Sanctions Screening: Building a Process That Holds Up
A sanctions screening process that a bank, PSP, VARA, DFSA, FSRA or CBUAE desk will accept is a documented loop: lists you subscribe to, names you search, moments you search them, a human disposition of each hit, a freeze without delay on a confirmed match, a goAML filing inside the live notice clock, a ban on tipping off, and records that reconstruct the decision. The reviewer samples the loop.
AML/CFT policy work writes the decision rights. UAE company formation and licensing produces the entity. The screening procedure is a separate artefact. Wallet analytics and KYT scenarios belong in a monitoring procedure, not in this file.
What does a reviewer sample in a sanctions screening process?
The first request is the field map and the last freeze file. A bank or PSP asks whether your customer types and payment rails would stop a listed person before funds move. VARA asks whether clients and virtual-asset transfers hit an updated list in real time and whether freeze records run eight years. DFSA and FSRA ask whether the DIFC or ADGM entity implements federal TFS plus their module. CBUAE asks whether Cabinet Decision 74 Article 21 searches run on the live UN Consolidated List and the UAE Local Terrorist List, and whether a confirmed match froze funds without prior notice.
Ksenia Babochkina, Commercial Director at Medici Expert, put the wider point on the compliance page: “Regulators move faster than founders expect. What was low-risk eighteen months ago can be a licensing requirement today.” Decree-Law 10 of 2025 and Cabinet Resolution 134 of 2025 rewrote the federal AML floor in late 2025. Targeted financial sanctions still sit on Cabinet 74 of 2020. The process has to cite the live instruments.
Staff who cannot operate the procedure without the consultant fail the walkthrough. The sample is a name, a payment, a list update on a public holiday, and a goAML acknowledgement.
Which UAE instruments bind the process in 2026?
Federal Decree by Law No. (10) of 2025 entered into force on 14 October 2025. Article 19 requires financial institutions, DNFBPs and VASPs to implement the Executive Office’s targeted financial sanctions instructions, apply CDD, refuse anonymous accounts, keep senior-management-approved policies, and retain records. Article 18 requires a suspicious transaction report to the Financial Intelligence Unit without delay where you suspect, or have reasonable grounds to suspect, proceeds or an intended crime
Cabinet Resolution No. (134) of 2025 entered into force on 14 December 2025. Article 14 prohibits establishing or continuing a relationship, and prohibits executing a transaction, where you cannot apply CDD. Article 19 of that Resolution is the STR tipping-off ban, not the TFS freeze rule. Article 5(3) allows simplified due diligence only after a documented low-risk assessment, in coordination with the supervisor, and only if TFS instructions still run in full. Article 5(4) requires extra internal controls where proliferation-financing risk is high, aimed at breach or circumvention of TFS.
Cabinet Decision No. (74) of 2020 remains the list-implementation statute. Article 1 defines “Without Delay” as within 24 hours of the listing decision by the UN Security Council, the Sanctions Committee or the UAE Cabinet. Article 15 requires any person to freeze funds on the Sanctions List and Local Lists without prior notice, covering funds owned or controlled, wholly or jointly, directly or indirectly, by the listed person, and funds of a person acting on their behalf or at their direction. Article 15(2) requires notice to the Executive Office within five business days of the freeze. Article 21 then sets the operating duties: register for list alerts, screen the named universe, freeze on match, lift on official delisting, notify the Supervisory Authority of the listed events, and forbid staff from telling the customer that a freeze is coming.
The Executive Office for Control and Non-Proliferation (EOCN) issues the operational TFS guidance and the list-alert service. CBUAE’s Targeted Financial Sanctions page, last updated 4 February 2026, restates four steps for licensed financial institutions: know the lists, screen, freeze or suspend without delay and without prior notice, and report through goAML. FATF Recommendations 6 and 7 describe freeze-without-delay TFS for terrorist financing and proliferation financing. Write the procedure to Cabinet 74 and Decree-Law 10. FATF is the overlay a correspondent will still quote. Older CBUAE LFI TFS guidance, still marked in force from 4 July 2021, prints a two-business-day notice to CBUAE and the Executive Office. The statute and the February 2026 CBUAE page use five. Confirm the live page for your licence before you hard-code an SLA.
