Insights AML
OFAC Screening UAE 2026: DNFBP Sanctions Checklist
OFAC screening UAE guide for DNFBPs — how to screen against the OFAC SDN list, UN 1267 and the UAE Local Terrorist List, with a 12-point checklist.

Key takeaways
- Three lists matter: OFAC SDN, UN 1267 and the UAE local terrorism list — screening one is not enough.
- Free official portals work for low-volume firms; fuzzy matching and PEP coverage require paid tools.
- Mid-tier vendors (ComplyAdvantage, Sanctions.io, ScreenIT) suit most UAE DNFBPs at sensible cost.
- Adverse media scoring closes the gap between a clean hit and a real-world risk signal.
- PEP screening extends to family members and close associates — not just the named official.
- Retain screening evidence for 5 years under Cabinet Decision 134 of 2025 record-keeping rules.
The OFAC screening UAE DNFBPs run is voluntary in law and unavoidable in practice. UAE rules require screening against the UN Security Council lists and the UAE Local Terrorist List, with freezing without delay. OFAC’s SDN List binds you commercially instead: any dirham-to-dollar settlement clears through a US correspondent bank that enforces it.
Three lists govern sanctions screening for every UAE DNFBP: the OFAC SDN List published by the US Treasury, the UN 1267 consolidated list issued under Security Council resolutions, and the UAE local terrorism list maintained by the Cabinet of Ministers. Screening only one of the three at onboarding, filing the printout, and never looking at the customer again is the single most common gap in UAE DNFBP sanctions screening — and it’s why firms bring us in to advise on AML compliance.
The lists overlap but aren’t interchangeable, the update cadences differ, and a sanctioned counterparty hiding behind a transliteration variant won’t appear on a free portal with no fuzzy logic. Sanctions screening is one of the easiest AML controls to do badly and one of the most expensive to get wrong. Penalty bands under Federal Decree-Law 10 of 2025 start at AED 10,000 per breach and run to AED 5 million for serious or repeated failures.
What OFAC screening UAE firms must document
Before you argue about vendors, get the legal floor straight. The table below carries only obligations we could read this week on a UAE government source, with the source named against each one. Anything a consultant tells you that is not in here should come with its own citation.
| Obligation | What the source actually says | Primary source |
|---|---|---|
| Which lists you screen | Customer databases and transactions are checked against “names listed in the lists issued by the Security Council or the sanctions or local terrorist lists” | Ministry of Economy & Tourism — Targeted Financial Sanctions |
| How often | ”Continuous search in the customer database before performing any operation or entering into a serious business relationship” | Ministry of Economy & Tourism |
| Speed of freezing | Screening immediately on designation, so that freezing measures are applied “without delay (within 24 hours)“ | Executive Office for Control & Non-Proliferation |
| Manner of freezing | Freeze “without delay and without prior notice to the listed person” | Ministry of Economy & Tourism |
| Reporting a true match | Confirmed Name Match Report to the Executive Office and your supervisory authority “through the goAML platform within five business days from taking any freezing measure” | Executive Office for Control & Non-Proliferation |
| Staying current | Reporting entities “are required to register to the Notification Alert System (NAS) on the EOCN’s website” for automated list-update emails | Executive Office for Control & Non-Proliferation |
| Governing law | Federal Decree-Law No. 10 of 2025 on AML/CFT and proliferation financing, which repeals Federal Decree-Law No. 20 of 2018; Executive Regulations in Cabinet Resolution No. 134 of 2025 | UAE Legislation portal |
Last verified: 4 August 2026. Sanctions designations and supervisory guidance change without notice — re-check the Executive Office and your own supervisory authority before you rely on any of it.
Read the table again and notice what is missing: OFAC. There is no row for it because no UAE authority tells you to screen the SDN List. The pressure comes from the payment rail rather than the regulator, which is exactly why so many firms treat it as optional and then discover it is not. If you also handle client onboarding for property or precious-metals counterparties, the VAT registration threshold in the UAE, our corporate tax registration deadline guide and the Ministry of Economy AML inspection playbook cover the rest of the same client file.
