Customer due diligence (CDD) is the structured process by which financial institutions (FIs), designated non-financial businesses and professions (DNFBPs), and virtual asset service providers (VASPs) identify, verify, and understand their customers, in order to assess and manage the risks of money laundering (ML), financing of terrorism (FT), and proliferation financing (PF).
This obligation sits at the intersection of governance, risk, and compliance. It is not a one-time onboarding check but a continuous, risk-calibrated requirement to know who customers are, understand why they use the service, monitor whether behaviour matches the stated profile, and refresh data whenever material circumstances change.
In the UAE, the process is legally mandated. Regulated entities that fail to implement it face administrative fines of up to AED 5,000,000 per violation, licence revocation, and, where criminal intent is established, criminal liability under the primary statute.
UAE Legal Framework
The legal framework governing due diligence obligations in the UAE rests on two instruments issued in late 2025. Together, they replaced Federal Decree-Law No. 20 of 2018 and Cabinet Decision No. 10 of 2019, which are no longer valid authority.
Federal Decree-Law No. 10 of 2025 (FDL 10/2025), the primary AML/CFT/CPF statute, requires every FI, DNFBP, and VASP to implement customer due diligence measures and continuous monitoring, calibrating their scope to the entity’s risk assessment and national risk assessment outcomes (Art. 19(1)(b)).
FDL 10/2025, Art. 19(1)(b): Implement Customer Due Diligence (CDD) Measures and continuous monitoring procedures, determining their scope based on the multiple risk dimensions…
Cabinet Resolution No. 134 of 2025 (CR 134/2025), the Executive Regulations of FDL 10/2025, provides the operational detail. Chapter Two, Division Three (Arts. 6-15) governs verification timing, identity and beneficial owner procedures, enhanced and simplified measures, ongoing monitoring, and the steps required when verification cannot be completed.
When Must Customer Due Diligence Be Performed?
CR 134/2025, Art. 7 sets out five triggers. The obligation applies:
- At the commencement of any business relationship (Art. 7(1)(a)).
- Whenever there is suspicion of ML, FT, or PF, regardless of an existing relationship (Art. 7(1)(b)).
- Where doubts arise about the accuracy or adequacy of previously obtained identification data (Art. 7(1)(c)).
- For FIs: occasional transactions of AED 55,000 or above (single or linked), or wire transfers of AED 3,500 or above (Art. 7(2)(a)-(b)).
- For VASPs: occasional transactions of AED 3,500 or above (Art. 7(3)).
Timing of verification is controlled by CR 134/2025, Art. 6(1): the customer’s identity must be verified before or during the commencement of the business relationship, or before executing the transaction. In low-risk situations only, completion may be deferred briefly provided verification is finalised as soon as possible, the deferral is operationally necessary, and adequate risk controls remain active (Art. 6(2)).
The Four Core Customer Due Diligence Measures
CR 134/2025, Arts. 8 and 9 define the minimum standard. Each measure reflects a distinct governance and risk control function:
1. Identify and Verify the Customer
Verification uses original documents, data, or information from a reliable and independent source (Art. 9(1)). The required data set varies by customer type:
- Natural persons: name as on the identity document, nationality, date and place of birth, residential address, employer details where applicable, and a true copy of a valid identity card or travel document.
- Legal persons and legal arrangements: legal name, legal form, memorandum of association, tax registration number, registered office address, names of senior management, and evidence of any authorised representatives. For trusts, identification extends to the trustee, settlor, trust protector, and beneficiaries or classes of beneficiaries (Art. 10(2)).
2. Identify and Verify the Beneficial Owner
Entities must identify the natural person who ultimately owns or controls the customer and verify that identity using reliable source documentation (Art. 10). For legal persons, the tiered test operates as follows:
- Tier 1: any natural person holding 25% or more of shares or voting rights (Art. 10(1)(a)).
- Tier 2: if no person qualifies at Tier 1, the natural person exercising legal or actual control by any means (Art. 10(1)(b)).
- Tier 3: if still unresolved, the natural person(s) holding a senior management position (Art. 10(1)(c)).
Where the customer’s controlling shareholder is a company listed on a regulated securities market subject to adequate disclosure requirements, Art. 11 permits reliance on publicly available registers rather than full beneficial owner verification.
