- Front
- AML Compliance
- UAE High-Risk Country Updates: How to Refresh Your AML Controls
UAE High-Risk Country Updates: How to Refresh Your AML Controls
High-risk country updates can affect customer risk ratings, EDD, transaction monitoring, sanctions screening and governance. Here is how UAE businesses can refresh AML controls in a practical, traceable way.
Key takeaways
- A high-risk country update should trigger customer, EDD, monitoring and governance reviews rather than only a screening-list change.
- FATF increased monitoring does not automatically mean every connected customer must be rejected or subjected to identical controls.
- UAE businesses should assess geographic risk together with customer, beneficial-owner, transaction and source-of-funds information.
- AML country risk and sanctions status require separate control logic.
- Compliance teams should maintain evidence linking the regulatory update to risk decisions, approvals and control testing.
- Country classifications should be verified against current FATF and applicable UAE regulatory sources.
What does a high-risk country mean for UAE AML compliance?
A high-risk country is a jurisdiction whose money laundering, terrorist financing or proliferation financing exposure requires increased attention under the applicable risk framework. The effect on a UAE business depends on the official classification, UAE regulatory instructions, the customer's actual connection to the jurisdiction and the overall risk profile of the relationship.
Geographic exposure may arise through more than nationality or residence. A UAE company may need to consider where a customer is incorporated, where its beneficial owners live, where funds originate, where counterparties are located and whether payments are routed through other jurisdictions.
This matters for mainland businesses and companies operating in commercial free zones that fall within DNFBP requirements. The Ministry of Economy and Tourism confirms its supervisory role over DNFBPs at state level and in commercial free zones.
A sensible geographic-risk methodology should therefore consider factors such as:
- customer residence and business location;
- incorporation or registration jurisdiction;
- beneficial-owner residence;
- source of funds and source of wealth;
- key counterparties;
- payment origin and destination;
- intermediary jurisdictions;
- branches and overseas operations; and
- expected cross-border activity.
The presence of one geographic factor should not automatically dictate the final customer rating. The assessment should reflect the business's approved risk methodology and the facts of the relationship.
A country-list update becomes a meaningful AML control only when the business can trace it from the regulatory change to the affected customer, decision and monitoring response. — KPM Global Services UAE consultant observation
What is the difference between the FATF black list and grey list?
FATF uses the terms “High-Risk Jurisdictions subject to a Call for Action” and “Jurisdictions under Increased Monitoring.” The first category involves significant strategic deficiencies and may require enhanced due diligence or countermeasures. Increased monitoring means a jurisdiction is working with FATF to address identified deficiencies under an agreed action plan.
As of the latest FATF publications dated 19 June 2026, the jurisdictions subject to a call for action remain the Democratic People's Republic of Korea, Iran and Myanmar. FATF's increased-monitoring list was also updated in June 2026, including the addition of Bosnia and Herzegovina and Iraq. Algeria and Namibia were no longer subject to increased monitoring following FATF's June review.
One distinction is particularly important for UAE compliance teams: FATF states that placement under increased monitoring does not, by itself, mean FATF is calling for enhanced due diligence against every relationship connected with that jurisdiction. FATF instead calls for a risk-based approach.
UAE businesses must still check whether UAE legislation, their supervisory authority or an applicable circular requires additional measures.
That is why copying a FATF list into screening software is not enough.
How should UAE businesses refresh AML controls after a country update?
A business should first verify the official update, identify which customers and transactions are affected, reassess relevant risk ratings and determine whether stronger controls are required. The response should then be documented, approved where appropriate and tested so the organisation can demonstrate that the regulatory change has been translated into an operating control.
1. Update the geographic-risk methodology
Start with the source of the change.
Confirm whether a jurisdiction has been added, removed or moved between categories. Record the publication date and identify any accompanying UAE regulatory measures.
Then review how the country appears within the business-wide risk assessment and customer risk-rating model.
A change may affect:
- customer onboarding risk;
- beneficial ownership risk;
- source-of-funds assessment;
- cross-border transaction risk;
- correspondent or intermediary exposure;
- customer review frequency; and
- escalation requirements.
Avoid changing scores manually without documenting why. Compliance teams should be able to explain which rule changed and how it affected the resulting classification.