Three lists, three different sources
UAE DNFBPs work against a layered sanctions regime. Each list has its own issuing authority, its own legal basis, and its own reach. You need to understand the distinctions before you can design a defensible screening policy.
The OFAC SDN List is maintained by the US Treasury’s Office of Foreign Assets Control. SDN stands for Specially Designated Nationals: individuals, companies, vessels, and aircraft that US persons cannot transact with. Its reach into the UAE is indirect but heavy. Any AED-to-USD conversion routes through a US correspondent bank, and that bank screens every counterparty against OFAC. A DNFBP that processes payments for an SDN-listed customer will lose its USD banking relationship before any UAE regulator gets involved. For real estate brokers, dealers in precious metals and stones (DPMS), and corporate service providers with international clients, OFAC exposure is operational reality even though it isn’t formally a UAE legal requirement.
The UN Security Council 1267 consolidated list is binding under UNSC resolutions 1267 (1999), 1989 (2011) and 2253 (2015). It targets individuals and entities associated with Al-Qaida, ISIL (Da’esh) and the Taliban. The UAE adopts the list through Ministry of Foreign Affairs notifications and circulars from the Executive Office of the Committee for Goods and Materials Subjected to Import and Export Control. Every UAE DNFBP must freeze without delay any funds or assets belonging to a listed person and file an immediate report through goAML — see our goAML registration and login guide for the mechanics.
The UAE Local Terrorist List is issued by the Cabinet of Ministers under Federal Decree-Law 10 of 2025 on Anti-Money Laundering and Countering the Financing of Terrorism and Proliferation. It is distributed through the Executive Office and includes individuals and entities designated by UAE authorities — sometimes in parallel with international designations, sometimes in advance. The local list carries direct domestic enforcement consequences. A DNFBP that fails to freeze listed assets faces both AML penalties under Cabinet Decision 134 of 2025 and potential criminal exposure under the parent decree-law.

Why one feed won’t cover you
The legal floor under Federal Decree-Law 10 of 2025 and Cabinet Decision 134 of 2025 requires screening against the UN consolidated list and the UAE local terrorism list at minimum. OFAC sits above that floor as a commercial necessity rather than a UAE regulatory mandate. For any firm with USD touchpoints the practical effect is the same: your bank will enforce OFAC whether or not the FIU does. Stacking all three sources is the only defensible posture.
The deeper issue is match quality. A free portal returns hits only on exact string matches. Real sanctioned persons routinely show up in transliterated form, with diacritics dropped, with surname-first ordering reversed, or with middle names omitted. “Mohammed” and “Muhammad” and “Mohamed” are the same name; a free OFAC search treats them as three different people. Fuzzy matching algorithms (Jaro-Winkler, Levenshtein distance, phonetic encoders like Soundex or Metaphone) close that gap. They’re standard in paid tools and absent from free ones.
There is a second practical point about who runs the sanctions check and how the result survives. A one-off OFAC lookup performed by whoever happened to be free that morning is not a control, because nobody can reconstruct it six months later. Name the person, name the source, timestamp the result. Firms running PEP and sanctions screening in Dubai under Ministry of Economy and Tourism supervision get asked for precisely that reconstruction during an inspection: show me the UN sanctions list check you ran on this client on this date, and show me what you did with what came back. Sanctions screening tools earn their licence cost here more than anywhere else, because AML screening software archives and timestamps the search on its own, while a browser tab leaves nothing behind.
The third gap is monitoring, and it’s the one firms underestimate most. Sanctions lists aren’t static. OFAC publishes updates weekly, sometimes daily during a sanctions wave; the UN issues amendments through the 1267/1989/2253 Sanctions Committee; the UAE Cabinet adds and removes names on its own cycle. A one-time onboarding screen only captures a snapshot. Rescreening the customer file every time a list updates is what captures the moving picture, and the Ministry of Economy and Tourism’s DNFBP supervisory framework expects exactly that, proportionate to risk.
How we’d pick a screening tool tier for an SME
Tool choice should follow your actual risk profile, transaction volume and budget rather than which vendor name you recognise. Three tiers cover most of the UAE DNFBP market.