Who sits in the screening universe?
Cabinet Decision 74 Article 21.2 names the search set: customer databases, parties to any transactions, potential customers, beneficial owners, and persons and organisations with which you have a direct or indirect relationship. You also search the customer database before a transaction and before you enter a business relationship. CBUAE restates that set for licensed financial institutions and, for hawala providers, adds the senior managing official of a legal person. An engine that only loads the onboarding-form name leaves directors, signatories, UBOs and the other side of a payment untested. The reviewer will ask which source systems feed the engine and which party types those fields cover.
Customers, beneficial owners, directors and related parties
Name screening covers every data set, separate from transaction records, that can show a listed person before you take them on. CBUAE’s screening guidance treats that set as customer names, beneficial owners, related parties collected under CDD, and third-party service providers where you outsource a function. Directors and authorised signatories sit in the “direct or indirect relationship” limb of Article 21.2. If the corporate file names them and the engine never sees them, the statutory search set is incomplete.
Beneficial-ownership evidence is a KYB file. The screening procedure does not rebuild that file. It states that every natural person identified as a beneficial owner, and every senior manager used as the fallback, is a screening subject from the moment the name is known, including before approval. Potential customers belong in the same run. A rejected applicant who matched a list still needs a record: Article 21.5 requires notice where a previous or occasional customer is later listed, and EOCN wants confirmed-name reports on prior relationships covering five years, including closed accounts.
Cabinet 74 Article 15 freezes funds owned or controlled by the listed person and funds of a person acting on their behalf or at their direction. EOCN’s examples freeze a company the listed person owns above 50 percent, a company they control through voting rights as a minority, and a non-listed person holding their power of attorney. Staff have to screen those names and freeze the controlled asset, not only the customer row.
Counterparties, payment parties and occasional users
Article 21.2 requires a search of parties to any transaction. CBUAE’s LFI TFS guidance adds incoming and outgoing transfers: originator, beneficiary, and, where the message carries them, other parties in the chain. Payment transparency fields that are empty or overwritten with “our customer” are a data-quality defect the sanctions team must escalate, because the engine cannot match a blank.
Occasional users sit in the same universe. A walk-in remittance, a one-off VASP conversion, or a seller in a property file is a potential customer and a party to a transaction. EOCN’s examples freeze an attempted exchange-house transfer and a cryptocurrency exchange wallet on a confirmed name. Name those moments in your rails.
Unilateral lists (OFAC, EU, UK) are a separate control. Banks and PSPs that clear dollars or euro will sample whether you screen them. EOCN states that a match on those lists does not trigger a TFS freeze or a CNMR/PNMR, and that you may file an STR/SAR and consult the supervisor. Write the extra list set as a correspondent requirement.
When must screening run?
Article 21.2 requires regular searches, an immediate search when you are notified of a list change, and a continuous search of the customer database before a transaction or a business relationship. EOCN lists four operational moments: on any update to the Local Terrorist List or the UN Consolidated List; prior to onboarding; on KYC reviews or changes to customer information; and before processing any transaction. CBUAE’s screening guidance, citing EOCN, expects name screening prior to onboarding and at least daily thereafter. A procedure that screens at onboarding and again at year-end misses the list-update clock that defines “without delay”.
Before onboarding and before a transaction
Pre-onboarding screening is a gate. Potential customers are in Article 21.2. If a partial match cannot be cleared from documents you already hold, EOCN’s examples require you to suspend or reject the application, refrain from services, and file a PNMR. You may ask for more identity data. You may not tell the applicant they hit a sanctions list.
Transaction screening is a second gate. Name screening of the static file does not discharge the duty to search parties to the payment. CBUAE distinguishes name screening from transaction screening, which is a movement of value. Live payment filtering belongs on rails that can move funds before a human reads an alert. A payment that left the house before the hit is a missed freeze plus a reporting event.
