Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · UAE

Sanctions risk assessment under UAE: scope and obligations

A trading house with operations across the Gulf discovers that a counterparty it has used for two years has a beneficial owner who appears on an international sanctions list. The question is immediate: has every transaction since the relationship began been a breach? What does the UAE sanctions regime require the business to do right now? And how does that obligation compare with what OFAC, OFSI, or the EU would demand of the same business?

Sanctions risk assessment under the UAE regime is a structured obligation requiring businesses to identify, evaluate, and mitigate exposure to sanctioned parties before and during any transaction. The UAE Executive Office for Control and Non-Proliferation – acting under the legal framework established by domestic Cabinet decisions and aligned with UN Security Council resolutions – administers the regime. As of August 2026, the UAE maintains its own autonomous sanctions list alongside full implementation of UN consolidated designations, and regulated entities are required to screen against both.

This briefing covers the governing authority, the scope of the obligations, the ownership and control test as it applies in the UAE, the key risk flags practitioners encounter, and when to involve sanctions counsel. Where the UAE position diverges from OFAC, OFSI, or EU practice, we note it directly.

Who governs sanctions risk assessment in the UAE?

The primary authority for sanctions in the UAE is the Executive Office for Control and Non-Proliferation (EOCN), which administers the UAE's autonomous targeted financial sanctions and implements Security Council obligations. Two further bodies are relevant to any serious risk assessment: the UAE Central Bank, which supervises financial institutions for sanctions compliance and issues binding guidance, and the Ministry of Economy, which bears responsibility for anti-money-laundering and counter-proliferation controls across designated non-financial businesses.

In our cross-border practice, businesses frequently underestimate how layered the UAE authority structure is. The EOCN publishes and maintains the UAE Local Terrorist List alongside the UN Consolidated List. Financial institutions are expected to screen against both in real time. Non-financial businesses – trading companies, free-zone operators, logistics providers – carry the same legal obligation, even though supervisory intensity differs.

The UAE's approach reflects its position as a signatory to and implementer of UN Chapter VII resolutions. Every designation made by the UN Security Council Committee is automatically operative in the UAE. Autonomous designations made by the UAE itself sit alongside those UN-derived entries. A sanctions risk assessment conducted only against one list is, by definition, incomplete.

What does that mean for a multinational running a single global screening programme? It means the UAE feed is a distinct data stream that cannot be replaced by an OFAC or EU list check. We regularly advise clients who have precisely this gap – robust OFAC and EU coverage, but no live connection to the EOCN Local Terrorist List or to the UAE Central Bank's published updates.

What is the legal basis for the obligations?

The UAE sanctions regime draws its authority from Cabinet decisions and ministerial resolutions that translate UN Security Council obligations into domestic law and establish the UAE's autonomous targeted-financial-sanctions capacity. No domestic statute equivalent to the US IEEPA or the UK SAMLA exists; instead, the legal instrument is a series of periodically renewed and amended Cabinet-level acts, supplemented by Central Bank guidance circulars for the financial sector.

For businesses this means two things. First, the legal basis is less codified than the OFAC or OFSI model. Updates to obligations – new designations, new procedural requirements, revised screening expectations – may come through administrative guidance rather than gazetted regulation, and the interval between updates can be short. Second, the absence of a single consolidating statute increases the importance of maintaining relationships with counsel who track the UAE regulatory feed continuously, rather than relying on annual compliance reviews.

The cross-regime dimension is significant. For a business subject to both the UAE regime and EU Council regulations, or both the UAE regime and US OFAC jurisdiction, the stricter prohibition governs each specific transaction. Where OFAC reaches through its secondary sanctions provisions – restrictions that can affect non-US persons who deal with designated parties – the UAE-based business must account for both regimes simultaneously. Failing to do so is not a UAE compliance failure; it is a US enforcement risk that operates regardless of the business's UAE obligations.

What does a UAE sanctions risk assessment cover?

A sanctions risk assessment under the UAE regime requires the business to identify all counterparties, transactions, goods, and routes that could intersect with a designated person, a blocked asset, or a prohibited programme, and then to evaluate the probability and severity of that intersection given the business's own profile. The output is a risk register that drives proportionate controls.