Free official sources. The OFAC SDN Search portal (sanctionssearch.ofac.treas.gov) returns exact-match results against the SDN, consolidated and sectoral lists. The UN 1267 consolidated list is published as XML and PDF on the Security Council Sanctions Committee site. The UAE Cabinet list is distributed by the Executive Office to registered entities. They’re free, authoritative and straight from the primary source, which is the whole appeal. What they don’t give you is fuzzy matching, PEP coverage, adverse media, an API or any kind of rescreening — everything runs by hand. That’s fine only for the lowest-volume DNFBPs with simple domestic counterparty profiles and the discipline to document every search.
Mid-tier paid tools. ComplyAdvantage, Sanctions.io and ScreenIT price on a subscription basis that scales with screening volume, entity count and how many feeds you switch on — request a quote from each vendor against your actual counterparty numbers rather than budgeting off a published rate card. They aggregate sanctions, PEP and adverse media feeds, support fuzzy matching, expose REST APIs for integration with practice management or CRM systems, and provide audit trails. ComplyAdvantage is the most widely adopted across the GCC mid-market. Sanctions.io offers a lower entry point and a simpler pricing structure for small firms. ScreenIT is a regional player with local support. Suitable for most UAE DNFBPs handling more than a handful of new counterparties a month, and for any firm with international or higher-risk client profiles.
Enterprise tier. World-Check One (LSEG Risk Intelligence, formerly Refinitiv), Dow Jones Risk & Compliance, and LexisNexis Bridger Insight occupy the top end. Annual licences scale by user count, module selection and beneficial-owner volume, and each vendor prices the deployment individually — ask for a scoped quote rather than a list price. They offer the deepest PEP and RCA coverage, the broadest adverse media corpus, enhanced due diligence reports on demand, and integration with case management workflows. Suitable for Big Four-tier audit firms, top-25 law firms, corporate service providers managing thousands of beneficial owners and any DNFBP under regulatory remediation orders.
Scoring adverse media properly
Adverse media (negative news linking a counterparty to financial crime, corruption, sanctions evasion, fraud or terrorism) is the connective tissue between a sanctions list and a real risk picture. A counterparty may not yet appear on any official list but still feature prominently in credible investigative reporting. UAE FIU expectations, communicated through goAML guidance and Ministry of Economy and Tourism supervisory notes, have moved toward structured adverse media review at onboarding and at each periodic refresh.
Scoring adverse media needs a weighting framework. Start with source credibility — a Reuters, Financial Times, OCCRP or ICIJ investigation carries far more weight than an anonymous blog. Layer on jurisdiction risk, because adverse media on a counterparty operating in a country near the bottom of Transparency International’s Corruption Perceptions Index should raise your priors before you read a word of it. Then look at the transactional pattern: the same adverse media report means something different when it sits next to cash-intensive transactions, complex ownership chains or rapid fund movement, and at that point it should trigger enhanced due diligence rather than a comment in the file.
Document the negative outcomes too. When you review adverse media and discount it (wrong person, dated coverage, civil dispute rather than criminal conduct), the rationale must be in the file. Regulators don’t penalise firms for finding nothing. They penalise firms for not looking.
AED 10K–5M
Administrative fine per violation that a Supervisory Authority may impose under Article 17(1)(b) of Federal Decree-Law No. 10 of 2025; Article 17(3) allows an incremental fine where the same violation repeats within a year
Two numbers get mixed up here constantly, so keep them apart. The AED 10,000–5,000,000 band above is the administrative fine a Supervisory Authority — the Ministry of Economy and Tourism for most DNFBPs, the Ministry of Justice for lawyers and notaries — may impose for breaching the Decree-Law or its Executive Regulations. That is a compliance failure, judged administratively, with a grievance route attached.
Article 27(1) is a different instrument entirely: a criminal court fine on a legal person convicted of money laundering, terrorist financing or proliferation financing committed on its behalf, running from AED 5,000,000 to AED 100,000,000 or the value of the criminal property involved, whichever is greater. The AED 100 million is not the ceiling people quote it as — and a firm that simply failed to run a screen is not facing that article at all.
