A bank with correspondent relationships across the Gulf receives a routine review notice from its compliance function. Three counterparties show indirect exposure to names appearing on a UAE-administered sanctions list. The question is immediate: does the bank pause activity, exit the relationships, or seek further information? That decision – taken under time pressure and incomplete information – is where correspondent-banking de-risking under the UAE regime either goes wrong or gets managed correctly.
De-risking (a financial institution exiting or curtailing a relationship to avoid sanctions exposure) in the UAE correspondent-banking context is governed by the UAE's autonomous sanctions regime, administered through the Executive Office for Control and Non-Proliferation (EOCN), alongside the UAE's implementation of United Nations Security Council consolidated-list obligations. As of January 2026, the UAE operates a dual-track system: UN-derived designations and autonomous UAE designations, both capable of triggering correspondent-bank exit obligations. The procedure, the tests for ownership and control, and the consequences of a mistimed exit differ materially from the OFAC and OFSI approaches.
This guide sets out the governing authority and legal basis, the step-by-step procedure for managing a de-risking decision, the cross-regime comparison a global correspondent cannot ignore, and the risk flags that most commonly cause matters to escalate.
What is the UAE sanctions regime and who administers it?
The UAE autonomous sanctions regime is administered by the EOCN, sitting within the National Security Council structure, and operates alongside UAE Cabinet Resolution frameworks that give domestic legal effect to UN Security Council measures and, increasingly, to autonomous UAE designations. The EOCN maintains the UAE Local Terrorist List and gives effect to the UN Consolidated List, which reflects binding Security Council obligations under Chapter VII of the UN Charter.
For a correspondent bank, the practical authority is the Central Bank of the UAE (CBUAE). The CBUAE issues anti-money-laundering and sanctions-related guidance to licensed financial institutions. That guidance specifies the screening obligations, the due-diligence standards, and – critically – the obligation to file a suspicious activity report and to freeze assets where a designated person or entity is identified. The CBUAE's supervisory reach extends to correspondent relationships: a UAE-licensed respondent bank that fails to screen its own customers adequately can itself become a source of sanctions risk to the international correspondent.
This dual-authority structure – EOCN for designation and the CBUAE for financial-sector supervision – is the first point of divergence from regimes such as OFAC, where a single authority manages both the list and the financial-sector enforcement posture. In our cross-border practice, we regularly see international correspondents underestimate the CBUAE's supervisory role, treating the UAE purely as a list-screening exercise rather than a supervised-entity compliance relationship.
Step 1: Identify the trigger and map the applicable list
The first step in any UAE correspondent-banking de-risking exercise is to identify precisely which list has generated the alert and to determine whether the match is against a UN Consolidated List name, a UAE Local Terrorist List name, or an autonomous UAE designation. The legal consequences and the procedural options differ across those three categories.
A match against the UN Consolidated List carries the strictest obligation. UN Security Council measures under Chapter VII are binding on all member states. A UAE-licensed respondent bank is obliged to freeze assets without delay. The international correspondent, if it processes a payment to or from a name on that list, faces exposure not only under the UAE regime but under every jurisdiction that implements UN obligations – which includes the EU, the UK, Switzerland, Canada, and Australia, as well as OFAC's own SDN List in most instances.
A match against the UAE Local Terrorist List or an autonomous UAE designation requires the same immediate freeze under UAE law, but the extraterritorial effect is narrower. Whether the international correspondent faces independent exposure in its home jurisdiction turns on whether its own regime has listed the same name. That mapping exercise – does the UAE name appear on the OFAC SDN, the OFSI Consolidated List, or the EU Consolidated List? – should happen in parallel with, not after, the initial UAE-list match. Have you confirmed whether the alert is UN-derived or UAE-autonomous? That question decides the cross-border scope of your obligation.
Practical discipline here matters. A screening system that conflates UN and UAE autonomous alerts will produce decisions that either over-restrict legitimate transactions or under-restrict genuinely prohibited ones. Mapping the source list is not an administrative formality; it is a legal prerequisite.
Step 2: Apply the ownership and control test under UAE rules
Once a direct name match is confirmed, the next step is to determine whether any entity in the correspondent-banking chain is captured indirectly through ownership or control by a designated person. The UAE regime applies an ownership and control test (the principle that a non-listed entity may be caught because a designated person owns or controls it) that broadly mirrors the approach taken by OFSI and the EU, rather than the purely mechanical threshold used by OFAC.
