Month: July 2026

Sanctions, PEP Screening, and UBO Compliance in UAE 2026: Navigating Geopolitical Risks and New Enforcement

Sanctions, PEP Screening, and UBO Compliance in UAE 2026: Navigating Geopolitical Risks and New Enforcement

PEP and Sanctions Screening Dubai

In June 2026, the Central Bank of the UAE fined a foreign bank branch AED 20 million and personally fined its Head of Compliance AED 300,000, in the same investigation, for failures across anti-money laundering, counter-terrorist financing, and sanctions controls. That single action tells you where 2026 enforcement is headed: institutions and the individuals responsible for their compliance frameworks are now targeted together.

If your business operates in Dubai or anywhere in the UAE, this is the year effective PEP and sanctions screening in Dubai stops being a documentation exercise and becomes a test of whether your controls actually work. The UAE’s next FATF Mutual Evaluation, under the stricter 5th Round Methodology, had its onsite visit in June 2026, and it measures real-world outcomes rather than policies sitting in a drawer. At First Compliance, we build AML and due diligence software for UAE businesses navigating exactly this shift, and this guide breaks down what sanctions, PEP, and UBO compliance actually require heading into the rest of the year.

Why enforcement got sharper in 2026:

Three things changed at once, and together they explain the pressure UAE businesses are feeling right now.

Federal Decree-Law No. 10 of 2025 raised the ceiling on penalties: administrative fines for AML/CFT violations by licensed financial institutions now range from AED 5 million to AED 100 million, with criminal sanctions and imprisonment possible in cases of wilful non-compliance or systemic failure. The April 2026 CBUAE guidance package built on this by formalising proliferation financing as a standalone risk category every institution must assess independently.

CBUAE enforcement moved from institutional fines to personal liability: the AED 20 million penalty mentioned above came with a separate AED 300,000 fine against the bank’s MLRO for failing to meet the responsibilities of the role. This follows a May 2025 case where a branch manager was personally fined AED 500,000 and permanently banned from the UAE financial sector over an AED 200 million sanctions failure. In 2025 alone, CBUAE issued over AED 370 million in AML/CFT fines. The pattern is now established: the institution and the person accountable for the framework are both on the hook.

The FATF 5th Round Mutual Evaluation tests outcomes, not paperwork: the UAE’s national AML/CFT/CPF Committee reported in June 2026 that money laundering cases handled by law enforcement rose nearly 46 per cent year on year, with frozen assets reaching AED 150 million and FIU information requests up 20.7 per cent. Assessors will be looking for evidence that beneficial ownership transparency, sanctions implementation, and cross-border cooperation produce measurable results, not just written procedures.

What sanctions screening actually covers:

Sanctions screening checks whether a customer, director, UBO, or connected party appears on the UAE Local Terrorist List, the UN Consolidated Sanctions List, or other applicable regimes such as OFAC and EU lists. Regulated entities must screen at defined touchpoints:

  • Before onboarding: to prevent a sanctioned individual or entity from entering the relationship in the first place.
  • Immediately after list updates: screening must happen without delay to meet freezing obligations under the UAE’s Targeted Financial Sanctions regime.
  • During periodic KYC reviews: to catch changes in a customer’s risk profile over time.

This is where the biggest gap shows up. A client can pass screening clean on Monday and appear on a sanctions list by Tuesday after a geopolitical event. Point-in-time checks alone leave that gap open, which is exactly why ongoing monitoring, not a one-time check, is what regulators and effective PEP and sanctions screening in Dubai now require.

PEP screening and the risk tier most businesses miss:

Being a politically exposed person is not itself a crime, but it does trigger Enhanced Due Diligence. Regulators typically classify PEPs into four risk tiers based on the seniority and reach of their position. Most compliance programmes screen the PEP directly and stop there, missing Tier 4: relatives and close associates.

RCAs are the blind spot: a corrupt official rarely places illicit funds in their own name. Funds move through a spouse’s, child’s, or associate’s account instead, so screening relatives and close associates carries the same weight as screening the politician. Getting this wrong is one of the most common findings in CBUAE enforcement actions, and it’s a core reason PEP and sanctions screening in Dubai has to go beyond a single-name check.

A practical tip worth knowing: the biggest operational pain point in screening isn’t missed matches; it’s false positives, where a system flags an innocent customer because they share a name with a sanctioned individual. Matching on date of birth and country alongside name, and applying fuzzy logic to catch spelling variants, cuts down false positives without weakening the check itself.

UBO compliance: the register regulators now cross-check:

Under Cabinet Decision No. 109 of 2023, UAE corporate entities must maintain an accurate, complete register of ultimate beneficial owners, with penalties for non-compliance set out in Cabinet Decision No. 132 of 2023. Identifying UBOs is a core part of Customer Due Diligence, and screening the UBO against sanctions and PEP lists is mandatory, not optional. False or misleading UBO information can now trigger criminal as well as administrative sanctions.

By 2026, UBO compliance isn’t a standalone registry task. It sits inside the same AML architecture as sanctions and PEP screening, and regulators expect all three to work together as one system rather than three separate checklists.

