Insights AML
SDD vs CDD vs EDD: Enhanced Due Diligence in Dubai and UAE AML
SDD vs CDD vs EDD compared for UAE firms — when enhanced due diligence applies in Dubai, plus triggers and evidence under current UAE AML rules.

Key takeaways
- Three diligence tiers — CDD, EDD and SDD — sit inside Cabinet Resolution 134 of 2025 and apply across every DNFBP sector.
- EDD is mandatory for foreign PEPs, FATF grey/black list jurisdictions, complex transactions, and many cash-intensive sectors.
- SDD is permitted only where risk is demonstrably low — never as a default shortcut for small clients.
- AED 55,000 (DPMS cash) and AED 3,500 (wire transfer) thresholds trigger occasional-transaction CDD even without a relationship.
- Penalties for inadequate CDD or EDD reach up to AED 5,000,000 per breach, with files retained for five years.
- A specialist accounting firm can draft the risk matrix, CDD/EDD templates and file audits — advisory support, not regulated AML officer roles.
SDD vs CDD vs EDD is a question of how much scrutiny the risk in front of you justifies: CDD is the default measure, EDD applies to higher-risk relationships, and SDD is allowed only where low risk is documented. Enhanced due diligence in Dubai runs on the same federal rules as the rest of the UAE — only the supervisor changes inside the DIFC.
UAE supervisors do not recognise a single, uniform anti-money-laundering customer file. Three tiers of due diligence — Customer Due Diligence (CDD), Enhanced Due Diligence (EDD) and Simplified Due Diligence (SDD) — sit inside the UAE’s AML executive regulation, Cabinet Resolution 134 of 2025, issued under Federal Decree-Law 10 of 2025. That framework repealed Cabinet Decision 10 of 2019 (at Article 70) and Federal Decree-Law 20 of 2018 (at Article 41 of the decree-law), and it carries the same risk-based structure forward.
One trigger did change, and it is the one DNFBPs most often quote at us. Article 6(2) of the repealed regulation applied the AED 55,000 occasional-transaction CDD trigger to Financial Institutions and DNFBPs; Article 7(2) of Cabinet Resolution 134 of 2025 applies it to Financial Institutions only, with a separate AED 3,500 trigger for occasional wire transfers. A DNFBP that reads its CDD duty off that threshold is reading an article that no longer names it.
What actually binds a DNFBP is Article 7(1): customer due diligence on commencing a business relationship, where a crime is suspected, and where there are doubts about the accuracy or adequacy of identification data previously obtained. Dealers in valuable metals and precious stones keep a AED 55,000 figure of their own, but it is a scoping test in Article 3(3) and it is cash only. The framework is risk-based on purpose. It expects DNFBPs to think before they paper.
What we see instead is most firms applying CDD blindly to every onboarding — which both misses the high-risk relationships that should have escalated to EDD and buries SDD-eligible counterparties under documentation they never needed. The result is protection that’s uneven where it matters, and inspection findings that read almost identically across the sector. Our AML compliance advisory work starts by rebuilding the risk-based customer classification before touching any individual file.
SDD vs CDD vs EDD: the short answer
SDD vs CDD vs EDD comes down to how much scrutiny the risk in front of you justifies. CDD is the standard measure you run on almost every customer: identify them, verify that identity against independent documents, find the beneficial owner and monitor the relationship. EDD is CDD plus more — you establish source of wealth and source of funds, get senior management to approve the file, and monitor harder because the customer, the country or the transaction carries elevated money-laundering risk. A foreign politically exposed person caught in PEP and sanctions screening is the textbook trigger. SDD is CDD dialled down: you still identify and monitor, but the evidence and refresh cadence ease off because you have written proof the risk is genuinely low.
