AML Checks Explained: How Businesses Verify Customers

AML checks explained, how businesses verify customer
Facebook
X (formerly Twitter)
LinkedIn
WhatsApp

Table of Contents

Quick Summary 

AML screening is not the same as checking someone’s passport. It’s a four-layer process: sanctions, PEPs, adverse media, and ownership structure, which runs after identity is confirmed. Most businesses run one layer. Regulators expect all four.

There’s a version of AML checks that a lot of businesses think they’re running.

They collect a passport copy. They fill in a KYC form. They move on. Identity verified, job completed. That’s identity verification. It is not AML screening. The two are related but not the same, and the gap between them is exactly where most AML checks and inspection findings fall.

This blog covers what AML screening involves: the four layers, how risk scores get set, and why screening a client once at onboarding is not sufficient. For the broader compliance framework, see our guide on “Navigating the Core Compliance Requirements for DNFBPs in the UAE”.

What is AML Screening?

AML screening is the process of checking a customer or transaction against external risk databases to identify flags that identity documents alone cannot reveal. Running thorough AML checks means going beyond the document stage.

A passport confirms someone is who they say they are. It says nothing about whether they’re on a UN sanctions list, whether they hold a government position that creates conflict-of-interest risk, or whether their name has appeared in financial crime reporting.

AML screening fills that gap. It runs in parallel with, not instead of, the identity verification step. Together, they form the complete customer due diligence (CDD) picture.

Under Federal Decree-Law No. 10 of 2025, regulated entities, including all DNFBPs, are obligated to screen customers before onboarding and on an ongoing basis throughout the business relationship. The Ministry of Economy & Tourism’s AML supervision unit audits both the fact of screening and the quality of the process.

The Four Layers of an AML Check

A complete AML check covers four distinct data sources. Most businesses, when inspected, are running one or two. All four are required.

Here’s how the layers break down — and what a missed hit means in practice:

LayerWhat It ChecksWhat a Miss Means
Sanctions ScreeningUAE local list, UN, OFAC, EU restrictive measuresTransaction with a sanctioned party = criminal liability
PEP ScreeningGovernment officials, military figures, state-enterprise board members, family members, and close associatesEDD not applied = direct compliance failure
Adverse MediaFinancial crime reporting, court records, regulatory actions, investigative journalismUndisclosed financial crime exposure onboarded
UBO / OwnershipThe natural person who ultimately owns or controls the entitySanctioned individual hidden behind a clean company name

1. Sanctions Screening

This checks the customer against the UAE local list, the UN Security Council Consolidated List, OFAC (US Treasury), and EU restrictive measures. A match means the customer faces asset freezing or transaction restrictions under applicable law.

Sanctions lists are updated without notice. A client who was clean at onboarding may appear on a list six months later. Real-time or near-real-time monitoring is the only way to catch that.

2. PEP Screening

A Politically Exposed Person (PEP) is any individual who holds or has held a prominent public position: head of state, senior government officials, military figures, judicial officers, board members of state-owned enterprises, and their immediate family members and known close associates.

PEP status doesn’t mean a client is a criminal. It means the risk of corruption is elevated, so the due diligence bar is higher. Accepting a PEP without applying Enhanced Due Diligence (EDD) is a direct compliance failure.

3. Adverse Media Screening

This runs the client’s name against financial crime reporting, court records, regulatory enforcement actions, and credible investigative journalism. The goal: surface associations that don’t appear on formal sanctions lists such as fraud suspicions, money-laundering investigations, and asset forfeiture proceedings.

This layer gets skipped most often. Neither “no database subscription” nor “no time” holds up in an inspection.

4. UBO and Ownership Screening

For corporate clients, AML screening must trace the Ultimate Beneficial Owner — the natural person who ultimately owns or controls the entity, directly or through intermediaries. If that person is on a sanctions list, is a PEP, or appears in adverse media, the entity is high-risk regardless of how clean the company name looks.

What Happens When a Client Screens as a PEP?

The UAE law does not set a fixed deactivation period for PEP status. Once classified as a PEP, a client remains subject to enhanced scrutiny until your compliance officer formally reassesses and documents a change in their risk profile. “They used to be a minister” is not a sufficient reason to downgrade them.

When a client screens as a PEP, standard CDD is replaced by Enhanced Due Diligence (EDD). That means:

  • Senior management approval is required before onboarding the client
  • Source of funds documentation- declaration letter signed by the client itself is not sufficient; verifiable evidence from a third party is required
  • Source of wealth documentation for higher-value relationships
  • More frequent review intervals throughout the relationship

EDD does not mean automatic rejection. It means you’ve assessed the risk properly and documented your reasoning. That documented reasoning is what MoET auditors look for.

How Risk Scoring Works in Practice?

