Sanctions screening in the UAE starts with regulatory routing, not a generic list bundle. A UAE-regulated business needs to identify the framework that applies to its legal entity and activity, then connect the relevant sanctions sources to customers, owners, counterparties, transactions, match handling, reporting and retained evidence.
This guide is for MLROs, compliance teams, operations leaders and technical owners at UAE financial institutions, payment businesses, exchange houses, fintechs and relevant designated non-financial businesses and professions (DNFBPs). It provides a sanctions-focused operating layer, not a complete UAE AML manual or legal advice.
For the jurisdiction-neutral method, use the practical sanctions screening guide. Here, the question is specifically:
Which UAE route applies, what does that route require, and can the screening control implement and evidence it?
Find your UAE regulatory route first
The federal AML framework changed in 2025. Current official materials recognise Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025, while current DFSA and FSRA sanctions rules continue to refer to the TFS obligations associated with Cabinet Resolution No. 74 of 2020.234
That does not make every UAE business subject to identical screening rules. Start with the entity and regulator:
| Business context | Starting point for the control |
|---|---|
| CBUAE-supervised financial institution, payment business, exchange house or other licensed financial institution | Federal framework, EOCN TFS requirements and applicable CBUAE rules or guidance |
| Relevant Person in DIFC | Applicable federal legislation plus the DFSA AML Module |
| Relevant Person in ADGM | Applicable federal legislation plus the FSRA AML Rulebook |
| Ministry-supervised DNFBP | Federal framework plus Ministry, EOCN and FIU requirements relevant to that DNFBP |
| VARA-licensed VASP in Dubai | Federal framework plus applicable EOCN, FIU and VARA rules |
| Financial-services business in DIFC | Determine DFSA and DIFC scope; do not route it to VARA merely because DIFC is in Dubai |
VARA's rulebook scope excludes DIFC.5 DIFC Relevant Persons are supervised under the DFSA framework, while ADGM Relevant Persons use the FSRA rulebook. A group with several UAE entities may therefore need a common control architecture with different approved sources, workflows and reporting routes.
Before implementation, record:
- the legal entity and licensed activity;
- the regulator and applicable federal or financial-free-zone framework;
- the products, customers, transaction types and geographic exposure;
- the owner of legal interpretation and reporting; and
- the source and date of every rule or guidance document used.
Official pages can retain legacy statutory references even after framework changes. Verify the current legislation and regulator rulebook immediately before relying on a legal statement.
Determine which sanctions lists apply
For UAE TFS implementation, EOCN guidance identifies two core sources: the UAE Local Terrorist List and the UN Security Council Consolidated List.16 Reporting entities should use current official sources and register for relevant EOCN notifications rather than relying on a static copy embedded in a policy or vendor presentation.
DFSA guidance illustrates this approach. For a DIFC Relevant Person, relevant sanctions lists may include UAE, EU, UK, US or other lists that actually apply to that firm.3 The examples do not mean that every DIFC or UAE business must screen every foreign regime.
A defensible source matrix should identify:
| Field | What to record |
|---|---|
| Source | Official list and issuing authority |
| Basis | Why the source applies to this entity, activity or workflow |
| Population | Which customers, parties or records enter the check |
| Trigger | Onboarding, list change, profile change, transaction event or another approved point |
| Response | Review, operational action, escalation and reporting route |
| Evidence | Source version or timestamp, input, result, reviewer and decision |
This prevents “global coverage” from replacing the firm's legal and operational analysis.
Map the required populations and events
UAE regulatory material can require more than a customer-name check. Current DFSA material for Relevant Persons addresses screening of databases and transactions. FSRA guidance for ADGM Relevant Persons addresses ongoing checks of customer databases and sanctions as well as transaction monitoring.34
The exact population and timing still depend on the applicable framework and business model. Map, where relevant:
- customers and organisational clients;
- already-identified beneficial owners and controllers;
- counterparties, beneficiaries, payees and other transaction parties;
- persons acting on behalf of or at the direction of a designated party; and
- existing records affected by a new or amended designation.
Do not treat these examples as a rule that every organisation must screen every party at every event. A CBUAE-supervised payment provider, a DIFC wealth manager and a Ministry-supervised DNFBP may need different control designs.