Digital asset legal support does not replace that gate. VARA-licensed VASPs must screen clients and transactions against UNSC and federal lists with automated systems that are updated and operate in real time, and must freeze virtual assets and money on a match. Wallet-risk scores sit in a KYT procedure. Every client and every transfer is a TFS screening subject before the asset moves.
List updates, weekends and ongoing rescreening
Registration on the EOCN alert service is an Article 21.1 duty. CBUAE tells licensed institutions to use the UN Security Council consolidated list page and the Executive Office local-list pages as the official sources, and to take the email alerts as the change signal. A vendor feed is a convenience. If the feed lags the EOCN mail, the freeze clock still runs from the listing decision.
EOCN is explicit about weekends and public holidays. If customers cannot access assets during the closure, screening starts from the first minute of business and freezing applies immediately. If they can access assets, the prohibition on use still applies. The procedure has to say who is on call and how the engine rescreens the full database when a listing lands on a Thursday evening.
Ongoing rescreening also fires when you change customer data. A new director, UBO, authorised signatory or counterparty on a standing instruction is a new screening subject. CBUAE’s “at least daily” name-screening expectation is the floor for LFIs using automated systems. Firms that screen by hand still need a dated log that the latest lists were run against the latest names before the next payment.
How do you dispose a hit: confirmed, partial, false positive?
EOCN describes four outcomes. A confirmed name match is a person, entity or group that matches the key identifiers on the UAE Local Terrorist List or the UN Consolidated List. A false positive is a hit that those identifiers (full name, date of birth, nationality, and the rest of the published set) prove is not the listed person. A partial name match is a hit you cannot take to either pole. A negative match is no hit.
Disposition is a named human decision with a second-person review on confirmed and unresolved partials. The second reviewer is independent of who originated the relationship. CBUAE expects documented whitelist treatment for names that were hits and then cleared, with periodic review, because a new listing can turn yesterday’s false positive into a freeze.
A confirmed match freezes. EOCN and CBUAE treat account closure as a failure to hold the funds. You prohibit services, keep the freeze until delisting or an EOCN cancellation through goAML, and you record the identifiers you used.
A partial match suspends. You stop the transaction and the service, keep the suspension until EOCN instructs you through goAML to cancel it or convert it to a freeze, and file a PNMR. Asking the customer for a story that “clears” a hit you cannot tell apart is how staff manufacture a false negative.
Politically exposed persons are a CDD category under Cabinet 134 Article 16, not a TFS listing. Screening products often mix PEP, adverse media and sanctions in one queue. A PEP hit is an EDD path: senior-management approval, source of funds and wealth, enhanced monitoring. It is not a freeze-without-delay event unless that person is also on the UN or UAE lists. Keep the queues separate.
Freeze without delay, notice clocks, and no tip-off
The freeze is the legal act. The goAML filing is the notice. A late freeze with a timely report is still a breach. Article 1 of Cabinet 74 measures “without delay” from the listing decision: 24 hours. Article 21.3 then requires you to freeze immediately when screening finds a match, without prior notice to the listed person. CBUAE’s February 2026 TFS page uses the same sequence: freeze or suspend first, then report. Staff who wait for a Monday committee after a Saturday listing have already missed the listing clock that the reviewer will reconstruct from the alert mail and the freeze timestamp.
Freeze, prohibition, and what you must not do
On a confirmed match you hold the funds. You do not send them, return them to the remitter, or pay them to the customer. Cash goes to a segregated place. Book funds go to a blocked account. A completed payment needs a notice to the counterparty so they can freeze the far end. EOCN’s examples freeze current accounts, cards, loan facilities, stock portfolios and policy benefits, including future receipts that the relevant UN resolutions attach to the frozen pot.
