Key Takeaways
- A KYC form in the UAE isn’t just a formality. It’s the paper trail that proves your business knew exactly who it was dealing with, before the relationship started, not after something went wrong.
- Customer due diligence UAE requirements now cover three tiers: Standard CDD, Simplified Due Diligence (SDD), and Enhanced Due Diligence (EDD) — applied based on risk assessment, not convenience.
- Under the 2025 framework, every KYC file must now include Proliferation Financing (PF) risk indicators. If yours doesn’t, it’s already out of date.
What is a KYC Form in the UAE?
Most people, including business owners, think KYC is a form you fill out when opening a bank account. For DNFBPs in the UAE, it’s much more than that. A KYC form UAE is the documented process through which your business verifies who a client is, where their money comes from, and whether the relationship carries financial crime risk — before a single service is delivered.
Under Federal Decree-Law No. (10) of 2025 and Articles 6 to 17 of Cabinet Resolution No. 134 of 2025, customer due diligence is a legal obligation, not a best practice. Every DNFBP must collect, verify, and document client information before onboarding. Not during. Not after, but before.
The Ministry of Economy & Tourism (MoET) supervises this process for mainland DNFBPs. If your KYC files are incomplete, inconsistent, or missing when an inspector arrives, that’s a standalone deficiency — regardless of how clean your compliance manual looks.
KYC Forms UAE: Individual vs. Legal Person
There are two separate KYC forms UAE: one for individual clients and one for corporate entities. The requirements differ significantly. Using the wrong form or applying individual CDD to a corporate client is a common deficiency MoET flags.
| Information Category | Individual KYC Form | Legal Person KYC Form |
| Identity | Passport, Emirates ID, visa | Trade license, MOA/AOA |
| Address | Residential address, proof of address | Registered & operating address |
| Ownership | Self-declaration, PEP status | UBO details (25%+ ownership) |
| Source of Funds | Salary, property sale, business revenue | Business revenue, share capital |
| Source of Wealth | Career earnings, inheritance, investments | UBO accumulated wealth |
| CPF / Sanctions | Dual-use goods, high-risk jurisdictions | Shell banks, virtual assets, dual-use goods |
| Structure | Third-party representation | Layered structures, nominee arrangements |
What is Customer Due Diligence UAE — and What Does It Actually Cover?
Customer due diligence UAE is the process of identifying, verifying, and continuously monitoring clients to assess their financial crime risk. It’s not a one-time tick-box at onboarding — it runs for the life of the business relationship and after 5 years from the date when this relationship ends.
Under the 2025 framework, CDD operates across three tiers, applied based on the client’s assessed risk level:
- Standard CDD– It should apply to every client, every time, at onboarding. No exceptions based on how straightforward the relationship looks. You need to collect identity documents, verify them, understand the purpose of the relationship, and establish a client risk rating.
- Simplified Due Diligence (SDD)– this is allowed only where genuinely low risk is documented. Applying this still requires a written justification.
- Enhanced Due Diligence (EDD) – this is mandatory for high-risk clients: Politically Exposed Persons (PEPs), clients from high-risk jurisdictions, complex ownership structures, and any transaction that raises Source of Funds or Source of Wealth questions.
Cash payments of AED 55,000 or above from any individual client require EDD, Source of Wealth verification, and Senior Management approval. That’s the standard — not a high-risk exception.
The 2025 law added a risk category most businesses missed. Every KYC form UAE must now capture Proliferation Financing (PF) indicators — mandatory, not optional.
Every client, individual or corporate, must now be screened for PF indicators.
What AML Checks Should Be Run on Every Client?
Completing the form isn’t enough. For every client, these AML checks are mandatory before onboarding is approved:

- Sanctions screening: check every client and beneficial owner against the UN Security Council Consolidated List and the UAE Local Terrorist List via the EOCN portal
- PEP screening: identify whether the client holds or has held a prominent public function in any jurisdiction. If yes, EDD applies immediately.
- UBO identification: for corporate clients, verify the ownership structure all the way to the natural person holding 25% or more. Nominee arrangements and layered structures require a corporate structure chart.
