay, and continuing ultimate responsibility. | The line between outsourcing and reliance. Our arrangement is outsourcing, so your file holds the evidence rather than a promise that someone else holds it. |
| Cabinet Resolution No. 134 of 2025, Articles 16 and 23 | PEP identification covering family members and close associates, and countermeasures for high-risk countries. | Screening scope and the country risk rules applied at onboarding and on review. |
| Cabinet Resolution No. 74 of 2020 | Targeted financial sanctions: screening against UN and UAE Local Terrorist Lists, freezing without delay, and reporting to the Executive Office for Control and Non-Proliferation. | Screening at onboarding and on an ongoing basis, with a defined escalation path that reaches your compliance officer rather than stopping with an analyst. |
| Cabinet Resolution No. 134 of 2025, Articles 19, 22 and 25 | Tipping-off prohibition and reporting procedures, the compliance officer at management level, and record keeping with prompt retrieval. | Confidentiality rules for analysts, escalation into your officer's decision, and file construction designed so records can be produced promptly on request. |
| Federal Decree-Law No. 10 of 2025 | The primary AML/CFT/CPF statute in force 14 October 2025, repealing FDL No. 20 of 2018 (Article 41). Risk-based preventive measures (Article 19), STR duties (Article 18), and administrative penalties of AED 10,000 to AED 5,000,000 per violation (Article 17). | The framework the whole operation answers to, and the reason files built under the 2018 law need review rather than assumption. |
| CBUAE Outsourcing Regulation for Banks, Circular No. 14/2021 | Bank outsourcing governance: a notice of no objection from the Central Bank before outsourcing, the board remaining responsible for outsourced activities, and Article 6 requiring the Master System of Record including confidential data to be maintained within the UAE. | For bank clients this determines the approval step, the supervision arrangement, and where data may sit. We build the no-objection process into the mobilisation timeline rather than discovering it later. |
| Federal Decree-Law No. 45 of 2021 (Personal Data Protection Law) | Restrictions on cross-border transfer of personal data (Article 23), breach notification (Article 9), and controller duties when appointing processors offering sufficient guarantees. | We process your customers' personal data on your instructions, which makes you controller and us processor, with the contract, location, and security terms that follow from it. |
| Cabinet Resolution No. 71 of 2024 and sectoral guidance | The DNFBP penalty schedule (41 listed violations, AED 50,000 to AED 1,000,000, doubling on recurrence within a year), MoET Guidelines for DNFBPs (September 2025), and the DFSA and FSRA rulebooks. | The standard files are built to withstand, expressed in the terms your own supervisor uses. |
The sentence to remember : outsourcing the work does not outsource the obligation, and for banks the board remains responsible for outsourced activities [CBUAE Outsourcing Regulation for Banks, Circular No. 14/2021]. Any provider who tells you otherwise is selling you a finding.
CDD Thresholds in the UAE: When Due Diligence Triggers
Due diligence is not only an onboarding event. It is triggered by circumstances, and the trigger points are specific:
Establishing a business relationship
dentification and verification before or during establishment, with the relationship’s purpose and intended nature understood and recorded.
Whether carried out in a single operation or in several that appear linked (applicable to financial institutions), which is why structuring detection matters at the counter as well as in monitoring.
Wire transfers at or above AED 3,500
With the originator and beneficiary information the transfer rules require (applicable to financial institutions).
Suspicion of ML, TF, or PF
Regardless of any threshold or exemption, and regardless of whether the customer is established.
Doubts about previously obtained data
Where the identification information you hold is no longer reliable or adequate, verification must be repeated.
Thresholds differ by sector and activity, and VASPs in particular operate to different occasional transaction limits. We configure the trigger rules to your licence rather than applying a single set across every client.