The practical scope breaks into four distinct dimensions. First, counterparty screening: every customer, supplier, intermediary, beneficial owner, and correspondent must be checked against the UAE Local Terrorist List and the UN Consolidated List before onboarding and on a rolling basis thereafter. Second, transaction screening: individual payments, shipments, and trade-finance instruments are screened against the same lists at the point of execution. Third, ownership and control analysis: where a counterparty has a complex shareholding structure, the assessment must trace beneficial ownership sufficiently to determine whether a listed person exercises ownership or control. Fourth, geographic and sector risk: the assessment must account for the elevated risk associated with certain geographic corridors and commodity flows that are well-documented in EOCN and Financial Action Task Force guidance.

How deep must the ownership analysis go? The UAE does not publish a mechanical percentage threshold analogous to OFAC's 50 percent rule (the US rule treating entities owned 50 percent or more by blocked persons as themselves blocked). Instead, UAE guidance – consistent with the approach taken by OFSI in the UK and the EU Council – uses a control test that is qualitative: the question is whether a listed person exercises effective control over the entity, regardless of the precise ownership percentage. In our experience this distinction matters most in joint-venture and free-zone structures, where minority stakes can carry board-appointment rights or veto powers that constitute control in substance.

For comparison: OFAC's ownership test is purely mathematical and applies a single bright-line figure. OFSI and the EU use both an ownership threshold and a separate control test; either limb can catch an otherwise non-listed entity. The UAE approach most closely resembles the OFSI and EU model, which means advisers familiar only with the OFAC bright-line rule need to adjust their methodology before conducting a UAE assessment.

What risk flags should a business prioritise?

Certain patterns consistently appear in UAE sanctions exposures that practitioners encounter. Understanding them before conducting a risk assessment allows the business to direct proportionate resources to the highest-risk areas rather than spreading screening effort uniformly across a low-risk counterparty base.

The first and most persistent flag is free-zone intermediary chains. The UAE free zones enable rapid incorporation with light documentation requirements. They are legitimate and extensively used in global trade. They are also regularly present in structures where beneficial ownership is obscured by multiple layers of intermediate companies across different jurisdictions. A sanctions risk assessment that screens the free-zone entity alone, without tracing the ownership chain to natural persons or controlling entities, will not satisfy the UAE or the UN obligation.

The second flag is cross-regime secondary-sanctions exposure. A business operating in the UAE with US-dollar-denominated transactions, or with any US nexus, faces OFAC reach that operates independently of UAE domestic law. We regularly advise Gulf-based businesses that have obtained UAE clearance for a transaction and then discover they require an OFAC-specific licence as well. The two analyses run in parallel, not in sequence.

The third flag is dual-use goods and proliferation risk. The UAE is a major transshipment hub, and the EOCN has expanded its focus on trade-based money laundering (the use of trade transactions to move value through sanctions barriers or to disguise prohibited transfers) and on goods that could contribute to weapons proliferation. A company involved in the movement of electronics, chemicals, metals, or industrial equipment through UAE trade corridors should treat this as an elevated-risk category and reflect it explicitly in its risk assessment.

The fourth flag is virtual assets. The UAE has established a regulated virtual-asset sector under the Virtual Assets Regulatory Authority (VARA) and the Abu Dhabi Global Market Financial Services Regulatory Authority. Sanctions screening obligations for virtual-asset service providers mirror those for conventional financial institutions. Any risk assessment covering a business with crypto or virtual-asset activity must include a specific module for that activity, with wallet-address screening alongside entity screening.

How does the UAE enforce sanctions compliance?

UAE enforcement operates through two primary channels: administrative penalties imposed by the relevant supervisory authority and, for the most serious cases, criminal referral under domestic anti-money-laundering and counter-terrorism financing legislation. The Central Bank can impose administrative sanctions on financial institutions for compliance failures, including failures to maintain an adequate risk assessment. The Ministry of Economy has corresponding powers for non-financial businesses.

