Skip to content

Insights AML

SDD vs CDD vs EDD: Enhanced Due Diligence in Dubai and UAE AML

SDD vs CDD vs EDD compared for UAE firms — when enhanced due diligence applies in Dubai, plus triggers and evidence under current UAE AML rules.

UAE DNFBP compliance officer comparing enhanced, customer and simplified due diligence files at a desk
UAE DNFBP compliance officer comparing enhanced, customer and simplified due diligence files at a desk Photo: Velmont Crest Editorial

Key takeaways

  1. Three diligence tiers — CDD, EDD and SDD — sit inside Cabinet Resolution 134 of 2025 and apply across every DNFBP sector.
  2. EDD is mandatory for foreign PEPs, FATF grey/black list jurisdictions, complex transactions, and many cash-intensive sectors.
  3. SDD is permitted only where risk is demonstrably low — never as a default shortcut for small clients.
  4. AED 55,000 (DPMS cash) and AED 3,500 (wire transfer) thresholds trigger occasional-transaction CDD even without a relationship.
  5. Penalties for inadequate CDD or EDD reach up to AED 5,000,000 per breach, with files retained for five years.
  6. A specialist accounting firm can draft the risk matrix, CDD/EDD templates and file audits — advisory support, not regulated AML officer roles.

SDD vs CDD vs EDD is a question of how much scrutiny the risk in front of you justifies: CDD is the default measure, EDD applies to higher-risk relationships, and SDD is allowed only where low risk is documented. Enhanced due diligence in Dubai runs on the same federal rules as the rest of the UAE — only the supervisor changes inside the DIFC.

UAE supervisors do not recognise a single, uniform anti-money-laundering customer file. Three tiers of due diligence — Customer Due Diligence (CDD), Enhanced Due Diligence (EDD) and Simplified Due Diligence (SDD) — sit inside the UAE’s AML executive regulation, Cabinet Resolution 134 of 2025, issued under Federal Decree-Law 10 of 2025. That framework repealed Cabinet Decision 10 of 2019 (at Article 70) and Federal Decree-Law 20 of 2018 (at Article 41 of the decree-law), and it carries the same risk-based structure forward.

One trigger did change, and it is the one DNFBPs most often quote at us. Article 6(2) of the repealed regulation applied the AED 55,000 occasional-transaction CDD trigger to Financial Institutions and DNFBPs; Article 7(2) of Cabinet Resolution 134 of 2025 applies it to Financial Institutions only, with a separate AED 3,500 trigger for occasional wire transfers. A DNFBP that reads its CDD duty off that threshold is reading an article that no longer names it.

What actually binds a DNFBP is Article 7(1): customer due diligence on commencing a business relationship, where a crime is suspected, and where there are doubts about the accuracy or adequacy of identification data previously obtained. Dealers in valuable metals and precious stones keep a AED 55,000 figure of their own, but it is a scoping test in Article 3(3) and it is cash only. The framework is risk-based on purpose. It expects DNFBPs to think before they paper.

What we see instead is most firms applying CDD blindly to every onboarding — which both misses the high-risk relationships that should have escalated to EDD and buries SDD-eligible counterparties under documentation they never needed. The result is protection that’s uneven where it matters, and inspection findings that read almost identically across the sector. Our AML compliance advisory work starts by rebuilding the risk-based customer classification before touching any individual file.

SDD vs CDD vs EDD: the short answer

SDD vs CDD vs EDD comes down to how much scrutiny the risk in front of you justifies. CDD is the standard measure you run on almost every customer: identify them, verify that identity against independent documents, find the beneficial owner and monitor the relationship. EDD is CDD plus more — you establish source of wealth and source of funds, get senior management to approve the file, and monitor harder because the customer, the country or the transaction carries elevated money-laundering risk. A foreign politically exposed person caught in PEP and sanctions screening is the textbook trigger. SDD is CDD dialled down: you still identify and monitor, but the evidence and refresh cadence ease off because you have written proof the risk is genuinely low.

