Sanctions Screening UAE: Complete AML Compliance Guide
Sanctions screening is one of those AML compliance tasks that can easily become a checkbox exercise. A business runs a customer's name through a screening system, gets no obvious match and moves on.
But effective sanctions compliance in the UAE involves much more than that.
Businesses need to know who they are dealing with, who ultimately owns or controls a customer, which parties are involved in transactions, which sanctions lists apply and what to do when a potential or confirmed match appears.
This is particularly important for Financial Institutions (FIs), Designated Non-Financial Businesses and Professions (DNFBPs) and Virtual Asset Service Providers (VASPs) that fall within the UAE's AML/CFT and Targeted Financial Sanctions (TFS) framework. The UAE Central Bank and Ministry of Economy & Tourism provide specific guidance on sanctions screening and TFS compliance.
In this guide, we'll explain sanctions screening in the UAE, including who needs to be screened, which lists businesses should monitor, when screening should take place, what counts as a potential or confirmed match, and what businesses should do when a match is identified.
What Is Sanctions Screening?
Sanctions screening is the process of checking customers, beneficial owners, counterparties and other relevant parties against applicable sanctions lists.
In the UAE, Targeted Financial Sanctions include measures connected to the UAE Local Terrorist List and the UN Security Council Consolidated List. The UAE framework requires relevant businesses to implement applicable sanctions measures without delay.
Depending on the business and transaction, screening may cover:
- Customers
- Potential customers
- Beneficial owners
- Directors
- Senior management
- Authorised signatories
- Agents
- Beneficiaries
- Payers and recipients
- Intermediaries
- Other relevant transaction parties
The objective is straightforward:
Identify sanctions exposure before the business unknowingly provides funds, assets or services to a designated person or entity.
What Are Targeted Financial Sanctions in the UAE?
Targeted Financial Sanctions, or TFS, are financial restrictions imposed on designated individuals, entities or groups.
The UAE implements relevant United Nations Security Council sanctions and maintains its own Local Terrorist List. Businesses covered by the framework must have appropriate systems and procedures to identify designated persons and take the required action.
TFS compliance is therefore closely connected with AML/CFT compliance, but it is not exactly the same thing as general AML transaction monitoring.
A business can have a strong transaction-monitoring system and still have weaknesses in its sanctions-screening process.
Who Needs Sanctions Screening in the UAE?
Sanctions requirements can apply to different types of businesses depending on their activities and regulatory status.
They are particularly relevant to:
- Financial Institutions
- Designated Non-Financial Businesses and Professions
- Virtual Asset Service Providers
- Other regulated or supervised entities covered by the applicable UAE TFS framework
For DNFBPs, sanctions compliance is specifically included within the UAE's AML/CFT compliance framework. The Ministry of Economy & Tourism's current DNFBP guidance identifies sanctions screening and compliance with targeted financial sanctions as part of the required AML/CFT/CPF control environment.
The exact requirements can differ according to the sector and Supervisory Authority, so businesses should always consider the rules applicable to their particular activity.
Which Sanctions Lists Should UAE Businesses Check?
Businesses should make sure their sanctions-screening process covers the applicable official lists.
1. UN Security Council Consolidated List
The United Nations publishes the consolidated list of individuals and entities designated under relevant Security Council sanctions regimes.
2. UAE Local Terrorist List
The UAE maintains its own Local Terrorist List.
The CBUAE directs supervised financial institutions to use official sources for the latest versions of the relevant sanctions lists and to remain aware of changes. It also requires LFIs to register with the Executive Office to receive automated notifications of updates.
Don't Rely on an Old Sanctions List
This is an easy mistake to make.
Sanctions lists can change. A person who was not listed when a customer was onboarded could be designated later.
Your screening process therefore needs a mechanism for receiving updates and screening the relevant customer and transaction data after list changes.
When Should Sanctions Screening Be Performed?
Sanctions screening should not be treated as a one-time KYC exercise.
Before Customer Onboarding
Businesses should screen customers before establishing the relationship.
For CBUAE-regulated financial institutions, the rulebook states that name screening should be performed before onboarding and before facilitating an occasional transaction.
Before Processing a Transaction
Transaction screening should take place at a point where the business can still stop or suspend the transaction if a sanctions concern is identified.
For CBUAE-regulated financial institutions, payments should be screened before completion of the transaction.
When Sanctions Lists Change
When a new designation is published, businesses need to determine whether they have relevant customers or relationships connected to the newly designated person or entity.
