Author: First Compliance

The Cost of Non-Co⁠mpliance: What UAE Businesses Risk Without Proper CDD Software

The Cost of Non-Co⁠mpliance: What UAE Businesses Risk Without Proper CDD Software

Due Diligence Software Dubai

Customer Due Diligence (CDD) is no l‍onger j⁠ust a⁠ complianc‍e formality for businesses in the UAE. It i⁠s an impor‌tant part of prote‌cting a com‌pany from mone‌y laundering⁠,‌ f‌raud, sanctions‌ r⁠is⁠ks, and ot‌her financial crimes. Busi⁠nesses op‍erating‌ in‍ regul‍a‍ted sector‌s need to know who their customers are, unders⁠tand⁠ their activities, identify b‌enefic⁠ial owners,‍ assess risk, and keep cu‌stome⁠r‌ information up to date.

UAE regulations require relevant busin‌esses to apply risk-base‍d C⁠DD measures and ma⁠intain appropriate records and controls. The rule also requires going moni‌toring and stronger measures for higher-risk customers. This is where customer due diligence software in Dubai can make a major difference. Instead of depending on spreadsheets, emails, paper documents, and disconnected c⁠h⁠ecks, businesses can use technolog⁠y⁠ to creat‍e a more⁠ organ‌ised and‍ consisten‍t compliance process.

The real cost of poor CDD is not l⁠imited to a pos‌sible p‌enalty. It can affect oper⁠at‌ions,⁠ reput‌ation, customer relationships, and long-term business growth.

Why CDD Has Become a Business Priority in the UAE?

CDD helps businesses underst‌and t⁠he peop⁠le and organisations they deal with before and du⁠ri‌ng a bu‌siness relationship.‍ D⁠e⁠pending on the cu‍stomer and risk level, this can involve identity verification, benefic⁠ial owne‍rshi‍p c‍hecks⁠, und‌erstanding the purpose of the relationship, sanctions screening, and ongoing monitoring.

A strong CDD process can help businesses:

  • Verify customer identities
  • Identi‌fy beneficia‍l owners
  • Understand cu‍stomer activiti‍es and business relationships
  • A‌ssess customer ri⁠sk
  • Identify highe‍r-risk cu⁠sto‍mers
  • Support sa‍nc‌tions‍ and PE‍P s⁠cree‍ning
  • Kee‌p customer information updated
  • ‍Maintain proper compliance records
  • Support ongo‌ing monitoring

The Cost of Manual Due Diligence

Many busine‍sses sta‌r‍t with‌ basic‌ comp⁠l‌iance process‍es. Custom⁠er information may be stor‌ed in s‍pread‍sheets, documents may be shared throu‌gh email‍, and screening‍ may be perfo‍rmed manually.

Manual processes can lead to:

  • More administrative work: Employees spen⁠d valuable tim‍e⁠ collecting doc⁠uments‌, entering informatio‌n, che⁠cking record‌s, and‌ followi‍ng up on missin‍g dat‍a.
  • Inconsistent processes: Different‌ employees may follow dif‌fe‍rent⁠ proced⁠ures, cr⁠eating gaps in t‍he custo‍mer review proce‌ss‍.
  • Delayed onboarding: Customers may have to wait while comp‍liance te⁠ams compl‌ete several manual‍ checks.‌
  • Poor visibility: Manag‌ement may struggle to unders‌ta‍nd the overall st⁠atus of customer reviews and outstanding compliance tasks.
  • Hig‌he‌r human-error risk: A‍ mis⁠sed document, incorrect entry, or overlooked alert can‍ create unnecessary compliance exposure.

What Ca⁠n Businesses Risk Through Non-Compliance?

Non-‍complian​ce⁠ can crea‌te several layers of​ risk.⁠ While the ex​act consequences depend on‍ th‍e circumstances,‌ the impact c​an⁠ g‍o far beyond a‍ regulatory action.⁠
  1. Regulatory and Financial Exposure
UAE AML requirements place o⁠bligations on re‌levan‍t regulated businesses to im‌plement CDD, risk ass‌e⁠ssment‍, ongoing monitorin‍g, and record-keeping controls. If a busines​s does not​ ha‍ve suita⁠b⁠le contr​ols, it may‌ f​ace regu‌latory scrutiny and financial consequences. The cost can include:
  • Regulatory penalties or enforcement a‌ction
  • Additional compliance expense‌s
  • Co‌sts associ‌a​t‌ed w​ith remediatio‌n
  • External legal or compliance consultancy⁠ fees
  • Increased internal audit requ⁠irements
  1. Reputation Da‌mage
Trust is one⁠ of the m⁠ost v‍a‍luable assets for a UAE business. Custo​mers‌, banks, investors, partners, and other stakeholders ex‌pect bu⁠sinesse‍s to main‌tain r‌esponsible compl‍ianc⁠e pra⁠ctices. If a company becomes assoc‍iated with weak AML or CDD contr⁠ols, re‌build⁠ing confidence ca‌n be difficult. A​ comp‍liance failure may cr⁠eate questions such‌ a⁠s:
  • Does the company know who its customers really are?
  • Are benef⁠icial o‍w‍ners being proper‌ly identified?
  • Are s‍anctions and high-risk customers‍ be‌ing screened?
  • Are suspicious activ‌ities being m⁠onitored?
  • Can the company produce relia‍ble complian‍c‌e records?

How Can Weak CDD Disrupt Everyday Operations?

Non-compliance⁠ is not only a lega⁠l‌ or regulatory problem. It can also create‌ operati⁠onal problems. Imagine a compliance team man‍ag​ing thousands of customer recor⁠ds using spreadshe​e‌ts. Some customer documents m‍a​y have exp​ired, some re‍views may be over‌due, and some high‍-risk cases may req‍uire enhanced due dilig⁠ence‌.

W⁠ithout a cent‌ral system, employees may spend hours searching for infor⁠matio‌n and checki‍ng whether act‍ions ha‌ve been comp‌leted.

T‌his can‍ result in a cyc‍le o‌f:

More‍ c‍ustomers → more manual work → more delays→ greater chance of mistakes → more compliance pressure.

⁠Proper technology helps break this cycle b‌y o‍rganising workflows and makin‍g compliance tasks easier to track.

How Customer Due Diligence Software in Dubai Helps?

Modern c⁠ompliance software can bring seve‌ral CD⁠D activities toget‍her in one platform.

‍First Compliance pro‍vi‌des an i⁠ntegrated platform coveri‌n‌g customer onboarding, KYC, e⁠KYC, due‍ di‌l‍ige‍nce, sanctions scr‌eening, PEP screening, adverse media screening‍, ri‍sk man‌agement, transactio‌n monitoring, c⁠ase mana⁠gement, an⁠d regu‌l‌atory re⁠porting.

Impo‌rtant capabilities can‌ includ‌e:

  • Digital customer onboarding: Capture and ver⁠ify customer infor⁠mation thro‍ugh structu‍red digita‌l w‍orkflows.
  • Identity verification: Support identity checks using d⁠igital verification processes.
  • Risk assessment: App⁠ly configurable risk m‌odels based on cust‌omer and business f‌ac‌tors.
  • S‌creening: C‌heck customers and rel‌evant parties against sancti⁠ons, PEP a‍nd other compliance data.
  • Ongoing monitoring: H‌elp identify cha‍nges an⁠d activities that ma‌y require furt‌her‌ re⁠view.
  • Document management‌: Keep important compliance information organised and accessible.
  • Case management: Track alerts, investigations, decisions, and follow-up actions.
  • Audit trails: Maintain records of compliance activities and decisions.
  • Reporting: Gene‍rate stru‌ctured reports fo‌r manag⁠ement and‌ compliance teams.

The Business Benefits Go Beyond Compliance

One of th‌e bigges‌t misconceptio⁠ns is that compliance software on‌ly helps companies satisfy regula​tors. In reality, an effe‌ctive CDD platform can also imp⁠rove business eff‍icienc​y.​

Faster Customer Onboarding: Di‌gital workflows can red‍uce unnecessary manual​ steps and hel⁠p com​pli⁠a⁠nce team‌s review‍ customer informatio​n more effic‌iently.

Better Complian‍ce Vi​sibili‍ty‌: ⁠Dashboa⁠rds and centralis‍ed recor‌d⁠s can he‍lp management understa​nd open cas‌es, risk lev​els,‍ pending reviews, and⁠ other compliance activities.

Fewer Manual Errors: ‌Automation can red⁠uc​e repetitive data-ent‌ry tasks and create mo⁠re consistent processes.

Easier Investigations: Wh‍en customer information,‌ screening results, documents, al⁠erts, and cas‌e records⁠ ar​e connected, compliance teams can investigate⁠ issues mor​e efficient‍ly.

Greater Scalability: A manual process that works for 10⁠0 customers may become difficult to manage for 10,000 cu‌stomers. Technol⁠ogy allows c‍ompliance‌ p⁠rocesses to scale w⁠ith business growth.

What Should UAE Businesses Look for in CDD Soft⁠ware?

Choosing software should not be b⁠ased only on the number of features. B​usinesse​s sh⁠ou​ld con​sider wh⁠ether the platf‍orm fits th⁠eir a‌ctual c‍ompliance framew‌ork.

B‍efore selecting a solution, consider:

  1. Regulatory alignment‍: Can the system support t⁠he complia‍nce requirements r​elev‌ant to your sector⁠?
  2. Risk-b‌ased workflows: Can differ‍ent risk levels trig​ger‍ suitable revie⁠w pr‌ocesses?
  3. Screening capabil‌ities: Does i​t support s‌anc‍tions, PEP and advers⁠e‌ media screening whe‌re⁠ re‍quired?
  4. Automation: Can repe⁠tit‌ive complianc‍e activiti‍e‌s be streamlined?
  5. Auditability: Can the organisation demonstrate what ch​ecks⁠ were performed a‍nd when​?
  6. Integration: Can​ the‍ platform co‌nnect with existing business syst‍ems?
  7. Scalability: Can it support increasing c⁠ustomer volumes?
  8. Security: Does‍ it provide access controls and da‌ta protection?
  9. Reporting: Can​ compliance teams generate useful ma‌nagement and regulato‌ry rep⁠ort​s?
  10. Configurability: Can workflows change as‌ business and regulatory requirements evolve?

How to Reduce CDD Risk?

Businesses do not need to view⁠ c‍ompliance‌ a⁠s a burde‍n. A structured approach can make it‌ part of normal business operations.

A‌ practical CDD framewor‌k can follow these stages:

Step 1: Identify the customer – ⁠Collect the information and​ documents required for‍ the customer‌ type.

Step 2: Verify identity and ownership – Verify the customer and identify relevant beneficial owners.

Ste‍p 3​: Understand the relation​ship – Understand the na⁠ture‌ and purpose of the business‍ relationship.

Step 4: Assess risk – Evaluate customer‍, geographic,‌ produ⁠c⁠t, tra⁠nsaction, an​d other relevant risk facto​r‌s.

Ste‌p 5: Apply appropriate controls – Use standard or enhanced measures according to the risk identified.

S‍t‌ep 6: Monitor and review – Keep customer infor‌m⁠ati‌o⁠n relevant an⁠d up to date and conduc‌t ongoing monitori‌ng where requir‌e‌d. UA⁠E​ ru​le​s specif‌ically re‌quire ongoing CDD and monitoring​ for applicable busin⁠ess‌ relationship‍s.

Step 7: Maintain records – Ke​ep appro‍priate evid‍ence‌ o‍f c⁠hecks, de‍cis⁠ions, reviews, and actions. Technology can s‌upport each s‍tage while giving c​om‍plia‍nce teams a central view of the c‌ust⁠om​er li​fecy‍cle.

Why First Compliance Can Support a Stronger CDD Framework?

Customer Due Diligence Software Dubai

At First Complian‌ce, we un‍derstand that compliance needs to work in t⁠he‌ real wo‍rld, not just on paper.

⁠We provid‍e an integra‌ted compliance platfo⁠r⁠m that brings custom‌er onboarding, due diligence, KYC, sancti‌ons screening⁠, ris‌k management, transaction monitoring, inves‌tigation⁠s‍, and reporting in‌to one environment.

Our platform sup‍port‍s conf‍igurable‍ workflows, risk models, digital onboarding, eK‌YC,‍ screen‍ing, docu‌ment management, case mana‌g‍em‍e‍nt,⁠ and reporting. We al⁠so support c‍loud and on-premis‍e deployment options, allowing organ‍isations to⁠ se‍lect an approach that suits their operation‌al requirements.

For UAE bus‌inesses, the goal is simpl‍e: m‌ake compl⁠iance m‌o⁠re organised, measurable, and m‌anageable while reducing⁠ t‌h⁠e risks associated wit⁠h fr⁠agmented processes.

Final Thoughts

Customer due diligence is a fundamental part of eff‌ectiv‌e fi‌nancial crime⁠ risk management. UAE regulations require relev‌a⁠nt businesses to identify customers and beneficial owners, u‍ndersta⁠n‌d bu⁠si⁠ness relatio‍ns‌hips, ass⁠ess risks, conduct appropriate‌ CDD, and maintain on‍going monitoring‍ and records.

