Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · UAE

Sanctions compliance programmes under UAE: a practical guide

A trading company headquartered in Dubai wins a significant contract with a counterparty it has worked with for years. A routine screening update flags a newly designated shareholder. The compliance team has no documented escalation path, no re-screening policy, and no senior sign-off procedure. The deal pauses. The regulators ask questions. The window for a clean resolution narrows. This situation, which we see with regularity in our cross-border practice, is the direct result of a compliance programme built around good intentions rather than documented procedures.

Sanctions compliance programmes under the UAE regime require businesses to demonstrate, in writing, that they can identify prohibited counterparties, halt transactions, escalate decisions, and report to the relevant authority – the UAE Executive Office for Control and Non-Proliferation (EOCN) and, for financial institutions, the Central Bank of the UAE (CBUAE). The UAE operates its own autonomous sanctions instrument alongside its obligations under UN Security Council resolutions. As of July 2026, the regime is actively supervised, with an enforcement posture that rewards documented programmes and penalises the absence of one.

This guide walks through each design phase of a UAE-compliant sanctions programme, compares the UAE requirements with parallel obligations under OFAC, OFSI, and the EU, and identifies the risk flags that most commonly surface during a regulatory review.

Step 1: Understanding the governing regime and supervisory authority

The UAE sanctions regime is governed by its autonomous national instrument and by the state's binding UN Security Council obligations under Chapter VII of the UN Charter. The EOCN holds primary responsibility for maintaining the domestic sanctions list and coordinating cross-government implementation. Financial institutions fall additionally under the supervisory jurisdiction of the CBUAE, which issues its own guidance on sanctions screening and compliance expectations for licensed firms.

What distinguishes the UAE from many Western regimes is its dual-track structure. An entity or individual can appear on the domestic UAE list without appearing on the UN Consolidated List, and vice versa. A compliance programme that screens only against one list is, by definition, incomplete. In our experience, this gap – screening the UN list but not the domestic instrument, or the reverse – is the most common structural weakness we identify during a compliance audit of a UAE-based business.

Beyond the domestic and UN lists, businesses operating in the UAE with US dollar payment flows, US-origin goods, or US counterparties remain subject to extraterritorial reach under OFAC. The SDN List (OFAC's list of Specially Designated Nationals and blocked persons) and the underlying IEEPA-based prohibitions apply regardless of where the transaction originates, if a US nexus exists. A UAE programme that treats OFAC as someone else's problem is not a complete programme. We return to this cross-border dimension in Step 4.

Step 2: Mapping the legal obligations before writing a single policy

Effective programme design starts with a legal-obligations map, not with a policy template. Before drafting a screening procedure, a compliance team must identify which regimes bind the entity, which supervisory authorities can enforce, and which counterparty categories create the greatest exposure.

This mapping exercise has three components. First, identify the entity's jurisdictional touchpoints: registered office, banking relationships, payment currencies, goods origins, counterparty locations, and ownership chain. A UAE-registered subsidiary of a European group may be subject to UAE, EU, and potentially OFAC obligations simultaneously. Each jurisdiction has its own prohibited-transaction list, licensing route, and reporting requirement. Second, identify the category of business activity. Financial institutions, money-service businesses, and designated non-financial businesses and professions (DNFBPs) – which include real-estate brokers, gold and precious-metals dealers, and legal and accounting professionals – face heightened supervisory expectations in the UAE. Third, confirm whether the entity handles goods that could trigger export-control obligations, since the UAE has its own strategic-goods controls that interact with, but are not identical to, the US EAR or the EU dual-use regime.

The output of this mapping exercise is a one-page obligations matrix: which regime, which authority, which prohibitions, which reporting lines, and which timelines. Without it, a policy document is a guess.

Step 3: The five core elements of the written programme

A defensible UAE sanctions compliance programme contains five documented elements that mirror the structure recognised by the major sanctions authorities globally – OFAC, OFSI, and the UAE supervisors alike. Divergences exist at the margins, but the core architecture is consistent.

The first element is senior management commitment. The programme must carry the explicit, documented endorsement of the board or executive leadership. This is not a formality. In any enforcement review, regulators look first at whether senior management treated sanctions as a business priority or delegated it entirely downward without oversight. A board resolution, a signed policy statement, or a standing agenda item at the compliance committee level satisfies this requirement in practice.

The second element is risk assessment. The business must assess its sanctions exposure across counterparties, geographies, products, and transaction types. The risk assessment is a living document, updated when the entity enters new markets, adds product lines, or identifies a change in the regulatory environment. A static risk assessment written once and never revisited will not satisfy a UAE supervisory review.

The third element is written policies and procedures. These must be specific enough to tell an employee, step by step, what to do when a screening alert fires. "Escalate to compliance" is not a procedure. A procedure specifies who receives the alert, within what timeframe, what information they review, who has authority to clear or block the transaction, and how the decision is recorded. The CBUAE's expectations for licensed financial institutions on this point are detailed and should be reviewed against the relevant supervisory guidance before finalisation.

