Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · UAE

Sanctions compliance programmes under UAE: a compliance guide

A trading company based in Dubai closes a supply agreement with a European counterparty. The goods move through a free-zone warehouse, the payment clears through a UAE-correspondent bank, and the compliance team files the documentation. Three months later, a regulator query arrives: did the company verify the end-destination and the ownership chain of its buyer before the deal closed? The team cannot answer with confidence. That gap – between having a policy and having a working programme – is where UAE sanctions enforcement bites.

Designing a sanctions compliance programme under the UAE regime means building a documented, tested system that meets the requirements of the Executive Office for Control and Non-Proliferation (EOCN) and aligns with the UAE's United Nations Security Council obligations. As of July 2026, the UAE maintains its own autonomous designation list alongside its implementation of UN Security Council Consolidated List obligations, and the EOCN has made clear that a written policy alone does not constitute compliance. A functioning programme must cover governance, screening, risk assessment, transaction monitoring, and a clear breach-response protocol.

This guide walks through each stage of designing and embedding that programme, compares the UAE approach with the positions taken by OFAC, OFSI, and the EU, and identifies the risk flags that most commonly expose cross-border businesses operating in or through the UAE.

Step 1: Understand who governs UAE sanctions and what they require

The EOCN is the UAE's primary authority for implementing financial sanctions, proliferation-related controls, and UN Security Council measures; it publishes the UAE Local Terrorist List and administers the asset-freeze and funds-reporting obligations that bind all persons and entities subject to UAE jurisdiction. Understanding its role is the essential starting point before any programme can be designed.

The UAE's sanctions obligations derive from two sources. First, the UAE, as a UN member state, is bound by Security Council resolutions adopted under Chapter VII of the UN Charter, and these are given domestic legal effect through UAE law. Second, the UAE has its own autonomous designation mechanism, through which the EOCN can list individuals and entities on the UAE Local Terrorist List independently of UN action. A programme that tracks only the UN Consolidated List will miss autonomous UAE designations. That is a structural gap, not a monitoring failure.

Beyond the EOCN, businesses operating in the UAE's financial sector must also be aware of the Central Bank of the UAE, which issues prudential guidance on sanctions compliance for licensed financial institutions. The two regimes are complementary rather than contradictory, but they impose overlapping obligations, and a programme must address both. For businesses with a presence in a UAE free zone, the relevant free-zone authority may also impose conditions on licences that touch on sanctions and export-control checks.

In our cross-border practice, the most common misunderstanding we encounter at the programme-design stage is the assumption that the UAE operates a purely reactive regime – that is, that it only ever enforces UN measures already implemented elsewhere. That assumption is incorrect. The EOCN has a domestic list, domestic powers of freezing and reporting, and a stated intention to bring the UAE's compliance culture in line with the standards expected of a major international financial centre. Designing a programme for the UAE today means designing it for active supervision, not passive compliance.

Step 2: Conduct a risk assessment calibrated to the UAE's exposure profile

Every programme must begin with a written risk assessment that maps the business's actual exposure to sanctions risk under the UAE regime and the foreign regimes that interact with its transactions. This is not a theoretical exercise. The risk assessment drives the design of every downstream control.

For businesses operating in or through the UAE, the exposure profile is distinctive. The UAE sits at the intersection of trade flows from South Asia, the Middle East, Africa, and Europe. Its free zones host tens of thousands of companies, including trading entities, logistics intermediaries, and financial-services businesses. A risk assessment must address:

  • the jurisdictions of counterparties, not just their place of incorporation;
  • the nature of goods or services transacted, with specific attention to dual-use items, technology, and commodities that appear on relevant control lists;
  • the payment corridors used and the correspondent-banking chains involved;
  • the ownership and control structures of counterparties and their ultimate beneficial owners;
  • the end-use and end-user risk in every material transaction.

The risk assessment must be documented, dated, and reviewed at least annually or when a material change in the business's activity or in the applicable sanctions regime occurs. In practice, we advise clients to build a risk-assessment template that captures each of these dimensions for each business line, rather than producing a single firm-wide document that is too general to drive specific controls. A document that describes risk in aggregate is an administrative artefact. A document that assigns risk ratings by business line, geography, and counterparty type is a working compliance tool.

Cross-regime interaction is a critical dimension of the risk assessment for UAE-based businesses. The UAE is not a sanctions-imposing jurisdiction in the same way as the United States, the United Kingdom, or the European Union, but transactions processed through UAE entities frequently involve US-dollar payments, European counterparties, or goods with a US-origin or EU-origin component. That means OFAC jurisdiction and EU sanctions regulations may apply to the same transaction that is being assessed under UAE law. The risk assessment must be honest about that overlap. A transaction that passes the UAE screening check may still expose a party to secondary-sanctions risk under OFAC, particularly where a US-dollar clearing bank is in the chain.

