Insights

Regulatory commentary, sector analysis, and due diligence best practices from our investigations team.

Regulatory Update

FATF 2026 and the UAE: What the Mutual Evaluation Means for Due Diligence

The UAE's removal from the FATF grey list in February 2024 was a significant milestone, the product of two years of legislative reform and institutional rebuilding. But grey list removal was a threshold test, not a final grade. The 5th Round Mutual Evaluation, with its onsite assessment in June 2026, applies the FATF's revised 2022 methodology, which places primary weight on demonstrated effectiveness rather than technical compliance. For regulated entities across ADGM, DIFC, DMCC and the onshore UAE market, this distinction is operationally consequential.

The regulatory context has also shifted materially. Federal Decree-Law No. 10 of 2025, in force since October 2025, replaces the 2018 AML framework with a comprehensive new law that criminalises proliferation financing as a standalone offence, introduces personal criminal liability for senior managers, and expands FIU enforcement powers. Cabinet Decision No. 134 of 2025 follows with 71 articles and close to 300 enforceable requirements covering every category of regulated entity, including, for the first time, commercial gaming operators. The CBUAE's April 2026 guidance adds a fourth compliance pillar: counter-proliferation financing, requiring a documented PF risk assessment separate from the AML/CFT framework.

The full paper argues that the central challenge facing regulated UAE entities in this evaluation is not technical compliance, where the legal architecture is largely sound, but the ability to demonstrate that policies and procedures have produced measurable outcomes: risk assessments that visibly respond to the UAE's 2024 National Risk Assessment findings, CDD decisions that reflect actual analysis of client risk rather than database output, STRs that identify specific predicate offences and typology matches rather than being filed defensively, and beneficial ownership verification that goes beyond registry submissions. FATF assessors under the fifth-round methodology interview private sector firms directly, examine individual transaction files, and ask compliance officers to account for their decisions.

The paper sets out what that evidential standard requires in practical terms, across IO3 (supervision), IO4 (preventive measures), IO5 (beneficial ownership transparency) and IO11 (proliferation financing), and explains where current market practice in the UAE falls short of what assessors will expect to find. It provides specific, actionable guidance for compliance officers, general counsel, investment directors and family office principals who need to understand not only what the law requires but what a defensible due diligence programme looks like under investigative scrutiny.

Sector Risk

Why Database-Only Screening Fails in the GCC

The UAE's AML framework is now among the most demanding in the world. Federal Decree-Law No. 10 of 2025, Cabinet Decision No. 134 of 2025, and the post-grey-list enforcement posture of the CBUAE, ADGM FSRA, and DFSA have created a regulatory environment where beneficial ownership verification, enhanced due diligence, and risk-based programme documentation are not aspirational standards; they are examination criteria. The CBUAE alone imposed fines exceeding AED 339 million on banks, exchange houses, and insurers between March and June 2025. That enforcement trajectory is continuing into 2026.

Against that standard, the compliance industry's default instrument remains the commercial screening database. WorldCheck, Refinitiv, Dow Jones Risk and Compliance, and their equivalents perform a genuine and necessary function: they surface sanctions matches, PEP classifications, and adverse media coverage from indexed sources. The problem is structural. UAE beneficial ownership registers are confidential, accessible only to competent authorities, not to private sector compliance teams. The UAE's more than 36 free zones each operate independent registration systems with no consolidated public database linking corporate structures across emirate boundaries. Nominee director arrangements, the primary mechanism through which real control is obscured in GCC corporate structures, do not appear in the documents these tools index. The UAE's 2024 National Risk Assessment, issued by the Ministry of Economy, identifies misuse of legal persons and nominee structures as a primary ML typology and explicitly requires DNFBPs to build detection of complex, opaque ownership structures into their due diligence frameworks.

This paper's central argument is that the gap between regulatory expectation and what database screening delivers is not a marginal deficiency. It is a design limitation. These tools were built for jurisdictions with publicly searchable court records, accessible corporate registries, and dense investigative media coverage. The GCC has none of these features in the same form. The information that answers the questions regulators actually ask, namely who controls this entity, what is their commercial reputation in this market, and does this structure have a purpose beyond opacity, exists in human networks, reference conversations, and direct document review. It cannot be extracted from a database.

