Which lists apply
All UAE persons and businesses must comply with the UAE's Local Terrorist List and the UN Security Council Consolidated List. Regulated sectors — financial institutions, DNFBPs and virtual asset service providers — are additionally expected to screen against the international lists relevant to their business, such as OFAC, EU and UK sanctions, as part of their AML programmes.
Screening duties apply to customers, and in practice also to suppliers, agents, beneficial owners and the parties behind the transactions you process.
When to screen
At minimum: at onboarding, before processing transactions where required, and whenever lists change. A customer who was clean in January can appear on a list in March — which is why one-off checks at account opening are not considered sufficient by supervisors.
Ongoing screening against updated lists, with alerts reviewed by a named person, is the standard examiners look for.
Handling matches without drowning in them
Screening common names against global lists generates false positives, and unmanaged alert volumes are where compliance teams lose their weekends. Fuzzy matching tuned to Arabic name transliteration, risk-based thresholds, and a clear disposition workflow — with every decision recorded — keep the process defensible and fast.
The audit trail is not bureaucracy: when a supervisor asks why an alert was cleared, 'analyst reviewed, evidence attached, decision logged' is the answer that closes the conversation.
Tooling that makes it routine
ICG MECOS implements sanctions, PEP and adverse-media screening for UAE businesses on ComplianceSuite, powered by LexisNexis WorldCompliance data — with batch and API screening options through Bridger Insight XG for higher volumes. Book a demo to see the workflow on your own data.
This article is general information from the ICG MECOS team, not legal advice. For guidance on your specific situation, speak to a qualified adviser or your regulator.