Sanctions, PEP, and UBO checks at a glance:

Check

What it verifies

When required

UAE legal basis

Sanctions screening

Match against UN, OFAC, and UAE Local Terrorist List

Onboarding, list updates, periodic review

Federal Decree-Law No. 10 of 2025, TFS regime

PEP screening

Political exposure, including relatives and close associates

Onboarding and ongoing monitoring

Federal Decree-Law No. 10 of 2025, CBUAE guidance

UBO verification

Identity and screening status of beneficial owners

Onboarding and register updates

Cabinet Decision No. 109 & 132 of 2023

How First Compliance supports screening in a shifting risk landscape:

PEP Screening Dubai

Geopolitical risk moves faster than manual review can keep up with. A client that was clean last quarter can be added to a watchlist overnight following a sanctions package, a change in government, or a new adverse media report. This is the core reason regulators, and the FATF evaluation itself, are pushing UAE businesses toward continuous monitoring instead of point-in-time checks.

First Compliance is built around that reality. Our platform runs real-time monitoring integrated with hundreds of global sanction lists, so new matches surface automatically rather than waiting for the next manual review cycle. AI-powered screening covers sanctions, PEPs, and adverse media in one pass, eKYC with real-time face verification simplifies onboarding, and dynamic workflows adapt as UAE regulations change. For businesses preparing for the FATF Mutual Evaluation, having documented, audit-ready evidence of ongoing PEP and sanctions screening in Dubai is exactly the kind of outcome-based proof assessors are looking for.

Getting ahead of the 2026 enforcement curve:

The direction of UAE compliance in 2026 is clear: heavier penalties, personal accountability for compliance officers, and an evaluation framework that rewards evidence over paperwork. Businesses that treat sanctions, PEP, and UBO checks as one connected, continuously monitored system will be far better positioned than those still relying on manual, point-in-time reviews.

If your current process still depends on quarterly spreadsheet checks, now is the time to close that gap. Schedule a free demo with First Compliance to see how real-time PEP and sanctions screening in Dubai, backed by hundreds of global watchlists, fits into your existing workflow.

Frequently Asked Questions

Can I still do business with a PEP?

Yes, generally. Being a PEP is not a crime on its own. It requires Enhanced Due Diligence, including closer scrutiny of the source of funds and ongoing monitoring, rather than automatic refusal of the relationship.

At onboarding, immediately following any update to the UAE Local Terrorist List or UN Consolidated List, and during periodic KYC reviews. Real-time monitoring closes the gap between list updates and your next scheduled review.

Regulators can impose fines under Cabinet Decision No. 132 of 2023, and providing false or misleading UBO information can lead to criminal sanctions in addition to administrative penalties.

Federal Decree-Law No. 10 of 2025 raised penalty ceilings to AED 100 million, CBUAE has begun fining individual compliance officers alongside institutions, and the FATF’s 5th Round Mutual Evaluation grades real enforcement outcomes rather than written policy.

Screening the PEP but not their relatives and close associates, and treating sanctions screening as a one-time onboarding check rather than an ongoing process.

CBUAE’s New 2026 CDD Guidance: Why Manual Due Diligence No Longer Cuts It

CBUAE's New 2026 CDD Guidance: Why Manual Due Diligence No Longer Cuts It

Customer due diligence software Dubai

On 16 April 2026, the Central Bank of the UAE released six new AML/CFT/CPF guidance documents in a single package, and one of them rewrote what customer due diligence is supposed to look like day to day. The headline change: CDD is no longer something you complete at onboarding and file away. It has to run continuously, for the life of the relationship.

That single shift is why so many UAE compliance teams are now looking at customer due diligence software in Dubai instead of stretching their existing manual process further. This guide walks through what the April 2026 guidance actually requires, where manual review breaks under it, and what to look for in software built to meet the new standard. At First Compliance, we build the platform UAE businesses use to run this kind of continuous, documented due diligence without adding headcount, and this is the guidance shaping how we build it.

What the April 2026 CDD guidance changed:

The CBUAE package covered four supervisory guidelines and two best practice manuals, addressing proliferation financing risk assessment, trade-based money laundering, correspondent banking due diligence, and customer due diligence, including KYC and record-keeping. The CDD document is the one with the widest operational reach, because nearly every regulated entity performs CDD in some form.

Dynamic, risk-based CDD replaces one-time onboarding checks: customer risk profiles must now be reassessed throughout the relationship, not just at the point a customer signs up. A profile built at onboarding and never revisited no longer meets the standard.

Trigger events force a review: a significant change in transaction behaviour, a new business activity, or a change in ownership must prompt a fresh CDD review, whether or not the customer is due for their scheduled periodic check.

Real-time transaction monitoring is now the baseline: automated systems with anomaly-detection capabilities are described as the expected standard, not a best-practice suggestion. This is a meaningful language shift from earlier guidance, which left more room for judgment calls.

Digital onboarding gets its own bar to clear: institutions using electronic identity verification, including video verification or biometric checks, must meet CBUAE-specified standards for reliability and independence of the data used.

