Building a Compliance Program in the UAE

Mainstream
Building a compliance program in the UAE is not a copy of the European or American model. It is the creation of a system that simultaneously meets local regulatory requirements and protects against the key risk of losing access to dollar settlements and correspondent accounts.
The question is not whether the company has policies and procedures on paper. The question is whether compliance works as a business filter at the time of decision-making. a new counterparty, payment or logistics route.
Therefore, an effective compliance program in Dubai begins with three checks:
- What is the real risk profile of a business, given its geography and industry?
- What transactions are made through UAE banks and what compliance officers of these banks see.
- How a company documents its "reasonable diligence" before questions arise
If these three issues are not resolved, the business risks not just a fine, but an instant blocking of accounts and loss of the ability to work through the jurisdiction of the UAE.
When Businesses in the UAE Need a Systemic Compliance Program
A system compliance program is necessary if:
- the company is registered with DMCC, DIFC, ADGM or on the UAE mainland;
- bank accounts in UAE banks are used;
- business is connected with deliveries through the countries of the “red flags” or the EAEU;
- There are dual-use goods in the supply chain.
- The ownership structure includes beneficiaries from several jurisdictions.
- Payments are made through UAE Dirham and converted.
- Partners or customers are under sanctioned control (not necessarily blocked);
- A request from the UAE Bank for a compliance framework is made;
- - to obtain a trade license or work with Dubai Customs;
- The company is scaling or attracting external funding.
The mistake most companies in the UAE make
Many companies start with the question:
Where to download the AML Policy Template for DMCC?
That's the wrong first question.
The right question is:
What compliance configuration will actually stop a questionable payment before it is sent, rather than after the account is blocked?
Sometimes a minimum package is enough to meet the requirements of the local regulator. Sometimes a multi-level screening and manual escalation system is required. Sometimes the key is not so much the internal regulations as the ability to explain to the bank the economic meaning and the ultimate recipient of each cross-border transfer.
Compliance in the UAE requires not formal policies, but operational discipline.
Step 1. Determine your risk profile and applicable regulations
The first thing to do is not write a policy, but answer questions about your business honestly.
Key points for analysis:
- Geography of shipments and payments (especially transit through the UAE);
- industry (trade, logistics, financial services, raw materials, technologies);
- the structure of counterparties and ultimate beneficiaries;
- product or service: Do they have dual-use signs?
- jurisdiction of the parent company;
- currency of settlement;
- which regulator controls your area (DMCC, DIFC, ADGM, mainland) and what specific requirements it has.
- The requirements of the bank with which the account is opened (often they are stricter than regulatory ones).
The DMCC Compliance Program will be fundamentally different from the DIFC Family Office Program. Scaling someone else’s policy without analyzing your own profile is a mistake.
Step 2. Integrate international sanctions requirements into the framework of the UAE
Key feature of the UAE: The law does not mirror all sanctions regimes of the EU or the United States. But UAE banks, working with the US dollar and international correspondent accounts, follow the standards of OFAC, the EU and the UN.
This creates a gap that companies relying only on formal compliance with UAE law fall into.
The programme should include:
- Lists of persons and organizations of the United Nations (mandatory for the UAE);
- OFAC lists (especially the SDN List)
- sectoral sanctions;
- The “50% rule” rule;
- control of re-exports;
- indicators of circumvention of sanctions through the UAE;
- a ban on working with sanctioned goods, even if the delivery does not concern the United States;
- Screening of end recipients, consignees and logistics intermediaries.
The program should answer the question not “Is the transaction allowed in the UAE?”, but “Will the transaction lead to the delisting of the correspondent bank and the closure of our account?”.
Step 3. Build KYC and Due Diligence of Contractors
The UAE has a very high concentration of companies set up for transactional business. This imposes special requirements for verification of counterparties.
Effective KYC in the UAE includes:
- Identification of the ultimate beneficiary (UBO) and not just the director
- verification of registration documents (license, Memorandum of Association);
- Understanding ownership structure (especially if there are trusts or foundations)
- Identifying links with high-risk jurisdictions;
- Screening UBO, directors and related companies for sanctions and reputation bases
- checking the commercial address (excluding virtual “pads” without substance);
- Business profile analysis: whether the declared activity is in accordance with the actual activity;
- escalation into manual mode if the counterparty is recently registered and has a minimum share capital.
Particular attention is paid to counterparties who offer to “solve the issue” with payment through alternative jurisdictions or intermediaries in the UAE.
Step 4. Set up transactional screening and export control
The weakest point of compliance programs in the UAE is control at the level of individual transactions. This is where most of the violations occur.