Screening a known owner is also not the same as discovering or verifying the ownership structure. The business verification versus AML screening guide explains that boundary.
Set screening and re-screening triggers
Current DFSA and FSRA materials support ongoing or regular sanctions controls and responses to relevant source and transaction events.34 They do not establish one universal technical instruction that every UAE-regulated business must screen every customer continuously in real time.
A firm should map the actual rule and its operating model to defined triggers, which may include:
- onboarding or approval of a new relationship;
- the addition of an owner, controller, counterparty, beneficiary or payee;
- a material customer or ownership change;
- a relevant payment or transaction event;
- an addition, amendment or removal in an applicable official source; and
- an approved periodic review where required by the framework and policy.
For each trigger, define the input data, decision point, permitted operational state, reviewer, escalation route and evidence. If a vendor claims “real-time” or “continuous” compliance, ask it to demonstrate the exact event, source-update path and service commitment rather than treating the phrase as a legal conclusion.
The practical sanctions screening guide contains the general trigger model. The UAE control should add the regulator- and activity-specific requirements, not duplicate that guide.
Address ownership and control separately
A clean company-name result does not settle UAE TFS exposure. EOCN guidance extends the relevant analysis beyond directly designated parties to entities directly or indirectly owned or controlled by them and to persons acting on their behalf or at their direction.1
Keep three tasks separate:
- Ownership discovery or verification: establish the ownership and control structure using reliable information.
- Screening identified people and entities: compare those parties with applicable sanctions data.
- Sanctions ownership-and-control analysis: determine whether restrictions extend to an unlisted entity under the applicable UAE framework and facts.
Do not substitute a generic AML beneficial-owner threshold or a foreign sanctions test for the UAE analysis. Preserve the ownership chain, source, effective date and reasoning used, and route uncertain cases to an authorised compliance or legal reviewer.
For the general distinction, see sanctions ownership and control and UBO and related-party screening.
Handle a possible match through the correct route
The useful workflow is not “match equals blocked”. Separate candidate generation, identity resolution, match classification, legal action and reporting:
Candidate generated → identity reviewed → false, partial or confirmed outcome → applicable freezing or prohibition analysis → correct report → retained evidence
EOCN guidance provides distinct processes for confirmed and partial name matches and addresses the relevant freezing, suspension, rejection and reporting steps.1 The precise action depends on the current official process, the facts and the applicable framework. A software score does not make that determination.
For each candidate:
- Preserve the exact screening input, source result and timestamp.
- Compare available identifiers, aliases and contextual information.
- Record matching, conflicting and missing facts.
- Classify the result using the firm's current approved terminology.
- Escalate a partial, potential or confirmed match through the applicable TFS procedure.
- Record the legal and operational decision separately from the screening outcome.
The detailed investigation record belongs in the sanctions alert documentation guide. Matching calibration belongs in the false-positive reduction guide.
Keep TFS match reporting separate from suspicion reporting
EOCN materials distinguish confirmed or potential designated-person match handling from suspicious-activity reporting where the concern is sanctions evasion or another suspicious pattern without such a list match.7 The UAE FIU uses goAML for STR and SAR submissions by reporting entities in scope.8
Do not treat a TFS match report, an STR or SAR, and a regulator notification as interchangeable. The compliance procedure should identify which route applies, who decides, which current form is used and what timing applies. Forms, report names and deadlines should be rechecked against current official instructions on publication and before a live filing.
Keep PEP screening connected but legally distinct
PEP screening may use the same customer data and review team, but it answers a different question. A sanctions candidate requires identity and applicability review against restrictive measures. PEP screening asks whether a customer or beneficial owner holds a qualifying public function or relationship and what risk-based measures follow.
For DIFC Relevant Persons, current DFSA rules address reasonable measures to determine whether a customer or beneficial owner is a PEP and, where applicable, senior-management approval, source-of-wealth and source-of-funds work and increased monitoring.9 FSRA materials similarly address PEP exposure through risk-sensitive controls for ADGM Relevant Persons.4
FATF describes PEP measures as preventive: PEP status should not be interpreted as evidence of criminal activity.10 It also does not create sanctions status or an automatic customer rejection.