3. Understand the Purpose and Nature of the Business Relationship
Entities must understand the customer’s business, its ownership and control structure, and the intended purpose of the relationship (Art. 9(3)-(4)). This is a risk intelligence function: it establishes the baseline against which all subsequent transaction monitoring is assessed. It also feeds directly into the governance layer, informing board-level risk appetite decisions and compliance officer reporting.
4. Ongoing Transaction Monitoring
Entities must scrutinise transactions throughout the business relationship to confirm consistency with the customer’s known profile, activities, and risk rating, including the source of funds where necessary. All verification records must be kept current, with heightened attention to high-risk customer categories (Art. 8).
Ongoing monitoring is not a back-office formality. It is the mechanism by which the governance and risk framework operates in real time, detecting divergence between a customer’s declared profile and actual behaviour. Without it, even a thorough onboarding process provides only superficial protection.
Standard, Enhanced, and Simplified CDD
The UAE AML framework calibrates the intensity of verification obligations to the risk profile of each customer and relationship. Three levels apply:
Standard CDD
The default level for customers presenting neither elevated nor demonstrably low risk. It covers all four core measures described above and applies to the majority of business relationships.
Enhanced Due Diligence (EDD)
EDD is mandatory where heightened risk is identified (CR 134/2025, Arts. 5(2) and 12). Situations requiring enhanced measures include:
- Politically Exposed Persons (PEPs): foreign, domestic, and those holding prominent positions in international organisations, together with their immediate family members and known close associates (Art. 16).
- High-risk customers: non-residents without a UAE identity card, customers with complex ownership structures, customers conducting economically unjustified transactions, or those executing large cash transactions (CR 134/2025, Art. 1).
- High-risk country exposure: customers or transactions linked to jurisdictions designated under Art. 23.
- Life insurance beneficiaries: where the beneficiary is a high-risk legal person or arrangement (Art. 12(2)).
EDD measures may include senior management approval, enhanced source-of-funds and source-of-wealth checks, first payment through a verified account, and increased monitoring frequency (Art. 5(2)).
Simplified Due Diligence (SDD)
SDD applies only where a documented risk assessment identifies genuinely low risk and no suspicion of a crime exists (Art. 5(3)). Permitted simplifications include deferred identity verification, reduced monitoring frequency, and inferring the relationship purpose from the transaction type. SDD never exempts any entity from targeted financial sanctions (TFS) screening or Suspicious Transaction Report (STR) obligations.
Consequences of CDD Non-Compliance
The UAE legal framework applies a graduated set of sanctions for verification failures. Each layer has distinct governance implications:
Administrative penalties (FDL 10/2025, Art. 17): the supervisory authority may issue a warning; impose a fine of AED 10,000 to AED 5,000,000 per violation; prohibit operation in the relevant sector; suspend or restrict activities; or revoke the operating licence.
Prohibition on transacting (CR 134/2025, Art. 14): where verification cannot be completed, the entity must not commence or continue the business relationship, must not execute the transaction, and must consider filing an STR with the Financial Intelligence Unit.
Criminal liability (FDL 10/2025, Art. 35): criminal penalties apply where a person provides false beneficial owner information, misuses accounts, or breaches the preventive measures obligations under Art. 19.
Critically, penalties extend beyond the institution. Under FDL 10/2025, Art. 17(1)(d)-(e), senior management and board members personally proven responsible for violations may face suspension, replacement, or restriction. This makes the verification regime a board-level governance matter, not a compliance department concern alone.
Who Must Apply CDD in the UAE?
The verification obligation applies across three regulated categories under FDL 10/2025, Art. 19(1)(b):
- Financial Institutions (FIs): banks, lenders, financial leasing entities, payment service providers, insurance companies, securities firms, money exchangers, and all entities carrying out the financial activities listed in CR 134/2025, Art. 2.
- DNFBPs: real estate brokers and agents, dealers in precious metals and stones (cash transactions of AED 55,000 or above), lawyers, notaries, independent accountants, company and trust service providers, and commercial gaming operators (CR 134/2025, Art. 3).
- VASPs: entities conducting virtual asset exchange, transfer, safekeeping, administration, or related financial services (CR 134/2025, Art. 4).
Each sector carries distinct risk characteristics that shape how verification is calibrated in practice. A VASP serving retail customers faces different beneficial owner identification challenges than a law firm completing a real estate transaction, yet both operate under the same legal architecture. Sound governance demands that each entity understands its specific risk profile and tailors its procedures accordingly.