If the acronyms themselves are the obstacle, read anti-money laundering explained from the beginning first, then come back to the tiers. Read the three as one sliding scale rather than three separate products. Every file starts from a risk assessment, and that assessment decides whether it settles at simplified, standard or enhanced. A firm that cannot show why a given customer landed on one rung rather than another has the gap supervisors probe first. The tiers themselves sit in the UAE AML executive regulation, and the reasoning behind each rating has to be on the customer record — not just the paperwork it produced.

The three tiers, defined

CDD — the default baseline

Customer Due Diligence is the floor everything else builds on — CDD UAE AML obligations run through the customer due diligence articles of the UAE’s AML executive regulation, Cabinet Resolution 134 of 2025. The firm identifies the customer and verifies that identity using reliable, independent source documents — passport, Emirates ID, trade licence, articles of association. It identifies the beneficial owner and takes reasonable measures to verify them, drilling through the legal arrangements until the natural persons exercising ultimate ownership or control are on record.

It understands, and where relevant documents, the purpose and intended nature of the relationship. And it monitors the relationship on an ongoing basis, checking transactions against the customer profile and refreshing documents as they change. A standardised customer due diligence (CDD) form for your UAE client onboarding turns these four obligations into a repeatable checklist, but none of it is a tick-box exercise — the form only works if the reasoning behind each rating sits on the file.

If you have only ever heard this called KYC, you are in the right place. KYC — Know Your Customer — is the everyday name for the identification and verification half of CDD, and banks in particular use the two terms as though they were synonyms. The distinction worth holding on to is that KYC describes the evidence-gathering step, while CDD is the wider obligation that also covers understanding the purpose of the relationship, identifying the ultimate beneficial owner, and monitoring the account for as long as it stays open. Every CDD file therefore contains KYC work, but a folder of KYC documents on its own does not discharge the CDD obligation. Supervisors read that gap closely, and “we collected the passport and the trade licence” is not an answer to “show me your customer due diligence”.

EDD — for higher-risk clients

Enhanced Due Diligence stacks extra layers on top of CDD. The firm establishes the source of funds for the specific transaction and the source of wealth behind the customer’s overall financial position. Senior management, not the relationship handler, signs off the onboarding or its continuation. Monitoring gets more frequent and more searching, with lower transaction thresholds tripping a review. And the firm goes looking for documentation to corroborate the customer’s story — bank statements, tax filings, audited accounts, asset valuations, contracts. This is the tier where a UAE DNFBP shows it has genuinely understood a complex or sensitive relationship rather than just filed it.

SDD — for demonstrably low-risk relationships

Simplified Due Diligence reduces the depth, timing and intensity of CDD measures without removing them. The firm still identifies the customer and beneficial owner, still understands the relationship, still monitors. What eases is the evidentiary burden, the refresh cadence and the scrutiny applied to ordinary-course transactions. But SDD has to rest on a documented low-risk assessment, and supervisors will push back on any firm that reaches for it without a written rationale on file.

UAE compliance officer reviewing customer due diligence files across three tiers

What pushes a file into EDD

The following relationships and circumstances move a customer into EDD under the UAE AML executive regulation and the Ministry of Economy supervisory guidance:

  • Foreign politically exposed persons (PEPs) — always EDD, including family members and close associates. Domestic PEPs are risk-based but most firms default to EDD.
  • Customers based in high-risk third countries — FATF grey-list and black-list jurisdictions, and any country the UAE has independently designated as higher risk.
  • Complex or unusual transactions with no apparent economic or lawful purpose, or transactions structured to avoid reporting thresholds.
  • Cash-intensive businesses — the gold and jewellery sector (see our guide to accounting for a gold trading company in the UAE), real estate (covered in our real estate accounting guide), and other DPMS categories where physical value moves with limited paper trail.
  • Correspondent banking relationships — though most DNFBPs are not directly exposed, downstream service providers may be.
  • Non-face-to-face onboarding without compensating controls such as video verification, certified-copy notarisation, or trusted-introducer routing.
  • Customers or sectors flagged by Ministry of Economy AML/CFT supervisory guidance, FIU typology bulletins, or adverse media indicating ML/TF concern.
  • Sanctions exposure — any nexus to OFAC SDN, UN 1267, UK OFSI or UAE local sanctions list triggers immediate EDD even where no direct match occurs.

