Chat with us, powered by LiveChat

High-Risk Onboarding: What Compliance Teams Look For

September 14, 2026

High-risk onboarding is the name a bank or PSP desk gives a file that cannot close on standard customer due diligence. The analyst has to produce an enhanced record: extra identity, a source-of-funds trail, a source-of-wealth story that matches the balances, senior-management approval, and an expected-activity profile monitoring can test.

Nataly Medici
Nataly Medici
Managing Partner and CEO

Cabinet Resolution 134/2025 Article 5 lists those measures. Article 14 closes the gate if due diligence cannot be applied.

Founders who treat the high-risk queue as a slower copy of a retail SME pack stall on the same five gaps: an ownership chain that stops at a company, a funds story the statements cannot carry, a licence that disagrees with the website, no written EDD narrative, and a licence address with no one the desk can call. AML, KYB and risk work is the framework the desk will read. Company formation and licensing is the permission layer that framework has to match.

What does "high-risk" mean to the onboarding desk?

FATF Recommendation 1 requires enhanced measures where money-laundering or terrorist-financing risk is higher. A UAE licensed financial institution, DNFBP or VASP maps that duty onto Cabinet 134/2025. Article 5 tells the institution to weigh customer, country, product, transaction and delivery-channel risk before it sets the mitigation level. The desk then has to show in writing which extra steps it took.

Appetite sits beside that legal floor. The Central Bank's 6 November 2025 CDD guidance requires a customer-acceptance policy that names relationships the institution will refuse. A complete EDD pack can fail if the sector is outside that policy. The analyst first decides whether enhanced work can start, or whether appetite will close the file.

Cabinet 134/2025 and the high-risk customer

Article 1 defines High-Risk Customers by personal profile, activities, the nature of the relationship, or geography. The examples include customers from high-risk countries, non-residents who do not hold a State-issued identity card, complex ownership, transactions that look economically or legally unjustified, large cash, dealings with unknown third parties, and residual categories the institution or the supervisor adds. Payments, money services, cash-intensive trades, personal asset-holding vehicles, politically exposed persons, and virtual-asset exposure all fall into that band at most desks. Virtual assets sit as one industry factor in that list.

Article 5 then lists the enhanced measures: extra identity and occupation data, beneficial-owner detail, public-source checks, a clearer purpose for the relationship, more frequent CDD refresh, reasonable measures on source of funds and wealth, heavier ongoing monitoring, a first payment through an equivalent-standard account in the customer's name, and senior-management approval to start or continue the relationship. The desk is collecting a file that supports that list.

FATF overlay and what the examiner later asks

FATF Recommendation 10 requires identification, verification, beneficial ownership, and purpose. Recommendation 12 adds PEP systems, senior-management approval, source of funds and wealth, and enhanced monitoring for foreign PEPs. Recommendation 19 requires enhanced due diligence for persons from countries for which FATF has called for such measures.

A later examiner of the bank will ask whether the institution scored the customer, applied matching measures, and kept the evidence. Your pack is part of that evidence. A thin file leaves the bank to decline or to reconstruct the narrative. Many desks will not reconstruct.

How does the desk score a high-risk file in the first hour?

The first hour is a completeness and coherence test. The analyst checks whether identity, ownership, licence, expected activity and screening can open as a case. CBUAE CDD guidance frames that as a customer risk profile: legal form and industry, products the account will use, geographies of expected activity, and claimed volumes. If those four cannot be read from the papers, the file sits in a request queue.

Screening runs in parallel: company, beneficial owners, directors and signatories against sanctions, PEP databases, adverse media and internal deny-or-exit lists. An unworked hit stalls the case. A match with a dated, sourced memo is a risk the desk can escalate.

Identity, control, and the beneficial-owner walk

Article 9 requires identification of the legal person from original documents or a reliable independent source: name and form, constitutional papers, tax number where corporate tax applies, registered office, and senior management. Article 10 walks ownership to a natural person at 25 percent or more, then to control by other means, then to senior management if no natural person appears. FATF Recommendation 24 caps any ownership threshold at 25 percent. Some correspondent packs, including Wolfsberg-style questionnaires, collect a 10 percent layer. A chart that stops at a holding company, or that names a nominee without the nominator, fails that walk.