Within the administrative track, Cabinet Resolution No. 71 of 2024 carries the itemised schedule for DNFBPs supervised by those two ministries: 41 numbered violations, each with its own band. Cite the item number rather than the article number. The annex cross-references Cabinet Decision 10 of 2019, which Article 70 of Cabinet Resolution 134 of 2025 repealed, so the article references inside it are now stale even though the schedule itself remains listed as in force on the Ministry of Economy and Tourism’s financial-crimes legislation page, checked 5 August 2026.
PEPs, RCAs and the family-member trap
Politically exposed persons (PEPs) carry inherently elevated money laundering risk because of their access to public funds, their ability to influence procurement and licensing, and their exposure to bribery and corruption. UAE rules under Cabinet Decision 134 of 2025 distinguish three PEP categories. Foreign PEPs — heads of state, ministers, senior judges, military officers and senior executives of state-owned enterprises in jurisdictions other than the UAE — are automatically higher-risk and require enhanced due diligence by default. Domestic PEPs — UAE officials in equivalent roles — require EDD where the relationship presents higher risk. International organisation PEPs — directors and senior officers of UN bodies, the IMF, the World Bank, the OECD and similar — sit alongside domestic PEPs on the risk-based test.
The obligation extends beyond the named PEP. Family members — spouse, parents, children, siblings — and known close associates (referred to as RCAs in screening tools) are treated as PEP-adjacent and screened on the same basis. Business partners, joint shareholders and trustees of structures controlled by a PEP all fall into the RCA net.
Enhanced due diligence for a PEP relationship requires senior management sign-off before onboarding or continuation, source-of-funds documentation, source-of-wealth narrative supported by independent evidence, more frequent ongoing review (typically annually rather than triennially), and explicit transaction monitoring thresholds. The PEP register is a living document — update it at every periodic review and capture the rationale for any change in PEP status or risk rating.

The DNFBP categories and where each one screens
Federal Decree-Law 10 of 2025 does not itself list the DNFBP categories — Article 1 defers to the Executive Regulations, and it is Article 3 of Cabinet Decision 134 of 2025 that sets them out. That article names five heads plus a catch-all for any further business the Supervisory Authority designates: commercial gaming operators (at or above AED 11,000 for a single or linked transaction); real estate brokers and agents; dealers in valuable metals and precious stones (at or above AED 55,000 for a single or linked cash transaction); lawyers, notaries, other independent legal professionals and independent accountants; and company and trust service providers.
Two points about that wording matter in practice. The professional heads are activity-gated, not status-gated — an accountant or a lawyer falls in scope when preparing, conducting or executing the specified transaction types (buying and selling real estate, managing client funds or accounts, organising contributions to form companies, forming or selling corporate entities), not merely by holding the qualification. And the statutory term is “independent accountants” rather than “auditors”, though the Ministry of Economy and Tourism’s own goAML registration material addresses auditing and accounting firms directly, so the profession is treated as in scope in practice. Where your work falls under the accountancy or legal heads, the operational breakdown below is how the screening actually lands.
- Real estate brokers and agents — screen every buyer, seller, landlord and tenant at onboarding; rescreen at contract signature and at funds receipt. Cross-border purchasers and cash-equivalent settlements raise the priority. Our real estate accounting in UAE briefing covers the broader compliance picture.
- Dealers in precious metals and stones (DPMS) — screen every counterparty for any single or linked transaction at or above the AED 55,000 threshold; for high-value clients and recurring suppliers, screen at onboarding and quarterly. See our gold and jewellery accounting in UAE guide for the DPMS context.
- Auditors — screen audit clients, beneficial owners and significant suppliers visible in the books; rescreen on engagement renewal and on material ownership changes.
- Accountants and bookkeepers — screen new clients, their beneficial owners and any counterparty appearing in payment files where the firm has visibility; rescreen on engagement renewal.
- Tax consultants — screen advisory clients, beneficial owners and structuring counterparties; rescreen on assignment of new work involving cross-border flows. If you are appointing one rather than acting as one, our buyer’s guide to tax consultants in Abu Dhabi covers the credential checks that matter.
- Lawyers, notaries and other independent legal professionals — screen clients, beneficial owners of corporate clients, and counterparties to transactions where the firm acts on a client’s behalf for property transfer, company formation, trust administration or asset management.