Article 15(3) forbids making funds available or providing financial or other related services to the listed person except with Office authorisation. VARA adds an explicit ban on withdrawals, transfers or use of frozen virtual assets and money. Delisting lifts the TFS freeze without a new EOCN approval unless another competent authority has a freeze order on the same person. A false-positive lift follows Article 18: the affected person petitions the Office, and you lift when the Office tells you to.
goAML clocks, FFR/CNMR versus PNMR, and no tip-off
Cabinet 74 Article 15(2) gives five business days from the freeze to notify the Office. EOCN’s live guidance puts confirmed-name and partial-name reports on goAML within five business days, measured from the freeze, the suspension, or the rejection, depending on the example. CBUAE’s TFS page, updated 4 February 2026, uses the same five-business-day window and names two goAML types: Fund Freeze Report for a confirmed match, Partial Name Match Report for a potential match. Older CBUAE LFI TFS guidance, still marked in force from 2021, and the registered-hawala Rulebook node, still print two business days. Write the SLA from the live page for your licence.
EOCN speaks of CNMR and PNMR. CBUAE’s current TFS page speaks of FFR and PNMR. Both land on goAML. Operations staff use the types their goAML registration displays. Non-goAML users email tfs@eocn.gov.ae within five business days of a freeze.
Article 21.7 of Cabinet 74 forbids staff from telling the customer or any third party that a freeze or other measure will be applied. Cabinet 134 Article 19 forbids telling the customer that an STR has been or will be filed. Those are two bans. A call to “explain a compliance hold” after a confirmed match tips the freeze. Discussing a planned STR tips the report. Group information-sharing under Cabinet 134 Article 32 is a narrow carve-out.
CNMR/FFR and PNMR are not STRs. EOCN tells reporting entities to file an STR/SAR where they suspect sanctions evasion without a UAE or UN name match, including unilateral-list hits. Use TFS reports for TFS matches. Use goAML STR/SAR for suspicion.
Process step × what the reviewer samples × what a software tick-box misses
August 2026 against Cabinet 74, the live EOCN TFS guidance, and the CBUAE TFS page dated 4 February 2026. Confirm the notice clock on the page that applies to your licence.
List sources and alerts
Sample EOCN registration, the UN consolidated list URL, the local-list URL, dated alert emails, and vendor-feed versus official-list reconciliation. A tick-box that says “Global watchlists on” with no EOCN subscription and no UN/UAE source fails.
Screening universe
The field map must cover customer, potential customer, UBO, directors, signatories, payment parties, and related parties, plus legal-person control/ownership freeze. Screening the customer-name field only, while the UBO sits in the KYB PDF and never in the engine, misses the universe.
Pre-onboarding screen
Reviewers sample rejected and suspended applications, PNMR on uncleared partials, and evidence that no services ran before clearance. Batch screen after the account is live is the software miss.
Ongoing name screen
Daily (or documented) full-file rescreen, rescreen on KYC change, and a named owner of Thursday-night listings. An annual “rescreen” in a policy sentence is not ongoing screening.
List-update clock
Time from EOCN/UN listing to engine load to freeze, plus a weekend/holiday runbook. Next-business-day batch presented as “without delay” fails the clock.
Transaction screen
Pre-execution filter on originator, beneficiary and message parties, with empty-field escalation. Posting then screening the ledger overnight is the miss.
Hit disposition
Four-way outcome, second-person review, identifier worksheet, whitelist governance. Auto-close below a score, or a PEP queue mixed with TFS, is not disposition.
Confirmed-match freeze
Blocked account or VA wallet, no return of funds, attempted-transaction record, and control/ownership freeze of related assets. Account closure or “exit the client” is not a freeze.
goAML notice
FFR/CNMR or PNMR acknowledgement inside the live clock, with attachments that show frozen assets. “We will notify the MLRO” or an email to the relationship manager is not notice.
No tip-off
Call logs and client messages around the freeze, plus scripts that forbid “compliance hold” explanations. A customer template that names sanctions is a tip-off.
Extra lists (OFAC/EU/UK)
Documented as correspondent controls, with an STR path and no CNMR on those hits. Using the same freeze playbook as Cabinet 74, or no screening at all, misses the extra-list path.