A critical feature of UAE enforcement is the obligation to report. Where a business identifies a hit – a counterparty that matches or closely resembles a designated party – it is required under the applicable Central Bank and EOCN guidance to report to the authorities within a defined period and to freeze any associated funds or assets pending further instruction. The specific reporting window is set out in the operative guidance in force at the time; verify the current position before relying on any stated timeline. Acting promptly is essential: delays in reporting narrow the options available to the business and can themselves become a compliance failure.

The interaction with international enforcement adds a further dimension. A UAE business that has also had contact with US persons or conducted US-dollar transactions may face a parallel OFAC enforcement inquiry. OFAC's extraterritorial reach is well-established: it does not require a direct US nexus at the transaction level in all cases, particularly where secondary-sanctions programmes are engaged. An enforcement matter in the UAE does not resolve an OFAC exposure, and vice versa. Businesses that discover a potential breach need to assess both regimes simultaneously and decide, with counsel, whether voluntary self-disclosure to any authority is appropriate.

Has the business documented its risk assessment adequately? In enforcement proceedings, the quality of documented risk assessment is often the determinative factor in distinguishing a reckless from a systemic breach from an isolated, good-faith compliance failure. A well-documented, proportionately calibrated assessment does not guarantee a particular outcome, but it is the baseline defence in any enforcement dialogue.

How does the UAE regime interact with other major regimes?

The UAE regime sits at the intersection of UN obligations, autonomous Gulf state measures, and the extraterritorial reach of OFAC, OFSI, and the EU Council. For a business with genuine cross-border exposure, all four need to be in scope simultaneously.

On UN alignment, the UAE is a member of the United Nations and gives direct legal effect to Security Council Chapter VII resolutions. Designations made by the Security Council committees are operative in the UAE from the moment of adoption. This means that a business screening against the UN Consolidated List has a head start, but it is not sufficient: the UAE's own autonomous list must also be checked, and updates to each list follow different timescales.

On OFAC interaction, the US sanctions regime reaches non-US businesses through secondary-sanctions provisions and through the requirement that any transaction cleared through the US financial system – or denominated in US dollars and cleared through a correspondent bank – is subject to OFAC jurisdiction. A UAE-based trading company that invoices in dollars and uses a correspondent clearing structure is squarely within OFAC's enforcement perimeter, regardless of whether it has any US presence. In our practice, the most common cross-regime gap we identify is a client who has conducted a thorough UAE risk assessment and a thorough OFAC check separately, but has not mapped the points of overlap where a UAE-cleared transaction nevertheless triggers an OFAC licensing requirement.

On EU interaction, EU Council regulations may apply extraterritorially in certain circumstances, and EU persons and EU-incorporated subsidiaries of UAE businesses remain subject to EU sanctions even when the transaction is executed in the UAE. The EU ownership and control test – which, like the UAE test, is qualitative and extends to control as well as formal ownership – applies to the EU-nexus leg of the transaction.

The practical rule for multi-regime transactions is straightforward: where two regimes both apply, the stricter prohibition governs. Running the analysis in the least-restrictive regime first and treating the result as sufficient is the most common structural error we encounter in cross-border compliance programmes.

In a recent matter, a logistics business with UAE free-zone registration and European clients discovered – during a diligence exercise for a trade-finance facility – that a subcontractor two steps removed in its supply chain had a beneficial owner subject to EU autonomous sanctions. The EU-nexus leg of the transaction was therefore prohibited under EU Council regulations, regardless of the UAE position. We mapped the ownership chain, confirmed the EU exposure, and advised on the restructuring of the supply chain before the facility closed. The matter resolved without a regulatory referral.

When should a business involve sanctions counsel?

Counsel involvement is most effective at three points in the risk lifecycle: before the risk assessment design is finalised, when a potential hit or match arises, and when an enforcement inquiry or reporting obligation is triggered.

At the design stage, counsel can ensure the methodology covers all relevant lists, applies the correct ownership and control test for each regime in scope, and documents the assessment in a form that will withstand regulatory scrutiny. A risk assessment designed without legal input is often technically deficient in ways that only become apparent in an enforcement context, when the deficiency matters most.