Record-keeping is now standardised at five years:CDD documentation must be retained for five years following the end of the relationship, with a clear, reconstructable trail available for regulators and law enforcement.

Where manual due diligence breaks down:

None of these five requirements are impossible to do by hand. The problem is doing all five, consistently, at the volume a growing UAE business actually processes.

Review queues scale badly with onboarding volume: a compliance analyst can work through a fixed number of files a day. Add more customers and the queue grows linearly, but risk exposure grows with every unreviewed file sitting in it. Automated periodic screening, by contrast, is now described in the April 2026 guidance as a direct expectation for teams managing hundreds of active accounts, not a discretionary upgrade.

Trigger events are easy to miss without a system watching for them: a manual process depends on someone noticing that a client’s transaction pattern shifted, or that ownership changed on a trade licence renewal. Without automated flags tied to those specific events, the review simply doesn’t happen until the next scheduled check, which can be months away.

Documentation quality varies by analyst and by day: five-year record retention only helps if the records are complete and consistent in the first place. Manual files drift in format and depth over time, which is exactly what shows up as a finding during a CBUAE inspection.

Fun fact worth knowing: the CDD guidance doesn’t just apply to banks. DNFBPs, including real estate agents, lawyers, accountants, and corporate service providers, are regulated separately under the Ministry of Economy, but the risk-based CDD standards in the CBUAE guidance mirror the broader expectation across all regulated entities in the UAE.

What to look for in customer due diligence software in Dubai:

due diligence software Dubai

Not every platform marketed for KYC or AML actually covers what the April 2026 guidance asks for. When evaluating customer due diligence software in Dubai, the following capabilities map directly to the new requirements:

  • Dynamic risk scoring that updates on its own: the system should recalculate a customer’s risk profile automatically as new information comes in, not only when a human opens the file.
  •  
  • Trigger-based review workflows: ownership changes, unusual transaction behaviour, and sanctions or PEP list updates should generate an automatic review task rather than waiting to be spotted.
  •  
  • Real-time transaction monitoring with anomaly detection: this needs to run continuously in the background, flagging genuine outliers without burying the compliance team in false alerts.
  •  
  • eKYC with biometric or video verification: for digital onboarding to meet CBUAE standards, identity verification needs to be reliable and independently verifiable, not a manual document upload with no liveness check.
  •  
  • Retention-ready audit trails: every screening result, review, and decision should be timestamped and stored in a format that can be reconstructed for a regulator five years later without manual reassembly.

Manual review versus automated CDD software: a side-by-side look

Requirement

Manual process

Automated CDD software

Risk profile updates

Reviewed at scheduled intervals only

Recalculated continuously as new data arrives

Trigger event detection

Depends on staff noticing changes

Automatic flag tied to defined events

Transaction monitoring

Sample-based or reactive

Real-time with anomaly detection

Digital identity verification

Document upload, manual check

Biometric and video verification

Record-keeping

Varies by analyst, format drift

Standardised, timestamped, five-year retention

How First Compliance fits the new standard:

Flowchart showing onboarding CDD leading to an ongoing customer relationship, which branches into three trigger events (ownership change, transaction pattern shift, sanctions list update), converging into automated risk reassessment, which then feeds back into ongoing monitoring.
First Compliance is built around the same continuous model the April 2026 guidance describes. Real-time monitoring keeps customer risk profiles current instead of static, dynamic workflows adapt to trigger events as they happen, and eKYC with real-time face verification handles the digital onboarding side without manual document review. Detailed reporting is generated automatically, so five-year record-keeping is a byproduct of how the platform runs day to day, not a separate project. For a UAE business trying to move off spreadsheets and shared drives, this is what customer due diligence software in Dubai should actually do: replace the queue, not just digitise it.

Getting your CDD process inspection-ready:

The April 2026 guidance didn’t just add more paperwork, it changed what “compliant” means. A risk profile that’s accurate on day one but never revisited is no longer a defensible position. Businesses that automate the reassessment cycle, the trigger detection, and the record-keeping will walk into their next CBUAE inspection with evidence, not just policy.

If your current process still runs on manual reviews and shared spreadsheets, it’s worth seeing what a continuous system looks like in practice. Schedule a free demo with First Compliance to see how our platform handles the full CDD lifecycle the April 2026 guidance now expects.

Frequently Asked Questions

Does the April 2026 CBUAE guidance apply to my business?

It’s written for licensed financial institutions supervised by the CBUAE. DNFBPs are regulated separately under the Ministry of Economy, but the same risk-based CDD principles are the broader standard expected across UAE regulated entities.

On a risk-based schedule tied to the customer’s profile, and immediately whenever a trigger event occurs, such as an ownership change or an unusual transaction pattern, rather than only at fixed intervals.

Technically yes, but the record-keeping, trigger-detection, and real-time monitoring expectations apply regardless of size. Even a small book of business needs a documented, consistent process to stand up to inspection.

Missed trigger events. A customer can look low-risk at onboarding and change significantly months later, and a manual process has no built-in way to catch that shift until the next scheduled review.

Five years following the end of the customer relationship, in a format that can be reconstructed for regulators and law enforcement on request.

Scroll to top