The desk also tests whether the people who will sign match the board resolution and the bank mandate. A founder who appears as UBO, director, MLRO and sole signatory is common at early stage. The file has to say who reviews alerts if that person is travelling, and who the bank calls when monitoring fires. Silence here is a governance gap.

Expected activity and the monitoring profile the desk has to write

Article 8 requires the institution to scrutinise later transactions against the customer, the nature of the activity, and the risks, including source of funds where needed. High-risk records get particular emphasis on keeping CDD current. The CBUAE guidance repeats that expected activity is the baseline against which unusual movement is judged. A business plan that says "global payments and advisory" with no corridors, no ticket sizes, and no client types gives the monitoring team nothing to code.

The same hour, the analyst opens the website and the licence. If the site sells a product the licence does not name, or names jurisdictions the company has no permission to serve, the risk profile cannot close. The desk will not spend a week on source-of-wealth papers while the activity story is in conflict.

How is a high-risk pack structured?

The pack the desk can finish is a stack of layers. The constitutional layer proves the legal person and the people who bind it. The control layer walks to natural persons and explains nominees. The permission layer shows what the company may do, in which place, under which supervisor. The funds layer shows where the first credit comes from and how high-risk owners built the wealth behind it. The narrative layer is the EDD memo: rating, extra steps, who approved, and monitoring.

That stack is what "bank-ready compliance documentation" means here: a file the analyst can risk-score without rebuilding the business from marketing copy. Approval remains the institution's decision.

Entity, permissions, and the covering note

The covering note is a map. Two pages that name the legal entity, the licence or registration, the products, the client types, the corridors, the account type requested, and the compliance officer the desk can call will save a round of questions. UAE company formation and licensing is where that permission layer is built. A covering note that claims a product the licence does not contain will reopen the file.

Constitutional documents have to match the covering note on name, number, directors and capital. Stale extracts, uncertified translations, and foreign papers that have not completed the UAE consular and MOFAIC chain where the bank requires them, all pause the file. The desk will not guess which version is current.

The EDD layer the standard SME pack never carries

Standard CDD stops at identity, ownership, purpose, and screening. The EDD layer adds the Article 5 extras in a form a second reviewer can audit: public-source checks, SoF/SoW evidence, the senior-management approval trail, and monitoring intensity. The CBUAE CDD guidance illustrates an annual review for a high-risk profile against a three-year cycle for low risk. If the company is a PEP relationship, Article 16 of Cabinet 134/2025 layers on PEP systems, senior-management approval, source of funds and wealth, and enhanced ongoing monitoring for foreign PEPs. Domestic PEPs follow the risk-based path in the same article. The CBUAE CDD PDF still points at older Decision numbering for PEPs; the live obligation is 134.

Founders often read this wait as bank delay. The second line is waiting for a memo it can sign.

Incomplete beneficial ownership: the stall that stops the case file

An incomplete UBO walk fails CDD under Article 14. Enhanced work does not start until the natural person who owns or controls the company is identified and verified. Charts that end at a BVI, Cayman or UAE holding company, trusts described as "family arrangements" without trustee, settlor and beneficiary classes, and bearer-style opacity that Cabinet 134/2025 treats as prohibited for companies in the State, all stop the file before it opens.

Nominees work when the nominator is named and the nominee agreement is in the pack. They stall when the local director is presented as the owner and the economic owner sits off-chart. Multi-layer groups need a dated chart, matching extracts, and IDs for every natural person at 25 percent and for anyone who controls from below that line. If a correspondent or PSP asks for 10 percent, answer that layer in the same chart.

Weak source of funds and source of wealth

Cabinet 134/2025 Article 5 requires reasonable measures to identify the source of funds and wealth of the customer and the beneficial owner once the relationship is high risk. The CBUAE CDD guidance splits the two questions and tells institutions to obtain evidence from the customer and to treat inconsistency between balances and stated wealth as a reason for further corroboration. A screenshot of a wallet, a one-line "savings from business," or a third-country statement with no path into the company does not close either question.

