Calder & Vance International Sanctions & Compliance Counsel

Cross-Border Transactions & Diligence · UAE

Sanctions due diligence in M&A under UAE: a practical guide

A multinational investment team reaches final-bid stage on a target headquartered in the UAE. The data room is open. The vendor's lawyers are pressing for a clean mark-up. Then the compliance officer flags a silent shareholder in a holding layer above the target – a name that appears on a UN Consolidated List. The deal is not dead. But every day without a clear sanctions analysis is a day of mounting exposure for the acquirer.

Sanctions due diligence in M&A under the UAE regime requires a structured review of the target's ownership and control chain against the UAE's autonomous sanctions lists, the UN Security Council Consolidated List as directly applied in the UAE, and – critically – the extraterritorial reach of OFAC and the EU Council regulations. The UAE applies UN-mandated measures directly and maintains its own autonomous sanctions (designations issued independently of UN authority) through the UAE Executive Office for Control and Non-Proliferation. A clean UAE screen is necessary but not sufficient for a cross-border deal.

This guide walks through the diligence process step by step: what to screen, how to apply the ownership and control tests across the UAE and the major extraterritorial regimes, where cross-border deals most commonly go wrong, and when to bring in specialist sanctions counsel. As of January 2026, the UAE has expanded its autonomous designations list and strengthened its enforcement posture, making structured pre-signing diligence more consequential than ever.

Step 1: Understand the governing authority and legal basis in the UAE

The UAE's sanctions regime is administered by the Executive Office for Control and Non-Proliferation (EOCN), which maintains the national UAE Sanctions List and implements UN Security Council measures under domestic law. The legal basis flows from UAE Cabinet resolutions and federal legislation giving effect to UN Chapter VII obligations. Financial institutions and non-financial businesses in the UAE are required to screen against both the UAE list and the UN Consolidated List as a matter of mandatory compliance under the applicable UAE anti-money-laundering and counter-proliferation-financing rules.

The EOCN publishes updates to the national list, and its guidance requires immediate action – including asset freezing and transaction blocking – when a match is identified. In our cross-border practice, we observe that many acquirers treat UAE diligence as a single-list screen. That misses the structure. The UAE applies UN measures directly, meaning that an entity designated only by the UN Security Council carries the same domestic legal consequence as one on the national list. A well-run diligence process screens both in parallel from the outset.

The EOCN also coordinates with the UAE Central Bank and the Financial Intelligence Unit on enforcement. This is not a regime where self-identification of a violation and quiet correction is straightforwardly available. Understanding the authority and its enforcement channels is therefore stage one of any serious diligence exercise.

Step 2: Map the ownership and control chain before you screen

Accurate screening in UAE M&A begins with mapping the full ownership and control chain of the target before a single name is run against a list. The practical reason is simple: the entity you are buying is often not the entity that carries the risk. Risk sits in the layers above it – through intermediate holdcos, nominee arrangements, or trust structures common in Gulf-region deal architectures.

UAE corporate structures frequently include free-zone entities, onshore mainland companies, and offshore vehicles registered in the DIFC or ADGM. Each layer can introduce a different beneficial owner. Under both UAE domestic rules and international anti-money-laundering standards, beneficial ownership must be traced through the chain. For a mid-market private equity deal, this mapping exercise alone can take a week of structured document review before screening begins.

Parallel to the UAE analysis, you must apply the 50 percent rule (OFAC's rule treating entities owned 50 percent or more, in the aggregate, by blocked persons as themselves blocked) and the EU and UK ownership and control tests (which extend to entities directly or indirectly owned or controlled by a listed person, with control assessed more broadly than a mechanical threshold). These tests operate on the same ownership map, but they reach different conclusions in some fact patterns – particularly where ownership is fragmented across multiple blocked parties who collectively pass the OFAC threshold but individually do not. Have you built an ownership chart that can be interrogated against each of these three tests simultaneously?

Step 3: Screen against the correct lists – UAE, UN, and the extraterritorial regimes

Screening in UAE M&A diligence is a multi-list exercise. The minimum scope for a cross-border deal is: the UAE Sanctions List, the UN Security Council Consolidated List, the OFAC SDN List (if the acquirer or target has US-person nexus, US-dollar clearing, or US-incorporated entities in the structure), the EU Consolidated List (if EU-person or EU-nexus is present), and the OFSI Consolidated List (for UK-nexus transactions). Secondary-sanctions risk under OFAC broadens the scope further: even non-US parties can face consequences for transactions that OFAC considers materially supportive of a designated person.

