A trading company based in the Gulf region is negotiating a distribution agreement with a European supplier. The counterparty appears clean on an initial screen. A second-layer review surfaces a minority shareholder with links to a listed entity. The question is not academic: does this counterparty fall within the prohibition? Under which regime? And does the answer change depending on whether the European supplier, its US-dollar clearing bank, or its freight forwarder is asking?
Counterparty due diligence under the UAE regime requires screening against the UAE's own domestic list and the UN Security Council Consolidated List, both of which the UAE has domestically implemented. The ownership-and-control test under the applicable UAE instruments differs from the mechanical 50 percent or more aggregate ownership rule applied by OFAC, and differs again from the EU's ownership-and-control analysis. Where a transaction touches the United States or the European Union simultaneously, the stricter prohibition governs – and that is almost always the US or EU standard, not solely the UAE domestic one.
This analysis sets out how the UAE counterparty due diligence regime works, where it diverges from OFAC, OFSI, and the EU, and what a cross-border business should do before it signs.
What legal authority governs counterparty due diligence in the UAE?
The UAE administers its sanctions and counterparty-screening obligations through a layered set of domestic instruments, the primary executive authority being the Executive Office for Control and Non-Proliferation and the UAE Cabinet. The UAE implements UN Security Council resolutions as a matter of domestic law, which means the UN Consolidated List is a hard legal obligation for any person or entity operating within the jurisdiction, not merely a voluntary compliance reference. Beyond the UN list, the UAE maintains its own Local Terrorist List and its own mechanisms for designating parties at the national level.
Regulated financial institutions in the UAE operate under licensing conditions set by the Central Bank of the UAE and the relevant free-zone financial regulators, including the DFSA in the DIFC and the FSRA in ADGM. Those regulators have issued customer due-diligence and sanctions-screening requirements that, in practice, exceed the minimum statutory obligations and approach the depth of the screening programmes required by OFSI and the major EU supervisors. Non-financial businesses – trading houses, distributors, logistics providers – are subject to the same UN-list obligations but face less granular regulatory guidance on methodology, which creates divergence in practice between the financial sector and the commercial sector.
One point practitioners must understand at the outset: the UAE does not operate a unified published sanctions list of the kind that OFAC publishes in its SDN List (OFAC's list of Specially Designated Nationals and blocked persons). The UAE's domestic designations are published in Cabinet resolutions and gazette notices, which require active monitoring to track. In our cross-border practice, this administrative difference is where non-specialist businesses most frequently fall short.
Related practices
- Sanctions compliance audit and testing – how we test screening logic and programme design across regimes.
- Crypto and VASP compliance under EU sanctions – ownership-and-control analysis for virtual-asset counterparties.
How does the UAE ownership-and-control test compare to OFAC and the EU?
This is where the regimes diverge most sharply, and where a cross-border business faces real analytical complexity. The three major tests – OFAC's 50 percent rule, the EU's ownership-and-control analysis, and the UAE's domestic approach – share a common objective but apply different mechanics.
Under OFAC, the test is mechanical. Any entity that blocked persons own 50 percent or more in the aggregate – whether directly or through intermediate layers – is itself treated as blocked, regardless of who controls management, regardless of the entity's conduct, and regardless of whether the blocked person exercises any operational role. Two listed persons each holding 25 percent of the same target reach the threshold together. The test is binary: at 50 percent, the entity is blocked; below 50 percent, the ownership test alone does not block it, though further analysis on control is still warranted in some programmes.
The EU's approach under the relevant Council regulations adds a control dimension alongside ownership. An entity that a designated person owns 50 percent or more is caught, but so is an entity over which a designated person exercises control by other means – through board majority, through contractual rights, through de facto influence over strategic decisions. The EU General Court has addressed this test in annulment proceedings, and the standard has been applied by EU member-state competent authorities in enforcement actions. In our experience before EU supervisors, the control analysis is the harder and more fact-sensitive element, precisely because it requires evidence about governance rather than just a cap-table review.