The fourth element is training. All staff who handle transactions, onboard customers, or make credit decisions must receive regular, documented sanctions training. Training records must be retained. In our cross-border practice, we regularly advise clients that training dated more than twelve months before a supervisory review will be treated as effectively lapsed; regulators expect evidence of annual refreshers at a minimum, with topic-specific updates when the regime changes.

The fifth element is audit and testing. The programme must be tested against real transaction data, not just described in a policy. Testing identifies whether the screening tool catches what it is supposed to catch, whether escalation paths work in practice, and whether staff follow documented procedures rather than informal habits. We address audit and testing in Step 6.

Step 4: Cross-border obligations and the OFAC extraterritorial dimension

Operating from the UAE does not insulate a business from OFAC, BIS, OFSI, or EU jurisdiction. Each regime has a different basis for asserting reach over a UAE-based entity.

OFAC's jurisdiction is triggered by US persons, US-dollar transactions cleared through the US financial system, US-origin goods or technology, and entities organised under US law – wherever located. A UAE trading company that pays a supplier in US dollars is routing that payment through a US correspondent bank. At that moment, OFAC's prohibitions apply. A UAE-based firm that re-exports US-origin components – even to a third country – must consider whether the transaction requires a BIS licence under the EAR (the Export Administration Regulations, the US export-control regime administered by the Bureau of Industry and Security). The 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked) applies globally; a UAE counterparty owned by a sanctioned person is blocked for all OFAC purposes, regardless of where the counterparty is registered.

OFSI, the UK's financial sanctions authority, and the EU Council regulations follow a broadly similar jurisdictional logic but diverge on the ownership-and-control test. Both OFSI and the EU apply an ownership and control test (the rule that a non-listed entity may be caught by a designation through a listed person's ownership or control) that goes beyond the mechanical 50 percent ownership threshold. Under the EU and UK approaches, a listed person who exercises effective control over an entity – even without majority ownership – can bring that entity within the prohibitions. This is a meaningful difference for complex group structures. A UAE programme that adopts OFAC's 50 percent rule verbatim and applies it to EU- and UK-related transactions will produce incorrect results in edge cases involving minority-but-controlling stakes.

Singapore and Japan, both in scope for businesses with Asia-Pacific counterparties, operate their own autonomous sanctions instruments alongside UN obligations. Neither regime currently has the extraterritorial reach of OFAC, but businesses with exposure to those jurisdictions should confirm the applicable country regime before structuring transactions. We have acted for trading groups whose UAE operations intersected with Singapore-registered counterparties, requiring a parallel analysis of both instruments before the transaction could proceed.

The practical implication for programme design is this: the regime map in Step 2 must drive the screening configuration. A screening tool calibrated only to the UAE domestic list and the UN Consolidated List will miss SDN-listed counterparties and EU-designated persons unless those lists are added explicitly. Most enterprise screening platforms cover OFAC, UN, EU, and OFSI as standard. The UAE domestic list requires a deliberate configuration step that not every vendor default includes.

Step 5: Ownership and control mapping – closing the beneficial-owner gap

Screening a counterparty's legal name against a sanctions list is necessary but insufficient. The real exposure in the UAE market – as in any market with complex ownership structures – lies in the beneficial-ownership layer beneath the contracting entity.

The UAE's beneficial-ownership rules require companies to maintain a register of ultimate beneficial owners and to submit that information to the relevant commercial register. This information is not always publicly accessible, which means a compliance team cannot rely solely on a registry search to resolve ownership questions. The programme must include a process for requesting beneficial-ownership declarations directly from counterparties and for escalating when a counterparty refuses or provides incomplete information.

In practice, the ownership check has three layers. First, identify all direct shareholders above a defined threshold – typically 25 percent or more for AML/beneficial-owner purposes, though for sanctions screening we recommend extending the check to any shareholder above ten percent where the business risk is elevated. Second, apply the OFAC 50 percent rule by aggregating all blocked persons' holdings across the ownership chain. Third, apply the OFSI/EU control test to any entity that touches a UK or EU regulatory nexus, asking whether any listed person has the practical ability to direct the entity's decisions regardless of formal shareholding.

Where the ownership structure is opaque – free-zone entities, trust arrangements, nominee directors – the programme should specify a defined escalation path before the business relationship proceeds. An unclear ownership chain is a red flag, not a reason to proceed with expedited onboarding.

Step 6: Audit, testing, and continuous improvement

A written programme that is never tested provides limited protection. Regulators in the UAE and globally look for evidence that a business knows its programme works, not merely that it has one.

Testing has two forms. Automated screening-tool testing validates that the technology catches what it is configured to catch – correct list versions, accurate name-matching algorithms, adequate transliteration handling for Arabic-script names. Manual transaction testing applies the written procedures to a sample of real past transactions and asks whether the documented process was followed. Gaps between the policy and the practice are the audit finding that most commonly produces a regulatory action.