Records and test
Five-year screening log (eight-year freeze log if VARA), and an independent test of thresholds, data completeness, and missed listings. A vendor certificate in the board pack is not that test.
Records, testing, and the walkthrough that still fails
EOCN requires records of all screening results for at least five years, and confirmed-name reports on prior relationships covering the same span, including closed accounts. Cabinet 134 Article 25 keeps the federal AML record clock at five years from the latest listed event. VARA-licensed VASPs keep freeze-action records for a minimum of eight years, and keep specified AML books for the same span, with no fixed end date where records may relate to UAE national security.
CBUAE wants independent testing of the screening system: expected alerts, threshold behaviour, and complete data from the core system into the engine. Board and senior management own the defects. A quality-assurance sample of disposition files is part of that programme.
Crypto compliance in 2026 is the wider stack around a VASP. Building real rules for crypto is the difference between a heading and an operable control. The walkthrough that fails is a licensed entity whose policy cites Decree-Law 10, whose screening vendor is switched on, and whose staff cannot show a dated list-update, a freeze that held funds, and a goAML acknowledgement. The AML/CFT policy states obligations and risk appetite. The sanctions screening procedure tells staff which lists, which names, which moments, which freeze, which report. KYT and wallet analytics watch movements after the name screen. Keep those three documents apart. Point each to the other.
Nataly Medici has said a licence rejected for sloppy documentation is harder to recover from than one that was never filed. A screening process copied from a software brochure fails the same way.
FAQ
What is the process of sanctions screening in the UAE?
You subscribe to EOCN list alerts, screen the Article 21.2 universe against the UN Consolidated List and the UAE Local Terrorist List at onboarding, on list updates, on KYC change and before transactions, dispose each hit, freeze a confirmed match without prior notice, and file through goAML inside the live notice clock. Records have to reconstruct that sequence.
When must sanctions screening be performed?
EOCN requires a run on every Local or UN list update, before onboarding, on KYC reviews or customer-data changes, and before any transaction. CBUAE’s screening guidance expects name screening before onboarding and at least daily thereafter for LFIs. “Without delay” for a new listing is within 24 hours of the listing decision under Cabinet 74 Article 1.
Who must you screen besides the customer?
Cabinet 74 Article 21.2 requires customer databases, potential customers, beneficial owners, parties to transactions, and persons or organisations with a direct or indirect relationship, including directors and signatories once you hold those names. Legal persons also need a control and ownership test so a listed UBO or attorney-in-fact freezes the asset they command.
What does freeze without delay mean?
Cabinet 74 Article 1 defines without delay as within 24 hours of the listing decision. Article 21.3 requires an immediate freeze when screening finds a match, without telling the listed person in advance. You hold the funds. You do not return them or close the account to move the problem off the book.
How long do you have to notify EOCN after a confirmed match?
Cabinet 74 Article 15(2), EOCN’s live TFS guidance, and CBUAE’s TFS page updated 4 February 2026 use five business days from the freeze (or from the suspension or rejection, in EOCN’s partial-match examples), via goAML. Older CBUAE LFI TFS guidance still prints two business days. Confirm the live page for your licence. Freeze first. File second.
Do OFAC or EU lists trigger a UAE TFS freeze?
A match on a unilateral or multilateral list other than the UN Consolidated List or the UAE Local Terrorist List does not trigger Cabinet 74 freeze or a CNMR/PNMR. EOCN tells you to consult the supervisor and to consider an STR/SAR. Correspondent banks may still require those extra lists as a contract control.
How long must you keep sanctions screening records?
EOCN: at least five years for screening results, plus confirmed-name reporting on prior relationships over five years, including closed accounts. Cabinet 134 Article 25: five years for AML records from the latest listed event. VARA: freeze-action records at least eight years if you hold that licence.
Can screening software alone satisfy a bank or VARA review?
A reviewer samples lists, universe, clocks, freeze files, goAML acknowledgements, tip-off controls and independent tests. A switched-on engine with no field map, no weekend runbook and no freeze record fails that sample. Choose a tool that can load official lists and your party types.