After reading the full paper, a compliance officer, general counsel, investment director, or family office principal will understand precisely where each commercial screening tool stops and where investigation must begin; how to structure a due diligence file that evidences the substance of enhanced due diligence rather than merely its completion; what documentation the CBUAE, ADGM FSRA, and DFSA are examining during inspections; and how to calibrate risk appetite against the specific information gaps that are inherent to GCC counterparty assessment.

Methodology

VARA Principal Person Due Diligence: What the Regulations Actually Require

The VARA licensing process has a well-documented due diligence obligation attached to it: every Board member, Senior Management officer, Responsible Individual and Person Exercising Control of a VASP must be assessed as a Fit and Proper Person. Most applicants treat this as a documentation exercise. Passport copies, self-completed declarations, a CV and a sanctions screen are assembled, and the box is marked complete. The Company Rulebook (Version 2.0, 19 May 2025), issued under the Virtual Assets and Related Activities Regulations 2023, describes a materially higher standard than this. The gap between what the regulation requires and what the market typically delivers is the subject of this paper.

The problem is threefold. The scope of persons who fall within VARA's Fit and Proper regime is broader than many VASPs have mapped. VARA defines Control functionally: any individual who can direct or materially influence the VASP's operations, strategy or risk decisions is in scope, regardless of whether they hold a formal title, hold UAE residency, or appear on the ownership chart. Non-resident founders with effective control, offshore holding company controllers and informal advisers with contractual veto rights are all caught by this definition, and they are routinely absent from the assessments submitted to VARA. The evidentiary standard, set out across six sub-sections of Part III of the Company Rulebook, covers qualification and experience, financial solvency, and a conduct-based assessment of honesty, integrity and reputation that explicitly requires VARA to examine criminal history, civil proceedings, regulatory investigations, dismissals for cause, and whether the individual has been candid and truthful with regulatory bodies. None of those criteria can be satisfied by a database query. Third, the obligation is continuous: Board members must be re-assessed at least annually, Responsible Individuals must be validated on an annual cycle, and any event that could affect an individual's fitness must be reported to VARA without delay.

The paper's central argument is this: a satisfactory Fit and Proper assessment is an investigative exercise, not a document collection exercise. It requires governance mapping that applies VARA's functional definition of Control, multi-jurisdictional public record research calibrated to what is actually accessible in each relevant market, structured reference interviews directed at the honesty and integrity criteria that database searches cannot address, and a documented assessment memorandum that records the basis for the conclusion and identifies any areas of residual uncertainty. VASPs that present VARA with passport copies and self-declarations have not discharged the obligation. They have created a documented gap in their licensing file.

After reading this paper, compliance officers, legal counsel, investment directors and family office principals with VASP exposure will understand precisely what Part III of the Company Rulebook requires at each stage of the Fit and Proper assessment, where the standard diverges from current market practice, what a defensible investigation looks like in terms of scope, methodology and documentation, and what the personal enforcement consequences are for Responsible Individuals and directors when the assessment is inadequate.

Case Commentary

The Hidden Risks in UHNW Household Staffing

A UHNW principal's residence and household staff represent one of the most exposed and least governed environments in the entire risk perimeter of a sophisticated individual or family. The personal assistant with access to travel schedules, the household manager who oversees domestic account arrangements, the private driver waiting outside a meeting with legal counsel: these individuals sit at the intersection of physical security, intelligence sensitivity and financial crime exposure. Yet the due diligence applied to their hiring in the UAE routinely reflects HR practice, not security practice.

This paper argues that the standard approach to UHNW household staffing in the UAE is structurally inadequate relative to the risk it creates. Three distinct risk categories converge in the household environment: physical security and intelligence leakage, which documented cases across the Gulf region show has been exploited to facilitate kidnapping and robbery; financial crime conduit risk, where senior household staff with access to financial information and transaction arrangements occupy the same structural position as the nominees and proximate associates identified in FATF and MENAFATF typologies as primary money laundering vehicles; and a systematic vetting gap, where multi-jurisdictional background checks, financial distress screening and verified employment history are absent from hiring processes even at the highest wealth levels.

