Ask ten UAE compliance officers what the CDD threshold is and most will say AED 55,000. They are right, for some entities, some of the time. They are also describing about a quarter of the picture.
The KYC requirements UAE regulators apply in 2026 run on at least four different monetary triggers depending on what you are and what you are doing, plus a set of beneficial ownership duties that became materially more prescriptive in December 2025 and that most firms have no process for at all. This guide sets out all of it.
Short answer: UAE customer due diligence triggers at AED 55,000 for financial institutions and dealers in precious metals and stones, AED 3,500 for occasional wire transfers and for virtual asset service providers, and AED 11,000 for commercial gaming operators — in each case for single or linked transactions. There is no threshold at all where suspicion arises. Beneficial ownership records must be updated within 15 working days of any change.
KYC requirements UAE: the four thresholds

The KYC requirements UAE entities face flow from Cabinet Resolution No. 134 of 2025, published in Official Gazette No. 811 on 15 November 2025 and in force from 14 December 2025. It sets out the regulated population in three articles: Article 2 covers financial institutions, Article 3 the six DNFBP categories, and Article 4 virtual asset service providers. Each carries its own trigger.
AED 55,000 — financial institutions and precious metals dealers
The familiar KYC threshold. Financial institutions apply CDD to occasional transactions at or above AED 55,000, whether a single transaction or several linked ones. Dealers in valuable metals and precious stones apply the same figure to single cash transactions or linked cash transactions.
Two details get missed. The DPMS threshold is a cash threshold specifically, and the phrase “or several linked transactions” is doing real work — a customer who buys three items at AED 20,000 each on the same afternoon has crossed the line.
AED 3,500 — wire transfers and virtual assets
Occasional wire transfers trigger KYC and CDD at AED 3,500, which is also the UAE Travel Rule threshold for originator and beneficiary information. Virtual asset service providers carry AED 3,500 as their general occasional-transaction threshold, which makes it the lowest in the regime — lower than the figure applying to banks.
That inversion surprises people. A VASP doing AED 4,000 of business must perform CDD; a bank doing the same amount as an occasional non-wire transaction need not. If you operate a virtual asset business, our crypto AML compliance work covers how this interacts with Travel Rule data and address attribution.
AED 11,000 — commercial gaming operators
Gaming operators were added to the DNFBP list in December 2025 and carry an AED 11,000 trigger for single or linked transactions. Transactions solely involving gaming chips or instruments are excluded from the calculation, which is a carve-out worth understanding precisely if it applies to you.
No threshold at all — suspicion
Where there is a suspicion of money laundering, terrorist financing or proliferation financing, or a doubt about the veracity of previously obtained identification data, CDD applies regardless of value. A AED 200 transaction that looks wrong triggers the full obligation.
The linked-transaction problem: every one of these thresholds applies to linked transactions as well as single ones, which means a simple per-transaction check does not implement any of them. You need aggregation logic that resolves the same customer across payment methods and sessions. Firms that configure a flat threshold and nothing else have built a control that catches only the careless.
Three levels of KYC and due diligence

KYC is not one standard applied uniformly. It has three levels, and choosing between them is the entire output of your customer risk assessment.
Standard KYC and CDD is the baseline: identify and verify the customer, identify the beneficial owners, understand the purpose and intended nature of the relationship, and monitor it on an ongoing basis.
Simplified due diligence is available only where risk is demonstrably low, and the word demonstrably matters. SDD is never a default, never available for a politically exposed person or a high-risk jurisdiction, and always requires a written justification tied to your risk assessment. Firms that apply SDD by customer type rather than by assessed risk are creating a finding.
Enhanced due diligence is mandatory in defined circumstances and is covered in detail below. The point for now is structural: if your AML risk assessment does not produce a defensible customer risk rating, you have no principled basis for choosing between these three columns, and every file becomes arguable.
The KYC data set: what you actually collect

KYC data requirements differ substantially between individuals and entities, and the entity side is where files are usually thin.
Natural persons
Full legal name as it appears on the identification document, nationality, date of birth, passport or Emirates ID number, residential address, contact details, the purpose of the relationship, and PEP status. Source of funds where the risk rating or transaction requires it.
Legal persons
Legal name and any trade name, trade licence and registration number, registered and operating addresses, constitutional documents, the full ownership and control structure, beneficial owners, directors and authorised signatories, and the nature of the business with expected activity levels.
The expected activity point is underrated. Recording what the customer says they will do is what makes later monitoring meaningful — without it, you have no baseline against which anything can look unusual.
Collecting is not verifying. Every item has to come from a reliable, independent source. A customer-completed form is a collection exercise. Verification means checking it against something the customer did not produce, and the distance between those two things is where most CDD findings sit.
Beneficial ownership: what changed in December 2025