AML checks are conducted on every client before the relationship begins. Once the identity verification and the four-layer screening are complete, every client gets a risk classification: low, medium, or high. That classification drives everything that follows, such as how much documentation you collect, how often you review, and how quickly you escalate unusual activity.

Think of it less as pass/fail and more as a dial. Several factors push that dial up or down:

Four factors that set the risk score in AML checks
  • Country risk: where the client is based, where the money comes from. Funds originating from sanctioned or high-risk jurisdictions move the needle fast. 
  • Sector risk: cash-heavy businesses, real estate, precious metals, virtual assets. These start at a higher baseline before you’ve even looked at the individual client. 
  • Product/service risk: some transaction types carry inherent risk, no matter how clean the client looks on paper. 
  • Client-specific: PEP status, layered ownership structures, reluctance to hand over documents, transactions that don’t match the stated business activity.

Where a client lands on that dial determines the workload. Low risk: SDD, reviewed annually. High risk: EDD, senior management approval, tighter monitoring, shorter review cycles. The gap between those two tracks is significant, which is why misclassifying a high-risk client as low is one of the first things MoET looks for.

Ongoing Monitoring- Why One-Time Checks Are Not Enough

AML screening at onboarding confirms a client was clean on the day you checked. It says nothing about what happens next.

Sanctions lists change. A client’s political exposure status changes. Their transaction behaviour changes. Their ownership structure changes. An AML program that checks once and files the results is not a program; it’s a snapshot.

AML checks don’t stop at onboarding. Ongoing monitoring requires:

  • Rescreening against updated sanctions lists at defined intervals, or in real time via an automated tool
  • Transaction monitoring- flagging payments inconsistent with the client’s stated business activity or risk profile
  • Periodic relationship review- formally reassessing the client’s risk classification based on current information
  • Trigger-based re-screening – certain events (a change in beneficial ownership, a large, unexpected transaction, adverse media coverage) should prompt an immediate review regardless of schedule

When a client’s profile changes materially, and your risk rating doesn’t, that discrepancy is exactly what triggers a Suspicious Transaction Report. See our goAML registration guide that briefly explains how the STR filing process works.

Screening Gaps That Attract MoET Scrutiny

These are the specific failures that come up repeatedly when businesses go through their first MoET inspection:

  • Screening only the named client, not the UBO- a clean company name means nothing if the person behind it is on a sanctions list
  • Running PEP checks against free online lists instead of a maintained database- free lists are incomplete and not updated in real time
  • No documentation of the screening result- the check was run, but there’s no record showing it happened
  • Client risk ratings set at onboarding and never reviewed- a static risk file is a compliance gap, not a compliance record
  • Adverse media checks skipped entirely- inspectors ask specifically about this layer
  • No process for re-screening when a sanctions list updates- set-and-forget is not compliant

If any of these apply to your current process, address them before the Ministry of Economy & Tourism (MoET) visits. Our guide on MoET Letters of Concern covers exactly what happens when they find these gaps.

AML Checks That Hold Up Under Inspection

AML screening isn’t complicated in concept. Confirm who the client is, then check whether they pose a risk. The execution – all four layers, documented, for every client, continuously –is where most businesses fail.

Businesses that pass Ministry of Economy & Tourism (MoET) inspections aren’t the ones with the most elaborate policies. They’re the ones whose day-to-day process matches what the policy says: screening logged, risk ratings reviewed, unusual transactions escalated. That consistency is what AML compliance looks like in practice.

Need An AML Screening Set Up Properly?

CorpLex handles the full compliance set-up for DNFBPs- screening tool selection, risk rating frameworks, KYC documentation, goAML registration, AML Policies and staff training. If your current process has gaps, we’ll find them before MoET does.

Contact us today!

FAQs

  1. Is a Google search sufficient for adverse media screening?

No. It produces no audit trail, fails to handle aliases, and doesn’t update automatically — all of which are required for a compliant screening process.

  1. Can I onboard a domestic PEP without Enhanced Due Diligence?

Depends on the risk level. Low or medium risk – EDD isn’t mandatory. But if the relationship is high risk, there’s no workaround. EDD applies, no exception.

  1. Does sanctions screening apply to every client, or just the risky ones?

Yes. It applies to every single client. Risk classification doesn’t decide whether you screen; it decides what you do when a hit comes back.

  1. One sanction check at onboarding- is that enough?

Not even close. Lists get updated without warning. A client who was clean in January can appear on a list by March. Rescreening must run throughout the relationship, not just at the start.

  1. PEP hit- does that mean the client is out?

No. It means the process gets heavier, not that the door closes. Senior management approval is required, EDD measures should be applied, and verification gets more thorough. If the documentation is satisfactory, you can proceed.

About Author

Related Posts

About Author

Maylyn A. Asilo

Recent Posts