Under OFAC, the 50 percent rule (OFAC's rule treating entities owned 50 percent or more in aggregate by blocked persons as themselves blocked) applies automatically to any entity owned at or above that threshold. The test is arithmetic. Under the UAE approach, and similarly under OFSI's guidance, ownership below a 50 percent threshold does not automatically block the entity – but effective control, through board appointment rights, veto powers, or economic dependency, can still catch it. That distinction is operationally significant for a correspondent bank reviewing a respondent that has a minority designated shareholder.
In our experience, the hardest cases arise where a designated person holds a stake of thirty to forty-five percent and simultaneously holds contractual rights that give them effective governance control. Under OFAC alone, that entity might not be blocked. Under the UAE regime, OFSI guidance, and EU Council regulation practice, the control analysis could reach a different answer. A correspondent operating across these regimes needs to run both analyses, and where they diverge, the stricter prohibition governs.
The practical output of this step is a written ownership-and-control mapping document that traces the designated person's interest through every layer of the respondent's corporate structure. That document serves two purposes: it supports the de-risking decision if exit is required, and it provides the evidence base if the correspondent later needs to demonstrate to its own regulator that the decision was reasoned.
Step 3: Decide between exit, enhanced monitoring, and escalation
Having mapped the list and the ownership chain, the correspondent bank faces a three-way decision: exit the relationship immediately, apply enhanced due diligence and continue subject to heightened monitoring, or escalate to the regulator before acting. Getting this sequencing wrong is the most common source of regulatory difficulty.
Exit is mandatory where the respondent itself is designated, or where the ownership-and-control analysis concludes that the respondent is effectively captured. There is no discretion in that scenario. The correspondent must cease activity, block any assets held, and file the required notification. The CBUAE's guidance specifies a short reporting window once a freeze obligation is identified; advisers should verify the current applicable period before relying on any stated deadline, as the CBUAE updates its guidance periodically.
Enhanced monitoring is the appropriate response where the alert is a potential match rather than a confirmed match, or where the designated person holds a minority interest that does not reach the control threshold under a full analysis. The correspondent should document the enhanced-diligence steps taken, the conclusion reached, and the basis for that conclusion. If circumstances change – if the designated person acquires additional shares, or if new information about control emerges – the analysis must be revisited.
Escalation to the regulator is the appropriate route where the situation is genuinely ambiguous and the correspondent cannot form a clear view. Under the UAE regime, a pre-clearance mechanism or voluntary escalation to the CBUAE is available in principle, though the procedural path is less codified than, for example, OFAC's specific-licence process or OFSI's licensing route. In our cross-border practice, we advise clients to escalate early rather than late: regulators across all major regimes treat prompt, documented escalation as a significant mitigating factor in enforcement proceedings.
A decision matrix for the three routes:
- Confirmed designation, direct match – immediate freeze and exit; file notification within the required period; preserve all records; do not send an advance warning to the respondent.
- Indirect exposure, ownership below control threshold – enhanced due diligence; documented analysis; periodic review; consider whether other regimes independently require action.
- Ambiguous match or novel control question – preserve the status quo; escalate to the CBUAE or seek legal advice; do not exit prematurely if exit itself could constitute a reportable event.
The position above covers the standard case. Your facts – the counterparty's structure, the goods or services being transferred, the route of the funds, and the specific regimes in play – change the analysis. For a structured review of a live de-risking decision, contact Calder & Vance at info@caldervance.com.
How does the UAE regime compare with OFAC, OFSI, and the EU?
The UAE correspondent-banking de-risking regime sits at the intersection of UN obligations – which are universal – and a growing body of autonomous UAE measures that increasingly diverge from, and in some cases are stricter than, the OFAC and OFSI approaches. For an international correspondent, understanding those divergences is not optional.
On the ownership test, as noted above, the UAE and the UK OFSI approach share a control-based analysis that can capture minority-owned entities, whereas OFAC's 50 percent rule is purely arithmetic. That divergence means a single respondent bank can be simultaneously unrestricted under OFAC and restricted under UAE and OFSI rules, or vice versa.
On licensing, OFAC operates a well-developed specific-licence regime that permits, under defined conditions, transactions that would otherwise be prohibited. OFSI operates a comparable licensing framework under the Sanctions and Anti-Money Laundering Act (SAMLA), with a structured application process. The UAE's licensing or authorisation mechanism for financial-sector transactions is less publicly documented and less frequently used in the correspondent-banking context. Where a correspondent needs a pathway to continue a transaction involving a potentially captured entity, the OFAC or OFSI licensing route is generally better mapped than the equivalent UAE pathway – a relevant difference for a dual-jurisdiction transaction.