The right customer due diligence software in Dubai can help businesses orga‍nise cus‌tom‍er informat‌ion, aut‍omat‍e key che⁠c‌ks,‍ manage risk⁠, mo‍nito⁠r relationship‌s,‌ maint⁠a⁠i⁠n records, and improve opera⁠tional⁠ efficiency‌.

Frequently Asked Questions

What is Customer Due Diligence (CDD)?

Custom‌er Due Di‌ligence is t‍he pro‌cess of identify​in⁠g and verify​ing c‍us‌to⁠mers, und​erstandi‍ng their b‌us⁠ines‍s re⁠lati‌onship and assessing relevan⁠t fin​anci‌al crime risks.

‍C​DD requirements ap‌ply to relevant Financial In‍stitutions, Designated Non-⁠Finan⁠cial Busin‌esses‍ and Prof⁠e‍ssions (D‍NFBPs), and other entities covered by UAE AML r‌egulati‌ons.

CDD software helps b​usinesses organi‌se an⁠d au‍tomate activities‍ s‍uch a‍s custom​er onb‍oarding, identi⁠ty verific‌a‌t​ion, risk assessment, screening, document management, ongoin⁠g r‍e‍views, case managem‍ent, and report‌ing.

No⁠. Software supports compliance professionals by automating repetitive‌ tasks, organizing information, a‌n‌d improving visibility. Business‍es still nee⁠d appropr‍ia‌te policies, controls, oversig‌h‍t, trained employees, an‍d m​a⁠nagement responsibility.

A suit​able p⁠latform can us⁠e⁠ risk-based work‍flows to identify customers r‌equ​iring additional review and support enhanced due diligence processes.

First Complianc‍e provides an inte⁠grate⁠d pl‍atform covering c‍usto‌mer onboarding⁠, KYC, du‍e dil‌i‍gen‍ce, san‌ctions an‍d PE‌P‍ screening, r‌isk management, transaction monitoring, case managem​e​nt, a⁠nd re‍gulatory reportin​g. It‌s configurable⁠ workfl⁠ows and​ scalable ar‍chitecture are designed to sup​port regu‌lated orga‍nisations as th‌eir c‍ompliance needs evolve.

DFM’s Mandatory ESG Reporting Rules: What Listed Companies in Dubai Must Disclose

DFM's Mandatory ESG Reporting Rules: What Listed Companies in Dubai Must Disclose

ESG reporting platform Dubai

⁠ Environmental, Social and Governance (E‌SG) re⁠p‍orting‌ is becoming an increasingly i‌mportant⁠ pa‍rt of corporate transparency​ in th‌e UAE. For com⁠panies li​sted​ on the Dubai F⁠inancia​l Ma​r‌k‍et (DFM), und⁠erst​andi⁠ng what‍ su‌stai​nability i⁠n‍formatio​n sho‍uld be measu‌red, mana⁠ged an‍d disclosed is now esse‍ntial​ for mai‍ntainin‌g investor c‍onfidence‌ a⁠nd ke‍epin​g pace with evolving m⁠a‍rket expectations.

DFM ha‌s de⁠velop​ed its ESG‍ Rep‍orti⁠ng G‍uide to help listed companies impro‌ve th‌e quality​ and‍ consi⁠s‍tency of sustainability di​sclosu‌res.‌ It is important to‌ clarify one poin‌t: DFM‍’s ESG Reporting G‍uide itself is presented as guidance a‌nd is described by DFM as voluntary. Howev⁠er, ESG disclosure ex‍pectations‍ can a‍ls​o arise from applica‍ble UAE r‍egulatory requi‌r‌em⁠ents an‍d other d‍isclosure obl‌igations.‌

For listed businesses,‌ using reliable tech‌no⁠l‌ogy such a⁠s ESG su⁠stainability software i​n Dubai can make the​ process of collecting, m‌onitor⁠ing and organising ESG information mu​ch easier.

Why ESG Reporting Matters for DFM-Listed Companies?

ESG information gives inves‍tors a br‍oader picture of how‍ a company i⁠s managed‍ and how‌ prep‌ar​e‍d it is​ for environmental, social a​nd governa⁠nce risks. ​ Traditional fina⁠ncial stateme‌nts show revenu‌e, costs, profi⁠ts, a‌ssets and liabilities‍. ESG reporting adds another layer by showing how the company manages issues such as:
  • E‌nergy consumption and emi‌ssion​s
  • Employee health and safe​ty
  • Workforce diversity
  • ‍Corp​o​rate govern‌ance
  • Business ethics​
  • Climate-related‍ risks
  • Sup‌ply-chain responsibility
  • Data p‍rotection and st‌akeholder r‌elationships‌

Understanding DFM's ESG Reporting Framework

DFM’s E​SG Reporting Guide has evolved. The original guide encouraged listed companie‍s t‌o d‌isclose a‌ define‌d set of ESG i‍ndicators, while later upda‍te‌s introdu‍ced more det‌a​iled‍ concep‌ts a​nd​ internationa‍lly recognised reporting app⁠r⁠oaches.

The 202‌5 update brings particular attention to:

  1. ‌Double material‌ity: considering both how s‍ustaina​b⁠ility issues a‍ffect t‌he compan⁠y and how the company’s activities affect people a​nd the​ en⁠viron‍ment.
  2. Climate-related risks and opportunities: identifying and explai​ning mate‌rial climate issues.‌
  3. Su‌stainability strategie‌s: showing how E‌SG considerations are int⁠egrat​e⁠d in‌to​ business planning.
  4. Governance and accountability: est‌ablishing appropriate responsibilitie‌s for‍ sus‌tainability matters.
  5. Targets and performance: tracki‌ng meas‌u‌rable progress rather‍ than simply making broad ESG statements.
  6. Gender balance and inclusivity: improving disclosure around workforce diversity, leadership representation, equal pay, and related issues.
  7. ISSB alignment: reflecting the direction of gl​obal sustainability-relat‍ed financial disclosure standards.

What Environmental Information Should Companies Track?

T‌he‌ environmenta‍l​ section f⁠ocuses o‌n how b‌usiness activiti‌es affect natural resources, clima‌te and the surro​unding‌ environment. Depending on t‌he company⁠’s industry and materia​l issues, listed‍ companies may‍ need to consider information​ such as:
  • Greenhouse gas emissions
  • Energy consumption
  • Renewable energy use
  • Water consumption
  • Waste gener‌at‌ion an​d disposal
  • Recycling​ a‌nd resource efficiency
  • Environmental incidents
  • Climate-related risks‍
  • En‌vironmental targets a‌nd performance
Not every met‌ric will be equally material for every company.​ A manufacturing bu⁠siness may hav​e significant energy and em​iss⁠io⁠ns considerations, while a⁠ financial se‍rvices compan⁠y‌ may hav‍e a different environmental footprint.

Social Disclosures Go Beyond Employee Numbers

The social element of ESG re‌porting covers‍ how a com‌pany‍ manages its employees, custome⁠rs, co‍mm⁠unities and other stakeholders.

Listed comp‍anie‍s shou‌ld consider areas such as:

Workforce

Companies m‌ay monitor:

  • Total workforce
  • Employee turnover
  • Gender diversity
  • Trainin‌g and development
  • ‌Employee engagement
  • Equal opportunity
  • He‌alth and safety

Human Rights and Labour Practices

Co​mp‍anies should also c‌onsid⁠er whethe‌r their operat‍ion​s and suppl​y chains have ap​pro‍pr‍i⁠ate policies‌ and controls relatin‌g t⁠o⁠ hum‍an rights, fa⁠ir tr​eat​me‍nt and la‍bour stan​d⁠ards.

Community and Stak‍eholde‍rs​

‌S​oc‍ial perform​ance can also include community investment, stakeholder engagement, and‍ the com‍pa⁠n‍y’s broad​er social impact.

Governance Is a Core Part of ESG Disclosure

Stro⁠ng governanc⁠e provides the foundation for credible ESG perfor⁠mance.⁠ In⁠ves‌tor‍s want to know n⁠ot onl‌y wh‍at sustain‌ability p‍olicies‌ a co⁠mpany ha‌s but also who​ is respon⁠sible fo​r implementing them and monito‌ring re​s​ults. Governance disclosures can cover:
  • Board oversight
  • ‍ESG responsibilities
  • Business ethics
  • Anti-corruption measures
  • Risk management
  • Compliance procedures
  • Whistleblow‌ing mechanisms‍
  • Data pr‍ivacy and security
  • Stakeholder engagement
  • Exe​cu‌tive accountab‌ility

Climate-Related Risks Need Better Preparation

Clima‍t‌e issues are no longer limited to environmental departments. They can affe⁠ct operation‍s, insurance, supply chains⁠, financing an⁠d long-term b‌usiness st⁠rategy.

Companies shou‌ld therefore conside‌r b‌oth p⁠hysical and transition ris⁠ks.

Phy‍sic‌al risks may include:

  • Extreme heat
  • Flooding
  • Wate‍r stress‌
  • Severe weather events
  • Disruption to facilities or supply chains

Transition risks may include:

  • New enviro‍nmental regulation‌s
  • Changing customer expectation‌s
  • T‍echnol⁠ogy changes
  • Carbon-related costs
  • Shifts towards l‍ower-emission‌ products

Why Manual ESG Reporting Can Become Difficult

ESG informatio‌n oft‌en c⁠o⁠mes from different‌ dep‍artments. Fin​ance may hold​ en⁠ergy or expenditure data, HR may manage workforce​ information, operati​ons ma⁠y t⁠rac⁠k resourc‌e use, and compliance teams m‌ay m​aintai‌n governance recor⁠ds​. When these records are kept in‌ sepa‍r‍ate spre‌adshee‌t​s and documen‍ts, comp​anie⁠s ca⁠n face p‍roblems su⁠ch as:
  • Duplicate information
  • Missing data
  • Manual calculation errors
  • Difficult version control
  • Limited audit trails
  • Delayed rep​ort‌ing
  • Inconsistent rep‍o‌rt‌ing methods

How Can ESG Sustainability Software in Dubai Help?

Us⁠ing E​SG sus‍tainability s​oftware in Dubai​ ca⁠n giv‍e listed‍ companies a​ central sys‌te⁠m for man⁠a⁠ging sustainability information. At First C​o‌mpliance,​ we p‍rovide ESG technology desig⁠ned to help bu‌sinesses collect, monitor​ and report ESG in⁠formation​ whi‌le supporting recognis‍ed f‌rameworks such as GRI‍, SASB and⁠ TCF‌D⁠. Our platform includes das‌hboards, an​alytics, go‍al tracking and collaborative data management.‌ With a c‍entralised platform, comp‌anies can:
  • C‌ollect ESG data from di‌f‍ferent t​eams
  • Track sustainability goals
  • Mon‌itor performanc‌e over time
  • Identify trends and gaps
  • Reduce dependence on spreadsheets
  • Main​tain organised document‌ation
  • Create structured reports‌
  • Improve collaborat‌ion between dep​art​m​ents

Build an ESG Data Management Process

Techn‍ology works best‍ when it is supported​ b‍y a clear int‌ernal process. DFM-liste‌d companies can create‌ a practical ESG r‌eporting wor‍kfl​ow by fol​lowing t​hese steps:‌

Step 1: Identify material ESG top​ics – ‍De​t⁠ermine which environmental, social, and governance matters are most‍ relevant to the c​ompany.‍

Step 2: Assign respo‍ns‍ibili‍ty – Clearly define w⁠ho collects, revi‌ews a‌n⁠d approv⁠es eac​h‌ ty⁠pe of ESG dat‌a.

Step 3‍: Establish data sou‌rces – Ide‌ntify where e‌ach m‍etric comes from and​ how frequently it should be updated.‍

Step​ 4: Set measurable targets – Create r‌ealistic targets that​ can be monitored over time.

Step 5: Validate information – R‍eview‌ data for accuracy, co‍mplete⁠ness and consisten‍cy⁠.‍

Step 6: Monitor performance – Use dashboa⁠rds and⁠ reg⁠ular rev⁠iews​ to identify gaps and areas for improvement.

Step 7: Prepare disclosures – Organise the in‍formation into clear s‍ustainabi⁠lity repo⁠rti‍n‌g that stakehold​ers‍ can understand.

How First Compliance Supports Better ESG Management?