During KYC Reviews
If customer information changes, the business should consider whether a new sanctions screening check is necessary.
On an Ongoing Basis
Sanctions risk can change after onboarding.
A customer may:
- Change ownership
- Add a new beneficial owner
- Change directors
- Begin dealing with new jurisdictions
- Start using new counterparties
- Become subject to a new designation
Ongoing screening helps businesses identify these changes.
For CBUAE-regulated LFIs, current guidance states that name screening should be conducted on an ongoing basis, with at least daily screening specified in the relevant guidance.
Who Should Be Screened?
A good sanctions-screening programme should go beyond the customer's name.
Customers
Screen both individual and corporate customers.
Beneficial Owners
This is particularly important for companies.
A company may not appear on a sanctions list, but its ultimate beneficial owner could be designated.
The CBUAE requires relevant LFIs to have systems for identifying whether a customer or beneficial owner has been added to an applicable sanctions list.
Directors and Senior Management
Depending on the applicable requirements and information collected during CDD, relevant individuals acting for or controlling a legal entity should also be considered.
Authorised Signatories
Someone signing or acting on behalf of the customer can be relevant to sanctions screening.
Transaction Parties
Depending on the transaction, screening may need to cover:
- Originator
- Beneficiary
- Buyer
- Seller
- Intermediary
- Agent
- Financial institution
- Other relevant parties
For financial institutions, CBUAE guidance specifically highlights the importance of screening available information relating to payers, payees and intermediaries.
What About Trade Transactions?
Sanctions screening becomes even more important when a business is involved in international trade.
Trade transactions can contain many parties and documents, including:
- Buyers
- Sellers
- Banks
- Agents
- Shipping companies
- Consignees
- Freight forwarders
- Vessels
- Ports
- Invoices
- Bills of lading
- Customs documents
The CBUAE's current guidance highlights the importance of screening trade-related information and, where appropriate, documentation such as invoices, bills of lading, shipping documents and customs declarations.
This is one reason why simply screening the customer's legal name may not be enough for businesses with significant international trade exposure.
What Information Should Be Used for Screening?
A name alone is rarely enough to establish whether a person is actually sanctioned.
Businesses should use available identifying information such as:
- Full name
- Former names
- Aliases
- Date of birth
- Nationality
- Address
- Passport or identification information
- Company registration information
- Ownership information
- Other relevant identifiers
This helps distinguish a genuine match from a false positive.
For example, your customer might have the same name as someone on a sanctions list but have a different date of birth, nationality and address.
That could indicate that the screening alert is not actually the sanctioned person.
What Is a Potential Sanctions Match?
A potential match occurs when the information held by the business appears similar to information on a sanctions list, but the business has not yet established whether the person or entity is actually the designated party.
For example:
- The name is identical
- The date of birth is similar
- The nationality is unknown
- The address is different
- Ownership information is incomplete
The business should not simply dismiss the alert.
It should investigate the available information and follow its internal escalation procedure.
What Is a False Positive?
A false positive occurs when a screening system identifies a possible match, but further investigation establishes that the customer is not the designated person or entity.
Common causes include:
- Common names
- Transliteration differences
- Spelling variations
- Different naming conventions
- Similar company names
- Missing identifiers
- Outdated customer information
The CBUAE guidance expects financial institutions to verify potential matches and maintain evidence supporting the false-positive decision.
That last point is important.
Don't simply mark an alert as "false positive" and move on.
Document why it was determined to be a false positive.
What Should a Business Do When a Potential Match Appears?
A practical process can look like this:
Screening alert → Investigation → Identifier comparison → Escalation → Match determination → Required action
The Compliance Officer or relevant sanctions team should review information such as:
- Name
- Date of birth
- Nationality
- Address
- Identification documents
- Company details
- Ownership structure
- Transaction information
The objective is to determine whether the alert is:
False positive → Potential match → Confirmed match
The business should also make sure that employees do not simply override alerts without appropriate review.
What Should You Do If There Is a Confirmed Match?
This is where businesses need to act quickly.
Under the UAE TFS framework, applicable funds or transactions must be frozen or suspended without delay when the relevant sanctions conditions are met. The CBUAE currently states that confirmed or potential matches identified through screening require immediate action for the institutions it supervises.
Businesses should not:
- Warn the customer before taking the required action
- Allow the transaction to continue simply because it is urgent
- Transfer the funds elsewhere
- Release frozen assets without proper authorisation
- Treat the matter as an ordinary KYC issue
Instead, the business should follow the applicable TFS procedure and reporting requirements.