If the acronyms themselves are the obstacle, read anti-money laundering explained from the beginning first, then come back to the tiers. Read the three as one sliding scale rather than three separate products. Every file starts from a risk assessment, and that assessment decides whether it settles at simplified, standard or enhanced. A firm that cannot show why a given customer landed on one rung rather than another has the gap supervisors probe first. The tiers themselves sit in the UAE AML executive regulation, and the reasoning behind each rating has to be on the customer record — not just the paperwork it produced.
The three tiers, defined
CDD — the default baseline
Customer Due Diligence is the floor everything else builds on — CDD UAE AML obligations run through the customer due diligence articles of the UAE’s AML executive regulation, Cabinet Resolution 134 of 2025. The firm identifies the customer and verifies that identity using reliable, independent source documents — passport, Emirates ID, trade licence, articles of association. It identifies the beneficial owner and takes reasonable measures to verify them, drilling through the legal arrangements until the natural persons exercising ultimate ownership or control are on record.
It understands, and where relevant documents, the purpose and intended nature of the relationship. And it monitors the relationship on an ongoing basis, checking transactions against the customer profile and refreshing documents as they change. A standardised customer due diligence (CDD) form for your UAE client onboarding turns these four obligations into a repeatable checklist, but none of it is a tick-box exercise — the form only works if the reasoning behind each rating sits on the file.
If you have only ever heard this called KYC, you are in the right place. KYC — Know Your Customer — is the everyday name for the identification and verification half of CDD, and banks in particular use the two terms as though they were synonyms. The distinction worth holding on to is that KYC describes the evidence-gathering step, while CDD is the wider obligation that also covers understanding the purpose of the relationship, identifying the ultimate beneficial owner, and monitoring the account for as long as it stays open. Every CDD file therefore contains KYC work, but a folder of KYC documents on its own does not discharge the CDD obligation. Supervisors read that gap closely, and “we collected the passport and the trade licence” is not an answer to “show me your customer due diligence”.
EDD — for higher-risk clients
Enhanced Due Diligence stacks extra layers on top of CDD. The firm establishes the source of funds for the specific transaction and the source of wealth behind the customer’s overall financial position. Senior management, not the relationship handler, signs off the onboarding or its continuation. Monitoring gets more frequent and more searching, with lower transaction thresholds tripping a review. And the firm goes looking for documentation to corroborate the customer’s story — bank statements, tax filings, audited accounts, asset valuations, contracts. This is the tier where a UAE DNFBP shows it has genuinely understood a complex or sensitive relationship rather than just filed it.
SDD — for demonstrably low-risk relationships
Simplified Due Diligence reduces the depth, timing and intensity of CDD measures without removing them. The firm still identifies the customer and beneficial owner, still understands the relationship, still monitors. What eases is the evidentiary burden, the refresh cadence and the scrutiny applied to ordinary-course transactions. But SDD has to rest on a documented low-risk assessment, and supervisors will push back on any firm that reaches for it without a written rationale on file.

What pushes a file into EDD
The following relationships and circumstances move a customer into EDD under the UAE AML executive regulation and the Ministry of Economy supervisory guidance:
- Foreign politically exposed persons (PEPs) — always EDD, including family members and close associates. Domestic PEPs are risk-based but most firms default to EDD.
- Customers based in high-risk third countries — FATF grey-list and black-list jurisdictions, and any country the UAE has independently designated as higher risk.
- Complex or unusual transactions with no apparent economic or lawful purpose, or transactions structured to avoid reporting thresholds.
- Cash-intensive businesses — the gold and jewellery sector (see our guide to accounting for a gold trading company in the UAE), real estate (covered in our real estate accounting guide), and other DPMS categories where physical value moves with limited paper trail.
- Correspondent banking relationships — though most DNFBPs are not directly exposed, downstream service providers may be.
- Non-face-to-face onboarding without compensating controls such as video verification, certified-copy notarisation, or trusted-introducer routing.
- Customers or sectors flagged by Ministry of Economy AML/CFT supervisory guidance, FIU typology bulletins, or adverse media indicating ML/TF concern.