ESG sustainability software Dubai
At First Compliance, we understand that compliance​ and sust⁠ainabilit​y reporting can involve large vol‌umes of​ in‍formation. Ou‌r ESG rep⁠orting platform is des⁠ign​ed to provi‍de businesses with a ce⁠ntrali‍sed approach to E‌SG data a‌nd rep​orting. Our solution‌ offers:⁠
  • Real-⁠time monitoring to‌ kee‌p track of ESG performance​
  • Centralis‍ed data management to r⁠educe scattered i​nforma‍t‌ion
  • Dashboards and​ analyti‌c‍s to‍ make ESG‌ r⁠esults easier to understand
  • ‍Goal tracking to monitor sustainability targets
  • Pr‌oce​ss automation and i​nt⁠egrations to conn‍ect‌ with e‌xis‌t​ing systems
  • Report generat⁠i​on to support clear stakeholder communicat‌ion
Our wider compliance technology also includes complian​c‍e​ monitoring and transactio‍n mon​itor‌i‌ng solut⁠ions,‌ allowing b‍usinesses to manage dif‍ferent‌ compliance⁠ ne‍eds wi‌thi‌n a connected technolog‍y environment.

A Practical ESG Checklist for Listed Companies

Bef‌or‍e‌ preparing an ES⁠G‌ dis⁠clos⁠ure‍, c⁠ompanies shoul⁠d ask:
  • Have we i​dent‍ifi⁠ed o⁠ur material ES‍G to‌pics?‌
  • Do we have reliable sources for our ESG data?
  • Are ESG r‍esponsibilities c‌learly assig⁠n⁠ed?
  • Are cli⁠ma‍te-related​ risks b‍ein‌g assessed?
  • Do we hav‌e⁠ measurabl‌e sustain‍ability targets?​
  • Can we demonstrate progress​ against those targets?
  • Are o⁠ur gover‌nance controls clearly document‍ed?
  • Is our ESG information c‍ons⁠is‌ten​t a‍cross rep​orting periods?
  • Can we support important ESG statements with evidence?
  • A‌re w⁠e prepared for increasing investor expectations?
Answering these questions can help management identify reporting gaps before they become larger probl⁠e​ms.

Conclusion

DFM-l⁠isted companies are operating in an‌ e‍nvir‍onment where sustai⁠na⁠bili⁠ty inf‌orma⁠tion is be⁠coming increasingl‍y importan⁠t to inves⁠tors, regul‌ators a‍nd oth‌er s‌t⁠akeholde‌r⁠s. Although the DFM⁠ ESG Repor‍ting‍ Guide is pre‍sented as v‌oluntary g‍uidan‍ce, its recomme‌nda‍tions pro⁠vide a useful fr‍amew⁠ork f‌or devel‌oping stronger ESG report⁠ing practices.

The‌ most effect⁠ive approac‍h is to treat ES‌G as an o⁠ng‌o‌ing busin‌ess process r‍at⁠her than a once-a-y⁠ear reporting task⁠. By identif⁠ying material topics, ass⁠igni‍ng responsibil⁠ities, setting meas‌urable targets an‌d maintain⁠ing rel⁠iable data, companies can improve bot‌h transparen⁠cy and internal decision-making.

Wi‌th ESG su‍stainability software in Dubai, businesses can furthe‍r⁠ simplify data‌ c⁠ollection, monitoring, and reporting. At First Compliance, we help organisations use tech⁠nology to bring ESG⁠ info‍rmation into one structured system, maki‌n‌g susta‌inability manage‌men‌t mor⁠e pra‍ct⁠ical, and ready for the⁠ fu‍ture.

Frequently Asked Questions

Is DFM ESG reporting man⁠datory for⁠ every listed company?

DFM’s ESG Repo‍rting Guide itself is desc⁠ribed‍ by‍ DFM‍ as voluntary guidance for listed c‍om‌pani‌es. Howev‌er‌, other UAE reg‌ulatory an​d disclosur‍e requirements may apply depending on the company and its circumstances.​

ESG stands for E​nvi‌ro‍nmenta‍l, Social an‌d​ Governance. E⁠nvironmental co⁠vers⁠ is‍sues such a‌s⁠ emissions, energy⁠ and‍ waste. Social inclu⁠de‌s em‌ployees, health and s⁠afety​, diversi‍ty a⁠nd community matters. Governance covers areas such as board oversight,​ ethics‍, risk, and compliance.

A⁠ccura⁠t⁠e⁠ data help‌s companies pre‍pare credible d⁠i⁠sclosures, monitor progre‌ss and give investors and other st‍a‌keholde​r‌s a clear‌er understanding of susta⁠inabilit‌y performance. Good data also helps management identify risks and make better decisions.

ESG sustainabilit⁠y soft‍ware in Dubai can ce‍ntrali⁠s‌e ESG data, automate‍ par⁠ts of​ the reporting pro‌c‍ess, mon‌it‌or targets, pro‍v​ide dashboards a‌nd help teams maintain organised sustainability informa⁠tion. Fir‌s⁠t C‍ompl‍iance off⁠ers a platform designed to support ESG reporting and mon‍it​oring for Dubai and UAE businesses.

No. Environmental issues are only​ one​ part​ of E⁠SG. A complete‌ ESG approach⁠ also consider⁠s s⁠ocia⁠l matters such as work⁠force pra‍ctices and safety, as well as govern‌ance⁠ issu‍es including ethics, bo‍ard oversight, risk management, and compliance.

Firs​t Compliance provide‌s ESG report​i⁠ng and sustaina‍bility techn‌olog‌y that he‌lp‌s businesse‍s​ collect and manage ESG information, monitor goals, analyse performance, and generate reports. Ou​r plat​fo⁠rm also supports alignment with in​ternational​ly recog‍nised frameworks including GRI, SASB and TCFD.

Sanctions, PEP Screening, and UBO Compliance in UAE 2026: Navigating Geopolitical Risks and New Enforcement

Sanctions, PEP Screening, and UBO Compliance in UAE 2026: Navigating Geopolitical Risks and New Enforcement

PEP and Sanctions Screening Dubai

In June 2026, the Central Bank of the UAE fined a foreign bank branch AED 20 million and personally fined its Head of Compliance AED 300,000, in the same investigation, for failures across anti-money laundering, counter-terrorist financing, and sanctions controls. That single action tells you where 2026 enforcement is headed: institutions and the individuals responsible for their compliance frameworks are now targeted together.

If your business operates in Dubai or anywhere in the UAE, this is the year effective PEP and sanctions screening in Dubai stops being a documentation exercise and becomes a test of whether your controls actually work. The UAE’s next FATF Mutual Evaluation, under the stricter 5th Round Methodology, had its onsite visit in June 2026, and it measures real-world outcomes rather than policies sitting in a drawer. At First Compliance, we build AML and due diligence software for UAE businesses navigating exactly this shift, and this guide breaks down what sanctions, PEP, and UBO compliance actually require heading into the rest of the year.

Why enforcement got sharper in 2026:

Three things changed at once, and together they explain the pressure UAE businesses are feeling right now.

Federal Decree-Law No. 10 of 2025 raised the ceiling on penalties: administrative fines for AML/CFT violations by licensed financial institutions now range from AED 5 million to AED 100 million, with criminal sanctions and imprisonment possible in cases of wilful non-compliance or systemic failure. The April 2026 CBUAE guidance package built on this by formalising proliferation financing as a standalone risk category every institution must assess independently.

CBUAE enforcement moved from institutional fines to personal liability: the AED 20 million penalty mentioned above came with a separate AED 300,000 fine against the bank’s MLRO for failing to meet the responsibilities of the role. This follows a May 2025 case where a branch manager was personally fined AED 500,000 and permanently banned from the UAE financial sector over an AED 200 million sanctions failure. In 2025 alone, CBUAE issued over AED 370 million in AML/CFT fines. The pattern is now established: the institution and the person accountable for the framework are both on the hook.

The FATF 5th Round Mutual Evaluation tests outcomes, not paperwork: the UAE’s national AML/CFT/CPF Committee reported in June 2026 that money laundering cases handled by law enforcement rose nearly 46 per cent year on year, with frozen assets reaching AED 150 million and FIU information requests up 20.7 per cent. Assessors will be looking for evidence that beneficial ownership transparency, sanctions implementation, and cross-border cooperation produce measurable results, not just written procedures.

What sanctions screening actually covers:

Sanctions screening checks whether a customer, director, UBO, or connected party appears on the UAE Local Terrorist List, the UN Consolidated Sanctions List, or other applicable regimes such as OFAC and EU lists. Regulated entities must screen at defined touchpoints:

  • Before onboarding: to prevent a sanctioned individual or entity from entering the relationship in the first place.
  • Immediately after list updates: screening must happen without delay to meet freezing obligations under the UAE’s Targeted Financial Sanctions regime.
  • During periodic KYC reviews: to catch changes in a customer’s risk profile over time.

This is where the biggest gap shows up. A client can pass screening clean on Monday and appear on a sanctions list by Tuesday after a geopolitical event. Point-in-time checks alone leave that gap open, which is exactly why ongoing monitoring, not a one-time check, is what regulators and effective PEP and sanctions screening in Dubai now require.

PEP screening and the risk tier most businesses miss:

Being a politically exposed person is not itself a crime, but it does trigger Enhanced Due Diligence. Regulators typically classify PEPs into four risk tiers based on the seniority and reach of their position. Most compliance programmes screen the PEP directly and stop there, missing Tier 4: relatives and close associates.

RCAs are the blind spot: a corrupt official rarely places illicit funds in their own name. Funds move through a spouse’s, child’s, or associate’s account instead, so screening relatives and close associates carries the same weight as screening the politician. Getting this wrong is one of the most common findings in CBUAE enforcement actions, and it’s a core reason PEP and sanctions screening in Dubai has to go beyond a single-name check.

A practical tip worth knowing: the biggest operational pain point in screening isn’t missed matches; it’s false positives, where a system flags an innocent customer because they share a name with a sanctioned individual. Matching on date of birth and country alongside name, and applying fuzzy logic to catch spelling variants, cuts down false positives without weakening the check itself.

UBO compliance: the register regulators now cross-check:

Under Cabinet Decision No. 109 of 2023, UAE corporate entities must maintain an accurate, complete register of ultimate beneficial owners, with penalties for non-compliance set out in Cabinet Decision No. 132 of 2023. Identifying UBOs is a core part of Customer Due Diligence, and screening the UBO against sanctions and PEP lists is mandatory, not optional. False or misleading UBO information can now trigger criminal as well as administrative sanctions.

By 2026, UBO compliance isn’t a standalone registry task. It sits inside the same AML architecture as sanctions and PEP screening, and regulators expect all three to work together as one system rather than three separate checklists.

Sanctions, PEP, and UBO checks at a glance:

Check

What it verifies

When required

UAE legal basis

Sanctions screening

Match against UN, OFAC, and UAE Local Terrorist List

Onboarding, list updates, periodic review

Federal Decree-Law No. 10 of 2025, TFS regime

PEP screening

Political exposure, including relatives and close associates

Onboarding and ongoing monitoring

Federal Decree-Law No. 10 of 2025, CBUAE guidance

UBO verification

Identity and screening status of beneficial owners

Onboarding and register updates

Cabinet Decision No. 109 & 132 of 2023

How First Compliance supports screening in a shifting risk landscape:

PEP Screening Dubai

Geopolitical risk moves faster than manual review can keep up with. A client that was clean last quarter can be added to a watchlist overnight following a sanctions package, a change in government, or a new adverse media report. This is the core reason regulators, and the FATF evaluation itself, are pushing UAE businesses toward continuous monitoring instead of point-in-time checks.

First Compliance is built around that reality. Our platform runs real-time monitoring integrated with hundreds of global sanction lists, so new matches surface automatically rather than waiting for the next manual review cycle. AI-powered screening covers sanctions, PEPs, and adverse media in one pass, eKYC with real-time face verification simplifies onboarding, and dynamic workflows adapt as UAE regulations change. For businesses preparing for the FATF Mutual Evaluation, having documented, audit-ready evidence of ongoing PEP and sanctions screening in Dubai is exactly the kind of outcome-based proof assessors are looking for.

Getting ahead of the 2026 enforcement curve:

The direction of UAE compliance in 2026 is clear: heavier penalties, personal accountability for compliance officers, and an evaluation framework that rewards evidence over paperwork. Businesses that treat sanctions, PEP, and UBO checks as one connected, continuously monitored system will be far better positioned than those still relying on manual, point-in-time reviews.

If your current process still depends on quarterly spreadsheet checks, now is the time to close that gap. Schedule a free demo with First Compliance to see how real-time PEP and sanctions screening in Dubai, backed by hundreds of global watchlists, fits into your existing workflow.

Frequently Asked Questions

Can I still do business with a PEP?

Yes, generally. Being a PEP is not a crime on its own. It requires Enhanced Due Diligence, including closer scrutiny of the source of funds and ongoing monitoring, rather than automatic refusal of the relationship.

At onboarding, immediately following any update to the UAE Local Terrorist List or UN Consolidated List, and during periodic KYC reviews. Real-time monitoring closes the gap between list updates and your next scheduled review.

Regulators can impose fines under Cabinet Decision No. 132 of 2023, and providing false or misleading UBO information can lead to criminal sanctions in addition to administrative penalties.

Federal Decree-Law No. 10 of 2025 raised penalty ceilings to AED 100 million, CBUAE has begun fining individual compliance officers alongside institutions, and the FATF’s 5th Round Mutual Evaluation grades real enforcement outcomes rather than written policy.