Enhanced Due Diligence: When It Applies and What It Requires
EDD applies where risk is higher, and the situations are not a matter of preference: politically exposed persons and their family members and close associates, customers or transactions connected to high-risk jurisdictions, complex or unusually large transactions without an apparent economic purpose, opaque ownership structures, and any situation your own risk assessment classifies as high risk.
What EDD looks like done properly. Article 5(2)(c) introduces these measures as examples rather than a closed checklist, and expects you to apply the ones proportionate to the risk you have identified:
Source of funds and source of wealth
Two different questions. Source of funds is where this money came from; source of wealth is how the customer accumulated their assets overall. Files that answer only the first are the most common EDD weakness we find.
Payment from customer’s own bank account
Where it fits the risk, take the first payment through an account in the customer’s own name held with a financial institution that is itself subject to equivalent due diligence standards.
Senior management approval
To establish or continue the relationship, evidenced with a name and a date rather than implied by the account being open. [Cabinet Resolution No. 134 of 2025, Article 5(2)(c)]
Deeper verification
Additional independent corroboration of identity, ownership, and the rationale for the structure or transaction.
Closer ongoing scrutiny
More frequent review and tighter monitoring parameters, set at onboarding rather than promised.
We perform the analytical work and prepare the file to the point of decision. The approval itself is yours, because it is a judgement the law assigns to your senior management.
Beneficial Ownership Verification to the 25% Standard
Identifying every natural person who owns or controls 25% or more of a legal person, and where no such person exists or doubt remains, applying the cascade to those exercising control by other means and then to the natural persons holding senior management positions [Cabinet Resolution No. 134 of 2025, Article 10]. Your beneficial ownership register duties sit alongside this [Cabinet Resolution No. 109 of 2023].
This is the slowest part of onboarding and the part most often abandoned halfway. A UAE holding company owned by an offshore entity owned by a trust is three registries, two jurisdictions, and often a document in another language. The temptation is to record the first layer and move on, and the resulting file names an owner who is not the beneficial owner. We work the structure to the natural person, document each layer with its evidence, and flag where the chain genuinely cannot be completed so your compliance officer can make an informed decision rather than an assumed one.
KYC Periodic Review, KYC Update and CDD Remediation
Three related activities that firms treat as one and should not.
Periodic review
Scheduled re-examination of a file at a frequency set by customer risk rating, typically annual for high risk and longer for lower ratings. Driven by the calendar and your risk model.
KYC update, or refresh
Refreshing expired documents and changed data: a lapsed passport, a new address, a change of authorised signatory, an ownership change. Driven by events and expiries rather than the calendar.
CDD remediation
A project to bring a defined population of existing files up to current standard, usually after an inspection finding, a change in the law, an acquisition, or the discovery that historic onboarding was inconsistent. Finite, scoped, and deadline-driven.
Remediation is where managed services earn their reputation, because the work is high-volume, time-boxed, and painful to absorb into a team that also has to onboard new business. It is also where the realignment to Federal Decree-Law No. 10 of 2025 is currently generating demand, since files built under the repealed 2018 framework do not automatically satisfy the current one.
KYC Outsourcing Models: Full, Overflow, Remediation and Targeted Support
| Model | Best For | How It Works |
|---|---|---|
| Full managed service | Firms without an internal KYC team, or with one that is fully occupied elsewhere | We run the whole CDD operation to your policy: onboarding, screening, EDD preparation, periodic review, and refresh, with escalation into your compliance officer |
| Overflow capacity | Seasonal peaks, campaign onboarding, or growth outpacing hiring | Your team handles business as usual and routes surplus volume to us, on the same standards and templates, so files are indistinguishable |
| Remediation project | Inspection findings, backlogs, acquisitions, or realignment to the 2025 framework | A defined population, a defined standard, a deadline, and a tracker your compliance officer and your supervisor can both follow |
| EDD only | Firms comfortable with standard onboarding but stretched by high-risk cases | We take the complex files: layered ownership, PEPs, source of wealth, high-risk jurisdictions, prepared to the point of your approval decision |
| Quality assurance only | Firms with an internal team wanting independent file testing rather than production | Sample-based file review against your policy and the law, with findings, patterns, and analyst-level feedback |
How Our Managed KYC Service Works, Step by Step
- Scoping and standards alignment
Your licence, supervisor, policy, risk model, and customer types, so our analysts apply your standards rather than generic ones.