- Sanctions exposure — any nexus to OFAC SDN, UN 1267, UK OFSI or UAE local sanctions list triggers immediate EDD even where no direct match occurs.
Enhanced due diligence in Dubai: mainland, free zone and DIFC
Enhanced due diligence in Dubai runs on the same federal foundation as the rest of the country, but which regulator inspects you depends on where you are licensed. A mainland Dubai DNFBP — an estate agent, a gold dealer, an accountant, a corporate service provider — sits under Federal Decree-Law 10 of 2025 and its executive regulation, Cabinet Resolution 134 of 2025 (which repealed Federal Decree-Law 20 of 2018 and Cabinet Decision 10 of 2019 respectively), is supervised by the Ministry of Economy, and registers with the Financial Intelligence Unit through goAML. Firms in commercial free zones such as DMCC or JAFZA follow the identical federal regime.
The DIFC is the exception. As a financial free zone it has its own regulator, the Dubai Financial Services Authority, whose AML rulebook applies to firms inside the district. The substance barely differs, because both frameworks put FATF standards into local rules, so the enhanced measures look the same wherever you sit: establish source of wealth and source of funds, obtain senior management approval before onboarding, screen against sanctions and PEP lists, and monitor more closely. What changes is the inspecting body and the exact reporting channel.
A worked example of enhanced due diligence in Dubai: a mainland Dubai real-estate brokerage onboards a buyer paying through a two-layer offshore structure, where the ultimate beneficial owner is a former deputy minister of a foreign state. Two EDD triggers fire at once — foreign PEP, and a complex structure with no obvious economic rationale. The correct file is not a thicker stack of passport copies.
It is a documented source-of-wealth narrative for the UBO (public office is not itself a source of wealth, so the file needs the underlying business or asset history), source-of-funds evidence for this specific purchase traced to an identifiable account, screening results for the UBO and every intermediate entity against sanctions and PEP lists, a written senior-management approval to open the relationship, and a shortened monitoring cycle recorded on the file. Miss the senior-management sign-off and the tier is technically unmet even where every other document is present.
If you run entities on both sides of the DIFC boundary — say a mainland trade licence alongside a DIFC-formed holding company — map which one answers to which supervisor before an inspection, not during one. Our MoE AML inspection playbook sets out what Ministry of Economy visits actually test at file level.
When CDD has to be done
CDD must be performed — not just on relationship opening — in the following circumstances:
- Establishing a business relationship, whether ongoing or one-off, regardless of value.
- Occasional transaction at or above AED 55,000 for designated non-financial businesses including dealers in precious metals and stones (the DPMS cash threshold).
- Wire transfer of AED 3,500 or more, with originator and beneficiary information obligations.
- Suspicion of money laundering or terrorism financing, regardless of any threshold or apparent customer status — and accompanied by a suspicious transaction report to the FIU via goAML.
- Doubt about the veracity or adequacy of previously obtained customer identification data — refresh is mandatory, not optional.
When SDD is genuinely allowed
SDD is the most over-claimed tier in UAE practice. Firms reach for it when documentation is hard to obtain, then describe the customer as “low risk” without a supporting analysis. That position fails on inspection. SDD is genuinely available in narrow scenarios:
- Regulated financial institutions licensed in jurisdictions with FATF-compliant AML/CFT regimes, where the firm has confirmed the regulatory status.
- Listed companies on regulated stock exchanges subject to disclosure requirements consistent with international standards.
- UAE federal and local government entities, including wholly-owned government companies, where ownership is transparent.
- Public administrations or enterprises in low-risk jurisdictions with appropriate transparency.
Even where SDD applies, the firm must still identify the beneficial owner if the ownership or control structure is complex, must apply ongoing monitoring proportionate to the relationship, and must escalate to standard CDD or EDD if any trigger event arises. The reduction is in depth and frequency — never in the existence of controls. Documenting the low-risk conclusion is a hard requirement.