When a potential hit arises, speed matters. The reporting obligation in the UAE – as under OFSI and OFAC – runs from the point of identification, not from the point of internal confirmation. In our experience, the gap between an initial screening alert and internal escalation is where the most avoidable losses occur. A business that moves quickly to engage counsel, document the match, and assess the reporting obligation preserves a range of options that close rapidly as time passes.

When an enforcement inquiry is received, the priority shifts to scoping the exposure accurately, assessing whether voluntary self-disclosure to any parallel regulator is appropriate, and preparing a coherent response. A voluntary self-disclosure (a formal notification by the regulated entity to the authority of an apparent breach, made before the authority has independently identified the breach) is a recognised mitigating factor under OFAC enforcement guidelines and, increasingly, under guidance from other regulators. Whether and how to make such a disclosure in a UAE and cross-regime context requires careful, jurisdiction-specific advice.

The position above covers the standard case. Your facts – the counterparty structure, the goods, the trade corridor, the regimes in play – change the analysis. A risk assessment designed for a single-jurisdiction financial institution is not the same as one designed for a multi-corridor trading operation with free-zone intermediate structures.

To discuss the design or review of your UAE sanctions risk assessment, contact Calder & Vance at info@caldervance.com.

Common misunderstandings about UAE sanctions risk assessment

One persistent misunderstanding is that the UAE regime is less demanding than the OFAC or EU regimes, and that a business subject to all three can treat the UAE check as a formality once the OFAC and EU screens are clear. This is incorrect. The UAE Local Terrorist List contains entries that do not appear on the OFAC SDN List or the EU Consolidated List. A clean OFAC and EU result does not produce a clean UAE result. The lists are separate, and all three must be checked independently.

A second misunderstanding is that free-zone registration reduces a business's sanctions obligation. It does not. Free-zone companies are subject to the same UAE sanctions laws as mainland-registered entities. Free-zone operators with licences in financial-services or trading activities face additional supervisory scrutiny, not reduced scrutiny. The attractiveness of free-zone structures for international trade does not alter the compliance obligation.

A third misunderstanding concerns virtual assets specifically. Some businesses assume that crypto-native transactions are outside the UAE sanctions regime because they do not pass through the conventional banking system. VARA regulations and Central Bank guidance have closed this gap. Virtual-asset service providers are required to implement sanctions screening equivalent to that expected of conventional financial institutions, including real-time wallet-address screening and entity screening against all applicable lists.

If a transaction has already been flagged, or a filing has been refused, or a counterparty alert has triggered internal escalation, early review preserves options that narrow with time. Contact Calder & Vance at info@caldervance.com.

Related practices

Frequently asked questions

Who administers sanctions risk assessment under UAE?
The Executive Office for Control and Non-Proliferation (EOCN) is the primary authority, administering the UAE Local Terrorist List and implementing UN Security Council designations. The UAE Central Bank supervises financial institutions for sanctions compliance and issues binding guidance circulars. The Ministry of Economy holds supervisory responsibility over designated non-financial businesses. All three bodies can initiate enforcement action for failures in sanctions risk assessment.
What does UAE prohibit in relation to sanctions risk assessment?
The UAE prohibits engaging in any financial transaction, service relationship, or asset transfer with a party designated on the UN Consolidated List or the UAE Local Terrorist List, and requires regulated entities to screen counterparties against both lists before and during any relationship. Failure to conduct an adequate risk assessment, failure to freeze matched assets, and failure to report a match within the required window are each independent compliance failures. The ownership and control test extends the prohibition to entities controlled by a designated person, not only those formally listed.
How is sanctions risk assessment enforced under UAE?
The UAE Central Bank can impose administrative penalties on financial institutions for screening and risk-assessment failures. The Ministry of Economy holds corresponding powers for non-financial businesses. Serious cases may be referred for criminal prosecution under domestic anti-money-laundering and counter-terrorism-financing legislation. Enforcement is increasingly active, and the UAE's mutual-evaluation processes under international standards have heightened supervisory focus on documented risk-assessment quality. Maintaining a clear written record of the assessment methodology and any escalation decisions is the primary practical defence.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.