Calder & Vance International Sanctions & Compliance Counsel

Licensing & Authorizations · UAE

How to choose the right licence route under UAE

A trading house based in the Gulf closes what it believes is a straightforward commodity deal. The counterparty is not listed. The goods are not restricted. Yet a bank in a third jurisdiction refuses to clear the payment, citing potential exposure under the UAE's autonomous sanctions regime. The compliance officer is left asking a question that should have been settled weeks earlier: is this transaction permitted outright, does it need a specific authorisation, or does an existing general authorisation already cover it?

Choosing between specific and general licences under the UAE regime requires a structured analysis: identify the applicable prohibition, determine whether any standing authorisation already applies, and – if not – assess whether the facts meet the threshold for a case-by-case application. The UAE's autonomous sanctions regime operates alongside United Nations Security Council obligations, and the interaction between the two determines which route is open. Neither route is automatic, and the cost of choosing the wrong one is a blocked transaction, a stalled payment, or an enforcement referral.

This guide sets out a decision sequence for compliance teams and general counsel working through that question, with comparisons to how OFAC, OFSI, and the EU handle equivalent decisions.

What is the UAE sanctions regime and who administers it?

The UAE administers its own autonomous sanctions programme through the Executive Office for Control and Non-Proliferation (EOCN), and it implements UN Security Council measures as a matter of treaty obligation under the UN Charter. These are two distinct legal sources with different procedural implications for licensing.

EOCN maintains the UAE's national target list and administers authorisation requests for transactions that would otherwise be prohibited. The regime covers asset freezes and dealing restrictions against designated individuals and entities, and it applies to persons operating in or through the UAE financial system – including branches of foreign banks, free-zone entities, and payment intermediaries. In our practice, one of the most frequent analytical errors is treating the UAE as a pass-through jurisdiction rather than a full regime participant with its own list, its own enforcement posture, and its own authorisation infrastructure.

The UN Consolidated List operates in parallel. Where a person is designated only at the UN level – not replicated on the UAE national list – the applicable obligation derives from Security Council resolutions given effect in UAE law. The practical importance of that distinction is that the authorisation route, the competent authority, and the procedural timeline can differ depending on which list generates the prohibition.

As of June 2026, businesses with UAE-nexus transactions must run two parallel screening exercises: one against the UAE national list maintained by EOCN, and one against the UN Consolidated List. Relying on a single list produces gaps that neither internal audit nor a regulator will accept as a complete answer.

What is the difference between a general authorisation and a specific authorisation under the UAE regime?

A general authorisation (sometimes called a general licence in analogous regimes) is a standing permission that EOCN or the relevant competent authority issues in advance, defining a category of transactions that are permitted without the need for a separate application in each case. A specific authorisation is a case-by-case approval granted on the particular facts of an individual transaction or relationship.

General authorisations typically cover activities in the public interest or otherwise systemically necessary: humanitarian transfers, certain legal fees, maintenance payments for frozen accounts, and limited categories of permitted business with designated parties. If a transaction falls within the precise scope of a published general authorisation, no further approval is required. The authorisation is self-executing, subject to record-keeping and, in some cases, notification obligations.

Specific authorisations are required when a transaction does not fit any available general authorisation. The applicant submits a request to EOCN, setting out the transaction, the parties, the purpose, the applicable prohibition, and the grounds on which approval is sought. EOCN reviews the request against the statutory criteria. The authority retains full discretion; there is no entitlement to approval even where the grounds appear strong.

The distinction matters for timing. Where a general authorisation applies, a transaction can – in principle – proceed promptly once the compliance team has documented its reliance on the relevant instrument. A specific authorisation application introduces a waiting period that should be built into deal timelines from the outset, not treated as a contingency measure after a payment has already been refused.

How does the authorisation decision sequence work in practice?

The decision sequence has four steps, each of which must be completed before moving to the next.

