Customer due diligence is the cornerstone of every AML compliance programme. The obligation to know your customer, to understand who they are, where their money comes from, and what they intend to do with it, is embedded in UAE law, FATF Recommendations and every regulator’s rulebook.
But CDD is not a single standard. The UAE framework distinguishes between standard customer due diligence, which applies to all customers by default, and enhanced due diligence, which applies when risk factors are present that demand a deeper level of scrutiny. Getting the distinction right, knowing when standard CDD is sufficient and when EDD is legally required, is one of the most common areas of practical difficulty for compliance teams.
This guide explains both standards in full: what each requires, when each is triggered, what documents are acceptable under UAE law and regulatory guidance, and how to handle the two concepts that trip up even experienced practitioners: source of funds versus source of wealth.
1. What Is Customer Due Diligence (CDD)? Definition & UAE Context
Customer due diligence, also referred to as client due diligence or KYC (know your customer), is the process by which a regulated entity identifies its customers, verifies that identity using reliable documentation, and develops an understanding of the nature and purpose of the business relationship.
Under Federal Decree-Law No. 20 of 2018 and its implementing Cabinet Decision No. 10 of 2019, all financial institutions and DNFBPs are required to apply CDD measures when:
Establishing a business relationship with a new customer
Conducting an occasional transaction of AED 55,000 or more (or equivalent in foreign currency)
There is a suspicion of money laundering or terrorist financing, regardless of transaction value
There are doubts about the veracity or adequacy of previously obtained customer identification data
Conducting wire transfers of any amount
The objective of CDD is to ensure that the firm knows enough about its customer to assess the risk they pose, monitor their activity against that profile, and identify transactions that are inconsistent with what has been declared. CDD is not a one-time event at onboarding, it is an ongoing obligation that continues for the life of the relationship.
CDD meaning in UAE law: the term “customer due diligence” in Cabinet Decision No. 10 of 2019 encompasses identification, verification, understanding of the business relationship, identification of the beneficial owner, and ongoing monitoring. All five elements are required. |
2. CDD vs EDD: When Each Applies
The relationship between standard CDD and enhanced due diligence is a sliding scale, not a binary choice. The UAE AML framework adopts a risk-based approach, which means the depth of due diligence applied must be proportionate to the risk presented by the customer, the transaction, the product and the jurisdiction.
Standard CDD | Enhanced Due Diligence (EDD) | |
Risk level | Low to medium risk customers | High risk customers, PEPs, complex structures, high-risk jurisdictions |
When triggered | Default: all new customers and relationships | Automatically where EDD triggers are met; risk-based otherwise |
Identity verification | Standard documents (Emirates ID, passport) | Same + additional verification measures where identity risk is elevated |
Beneficial ownership | Identify and verify UBO to 25% threshold | Identify and verify UBO + verify control chain; lower thresholds may apply |
Source of funds | Understand expected nature of transactions | Document and verify source of funds for specific transactions |
Source of wealth | Not required as standard | Required: must be documented and verified for PEPs and high-risk clients |
Proof of address | One acceptable document | Two independent documents; bank statements preferred |
Ongoing monitoring | Periodic review aligned to risk rating | More frequent reviews; enhanced transaction monitoring thresholds |
Senior management approval | Not required | Required before establishing or continuing the relationship |
Regulatory basis (UAE) | Federal Decree-Law 20/2018 + Cabinet Decision 10/2019 | Cabinet Decision 10/2019 Arts. 4–7; CBUAE/DFSA/FSRA guidance |
One common misconception is that EDD is only required for PEPs. In practice, EDD is required wherever the firm’s risk assessment identifies elevated risk, whether because of the customer’s profile, the country they operate in, the complexity of their corporate structure, the nature of the product or service being used, or the transaction patterns observed. PEPs are an automatic EDD trigger, but they are not the only one.
3. Standard CDD Requirements Under UAE AML Law
Standard CDD covers four core elements that must be completed before a business relationship is established or a significant occasional transaction is executed.