The system shall ensure that:
- verification of the final customer and end use;
- control not only of the seller and the buyer, but also of the consignee and the notified party;
- screening of ships (for sea transportation) and air carriers;
- verification of dual purpose of goods by EU and US codes;
- Stopping a transaction when it coincides with sanctions circumvention indicators (for example, changing the route at the last minute);
- tracking payments: whether the payer is the same as the buyer under the contract;
- escalation to the compliance officer level in case of any inconsistencies in payment instructions.
In the UAE, transactional screening must take into account that the dirham is not a reserve currency, but payments in USD are made through the strict compliance filters of correspondent banks.
Step 5. Appoint a Compliance Officer with Real Authority
The appointment of a compliance officer is a requirement of free zone regulators, such as the DMCC. But formal appointments do not protect business.
Role requirements:
- Direct access to CEO and senior management;
- the right to veto a transaction or payment without the consent of the commercial department;
- Independence from sales and operating activities;
- understanding not only AML, but also sanctions, export controls and bank compliance;
- the possibility of initiating an independent investigation against any counterparty;
- Experience of cooperation with UAE banks and their compliance departments.
In small and medium-sized companies, outsourcing of the Compliance Officer (MLRO) function is a frequent solution, in which real expertise is provided without conflicts of interest.
Step 6. Building a relationship with the bank and documenting everything
A bank account in the UAE is not just a financial instrument. It is the main compliance controller of your business.
It is necessary:
- provide the bank with its compliance program and AML policy in advance;
- appoint a contact person to interact with the bank;
- For any non-standard payment, proactively provide a package of documents: contract, invoice, confirmation of the origin of the goods, KYC of the counterparty, confirmation of the final recipient, logistics documents;
- prevent the “splitting” of payments or the replacement of the purpose of payment;
- timely update information about the beneficiaries and the structure of the company in the bank;
- inform the bank of significant changes in the business before they affect transactions.
The main rule is: The bank should see you as a predictable customer with a transparent transaction model, not a source of surprises.
Step 7. Implementing Red Flag Education and Culture
The most perfect rules are useless if the employee exhibiting the invoice does not see the red flags.
An effective training programme includes:
- regular trainings on recognition of indicators of circumvention of sanctions;
- Training in UAE specifics (how geography is used to circumvent);
- analysis of real cases of bank failures and account freezes in Dubai;
- Training for non-compliant staff: logisticians, traders, accountants;
- testing of employees for knowledge of procedures;
- Clear escalation scenarios: Who should I go to if something is disturbing?
- Documentation of all trainings (required for the regulator and the bank).
A compliance culture is when reporting a questionable counterparty is perceived by management as a business rescue rather than a sales hindrance.
Step 8. Set up audit, incident response and updates
The compliance program cannot be static. The sanctions lists, circumvention schemes and focus of UAE regulators are constantly changing.
It is necessary:
- conduct an independent audit of the compliance program at least once a year;
- Test the effectiveness of screening on control examples;
- Update policies and procedures when changing the UAE’s sanctions regimes and legislation;
- have a written action plan when a violation is detected (for example, when paying in favor of a sanctioned person);
- Investigate incidents documented and with the participation of a legal adviser;
- consider the possibility of self-disclosure in the event of a serious breach, assessing the risks and benefits.
The lack of regular audits in the UAE is a signal to both the regulator and the bank that the compliance program exists only on paper.
Compliance program vs. scoring of counterparties: what's the difference
| Criteria | Full Compliance Program | Basic KYC scoring |
|---|---|---|
| Level of protection | Protection against account blocking and reputational risks | Protection from an unreliable counterparty |
| Coverage | Sanctions, AML, export control, bank compliance | Verification of reliability and solvency |
| Focus. | The entire transaction and supply chain | Specific counterparty |
| Bank interaction | Proactive, systemic | Reactive, upon request |
| Regulator's requirement | Mandatory for many areas of the UAE | Not necessarily, but preferably. |
| Cost of implementation | Above, requires expertise and audit | Below, often automated |
| Risk in the absence | Critical (account blocking, investigation) | High (financial losses, court) |
Scoring is part of the due diligence of the counterparty. Compliance program is a system of protection of the whole business, where scoring is only one of the tools.
Common mistakes in building a compliance program in the UAE
- Copying the policies of another company. Without taking into account its risk profile, structure and requirements of a particular bank, the program does not work.
- Ignoring the OFAC logic of sanctions. In the UAE, you can not formally violate the local law, but lose the account due to non-compliance with the requirements of correspondent banks.
- Appointment of a compliance officer without experience. Nominee employee will not stop a dangerous transaction and will not be able to protect the position of the company before the bank.
- Lack of control over logistics. The contract and payment may be “clean,” but the actual route of the goods with transshipment in the port associated with risk will destroy all protection.
- Disregard of substance. A shell company in DMCC without a real office, staff and equipment is a red flag for any bank.
- Keeping policies on the table without implementation. The regulator and the bank in the UAE today check not the availability of documents, but real transactions and their documentation in dynamics.