Keep the sequence clear:
| Sanctions control | PEP control |
|---|---|
| Resolve the candidate and applicable restrictive measure | Confirm identity, role or qualifying relationship |
| Assess ownership or control where relevant | Assess the customer's risk in context |
| Determine freezing, prohibition and TFS reporting requirements | Apply relevant approval, due-diligence and monitoring measures |
| Preserve the legal and operational outcome | Preserve the classification, risk rationale and decision |
Use the PEP screening guide for the full process and Checklynx PEP screening for the product route. Adverse media may provide additional risk context, but it does not establish PEP or sanctions status.
Test whether software can support the UAE control
Keep the acceptance test UAE-specific. The complete procurement and POC methodology belongs in how to choose sanctions screening software.
Ask a prospective provider to demonstrate:
- provenance for the required UAE and UN source data;
- how additions, amendments, removals and failed source updates are detected and evidenced;
- re-screening or event handling aligned with the firm's approved timing;
- person and entity results with enough identity data to resolve candidates;
- relevant Arabic-script, transliterated, alias, common-name and sparse-identifier cases from the buyer's population;
- screening of identified owners and controllers while preserving the supplied ownership context;
- customer, database and transaction-party workflows required by the buyer's regulatory and business model;
- separate and explainable candidate, false, partial or unresolved, and confirmed outcomes;
- retained source, input, configuration, reviewer, rationale, action and timestamps; and
- controlled handoff to the firm's current TFS, FIU and regulator procedures without presenting the software as the legal decision-maker.
FSRA guidance makes an important buyer principle explicit for ADGM Relevant Persons: using a third-party database does not transfer responsibility for effective systems and controls to the vendor.4 Apply the same practical caution wherever the firm's own framework leaves it accountable for the control.
CBUAE's 2026 thematic-review programme includes sanctions screening against the UAE Local List and UNSC Sanctions List in the banking sector.11 That is evidence that screening effectiveness and testing are active supervisory issues for that population—not a basis for inventing a universal test threshold.
Apply the control to the regulated context
These examples are illustrative operating patterns, not universal legal instructions.
CBUAE-supervised payment provider or exchange house
The firm maps customer records, relevant owners and payment parties to the applicable TFS control. A new beneficiary creates a candidate during a cross-border transfer. Operations follow the approved containment and escalation procedure while a reviewer resolves identity and the authorised owner determines the TFS and reporting outcome. The example does not mean every payment product requires an identical technical architecture.
DIFC wealth manager or fintech
A corporate customer has an identified beneficial owner who may be a PEP, while a new payment counterparty creates a sanctions candidate. The PEP question follows the DFSA risk-based PEP route; the sanctions candidate follows the applicable list, match and TFS route. Shared customer data does not make the outcomes interchangeable.
ADGM financial-services firm
The firm uses an external screening database but retains ownership of source scope, effective ongoing controls, candidate review, transaction monitoring and escalation. It tests whether reviewers can reconstruct a result after a source change rather than accepting the existence of the database as proof of compliance.
Ministry-supervised DNFBP
A real-estate business or another DNFBP maps its own customers, relevant owners, counterparties and reportable events rather than copying a bank's payment workflow. The control follows the federal, EOCN, Ministry and FIU requirements applicable to that business.
VARA-licensed VASP in Dubai
The VASP applies its relevant VARA rules alongside the federal TFS framework and routes crypto-specific questions to its dedicated control design. DIFC is outside VARA's territorial scope, so a DIFC business should not use this path merely because it is located in Dubai.5 See AML screening for crypto and VASPs for the industry-specific boundary.
UAE sanctions-screening checklist
Once those requirements are defined, Checklynx sanctions screening can support portal, CSV and API screening, configured monitoring, review cases and decision evidence. The customer determines the applicable sources, parties, policy and final legal outcome.
Frequently asked questions
Which sanctions lists should a UAE-regulated business screen?
EOCN guidance identifies the UAE Local Terrorist List and UNSC Consolidated List for UAE TFS implementation.1 Other regimes, such as EU, UK or US sanctions, should enter the control when they apply to the entity, activity, transaction, group or another relevant relationship—not automatically.