Element 1: Customer Identification
The firm must identify the customer using reliable, independent source data. For individuals, this means obtaining full legal name, date of birth, nationality, residential address and a government-issued photo ID. For legal entities, it means obtaining the entity’s legal name, registration number, registered address, legal form and jurisdiction of incorporation.
Element 2: Identity Verification
Identification must be verified against reliable documents, data or information. The UAE standard for verification is that the information provided by the customer is cross-referenced against original or certified copies of documents that a reasonable person would consider reliable, typically government-issued IDs, official registries and regulated financial institution records.
For UAE residents, the Emirates ID is the primary verification document and is cross-referenceable against the ICP (Federal Authority for Identity, Citizenship, Customs and Port Security) database. For foreign nationals and non-residents, a valid passport is the primary document.
Element 3: Beneficial Ownership
Where the customer is a legal entity or arrangement, the firm must identify and take reasonable measures to verify the identity of the ultimate beneficial owner: the natural person(s) who ultimately own or control the entity. Cabinet Decision No. 10 of 2019 defines the UBO threshold as 25% ownership or control. Firms may apply a lower threshold where their risk assessment indicates this is appropriate.
Where no natural person can be identified at or above the threshold, the firm must identify the natural person(s) who exercise control through other means, including through a chain of ownership, through voting rights, or through senior management authority.
Element 4: Purpose and Nature of the Relationship
The firm must understand why the customer is opening the relationship, what products or services they intend to use, what volume and type of transactions are expected, and, at a high level, the nature of the customer’s business or source of income. This information forms the baseline against which future transaction monitoring is conducted.
4. Enhanced Due Diligence (EDD) Triggers: PEPs, High-Risk Countries, Complex Structures
UAE law and regulatory guidance specify a number of circumstances in which enhanced due diligence is mandatory rather than discretionary. The most significant are:
Politically Exposed Persons (PEPs)
A PEP is an individual who holds, or has held within the preceding twelve months, a prominent public function, including heads of state, senior government officials, senior politicians, senior executives of state-owned enterprises, senior military officers, members of the judiciary, and senior officials of international organisations. Family members and close associates of PEPs are treated as PEPs for AML purposes.
EDD for PEPs requires: senior management approval before establishing or continuing the relationship; reasonable measures to establish the source of wealth and source of funds; and enhanced ongoing monitoring of the relationship and transactions.
High-Risk Countries
Customers who are nationals of, resident in, or whose funds originate from, jurisdictions identified as high-risk require EDD. The UAE applies the FATF’s lists of jurisdictions subject to increased monitoring or a call for action, supplemented by the UAE Cabinet’s own list of high-risk states. Firms must maintain current versions of both lists and screen customers against them at onboarding and on an ongoing basis.
Complex or Opaque Corporate Structures
Where a customer uses a complex corporate structure, such as multiple holding layers, offshore jurisdictions, nominee arrangements, trusts or foundations, without an apparent legitimate commercial rationale, EDD is required. The firm must understand the structure, verify the UBO at each level, and satisfy itself that the structure is not designed to obscure the identity of the beneficial owner.