This gap feels personal to founders. The desk needs the first credit, and the wealth behind the capital, to be reconstructable if a supervisor samples the file.

Source of funds: the money that will hit the account

Source of funds is the origin of money that funds the account and that will move through it: salary, share subscription, loan, sale of property, retained earnings from a named account. The evidence is the outgoing statement, the subscription or investment papers, and a path that matches names and amounts. Converted virtual assets still need a fiat origin the bank can read. Article 5 contemplates a first payment through an equivalent-standard account in the customer's name. Plan that rail before you apply.

Source of wealth: how the owners built the capital

Source of wealth is the history that produced the owners' net worth: dividends, an exit, inheritance, professional income over time. The CBUAE example of inheritance versus salary is the right grain. Where balances dwarf the stated career, the desk will ask for tax filings, sale contracts, or public records it can confirm. PEPs attract this question under Article 16 as well as under the general high-risk list. A new company does not take the UBO's wealth out of scope.

Licence and activity mismatch

Article 9 requires the institution to understand the purpose and intended nature of the relationship and the nature of the customer's business and ownership structure. The CBUAE expected-activity block is the same test in operational language. A consultancy licence with a website that sells payment processing, a free-zone activity list that does not include the product on the homepage, or a pending licence treated as if it were a live permission, all produce a conflict the analyst cannot risk-score.

Virtual-asset companies meet a sharper version of this test under CBUAE guidance on VA and VASP risk, including administrative operating accounts versus transactional client-money accounts, and a duty not to service unlicensed VASP activity. Forex, money services, and unlicensed lending follow the same rule: permission must match the flows. Crypto compliance in 2026 covers the control stack when virtual-asset exposure is the factor that pushed the rating up.

Fix the website and the licence, or add a scope note the bank can file, before you submit. Updating copy during onboarding while the case is on hold adds calendar time you will not get back.

The missing EDD narrative

Enhanced due diligence is a documented decision. FATF's risk-based approach does not let the institution apply "more papers" without recording why the rating is high and which extra measures match that rating. Cabinet 134/2025 Article 5 is a list of examples; the file still needs a memo that selects from that list. Senior-management approval is an item on the list. If the pack has no paper that a second-line officer signed, the first-line analyst cannot finish.

Founders often send policies without a customer-specific narrative. A generic AML manual that could sit on any company in any sector tells the desk the extra work has not been done for this relationship. The memo the desk needs is short: the rating, the factors (geography, product, PEP, complex ownership, cash, VA exposure), the extra evidence, residual risk, and monitoring intensity. Building real rules for crypto helps where the product is a virtual-asset rulebook. A payments or holding-company file needs the same decision on paper, without the token overlay.

External intelligence reports appear in the CBUAE CDD examples of EDD when public sources are not enough. Decide before submission whether ownership or geography already requires one.

Thin substance and who the desk can call

Article 9 asks for a registered office or principal place of business, and for foreign persons a legal representative in the State where one exists. The desk reads that together with expected geography. A flexi-desk licence, no UAE-resident director, an MLRO who is also the CEO sitting in another time zone, and a website that describes a team the corporate documents do not name, produce a substance question. Extra PDFs do not fix a structure in which no one can answer a monitoring query in the bank's working hours.

Governance, for this desk, is narrow: who binds the company, who owns compliance, and who picks up the phone. A board resolution, a named compliance officer whose CV matches the licence file, and an escalation path from first-line review to senior management are the signals. AML/CFT policy and onboarding design is the work that makes those signals operational. A structure that cannot be explained in two paragraphs will generate questions before the funds layer opens.

Bank, PSP and CEX desks: three reviews, one fact order

A licensed bank, a payment institution, and a centralised exchange each run a high-risk desk with a different residual-risk problem. The papers overlap. The stall points do not. Payments nested through a PSP create correspondent-style exposure the bank does not carry in the same form. An exchange onboards the entity as a trading counterparty, then the bank still has to underwrite the fiat rail. Read the three in the same order: what pushes the file into high-risk, what the desk weights, where files stall, the clock, when the path fits, and when it fails. Confirm live product terms; the clocks below are planning ranges, not a quote.