Under the applicable UAE instruments, the position formally mirrors the UN framework, which does not prescribe an express ownership-percentage trigger equivalent to OFAC's 50 percent rule. What the UAE rules require in practice – and what the Central Bank and the DIFC/ADGM regulators have elaborated in their guidance – is a substance-over-form enquiry: who benefits from the entity, who directs it, and whether the structure is designed or operated in a way that makes a designated person the effective beneficiary of any transaction. This is closer in spirit to the EU control test than to OFAC's mechanical threshold, but the evidentiary standard and the enforcement record are less developed and less publicly transparent.
The practical consequence: a counterparty that passes OFAC's ownership test may still require deeper analysis under UAE rules if a designated person exercises de facto control; and a counterparty that passes UAE domestic screening may still be blocked under OFAC if aggregate ownership crosses the threshold. Where a transaction touches US dollars or US persons, the OFAC analysis is not optional regardless of what the UAE domestic result shows.
The position above covers the standard case. Your facts – the counterparty, the shareholder structure, the sector, the US-dollar clearing route – change the analysis materially. For a counterparty-specific assessment, contact Calder & Vance at info@caldervance.com.
What does the UN Consolidated List add to a UAE due diligence analysis?
The UN Security Council Consolidated List is not background noise in a UAE counterparty review – it is a primary legal obligation. The UAE has implemented binding UN Security Council resolutions under Chapter VII of the UN Charter as domestic law, meaning that any transaction involving a UN-listed party is prohibited under UAE law regardless of whether that party also appears on any domestic UAE, OFAC, or EU list. The UN list, administered by the relevant Security Council committees, covers designated individuals and entities linked to terrorism financing, proliferation, and related threats.
What makes the UN list operationally significant in the UAE context is the structure of the country's trade. The UAE is a major re-export hub. Goods originating in the United States, the European Union, and other major jurisdictions transit through UAE free zones and ports before reaching end destinations. This transit role means that a UAE-based trading entity faces a compounded due diligence obligation: it must screen not only its direct counterparty but also, where goods have dual-use characteristics or where the ultimate destination is uncertain, the ultimate consignee.
The UN list also interacts with the OFAC and EU lists in a way that creates a layered minimum floor. A UN-listed entity is listed in all three systems. But OFAC and EU designations frequently go beyond the UN list. In practice, a screening programme that covers only the UN Consolidated List will miss a large population of designated parties who are listed by OFAC, the EU, or both, but not (or not yet) by the UN. This gap is a material compliance risk for any UAE-based entity with exposure to US-dollar transactions or EU counterparties.
The lesson is structural: a compliant UAE counterparty review screens the UN list as a legal floor, then screens OFAC and EU lists as a risk-management ceiling. Whether those additional checks are legally mandatory for a given entity turns on the entity's jurisdictional nexus and the currency and routing of its transactions. This is not a question of preference; it is a question of which prohibitions legally bite on the facts.
Where do financial institutions and commercial businesses diverge in their UAE due diligence obligations?
The UAE regulatory architecture creates a meaningful gap between the obligations of licensed financial institutions and those of the commercial sector. Understanding that gap matters because cross-border transactions typically involve both – and the weakest link in the due diligence chain determines overall exposure.
Licensed financial institutions in the UAE – banks, exchange houses, payment service providers, insurance entities, and virtual-asset service providers – operate under sector-specific anti-money-laundering and sanctions obligations issued by the Central Bank, the DIFC's DFSA, and the ADGM's FSRA. Those obligations require tiered customer due diligence, beneficial-ownership identification, enhanced due diligence for higher-risk relationships, ongoing transaction monitoring, and formal sanctions-screening programmes with documented escalation procedures. The regulatory expectations in the DIFC and ADGM in particular approach the depth of what OFSI and the EU's national competent authorities require of regulated firms in their jurisdictions.