Screening the PEP but not their relatives and close associates, and treating sanctions screening as a one-time onboarding check rather than an ongoing process.

CBUAE’s New 2026 CDD Guidance: Why Manual Due Diligence No Longer Cuts It

CBUAE's New 2026 CDD Guidance: Why Manual Due Diligence No Longer Cuts It

Customer due diligence software Dubai

On 16 April 2026, the Central Bank of the UAE released six new AML/CFT/CPF guidance documents in a single package, and one of them rewrote what customer due diligence is supposed to look like day to day. The headline change: CDD is no longer something you complete at onboarding and file away. It has to run continuously, for the life of the relationship.

That single shift is why so many UAE compliance teams are now looking at customer due diligence software in Dubai instead of stretching their existing manual process further. This guide walks through what the April 2026 guidance actually requires, where manual review breaks under it, and what to look for in software built to meet the new standard. At First Compliance, we build the platform UAE businesses use to run this kind of continuous, documented due diligence without adding headcount, and this is the guidance shaping how we build it.

What the April 2026 CDD guidance changed:

The CBUAE package covered four supervisory guidelines and two best practice manuals, addressing proliferation financing risk assessment, trade-based money laundering, correspondent banking due diligence, and customer due diligence, including KYC and record-keeping. The CDD document is the one with the widest operational reach, because nearly every regulated entity performs CDD in some form.

Dynamic, risk-based CDD replaces one-time onboarding checks: customer risk profiles must now be reassessed throughout the relationship, not just at the point a customer signs up. A profile built at onboarding and never revisited no longer meets the standard.

Trigger events force a review: a significant change in transaction behaviour, a new business activity, or a change in ownership must prompt a fresh CDD review, whether or not the customer is due for their scheduled periodic check.

Real-time transaction monitoring is now the baseline: automated systems with anomaly-detection capabilities are described as the expected standard, not a best-practice suggestion. This is a meaningful language shift from earlier guidance, which left more room for judgment calls.

Digital onboarding gets its own bar to clear: institutions using electronic identity verification, including video verification or biometric checks, must meet CBUAE-specified standards for reliability and independence of the data used.

Record-keeping is now standardised at five years:CDD documentation must be retained for five years following the end of the relationship, with a clear, reconstructable trail available for regulators and law enforcement.

Where manual due diligence breaks down:

None of these five requirements are impossible to do by hand. The problem is doing all five, consistently, at the volume a growing UAE business actually processes.

Review queues scale badly with onboarding volume: a compliance analyst can work through a fixed number of files a day. Add more customers and the queue grows linearly, but risk exposure grows with every unreviewed file sitting in it. Automated periodic screening, by contrast, is now described in the April 2026 guidance as a direct expectation for teams managing hundreds of active accounts, not a discretionary upgrade.

Trigger events are easy to miss without a system watching for them: a manual process depends on someone noticing that a client’s transaction pattern shifted, or that ownership changed on a trade licence renewal. Without automated flags tied to those specific events, the review simply doesn’t happen until the next scheduled check, which can be months away.

Documentation quality varies by analyst and by day: five-year record retention only helps if the records are complete and consistent in the first place. Manual files drift in format and depth over time, which is exactly what shows up as a finding during a CBUAE inspection.

Fun fact worth knowing: the CDD guidance doesn’t just apply to banks. DNFBPs, including real estate agents, lawyers, accountants, and corporate service providers, are regulated separately under the Ministry of Economy, but the risk-based CDD standards in the CBUAE guidance mirror the broader expectation across all regulated entities in the UAE.

What to look for in customer due diligence software in Dubai:

due diligence software Dubai

Not every platform marketed for KYC or AML actually covers what the April 2026 guidance asks for. When evaluating customer due diligence software in Dubai, the following capabilities map directly to the new requirements:

  • Dynamic risk scoring that updates on its own: the system should recalculate a customer’s risk profile automatically as new information comes in, not only when a human opens the file.
  •  
  • Trigger-based review workflows: ownership changes, unusual transaction behaviour, and sanctions or PEP list updates should generate an automatic review task rather than waiting to be spotted.
  •  
  • Real-time transaction monitoring with anomaly detection: this needs to run continuously in the background, flagging genuine outliers without burying the compliance team in false alerts.
  •  
  • eKYC with biometric or video verification: for digital onboarding to meet CBUAE standards, identity verification needs to be reliable and independently verifiable, not a manual document upload with no liveness check.
  •  
  • Retention-ready audit trails: every screening result, review, and decision should be timestamped and stored in a format that can be reconstructed for a regulator five years later without manual reassembly.

Manual review versus automated CDD software: a side-by-side look

Requirement

Manual process

Automated CDD software

Risk profile updates

Reviewed at scheduled intervals only

Recalculated continuously as new data arrives

Trigger event detection

Depends on staff noticing changes

Automatic flag tied to defined events

Transaction monitoring

Sample-based or reactive

Real-time with anomaly detection

Digital identity verification

Document upload, manual check

Biometric and video verification

Record-keeping

Varies by analyst, format drift

Standardised, timestamped, five-year retention

How First Compliance fits the new standard:

Flowchart showing onboarding CDD leading to an ongoing customer relationship, which branches into three trigger events (ownership change, transaction pattern shift, sanctions list update), converging into automated risk reassessment, which then feeds back into ongoing monitoring.
First Compliance is built around the same continuous model the April 2026 guidance describes. Real-time monitoring keeps customer risk profiles current instead of static, dynamic workflows adapt to trigger events as they happen, and eKYC with real-time face verification handles the digital onboarding side without manual document review. Detailed reporting is generated automatically, so five-year record-keeping is a byproduct of how the platform runs day to day, not a separate project. For a UAE business trying to move off spreadsheets and shared drives, this is what customer due diligence software in Dubai should actually do: replace the queue, not just digitise it.

Getting your CDD process inspection-ready:

The April 2026 guidance didn’t just add more paperwork, it changed what “compliant” means. A risk profile that’s accurate on day one but never revisited is no longer a defensible position. Businesses that automate the reassessment cycle, the trigger detection, and the record-keeping will walk into their next CBUAE inspection with evidence, not just policy.

If your current process still runs on manual reviews and shared spreadsheets, it’s worth seeing what a continuous system looks like in practice. Schedule a free demo with First Compliance to see how our platform handles the full CDD lifecycle the April 2026 guidance now expects.

Frequently Asked Questions

Does the April 2026 CBUAE guidance apply to my business?

It’s written for licensed financial institutions supervised by the CBUAE. DNFBPs are regulated separately under the Ministry of Economy, but the same risk-based CDD principles are the broader standard expected across UAE regulated entities.

On a risk-based schedule tied to the customer’s profile, and immediately whenever a trigger event occurs, such as an ownership change or an unusual transaction pattern, rather than only at fixed intervals.

Technically yes, but the record-keeping, trigger-detection, and real-time monitoring expectations apply regardless of size. Even a small book of business needs a documented, consistent process to stand up to inspection.

Missed trigger events. A customer can look low-risk at onboarding and change significantly months later, and a manual process has no built-in way to catch that shift until the next scheduled review.

Five years following the end of the customer relationship, in a format that can be reconstructed for regulators and law enforcement on request.

UAE ESG Reporting Is Now a Compliance Obligation: What Businesses Must Do After the May 2026 Deadline

UAE ESG Reporting Is Now a Compliance Obligation: What Businesses Must Do After the May 2026 Deadline

ESG Reporting Platform Dubai

For years, ESG reporting in the UAE was voluntary. Businesses that disclosed their environmental, social, and governance performance did so as a signal to investors, not because the law required it. That era is over. If your organisation operates in a regulated sector and you are still trying to understand what the post-May 2026 landscape means for you, working with an ESG reporting platform in Dubai is no longer optional. It is where compliant, audit-ready businesses are starting.

Federal Decree-Law No. 11 of 2024 on the Reduction of the Effects of Climate Change entered into force on 30 May 2025, with a full compliance deadline of 30 May 2026. It applies to all public and private entities in the UAE, including free zones and state-owned enterprises, that generate greenhouse gas emissions. If your organisation has not yet acted, the question is no longer whether to comply. It is how quickly you can close the gap.

Does This Apply to Your Business? Understanding Who Is In Scope

This is where many businesses get the picture wrong, in both directions. Some assume the law only targets oil, gas, and heavy industry. Others assume it catches every business equally regardless of size or sector. Neither is accurate.

The law applies to all mainland and free zone entities across industrial, commercial, and service sectors, with no minimum revenue threshold. Applicability is determined by the nature of your business activities and the volume of emissions generated, not by company size or turnover.

In practical terms, this means:

The law primarily targets high-emission sectors including logistics, shipping, manufacturing, real estate developers, and energy-intensive operations. These businesses face the most immediate, clearly defined obligations and are where enforcement attention is concentrated first.

Businesses in high-emission sectors, as defined by the upcoming executive regulations, are required to comply from their assigned reporting year. Smaller businesses and lower-emission service sector firms may have voluntary pathways initially but should prepare for eventual inclusion.

So if you run a small professional services firm, you are technically in scope because every business generates some Scope 1 and Scope 2 emissions, but active enforcement is not currently directed at low-emission service businesses. The more immediate pressure for those businesses will likely come from clients, particularly large corporates and financial institutions, who need to account for supply chain emissions in their own Scope 3 reporting.

If you operate in financial services, fintech, real estate, logistics, manufacturing, construction, or any regulated sector, your obligations are direct, immediate, and enforced.

What the Law Requires

For in-scope businesses, the core obligations under Federal Decree-Law No. 11 of 2024 are:

  • Measurement and documentation of Scope 1 and Scope 2 GHG emissions
  • Registration on the national Measurement, Reporting, and Verification (MRV) platform
  • Use of MOCCAE-approved methodologies, primarily ISO 14064 or the GHG Protocol
  • Independent third-party verification by a MOCCAE-accredited verifier before submission
  • A structured, documented emissions reduction plan
  • Retention of all supporting data and calculations for a minimum of five years for regulatory review

Self-reported data alone does not satisfy the law. Emissions reports must be independently verified by a MOCCAE-accredited third-party verifier before submission.

On Scope 3: Federal Decree-Law No. 11 currently mandates Scope 1 and Scope 2 reporting. However, MOCCAE has indicated the framework will expand, and businesses should begin cataloguing Scope 3 data now, as Scope 3 visibility will be essential for future compliance cycles and green financing assessments.

Penalties for Non-Compliance

Administrative fines range from AED 50,000 to AED 2,000,000 depending on the nature, severity, and impact of the violation. MOCCAE and other authorised bodies enforce the law through regular inspections, detailed audits, and mandatory corrective orders. For repeat offences within two years of a prior conviction, fines may be doubled.

Beyond financial penalties, appearing on a regulatory adverse list carries long-term consequences for banking relationships, investor confidence, and contract eligibility, particularly for businesses serving government entities or regulated counterparties.

What In-Scope Businesses Must Do Now

If your compliance programme is incomplete, these are the priority actions:

Action Detail
Emissions inventory Establish a verified Scope 1 and Scope 2 GHG inventory
MRV platform registration Register with MOCCAE’s national platform if not completed
Methodology alignment Use ISO 14064 or GHG Protocol as approved by MOCCAE
Framework alignment Align disclosures with IFRS S1/S2, ISSB, TCFD, or GRI
Third-party verification Engage a MOCCAE-accredited independent verifier
Reduction plan Document a structured, time-bound emissions reduction strategy
Records retention Maintain all supporting data for a minimum of five years

Companies commonly underestimate three implementation challenges: ESG data fragmentation across departments, Scope 3 emissions complexity, and greenwashing risk from vague disclosures without data backing. Each requires a systematic approach, not a one-time document exercise.

Why Regulated Businesses Need an ESG Reporting Platform in Dubai

ESG sustainability software Dubai

Manual ESG data collection across departments is one of the most common bottlenecks compliance teams face. Spreadsheets pulling from separate HR, facilities, and procurement systems create version control problems, audit trail gaps, and verification failures that a MOCCAE-accredited verifier will flag immediately.

An ESG reporting platform in Dubai built for the UAE regulatory environment removes these bottlenecks by centralising data collection, automating emissions calculations, and generating audit-ready outputs aligned with applicable frameworks.

For regulated businesses managing AML, KYC, sanctions screening, and ESG obligations simultaneously, the operational value of an integrated compliance platform is significant. First Compliance’s Regulatory Reporting module is designed to handle exactly this kind of multi-framework environment, connecting data across your compliance obligations and reducing the manual burden on your team.

Selecting the right compliance platform is not just a technology decision. It is a risk management decision. Organisations relying on fragmented manual processes face higher exposure to data inaccuracies, missed deadlines, and third-party verification failures.

The Enforcement Phase Has Begun

The May 30, 2026 deadline has passed. For financial institutions, real estate developers, logistics operators, and all regulated businesses in the UAE, the obligation is now active and enforceable. Every week without a compliant emissions inventory, a registered MRV account, or a verified reduction plan increases both penalty exposure and the cost of remediation.