- Arrangement design
Outsourcing agreement, data protection terms, systems access, software integration, and provisioning of screening and watchlist access.
- Playbook build
Documented procedures, checklists, escalation rules, and quality standards specific to you, so decisions are consistent and reviewable.
- Analyst training and pilot
A pilot batch worked and reviewed with your compliance officer before volume starts, which is where standards get calibrated.
- Production
Cases received, checks performed, screening run, structures worked, files built, and anything requiring judgement escalated to your officer with the analysis complete.
- [Cabinet Resolution No. 134 of 2025, Articles 6 to 10]
- Quality assurance
Internal sampling of our own output against your playbook, with results reported to you rather than kept in-house.
- Reporting and governance
Volumes, turnaround, escalations, and quality metrics on a regular cycle, so your officer can supervise the arrangement and evidence that supervision.
- Handback and records
Files and evidence delivered into your systems in a form you can retrieve promptly, with retention aligned to your obligations.
- [Cabinet Resolution No. 134 of 2025, Article 25]
KYC and CDD Services: What You Receive
Deliverable
What It Does
Completed CDD files
Built to your policy and the Executive Regulations, structured so an inspector can follow the reasoning
Documented KYC playbook
Your procedures, checklists, and escalation rules, which stay yours if the arrangement ends
Beneficial ownership analysis
Structures worked to the natural person with each layer evidenced, and unresolvable chains flagged rather than assumed
Screening records
Sanctions, PEP, and adverse media results with disposition reasoning, not just a cleared status
EDD packs
Source of funds and source of wealth analysis prepared to the point of your senior management decision
Customer risk ratings
Applied using your model, with the rationale recorded so ratings can be defended and re-tested
Periodic review and refresh schedule
Driven by risk rating and document expiry, with a tracker your officer runs
Quality assurance reporting
Our own sampling results, error patterns, and corrective actions, reported to you
Management information
Volumes, turnaround, escalation rates, and ageing, which is also the evidence that you supervised the arrangement
See which model fits your volumes
A 15-minute call is usually enough. Tell us your customer types and monthly volume and we will map the arrangement.
Data Protection in Outsourced KYC
Outsourced KYC means someone else handling your customers’ identity documents, addresses, ownership details, and, in EDD cases, their financial histories. That is among the most sensitive data your business holds, and how it is handled deserves a straight answer, not reassurance.
Under the Personal Data Protection Law, you are the controller, and we are the processor, which means we act on your documented instructions. You retain the accountability [Federal Decree-Law No. 45 of 2021].
KYC Software or KYC Managed Services?
A question worth answering plainly, because they solve different problems and firms often buy the wrong one.
Software solves a throughput and consistency problem
It verifies identities, runs screening, stores files, and enforces a workflow. It does not decide whether a beneficial ownership chain is credible, judge whether a source-of-wealth explanation holds together, or work a structure through three registries in two languages.
A managed service solves a capacity and judgement problem
Trained analysts perform the work that requires reading, reasoning, and chasing, which is most of what a difficult file consists of.
Most firms at scale need both, and the sequencing usually runs software first for the mechanical checks and people for the exceptions. If you are choosing between platforms, our AML software selection service runs that as a structured process, and if you already have a screening system, our testing and validation service establishes whether it is doing what you think it is.
Choosing a KYC Service Provider in the UAE
Since the market has widened considerably, here are the questions that separate providers, and we would rather you ask them of everyone, including us.
Whose policy governs the work?
If the provider applies its own standard rather than yours, your files will align with someone else’s risk appetite.