Enhanced due diligence in Dubai: mainland, free zone and DIFC

Enhanced due diligence in Dubai runs on the same federal foundation as the rest of the country, but which regulator inspects you depends on where you are licensed. A mainland Dubai DNFBP — an estate agent, a gold dealer, an accountant, a corporate service provider — sits under Federal Decree-Law 10 of 2025 and its executive regulation, Cabinet Resolution 134 of 2025 (which repealed Federal Decree-Law 20 of 2018 and Cabinet Decision 10 of 2019 respectively), is supervised by the Ministry of Economy, and registers with the Financial Intelligence Unit through goAML. Firms in commercial free zones such as DMCC or JAFZA follow the identical federal regime.

The DIFC is the exception. As a financial free zone it has its own regulator, the Dubai Financial Services Authority, whose AML rulebook applies to firms inside the district. The substance barely differs, because both frameworks put FATF standards into local rules, so the enhanced measures look the same wherever you sit: establish source of wealth and source of funds, obtain senior management approval before onboarding, screen against sanctions and PEP lists, and monitor more closely. What changes is the inspecting body and the exact reporting channel.

A worked example of enhanced due diligence in Dubai: a mainland Dubai real-estate brokerage onboards a buyer paying through a two-layer offshore structure, where the ultimate beneficial owner is a former deputy minister of a foreign state. Two EDD triggers fire at once — foreign PEP, and a complex structure with no obvious economic rationale. The correct file is not a thicker stack of passport copies.

It is a documented source-of-wealth narrative for the UBO (public office is not itself a source of wealth, so the file needs the underlying business or asset history), source-of-funds evidence for this specific purchase traced to an identifiable account, screening results for the UBO and every intermediate entity against sanctions and PEP lists, a written senior-management approval to open the relationship, and a shortened monitoring cycle recorded on the file. Miss the senior-management sign-off and the tier is technically unmet even where every other document is present.

If you run entities on both sides of the DIFC boundary — say a mainland trade licence alongside a DIFC-formed holding company — map which one answers to which supervisor before an inspection, not during one. Our MoE AML inspection playbook sets out what Ministry of Economy visits actually test at file level.

When CDD has to be done

CDD must be performed — not just on relationship opening — in the following circumstances:

  • Establishing a business relationship, whether ongoing or one-off, regardless of value.
  • Occasional transaction at or above AED 55,000 for designated non-financial businesses including dealers in precious metals and stones (the DPMS cash threshold).
  • Wire transfer of AED 3,500 or more, with originator and beneficiary information obligations.
  • Suspicion of money laundering or terrorism financing, regardless of any threshold or apparent customer status — and accompanied by a suspicious transaction report to the FIU via goAML.
  • Doubt about the veracity or adequacy of previously obtained customer identification data — refresh is mandatory, not optional.

When SDD is genuinely allowed

SDD is the most over-claimed tier in UAE practice. Firms reach for it when documentation is hard to obtain, then describe the customer as “low risk” without a supporting analysis. That position fails on inspection. SDD is genuinely available in narrow scenarios:

  • Regulated financial institutions licensed in jurisdictions with FATF-compliant AML/CFT regimes, where the firm has confirmed the regulatory status.
  • Listed companies on regulated stock exchanges subject to disclosure requirements consistent with international standards.
  • UAE federal and local government entities, including wholly-owned government companies, where ownership is transparent.
  • Public administrations or enterprises in low-risk jurisdictions with appropriate transparency.

