Calder & Vance International Sanctions & Compliance Counsel

Enforcement & Investigations · UAE

Internal sanctions investigations under UAE: procedure and pitfalls

A trading company based in Dubai discovers, mid-deal, that a payment instruction has passed through a bank account linked to a name on a designated-persons list. The transaction has already settled. The compliance officer escalates. Now what? This is the moment that determines whether a manageable compliance event becomes a formal enforcement matter – and the UAE's regulatory architecture makes the first 48 hours consequential in ways that differ from OFAC or OFSI procedure.

An internal sanctions investigation (a structured internal review to determine whether a potential breach of applicable sanctions obligations has occurred, who was involved, and what remediation is required) under the UAE regime follows a specific sequence: scope the trigger, preserve evidence, map the applicable UAE prohibitions, assess cross-border exposure, and determine whether voluntary disclosure is warranted. The UAE's primary sanctions authority – the Executive Office for Control and Non-Proliferation (CBUAE and the relevant supervisory bodies acting under Federal Decree-Law and Cabinet resolutions) – expects firms to demonstrate a structured, documented response. As of March 2026, the UAE's sanctions obligations derive from UN Security Council resolutions implemented domestically and from the UAE autonomous-sanctions framework, both of which carry criminal and civil enforcement powers.

This guide walks through the procedure step by step, identifies the points where investigations most often go wrong, and flags the interactions with OFAC, OFSI, and EU obligations that arise whenever a UAE-nexus event sits inside a larger cross-border transaction.

Step 1 – Scoping the trigger: what has actually occurred?

The first task in any internal investigation is to define precisely what the potential violation is, which legal obligations it engages, and which regulator has jurisdiction. Under the UAE regime, a trigger event might include: a transaction involving a designated person or entity on the UAE targeted-financial-sanctions list; a payment instruction routed through a blocked account; a trade finance facility supporting a shipment of controlled goods; or a beneficial owner identified, after the fact, as a listed individual. Each trigger has a different regulatory consequence and a different investigation path.

Do not assume that because an event is "small" it is outside the enforcement perimeter. In our practice, the investigations that create the greatest exposure are often not the most complex transactions but the ones where a low-value trigger was not recognised as a trigger at all. A mis-classified shipment, a payment to a third-party intermediary, or a change in beneficial ownership that was never re-screened – these are the events that generate notices.

At this stage, write a one-page scope memorandum. It should identify: the potential breach, the transaction dates, the parties involved, the relevant list (UAE, UN Consolidated List, or another regime's list), and the business line concerned. Do not circulate it beyond the investigation team. Scope creep and premature escalation to business leadership before the facts are established are two of the most common causes of investigation failure.

Step 2 – Evidence preservation and the investigation team

Evidence preservation must happen before any party with access to relevant documents is notified of the investigation. This is not unique to UAE – it is standard practice in any sanctions investigation – but the UAE's corporate-records environment adds particular complexity. Many businesses operating in UAE free zones maintain records across multiple jurisdictions, and the chain of custody for digital communications, payment instructions, and shipping documentation must be established quickly.

Assemble a small investigation team. It should include in-house legal counsel or external sanctions counsel, a compliance lead with access to screening logs and transaction records, and, if the matter touches export controls or dual-use goods, a technical specialist. Keep the team deliberately small at the outset. Wider involvement before the facts are mapped increases the risk of inconsistent accounts and premature disclosure.

Preserve: transaction records, SWIFT messages, screening logs and the version of the list that was active at the relevant date, know-your-customer and beneficial-ownership files, internal approval records, and any relevant email or messaging-platform communications. A practical point: in our experience, firms frequently have the transaction data but cannot produce the screening log for the date of the transaction. This gap is the single most damaging evidentiary deficiency in a UAE enforcement review, because it prevents the firm from demonstrating that a good-faith check was performed.

The investigation team should also conduct a litigation-hold analysis. If external counsel are engaged, the scope of privilege under UAE law differs from the position under English law or US law, and documents generated during the investigation may not attract the same protection. Take advice on this point early.

Step 3 – Mapping the UAE obligations: which rules apply?

The UAE sanctions regime operates on two legal bases. The first is the direct implementation of UN Security Council resolutions into UAE domestic law through Cabinet decisions and executive orders. These create binding obligations on all persons and entities operating within, or through, the UAE. The second is the UAE's autonomous-sanctions framework, which designates individuals and entities under UAE-specific lists maintained and published by the Executive Office.

For the purposes of an internal investigation, the critical question is: which list or lists were breached, and under which legal basis? The answer determines the reporting obligation, the enforcement authority, and the potential penalty range. A breach of a UN-mandated prohibition carries different procedural consequences from a breach of the UAE autonomous list, even if the same transaction is involved.