SDD vs CDD: what actually changes
SDD vs CDD is the comparison firms get wrong most often, because the two tiers share the same building blocks and differ only in intensity. Under standard CDD you identify the customer, verify that identity from independent sources, establish the beneficial owner and monitor the relationship throughout. Simplified due diligence keeps every one of those obligations — nothing is removed — but eases the evidence you gather, how often you refresh it, and how closely you scrutinise ordinary transactions. You might accept a single reliable identity source rather than several, refresh on a three-year cycle instead of two, and monitor with a lighter touch.
The real difference is the entry ticket. CDD is the default you may apply to almost anyone; SDD only opens up once you have written down why the money-laundering risk is demonstrably low — a regulated bank, a listed company, a government entity. Reach for SDD without that recorded assessment and, on inspection, it reads as CDD you simply failed to finish. If a trigger event appears, you escalate straight back to full CDD or EDD. And you still confirm the beneficial owner where the ownership structure is complex — our UBO declaration guide covers that step and its annual refresh.
3 tiers
CDD, EDD and SDD under the UAE AML executive regulation

CDD vs EDD vs SDD, requirement by requirement
| Requirement | CDD | EDD | SDD |
|---|---|---|---|
| Customer identification | Required | Required | Required |
| Identity verification (independent source) | Required | Required, with additional corroborating documents | Required, may use single reliable source |
| Beneficial owner identification | Required | Required, drilled to natural persons with corroboration | Required where structure is complex |
| Source of funds | Risk-based | Mandatory | Not required unless triggered |
| Source of wealth | Not required | Mandatory | Not required |
| Ongoing monitoring frequency | Standard | Intensified with lower review thresholds | Reduced but not eliminated |
| Senior management approval | Not required | Required to onboard and to continue | Not required |
| Refresh cadence (working baseline) | 2 years | Annual or 6 months | 3 years |
| Retention period | 5 years from end of relationship | 5 years from end of relationship | 5 years from end of relationship |
| Documented rationale on file | Risk rating | Risk rating + EDD justification + approvals | Risk rating + low-risk justification |
Where each tier is actually written down
A lot of UAE material describes the three tiers without ever pointing at the provision that creates them, which makes it hard to argue a position with an inspector. In Cabinet Resolution No. 134 of 2025 the tiers are not spread across the document — EDD and SDD both sit inside Article 5, the risk-identification and risk-mitigation article, and the measures are listed by example rather than left to interpretation.
| Tier | Where it sits in CR 134/2025 | What the article actually says |
|---|---|---|
| Risk assessment that drives the tiering | Article 5(1) | Consider customer, country and geographic, product, service, transaction and delivery-channel risks before setting the overall risk level; document the process and retain the study |
| CDD trigger — business relationship | Article 7 | Applied before establishing the relationship |
| CDD trigger — occasional transaction | Article 7(2)(a) | AED 55,000, single or linked transactions |
| CDD trigger — wire transfer | Article 7(2)(b) | AED 3,500 |
| CDD trigger — virtual asset service providers | Article 7(3) | AED 3,500 on occasional transactions |
| Beneficial owner identification | Article 10 | The natural person with ultimate ownership or effective control, direct or indirect |
| EDD measures | Article 5(2)(c) | Seven listed measures, “by way of example” |
| SDD measures | Article 5(3) | Four listed measures, permitted only where low risk is identified |
| PEP handling | Article 16 | Risk-management systems to detect PEPs, senior-management approval, source of funds and wealth |
| Record retention | Article 25 | Not less than five years |
| Independent audit of the programme | Article 21(6) | An independent audit function to test effectiveness and adequacy |
Article and threshold references above are quoted from Cabinet Resolution No. 134 of 2025, checked 5 August 2026.