Where do the records live, and can you retrieve them promptly?
Prompt retrieval is the legal standard [Cabinet Resolution No. 134 of 2025, Article 25]. A provider holding your evidence in their system is a retrieval problem waiting for an inspection.
Is this outsourcing or reliance?
Different legal tests, different conditions, and providers aren’t always clear about what they are offering.
Who makes the decisions that require judgement?
Define escalation to your compliance officer; don’t improvise it.
What are the data protection terms?
Location, access, sub-processors, breach notification, and exit.
How do you measure quality, and do you see the results?
A provider that samples its own work and reports the errors to you is telling you something a testimonial cannot.
Who Needs KYC and CDD Services in the UAE?
Banks, exchange houses, and payment providers
High onboarding volumes, complex structures, and the strictest supervisory expectations, with the Circular No. 14/2021 approval path applying to banks.
[Cabinet Resolution No. 134 of 2025, Article 2]
DNFBPs
Real estate brokers, dealers in precious metals and stones, corporate service providers, lawyers, notaries, and accountants, where CDD arrives in bursts around transactions rather than steadily
[Cabinet Resolution No. 134 of 2025, Article 3]
VASPs and fintechs
Fast onboarding, digital-first customers, and different occasional transaction thresholds, where the pressure is to keep due diligence rigorous at speed.
[Cabinet Resolution No. 134 of 2025, Articles 4, 7(3) and 36]
Insurers and insurance intermediaries.
Policyholder and beneficiary due diligence, where the beneficiary may not appear until a claim.
Firms under a remediation deadline.
Where a supervisor, a bank, or an acquisition has created a defined population of files that must be brought to standard by a date.
Penalties for Inadequate Customer Due Diligence
- Administrative penalties. AED 10,000 to AED 5,000,000 per violation, plus warnings, licence restrictions, and public naming. CDD failures are counted per breach so that a systemic file weakness can trigger multiple penalties rather than a single one. [Federal Decree-Law No. 10 of 2025, Article 17]
- The DNFBP penalty schedule. 41 listed violations at AED 50,000 to AED 1,000,000 for MoET- and MoJ-supervised businesses, doubling if the same violation recurs within one year. [Cabinet Resolution No. 71 of 2024]
- The commercial cost that arrives first. Banks review correspondent and account relationships based on CDD quality, and a file population that cannot withstand review affects banking access long before a supervisor is involved.
- Accountability does not transfer. Outsourcing the work leaves the obligation with you, and for banks, the board remains responsible for outsourced activities. [CBUAE Outsourcing Regulation for Banks, Circular No. 14/2021]
KYC and CDD by Sector in the UAE
- Real estate brokers and agents
Non-resident buyers, third-party payers, and beneficial ownership through layered purchase vehicles, with transaction-driven volume spikes.
- Dealers in precious metals and stones
The AED 55,000 occasional transaction threshold applied at the counter, walk-in customers, and linked-transaction detection.
- Corporate service providers
The heaviest beneficial ownership work in the market: nominees, trusts, and multi-jurisdiction structures where the 25% test genuinely requires investigation.
- Lawyers, notaries, and accountants
Determining which engagements fall within DNFBP scope, then applying client- and matter-level due diligence without obstructing fee earners.
- Banks and exchange houses
Volume, remittance corridors, and periodic review cycles that generate more work than onboarding does.
- VASPs
Digital onboarding at speed, wallet and counterparty considerations, and the AED 3,500 occasional transaction threshold.
- Supply chain and counterparty due diligence
Know your business and know your supplier checks, which sit outside the strict AML obligation and are increasingly demanded by banks and counterparties.