Confirmed Match vs Potential Match
These two situations should not be confused.
Confirmed Match
The business has established that the customer or relevant party is the person or entity designated on the applicable sanctions list.
The required freezing, prohibition and reporting measures should be implemented without delay.
Potential Match
There are similarities, but the business cannot yet establish whether the customer is actually the designated person.
The matter should be escalated and investigated according to the applicable procedure.
For CBUAE-supervised financial institutions, current guidance states that confirmed and potential matches are reported through goAML using the applicable reporting mechanisms, including the Fund Freeze Report (FFR) for confirmed matches and Partial Name Match Report (PNMR) for potential matches.
The precise reporting process can depend on the entity's regulatory framework, so businesses should follow the current instructions of their Supervisory Authority and the UAE FIU.
How Quickly Must a Business Act?
Sanctions compliance is time-sensitive.
The UAE framework uses the concept of implementing freezing measures without delay. The CBUAE's guidance states that, in the applicable context, "without delay" means within 24 hours of the relevant listing decision.
For businesses, the practical lesson is simple:
Don't put sanctions alerts into a normal queue and deal with them days later.
Your AML compliance programme should have an escalation process that allows potentially serious sanctions alerts to be investigated and acted upon immediately.
Sanctions Screening vs AML Transaction Monitoring
These two processes work together but are not identical.
Sanctions Screening
The primary question is:
Is this customer, entity or transaction party connected to a designated person or entity?
Transaction Monitoring
The question is:
Does this customer's activity appear unusual or potentially suspicious based on their profile and expected behaviour?
A business needs both where applicable.
A customer might pass sanctions screening but still generate a transaction-monitoring alert because of unusual activity.
Likewise, a customer could trigger a sanctions alert even when their transaction behaviour does not appear unusual.
Sanctions Screening vs PEP Screening
PEP screening is another AML control that is often confused with sanctions screening.
PEP Screening
Identifies politically exposed persons and related risk.
Sanctions Screening
Identifies designated individuals and entities subject to applicable sanctions.
A person can be:
- A PEP but not sanctioned
- Sanctioned but not a PEP
- Both
- Neither
Therefore, PEP screening cannot replace sanctions screening.
Businesses should maintain separate controls while integrating them into their wider AML/KYC programme.
Manual or Automated Sanctions Screening?
There is no single solution that works for every business.
Businesses may use:
- Manual screening
- Automated screening software
- Integrated AML/KYC platforms
- Internal databases
- Third-party screening providers
The right approach depends on the business's:
- Customer volume
- Transaction volume
- Risk profile
- Geographic exposure
- Products and services
- Regulatory requirements
- Operational resources
The CBUAE states that sanctions-screening controls should be appropriately calibrated to the sanctions risks associated with customers, products, services, delivery channels and geographic exposure.
For a small business with a limited number of customers, a well-controlled manual process may be workable in some circumstances.
For a large financial institution processing thousands of transactions, automated screening is generally much more practical.
What Makes a Good Sanctions Screening System?
Technology alone does not make a sanctions programme effective.
A good programme should include:
Clear Governance
Someone should be responsible for sanctions compliance.
Updated Sanctions Lists
Your business needs a reliable process for receiving list updates.
Appropriate Screening Rules
Screening parameters should reflect the business's risk profile.
Fuzzy Matching
The system should be able to identify relevant name variations where appropriate.
Alert Management
Potential matches should be investigated consistently.
Escalation Procedures
Employees should know when and how to escalate an alert.
Documentation
Decisions should be recorded and supported.
Ongoing Testing
The business should periodically test whether its screening controls actually work.
Common Sanctions Screening Mistakes in the UAE
1. Screening Only at Onboarding
A customer can become sanctioned after the relationship starts.
Ongoing screening is therefore essential.
2. Screening Only the Company's Name
A company's beneficial owner or another relevant party could be designated.
3. Using an Outdated List
An old sanctions list can create a serious compliance gap.
4. Treating Every Match as Confirmed
A name match does not automatically mean it is the designated person.
5. Closing False Positives Without Evidence
A false-positive decision should be properly documented.
6. Ignoring Transaction Parties
Sanctions exposure can arise through counterparties, intermediaries or beneficiaries.
7. Delaying Action on a Potential Match
Sanctions alerts can require immediate escalation and action.
8. Relying Entirely on Software
A screening tool can identify alerts, but trained staff still need to investigate and resolve them.
