On 16 April 2026, the Central Bank of the UAE released six new AML/CFT/CPF guidance documents in a single package, and one of them rewrote what customer due diligence is supposed to look like day to day. The headline change: CDD is no longer something you complete at onboarding and file away. It has to run continuously, for the life of the relationship.
That single shift is why so many UAE compliance teams are now looking at customer due diligence software in Dubai instead of stretching their existing manual process further. This guide walks through what the April 2026 guidance actually requires, where manual review breaks under it, and what to look for in software built to meet the new standard. At First Compliance, we build the platform UAE businesses use to run this kind of continuous, documented due diligence without adding headcount, and this is the guidance shaping how we build it.
The CBUAE package covered four supervisory guidelines and two best practice manuals, addressing proliferation financing risk assessment, trade-based money laundering, correspondent banking due diligence, and customer due diligence, including KYC and record-keeping. The CDD document is the one with the widest operational reach, because nearly every regulated entity performs CDD in some form.
Dynamic, risk-based CDD replaces one-time onboarding checks: customer risk profiles must now be reassessed throughout the relationship, not just at the point a customer signs up. A profile built at onboarding and never revisited no longer meets the standard.
Trigger events force a review: a significant change in transaction behaviour, a new business activity, or a change in ownership must prompt a fresh CDD review, whether or not the customer is due for their scheduled periodic check.
Real-time transaction monitoring is now the baseline: automated systems with anomaly-detection capabilities are described as the expected standard, not a best-practice suggestion. This is a meaningful language shift from earlier guidance, which left more room for judgment calls.
Digital onboarding gets its own bar to clear: institutions using electronic identity verification, including video verification or biometric checks, must meet CBUAE-specified standards for reliability and independence of the data used.
Record-keeping is now standardised at five years:CDD documentation must be retained for five years following the end of the relationship, with a clear, reconstructable trail available for regulators and law enforcement.
None of these five requirements are impossible to do by hand. The problem is doing all five, consistently, at the volume a growing UAE business actually processes.
Review queues scale badly with onboarding volume: a compliance analyst can work through a fixed number of files a day. Add more customers and the queue grows linearly, but risk exposure grows with every unreviewed file sitting in it. Automated periodic screening, by contrast, is now described in the April 2026 guidance as a direct expectation for teams managing hundreds of active accounts, not a discretionary upgrade.
Trigger events are easy to miss without a system watching for them: a manual process depends on someone noticing that a client’s transaction pattern shifted, or that ownership changed on a trade licence renewal. Without automated flags tied to those specific events, the review simply doesn’t happen until the next scheduled check, which can be months away.
Documentation quality varies by analyst and by day: five-year record retention only helps if the records are complete and consistent in the first place. Manual files drift in format and depth over time, which is exactly what shows up as a finding during a CBUAE inspection.
Fun fact worth knowing: the CDD guidance doesn’t just apply to banks. DNFBPs, including real estate agents, lawyers, accountants, and corporate service providers, are regulated separately under the Ministry of Economy, but the risk-based CDD standards in the CBUAE guidance mirror the broader expectation across all regulated entities in the UAE.
Not every platform marketed for KYC or AML actually covers what the April 2026 guidance asks for. When evaluating customer due diligence software in Dubai, the following capabilities map directly to the new requirements:
Requirement | Manual process | Automated CDD software |
Risk profile updates | Reviewed at scheduled intervals only | Recalculated continuously as new data arrives |
Trigger event detection | Depends on staff noticing changes | Automatic flag tied to defined events |
Transaction monitoring | Sample-based or reactive | Real-time with anomaly detection |
Digital identity verification | Document upload, manual check | Biometric and video verification |
Record-keeping | Varies by analyst, format drift | Standardised, timestamped, five-year retention |
The April 2026 guidance didn’t just add more paperwork, it changed what “compliant” means. A risk profile that’s accurate on day one but never revisited is no longer a defensible position. Businesses that automate the reassessment cycle, the trigger detection, and the record-keeping will walk into their next CBUAE inspection with evidence, not just policy.
If your current process still runs on manual reviews and shared spreadsheets, it’s worth seeing what a continuous system looks like in practice. Schedule a free demo with First Compliance to see how our platform handles the full CDD lifecycle the April 2026 guidance now expects.
It’s written for licensed financial institutions supervised by the CBUAE. DNFBPs are regulated separately under the Ministry of Economy, but the same risk-based CDD principles are the broader standard expected across UAE regulated entities.
On a risk-based schedule tied to the customer’s profile, and immediately whenever a trigger event occurs, such as an ownership change or an unusual transaction pattern, rather than only at fixed intervals.
Technically yes, but the record-keeping, trigger-detection, and real-time monitoring expectations apply regardless of size. Even a small book of business needs a documented, consistent process to stand up to inspection.
Missed trigger events. A customer can look low-risk at onboarding and change significantly months later, and a manual process has no built-in way to catch that shift until the next scheduled review.
Five years following the end of the customer relationship, in a format that can be reconstructed for regulators and law enforcement on request.
First Compliance is a comprehensive compliance and due diligence software platform designed to meet the rigorous standards of global regulations. Developed by a team of experts in law, compliance, and anti-financial crime, our tool leverages advanced technology to streamline investigations and ensure thorough due diligence.
First Compliance is a comprehensive compliance and due diligence software platform designed to meet the rigorous standards of global regulations. Developed by a team of experts in law, compliance, and anti-financial crime, our tool leverages advanced technology to streamline investigations and ensure thorough due diligence.
Your request for a demo has been received.
Our team will get in touch with you shortly to schedule the session.
We look forward to showing you how our solution can help your business.