This is the KYC section most firms should read twice, because the obligations expanded and very few internal processes moved with them.
The 15-working-day rule
Regulated entities must update essential information, including the beneficial ownership database, within 15 working days of any change being identified. That is a hard operational deadline attached to an event most firms do not systematically detect.
Ask yourself how you would know if a corporate customer’s ultimate owner changed next month. For most firms the honest answer is that they would find out at the next periodic review, which might be a year away. Fifteen working days requires either customer undertakings that actually get enforced, registry monitoring, or both.
Bearer shares are prohibited
Bearer shares are now expressly prohibited, with a 30-day conversion period. If any entity in a customer’s ownership chain has them, that is no longer a red flag to assess — it is an unlawful structure that has to be resolved.
Nominee status must be disclosed
Nominee arrangements must be disclosed promptly rather than surfaced on enquiry. A nominee shareholder who does not declare the arrangement is in breach, and your onboarding questions should ask the point directly rather than relying on the ownership table to reveal it.
You cannot rely on the customer’s word
Regulated entities are expected to verify beneficial ownership independently rather than accept a customer declaration at face value. A signed UBO form is the start of the process, not the end of it. Registrars now verify and in part publish core company data, which gives you an independent reference point you are expected to use.
Trusts and other legal arrangements face clearer and broader duties, and the ownership and control analysis for them is genuinely harder than for a company. If your KYC and CDD procedures were written against the 2019 regulations, the beneficial ownership section is the part most likely to be out of date.
When KYC has to be re-run

The single most common KYC misconception is that CDD is something you do at onboarding. It is a state you have to keep current, and there are eight events that reopen it.
Two of those KYC triggers deserve highlighting. A change in beneficial ownership triggers the 15-working-day clock described above. And divergence between actual behaviour and the stated purpose of the relationship is a CDD trigger, not merely a monitoring alert — if a customer who described modest local activity starts sending regular payments to a high-risk jurisdiction, the file needs reopening, not just the transaction reviewing.
This is where transaction monitoring and KYC stop being separate disciplines. Monitoring that never feeds back into the customer file produces alerts that get closed individually while the underlying risk rating stays wrong indefinitely.
Enhanced due diligence: when, and what it adds