Even where SDD applies, the firm must still identify the beneficial owner if the ownership or control structure is complex, must apply ongoing monitoring proportionate to the relationship, and must escalate to standard CDD or EDD if any trigger event arises. The reduction is in depth and frequency — never in the existence of controls. Documenting the low-risk conclusion is a hard requirement.

SDD vs CDD: what actually changes

SDD vs CDD is the comparison firms get wrong most often, because the two tiers share the same building blocks and differ only in intensity. Under standard CDD you identify the customer, verify that identity from independent sources, establish the beneficial owner and monitor the relationship throughout. Simplified due diligence keeps every one of those obligations — nothing is removed — but eases the evidence you gather, how often you refresh it, and how closely you scrutinise ordinary transactions. You might accept a single reliable identity source rather than several, refresh on a three-year cycle instead of two, and monitor with a lighter touch.

The real difference is the entry ticket. CDD is the default you may apply to almost anyone; SDD only opens up once you have written down why the money-laundering risk is demonstrably low — a regulated bank, a listed company, a government entity. Reach for SDD without that recorded assessment and, on inspection, it reads as CDD you simply failed to finish. If a trigger event appears, you escalate straight back to full CDD or EDD. And you still confirm the beneficial owner where the ownership structure is complex — our UBO declaration guide covers that step and its annual refresh.

3 tiers

CDD, EDD and SDD under the UAE AML executive regulation

UAE DNFBP compliance team comparing risk classifications across customer files

CDD vs EDD vs SDD, requirement by requirement

RequirementCDDEDDSDD
Customer identificationRequiredRequiredRequired
Identity verification (independent source)RequiredRequired, with additional corroborating documentsRequired, may use single reliable source
Beneficial owner identificationRequiredRequired, drilled to natural persons with corroborationRequired where structure is complex
Source of fundsRisk-basedMandatoryNot required unless triggered
Source of wealthNot requiredMandatoryNot required
Ongoing monitoring frequencyStandardIntensified with lower review thresholdsReduced but not eliminated
Senior management approvalNot requiredRequired to onboard and to continueNot required
Refresh cadence (working baseline)2 yearsAnnual or 6 months3 years
Retention period5 years from end of relationship5 years from end of relationship5 years from end of relationship
Documented rationale on fileRisk ratingRisk rating + EDD justification + approvalsRisk rating + low-risk justification

Where each tier is actually written down

A lot of UAE material describes the three tiers without ever pointing at the provision that creates them, which makes it hard to argue a position with an inspector. In Cabinet Resolution No. 134 of 2025 the tiers are not spread across the document — EDD and SDD both sit inside Article 5, the risk-identification and risk-mitigation article, and the measures are listed by example rather than left to interpretation.

TierWhere it sits in CR 134/2025What the article actually says
Risk assessment that drives the tieringArticle 5(1)Consider customer, country and geographic, product, service, transaction and delivery-channel risks before setting the overall risk level; document the process and retain the study
CDD trigger — business relationshipArticle 7Applied before establishing the relationship
CDD trigger — occasional transactionArticle 7(2)(a)AED 55,000, single or linked transactions
CDD trigger — wire transferArticle 7(2)(b)AED 3,500
CDD trigger — virtual asset service providersArticle 7(3)AED 3,500 on occasional transactions
Beneficial owner identificationArticle 10The natural person with ultimate ownership or effective control, direct or indirect
EDD measuresArticle 5(2)(c)Seven listed measures, “by way of example”
SDD measuresArticle 5(3)Four listed measures, permitted only where low risk is identified
PEP handlingArticle 16Risk-management systems to detect PEPs, senior-management approval, source of funds and wealth
Record retentionArticle 25Not less than five years
Independent audit of the programmeArticle 21(6)An independent audit function to test effectiveness and adequacy

Article and threshold references above are quoted from Cabinet Resolution No. 134 of 2025, checked 5 August 2026.