The position above covers the standard design case. Your specific risk profile – the sectors you operate in, the payment rails you use, the jurisdictions of your counterparties – changes the analysis considerably. For a tailored risk-assessment review, contact Calder & Vance at info@caldervance.com.

Step 3: Design the screening architecture and the ownership-chain test

Screening is the operational core of a UAE sanctions compliance programme. It must cover counterparties, beneficial owners, goods, and payment routes against the UAE Local Terrorist List, the UN Consolidated List, and – for businesses with exposure to extraterritorial regimes – the OFAC SDN List (OFAC's list of Specially Designated Nationals and blocked persons), the OFSI consolidated list, and the EU consolidated list.

The screening tool must be configured to match the language variants and transliteration patterns that appear in UAE-relevant names. Arabic-script names present a transliteration challenge that off-the-shelf screening tools frequently handle poorly. A tool calibrated for English-language names will generate both false positives on legitimate counterparties and – more seriously – false negatives on listed parties whose names have been transcribed in an unexpected variant. Validating the tool's performance against UAE-specific name variants is a necessary step in programme design, not an optional refinement.

The ownership test under UAE sanctions follows a logic similar to the test applied under OFSI and the EU: ownership and control (the test for whether a non-listed entity is caught through a listed person's ownership or direction of it) must be assessed in substance, not just in the legal documents. A counterparty with a clean corporate registration may still be owned or controlled by a listed person through nominee arrangements, trust structures, or layered holding companies. The programme must include a procedure for tracing ownership chains to the ultimate beneficial owner, and for escalating where the ownership picture is unclear or incomplete.

How does the UAE's ownership test compare to OFAC's 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked)? OFAC's test is mechanical: aggregate ownership at or above the threshold triggers the block, regardless of control. The UAE approach, in common with OFSI and the EU, incorporates a control dimension: a listed person who directs a company's affairs without holding a majority share may still cause that company to be treated as caught. In practice, this means that passing the 50 percent screen is a necessary but not sufficient check under the UAE regime. A compliance programme must include a control assessment, not just an ownership calculation.

Transaction monitoring complements screening. Screening checks a counterparty at a point in time; monitoring tracks patterns in actual transactions – payment amounts, routing, timing, and volume – that may indicate exposure that a name check would not surface. For a trading business operating at volume through the UAE, a rule-based monitoring layer applied to transaction data is a proportionate control.

How does the UAE regime differ from OFAC, OFSI, and the EU?

The UAE regime is narrower in its designation scope than OFAC or the EU, but it operates within a legal environment where extraterritorial exposure from those regimes is a routine business reality. Understanding the points of divergence is essential to designing a programme that addresses all applicable obligations without creating duplication that impedes legitimate trade.

The key structural differences are as follows:

Jurisdictional scope. OFAC's regulations apply to US persons wherever located, to transactions in US dollars anywhere in the world, and – for certain country-specific programmes – on an extraterritorial basis to non-US persons. OFSI's regulations apply to UK persons and to conduct within the UK. The EU's sanctions apply to EU persons and to conduct within EU territory. The UAE's sanctions apply to persons subject to UAE jurisdiction: entities incorporated in the UAE, persons resident in the UAE, and transactions processed through UAE financial institutions. A UAE-incorporated company is not automatically subject to OFAC jurisdiction, but if its transactions clear in US dollars through a US-correspondent bank, OFAC's rules engage regardless.

Licensing. OFAC operates a well-developed specific licence (a case-by-case authorisation to conduct an otherwise prohibited transaction) and general licence (a standing authorisation that permits a defined category of transactions without a separate application) system. OFSI also issues licences, including an own-legal-costs licence with a short reporting window. The EU has provision for national-competent-authority licensing. The UAE licensing framework is less developed in published precedent, and the EOCN's practice on licence applications is still evolving. For businesses that face a licence requirement simultaneously under OFAC and UAE law, coordinating those applications requires careful sequencing and cannot be done in parallel without an understanding of each authority's requirements.

Reporting obligations. OFSI requires a person who knows or suspects they hold frozen assets to report to OFSI within a short statutory window. The UAE imposes its own mandatory reporting obligations on persons who hold or control funds subject to a freeze. The exact timing and form of reporting differs between regimes. A UAE-based bank that holds funds subject to both OFSI and UAE freeze orders must report to both authorities on their respective timetables.

Enforcement posture. OFAC and OFSI have published detailed enforcement guidance, including disclosure frameworks and penalty-calculation methodologies. The EOCN's published enforcement guidance is less detailed, but the direction of travel is toward more active supervision. Businesses operating in the UAE should not assume that the EOCN's enforcement posture today is a reliable guide to its posture in twelve months.