Does every UAE business need continuous real-time sanctions screening?
Do not apply that as a universal rule. Current regulator materials use requirements such as ongoing or regular screening and address database, list-change and transaction controls for defined regulated populations. The firm should identify its applicable rule and translate it into documented triggers and service requirements.
Are DIFC, ADGM and onshore UAE sanctions requirements identical?
No. Applicable federal TFS obligations interact with distinct supervisory frameworks. DIFC Relevant Persons use the DFSA AML Module, ADGM Relevant Persons use the FSRA AML Rulebook, and onshore institutions or DNFBPs follow their applicable federal and supervisory route.
Does a sanctions candidate require an automatic freeze or rejection?
No. A candidate is an input to review. The identity, match classification, applicable restriction, ownership/control facts and current official procedure determine the required legal and operational response. Partial and confirmed matches should follow the firm's approved UAE TFS escalation process.
Can an unlisted company still create UAE sanctions exposure?
Yes. EOCN guidance addresses entities directly or indirectly owned or controlled by designated parties and persons acting on their behalf or at their direction.1 The analysis is fact-specific and should not be replaced with a foreign sanctions formula.
Is a TFS match report the same as an STR or SAR?
No. EOCN materials distinguish designated-person match handling from suspicious-activity reporting, while goAML provides the UAE FIU route for STR/SAR submissions by reporting entities in scope.78 Check the current official forms and deadlines for the live case.
Is a PEP automatically sanctioned in the UAE?
No. PEP status is a risk-relevant classification, not sanctions status or evidence of criminality. Applicable PEP controls can include approval, source-of-wealth or source-of-funds work and enhanced monitoring; they do not create an automatic sanctions prohibition.
What should a UAE buyer test in sanctions screening software?
Test applicable UAE and UN source provenance, update handling, Arabic and transliterated identities, customer and transaction-party workflows, ownership context, distinct match outcomes, reporting handoff and reconstructable evidence. Use the general sanctions software buyer guide for the full procurement method.
Official sources
Footnotes
-
Executive Office for Control and Non-Proliferation, Guidance on Targeted Financial Sanctions for Financial Institutions and Designated Non-Financial Businesses and Professions, official UAE TFS implementation guidance, July 2025. ↩ ↩2 ↩3 ↩4 ↩5 ↩6
-
Central Bank of the UAE Rulebook, Cabinet Resolution No. 134 of 2025 regarding the Executive Regulations of Federal Decree-Law No. 10 of 2025, current federal AML framework, accessed 9 September 2026. ↩
-
Dubai Financial Services Authority, AML Rule 7.6.2 and guidance, sanctions requirements and guidance for DIFC Relevant Persons, current version accessed 9 September 2026. ↩ ↩2 ↩3 ↩4
-
ADGM Financial Services Regulatory Authority, Anti-Money Laundering and Sanctions Rules and Guidance, sanctions and PEP rules and guidance for ADGM Relevant Persons, current version accessed 9 September 2026. ↩ ↩2 ↩3 ↩4 ↩5
-
Virtual Assets Regulatory Authority, Compliance and Risk Management Rulebook, scope and compliance rules for VARA-licensed VASPs, accessed 9 September 2026. ↩ ↩2
-
United Nations Security Council, United Nations Security Council Consolidated List, live official UN source, accessed 9 September 2026. ↩
-
Executive Office for Control and Non-Proliferation, Instructions for implementing targeted financial sanctions, current operational instructions for confirmed and potential matches, freezing and reporting, accessed 9 September 2026. ↩ ↩2
-
UAE Financial Intelligence Unit, goAML registration and reporting service, official UAE FIU channel, accessed 9 September 2026. ↩ ↩2
-
Dubai Financial Services Authority, AML Rule 7.3.8, PEP requirements for DIFC Relevant Persons, accessed 9 September 2026. ↩
-
Financial Action Task Force, Politically Exposed Persons: Recommendations 12 and 22, international preventive guidance, accessed 9 September 2026. ↩
-
Central Bank of the UAE, AML thematic review programme, 2026 supervisory-review topics including sanctions screening, accessed 9 September 2026. ↩