Know Your Customer (KYC) and Customer Due Diligence (CDD) are the cornerstones of any AML compliance programme. Under UAE Federal Decree-Law No. 10 of 2025, all designated entities — financial institutions, DNFBPs, and VASPs — are required to identify and verify their customers before establishing a business relationship.
Yet CDD is one of the most frequently cited deficiencies during UAE AML inspections. Many businesses either skip steps, collect insufficient documentation, or fail to review customer records on an ongoing basis.
This article explains what KYC and CDD require, who you must verify, what documents to collect, and when Enhanced Due Diligence (EDD) is mandatory.
What is the Difference Between KYC, CDD, and EDD?
These terms are often used interchangeably but have distinct meanings:
- KYC (Know Your Customer) — the overall process of identifying who your customer is and understanding the nature of your business relationship with them.
- CDD (Customer Due Diligence) — the specific verification steps required at onboarding and throughout the relationship. The standard form of CDD.
- SDD (Simplified Due Diligence) — a reduced level of checks permitted for very low-risk customers, subject to supervisory approval.
- EDD (Enhanced Due Diligence) — additional, deeper checks required for higher-risk customers, PEPs, and customers from high-risk jurisdictions.
When Must You Conduct CDD?
The UAE law specifies the following trigger points for conducting CDD:
- Before establishing a business relationship with a new customer
- Before executing occasional transactions above the applicable threshold (typically AED 55,000 / USD 15,000)
- When there is suspicion of money laundering or terrorist financing, regardless of any exemptions
- When you have doubts about the accuracy or adequacy of previously obtained customer information
- At periodic review — existing customers must be re-verified based on their risk rating
What Information Must You Collect?
For Individual Customers
| Information Required | Acceptable Documents |
|---|---|
| Full legal name | Emirates ID, Passport, National ID |
| Date of birth | From identity document |
| Nationality | Passport or Emirates ID |
| Residential address | Utility bill, bank statement (within 3 months) |
| Source of funds | Bank statements, employment letter, salary certificate |
| Source of wealth (for higher-risk) | Tax returns, business ownership evidence |
| Purpose of business relationship | Customer declaration |
For Corporate Customers
| Information Required | Acceptable Documents |
|---|---|
| Legal entity name and structure | Trade licence, MoA/AoA, Certificate of Incorporation |
| Registered address and principal place of business | Trade licence, official correspondence |
| Nature of business / primary activities | Trade licence, website, financial statements |
| Identity of directors and authorised signatories | Emirates ID / Passport copies |
| Beneficial owners (holding ≥25% directly or indirectly) | Shareholder register, ownership declaration |
| Source of funds | Bank statements, audited accounts |
| Regulatory status (if applicable) | Licence from relevant authority |
Risk-Based Approach: SDD, CDD, and EDD
The UAE law requires a risk-based approach to CDD. The level of due diligence applied must be proportionate to the risk the customer presents:
Simplified Due Diligence (SDD) — Low Risk
May be applied to customers where the risk of money laundering or terrorist financing is demonstrably low. Permitted only in limited circumstances and subject to supervisor approval. Does not mean no CDD — it means reduced documentation and monitoring.
Standard CDD — Medium Risk
The baseline for most customers. Full identity verification, beneficial ownership identification, source of funds assessment, and purpose of relationship confirmation. Ongoing monitoring at intervals determined by risk score.
Enhanced Due Diligence (EDD) — High Risk
- Politically Exposed Persons (PEPs) and their close associates and family members
- Customers from FATF high-risk or monitored jurisdictions
- Customers involved in complex or unusual transactions with no clear commercial purpose
- Non-face-to-face (remote) onboarding where risk cannot otherwise be mitigated
- Correspondent relationships with high-risk institutions
- Any customer where your risk assessment indicates elevated ML/TF risk
Ongoing Monitoring
CDD is not a one-time exercise at onboarding. UAE law requires ongoing monitoring throughout the customer relationship, including:
- Reviewing transactions to ensure they are consistent with the customer's known profile and source of funds
- Updating customer records when information changes or expires
- Conducting periodic risk re-assessments (frequency based on risk rating — typically annually for high-risk, every 3 years for medium, every 5 years for low)
- Identifying and investigating unusual or suspicious activity
What Happens if You Can't Complete CDD?
If you are unable to complete the required Customer Due Diligence — for example, because the customer refuses to provide information, or the beneficial ownership cannot be established — you must:
- Not establish the business relationship, or terminate it if already established
- Consider whether the refusal itself gives rise to suspicion warranting an STR
- File an STR with the UAE FIU via the goAML portal if suspicion exists
Getting CDD Right
AML Expert UAE designs and implements KYC and CDD programmes tailored to your specific business, customer base, and risk profile. A well-designed CDD framework reduces compliance burden while fully meeting your regulatory obligations.
Is Your KYC Programme Inspection-Ready?
We review, design, and implement CDD frameworks for UAE businesses across all sectors. Free consultation available.
Free Consultation