- Corporate service providers — screen at company formation, on every shareholder change, on every director appointment, and on registered agent renewal.
The DNFBPs that survive a Ministry of Economy and Tourism inspection are not the ones with the most expensive tool — they are the ones whose screening logs, escalation memos and STR rationales tell a coherent story.
The 12-point screening checklist
The following twelve-point checklist captures what a defensible UAE DNFBP sanctions screening programme looks like in practice. Treat it as a baseline; layer additional controls where the risk profile demands.
- Onboarding screen — every new customer, beneficial owner (25%+ ownership or control), and authorised signatory screened against OFAC SDN, UN 1267 and the UAE local list before contract signature or fee receipt.
- Ongoing rescreening cadence — automated daily or weekly for paid tool users; documented monthly manual review for free-portal users. Capture the rescreen date and result for every counterparty.
- List source URLs in the policy — name the exact source (sanctionssearch.ofac.treas.gov, scsanctions.un.org/consolidated, Executive Office circulars) so any inspector can verify the source.
- Fuzzy matching tolerance — document the tool’s matching threshold (typically 80–90%) and the protocol for reviewing borderline hits.
- PEP register — separate register for PEPs and RCAs with status, risk rating, senior management approval date and next review date.
- Adverse media protocol — defined sources, scoring framework and disposition recorded for every counterparty flagged.
- Hit escalation path — first-line review by the analyst, second-line review by the compliance officer, escalation to senior management for confirmed true positives.
- STR trigger thresholds — clear criteria for filing a Suspicious Transaction Report through goAML; document the rationale even where no STR is filed.
- Freeze and report protocol — written procedure for immediate freeze of funds belonging to a listed person and immediate report to the FIU.
- Record retention 5 years — all screening evidence, hit reviews, EDD files and STR filings retained for at least five years from the end of the business relationship or the date of the occasional transaction.
- Annual policy review — sanctions and PEP screening policy reviewed and approved by senior management at least annually, and following any material regulatory change.
- Training register — every staff member with screening responsibility receives initial and annual refresher training; attendance and content logged.
What one screening record has to contain
A UAE inspection does not test whether you own a screening tool. It tests whether you can reproduce a specific search on a specific counterparty on a specific date, and show what you did with the result. That reproduction is the whole control, and it lives or dies on what each record captures.
| Field in the record | Why an inspector asks for it |
|---|---|
| Counterparty name exactly as searched | Shows what was actually run, not what you meant to run |
| Transliteration variants tried | A single Latin spelling of an Arabic name is one search, not a screen |
| Each source named separately | UN, UAE local list and OFAC are three checks; one line saying “screened” evidences none of them |
| Date and time | Ties the search to a list version and to the point in the relationship |
| Fuzzy-match threshold applied | Lets the inspector judge whether a near-miss would have surfaced |
| Result, in the tool’s own words | Distinguishes no match, potential match and confirmed match |
| Who ran it, by name | Makes it a control rather than a task somebody happened to do |
| Disposition and approver | Records the judgement, which is the part regulators actually test |
| Storage location and retention date | Proves the evidence still exists when it is asked for |
The gap that turns up most often in UAE DNFBP files is the second row. A firm in Dubai screens “Mohammed Al Rashid”, finds nothing, files the printout, and never records that it did not also try Mohamed, Muhammad or a surname-first ordering. The screen looks complete on paper and covered one spelling in practice.
The second most common gap is the last row. Records held only in a departed employee’s mailbox, or in a trial account of a tool the firm no longer licenses, are records the firm cannot produce. That matters everywhere, but it matters most for the smaller DNFBPs — the single-office practices across Dubai, Abu Dhabi and Sharjah that run screening off free portals and store the evidence wherever seemed sensible at the time. Free portals are a defensible choice for a genuinely low-volume UAE firm. Storing their output in someone’s downloads folder is not, and the AED cost of fixing that is essentially nil compared with the penalty bands above.