Other EDD Triggers
Correspondent banking relationships: EDD is mandatory for all new correspondent banking relationships, including assessment of the respondent institution’s AML controls and prohibition on shell bank relationships
Non-face-to-face customers: where the customer relationship is established without physical presence, additional verification measures are required to compensate for the increased identity risk
High-value or high-risk transactions: large or unusual transactions that are inconsistent with the customer’s profile or that involve unusual payment methods or counterparties
Customers in high-risk DNFBP sectors: real estate buyers using corporate vehicles, gold dealers conducting large cash transactions, and VASP-related flows
⚠️ Common EDD Failures Identified in UAE Regulatory Inspections • Treating PEP status as a box-ticking exercise: screening customers against PEP lists but failing to conduct source of wealth analysis or obtain senior management approval • Accepting self-declarations of source of funds without corroborating documentary evidence • Failing to apply EDD to the UBOs of corporate customers, even where the entity itself does not appear high-risk • Not updating EDD when a customer’s risk rating changes mid-relationship, for example, when a customer becomes a PEP or moves funds from a newly designated high-risk jurisdiction • Approving EDD cases at a level below the required seniority, or without genuinely reviewing the underlying risk assessment |
5. Source of Funds vs Source of Wealth: How to Document
Source of funds and source of wealth are related but distinct concepts. Confusing them, or treating them as interchangeable, is one of the most common EDD errors in practice. The table below sets out the key differences:
Source of Funds (SoF) | Source of Wealth (SoW) | |
Definition | Origin of the specific funds used in a particular transaction or relationship | How the customer accumulated their total net worth over time |
Question it answers | Where did this money come from? | How did this person become wealthy? |
When required | All EDD cases; high-value cash transactions; real estate purchases | PEPs; private banking clients; high-risk high-net-worth customers |
Acceptable evidence | Bank statement showing fund receipt; sale proceeds; payslips; dividend records; loan agreements | Tax returns; business ownership documents; inheritance records; property sale agreements; audited financial statements |
Verification approach | Documentary: match the stated source to a verifiable transaction | Documentary + intelligence: cross-reference stated wealth against open-source data, corporate records, adverse media |
UAE regulatory basis | Cabinet Decision 10/2019; CBUAE and DFSA guidance on EDD | DFSA AML Module; CBUAE Private Banking guidelines; FATF Guidance on PEPs |
Practical Guidance on Documentation
For source of funds, the standard is documentary: the firm should be able to trace the specific funds used in a transaction back to an identifiable, legitimate origin. A customer who says the funds come from the sale of a property should be able to provide a sale and purchase agreement, a transfer receipt or a bank statement showing the sale proceeds being received.
For source of wealth, the standard is both documentary and analytical. The firm must not only collect documents showing how the customer built their wealth but must assess whether those documents are consistent with the customer’s profile, background, stated profession and publicly available information.
A source of funds declaration form completed by the customer is a starting point, not an endpoint. The obligation is to verify the declared source, not merely to obtain a declaration. Regulators have found repeatedly that firms accept unverified declarations as satisfying their EDD obligations, when in fact the obligation is to verify. |
6. Proof of Address Requirements in UAE
Proof of address (PoA) is a CDD requirement for all individual customers. The purpose is to verify that the customer resides where they claim to reside, which in turn affects their risk rating, applicable sanctions screening and regulatory obligations. In the UAE, proof of address requirements is particularly nuanced given the high proportion of expatriate residents and non-resident investors.
Acceptable Proof of Address Documents in UAE
DEWA (Dubai Electricity and Water Authority) bill – widely accepted as a primary PoA document for Dubai residents
SEWA (Sharjah Electricity and Water Authority) or ADDC/AADC utility bills – equivalent for Sharjah and Abu Dhabi residents
Ejari tenancy contract registration – accepted as proof of residential address in Dubai
UAE bank statement showing the customer’s name and residential address – must be dated within three months
Official government correspondence addressed to the customer at their residential address
UAE driving licence (where issued with a residential address)
Proof of Address for Non-Residents and Foreign Nationals
For non-UAE-resident customers, proof of address must be sourced from their country of residence. Acceptable documents follow the same principles: utility bills, bank statements or official government correspondence, all dated within three months. For customers resident in high-risk countries or jurisdictions with elevated document fraud risk, firms typically require documents to be notarised, apostilled or certified by a regulated professional.
For EDD cases, a single proof of address document is generally insufficient. Best practice is to obtain two independent documents from different sources, with at least one being a bank statement or regulated financial institution record.
7. Customer Identification Procedures (Individuals & Entities)
The documents required for customer identification differ between natural persons and legal entities. The tables below set out the standard requirements under the UAE framework, with EDD additions noted.