The regulatory dimension is not theoretical. Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025 have replaced the UAE's 2018 AML framework and introduced a constructive knowledge standard: regulated entities can no longer use absence of actual knowledge as a defence where warning signs were present and should have been identified. For ADGM and DIFC-regulated family offices, wealth managers, private bankers and legal advisers serving PEP clients, the obligation to understand risk flowing through close associates extends logically to the household environment. An EDD file that documents the client's business structure but not the access arrangements of the individuals managing their residence is incomplete in a post-grey-list compliance environment where supervisory expectations are now explicit and documented.

After reading the full paper, compliance officers, legal counsel and family office principals will understand exactly what a credible household staff vetting programme looks like, how information compartmentalisation should be applied within a private residence, what periodic re-screening should cover, and how the household risk environment should be documented within an EDD file for a PEP-connected client. The paper draws on FATF Recommendation 12, Cabinet Decision No. 10 of 2019, Federal Decree-Law No. 9 of 2022 on Domestic Workers and the CBUAE's 2026 guidance package to ground its practitioner implications in the actual regulatory framework, not generic risk commentary.

Commodities

OECD Annex II and the Provenance Gap: Why Desk-Based DD Fails in Physical Metals

In July 2024, the UAE Ministry of Economy suspended 32 gold refineries for three months after field inspections found 256 AML violations across the country's precious metals sector. This was not an enforcement action triggered by unknown risks or marginal operators. It followed grey list removal in February 2024, regulatory reform and years of compliance investment. The violations confirmed that documentary compliance and substantive provenance verification are not the same thing, and that regulators have begun treating them differently.

The core problem is structural. The UAE's 2024 National Risk Assessment rated the Dealers in Precious Metals and Stones sector as medium-to-high risk. The country is now the world's second-largest gold trading hub, with precious metals foreign trade reaching AED 625 billion (approximately USD 170 billion) in 2024. A significant proportion of that metal originates from or transits through conflict-affected and high-risk areas: Sudan, Chad, Libya, Uganda and Togo all appear in 2024 import data as significant source or transit jurisdictions, despite most producing negligible domestic output. The documentary mechanisms used to assert clean provenance in those supply chains, namely certificates of origin, supplier declarations and transit records, are the same instruments that UN expert groups and investigative bodies have documented as routinely falsified.

This paper argues that Annex II of the OECD Due Diligence Guidance for Responsible Supply Chains of Minerals from Conflict-Affected and High-Risk Areas (Third Edition, 2016) sets a standard that desk-based review is structurally incapable of meeting for high-risk supply chains. Treating accreditation to the LBMA Good Delivery List or DMCC membership as a proxy for provenance verification on specific consignments, or accepting counterparty-provided documentation as conclusive evidence of mine of origin, does not satisfy the requirement to identify the factual circumstances of extraction, transport and trade that Annex II Step 2 imposes. That determination requires investigative work: source interviews, on-the-ground supply chain assessment, intelligence-led verification of declared trade routes and counterparty integrity.

Compliance officers, general counsel, trade finance providers and investment professionals whose institutions have exposure to the UAE physical metals sector will find in the full paper a precise account of where desk-based review succeeds and where it fails; what the regulatory obligations under UAE federal law, LBMA Guidance and the OECD framework actually require of upstream and downstream participants; and what a credible provenance verification programme looks like in operational terms. The paper draws on the enforcement record, including the July 2024 suspension action, the 2024 National Risk Assessment findings and import data published through UN Comtrade and SWISSAID's May 2026 analysis, to ground the argument in current, documented fact rather than general supply chain commentary.