How Velmont Crest helps
Velmont Crest works alongside DNFBP compliance officers and senior management as an advisory partner. We help firms evaluate sanctions and PEP tool vendors against actual risk profile and transaction volume: a vendor scorecard, structured demos, fuzzy-match thresholds validated against your real counterparty population. We help draft the sanctions screening policy, the PEP policy, and the adverse media protocol so they meet Cabinet Decision 134 of 2025 expectations and your supervisor’s published guidance.
We support the bookkeeping and reconciliation layer underneath (see our accounting and bookkeeping services) so the customer master in the ledger and the customer master in the screening tool stay in sync. Where corporate tax registration and screening intersect for high-net-worth or international clients, our corporate tax services team coordinates the workstreams. We don’t act as your compliance officer of record. The compliance officer role, the freeze decision and the STR filing stay with your designated person and senior management. That’s the regulator’s expectation and ours.
What we deliver is the documentation, the audit trail, and the training that lets your compliance officer do the job without surprises during a supervisory inspection.
FAQs
These are the questions DNFBPs put to us most often when they sit down and stress-test their own screening programme against where the Ministry of Economy and Tourism and the FIU are now.
The pattern holds across the country. An accounting practice in Dubai, a real estate brokerage in Abu Dhabi, a precious-metals dealer in Sharjah and a corporate service provider in Ajman all sit under the same UAE federal framework, even where the supervisory authority that inspects them differs — so the questions below arrive in the same form wherever in the UAE the firm is licensed. What changes by emirate is who knocks on the door, not what they expect to find behind it. The UAE firms that come unstuck are usually the ones treating screening as a head-office policy rather than a per-office habit, and discovering mid-inspection that one branch has quietly been doing it its own way.
Sanctions screening is one of those areas where a small process gap sits harmlessly for months and then turns existential the day it matters. The lists move weekly, the tools vary wildly, and the regulator now expects continuous monitoring and documented adverse media review — not a one-time onboarding printout filed and forgotten. If you’d like us to review your current setup, benchmark your tool against the alternatives, or draft a defensible policy aligned to Cabinet Decision 134 of 2025, our AML compliance advisory service is the place to start.
Frequently asked questions
- What is the difference between the OFAC SDN list, UN 1267 and the UAE local sanctions list?
- They come from different authorities and reach different things. The OFAC SDN List comes from the US Treasury's Office of Foreign Assets Control and captures Specially Designated Nationals — the individuals, entities and vessels US persons can't deal with. UN 1267 is the consolidated list under Security Council resolutions 1267, 1989 and 2253, aimed at Al-Qaida and ISIL affiliates, and it binds every UN member state. The UAE local terrorism list is issued by the Cabinet of Ministers, circulated through the Executive Office, and carries domestic enforcement weight under Federal Decree-Law 10 of 2025. They overlap a lot in practice, but they're not the same list and they don't update on the same clock.
- Do UAE DNFBPs need to screen against all three lists?
- Legally, two of them. Federal Decree-Law 10 of 2025 and Cabinet Decision 134 of 2025 require screening against the UN consolidated list and the UAE local terrorism list at minimum. OFAC isn't a UAE regulatory requirement on its face. But the moment you touch USD correspondent banking, US-domiciled clients or US dollar settlement, OFAC becomes a commercial necessity — the correspondent bank will walk at the first sign of a sanctioned counterparty, and it won't wait for the FIU. So in practice nearly every UAE DNFBP screens all three anyway, and the policy just needs to spell out each source, how often it's checked, and what happens when a name comes back.
- Which sanctions screening tools do UAE firms actually use?
- It splits roughly by size. Smaller DNFBPs lean on the free official portals — the OFAC SDN Search at sanctionssearch.ofac.treas.gov, the UN 1267 consolidated list, and the UAE Cabinet list circulated by the Executive Office. They work, but there's no fuzzy match, no PEP coverage, no adverse media. Mid-market firms graduate to ComplyAdvantage, Sanctions.io or ScreenIT for API access, fuzzy matching and integrated PEP feeds. At the top end — big auditors, top-tier law firms, corporate service providers sitting on thousands of beneficial owners — you'll find World-Check (Refinitiv), Dow Jones Risk & Compliance or LexisNexis Bridger. The tool should track your risk, not your letterhead.
- How does adverse media screening fit into the AML programme?
