KYC & CDD

KYC & Customer Due Diligence Requirements for UAE Businesses

August 2026  ·  7 min read  ·  By AML Expert UAE

Know Your Customer (KYC) and Customer Due Diligence (CDD) are the cornerstones of any AML compliance programme. Under UAE Federal Decree-Law No. 10 of 2025, all designated entities — financial institutions, DNFBPs, and VASPs — are required to identify and verify their customers before establishing a business relationship.

Yet CDD is one of the most frequently cited deficiencies during UAE AML inspections. Many businesses either skip steps, collect insufficient documentation, or fail to review customer records on an ongoing basis.

This article explains what KYC and CDD require, who you must verify, what documents to collect, and when Enhanced Due Diligence (EDD) is mandatory.

What is the Difference Between KYC, CDD, and EDD?

These terms are often used interchangeably but have distinct meanings:

When Must You Conduct CDD?

The UAE law specifies the following trigger points for conducting CDD:

What Information Must You Collect?

For Individual Customers

Information RequiredAcceptable Documents
Full legal nameEmirates ID, Passport, National ID
Date of birthFrom identity document
NationalityPassport or Emirates ID
Residential addressUtility bill, bank statement (within 3 months)
Source of fundsBank statements, employment letter, salary certificate
Source of wealth (for higher-risk)Tax returns, business ownership evidence
Purpose of business relationshipCustomer declaration

For Corporate Customers

Information RequiredAcceptable Documents
Legal entity name and structureTrade licence, MoA/AoA, Certificate of Incorporation
Registered address and principal place of businessTrade licence, official correspondence
Nature of business / primary activitiesTrade licence, website, financial statements
Identity of directors and authorised signatoriesEmirates ID / Passport copies
Beneficial owners (holding ≥25% directly or indirectly)Shareholder register, ownership declaration
Source of fundsBank statements, audited accounts
Regulatory status (if applicable)Licence from relevant authority
Beneficial Ownership: One of the most critical and frequently missed CDD requirements. You must identify all natural persons who ultimately own or control 25% or more of the customer entity. Shell structures and nominee arrangements must be looked through.

Risk-Based Approach: SDD, CDD, and EDD

The UAE law requires a risk-based approach to CDD. The level of due diligence applied must be proportionate to the risk the customer presents:

Simplified Due Diligence (SDD) — Low Risk

May be applied to customers where the risk of money laundering or terrorist financing is demonstrably low. Permitted only in limited circumstances and subject to supervisor approval. Does not mean no CDD — it means reduced documentation and monitoring.

Standard CDD — Medium Risk

The baseline for most customers. Full identity verification, beneficial ownership identification, source of funds assessment, and purpose of relationship confirmation. Ongoing monitoring at intervals determined by risk score.

Enhanced Due Diligence (EDD) — High Risk

  • Politically Exposed Persons (PEPs) and their close associates and family members
  • Customers from FATF high-risk or monitored jurisdictions
  • Customers involved in complex or unusual transactions with no clear commercial purpose
  • Non-face-to-face (remote) onboarding where risk cannot otherwise be mitigated
  • Correspondent relationships with high-risk institutions
  • Any customer where your risk assessment indicates elevated ML/TF risk

Ongoing Monitoring

CDD is not a one-time exercise at onboarding. UAE law requires ongoing monitoring throughout the customer relationship, including:

What Happens if You Can't Complete CDD?

If you are unable to complete the required Customer Due Diligence — for example, because the customer refuses to provide information, or the beneficial ownership cannot be established — you must:

  1. Not establish the business relationship, or terminate it if already established
  2. Consider whether the refusal itself gives rise to suspicion warranting an STR
  3. File an STR with the UAE FIU via the goAML portal if suspicion exists
Tipping off: Once you file an STR, you must not tell the customer that you have done so. Informing a customer that they have been reported (or that their file is under review for suspicious activity) is itself an offence under UAE law.

Getting CDD Right

AML Expert UAE designs and implements KYC and CDD programmes tailored to your specific business, customer base, and risk profile. A well-designed CDD framework reduces compliance burden while fully meeting your regulatory obligations.

Is Your KYC Programme Inspection-Ready?

We review, design, and implement CDD frameworks for UAE businesses across all sectors. Free consultation available.

Free Consultation