The seven EDD measures, as the regulation lists them
Article 5(2)(c) does not say “apply enhanced due diligence” and leave you to invent it. It gives seven examples, and an inspection file that shows several of them applied to a high-risk client is a far easier conversation than one that shows a note saying “EDD applied”.
| # | Measure, as Article 5(2)(c) words it |
|---|---|
| 1 | Obtaining and verifying additional information on the customer’s identity and occupation, the beneficial owner, the amount of funds, and information from public databases and open sources |
| 2 | Obtaining additional information on the purpose of the business relationship, or the reasons for expected or actual transactions |
| 3 | Updating customer due diligence information on the customer and the beneficial owner more regularly |
| 4 | Taking reasonable measures to identify the source of funds and wealth of the customer and the beneficial owner |
| 5 | Increasing the degree and level of ongoing monitoring, and selecting transaction patterns requiring further scrutiny |
| 6 | Carrying out the first payment through an account in the customer’s name at a financial institution subject to equivalent due diligence standards |
| 7 | Obtaining senior management approval to commence or continue the business relationship |
Measure six is the one UAE firms skip most often and the one that is easiest to evidence, because it leaves a bank record rather than a memo.
The SDD condition nearly every guide leaves out
Simplified due diligence is not a lighter default you can elect into on your own judgement. Article 5(3) permits it only where the firm has first satisfied the risk-assessment and risk-mitigation requirements in Clauses (1) and (2), only where low risks are identified, only where there is no suspicion that a crime has been committed — and, in the regulation’s own words, only “in coordination with the Supervisory Authority”. That last condition is a gate, not a formality, and it does not appear in most published summaries of the UAE regime.
| Permitted SDD measure | Article 5(3) wording |
|---|---|
| Deferred verification | Verifying the identity of the customer and the beneficial owner after the relationship commences |
| Longer refresh cycle | Updating customer data at longer intervals |
| Lighter monitoring | Reducing the frequency of ongoing monitoring and transaction scrutiny |
| Inferred purpose | Inferring the purpose and nature of the relationship from the type of transaction, without collecting information separately |
Note what SDD never permits: skipping identification entirely, skipping sanctions screening, or continuing once suspicion arises. Article 5(3) requires “full implementation of the instructions issued by the Executive Office or other Competent Authorities in relation to Targeted Financial Sanctions” even in the simplified tier. A firm in Dubai, Abu Dhabi or Sharjah that treats SDD as “we did not really check” has misread the provision, and item 34 of the Cabinet Resolution No. 71 of 2024 annex — AED 50,000 to AED 1,000,000 for failing to screen against the lists — attaches regardless of tier.
What each tier costs when it is done badly
Tiering is not an abstract exercise. Each of the three tiers maps onto a specific numbered violation in the annex to Cabinet Resolution No. 71 of 2024, and the figures below are the published minimum and maximum the Ministry applies per violation in Dubai, Abu Dhabi, Sharjah or anywhere else in the UAE — the annex is federal and does not vary by emirate.
| Failure | Annex item | Minimum | Maximum |
|---|---|---|---|
| No CDD before a relationship or an occasional transaction at or above AED 55,000 | 9 | AED 50,000 | AED 200,000 |
| Identity of customer or real beneficiary not verified from a reliable independent source | 11 | AED 50,000 | AED 200,000 |
| Purpose and nature of the relationship and the ownership structure not understood | 12 | AED 50,000 | AED 200,000 |
| Beneficial owner of a legal person not identified and validated | 13 | AED 50,000 | AED 200,000 |
| EDD not applied where high risk was identified | 15 | AED 100,000 | AED 500,000 |
| EDD not applied to a counterparty in a high-risk jurisdiction | 16 | AED 100,000 | AED 500,000 |
| No system to determine whether a customer or beneficial owner is a PEP | 18 | AED 50,000 | AED 200,000 |
| No ongoing auditing and monitoring of the continuing relationship | 19 | AED 50,000 | AED 500,000 |
| Third-party reliance for CDD without the required measures | 20 | AED 50,000 | AED 200,000 |
| Records and data not kept for the specified periods | 26 | AED 50,000 | AED 200,000 |
Figures quoted from the list annexed to Cabinet Resolution No. 71 of 2024, from the Ministry of Economy and Tourism’s published copy, checked 5 August 2026. Article 5(2) of that Resolution lets the Ministry double any of these where the violation is repeated.