Financial institutions and designated non-financial businesses and professions (DNFBPs) operating in the UAE are also subject to obligations under the UAE's anti-money-laundering and counter-terrorism-financing regime, which interacts directly with the sanctions regime. A sanctions hit will frequently engage AML reporting obligations as well. Map both before deciding on the disclosure strategy.

One point that is often misunderstood: the UAE's obligations extend to entities operating in the free zones, including the Dubai International Financial Centre and Abu Dhabi Global Market, which have their own regulatory authorities and their own sanctions-related rules. A single transaction may engage the mainland UAE authority, the DIFC Authority, and potentially ADGM – each with its own reporting channel and timeline.

Step 4 – The cross-border dimension: OFAC, OFSI, and EU exposure

A UAE-nexus sanctions event rarely sits in isolation. Most transactions involving UAE counterparties also involve US-dollar clearing, European correspondent banks, or UK-regulated financial institutions. That means a single event can simultaneously engage OFAC, OFSI, and EU obligations. The investigation team must assess each of these exposures independently.

Under OFAC's rules, US-dollar clearing through a US correspondent bank is sufficient to engage US jurisdiction, even if neither party to the underlying transaction is a US person. This is the extraterritorial dimension that surprises many UAE-based businesses most. A transaction that looks entirely local – a UAE exporter, a UAE importer, a UAE bank – can engage OFAC if the payment clears in US dollars through New York. OFAC's 50 percent rule (the rule that treats any entity owned 50 percent or more in the aggregate by one or more blocked persons as itself blocked, regardless of whether it appears on a list) applies to the analysis of counterparty exposure regardless of where the transaction occurs.

Under OFSI, a UK nexus can be established through a UK-incorporated party, a UK correspondent bank, or a transaction involving sterling. UK-incorporated subsidiaries of UAE groups are directly within OFSI's jurisdiction, and the investigation team must check whether any UK entity in the group is a party to, or a facilitator of, the transaction under review.

The EU position is more complex where the transaction involves EU-incorporated entities or EU-currency clearing. EU sanctions regulations impose obligations on all EU persons, wherever they act, and on all transactions conducted in part within the EU. Where a UAE business operates a European entity – as many DIFC-headquartered groups do – the EU exposure must be assessed as a separate track of the investigation.

The practical consequence: the investigation scope, the disclosure decision, and the remediation plan must be designed to address all live jurisdictions in parallel, not sequentially. A voluntary self-disclosure to a UAE authority that omits OFAC exposure does not close the OFAC position. A remediation plan that satisfies OFSI does not satisfy the EU regulator. We regularly advise clients where the UAE event is actually the smallest of three concurrent jurisdictional exposures.

The position above covers the standard cross-border case. Your facts – the counterparty, the currency, the goods, the correspondent banks, the group structure – change the analysis substantially. For an assessment of your specific exposure under the UAE regime and any concurrent OFAC, OFSI, or EU obligations, contact Calder & Vance at info@caldervance.com.

Step 5 – Voluntary disclosure: the decision and the mechanics

The decision to make a voluntary disclosure – a VSD (voluntary self-disclosure to a regulator of an apparent breach, before the regulator identifies it independently) – is the most consequential decision in any internal investigation. Under the UAE regime, voluntary disclosure to the relevant supervisory authority is generally viewed favourably and may reduce the severity of a regulatory response. But a VSD filed without adequate preparation, with incomplete facts, or before the scope of the breach is fully understood can make the position worse, not better.

Before filing, the investigation team should have: a complete transaction map, an identified breach theory (which prohibition was engaged, on which legal basis), a preliminary root-cause analysis, and a draft remediation plan. Filing before these elements are in place invites follow-up requests that expose gaps in the firm's compliance controls and document preservation.

The mechanics differ between the UAE mainland authority and the DIFC and ADGM regulators. Each has its own prescribed reporting format, its own timeline for acknowledgement, and its own process for managing follow-up. The investigation team should not assume that a format designed for one authority will satisfy another, even if the underlying transaction is the same.

If the cross-border analysis in Step 4 identified concurrent OFAC exposure, the VSD strategy must address OFAC separately. OFAC has its own VSD programme under IEEPA, with its own requirements for content, timing, and the format of the submission. A UAE VSD does not substitute for an OFAC VSD, and the two processes must be coordinated but kept formally separate. The same logic applies to OFSI, which has its own reporting and disclosure procedure under the relevant UK sanctions regulations.

If a transaction has already been flagged by a counterparty, a correspondent bank, or a regulator, or if a filing has been refused, an early review of the disclosure options can preserve routes that narrow significantly with time. Contact Calder & Vance at info@caldervance.com for a confidential initial assessment.

Step 6 – Remediation, record-keeping, and lessons learned

An internal investigation that concludes without a documented remediation plan has not concluded. UAE regulatory authorities – like OFAC, OFSI, and EU supervisors – assess not only whether a breach occurred but whether the firm has taken credible steps to prevent recurrence. Remediation is the practical evidence that the compliance failure has been addressed at its root cause.