Customer Due Diligence in a Governance, Risk, and Compliance Framework
The verification obligation does not stand alone. It functions within a three-layer GRC architecture, and the strength of each layer determines whether the overall framework is genuinely protective or merely formally compliant.
Governance: Policies, procedures, and risk appetite must be approved by senior management as required by FDL 10/2025, Art. 19(1)(d). The compliance officer, whose appointment and duties are set out in CR 134/2025, Art. 22, holds primary responsibility for ensuring the framework is operational, tested, and current. Board accountability is reinforced by Art. 17(1)(d)-(e), which allows personal sanctions against executives responsible for failures.
Risk: Calibration must follow the risk-based approach mandated by FDL 10/2025, Art. 19(1)(a). This means conducting documented risk assessments, translating those assessments into differentiated procedure levels (Standard, EDD, or SDD), assigning customer risk ratings at onboarding, and revising them through ongoing monitoring. Alignment with the national risk assessment outcomes is required, not optional.
Compliance: Operational procedures must be documented, tested, and available to the supervisory authority on request. Record retention under CR 134/2025, Art. 25 requires that verification records be kept for a minimum of five years, ensuring full auditability across the customer lifecycle. Third-party reliance arrangements under Art. 20 must be formally documented, with accountability remaining with the relying entity.
A programme built around data collection alone will not hold up under supervisory scrutiny. Effective customer due diligence demands governance accountability at board level, risk intelligence embedded in the onboarding and monitoring process, and compliance execution rigorous enough to withstand a regulatory inspection.
How GRC Advisors Helps You Build a Verification Framework That Holds
Customer due diligence is where governance, risk, and compliance converge at the sharpest point of regulatory exposure. At GRC Advisors, we do not treat it as a box to tick. We design, implement, and embed verification frameworks that reflect how your business actually operates, what risks it actually carries, and what a supervisory authority will actually look for when it examines your files.
Our consultants bring deep, current expertise in UAE AML law, including FDL 10/2025 and CR 134/2025. We work with financial institutions, DNFBPs, and VASPs at every stage of the compliance lifecycle, from policy architecture through to inspection readiness.
Frequently Asked Questions
What is the difference between KYC and customer due diligence (CDD)?
Know Your Customer (KYC) is a widely used industry term for the general practice of identifying and understanding customers. Under UAE AML law, the precise statutory term is CDD, covering four specific obligations: identity verification, beneficial owner identification, understanding the business relationship, and ongoing monitoring. KYC and CDD are used interchangeably in industry but only the latter appears in FDL 10/2025 and CR 134/2025.
When is Enhanced Due Diligence (EDD) required instead of standard CDD?
EDD is mandatory wherever heightened risk is identified, including dealings with Politically Exposed Persons, customers or counterparts linked to high-risk countries, customers with complex or opaque ownership structures, and life insurance beneficiaries that are high-risk legal persons or arrangements. EDD requires additional steps beyond the standard verification baseline: senior management approval, deeper source-of-funds checks, and increased monitoring frequency.
Can customer due diligence be outsourced to a third party?
Yes, under strict conditions. CR 134/2025, Art. 20 permits a regulated entity to rely on a third party for verification execution, provided the relying entity retains full regulatory responsibility, the third party is subject to equivalent AML/CFT obligations and is appropriately supervised, and all required information is immediately available upon request. Outsourcing execution does not reduce or transfer legal accountability to the supervisory authority.
What must a business do when it cannot complete CDD on a customer?
Under CR 134/2025, Art. 14, the entity must not establish or continue the business relationship and must not execute the transaction. It must also consider filing a Suspicious Transaction Report with the UAE Financial Intelligence Unit. The only exception is where applying verification measures could alert a suspected criminal: in that case, the entity may withhold those specific measures but must file the STR immediately, stating the reasons for not applying them.
What AED thresholds trigger CDD for occasional transactions?
For financial institutions, the threshold for occasional cash or non-wire transactions is AED 55,000 (single or linked). For wire transfers by FIs, the threshold is AED 3,500. For virtual asset service providers, the threshold is AED 3,500 for occasional transactions, single or linked. These thresholds are set by CR 134/2025, Art. 7(2)(a)-(b) and Art. 7(3).