Individuals
Document Type | UAE Residents | Non-Residents / Foreign Nationals |
Primary ID | Emirates ID (mandatory for UAE residents) | Valid passport (biographic page) |
Secondary ID | Passport (if non-GCC national) | National ID card (where issued) |
Proof of address | Utility bill, DEWA/SEWA statement, Ejari tenancy contract, bank statement (all ≤ 3 months) | Bank statement, utility bill, official correspondence (≤ 3 months); notarised if from high-risk country |
Visa / residency | UAE residence visa page | Entry visa; business visa; tourist visa where relevant |
Additional (EDD) | Source of funds declaration + supporting evidence | Source of wealth documentation; enhanced background screening |
Legal Entities and Corporate Structures
Requirement | Documents / Information |
Legal existence | Certificate of incorporation or equivalent; commercial licence; memorandum and articles of association |
Registered address | Certificate of incorporation showing registered address; official company search or registry extract |
Ownership structure | Share register; ownership chart showing all legal persons in the chain to the UBO level |
UBO identification | Full legal name, date of birth, nationality and residential address of all natural persons owning or controlling ≥25% (or lower where firm applies a lower threshold) |
UBO verification | Certified copy of passport or national ID for each UBO; EDD may require additional evidence |
Authorised signatories | Board resolution authorising the relationship; specimen signatures; ID of all authorised signatories |
Nature of business | Business description; website; financial statements or management accounts; sector licensing |
EDD additions | Beneficial ownership register extract (where jurisdiction requires); legal opinion on structure (complex cases); source of wealth of UBOs |
For entities incorporated in jurisdictions without public beneficial ownership registers, or in jurisdictions identified as high-risk, the verification standard is higher: firms must take additional steps to satisfy themselves of the accuracy of the UBO information provided, which may include legal opinions, corporate registry searches and third-party intelligence databases.
8. Ongoing Monitoring: The Often-Forgotten CDD Pillar
CDD is not completed at onboarding. Under UAE law and all applicable regulator frameworks, the obligation to know your customer continues for the entire duration of the business relationship. Ongoing monitoring has two components: transaction monitoring and periodic review.
Transaction Monitoring
Firms must monitor customer transactions on an ongoing basis to ensure they are consistent with the firm’s knowledge of the customer, the customer’s stated business and risk profile, and the nature of the relationship. Transactions that are inconsistent with the customer’s profile must be flagged, reviewed and, where appropriate, reported.
Transaction monitoring can be automated (through systems that apply rules or models to flag anomalous activity) or manual (through relationship manager review). For high-risk customers, the monitoring thresholds and review frequency should be enhanced relative to low-risk customers.
Periodic CDD Review
Customer files must be reviewed periodically to ensure the information held remains accurate and up to date. The frequency of review should be determined by the customer’s risk rating:
High-risk customers (including PEPs and EDD cases): annual review as a minimum; more frequent where transaction patterns change
Medium-risk customers: review every two to three years, or when triggered by changes in the relationship
Low-risk customers: review every three to five years, or when triggered
Trigger events that should prompt an immediate out-of-cycle review include: a change in the customer’s UBO; the customer becoming a PEP; a significant change in transaction volumes or patterns; adverse media coverage; or a change in the customer’s business activity or jurisdiction.
✓ CDD & EDD Programme Checklist for UAE Firms ✔ CDD policy documented, risk-based and aligned to Federal Decree-Law 20/2018 and Cabinet Decision 10/2019 ✔ Customer risk rating methodology defined and applied consistently at onboarding ✔ PEP screening conducted at onboarding using an up-to-date commercial screening tool ✔ FATF and UAE Cabinet high-risk country lists maintained and applied ✔ UBO identification and verification completed for all corporate customers ✔ EDD triggers documented and EDD checklists applied consistently where triggered ✔ Source of funds verified (not merely declared) for all EDD cases ✔ Source of wealth documented and assessed for PEPs and private banking clients ✔ Proof of address obtained from all individual customers ✔ Senior management approval obtained and documented before establishing EDD relationships ✔ Transaction monitoring rules calibrated to customer risk profiles ✔ Periodic CDD review schedule established and tracked by risk rating ✔ Trigger-event CDD review process defined and operationalised |
B-AML helps regulated businesses and DNFBPs across the UAE design, implement and audit CDD and EDD frameworks that meet regulatory requirements, from policy development and document checklists to EDD file reviews and transaction monitoring calibration. |