- Source of Funds verification: understand where the specific funds used in this transaction came from. Salary, property sale, business revenue — documented, not just declared.
- Source of Wealth verification: required for EDD cases. Covers how the client accumulated their total wealth, not just the funds in this transaction.
Every AML checks record, including the MLRO’s reasoning, not just the outcome, must be retained for five (5) years. MoET doesn’t just audit reports, but it audits the decision-making behind them.
Customer Due Diligence UAE: When Each Tier Applies
| CDD Tier | When It Applies | Key Requirements |
| Standard CDD | All clients at onboarding | ID verification, SOF, risk rating |
| Simplified Due Diligence (SDD) | Documented low-risk clients only | Written justification required |
| Enhanced Due Diligence (EDD) | PEPs, high-risk jurisdictions, complex structures, cash ≥ AED 55,000 | SOW verification, Senior Management approval, deeper UBO verification |
Customer Due Diligence UAE Is Ongoing — Not a One-Time Process
Filing the KYC form at onboarding closes the first gate. It doesn’t close all of them.
Under Article 19(1)(b) of Federal Decree-Law No. (10) of 2025, customer due diligence UAE obligations run continuously for the life of the client relationship. That means periodic KYC refreshes when circumstances change, immediate re-screening when a client’s risk profile shifts, and ongoing transaction monitoring against the established client baseline.
Mid-relationship triggers include: UBO changes, new business activities, transactions outside the declared SOF pattern, or a fresh sanctions match. Each one requires the MLRO to review the risk rating and document the outcome — regardless of whether an STR follows.
Summary & Call to Action
A KYC form UAE is not paperwork. It’s your documented proof that AML checks were run, business risk was assessed, and the MLRO made an informed decision before the client relationship started. Without it, every service you perform for such a client carries exposure.
The 2025 law raised the bar. Standard identity collection isn’t enough anymore. PF indicators, UBO verification, Source of Wealth declaration, and third-party payment controls are now baseline requirements — not EDD add-ons. If your KYC forms were drafted before December 2025, they need to be reviewed.
For a full picture of how KYC sits inside your broader compliance obligations, see our guide on AML compliance requirements for UAE DNFBPs. And if your business has already received a MoET Letter of Concern citing CDD gaps, the remediation window is tight.
How CorpLex Helps
CorpLex builds sector-specific KYC forms and full customer due diligence UAE frameworks for DNFBPs. See our AML Compliance Setup service for more.
Need a compliant KYC form for your UAE business? Talk to CorpLex, we build CDD frameworks that hold up under MoET inspection.
Frequently Asked Questions
- What is the difference between KYC and CDD?
KYC (Know Your Customer) is the collection stage in which you gather identity documents, Sources of Funds, and ownership information. CDD (Customer Due Diligence) is the broader process that includes verifying information, assessing risk, and monitoring the relationship on an ongoing basis. KYC is the input, while CDD is the framework.
- Does every DNFBP in the UAE need to run AML checks?
Yes. AML checks are mandatory for every DNFBP regardless of size, sector, or transaction volume. All required businesses are on equal footing under the 2025 law. The only variable is the depth of due diligence applied, which is determined by the client’s risk rating.
- What happens if a client refuses to provide KYC documents?
You should not onboard them. A client who won’t supply identity documents, source of funds, or UBO details is considered a red flag. Under UAE AML law, refusal to provide CDD documentation is itself a suspicious indicator. The MLRO needs to assess whether an STR is warranted.
- Does KYC need to be repeated if a client comes back for a new service?
Yes. This applies if the new service falls outside the scope of the original KYC or if significant time has passed since the last review. The original form reflects the relationship as documented. A new transaction type, a change in business activity, or a shift in risk profile all require the file to be revisited and updated before work proceeds.
- Can a business refuse to accept a client based on KYC findings?
Yes. Completing the form does not mean that you should proceed. The MLRO can only decide upon review of the file and assigning a risk rating. If the risk profile is unacceptable, the business relationship is declined. No reason needs to be provided to the applicant.