Licensed bank desk

What pushes the file into high-risk: the bank's own risk methodology plus Cabinet 134/2025 categories, including industry (financial services, cash-intensive, VA), complex ownership, PEP, high-risk geography, and non-face-to-face onboarding without compensating checks. CBUAE CDD names those industry and structure examples in plain language.

What the desk weights: a CDD file it can defend to the Central Bank, including UBO walk, SoF/SoW for the high-risk band, expected AED and cross-border flows, and senior-management approval. UAE payroll through the Wage Protection System and government-fee payments still point many groups at a licensed-bank IBAN even when they also hold EMI accounts.

Where files stall: incomplete UBO, SoF that cannot be reconstructed, licence mismatch, and appetite. C 2/2026 Article 4.52, from 13 September 2026, will require a register of SME account requests, rejections and reasons, opening times, and counts by low, medium and high ML/TF risk. On 24 August 2026 that regulation is published and not yet in force.

Clock: Medici's public FAQ cites two to four weeks for a standard corporate file and six to eight weeks for high-risk crypto or fintech, counted from a complete pack. Incomplete papers reset the count. Confirm the live product terms with the institution.

Fits when: you need a UAE-licensed bank relationship, you can finish CDD, and the sector is inside appetite. Fails when: the sector is excluded by policy, CDD cannot be completed, or you needed a transactional VASP client-money account and have not planned the extra control and, where applicable, non-objection path that guidance describes for that account type.

PSP and EMI desk

What pushes the file into high-risk: nested flows, third-country clients, high-risk MCC or product types, and the PSP's own licence conditions. The PSP is underwriting your customers as well as you.

What the desk weights: KYB that matches its programme, your own onboarding rules, sanctions and Travel Rule or equivalent payment-transparency controls where the product moves value to VASPs or other PSPs, and a volume forecast its monitoring can hold.

Where files stall: a policy that names no tools, a client perimeter the website contradicts, and a UBO chain the PSP's threshold (sometimes tighter than 25 percent) cannot close.

Clock: often shorter than a full bank file when the product is a payment account rather than a current account with lending, and still weeks on high-risk names. A PSP IBAN does not cover every UAE bank use case.

Fits when: settlement rails and multi-currency collections are the job, and you already hold or can hold a licensed-bank account for payroll and local AED where required. Fails when: you needed WPS, a local cheque book, or a relationship the PSP's licence cannot support.

CEX and institutional exchange desk

What pushes the file into high-risk: corporate or institutional onboarding, source of crypto-assets, nested VASP clients, and jurisdictions on the exchange's restricted list.

What the desk weights: entity documents, UBO, the licence that authorises the activity you will fund or trade, and a funds trail from named accounts or wallets the venue can screen.

Where files stall: treasury wallets with no fiat origin, an entity that is not the licensed operating company, and a business description that looks like an unlicensed VASP.

Clock: venue-specific; treat it as a second high-risk file.

Fits when: the venue is a counterparty you can name in the bank's expected-activity note. Fails when: the exchange relationship is the only fiat story and the UAE operating company has no licensed-bank or authorised PSP rail for payroll and fees.

When the file stalls, and after a recorded refusal

A stall is a request for a missing layer. Answer it with the layer, not with a restatement of the pitch deck. Parallel applications to three institutions with the same gap produce three files that look alike to the next analyst, including against internal deny-or-exit lists the CBUAE CDD guidance expects institutions to screen.

A recorded refusal is a different sequence. Ask for the reason in writing where product terms allow it. C 2/2026 Article 3.12, once in force, will require a written reason except for financial-crime grounds or a legal bar. Financial-crime silence means the next pack has to assume a CDD or sanctions problem you have not closed. Nataly Medici, Managing Partner and CEO at Medici Expert, puts the documentation cost in one line: "We tell clients early: a license rejected for sloppy documentation is harder to recover from than one that was never filed." Fix the gap, then apply. The ordinary UAE corporate account path for a complete low-complexity file sits on a two-to-four-week band in Medici's public FAQ; high-risk files live on a longer clock because the EDD layer exists. UAE company formation and licensing is the licence side of that file.

