KYC in the UAE: CBUAE, DIFC, ADGM and Digital Identity

KYC in the UAE: CBUAE, DIFC, ADGM and Digital Identity

The UAE spent three years on the FATF grey list and came off it in February 2024. That exit did not relax the rules — it entrenched them. Supervisory intensity, enforcement action and the evidentiary bar for compliance programmes have all risen since. This guide covers what KYC in the UAE requires today, across the mainland and the financial free zones.

General information, not legal advice. Confirm current requirements against CBUAE, DFSA and FSRA publications before relying on them.

Three regimes, not one

The single most common mistake in UAE compliance planning is assuming one rulebook. There are three:

  • Onshore / mainland — supervised by the Central Bank of the UAE (CBUAE) for licensed financial institutions, with other sectors under their own supervisors
  • DIFC — Dubai International Financial Centre, supervised by the DFSA under its own AML rulebook
  • ADGM — Abu Dhabi Global Market, supervised by the FSRA, likewise with its own regime

Federal AML law applies across all of them, but the detailed obligations, reporting formats and supervisory expectations differ. If you operate in more than one, you need configurable rules per entity — not a single global policy.

Virtual asset businesses add a fourth layer: VARA in Dubai, which has been notably active in enforcement.

goAML: the reporting channel

Suspicious transaction reports in the UAE go to the Financial Intelligence Unit through the goAML platform. Registration on goAML is itself a compliance obligation for reporting entities — not merely a technical step. Supervisors check that you are registered, that you have designated a compliance officer, and that reports are filed properly.

Core CDD requirements

Identification and verification

For individuals you must collect and verify full legal name, date of birth, nationality, residential address and national identification. For UAE residents that centres on the Emirates ID; for non-residents, passport and supporting documentation.

Verification must come from reliable, independent sources. Collecting a document is not verifying it.

Beneficial ownership

Corporate customers require identification of the natural persons who ultimately own or control the entity. Given the prevalence of multi-layered structures and offshore holding companies in the UAE market, this is where the real work sits — and where supervisors focus.

Enhanced due diligence

Required for PEPs, high-risk jurisdictions, complex structures and correspondent relationships. Expect source of wealth evidence, senior management approval and heightened ongoing monitoring.

Ongoing monitoring

Transactions must be monitored against the expected customer profile, and customer information kept current. Periodic review cycles are increasingly regarded as a floor rather than a standard — event-driven review is the direction of travel.

Record keeping

Five years following the end of the relationship or the date of the transaction, retrievable on request.

UAE Pass and digital identity

The UAE has invested heavily in national digital identity. UAE Pass provides authenticated digital identity for residents and citizens, and the CBUAE has issued specific guidance on the use of digital identification for customer due diligence.

The regulatory position is that digital identity systems can satisfy CDD requirements where they are sufficiently reliable and independent — but the institution remains responsible for satisfying itself of that reliability. Using a digital ID service does not transfer the obligation.

As in Saudi Arabia, national digital identity covers residents well and non-residents not at all. Given the UAE’s expatriate-majority population and heavy cross-border business, document-based verification remains essential rather than a fallback.

What changed after the grey list exit

Removal from the grey list in February 2024 followed substantial legislative and operational reform. The practical consequences for compliance teams:

  • Enforcement is real and public. Regulators across the UAE have issued significant penalties, and VARA alone has fined virtual asset businesses tens of millions of dirhams since 2024.
  • Beneficial ownership scrutiny has intensified. Registry requirements tightened considerably during the remediation period and have not loosened.
  • Evidence matters more than policy. Supervisors increasingly test whether documented procedures are actually operating, not merely whether they exist.

Where UAE programmes struggle

Multi-jurisdiction complexity. A group operating onshore, in DIFC and in ADGM needs three rule sets running in parallel. Systems that support one global policy force manual workarounds.

Document diversity. An expatriate-majority customer base means passports and ID documents from dozens of countries, in multiple scripts. Coverage that works for Gulf documents but fails on South Asian, African or European ones creates uneven failure rates across customer segments.

Arabic and bilingual documentation. Trade licences, commercial registrations and government correspondence are Arabic or bilingual. Extraction quality directly determines downstream data quality.

Deepfake and injection attacks. The UAE is a high-value target, and attacks on remote onboarding have become materially more sophisticated. Liveness detection designed before 2023 no longer holds.

Frequently asked questions

Is the UAE still on the FATF grey list?

The UAE was removed in February 2024. Requirements did not relax as a result — supervisory intensity increased.

Do DIFC and ADGM follow CBUAE rules?

No. Both financial free zones have their own AML rulebooks and supervisors — the DFSA and FSRA respectively. Federal law applies across all, but detailed obligations differ.

How long must KYC records be kept?

Five years from the end of the customer relationship or the date of the transaction, and they must be retrievable.

Can UAE Pass alone satisfy KYC?

It can form a reliable part of identity verification for eligible customers, subject to the institution satisfying itself of the system’s reliability. It does not cover non-residents, corporate structures or supporting documentation.

What is goAML?

The UAE Financial Intelligence Unit’s reporting platform. Registration is a compliance obligation for reporting entities, and suspicious transaction reports are filed through it.

How iPass helps

iPass handles the document diversity a UAE customer base actually presents. Arabic and English OCR with intelligent document processing reads Emirates IDs, trade licences and bilingual documents natively. Forensic-grade identity verification pairs document authentication with liveness detection built for current-generation deepfake and injection attacks. AML screening with perpetual KYC monitoring supports per-entity rule configuration, so onshore, DIFC and ADGM operations can run different policies on one platform.

See pricing or talk to our team.

Related guides