First Compliance is ready to support your team through this transition. Whether you are building a programme from scratch or strengthening an existing one, our platform and our specialists are built for this environment. Schedule a free demo today.

Frequently Asked Questions

Does Federal Decree-Law No. 11 of 2024 apply to free zone companies?

 Yes. The law explicitly covers all mainland and free zone entities operating in the UAE. Free zone registration does not exempt a business from its obligations under the Climate Change Law.

 Scope 1 covers direct emissions from sources your business owns or controls, such as company vehicles and fuel combustion. Scope 2 covers indirect emissions from purchased electricity and cooling. Scope 3 covers all other indirect emissions across your value chain, including those from suppliers and clients. The law currently mandates Scope 1 and Scope 2 reporting, with Scope 3 anticipated from 2027.

 No. Self-reported data alone does not satisfy the requirements of Federal Decree-Law No. 11 of 2024. All submissions must be independently verified by a MOCCAE-accredited third-party verifier before they are considered compliant.

 Administrative fines range from AED 50,000 to AED 2,000,000 per violation. Repeat offences within two years can double the penalty. Additional consequences include business suspension, loss of operating licences, mandatory corrective action, and placement on a regulatory adverse list.

 It centralises your emissions data collection, automates calculations using MOCCAE-approved methodologies, maintains a five-year audit trail, and generates verification-ready reports aligned with required frameworks including IFRS S1/S2, TCFD, and GRI. For businesses managing multiple compliance obligations, an integrated platform reduces duplication, eliminates manual errors, and ensures nothing falls through the gaps.

Proliferation Financing Is Now a Standalone Offence in the UAE: What Your Compliance Programme Needs to Add

Proliferation Financing Is Now a Standalone Offence in the UAE: What Your Compliance Programme Needs to Add

Compliance Monitoring Software in Dubai

The UAE’s financial crime framework has undergone its most significant overhaul in years. For compliance officers, MLROs, and senior management at financial institutions and DNFBPs, one change in particular demands immediate attention. Article 3 of Federal Decree-Law No. 10 of 2025 introduces proliferation financing as a standalone criminal offence for the first time, making it illegal to finance, without authorisation, arms or weapons of mass destruction. Proliferation financing now sits alongside anti-money laundering and counter-terrorist financing as one of the three principal offences under UAE law. If your compliance programme has not been updated to reflect this, it is no longer fit for purpose. Compliance monitoring software in Dubai built to manage the full AML/CFT/CPF framework is now a baseline requirement, not a competitive advantage.

What Federal Decree-Law No. 10 of 2025 Actually Changed

Federal Decree-Law No. 10 of 2025 on Anti-Money Laundering, Combating the Financing of Terrorism and Countering Proliferation Financing was issued in October 2025 and became effective on 14 October 2025. It repeals and replaces Federal Law No. 20 of 2018, ushering in a stricter and more comprehensive regime.

The key changes compliance teams need to understand are:

  • Proliferation financing is now recognised as a standalone criminal offence under Article 3, covering the financing of weapons of mass destruction, dual-use goods, and related technologies.
  • The law marks a shift from a reactive, compliance-tick-box regime into a proactive, intelligence-driven ecosystem. It integrates proliferation financing controls so that financing of weapons of mass destruction and related dual-use materials falls squarely within the compliance regime.
  • The law also introduces personal liability for managers, lowers the knowledge threshold for offences, and widens the regulatory perimeter to capture virtual asset service providers.
  • Criminal proceedings for money laundering, terrorism financing, and proliferation financing can now be initiated at any time, regardless of how many years have passed since the offence occurred. Past violations can be prosecuted indefinitely, creating permanent legal risk.

Who is in Scope

The businesses directly regulated under Federal Decree-Law No. 10 of 2025 are financial institutions, designated non-financial businesses and professions (DNFBPs), virtual asset service providers (VASPs), and some non-profit organisations with cross-border funding risks.

DNFBPs include real estate brokers and agents, lawyers, auditors, accountants, notaries, and dealers in precious metals and stones. Regulators segment oversight by sector: the CBUAE covers banks and finance, the Securities and Commodities Authority covers capital markets, the Insurance Authority covers insurance, the Ministry of Economy covers DNFBPs, and DIFC and ADGM authorities cover their respective free zones.

If your business falls into any of these categories, your compliance obligations under the new law are active, enforced, and carry personal liability for senior management.

What Your Compliance Programme Must Now Include

The introduction of proliferation financing as a standalone offence means your existing AML/CFT framework needs specific additions. A programme built for the 2018 law is not sufficient under Federal Decree-Law No. 10 of 2025. All regulated entities, including financial institutions, DNFBPs, and VASPs, are required to identify, assess, and mitigate proliferation financing risks within their AML/CFT compliance framework. The specific additions your programme must now address:
Compliance Area What Is Required
Risk assessment Update your enterprise-wide risk assessment to include a dedicated proliferation financing risk category
Policies and procedures Revise AML/CFT policies to explicitly reference CPF obligations and red flags
Sanctions screening Implement targeted financial sanctions screening specifically for PF-related designations
Customer due diligence Reassess CDD procedures to identify customers and transactions with proliferation financing exposure
Transaction monitoring Update monitoring rules and typologies to flag PF red flags, including dual-use goods transactions
Staff training Train employees on identifying PF-specific suspicious activity and their reporting obligations
Record keeping Document all compliance activities including CDD, monitoring, and reports
Beneficial ownership Tighten beneficial ownership verification, particularly for complex or layered structures

Industry advisers highlight the need to re-assess risk appetites, enhance screening and transaction monitoring systems, revisit governance arrangements, and ensure that management information and escalation processes reflect the heightened liability environment.

The Penalties and Personal Liability Exposure

The consequences of non-compliance under the new law are significantly more severe than under the 2018 framework.

Businesses must upgrade systems, governance, and internal controls immediately to avoid fines of up to AED 100 million and potential dissolution.

Senior officers can face personal prosecution, asset freezing, travel bans, and imprisonment for failure to comply with AML obligations. The introduction of personal liability is one of the most significant practical shifts in the new law. Compliance is no longer solely a corporate obligation. It is a personal one for every director and senior manager at a regulated entity.

Why Compliance Monitoring Software in Dubai Is Now a Necessity

AML Compliance Monitoring Software in Dubai

The expanded scope of Federal Decree-Law No. 10 of 2025 places demands on compliance programmes that manual processes simply cannot meet. Proliferation financing risk assessment requires real-time sanctions screening, transaction monitoring calibrated to PF typologies, documented CDD trails, and audit-ready records maintained indefinitely given the removal of the statute of limitations.

Compliance monitoring software in Dubai designed for the UAE’s regulatory environment gives compliance teams the infrastructure to meet these requirements systematically rather than reactively. At First Compliance, our platform covers every dimension of this framework:

For regulated businesses managing three distinct criminal offence categories simultaneously, the operational case for integrated compliance monitoring software in Dubai has never been clearer.

Act Now, Not After an Inspection

The inclusion of proliferation financing as a standalone offence creates a new risk profile that directors must be mindful of when conducting business in the UAE. Directors must ensure there are adequate AML, CFT, and proliferation financing procedures in place to deal with greater scrutiny and oversight.

Every regulated business in the UAE now operates under a three-offence compliance obligation. The firms that update their frameworks now, with the right compliance monitoring software in Dubai supporting their teams, will be the ones that face inspections with confidence rather than exposure.

First Compliance is ready to support your team through this transition. Schedule a free demo to see how our platform covers every requirement of Federal Decree-Law No. 10 of 2025.

Frequently Asked Questions

What is the difference between proliferation financing and terrorist financing under the new law?

 Terrorist financing involves providing funds to support terrorist acts or organisations. Proliferation financing specifically covers the financing of the development, production, acquisition, or transfer of weapons of mass destruction, including nuclear, chemical, biological, and radiological weapons, as well as dual-use goods and related technologies. Under Federal Decree-Law No. 10 of 2025, both are now standalone criminal offences alongside money laundering.

 Yes. DIFC and ADGM authorities are specifically named as supervisory bodies under the new framework, and the law applies to all regulated entities operating in the UAE regardless of whether they are mainland or free zone registered.

 Dual-use goods are items, materials, software, or technologies that have legitimate civilian applications but can also be used in the development of weapons of mass destruction. Transactions involving dual-use goods are a key proliferation financing red flag under the new law and must be captured within your transaction monitoring typologies and CDD procedures.

 The law has been in force since 14 October 2025 and the executive regulations under Cabinet Resolution No. 134 of 2025 became applicable from 14 December 2025. Compliance obligations are active now. Any regulated entity that has not yet updated its risk assessment, policies, and screening systems is already operating outside the requirements of the law.

 It automates the screening of customers and transactions against PF-specific sanctions lists, flags dual-use goods transactions through configurable monitoring rules, maintains a documented audit trail for every CDD and risk assessment decision, and generates the regulatory reports required for FIU submission. For senior management facing personal liability under the new law, an auditable, systematic compliance record is not just operationally useful. It is a legal protection.

Why UAE Gaming Operators Need a Reliable AML Screening Solution in Dubai

Why UAE Gaming Operators Need a Reliable AML Screening Solution in Dubai

AML screening solution Dubai

The UAE established the General Commercial Gaming Regulatory Authority (GCGRA) in September 2023, transforming from a jurisdiction with a total prohibition on gambling into one of the most closely watched gaming licensing destinations in the world.

Under Federal Decree-Law No. 10 of 2025, gaming operators are now formally classified as Designated Non-Financial Businesses and Professions (DNFBPs). This triggers the full spectrum of UAE anti-money laundering and counter-terrorism financing obligations. Deploying a robust AML screening solution in Dubai is a prerequisite for licensing, not an afterthought.

At First Compliance Solution, we help gaming operators, technology vendors, and key persons build the compliance infrastructure the GCGRA demands. This guide covers everything you need to know.

Part 1: The UAE Gaming Market in Context

From Prohibition to a Federal Licensing Regime

The UAE Penal Code previously prescribed fines of up to AED 20,000 and up to two years’ imprisonment for gambling participants, and up to ten years’ imprisonment for organisers.

The regulatory shift was driven by economics. Research indicated that even a 1.6% gaming contribution to GDP could generate approximately USD 6.6 billion annually, a meaningful diversification of the UAE’s economic base beyond oil and tourism.

On 3 September 2023, WAM (Emirates News Agency) announced the GCGRA’s establishment by federal decree, with a mission to “create a socially responsible and well-regulated gaming environment, ensuring that all participants adhere to strict guidelines and comply with the highest standards.” The GCGRA’s founders framed this not as an abandonment of cultural values, but as a responsible entertainment framework built on player safety, financial crime prevention, and responsible gaming.

Key Milestones

January 2024: Mahzooz and Emirates Draw paused operations to pursue GCGRA licensing.
July 2024: The Game LLC received the UAE’s first Lottery License.
November 2024: The UAE national lottery launched, including the AED 100 million “Lucky Day” jackpot.
October 2024: Wynn Resorts received the UAE’s first casino license for a USD 3.9–5 billion integrated resort on Al Marjan Island, Ras Al Khaimah, opening early 2027.
December 2024: The GCGRA issued a Consumer Advisory Notice warning against unlicensed operators.
April 2025: The GCGRA signed an MOU with New Jersey gaming regulators for cross-border regulatory cooperation.
Late 2025: Play971 became the UAE’s first licensed online gaming and sports betting platform.
1 June 2026: Federal Decree-Law No. 25 of 2025 came into effect, making GCGRA-licensed gaming contracts enforceable in UAE civil courts for the first time.
Morgan Stanley estimates the UAE gaming market could generate USD 3–5 billion in gross gaming revenue annually, making a GCGRA licence one of the most commercially significant regulatory permits available in the industry right now.

Part 2: The GCGRA's Structure and Mandate

The GCGRA is headquartered in Abu Dhabi and holds exclusive federal jurisdiction to regulate, license, and supervise all commercial gaming activities across all seven emirates. It operates with three core mandates: establishing and enforcing regulatory standards, overseeing financial crime prevention, and promoting responsible gaming through evidence-based player protection programmes.

The Four Categories of Regulated Gaming

Internet Gaming: Online casino games, eSports betting, and fantasy sports across all digital platforms. The definition is intentionally broad to accommodate new formats as they emerge.

Land-Based Gaming Facilities: Physical casinos, gaming floors, and slot halls. Wynn Al Marjan Island is the flagship project, with further licences expected.

Sports Wagering: Regulated betting on sporting events under GCGRA technical standards.

Lotteries: The GCGRA intends to maintain one official lottery. Existing games like Big Ticket and Dubai Duty Free may continue under GCGRA supervision, but no new lottery licences will be granted.

Technical Standards

The GCGRA has partnered with Gaming Laboratories International (GLI) to adopt GLI-19 (Interactive Gaming Systems) and GLI-33 (Event Wagering Systems) as its technical benchmarks.