Methodology

Intelligence-Led Due Diligence: What It Means in the UAE in 2026

The standard due diligence toolkit deployed across the UAE's financial centres was built to solve a different problem in a different place. Sanctions lists, PEP databases and registry checks emerged from the post-2008 Western regulatory response: a framework designed for markets where company registers are searchable and reliable, where court records are accessible, and where professional reputations are built through auditable histories rather than family networks. The GCC is not that market, and the tools designed for Western compliance are not adequate to the task of managing counterparty risk in Abu Dhabi or Dubai in 2026.

This paper makes that argument with specificity. The structural information gap in the GCC is not a temporary deficiency awaiting regulatory resolution. It is a product of how commerce operates in this region: opaque free zone structures across more than 40 UAE licensing authorities, beneficial ownership registers that are maintained within regulatory systems but are not independently verifiable by counterparties, nominee arrangements that are difficult to detect when informal, and social capital built through personal and family networks that leave no documentary trace in any database. UAE Cabinet Resolution No. 109 of 2023 mandates beneficial ownership disclosure; it does not make that information independently accessible. The gap between formal disclosure and independent verification is precisely where risk resides.

The regulatory pressure is intensifying this problem rather than resolving it. Federal Decree-Law No. 10 of 2025, which replaced the 2018 AML framework and came into force on 14 October 2025, expands the evidentiary standard required to demonstrate adequate due diligence, introduces explicit personal liability for senior managers, and applies to entities supervised by the CBUAE, the DFSA and the ADGM FSRA alike. The UAE's FATF Mutual Evaluation, scheduled for June 2026 under the 5th Round methodology, will assess operational effectiveness: not whether policies exist, but whether the due diligence process produced real risk reduction in actual cases. A database query run and a senior management signature do not satisfy that standard.

The paper sets out what intelligence-led due diligence actually means in operational terms: structured human source enquiry, not reference calls to provided contacts; independent beneficial ownership verification, not reliance on register extracts; source-of-wealth corroboration grounded in evidence, not self-declaration; and analytical conclusions documented with the chain-of-custody discipline that an investigation, rather than a process, requires. These are the methods that reach the information that a sanctions screen cannot: who actually controls an entity, what the source of funds genuinely is, and what a counterparty's standing in the relevant community means for the risk a business relationship carries.

Compliance officers, MLROs, investment directors and general counsel responsible for counterparty due diligence in the UAE will find in this paper a clear account of why the current market standard is inadequate, what the regulatory framework now actually requires, and what the concrete steps are to close the gap before the 2026 assessment cycle begins.

Corporate Structures

Structuring Blind Spots: How Layered UAE Ownership Defeats Standard Due Diligence

Pre-acquisition due diligence in the UAE routinely returns a clean result for corporate structures that are not clean. The mechanism is not fraud in the conventional sense, and it does not require the target to lie on any disclosed document. It requires only that the beneficial interest of consequence sits at a structural layer that no database or registry search can reach.

The UAE has invested substantially in beneficial ownership transparency since its FATF grey-listing in March 2022 and removal in February 2024. Cabinet Decision No. 109 of 2023 extended UBO register obligations to mainland and non-financial free zone entities. ADGM's Beneficial Ownership and Control Regulations 2022, amended in April 2024, and the DIFC's UBO Regulations cover the principal financial free zones. Federal Decree-Law No. 10 of 2025, in force from October 2025, criminalises false UBO reporting and introduces personal liability for senior managers. The framework is increasingly robust.

None of that framework gives a private sector acquirer direct access to the registers it has created. ADGM's record of beneficial owners is restricted to designated Registration Authority personnel. The DIFC equivalent is accessible to regulators and law enforcement, not to counterparties. RAK ICC registers are held by the relevant authority, not publicly searchable. The gap between regulatory transparency, which flows to competent authorities, and transactional transparency, which flows to deal counterparties, is structural and deliberate. It does not close because the regulations improve.

The full paper examines how layered structures combining UAE free zone holding vehicles with offshore co-domicile arrangements in the Cayman Islands, BVI or Jersey are used, in both legitimate and abusive contexts, to place beneficial ownership information outside the reach of conventional diligence methods. It works through the specific structural combinations most frequently encountered in ADGM, DIFC, DMCC and RAK ICC deal environments, identifies the points at which PEP-connected interests are most commonly embedded below the surface of disclosed ownership records, and explains why the FATF's revised Recommendation 24 multi-pronged approach, designed for law enforcement, does not resolve the problem for private transaction parties.