In our practice we regularly advise acquirers who run a single-jurisdiction screen and assume extraterritorial exposure is someone else's problem. It is not. A UAE-domiciled target with a correspondent-banking relationship routed through a US-dollar correspondent, or with a subsidiary incorporated in the British Virgin Islands, carries OFAC and OFSI exposure regardless of where the acquirer is headquartered. For more on how US-dollar clearing creates OFAC nexus for non-US parties, see our analysis of correspondent banking and de-risking under OFAC.

The screening itself must be run at the point of signing (or as close to it as deal mechanics allow) and again at completion. List changes between signing and closing have caused real problems in deals we have reviewed. A name added to the SDN List between exchange and completion can turn a consented acquisition into a prohibited transaction – without any fault on the acquirer's part. Building a re-screen obligation into the SPA is therefore not a formality; it is material risk allocation.

Step 4: Apply the ownership tests across each regime

Once the ownership map is built and the lists are identified, the next step is applying each regime's test to the mapped structure. The UAE and UN regimes look for persons on their respective lists appearing in the ownership or control chain. The OFAC test is the mechanical 50 percent or more aggregate threshold. The EU and UK tests are broader: they reach entities not only owned but also controlled by a designated person, and control is assessed through influence over management decisions, veto rights, and contractual arrangements – not only through equity.

These differences can produce divergent conclusions on the same fact pattern. Consider a target where a listed individual holds 45 percent of equity and exercises effective management control through a shareholders' agreement. OFAC's 50 percent rule is not technically triggered. But the EU ownership-and-control test and the UK equivalent almost certainly would capture the entity. For a deal with EU-nexus, that conclusion is material even if the OFAC analysis is clean. Cross-border M&A diligence therefore cannot simply pick the most convenient test. It must apply each regime's test fully and record the conclusion against each.

Where a hit is identified, the question is whether it is a true match or a false positive. Effective de-duplication – confirming that a screened name is or is not the same person as the listed individual – requires documentary verification: passports, corporate registration documents, date-of-birth confirmation, and address records. For private targets in the UAE, obtaining this documentation requires thoughtful engagement with the vendor's legal team; it is best built into the diligence letter from the outset rather than introduced as a late request.

What are the common risk flags in UAE M&A sanctions diligence?

Several patterns recur in UAE M&A diligence that elevate sanctions risk beyond the baseline. The first is nominee shareholding: under UAE onshore corporate law, foreign ownership restrictions have historically been managed through nominee arrangements. The beneficial owner behind a nominee may not appear on the face of the corporate register. Any structure involving a nominee requires diligence into the beneficial owner's identity, not only the nominee's.

The second recurring flag is complex free-zone structuring. Free zones such as the DIFC, ADGM, JAFZA, and others each operate under their own corporate laws and disclosure regimes. Ownership information in free-zone entities is not always centrally accessible. Where a target has free-zone holding layers, the diligence exercise must go to the free-zone authority's own records and to the constitutional documents of each entity.

Third, third-country connected parties present elevated risk in UAE deals. The UAE's geographic position and its role as a regional trading and finance hub mean that targets frequently have commercial relationships – joint ventures, agency agreements, supply contracts – with counterparties in jurisdictions subject to comprehensive or sector-specific sanctions programmes. These relationships do not automatically prohibit a transaction, but they must be reviewed: do they involve prohibited activities under any of the applicable regimes? Do they generate revenue that would be blocked post-acquisition?

Finally, watch for pre-existing licence positions. A target may have obtained authorisations under one regime to engage in activities that another regime prohibits without licence. If the target is acquired, those licences do not automatically transfer to the acquirer. In our experience, this is one of the most underweighted risks in UAE cross-border deals – and one of the most consequential post-closing discoveries.

How does UAE sanctions diligence differ from OFAC and EU approaches?

The UAE regime differs from OFAC and EU practice in three respects that directly affect how diligence is structured. First, the UAE does not apply its own extraterritorial measures to the same breadth as OFAC does under IEEPA. OFAC's secondary-sanctions authorities can reach non-US parties transacting with designated persons, even in transactions with no US touchpoint. The UAE autonomous sanctions do not operate on that model: their reach is primarily territorial and transactional within UAE jurisdiction. This distinction matters for deal structuring – but it does not eliminate the risk, because OFAC and EU extraterritorial measures still apply to the acquirer's own position.

Second, the UAE does not have a general-licensing regime of the breadth available under OFAC or the EU. OFAC maintains general licences (standing authorisations for defined categories of transactions) and specific licences (case-by-case authorisations), and the EU Council issues derogations through Council decisions. The UAE's authorisation architecture is less developed. Where a UAE-law prohibition is identified, there is no equivalent off-the-shelf general licence to check. The analysis requires a direct engagement with the EOCN or with local counsel in the relevant jurisdiction.