The seven EDD measures, as the regulation lists them

Article 5(2)(c) does not say “apply enhanced due diligence” and leave you to invent it. It gives seven examples, and an inspection file that shows several of them applied to a high-risk client is a far easier conversation than one that shows a note saying “EDD applied”.

#Measure, as Article 5(2)(c) words it
1Obtaining and verifying additional information on the customer’s identity and occupation, the beneficial owner, the amount of funds, and information from public databases and open sources
2Obtaining additional information on the purpose of the business relationship, or the reasons for expected or actual transactions
3Updating customer due diligence information on the customer and the beneficial owner more regularly
4Taking reasonable measures to identify the source of funds and wealth of the customer and the beneficial owner
5Increasing the degree and level of ongoing monitoring, and selecting transaction patterns requiring further scrutiny
6Carrying out the first payment through an account in the customer’s name at a financial institution subject to equivalent due diligence standards
7Obtaining senior management approval to commence or continue the business relationship

Measure six is the one UAE firms skip most often and the one that is easiest to evidence, because it leaves a bank record rather than a memo.

The SDD condition nearly every guide leaves out

Simplified due diligence is not a lighter default you can elect into on your own judgement. Article 5(3) permits it only where the firm has first satisfied the risk-assessment and risk-mitigation requirements in Clauses (1) and (2), only where low risks are identified, only where there is no suspicion that a crime has been committed — and, in the regulation’s own words, only “in coordination with the Supervisory Authority”. That last condition is a gate, not a formality, and it does not appear in most published summaries of the UAE regime.

Permitted SDD measureArticle 5(3) wording
Deferred verificationVerifying the identity of the customer and the beneficial owner after the relationship commences
Longer refresh cycleUpdating customer data at longer intervals
Lighter monitoringReducing the frequency of ongoing monitoring and transaction scrutiny
Inferred purposeInferring the purpose and nature of the relationship from the type of transaction, without collecting information separately

Note what SDD never permits: skipping identification entirely, skipping sanctions screening, or continuing once suspicion arises. Article 5(3) requires “full implementation of the instructions issued by the Executive Office or other Competent Authorities in relation to Targeted Financial Sanctions” even in the simplified tier. A firm in Dubai, Abu Dhabi or Sharjah that treats SDD as “we did not really check” has misread the provision, and item 34 of the Cabinet Resolution No. 71 of 2024 annex — AED 50,000 to AED 1,000,000 for failing to screen against the lists — attaches regardless of tier.

What each tier costs when it is done badly

Tiering is not an abstract exercise. Each of the three tiers maps onto a specific numbered violation in the annex to Cabinet Resolution No. 71 of 2024, and the figures below are the published minimum and maximum the Ministry applies per violation in Dubai, Abu Dhabi, Sharjah or anywhere else in the UAE — the annex is federal and does not vary by emirate.

FailureAnnex itemMinimumMaximum
No CDD before a relationship or an occasional transaction at or above AED 55,0009AED 50,000AED 200,000
Identity of customer or real beneficiary not verified from a reliable independent source11AED 50,000AED 200,000
Purpose and nature of the relationship and the ownership structure not understood12AED 50,000AED 200,000
Beneficial owner of a legal person not identified and validated13AED 50,000AED 200,000
EDD not applied where high risk was identified15AED 100,000AED 500,000
EDD not applied to a counterparty in a high-risk jurisdiction16AED 100,000AED 500,000
No system to determine whether a customer or beneficial owner is a PEP18AED 50,000AED 200,000
No ongoing auditing and monitoring of the continuing relationship19AED 50,000AED 500,000
Third-party reliance for CDD without the required measures20AED 50,000AED 200,000
Records and data not kept for the specified periods26AED 50,000AED 200,000

Figures quoted from the list annexed to Cabinet Resolution No. 71 of 2024, from the Ministry of Economy and Tourism’s published copy, checked 5 August 2026. Article 5(2) of that Resolution lets the Ministry double any of these where the violation is repeated.