Direct answer: Enhanced due diligence is mandatory for politically exposed persons and their family members and close associates, for relationships connected to high-risk jurisdictions, for complex or unusually large transactions without clear economic purpose, for opaque ownership structures, and for anything your own risk assessment rates high. It requires senior management approval, establishing both source of funds and source of wealth, additional documentation, and closer ongoing monitoring.
The KYC distinction that causes most difficulty is source of funds versus source of wealth.
Source of funds is the origin of the specific money involved in this transaction or relationship — the proceeds of a named property sale, a documented salary, a particular business account. Source of wealth is the origin of the customer’s overall net worth: how they came to have money at all. A customer can evidence source of funds perfectly and still leave source of wealth entirely unexplained, and for EDD you need both.
Senior management approval is also frequently mishandled. The requirement is a genuine decision by someone with authority to decline, recorded with reasons. An initialled form passed around after the account was already opened does not meet it.
PEP status is not a permanent classification either. People become PEPs, and close associates change. That is why rescreening matters and why sanctions and PEP screening needs to run continuously rather than at onboarding only.
Where KYC and CDD go wrong in practice
Across KYC file reviews, the same defects recur.
- One threshold configured globally, ignoring the wire transfer, VASP and gaming figures
- No aggregation logic, so linked transactions never accumulate
- Beneficial ownership taken from a customer declaration with no independent check
- No mechanism to detect a UBO change, making the 15-working-day rule unmeetable
- Simplified due diligence applied by customer category rather than by assessed risk
- EDD files evidencing source of funds but silent on source of wealth
- Senior management approval recorded after the relationship went live
- Expected activity never captured, so monitoring has no baseline
- Documents collected and filed but never verified against an independent source
- Risk ratings assigned at onboarding and never revisited
Almost all of these are design defects rather than effort problems. The staff are doing what the procedure says; the procedure is incomplete. That is why remediation normally starts with AML policy development and works down into the files, rather than the other way round.
A practical way to test your own KYC files
If you want to know where your KYC stands without commissioning anything, this takes an afternoon.
- Pull ten files at random. Not ten good ones. Use a random selection across risk ratings and onboarding dates.
- Check the date of the most recent CDD refresh. If the majority were last touched at onboarding, ongoing CDD is not operating.
- For every corporate file, find the beneficial owner evidence. Ask whether it came from the customer or from an independent source.
- For every high-risk file, look for source of wealth. Source of funds will usually be there. Source of wealth often is not.
- Check whether expected activity was recorded. If not, your monitoring has nothing to compare against.
- Test one linked-transaction scenario in your system. Three transactions below the threshold, same customer, same week. See whether anything fires.
Whatever that exercise finds, an examiner would find the same thing, because they run a version of it themselves. Doing it first means the findings are yours, on your timeline — which is also what an independent AML audit produces in a form you can show a supervisor.
KYC requirements UAE: frequently asked questions
What is the CDD threshold in the UAE?
There is no single figure. Financial institutions and dealers in precious metals and stones apply CDD at AED 55,000 for occasional transactions, single or linked. Occasional wire transfers trigger at AED 3,500. Virtual asset service providers apply AED 3,500. Commercial gaming operators apply AED 11,000. Where suspicion arises, no threshold applies.
What is the difference between KYC and CDD?
In practice they are used interchangeably in the UAE. KYC usually describes identifying and verifying the customer; CDD is the broader regulatory obligation that includes identification, beneficial ownership, understanding the purpose of the relationship, and ongoing monitoring. UAE legislation uses customer due diligence.
Why do VASPs have a lower threshold than banks?
Virtual asset service providers carry an AED 3,500 occasional transaction threshold, the lowest in the regime, reflecting the assessed risk of the sector. It means a virtual asset business must perform CDD on amounts well below the level at which a bank’s occasional transaction obligation is triggered.
What does ‘linked transactions’ mean?
Separate transactions that together form part of a single pattern or purpose. Every UAE CDD threshold applies to linked transactions as well as single ones, which means a simple per-transaction check does not implement the requirement. Aggregation logic that resolves the same customer across sessions and payment methods is required.
How quickly must beneficial ownership records be updated?
Within 15 working days of any change being identified. This is a hard deadline that requires a mechanism for detecting changes, not just a process for recording them once known.
Can we rely on a customer’s declaration of its beneficial owners?
No. Regulated entities are expected to verify beneficial ownership independently rather than accept a customer declaration at face value. A signed UBO form is the beginning of the exercise, not the conclusion of it.
Are bearer shares allowed in the UAE?
No. Bearer shares are expressly prohibited under the 2025 executive regulations, with a 30-day conversion period. Their presence anywhere in a customer’s ownership chain is an unlawful structure rather than a risk factor to be assessed.
When is enhanced due diligence mandatory?
For politically exposed persons and their family members and close associates, relationships connected to high-risk jurisdictions, complex or unusually large transactions without clear economic purpose, opaque ownership structures, correspondent banking, and any relationship your risk assessment rates high.
What is the difference between source of funds and source of wealth?
Source of funds is the origin of the specific money in this transaction or relationship. Source of wealth is the origin of the customer’s overall net worth. Enhanced due diligence requires both, and files that evidence the first but not the second are a common finding.
When can simplified due diligence be applied?
Only where risk is demonstrably low and the assessment is documented. It is never a default, is never available for a PEP or a high-risk jurisdiction, and must be justified against your risk assessment rather than applied by customer category.
How often should CDD be refreshed?
On a risk-based cycle set by your own policy, and immediately on any of the trigger events — a threshold being crossed, suspicion arising, doubt about existing identification, beneficial ownership changing, a risk rating moving, or behaviour diverging from the stated purpose.
What is the beneficial ownership threshold?
Beneficial ownership is generally assessed at 25% ownership or control, but the test is ownership or control. A person controlling the entity through other means is a beneficial owner even below that percentage, and stopping the analysis at the percentage is a common error.
Do we need to record expected transaction activity?
Yes, and it matters more than firms assume. Understanding the purpose and intended nature of the relationship is a CDD requirement, and the record of expected activity is the baseline against which monitoring identifies anything unusual. Without it, monitoring has nothing to compare against.
What are the penalties for CDD failures?
Administrative penalties under Federal Decree-Law No. 10 of 2025 run from AED 10,000 to AED 5,000,000 per violation. Because CDD failures are usually systemic rather than isolated, findings tend to be generated across every affected file rather than once for the firm.
KYC requirements UAE: where this leaves you
KYC is the control most firms believe they have under control, because it is the one they touch every day. It is also the one where inspectors pull a random sample and find the gap between the procedure and the practice.
The three things worth checking this week are short. Does your system apply more than one threshold. Could you tell if a corporate customer’s beneficial owner changed tomorrow. And do your high-risk files evidence source of wealth, or only source of funds.
Ontrax builds and remediates KYC and CDD frameworks for financial institutions, DNFBPs and virtual asset businesses from DIFC, Dubai — threshold configuration, customer risk methodology, beneficial ownership procedures, EDD standards and file remediation. Where the gap is capacity rather than design, we also provide an outsourced AML function and MLRO provision.
If the ten-file test above surfaces more than you expected, that is the usual result and it is fixable. Get in touch.
Primary sources and further reading
- UAE Ministry of Economy and Tourism — DNFBP guidelines and the Implementation Guide on customer due diligence
- Central Bank of the UAE — AML/CFT guidelines and the CBUAE Rulebook, including sector-specific CDD bands
- UAE National Committee for AML/CFT — national framework and guidance publications
- Financial Action Task Force — Recommendations 10, 12 and 24 on due diligence, PEPs and beneficial ownership