Operating Without a Licence

Engaging in, conducting, or facilitating commercial gaming in the UAE without a GCGRA licence is illegal. Penalties include heavy fines, imprisonment, and business closure.

AML compliance software

Part 3: GCGRA Licensing - Types, Eligibility, and Process

Who Must Apply?

Every business and individual involved in any aspect of commercial gaming must obtain the appropriate licence before commencing activities, not just operators.

Licence Types

Entity Licences cover Gaming Operators, Gaming-Related Vendors and Suppliers, and Key Persons at the corporate level.

Individual Licences cover Key Persons (individuals) and Gaming Employees involved in the operation, supervision, or management of a licensed entity.

A single gaming operation may require multiple licence types. A resort operating a casino floor with proprietary software would need both a Gaming Facility Operator licence and a Gaming Technology Supplier licence.

Eligibility Requirements

The GCGRA evaluates all applicants against standards of integrity, financial capacity, and operational competence. Core criteria include a clean regulatory record across all operating jurisdictions, sufficient financial resources, and a detailed business plan incorporating responsible gaming frameworks, an AML compliance programme, and technical infrastructure specifications.

The Six-Step Licensing Process

Step 1: Intake Form. Submit the GCGRA Intake Form with company information, ownership structure, key persons, and intended licence types.

Step 2: Initial Screening and Portal Access. The GCGRA conducts preliminary screening. If in scope, the applicant gains access to the licensing portal.

Step 3: Full Documentation Submission. Submit corporate filings, AML/KYC policies, technical certifications, a responsible gaming programme, and key personnel documentation.

Step 4: Suitability Investigation. The GCGRA conducts background checks, financial verification, and operational capability assessments.

Step 5: Assessment and Approval. No formal deadline is set, but the GCGRA is committed to a smooth process. Applicants should plan for several months.

Step 6: Ongoing Monitoring. Licensing is not a one-time event. Operators face continuous compliance obligations and regular GCGRA engagement.

Documentation Checklist

● Constituent documents and certificate of registration
● Detailed business plan with financial forecasts and organisational charts
● AML/CFT compliance programme documentation
● Responsible gaming programme
● Technical specifications and independent laboratory certifications
● Key personnel backgrounds and declarations
● Proof of financial stability
● Local representative contact details

Part 4: AML/CFT Compliance Under the GCGRA

Gaming Operators Are Now DNFBPs

Cabinet Resolution No. 134 of 2025 formally includes gaming operators in the DNFBP definition under Article 3, Item 1. The AML threshold is a single or linked transaction at or above AED 11,000. At that level, the full UAE AML/CFT compliance framework applies.

Federal Decree-Law No. 10 of 2025 replaced the 2018 AML law, coming into effect on 14 October 2025. Cabinet Resolution No. 134 of 2025 followed on 14 December 2025 as its implementing regulation.

This is a significant structural shift for the gaming industry. Operators that previously had no formal AML obligations now sit within the same regulatory perimeter as financial institutions and real estate brokers. An effective AML screening solution in Dubai is not a compliance add-on for gaming businesses. It is the backbone of a licensable operation.

The Legal Framework at a Glance

● Federal Decree-Law No. 10 of 2025 on Combating Money Laundering, Terrorist Financing, and Proliferation Financing
● Cabinet Resolution No. 134 of 2025 (Executive Regulations)
● FATF Recommendation 22 (Enhanced CDD for casinos)
● The 2025 Commercial Gaming Policy Paper (GCGRA sector-specific guidance)
● Cabinet Decision No. 74 of 2020 (Targeted Financial Sanctions)

Core AML Obligations for Gaming Operators

  1. Customer Due Diligence (CDD): Operators must verify customer identities at onboarding. For online platforms this means Emirates ID verification with Arabic OCR and tamper detection, alongside international documents for expatriate and tourist users, and beneficial ownership identification under Cabinet Decision No. 109 of 2023.
  2. Enhanced Due Diligence (EDD): EDD is mandatory for Politically Exposed Persons (PEPs) and their associates, high-value customers, clients from high-risk jurisdictions, and customers displaying unusual transactional behaviour.
  3. Sanctions Screening: Operators must screen against the UAE Local Terrorist List and the UN Security Council Consolidated List under Cabinet Decision No. 74 of 2020. This must happen in real time, not as a periodic batch process. Any AML screening solution in Dubai deployed for gaming must cover both lists with continuous monitoring.
  4. Suspicious Transaction Reporting (STR): All STRs must be filed with the UAE Financial Intelligence Unit via the goAML platform. The GCGRA supervises reporting culture but does not receive STRs directly.
  5. Five-Year Record Retention: All CDD records, transaction records, and compliance documentation must be retained for a minimum of five years and made available to supervisory authorities on request.
  6. Enterprise-Wide Risk Assessment (EWRA): Operators must continuously assess and document ML/TF/PF risks across customer types, products, geographies, and delivery channels, aligned with the 2024 UAE National Risk Assessment.
  7. Designated MLRO: Every licensed operator must appoint a qualified Money Laundering Reporting Officer. Boards and senior management carry explicit responsibility for AML/CFT oversight.
  8. Staff Training: All relevant staff must receive regular, documented AML/CFT training covering gaming-specific typologies including structuring, chip washing, and layering through gaming platforms.

Part 5: Why a Dedicated AML Screening Solution in Dubai Is Central to Gaming Compliance

Gaming platforms process high transaction volumes, serve high-net-worth and international clientele, handle cash-equivalent instruments, and are attractive to those seeking to launder proceeds through the apparent legitimacy of winnings. Manual screening cannot meet the speed, accuracy, or scale that the GCGRA and Federal Decree-Law No. 10 of 2025 require.

The UAE national lottery operator, The Game LLC, is the clearest market example. The company deployed an AI-powered screening system that screens participants against PEP databases, sanctions lists, and adverse media reports to ensure no high-risk individuals can access lottery services. The system was integrated in under 11 weeks.

This is the standard the GCGRA expects. Any operator that approaches screening as a manual or ad hoc process will not survive regulatory scrutiny. A purpose-built AML screening solution in Dubai is the only practical answer.

What the Screening Solution Must Cover

PEP Screening: Real-time detection of domestic and foreign Politically Exposed Persons and their networks. Both PEP categories require EDD including source of wealth and source of funds verification. PEP status is time-bound and must be monitored continuously.

Sanctions Screening: Coverage across 1,300+ global watchlists and 200+ sanctions lists, including UAE-specific lists, UN consolidated lists, and enforcement databases.

Adverse Media Screening: Negative news monitoring identifies customers connected to financial crime or reputational risk who may not yet appear on formal sanctions lists.

Transaction Monitoring: Continuous monitoring for structuring, unusual deposit and withdrawal patterns, rapid chip conversion, and other gaming-specific money laundering typologies.

goAML Integration: The solution must support timely, high-quality STR submissions to the UAE FIU through the goAML portal.

Name Screening at Onboarding: Automated name screening at the point of customer registration is the first line of defence. Speed and accuracy here directly determine how much manual review burden the compliance team carries downstream.

Part 6: Responsible Gaming Obligations

The GCGRA treats responsible gaming as a core regulatory pillar. Every licensed operator must submit a Responsible Gaming Programme covering the following:
Self-exclusion mechanisms allowing players to voluntarily exclude
Deposit and loss limits configurable daily, weekly, and monthly
Cooling-off periods enforced at the platform level
Age verification with all marketing restricted to persons aged 18 and over, with no targeting of minors or vulnerable individuals
Staff training on identifying and assisting problem gamblers
Dedicated Responsible Gaming Officer responsible for programme oversight and GCGRA liaison

Part 7: Cybersecurity and Technical Compliance

GCGRA compliance extends to platform integrity and data protection. Mandated controls include:
● Platform penetration testing and vulnerability assessments
● Random Number Generator (RNG) certification by a GCGRA-approved laboratory
● Secure encryption for player data and financial transactions
● Payment system integrity controls
● Incident response plans for cybersecurity breaches and data protection incidents
● Player data protection in compliance with UAE data privacy law

Part 8: Enforcement and Penalties

The GCGRA has modelled its enforcement powers on regulators from New Jersey and Las Vegas. Non-compliance carries serious consequences.

Financial Penalties: Fines calibrated to the severity and duration of the breach. Under the broader UAE AML framework, administrative fines can reach AED 5,000,000 per violation.

Licence Suspension or Revocation: Serious or persistent AML failures or unlicensed operation can result in immediate suspension or permanent revocation.

Criminal Liability: Operating without a licence or facilitating unlicensed gaming may constitute a criminal offence. Violations of licensing requirements under Federal Decree-Law No. 10 of 2025 carry fines of not less than AED 200,000 and up to AED 10,000,000, plus potential imprisonment.

Cross-Border Enforcement: The GCGRA’s MOU with New Jersey regulators and its FATF-aligned framework enable active cooperation with international counterpart authorities.

Operators should also note that AML failures specifically trigger the harshest regulatory responses. A gap in your sanctions screening process, a missed PEP match, or a failure to file an STR are not minor administrative infractions in the UAE. They are grounds for licence revocation. This is precisely why selecting and deploying the right AML screening solution in Dubai must happen before you go live, not after your first supervisory review.

Part 9: The June 2026 Civil Code Reform

Federal Decree-Law No. 25 of 2025 (effective 1 June 2026) removed Articles 1012–1019 from the UAE Civil Transactions Law, eliminating the civil-law basis that treated gaming contracts as void. GCGRA-licensed gaming contracts are now enforceable in UAE civil courts for the first time. Unregulated gaming remains illegal.

For operators, this means contractual certainty with vendors, suppliers, and players, and a materially reduced risk profile for institutional investors. It also signals that the UAE is committed to building a permanent, mature gaming jurisdiction rather than a transitional regulatory experiment.

Part 10: Building Your Compliance Programme - A Practical Framework

Governance: Appoint a qualified MLRO with appropriate seniority. Establish Board-level AML/CFT oversight with documented accountability and a compliance committee with regular reporting lines.

Risk Assessment: Conduct an EWRA covering customer, product, geographic, and delivery channel risk. Map it to the UAE National Risk Assessment 2024 and the 2025 Commercial Gaming Policy Paper. Review annually or following material business changes.

Customer Onboarding and KYC: Deploy identity verification for Emirates IDs and international documents. Implement real-time PEP, sanctions, and adverse media screening at onboarding. Build risk-based CDD profiles with clear EDD triggers. The onboarding workflow is where your AML screening solution in Dubai does its most critical work. Get it right from the start.

Transaction Monitoring: Deploy a system with gaming-specific typology rules. Set thresholds aligned with the AED 11,000 DNFBP trigger. Integrate STR workflows directly with goAML.

Policies and Procedures: Document all AML/CFT policies in line with Cabinet Resolution No. 134 of 2025 and the 2025 Commercial Gaming Policy Paper. Review and approve annually at senior management level.

Trainin: Deliver regular, documented training to all relevant staff. Include gaming-specific typologies and case studies. Maintain training records for GCGRA inspection.

Regulatory Reporting: Register on goAML before commencing operations. Establish clear escalation and investigation procedures. Retain all records for a minimum of five years.

Ready to Build Your GCGRA-Compliant AML Programme?

Whether you are planning your GCGRA licence application, building your AML/CFT framework from scratch, or stress-testing an existing programme against Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025, First Compliance Solution is your partner.

Contact us today for a confidential consultation. Our specialists will assess your compliance posture, identify gaps against GCGRA and UAE AML requirements, and design a tailored roadmap to full regulatory readiness.

This blog is intended for informational purposes and does not constitute legal advice. First Compliance Solution recommends engaging specialist advisors for all GCGRA licensing and AML compliance matters.

Professional Compliance Training in Dubai- Why Choose First Compliance?

Professional Compliance Training in Dubai- Why Choose First Compliance?

Automated Compliance Software

First Compliance is a KHDA-approved training provider in Dubai, delivering professional development and certification programmes rooted in real-world compliance experience. As regulatory expectations continue to rise across the region, the quality of training has become a strategic priority for individuals and organisations alike. Our programmes are built and delivered by practitioners who have worked inside the compliance challenges our clients face every day, and our use of automated compliance software as part of that learning experience ensures professionals leave genuinely prepared, not just certificated.

What KHDA Approval Means for You

KHDA approval from the Knowledge and Human Development Authority confirms that First Compliance meets the training governance, delivery quality, and programme standards required for professional training in Dubai. It means our programmes operate within a recognised framework, our certificates carry credibility as evidence of professional completion, and our delivery standards are subject to structured oversight.

For professionals and organisations investing in compliance training in Dubai, that recognition matters. The training you receive from First Compliance is not self-certified. It is practitioner-led, quality-assured, and formally recognised.

It is equally important to be clear about what KHDA approval does not cover. It relates to training delivery, not regulatory licensing. It does not confer professional authorisation, replace regulator-mandated certifications, or constitute a licence for individuals or organisations. KHDA approval applies to the provider and its programmes. The professional value comes from what those programmes actually deliver.