Read down that column and the shape of the regime becomes obvious. Getting the tier wrong upward — applying CDD where EDD was needed — is priced at AED 100,000 to AED 500,000. Getting the mechanics wrong within a tier is generally AED 50,000 to AED 200,000. And SDD applied where it was not permitted is not a discount at all: the file simply fails item 9, because the CDD that should have happened did not.

How AML risk maps across the DNFBP sectors

The UAE’s DNFBP sectors each carry characteristic risk patterns, and they do not all answer to the same supervisor — the Ministry of Economy oversees real estate brokers, dealers in precious metals and stones, auditors and accountants, and corporate service providers, while lawyers and notaries fall under the Ministry of Justice. The split between CDD and EDD reflects the inherent risk profile of the work:

  1. Real estate brokers and agencies — EDD on all cash-heavy transactions, transactions involving offshore corporate buyers, and high-value residential or commercial deals. Beneficial ownership of corporate purchasers must be drilled to natural persons.
  2. Dealers in precious metals and stones (DPMS) — EDD on any single or linked cash transaction at or above AED 55,000, and on relationships with high-volume traders regardless of payment method. The gold and jewellery sector remains under intensive Ministry of Economy focus.
  3. Auditors — risk-based EDD driven by client portfolio composition. Auditors with concentrated exposure to cash-intensive sectors, offshore structures, or higher-risk jurisdictions should expect to operate substantial EDD volume.
  4. Independent accountants — EDD when the client uses complex group structures, nominee arrangements, multiple jurisdictions, or operates in higher-risk sectors. Bookkeeping engagements still fall within scope where the accounting and bookkeeping work touches transactional records.
  5. Tax consultants — EDD where the engagement involves aggressive tax planning, cross-border structuring or any arrangement whose primary purpose appears to be obscuring beneficial ownership. Standard corporate tax compliance work for resident UAE businesses typically sits at CDD level.
  6. Lawyers, notaries and independent legal professionals — EDD on trust and foundation formation, asset transfers without clear commercial rationale, escrow arrangements, and any client managing money or assets for third parties.
  7. Corporate service providers — EDD on any nominee shareholder or director arrangement, any structure where the beneficial owner is concealed by the legal form, and any high-volume incorporation client. Our corporate service provider AML programme guide maps the CDD and EDD layers a formation agent has to run at incorporation.

Tier misclassification is the most common inspection finding we see, not missing files. Firms apply standard CDD to a foreign PEP routed through an offshore structure, then bury a regulated bank counterparty in the same paperwork. The risk-based approach in the UAE AML rules expects you to triage before you paper.

— Velmont Crest advisory note

Where an accounting firm fits in

Velmont Crest is positioned as advisory support — we are not appointed as your AML officer and we do not represent your firm to supervisors. Within that boundary, the work we typically undertake on a DD programme covers:

  • Risk-based customer classification matrix — drafting a written methodology that scores each customer across geographic, sectoral, transactional, ownership-structure and delivery-channel risk dimensions, with documented thresholds for CDD, EDD and SDD assignment.
  • CDD, EDD and SDD templates — building the standardised checklists, evidence requirements, approval routings and refresh schedules each tier demands, mapped to the UAE AML executive regulation.
  • Staff training — onboarding, refresher and role-specific training for relationship handlers, finance teams and senior management on tier triggers and red flags.
  • File audits — sampling open customer files against the matrix, identifying tier-misclassification and remediation gaps before supervisors do.
  • MLRO escalation support — assisting your appointed officer with structuring escalation logs, internal suspicion routing and goAML report drafting.

We do not perform regulated AML functions and we do not hold a designated supervisor role. Where a programme gap requires a licensed activity, we say so and refer.

