“You cannot manage a risk you have not measured, and in AML compliance, PEP screening is how you measure the political-exposure risk hiding inside your customer book.”
Customer Due Diligence, or CDD, is the process a UAE business uses to confirm who its customer really is and to judge whether that relationship carries any financial-crime risk. It is not a one-off form. It is a full lifecycle that starts before onboarding and continues for as long as the account stays open. Somewhere inside that lifecycle sits PEP screening, the specific check that flags Politically Exposed Persons, their close relatives, and known associates.
Under the UAE’s AML/CFT framework, driven by Federal Decree-Law No. 20 of 2018 and its executive regulations, financial institutions and Designated Non-Financial Businesses and Professions (DNFBPs) are required to identify PEPs and apply extra safeguards when they find one. This includes banks, exchange houses, insurers, real-estate brokers, gold and precious-metals dealers, auditors, corporate service providers, and virtual-asset firms. If your regulator expects a suspicious transaction report from you, PEP screening is part of the baseline they will audit against.
KYC, CDD, EDD, and PEP screening: how they actually connect
These four terms get used almost interchangeably, which causes real confusion during audits. They are related, but not the same.
- KYC (Know Your Customer) is the identity layer. Collecting the passport copy, Emirates ID, trade licence, ownership chart. It answers “who is this?”
- CDD (Customer Due Diligence) is the wider process that includes KYC plus risk assessment, source-of-funds review, purpose of the relationship, and screening against sanctions and PEP lists. It answers “who is this and how risky are they?”
- PEP screening is one specific check inside CDD. It compares the customer, beneficial owners, and often authorised signatories against curated PEP databases.
- EDD (Enhanced Due Diligence) is what you apply on top of standard CDD when the customer is higher risk, which includes every confirmed PEP. It answers “given the risk, what extra evidence and approval do I need?”
A useful way to picture it: KYC is a subset of CDD, PEP screening is a step in CDD, and EDD is triggered by CDD findings. Getting these distinctions right in your policy manual makes examiner conversations far shorter.

A simple CDD process, with PEP screening in its right place
Most UAE-licensed firms structure their CDD workflow around the same core steps. PEP screening usually lives at step three, but the checks should also fire again whenever a customer’s details change or a periodic review is due.
- Customer identification. Collect and verify identity documents, trade licences, and ultimate beneficial ownership up to the 25% threshold set by UAE regulations.
- Initial risk assessment. Score the customer on jurisdiction, industry, product used, delivery channel, and transaction pattern.
- Sanctions and PEP screening. Run the individual, entity, UBOs, directors, and authorised signatories against sanctions lists and PEP databases.
- Decision. Approve at standard CDD level, escalate to EDD, or decline. A PEP hit does not automatically mean rejection. It means “escalate.”
- Enhanced Due Diligence (if triggered). Obtain senior-management approval, document source of wealth and source of funds, and set a stricter monitoring rule set.
- Ongoing monitoring. Rescreen against updated lists, review transactions for unusual patterns, and refresh CDD data on a risk-based cycle.
- Reporting. File a Suspicious Transaction Report with the UAE FIU through the goAML portal if anything crosses the threshold.
One of the most common mistakes is treating a positive PEP match as a red flag that ends the relationship. It is not. The FATF Recommendations that the UAE aligns with are clear: being a PEP is a risk indicator, not a crime. A cabinet-level official may have entirely legitimate wealth. The obligation on the business is to understand that wealth and monitor it properly, not to refuse service by default.
Where the risk becomes unmanageable is when a firm skips the extra work. Onboarding a PEP under standard CDD, without senior sign-off and without documenting source of wealth, is where regulatory penalties tend to land. Recent enforcement actions in the UAE have run into the millions of dirhams for exactly this failure pattern.
What EDD looks like in practice, and why ongoing monitoring is the real test
Once a PEP is confirmed, Enhanced Due Diligence turns the volume up on every part of the file. Expect to gather more evidence, involve more senior people, and revisit the relationship more often.