Read down that column and the shape of the regime becomes obvious. Getting the tier wrong upward — applying CDD where EDD was needed — is priced at AED 100,000 to AED 500,000. Getting the mechanics wrong within a tier is generally AED 50,000 to AED 200,000. And SDD applied where it was not permitted is not a discount at all: the file simply fails item 9, because the CDD that should have happened did not.
How AML risk maps across the DNFBP sectors
The UAE’s DNFBP sectors each carry characteristic risk patterns, and they do not all answer to the same supervisor — the Ministry of Economy oversees real estate brokers, dealers in precious metals and stones, auditors and accountants, and corporate service providers, while lawyers and notaries fall under the Ministry of Justice. The split between CDD and EDD reflects the inherent risk profile of the work:
- Real estate brokers and agencies — EDD on all cash-heavy transactions, transactions involving offshore corporate buyers, and high-value residential or commercial deals. Beneficial ownership of corporate purchasers must be drilled to natural persons.
- Dealers in precious metals and stones (DPMS) — EDD on any single or linked cash transaction at or above AED 55,000, and on relationships with high-volume traders regardless of payment method. The gold and jewellery sector remains under intensive Ministry of Economy focus.
- Auditors — risk-based EDD driven by client portfolio composition. Auditors with concentrated exposure to cash-intensive sectors, offshore structures, or higher-risk jurisdictions should expect to operate substantial EDD volume.
- Independent accountants — EDD when the client uses complex group structures, nominee arrangements, multiple jurisdictions, or operates in higher-risk sectors. Bookkeeping engagements still fall within scope where the accounting and bookkeeping work touches transactional records.
- Tax consultants — EDD where the engagement involves aggressive tax planning, cross-border structuring or any arrangement whose primary purpose appears to be obscuring beneficial ownership. Standard corporate tax compliance work for resident UAE businesses typically sits at CDD level.
- Lawyers, notaries and independent legal professionals — EDD on trust and foundation formation, asset transfers without clear commercial rationale, escrow arrangements, and any client managing money or assets for third parties.
- Corporate service providers — EDD on any nominee shareholder or director arrangement, any structure where the beneficial owner is concealed by the legal form, and any high-volume incorporation client. Our corporate service provider AML programme guide maps the CDD and EDD layers a formation agent has to run at incorporation.
Tier misclassification is the most common inspection finding we see, not missing files. Firms apply standard CDD to a foreign PEP routed through an offshore structure, then bury a regulated bank counterparty in the same paperwork. The risk-based approach in the UAE AML rules expects you to triage before you paper.
Where an accounting firm fits in
Velmont Crest is positioned as advisory support — we are not appointed as your AML officer and we do not represent your firm to supervisors. Within that boundary, the work we typically undertake on a DD programme covers:
- Risk-based customer classification matrix — drafting a written methodology that scores each customer across geographic, sectoral, transactional, ownership-structure and delivery-channel risk dimensions, with documented thresholds for CDD, EDD and SDD assignment.
- CDD, EDD and SDD templates — building the standardised checklists, evidence requirements, approval routings and refresh schedules each tier demands, mapped to the UAE AML executive regulation.
- Staff training — onboarding, refresher and role-specific training for relationship handlers, finance teams and senior management on tier triggers and red flags.
- File audits — sampling open customer files against the matrix, identifying tier-misclassification and remediation gaps before supervisors do.
- MLRO escalation support — assisting your appointed officer with structuring escalation logs, internal suspicion routing and goAML report drafting.
We do not perform regulated AML functions and we do not hold a designated supervisor role. Where a programme gap requires a licensed activity, we say so and refer.