Commercial businesses – trading companies, distributors, logistics providers, manufacturers – face the same UN-list obligation but are subject to lighter supervisory guidance on methodology. There is no UAE equivalent of, say, the OFSI guidance on financial-sanctions compliance for non-financial businesses that sets out a structured five-element programme. This lighter touch creates a compliance cliff between the financial and commercial sectors. In our practice, we regularly advise manufacturers and trading houses whose counterparty screening amounts to a name-match against a single list, a methodology that would not withstand regulatory scrutiny in the financial sector and that misses significant risk in complex ownership structures.
The divergence has a second dimension: record-keeping. Financial institutions in the UAE are required to maintain customer due diligence records for defined statutory periods. Commercial businesses are not subject to the same granular record-keeping rules under the sanctions instruments, though general commercial law and anti-money-laundering obligations impose retention requirements. In a cross-border context, a commercial counterparty that cannot produce documented screening results creates a gap that its bank – subject to its own obligations – will need to assess and may treat as an enhanced-risk indicator.
If a transaction has already been flagged by a financial institution, or a counterparty relationship has been placed on hold pending enhanced due diligence, an early review of the underlying screening methodology can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com to discuss.
How does secondary-sanctions risk interact with a UAE counterparty analysis?
Secondary-sanctions risk is, in our experience, the element most frequently underweighted by UAE-based businesses and their advisers. The analysis should not end at the question of whether a counterparty is listed. It must also address whether transacting with an unlisted counterparty could expose a US-person or a US-dollar transaction to OFAC enforcement on secondary-sanctions grounds.
Secondary sanctions – which operate under IEEPA and related statutes – can prohibit or penalise transactions by non-US persons with certain categories of counterparty, even where those counterparties are not themselves on the SDN List. They target conduct rather than status. A UAE-based company transacting with an entity that has significant business in a jurisdiction subject to a US secondary-sanctions programme may expose its US-dollar clearing relationships, its US-person employees or directors, and any US-origin goods or technology in the supply chain to OFAC scrutiny.
This risk is not symmetric across regimes. The EU does not operate a secondary-sanctions programme of the same jurisdictional reach. OFSI's enforcement is primarily directed at UK persons and UK-nexus transactions. The UAE has no secondary-sanctions regime of its own. It is therefore specifically US secondary-sanctions risk that a UAE-based cross-border business must evaluate when its counterparty has supply-chain or financial links to jurisdictions under US secondary-sanctions pressure.
What does a prudent analysis look like? It identifies the counterparty's revenue sources and business relationships – not just its ownership structure. It asks whether any material portion of the counterparty's business is connected to a jurisdiction subject to US secondary-sanctions coverage. It assesses the transaction's US nexus: does it clear in US dollars? Does it involve US-origin goods? Is any US person a party or a service provider? Where the answers engage secondary-sanctions risk, the due diligence programme must respond to that risk explicitly, not merely note and pass it.
Can secondary-sanctions risk always be quantified? Rarely with precision. It can be mapped, assessed, and managed with appropriate contractual protections and, where warranted, a licensing enquiry. But the starting point is accurate identification, and that requires more than a list-check.
What are the common risk flags in UAE counterparty reviews?
Practitioner experience across UAE-nexus due diligence matters points to a consistent set of risk flags that a thorough counterparty review must address. These are the patterns that repeatedly surface in escalation reviews and enforcement inquiries.
Complex free-zone structures with opaque beneficial ownership remain the most common risk indicator in the UAE context. The UAE's free zones offer legitimate and widely used commercial benefits, but they also allow rapid entity formation with limited public disclosure of beneficial ownership. A counterparty incorporated in a UAE free zone without a verified and current beneficial-ownership analysis is an unresolved risk, not a clean result.
Correspondent-banking chains that pass through UAE entities warrant specific attention. Where a UAE entity sits within a multi-leg payment chain, each institution in the chain faces its own screening obligation. A UAE financial institution clearing funds for a correspondent bank customer is not relieved of its own due diligence obligation by the correspondent bank's screening. We regularly advise banks on correspondent-chain analysis where a UAE nexus introduces layered risk.