Calder & Vance regularly advises clients undertaking a compliance programme review. In one recent engagement, a UAE-based financial services business discovered that its screening tool had been running on a list version that had not updated correctly for a period of several months. The gap was identified in an internal audit, corrected, and disclosed to the relevant authority. Early identification and prompt remediation substantially improved the regulatory outcome compared with the alternative of a supervisory discovery. That experience is representative of what proactive testing achieves.

The audit cycle should run at minimum annually. After a significant regulatory change – a new designation on the UAE domestic list, a material update to OFAC guidance, or a change in the business's own ownership or product range – an out-of-cycle review is warranted. Record-keeping for audit findings and remediation steps should be maintained for a period consistent with the applicable country regime's requirements; verify the current retention period before finalising your programme documentation.

For a focused audit of your current programme's structure, see our compliance audit and testing service, which applies a structured testing methodology to identify gaps before a regulator does.

Step 7: Escalation, reporting, and voluntary self-disclosure

A programme that identifies a potential breach must have a documented path for what happens next. Escalation without a written procedure defaults to informal judgment, and informal judgment is unreliable under pressure.

The written escalation procedure should specify: who receives the initial alert; what information is assembled for their review; the timeframe for a first-level decision; who has authority to clear, block, or escalate further; and what record is created at each stage. The senior compliance officer or general counsel should sit at the top of that chain, with board visibility for any matter above a defined materiality threshold.

Where a potential breach is identified, the question of voluntary self-disclosure – a VSD (a self-initiated report to a regulator, typically made before the regulator has identified the issue independently) – arises quickly. In our cross-border practice, the consistent position across OFAC, OFSI, and the UAE supervisors is that a timely, accurate, and complete VSD is treated as a significant mitigating factor in any subsequent enforcement action. The difference in regulatory outcome between a prompt VSD and a discovery by the regulator can be material.

Timing is critical. The window between identifying a potential breach and the point at which a VSD loses its mitigating value is short. Engaging counsel early – before the regulatory contact begins – preserves the widest range of options. If a potential breach has already been flagged, an early review can preserve options that narrow with time. For a confidential assessment, contact Calder & Vance at info@caldervance.com.

Common mistakes and risk flags: the myth of the one-time exercise

The most persistent myth we encounter in advising UAE-based businesses is that a sanctions compliance programme is a one-time exercise: design it, file it, and move on. This is incorrect, and it is the myth that most reliably leads to enforcement exposure.

Sanctions lists change continuously. The UAE domestic list, the UN Consolidated List, the SDN List, and the EU and OFSI consolidated lists are all subject to additions, amendments, and removals on an ongoing basis. A programme that does not re-screen existing customer portfolios against updated lists will accumulate hidden exposure. The question is not whether a previously screened counterparty will appear on a list in the future; experience shows that it happens. The question is whether the programme will catch it when it does.

Beyond re-screening, the risk flags we most commonly identify are: ownership structures that have not been re-verified after a counterparty restructuring; training records that cannot be produced for key personnel; escalation procedures that exist in writing but have never been tested; and screening tools configured to a narrower list set than the business's actual jurisdictional exposure requires. Each of these is correctable before a regulatory review. None of them corrects itself.

Related practices

Frequently asked questions

What are the steps to design a sanctions compliance programme under UAE?
A UAE sanctions compliance programme follows seven sequential steps: map your legal obligations across all applicable regimes; confirm supervisory authority (EOCN and, for financial institutions, CBUAE); document senior management commitment; conduct a risk assessment; write specific policies and procedures covering screening, escalation, and record-keeping; deliver and record training; and test the programme against real transaction data. Each step must be documented. A programme that skips documentation at any stage provides limited protection in a regulatory review.
What is the most common mistake in sanctions compliance programmes?
The most common mistake is treating the programme as a one-time design exercise rather than a continuously maintained control. Sanctions lists update regularly, ownership structures change, and new counterparties carry risks that a static programme will not detect. The second most common mistake is screening only one list – typically the UN Consolidated List – when the business's actual exposure spans the UAE domestic instrument, OFAC's SDN List, and the EU or OFSI consolidated lists. Both mistakes are correctable before a regulatory review surfaces them.
How does UAE differ from other regimes here?
The UAE operates a dual-track sanctions structure: an autonomous domestic instrument administered by the EOCN, alongside binding UN Security Council obligations. Unlike OFAC, the UAE regime does not apply the same extraterritorial reach beyond its borders, but businesses with US dollar payment flows or US-origin goods remain independently subject to OFAC. The UAE's ownership-and-control test for beneficial ownership purposes follows its own domestic rules, which differ in detail from OFAC's mechanical 50 percent rule and from the EU and OFSI control tests. A programme designed for OFAC compliance alone will not satisfy a UAE supervisory review.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.