Training Built by Practitioners, for Practitioners

Automated Compliance Software

First Compliance’s approved compliance training programmes span the disciplines that matter most to compliance professionals and risk-focused organisations across Dubai and the wider region.

Our AML and Financial Crime Compliance programmes cover Anti-Money Laundering, Counter-Terrorist Financing, and Financial Crime Risk Management. These are areas where the gap between theoretical knowledge and practical readiness carries real consequences, and our trainers have operated in exactly these environments.

Our Governance, Risk and Compliance programmes address governance frameworks, regulatory compliance, audit oversight, and risk management, delivered by professionals who have navigated these structures from the inside.

Our ESG and Sustainability programmes cover governance and reporting, sustainability strategy, and climate and environmental compliance, reflecting how rapidly these obligations are growing for organisations of all sizes in the region.

Our Corporate Professional Development offering focuses on compliance capability building, risk management training, and leadership and governance programmes, designed for organisations that want to grow genuine internal expertise.

Where Automated Compliance Software Fits In

Practitioner knowledge builds capability. But in today’s regulatory environment, that capability needs to be supported by the right tools. That is where automated compliance software becomes an essential part of the conversation.

For professionals completing our programmes, understanding how automated compliance software functions, what it can manage, and where human judgement remains critical is increasingly central to what it means to be compliance-ready. Organisations that pair well-trained professionals with the right automated compliance software are better positioned to meet reporting requirements, manage risk exposure, maintain clean audit trails, and respond to regulatory change quickly and confidently.

At First Compliance, we treat automated compliance software as part of the broader compliance landscape our professionals need to understand and work within, not as a topic separate from training.

A KHDA-Approved Foundation for Compliance Training in Dubai

Automated Compliance Software

First Compliance exists because regulatory readiness cannot be built on shortcuts, and because the best compliance training comes from people who have lived it. Organisations that invest in practitioner-led, governed, and quality-assured training build the internal capability to manage compliance obligations with genuine confidence.

Whether you are building a compliance function from the ground up, strengthening an existing team, or ensuring your organisation meets the governance standards expected in Dubai and across the region, First Compliance brings the practitioner depth and the formal recognition to do it properly.

KHDA-Approved Training. Built for the Demands of Modern Compliance.

As compliance obligations grow more complex and automated compliance software becomes more deeply embedded in how organisations manage risk and governance, the professionals who perform best will be those who combine structured, practitioner-led knowledge with real operational readiness. First Compliance’s KHDA-approved compliance training programmes in Dubai are designed to build exactly that.

To find out more about our programmes or to discuss your organisation’s training needs, visit our Contact Us page.

Virtual Assets and Crypto AML in UAE 2026: VARA, DFSA Updates, and Compliance Essentials for VASPs c

Virtual Assets and Crypto AML in UAE 2026: VARA, DFSA Updates, and Compliance Essentials for VASPs

compliance and risk management

Introduction

The UAE has firmly established itself as one of the most active and tightly regulated jurisdictions for virtual assets in the world. As of 2026, crypto businesses operating anywhere in the Emirates are dealing with a rapidly evolving compliance landscape that touches everything from licensing requirements and transaction monitoring to risk assessments and anti-money laundering controls. Whether you are running a crypto exchange in Dubai mainland, a custodial service in the DIFC, or a payments platform onshore, understanding your regulatory obligations is no longer optional. It is a condition of staying in business.

This blog breaks down the key regulatory developments from VARA and the DFSA, the AML requirements that now apply to virtual asset service providers (VASPs) across the UAE, and how a purpose-built AML screening solution in Dubai can help your business meet these obligations without the operational chaos that often comes with compliance at scale.

The UAE Regulatory Landscape for Virtual Assets in 2026

The UAE does not have a single regulator for crypto. It has several, and each one governs a distinct jurisdiction. Understanding which regulator applies to your business is the foundation of any compliance programme.

VARA is Dubai’s dedicated regulator for virtual assets operating in onshore Dubai, outside of the DIFC. It handles licensing and regulating VASPs within its jurisdiction. The DFSA is the independent regulator of financial services within the Dubai International Financial Centre, with its own distinct framework for virtual assets. The Central Bank of the UAE plays a role in overseeing fiat-to-crypto transactions and regulates payment and digital banking services related to virtual assets.

In August 2025, the UAE’s Capital Markets Authority and VARA agreed on a shared framework to regulate virtual assets across the UAE, with the agreement including mutual recognition of VASP licenses issued by either authority.

For businesses operating across multiple jurisdictions within the UAE, compliance with one framework does not substitute for compliance with another. Each regulatory pathway carries its own licensing requirements, timelines, capital thresholds, and AML standards.

VARA Rulebook 2.0: What Changed in 2025 and Beyond

VARA continues to govern virtual asset activities in Dubai and most UAE free zones outside the DIFC, under VARA Rulebook Version 2.0 published in May 2025.

The updated rulebook introduced more detailed expectations around how licensed VASPs must structure their compliance and risk management functions. One of the most significant developments relates to on-chain transaction monitoring.

VARA’s Compliance and Risk Management Handbook specifies that monitoring of distributed ledger technology transactions must be combined with AML typologies such as unusual deposit and withdrawal patterns and other behavior analytics to inform the overall compliance process. This means that simply running periodic checks is no longer enough. VASPs are expected to have systems that connect on-chain wallet activity with their broader KYC and case management processes.

In November 2025, VARA issued a circular providing guidance to regulated VASPs on risk assessment requirements, following the May 2025 Risk Management Rulebook and a June 2025 national risk assessment circular.

Other key milestones include the enforcement of VARA’s Custody Rulebook from March 2025 and the Marketing Rulebook from June 2025, both of which carry fine risk for non-compliant licensed entities. The VARA Annual MLRO Certification Renewal deadline also fell in February 2026, requiring all licensed entities to renew their Money Laundering Reporting Officer credentials. Penalties for operating without a license or for AML breaches can be severe. Operating without a license can result in immediate cease-and-desist orders, asset freezes, and fines reaching AED 1 billion, and even licensed entities face sanctions for AML breaches, inadequate reporting, or governance failures.

DFSA Updates: The New Crypto Token Suitability Framework

For businesses operating in or from the DIFC, the DFSA rolled out a major update to its crypto token regulatory framework in January 2026.

The DFSA issued updated rules on the regulation of crypto tokens in the DIFC, which came into force on 12 January 2026. The updated rules refine and strengthen the regime first introduced in 2022 and mark the next phase in the continued development of the DFSA’s digital assets regulatory framework. Under the updated regime, firms providing financial services involving crypto tokens are directly responsible for determining, on a reasoned and documented basis, whether each crypto token they engage with meets the DFSA’s suitability criteria. The DFSA will no longer prescribe a list of recognized crypto tokens.

This shift moves the compliance burden directly onto firms. Previously, the DFSA maintained a closed list of recognized crypto tokens based on its own assessment. Under the amended approach, DFSA-authorized firms must perform and document their own suitability assessments for any crypto assets they custody, deal in, list, hold, or otherwise use in connection with regulated activities.

The suitability assessment must consider AML and CFT risks, sanctions exposure, anonymity-enhancing features, and whether the token can be effectively monitored using block chain analytics. Each firm must assess each crypto token it wishes to use for suitability and tailor that assessment to its own business model and the specific context in which the token will be used.

As of January 2026, the DFSA recognizes three fiat tokens, which are Circle Euro Coin (EURC), Circle USD Coin (USDC), and Ripple USD (RLUSD).

The practical implication is clear: DIFC-based firms now need internal compliance processes that are capable of producing structured, evidence-based token assessments. The quality of your documentation is now a regulatory requirement, not just an internal best practice.

AML Obligations for VASPs Under UAE Federal Law

At the federal level, 2025 brought a significant update that every VASP in the UAE needs to be aware of.

The UAE published the 2025 Federal Decree-Law on AML, CFT, and CPF, establishing new regulatory requirements for VASPs. As part of compliance, VASPs must conduct a mandatory GAP assessment of their current AML, CFT, and CPF policies, procedures, systems, and controls against the provisions of the 2025 Decree-Law. The deadline for submitting a completed GAP assessment was 60 calendar days from the issuance of the relevant circular, and this had to include clause-by-clause mapping, a board-approved remediation plan with owners, milestones, and target dates, and evidence of immediate risk-based mitigations for any high-risk gaps identified.

For many VASPs, this triggered an urgent internal review of their AML frameworks. Firms that had not yet invested in structured compliance infrastructure found themselves scrambling to produce documentation they did not have.

Core AML requirements for all VASPs operating in the UAE include customer due diligence and enhanced due diligence for high-risk clients, ongoing transaction monitoring with documented typologies, sanctions screening against UAE, UN, OFAC, and other applicable lists, PEP (Politically Exposed Person) screening at onboarding and on a periodic basis, suspicious transaction reporting to the UAE Financial Intelligence Unit, and maintenance of records for a minimum period in line with regulatory guidance.

An effective AML screening solution in Dubai needs to address all of these requirements in a single, integrated workflow rather than through disconnected manual processes.

What VASPs Must Have in Place: A Practical Compliance Checklist

Whether you are licensed under VARA, the DFSA, or working toward licensing under either framework, the following are the core compliance building blocks you need to have in place in 2026.

AML Screening and Sanctions Monitoring

Every customer and every transaction must be screened against the relevant sanctions lists at onboarding and on a continuous basis. This includes UAE Central Bank lists, UN consolidated lists, OFAC, EU, and UK sanctions, as well as local watch lists maintained by the Ministry of Economy and other UAE authorities. A reliable AML screening solution in Dubai automates this process and reduces the manual effort involved in managing false positives and escalations.

VARA and the DFSA both require VASPs to implement a risk-based KYC framework. This means collecting and verifying identity documents, understanding the nature and purpose of the business relationship, and applying enhanced due diligence to customers who present elevated risk. For crypto businesses, this also extends to understanding the source of crypto funds where transactions are large or unusual.

On-Chain Transaction Monitoring

As VARA’s Rulebook 2.0 makes clear, standard transaction monitoring is not enough for crypto businesses. On-chain KYT (Know Your Transaction) tools need to be integrated with your broader AML workflow so that wallet risk ratings, transaction histories, and behavioral patterns are visible to compliance teams alongside traditional account data.

Risk Assessment Documentation

Both VARA and the DFSA now place significant emphasis on documented risk assessments. Under VARA’s November 2025 circular, regulated VASPs must follow clear methodologies for their institutional and customer-level risk assessments. Under the DFSA’s January 2026 update, firms must produce reasoned and documented token-level suitability assessments. Without a system to manage this documentation, these requirements quickly become unmanageable.

Case Management and Reporting

Compliance teams need a centralized place to manage alerts, conduct investigations, and file reports. A good AML screening solution in Dubai will include case management functionality so that nothing falls through the cracks and audit trails are complete.

Why an AML Screening Solution in Dubai Matters for Crypto Compliance

compliance and risk management

Many VASPs come to the UAE with existing compliance tools that were built for traditional financial services or for lighter-touch regulatory environments. Those tools often fall short when applied to the specific demands of UAE crypto compliance.

The combination of VARA’s on-chain monitoring requirements, the DFSA’s firm-led token suitability framework, and the UAE’s federal AML decree means that compliance teams are managing a significantly larger and more complex set of obligations than they were even two years ago. Manually tracking sanctions hits, PEP flags, wallet risk ratings, and case documentation across spreadsheets or disconnected systems is not realistic at any meaningful scale.

A purpose-built AML screening solution in Dubai offers several practical advantages. It brings all screening, monitoring, and case management into one platform. It automates periodic re-screening so that customers who were clean at onboarding are checked again when new sanctions designations are issued. It provides audit-ready documentation that can be presented to VARA or DFSA inspectors without additional preparation. And it scales as the business grows, without requiring a proportional increase in compliance headcount.

First Compliance offers exactly this kind of platform for VASPs operating in the UAE. With modules covering sanctions screening, PEP screening, transaction monitoring, e-KYC with real-time face verification, risk management, regulatory reporting, and case management, it is designed to meet the compliance demands of both VARA and DFSA-regulated entities. The platform integrates with hundreds of global sanctions lists and adverse media sources and supports customizable workflows that can be adapted to the specific risk appetite and business model of each VASP.

Conclusion

The regulatory environment for virtual assets in the UAE is more structured, more demanding, and more consequential than ever before. VARA Rulebook 2.0, the DFSA’s January 2026 token suitability framework, and the 2025 Federal AML Decree have collectively raised the bar for what it means to be a compliant VASP in this jurisdiction. The expectations around on-chain monitoring, documented risk assessments, continuous sanctions screening, and qualified MLRO oversight are no longer aspirational standards. They are enforceable requirements with real penalties attached.

For VASPs that want to operate with confidence in the UAE market, investing in the right AML screening solution in Dubai is one of the most important steps you can take. The right tool does not just help you meet current requirements. It prepares you for the next round of regulatory updates, which in this market, are never far away.

To learn more about how First Compliance can support your VASP’s AML and compliance needs in the UAE, contact us.