The paper's central argument is that standard pre-acquisition due diligence is calibrated for transparent Western ownership registries and is structurally ill-suited to the GCC without a human-source layer. The practitioner implications are specific: how to map structural risk before commissioning diligence, which entity types should trigger elevated investigation regardless of disclosed ownership, how to apply FATF Recommendation 12 PEP standards to the full corporate network rather than only to named UBOs, and when database-only diligence creates residual liability rather than protection.

Employment Risk

Why SMBs Get the Most Dangerous Hires: The UAE's Pre-Employment Screening Gap

SMBs represent more than 94% of all businesses in the UAE and employ approximately 86% of the private sector workforce. They are also, by any available measure, the category of business least likely to conduct meaningful pre-employment screening on the people they hire. The result is a structural concentration of insider fraud risk in precisely the part of the economy with the least capacity to absorb it.

The Association of Certified Fraud Examiners' 2024 "Occupational Fraud: A Report to the Nations" found that organisations with fewer than 100 employees suffer a median fraud loss of USD 141,000 per incident, with the typical scheme running for twelve months before detection. The same report found that fraud losses as a percentage of annual revenue are consistently higher for smaller organisations, and that weak or absent internal controls were correlated with more than half of all cases. In the UAE context, these figures are amplified by a workforce that is overwhelmingly expatriate in origin, arriving from jurisdictions where verification infrastructure varies enormously, and by a hiring culture that treats personal referral as a substitute for documented due diligence rather than a supplement to it.

The full paper argues that this is a gap with regulatory as well as commercial consequences. Federal Decree-Law No. 33 of 2021 on the Regulation of Employment Relationships does not mandate pre-employment background checks, which means the burden of identifying bad actors falls entirely on the employer, without requiring the employer to exercise it. For SMBs that fall within AML/CFT obligations as DNFBPs under Federal Decree-Law No. 20 of 2018, or as regulated entities within ADGM, DIFC or DMCC frameworks, FATF Recommendation 18's requirement for adequate recruitment screening procedures as part of an AML/CFT internal programme applies directly. With the UAE's 5th Round FATF Mutual Evaluation scheduled for mid-2026, supervisors will be looking for documented evidence that these standards are being met in practice, not merely referenced in a policy document. The UAE's 2024 National Risk Assessment identified fraud as one of the two highest-rated predicate offences for money laundering, making employee-enabled financial misconduct a live AML exposure, not merely an HR problem.

The paper provides a specific account of the three most underestimated risk categories in UAE SMB hiring: credential fraud and the obligations under Federal Law No. 9 of 2021; the falsified or deliberately incomplete employment history that database and document checks do not surface; and the internal access structures of small businesses that give a dishonest insider the operational conditions to commit sustained fraud with minimal risk of early detection. For compliance officers, general counsel and operations directors, the paper sets out what a defensible pre-employment verification standard looks like in the UAE context, what it costs, and why the argument against it does not survive scrutiny.

Vendor Due Diligence

Licensed but Unknown: Counterparty Risk in UAE Construction and Infrastructure

The UAE construction and infrastructure market was valued at USD 66.89 billion in 2024. Across that market, hundreds of subcontractors, suppliers and service providers are engaged every month by project owners, developers, investment funds and family offices. The majority of those engagements begin and end with a trade licence check, a sanctions database query and a request for bank details. That process is not due diligence. It is administrative confirmation that a company exists.

The core problem is structural. The UAE operates more than 45 free zones, each with its own registration authority. Beneficial ownership declarations under Cabinet Resolution No. 109 of 2023 are filed with licensing authorities, not consolidated in a publicly searchable national register accessible to counterparties. A valid trade licence tells you that a company has been registered and holds an activity permit. It does not tell you who ultimately controls or benefits from it, whether those persons are sanctioned or politically exposed, or whether the entity has the operational substance its licence implies.