- Adverse media — negative news tying a counterparty to financial crime, fraud, corruption or sanctions evasion — fills the gap between a clean sanctions hit and a real risk picture. Someone can be off every official list and still be all over credible investigative reporting. UAE FIU expectations have shifted toward structured adverse media checks at onboarding and at each periodic review. Score what you find by source credibility, recency, jurisdiction risk (the Transparency International CPI is a useful cross-reference) and relevance to the actual transactions. And here's the part firms keep getting wrong: write down why the adverse media did or didn't trigger enhanced due diligence. Regulators flag the missing documentation, not the judgement call.
- What does DNFBP mean?
- DNFBP stands for Designated Non-Financial Business or Profession — the FATF term the UAE uses for businesses outside banking that handle enough client money, property or corporate structure to attract launderers. The governing list is Article 3 of Cabinet Decision 134/2025: commercial gaming operators; real estate brokers and agents; dealers in valuable metals and precious stones; lawyers, notaries, other independent legal professionals and independent accountants; and company and trust service providers. Those heads are activity-gated: an accountant or lawyer is caught when executing the specified transactions, not by holding the qualification. In scope, the obligation set is goAML registration, a compliance officer, CDD, sanctions and PEP screening, and retention.
- What is a politically exposed person?
- A politically exposed person, usually shortened to PEP, is someone entrusted with a prominent public function. That covers heads of state and government, ministers, senior judges, senior military and police officers, senior political party officials and senior executives of state-owned enterprises. The definition turns on the role, not on any suggestion of wrongdoing. The reason it matters is that the position brings access to public funds and influence over licensing and procurement, which raises the laundering risk attached to the relationship. Once someone is identified as a PEP, immediate family members and known close associates are screened on the same basis.
- Which countries does OFAC sanction?
- OFAC runs both comprehensive country programmes and narrower targeted ones, and the set shifts as US foreign policy shifts, so any country list written into your policy will be stale within a year. Point the policy at the source instead — the sanctions programmes page on the US Treasury OFAC website — and check it at every policy review. The practical implication for a UAE DNFBP is that country risk and name risk are two separate screens. A counterparty can come back clean on the SDN list and still sit in a jurisdiction your correspondent bank will not settle US dollars for. Screen the name, then check the jurisdiction.
- Is OFAC screening mandatory in the UAE?
- Not as a matter of UAE law. What UAE law mandates is screening against the United Nations Security Council lists and the UAE Local Terrorist List, and freezing matched funds without delay and without notifying the listed person — the Ministry of Economy and Tourism sets that out in its targeted financial sanctions guidance, and the Executive Office for Control and Non-Proliferation puts the freezing window at 24 hours. OFAC screening UAE firms run sits on top of that floor for a commercial reason rather than a legal one: dirham-to-dollar settlement clears through a US correspondent bank, and that bank enforces the SDN List on its own account. In practice almost every DNFBP with dollar exposure screens all three sources.
- How quickly must a UAE DNFBP freeze and report a sanctions match?
- The Executive Office for Control and Non-Proliferation states that screening must be carried out immediately after a designation so that freezing measures are applied without delay, which it defines as within 24 hours. Once you have frozen, you submit a Confirmed Name Match Report through the goAML platform to the Executive Office and to your supervisory authority within five business days of taking the freezing measure. The Ministry of Economy and Tourism adds that the freeze happens without prior notice to the listed person. Registering for the Executive Office's Notification Alert System is what gets you the designation email in the first place.
- What are UAE DNFBP obligations for PEP screening?
- It depends which kind of PEP you're dealing with. UAE rules treat foreign PEPs as automatically higher-risk, so enhanced due diligence is the default there; domestic PEPs (UAE officials) and international organisation PEPs only need EDD where the relationship itself is higher-risk. The obligation doesn't stop at the named person either. It reaches family members and known close associates — spouses, parents, children, siblings, business partners — who screen on the same basis. Source-of-funds and source-of-wealth checks become mandatory, and you need senior management sign-off to onboard or keep a PEP. Re-screen the register at least every 12 months, and write down why any risk rating changed.
Filed under: OFAC, AML compliance, DNFBP, sanctions screening, UN 1267, PEP
Published · Updated