Checklist for CEO at Dubai Compliance Program Launch
Before starting or auditing a compliance program, you must answer 15 questions:
- In which free zone or mainland is the company registered and what are its regulatory responsibilities?
- Who are the ultimate beneficiaries of our business and is this documented?
- What does the card of our payments look like: Where and where does the money go?
- Do our products pass through the red flag zones?
- Do we have any contractors with registration in the UAE, but without a real presence?
- Who is our compliance officer and does he have the real right to stop the deal?
- Has our UAE bank asked for a compliance structure or clarification on payments?
- Are we looking at the end recipients of the product, not just the direct buyer?
- Is our export control documented for each shipment?
- Can we collect a full compliance file in 24 hours for any bank request?
- Does our AML policy meet the requirements of a specific zone regulator?
- Has our compliance officer been trained in the past year?
- Has our program been independently audited in the past 12 months?
- Do we have a plan of action when freezing the bank?
- Does our actual activity match the license?
What an Effective Compliance Program Looks Like in the UAE
An effective program is usually built on five levels:
1. Regulatory Alignment
Synchronization with the requirements of the regulator (DMCC, DIFC, etc.) and the UAE legislation on AML / CFT.
2. Sanctions & Export Control Screen
Automated and manual control of key sanctions lists and lists of dual-use goods, taking into account the specifics of the UAE as a transit hub.
3. Operational KYC & Due Diligence
Continuous verification of not only direct counterparties, but also the entire chain: from the manufacturer to the final recipient, including logistics hubs.
4. Bank & Transaction Interface
Proactive documentation and communication with the bank on each non-standard transaction. Preparing for payment protection before it is sent.
5. Governance, Audit & Training
Real management engagement, independent auditing and regular staff training, making compliance part of the company’s operating DNA.
Without the fifth level, the first four quickly become a formality.
FAQ
Is a compliance program required for a company in the DMCC or DIFC?
Yeah. The DMCC and DFSA (in DIFC) regulators explicitly require AML policies, MLRO designation, and due diligence. However, the formal existence of policies without taking into account the sanctions requirements of correspondent banks does not protect against the main business risk.
What is the difference between compliance in the UAE and European compliance?
In the UAE, compliance must simultaneously meet less stringent local requirements under the letter of the law, but be hypersensitive to the sanctions risks of the US and the EU due to the dependence of the banking system on the dollar. This creates a unique two-tier system.
Can you build a compliance program without external consultants?
It is possible if the state has a specialist who understands both the UAE law, the OFAC/EU sanctions regulation, and the internal cuisine of the compliance departments of Dubai banks. In practice, this combination is rare, and companies often resort to outsourcing functions or design development with outside lawyers.
What happens if the program is ineffective?
The most likely scenario is not a fine from the regulator, but a sudden locking of the bank account and a request for the provision of a huge array of documents on past transactions. It stops the business instantly.
How often should I update the compliance program?
It is recommended that policies be reviewed at least once a year. Screening procedures and a list of red flags to be tracked – immediately upon changes in sanctions regimes, new circumvention schemes or upon receipt of any request from a bank that identifies a “weak spot”.
Is substance (real presence) important for compliance?
Critical. The absence of substance in the UAE company is one of the main factors that leads to the refusal to open an account, its closure or refusal to make a payment, even with ideal documents on paper.
Can automatic screening services be used?
Yes, they are necessary. But they don’t have to be the only barrier. In the UAE, manual verification of sanctions bypassing through complex structures involving local companies is critical, which the algorithm can skip.
Related services
- Sanctions, Export Controls & International Compliance
- Corporate Investigations, Regulatory Investigations & Business Integrity
- International Regulatory Risk & Strategic Advisory
- Commercial Contracts
- International Trade, Distribution & Cross-Border Transactions
Related material
- Sanctions risks when using accounts in the UAE
- Checking the counterparty in the UAE: practical guide
- How to Avoid Losing a Bank Account in Dubai Due to Compliance
- Export controls and dual-use goods in shipments through the UAE
- The role of MLRO in the DMCC: function and responsibility
- Bypassing sanctions and red flags for business in UAE
- Structuring International Trading Transactions through Dubai
Conclusion
Building an effective compliance program in the UAE does not require copying Western templates, but creating an operating system of protection, sharpened under the duality of local jurisdiction.
A strong program is based on understanding your risk profile, uncompromising sanction screening, built-up relationships with the bank and the real independence of compliance officer.
In Dubai, compliance is not a back office function. This is a condition of access to the financial system, and therefore to the existence of a business. The winner is not the one who wrote the most comprehensive policy. The winner is the one who prevents the only bank call that can stop everything.
Have a question about the topic of this article?
Write to us and we will respond within one business day.