- Obtain written approval from senior management before opening or continuing the account.
- Document source of wealth (how the overall net worth was built) and source of funds (where the specific money in this transaction came from), with supporting evidence.
- Screen close family members and known associates, not only the PEP themselves.
- Apply tighter transaction-monitoring rules with lower alert thresholds.
- Shorten the CDD refresh cycle, typically to annual or every six months rather than the standard three-year window.
- Keep a clear audit trail of every decision, review, and escalation.
- Rescreen the customer against updated PEP and sanctions lists on a continuous or at least daily basis.
This is why firms that take compliance seriously invest in due diligence consulting before their next regulatory inspection. Building a defensible EDD file after the fact is painful. Building it correctly during onboarding is straightforward.
The ongoing-monitoring piece deserves its own emphasis. A person who is not a PEP today may become one tomorrow: a senior civil servant is promoted, a business partner is appointed to a state-owned enterprise, a family member enters politics. If you only screen at onboarding, you will miss every one of these changes. Continuous screening against refreshed lists is what turns CDD from a form-filling exercise into an actual control.
Why automation is no longer optional
Manual PEP screening was viable when your book was small and lists were short. It is not viable now. Global PEP databases run into the millions of records, are updated daily, and include fuzzy matching for transliteration variants that matter enormously in the Arabic-name context. A single MLRO cannot keep pace by hand.
Automated screening tools handle three things a human team struggles with: they run every customer against updated lists overnight, they apply consistent scoring so two analysts do not reach different conclusions on the same name, and they log every check with a timestamp that stands up in an audit. For UAE firms working across GCC languages, the ability to match Arabic and Latin script variants of the same name is the difference between catching a PEP and missing one entirely.
Frequently asked questions
Is every UAE business required to do PEP screening?
No, only entities covered by the UAE AML/CFT framework. That includes banks, exchange houses, insurers, and all DNFBPs such as real-estate brokers, gold and precious-metals dealers, auditors, corporate service providers, and virtual-asset service providers. If you are unsure whether your licence category is in scope, check with your regulator or a qualified compliance advisor before assuming you are exempt.
Does a PEP match mean I have to refuse the customer?
No. A PEP status is a risk indicator, not a prohibition. The regulatory expectation is that you escalate the file to Enhanced Due Diligence, obtain senior-management approval, document source of wealth and source of funds, and apply stricter ongoing monitoring. Blanket de-risking of all PEPs is actually discouraged by FATF and by UAE supervisors.
How often should I rescreen existing customers?
Best practice in the UAE is continuous or daily rescreening against updated sanctions and PEP lists, because a customer’s status can change at any time. Full CDD file refresh is risk-based: typically every three years for low-risk customers, annually or more often for high-risk customers and confirmed PEPs.
What is the difference between a domestic PEP and a foreign PEP?
A foreign PEP holds or has held a prominent public function in a country other than the UAE. A domestic PEP holds such a function inside the UAE. International organisation PEPs, such as senior officers of the UN or IMF, form a third category. All three require enhanced measures under the UAE framework, though supervisors expect firms to calibrate the intensity of EDD to the specific risk profile.
What are the penalties for failing to conduct proper PEP screening?
Penalties in the UAE range from administrative fines that can reach several million dirhams per breach, to licence suspension or revocation, and in serious cases criminal liability for the officers responsible. Reputational damage and correspondent-banking de-risking often cost even more than the direct fine.
Do I need to screen beneficial owners as well as the direct customer?
Yes. UAE regulations require identification and verification of Ultimate Beneficial Owners at the 25% ownership or control threshold, and those UBOs must be screened against sanctions and PEP lists just like the primary customer. Directors and authorised signatories are usually included in the same screening workflow.
Can a small firm run PEP screening without a dedicated compliance team?
It is possible but risky. Even small DNFBPs are expected to have a designated compliance officer and a documented AML programme. Most small firms outsource the screening technology to a specialist provider and either hire a part-time MLRO or retain an external compliance consultant to review escalations and file reports through the goAML portal.