2. Identify and reassess existing customers
A country-risk update can affect customers who were considered acceptable when they were first onboarded.
Search customer records for relevant exposure through addresses, incorporation data, beneficial owners, bank accounts, counterparties and historical transactions.
Where the updated exposure changes the customer's overall risk, businesses should consider an event-driven review rather than simply waiting for the next scheduled periodic review.
Example 1: A fictional Dubai-based corporate services provider has a long-standing customer incorporated in Europe, but one of its beneficial owners resides in a jurisdiction newly affected by a UAE high-risk country circular. The firm does not automatically exit the relationship. Its compliance team reassesses the beneficial-owner exposure, refreshes supporting information and documents whether the overall customer rating should change.
3. Strengthen EDD where the risk requires it
Enhanced due diligence should respond to the identified risk rather than become an exercise in collecting more paperwork.
Depending on the circumstances and applicable UAE requirements, the business may need additional information regarding:
- the customer and beneficial owner;
- ownership and control;
- the purpose of the relationship;
- expected transaction activity;
- source of funds;
- source of wealth where relevant;
- the commercial purpose of particular transactions; and
- independent information supporting the customer's explanation.
The current UAE AML framework requires regulated entities to consider country and geographic risk as part of their broader risk assessment, while Article 23 of Cabinet Resolution No. 134 of 2025 addresses high-risk countries specifically.
The important control is analysis. A passport, bank statement or corporate document is useful only if the compliance team evaluates whether the information is consistent with what it knows about the customer.
4. Review transaction-monitoring scenarios
Country risk can also change the significance of future transactions.
A UAE business may need to reassess scenarios involving:
- payments to or from higher-risk jurisdictions;
- unexplained routing through third countries;
- new counterparties in elevated-risk locations;
- significant changes in transaction frequency;
- transactions inconsistent with the customer's stated activity; or
- unusual cross-border movement of funds.
Avoid creating an alert simply because a country appears on a monitored list. That approach can produce unnecessary alerts without improving detection.
A more useful approach combines geography with customer type, value, frequency, counterparty, product, expected activity and transaction purpose.
Example 2: A fictional UAE accounting practice supports a trading company whose customer profile indicates business mainly within the GCC. The client suddenly begins receiving material payments from counterparties in a higher-risk jurisdiction. The accounting firm does not treat the geography alone as proof of suspicious activity, but the change may justify further enquiries, updated customer information and escalation under its AML procedures.
5. Keep sanctions and AML geographic risk separate
A high-risk or increased-monitoring classification is not the same thing as a sanctions designation.
FATF's June 2026 increased-monitoring guidance specifically describes the category as a process under which jurisdictions are working to resolve strategic deficiencies. FATF also states that its standards do not envisage cutting off entire classes of customers merely because a jurisdiction is under increased monitoring.
Businesses should therefore maintain distinct controls for:
- AML country risk;
- targeted financial sanctions;
- terrorist financing;
- proliferation financing;
- sanctions-evasion indicators;
- customer screening; and
- payment and counterparty screening.
The results can inform each other, but one should not automatically substitute for another.
What common mistakes do businesses make?
The most common weakness is treating a country-list update as a software administration task rather than a compliance event.
Other recurring mistakes include:
- treating every FATF grey-listed jurisdiction as automatically prohibited;
- changing a screening list without reassessing existing customers;
- applying identical EDD to every customer with geographic exposure;
- confusing AML country risk with sanctions status;
- relying only on a commercial country-risk database;
- overlooking beneficial-owner or counterparty locations;
- failing to update transaction-monitoring logic;
- keeping no record of why customer ratings changed;
- failing to communicate revised procedures to relevant staff; and
- updating a policy without testing whether the operational system reflects the change.
For increased-monitoring jurisdictions specifically, automatic de-risking can also conflict with FATF's stated risk-based approach.
What should an AML control-refresh file contain?
A well-organised compliance file should allow an internal reviewer, auditor or regulator to understand what changed, who was affected and how the business responded.