One practical point worth isolating: the UAE's position as an international trading hub means that goods transiting through UAE free zones may be subject to export-control scrutiny from the jurisdiction of their origin. US-origin goods transiting a UAE free zone remain subject to the US Export Administration Regulations (the EAR), and a UAE-based re-exporter of such goods is bound by EAR end-use and end-user controls. A sanctions compliance programme that does not address export controls is incomplete for a business that handles physical goods.

If a transaction has already been flagged under one of these regimes, or if a filing has been refused, an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com for a confidential initial review.

Step 4: Establish governance, training, and a breach-response protocol

A sanctions compliance programme without a governance structure is a document. A programme with a governance structure is a system. The difference matters because regulators – including the EOCN – assess programmes by examining whether the governance is real: whether the responsible person has authority, resources, and direct access to senior management, and whether the programme is actually followed in practice.

At a minimum, the governance structure for a UAE-based or UAE-active business must designate:

  • a named compliance officer with responsibility for the UAE sanctions programme, distinct from the general AML officer where the business is large enough to separate the roles;
  • a clear escalation path for potential screening hits, ownership-chain issues, and transaction-monitoring alerts;
  • a documented procedure for senior-management sign-off on high-risk transactions or decisions to proceed despite a residual concern;
  • a record-keeping standard for screening decisions, risk assessments, and transaction-monitoring outcomes.

Training must be role-differentiated. The front-line relationship manager and the compliance analyst require different training. Generic annual training that covers sanctions at a headline level does not constitute a functioning training programme. In our experience, the businesses most exposed to enforcement risk are those where the training record is current but the operational staff cannot describe what they would do if a counterparty screened as a possible match. Training is a means to operational competence, not a compliance checkbox.

A VSD (voluntary self-disclosure to a regulator) protocol must be documented before it is needed. Under OFAC's framework, a timely and complete VSD is treated as a significant mitigating factor in penalty calculations. OFSI has an analogous disclosure path. The EOCN's practice on voluntary disclosure is developing, but the principle that prompt, candid disclosure is better than reactive defence is sound across all the major regimes. The protocol must specify: who makes the decision to disclose, who prepares the filing, and what records must be preserved in the interim.

Record-keeping standards matter. Across the major regimes – OFAC, OFSI, EU, and UAE – a multi-year record-keeping obligation applies to sanctions-related transactions. The exact period varies by regime and by category of record. A programme must specify the minimum retention period for each record type, the storage format, and the retrieval procedure. Five-year retention is a commonly cited standard across several major regimes, but the programme should specify the applicable period for each relevant regime rather than applying a single figure across the board.

Step 5: Test, audit, and continuously improve the programme

A programme that is designed but never tested is not a functioning compliance system. Regulators assess the testing record when evaluating whether a business's compliance commitment is genuine or performative. Testing must include both desk-based reviews and live transaction sampling.

Testing should address:

  • screening coverage: does the tool screen against all required lists, including the UAE Local Terrorist List, the UN Consolidated List, and the relevant extraterritorial lists?
  • screening accuracy: does the tool correctly identify likely matches and avoid systematic false negatives on Arabic-script name variants?
  • escalation: are potential hits escalated correctly, and are escalation decisions documented?
  • ownership-chain assessment: when a counterparty presents a complex ownership structure, does the procedure produce a documented conclusion?
  • training effectiveness: do operational staff demonstrate the knowledge the training is designed to produce?

The testing record must be documented. An audit log that shows the date of each test, the scope, the findings, and the remediation steps taken is the artefact that demonstrates programme maturity. A regulator reviewing the programme will look at that log as evidence of management commitment, not just management declaration.

Independent review is a further step that businesses with material sanctions exposure in the UAE should consider. An external review by a sanctions compliance specialist – one who is familiar with the EOCN's requirements and with the extraterritorial regimes that interact with UAE-based transactions – tests the programme against the standard that a regulator would apply, not just the standard the internal team has set for itself. We regularly advise businesses at this stage, including for programmes that have been in place for some time and need to be brought up to a current regulatory standard.

The interaction between UAE sanctions compliance and export-control obligations is worth addressing specifically in the testing phase. A UAE-based exporter or re-exporter of dual-use goods is subject to UAE export controls, and may also be subject to EAR controls if the goods have a US-origin component. Testing the export-control classification procedure alongside the sanctions screening procedure surfaces gaps that neither check, run alone, would identify.