A well-structured remediation plan should address: the specific control gap that permitted the breach (a failure in screening logic, a gap in beneficial-ownership mapping, an inadequate dual-use classification process, or a breakdown in approval escalation); the corrective action taken (re-screening, system update, training, revised policy); the timeline for implementation; and the governance mechanism that will confirm completion. The plan should be signed off at the appropriate level of management and retained as part of the investigation record.

Record-keeping is itself an obligation, not merely good practice. Under the applicable UAE rules and under OFAC guidance, firms are expected to retain the records of a sanctions review – including the investigation file, the disclosure correspondence, and the remediation documentation – for a defined period. The precise retention requirement varies by regulator and by instrument; verify the current position before implementing a document-retention schedule, because it may differ from the five-year standard applicable in some other regimes.

The lessons-learned phase is where the investigation generates its lasting value. In our experience, firms that treat the post-investigation review as a compliance-improvement exercise – rather than a box-ticking exercise – reduce the likelihood of a repeat event significantly. This means testing the revised controls against the scenario that generated the original breach, not merely updating the written policy.

Common pitfalls: where UAE investigations go wrong

The most common failure point is not the breach itself; it is the response. Investigations that expand without a defined scope, that circulate preliminary findings to business leadership before the facts are established, or that conflate the UAE, OFAC, and EU disclosure obligations into a single process routinely produce worse outcomes than those that follow a structured, phased approach.

A common myth deserves direct correction: "if the transaction is purely local – UAE parties, UAE bank, UAE currency – then OFAC and OFSI are irrelevant." This is incorrect. The extraterritorial reach of OFAC's prohibitions extends to any transaction that clears in US dollars, regardless of the location of the parties. The involvement of a UK correspondent bank, a UK-incorporated entity in the chain, or a sterling component engages OFSI. The "purely local" transaction is far rarer than many compliance teams assume.

A second frequent error is failing to distinguish between a UN-mandated list hit and a UAE autonomous-list hit. The legal basis, the reporting obligation, and the enforcement authority differ. Treating them as interchangeable leads to filings that reach the wrong authority, on the wrong timeline, with the wrong content.

Third: the investigation team is too large. Wider circulation of early findings before the scope is established creates inconsistent accounts, increases the risk of inadvertent disclosure, and can compromise the firm's position if the matter proceeds to formal enforcement. Keep the team small; expand it only when the facts support it.

Fourth: privilege is not analysed at the outset. Under UAE law, the scope of legal professional privilege differs from the English or US position. Documents generated during the investigation – including internal memos, interview notes, and the scope memorandum – may not attract the protection that counsel and the investigation team assume. This matters because an enforcement inquiry may subsequently seek production of those documents.

Fifth: the remediation plan is prepared after the disclosure, not before. Filing a VSD without a remediation plan in hand signals to the regulator that the firm has not yet understood the root cause of the breach. Prepare the plan as part of the investigation, not as a response to the regulator's first follow-up letter.

Related practices

Frequently asked questions

What are the steps to run an internal investigation under UAE?
The procedure follows six stages: scope the trigger event precisely; preserve evidence before any wider notification; map the applicable UAE prohibitions and identify the relevant list and legal basis; assess concurrent OFAC, OFSI, and EU exposure; decide on voluntary disclosure and prepare the submission with complete facts and a draft remediation plan; and close with a documented remediation and lessons-learned review. Each stage should produce a written record that can be produced to a regulator if the matter proceeds to formal inquiry. The sequence is not advisory; departing from it without good reason creates evidentiary gaps that are difficult to close later.
What is the most common mistake in internal sanctions investigations?
The most common error is treating the investigation as a single-jurisdiction exercise when the facts engage multiple concurrent regimes. A UAE-nexus event that involves US-dollar clearing, a UK correspondent bank, or an EU-incorporated group entity simultaneously engages OFAC, OFSI, and EU obligations. A disclosure strategy that addresses only the UAE authority leaves the other exposures open. The second most common error is filing a voluntary disclosure before the investigation is complete – before the scope of the breach, the root cause, and the remediation plan are established – which invites follow-up that exposes further gaps.
How does UAE differ from other regimes here?
The UAE regime is distinctive in three respects. First, it operates on a dual legal basis – UN-mandated obligations and UAE autonomous-sanctions measures – each with a different authority, reporting channel, and enforcement consequence; distinguishing the two is essential before any disclosure decision. Second, entities operating in the DIFC and ADGM free zones face a separate regulatory layer with their own rules and reporting requirements, running in parallel with the mainland UAE authority. Third, the scope of legal professional privilege in the UAE differs from the English and US positions, which affects how investigation documents should be generated and retained from day one.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.