A practical checklist before inspection day

  1. Document a written risk-based methodology approved by senior management, covering all five risk dimensions and tier-assignment thresholds.
  2. Build a customer risk-rating matrix that produces a defensible score on every onboarding and every periodic refresh.
  3. Train relationship handlers on EDD triggers, with a particular focus on PEP identification, jurisdiction screening and complex-structure escalation.
  4. Implement screening against OFAC SDN, UN 1267, UK OFSI, EU sanctions and the UAE local sanctions list — at onboarding and on a rolling basis.
  5. Capture beneficial ownership for every corporate customer, drilled to natural persons with verification evidence retained.
  6. Establish source of funds and source of wealth files for every EDD customer, with documented corroboration.
  7. Route EDD onboardings through senior management approval with the approval recorded on the customer file.
  8. Set risk-based refresh cycles — annual minimum for EDD, two years for standard CDD, three years for SDD — with trigger-event override.
  9. Retain all CDD, EDD and SDD records, including rationale, for at least five years from the end of the relationship or completion of the occasional transaction.
  10. Audit a sample of files quarterly against the matrix and remediate findings before the next supervisory inspection cycle.

UAE supervisors are no longer testing whether DNFBPs have an AML policy. That battle was won. The current inspection focus is whether the policy is applied with discipline at the file level, whether tier classification is defensible, and whether EDD actually intensifies scrutiny rather than producing the same CDD paperwork with a different cover sheet.

The bar keeps rising. Ministry of Economy supervisory visits across 2025 and into 2026 have shown more willingness to test the underlying rationale on individual files, not just confirm a policy exists. Inspectors ask why a particular customer was rated standard rather than enhanced, who reviewed the rating, and how the conclusion was evidenced. Firms relying on a generic policy document with no file-level reasoning have found the gap difficult to close mid-inspection.

If you would like a review of how your current programme classifies clients across CDD, EDD and SDD, our team can sample your open files against current UAE AML expectations and produce a remediation matrix you can work through internally. Start a conversation through our AML compliance support page.