A practical checklist before inspection day
- Document a written risk-based methodology approved by senior management, covering all five risk dimensions and tier-assignment thresholds.
- Build a customer risk-rating matrix that produces a defensible score on every onboarding and every periodic refresh.
- Train relationship handlers on EDD triggers, with a particular focus on PEP identification, jurisdiction screening and complex-structure escalation.
- Implement screening against OFAC SDN, UN 1267, UK OFSI, EU sanctions and the UAE local sanctions list — at onboarding and on a rolling basis.
- Capture beneficial ownership for every corporate customer, drilled to natural persons with verification evidence retained.
- Establish source of funds and source of wealth files for every EDD customer, with documented corroboration.
- Route EDD onboardings through senior management approval with the approval recorded on the customer file.
- Set risk-based refresh cycles — annual minimum for EDD, two years for standard CDD, three years for SDD — with trigger-event override.
- Retain all CDD, EDD and SDD records, including rationale, for at least five years from the end of the relationship or completion of the occasional transaction.
- Audit a sample of files quarterly against the matrix and remediate findings before the next supervisory inspection cycle.
UAE supervisors are no longer testing whether DNFBPs have an AML policy. That battle was won. The current inspection focus is whether the policy is applied with discipline at the file level, whether tier classification is defensible, and whether EDD actually intensifies scrutiny rather than producing the same CDD paperwork with a different cover sheet.
The bar keeps rising. Ministry of Economy supervisory visits across 2025 and into 2026 have shown more willingness to test the underlying rationale on individual files, not just confirm a policy exists. Inspectors ask why a particular customer was rated standard rather than enhanced, who reviewed the rating, and how the conclusion was evidenced. Firms relying on a generic policy document with no file-level reasoning have found the gap difficult to close mid-inspection.
If you would like a review of how your current programme classifies clients across CDD, EDD and SDD, our team can sample your open files against current UAE AML expectations and produce a remediation matrix you can work through internally. Start a conversation through our AML compliance support page.
Frequently asked questions
- SDD vs CDD vs EDD — what is the difference?
- They are three intensities of the same obligation, not three different products. CDD is the baseline you run on almost every customer: identify them, verify that identity against reliable independent documents, identify the beneficial owner, understand the purpose of the relationship and monitor it. EDD is CDD plus more — establish source of wealth and source of funds, obtain senior management approval before onboarding or continuing, and monitor more frequently at lower trigger thresholds. SDD is CDD dialled down: you still identify, still monitor, but the evidence depth and refresh cadence ease off. The tier is decided by a documented risk assessment, and the reasoning has to sit on the customer file.
- SDD vs CDD — what actually changes between the two?
- Nothing is removed; the intensity drops. Under SDD you still identify and verify the customer, still identify the beneficial owner where the structure is complex, still understand the relationship, and still monitor it. What eases is the evidentiary burden, how often documents are refreshed, and how closely ordinary-course transactions are scrutinised. The critical difference is the gate in front of it: CDD is the default that needs no justification, while SDD is only available where you have written down why the money-laundering and terrorism-financing risk is demonstrably low. Reaching for SDD without that documented rationale is one of the findings UAE supervisors raise most often.
- What does enhanced due diligence in Dubai involve?
- The same measures as anywhere else in the UAE, because the framework is federal: establish the customer's source of wealth and the source of funds for the transaction, obtain senior management approval before opening or continuing the relationship, screen against sanctions and PEP lists, corroborate the customer's story with independent documents, and monitor more frequently. What differs in Dubai is who inspects you. A mainland Dubai DNFBP and firms in commercial free zones such as DMCC or JAFZA answer to the Ministry of Economy and register with the Financial Intelligence Unit through goAML. Firms inside the DIFC answer to the Dubai Financial Services Authority under its own AML rulebook.
- What automatically triggers Enhanced Due Diligence in the UAE?