Step 1: Establish whether the transaction is prohibited at all. Begin with a full screening of all parties – the counterparty, its beneficial owners, the intermediary banks, and the commodity or service involved – against both the UAE national list and the UN Consolidated List. If no designated party or prohibited item is present, no authorisation of any kind is required. This step is where many firms lose time by jumping to licensing questions before confirming that a prohibition actually applies.

Step 2: Identify the source and scope of the prohibition. If a designated person is involved, identify whether the prohibition arises from the UAE national list, from a UN Security Council measure, or from both simultaneously. This matters because the available authorisation instruments, and in some cases the competent authority, differ by source.

Step 3: Check all published general authorisations for coverage. EOCN publishes general authorisations for defined categories. Run the transaction facts against each instrument. Coverage must be exact: a transaction that is similar to, but not squarely within, a general authorisation does not qualify. In our experience, firms regularly overread the scope of general authorisations, assuming coverage that a regulator would not confirm. If there is any doubt about coverage, treat it as non-coverage and proceed to step four.

Step 4: Assess specific authorisation eligibility and apply. If no general authorisation covers the transaction, determine whether the grounds for a specific authorisation are met – principally that the purpose is legitimate, the counterparty's involvement is unavoidable, and the authorisation would not undermine the policy objective of the underlying designation. Prepare the application with full supporting documentation, submit to EOCN, and do not proceed with the transaction until approval is granted.

Is there ever a case where a firm can proceed without going through all four steps? Only if the facts have already been fully analysed by qualified counsel and the conclusion is that no designated person and no prohibited item is involved. Proceeding on assumption rather than analysis is itself a compliance failure.

How does the UAE approach compare with OFAC, OFSI, and the EU?

The UAE regime follows the same structural distinction between general and specific authorisations as OFAC, OFSI, and the EU, but the substantive tests, procedural timelines, and available categories differ in ways that matter for cross-border transactions.

Under OFAC, general licences (standing authorisations published in the US Federal Register) cover a broad range of activities including personal remittances, certain food and medicine shipments, and professional services under specific programme conditions. OFAC also processes specific licence applications on a case-by-case basis. OFAC's published guidance indicates that licence applications can take months to resolve, and in complex cases the timeline extends further. Critically, the 50 percent rule under IEEPA-based sanctions means that an entity owned 50 percent or more by a blocked person is itself treated as blocked – a test that applies independently of whether the entity appears on the SDN List. This aggregation rule has no direct analogue in UAE national list practice, which creates divergence risks for transactions touching both regimes.

Under OFSI in the UK, the licensing regime under the Sanctions and Anti-Money Laundering Act ("SAMLA") involves six published licensing grounds – including humanitarian assistance, legal expenses, and the prior obligations ground – and OFSI issues both general licences and specific licences. The ownership and control test under UK law goes beyond a mechanical ownership percentage: it also captures entities that a designated person controls by other means, even without a majority ownership stake. That broader test means that a counterparty cleared under a UAE national-list screening may still require additional analysis for UK-nexus portions of the same transaction.

The EU licensing regime under the relevant Council regulations similarly provides specific licences (individual authorisations) and, in some cases, general licences. Competent authorities in member states administer EU licensing; there is no single EU-level licensing office. The EU General Court provides a route to challenge designations, but it does not adjudicate licensing decisions. EU sanctions also carry ownership and control tests that, like the UK, capture entities controlled by designated persons through contractual or structural means falling short of majority ownership.

What this comparison produces for a compliance team advising on a UAE-nexus transaction is a layered obligation: the UAE analysis must be completed, and then each additional regime with a nexus to the transaction – OFAC if US persons or US-origin goods are involved, OFSI if UK entities are party, EU rules if EU persons or goods are implicated – must be analysed separately. The strictest applicable prohibition governs; obtaining a UAE specific authorisation does not authorise the same transaction under OFAC.

We regularly advise clients on exactly this multi-regime layering problem. The question is not which regime applies, but which of several applicable regimes is most restrictive and what the combined licensing burden looks like.