Risk flags and when to involve sanctions counsel

Certain facts patterns consistently indicate elevated risk in a UAE sanctions compliance context. Recognising them before a transaction is approved, rather than after a query arrives, is the difference between a compliance programme that functions and one that merely exists.

The highest-frequency risk flags in our practice are:

  • Counterparties with opaque ownership chains. A UAE-incorporated counterparty whose ultimate beneficial owner cannot be identified through public records and whose documents are incomplete is a risk flag, not a normal due-diligence gap to be accepted. Under both the UAE's ownership-and-control test and OFAC's 50 percent rule, the compliance team must be able to form a documented view on ownership before the transaction proceeds.
  • Transactions involving goods with dual-use potential. The EAR and UAE export-control rules both require an assessment of the classification of goods and the end-use and end-user risk. A transaction that involves goods with potential military, nuclear, or surveillance applications requires a heightened diligence process.
  • US-dollar payment routing through UAE-correspondent banks. Where a UAE entity is transacting in US dollars, the correspondent bank in the payment chain is subject to OFAC jurisdiction. A transaction that the UAE-entity considers to be a purely domestic commercial matter may constitute an apparent OFAC violation from the perspective of the correspondent bank. The programme must address this structural exposure.
  • Secondary-sanctions exposure. A UAE business that transacts with counterparties in jurisdictions subject to extensive US secondary-sanctions measures may expose its non-US financial institution counterparts to US secondary-sanctions risk. Even where the UAE business itself is not a US person, the secondary-sanctions dimension must be assessed.
  • Free-zone entities without a visible business rationale. A counterparty incorporated in a UAE free zone whose business activities are unclear, whose directors or shareholders are not readily identifiable, and whose transactions do not match a coherent commercial purpose is a red flag warranting enhanced due diligence before any commercial engagement proceeds.

A compliance programme that does not train staff to recognise these patterns – and that does not include an escalation path for transactions that match them – will produce systematic gaps between its written standard and its operational reality. That gap is precisely what a regulator looks for in an enforcement investigation.

The myth worth addressing directly: some businesses entering the UAE market assume that, because the UAE is not a sanctions-imposing jurisdiction in the Western mould, a lighter-touch programme is adequate. That assumption conflates the EOCN's current enforcement posture with its legal requirements and its direction of travel. The legal obligations are real and serious. Enforcement capacity is growing. And extraterritorial exposure from OFAC, OFSI, and the EU is present in virtually every transaction that involves non-UAE counterparties, US-dollar payments, or goods with a Western-origin component. The compliance standard must be calibrated to the actual risk, not to a perception of the risk that was formed several years ago.

Related practices

Frequently asked questions

What are the steps to design a sanctions compliance programme under UAE?
Designing a UAE sanctions compliance programme involves five sequential steps: (1) understand the governing authorities – the EOCN and the Central Bank of the UAE – and the legal instruments that give effect to UN Security Council obligations and autonomous UAE designations; (2) conduct a written risk assessment calibrated to the business's counterparty profile, sectors, payment corridors, and goods; (3) build a screening architecture that covers the UAE Local Terrorist List, the UN Consolidated List, and any applicable extraterritorial lists, with a tested ownership-and-control assessment procedure; (4) establish governance with a named compliance officer, a documented escalation path, role-differentiated training, and a VSD protocol; and (5) test, audit, and improve the programme through periodic desk reviews, live transaction sampling, and, for businesses with material exposure, an independent external review.
What is the most common mistake in sanctions compliance programmes?
The most common mistake is treating a written policy as a functioning programme. A policy describes what should happen; a programme is the set of controls, procedures, trained staff, and governance structures that make it happen in practice. Regulators across all the major regimes – including the EOCN – assess the operational reality of a programme, not its documentation. Businesses that invest in drafting policies but do not invest in testing, training, and governance frequently discover that their programme fails the moment it is examined by a regulator or stress-tested by an actual screening hit. A close second is screening only against the primary regime list and omitting either the UAE Local Terrorist List or the applicable extraterritorial lists.
How does UAE differ from other regimes here?
The UAE regime differs in three material respects from OFAC, OFSI, and the EU. First, its designation scope is narrower: the UAE's autonomous list is smaller than the OFAC SDN List or the EU and UK consolidated lists. Second, its licensing framework is less developed in published precedent, making it harder to predict EOCN practice on licence applications than OFAC or OFSI practice. Third, the UAE's jurisdictional basis is territorial rather than personal: it applies to conduct and persons within UAE jurisdiction, not to UAE nationals worldwide or to transactions in UAE dirhams clearing globally. However, the UAE's position as a major trading hub means that virtually every material transaction carries some layer of extraterritorial exposure from OFAC, OFSI, or EU sanctions, which makes the compliance standard in practice as demanding as in any of those regimes.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.