- A handful of things flip a customer into EDD with no judgement call involved under the UAE AML rules. Foreign politically exposed persons — plus their family and close associates — always require it. So does anyone, customer or beneficial owner, resident in a FATF grey- or black-list jurisdiction. Complex or oddly large transactions with no clear economic purpose pull you into enhanced scrutiny too, as do non-face-to-face onboarding without compensating controls, correspondent banking, and sectors the Ministry of Economy has flagged. Domestic PEPs are technically risk-based, but honestly, most firms just default them to EDD.
- When is Simplified Due Diligence actually permissible?
- Far less often than firms wish. SDD only applies where ML/TF risk is demonstrably low, and you have to write down why you reached that conclusion. The clean examples are UAE government entities, listed companies on well-regulated exchanges, and regulated financial institutions sitting in FATF-compliant jurisdictions. Even then it isn't a free pass. You still identify the beneficial owner where the structure is complex, and you still monitor, just less intensively. What you're dialling down is depth and frequency, not the controls themselves.
- Who decides which due diligence tier applies to a client?
- You do — the DNFBP itself, working from a documented risk-based methodology that senior management has signed off. There's no government list that classifies your clients for you. The UAE AML rules expect you to assess ML/TF risk across customers, countries, products, services, transactions and delivery channels, then apply controls that fit. In practice the compliance function (with an advisory firm helping where in-house capacity is thin) builds a risk-rating matrix, scores each onboarding, and pushes the higher-risk files up for senior management approval before the file opens. Inspectors then check the matrix exists, gets applied consistently, and that the reasoning is on record.
- Does every PEP automatically require Enhanced Due Diligence?
- Foreign PEPs, yes — non-negotiable under the UAE AML rules, and the same goes for their immediate family and close associates. Domestic PEPs and people entrusted with prominent functions by international organisations are the grey area: they're handled on a risk-sensitive basis, so EDD where higher risk shows up, and enhanced standard CDD with PEP-specific monitoring where it doesn't. Most well-run DNFBPs don't bother litigating that line internally and just apply EDD across the board. For any PEP, EDD means senior management approval, established source of wealth and funds, and tighter ongoing monitoring.
- What is KYC, and is it the same thing as CDD?
- KYC stands for Know Your Customer. In practice it names the identification and verification part of the work — collecting the passport, Emirates ID, trade licence or articles of association, and checking them against reliable independent sources. CDD is broader. On top of that identification work it requires you to identify the ultimate beneficial owner, understand the purpose and intended nature of the relationship, and monitor it on an ongoing basis. Banks tend to use the two words interchangeably, which is where most of the confusion starts. For a UAE DNFBP the safe reading is that KYC is one component of CDD, never a substitute for it.
- What is money laundering, and what does AML/CFT mean in the UAE?
- Money laundering is the process of making the proceeds of crime look like legitimate income, typically by moving funds through layers of transactions until the original source is obscured. AML stands for anti-money laundering — the framework of obligations built to detect and prevent that. CFT, countering the financing of terrorism, sits alongside it and is regulated together with it, which is why UAE material almost always refers to AML/CFT as a single regime. For designated non-financial businesses and professions, that regime is what generates the due diligence tiers, the goAML reporting duty and the record-keeping obligations this guide covers.
- How often should we refresh CDD and EDD documentation?
- It's driven by risk. The working baseline most UAE DNFBPs run is three years for low-risk customers, two for standard, and at least annually for EDD — dropping to every six months for the riskiest files. But the schedule is only a floor. A change in beneficial ownership, an odd transaction pattern, a shift in country risk, adverse media, a change in PEP status — any of these forces an immediate refresh regardless of where you are in the cycle. And every CDD, EDD and SDD record, evidence and rationale included, stays on file for at least five years after the relationship ends or the occasional transaction completes.
Filed under: EDD, CDD, SDD, AML compliance, DNFBP, due diligence
Published · Updated