What are the most common risk flags in UAE licensing decisions?

The most common risk flags arise not from the most obvious sanctions issues but from the gaps that a partial analysis leaves open.

Overreliance on a general authorisation. A general authorisation has a defined scope. It covers what it says, no more. Firms extend coverage by analogy – assuming that if humanitarian transfers are permitted, certain related commercial activities must also be permitted. That reasoning does not hold. A regulator reviewing a transaction after the fact will apply the text of the authorisation strictly.

Failure to update the analysis when deal terms change. An authorisation granted – whether general or specific – is issued in respect of the transaction as described. If the parties, the amounts, the goods, the route, or the intermediaries change materially, the existing authorisation may no longer cover the revised transaction. The compliance team must reassess. We have acted for clients where a mid-deal amendment invalidated an existing authorisation without anyone in the deal team recognising the consequences.

Incomplete ownership and control mapping. Even where the direct counterparty is not designated, a beneficial owner at a higher level may be. The UAE regime, like OFAC and OFSI, requires analysis of the ownership chain, not merely the contractual counterparty. Relying on a counterparty's self-certification, without independent verification against the relevant lists, is not a sufficient compliance procedure.

Timing errors on specific authorisation applications. A specific authorisation cannot be granted retroactively in most cases. Proceeding with a transaction on the assumption that an application will succeed – before the approval is in hand – constitutes dealing without authorisation. The enforcement consequence of that error can be significant, and it cannot always be remedied by a subsequent voluntary disclosure.

Failing to address secondary-sanctions risk. A UAE-authorised transaction may still expose non-UAE persons – particularly US persons, US financial institutions, or entities with US-origin goods in the supply chain – to secondary-sanctions exposure under OFAC's extraterritorial programmes. Secondary-sanctions risk does not disappear because the primary jurisdiction has granted an authorisation.

When does the analysis change? Decision branches by situation

The authorisation question presents differently depending on three key situational variables: who the designated person is, what the transaction involves, and which other regimes have a nexus.

Situation A: A UN-listed entity is the counterparty, and no UAE general authorisation covers the transaction. The applicable path is a specific authorisation application under the UAE instrument implementing the relevant Security Council resolution, and potentially a parallel application to the UN Security Council committee if the UN framework itself provides for national derogations. The timeline for Security Council committee processes extends well beyond typical commercial deal cycles. If the transaction cannot be restructured to remove the designated party, a decision must be made early about whether to pursue authorisation at all.

Situation B: A UAE-nationally-listed entity (not UN-listed) is the counterparty, and a general authorisation plausibly applies. Complete the four-step decision sequence. Document the analysis in writing at the time of the decision, not after a query arises. Retain the documentation for the period required by the applicable record-keeping rules, which under UAE practice aligns broadly with the international standard of at least five years, though the precise requirement should be verified in the applicable instrument.

Situation C: The counterparty is not designated but has a beneficial owner approaching a relevant ownership threshold. Do not apply the general authorisation analysis as if ownership were conclusively absent. Obtain a full beneficial-ownership certificate, run it against both lists, and map aggregated holdings. If the combined holdings of any listed person reach a material level, treat the entity as potentially caught and obtain legal advice before proceeding.

Situation D: The transaction has both UAE and OFAC nexus. Secure the UAE authorisation first (since UAE-nexus activity is the territorial question), then conduct the OFAC analysis independently. The two authorisation procedures run in parallel but produce separate outcomes. Neither one substitutes for the other.

What documentation supports a UAE licensing application?

A well-prepared specific authorisation application under the UAE regime includes, at minimum, the following elements.

First, a clear description of the transaction: the parties, the amounts (or volume), the goods or services, the payment route, and the timeline. Incomplete or vague transaction descriptions are the most common reason EOCN requests further information, extending the processing timeline.

Second, an identification of the specific prohibition engaged: the designation that applies, the list on which it appears, and the conduct that would be prohibited absent authorisation. The application must be precise about what it is seeking permission to do.