9. Forgetting About Beneficial Ownership
A company may appear clean while its ultimate beneficial owner creates sanctions exposure.
10. Treating Sanctions Screening as Separate From AML
Sanctions controls should be integrated into the broader AML/CFT/CPF compliance framework.
How to Build a Sanctions Screening Process
A practical process can be structured into ten steps.
Step 1: Identify Your Sanctions Risk
Consider your customers, products, services, countries, payment channels and business partners.
Step 2: Identify Applicable Lists
Make sure your process covers the official UAE and UN sanctions lists relevant to your business.
Step 3: Screen Customers Before Onboarding
Do not establish the relationship before completing the required screening.
Step 4: Screen Beneficial Owners and Relevant Connected Parties
Understand who ultimately owns and controls your customers.
Step 5: Screen Transactions
Screen relevant transaction parties before the transaction is completed where required.
Step 6: Keep Lists Updated
Create a reliable process for receiving sanctions-list updates.
Step 7: Investigate Alerts
Compare identifiers and determine whether the alert is a false positive, potential match or confirmed match.
Step 8: Escalate Quickly
Serious sanctions alerts should go directly to the appropriate Compliance Officer or sanctions function.
Step 9: Freeze or Suspend Where Required
Apply the applicable TFS measures without delay.
Step 10: Report and Document
Submit the required report through the applicable channel and maintain evidence of the investigation and action taken.
Sanctions Screening Checklist for UAE Businesses
Use this as a practical starting point for your internal AML compliance programme:
- Identify applicable sanctions requirements
- Register for relevant sanctions-list notifications
- Screen customers before onboarding
- Screen beneficial owners
- Screen relevant directors and authorised persons
- Screen transaction parties
- Keep sanctions lists updated
- Conduct ongoing screening
- Review potential matches promptly
- Compare multiple identifiers
- Document false-positive decisions
- Escalate confirmed or potential matches
- Freeze or suspend where legally required
- Submit the applicable report
- Maintain complete records
- Test the effectiveness of screening controls
- Train employees involved in sanctions compliance
Frequently Asked Questions
Is sanctions screening mandatory in the UAE?
For businesses covered by the UAE Targeted Financial Sanctions framework, applicable sanctions-screening and compliance obligations are mandatory. The exact requirements depend on the entity and its regulatory framework. UAE authorities specifically require relevant financial institutions and DNFBPs to implement applicable TFS measures.
Which sanctions lists should UAE businesses screen?
The UAE framework includes the UAE Local Terrorist List and the UN Security Council Consolidated List. Businesses should use official sources and maintain a process for receiving updates.
Should beneficial owners be screened?
Yes. Beneficial ownership is an important part of sanctions screening, particularly for corporate customers. CBUAE rules require relevant LFIs to identify whether customers or beneficial owners have been designated.
How often should sanctions screening be performed?
Screening should take place before onboarding and during relevant transactions, with ongoing screening thereafter. For CBUAE-regulated LFIs, current guidance specifies ongoing name screening at least daily.
What should I do if a customer's name matches a sanctions list?
Do not automatically assume it is a confirmed match. Investigate the alert using additional identifiers such as date of birth, nationality, address, identification details and ownership information. If it is a confirmed or potential match, follow the applicable TFS escalation, freezing/suspension and reporting procedures.
Is a sanctions match the same as an STR?
Not necessarily. Sanctions-related matches have their own reporting and TFS procedures. For CBUAE-supervised financial institutions, current guidance provides specific goAML reporting mechanisms for confirmed and potential sanctions matches.
Can a business continue a transaction while investigating a sanctions alert?
Businesses should not simply allow a transaction to proceed as normal when a potential or confirmed sanctions match has triggered the applicable TFS procedure. The required suspension or freezing measures should be applied in accordance with the applicable UAE framework.
Final Thoughts
Sanctions screening in the UAE is not just about putting a customer's name into a database.
An effective sanctions compliance programme should connect KYC, beneficial ownership, customer screening, transaction screening, sanctions-list management, alert investigation, escalation, freezing measures, reporting and record keeping.
The most important thing is to have a process that works before, during and after a sanctions alert.
Before onboarding, screen the customer and relevant connected parties.
During transactions, screen the parties and information that may create sanctions exposure.
After a potential match, investigate it properly and document your decision.
And if a confirmed or applicable potential match is identified, act quickly and follow the UAE's TFS requirements.
Good sanctions screening is not about generating fewer alerts. It is about making sure the right alerts are identified, investigated and acted upon before they become a compliance problem.