Why AML UAE for KYC and CDD Managed Services
Running files is a different discipline from advising on them, and we do both, which is the point:
300+
AML compliance projects across FIs, DNFBPs, and VASPs, so our analysts have seen the structures and the red flags rather than only the procedures
1000+
EWRA and AML/CFT/CPF policy sets delivered, which is why our analysts can apply your policy accurately: we write these documents for a living
750+
professionals trained across 3,000+ hours, and the same training standard is applied internally to the people working your files
Under 4 hours
typical turnaround on compliance queries during an engagement, because a stalled file is a commercial problem as well as a compliance one
One commitment that shapes the arrangement: your files, your playbook, and your records remain yours, delivered into your systems and retrievable by you. If you end the arrangement, you keep everything needed to carry on, including the procedures we built. A managed service that leaves you unable to operate without it has created a dependency, not a control.
The Team Behind Your Files

Pathik Shah
CAMS, FCA, CS, CISA, DISA (ICAI), FAFP (ICAI)
Experience
28+ years
Regulatory Coverage
MoET, MoJ, CBUAE, CMA, FSRA, DFSA, VARA · AML/CFT framework design, RegTech

Jyoti Maheshwari
CAMS, ACA
Experience
11+ years
Regulatory Coverage
MoET, MoJ, CBUAE, CMA, FSRA, DFSA, VARA · AML/CFT/CPF framework, health checks

Dipali Vora
CAMS, ACS
Experience
10+ years
Regulatory Coverage
MoET, MoJ, CBUAE, CMA, FSRA, DFSA, VARA · Consulting, training, implementation

Monika Shah
CAMS
Experience
3+ years
Regulatory Coverage
MoET, MoJ, CBUAE, CMA, FSRA, DFSA, VARA · managed KYC, consulting, goAML reporting
What Our KYC File Reviews Have Found
The onboarding that stopped at layer one
A corporate service provider had complete files on every entity it onboarded and had recorded the immediate shareholder in each case. In roughly a third of files, the immediate shareholder was itself a company, and the natural person behind it had never been identified. Every file looked finished. The remediation was not complicated; it was simply a matter of volume, and it required a defined project rather than an instruction to the team to catch up.
Source of funds without source of wealth
An EDD population where every file answered where the money for this transaction came from and none addressed how the customer had accumulated their wealth overall. The distinction sounds academic until an inspector asks the second question, at which point a file that answers only the first shows that the EDD was procedural rather than analytical.
Periodic review that had quietly stopped
Reviews were scheduled by risk rating, and the schedule was being followed for the customers who had a rating. A batch onboarded during a system migration had never been rated, so it never entered the review cycle and went untouched for four years. Nobody had done anything wrong on any given day, which is how the most durable gaps form.
FAQs on KYC and CDD Services in the UAE
KYC, or know your customer, is the identification and verification of a customer’s identity using reliable, independent source documents, data, or information. In UAE law, it forms part of the wider customer due diligence obligation set out in Articles 6 to 10 of Cabinet Resolution No. 134 of 2025.
KYC is the identification and verification step. CDD (customer due diligence) is the full obligation: identification and verification, understanding the purpose and intended nature of the relationship, identifying and verifying beneficial owners, screening, risk rating, and ongoing monitoring. Where the law imposes duties, it imposes them as CDD, so a firm that has done KYC has completed one component rather than the requirement.
The measures required to identify and understand your customers and the risk they present, applied before or during the establishment of a business relationship and continuously thereafter, and calibrated to risk. It requires identity verification from reliable independent sources, understanding the relationship’s purpose, beneficial ownership identification to the 25% standard, and ongoing due diligence keeping information current [Cabinet Resolution No. 134 of 2025, Articles 6 to 10].
Yes. A third party may perform the work on your behalf under your policies and standards. What cannot be outsourced is the obligation: the records remain yours and must be retrievable promptly [Cabinet Resolution No. 134 of 2025, Article 25], your compliance officer retains the decisions requiring judgement, and you must supervise the arrangement. For banks, the board remains responsible for outsourced activities, and a Central Bank notice of no objection applies before outsourcing [CBUAE Outsourcing Regulation for Banks, Circular No. 14/2021].