Third, the UAE's enforcement posture has historically been less public than OFAC's. OFAC publishes enforcement actions with penalty amounts, findings-of-fact, and compliance commitments. The UAE enforcement record is less systematically published, which can create a misleading impression that enforcement risk is low. In our practice, we treat the absence of published enforcement as a data point about transparency, not about risk appetite. The EOCN's powers and its coordination with international enforcement partners make enforcement real.

For an understanding of how the UN Consolidated List applies across multiple regimes – including the UAE – see our companion guide on sanctions diligence in M&A under the UN regime. For trade-connected transactions involving maritime elements, our guide on maritime shipping sanctions under the Australian regime addresses a further layer of exposure that arises in some Gulf-region supply-chain deals.

Step 5: Document findings, escalate hits, and structure the transaction

The output of a sanctions diligence exercise in M&A is a documented findings memorandum, not a simple clear/no-clear conclusion. Every list screened, every entity and individual reviewed, every hit considered and resolved as a true match or false positive, and the methodology applied to each conclusion must be recorded. This documentation serves two functions: it supports a deal-sign-off decision, and it constitutes the evidential basis for any voluntary self-disclosure or enforcement defence if a question arises later.

Where a true hit is identified, the escalation sequence matters. The immediate question is whether the transaction is prohibited as structured. That requires applying the prohibition rules of each relevant regime to the specific transaction, not a general conclusion about the target. A prohibited transaction is one that meets the specific elements of a prohibition – involving a blocked person, in a covered category of activity, within the regime's jurisdiction. If the transaction is prohibited, the next question is whether an authorisation is available and whether to apply for it.

If the hit is on a minority shareholder below relevant thresholds, the next question is whether the structure can be modified – for example, through a condition precedent requiring the vendor to procure the exit of the problematic interest before completion – without itself creating a sanctions problem. This is where transactional structuring and sanctions law intersect. The modification must not itself constitute a prohibited transaction under any applicable regime.

In a recent matter, a financial-sector acquirer identified a listed minority shareholder in a second-tier holding entity of a UAE target. We mapped the ownership consequences against OFAC's 50 percent rule, the EU ownership-and-control test, and the UAE domestic prohibitions simultaneously. The deal was restructured with a condition precedent requiring a buy-out of the relevant interest at a fair-value price, documented as an independent commercial transaction. The matter was resolved at the pre-signing stage, preserving the deal timeline. No outcome of this kind is guaranteed; results depend entirely on the specific facts and the regimes in play.

If the transaction proceeds to signing with a known risk – for example, a potential match under active investigation – the representations and warranties in the SPA must reflect the actual risk position. Giving clean sanctions warranties when a known issue exists creates legal exposure for the warrantor and may constitute a misrepresentation. In our experience, the instinct to close at pace is understandable, but it cannot override the obligation to record accurately what is known.

Related practices

Frequently asked questions

What are the steps to run sanctions diligence in a deal under UAE?
Sanctions diligence in UAE M&A follows five structured steps. First, confirm the governing authority – the EOCN administers the UAE regime, which directly applies UN Security Council measures and autonomous UAE designations. Second, map the full ownership and control chain of the target. Third, screen all persons and entities in the chain against the UAE, UN, OFAC, EU, and UK lists as the deal's nexus requires. Fourth, apply each regime's ownership or control test to any hits. Fifth, document all findings formally and resolve or escalate any true matches before signing. A re-screen at completion is also required given the risk of list changes between exchange and closing.
What is the most common mistake in sanctions due diligence in M&A?
The most common error is running a single-jurisdiction screen and treating it as sufficient. In UAE M&A, a clean domestic screen does not address OFAC's secondary-sanctions reach, the EU ownership-and-control test, or the UK OFSI position – any of which can prohibit the transaction independently of whether the UAE rules bite. A related error is screening only the target entity and not the full ownership chain above it, which is where designation risk most often sits in Gulf-region deal structures involving multi-layer holdcos or nominee arrangements.
How does UAE differ from other regimes here?
Three differences are material. The UAE does not apply extraterritorial measures with the breadth of OFAC's secondary-sanctions authorities. The UAE lacks a comprehensive general-licensing architecture comparable to OFAC's or the EU's, so there is no standing authorisation to check when a prohibition is identified – direct EOCN engagement is required. And UAE enforcement actions are not systematically published, which can obscure the real level of enforcement risk. In cross-border deals, these differences mean the UAE analysis must be run alongside, not instead of, an OFAC and EU screen.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.