Businesses should consider retaining:
- the applicable FATF or UAE regulatory publication;
- date the update was identified;
- updated country-risk inventory;
- revised risk-scoring methodology where applicable;
- list of affected customers and beneficial owners;
- customer reassessment records;
- refreshed CDD or EDD documents;
- source-of-funds or source-of-wealth evidence where required;
- transaction-monitoring change records;
- screening-system change records;
- compliance review notes;
- escalation and approval records;
- revised policies or procedures;
- staff communication or training evidence; and
- testing results confirming that revised controls operate as intended.
The Ministry of Economy and Tourism's AML portal currently lists the 2025 AML law, its 2025 Executive Regulations and Circular No. 1 of 2026 concerning updated high-risk and increased-monitoring lists and related measures.
How can KPM Global Services UAE assist?
KPM Global Services UAE can support businesses that need to translate regulatory country-risk changes into workable AML procedures.
Depending on the activity, customer base and regulatory scope, support can include:
- reviewing business-wide and customer risk assessments;
- assessing geographic-risk methodologies;
- updating AML policies and procedures;
- reviewing customer due diligence and EDD files;
- supporting event-driven customer reviews;
- reviewing beneficial ownership documentation;
- assessing transaction-monitoring procedures;
- reviewing sanctions and screening workflows;
- preparing compliance documentation and control evidence; and
- helping management identify gaps before an internal or regulatory review.
For Dubai and wider UAE businesses, the aim should be a control framework that staff can actually apply rather than a policy that exists only on paper.
Businesses should also confirm sector-specific expectations with the supervisory authority relevant to their activity, particularly where Financial, Accounting, DNFBP, virtual asset or other regulated activities are involved.
What should businesses do when the next country update appears?
Treat the update as a defined compliance trigger.
Verify the source first. Identify affected relationships. Reassess customer and transaction risk. Apply proportionate EDD or other measures where required. Keep sanctions analysis separate. Record decisions and approvals. Then test whether the revised controls have actually been implemented.
FATF lists can change following plenary reviews, while UAE authorities may publish their own circulars and measures. Operational country-risk lists should therefore be checked against the latest applicable official sources rather than relying on an article or an old internal spreadsheet.
This article is for informational purposes and does not constitute legal, tax, accounting, or financial advice.
Questions and answers
Q: Does the UAE require enhanced due diligence for high-risk countries?
A: Enhanced measures may be required where a relationship or transaction presents higher geographic risk under the applicable UAE framework and regulatory instructions. Cabinet Resolution No. 134 of 2025 contains specific provisions for high-risk countries, so businesses should assess the particular classification and measures that apply.
Q: Is every FATF grey-listed country prohibited for UAE businesses?
A: No. FATF states that jurisdictions under increased monitoring are working to address identified strategic deficiencies and that its standards do not envisage automatic de-risking of whole classes of customers. UAE businesses must still apply their own risk-based controls and any applicable UAE requirements.
Q: Should existing customers be reviewed when a country's risk status changes?
A: Potentially, yes. If the update changes a customer's geographic exposure or overall risk rating, the business should consider an event-driven review, refreshed CDD or EDD and changes to ongoing monitoring.
Q: Is a high-risk country the same as a sanctioned country?
A: No. FATF country classifications and sanctions designations address different regulatory risks. Businesses should maintain separate AML geographic-risk and sanctions-screening controls, while considering where the risks overlap.
Q: How often should a UAE business update its high-risk country list?
A: The list should be monitored on an ongoing and event-driven basis rather than relying only on an annual update. Compliance teams should follow the latest applicable FATF publications and UAE supervisory circulars and reflect material changes promptly in their internal controls.
More in AML Compliance
View all AML Compliance →
How to Build a Customer Risk Rating Model for a DNFBP in the UAE
A practical UAE-focused guide to building a customer risk rating model for DNFBPs, covering AML/CFT risk factors, scoring, weighting, EDD triggers, reviews, governance, and documentation.

STR vs SAR in the UAE: When and How Suspicion Should Be Reported
Understand the practical difference between STR and SAR reporting in the UAE, when reasonable suspicion may arise, who must report, and how the goAML submission process typically works.

goAML Registration for UAE DNFBPs: Step-by-Step Guide
A practical UAE guide to goAML registration for DNFBPs, covering eligibility, documents, SACM access, application steps, common errors, and ongoing AML duties.