Outsourcing means someone performs the work for you under your policy, with the obligation and the records staying with you. Reliance means accepting due diligence already performed by another regulated party instead of repeating it, permitted subject to conditions in Article 20 of Cabinet Resolution No. 134 of 2025: immediate access to the information, the ability to obtain underlying documentation without delay, and satisfaction that the third party is regulated and supervised. Ultimate responsibility remains yours either way. Our service is outsourcing, so your file holds the evidence, not a promise that someone else holds it.
Where risk is higher: politically exposed persons and their family members and close associates, connections to high-risk jurisdictions, complex or unusually large transactions without apparent economic purpose, opaque ownership, and anything your risk assessment classifies as high risk. EDD requires source of funds and source of wealth analysis, deeper verification, closer ongoing scrutiny, and senior management approval to establish or continue the relationship [Cabinet Resolution No. 134 of 2025, Article 5(2)(c)].
Three triggers apply to everyone: establishing a business relationship, suspicion of ML, TF, or PF regardless of any threshold, and doubt about the veracity or adequacy of identification data you already hold. The monetary triggers are narrower. Financial institutions apply CDD to occasional transactions at or above AED 55,000, whether in one operation or several that appear linked, and to wire transfers at or above AED 3,500. VASPs apply this to occasional transactions of AED 3,500 or more [Cabinet Resolution No. 134 of 2025, Article 7]. Thresholds vary by sector and activity, so confirm the position for your licence.
Any natural person who ultimately owns or controls 25% or more of a legal person, whether directly or indirectly. Where no such person is identified, or doubt remains, the obligation cascades to any natural person exercising control by other means, and failing that to the natural persons holding senior management positions [Cabinet Resolution No. 134 of 2025, Article 10]. Take reasonable measures to verify their identity, not just record their names.
There is no single interval. Periodic review frequency should follow the customer’s risk rating: high-risk relationships are reviewed more often, typically annually, and lower ratings less frequently. Separately, files must be updated for events such as document expiry, ownership or control changes, changes to the relationship, and any doubt about previously obtained information. The underlying obligation is to keep CDD information current, not to check it on a fixed date.
A scoped project to bring a defined population of existing customer files up to current standards, usually triggered by an inspection finding, a change in the law, an acquisition, or the discovery that historic onboarding was inconsistent. The realignment to Federal Decree-Law No. 10 of 2025 is a current driver, since files built under the repealed 2018 framework do not automatically meet the current requirements. Remediation is finite and deadline-driven, which is why firms usually outsource it first.
Banks must obtain a notice of no objection from the Central Bank before outsourcing an activity. The definition of outsourcing is broad, covering arrangements with any party inside or outside the UAE, including related parties, to perform continuously an activity the bank could undertake itself [CBUAE Outsourcing Regulation for Banks, Circular No. 14/2021]. We build that approval step into the mobilisation timeline rather than discovering it at go-live.
Yes, and this is the single most important operational point. Your records must be complete and retrievable promptly on request [Cabinet Resolution No. 134 of 2025, Article 25]. Files and evidence are delivered into your systems in a form you can produce yourself, and you keep the playbook and procedures if the arrangement ends. A provider holding your evidence in their own system is a retrieval problem waiting for an inspection.
They solve different problems. Software delivers throughput and consistency on mechanical checks: identity verification, screening, workflow, storage. A managed service supplies judgement and capacity for the work that requires reading, reasoning, and chasing, such as working a beneficial ownership chain through multiple jurisdictions or testing whether a source of wealth explanation holds together. Most firms at scale need both. If you are choosing a platform, our AML software selection service covers requirements and vendor evaluation.
Keep the obligation. Lose the backlog.
One short form, one focused conversation, and a scoped arrangement. A CAMS-certified specialist will come back with the model, timeline, and price.