Re-export and transshipment patterns are a structural risk feature of the UAE's trade role. Goods that transit UAE free zones on their way to a third destination require analysis of the ultimate consignee, not just the immediate buyer. Where goods have dual-use characteristics – and the applicable export-control instruments govern this broadly – the end-use obligation is not discharged by the first transaction in the chain.
Virtual-asset transactions routed through UAE-based VASPs add a further dimension. The DFSA and FSRA have issued licensing and compliance frameworks for virtual-asset service providers, but the interplay between VASP-to-VASP transactions, wallet-address screening, and sanctions obligations is still developing. For the cross-border dimension of this question, see our analysis of crypto and VASP compliance under EU sanctions and VASP compliance under OFAC.
Finally, the myth that a UAE-based counterparty is insulated from OFAC risk because it is not a US person needs to be corrected directly. OFAC's jurisdiction extends to US-dollar transactions and to conduct by non-US persons where sufficient US nexus exists. A UAE company that processes US-dollar payments for a designated counterparty, or that uses US financial infrastructure in doing so, is exposed. The jurisdictional perimeter is not drawn at nationality or incorporation; it is drawn by transaction nexus.
A practitioner scenario: re-export risk and layered ownership
In a recent matter, a UAE-based distribution company was conducting due diligence on a prospective supplier of industrial components. The supplier was incorporated in a European jurisdiction and appeared on no sanctions list. A second-layer review identified that a minority stake in the supplier's parent holding company was held by an individual who, while not himself designated, had a documented business relationship with a listed entity in a jurisdiction subject to US secondary-sanctions coverage.
We were instructed to assess the exposure across three regimes: OFAC, the EU, and UAE domestic law. The OFAC analysis turned on whether the minority stake, combined with any other holdings, reached the 50 percent aggregate threshold. It did not. However, the secondary-sanctions analysis required us to assess whether transacting with the supplier – given its parent's relationship with the designated-adjacent individual – created sufficient nexus to a secondary-sanctions-covered jurisdiction to engage US risk. That analysis was not resolvable by a list-check.
The EU analysis required us to assess control: did the individual's position in the parent's governance structure give him the ability to direct the supplier's decisions? The answer, after reviewing governance documents, was no. The UAE domestic analysis confirmed no domestic-list hit and no UN-list designation. The matter proceeded after the UAE distribution company obtained a contractual representation from the supplier regarding its ownership structure and adopted an ongoing monitoring obligation for any change in the parent's shareholder profile.
The outcome was not a guarantee. It was a documented risk assessment that allowed the transaction to proceed on an informed basis. That is what counterparty due diligence is designed to produce.
When should a cross-border business involve sanctions counsel?
Counsel involvement is not solely a response to a detected problem. There are identifiable points in a transaction or compliance programme where specialist input changes the risk profile materially.
Before a transaction: where a counterparty review surfaces a potential ownership or control issue – any shareholder link to a listed person, any business presence in a secondary-sanctions-sensitive jurisdiction, or any dual-use goods component – a structured legal analysis is more reliable than an internal judgement call. The asymmetry of penalties versus the cost of advice is significant.
When a financial institution flags a transaction: correspondent banks and clearing institutions routinely request enhanced due diligence information before processing US-dollar transactions with UAE nexus. Where a bank has placed a hold on a transaction pending that information, the response package needs to be structured and credible. An ad-hoc response that does not address the specific risk the bank has identified rarely resolves the hold efficiently.
When designing a counterparty screening programme: a business that is scaling its UAE operations, extending into new free zones, or adding digital-asset components to its payments infrastructure needs a screening programme that reflects the actual risk profile of its counterparty population. A generic off-the-shelf solution without regime-specific configuration is not a defence to a supervisory enquiry.
At acquisition: where a merger or acquisition involves a UAE-based target or a target with UAE counterparty exposure, pre-signing due diligence must address the target's historical screening practices, any self-identified breaches, and the adequacy of its counterparty-risk controls. We have acted for both acquirers and targets in this context, assessing and designing remediation programmes as part of transaction due diligence.