Frequently asked questions

SDD vs CDD vs EDD — what is the difference?
They are three intensities of the same obligation, not three different products. CDD is the baseline you run on almost every customer: identify them, verify that identity against reliable independent documents, identify the beneficial owner, understand the purpose of the relationship and monitor it. EDD is CDD plus more — establish source of wealth and source of funds, obtain senior management approval before onboarding or continuing, and monitor more frequently at lower trigger thresholds. SDD is CDD dialled down: you still identify, still monitor, but the evidence depth and refresh cadence ease off. The tier is decided by a documented risk assessment, and the reasoning has to sit on the customer file.
SDD vs CDD — what actually changes between the two?
Nothing is removed; the intensity drops. Under SDD you still identify and verify the customer, still identify the beneficial owner where the structure is complex, still understand the relationship, and still monitor it. What eases is the evidentiary burden, how often documents are refreshed, and how closely ordinary-course transactions are scrutinised. The critical difference is the gate in front of it: CDD is the default that needs no justification, while SDD is only available where you have written down why the money-laundering and terrorism-financing risk is demonstrably low. Reaching for SDD without that documented rationale is one of the findings UAE supervisors raise most often.
What does enhanced due diligence in Dubai involve?
The same measures as anywhere else in the UAE, because the framework is federal: establish the customer's source of wealth and the source of funds for the transaction, obtain senior management approval before opening or continuing the relationship, screen against sanctions and PEP lists, corroborate the customer's story with independent documents, and monitor more frequently. What differs in Dubai is who inspects you. A mainland Dubai DNFBP and firms in commercial free zones such as DMCC or JAFZA answer to the Ministry of Economy and register with the Financial Intelligence Unit through goAML. Firms inside the DIFC answer to the Dubai Financial Services Authority under its own AML rulebook.
What automatically triggers Enhanced Due Diligence in the UAE?
A handful of things flip a customer into EDD with no judgement call involved under the UAE AML rules. Foreign politically exposed persons — plus their family and close associates — always require it. So does anyone, customer or beneficial owner, resident in a FATF grey- or black-list jurisdiction. Complex or oddly large transactions with no clear economic purpose pull you into enhanced scrutiny too, as do non-face-to-face onboarding without compensating controls, correspondent banking, and sectors the Ministry of Economy has flagged. Domestic PEPs are technically risk-based, but honestly, most firms just default them to EDD.
When is Simplified Due Diligence actually permissible?
Far less often than firms wish. SDD only applies where ML/TF risk is demonstrably low, and you have to write down why you reached that conclusion. The clean examples are UAE government entities, listed companies on well-regulated exchanges, and regulated financial institutions sitting in FATF-compliant jurisdictions. Even then it isn't a free pass. You still identify the beneficial owner where the structure is complex, and you still monitor, just less intensively. What you're dialling down is depth and frequency, not the controls themselves.
Who decides which due diligence tier applies to a client?
You do — the DNFBP itself, working from a documented risk-based methodology that senior management has signed off. There's no government list that classifies your clients for you. The UAE AML rules expect you to assess ML/TF risk across customers, countries, products, services, transactions and delivery channels, then apply controls that fit. In practice the compliance function (with an advisory firm helping where in-house capacity is thin) builds a risk-rating matrix, scores each onboarding, and pushes the higher-risk files up for senior management approval before the file opens. Inspectors then check the matrix exists, gets applied consistently, and that the reasoning is on record.
Does every PEP automatically require Enhanced Due Diligence?
Foreign PEPs, yes — non-negotiable under the UAE AML rules, and the same goes for their immediate family and close associates. Domestic PEPs and people entrusted with prominent functions by international organisations are the grey area: they're handled on a risk-sensitive basis, so EDD where higher risk shows up, and enhanced standard CDD with PEP-specific monitoring where it doesn't. Most well-run DNFBPs don't bother litigating that line internally and just apply EDD across the board. For any PEP, EDD means senior management approval, established source of wealth and funds, and tighter ongoing monitoring.
What is KYC, and is it the same thing as CDD?
KYC stands for Know Your Customer. In practice it names the identification and verification part of the work — collecting the passport, Emirates ID, trade licence or articles of association, and checking them against reliable independent sources. CDD is broader. On top of that identification work it requires you to identify the ultimate beneficial owner, understand the purpose and intended nature of the relationship, and monitor it on an ongoing basis. Banks tend to use the two words interchangeably, which is where most of the confusion starts. For a UAE DNFBP the safe reading is that KYC is one component of CDD, never a substitute for it.
What is money laundering, and what does AML/CFT mean in the UAE?
Money laundering is the process of making the proceeds of crime look like legitimate income, typically by moving funds through layers of transactions until the original source is obscured. AML stands for anti-money laundering — the framework of obligations built to detect and prevent that. CFT, countering the financing of terrorism, sits alongside it and is regulated together with it, which is why UAE material almost always refers to AML/CFT as a single regime. For designated non-financial businesses and professions, that regime is what generates the due diligence tiers, the goAML reporting duty and the record-keeping obligations this guide covers.
How often should we refresh CDD and EDD documentation?
It's driven by risk. The working baseline most UAE DNFBPs run is three years for low-risk customers, two for standard, and at least annually for EDD — dropping to every six months for the riskiest files. But the schedule is only a floor. A change in beneficial ownership, an odd transaction pattern, a shift in country risk, adverse media, a change in PEP status — any of these forces an immediate refresh regardless of where you are in the cycle. And every CDD, EDD and SDD record, evidence and rationale included, stays on file for at least five years after the relationship ends or the occasional transaction completes.

Filed under: EDD, CDD, SDD, AML compliance, DNFBP, due diligence

Published · Updated