This paper argues that the information gap between regulatory status and operational reality creates direct legal and commercial exposure for the organisations engaging these vendors, not only for the vendors themselves. Federal Decree-Law No. 10 of 2025, which came into force in October 2025 as the UAE's principal AML/CFT instrument, extends personal liability to senior management for negligence in AML controls. The UAE Ministry of Economy's Circular No. 6 of 2025 requires all DNFBPs to apply a structured, two-stage risk assessment process to counterparties. The UAE's 2024 National Risk Assessment identified nominee structure misuse and the abuse of legal persons as key typologies. These are not abstract regulatory concerns. They describe a documented failure mode that operates inside normal commercial procurement.

The paper sets out what a defensible standard of vendor due diligence actually requires in the current UAE environment: establishing the full UBO chain to natural person level, verifying operational substance, screening across the ownership structure rather than at entity level only, and building contractual protections that give the engaging organisation a right to respond when a counterparty's risk profile changes. These steps are calibrated to the risk-based approach now mandated across all regulatory frameworks operating in the UAE, from CBUAE and Ministry of Economy supervision of DNFBPs to the DFSA and FSRA regimes within DIFC and ADGM.

Readers in compliance, legal, investment and family office roles will be able to assess where their current vendor onboarding processes fall short of the standard now expected under Federal Decree-Law No. 10 of 2025, and what changes to process, contract structure and screening scope address the identified gaps.

OPSEC

Digital Exhaust as a Supply-Chain Risk: What Your Website Tells the World About Your Clients

Every website a compliance officer, investigator, general counsel, or family office principal visits during the ordinary course of their work leaves a trace. Analytics scripts, advertising pixels, and the real-time bidding auctions that place ads on nearly every commercial page do not simply count visitors. They broadcast what a person is reading, when, from where, and often who they are, to networks of data brokers and advertising intermediaries that the visited website's own owner never sees and cannot control. For firms that handle sensitive engagements, this is not a privacy inconvenience. It is a supply-chain risk.

The Irish Council for Civil Liberties' 2022 and 2023 investigations into online advertising's Real-Time Bidding system found that RTB auctions broadcast behavioural and location data approximately 178 trillion times a year across the US and Europe, and that the industry's own audience-targeting taxonomies include categories such as "intelligence and counterterrorism" and "military personnel." That data has been documented flowing to data brokers in Russia and China. A due diligence firm, a law firm, or a family office whose website runs standard third-party analytics and ad tracking is not just measuring its own traffic. It is feeding a visitor's browsing behaviour, including the fact that they visited a due diligence, legal, or investigative website at all, into a data supply chain with no technical limit on redistribution.

This is not a hypothetical concern raised only by privacy advocates. In the United States, a wave of litigation against hospital systems and healthcare providers over the Meta Pixel established, in court filings and settlements running into 2024 and 2025, that a tracking script embedded for ordinary marketing analytics can transmit visitor-identifying data to a third-party advertising platform without the website operator intending it or the visitor knowing it. The mechanism in those cases is functionally identical to the mechanism operating on thousands of professional services websites today. The party exposed is not only the website's visitor. It is every client, counterparty, or matter that visitor's browsing pattern could indirectly reveal.

For firms operating in the UAE, this sits inside an active regulatory framework, not a gap in one. Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data classifies browsing and location data capable of identifying a person as personal data subject to consent and cross-border transfer controls, and the EU's GDPR and ePrivacy framework, directly relevant for any UAE firm serving European clients or counterparties, treats third-party tracking cookies and real-time bidding data the same way. When a firm's own website loads third-party trackers, it does the same thing it would criticise a counterparty for doing during due diligence: it passes visitor data to outside companies it does not audit and cannot control.

The paper sets out what "digital exhaust" actually is, how the advertising and analytics supply chain moves it from a single page load to a global data-broker ecosystem, why this constitutes an underexamined third-party risk for any organisation handling sensitive client relationships, and a simple, verifiable test, open to any reader on any website, including this one, for establishing exactly what a site sends, and to whom, before a single form is submitted.

Free Tier 1 Screening → Click to access the login or register cheese