Third, the legal grounds for the authorisation: the statutory criterion on which the applicant relies and the factual basis for it. Grounds that are commonly available include humanitarian necessity, prior contractual obligation, or the avoidance of a disproportionate impact on a non-designated third party. The application should address each criterion squarely rather than in general terms.

Fourth, supporting evidence: corporate documents, contractual records, evidence of the legitimate purpose, and – where relevant – certifications from counterparties or relevant authorities in other jurisdictions. An application that asserts grounds without evidencing them is unlikely to succeed.

Fifth, a proposed compliance structure for the authorised transaction: how the authorised funds or goods will flow, what controls will be applied, and how the authorisation conditions will be monitored. EOCN, like OFAC and OFSI, expects applicants to demonstrate that they can operationalise the authorisation without risk of diversion.

Record-keeping obligations attach from the moment a general authorisation is relied upon or a specific authorisation application is submitted. The general international standard for sanctions record-keeping is five years, and UAE practice broadly tracks this, though the applicable instrument should be verified in each case before reliance.

Related practices at Calder & Vance that bear on UAE licensing matters:

A common misconception: UAE authorisation is not a universal clearance

A persistent myth in cross-border compliance practice is that obtaining a UAE-specific authorisation resolves the full compliance picture for a transaction touching UAE parties. It does not.

A UAE authorisation is a permission granted by the UAE competent authority under UAE law. It has no legal effect on the obligations of US persons under OFAC rules, UK persons under OFSI rules, EU persons under the relevant Council regulation, or non-UAE financial intermediaries clearing in other jurisdictions. Each regime must be addressed on its own terms.

This is not a technical nicety. It is a frequent source of enforcement risk. We have advised on matters where a UAE authorisation was in place and fully documented, and a correspondent bank in a third jurisdiction still declined the transaction on its own compliance assessment. The UAE authorisation did not bind the correspondent. Understanding this limitation before the transaction is structured is materially more valuable than discovering it after a payment has been blocked.

The inverse also applies. A transaction may be fully clear under OFAC – no US person, no US-origin goods, no US dollar clearing – and still require a UAE authorisation where a UAE-nexus exists. Jurisdictional analysis must be conducted for every regime with a plausible connection to the transaction, in sequence, not by assumption.

Frequently asked questions

What are the steps to choose the right licence route under UAE?
The decision sequence has four steps: first, confirm whether the transaction is prohibited at all by screening all parties against both the UAE national list and the UN Consolidated List; second, identify which list and which instrument generates the prohibition; third, check whether any published general authorisation covers the transaction precisely as structured; and fourth, if no general authorisation applies, assess whether the grounds for a specific authorisation are met and prepare a full application to EOCN. None of these steps can be skipped. Document each in writing at the time the analysis is conducted, not after the fact.
What is the most common mistake in choosing between specific and general licences?
The most common error is overreading the scope of a general authorisation – assuming that because a category of transaction is covered, adjacent or similar transactions are also covered. General authorisations are narrowly construed by regulators. If a transaction does not fall squarely within the published text of the instrument, it requires a specific authorisation. A second common error is treating a UAE authorisation as resolving the compliance position under OFAC, OFSI, or the EU, which it does not. Both errors can result in an unauthorised transaction and potential enforcement exposure.
How does UAE differ from other regimes here?
The UAE runs two parallel frameworks: its own autonomous national list administered by EOCN, and UN Security Council measures implemented as treaty obligations. Unlike OFAC, the UAE does not apply a mechanical 50 percent ownership rule that automatically blocks entities above that threshold; ownership and control analysis under the UAE regime requires examination of the applicable instrument rather than reliance on a universal rule. Unlike the EU, there is a single national competent authority for authorisations rather than member-state-level licensing bodies. Unlike OFSI, the UAE does not publish a codified set of named licensing grounds in the same form, so practitioners must work from the published authorisations and the statutory criteria case by case.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.