A complete pack is not a right to an account. Appetite decisions survive a finished file. The work is to remove the stalls the desk is required to raise, so the remaining question is the one the institution's board already answered in its risk-appetite statement.

What a bank-ready high-risk file looks like in practice

A file that moves is coherent across layers. The covering note, the licence, the website, the ownership chart, the SoF path, the SoW story, the AML policy, and the EDD memo describe one company. The monitoring profile uses numbers the business can defend in month three. Senior management at the applicant has signed the same story the bank's senior management is asked to approve.

Confirm live rules before you file. Cabinet 134/2025 and the November 2025 CDD guidance are the UAE spine as of August 2026. C 2/2026 SME customer-protection clocks and rejection records apply from 13 September 2026. FATF lists and the institution's appetite change without a press release to you. Commercial formation, advisory, compliance and banking fees sit outside this map and are not a Medici quote.

FAQ

What is the difference between KYC, CDD and EDD?

KYC is the identity work on a natural person. CDD is the duty to identify the customer and beneficial owner, understand purpose, and monitor the relationship. In the UAE that duty sits in Cabinet 134/2025 Articles 6 to 10 and 14. EDD is the extra measures Article 5 requires when the customer or the geography is high risk: more information, SoF/SoW, heavier monitoring, and senior-management approval.

What high-risk factors do KYC teams flag at onboarding?

Cabinet 134/2025 Article 1 points at high-risk countries, non-residents without a State identity card, complex ownership, unjustified or cash-heavy transactions, and unknown third parties. The CBUAE CDD guidance adds higher-risk industries such as financial services, unusual legal-entity structures, cash-intensive businesses, and personal asset-holding vehicles. PEP status and FATF high-risk country exposure sit on top of that list. The institution's appetite statement can exclude a sector even when those factors are documented.

Does enhanced due diligence mean the bank will open the account?

EDD is a condition of taking the relationship. The institution applies Article 14 if CDD cannot be completed, and it applies its customer-acceptance policy. A complete EDD pack lets the desk decide. Approval remains a separate appetite and residual-risk call.

How long does high-risk onboarding take at a UAE bank or PSP?

Medici's public FAQ cites six to eight weeks for high-risk crypto and fintech files from a complete pack, against two to four weeks for a standard corporate file. Each request for a missing layer stops that count. PSP and exchange desks follow their own service levels. C 2/2026's three-business-day expectation, once in force, is for low-risk SME files with complete CDD, not for high-risk EDD.

What does a bank-ready compliance file contain at a high-risk rating?

It contains the CDD core plus an EDD layer: a covering note that matches licence and website, an ownership walk to natural persons, SoF evidence for the first credit, SoW evidence for high-risk owners, a customer-specific narrative and senior-management trail, and a monitoring profile with corridors and volumes. The stall happens when a layer is missing or the layers disagree.

Why do compliance teams ask for source of wealth as well as source of funds?

Source of funds explains the money in the account. Source of wealth explains how the owners accumulated the capital behind that money. Cabinet 134/2025 Article 5 and the CBUAE CDD guidance both require SoW measures on higher-risk relationships. Balances that dwarf the stated career without corroboration keep the file open.

Can I apply to several banks while one high-risk file is on hold?

You can. If the hold is a CDD gap, the second desk will raise the same gap, and internal decline lists capture prior financial-crime exits. Finish the layer, then multiply applications. Appetite-only declines are the case where a second institution with a different policy is the rational next step.

Sources

Connect with our experts

Get full clarity on licensing, compliance and structuring before you spend time and budget on the wrong move.

Book a Free Call

Ready to build a structure that actually works?

Whether you are launching a fintech company, applying for a license, entering the UAE, issuing a token or preparing for regulatory review — we can help you choose the right path before costly mistakes happen.

Book a Free Call