On reporting, the EU regime imposes specific asset-freeze reporting obligations on member-state competent authorities, with timelines that practitioners must verify against the current applicable Council regulation. The UK OFSI reporting obligation for suspected designated-person holdings is well-established. The CBUAE's reporting requirements operate on a parallel track and should be treated as independent obligations: a correspondent that satisfies its OFSI or OFAC reporting duty has not automatically satisfied its CBUAE obligation.
On extraterritorial reach, the UAE autonomous sanctions regime does not carry the secondary-sanctions exposure characteristic of the US OFAC regime. OFAC's secondary-sanctions programmes – which can target non-US persons transacting with certain designated counterparties – have no direct analogue in the UAE autonomous framework. That said, a correspondent processing a payment through a US-dollar clearing bank will face OFAC compliance obligations regardless of the UAE position. Dollar-clearing is the hidden extraterritorial vector that turns a UAE-only matter into a dual-jurisdiction compliance event.
Switzerland (SECO), Canada (GAC), and Australia (DFAT) each operate their own autonomous sanctions regimes. For a correspondent with operations in those jurisdictions, a UAE designation may not be implemented under their domestic rules, and a name absent from their lists may still require action under UAE rules. Cross-mapping is essential.
Common risk flags and pitfalls in UAE de-risking decisions
In our experience advising financial institutions on UAE correspondent-banking matters, five risk flags recur with disproportionate frequency.
First, the delayed escalation trap. A compliance officer identifies a potential match and parks it pending further information. The delay itself becomes the problem: if the match is later confirmed, the correspondent may face questions about why activity continued during the review period. Establishing a documented triage protocol – with a hard deadline for escalating from initial alert to compliance decision – is a basic operational control that many institutions still lack.
Second, treating the UAE as a list-only jurisdiction. The UAE regime is not a passive list-screening exercise. The CBUAE's supervised-entity expectations include customer due-diligence standards, ongoing monitoring obligations, and requirements for the quality of the respondent bank's own compliance programme. A correspondent that satisfies its list-screening obligation but fails to assess the respondent's AML/sanctions programme quality is carrying a risk it has not priced.
Third, the single-regime analysis error. A payment may be clean under UAE rules and problematic under OFAC, or clean under OFAC and caught under UAE and EU rules simultaneously. Running each regime's analysis independently, then synthesising the result, is the only reliable method. Shortcuts that test against one list and assume others are equivalent produce material gaps.
Fourth, advance disclosure to the respondent. Where an exit decision is made following confirmation of a designation, tipping off the respondent before the freeze is effected is itself a breach in most regimes. The notification obligation runs to the regulator, not to the designated counterparty. This sounds obvious, but in practice, relationship-driven banking cultures create pressure to communicate exit decisions in advance. That pressure must be resisted.
Fifth, record-keeping gaps. An exit decision that cannot be reconstructed from contemporaneous documents is an exit decision that will look arbitrary or pretextual in a supervisory review. Records should capture: the alert and its source, the ownership-and-control analysis, the compliance decision and its basis, the steps taken to give effect to the decision, and any communications with the regulator. Retention of these records in line with applicable requirements – which advisers should verify against the CBUAE's current guidance – is a basic but frequently under-resourced obligation.
If a transaction has already been flagged, or a relationship has been exited without adequate documentation, an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com for a confidential assessment.
The AUDIENCE_MYTH corrected: de-risking is not the safe default
A persistent assumption in correspondent-banking compliance is that exiting a relationship – de-risking – is always the conservative and therefore safe choice. That assumption is incorrect, and regulators in the UAE, the UK, and increasingly elsewhere have said so explicitly.
An exit decision that cannot be supported by documented analysis exposes the correspondent to allegations of arbitrary or discriminatory conduct. In some circumstances, a premature or undocumented exit is itself a reportable event under AML frameworks. The CBUAE, like the CBUAE's peer authorities, expects that de-risking decisions are reasoned, proportionate, and documented – not reflexive. Wholesale de-risking of an entire correspondent corridor, without counterparty-by-counterparty analysis, is a compliance failure, not a compliance success.
The operationally safe position is: analyse each counterparty individually, apply the correct test for each regime in scope, document the conclusion, and act proportionately. Blanket exit and blanket retention are both wrong. The question is always whether, on the specific facts, the risk is manageable within a documented enhanced-monitoring regime or requires exit.
Related practices
- Correspondent-banking de-risking under OFAC – OFAC-specific procedures, the 50 percent rule, and US licensing options for correspondent banks.
- Correspondent-banking de-risking under UN measures – managing UN Consolidated List obligations across multiple implementing jurisdictions.
- Divesting a sanctioned interest under the Australian regime – DFAT autonomous sanctions and divestment procedures for cross-border transactions.