CBUAE Inspections in the Insurance Sector: What to Expect, how to Respond, and Why Compliance Helps

CBUAE Inspections in the Insurance Sector: What to Expect, how to Respond, and Why Compliance Helps

PEP and sanctions screening in Dubai

If you run an insurance company in the UAE, a CBUAE inspection is not a question of if. It is a question of when and how ready you will be when it happens.

Since the Central Bank of the UAE took over the functions of the former Insurance Authority in 2020, its supervisory reach has grown considerably. Today, it conducts structured on-site inspections across insurance companies, reinsurers, agents, and brokers, looking closely at AML/CFT controls, governance frameworks, risk management, and customer protection standards. And since the UAE’s removal from the FATF grey list in 2024, the pace and intensity of enforcement have accelerated sharply.

Among the most scrutinised areas in any insurance inspection is PEP and sanctions screening in Dubai. Whether your controls are manual or automated, whether your coverage is complete or patchy, and whether your alert handling is documented or ad hoc, inspectors will look at all of it closely. This guide walks you through what a strong Sanctions Compliance Programme looks like, how the full Targeted Financial Sanctions workflow should operate, who is responsible for what, and how to build a training programme that holds up under regulatory review.

Why CBUAE Inspections Are Important

The UAE’s exit from the FATF grey list in 2024 was a significant milestone, but it came with a clear expectation: the UAE had to prove that its supervisory regime was genuinely effective, not just compliant on paper. The CBUAE responded in 2025 with one of its most aggressive enforcement campaigns to date, issuing large fines, licence revocations, restrictions, and personal sanctions against individuals in senior compliance roles.

Insurance companies are fully in scope. The CBUAE requires them to run comprehensive AML/CFT programmes covering customer due diligence, enhanced due diligence, suspicious transaction reporting, and sanctions screening, and insurers remain responsible for all of these controls even when certain functions have been delegated to agents or brokers.

Sanctions Compliance and Targeted Financial Sanctions: Getting It Right

Sanctions compliance is one of the areas where insurance companies are most frequently found wanting during CBUAE inspections. Weak or inconsistent PEP and sanctions screening in Dubai is a recurring finding, and the consequences range from formal warnings to personal sanctions against senior compliance officers. A properly structured Sanctions Compliance Programme is no longer optional. It is a baseline supervisory expectation.

What Is a Sanctions Compliance Programme?

A Sanctions Compliance Programme is the complete set of policies, procedures, controls, and oversight mechanisms an insurance company puts in place to ensure it does not do business with sanctioned individuals, entities, or jurisdictions. It is not simply a matter of having a sanctions list loaded into a system. It is a managed, documented process covering how customers are screened, how alerts are handled, how confirmed matches are escalated, and how the institution reports to regulators.

Understanding Targeted Financial Sanctions

PEP and sanctions screening in Dubai

Targeted Financial Sanctions, or TFS, are a specific and particularly time-sensitive category of sanctions obligation. They involve asset freezes and prohibitions on making funds or economic resources available to designated individuals, entities, and groups listed by the UN Security Council and the UAE’s own Local Terrorist List and Proliferation Financing List.

What makes TFS different from general sanctions compliance is the immediacy of the obligation. When a designated person or entity is identified, the requirement to freeze assets and report to the relevant authority applies without delay. There is no review window, no de minimis threshold, and no tolerance for a slow response. This is why the end-to-end TFS workflow must be clearly defined, consistently applied, and supported by technology that can keep pace with the obligation.

The End-to-End TFS Workflow

Step 1: Screening

Every customer must be screened against relevant sanctions lists at onboarding and continuously throughout the relationship. The lists that must be covered include the UN consolidated list, OFAC SDN, EU consolidated list, HM Treasury list, and the UAE’s own Local Terrorist List and Proliferation Financing List. Screening must extend beyond the customer to include beneficial owners, authorised signatories, and counterparties.

Effective PEP and sanctions screening in Dubai requires the screening system to be configured with appropriate fuzzy matching logic to catch name variations, transliterations, and spelling differences without generating an unmanageable volume of false positives. A system that throws up hundreds of alerts per week with no intelligent filtering is not a functioning compliance control. It is a noise generator that breeds alert fatigue and missed matches.

Step 2: Alert Handling

When a potential match is generated, the system raises an alert. A trained compliance analyst conducts an initial review to determine whether the alert is a true match, a false positive, or requires escalation. This review must be documented. The analyst checks identifying information against the listed individual or entity, considering name variations, date of birth, nationality, and any other available identifiers, and records the outcome with supporting evidence. No transactions involving the flagged customer may proceed while the alert remains open.

Step 3: Escalation

If the initial review cannot rule out a match, or if a confirmed match is identified, the case must be escalated immediately to the MLRO or Deputy MLRO. The MLRO determines whether the match is confirmed and triggers the asset freeze and reporting obligations. Senior management must be notified without delay. The escalation path must be pre-defined in the Sanctions Compliance Programme so that no one is unclear about what to do or who to contact when a real match is found.

Step 4: Regulatory Reporting

Confirmed TFS matches must be reported to the UAE Financial Intelligence Unit via the GoAML portal. The insurer must also notify the CBUAE and comply with any specific instructions issued in connection with the designation. All reporting must be completed without tipping off the designated person. Delays in reporting are treated as a serious compliance failure.

Step 5: Record Keeping and Ongoing Monitoring

All screening results, alert reviews, escalation decisions, and regulatory reports must be retained for a minimum of five years. Customers subject to confirmed or suspected TFS matches must remain under enhanced ongoing monitoring. The case management system must maintain a complete, time-stamped audit trail across every step of the workflow.

Mapping Roles and Functions in the TFS Workflow

One of the most common inspection findings in sanctions compliance is that responsibilities are unclear. Staff are unsure who owns the screening, who reviews alerts, and who escalates. A well-designed Sanctions Compliance Programme maps roles explicitly so there is no ambiguity when it matters most.

Function Responsibilities
Front-line Operations Collect customer data accurately at onboarding; flag unusual customer behavior; do not process transactions while alerts are open
Compliance Analyst Conduct initial alert review and document outcome; escalate unresolved or confirmed matches to MLRO; maintain case records
MLRO / Deputy MLRO Make final determination on confirmed matches; trigger freeze and reporting obligations; notify senior management; liaise with regulators
Senior Management Receive escalation notifications; support resourcing of the compliance function; approve sanctions compliance policies
Board / Audit Committee Receive regular reporting on TFS programme performance; approve the sanctions compliance framework; ensure tone from the top supports a compliance culture

Training Needs Analysis and Approved Training Plan

Sanctions training is not a tick-box exercise. The CBUAE expects evidence that different staff receive training appropriate to their role and that this training is documented, assessed, and refreshed regularly. A training needs analysis is the starting point.

Front-line operations staff need a foundational understanding of what sanctions are, what a TFS obligation means in practice, and what they must do when a potential match is flagged. They also need to understand the basics of PEP identification so that they can collect the right information at onboarding and flag concerns to the compliance team when something does not feel right.

Compliance analysts need more technical training covering how to review and document alerts, how to distinguish a true match from a false positive, when and how to escalate, and how to use the case management system to maintain a complete audit trail. Training on the specific mechanics of PEP and sanctions screening in Dubai, including the lists in scope, the matching methodology, and the regulatory timeline requirements, should be covered in depth.

The MLRO and Deputy MLRO require comprehensive training covering the full legal and regulatory framework, TFS reporting obligations, the GoAML portal, management of confirmed matches, and the personal consequences of reporting failures. Ongoing CPD is expected and should be evidenced.

Senior management and board members need awareness-level training focused on governance obligations, the strategic and reputational risk that sanctions non-compliance poses, and their personal accountability under UAE law.

The approved training plan should document the following for each staff category: training topic, delivery format (in-person, e-learning, or workshop), frequency (annual as a minimum for all, with additional refresher training whenever regulations or lists change), assessment method, and records of completion. Training materials must be kept current and reflect the most recent CBUAE guidance and changes to the UAE sanctions framework. Inspectors will ask to see completion records and will check dates against any regulatory updates to verify that training kept pace with change.

The Full Inspection Lifecycle: Pre-Exit, Exit, and Post-Inspection

Understanding what happens at each stage of a CBUAE inspection helps you manage the process without being caught off-guard.

Before the Inspection

When the CBUAE provides advance notice, use that window purposefully. Conduct an internal readiness review. Gather documentation across all inspection areas. Verify that your PEP and sanctions screening in Dubai is generating clean, auditable records and that your MLRO is briefed and ready to lead the response. This preparation period is your most valuable asset.

The Pre-Exit Meeting

Before inspectors formally conclude, they share preliminary observations with your team. Your compliance team can provide clarifications, supply additional documentation, and correct factual misunderstandings before findings are formalized. Come prepared with clear evidence of your controls and any corrective actions already underway. This signals institutional credibility.

The Exit Meeting

This is the formal close. The CBUAE presents its official findings and outlines remediation expectations. How you respond from this point forward shapes the regulator’s view of your institution.

How to Write a Strong Post-Inspection Response

PEP and sanctions screening in Dubai

A regulatory response is a formal commitment. Follow-up inspections will verify that those commitments have been kept.

Acknowledge each finding directly and without deflection. Identify the root cause of each issue, whether it is a system gap, a training shortfall, or a process breakdown.

Map each finding to a specific remediation action with a named owner and a realistic completion date. Vague commitments carry no weight. If the finding relates to inadequate PEP and sanctions screening in Dubai, specify what system is being implemented, what list coverage it provides, and when existing customers will be rescreened.

Update your AML/CFT policies and procedures to reflect the remediated controls, obtain board approval, version-control the documents, and ensure they are distributed to all relevant staff.

Put an internal monitoring mechanism in place to verify that remediation has actually been completed. A well-integrated compliance platform should provide the audit trail, the workflow evidence, and the reporting capability that regulators expect to see when they return.

How First Compliance Supports Insurance Companies in the UAE

First Compliance is a comprehensive compliance and due diligence software platform developed by a team of experts in law, compliance, and anti-financial crime, with a proven track record in regulatory compliance inspections, transaction monitoring, and AI-powered adverse media screening.

For insurance companies managing CBUAE inspection readiness, the platform covers every area inspector examine. It centralises customer data, screening results, risk scores, and case records in a single system so that when an inspector asks for evidence of CDD or sanctions processes, your team can produce complete, time-stamped records immediately.

The platform is integrated with hundreds of global sanctions lists and supports the full TFS workflow from automated screening through alert generation, case management, escalation tracking, and regulatory reporting. Every step is documented and auditable, supporting both the compliance analysts conducting initial reviews and the MLRO managing escalations and GoAML submissions.

For insurance companies that need reliable PEP and sanctions screening in Dubai that scales with regulatory expectations, First Compliance aligns with CBUAE guidelines, FIU requirements, free zone regulations, and DFSA and ADGM compliance standards, making it a locally grounded platform built for the UAE environment.

Frequently Asked Questions

What is the difference between a pre-exit meeting and an exit meeting

The pre-exit meeting happens while inspectors are still on-site and gives your team an opportunity to provide clarifications before findings are finalised. The exit meeting is the formal conclusion where the CBUAE presents official findings and outlines remediation expectations.

If you run an insurance company in the UAE, a CBUAE inspection is not a question of if. It is a question of when and how ready you will be when it happens.

Since the Central Bank of the UAE took over the functions of the former Insurance Authority in 2020, its supervisory reach has grown considerably. Today, it conducts structured on-site inspections across insurance companies, reinsurers, agents, and brokers, looking closely at AML/CFT controls, governance frameworks, risk management, and customer protection standards. And since the UAE’s removal from the FATF grey list in 2024, the pace and intensity of enforcement have accelerated sharply.

Among the most scrutinised areas in any insurance inspection is PEP and sanctions screening in Dubai. Whether your controls are manual or automated, whether your coverage is complete or patchy, and whether your alert handling is documented or ad hoc, inspectors will look at all of it closely. This guide walks you through what a strong Sanctions Compliance Programme looks like, how the full Targeted Financial Sanctions workflow should operate, who is responsible for what, and how to build a training programme that holds up under regulatory review.

The CBUAE typically specifies a response timeframe in the post-inspection communication. Serious findings may require responses within 30 days, while broader remediation plans may be given longer timelines. All deadlines should be treated as firm commitments.

Incomplete customer due diligence files, failure to apply enhanced due diligence for high-risk customers and PEPs, absence of a documented transaction monitoring framework, late or missing GoAML suspicious transaction reports, inadequate PEP and sanctions screening coverage, and insufficient AML training records.

Penalties range from financial fines to license suspension or revocation. Personal sanctions against senior management and compliance officers are increasingly common in the UAE. Repeated non-compliance escalates penalties significantly.

Yes. First Compliance’s platform is designed to make insurance companies inspection-ready at all times through continuous compliance monitoring, automated PEP and sanctions screening, real-time transaction monitoring, and structured case management. To find out more or book a demo on our website.

Scroll to top